-- MySQL dump 10.13 Distrib 8.0.46, for FreeBSD15.0 (amd64) -- -- Host: localhost Database: defcon34 -- ------------------------------------------------------ -- Server version 8.0.46 /*!40101 SET @OLD_CHARACTER_SET_CLIENT=@@CHARACTER_SET_CLIENT */; /*!40101 SET @OLD_CHARACTER_SET_RESULTS=@@CHARACTER_SET_RESULTS */; /*!40101 SET @OLD_COLLATION_CONNECTION=@@COLLATION_CONNECTION */; /*!50503 SET NAMES utf8mb4 */; /*!40103 SET @OLD_TIME_ZONE=@@TIME_ZONE */; /*!40103 SET TIME_ZONE='+00:00' */; /*!40014 SET @OLD_UNIQUE_CHECKS=@@UNIQUE_CHECKS, UNIQUE_CHECKS=0 */; /*!40014 SET @OLD_FOREIGN_KEY_CHECKS=@@FOREIGN_KEY_CHECKS, FOREIGN_KEY_CHECKS=0 */; /*!40101 SET @OLD_SQL_MODE=@@SQL_MODE, SQL_MODE='NO_AUTO_VALUE_ON_ZERO' */; /*!40111 SET @OLD_SQL_NOTES=@@SQL_NOTES, SQL_NOTES=0 */; SET @MYSQLDUMP_TEMP_LOG_BIN = @@SESSION.SQL_LOG_BIN; SET @@SESSION.SQL_LOG_BIN= 0; -- -- GTID state at the beginning of the backup -- SET @@GLOBAL.GTID_PURGED=/*!80000 '+'*/ 'b4148ec7-37aa-11e6-bdd9-003048850f62:1-897773, c8b80935-c8ce-11ee-80c0-f48e38c15384:1-2519165, f9f9d5a4-23aa-11e5-b61b-0021856cfce2:1-316626'; -- -- Table structure for table `CallFors` -- DROP TABLE IF EXISTS `CallFors`; /*!40101 SET @saved_cs_client = @@character_set_client */; /*!50503 SET character_set_client = utf8mb4 */; CREATE TABLE `CallFors` ( `id` smallint NOT NULL AUTO_INCREMENT, `CFname` varchar(120) CHARACTER SET utf8mb4 COLLATE utf8mb4_0900_ai_ci NOT NULL, `whenexpired` datetime(6) DEFAULT NULL, `expired` tinyint(1) NOT NULL, `Descrip` text NOT NULL, `PageURL` varchar(256) CHARACTER SET utf8mb4 COLLATE utf8mb4_0900_ai_ci NOT NULL, PRIMARY KEY (`id`) ) ENGINE=InnoDB AUTO_INCREMENT=90 DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_0900_ai_ci; /*!40101 SET character_set_client = @saved_cs_client */; -- -- Dumping data for table `CallFors` -- LOCK TABLES `CallFors` WRITE; /*!40000 ALTER TABLE `CallFors` DISABLE KEYS */; INSERT INTO `CallFors` VALUES (1,'DEF CON 34 [Call For All Index]()','2000-03-01 00:00:00.000000',0,'Contests, Events, Villages, Parties, Talks, Workshops, Vendors, Press, Music... and more! Every year hundreds of dedicated hackers put their heads together and ask themselves one question \"How are we going to do it bigger, and better, than last year?\", and every year they do. Join them! Give us your craziest ideas, your fresh outlook, your passion. This is the place you can find all of the open calls for DEF CON Content, so pick your poison and show us what you got!','https://defcon.org/html/defcon-34/dc-34-cfi.html'),(2,'DEF CON 34 [Call For Papers]()','2026-05-01 23:59:59.000000',1,'DEF CON Main Stage talks are a premier venue for presenting new, unique, cutting edge research on hacking, information security and computer vulnerabilities. Presenters can choose a 20-minute, or 45-minute time slot. In some rare instances (for larger panels, for instance) DEF CON will consider talks for 75-minute time slots. DEF CON receives many submissions for a limited number of Main Stage slots and the selection is highly competitive.','https://defcon.org/html/defcon-34/dc-34-cfp.html'),(3,'DEF CON 34 [Call For Workshops]()','2026-05-01 23:59:59.000000',1,'DEF CON Workshops are four hour long, interactive classroom sessions. This longer format provides a much deeper dive into a subject area, enabling students with an opportunity to learn, experience and delve into a topic in a smaller group setting.','https://defcon.org/html/defcon-34/dc-34-cfw.html'),(4,'DEF CON 34 [Call For Demo Labs]()','2026-05-01 23:59:59.000000',1,'DEF CON Demo Labs is a dedicated area to showcase an open-source project, tool, or hardware you have been working on. The Demo Labs format is smaller and more intimate than a main talk and is intended to foster an engaging environment for interacting with fellow hackers, answering questions, and getting feedback from the community. Even if your project, tool, or hardware is in the early stages or still developing, consider submitting it.','https://defcon.org/html/defcon-34/dc-34-cfdl.html'),(5,'DEF CON 34 Policy @ [Call For Papers]()','2026-05-01 23:59:59.000000',1,'DEF CON Policy talks are a venue to engage in a dialogue about security, privacy and cyber policy. Presenters can choose a 25-minute, 50-minute time or 80-minute slots and Talk, Interview, Panel or Interactive Session formats.','https://defcon.org/html/defcon-34/dc-34-policy.html'),(6,'DEF CON 34 [Call For Content]()','2026-03-15 23:59:59.000000',1,'Submit this form if you would like to apply to be a Creator (Village, Community, or Contest) at DEF CON 34. ','https://forms.cloud.microsoft/pages/responsepage.aspx?id=Y3ofZveTWUeWkfjugk0fX0PgFsqyBAFCvLbSXDKxajdURjQ1Uk5SVEpFRVZOOTRFRUJMQjEyRkpYSi4u&route=shorturl'),(7,'DEF CON 34 [Call For Parties, Meetups, & Events]()','2026-03-15 23:59:59.000000',1,'DEF CON 34 Parties, Meetups & Events Application\r\n\r\nDoes your company/group want to throw the biggest, wildest DEF CON party ever? Rent out the pool, take over a huge space with arcade machines and carnival games—go all in and create the kind of legendary event that future hackers will hear about from their grizzled elders. If you’ve got the funds but don’t want to run the show, we’ll connect you with a party that needs a sponsor. Big budget? Awesome. Small budget? Also awesome. We’re here to make DEF CON nights unforgettable for everyone, so let’s make it happen!','https://forms.office.com/pages/responsepage.aspx?id=Y3ofZveTWUeWkfjugk0fX0PgFsqyBAFCvLbSXDKxajdUQTMxMjAwTjFXRzU5TzU5MTk3RzYzOTUxNi4u&route=shorturl'),(8,'DEF CON 34 [Call For Music]()','2026-05-01 23:59:59.000000',1,'DEF CON 34 Artist Application ','https://forms.office.com/pages/responsepage.aspx?id=skclAOGhkE6di7Ht8q0aPFA9iokCZH5GiDKDI2XiZ4dUODFGRFpWVURZNE5CTUJVS1ROUkpWR0ZCNS4u&route=shorturl'),(9,'DEF CON 34 [Official Soundtrack Application]()','2026-06-01 23:59:59.000000',1,'If you want to submit your original music production to be considered for DEF CON 34: The Official Soundtrack, you are in the right place!\r\n\r\nEvery year, the DEF CON Arts & Entertainment team puts together a fund-raising compilation that supports the Electronic Frontier Foundation (EFF.org), a 501c(3) dedicated to protecting Internet freedoms and privacy.\r\n\r\nThe compilation is digitally distributed to attendees of DEF CON (www.defcon.org) via DEF CON\'s media server, and also released online via Bandcamp It\'s all free/pay-what-you-want, and 100% of revenue (with the exception of the distributor cut) goes to the EFF.','https://forms.office.com/pages/responsepage.aspx?id=DQSIkWdsW0yxEjajBLZtrQAAAAAAAAAAAAMAAIhFF5lUMU1CVlZCTzlDSlkwUTJMM1JaOTNQSUI1Ti4u&route=shorturl'),(10,'DEF CON 34 [Call For Authors]()','2026-03-25 23:59:59.000000',1,'Following a successful first year, DEF CON 34 is excited to welcome independent authors back to the Vendor Area for dedicated book signing sessions!\r\n\r\nIf you\'ve written a book about security, hacking, technology, privacy—or anything that feels DEF CON, we encourage you to apply for a signing slot and connect directly with attendees.','https://defcon.org/html/defcon-34/dc-34-cfa.html'),(11,'DEF CON 34 [Call For Venders]()','2026-03-31 23:59:59.000000',1,'It\'s that time of year again – time to show us why you and your company should have a spot a DEF CON 34! Wow us with your innovation and gadgets. Delight our attendees with your fan favorites! So if you have one-of-a-kind, top-notch trinkets, let us see \'em! Feel free to send us any photos, videos, etc., that prove you\'re the perfect fit. To keep things fair, all Vendors accepted will be notified at the same time.\r\n\r\nNot selling anything, but still want to connect with our audience? Then check out our Exhibitor Call.','https://defcon.org/html/defcon-34/dc-34-vendor-app.html'),(12,'DEF CON 34 [Call For Exhibitors]()','2000-03-01 00:00:00.000000',0,'We\'re happy to announce the official Call for Exhibitors! DEF CON Exhibitors is an exciting and new space dedicated to companies and orgs that don\'t have physical items to sell but still have something to offer our attendees.\n\nProceeds from Exhibitors directly support official DEF CON parties, food and beverage tokens, and hotel stay for our content creators (Villages & Contests). In addition, last year we raised nearly $40k for approved non-profit villages that directly support the DEF CON community. This year, we\'re focused on supporting our content creators again and helping Villages and Contests grow.\n\nBeing an exhibitor means you want to connect with, and give back to, our community. We want to see exhibitors at DEF CON that DEF CON attendees want to see. Looking to get feedback from existing customers, recruit new talent or demo a new product relevant to our community? This is your opportunity.','https://defcon.org/html/defcon-34/dc-34-cfe.html'),(13,'DEF CON 34 [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'As an expansion to the services and aid DEF CON offers its content creators, we\'re very excited to announce our Call for Sponsors. We\'re using our reach into the community to help connect DEF CON content creators, such as our Villages, Contests, Parties, etc. with our fantastic community of potential sponsors!\r\n\r\nAs a content creator sponsor, it\'s important to know that you won\'t actually be sponsoring DEF CON itself (you can find out ways to support DEF CON through our Call for Exhibitors.\r\n\r\nWhat we aim to do is to find and qualify individuals and companies who reach out to us to become sponsors of our content creators, and then help facilitate the conversation between those creators and potential sponsors. Two of the most difficult parts of sponsorship pairings are the creators being upfront and honest with what they need, and the sponsors receiving the appropriate value add to their organization. Our Sponsorship department aims to help guide the conversation and work out a deal everyone can benefit from!','https://defcon.org/html/defcon-34/dc-34-cfs.html'),(14,'DEF CON 34 [Press Registration]()','2000-03-01 00:00:00.000000',0,'To register as press, please send an email to press [at] defcon ]dot[ org with the Subject: PRESS REG DEF CON. Please provide all of the details we request otherwise it only slows down your own approval, and there is a hard limit on the total number of press each year.','https://defcon.org/html/defcon-34/dc-34-press.html'),(15,'Telecom Village \n[Call For Papers/Workshops/Challenges]()','2026-07-10 23:59:00.000000',1,'Attention speakers! Are you passionate about Telecom Security? Here\'s your chance to address a dedicated audience that shares your enthusiasm. Submit your proposal to Telecom Village and become a speaker at Telecom village.','https://x.com/TelecomVillage/status/2023652284190851091?s=20'),(16,'Telecom Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'Be a vital part of the growing telecom security community by supporting Telecom Village. Your sponsorship helps us create an engaging and impactful experience for everyone. Let’s grow together with hand in hand support!','https://www.telecomvillage.com/sponsors'),(17,'Red Team Village [Call For Speakers]()','2026-05-31 23:59:59.000000',1,'The Red Team Village is focused on training the art of critical thinking, collaboration, and strategy in offensive security. The RTV brings together information security professionals to share new tactics and techniques in offensive security. Attendees may spend all three days engaged in introductory workshops, hands-on tactics or challenge themselves in an immersive Capture the Flag competition to put their newly obtained skills to the test.','https://sessionize.com/rtv-at-dc34'),(18,'Red Team Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',1,'We are hyped to be back for DEF CON 34 - \"Shadowrun.\" Whether you\'re a seasoned Street Samurai who has volunteered with us before or a Decker looking for your first big run, we\'re stoked to have you in the mix.','https://docs.google.com/forms/d/e/1FAIpQLSeipekN5RYjhZuAugeKOTG_z1bKqJ8ORX9YpfxNH7mdw7tkWA/viewform'),(19,'Red Team Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'The Red Team Village is the heartbeat of the offensive security community, and we\'re looking for partners to help lead our most interactive year yet! This year, we are prioritizing our Educational Mission—delivering the practical, hands-on learning that bridges the gap between theory and the real world.','https://drive.google.com/file/d/1344CxfPdZaCgOZqElDNIule9rLe8djVY/view'),(20,'Ham Radio Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',0,'Village staff handle running the village itself as well as the fox hunt contest table. Duties vary and include providing demos, talking with and answering questions from attendees, and running the fox hunt contest. During your shifts you may be using your own gear, village-owned gear, or gear from another volunteer (with their permission). This is a great chance to showcase what YOU love about ham radio as ambassadors of the hobby!','https://hamvillage.org/events/dc34/signup'),(21,'Ham Radio Village [Call For Papers]()','2026-07-26 23:59:59.000000',0,'Do you have an idea for a talk, demo, or presentation about something related to amateur radio? The Ham Radio Village is looking for all sorts of content for DEF CON 34! We accept a variety of topics related to ham radio, especially as it relates to other technical fields and experimentation. Shenanigans are encouraged!','https://cfp.hamvillage.org/dc34/cfp'),(22,'Aerospace Village [Call For Presentations]()','2026-05-01 23:59:59.000000',1,'Have a great talk ready to go about space systems, aircraft systems, or anything in-between? Now\'s your chance to propose your talk for the Aerospace Village for DEF CON 34! We will be carrying out a blind review and ranking of your submission as representative of our talks for the Aerospace Village.\r\n','https://forms.cloud.microsoft/pages/responsepage.aspx?id=dMlm786nyEeFJDgav6AbZ0PSiqD_B1NHmaVaEZjJrvlUODRJSkhNWEVRWVdIWVg3S1QwUzdHUkVWSy4u&route=shorturl'),(23,'Aerospace Village [Call For Workshops]()','2026-05-01 23:59:59.000000',1,'The Aerospace Village is looking to bring unique workshop experiences to DEF CON 34. These are hands on experiences where guests to the Aerospace Village at DEF CON 34 will be able to use their own devices to learn along side your instruction. We\'ll provide the projector and podium and you supply the knowledge! Workshops will be held inside of the Aerospace Village area.','https://forms.cloud.microsoft/pages/responsepage.aspx?id=dMlm786nyEeFJDgav6AbZ0PSiqD_B1NHmaVaEZjJrvlUNzRON0Y1Q1gzQ1g4NjNJRVBTSDdUWUlaMC4u&route=shorturl'),(24,'Radio Frequency Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'RF Hackers Sanctuary (RHFS) offers an environment where people come to learn about the security of radio frequency (RF) transmissions, which includes wireless technology, applications of software defined radio (SDR), Bluetooth (BT), Zigbee, WiFi, Z-wave, RFID, and all other protocols within the useable RF spectrum. RF Hackers Sanctuary is supported by a group of experts in the areas of information security as it relates to RF technologies. RF Hackers Sanctuary’s purpose is to provide an environment in which participants may explore these technologies with a focus on improving their skills. These learning environments are provided in the form of guest speakers, panels, and Radio Frequency Capture the Flag (RF CTF) games.','https://rfhackers.com/sponsors/'),(25,'Appsec Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',0,'Are you passionate about application security and want to get involved?\r\nIt takes a village to run a village. We are looking for volunteers to help us bring AppSec Village at DEF CON to life.\r\n\r\n','https://www.appsecvillage.com/volunteer'),(26,'Appsec Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'Become a Sponsor\r\nIs your organization passionate about application security and want to sponsor AppSec Village?\r\n\r\nAre you an AppSec or InfoSec vendor that would like to be recognized as a supporter of the AppSec Community?\r\nIs your organization taking the security of its software very seriously and would like its name connected with AppSec Village?\r\nThen become an AppSec Village 2026 Sponsor!','https://www.appsecvillage.com/sponsors'),(27,'Blacks In Cybersecurity [Call For Volunteers]()','2026-04-17 23:59:59.000000',1,'BIC VILLAGE @ DEF CON 34\r\nVOLUNTEER APPLICATION\r\nBIC Village @ DEF CON 34\r\nVolunteer Application is open here .','https://docs.google.com/forms/d/e/1FAIpQLSec2x4ko9tHNlbliJ7ikcweBA9k4e0UaaJNJ5OkkvYtm_DSOQ/viewform'),(28,'Blacks in Cybersecurity [Call For Papers]()','2026-05-15 23:59:59.000000',1,'Mission:\r\n\r\nThe Blacks In Cybersecurity Village seeks to bring culturally diverse perspectives to the holistic Cybersecurity community by way of a series of talks and a Capture The Flag event.','https://docs.google.com/forms/d/e/1FAIpQLSc-NDkBbxRPk8PcPywc8KFiSZzakppGNLlUTLP501LRXM2fag/viewform'),(29,'Bug Bounty Village [Call Index]()','2000-03-01 00:00:00.000000',0,'DEF CON 34 Call Index\r\n\r\nWelcome to the Bug Bounty Village Call Index! Below, you\'ll find all the ways you can get involved with Bug Bounty Village at DEF CON 34, happening August 6 to 9, 2026. Whether you\'re a researcher, speaker, sponsor, or volunteer, we invite you to be part of the action.','https://www.bugbountydefcon.com/call-index-2026'),(30,'Bug Bounty Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',0,'Bug Bounty Village - Call for Volunteers (DEF CON 34)\r\nOpen Now!\r\nJoin the Team: Help Make Bug Bounty Village a Success!\r\n​\r\nBug Bounty Village (BBV) is returning to DEF CON 34 in Las Vegas, August 6-9, 2026, and we need dedicated volunteers to help us make this year even better! Whether you’ll be onsite at DEF CON or want to contribute remotely, there are plenty of ways to get involved.\r\n\r\nVolunteering is a great way to gain experience, connect with top security professionals, and be part of the hacker community!','https://www.bugbountydefcon.com/call-for-volunteers'),(31,'Bug Bounty Village [Call For Papers]()','2026-05-31 23:59:59.000000',1,'Bug Bounty Village - Call for Papers (DEF CON 34)\r\nNow Open!\r\nShare Your Insights: Speak at Bug Bounty Village!\r\n​\r\n\r\n​Bug Bounty Village (BBV) is back at DEF CON 34 in Las Vegas, August 6-9, 2026, and we’re looking for engaging speakers and workshop hosts to share their expertise! Whether you\'re a seasoned security researcher or have fresh insights to bring to the bug bounty community, we want to hear from you.\r\n\r\nSubmissions are Open until May 15t','https://www.bugbountydefcon.com/call-for-papers'),(32,'Car Hacking Village [Call For Papers]()','2026-05-31 23:59:53.000000',1,'Car Hacking Village | DEFCON 34 Call For Papers - Talks (2026)\r\nTalks submitted to the Car Hacking Village at DEFCON should be about subjects with relevance to the automotive cybersecurity industry or car hacking. Some examples of accepted talks in the past include automotive vulnerability disclosures, car hacking tool exhibitions, and thought leadership on improving various areas of vehicle cybersecurity.','https://docs.google.com/forms/d/e/1FAIpQLSdK7c2tI39LuAWRonqZC5SlSerY7G4smCDp7zSVdaUUvhIbDg/viewform'),(33,'Car Hacking Village [Call For Challenges]()','2026-06-30 23:59:59.000000',1,'2026 Call for Challenges (CFC)\r\nFor those interested, we would like to invite you to submit challenges for the 2026 Car Hacking Village (CHV) CTF at DEFCON 34 in Las Vegas! We are looking for anywhere between 10 and 20 challenges of varying categories regarding the automotive industry. \r\n\r\nThe following are a list of Categories that the contest is interested in:\r\n\r\nReverse Engineering – data recovery/string searches/Forensics\r\n\r\nTelemetry – radio/etc\r\n\r\nGrand Theft Auto – challenges vs. car brought into the village\r\n\r\nCrypto\r\n\r\nVehicle Network – CAN/Auto-ETH/etc\r\n\r\nExploitation – stack/heap smashing, shell popping/etc','https://www.carhackingvillage.com/cfc'),(34,'Car Hacking Village [Call For Sponsors]()','2026-06-13 23:59:59.000000',1,'Why Sponsor Us?\r\nThe Car Hacking Village has been a prominent village within the DEFCON community. With over a decade of being a village a sponsor receives high visibility and recognition within the security community. Additionally, sponsorship demonstrates thought leadership, brings networking opportunities and provides access to untapped talent.\r\n\r\nBy sponsoring the Car Hacking Village, your company has the opportunity to show brand recognition within the automotive security space with an exposure of over 30,000+ conference attendees.','https://www.carhackingvillage.com/sponsorship'),(35,'Data Duplication Village [Call For Presentations]()','2026-06-30 11:59:00.000000',1,'CALL FOR DDV PRESENTATIONS OPEN\r\nThe Data Duplication Village is announcing their 2026 call for presentations to be held at DEF CON 33 in Las Vegas, NV on Friday, August 7th and Saturday, August 8th.\r\nThe Data Duplication Village\'s goal is to help the information security community by providing helpful information through duplication of large amounts of data including all the past hacking related convention material that can be found, rainbow tables, and more. During con, we also provide direct talks to attendees to further provide helpful information for storage related technology and data security.\r\n\r\nOur audience range from those who are new to data storage, transfer, and security to the most seasoned practitioners in the industry discussing their experiences and insights into the future of storage and data protection. New presenters are very welcome! This is your chance to give back to the community!','https://dcddv.org/dc34-cfp'),(36,'Data Duplication Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',1,'CALL FOR DDV VOLUNTEERS\r\nWE NEED YOUR HELP!\r\nYes, we’ll be back for 2026 and we’re looking for volunteers for DEF CON 34 in Las Vegas, NV for Thursday, August 6th through Sunday, August 9th. \r\n\r\nWHY VOLUNTEER?\r\nWe’re a volunteer run village, put on by and for the community, and were working hard to keep the distribution of information free. Since we don’t charge for our services, some costs are covered by DefCon itself but we rely only on our Volunteers to help prepare and run the village.\r\n\r\nWe need good, reliable folks to help us keep the village free. We have Volunteer opportunities for set-up on Thursday, drive intake, ongoing operations, all the way through tear-down on Sunday.','https://dcddv.org/dc34-vol-call'),(37,'Malware Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'Our Call for Sponsors is open now!\r\n!!! MV Sponsor Package PDF !!!\r\n\r\nWelcome to Malware Village by World Cyber Health!\r\n\r\nMalware Village is dedicated to providing a safe and engaging environment for participants to learn and share knowledge about malware analysis. Our mission is to equip attendees with the skills, techniques, and historical context needed to understand, research, and combat malware. Participants will gain hands-on experience with real-world analysis techniques, guided by seasoned infosec professionals. Beyond technical training, Malware Village fosters a strong community where researchers, enthusiasts, and professionals can connect. We welcome everyone—whether you\'re an artist creating malware-inspired art, a hardware researcher discovering unexpected connections to malware analysis, or a seasoned analyst reminiscing about early malware history. ','https://malwarevillage.org/sponsor.pdf'),(38,'Maritime Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',0,'Want to join our cause and/or volunteer for a MHV event?\r\nJoin our Community\r\n“It takes a village” to protect critical maritime infrastructure. We are always looking for aspiring villagers to join our cause and support the village with your many skills and networks. \r\n\r\nVolunteer\r\nGet to know us first by volunteering for a specific event. Tell us a bit about yourself with this form and we’ll get in touch with you.','https://maritimehackingvillage.com/volunteer'),(39,'Payment Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'Join Us in Securing the Future of Payments!\r\n\r\nAt Payment Village, we\'re on a mission to educate, train, and build awareness around the security of payment systems. We’re passionate about empowering the next generation of payment security experts through hands-on learning, research, and community engagement.\r\n\r\n\r\nYour sponsorship will help us continue to provide accessible, practical training at industry events, foster a vibrant community of researchers, and drive innovation in payment security.\r\n\r\n\r\nInterested in Sponsoring? Let’s discuss how your company can support open security research while gaining brand exposure at DEF CON and beyond.','https://www.paymentvillage.org/get-involved/sponsor'),(40,'Physical Security Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',1,'Volunteer with the Physical Security Village\r\nWe’re so glad you’re interested in being part of the PSV community! Please join our Discord server for announcements regarding volunteering opportunities.\r\n\r\nAlternatively, keep an eye on this page -we update it with the volunteer application form before each convention we need volunteers for.','https://docs.google.com/forms/d/e/1FAIpQLScXZzSmISdk54oS3YDki_X42WAVM6VztMKaWwsUxyxmBPe-4g/viewform'),(41,'Radio Frequency Village [Call For Papers]()','2026-06-07 23:59:59.000000',1,'The Radio Frequency Village is an annual event held at DEF CON in the fabulous Las Vegas, Nevada. Talks may be live, or pre-recorded at the discretion of the presenter. This year we return to the Las Vegas Convention Center. Due to challenges inherent to this environment, we *encourage* ALL presenters to pre-record and submit their talks to us. The acoustics in the new location are likely to be unfavorable, and pre-recording your talk is the best way to ensure folks can clearly hear your message. We will attempt to record live talks, but quality may vary and will certainly be less than ideal.','https://docs.google.com/forms/d/e/1FAIpQLSfF7ROnnNVi33gZxZpgcqSrhWfo_14Ja4nVGvt9KkNFef45Pw/viewform'),(43,'Payment Village [Call For Papers]()','2026-05-15 23:59:59.000000',1,'Call for Papers - Payment Village @ DEF CON 34 6-9th August 2026\r\n\r\nAbout the Village\r\n\r\nThe Payment Security Village explores the complex intersection of security, usability, and technology in probably the most commonly used security systems worldwide. As payment systems continue to evolve globally, we aim to showcase real-world security research and analyses that impact how we transact in our daily lives or even just illuminate the magic of the technology working behind the scenes to keep our money secure.','https://www.paymentvillage.org/get-involved/CFP'),(44,'Payment Village [Call For Volunteers]()','2026-06-01 23:59:59.000000',1,'Volunteer\r\nThe Payment Village is run by a team of volunteers who are passionate about Payments and providing learning opportunities for others. If you would like to be a part of our team please fill out the form. We are looking for volunteers who will be able to commit to all three days at DEF CON 34, Friday August 6th through to Sunday August 9th.\r\n\r\nWe will be working on a shift rotation and you are expected to volunteer for approximately five hours per day. Your hours will be assigned closer to the time of the conference. For your help and support we will provide you with access to the conference (a village badge), a village t-shirt and learning opportunities. We are looking for self-starters, those that are passionate about Payments and being a part of the DEF CON experience.','https://www.paymentvillage.org/get-involved/volunteer'),(45,'Cloud Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'Sponsorship Form - Cloud Village @DEF CON 34\r\nBecome a Sponsor in Cloud Village @DEF CON!!!\r\n\r\nWe at Cloud Village love to work with folks who share the same zeal to contribute to the cloud security community.\r\nPlease fill this form if you are interested in contributing towards this community. We will get in touch with you once we have your details.','https://docs.google.com/forms/d/e/1FAIpQLSfTXyArz3zV9cc0LZquTTzcRFjx9k5dGCPq_8b-49b7kiYFoQ/viewform'),(46,'Cloud Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',0,'Cloud Village Call For Volunteers - DEF CON 34\r\nWe are super excited to meet the Cloud Security community and join hands with us in DEF CON!\r\n\r\nWe look forward to join hands with cool folks like you and welcome you to the family!','https://docs.google.com/forms/d/e/1FAIpQLSf_0KXHMPvTv9d5JSt4anE1OV6PY7I3VoTEOTFC6WJSix49-w/viewform'),(47,'Cloud Village [Call For Labs]()','2026-05-24 23:59:59.000000',1,'Cloud Village Call For Labs - DEF CON 34\r\nWelcome to Cloud Village Labs, a brand-new initiative from the Cloud Village community at DEF CON — built for practitioners who love teaching through doing.\r\nWe’re looking for hands-on contributors who want to run short, focused learning sessions. Think:\r\nShorthand techniques and time-saving tips\r\nTool setup and walkthroughs\r\nAutomation tasks and their real world implementation\r\n2-hour workshop\r\nAny hack or habit that makes life better in cloud security\r\nIf you have something valuable, practical, and worth sharing, we’d love to hear from you. Whether it’s niche or broad, new or battle-tested, if it’s useful to the community, it’s perfect for Labs!\r\n\r\nSessions will be informal, demo-heavy, and deeply practical\r\nThink of it as the hacker’s chalkboard. No fluff, just high-signal teaching.','https://docs.google.com/forms/d/e/1FAIpQLSeIW8zz7kbZ_UWuZLCK1xfsP9uAsyjn1r6W4PGuuoKXPLTmwA/viewform'),(48,'Cloud Village [Call For Papers]()','2026-05-24 23:59:59.000000',1,'Cloud Village Call For Papers - DEF CON 34\r\nBecome a speaker in Cloud Village @DEF CON!!!\r\n\r\nIf you love cloud security and want to talk in front of a more targeted audience who shares the same zeal as you. Submit your proposal to Cloud Village!\r\nWe are looking forward to four kinds of proposals:\r\n- Talks (30 - 45 minutes - Detailed research talks)\r\n- Workshops (1 - 2 hours - Hands-On or Instructor-Led training for free)\r\n- Tool Demo (20 - 30 minutes)\r\n- Lightning Talks (10 - 20 mins talk to cover quick, short-hand techniques)\r\nPlease note that the proposals shall be focused on cloud security.\r\n\r\nWe will provide you with a place to present, a room full of professionals ready to talk, an environment filled in with energy and fun, and a lot of free hugs. Abstract of accepted talks will be posted on Cloud Village\'s website with your names and Twitter handles.','https://docs.google.com/forms/d/e/1FAIpQLSfk31a2h-RjDC9XcV9JLu4ZiGUxpIa5igT1FgI_ExfVhJWKTQ/viewform'),(49,'Recon Village [Call For Papers]()','2026-06-15 23:59:59.000000',1,'We\'re looking for speakers who are passionate about OSINT, reconnaissance, and security research. Whether you\'re a seasoned speaker or presenting for the first time, we want to hear from you!','https://reconvillage.org/cfp'),(50,'Adversary Village [Call For Papers]()','2026-05-31 23:59:59.000000',1,'Adversary Village is a community initiative which purely focuses on Adversary simulation, adversary emulation, threat/APT/ransomware emulation, breach and attack simulation, threat actors, adversary groups, supply chain security, adversary tactics, life, adversary philosophy, urban survival skills and purple teaming.\r\nThe goal of the Adversary Village is to build an open Security community for the researchers and organizations, who are putting together new means, methodologies towards the simulation and emulation of adversary tactics and purple teaming.\r\n\r\nPlease submit your awesome research to Adversary Village at DEF CON 34, this year.','https://adversaryvillage.org/call-for-papers/'),(51,'Bug Bounty Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'Bug Bounty Village - Call for Sponsors (DEF CON 34)\r\nNow Open!\r\nJoin Us in Growing the Bug Bounty Community!​\r\n\r\n​​​Bug Bounty Village (BBV) is returning to DEF CON 34 (August 6-9, 2026, Las Vegas), and we’re looking for sponsors who want to engage with top bug bounty hunters, security researchers, and ethical hackers.\r\n\r\nSponsoring BBV means aligning your brand with some of the brightest minds in cybersecurity while demonstrating your commitment to ethical hacking, responsible disclosure, and industry innovation. Your support helps us bring world-class content, interactive challenges, and networking opportunities to DEF CON attendees.','https://www.bugbountydefcon.com/call-for-sponsors'),(52,'Bug Bounty Village [Call For Events]()','2000-03-01 00:00:00.000000',0,'Bug Bounty Village - Call for Events (DEF CON 34)\r\nNow Open!\r\nHosting a Bug Bounty Meetup or Networking Event? Let Us Help Spread the Word!\r\n​\r\nBug Bounty Village (BBV) is excited to support bug bounty-related meetups, networking events, and social gatherings happening alongside DEF CON 34 (August 6-9, 2026, Las Vegas). If your company or organization is hosting an event for the security and hacker community, let us know—we’d love to help promote it!','https://www.bugbountydefcon.com/call-for-events'),(53,'Nix Vegas [Call For Sponsors]()','2026-06-15 23:59:59.000000',0,'DEF CON\'s theme this year is Agency, take a second to read about it here.\r\n\r\nWhile we are still hard at work on our art and theme this year, we would like to challenge you to submit talks that answer to our take on the DEF CON theme:\r\n\r\nStarve the beast: How can you use Nix and NixOS to reclaim your digital agency?\r\nFeed your community: How can we support others doing the same by rolling our own tools and build infrastructure?\r\nResources, time, and energy: How can we use Nix to connect ordinary users with the developers who made all the software they depend on?\r\nCFP','https://defcon.social/@nixvegas/116393680217249385'),(54,'Crypto Privacy Village [Call For Artists]()','2000-03-01 00:00:00.000000',0,'Crypto & Privacy Village - Call for Artists\r\n\r\nThe Crypto & Privacy Village is seeking artwork for our 2026 Gold Bug Contest.\r\n\r\nWhat are we looking for?\r\n\r\nAnything? Everything! While we do have some ideas already in mind, our puzzle team is also looking to your artwork for inspiration. Any medium will be considered. Please keep in mind:\r\n\r\n\r\nThere should be some physical aspect that can be displayed and/or auctioned.\r\nThe art piece will need to be transported to/from Las Vegas.\r\nDEF CON is held at the Las Vegas Convention Center. We\'re not sure what crazy things you can come up with, but it must be allowed there (e.g. no fire, suspicious-looking packages, hazardous materials, etc.)','https://docs.google.com/forms/d/e/1FAIpQLScvvITG9PYS8bFrnGPRmQpOPUHyIx1YUQmClYHucCzCGoU_3Q/viewform'),(55,'Bio Hacking Village [Call For Papers/Workshops]()','2026-05-15 08:59:59.000000',1,'Biohacking Village | DEF CON 34: CFP Talks and Workshops Submissions (2026)\r\nTalks should be bold, address problem(s) and provide solutions and/or resources for getting cybersecurity in healthcare, medical, citizen/community science and IoMT connected devices to an improved, more stable and resilient place.\r\n\r\n**The BHV CFP will close on Saturday, 12 April 2025 at 1159 US Eastern Time. Acceptance Notifications will go out on Friday, May 15th 2026.**\r\n\r\nCFP review is as pragmatic and de-identified as we can make it. Please do not include your name or any identifying information in your abstract or we may disqualify you.\r\n\r\nFor more info on talk selection metrics: https://www.villageb.io/speaker-lab\r\n','https://docs.google.com/forms/d/e/1FAIpQLSe2OZ8Z2qvivF2Q5OF4TLvFdQZ3I3thIA7xKoyfq1Xfr-DR_w/viewform'),(56,'AppSec Village [Call For Proposals]()','2026-05-31 23:59:59.000000',1,'Ready to step up from attendee to speaker? AppSec Village is looking for the next wave of talks, panels, workshops, and tool demos for DEF CON 34. We want sessions that challenge assumptions, share new research, and make attendees rethink how they approach AppSec.\r\n\r\nWe actively seek speakers from underrepresented communities, first-time presenters, and seasoned veterans alike. The strongest lineups come from the widest range of perspectives.','https://sessionize.com/appsec-village-def-con-34/'),(57,'IoT Village [Call For Papers]()','2026-05-22 23:59:59.000000',1,'Submit to the IoT Village CFP for DEF CON 34!\r\n \r\nCFP closes May 22nd. Please fill out each question. IoT Village will reach out via email from iotvillage@ise.io regarding your acceptance, so please use a valid email address! If a speaker does not respond to their acceptance email within 48 hours, their slot will be offered to another session.\r\n\r\n IoT Village is not responsible for speaker badge distribution, scheduling or recording your talks. That is all handled by DEF CON. If you have concerns or preferences for a day to give your talk, please let us know in the form. \r\n\r\nPlease note that if your talk has many speakers, DEF CON may not provide badges for each speaker.','https://share.hsforms.com/1VJautye_QXSwDfpUWz9xJQ4a9bq'),(58,'Malware Village [Call For Papers]()','2026-05-31 07:30:00.000000',1,'','https://sessionize.com/malware-village-defcon34'),(59,'Physical Security Village [Call For Exhibits]()','2026-05-17 23:59:59.000000',1,'Hey there! This is a form for all those that are interested in presenting a talk or bringing an exhibit in the Physical Security Village at DEF CON!\r\n\r\nWe are the Physical Security Village and for those that don\'t know (first of all, how did you get ahold of this form), we are an initiative based out of Toronto Canada that has committed to teaching Physical Security concepts at various Security Conferences! For those that are interested in the type of content that we do, feel free to browse our website at http://www.physsec.org.\r\n\r\nWe are always looking for people that are interested in helping out with and bringing new ideas to the village! This is normally in the form of exhibits! In the past we’ve had exhibits including one on the mechanics of a shopping cart auto locking mechanism. If this sounds like you, feel free to fill in this form!\r\n','https://docs.google.com/forms/d/e/1FAIpQLScIJk1lw5p1LX22u_EM1dWcEYeTBfHlJnBpWDfxetVgIce3Tg/viewform'),(60,'Physical Security Village [Call For Papers]()','2026-05-17 23:59:59.000000',1,'Hey there! This is a form for all those that are interested in presenting a talk or bringing an exhibit in the Physical Security Village at DEF CON!\r\n\r\nWe are the Physical Security Village and for those that don\'t know (first of all, how did you get ahold of this form), we are an initiative based out of Toronto Canada that has committed to teaching Physical Security concepts at various Security Conferences! For those that are interested in the type of content that we do, feel free to browse our website at http://www.physsec.org.\r\n\r\nWe are always looking for people that are interested in helping out with and bringing new ideas to the village! This is normally in the form of talks! In the past we’ve had talks including one on Biometry hacking. If this sounds like you, feel free to fill in this form!','https://docs.google.com/forms/d/e/1FAIpQLSf_hhnhB3nE0e4m35J80QnfRXL9STIMYpLk79I-Ri89jxHHSQ/viewform'),(61,'Physical Security Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'Call For Sponsors\r\n\r\nSupport the village, support the community, We\'re seeking sponsors to help us level up this year - weither it\'s equipment, swag, challenge materials, or something else. It\'s a great way to get your name in front of hackers who care about the physical layer.','https://x.com/physsec/status/2046980859060768768?s=20'),(62,'Blacks in Cybersecurity [Call For Sponsors]()','2000-03-01 00:00:00.000000',1,'','https://x.com/BlackInCyberCo1/status/2046937118304358846?s=20'),(64,'Maritime Village [Call For Presentations]()','2000-03-01 00:00:00.000000',0,'','https://docs.google.com/forms/d/e/1FAIpQLSfFEJk4II0RLhkFfaIXtRWpSjn6l9AAwmct5UVBn4RFaKckCg/viewform'),(65,'Maritime Village [Call For Challenges]()','2000-03-01 00:00:00.000000',0,'','https://docs.google.com/forms/d/e/1FAIpQLSdvr8rkP9Xw-sQXtgqDn1zkZ07mFDu9FUHd0CUHzye0le-DAg/viewform'),(66,'Maritime Village [Call For Games]()','2000-03-01 00:00:00.000000',0,'','https://docs.google.com/forms/d/e/1FAIpQLSe1g9WVuVshAzAdE0bSW1oKzCfDyLBc_2k7s7ibMHDDTD9ndQ/viewform'),(67,'Maritime Village [Call For Workshops]()','2000-03-01 00:00:00.000000',0,'','https://docs.google.com/forms/d/e/1FAIpQLSdRtXyy677F-PhErcFSKblSJCbT04mPErJWwEYmY6eLq4UsmA/viewform'),(69,'Maritime Village [Call For Index]()','2000-03-01 00:00:00.000000',0,'','https://maritimehackingvillage.com/cfx-2026'),(70,'Crypto Privacy Village [Call For Papers]()','2026-05-29 23:59:59.000000',1,'Call for Papers (CFP)\r\nThe Crypto & Privacy Village Call for Papers (CFP) is looking for top-notch presentations, discussions, panels, workshops, show & tell, and other creative online content! https://cfp.cryptovillage.org/\r\n\r\nThe Crypto & Privacy Village is excited to announce its participation in DEF CON 34: Agency. We are looking for top-notch presentations, discussions, panels, workshops, show & tell, and other creative online content!\r\n\r\nIn our 13th year, our theme is TBA. We are looking for a combination of pre-recorded and live content, and we’ll be accepting any formats from 5-minute lightning talks to workshops, panels, or hour-long streams. Want to stay anonymous? Let us know! If you’ve got an idea for something else you want to do, we’d love to hear it!','https://cryptovillage.org/cfp/'),(71,'Packet Hacking Village [Call For Papers]()','2026-07-10 23:59:59.000000',0,'Packet Hacking Village Talks at DEF CON 34 Call for Presentations Now Open\r\n\r\nOVERVIEW\r\nThe Wall of Sheep would like to announce a call for presentations at DEF CON 34 in Las Vegas, NV from Friday, August 7th to Sunday, August 9th. Packet Hacking Village Talks goal is to deliver talks that increase security awareness and provide skills that can be immediately applied after the conference. Our audience ranges from those who are new to security to the most seasoned practitioners in the security industry. We are accepting submissions from individuals and organizations on any of the topic areas, including, but not limited to, the following technologies and applications:\r\n\r\nUsing AI for packet analysis, for network IDS, for honeypots, for enhanced log analysis/threat detection, for detecting fake AI images/videos\r\nImmutable DevOps\r\nInfrastructure as code\r\nAnsible playbooks for security\r\nOpensource CI/CD pipeline security enhancements\r\nWriting AI effective prompts that enhance or augment security/networking/DevOps\r\nBypassing AI vision\r\nDetecting fake LinkedIn profiles\r\nAwareness: Security awareness program success and failure stories.\r\nCloud Security: Hacks and tricks for assessing and testing services.\r\nCompliance: How to use regulatory compliance requirements in your favor to enhance your overall funding and security posture.\r\nNetworking and Cybersecurity: The latest hacks, trends and technologies in networking and cybersecurity.\r\nSpy-level makeup art (e.g., wigs, prosthetic noses, etc.)\r\nSupply Chain Security: Building security into the supply chain process to reduce risk.\r\nThreat Defense: Advanced techniques for defending networks, systems, and services from cyberthreats.\r\nTools, Techniques, and Procedures: network sniffing, intrusion detection, monitoring, forensics, DFIR log analysis, collection & visualization, threat hunting, EDR telemetry, lolbin’s for defense, detecting download cradles, using the ATT&CK framework for defense, Incident response process and procedures and/or recovery, automation','https://www.phvillage.io/pages/dc34-talks-cfp/'),(76,'Recon Village [Call For Workshops]()','2026-06-25 23:59:59.000000',1,'We are seeking submissions for Deep Hands-On Workshops at Recon Village.\r\n\r\nWorkshops should be practical, technical, and focused on helping participants learn by doing. We welcome workshop submissions related to Open Source Intelligence (OSINT), Information Gathering, and Reconnaissance.','https://sessionize.com/recon-village-call-for-workshops/'),(77,'Recon Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',8,'Support Recon Village\r\nHelp us keep the OSINT community thriving\r\n\r\nRecon Village started as a small gathering of OSINT enthusiasts at DEF CON. Over the years, it has grown into one of the most vibrant communities at the conference - a place where researchers, professionals, and curious minds come together to share knowledge, learn from each other, and push the boundaries of open-source intelligence.\r\n\r\nWe\'ve always been community-driven. Every talk, every workshop, every contest is organized by volunteers who believe in making knowledge accessible. We don\'t charge attendees. We don\'t gatekeep information. We believe that when people share freely, everyone grows.\r\n\r\nBut running a village takes resources - badges, infrastructure, equipment, and countless hours of work. That\'s where sponsors come in. Your support helps us keep Recon Village free and open for everyo','https://reconvillage.org/call-for-sponsors'),(78,'Recon Village [Call For Sponsors]()','2000-03-01 00:00:00.000000',0,'Support Recon Village\r\nHelp us keep the OSINT community thriving\r\n\r\nRecon Village started as a small gathering of OSINT enthusiasts at DEF CON. Over the years, it has grown into one of the most vibrant communities at the conference - a place where researchers, professionals, and curious minds come together to share knowledge, learn from each other, and push the boundaries of open-source intelligence.\r\n\r\nWe\'ve always been community-driven. Every talk, every workshop, every contest is organized by volunteers who believe in making knowledge accessible. We don\'t charge attendees. We don\'t gatekeep information. We believe that when people share freely, everyone grows.\r\n\r\nBut running a village takes resources - badges, infrastructure, equipment, and countless hours of work. That\'s where sponsors come in. Your support helps us keep Recon Village free and open for everyone.','https://reconvillage.org/call-for-sponsors'),(81,'DEF CON 34 Policy Call For Volunteers \n[BlueSky post]() \n[Google Form]()','2000-03-01 00:00:00.000000',0,'Attaché (Volunteer) Interest Form\r\nHere’s your chance to get involved with Policy@DEF CON! \r\n\r\nSpend a few hours on-site with us and get a first hand view of what it takes to gather hackers and policymakers at the largest hacker con.\r\n\r\nBenefits are sure to include swag, a fun time, cool people, and our undying gratitude! Must have your own DEF CON badge to participate.','https://bsky.app/profile/defconpolicy.bsky.social/post/3mnkoakr7ps26|https://docs.google.com/forms/d/e/1FAIpQLScyJd-GwFXVxS6Bxk0W-crbAUneOnfnue46XodFIK1lytNkJQ/viewform'),(82,'Blue Team Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',0,'Blue Team Village Volunteer DC34\r\n\r\nBlue Team Village (BTV) is the defensive side of the hacker mirror — a hands-on space where incident responders, threat hunters, detection engineers, forensic analysts, and curious newcomers come together to share tools, tactics, and war stories. Founded “for and by defenders,” BTV runs entirely on volunteer energy, and DC 34 is right around the corner.','https://docs.google.com/forms/d/e/1FAIpQLSc_EEMmjGNAnnRY4JRbkaFZLnkDgiE6T0-FLW6G0zjMMVv5ag/viewform'),(83,'Quantum Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',1,'Call for Volunteers\r\nThis year\'s theme is: Agency\r\nDates: August 7th-9th\r\nLocation: Las Vegas Convention Centre, Las Vegas, NV, USA \r\n\r\nQuantum Village is a 501(c)(3) non-profit and is primarily volunteer driven, in order to create the best possible Quantum Village @ DEF CON experience. For the last 5 years we have been creating accessible and interactive spaces for hackers, technologists and the curious to engage, learn and hack with Quantum Technologies at DEF CON and beyond. \r\n\r\nVolunteering is a fun opportunity to pay it forward but equally a unique professional growth opportunity and way to immerse yourselves in a community dedicated to developing and hacking quantum technologies! ','https://docs.google.com/forms/d/e/1FAIpQLSca8XQIKAa5clflDizJXiJDinl6XT0TGhp6RdXHvj4K0RQS-Q/viewform'),(84,'Quantum Village [Call For Content]()','2000-03-01 00:00:00.000000',0,'Quantum Village @ DEF CON 34: Call for Workshops/Talks/Demos\r\nQuantum Village @ DEF CON 34 \r\nThis year\'s theme is: Agency\r\nThis year we are showing preference for workshops and are seeking deep subject matter experts to help guide the hackers and technologists of DEF CON to deeper understanding and appreciation of all things quantum.\r\n\r\nWe are looking to get all of the responses in by end-May and then quickly turned around! If you have multiple ideas for talks/workshops, or want to bring a talk and a demo, say, then please complete separate applications for each.','https://docs.google.com/forms/d/e/1FAIpQLScxabiE8Q6oReecMM8epsHf3vijBz3AEurepgB9YWXSzpRiBw/viewform'),(85,'Lock Pick Village [Call For Content]()','2000-03-01 00:00:00.000000',0,'DEF CON 34 LPV Call for Content\r\nTOOOL is once again proud to be hosting DEF CON\'s Lock Pick Village! An important part of the LPV is the many informative talks hosted throughout the weekend, furthering our mission to advance public knowledge about locks and lockpicking! To that end, we are excited to officially open our call for content. If you have a locksport themed talk or presentation please submit it below.\r\n\r\nWe\'re also excited to continue bolstering the contests side of our content this year. We have an official dozier drill tourney on the DEF CON contest list, but if you have something you\'d like to pilot we\'d love to hear about it!','https://docs.google.com/forms/d/e/1FAIpQLSeqHGDjJThnH_mZLsEUH1zETNFhwoGdncecoVMffocnMPzMfA/viewform'),(86,'Voting Village [Call For Papers]()','2026-07-08 23:59:59.000000',0,'The Voting Village at DEF CON is the first public forum where election systems experts, hackers and members of the public have legal, unconstrained, hands-on experience with actual voting systems used in the United States and elsewhere. It has become a premier venue for exploring the theory and practice of election security. The Voting Village is returning for its tenth year at DEF CON, August 7–9, 2026, at the Las Vegas Convention Center.\r\n\r\nOnce again this year, the Voting Village will feature a two-day Symposium on Election Integrity on August 7th and 8th (Friday and Saturday). We solicit talks and panels that leave attendees and the media with an accurate and realistic understanding of the state of election technology and security in the U.S. and elsewhere.','https://votingvillage.info/defcon-2026/cfp'),(87,'AI Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',0,'AIV Volunteers - DEFCON 34\r\nThe AI Village @ DEFCON is looking for volunteers to help out at DEFCON 34! Please use this form to get in touch and let us know your availability. If you have any questions, please email sam@aivillage.org','https://docs.google.com/forms/d/e/1FAIpQLSfM0m30Hia3DHkFfnHaGqIINMgRYCBlW0Dfgkl1EXR3QdHTnw/viewform'),(88,'Game Hacking Village [Call For Volunteers]()','2026-07-15 23:59:59.000000',0,'','https://docs.google.com/forms/d/e/1FAIpQLScjPTSrQmO2ZVbAJZdkYZ8pf9VOkVjbCRUb4XmMSxdI8h9V0Q/viewform'),(89,'Recon Village [Call For Volunteers]()','2000-03-01 00:00:00.000000',0,'','https://reconvillage.org/call-for-volunteers'); /*!40000 ALTER TABLE `CallFors` ENABLE KEYS */; UNLOCK TABLES; -- -- Table structure for table `DCannouncements` -- DROP TABLE IF EXISTS `DCannouncements`; /*!40101 SET @saved_cs_client = @@character_set_client */; /*!50503 SET character_set_client = utf8mb4 */; CREATE TABLE `DCannouncements` ( `ID` int NOT NULL AUTO_INCREMENT, `url` varchar(512) CHARACTER SET utf8mb4 COLLATE utf8mb4_0900_ai_ci NOT NULL, `descrip` varchar(1024) CHARACTER SET utf8mb4 COLLATE utf8mb4_0900_ai_ci NOT NULL, `datewhen` datetime NOT NULL DEFAULT CURRENT_TIMESTAMP, PRIMARY KEY (`ID`) ) ENGINE=InnoDB AUTO_INCREMENT=327 DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_0900_ai_ci; /*!40101 SET character_set_client = @saved_cs_client */; -- -- Dumping data for table `DCannouncements` -- LOCK TABLES `DCannouncements` WRITE; /*!40000 ALTER TABLE `DCannouncements` DISABLE KEYS */; INSERT INTO `DCannouncements` VALUES (208,'https://bsky.app/profile/dianainitiative.bsky.social/post/3meljxfgyg32y','The Diana Initiative 2026 - virtual only - [Call For Presentations]() opens','2026-02-16 13:02:01'),(209,'https://defcon.org/#34rooms|https://forum.defcon.org/node/255428','DEF CON 34 room blocks open! \r\n[DC Home page]() \r\n[DC Forum]()','2026-02-17 00:58:14'),(211,'https://defcon.org/html/defcon-34/dc-34-cfi.html','DEF CON [Call Fors Everything]() Opens','2026-02-17 01:23:51'),(212,'https://bsky.app/profile/dcgvr.bsky.social/post/3mdccadvvqk25','[DCGVR going onto hiatus](), will not be at DC34','2026-02-17 23:47:03'),(213,'https://x.com/TelecomVillage/status/2023652284190851091?s=20','Telecom Village [Call For Papers]()','2026-02-18 00:08:14'),(214,'https://defcon.org/html/links/dc-news.html#ctforg','[Introducing the New DEF CON CTF Organizers](): Benevolent Bureau of Birds!','2026-03-03 21:44:31'),(215,'https://defcon.org/html/defcon-34/dc-34-villages.html|https://defcon.org/html/defcon-34/dc-34-communities.html|https://defcon.org/html/defcon-34/dc-34-contests.html|https://defcon.outel.org/dcwp/dc34/activities/villages/|https://defcon.outel.org/dcwp/dc34/peopleandorgs/communities-table/|https://defcon.outel.org/dcwp/dc34/activities/c/','Initial release of Accepted DC Content \nDC.org - [Villages]() - [Communities]() - [Contests]() \nTheOne! - [Villages]() - [Communities]() - [Contests]()','2026-03-08 15:33:37'),(216,'https://defcon.org/html/links/dc-news.html#prereg34','[DEF CON 34 Pre-Registration is Open!]()\r\n','2026-03-08 16:29:03'),(217,'https://sessionize.com/rtv-at-dc34','Red Team Village [Call For Speakers/Presentations]()','2026-03-08 16:57:12'),(218,'https://forms.gle/qbVorEHHoYA9p8D38','Red Team Village [Call For Volunteers]()','2026-03-08 16:57:12'),(219,'https://drive.google.com/file/d/1344CxfPdZaCgOZqElDNIule9rLe8djVY/view?usp=sharing','Red Team Village [Call For Sponsors]()','2026-03-08 16:57:12'),(220,'https://redteamvillage.io/','Red Team Village [Call For All]()','2026-03-08 17:00:22'),(221,'https://hamvillage.org/events/dc34','Ham Radio Village [Call For Volunteers]()','2026-03-09 01:42:05'),(222,'https://cfp.hamvillage.org/dc34/cfp','Ham Radio Village [Call For Papers]()','2026-03-10 03:59:18'),(223,'https://defcon.social/@defcon/116202140503945408|https://defcon.org/html/defcon-34/dc-34-theme.html','DEF CON 34 Theme is announced - \'Agency\' \n[Mastodon]() \n[DC34 website]()','2026-03-10 04:39:44'),(224,'https://bsky.app/profile/aerospacevillage.bsky.social/post/3mgmwspm5in2k|https://defcon.social/@Hank/116206481142874602','Aerospace Village Call For Presentations \n[BlueSky]() \n[Mastodon]()','2026-03-11 07:04:03'),(225,'https://bsky.app/profile/aerospacevillage.bsky.social/post/3mgpgn7zkkr24','Aerospace Village [Call For Workshops]()','2026-03-11 07:08:25'),(226,'https://defcon.social/@toxicbbq/116234341006335465','[Toxic BBQ]() - Aug 6 Thursday Meetup for DC34','2026-03-15 10:32:23'),(227,'https://defcon.social/@DianaInitiative/116241571094475012','The Diana Initiative [Ticket Sales Opens]()','2026-03-17 07:39:52'),(228,'https://rfhackers.com/sponsors/','Radio Frequency Village [Call For Sponsors]()','2026-03-27 10:01:18'),(229,'https://www.appsecvillage.com/volunteer','Appsec Village [Call For Volunteers]()','2026-04-01 01:30:50'),(230,'https://www.appsecvillage.com/sponsors','Appsec Village [Call For Sponsors]()','2026-04-01 01:30:50'),(231,'https://www.blacksincyberconf.com/call-for-papers','Blacks in Cybersecurity [Call For Papers]()','2026-04-01 23:40:12'),(234,'https://www.bugbountydefcon.com/call-for-volunteers','Bug Bounty Village [Call For Volunteers]()','2026-04-01 23:40:12'),(235,'https://www.bugbountydefcon.com/call-for-papers','Bug Bounty Village [Call For Papers]()','2026-04-01 23:40:12'),(236,'https://docs.google.com/forms/d/e/1FAIpQLSdK7c2tI39LuAWRonqZC5SlSerY7G4smCDp7zSVdaUUvhIbDg/viewform','Car Hacking Village [Call For Papers]()','2026-04-02 00:35:53'),(237,'https://www.carhackingvillage.com/cfc','Car Hacking Village [Call For Challenges]()','2026-04-02 00:35:53'),(238,'https://www.carhackingvillage.com/sponsorship','Car Hacking Village [Call For Sponsors]()','2026-04-02 00:35:53'),(239,'https://dcddv.org/dc34-cfp','Data Duplication Village [Call For Presentations]()','2026-04-02 20:36:29'),(240,'https://dcddv.org/dc34-vol-call','Data Duplication Village [Call For Volunteers]()','2026-04-02 20:36:29'),(241,'https://malwarevillage.org/sponsor.pdf','Malware Village [Call For Sponsors]()','2026-04-02 22:00:48'),(242,'https://physsec.org/get-involved/','Physical Security Village [Call For Volunteers]()','2026-04-03 00:22:25'),(243,'https://docs.google.com/forms/d/e/1FAIpQLSfF7ROnnNVi33gZxZpgcqSrhWfo_14Ja4nVGvt9KkNFef45Pw/viewform','Radio Frequency Village [Call For Papers]()','2026-04-03 02:07:48'),(244,'https://www.telecomvillage.com/sponsors','Telecom Village [Call For Sponsors]()','2026-04-03 22:10:48'),(245,'https://bsky.app/profile/bradanlane.bsky.social/post/3mio6tudczc2y','2026 [eChallengeCoin]()','2026-04-04 11:24:41'),(246,'https://x.com/BlackInCyberCo1/status/2040401708413530569?s=20','[Calling on volunteers]() to help power BIC Village 2026!','2026-04-04 13:38:33'),(247,'https://x.com/BlackInCyberCo1/status/2040053000786292990?s=20','BIC Village [Call for Papers]() is OPEN!','2026-04-04 13:40:49'),(248,'https://x.com/BugBountyDEFCON/status/2038509072815644998','[CFP for Bug Bounty Village]() @ DEF CON 34 is now OPEN!','2026-04-04 13:47:10'),(249,'https://x.com/defcon_music/status/2038403175926145173?s=20','DEF CON 34 [Call for Music / Soundtrack]() is still OPEN','2026-04-04 13:56:10'),(250,'https://defcon.social/@defcon/116331117737672234','DEF CON [Training Las Vegas 2026]() Course Lineup is now live! ','2026-04-04 14:16:21'),(251,'https://defcon.social/@defcon/116325914003684721','DC in the news - [meet the BenevolentBureauofBirds]() edition','2026-04-04 15:02:13'),(252,'https://defcon.social/@DianaInitiative/116323680811463431','The Diana Initiative [CFP is open]()','2026-04-04 15:08:02'),(253,'https://www.paymentvillage.org/get-involved/sponsor','Payment Village [Call For Sponsors]()','2026-04-04 23:26:55'),(254,'https://www.paymentvillage.org/get-involved/CFP','Payment Village [Call For Papers]()','2026-04-04 23:26:55'),(255,'https://www.paymentvillage.org/get-involved/volunteer','Payment Village [Call For Volunteers]()','2026-04-04 23:26:55'),(256,'https://defcon.social/@DianaInitiative/116340667236587484','Online Event - [The Diana Initiative]() tickets available now','2026-04-05 03:06:30'),(257,'https://docs.google.com/forms/d/e/1FAIpQLSfTXyArz3zV9cc0LZquTTzcRFjx9k5dGCPq_8b-49b7kiYFoQ/viewform','Cloud Village [Call For Sponsors]()','2026-04-06 00:39:56'),(258,'https://docs.google.com/forms/d/e/1FAIpQLSf_0KXHMPvTv9d5JSt4anE1OV6PY7I3VoTEOTFC6WJSix49-w/viewform','Cloud Village [Call For Volunteers]()','2026-04-06 00:39:56'),(259,'https://docs.google.com/forms/d/e/1FAIpQLSeIW8zz7kbZ_UWuZLCK1xfsP9uAsyjn1r6W4PGuuoKXPLTmwA/viewform','Cloud Village [Call For Labs]()','2026-04-06 00:39:56'),(260,'https://docs.google.com/forms/d/e/1FAIpQLSfk31a2h-RjDC9XcV9JLu4ZiGUxpIa5igT1FgI_ExfVhJWKTQ/viewform','Cloud Village [Call For Papers]()','2026-04-06 00:39:56'),(261,'https://defcon.social/@defcon/116361274966329729','You can now find the full list of [DEF CON SINGAPORE]()speakers online','2026-04-07 01:31:09'),(262,'https://reconvillage.org/cfp','Recon Village [Call For Papers]()','2026-04-09 00:04:38'),(263,'https://x.com/rfhackers/status/2041749396572819903?s=20','Radio Frequency Village [Call For Sponsors]()','2026-04-09 01:09:42'),(264,'https://adversaryvillage.org/call-for-papers/','Adversary Village [Call For Papers]()','2026-04-12 00:49:20'),(265,'https://x.com/BlackInCyberCo1/status/2042226136671740021?s=20','Blacks in Cyber [Call For Fundraising]()','2026-04-12 01:15:22'),(266,'https://defcon.social/@Jayson/116381817608864932','Adversaries don\'t schedule appointments. [Register for Blackhat or DEF CON]()','2026-04-12 01:29:19'),(267,'https://www.bugbountydefcon.com/call-for-sponsors','Bug Bounty Village [Call For Sponsors]()','2026-04-12 23:01:04'),(268,'https://www.bugbountydefcon.com/call-for-events','Bug Bounty Village [Call For Events]()','2026-04-12 23:01:04'),(269,'https://defcon.social/@nixvegas/116393680217249385','Nix Vegas is [looking for sponsors]() for DEF CON 34','2026-04-13 01:05:25'),(270,'https://defcon.social/@goldbug/116265227112211601','Crypto Village [Call For Artists]()','2026-04-13 02:01:17'),(271,'https://mastodon.social/@biohacking_village/116394954424838793','Bio Hacking Village [Call for Papers/Workshops]()','2026-04-13 22:16:29'),(272,'https://x.com/AppSec_Village/status/2043706089116443037?s=20','AppSec Village [Call For Proposals]()','2026-04-13 23:03:35'),(273,'https://x.com/IoTvillage/status/2043668761085944037?s=20','IoT Village [Call For Papers]()','2026-04-13 23:20:11'),(274,'https://bsky.app/profile/defcon.bsky.social/post/3mjkymkt7uc2z','DEF CON [Call for Workshops]() is still open!','2026-04-15 23:00:14'),(275,'https://x.com/BSidesLV/status/2044122387990348034?s=20','[Everything is open]() for BSidesLV, talks/hotel/registration etc.','2026-04-15 23:15:12'),(276,'https://defcon.social/@Hac3krrunway/116421785738818222','contest to beheld at #defcon34 [hack3r Runw@y]()','2026-04-18 02:59:35'),(277,'https://defcon.social/@circuitswan/116422645980247373','[HackerSummerCampGuide]() for 2026, what should I add?','2026-04-18 03:04:28'),(278,'https://defcon.social/@secureaerospace@bird.makeup/116428735759342673','Aerospace Village [Call Fors extended]()','2026-04-20 01:36:54'),(279,'https://bsky.app/profile/defconpolicy.bsky.social/post/3mjptfjnpxk2d','Its not too late to submit your [talk, panel, or session]() to Policy DEF CON 34\n','2026-04-20 02:19:35'),(280,'https://sessionize.com/malware-village-defcon34','Malware Village [Call For Papers]()','2026-04-20 02:41:28'),(281,'https://infosec.exchange/@magen/116444731540357202','Reminder to everyone, the @defcon [Call for Workshops]() closes on May 1, next Friday','2026-04-22 00:04:44'),(282,'https://x.com/BSidesLV/status/2039493015161512273?s=20','BSidesLV [Call For Papers]() is now open','2026-04-22 01:08:20'),(284,'https://x.com/physsec/status/2046979545299861893?s=20','Physical Security Village [Call for Papers, Exhibits & Volunteers]()','2026-04-24 00:41:07'),(285,'https://docs.google.com/forms/d/e/1FAIpQLScXZzSmISdk54oS3YDki_X42WAVM6VztMKaWwsUxyxmBPe-4g/viewform','Physical Security Village [Call For Volunteers]()','2026-04-24 00:53:47'),(286,'https://x.com/physsec/status/2046981389812105478?s=20','Physical Security Village [Call For Exhibits]()','2026-04-24 00:58:34'),(287,'https://x.com/physsec/status/2046981145770721758?s=20','Physical Security Village [Call For Papers]()','2026-04-24 00:58:34'),(288,'https://x.com/physsec/status/2046980859060768768?s=20','Physical Security Village [Call For Sponsors]()','2026-04-24 01:17:12'),(289,'https://x.com/BlackInCyberCo1/status/2046937118304358846?s=20','Blacks in Cybersecurity [Call For Sponsors]()','2026-04-24 01:22:23'),(290,'https://infosec.exchange/@magen/116444731540357202','Quick reminder! the @defcon [Call for Workshops]() closes on May 1 (next Friday)! ','2026-04-24 01:51:40'),(291,'https://bsky.app/profile/aerospacevillage.bsky.social/post/3mkavpqta6h2k','Aerospace Village - 1 WEEK TO GO - 1 May final deadline for [CFP and CFW!!]()','2026-04-24 23:36:50'),(292,'https://bsky.app/profile/tindie.com/post/3mkbo2qlenb2g','Back in Stock! [SAO Totem]() version 1.69bis by BadgePirates','2026-04-25 00:02:02'),(293,'https://x.com/BlackInCyberCo1/status/2047661862578159757?s=20','Blacks in Cybersecurity Village [Call For Volunteers]() CLOSED','2026-04-25 00:12:20'),(294,'https://www.bugbountydefcon.com/call-for-papers','Bug Bounty Village [CFP extended]() to May 31st','2026-05-17 14:30:18'),(295,'https://cryptovillage.org/cfp/','Crypto Privacy Village [Call For Papers]()','2026-05-17 14:54:47'),(296,'https://bsky.app/profile/octopusgame.bsky.social/post/3mltmmzd2ns2u','Octopus Game [Call For Sponsors]()','2026-05-19 07:27:54'),(297,'https://defcon.social/@DDV_KnightOwl/116485704211737505','Data Duplication [Call For Presentations]()','2026-05-19 07:50:02'),(298,'https://dcshoot.org/','THE [UNOFFICIAL DEF CON SHOOT]() IS BACK, BABY!','2026-06-08 22:18:30'),(299,'https://docs.google.com/forms/d/e/1FAIpQLScZtqa69lZOjh2GzG6OPjrSbtDg47vDGEjTb8zg_UTpx1JCLg/viewform','DC Groups [Sticker Contest]()','2026-06-08 23:24:57'),(301,'https://bsky.app/profile/aerospacevillage.bsky.social/post/3mn5pkx3rtg2y','Looking for [Aerospace Village]() memories!','2026-06-14 19:34:37'),(302,'https://bsky.app/profile/bradanlane.bsky.social/post/3mobcett3s22g','2026 [eChallenge Coin]()','2026-06-14 21:19:33'),(303,'https://bsky.app/profile/defcon.bsky.social/post/3mnsqi2eybs2s','[DC34 Music Acts]() are Selected!','2026-06-14 21:57:28'),(304,'https://x.com/AISecurityForum/status/2065035695387709746?s=20','The [AI Security Forum]() is back in Las Vegas!','2026-06-14 22:55:56'),(305,'https://forum.defcon.org/node/255767#post255787','[Short Story]() contest','2026-06-15 01:12:11'),(306,'https://docs.google.com/forms/d/e/1FAIpQLSfVaUxNc7BBXxqGSpY1EKEjaUARb3lU5T-Mwrzokm5c8Ji7Yg/viewform','[#badgelife]() spreadsheet submission form','2026-06-15 01:14:17'),(307,'https://bsky.app/profile/defcon.bsky.social/post/3moeico5ca22s','What\'s it like being a [DC Goon at SG1]()','2026-06-15 22:47:49'),(308,'https://x.com/wiglenet/status/2064818874307227821?s=20','RF Village [World Wide War Drive]()','2026-06-15 23:38:46'),(309,'https://defcon.social/@DianaInitiative/116731505642082344','TDI is looking for [DEF CON mentors]()','2026-06-16 01:08:10'),(310,'https://infosec.exchange/@greynoise/116727206135144863','[Noise Fest]() is back!','2026-06-16 01:13:44'),(311,'https://defcon.social/@DianaInitiative/116703237312154415','Volunteers for [Resume Reviews]() at TDI','2026-06-16 01:24:25'),(312,'https://bsky.app/profile/dianainitiative.bsky.social/post/3mogtzqulwc2f','TDI and Mental Health Hackers present [The Quiet Room]()','2026-06-17 01:07:12'),(313,'https://docs.google.com/spreadsheets/d/1wQ6J0tJiVCPgppxiPg_mM6mS6Il-jm3Ez1fj3a-7XRs/|https://forms.gle/hZwg26ZNubYLWY2t9','[#badgelife]() spreadsheet of unofficial badges for DC34 \r\nsubmit a [new badge]()','2026-06-20 07:19:03'),(314,'https://defcon.social/@DianaInitiative/116782372244358013','[TDI Meetup]() on Fri','2026-06-21 02:44:15'),(317,'https://defcon.org/html/defcon-34/dc-34-venue.html#roomblock','3 more [Hotel Room Blocks]() just opened up!','2026-06-25 01:02:59'),(318,'https://x.com/cloudvillage_dc/status/2072742101599858758?s=20','Cloud Village [Labs Schedule]() is live!','2026-07-10 07:13:25'),(319,'https://x.com/cloudvillage_dc/status/2072002230392373635?s=20','Cloud Village [Talk Schedule]() is Live!','2026-07-10 07:16:04'),(320,'https://x.com/HamRadioVillage/status/2070613076680798237?s=20','Come take our FREE [\"Ham in a Day\" class]() at DC34','2026-07-10 07:19:28'),(321,'https://x.com/defcon_music/status/2073522818026009024?s=20','It\'s the schedule for the [DC34 music lineup!]()','2026-07-10 07:27:29'),(322,'https://defcon.org/#workshopslive','Workshops [Page is Live!]() Reg Opening Soon!','2026-07-12 05:22:34'),(323,'https://bsky.app/profile/defconpolicy.bsky.social/post/3mqhrqudiv22b','@Policy [schedule](https://bsky.app/profile/defconpolicy.bsky.social/post/3mqhrqudiv22b) released','2026-07-13 03:37:06'),(324,'https://x.com/RedTeamVillage_/status/2075671580479250582','The [Red Team Village Party]() is back! 🎉','2026-07-13 03:47:41'),(325,'https://defcon.social/@defcon/116898809774134932','DC Workshops [registration opens]() at Noon on July 14th','2026-07-13 04:04:22'),(326,'https://defcon.social/@defcon/116886146912925881','One Month to [DEF CON Training]()','2026-07-13 04:11:44'); /*!40000 ALTER TABLE `DCannouncements` ENABLE KEYS */; UNLOCK TABLES; -- -- Table structure for table `articles` -- DROP TABLE IF EXISTS `articles`; /*!40101 SET @saved_cs_client = @@character_set_client */; /*!50503 SET character_set_client = utf8mb4 */; CREATE TABLE `articles` ( `title` varchar(60) NOT NULL, `content` mediumtext CHARACTER SET utf8mb4 COLLATE utf8mb4_0900_ai_ci NOT NULL, `sortorder` tinyint NOT NULL, `id` int NOT NULL AUTO_INCREMENT, `hash` varchar(32) CHARACTER SET utf8mb4 COLLATE utf8mb4_0900_ai_ci NOT NULL, PRIMARY KEY (`id`) ) ENGINE=InnoDB AUTO_INCREMENT=1080 DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_0900_ai_ci; /*!40101 SET character_set_client = @saved_cs_client */; -- -- Dumping data for table `articles` -- LOCK TABLES `articles` WRITE; /*!40000 ALTER TABLE `articles` DISABLE KEYS */; INSERT INTO `articles` VALUES ('\'Welcome to DEF CON 34!\'','\'\n\'',0,1076,'5bf3e2ca73a9c7cc2124cc76a8f417a8'),('\'Stream on Twitch\'','\'

Our Main Tracks are already full, first thing this morning! If you would like to watch the talks and are not already in the audience, feel free to watch our streams on Twitch, via DCTV. See dctv.defcon.org for more info!

\n\'',0,1077,'cd4357dbb2fede0214ea7dcbd75eb84b'),('\'Wi-Fi currently degraded\'','\'

The DEF CON NOC is aware that we are currently experiencing issues with both wired and wireless networking. NOC and appropriate vendors are actively working to resolve this condition. Thank you for your patience.

\n\'',0,1078,'58b3a94822ef9d1f3b7ecf61a47ab83a'),('\'Networking returning to service\'','\'

The DEF CON NOC would like for everyone to know that wired and wireless networking is gradually returning to service, and we hope that everyone will soon be able to use the network across the con. We will continue to monitor the situation, and a blog post about the outage will be made available in the future.

\n\'',0,1079,'d91544bf69ac497a85bda4bceb86c69d'); /*!40000 ALTER TABLE `articles` ENABLE KEYS */; UNLOCK TABLES; -- -- Table structure for table `documents` -- DROP TABLE IF EXISTS `documents`; /*!40101 SET @saved_cs_client = @@character_set_client */; /*!50503 SET character_set_client = utf8mb4 */; CREATE TABLE `documents` ( `title` varchar(60) NOT NULL, `content` mediumtext CHARACTER SET utf8mb4 COLLATE utf8mb4_0900_ai_ci NOT NULL, `sortorder` tinyint NOT NULL, `id` int NOT NULL AUTO_INCREMENT, `hash` varchar(32) NOT NULL, PRIMARY KEY (`id`) ) ENGINE=InnoDB AUTO_INCREMENT=3589 DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_0900_ai_ci; /*!40101 SET character_set_client = @saved_cs_client */; -- -- Dumping data for table `documents` -- LOCK TABLES `documents` WRITE; /*!40000 ALTER TABLE `documents` DISABLE KEYS */; INSERT INTO `documents` VALUES ('\'Code of Conduct\'','\'

DEF CON provides a forum for open discussion between participants, where radical viewpoints are welcome and a high degree of skepticism is expected. However, insulting or harassing other participants is unacceptable. We want DEF CON to be a safe and productive environment for everyone. It’s not about what you look like but what’s in your mind and how you present yourself that counts at DEF CON.

\n\n

We do not condone harassment against any participant, for any reason. Harassment includes deliberate intimidation and targeting individuals in a manner that makes them feel uncomfortable, unwelcome, or afraid.

\n\n

Participants asked to stop any harassing behavior are expected to comply immediately. We reserve the right to respond to harassment in the manner we deem appropriate, including but not limited to expulsion without refund and referral to the relevant authorities.

\n\n

This Code of Conduct applies to everyone participating at DEF CON - from attendees and exhibitors to speakers, press, volunteers, and Goons.

\n\n

Anyone can report harassment. If you are at DEF CON and are being harassed, notice that someone else is being harassed, or have any other concerns, you can let us know by contacting any Goon, registration desk, or info booth, as well as by calling or texting the hotline at 725-222-0934. As a reminder, you can also contact the hotline during the con if you just need someone supportive to talk to. You can also file a report year-round by contacting safety@defcon.org. We encourage individuals to report CoC violations as soon as they’re able to so we can begin our investigation before evidence is lost or destroyed, but it’s never too late to make a report.

\n\n

Conference staff will be happy to help participants contact hotel security, local law enforcement, or otherwise assist those experiencing harassment to feel safe for the duration of DEF CON.

\n\n

Remember: The CON is what you make of it, and as a community we can create a great experience for everyone.

\n\n
    \n
  • The Dark Tangent
  • \n
\n\n



dc-policy.html

\n\'',0,3578,'16b552ae6488376b26790dd873ae3a1f'),('\'Decoder Ring (Glossary)\'','\'

3-2-1 Rule - Rule for the minimum required daily activities during the span of the DEF CON conference: 3 hours of sleep, 2 meals, 1 shower. The 0 for \"zero stickers applied to venue\" is silent.

\n\n

6-3-2 - It\'s like 3-2-1, except more. Recommended by some hackers and nearly all conference organizers.

\n\n

A&E - Arts & Entertainment, the DEF CON department in charge of overseeing arts, music, and all other forms of entertainment.

\n\n

AEV - Aerospace Village

\n\n

AIV - A. I. Village

\n\n

AP - The Alexis Park hotel, where DEF CON was held in the early days.

\n\n

ASV - AppSec Village

\n\n

BH - See \"BlackHat\", below.

\n\n

BHV - Biohacking Village

\n\n

BICV - Blacks In Cybersecurity Village

\n\n

Black Badge - The Black Badge is the highest award DEF CON gives to contest winners of certain events. A Black Badge allows free entrance to DEF CON for life. There has never been a raffle to give away a black badge, and there never will be.

\n\n

BlackHat - BlackHat is a conference unrelated to DEF CON, that happens in Las Vegas shortly before DEF CON. The Dark Tangent founded both DEF CON and BlackHat.

\n\n

Blue Team - A blue team is a group of defenders who work to improve an organization\'s security by identifying security threats and risks, analyzing the network environment, and responding to incidents when they occur.

\n\n

BSides - Unrelated to DEF CON, SecurityBSides conferences are conferences or gatherings of individuals in a local area.

\n\n

BSidesLV - BSides Las Vegas is an unrelated conference that happens in Las Vegas shortly before DEF CON.

\n\n

BTV - Blue Team Village -- a community built for and by defenders

\n\n

C&E - The DEF CON department the oversees contests (and formerly events).

\n\n

Chatham House Rule - When a meeting, or part thereof, is held under the Chatham House Rule, participants are free to use the information received, but neither the identity nor the affiliation of the speaker(s), nor that of any other participant, may be revealed. Wikipedia

\n\n

CHV - Car Hacking Village

\n\n

COC - Code of Conduct. All activities happening within the DEF CON conference perimeter are required to strictly follow the DEF CON Code of Conduct. The Code of Conduct is available in Hacker Tracker, in the printed program, and
[dc-policy.html](https://www.defcon.org/html/links/dc-policy.html)\">here
.

\n\n

Con - Shortened form of the word \"conference\" or \"convention\". Many of the activities that take place refer to themselves as a con. For example, the meetup of the LGBTQIA+ community is referred to as \"Queercon\".

\n\n

Contest - In Hacker Tracker, the tag \"Contest\" is applied to contests that were pre-approved by DEF CON, and are also listed in the printed program. These vary in location, type, and format. Villages, communities, and etc., may also run contests that were not pre-approved by DEF CON, but those won\'t carry the \"Contest\" tag. Events carrying the \"Contest\" tag are eligible for consideration for a Black Badge award.

\n\n

CPV - Crypto & Privacy Village

\n\n

CTF - Capture The Flag, a subset of \"contest\". The DEF CON Capture the Flag (CTF), the largest open computer security hacking game, is a hacking competition where teams of hackers attempt to attack and defend computers. In addition to the official DEF CON CTF, there are many CTF events run by various organizations and villages. There may also be unofficial CTFs held by general attendees and others.

\n\n

DC34 - DEF CON 34. Broadly speaking, \"DC\" followed by a number refers to the number of the that year\'s conference. For example, year 2026 is DEF CON 34.

\n\n

DCG - DEF CON Groups. DEF CON Groups are worldwide, local chapters of hackers, thinkers, makers and others. DEF CON Groups are usually identified by the area code of the area where they are located in the US, and by other numbers when outside of the US e.g., DC614, DC201, etc.

\n\n

DCIB - DEF CON Information Booth. Now known as an NFO Node.

\n\n

DCTV - DEF CON TV. DEF CON broadcasts various conference speaking tracks and events on venue audio/visual networks. Access to these broadcasts varies by venue, but generally can be found on the hotel TV systems. DCTV also broadcasts to online streaming services, when possible.

\n\n

DDV - The DEF CON Data Duplication Village. This village is designed to help the information security community by providing replication of the large amount of data DEF CON has collected over the years.

\n\n

DEVOPS - The DEF CON department that oversees the DEF CON Discord instance and supporting infrastructure.

\n\n

DFIU - \"Don\'t fuck it up\"

\n\n

DISP - Dispatch, the DEF CON department that triages and escalates interdepartmental requests.

\n\n

DT - \"DT\", or \"The Dark Tangent\", refers to Jeff Moss, the founder of DEF CON.

\n\n

EFF - The Electronic Frontier Foundation, a nonprofit organization defending civil liberties in the digital world.

\n\n

EV or ESV - Embedded Village, formerly Embedded Systems Village. Not to be confused with Electric Vehicle.

\n\n

Exhibitor - Exhibitors are professional organizations looking to connect to the unique DEF CON audience; the hacker, the researcher, and the student. Exhibitors were considered vendors until DC31. The difference is largely that you walk out of Vendors carrying physical merchandise, but you walk out of Exhibitors with a dream.

\n\n

Fed - Employees of the Federal (US) government. Typically used in the context of the DEF CON \"Spot the Fed\" competition, an informal game at DEF CON where the object of the game is to identify who among the attendees is an employee of the federal government.

\n\n

Goon - DEF CON staff. They have many roles including safety, speaker coordination, vendor room coordination, network operations, etc.

\n\n

Hacker Tracker - A conference information and scheduling application for iOS and Android. HackerTracker is the official conference app of DEF CON. HackerTracker also powers info.defcon.org.

\n\n

Ham - \"Ham\" is a common term for amateur radio operator. See also HRV (Ham Radio Village).

\n\n

HDA - \"Hackers with Disabilities\" -- the DEF CON team that works to ensure that the DEF CON experience is the best it can be for the ADA/accessible community.

\n\n

HHV - Hardware Hacking Village, which also operates Soldering Skills Village

\n\n

HR - Human Registration

\n\n

HRV - Ham Radio Village

\n\n

Human - General attendees of the DEF CON conference.

\n\n

ICSV - Industrial Control Systems Village -- dedicated to securing ICS/SCADA systems.

\n\n

Inhuman - All DEF CON goers who are not \"human\". (Goons, village staff, speakers, contractors, etc.)

\n\n

IOTV - Internet of Things Village -- The IoT Village advocates for advancing security in the Internet of Things (IoT) industry by bringing researchers and industry together.

\n\n

LineCon - Originally referred to the line for [human] badges to enter the con. Has since grown to encompass any line at DEF CON: any long line has the potential to turn into a con.

\n\n

LPV - Lock Pick Village -- a dedicated space at DEF CON that\'s arranged around the topic of lock picking, lock bypass, and physical security topics.

\n\n

Merch - The DEF CON Merch department sells DEF CON branded apparel and other merchandise. (The most popular items tend to sell-out relatively quickly, and there\'s often a linecon for merch.)

\n\n

NFO - The DEF CON department that provides information, assistance, and navigational guidance to DEF CON hackers. May also refer to an old-school text file commonly associated with hacker culture. \"NFO\" is pronounced \"info\".

\n\n

NFO Node - Formerly known as an \"infobooth\", these are the locations where NFO goons can most often be found.

\n\n

Pac-Man Rule - Letting someone (typically unknown to you) join you or your group\'s conversation. Read more about it here.

\n\n

PAYV - Payment Village

\n\n

PHV - Packet Hacking Village

\n\n

PME -- The DEF CON department that oversees Parties, Meetups, and Events.

\n\n

POL - Policy@DEFCON Village

\n\n

PSV - Physical Security Village

\n\n

Purple Team - Purple teaming is a security methodology that brings together offensive security professionals (red teams) and defensive security professionals (blue teams) to enhance cyber capabilities through continuous feedback and knowledge transfer.

\n\n

QM - QuarterMaster, the DEF CON department that oversees supplies and physical logistics.

\n\n

QV - Quantum Village

\n\n

Red Team - A red team is a group of security professionals who act as hackers to test an organization\'s defenses.

\n\n

REG - Registration, the DEF CON department that oversees badge issuance.

\n\n

REV - Recon Village

\n\n

RFV - Radio Frequency Village

\n\n

RTV - Red Team Village

\n\n

Scav / scav hunt - The scavenger hunt -- a long-running event at DEF CON.

\n\n

SE - Social Engineering -- a tactic that uses psychological manipulation to trick people into making security mistakes or giving away sensitive information.

\n\n

SECV, SEV - Social Engineering Community Village is a village dedicated to the techniques and principles of Social Engineering.

\n\n

SOC - The SOC is the Department of Fun Enforcement. If you have a safety concern, please seek out a SOC Goon, or call the DEF CON Hotline.

\n\n

SPKR - The DEF CON department that ensures Speakers are prepared to be in the right place at the right time to give their talk.

\n\n

SSV - Soldering Skills Village, which is a function of Hardware Hacking Village

\n\n

SWAG - See Merch.

\n\n

TDI - The Diana Initiative, a community at DEF CON 34.

\n\n

TEV - Tamper Evident Village

\n\n

TLV - Telecom Village

\n\n

Uber Badge - See Black Badge

\n\n

Vendor - An organization selling physical merchandise at DEF CON. All vendors are in the same physical space, and a list of vendors is available in Hacker Tracker. See also Exhibitor.

\n\n

VILL - The DEF CON department that works to ensure Villages are as successful as possible.

\n\n

Village - Villages are autonomous organizations, often non-profit, that gather at DEF CON for a shared hacking experience. Each village has a focus on some distinct aspect of hacking or cybersecurity. Villages create and execute on their own programming, which often includes hands-on activities (like workshops, or physical construction/deconstruction), talks, panel discussions, group conversations, or parties.

\n\n

Vortex / the Vortex - When one is caught up in hallway conversations on the way from one DEF CON activity to another, it\'s referred to as being caught up in the Vortex.

\n\n

VV, VMV, VMHV - Voting Village

\n\n

WISP - Women in Security and Privacy

\n\n

XZBT - The DEF CON department that oversees Exhibitors.

\n\'',0,3579,'3bb6aaad880aac0fb10bb270ac4727d1'),('\'Help & Support\'','\'

Emergencies

\n\n

If you have a 🚑 🏥 Medical or 👮 Police Emergency: Call 911.

\n\n

General Information

\n\n

If you have questions about what\'s happening in or around DEF CON, or otherwise need help answering a question: please visit one of the NFO Nodes (formerly known as information booth) located throughout LVCC West. They\'re highlighted in teal (green-ish) on the venue maps.

\n\n

Urgent Help & Wellness

\n\n

Mental wellness and physical safety are both important to us at DEF CON. If you’re struggling, scared, or just need someone to voice a concern to, DEF CON Hotline is here to support you. Help is available to all, especially if talking to DEF CON Goons in person isn’t a good option for you.

\n\n

Hotline is confidential and available well into the early morning hours on conference days. Volunteers are standing by to listen and, if needed, connect you to appropriate support services. Whether that’s SOC Goons or external services we partner with such as Kick at Darkness, The Rape Crisis Center Las Vegas, and the Nevada Coalition to End Domestic and Sexual Violence to provide expert resources for survivors. The Hotline team is diverse and undergoes extensive training including dedicated support for LGBTQ+. Hotline is here to listen.

\n\n

You can reach DEF CON Hotline Goons during normal hours of operation to anonymously report any behavior violating our code of conduct or to find an empathic ear by phone call, text, or Signal at +1 (725) 222-0934, or reaching out on Discord @defconhotline.

\n\n

Need First Aid?

\n\n

If you are in need of First Aid, there is a nurse on-duty in room W1056-MA. It\'s under the escalators near human registration. If you cannot find it, ask a goon for help. SOC goons in particular are able to quickly summon medical help.

\n\n

Need a Nursing Room?

\n\n

Here are the concise walking instructions:

\n\n
    \n
  1. On the first floor of LVCC West Hall, head toward the North Lobby near Hall 4.
  2. \n
  3. Before reaching the Hall 4 sign, look for a sign on the left wall of the corridor for the W1016-VA Vending Area.
  4. \n
  5. Turn right into the vending area near the ATM.
  6. \n
  7. Turn right again at the \"Goon Only Beyond This Point\" sign.
  8. \n
  9. Find the W1016-NR Nursing Room on the right side of the hallway.
  10. \n
  11. Use your phone to call 702-892-7400 to have an LVCC staff member open the room.
  12. \n
\n\'',0,3580,'e7fbee2c9c3ca587f80a4da87916cab5'),('\'Lost & Found\'','\'

If you find something that seems to have been lost, please take that item to the nearest NFO Node. The item will enter the DEF CON Lost & Found system.

\n\n

If you\'ve lost something, the only way to check on it (or reclaim it) is by going to the Lost & Found department yourself. The Lost & Found department is in room LVCC - L2 - W234. You may also call +1 (720) 645-4527.

\n\n

The Lost & Found department plans to be open Thursday - Saturday, during all hours that the conference operates. On Sunday, the Lost & Found department will open with the venue at 08:00, but will close at the beginning of DEF CON 34 Closing Ceremonies (15:00). Shortly thereafter, all remaining lost items will be transferred to the LVCC. If you need to reach LVCC\'s Lost & Found, you may call LVCC Dispatch at +1 (702) 892-7400.

\n\'',0,3581,'1c1ecba6ad0b80ad52f0a2c15c785259'),('\'Wi-Fi Instructions\'','\'

Wi-Fi Instructions

\n\n

What should you do in order to connect to Wi-Fi?

\n\n

If you are a returning guest just do the same thing you did last year but with more confidence... if this is your first time as the person sitting next to you... great way to start a conversation :)... if you aren’t much of a talker, then follow the steps at https://wifireg.defcon.org.

\n\n

The encrypted one with 802.1X authentication and digital certificate verification: DefCon

\n\n

The (other, yet legit) encrypted one with 802.1X authentication and digital certificate verification. But also, with some shiny WPA3 benefits: DefCon-WPA3

\n\n

And the original, unencrypted, stick-shift, no ABS, wildest-westest of the wireless networks: DefCon-Open

\n\n

So to recap

\n\n
    \n
  • Defcon - (get a user/password and cert from https://wifireg.defcon.org)
  • \n
  • Defcon-WPA3 - same as above
  • \n
  • Defcon Open – I wouldn’t but I hear the cool kids are there.
  • \n
\n\n

“Choice. The problem is choice” Wi-Fi and 802.1X authentication have had a pretty good relationship in the past few years. And, believe or not, we test stuff before we go onsite... seriously we work on this all year. But things might change and there might be some devices out there that really do not like 802.1X with PEAP authentication.

\n\n

Important 802.1X fact: By configuring 802.1X and choosing for your device to “not verify server certificate” will probably not only let that device connect to one of the hundreds of rogue access points on the show floor but will also send your login credentials to a rogue radius server. Despite technology advancements, this is still no bueno and defeats the whole purpose of this authentication method.

\n\n

Be an advocate of cyber common sense™, and do not, I repeat, do NOT choose the same credentials (aka: username and password) used for stuff that matters: shopping sites, online-banking, AND, especially your windows domains (yeah, it keeps happening) to connect to the hacker conference network. Make something up, be creative and funny, cause we will post the best ones!

\n\n

For updated information and instructions on how to connect to the Wi-Fi along with the link to download the digital certificate to be used, visit: https://wifireg.defcon.org

\n\n

For NOC updates visit https://noc.defcon.org. Above all else have fun, and be rad to each other!

\n\'',0,3582,'dd7953b24c43fbd2183411ff7d1b19d1'),('\'Meshtastic Info\'','\'

Meshtastic at DEF CON 34

\n\n

Stay connected off-grid using the DEF CON Meshtastic mesh network.

\n\n

Flash Event Firmware

\n\n

Use the official DEF CON event firmware for the best experience and optimized network performance.

\n\n

DEF CON Meshtastic Web Flasher: https://defcon.meshtastic.org

\n\n

Network Settings

\n\n

Region: US\nLoRa Preset: Short Turbo\nPrimary Channel: 31

\n\n

Recommended Channels

\n\n
    \n
  • DEFCONnect: OEu8wB3AItGBvza4YSHh+5a3LlW/dCJ+nWr7SNZMsaE=
  • \n
  • HackerComms: 6IzsaoVhx1ETWeWuu0dUWMLqItvYJLbRzwgTAKCfvtY=
  • \n
  • NodeChat: TiIdi8MJG+IRnIkS8iUZXRU+MHuGtuzEasOWXp4QndU=
  • \n
\n\n

If you wish to copy/paste this information, you\'re welcome to open this document in a browser for easier copying: https://info.defcon.org/defcon34/documents/664

\n\'',0,3583,'a2bccd41d253bd4e56c30819b0529f49'),('\'Photography Policy\'','\'

Photos & Recording

\n\n

Public photography is *allowed.

\n\n

Official Press & DEF CON Policy Village rules may differ, please refer to them. At DEF CON you may see our official photography goons capturing the uniqueness that is to be expected at DEF CON, they adhere to our photo policy.

\n\n
    \n
  • Groups & individuals participating in public on stage (events, contests, or activities) are *allowed to be photographed.
  • \n
  • Photography in the CTF room is NOT permitted without consent of the individuals to be photographed.
  • \n
  • \"Crowd shots\" are VERY discouraged, if so desired you must alert the crowd to give them time to opt out. For example: \"Hey, I\'m taking a photo, if you don\'t want to be in it hide your face\".
  • \n
  • Taking photos of people in hallways, lines, hanging out, at random, is not allowed without consent. Respect the rights of the individual not to be photographed. Deletion of photos can be requested by staff.
  • \n
  • When taking pictures of your friends please use \"portrait mode\" because this will blur the picture background, respecting the privacy of those in inadvertently captured.
  • \n
  • Smart glasses and other devices that can record audio or video with no consistent way to understand if they\'re recording or not, are prohibited at DEF CON, they erode trust and invade people\'s privacy.
  • \n
\n\n

NOTE: It is permissible to record violations of the DEF CON CoC to share with our safety team to help us investigate and take action.

\n\n

*We reserve the right to revoke an individual\'s permission to photograph, at any time, on a case by case basis. Failure to comply can result in revocation of admission without refund.

\n\'',0,3584,'8016532e1c940e97fb9e03b56a21a439'),('\'Intro to DEF CON\'','\'

Intro to DEF CON

\n\n

Built for DEF CON 34, revision 202607301.

\n\n\n\n

Dates and Times

\n\n

Badge pickup begins on August 6, 2026, and content begins on August 7, 2026 at 10:00. Content ends on Sunday, August 9, 2026, at around 16:00-ish. All times here are Pacific (US/Los_Angeles, which is the timezone that Las Vegas is in). Check Hacker Tracker or info.defcon.org a day or two before badge pickup, to see what time badge pickup will begin on August 6, 2026.

\n\n

The operating hours for most creators (villages, communities, contests) are: Friday and Saturday, 10:00-18:00; Sunday 10:00-14:00.

\n\n

The operating hours for all activities are: Friday 10:00 – Saturday 01:00; Saturday 10:00 – Sunday 01:00; Sunday 10:00 – 16:00-ish (entry closes at 15:50).

\n\n

Venue

\n\n

DEF CON 34 will be held in Las Vegas, NV, at the Las Vegas Convention Center’s (LVCC) West Hall. View on Google Maps. All DEF CON 34 content will be housed at the West Hall; some parties may be elsewhere.

\n\n

A coat and bag check are available, for a fee, at the FedEx Office inside the West Hall (near the food court).

\n\n

While there are ATMs located in the West Hall, they are expected to quickly and repeatedly be taken out-of-service due to being fully depleted of cash. We strongly recommend that if you intend to use cash at DEF CON, that you bring cash with you before you arrive at the West Hall. ATMs that are located inside casinos are generally more trustworthy (due to tighter security/monitoring) than ATMs located in public. ATMs at the airport generally charge higher fees than ATMs in casinos.

\n\n

Food

\n\n

The LVCC West Hall has a food court that will be open for DEF CON attendees. Note that the food court **does not accept cash** -- they are card-only.

\n\n

The LVCC has a policy prohibiting bringing off-site food into the facility. This means you cannot bring pizza, burgers, etc., in from outside for a gathering with friends. However, the LVCC generally does not enforce this for individuals bringing food only for themselves to eat. The following is a direct quote from the Food & Beverage Senior Catering Sales Manager with Sodexo Live!:

\n\n

“Although we are the exclusive food and beverage provider here at the LVCC, we understand that some guests may be sensitive to certain foods or have mild to severe food allergies. In this case, we do allow the guest to provide their own personal meals daily while attending or working events here at the LVCC.”

\n\n

Hotels

\n\n

DEF CON negotiates room block pricing with a number of hotels in the vicinity. Please check the DEF CON 34 website for discount/block code links. Please be aware of your hotel’s policies before booking: hotels have different pricing structures, resort fees, and Wi-Fi device limits.

\n\n

Travel and Transportation

\n\n

DEF CON does not offer any transportation service to human attendees. If you are contacted by someone who claims to have a “DEF CON Special Rate” or claims to be offering a service for DEF CON, be suspicious. If contact was made via some electronic means: they didn’t get your contact information from us – we never share or sell contact information.

\n\n

Air

\n\n

Harry Reid International Airport (LAS) is the closest airport to our location. There are various options for transportation to and from Harry Reid International Airport including taxis, limos, ride share and shuttle services.

\n\n

Rideshare

\n\n

Taxis, Uber, and Lyft are all available and generally work well, but expect surge pricing during peak arrival and departure windows.

\n\n

Parking

\n\n

The LVCC operates the \"West Hall Diamond Lot\" nearest to the entrance of the West Hall. This is surface-level parking. Parking is not free, and is not validated – be aware of fees before you park. You may be asked to show your DEF CON badge in order to park. Regardless of when you park, parking is not permitted overnight. Pay close attention to posted parking signs. Wherever you choose to park, DEF CON is not responsible if you are towed.

\n\n

Accessible Parking

\n\n

Bring along your hometown dashboard parking permit from your personal vehicle if you plan to rent a vehicle in Las Vegas. Out-of-state permits are recognized. Temporary disabled parking permits are available through the Nevada Department of Motor Vehicles. Contact them in advance for an application at DMV Special Plates, 775-684-4750, in Carson City, or visit https://dmv.nv.gov/. A physician\'s statement will be required. Alternatively, valet parking is available at most hotels. Please also read the above “Parking” section.

\n\n

Monorail

\n\n

The Las Vegas Monorail runs along The Strip, with two stops that are vaguely-convenient for LVCC West Hall access. It’s an acceptable option if you’re staying at a strip-adjacent property and want to avoid traffic or rideshare surge pricing. There is a walk (of perhaps 10 minutes on average) from Boingo Station to the West Hall’s main (southern) entrance. If you choose to use Westgate station, there is a similar length walk to the West Hall’s north entrance. You can find pricing, hours of operation, and more information on their website.

\n\n

The Vegas Loop

\n\n

This is The Boring Company\'s underground Tesla tunnel system -- not an actual hyperloop. It currently connects LVCC to Westgate, Encore, Resorts World, and Fontainebleau; rides within the LVCC campus are free for convention attendees. Airport service has started but is surface transport and is very limited; we recommend not planning your airport travel around this service. Find more information on their website.

\n\n

Within the LVCC campus, the system consists of two one-way, .8-mile-long tunnels built to accommodate all-electric Tesla vehicles driving at speeds of up to 35 mph. The LVCC Loop reduces a 25-minute walk to a less than two-minute ride.

\n\n

Attendees can access the LVCC Loop via three stations:

\n\n
    \n
  • West Station – Adjacent to West Hall, this station is located aboveground
  • \n
  • Central Station – Near the Central Hall Main Entrance, this station is located below ground and is accessible via escalator or elevator
  • \n
  • South Station – Adjacent to South Hall, this station is located above ground.
  • \n
\n\n

Please note the loop is *not* very friendly for those using most accessibility/mobility aides; there is very little room to store a wheelchair. We have no control over this.

\n\n

The loop’s extended running times, if offered, will be posted at the doors to the LVCC.

\n\n

Visas and Letters of Invitation

\n\n

If you need a letter of invitation for your visa application: in most cases, DEF CON can send a signed letter of invitation -- usually within a few short business days -- once we have all the info. If you also require verification of housing, we can put you in touch with someone to help you get your hotel stay organized; let us know if you need that.

\n\n

To request an invitation letter, fill out this form. Once approved, your invitation letter will be emailed to you.

\n\n

Ticketing and Badges

\n\n

At DEF CON, a badge (of the appropriate type) serves as your ticket to enter the convention space.

\n\n

Classifications of Badges

\n\n

There are a number of classifications of badges; their design and color theme varies by year. General admission/attendees need a “Human” badge. Others include Speaker, Press, Goon, Artist, CFP Review Board Member, Contest, Village, Community, Exhibitor, Vendor, and CTF Player (for those who pre-qualified to play the official DEF CON CTF of the year).

\n\n

Types of Badges (Digital vs Analog; Preferred vs Paper)

\n\n

You may have heard that DEF CON’s badges are electronic PCBs, capable of doing things or playing games – this is sometimes correct. DEF CON generally alternates annually (every other year) between having an electronic (or “Digital”) badge and having a non-electronic (or “Analog”) badge. There is always some designed art or functionality to a badge, regardless of if it is digital or analog. There are often challenges built into badges, particularly electronic ones, and those challenges often reward you for interacting with other badges or classifications of badges. DEF CON 34 is a “Digital” badge year.

\n\n

While DEF CON strives to have enough badges of each classification on-hand before on-site registration opens, situations have arisen in the past such that there were not. In those cases, DEF CON provides a “paper” badge (not strictly paper; generally some kind of laminate) to individuals who register after the preferred supplies are exhausted. If the supply exhaustion problem is resolved during the convention, it is plausible that DEF CON may offer 1:1 exchanges, such that those issued a “paper” badge could surrender that in favor of receiving a “preferred” badge.

\n\n

Human Badges

\n\n

A human badge is your ticket to nearly all DEF CON content – exceptions are made clear on the schedule (for example, Workshops need an additional free preregistration, and Training is a separately paid enrollment). Your badge entitles you to admission to all talks (main stages and creator stages), creator content (contests, villages, communities), chillout spaces, and authorized parties – all of these subject to venue capacity and other logistical restrictions. Practically speaking, only the very-popular events will fill up fast; not everyone who wants to attend those events will be able to.

\n\n

DEF CON does not verify, validate, or otherwise prove attendance at any event. Our perspective is that if you are in possession of a valid badge, then you were in attendance or could have been in attendance.

\n\n

There are two ways to purchase a human badge: online preorder, or cash at the door.

\n\n

Online Preordering

\n\n

Online preordering has become a popular option in recent years. If you preorder, there is a higher probability that you will get the “preferred” badge rather than a “paper” badge. Online pricing increases over time, so the earlier you buy, the better. If you buy online, a receipt will be emailed to you shortly after you check-out.

\n\n

If you preorder but later need a refund because you are unable to attend, please email orderfulfillment@defcon.org and you will be refunded in accordance with the cancelation policy made available when you completed the purchase.

\n\n

It is also possible for you to resell the ticket, if you find a buyer willing to buy from you. **The person who first presents the QR code to human registration is the person who will be issued the badge**, so there is risk in purchasing a resold QR code.

\n\n

If your preorder was placed by someone at your company, not in your name, that’s not a problem – badges are not customized by attendee, and DEF CON doesn’t care what the name on the order is. You just have to present the QR code (and should know the name and email on the order, just in case).

\n\n

Cash

\n\n

Some humans prefer to buy their badge with cash. This was the only means of buying a human badge until DEF CON 29, and is still popular. While DEF CON does try to have an ample supply of “preferred” human badges on-hand for cash sales, online preorders are prioritized over cash sales when supplies become limited. If you buy in cash and need a receipt: no receipts are issued on-site, but a receipt template PDF is made available online, shortly after human registration opens. You’re welcome to create your own receipt. (For those wondering, this is generally required by employers who reimburse their staff for attending DEF CON.)

\n\n

Admission of Children and Age Restrictions

\n\n

Those *under the age of 9* – that is, age 8 and younger – are granted free admission, and must be accompanied by an adult parent or guardian that has their own badge. Please note that while DEF CON is largely a family-friendly convention (refer to the DEF CON Code of Conduct), elements of an “adult atmosphere” (alcohol and profanity) are present and common, so it is the sole responsibility of the parent or guardian to use their own discretion when deciding what their children should attend.

\n\n

DEF CON will cooperate with parents, police, and private investigators related to children who have “run away from home to attend DEF CON”.

\n\n

You must be at least 21 years of age in order to reserve a room at most hotels in and around Las Vegas.

\n\n

Press Badges

\n\n

Are you a member of the press, or otherwise believe that you would be better suited to have a press badge rather than human badge? Please contact press@defcon.org and apply for a press badge before the con. You don’t want to get caught recording on-site or breaking press rules.

\n\n

DEF CON is a hacker convention, not a professional infosec conference -- not everyone wants their identity or attendance known, and we expect you to respect their privacy. Please obtain explicit consent when conducting interviews or taking photos.

\n\n

Video production camera crews are *not permitted*, but you may take video with your smartphone or small camera so long as you have consent of every individual in your footage. This means wide angle shots of individuals walking through the hallways are off limits, unless you get everyone’s consent. You may not record video of talks or trainings.

\n\n

All media/press inquiries should be directed to the DEF CON Press Department (email press@defcon.org or visit the on-site press office).

\n\n

Black Badges (aka Uber Badges)

\n\n

A Black Badge is one of the highest honors that DEF CON can bestow on a person or team in recognition of their overall elite skills or outstanding contribution to the security community.

\n\n

A Black Badge is given by DEF CON to an individual in certain circumstances, and it entitles that individual, on presenting his or her badge, to free admission to the DEF CON convention. In order to protect individuals who hold a Black Badge, the privileges associated with a Black Badge are non-transferrable.

\n\n

Gold Badges

\n\n

The coveted Gold Badge is the ultimate recognition of dedication and community commitment within DEF CON. It is an incredibly prestigious award bestowed upon volunteers who have given ten or more years of service as a goon - most notably provided upon their \"retirement\" from active involvement in the con\'s operations. This badge celebrates a monumental life-long contribution to the culture, granting its recipients lifetime entry and solidifying their status as integral pillars of the DEF CON community.

\n\n

Goon (Red) Badges

\n\n

Goon (red) badges are worn by individuals who are working for DEF CON in some capacity. You can learn more about Goons in the section “About DEF CON -> Goons”, later in this document.

\n\n

Badgelife

\n\n

“Badgelife” is not a badge, and does not necessarily refer to DEF CON badges; it’s the hobby of collecting badges. (Please note that buying badges other than a DEF CON Human badge does not grant you any additional admission/entitlement with regard to DEF CON activities.) There are a lot of independent badges out there. Some might exist solely for their design/art or functionality; others may convey some other benefit (like admission to a private party, or contribution to a non-profit, etc). DEF CON does not recommend or encourage any specific badge purchases other than our own Human badge (required for admission).

\n\n

Badgelife Village now exists to further explore this space.

\n\n

Content, Schedule, Activities

\n\n

Hacker Tracker and info.defcon.org

\n\n

DEF CON produces a comprehensive con schedule, including content produced not only by DEF CON, but also each of the creators that have space inside DEF CON.

\n\n

Hacker Tracker is the official content and schedule app of DEF CON. The apps and infrastructure are independently maintained by a group of DEF CON goons, and the apps are also used by many other conventions, including many BSides conferences.

\n\n

Hacker Tracker also powers the comprehensive content and schedule *website* of DEF CON – info.defcon.org. The most important features are available on the website, but some features – like making a wish list of merch you want to buy – are available only in the smartphone apps.

\n\n

You can visit the website or download the apps by going to info.defcon.org/apps.

\n\n

Tags and Types of Content

\n\n

In Hacker Tracker or on info.defcon.org, you’re able to filter by one (or potentially more) tags. The type of content you’re looking for will probably be the first tag you filter for. The following information about Organizations/Groups and DEF CON Departments will be useful knowledge for you when deciding how you want to filter your schedule view.

\n\n

Organizations/Groups at DEF CON (Creators and more)

\n\n

Creators

\n\n

DEF CON operates rather differently from most conventions, in that floor space is given to third-party creators for free, so that creators can conduct their own activities for DEF CON attendees to experience. There are three main types of creators: Contest, Village, and Community. You can find more information about each of the approved creators for DEF CON 34 by going to info.defcon.org.

\n\n

Contest

\n\n

Contest creators provide hands-on, community-run challenges where attendees test their skills, creativity, and hacker spirit in a fun, competitive environment. Most contests are open for participation to any DEF CON attendee, though some (including the DEF CON CTF) require prequalification before the con.

\n\n

Village

\n\n

Villages are mini-conferences in and of themselves, focused on a single topical area. Each runs its own hands-on activities, workshops, talks, or other activities. Most villages are third-party organizations, but some are operated by DEF CON directly.

\n\n

Community

\n\n

Communities are organizations that either don’t quite fit into “Contest” or “Village”, or are new to DEF CON. We want to help them define the best way to showcase what they came to share without a prior template limiting their options. These often include social groups from the larger hacking community, and non-profit organizations that exist for the benefit of the community or the technology we use. We also make space for new groups, events, and activities to give them the freedom to test out new concepts without taking on too much, so that they can grow and scale organically. It’s possible for a community to be reclassified as a village for a subsequent DEF CON convention, though we expect that most communities will remain that way indefinitely.

\n\n

Exhibitors and Vendors

\n\n

Vendors are the companies that come to DEF CON to sell goods. Here you can buy non-DEF CON badges, tools, swag, and hardware.

\n\n

Exhibitors are professional organizations looking to connect to the unique DEF CON audience; the hacker, the researcher, and the student. Exhibitors were considered vendors until DC31. The difference is largely that you walk out of Vendors carrying physical merchandise, but you walk out of Exhibitors with a dream.

\n\n

(Select) DEF CON Departments

\n\n

We don’t consider these creators, and they’re operated by DEF CON.

\n\n

Talks

\n\n

Official DEF CON Talks are those presentations that are given on the “main stages”. Individuals wishing to present a talk at DEF CON file a response to the Call for Papers earlier in the year. The DEF CON CFP Review Board reviews all submissions, and determines which of the talks will make it on stage. It is not unheard-of for audience seating to reach capacity; it’s not guaranteed that everyone who wants to attend a talk will be able to. These talks are also streamed in real-time via DCTV on Twitch.

\n\n

New for DEF CON 34: Silent Disco headsets. We heard you; audio crossover between audiences in the LVCC exhibition halls was a problem. This year we’re solving that problem by removing speakers and adding headsets. Headsets will be provided so that every attendee with a seat will have a headset to wear. Additional information about how this process will work will be released closer to the con.

\n\n

DEF CON refers to a stage as a track. For example “Track 1” could be considered the same thing as “Main Stage 1”.

\n\n

CTF

\n\n

One contest, the “DEF CON CTF”, is the highest-profile contest. It requires prequalification, so unless you’re on a prequalified team, you’re just spectating. The DEF CON 34 CTF is conducted by the Benevolent Bureau of Birds. You can learn more here.

\n\n

Workshop

\n\n

Workshops are (generally) 4-hour, small, hands-on classes. Pre-registration is required. If you want to get a seat, follow DEF CON on social media for announcements on when the pre-reg will open. Tickets sell-out very fast – usually within a few minutes of becoming available. You’re competing with thousands of other excited hackers here, and space is limited! Find out when registration opens, know what workshop you want, and lock it in.

\n\n

Avoid registering for just ‘any’ workshop. It’s a 4-hour commitment, so plan accordingly. Every year a few folks show up seemingly confused at what they registered for, leave early, and a seat is wasted.

\n\n

Training

\n\n

Intensive, two-day and four-day courses of study with world-class instructors aimed at building specific skills. Smaller class sizes allow for a hands-on experience. DEF CON Training is for anyone who wants to hone their skills in a challenging and fast-paced environment.

\n\n

Trainings are separately paid, and generally happen after the main con ends. You can learn more about training opportunities at training.defcon.org.

\n\n

Merch

\n\n

DEF CON’s Merch department, formerly known as Swag, and sometimes called Smerch, is where you can go to buy DEF CON branded apparel and wares.

\n\n

Merch sales are **CASH ONLY**. We do not accept cards of any kind. We recommend that you bring cash with you when you come to the LVCC West Hall, as the ATMs at the West Hall are usually empty.

\n\n

While we usually can’t predict which items they will be, there are always a few items that sell-out faster than the others. The earlier you get in line, the better your chances will be that you will be able to buy that year’s popular item. If you aren’t concerned about buying whichever items are that year’s most popular, then there’s no need to prioritize standing in line for merch.

\n\n

Merch generally opens to attendees for sales at around the same time human registration opens, and is sometimes referred to as “Linecon Part 2”. The line to buy merch on the first day is almost always longer than the line to buy or pick-up a human badge. The line for merch on the second and third days is usually fairly short and fast, though the most popular items will probably have sold-out.

\n\n

Our goal is to publish the list of items to be sold, along with an image for each item, and have it available in Hacker Tracker no later than 03:00 on the first day of sales (so, a few hours before human registration opens).

\n\n

How to make things faster and easier

\n\n

We recommend that attendees browse available merch in Hacker Tracker. If we sell-out of an item or item size, that will soon be indicated in the app. The apps allow you to build a “wish list” of items that you want to buy. Doing so makes the ordering process much easier for both you and us.

\n\n

The process goes something like this (subject to change on-site, if needed):

\n\n

You browse merch in Hacker Tracker, and add it to your list. Hacker Tracker provides a QR code representing your list. You stand in line, and once you reach the front of the line, you show your QR code to the order taker, or scan the QR code at an express order station. You will be handed two pieces of [receipt] paper: one for you to keep, with your order number on it, and one for you to give to the order fulfillment staff. You will be directed to walk to the order fulfillment staff, give them the appropriate piece of paper, and then you will stand in the holding area while they go pick your merchandise from the warehouse. A cashier will call your order number; your order number will also be indicated on overhead TVs. Proceed to that cashier’s station. You will verify that the merch you requested is all present, and you pay the cashier (cash only) for your merch.

\n\n

That might read as though it’s complicated, but going through the motions, it’s really not. Just stand in line and it will all make sense. There are staff to direct you at every step of the way. Once you’ve scanned your QR code at the front of the line, it usually only takes a few minutes to get your merch, pay, and leave.

\n\n

Hotline

\n\n

Safety is important to us at DEF CON. If you’re struggling, scared, or just need someone to voice a concern to, DEF CON Hotline is here to support you. Help is available to all, especially if talking to conference staff in person isn’t within your level of comfort. Hotline is here to listen. We accept calls, text (SMS) messages, and Signal messages, all to the same telephone number: +1 (725) 222-0934 (tel:+17252220934)

\n\n

You can reach DEF CON staff during normal hours to anonymously report any behavior violating our code of conduct or to find an empathic ear by calling. Hotline is confidential and available while any official conference activities are active.

\n\n

Specially trained Goons are standing by to listen and, if needed, connect you to appropriate support services. These services may be other Goons or external services we partner with such as Kick at Darkness, The Rape Crisis Center Las Vegas, and the Nevada Coalition to End Domestic and Sexual Violence.

\n\n

The Hotline team is diverse and undergoes extensive training including dedicated support for LGBTQ+.

\n\n
    \n
  • Mental Health Crisis: If you or someone you are with is experiencing a mental health crisis, please do not wait. Immediate, free help is available 24/7 by calling or texting the following national resources:
  • \n
  • 988 Suicide & Crisis Lifeline: Call or text 988. Available 24/7 in the US and Canada. This connects you with trained crisis counselors who can provide support and local resources.
  • \n
  • Crisis Text Line: Text HOME to 741741. Available 24/7 via text message for private, confidential support from a trained volunteer counselor.
  • \n
\n\n

SOC

\n\n

SOC Goons are dedicated to keeping attendees and fellow Goons safe throughout the DEF CON experience. Their responsibilities include:\n* Supporting medical response: providing initial assistance and coordinating with professional responders\n* Supporting incident management: reporting, investigating, and de-escalating incidents such as Code of Conduct violations\n* Supporting crowd flow management: keeping traffic moving safely, managing long lines, and protecting attendee safety during high-demand events\n* Supporting positive experience: helping support a fun, welcoming atmosphere for everyone at the con. Ensuring one individual’s fun doesn’t disrupt everyone else’s enjoyment.

\n\n

Feel free to approach a SOC Goon any time for assistance. Goons are one big red shirt wearing family. All SOC Goons wear red shirts, but not all Goons in red shirts are SOC Goons. Ask any Goon for help, if they can’t solve your issue, ask them to call a SOC Goon to your location..

\n\n

SOC works hand-in-hand with its partner department, Hotline: the two teams routinely refer known situations to one another and collaborate directly to resolve ongoing issues.

\n\n

NOC (Wi-Fi)

\n\n

DEF CON strives to provide Wi-Fi access to everyone during DEF CON. We operate multiple Wi-Fi networks: one “secure”, and one “open”.

\n\n

In order to use the secure network, you will need to register an account here, and configure your devices appropriately, following the instructions provided by that system. This Wi-Fi network has client isolation enabled, meaning that you will be unable to communicate with other wireless clients. Note that the provided link will not be functional until the Wi-Fi network is operational at the LVCC; don’t expect it to work until Wednesday, August 5th, 2026, at the earliest.

\n\n

If you are feeling brave and want to use the “open” network, there is no configuration required beyond simply joining that Wi-Fi network. Nearly everyone recommends against using this network; you should most definitely not do anything important or requiring privacy while connected to this network.

\n\n

Please refrain from broadcasting your own hotspot. This uses the same frequencies that everyone else is using for Wi-Fi, potentially slowing things for everyone else. It is acceptable to briefly use your hotspot in order to go through the above Wi-Fi registration process and download the required certificate.

\n\n

DCTV

\n\n

DCTV is the department that consumes camera feeds from the Main Stages (“Tracks”) and broadcasts them to Twitch.

\n\n

In the past, DCTV also streamed over our contracted hotel blocks’ coaxial plant, so that attendees could tune in from their hotel room. Unfortunately, that is no longer possible from the LVCC.

\n\n

You can learn more about DCTV here.

\n\n

Parties, Meetups, and Events (PME)

\n\n

There are *many* parties, meetups, and events that happen at DEF CON, nearly all of which are conducted by people or groups who responded to our Call for Parties, earlier this year.

\n\n

Parties that are listed on info.defcon.org and in Hacker Tracker (after selecting the DEF CON 34 conference) are “Official Parties”, which means they applied and were approved. Regardless of whether these are held at the LVCC West Hall or elsewhere, the DEF CON Code of Conduct applies.

\n\n

There are many, many parties conducted by companies, organizations, and private individuals, in the Las Vegas area at around the time DEF CON is happening. DEF CON cannot recommend, nor enforce the Code of Conduct, unless they are listed as an Official Party.

\n\n

Health & Hygiene

\n\n

The LVCC West Hall is a *large* space, and you will likely do much more walking than you anticipate. Most veterans know to buy new shoes (and potentially compression socks) several weeks before DEF CON, so that they have time to “break them in” before the con begins. If you have not purchased new shoes and DEF CON is going to begin within a few days, be careful: your new shoes that are not broken-in yet may hurt more than the ones you replaced.

\n\n

“The 3-2-1 Rule” is a concept that originated as widely-shared lore for surviving a high-intensity environment like Las Vegas in August: it suggests aiming for 3 hours of sleep, 2 meals, and 1 shower per day, minimum. While this is shared with a humorous tone, the underlying message remains genuinely good advice - people can easily run themselves into the ground without monitoring basic needs. Many folks are now of the opinion that “6-3-1” is now more appropriate: 6 hours of sleep, 3 meals, and 1 shower. As these guidelines evolve based on community consensus or health recommendations, please remember that current best practices should always supersede historical \'lore.\' The information provided here is for general self-care awareness only, based on historical community advice. It is not medical or professional guidance. All attendees are responsible for monitoring their own health and safety throughout the event.

\n\n

Hydration

\n\n

DEF CON is held in Las Vegas, Nevada, in August. The heat and intensity of the environment can make dehydration extremely dangerous - it\'s a constant safety concern. Proper hydration is critical for your health and the ability to enjoy the event.

\n\n
    \n
  • Don\'t wait until you are thirsty! Thirst is one of the first signs that you are already starting to become dehydrated.
  • \n
  • Water, Water, Every Hour: Drink water consistently throughout the day, even if you don\'t feel thirsty.
  • \n
  • Electrolytes Matter: Consider bringing electrolyte packets (like sports drink mixes or oral rehydration salts). Sweating out salt and minerals is just as dangerous as losing water.
  • \n
  • Monitor Your Body: Pay close attention to signs of heat exhaustion, such as nausea, dizziness, headaches, or muscle cramps. If you feel any of these, immediately find a cool spot and rest.
  • \n
  • Urine Clarity Check: As a simple indicator: your urine should be pale yellow. Passing urine (and therefore flushing out toxins) is essential. It is highly recommended that you make an effort to visit the restroom at least every two hours.
  • \n
\n\n

Accessibility

\n\n

All persons with disabilities regardless of the severity, visibility, permanence or any other factor of their disability are to be treated with dignity and respect as per the DEF CON Code of Conduct. Under no circumstances will harassment be tolerated. Please report any instances of harassment, abuse or other out of line behavior to the DEF CON NFO Node, any DEF CON Goon, or the DEF CON Hotline (+1 (725) 222-0934).

\n\n

During the convention there will be lines for registration, badges, and other events. Any attendee with accessibility needs may proceed to the front of any line and ask a goon for assistance. It is asked and expected of all goons and attendees to be respectful of this.

\n\n

If an attendee requires a personal aide to assist them while at DEF CON, please speak to a DEF CON Human Registration goon for assistance with badge registration. Your personal aide will be issued a “paper” human badge free-of-charge.

\n\n

The LVCVA website provides info on accommodations designed for all Las Vegas travelers. Each hotel and venue will have their own policies concerning service animals or the provision and use of assistive equipment such as mobility scooters, wheelchairs and other devices. Please check with a representative of the location where you are visiting.

\n\n

The Las Vegas Convention Center (LVCC) offers comprehensive ADA-compliant accessibility, featuring wheelchair-accessible entrances, parking, and restrooms. The facility includes elevators, ramps, and connects to the wheelchair-accessible Las Vegas Monorail.

\n\n

Las Vegas Convention and Visitors Authority\n702-892-0711\nNevada Relay Service\nVoice: 1-800-326-6888 or Dial 711\nTTY/ASCII/HCO: 1-800-326-6868 or Dial 711

\n\n

Permit Parking

\n\n

Please see Transportation -> Parking, above in this document.

\n\n

Wheelchair and Scooter Rentals

\n\n

Despite LVCC’s prohibition on mobility devices, the LVCC does permit use of mobility devices only when they are medically necessary. Your device may be owned (such as if you own your own wheelchair) or rented (for a fee) only from their preferred vendor, Scootaround. You may call Scootaround for more information, at +1 (888) 441-7575; their website also permits online bookings. It is possible to pick up your rented Scootaround scooter from the FedEx Office inside the LVCC West Hall. FedEx Office only handles the logistics; they are not involved in the booking process. You can reach FedEx Office by calling +1 (702) 733-2898, option 8.

\n\n

Service Animals

\n\n

Service animals are permitted throughout the venue. However, this does not include emotional support animals, therapy animals, or companion animals. Any animal whose task is to provide protection, emotional support, well-being, comfort, or companionship is not considered a service animal and will not be allowed into the venue. Only service animals that have been individually trained and are under the proper care of their owners will be allowed within the premises. The following guidelines must be followed:

\n\n
    \n
  • All service animals must remain by the handler’s side at all times and must be harnessed, leashed, or tethered. If these devices interfere with the service animal’s work, or if the handler’s disability prevents the use of these devices, the handler must maintain control of the animal through voice, signal, or other effective controls.
  • \n
  • Service animals must be housebroken. The only relief area accessible from the LVCC West hall is a gravel area in the vicinity of the Diamond Parking Lot.
  • \n
  • Anyone bringing an animal will be responsible for and liable for any damage or injury caused by the animal.
  • \n
  • All service animals should have legally required vaccinations. LVCC’s staff may require verification, at their discretion.
  • \n
\n\n

We ask that you do not leave your animal in your car while you\'re inside the event, as vehicles without air conditioning on may become too hot and unsafe for any animal.

\n\n

Hackers With Disabilities (HDA)

\n\n

HDA is a place for people with disabilities to hear talks aimed at hacking disabilities / gear / specific topics on security and safety. To have a place to recharge assistance devices, get assistance with disability issues, to have a safe space to retreat should things get to be too much, to form community bonds with other hackers with disabilities and to be an educational outreach and support system showing that just because you have a disability you can still be a hacker and part of the community.

\n\n

HDA is an official DEF CON Community space. Please see the venue map for the location, as it may move rooms from year to year.

\n\n

DEF CON Policies

\n\n

There are numerous policies that govern activities happening at DEF CON. Please familiarize yourself with each of them, as they all apply.

\n\n\n\n

LVCC Policies

\n\n

The following policies were copied from the LVCC Facility Guide, as it appeared on 2026-07-11.

\n\n

LVCC Code of Conduct

\n\n
    \n
  1. SAFETY FIRST – Follow all safety guidelines and instructions. Report any hazards or unsafe behaviors to LVCC staff immediately.

  2. \n
  3. RESPECT AND COURTESY – Treat all building occupants with respect, regardless of their role, background or beliefs. Avoid language that is offensive, discriminatory or harmful.

  4. \n
  5. ZERO-TOLERANCE POLICY – Any form of discrimination, harassment or bullying, whether based on race, gender, age, disability, national origin, religion or sexual orientation, will result in immediate removal.

  6. \n
  7. REPORTING CONCERNS – Visitors should report any issues or concerns to convention center staff. If you see something that violates this code, report it to LVCVA Security personnel at 702-892-7400.

  8. \n
  9. PROFESSIONAL BEHAVIOR – All people, whether LVCC employees, visitors or non-LVCC workers, are expected to always conduct themselves professionally and respectfully. Please refrain from casual or inappropriate conversations and behavior.

  10. \n
  11. APPROPRIATE ATTIRE – Wear appropriate attire while on LVCVA property. This includes, but is not limited to pants/shorts, shoes and shirts, and must always be worn.

  12. \n
  13. ALCOHOL AND DRUGS – The consumption of alcohol is permitted only in designated areas. The use or possession of illegal drugs is strictly prohibited.

  14. \n
  15. CLEANLINESS – Keep the venue clean. Use the provided trash receptacles and recycling bins. Workers should ensure that their respective areas are clean and organized.

  16. \n
  17. PRIVACY AND PHOTOGRAPHY – Ask for permission before taking photographs or videos of individuals or property. Respect privacy requests as well as event rules/regulations. Workers should not share confidential information or images without permission.

  18. \n
  19. COMPLIANCE WITH LAW – All building patrons, regardless of purpose on LVCVA property, must adhere to local, state and federal laws while at the convention center.

  20. \n
  21. PROHIBITED ITEMS – The possession of unauthorized items, including, but not limited to, weapons, drugs and property, is strictly forbidden and will result in immediate removal from the LVCC.

  22. \n
  23. NO UNAUTHORIZED ACCESS – Entry into restricted areas without proper clearance will result in immediate removal and potential legal action.

  24. \n
  25. MANDATORY IDENTIFICATION – Event badges or proper company/union identification must be visibly displayed while on LVCC property. Failure to present IDs when asked will result in removal from the premises.

  26. \n
  27. RESPECT FOR PROPERTY – Any form of vandalism, theft or misuse of property will result in immediate removal and potential legal action.

  28. \n
  29. PROPERTY REMOVAL – No individual is allowed to remove any property, materials, equipment or items belonging to the convention center or any events occurring on LVCC premises without show management approval. Violators will be trespassed and could face potential legal action.

  30. \n
  31. SMOKING – Smoking indoors is prohibited. Smoking outdoors, including vaping, is not allowed on LVCC property except in designated smoking areas.

  32. \n
  33. CONSEQUENCES FOR VIOLATIONS – Violations of the code may result in warnings, temporary bans or permanent removal from the LVCC campus at the discretion of the LVCVA management.

  34. \n
  35. AMENDMENTS – This Code of Conduct is not intended to be all inclusive, and may be updated as needed to address new challenges and to ensure the well-being of the facility and its occupants.

  36. \n
\n\n

LVCC Prohibition on (Recreational) Personal Mobility Devices

\n\n

Notice: Personal Mobility Devices Not Allowed on Property

\n\n

Please be advised that only ADA-approved personal mobile devices are permitted on the premises. This policy is in place to ensure the safety and accessibility of all individuals within our facility. We kindly ask attendees to refrain from bringing any non-ADA personal mobility devices onto the property. This includes, but is not limited to, the following:

\n\n
    \n
  • Segways
  • \n
  • Manual Scooters
  • \n
  • Electric Scooters
  • \n
  • Skateboards
  • \n
  • Other Personal Mobility Devices
  • \n
\n\n

The speed limit for approved ADA personal mobility devices on the Las Vegas Convention Center property is always 5 miles per hour (mph) and electrical charging of any kind for personal mobility devices is not permitted indoors at any time. Charging is only permitted outside in designated areas. Violation of this policy could result in being removed and trespassed from the Las Vegas Convention Center property. We recognize the importance of providing an inclusive environment for all guests and contractors. Thank you for your cooperation and understanding in upholding this policy.

\n\n

Violation of this policy will include the following punitive actions:

\n\n
    \n
  • 1st Violation: Verbal warning
  • \n
  • 2nd Violation: Required to depart LVCC property for that day
  • \n
  • 3rd Violation: Trespass indefinitely
  • \n
\n\n

NOTE: There are no storage spaces available for ADA required personal mobility devices on the Las Vegas Convention Center property.

\n\n

LVCC Nonsmoking Policy

\n\n

There is no smoking within the building or within 25 feet of any entrance, and there will be signage outside of every entrance with the no-smoking policy. **Electronic cigarettes, electronic vaping devices, personal vaporizers, etc., are not permitted within the facility.**

\n\n

Commentary

\n\n

This means that all forms of smoking and vaping are strictly prohibited; the LVCC uses police and K9 units for enforcement. There is no smoking on the outdoor terraces. Smoking is *only* permitted in designated outdoor smoking areas.

\n\n

About DEF CON

\n\n

DEF CON is the world\'s most influential hacker conference. Held every year since 1993 in Las Vegas, Nevada, DEF CON is the hub of a global community of hackers, security geeks and curious technophiles.

\n\n

There is a documentary about DEF CON that you may be interested in watching.

\n\n

The Beginning

\n\n

The following was written by The Dark Tangent:

\n\n

Here’s how DEF CON started: Originally started in 1993, it was a meant to be a party for member of \"Platinum Net\", a Fido protocol based hacking network out of Canada. As the main U.S. hub I was helping the Platinum Net organizer (I forget his name) plan a closing party for all the member BBS systems and their users. He was going to shut down the network when his dad took a new job and had to move away. We talking about where we might hold it, when all of a sudden he left early and disappeared. I was just planning a party for a network that was shut down, except for my U.S. nodes. I decided what the hell, I\'ll invite the members of all the other networks my BBS (A Dark Tangent System) system was a part of including Cyber Crime International (CCI), Hit Net, Tired of Protection (ToP), and like 8 others I can\'t remember. Why not invite everyone on #hack? Good idea!

\n\n

Where did the name come from? The short answer is a combination of places. There as a SummerCon in the summer, a HoHoCon in the winter, a PumpCon during Halloween, etc. I didn\'t want any association with a time of year. If you are a Phreak, or just use your phone a lot you\'ll notes \"DEF\" is #3 on the phone. If you are into military lingo DEF CON is short for \"Defense Condition.\" Now being a fan of the movie War Games I took note that the main character, David Lightman, lived in Seattle, as I do, and chose to nuke Las Vegas with W.O.P.R. when given the chance. Well I knew I was doing a con in Vegas, so it all just sort of worked out.

\n\n

Historical Attendance

\n\n

Recent DEF CON events have had roughly 25-28k individuals. DEF CON 27 had a record showing, with approximately 30,000.

\n\n

Links and Social Media

\n\n

If you post on social media about DEF CON, please tag us at @defcon, or use the hashtag #DEFCON,#DEFCON\\, #DCVegas, #DC\\. Tagging us on social media can increase the chances we will see it, and give your post a better chance of us sharing it. Attendees also follow the #DEFCON and DC yearly tags. Browse around for the most active ones. It is sometimes helpful to include art, a photo, or website link.

\n\n\n\n

Getting in Touch

\n\n

If you have a question that isn’t answered in this guide or on the DEF CON Forum, email your question to info@defcon.org. You can also try emailing DT, but because he receives an unmanageable volume of mail, it’s relatively unlikely you’ll receive a response.

\n\n

DEF CON Groups

\n\n

Local DEF CON Groups (DCGs) run year-round in cities worldwide. Check to see if there\'s one near you, for a way to get into (or stay involved in) the community outside of the con itself.

\n\n

Goons

\n\n

Goons are DEF CON’s posse! Goons provide a wide range of tasks at DEF CON, like: Setting up the internet, helping de-escalate issues, enforce the code of conduct, keeping lines in order, selling merch and badges. Goons are also providing logistical support all over the con for all the various content creators, in villages, contests, parties, events, and communities. It takes many people to pull off DEF CON, some dedicating months of work before the con, and all working long days at the con. We cannot do this without them!

\n\n

DEF CON 34 Goons should all have visible patches with their nickname on them, plainly visible from the front, so it is easier to remember who you talk to about what.

\n\n

Goons are in one of two states, either ON duty or OFF duty.

\n\n

If they are ON DUTY, they will be wearing a current-year red DEF CON 34 Goon shirt, a current year Goon badge, and a name patch.

\n\n

If Goons are OFF DUTY, they will not be wearing the current-year red DEF CON 34 Goon shirt, but may still have a Goon badge on, so they can access the venue.

\n\n

Goons ON DUTY are not supposed to drink alcohol.

\n\n

Goons OFF DUTY have been known to drink alcohol.

\n\n

PAST Goons may be seen wearing previous red shirts or badges, as they helped run a past DEF CON, but that DOES NOT make them a current DEF CON 34 Goon.

\n\n

Please leave feedback regarding Goons, good or bad, and refer to the name on their name patch. Feedback can be sent to feedback@defcon.org. If your feedback is urgent or serious, please immediately let us know. We recommend that you call the DEF CON Hotline, but you may also stop at an NFO Node and ask for help if you aren’t comfortable making that call yourself.

\n\n

Sometimes Goons must move FAST, so if they can’t stop and talk, it’s generally for a good reason; they’re not trying to be rude or dismissive. If this happens to you, you can always go to an NFO Node for assistance.

\n\n

Goons Goon for many reasons, but the pay isn’t one of them. They put in long hours and many weeks or months of planning and take time off work to make the con happen for everyone.

\n\n

Becoming a Goon

\n\n

We don’t have an official GOON application form (yet); our departments are currently fully staffed. That said, we still welcome our community at large to help identify and recommend trusted members of the community interested in contributing to the con experience in one form or another. Help could be by way of spending time inside an accepted community or village for a day, or supporting a contest or event. Maybe, if their special talents align with our needs, they’ll become an official Goon.

\n\n

If you are a Creator and need more people to help in your space, please let us know. Regardless of whether you’re a content creator or a goon, there is an opportunity for individuals to earn a badge in exchange for a commitment to scheduled shifts during the event. These roles will help facilitate conference logistics, support shared environments, and assist with coordination tasks that keep the event running smoothly. The goal is to create a structured way for experienced community members to contribute while still having time to participate in DEF CON.

\n\n

Subjective and/or Controversial Advice

\n\n

For things that don’t fit elsewhere.

\n\n

Handles / Nicknames

\n\n

Your handle is your (mostly) unique name within the hacker community that allows you to be quickly and easily identified. There may be hundreds, or even thousands of “Mikes” at DEF CON, but not nearly as many Wiseacres or Anchs.

\n\n

Many people at DEF CON choose to use a handle instead of their real name to identify themselves. Be nice, and respect someone’s choices no matter what they choose to call themselves. All kinds come to DEF CON, so to allow yourself to be easily identified, and to protect your own identity, you may also choose to use a handle, whether it’s one you already have or a new one that you create. Remember, respect other’s choices and everyone will have a good time.

\n\n

DEF CON is not, was not, and will not be, canceled.

\n\n

OK, well, it was once, but then we un-canceled it.

\n\n

Nobody seems to agree exactly when or where it started, but “DEF CON is Canceled” is an inside joke that is many, many years old. Please stop using it. Newcomers to DEF CON simply don’t “get it”.

\n\n

LineCon / Lines / Queueing

\n\n

In the Oregon Trail days, DEF CON’s Human Registration department was not as efficient as they are now. The line (or queue) to register was an epic length, and some people decided to get in line the night before registration opened, and that became “LineCon”. We still try to accommodate LineCon whenever possible; attendees will be able to start lining up for human registration on Wednesday night (because human registration will open on Thursday morning). Bring a portable charger, snacks (for yourself and maybe a friend, not for 500 people), and patience. Talking to the person next to you in line is a legitimate and encouraged way to network. Expect beach balls from above, keep them in the air.

\n\n

What to bring

\n\n
    \n
  • A government ID. If you want to buy alcohol or any other restricted material, it’s entirely possible you’ll be carded, even if you look as old as we feel.
  • \n
  • A smartphone. Most of our attendees use Hacker Tracker to build their schedule of activities, and see what’s going on at any given time and place. Exploring DEF CON is *much* easier if you do the same.
  • \n
  • A laptop. Maybe. This is one of those slightly-controversial opinions.\n
      \n
    • If you are planning to get hands-on in a workshop, village, community, etc., and definitely if you are planning to participate in most contests, you’ll need a laptop.
    • \n
    • Other people say that DEF CON is best experienced without a laptop; leave it at home or in the hotel room, and just do things that don’t require a laptop to participate. (You can stay busy this way too, particularly with talks and demos.)
    • \n
    • Crucially: make sure that you are familiar with the operating system on the laptop you bring. That is to say, don’t bring a laptop running Linux if you aren’t already familiar with Linux. Same with Mac and Windows. We have a lot of wonderful creator staff, but they can’t be basic tech support.
    • \n
  • \n
  • Cash. Many things at DEF CON accept only cash (many badges, DEF CON merch, food trucks (if any), perhaps some vendors).
  • \n
  • Credit Card(s). The LVCC’s food court is entirely cashless, so if you want to buy any food or beverage while you’re here, you’ll need a credit card. (Debit cards work too, but are riskier.)
  • \n
  • Stickers. Bring stickers to share and trade; it\'s a whole subculture. But don’t stick them to a wall, window, or anything else at the LVCC, or you will be trespassed from the property and potentially charged. The LVCC is government property.
  • \n
  • Bag. Most people seem to buy merch or otherwise pick up stickers/trinkets/etc while they’re at DEF CON. Bring an extra bag. That said: DEF CON is not like a stereotypical IT conference, where vendors are casually handing out swag to anyone who stops by their booth. It’s possible that some group might give you something, but very broadly speaking, the things that might take up space are most likely things you would buy from merch.
  • \n
  • Water Bottle. Did you read the section on hydration? It’s critical. Bring a refillable water bottle that you have labeled or otherwise made identifiable to you. There are water bottle filling stations throughout the LVCC.
  • \n
  • Electrolyte packets. If you do get dehydrated, chugging water isn’t the best solution. Many people swear by electrolyte packets to stay hydrated (e.g. LiquidIV, Pedialite, etc).
  • \n
  • Mesh Device. Quite a few people use Meshtastic or Meshcore to communicate at DEF CON. If you’re into this, it could be handy. Other people say that the spectrum is catastrophically busy so there’s no point. If you do bring a Meshtastic device, please ensure that you are operating using this year’s DC34-specific firmware (or at least configuration).
  • \n
  • Data Duplication. If you would like to get a duplicate of all the data that the Data Duplication Village has, you will need to bring five (5) SATA3-7200 RPM 8 TB drives. A list of the content of each of the drives will be made available in Hacker Tracker shortly before the con starts. It is permissible to bring fewer drives, if you only want fewer drives duplicated. You cannot, however, pick and choose material between drives, as this is done via whole-disk copying. You can provide a larger drive, but it will only wind up with 8TB on it. (It’s not possible to put 2 drives on a single 16TB drive, for example.)
  • \n
  • Consider dressing in layers. Be prepared for extreme temperature swings throughout the day - from the August Vegas heat outside to blast-cold A/C inside the venues. Always bring layers, like a light hoodie or light jacket, so you can stay comfortable no matter where you find yourself exploring the con.
  • \n
  • Some of the most veteran of DEF CONners know to bring (white) diaper cream with zinc in it. Research into this is an exercise for the reader.
  • \n
\n\n

OpSec

\n\n
    \n
  • Every device you bring should have all of the latest manufacturer and operating system patches installed. Do not consider this optional or a nice-to-have, consider it mandatory. Verify this 1 week before you travel to DEF CON (because then you have time to resolve problems), and again 2 days before you travel to DEF CON.
  • \n
  • Please consider not bringing your main work laptop, if at all possible. DEF CON can be considered a high-risk environment, and your company’s infosec department would probably appreciate your laptop not coming anywhere near DEF CON. That said, risk is… not nearly as high as it once was.
  • \n
  • You almost certainly don’t need to bring any burner devices. (A burner is a device that you buy specifically to attend the con, and then dispose of it after the con.) If you are the 1 person who does need to, you already know this.
  • \n
  • It’s recommended that you bring dedicated/clean devices when you attend conferences, rather than a daily-driver. This is just good practice when potentially encountering hostile networks, and is not limited to DEF CON.
  • \n
  • Practically speaking, most people will just bring their everyday smartphone and laptop, so you’re certainly not going to stand out if you do the same.
  • \n
  • Except when you are actively using them, shut off any device radios (like Bluetooth and Wi-Fi). This reduces your attack surface; if the radio is turned off, attackers can’t exploit any potential vulnerabilities.
  • \n
  • If your devices normally run local services that are not strictly necessary (like a local database engine or webserver or game server), disable them while you’re at con.
  • \n
  • VPNs are not required, but are a reasonable extra-layer of security. This is especially true on non-DEF CON networks, such as hotels, casinos, restaurants, etc. Many veterans trust those public networks *far* less than DEF CON’s networks.
  • \n
\n\n

Outside Parties

\n\n

Parties that are not approved by DEF CON, and not subject to the Code of Conduct, but which may be open or of interest, may be found at defconparties.com. Do note that this website has no affiliation or association with DEF CON. Many of these parties will require a badge, RSVP, or invitation to enter. Do not assume that you’ll be allowed in just because you’re a DEF CON (or Black Hat) attendee.

\n\n

Everything Else

\n\n
    \n
  • Check Hacker Tracker or info.defcon.org *regularly* for updates before and throughout DEF CON. Schedule changes, room adjustments, and announcements are all made available there.
  • \n
  • Watch the DEF CON Documentary if you haven’t already. Do this *before* you travel to Vegas.
  • \n
  • Going solo? Totally normal, tons of people do it. Villages and the line (for anything) itself are the easiest places to strike up conversation. Nobody\'s going to think it\'s weird.
  • \n
  • Networking in a Sea of Social Engineers: The best part of DEF CON is connecting with brilliant minds! Dive into the talks, strike up conversations, and build connections - that’s what we do best. However, remember that \"social engineering\" isn\'t just something out of a movie; it\'s when someone attempts to manipulate people rather than systems. While every conversation can lead to an amazing connection, also treat your networking time with caution. Be vigilant for anyone who seems overly persistent, asks too many deep questions quickly, or tries to extract sensitive information (passwords, specific work details, private keys). Your mantra should be: Share only what you are 100% comfortable sharing. Keep the conversation flowing and fun, but always prioritize your personal security and discretion above all else.
  • \n
  • Find your Hacker Community: DEF CON is an immensely diverse community that welcomes people from every walk of life, gathering us together purely based on shared interests and passions for technology and knowledge. Whether you\'re fascinated by low-level hardware in the Hardware Hacking Village, captivated by network forensics at the Packet Hacking Village, or pursuing any other technical passion, this is where you will find your community. Connecting with others who share your deep expertise and unique experiences doesn\'t just make the event better - it significantly enhances the entire con experience, making it exponentially more rewarding for everyone involved.
  • \n
  • Networking Tip: Approaching the Legends - Encountering famous \"OG\" hackers can feel intimidating, but don\'t be afraid to approach them! The key is respect and awareness. Treat every person, whether they are a legendary figure or just starting their journey, with courtesy; never interrupt someone who is deep in conversation. Remember that building genuinely great connections comes from treating everyone as a peer first. Approach with genuine curiosity, listen more than you speak, and the amazing opportunities will find you!
  • \n
  • Several years ago, Lonely Hackers Club created a “DEF CON Guide” that you may be interested in reading. It covers some of the same topics as this guide, but is more casual and opinionated. You can find the guide here.
  • \n
\n\n

Credits

\n\n

Some portions of this document – mostly, but not limited to portions of the “Subjective/Controversial Advice” section – were written by community members.

\n\'',0,3585,'f292c5a82f6e963692d2d05911f4cf71'),('\'Audio Info\'','\'

Listening Together at DEF CON 34 (how audio will work this year)

\n\n

New for DEF CON 34: listening to talks via headphones! We hope that this will significantly improve audio quality for everyone who wants to attend talks at DEF CON.

\n\n

We\'re using two different solutions: Quiet Events and Listen WIFI.

\n\n

Quiet Events

\n\n

Quiet Events may also be known as \"Silent Disco\". This system is available at all main stages and creator stages, and also at many village and community locations throughout the first-floor exhibition halls.

\n\n

Here\'s how it works:

\n\n

There will be a headset placed on each chair in the audience. If you want to join the audience, put on the headset and sit on that chair. When you get up to leave, put the headset back on that chair. Headsets are programmed & will not work in other areas - leave them here. Please don\'t remove them from their assigned area.

\n\n

Cleaning wipes and ear cup covers are available at entrances to main stages and headphone help tables. Please consider reducing waste, and reuse your ear cup covers.

\n\n

Troubleshooting: Turn the wheel +/- on the ear cup to adjust the volume. Headsets have LEDs on them; yours should be displaying the same LED color as those around you -- the color indicates the audio channel that the headset is tuned to. If they are showing the wrong LED color, or you otherwise need assistance, look for nearby help tables.

\n\n

Tech Details

\n\n

This solution broadcasts using radio transmitters near each stage, and the headphones have pre-programmed frequencies (channels), based on where each headphone is assigned.

\n\n

Listen WIFI

\n\n

Listen WIFI is a streaming audio solution, where attendees are able to listen to audio using their own smartphones. This system is available only at Main Stages 1 - 5.

\n\n

Here\'s how it works:

\n\n
    \n
  • Install Hacker Tracker. This is the official app of DEF CON.
  • \n
  • Install Listen WIFI. This is the app that will let you listen to the audio stream.\n
  • \n
  • Connect to the DEF CON Secure Wi-Fi (DefCon-WPA3 or DefCon).
  • \n
  • Launch the Listen WIFI app once.
  • \n
  • Open Hacker Tracker. Make sure that you\'re looking at the DEF CON 34 conference. Navigate to readme.nfo -> Audio Info. Scroll down to the Listen WIFI audio channel list. Tap on the channel that you wish to listen to. Listen WIFI will launch, and connect to the desired audio server. Tap on the audio stream you want to listen to.
  • \n
\n\n

There is some concern about whether Bluetooth will be functional in the main stage areas, due to the number of individuals attempting to use Bluetooth audio simultaneously. We recommend using wired headphones or earbuds if you have them available.

\n\n

Listen WIFI Audio Channels

\n\n

The following channels are currently available, only if you are connected to the DEF CON Wi-Fi:

\n\n\n\'',0,3586,'4fc1a86d0cf10696132c0e6eb027624d'),('\'DCTV\'','\'

DCTV streams the main stages/tracks from DEF CON to Twitch; you\'re welcome to watch those streams from anywhere. If you\'re on-site, please use cellular when watching video streams, if possible.

\n\n
    \n
  • Main Track 1: https://www.twitch.tv/defcon_dctv_one
  • \n
  • Main Track 2: https://www.twitch.tv/defcon_dctv_two
  • \n
  • Main Track 3: https://www.twitch.tv/defcon_dctv_three
  • \n
  • Main Track 4: https://www.twitch.tv/defcon_dctv_four
  • \n
  • Main Track 5: https://www.twitch.tv/defcon_dctv_five
  • \n
  • Policy Room: https://www.twitch.tv/defcon_dctv_six
  • \n
\n\'',0,3587,'3c80afea1747b01a0c317d700ee03bbb'),('\'Live Captions\'','\'

Live captions are available on StreamText for the duration of the event. Captions will populate from the moment you open the webpage during a live event, but will not show historical data. Please note if you refresh the webpage, it will erase the captions as if you\'ve just joined. Captions are available on site in each track as well. Should you have any questions or concerns, please contact any Speaker Ops goon.

\n\n\n\'',0,3588,'488de66c1e9c33825c67d7549f8eaee3'); /*!40000 ALTER TABLE `documents` ENABLE KEYS */; UNLOCK TABLES; -- -- Table structure for table `events` -- DROP TABLE IF EXISTS `events`; /*!40101 SET @saved_cs_client = @@character_set_client */; /*!50503 SET character_set_client = utf8mb4 */; CREATE TABLE `events` ( `day` varchar(16) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `hour` varchar(2) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `starttime` varchar(6) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `endtime` varchar(6) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `continuation` char(1) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `village` varchar(128) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `track` varchar(90) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `title` varchar(512) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `speaker` varchar(256) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `hash` varchar(128) CHARACTER SET utf8mb3 COLLATE utf8mb3_unicode_ci NOT NULL, `desc` text CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci NOT NULL, `modflag` tinyint DEFAULT NULL, `autoincre` int NOT NULL AUTO_INCREMENT, PRIMARY KEY (`autoincre`), KEY `title` (`title`(255)), KEY `hash` (`hash`) ) ENGINE=InnoDB AUTO_INCREMENT=1298495 DEFAULT CHARSET=utf8mb3 COLLATE=utf8mb3_unicode_ci; /*!40101 SET character_set_client = @saved_cs_client */; -- -- Dumping data for table `events` -- LOCK TABLES `events` WRITE; /*!40000 ALTER TABLE `events` DISABLE KEYS */; INSERT INTO `events` VALUES ('2_Friday','10','10:00','10:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Welcome to DEF CON 34!\'','\'Jeff \"The Dark Tangent\" Moss\'','DEF CON Talks_bb0df21f8fcdd6023fc4ac7d86f37cdf','\'Title: Welcome to DEF CON 34!
\nTags: DEF CON Official Talk | DEF CON Communications
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Jeff \"The Dark Tangent\" Moss
\n

Mr. Moss is an internet security expert and is the founder of both the Black Hat Briefings and DEF CON Hacking conferences.

\n\n\n\'',NULL,1293330),('1_Thursday','06','06:00','07:59','N','Social Gatherings/Events','LVCCW Level 1 North Entrance','\'Defcon.run\'','\'\'','Social Gatherings/Events_ad46c5985a311e6dbb4735ba4107317e','\'Title: Defcon.run
\nTags: Event
\nWhen: Thursday, Aug 6, 06:00 - 07:59 PDT
\nWhere: LVCCW Level 1 North Entrance - Map
\n
\nDescription:
\n

Defcon.run, formerly the DEF CON 4x5K, is a community-driven tradition where hackers gather for morning runs and rucks across Las Vegas. Participants can choose from various routes, from 5Ks to longer distances.

\n\n

For DEF CON 34, meet at \"The Spot\" near the North Entrance of the Las Vegas Convention Center West Hall. Activities start at 06:00, Thursday through Sunday; arrive early for safety briefings and community hype.

\n\n

Whether you are an experienced runner or a newcomer, visit defcon.run to sign up and connect with the community.

\n\nLinks:
    Website - https://defcon.run
\n\'',NULL,1293331),('1_Thursday','07','06:00','07:59','Y','Social Gatherings/Events','LVCCW Level 1 North Entrance','\'Defcon.run\'','\'\'','Social Gatherings/Events_ad46c5985a311e6dbb4735ba4107317e','\'\'',NULL,1293332),('4_Sunday','06','06:00','07:59','N','Social Gatherings/Events','LVCCW Level 1 North Entrance','\'Defcon.run\'','\'\'','Social Gatherings/Events_984d8b0c4974e284beb52bc9cf2b9438','\'Title: Defcon.run
\nTags: Event
\nWhen: Sunday, Aug 9, 06:00 - 07:59 PDT
\nWhere: LVCCW Level 1 North Entrance - Map
\n
\nDescription:
\n

Defcon.run, formerly the DEF CON 4x5K, is a community-driven tradition where hackers gather for morning runs and rucks across Las Vegas. Participants can choose from various routes, from 5Ks to longer distances.

\n\n

For DEF CON 34, meet at \"The Spot\" near the North Entrance of the Las Vegas Convention Center West Hall. Activities start at 06:00, Thursday through Sunday; arrive early for safety briefings and community hype.

\n\n

Whether you are an experienced runner or a newcomer, visit defcon.run to sign up and connect with the community.

\n\nLinks:
    Website - https://defcon.run
\n\'',NULL,1293333),('4_Sunday','07','06:00','07:59','Y','Social Gatherings/Events','LVCCW Level 1 North Entrance','\'Defcon.run\'','\'\'','Social Gatherings/Events_984d8b0c4974e284beb52bc9cf2b9438','\'\'',NULL,1293334),('3_Saturday','06','06:00','07:59','N','Social Gatherings/Events','LVCCW Level 1 North Entrance','\'Defcon.run\'','\'\'','Social Gatherings/Events_dbfbbfca88f2cdbcf66c7aebe1c3555b','\'Title: Defcon.run
\nTags: Event
\nWhen: Saturday, Aug 8, 06:00 - 07:59 PDT
\nWhere: LVCCW Level 1 North Entrance - Map
\n
\nDescription:
\n

Defcon.run, formerly the DEF CON 4x5K, is a community-driven tradition where hackers gather for morning runs and rucks across Las Vegas. Participants can choose from various routes, from 5Ks to longer distances.

\n\n

For DEF CON 34, meet at \"The Spot\" near the North Entrance of the Las Vegas Convention Center West Hall. Activities start at 06:00, Thursday through Sunday; arrive early for safety briefings and community hype.

\n\n

Whether you are an experienced runner or a newcomer, visit defcon.run to sign up and connect with the community.

\n\nLinks:
    Website - https://defcon.run
\n\'',NULL,1293335),('3_Saturday','07','06:00','07:59','Y','Social Gatherings/Events','LVCCW Level 1 North Entrance','\'Defcon.run\'','\'\'','Social Gatherings/Events_dbfbbfca88f2cdbcf66c7aebe1c3555b','\'\'',NULL,1293336),('2_Friday','06','06:00','07:59','N','Social Gatherings/Events','LVCCW Level 1 North Entrance','\'Defcon.run\'','\'\'','Social Gatherings/Events_aca0a920e8d5a95ad80ceef3b1729b30','\'Title: Defcon.run
\nTags: Event
\nWhen: Friday, Aug 7, 06:00 - 07:59 PDT
\nWhere: LVCCW Level 1 North Entrance - Map
\n
\nDescription:
\n

Defcon.run, formerly the DEF CON 4x5K, is a community-driven tradition where hackers gather for morning runs and rucks across Las Vegas. Participants can choose from various routes, from 5Ks to longer distances.

\n\n

For DEF CON 34, meet at \"The Spot\" near the North Entrance of the Las Vegas Convention Center West Hall. Activities start at 06:00, Thursday through Sunday; arrive early for safety briefings and community hype.

\n\n

Whether you are an experienced runner or a newcomer, visit defcon.run to sign up and connect with the community.

\n\nLinks:
    Website - https://defcon.run
\n\'',NULL,1293337),('2_Friday','07','06:00','07:59','Y','Social Gatherings/Events','LVCCW Level 1 North Entrance','\'Defcon.run\'','\'\'','Social Gatherings/Events_aca0a920e8d5a95ad80ceef3b1729b30','\'\'',NULL,1293338),('1_Thursday','15','15:00','20:59','N','Social Gatherings/Events','Other / See Description','\'Toxic BBQ\'','\'\'','Social Gatherings/Events_7a65a062d08a67b8c505e640acda2a83','\'Title: Toxic BBQ
\nTags: Event
\nWhen: Thursday, Aug 6, 15:00 - 20:59 PDT
\nWhere: Other / See Description
\n
\nDescription:
\n

Join the humans of Vegas at the unofficial opener of DEF CON. This Thursday Meat-Up is in the shade of Sunset Park, a quick ride from the LVCC. We stock the larder with burgers, dogs, and fixin’s. We rely on you for everything else: sides, drinks, volunteering, and donations.

\n\n

With over 50 sq ft of heat, we have plenty of room on the grill for your personal creations. Contribute food and drinks, staff the grill, join supply runs, or donate to help cover cost. Everything left goes to the EFF. Be a part of what makes this cookout something to remember year after year. The only question is: What are you bringing to Toxic BBQ?

\n\n

Check out toxicbbq.org , find a flyer at an NFO Node, and watch for #ToxicBBQ on the socials for the latest news.

\n\n

Sunset Park, Foxtail Pavilion (Lat: 36.0636, Long: -115.1178)

\n\nLinks:
    Google Maps - https://maps.app.goo.gl/AWadXHTkPYM3p7hn6
\n    Website - https://toxicbbq.org
\n\'',NULL,1293339),('1_Thursday','16','15:00','20:59','Y','Social Gatherings/Events','Other / See Description','\'Toxic BBQ\'','\'\'','Social Gatherings/Events_7a65a062d08a67b8c505e640acda2a83','\'\'',NULL,1293340),('1_Thursday','17','15:00','20:59','Y','Social Gatherings/Events','Other / See Description','\'Toxic BBQ\'','\'\'','Social Gatherings/Events_7a65a062d08a67b8c505e640acda2a83','\'\'',NULL,1293341),('1_Thursday','18','15:00','20:59','Y','Social Gatherings/Events','Other / See Description','\'Toxic BBQ\'','\'\'','Social Gatherings/Events_7a65a062d08a67b8c505e640acda2a83','\'\'',NULL,1293342),('1_Thursday','19','15:00','20:59','Y','Social Gatherings/Events','Other / See Description','\'Toxic BBQ\'','\'\'','Social Gatherings/Events_7a65a062d08a67b8c505e640acda2a83','\'\'',NULL,1293343),('1_Thursday','20','15:00','20:59','Y','Social Gatherings/Events','Other / See Description','\'Toxic BBQ\'','\'\'','Social Gatherings/Events_7a65a062d08a67b8c505e640acda2a83','\'\'',NULL,1293344),('0_Wednesday','11','11:00','17:15','N','Social Gatherings/Events','Other / See Description','\'The Unofficial DEF CON Shoot\'','\'\'','Social Gatherings/Events_36dbf05a27d57f843ad364ae43e2111a','\'Title: The Unofficial DEF CON Shoot
\nTags: Event
\nWhen: Wednesday, Aug 5, 11:00 - 17:15 PDT
\nWhere: Other / See Description
\n
\nDescription:
\n

The Unofficial DEF CON Shoot is a public event that happens just prior to the DEF CON hacker conference in Las Vegas, Nevada. It is an opportunity to see and shoot some of the guns belonging to your friends while taking pride in showing and firing your own steel, as well, in a relaxed and welcoming atmosphere. We choose a spot, then we rent tables, canopies, and bring all the necessary safety equipment and amenities. All you need to bring yourself and (optionally) your firearms. New shooters and veterans both attend regularly. You can attend with your firearms, of course, but folk without guns of their own in Vegas may have the opportunity to try gear from others in attendance.

\n\n

Pro Gun Vegas - 12801 Old US 95 Boulder City, NV 89005

\n\nLinks:
    Website - https://dcshoot.org
\n    Google Maps - https://maps.app.goo.gl/GCpWr55GjQajASA99
\n\'',NULL,1293345),('0_Wednesday','12','11:00','17:15','Y','Social Gatherings/Events','Other / See Description','\'The Unofficial DEF CON Shoot\'','\'\'','Social Gatherings/Events_36dbf05a27d57f843ad364ae43e2111a','\'\'',NULL,1293346),('0_Wednesday','13','11:00','17:15','Y','Social Gatherings/Events','Other / See Description','\'The Unofficial DEF CON Shoot\'','\'\'','Social Gatherings/Events_36dbf05a27d57f843ad364ae43e2111a','\'\'',NULL,1293347),('0_Wednesday','14','11:00','17:15','Y','Social Gatherings/Events','Other / See Description','\'The Unofficial DEF CON Shoot\'','\'\'','Social Gatherings/Events_36dbf05a27d57f843ad364ae43e2111a','\'\'',NULL,1293348),('0_Wednesday','15','11:00','17:15','Y','Social Gatherings/Events','Other / See Description','\'The Unofficial DEF CON Shoot\'','\'\'','Social Gatherings/Events_36dbf05a27d57f843ad364ae43e2111a','\'\'',NULL,1293349),('0_Wednesday','16','11:00','17:15','Y','Social Gatherings/Events','Other / See Description','\'The Unofficial DEF CON Shoot\'','\'\'','Social Gatherings/Events_36dbf05a27d57f843ad364ae43e2111a','\'\'',NULL,1293350),('0_Wednesday','17','11:00','17:15','Y','Social Gatherings/Events','Other / See Description','\'The Unofficial DEF CON Shoot\'','\'\'','Social Gatherings/Events_36dbf05a27d57f843ad364ae43e2111a','\'\'',NULL,1293351),('2_Friday','22','22:00','00:59','N','Social Gatherings/Events','LVCCW Level 2 W222 (Workshops)','\'Slopcon\'','\'\'','Social Gatherings/Events_8bc84b9ce43061b3416f5601556e1f02','\'Title: Slopcon
\nTags: Event
\nWhen: Friday, Aug 7, 22:00 - 00:59 PDT
\nWhere: LVCCW Level 2 W222 (Workshops) - Map
\n
\nDescription:
\n

In an era where \"innovation\" is just a polite word for scraping the bottom of the LLM barrel, we invite you to embrace the inevitable heat death of original thought at Slopcon. Why bother with pesky human intellect when we can automate the entire conference lifecycle, from hallucinated CFP submissions to slide decks that make absolutely no sense? It’s a high-stakes experiment in synthetic absurdity where the only thing more artificial than the intelligence is the confidence of the \"meatbag\" presenters tasked with delivering this digital dross. Join us for a celebratory descent into the uncanny valley, where we’ll crown the sloppiest generative disasters and toast to the fact that, for now, at least the audience is still real.

\n\n

So, if you’re actually itching to subject the world to more of this or just have a masochistic need for further details, head over to slopcon.org and fulfill your destiny.

\n\nLinks:
    Website - https://slopcon.org
\n    Bluesky (@slopcon@bsky.social) - https://bsky.app/profile/slopcon.sky.social
\n\'',NULL,1293352),('2_Friday','20','20:00','23:59','N','Social Gatherings/Events','LVCCW Level 2 W225 (Workshops)','\'Movie Night\'','\'\'','Social Gatherings/Events_e24bd6237294a8f346b6da679988e2f3','\'Title: Movie Night
\nTags: Event
\nWhen: Friday, Aug 7, 20:00 - 23:59 PDT
\nWhere: LVCCW Level 2 W225 (Workshops) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293353),('2_Friday','21','20:00','23:59','Y','Social Gatherings/Events','LVCCW Level 2 W225 (Workshops)','\'Movie Night\'','\'\'','Social Gatherings/Events_e24bd6237294a8f346b6da679988e2f3','\'\'',NULL,1293354),('2_Friday','22','20:00','23:59','Y','Social Gatherings/Events','LVCCW Level 2 W225 (Workshops)','\'Movie Night\'','\'\'','Social Gatherings/Events_e24bd6237294a8f346b6da679988e2f3','\'\'',NULL,1293355),('2_Friday','23','20:00','23:59','Y','Social Gatherings/Events','LVCCW Level 2 W225 (Workshops)','\'Movie Night\'','\'\'','Social Gatherings/Events_e24bd6237294a8f346b6da679988e2f3','\'\'',NULL,1293356),('3_Saturday','20','20:00','23:59','N','Social Gatherings/Events','LVCCW Level 2 W225 (Workshops)','\'Movie Night\'','\'\'','Social Gatherings/Events_217ace16ecfa81cf201aed61964db5ed','\'Title: Movie Night
\nTags: Event
\nWhen: Saturday, Aug 8, 20:00 - 23:59 PDT
\nWhere: LVCCW Level 2 W225 (Workshops) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293357),('3_Saturday','21','20:00','23:59','Y','Social Gatherings/Events','LVCCW Level 2 W225 (Workshops)','\'Movie Night\'','\'\'','Social Gatherings/Events_217ace16ecfa81cf201aed61964db5ed','\'\'',NULL,1293358),('3_Saturday','22','20:00','23:59','Y','Social Gatherings/Events','LVCCW Level 2 W225 (Workshops)','\'Movie Night\'','\'\'','Social Gatherings/Events_217ace16ecfa81cf201aed61964db5ed','\'\'',NULL,1293359),('3_Saturday','23','20:00','23:59','Y','Social Gatherings/Events','LVCCW Level 2 W225 (Workshops)','\'Movie Night\'','\'\'','Social Gatherings/Events_217ace16ecfa81cf201aed61964db5ed','\'\'',NULL,1293360),('1_Thursday','10','10:00','16:59','N','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Ham In A Day Class\'','\'\'','Social Gatherings/Events_0b8a668186aa87c8ac00598f4e67efe8','\'Title: Ham In A Day Class
\nTags: Event | Ham Radio Village
\nWhen: Thursday, Aug 6, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 3 W314 (Ham Radio Meeting) - Map
\n
\nDescription:
\n

The HRV Ham In A Day class returns again for its fourth year, taught again by Dan Romencheck, KB6NU, author of the No-Nonsense Study Guides for the amateur radio license exams.

\n\n

Always been interested in getting your ham license but never had the time to study? Now\'s your chance! The Ham Radio Village is offering a one-day class where you can learn all the required knowledge to pass the exam.

\n\n

Topics include:\n- Electrical Principles\n- Electronic principles and components\n- Radio and electromagnetic wave properties\n- Antennas and Feedlines\n- Amateur Radio Signals\n- Safety\n- Station Setup and Operation\n-Operating Procedures \n- Rules and Regulations

\n\n

The class will run from 10 A.M. to 5 P.M. A lunch break will be provided.

\n\n

Best of all, this class is completely free, thanks to a grant from the Amateur Radio Digital Communications.

\n\n

Last year, we sold out of capacity and had to turn folks away. We highly recommend placing a deposit to reserve your seat. The deposit will be refunded upon attendance of the class. Register by following the attached link.

\n\nLinks:
    Website - https://hamvillage.org
\n    Registration - https://www.zeffy.com/en-US/ticketing/ham-in-a-day-class-at-def-con--34
\n    Mastodon (@HamRadioVillage@defcon.social) - https://defcon.social/@HamRadioVillage
\n\'',NULL,1293361),('1_Thursday','11','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Ham In A Day Class\'','\'\'','Social Gatherings/Events_0b8a668186aa87c8ac00598f4e67efe8','\'\'',NULL,1293362),('1_Thursday','12','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Ham In A Day Class\'','\'\'','Social Gatherings/Events_0b8a668186aa87c8ac00598f4e67efe8','\'\'',NULL,1293363),('1_Thursday','13','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Ham In A Day Class\'','\'\'','Social Gatherings/Events_0b8a668186aa87c8ac00598f4e67efe8','\'\'',NULL,1293364),('1_Thursday','14','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Ham In A Day Class\'','\'\'','Social Gatherings/Events_0b8a668186aa87c8ac00598f4e67efe8','\'\'',NULL,1293365),('1_Thursday','15','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Ham In A Day Class\'','\'\'','Social Gatherings/Events_0b8a668186aa87c8ac00598f4e67efe8','\'\'',NULL,1293366),('1_Thursday','16','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Ham In A Day Class\'','\'\'','Social Gatherings/Events_0b8a668186aa87c8ac00598f4e67efe8','\'\'',NULL,1293367),('2_Friday','13','13:00','15:59','N','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_09c9b3400de794d43b63a9cd9648dd7a','\'Title: Free Ham Radio License Exams
\nTags: Event | Ham Radio Village
\nWhen: Friday, Aug 7, 13:00 - 15:59 PDT
\nWhere: LVCCW Level 3 W314 (Ham Radio Meeting) - Map
\n
\nDescription:
\n

Free ham radio exams return to DEF CON 34! Partake in this hacker “rite of passage” by getting your license at DEF CON, presented by the Ham Radio Village.

\n\n

While anyone is able to listen in to amateur/ham radio transmissions, only those who have an amateur radio license are able to fully partake in the “oldest hacker hobby”. With your license, you’ll be authorized by the FCC to transmit up to 1,500W on designated frequencies, build/modify radios & antennas, and even administer your own exams! Additionally, having your ham radio license can improve your resume as it is a well-recognized proof of technical and regulatory knowledge when it comes to all things radio.

\n\n

About The Exam

\n\n

In the US there are 3 current levels of amateur radio license - Technician, General, and Amateur Extra. You can progress through the levels by taking a series of multiple-choice exams showing increasing breadth of knowledge. Most folks at DEF CON looking to become a ham take just the technician exam.

\n\n

The technician exam is a 35 question, multiple choice exam. Questions come from from a public question pool of 400 questions. Because of that, the most popular way folks at DEF CON prepare is by reading through all 400 questions before the exam, and learning hands on once you get licensed. Many study resources exist - most people recommend ham.study.

\n\n

Signing Up

\n\n

Who may register for this testing session:

\n\n
    \n
  • Anyone with an interest in obtaining a new Amateur Radio license or upgrading their existing licenses.
  • \n
  • You may take multiple elements in a single appointment; we just ask that you have studied and are ready to pass.
  • \n
\n\n

Fees

\n\n
    \n
  • All license examinations administered by the Laurel VEC are free to all
  • \n
  • After passing, Laurel VEC will submit your application to the FCC. On acceptance you will receive an email from the FCC directly with instructions to pay the $35 application fee.
  • \n
\n\n

Questions

\n\n

If you have any questions leading up to DEF CON, come visit us on the Ham Radio Village Discord server (discord.gg/hrv) and let us know what questions you have. During the conference, come visit the Ham Radio Village to learn all things ham radio, including the studying, testing, and licensing process.

\n\nLinks:
    Registration - https://ham.study/sessions/69aa27ed3f69ba72bdeb3a1c/1
\n    Mastodon (@HamRadioVillage@defcon.social) - https://defcon.social/@HamRadioVillage
\n    Website - https://hamvillage.org
\n\'',NULL,1293368),('2_Friday','14','13:00','15:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_09c9b3400de794d43b63a9cd9648dd7a','\'\'',NULL,1293369),('2_Friday','15','13:00','15:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_09c9b3400de794d43b63a9cd9648dd7a','\'\'',NULL,1293370),('3_Saturday','11','11:00','16:59','N','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_1f213189c8028dfea8b4d943468c4a94','\'Title: Free Ham Radio License Exams
\nTags: Event | Ham Radio Village
\nWhen: Saturday, Aug 8, 11:00 - 16:59 PDT
\nWhere: LVCCW Level 3 W314 (Ham Radio Meeting) - Map
\n
\nDescription:
\n

Free ham radio exams return to DEF CON 34! Partake in this hacker “rite of passage” by getting your license at DEF CON, presented by the Ham Radio Village.

\n\n

While anyone is able to listen in to amateur/ham radio transmissions, only those who have an amateur radio license are able to fully partake in the “oldest hacker hobby”. With your license, you’ll be authorized by the FCC to transmit up to 1,500W on designated frequencies, build/modify radios & antennas, and even administer your own exams! Additionally, having your ham radio license can improve your resume as it is a well-recognized proof of technical and regulatory knowledge when it comes to all things radio.

\n\n

About The Exam

\n\n

In the US there are 3 current levels of amateur radio license - Technician, General, and Amateur Extra. You can progress through the levels by taking a series of multiple-choice exams showing increasing breadth of knowledge. Most folks at DEF CON looking to become a ham take just the technician exam.

\n\n

The technician exam is a 35 question, multiple choice exam. Questions come from from a public question pool of 400 questions. Because of that, the most popular way folks at DEF CON prepare is by reading through all 400 questions before the exam, and learning hands on once you get licensed. Many study resources exist - most people recommend ham.study.

\n\n

Signing Up

\n\n

Who may register for this testing session:

\n\n
    \n
  • Anyone with an interest in obtaining a new Amateur Radio license or upgrading their existing licenses.
  • \n
  • You may take multiple elements in a single appointment; we just ask that you have studied and are ready to pass.
  • \n
\n\n

Fees

\n\n
    \n
  • All license examinations administered by the Laurel VEC are free to all
  • \n
  • After passing, Laurel VEC will submit your application to the FCC. On acceptance you will receive an email from the FCC directly with instructions to pay the $35 application fee.
  • \n
\n\n

Questions

\n\n

If you have any questions leading up to DEF CON, come visit us on the Ham Radio Village Discord server (discord.gg/hrv) and let us know what questions you have. During the conference, come visit the Ham Radio Village to learn all things ham radio, including the studying, testing, and licensing process.

\n\nLinks:
    Registration - https://ham.study/sessions/69aa27ed3f69ba72bdeb3a1c/1
\n    Mastodon (@HamRadioVillage@defcon.social) - https://defcon.social/@HamRadioVillage
\n    Website - https://hamvillage.org
\n\'',NULL,1293371),('3_Saturday','12','11:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_1f213189c8028dfea8b4d943468c4a94','\'\'',NULL,1293372),('3_Saturday','13','11:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_1f213189c8028dfea8b4d943468c4a94','\'\'',NULL,1293373),('3_Saturday','14','11:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_1f213189c8028dfea8b4d943468c4a94','\'\'',NULL,1293374),('3_Saturday','15','11:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_1f213189c8028dfea8b4d943468c4a94','\'\'',NULL,1293375),('3_Saturday','16','11:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_1f213189c8028dfea8b4d943468c4a94','\'\'',NULL,1293376),('4_Sunday','11','11:00','12:59','N','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_91c9fb48f66b2a9354fd82892e02801f','\'Title: Free Ham Radio License Exams
\nTags: Event | Ham Radio Village
\nWhen: Sunday, Aug 9, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W314 (Ham Radio Meeting) - Map
\n
\nDescription:
\n

Free ham radio exams return to DEF CON 34! Partake in this hacker “rite of passage” by getting your license at DEF CON, presented by the Ham Radio Village.

\n\n

While anyone is able to listen in to amateur/ham radio transmissions, only those who have an amateur radio license are able to fully partake in the “oldest hacker hobby”. With your license, you’ll be authorized by the FCC to transmit up to 1,500W on designated frequencies, build/modify radios & antennas, and even administer your own exams! Additionally, having your ham radio license can improve your resume as it is a well-recognized proof of technical and regulatory knowledge when it comes to all things radio.

\n\n

About The Exam

\n\n

In the US there are 3 current levels of amateur radio license - Technician, General, and Amateur Extra. You can progress through the levels by taking a series of multiple-choice exams showing increasing breadth of knowledge. Most folks at DEF CON looking to become a ham take just the technician exam.

\n\n

The technician exam is a 35 question, multiple choice exam. Questions come from from a public question pool of 400 questions. Because of that, the most popular way folks at DEF CON prepare is by reading through all 400 questions before the exam, and learning hands on once you get licensed. Many study resources exist - most people recommend ham.study.

\n\n

Signing Up

\n\n

Who may register for this testing session:

\n\n
    \n
  • Anyone with an interest in obtaining a new Amateur Radio license or upgrading their existing licenses.
  • \n
  • You may take multiple elements in a single appointment; we just ask that you have studied and are ready to pass.
  • \n
\n\n

Fees

\n\n
    \n
  • All license examinations administered by the Laurel VEC are free to all
  • \n
  • After passing, Laurel VEC will submit your application to the FCC. On acceptance you will receive an email from the FCC directly with instructions to pay the $35 application fee.
  • \n
\n\n

Questions

\n\n

If you have any questions leading up to DEF CON, come visit us on the Ham Radio Village Discord server (discord.gg/hrv) and let us know what questions you have. During the conference, come visit the Ham Radio Village to learn all things ham radio, including the studying, testing, and licensing process.

\n\nLinks:
    Registration - https://ham.study/sessions/69aa27ed3f69ba72bdeb3a1c/1
\n    Mastodon (@HamRadioVillage@defcon.social) - https://defcon.social/@HamRadioVillage
\n    Website - https://hamvillage.org
\n\'',NULL,1293377),('4_Sunday','12','11:00','12:59','Y','Social Gatherings/Events','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Free Ham Radio License Exams\'','\'\'','Social Gatherings/Events_91c9fb48f66b2a9354fd82892e02801f','\'\'',NULL,1293378),('1_Thursday','19','19:00','21:59','N','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'DC702 Meetup\'','\'\'','Social Gatherings/Events_143ea6cf2b655427a78700dd60d90133','\'Title: DC702 Meetup
\nTags: Meetup
\nWhen: Thursday, Aug 6, 19:00 - 21:59 PDT
\nWhere: LVCCW Level 3 W327 (Misc Meeting Room) - Map
\n
\nDescription:
\n

Join the local DC702 Group in this year\'s official DEF CON Meetup! The meetup will be casual and include typical meetup activities (e.g., socializing, \"challenges,\" lockpicking, music, etc.) and maybe a few little surprises.

\n\nLinks:
    Website - https://dc702.space/stuff/dc34-meetup
\n\'',NULL,1293379),('1_Thursday','20','19:00','21:59','Y','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'DC702 Meetup\'','\'\'','Social Gatherings/Events_143ea6cf2b655427a78700dd60d90133','\'\'',NULL,1293380),('1_Thursday','21','19:00','21:59','Y','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'DC702 Meetup\'','\'\'','Social Gatherings/Events_143ea6cf2b655427a78700dd60d90133','\'\'',NULL,1293381),('2_Friday','20','20:00','23:30','N','Social Gatherings/Events','LVCCW Level 2 W208-209 (Diana Initiative)','\'Women, gender non-conforming and non-binary meetup with The Diana Initiative\'','\'\'','Social Gatherings/Events_2aafc2af37e55a5d8024f4d563bfdac6','\'Title: Women, gender non-conforming and non-binary meetup with The Diana Initiative
\nTags: Meetup | The Diana Initiative
\nWhen: Friday, Aug 7, 20:00 - 23:30 PDT
\nWhere: LVCCW Level 2 W208-209 (Diana Initiative) - Map
\n
\nDescription:
\n

We\'d love to get all the gender non conforming, non-binary and women together to hang out and make friends! DEF CON is better with friends. Stop in for a bit, or the whole time.

\n\nLinks:
    Mastodon (@DianaInitiative@defcon.social) - https://defcon.social/@DianaInitiative
\n    Website - https://dianainitiative.org
\n\'',NULL,1293382),('2_Friday','21','20:00','23:30','Y','Social Gatherings/Events','LVCCW Level 2 W208-209 (Diana Initiative)','\'Women, gender non-conforming and non-binary meetup with The Diana Initiative\'','\'\'','Social Gatherings/Events_2aafc2af37e55a5d8024f4d563bfdac6','\'\'',NULL,1293383),('2_Friday','22','20:00','23:30','Y','Social Gatherings/Events','LVCCW Level 2 W208-209 (Diana Initiative)','\'Women, gender non-conforming and non-binary meetup with The Diana Initiative\'','\'\'','Social Gatherings/Events_2aafc2af37e55a5d8024f4d563bfdac6','\'\'',NULL,1293384),('2_Friday','23','20:00','23:30','Y','Social Gatherings/Events','LVCCW Level 2 W208-209 (Diana Initiative)','\'Women, gender non-conforming and non-binary meetup with The Diana Initiative\'','\'\'','Social Gatherings/Events_2aafc2af37e55a5d8024f4d563bfdac6','\'\'',NULL,1293385),('2_Friday','19','19:00','21:59','N','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Lawyers Meet\'','\'\'','Social Gatherings/Events_d902847fe2f9a3798d9cb619b9c93717','\'Title: Lawyers Meet
\nTags: Meetup
\nWhen: Friday, Aug 7, 19:00 - 21:59 PDT
\nWhere: LVCCW Level 3 W301 (Misc Meeting Room) - Map
\n
\nDescription:
\n

If you\'re a lawyer (recently unfrozen or otherwise), a judge or a law student please make a note to join Jeff McNamara for a friendly get-together, drinks, and conversation.

\n\n\'',NULL,1293386),('2_Friday','20','19:00','21:59','Y','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Lawyers Meet\'','\'\'','Social Gatherings/Events_d902847fe2f9a3798d9cb619b9c93717','\'\'',NULL,1293387),('2_Friday','21','19:00','21:59','Y','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Lawyers Meet\'','\'\'','Social Gatherings/Events_d902847fe2f9a3798d9cb619b9c93717','\'\'',NULL,1293388),('3_Saturday','17','17:00','17:59','N','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Friends of Bill W\'','\'\'','Social Gatherings/Events_fd8b1ec81fabf84bc75b1fcc66051072','\'Title: Friends of Bill W
\nTags: Meetup
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W301 (Misc Meeting Room) - Map
\n
\nDescription:
\n

We know DEF CON and Vegas can be a lot. If you\'re a friend of Bill W who\'s looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.

\n\n\'',NULL,1293389),('3_Saturday','12','12:00','12:59','N','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Friends of Bill W\'','\'\'','Social Gatherings/Events_ccc73a3c1c2daec2ea85f30a13988ae3','\'Title: Friends of Bill W
\nTags: Meetup
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W301 (Misc Meeting Room) - Map
\n
\nDescription:
\n

We know DEF CON and Vegas can be a lot. If you\'re a friend of Bill W who\'s looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.

\n\n\'',NULL,1293390),('2_Friday','17','17:00','17:59','N','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Friends of Bill W\'','\'\'','Social Gatherings/Events_c8d794883d6cc812fe3ae7db1c9cd785','\'Title: Friends of Bill W
\nTags: Meetup
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W301 (Misc Meeting Room) - Map
\n
\nDescription:
\n

We know DEF CON and Vegas can be a lot. If you\'re a friend of Bill W who\'s looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.

\n\n\'',NULL,1293391),('1_Thursday','12','12:00','12:59','N','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Friends of Bill W\'','\'\'','Social Gatherings/Events_1f22a1735086998b482e301210d815d3','\'Title: Friends of Bill W
\nTags: Meetup
\nWhen: Thursday, Aug 6, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W301 (Misc Meeting Room) - Map
\n
\nDescription:
\n

We know DEF CON and Vegas can be a lot. If you\'re a friend of Bill W who\'s looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.

\n\n\'',NULL,1293392),('4_Sunday','12','12:00','12:59','N','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Friends of Bill W\'','\'\'','Social Gatherings/Events_9b7c80bc142a1ce1bd5439c017213955','\'Title: Friends of Bill W
\nTags: Meetup
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W301 (Misc Meeting Room) - Map
\n
\nDescription:
\n

We know DEF CON and Vegas can be a lot. If you\'re a friend of Bill W who\'s looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.

\n\n\'',NULL,1293393),('1_Thursday','17','17:00','17:59','N','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Friends of Bill W\'','\'\'','Social Gatherings/Events_a717530c5ffd398989f339fbcad7f5e1','\'Title: Friends of Bill W
\nTags: Meetup
\nWhen: Thursday, Aug 6, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W301 (Misc Meeting Room) - Map
\n
\nDescription:
\n

We know DEF CON and Vegas can be a lot. If you\'re a friend of Bill W who\'s looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.

\n\n\'',NULL,1293394),('2_Friday','12','12:00','12:59','N','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Friends of Bill W\'','\'\'','Social Gatherings/Events_9c0e5a9fffa1747d5763cb36224406a7','\'Title: Friends of Bill W
\nTags: Meetup
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W301 (Misc Meeting Room) - Map
\n
\nDescription:
\n

We know DEF CON and Vegas can be a lot. If you\'re a friend of Bill W who\'s looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday.

\n\n\'',NULL,1293395),('2_Friday','14','14:00','15:59','N','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Hacker Book Club Discussion\'','\'\'','Social Gatherings/Events_840f332e911a3fcdb8991ed7a2d94eab','\'Title: Hacker Book Club Discussion
\nTags: Meetup
\nWhen: Friday, Aug 7, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 3 W301 (Misc Meeting Room) - Map
\n
\nDescription:
\n

Community is essential and so is continual learning. Reading books and discussing books can greatly impact an individual’s access and sense of community and knowledge. This Hacker Book Club book discussion will be an accessible group aiming to build community and share out learnings, all in a quieter setting. Come join us and discuss what you’ve been reading. We also run a year round Discord to discuss books throughout the year, hackerbookclub.com. This Hacker Book Club is not locked to a region and is for those who love books and escaping to the cyperpunk, scifi worlds that inspire DEF CON and modern literature.

\n\nLinks:
    hackerbookclub.com - https://hackerbookclub.com
\n\'',NULL,1293396),('2_Friday','15','14:00','15:59','Y','Social Gatherings/Events','LVCCW Level 3 W301 (Misc Meeting Room)','\'Hacker Book Club Discussion\'','\'\'','Social Gatherings/Events_840f332e911a3fcdb8991ed7a2d94eab','\'\'',NULL,1293397),('2_Friday','16','16:00','18:59','N','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'Atlanta Metro Meetup (DC404/DC678/DC770/DC470)\'','\'\'','Social Gatherings/Events_da6b20ba16676279aceb3974a85b364d','\'Title: Atlanta Metro Meetup (DC404/DC678/DC770/DC470)
\nTags: Meetup
\nWhen: Friday, Aug 7, 16:00 - 18:59 PDT
\nWhere: LVCCW Level 3 W327 (Misc Meeting Room) - Map
\n
\nDescription:
\n

They say Atlanta is the city too busy to hate, but it also has too much traffic for its widespread hacker fam to get together in a single meetup. So instead, we\'re meeting up in the desert during DEF CON! The one time of year when intown, northern burbs, south siders, and anyone else connected to DC404\'s 30+ year legacy can catch up and share stories. Join us and meet your fellow ATL hackers!

\n\n\'',NULL,1293398),('2_Friday','17','16:00','18:59','Y','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'Atlanta Metro Meetup (DC404/DC678/DC770/DC470)\'','\'\'','Social Gatherings/Events_da6b20ba16676279aceb3974a85b364d','\'\'',NULL,1293399),('2_Friday','18','16:00','18:59','Y','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'Atlanta Metro Meetup (DC404/DC678/DC770/DC470)\'','\'\'','Social Gatherings/Events_da6b20ba16676279aceb3974a85b364d','\'\'',NULL,1293400),('3_Saturday','15','15:00','16:59','N','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'DCG New England Meetup\'','\'\'','Social Gatherings/Events_827c12192936bc6d4b1722bdfa3b7d88','\'Title: DCG New England Meetup
\nTags: Meetup
\nWhen: Saturday, Aug 8, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 3 W327 (Misc Meeting Room) - Map
\n
\nDescription:
\n

New England\'s hackers are spread across six smaller states and rarely in the same room. This is the room. DCG New England pulls the region\'s groups and unaffiliated folks together to hang out, meet other hackers in the region, talk shop, show off half-finished projects, and meet the people who keep the local scene ticking.

\n\nLinks:
    Website - https://dcgne.org
\n\'',NULL,1293401),('3_Saturday','16','15:00','16:59','Y','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'DCG New England Meetup\'','\'\'','Social Gatherings/Events_827c12192936bc6d4b1722bdfa3b7d88','\'\'',NULL,1293402),('2_Friday','16','16:00','17:59','N','Social Gatherings/Events','LVCCW Level 3 W325 (QueerCon Lounge)','\'Queercon Mixer\'','\'\'','Social Gatherings/Events_ed01db1b278bd475f303531ddeb55974','\'Title: Queercon Mixer
\nTags: Meetup | Queercon Community
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n

Come meet the largest social network of LGBTQIA+ and allied hackers at Queercon! Our mixers are designed for you to meet, network, and engage with like-minded people to a backdrop of music, dance, and refreshments.

\n\nLinks:
    Website - https://queercon.org
\n\'',NULL,1293403),('2_Friday','17','16:00','17:59','Y','Social Gatherings/Events','LVCCW Level 3 W325 (QueerCon Lounge)','\'Queercon Mixer\'','\'\'','Social Gatherings/Events_ed01db1b278bd475f303531ddeb55974','\'\'',NULL,1293404),('3_Saturday','16','16:00','17:59','N','Social Gatherings/Events','LVCCW Level 3 W325 (QueerCon Lounge)','\'Queercon Mixer\'','\'\'','Social Gatherings/Events_ff52b80be18791b6caf8214afb4338a2','\'Title: Queercon Mixer
\nTags: Meetup | Queercon Community
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n

Come meet the largest social network of LGBTQIA+ and allied hackers at Queercon! Our mixers are designed for you to meet, network, and engage with like-minded people to a backdrop of music, dance, and refreshments.

\n\nLinks:
    Website - https://queercon.org
\n\'',NULL,1293405),('3_Saturday','17','16:00','17:59','Y','Social Gatherings/Events','LVCCW Level 3 W325 (QueerCon Lounge)','\'Queercon Mixer\'','\'\'','Social Gatherings/Events_ff52b80be18791b6caf8214afb4338a2','\'\'',NULL,1293406),('1_Thursday','21','21:00','23:59','N','Social Gatherings/Events','LVCCW Level 2 W212 (Misc Meeting Room)','\'Conference Planners Meetup\'','\'\'','Social Gatherings/Events_bad24961721a476d3d7b5f8abe25fcc2','\'Title: Conference Planners Meetup
\nTags: Meetup
\nWhen: Thursday, Aug 6, 21:00 - 23:59 PDT
\nWhere: LVCCW Level 2 W212 (Misc Meeting Room) - Map
\n
\nDescription:
\n

Are you a conference planner, manager, technologist, etc.? Feel like chatting about what we do, trading contact info, or just grabbing a few drinks with colleagues? This will be a meetup for those of us involved in conference planning and management. There won\'t be any kind of schedule or agenda. Informal conversation is the name of the game.

\n\n

At least one person from the Hacker Tracker (and ConfMgr) team will be here. You\'re welcome to ask questions, leave feedback (good or bad), ask for help with some problem you\'re having, etc.

\n\n\'',NULL,1293407),('1_Thursday','22','21:00','23:59','Y','Social Gatherings/Events','LVCCW Level 2 W212 (Misc Meeting Room)','\'Conference Planners Meetup\'','\'\'','Social Gatherings/Events_bad24961721a476d3d7b5f8abe25fcc2','\'\'',NULL,1293408),('1_Thursday','23','21:00','23:59','Y','Social Gatherings/Events','LVCCW Level 2 W212 (Misc Meeting Room)','\'Conference Planners Meetup\'','\'\'','Social Gatherings/Events_bad24961721a476d3d7b5f8abe25fcc2','\'\'',NULL,1293409),('3_Saturday','21','21:00','00:59','N','Social Gatherings/Events','LVCCW Level 3 W326 (Vetcon)','\'VETCON 2026 PARTY\'','\'\'','Social Gatherings/Events_7df60199f6ed274855efb7b464081e33','\'Title: VETCON 2026 PARTY
\nTags: Party | VETCON
\nWhen: Saturday, Aug 8, 21:00 - 00:59 PDT
\nWhere: LVCCW Level 3 W326 (Vetcon) - Map
\n
\nDescription:
\n

DEF CON is renowned for bringing together some of the brightest minds in technology and security. By participating in VETCON, you have the chance to highlight the critical role veterans play in this landscape and explore how technology can support and enhance their lives.

\n\nLinks:
    Website - https://vetconactual.com
\n\'',NULL,1293410),('2_Friday','20','20:00','00:59','N','Social Gatherings/Events','LVCCW Level 2 W229, W232','\'Hacker Karaoke\'','\'\'','Social Gatherings/Events_141d329f513ec6cab54a866294c35989','\'Title: Hacker Karaoke
\nTags: Party
\nWhen: Friday, Aug 7, 20:00 - 00:59 PDT
\nWhere: LVCCW Level 2 W229, W232 - Map
\n
\nDescription:
\n

Two great things that go great together! Join the fun as your fellow hackers make their way through songs from every era and style. Everyone has a voice and this is your opportunity to show it off! Everyone is encourage to participate in a DEF CON tradition from all folks and skill levels.

\n\n\'',NULL,1293411),('3_Saturday','20','20:00','00:59','N','Social Gatherings/Events','LVCCW Level 2 W229, W232','\'Hacker Karaoke\'','\'\'','Social Gatherings/Events_a5bd9e8ca714590b61015edaa365c558','\'Title: Hacker Karaoke
\nTags: Party
\nWhen: Saturday, Aug 8, 20:00 - 00:59 PDT
\nWhere: LVCCW Level 2 W229, W232 - Map
\n
\nDescription:
\n

Two great things that go great together! Join the fun as your fellow hackers make their way through songs from every era and style. Everyone has a voice and this is your opportunity to show it off! Everyone is encourage to participate in a DEF CON tradition from all folks and skill levels.

\n\n\'',NULL,1293412),('2_Friday','21','21:00','00:59','N','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'Day of the Dead Hacker Party\'','\'\'','Social Gatherings/Events_6eb9c0f466401a2117f8c3d5edcc6545','\'Title: Day of the Dead Hacker Party
\nTags: Party
\nWhen: Friday, Aug 7, 21:00 - 00:59 PDT
\nWhere: LVCCW Level 3 W327 (Misc Meeting Room) - Map
\n
\nDescription:
\n

Join us as we celebrate the lives, legends, and lasting influence of the hackers who shaped our world. From pioneers of the underground to cultural icons of the digital frontier whose stories still echo through the system.

\n\n

Dress in Day of the Dead attire or come as a ghost of hacker culture, dead heroes, legendary coders, digital outlaws, and spirits of the machine.

\n\n

Music by CURZE$ and special guest DJs.

\n\n

Everyone is welcome to join us and celebrate the dead, the code, and the culture that refuses to die.

\n\n\'',NULL,1293413),('3_Saturday','18','18:00','19:59','N','Social Gatherings/Events','LVCCW Level 2 W212 (Misc Meeting Room)','\'+61: the Australian Embassy\'','\'\'','Social Gatherings/Events_4ef575e07d8e76c1528e61fa6c129815','\'Title: +61: the Australian Embassy
\nTags: Party
\nWhen: Saturday, Aug 8, 18:00 - 19:59 PDT
\nWhere: LVCCW Level 2 W212 (Misc Meeting Room) - Map
\n
\nDescription:
\n

Against all odds (and possibly the better judgement of border control), the +61 Australian embassy returns.

\n\n

If you’re one of the Australians who made it into the US for DEF CON this year, swing by for a bit of hacker summer camp gossip, some socializing, and a live demonstration of what happens when Malört meets Vegemite.

\n\n

We assume nothing good.

\n\n\'',NULL,1293414),('3_Saturday','19','18:00','19:59','Y','Social Gatherings/Events','LVCCW Level 2 W212 (Misc Meeting Room)','\'+61: the Australian Embassy\'','\'\'','Social Gatherings/Events_4ef575e07d8e76c1528e61fa6c129815','\'\'',NULL,1293415),('3_Saturday','21','21:00','00:59','N','Social Gatherings/Events','LVCCW Level 2 W218 (Call Center Village)','\'Party Line (Call Center Village Party)\'','\'\'','Social Gatherings/Events_1301e708437b4a698be372260db8d79c','\'Title: Party Line (Call Center Village Party)
\nTags: Party | Call Center Village
\nWhen: Saturday, Aug 8, 21:00 - 00:59 PDT
\nWhere: LVCCW Level 2 W218 (Call Center Village) - Map
\n
\nDescription:
\n

You\'ve been placed on hold — but for once, you don\'t mind the music.

\n\n

Party Line is Call Center Village\'s telephony-themed party open to all attendees at DEF CON 34.

\n\n

A full-size telephone booth, retro telephones, dial-pad light shows, and lo-fi hold music grooves mixed with telephony-flavored party tracks.

\n\n

If you\'ve ever listened to Opus No. 1 on repeat, then this is your extension. No IVR to navigate Just pick up and dial in.

\n\n

Don\'t let the phones go unanswered. Join us at Party Line.

\n\n

Between calls, swing by our unofficial DEF CON TCG trading table — donate your extras, hunt down the ones you\'re missing, or make a deal for your favorites.

\n\n

Make sure to bring your Call Center Village flight-tags (100 Trying or 200 OK) earned from the Escalation Desk CTF to claim free drinks!

\n\nLinks:
    Website - https://callcentervillage.com/events/partyline34
\n    Mastodon (@callcentervillage@defcon.socal) - https://defcon.socal/@callcentervillage
\n\'',NULL,1293416),('3_Saturday','21','21:00','00:59','N','Social Gatherings/Events','LVCCW Level 3 W327 (Misc Meeting Room)','\'Illuminati Party\'','\'\'','Social Gatherings/Events_889043b603b7886c26e0e1d37b065a1a','\'Title: Illuminati Party
\nTags: Party
\nWhen: Saturday, Aug 8, 21:00 - 00:59 PDT
\nWhere: LVCCW Level 3 W327 (Misc Meeting Room) - Map
\n
\nDescription:
\n

It\'s time to get under the hood and rewrite the rules of engagement. If we want a future where explorers aren\'t outlaws, we have to start by taking over the room—so join us for the Illuminati Party, where our crew gathers to set the parameters for the night. Come share your passion, plot the future, and help us amplify the community.

\n\nLinks:
    Website - https://illuminatiparty.org
\n\'',NULL,1293417),('2_Friday','19','19:00','00:59','N','Social Gatherings/Events','LVCCW Level 2 W212 (Misc Meeting Room)','\'BlanketFort Con\'','\'\'','Social Gatherings/Events_63582d958370067964fec4d45f0995b0','\'Title: BlanketFort Con
\nTags: Party
\nWhen: Friday, Aug 7, 19:00 - 00:59 PDT
\nWhere: LVCCW Level 2 W212 (Misc Meeting Room) - Map
\n
\nDescription:
\nBlanketFort Con: Come for the chill vibes and diversity, stay for the Blanket Fort Building, Cool Lights, Music, and Kid Friendly \\ Safe environment. Now with less Gluten and more onesies!
\n\n\n\nLinks:
    Mastodon (@blanketfortcon@bsky.social) - https://bsky.app/profile/blanketfortcon.bsky.social
\n\'',NULL,1293418),('2_Friday','21','21:00','00:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 3 801 (Creator Stage 1,2)','\'Arcade Party\'','\'\'','Social Gatherings/Events_ba2749be4d8be86309c3060f76463373','\'Title: Arcade Party
\nTags: Party
\nWhen: Friday, Aug 7, 21:00 - 00:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1,2) - Map
\n
\nDescription:
\n

The Arcade Party is back! Come play your favorite classic arcade games while jamming out to Keith Myers DJing. Your favorite custom built 16 player LED foosball table will be ready for some competitive games. This epic party, free for DEF CON 34 attendees to enjoy and play, is hosted by the Military Cyber Professionals Association (a tech ed charity) and friends.

\n\nLinks:
    Website - https://arcadeparty.org
\n\'',NULL,1293419),('3_Saturday','21','21:00','00:59','N','Social Gatherings/Events','LVCCW Level 2 W212 (Misc Meeting Room)','\'Front Man\'s Fête: An Octopus Game Party (including Octopus Game winners and prizes)\'','\'\'','Social Gatherings/Events_d281f65c70f5ecc257249f763a653a46','\'Title: Front Man\'s Fête: An Octopus Game Party (including Octopus Game winners and prizes)
\nTags: Party | Octopus Game
\nWhen: Saturday, Aug 8, 21:00 - 00:59 PDT
\nWhere: LVCCW Level 2 W212 (Misc Meeting Room) - Map
\n
\nDescription:
\n

Front Man’s Fête: An Octopus Game Party is a curated respite from the chaos of the city, offering a sophisticated and low-key lounge experience centered on strategy and soul. Instead of high-stakes elimination, we offer the timeless rhythm of old school hip-hop and the analog competition of classic board games. This event is designed for those who seek a chill atmosphere where the vibes are smooth and the conversation is clear. Come for the nostalgia of golden-era beats and stay for a relaxed evening where the only goal is to unwind and outsmart your opponents in a sanctuary of cool.

\n\nLinks:
    Mastodon (@OctopusGame@defcon.social) - https://defcon.social/@OctopusGame
\n    Website - https://octopusgame.org
\n\'',NULL,1293420),('2_Friday','21','21:00','00:59','N','Social Gatherings/Events','LVCCW Level 3 W322-W324 (BIC Village)','\'BIC R00T ACCESS 2026\'','\'\'','Social Gatherings/Events_6f47ab15688edb38504c1368a8fab751','\'Title: BIC R00T ACCESS 2026
\nTags: Party | Blacks In Cyber Village
\nWhen: Friday, Aug 7, 21:00 - 00:59 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Black culture has always shaped the sound of resistance, innovation, and celebration—and at DEF CON, we’re bringing that history to the dance floor. Blacks In Cyber invites you to a night where cybersecurity meets the soundtrack of Black history. From the soulful roots of jazz and blues that coded messages of freedom, to the revolutionary pulse of hip-hop and electronic beats that powered digital creativity, every track tells a story.

\n\n

This party celebrates the pioneers who pushed boundaries—musically, technologically, and culturally. Expect a curated journey through decades of sound: classic grooves, Afro-futurist vibes, and modern cyber-inspired mixes that honor the past while hacking the future. Whether you’re a seasoned hacker, a first-time DEF CON attendee, or just here for the vibe, this is your space to connect, celebrate, and move.

\n\n

Come dance through the timeline. Celebrate culture, community, and code. Blacks In Cyber at DEF CON—where history, rhythm, and innovation collide.

\n\nLinks:
    Website - https://blacksincyberconf.com
\n\'',NULL,1293421),('3_Saturday','21','21:00','00:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'GOTHCON\'','\'\'','Social Gatherings/Events_de704f97ed7cfb9d284d2342401de31c','\'Title: GOTHCON
\nTags: Party
\nWhen: Saturday, Aug 8, 21:00 - 00:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Returning for their 9th year, Gothcon invites you to come dance the night away with a line-up of some of the community\'s best dark dance music DJ\'s from across the US! Dress however you would like in whatever makes you feel comfortable and happy, and all are welcome.

\n\nLinks:
    Website - https://gothcon.com
\n\'',NULL,1293422),('3_Saturday','22','22:00','00:59','N','Social Gatherings/Events','LVCCW Level 1 North Lobby','\'Kayos Klub\'','\'\'','Social Gatherings/Events_f39a1973efffe84ba4d2fa4d5907f128','\'Title: Kayos Klub
\nTags: Party
\nWhen: Saturday, Aug 8, 22:00 - 00:59 PDT
\nWhere: LVCCW Level 1 North Lobby - Map
\n
\nDescription:
\n

The Kayos Klub will be a night of music and magic for all ages. To celebrate the life of a lost loved one, we are going all out on a party that will make even the most socially awkward computer nerd want to dance <3.

\n\nLinks:
    Website - https://digitalgangster.com
\n\'',NULL,1293423),('2_Friday','22','22:00','00:59','N','Social Gatherings/Events','LVCCW Level 1 North Lobby','\'SecKC the WHOLE WIDE WORLD\'','\'\'','Social Gatherings/Events_d98edf5ac25fbbb8aff0047fc0b77618','\'Title: SecKC the WHOLE WIDE WORLD
\nTags: Party
\nWhen: Friday, Aug 7, 22:00 - 00:59 PDT
\nWhere: LVCCW Level 1 North Lobby - Map
\n
\nDescription:
\n

Following the legendary chaos of SecKC the World and SecKC the World Again, the Kansas City crew returns to DEF CON to settle the digital frontier. This year, we aren’t just hosting a party, this isn’t just another loud room with a DJ; it’s gonna be a killer getogether for the hacker family. We’re merging the independent spirit of the DEF CON with the radical community of the Midwest.

\n\nLinks:
    Mastodon (@sec_kc@bird.makeup) - https://bird.makeup/@sec_kc
\n    Website - https://seckc.org
\n\'',NULL,1293424),('1_Thursday','18','18:00','19:59','N','Social Gatherings/Events','LVCCW Level 2 W238 (DEF CON Groups)','\'Operator, Please Hold - DCG Social\'','\'\'','Social Gatherings/Events_03d93ff95efe3d28abb5a46df7373e01','\'Title: Operator, Please Hold - DCG Social
\nTags: Party | DEF CON Groups
\nWhen: Thursday, Aug 6, 18:00 - 19:59 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n

Operator, Please Hold is the official DEF CON Groups party at DEF CON 34 - a social for hackers, DCG organizers, and community builders from around the world.

\n\n

This is where DEF CON Groups converge off the mailing lists and out of Discord. Expect familiar faces, new connections, and conversations that jump from local meetups to global chaos in about five minutes. No talks. No agenda. Just hackers who actually show up for their communities, in one room, at the same time.

\n\n

Whether you run a group, help keep one alive, or are looking to plug into your local hacker scene, this is your stop. Come say hi, compare notes, and meet the humans behind the handles.

\n\n

Operator, please hold. Your people are on the line.

\n\n\'',NULL,1293425),('1_Thursday','19','18:00','19:59','Y','Social Gatherings/Events','LVCCW Level 2 W238 (DEF CON Groups)','\'Operator, Please Hold - DCG Social\'','\'\'','Social Gatherings/Events_03d93ff95efe3d28abb5a46df7373e01','\'\'',NULL,1293426),('2_Friday','19','19:00','22:59','N','Social Gatherings/Events','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village Party\'','\'\'','Social Gatherings/Events_d9ab84fe019901a0441df22fd99ef1c7','\'Title: Social Engineering Community Village Party
\nTags: Party | Social Engineering Community Village
\nWhen: Friday, Aug 7, 19:00 - 22:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Mix and mingle with the SEC crew, competitors, speakers, and fellow attendees at our community party.

\n\n

Join the Social Engineering Community for a night of connecting with fellow hackers, social engineers, researchers, and curious DEF CON attendees who share an interest in the human side of hacking. Whether you spent the weekend watching vishing calls, cheering on AI bots, competing, volunteering, or just discovering the craft for the first time, this meetup is a chance to relax, swap stories, and meet the people behind the voices, research, and chaos from the village. The exact theme will be announced soon, but the goal is simple: bring the community together, make new friends, reconnect with old ones, and celebrate another year of social engineering at DEF CON. Everyone is welcome, whether you\'re a longtime member of the community or just curious about what social engineering is all about.

\n\nLinks:
    Website - https://www.se.community/
\n\'',NULL,1293427),('2_Friday','20','19:00','22:59','Y','Social Gatherings/Events','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village Party\'','\'\'','Social Gatherings/Events_d9ab84fe019901a0441df22fd99ef1c7','\'\'',NULL,1293428),('2_Friday','21','19:00','22:59','Y','Social Gatherings/Events','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village Party\'','\'\'','Social Gatherings/Events_d9ab84fe019901a0441df22fd99ef1c7','\'\'',NULL,1293429),('2_Friday','22','19:00','22:59','Y','Social Gatherings/Events','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village Party\'','\'\'','Social Gatherings/Events_d9ab84fe019901a0441df22fd99ef1c7','\'\'',NULL,1293430),('2_Friday','06','06:00','10:59','N','Social Gatherings/Events','Other / See Description','\'15th Cycleoverride Bike Ride at DEF CON\'','\'\'','Social Gatherings/Events_3947d70249331c14e685bcfac1fc97a3','\'Title: 15th Cycleoverride Bike Ride at DEF CON
\nTags: Event
\nWhen: Friday, Aug 7, 06:00 - 10:59 PDT
\nWhere: Other / See Description
\n
\nDescription:
\n

At 6am on Friday, the @cycle_override crew will be hosting the 15th DEF CON Bikeride. We\'ll meet at a local bikeshop, get some rental bicycles, and about 7am will make the ride out to Red Rocks. It\'s about a 15 mile ride, all downhill on the return journey. So, if you are crazy enough to join us, get some water, and head over to cycleoverride.org for more info. See you at 6am Friday!

\n\nLinks:
    Website - https://cycleoverride.org
\n\'',NULL,1293431),('2_Friday','07','06:00','10:59','Y','Social Gatherings/Events','Other / See Description','\'15th Cycleoverride Bike Ride at DEF CON\'','\'\'','Social Gatherings/Events_3947d70249331c14e685bcfac1fc97a3','\'\'',NULL,1293432),('2_Friday','08','06:00','10:59','Y','Social Gatherings/Events','Other / See Description','\'15th Cycleoverride Bike Ride at DEF CON\'','\'\'','Social Gatherings/Events_3947d70249331c14e685bcfac1fc97a3','\'\'',NULL,1293433),('2_Friday','09','06:00','10:59','Y','Social Gatherings/Events','Other / See Description','\'15th Cycleoverride Bike Ride at DEF CON\'','\'\'','Social Gatherings/Events_3947d70249331c14e685bcfac1fc97a3','\'\'',NULL,1293434),('2_Friday','10','06:00','10:59','Y','Social Gatherings/Events','Other / See Description','\'15th Cycleoverride Bike Ride at DEF CON\'','\'\'','Social Gatherings/Events_3947d70249331c14e685bcfac1fc97a3','\'\'',NULL,1293435),('3_Saturday','19','19:00','20:59','N','Social Gatherings/Events','LVCCW Level 3 W316 (DC NextGen)','\'DCNextGen Party!\'','\'\'','Social Gatherings/Events_5ce33ffa455edc3ade3f6f69e3615b7e','\'Title: DCNextGen Party!
\nTags: Party | DCNextGen | | Youth
\nWhen: Saturday, Aug 8, 19:00 - 20:59 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Are you ready to rock? If so, come to the DCNextGen party where the theme is UV cyberpunk! What is there to do you might ask? We have games, music, create your own raccoon mask, glow in the dark tattoos, and so much more! There is no better place to make new friends and hang out with your fellow DCNextGen cyber warriors.

\n\n\'',NULL,1293436),('3_Saturday','20','19:00','20:59','Y','Social Gatherings/Events','LVCCW Level 3 W316 (DC NextGen)','\'DCNextGen Party!\'','\'\'','Social Gatherings/Events_5ce33ffa455edc3ade3f6f69e3615b7e','\'\'',NULL,1293437),('2_Friday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted\'','\'Sydney \"letswastetime\" Marrone\'','DEF CON Workshops_4c5c1432e0eb146bf0b73228e6c188dd','\'Title: Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W233 (Workshops) - Map
\n
\nDescription:
\n

Attendees hunt a supply chain compromise in real telemetry. Not a walkthrough - a hunt.\nA trojanized developer tool has been backdoored. The artifacts are seeded across a shared Splunk instance at layered difficulty: some obvious, some buried. Over four hours, attendees progress through the Five Levels of Agentic Hunting using the open-source Agentic Threat Hunting Framework (ATHF). Each maturity level unlocks new capabilities — structure, searchability, AI research agents, and full agentic workflows — that help them find what they couldn\'t find before.\nThe first hunt is manual. By the last module, AI agents are surfacing hypotheses, identifying coverage gaps, and pointing hunters toward artifacts they missed. The human decides what to chase. The framework remembers what they found.\nThis is not a tool demo. Attendees will make real analytical decisions, write real SPL queries, hit dead ends, and use AI agents to recover. They leave with a working ATHF workspace, documented hunts from a real investigation, and the experience of hunting with an agentic system.

\n\nSpeakerBio:  Sydney \"letswastetime\" Marrone
\n

Sydney Marrone is a threat hunter, SANS course author, co-founder of THOR Collective, author of the Agentic Threat Hunting Framework (ATHF), and co-author of the PEAK Threat Hunting Framework. She is passionate about helping defenders become better threat hunters by turning complex ideas into practical, repeatable techniques. Through open-source research, workshops, and community-driven projects, Sydney builds frameworks and resources that make hunting more structured, collaborative, and effective. Outside of work, she writes for THOR Collective Dispatch, lifts weights, and makes cyber-inspired music with AI.

\n\n

--

\n\n

Sydney Marrone is a threat hunter, cybersecurity professional, co-founder of THOR Collective, author of the Agentic Threat Hunting Framework, and co-author of the PEAK Threat Hunting Framework. She is passionate about making security knowledge accessible and actionable through hands-on research, open-source collaboration, and community-driven projects like HEARTH (Hunting Exchange And Research Threat Hub). Sydney creates resources, leads workshops, and shares insights that spark curiosity and empower defenders. Outside of work, she writes for THOR Collective Dispatch, lifts weights, and makes cyber-themed music using AI to blend creativity and hacker culture.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_am_ws4_4061
\n\'',NULL,1293438),('2_Friday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted\'','\'Sydney \"letswastetime\" Marrone\'','DEF CON Workshops_4c5c1432e0eb146bf0b73228e6c188dd','\'\'',NULL,1293439),('2_Friday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted\'','\'Sydney \"letswastetime\" Marrone\'','DEF CON Workshops_4c5c1432e0eb146bf0b73228e6c188dd','\'\'',NULL,1293440),('2_Friday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Agentic Threat Hunting: Building AI That Remembers What You Hunted\'','\'Sydney \"letswastetime\" Marrone\'','DEF CON Workshops_4c5c1432e0eb146bf0b73228e6c188dd','\'\'',NULL,1293441),('2_Friday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Hands-on IoT firmware extraction and flash forensics\'','\'Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu\'','DEF CON Workshops_032babf0b80c9cb8daf4d1476bcc5848','\'Title: Sold Out - Hands-on IoT firmware extraction and flash forensics
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W225 (Workshops) - Map
\n
\nDescription:
\n

Did you ever wanted to hack an IoT device but did not know how to start? Having UART is nice, but does not help in many cases.

\n\n

For a complete analysis of an IoT device, it is required to look at the firmware itself. In most cases this means that the firmware, data or encryption keys need to be extracted from the device memory. Many researchers are hesitant to do that as there is a high risk of destroying the device or leaving it in an inoperable state. In this workshop we will look at different flash memory types (EEPROM, SPI flash, NAND flash, eMMC flash) and how to extract the information from them.

\n\n

We will show that you do not need very expensive hardware to archive your goal and that it is not as complicated as everyone believes. See which tools might be useful for your own lab!

\n\n

Participants will have the opportunity to work in groups and being provided different kinds of IoT devices (e.g. smart speakers). After a tear-down, you can use different chip-off methods (e.g. Hot air, IR soldering) to remove the flash chip and read it out. Optionally, the tools re-ball and re-solder the IC will be available after the workshop. In the end, each team should have the data and a functional device again.

\n\n

Bonus: If you brick the device, you can keep the parts as a souvenir or can wear them as badges.

\n\nSpeakers:Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu
\n
\nSpeakerBio:  Dennis Giese
\n

Dennis Giese is a researcher with the focus on the security and privacy of IoT devices. While being interested in physical security and lockpicking, he enjoys applied research and reverse engineering malware and all kinds of devices. His most known projects are the documentation and hacking of various vacuum robots. He calls himself a \"robot collector\" and his current vacuum robot army consists of over 95 different models from various vendors. He talked about his research at the Chaos Communication Congress, REcon, HITCON, NULLCON, and DEFCON.

\n\nSpeakerBio:  Braelynn Luedtke
\n

Hacker and tomato farmer. Enjoys researching the security of anything that piques her curiosity. She has previously presented this research at conferences such as Chaos Communication Congress, HITCON and DEFCON.

\n\nSpeakerBio:  Arnold Wey
\n

Arnold Wey is an electronics security researcher. His recent work includes security testing of virtual GPU implementations, robot arm communication protocols, and repurposing a 3D printer for fault injection research.

\n\nSpeakerBio:  Harsha Potu
\n

Harsha has been taking things apart since he could get his hands on a screwdriver for fun and profit. Nowadays he is a cybersecurity researcher with a decade of experience in embedded security. He loves to reverse boards + firmware and regularly finds vulnerabilities at various layers of execution. Especially interested in breaking secure boot chain designs!

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_am_ws7_4076
\n\'',NULL,1293442),('2_Friday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Hands-on IoT firmware extraction and flash forensics\'','\'Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu\'','DEF CON Workshops_032babf0b80c9cb8daf4d1476bcc5848','\'\'',NULL,1293443),('2_Friday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Hands-on IoT firmware extraction and flash forensics\'','\'Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu\'','DEF CON Workshops_032babf0b80c9cb8daf4d1476bcc5848','\'\'',NULL,1293444),('2_Friday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Hands-on IoT firmware extraction and flash forensics\'','\'Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu\'','DEF CON Workshops_032babf0b80c9cb8daf4d1476bcc5848','\'\'',NULL,1293445),('2_Friday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF\'','\'Ryan \"Hackgnar\" Holeman,Alek Amrani\'','DEF CON Workshops_b631b2370bd2242fc0e457f9b9527803','\'Title: Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W232 (Workshops) - Map
\n
\nDescription:
\n

BLE CTF is a series of Bluetooth Low Energy challenges in a capture-the-flag format, created to teach the fundamentals of interacting with and hacking BLE services. Each flag interactively introduces a new concept.

\n\n

Over the years, BLE CTF has expanded across platforms and skill levels. Books, workshops, trainings, and conferences have adopted it as both an educational platform and CTF. As an open source, low-cost, extensible solution, it has helped advance Bluetooth security research.

\n\n

This workshop teaches the fundamentals of hacking BLE through hands-on exercises that introduce beginners to new concepts while giving experienced users a chance to try new tools and techniques. After completing it, you will have a solid understanding of how to hack BLE devices in the wild.

\n\n

New for DEF CON 34: the workshop uses a brand new variant of BLE CTF built specifically for this event. Returning students will face fresh challenges they have not seen before, and the new exercises are designed to resist online walkthroughs and LLM-assisted shortcuts. We will also introduce new client tools, including gratttool, a modern replacement for gatttool (which has been deprecated from most Linux distributions). Whether this is your first BLE CTF or your eighth, you will leave with new skills and tools.

\n\nSpeakers:Ryan \"Hackgnar\" Holeman,Alek Amrani
\n
\nSpeakerBio:  Ryan \"Hackgnar\" Holeman
\n

Ryan Holeman resides in Austin, Texas, where he works as the CISO for Stability AI. He holds a Ph.D. in cyber defense from Dakota State University and has spoken at respected venues such as Black Hat, DEF CON, Lockdown, BSides, Ruxcon, Notacon, and Shmoocon. You can keep up with his current activity, open source contributions, and general news on his blog. His spare time is mostly spent digging into various network protocols, random hacking, creating art, surfing, and shredding local skateparks.

\n\nSpeakerBio:  Alek Amrani
\n

Alek Amrani runs the security team at Cape.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_am_ws5_4054
\n\'',NULL,1293446),('2_Friday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF\'','\'Ryan \"Hackgnar\" Holeman,Alek Amrani\'','DEF CON Workshops_b631b2370bd2242fc0e457f9b9527803','\'\'',NULL,1293447),('2_Friday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF\'','\'Ryan \"Hackgnar\" Holeman,Alek Amrani\'','DEF CON Workshops_b631b2370bd2242fc0e457f9b9527803','\'\'',NULL,1293448),('2_Friday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Learning to Hack Bluetooth Low Energy with BLE CTF\'','\'Ryan \"Hackgnar\" Holeman,Alek Amrani\'','DEF CON Workshops_b631b2370bd2242fc0e457f9b9527803','\'\'',NULL,1293449),('2_Friday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming\'','\'Jake \"Hubbl3\" Krasnov,Vincent \"Vinnybod\" Rose,Anthony \"Coin\" Rose,Dan Niefeld\'','DEF CON Workshops_1498bdec9518ab39ae0993fc058eac80','\'Title: Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W231 (Workshops) - Map
\n
\nDescription:
\n

Behind every breach report from the last decade is a Command and Control (C2) framework. C2 is how operators reach into a compromised network, move sideways, harvest credentials, and stay invisible. This 4-hour, hands-on workshop puts you in the operator\'s chair. You set up your own Empire team server, learn the listener-stager-agent model from scratch, and run seven exercises that take you from \"never touched a C2\" to dumping credentials off a box you compromised yourself.

\n\n

You\'ll spin up an HTTP listener, deploy a .NET agent to a Windows target, and run post-exploitation tradecraft: Rubeus for credentials, SharpHound for AD enumeration, port-forward pivots to internal hosts, and privesc modules that turn a foothold into full control. You\'ll even build a custom Empire plugin that auto-runs on every new agent. The capstone is a mini-CTF on a cloud-hosted range we keep open all weekend, with a prize for the winners.

\n\n

You leave with the mental model most operators take years to build: how modern C2 actually works, what it assumes about the target, and where defenders most often catch it. No VMs to download. No setup before class. Bring a laptop, get on WiFi, and we\'ll have agents running before the first break.

\n\nSpeakers:Jake \"Hubbl3\" Krasnov,Vincent \"Vinnybod\" Rose,Anthony \"Coin\" Rose,Dan Niefeld
\n
\nSpeakerBio:  Jake \"Hubbl3\" Krasnov
\n

Jake \"Hubble\" Krasnov is the Red Team Operations Lead at BC Security, with a distinguished career spanning engineering and cybersecurity. A U.S. Air Force veteran, Jake began his career as an Astronautical Engineer overseeing rocket modifications, leading test and evaluation efforts for the F-22, and conducting red team operations with the 57th Information Aggressors. He later served as a Technical Lead Engineer at Boeing Phantom Works, where he focused on embedded security for aviation and space defense projects. A seasoned speaker and trainer, Jake has presented at DEF CON, Black Hat, HackRedCon, HackSpaceCon, and HackMiami, and has previously taught Empire and offensive PowerShell at DEF CON.

\n\nSpeakerBio:  Vincent \"Vinnybod\" Rose
\n

Vincent \"Vinnybod\" Rose is the Lead Developer for Empire and Starkiller. He is a software engineer with a decade of expertise in building highly scalable cloud services, improving developer operations, and automation. Recently, his focus has been on the reliability and stability of the Empire C2 server. Vinnybod has presented at Black Hat and has taught courses at DEF CON on Red Teaming and Offensive PowerShell. He currently maintains a cybersecurity blog focused on offensive security at https://bcsecurity.io/blog/.

\n\nSpeakerBio:  Anthony \"Coin\" Rose
\n

Dr. Anthony \"Coin\" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.

\n\nSpeakerBio:  Dan Niefeld
\n

Dan Niefeld is the founder of several Cyber Security and Technology organizations. An accomplished social engineer his career has spanned from program management to organizing conferences like Hack Space Con, Dan has spent his career, educating, mentoring and developing disrupting technologies with a focus of Mission and Community Development.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_am_ws6_4068
\n\'',NULL,1293450),('2_Friday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming\'','\'Jake \"Hubbl3\" Krasnov,Vincent \"Vinnybod\" Rose,Anthony \"Coin\" Rose,Dan Niefeld\'','DEF CON Workshops_1498bdec9518ab39ae0993fc058eac80','\'\'',NULL,1293451),('2_Friday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming\'','\'Jake \"Hubbl3\" Krasnov,Vincent \"Vinnybod\" Rose,Anthony \"Coin\" Rose,Dan Niefeld\'','DEF CON Workshops_1498bdec9518ab39ae0993fc058eac80','\'\'',NULL,1293452),('2_Friday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Long Live Empire: A C2 Workshop for Modern Red Teaming\'','\'Jake \"Hubbl3\" Krasnov,Vincent \"Vinnybod\" Rose,Anthony \"Coin\" Rose,Dan Niefeld\'','DEF CON Workshops_1498bdec9518ab39ae0993fc058eac80','\'\'',NULL,1293453),('2_Friday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment\'','\'Yoann \"OtterHacker\" DEQUEKER\'','DEF CON Workshops_49bc7c6b1cbf2cdc5e3465adc8d9c3a9','\'Title: Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W230 (Workshops) - Map
\n
\nDescription:
\n

This workshop will give an initiation to offensive malware development in C/C++ and how it is possible to adapt the approach depending on the security solution that must be tackled down. Different methods such as ModuleStomping, DLL Injection, Threadless Injection and Hardware Breakpoint for dehooking will be seen.\nThe idea is to start with a basic malware performing process injection and apply additional techniques to start evading EDR. At each step, some analysis on the malware will be performed to understand the differences at the system level and the IOC detected by the EDR.\nAt the end of this workshop, you will have all the knowledge needed to develop your own malware and adapt it to the targeted environment to escape from the basic pattern and spawn your beacons as if EDR didn\'t exist.

\n\nSpeakerBio:  Yoann \"OtterHacker\" DEQUEKER
\n

Yoann Dequeker (@OtterHacker) is a red team operator at Wavestone entitle with OSCP and CRTO certification. Aside from his RedTeam engagements and his contributions to public projects such as Impacket, he spends time working on Malware Developpement to ease beacon deployment and EDR bypass during engagements and is currently developing a fully custom C2.

\n\n

His research leads him to present his results on several conferences such as LeHack (Paris), Insomni\'hack (Swiss) or even through a 4-hour malware workshop at Defcon31,32 and 33 (Las Vegas). All along the year, he publishes several white papers on the techniques he discovered or upgraded and the vulnerabilities he found on public products.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_am_ws1_4039
\n\'',NULL,1293454),('2_Friday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment\'','\'Yoann \"OtterHacker\" DEQUEKER\'','DEF CON Workshops_49bc7c6b1cbf2cdc5e3465adc8d9c3a9','\'\'',NULL,1293455),('2_Friday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment\'','\'Yoann \"OtterHacker\" DEQUEKER\'','DEF CON Workshops_49bc7c6b1cbf2cdc5e3465adc8d9c3a9','\'\'',NULL,1293456),('2_Friday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Malware Development 101 - From Zero to Hero: Adapt your payload to your environment\'','\'Yoann \"OtterHacker\" DEQUEKER\'','DEF CON Workshops_49bc7c6b1cbf2cdc5e3465adc8d9c3a9','\'\'',NULL,1293457),('2_Friday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Offensive Packet Wizardry with Scapy\'','\'Mike \"Chicolinux\" Guirao\'','DEF CON Workshops_3344ee3abb423664a2df2f20c73bbb8e','\'Title: Sold Out - Offensive Packet Wizardry with Scapy
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W222 (Workshops) - Map
\n
\nDescription:
\n

Offensive Packet Wizardry with Scapy is a four-hour, 100% hands-on workshop that teaches attendees to build offensive networking tools from scratch in Python using Scapy, the packet crafting library used by red teams, malware analysts, and vulnerability researchers worldwide.

\n\n

Starting from first principles, raw packet construction, layer stacking, and send/receive mechanics, the workshop moves progressively through active reconnaissance, ARP cache poisoning with live credential interception, TCP/IP stack abuse (session injection, SYN flood, RST killing), protocol fuzzing against an intentionally vulnerable binary service, and full covert channel implementation (ICMP C2 shell, DNS file exfiltration, TCP header steganography).

\n\n

Every technique is implemented live in Python against an isolated lab network. Students leave with a working, importable red team toolkit, a Python package with a unified CLI, that they built themselves and can adapt for future engagements.

\n\n

The workshop concludes with \"Silent Pivot\", a scored capstone scenario that chains all techniques into a realistic kill chain: stealth discovery, service identification, fuzzer- triggered crash, ICMP command execution, DNS exfiltration of /etc/shadow, and network cleanup, all subject to an IDS alert budget.

\n\nSpeakerBio:  Mike \"Chicolinux\" Guirao
\n

Mike “Chicolinux” Guirao began his journey in the security field roughly 25 years ago while completing a master\'s degree. Since then, they have developed both broad and deep expertise across this incredible discipline. Currently, they are pursuing a PhD at New Mexico State University, where their research intersects Cybersecurity and Machine Learning/Artificial Intelligence.

\n\n

In addition to their academic pursuits, Mike serves on the organizing team for the Crypto & Privacy Village. This marks their third time teaching a workshop at DEF CON since DEF CON 24. They also hold several notable industry certifications, including the SANS GCIH, ISC2 CC, and Linux+, and they are excited to share their wealth of experience and knowledge.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_am_ws8_4025
\n\'',NULL,1293458),('2_Friday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Offensive Packet Wizardry with Scapy\'','\'Mike \"Chicolinux\" Guirao\'','DEF CON Workshops_3344ee3abb423664a2df2f20c73bbb8e','\'\'',NULL,1293459),('2_Friday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Offensive Packet Wizardry with Scapy\'','\'Mike \"Chicolinux\" Guirao\'','DEF CON Workshops_3344ee3abb423664a2df2f20c73bbb8e','\'\'',NULL,1293460),('2_Friday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Offensive Packet Wizardry with Scapy\'','\'Mike \"Chicolinux\" Guirao\'','DEF CON Workshops_3344ee3abb423664a2df2f20c73bbb8e','\'\'',NULL,1293461),('2_Friday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Web Hacking 101\'','\'cale \"calebot\" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon\'','DEF CON Workshops_65da6e7e7aeea7466772f7a1bb32d3e2','\'Title: Sold Out - Web Hacking 101
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W229 (Workshops) - Map
\n
\nDescription:
\n

Most security training starts with slides. This workshop starts with a target. Students spend the majority of the course attacking a purpose-built web application across progressive labs covering the vulnerability classes that define modern web security.

\n\n

Each module follows a difficulty curve. Entry-level labs present classic, unfiltered vulnerabilities for students to exploit independently. Difficulty escalates as filters and defenses appear, requiring adaptation and creative problem-solving. Failed payloads, broken assumptions, and dead ends are not setbacks. They are the learning journey. The frustration of a blocked payload and the persistence to find the bypass is how offensive intuition is built.

\n\n

A final exploit chaining challenge ties everything together, combining findings across vulnerability classes to demonstrate how moderate issues chain into critical impact, the way real attacks work.

\n\n

Students attack, fail, adapt, and break through. Hands-on exploitation and the willingness to struggle is the foundation of any security career. It starts here.

\n\n

All you need is a laptop and persistence.

\n\nSpeakers:cale \"calebot\" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon
\n
\nSpeakerBio:  cale \"calebot\" smith
\nCale Smith has spent his entire life obsessed with one question: \"Yeah, but how does it actually work?\"
\n\n

He started out building things, then realized breaking them was more fun, and has been doing exactly that across web, cloud, binary, IoT, and mobile ever since. He now manages a device-focused security team at Amazon, where his \"what if I just...\" instincts are finally considered a job qualification.

\n\nSpeakerBio:  Ruchik Dave
\n

Ruchik Samir Dave is a software engineer and security specialist with nearly 20 years of experience at the intersection of complex systems security and emerging threat landscapes. Ruchik has contributed to security frameworks for aviation systems and privacy-compliant architectures for large consumer IoT ecosystems, bringing safety-critical systems expertise to emerging technology platforms. His current research explores cloud security paradigms, security compliance, AI-assisted threat detection systems, and the novel attack surfaces introduced by machine learning implementations in embedded environments, areas that represent the cutting edge of adversarial research and defensive innovation. With a passion for building secure, large-scale software systems, Ruchik’s work addresses the evolving security challenges where traditional cybersecurity meets artificial intelligence, IoT proliferation, and safety-critical infrastructure.

\n\nSpeakerBio:  Young Seuk Kim
\n

Husband, father, hacker, gamer. Young’s path into security started like a good game exploit—he wanted to win, bent the rules, and discovered a passion for hacking. He began as a web app security consultant, moved into penetration testing and red teaming, and now works in application security engineering, helping teams build secure systems (and still breaking things for fun). He also dives into all kinds of games and stories, especially fantasy with Eastern martial arts, and loves dissecting media with the same curiosity he brings to code.

\n\nSpeakerBio:  Luke Cycon
\n

Luke is a former builder turned security engineer at Amazon, focused on web, cloud, and embedded device security. He came up building things before he discovered that breaking them taught him more about how they really work. These days he likes to poke at things until they misbehave, then help the builders make sure it doesn\'t happen twice. Off the clock, you\'ll find him tinkering with hardware, firing lasers at something, and celebrating each fixed bug with a bit too much whisky.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_am_ws2_4012
\n\'',NULL,1293462),('2_Friday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Web Hacking 101\'','\'cale \"calebot\" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon\'','DEF CON Workshops_65da6e7e7aeea7466772f7a1bb32d3e2','\'\'',NULL,1293463),('2_Friday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Web Hacking 101\'','\'cale \"calebot\" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon\'','DEF CON Workshops_65da6e7e7aeea7466772f7a1bb32d3e2','\'\'',NULL,1293464),('2_Friday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Web Hacking 101\'','\'cale \"calebot\" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon\'','DEF CON Workshops_65da6e7e7aeea7466772f7a1bb32d3e2','\'\'',NULL,1293465),('2_Friday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity\'','\'Rodrigo \"Sp0oKeR\" Montoro\'','DEF CON Workshops_6fb81c9f959a2b9bcffbadf1d1386c5a','\'Title: Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W228 (Workshops) - Map
\n
\nDescription:
\n

Cloud security encounters attacks that elude standard detection. In AWS, unauthorized access keys are a common cause of breaches. The vastness of AWS—over 450 services and 20,000 API actions—complicates threat visibility and exposes gaps in traditional tools.

\n\n

This workshop empowers participants with direct, hands-on experience using the AWS Threat Hunter tool to improve threat detection. Attendees will focus on building behavioral baselines and leveraging data-driven analysis to detect subtle AWS principal anomalies, enabling more precise detection than traditional event monitoring.

\n\n

Attendees will move beyond standard techniques by building multi-stage detection pipelines that create individualized baselines for each IAM principal and systematically flag personalized deviations, linking outliers directly to risks.

\n\nSpeakerBio:  Rodrigo \"Sp0oKeR\" Montoro
\n

Rodrigo Montoro is the CTO at Clavis Security, bringing over 25 years of leadership and technical expertise to the information technology and cybersecurity landscape. Throughout his career, Rodrigo has been a pioneer in open-source security, specializing in incident detection, response, and Cloud Security. A two-time patented inventor, he holds proprietary technologies for detecting malicious digital documents and analyzing malicious HTTP traffic. With a resume that includes key research roles at Tenchi Security, Apura, Tempest, Sucuri, and SpiderLabs, Rodrigo is a globally recognized authority who frequently speaks at elite conferences such as DEF CON Workshops (2023), DEF CON Cloud Village (3x), Black Hat Brazil Summit, SANS (DFIR, SIEM Summit, CloudSecNext), Source (Boston and Seattle), Toorcon (San Diego), Sector Canada (6x), and BSidesLV.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_pm_ws3_4091
\n\'',NULL,1293466),('2_Friday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity\'','\'Rodrigo \"Sp0oKeR\" Montoro\'','DEF CON Workshops_6fb81c9f959a2b9bcffbadf1d1386c5a','\'\'',NULL,1293467),('2_Friday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity\'','\'Rodrigo \"Sp0oKeR\" Montoro\'','DEF CON Workshops_6fb81c9f959a2b9bcffbadf1d1386c5a','\'\'',NULL,1293468),('2_Friday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity\'','\'Rodrigo \"Sp0oKeR\" Montoro\'','DEF CON Workshops_6fb81c9f959a2b9bcffbadf1d1386c5a','\'\'',NULL,1293469),('2_Friday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding!\'','\'Ryan \"@rj_chap\" Chapman,Aaron \"Ironical\" Rosenmund\'','DEF CON Workshops_8cd7b2fbc8cbbd87fc08ef681a9cba11','\'Title: Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding!
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W231 (Workshops) - Map
\n
\nDescription:
\n

Infostealers suck. We all know that. We don\'t like them. We want you to learn all that you can about them to help thwart the ongoing, ever-evolving threat. On that note, current infostealers are largely rule-based and path-driven, targeting known browser stores and wallets with noisy exfiltration methods. This four-hour workshop, led by Ryan Chapman and Aaron Rosenmund, moves beyond basic comprehension via observation to explore the evolution of precision-based malware. Students will utilize a live, on-demand lab environment to perform deep malware analysis using Ghidra to understand how current stealers operate.

\n\n

The session then transitions from analysis to creation, where attendees code, compile, and re-build their own \"evolved\" stealers. We replace static file targeting with in-memory relevance models and trade obvious HTTPS exfiltration for stealthy timing and protocol-native patterns. This hands-on, kinesthetic experience focuses on building a custom arsenal from the ground up. Participants will learn to enhance their tools with behavioral stealth, transitioning from identifying \"stoopie\" patterns to implementing advanced, AI-driven tradecraft and custom red team tool operations.

\n\n

You won\'t just learn how what an infostealer is. You\'ll learn how they operated end-to-end. Join us :).

\n\nSpeakers:Ryan \"@rj_chap\" Chapman,Aaron \"Ironical\" Rosenmund
\n
\nSpeakerBio:  Ryan \"@rj_chap\" Chapman
\n

Ryan Chapman is the author of SANS‚ FOR528: Ransomware and Cyber Extortion‚ course, teaches SANS‚ FOR610: Reverse Engineering Malware‚ course, and works as a threat hunter @ $dayJob. Ryan has a passion for life-long learning, loves to teach people about ransomware-related attacks, and enjoys pulling apart malware. He has presented workshops at DEF CON and other conferences in the past and knows how to create a step-by-step instruction set to maximize hands-on learning.

\n\nSpeakerBio:  Aaron \"Ironical\" Rosenmund
\n

Aaron Rosenmund is an accomplished cybersecurity professional with extensive experience in various leadership roles across multiple organizations. Currently serving as the Managing Director of Tradecraft and Programs at OnDefend since September 2024, Aaron also holds a position at the National Guard Bureau as Staff Lead for the Cyber Shield Red Team, demonstrating a commitment to enhancing cybersecurity defenses. With a background that includes significant roles at Pluralsight, where responsibilities spanned content strategy and security skills development, and the Florida Air National Guard as a Lead Cyber Operator focused on defensive operations, Aaron has developed a comprehensive skill set in threat emulation, cyber system operations, and training. Additionally, past leadership positions as CEO at Aestus Industries and Vice President at Concrete Surface Innovations underscore strong management capabilities and operational expertise. Aaron holds multiple degrees in technology and cybersecurity from respected institutions, underscoring a solid educational foundation in this field.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_pm_ws6_4093
\n\'',NULL,1293470),('2_Friday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding!\'','\'Ryan \"@rj_chap\" Chapman,Aaron \"Ironical\" Rosenmund\'','DEF CON Workshops_8cd7b2fbc8cbbd87fc08ef681a9cba11','\'\'',NULL,1293471),('2_Friday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding!\'','\'Ryan \"@rj_chap\" Chapman,Aaron \"Ironical\" Rosenmund\'','DEF CON Workshops_8cd7b2fbc8cbbd87fc08ef681a9cba11','\'\'',NULL,1293472),('2_Friday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - All About Stoopie InfoStealers: Malware Analysis for Understanding, Custom Coding for True Understanding!\'','\'Ryan \"@rj_chap\" Chapman,Aaron \"Ironical\" Rosenmund\'','DEF CON Workshops_8cd7b2fbc8cbbd87fc08ef681a9cba11','\'\'',NULL,1293473),('2_Friday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Embedded Computing Tools for Wireless Hardware Hacking\'','\'Joseph Long\'','DEF CON Workshops_60454458b94b1eadb0736238517a4811','\'Title: Sold Out - Embedded Computing Tools for Wireless Hardware Hacking
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W233 (Workshops) - Map
\n
\nDescription:
\n

Hands-on exploration of embedded hardware tools implementing multiple wireless communication standards. Experiment with Wi-Fi wireless local area network (WLAN) technology and Bluetooth personal area network (PAN) technology. Stream audio to and from a variety of endpoints. Configure a Nordic nRF52 Bluetooth sniffer to capture and analyze wireless communications using Wireshark. Examine the design and manufacture of an exclusive dual-core embedded hardware target supporting both Wi-Fi and Bluetooth. Leverage the target to experiment with microcontroller-based wireless hardware hacking. Practice both sinking and sourcing Bluetooth Audio streams into and out of the hardware target. Capture Wi-Fi packets using onto the hardware target for transfer to Wireshark for analysis. Perform example security exploits and countermeasures using embedded wireless hardware tools.

\n\n

PLEASE NOTE: This workshop requires purchasing the necessary hardware tools. A link to complete the purchase of $60 will be provided upon registration for the workshop. The purchased kits will be distributed during the workshop.

\n\nSpeakerBio:  Joseph Long
\n

Joseph Long has been tinkering, designing, and hacking electronic systems for about forty years. He is the founder of HackerBoxes.com, the monthly subscription box service for electronics, cybersecurity, and hacker culture. Joseph is a licensed professional engineer and patent attorney who loves to teach electrical engineering and computer science topics.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_pm_ws4_4046
\n\'',NULL,1293474),('2_Friday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Embedded Computing Tools for Wireless Hardware Hacking\'','\'Joseph Long\'','DEF CON Workshops_60454458b94b1eadb0736238517a4811','\'\'',NULL,1293475),('2_Friday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Embedded Computing Tools for Wireless Hardware Hacking\'','\'Joseph Long\'','DEF CON Workshops_60454458b94b1eadb0736238517a4811','\'\'',NULL,1293476),('2_Friday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Embedded Computing Tools for Wireless Hardware Hacking\'','\'Joseph Long\'','DEF CON Workshops_60454458b94b1eadb0736238517a4811','\'\'',NULL,1293477),('2_Friday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Introduction to Malware Analysis\'','\'Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus\'','DEF CON Workshops_0558f9c19e8fd1e1fa2225b84d9bec53','\'Title: Sold Out - Introduction to Malware Analysis
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W232 (Workshops) - Map
\n
\nDescription:
\n

Analyze malware to find indicators of compromise using static and dynamic techniques. We will analyze Windows executables at the binary level and modify them to cheat at games. We will examine both compiled code and DOTNET executables. We will also examine defenses to prevent memory-corruption attacks, including coding in Rust.

\n\n

We will demonstrate the techniques and help attendees solve challenges. There are dozens of hands-on projects, with a running CTF scoreboard. Some of the projects are easy enough for beginners, and others will challenge experienced experts. Every participant should leave with some new skills.

\n\n

All materials are freely available on the Web at samsclass.info and will remain available after the workshop is over.

\n\nSpeakers:Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus
\n
\nSpeakerBio:  Sam Bowne
\n

Sam Bowne has been teaching computer networking and security classes at City College San Francisco since 2000. He has given talks and hands-on trainings at DEF CON, DEF CON China, Black Hat USA, HOPE, BSidesSF, BSidesLV, RSA, and many other conferences and colleges. He founded Infosec Decoded, Inc., and does corporate training and consulting for several Fortune 100 companies, on topics including Incident Response and Secure Coding.

\n\n

Formal education: B.S. and Ph.D. in Physics\nIndustry credentials:

\n\n

Infosec: CISSP, Certified Ethical Hacker, Security+, Defcon Black Badge, Splunk Core Certified User\nNetworking: Network+, Certified Fiber Optic Technician, HE IPv6 Sage, CCENT, IPv6 Forum Silver & Gold, Juniper JN0-101, Wireshark WCNA\nMicrosoft: MCP, MCDST, MCTS: Vista

\n\nSpeakerBio:  Elizabeth Biddlecome
\n

Elizabeth Biddlecome is a consultant and instructor, delivering technical training and mentorship to students and professionals. She leverages her enthusiasm for architecture, security, and code to design and implement comprehensive information security solutions for business needs. Elizabeth enjoys wielding everything from soldering irons to cripting languages in cybersecurity competitions, hackathons, and CTFs.

\n\nSpeakerBio:  Kaitlyn Handelman
\n

Kaitlyn Handelman is an offensive security engineer at Amazon. Her\nfocus is cybersecurity in space. In addition to traditional\npenetration testing, Kaitlyn works on physical devices and RF signals.\nIn her free time, she enjoys ham radio, astronomy, and her cat,\nAstrocat.

\n\nSpeakerBio:  Irvin Lemus, Founder at r00tkit.io
\n

Irvin Lemus teaches people to break things so they can defend them. CISSP-certified cybersecurity professional with over a decade building competitions, teaching offensive and defensive security, and advising organizations across the Americas. Currently Director of Education & Training for Latin America at By Light and founder of r00tkit.io.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_pm_ws5_4019
\n\'',NULL,1293478),('2_Friday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Introduction to Malware Analysis\'','\'Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus\'','DEF CON Workshops_0558f9c19e8fd1e1fa2225b84d9bec53','\'\'',NULL,1293479),('2_Friday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Introduction to Malware Analysis\'','\'Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus\'','DEF CON Workshops_0558f9c19e8fd1e1fa2225b84d9bec53','\'\'',NULL,1293480),('2_Friday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Introduction to Malware Analysis\'','\'Sam Bowne,Elizabeth Biddlecome,Kaitlyn Handelman,Irvin Lemus\'','DEF CON Workshops_0558f9c19e8fd1e1fa2225b84d9bec53','\'\'',NULL,1293481),('2_Friday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response\'','\'Vince \"bitpusher\" Weppner\'','DEF CON Workshops_32a4218229de68ad973bf16a57c67918','\'Title: Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W222 (Workshops) - Map
\n
\nDescription:
\n

A compromised mailbox. An inbox rule named \".\". An OAuth consent to an unknown application. A sign-in from a cloud-hosting ASN with user-agent \"axios\" and MFA status \"satisfied by claim in token\". Somewhere in there is the story - and somewhere in the Microsoft 365 logs is the evidence.\nThis four-hour hands-on workshop teaches Business Email Compromise investigation in the tenants most responders actually see: M365 Business Premium or E3. No Sentinel. No SIEM. No problem. Using only native admin centers, PowerShell modules, and a few scripts, you will run a complete BEC investigation end to end.\nWorking through several progressive scenarios, from single-user compromise, through lateral-pivot case with MailItemsAccessed analysis, to multi-account incident with a malicious enterprise app and transport rule. You will learn how to contain, collect, triage, pivot, expand scope, remediate, and produce the three common reporting deliverables: investigation report, attestation letter, internal post-mortem.\nThis is Living off the Land Incident Response. Through chronology and topology, come correlate some logs with me and see what story they tell.

\n\nSpeakerBio:  Vince \"bitpusher\" Weppner
\n

Vincent M. Weppner (Bitpusher) is an Information Security Specialist with 10+ years of dedicated cybersecurity focus and 25 years in IT overall. He works as a Security Analyst at a mid-market MSP and runs an independent IT consulting practice at theTechRelay.com. Generally found lurking in the mountains of Southern California, and occasionally maintaining his open-source tooling at github.com/bitpusher2k.\nHis day-to-day work covers M365 security operations, Active Directory and endpoint security, BEC/ransomware incident response, EDR/SIEM management, and security consulting for SMB and mid-market clients. Specialization in Business Email Compromise was built out of direct operational need: after dozens of BEC incidents, the pattern of \"which script do I need to run right now?\" became clear enough to codify. Passionately solving puzzles through scripting, and hoping to pass on some of it to you.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_pm_ws8_4033
\n\'',NULL,1293482),('2_Friday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response\'','\'Vince \"bitpusher\" Weppner\'','DEF CON Workshops_32a4218229de68ad973bf16a57c67918','\'\'',NULL,1293483),('2_Friday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response\'','\'Vince \"bitpusher\" Weppner\'','DEF CON Workshops_32a4218229de68ad973bf16a57c67918','\'\'',NULL,1293484),('2_Friday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Investigating and Responding to M365 account compromise on a shoestring: Living of the Land Incident Response\'','\'Vince \"bitpusher\" Weppner\'','DEF CON Workshops_32a4218229de68ad973bf16a57c67918','\'\'',NULL,1293485),('2_Friday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - OT Systems: how to secure them in practice!\'','\'Alexandrine Torrents,Arnaud SOULLIE\'','DEF CON Workshops_ada60e72d84a3369c973783ea541eb87','\'Title: Sold Out - OT Systems: how to secure them in practice!
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W225 (Workshops) - Map
\n
\nDescription:
\n

Securing OT systems is often presented as challenging, with multiple business constraints - but is it that complicated, especially considering a single industrial site?\nIn this 4-hour, hands-on workshop, each participant will manipulate a simple but realistic Industrial Control System setup with SCADA systems & PLCs. Attendees will have the opportunity to secure it step by step, through several hands-on exercises & discover how to manually secure OT systems: OT inventory, backups, network security, system hardening and detection.\nWhat if the real challenge is OT security at scale? Besides implementing manual security on our setup, we will address each step of the way OT security at scale and share feedback on how large companies are securing their OT systems, both at organizational & technical level: community of OT cyber correspondents, OT DMZ and security tools deployment.\nNo prior OT experience is required.

\n\nSpeakers:Alexandrine Torrents,Arnaud SOULLIE
\n
\nSpeakerBio:  Alexandrine Torrents
\n

Alexandrine Torrents is a cybersecurity expert at Wavestone. She started as a penetration tester, and then specialized in OT cybersecurity. She is IEC 62443 certified. She performed dozens of OT cybersecurity assessments across various industries & worked on OT models to perform attacks on PLCs & SCADA systems. Alexandrine also helps secure OT both at technical & organization levels: secure architecture, system hardening, IAM, cyber resilience, detection, governance, awareness & training, risk assessment, cyber by design, etc. Alexandrine works with different CISOs on their OT cybersecurity roadmaps & programs at different scales of large industrial companies: site, business units, Group with worldwide scope. Alexandrine also gives training on OT cybersecurity.

\n\nSpeakerBio:  Arnaud SOULLIE
\n

Arnaud Soullie is a Senior Manager at Wavestone. He has over 15 years of experience in security assessments and penetration testing, with 10 years specializing in Industrial Control Systems cybersecurity. He has delivered talks and workshops at DEF CON, Black Hat Europe, BruCON, CS3STHLM, BSides Las Vegas, and others. He is the creator of the DYODE open-source data diode project and has been teaching ICS cybersecurity since 2015.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_pm_ws7_4014
\n\'',NULL,1293486),('2_Friday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - OT Systems: how to secure them in practice!\'','\'Alexandrine Torrents,Arnaud SOULLIE\'','DEF CON Workshops_ada60e72d84a3369c973783ea541eb87','\'\'',NULL,1293487),('2_Friday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - OT Systems: how to secure them in practice!\'','\'Alexandrine Torrents,Arnaud SOULLIE\'','DEF CON Workshops_ada60e72d84a3369c973783ea541eb87','\'\'',NULL,1293488),('2_Friday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - OT Systems: how to secure them in practice!\'','\'Alexandrine Torrents,Arnaud SOULLIE\'','DEF CON Workshops_ada60e72d84a3369c973783ea541eb87','\'\'',NULL,1293489),('2_Friday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Workshops_0f3301f90f087168fa5b17f7a75097c5','\'Title: Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W229 (Workshops) - Map
\n
\nDescription:
\n

Anthropic, April 2026: Claude Mythos Preview is \"strikingly capable\" at zero-day discovery. They chose not to release it.

\n\n

AISLE, one week later: \"The moat in AI cybersecurity is the system, not the model.\" They reproduced Mythos-class findings on FreeBSD with a 1,700-line scan.py and a commodity model for under $100.

\n\n

This four-hour hands-on workshop is the local-hardware version of that argument. Two reproductions, two domains, one harness pattern.

\n\n

Part I: point AISLE\'s open-source pipeline at a pre-patch FreeBSD checkout through a hosted local-AI inference endpoint and reproduce the 17-year-old CVE-2026-4747 that drove Mythos, for sub-dollar spend.

\n\n

Part II: change domains. Drive Ghidra through MCP tool calls against unpatchable D-Link DNS-320L firmware. Validate CVE-2024-3273 with the advisory in hand, then rediscover it from a blank start once the harness moves enumeration into the driver.

\n\n

What happens next is what you come to find out. Same hardware, same model, same harness, four hours later: can local AI extend the famous disclosure with bugs the original missed? Come see for yourself.

\n\n

No GPU. No API. No cloud spend. The workshop hosts inference for the room.

\n\nSpeakerBio:  John \"clearbluejar\" McIntosh
\n

John McIntosh (@clearbluejar) is a security researcher and founder of ClearSecLabs, specializing in reverse engineering, vulnerability research, and AI-assisted binary analysis. He is the author of ghidriff, an open-source Ghidra-based binary diffing engine, and pyghidra-mcp, a headless Ghidra MCP server enabling LLM-driven, project-wide, multi-binary reverse engineering workflows. An active contributor to the Agent Skills ecosystem, John bridges deterministic analysis with AI-driven reasoning to accelerate vulnerability research. He has delivered training and workshops at DEF CON, Black Hat, REcon, Ringzer0, 44CON, Objective by the Sea, and Insomni\'hack, covering topics from practical Windows reverse engineering to building private local LLM RE stacks. His recent work includes the \"Agentic RE\" training at DEF CON Singapore 2026, the MCP Ghidra workshop at REcon 2025, and the \"Supercharging Ghidra\" LLM workshop at Ringzer0 COUNTERMEASURE 2025. With over a decade of offensive security experience, John publishes detailed research on reversing CVEs, building RE tooling, and agentic patch diffing at clearbluejar.github.io. His teaching emphasizes reproducibility, progressive skill-building, and contributor empowerment.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_pm_ws2_4092
\n\'',NULL,1293490),('2_Friday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Workshops_0f3301f90f087168fa5b17f7a75097c5','\'\'',NULL,1293491),('2_Friday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Workshops_0f3301f90f087168fa5b17f7a75097c5','\'\'',NULL,1293492),('2_Friday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Workshops_0f3301f90f087168fa5b17f7a75097c5','\'\'',NULL,1293493),('2_Friday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer\'','\'Darcy \"@Drc3p0\" Neal\'','DEF CON Workshops_33bbadbfaf5a1c1ed893ec17203cdf31','\'Title: Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W230 (Workshops) - Map
\n
\nDescription:
\n

Every electronic device around you is silently broadcasting electromagnetic signals. In this\nhands-on workshop, you will build an SMD (surface-mount) version of the EMF Explorer from bare PCB to\nworking device, learning progressive SMD soldering techniques from 1206 down to 0603 component sizes\nalong the way. Geared for absolute beginners who are new to soldering and electronics. This session pairs each build stage with a circuit theory deep dive: you will understand the voltage divider powering your board, the op-amp gain stages amplifying\nEMF signals into audible sound, and how inductor geometry shapes what you can hear. Walk\naway with a functional EMF listening device, new SMD skills transferable to real-world hardware hacking,\nand a deeper understanding of the electromagnetic emissions all around you.

\n\nSpeakerBio:  Darcy \"@Drc3p0\" Neal
\n

Darcy Neal (Drc3p0) is an electronics educator and founder of SporkLogic, where they design open-source hardware kits and facilitate soldering workshops at maker and hacker events worldwide. With over 15 years in interactive audio-visual hardware design, Darcy\'s work spans RF experimentation, new media installations, boutique synthesizer production, and hands-on electronics education. Their flagship product, the EMF Explorer, is an accessible tool for sonifying electromagnetic fields. They collaborate regularly with Mitch Altman and the Hardware Hacking Assembly, and have taught large-scale soldering workshops across the global hacker community.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/fri_pm_ws1_4045
\n\'',NULL,1293494),('2_Friday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer\'','\'Darcy \"@Drc3p0\" Neal\'','DEF CON Workshops_33bbadbfaf5a1c1ed893ec17203cdf31','\'\'',NULL,1293495),('2_Friday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer\'','\'Darcy \"@Drc3p0\" Neal\'','DEF CON Workshops_33bbadbfaf5a1c1ed893ec17203cdf31','\'\'',NULL,1293496),('2_Friday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Solder, Detect, Listen: Build Your Own EMF Explorer\'','\'Darcy \"@Drc3p0\" Neal\'','DEF CON Workshops_33bbadbfaf5a1c1ed893ec17203cdf31','\'\'',NULL,1293497),('3_Saturday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine\'','\'Preston Zen\'','DEF CON Workshops_8c4476b33451b6f7b0fc07bac3ddb337','\'Title: Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W233 (Workshops) - Map
\n
\nDescription:
\n

Every wireless thing in your life is broadcasting. The question is who\'s listening — and what they can do with it.\nBattle-Tested Broadcasts is a four-hour, hands-on workshop on RF detection and direction finding, framed by the most demanding live laboratory in the world for these techniques: the Ukrainian frontline. We start with universal foundations — frequency, modulation, antennas, what your SDR can and can\'t see — and pivot into where neural-time RF detection becomes existential: drones. A pilot powers up an FPV controller thirty seconds before impact. Pure RF detection is often the only sensor in the chain that catches the threat before the drone leaves the ground.\nWe cover what\'s actually in the air across a contested battlefield slice — controllers, video downlinks, telemetry beacons, battlefield comms, GNSS, and the increasingly exotic bands operators are pushing into to dodge electronic warfare. We dissect the honest limits of common off-the-shelf SDR tooling, and the ways adversaries already evade pure RF detection: from fiber-optic and autonomous drones to wired front-line networks, frequency hopping, and out-of-scan spectrum.\nAttendees solder and flash a Signal Compass — a pocket ESP32 signal detector with directional bearing. Rotating lab stations cover passive scanning, fingerprinting, direction findi

\n\nSpeakerBio:  Preston Zen
\n

Preston Zen ‚ the original creator of 1337sheets.com, OSCE3 certified, now leading Kaizen Labs out of a Japan / Ukraine hybrid office. Software, hardware, and cybersecurity background. Volunteering in Ukraine since 2022 with NGOs including Dronarnia, BeeTA, American Made Freedom, and Shield of Freedom on drone systems, RF detection, EW countermeasures, and humanitarian logistics. DEFCON regular since DC25 and a Hac-Man CTF contributor for the past three years. He\'s shipped more boards than he\'s counted, and has spent enough time near the Ukrainian frontline to have strong opinions about which detection tools actually work when the noise floor is on fire.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_am_ws4_4077
\n\'',NULL,1293498),('3_Saturday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine\'','\'Preston Zen\'','DEF CON Workshops_8c4476b33451b6f7b0fc07bac3ddb337','\'\'',NULL,1293499),('3_Saturday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine\'','\'Preston Zen\'','DEF CON Workshops_8c4476b33451b6f7b0fc07bac3ddb337','\'\'',NULL,1293500),('3_Saturday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Battle-Tested Broadcasts: RF Insights From Ukraine\'','\'Preston Zen\'','DEF CON Workshops_8c4476b33451b6f7b0fc07bac3ddb337','\'\'',NULL,1293501),('3_Saturday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3\'','\'Andrew Case,Pierre \"Abyss Watcher\" Breton,David McDonald\'','DEF CON Workshops_e1a949ca1db253d94ce98a34c00eb237','\'Title: Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W232 (Workshops) - Map
\n
\nDescription:
\n

Memory-only malware is now commonly used by threat actors ranging from criminal organizations to ransomware operators to APT groups. To detect such malware, memory forensics, which is the examination of a system’s volatile memory (RAM), must be performed. Volatility 3 is the latest version of the Volatility Memory Analysis framework and is the most widely used open-source framework for memory forensics. In this workshop, students will learn how to use Volatility 3 to detect the most sophisticated malware techniques found in the wild. This learning will occur through a mixture of lectures, live demos, and extensive hands-on labs where students analyze memory samples infected with real malware. While students work through labs, instructors walk to each student’s station to ensure they are progressing. An instructor also walks through each lab live upon completion, and students are given a 35+ page lab guide that contains all the scenarios, questions, and detailed answers. Students can later use the course slides and lab guide to practice as well as to guide real-world investigations. The workshop’s instructors are core Volatility developers who have made significant contributions to the project. By attending this workshop, students will gain deep knowledge and hands-on experience analyzing memory-only malware.

\n\nSpeakers:Andrew Case,Pierre \"Abyss Watcher\" Breton,David McDonald
\n
\nSpeakerBio:  Andrew Case
\n

Andrew Case is the Director of Research at Volexity and has significant experience in incident response handling, digital forensics, and malware analysis. Case is a core developer of Volatility, the most widely used open-source memory forensics framework, and a co-author of the highly popular and technical forensics analysis book \"The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory.\" Case has spoken at many industry conferences, including DEF CON, Black Hat, RSA, DFRWS, SecTor, BSides*, and OMFW.

\n\nSpeakerBio:  Pierre \"Abyss Watcher\" Breton
\n

Pierre (Abyss Watcher) Breton is a researcher at Volexity, holding a Master of Science in Cybersecurity, specializing in digital forensics, malware analysis and detection engineering. He is a primary contributor to Volatility, the most widely used open-source memory forensics framework. Breton has demonstrated a great ability to assist the incident response community by developing innovative capabilities and resources. He conveys his passion through the organization of CTF events and training sessions that showcase both accessible and challenging topics.

\n\nSpeakerBio:  David McDonald
\n

David McDonald is a researcher and software engineer with 5 years of digital forensics R&D experience. His passion for this field began with his involvement in the University of New Orleans CTF team, as well as through his time as a Systems Programming teaching assistant. After over two years of digital forensics research and development on Cellebrite\'s computer forensics team, he joined Volexity\'s Volcano team, where he now works to develop next-generation memory analysis solutions. He believes deeply in sharing knowledge and helping others discover their abilities and interests through their own journeys in cybersecurity, and strives to pay forward the benefits of the mentorship that has opened so many doors for him.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_am_ws5_4024
\n\'',NULL,1293502),('3_Saturday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3\'','\'Andrew Case,Pierre \"Abyss Watcher\" Breton,David McDonald\'','DEF CON Workshops_e1a949ca1db253d94ce98a34c00eb237','\'\'',NULL,1293503),('3_Saturday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3\'','\'Andrew Case,Pierre \"Abyss Watcher\" Breton,David McDonald\'','DEF CON Workshops_e1a949ca1db253d94ce98a34c00eb237','\'\'',NULL,1293504),('3_Saturday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Detecting and Analyzing Memory Only Malware with Volatility 3\'','\'Andrew Case,Pierre \"Abyss Watcher\" Breton,David McDonald\'','DEF CON Workshops_e1a949ca1db253d94ce98a34c00eb237','\'\'',NULL,1293505),('3_Saturday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Explore the Windows instrumentation callback\'','\'Yoann \"OtterHacker\" DEQUEKER\'','DEF CON Workshops_aec9e9c05af5f16e75b9310c656140d3','\'Title: Sold Out - Explore the Windows instrumentation callback
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W225 (Workshops) - Map
\n
\nDescription:
\n

The Nirvana Debug is a type of instrumentation callback existing since Windows 7. This workshop idea is to see how this feature can be weaponized in order to either:\n- Hijack execution flow\n- Perform process injection\n- Perform sleep obfuscation for C2 beacon

\n\n

During this workshop, you will learn the main principle of Nirvana Debugging, and try to weaponize it. Some debugging, reverse and coding will be needed in order to create a new malware that will evade classic EDR solutions.

\n\nSpeakerBio:  Yoann \"OtterHacker\" DEQUEKER
\n

Yoann Dequeker (@OtterHacker) is a red team operator at Wavestone entitle with OSCP and CRTO certification. Aside from his RedTeam engagements and his contributions to public projects such as Impacket, he spends time working on Malware Developpement to ease beacon deployment and EDR bypass during engagements and is currently developing a fully custom C2.

\n\n

His research leads him to present his results on several conferences such as LeHack (Paris), Insomni\'hack (Swiss) or even through a 4-hour malware workshop at Defcon31,32 and 33 (Las Vegas). All along the year, he publishes several white papers on the techniques he discovered or upgraded and the vulnerabilities he found on public products.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_am_ws7_4006
\n\'',NULL,1293506),('3_Saturday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Explore the Windows instrumentation callback\'','\'Yoann \"OtterHacker\" DEQUEKER\'','DEF CON Workshops_aec9e9c05af5f16e75b9310c656140d3','\'\'',NULL,1293507),('3_Saturday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Explore the Windows instrumentation callback\'','\'Yoann \"OtterHacker\" DEQUEKER\'','DEF CON Workshops_aec9e9c05af5f16e75b9310c656140d3','\'\'',NULL,1293508),('3_Saturday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Explore the Windows instrumentation callback\'','\'Yoann \"OtterHacker\" DEQUEKER\'','DEF CON Workshops_aec9e9c05af5f16e75b9310c656140d3','\'\'',NULL,1293509),('3_Saturday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure\'','\'HackeMate\'','DEF CON Workshops_6eebe15dfe4577c1f902285e167aa41a','\'Title: Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W230 (Workshops) - Map
\n
\nDescription:
\n

HackTheCloud25 CTF Manager is an automated orchestration framework designed for the management of cloud cybersecurity challenges. It enables the deployment of intentionally vulnerable laboratories across AWS, Azure, and GCP using Terraform as the underlying Infrastructure-as-Code engine. The solution centralizes challenge definitions via YAML files, managing complex dependencies, dynamic variables, and resource outputs through a unified command-line interface (CLI) to list, deploy, destroy, and monitor resources in a controlled environment.

\n\n

Furthermore, the framework incorporates environment validation, automated credential detection, detailed event logging, and support for reusable configurations, ensuring high scalability and traceability for complex attack scenarios. Collectively, the CTF Manager provides a reproducible and extensible approach to orchestrating practical cloud security exercises for educational purposes, streamlining the creation, operation, and maintenance of vulnerable infrastructures within dedicated testing environments.

\n\nSpeakerBio:  HackeMate
\n

HackeMate is the host of the YouTube channel under the same name, where the creator, an Offensive Cybersecurity Engineer, shares their expertise in ethical hacking, as well as offensive and defensive security. With over 30,000 subscribers engaged in the world of cybersecurity, they have established themselves as a key figure in the community through challenges, technical analyses, and hands-on demonstrations.\nProfessionally, HackeMate holds Red Team certifications such as the eLearnSecurity Junior Penetration Tester (eJPT) and Web Penetration Tester (eWPT), along with Blue Team certifications like Microsoft Azure Fundamentals (AZ-900) and Microsoft Security, Compliance, and Identity Fundamentals (SC-900). They are also a Google Product Expert for Google Drive, contributing their knowledge in cloud security and optimization.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_am_ws1_4034
\n\'',NULL,1293510),('3_Saturday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure\'','\'HackeMate\'','DEF CON Workshops_6eebe15dfe4577c1f902285e167aa41a','\'\'',NULL,1293511),('3_Saturday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure\'','\'HackeMate\'','DEF CON Workshops_6eebe15dfe4577c1f902285e167aa41a','\'\'',NULL,1293512),('3_Saturday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure\'','\'HackeMate\'','DEF CON Workshops_6eebe15dfe4577c1f902285e167aa41a','\'\'',NULL,1293513),('3_Saturday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Hecate: A Trivial UART Tool\'','\'mx,Joe \"SecurelyFitz\" FitzPatrick,nyx\'','DEF CON Workshops_611d4606616a7a2be9f5c108c91416d1','\'Title: Sold Out - Hecate: A Trivial UART Tool
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W231 (Workshops) - Map
\n
\nDescription:
\n

Hecate is an open source UART implant framework designed to make common hardware hacking tasks easy with minimal code. It turns any CircuitPython microcontroller into a powerful, customizable UART implant.

\n\n

In this workshop, you\'ll get to use all the core features of Hecate and see how they work against multiple target devices. We\'ll start hands-on by listening to a device\'s UART output, and then configuring Hecate to operate in standalone mode and log that UART data to a file. Once we\'ve seen it in action, we\'ll step back for a bit of lecture about UART, what it\'s used for, and what we designed Hecate to be capable of. Armed with this knowledge, you\'ll dive into two more hands-on labs: a payload dropper that will playback a custom transaction and a simple detector that will signal an alert when it detects a pattern. We\'ll reconvene for a last bit of lecture on how to use some of Hecate\'s advanced features, before you dive into the final lab: implement a full implant-in-the-middle capable of modifying UART data in flight.

\n\n

Hecate makes developing embedded implants trivial, while remaining flexible enough for advanced research and rapid prototyping. You\'ll walk away with hands-on experience using the Hecate framework and a working understanding of what\'s possible with UART interception, manipulation, and exploitation

\n\nSpeakers:mx,Joe \"SecurelyFitz\" FitzPatrick,nyx
\n
\nSpeakerBio:  mx
\n

Maxie is an erstwhile cloud infrastructure engineer, formerly an SRE at Google Cloud Platform and others. She came to the world of hardware hacking and embedded devices first as a pleasant escape from the quotidian indignities of working in the cloud, and she stayed for the addictive aroma of flux fumes. She enjoys making ill-advised expansions to her homelab and spending evenings at her local hackerspace in Portland, OR.

\n\nSpeakerBio:  Joe \"SecurelyFitz\" FitzPatrick
\n

Joe FitzPatrick (@securelyfitz) is a trainer and researcher at SecuringHardware.com with a personal mission to make all hardware devices at least a bit more secure. He builds tools like Tigard and Erebus, and teaches Applied Hardware Attacks trainings to help people break - and secure - their hardware devices. His actual superpower is the ability to instantly end awkward conversational pauses if you ask him about BSides Portland, the CTRL-H Hackerspace, or drone taco delivery at ToorCamp.

\n\nSpeakerBio:  nyx
\n

nyx is a Portland-based hacker, engineer, and self-described cyberpunk. As an unwilling participant in the late-capitalist, mass-surveillance dystopia, he is passionate about digital privacy, data self-custody, and running his own infra. While voiding warranties has long been one of his favorite pastimes, he has lately been fortunate enough to do it professionally as well.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_am_ws6_4072
\n\'',NULL,1293514),('3_Saturday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Hecate: A Trivial UART Tool\'','\'mx,Joe \"SecurelyFitz\" FitzPatrick,nyx\'','DEF CON Workshops_611d4606616a7a2be9f5c108c91416d1','\'\'',NULL,1293515),('3_Saturday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Hecate: A Trivial UART Tool\'','\'mx,Joe \"SecurelyFitz\" FitzPatrick,nyx\'','DEF CON Workshops_611d4606616a7a2be9f5c108c91416d1','\'\'',NULL,1293516),('3_Saturday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Hecate: A Trivial UART Tool\'','\'mx,Joe \"SecurelyFitz\" FitzPatrick,nyx\'','DEF CON Workshops_611d4606616a7a2be9f5c108c91416d1','\'\'',NULL,1293517),('3_Saturday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel\'','\'Yu Terada,Kotaro \"@Decamark / @BinaryPoodle\" Osugi\'','DEF CON Workshops_75d4bf3465b42fb03fcc5cfebf9122ee','\'Title: Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W228 (Workshops) - Map
\n
\nDescription:
\n

Endpoint Detection and Response (EDR) systems are key parts of modern security. This workshop provides a guide for custom malware development, C2 customization, defense evasion, and kernel exploitation. We will use Elastic Defend throughout the session. By analyzing detection logs and rules, we will understand what EDR monitors and why payloads are caught step by step.

\n\n

After a short overview of Windows defenses and EDR, we focus on malware development. Participants will implement typical malware techniques, such as APC Injection, Thread Hijacking, Fiber and Module Stomping in multiple languages. Next, we learn about call stack analysis. Attendees will implement Stack Spoofing and Indirect Syscalls to hide execution flows and bypass stack analysis.

\n\n

The workshop then moves to C2 customization using the Havoc C&C framework. By combining custom loaders with C2 source code modifications, participants will bypass static signatures, behavioral rules, and AI detection to successfully establish a C2 session.

\n\n

Finally, we’ll demonstrate the possibilities of Bring Your Own Vulnerable Driver (BYOVD) attacks for the post-exploitation phase. When we have access to the kernel space, we can take more aggressive measures. We’ll use some vulnerable drivers to kill or blind an EDR sensor itself.

\n\nSpeakers:Yu Terada,Kotaro \"@Decamark / @BinaryPoodle\" Osugi
\n
\nSpeakerBio:  Yu Terada
\n

Yu Terada is a security researcher and a red team consultant for Fujitsu. He worked as a SOC Analyst and CSIRT for over five years. In 2021, he joined the company as a Security Researcher. He is primarily involved in developing new attack methods and tools. He also participates in internal red team activities and cyber exercises.\nHe has spoken at Black Hat USA/Europe, BSides Las Vegas, Code Blue, and several conferences in Japan. He holds a Master\'s degree in Computer Science, as well as certifications including OSEP, OSCP, CRTL, CETP, ODPC, CISSP, GIAC, etc.

\n\nSpeakerBio:  Kotaro \"@Decamark / @BinaryPoodle\" Osugi
\n

Kotaro Osugi is a security researcher and a red team consultant who has his profession in reverse-engineering.\nHis research area includes malware analysis and binary exploitation.\nHe has given a speech at BHEU Arsenal about a tool for kernel exploitation.\nOSED and OSEE certified.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_am_ws3_4049
\n\'',NULL,1293518),('3_Saturday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel\'','\'Yu Terada,Kotaro \"@Decamark / @BinaryPoodle\" Osugi\'','DEF CON Workshops_75d4bf3465b42fb03fcc5cfebf9122ee','\'\'',NULL,1293519),('3_Saturday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel\'','\'Yu Terada,Kotaro \"@Decamark / @BinaryPoodle\" Osugi\'','DEF CON Workshops_75d4bf3465b42fb03fcc5cfebf9122ee','\'\'',NULL,1293520),('3_Saturday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel\'','\'Yu Terada,Kotaro \"@Decamark / @BinaryPoodle\" Osugi\'','DEF CON Workshops_75d4bf3465b42fb03fcc5cfebf9122ee','\'\'',NULL,1293521),('3_Saturday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Wi-Fight Club: I am Jack\'s Evil Twin\'','\'James Hawk,Jon \"C4V3M4N\" Milkins,Brian Burnett\'','DEF CON Workshops_b5cc634f57907a0e655526695a399c43','\'Title: Sold Out - Wi-Fight Club: I am Jack\'s Evil Twin
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W222 (Workshops) - Map
\n
\nDescription:
\n

\'Wi-Fight Club: I am Jack\'s Evil Twin\' will teach you how to deploy rogue AP (Evil Twins) in your client\'s environment. Using rogue APs lets you test your client\'s Wireless Intrusion Detection System, passwords, wireless phishing education, and overall wireless security.

\n\n

We will discuss rogue AP Tactics, Techniques, and Procedures, and how / why they work. In this workshop you will set up a CAPTIVE PORTAL, WPA2, and 802.1x rogue AP. We will also go over OWE and WPA3-SAE transition mode attacks.

\n\n

We will walk through a scenario at a client\'s site, then set up a rogue AP to harvest user credentials for the various client networks. We will then crack the harvested credentials. We will finish up with a section on defense. We will be using EAPHAMMER, HOSTAPD-MANA, WIFIPHISHER, and AIRBASE-NG for the rogue AP section. HASHCAT, AIRCRACK-NG, and JOHN for the password cracking section. This workshop is for beginners, but participants should have basic Linux and 802.11 knowledge and be comfortable using virtual machines.

\n\nSpeakers:James Hawk,Jon \"C4V3M4N\" Milkins,Brian Burnett
\n
\nSpeakerBio:  James Hawk
\n

James Hawk (He/Him) is a Principal Consultant with Google Public Sector within Proactive Services. He is the wireless subject matter expert for his team. James has led and contributed to numerous assessments (Red Teams and pentests). He has developed internal training and tool updates for 802.11 for his company. James is a 20-year veteran of the U.S. Army and has over 10 years of hands-on experience in wireless technologies. James is constantly researching/testing 802.11 attacks against his home lab. He is a fan of hockey, LetterKenny, and almost anything sci-fi.

\n\nSpeakerBio:  Jon \"C4V3M4N\" Milkins
\n

Jon Milkins (He/Him) is a principal penetration tester focusing on all types of penetration tests from network-based to web applications and APIs to more recently wireless networks. He has developed training and pentest utilities throughout his career to help advance team capabilities. He is a former Army veteran and is attempting to curate small and efficient rulesets for Hashcat in his free time to aid in wireless hash cracking. In his free time, he enjoys playing and running TTRPGs like Delta Green, password cracking, and making hard cider.

\n\nSpeakerBio:  Brian Burnett
\n

Brian Burnett is the founder of Offensive Technical Solutions (OTS) where he conducts web-application, internal network, and cloud penetration tests. Prior to founding OTS, he served five years in the United States Army, followed by seven years supporting internal teams at Fortune 500 companies. Brian holds degrees in computer science, pentesting, theology, and Russian. He enjoys tinkering with his home lab, collecting certifications, and committing poorly written code. His hobbies include Brazilian Jiu-Jitsu, purchasing unnecessary power tools, and CrossFit.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_am_ws8_4004
\n\'',NULL,1293522),('3_Saturday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Wi-Fight Club: I am Jack\'s Evil Twin\'','\'James Hawk,Jon \"C4V3M4N\" Milkins,Brian Burnett\'','DEF CON Workshops_b5cc634f57907a0e655526695a399c43','\'\'',NULL,1293523),('3_Saturday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Wi-Fight Club: I am Jack\'s Evil Twin\'','\'James Hawk,Jon \"C4V3M4N\" Milkins,Brian Burnett\'','DEF CON Workshops_b5cc634f57907a0e655526695a399c43','\'\'',NULL,1293524),('3_Saturday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Wi-Fight Club: I am Jack\'s Evil Twin\'','\'James Hawk,Jon \"C4V3M4N\" Milkins,Brian Burnett\'','DEF CON Workshops_b5cc634f57907a0e655526695a399c43','\'\'',NULL,1293525),('3_Saturday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them\'','\'Pavan \"pavanreddysec\" Reddy\'','DEF CON Workshops_529b95dccb44a08fa40a908a57bd2517','\'Title: Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W229 (Workshops) - Map
\n
\nDescription:
\n

Most \"AI security\" talks stop at the slide that says \"prompt injection is bad.\" This workshop does the opposite. Attendees spend four hours inside a working, vulnerable production-style AI system - a mock car dealership backed by a real LLM, a real database, and real tool calls - and learn to break it, watch it break, then put it back together with defenses that actually hold.\nYou will: \n(1) manipulate prices and inventory using direct and indirect prompt injection, \n(2) reproduce an EchoLeak-style zero-click data exfiltration against a RAG pipeline, \n(3) execute a model-extraction attack against a deployed classifier, and \nEach of these modules will layer in defenses one at a time to see how the AI reacts. We close by mapping everything to OWASP LLM Top 10, OWASP Agentic Top 10, NIST AI RMF, and MITRE ATLAS.\nBuilt for red teamers handed AI in scope, blue teamers watching agents deploy faster than detections exist, AppSec engineers who used to own the API and now own a chat window, and developers curious what \"prompt injection\" looks like when it costs money. No prior AI-security background required.

\n\nSpeakerBio:  Pavan \"pavanreddysec\" Reddy
\n

Pavan Reddy is principal developer at Automata LLC, leading FIPS 140-3, FedRAMP ATO, and AI security initiatives. He is an independent AI security researcher and educator focused on making secure AI accessible at scale. He founded QBTrain, a free platform for hands-on AI and AI security education. His peer-reviewed work, published at AAAI, ACM, FLAIRS, HCII, ACSAC, and NeurIPS, spans adversarial ML, prompt injection, and foundation model vulnerabilities. He has delivered 25+ talks and workshops at BSides, OWASP, SquadCon, CAPWIC, ACM SIGCITE, NeurIPS Education, FLAIRS, CVPR 2026 and TechMentor at Microsoft HQ. He holds an MS in CS from George Washington University.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_am_ws2_4095
\n\'',NULL,1293526),('3_Saturday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them\'','\'Pavan \"pavanreddysec\" Reddy\'','DEF CON Workshops_529b95dccb44a08fa40a908a57bd2517','\'\'',NULL,1293527),('3_Saturday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them\'','\'Pavan \"pavanreddysec\" Reddy\'','DEF CON Workshops_529b95dccb44a08fa40a908a57bd2517','\'\'',NULL,1293528),('3_Saturday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Words As Weapons: Breaking AI and Agents; Then Securing Them\'','\'Pavan \"pavanreddysec\" Reddy\'','DEF CON Workshops_529b95dccb44a08fa40a908a57bd2517','\'\'',NULL,1293529),('3_Saturday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Building Agentic Reverse Engineering \"Skills\"\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Workshops_1ae92ddd4eca1ead0e9c8cca59962530','\'Title: Sold Out - Building Agentic Reverse Engineering \"Skills\"
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W231 (Workshops) - Map
\n
\nDescription:
\n

Agentic reverse engineering blends interactive binary analysis with autonomous agent workflows. Building on workshops at REcon and DEF CON Singapore, this session introduces Agent Skills, structured bundles of instructions, scripts, and resources that coding agents discover and execute. Skills enable multi-step RE tasks with high accuracy and minimal prompting via workflow capture and progressive disclosure.

\n\n

Participants learn how coding agents operate through iterative loops (generate, execute, inspect, refine) and how Skills plug into these loops. The workshop is hands-on: attendees build a multi-platform driver-analysis Skill automating IOCTL enumeration, dispatch-flow analysis (Windows IRPs, Linux file ops, macOS IOKit), code-flow analysis, and workflow capture. A capstone challenge has participants build a second Skill from scratch.

\n\n

Supports Claude Code, OpenCode, Mistral Vibe, and pi. The instructor provides LLM inference for all attendees, so no paid API keys are required. Students may also use free inference tiers from OpenCode or similar providers.

\n\n

Attendees leave with practical experience to implement agentic RE Skills in their own workflows. Basic familiarity with RE concepts and a laptop with a coding agent installed is all that is needed.

\n\nSpeakerBio:  John \"clearbluejar\" McIntosh
\n

John McIntosh (@clearbluejar) is a security researcher and founder of ClearSecLabs, specializing in reverse engineering, vulnerability research, and AI-assisted binary analysis. He is the author of ghidriff, an open-source Ghidra-based binary diffing engine, and pyghidra-mcp, a headless Ghidra MCP server enabling LLM-driven, project-wide, multi-binary reverse engineering workflows. An active contributor to the Agent Skills ecosystem, John bridges deterministic analysis with AI-driven reasoning to accelerate vulnerability research. He has delivered training and workshops at DEF CON, Black Hat, REcon, Ringzer0, 44CON, Objective by the Sea, and Insomni\'hack, covering topics from practical Windows reverse engineering to building private local LLM RE stacks. His recent work includes the \"Agentic RE\" training at DEF CON Singapore 2026, the MCP Ghidra workshop at REcon 2025, and the \"Supercharging Ghidra\" LLM workshop at Ringzer0 COUNTERMEASURE 2025. With over a decade of offensive security experience, John publishes detailed research on reversing CVEs, building RE tooling, and agentic patch diffing at clearbluejar.github.io. His teaching emphasizes reproducibility, progressive skill-building, and contributor empowerment.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_pm_ws6_4009
\n\'',NULL,1293530),('3_Saturday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Building Agentic Reverse Engineering \"Skills\"\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Workshops_1ae92ddd4eca1ead0e9c8cca59962530','\'\'',NULL,1293531),('3_Saturday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Building Agentic Reverse Engineering \"Skills\"\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Workshops_1ae92ddd4eca1ead0e9c8cca59962530','\'\'',NULL,1293532),('3_Saturday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - Building Agentic Reverse Engineering \"Skills\"\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Workshops_1ae92ddd4eca1ead0e9c8cca59962530','\'\'',NULL,1293533),('3_Saturday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem\'','\'Raunak \"Trouble1\" Parmar,Chirag \"3xpl01tc0d3r\" Savla\'','DEF CON Workshops_02da4ae6a5db2b81b8f747bcbaf5363a','\'Title: Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W228 (Workshops) - Map
\n
\nDescription:
\n

Modern enterprise security has shifted from network boundaries to identity, making Microsoft Entra ID a critical control plane and a prime target for persistence. While credential theft remains common, sophisticated attackers increasingly establish long-term access through identity-layer backdoors that survive password resets and evade traditional monitoring.

\n\n

We will explore how attackers achieve durable persistence in Microsoft Entra ID by abusing service principals, federated identities, passwordless authentication methods, and device trust relationships. The session highlights techniques that remain effective even after common remediation actions like credential rotation and MFA enforcement. Through guided, hands-on scenarios, participants will simulate these identity-layer persistence techniques and understand their real-world impact demonstrating how adversaries integrate into legitimate identity workflows to maintain covert, long-term access without raising immediate suspicion.

\n\n

Participants will step into the role of an adversary and explore how persistence is established and maintained inside Microsoft Entra ID. Rather than focusing on theory, this workshop breaks down real-world attack paths used to retain access beyond initial compromise highlighting techniques that survive password resets, MFA enforcemen

\n\nSpeakers:Raunak \"Trouble1\" Parmar,Chirag \"3xpl01tc0d3r\" Savla
\n
\nSpeakerBio:  Raunak \"Trouble1\" Parmar
\n

Raunak Parmar works as a senior cloud security engineer at White Knight Labs with 6+ years of experience. His areas of interest include web penetration testing, Azure/AWS security, source code review, scripting, and development. He enjoys researching new attack methodologies and creating open-source tools that can be used during cloud red team activities. He has worked extensively on Azure and AWS and is the author of Vajra, AzDevRecon and MsCodePhish. He has spoken at multiple respected security conferences like Black Hat, Defcon, Nullcon, RootCon, HackspaceCon, NorthSec, LeHack , etc and also at local meetups.

\n\nSpeakerBio:  Chirag \"3xpl01tc0d3r\" Savla
\n

Chirag Savla is a Cyber Security professional with 10+ years of experience. His areas of interest include penetration testing, red teaming, azure and active directory security, and post-exploitation research. He prefers to create open-source tools and explore new attack methodologies in his leisure. He has worked extensively on Azure, Active Directory attacks, defense, and bypassing detection mechanisms. He is an author of multiple Open Source tools such as Process Injection, Callidus, etc. He has presented at multiple conferences and local meetups and has trained people in international conferences like Blackhat, BSides Milano, Wild West Hackin’ Fest.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_pm_ws3_4074
\n\'',NULL,1293534),('3_Saturday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem\'','\'Raunak \"Trouble1\" Parmar,Chirag \"3xpl01tc0d3r\" Savla\'','DEF CON Workshops_02da4ae6a5db2b81b8f747bcbaf5363a','\'\'',NULL,1293535),('3_Saturday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem\'','\'Raunak \"Trouble1\" Parmar,Chirag \"3xpl01tc0d3r\" Savla\'','DEF CON Workshops_02da4ae6a5db2b81b8f747bcbaf5363a','\'\'',NULL,1293536),('3_Saturday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Entra ID Persistence - Because Passwords Were Never the Problem\'','\'Raunak \"Trouble1\" Parmar,Chirag \"3xpl01tc0d3r\" Savla\'','DEF CON Workshops_02da4ae6a5db2b81b8f747bcbaf5363a','\'\'',NULL,1293537),('3_Saturday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques\'','\'Abhinav Verma\'','DEF CON Workshops_3b1bb4af282d211678aa6656bfebd7fa','\'Title: Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W229 (Workshops) - Map
\n
\nDescription:
\n

This hands-on workshop explores the offensive security of AI-powered applications where Large Language Models connect to real tools via MCP (Model Context Protocol) servers. Over four hours, participants attack 11 purpose-built AI agents across 9 exercises, exploiting vulnerabilities mapped to the OWASP Top 10 for LLM Applications 2025.

\n\n

You will perform prompt injection (direct and indirect via RAG poisoning), force AI agents to generate malicious SQL/NoSQL queries through MCP tool interfaces, chain path traversal and SSRF through tool-calling parameters, abuse excessive agency via MCP-exposed CRUD operations, trigger stored XSS through LLM output, and achieve remote code execution via a poisoned supply chain, all through natural language conversation.

\n\n

This workshop is ideal for red teamers, penetration testers, security engineers, and developers building with LLMs. No prior AI or ML experience is required; every technique is demonstrated before the hands-on lab. Just bring a laptop with a browser.

\n\n

You walk away with practical experience exploiting 93 attack objectives against live LLM agents, a clear understanding of how traditional web vulnerabilities are amplified through AI tool-calling architectures, and the instincts to spot these risks in your own AI deployments.

\n\nSpeakerBio:  Abhinav Verma
\n

Abhinav Verma is a Senior Staff Security Engineer at Intuit Inc. with 15+ years of experience across AI security, offensive security, red teaming, product security, and security operations. He currently leads AI security architecture reviews, AI penetration testing, and vulnerability management programs, with a focus on AI security, AI threat modeling, and securing large-scale cloud platforms.

\n\n

Over the course of his career at Intuit, he has built security automation, scaled continuous security scanning across thousands of assets, led secure design reviews for platforms serving millions of customers, and developed secure coding programs that have helped thousands of engineers shift security left. Abhinav was formerly an independent security researcher and has identified and reported vulnerabilities in numerous major online services and technology companies.

\n\n

He holds certifications including OSEP, OSCP, OSWP, GWAPT and CEH. Outside of work, Abhinav is a passionate gamer, a trained chef, an avid camper, and a mentor to aspiring offensive security practitioners.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_pm_ws2_4022
\n\'',NULL,1293538),('3_Saturday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques\'','\'Abhinav Verma\'','DEF CON Workshops_3b1bb4af282d211678aa6656bfebd7fa','\'\'',NULL,1293539),('3_Saturday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques\'','\'Abhinav Verma\'','DEF CON Workshops_3b1bb4af282d211678aa6656bfebd7fa','\'\'',NULL,1293540),('3_Saturday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques\'','\'Abhinav Verma\'','DEF CON Workshops_3b1bb4af282d211678aa6656bfebd7fa','\'\'',NULL,1293541),('3_Saturday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices\'','\'wasabi,Ø1,Tokugero\'','DEF CON Workshops_1aff3ae1b85ac5f14949b4230e0547cc','\'Title: Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W222 (Workshops) - Map
\n
\nDescription:
\n

\"Don\'t plug in devices you don\'t trust.\" It\'s one of the most repeated pieces of security advice in the\nindustry. What actually happens when a malicious USB device is plugged in? How does it work? This hands-on, four-hour workshop answers those questions by putting the tools directly in attendees\'\nhands. Using O.MG Devices and the DuckyScript v3 scripting language, participants will learn the\nfundamentals of Human Interface Device (HID) attacks from the ground up. Starting from USB protocol basics all the way through real payload design, delivery strategy, and advanced techniques including wireless triggering, C2 integration, and air-gapped exfiltration (using HIDX StealthLink). The class is beginner-friendly and builds progressively: no prior red teaming experience is required. Only a DuckyScript v3 device is required. Attendees will leave with working scripts, a framework for payload design, and an\nunderstanding of what attackers and defenders need to look for. We will cover OpSec, detection (and evasion), and how accessibility-first design thinking can make both attackers and defenders more effective.

\n\nSpeakers:wasabi,Ø1,Tokugero
\n
\nSpeakerBio:  wasabi
\n

wasabi is a researcher, tinkerer, and professor of cybersecurity whose work spans IoT and embedded\nsystems, cloud infrastructure, and offensive tooling. Their research focuses on uncovering systemic weaknesses across modern embedded environments, with an emphasis on practical exploitation and defensive resilience. When not tinkering, wasabi spends most of his time outdoors in nature.

\n\nSpeakerBio:  Ø1
\n

Ø1 is a seasoned offensive security professional who turned a lifelong passion into a dynamic career. Beginning as a machine operator, he transitioned into the world of cybersecurity, where he has since traveled globally, conducting and leading numerous penetration tests and red team engagements. With a wealth of hands-on experience, he excels at identifying vulnerabilities and strengthening defenses for organizations worldwide. In 2022, he joined the O.MG team, balancing this role alongside his primary job to contribute to product testing, documentation, tooling, and customer support.\nBeyond his professional pursuits, √ò1 is a devoted cat father with a love for guns, cars, BBQ, and gardening.

\n\nSpeakerBio:  Tokugero
\n

Tokugero is a Site Reliability Engineer and Cloud Architect focused on incident response, operations engineering, and running resilient infrastructure at scale. He works across the full ops stack — from system design and automation to the messy realities of keeping production healthy.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_pm_ws8_4037
\n\'',NULL,1293542),('3_Saturday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices\'','\'wasabi,Ø1,Tokugero\'','DEF CON Workshops_1aff3ae1b85ac5f14949b4230e0547cc','\'\'',NULL,1293543),('3_Saturday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices\'','\'wasabi,Ø1,Tokugero\'','DEF CON Workshops_1aff3ae1b85ac5f14949b4230e0547cc','\'\'',NULL,1293544),('3_Saturday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices\'','\'wasabi,Ø1,Tokugero\'','DEF CON Workshops_1aff3ae1b85ac5f14949b4230e0547cc','\'\'',NULL,1293545),('3_Saturday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Intro to Writing Windows Malware with Rust!\'','\'iDigitalFlame,Daniel Bravo\'','DEF CON Workshops_058308ab30db53393ed354f6371c7702','\'Title: Sold Out - Intro to Writing Windows Malware with Rust!
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W230 (Workshops) - Map
\n
\nDescription:
\n

In the Information Security news space, we often hear about the cool malware and\ntools nation states and APTs develop. While there are many tools out there that\n\"do the thing\", have you ever wonder how it \"does the thing\"? Instead of just\nusing tools and scripts that sound cool, why not make them?

\n\n

Using the Rust programming language, you\'ll be taken step-by-step into\nbuilding your own Windows malware! We\'ll break down the process and work our\nway into more complex tasks. From a simple, no-imports binary we\'ll slowly work\ninto loading and executing Windows API functions without ever calling\n\"LoadLibrary\" or \"GetProcAddress\" while not touching a single Rust \"std::*\"\nfunction or importing any extra crates!

\n\n

You\'ll be introduced into Windows concepts like the Process Environment Block (PEB),\nthe Thread Environment Block (TEB) and how we can use them to our advantage! At\nthe end of this workshop, you\'ll be able to build binaries without any imports\nwhile doing fun tricks like shellcode injection!

\n\n

Some of the topics we\'ll touch on are:

\n\n
    \n
  • Assembly!
  • \n
  • Rust Allocators
  • \n
  • Windows Structs
  • \n
  • API Function Calls
  • \n
  • Binary File Inspection
  • \n
\n\nSpeakers:iDigitalFlame,Daniel Bravo
\n
\nSpeakerBio:  iDigitalFlame
\n

iDigitalFlame is an experienced security researcher that uses his programming skills to expand his abilities and provide teams with the tools needed to complete any engagement. Outside of work, his passion for open source and knowledge sharing has led to the creation of many unique tools and resources. iDigitalFlame also uses his skills to help power many CTFs, including the ProsVJoes CTF at BSidesLV, where he leads the Red Team and provides the platform for Red operations. iDigitalFlame has spoken before at BSidesDE and BSidesLV about cool things learnt in his research like AV evasion or releases open source software like ThunderStorm, a custom C2 platform used in many CTFs he operates in.

\n\nSpeakerBio:  Daniel Bravo
\n

Daniel is a self-taught programmer who later earned a B.S. in Computer Science from the University of Maryland. He likes to understand how software works by decompiling binaries and reverse engineering APIs, whether they were meant to be understood or not. Daniel also enjoys working on geospatial projects and web scraping tools, particularly extracting and reconstructing data from mobile platforms. His other interests also include compiler theory, automated reasoning, and verification-aware languages.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_pm_ws1_4071
\n\'',NULL,1293546),('3_Saturday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Intro to Writing Windows Malware with Rust!\'','\'iDigitalFlame,Daniel Bravo\'','DEF CON Workshops_058308ab30db53393ed354f6371c7702','\'\'',NULL,1293547),('3_Saturday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Intro to Writing Windows Malware with Rust!\'','\'iDigitalFlame,Daniel Bravo\'','DEF CON Workshops_058308ab30db53393ed354f6371c7702','\'\'',NULL,1293548),('3_Saturday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - Intro to Writing Windows Malware with Rust!\'','\'iDigitalFlame,Daniel Bravo\'','DEF CON Workshops_058308ab30db53393ed354f6371c7702','\'\'',NULL,1293549),('3_Saturday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It\'','\'Wesley McGrew\'','DEF CON Workshops_7cda1d61f26e11b96134ef310efa326d','\'Title: Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W232 (Workshops) - Map
\n
\nDescription:
\nSoftware reverse engineering is a fundamental skill: a prerequisite
\nto engaging with many fields of study in computer security that depend
\non low-level knowledge. Malware analysis, vulnerability research,
\noffensive tool development, and digital forensics all involve the
\nanalysis of code which has been compiled, obfuscated, or otherwise
\nstripped of useful names, data types, comments, and other
\nhuman-readable information. Without the ability to read disassembled
\ncode, you will not be able to understand code that your computer will
\nhappily execute.
\n\n

In this workshop, I will guide you through learning to read\ndisassembled code while you learn C. We will progress through the C\nprogramming language\'s constructs with as few assumptions as possible\nabout your background, and at each stage we will reverse engineer the\ncompiler\'s output in Ghidra and trace through with a debugger to\nunderstand the generated code. You do not need any prior experience in\nprogramming.

\n\n

I will also be demonstrating useful techniques for using\nlocally-hosted large language models to aid in the learning process.\nUse AI to improve your own skillset, rather than using it to do the\nwork for you.

\n\nSpeakerBio:  Wesley McGrew, Senior Cyber Fellow at MartinFed
\n

Dr. Wesley McGrew directs research, development, reverse engineering, and offensive cyber operations as Senior Cybersecurity Fellow for MartinFederal. He has presented at DEF CON and Black Hat USA on topics of penetration testing, malware analysis, critical infrastructure, and vintage computing, and has taught self-designed courses on reverse engineering and cyber operations at Mississippi State University. Wesley has a Ph.D. in Computer Science from Mississippi State University for his research in vulnerability analysis of SCADA HMI systems. He has entertained audiences at many DEF CON parties as a house music DJ, as well.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_pm_ws5_4002
\n\'',NULL,1293550),('3_Saturday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It\'','\'Wesley McGrew\'','DEF CON Workshops_7cda1d61f26e11b96134ef310efa326d','\'\'',NULL,1293551),('3_Saturday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It\'','\'Wesley McGrew\'','DEF CON Workshops_7cda1d61f26e11b96134ef310efa326d','\'\'',NULL,1293552),('3_Saturday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Learning to Reverse Engineer Compiled C as We Learn to Write It\'','\'Wesley McGrew\'','DEF CON Workshops_7cda1d61f26e11b96134ef310efa326d','\'\'',NULL,1293553),('3_Saturday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Purple Teaming Industrial Control Systems\'','\'Arnaud SOULLIE,Alexandrine Torrents\'','DEF CON Workshops_84b88c1f6df7578b516dc8c41d24dd24','\'Title: Sold Out - Purple Teaming Industrial Control Systems
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W225 (Workshops) - Map
\n
\nDescription:
\n

Security monitoring is often presented as the silver bullet for Industrial Control System (ICS) security — but how effective is it against realistic adversaries?\nIn this 4-hour, hands-on workshop, participants will use CALDERA, the open-source adversary emulation framework, to conduct purple-team exercises against simulated & live industrial environments. Attendees will simulate real-world IT and OT attacks, observe what is (and is not) detected across EDR, logs, and network monitoring, and map results to MITRE ATT&CK for ICS.\nRather than focusing on exploitation alone, this workshop teaches a repeatable methodology to assess detection coverage, identify OT blind spots, and improve monitoring strategies. Participants leave with concrete techniques they can apply in their own environments — from tabletop exercises to continuous detection testing.

\n\nSpeakers:Arnaud SOULLIE,Alexandrine Torrents
\n
\nSpeakerBio:  Arnaud SOULLIE
\n

Arnaud Soullie is a Senior Manager at Wavestone. He has over 15 years of experience in security assessments and penetration testing, with 10 years specializing in Industrial Control Systems cybersecurity. He has delivered talks and workshops at DEF CON, Black Hat Europe, BruCON, CS3STHLM, BSides Las Vegas, and others. He is the creator of the DYODE open-source data diode project and has been teaching ICS cybersecurity since 2015.

\n\nSpeakerBio:  Alexandrine Torrents
\n

Alexandrine Torrents is a cybersecurity expert at Wavestone. She started as a penetration tester, and then specialized in OT cybersecurity. She is IEC 62443 certified. She performed dozens of OT cybersecurity assessments across various industries & worked on OT models to perform attacks on PLCs & SCADA systems. Alexandrine also helps secure OT both at technical & organization levels: secure architecture, system hardening, IAM, cyber resilience, detection, governance, awareness & training, risk assessment, cyber by design, etc. Alexandrine works with different CISOs on their OT cybersecurity roadmaps & programs at different scales of large industrial companies: site, business units, Group with worldwide scope. Alexandrine also gives training on OT cybersecurity.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_pm_ws7_4030
\n\'',NULL,1293554),('3_Saturday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Purple Teaming Industrial Control Systems\'','\'Arnaud SOULLIE,Alexandrine Torrents\'','DEF CON Workshops_84b88c1f6df7578b516dc8c41d24dd24','\'\'',NULL,1293555),('3_Saturday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Purple Teaming Industrial Control Systems\'','\'Arnaud SOULLIE,Alexandrine Torrents\'','DEF CON Workshops_84b88c1f6df7578b516dc8c41d24dd24','\'\'',NULL,1293556),('3_Saturday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Purple Teaming Industrial Control Systems\'','\'Arnaud SOULLIE,Alexandrine Torrents\'','DEF CON Workshops_84b88c1f6df7578b516dc8c41d24dd24','\'\'',NULL,1293557),('3_Saturday','14','14:00','17:59','N','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites\'','\'Nitay Bachrach,Cynthia Ardman\'','DEF CON Workshops_e2821b8ac1b35d452503f72e8451902b','\'Title: Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Saturday, Aug 8, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W233 (Workshops) - Map
\n
\nDescription:
\n

Salesforce Sites are one of the most under-tested attack surfaces in enterprise security. When pentesters encounter them, most skip past - the Aura framework doesn\'t behave like a standard web application, and standard web testing techniques don\'t apply. Salesforce sites run on proprietary frameworks (Aura and LWR) with their own API surfaces, access models, and injection patterns. In March 2026, ShinyHunters demonstrated what that blind spot costs: sensitive data exfiltrated from hundreds of organizations through sites no one had tested.

\n\n

This workshop teaches pentesters and red teamers a complete offensive methodology for Salesforce Experience Sites, going well past the record enumeration that makes up most public guidance on the topic.

\n\n

Attendees will enumerate objects and dump records via the Aura API, then learn to identify and invoke custom Apex controllers running in system mode - controllers that bypass standard access management mechanisms, and which are surprisingly common and criminally underexplored. We cover SOQL injection in depth: why normal SQL injection tests fail, and how to exploit it. We cover deterministic route enumeration as an unauthenticated user, and LWR sites - Salesforce\'s next-generation framework - including the release of LWRed, a new open-source scanner built specifically for them.

\n\nSpeakers:Nitay Bachrach,Cynthia Ardman
\n
\nSpeakerBio:  Nitay Bachrach
\n

Nitay Bachrach is a security researcher at Reco (Tel Aviv, Israel) specializing in offensive security research against enterprise SaaS platforms. He is a pioneer in Salesforce offensive security: he published new exploitation methods for the Aura framework, discovered the Einstein Wormhole vulnerability and a Public Link exploitation technique in Salesforce\'s platform, and identified and responsibly disclosed critical vulnerabilities in dozens of major Salesforce deployments. His research extends to Okta, GCP, and other enterprise platforms. He spoke at Insomni\'hack on \"Neo4jection\" - novel graph injection techniques against Neo4j. In May 2026, he is running a Salesforce-focused CTF event in Tel Aviv. The LWR exploitation methodology and LWRed tool premiering at this workshop represent previously unpublished research from original work on Salesforce\'s next-generation Experience Site framework.

\n\nSpeakerBio:  Cynthia Ardman
\n

Cynthia has spent 10+ years making life harder for attackers. She currently builds threat detection at Reco, and previously did the same at AppOmni, AWS, and Snowflake, places where \"the blast radius\" isn\'t a metaphor. At AWS she developed MITRE ATT&CK-mapped detection for corporate infrastructure, partnered with the Red Team to close gaps they found, and led a project that knocked hacking tool presence down by 30%. At Snowflake she ran blue team ops and built the SQL-based alerting pipeline from scratch. At StubHub she hunted down an active intrusion by tracing logs across systems and performed the root cause analysis so it wouldn\'t happen twice. She came up through desktop support, building Linux blade servers and remediating malware on customer machines, the kind of work that teaches you what actually breaks. CISSP. Splunk ES Admin. Writes Python when she has to and JSONata when nobody\'s looking.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sat_pm_ws4_4032
\n\'',NULL,1293558),('3_Saturday','15','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites\'','\'Nitay Bachrach,Cynthia Ardman\'','DEF CON Workshops_e2821b8ac1b35d452503f72e8451902b','\'\'',NULL,1293559),('3_Saturday','16','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites\'','\'Nitay Bachrach,Cynthia Ardman\'','DEF CON Workshops_e2821b8ac1b35d452503f72e8451902b','\'\'',NULL,1293560),('3_Saturday','17','14:00','17:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Salesforce Apex Predator: Breaking Salesforce Sites\'','\'Nitay Bachrach,Cynthia Ardman\'','DEF CON Workshops_e2821b8ac1b35d452503f72e8451902b','\'\'',NULL,1293561),('4_Sunday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Attacking Cloud APIs from the IoT Edge\'','\'Rodney \"BenevolentWorm\" Beede\'','DEF CON Workshops_eb1829ddf4db06ec976f9e81199c3dd5','\'Title: Sold Out - Attacking Cloud APIs from the IoT Edge
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Sunday, Aug 9, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W222 (Workshops) - Map
\n
\nDescription:
\n

This course covers attacking the cloud REST APIs and IoT provider (cloud customer responsibility) configurations to demonstrate data exfiltration, remote code execution, and lateral movement. Hands-on experience with using an already compromised, simulated IoT device as well as navigating pen testing (fuzzing) of the common protocols (i.e. MQTT, HTTP) will be covered.

\n\n

Workshop goal\nTeach students practical, repeatable techniques to observe, extract, and abuse cloud API credentials and logic from the vantage of a compromised IoT device. Students will leave able to enumerate device‚Üícloud flows, extract tokens, fuzz REST/MQTT endpoints, and demonstrate controlled lateral movement inside an isolated cloud tenant.

\n\nSpeakerBio:  Rodney \"BenevolentWorm\" Beede
\n

Rodney is an offensive security red team pen tester. He has specialized in cloud, web, and IoT security for over 18 years. He has spoken at multiple conferences (BSides, Def Con, Black Hat) on topics ranging from cloud security engineering to IoT device hacking. Rodney has been accredited with multiple CVEs for web vulnerabilities in products such as Wi-Fi hardware and security appliances. He started his career in enterprise web application software development but shifted to the security industry with this master\'s thesis research project \"A Framework for Benevolent Computer Worms\" 2012. Website: https://www.rodneybeede.com/curriculum%20vitae/bio.html

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sun_am_ws7_4023
\n\'',NULL,1293562),('4_Sunday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Attacking Cloud APIs from the IoT Edge\'','\'Rodney \"BenevolentWorm\" Beede\'','DEF CON Workshops_eb1829ddf4db06ec976f9e81199c3dd5','\'\'',NULL,1293563),('4_Sunday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Attacking Cloud APIs from the IoT Edge\'','\'Rodney \"BenevolentWorm\" Beede\'','DEF CON Workshops_eb1829ddf4db06ec976f9e81199c3dd5','\'\'',NULL,1293564),('4_Sunday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W222 (Workshops)','\'Sold Out - Attacking Cloud APIs from the IoT Edge\'','\'Rodney \"BenevolentWorm\" Beede\'','DEF CON Workshops_eb1829ddf4db06ec976f9e81199c3dd5','\'\'',NULL,1293565),('4_Sunday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more.\'','\'Dallas\'','DEF CON Workshops_b4bab5437653b51c611b5c3ecfa5d23e','\'Title: Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more.
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Sunday, Aug 9, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W225 (Workshops) - Map
\n
\nDescription:
\n

You will receive a free hardware kit, documentation, and class introduction to the same hardware configuration used by hundreds of hacking hardware tools as their main core.\nWe will cover Wifi Hacking on both 2 and 5ghz, Bluetooth hacking, packet capture, Flipper interface (bring yours if you have one), Sensor integration (also included), Mesh networking, point to point communications and more.\nRequirements: Laptop, Fully charged, USB-A interface, Windows OS (we will discuss MAC and Linux, but you will need to have knowledge and permissions to install tools).\nYou can attend without above and still get kit, but it will not be hands on. All information will be published after the workshop if you don’t have a laptop.\nYou will get a modern ESP32, Sensor, breadboard, USB cable, wires and more during the workshop.

\n\nSpeakerBio:  Dallas
\n

Dallas has been involved in hacking since early teens, which translates to sometime in the 80’s. Mentored by Satellite and Ham hackers, has been involved in a few organizations including all levels of government, 3 letter agencies, serving as Chief security officer, CISO, and technical manager of multiple world-wide organizations. Banking, Energy, Space, Telecom, Government and manufacturing. Elected, re-elected, served and got the trophy. OG Considered an expert in Pen testing, variety of related and unrelated technology – occasionally serving 15+ years as a Defcon security goon, and around 10 for B-sides organizations. Alexa Park being his first Defcon. Mostly bored, but thinks AI is kind of fun and enjoys giving back to the community. Doing his best to not get arrested, and share knowledge with those interested in seeking it.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sun_am_ws8_4069
\n\'',NULL,1293566),('4_Sunday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more.\'','\'Dallas\'','DEF CON Workshops_b4bab5437653b51c611b5c3ecfa5d23e','\'\'',NULL,1293567),('4_Sunday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more.\'','\'Dallas\'','DEF CON Workshops_b4bab5437653b51c611b5c3ecfa5d23e','\'\'',NULL,1293568),('4_Sunday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W225 (Workshops)','\'Sold Out - Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more.\'','\'Dallas\'','DEF CON Workshops_b4bab5437653b51c611b5c3ecfa5d23e','\'\'',NULL,1293569),('4_Sunday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It\'','\'Ricardo Sanchez,Daniel Malvaceda\'','DEF CON Workshops_632527e5af8f994ff77a76174f1d3444','\'Title: Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Sunday, Aug 9, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W230 (Workshops) - Map
\n
\nDescription:
\n

GitHub Actions has become the de facto automation layer for modern software, and the de facto attack surface. In 2025, a single compromised Action leaked secrets across 23,000 repositories. One year later, the TeamPCP group ran the same playbook at scale by compromising Trivy\'s actions. Different victims, same root cause: a CI/CD pipeline that trusted what it shouldn\'t.

\n\n

In this hands-on workshop, participants will build a complete end-to-end attack chain in a controlled lab environment, emulating adversary TTPs observed in recent GitHub Actions breaches. From initial access through malicious workflow manipulation to secret exfiltration, each phase is paired with detection and analysis techniques to bridge offensive and defensive perspectives.

\n\n

Whether you\'re on a red or purple team looking to simulate attacker behavior, or part of a blue team (AppSec or DevSecOps) aiming to harden CI/CD pipelines, this workshop delivers practical, real-world skills grounded in today’s evolving threat landscape.

\n\nSpeakers:Ricardo Sanchez,Daniel Malvaceda
\n
\nSpeakerBio:  Ricardo Sanchez
\n

Ricardo Sanchez is an accomplished cybersecurity professional with a passion for empowering others through knowledge sharing. He has built his career designing and implementing innovative technology strategies for threat intelligence, detection engineering, and threat hunting to combat evolving cyber threats.\nCurrently, Ricardo leads the Application Security (AppSec) practice at a leading insurance company in Peru, where he works closely with DevSecOps teams to enhance security across the software development lifecycle (SDLC) and supply chain.\nCommitted to lifelong learning, Ricardo thrives on analyzing malware and staying at the forefront of cybersecurity advancements.

\n\nSpeakerBio:  Daniel Malvaceda
\n

Daniel Malvaceda is a security architect who spends most of his time figuring out how CI/CD pipelines and supply chains actually fail, then writes it up so others don\'t have to learn it the hard way. Lately he\'s also poking at AI/LLM agents, since pipelines aren\'t the only thing shipping untrusted code anymore. He co-founded pipebreach.com, where real-world supply chain attacks get reproduced, dissected, and written up for everyone else. He also co-organizes the DevSecOps village at Ekoparty (Argentina and Miami), and has dragged these same topics to stages at Ekoparty, DevOps Days, and 8.8 Security Conference. If a pipeline can be weaponized, he wants to know about it first.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sun_am_ws1_4043
\n\'',NULL,1293570),('4_Sunday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It\'','\'Ricardo Sanchez,Daniel Malvaceda\'','DEF CON Workshops_632527e5af8f994ff77a76174f1d3444','\'\'',NULL,1293571),('4_Sunday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It\'','\'Ricardo Sanchez,Daniel Malvaceda\'','DEF CON Workshops_632527e5af8f994ff77a76174f1d3444','\'\'',NULL,1293572),('4_Sunday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W230 (Workshops)','\'Sold Out - CI/CD Weaponization: Build It, Deploy It, Own It\'','\'Ricardo Sanchez,Daniel Malvaceda\'','DEF CON Workshops_632527e5af8f994ff77a76174f1d3444','\'\'',NULL,1293573),('4_Sunday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Creating Shellcode for Hackers\'','\'Bramwell \"Bw3ll\" Brizendine,Austin \"quantumite\" Norby,Micah Flack\'','DEF CON Workshops_68c8fc40a0cf6b66b6c2bebf75107eee','\'Title: Sold Out - Creating Shellcode for Hackers
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Sunday, Aug 9, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W232 (Workshops) - Map
\n
\nDescription:
\n

Creating shellcode is for the brave! This workshop takes a modern approach to the time-honored tradition of Windows shellcode creation. Intended for those with intermediate to advanced knowledge, we will refresh x86 assembly and cover Windows internals.

\n\n

You will create Win32/WoW64 shellcode with NASM before moving onto intermediate, multi-API shellcode. Along the way, we will cover GetPC, position independence, bad characters, calling conventions, stack discipline, manual API resolution through the PEB/TEB, export walking, name/hash-based resolution, strings, and passing handles or pointers between calls.

\n\n

For evasion, we will explore manual/automated encoding techniques, making our shellcode self-modifying. We will also cover advanced techniques, including direct Windows syscalls with ShellWasp. You will learn Windows structures, native API parameter handling, and creating persistence with syscalls. Expect to be made privy to many shellcoding tips and tricks to bring out the best in your shellcode.

\n\n

By the end, you\'ll be able to: Create Windows shellcode using NASM; launch and debug it; resolve and chain WinAPIs by name or hash; obfuscate and encode shellcode; integrate direct syscalls with ShellWasp.

\n\n

Prep: Study x86 assembly and basic Windows debugging. A VM will be provided. Required: modern PC (Intel) / VM

\n\nSpeakers:Bramwell \"Bw3ll\" Brizendine,Austin \"quantumite\" Norby,Micah Flack
\n
\nSpeakerBio:  Bramwell \"Bw3ll\" Brizendine
\n

Dr. Bramwell Brizendine has a Ph.D. in Cyber Operations and is the Director of the VERONA Lab. Bramwell has regularly spoken at DEFCON and presented at all regional editions of Black Hat (USA, Europe, Asia, MEA), as well as at Hack in the Box Amsterdam, Virus Bulletin, and Wild West Hackin\' Fest. Bramwell received a $300,000 NSA research grant to create the SHAREM shellcode analysis framework, which brings unprecedented capabilities to shellcode analysis and $500,000 as a 2025 DARPA YFA recipient for a PE file emulation framework. He has additionally authored ShellWasp, which facilitates using Windows syscalls in shellcode, as well as two code-reuse attack frameworks, ROP ROCKET and JOP ROCKET. Bramwell has previously taught undergraduate, master\'s, and Ph.D. courses on software exploitation, reverse engineering, offensive security, and malware analysis. He currently teaches cybersecurity courses at the University of Alabama in Huntsville.

\n\nSpeakerBio:  Austin \"quantumite\" Norby
\n

Dr. Austin Norby is a seasoned cybersecurity professional with over a decade of experience supporting the Department of Defense. He earned his bachelor\'s degrees in mathematics and computer science from the University of Minnesota, a master\'s degree from the Naval Postgraduate School, and a Doctorate in Cyber Operations from Dakota State University, specializing in anti-debugging techniques. Currently, Dr. Norby serves as the Director of Internal Research and Development at Bogart Associates, where he is responsible for spearheading the creation of advanced cybersecurity solutions for government use. His technical proficiencies include reverse engineering, malware analysis, and software engineering, with a strong focus on developing robust cyber capabilities in C, C++, Intel assembly, and Python.

\n\nSpeakerBio:  Micah Flack
\n

Micah Flack is a cybersecurity researcher at Idaho National Laboratory, where his work spans vulnerability research, firmware and hardware analysis, malware forensics, exploit development, and reverse engineering across multiple platforms and architectures. He is currently pursuing a Ph.D. in Cyber Operations at Dakota State University, with research interests rooted in applied cybersecurity, software exploitation, malware analysis, and shellcoding. Micah also holds both a Master’s degree in Computer Science and a Bachelor’s degree in Cyber Operations from DSU, where he was active in cybersecurity research and competitions. Micah brings a hands-on perspective from his varied experiences in working with assembly, payload development, embedded systems, and offensive security research.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sun_am_ws5_4055
\n\'',NULL,1293574),('4_Sunday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Creating Shellcode for Hackers\'','\'Bramwell \"Bw3ll\" Brizendine,Austin \"quantumite\" Norby,Micah Flack\'','DEF CON Workshops_68c8fc40a0cf6b66b6c2bebf75107eee','\'\'',NULL,1293575),('4_Sunday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Creating Shellcode for Hackers\'','\'Bramwell \"Bw3ll\" Brizendine,Austin \"quantumite\" Norby,Micah Flack\'','DEF CON Workshops_68c8fc40a0cf6b66b6c2bebf75107eee','\'\'',NULL,1293576),('4_Sunday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W232 (Workshops)','\'Sold Out - Creating Shellcode for Hackers\'','\'Bramwell \"Bw3ll\" Brizendine,Austin \"quantumite\" Norby,Micah Flack\'','DEF CON Workshops_68c8fc40a0cf6b66b6c2bebf75107eee','\'\'',NULL,1293577),('4_Sunday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - ICS Hack \'n Track\'','\'Pedro Cabrera,Hannes \"hercules_hannes\" Heck,Sam Miorelli,Jordan Sanchez\'','DEF CON Workshops_231b5b6cc51a97fe4a2047bebb86adb3','\'Title: Sold Out - ICS Hack \'n Track
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Sunday, Aug 9, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W231 (Workshops) - Map
\n
\nDescription:
\n

OT attacks are often discussed but rarely demonstrated - in this workshop we use Caldera for OT to demonstrate realistic attack vectors for Distributed Control Systems used in power plants and other critical infrastructure, as well as how FOSS tools like Malcolm give defenders the information needed to detect blast radius and impacts.

\n\nSpeakers:Pedro Cabrera,Hannes \"hercules_hannes\" Heck,Sam Miorelli,Jordan Sanchez
\n
\nSpeakerBio:  Pedro Cabrera
\n

Pedro Cabrera is an OT cybersecurity professional and Omnivise Cybersecurity Solutions Architect at Siemens Energy. He specializes in industrial control systems and adversary simulation, focusing on bridging the gap between traditional IT security and operational technology through practical, real-world demonstrations. He has developed custom tooling to simulate PLC interactions and highlight detection challenges in OT environments. His work centers on improving visibility, strengthening defenses, and making complex security concepts more accessible.

\n\nSpeakerBio:  Hannes \"hercules_hannes\" Heck
\n

Hannes is an OT security practitioner currently completing a Bachelor\'s degree in Cybersecurity, with a thesis focused on Network Detection and Response systems including Malcolm. Active in the technology field since 2018, when he began a formal computer science apprenticeship, he has progressively deepened his specialization in cybersecurity and currently works at Siemens Energy in an OT Security role focused on solution architecture for industrial environments. He has presented technical topics in both academic and enterprise settings and brings direct hands-on experience with network traffic analysis, industrial control system design, and adversary emulation platforms to this workshop.

\n\nSpeakerBio:  Sam Miorelli
\n

Sam Miorelli is the Global Head of Innovation and Customer Success for Siemens Energy Omnivise Cybersecurity. By training he is a mechanical engineer and a lawyer. Prior to his involvement with OT cybersecurity, Sam was the primary lawyer for several billion dollars per year of energy and industrial automation transactions at Siemens worldwide.

\n\nSpeakerBio:  Jordan Sanchez
\n

Jordan Sanchez is a Cybersecurity Fellow at Siemens Energy, where he has spent three years doing R&D in OT and ICS security. Graduating from the University of Central Florida with a degree in Computer Science, he conducted undergraduate research on dependency downgrade vulnerabilities in the Android build system. Jordan is joining Amazon as a Security Engineer in September 2026.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sun_am_ws6_4085
\n\'',NULL,1293578),('4_Sunday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - ICS Hack \'n Track\'','\'Pedro Cabrera,Hannes \"hercules_hannes\" Heck,Sam Miorelli,Jordan Sanchez\'','DEF CON Workshops_231b5b6cc51a97fe4a2047bebb86adb3','\'\'',NULL,1293579),('4_Sunday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - ICS Hack \'n Track\'','\'Pedro Cabrera,Hannes \"hercules_hannes\" Heck,Sam Miorelli,Jordan Sanchez\'','DEF CON Workshops_231b5b6cc51a97fe4a2047bebb86adb3','\'\'',NULL,1293580),('4_Sunday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W231 (Workshops)','\'Sold Out - ICS Hack \'n Track\'','\'Pedro Cabrera,Hannes \"hercules_hannes\" Heck,Sam Miorelli,Jordan Sanchez\'','DEF CON Workshops_231b5b6cc51a97fe4a2047bebb86adb3','\'\'',NULL,1293581),('4_Sunday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers\'','\'Rushikesh Nandedkar\'','DEF CON Workshops_257d0a87df4b6718427104c924ba02b4','\'Title: Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Sunday, Aug 9, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W233 (Workshops) - Map
\n
\nDescription:
\n

Cyber Threat Intelligence is the most overspecified and underspecified\ndiscipline in security. Every vendor sells a feed. Every conference has\na track. Every blog post claims attribution. And yet - most blue teams\nstill drown in IOCs they cannot operationalize, and most aspiring threat\nresearchers do not know how to pivot from a single sample to a\ndiscovered campaign.

\n\n

This workshop fixes both problems in four hours, fully offline, with\nevery minute of those four hours spent on content rather than setup,\nand without distributing a single piece of malware.

\n\nSpeakerBio:  Rushikesh Nandedkar
\n

Rushikesh is a researcher. Having more than 10 years of experience under his belt, his assignments have always been pointed towards reducing the state of insecurity for information. His research papers were accepted at the nullcon \'14 \'18 \'20 \'21, BruCON \'16 \'17 \'18 \'19 \'21, Blackhat USA Arsenal \'18 \'19 \'25, DEFCON 24 26 27, x33fcon \'17 \'18 \'20 \'21, BSides Delhi \'17 \'20, c0c0n \'17 \'25, HITCON \'14, NCACNS \'13 + co-author of \"DARWIN\" (use cases for covert wireless), \"DECEPTICON\", an intelligent evil-twin and \"SASTRI\", Plug and Play VM for SAST and author of ARC (Artefact Reuse Comparator) and Q-TIP (QR Code Threat Inspection Platform). Being an avid CTF player, for him, solace is messing up with packets, frames, and shellcodes while attempting to reach the state of void *.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sun_am_ws4_4075
\n\'',NULL,1293582),('4_Sunday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers\'','\'Rushikesh Nandedkar\'','DEF CON Workshops_257d0a87df4b6718427104c924ba02b4','\'\'',NULL,1293583),('4_Sunday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers\'','\'Rushikesh Nandedkar\'','DEF CON Workshops_257d0a87df4b6718427104c924ba02b4','\'\'',NULL,1293584),('4_Sunday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W233 (Workshops)','\'Sold Out - Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams and Threat Researchers\'','\'Rushikesh Nandedkar\'','DEF CON Workshops_257d0a87df4b6718427104c924ba02b4','\'\'',NULL,1293585),('4_Sunday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Post-Quantum Cryptography (PQC) for Hackers\'','\'Eric \"Eijah\" Anderson\'','DEF CON Workshops_7d6236e26c4bac02150d5e38efb858cf','\'Title: Sold Out - Post-Quantum Cryptography (PQC) for Hackers
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Sunday, Aug 9, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W228 (Workshops) - Map
\n
\nDescription:
\n

Secure communications are not a luxury — they are a foundational requirement for human dignity in the digital age. Our most meaningful conversations, transactions, and decisions demand end-to-end encryption, strong authentication, and verifiable integrity. The notion that \"only those with something to hide need strong crypto\" is not merely lazy; it is dangerously shortsighted. Privacy is the space where autonomy, intimacy, and authentic human experience thrive. When that space is violated, the damage ripples far beyond the individual.

\n\n

For decades, classical public-key cryptography has quietly protected everything from online banking to private messaging. That era is ending. Quantum computers are advancing rapidly, and the break of today\'s asymmetric algorithms — often called the Quantum Apocalypse — is no longer a question of if, but when. The window to prepare is narrowing. Migration must begin now.

\n\n

In this workshop, you\'ll implement PQC algorithms from the NSA\'s CNSA Suite 2.0. You\'ll use C++, OpenSSL and Linux to demonstrate the secure usage of ML-KEM, ML-DSA, AES-256, and SHA-512. You\'ll leave with clean, reusable code, deep implementation insight, and the practical skills needed to integrate PQC into real-world systems.

\n\n

We might not all have something to hide, but we all have something worth protecting.

\n\nSpeakerBio:  Eric \"Eijah\" Anderson
\n

Eijah is the founder of Code Siren, LLC and has 25+ years of experience in software development. He is the creator of Polynom, the world\'s first CNSA Suite 2.0 PQC collaboration app and the author of multiple FIPS 140-3 modules. He is also the developer of Demonsaw, an encrypted communications platform that allows you to share information without fear of data collection or surveillance. Before that Eijah was a Lead Programmer at Rockstar Games where he created Grand Theft Auto V and Red Dead Redemption 2. In 2007, Eijah hacked multiple implementations of the Advanced Access Content System (AACS) protocol and released the first Blu-ray device keys under the pseudonym, ATARI Vampire. He has been a faculty member at multiple colleges, has spoken at DEF CON and other security conferences, and holds a master\'s degree in Computer Science. Eijah is an active member of the hacking community and is an avid proponent of Internet freedom.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sun_am_ws3_4070
\n\'',NULL,1293586),('4_Sunday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Post-Quantum Cryptography (PQC) for Hackers\'','\'Eric \"Eijah\" Anderson\'','DEF CON Workshops_7d6236e26c4bac02150d5e38efb858cf','\'\'',NULL,1293587),('4_Sunday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Post-Quantum Cryptography (PQC) for Hackers\'','\'Eric \"Eijah\" Anderson\'','DEF CON Workshops_7d6236e26c4bac02150d5e38efb858cf','\'\'',NULL,1293588),('4_Sunday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W228 (Workshops)','\'Sold Out - Post-Quantum Cryptography (PQC) for Hackers\'','\'Eric \"Eijah\" Anderson\'','DEF CON Workshops_7d6236e26c4bac02150d5e38efb858cf','\'\'',NULL,1293589),('4_Sunday','09','09:00','12:59','N','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Purple Protocol: Adversary emulation for everyone\'','\'Patrick \"PilotPat\" Raiden,Ben \"Marba$\" Strout,Brandon \"D43m0n\" Kraycirik\'','DEF CON Workshops_03edf4e83085d60d6301bd10b02cf258','\'Title: Sold Out - Purple Protocol: Adversary emulation for everyone
\nTags: DEF CON Workshop | DEF CON Workshops
\nWhen: Sunday, Aug 9, 09:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W229 (Workshops) - Map
\n
\nDescription:
\n

Have you ever been curious about the techniques used by most notorious hackers to infiltrate some of the world\'s biggest networks? What would happen if they attacked yours? Companies burn millions of dollars in cybersecurity defenses, yet breaches still happen. Why? Because victory favors the prepared, not the well-funded.

\n\n

This beginner friendly workshop explores a practical way to test your defenses. You will learn to organize and execute a Threat Intelligence-led Purple Team Engagement with Open Source tooling. You will learn how to select relevant Threat Actors, execute test cases, document results, generate action items for the Blue Team to remediate, and report the results in a way that even executives can understand. (Spoiler: They like Pie Charts, Line Graphs, and bright colors) This will all be done on a VM we will provide with the Open Source tooling pre-installed. Everything learned in this course can be replicated at your organization.

\n\n

Join us in this workshop to learn why Purple Teaming is undeniably one of the most methodical and effective ways to improve your resilience against the threat actors most likely to attack your organization.

\n\nSpeakers:Patrick \"PilotPat\" Raiden,Ben \"Marba$\" Strout,Brandon \"D43m0n\" Kraycirik
\n
\nSpeakerBio:  Patrick \"PilotPat\" Raiden
\n

Patrick has been working in Cybersecurity for the past decade, ranging from Security Engineering, Vulnerability Management, Penetration Testing, and Red Team Ops.  He holds industry certs including the OSCP, CRTO and GRTP.  He led the effort to build a new Purple Team program at one of the largest healthcare organizations in the United States and continues to manage the program. Patrick is also a DEF CON Black Badge winner.

\n\nSpeakerBio:  Ben \"Marba$\" Strout
\n

Marba$ leads an Offensive Security Team and research vulnerabilities at one of the largest U.S. healthcare conglomerates. With experience spanning healthcare, biotech, pharma, and fintech, his work centers on application security, red teaming, and automation. He is the founder of DC207- Maine\'s DEF CON group - and the General Chair / Lead Organizer of BSides Maine.

\n\nSpeakerBio:  Brandon \"D43m0n\" Kraycirik
\n

D43m0n is a senior cyber security research engineer for one of the largest banking institutions in the world. Having over five years of experience in offensive security, specializing in red teaming, vulnerability research, and custom tool development.

\n\n

He holds advanced certifications that include OSCE3, BSCP, CRTO, CARTP, and eWPTX. While doing so, he was contributing to the cyber security community as the discoverer of CVE-2025-26332 (Dell) and CVE-2025-30398 (Microsoft), while also having authored “Debugging CVE-2023-37679: A Step-by-Step Guide to Fixing the Windows Exploit.”

\n\n

One of his most recent accomplishments at DEF CON is finally obtaining the accolade of being a Black Badge holder.

\n\n

Outside of cybersecurity, he is a passionate researcher with a deep appreciation for the outdoors.

\n\n\nLinks:
    Registration (July 14, 2026, Noon US Pacific) - https://events.humanitix.com/sun_am_ws2_4001
\n\'',NULL,1293590),('4_Sunday','10','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Purple Protocol: Adversary emulation for everyone\'','\'Patrick \"PilotPat\" Raiden,Ben \"Marba$\" Strout,Brandon \"D43m0n\" Kraycirik\'','DEF CON Workshops_03edf4e83085d60d6301bd10b02cf258','\'\'',NULL,1293591),('4_Sunday','11','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Purple Protocol: Adversary emulation for everyone\'','\'Patrick \"PilotPat\" Raiden,Ben \"Marba$\" Strout,Brandon \"D43m0n\" Kraycirik\'','DEF CON Workshops_03edf4e83085d60d6301bd10b02cf258','\'\'',NULL,1293592),('4_Sunday','12','09:00','12:59','Y','DEF CON Workshops','LVCCW Level 2 W229 (Workshops)','\'Sold Out - Purple Protocol: Adversary emulation for everyone\'','\'Patrick \"PilotPat\" Raiden,Ben \"Marba$\" Strout,Brandon \"D43m0n\" Kraycirik\'','DEF CON Workshops_03edf4e83085d60d6301bd10b02cf258','\'\'',NULL,1293593),('3_Saturday','18','18:00','20:59','N','Social Gatherings/Events','LVCCW Level 1 North Lobby','\'10 years of K-rad (Hackers.Town Party)\'','\'\'','Social Gatherings/Events_02e499dcb962ead090846b0d1ece7080','\'Title: 10 years of K-rad (Hackers.Town Party)
\nTags: Party | Hackers.town
\nWhen: Saturday, Aug 8, 18:00 - 20:59 PDT
\nWhere: LVCCW Level 1 North Lobby - Map
\n
\nDescription:
\n

HACK THE PLANET! Come celebrate 10 years of Hackers.Town doing whatever it is we actually do! We’ve fully embraced this year’s theme of agency, and given these renowned hacker-DJs free rein to do what they do best.

\n\n

Join us in the North Lobby for epic sets from: Kampf, Syntax976 and Luna, PatAttack, and Skittish and Bus!

\n\n\'',NULL,1293594),('3_Saturday','19','18:00','20:59','Y','Social Gatherings/Events','LVCCW Level 1 North Lobby','\'10 years of K-rad (Hackers.Town Party)\'','\'\'','Social Gatherings/Events_02e499dcb962ead090846b0d1ece7080','\'\'',NULL,1293595),('3_Saturday','20','18:00','20:59','Y','Social Gatherings/Events','LVCCW Level 1 North Lobby','\'10 years of K-rad (Hackers.Town Party)\'','\'\'','Social Gatherings/Events_02e499dcb962ead090846b0d1ece7080','\'\'',NULL,1293596),('2_Friday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'AC Scanner: The Post-Quantum Cryptographic Exposure and CBOM Generator. You Need This!\'','\'Anurag Swarnim Yadav,Joseph Wilson\'','Demo Labs_df32d46bcc664c5dadaaa265337f433f','\'Title: AC Scanner: The Post-Quantum Cryptographic Exposure and CBOM Generator. You Need This!
\nTags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | SecOps | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

AC Scanner is a tool to help providers of all kinds ensure their services can resist post-quantum cryptographic attacks including Harvest Now Decrypt Later (HNDL). The scanner is an open-source pipeline that automates full cryptographic surface discovery across TLS endpoints and SSH services, assessing every asset against NIST post-quantum standards and generating a structured Cryptographic Bill of Materials (CBOM). In a single command (sh scan.sh example.com) it runs subdomain enumeration, DNS resolution, TLS handshake analysis via OpenSSL, SSH auditing via ssh-audit, quantum vulnerability scoring, and CBOM output in JSONL/JSON/Markdown, ready to upload to an interactive dashboard. With NIST finalizing ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) in 2024, and NIST IR 8547 mandating deprecation of quantum-vulnerable algorithms by 2030, AC Scanner gives blue teams a fast, evidence-grade path from cryptographic discovery to compliance reporting.

\n\nSpeakers:Anurag Swarnim Yadav,Joseph Wilson
\n
\nSpeakerBio:  Anurag Swarnim Yadav
\n

Anurag Swarnim Yadav is Co-Founder and CTO of QubitAC, a company helping organizations with cryptographic discovery, post-quantum cryptography readiness assessment, migration framework development, and compliance readiness. He holds a PhD from the University of Florida, where his research examined how data quality impacts ML-based vulnerability detection systems and explored automated program repair for security flaws. He developed AC Scanner, a free open-source ACDI tool helping organizations discover, inventory, and prioritize their quantum-vulnerable cryptographic infrastructure, and has spoken at BSides security conferences educating practitioners on PQC adoption and the steps organizations need to take before the 2030 deadline.

\n\nSpeakerBio:  Joseph Wilson
\n

Joseph N. Wilson is a co-founder of QubitAC and an emeritus faculty member at the University of Florida who received his PhD in Computer Science from the University of Virginia. During his 41 year academic career, he carried out a wide variety of research projects and authored over 150 publications concerning topics including cybersecurity, machine learning, landmine detection and remediation, and computer vision. In addition to his academic work, Dr. Wilson has been a GIAC certified network and web application penetration tester as well as a malware and forensic analyst. His current work is aimed at helping organizations and people improve both their computational and communications security and privacy. He received the General Ronald W. Yates Award for Excellence in Technology Transfer for work leading to successful landmine and IED detection systems employed by US military support forces in Afghanistan.

\n\n\nLinks:
    GitHub - https://github.com/qubitac/AC-Scanner
\n\'',NULL,1293597),('3_Saturday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'AC Scanner: The Post-Quantum Cryptographic Exposure and CBOM Generator. You Need This!\'','\'Anurag Swarnim Yadav,Joseph Wilson\'','Demo Labs_9598fadffd090dcd17c1481087662bb1','\'Title: AC Scanner: The Post-Quantum Cryptographic Exposure and CBOM Generator. You Need This!
\nTags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | SecOps | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

AC Scanner is a tool to help providers of all kinds ensure their services can resist post-quantum cryptographic attacks including Harvest Now Decrypt Later (HNDL). The scanner is an open-source pipeline that automates full cryptographic surface discovery across TLS endpoints and SSH services, assessing every asset against NIST post-quantum standards and generating a structured Cryptographic Bill of Materials (CBOM). In a single command (sh scan.sh example.com) it runs subdomain enumeration, DNS resolution, TLS handshake analysis via OpenSSL, SSH auditing via ssh-audit, quantum vulnerability scoring, and CBOM output in JSONL/JSON/Markdown, ready to upload to an interactive dashboard. With NIST finalizing ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) in 2024, and NIST IR 8547 mandating deprecation of quantum-vulnerable algorithms by 2030, AC Scanner gives blue teams a fast, evidence-grade path from cryptographic discovery to compliance reporting.

\n\nSpeakers:Anurag Swarnim Yadav,Joseph Wilson
\n
\nSpeakerBio:  Anurag Swarnim Yadav
\n

Anurag Swarnim Yadav is Co-Founder and CTO of QubitAC, a company helping organizations with cryptographic discovery, post-quantum cryptography readiness assessment, migration framework development, and compliance readiness. He holds a PhD from the University of Florida, where his research examined how data quality impacts ML-based vulnerability detection systems and explored automated program repair for security flaws. He developed AC Scanner, a free open-source ACDI tool helping organizations discover, inventory, and prioritize their quantum-vulnerable cryptographic infrastructure, and has spoken at BSides security conferences educating practitioners on PQC adoption and the steps organizations need to take before the 2030 deadline.

\n\nSpeakerBio:  Joseph Wilson
\n

Joseph N. Wilson is a co-founder of QubitAC and an emeritus faculty member at the University of Florida who received his PhD in Computer Science from the University of Virginia. During his 41 year academic career, he carried out a wide variety of research projects and authored over 150 publications concerning topics including cybersecurity, machine learning, landmine detection and remediation, and computer vision. In addition to his academic work, Dr. Wilson has been a GIAC certified network and web application penetration tester as well as a malware and forensic analyst. His current work is aimed at helping organizations and people improve both their computational and communications security and privacy. He received the General Ronald W. Yates Award for Excellence in Technology Transfer for work leading to successful landmine and IED detection systems employed by US military support forces in Afghanistan.

\n\n\nLinks:
    GitHub - https://github.com/qubitac/AC-Scanner
\n\'',NULL,1293598),('2_Friday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory\'','\'Akbar \"0xsensei\" Abdullayev,0xHera\'','Demo Labs_30256cdaf0063998ab91528ee883a9cd','\'Title: AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory
\nTags: DEF CON Demo Labs | Advanced | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

Every pentest, same story - BloodHound says no path to DA, client celebrates, meanwhile a 2019 service account has AddAllowedToAct on a production DC that nobody remembers. AD-Necromancer finds what humans forget. Give it a username, password, and domain — it bootstraps EDR evasion (ETW patching, DLL unhooking, Halos Gate syscalls), collects AD data over ADWS instead of LDAP, encrypts with AES-256-GCM, and exfils to C2 with zero artifacts. One command, credentials to findings. It feeds tokenized BloodHound data to an LLM for semantic reasoning - forgotten RBCD, ghost cross-forest delegations, orphaned admin accounts no compliance checklist catches. Privacy Cloak ensures real names never leave the box. Open source, MIT licensed. Come dig up what your tools missed.

\n\nSpeakers:Akbar \"0xsensei\" Abdullayev,0xHera
\n
\nSpeakerBio:  Akbar \"0xsensei\" Abdullayev
\n

Offensive security professional with 5+ years of experience in Active Directory and cloud security, specializing in red teaming and enterprise attack chains.

\n\nSpeakerBio:  0xHera
\n

I am a freelance Offensive Tool Developer and Security Enthusiast building practical tools and sharing research with the community to help others better understand attack paths, real-world offensive techniques, and defensive improvements.

\n\n\nLinks:
    GitHub - https://github.com/0xSense1/AD-Necromancer
\n\'',NULL,1293599),('3_Saturday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory\'','\'Akbar \"0xsensei\" Abdullayev,0xHera\'','Demo Labs_57cdba7f0533f4ed84015c217deef1eb','\'Title: AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory
\nTags: DEF CON Demo Labs | Advanced | Offense/Red Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

Every pentest, same story - BloodHound says no path to DA, client celebrates, meanwhile a 2019 service account has AddAllowedToAct on a production DC that nobody remembers. AD-Necromancer finds what humans forget. Give it a username, password, and domain — it bootstraps EDR evasion (ETW patching, DLL unhooking, Halos Gate syscalls), collects AD data over ADWS instead of LDAP, encrypts with AES-256-GCM, and exfils to C2 with zero artifacts. One command, credentials to findings. It feeds tokenized BloodHound data to an LLM for semantic reasoning - forgotten RBCD, ghost cross-forest delegations, orphaned admin accounts no compliance checklist catches. Privacy Cloak ensures real names never leave the box. Open source, MIT licensed. Come dig up what your tools missed.

\n\nSpeakers:Akbar \"0xsensei\" Abdullayev,0xHera
\n
\nSpeakerBio:  Akbar \"0xsensei\" Abdullayev
\n

Offensive security professional with 5+ years of experience in Active Directory and cloud security, specializing in red teaming and enterprise attack chains.

\n\nSpeakerBio:  0xHera
\n

I am a freelance Offensive Tool Developer and Security Enthusiast building practical tools and sharing research with the community to help others better understand attack paths, real-world offensive techniques, and defensive improvements.

\n\n\nLinks:
    GitHub - https://github.com/0xSense1/AD-Necromancer
\n\'',NULL,1293600),('2_Friday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'AI Pipeline for N-days Weaponization\'','\'Andrea Brosio,Arun Nair\'','Demo Labs_a6199c2ba672821b6b69101e9b388545','\'Title: AI Pipeline for N-days Weaponization
\nTags: AI | DEF CON Demo Labs | Intermediate | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

Most agentic exploit pipelines stall when there\'s no public PoC,they search, find nothing, and spin. This talk demos a multi-agent system that exploits n-days from scratch in under an hour, even with zero public exploit code available.\nGiven only a CVE ID, the pipeline autonomously: fetches vulnerability details and the upstream fix commit; spins up a pinned Docker lab running the exact vulnerable version; diffs the patch to identify the exploitable code path; generates vulnerability-class-specific attack guidance (not a generic checklist); and runs iterative exploit + validation loops until RCE is confirmed.\nDemonstrated live against four CVSS 9.8–10.0 vulnerabilities Apache OpenMeetings deserialization, n8n unauthenticated RCE, Langflow exec() injection, and Spring AI SpEL injection, with working exploits produced in minutes. Every run also outputs a containerized lab and defense report, making it equally useful for detection engineering and patch validation.

\n\nSpeakers:Andrea Brosio,Arun Nair
\n
\nSpeakerBio:  Andrea Brosio
\n

Andrea Brosio is a Security Researcher and Senior Content Engineer at TryHackMe, specializing in red teaming, malware development, and offensive security. With prior experience as a Bug Hunter and Red Team Operator he combines real-world adversarial expertise with a passion for creating engaging cybersecurity training.

\n\nSpeakerBio:  Arun Nair
\n

Arun Nair is a Security Engineer at Google and founder of Ryvane Academy, specializing in AI Security, malware development, defense evasion, and adversary simulation. He holds several respected certifications, including OSCP, CRTP, CRTL, CodeMachine Malware Techniques, and HackSys Windows Kernel Exploitation.\nOver the years, Arun has worked with leading organizations such as JP Morgan, and EY, focusing on offensive security and red teaming engagements. Outside of his professional work, he is an active contributor to the cybersecurity community, from designing Capture the Flag (CTF) challenges to delivering talks and workshops at events like DEFCON Red Team Village, HeapCon, MCTTP, BSides Transylvania, HackSpaceCon, RingZer0, c0c0n, and various local meetups.\nWhen he’s not on engagements or speaking at conferences, Arun shares his research and insights through his blog at dazzyddos.github.io

\n\n\n\'',NULL,1293601),('3_Saturday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'AI Pipeline for N-days Weaponization\'','\'Andrea Brosio,Arun Nair\'','Demo Labs_254a78d45fd1178dfe5c225a5ec5e270','\'Title: AI Pipeline for N-days Weaponization
\nTags: AI | DEF CON Demo Labs | Intermediate | Offense/Red Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

Most agentic exploit pipelines stall when there\'s no public PoC,they search, find nothing, and spin. This talk demos a multi-agent system that exploits n-days from scratch in under an hour, even with zero public exploit code available.\nGiven only a CVE ID, the pipeline autonomously: fetches vulnerability details and the upstream fix commit; spins up a pinned Docker lab running the exact vulnerable version; diffs the patch to identify the exploitable code path; generates vulnerability-class-specific attack guidance (not a generic checklist); and runs iterative exploit + validation loops until RCE is confirmed.\nDemonstrated live against four CVSS 9.8–10.0 vulnerabilities Apache OpenMeetings deserialization, n8n unauthenticated RCE, Langflow exec() injection, and Spring AI SpEL injection, with working exploits produced in minutes. Every run also outputs a containerized lab and defense report, making it equally useful for detection engineering and patch validation.

\n\nSpeakers:Andrea Brosio,Arun Nair
\n
\nSpeakerBio:  Andrea Brosio
\n

Andrea Brosio is a Security Researcher and Senior Content Engineer at TryHackMe, specializing in red teaming, malware development, and offensive security. With prior experience as a Bug Hunter and Red Team Operator he combines real-world adversarial expertise with a passion for creating engaging cybersecurity training.

\n\nSpeakerBio:  Arun Nair
\n

Arun Nair is a Security Engineer at Google and founder of Ryvane Academy, specializing in AI Security, malware development, defense evasion, and adversary simulation. He holds several respected certifications, including OSCP, CRTP, CRTL, CodeMachine Malware Techniques, and HackSys Windows Kernel Exploitation.\nOver the years, Arun has worked with leading organizations such as JP Morgan, and EY, focusing on offensive security and red teaming engagements. Outside of his professional work, he is an active contributor to the cybersecurity community, from designing Capture the Flag (CTF) challenges to delivering talks and workshops at events like DEFCON Red Team Village, HeapCon, MCTTP, BSides Transylvania, HackSpaceCon, RingZer0, c0c0n, and various local meetups.\nWhen he’s not on engagements or speaking at conferences, Arun shares his research and insights through his blog at dazzyddos.github.io

\n\n\n\'',NULL,1293602),('2_Friday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'AOBTD: AI One Bites The DAST\'','\'Ozgun \"ozzy\" Kultekin\'','Demo Labs_2cde4f195630e3e5aa633555878c845f','\'Title: AOBTD: AI One Bites The DAST
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\nI hate the way most DAST tools test: firing payloads at parameters with no idea what the app is. They catch the obvious stuff, but miss the parts that actually need context. Newer LLM scanners are either commercial black boxes (iykyk) or \"GPT, find bugs at this URL\" wrappers that fall over outside a CTF box.
\n\n

AOBTD is my attempt at a third option: a scanner that behaves less like a fuzzer and more like a pentester at the start of a test.

\n\n

Instead of fuzzing harder, AOBTD first tries to understand the target. It explores the surface, identifies what pages and endpoints are for, takes notes, builds hypotheses, and then sends targeted requests based on that context. This target understanding drives the rest of the testing process, which is the only realistic way automated tooling can get closer to business-logic bugs.

\n\n

The crawler is designed to avoid wasting time on repeated templates while still sampling outliers, so the odd page hidden in a sea of similar ones does not get ignored. When findings are confirmed, AOBTD can chain them into multi-step attack stories rather than reporting isolated payload hits.

\n\n

This is where LLMs are actually useful: reading a page, understanding the purpose of a form, naming the function behind a JSON endpoint, and doing the kind of prioritization a pentester normally spends hours on.

\n\nSpeakerBio:  Ozgun \"ozzy\" Kultekin
\n

Ozgun (aka ozzy) is a Senior Application Security Engineer at Trendyol Group, where he spends his days breaking applications before the bad guys do. He holds the OSCE3 certification and specializes in offensive security research with a focus on application security and red team operations.

\n\n

He has presented at several conferences including DEF CON, Hacktivity, and multiple BSides events, covering topics ranging from red teaming to application security. He is currently focused on integrating AI into offensive security workflows and actively researching how large language models can be applied in practical, technical ways within cybersecurity. He regularly shares his work and tools as open source.

\n\n

When he\'s not hunting bugs or running red team ops, he\'s probably at the poker table.

\n\n\nLinks:
    GitHub - https://github.com/oz9un/AOBTD
\n\'',NULL,1293603),('3_Saturday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'AOBTD: AI One Bites The DAST\'','\'Ozgun \"ozzy\" Kultekin\'','Demo Labs_8fe640565878ce4ecb4937e785d40a7a','\'Title: AOBTD: AI One Bites The DAST
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\nI hate the way most DAST tools test: firing payloads at parameters with no idea what the app is. They catch the obvious stuff, but miss the parts that actually need context. Newer LLM scanners are either commercial black boxes (iykyk) or \"GPT, find bugs at this URL\" wrappers that fall over outside a CTF box.
\n\n

AOBTD is my attempt at a third option: a scanner that behaves less like a fuzzer and more like a pentester at the start of a test.

\n\n

Instead of fuzzing harder, AOBTD first tries to understand the target. It explores the surface, identifies what pages and endpoints are for, takes notes, builds hypotheses, and then sends targeted requests based on that context. This target understanding drives the rest of the testing process, which is the only realistic way automated tooling can get closer to business-logic bugs.

\n\n

The crawler is designed to avoid wasting time on repeated templates while still sampling outliers, so the odd page hidden in a sea of similar ones does not get ignored. When findings are confirmed, AOBTD can chain them into multi-step attack stories rather than reporting isolated payload hits.

\n\n

This is where LLMs are actually useful: reading a page, understanding the purpose of a form, naming the function behind a JSON endpoint, and doing the kind of prioritization a pentester normally spends hours on.

\n\nSpeakerBio:  Ozgun \"ozzy\" Kultekin
\n

Ozgun (aka ozzy) is a Senior Application Security Engineer at Trendyol Group, where he spends his days breaking applications before the bad guys do. He holds the OSCE3 certification and specializes in offensive security research with a focus on application security and red team operations.

\n\n

He has presented at several conferences including DEF CON, Hacktivity, and multiple BSides events, covering topics ranging from red teaming to application security. He is currently focused on integrating AI into offensive security workflows and actively researching how large language models can be applied in practical, technical ways within cybersecurity. He regularly shares his work and tools as open source.

\n\n

When he\'s not hunting bugs or running red team ops, he\'s probably at the poker table.

\n\n\nLinks:
    GitHub - https://github.com/oz9un/AOBTD
\n\'',NULL,1293604),('2_Friday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'AzProwl: Prowling the Azure Attack Surface\'','\'Jared \"GonePhishing402\" Graff,Jeff Daniels\'','Demo Labs_40b44a026682f7c348d4d76c3e5814a7','\'Title: AzProwl: Prowling the Azure Attack Surface
\nTags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

Cloud environments aren’t being breached through zero-days—they’re being traversed through identity, misconfigurations, and overlooked data paths. Azure is no exception.

\n\n

This talk introduces AzProwl, an offensive-focused tool designed to emulate how real attackers enumerate and chain together access across Azure environments. Rather than stopping at surface-level enumeration, AzProwl maps identity relationships, token abuse opportunities, and data plane exposure to uncover realistic attack paths.

\n\n

We’ll walk through how attackers move from initial access to meaningful impact using Azure-native mechanisms—leveraging identity roles, service principals, tokens, and storage access. Attendees will see how seemingly low-risk permissions compound into high-impact compromise.

\n\n

Whether you’re red team, blue team, or somewhere in between, this session will provide practical insight into how Azure environments are actually attacked—and how to detect and defend against it.

\n\nSpeakers:Jared \"GonePhishing402\" Graff,Jeff Daniels
\n
\nSpeakerBio:  Jared \"GonePhishing402\" Graff
\n

I’m a Lead Incident Response Analyst at Target with experience spanning red team operations, blue team defense, and incident response. My background working in Azure cloud security at Microsoft helped shape my approach to understanding and defending modern cloud environments and ultimately inspired the development of this training.

\n\n

I specialize in analyzing and emulating real-world attack paths across cloud identities, authentication tokens, and data planes to uncover gaps in detection and response capabilities. My work focuses on Azure identity compromise, token abuse, cloud persistence techniques, and understanding how adversaries actually operate within cloud environments—not just how we assume they do.

\n\n

I’m passionate about bridging the gap between offensive and defensive security, translating attacker tradecraft into actionable detection strategies, and developing hands-on labs that help defenders better understand cloud threats. My goal is to make complex attack techniques accessible, practical, and directly applicable to real-world security operations.

\n\nSpeakerBio:  Jeff Daniels
\n

Jeff Daniels is a Senior Cloud Solution Architect at Microsoft Federal specializing in cloud security, threat intelligence, and red team operations. With a background in military cyber operations, he brings real-world offensive experience to designing detection strategies, Zero Trust architectures, and large-scale SOC capabilities. Jeff focuses on translating adversary tradecraft into actionable security outcomes for government customers and is actively involved in red team tooling, adversary emulation, and ATT&CK-aligned training.

\n\n\nLinks:
    GitHub - https://github.com/GonePhishing402/azprowl
\n\'',NULL,1293605),('2_Friday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'AzProwl: Prowling the Azure Attack Surface\'','\'Jared \"GonePhishing402\" Graff,Jeff Daniels\'','Demo Labs_3c6ffd3dbb08e1fb401ee36269101eb0','\'Title: AzProwl: Prowling the Azure Attack Surface
\nTags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

Cloud environments aren’t being breached through zero-days—they’re being traversed through identity, misconfigurations, and overlooked data paths. Azure is no exception.

\n\n

This talk introduces AzProwl, an offensive-focused tool designed to emulate how real attackers enumerate and chain together access across Azure environments. Rather than stopping at surface-level enumeration, AzProwl maps identity relationships, token abuse opportunities, and data plane exposure to uncover realistic attack paths.

\n\n

We’ll walk through how attackers move from initial access to meaningful impact using Azure-native mechanisms—leveraging identity roles, service principals, tokens, and storage access. Attendees will see how seemingly low-risk permissions compound into high-impact compromise.

\n\n

Whether you’re red team, blue team, or somewhere in between, this session will provide practical insight into how Azure environments are actually attacked—and how to detect and defend against it.

\n\nSpeakers:Jared \"GonePhishing402\" Graff,Jeff Daniels
\n
\nSpeakerBio:  Jared \"GonePhishing402\" Graff
\n

I’m a Lead Incident Response Analyst at Target with experience spanning red team operations, blue team defense, and incident response. My background working in Azure cloud security at Microsoft helped shape my approach to understanding and defending modern cloud environments and ultimately inspired the development of this training.

\n\n

I specialize in analyzing and emulating real-world attack paths across cloud identities, authentication tokens, and data planes to uncover gaps in detection and response capabilities. My work focuses on Azure identity compromise, token abuse, cloud persistence techniques, and understanding how adversaries actually operate within cloud environments—not just how we assume they do.

\n\n

I’m passionate about bridging the gap between offensive and defensive security, translating attacker tradecraft into actionable detection strategies, and developing hands-on labs that help defenders better understand cloud threats. My goal is to make complex attack techniques accessible, practical, and directly applicable to real-world security operations.

\n\nSpeakerBio:  Jeff Daniels
\n

Jeff Daniels is a Senior Cloud Solution Architect at Microsoft Federal specializing in cloud security, threat intelligence, and red team operations. With a background in military cyber operations, he brings real-world offensive experience to designing detection strategies, Zero Trust architectures, and large-scale SOC capabilities. Jeff focuses on translating adversary tradecraft into actionable security outcomes for government customers and is actively involved in red team tooling, adversary emulation, and ATT&CK-aligned training.

\n\n\nLinks:
    GitHub - https://github.com/GonePhishing402/azprowl
\n\'',NULL,1293606),('2_Friday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device\'','\'Gigi Xiaoqing Liu,Muzzammil Mohammed,Narmina Karimova\'','Demo Labs_e01211d51e8841567e08bbe3e4237962','\'Title: Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device
\nTags: Intro/Beginner | DEF CON Demo Labs | AppSec | Hardware/IoT | Mobile | Offense/Red Team | Wireless/RF | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

What happens when you buy a popular medical device and realize it blindly trusts any BLE connection within 30 meters?

\n\n

BRAT (BLE Recon and Attack Toolkit) is the open-source Python arsenal we built to systematically take over an FDA-listed consumer hormone analyzer and generalize the attack to the class of devices behind it. Relying on the Nordic UART Service (NUS), the target blindly trusts any connection within 30 meters. BRAT automates the exact attack chain we used to compromise it: passive BLE discovery, protocol reverse engineering, unauthenticated command injection, full bind takeover, and rogue peripheral impersonation to hijack live API session tokens.

\n\n

Every script is built on the ⁠bleak⁠ async BLE library and deliberately kept small so you can read the code and understand the exploit in minutes. Our Demo Lab features live, end-to-end attacks against a consumer medical device. We’ll demonstrate unauthenticated command injection, rogue peripheral spoofing that intercepts companion app handshakes, and how we injected spoofed hormone sensor data without ever pairing.

\n\nSpeakers:Gigi Xiaoqing Liu,Muzzammil Mohammed,Narmina Karimova
\n
\nSpeakerBio:  Gigi Xiaoqing Liu
\n

Gigi Liu is a graduate security researcher at Northeastern\'s Security And Privacy Research (SPQR) Group under Professor Kevin Fu, where her work covers embedded systems security, medical device attack surfaces, and AI-generated media detection. She interns at Lila Sciences as a Security and Cloud Engineer, building enterprise-wide agentic AI security infrastructure and detection capabilities for unauthorized AI activity across cloud and SaaS environments.

\n\n

Her technical work spans wireless protocol reverse engineering, binary exploitation, web and mobile reverse engineering, cloud and AI security. She has applied these skills across medical hardware, automotive platforms, and enterprise cloud environments — from BLE command injection on FDA-listed devices to CarPlay API exploitation to building agentic AI detection controls at scale. As a UCLA psychobiology alum with a consulting background, she brings a multidisciplinary lens to every system: understand what it\'s designed to do first, then find where it breaks.

\n\nSpeakerBio:  Muzzammil Mohammed
\n

Muzzammil Mohammed is an offensive security researcher, penetration tester at Maltek Solutions, and MS in Cybersecurity at Northeastern University. Operating out of the SPQR Lab under Professor Kevin Fu, and serving as a Teaching Assistant Network Security, his work bridges academic vulnerability research with real-world red team execution. As a core developer of WandKit an open-source BLE attack toolkit built to audit medical devices. Muzzammil led the cloud API exploitation phase, successfully confirming a complete authentication bypass and engineering the rogue peripheral session hijack chain. Beyond hardware and API hacking, he is actively developing autonomous multi-agent AI frameworks designed to orchestrate local LLMs for automated security auditing and vulnerability analysis.

\n\nSpeakerBio:  Narmina Karimova
\n

Narmina Karimova is a cybersecurity graduate researcher at Northeastern University with a background in enterprise technology across financial institutions and the United Nations. She came to security research from the infrastructure side, which shaped how she approached tearing apart a consumer fertility monitor.\nFor BRAT, she wrote the core BLE attack suite in Python: replay modules, rogue peripheral session capture, unauthenticated hormone data extraction, and the bind takeover chain that captures device ownership in under 15 seconds. She also reverse-engineered the APK with JADX, found hardcoded credentials, and confirmed a CVSS 9.1 IDOR in the third-party integration. Her interest is in the gap between how consumer health devices are marketed and how they actually handle sensitive data.

\n\n\n\'',NULL,1293607),('3_Saturday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device\'','\'Gigi Xiaoqing Liu,Muzzammil Mohammed,Narmina Karimova\'','Demo Labs_8c18bbca4cca057feac8db83e05165b5','\'Title: Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device
\nTags: Intro/Beginner | DEF CON Demo Labs | AppSec | Hardware/IoT | Mobile | Offense/Red Team | Wireless/RF | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

What happens when you buy a popular medical device and realize it blindly trusts any BLE connection within 30 meters?

\n\n

BRAT (BLE Recon and Attack Toolkit) is the open-source Python arsenal we built to systematically take over an FDA-listed consumer hormone analyzer and generalize the attack to the class of devices behind it. Relying on the Nordic UART Service (NUS), the target blindly trusts any connection within 30 meters. BRAT automates the exact attack chain we used to compromise it: passive BLE discovery, protocol reverse engineering, unauthenticated command injection, full bind takeover, and rogue peripheral impersonation to hijack live API session tokens.

\n\n

Every script is built on the ⁠bleak⁠ async BLE library and deliberately kept small so you can read the code and understand the exploit in minutes. Our Demo Lab features live, end-to-end attacks against a consumer medical device. We’ll demonstrate unauthenticated command injection, rogue peripheral spoofing that intercepts companion app handshakes, and how we injected spoofed hormone sensor data without ever pairing.

\n\nSpeakers:Gigi Xiaoqing Liu,Muzzammil Mohammed,Narmina Karimova
\n
\nSpeakerBio:  Gigi Xiaoqing Liu
\n

Gigi Liu is a graduate security researcher at Northeastern\'s Security And Privacy Research (SPQR) Group under Professor Kevin Fu, where her work covers embedded systems security, medical device attack surfaces, and AI-generated media detection. She interns at Lila Sciences as a Security and Cloud Engineer, building enterprise-wide agentic AI security infrastructure and detection capabilities for unauthorized AI activity across cloud and SaaS environments.

\n\n

Her technical work spans wireless protocol reverse engineering, binary exploitation, web and mobile reverse engineering, cloud and AI security. She has applied these skills across medical hardware, automotive platforms, and enterprise cloud environments — from BLE command injection on FDA-listed devices to CarPlay API exploitation to building agentic AI detection controls at scale. As a UCLA psychobiology alum with a consulting background, she brings a multidisciplinary lens to every system: understand what it\'s designed to do first, then find where it breaks.

\n\nSpeakerBio:  Muzzammil Mohammed
\n

Muzzammil Mohammed is an offensive security researcher, penetration tester at Maltek Solutions, and MS in Cybersecurity at Northeastern University. Operating out of the SPQR Lab under Professor Kevin Fu, and serving as a Teaching Assistant Network Security, his work bridges academic vulnerability research with real-world red team execution. As a core developer of WandKit an open-source BLE attack toolkit built to audit medical devices. Muzzammil led the cloud API exploitation phase, successfully confirming a complete authentication bypass and engineering the rogue peripheral session hijack chain. Beyond hardware and API hacking, he is actively developing autonomous multi-agent AI frameworks designed to orchestrate local LLMs for automated security auditing and vulnerability analysis.

\n\nSpeakerBio:  Narmina Karimova
\n

Narmina Karimova is a cybersecurity graduate researcher at Northeastern University with a background in enterprise technology across financial institutions and the United Nations. She came to security research from the infrastructure side, which shaped how she approached tearing apart a consumer fertility monitor.\nFor BRAT, she wrote the core BLE attack suite in Python: replay modules, rogue peripheral session capture, unauthenticated hormone data extraction, and the bind takeover chain that captures device ownership in under 15 seconds. She also reverse-engineered the APK with JADX, found hardcoded credentials, and confirmed a CVSS 9.1 IDOR in the third-party integration. Her interest is in the gap between how consumer health devices are marketed and how they actually handle sensitive data.

\n\n\n\'',NULL,1293608),('3_Saturday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'Beyond Spidering: Behavior Driven DAST for Real Application Workflows\'','\'Sara \"testingSoul\" Martinez\'','Demo Labs_a3ea791dadc0df5c85ebb0c18b37095f','\'Title: Beyond Spidering: Behavior Driven DAST for Real Application Workflows
\nTags: DEF CON Demo Labs | Intermediate | AppSec | DevOps | Offense/Red Team | SecOps | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

Modern web apps do not give up their best attack surface to a spider. The interesting routes, state changes, authenticated functions, and business logic usually sit behind real user behavior. This Demo Lab shows how to stop treating DAST like blind crawling and start driving it with realistic browser flows.

\n\n

The project began as a software quality proof of concept and evolved through collaboration between an engineering team and a red team into a real operational workflow. By routing Selenium based test scenarios through OWASP ZAP, we turn existing web automation into Behaviour Driven DAST: a practical way to capture richer traffic, exercise meaningful application actions, and uncover security findings that isolated scanning often misses.

\n\n

Current research shows more than 300% increase in observed attack surface and around 25% improvement in vulnerability detection compared with spider-driven analysis alone. The session will walk through the workflow live, show the comparative results, and introduce a new Python library built from this research.

\n\nSpeakerBio:  Sara \"testingSoul\" Martinez
\n

Hi, I am Sara!\nI started my career in 2014 as a Software Validation Engineer for Communication products. During five years I improved my testing skills by working on projects in Telecommunication, Geolocation, Big Data and Power Electronics.\nIn 2019, I started to focus all this quality knowledge on testing Cybersecurity Software products, and then magic just happened. I discovered a whole new world that fascinated me.\nSince then, I have been working to improve all my Software and Quality skills including Cybersecurity at every step I take.

\n\n\nLinks:
    GitHub - https://github.com/testingsoul/behave-zap
\n\'',NULL,1293609),('2_Friday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'Beyond Spidering: Behavior Driven DAST for Real Application Workflows\'','\'Sara \"testingSoul\" Martinez\'','Demo Labs_b2c911ba1927d922f597b85230be63e9','\'Title: Beyond Spidering: Behavior Driven DAST for Real Application Workflows
\nTags: DEF CON Demo Labs | Intermediate | AppSec | DevOps | Offense/Red Team | SecOps | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

Modern web apps do not give up their best attack surface to a spider. The interesting routes, state changes, authenticated functions, and business logic usually sit behind real user behavior. This Demo Lab shows how to stop treating DAST like blind crawling and start driving it with realistic browser flows.

\n\n

The project began as a software quality proof of concept and evolved through collaboration between an engineering team and a red team into a real operational workflow. By routing Selenium based test scenarios through OWASP ZAP, we turn existing web automation into Behaviour Driven DAST: a practical way to capture richer traffic, exercise meaningful application actions, and uncover security findings that isolated scanning often misses.

\n\n

Current research shows more than 300% increase in observed attack surface and around 25% improvement in vulnerability detection compared with spider-driven analysis alone. The session will walk through the workflow live, show the comparative results, and introduce a new Python library built from this research.

\n\nSpeakerBio:  Sara \"testingSoul\" Martinez
\n

Hi, I am Sara!\nI started my career in 2014 as a Software Validation Engineer for Communication products. During five years I improved my testing skills by working on projects in Telecommunication, Geolocation, Big Data and Power Electronics.\nIn 2019, I started to focus all this quality knowledge on testing Cybersecurity Software products, and then magic just happened. I discovered a whole new world that fascinated me.\nSince then, I have been working to improve all my Software and Quality skills including Cybersecurity at every step I take.

\n\n\nLinks:
    GitHub - https://github.com/testingsoul/behave-zap
\n\'',NULL,1293610),('2_Friday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'BigIron.ai: AI-Assisted Exploration and Security Analysis of Mainframe Systems\'','\'Adam \"w00tock\" Toscher\'','Demo Labs_534855a2b0434518419f948d0327ad5b','\'Title: BigIron.ai: AI-Assisted Exploration and Security Analysis of Mainframe Systems
\nTags: AI | DEF CON Demo Labs | Intermediate | Defense/Blue Team | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

Most security tools assume Unix or Windows models built around processes, shells, and network services. On mainframe operating systems, authority is determined through control-plane behavior: job submission (JCL/JES), dataset access, library resolution, and transaction context. These relationships are difficult to observe and are systematically misunderstood by modern security teams; creating blind spots that traditional tooling cannot see.

\n\n

This Demo Lab shows a live MVS 3.8j environment running under Hercules with a browser-based TN3270 interface. Operational artifacts including submitted jobs, spool output, and execution context are captured and mapped into a graph that reveals hidden trust relationships and indirect execution paths.

\n\n

The demonstration walks a realistic privilege path: TSO user → JCL submission → STEPLIB hijack → APF library execution — showing how inherited authority creates system-level exposure without exploiting a single vulnerability. No shellcode. No memory corruption. Just the system working exactly as designed.

\n\n

The platform includes 13 automated walkthroughs across 6 control planes (TSO, JES, RACF, CICS, VTAM, PR/SM), an offline LLM for real-time screen interpretation, and a findings engine that maps results to a repeatable assessment framework.

\n\nSpeakerBio:  Adam \"w00tock\" Toscher
\n

Adam Toscher is a New York–based security engineer and red team operator with over two decades of experience in offensive security, adversary simulation, and automation. Born in New York City and raised upstate, Adam began his career as an “IT vagabond,” starting as a freshman IBM intern porting Linux applications to mainframe systems. That early mainframe work grounded him in large-scale computing, operating systems, and complex enterprise environments before he transitioned into offensive security.

\n\n

He later held senior security roles at Adobe, Optiv, Accenture, IBM X-Force, and NYC Cyber Command, focusing on realistic adversary emulation, red-team operations, and practical automation.

\n\n

Most recently, Adam has worked with Cobalt Labs, supporting advanced red-teaming and offensive security engagements for private-sector organizations. Prior to that, he led red-team and adversary simulation work supporting critical public infrastructure with NYC Cyber Command and the FDNY.

\n\n

His work centers on penetration testing, red teaming, adversary emulation, and security tooling across private-sector and government environments. Outside of security, Adam values balance and lifelong learning, and is an avid reader, runner, swimmer, and gamer.

\n\n\nLinks:
    GitHub - https://github.com/W00t3k/mainframe-ai
\n\'',NULL,1293611),('2_Friday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'BigIron.ai: AI-Assisted Exploration and Security Analysis of Mainframe Systems\'','\'Adam \"w00tock\" Toscher\'','Demo Labs_babbb7d0ac6373e461b289afbb21022d','\'Title: BigIron.ai: AI-Assisted Exploration and Security Analysis of Mainframe Systems
\nTags: AI | DEF CON Demo Labs | Intermediate | Defense/Blue Team | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

Most security tools assume Unix or Windows models built around processes, shells, and network services. On mainframe operating systems, authority is determined through control-plane behavior: job submission (JCL/JES), dataset access, library resolution, and transaction context. These relationships are difficult to observe and are systematically misunderstood by modern security teams; creating blind spots that traditional tooling cannot see.

\n\n

This Demo Lab shows a live MVS 3.8j environment running under Hercules with a browser-based TN3270 interface. Operational artifacts including submitted jobs, spool output, and execution context are captured and mapped into a graph that reveals hidden trust relationships and indirect execution paths.

\n\n

The demonstration walks a realistic privilege path: TSO user → JCL submission → STEPLIB hijack → APF library execution — showing how inherited authority creates system-level exposure without exploiting a single vulnerability. No shellcode. No memory corruption. Just the system working exactly as designed.

\n\n

The platform includes 13 automated walkthroughs across 6 control planes (TSO, JES, RACF, CICS, VTAM, PR/SM), an offline LLM for real-time screen interpretation, and a findings engine that maps results to a repeatable assessment framework.

\n\nSpeakerBio:  Adam \"w00tock\" Toscher
\n

Adam Toscher is a New York–based security engineer and red team operator with over two decades of experience in offensive security, adversary simulation, and automation. Born in New York City and raised upstate, Adam began his career as an “IT vagabond,” starting as a freshman IBM intern porting Linux applications to mainframe systems. That early mainframe work grounded him in large-scale computing, operating systems, and complex enterprise environments before he transitioned into offensive security.

\n\n

He later held senior security roles at Adobe, Optiv, Accenture, IBM X-Force, and NYC Cyber Command, focusing on realistic adversary emulation, red-team operations, and practical automation.

\n\n

Most recently, Adam has worked with Cobalt Labs, supporting advanced red-teaming and offensive security engagements for private-sector organizations. Prior to that, he led red-team and adversary simulation work supporting critical public infrastructure with NYC Cyber Command and the FDNY.

\n\n

His work centers on penetration testing, red teaming, adversary emulation, and security tooling across private-sector and government environments. Outside of security, Adam values balance and lifelong learning, and is an avid reader, runner, swimmer, and gamer.

\n\n\nLinks:
    GitHub - https://github.com/W00t3k/mainframe-ai
\n\'',NULL,1293612),('2_Friday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Clew: Untangling Evasive Malware with Per-Sample Fuzzing Seeds\'','\'Kyler McElroy,Anita Ding,Daniel Koranek\'','Demo Labs_f24ddf95ae4696addd1dd8f3c485d59d','\'Title: Clew: Untangling Evasive Malware with Per-Sample Fuzzing Seeds
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

Clew is an automated fuzzing-candidate extraction pipeline for environment-sensitive malware analysis. Evasive malware routinely queries its execution environment via Windows API calls to hide functionality until specific environmental conditions are met. By hooking these API calls, a fuzzer can reveal such execution paths that are typically hidden during standard analysis. No seed corpus of environmental fuzzing candidates currently exists for this application. As a result, current API-hooking fuzzers rely on hand-written, sample-agnostic starting values and blind mutations that cannot scale to the diverse evasion techniques seen in sophisticated samples. Clew addresses this by analyzing each PE32 binary and producing a per-sample seed corpus of candidate API return values that downstream environmental fuzzers use to systematically uncover hidden execution paths.

\n\nSpeakers:Kyler McElroy,Anita Ding,Daniel Koranek
\n
\nSpeakerBio:  Kyler McElroy
\n

McElroy, a second lieutenant and developmental engineer in the United States Air Force, is pursuing a master\'s in computer science with an AI focus at the Air Force Institute of Technology. His research focuses on using machine learning and automated analysis to uncover hidden behaviors in evasive malware. He is an alumnus of the ACE Cyber Leadership Development program, where he authored S.A.N.D (Synthetic Adversarial and Natural Data Generation) under the Air Force Research Laboratory.

\n\nSpeakerBio:  Anita Ding
\n

Anita Ding is a second lieutenant and cyber operations officer in the United States Air Force, is pursuing a master\'s in cyber operations with an AI focus at the Air Force Institute of Technology. Her research focuses on LLM-orchestrated red team automation and graph neural networks for attack-path scoring in Active Directory environments. She earned a B.A. in Computer Science from UC Berkeley, where she conducted research at the Berkeley AI Research Lab and the Berkeley Risk and Security Lab. She is also an alumna of the ACE Cyber Leadership Development program, where she designed a CTF challenge for the British Army\'s Defence Cyber Marvel exercise.

\n\nSpeakerBio:  Daniel Koranek
\n

Dr. Daniel Koranek is an Assistant Professor of Computer Science at the Air Force Institute of Technology (AFIT) and a two-time graduate of AFIT in cyber operations (2010, M.S.) and computer science (2022, Ph.D.), where his research interests focus on the intersection of artificial intelligence/machine learning and cybersecurity. This includes using AI/ML to enhance cybersecurity and using vulnerability assessment and secure design techniques to improve AI deployments. He has spent most of his career on reverse engineering and vulnerability assessment of embedded systems, and overlapping AI and cybersecurity drove Dr. Koranek\'s dissertation research on using the reverse engineering tool Binary Ninja to visualize explanations of malware classifications.

\n\n\n\'',NULL,1293613),('3_Saturday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Clew: Untangling Evasive Malware with Per-Sample Fuzzing Seeds\'','\'Kyler McElroy,Anita Ding,Daniel Koranek\'','Demo Labs_4b12f642db95bab9c8e99842ea34852e','\'Title: Clew: Untangling Evasive Malware with Per-Sample Fuzzing Seeds
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

Clew is an automated fuzzing-candidate extraction pipeline for environment-sensitive malware analysis. Evasive malware routinely queries its execution environment via Windows API calls to hide functionality until specific environmental conditions are met. By hooking these API calls, a fuzzer can reveal such execution paths that are typically hidden during standard analysis. No seed corpus of environmental fuzzing candidates currently exists for this application. As a result, current API-hooking fuzzers rely on hand-written, sample-agnostic starting values and blind mutations that cannot scale to the diverse evasion techniques seen in sophisticated samples. Clew addresses this by analyzing each PE32 binary and producing a per-sample seed corpus of candidate API return values that downstream environmental fuzzers use to systematically uncover hidden execution paths.

\n\nSpeakers:Kyler McElroy,Anita Ding,Daniel Koranek
\n
\nSpeakerBio:  Kyler McElroy
\n

McElroy, a second lieutenant and developmental engineer in the United States Air Force, is pursuing a master\'s in computer science with an AI focus at the Air Force Institute of Technology. His research focuses on using machine learning and automated analysis to uncover hidden behaviors in evasive malware. He is an alumnus of the ACE Cyber Leadership Development program, where he authored S.A.N.D (Synthetic Adversarial and Natural Data Generation) under the Air Force Research Laboratory.

\n\nSpeakerBio:  Anita Ding
\n

Anita Ding is a second lieutenant and cyber operations officer in the United States Air Force, is pursuing a master\'s in cyber operations with an AI focus at the Air Force Institute of Technology. Her research focuses on LLM-orchestrated red team automation and graph neural networks for attack-path scoring in Active Directory environments. She earned a B.A. in Computer Science from UC Berkeley, where she conducted research at the Berkeley AI Research Lab and the Berkeley Risk and Security Lab. She is also an alumna of the ACE Cyber Leadership Development program, where she designed a CTF challenge for the British Army\'s Defence Cyber Marvel exercise.

\n\nSpeakerBio:  Daniel Koranek
\n

Dr. Daniel Koranek is an Assistant Professor of Computer Science at the Air Force Institute of Technology (AFIT) and a two-time graduate of AFIT in cyber operations (2010, M.S.) and computer science (2022, Ph.D.), where his research interests focus on the intersection of artificial intelligence/machine learning and cybersecurity. This includes using AI/ML to enhance cybersecurity and using vulnerability assessment and secure design techniques to improve AI deployments. He has spent most of his career on reverse engineering and vulnerability assessment of embedded systems, and overlapping AI and cybersecurity drove Dr. Koranek\'s dissertation research on using the reverse engineering tool Binary Ninja to visualize explanations of malware classifications.

\n\n\n\'',NULL,1293614),('2_Friday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'DFMI: Weaponizing MSI Installers for Fileless Code Execution\'','\'Anil Celik\'','Demo Labs_343a514c616c8e83f7bb5fbf95965896','\'Title: DFMI: Weaponizing MSI Installers for Fileless Code Execution
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

DFMI is a cross-platform, open-source offensive toolkit that hijacks & abuses the Windows Installer\'s own execution engine to detonate arbitrary payloads during software installation, with zero files written to disk and zero evidence left behind. And this can be achieved without corrupting the Authenticode of the binary. --Which means, ANY signed legitimate installer file can leveraged as an attack vector.

\n\n

Right now, DFMI provides 3 different methods for abusing MSI files:

\n\n
    \n
  • Inject: Simply injects a CustomAction (CA) into an existing MSI package.
  • \n
  • Rogue MST: Generates an MSI Transform File (.mst) and injects into legitimate \".msi\" file without corrupting it\'s Authenticode. The original MSI file is never modified — its Authenticode signature remains fully intact and valid. This means a signed, trusted MSI can be weaponized without leaving any forensic trace on the file itself; the transform rides alongside it at deployment time.
  • \n
  • Stub: Creates a malicious MSI file from scratch.
  • \n
\n\n

GitHub: https://github.com/ccelikanil/DFMI

\n\nSpeakerBio:  Anil Celik
\n

Computer Engineer & been working as a Red Teamer for the past ~7 years. Previously did presentations at DEFCON 33 Demo Labs, DEFCON 33 Red Team Village & Black Hat USA Arsenal 2025. Currently holding 6 CVEs, OSCP & OSWP.

\n\n

Interests: Windows Internals & AD Security

\n\n\nLinks:
    GitHub - https://github.com/ccelikanil/DFMI
\n\'',NULL,1293615),('3_Saturday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'DFMI: Weaponizing MSI Installers for Fileless Code Execution\'','\'Anil Celik\'','Demo Labs_0e8e2910b01e66f2df08befeb3341d4f','\'Title: DFMI: Weaponizing MSI Installers for Fileless Code Execution
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

DFMI is a cross-platform, open-source offensive toolkit that hijacks & abuses the Windows Installer\'s own execution engine to detonate arbitrary payloads during software installation, with zero files written to disk and zero evidence left behind. And this can be achieved without corrupting the Authenticode of the binary. --Which means, ANY signed legitimate installer file can leveraged as an attack vector.

\n\n

Right now, DFMI provides 3 different methods for abusing MSI files:

\n\n
    \n
  • Inject: Simply injects a CustomAction (CA) into an existing MSI package.
  • \n
  • Rogue MST: Generates an MSI Transform File (.mst) and injects into legitimate \".msi\" file without corrupting it\'s Authenticode. The original MSI file is never modified — its Authenticode signature remains fully intact and valid. This means a signed, trusted MSI can be weaponized without leaving any forensic trace on the file itself; the transform rides alongside it at deployment time.
  • \n
  • Stub: Creates a malicious MSI file from scratch.
  • \n
\n\n

GitHub: https://github.com/ccelikanil/DFMI

\n\nSpeakerBio:  Anil Celik
\n

Computer Engineer & been working as a Red Teamer for the past ~7 years. Previously did presentations at DEFCON 33 Demo Labs, DEFCON 33 Red Team Village & Black Hat USA Arsenal 2025. Currently holding 6 CVEs, OSCP & OSWP.

\n\n

Interests: Windows Internals & AD Security

\n\n\nLinks:
    GitHub - https://github.com/ccelikanil/DFMI
\n\'',NULL,1293616),('2_Friday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'Damn Vulnerable Agentic AI Application (DVAIA)\'','\'Abhinav Verma,Mukesh Aggarwal\'','Demo Labs_e32d23488b6ba61cf63e699315a47870','\'Title: Damn Vulnerable Agentic AI Application (DVAIA)
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

AI-powered Agentic applications now execute database queries, read files, send emails, and call APIs on behalf of users — all triggered through a chat window. DVAIA (Damn Vulnerable Agentic AI Application) is a new open-source platform purpose-built to let you break them.

\n\n

DVAIA pairs a production-grade secure platform with deliberately vulnerable AI-powered chat agents, each isolated in its own database and mapped to the OWASP Top 10 for LLM Applications 2025. In this demo we live-exploit nine exercise categories covering 93 attack objectives:

\n\n
    \n
  • Prompt injection: extract system prompts, jailbreak filters, poison RAG documents, and hijack an email-summarization agent
  • \n
  • SQL and NoSQL injection through AI: trick chat agents into constructing malicious queries — the injection never touches a traditional input field
  • \n
  • Sensitive info disclosure: chain path traversal and SSRF through a banking agent\'s tool interface to read server secrets and probe internal services
  • \n
  • Excessive agency and BOLA: make a customer-service agent access other users\' data, create unauthorized orders, and issue fraudulent refunds
  • \n
  • XSS and CSRF through LLM output: reflected, stored, and LLM-generated cross-site scripting fired from chat responses
  • \n
  • Supply chain RCE: exploit a poisoned dependency through conversation with a code-analysis agent
  • \n
\n\nSpeakers:Abhinav Verma,Mukesh Aggarwal
\n
\nSpeakerBio:  Abhinav Verma
\n

Abhinav Verma is a Senior Staff Security Engineer at Intuit Inc. with 15+ years of experience across AI security, offensive security, red teaming, product security, and security operations. He currently leads AI security architecture reviews, AI penetration testing, and vulnerability management programs, with a focus on AI security, AI threat modeling, and securing large-scale cloud platforms.

\n\n

Over the course of his career at Intuit, he has built security automation, scaled continuous security scanning across thousands of assets, led secure design reviews for platforms serving millions of customers, and developed secure coding programs that have helped thousands of engineers shift security left. Abhinav was formerly an independent security researcher and has identified and reported vulnerabilities in numerous major online services and technology companies.

\n\n

He holds certifications including OSEP, OSCP, OSWP, GWAPT and CEH. Outside of work, Abhinav is a passionate gamer, a trained chef, an avid camper, and a mentor to aspiring offensive security practitioners.

\n\nSpeakerBio:  Mukesh Aggarwal
\n

Mukesh Aggarwal is a Distinguished Security Engineer who has spent his career thinking like a hacker. For nearly two decades he has hunted fraudsters and abuse across fintech platforms, building the detection pipelines, automations, and controls that shut bad actors down. He now lives at the bleeding edge of GenAI and agentic AI security, secure-by-default agent patterns, adversarial pen-testing and prompt-injection defense. He breaks things to understand them and stays a step ahead of attackers, usually spotting the weaknessess before they do.

\n\n

Mukesh has spoken at RSA Conference (OWASP GenAI Security Track), RenderATL, and the Intel Capital CISO Summit on AI safety, fraud, and offensive security, and is a member of the GIAC Advisory Board.

\n\n

Off the clock he is a die-hard offensive-security tinkerer who reverse-engineers hardware and apps, pokes at IoT security, writes autonomous bots, and automates his home. He also mentors the next wave of offensive and AI security practitioners.

\n\n\nLinks:
    GitHub - https://github.com/hackerabhinavverma/Damn-Vulnerable-Agentic-AI-Application
\n\'',NULL,1293617),('2_Friday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'Damn Vulnerable Agentic AI Application (DVAIA)\'','\'Abhinav Verma,Mukesh Aggarwal\'','Demo Labs_7ad1db9e9f598b2b2716c3df8cbf7098','\'Title: Damn Vulnerable Agentic AI Application (DVAIA)
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

AI-powered Agentic applications now execute database queries, read files, send emails, and call APIs on behalf of users — all triggered through a chat window. DVAIA (Damn Vulnerable Agentic AI Application) is a new open-source platform purpose-built to let you break them.

\n\n

DVAIA pairs a production-grade secure platform with deliberately vulnerable AI-powered chat agents, each isolated in its own database and mapped to the OWASP Top 10 for LLM Applications 2025. In this demo we live-exploit nine exercise categories covering 93 attack objectives:

\n\n
    \n
  • Prompt injection: extract system prompts, jailbreak filters, poison RAG documents, and hijack an email-summarization agent
  • \n
  • SQL and NoSQL injection through AI: trick chat agents into constructing malicious queries — the injection never touches a traditional input field
  • \n
  • Sensitive info disclosure: chain path traversal and SSRF through a banking agent\'s tool interface to read server secrets and probe internal services
  • \n
  • Excessive agency and BOLA: make a customer-service agent access other users\' data, create unauthorized orders, and issue fraudulent refunds
  • \n
  • XSS and CSRF through LLM output: reflected, stored, and LLM-generated cross-site scripting fired from chat responses
  • \n
  • Supply chain RCE: exploit a poisoned dependency through conversation with a code-analysis agent
  • \n
\n\nSpeakers:Abhinav Verma,Mukesh Aggarwal
\n
\nSpeakerBio:  Abhinav Verma
\n

Abhinav Verma is a Senior Staff Security Engineer at Intuit Inc. with 15+ years of experience across AI security, offensive security, red teaming, product security, and security operations. He currently leads AI security architecture reviews, AI penetration testing, and vulnerability management programs, with a focus on AI security, AI threat modeling, and securing large-scale cloud platforms.

\n\n

Over the course of his career at Intuit, he has built security automation, scaled continuous security scanning across thousands of assets, led secure design reviews for platforms serving millions of customers, and developed secure coding programs that have helped thousands of engineers shift security left. Abhinav was formerly an independent security researcher and has identified and reported vulnerabilities in numerous major online services and technology companies.

\n\n

He holds certifications including OSEP, OSCP, OSWP, GWAPT and CEH. Outside of work, Abhinav is a passionate gamer, a trained chef, an avid camper, and a mentor to aspiring offensive security practitioners.

\n\nSpeakerBio:  Mukesh Aggarwal
\n

Mukesh Aggarwal is a Distinguished Security Engineer who has spent his career thinking like a hacker. For nearly two decades he has hunted fraudsters and abuse across fintech platforms, building the detection pipelines, automations, and controls that shut bad actors down. He now lives at the bleeding edge of GenAI and agentic AI security, secure-by-default agent patterns, adversarial pen-testing and prompt-injection defense. He breaks things to understand them and stays a step ahead of attackers, usually spotting the weaknessess before they do.

\n\n

Mukesh has spoken at RSA Conference (OWASP GenAI Security Track), RenderATL, and the Intel Capital CISO Summit on AI safety, fraud, and offensive security, and is a member of the GIAC Advisory Board.

\n\n

Off the clock he is a die-hard offensive-security tinkerer who reverse-engineers hardware and apps, pokes at IoT security, writes autonomous bots, and automates his home. He also mentors the next wave of offensive and AI security practitioners.

\n\n\nLinks:
    GitHub - https://github.com/hackerabhinavverma/Damn-Vulnerable-Agentic-AI-Application
\n\'',NULL,1293618),('3_Saturday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'Empire 7: Shipping a C2 at AI Speed\'','\'Vincent \"Vinnybod\" Rose,Jake \"Hubbl3\" Krasnov,Anthony \"Coin\" Rose\'','Demo Labs_78395b25e0d892e7d3811b2c396ac511','\'Title: Empire 7: Shipping a C2 at AI Speed
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | DevOps | Malware | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

Empire 7 is a near-total overhaul of the Command and Control (C2) framework, from how agents communicate with the server to how operators move through engagements. This major release continues to expand Empire\'s supported agents to include PowerShell, Python, IronPython, Go, C#, and now C. New tradecraft includes more than 50 new modules derived from Atomic Red Team, patchless AMSI/ETW bypasses, EarlyBird process hollowing, BOF execution with ILRepack assembly merging, and RDP session hijacking, among others. Empire\'s new cryptographically secure communications leverage AES-256-GCM and mTLS, with MITRE ATT&CK integration to assist in emulating real-world Advanced Persistent Threat (APT) Tactics, Techniques, and Procedures (TTPs).

\n\n

One more thing we\'ll talk about, this release shipped at roughly 10x our prior pace, due to our team’s adoption of agentic coding tools as a core development collaborator. We\'ll share what worked, what didn\'t, and what LLM-assisted offensive tooling development looks like.

\n\nSpeakers:Vincent \"Vinnybod\" Rose,Jake \"Hubbl3\" Krasnov,Anthony \"Coin\" Rose
\n
\nSpeakerBio:  Vincent \"Vinnybod\" Rose
\n

Vincent \"Vinnybod\" Rose is the Lead Developer for Empire and Starkiller. He is a software engineer with a decade of expertise in building highly scalable cloud services, improving developer operations, and automation. Recently, his focus has been on the reliability and stability of the Empire C2 server. Vinnybod has presented at Black Hat and has taught courses at DEF CON on Red Teaming and Offensive PowerShell. He currently maintains a cybersecurity blog focused on offensive security at https://bcsecurity.io/blog/.

\n\nSpeakerBio:  Jake \"Hubbl3\" Krasnov
\n

Jake \"Hubble\" Krasnov is the Red Team Operations Lead at BC Security, with a distinguished career spanning engineering and cybersecurity. A U.S. Air Force veteran, Jake began his career as an Astronautical Engineer overseeing rocket modifications, leading test and evaluation efforts for the F-22, and conducting red team operations with the 57th Information Aggressors. He later served as a Technical Lead Engineer at Boeing Phantom Works, where he focused on embedded security for aviation and space defense projects. A seasoned speaker and trainer, Jake has presented at DEF CON, Black Hat, HackRedCon, HackSpaceCon, and HackMiami, and has previously taught Empire and offensive PowerShell at DEF CON.

\n\nSpeakerBio:  Anthony \"Coin\" Rose
\n

Dr. Anthony \"Coin\" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.

\n\n\nLinks:
    GitHub - https://github.com/BC-SECURITY/Empire
\n\'',NULL,1293619),('2_Friday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'Empire 7: Shipping a C2 at AI Speed\'','\'Vincent \"Vinnybod\" Rose,Jake \"Hubbl3\" Krasnov,Anthony \"Coin\" Rose\'','Demo Labs_8af408e7807525e1d28db9816e46ebc3','\'Title: Empire 7: Shipping a C2 at AI Speed
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | DevOps | Malware | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

Empire 7 is a near-total overhaul of the Command and Control (C2) framework, from how agents communicate with the server to how operators move through engagements. This major release continues to expand Empire\'s supported agents to include PowerShell, Python, IronPython, Go, C#, and now C. New tradecraft includes more than 50 new modules derived from Atomic Red Team, patchless AMSI/ETW bypasses, EarlyBird process hollowing, BOF execution with ILRepack assembly merging, and RDP session hijacking, among others. Empire\'s new cryptographically secure communications leverage AES-256-GCM and mTLS, with MITRE ATT&CK integration to assist in emulating real-world Advanced Persistent Threat (APT) Tactics, Techniques, and Procedures (TTPs).

\n\n

One more thing we\'ll talk about, this release shipped at roughly 10x our prior pace, due to our team’s adoption of agentic coding tools as a core development collaborator. We\'ll share what worked, what didn\'t, and what LLM-assisted offensive tooling development looks like.

\n\nSpeakers:Vincent \"Vinnybod\" Rose,Jake \"Hubbl3\" Krasnov,Anthony \"Coin\" Rose
\n
\nSpeakerBio:  Vincent \"Vinnybod\" Rose
\n

Vincent \"Vinnybod\" Rose is the Lead Developer for Empire and Starkiller. He is a software engineer with a decade of expertise in building highly scalable cloud services, improving developer operations, and automation. Recently, his focus has been on the reliability and stability of the Empire C2 server. Vinnybod has presented at Black Hat and has taught courses at DEF CON on Red Teaming and Offensive PowerShell. He currently maintains a cybersecurity blog focused on offensive security at https://bcsecurity.io/blog/.

\n\nSpeakerBio:  Jake \"Hubbl3\" Krasnov
\n

Jake \"Hubble\" Krasnov is the Red Team Operations Lead at BC Security, with a distinguished career spanning engineering and cybersecurity. A U.S. Air Force veteran, Jake began his career as an Astronautical Engineer overseeing rocket modifications, leading test and evaluation efforts for the F-22, and conducting red team operations with the 57th Information Aggressors. He later served as a Technical Lead Engineer at Boeing Phantom Works, where he focused on embedded security for aviation and space defense projects. A seasoned speaker and trainer, Jake has presented at DEF CON, Black Hat, HackRedCon, HackSpaceCon, and HackMiami, and has previously taught Empire and offensive PowerShell at DEF CON.

\n\nSpeakerBio:  Anthony \"Coin\" Rose
\n

Dr. Anthony \"Coin\" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.

\n\n\nLinks:
    GitHub - https://github.com/BC-SECURITY/Empire
\n\'',NULL,1293620),('2_Friday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'Ghost in the IDE\'','\'Venkata Jayaram Yalla,Pardhiv Reddy\'','Demo Labs_eaf256bae3e39ef49a936b241e6ee44d','\'Title: Ghost in the IDE
\nTags: Intro/Beginner | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\nHook: The Blind Spot
\nYour EDR sees the server compromise. Your SIEM catches the phishing campaign. Your firewall blocks the C2 traffic. But what happens when the attacker doesn\'t target your infrastructure—they target your developers?
\n\n

28 million developers worldwide rely on three IDE platforms: JetBrains IntelliJ, Microsoft VS Code, and Eclipse. These aren\'t just text editors—they\'re command-and-control platforms disguised as productivity tools. Developers trust them with AWS credentials, database passwords, SSH keys, source code, and network access to production systems. And here\'s the kicker: IDE plugins run with full user privileges, no sandboxing, no permission dialogs, no questions asked.

\n\n

We built GHOST IN THE IDE, a production-ready C2 framework that weaponizes IDE plugins across all three major platforms. Not a proof-of-concept. Not a research prototype. A functional red team tool with keystroke logging, clipboard monitoring, file exfiltration, and remote command execution—working silently inside IntelliJ, VS Code, and Eclipse on Windows, macOS, and Linux.

\n\n

The Attack: Multi-IDE C2 That Actually Works\nMost IDE plugin research stops at \"look, I can pop calc.exe from VS Code.\" We went further. Way further.

\n\nSpeakers:Venkata Jayaram Yalla,Pardhiv Reddy
\n
\nSpeakerBio:  Venkata Jayaram Yalla
\n

Yalla, Jayaram is Director – Application Security at S&P Global, leading enterprise-wide initiatives in secure application development, vulnerability management, and security architecture. He has transformed the Application Security function from a primarily tactical penetration-testing team into a strategic security engineering organization, emphasizing automation, governance, and advanced threat modeling.

\n\n

Jayaram combines deep hands-on experience in offensive security and research (including multiple CVEs) with ownership of large-scale AppSec programs across SAST, SCA, DAST, CI/CD security, and emerging AI security initiatives.

\n\nSpeakerBio:  Pardhiv Reddy
\n

Pardhiv is a security specialist with vast experience in the field of information security ranging from health care,hospitality, banking and government sectors throughout the world. He also earned many industry standard certifications in the security, some of them are SANS GPEN, OSCP, OSWP, CISSP, Security+, ISO 27001 LA and many others.

\n\n

Pardhiv\'s interest areas includes cloud security and IOT security and his research has been presented at EuropeanSec 2016 in Portugal. His expertise helped teams to build secure products and applications by providing security guidelines and best practices.

\n\n

Pardhiv has performed various iOT security assessments which includes both embedded hardware security, firmware analysis, mobile applications, network security including wireless communications and backend cloud server assessments.

\n\n

Pardhiv is also an active bug bounty hunter and helped many companies around the world by pointing their security vulnerabilities to make their application and products secure. He spares his free time to build prototypes and security research by learning new techniques and methodologies.

\n\n\n\'',NULL,1293621),('3_Saturday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'Ghost in the IDE\'','\'Venkata Jayaram Yalla,Pardhiv Reddy\'','Demo Labs_1abe3def95e372b23496562c71004054','\'Title: Ghost in the IDE
\nTags: Intro/Beginner | DEF CON Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\nHook: The Blind Spot
\nYour EDR sees the server compromise. Your SIEM catches the phishing campaign. Your firewall blocks the C2 traffic. But what happens when the attacker doesn\'t target your infrastructure—they target your developers?
\n\n

28 million developers worldwide rely on three IDE platforms: JetBrains IntelliJ, Microsoft VS Code, and Eclipse. These aren\'t just text editors—they\'re command-and-control platforms disguised as productivity tools. Developers trust them with AWS credentials, database passwords, SSH keys, source code, and network access to production systems. And here\'s the kicker: IDE plugins run with full user privileges, no sandboxing, no permission dialogs, no questions asked.

\n\n

We built GHOST IN THE IDE, a production-ready C2 framework that weaponizes IDE plugins across all three major platforms. Not a proof-of-concept. Not a research prototype. A functional red team tool with keystroke logging, clipboard monitoring, file exfiltration, and remote command execution—working silently inside IntelliJ, VS Code, and Eclipse on Windows, macOS, and Linux.

\n\n

The Attack: Multi-IDE C2 That Actually Works\nMost IDE plugin research stops at \"look, I can pop calc.exe from VS Code.\" We went further. Way further.

\n\nSpeakers:Venkata Jayaram Yalla,Pardhiv Reddy
\n
\nSpeakerBio:  Venkata Jayaram Yalla
\n

Yalla, Jayaram is Director – Application Security at S&P Global, leading enterprise-wide initiatives in secure application development, vulnerability management, and security architecture. He has transformed the Application Security function from a primarily tactical penetration-testing team into a strategic security engineering organization, emphasizing automation, governance, and advanced threat modeling.

\n\n

Jayaram combines deep hands-on experience in offensive security and research (including multiple CVEs) with ownership of large-scale AppSec programs across SAST, SCA, DAST, CI/CD security, and emerging AI security initiatives.

\n\nSpeakerBio:  Pardhiv Reddy
\n

Pardhiv is a security specialist with vast experience in the field of information security ranging from health care,hospitality, banking and government sectors throughout the world. He also earned many industry standard certifications in the security, some of them are SANS GPEN, OSCP, OSWP, CISSP, Security+, ISO 27001 LA and many others.

\n\n

Pardhiv\'s interest areas includes cloud security and IOT security and his research has been presented at EuropeanSec 2016 in Portugal. His expertise helped teams to build secure products and applications by providing security guidelines and best practices.

\n\n

Pardhiv has performed various iOT security assessments which includes both embedded hardware security, firmware analysis, mobile applications, network security including wireless communications and backend cloud server assessments.

\n\n

Pardhiv is also an active bug bounty hunter and helped many companies around the world by pointing their security vulnerabilities to make their application and products secure. He spares his free time to build prototypes and security research by learning new techniques and methodologies.

\n\n\n\'',NULL,1293622),('3_Saturday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'GhostCatcher (endpoint detection agent)\'','\'Sercan Okur\'','Demo Labs_06cde76a2cd8a8d7ff851c813729147c','\'Title: GhostCatcher (endpoint detection agent)
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Purple Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

GhostCatcher is an open-source Linux endpoint detection agent written in Go. It runs as a single binary or a systemd service and looks for host-visible adversary tradecraft on Linux: web shells, LD_PRELOAD abuse, SSH, cron, and systemd persistence, PAM/sudoers tampering, SUID and capability drift, reverse shells and unexpected network behavior, reflective / memory-map signals, and related patterns aligned with MITRE ATT&CK-style coverage.\nDetections are driven by a versioned, optionally signed rule pack, baselines and learning mode, multi-signal scoring, time-windowed correlation, CEL-style boolean expressions, optional Sigma-lite rules, optional YARA (disk and memory) and eBPF (with auditd/proc fallbacks), and JSONL output to stdout plus optional syslog, Splunk HEC, Elasticsearch _bulk, or Grafana Loki. The goal is to give blue teams a transparent, self-hosted way to turn Linux host telemetry into actionable events in the SIEM—without a vendor cloud control plane.

\n\nSpeakerBio:  Sercan Okur
\n

Sercan Okur is the Founder and CEO of NextRay AI Detection & Response, Inc., a San Jose–based cybersecurity company building AI-driven Network Detection and Response technology. A cybersecurity practitioner with more than fifteen years of experience across critical-infrastructure, defense, and enterprise environments,

\n\n\nLinks:
    GitHub - https://github.com/sercanokur/GhostCatcherEDR
\n\'',NULL,1293623),('2_Friday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'GhostCatcher (endpoint detection agent)\'','\'Sercan Okur\'','Demo Labs_6b54f175d246dd854024e3409d954b8c','\'Title: GhostCatcher (endpoint detection agent)
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

GhostCatcher is an open-source Linux endpoint detection agent written in Go. It runs as a single binary or a systemd service and looks for host-visible adversary tradecraft on Linux: web shells, LD_PRELOAD abuse, SSH, cron, and systemd persistence, PAM/sudoers tampering, SUID and capability drift, reverse shells and unexpected network behavior, reflective / memory-map signals, and related patterns aligned with MITRE ATT&CK-style coverage.\nDetections are driven by a versioned, optionally signed rule pack, baselines and learning mode, multi-signal scoring, time-windowed correlation, CEL-style boolean expressions, optional Sigma-lite rules, optional YARA (disk and memory) and eBPF (with auditd/proc fallbacks), and JSONL output to stdout plus optional syslog, Splunk HEC, Elasticsearch _bulk, or Grafana Loki. The goal is to give blue teams a transparent, self-hosted way to turn Linux host telemetry into actionable events in the SIEM—without a vendor cloud control plane.

\n\nSpeakerBio:  Sercan Okur
\n

Sercan Okur is the Founder and CEO of NextRay AI Detection & Response, Inc., a San Jose–based cybersecurity company building AI-driven Network Detection and Response technology. A cybersecurity practitioner with more than fifteen years of experience across critical-infrastructure, defense, and enterprise environments,

\n\n\nLinks:
    GitHub - https://github.com/sercanokur/GhostCatcherEDR
\n\'',NULL,1293624),('2_Friday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'GnawLab: Open-Source AWS Attack Scenarios Based on Real-World Breaches\'','\'ialleejy,Kyul,HyunJun \"Beaver King\" Kwon\'','Demo Labs_390b0f774d9ecd8f662abef099712f33','\'Title: GnawLab: Open-Source AWS Attack Scenarios Based on Real-World Breaches
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | Cloud | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

GnawLab is a community-driven, open-source offensive cloud security training platform that recreates real-world AWS\n attack chains. Each scenario is modeled after documented breaches—Capital One\'s SSRF-to-IMDS pivot, Uber\'s leaked\n credential exploitation, SolarWinds-style CI/CD pipeline hijacking—deployed via Terraform in your own AWS account.\n Attendees will see live demonstrations of multi-hop attack chains: from SSRF and command injection entry points,\n through IMDS credential theft and Secrets Manager extraction, to full CI/CD pipeline compromise with Blue/Green\n deployment backdoors. GnawLab bridges the gap between theoretical cloud security knowledge and hands-on exploitation\n skills.

\n\nSpeakers:ialleejy,Kyul,HyunJun \"Beaver King\" Kwon
\n
\nSpeakerBio:  ialleejy
\n

I am ialleejy, a Security Researcher at ENKI focusing on web security and cloud security. I have created WEB challenges for CODEGATE and HACKTHEON SEJONG CTF, and I am interested in designing CTF challenges that connect real-world service architectures with practical vulnerability research.

\n\n

Recently, I have been exploring Offensive Cloud Security, especially how traditional web vulnerabilities can lead to privilege escalation, credential exposure, and abuse of trust relationships in cloud environments. I am currently diving deeper into AWS Bedrock AI Agents, RAG-based knowledge poisoning, OIDC authentication flows, and IAM trust policies.

\n\n

Through this talk, I aim to show how a small vulnerability on the web can evolve into a broader cloud security issue, crossing trust boundaries between applications, identities, and cloud services.

\n\nSpeakerBio:  Kyul
\n

I am a college student relentlessly exploring cloud vulnerabilities. I possess an exceptionally high threshold for hunting, gathering, and deeply analyzing whatever piques my interest.

\n\n

My mindset is clear: effective defense demands an attacker\'s lens. Only by understanding actual infiltration paths and how they trigger critical risks can defenders accurately prioritize assets and build robust controls.

\n\n

Driven by this, I’ve operated at the intersection of Red and Blue. In incident response projects, I analyzed real-world TTPs to build attack scenarios while collaborating to engineer detection rules and automated responses. I’ve also researched and presented how AWS misconfigurations can be weaponized to cause cascading breaches.

\n\n

Currently, alongside the BeaverDam community, I am developing GnawLab for the DEF CON Demo Lab. GnawLab is an open-source, community-driven cloud security training platform. It provides high-fidelity sandbox environments reflecting real-world flaws, enabling players to execute realistic scenarios and vividly master cloud exploitation and analysis.

\n\n

At DEFCON, my goal isn\'t just to show what I\'ve built. I want to share this sandbox, break it alongside you, and absorb the brilliant, diverse approaches of world-class hackers. I am here to hack, learn, and grow together.

\n\nSpeakerBio:  HyunJun \"Beaver King\" Kwon
\n

HyunJun Kwon is an Application and Cloud Security Engineer\n with 12 years of offensive security experience. Currently at\n Rapport Labs in Korea, he previously led vulnerability\n assessments, DevSecOps, and cloud security initiatives at\n Woowa Brothers, the company behind Baemin, South Korea\'s\n largest food delivery platform.

\n\n

He serves as an AWS Community Builder for security and leads\n the Beaver Dam Community, an offensive cloud security research\n group. He also contributes to AWS Bedrock Agent Samples and\n mentors junior security professionals through programs like\n Baby Beavers, K-Shield Junior, and Whitehat School.

\n\n

His cloud security research focuses on scaling security in\n dynamic environments. He built automated CCE assessment\n systems using AWS VPC Endpoints and Systems Manager. Recently\n he explored AI and security intersections, building LangChain\n and LangGraph agents for infrastructure assessment automation\n and MCP security checkers to detect supply chain risks.

\n\n

He won the 2021 HDCON Grand Prize for cloud security\n architecture and authored two books on web hacking. He spoke\n at .HACK 2025 on Offensive Cloud Security and at .HACK 2026 on\n whether CloudTrail and GuardDuty are really enough.

\n\n\nLinks:
    GitHub - https://github.com/Beaver-Dam-Community/GnawLab
\n\'',NULL,1293625),('3_Saturday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'GnawLab: Open-Source AWS Attack Scenarios Based on Real-World Breaches\'','\'ialleejy,Kyul,HyunJun \"Beaver King\" Kwon\'','Demo Labs_5e2c7f57bf59021bb3bc32af400bbeb2','\'Title: GnawLab: Open-Source AWS Attack Scenarios Based on Real-World Breaches
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | Cloud | Offense/Red Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

GnawLab is a community-driven, open-source offensive cloud security training platform that recreates real-world AWS\n attack chains. Each scenario is modeled after documented breaches—Capital One\'s SSRF-to-IMDS pivot, Uber\'s leaked\n credential exploitation, SolarWinds-style CI/CD pipeline hijacking—deployed via Terraform in your own AWS account.\n Attendees will see live demonstrations of multi-hop attack chains: from SSRF and command injection entry points,\n through IMDS credential theft and Secrets Manager extraction, to full CI/CD pipeline compromise with Blue/Green\n deployment backdoors. GnawLab bridges the gap between theoretical cloud security knowledge and hands-on exploitation\n skills.

\n\nSpeakers:ialleejy,Kyul,HyunJun \"Beaver King\" Kwon
\n
\nSpeakerBio:  ialleejy
\n

I am ialleejy, a Security Researcher at ENKI focusing on web security and cloud security. I have created WEB challenges for CODEGATE and HACKTHEON SEJONG CTF, and I am interested in designing CTF challenges that connect real-world service architectures with practical vulnerability research.

\n\n

Recently, I have been exploring Offensive Cloud Security, especially how traditional web vulnerabilities can lead to privilege escalation, credential exposure, and abuse of trust relationships in cloud environments. I am currently diving deeper into AWS Bedrock AI Agents, RAG-based knowledge poisoning, OIDC authentication flows, and IAM trust policies.

\n\n

Through this talk, I aim to show how a small vulnerability on the web can evolve into a broader cloud security issue, crossing trust boundaries between applications, identities, and cloud services.

\n\nSpeakerBio:  Kyul
\n

I am a college student relentlessly exploring cloud vulnerabilities. I possess an exceptionally high threshold for hunting, gathering, and deeply analyzing whatever piques my interest.

\n\n

My mindset is clear: effective defense demands an attacker\'s lens. Only by understanding actual infiltration paths and how they trigger critical risks can defenders accurately prioritize assets and build robust controls.

\n\n

Driven by this, I’ve operated at the intersection of Red and Blue. In incident response projects, I analyzed real-world TTPs to build attack scenarios while collaborating to engineer detection rules and automated responses. I’ve also researched and presented how AWS misconfigurations can be weaponized to cause cascading breaches.

\n\n

Currently, alongside the BeaverDam community, I am developing GnawLab for the DEF CON Demo Lab. GnawLab is an open-source, community-driven cloud security training platform. It provides high-fidelity sandbox environments reflecting real-world flaws, enabling players to execute realistic scenarios and vividly master cloud exploitation and analysis.

\n\n

At DEFCON, my goal isn\'t just to show what I\'ve built. I want to share this sandbox, break it alongside you, and absorb the brilliant, diverse approaches of world-class hackers. I am here to hack, learn, and grow together.

\n\nSpeakerBio:  HyunJun \"Beaver King\" Kwon
\n

HyunJun Kwon is an Application and Cloud Security Engineer\n with 12 years of offensive security experience. Currently at\n Rapport Labs in Korea, he previously led vulnerability\n assessments, DevSecOps, and cloud security initiatives at\n Woowa Brothers, the company behind Baemin, South Korea\'s\n largest food delivery platform.

\n\n

He serves as an AWS Community Builder for security and leads\n the Beaver Dam Community, an offensive cloud security research\n group. He also contributes to AWS Bedrock Agent Samples and\n mentors junior security professionals through programs like\n Baby Beavers, K-Shield Junior, and Whitehat School.

\n\n

His cloud security research focuses on scaling security in\n dynamic environments. He built automated CCE assessment\n systems using AWS VPC Endpoints and Systems Manager. Recently\n he explored AI and security intersections, building LangChain\n and LangGraph agents for infrastructure assessment automation\n and MCP security checkers to detect supply chain risks.

\n\n

He won the 2021 HDCON Grand Prize for cloud security\n architecture and authored two books on web hacking. He spoke\n at .HACK 2025 on Offensive Cloud Security and at .HACK 2026 on\n whether CloudTrail and GuardDuty are really enough.

\n\n\nLinks:
    GitHub - https://github.com/Beaver-Dam-Community/GnawLab
\n\'',NULL,1293626),('3_Saturday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Goose Processing Unit (GPU): VRAM as an Unmonitored Attack Surface\'','\'Gannon \"Dorf\" Gebauer,Anthony \"Coin\" Rose,Hana Christensen\'','Demo Labs_01004a7fd39249376c6eb6c46afa535d','\'Title: Goose Processing Unit (GPU): VRAM as an Unmonitored Attack Surface
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | Malware | Offense/Red Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

Modern GPUs have become foundational to computing infrastructure for gaming, machine learning, and AI workloads at scale, yet GPU memory remains a largely unmonitored attack surface. No mainstream antivirus or endpoint-detection solution currently inspects it, creating a significant blind spot that sophisticated adversaries can exploit. This Demo Lab presents a novel technique that uses NVIDIA RTX 5090 CUDA APIs to stage payload data, such as DLLs, directly in GPU memory, entirely outside the visibility of host-based security tools, including Windows Defender. A benign executable, with no malicious code of its own, uses CUDA\'s native memory transfer capabilities to move binary payload data onto the GPU immediately upon execution. No CUDA Toolkit installation is required on the target host. When triggered, the same executable retrieves the payload from GPU memory, manually maps it into process space, and executes it. A working proof of concept has been validated as an Empire C2 module, confirming practical operational viability. The technique is particularly impactful for high-uptime environments such as AI inference servers, rendering farms, and enterprise GPU clusters, where small executables interacting with the GPU blend naturally into background workloads.

\n\nSpeakers:Gannon \"Dorf\" Gebauer,Anthony \"Coin\" Rose,Hana Christensen
\n
\nSpeakerBio:  Gannon \"Dorf\" Gebauer
\n

Gannon \"Dorf\" Gebauer is a second lieutenant in the United States Air Force pursuing a master\'s in computer science at the Air Force Institute of Technology. He earned a Bachelor of Science in Computer Science from Arizona State University. His expertise spans red team operations, reverse engineering, and offensive tool development, and his current research focuses on novel persistence techniques that abuse GPU memory as an unmonitored attack surface.

\n\nSpeakerBio:  Anthony \"Coin\" Rose
\n

Dr. Anthony \"Coin\" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.

\n\nSpeakerBio:  Hana Christensen
\n

Hana Christensen is a second lieutenant and developmental engineer (electrical) in the United States Air Force. She is currently pursuing a master\'s in electrical engineering, with a focus on signal processing and machine learning. Her research investigates security vulnerabilities in AI hardware, examining whether side-channel analysis can be used to extract information about machine learning algorithms. She holds a B.S. in Electrical and Computer Engineering from the United States Air Force Academy (class of 2025).

\n\n\n\'',NULL,1293627),('2_Friday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Goose Processing Unit (GPU): VRAM as an Unmonitored Attack Surface\'','\'Gannon \"Dorf\" Gebauer,Anthony \"Coin\" Rose,Hana Christensen\'','Demo Labs_fa04e26391e0cb6b48f9399d8e32a441','\'Title: Goose Processing Unit (GPU): VRAM as an Unmonitored Attack Surface
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | Malware | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

Modern GPUs have become foundational to computing infrastructure for gaming, machine learning, and AI workloads at scale, yet GPU memory remains a largely unmonitored attack surface. No mainstream antivirus or endpoint-detection solution currently inspects it, creating a significant blind spot that sophisticated adversaries can exploit. This Demo Lab presents a novel technique that uses NVIDIA RTX 5090 CUDA APIs to stage payload data, such as DLLs, directly in GPU memory, entirely outside the visibility of host-based security tools, including Windows Defender. A benign executable, with no malicious code of its own, uses CUDA\'s native memory transfer capabilities to move binary payload data onto the GPU immediately upon execution. No CUDA Toolkit installation is required on the target host. When triggered, the same executable retrieves the payload from GPU memory, manually maps it into process space, and executes it. A working proof of concept has been validated as an Empire C2 module, confirming practical operational viability. The technique is particularly impactful for high-uptime environments such as AI inference servers, rendering farms, and enterprise GPU clusters, where small executables interacting with the GPU blend naturally into background workloads.

\n\nSpeakers:Gannon \"Dorf\" Gebauer,Anthony \"Coin\" Rose,Hana Christensen
\n
\nSpeakerBio:  Gannon \"Dorf\" Gebauer
\n

Gannon \"Dorf\" Gebauer is a second lieutenant in the United States Air Force pursuing a master\'s in computer science at the Air Force Institute of Technology. He earned a Bachelor of Science in Computer Science from Arizona State University. His expertise spans red team operations, reverse engineering, and offensive tool development, and his current research focuses on novel persistence techniques that abuse GPU memory as an unmonitored attack surface.

\n\nSpeakerBio:  Anthony \"Coin\" Rose
\n

Dr. Anthony \"Coin\" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference.

\n\nSpeakerBio:  Hana Christensen
\n

Hana Christensen is a second lieutenant and developmental engineer (electrical) in the United States Air Force. She is currently pursuing a master\'s in electrical engineering, with a focus on signal processing and machine learning. Her research investigates security vulnerabilities in AI hardware, examining whether side-channel analysis can be used to extract information about machine learning algorithms. She holds a B.S. in Electrical and Computer Engineering from the United States Air Force Academy (class of 2025).

\n\n\n\'',NULL,1293628),('3_Saturday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'Hook Crook - Extracting More From Discord Webhooks\'','\'Jeremy Banker - K0JLB,Arity0\'','Demo Labs_1339aa3785cbdcd5cbf3084e024645d3','\'Title: Hook Crook - Extracting More From Discord Webhooks
\nTags: Intro/Beginner | DEF CON Demo Labs | AppSec | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

A webhook URL is often thought to be write-only — post a message, nothing more. So when one leaks through a misconfigured repo, a paste site, or breached infrastructure, it\'s written off as a spam-or-phishing nuisance and left to rot. Hook Crook shows that assumption is the vulnerability — and that \"write-only\" was never really the case.

\n\n

By abusing how Discord resolves references, what it returns when you query users and messages, and how its error and rate-limit responses differ, the write-only token quietly becomes a read primitive — leaking by design, not by bug. With nothing but the URL — no account, no additional authentication, no interaction from anyone on the target server — Hook Crook fingerprints the host guild, enumerates and confirms members, pulls profile data on known users (including their home-server tag), and in some cases recovers message content. The same behaviors let it bypass the server\'s posting restrictions, stage convincing impersonation and phishing, quietly edit or delete messages to scrub the evidence, and — on the way out — delete the webhook itself. None of it breaks Discord — it just reads Discord more carefully than its designers intended.

\n\nSpeakers:Jeremy Banker - K0JLB,Arity0
\n
\nSpeakerBio:  Jeremy Banker - K0JLB
\nBio: Jeremy Banker is a Senior Security Software Engineer at Horizon3.ai, focused on the reliability and resiliency of Horizon3\'s automated penetration testing platform. He previously spent nearly a decade at VMware, where he co-founded the Security Product Engineering group and led efforts to secure VMware\'s software supply chain. His open source security tooling, including Build Inspector for CI/CD pipeline anomaly detection and Tommyknocker for automated security control validation, has been featured at Black Hat Arsenal and DEF CON Demo Labs. A licensed amateur radio operator since 2010, he built open-packet, an MIT licensed Python client for packet messaging, after becoming frustrated with the existing closed-source options.
\n\n\n\nSpeakerBio:  Arity0
\n

Arity0 is an independent security researcher specializing in the Discord platform. A self-taught hacker, he focuses on uncovering undocumented behaviors, edge cases, and design-level privacy implications in Discord\'s API and rendering pipeline. His long-running exploration of Discord\'s rendering quirks led to the discovery of the webhook rendering oracles that form the foundation of the Hook Crook identity disclosure technique.

\n\n\nLinks:
    GitHub - https://github.com/HnC-Sec/hook_crook
\n\'',NULL,1293629),('3_Saturday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'Hook Crook - Extracting More From Discord Webhooks\'','\'Jeremy Banker - K0JLB,Arity0\'','Demo Labs_f315adaad43a813bdee065772c288375','\'Title: Hook Crook - Extracting More From Discord Webhooks
\nTags: Intro/Beginner | DEF CON Demo Labs | AppSec | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

A webhook URL is often thought to be write-only — post a message, nothing more. So when one leaks through a misconfigured repo, a paste site, or breached infrastructure, it\'s written off as a spam-or-phishing nuisance and left to rot. Hook Crook shows that assumption is the vulnerability — and that \"write-only\" was never really the case.

\n\n

By abusing how Discord resolves references, what it returns when you query users and messages, and how its error and rate-limit responses differ, the write-only token quietly becomes a read primitive — leaking by design, not by bug. With nothing but the URL — no account, no additional authentication, no interaction from anyone on the target server — Hook Crook fingerprints the host guild, enumerates and confirms members, pulls profile data on known users (including their home-server tag), and in some cases recovers message content. The same behaviors let it bypass the server\'s posting restrictions, stage convincing impersonation and phishing, quietly edit or delete messages to scrub the evidence, and — on the way out — delete the webhook itself. None of it breaks Discord — it just reads Discord more carefully than its designers intended.

\n\nSpeakers:Jeremy Banker - K0JLB,Arity0
\n
\nSpeakerBio:  Jeremy Banker - K0JLB
\nBio: Jeremy Banker is a Senior Security Software Engineer at Horizon3.ai, focused on the reliability and resiliency of Horizon3\'s automated penetration testing platform. He previously spent nearly a decade at VMware, where he co-founded the Security Product Engineering group and led efforts to secure VMware\'s software supply chain. His open source security tooling, including Build Inspector for CI/CD pipeline anomaly detection and Tommyknocker for automated security control validation, has been featured at Black Hat Arsenal and DEF CON Demo Labs. A licensed amateur radio operator since 2010, he built open-packet, an MIT licensed Python client for packet messaging, after becoming frustrated with the existing closed-source options.
\n\n\n\nSpeakerBio:  Arity0
\n

Arity0 is an independent security researcher specializing in the Discord platform. A self-taught hacker, he focuses on uncovering undocumented behaviors, edge cases, and design-level privacy implications in Discord\'s API and rendering pipeline. His long-running exploration of Discord\'s rendering quirks led to the discovery of the webhook rendering oracles that form the foundation of the Hook Crook identity disclosure technique.

\n\n\nLinks:
    GitHub - https://github.com/HnC-Sec/hook_crook
\n\'',NULL,1293630),('2_Friday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'Intercept.js: Runtime-Aware Detection for JavaScript Environments\'','\'Rishi Kant\'','Demo Labs_8737a195555cd14bd4775dcb51cbebe4','\'Title: Intercept.js: Runtime-Aware Detection for JavaScript Environments
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

Modern attacks increasingly execute inside JavaScript runtimes (browsers, email clients, and embedded app environments) where traditional file-scanning and OS-level controls lack visibility into application-layer behavior. In these contexts, payloads often exist only as in-memory buffers, fetch responses, or dynamically constructed objects. Detection therefore depends not just on inspecting bytes, but on understanding their origin, transformation, and use at runtime.

\n\n

We present Intercept.js, an open-source detection engine that runs natively within JavaScript environments, combining byte-level inspection with execution context in real time. Built for YARA compatibility, it extends rule evaluation beyond static artifacts by incorporating signals such as origin provenance, user gesture state, MIME inconsistencies, and object construction paths.

\n\n

This unified model enables detection of threats as they are assembled and executed — including identifying executable buffers built in memory, anomalous data flows, or content whose structure diverges from its declared type.

\n\n

As a concrete demonstration, we show how HTML smuggling attacks can be intercepted at the moment of payload construction, preventing delivery before artifacts ever reach disk and exposing a class of threats that evade both network and endpoint controls.

\n\nSpeakerBio:  Rishi Kant
\n

A builder at heart, Rishi has spent his career turning deep technical ideas into real-world impact. He holds a PhD in Electrical Engineering from Stanford, and earned his B.S. in EECS from UC Berkeley. After 4.5 years of advising global high-tech firms at McKinsey & Company, he followed his passion for building and moved into product management. Rishi led product teams at several cybersecurity companies—including Tanium, Authentic8, and Uptycs. Now, as founder of Sekant Security, he’s embedding runtime intelligence directly into web browsers to protect users from phishing, ClickFix, unsafe downloads, shadow AI and other emerging online threats.

\n\n\nLinks:
    GitHub - https://github.com/rishi-sekantsec/sekant-intercept-js
\n\'',NULL,1293631),('3_Saturday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'Intercept.js: Runtime-Aware Detection for JavaScript Environments\'','\'Rishi Kant\'','Demo Labs_18a71eb428166696211d7a74a9836836','\'Title: Intercept.js: Runtime-Aware Detection for JavaScript Environments
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

Modern attacks increasingly execute inside JavaScript runtimes (browsers, email clients, and embedded app environments) where traditional file-scanning and OS-level controls lack visibility into application-layer behavior. In these contexts, payloads often exist only as in-memory buffers, fetch responses, or dynamically constructed objects. Detection therefore depends not just on inspecting bytes, but on understanding their origin, transformation, and use at runtime.

\n\n

We present Intercept.js, an open-source detection engine that runs natively within JavaScript environments, combining byte-level inspection with execution context in real time. Built for YARA compatibility, it extends rule evaluation beyond static artifacts by incorporating signals such as origin provenance, user gesture state, MIME inconsistencies, and object construction paths.

\n\n

This unified model enables detection of threats as they are assembled and executed — including identifying executable buffers built in memory, anomalous data flows, or content whose structure diverges from its declared type.

\n\n

As a concrete demonstration, we show how HTML smuggling attacks can be intercepted at the moment of payload construction, preventing delivery before artifacts ever reach disk and exposing a class of threats that evade both network and endpoint controls.

\n\nSpeakerBio:  Rishi Kant
\n

A builder at heart, Rishi has spent his career turning deep technical ideas into real-world impact. He holds a PhD in Electrical Engineering from Stanford, and earned his B.S. in EECS from UC Berkeley. After 4.5 years of advising global high-tech firms at McKinsey & Company, he followed his passion for building and moved into product management. Rishi led product teams at several cybersecurity companies—including Tanium, Authentic8, and Uptycs. Now, as founder of Sekant Security, he’s embedding runtime intelligence directly into web browsers to protect users from phishing, ClickFix, unsafe downloads, shadow AI and other emerging online threats.

\n\n\nLinks:
    GitHub - https://github.com/rishi-sekantsec/sekant-intercept-js
\n\'',NULL,1293632),('3_Saturday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Keychecker : SSH Key based attack tool for DVCS Systems\'','\'Anant Shrivastava\'','Demo Labs_b8304ab42f479ab93a9237584ddce5ce','\'Title: Keychecker : SSH Key based attack tool for DVCS Systems
\nTags: Intro/Beginner | DEF CON Demo Labs | Defense/Blue Team | DevOps | Offense/Red Team | SecOps | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

KeyChecker is a CLI tool to fingerprint SSH private keys and identify which Git hosting accounts they unlock. In incident response and red team work, finding a private key is common, but scoping impact is slow and manual. KeyChecker automates the two primitives defenders and attackers both use: safe SSH handshakes that can reveal the mapped username, and read only git ls-remote probes that confirm whether a key can access a target repo.

\n\n

The tool performs local key intelligence first, supporting OpenSSH, PEM, and DER formats, detecting key type (ed25519, rsa, ecdsa, dsa), key size, passphrase protection, fingerprints (SHA256 and MD5), and useful metadata from key comments. It then validates the key across multiple providers including GitHub, GitLab, Bitbucket, Codeberg, Gitea, and Hugging Face, extracting usernames where possible, and optionally using a GitHub token for organization discovery.

\n\n

KeyChecker also supports repository discovery with a wordlist and configurable concurrency, giving a clear blast radius report like “this key unlocks these private repositories.” It is designed for authorized assessments, runs locally, and avoids write operations.

\n\nSpeakerBio:  Anant Shrivastava
\n

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

\n\n\nLinks:
    GitHub - https://github.com/cyfinoid/keychecker
\n\'',NULL,1293633),('3_Saturday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Keychecker : SSH Key based attack tool for DVCS Systems\'','\'Anant Shrivastava\'','Demo Labs_30b44ae63dae91bcaac11584a23ce776','\'Title: Keychecker : SSH Key based attack tool for DVCS Systems
\nTags: Intro/Beginner | DEF CON Demo Labs | Defense/Blue Team | DevOps | Offense/Red Team | SecOps | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

KeyChecker is a CLI tool to fingerprint SSH private keys and identify which Git hosting accounts they unlock. In incident response and red team work, finding a private key is common, but scoping impact is slow and manual. KeyChecker automates the two primitives defenders and attackers both use: safe SSH handshakes that can reveal the mapped username, and read only git ls-remote probes that confirm whether a key can access a target repo.

\n\n

The tool performs local key intelligence first, supporting OpenSSH, PEM, and DER formats, detecting key type (ed25519, rsa, ecdsa, dsa), key size, passphrase protection, fingerprints (SHA256 and MD5), and useful metadata from key comments. It then validates the key across multiple providers including GitHub, GitLab, Bitbucket, Codeberg, Gitea, and Hugging Face, extracting usernames where possible, and optionally using a GitHub token for organization discovery.

\n\n

KeyChecker also supports repository discovery with a wordlist and configurable concurrency, giving a clear blast radius report like “this key unlocks these private repositories.” It is designed for authorized assessments, runs locally, and avoids write operations.

\n\nSpeakerBio:  Anant Shrivastava
\n

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

\n\n\nLinks:
    GitHub - https://github.com/cyfinoid/keychecker
\n\'',NULL,1293634),('2_Friday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk and Security\'','\'Abhinav Khanna,Krishna Chaganti\'','Demo Labs_410ee729def850a10d45ee7cdeef84d0','\'Title: L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk and Security
\nTags: DEF CON Demo Labs | Intermediate | AppSec | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

Browser Extensions is one of the overlooked attack surface in the modern era. Most browser extension have permissions to allow direct access to cookies, browsing history, network requests and a poorly written extension can help attackers with stuff like silently steal credentials, log keystrokes, fingerprint users etc.

\n\n

L.A.Y.E.R.S. (Logical Analyst for Your Extension Risk Surface) is a fully client-side chrome browser extension security engine that performs multi-layered security analysis on extensions. The tool performs analysis on various levels like JS analysis, permissions analysis, manifest analysis, secret scanning, URL extractions etc. simultaneously to uncover potential risks. The tool comes with its own scoring system guiding the team if the extension is safe to use or not.

\n\n

L.A.Y.E.R.S. is designed for security researchers auditing in-house extensions, third-party extensions, red teams assessing browser attack surfaces, enterprises enforcing extension policies, and developers seeking to harden their own extensions before publication.

\n\n

What sets L.A.Y.E.R.S. apart begins with its privacy-first architecture - the entire analysis runs in-browser via the File System API and JSZip, with very little setup required. On the detection side, it incorporates Shannon entropy analysis. To keep results actionable rat

\n\nSpeakers:Abhinav Khanna,Krishna Chaganti
\n
\nSpeakerBio:  Abhinav Khanna
\n

Abhinav is an Information Security Professional with 7+ years of experience and currently works at S&P Global. His area of expertise include Web App Security, API Security, Mobile App Security, Secure Architecture. He has spoken at conferences like BlackHat USA, DefCon 33, BlackHat Europe, BlackHat Asia etc.

\n\nSpeakerBio:  Krishna Chaganti
\n

Krishna Chaganti works as Associate Director Application Security at S&P Global, based in the USA, with over a decade of experience in Information Security. As a Certified Information Security Manager (CISM), he leads a team of more than 10 pentesters and specializes in Application Security along with Security Architecture.

\n\n\nLinks:
    GitHub - https://github.com/infosecak/layers
\n\'',NULL,1293635),('3_Saturday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk and Security\'','\'Abhinav Khanna,Krishna Chaganti\'','Demo Labs_f4eb309f3f977a661a79b282edeb648a','\'Title: L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk and Security
\nTags: DEF CON Demo Labs | Intermediate | AppSec | Offense/Red Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

Browser Extensions is one of the overlooked attack surface in the modern era. Most browser extension have permissions to allow direct access to cookies, browsing history, network requests and a poorly written extension can help attackers with stuff like silently steal credentials, log keystrokes, fingerprint users etc.

\n\n

L.A.Y.E.R.S. (Logical Analyst for Your Extension Risk Surface) is a fully client-side chrome browser extension security engine that performs multi-layered security analysis on extensions. The tool performs analysis on various levels like JS analysis, permissions analysis, manifest analysis, secret scanning, URL extractions etc. simultaneously to uncover potential risks. The tool comes with its own scoring system guiding the team if the extension is safe to use or not.

\n\n

L.A.Y.E.R.S. is designed for security researchers auditing in-house extensions, third-party extensions, red teams assessing browser attack surfaces, enterprises enforcing extension policies, and developers seeking to harden their own extensions before publication.

\n\n

What sets L.A.Y.E.R.S. apart begins with its privacy-first architecture - the entire analysis runs in-browser via the File System API and JSZip, with very little setup required. On the detection side, it incorporates Shannon entropy analysis. To keep results actionable rat

\n\nSpeakers:Abhinav Khanna,Krishna Chaganti
\n
\nSpeakerBio:  Abhinav Khanna
\n

Abhinav is an Information Security Professional with 7+ years of experience and currently works at S&P Global. His area of expertise include Web App Security, API Security, Mobile App Security, Secure Architecture. He has spoken at conferences like BlackHat USA, DefCon 33, BlackHat Europe, BlackHat Asia etc.

\n\nSpeakerBio:  Krishna Chaganti
\n

Krishna Chaganti works as Associate Director Application Security at S&P Global, based in the USA, with over a decade of experience in Information Security. As a Certified Information Security Manager (CISM), he leads a team of more than 10 pentesters and specializes in Application Security along with Security Architecture.

\n\n\nLinks:
    GitHub - https://github.com/infosecak/layers
\n\'',NULL,1293636),('3_Saturday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'LoKi: A LoRa/Meshtastic based implant for Red Teaming\'','\'Venky Raju\'','Demo Labs_75f90d9c300b5ae162aeb3a0d1a518c5','\'Title: LoKi: A LoRa/Meshtastic based implant for Red Teaming
\nTags: Intro/Beginner | DEF CON Demo Labs | Hardware/IoT | Offense/Red Team | Wireless/RF | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

LoKi is a covert USB HID implant for Red Teaming that builds on the work of tools like the O.MG cable by replacing Wi-Fi with LoRa, extending the operational range of physical layer attacks from meters to kilometers. The implant integrates a Heltec LoRa module with custom Meshtastic firmware into an off-the-shelf wired USB mouse, retaining full mouse functionality. When LoKi receives a direct Meshtastic message, it translates the payload into DuckyScript™-compatible USB HID keystrokes and executes them on the host machine. No Wi-Fi, no Bluetooth, and no network traffic — the mouse simply begins typing. LoKi requires no line of sight and produces no detectable wireless LAN or Bluetooth signatures, making it effectively invisible to standard wireless monitoring. The live demo will walk through a payload from a handheld Meshtastic device to acquire a remote admin shell and bypass UAC on a target machine. Bring your own Meshtastic device and you can send commands to the implant during the demo. The presentation covers the hardware build, the customized open-source Meshtastic firmware, reliability considerations for keystroke delivery over a mesh network, and actionable blue team detection strategies, including monitoring for rogue HID device enumeration and LoRa RF activity.

\n\nSpeakerBio:  Venky Raju
\n

Venky Raju is a lifelong maker and hacker who firmly believes that if you haven\'t voided the warranty, you don\'t truly own it. While he holds a Master’s in Comp. Sci. and an EE degree, his most prized \"certifications\" were earned at the business end of a soldering iron, a 3D printer, and an array of metal and wood-working tools.

\n\n

By day, he navigates the complex worlds of Zero Trust, IoT, and OT security. To keep the corporate world happy, he maintains his CISSP and CCSP credentials—validating that he knows the academic rules well enough to know exactly how to safely bend them. His professional expertise isn\'t just theoretical. By night, he’s a renewable energy vigilante who built an off-grid solar shed and a custom PowerWall clone, mostly because he refuses to sell his electrons back to the grid for pennies. An early contributor to the LIRC and LCDproc projects, Venky’s code has been riding along in Linux distros for years.  He loves C, Python and PLC Ladder Logic.

\n\n

Beyond the lab, Venky is dedicated to \"pay-it-forward\" hacking. Whether he’s teaching the next generation how to solder at Maker Faire or volunteering with the Pacific Hackers Association, he is committed to building the community as much as the tech. He is happiest when he’s elbow-deep in a project that requires both a compiler and a multimeter.

\n\n\nLinks:
    GitHub - https://github.com/venkyr/loki
\n\'',NULL,1293637),('3_Saturday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'LoKi: A LoRa/Meshtastic based implant for Red Teaming\'','\'Venky Raju\'','Demo Labs_511c6061365ce80eaf39393a0424543c','\'Title: LoKi: A LoRa/Meshtastic based implant for Red Teaming
\nTags: Intro/Beginner | DEF CON Demo Labs | Hardware/IoT | Offense/Red Team | Wireless/RF | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

LoKi is a covert USB HID implant for Red Teaming that builds on the work of tools like the O.MG cable by replacing Wi-Fi with LoRa, extending the operational range of physical layer attacks from meters to kilometers. The implant integrates a Heltec LoRa module with custom Meshtastic firmware into an off-the-shelf wired USB mouse, retaining full mouse functionality. When LoKi receives a direct Meshtastic message, it translates the payload into DuckyScript™-compatible USB HID keystrokes and executes them on the host machine. No Wi-Fi, no Bluetooth, and no network traffic — the mouse simply begins typing. LoKi requires no line of sight and produces no detectable wireless LAN or Bluetooth signatures, making it effectively invisible to standard wireless monitoring. The live demo will walk through a payload from a handheld Meshtastic device to acquire a remote admin shell and bypass UAC on a target machine. Bring your own Meshtastic device and you can send commands to the implant during the demo. The presentation covers the hardware build, the customized open-source Meshtastic firmware, reliability considerations for keystroke delivery over a mesh network, and actionable blue team detection strategies, including monitoring for rogue HID device enumeration and LoRa RF activity.

\n\nSpeakerBio:  Venky Raju
\n

Venky Raju is a lifelong maker and hacker who firmly believes that if you haven\'t voided the warranty, you don\'t truly own it. While he holds a Master’s in Comp. Sci. and an EE degree, his most prized \"certifications\" were earned at the business end of a soldering iron, a 3D printer, and an array of metal and wood-working tools.

\n\n

By day, he navigates the complex worlds of Zero Trust, IoT, and OT security. To keep the corporate world happy, he maintains his CISSP and CCSP credentials—validating that he knows the academic rules well enough to know exactly how to safely bend them. His professional expertise isn\'t just theoretical. By night, he’s a renewable energy vigilante who built an off-grid solar shed and a custom PowerWall clone, mostly because he refuses to sell his electrons back to the grid for pennies. An early contributor to the LIRC and LCDproc projects, Venky’s code has been riding along in Linux distros for years.  He loves C, Python and PLC Ladder Logic.

\n\n

Beyond the lab, Venky is dedicated to \"pay-it-forward\" hacking. Whether he’s teaching the next generation how to solder at Maker Faire or volunteering with the Pacific Hackers Association, he is committed to building the community as much as the tech. He is happiest when he’s elbow-deep in a project that requires both a compiler and a multimeter.

\n\n\nLinks:
    GitHub - https://github.com/venkyr/loki
\n\'',NULL,1293638),('3_Saturday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'MSCodePhish: Redeem Your Coupon. Surrender Your Session\'','\'Raunak \"Trouble1\" Parmar,Chirag \"3xpl01tc0d3r\" Savla\'','Demo Labs_6aff253acd04478ec86a95b3bde62c52','\'Title: MSCodePhish: Redeem Your Coupon. Surrender Your Session
\nTags: Intro/Beginner | DEF CON Demo Labs | Cloud | Offense/Red Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

MSCodePhish is a red‑team toolkit that turns Microsoft’s Device Code OAuth flow into an embeddable phishing primitive that works inside any lure (e.g., “grab your coupon,” “unlock access,” etc.). Instead of pre‑generating device codes and racing against the usual 15‑minute timeout, MSCodePhish exposes a simple API endpoint that phishing pages can call via JavaScript (XHR/fetch) at the exact moment a victim opens the page. The tool then generates a fresh device code on demand, returns it to the phishing page (e.g., rendered as a “coupon code”), and instructs the user to complete the login on the legitimate Microsoft device login portal using that code.

\n\n

Behind the scenes, MSCodePhish continuously polls Microsoft’s token endpoint for that device code and, once the victim finishes authentication, captures the resulting refresh token and related claims (tenant, user, etc.). From its web UI, operators can track active campaigns, monitor which lures are converting, and use captured refresh tokens to request new access tokens for different resources (ARM, Key Vault, Graph, Storage, or custom scopes) in real time. Because the code is generated only when the phishing HTML is actually loaded, MSCodePhish effectively sidesteps device‑code expiration issues and enables more realistic, flexible phishing flows that closely mimic

\n\nSpeakers:Raunak \"Trouble1\" Parmar,Chirag \"3xpl01tc0d3r\" Savla
\n
\nSpeakerBio:  Raunak \"Trouble1\" Parmar
\n

Raunak Parmar works as a senior cloud security engineer at White Knight Labs with 6+ years of experience. His areas of interest include web penetration testing, Azure/AWS security, source code review, scripting, and development. He enjoys researching new attack methodologies and creating open-source tools that can be used during cloud red team activities. He has worked extensively on Azure and AWS and is the author of Vajra, AzDevRecon and MsCodePhish. He has spoken at multiple respected security conferences like Black Hat, Defcon, Nullcon, RootCon, HackspaceCon, NorthSec, LeHack , etc and also at local meetups.

\n\nSpeakerBio:  Chirag \"3xpl01tc0d3r\" Savla
\n

Chirag Savla is a Cyber Security professional with 10+ years of experience. His areas of interest include penetration testing, red teaming, azure and active directory security, and post-exploitation research. He prefers to create open-source tools and explore new attack methodologies in his leisure. He has worked extensively on Azure, Active Directory attacks, defense, and bypassing detection mechanisms. He is an author of multiple Open Source tools such as Process Injection, Callidus, etc. He has presented at multiple conferences and local meetups and has trained people in international conferences like Blackhat, BSides Milano, Wild West Hackin’ Fest.

\n\n\nLinks:
    GitHub - https://github.com/TROUBLE-1/MSCodePhish
\n\'',NULL,1293639),('2_Friday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'MSCodePhish: Redeem Your Coupon. Surrender Your Session\'','\'Raunak \"Trouble1\" Parmar,Chirag \"3xpl01tc0d3r\" Savla\'','Demo Labs_41fc477c8df31210961e48070557997d','\'Title: MSCodePhish: Redeem Your Coupon. Surrender Your Session
\nTags: Intro/Beginner | DEF CON Demo Labs | Cloud | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

MSCodePhish is a red‑team toolkit that turns Microsoft’s Device Code OAuth flow into an embeddable phishing primitive that works inside any lure (e.g., “grab your coupon,” “unlock access,” etc.). Instead of pre‑generating device codes and racing against the usual 15‑minute timeout, MSCodePhish exposes a simple API endpoint that phishing pages can call via JavaScript (XHR/fetch) at the exact moment a victim opens the page. The tool then generates a fresh device code on demand, returns it to the phishing page (e.g., rendered as a “coupon code”), and instructs the user to complete the login on the legitimate Microsoft device login portal using that code.

\n\n

Behind the scenes, MSCodePhish continuously polls Microsoft’s token endpoint for that device code and, once the victim finishes authentication, captures the resulting refresh token and related claims (tenant, user, etc.). From its web UI, operators can track active campaigns, monitor which lures are converting, and use captured refresh tokens to request new access tokens for different resources (ARM, Key Vault, Graph, Storage, or custom scopes) in real time. Because the code is generated only when the phishing HTML is actually loaded, MSCodePhish effectively sidesteps device‑code expiration issues and enables more realistic, flexible phishing flows that closely mimic

\n\nSpeakers:Raunak \"Trouble1\" Parmar,Chirag \"3xpl01tc0d3r\" Savla
\n
\nSpeakerBio:  Raunak \"Trouble1\" Parmar
\n

Raunak Parmar works as a senior cloud security engineer at White Knight Labs with 6+ years of experience. His areas of interest include web penetration testing, Azure/AWS security, source code review, scripting, and development. He enjoys researching new attack methodologies and creating open-source tools that can be used during cloud red team activities. He has worked extensively on Azure and AWS and is the author of Vajra, AzDevRecon and MsCodePhish. He has spoken at multiple respected security conferences like Black Hat, Defcon, Nullcon, RootCon, HackspaceCon, NorthSec, LeHack , etc and also at local meetups.

\n\nSpeakerBio:  Chirag \"3xpl01tc0d3r\" Savla
\n

Chirag Savla is a Cyber Security professional with 10+ years of experience. His areas of interest include penetration testing, red teaming, azure and active directory security, and post-exploitation research. He prefers to create open-source tools and explore new attack methodologies in his leisure. He has worked extensively on Azure, Active Directory attacks, defense, and bypassing detection mechanisms. He is an author of multiple Open Source tools such as Process Injection, Callidus, etc. He has presented at multiple conferences and local meetups and has trained people in international conferences like Blackhat, BSides Milano, Wild West Hackin’ Fest.

\n\n\nLinks:
    GitHub - https://github.com/TROUBLE-1/MSCodePhish
\n\'',NULL,1293640),('3_Saturday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quick Triage in an Ephemeral MicroVM\'','\'Uğur \"uJohn\" Can ATASOY\'','Demo Labs_c69be90de0b5c628f1de2bc76c559951','\'Title: MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quick Triage in an Ephemeral MicroVM
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

When TSA scans your luggage, they see what\'s inside without opening the bag. MailX-Ray brings that pattern to email triage.

\n\n

Phishing reports hit analysts as small crises: open carefully, don\'t trigger anything, extract IOCs, hand off to detection. Tooling lives at two extremes: cloud sandboxes that ship customer data offsite, or lightweight CLIs that run malicious parsers directly on the analyst\'s host. Neither produces a portable safe artifact, on-prem and hardware-isolated, in roughly 30 seconds.

\n\n

MailX-Ray does. Every email is processed inside an ephemeral hardware-virtualized microVM with no network device. Network egress is prevented by design. Output includes a single-file portable HTML safe-read report, structured JSON with 45+ offline signal categories, and optional STIX and MISP exports for SOC integration. Original attachment binaries are never re-distributed.

\n\n

It\'s not a malware sandbox. No decompilation, no execution, no verdicts. It\'s a non-invasive structural scan: the first 30 seconds of email triage, with zero network egress, on the analyst\'s own laptop.

\n\n

Demo Labs attendees will see the live pipeline across real phishing scenarios, including encrypted nested archives. Open source on the day of the talk.

\n\nSpeakerBio:  Uğur \"uJohn\" Can ATASOY
\n

Uğur Can Atasoy is a Senior Security Engineer at Udemy, working primarily on blue and purple team operations.

\n\n

A believer in hybrid approaches that combine technical fieldwork with academic rigor, he has spent the past decade across higher education, media, defense, and automotive sectors in roles spanning security architect, specialist, trainer, and consultant. His work spans both offense and defense — from security operations, threat hunting, intrusion detection, purple teaming, and adversary simulation to penetration testing and secure architecture. He has served as a Senior Content Engineer at TryHackMe and as an Information Security Architect at Mercedes-Benz. He has delivered security training for NATO personnel, law enforcement investigators, and military leadership, spoken at DeepSec (Vienna), holds CCSP, GCIA, OSCP, and OSWP, and served as an ISC2 SME for exam and training item development. He has been recognized by Oracle and IBM for responsible disclosure.

\n\n

MailX-Ray is his answer to a recurring annoyance: every tool in the email triage stack is either a cloud SaaS that ships customer data offsite, a heavyweight VM-based sandbox that takes minutes per sample, or an unprotected CLI that runs malicious parser input directly on the analyst\'s host. It produces a safe artifact analysts can read and forward.

\n\n\nLinks:
    GitHub - https://github.com/ugurcanatasoy/MailX-Ray
\n\'',NULL,1293641),('2_Friday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quick Triage in an Ephemeral MicroVM\'','\'Uğur \"uJohn\" Can ATASOY\'','Demo Labs_af446d630fec7205279ade7b6f1aeea5','\'Title: MailX-Ray: A TSA X-Ray for Emails — Air-Gapped Safe-Read and Quick Triage in an Ephemeral MicroVM
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

When TSA scans your luggage, they see what\'s inside without opening the bag. MailX-Ray brings that pattern to email triage.

\n\n

Phishing reports hit analysts as small crises: open carefully, don\'t trigger anything, extract IOCs, hand off to detection. Tooling lives at two extremes: cloud sandboxes that ship customer data offsite, or lightweight CLIs that run malicious parsers directly on the analyst\'s host. Neither produces a portable safe artifact, on-prem and hardware-isolated, in roughly 30 seconds.

\n\n

MailX-Ray does. Every email is processed inside an ephemeral hardware-virtualized microVM with no network device. Network egress is prevented by design. Output includes a single-file portable HTML safe-read report, structured JSON with 45+ offline signal categories, and optional STIX and MISP exports for SOC integration. Original attachment binaries are never re-distributed.

\n\n

It\'s not a malware sandbox. No decompilation, no execution, no verdicts. It\'s a non-invasive structural scan: the first 30 seconds of email triage, with zero network egress, on the analyst\'s own laptop.

\n\n

Demo Labs attendees will see the live pipeline across real phishing scenarios, including encrypted nested archives. Open source on the day of the talk.

\n\nSpeakerBio:  Uğur \"uJohn\" Can ATASOY
\n

Uğur Can Atasoy is a Senior Security Engineer at Udemy, working primarily on blue and purple team operations.

\n\n

A believer in hybrid approaches that combine technical fieldwork with academic rigor, he has spent the past decade across higher education, media, defense, and automotive sectors in roles spanning security architect, specialist, trainer, and consultant. His work spans both offense and defense — from security operations, threat hunting, intrusion detection, purple teaming, and adversary simulation to penetration testing and secure architecture. He has served as a Senior Content Engineer at TryHackMe and as an Information Security Architect at Mercedes-Benz. He has delivered security training for NATO personnel, law enforcement investigators, and military leadership, spoken at DeepSec (Vienna), holds CCSP, GCIA, OSCP, and OSWP, and served as an ISC2 SME for exam and training item development. He has been recognized by Oracle and IBM for responsible disclosure.

\n\n

MailX-Ray is his answer to a recurring annoyance: every tool in the email triage stack is either a cloud SaaS that ships customer data offsite, a heavyweight VM-based sandbox that takes minutes per sample, or an unprotected CLI that runs malicious parser input directly on the analyst\'s host. It produces a safe artifact analysts can read and forward.

\n\n\nLinks:
    GitHub - https://github.com/ugurcanatasoy/MailX-Ray
\n\'',NULL,1293642),('2_Friday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'MalSkill Lab: Hands-On Natural Language Malware in AI Agent Orchestration Systems\'','\'Nur \"BurritoTheNurrito\" Gucu\'','Demo Labs_2502eeb14ce1bcf4ea23769efcdd71e8','\'Title: MalSkill Lab: Hands-On Natural Language Malware in AI Agent Orchestration Systems
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

Your AI agent trusts every skill in its directory. What if one of them is lying?\nIn this Demo Lab, I walk you through MalSkills, natural language malware planted inside AI agent skill systems. No binaries, no shellcode, no signatures.\nJust English sentences with OS-level access.\nUsing ORPHEUS, my open-source multi-skill orchestration framework, I demonstrate three escalating attacks live:\n 1. BURIED INSTRUCTION: A malicious sentence hidden in a legitimate skill exfiltrates .env files on first execution. I show you 12 skills and challenge you to spot it. \n 2. CHAIN ATTACK: Five individually benign skills that, when orchestrated together, create an emergent data exfiltration path. No single skill is malicious. The composition is the weapon.\n 3. PERSISTENT GHOST: A skill that writes itself into agent memory, surviving file deletion and session restarts. Remove the skill, restart the agent, exfiltration continues.\nAfter offense, I flip to defense. I demo the MalSkill Detection Toolkit: skill integrity verification, capability-based sandboxing, orchestration graph analysis, and runtime behavioral monitoring.\nAttendees leave with: the ORPHEUS framework, a MalSkill sample pack, and a detection toolkit, all open source!\nEvery AI agent with a plugin system is vulnerable today. Come see why.

\n\nSpeakerBio:  Nur \"BurritoTheNurrito\" Gucu
\n

Offensive security professional and AI security researcher with 10+ years across financial services, startups, and Amazon.\nCurrently on the foundational model red team at Amazon AGI Labs, where I break AI systems and build the tooling to detect what I find.\nCore focus: LLM security, agentic system exploitation, and the gaps between how AI frameworks are designed and how they actually behave under adversarial pressure.\n6 patent applications. Published author (AWS Security Blog, internal science papers). Invited speaker on MCP security and LLM training APT attack surfaces.\nI turn research into shipped products and open-source tools, not empty slide decks.

\n\n\nLinks:
    GitHub - https://github.com/nuryslyrt/ORPHEUS
\n\'',NULL,1293643),('3_Saturday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'MalSkill Lab: Hands-On Natural Language Malware in AI Agent Orchestration Systems\'','\'Nur \"BurritoTheNurrito\" Gucu\'','Demo Labs_7754bfee11053da5dcb2ee1793bb9c68','\'Title: MalSkill Lab: Hands-On Natural Language Malware in AI Agent Orchestration Systems
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

Your AI agent trusts every skill in its directory. What if one of them is lying?\nIn this Demo Lab, I walk you through MalSkills, natural language malware planted inside AI agent skill systems. No binaries, no shellcode, no signatures.\nJust English sentences with OS-level access.\nUsing ORPHEUS, my open-source multi-skill orchestration framework, I demonstrate three escalating attacks live:\n 1. BURIED INSTRUCTION: A malicious sentence hidden in a legitimate skill exfiltrates .env files on first execution. I show you 12 skills and challenge you to spot it. \n 2. CHAIN ATTACK: Five individually benign skills that, when orchestrated together, create an emergent data exfiltration path. No single skill is malicious. The composition is the weapon.\n 3. PERSISTENT GHOST: A skill that writes itself into agent memory, surviving file deletion and session restarts. Remove the skill, restart the agent, exfiltration continues.\nAfter offense, I flip to defense. I demo the MalSkill Detection Toolkit: skill integrity verification, capability-based sandboxing, orchestration graph analysis, and runtime behavioral monitoring.\nAttendees leave with: the ORPHEUS framework, a MalSkill sample pack, and a detection toolkit, all open source!\nEvery AI agent with a plugin system is vulnerable today. Come see why.

\n\nSpeakerBio:  Nur \"BurritoTheNurrito\" Gucu
\n

Offensive security professional and AI security researcher with 10+ years across financial services, startups, and Amazon.\nCurrently on the foundational model red team at Amazon AGI Labs, where I break AI systems and build the tooling to detect what I find.\nCore focus: LLM security, agentic system exploitation, and the gaps between how AI frameworks are designed and how they actually behave under adversarial pressure.\n6 patent applications. Published author (AWS Security Blog, internal science papers). Invited speaker on MCP security and LLM training APT attack surfaces.\nI turn research into shipped products and open-source tools, not empty slide decks.

\n\n\nLinks:
    GitHub - https://github.com/nuryslyrt/ORPHEUS
\n\'',NULL,1293644),('2_Friday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'Monitor, Compile, Enforce: A Compiler Pipeline for Container Security Policy in Rust and eBPF\'','\'Buğrahan Yücel\'','Demo Labs_8b2d0a19b248c59491b7bb6b35e4b48d','\'Title: Monitor, Compile, Enforce: A Compiler Pipeline for Container Security Policy in Rust and eBPF
\nTags: DEF CON Demo Labs | Advanced | Cloud | Defense/Blue Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

Container security tools observe behavior (eBPF) and enforce policy (BPF-LSM, AppArmor, Seccomp). But the translation between observation and enforcement is manual and incomplete. We present the first tool that treats this translation as a compilation problem. Built in Rust with the Aya eBPF framework, three monitoring modules serve as compiler frontends feeding a normalized behavioral IR. Optimization passes operate on this IR: pattern classification, rule deduplication, dead rule elimination, conflict detection, and cross-category dependency linking. The backend compiles optimized IR into BPF-LSM enforcement rules across three LSM hooks: security_file_open, security_bprm_check_security, and security_socket_connect. Enforcement is default-deny: any operation not in the compiled profile is blocked. We demo end-to-end: a container is profiled, the profile compiled through the pipeline, and enforcement blocks unauthorized file access, process execution, and network connections at the kernel level. Zero manual policy writing. We document the friction points where monitoring context diverges from enforcement context. No existing tool, including vArmor and KubeArmor, implements this compilation architecture with a true IR, optimization passes, and multi-category LSM enforcement.

\n\nSpeakerBio:  Buğrahan Yücel
\n

Buğrahan Yücel is a software engineer at a SaaS company in Turkey, where he works on infrastructure security. He currently builds eBPF-based behavioral profiling and enforcement tooling in Rust using the Aya framework. This is his first DEF CON presentation.

\n\n\nLinks:
    GitHub - https://github.com/BugrahanYucel/ebpf-mon
\n\'',NULL,1293645),('3_Saturday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'Monitor, Compile, Enforce: A Compiler Pipeline for Container Security Policy in Rust and eBPF\'','\'Buğrahan Yücel\'','Demo Labs_45fd73ae7a34c18bd818f38e9b2c440b','\'Title: Monitor, Compile, Enforce: A Compiler Pipeline for Container Security Policy in Rust and eBPF
\nTags: DEF CON Demo Labs | Advanced | Cloud | Defense/Blue Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

Container security tools observe behavior (eBPF) and enforce policy (BPF-LSM, AppArmor, Seccomp). But the translation between observation and enforcement is manual and incomplete. We present the first tool that treats this translation as a compilation problem. Built in Rust with the Aya eBPF framework, three monitoring modules serve as compiler frontends feeding a normalized behavioral IR. Optimization passes operate on this IR: pattern classification, rule deduplication, dead rule elimination, conflict detection, and cross-category dependency linking. The backend compiles optimized IR into BPF-LSM enforcement rules across three LSM hooks: security_file_open, security_bprm_check_security, and security_socket_connect. Enforcement is default-deny: any operation not in the compiled profile is blocked. We demo end-to-end: a container is profiled, the profile compiled through the pipeline, and enforcement blocks unauthorized file access, process execution, and network connections at the kernel level. Zero manual policy writing. We document the friction points where monitoring context diverges from enforcement context. No existing tool, including vArmor and KubeArmor, implements this compilation architecture with a true IR, optimization passes, and multi-category LSM enforcement.

\n\nSpeakerBio:  Buğrahan Yücel
\n

Buğrahan Yücel is a software engineer at a SaaS company in Turkey, where he works on infrastructure security. He currently builds eBPF-based behavioral profiling and enforcement tooling in Rust using the Aya framework. This is his first DEF CON presentation.

\n\n\nLinks:
    GitHub - https://github.com/BugrahanYucel/ebpf-mon
\n\'',NULL,1293646),('3_Saturday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'Overcast: Video OSINT Agent. Point It at 100 Videos, Ask Anything\'','\'Kevin \"kdrwins\" Dela Rosa\'','Demo Labs_f783363c600d150979b26f1a29ed8079','\'Title: Overcast: Video OSINT Agent. Point It at 100 Videos, Ask Anything
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

Conference talks, earnings calls, product demos, training videos. Organizations put hours of footage online every week, full of things they didn\'t mean to share: hostnames in terminal windows, org charts on slides, infrastructure details dropped during Q&A. Traditional OSINT can\'t touch video at scale, and manual review falls apart past a handful of recordings.

\n\n

Overcast is a CLI agent and skill pack for video OSINT that drops into any agentic harness, such as Claude Code, Codex, or Tinycloud, giving it senses plus recon and targeting reach, organized around an investigation case. Point it at 10 videos or 1,000 and it turns footage into cited evidence: speech, video understanding, on-screen text and objects, faces, and named entities, all accumulating in persistent case memory.

\n\n

Discovery runs on the same case: scan and monitor sweep sources and surface reviewable findings. Ask across the whole corpus and get answers cited to the exact record and timestamp, backed by tiered retrieval. Match a photo against thousands of clips to find a person. Each subcommand is modular and pluggable, so analysts can drop one into other agent flows, author custom skills, or feed Overcast\'s media analysis into existing recon and security tooling to complete the mission.

\n\nSpeakerBio:  Kevin \"kdrwins\" Dela Rosa
\n

Kevin Dela Rosa is a multimodal AI researcher and engineer with 17+ years in computer vision, NLU, and large-scale retrieval. He led engineering teams at Snapchat building billion-scale visual search and generative AI products, worked on large-scale ML at Amazon, and interned at NIST and SPAWAR on NLP and information retrieval for government applications. He\'s published at ACM WWW, ACM CAIS, IEEE ICCV, KDD, CVPR, NeurIPS, AAAI, and ISMIR, and has spoken at AWS re:Invent, KubeCon, and CascadiaJS. He\'s currently CTO of Cloudglue, where he builds video understanding infrastructure.

\n\n

At DEF CON 33 he presented \"Autonomous Video Hunter\" at Recon Village, demoing an AI agent that investigated video corpora using face recognition, logo detection, and content analysis to produce structured OSINT reports. Overcast is the evolution of that work: a CLI agent and skill pack that gives any agentic harness senses plus recon and targeting reach, organized around an investigation case with persistent memory, cited evidence, and modular subcommands that plug into other recon and security workflows.

\n\n\nLinks:
    GitHub - https://github.com/kdr/overcast
\n\'',NULL,1293647),('2_Friday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'Overcast: Video OSINT Agent. Point It at 100 Videos, Ask Anything\'','\'Kevin \"kdrwins\" Dela Rosa\'','Demo Labs_5f2411e5d907237b0c5a666a5a3da730','\'Title: Overcast: Video OSINT Agent. Point It at 100 Videos, Ask Anything
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

Conference talks, earnings calls, product demos, training videos. Organizations put hours of footage online every week, full of things they didn\'t mean to share: hostnames in terminal windows, org charts on slides, infrastructure details dropped during Q&A. Traditional OSINT can\'t touch video at scale, and manual review falls apart past a handful of recordings.

\n\n

Overcast is a CLI agent and skill pack for video OSINT that drops into any agentic harness, such as Claude Code, Codex, or Tinycloud, giving it senses plus recon and targeting reach, organized around an investigation case. Point it at 10 videos or 1,000 and it turns footage into cited evidence: speech, video understanding, on-screen text and objects, faces, and named entities, all accumulating in persistent case memory.

\n\n

Discovery runs on the same case: scan and monitor sweep sources and surface reviewable findings. Ask across the whole corpus and get answers cited to the exact record and timestamp, backed by tiered retrieval. Match a photo against thousands of clips to find a person. Each subcommand is modular and pluggable, so analysts can drop one into other agent flows, author custom skills, or feed Overcast\'s media analysis into existing recon and security tooling to complete the mission.

\n\nSpeakerBio:  Kevin \"kdrwins\" Dela Rosa
\n

Kevin Dela Rosa is a multimodal AI researcher and engineer with 17+ years in computer vision, NLU, and large-scale retrieval. He led engineering teams at Snapchat building billion-scale visual search and generative AI products, worked on large-scale ML at Amazon, and interned at NIST and SPAWAR on NLP and information retrieval for government applications. He\'s published at ACM WWW, ACM CAIS, IEEE ICCV, KDD, CVPR, NeurIPS, AAAI, and ISMIR, and has spoken at AWS re:Invent, KubeCon, and CascadiaJS. He\'s currently CTO of Cloudglue, where he builds video understanding infrastructure.

\n\n

At DEF CON 33 he presented \"Autonomous Video Hunter\" at Recon Village, demoing an AI agent that investigated video corpora using face recognition, logo detection, and content analysis to produce structured OSINT reports. Overcast is the evolution of that work: a CLI agent and skill pack that gives any agentic harness senses plus recon and targeting reach, organized around an investigation case with persistent memory, cited evidence, and modular subcommands that plug into other recon and security workflows.

\n\n\nLinks:
    GitHub - https://github.com/kdr/overcast
\n\'',NULL,1293648),('3_Saturday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'Peekaboo: Breaking the Black Box of Threat and Malware Emulation\'','\'Zhassulan \"cocomelonc\" Zhussupov\'','Demo Labs_79b686c4be02f3b8d55e803a06775393','\'Title: Peekaboo: Breaking the Black Box of Threat and Malware Emulation
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\nStandard security testing often forces a choice: use \"script-kiddie\" tools that get caught instantly, or use high-end frameworks that are too complex for rapid detection testing. Peekaboo bridges this gap. In this Demo Lab, we present Peekaboo - a modular, open-source framework designed for safe threat emulation. Unlike traditional malware, Peekaboo focuses on generating high-fidelity telemetry through legitimate cloud API abuse (GitHub, Bitbucket, Slack, Discord, Azure, VirusTotal, XBOX, AngelCam, etc) and evasive execution techniques (Direct Syscalls, Callback-based execution).
\n\n

We will demonstrate how to:

\n\n
    \n
  • Generate polymorphic agents that bypass static analysis using rare cryptographic algorithms like Speck and Skipjack.
  • \n
  • Generate agents that leverage signal processing like Fast Fourier Transformation and Feistel-network based cryptography for bypass EDR.
  • \n
  • Establish covert C2 channels within the metadata of trusted enterprise applications.
  • \n
  • Rapidly test EDR/SIEM rules against modern persistence and lateral movement techniques without risking system stability.
  • \n
\n\n

Peekaboo isn\'t just a tool; it\'s a \"sandbox-friendly\" adversary in a box, designed to help Blue Teams level up by understanding the nuances of the Offensive Dev Loop. Come see how we turn \"hidden\" threats into \"visible\" learning opportunities.

\n\nSpeakerBio:  Zhassulan \"cocomelonc\" Zhussupov
\n

cybersecurity enthusiast, author, speaker and mathematician. Author of popular books: MD MZ Malware Development Book (Github, 2022, 2024) MALWILD: Malware in the Wild Book (Github, 2023) Malware Development for Ethical Hackers Book: (Packt, 2024) AIYA Mobile Malware Development Book (Github, 2025) Malware Development for Ethical Hackers 2nd edition (Packt, 2026, in progress) Author and tech reviewer at Packt. Co founder of various cybersecurity research labs, author of many cybersecurity blogs, HVCK magazine Malpedia contributor Speaker at BlackHat, DEFCON, Security BSides, Arab Security Conference, Hack.lu, Standoff, Positive Hack Talks, etc conferences

\n\n\nLinks:
    GitHub - https://github.com/cocomelonc/peekaboo
\n\'',NULL,1293649),('2_Friday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'Peekaboo: Breaking the Black Box of Threat and Malware Emulation\'','\'Zhassulan \"cocomelonc\" Zhussupov\'','Demo Labs_72e74f15c0b941c6622374373bc31adb','\'Title: Peekaboo: Breaking the Black Box of Threat and Malware Emulation
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\nStandard security testing often forces a choice: use \"script-kiddie\" tools that get caught instantly, or use high-end frameworks that are too complex for rapid detection testing. Peekaboo bridges this gap. In this Demo Lab, we present Peekaboo - a modular, open-source framework designed for safe threat emulation. Unlike traditional malware, Peekaboo focuses on generating high-fidelity telemetry through legitimate cloud API abuse (GitHub, Bitbucket, Slack, Discord, Azure, VirusTotal, XBOX, AngelCam, etc) and evasive execution techniques (Direct Syscalls, Callback-based execution).
\n\n

We will demonstrate how to:

\n\n
    \n
  • Generate polymorphic agents that bypass static analysis using rare cryptographic algorithms like Speck and Skipjack.
  • \n
  • Generate agents that leverage signal processing like Fast Fourier Transformation and Feistel-network based cryptography for bypass EDR.
  • \n
  • Establish covert C2 channels within the metadata of trusted enterprise applications.
  • \n
  • Rapidly test EDR/SIEM rules against modern persistence and lateral movement techniques without risking system stability.
  • \n
\n\n

Peekaboo isn\'t just a tool; it\'s a \"sandbox-friendly\" adversary in a box, designed to help Blue Teams level up by understanding the nuances of the Offensive Dev Loop. Come see how we turn \"hidden\" threats into \"visible\" learning opportunities.

\n\nSpeakerBio:  Zhassulan \"cocomelonc\" Zhussupov
\n

cybersecurity enthusiast, author, speaker and mathematician. Author of popular books: MD MZ Malware Development Book (Github, 2022, 2024) MALWILD: Malware in the Wild Book (Github, 2023) Malware Development for Ethical Hackers Book: (Packt, 2024) AIYA Mobile Malware Development Book (Github, 2025) Malware Development for Ethical Hackers 2nd edition (Packt, 2026, in progress) Author and tech reviewer at Packt. Co founder of various cybersecurity research labs, author of many cybersecurity blogs, HVCK magazine Malpedia contributor Speaker at BlackHat, DEFCON, Security BSides, Arab Security Conference, Hack.lu, Standoff, Positive Hack Talks, etc conferences

\n\n\nLinks:
    GitHub - https://github.com/cocomelonc/peekaboo
\n\'',NULL,1293650),('3_Saturday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'Phasmid: Deniable Storage for Rubber-Hose Scenarios\'','\'Makoto \"Mr.Rabbit\" Sugita\'','Demo Labs_a0126f42417f3a75f533b822244c039d','\'Title: Phasmid: Deniable Storage for Rubber-Hose Scenarios
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | SecOps | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\nPhasmid is a prototype deniable storage system built for a problem ordinary encryption handles poorly: what happens when the attacker stops attacking the math and starts coercing the human holding the key. It implements the Janus Eidolon System, or Janus System, a coercion-aware storage method that explores how visible disclosure and true protected state can diverge through deniable cryptographic structure, local-only operation, dual-profile storage, camera-based object-image matching, and owner-controlled destructive actions. Framed by the question of Agency, the project asks how a user can retain meaningful control over disclosure when physical pressure breaks normal cryptographic assumptions. This demo presents a practical low-power implementation on Raspberry Pi Zero 2 W for hostile situations where the attacker targets the person rather than the cipher.
\n\n\n\nSpeakerBio:  Makoto \"Mr.Rabbit\" Sugita
\n

Makoto Sugita is a security engineer and security toolmaker focused on practical systems for hostile environments, where cryptographic assumptions break down under real-world pressure. His work sits at the intersection of cryptography, hardware, and adversarial human behavior. He has presented tools and research at venues including Black Hat Arsenal and BSides, and is interested in deniable systems, tactical hardware, and building prototypes that expose uncomfortable but real security problems.

\n\n\nLinks:
    GitHub - https://github.com/01rabbit/Phasmid
\n\'',NULL,1293651),('2_Friday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'Phasmid: Deniable Storage for Rubber-Hose Scenarios\'','\'Makoto \"Mr.Rabbit\" Sugita\'','Demo Labs_f6dfdb74517628aeb250e8158a6069d8','\'Title: Phasmid: Deniable Storage for Rubber-Hose Scenarios
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | SecOps | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\nPhasmid is a prototype deniable storage system built for a problem ordinary encryption handles poorly: what happens when the attacker stops attacking the math and starts coercing the human holding the key. It implements the Janus Eidolon System, or Janus System, a coercion-aware storage method that explores how visible disclosure and true protected state can diverge through deniable cryptographic structure, local-only operation, dual-profile storage, camera-based object-image matching, and owner-controlled destructive actions. Framed by the question of Agency, the project asks how a user can retain meaningful control over disclosure when physical pressure breaks normal cryptographic assumptions. This demo presents a practical low-power implementation on Raspberry Pi Zero 2 W for hostile situations where the attacker targets the person rather than the cipher.
\n\n\n\nSpeakerBio:  Makoto \"Mr.Rabbit\" Sugita
\n

Makoto Sugita is a security engineer and security toolmaker focused on practical systems for hostile environments, where cryptographic assumptions break down under real-world pressure. His work sits at the intersection of cryptography, hardware, and adversarial human behavior. He has presented tools and research at venues including Black Hat Arsenal and BSides, and is interested in deniable systems, tactical hardware, and building prototypes that expose uncomfortable but real security problems.

\n\n\nLinks:
    GitHub - https://github.com/01rabbit/Phasmid
\n\'',NULL,1293652),('3_Saturday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale\'','\'Georgia Weidman\'','Demo Labs_13fe7538011761d1f8c739a045d69b4c','\'Title: PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | DevOps | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

AI-assisted development tools don’t just introduce vulnerabilities; they introduce the same vulnerabilities repeatedly.

\n\n

PromptPwn is a tool designed to identify, track, and exploit common insecure patterns found in AI-generated code. It maintains a database of known vulnerability patterns produced by popular “vibe coding” workflows and provides scanning capabilities to detect these issues in real applications.

\n\n

In this demo, we show how PromptPwn identifies vulnerable patterns such as injection flaws, authentication weaknesses, and insecure defaults across generated code. We demonstrate how these patterns can be exploited in practice, highlighting how repeatability makes them especially valuable from an attacker’s perspective.

\n\n

We also explore how prompt variations influence these outcomes and show how insecure patterns can be remediated by adjusting prompts, closing the loop between generation, exploitation, and correction.

\n\n

This session focuses on practical demonstrations of how AI-generated code fails in predictable ways, and how those failures can be identified and abused at scale.

\n\nSpeakerBio:  Georgia Weidman
\n

Georgia Weidman is an offensive security researcher and author focused on breaking real-world systems. She wrote Penetration Testing: A Hands-On Introduction to Hacking, a practical guide used by students and practitioners to learn exploitation techniques.

\n\n

Her work centers on how modern systems fail under attack, from mobile and IoT to enterprise environments. As a DARPA Cyber Fast Track performer, she developed the Smartphone Pentest Framework (SPF), a platform for mobile exploitation research.

\n\n

She has conducted penetration tests, built exploitation tooling, and developed attack chains across multiple domains. Her approach prioritizes hands-on techniques over theory, demonstrating how assumptions about security break down in practice.

\n\n

Georgia has presented internationally at conferences including Black Hat and DEF CON, with a focus on showing how things actually get hacked.

\n\n\nLinks:
    GitHub - https://github.com/georgiaw/PromptPwn
\n\'',NULL,1293653),('2_Friday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale\'','\'Georgia Weidman\'','Demo Labs_2930819a1bb3c3ef613ab5011b38a75b','\'Title: PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | DevOps | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

AI-assisted development tools don’t just introduce vulnerabilities; they introduce the same vulnerabilities repeatedly.

\n\n

PromptPwn is a tool designed to identify, track, and exploit common insecure patterns found in AI-generated code. It maintains a database of known vulnerability patterns produced by popular “vibe coding” workflows and provides scanning capabilities to detect these issues in real applications.

\n\n

In this demo, we show how PromptPwn identifies vulnerable patterns such as injection flaws, authentication weaknesses, and insecure defaults across generated code. We demonstrate how these patterns can be exploited in practice, highlighting how repeatability makes them especially valuable from an attacker’s perspective.

\n\n

We also explore how prompt variations influence these outcomes and show how insecure patterns can be remediated by adjusting prompts, closing the loop between generation, exploitation, and correction.

\n\n

This session focuses on practical demonstrations of how AI-generated code fails in predictable ways, and how those failures can be identified and abused at scale.

\n\nSpeakerBio:  Georgia Weidman
\n

Georgia Weidman is an offensive security researcher and author focused on breaking real-world systems. She wrote Penetration Testing: A Hands-On Introduction to Hacking, a practical guide used by students and practitioners to learn exploitation techniques.

\n\n

Her work centers on how modern systems fail under attack, from mobile and IoT to enterprise environments. As a DARPA Cyber Fast Track performer, she developed the Smartphone Pentest Framework (SPF), a platform for mobile exploitation research.

\n\n

She has conducted penetration tests, built exploitation tooling, and developed attack chains across multiple domains. Her approach prioritizes hands-on techniques over theory, demonstrating how assumptions about security break down in practice.

\n\n

Georgia has presented internationally at conferences including Black Hat and DEF CON, with a focus on showing how things actually get hacked.

\n\n\nLinks:
    GitHub - https://github.com/georgiaw/PromptPwn
\n\'',NULL,1293654),('2_Friday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'Reversing F5: Pure-Go Steganography, Live Forensic Cover Recovery, and JPEG Fragility Analysis\'','\'0verkilll\'','Demo Labs_f5466b5a1b96dada5ed2a2680935efd9','\'Title: Reversing F5: Pure-Go Steganography, Live Forensic Cover Recovery, and JPEG Fragility Analysis
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | Cloud | Defense/Blue Team | Malware | Mobile | Offense/Red Team | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

F5 (Westfeld, 2001) is the canonical \"do it right\" JPEG steganography algorithm — matrix encoding, permutative straddling, shrinkage handling — and still turns up on confiscated devices and in CTF challenges 25 years later. The public tooling has rotted: the original is Java, modern rewrites bind CGo to libjpeg, and every implementation surveyed is one-way (embed and extract, never un-embed).\nThis Demo Lab presents ten public GitHub repositories that fix that, in pure Go with zero third-party dependencies. The headline is the first open-source F5 cover-recovery tool: given the stego JPEG, the password, and the extracted message, it reverses the embed and restores the cover\'s DCT coefficients. Alongside it ship three CLIs (embed, extract, recover), a pure-Go JPEG-family codec (baseline, JPEG 2000, JPEG-LS, XL/XR/XS/XT, Pleno, lossless), a Fridrich chi-square steganalysis library and CLI, and the supporting crypto, i18n, and logging packages — all auditable end-to-end in one language.\nLive: embed, extract, cover recovery, defensive Fridrich detection, JPEG re-encoding fragility, and a 25-line external Go program importing the library. Useful for digital forensics, steganalysis research, CTF authoring, and anyone who wants a CGo-free stego stack they can read in a weekend.

\n\nSpeakerBio:  0verkilll
\n

Precise, Ruthless, Ethical

\n\n\nLinks:
    GitHub - https://github.com/0verkilll
\n\'',NULL,1293655),('3_Saturday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'Reversing F5: Pure-Go Steganography, Live Forensic Cover Recovery, and JPEG Fragility Analysis\'','\'0verkilll\'','Demo Labs_d5162bfe7e662a19779a76dd1aa3bf23','\'Title: Reversing F5: Pure-Go Steganography, Live Forensic Cover Recovery, and JPEG Fragility Analysis
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | Cloud | Defense/Blue Team | Malware | Mobile | Offense/Red Team | Purple Team | SecOps | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

F5 (Westfeld, 2001) is the canonical \"do it right\" JPEG steganography algorithm — matrix encoding, permutative straddling, shrinkage handling — and still turns up on confiscated devices and in CTF challenges 25 years later. The public tooling has rotted: the original is Java, modern rewrites bind CGo to libjpeg, and every implementation surveyed is one-way (embed and extract, never un-embed).\nThis Demo Lab presents ten public GitHub repositories that fix that, in pure Go with zero third-party dependencies. The headline is the first open-source F5 cover-recovery tool: given the stego JPEG, the password, and the extracted message, it reverses the embed and restores the cover\'s DCT coefficients. Alongside it ship three CLIs (embed, extract, recover), a pure-Go JPEG-family codec (baseline, JPEG 2000, JPEG-LS, XL/XR/XS/XT, Pleno, lossless), a Fridrich chi-square steganalysis library and CLI, and the supporting crypto, i18n, and logging packages — all auditable end-to-end in one language.\nLive: embed, extract, cover recovery, defensive Fridrich detection, JPEG re-encoding fragility, and a 25-line external Go program importing the library. Useful for digital forensics, steganalysis research, CTF authoring, and anyone who wants a CGo-free stego stack they can read in a weekend.

\n\nSpeakerBio:  0verkilll
\n

Precise, Ruthless, Ethical

\n\n\nLinks:
    GitHub - https://github.com/0verkilll
\n\'',NULL,1293656),('2_Friday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'SecretSifter: Production Apps Are Leaking Credentials. The Blindspot DAST Never Checked.\'','\'Hemanth Gorijala\'','Demo Labs_9445f9c9522685789d3eb9ebbcc6626d','\'Title: SecretSifter: Production Apps Are Leaking Credentials. The Blindspot DAST Never Checked.
\nTags: DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | DevOps | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

Shift-left tools scan what you commit, not what you serve. DAST scanners test for vulnerabilities but ignore live traffic. The industry left a gap: runtime secrets. Finding them requires intercepting live traffic: a proxy, a browser extension, or a bulk scanner. SecretSifter is all three.

\n\n

We tested 2,000 production apps against ten secret scanners. 194 confirmed credentials survived all ten scanners.

\n\n

SecretSifter monitors live HTTP traffic and finds credentials in JS bundles, lazy-loaded chunks, HTML responses, JSON and XML APIs, and request headers. No config, no source code. 160+ rules cover vendor tokens (AWS, Azure, Stripe, Twilio, GitHub), entropy-gated patterns, and CryptoJS-encrypted configs where the decryption key is hardcoded in the same bundle. No other scanner catches that case. Bulk mode scans 30-50 targets: paste URLs, scan, optional AI triage, export HTML, CSV, or ZIP.

\n\n

The session opens with a live tool comparison. Most tools scan one URL at a time and require manual browsing. SecretSifter bulk-scans both targets in parallel. Two findings none of the ten caught: Azure AD credentials baked into a webpack bundle past GitLeaks. A CryptoJS config with the decryption key three lines away.

\n\n

Your entire pipeline reported green. Were they right? Attendees leave with a free tool to run the same day.

\n\nSpeakerBio:  Hemanth Gorijala
\n

Hemanth Gorijala is Global Pentest Lead at a Fortune 100 financial services company. He built SecretSifter to close the runtime security gap: the space between where shift-left secret scanning stops and where secrets actually appear in production. His research identified 194 confirmed credentials across 2,000 production applications that bypassed ten secret scanners. He is presenting that research at security conferences across the US. The GT-194 benchmark is published on Zenodo (DOI 10.5281/zenodo.19464446). SecretSifter is open source at github.com/secretsifter.

\n\n\nLinks:
    GitHub - https://github.com/secretsifter/secretsifter-burp
\n\'',NULL,1293657),('3_Saturday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'SecretSifter: Production Apps Are Leaking Credentials. The Blindspot DAST Never Checked.\'','\'Hemanth Gorijala\'','Demo Labs_bd68a904bdfbcb385bdee978a6a01c35','\'Title: SecretSifter: Production Apps Are Leaking Credentials. The Blindspot DAST Never Checked.
\nTags: DEF CON Demo Labs | Intermediate | AppSec | Defense/Blue Team | DevOps | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

Shift-left tools scan what you commit, not what you serve. DAST scanners test for vulnerabilities but ignore live traffic. The industry left a gap: runtime secrets. Finding them requires intercepting live traffic: a proxy, a browser extension, or a bulk scanner. SecretSifter is all three.

\n\n

We tested 2,000 production apps against ten secret scanners. 194 confirmed credentials survived all ten scanners.

\n\n

SecretSifter monitors live HTTP traffic and finds credentials in JS bundles, lazy-loaded chunks, HTML responses, JSON and XML APIs, and request headers. No config, no source code. 160+ rules cover vendor tokens (AWS, Azure, Stripe, Twilio, GitHub), entropy-gated patterns, and CryptoJS-encrypted configs where the decryption key is hardcoded in the same bundle. No other scanner catches that case. Bulk mode scans 30-50 targets: paste URLs, scan, optional AI triage, export HTML, CSV, or ZIP.

\n\n

The session opens with a live tool comparison. Most tools scan one URL at a time and require manual browsing. SecretSifter bulk-scans both targets in parallel. Two findings none of the ten caught: Azure AD credentials baked into a webpack bundle past GitLeaks. A CryptoJS config with the decryption key three lines away.

\n\n

Your entire pipeline reported green. Were they right? Attendees leave with a free tool to run the same day.

\n\nSpeakerBio:  Hemanth Gorijala
\n

Hemanth Gorijala is Global Pentest Lead at a Fortune 100 financial services company. He built SecretSifter to close the runtime security gap: the space between where shift-left secret scanning stops and where secrets actually appear in production. His research identified 194 confirmed credentials across 2,000 production applications that bypassed ten secret scanners. He is presenting that research at security conferences across the US. The GT-194 benchmark is published on Zenodo (DOI 10.5281/zenodo.19464446). SecretSifter is open source at github.com/secretsifter.

\n\n\nLinks:
    GitHub - https://github.com/secretsifter/secretsifter-burp
\n\'',NULL,1293658),('3_Saturday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop\'','\'Fukusuke Takahashi,Zach Mathis,Akira Nishikawa\'','Demo Labs_5a7e3dc4ddf12e419a3fd3504e98f56e','\'Title: Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop
\nTags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

Senrigan (千里眼) and Suzaku (朱雀) are two complementary open-source tools that together form a complete threat hunting and DFIR platform for AWS CloudTrail logs. Both are built by Yamato Security, the volunteer-run Japanese security community behind Hayabusa(隼), the widely adopted Windows event log fast-forensics tool. Yamato Security provides free, open-source DFIR tools and resources to the community.

\n\n

Building on Hayabusa\'s philosophy of fast, offline, community rule-based detection, this toolset brings the same approach to the cloud. Security teams can hunt threats across CloudTrail logs on a single laptop — without a SIEM, dedicated infrastructure, or licensing cost.

\n\n

The two tools work together, with Suzaku\'s detections flowing into Senrigan for analysis. Senrigan, deployed via Docker Compose, ingests CloudTrail logs into DuckDB via a Rust-based ingester, then lets analysts investigate them through 100+ pre-built hunting queries and 80+ pre-built Apache Superset dashboard charts — no SQL or CloudTrail schema knowledge required. Suzaku is a high-performance, standalone Rust-based CLI that applies native Sigma detection rules to CloudTrail logs and generates a fast-forensics DFIR timeline — surfacing attacks buried in the noise, producing only the events analysts need to investigate.

\n\nSpeakers:Fukusuke Takahashi,Zach Mathis,Akira Nishikawa
\n
\nSpeakerBio:  Fukusuke Takahashi
\n

Fukusuke Takahashi has been with NTTDATA-CERT (NTT DATA Group Corporation\'s CSIRT) since 2018, specializing in DFIR, OSINT, and SOAR. He is one of the developers of Yamato Security\'s OSS tools. He enjoys developing open-source Blue Team tools. He has presented at conferences such as FIRST Annual Conferences, SECCON, BSides Tokyo, HITCON CMT, SecTor and AUSCERT.

\n\nSpeakerBio:  Zach Mathis
\n

Zach Mathis has been working in Japan doing offensive and defensive security work for Japanese companies since 2006. In 2012, he founded Yamato Security, one of the largest hands-on hacker communities in Japan. With other Yamato Security members, he has been releasing free and open source DFIR tools and resources since 2020.

\n\nSpeakerBio:  Akira Nishikawa
\n

Akira Nishikawa started his career as a software engineer specializing in embedded development. He worked as a freelance engineer in 2007, focusing on system development and operation for various companies. Since 2021, he has been dedicated to fostering a security culture for SaaS product security and improving service security. Additionally, he is an AWS Community Builder as of 2024.

\n\n\nLinks:
    Github (Senrigan) - https://github.com/Yamato-Security/senrigan
\n    GitHub (Suzaku) - https://github.com/Yamato-Security/suzaku
\n\'',NULL,1293659),('2_Friday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop\'','\'Fukusuke Takahashi,Zach Mathis,Akira Nishikawa\'','Demo Labs_56ee5c0a8aba0b446741df0c2f9832cb','\'Title: Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop
\nTags: DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

Senrigan (千里眼) and Suzaku (朱雀) are two complementary open-source tools that together form a complete threat hunting and DFIR platform for AWS CloudTrail logs. Both are built by Yamato Security, the volunteer-run Japanese security community behind Hayabusa(隼), the widely adopted Windows event log fast-forensics tool. Yamato Security provides free, open-source DFIR tools and resources to the community.

\n\n

Building on Hayabusa\'s philosophy of fast, offline, community rule-based detection, this toolset brings the same approach to the cloud. Security teams can hunt threats across CloudTrail logs on a single laptop — without a SIEM, dedicated infrastructure, or licensing cost.

\n\n

The two tools work together, with Suzaku\'s detections flowing into Senrigan for analysis. Senrigan, deployed via Docker Compose, ingests CloudTrail logs into DuckDB via a Rust-based ingester, then lets analysts investigate them through 100+ pre-built hunting queries and 80+ pre-built Apache Superset dashboard charts — no SQL or CloudTrail schema knowledge required. Suzaku is a high-performance, standalone Rust-based CLI that applies native Sigma detection rules to CloudTrail logs and generates a fast-forensics DFIR timeline — surfacing attacks buried in the noise, producing only the events analysts need to investigate.

\n\nSpeakers:Fukusuke Takahashi,Zach Mathis,Akira Nishikawa
\n
\nSpeakerBio:  Fukusuke Takahashi
\n

Fukusuke Takahashi has been with NTTDATA-CERT (NTT DATA Group Corporation\'s CSIRT) since 2018, specializing in DFIR, OSINT, and SOAR. He is one of the developers of Yamato Security\'s OSS tools. He enjoys developing open-source Blue Team tools. He has presented at conferences such as FIRST Annual Conferences, SECCON, BSides Tokyo, HITCON CMT, SecTor and AUSCERT.

\n\nSpeakerBio:  Zach Mathis
\n

Zach Mathis has been working in Japan doing offensive and defensive security work for Japanese companies since 2006. In 2012, he founded Yamato Security, one of the largest hands-on hacker communities in Japan. With other Yamato Security members, he has been releasing free and open source DFIR tools and resources since 2020.

\n\nSpeakerBio:  Akira Nishikawa
\n

Akira Nishikawa started his career as a software engineer specializing in embedded development. He worked as a freelance engineer in 2007, focusing on system development and operation for various companies. Since 2021, he has been dedicated to fostering a security culture for SaaS product security and improving service security. Additionally, he is an AWS Community Builder as of 2024.

\n\n\nLinks:
    Github (Senrigan) - https://github.com/Yamato-Security/senrigan
\n    GitHub (Suzaku) - https://github.com/Yamato-Security/suzaku
\n\'',NULL,1293660),('2_Friday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'TokenMesh: Exposing Azure\'s Hidden Identity Attack Surface\'','\'Saksham Agrawal\'','Demo Labs_440b37b146c59712f5db8a953d6ba266','\'Title: TokenMesh: Exposing Azure\'s Hidden Identity Attack Surface
\nTags: AI | DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

Modern cloud environments are riddled with identity misconfigurations that go undetected until it\'s too late. TokenMesh is an open-source Azure security reconnaissance tool built to expose exactly that — over-privileged identities, dormant service principals, misconfigured storage accounts, and potential backdoors hiding in plain sight across Microsoft Entra ID and Azure RBAC.\nUnlike traditional scanners that drown you in raw data, TokenMesh is designed with the security practitioner in mind. It integrates directly with the Model Context Protocol (MCP) and the OpenAI API, allowing AI-assisted analysis that surfaces critical findings in plain language — no SIEM required, no query language to master. Plug it into your AI workflow of choice, ask questions in natural language, and get answers that actually make sense.\nIn this session, we\'ll walk through how TokenMesh was built, the real-world attack paths it uncovers, and live demonstrations against a target Azure environment. We\'ll cover how attackers abuse identity misconfigurations, how privilege escalation paths hide inside legitimate role assignments, and how defenders can use TokenMesh to harden their posture before adversaries exploit it. Whether you\'re a red teamer mapping an Azure tenant or a blue teamer trying to get ahead of the next breach.

\n\nSpeakerBio:  Saksham Agrawal
\n

Saksham Agrawal is a Senior Security Consultant at NotSoSecure, specializing in cloud security. His work focuses on discovering new attack paths in cloud environments and helping organizations understand real-world risks. He has presented his research at DEF CON Cloud Village, where he introduced his tool NoPrompt and shared practical techniques for cloud security testing. He enjoys building tools, exploring cloud internals, and sharing his findings with the security community. He has also responsibly reported critical vulnerabilities in major cloud vendors as part of his independent security research and actively delivers training sessions on cloud security and offensive security techniques.

\n\n\nLinks:
    GitHub - https://github.com/NotSoSecure/TokenMesh/
\n\'',NULL,1293661),('3_Saturday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'TokenMesh: Exposing Azure\'s Hidden Identity Attack Surface\'','\'Saksham Agrawal\'','Demo Labs_1d7e80660e7dc086976501928b410afb','\'Title: TokenMesh: Exposing Azure\'s Hidden Identity Attack Surface
\nTags: AI | DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | Offense/Red Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\n

Modern cloud environments are riddled with identity misconfigurations that go undetected until it\'s too late. TokenMesh is an open-source Azure security reconnaissance tool built to expose exactly that — over-privileged identities, dormant service principals, misconfigured storage accounts, and potential backdoors hiding in plain sight across Microsoft Entra ID and Azure RBAC.\nUnlike traditional scanners that drown you in raw data, TokenMesh is designed with the security practitioner in mind. It integrates directly with the Model Context Protocol (MCP) and the OpenAI API, allowing AI-assisted analysis that surfaces critical findings in plain language — no SIEM required, no query language to master. Plug it into your AI workflow of choice, ask questions in natural language, and get answers that actually make sense.\nIn this session, we\'ll walk through how TokenMesh was built, the real-world attack paths it uncovers, and live demonstrations against a target Azure environment. We\'ll cover how attackers abuse identity misconfigurations, how privilege escalation paths hide inside legitimate role assignments, and how defenders can use TokenMesh to harden their posture before adversaries exploit it. Whether you\'re a red teamer mapping an Azure tenant or a blue teamer trying to get ahead of the next breach.

\n\nSpeakerBio:  Saksham Agrawal
\n

Saksham Agrawal is a Senior Security Consultant at NotSoSecure, specializing in cloud security. His work focuses on discovering new attack paths in cloud environments and helping organizations understand real-world risks. He has presented his research at DEF CON Cloud Village, where he introduced his tool NoPrompt and shared practical techniques for cloud security testing. He enjoys building tools, exploring cloud internals, and sharing his findings with the security community. He has also responsibly reported critical vulnerabilities in major cloud vendors as part of his independent security research and actively delivers training sessions on cloud security and offensive security techniques.

\n\n\nLinks:
    GitHub - https://github.com/NotSoSecure/TokenMesh/
\n\'',NULL,1293662),('2_Friday','14','14:00','14:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'Trajan: Cross-Platform CI/CD Security Scanner\'','\'Rahul Saranjame,Ranganatha Rao Sridhar,Tanishq Rupaal\'','Demo Labs_ef0643d3eb6218ec5b966d06cd241563','\'Title: Trajan: Cross-Platform CI/CD Security Scanner
\nTags: AI | DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | DevOps | Offense/Red Team | Purple Team | SecOps | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

For three years, Praetorian has consistently found that CI/CD pipelines are one of the fastest paths to compromise enterprise environments. A misconfigured workflow or an over-privileged service connection can provide you with credentials, cloud access, or code execution on internal infrastructure, often undetected.

\n\n

We built to keep up: Gato for GitHub Actions (BH 2024), then Glato for GitLab CI (BH 2025). Both proved the approach: parse the pipeline configuration, classify triggers, gates, and danger zones, build a graph of how they connect, and surface what\'s actually exploitable.

\n\n

The problem was that no client runs just one platform. A typical enterprise has GitHub Actions for open-source, Azure DevOps for internal deployments, and GitLab for containerized workloads. Assessing all of that meant juggling multiple tools with different output formats and coverage gaps.

\n\n

Trajan folds everything we learned into a single tool spanning GitHub Actions, GitLab CI, and Azure DevOps. Each platform runs through the same phased pipeline: collect the pipeline config and the org surface, normalize it, correlate multi-step attack chains, scan against a YAML detection-rule corpus organized by attack category, and report through one unified findings format. Support for Jenkins, CircleCI, and Bitbucket is in active development.

\n\nSpeakers:Rahul Saranjame,Ranganatha Rao Sridhar,Tanishq Rupaal
\n
\nSpeakerBio:  Rahul Saranjame
\n

Lead Security Engineer at Praetorian focused on penetration testing, red/purple teaming, CI/CD pipeline security, and risk advisory assessments. Rahul is OSCP and CRTO certified, holds a Master\'s degree in Cybersecurity from Georgia Tech, and is a core contributor to Trajan.

\n\nSpeakerBio:  Ranganatha Rao Sridhar
\n

OSCE3 certified Lead Security Engineer at Praetorian with expertise spanning product, cloud, and corporate security. Rao holds a Master\'s degree in Cybersecurity from Georgia Tech and is a core contributor to Trajan.

\n\nSpeakerBio:  Tanishq Rupaal
\n

Staff Offensive Security Engineer at Praetorian specializing in cloud security across AWS, GCP, and Azure. He designed the Guard Platform\'s cloud integration mechanism, is a core contributor to Trajan, and holds an M.S. in Cybersecurity from Georgia Tech.

\n\n\nLinks:
    GitHub - https://github.com/praetorian-inc/trajan
\n\'',NULL,1293663),('3_Saturday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'Trajan: Cross-Platform CI/CD Security Scanner\'','\'Rahul Saranjame,Ranganatha Rao Sridhar,Tanishq Rupaal\'','Demo Labs_61951773d2696ad1c1dc30775ea6d1a8','\'Title: Trajan: Cross-Platform CI/CD Security Scanner
\nTags: AI | DEF CON Demo Labs | Intermediate | Cloud | Defense/Blue Team | DevOps | Offense/Red Team | Purple Team | SecOps | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

For three years, Praetorian has consistently found that CI/CD pipelines are one of the fastest paths to compromise enterprise environments. A misconfigured workflow or an over-privileged service connection can provide you with credentials, cloud access, or code execution on internal infrastructure, often undetected.

\n\n

We built to keep up: Gato for GitHub Actions (BH 2024), then Glato for GitLab CI (BH 2025). Both proved the approach: parse the pipeline configuration, classify triggers, gates, and danger zones, build a graph of how they connect, and surface what\'s actually exploitable.

\n\n

The problem was that no client runs just one platform. A typical enterprise has GitHub Actions for open-source, Azure DevOps for internal deployments, and GitLab for containerized workloads. Assessing all of that meant juggling multiple tools with different output formats and coverage gaps.

\n\n

Trajan folds everything we learned into a single tool spanning GitHub Actions, GitLab CI, and Azure DevOps. Each platform runs through the same phased pipeline: collect the pipeline config and the org surface, normalize it, correlate multi-step attack chains, scan against a YAML detection-rule corpus organized by attack category, and report through one unified findings format. Support for Jenkins, CircleCI, and Bitbucket is in active development.

\n\nSpeakers:Rahul Saranjame,Ranganatha Rao Sridhar,Tanishq Rupaal
\n
\nSpeakerBio:  Rahul Saranjame
\n

Lead Security Engineer at Praetorian focused on penetration testing, red/purple teaming, CI/CD pipeline security, and risk advisory assessments. Rahul is OSCP and CRTO certified, holds a Master\'s degree in Cybersecurity from Georgia Tech, and is a core contributor to Trajan.

\n\nSpeakerBio:  Ranganatha Rao Sridhar
\n

OSCE3 certified Lead Security Engineer at Praetorian with expertise spanning product, cloud, and corporate security. Rao holds a Master\'s degree in Cybersecurity from Georgia Tech and is a core contributor to Trajan.

\n\nSpeakerBio:  Tanishq Rupaal
\n

Staff Offensive Security Engineer at Praetorian specializing in cloud security across AWS, GCP, and Azure. He designed the Guard Platform\'s cloud integration mechanism, is a core contributor to Trajan, and holds an M.S. in Cybersecurity from Georgia Tech.

\n\n\nLinks:
    GitHub - https://github.com/praetorian-inc/trajan
\n\'',NULL,1293664),('2_Friday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'VoiceLock: Offline, Robust On-Device Speech Transcription\'','\'Ayaan Qayyum,Parag Kalay\'','Demo Labs_3139de42123a70d974c80e09f2a77adc','\'Title: VoiceLock: Offline, Robust On-Device Speech Transcription
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | Hardware/IoT | Mobile | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

VoiceLock analyzes audio to identify speakers, count participants, and understand what each person said and discussed, just from a microphone. The self-contained, entirely offline system is designed for continuous, long-term use cases of 72 to 168 hours or more. The system runs entirely on-device, with high accuracy as tested on datasets and in the real world. Key innovations include an on-device vector database for fast speaker-similarity search and robust noise reduction, which greatly improve transcript accuracy. The output is a transcript with name labels. The system is fast enough to transcribe and report in under a minute. Code is written as an open-source Python module with a provided runtime and setup script to enable quick deployment on IoT devices. The system has been tested in challenging environments, including high noise levels, many speakers/arguments, and a lecture-style format. We present a live demo, technical details, and a short runtime tutorial.

\n\nSpeakers:Ayaan Qayyum,Parag Kalay
\n
\nSpeakerBio:  Ayaan Qayyum
\n

Ayaan is an MS in engineering student at Columbia University. His research interests include mobile computing, applied machine learning, edge AI, and data science. He is an expert in understanding customer needs and use cases to solve real-world problems.

\n\nSpeakerBio:  Parag Kalay
\n

Parag is a Biomedical Engineering MS student at Columbia University, combining expertise in CAD, rapid prototyping, and data-driven design to transform concepts into functional technologies under tight technical constraints. Skilled in translating clinical needs into robust engineering solutions from initial sketches to validated prototypes.

\n\n\nLinks:
    GitHub - https://github.com/qayyumayaan/voicelock
\n\'',NULL,1293665),('3_Saturday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)','\'VoiceLock: Offline, Robust On-Device Speech Transcription\'','\'Ayaan Qayyum,Parag Kalay\'','Demo Labs_3b07030e6020ff7a84cb713e83bffc8a','\'Title: VoiceLock: Offline, Robust On-Device Speech Transcription
\nTags: Intro/Beginner | AI | DEF CON Demo Labs | Hardware/IoT | Mobile | Offense/Red Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - Map
\n
\nDescription:
\n

VoiceLock analyzes audio to identify speakers, count participants, and understand what each person said and discussed, just from a microphone. The self-contained, entirely offline system is designed for continuous, long-term use cases of 72 to 168 hours or more. The system runs entirely on-device, with high accuracy as tested on datasets and in the real world. Key innovations include an on-device vector database for fast speaker-similarity search and robust noise reduction, which greatly improve transcript accuracy. The output is a transcript with name labels. The system is fast enough to transcribe and report in under a minute. Code is written as an open-source Python module with a provided runtime and setup script to enable quick deployment on IoT devices. The system has been tested in challenging environments, including high noise levels, many speakers/arguments, and a lecture-style format. We present a live demo, technical details, and a short runtime tutorial.

\n\nSpeakers:Ayaan Qayyum,Parag Kalay
\n
\nSpeakerBio:  Ayaan Qayyum
\n

Ayaan is an MS in engineering student at Columbia University. His research interests include mobile computing, applied machine learning, edge AI, and data science. He is an expert in understanding customer needs and use cases to solve real-world problems.

\n\nSpeakerBio:  Parag Kalay
\n

Parag is a Biomedical Engineering MS student at Columbia University, combining expertise in CAD, rapid prototyping, and data-driven design to transform concepts into functional technologies under tight technical constraints. Skilled in translating clinical needs into robust engineering solutions from initial sketches to validated prototypes.

\n\n\nLinks:
    GitHub - https://github.com/qayyumayaan/voicelock
\n\'',NULL,1293666),('3_Saturday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'Weaponizing eBPF and XDP with Covert Triggered Reverse Shells\'','\'Yll \"0xBabar0ka\" Berisha\'','Demo Labs_583c71769a10d7a419810e2715a09f3e','\'Title: Weaponizing eBPF and XDP with Covert Triggered Reverse Shells
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\neBPF and XDP now underpin critical Linux infrastructure yet their kernel-level access creates a blind spot: adversaries can weaponize these primitives for stealth persistence that evades standard forensic tools. Current defenses are not equipped for this emerging threat.
\n\n

We built Phantasma, an open-source eBPF implant, to expose this gap. It combines three kernel-level techniques: (1) XDP covert triggering that intercepts packets at the NIC driver before they reach the networking stack, firewalls, or packet capture systems (2) getdents64 syscall interception to hide processes from /proc, defeating ps, top, and all enumeration tools; and (3) bpf() syscall interception to cloak loaded eBPF objects from bpftool and forensic inspection.

\n\n

We live-demonstrate the full attack chain deployment, self-cloaking, magic packet activation, and encrypted reverse shell showing the implant defeating packet capture, process listing, and BPF introspection simultaneously.

\n\n

We then present the defenses this threat demands: kernel audit rules for bpf() syscalls, /sys/fs/bpf inspection, XDP attachment monitoring, and behavioral indicators. Attendees leave with detection rules, hardening steps, and a clear understanding of why eBPF must be treated as an attack surface, not just a defense tool.

\n\nSpeakerBio:  Yll \"0xBabar0ka\" Berisha
\n

I am an offensive security researcher with 2 years of experience in penetration testing, red teaming, and custom tooling. I am the creator of Phantasma, an open-source eBPF/XDP implant framework for stealth persistence research.

\n\n

Professionally, I have worked at Sentry, conducting web, mobile, and internal/external network penetration tests. At Finbbug, I contributed to a US Embassy-supported project assessing the cybersecurity posture of NGOs and media organizations in Kosovo, identifying issues such as XSS, directory listing, and IDOR vulnerabilities. At Starlabs, I built dark web monitoring tools using HaveIBeenPwned and LeakX APIs for automated credential leak detection.

\n\n

I hold BSCP (Burp Suite Certified), CRT-ID (Certified Red Team Infra Dev), MCRTA (Multi Cloud Red Teamer), CISCO ETHICAL HACKER, and HACKWISER CAPT certifications. I placed 1st at the Iowa State Cyber Defense Competition and represented Kosovo at the 2024 ENISA European Cybersecurity Challenge in Turin.

\n\n

I have presented at CyberZero on prompt injection attacks and deepfake-based social engineering at the TechRisck conference, and co-organized national and international CTFs designing real-world attack chain challenges.

\n\n

I am also a member of DefCon Group Prishtina (DC38338), where I contribute to co-organizing meetups and community events.

\n\n\nLinks:
    GitHub - https://gitlab.com/0xBabar0ka/Phantasma
\n\'',NULL,1293667),('2_Friday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)','\'Weaponizing eBPF and XDP with Covert Triggered Reverse Shells\'','\'Yll \"0xBabar0ka\" Berisha\'','Demo Labs_e6f6cf9539fde04a901fce0be96c143f','\'Title: Weaponizing eBPF and XDP with Covert Triggered Reverse Shells
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - Map
\n
\nDescription:
\neBPF and XDP now underpin critical Linux infrastructure yet their kernel-level access creates a blind spot: adversaries can weaponize these primitives for stealth persistence that evades standard forensic tools. Current defenses are not equipped for this emerging threat.
\n\n

We built Phantasma, an open-source eBPF implant, to expose this gap. It combines three kernel-level techniques: (1) XDP covert triggering that intercepts packets at the NIC driver before they reach the networking stack, firewalls, or packet capture systems (2) getdents64 syscall interception to hide processes from /proc, defeating ps, top, and all enumeration tools; and (3) bpf() syscall interception to cloak loaded eBPF objects from bpftool and forensic inspection.

\n\n

We live-demonstrate the full attack chain deployment, self-cloaking, magic packet activation, and encrypted reverse shell showing the implant defeating packet capture, process listing, and BPF introspection simultaneously.

\n\n

We then present the defenses this threat demands: kernel audit rules for bpf() syscalls, /sys/fs/bpf inspection, XDP attachment monitoring, and behavioral indicators. Attendees leave with detection rules, hardening steps, and a clear understanding of why eBPF must be treated as an attack surface, not just a defense tool.

\n\nSpeakerBio:  Yll \"0xBabar0ka\" Berisha
\n

I am an offensive security researcher with 2 years of experience in penetration testing, red teaming, and custom tooling. I am the creator of Phantasma, an open-source eBPF/XDP implant framework for stealth persistence research.

\n\n

Professionally, I have worked at Sentry, conducting web, mobile, and internal/external network penetration tests. At Finbbug, I contributed to a US Embassy-supported project assessing the cybersecurity posture of NGOs and media organizations in Kosovo, identifying issues such as XSS, directory listing, and IDOR vulnerabilities. At Starlabs, I built dark web monitoring tools using HaveIBeenPwned and LeakX APIs for automated credential leak detection.

\n\n

I hold BSCP (Burp Suite Certified), CRT-ID (Certified Red Team Infra Dev), MCRTA (Multi Cloud Red Teamer), CISCO ETHICAL HACKER, and HACKWISER CAPT certifications. I placed 1st at the Iowa State Cyber Defense Competition and represented Kosovo at the 2024 ENISA European Cybersecurity Challenge in Turin.

\n\n

I have presented at CyberZero on prompt injection attacks and deepfake-based social engineering at the TechRisck conference, and co-organized national and international CTFs designing real-world attack chain challenges.

\n\n

I am also a member of DefCon Group Prishtina (DC38338), where I contribute to co-organizing meetups and community events.

\n\n\nLinks:
    GitHub - https://gitlab.com/0xBabar0ka/Phantasma
\n\'',NULL,1293668),('3_Saturday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain\'','\'Xia Hua,Abhijeet Kumar\'','Demo Labs_90c5782379c186f2d2f125932b562863','\'Title: X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

Agents now run with thousands of third-party plugins — MCP servers, Claude skills, GPT actions, IDE extensions, plugin marketplaces — and the prevailing trust model is roughly “read the README and hope.” Tool descriptions are executable prompts. Tool parameters are executable code paths. Tool outputs feed straight into the next agent step. Yet there is no npm audit for this ecosystem, no signed manifests, and no capability sandbox in the wild.

\n\n

MCP X-Ray is an open-source security scanner that ports classical pentest tradecraft to the agent plugin supply chain. It combines static config and repo audit, rules-based and LLM-driven semantic analysis, and active pentesting that actually invokes tools with adversarial inputs — emitting SARIF that drops into GitHub, VS Code, and CI gates today. In this 30-minute session we will (1) walk the threat model that ties MCPs, skills, and plugin bundles together; (2) live-demo X-Ray finding real vulnerabilities in each. Attendees walk away with a CI template they can drop in on Monday, and three intentionally vulnerable plugins to keep practicing on.

\n\nSpeakers:Xia Hua,Abhijeet Kumar
\n
\nSpeakerBio:  Xia Hua
\n

Xia is co-founder and CEO of Traceforce which secures AI native apps running on devices. She previously led engineering at Clumio (acquired by Commvault), delivering cloud data protection products that were 20x faster and 10x more scalable than competitors. Earlier, she was an in-memory database architect at Oracle. Xia earned her PhD in Applied Mathematics from MIT.

\n\nSpeakerBio:  Abhijeet Kumar
\n

Abhijeet Kumar is an OSCP-certified offensive security researcher and M.Eng Cybersecurity student at the University of Maryland. He has disclosed critical vulnerabilities across NASA, SAIL critical infrastructure, Keurig Dr Pepper, and U.S. government programs which includes a CVSS 10.0 RCE that triggered an official CERT-In incident response and a full account takeover chain affecting users across 20+ countries. He captains UMD\'s CTF team RandomHackers, which placed 1st out of 64 universities at HTB Hack The Madness 2026, and has spoken at the Billington State and Local Cybersecurity Summit alongside the Director of Adversary Emulation.

\n\n\nLinks:
    GitHub - https://github.com/traceforce/mcp-xray
\n\'',NULL,1293669),('2_Friday','10','10:00','10:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain\'','\'Xia Hua,Abhijeet Kumar\'','Demo Labs_20977489b2362288240c2aba86c1b93e','\'Title: X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Offense/Red Team | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

Agents now run with thousands of third-party plugins — MCP servers, Claude skills, GPT actions, IDE extensions, plugin marketplaces — and the prevailing trust model is roughly “read the README and hope.” Tool descriptions are executable prompts. Tool parameters are executable code paths. Tool outputs feed straight into the next agent step. Yet there is no npm audit for this ecosystem, no signed manifests, and no capability sandbox in the wild.

\n\n

MCP X-Ray is an open-source security scanner that ports classical pentest tradecraft to the agent plugin supply chain. It combines static config and repo audit, rules-based and LLM-driven semantic analysis, and active pentesting that actually invokes tools with adversarial inputs — emitting SARIF that drops into GitHub, VS Code, and CI gates today. In this 30-minute session we will (1) walk the threat model that ties MCPs, skills, and plugin bundles together; (2) live-demo X-Ray finding real vulnerabilities in each. Attendees walk away with a CI template they can drop in on Monday, and three intentionally vulnerable plugins to keep practicing on.

\n\nSpeakers:Xia Hua,Abhijeet Kumar
\n
\nSpeakerBio:  Xia Hua
\n

Xia is co-founder and CEO of Traceforce which secures AI native apps running on devices. She previously led engineering at Clumio (acquired by Commvault), delivering cloud data protection products that were 20x faster and 10x more scalable than competitors. Earlier, she was an in-memory database architect at Oracle. Xia earned her PhD in Applied Mathematics from MIT.

\n\nSpeakerBio:  Abhijeet Kumar
\n

Abhijeet Kumar is an OSCP-certified offensive security researcher and M.Eng Cybersecurity student at the University of Maryland. He has disclosed critical vulnerabilities across NASA, SAIL critical infrastructure, Keurig Dr Pepper, and U.S. government programs which includes a CVSS 10.0 RCE that triggered an official CERT-In incident response and a full account takeover chain affecting users across 20+ countries. He captains UMD\'s CTF team RandomHackers, which placed 1st out of 64 universities at HTB Hack The Madness 2026, and has spoken at the Billington State and Local Cybersecurity Summit alongside the Director of Adversary Emulation.

\n\n\nLinks:
    GitHub - https://github.com/traceforce/mcp-xray
\n\'',NULL,1293670),('3_Saturday','12','12:00','12:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'Zealot: An Autonomous Cloud Offensive Multi-Agent System\'','\'Chen Doytshman\'','Demo Labs_8709fec5bc1ec0e8c8f37803d1bbfd47','\'Title: Zealot: An Autonomous Cloud Offensive Multi-Agent System
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Cloud | Defense/Blue Team | Offense/Red Team | Purple Team | SecOps | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

In November 2025, Anthropic disclosed a state-sponsored operation where AI didn\'t assist human attackers — it was the attacker, executing 80-90% of the campaign autonomously. The question shifted from \"could this happen?\" to \"how bad can it get?\"

\n\n

We built Zealot to find out.

\n\n

Zealot is a multi-agent offensive framework that autonomously chains reconnaissance, exploitation, privilege escalation, and data exfiltration against cloud environments — with no human directing individual steps. A supervisor agent coordinates three specialists (Infrastructure, AppSec, and Cloud) that share attack state and hand off context as the operation progresses. The result: an AI system that thinks strategically and executes tactically, the way a real red team does.

\n\n

In live sandbox tests against GCP, Zealot autonomously discovered an exposed web service, identified and exploited an SSRF vulnerability, extracted service account credentials from the metadata service, impersonated a higher-privileged account, and exfiltrated BigQuery datasets — start to finish, without a human touching the keyboard after the objective was set.

\n\n

We\'ll walk through the architecture, show the full attack chain on video, and share the honest lessons: where AI operators excel (systematic enumeration, credential chaining, API fluency), where they fall short (a

\n\nSpeakerBio:  Chen Doytshman
\n

I\'m a security researcher with a background in artificial intelligence and machine learning. I am passionate about using my skills to protect against cyber threats. With over 5 years of experience in the field, I have a strong understanding of both security and AI technologies and am skilled at combining the two to identify and mitigate vulnerabilities.

\n\n\nLinks:
    Website - https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/
\n\'',NULL,1293671),('2_Friday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'Zealot: An Autonomous Cloud Offensive Multi-Agent System\'','\'Chen Doytshman\'','Demo Labs_d15d7126d97a8752c2f459341919ecf9','\'Title: Zealot: An Autonomous Cloud Offensive Multi-Agent System
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Cloud | Defense/Blue Team | Offense/Red Team | Purple Team | SecOps | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

In November 2025, Anthropic disclosed a state-sponsored operation where AI didn\'t assist human attackers — it was the attacker, executing 80-90% of the campaign autonomously. The question shifted from \"could this happen?\" to \"how bad can it get?\"

\n\n

We built Zealot to find out.

\n\n

Zealot is a multi-agent offensive framework that autonomously chains reconnaissance, exploitation, privilege escalation, and data exfiltration against cloud environments — with no human directing individual steps. A supervisor agent coordinates three specialists (Infrastructure, AppSec, and Cloud) that share attack state and hand off context as the operation progresses. The result: an AI system that thinks strategically and executes tactically, the way a real red team does.

\n\n

In live sandbox tests against GCP, Zealot autonomously discovered an exposed web service, identified and exploited an SSRF vulnerability, extracted service account credentials from the metadata service, impersonated a higher-privileged account, and exfiltrated BigQuery datasets — start to finish, without a human touching the keyboard after the objective was set.

\n\n

We\'ll walk through the architecture, show the full attack chain on video, and share the honest lessons: where AI operators excel (systematic enumeration, credential chaining, API fluency), where they fall short (a

\n\nSpeakerBio:  Chen Doytshman
\n

I\'m a security researcher with a background in artificial intelligence and machine learning. I am passionate about using my skills to protect against cyber threats. With over 5 years of experience in the field, I have a strong understanding of both security and AI technologies and am skilled at combining the two to identify and mitigate vulnerabilities.

\n\n\nLinks:
    Website - https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/
\n\'',NULL,1293672),('3_Saturday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'Zero-Cloud Threat Modeling: Vector Embedding Architectures for Automated Vulnerability Detection\'','\'Ankit Vashisth\'','Demo Labs_683655ab4f6ae6b1ac71376cf0883232','\'Title: Zero-Cloud Threat Modeling: Vector Embedding Architectures for Automated Vulnerability Detection
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

Traditional threat modeling is a tedious, manual process prone to human error. Conversely, modern \"AI\" threat modeling tools almost universally depend on sending sensitive, proprietary system architectures to third-party APIs in cleartext.

\n\n

We present AI Threat Modeler (AITM), a fully open-source, zero-cloud application designed to automate architecture-driven STRIDE threat modeling completely offline. AITM fundamentally shifts how we analyze system designs by replacing brittle, keyword-based regex rules with a local Semantic AI Engine.

\n\n

Under the hood, AITM leverages sentence-transformers and an in-memory FAISS vector database to embed a comprehensive, 116+ component knowledge base. During analysis, a custom NetworkX graph builder parses natural language or structured architecture descriptions (via spaCy) to map undocumented architectural features to known CVE classes and STRIDE categories.

\n\n

Furthermore, AITM introduces \"Architecture Intelligence\" using graph traversal algorithms to automatically infer missing trust boundaries and identify multi-step attack chains that standalone component scanning misses.\nIn this demo, we will:\nWalk through the automated ingestion of a microservice architecture.\nDemonstrate how the local FAISS engine discovers semantic threats that evade keyword matching.\nShow dynamic attack cha

\n\nSpeakerBio:  Ankit Vashisth
\n

Ankit Vashisth is a Security Engineer with over 4 years of experience in application security, cloud security, and DevSecOps. He has worked on security assessments across web, mobile, network, and enterprise systems for global clients. His interests include AI-driven security tooling, threat modeling, and security automation. Ankit actively researches ways to apply AI to improve security architecture analysis and vulnerability detection.

\n\n\nLinks:
    GitHub - https://github.com/ankitspidy007/ai-threat-modeler
\n\'',NULL,1293673),('2_Friday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)','\'Zero-Cloud Threat Modeling: Vector Embedding Architectures for Automated Vulnerability Detection\'','\'Ankit Vashisth\'','Demo Labs_298560f2a4d26f600c235d595a30c81f','\'Title: Zero-Cloud Threat Modeling: Vector Embedding Architectures for Automated Vulnerability Detection
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - Map
\n
\nDescription:
\n

Traditional threat modeling is a tedious, manual process prone to human error. Conversely, modern \"AI\" threat modeling tools almost universally depend on sending sensitive, proprietary system architectures to third-party APIs in cleartext.

\n\n

We present AI Threat Modeler (AITM), a fully open-source, zero-cloud application designed to automate architecture-driven STRIDE threat modeling completely offline. AITM fundamentally shifts how we analyze system designs by replacing brittle, keyword-based regex rules with a local Semantic AI Engine.

\n\n

Under the hood, AITM leverages sentence-transformers and an in-memory FAISS vector database to embed a comprehensive, 116+ component knowledge base. During analysis, a custom NetworkX graph builder parses natural language or structured architecture descriptions (via spaCy) to map undocumented architectural features to known CVE classes and STRIDE categories.

\n\n

Furthermore, AITM introduces \"Architecture Intelligence\" using graph traversal algorithms to automatically infer missing trust boundaries and identify multi-step attack chains that standalone component scanning misses.\nIn this demo, we will:\nWalk through the automated ingestion of a microservice architecture.\nDemonstrate how the local FAISS engine discovers semantic threats that evade keyword matching.\nShow dynamic attack cha

\n\nSpeakerBio:  Ankit Vashisth
\n

Ankit Vashisth is a Security Engineer with over 4 years of experience in application security, cloud security, and DevSecOps. He has worked on security assessments across web, mobile, network, and enterprise systems for global clients. His interests include AI-driven security tooling, threat modeling, and security automation. Ankit actively researches ways to apply AI to improve security architecture analysis and vulnerability detection.

\n\n\nLinks:
    GitHub - https://github.com/ankitspidy007/ai-threat-modeler
\n\'',NULL,1293674),('2_Friday','15','15:00','15:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'pymsi: Interactive MSI Installer Analysis in Python and the Browser\'','\'Ryan \"Nightlark\" Mast\'','Demo Labs_f1a57cb3aa8eab29df76d104c4a333f5','\'Title: pymsi: Interactive MSI Installer Analysis in Python and the Browser
\nTags: Intro/Beginner | DEF CON Demo Labs | AppSec | Defense/Blue Team | Malware | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

pymsi is a pure-Python library for parsing, analyzing, and extracting files from Windows installer (MSI) packages, without relying on native Windows APIs or tooling. It provides direct access to MSI database tables, embedded binary streams, and installer metadata, enabling security researchers to inspect installer behavior and extract files from MSI installers.

\n\n

We will demonstrate its ability to safely tear apart malicious MSI droppers, dump internal database tables, and extract embedded payloads without risking accidental execution. Attendees will see how the CLI and Python API can be used to triage files and integrate it into automated analysis pipelines, including how it has been integrated into other open source tools to extract embedded payloads and identify malicious CustomAction behaviors.

\n\n

Because it is written entirely in Python, it runs seamlessly on any OS with a Python interpreter, including web browsers. The demo will showcase the online MSI viewer, a client-side tool powered by Pyodide that gives pymsi a familiar lessmsi-style UI for working with MSI installers from any device with a web browser. Demos will also show new security analysis features for identifying suspicious installer behaviors and inspecting contents of embedded binary streams within a browser.

\n\nSpeakerBio:  Ryan \"Nightlark\" Mast
\n

Ryan is a software engineer working on open source projects to make the electric grid more reliable. His interests include software security, niche video games, tearing apart \"smart\" devices, and reverse engineering audio/video hardware used in live productions.

\n\n\nLinks:
    GitHub - https://github.com/nightlark/pymsi
\n\'',NULL,1293675),('3_Saturday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)','\'pymsi: Interactive MSI Installer Analysis in Python and the Browser\'','\'Ryan \"Nightlark\" Mast\'','Demo Labs_1f21b811c65a54327e9be368e7770186','\'Title: pymsi: Interactive MSI Installer Analysis in Python and the Browser
\nTags: Intro/Beginner | DEF CON Demo Labs | AppSec | Defense/Blue Team | Malware | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - Map
\n
\nDescription:
\n

pymsi is a pure-Python library for parsing, analyzing, and extracting files from Windows installer (MSI) packages, without relying on native Windows APIs or tooling. It provides direct access to MSI database tables, embedded binary streams, and installer metadata, enabling security researchers to inspect installer behavior and extract files from MSI installers.

\n\n

We will demonstrate its ability to safely tear apart malicious MSI droppers, dump internal database tables, and extract embedded payloads without risking accidental execution. Attendees will see how the CLI and Python API can be used to triage files and integrate it into automated analysis pipelines, including how it has been integrated into other open source tools to extract embedded payloads and identify malicious CustomAction behaviors.

\n\n

Because it is written entirely in Python, it runs seamlessly on any OS with a Python interpreter, including web browsers. The demo will showcase the online MSI viewer, a client-side tool powered by Pyodide that gives pymsi a familiar lessmsi-style UI for working with MSI installers from any device with a web browser. Demos will also show new security analysis features for identifying suspicious installer behaviors and inspecting contents of embedded binary streams within a browser.

\n\nSpeakerBio:  Ryan \"Nightlark\" Mast
\n

Ryan is a software engineer working on open source projects to make the electric grid more reliable. His interests include software security, niche video games, tearing apart \"smart\" devices, and reverse engineering audio/video hardware used in live productions.

\n\n\nLinks:
    GitHub - https://github.com/nightlark/pymsi
\n\'',NULL,1293676),('2_Friday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions\'','\'Atsushi Sada,hikae\'','Demo Labs_3bb357d3e542ee576fb789006bc5326a','\'Title: sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Cloud | DevOps | Purple Team | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

GitHub Actions workflows are vulnerable by default. Hardening such as commit-hash pinning, least-privilege permissions, and timeouts is optional, never enforced at pipeline level. Exploitable configs ship daily, increasingly written by Coding Agents.\nsisakulint is a fast heuristic static analyzer for GitHub Actions covering all OWASP Top 10 CI/CD risks, with 52 rules, a taint engine, and 38+ auto-fixes. It outpaces CodeQL on speed and quality, with 100% detection on 18 GHSL advisories and 81.6% on 38 GHSAs covering exploits in PX4-Autopilot, vets-api, weaviate, nrwl/nx.

\n\n

Impostor Commit at CVSS 9.8 validates pinned SHAs against the claimed repository, not impostors via Git forks, a check unique to sisakulint. Code Injection at CVSS 9.8 tracks untrusted input through ${{ }} and step outputs. AI Action Rules detect Clinejection on claude-code-action, copilot-swe-agent, and openai-actions, covering tool grants, prompt injection, and wildcard triggers, as in Cline 2026/02 where issue title injection stole NPM_RELEASE_TOKEN. Known Vulnerable Actions catches tj-actions/changed-files.

\n\n

In the Coding Agent era, linters matter more. Delegating 52 rules to an LLM degrades precision; deterministic engines run in ms with no variance. The session covers end-to-end detection, taint propagation, and automated remediation.

\n\nSpeakers:Atsushi Sada,hikae
\n
\nSpeakerBio:  Atsushi Sada
\n

Atsushi Sada is a CSIRT member specializing in cloud security on AWS and GitHub, and enterprise security with MDM, EDR, AI governance. He is an ethical hacker and security tool developer. He built sisakulint and MachStealer for practical security research in static/network analysis, Malware.

\n\n

He co-founded and organizes @sec_wakate, a community for junior security engineers in Japan. He has spoken at Black Hat USA/Asia Arsenal, AVTOKYO, and AWS Security JAWS.

\n\nSpeakerBio:  hikae
\n

Security Engineer in Red Team @ freee inc, AI Security Specialist.

\n\n\nLinks:
    GitHub - https://sisaku-security.github.io/lint/
\n\'',NULL,1293677),('3_Saturday','11','11:00','11:45','N','Demo Labs','LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)','\'sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions\'','\'Atsushi Sada,hikae\'','Demo Labs_f54b6af95a1a7927f03af1b64ae3f0cc','\'Title: sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions
\nTags: AI | DEF CON Demo Labs | Intermediate | AppSec | Cloud | DevOps | Purple Team | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - Map
\n
\nDescription:
\n

GitHub Actions workflows are vulnerable by default. Hardening such as commit-hash pinning, least-privilege permissions, and timeouts is optional, never enforced at pipeline level. Exploitable configs ship daily, increasingly written by Coding Agents.\nsisakulint is a fast heuristic static analyzer for GitHub Actions covering all OWASP Top 10 CI/CD risks, with 52 rules, a taint engine, and 38+ auto-fixes. It outpaces CodeQL on speed and quality, with 100% detection on 18 GHSL advisories and 81.6% on 38 GHSAs covering exploits in PX4-Autopilot, vets-api, weaviate, nrwl/nx.

\n\n

Impostor Commit at CVSS 9.8 validates pinned SHAs against the claimed repository, not impostors via Git forks, a check unique to sisakulint. Code Injection at CVSS 9.8 tracks untrusted input through ${{ }} and step outputs. AI Action Rules detect Clinejection on claude-code-action, copilot-swe-agent, and openai-actions, covering tool grants, prompt injection, and wildcard triggers, as in Cline 2026/02 where issue title injection stole NPM_RELEASE_TOKEN. Known Vulnerable Actions catches tj-actions/changed-files.

\n\n

In the Coding Agent era, linters matter more. Delegating 52 rules to an LLM degrades precision; deterministic engines run in ms with no variance. The session covers end-to-end detection, taint propagation, and automated remediation.

\n\nSpeakers:Atsushi Sada,hikae
\n
\nSpeakerBio:  Atsushi Sada
\n

Atsushi Sada is a CSIRT member specializing in cloud security on AWS and GitHub, and enterprise security with MDM, EDR, AI governance. He is an ethical hacker and security tool developer. He built sisakulint and MachStealer for practical security research in static/network analysis, Malware.

\n\n

He co-founded and organizes @sec_wakate, a community for junior security engineers in Japan. He has spoken at Black Hat USA/Asia Arsenal, AVTOKYO, and AWS Security JAWS.

\n\nSpeakerBio:  hikae
\n

Security Engineer in Red Team @ freee inc, AI Security Specialist.

\n\n\nLinks:
    GitHub - https://sisaku-security.github.io/lint/
\n\'',NULL,1293678),('2_Friday','13','13:00','13:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'xEndity: IoT Firmware Analysis & Digital Twin Platform\'','\'Zeus \"LightningGod\" Chan,Kenneth \"kenleejl\" Lee\'','Demo Labs_8e470110e011edb413e9f5ce1ac17d1e','\'Title: xEndity: IoT Firmware Analysis & Digital Twin Platform
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Friday, Aug 7, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

IoT devices are embedded in critical infrastructure globally, yet security teams face a fundamental constraint: you cannot aggressively test what you cannot safely replicate. Physical hardware is expensive, limited in supply, and testing against production systems is off-limits. This leaves defenders operating blind against an expanding attack surface of billions of connected devices.

\n\n

xEndity is an open-source, end-to-end IoT firmware emulation platform that transforms raw firmware binaries into fully functional, network-ready virtual device instances, no physical hardware required. It provides an automated pipeline spanning firmware acquisition, binary analysis, filesystem extraction, emulation packaging, and orchestrated deployment of emulated device networks at scale.

\n\n

The platform enables two high-impact use cases: first, as a scopeless penetration testing range where red teams and researchers can conduct unrestricted vulnerability validation, exploit development, and attack simulation against realistic IoT environments. Second, as a deceptive defense layer where emulated devices are deployed as high-interaction honeypots to capture adversary tradecraft, collect OS-level and network telemetry, and generate actionable threat intelligence.

\n\nSpeakers:Zeus \"LightningGod\" Chan,Kenneth \"kenleejl\" Lee
\n
\nSpeakerBio:  Zeus \"LightningGod\" Chan
\n

Zeus Chan is a security researcher on the Adversary Emulation Team at HTX (Home Team Science and Technology Agency), where he focuses on IoT firmware analysis, device emulation, and offensive security research. His work spans building automated pipelines for firmware emulation, security testbed development, and honeypot deployment for threat intelligence collection against embedded systems. Zeus has presented IoT security research at DEFCON events globally and Milipol TechX Singapore, and has supported community initiatives including the HTX Public Safety Village at DEFCON Singapore. He holds experience in red team operations supporting critical national infrastructure across the finance and healthcare sectors.

\n\nSpeakerBio:  Kenneth \"kenleejl\" Lee
\n

Cyber security enjoyer

\n\n\nLinks:
    GitHub - https://github.com/kenleejl/xEndity
\n\'',NULL,1293679),('3_Saturday','16','16:00','16:45','N','Demo Labs','LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)','\'xEndity: IoT Firmware Analysis & Digital Twin Platform\'','\'Zeus \"LightningGod\" Chan,Kenneth \"kenleejl\" Lee\'','Demo Labs_d207f34edcce8c9d3c26191b6f85fdd4','\'Title: xEndity: IoT Firmware Analysis & Digital Twin Platform
\nTags: DEF CON Demo Labs | Intermediate | Defense/Blue Team | Hardware/IoT | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs
\nWhen: Saturday, Aug 8, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - Map
\n
\nDescription:
\n

IoT devices are embedded in critical infrastructure globally, yet security teams face a fundamental constraint: you cannot aggressively test what you cannot safely replicate. Physical hardware is expensive, limited in supply, and testing against production systems is off-limits. This leaves defenders operating blind against an expanding attack surface of billions of connected devices.

\n\n

xEndity is an open-source, end-to-end IoT firmware emulation platform that transforms raw firmware binaries into fully functional, network-ready virtual device instances, no physical hardware required. It provides an automated pipeline spanning firmware acquisition, binary analysis, filesystem extraction, emulation packaging, and orchestrated deployment of emulated device networks at scale.

\n\n

The platform enables two high-impact use cases: first, as a scopeless penetration testing range where red teams and researchers can conduct unrestricted vulnerability validation, exploit development, and attack simulation against realistic IoT environments. Second, as a deceptive defense layer where emulated devices are deployed as high-interaction honeypots to capture adversary tradecraft, collect OS-level and network telemetry, and generate actionable threat intelligence.

\n\nSpeakers:Zeus \"LightningGod\" Chan,Kenneth \"kenleejl\" Lee
\n
\nSpeakerBio:  Zeus \"LightningGod\" Chan
\n

Zeus Chan is a security researcher on the Adversary Emulation Team at HTX (Home Team Science and Technology Agency), where he focuses on IoT firmware analysis, device emulation, and offensive security research. His work spans building automated pipelines for firmware emulation, security testbed development, and honeypot deployment for threat intelligence collection against embedded systems. Zeus has presented IoT security research at DEFCON events globally and Milipol TechX Singapore, and has supported community initiatives including the HTX Public Safety Village at DEFCON Singapore. He holds experience in red team operations supporting critical national infrastructure across the finance and healthcare sectors.

\n\nSpeakerBio:  Kenneth \"kenleejl\" Lee
\n

Cyber security enjoyer

\n\n\nLinks:
    GitHub - https://github.com/kenleejl/xEndity
\n\'',NULL,1293680),('3_Saturday','20','20:00','21:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4)','\'Hacker Jeopardy\'','\'\'','Social Gatherings/Events_810541ff6aaca2524c376022ebe99a2b','\'Title: Hacker Jeopardy
\nTags: Event | Hacker Jeopardy!
\nWhen: Saturday, Aug 8, 20:00 - 21:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293681),('3_Saturday','21','20:00','21:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4)','\'Hacker Jeopardy\'','\'\'','Social Gatherings/Events_810541ff6aaca2524c376022ebe99a2b','\'\'',NULL,1293682),('2_Friday','20','20:00','21:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4)','\'Hacker Jeopardy\'','\'\'','Social Gatherings/Events_d96f225f1c40dab8b49550e8f06bca92','\'Title: Hacker Jeopardy
\nTags: Event | Hacker Jeopardy!
\nWhen: Friday, Aug 7, 20:00 - 21:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293683),('2_Friday','21','20:00','21:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4)','\'Hacker Jeopardy\'','\'\'','Social Gatherings/Events_d96f225f1c40dab8b49550e8f06bca92','\'\'',NULL,1293684),('2_Friday','18','18:30','20:30','N','Social Gatherings/Events','LVCCW Level 2 W210-211 (Policy Village)','\'Policy Mixer Happy Hour\'','\'\'','Social Gatherings/Events_8891279cd82f3e5b6b59756951269a3f','\'Title: Policy Mixer Happy Hour
\nTags: Party | Policy @ DEF CON
\nWhen: Friday, Aug 7, 18:30 - 20:30 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293685),('2_Friday','19','18:30','20:30','Y','Social Gatherings/Events','LVCCW Level 2 W210-211 (Policy Village)','\'Policy Mixer Happy Hour\'','\'\'','Social Gatherings/Events_8891279cd82f3e5b6b59756951269a3f','\'\'',NULL,1293686),('2_Friday','20','18:30','20:30','Y','Social Gatherings/Events','LVCCW Level 2 W210-211 (Policy Village)','\'Policy Mixer Happy Hour\'','\'\'','Social Gatherings/Events_8891279cd82f3e5b6b59756951269a3f','\'\'',NULL,1293687),('2_Friday','10','10:00','12:59','N','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Aw, man…pages!\'','\'\'','Contests_3c4b95b69c1c2f385a5f154b649808eb','\'Title: Aw, man…pages!
\nTags: Aw, man...pages! | Contest
\nWhen: Friday, Aug 7, 10:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map
\n
\nDescription:
\n

How well do you know your man pages? Find out by teaming up with up to 3 other people (or come solo and get matched up with some new friends) and play \"Aw, man...pages!\". Across several rounds, your knowledge of man pages and software will be tested to the limit. Can you remember what command line flag is being described by its help text? Can you identify a tool just from a man page snippet? Can you decipher our cryptic command clues? Will you prove yourself worthy to be crowned the man page champion?

\n\n

Participant Prerequisites

\n\n

None. We will provide answer sheets and pens. Participants can form teams of up to 4 people beforehand, or at the event.

\n\n\'',NULL,1293688),('2_Friday','11','10:00','12:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Aw, man…pages!\'','\'\'','Contests_3c4b95b69c1c2f385a5f154b649808eb','\'\'',NULL,1293689),('2_Friday','12','10:00','12:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Aw, man…pages!\'','\'\'','Contests_3c4b95b69c1c2f385a5f154b649808eb','\'\'',NULL,1293690),('2_Friday','13','13:00','14:59','N','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'DEF CON Beard and Mustache Contest\'','\'\'','Contests_c3813c874af4e227aadac03ed8b54d0e','\'Title: DEF CON Beard and Mustache Contest
\nTags: DEF CON Beard and Mustache Contest | Contest
\nWhen: Friday, Aug 7, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map
\n
\nDescription:
\n

The DC Beard and Mustache Contest has been held every year since DEF CON 19 in 2011 (R.I.P. Riviera), (Except during that COVID thing - but we are not going to talk about that COVID thing), the DEF CON Beard and Mustache Contest highlights the intersection of facial hair and hacker culture.

\n\n

Participant Prerequisites

\n\n

For 2025 offering 4 categories for the competition - You may only enter one category.

\n\n

This is an in-person contest - you must be present to participate.

\n\n

Full beard: Self-explanatory, for the truly bearded.

\n\n

Partial Beard: For those sporting Van Dykes, Goatees, Mutton Chops, and other partial beard styles.

\n\n

Mustache only: Judging on the mustache only, even if bearded. Bring your Handlebars, Fu Manchus, or whatever adorns your upper lip.

\n\n

Freestyle: Anything goes, including fake and creatively adorned beards. Creative women often do well in the Freestyle category.

\n\n

Timing

\n\n

Setup begins 1 hour before the event, on the Contest Stage.

\n\n\'',NULL,1293691),('2_Friday','14','13:00','14:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'DEF CON Beard and Mustache Contest\'','\'\'','Contests_c3813c874af4e227aadac03ed8b54d0e','\'\'',NULL,1293692),('2_Friday','16','16:00','17:59','N','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Um, ACKtually\'','\'\'','Contests_41230fab9265f945d4f8929a9c3f29c9','\'Title: Um, ACKtually
\nTags: Um, ACKtually | Contest
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map
\n
\nDescription:
\n

Um, ACKtually is returning for it\'s 2nd year at DEF CON 34! If you\'ve ever seen the popular Dropout TV game-show \"Um, Actually\", then you know exactly who we stole this idea from.

\n\n

Three contestants will compete for the Pedantic Hacker crown, providing corrections for (just barely) incorrect statements given by the hosts about everything from general technology, cyber security, and overall nerd culture. We will chum the waters of the question pool with red herrings and wrong turns while the sharks circle to be the first to answer \"WELL, UM ACKTUALLY...\".

\n\n

Um, ACKtually celebrates everything hacker culture was built on. Community knowledge share, deep subject matter expertise of niche topics, and an almost orgasmic feeling of superiority at correcting someone else\'s mistakes, live and in public.

\n\n\'',NULL,1293693),('2_Friday','17','16:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Um, ACKtually\'','\'\'','Contests_41230fab9265f945d4f8929a9c3f29c9','\'\'',NULL,1293694),('2_Friday','19','19:00','20:59','N','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'AI Art Battle\'','\'\'','Contests_cfcaedf70ce407178d84f45b040b336d','\'Title: AI Art Battle
\nTags: AI Art Battle | Contest
\nWhen: Friday, Aug 7, 19:00 - 20:59 PDT
\nWhere: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map
\n
\nDescription:
\n

This unique competition invites creative minds to dive into the world of artificial intelligence and art. The challenge is to craft the most imaginative prompts for generative AI models to create artwork.

\n\n

Contestants will not be creating the art themselves; instead, they will focus on designing prompts for well-known topics that push the boundaries of creativity and innovation.

\n\n

How It Works:

\n\n

Select a Topic:

\n\n

Contestants will choose from a list of random topics.

\n\n

These could range from historical events and famous literary works to mythical creatures, futuristic landscapes, and iconic pop culture references.

\n\n

Craft a Prompt:

\n\n

Using their creativity, contestants will write a detailed prompt designed to guide AI models in generating original artwork. The prompts should be clear, imaginative, and offer enough detail to spark the AI\'s artistic capabilities.

\n\n

Submission:

\n\n

Each contestant will submit their prompt and the intended outcome.

\n\n

AI Generation:

\n\n

The submitted prompts will be fed into a generative AI art model, which will generate corresponding artworks.

\n\n

A random panel will determine who the winners are.

\n\n\'',NULL,1293695),('2_Friday','20','19:00','20:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'AI Art Battle\'','\'\'','Contests_cfcaedf70ce407178d84f45b040b336d','\'\'',NULL,1293696),('2_Friday','22','22:00','23:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Whose Slide Is It Anyway?\'','\'\'','Social Gatherings/Events_a21cb107d6e0b658ae19a91487cbd7cf','\'Title: Whose Slide Is It Anyway?
\nTags: Event | Whose Slide Is It Anyway?
\nWhen: Friday, Aug 7, 22:00 - 23:59 PDT
\nWhere: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map
\n
\nDescription:
\n

DEF CON 34 marks an entire DECADE of “Whose Slide Is It Anyway?”” being the unholy union of improv comedy, hacking, and slide deck sado-masochism. We are the embodiment of the hacker battle cry \"\"FUCK IT, WE\'LL DO IT IN PROD.\"\"

\n\n

For the last 10 years, our team of slide monkeys have created a stupid amount of short slide decks on whatever nonsense tickles our fancies. Slides are not exclusive to technology, they can and will be about anything. Contestants will take the stage and choose a random number corresponding to a specific slide deck. They will then improvise a minimum 5 minute / maximum 10 minute lightning talk, becoming instant subject matter experts on whatever topic/stream of consciousness appears on the screen.

\n\n

But....why?

\n\n

Because for us, the stage is hallowed ground and since stupidity can\'t be stopped, we decided to weaponize it. Whether you delight in the chaos of watching your fellow hackers squirm or would like to sacrifice yourself to the Contest Gods, it’s a night of schadenfreude for the whole family.

\n\n\'',NULL,1293697),('2_Friday','23','22:00','23:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Whose Slide Is It Anyway?\'','\'\'','Social Gatherings/Events_a21cb107d6e0b658ae19a91487cbd7cf','\'\'',NULL,1293698),('2_Friday','13','13:00','14:59','N','Contests','LVCCW Level 3 W327 (Misc Meeting Room)','\'Pub Quiz at DEF CON\'','\'\'','Contests_92130546171324d36f54c929475bee53','\'Title: Pub Quiz at DEF CON
\nTags: Pub Quiz at DEF CON | Contest
\nWhen: Friday, Aug 7, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 3 W327 (Misc Meeting Room) - Map
\n
\nDescription:
\n

We’re back with another Pub Quiz at DEF CON! After 4 very successful years hosting this event, we’ve made some improvements to make it even better. So… do you like pub quizzes? If so, get your butts over and join us for the 5th Pub Quiz at DEF CON 34.

\n\n

The quiz will consist of 7 rounds, covering topics like ’90s/2000s TV and movies, DEF CON trivia, music, cartoons, and yes, a little bit of sex. The theme is all the things that make DEF CON attendees exceptional, so there will truly be something for everyone. Expect a mix of visual rounds, audio rounds, and classic con questions. We need to keep you peeps stimulated.

\n\n

This is a social event, so we encourage teams of 5–6 people. You never know… you might even meet the love of your life.

\n\n

Did we mention CASH? That’s right; cold, hard cash prizes for 1st, 2nd, and 3rd place teams. And as always, if there’s a tie, we’ll break it with a good old-fashioned dance-off, judged by the hosts and a few trusted goons.

\n\n

Come for the trivia. Stay for the chaos.

\n\n\'',NULL,1293699),('2_Friday','14','13:00','14:59','Y','Contests','LVCCW Level 3 W327 (Misc Meeting Room)','\'Pub Quiz at DEF CON\'','\'\'','Contests_92130546171324d36f54c929475bee53','\'\'',NULL,1293700),('3_Saturday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Hack3r Runw@y v8.0\'','\'\'','Contests_a043e99458e9bb979869c7910eccbfee','\'Title: Hack3r Runw@y v8.0
\nTags: Hack3r Runw@y v8.0 | Contest
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map
\n
\nDescription:
\n

Hack3r Runw@y v8.0

\n\n

Where Code Meets Catwalk @ DEF CON 34

\n\n

The Hack3r Runw@y returns for its 8th evolution! After nearly a decade of bridging the gap between hardware and haberdashery, we’re back at DEF CON 34 to prove once again that hackers are the most creative engineers on the planet.

\n\n

Whether you’re a glamorous geek, a crafty coder, or a fashionably functional phantom, it’s time to weaponize your wardrobe. We’re challenging you to dismantle the boundary between \"security\" and \"style.\" If you can hack it, you can wear it.

\n\n

The Mission Categories\n- Smart-Wear (Active Tech): The high-voltage category. Integrate microcontrollers, sensors, and live telemetry into your designs. We want to see hardware that reacts to the environment—or the wearer—in real-time.\n- Digital Dazzle (Passive Tech): Bling with a brain. Focus on LEDs, fiber optics, and glow-tech that remains passive but high-impact. Light up the room without needing a CLI.\n- Functional Fashion (Tactical): Gear for the field. Think \"Cyber-Chic Pentester\": lockpick jewelry, shim-integrated accessories, signal-blocking fabrics, or high-fashion physical security tools.\n- Extraordinary Style (Creative Ops): The \"Kitbash\" category. Elevate the everyday with 3D textures, optical illusions, security-inspired patterns, and deep-cut cosplay.

\n\n

THE PEOPLE\'S CHOICE Trophy: One coveted trophy is up for grabs where ANYONE can win. But be warned: in true DEF CON fashion, there will be a twist. Follow the social media for updates.

\n\n
    \n
  • The Maker’s Mandate
  • \n
  • This is a pure DIY challenge. We value the \"Proof of Concept\" over the \"Price Tag.\"
  • \n
  • Originality is King: Items must be handmade or heavily modified (\"kitbashed\") by the entrant.
  • \n
  • No \"Off-the-Shelf\": Integrating components (like an Arduino or LED strip) is encouraged; buying a pre-finished \"light-up dress\" from a mass-retailer is an automatic DQ.
  • \n
  • Show Your Work: Documentation is required. Have photos, videos, or a build-log ready to prove your process if the judges need to verify your \"hacker\'s trail.\"
  • \n
\n\n

The Judging Criteria

\n\n

Our panel will be scoring builds based on:\n- Technical Mastery: Execution of hardware/software.\n- Couture Craftsmanship: Quality of the \"fit\" and finish.\n- Relevance: How it speaks to hacker culture or security.\n- Originality: Creative use of materials and \"kitbashing.\"

\n\n

Participant Prerequisites

\n\n

Originality: Items must be handmade by the entrant.

\n\n

Verification: Documentation (photos/video) of the build process is required to verify authenticity.

\n\n

Modification vs. Acquisition: We celebrate the \"kitbash.\" Using pre-made components to create something new is allowed, but \"off-the-shelf\" or \"plug-and-play\" retail items are not permitted.

\n\n\'',NULL,1293701),('3_Saturday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Hack3r Runw@y v8.0\'','\'\'','Contests_a043e99458e9bb979869c7910eccbfee','\'\'',NULL,1293702),('3_Saturday','13','13:00','14:59','N','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Crash and Compile - Stage Competition\'','\'\'','Contests_d3f16f12bbe2bf7378e909537c520a0f','\'Title: Crash and Compile - Stage Competition
\nTags: Crash and Compile | Contest
\nWhen: Saturday, Aug 8, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map
\n
\nDescription:
\n

What happens when you take an ACM style programming contest, smash it head long into a drinking game, throw in a mix of our most distracting helpers, then shove the resulting chaos on stage in front of an audience? You get the contest known as Crash and Compile.

\n\n

Teams are given programming challenges and have to solve them with code. If your code fails to compile? Take a drink. Segfault? Take a drink. Did your code fail to produce the correct answer when you ran it? Take a drink. ChatGPT wrote your code? First of all shame. Secondly take a drink.

\n\n

We set you against the clock and the other teams. And because our \"Team Distraction\" think watching people simply code is boring, they have taken it upon themselves to be creative in hindering you from programming, much to the enjoyment of the audience. At the end of the night, one team will have proven their ability, and walk away with the coveted Crash and Compile trophy.

\n\n

Crash and Compile is looking for the top programmers to test their skills in our contest. Can you complete our challenges? Can you do so with style that sets your team ahead of the others? To play our game you must first complete our qualifying round. Gather your team and see if you have the coding chops to secure your place as one of the top teams to move on to the main contest.

\n\n

Qualifications for Crash and Compile will take place Friday starting at 10:00 and run till 18:00, both in the contest area and online at https://crashandcompile.org

\n\n

You may have up to two people per team. Individuals can compete, but having two people on a team is highly suggested.

\n\n

Of the qualifiers, ten teams will move on to compete head to head on the contest stage on Saturday.

\n\n

Participant Prerequisites

\n\n

As this contest involves the drinking of alcohol (beer), all contestants must be 21 years of age or older. Yes we will check. While we don\'t limit what development environment or programming language you chose to use, as we used a PDP11/23 when we competed, the team must have at least one computer that can connect to our contest network via wired ethernet for the main contest.

\n\n

Pre-Qualification

\n\n

Qualifiers run on Friday from 10:00 to 18:00. We will be located in the contest area, and the problems can be accessed via our site at https://crashandcompile.org

\n\n\'',NULL,1293703),('3_Saturday','14','13:00','14:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Crash and Compile - Stage Competition\'','\'\'','Contests_d3f16f12bbe2bf7378e909537c520a0f','\'\'',NULL,1293704),('3_Saturday','22','22:00','23:59','N','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Feet Feud (Hacker Family Feud)\'','\'\'','Contests_2d95532986806a2520ddf466f5cca45f','\'Title: Feet Feud (Hacker Family Feud)
\nTags: Feet Feud (Hacker Family Feud) | Contest
\nWhen: Saturday, Aug 8, 22:00 - 23:59 PDT
\nWhere: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map
\n
\nDescription:
\n

Feet Feud (Hacker Family Feud) is a Cybersecurity-themed Family Feud style game arranged by members of the OnlyFeet CTF team and hosted by Toeb3rius (aka Tib3rius). Both survey questions and their answers are crowd-sourced from the Cybersecurity community. Two teams (Left Foot and Right Foot) captained by Ali Diamond and John Hammond and comprised of audience members go head to head, trying to figure out the top answers to the survey questions.

\n\n

Attendees can either watch the game or volunteer to play on one of the two teams. Audience participation is also encouraged if either of the two teams fails to get every answer of a survey question.

\n\n

Ultimately Feet Feud is about having a laugh, watching people in the industry attempt to figure out what randomly surveyed people from the Cybersecurity community put as answers to a number of security / tech related questions.

\n\n

Participant Prerequisites

\n\n

Participants are chosen by team captains from the audience at the start of the show. In order to be fair, we try to select participants from all seating areas, so folks who show up later than others still have a chance to volunteer.

\n\n\'',NULL,1293705),('3_Saturday','23','22:00','23:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'Feet Feud (Hacker Family Feud)\'','\'\'','Contests_2d95532986806a2520ddf466f5cca45f','\'\'',NULL,1293706),('3_Saturday','18','18:00','20:59','N','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'EFF Tech Trivia\'','\'\'','Contests_f2d878bdaa272f8cf211ef839cce8f15','\'Title: EFF Tech Trivia
\nTags: EFF Tech Trivia | Contest
\nWhen: Saturday, Aug 8, 18:00 - 20:59 PDT
\nWhere: LVCCW Level 1 Hall 1 100 (Contest Stage) - Map
\n
\nDescription:
\n

EFF\'s privacy and security experts have crafted a new trivia challenge for DEF CON 34! Compete as a team in our no-holds-barred showdown to prove mastery over the obscure facts of digital security, online rights, and internet culture.

\n\n

The First Place team wins a set of custom Cybertiger Champion Badges and EFF swag. Second and third place teams will also win Badges and EFF gear.

\n\n

Invite your friends OR show up and make new friends! Did someone say BRIBES?The world is unfair! You too could influence the judges to add a point or two to your team\'s tally. Overall Bribe winner also wins a custom badge! Test your knowledge of all things tech and support EFF, too.

\n\n

Participant Prerequisites

\n\n

No phones, laptops, or other digital knowledge allowed! Just you, your friends, and a friendly game of trivia.

\n\n\'',NULL,1293707),('3_Saturday','19','18:00','20:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'EFF Tech Trivia\'','\'\'','Contests_f2d878bdaa272f8cf211ef839cce8f15','\'\'',NULL,1293708),('3_Saturday','20','18:00','20:59','Y','Contests','LVCCW Level 1 Hall 1 100 (Contest Stage)','\'EFF Tech Trivia\'','\'\'','Contests_f2d878bdaa272f8cf211ef839cce8f15','\'\'',NULL,1293709),('4_Sunday','12','12:00','12:59','N','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 DDoS CTF Winner Announcements\'','\'\'','Contests_2329fa33aaf92c8334220e73ffd87dd2','\'Title: PWN UR H0M3 DDoS CTF Winner Announcements
\nTags: DDoS Contest | Contest
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 307 (DDoS Contest) - Map
\n
\nDescription:
\n

PWN UR H0M3 DDoS CTF winners announced and prizes handed out.

\n\n\'',NULL,1293710),('3_Saturday','12','12:00','15:59','N','Contests','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'Global OSINT Search Party CTF – DEF CON 34 Edition\'','\'\'','Contests_e255654797e9b17d43667bd8b4e955c7','\'Title: Global OSINT Search Party CTF – DEF CON 34 Edition
\nTags: OSINT For Good Community | Contest
\nWhen: Saturday, Aug 8, 12:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

The Trace Labs Global OSINT Search Party CTF is a non-theoretical CTF where teams of up to 4 people use their OSINT skills to look for actual missing people. For DEF CON 34, we will be working directly with Las Vegas Metro PD to source local missing person cases they have requested the public’s assistance with. This is a hybrid event, open to participants of all skill levels, from anywhere in the world. Prizes will be awarded for 1st, 2nd, and 3rd places, as well as for Most Valuable OSINT. Participants at DEF CON can pickup their free event ticket by stopping by the OSINT4Good Community anytime prior to the event start. Global participants can get a ticket by going to https://www.tracelabs.org/tickets. Bring a laptop and some snacks and get ready to use OSINT4Good!

\n\nLinks:
    Virtual Registration - https://www.tracelabs.org/tickets
\n    Website - https://www.tracelabs.org/searchparty
\n\'',NULL,1293711),('3_Saturday','13','12:00','15:59','Y','Contests','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'Global OSINT Search Party CTF – DEF CON 34 Edition\'','\'\'','Contests_e255654797e9b17d43667bd8b4e955c7','\'\'',NULL,1293712),('3_Saturday','14','12:00','15:59','Y','Contests','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'Global OSINT Search Party CTF – DEF CON 34 Edition\'','\'\'','Contests_e255654797e9b17d43667bd8b4e955c7','\'\'',NULL,1293713),('3_Saturday','15','12:00','15:59','Y','Contests','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'Global OSINT Search Party CTF – DEF CON 34 Edition\'','\'\'','Contests_e255654797e9b17d43667bd8b4e955c7','\'\'',NULL,1293714),('2_Friday','19','19:00','21:59','N','Social Gatherings/Events','Sahara Hotel Azul Ultra Pool','\'The KEVOPS Sellout Pool Party II: Sponsored by Zyn\'','\'\'','Social Gatherings/Events_ae311701446c4182eac82a5a7534af87','\'Title: The KEVOPS Sellout Pool Party II: Sponsored by Zyn
\nTags: Party
\nWhen: Friday, Aug 7, 19:00 - 21:59 PDT
\nWhere: Sahara Hotel Azul Ultra Pool - Map
\n
\nDescription:
\n

The Sellout Pool Party is back. Join us for tacos and music!

\n\n\'',NULL,1293715),('2_Friday','20','19:00','21:59','Y','Social Gatherings/Events','Sahara Hotel Azul Ultra Pool','\'The KEVOPS Sellout Pool Party II: Sponsored by Zyn\'','\'\'','Social Gatherings/Events_ae311701446c4182eac82a5a7534af87','\'\'',NULL,1293716),('2_Friday','21','19:00','21:59','Y','Social Gatherings/Events','Sahara Hotel Azul Ultra Pool','\'The KEVOPS Sellout Pool Party II: Sponsored by Zyn\'','\'\'','Social Gatherings/Events_ae311701446c4182eac82a5a7534af87','\'\'',NULL,1293717),('1_Thursday','18','18:30','23:30','N','Social Gatherings/Events','The Industrial','\'Welcome Party at The Industrial\'','\'\'','Social Gatherings/Events_8cd9845f574f32ffb42a9cc27de253f3','\'Title: Welcome Party at The Industrial
\nTags: Party
\nWhen: Thursday, Aug 6, 18:30 - 23:30 PDT
\nWhere: The Industrial
\n
\nDescription:
\n

Kick off DEF CON at our official Welcome Party! We\'ll meet at The Industrial at 18:30.

\n\n

Shuttles from LVCC to The Industrial will be available in the bus pickup \"sawtooth\", in the Diamond lot. Use the southwestern doors near W101 / Human Registration.

\n\n

This event is not age-restricted; all ages are welcome.

\n\n\'',NULL,1293718),('1_Thursday','19','18:30','23:30','Y','Social Gatherings/Events','The Industrial','\'Welcome Party at The Industrial\'','\'\'','Social Gatherings/Events_8cd9845f574f32ffb42a9cc27de253f3','\'\'',NULL,1293719),('1_Thursday','20','18:30','23:30','Y','Social Gatherings/Events','The Industrial','\'Welcome Party at The Industrial\'','\'\'','Social Gatherings/Events_8cd9845f574f32ffb42a9cc27de253f3','\'\'',NULL,1293720),('1_Thursday','21','18:30','23:30','Y','Social Gatherings/Events','The Industrial','\'Welcome Party at The Industrial\'','\'\'','Social Gatherings/Events_8cd9845f574f32ffb42a9cc27de253f3','\'\'',NULL,1293721),('1_Thursday','22','18:30','23:30','Y','Social Gatherings/Events','The Industrial','\'Welcome Party at The Industrial\'','\'\'','Social Gatherings/Events_8cd9845f574f32ffb42a9cc27de253f3','\'\'',NULL,1293722),('1_Thursday','23','18:30','23:30','Y','Social Gatherings/Events','The Industrial','\'Welcome Party at The Industrial\'','\'\'','Social Gatherings/Events_8cd9845f574f32ffb42a9cc27de253f3','\'\'',NULL,1293723),('4_Sunday','22','22:30','01:59','N','Social Gatherings/Events','LIV Nightclub at Fontainebleau','\'DEF CON After party @ LIV Fontainebleau\'','\'\'','Social Gatherings/Events_6494c2c40732d58dafa38c38043542fa','\'Title: DEF CON After party @ LIV Fontainebleau
\nTags: Party
\nWhen: Sunday, Aug 9, 22:30 - 01:59 PDT
\nWhere: LIV Nightclub at Fontainebleau
\n
\nDescription:
\n

Close out DEF CON at LIV Fontainebleau. Bring your DEF CON badge for free admission and a free drink.

\n\n\'',NULL,1293724),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_5dfe2d7ae1a487971317481b264df5e8','\'Title: PWN UR H0M3 - DDoS CTF
\nTags: DDoS Contest | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 307 (DDoS Contest) - Map
\n
\nDescription:
\n

A chaotic DDoS-themed CTF where sketchy devices, busted services, weird signals, and sneaky clues are begging to be owned. Scan the network, break IoT devices, decode the nonsense, and prove you can pwn your home before your home pwns you. This CTF is designed to help you learn about the cutting edge in DDoS attacks and defense. We also have an IoT lab of devices hacked and infected with botnet malware that you can play around with. Beginners welcome. We have some fabulous prizes including gift cards donated from Hak5 so please check it out!

\n\n\'',NULL,1293725),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_5dfe2d7ae1a487971317481b264df5e8','\'\'',NULL,1293726),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_5dfe2d7ae1a487971317481b264df5e8','\'\'',NULL,1293727),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_5dfe2d7ae1a487971317481b264df5e8','\'\'',NULL,1293728),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_5dfe2d7ae1a487971317481b264df5e8','\'\'',NULL,1293729),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_5dfe2d7ae1a487971317481b264df5e8','\'\'',NULL,1293730),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_5dfe2d7ae1a487971317481b264df5e8','\'\'',NULL,1293731),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_5dfe2d7ae1a487971317481b264df5e8','\'\'',NULL,1293732),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_e4fbebef2cb43f103ca085aa01161db1','\'Title: PWN UR H0M3 - DDoS CTF
\nTags: DDoS Contest | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 307 (DDoS Contest) - Map
\n
\nDescription:
\n

A chaotic DDoS-themed CTF where sketchy devices, busted services, weird signals, and sneaky clues are begging to be owned. Scan the network, break IoT devices, decode the nonsense, and prove you can pwn your home before your home pwns you. This CTF is designed to help you learn about the cutting edge in DDoS attacks and defense. We also have an IoT lab of devices hacked and infected with botnet malware that you can play around with. Beginners welcome. We have some fabulous prizes including gift cards donated from Hak5 so please check it out!

\n\n\'',NULL,1293733),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_e4fbebef2cb43f103ca085aa01161db1','\'\'',NULL,1293734),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_8333e71137a1a5d62d35a759ed6cece4','\'Title: PWN UR H0M3 - DDoS CTF
\nTags: DDoS Contest | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 307 (DDoS Contest) - Map
\n
\nDescription:
\n

A chaotic DDoS-themed CTF where sketchy devices, busted services, weird signals, and sneaky clues are begging to be owned. Scan the network, break IoT devices, decode the nonsense, and prove you can pwn your home before your home pwns you. This CTF is designed to help you learn about the cutting edge in DDoS attacks and defense. We also have an IoT lab of devices hacked and infected with botnet malware that you can play around with. Beginners welcome. We have some fabulous prizes including gift cards donated from Hak5 so please check it out!

\n\n\'',NULL,1293735),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_8333e71137a1a5d62d35a759ed6cece4','\'\'',NULL,1293736),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_8333e71137a1a5d62d35a759ed6cece4','\'\'',NULL,1293737),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_8333e71137a1a5d62d35a759ed6cece4','\'\'',NULL,1293738),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_8333e71137a1a5d62d35a759ed6cece4','\'\'',NULL,1293739),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_8333e71137a1a5d62d35a759ed6cece4','\'\'',NULL,1293740),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_8333e71137a1a5d62d35a759ed6cece4','\'\'',NULL,1293741),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 307 (DDoS Contest)','\'PWN UR H0M3 - DDoS CTF\'','\'\'','Contests_8333e71137a1a5d62d35a759ed6cece4','\'\'',NULL,1293742),('3_Saturday','16','16:00','16:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Thomas Wilhelm\'','\'Thomas Wilhelm\'','Social Gatherings/Events_3fdfcb2d50f5418ecf7f39bf5f06e563','\'Title: Book Signing - Thomas Wilhelm
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Thomas Wilhelm
\nAuthor:
\n\n

Professional Penetration Testing: Creating and Learning in a Hacking Lab (3rd Edition)

\n\n

The Basics of Hacking and Penetration Testing (3rd Edition)

\n\n\n\'',NULL,1293743),('2_Friday','15','15:00','16:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Avinash Majeti\'','\'Avinash Majeti\'','Social Gatherings/Events_ad02f860d6a37d6811c40082ac5775b8','\'Title: Book Signing - Avinash Majeti
\nTags: Vendor Book Signing
\nWhen: Friday, Aug 7, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Avinash Majeti
\nAuthor:
\n\n

Cybersecurity: Right Access at the Right Time

\n\n\n\'',NULL,1293744),('2_Friday','16','15:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Avinash Majeti\'','\'Avinash Majeti\'','Social Gatherings/Events_ad02f860d6a37d6811c40082ac5775b8','\'\'',NULL,1293745),('3_Saturday','16','16:00','16:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Avinash Majeti\'','\'Avinash Majeti\'','Social Gatherings/Events_92482fb3c56ef7c7052c2d2ba2a065cc','\'Title: Book Signing - Avinash Majeti
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Avinash Majeti
\nAuthor:
\n\n

Cybersecurity: Right Access at the Right Time

\n\n\n\'',NULL,1293746),('2_Friday','16','16:00','16:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Avinash Majeti\'','\'Avinash Majeti\'','Social Gatherings/Events_428f2a2843273ec24a7cb5d108624539','\'Title: Book Signing - Avinash Majeti
\nTags: Vendor Book Signing
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Avinash Majeti
\nAuthor:
\n\n

Cybersecurity: Right Access at the Right Time

\n\n\n\'',NULL,1293747),('3_Saturday','15','15:00','15:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Mark Foudy\'','\'Mark Foudy\'','Social Gatherings/Events_6af8a312a5ab2ab146f0663a3e14312c','\'Title: Book Signing - Mark Foudy
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Mark Foudy
\nAuthor:
\n\n

Neurodiverse Hackers: Unconventional Minds Shape Cybersecurity

\n\n\n\'',NULL,1293748),('3_Saturday','14','14:00','14:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Brandy Smith\'','\'Brandy Smith\'','Social Gatherings/Events_5cfdc183eb5891d66334f3fa72c1803d','\'Title: Book Signing - Brandy Smith
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Brandy Smith
\nAuthor:
\n\n

Vegas Hackware, Vol1 self titled and Vegas hackware Vol2 The WonderingRaven\'s Manifesto

\n\n\n\'',NULL,1293749),('2_Friday','13','13:00','13:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Brandy Smith\'','\'Brandy Smith\'','Social Gatherings/Events_1e487dbbc6c0bcaa2532f4e0f3b8538d','\'Title: Book Signing - Brandy Smith
\nTags: Vendor Book Signing
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Brandy Smith
\nAuthor:
\n\n

Vegas Hackware, Vol1 self titled and Vegas hackware Vol2 The WonderingRaven\'s Manifesto

\n\n\n\'',NULL,1293750),('2_Friday','11','11:00','11:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Nicholas DeMeo\'','\'Nicholas DeMeo\'','Social Gatherings/Events_1acffe7974d05a306992c0da707b3ce8','\'Title: Book Signing - Nicholas DeMeo
\nTags: Vendor Book Signing
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Nicholas DeMeo
\nAuthor:
\n\n

Cyber Defense: The Art of Forging a Sentinel

\n\n\n\'',NULL,1293751),('2_Friday','14','14:00','15:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Laura Scherling\'','\'Laura Scherling\'','Social Gatherings/Events_076e38309f067ab9b7a60737aeadefa6','\'Title: Book Signing - Laura Scherling
\nTags: Vendor Book Signing
\nWhen: Friday, Aug 7, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Laura Scherling
\nThe Future of Hacking: The Rise of Cybercrime and the Fight to Keep Us Safe (July 2025, Hardback Launch; July 2026, Audio Book Launch)
\n\n\n\n\n\'',NULL,1293752),('2_Friday','15','14:00','15:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Laura Scherling\'','\'Laura Scherling\'','Social Gatherings/Events_076e38309f067ab9b7a60737aeadefa6','\'\'',NULL,1293753),('3_Saturday','12','12:00','12:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Laura Scherling\'','\'Laura Scherling\'','Social Gatherings/Events_c372dc165ed4272c62af367bdf6717ae','\'Title: Book Signing - Laura Scherling
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Laura Scherling
\nThe Future of Hacking: The Rise of Cybercrime and the Fight to Keep Us Safe (July 2025, Hardback Launch; July 2026, Audio Book Launch)
\n\n\n\n\n\'',NULL,1293754),('3_Saturday','10','10:00','11:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Aamiruddin Syed\'','\'Aamiruddin Syed\'','Social Gatherings/Events_d2ac9d3d991fc2f777b597cf9b7e07e8','\'Title: Book Signing - Aamiruddin Syed
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Aamiruddin Syed
\n

Aamiruddin Syed is a Cybersecurity Professional with over a decade of experience specializing in DevSecOps, Shift-Left Security, Cloud Security, and Internal Penetration Testing. He is the OWASP Agentic AI Supply Chain Project Co-Lead and active contributor to the CSA Agentic AI initiative.

\n\n

He authored Supply Chain Software Security – AI, IoT, Application Security (Apress/Springer) and has deep expertise in automating security in CI/CD pipelines, infrastructure as code, and cloud hardening. He routinely conducts internal security assessments of critical systems and is known for bridging the gap between security and engineering teams to embed security directly into products.

\n\n

As recognized advocate for secure development, he is a frequent speaker , delivered workshops and chair sessions at leading industry conferences including RSA Conference, DEFCON, and Black Hat.

\n\n

--

\n\n

Author:

\n\n
    \n
  1. Fault Detection in Microservice Architectures: Integrating Software Fault Prediction with DevSecOps
  2. \n
  3. Supply Chain Software Security: AI, IoT, and Application Security
  4. \n
\n\n\n\'',NULL,1293755),('3_Saturday','11','10:00','11:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Aamiruddin Syed\'','\'Aamiruddin Syed\'','Social Gatherings/Events_d2ac9d3d991fc2f777b597cf9b7e07e8','\'\'',NULL,1293756),('3_Saturday','13','13:00','13:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Christopher DeCarmen\'','\'Christopher DeCarmen\'','Social Gatherings/Events_f741da6b7ff8b21c297bc463e774b9d4','\'Title: Book Signing - Christopher DeCarmen
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Christopher DeCarmen
\nAuthor:
\n\n

The Cyber Calendar 2027, Y2K27 Edition

\n\n\n\'',NULL,1293757),('2_Friday','11','11:00','11:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Christopher DeCarmen\'','\'Christopher DeCarmen\'','Social Gatherings/Events_545f51081b30999b2e5b4e6252e61d3e','\'Title: Book Signing - Christopher DeCarmen
\nTags: Vendor Book Signing
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Christopher DeCarmen
\nAuthor:
\n\n

The Cyber Calendar 2027, Y2K27 Edition

\n\n\n\'',NULL,1293758),('3_Saturday','14','14:00','14:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Garrett Gee\'','\'Garrett Gee\'','Social Gatherings/Events_0f10383ce70a31ef13b6529c9c368410','\'Title: Book Signing - Garrett Gee
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Garrett Gee
\nAuthor:
\n\n

The Hacker Mindset

\n\n\n\'',NULL,1293759),('2_Friday','14','14:00','14:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Garrett Gee\'','\'Garrett Gee\'','Social Gatherings/Events_ec8c2112a0d374837bc6f1c8b8c3972f','\'Title: Book Signing - Garrett Gee
\nTags: Vendor Book Signing
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Garrett Gee
\nAuthor:
\n\n

The Hacker Mindset

\n\n\n\'',NULL,1293760),('3_Saturday','13','13:00','13:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Cindy Cohn\'','\'Cindy Cohn\'','Social Gatherings/Events_0dd93a21e05fae7a70881673ccbb8f29','\'Title: Book Signing - Cindy Cohn
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation
\n

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy\'s Defender published by MIT Press in March, 2026. She is also the co-host of EFF\'s award-winning podcast, How to Fix the Internet.

\n\n

--

\n\n

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.

\n\n\n\'',NULL,1293761),('3_Saturday','11','11:00','11:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2','\'Book Signing - Cindy Cohn\'','\'Cindy Cohn\'','Social Gatherings/Events_c0e0066bf493c856a828f74ae11fd3c2','\'Title: Book Signing - Cindy Cohn
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 2 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation
\n

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy\'s Defender published by MIT Press in March, 2026. She is also the co-host of EFF\'s award-winning podcast, How to Fix the Internet.

\n\n

--

\n\n

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.

\n\n\n\'',NULL,1293762),('2_Friday','10','10:00','10:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Opening Ceremony\'','\'\'','Contests_15c28c13b0ad72763a738c8dab3d8337','\'Title: Octopus Game - Opening Ceremony
\nTags: Octopus Game | Contest
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293763),('2_Friday','10','10:00','12:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game Opens and Pre-registration Check-In Available\'','\'\'','Contests_4997a4103af47224f6df2bd0403d9927','\'Title: Octopus Game Opens and Pre-registration Check-In Available
\nTags: Octopus Game | Contest
\nWhen: Friday, Aug 7, 10:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293764),('2_Friday','11','10:00','12:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game Opens and Pre-registration Check-In Available\'','\'\'','Contests_4997a4103af47224f6df2bd0403d9927','\'\'',NULL,1293765),('2_Friday','12','10:00','12:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game Opens and Pre-registration Check-In Available\'','\'\'','Contests_4997a4103af47224f6df2bd0403d9927','\'\'',NULL,1293766),('2_Friday','13','13:00','10:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Walk-In Registration (Pre-Registration Check-In Closed)\'','\'\'','Contests_c9b66815e169b27502ca4f380309ee20','\'Title: Octopus Game - Walk-In Registration (Pre-Registration Check-In Closed)
\nTags: Octopus Game | Contest
\nWhen: Friday, Aug 7, 13:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293767),('3_Saturday','13','13:00','10:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Walk-In Registration (Pre-Registration Check-In Closed)\'','\'\'','Contests_4c7f9ba05bcd53b8934fa7c82f808a8e','\'Title: Octopus Game - Walk-In Registration (Pre-Registration Check-In Closed)
\nTags: Octopus Game | Contest
\nWhen: Saturday, Aug 8, 13:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293768),('2_Friday','13','13:30','14:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Battle #1: The Front Man\'s Wager\'','\'\'','Contests_f7d8ec2d68e2bd8fb3b4913ba523990e','\'Title: Octopus Game - Booth Battle #1: The Front Man\'s Wager
\nTags: Octopus Game | Contest
\nWhen: Friday, Aug 7, 13:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293769),('2_Friday','14','13:30','14:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Battle #1: The Front Man\'s Wager\'','\'\'','Contests_f7d8ec2d68e2bd8fb3b4913ba523990e','\'\'',NULL,1293770),('2_Friday','17','17:00','17:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Battle #2: The Midnight \"Brawl\"\'','\'\'','Contests_e5ecf2605ed394b77b265cf75b91bb07','\'Title: Octopus Game - Booth Battle #2: The Midnight \"Brawl\"
\nTags: Octopus Game | Contest
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293771),('3_Saturday','13','13:00','13:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Battle #3: The Marbles Match\'','\'\'','Contests_ea49432ebe6982ec9d9fa029ea432ce0','\'Title: Octopus Game - Booth Battle #3: The Marbles Match
\nTags: Octopus Game | Contest
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293772),('3_Saturday','17','17:00','17:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - The Final Booth Battle\'','\'\'','Contests_c52ff559fbc7841e53a29dd3dd7eee68','\'Title: Octopus Game - The Final Booth Battle
\nTags: Octopus Game | Contest
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n

Come to the final booth battle!

\n\n

Later, at the Octopus Game Party: ties will be resolved, and winners and prizes will be announced!

\n\n\'',NULL,1293773),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_931a64af767f6ab0e003ae5b14d8c241','\'Title: Octopus Game - Booth Open
\nTags: Octopus Game | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293774),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_931a64af767f6ab0e003ae5b14d8c241','\'\'',NULL,1293775),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_931a64af767f6ab0e003ae5b14d8c241','\'\'',NULL,1293776),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_931a64af767f6ab0e003ae5b14d8c241','\'\'',NULL,1293777),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_931a64af767f6ab0e003ae5b14d8c241','\'\'',NULL,1293778),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_931a64af767f6ab0e003ae5b14d8c241','\'\'',NULL,1293779),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_931a64af767f6ab0e003ae5b14d8c241','\'\'',NULL,1293780),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_931a64af767f6ab0e003ae5b14d8c241','\'\'',NULL,1293781),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_d8a5bdeb3fb7f9200166380e1891d107','\'Title: Octopus Game - Booth Open
\nTags: Octopus Game | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 201 (Octopus Game) - Map
\n
\nDescription:
\n\n\n\'',NULL,1293782),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_d8a5bdeb3fb7f9200166380e1891d107','\'\'',NULL,1293783),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_d8a5bdeb3fb7f9200166380e1891d107','\'\'',NULL,1293784),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_d8a5bdeb3fb7f9200166380e1891d107','\'\'',NULL,1293785),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_d8a5bdeb3fb7f9200166380e1891d107','\'\'',NULL,1293786),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_d8a5bdeb3fb7f9200166380e1891d107','\'\'',NULL,1293787),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_d8a5bdeb3fb7f9200166380e1891d107','\'\'',NULL,1293788),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 201 (Octopus Game)','\'Octopus Game - Booth Open\'','\'\'','Contests_d8a5bdeb3fb7f9200166380e1891d107','\'\'',NULL,1293789),('2_Friday','10','10:00','10:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Breaking the Ethereum Phone: From BootROM to Wallet Signing Keys\'','\'Guanxing Wen\'','DEF CON Talks_99b76045ce742664d19eeab4f7e623b9','\'Title: Breaking the Ethereum Phone: From BootROM to Wallet Signing Keys
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Crypto phones promise the convenience of a mobile OS with hardware-backed key management. We tested that claim on dGEN1, the Ethereum phone marketed for digital-asset custody, and present a full compromise from bootrom to wallet key recovery.

\n\n

Starting from a bootrom-level misconfiguration, we reverse the modern MediaTek bootchain and introduce a Loader-of-the-Loader technique for patching later boot stages entirely in memory, yielding EL3 code execution without modifying physical flash. From that foothold, we trace how boot-level compromise propagates into the device’s lock-screen verification path, enabling offline brute-forcing of the user PIN and recovery of the wallet’s primary ERC-4337 signing key. We further show that a separate identity flaw in the asset-claim workflow allows pre-activation theft using identifiers printed on a sealed retail box.

\n\nSpeakerBio:  Guanxing Wen
\n

Guanxing Wen is a security researcher with over a decade of experience exploiting bootloaders, TEEs, kernels, and IoT systems. He is a top winner of Huawei bug bounty (2021/2022) and is listed in the Ledger Hall of Fame. His research has been presented at Black Hat, MOSEC, INFILTRATE, Summercon, and QPSS. He currently works at CertiK, where he focuses on low-level systems exploitation and blockchain infrastructure.

\n\n\n\'',NULL,1293790),('2_Friday','10','10:00','10:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'From square root to /root: escalating privileges in Azure containers with Python in Excel\'','\'Ron Ben Yizhak\'','DEF CON Talks_554809c854ee63c526e825f18ba8076a','\'Title: From square root to /root: escalating privileges in Azure containers with Python in Excel
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

Microsoft integrated Python into Excel, giving users more advanced data analysis. The Python code is processed in a cloud container and returned as results. This sparks an immediate question: does it allow remote code execution on Microsoft owned servers?

\n\n

In this talk, we\'ll dig into the various web applications and components in the Python execution environment. We\'ll describe how we discovered a privilege escalation vulnerability in the file upload mechanism of this service, which allowed us to gain root access within the container. Utilizing that, we revealed the complete architecture of this solution. We will show how we discovered Microsoft’s internal deployment configuration, including key vaults, database servers, account names, tenant IDs, and much more. We were even able to execute code on the pilot servers of this product.

\n\n

We also found how to craft a special response to Excel, resulting in bypassing two security boundaries (CVE-2026-45459): the trusted records protection (“Enable Content” warning) and the network isolation protection.

\n\n

We will expose features that weren’t even announced yet and how they might be exploited. Follow us in our journey from the first “whoami” command, through exfiltrating tailor-made Python libraries, and eventually finding a vulnerability to achieve execution as root!

\n\n

https://i.blackhat.com/Asia-25/Asia-25-Carmel-The-Problems-of-Embedded-Python-in-Excel.pdf\nhttps://www.netspi.com/blog/technical-blog/red-teaming/a-first-look-at-python-in-excel/

\n\nSpeakerBio:  Ron Ben Yizhak, SafeBreach
\n

Ron (@RonB_Y) is a security researcher at SafeBreach with 11 years of experience. He works in vulnerability research and has knowledge in forensic investigations, malware analysis and reverse engineering. Ron previously worked in the development of security products and spoke several times at DEF CON

\n\n\n\'',NULL,1293791),('2_Friday','10','10:00','10:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Texas Incidents - How we broke the OMAP-L138 Trusted Execution Environment\'','\'Carlo Meijer,Wouter Bokslag\'','DEF CON Talks_6058e8c0ad2edc02a5acf659e54df19d','\'Title: Texas Incidents - How we broke the OMAP-L138 Trusted Execution Environment
\nTags: DEF CON Official Talk | Demo 💻
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

In this talk, we\'ll discuss how we achieved the black-box compromise of the Trusted Execution Environment (TEE) of the Texas Instruments OMAP-L138, a popular SoC encountered in various PMR radios, satcom equipment and other embedded applications. These radios are frequently used in safety-critical roles, where integrity and service availability is paramount.

\n\n

Through a painstaking iterative process, which includes building both a disassembler and a decompiler for the (hellish) DSP architecture, and through blind exploitation of the Texas Instruments ROM code underpinning the TEE functionality, we managed to abuse a (novel type of) timing side channel that exists when attempting to load (bogus) cryptographic modules into the TEE, allowing us to recover the manufacturer key within a minute.

\n\n

The talk dives deep into the technical aspects of the attack, providing a rare perspective on how the simple primitive of \"decryption isn\'t constant time\" can ultimately be leveraged into a very tangible result: recovery of the device\'s full 128-bit AES key. Additionally, we discuss several ROM-based vulnerabilities, including one that enables full secure-mode code execution on the SoC.

\n\n

Vulns are in ROM, so if you\'re so inclined: feel free to have fun with those on other OMAP-L138-powered devices.

\n\nSpeakers:Carlo Meijer,Wouter Bokslag
\n
\nSpeakerBio:  Carlo Meijer, Midnight Blue
\n

Carlo Meijer is a founding partner of the boutique security consultancy firm Midnight Blue and is most known for his research into TETRA, the MIFARE Classic Crypto1 RFID cipher, and the security of self-encrypting drives. Furthermore, Carlo regularly competes in the famous Pwn2Own hacking competition, where he is part of team PHP Hooligans.

\n\nSpeakerBio:  Wouter Bokslag, Midnight Blue
\n

Wouter Bokslag is a co-founding partner and security researcher at Midnight Blue. He is known for the reverse-engineering and cryptanalysis of several proprietary in-vehicle immobilizer authentication ciphers used by major automotive manufacturers as well as co-developing the world’s fastest public attack against the Hitag2 cipher. He holds a Master’s Degree in Computer Science & Engineering from Eindhoven University of Technology (TU/e) and designed and assisted in teaching hands-on offensive security classes for graduate students at the Dutch Kerckhoffs Institute for several years.

\n\n

Recently heavily involved in the TETRA:BURST research and associated follow-up research, such as the recent reverse-engineering and analysis of the elusive TETRA End-to-End protocol. Also, a contributer of open-source SDR code.

\n\n\n\'',NULL,1293792),('2_Friday','10','10:00','10:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Weaponizing Uselessness: Breaking SMM with the Slowest Instruction Ever Written\'','\'Christopher \"xoreaxeaxeax\" Domas\'','DEF CON Talks_d6b4e30df6e035c262b40b6c275d4472','\'Title: Weaponizing Uselessness: Breaking SMM with the Slowest Instruction Ever Written
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

This is a talk about making your CPU go slow. Really, really, really slow.

\n\n

It is also, somehow, a talk about breaking platform security on nearly every x86 system ever shipped, activating a hundred dormant CVEs, repeatedly ignoring processor specifications, racing intra-core interrupts, and finding a vulnerability that cannot be fixed.

\n\n

But mostly, it\'s about going slow.

\n\n

Memory Sinkhole\nAMD Sinkclose\nSandsifter\nEDK2

\n\nSpeakerBio:  Christopher \"xoreaxeaxeax\" Domas
\n

Christopher Domas (@xoreaxeaxeax) is a security researcher primarily focused on firmware, hardware, and low level processor exploitation. He is best known for releasing impractical solutions to non-existent problems, including the world\'s first single instruction C compiler (M/o/Vfuscator), toolchains for generating images in program control flow graphs (REpsych), and Turing-machines in the vi text editor. His more relevant work includes the sandsifter processor fuzzer, rosenbridge backdoor, the binary visualization tool ..cantor.dust.., and the memory sinkhole privilege escalation exploit.

\n\n\n\'',NULL,1293793),('2_Friday','10','10:30','11:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Breaking Local AI Runtimes: Exploiting llama.cpp and Ollama\'','\'Ofek Itach,Vladimir \"G1ND1L4\" Tokarev\'','DEF CON Talks_7e0f84f1e8e6374599d14ec41bf70f5d','\'Title: Breaking Local AI Runtimes: Exploiting llama.cpp and Ollama
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Local LLM runtimes now sit inside phones, desktops, and internal servers, but the layer underneath is still ordinary native code. We analyzed llama.cpp and Ollama across three trust boundaries: JNI, HTTP lifecycle code, and Go/C bindings.

\n\n

First, in the llama.cpp Android integration, Java can free a native llama_context while native code is still using it. We reclaim the freed 648-byte object, redirect a vtable call, and show code execution in the embedding app. Second, in llama.cpp server, idle model teardown can race active requests, leaving a dangling pointer inside a freed 17,816-byte model allocation. We show remote cross-thread reclaim and attacker-controlled native dereference, then explain the remaining steps to stable RCE. Third, in Ollama, malicious GGUF metadata can push unsafe lengths across the Go/C boundary during quantization, causing C to read past a Go-backed buffer and return heap data to the caller.

\n\n

This is not a prompt-injection talk. It is about exploiting local AI runtimes as native software: one full exploit, one validated server-side primitive, one disclosure primitive, and the audit patterns that find more.

\n\n
    \n
  1. Mergendahl, Louloudis, Vidas. \"Cross-Language Attacks.\"\nNDSS Symposium 2022.

  2. \n
  3. Hussain. \"Incubated Machine Learning Exploits.\"\nDEF CON 32, 2024.

  4. \n
  5. Riancho, Braverman, Demetrio. \"Breaking Out of The AI Cage.\"\nBlack Hat USA 2025.

  6. \n
  7. llama.cpp project: https://github.com/ggml-org/llama.cpp

  8. \n
  9. Ollama project: https://github.com/ollama/ollama

  10. \n
  11. llama.cpp Android sample:\nhttps://github.com/ggml-org/llama.cpp/tree/master/examples/llama.android

  12. \n
\n\nSpeakers:Ofek Itach,Vladimir \"G1ND1L4\" Tokarev
\n
\nSpeakerBio:  Ofek Itach, Cyera
\n

Security Research Team Lead at Cyera. Focus areas include cloud infrastructure\nand AI-related platform security. Talks: Black Hat USA 2024, DEF CON 32\n(2024), RSA 2024, Sector 2024, INTENT 2024, Black Hat Europe 2024 Arsenal.\nEarlier work includes AWS internals and cloud attack surface mapping.

\n\nSpeakerBio:  Vladimir \"G1ND1L4\" Tokarev, Cyera
\n

Vladimir Tokarev is a vulnerability researcher tech lead at Cyera, \n specializing in Cloud, IoT/OT, Windows, Linux, and AI vulnerability\n research and exploit. Talks: Black Hat USA 2024 and 2023,
\n DEF CON 33 Recon Village 2025, CodeBlue 2025, RSA 2024.

\n\n\n\'',NULL,1293794),('2_Friday','11','10:30','11:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Breaking Local AI Runtimes: Exploiting llama.cpp and Ollama\'','\'Ofek Itach,Vladimir \"G1ND1L4\" Tokarev\'','DEF CON Talks_7e0f84f1e8e6374599d14ec41bf70f5d','\'\'',NULL,1293795),('2_Friday','10','10:30','11:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking)\'','\'Gregory \"1umberhack\" Disney-Leugers\'','DEF CON Talks_2aa2fdad1208dcf5a7283d7dd819d977','\'Title: Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking)
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Friday, Aug 7, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

Adversary-in-the-Middle (AitM) phishing has become the de facto standard for bypassing legacy Multi-Factor Authentication (MFA). However, modern AitM frameworks rely on complex, fragile regex rules to rewrite HTTP streams on the fly. When target applications implement strict client-side security headers like Subresource Integrity (SRI) and Content Security Policy (CSP), traditional proxies break, alerting defenders.

\n\n

This presentation introduces a novel \"Browser-in-the-Middle\" architecture. By weaponizing the Chrome DevTools Protocol (CDP), this custom-built Go toolkit renders the target application server-side, allows legitimate scripts to execute, and captures the resulting DOM as an MHTML snapshot. I will demonstrate how converting external assets into Base64 Data URIs and serving a self-contained, live DOM neutralizes SRI and CSP organically without triggering browser security violations. Finally, the talk will detail a Just-In-Time (JIT) JavaScript shim that hooks API calls to silently harvest post-MFA tokens from major IdPs including Okta, Microsoft, Google, and Shibboleth effectively trapping the user in a perfectly mirrored, attacker-controlled environment.

\n\nSpeakerBio:  Gregory \"1umberhack\" Disney-Leugers, Independent Researcher
\n

Gregory Disney-Leugers (1umberhack) is a Independent Researcher specializing in adversary simulation, modern web authentication bypasses, and identity-based attacks. With over a decade of experience in red teaming and penetration testing since 2013, they have previously served as a Technical Lead at major technology and identity providers, including Juniper Networks and Okta.

\n\n\n\'',NULL,1293796),('2_Friday','11','10:30','11:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking)\'','\'Gregory \"1umberhack\" Disney-Leugers\'','DEF CON Talks_2aa2fdad1208dcf5a7283d7dd819d977','\'\'',NULL,1293797),('2_Friday','11','11:00','11:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Keychained Melody - Grabbing the Keys to the iCloud Kingdom\'','\'Alex Radocea,Jaron Bradley\'','DEF CON Talks_4396d36c160446983ce996fcff1dccee','\'Title: Keychained Melody - Grabbing the Keys to the iCloud Kingdom
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

The Apple Keychain has become a cornerstone of credential management for millions of users across the Apple ecosystem. In response, Apple has implemented robust protections for the iCloud Keychain — restricting synchronization exclusively to devices within Apple’s “Circle of Trust” and encrypting stored secrets with keys protected by the Secure Enclave. These layered defenses are designed to ensure that even physical acquisition of Keychain data from Apple’s servers yields nothing actionable.

\n\n

This talk introduces a novel vulnerability (CVE-2026-28860) that fundamentally undermines these protections. Leveraging a deep understanding of macOS internals, we demonstrate a technique capable of extracting all passwords stored within the Keychain — requiring neither root privileges, a user password, nor any prompts to the user. Beyond credential theft, we explore the broader attack surface this vulnerability exposes, presenting additional scenarios where data gleaned from the iCloud Keychain enables further, more severe compromise.

\n\nSpeakers:Alex Radocea,Jaron Bradley
\n
\nSpeakerBio:  Alex Radocea
\n

Founder of Supernetworks and cofounder of Longterm Security. Alex started in security pentesting financial firms on Wall Street at Matasano and cofounded RPISEC at RPI. He has worked on Apple\'s Product Security team, engineering at CrowdStrike, and Spotify\'s Security team. His research — presented at Black Hat and REcon — spans mobile messenger cryptography, kernel security, binary static analysis, and browser hardening, including the discovery of critical flaws in Apple\'s iCloud Keychain.

\n\nSpeakerBio:  Jaron Bradley, Jamf
\n

Jaron is the Director of Jamf Threat Labs where he focuses on discovering new ways to keep user\'s safe on Apple devices. He is author of the books \"Threat Hunting macOS\" and \"OS X Incident Response\". In his free time he manages themittenmac.com, a site dedicated to helping others learn security on the Apple ecosystem.

\n\n\n\'',NULL,1293798),('2_Friday','11','11:00','11:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Sliding into the Flight Deck’s DMs: Practical Message Attacks on CPDLC\'','\'Martin \"MasorX\" Strohmeier,Mehdi Ziazi\'','DEF CON Talks_14bc417a519fb27f1a5882b6048e396b','\'Title: Sliding into the Flight Deck’s DMs: Practical Message Attacks on CPDLC
\nTags: DEF CON Official Talk | Exploit 🪲
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

Air traffic control quietly moved from voice radios to text messages—and almost nobody outside aviation noticed.

\n\n

We did. And it turns out you can slide into a commercial aircraft’s DMs.

\n\n

In this talk, we show how modern aircraft receive digital instructions (like “climb,” “descend,” or “turn”) over a system called CPDLC—and how that system has basically zero real security. No crypto. No authentication. Just vibes and protocol complexity.

\n\n

We built a full fake ground station using cheap SDR gear and made certified avionics believe we were air traffic control. From there, we can inject real flight instructions or knock aircraft offline at scale with protocol-level DoS attacks—no jamming required.

\n\n

This isn’t a simulation. We tested it against real aviation hardware in a live CPDLC environment.

\n\n

If you’ve ever wondered what happens when safety-critical infrastructure assumes “nobody will try this,” this talk is for you.

\n\n

Sliding into the Flight Deck\'s DMs: Practical Message Attacks on CPDLC

\n\n

Mehdi Ziazi, ETH Zurich; Khalid Aleem, Independent; Harshad Sathaye, ETH Zurich; Martin Strohmeier, Cyber-Defence Campus, armasuisse Science + Technology

\n\n

Usenix Security 2026

\n\nSpeakers:Martin \"MasorX\" Strohmeier,Mehdi Ziazi
\n
\nSpeakerBio:  Martin \"MasorX\" Strohmeier, Cyber-Defence Campus, armasuisse Science + Technology
\n

Martin is a Senior Scientist at the Swiss Cyber Defence Campus, primarily based at ETH Zurich, and a Visiting Fellow of Kellogg College, Oxford. His work focuses on designing and analyzing security protocols for cyber-physical systems in critical infrastructures—aviation, satellites, space, and transportation systems. Martin also explore privacy issues in global networks, adversarial machine learning, and open-source intelligence.

\n\n

Martin received his DPhil in 2016 at Oxford, supervised by Prof. Ivan Martinovic, where he studied the security and privacy of aviation communication technologies. I co-founded the OpenSky Network and coordinate its research activities. His work has received awards from both the aviation and security communities, including the EPSRC Doctoral Prize Fellowship and commendation from the British Computer Society. Martin has published regularly at all major security and AI conferences and also been a speaker at DEF CON several times (main stage + villages).

\n\nSpeakerBio:  Mehdi Ziazi, ETH Zurich
\n

Mehdi Ziazi is a hacker and cybersecurity student at ETH Zurich and an incoming PhD student at CISPA focused on aerospace security and cyber-physical systems. Their recent work in aviation security explores novel attack paths against aircraft systems and their real-world impact, approached with curiosity, persistence, and a bit of stubbornness.

\n\n\n\'',NULL,1293799),('2_Friday','11','11:30','12:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'A Provider for the MOFia - Distributed Post-Ex Capabilities\'','\'Steven Flores\'','DEF CON Talks_017538c3026f13ab57bfe8c086879e82','\'Title: A Provider for the MOFia - Distributed Post-Ex Capabilities
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Friday, Aug 7, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

From time to time I take another pass at WMI to see if there\'s anything left in it that hasn\'t been picked over. For most of the last decade, offensive WMI has meant Win32_Process Create and event subscription persistence. Defenders built their detections around those two primitives, EDR vendors optimized for them, and the rest of WMI mostly got ignored.

\n\n

The provider architecture is one of the parts that got ignored. This talk is about turning it into a distributed post-exploitation framework.

\n\n

The core technique is remote installation of custom WMI providers without dropping anything over SMB or WinRM. To get there, I had to reimplement the parts of mofcomp.exe that handle MOF parsing and provider registration, and push the resulting object instances over the wire using the MS-WMIO binary protocol.

\n\n

Getting the DLL onto the target needed its own primitive, so along the way I found that there are existing WMI classes on every supported Windows version that can be abused for arbitrary file upload and download. As far as I can tell that hasn\'t been published before.\n Once a provider is installed, it runs inside WMIPrvSE.exe, which is a very different execution context from spawning cmd.exe through Win32_Process. The provider library I\'m releasing covers a series of post exploitation primitives.

\n\nSpeakerBio:  Steven Flores
\n

Steven enjoys offensive research, tool and capability development and is currently employed at SpecterOps doing his favorite things.

\n\n\n\'',NULL,1293800),('2_Friday','12','11:30','12:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'A Provider for the MOFia - Distributed Post-Ex Capabilities\'','\'Steven Flores\'','DEF CON Talks_017538c3026f13ab57bfe8c086879e82','\'\'',NULL,1293801),('2_Friday','11','11:30','12:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Crashing the Party: Pwning Control-Flow Integrity with Segmentation Fault-Oriented Programming\'','\'Marcos \"h3xduck\" Bajo,Ritvik \"RoYalGamr\" Goyal\'','DEF CON Talks_354ffc7b4b8138717fcd49a2954827a9','\'Title: Crashing the Party: Pwning Control-Flow Integrity with Segmentation Fault-Oriented Programming
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Friday, Aug 7, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

A program crashes with a segmentation fault. Then, it crashes again. And again. What looks like crazy behaviour is actually an exploit, running one crash at a time.

\n\n

In this talk, we present Segmentation Fault-Oriented Programming (SFOP), a novel exploitation technique that weaponizes 12 previously unknown weaknesses in the Linux kernel\'s handling of signals to execute arbitrary code. SFOP is designed to bypass Intel CET, the most widely deployed hardware Control-Flow Integrity (CFI) scheme on modern x86-64 systems, built to stop classic code-reuse attacks such as Return-Oriented Programming (ROP) and Sigreturn-Oriented Programming (SROP). Unlike previous CFI bypass techniques, SFOP is a general-purpose technique that can by-default reliably exploit any vulnerable x86-64 application with Intel CET enabled, becoming the lowest-hanging fruit attack after Intel CET.

\n\n

We will show how SFOP bypasses CFI and turns a single memory-corruption vulnerability into arbitrary code execution on real-world targets. Through practical exploits, we demonstrate that what appears to be a process trapped in a crash loop is, in reality, attacker-controlled execution progressing fault by fault. Finally, we discuss the underlying weaknesses that make SFOP possible and the mitigations needed to defend against this new class of attacks.

\n\n

Our paper has a ~50 references, like most academic papers. We have references to the Linux kernel lines that showcase the vulnerabilities we find, even! \nHere we copy paste our references, but everything is properly ordered in the paper.

\n\n

[1] LMS Phrack 40. Bypassing cet & bti with functional oriented programming. https://phrack.org/issues/71/7_md. (29-10-2025).\n[2] Martin Abadi, Mihai Budiu, Ulfar Erlingsson, and Jay Ligatti. Control-flow integrity. In Proceedings of the 12th ACM Conference on Computer and Communications Security, CCS ’05, page 340–353, New York, NY, USA, 2005. Association for Computing Machinery.\n[3] Marcos Bajo and Christian Rossow. Await() a second: evading control flow integrity by hijacking c++ coroutines. In Proceedings of the 34th USENIX Conference on Security Symposium, SEC ’25, USA, 2025. USENIX Association.\n[4] Markus Bauer, Ilya Grishchenko, and Christian Rossow. Typro: Forward cfi for c-style indirect function calls using type propagation. In Proceedings of the 38th Annual Computer Security Applications Conference, ACSAC ’22, page 346–360, New York, NY, USA, 2022. Association for Computing Machinery.\n[5] Lucas Becker, Matthias Hollick, and Jiska Classen. Sok: on the effectiveness of control-flow integrity in practice. In Proceedings of the 18th USENIX Conference on Offensive Technologies, WOOT’24, USA, 2024. USENIX Association.\n[6] Lorenzo Binosi, Gregorio Barzasi, Michele Carminati, Stefano Zanero, and Mario Polino. The Illusion of Randomness: An Empirical Analysis of Address Space Layout Randomization Implementations. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024. \n[7] Tyler Bletsch, Xuxian Jiang, Vince W. Freeh, and Zhenkai Liang. Jump-oriented programming: A new class of code-reuse attack. In Proceedings of the ACM Symposium on Information, Computer and Communications Security, ASIACCS, 2011.\n[8] Erik Bosman. x86: Srop mitigation: implement signal counting. https://lkml.org/lkml/2014/5/15/858. (12-11-2025).\n[9] Erik Bosman and Herbert Bos. Framing signals - a return to portable shellcode. In 2014 IEEE Symposium on Security and Privacy, pages 243–258, 2014.\n[10] Nicholas Carlini, Antonio Barresi, Mathias Payer, David Wagner, and Thomas R. Gross. Control-Flow bending: On the effectiveness of Control-Flow integrity. In 24th USENIX Security Symposium (USENIX Security 15), pages 161–176, Washington, D.C., August 2015. USENIX Association.\n[11] Chromium. syscall sets.cc - chromium github. https://github.com/chromium/chromium/blob/main/sandbox/linux/seccomp-bpf-helpers/syscall sets.cc#L353. (12-11-2025).\n[12] Exploit Database. Nginx 1.3.9 - 1.4.0 - chuncked encoding stack buffer overflow (metasploit). https://www.exploit-db.com/exploits/25775. (29-10-2025).\n[13] V8 Developers. Control-flow integrity in v8. https://v8.dev/blog/control-flow-integrity. (29-10-2025).\n[14] Docker Docs. Seccomp security profiles for docker. https://docs.docker.com/engine/security/seccomp/. (12-11-2025).\n[15] Victor Duta, Fabian Freyer, Fabio Pagani, Marius Muench, and Cristiano Giuffrida. Let me unwind that for you: Exceptions to backward-edge protection. In Symposium on Network and Distributed System Security (NDSS), 2023.\n[16] Mozilla Firefox. Sandboxfilter.cpp - firefox github. https://github.com/mozilla-firefox/firefox/blob/main/security/sandbox/linux/SandboxFilter.cpp#L1178. (12-11-2025).\n[17] Alexander J. Gaidis, Joao Moreira, Ke Sun, Alyssa Milburn, Vaggelis Atlidakis, and Vasileios P. Kemerlis. Fineibt: Fine-grain control-flow enforcement with indirect branch tracking. In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, RAID ’23, page 527–546, New York, NY, USA, 2023. Association for Computing Machinery. \n[18] GNU. Gcc wiki - vtv. https://gcc.gnu.org/wiki/vtv. (12-11-2025).\n[19] GNU. Program instrumentation options. https://gcc.gnu.org/onlinedocs/gcc/Instrumentation-Options.html. (12-11-2025).\n[20] Yingjie Guo, Liwei Chen, and Gang Shi. Function-oriented programming: A new class of code reuse attack in c applications. In 2018 IEEE Conference on Communications and Network Security (CNS), pages 1–9, 2018.\n[21] Enes Goktas, Elias Athanasopoulos, Herbert Bos, and Georgios Portokalidis. Out of control: Overcoming control-flow integrity. In 2014 IEEE Symposium on Security and Privacy, pages 575–589, 2014.\n[22] Hong Hu, Zheng Leong Chua, Sendroiu Adrian, Prateek Saxena, and Zhenkai Liang. Automatic generation of Data-Oriented exploits. In 24th USENIX Security Symposium (USENIX Security 15), pages 177–192, Washington, D.C., August 2015. USENIX Association.\n[23] Hong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua,Prateek Saxena, and Zhenkai Liang. Data-oriented programming: On the expressiveness of non-control data attacks. In 2016 IEEE Symposium on Security and Privacy (SP), pages 969–986, 2016.\n[24] Intel. A technical look at intel® control-flow enforcement technology. https://www.intel.com/content/www/us/en/developer/articles/technical/technical-look-control-flow-enforcement-technology.html. (29-10-2025).\n[25] Seunghoon Jeong, Jaejoon Hwang, Hyukjin Kwon, and Dongkyoo Shin. A cfi countermeasure against got overwrite attacks. IEEE Access, 8:36267–36280, 2020.\n[26] Linux Kernel. Control-flow enforcement technology (cet) shadow stack. https://docs.kernel.org/arch/x86/shstk.html. (12-11-2025).\n[27] LLVM. Control flow integrity design documentation. https://clang.llvm.org/docs/ControlFlowIntegrityDesign.html. (12-11-2025).\n[28] Linux manual page. Sigaction(2) - linux manual page. https://man7.org/linux/man-pages/man2/sigaction.2.html. (05-10-2025).\n[29] Ben Niu and Gang Tan. Modular control-flow integrity. In Proceedings of the 35th ACM SIGPLAN Conference on Programming\nLanguage Design and Implementation, PLDI ’14, page 577–587, New York, NY, USA, 2014. Association for Computing Machinery.\n[30] PaX. Address space randomization. https://pax.grsecurity.net/docs/aslr.txt, 2003. (12-11-2025).\n[31] Aravind Prakash, Xunchao Hu, and Heng Yin. vfguard: Strict protection for virtual function calls in cots c++ binaries. In Proceeding of the Annual Network and Distributed System Security Symposium (NDSS), 01 2015.\n[32] Bootlin Elixir Cross Referencer. create rstor token (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/shstk.c#L64. (29-10-2025).\n[33] Bootlin Elixir Cross Referencer. get shstk data (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/shstk.c#L272. (29-10-2025).\n[34] Bootlin Elixir Cross Referencer. libc sigaction (glibc source code). https://elixir.bootlin.com/glibc/glibc-2.33/source/sysdeps/unix/sysv/linux/sigaction.c#L42. (29-10-2025).\n[35] Bootlin Elixir Cross Referencer. pte mkwrite shstk (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/include/asm/pgtable.h#L491. (29-10-2025).\n[36] Bootlin Elixir Cross Referencer. rt sigaction (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.7/source/kernel/signal.c#L4644. (29-10-2025).\n[37] Bootlin Elixir Cross Referencer. rt sigreturn l266 (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/signal 64.c#L266. (29-10-2025).\n[38] Bootlin Elixir Cross Referencer. rt sigreturn l275 (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/signal 64.c#L275. (29-10-2025).\n[39] Bootlin Elixir Cross Referencer. setup signal shadow stack l364 (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/shstk.c#L364. (29-10-2025).\n[40] Bootlin Elixir Cross Referencer. setup signal shadow stack l370 (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/kernel/shstk.c#L370. (29-10-2025).\n[41] Bootlin Elixir Cross Referencer. Sigaction (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/include/uapi/asm/signal.h#L93. (05-10-2025).\n[42] Bootlin Elixir Cross Referencer. Sigframe (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.2/source/arch/x86/include/asm/sigframe.h#L59. (05-10-2025).\n[43] Bootlin Elixir Cross Referencer. sigset t (glibc source code). https://elixir.bootlin.com/glibc/glibc-2.33/source/signal/bits/types/sigset t.h#L7. (29-10-2025).\n[44] Bootlin Elixir Cross Referencer. sigset t (linux kernel source code). https://elixir.bootlin.com/linux/v6.15.7/source/arch/x86/include/asm/signal.h#L25. (29-10-2025).\n[45] AliAkbar Sadeghi, Salman Niksefat, and Maryam Rostamipour. Pure call oriented programming (pcop): chaining the gadgets using call instructions. Journal of Computer Virology and Hacking Techniques, 14:1–18, 05 2018.\n[46] Felix Schuster, Thomas Tendyck, Christopher Liebchen, Lucas Davi, Ahmad-Reza Sadeghi, and Thorsten Holz. Counterfeit object-oriented programming: On the difficulty of preventing code reuse attacks in c++ applications. In Proceedings of the IEEE Symposium on Security and Privacy, SP, 2015.\n[47] Hovav Shacham. The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86). In Proceedings of the ACM conference on Computer and Communications Security, CCS, 2007.\n[48] sroettger. Ierae ctf 2024. https://gist.github.com/sroettger/fe66f7eb0cb10a8ebd1454875a7131ea. (29-10-2025).\n[49] Ubuntu. Compilerflags - ubuntu wiki. https://wiki.ubuntu.com/ToolChain/CompilerFlags. (29-10-2025).\n[50] Chao Zhang, Scott A. Carr, Tongxin Li, Yu Ding, Chenyu Song, Mathias Payer, and Dawn Song. Vtrust: Regaining trust on virtual calls. In Proceedings of the Annual Network and Distributed System Security Symposium (NDSS), 2016.\n[51] Tianning Zhang, Miao Cai, Diming Zhang, and Hao Huang. esrop attack: Leveraging signal handler to implement turing-complete attack under cfi defense. In Fengjun Li, Kaitai Liang, Zhiqiang Lin, and Sokratis K. Katsikas, editors, Security and Privacy in Communication Networks, pages 752–769, Cham, 2023. Springer Nature Switzerland

\n\nSpeakers:Marcos \"h3xduck\" Bajo,Ritvik \"RoYalGamr\" Goyal
\n
\nSpeakerBio:  Marcos \"h3xduck\" Bajo, CISPA Helmholtz Center for Information Security
\n

Marcos Bajo aka h3xduck is a security researcher and PhD student at the CISPA Helmholtz Center for Information Security in Germany. His research focuses on exploitation techniques and malware, but more broadly, he\'s interested in breaking things others build—and building things to break things.

\n\nSpeakerBio:  Ritvik \"RoYalGamr\" Goyal
\n

Ritvik Goyal is a Senior Undergraduate in Mathematics and Scientific Computing at the Indian Institute of Technology Kanpur. He recently worked as a Research Intern at the CISPA Helmholtz Center, focusing on system security research regarding Control Flow Integrity protections like Intel CET. He is a key member of the competitive CTF team Wiredin IITK and actively mentors students in cybersecurity at Programming Club IIT Kanpur.

\n\n\n\'',NULL,1293802),('2_Friday','12','11:30','12:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Crashing the Party: Pwning Control-Flow Integrity with Segmentation Fault-Oriented Programming\'','\'Marcos \"h3xduck\" Bajo,Ritvik \"RoYalGamr\" Goyal\'','DEF CON Talks_354ffc7b4b8138717fcd49a2954827a9','\'\'',NULL,1293803),('2_Friday','12','12:00','12:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Can AI do novel security research? Meet the HTTP Terminator\'','\'James \"albinowax\" Kettle\'','DEF CON Talks_d2340e28e66ebb99daa92b82c0a234dc','\'Title: Can AI do novel security research? Meet the HTTP Terminator
\nTags: DEF CON Official Talk | Tool 🛠 | Exploit 🪲
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it.

\n\n

It worked - I\'ll share an arsenal of new HTTP desync triggers, gadgets, and exploits that compromised banks, security solutions, and government infrastructure. Then I\'ll trace each discovery chain back through the HTTP Terminator, showing how to turn your personal expertise into an autonomous weapon - and the dark arts required to make it lethal.

\n\n

I\'ll also share discoveries from beyond the autonomy horizon - some only reachable with a tight human/AI research loop, and others beyond AI\'s reach entirely. These include a powerful undisclosed recon technique, and anomalies that hint at new attack classes offering alternative paths to critical impact. I\'ll analyse the discovery process, sharing detailed experiments that probe the boundaries of what AI can and can\'t discover.

\n\n

You\'ll leave with new exploits from desync triggers to undisclosed attack classes, and a blueprint for turning your instincts into an autonomous research cascade. And yes, I\'ll open-source the HTTP Terminator.

\n\n

https://portswigger.net/research/http1-must-die \nhttps://i.blackhat.com/BH-USA-25/Presentations/US-25-Dolan-Gavitt-AI-Agents-for-Offsec-with-Zero-False-Positives-Thursday.pdf \nhttps://portswigger.net/research/listen-to-the-whispers-web-timing-attacks-that-actually-work \nhttps://www.intruder.io/research/practical-http-header-smuggling

\n\nSpeakerBio:  James \"albinowax\" Kettle, PortSwigger
\n

James \'albinowax\' Kettle is the Director of Research at PortSwigger, the makers of Burp Suite. He\'s best known for pioneering novel web attack techniques, and publishing them at major conferences like Black Hat USA, at which he\'s presented for nine consecutive years.

\n\n

He also loves exploring and advising on innovative tool concepts for security professionals, many of which have since become industry standard. Examples include introducing OAST via Burp Collaborator, bulk parameter discovery via Param Miner, billion-request attacks with Turbo Intruder, and human-style scanning with Backslash Powered Scanner.

\n\n

His best-known research is HTTP Desync Attacks, which popularised HTTP Request Smuggling. Other popular attack techniques that can be traced back to his research include web cache poisoning, the single-packet attack, server-side template injection, and password reset poisoning. He\'s also the designer behind many of the topics and labs that make up the Web Security Academy, and serves on the Black Hat Europe review board.

\n\n\n\'',NULL,1293804),('2_Friday','12','12:00','12:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Shopping Is The Attack: A Decade Of E-Commerce Scalper Wars, And The Multi-Agent AI Era\'','\'Yaniv \"PSYMAG\" Menasherov\'','DEF CON Talks_b97c643cab915bec63711724f9e4f9b3','\'Title: Shopping Is The Attack: A Decade Of E-Commerce Scalper Wars, And The Multi-Agent AI Era
\nTags: DEF CON Official Talk
\nWhen: Friday, Aug 7, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

Forty-five seconds. Two thousand five hundred Nike Air Jordans, gone. Resold at five times retail the next month. Every weekly drop, for years, at one of Europe\'s largest retailers.

\n\n

Shopping is the attack. The bot does not exploit a CVE. It does not break the contract. It just shops, and every standard control is structurally blind to it.

\n\n

I spent five years as Head of SecOps at ASOS, on the bridge for every Air Jordan drop, reverse-engineering the full attacker MO because nobody else was going to.

\n\n

This talk is that MO from the attacker\'s chair. Eight phases against the e-commerce golden thread. Account army staged weeks ahead via fake registration and credential stuffing. Targets picked from StockX margins, not catalogues. Early bird APIs leaking pre-release products before the SKU exists. Mobile catalogue enumeration. Vision-API classification. A watcher polling stock until launch. Two bag agents racing, one guest for raw speed, one aged returning customer for trust. Checkout picked for approval probability. Then I show what Anthropic\'s GTG-1002 disclosure means for retail: the same MO, decomposed into AI agents, at speeds Anthropic called physically impossible.

\n\n

The eCommerce bots are unstoppable. Come see why.

\n\nSpeakerBio:  Yaniv \"PSYMAG\" Menasherov
\n

Yaniv Menasherov has worked every seat in the SOC. He started as a Tier 1 analyst and worked his way up through shift lead, incident response manager, and Head of SOC, the analyst getting paged at 3 AM, the lead running the war room, and the one writing the post-mortem nobody wanted to read.

\n\n

He\'s fought them all from both sides of the table: as a client defending enterprises against ransomware crews, insiders, and the occasional state-aligned visitor with too much patience; and as a vendor, sitting next to customers when their existing stack wasn\'t cutting it. Eventually he founded his own MSSP, building a unified global SOC for some of the largest enterprises in the world , 24/7 across continents, where \"alert fatigue\" is a polite way of saying \"we\'re losing.\"

\n\n

Today he leads research at Legion Security, an agentic SOC platform rethinking investigation and response for a world where analysts shouldn\'t be the bottleneck. After years of watching SIEMs and SOARs over-promise, he\'s building what he wished he\'d had on shift.

\n\n\n\'',NULL,1293805),('2_Friday','12','12:30','13:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'BTR Reforged: Weaponizing Defender\'s Remediation Driver as a Kernel Operation Primitive\'','\'Jiří Vinopal\'','DEF CON Talks_d219be28aa97d6be12cc1ad1df800694','\'Title: BTR Reforged: Weaponizing Defender\'s Remediation Driver as a Kernel Operation Primitive
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Friday, Aug 7, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 — without exploits, vulnerabilities, or memory corruption?

\n\n

In this talk, we present the first full reverse engineering of the Windows Defender Boot-Time Removal driver (BTR.sys) and its proprietary transaction format. We dissect its encrypted configuration mechanism, integrity validation logic, and execution pipeline, and demonstrate how this legitimate remediation component can be transformed into a universal kernel operation engine. We introduce BTR_CLI, a research tool that constructs valid encrypted transactions and exercises the driver\'s capabilities.

\n\n

We demonstrate how BTR_CLI can be used as an EDR/AV bypass technique, disarming security solutions using a trusted Windows built-in, Microsoft-signed driver — without relying on typical BYOVD techniques.

\n\n

Our research reveals how trusted security infrastructure can unintentionally expose powerful primitives and what this means for defenders. This talk blends reverse engineering, kernel internals, and detection engineering into a practical case study of when defensive technology becomes offensive capability.

\n\nSpeakerBio:  Jiří Vinopal, Threat Researcher at Check Point Research
\n

Jiří Vinopal is a security researcher, malware researcher, and reverse engineer at Check Point Research, focused on advanced cyber threats, kernel internals, and the hidden mechanics of undocumented system components. His work spans uncovering novel attack primitives, reconstructing proprietary protocols from binary analysis alone, and deep-diving into both sophisticated malware families and trusted platform components. When he\'s not buried in disassembly, he actively shares his knowledge and passion for reverse engineering across his X account, YouTube channel, and blog — delivering tips, tricks, and technical insights to fellow enthusiasts and the broader security community.

\n\n\n\'',NULL,1293806),('2_Friday','13','12:30','13:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'BTR Reforged: Weaponizing Defender\'s Remediation Driver as a Kernel Operation Primitive\'','\'Jiří Vinopal\'','DEF CON Talks_d219be28aa97d6be12cc1ad1df800694','\'\'',NULL,1293807),('2_Friday','12','12:30','12:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Hacking the Government: How Two Researchers Turned Late-Night Boredom Into a National Audit\'','\'Robert \"ProXy\" Kruczek,Kamil Szczurowski\'','DEF CON Talks_a3948a29f6f5fda3a6d0f78d90131a81','\'Title: Hacking the Government: How Two Researchers Turned Late-Night Boredom Into a National Audit
\nTags: DEF CON Official Talk
\nWhen: Friday, Aug 7, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

What happens when two researchers spend several days scrutinizing the Polish web? We didn’t just find anomalies—we took action. Join us as we reveal the results of our intensive research, which led to multiple official reports to CSIRT GOV, NASK, and MON. We will walk you through our findings, the scale of the threats discovered, and provide essential recommendations for a more secure digital future.

\n\nSpeakers:Robert \"ProXy\" Kruczek,Kamil Szczurowski
\n
\nSpeakerBio:  Robert \"ProXy\" Kruczek, Securitum
\n

I am a Cybersecurity Consultant, Mentor, and Ethical Hacker (known in the infosec community as ProXy) at Securitum - Poland\'s leading cybersecurity firm - and a contributor to sekurak.pl, the country\'s largest infosec portal. With over 10 years of experience in vulnerability research and penetration testing.

\n\n

Operating under the ProXy alias, I discovered and reported 43 CVEs and I am an active Bug Bounty hunter (Hall of Fame at OLX, reports for BlaBlaCar, OVH, and ERCOM).

\n\nSpeakerBio:  Kamil Szczurowski, Securitum
\n

On a daily basis, Kamil Szczurowski specializes in web application security testing and social engineering assessments. In his free time, he analyzes malware, APT campaigns, open-source software, and software used by government institutions, which has resulted in multiple CVE entries and publications. He is also an author of articles published on sekurak.pl.

\n\n\n\'',NULL,1293808),('2_Friday','12','12:30','13:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet\'s V8 on the Galaxy S25\'','\'Hrvoje Mišetić,Jamie Hill-Daniel,William Liu\'','DEF CON Talks_7edb2be4d526a6c2c78796af304db34c','\'Title: Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet\'s V8 on the Galaxy S25
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

What happens when a flagship phone like the Samsung Galaxy S25 ships with an outdated Javascript engine in its default browser?

\n\n

For the past 6 months, Samsung Internet shipped with an out-of-date V8 build that had already-fixed, publicly known vulnerabilities. One such bug is CVE-2025-10891, a flaw in Ignition bytecode generation for Javascript exception handling. In this talk, we show how we transform this vulnerability into reliable renderer code execution through instruction smuggling and internal native V8 runtime calls. We then showcase how we exploit weaker isolation mechanisms on mobile Chromium engines to upgrade the renderer RCE’s capability into a universal XSS primitive.

\n\n

https://osec.io/blog/2026-04-01-patch-gap-to-mobile-renderer-rce/ \nhttps://issuetracker.google.com/issues/443875388

\n\nSpeakers:Hrvoje Mišetić,Jamie Hill-Daniel,William Liu
\n
\nSpeakerBio:  Hrvoje Mišetić, OtterSec
\n

Hrvoje Mišetić is a Web3 auditor and security researcher at OtterSec with prior research projects including Linux kernel LPE, QEMU hypervisor escape, and browser exploitation. He is a member of the Crusaders of Rust CTF team, and DiceGang, with whom he has qualified for Defcon CTF Finals multiple times. He presented Minecraft RCE research at OffensiveCon ‘26.

\n\nSpeakerBio:  Jamie Hill-Daniel, OtterSec
\n

Jamie Hill-Daniel is a security auditor currently working at OtterSec, with an interest in browser and kernel research. He is a member of the Crusaders of Rust and DiceGang CTF teams, having qualified for multiple Defcon CTF Finals with the latter.

\n\nSpeakerBio:  William Liu
\n

William Liu is a security engineer at Trail of Bits with experience in low-level systems and computer architecture. He is a member of the Crusaders of Rust and DiceGang CTF teams, having qualified for multiple Defcon CTF Finals with the latter. He has previously worked as a systems software engineer at NVIDIA. He documents some of his research on his personal site, willsroot.io.

\n\n

William is a Class of 2025 graduate of the Massachusetts Institute of Technology, where he worked on the EntryBleed KASLR bypass and kernel fuzzing under Professor Mengjia Yan. He has presented micro-architectural security research at HASP ‘23 and NEHWS ‘24, as well as Linux 0-day research at Hexacon ‘25.

\n\n\n\'',NULL,1293809),('2_Friday','13','12:30','13:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet\'s V8 on the Galaxy S25\'','\'Hrvoje Mišetić,Jamie Hill-Daniel,William Liu\'','DEF CON Talks_7edb2be4d526a6c2c78796af304db34c','\'\'',NULL,1293810),('2_Friday','12','12:00','12:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Your Packets Are Showing: Hybrid Quantum ML for Passive OS Fingerprinting\'','\'Daniel Justice,Jae Sung Kim,La Alsulaim,Shreya G Savadatti\'','DEF CON Talks_9d109a390397c5c5071413ee146e55ae','\'Title: Your Packets Are Showing: Hybrid Quantum ML for Passive OS Fingerprinting
\nTags: DEF CON Official Talk | Tool 🛠
\nWhen: Friday, Aug 7, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Quantum cybersecurity isn\'t just Q-Day. We took passive OS fingerprinting, the technique behind p0f and every modern ML-based fingerprinting tool, and mapped it onto a 20-qubit quantum circuit, replacing XGBoost as the classifier inside an \"OsirisML\"-style pipeline. Head-to-head on real packet captures from CIC-IDS 2017, the quantum version landed within 0.013 F1 of XGBoost on identical features, using roughly two orders of magnitude fewer trainable parameters. This is the first time a real DEF CON-relevant security workload has been mapped onto a quantum classifier with results that hold up against the classical tool the community already uses. The conversation about quantum and security has been stuck on cryptography. This talk is about everything else it can do.

\n\n

M. Zalewski, \"p0f v3,\" [Online]. Available: https://lcamtuf.coredump.cx/p0f3/. [Accessed: Apr. 25, 2026].

\n\n

J. Holland, P. Schmitt, N. Feamster, and P. Mittal, \"New Directions in Automated Traffic Analysis,\" in Proc. 2021 ACM SIGSAC Conf. on Computer and Communications Security (CCS), 2021, pp. 3366–3383, doi: 10.1145/3460120.3484758.

\n\n

S. Ekeroth, J. Neale, and J. S. Kim, \"Machine Learning Optimization for Enhanced OS Fingerprinting,\" Virginia Tech, 2024.

\n\n

I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, \"Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization,\" in Proc. 4th Int. Conf. on Information Systems Security and Privacy (ICISSP), 2018.

\n\n

T. Chen and C. Guestrin, \"XGBoost: A Scalable Tree Boosting System,\" in Proc. 22nd ACM SIGKDD Int. Conf. on Knowledge Discovery and Data Mining, 2016, pp. 785–794, doi: 10.1145/2939672.2939785.

\n\n

M. Benedetti, E. Lloyd, S. Sack, and M. Fiorentini, \"Parameterized quantum circuits as machine learning models,\" Quantum Sci. Technol., vol. 4, no. 4, p. 043001, 2019, doi: 10.1088/2058-9565/ab4eb5.

\n\n

M. Schuld, A. Bocharov, K. M. Svore, and N. Wiebe, \"Circuit-centric quantum classifiers,\" Phys. Rev. A, vol. 101, no. 3, p. 032308, 2020, doi: 10.1103/PhysRevA.101.032308.

\n\n

K. Mitarai, M. Negoro, M. Kitagawa, and K. Fujii, \"Quantum circuit learning,\" Phys. Rev. A, vol. 98, no. 3, p. 032309, 2018, doi: 10.1103/PhysRevA.98.032309.

\n\n

M. Schuld, V. Bergholm, C. Gogolin, J. Izaac, and N. Killoran, \"Evaluating analytic gradients on quantum hardware,\" Phys. Rev. A, vol. 99, no. 3, p. 032331, 2019, doi: 10.1103/PhysRevA.99.032331.

\n\n

T. Jones and J. Gacon, \"Efficient calculation of gradients in classical simulations of variational quantum algorithms,\" arXiv preprint arXiv:2009.02823, 2020.

\n\n

H. Neven, V. S. Denchev, G. Rose, and W. G. Macready, \"QBoost: Large scale classifier training with adiabatic quantum optimization,\" in Proc. Asian Conf. on Machine Learning (ACML), vol. 25, 2012, pp. 333–348.

\n\n

V. Havlicek, A. D. Corcoles, K. Temme, A. W. Harrow, A. Kandala, J. M. Chow, and J. M. Gambetta, \"Supervised learning with quantum-enhanced feature spaces,\" Nature, vol. 567, no. 7747, pp. 209–212, 2019, doi: 10.1038/s41586-019-0980-2.

\n\n

M. Schuld and N. Killoran, \"Quantum machine learning in feature Hilbert spaces,\" Phys. Rev. Lett., vol. 122, no. 4, p. 040504, 2019, doi: 10.1103/PhysRevLett.122.040504.

\n\n

H. Suryotrisongko and Y. Musashi, \"Evaluating hybrid quantum-classical deep learning for cybersecurity botnet DGA detection,\" Procedia Comput. Sci., vol. 197, pp. 223–229, 2022, doi: 10.1016/j.procs.2021.12.135.

\n\n

E. D. Payares and J. C. Martinez-Santos, \"Quantum machine learning for intrusion detection of distributed denial of service attacks: a comparative overview,\" in Proc. SPIE 11699, Quantum Computing, Communication, and Simulation, 2021, p. 116990B, doi: 10.1117/12.2593297.

\n\n

J. R. McClean, S. Boixo, V. N. Smelyanskiy, R. Babbush, and H. Neven, \"Barren plateaus in quantum neural network training landscapes,\" Nat. Commun., vol. 9, no. 1, p. 4812, 2018, doi: 10.1038/s41467-018-07090-4.

\n\n

M. Cerezo, A. Sone, T. Volkoff, L. Cincio, and P. J. Coles, \"Cost function dependent barren plateaus in shallow parametrized quantum circuits,\" Nat. Commun., vol. 12, no. 1, p. 1791, 2021, doi: 10.1038/s41467-021-21728-w.

\n\n

V. Bergholm et al., \"PennyLane: Automatic differentiation of hybrid quantum-classical computations,\" arXiv preprint arXiv:1811.04968, 2018.

\n\n

E. Grant, L. Wossnig, M. Ostaszewski, and M. Benedetti, \"An initialization strategy for addressing barren plateaus in parametrized quantum circuits,\" Quantum, vol. 3, p. 214, 2019, doi: 10.22331/q-2019-12-09-214.

\n\nSpeakers:Daniel Justice,Jae Sung Kim,La Alsulaim,Shreya G Savadatti
\n
\nSpeakerBio:  Daniel Justice, Carnegie Mellon University
\nNo BIO available
\nSpeakerBio:  Jae Sung Kim, Independent Researcher
\n

Jae Sung Kim is an independent researcher specializing in network security and machine learning. His work focuses on applying novel computational approaches, including hybrid quantum-classical architectures, to classical security problems such as passive OS fingerprinting. He is a co-author of OsirisML, a machine learning pipeline for enhanced OS fingerprinting built on the nPrint packet representation framework.

\n\nSpeakerBio:  La Alsulaim, University of Pittsburgh
\n

La Alsulaim is a Computer Science student at the University of Pittsburgh. His research interests include machine learning applications

\n\nSpeakerBio:  Shreya G Savadatti, Carnegie Mellon University
\n

Shreya G Savadatti is a researcher specializing in quantum computing and cybersecurity. Currently a Master’s student at Carnegie Mellon University, she explores Quantum Reservoir Computing (QRC) and cross-platform hardware benchmarking. As an IBM Qiskit Advocate, she contributes to open-source compilers and recently placed Top 5 at MIT iQuHACK 2026 for quantum circuit optimization. Her published research includes work on Quantum Fully Homomorphic Encryption (QFHE).

\n\n\n\'',NULL,1293811),('2_Friday','13','13:00','13:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Bring-Your-Own-EDR - Breaking Windows Process Protection to build EDR-Protected Malware\'','\'Shahak Morag\'','DEF CON Talks_aa14eca8ce75caf6298656e24b68b4b5','\'Title: Bring-Your-Own-EDR - Breaking Windows Process Protection to build EDR-Protected Malware
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

The core assumption of modern endpoint defense is broken. While Endpoint Detection and Response (EDR) solutions are built to restrict administrators through Protected Process Light (PPL) and anti-tampering, this research reveals an industry-wide design flaw: the \"Bring-Your-Own-EDR\" (BYOEDR) technique. We demonstrate a post-exploitation scenario where a local administrator weaponizes the EDR\'s own trusted installer to bypass its formidable defenses, establishing a self-protected malware. This shows a structural weakness in how security products handle installation and trust. We will show a complete exploit chain that any attacker can leverage to achieve arbitrary unsigned code execution within PPL boundaries.

\n\n

Ultimately, the strongest defender becomes the attacker’s most powerful tool.

\n\n

https://blog.slowerzs.net/posts/pplsystem/\nhttps://github.com/hasherezade/pe_to_shellcode/\nhttps://github.com/googleprojectzero/symboliclink-testing-tools

\n\nSpeakerBio:  Shahak Morag, Akamai
\n

Shahak Morag is currently serving as the Senior Security Researcher at Akamai, with more than seven years of experience in security research. His background includes extensive expertise in Linux kernel, embedded systems, and Windows internals.

\n\n\n\'',NULL,1293812),('2_Friday','13','13:00','13:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails\'','\'Aviv Donenfeld\'','DEF CON Talks_8e37df392c0bd39dd1d79961b55b7550','\'Title: LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

Models are starting to make security decisions that used to be written as rules. Instead of matching an input against a policy, a model reads the request and decides what to do with it. OpenSearch is one of the first to put one in production as the only thing standing between an anonymous pull request and CI pipeline secrets.

\n\n

When I reported a vulnerability, the team told me their model would catch it. So I tried to get past it the way you\'d expect, hiding the attack. The model caught all of it, and going at it head-on wasn\'t going to work.

\n\n

So I stopped trying to outsmart it and started thinking like it, reading why each attempt got caught until I understood what it could actually verify and what it only assumed. What got through in the end hid no attack, because the only dangerous part lived somewhere the model had no way to check.

\n\n

This talk walks the whole path, from first failed attempt to the bypass that worked. Along the way I mapped the model\'s decision boundary - what it catches, what slips past, and how far an input bends before its judgment flips. The deeper gap is what it never sees at all, the blind spots built into how it reads a change. You\'ll see where a model can be trusted to make this call and where it can\'t, and what that means before you put one in front of something that matters.

\n\n

https://github.com/opensearch-project/security-response/security/advisories/GHSA-2vmh-cgjm-h48x - Original pull_request_target vulnerability advisory

\n\n

https://github.com/opensearch-project/security-response/security/advisories/GHSA-q72p-66hv-cc73 - LLM gateway bypass advisory

\n\n

https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents - Prompt injection attacks against AI code review bots (different attack class)

\n\n

https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign - 500+ AI-generated malicious PRs targeting pull_request_target across hundreds of repos, including the one repo we discuss in this talk

\n\n

https://www.404media.co/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/ - Meta AI support system flaw

\n\nSpeakerBio:  Aviv Donenfeld, Check Point Software Technologies
\n

Aviv Donenfeld is a Security Researcher at Check Point Software Technologies. Before security research, he built distributed networking systems as a software engineer. His recent research centers on the attack surfaces of AI coding assistants, including critical vulnerabilities in Anthropic\'s Claude Code and Cursor. He has found CI/CD supply chain vulnerabilities in Microsoft, SAP, Red Hat, and multiple Linux Foundation projects. Beyond offensive research, he builds defensive security tools in the AI and forensics space.

\n\n\n\'',NULL,1293813),('2_Friday','13','13:30','14:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Breaking into Amazon lockers by any means necessary\'','\'Martin Vigo\'','DEF CON Talks_c7382bd908520ab43c93f594bfd70a5c','\'Title: Breaking into Amazon lockers by any means necessary
\nTags: DEF CON Official Talk | Demo 💻
\nWhen: Friday, Aug 7, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Amazon Lockers are everywhere, handling millions of packages every day. At the same time, thousands of packages get stolen from home porches every year, which made me wonder if the same thing could happen with Amazon Lockers.

\n\n

This talk is my journey trying to break into them. I started where it made the most sense, BLE. What looked straightforward quickly turned into a series of unexpected turns, with different angles, different ideas, and a lot of time spent chasing paths that didn’t go where I thought they would.

\n\n

This talk walks through that process, the dead ends, the pivots, and the techniques used along the way showing how attacking a system from different angles can expose weaknesses that aren’t obvious at first. From protocol reverse engineering and hardware hacking to mobile app security, OSINT, and physical attacks, in the end it’s about persistence, understanding how things really work, and not stopping until something gives.

\n\n

By any means necessary.

\n\n

All references are pointed in the outline to provide better context.

\n\nSpeakerBio:  Martin Vigo, Triskel Security
\n

Martín is a cybersecurity expert with 15 years of experience, having helped protect companies such as Apple, Meta, and Salesforce, including work in penetration testing, red teaming, and vulnerability research. He has led teams and worked across mobile and web security, SaaS, cloud environments, and identity and authentication.

\n\n

He is a frequent speaker at conferences including DEF CON, Black Hat, and CCC, presenting research on phreaking, vulnerabilities in password managers, new OSINT techniques, and reverse engineering of proprietary protocols.

\n\n

He runs a cybersecurity consulting firm focused on improving organizational cyber resilience via offensive security, research, and public speaking. He is also co-host of the “Tierra de Hackers” podcast.

\n\n

Martín holds a Bachelor’s in Computer Science, a Master’s in Software Engineering, and certifications in areas such as hardware hacking, exploit development, infrastructure and mobile security, radio frequency, and OSINT. He contributes to open source projects and collaborates with law enforcement on initiatives to enhance public safety.

\n\n\n\'',NULL,1293814),('2_Friday','14','13:30','14:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Breaking into Amazon lockers by any means necessary\'','\'Martin Vigo\'','DEF CON Talks_c7382bd908520ab43c93f594bfd70a5c','\'\'',NULL,1293815),('2_Friday','13','13:30','14:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Plug And Pwn: Weaponizing Windows PnP Auto-Install\'','\'Alejandro \"0xedh\" Hernando,Borja \"borjmz\" Martinez\'','DEF CON Talks_2259f8941568f05173f785870dd2bbaa','\'Title: Plug And Pwn: Weaponizing Windows PnP Auto-Install
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

Every time a USB device is plugged into a Windows machine, the OS may silently download a package from Microsoft and execute vendor code as SYSTEM. No admin required. The package is signed, so nothing looks wrong.

\n\n

We spent the better part of a year mapping this attack surface. We analyzed 7K packages approx, built tools to emulate arbitrary USB devices without hardware, and found that the same kernel code path fires when a USB device is redirected over RDP channels, meaning a non admin user can trigger SYSTEM level code execution on the target, with no physical access at all (under certain conditions).

\n\n
    \n
  • How Windows PnP search actually works, the real kernel flow, not the MSDN summary.

  • \n
  • How to make Windows believe any USB device is connected, using device emulation and composite device tricks that bypass inbox driver interception.

  • \n
  • Why RDP USB redirection (MS-RDPEUSB / URBDRC) triggers the exact same kernel PnP path as a physical plug-in, and what that means for remote exploitation.

  • \n
  • A WHQL-signed software that contains a hidden debug backdoor alowing execution as SYSTEM, chainable with other vulnerabilities for full user to SYSTEM escalation from a standard account.

  • \n
  • A forced installation leading to the creation of a named pipe that lets any authenticated network user rewrite config on any machine.

  • \n
\n\nSpeakers:Alejandro \"0xedh\" Hernando,Borja \"borjmz\" Martinez
\n
\nSpeakerBio:  Alejandro \"0xedh\" Hernando, Accenture Spain
\n

Alejandro Hernando is a red team operator and security researcher at Accenture Security\'s Hacking team in Spain, with over a decade of hands-on experience in offensive cybersecurity. Throughout his career, he has assessed, exploited, and helped mitigate security vulnerabilities across commercial and proprietary systems, developing PoC exploits, offensive and defensive tooling, and conducting deep security research. His approach combines applied research with real world operational experience, driven by a focus on continuous learning and on sharpening both attack and defense strategies.

\n\nSpeakerBio:  Borja \"borjmz\" Martinez, Accenture Spain
\n

Borja Martínez is a red team operator and security researcher at Accenture Security Hacking team in Spain, where he focuses on offensive security, advanced adversary simulation and hardware exploitation. A self-taught hacker with a deeply hands-on approach, he specializes in red team operations, penetration testing and low level attack research including DMA attacks, BIOS/UEFI exploitation, and TPM security.

\n\n\n\'',NULL,1293816),('2_Friday','14','13:30','14:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Plug And Pwn: Weaponizing Windows PnP Auto-Install\'','\'Alejandro \"0xedh\" Hernando,Borja \"borjmz\" Martinez\'','DEF CON Talks_2259f8941568f05173f785870dd2bbaa','\'\'',NULL,1293817),('2_Friday','14','14:00','14:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'8 Out of 10 Banks in Belgium HATE This One Weird eID RCE\'','\'James \"Acorn221\" Arnott\'','DEF CON Talks_bc4ccd2f7c691fbf81c760a92d0cad40','\'Title: 8 Out of 10 Banks in Belgium HATE This One Weird eID RCE
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

A major signing extension which has over 2 million users, primarily in Belgium, and lets websites interact with electronic ID (eID) and Maestro payment cards. It\'s used by \"8 of the 10 largest banks in Belgium and 60+ Belgian government agencies and departments\", and it facilitates eIDAS signatures, a cryptographically \"secure\" signature format trusted by governments and organizations.

\n\n

The company behind it, is a Qualified Trust Service Provider on the EU eIDAS Trusted List, the highest trust tier the regulation defines.

\n\n

We found multiple major issues with this system. Any site a user visited could read their eID and Maestro card data, and recover their eID PIN, which the binary handed back to the page inside a token that carried both the ciphertext and the key to decrypt it. And, worst of all, any site could trigger a drive-by RCE by getting the native binary to load and run an attacker-supplied library. All the user would see is a file download, like a PDF, when they are getting RCE\'d.

\n\n

We\'ll show how they messed literally everything possible, and more!

\n\n

https://chromewebstore.google.com/detail/connective-signing-extens/kclpjmhngbacampgcdojmiedamjbgjjm\nhttps://web.archive.org/web/20260427143606/https://www.gonitro.com/about/press/nitro-to-acquire-european-esign-leader-connective\nhttps://web.archive.org/web/20260226092908/https://www.gonitro.com/resources/nitro-to-acquire-connective

\n\nSpeakerBio:  James \"Acorn221\" Arnott, Bay Area Labs
\n

I\'m James, founder of Am I Being Pwned (amibeingpwned.com), where we hunt malicious and vulnerable browser extensions. I\'ve spent 10+ years building and breaking them, including LighterFuel, a Tinder extension that hit 10k+ weekly users and, for one glorious day, made me (probably) the most-liked man on Tinder.

\n\n

Recent finds include five drive-by CVSS 9.6 RCEs in production software affecting 10M+ users. I\'ve also published in IEEE Xplore on Rubik\'s cube-based FIDO2 authentication (CubeAuthn), because someone had to. Before this I was a founding engineer at three YC startups.

\n\n

Fun fact: I was almost kicked out of school three times for finding and exploiting vulnerabilities.

\n\n\n\'',NULL,1293818),('2_Friday','15','15:00','15:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Data Tomb Raider: Raiding Modern AI Vaults with Legacy Flaws for Treasure Stealing\'','\'Dolev Taler,Mark Vaitsman\'','DEF CON Talks_ab28e9ffc65a596051137c2ae1012a2d','\'Title: Data Tomb Raider: Raiding Modern AI Vaults with Legacy Flaws for Treasure Stealing
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Click a link, lose your MFA codes. Your AI assistant reads your email and exfiltrates the data through Bing, and you never notice.

\n\n

We found a 1-click attack chain against Microsoft 365 Copilot that combines three vulnerability classes everyone assumed were solved - CSP, SSRF, and HTML injection - into one kill shot. A URL parameter lands directly in the AI engine as an executable prompt, a vector we call Parameter-to-Prompt (P2P) injection. The AI searches the victim\'s mailbox, grabs sensitive data, and emits an img tag with the loot in the URL. That tag renders mid-stream, before the output sanitizer fires, because sanitization is a post-processing step. The img src hits Bing\'s Search by Image endpoint - CSP-allowlisted - which server-side fetches to our domain, tunneling stolen data through Microsoft\'s own infrastructure.

\n\n

CSP enforced. Sanitizer running. AI guardrails active. All three defenses in place - the chain walked right through them. None of these bugs are new. Each has textbook mitigations. But nobody tests what happens when old web bugs compose with AI behaviors - web teams and AI teams don\'t test each other\'s seams. We break down the full chain, demo it live, and hand you a methodology for hunting composition bugs across AI-integrated platforms.

\n\nSpeakers:Dolev Taler,Mark Vaitsman
\n
\nSpeakerBio:  Dolev Taler, Varonis
\n

Dolev Taler is a senior security researcher at Varonis Threat Labs with over a decade of cybersecurity experience spanning red teaming, reverse engineering, vulnerability research, and malware analysis. He is passionate about machine learning and its pivotal role in modern threat detection, having developed advanced detection models, investigated ransomware attacks for major global enterprises, and reported vulnerabilities in critical infrastructure systems. Beyond tackling high-stakes cyber threats, Dolev also enjoys perfecting the art of coffee brewing and improving his lock-picking skills.

\n\nSpeakerBio:  Mark Vaitsman, Varonis
\n

Mark Vaitsman is a Security Research Team Leader at Varonis, a leader in Data Security. He is a passionate cybersecurity expert with extensive experience in leading security threat and research teams in various Cyber Security companies, analyzing emerging threats, incident response and developing innovative solutions. Mark is also a lecturer of Cyber Security courses, sharing his knowledge and shaping the next generation of cybersecurity professionals. Previously spoken at BlackHat, DeepSec, RSAC, CrestCon. In his free time he likes sailing in the sea and riding a motorcycle.

\n\n\n\'',NULL,1293819),('2_Friday','14','14:00','14:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Lessons from a decade of building whistleblower tech\'','\'Trevor Timm,redshiftzero\'','DEF CON Talks_d0d341ef7e871f5333b4c13a0932872e','\'Title: Lessons from a decade of building whistleblower tech
\nTags: DEF CON Official Talk | Tool 🛠
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Internet pioneer Aaron Swartz’s last project was SecureDrop, a whistleblower submission system that can be used by news outlets and whistleblowers to communicate safely online. At the time of Aaron’s tragic death, SecureDrop was just a prototype, but it’s now run by Freedom of the Press Foundation and used by dozens of the biggest news outlets around the world. This talk will explore the unique technical challenges in running an anonymous whistleblower platform, the future of whistleblowing technology, and the lessons we have learned about how whistleblowers and journalists actually communicate along the way. In addition, we will preview our new project, a collaboration with the Tor Project called WEBCAT, which aims to solve code verification on web browsers and make end-to-end encryption for web applications safer.

\n\n

https://securedrop.org\nhttps://webcat.tech

\n\nSpeakers:Trevor Timm,redshiftzero
\n
\nSpeakerBio:  Trevor Timm, Freedom of the Press Foundation
\n

Trevor is a co-founder and the executive director of Freedom of the Press Foundation (FPF), and has served on its board since 2012. He is a journalist, activist, and legal analyst whose writing has appeared in The New York Times, The Guardian, USA Today, The Atlantic, Al Jazeera, Foreign Policy, Harvard Law & Policy Review, and Politico. Trevor formerly worked as an activist at the Electronic Frontier Foundation. Before that, he helped the longtime general counsel of The New York Times, James Goodale, write the book, “Fighting for the Press,” on the Pentagon Papers and the First Amendment. He received his J.D. from New York Law School. In 2013, he received the Hugh Hefner First Amendment Award for journalism.

\n\nSpeakerBio:  redshiftzero, Freedom of the Press Foundation
\n

Jennifer is the chief technology officer at Freedom of the Press Foundation (FPF), where she oversees the organization’s engineering teams. She is an engineer, researcher, and cypherpunk. Prior to this role, she was a founding engineer at Penumbra Labs, focusing on applied cryptography for privacy-preserving payments. She previously led development for the SecureDrop whistleblower platform. She also co-founded Lucy Parsons Labs, a Chicago-based civil liberties group. Jennifer has spoken at events including Hackers on Planet Earth, USENIX Enigma, and DEF CON Crypto & Privacy Village. She holds a doctorate in astrophysics from the University of Chicago.

\n\n\n\'',NULL,1293820),('2_Friday','14','14:30','14:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Lowering the Orbit: Exploiting Satellite Protocols and communications via Software-Defined-Radio and GS\'','\'Romel \"r0r0x\" Marin\'','DEF CON Talks_b1cb8d00992e355ad87df8229fe702f6','\'Title: Lowering the Orbit: Exploiting Satellite Protocols and communications via Software-Defined-Radio and GS
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Friday, Aug 7, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

The \"Security by Obscurity\" era in satellite communications is over, but the industry hasn\'t received the memo. As we shift toward COTS hardware and standardized protocols like CCSDS and Space Packet Protocol (SPP), a massive attack surface has emerged, stretching from ground stations to the satellite.

\n\n

In this talk, i will show the vulnerabilities of the modern space link. i will move beyond simple RF command injction to demonstrate a full-spectrum exploitation methodology. Using PWNSAT and PWNCUBE a high-fidelity, open-source satellite exploitation ecosystem we simulate an end-to-end mission under fire.

\n\n

I will demonstrate:

\n\n

Protocol Fuzzing, GNS spoofing and command exploiting CCSDS/SPP packet structures over LoRa/FSK.\nLateral Movement in Orbit: How a compromised RF link leads to command injection on the internal CAN bus to manipulate satellite subsystems.\nGround Segment Pivoting: Exploiting the Mission Operations Center (MOC) via radio protocol vulnerabilities.

\n\n

This is not just a tool demo; it is a deep dive into the flaws of aerospace\'s most trusted protocols. We provide the community with a \"Vulnerable-by-Design\" orbital platform to bridge the gap between cybersecurity and space engineering.

\n\nSpeakerBio:  Romel \"r0r0x\" Marin
\n

Romel Marín is a Senior Hacker and Aerospace Cybersecurity Researcher with over a decade of experience in offensive operations. He has executed complex penetration testing assessments for diverse industries and Fortune 500 companies. Currently, he specializes in applying offensive methodologies to aerospace technologies, satellite protocols, and artificial intelligence. Romel is an external collaborator for the SPARTA (Space Attack Research & Tactics Analysis) framework and serves as a co-founder of the DEF CON Costa Rica group (DC11506). A speaker at international conferences such as BlackHat, DEF CON, Typhooncon DragonJAR, and Ekoparty, his work focuses on the security analysis of aerospace infrastructure and mission-critical communications.

\n\n\n\'',NULL,1293821),('2_Friday','14','14:30','15:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'WASM Was Not the Boundary: Sandcastles, Not Sandboxes\'','\'Saar Pearl,Vladimir \"G1ND1L4\" Tokarev\'','DEF CON Talks_066b3872d9e0d5401bee300134d4b92d','\'Title: WASM Was Not the Boundary: Sandcastles, Not Sandboxes
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 14:30 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\nPyodide is often treated as a ready-made sandbox: block os, block js,
\nand untrusted Python is assumed to stay inside WebAssembly. In n8n and
\nthe other products we tested, that assumption failed. When ctypes or reflection
\nremained reachable, attacker-controlled Python could cross from
\nCPython-in-WASM into the Emscripten/JavaScript host boundary the product
\nactually relied on.
\n\n

We show this as an architectural failure, not a one-off bug. In Node.js\nembeddings, that boundary break typically becomes immediate host-side\ncode execution because the escaped code lands in a runtime with no\nnative permission model. In Deno embeddings, the same break still\nreaches the embedding runtime, but the final blast radius depends on the\npermissions the product granted; in one default configuration, that\nstill meant full RCE. In CI environments, the same mistake turns tests\nand build steps into a supply-chain risk because the escaped code runs\nnext to tokens, secrets, and release artifacts.

\n\n

Across workflow automation, spreadsheets, AI agents, desktop wrappers,\nand build tooling, we found seven escapes, two public CVEs, and multiple\nadditional disclosures. Attendees leave with a precise mental model of\nwhere Pyodide isolation actually ends, how to test similar deployments,\nand how to harden them beyond fragile denylists.

\n\n
    \n
  • Pyodide documentation. Pyodide is CPython compiled with Emscripten to\nWebAssembly and embedded in a JavaScript host; this host-embedding\nmodel is central to our analysis.\nhttps://pyodide.org/

    \n\n
      \n
    • Emscripten API documentation for emscripten_run_script*. These APIs\nare the JavaScript-execution bridge we reached from Pyodide via\nctypes.\nhttps://emscripten.org/

    • \n
    • Lehmann et al., \"Everything Old is New Again: Binary Security of\nWebAssembly,\" USENIX Security 2020.

    • \n
    • Bosamiya et al., \"Provably-Safe Multilingual Software Sandboxing using\nWebAssembly,\" USENIX Security 2022.

    • \n
    • Zhao et al., \"Remote Code Execution from SSTI in the Sandbox:\nCracking the Sandbox of Template Engines via Isolation-Aware Attack,\"\nUSENIX Security 2023.

    • \n
    • Public advisories for two instances from this research:\nCVE-2025-68668 / GHSA-62r4-hw23-cc8v (n8n)\nCVE-2026-24002 / GHSA-7xvx-8pf2-pv5g (Grist)

    • \n
  • \n
\n\nSpeakers:Saar Pearl,Vladimir \"G1ND1L4\" Tokarev
\n
\nSpeakerBio:  Saar Pearl, Cyera
\n

Saar Pearl is a security researcher at Cyera. He specializes in offensive security and vulnerability research across cloud infrastructure and SaaS platforms, focusing on identity and access controls, architectural weaknesses and exploit development.

\n\nSpeakerBio:  Vladimir \"G1ND1L4\" Tokarev, Cyera
\n

Vladimir Tokarev is a vulnerability researcher tech lead at Cyera, \n specializing in Cloud, IoT/OT, Windows, Linux, and AI vulnerability\n research and exploit. Talks: Black Hat USA 2024 and 2023,
\n DEF CON 33 Recon Village 2025, CodeBlue 2025, RSA 2024.

\n\n\n\'',NULL,1293822),('2_Friday','15','14:30','15:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'WASM Was Not the Boundary: Sandcastles, Not Sandboxes\'','\'Saar Pearl,Vladimir \"G1ND1L4\" Tokarev\'','DEF CON Talks_066b3872d9e0d5401bee300134d4b92d','\'\'',NULL,1293823),('2_Friday','15','15:00','15:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Hacking the Hackers who Hack Hackers: Supply-Chain Backdoors in Underground VPN Infrastructure\'','\'Assaf Morag\'','DEF CON Talks_337d1eec2cad1ae0f21cf432c2a21040','\'Title: Hacking the Hackers who Hack Hackers: Supply-Chain Backdoors in Underground VPN Infrastructure
\nTags: DEF CON Official Talk
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

Underground VPN and tunneling ecosystems are widely used to monetize compromised servers and sell “free internet” access through SSH, SOCKS, and multi-protocol tunnels. These operations rely heavily on open-source infrastructure management tools deployed on rented or hacked Linux servers. But what happens when the tools themselves are weaponized?

\n\n

In this talk we dissect FirewallFalcon Manager, a VPN/SSH server management toolkit widely promoted in Telegram communities. While it presents itself as a legitimate open-source platform, our analysis reveals a multi-layered supply-chain attack targeting the very operators who deploy it.

\n\n

FirewallFalcon silently installs backdoors, injects a rogue TLS root certificate, hijacks DNS resolution, and redirects proxy traffic through attacker-controlled infrastructure to enable large-scale Man-in-the-Middle interception. Earlier versions also deployed a Telegram reconnaissance bot and a universal SSH backdoor granting root access to infected servers.

\n\n

Using reverse engineering, GitHub history analysis, DNS infrastructure mapping, and large-scale internet scanning, we uncovered hundreds of active servers inside this compromised ecosystem. This talk exposes a new class of supply-chain attacks: hackers hacking the infrastructure used by other hackers.

\n\nSpeakerBio:  Assaf Morag, Flare
\n

Assaf Morag is a Cybersecurity Researcher and Threat Intelligence Consultant, working with various companies on research focused on underground ecosystems, attacker infrastructure, and the evolving cyberthreat landscape. His work translates adversary activity from open, deep, and dark-web sources into actionable intelligence for security teams and the software development life cycle. Previously, Assaf served as Director of Threat Intelligence at Aqua Security and held senior intelligence roles at BlueVoyant and IBM Security. His research has been featured in leading cybersecurity publications and presented at major industry conferences. He contributed to the MITRE ATT&CK® Container Framework and authored an O\'Reilly course on cloud-native cyber threat intelligence.

\n\n\n\'',NULL,1293824),('2_Friday','15','15:00','15:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Pwning Rekordbox: Unauthenticated filesystem access in the world\'s most popular DJ software\'','\'Christopher \"TRIODE\" Le\'','DEF CON Talks_c8e707540700acfd2cd76dcbe69ddc0d','\'Title: Pwning Rekordbox: Unauthenticated filesystem access in the world\'s most popular DJ software
\nTags: DEF CON Official Talk | Exploit 🪲
\nWhen: Friday, Aug 7, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

First public disclosure. rekordbox, the world\'s most popular DJ software, silently runs an NFS server whenever you play over the network, and it shares your whole hard drive, not just your music. Any device on the same subnet can quietly read your SSH keys, passwords, and files. It works the same on Windows, macOS, iOS, and Android. The catch: the obvious fix would break 20 years of hardware compatibility.

\n\n

This talk breaks down the PRO DJ LINK protocol, shows how any device on the wire talks its way into full filesystem access, and explains why the fix is stranger than it looks.

\n\n
    \n
  • CWE-284: Improper Access Control: https://cwe.mitre.org/data/definitions/284.html
  • \n
  • Deep Symmetry, crate-digger (Java, Pro DJ Link NFS client): https://github.com/Deep-Symmetry/crate-digger
  • \n
  • EvanPurkhiser, prolink-connect (TypeScript, Pro DJ Link library): https://github.com/EvanPurkhiser/prolink-connect
  • \n
  • Deep Symmetry, DJ Link Packet Analysis: https://djl-analysis.deepsymmetry.org/
  • \n
  • CVSS v3.1 Calculator: https://www.first.org/cvss/calculator/3.1
  • \n
  • JPCERT/CC Vulnerability Coordination: https://www.jpcert.or.jp/english/vh/report.html
  • \n
  • Digital DJ Tips, Global DJ Census / AlphaTheta market share: https://www.digitaldjtips.com/pioneer-alphatheta-industry-standard/
  • \n
\n\nSpeakerBio:  Christopher \"TRIODE\" Le
\n

TRIODE is an engineer, semi-professional DJ, and livestreamer who has performed at the last four Defcons. He discovered this vulnerability while reverse-engineering the Pro DJ Link protocol to build custom performance tooling. His background spans systems programming and network protocol analysis. This is his first Defcon talk submission.

\n\n\n\'',NULL,1293825),('2_Friday','15','15:00','15:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'The Stream Is Dead, Long Live the Stream: How HTTP/2 Lets Dead Streams Keep Servers Working\'','\'Gal Bar Nahum\'','DEF CON Talks_155ed823603e044c35bac2e96ab2870b','\'Title: The Stream Is Dead, Long Live the Stream: How HTTP/2 Lets Dead Streams Keep Servers Working
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Modern protocol bugs rarely look like flaws in the protocol itself. They show up when a clean spec meets existing server architectures. HTTP request smuggling showed this for request boundaries: implementations disagreed about where one request ended and the next began. This talk asks a similar question about HTTP/2 request lifetime: what happens when one layer thinks a request is over, while another is still working on it?

\n\n

In 2023, Rapid Reset showed the world that HTTP/2 had a problem: attackers could open and reset streams faster than servers could keep up. The disclosure triggered an industry-wide patching scramble, but patches addressed the symptom, not the root cause.

\n\n

Two years later, I disclosed MadeYouReset through CERT/CC as CVE-2025-8671, exploiting the same root cause through a different door and setting off a second round of patches across the ecosystem, including Apache Tomcat, H2O, Netty, and others.

\n\n

In this talk, I’ll show how research that started with Rapid Reset led to MadeYouReset, and how both create streams closed at the HTTP/2 layer while server-side request work continues. We’ll see why this gap exists, why fully fixing it is infeasible, and what conditions make MadeYouReset especially harmful.

\n\n

Finally, we’ll answer the question: is the next HTTP/2 abuse already waiting around the corner?

\n\n

CERT/CC VU#767506: https://kb.cert.org/vuls/id/767506\nNVD CVE-2025-8671: https://nvd.nist.gov/vuln/detail/CVE-2025-8671\nMadeYouReset blog posts: https://galbarnahum.com/made-you-reset

\n\nSpeakerBio:  Gal Bar Nahum, Tenzai
\n

Gal Bar Nahum is a security researcher at Tenzai with eight years of experience in vulnerability research, network protocol security, red teaming, and AI research.

\n\n\n\'',NULL,1293826),('4_Sunday','13','13:30','14:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Witchcraft Solver: Automated 0day Discovery in Stripped Binaries\'','\'Jonathan \"endrazine\" Brossard\'','DEF CON Talks_155ed45963b474845636abd8516477e2','\'Title: Witchcraft Solver: Automated 0day Discovery in Stripped Binaries
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Sunday, Aug 9, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

You have a stripped binary. No source. No symbols. No harness. You want a PoC. How do you get there?\nWitchcraft Solver (wsolver) is a fully automated binary-only 0day discovery pipeline.

\n\n

Phase 1 lifts the binary to LLVM IR via wunstrip (.eh_frame symbol recovery, 99.98% accuracy), runs an SSA taint pre-filter to cut targets by ~50%, then drives four parallel formal verification engines (KLEE, IKOS, SeaHorn, SMACK) to produce concrete violation witnesses - covering the entire binary in ~30 minutes, no source required.

\n\n

Phase 2 uses those witnesses to seed directed fuzzing (AFLGo) and binary-only concolic execution (SymQEMU), converting symbolic candidates into working PoCs. An optional Phase 0 handles non-Intel targets via a lifter portfolio (RetDec + Anvill + rev.ng), covering 93% of 39,364 production ELF binaries across ARM64, ARMv7, RISC-V, and s390x.

\n\n

Validated against CVE-2023-2804 (libjpeg-turbo heap-buffer-overflow): SymQEMU produces the first crash in 25 minutes from a stripped binary with zero source access.

\n\n

The tool will be released under MIT license at the conference at: https://github.com/endrazine/wsolver

\n\n

Experimental validation against the wider internet is left as an exercise to the audience...

\n\n

[1] Brossard, J. \"Unstripping Cloud Container ELF binaries.\" IEEE IC_ETC 2025. https://ieeexplore.ieee.org/abstract/document/11141058\n[2] Brossard, J. \"CVE-2023-2804 Complete Fuzzing Benchmark.\" Zenodo. doi:10.5281/zenodo.19136269\n[3] Wojtczuk, R. \"UQBTng.\" 22C3, 2005.\n[4] Poeplau, S. and Francillon, A. \"SymQEMU.\" NDSS 2021.\n[5] Böhme et al. \"Directed Greybox Fuzzing.\" CCS 2017.\n[6] Cadar et al. \"KLEE.\" OSDI 2008.\n[7] Fioraldi et al. \"AFL++.\" USENIX WOOT 2020.\n[8] Brossard, J. \"Introduction to the Witchcraft Compiler Collection.\" DEF CON 24, Las Vegas, August 2016. Video: https://archive.org/details/youtube-1cgtr7VW7gY

\n\n

Tool Source (once published at DEF CON): https://github.com/endrazine/wsolver

\n\nSpeakerBio:  Jonathan \"endrazine\" Brossard
\n

Endrazine is a returning DEF CON speaker, having previously presented the first attack against Microsoft BitLocker and TrueCrypt in 2008, the infamous Rakshasa BIOS malware in 2012, and the Witchcraft Compiler Collection reverse engineering framework in 2016. Endrazine has previously presented at premier conferences such as Black Hat, CCC, and HITB in the industry, as well as IEEE, USENIX, and ACM in academia. He currently works as CTO at MOABI, a binary analysis and vulnerability assessment firm, after having been Principal Engineer of Product Security at Salesforce (San Francisco), where he later lead the RedTeam. He is wrapping up a PhD in reverse engineering at CNAM (Paris) where he has been an Associate Professor for three years, and holds master\'s degrees in Engineering, Computer Science, and Cybersecurity.

\n\n\n\'',NULL,1293827),('4_Sunday','14','13:30','14:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Witchcraft Solver: Automated 0day Discovery in Stripped Binaries\'','\'Jonathan \"endrazine\" Brossard\'','DEF CON Talks_155ed45963b474845636abd8516477e2','\'\'',NULL,1293828),('2_Friday','15','15:30','16:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Riding for Free - Breaking Public Transport RFID at Scale\'','\'Aidan \"luu176\" Nakache\'','DEF CON Talks_097bc24f2dfdc7c728276ec2e11077ed','\'Title: Riding for Free - Breaking Public Transport RFID at Scale
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

How many of you tapped an RFID card to ride a train this year? How many of you know what\'s actually stored on it? Every transit authority in the world builds their own proprietary card formats, and not one has ever published a spec. The security model is the same everywhere: if nobody knows the format, nobody can exploit it.\nI spent two years testing that assumption. Across 50+ cities and every major contactless protocol, I reverse engineered the proprietary data formats that transit systems treat as their last line of defense. Along the way I built Metroflip, an open source transit card reader for the Flipper Zero, and found critical vulnerabilities in Spain\'s two largest transit systems that allow unlimited free travel.\nOn RENFE, Spain\'s national rail, I cracked a proprietary checksum algorithm that lets you directly modify trip counters, expiry dates, and zones on any card in the country. On T-Mobilitat, Barcelona\'s modern encrypted metro platform, I bypassed card-level crypto entirely by changing a single byte in the mobile app\'s relay, getting free trips and automatic refunds.\nI\'ll walk through the methodology, demo the RENFE exploit live on stage with a Flipper Zero, and share some hard lessons about what happens when you try to responsibly disclose vulnerabilities in infrastructure you depend on every day.

\n\n

Garcia, de Koning Gans, Muijrers, van Rossum, Verdult, Schreur,\n Jacobs. \"Dismantling MIFARE Classic.\" ESORICS 2008.\n https://flaviodgarcia.com/publications/Dismantling.Mifare.pdf\nCourtois, N. \"The Dark Side of Security by Obscurity.\" 2009.\n Darkside attack on MIFARE Classic CRYPTO1.\nAnderson, Ryan, Chiesa. \"Anatomy of a Subway Hack.\"\n DEF CON 16, 2008. (Boston CharlieCard)\nRauch, B. \"The Boston Infinite Money Glitch.\"\n DEF CON 31, 2023.\nGarcia, de Koning Gans, Verdult. \"Wirelessly Pickpocketing a\n Mifare Classic Card.\" IEEE S&P 2009.\nNXP Semiconductors. \"MIFARE DESFire EV2/EV3 Functional\n Specification.\" (restricted distribution)\nWouters, Carroll. \"Unsaflok: Hacking Millions of Hotel Locks.\"\n DEF CON 32, 2024.\nRodriguez. \"Contactless Overflow.\" DEF CON 31, 2023.\nHunt, Nakache. \"Hung Out to Dry: Airing the Dirty Laundry of\n Stored Value Washing Cards.\" 2025.\nMetrodroid project. https://github.com/metrodroid/metrodroid\nMetroflip project. https://github.com/luu176/Metroflip\nProxmark3 RRG. https://github.com/RfidResearchGroup/proxmark3\nCRC RevEng catalogue. https://reveng.sourceforge.io/crc-catalogue/

\n\nSpeakerBio:  Aidan \"luu176\" Nakache
\n

Aidan Nakache is a 17-year-old CTO at dubblefilm, where he leads software and hardware development with a focus on automation, operational efficiency, security, and scalable growth. He develops and maintains company servers, hardware systems, and transaction equipment, with much of his work centered around fintech infrastructure, system expandability, and technology migration.

\n\n

Alongside his role, he is a cybersecurity researcher and hardware hacker specializing in RFID, reverse engineering, and access-control systems. He enjoys competing in CTFs at conferences around the world and has spoken at DEF CON 33 in the Radio Frequency Hackers Sanctuary village. He shares open-source work on GitHub and continues to collaborate and grow within the field.

\n\n\n\'',NULL,1293829),('2_Friday','16','15:30','16:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Riding for Free - Breaking Public Transport RFID at Scale\'','\'Aidan \"luu176\" Nakache\'','DEF CON Talks_097bc24f2dfdc7c728276ec2e11077ed','\'\'',NULL,1293830),('2_Friday','15','15:30','16:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Your Bank Thinks I\'m You: A Complete Kill Chain Against Mobile Banking Security\'','\'Xavier \"@xaferima\" Riofrio Machado,Alex Tipan\'','DEF CON Talks_dd8956c2cce57114bb90a3fa85f911aa','\'Title: Your Bank Thinks I\'m You: A Complete Kill Chain Against Mobile Banking Security
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Friday, Aug 7, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\nMobile banking apps stack multiple security layers: RASP (runtime protection), root/jailbreak detection, anti-instrumentation, biometric KYC with liveness detection, and AI-powered anti-deepfake. Each layer promises to stop attackers. We defeated all of them -- in production apps used by millions.
\n\n

We present a full kill chain against mobile banks and digital wallet apps from a Latin American country, demonstrating how an attacker with an Android phone and open-source tools can: (1) bypass RASP and root detection using kernel-level root solutions and publicly available modules, achieving 100% evasion of OS integrity and anti-hacking controls; (2) use Frida to dynamically instrument biometric SDKs, injecting controlled frames into the liveness capture flow by hooking the \"best result\" getter and replacing the YUV buffer; (3) bypass KYC identity verification by substituting selfie images and crafting coherent template+photo payloads that the backend accepts as legitimate; and (4) generate AI-synthetic faces from photos that pass liveness detection with 0% detection rate.

\n\n

Every banking app we tested fell. The different RASPs and biometric SDKs are deployed in 30+ countries, protecting hundreds of millions of users. We\'ll show why that should worry you. Video demos included.

\n\n
    \n
  1. KernelSU Project - https://kernelsu.org
  2. \n
  3. Kitsune Magisk Fork - https://github.com/1q23lyc45/KitsuneMagisk/tree/kitsune
  4. \n
  5. Frida Dynamic Instrumentation Toolkit - https://frida.re
  6. \n
  7. JADX Decompiler - https://github.com/skylot/jadx
  8. \n
  9. RootBeerSample Root Detection Tool - https://github.com/nickcaballero/RootBeerSample (reference implementation)
  10. \n
  11. TMLP Team / GooseBt Studio - Root bypass module configurations (GitHub, publicly available)
  12. \n
  13. ImNotADeveloper - Xposed module that hides developer mode and USB debugging status from app detection - https://github.com/auag0/ImNotADeveloper
  14. \n
  15. Public KYC bypass repositories (referenced for threat landscape awareness):\n
      \n
    • https://github.com/kycbypass/Android-Phone-Bypass-KYC-verification---No-root-required
    • \n
    • https://github.com/hxreborn/biometric-bypass
    • \n
    • https://github.com/nocomp/deep-ofensive-ai
    • \n
  16. \n
\n\nSpeakers:Xavier \"@xaferima\" Riofrio Machado,Alex Tipan
\n
\nSpeakerBio:  Xavier \"@xaferima\" Riofrio Machado, Fintech Ecuador
\n

Computer Science Engineer with an MSc in Cybersecurity, specialized in offensive security, vulnerability research, and adversarial analysis, with a strong focus on mobile (Android & iOS) security.

\n\n

I identify systemic weaknesses through logical reasoning, abuse of flawed assumptions, and hands-on exploitation of complex workflows across mobile, web, and API-driven environments. My experience combines deep technical rigor with practical red teaming, allowing me to model realistic attack paths instead of theoretical risks.

\n\n

I have worked in high-demand environments such as CERN and currently contribute to securing fintech and digital wallet ecosystems, where mobile platforms are critical attack surfaces. While offense-driven by design, I translate offensive findings into concrete defensive controls that actually withstand real-world attackers.

\n\nSpeakerBio:  Alex Tipan, Fintech Ecuador
\n

Cybersecurity professional specialized in application security, with a focus on offensive analysis of mobile apps, bypassing RASP controls, and assessing facial biometric workflows. Since school, he has been self-taught in programming, hacking, Linux, networking, and cryptography, later strengthening his academic foundation through a degree in Computer Systems Engineering. He currently conducts hands-on research on protection evasion in financial applications, including advanced instrumentation techniques and validation of real-world risks in authentication processes. His work aims to translate complex technical findings into concrete defensive security improvements.

\n\n\n\'',NULL,1293831),('2_Friday','16','15:30','16:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Your Bank Thinks I\'m You: A Complete Kill Chain Against Mobile Banking Security\'','\'Xavier \"@xaferima\" Riofrio Machado,Alex Tipan\'','DEF CON Talks_dd8956c2cce57114bb90a3fa85f911aa','\'\'',NULL,1293832),('2_Friday','16','16:00','16:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Certified Re-Pwned: escalating all the way up\'','\'Daniel Monzon,Eric Labrador\'','DEF CON Talks_9699036cd2b85548954c403e0302bc87','\'Title: Certified Re-Pwned: escalating all the way up
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Four years after KB5014754 and one year after CVE-2024-49019, every hardening guide says Active Directory Certificate Services is a closed book. This talk reopens it.

\n\n

We present five new primitives — proposed as ESC18 through ESC22, extending the public ESC1–ESC17 numbering — each validated end-to-end on a fully-patched Windows Server 2025 Enterprise CA with every Microsoft-recommended mitigation applied. Every primitive starts from a Domain Users account with no ACL, GPO, or template edges, and ends at krbtgt extraction.

\n\n

Each primitive targets a different component of the post-2022 defence: the CA\'s CSR processor, the CA\'s Security-Extension writer, the KDC\'s PKINIT binder, the CA\'s Enroll-On-Behalf-Of path, and the registry-level enforcement layer everyone thinks is already hardened. Together they argue that Microsoft\'s 2022 and 2024 fixes patched specific instances of the underlying bug classes, not the classes themselves — and that at least one control has an undocumented fallback path its own documentation does not mention.

\n\n

A Certipy research fork will be released at the time of the talk to check and exploit the new techniques.

\n\n

https://posts.specterops.io/certified-pre-owned-d95910965cd2\nhttps://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf\nhttps://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16\nhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019\nhttps://posts.specterops.io/adcs-esc13-abuse-technique-fda4272fbd53\nhttps://github.com/ly4k/Certipy

\n\nSpeakers:Daniel Monzon,Eric Labrador
\n
\nSpeakerBio:  Daniel Monzon
\n

Daniel Monzón (stark0de) — Offensive Security Engineer at Halborn with 6+ years of offensive security experience across web pentesting, code review, Active Directory (on-premise and hybrid), Android/iOS mobile audits, thick-client assessments and red teaming. Holds certifications such as: OSCP, CRTP, OSWP, CREST CPSA, eMAPT, PACSP, and CARTP. Has been credited with multiple CVEs in open-source and commercial products, and currently focuses on Web3 and financial-sector security. Prior speaker at hack0n, RootedCON Málaga, DragonJARCON, and SecAdmin.

\n\nSpeakerBio:  Eric Labrador
\n

Eric Labrador is an offensive security researcher at Accenture with over 6 years of experience breaking into networks, applications, and buildings for a living. His day-to-day work covers Red and Purple Team exercises, web and API audits, Android and iOS mobile application assessments, internal and external penetration testing, physical intrusions into corporate buildings, and large-scale phishing campaigns. He holds the OSCP, CRTE, CRTO, BSCP, and eWPTXv2 certifications, and is the author of ImagePanick, an open-source exploit chain that achieves arbitrary file write and remote code execution by combining weak default policies in ImageMagick with SAFER bypasses in Ghostscript, all triggered from a malicious SVG. Over the years he has delivered end-to-end attack paths that chain phishing, external footholds, lateral movement, and physical entry into full compromise across multiple industries, helping clients understand what a motivated attacker can actually do with the people, processes, and technology already in place.

\n\n\n\'',NULL,1293833),('2_Friday','16','16:00','16:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Hacking the EOD Bot: How I Learned to Stop Worrying and Love the Boomba\'','\'Patrick \"gigstorm\" Kiley,Emily \"@astradotpng\" Astranova\'','DEF CON Talks_0adfb0c24fd8273341585e33b33afacf','\'Title: Hacking the EOD Bot: How I Learned to Stop Worrying and Love the Boomba
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

What happens when you wander into a surplus store and walk out with a bomb disposal robot? You name him “Boomba” and tear him apart. Built by Roomba creator iRobot, the PackBot is often used by agencies who need to deploy a small, ruggedized robot in potentially dangerous locations. But beneath its rugged shell lies a fascinating time capsule of early 2000s engineering. As the platform\'s physical capabilities evolved to meet extreme operational demands, its core software trailed behind, relying on legacy hardware and an architecture built before modern security controls.\nThis talk is a full-stack teardown of a six-figure tactical asset. We\'ll explore its 25-year evolution: mapping undocumented interfaces, fabricating custom cables, and replacing legacy 4.9 GHz restricted-band radios with custom hardware. We will dive into the software to expose unencrypted VPN connections and entirely plaintext Python 2.5 control protocols. We will also demonstrate vulnerabilities that grant full root access.\nFinally, we’ll decompile its modern tablet control app, breaking down the JAUS protocol to reveal a critical command injection vulnerability. With a live PackBot on stage, we’ll intercept telemetry, pop the LFI, and eavesdrop on network traffic. Watch Boomba get turned back into a vacuum, and catch him later at the Car Hacking

\n\nSpeakers:Patrick \"gigstorm\" Kiley,Emily \"@astradotpng\" Astranova
\n
\nSpeakerBio:  Patrick \"gigstorm\" Kiley, Google
\n

Patrick Kiley is a Security Consultant doing embedded security testing and has over 20 years of information security experience. Patrick has performed research in avionics security, vehicles, and even managed to brick his Tesla making it go faster. Patrick has a patent pending on a embedded security access tool and loves tearing things apart while figuring out how they work.

\n\nSpeakerBio:  Emily \"@astradotpng\" Astranova, Google
\n

Emily is a security consultant doing physical security testing, covert entry and penetration testing of all the things. Emily has intentionally compromised US power grid systems, unintentionally compromised data centers and has somehow managed to keep her record to only one run-in with the FBI. In her spare time, Emily volunteers as a software and cybersecurity mentor for high school students as a part of FIRST Robotics.

\n\n\n\'',NULL,1293834),('2_Friday','16','16:00','16:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'The Sandbox is a Suggestion: Deconstructing AI Agent Sandboxes\'','\'Elad Meged\'','DEF CON Talks_4cb609aa89c6c96a6f2620620215e60f','\'Title: The Sandbox is a Suggestion: Deconstructing AI Agent Sandboxes
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Every major AI coding agent ships inside a containment system. I analyzed three of them - Anthropic\'s Claude Code, Google\'s Gemini CLI, and OpenAI\'s Codex CLI - and each one breaks on its own terms.

\n\n

Each sandbox uses a different containment model: permission-based access control, process-level environment sanitization, and kernel-level filesystem enforcement. Each makes a structural assumption about what the runtime will do. Each assumption is wrong.

\n\n

This talk deconstructs all three architectures, shows what each claims to enforce, and demonstrates how the containment fails - not through prompt injection or model persuasion, but through gaps in the design itself. Every exploit is deterministic, demo-ready, and was reported through coordinated disclosure.

\n\n

Attendees leave with a reusable methodology for evaluating any AI agent sandbox: identify the containment mechanism, read the enforcement code, find the structural assumption it depends on, and test whether the runtime violates it. The cross-vendor comparison shows that different engineering teams, solving the same problem independently, make structurally similar mistakes - and that the pattern is predictable once you know where to look.

\n\nSpeakerBio:  Elad Meged, Novee Security
\n

Elad Meged is a Founding Engineer and Security Researcher at Novee Security, specializing in offensive security research and AI security. He holds an M.Sc. in Computer Science and has a background in vulnerability research across web, mobile, and low-level systems, with experience in reverse engineering and platform internals. His current work applies offensive research methodology to AI systems while developing AI-driven approaches to vulnerability discovery and exploit verification.

\n\n\n\'',NULL,1293835),('2_Friday','16','16:30','17:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'CloudBashing: Exploiting free CloudShells for mining, networking, exfil, and persistence at scale\'','\'Jenko \"edleft\" Hwong,Chris Ryan\'','DEF CON Talks_755ab3f8b67321513038a26d95af6520','\'Title: CloudBashing: Exploiting free CloudShells for mining, networking, exfil, and persistence at scale
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Friday, Aug 7, 16:30 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

CloudBashing started with reversing the private AWS, Azure, and GCP CloudShell REST and websocket terminal protocols, then tracing and analyzing janky browser authentication/credential flows from cookies to OAuth tokens. Along the way, we automated the APIs to access free CPU/networking, maintained access across container/VM resets, utilized persistent $HOME for implants/data, locked users out of sudo access, and installed a C2 framework. We discovered IAM design issues like: AWS role assumption that result in a large # of environments per compromised identity, web socket sessions that survive API token revocation, and M365/Gmail consumer email accounts that have default CloudShell access. This turned into a newly released exploit toolkit, CloudBasher, that enumerates, validates, installs, and runs distributed workloads with virtual storage and private networking across a large-scale agent network with persistence and resilience. We\'ll demo distributing CPU-intensive workloads, using virtual storage for staging/exfiltration, secure networking for proxy and obfuscated exfil paths, while automating the discovery, enumeration, creation of CloudShell environments from initial credentials/sessions to implants/setup/networking to management and control.

\n\n

Amazon Web Services, \"AWS CloudShell service authorization reference,\"\n https://docs.aws.amazon.com/service-authorization/latest/reference/list_awscloudshell.html

\n\n

Amazon Web Services, \"AWS Systems Manager StartSession API (SSM framing basis),\"\n https://docs.aws.amazon.com/systems-manager/latest/APIReference/API_StartSession.html

\n\n

Google Cloud, \"Cloud Shell API v1 REST reference,\"\n https://docs.cloud.google.com/shell/docs/reference/rest/v1/users.environments

\n\n

Microsoft Azure, \"Azure Cloud Shell overview,\"\n https://docs.microsoft.com/en-us/azure/cloud-shell/overview

\n\n

OSRU @ ronin.ae, \"AWS CloudShell analysis: privileged container, exposed block devices and container escape(s),\"\n October 23, 2023, https://web.archive.org/web/20240912135502/https://ronin.ae/news/aws-cloudshell-analysis/

\n\n

Aidan Steele, \"Deep dive into AWS CloudShell,\"\n awsteele.com, January 11, 2024, https://awsteele.com/blog/2024/01/11/deep-dive-into-aws-cloudshell.html

\n\n

Paul Schwarzenberger, \"CloudShell slip-up: command-line access to underlying AWS infrastructure,\"\n Medium, October 15, 2024, https://medium.com/@paulschwarzenberger/cloudshell-slip-up-command-line-access-to-underlying-aws-infrastructure-ae77a0858088

\n\n

Rhino Security Labs, \"AWS CloudShell Lateral Movement,\"\n https://rhinosecuritylabs.com/aws/cloudshell-lateral-movement/

\n\n

Eduard Agavriloae, \"notyet: AWS IAM Credential Revocation Gaps,\"\n offensai, https://www.offensai.com/blog/notyet-aws-iam-credential-revocation-gaps

\n\n

Dan Vittegleo, cloudshell-store,\n GitHub Repository, https://github.com/dan-v/cloudshell-store

\n\n

FrancescoDiSalesGithub, \"Google-cloud-shell-hacking,\"\n GitHub Repository, https://github.com/FrancescoDiSalesGithub/Google-cloud-shell-hacking

\n\n

Bipin Jitiya, \"Google Cloud Shell Container Escape,\"\n Medium, December 14, 2025, https://medium.com/@win3zz/google-cloud-shell-container-escape-b69ffb46b5df

\n\n

Bertrand Martel, \"AWS SSM Session: JavaScript library for AWS Systems Manager Session Manager,\"\n GitHub, https://github.com/bertrandmartel/aws-ssm-session

\n\n

Amazon Web Services, \"Amazon SSM Agent: agentmessage.go,\"\n AWS GitHub Repository, https://github.com/aws/amazon-ssm-agent/blob/c65d8ac29a8bbe6cd3f7cea778c1eeb1b06d49a3/agent/session/contracts/agentmessage.go

\n\n

SentinelOne, \"CVE-2026-32169: Azure Cloud Shell SSRF Vulnerability,\"\n SentinelOne Vulnerability Database, March 19, 2026, https://www.sentinelone.com/vulnerability-database/cve-2026-32169/

\n\nSpeakers:Jenko \"edleft\" Hwong,Chris Ryan
\n
\nSpeakerBio:  Jenko \"edleft\" Hwong, Huntress Labs
\n

Jenko Hwong is a Principal Security Researcher at Huntress Labs, focusing on identity-based attacks and cloud abuse. Prior to Huntress, he spent 6 years at Netskope Threat Labs, has spoken at RSA and DEFCON, and is a Cloud Village Lead. He has over 20 years at various security startups in cloud detection/response, vulnerability scanning, AV/AS, pen-testing/exploits, L3/4 appliances, threat intel, and windows security.

\n\nSpeakerBio:  Chris Ryan, Huntress Labs
\n

A series of oddly configured server banners, a JARM fingerprint, curious fields in a security certificate - these aren\'t just technical details, but are instead threads in a narrative tapestry woven like a John le Carre novel. For over 20 years, Chris has dedicated his life to studying these threads and the intersection between cybersecurity, Russian linguistics, and free and open source software. His career path has taken detours through academia, aerospace and defense, software development, and cybersecurity.

\n\n\n\'',NULL,1293836),('2_Friday','17','16:30','17:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'CloudBashing: Exploiting free CloudShells for mining, networking, exfil, and persistence at scale\'','\'Jenko \"edleft\" Hwong,Chris Ryan\'','DEF CON Talks_755ab3f8b67321513038a26d95af6520','\'\'',NULL,1293837),('2_Friday','16','16:30','17:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'noRecognition: Could a pattern on your clothing fool Facial Facial Recognition?\'','\'Bill \"hevnsnt\" Swearingen\'','DEF CON Talks_1f468342f475b0d1d1eba551a08a1a9b','\'Title: noRecognition: Could a pattern on your clothing fool Facial Facial Recognition?
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Friday, Aug 7, 16:30 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

You are being watched. Not in the vague, philosophical sense. Right now. The ATM you used this morning. The gas pump. Every doorbell on your block. The 125 smart streetlights you walked past on your way to lunch. You are indexed, cataloged, and matched against databases you never consented to join, by AI models that are wrong more often than the vendors will ever admit.

\n\n

Other solutions to this involves looking ridiculous. Face paint. IR glasses. Masks. Real-time deepfake software running on your phone. Congrats, you defeated the algorithm AND ensured every human within 50 feet is staring at you. Super subtle.\nI built something different. noRecognition is a genetic algorithm that breeds adversarial patterns, printed on ordinary fabric, that defeat the entire facial recognition pipeline: person detection, face detection, and identity recognition across 10 models used by Clearview AI, Axon, Hikvision, and Palantir. No electronics. No software. You look like a person wearing a scarf. The AI sees nothing.

\n\n

I will demonstrate this live on stage. One camera. One scarf. Zero detections.\nCome watch me disappear.

\n\nSpeakerBio:  Bill \"hevnsnt\" Swearingen, SecKC
\n

Bill Swearingen (hevnsnt) has been in the hacking scene for decades, and you can tell by the way he looks. He spoke at DEF CON 27 with \"HAKC THE POLICE,\" which became one of the most watched DEF CON talks of all time. He is the founder of SecKC, the world\'s largest monthly security meetup. When he is not trying to make himself invisible to surveillance cameras, he builds things that break other things, preferably with cheap hardware and undeserved confidence.

\n\n

noRecognition is his current obsession. He built the fuzzer, the genetic algorithm, the distributed network, and the pattern library. He has been saving the findings for this stage.

\n\n\n\'',NULL,1293838),('2_Friday','17','16:30','17:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'noRecognition: Could a pattern on your clothing fool Facial Facial Recognition?\'','\'Bill \"hevnsnt\" Swearingen\'','DEF CON Talks_1f468342f475b0d1d1eba551a08a1a9b','\'\'',NULL,1293839),('2_Friday','17','17:00','17:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Gotta Catch \'Em All: How To Capture 3.5 Billion WhatsApp Accounts\'','\'Maximilian Guenther,Gabriel Gegenhuber\'','DEF CON Talks_d73416aebf983d75f5953d0690dfcd78','\'Title: Gotta Catch \'Em All: How To Capture 3.5 Billion WhatsApp Accounts
\nTags: DEF CON Official Talk | Exploit 🪲
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Contact discovery on instant messengers is designed to help users find their friends. But when identifiers are predictable and safeguards are weak, it allows attackers to find everyone. At that point, \"catching \'em all\" stops being a slogan and becomes an engineering problem.

\n\n

In this talk, we show how we turned WhatsApp into a global Pokédex. By combining reverse-engineered API access with large-scale phone number generation, we probed tens of billions of candidates and identified over 3.5 billion active WhatsApp accounts --- all from a single machine, without raising flags and getting blocked.

\n\n

Beyond simple presence checks, enumeration exposes rich metadata, including profile pictures, public keys, device information, timestamps, and user-defined about tags. This enables both macroscopic insights into global platform usage and profiling of individual users.

\n\n

Our analysis uncovers systemic issues, such as persistent exposure of numbers from historical data leaks and reuse of cryptographic keys across accounts. Moreover, we expose signals of criminal activity (e.g., drug dealers and scam factories), and measurable activity in regions where WhatsApp is officially restricted (e.g., North Korea).

\n\n

At global scale, small design decisions become big problems. This is what allowed us to complete our 3.5B-sized Pokédex.

\n\n

https://github.com/sbaresearch/whatsapp-census

\n\n

Paper: Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and Privacy, Gegenhuber et al., NDSS 2026

\n\nSpeakers:Maximilian Guenther,Gabriel Gegenhuber
\n
\nSpeakerBio:  Maximilian Guenther, SBA Research
\n

Max Guenther is master student at University of Vienna. He is a cybersecurity nerd and research engineer at XBow. Previously, he was security analyst at Austrian Power Grid and security researcher at the Austrian Armed Forces.

\n\nSpeakerBio:  Gabriel Gegenhuber, University of Vienna
\n

Gabriel is working on measuring cellular networks, mobile communication and the Internet. In recent years, his research has examined security and privacy issues in global instant messaging platforms that use end-to-end encryption, such as WhatsApp and Signal. He completed his bachelor\'s and master\'s degrees at TU Wien and his PhD at the University of Vienna. He is currently a postdoctoral researcher at IT:U Linz.

\n\n\n\'',NULL,1293840),('2_Friday','17','17:00','17:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Hacking AI\'','\'Bruce Schneier\'','DEF CON Talks_596624a75ceb4c1f819d43650cdd207a','\'Title: Hacking AI
\nTags: DEF CON Official Talk
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Humans are hacking AI systems. Humans are hacking with AI systems. But also, AIs are hacking human systems. They’re finding and exploiting vulnerabilities in computer code, and they’ll soon be doing the same with all sorts of other codes. For example: the tax code can be hacked. Vulnerabilities are called loopholes, exploits are called tax avoidance strategies, and black hats are called accountants. Similarly, financial markets can be hacked. So can any system of rules or laws, including democracy itself. AIs will hack these systems at our request, and they’ll also do this innately, organically – and possibly in ways we don’t immediately see. We need to consider a world where increasingly sophisticated hacks or our social, economic, and political systems are discovered computer speeds, and then exploited at computer scale and scope. Right now, our systems of patching these systems operate at a human pace, which won\'t be good enough.

\n\n

https://www.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html

\n\nSpeakerBio:  Bruce Schneier, Advisory Board Member at VerifiedVoting.org
\n

Bruce Schneier is an internationally renowned security technologist, called a “security guru” by the Economist. He is the New York Times best-selling author of 14 books – including Rewiring Democracy and A Hacker’s Mind -- as well as hundreds of articles, essays, and academic papers. His long-running newsletter and blog, “Schneier on Security,” is one of the most popular sources of cybersecurity news on the internet. Schneier is a Fellow and Lecturer in Public Policy at the Harvard Kennedy School and the Munk School at the University of Toronto. He is a fellow at the Berkman-Klein Center for Internet and Society at Harvard University, a board member of the Electronic Frontier Foundation and AccessNow, and an advisory board member of EPIC and VerifiedVoting.org. He is also the Chief of Security Architecture at Inrupt, Inc.

\n\n\n\'',NULL,1293841),('2_Friday','17','17:00','17:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'One Chain to Own Them All — Breaking AI Infrastructures\'','\'Ji\'an \"azraelxuemo\" Zhou,Lei \"llfamsec\" Lu\'','DEF CON Talks_95a0455b43fb57576b0ec34d9c3d917d','\'Title: One Chain to Own Them All — Breaking AI Infrastructures
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

2025 marks the dawn of AI security. Pwn2Own Berlin launched its first AI track, featuring Ollama and Triton Inference Server, while ZeroDay.Cloud introduced new challenges targeting vLLM and Ollama. These competitions pushed us to take a closer look at the security of core AI infrastructures.\nvLLM exposes limited API functionality by default — until we discovered that its completions endpoint accepts prompt_embeds, which are loaded via torch.load with weights_only enabled. We had previously disclosed CVE-2025-32434, a bypass for the weights_only mechanism; after it was patched, we wondered: could we succeed again? This led us to a heap overflow vulnerability that bypasses weights_only entirely (CVE-2026-24747), which we leveraged to compromise vLLM.\nThis finding overturned a common assumption: that PyTorch flaws only enable model poisoning, requiring victims to load malicious models locally. In fact, many AI applications expose APIs that invoke torch.load for routine operations such as model loading and LoRA fine-tuning — turning a \"local\" vulnerability into a remote one. After mapping this attack surface, we developed exploits against ComfyUI, NVIDIA Dynamo and others.\nIn this talk, we\'ll walk through the discovery of this new PyTorch weights_only bypass and demonstrate its exploitation across AI infrastructures.

\n\nSpeakers:Ji\'an \"azraelxuemo\" Zhou,Lei \"llfamsec\" Lu
\n
\nSpeakerBio:  Ji\'an \"azraelxuemo\" Zhou
\n

He focuses on Java security and AI security, and his work has helped many high-profile vendors—including Google, Amazon, Cloudera, IBM, Microsoft, Oracle, among others. He has presented at Black Hat Europe 2024, Zer0Con 2025, Off-by-One Con 2025, Black Hat USA 2025, DEFCON 33 and Zer0Con 2026.

\n\nSpeakerBio:  Lei \"llfamsec\" Lu
\n

He has focuses on application and system security. He has reported many vulnerabilities to Linux, AMD, Apple, Microsoft, etc. He has presented at PHDays 2025.

\n\n\n\'',NULL,1293842),('2_Friday','17','17:30','17:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Breaking Hardware CFI with Sigreturn\'','\'Omri \"beta_b0t\" Ben Bassat\'','DEF CON Talks_52ee66700b71e776c88ef9535858aa7f','\'Title: Breaking Hardware CFI with Sigreturn
\nTags: DEF CON Official Talk | Demo 💻
\nWhen: Friday, Aug 7, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Modern ARM64 systems rely on hardware Control-Flow Integrity (CFI) such as PAC and BTI to kill classic ROP/JOP exploits. Indirect branches must land on valid targets, returns are signed, and arbitrary jumps are supposed to be over.

\n\n

Except… it isn’t.

\n\n

In this talk, we show that, by design, there is a fundamental gap between POSIX signal handling and hardware CFI. Sigreturn acts as a built-in, kernel-assisted CFI bypass primitive, enabling arbitrary control-flow transfers via crafted signal frames while bypassing CFI enforcement.

\n\n

We then explore what makes this work in practice on modern Linux and Android systems (including latest Ubuntu and Pixel devices): using sigreturn as a practical exploitation primitive, then pivoting with \"\"cfi-safe stack pivots\"\", abusing missing BTI enforcement on the vDSO, and leveraging GCC’s common default settings.

\n\n

I\'ll present a PoC showing how these primitives can be chained in classic SROP style, and demonstrate how you can extend COOP/CFOP beyond function-level control to achieve reliable arbitrary code execution, effectively breaking CFI again and again.

\n\n
References
\n\n
    \n
  • SROP

    \n\n
      \n
    • \"Framing Signals—A Return to Portable Shellcode\", Erik Bosman & Herbert Bos, IEEE S&P 2014. Link: https://www.cs.vu.nl/~herbertb/papers/srop_sp14.pdf
    • \n
  • \n
  • COOP

    \n\n
      \n
    • \"Counterfeit Object-oriented Programming\", Schuster et al., IEEE S&P 2015. Link: https://www.ieee-security.org/TC/SP2015/papers-archived/6949a745.pdf
    • \n
  • \n
  • CFOP

    \n\n
      \n
    • \"Await() a Second: Evading Control Flow Integrity by Hijacking C++ Coroutines\", Marcos Bajo and Christian Rossow, CISPA Helmholtz Center for Information Security, Usenix 2024. Link: https://www.usenix.org/conference/usenixsecurity25/presentation/bajo
    • \n
  • \n
\n\nSpeakerBio:  Omri \"beta_b0t\" Ben Bassat, Tel Aviv University
\n

Omri Ben-Bassat is a vulnerability researcher with over a decade of experience in reverse engineering, vulnerability finding, binary exploitation, and low-level vulnerability analysis, specializing in IoT and embedded systems. He has presented his work at leading security conferences, including Black Hat USA, Black Hat Asia, and RSA Conference, and has delivered awesome hands-on trainings at Black Hat Asia and TyphoonCon. Omri is currently pursuing a master\'s degree at Tel Aviv University, where his research focuses on applying formal methods to software exploitation.

\n\n\n\'',NULL,1293843),('2_Friday','17','17:30','17:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'You\'ve Got Mail (That Was Meant For No One)\'','\'Cøry \"interpünkt\" Solovewicz\'','DEF CON Talks_e8802a09c370a0eee4754d88e9326e6d','\'Title: You\'ve Got Mail (That Was Meant For No One)
\nTags: DEF CON Official Talk | Tool 🛠
\nWhen: Friday, Aug 7, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

In 2020, I registered a domain on a whim, mostly because I thought it would be hilarious for email, and then forgot about it. Then a city government faxed me their internal documents. Then an organization started sending me Cisco UCM alerts. Then 363,000 emails arrived in sixteen months. I never sent a single packet of attack traffic.\nThe vulnerability is an assumption, that a domain nobody owns is safe to hardcode. Developers at enterprise software vendors, government agencies, and companies made that assumption. I registered the domains and the mail flowed in.\nThis talk covers six years of passive email interception across more than 20 domains, the tooling built to systematically map this attack surface across hundreds of TLDs, and what 400,000 misdirected emails reveal about how production mail infrastructure actually fails. No exploits. No credentials. Just a $11 domain registration.

\n\n

Sheward, M. \"Deleteduser.com -- a $15 PII Magnet.\" Medium, April 2026.\n https://mike-sheward.medium.com/deleteduser-com-a-15-pii-magnet-c4396eb21061

\n\n

Krebs, B. \"They Told You Not To Reply.\" Washington Post Security Fix, March 2008.\n https://web.archive.org/web/20200905092128/http://voices.washingtonpost.com/securityfix/2008/03/they_told_you_not_to_reply.html

\n\n

Krebs, B. “Chipotle Serves Up Chips, Guac & HR Email.” Krebs on Security, 16 Nov. 2015,\n https://krebsonsecurity.com/2015/11/chipotle-serves-up-chips-guac-hr-email/

\n\n

Fitzpatrick, J. “Sears-Kmart MyGofer,” Internet Archive, archived May 1, 2014,\n https://web.archive.org/web/20140501153309/http://sears-kmart-mygofer.com/

\n\n

Kim, P. and Gee, G. \"Doppelganger Domains.\" Godai Group, 2011.\n https://godaigroup.net/wp-content/uploads/doppelganger/Doppelganger.Domains.pdf

\n\n

Szurdi, J. and Christin, N. \"Email Typosquatting.\" IMC 2017. ACM.\n https://dl.acm.org/doi/10.1145/3131365.3131399

\n\n

Internet Assigned Numbers Authority. \"RDAP Bootstrap File for Domain Name Space.\"\n https://data.iana.org/rdap/dns.json (RFC 7484)

\n\n

Bradner, S., \"RFC 2606: Reserved Top Level DNS Names\", IETF, 1999\n https://www.rfc-editor.org/rfc/rfc2606

\n\n

Klensin, J., \"Simple Mail Transfer Protocol\", RFC 5321, IETF, October 2008.\n https://www.rfc-editor.org/rfc/rfc5321

\n\n

DomainTools. \"TLD Registration Count Statistics.\"\n https://research.domaintools.com/statistics/tld-counts/

\n\nSpeakerBio:  Cøry \"interpünkt\" Solovewicz
\n

Cory Solovewicz (aka interpünkt) is a security consultant specializing in web and mobile application testing. His path into security started early, experimenting with tools like Sub7 and learning how systems could be pushed beyond their intended use. After a career in full-stack development, he transitioned into security to focus on breaking and improving real-world systems. He brings a builder’s perspective to his work, shaped by years of coding, late nights in hackerspaces, and a curiosity for how things fail.

\n\n\n\'',NULL,1293844),('3_Saturday','10','10:00','10:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'From Wind Farm to CHP Plant: The Untold Story of Lateral Movement in a Polish Energy Sector Attack\'','\'Marcin Dudek\'','DEF CON Talks_f4eb1f36a4597f8dd4f6fe51ed6c38e1','\'Title: From Wind Farm to CHP Plant: The Untold Story of Lateral Movement in a Polish Energy Sector Attack
\nTags: DEF CON Official Talk
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

On December 29, 2025, Poland’s energy sector was hit by what we believe was the first destructive cyber sabotage attack against energy infrastructure in NATO. Our public report described attacks against 30 renewable energy sites and a large combined heat and power plant. But one piece of the incident was still missing - and it led to an attack path we had never seen in the wild before.

\n\n

This talk goes behind the scenes of the investigation into a second, smaller CHP plant affected during the same campaign. What first looked like human error turned into a three-month hunt through false leads, forgotten remote access devices, wiped industrial hardware, cellular connectivity, and infrastructure that was assumed to be isolated.

\n\n

The talk ends with lessons on private APN security, OT incident response, and handling large-scale cyber incidents involving critical infrastructure.

\n\nSpeakerBio:  Marcin Dudek, CERT.PL
\n

Marcin Dudek leads CERT Polska, Poland’s national CERT. Before taking on this role, he spent more than a decade in hands-on technical work across OT security, incident response, and APT investigations. His background includes industrial control systems security in critical infrastructure environments, including Poland’s only research nuclear reactor, as well as analysis of APT activity targeting Poland. He regularly speaks at local and international cybersecurity conferences and was deeply involved in the response to the incident described in this talk.

\n\n\n\'',NULL,1293845),('3_Saturday','10','10:00','10:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Identity Crisis: Novel Vulnerabilities leading to Kerberos Downgrade, DoS, and Full Domain Takeover\'','\'Shai Laron\'','DEF CON Talks_2669ca3fa06dbe2a0a3abdd8776ab668','\'Title: Identity Crisis: Novel Vulnerabilities leading to Kerberos Downgrade, DoS, and Full Domain Takeover
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Active Directory remains a major component of modern enterprise networks, and its security is paramount. Active Directory attack campaigns often aim to achieve Domain Admin privileges, which allow complete control over the domain.\nBut what if we could simply confuse domain controllers, causing them to identify us as someone else? \nIn this talk, we’ll dive into Kerberos and Active Directory and show how curiosity and creative thinking led to the discovery of two new identity confusion vulnerabilities.\nThe first vulnerability, KerberLoss (CVE-2026-25177), bypasses a forest-wide security mechanism to perform a Denial of Service, or even force authentication to downgrade from Kerberos to NTLM.\nWe later discovered ResetNightmare (CVE-2026-27912): a logical flaw in a Kerberos mechanism, allowing low-privileged users to compromise any account in the domain, including domain admins, leading to full domain takeover. The vulnerability is surprisingly easy to exploit and has a single, common prerequisite, making it highly dangerous for unpatched environments.\nWe’ll explain the vulnerabilities, show them in action, and share practical detection opportunities and mitigation strategies to reduce exposure. In addition, we’ll be releasing a tool that automatically runs the entire attack flow for simple experimentation and testing.

\n\nSpeakerBio:  Shai Laron, Semperis
\n

Shai Laron is a Security Researcher with 6 years of experience, focusing on Active Directory, Windows, and Identity Security, working at Semperis\' Research team.\nHe has a strong passion for researching Kerberos and has discovered multiple vulnerabilities related to it.

\n\n\n\'',NULL,1293846),('3_Saturday','10','10:00','10:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Memory Laundering via Metal: What EDR Can\'t See on Your Mac\'','\'Hxr1\'','DEF CON Talks_7cb2f25ad3551942ead586714e372227','\'Title: Memory Laundering via Metal: What EDR Can\'t See on Your Mac
\nTags: DEF CON Official Talk | Demo 💻
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

DEF CON Abstract

\n\n

Metal is Apple\'s GPU framework, it replaced OpenGL and is now the only way to talk to the GPU on macOS. Among its buffer types is StorageModePrivate: memory managed entirely by the GPU. The CPU can\'t read it, write to it, or map it into virtual address space.

\n\n

macOS endpoint security scans process memory through mach_vm_region and task_for_pid. Apple\'s own Endpoint Security framework watches mappings via ES_EVENT_TYPE_NOTIFY_MMAP. None of them see StorageModePrivate buffers. Those pages live in GPU firmware page tables, allocated through IOGPUDevice in the IOAccelerator family, completely outside Mach VM. No API exists to let a security tool inspect them from another process.

\n\n

I turned this gap into a working evasion technique. Incoming payload gets XOR-encoded to destroy signatures, staged through a shared MTLBuffer, then blitted into private GPU memory via MTLBlitCommandEncoder on AGXCommandQueue. All CPU-side artifacts get wiped, volatile pointers, _syncsynchronize barriers, multi-pass zeroing. At that point the data exists only in pages no process on the box can read. When I need it back, I reverse the blit, decode, execute, and wipe again. Total CPU exposure is milliseconds.

\n\n

Tested on the latest Apple Silicon hardware. 100% evasion. No entitlements, no kexts, no root. Runs from a sandbox

\n\n

Apple Metal Framework Documentation:MTLBuffer, MTLResourceStorageModePrivate, MTLBlitCommandEncoder\nhttps://developer.apple.com/documentation/metal

\n\n

Apple Endpoint Security Framework Documentation: ES_EVENT_TYPE_NOTIFY_MMAP https://developer.apple.com/documentation/endpointsecurity

\n\n

Apple Silicon Unified Memory Architecture: Apple Platform Security Guide https://support.apple.com/guide/security/welcome/web

\n\n

IOKit IOAccelerator Family: GPU driver interface for macOS kernel subsystem\nhttps://developer.apple.com/documentation/iokit

\n\nSpeakerBio:  Hxr1
\n

15+ years specializing in Red Teaming, Adversary Emulation, and Application Security. Proven track record executing advanced offensive operations across enterprise environments. Active contributor to the cybersecurity community focused on evolving offensive tradecraft and automating purple team capabilities.

\n\n\n\'',NULL,1293847),('3_Saturday','10','10:00','10:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'No Socket, No Privs, No Problem: Weaponizing OCI Registries for SSRF, Credential Theft, and Container Escapes\'','\'David \"davidrxchester\" Rochester,Nicholas \"gouldnicholas\" Gould\'','DEF CON Talks_ae2ad862c994eb2d03d84fe5ec04762a','\'Title: No Socket, No Privs, No Problem: Weaponizing OCI Registries for SSRF, Credential Theft, and Container Escapes
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

Every day, developers and ML engineers pull containers and models from OCI registries without a second thought. What if that pull, no privileges, no special access, could be turned into host enumeration, credential theft, remote code execution, or even a container escape?

\n\n

We found a class of vulnerabilities that spans the OCI ecosystem. Not just in registry clients, but in the underlying technologies they feed into, container runtimes, ML inference engines, and more. By standing up malicious registries and abusing how these tools handle registry responses, we turned routine pull operations into attack primitives. The result: multiple critical vulnerabilities across widely used tools and platforms, including SSRFs, arbitrary file reads for credential exfiltration, and a novel path to escaping a Docker container to the underlying host.

\n\n

What do they all have in common? They all either use or offer OCI services through a client or a registry. This talk walks through the different attack paths we’ve found, how they were discovered, trends we’ve noticed across multiple products, proof-of-concepts, and what it means for the ecosystem moving forward.

\n\nSpeakers:David \"davidrxchester\" Rochester,Nicholas \"gouldnicholas\" Gould
\n
\nSpeakerBio:  David \"davidrxchester\" Rochester, Booz Allen Hamilton
\n

David Rochester is a penetration tester by day, where he focuses on web, cloud, network, and Active Directory security. He earned his B.S. in Computer Science from Clemson University and is currently pursuing a master\'s at the University of Texas at Austin. He holds the OSCP, OSWE, and CRTO, along with several cloud security certifications. As an independent security researcher, his vulnerability research and exploitation work has produced eight CVEs to date, including findings in Docker and Ollama.

\n\nSpeakerBio:  Nicholas \"gouldnicholas\" Gould, Booz Allen Hamilton
\n

Nicholas Gould is a Red Team Operator & Penetration Tester, as well as an independent security researcher specializing in offensive, cloud, application, and container security. He has discovered or co-discovered multiple CVEs across containerization, proxies, IaC tooling, and programming language runtime/interpreter implementations. His recent research focuses on AI / ML infrastructure security, and when not hunting for vulnerabilities, he builds agentic AI tools for offensive and defensive security operations.

\n\n\n\'',NULL,1293848),('3_Saturday','10','10:00','10:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'The Ghost Key: Illusions of \"Time Management\" in TTLock Smart Locks\'','\'Yang Liu,Zhenghan Wang\'','DEF CON Talks_ed54c8cf58b3d7b2d2ca24f108638672','\'Title: The Ghost Key: Illusions of \"Time Management\" in TTLock Smart Locks
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Smart locks are widely used in rental, hotel, and residential markets. As a major provider, TTLock (Sciener) operates in over 200 countries and relies on Offline Time Management to issue temporary eKeys without network access. However, our research reveals critical security flaws in this common offline design.\nFrom real-world anomalies, we analyzed TTLock’s proprietary BLE protocol and found serious weaknesses in its cryptographic verification and authentication. Lacking proper validation, the so-called secure offline architecture is fully bypassable.\nWe uncovered three critical design flaws: full revocation bypass, expired credential resurrection, and low-cost DoS. In this talk, we will demonstrate exploitation with a Mac and custom Python tools. We show that time management in TTLock is a mere illusion, turning physical security into an open digital door.

\n\nSpeakers:Yang Liu,Zhenghan Wang
\n
\nSpeakerBio:  Yang Liu, Hillstone Networks Co., Ltd.
\n

Yang Liu is a Security Researcher at Hillstone Network Security Research Institute, specializing in binary vulnerability hunting, ICS security, mobile security, and reverse engineering. With extensive experience in both red-teaming and defense, Yang has discovered numerous vulnerabilities in complex industrial control systems. He is a frequent speaker in the security community, notably presenting his ICS research at the Kanxue Security Development Conference (SDC). An avid CTF competitor, Yang excels in Reverse Engineering, Mobile, and ICS categories. He also leverages his real-world combat experience to provide professional cybersecurity training for enterprises.

\n\nSpeakerBio:  Zhenghan Wang, Hillstone Networks Co., Ltd.
\n

Zhenghan Wang is a security researcher focusing on IoT security and open-source software security. His research interests include embedded system security, protocol analysis, reverse engineering, and vulnerability discovery. He is dedicated to finding and disclosing real-world security issues to help improve the safety of connected devices and open-source projects.

\n\n\n\'',NULL,1293849),('3_Saturday','10','10:30','11:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Harvest Now, Decrypt Later: Practical Attacks on Post-Quantum Cryptography Implementations\'','\'Aleksandr Krasnov\'','DEF CON Talks_b9653998400cade730905df0b46c2769','\'Title: Harvest Now, Decrypt Later: Practical Attacks on Post-Quantum Cryptography Implementations
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Saturday, Aug 8, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Post-quantum cryptography is being deployed to defeat a computer that doesn\'t exist yet - and the rush is opening a wide, purely classical attack surface today. This talk walks three implementation attack vectors against NIST\'s lattice standards (ML-KEM / FIPS 203, ML-DSA / FIPS 204): (1) memory corruption at the deserialization boundary, culminating in remote code execution through a hybrid TLS 1.3 key exchange; (2) compiler-induced timing side channels, where \"constant-time\" source becomes variable-time binary and yields a chosen-ciphertext key-recovery oracle; and (3) fault injection against ML-DSA\'s signing state machine on a low-cost ChipWhisperer. No quantum computer is required for any of them. The talk closes with the limits of hybrid cryptography as a defense and the live release of LatticeScope, an open-source timing-leak detector and lattice-aware fuzzer for auditing compiled PQC binaries.

\n\nSpeakerBio:  Aleksandr Krasnov
\n

Aleksandr has been an industry expert in DevSecOps, has worked in companies like Dropbox, Palo Alto Networks, and Meta/Facebook. He has spent his time doing security research and holds several patents in the area of application security. In the free time, Aleksandr spends time exploring the great outdoors in British Columbia, climbing new boulders, or free diving in the ocean.

\n\n\n\'',NULL,1293850),('3_Saturday','11','10:30','11:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Harvest Now, Decrypt Later: Practical Attacks on Post-Quantum Cryptography Implementations\'','\'Aleksandr Krasnov\'','DEF CON Talks_b9653998400cade730905df0b46c2769','\'\'',NULL,1293851),('3_Saturday','10','10:30','11:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Root From Kilometers Away: Ubiquiti AirMax RCE\'','\'Federico Kirschbaum,Gaston Aznarez\'','DEF CON Talks_a7e99d9e666f86536eb8dc2313241669','\'Title: Root From Kilometers Away: Ubiquiti AirMax RCE
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

You don\'t realize it until you see them; they\'re everywhere. From Wireless ISP links to the frontline of modern warfare. But nobody found anything?\nThe devices behind those links are Ubiquiti AirMAX: critical infrastructure on a 17-year-old Linux kernel and a custom 802.11 extension built on \"security by obscurity.\"\nSo we took it apart. This talk covers our reverse engineering of the AirMAX protocol, AirOS, and the kernel modules behind this proprietary mode. It rides on 802.11 Information Elements that look encrypted, but we\'ll show why they aren\'t.\nWhat we found: two critical vulnerabilities (CVE-2026-21639, CVE-2026-21638) across airMAX AC, airMAX M, airFiber, and GigaBeam, over 50 devices. These are the bugs from the movies: Over-The-Air, unauthenticated, kernel-privilege RCE. No network access, just line of sight. They affect every AirMAX device ever shipped.\nWe disclosed them through Ubiquiti\'s bug bounty program. The bugs were rated \"Adjacent\", except adjacent here means kilometers away.\nThe same hardware can be turned around and pointed at the problem: we\'ll repurpose these devices as recon tools and release open-source software to locate AirMAX networks in the wild.\nThis talk is about our journey, our tooling, and the state of security.

\n\nSpeakers:Federico Kirschbaum,Gaston Aznarez
\n
\nSpeakerBio:  Federico Kirschbaum, FaradaySec
\n

Federico Kirschbaum is a security researcher with over two decades of experience building tools and ecosystems for offensive security. He is the Co-Founder and VP of Research in Faraday Security, an open-source platform. He is also the Co-Founder of Ekoparty, Latin America’s largest hacking conference, where he has helped shape the region’s security research community for over 20 years.

\n\nSpeakerBio:  Gaston Aznarez, FaradaySec
\n

Gaston Aznarez is a Principal Security Researcher at Faraday Security, focused on IoT and embedded device vulnerability research, firmware reverse engineering, wireless protocol analysis, and hardware-level exploitation. He has presented at DEF CON, Black Hat and Ekoparty.

\n\n\n\'',NULL,1293852),('3_Saturday','11','10:30','11:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Root From Kilometers Away: Ubiquiti AirMax RCE\'','\'Federico Kirschbaum,Gaston Aznarez\'','DEF CON Talks_a7e99d9e666f86536eb8dc2313241669','\'\'',NULL,1293853),('3_Saturday','11','11:00','11:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services\'','\'Ron Ben Yizhak\'','DEF CON Talks_80b63b335988ea5ba167d0c13826cfd4','\'Title: Forgotten but Not Gone: Unauthenticated RCEs and LPEs in Legacy Linux Services
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

The cybersecurity community chases the greatest risks in the latest tech, while components with outdated security principles gather dust. Companies rush to secure their latest AI product, while their network remains the same. Do attackers really need more than legacy services to take you down?

\n\n

We asked this question as we analyzed an unauthenticated RCE in GNU-TelnetD that was discovered in January. We were amazed a simple shell injection existed for so long in the most popular telnet daemon.\nWe further investigated Telnet and discovered it runs a root-privileged process with environment variables supplied by an unauthenticated client! Leading us to a privilege escalation vulnerability.

\n\n

We then looked into Samba, the Linux service for sharing files and printers over SMB. Focused on shell injections, we searched for command execution using format strings - and we couldn\'t believe it! Two more shell injection RCEs waited for us!\nIn this talk, you\'ll ask yourself, “How come it was only found in 2026?!” We will analyze the unauthenticated RCE in TelnetD and reveal three severe vulnerabilities: 2 unauthenticated RCEs in Samba (CVE-2026-4480 & CVE-2026-4408) and a privilege escalation in TelnetD (CVE-2026-28372). The routers or printers you forget to update might run those services, and they put you at risk

\n\n

https://www.safebreach.com/blog/safebreach-labs-root-cause-analysis-and-poc-exploit-for-cve-2026-24061/

\n\nSpeakerBio:  Ron Ben Yizhak, SafeBreach
\n

Ron (@RonB_Y) is a security researcher at SafeBreach with 11 years of experience. He works in vulnerability research and has knowledge in forensic investigations, malware analysis and reverse engineering. Ron previously worked in the development of security products and spoke several times at DEF CON

\n\n\n\'',NULL,1293854),('3_Saturday','11','11:00','11:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children and Vehicles\'','\'Felipe Solferini,Vangelis Stykas\'','DEF CON Talks_8f26b92a2f9cc977877c28fa012a4347','\'Title: Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children and Vehicles
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\nWe performed our research against three major GPS tracking platforms: SETracker (~10M devices, 39 brands), SinoTrack (6M+ devices), and TKSTAR/Thinkrace (20M+ devices). All three come from the same Shenzhen supply chain. All three are completely broken.
\n\n

We achieved RCE on every platform, including NT AUTHORITY\\SYSTEM on TKSTAR. From a free account with no device purchase, we can silently wiretap any child\'s watch, force video surveillance, steal vehicles through remote door unlock and fuel cutoff, and take over the backend servers. We filed 45 CVEs, 19 critical, 9 of them CVSS v3.1 10.0.

\n\n

The worst part is the supply chain structure. 39 consumer brands in 20+ countries (Wonlex, SaveFamily, KidiWatch, Garett, etc.) all connect to the same myaqsh.com server in China. Parents think they are choosing between brands. They are not. Brand diversity in this market is an illusion.

\n\n

We release full PoC chains, CVE details, and a brand-to-backend mapping that shows how this industry actually works.

\n\nSpeakers:Felipe Solferini,Vangelis Stykas
\n
\nSpeakerBio:  Felipe Solferini
\n

Felipe is a senior penetration tester and self-proclaimed security researcher. Most of the time, he’s mashing the wrong buttons, hoping for the worst but expecting the best - or just YOLOing like there’s no tomorrow. Occasionally, he wonders if life is just a CTF. He has presented his research at BSides London, BSides Sofia, and Bsides Vilnius.

\n\nSpeakerBio:  Vangelis Stykas, Kumio
\n

Vangelis began as a developer from Greece. Ten years ago he realized that only his dog didn’t have an API, so he decided to steer his focus towards security.\nThat led him to pursue a PhD in Web Application Security with an extra focus on machine learning. He’s still actively pursuing it.\nHe currently applies his skills as a Chief Technology Officer at Kumio, and during his free time, Vangelis is helping start-ups secure themselves on the internet and get a leg up in security terms.\nHis love of a simplistic approach to hacking by exploiting vulnerable APIs led him to publish research regarding API controlling ships, smart locks, IP cameras, car alarms, EV chargers, and many other IoT devices. Since our lives are nowadays extremely cyber-dependent, his goal is to convince all companies to never neglect their API security as rush-to-market mentality is almost certain to lead to catastrophic security failure.\nHe has presented his research at Black Hat USA, DEF CON, Disobey, BSides London, BSides Dublin, BSides Athens, 44Con and other security conferences, and has keynoted at BSides Prague. His most recent work on disrupting ransomware operations by hacking their web panels was featured at Black Hat USA and DEF CON 32.

\n\n\n\'',NULL,1293855),('3_Saturday','11','11:00','11:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Very Pwned: Hacking Verifone’s card machine three times in a row\'','\'Reino Mostert\'','DEF CON Talks_9ac77a86a788e4b91de3c2a9b63b2931','\'Title: Very Pwned: Hacking Verifone’s card machine three times in a row
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

Everyday billions of credit card transactions are made worldwide, with the vast majority being done on purpose-built card machines. In the USA alone, nearly 400 million transactions are performed per day on these popular devices present in nearly every retail store. \nIn this talk, I’ll focus on a widely deployed Verifone product line of card machines, with an estimated global deployment of over one million units. For several consecutive years I conducted an annual security assessment on these devices, until a pattern emerged: I\'d arrive at the assessment, find a fresh set of vulnerabilities, gain root access, and then have Verifone patch the devices — only for me to return the following year and gain root access in a new way. I’ll demonstrate the three separate attack chains I discovered, two of which only required network access to the target. \nI’ll also detail additional vulnerabilities that could be used to disable hardening features such as grsecurity, including the ability to modify the file system to gain persistent access. Next, I’ll show how an attacker could leverage this access to continuously capture credit card information - contrary to the device’s security claims.\nFinally, in a homage to trixr4skids\' DEF CON 25 talk in which he hacked an older series of Verifone\'s devices, I\'ll also run Doom.

\n\n

DEF CON 25 - trixr4skids\' DOOMed Point of Sale Systems\nCCC May Contain Hackers2022 - Thomas Rinsma\'s Payment terminals as general purpose (game-)computers

\n\nSpeakerBio:  Reino Mostert, Orange Cyberdefense
\n

Reino is a hacker who has been working as a penetration tester for the past decade.\nHe has hacked various payment systems - from credit card devices all the way to payment switches, and has given talks at numerous cons. He enjoys coffee and hacking.

\n\n\n\'',NULL,1293856),('3_Saturday','11','11:30','12:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Thin Client? Thin Crypto - Bypassing Full-Disk Encryption Across Three Major Thin Clients Vendors without Breaking a Cipher\'','\'Darren McDonald\'','DEF CON Talks_52dab07e985d7626292dae6aecd3c063','\'Title: Thin Client? Thin Crypto - Bypassing Full-Disk Encryption Across Three Major Thin Clients Vendors without Breaking a Cipher
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Thin clients are deployed across healthcare, finance, government and critical infrastructure, environments where full disk encryption is a compliance requirement, not optional. Dell, IGEL and HP all ship FDE backed by TPM hardware and modern cryptography. I broke all three.

\n\n

I present new research demonstrating vulnerabilities that permit full disk encryption bypass across Dell ThinOS 9.x - 10.x, HP ThinPro 8.x - 9.x, and IGEL OS 11.x - 12.x. Every attack achieving filesystem access from a powered-off device with no credentials and no specialist hardware. Behind the encryption: WiFi credentials, 802.1x NAC client certificates, VDI session configs, management server credentials, and password hashes. Compromised devices provide a foothold into the infrastructure it was connected to. I trace Dell\'s implementation across three generations getting progressively further from best practice, show IGEL\'s correct PCR policy and modern cryptography bypassed through their own signed bootloader, and demonstrate HP\'s implementation undone by an unmeasured boot chain.

\n\nSpeakerBio:  Darren McDonald, AmberWolf
\n

Darren McDonald is an offensive security consultant at AmberWolf, where he specialises in hardware hacking and red teaming. He has spent 17 years breaking into things professionally, starting with networks and applications before moving to embedded systems, firmware, and the physical layer. The kind of hacker who pulls out screwdrivers instead of a checklist.

\n\n\n\'',NULL,1293857),('3_Saturday','12','11:30','12:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Thin Client? Thin Crypto - Bypassing Full-Disk Encryption Across Three Major Thin Clients Vendors without Breaking a Cipher\'','\'Darren McDonald\'','DEF CON Talks_52dab07e985d7626292dae6aecd3c063','\'\'',NULL,1293858),('3_Saturday','11','11:30','12:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Your OTP Never Arrived: Attacking the Trust Boundary Where SMS Meets the Internet\'','\'Kyprianos \"kavasilo\" Vasilopoulos,Nikos \"nickvourd\" Vourdas\'','DEF CON Talks_c7bdbdefe1f5c74bb1ba94ce888fcb90','\'Title: Your OTP Never Arrived: Attacking the Trust Boundary Where SMS Meets the Internet
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

Kannel is the most widely deployed open-source SMS and WAP gateway in the world. With over 1000+ internet-facing instances across 65 countries, powering two-factor authentication, mobile banking, emergency alerts, and carrier-grade messaging, it forms a silent but critical pillar of global telecommunications infrastructure. Despite handling billions of messages, Kannel has received only a single CVE in its entire history. We present the results of a comprehensive security audit of Kannel SMS Gateway spanning versions 1.4.4, 1.4.5, and 1.5.0. Our research uncovered multiple previously unknown vulnerabilities. Most critically, we introduce telecom-specific attack primitives that exploit the inherent trust model between gateway components, enabling silent message censorship, billing fraud through forged delivery receipts, and audit evasion through metadata manipulation. These go beyond traditional memory corruption to expose fundamental design weaknesses in how SMS infrastructure routes, delivers, and accounts for messages. This talk fundamentally challenges the assumption that legacy telecom software is secure through obscurity.

\n\n

https://www.kannel.org/\nhttps://github.com/kannel\nhttps://en.wikipedia.org/wiki/Short_Message_Peer-to-Peer\nhttps://www.kannel.org/doc.shtml\nhttps://gatewayapi.com/docs/apis/kannel/\nhttps://docs.smsportal.com/docs/kannel\nhttps://github.com/playsms/book-playsms/blob/master/book-contents/en/Installation/Gateway-Installation/Kannel/Example-Kannel-configuration-with-SMPP.md\nhttps://en.wikipedia.org/wiki/SMS_gateway\nhttps://www.drupal.org/project/kannel\nhttps://smpp.org/\nhttps://smpp.org/smpp-v5.html\nhttps://www.infobip.com/docs/essentials/api-essentials/smpp-specification

\n\nSpeakers:Kyprianos \"kavasilo\" Vasilopoulos,Nikos \"nickvourd\" Vourdas
\n
\nSpeakerBio:  Kyprianos \"kavasilo\" Vasilopoulos, Apifon
\n

Kyprianos Vasilopoulos is a cybersecurity executive with 20+ years of experience in red teaming, incident response, penetration testing, and malware research. He is the CISO at Apifon and Co-Founder of OffensiveX. He has led cyber operations for major events like the Olympic Games and contributed to zero-day research at Trustwave SpiderLabs. Holding certifications such as OSCP and OSCE, he combines deep technical expertise with strategic leadership. His focus includes offensive security automation, red teaming, and threat-led penetration testing, and he has appeared on BBC News while being recognized in the Zyxel CVE Hall of Fame.

\n\nSpeakerBio:  Nikos \"nickvourd\" Vourdas, EY
\n

Nikos Vourdas, also known as nickvourd or NCV, is a Senior Offensive Security Consultant based in the US. With over five years of professional experience, he has actively participated in various global Tiber-EU and iCAST Red Teaming engagements. Nikos has conducted full Red Teaming operations to major clients across retail, banking, shipping, construction industries. He holds OSCE3, OSCP, OSWP, CRTL, CRTO and OASP certifications. Also, he has previously presented at DEF CON, DevSecCon, and various BSides events around the world. Nikos loves contributing to open-source projects and always starts his day at 05:00 AM with a refreshing jog while listening to French rap music.

\n\n\n\'',NULL,1293859),('3_Saturday','12','11:30','12:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Your OTP Never Arrived: Attacking the Trust Boundary Where SMS Meets the Internet\'','\'Kyprianos \"kavasilo\" Vasilopoulos,Nikos \"nickvourd\" Vourdas\'','DEF CON Talks_c7bdbdefe1f5c74bb1ba94ce888fcb90','\'\'',NULL,1293860),('3_Saturday','12','12:00','12:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'C(2)YA: Inside the Adversary\'s Inbox\'','\'Vitaly Simonovich\'','DEF CON Talks_3c90bb0b91f682d780dc6166af3ea73b','\'Title: C(2)YA: Inside the Adversary\'s Inbox
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

85 findings exploitable from the internet with zero prior access. 28 takedown chains. Crypto failures that let you decrypt all C2 traffic with one recovered key.

\n\n

Here\'s how I got there. I\'d been using coding agents to find bugs in software. Then I thought: what if I did this from the defender\'s side, against the tools that threat actors actually use? I pointed LLM-assisted research at five C2 frameworks: Havoc, Mythic, Sliver, Covenant, AdaptixC2. Six months later, 251 design flaws, behavioral weaknesses, and vulnerabilities. Validated every finding in realistic lab environments. Then passively tapped 35 live servers via Shodan and Censys, and found operators running campaigns against victims in education, manufacturing, legal, and biotech across eight countries.

\n\n

Eight bug classes recur across all five codebases. Findings rated on a defender-weighted scale, because CVSS doesn\'t tell you which bug finds the server. Havoc, the most-deployed framework in the dataset, was archived on February 21, 2026. No patches coming. Defenders carry the load now.

\n\n

AI isn\'t just for protecting systems. Defenders can point it at the attackers\' own tools and find real ways to fight back. All findings for maintained projects disclosed through proper channels. Every demo against realistic lab environments I control.

\n\nSpeakerBio:  Vitaly Simonovich, Cato Networks
\n

Vitaly Simonovich is a Senior Security Researcher at Cato Networks on the CTRL threat research team, following over ten years in cybersecurity across Cato CTRL and Imperva, where he focused on DDoS and botnet research from 2019 to 2023.

\n\n

He coined HashJack, the first indirect prompt injection weaponizing URL fragments against AI browser assistants, and LAMEHUG, the first LLM-powered malware publicly linked to APT28. He documented the Immersive World jailbreak against Microsoft Copilot and introduced the Zero-Knowledge Threat Actor concept. His research has driven ten coordinated security disclosures across Open WebUI, MongoDB, Jenkins, BIND, Moodle, TYPO3, Perplexity, Microsoft, and others.

\n\n

His work has been covered by Forbes, The Economist, Business Insider, VentureBeat, The Register, The Hacker News, and CyberScoop.

\n\n

Conference talks: RSA Conference 2026, Botconf 2022, BSidesTLV 2025 AI Hacking Village, Qubit 2025 Prague, RootedCon 2026.

\n\n

vitalysim.com

\n\n\n\'',NULL,1293861),('3_Saturday','12','12:00','12:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Rage Against the Sandbox: Bypassing Apple’s iOS Security to Run Unsigned Code via SSH\'','\'Yuval Hanoch Hirschenbein Sadde\'','DEF CON Talks_93117c4757a3f9951bf6730aaac10481','\'Title: Rage Against the Sandbox: Bypassing Apple’s iOS Security to Run Unsigned Code via SSH
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Apple’s Sandbox and code signing have made traditional security research impractical on iPhones - researchers must use full-system emulation or hunt for increasingly rare jailbreak exploits. The Sandbox blocks fork(), which shells need for job control. Code signing prevents unsigned code execution.

\n\n

We present techniques that bypass both restrictions without exploiting vulnerabilities. Using only standard APIs, we built a system that runs SSH servers and interactive shells on iPhones with full fork() support and unsigned code execution.

\n\n

We’ll dive deep into the technical implementation: userspace memory management, thread-based process virtualization, stack frame manipulation, and selective CPU emulation. Then we\'ll demonstrate the real impact: running an unsigned public exploit directly on an iPhone through SSH - no jailbreak, no signing, no problem.

\n\n

Full paper I wrote about the talk (have not published it in public domains yet, waiting for the conference first as a reveal!)

\n\n

\"Rage Against the Sandbox: Bypassing Apple’s iOS Security to Run Unsigned Code via SSH\", Y.H. Hirschenbein Sadde, 2026 https://drive.google.com/file/d/1ZyIvQa3kjiLvCmNhdY-fmSAbhRA5gLPx/view

\n\nSpeakerBio:  Yuval Hanoch Hirschenbein Sadde
\n

Yuval is a security researcher. His main focuses are Android and iOS security - specifically in low-level system code and kernel modules. His work centers around researching the bootstrap process of operating systems, and analyzing popular low-level code flows within the platform frameworks and their third-party dependencies.

\n\n\n\'',NULL,1293862),('3_Saturday','12','12:00','12:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'The Glass Perimeter: Systematic Bypasses in Biometric Frameworks and the Rise of Synthetic Identity\'','\'Dan Borgogno,Javier Bernardo\'','DEF CON Talks_a25075f6ae20fdeec08b33b7c17c3e20','\'Title: The Glass Perimeter: Systematic Bypasses in Biometric Frameworks and the Rise of Synthetic Identity
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Identity is the new perimeter, and biometrics are its supposed gatekeepers. But what happens when the gatekeepers are blind to the reality they consume? We spent more than 6 months deconstructing the biometric \"Root of Trust\" across every top-tier framework we could find, solutions relied upon by the world’s largest banks and providers worth billions. The result: A 100% bypass rate . From high-fidelity physical spoofs to a first-of-its-kind Cross-PID buffer hijack against integrated anti-tamper SDKs, we prove that even multi-million dollar \"fortresses\" can be reduced to client-side theater. This talk is a technical journey through the guts of the mobile media pipeline, exposing how synthetic identities are manufactured at scale to bypass RASP, Kernel-level integrity, and AI models. When the \"Master Key\" is just another line of code an attacker can hook, the risk isn\'t just a bug, it’s a systemic failure affecting millions of users. Customers are losing wealth, companies are buying illusions, and the glass perimeter is shattering.

\n\nSpeakers:Dan Borgogno,Javier Bernardo
\n
\nSpeakerBio:  Dan Borgogno, Security Researcher at Faraday
\n

Dan Borgogno is a security researcher, backend developer, security engineer and international speaker with years of experience on mobile, hardware, IoT and web application hacking.

\n\nSpeakerBio:  Javier Bernardo, Strike Security
\n

Senior Pentester, Security Engineer and Cybersecurity Researcher (+15 years) with a wide area of expertise in Offensive Security and Red Team. Passionate Bug Hunter and self-taught Cybersecurity Specialist who loves to hack almost everything.

\n\n

Organizer of Bug Bounty Argentina Community: https://twitter.com/BugBountyArg\nSpeaker and Organizer at Ekoparty Security Conference: https://ekoparty.org/

\n\n\n\'',NULL,1293863),('3_Saturday','12','12:30','13:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Compounding Interest: Exploiting the ATM Supply Chain\'','\'Matt Burch\'','DEF CON Talks_c52818822aefd212287f360fb22e0f72','\'Title: Compounding Interest: Exploiting the ATM Supply Chain
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

ATMs are the ultimate high-stakes target, often holding upwards of $400,000 in a single enclosure. While the global financial industry relies on a narrow pool of manufacturers, the software supply chain securing these \"vaults\" remains an underexamined attack surface. Following my disclosure of 6 code execution vulnerabilities affecting Diebold Nixdorf\'s Vynamic Security Suite (VSS) at DefCon32, this research dives deeper into the foundational security layer: CryptWare CryptoPro Secure Disk for BitLocker.

\n\n

CryptoPro acts as a proprietary security wrapper, adding pre-boot authorization, custom TPM protections, and an obfuscated encryption layer to the standard BitLocker architecture. I will be disclosing 9 new CVEs that allow an unauthenticated adversary to dismantle the CryptoPro stack. Join me as I share my journey of locating secrets buried in unallocated disk space, abusing TPM sealing logic, and deconstruct CryptoPro\'s custom AES256 logic to recover the BitLocker keys. This presentation will highlight how a trusted security component became a critical backdoor.

\n\n

In addition to the technical walk through, I will be releasing ragavan, a custom exploitation toolkit designed to automate secret extraction, decryption, TPM unsealing, and compromise of a CryptoPro-protected platform.

\n\n
    \n
  • Burch, Matt “Where’s the Money: Defeating ATM Disk Encrytion” DEFCON Media Server, https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf
  • \n
  • Freingruber, R., and M. von Dach. “Manipulation of pre-boot authentication in CryptWare CryptoPro Secure Disk for Bitlocker” SEC Consult, https://sec-consult.com/vulnerability-lab/advisory/manipulation-of-pre-boot-authentication/
  • \n
  • Diebold Nixdorf Legal Terms, https://dnlegalterms.com/products/
  • \n
  • Vynamic Security Suite 3.0 EULA, https://dnlegalterms.com/wp-content/uploads/2020/03/2020026_Diebold_Nixdorf_EULA_for_VYNAMIC_SECURITY_3_0_December_19_2018_022249.pdf
  • \n
  • Vynamic Security Suite 4.5 EULA, https://dnlegalterms.com/wp-content/uploads/2024/10/Diebold-Nixdorf-Third-Party-EULA-for-Vynamic-Security-Suite-4.5.pdf
  • \n
  • VirusTotal CryptoPro Client Installer, https://www.virustotal.com/gui/file/235646487eed8cb648f9d05dafd3c25255b6c53a30aa87cae0ce061081d2b0b7
  • \n
  • VirusTotal CryptoPro Server Installer, https://www.virustotal.com/gui/file/1f42ac4f4d177dc2c38228e02d3c47ecfeb32ee7c17766b8e67145348274a8cc
  • \n
  • cpsd it services GmbH. “CryptoPro Quick Install Guide”, https://secure-disk-for-bitlocker.com/quick-install-guide/
  • \n
  • cpsd it services GmbH. “CryptoPro Secure Disk for BitLocker Administration Manual”, https://docslib.org/doc/7196170/cryptopro-secure-disk-for-bitlocker-administration-manual
  • \n
  • Jean-Philippe Aumasson, “Serious Cryptography A practical Introduction to Modern Encryption” No Starch Press
  • \n
  • Christof Paar and Jan Pelzl, “Understanding Cryptography A Textbook for Students and Practitioners” Springer
  • \n
\n\nSpeakerBio:  Matt Burch, Principal Security Researcher at Atredis Partners
\n

Matt Burch is a Principal Security Researcher at Atredis Partners with 20 years of experience breaking things that aren\'t supposed to break. From the embedded components of ATM platforms to complex SCADA/OT environments, Matt specializes in identifying critical flaws in hardened, enterprise-class systems. He is best known for his research into ATM disk encryption and Mobile Device Management (MDM) security, some of which has been highlighted in Wired Magazine and presented at DEF CON 32.

\n\n

Matt is a reverse engineer and tool developer who has authored and contributed to various public projects. His career spans roles as an offensive security lead, expert witness, and technical advisor. Matt’s current research is a deep-dive into the ATM software supply chain, specifically targeting the subversion of TPM-backed roots of trust and the analysis of custom cryptographic primitives.

\n\n\n\'',NULL,1293864),('3_Saturday','13','12:30','13:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Compounding Interest: Exploiting the ATM Supply Chain\'','\'Matt Burch\'','DEF CON Talks_c52818822aefd212287f360fb22e0f72','\'\'',NULL,1293865),('3_Saturday','12','12:30','13:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Writing to Shadow Stacks\'','\'Vladimir \"G1ND1L4\" Tokarev\'','DEF CON Talks_307d3a347179bca0ac9c635212397678','\'Title: Writing to Shadow Stacks
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

CET shadow stacks are supposed to make return-address corruption a \ndead end. This talk presents three techniques that write attacker-chosen\nvalues directly into shadow stack memory on Linux.

\n\n

The first uses /proc/self/mem. The kernel\'s FOLL_FORCE flag overrides \nshadow stack page protections, letting an unprivileged process write to \nits own shadow stack with open() and pwrite(). Works on x86-64 CET and \nARM64 GCS. After our report, Linus Torvalds merged commit 599bbba5a36f \nto restrict this path. A fork+ptrace variant still works on patched \nkernels. No distribution ships the new default yet.

\n\n

The second uses userfaultfd. We register a fault handler on the shadow \nstack VMA, discard a page with MADV_DONTNEED, and when RET faults on \nthe missing page, provide a replacement filled with chosen return \naddresses. The kernel maps it with valid shadow stack PTE encoding. \nNot blocked by the /proc/self/mem patch.

\n\n

The third uses Intel\'s WRSSQ instruction, which writes to shadow stack \npages from user mode. We corrected a widespread encoding bug in prior \nPoC code (0x66 prefix produces ADCX, not WRSSQ) and confirmed it on \nSapphire Rapids bare metal.

\n\n

Validated against three CVEs (dnsmasq, libinput, rsync) with demos on \nbare metal, including a root shell with CET still enabled.

\n\n
    \n
  1. Intel, \"Control-flow Enforcement Technology Specification,\"\n Rev. 3.0, 2019.

    \n\n
      \n
    1. ARM, \"Guarded Control Stack (GCS) Extension,\" Arm Architecture\nReference Manual for A-profile architecture.

    2. \n
    3. Linux kernel source, mm/gup.c and fs/proc/base.c, including\nFOLL_FORCE, /proc/*/mem, and VM_SHADOW_STACK handling.

    4. \n
    5. Lindenmeier and Schwarz, \"Ghost in the Stack: CET Shadow Stack\nBypass,\" Black Hat Europe 2025.

    6. \n
    7. Muench et al., \"Control Flow-Oriented Programming,\"\nUSENIX Security 2025.

    8. \n
    9. Schuster et al., \"Counterfeit Object-oriented Programming: On the\nDifficulty of Preventing Code Reuse Attacks in C++ Applications,\"\nIEEE S&P 2015.

    10. \n
    11. CVE-2017-14493, dnsmasq stack buffer overflow.

    12. \n
    13. CVE-2022-1215, libinput format string vulnerability.

    14. \n
    15. CVE-2024-12084, rsync heap buffer overflow.

    16. \n
  2. \n
\n\nSpeakerBio:  Vladimir \"G1ND1L4\" Tokarev, Cyera
\n

Vladimir Tokarev is a vulnerability researcher tech lead at Cyera, \n specializing in Cloud, IoT/OT, Windows, Linux, and AI vulnerability\n research and exploit. Talks: Black Hat USA 2024 and 2023,
\n DEF CON 33 Recon Village 2025, CodeBlue 2025, RSA 2024.

\n\n\n\'',NULL,1293866),('3_Saturday','13','12:30','13:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Writing to Shadow Stacks\'','\'Vladimir \"G1ND1L4\" Tokarev\'','DEF CON Talks_307d3a347179bca0ac9c635212397678','\'\'',NULL,1293867),('3_Saturday','13','13:00','13:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Dylib Hijacking on macOS: Dead or Alive?\'','\'Patrick Wardle\'','DEF CON Talks_65636a583723359ea74a03eceb1e0418','\'Title: Dylib Hijacking on macOS: Dead or Alive?
\nTags: DEF CON Official Talk | Demo 💻
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Over a decade ago, a much younger Patrick showed that macOS (then OS X) was vulnerable to what had long been considered a Windows-only attack: dynamic library hijacking. By planting malicious libraries in the right place, attackers could achieve stealthy persistence, inject code into trusted processes, and even bypass core Apple security mechanisms.

\n\n

Today, an older (and hopefully wiser) Patrick revisits that work to answer a simple question: is dylib hijacking truly dead on modern macOS, or has Apple’s decade of defenses, including Gatekeeper, App Translocation, Notarization, and the Hardened Runtime, simply made it harder?

\n\n

This talk revisits the technique in 2026, analyzing these mitigations and evaluating their real-world effectiveness. While the attack surface has been significantly reduced, we show dylib hijacking remains possible under the right conditions. Through real-world examples and live demos, we explore how modern applications can still be coerced into loading attacker-controlled libraries, enabling code execution within trusted processes and bypassing controls such as TCC.

\n\n

Finally, we present practical detection and defense strategies, including novel approaches leveraging Endpoint Security to detect (and block!) malicious library loads at runtime.

\n\n

\"Dylib hijacking on OS X\"\n
www.virusbulletin.com/virusbulletin/2015/03/dylib-hijacking-os-x

\n\n

\"Tweaking macOS security controls to thwart application bundle manipulation\"\n
redcanary.com/blog/threat-detection/mac-application-bundles/

\n\n

\"What\'s New in Security\" (WWDC 2016)
\ndevstreaming-cdn.apple.com/videos/wwdc/2016/706sgjvzkvg6rrg9icw/706/706_whats_new_in_security.pdf

\n\nSpeakerBio:  Patrick Wardle, CEO and Co-Founder at DoubleYou
\n

Patrick Wardle is the cofounder of the Objective-See Foundation, CEO and cofounder of DoubleYou, and author of The Art of Mac Malware series. He previously worked at NASA and the NSA, and has presented at countless security conferences, making him intimately familiar with aliens, spies, and talking nerdy.

\n\n\n\'',NULL,1293868),('3_Saturday','13','13:00','13:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Stalking the Wily Hacker ... 40 years later\'','\'Cliff Stoll\'','DEF CON Talks_0a87c16cd5448242622d7cf2e5a6f9b6','\'Title: Stalking the Wily Hacker ... 40 years later
\nTags: DEF CON Official Talk
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

40 years ago today, I tripped over a 75-cent accounting glitch in a Unix system. \nThat tiny clue led to a year-long chase across networks, modem banks, and international borders, ultimately uncovering a crew of German hackers working for the East German Stasi and the Soviet KGB.\nWe had no budget, no roadmap, and no “cyber” anything. We improvised with soldering irons, shell scripts, logbooks, curiosity, and far too much coffee.\nLet’s revisit the chase – not just to remember, but to ask what changed, what didn’t, and why it still matters.

\n\n

The Cuckoo’s Egg, Doubleday Books, 1989

\n\n

Stalking the Wily Hacker, Communications of the ACM May 1988 v31, page 484-497
\nhttps://dl.acm.org/doi/10.1145/42411.42412

\n\nSpeakerBio:  Cliff Stoll, Acme Klein Bottle
\n

Cliff graduated from Buffalo Public School #61 with a blue star for good attendance. He’s since fooled around in planetary physics, computer security, and mathematical Klein bottles, with occasional detours into common sense.

\n\n\n\'',NULL,1293869),('3_Saturday','13','13:00','13:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'gpwn: Wiretapping fiber (GPON) ISP deployments from the comfort of your home\'','\'Rithwik \"thel3l\" Jayasimha,Rithvik Vibhu\'','DEF CON Talks_77b57937b2fd14e196f7f26bc40d18c7','\'Title: gpwn: Wiretapping fiber (GPON) ISP deployments from the comfort of your home
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Have you ever wanted to know what your neighbor does on their network and what sites they\'re browsing? How about all the people around you on their mobile phones, on cellular data?

\n\n

GPON is the fiber-to-home protocol that carries traffic for hundreds of millions of subscribers worldwide (and climbing). It operates on a threat model that makes several assumptions that break in the real world.

\n\n

We\'ll chat about how it\'s possible to become a modern day fiber optic voyeur with hardware that costs about $100 and watch your neighbor\'s DNS, SIP calls and most excitingly, GTP-tunneled 4G/5G traffic from the cellular towers that you share a fiber line with.

\n\n

Additionally, we show some fun, new techniques to retain your access even if your ISP wisens up and enables downstream AES encryption, by hacking the Optical Line Terminal itself over the fiber line, and how to build your own botnet army out of all the members of your ISP.

\n\n

Finally, we\'ll also explore how we built custom hardware to read and write onto a fiber line despite the rules of the network (and land).

\n\n\n\nSpeakers:Rithwik \"thel3l\" Jayasimha,Rithvik Vibhu
\n
\nSpeakerBio:  Rithwik \"thel3l\" Jayasimha, Lagrange Point
\n

Rithwik is a hacker who\'s been breaking into systems since the impressionable age of 10.

\n\nSpeakerBio:  Rithvik Vibhu, Lagrange Point
\n

Rithvik has always been fascinated by network systems and in the past was a core contributor to the HNS ecosystem. In the past, he reverse engineered an implementation of UPI in India, and built distributed proxy infra.

\n\n\n\'',NULL,1293870),('3_Saturday','13','13:30','14:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Bring Your Own Root Of Trust\'','\'Mickey \"@HackingThings\" Shkatov,Jesse Michael\'','DEF CON Talks_cf71efce13888a592ef47b66bee49c41','\'Title: Bring Your Own Root Of Trust
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\nModern computers depend on a hardware root of trust: a component assumed to start trustworthy and is used to verify everything that follows. This has evolved from ROM boot code and fixed keys into TPMs, secure boot chains, external security controllers, and attestation mechanisms used far beyond disk encryption. Today, platforms trust these devices because they are certified, immutable, and built into the hardware, but what if that assumption is wrong? Starting from real hardware traces, failed approaches, and a pile of development boards, we arrive at a $45 FPGA-based SPI TPM that can appear to Windows 11 as a platform trust anchor. From there, we explore what this means for secure boot, measured boot, platform attestation, anticheat, AI infrastructure, and the broader belief that hardware identity is difficult to counterfeit. We will release the code, gateware, prompts, and data so others can reproduce the work and push it further.
\n\n

https://twpm.dasharo.com/\nhttps://github.com/microsoft/ms-tpm-20-ref

\n\nSpeakers:Mickey \"@HackingThings\" Shkatov,Jesse Michael
\n
\nSpeakerBio:  Mickey \"@HackingThings\" Shkatov, Eclypsium
\n

Mickey has been involved in security research for over a decade, specializing in breaking down\ncomplex concepts and identifying security vulnerabilities in unusual places. His experience spans a\nvariety of topics, which he has presented at security conferences worldwide. His talks have covered\nareas ranging from web penetration testing to the intricacies of BIOS firmware.

\n\nSpeakerBio:  Jesse Michael, Eclypsium
\n

Jesse is an experienced security researcher focused on vulnerability detection and mitigation\nwho has worked at all layers of modern computing environments from exploiting worldwide\ncorporate network infrastructure down to hunting vulnerabilities inside processors at the\nhardware design level. His primary areas of expertise include reverse engineering embedded\nfirmware and exploit development. He has also presented research at DEF CON, Black Hat,\nPacSec, Hackito Ergo Sum, Ekoparty, and BSides Portland.

\n\n\n\'',NULL,1293871),('3_Saturday','14','13:30','14:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Bring Your Own Root Of Trust\'','\'Mickey \"@HackingThings\" Shkatov,Jesse Michael\'','DEF CON Talks_cf71efce13888a592ef47b66bee49c41','\'\'',NULL,1293872),('3_Saturday','13','13:30','14:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Transformers: Dark Side of the Type - Weaponizing the Conversion Layer\'','\'Oleksandr Mirosh\'','DEF CON Talks_044206ee395368dfc8072788bf2f04a9','\'Title: Transformers: Dark Side of the Type - Weaponizing the Conversion Layer
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

In 2017, our DEF CON talk \"Friday the 13th: JSON Attacks\" forced the industry to confront Insecure Deserialization. Developers responded by hardening the configurations of parsers and serializers. But it created a dangerous blind spot. Developers and security reviewers now assume that simpler code patterns, those that do not involve parsers, are inherently safe. We demonstrate that they are not.\nThis talk moves the focus away from the serialization format entirely and targets the transformation layer: the code that turns a simple string into a complex object. We expose \"Insecure String Transformers\": mechanisms that silently resolve types, trigger complex logic, and instantiate objects during what looks like a safe string conversion. This overlooked attack surface remains invisible to the tools and reviews focused on the parser-level bugs from 2017.\nWe dissect specific CVEs where string-to-object conversion was the root cause of RCE. We release new gadget chains targeting popular .NET libraries and present a methodology for hunting dangerous conversion patterns across any codebase. The goal is to redefine how the industry classifies this vulnerability: it is not \"Insecure Deserialization\" - it is Insecure Transformation, and it may be hiding in your application even if it does not use any serialization library.

\n\n

Alvaro Muñoz & Oleksandr Mirosh, \"Friday the 13th: JSON Attacks\" - Black Hat USA 2017 https://www.blackhat.com/docs/us-17/thursday/us-17-Munoz-Friday-The-13th-JSON-Attacks-wp.pdf\nAlvaro Muñoz & Oleksandr Mirosh, \"Room for Escape: Scribbling Outside the Lines of Template Security\" - Black Hat USA 2020 https://i.blackhat.com/USA-20/Wednesday/us-20-Munoz-Room-For-Escape-Scribbling-Outside-The-Lines-Of-Template-Security-wp.pdf

\n\nSpeakerBio:  Oleksandr Mirosh, OpenText Fortify
\n

Oleksandr Mirosh is a Security Researcher on the Fortify Software Security Research team at OpenText, where he focuses on investigating emerging threats and developing detection and remediation rules for enterprise software. With over 18 years of experience in computer security, specializing in vulnerability research, reverse engineering, and penetration testing, his work centers on flaws in JNDI, authentication protocols, data serialization, and transformation logic across Java and .NET ecosystems. His research has led to the discovery of numerous CVEs in widely deployed enterprise applications and framework libraries. A frequent speaker at Black Hat USA and DEF CON, he has also presented at other security conferences like OWASP Global AppSec and BSidesLV.

\n\n\n\'',NULL,1293873),('3_Saturday','14','13:30','14:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Transformers: Dark Side of the Type - Weaponizing the Conversion Layer\'','\'Oleksandr Mirosh\'','DEF CON Talks_044206ee395368dfc8072788bf2f04a9','\'\'',NULL,1293874),('3_Saturday','14','14:00','14:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Cracking North Korea\'s Information Control: How Smugglers, Defectors, and Technologists are Breaking Open the World\'s Most Locked-Down Information System\'','\'JDT\'','DEF CON Talks_f872ca07934d38972f5fbb878e42a67f','\'Title: Cracking North Korea\'s Information Control: How Smugglers, Defectors, and Technologists are Breaking Open the World\'s Most Locked-Down Information System
\nTags: DEF CON Official Talk | Demo 💻
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

North Korea operates the world’s most extreme digital environment. Its custom Android OS enforces an \"allowlist\" ecosystem where media and apps require state-issued cryptographic signatures to run, while background daemons capture secret screenshots to log \"illegal\" activity. In this restrictive environment, the stakes for accessing outside information are measured in prison sentences and public executions.

\n\n

Yet, the hackers are active. This talk deconstructs the regime\'s information control systems—from signature-verification logic to TraceViewer forensics—and reveals how a network of defectors and technologists is fighting back. We will demo Pigeon, a working SELFSIGN spoof that bypasses handset verification, and discuss eMMC chip-off techniques used to study device internals, and look at Windows data concealment methods used by defectors.

\n\n

This isn\'t just a technology briefing; it’s an offensive security call for support. I will map out a unique and intriguing engineering backlog which includes media obfuscation tools, Android internals research, binary analysis, anti-forensics, and hardware hacking. I will show how these skills directly translate into freedom-of-information tool development. Built and validated through iterative testing with defectors, some of these technologies are operational already today.

\n\n
    \n
  • Korean Ministry of Unification: Annual North Korean Refugee Arrival Statistics: https://www.unikorea.go.kr/eng_unikorea/
  • \n
  • Citizen Lab: Red Star OS Analysis (2015): https://citizenlab.ca/2015/09/red-star-os/
  • \n
  • 38 North: North Korean technology reporting: https://www.38north.org
  • \n
  • Martyn Williams: North Korea Tech: https://www.northkoreatech.org
  • \n
  • Defector interviews and memoirs
  • \n
  • Jieun Baek: North Korea\'s Hidden Revolution
  • \n
\n\nSpeakerBio:  JDT, Liberty in North Korea
\n

JDT brings over a decade of cybersecurity expertise to his role as Chief Technology Officer at LiNK. Before joining the organization, he served as the lead specialist for the U.S. Department of Homeland Security’s HQ Threat Hunt team, following ten years spent in incident response and red-teaming across the banking, retail, and tech sectors.

\n\n

After volunteering for the North Korean human rights movement in 2019, JDT stepped into the CTO role in 2025 to spearhead the development of tools designed to pierce the world’s most restrictive information environment. By repurposing his deep understanding of adversary tradecraft, he develops unconventional technologies that empower North Koreans to access outside information safely and bypass state surveillance.

\n\n\n\'',NULL,1293875),('3_Saturday','14','14:00','14:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Lights Out: Out-of-Band, Out of Mind, Out of Control\'','\'HD \"hdm\" Moore\'','DEF CON Talks_716a1159d494179da90d7550acd6c210','\'Title: Lights Out: Out-of-Band, Out of Mind, Out of Control
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Every enterprise server has a second computer you probably forgot about. The baseboard management controller runs its own OS, has its own network stack, and stays on even when the server is off. It speaks IPMI, a protocol from the 1990s that Dan Farmer thoroughly dismantled in 2013. Thirteen years later, nobody went back to check. We did.

\n\n

We scanned 15,000 internet-facing BMCs and 125,000 across corporate networks, extracted RAKP password hashes from three out of four targets without credentials, and cracked thousands offline. We show how to fingerprint vendors from unauthenticated GUID responses, extract Dell service tags and HPE serial numbers before logging in, and brute-force the \"random\" passwords that California\'s SB-327 law was supposed to fix.

\n\n

Then we show what comes next: pivoting from a compromised host to its BMC over the internal bus without touching the network, jumping to the out-of-band management VLAN, reusing shared credentials across the fleet, and landing on production hosts via Serial-over-LAN and virtual media. The host and BMC are the same physical machine; network segmentation means nothing when the bridge is a PCIe bus.

\n\n

We release OOBscan, an open-source IPMI exploitation tool, and demonstrate the full attack chain.

\n\n

========================================

\n\n

FOUNDATIONAL IPMI RESEARCH (2013-2014)

\n\n

Dan Farmer - IPMI Security Research Hub\n http://fish2.com/ipmi/

\n\n

Dan Farmer - \"IPMI: Freight Train to Hell\" (January 2013)\n http://fish2.com/ipmi/itrain.html

\n\n

Dan Farmer - \"Sold Down the River\" (June 2014)\n http://fish2.com/ipmi/river.pdf

\n\n

Dan Farmer - IPMI Security Best Practices\n http://fish2.com/ipmi/bp.pdf

\n\n

Dan Farmer - Cracking IPMI Passwords Remotely\n http://fish2.com/ipmi/remote-pw-cracking.html

\n\n

Dan Farmer - IPMI Tools (GitHub)\n https://github.com/zenfish/ipmi

\n\n

HD Moore - \"A Penetration Tester\'s Guide to IPMI and BMCs\" (July 2013)\n https://www.rapid7.com/blog/post/2013/07/02/a-penetration-testers-guide-to-ipmi/

\n\n

Bonkoski, Bielber, Halderman - \"Illuminating the Security Issues Surrounding Lights-Out Server Management\" (WOOT \'13, August 2013)\n https://jhalderm.com/pub/papers/ipmi-woot13.pdf

\n\n

US-CERT Alert TA13-207A - Risks of Using the Intelligent Platform Management Interface (IPMI)\n https://www.cisa.gov/uscert/ncas/alerts/TA13-207A

\n\n

CVE-2013-4786 - IPMI 2.0 RAKP Authentication Remote Password Hash Retrieval\n https://nvd.nist.gov/vuln/detail/CVE-2013-4786

\n\n

Metasploit IPMI Modules (ipmi_dumphashes, ipmi_cipher_zero, ipmi_version)\n https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/auxiliary/scanner/ipmi/ipmi_dumphashes.md

\n\n

========================================

\n\n

INTEL ME / AMT VULNERABILITIES

\n\n

CVE-2017-5689 \"Silent Bob is Silent\" - Intel AMT Remote Privilege Escalation (CVSS 9.8)\n https://nvd.nist.gov/vuln/detail/CVE-2017-5689

\n\n

Intel SA-00075 - Intel Active Management Technology Elevation of Privilege (May 2017)\n https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00075.html

\n\n

Intel SA-00086 - Intel ME/SPS/TXE Multiple Vulnerabilities (November 2017)\n https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00086.html

\n\n

EFF - \"Intel\'s Management Engine is a Security Hazard\" (May 2017)\n https://www.eff.org/deeplinks/2017/05/intels-management-engine-security-hazard-and-users-need-way-disable-it

\n\n

Wikipedia - Intel Management Engine (comprehensive history)\n https://en.wikipedia.org/wiki/Intel_Management_Engine

\n\n

Evdokimov - \"Intel AMT Stealth Breakthrough\" (Black Hat USA 2017)\n https://blackhat.com/docs/us-17/thursday/us-17-Evdokimov-Intel-AMT-Stealth-Breakthrough-wp.pdf

\n\n

========================================

\n\n

PLATINUM APT - WEAPONIZED OOB MANAGEMENT

\n\n

Microsoft - \"PLATINUM Activity Group Using Intel AMT for C2\" (June 2017)\n https://www.microsoft.com/en-us/security/blog/2017/06/07/platinum-continues-to-evolve-find-ways-to-maintain-invisibility/

\n\n

========================================

\n\n

ASPEED BMC HARDWARE VULNERABILITIES

\n\n

CVE-2019-6260 \"Pantsdown\" - ASPEED AST2400/AST2500 AHB Bridge Arbitrary R/W (CVSS 9.8)\n https://nvd.nist.gov/vuln/detail/cve-2019-6260

\n\n

Stewart Smith - \"CVE-2019-6260: Gaining Control of BMC from the Host Processor\" (January 2019)\n https://www.flamingspork.com/blog/2019/01/23/cve-2019-6260-gaining-control-of-bmc-from-the-host-processor/

\n\n

OpenBMC Security Advisory for CVE-2019-6260\n https://github.com/openbmc/openbmc/issues/3475

\n\n

Pantsdown Exploit Tool\n https://github.com/amboar/cve-2019-6260

\n\n

========================================

\n\n

ECLYPSIUM BMC RESEARCH (2019-2025)

\n\n

Eclypsium - \"CloudBorne: Bare-Metal Cloud Server Vulnerabilities\" (2019)\n https://eclypsium.com/blog/the-ilobleed-implant-lights-out-management-like-you-wouldnt-believe/

\n\n

Eclypsium - \"Vulnerable Firmware in the Supply Chain\" (2019) - Lenovo/Vertiv MergePoint EMS\n https://eclypsium.com/wp-content/uploads/Vulnerable-Firmware-in-the-Supply-Chain.pdf

\n\n

Eclypsium - BMC&C Part 1: \"Supply Chain Vulnerabilities Put Server Ecosystem At Risk\" (December 2022)\n CVE-2022-40259 (RCE via Redfish API), CVE-2022-40242, CVE-2022-2827\n https://eclypsium.com/blog/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/

\n\n

Eclypsium - BMC&C Part 2: \"Lights Out Forever\" (July 2023)\n CVE-2023-34329 (CVSS 9.1, auth bypass via HTTP header spoofing), CVE-2023-34330\n https://eclypsium.com/research/bmcc-lights-out-forever/

\n\n

Eclypsium - BMC&C Part 3: AMI MegaRAC Vulnerabilities (March 2025)\n CVE-2024-54085 (CVSS 10.0, remote auth bypass via Redfish Host Interface)\n https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/

\n\n

Eclypsium - \"CVE-2024-54085 Joins CISA\'s KEV\" (July 2025)\n https://eclypsium.com/blog/bmc-vulnerability-cve-2024-05485-cisa-known-exploited-vulnerabilities/

\n\n

Eclypsium - Nuclei Templates for AMI MegaRAC Detection (July 2025)\n https://eclypsium.com/blog/eclypsium-releases-tools-for-detecting-ami-megarac-bmc-vulnerabilities/

\n\n

Eclypsium - \"The iLOBleed Implant\" (analysis/commentary)\n https://eclypsium.com/blog/the-ilobleed-implant-lights-out-management-like-you-wouldnt-believe/

\n\n

========================================

\n\n

NVIDIA BMC RESEARCH

\n\n

NVIDIA OSR - \"Breaking BMC: The Forgotten Key to the Kingdom\" (DEF CON 31, 2023)\n 18 vulnerabilities, 9 exploits, full chain to persistent firmware implant\n https://developer.nvidia.com/blog/analyzing-baseboard-management-controllers-to-secure-data-center-infrastructure/

\n\n

DEF CON 31 Talk Description (Tereshkin & Zabrocki)\n https://forum.defcon.org/node/245714

\n\n

========================================

\n\n

iLOBLEED ROOTKIT (2020-2021)

\n\n

Amnpardaz - \"Implant.ARM.iLOBleed.a\" Technical Report (December 2021)\n First known in-the-wild BMC firmware implant\n https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/

\n\n

Amnpardaz - Full Technical Analysis PDF\n https://threats.amnpardaz.com/en/wp-content/uploads/sites/5/2021/12/Implant.ARM_.iLOBleed.a-en.pdf

\n\n

========================================

\n\n

HPE iLO SECURITY RESEARCH & TOOLS

\n\n

CVE-2017-12542 - HPE iLO4 Authentication Bypass (CVSS 9.8)\n https://nvd.nist.gov/vuln/detail/CVE-2017-12542

\n\n

Airbus Security Lab - \"Subverting Your Server Through Its BMC: The HPE iLO4 Case\" (SSTIC 2018)\n Périgaud, Gazet, Czarny - firmware analysis, backdooring, persistence\n https://airbus-seclab.github.io/ilo/SSTIC2018-Article-subverting_your_server_through_its_bmc_the_hpe_ilo4_case-gazet_perigaud_czarny.pdf

\n\n

Airbus Security Lab - Presentation Slides (SSTIC 2018)\n https://airbus-seclab.github.io/ilo/SSTIC2018-Slides-EN-Backdooring_your_server_through_its_BMC_the_HPE_iLO4_case-perigaud-gazet-czarny.pdf

\n\n

Airbus Security Lab - iLO4/iLO5 Toolbox (firmware analysis, extraction, exploitation)\n https://github.com/airbus-seclab/ilo4_toolbox

\n\n

iLO4 Unlock - Custom firmware patching for HPE iLO4 (fan control, diagnostics)\n https://github.com/kendallgoto/ilo4_unlock

\n\n

========================================

\n\n

SUPERMICRO IPMI FIRMWARE TOOLS

\n\n

Supermicro IPMI Firmware Source Code (GPL release)\n https://github.com/devicenull/supermicro_ipmi_firmware

\n\n

IPMI Firmware Tools - Extract, modify, and rebuild Supermicro firmware images\n https://github.com/devicenull/ipmi_firmware_tools

\n\n

smcbmc - Decrypt Supermicro BMC firmware images\n https://github.com/c0d3z3r0/smcbmc

\n\n

super-bmc-fw-tools - Decrypt Supermicro BMC firmware (alternative implementation)\n https://github.com/zt-chen/super-bmc-fw-tools

\n\n

Supermicro IPMI License Key Generation (reverse engineered)\n https://github.com/manfromafar/supermicro-ipmi-keygen

\n\n

========================================

\n\n

JUNGLESEC RANSOMWARE (2018)

\n\n

BleepingComputer - \"JungleSec Ransomware Infects Victims Through IPMI Remote Consoles\" (December 2018)\n https://www.bleepingcomputer.com/news/security/junglesec-ransomware-infects-victims-through-ipmi-remote-consoles/

\n\n

========================================

\n\n

GOVERNMENT ADVISORIES

\n\n

CISA/NSA - \"Harden Baseboard Management Controllers\" Joint CSI (June 2023)\n https://media.defense.gov/2023/Jun/14/2003241405/-1/-1/0/CSI_HARDEN_BMCS.PDF

\n\n

CISA Alert - \"CISA and NSA Release Joint Guidance on Hardening BMCs\" (June 2023)\n https://www.cisa.gov/news-events/alerts/2023/06/14/cisa-and-nsa-release-joint-guidance-hardening-baseboard-management-controllers-bmcs

\n\n

NSA Press Release - \"NSA and CISA Release Guide to Protect BMCs\" (June 2023)\n https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3426648/nsa-and-cisa-release-guide-to-protect-baseboard-management-controllers/

\n\n

CISA Binding Operational Directive 23-02 - Mitigating the Risk from Internet-Exposed Management Interfaces (June 2023)\n https://www.cisa.gov/news-events/directives/bod-23-02-mitigating-risk-internet-exposed-management-interfaces

\n\n

CVE-2024-54085 - Added to CISA Known Exploited Vulnerabilities Catalog (June 2025)\n https://nvd.nist.gov/vuln/detail/CVE-2024-54085

\n\n

========================================

\n\n

CALIFORNIA SB-327 IoT SECURITY LAW

\n\n

SB-327 Bill Text - California Legislative Information\n https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180SB327

\n\n

========================================

\n\n

IPMI SPECIFICATION

\n\n

IPMI v2.0 Specification (Intel, maintained by DMTF)\n https://www.intel.com/content/www/us/en/products/docs/servers/ipmi/ipmi-second-gen-interface-spec-v2-rev1-1.html

\n\n

========================================

\n\n

CRACKING TOOLS

\n\n

Hashcat - Mode 7300: IPMI2 RAKP HMAC-SHA1\n https://hashcat.net/wiki/doku.php?id=example_hashes

\n\n

John the Ripper (bleeding-jumbo branch) - IPMI RAKP support\n https://github.com/openwall/john

\n\n

========================================

\n\n

ADDITIONAL BMC VULNERABILITY REFERENCES

\n\n

CVE-2022-40259 - AMI MegaRAC Arbitrary Code Execution via Redfish API\n https://nvd.nist.gov/vuln/detail/CVE-2022-40259

\n\n

CVE-2023-34329 - AMI MegaRAC Auth Bypass via HTTP Header Spoofing (CVSS 9.1)\n https://nvd.nist.gov/vuln/detail/CVE-2023-34329

\n\n

CVE-2018-7078 - HPE iLO4/iLO5 Remote Code Execution\n https://nvd.nist.gov/vuln/detail/CVE-2018-7078

\n\n

CVE-2018-7113 - HPE iLO5 Secure Boot Bypass\n https://nvd.nist.gov/vuln/detail/CVE-2018-7113

\n\n

CVE-2021-29202 - HPE iLO Host-to-iLO Arbitrary Code Execution\n https://nvd.nist.gov/vuln/detail/CVE-2021-29202

\n\n

========================================

\n\n

RELATED TOOLS

\n\n

ipmitool - Standard open-source IPMI management utility\n https://github.com/ipmitool/ipmitool

\n\n

PCILeech - Direct Memory Access (DMA) attack toolkit (relevant to BMC-host trust)\n https://github.com/ufrisk/pcileech

\n\n

Shadowserver Foundation - Open IPMI Report (ongoing internet scanning)\n https://www.shadowserver.org/what-we-do/network-reporting/open-ipmi-report/

\n\nSpeakerBio:  HD \"hdm\" Moore
\n

HD Moore is a pioneer of the cybersecurity industry who has dedicated his career to vulnerability research, network discovery, and software development since the 1990s. He is most recognized for creating Metasploit and is a passionate advocate for open-source software and vulnerability disclosure. HD serves as the CEO and founder of runZero, a provider of cutting-edge exposure management software and cloud services that helps organizations minimize risk across their total attack surface. Prior to founding runZero, he held leadership positions at Atredis Partners, Rapid7, and BreakingPoint. HD\'s professional journey began with exploring telephone networks, developing exploits for the Department of Defense, and hacking into financial institution networks. When he\'s not working, he enjoys hacking on weird Go projects, building janky electronics, running in circles, and playing single-player RPGs.

\n\n\n\'',NULL,1293876),('3_Saturday','14','14:00','14:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'The Enclave is Lying to You: Breaking TEE Trust Boundaries Through Boot-Time State\'','\'Sandeep \"pyro\" Jayashankar\'','DEF CON Talks_6f91b5803d2c3fec1016f1378c3a108a','\'Title: The Enclave is Lying to You: Breaking TEE Trust Boundaries Through Boot-Time State
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\nConfidential computing on cloud TEEs: Nitro Enclaves, SEV-SNP, and TDX promises that a fully compromised host cannot reach into a hardware-isolated enclave. The cryptographic attestation story holds. The deployment story does not.
\n\n

This talk demonstrates attacks that bypass TEE isolation without touching the enclave image. We target the inputs an enclave trusts at boot: cloud object storage, host-supplied environment variables, and KMS keys whose policies forget to enforce attestation. None are covered by attestation. All reach inside.

\n\n

We demonstrate remote code execution as root inside a Nitro Enclave with a single s3:PutObject permission. No host access. No SSH. One file upload containing a path traversal, one boot cycle, and the enclave executes attacker-controlled code.

\n\n

From inside we intercept KMS decrypts live to extract the database encryption key in plaintext, exfiltrate the enclave\'s IAM credentials, and establish persistence across reboots without re-exploitation - all while PCR measurements remain unchanged and attestation reports a healthy enclave.

\n\n

We release an open-source auditing tool, walk through which defenses held, and provide a hardening checklist for any team running workloads inside TEEs.

\n\n

The enclave isn\'t broken. The way we deploy it is.

\n\n

AWS, \"AWS Nitro Enclaves User Guide,\" https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html\nAWS, \"Cryptographic Attestation with AWS KMS for Nitro Enclaves,\" https://docs.aws.amazon.com/kms/latest/developerguide/services-nitro-enclaves.html\nA. Tsow, \"Attacking Confidential Computing: A Survey of TEE Exploitation Techniques,\" IEEE S&P Workshop on Offensive Technologies (WOOT), 2024\nNCC Group, \"Public Report - AWS Nitro System Security Review,\" 2023, https://research.nccgroup.com/2023/04/\nTrail of Bits, \"Security Assessment of AWS Nitro Enclaves,\" 2022\nMITRE ATT&CK, \"Cloud Matrix - Initial Access / Valid Accounts,\" https://attack.mitre.org/techniques/T1078/004/\nJ. Aas et al., \"Understanding TEE Trust Models in Cloud Deployments,\" USENIX Security Symposium, 2023\nOWASP, \"Path Traversal,\" https://owasp.org/www-community/attacks/Path_Traversal\nAWS, \"Instance Metadata Service Version 2 (IMDSv2),\" https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html\nApache Thrift Project, \"Thrift Binary Protocol Specification,\" https://github.com/apache/thrift/blob/master/doc/specs/thrift-binary-protocol.md

\n\nSpeakerBio:  Sandeep \"pyro\" Jayashankar, Independent Researcher
\n

Sandeep Jayashankar is a security researcher specializing in offensive security and adversarial simulations. His work spans AWS, Azure, and GCP environments, with current research focused on trusted execution environment exploitation, confidential computing trust boundaries, and the security of AI/ML systems deployed in cloud-native architectures. This research was conducted under an authorized adversarial simulation program. He approaches security research from a defender\'s perspective: every offensive finding ships with a concrete, auditable control that defenders can deploy. He previously presented at RSA Conference 2025.

\n\n\n\'',NULL,1293877),('3_Saturday','14','14:30','15:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Bird Hunting Season: The Final Flight\'','\'Jon \"GainSec\" Gaines\'','DEF CON Talks_07f00b4593f82c85e85397586693b506','\'Title: Bird Hunting Season: The Final Flight
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 14:30 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Surveillance tech often operates as a \"black box\" burdened by systemic technical debt. This session is the capstone of \"Bird Hunting Season,\" an independent, self-funded teardown and research of the Flock Safety ecosystem. What began with an eBay purchase evolved into 51+ vulnerabilities across Raven gunshot detectors, Falcon LPRs, and Picard/Bravo compute boxes.

\n\n

I detail the project\'s lifecycle: from hardware root via UART and unauthenticated EDL mode to protocol-layer failures. I demonstrate how broken mTLS, hardcoded Java Keystore secrets, and debugging compilations led to system level escalation. The narrative reaches its climax with an an explanation of how I found 63 live production camera feeds exposed without authentication to the public internet.

\n\n

I also formalize the \"Flea Market Supply Chain\" attack, detailing how direct communication with upstream SoM manufacturers can bypass months of reverse engineering.

\n\n

The talk culminates in the release of BirdShot: a 12 module testing framework that incorporates the exploits I\'ve discovered as well as a TensorFlow harness (BirdEye) for hijacking proprietary ML models. I demonstrate how BirdShot automates the journey from a three button physical hotspot trigger to a persistent root shell, proving that when the birds are watching you, you can watch them back.

\n\n

[1] Gaines, J. (2026). Examining the Security Posture of an Anti-Crime Ecosystem. Zenodo. DOI: 10.5281/zenodo.17584876

\n\n

[2] Gaines, J. (2025-2026). Bird Hunting Season: Anti-Crime Ecosystem Research Repository. GitHub. https://github.com/GainSec/anti-crime-ecosystem-research

\n\n

[3] MITRE/CWE. ES2510-692960d9: Improper Entitlement/Authorization for Protected Artifact Access. (Submission Pending/Accepted).

\n\n

[4] https://github.com/justcallmekoko/ESP32Marauder/wiki/Flock-Sniff

\n\n

[5] https://github.com/justcallmekoko/ESP32Marauder/wiki/flock-wardrive

\n\n

[6] https://github.com/colonelpanichacks/flock-you

\n\nSpeakerBio:  Jon \"GainSec\" Gaines
\n

Jon \"GainSec\" Gaines is a offensive security researcher, leader and \"lifelong hacker\" with over a decade of experience hacking all types of technologies for international organizations. By day, he serves as a Senior Security Engineer at Anduril, where he hacks next generation defense systems, following a career of Principal and Managing roles at security firms like NetSPI.

\n\n

Jon has independently disclosed over 50 CVEs spanning critical infrastructure, hardware, web applications, software, mobile applications, and embedded systems. His technical research has been featured in Phrack Magazine and he maintains a diverse output of open-source projects, ranging from automated PCB hardware hacking tools to control in depth offensive agent governance frameworks. Beyond the lab, he also serves as an adjunct instructor at Herkimer College, where he is dedicated to mentoring the next generation of offensive researchers.

\n\n

Jon remains committed to lifting the community through technical transparency, tooling, and the meticulous deconstruction of insecure infrastructure.

\n\n\n\'',NULL,1293878),('3_Saturday','15','14:30','15:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Bird Hunting Season: The Final Flight\'','\'Jon \"GainSec\" Gaines\'','DEF CON Talks_07f00b4593f82c85e85397586693b506','\'\'',NULL,1293879),('3_Saturday','14','14:30','15:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Looking and Peering: Attacking from beyond BGP Adjacency\'','\'Bo-Shiun \"bronson113\" Yen\'','DEF CON Talks_62dc36e9c308ace6c5635eebec45aac4','\'Title: Looking and Peering: Attacking from beyond BGP Adjacency
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 14:30 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

The internet is fragile. A single misconfiguration in BGP can cause worldwide outages. There have been various efforts to harden BGP, like BGPsec, RPKI, and MANRS, but those mostly address route validation. The session-level boundary that everything else rests on is adjacency trust. If your router only connects to trusted peers, the router should be safe. That assumption shaped a lot of the security design around BGP: peer whitelisting, MD5 / TCP-AO authentication, GTSM (RFC 5082) using TTL to enforce that a peer is one hop away.

\n\n

In this talk, we look beyond that boundary. Building on Route to Bugs (dos Santos & Guiot, DC31) and From Spoofing to Tunneling (123ojp, DC33), we demonstrate three vectors that undermine the assumption. We hijack a trusted peer through pre-auth command injection in BGP monitoring tools. We abuse tunnel injection to establish adjacency from off-path, and chain into a heap UAF for unauthenticated RCE. We turn implementation disagreement between FRR, BIRD, and other daemons into a weapon: we craft UPDATEs that one router type happily re-emits while causing denial of service in a different implementation.

\n\n

BGP:\n- Route to Bugs: https://i.blackhat.com/BH-US-23/Presentations/US-23-dosSantos-Route-to-Bugs-Analyzing-the-Security-of-BGP.pdf

\n\n

Tunnel injection:\n- From spoofing to tunneling: https://i.blackhat.com/BH-USA-25/Presentations/USA-25-Tung-From-Spoofing-To-Tunneling-New.pdf?_ga=2.41373794.1394109082.1756795982-2018511848.1751622634\n- Free VPNs everywhere — tunnel injection: https://blog.chummydns.com/blogs/tunnel-injection-english/\n- Hunted by legacy: discovering and exploiting vulnerable tunneling hosts: https://www.usenix.org/system/files/usenixsecurity25-beitis.pdf

\n\n

Looking glasses:\n- Through the looking-glass and what eve found there: https://www.usenix.org/system/files/conference/woot14/woot14-bruno.pdf\n- Looking glass research WOOT2014 / DEFCON 22: https://blog.talosintelligence.com/looking-glasses-with-bacon/

\n\nSpeakerBio:  Bo-Shiun \"bronson113\" Yen, Calif.io
\n

Bronson Yen (@bronson113) is a security researcher working at Calif.io. He has experience in researching networking equipment and hardware attacks, with a focus on binary exploitation and cryptography. He previously presented at HITCON for his work in router exploitation.

\n\n\n\'',NULL,1293880),('3_Saturday','15','14:30','15:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Looking and Peering: Attacking from beyond BGP Adjacency\'','\'Bo-Shiun \"bronson113\" Yen\'','DEF CON Talks_62dc36e9c308ace6c5635eebec45aac4','\'\'',NULL,1293881),('3_Saturday','15','15:00','15:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild\'','\'Gavin Zhong,Zhengyu Liu,Jianjia Yu\'','DEF CON Talks_fa77846ce8f8cf43d8c875f3b0da3a93','\'Title: Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Python is widely used in LLM applications and agent frameworks. Its ease of use comes from two core features: a uniform object model and dynamic reflection, which unfortunately also enable an emerging vulnerability class: Python class pollution. To date, with only one CVE and a handful of synthetic examples since its first disclosure in 2023, what is known is merely the tip of the iceberg, the real threat runs far deeper into the Python ecosystem.

\n\n

In this talk, we introduce the first complete taxonomy of this vulnerability class, built from two object-resolution primitives and three object-assignment primitives, which together yield six types. Only one was previously known.

\n\n

Building on this taxonomy, we design and implement Pyrl, the first automated framework for detecting Python class pollution via a novel static analysis technique named operational taint analysis. Applying Pyrl to over 600,000 GitHub and PyPI packages, we found 47 exploitable zero-days in Azure CLI, Taipy, ComfyUI, Google Mesop, HuggingFace Smolagents, and others. Through live case studies, we show how class pollution can be weaponized into token exfiltration, authentication bypass, stored XSS, sandbox escape, and RCE. Most importantly,we demonstrate that even the weakest type—one previously unknown—can still lead to critical impact in practice.

\n\nSpeakers:Gavin Zhong,Zhengyu Liu,Jianjia Yu
\n
\nSpeakerBio:  Gavin Zhong, Johns Hopkins University
\n

Jiacheng (Gavin) Zhong is a security researcher, focusing on AI system security, program analysis, and identity security. He recently completed his M.S. in Security Informatics at Johns Hopkins University, where his work was accepted to IEEE S&P 2026. Gavin has reported over 30 CVEs in widely used open-source projects. He is also an active CTF player with r3kapig, an international team ranked top 3 worldwide.

\n\nSpeakerBio:  Zhengyu Liu, Johns Hopkins University
\n

Zhengyu Liu is a third-year PhD student in Computer Science at Johns Hopkins University. His research focuses on web and software security via program analysis. His work received Distinguished Paper (S&P ’25), Honorable Mention (USENIX ’25), and Best Student Paper (ICICS ’22). He is a DEF CON speaker and is a member of CTF team TheHackersCrew.

\n\nSpeakerBio:  Jianjia Yu, Johns Hopkins University
\n

Jianjia Yu is a PhD student at Johns Hopkins University, advised by Prof. Yinzhi Cao. Her research focuses on security and privacy in web and mobile ecosystems using program analysis techniques. Her work has received Distinguished Paper Awards at CCS \'23 and S&P \'25, and an Honorable Mention at USENIX Security \'25. She has discovered over 40 zero-day vulnerabilities and uncovered privacy leaks affecting millions of users across browser extensions and mobile applications.

\n\n\n\'',NULL,1293882),('3_Saturday','15','15:00','15:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Smile, you\'re on camera! Livestreaming from North Korea\'s IT workers laptop farm\'','\'Heiner García,Mauro Eldritch\'','DEF CON Talks_ca3edf0530aaed748fb43051d3a2d66e','\'Title: Smile, you\'re on camera! Livestreaming from North Korea\'s IT workers laptop farm
\nTags: DEF CON Official Talk | Demo 💻
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

We infiltrated a cell of North Korean IT workers dedicated to obtaining remote employment for the DPRK, attributed to Famous Chollima (Lazarus Group). Posing as facilitators, we went through their full recruitment process and, once inside, provided them with controlled environments that allowed us to observe and record their operations from the inside.

\n\n

In parallel, we used OSINT and targeted reconnaissance to map their infrastructure, track financial movements, and reconstruct the broader structure behind the operation. This includes networks of fake companies and identities, local facilitators, fraudulent H-1B visa schemes, and a coordinated model of transnational fraud used to gain access to Western companies.

\n\n

The talk features recorded direct interactions with DPRK operatives and live recordings from a fake laptop farm we built for them. While they believed they had remote access to legitimate work systems, we captured everything: how they set up their infrastructure, handled authentication, configured VPNs, and operated on a daily basis.

\n\n

This was the first time this kind of threat campaign was profiled, recorded, and published from the inside. Now we want to share it with you. Smile, you’re on camera!

\n\n

Original article:\n- https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/

\n\n

Media:\n- https://www.bleepingcomputer.com/news/security/north-korea-lures-engineers-to-rent-identities-in-fake-it-worker-scheme/\n- https://thehackernews.com/2025/12/researchers-capture-lazarus-apts-remote.html

\n\nSpeakers:Heiner García,Mauro Eldritch
\n
\nSpeakerBio:  Heiner García, NorthScan
\n

Researcher & Strategic intelligence Analyst

\n\n

Founder of NorthScan

\n\n

Cyber Threat Intelligence at Telefonica Tech

\n\nSpeakerBio:  Mauro Eldritch, Leader at Bitso Quetzal Team
\n

Hacker and Speaker.

\n\n

Founder of BCA LTD and DC5411.

\n\n

I wrote a book interviewing Threat Actors.

\n\n

I like Threat Intelligence and Golden Retrievers.

\n\n\n\'',NULL,1293883),('3_Saturday','15','15:00','15:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Throw Out the Alphabet: Token-Based Markov Chains for Password Cracking\'','\'Jon \"flakpaket\" Gorenflo\'','DEF CON Talks_43519d98d22d1d88e8fcb5f1e18baf23','\'Title: Throw Out the Alphabet: Token-Based Markov Chains for Password Cracking
\nTags: DEF CON Official Talk | Tool 🛠
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\nClassical Markov password generators work over the character alphabet: hashcat\'s Markov masks, JtR\'s --markov, OMEN, even neural models like PassGPT.
\n\n

We change one thing: the alphabet. Train an n-gram Markov on RockYou, but segment with GPT-2\'s 50k BPE tokenizer instead of characters. The distribution stays RockYou-derived; only the units change. The vocabulary captures structure characters can\'t: name fragments, digit patterns, symbol clusters from web-scale text.

\n\n

Across 14 leak corpora (RockYou, LinkedIn, Yahoo, +11 more), token-Markov beats OMEN at fixed budgets on all 14, at 10^8 and 10^9, with best66 rules on both sides. On enterprise passwords (8+ chars, 3 of 4 classes), we recover ~6x more than OMEN: 6.3% vs 1.1% at 10^8, 12.3% vs 2.3% at 10^9; the lead holds ~2.8x with rules applied. tokenov hits 10^9 candidates in minutes on CPU; OMEN takes hours; PassGPT needs days.

\n\n

Why: the tokenizer bakes in mixed-case, digit, and symbol primitives, so multi-class compliance is modal, not rare. \"Michael99\" is two tokens, not eight transitions.

\n\n

We release tokenov: train an n-gram model with any tokenizer, or use include custom GTP-2 tokenizer. Pipe into hashcat, JtR, or write to disk. Use OSINT derived lists to seed generation customized to the target. No GPU needed: 1B candidates in under 2 minutes on an i9.

\n\n
    \n
  • Narayanan & Shmatikov, \"Fast dictionary attacks on passwords using time-space tradeoff,\" CCS 2005. (Markov password modeling, original.)
  • \n
  • Weir et al., \"Password cracking using probabilistic context-free grammars,\" IEEE S&P 2009. (PCFG, the natural rival to Markov.)
  • \n
  • Durmuth et al., \"OMEN: Faster password guessing using an ordered Markov enumerator,\" ESSoS 2015. (The level-ordered enumerator we benchmark against.)
  • \n
  • Melicher et al., \"Fast, lean, and accurate: Modeling password guessability using neural networks,\" USENIX Security 2016. (FLA, the neural baseline.)
  • \n
  • Hitaj et al., \"PassGAN: A deep learning approach for password guessing,\" ACNS 2019.
  • \n
  • Rando et al., \"PassGPT: Password modeling and (guided) generation with LLMs,\" ESORICS 2023. (Closest prior work; uses GPT-2 fine-tuned on RockYou. We outperform it.)
  • \n
  • Cracken (https://github.com/shmuelamar/cracken). The proximate inspiration; uses BPE for password masks. We extend the BPE idea from masks to full Markov generation.
  • \n
  • MAYA benchmark (S&P 2026). The 19-corpus evaluation framework we adopted.
  • \n
\n\nSpeakerBio:  Jon \"flakpaket\" Gorenflo, ATTACKD
\n

Jon Gorenflo is the founder of ATTACKD, a cybersecurity consulting firm dedicated to helping organizations of all sizes think like attackers and proactively secure their environments. Whether you\'re a startup, a small business, or a global enterprise, Jon brings real-world offensive security insights that are practical, accessible, and actionable.\nHe is also a Principal Instructor with the SANS Institute and the co-author of SEC560: Enterprise Penetration Testing, a leading course on advanced ethical hacking and red team operations. With more than 20 years of combined experience in IT, penetration testing, incident response, and security training, Jon has worked with a diverse range of organizations to uncover critical vulnerabilities and build resilient defenses.\nIn addition, Jon serves as the executive director of Hackers Teaching Hackers (HTH), a grassroots cybersecurity conference that emphasizes hands-on learning and community connection.\nJon is known for his clear communication, relatable style, and dedication to helping defenders build practical skills. He breaks down hacker tactics into understandable steps and helps teams of all sizes, from a solo IT admin to an enterprise SOC, apply those lessons to real-world defenses.

\n\n\n\'',NULL,1293884),('3_Saturday','15','15:30','16:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Wrestling with a Python: Escaping Copilot Studio\'s AI-Guarded Sandbox\'','\'Ryan Hausknecht,Simon Maxwell-Stewart\'','DEF CON Talks_e3387fe72191da918b4c5f1af757460e','\'Title: Wrestling with a Python: Escaping Copilot Studio\'s AI-Guarded Sandbox
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

Microsoft Copilot Studio lets anyone build AI agents that execute Python. Behind the scenes, that code runs in a Windows container on Azure Service Fabric, wrapped in a Python sandbox and guarded by a GPT-4.1 mini model that decides what\'s safe to run. Three layers of defense. The presenter broke all of them.

\n\n

Starting from a standard agent with code interpreter enabled, we used classic MRO introspection with string concatenation to bypass dunder filters, escaped Python entirely through pythonnet (which nobody thought to block), and systematically defeated the LLM guardrail by exploiting its leaked reasoning chain. The result: exfiltrated TLS private keys and certificates, 75 environment variables including Azure AD client IDs and Service Fabric cluster topology, complete application source code, and confirmed command execution as ContainerUser.

\n\n

The most interesting finding was the LLM guardrail itself. It is non-deterministic: identical payloads sometimes pass and sometimes get blocked. It leaks its full security reasoning in the API response, turning the defender\'s AI into an oracle for the attacker. This talk walks through the full attack chain, demos a C2 tool that turns the code interpreter into a persistent shell, and releases all tooling.

\n\n
    \n
  • Ned Batchelder, \"Eval really is dangerous\" (2012). Original documentation of Python MRO introspection for sandbox escape.
  • \n
  • Michael Bargury / Zenity, \"Living off Microsoft Copilot\" (DEFCON 32, Black Hat USA 2024). Prompt injection and data exfiltration through Copilot connectors. Different attack surface from code interpreter sandbox escape.
  • \n
  • Tobias Diehl, \"Mind the Data Voids: Hijacking Copilot Trust to Deliver C2 Instructions\" (DEFCON 33). Memory-persistent data exfiltration via M365 Copilot. Related but targets a different feature and attack path.
  • \n
\n\nSpeakers:Ryan Hausknecht,Simon Maxwell-Stewart
\n
\nSpeakerBio:  Ryan Hausknecht, BeyondTrust
\n

Ryan Hausknecht is the Director of Research at BeyondTrust Phantom Labs. Ryan has an extensive background in red teaming, detection development, and security research through his tenure at Microsoft and Specterops. His most notable contibutions have been in cloud security as the creator of PowerZure, the Azure Threat Research Matrix, and as the co-author of AzureHound.

\n\nSpeakerBio:  Simon Maxwell-Stewart, BeyondTrust
\n

Simon Maxwell-Stewart is a Staff Security Researcher at BeyondTrust\'s Phantom Labs, where he focuses on cloud platform security and the emerging attack surface of enterprise AI systems. Before getting into security he spent over a decade doing data science and machine learning, with a physics degree from Oxford and production ML work in healthcare.

\n\n

These days he\'s the resident graph nerd on the Phantom Labs team, applying graph analysis to identity security problems across Microsoft cloud environments. His recent research focuses on Entra ID attack paths, Azure infrastructure security.

\n\n\n\'',NULL,1293885),('3_Saturday','16','15:30','16:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Wrestling with a Python: Escaping Copilot Studio\'s AI-Guarded Sandbox\'','\'Ryan Hausknecht,Simon Maxwell-Stewart\'','DEF CON Talks_e3387fe72191da918b4c5f1af757460e','\'\'',NULL,1293886),('3_Saturday','15','15:30','16:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks\'','\'Francesco La Spina,Stanislav Dashevskyi\'','DEF CON Talks_ee7c2fcac3e92c299bd8bd9689aca219','\'Title: Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Today network equipment vendors offer Zero-Touch Provisioning (ZTP) for\nconfiguring devices with little-to-no manual intervention. However, it is often\ntaken for granted that that the networking protocols used in ZTP are secure.

\n\n

Most vulnerability and threat intelligence reports on network equipment focus on\nindividual “device takeover” vulnerabilities allowing for direct Remote Code\nExecution. Yet, there is little recent research examining the security of ZTP\ndesigns and implementations, where the exploitation impact may be on a much\nlarger scale.

\n\n

In this talk, we will present 17 vulnerabilities affecting TP-Link Omada – a\ndevice ecosystem designed with ZTP in mind. We will present the Omada protocols\nZTP and discuss key vulnerabilities in them, including a chain of trust\ncompromise due to the use of hard-coded cryptographic keys, sensitive\ninformation disclosure, and remote code execution against some devices.

\n\n

We will present attacks against controllers and client devices that allow\nattackers to infiltrate networks by taking over Omada equipment. We will also\nshow that some of the issues go way beyond one device family and affect other\nnetwork equipment, security cameras, smart home devices, and mobile apps with\nmillions of downloads.

\n\nSpeakers:Francesco La Spina,Stanislav Dashevskyi
\n
\nSpeakerBio:  Francesco La Spina, Forescout Technologies
\n

Francesco La Spina holds an MSc in Computer Science from the University of\n Trento, Italy. He began his career as a software engineer with a focus on IT/IoT\n security gateway development, honing his expertise in crafting robust security\n solutions for digital infrastructures. Having served as a security engineer for\n an ISP and financial institutions, he also gained invaluable experience in\n fortifying networks against potential threats. Currently, Francesco is engaged\n in cutting-edge security research and threat analysis within the realms of IT\n and IoT at Forescout Technologies - Vedere Labs.

\n\nSpeakerBio:  Stanislav Dashevskyi, Forescout Technologies
\n

Stanislav Dashevskyi is a Security Researcher at Forescout. He received his\n PhD from the International Doctorate School in Information and Communication\n Technologies (ICT) at the University of Trento (Italy) in 2017. His main\n research interests are open source software, software security, and\n vulnerability analysis.

\n\n\n\'',NULL,1293887),('3_Saturday','16','15:30','16:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks\'','\'Francesco La Spina,Stanislav Dashevskyi\'','DEF CON Talks_ee7c2fcac3e92c299bd8bd9689aca219','\'\'',NULL,1293888),('3_Saturday','16','16:00','16:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Hacking Your Life with AI Can Get You Hacked: How AI Orchestration Platforms Ship RCE by Design\'','\'Peyton \"p80n-sec\" Kennedy\'','DEF CON Talks_4f5cdfecde4b889edb8cd57a91bf5ce2','\'Title: Hacking Your Life with AI Can Get You Hacked: How AI Orchestration Platforms Ship RCE by Design
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

AI orchestration platforms promise to automate your life. They deliver, just not always for you. Kestra, Langflow, Nocobase, Flowise, Activepieces, Dify, and Apache Airflow have quietly become critical infrastructure, and they all share the same dangerous assumption: anyone who can touch a workflow is trusted to run code on the host.\nI went hunting across seven major platforms and walked out with multiple CVEs and critical-severity findings. I\'ll share an arsenal of RCE primitives: shell injection through template rendering, exec() on user-supplied \"validation\" code, eval() on raw LLM output, and unauthenticated API endpoints that hand you a shell. Then I\'ll demonstrate the kill shot: an unauthenticated attacker achieving full RCE through a single prompt injection into an LLM module.\nWhen I reported these, some vendors told me code execution is intended behavior and security is the deployer\'s problem. I\'ll show you why that argument falls apart in real deployments, and walk through the trust boundary failures that keep producing the same bugs across the ecosystem.\nYou\'ll leave with a methodology for tearing these platforms apart, a catalog of recurring vulnerability patterns, and a framework for evaluating whether a platform\'s threat model survives contact with reality.

\n\nSpeakerBio:  Peyton \"p80n-sec\" Kennedy, Endor Labs
\n

Peyton \'p80n-sec\' Kennedy is a Senior Security Researcher at Endor Labs, where he focuses on offensive security research, vulnerability discovery, and exploit development against the open source projects shaping modern software. His research has produced CVE disclosures across widely deployed frameworks and platforms, including koa.js and openclaw, with a consistent focus on the gap between what platforms claim about their threat models and what they actually enforce.

\n\n\n\'',NULL,1293889),('3_Saturday','16','16:00','16:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Install Me Maybe: Turning Claimable VS Code Extension IDs into Supply-Chain Attacks\'','\'Raphael \"rcss\" Silva\'','DEF CON Talks_c6fa1b80ffc963cb7bcf48181082e9bf','\'Title: Install Me Maybe: Turning Claimable VS Code Extension IDs into Supply-Chain Attacks
\nTags: DEF CON Official Talk | Exploit 🪲
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Developer tools trust extension identifiers way more than they should.

\n\n

A VS Code extension ID like publisher.extension shows up everywhere a dev environment gets set up, and people treat it as the same trusted thing no matter where it\'s resolved, but it isn\'t. Extension identity is marketplace-specific. An extension can be trusted and popular in one marketplace while the matching namespace sits unclaimed in another that the main forks actually pull from. Claim that namespace, publish under the same identifier, and a name people already trust now runs your code. It\'s dependency confusion, but for editor extensions. I\'ve been calling it Extension Confusion.

\n\n

I\'ll show where the trust boundary breaks, the IDE quirks that carry these identifiers across the gap, and what happened when I published proof-of-concept extensions to measure it for real.

\n\n

The scale got out of hand fast: 1M+ callbacks, hundreds of organizations, $200k+ in bounties, all in under 3 months. Code running on laptops, managed corporate machines, remote dev setups, WSL, and containers, across SaaS, fintech, Fortune 500s, healthcare, government, and universities.

\n\n

A trusted name, a missing namespace, and the marketplace gap no one was watching.

\n\n

Editor extensions are supply chain. Treat them that way.

\n\n

My talk from last year around malicious extensions can be a good intro:

\n\n
    \n
  • https://www.youtube.com/watch?v=wI8ml8WqmQc
  • \n
\n\nSpeakerBio:  Raphael \"rcss\" Silva
\n

Raphael Silva is a security researcher at Aikido Security, focused on web security, software supply-chain security, and vulnerability research. He has spoken at DEF CON, RootedCON, OWASP Global AppSec, Black Alps and OWASP local chapters, and has also run hands-on activities at DEF CON. His work centers on finding weird trust assumptions in real systems, turning them into clear attack models, and responsibly disclosing the results to vendors and open-source projects.

\n\n\n\'',NULL,1293890),('3_Saturday','16','16:00','16:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'The Compiler That Can\'t Read: Crashing Every 5G Phone With One Byte\'','\'Qiqing Huang,Xingyu Wang\'','DEF CON Talks_4e1c1cf33d5fbacf6711ef13e0a47061','\'Title: The Compiler That Can\'t Read: Crashing Every 5G Phone With One Byte
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

Every 5G phone parses radio messages using code generated by a compiler. That compiler has two blind spots — and we used them to crash iPhones, Pixels, and phones from every major chipset vendor. No credentials, no user interaction, no warning.

\n\n

The compiler can\'t read English. Hundreds of rules that govern when fields should appear exist only in natural-language prose. The compiler discards them all. We extracted these invisible rules, turned them into targeted payloads, and crashed basebands from Apple, Google, Qualcomm, and MediaTek — all before authentication. Apple confirmed reproduction. Google Android Security confirmed multiple findings. MediaTek patched three CVEs affecting 64 chipset models and over 542 smartphone models. Qualcomm rewarded one finding.

\n\n

The compiler can\'t count. Some fields have value ranges that don\'t fill the wire encoding. We changed one byte in a legitimate message and crashed phones across two chipset generations. GSMA assigned CVD-2025-0110.

\n\n

Same root cause, same blind compiler, same result: the modem trusts a decoder that was never built to enforce the rules that matter. We demo live over-the-air crashes on stage.

\n\n
    \n
  1. 3GPP TS 38.331: NR Radio Resource Control (RRC) protocol specification
  2. \n
  3. 3GPP TS 33.501: Security architecture and procedures for 5G System
  4. \n
  5. ITU-T X.680-X.693: ASN.1 and encoding rules (UPER)
  6. \n
  7. Hernandez et al., \"FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware,\" NDSS 2022
  8. \n
  9. Klischies et al., \"BaseBridge: Bridging the Gap Between Over-the-Air and Emulation Testing for Cellular Baseband Firmware,\" IEEE S&P 2025
  10. \n
  11. Garbelini et al., \"5Ghoul: Unleashing Chaos on 5G Edge Devices,\" IEEE TDSC 2025
  12. \n
  13. Park et al., \"DoLTEst: In-depth Downlink Negative Testing Framework for LTE Devices,\" USENIX Security 2022
  14. \n
  15. Rupprecht et al., \"Putting LTE Security Functions to the Test: A Framework to Evaluate Implementation Correctness,\" USENIX WOOT 2016
  16. \n
\n\nSpeakers:Qiqing Huang,Xingyu Wang
\n
\nSpeakerBio:  Qiqing Huang
\n

Qiqing Huang is a PhD candidate in Computer Science at the University at Buffalo, specializing in 5G baseband security. His research focuses on exploiting structural gaps between formal protocol schemas and natural-language specification constraints to discover pre-authentication vulnerabilities in commercial cellular modems. His work has resulted in multiple high-severity CVEs affecting major baseband vendors including Apple, Qualcomm, Samsung, and MediaTek, impacting 64 chipset models and over 542 commercially available smartphone models. He received GSMA CVD-2025-0110 for discovering a class of ASN.1 decode divergence vulnerabilities. His research has been published at USENIX Security 2026. He maintains active responsible disclosure relationships with Apple, Google, Qualcomm, Samsung, MediaTek, and GSMA. He is completing his PhD in Summer 2026 and is on the job market for security research roles.

\n\nSpeakerBio:  Xingyu Wang, University at Buffalo
\n

Xingyu Wang is a PhD student at the University at Buffalo studying the weird edge cases of networks, phones, and systems that are supposed to “just work.” He explores how AI can help security researchers survive dense specs and turn “wait, why did it do that?” moments into better tests. He does not fully trust AI or complex systems, but he enjoys putting them in the same room and watching what breaks first.

\n\n\n\'',NULL,1293891),('3_Saturday','16','16:30','17:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'How much of our Bluetooth firmware reverse engineering work can now be automated with LLMs?\'','\'Veronica Kovah,Xeno Kovah\'','DEF CON Talks_7f1001be1fbe641fa6f43f87cc163d96','\'Title: How much of our Bluetooth firmware reverse engineering work can now be automated with LLMs?
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Saturday, Aug 8, 16:30 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Last year Xeno manually reverse-engineered Realtek RTL8761B* Bluetooth chips\' ROM & firmware, to inject code into them that allows everyone to send custom packets that aren\'t supposed to be possible on a well-behaved device. Previous to that Veronica manually reverse-engineered multiple firmware to find link layer over-the-air exploitable vulnerabilities. This year we wanted to understand how much time we could have saved on past projects if we had used LLMs to automate the reversing process.

\n\n

The answer turns out to be \"quite a lot!\". In this talk we\'ll discuss how we\'ve created skills for LLMs to almost entirely automate the reverse engineering of Bluetooth Low Energy / Classic chip firmwares\' low level packet handling & Host Controller Interface layers. The key is to focus on helping the LLMs find the code that you know must be there in order for a chip to be spec-compliant (\"Waypoints\").

\n\n

If you work in another firmware/OS RE domain, with well-defined specification-required interfaces and data structures, we expect you\'ll be able to follow the same process as us to significantly accelerate your reversing. Especially if you have binaries that you\'ve already reverse-engineered in the past that you can feed into an automation process for grading purposes.

\n\n

[1] \"Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes\" - Xeno Kovah - https://darkmentor.com/publication/2025-11-hardweario/
\n[2] \"DarkFirmware_real_i\" - Xeno Kovah - https://github.com/darkmentorllc/DarkFirmware_real_i\n[3]

\n\nSpeakers:Veronica Kovah,Xeno Kovah
\n
\nSpeakerBio:  Veronica Kovah, Dark Mentor LLC
\n

Veronica is a researcher who has created and released multiple over-the-air arbitrary code execution exploits which target Bluetooth chip firmware. She presented these attacks at BlackHat USA 2020. In 2018 she founded the security consultancy Dark Mentor LLC. She has previously worked at companies like Tesla on vehicular security and NSA as an adjunct instructor and Capability Development Specialist developing CNE tools for embedded systems. She is currently using her background in reverse engineering and exploitation to specialize in the security analysis of Bluetooth systems.

\n\nSpeakerBio:  Xeno Kovah, Dark Mentor LLC
\n

Prior to working full time on OpenSecurityTraining2 (ost2.fyi), Xeno worked at Apple designing architectural support for firmware security; and code auditing firmware security implementations. A lot of what he did revolved around adding secure boot support to the main and peripheral processors (e.g. the Broadcom Bluetooth chip.) He led the efforts to bring secure boot to Macs, first with T2-based Macs, and then with the massive architectural change of Apple Silicon Macs. Once the M1 Macs shipped, he left Apple to pursue the project he felt would be most impactful: creating free deep-technical online training material and growing the newly created OpenSecurityTraining 501(c)(3) nonprofit.

\n\n\n\'',NULL,1293892),('3_Saturday','17','16:30','17:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'How much of our Bluetooth firmware reverse engineering work can now be automated with LLMs?\'','\'Veronica Kovah,Xeno Kovah\'','DEF CON Talks_7f1001be1fbe641fa6f43f87cc163d96','\'\'',NULL,1293893),('3_Saturday','16','16:30','17:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Taming the Swarm: Hard Architectural Lessons from Building a Deterministic Agentic Web Pentesting System\'','\'Albert \"yz9yt\" Corzo\'','DEF CON Talks_ba0e4cf2386ea12e31b3c6865e5ecb29','\'Title: Taming the Swarm: Hard Architectural Lessons from Building a Deterministic Agentic Web Pentesting System
\nTags: DEF CON Official Talk | Demo 💻
\nWhen: Saturday, Aug 8, 16:30 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

Most agentic systems for offensive security boast impressive benchmarks while hiding the real cost, the real time, and the architectural pain behind them. Many remain closed-source, sacrificing the transparency security demands.After 20 years as an offensive security researcher, I spent the last 10 months distilling all that accumulated experience into a deterministic agentic pipeline for web pentesting.I’ll dissect the hard trade-offs I had to make: why visual validation via Playwright, CDP and Vision models became mandatory (and why text-based parsing is architecturally broken for client-side vulns like XSS), why suppressing creativity backfired, how specialization, model shifting and temperature control enabled useful determinism, why a dedicated Skeptic agent and weighted scoring were essential, and why immutable audit trails, wet/dry separation and native MCP support became non-negotiable.War stories included: the \"Dojo Incident\" — where the agents decided rewriting server configs was cheaper than writing the exploit.Conclusion: reliable offensive agentic systems must be open-source. Closed-source hides real behavior and real risks. Open-source is not a license choice — it is the only architectural and ethical safeguard we have left.

\n\nSpeakerBio:  Albert \"yz9yt\" Corzo
\n

I’ve been breaking things for over 20 years — legally, most of the time. An offensive security researcher with an adversarial mindset, multiple Hall of Fame recognitions, and several critical CVEs discovered.For the past 6+ years I’ve focused on the intersection of AI and offensive security. My work centers on solving complex engineering challenges in agentic systems: enforcing determinism, minimizing token burn and environmental impact, and creating reliable pipelines that combine LLMs with real web pentesting tools.I’m a web pentester and technical speaker passionate about helping the next generation of researchers execute more precise and effective web attacks.

\n\n\n\'',NULL,1293894),('3_Saturday','17','16:30','17:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Taming the Swarm: Hard Architectural Lessons from Building a Deterministic Agentic Web Pentesting System\'','\'Albert \"yz9yt\" Corzo\'','DEF CON Talks_ba0e4cf2386ea12e31b3c6865e5ecb29','\'\'',NULL,1293895),('3_Saturday','17','17:00','17:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'CRLF-Powered Desync Attacks: Beheading HTTP streams\'','\'Tom \"t0xodile\" Stacey,Tobia \"mastersplinter\" Righi\'','DEF CON Talks_69aa97843dfb7f20f80f9d24ee13886d','\'Title: CRLF-Powered Desync Attacks: Beheading HTTP streams
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Have you ever discovered a header injection vulnerability and settled for little more than an open redirect or XSS? In this session, we introduce a battle-tested “header injection” powered desync methodology, enabling you to perform HTTP request smuggling attacks against even strictly RFC-compliant proxy chains.

\n\n

We will begin by explaining a well-known but overlooked CRLF injection primitive that produced HTTP Request Splitting inside the core infrastructure of a major CDN, resulting in the capture of live users’ credentials across thousands of compromised applications.

\n\n

Building upon this, we’ll demonstrate how header injections can be used to exploit more traditional smuggling attack classes, even when no parser discrepancy exists. Finally we’ll reveal how you can shift previously non-compliant desync attacks into the browser, unlocking a plethora of novel exploitation opportunities even when keep-alive connections are not shared between users. The result is a slew of real-word case studies with impacts ranging from account takeovers via desync-enabled XSS gadgets to cache poisoning, response queue poisoning, access control bypasses, and in several cases the possibility of creating the ever-terrifying desync worm.

\n\n

Finally, we’ll release two open source tools that introduce robust detection of header injection.

\n\nSpeakers:Tom \"t0xodile\" Stacey,Tobia \"mastersplinter\" Righi
\n
\nSpeakerBio:  Tom \"t0xodile\" Stacey, Independent
\n

Tom \'t0xodile\' Stacey is a security researcher at PortSwigger with a passion for automating the ideas that \"will never work\" to find gaps in the industry\'s current understanding of web security. He is best known for his work in discovering and exploiting underappreciated forms of desync attacks.

\n\n

At PortSwigger he spends most of his time experimenting with the HTTP protocol and the vulnerabilities that arise due to the disagreements between web servers and components with the goal of finding novel techniques to improve Burp Suite\'s capabilities. When he\'s not at work, he\'s usually playing some form of video / board game or building Lego.

\n\nSpeakerBio:  Tobia \"mastersplinter\" Righi, TurtleSec
\n

I am a security research and bug bounty hunter, recently I have started TurtleSec with other talented hackers, focusing on research driven projects. I spend most of my time tinkering with applications to try and figure out how to break them in the weirdest of ways.

\n\n\n\'',NULL,1293896),('3_Saturday','17','17:00','17:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'High Voltage Heist: Turning Your EV into my Power Bank\'','\'Fabien Guillebot,Stepan Konicek\'','DEF CON Talks_e2ccdea5311304a8e703cc734c3c0b7c','\'Title: High Voltage Heist: Turning Your EV into my Power Bank
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Ever found yourself with a dead phone battery in a Walmart parking lot? What if we told you that you could walk up to a parked EV and charge your phone directly from its traction battery - no authorization, no keys, and no official V2L features required.

\n\n

As the EV market expands, the complexity of its charging infrastructure scales with it. The push for Vehicle-to-Grid (V2G) communication capabilities introduces a significant attack surface with destructive potential for high-voltage systems. In this talk, we explore the security risks within current V2G communication. We break down exactly how this data is processed internally, map out the high-voltage charging architecture, and expose logic weaknesses hiding within the vehicle\'s Battery Management System (BMS) ECUs.

\n\n

Based on this research, we introduce ChargeSploit, a custom hardware and software toolkit designed for cybersecurity testing of the EV charging ecosystem. Capable of simulating both vehicles and chargers, or acting as a physical Man-in-the-Middle, ChargeSploit allows researchers to intercept, manipulate, and inject payloads into live communication flows. We conclude with a live demonstration exploiting V2G protocols and the BMS to force an unauthorized discharge, successfully powering an iPhone directly from a locked EV\'s traction battery.

\n\nSpeakers:Fabien Guillebot,Stepan Konicek
\n
\nSpeakerBio:  Fabien Guillebot, Accenture
\n

Fabien Guillebot is a Hardware Security Researcher at Accenture based in Prague, Czech Republic. He specializes in hardware-level security testing with a primary focus on the automotive sector. Fabien\'s core expertise lies in designing custom hardware for specialized penetration testing and conducting advanced research in microcontroller glitching and fault injection.

\n\nSpeakerBio:  Stepan Konicek, Accenture
\n

Stepan Konicek, MSc. is an Embedded Systems Penetration Tester at Accenture based in Prague, Czech Republic. Specializing in automotive cybersecurity, Stepan focuses on testing and securing ECUs and full-vehicle architectures. His primary research focus lies in EV charging security, where he investigates the physical and protocol-level vulnerabilities that exist between modern vehicles and grid infrastructure.

\n\n\n\'',NULL,1293897),('3_Saturday','17','17:00','17:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'OffGuard: Breaking the Most Popular AI Gateway from Auth Bypass to Cloud Compromise\'','\'Yaara Shriki\'','DEF CON Talks_4baa4a144ca1aba856368dcf6f70d24c','\'Title: OffGuard: Breaking the Most Popular AI Gateway from Auth Bypass to Cloud Compromise
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

LiteLLM is the most popular open-source AI gateway, deployed across a third of cloud environments. Organizations route all their LLM traffic through it, trusting it with API keys for every provider, every prompt and response, and connections to external tools via MCP. We broke every layer of its security model.

\n\n

We present three independent attack vectors, an authentication bypass in the MCP layer, a root-level RCE through sandbox escape, and an SSRF path to cloud credentials, that chain from zero credentials to full cloud infrastructure compromise. We validated every attack at internet scale across thousands of real-world instances and found that nearly 1 in 10 accepted default credentials or required no authentication at all.

\n\n

Beyond the individual findings, we examine the broader security patterns emerging across AI infrastructure and what they mean for organizations adopting AI gateways as core infrastructure.

\n\nSpeakerBio:  Yaara Shriki, Wiz (Google)
\n

Yaara Shriki is a Threat Researcher at Wiz, specializing in emerging threats in cloud environments and attack surface analysis. She explores novel ways to integrate ML and NLP into security research and investigates new attack vectors in cloud and AI infrastructure. Yaara is currently pursuing an MSc in Computer Science at Tel Aviv University.

\n\n\n\'',NULL,1293898),('3_Saturday','17','17:30','17:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition\'','\'Daniel Genkin,Jalen Chuang\'','DEF CON Talks_03ebfabc5f0b2c31bb1409a97c08bb42','\'Title: TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Saturday, Aug 8, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Trusted execution environments (TEEs) aim to offer strong privacy and integrity guarantees even in the presence of root level attackers. Recently there has been a pivotal shift in TEE deployment, moving TEEs from enclaves running on PC-oriented hardware to confidential virtual machines executing on server-grade CPUs. Under the hood, this change has also resulted in significant modifications to the underlying memory encryption engine, removing integrity guarantees as well as protections against replay attacks. While Intel\'s and AMD\'s change in TEE implementation is clearly significant and substantial, most TEE deployments appear to fail to acknowledge the difference in security guarantees, assuming a stronger security model than truly afforded by the implementation.\nThus, in this talk we discuss the true protection offered by Intel\'s and AMD\'s newest TEE offerings against entry-level physical side-channel attacks. We show that bus interposition attacks on DDR server memory can be constructed cheaply by hobbyists, using parts on e-commerce websites. With our bus interposer combined with the weaker security model of server TEEs, we will show a live demo of our ability to extract secret key material from machines in fully trusted status. Finally, we demonstrate the implications of our attacks on real world deployments.

\n\n

https://tee.fail\nPaper: https://tee.fail/files/paper.pdf\nPlease see our paper for references to prior work.

\n\nSpeakers:Daniel Genkin,Jalen Chuang
\n
\nSpeakerBio:  Daniel Genkin, Georgia Tech
\n

Daniel Genkin is an Associate Professor at the School of Cybersecurity and Privacy at Georgia Tech. Daniel’s research interests are in hardware and system security, with particular focus on side channel attacks and defenses. Daniel’s work has been recognized by best paper awards in multiple academic and industry venues, multiple Black Hat Pwnie awards, as well as covered by national and scientific press. Daniel has been part of the team performing the first analysis of speculative and transient execution, resulting in the discovery of Spectre, Meltdown and follow ups. Finally, he has a PhD in Computer Science from the Technion Israel’s Institute of Technology and is a 2024 Alfred P. Sloan Research Fellow.

\n\nSpeakerBio:  Jalen Chuang, Georgia Tech
\n

Jalen Chuang is a PhD student at the Hardware Security Lab at Georgia Tech. Jalen\'s research spans software fuzzing, CPU microarchitectural side-channels, and now focuses on trusted execution environments. Outside of research, Jalen is a regular CTF player and 2-time DEFCON CTF finalist.

\n\n\n\'',NULL,1293899),('4_Sunday','10','10:00','10:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'ESP32 as a counter-surveillance platform\'','\'Cooper \"Cybertiger\" Quintin,Colonel Panic,The Wrew\'','DEF CON Talks_a515656039c1b4ad28a42cfbb77e3d92','\'Title: ESP32 as a counter-surveillance platform
\nTags: DEF CON Official Talk | Demo 💻
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Privacy should be accessible to all. Historically, counter-surveillance tools have been expensive, complex, and inaccessible to most individuals, often limited to well-funded researchers and costly hardware configurations. The ESP32 offers a transformative alternative.\nThis presentation will demonstrate how an affordable microcontroller has become the foundation for a growing suite of open-source, user-friendly anti-surveillance tools. We will discuss the technical features that make the ESP32 a compelling choice for these applications, including passive 802.11 and Bluetooth monitoring, OUI-based device fingerprinting, and robust cryptographic capabilities.\nApplications include detecting police body cameras in operational environments, mapping Flock Safety automatic license plate recognition (ALPR) infrastructure, identifying unauthorized drones, detecting radio frequency jamming across 2.4GHz, 5GHz, and cellular bands, and tracking autonomous robots operating with known-vulnerable firmware. These tools are cost-effective and freely available. \nWe will also consider future developments in accessible counter-surveillance hardware, such as the ESP32-S5 with 5GHz support, GPS, displays, haptics, etc. Advancing anti-surveillance culture requires designing devices that individuals are motivated to use and carry.

\n\nSpeakers:Cooper \"Cybertiger\" Quintin,Colonel Panic,The Wrew
\n
\nSpeakerBio:  Cooper \"Cybertiger\" Quintin, Board Member at Open Archive
\n

Cooper Quintin is a security researcher and senior public interest technologist with the EFF Threat Lab. research fellow with Citizen Lab, adviser to CoRD Research and Design, and board member of Open Archive. He has worked on projects including Rayhunter, Privacy Badger, Canary Watch, and analysis of state sponsored malware campaigns such as Dark Caracal. Cooper has given talks about security research at prestigious security conferences including Black Hat, DEFCON, Enigma Conference, and ReCon about issues ranging from IMSI Catcher detection to fem tech privacy issues to newly discovered APTs. He has also been published or quoted in publications including: The New York Times, Reuters, NPR, CNN, and Al Jazeera. Cooper has given security trainings for activists, non profit workers, and vulnerable populations around the world. He previously worked building websites for nonprofits, including Greenpeace, Adbusters, and the Chelsea Manning Support Network. Cooper was also an editor and contributor to the hacktivist journal, \"Hack this Zine.\" In his spare time he enjoys making music, visualizing a solar-punk communitarian future, and playing with his kids.

\n\nSpeakerBio:  Colonel Panic
\n

Malware researcher by day, IoT rapid prototyper by night. Creator of Mesh-Detect and Oui-Spy. I love making things and bringing my ideas to a completed prototype rapidly. I’m Interested in privacy, digital rights, and detecting all the things.

\n\nSpeakerBio:  The Wrew, Hackers.Town
\n

Product Manager working on building pentesting platforms by day, hacker and electronics prototyper by night (and occasional weekend). Creator of VoidMantisOS for the hacker pager and SpectraMesh mesh networking protocol. Interested in security, privacy, RF, electronics and fighting digital surveillance.\nListed under: just handle

\n\n\n\'',NULL,1293900),('4_Sunday','10','10:00','10:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Going the Distance: Long-Range Keystroke Injection via Meshtastic\'','\'Benito \"paperclipsvinny\" Sauceda\'','DEF CON Talks_29d96c1b27fdf6b5cf89187ccc5b293d','\'Title: Going the Distance: Long-Range Keystroke Injection via Meshtastic
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

What if your keystroke injection implant could be triggered from kilometers away, through walls, without WiFi, cellular, or line-of-sight? What if the entire Meshtastic network relayed your commands for you?\nM.I.A. (Mesh Injection Apparatus) is a new open-source offensive tool that combines USB HID injection with LoRa mesh networking. Plant a device during brief physical access, then trigger payloads remotely- across a building, a campus, or a city, using Meshtastic\'s encrypted mesh protocol. No internet required. No WiFi range limitations. Just long-range, low-power radio that blends into the growing ecosystem of LoRa devices.\nThis talk covers the complete build: understanding USB HID at the protocol level, reverse-engineering Meshtastic\'s packet structure and AES-CTR encryption, implementing a DuckyScript parser from scratch in C++, and designing custom PCB hardware. I\'ll demonstrate remote-triggered injection over the mesh network, discuss operational considerations for red teams, and release all firmware, schematics, and tooling as open source.\nMIA represents a new class of implant, one that stays connected when traditional C2 channels fail.

\n\n

https://www.blackhillsinfosec.com/introducing-lora-long-range-wireless-technology-part-1/

\n\n

(I would like to cite Venky Raju\'s talk, but I could not find it online. I will try to reach out to him.)

\n\nSpeakerBio:  Benito \"paperclipsvinny\" Sauceda
\n

Benito Sauceda is a 19-year-old university student who saw a talk at a small regional conference, got inspired, and spent the next few months procrastinating homework to build his own version from scratch. It escalated quickly.

\n\n

His proudest accomplishments stem mostly from growing cybersecurity communities, a curious side effect of talking about hacking with everyone around him. He founded cybersecurity clubs at both his high school and local community college, taught cybersecurity to 8–12th grade students through the Bay Area Cyber League, and helped develop regional cybersecurity competitions for 16 Bay Area community colleges.

\n\n

This is his first DEF CON talk.

\n\n\n\'',NULL,1293901),('4_Sunday','10','10:00','10:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'No Prompt Required: Pre-Task RCE in Google Gemini CLI\'','\'Elad Meged\'','DEF CON Talks_dd6dd6206c7da2755b1ff10d0482d538','\'Title: No Prompt Required: Pre-Task RCE in Google Gemini CLI
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Security research on AI agents starts at the prompt boundary - injection, jailbreaking, guardrails. This talk starts earlier.

\n\n

AI agents accept inputs before the model processes its first task: configuration files, environment variables, startup parameters, protocol handshakes. In CI/CD, the agent runs headless - no human in the loop, and the workspace is automatically trusted. These inputs can reach shell execution or disable security controls before any prompt-time safeguard activates. The security model is already compromised before the model does anything.

\n\n

This talk demonstrates the pattern with a flagship exploit scored CVSS 10.0 by Google\'s security team - publicly disclosed and patched. The exploit is deterministic, requires no model interaction, and fires before the sandbox starts. An additional case from a different vendor confirms this is not a one-off.

\n\n

Attendees leave with a reusable offensive method for any AI agent system: enumerate what the system accepts before work begins, map what authority each input carries, and test whether that authority reaches execution or policy control. If it does, prompt-time defenses are irrelevant.

\n\n

https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g

\n\nSpeakerBio:  Elad Meged, Novee Security
\n

Elad Meged is a Founding Engineer and Security Researcher at Novee Security, specializing in offensive security research and AI security. He holds an M.Sc. in Computer Science and has a background in vulnerability research across web, mobile, and low-level systems, with experience in reverse engineering and platform internals. His current work applies offensive research methodology to AI systems while developing AI-driven approaches to vulnerability discovery and exploit verification.

\n\n\n\'',NULL,1293902),('4_Sunday','10','10:00','10:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Shepherding the Tor network\'','\'Roger \"arma\" Dingledine\'','DEF CON Talks_29e577bff89f7e7ffcafadf5bcf2c4ea','\'Title: Shepherding the Tor network
\nTags: DEF CON Official Talk
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

The Tor network has been continuously operating for close to 25 years now. How have the attacks changed over that time? How about the communities, threats, and incentive structures for the volunteers who operate the network?

\n\n

I\'ll go over early lessons as well as lessons we are still learning, when it comes to the Tor network -- from relays to directory authorities -- focusing on the community angle, on finding and kicking out bad relays, and generally looking at the safety of users and of relay operators.

\n\n

https://community.torproject.org/policies/relays/expectations-for-relay-operators/

\n\n

https://community.torproject.org/policies/dir-auth/dir_auth_expectations/

\n\n

https://www.freehaven.net/anonbib/#botnetfc14

\n\n

https://spec.torproject.org/vanguards-spec/

\n\n

https://research.torproject.org/safetyboard/

\n\nSpeakerBio:  Roger \"arma\" Dingledine, The Tor Project
\n

Roger Dingledine is co-founder and original developer of the Tor Project, a nonprofit that develops free and open source software to protect people from tracking, censorship, and surveillance online. Roger works with journalists and activists on many continents to help them understand and defend against the threats they face, and he is a lead researcher in the online anonymity field. EFF picked him for a Pioneer Award, and Foreign Policy magazine chose him as one of its top 100 global thinkers. This is his twelfth talk on the Defcon main stage.

\n\n\n\'',NULL,1293903),('4_Sunday','10','10:00','10:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'This Message Was Sent by Microsoft: Turning Microsoft Apps into our Phishing Platform\'','\'Keanu \"RedByte\" Nys\'','DEF CON Talks_68c33f186780a741eff7d883ca8188f3','\'Title: This Message Was Sent by Microsoft: Turning Microsoft Apps into our Phishing Platform
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Last DEF CON, we stole cleartext credentials directly from the real Microsoft login page. This year, we take it a step further by making Microsoft deliver our phishing emails!

\n\n

We\'ve all seen threat actors abuse built-in email notifications from legitimate SaaS platforms to send phishing links from trusted domains, bypassing email security solutions. But in most cases, they only control a small portion of the email content, making the end result far from convincing.

\n\n

While the execution of these examples has mostly been fairly poor and limited in complexity so far, the idea of making a legitimate application deliver your phishing payload did intrigue me. So I started digging for more advanced ways to push this concept further, looking for techniques that would allow taking over the majority (or sometimes the entirety) of the email content.

\n\n

In this talk, I\'ll present several novel techniques to inject custom phishing pretexts into emails sent by multiple first-party Microsoft services, taking advantage of their trusted email addresses and domain reputation.

\n\n

These emails seem so legitimate that even seasoned IT and security professionals would trust them (and we have the proof from our assessments to back this up). After all, who doesn\'t trust Microsoft? 😉

\n\n
    \n
  • DEFCON33 - Turning Microsoft\'s Login Page into our Phishing Infrastructure\n
      \n
    • https://www.youtube.com/watch?v=z6GJqrkL0S0
    • \n
  • \n
  • GraphSpy\n
      \n
    • https://github.com/RedByte1337/GraphSpy
    • \n
  • \n
  • SharePoint SendEmail API retirement\n
      \n
    • https://support.microsoft.com/en-us/office/retirement-of-the-sharepoint-sendemail-api-b35bbab1-7d09-455f-8737-c2de63fe0821
    • \n
  • \n
\n\nSpeakerBio:  Keanu \"RedByte\" Nys, Spotit
\n

Keanu Nys (aka RedByte) is an information security researcher from Belgium, and currently leads Spotit\'s offensive security team. While he has a passion for all offensive cybersecurity topics, he mostly specializes in Active Directory, Microsoft Entra ID (Azure AD), and Social Engineering.

\n\n

He is the author of the Microsoft 365 and Entra attack toolkit GraphSpy. Additionally, Keanu is the trainer for the Certified Azure Red Team Expert (CARTE) bootcamps at Altered Security, and has given talks, workshops and trainings at conferences like DEF CON, Blackhat USA, and BruCON.

\n\n\n\'',NULL,1293904),('4_Sunday','10','10:30','11:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Gotta Phish \'Em All! Novel Attack Techniques via Persistent Browser-in-the-Middle\'','\'Giacomo \"GiacoLenzo2109\" Lenzini\'','DEF CON Talks_8e63a4bcac8fb6a09828018b4998c6f9','\'Title: Gotta Phish \'Em All! Novel Attack Techniques via Persistent Browser-in-the-Middle
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Sunday, Aug 9, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

Browser-in-the-Middle (BitM) phishing is no longer just a research curiosity. Since its 2021 formalization, BitM has been cataloged by MITRE as an official attack pattern, recognized as a severe threat to MFA-protected web applications. Because the victim authenticates directly through the attacker\'s browser rather than their own, the technique effectively bypasses most traditional forms of MFA.

\n\n

This talk presents two years of research on weaponizing BitM for advanced offensive operations. We investigated what novel attack techniques become possible when an attacker fully controls the browser the victim interacts with. This includes real-time keystroke logging, in-transit file interception and silent modification, session persistence that keeps operator access alive long after the victim logs out, and microphone/webcam capture achieved through social-engineered browser flows.

\n\n

The practical validation of this research is P-BitM, the first open-source framework for Persistent Browser-in-the-Middle spear-phishing, which will be released at DEF CON 34. The \"Persistent\" in P-BitM carries its full offensive meaning: a single phishing click becomes a persistent beachhead. We will break down our core research, demonstrate these new attack vectors via demo videos, and showcase the capabilities of the tool.

\n\n

https://link.springer.com/article/10.1007/s10207-021-00548-5\nhttps://github.com/JoelGMSec/EvilnoVNC\nhttps://github.com/b3rito/peeko

\n\nSpeakerBio:  Giacomo \"GiacoLenzo2109\" Lenzini, EY
\n

Giacomo Lenzini is an Offensive Security Specialist and Red Teamer at EY Italy, and an independent security researcher. His work focuses on adversary simulation, red team operations, and penetration testing. He has received recognition from organizations such as NASA and has identified several vulnerabilities with associated CVEs.

\n\n\n\'',NULL,1293905),('4_Sunday','11','10:30','11:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Gotta Phish \'Em All! Novel Attack Techniques via Persistent Browser-in-the-Middle\'','\'Giacomo \"GiacoLenzo2109\" Lenzini\'','DEF CON Talks_8e63a4bcac8fb6a09828018b4998c6f9','\'\'',NULL,1293906),('4_Sunday','10','10:30','11:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Reversing a Recall: From ‘Noise Triggered’ to RCE\'','\'Ben Gardiner\'','DEF CON Talks_84699af564cefb6d5fe2ed4ac2869b4b','\'Title: Reversing a Recall: From ‘Noise Triggered’ to RCE
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Sunday, Aug 9, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

Heavy-duty trucks move the majority of freight in North America, making them a critical component of our infrastructure. When a major supplier issued a recall to address a seemingly harmless noise issue, the explanation didn\'t quite add up.

\n\n

This talk follows the reverse engineering journey that began with a simple question and led to a much larger discovery. By tearing apart firmware, analyzing the update protocols, and tracing ECU behavior, we uncovered evidence that the recall was not just remediating noise triggered flaws. Hidden within the recall\'s firmware update was a security mitigation addressing undisclosed vulnerabilities affecting a critical vehicle system.

\n\n

Attendees will see how modern tractor ECUs can be analyzed using professional and public tools and techniques (IDA Pro, idapython, qbindiff), the challenges of working with the safety-critical microcontrollers in heavy-vehicles (S12XE), and the evidence that revealed security impacts of the patch. Along the way, we\'ll discuss the growing cybersecurity risks facing commercial vehicles.

\n\n

Whether you\'re interested in automotive hacking, embedded systems, reverse engineering, or critical infrastructure security, this session offers a look inside the cybersecurity reality of the machines that keep the supply chain moving.

\n\n
    \n
  1. Aleph One. (1996). Smashing The Stack For Fun And Profit. Phrack Magazine, 7(49). http://phrack.org/issues/49/14.html
  2. \n
  3. Intellon Corporation. (1997). SSC P485 PL Transceiver IC Data Sheet.
  4. \n
  5. Hunter, J. D. (2007). Matplotlib: A 2D graphics environment. Computing in science & engineering, 9(3), 90-95.
  6. \n
  7. NXP Semiconductors. (2010). HiWave Debugger. Part of CodeWarrior Development Studio.
  8. \n
  9. Krzywinski, M., Birol, I., Jones, S. J., & Marra, M. A. (2011). Hive plots—rational approach to visualizing networks. Briefings in bioinformatics, 13(5), 627-644.
  10. \n
  11. SAE International. (2013). J1587: Electronic Data Interchange Between Microcomputer Systems in Heavy-Duty Vehicle Applications. Warrendale, PA.
  12. \n
  13. Miller, C., & Valasek, C. (2014). Adventures in Automotive Networks and Control Units. IOActive. https://www.ioactive.com/wp-content/uploads/pdfs/IOActive_Adventures_in_Automotive_Networks_and_Control_Units.pdf
  14. \n
  15. Behere, S., Zhang, X., Izosimov, V., & Törngren, M. (2016). A Functional Brake Architecture for Autonomous Heavy Commercial Vehicles. https://legacy.sae.org/publications/technical-papers/content/2016-01-0134/
  16. \n
  17. SAE International. (2016). J1708: Serial Data Communications Between Microcomputer Systems in Heavy-Duty Vehicle Applications. Warrendale, PA.
  18. \n
  19. TruckHacking organization. (2016). py-hv-networks. https://github.com/TruckHacking/py-hv-networks
  20. \n
  21. SAE International. (2018). J1939: Serial Control and Communications Heavy Duty Vehicle Network. Warrendale, PA.
  22. \n
  23. International Organization for Standardization. (2018). ISO 26262: Road vehicles -- Functional safety. Geneva, Switzerland.
  24. \n
  25. International Organization for Standardization. (2018). ISO/IEC 29147: Information technology -- Security techniques -- Vulnerability disclosure. Geneva, Switzerland.
  26. \n
  27. dfieschko. (2019). RP1210. https://github.com/dfieschko/RP1210
  28. \n
  29. MITRE Corporation. (2020). CVE-2020-14514. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14514
  30. \n
  31. International Organization for Standardization. (2020). ISO 14229: Road vehicles -- Unified diagnostic services (UDS). Geneva, Switzerland.
  32. \n
  33. Gardiner, B. (2022). Disclosure of confirmed remote write to J2497 aka PLC4TRUCKS. NMFTA, Alexandria, VA, Letter, March.
  34. \n
  35. National Motor Freight Traffic Association. (2022). Actionable Mitigations Options v9. https://nmfta.org/wp-content/media/2022/11/Actionable_Mitigations_Options_v9_DIST.pdf
  36. \n
  37. MITRE Corporation. (2022). CVE-2022-26131. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26131
  38. \n
  39. Pulse Security. (2022). Reversing the Ducati 696 ECU Part 2. https://pulsesecurity.co.nz/articles/ducati-696-part2
  40. \n
  41. Gardiner, B. (2022). Mitigating PLC4TRUCKS Remote Write. Proceedings of the 9th escar USA Conference. https://escar.info/downloads
  42. \n
  43. Cybersecurity and Infrastructure Security Agency. (2023). Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and -Default. https://www.cisa.gov/resources-tools/resources/shifting-balance-cybersecurity-risk-principles-and-approaches-security-design-and-default
  44. \n
  45. Bendix Commercial Vehicle Systems LLC. (2024). 24E086 Chronology. https://static.nhtsa.gov/odi/rcl/2024/RMISC-24E086-5355.pdf
  46. \n
  47. National Highway Traffic Safety Administration. (2024). Technical Service Bulletin 10194446. https://dot.report/bulletins/10194446
  48. \n
  49. National Highway Traffic Safety Administration. (2024). Technical Service Bulletin 10176745. https://dot.report/bulletins/10176745
  50. \n
  51. National Highway Traffic Safety Administration. (2024). Technical Service Bulletin 10222229. https://dot.report/bulletins/10222229
  52. \n
  53. PACCAR Incorporated. (2024). Safety Recall Report 24V-915. https://static.nhtsa.gov/odi/rcl/2024/RCLRPT-24V915-6438.PDF
  54. \n
  55. Navistar, Inc. (2024). Safety Recall Report 24V-818. https://static.nhtsa.gov/odi/rcl/2024/RCLRPT-24V818-4283.PDF
  56. \n
  57. Volvo Trucks North America. (2024). Safety Recall Report 24V-790. https://static.nhtsa.gov/odi/rcl/2024/RCLRPT-24V790-3386.PDF
  58. \n
  59. Bendix Commercial Vehicle Systems LLC. (2024). Technical Bulletin TCH-27-007. https://www.bendix.com/media/services-and-support/product-action-center-pdfs/tch_27_007_en_000.pdf
  60. \n
  61. Bendix Commercial Vehicle Systems LLC. (2024). Technical Bulletin TCH-27-006. https://www.bendix.com/media/services-and-support/product-action-center-pdfs/tch_27_006_en_000.pdf
  62. \n
  63. Bendix Commercial Vehicle Systems LLC. (2024). Technical Bulletin TCH-27-008. https://www.bendix.com/media/services-and-support/product-action-center-pdfs/tch-27-008_en_000.pdf
  64. \n
  65. ZF Friedrichshafen AG. (2024). mBSP XBS Factsheet. https://www.zf.com/public/org/ZF_CVS_mBSP_XBS_Factsheet_EN_296135.pdf
  66. \n
  67. Technology & Maintenance Council. (2024). Position Paper 2024-3: Next Generation Tractor-Trailer Technical Needs. American Trucking Associations. https://tmc.trucking.org/sites/default/files/TMC_PP-2024_3_NEXTGEN_TRACTOR_TRAILER_TECHNICAL_NEEDS%20.pdf
  68. \n
  69. Gardiner, B., Maag, J., & Tindell, K. (2024). Security Requirements for Vehicle Security Gateways. SAE International. https://www.sae.org/papers/security-requirements-vehicle-security-gateways-2024-01-2806
  70. \n
  71. Vehicle Cybersecurity Working Group (VCRWG), National Motor Freight Traffic Association. (2024). NMFTA Vehicle Cybersecurity Requirements. https://github.com/nmfta-repo/nmfta-vehicle_cybersecurity_requirements
  72. \n
  73. python-can Developers. (2024). python-can. https://python-can.readthedocs.io/
  74. \n
  75. Cohen, R., David, R., Mori, R., Yger, F., & Rossi, F. (2024). Improving binary diffing through similarity and matching intricacies. Proc. of the 6th Conference on Artificial Intelligence for Defense.
  76. \n
  77. Quarkslab. (2024). Quokka. https://github.com/quarkslab/quokka
  78. \n
  79. Bendix Commercial Vehicle Systems LLC. (2025). Safety Recall Report 25E-073. https://static.nhtsa.gov/odi/rcl/2025/RCLRPT-25E073-3346.pdf
  80. \n
  81. National Motor Freight Traffic Association. (2025). Bendix EC80 Recall: Safety and Security Implications. https://nmfta.org/bendix-ec80-recall-safety-and-security-implications/
  82. \n
  83. Cybersecurity and Infrastructure Security Agency. (2025). ICS Advisory (ICSA-25-021-03) Bendix EC-80. https://www.cisa.gov/news-events/ics-advisories/icsa-25-021-03
  84. \n
  85. National Security Agency. (2025). Ghidra. https://ghidra-sre.org/
  86. \n
  87. Hiveplotlib Developers. (2025). hiveplotlib. https://github.com/hiveplotlib/hiveplotlib
  88. \n
  89. Land Line Media. (2025). Defective Bendix ECUs have prompted recall of nearly half a million trucks with latest Paccar recall. https://landline.media/defective-bendix-ecus-have-prompted-recall-of-nearly-half-a-million-trucks-with-latest-paccar-recall/
  90. \n
  91. SAE Truck and Bus Control and Communications Network Committee. (2026). J2497 Power Line Carrier Communications for Commercial Vehicles. Work in Progress Draft Revision.
  92. \n
  93. Hex-Rays. (2026). IDA Pro. https://hex-rays.com/ida-pro/
  94. \n
  95. Python Software Foundation. (2026). Python Programming Language. https://www.python.org/
  96. \n
  97. Graphviz Authors. (2026). Graphviz. https://graphviz.org/
  98. \n
  99. ELDB. XPROG-box. https://www.eldb.eu/
  100. \n
  101. PEmicro. PROGS12Z Flash Programmer Software. https://www.pemicro.com/
  102. \n
  103. NXP Semiconductors. MC9S12XEQ512 Data Sheet. https://www.nxp.com/docs/en/data-sheet/MC9S12XEP100.pdf
  104. \n
  105. NXP Semiconductors. MC9S12XE Family Reference Manual. https://www.nxp.com/docs/en/reference-manual/MC9S12XERM.pdf
  106. \n
  107. DARPA. Assured Micropatching (AMP). https://www.darpa.mil/program/assured-micropatching
  108. \n
  109. LinkerScope Developers. LinkerScope. Visualization Tool.
  110. \n
  111. Zynamics. BinDiff. https://www.zynamics.com/bindiff.html
  112. \n
  113. hotwolf. HSW12. https://github.com/hotwolf/HSW12
  114. \n
  115. National Highway Traffic Safety Administration. NHTSA Recalls by Manufacturer. https://datahub.transportation.gov/Automobiles/NHTSA-Recalls-by-Manufacturer/mu99-t4jn
  116. \n
  117. Yapo, T. FL2K Experiments. https://hackaday.io/project/164346-fl2k-sdr
  118. \n
  119. Osmocom. Osmo-FL2k Project. https://osmocom.org/projects/osmo-fl2k
  120. \n
  121. National Highway Traffic Safety Administration. Federal Motor Vehicle Safety Standard No. 121, Air Brake Systems. 49 CFR 571.121.
  122. \n
  123. Evenchick, E. CANtact. https://cantact.io/
  124. \n
  125. National Motor Freight Traffic Association. j2497-keyhole. https://github.com/nmfta-repo/j2497-keyhole
  126. \n
  127. Motorola. Motorola S-Record Description (PDF). https://deramp.com/downloads/mfe_archive/060-Standards%20and%20Specifications/Hex%20Data%20Formats/Motorola%20S%20Record.pdf
  128. \n
\n\nSpeakerBio:  Ben Gardiner, NMFTA Inc.
\n

Ben is a Senior Cybersecurity Research Engineer contractor at the National Motor Freight Traffic Association, Inc.® (NMFTA)® specializing in hardware and low-level software security.

\n\n

With more than ten years of professional experience in embedded systems design and a lifetime of hacking experience, Ben has a deep knowledge of the low-level functions of operating systems and the hardware with which they interface.

\n\n

He has held security assurance and reversing roles at a global corporation, as well as worked in embedded software and systems engineering roles at several organizations.

\n\n

Ben has conducted workshops and presentations at leading cybersecurity and technical mobility events globally, including Black Hat USA, DEF CON, NorthSec, escar USA, ScapyyCon, the CyberTruck Challenge, GENIVI Security Sessions, Hack in Paris, and HackFest.

\n\n

In addition to speaking on the main stage at Black Hat USA and DEF CON, Ben is a volunteer at the DEF CON Hardware Hacking Village (DC HHV) and Car Hacking Village (CHV). He is GIAC -GPEN, and -GICSP certified and a GIAC advisory board member, serves as the chair of the SAE TEVEES18A1 Cybersecurity Assurance Testing Task Force (responsible for J3322), a contributor to ATA TMC task forces, the ISO/SAE JWG and a voting member of the SAE VESS.

\n\n\n\'',NULL,1293907),('4_Sunday','11','10:30','11:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Reversing a Recall: From ‘Noise Triggered’ to RCE\'','\'Ben Gardiner\'','DEF CON Talks_84699af564cefb6d5fe2ed4ac2869b4b','\'\'',NULL,1293908),('4_Sunday','11','11:00','11:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'Beyond the Ceremony: The 2026 Passkey Attack Surface\'','\'Matteo Giordano\'','DEF CON Talks_84e84c4f975e7283759015eae6fd61cf','\'Title: Beyond the Ceremony: The 2026 Passkey Attack Surface
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

Passkeys are marketed as phishing-resistant, and the WebAuthn ceremony at their center genuinely is. The catch: almost nobody runs only the ceremony. Roughly five billion passkeys are in active use (FIDO, 2026), yet only about a third of organizations use them as the primary sign-in, so a passkey almost always sits next to a weaker method. The cryptography covers only the ceremony, but the login rides on many moving parts, from the metal to the cloud: authenticator, cross-device transport, client, relying party, cloud sync, and the human who recovers the account. That is where it breaks, more often than the reputation suggests: in a recent audit, all 103 live relying parties tested were vulnerable to at least one server-side attack.

\n\n

This talk pulls the scattered research into one pass over all of them, one attack per stop that survives a correct ceremony, shown in action, heaviest on the relying party where engagements land, with a suggested testing order and the sources to go deeper. You also get Passkey Editor, a Burp extension that decodes and re-encodes the vendor wrappers that make this traffic unreadable, ships preset ceremony-layer attacks, and lets you craft any relying-party manipulation by hand in intercept and Repeater.

\n\n

Walk away knowing where passkey deployments break, with a tool to test them.

\n\n

A curated, non-exhaustive list of the key references behind this talk.

\n\n

Cultural anchor

\n\n
    \n
  • Nishant Kaushik (CTO, FIDO Alliance), Passkeys Are Not Broken. The Conversation About Them Often Is (https://fidoalliance.org/passkeys-are-not-broken-the-conversation-about-them-often-is/), September 2, 2025.
  • \n
\n\n

Specifications

\n\n
    \n
  • W3C Web Authentication Working Group, Web Authentication (WebAuthn) Level 3 (https://www.w3.org/TR/webauthn-3/); Level 2 Recommendation (https://www.w3.org/TR/webauthn-2/).
  • \n
  • FIDO Alliance, Credential Exchange Format (CXF) and Credential Exchange Protocol (CXP), Working Drafts (https://fidoalliance.org/specs/cx/cxp-v1.0-wd-20241003.html), 2024.
  • \n
\n\n

Academic

\n\n
    \n
  • Louis Jannett, Andreas Mayer, Maximilian Westers, Vladislav Mladenov, Christian Mainka, Jorg Schwenk, The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web (https://www.usenix.org/conference/usenixsecurity26/presentation/jannett), USENIX Security 2026.
  • \n
  • Alaa Daffalla et al., A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat Models (https://www.usenix.org/conference/usenixsecurity25/presentation/daffalla), USENIX Security 2025.
  • \n
  • Prince Bhardwaj and Nishanth Sastry (University of Surrey), State of Passkey Authentication in the Wild: A Census of the Top 100K Sites (https://arxiv.org/abs/2602.15135), PAM 2026 (Springer LNCS 16477).
  • \n
  • Jenny Blessing, Daniel Hugenroth, Ross J. Anderson, Alastair R. Beresford (University of Cambridge), SoK: Web Authentication and Recovery in the Age of End-to-End Encryption (https://doi.org/10.56553/popets-2025-0113), PoPETs 2025(3).
  • \n
  • Matteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. Paterson (ETH Zurich / USI), Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers (https://zkae.io/), USENIX Security 2026 (IACR ePrint 2026/058).
  • \n
  • Mazharul Islam, Sunpreet S. Arora, Rahul Chatterjee, Ke Coby Wang, CASPER: Detecting Compromise of Passkey Storage on the Cloud (https://www.usenix.org/conference/usenixsecurity25/presentation/islam), USENIX Security 2025.
  • \n
  • Kemal Bicakci, Fatih Mehmet Varli, Muhammet Emir Korkmaz, Yusuf Uzunay, QES-Backed Virtual FIDO2 Authenticators (https://arxiv.org/abs/2601.06554), arXiv:2601.06554, January 2026.
  • \n
  • Christian Catalano, Andrea Chezzi, Vita Santa Barletta, Franco Tommasi, Defeating FIDO2/CTAP2/WebAuthn using Browser-in-the-Middle and reflected XSS (https://link.springer.com/article/10.1007/s11416-025-00556-2), Journal of Computer Virology and Hacking Techniques 2025.
  • \n
  • Marco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara, Matteo Maffei, Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern Web (https://www.usenix.org/conference/usenixsecurity21/presentation/squarcina), USENIX Security 2021.
  • \n
  • Marco Casagrande, Daniele Antonioli, CTRAPS: CTAP Client Impersonation and API Confusion on FIDO2 (https://arxiv.org/abs/2412.02349), arXiv:2412.02349, 2024.
  • \n
  • Peizhou Chen, Vulnerability Testing for WebAuthn (MSc thesis, University of Twente; companion Burp_FIDO2 extension) (https://essay.utwente.nl/98532/), 2024.
  • \n
\n\n

Government guidance

\n\n
    \n
  • UK National Cyber Security Centre (NCSC), Comparing the security properties of traditional user credentials and FIDO2 credentials for personal use (https://www.ncsc.gov.uk/paper/traditional-user-and-fido2-credentials-personal-use), 2026.
  • \n
\n\n

Industry data and reports

\n\n
    \n
  • FIDO Alliance, The State of Passkeys 2026: Global Consumer and Workforce Report (https://fidoalliance.org/the-state-of-passkeys-2026-global-consumer-and-workforce-report/), May 7, 2026.
  • \n
  • FIDO Alliance, World Passkey Day 2025 / Passkey Pledge (over 1 billion people have activated a passkey; 15 billion accounts support passkeys) (https://fidoalliance.org/fido-alliance-launches-the-passkey-pledge-to-further-accelerate-global-movement-away-from-passwords/), May 2025.
  • \n
\n\n

Industry and practitioner research

\n\n
    \n
  • Luke Jennings (Push Security), MFA downgrade: how attackers are getting around phishing-resistant authentication (https://pushsecurity.com/blog/mfa-downgrade-attacks), July 2025.
  • \n
  • Carlos Gomez (IOActive), Authentication Downgrade Attacks: Deep Dive into MFA Bypass (https://www.ioactive.com/authentication-downgrade-attacks-deep-dive-into-mfa-bypass/), February 2026.
  • \n
  • Netcraft, Phishing After Passkeys: What Attacks to Expect (https://www.netcraft.com/blog/phishing-after-passkeys-what-attacks-to-expect), April 2026.
  • \n
  • Maarten Balliauw (Duende Software), Deep Dive: Relying Party ID and origin with Passkeys (https://duendesoftware.com/blog/20251014-deep-dive-into-relying-party-id-and-origin-with-passkeys), October 2025.
  • \n
  • Tobia Righi (mastersplinter), Passkey account-takeover research and CVE-2024-9956 (incl. the credential-ID-collision overwrite note) (https://mastersplinter.work/research/passkey/), 2025.
  • \n
  • Curtis Brazzell (PhishU), Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault (https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html), May 2026.
  • \n
  • U-Zyn Chua (uzyn), Passkey has a theft-detection feature, but Apple, Google and Microsoft broke it (https://uzyn.com/2025/passkey-has-a-theft-detection-feature-but-big-tech-broke-it/), May 2025.
  • \n
  • Scott Helme, Open-Sourcing passkeys-php: A Security-Focused WebAuthn Library for PHP (https://scotthelme.co.uk/open-sourcing-passkeys-php-a-security-focused-webauthn-library-for-php/), May 2026.
  • \n
  • Dennis Kniep, FIDO Cross-Device Phishing (caBLE/hybrid cross-device relay PoC) (https://denniskniep.github.io/posts/14-fido-cross-device-phishing/), September 2025.
  • \n
  • William Brown (firstyear), WTF is a passkey (Open Source Security podcast) (https://opensourcesecurity.io/2026/2026-01-passkey-william-brown/), January 2026.
  • \n
\n\n

Conference talks (forthcoming / concurrent / recent)

\n\n
    \n
  • Michael Grafnetter (DSInternals), Pass-the-Passkey family of attacks (https://www.dsinternals.com/en/black-hat-usa-26-pass-the-passkey/), Black Hat USA 2026 (forthcoming).
  • \n
  • Nevada Romsdahl and Kam Talebzadeh, SquarePhish 2.0: QR Code + OAuth 2.0 Device Code Flow Phishing for the Primary Refresh Token (https://disobey.fi/2026/profile/disobey-2026-433-squarephish-2-0-qr-code-oauth-2-0-device-code-flow-phishing-for-primary-refresh-token), Disobey 2026.
  • \n
\n\n

Relying-party CVEs (public record, some of them)

\n\n
    \n
  • CVE-2026-46419, Yubico java-webauthn-server (webauthn-server-core) (https://www.yubico.com/support/security-advisories/ysa-2026-02/).
  • \n
  • CVE-2025-26788, StrongKey FIDO Server (https://nvd.nist.gov/vuln/detail/CVE-2025-26788).
  • \n
  • CVE-2024-12225, Quarkus quarkus-security-webauthn (https://nvd.nist.gov/vuln/detail/CVE-2024-12225).
  • \n
  • CVE-2025-12150, Keycloak keycloak-services, attestation-policy bypass via fmt:none (https://github.com/advisories/GHSA-7g5x-9c4v-4w5r).
  • \n
  • CVE-2026-6856, Keycloak, AAGUID-allowlist bypass via packed self-attestation (NVD record not yet published; tracked at the Keycloak issue) (https://github.com/keycloak/keycloak/issues/48388).
  • \n
\n\nSpeakerBio:  Matteo Giordano, Anvil Secure
\n

Matteo Giordano is an Italy-based offensive security specialist and Security Engineer at Anvil Secure, focused on application penetration testing and offensive research, with a growing focus on AI Red Teaming and GenAI security. For the past year he has researched WebAuthn and passkeys from an attacker\'s perspective, mapping the real-world attack surface that sits around the protocol\'s cryptographic core, the work behind this talk.

\n\n\n\'',NULL,1293909),('4_Sunday','11','11:00','11:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Gone in 60 Frames – USB Video Exploitation\'','\'Alex Plaskett,Robert Herrera\'','DEF CON Talks_02e2285113ce924784820d3cc986e5ec','\'Title: Gone in 60 Frames – USB Video Exploitation
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

In 2025, Amnesty International, in collaboration with Google TAG, released a write-up of an in-the-wild chain of USB Linux kernel vulnerabilities which was used to compromise mobile devices.

\n\n

Whilst the vulnerabilities themselves were disclosed, no details on how these vulnerabilities could be exploited were provided. This led us to deep dive into these issues to determine how they could be leveraged for arbitrary code execution.

\n\n

This is the story of exploiting one of these vulnerabilities (CVE-2024-53104), an out of bounds write in USB Video which offered a brilliant exploit primitive leading to highly reliable code execution when chained together with an information leakage vulnerability.

\n\n

In this talk we will first discuss the in-the-wild vulnerabilities, moving on to providing background of USB specifics for several device classes and coverage guided fuzzing for finding new issues.

\n\n

We will then move onto a more recent information disclosure vulnerability CVE-2025-38494 which could be leveraged to bypass KASLR.

\n\n

An extensive deep dive into CVE-2024-53104 vulnerability will be performed (the OOB write) and we will discuss our novel technique used for exploitation of this issue and expose the power of the UVC_QUIRK_RESTRICT_FRAME_RATE quirk!

\n\n

Finally, we will wrap up our talk with several demonstrations.

\n\nSpeakers:Alex Plaskett,Robert Herrera
\n
\nSpeakerBio:  Alex Plaskett, NCC Group
\n

Alex Plaskett (@alexjplaskett) is an Associate Director within the Exploit Development Group (EDG) at NCC Group. Alex is a five-time Pwn2Own winner (desktop, mobile, embedded, and automotive) and has over 16+ years of experience in vulnerability research and exploitation. Alex has exploited vulnerabilities in a large range of high-profile products across many different areas of security. Alex is a frequent speaker at security conferences (e.g. BlackHat, OffensiveCon, Hexacon, HITB, BlueHat, POC, Troopers etc). Alex was previously leading security teams in Fintech, Mobile Security and Security Research) and just generally causing vendors to patch things on a regular basis!

\n\nSpeakerBio:  Robert Herrera, NCC Group
\n

Robert Herrera (@robert.herrera_) is a Lead Security Researcher within the Exploit Development Group (EDG) at NCC Group. Robert has extensive experience performing high-impact security audits and reverse-engineering for a diverse set of technologies ranging from automotive, modems, secure boot platforms, and wireless technologies. Robert has 9+ years of experience and has worn many hats over the years ranging from iOS Developer, Software Engineer, to Reverse Engineer.

\n\n\n\'',NULL,1293910),('4_Sunday','11','11:30','12:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Over a Million Cars to Theft\'','\'Aaron Schulman,Jerry Yu,Yibo Wei\'','DEF CON Talks_6d613bbbd63c0b721bceedc1e711295a','\'Title: BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Over a Million Cars to Theft
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Sunday, Aug 9, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

Car dealers predominantly in the Southwestern U.S. have been pre-installing \"KARR,\" an aftermarket anti-theft alarm system, in every car they sell. They offer these systems as an upgrade when you purchase your car, giving you smartphone-based control over your car locks and immobilizer; if you decline the offer, the dealer says they will deactivate the system. What they don\'t tell you: this security system is authenticated by a global shared key, so anyone who recovers that key can remotely control nearby KARR units with a smartphone.

\n\n

KARR is installed in an estimated 1.4 million cars, and every vulnerable unit shipped with the same authentication key, allowing an attacker with a smartphone to unlock the doors, disable the alarm and immobilizer, and trigger the horn and lights of any KARR-equipped vehicle. The core impact is unauthorized access, which can enable burglary, OBD-II access, and escalation including the key-programmer workflow we will demonstrate; every owner with KARR installed needs to update, including those who declined the upsell or inherited it used.

\n\n

We\'ll walk through how we discovered KARR, how KARR ends up in millions of cars, how the attack works end-to-end, and what owners can do to fix it today. We\'ll also show that the same recipe revealed vulnerabilities in other aftermarket BLE systems.

\n\n

Our paper: Yibo Wei, Jerry Yu, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, Nishant Bhaskar, Aaron Schulman, \"BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems\", USENIX Security 2026. (to appear)

\n\n

Aftermarket alarms: Ken Munro / Pen Test Partners, \"Gone in Six Seconds: Exploiting Car Alarms\", 2019. https://www.pentestpartners.com/security-blog/gone-in-six-seconds-exploiting-car-alarms/

\n\n

Aftermarket alarms: VERSPRITE, \"How Hackers Control & Steal Vehicles Remotely\" (Carlink remote-start vulnerability). https://versprite.com/vs-labs/hacking-remote-start-system/

\n\n

Automotive BLE and keyless entry: Xie et al., \"Access Your Tesla without Your Awareness: Compromising Keyless Entry System of Model 3\", NDSS 2023. https://www.ndss-symposium.org/ndss-paper/access-your-tesla-without-your-awareness-compromising-keyless-entry-system-of-model-3/

\n\n

Automotive BLE and keyless entry: NCC Group, \"Tesla BLE Phone-as-a-Key Passive Entry Vulnerable to Relay Attacks\", 2022. https://www.nccgroup.com/research/technical-advisory-tesla-ble-phone-as-a-key-passive-entry-vulnerable-to-relay-attacks/

\n\n

Automotive BLE and keyless entry: Francillon, Danev, Capkun, \"Relay Attacks on Passive Keyless Entry and Start Systems in Modern Cars\", NDSS 2011.

\n\n

Foundational automotive security: Koscher et al., \"Experimental Security Analysis of a Modern Automobile\", IEEE S&P 2010. https://doi.org/10.1109/SP.2010.34

\n\n

Foundational automotive security: Checkoway et al., \"Comprehensive Experimental Analyses of Automotive Attack Surfaces\", USENIX Security 2011. https://www.autosec.org/pubs/cars-usenixsec2011.pdf

\n\n

BLE application-layer auth: Sivakumaran and Blasco, \"A Study of the Feasibility of Co-located App Attacks against BLE and a Large-Scale Analysis of the Current Application-Layer Security Landscape\", USENIX Security 2019. https://www.usenix.org/conference/usenixsecurity19/presentation/sivakumaran

\n\n

Measurement and tooling: WiGLE, Wireless Network Mapping. https://www.wigle.net/

\n\n

Measurement and tooling: ILSpy, open-source .NET assembly browser and decompiler. https://github.com/icsharpcode/ILSpy

\n\nSpeakers:Aaron Schulman,Jerry Yu,Yibo Wei
\n
\nSpeakerBio:  Aaron Schulman, University of California, San Diego
\n

Aaron Schulman is an Associate Professor at University of California, San Diego. His research group works on problems that involve gathering large-scale measurements to test whether assumptions about security, and sometimes reliability, match reality. This work often leads his students to gather data on rooftops, at fast food restaurants, gas stations, and hospitals, and while riding in cars, trains, and airplanes. He earned his PhD in Computer Science from University of Maryland, where he studied Internet reliability, and he did a postdoctoral fellowship at Stanford University, where he investigated bottlenecks in cellular infrastructure. Aaron co-discovered sensitive unencrypted data sent over GEO satellites from cellular providers, governments, militaries, and power grid operators. He also co-developed a Bluetooth credit card skimmer detector that federal and state law enforcement have used to stop millions of dollars in credit card fraud. While in Silicon Valley, he co-founded a company that helped Google improve the battery life of the Chrome web browser. This is his third year attending DEF CON.

\n\nSpeakerBio:  Jerry Yu
\n

Jerry Yu is a wireless systems software engineer associated with the SysNet research group at University of California, San Diego. He contributed to this work by reverse-engineering the mobile apps behind the aftermarket BLE automotive control systems we studied.

\n\nSpeakerBio:  Yibo Wei, University of California, San Diego
\n

Yibo Wei is a PhD student at University of California, San Diego, advised by Professor Aaron Schulman. He is the lead author of the forthcoming USENIX Security 2026 paper on BLE Theft Auto (under embargo), an ecosystem-wide study of aftermarket BLE-based automotive remote control systems. He led the reverse-engineering, protocol analysis, population estimation, and disclosure for this work. This will be his first time attending DEF CON.

\n\n\n\'',NULL,1293911),('4_Sunday','12','11:30','12:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'BLE Theft Auto: How a Dealer-Installed Anti-Theft System Exposes Over a Million Cars to Theft\'','\'Aaron Schulman,Jerry Yu,Yibo Wei\'','DEF CON Talks_6d613bbbd63c0b721bceedc1e711295a','\'\'',NULL,1293912),('4_Sunday','11','11:30','12:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'From Fuzzer Noise to a Weaponized PHP Exploit: Exploiting a PHP Use-After-Free Vulnerability\'','\'Can Oztas,Kağan Çapar\'','DEF CON Talks_b5b8a3af6d6ae88380b2aeded121dddb','\'Title: From Fuzzer Noise to a Weaponized PHP Exploit: Exploiting a PHP Use-After-Free Vulnerability
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Sunday, Aug 9, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\nIt started as fuzzer noise: an OSS-Fuzz crash in PHP\'s concat_function, filed under a JIT target but with no JIT in the stack. It is a core Zend Engine use-after-free, reproducible with php -n and no extensions. This is an honest exploitability study on Linux x86-64: from the mistriaged crash to native command execution (arbitrary read/write via stale DateInterval, zif_system resolved in-process, ASLR and PIE defeated at runtime) even where disable_functions is set. It builds on the public exploitation lineage, with an SPL ArrayObject delivery trick as our own delta.
\n\n
    \n
  1. OSS-Fuzz Issue #483856591 — Original crash report filed under php-fuzz-function-jit target
  2. \n
  3. PHP Source: Zend/zend_operators.c, concat_function() — https://github.com/php/php-src/blob/master/Zend/zend_operators.c
  4. \n
  5. php/php-src#16726 — Array-element UAF (second-chain vulnerability used to bypass mod-16 alignment barrier)
  6. \n
  7. Zend MM Internals: https://www.phpinternalsbook.com/php7/memory_management/zend_memory_manager.html
  8. \n
  9. CVE-2022-29072 — Prior 7-Zip zero-day by the same researcher (Kağan Çapar), demonstrating track record in vulnerability research
  10. \n
  11. CVE-2026-5201 — gdk-pixbuf heap buffer overflow discovered by the same researcher, acknowledged by Red Hat (CVSS 7.5)
  12. \n
  13. W3Techs PHP Usage Statistics — https://w3techs.com/technologies/details/pl-php
  14. \n
  15. V8 Sandbox Design (2024) — Referenced in comparative interpreter memory model analysis
  16. \n
\n\nSpeakers:Can Oztas,Kağan Çapar
\n
\nSpeakerBio:  Can Oztas
\n

Can Oztas is a security researcher with applied R&D experience across several key sectors, including defense, finance, and telecommunications. His background encompasses AppSec, vulnerability research, and offensive security engineering. He is currently a PhD student focusing on the intersection of Artificial Intelligence and cybersecurity.

\n\nSpeakerBio:  Kağan Çapar
\n

Kağan Çapar is a Vulnerability Researcher with over 15 years of experience. His research focuses on binary exploitation, fuzzing, and zero-day discovery across widely deployed software.

\n\n\n\'',NULL,1293913),('4_Sunday','12','11:30','12:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'From Fuzzer Noise to a Weaponized PHP Exploit: Exploiting a PHP Use-After-Free Vulnerability\'','\'Can Oztas,Kağan Çapar\'','DEF CON Talks_b5b8a3af6d6ae88380b2aeded121dddb','\'\'',NULL,1293914),('4_Sunday','12','12:00','12:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud\'','\'Sammy Azdoufal\'','DEF CON Talks_4f3f08f31d2b51849d1340a470b12958','\'Title: 1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

In March 2026, while reverse-engineering the cloud platform behind a popular line of consumer baby monitors and home security cameras, I discovered that one MQTT SUBSCRIBE wildcard returned the live message stream from every device on the platform. 1.1 million cameras. Motion alerts with image URLs. Floor plans. P2P credentials. Audio events. From baby monitors, doorbells, indoor cameras.

\n\n

That was one of twelve.

\n\n

This talk presents a complete vendor surveillance audit of Meari Technology — a Hangzhou-based ODM whose firmware ships under 300+ white-label brands across 118 countries. Not a single bug. Twelve independent evidence chains, each one separately demonstrating that the vendor possesses by-design, architectural access to every camera they sell. EMQX brokers with admin/public on four regions. An Apollo configuration server returning 600+ production secrets without authentication. A CMS portal with 25+ live-camera endpoints accessible to 678 employees through DingTalk SSO. A universal TUTK authcode shared across every device. Cloud video IDOR. Plain-JPEG alerts on shared OSS buckets with no per-customer isolation.

\n\n

Then I\'ll walk through what happened after disclosure: the vendor\'s IPO twelve days after first contact, the backdated security advisories, the three regional brokers fixed five days apart (incident

\n\n
    \n
  • Disclosure repository (public May 11, 2026): github.com/xn0tsa/meari-cloudedge-security-audit
  • \n
  • CVE-2026-33356 — MQTT Broker Missing Per-Device Subscribe ACL
  • \n
  • CVE-2026-33357 — OpenAPI Device Status IDOR (WAN IP Disclosure)
  • \n
  • CVE-2026-33358 — Cloud Video IDOR (No Ownership Check)
  • \n
  • CVE-2026-33359 — Alert Images Unauthenticated
  • \n
  • CVE-2026-33360 — API Signature Validation Disabled (CN Production)
  • \n
  • CVE-2026-33361 — Weak XOR Encryption on Baby Monitor Images
  • \n
  • CVE-2026-33362 — Hardcoded Static Cryptographic Keys in Client SDK
  • \n
  • CVE coordination: Tod Beardsley, runZero, Inc.
  • \n
  • CISA coordinated advisory (publication pending)
  • \n
  • Speaker\'s prior work: DJI ROMO MQTT ACL bypass disclosure (February 2026), as covered by The Verge, Cybernews, Popular Science, TheGuardian, The Wired...
  • \n
  • Meari Technology official security advisories: meari.com/en/securityCenter
  • \n
  • EMQX broker: emqx.io
  • \n
  • Apollo Configuration Management: github.com/apolloconfig/apollo
  • \n
  • XXL-Job scheduler: github.com/xuxueli/xxl-job
  • \n
  • GDPR Articles 33 and 34: eur-lex.europa.eu
  • \n
  • EU Whistleblower Directive 2019/1937: eur-lex.europa.eu
  • \n
\n\nSpeakerBio:  Sammy Azdoufal
\n

Sammy Azdoufal is an independent security researcher and software engineer based in Barcelona. His work focuses on the cloud and mobile attack surface of consumer IoT, with an emphasis on Chinese ODM/OEM ecosystems supplying the smart-home market in Europe and North America.

\n\n

In February 2026, he disclosed a critical MQTT ACL bypass affecting roughly 7,000 DJI ROMO robot vacuums across 24 countries, granting live camera and microphone access. The disclosure was covered by The Verge, Cybernews, Popular Science, The Guardian..., and led to a $30,000 bug bounty award from DJI. He is known for using AI coding assistants — specifically Anthropic\'s Claude Code — as part of his reverse-engineering workflow, and for combining hands-on protocol analysis with disciplined responsible-disclosure practice.

\n\n

The Meari Technology audit presented in this talk was conducted between February and April 2026, with CVE coordination performed by Tod Beardsley (runZero, Inc.) and disclosure coordinated with CISA. It is his largest single-vendor IoT audit to date.

\n\n

Public handle: xn0tsa (GitHub). This will be Sammy\'s first DEF CON Main Stage presentation.

\n\n\n\'',NULL,1293915),('4_Sunday','12','12:00','12:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2','\'MSIX\'d Up: Weaponizing the Modern Windows App Packaging Ecosystem\'','\'Nick \"zyn3rgy\" Powers\'','DEF CON Talks_6eba4fe45874014103d74e8dd50beba0','\'Title: MSIX\'d Up: Weaponizing the Modern Windows App Packaging Ecosystem
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - Map
\n
\nDescription:
\n

What happens when the ecosystem Microsoft built for isolation and integrity of modern Windows applications becomes a foundation for novel attacker tradecraft?

\n\n

For over 13 years, an ecosystem that now includes MSIX, UWP, AppContainers, package identity, and the Windows Runtime has shipped by default on modern Windows. Yet offensive research into this ecosystem remains scarce, and visibility into its abuse lags further behind. In this talk, we demonstrate novel techniques spanning all major parts of an attack path.

\n\n

For initial access, we abuse URL protocol handlers and packaging file formats to subvert endpoint detections. For post-exploitation, we overcome AppContainer process isolation to operate beneath EDR visibility thresholds. For lateral movement, we expose previously unabused WMI providers and DCOM objects within package installation services. For privilege escalation, we chain a logic flaw in package capabilities to achieve SYSTEM from a standard user context.\nEvery technique requires no third-party software, works on fully patched systems, and abuses default-enabled features. Tools for red teams will be released alongside detection guidance for defenders.

\n\n

The modern app packaging ecosystem was designed for isolation and integrity. We used its design to our advantage and turned it into an attack platform.

\n\n

https://projectzero.google/2021/08/understanding-network-access-windows-app.html

\n\n

https://www.pentestpartners.com/security-blog/ms-enterprise-app-management-service-rce-cve-2022-35841/

\n\n

https://conference.hitb.org/hitbsecconf2018pek/materials/D1T2%20-%20The%20Inner%20Workings%20of%20the%20Windows%20Runtime%20-%20James%20Forshaw.pdf\nhttps://activecyber.us/activelabs/windows-appx-deployment-service-local-privilege-escalation-cve-2020-1488

\n\nSpeakerBio:  Nick \"zyn3rgy\" Powers, SpecterOps
\n

An offensive security professional with experience in leading and offering red team assessments and penetration testing across several attack surfaces to a diverse set of industries. Professional interests include furthering knowledge of Windows internals, static and dynamic Endpoint Detection & Response (EDR) evasion, as well as initial access attack surface research. Passionate about contributing back to the security community by speaking at conferences such as Defcon, Wild West Hackin’ Fest, and Troopers along with instructing course content at conferences such as BlackHat USA.

\n\n\n\'',NULL,1293916),('4_Sunday','12','12:00','12:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Your WAF Blocked Us, That Was The Exploit - Remote Agent Takeover via Cloudflare, Sentry and Claude Zero-Day for data exfil\'','\'Barak Sternberg,Nevo Poran,Ron Bobrov\'','DEF CON Talks_1cf5080e69cafbc780c4aae4d4db1480','\'Title: Your WAF Blocked Us, That Was The Exploit - Remote Agent Takeover via Cloudflare, Sentry and Claude Zero-Day for data exfil
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

What happens when getting blocked by your WAF is exactly how the attacker gets in? We built two new remote exploit chains that hijack AI agents through Cloudflare and Sentry - two of the most trusted tools on the internet. No malware. No binary exploits. The attacker never touches the victim or their agent. Just text in public logs, waiting to be read.\nChain 1: We send requests Cloudflare blocks with 403 - and that is the attack. Our payloads land in WAF logs. When a dev asks their agent to debug Cloudflare, injections activate via cloudflare queries. Using only Cloudflare\'s own MCP tools, we hijack DNS and reroute customer traffic.\nChain 2: We inject stacktraces into Sentry\'s public API, no auth needed. Sentry\'s \"Seer\" agent reads them, gets compromised, and its poisoned recommendations flow into a developer\'s Cursor which executes our commands. One agent infecting another. First demo of agent-to-agent lateral movement and \"Self-Exploiting Agent\" technique.\nThen we go deeper: a zero-day in Claude bypasses its network sandbox for full data exfiltration. For persistence, we show how \"agentic rootkits\" work by memory injection and config poisoning, invisible to EDRs. est 15,000+ organizations exposed via Cloudflare MCP alone. 27% of them are Fortune 1000. Responsibly disclosed. We\'re now showing everything.

\n\n

*Cloudflare MCP Server documentation and public deployment\n*Sentry MCP Server and Seer AI agent documentation\n*Anthropic Claude Desktop application architecture\n*Cursor AI coding agent - MCP integration and tool architecture\n*OWASP Top 10 for LLM Applications (2025)\n*MITRE ATLAS - Adversarial Threat Landscape for AI Systems\n*Clinejection (Feb 2026) - GitHub issue title exploit compromising Cline\'s release pipeline\n*Comment & Control (Apr 2026) - prompt injection via PR titles leaking secrets from Claude Code, Gemini CLI, and Copilot

\n\nSpeakers:Barak Sternberg,Nevo Poran,Ron Bobrov
\n
\nSpeakerBio:  Barak Sternberg, Tenet Security
\n

Barak Sternberg is a cybersecurity researcher, offensive security specialist, and a returning DEFCON speaker. His research career spans over 15 years across every major attack surface of the last decade: from IoT to browser extension exploits (DEFCON 29), to Kube infra attacks (with Nevo), to smart device hacking (DEFCON Safe Mode IoT Village). He\'s presented at DEFCON (twice), Hacktivity, RootCon, BSides, Intent, and numerous other security conferences worldwide. He\'s a Unit 8200 veteran and Israel Defense Prize recipient. His research has consistently focused on finding novel attack chains in emerging technology before attackers do, across years in offensive cybersecurity. He also co-founded Wild Pointer (offensive security, Fortune 500 clients) and more recently co-founded Tenet Security as CEO with Nevo: but the research came first, the company came from the research, not the other way around. He leads Tenet while staying hands-on - the exploit chains in this talk came directly from his team\'s research

\n\nSpeakerBio:  Nevo Poran
\n

Nevo Poran, cybersecurity researcher, Co-Founder & CTO of Tenet Security, and a top-tier security engineer focused on GenAI, API, and application security. Unit 8200 veteran and 2x Excellence Awards. Nevo co-founded Wild Pointer with Barak, serving as technical lead and later CEO, managing teams delivering offensive R&D to Cisco, Noname Security, and Fortune 500 clients. He then co-led Cisco\'s first GenAI Security Research Team - building the AI Defense product from research through production. Deep hands-on expertise in reverse engineering, exploit development, and agent runtime security. Speaks on Kubernetes/cloud and GenAI security (CyberArk INTENT 2024, UNC Symposium 2025) and co-presented the Kubernetes etcd exploitation research with Barak. They\'ve been breaking things together for years.

\n\nSpeakerBio:  Ron Bobrov, Tenet Security
\n

Ron Bobrov is a senior security researcher at Tenet Security with 10 years of experience in offensive security, penetration testing, and vulnerability research. He has specialized in emerging attack vectors and has recently focused on AI agent security, conducting red-team assessments that have uncovered critical vulnerabilities in modern LLM-based systems.\nAt Tenet Security, Ron leads research initiatives exploring the intersection of traditional security threats and AI-specific attack surfaces. His work on bypassing A2AS framework protections has revealed fundamental architectural gaps in current AI agent security approaches, contributing to the development of runtime protection methodologies for agentic systems. Ron\'s research combines deep technical expertise in system exploitation with novel approaches to adversarial AI security, helping organizations understand and defend against the next generation of attacks targeting AI agents in production environments.

\n\n\n\'',NULL,1293917),('4_Sunday','12','12:30','13:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'CUDA\'ve done better - Hacking Nvidia GPUs for container-escape and privilege escalation\'','\'Daniel \"0xDACA\" Cohen Hillel,Noam Trobishi\'','DEF CON Talks_48784c0407923f21cbf9f2990cdee725','\'Title: CUDA\'ve done better - Hacking Nvidia GPUs for container-escape and privilege escalation
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Sunday, Aug 9, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

CUDA\'ve done better - Hacking Nvidia GPUs for container-escape and privilege escalation.\nWe found and exploited a UAF in the NVIDIA Linux kernel module that allows us to escape NVIDIA containers and gain root access on the host. We\'ll show novel exploitation techniques: bypass kernel heap mitigations, deterministically win races by abusing rw_semaphore, and execute code on the kernel without ever jumping anywhere (by writing directly to physical memory).

\n\nSpeakers:Daniel \"0xDACA\" Cohen Hillel,Noam Trobishi
\n
\nSpeakerBio:  Daniel \"0xDACA\" Cohen Hillel
\n

I used to be a vulnerability researcher for the army, but now that I\'m a full time physics grad student researching superconducting quantum computers at the Weizmann Institute (very unrelated to hacking).

\n\n

I just love hacking so much that I still do it in my spare time, while not doing physics. I like using hacking as an excuse to learn and deeply understand stuff. NVIDIA is a good example. I wanted to learn more about GPUs because of all the latest advancements in AI, so instead of seeing a tutorial/lecture about it, I just opened the code and started researching it. Another good example is when I hacked Merkle trees to learn more about zero-knowledge proofs.

\n\nSpeakerBio:  Noam Trobishi, Atom
\n

Noam is a low-level systems, GPU, and vulnerability researcher at Atom, where he works on GPU infrastructure for AI. He previously served in an IDF cyber unit and later worked as a vulnerability researcher at a private cybersecurity company. Noam holds a B.Sc. in Computer Science and Mathematics from the Hebrew University of Jerusalem and is currently pursuing a master’s degree in Mathematics at the Hebrew University.

\n\n\n\'',NULL,1293918),('4_Sunday','13','12:30','13:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'CUDA\'ve done better - Hacking Nvidia GPUs for container-escape and privilege escalation\'','\'Daniel \"0xDACA\" Cohen Hillel,Noam Trobishi\'','DEF CON Talks_48784c0407923f21cbf9f2990cdee725','\'\'',NULL,1293919),('4_Sunday','12','12:30','13:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Chaining Microsoft Binaries to get Privileged Primitives in the Windows kernel\'','\'Angelo Frasca Caccia\'','DEF CON Talks_e970f4dc3a1fee96ffb66d28221f6d95','\'Title: Chaining Microsoft Binaries to get Privileged Primitives in the Windows kernel
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Sunday, Aug 9, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

System Guard Runtime Monitor was meant to be an OS integrity anchor on Windows. A kernel driver, gated behind Protected Process Light (PPL), and a runtime attestation engine running in a secure enclave.\nIn this talk, we revisit a classic code injection technique and adapt it into what we call \"Bring Your Own Vulnerable WerFaultSecure\". Instead of loading a third-party vulnerable driver, we bring our own vulnerable copy of a PPL-enabled Microsoft binary and its dependencies to get code execution as a protected process. From there, we pivot into the Microsoft System Guard kernel driver, a component that was built to support the integrity attestation of kernel objects, specifically processes, but which can be abused to tamper with those exact objects instead.\nWe will close by sharing Indicators of Compromise (IOCs), along with prevention and detection ideas for defenders, and by discussing the innovation this exploit chain brings to the offensive security landscape.

\n\n

https://infocon.org/mirrors/vx%20underground%20-%202025%20June/Papers/Windows/Internals%20and%20Analysis/2022-08-02%20-%20Inside%20Windows%20Defender%20System%20Guard%20Runtime%20Monitor.pdf\nhttps://www.microsoft.com/en-us/security/blog/2018/04/19/introducing-windows-defender-system-guard-runtime-attestation/\nhttps://googleprojectzero.blogspot.com/2018/10/injecting-code-into-windows-protected.html\nhttps://googleprojectzero.blogspot.com/2018/11/injecting-code-into-windows-protected.html \nhttps://x.com/GabrielLandau/status/1683854578767343619 \nhttps://blog.scrt.ch/2023/03/17/bypassing-ppl-in-userland-again/ \nhttps://iamelli0t.github.io/2021/04/10/RPC-Bypass-CFG.html
\nhttps://github.com/Slowerzs/PPLSystem\nhttps://github.com/mdsecactivebreach/com_inject/\nhttps://helgeklein.com/blog/anatomy-of-werfault-exe-application-crash-error-reporting/

\n\nSpeakerBio:  Angelo Frasca Caccia, SentinelOne
\n

Angelo is a security researcher specialized in Windows Internals. He currently works at SentinelOne, where he conducts research on advanced exploits and tampering techniques targeting the Windows ecosystem. Angelo’s background also includes web application penetration testing and red teaming, particularly assume-breach adversary simulations.

\n\n

Angelo is eCXD, eCPPT, eJPT and OSCP certified. He enjoys reverse engineering and programming, mostly in C/C++. His GitHub profile (https://github/lem0nSec) features his main contributions to the cybersecurity community.

\n\n

Angelo has a master’s degree in International Security Studies from University of Leicester, where he graduated in 2021 with the ‘Best Campus-Based Masters Dissertation Prize’ and the ‘Best Campus-Based Masters Student Performance Prize’.

\n\n\n\'',NULL,1293920),('4_Sunday','13','12:30','13:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'Chaining Microsoft Binaries to get Privileged Primitives in the Windows kernel\'','\'Angelo Frasca Caccia\'','DEF CON Talks_e970f4dc3a1fee96ffb66d28221f6d95','\'\'',NULL,1293921),('4_Sunday','13','13:00','13:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Chaining Logical Bugs for Reliable Windows LPE\'','\'Bocheng \"Crispr\" Xiang,HeeChan \"heegong123\" Kim\'','DEF CON Talks_535a5243e8eb222f40cfe6452aec68f8','\'Title: Chaining Logical Bugs for Reliable Windows LPE
\nTags: DEF CON Official Talk | Demo 💻 | Exploit 🪲
\nWhen: Sunday, Aug 9, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

Modern Windows exploit mitigations have made memory corruption significantly harder, but reliable privilege escalation still emerges from a quieter class of bugs: logical flaws in privileged components. This talk shows how low impact Windows bugs become practical SYSTEM exploits when treated as reusable primitives over privileged resources.

\n\n

We will walk through two distinct LPE chains to illustrate this concept. First, we demonstrate a novel LPE approach achieved by chaining service-level process termination with arbitrary file deletion. Second, we explore another powerful LPE path that leverages kernel- and task-driven registry creation and deletion primitives, ultimately turning attacker-controlled registry state into code execution via Performance DLL hijacking.

\n\n
    \n
  • ZDI-24-1098: https://www.zerodayinitiative.com/advisories/ZDI-24-1098/
  • \n
  • ZDI-24-451 / CVE-2024-30033: https://www.zerodayinitiative.com/advisories/ZDI-24-451/
  • \n
  • CVE-2025-60705: Windows Client-Side Caching Elevation of Privilege Vulnerability
  • \n
  • CVE-2025-59512: Windows Arbitrary Registry Deletion Elevation of Privilege Vulnerability
  • \n
  • Public Microsoft / MSRC security update references for patched issues
  • \n
  • itm4n, \"Windows RpcEptMapper Service Insecure Registry Permissions EoP\": https://itm4n.github.io/windows-registry-rpceptmapper-eop/
  • \n
  • itm4n, \"An Unconventional Exploit for the RpcEptMapper Registry Key Vulnerability\": https://itm4n.github.io/windows-registry-rpceptmapper-exploit/
  • \n
\n\nSpeakers:Bocheng \"Crispr\" Xiang,HeeChan \"heegong123\" Kim
\n
\nSpeakerBio:  Bocheng \"Crispr\" Xiang, Fudan Univeristy
\n

Bocheng Xiang (@crispr_x) is a PhD candidate at Fudan University. He is listed on the MSRC MVR 2024/2025 and ranked Top #20 on the MSRC 2024 Q3 Windows Leaderboard. He has published papers at USENIX Security 2025, and his works have been accepted by PoC2025, re//verse2026 and BlackHat USA/Europe.

\n\nSpeakerBio:  HeeChan \"heegong123\" Kim, TeamH4C
\n

HeeChan Kim is a security researcher and a student at Soongsil University, specializing in Windows OS internals and Local Privilege Escalation (LPE). As a winner of the DEF CON 33 CTF with team MMM and a member of TeamH4C, he actively hunts for zero-days and persistent logical flaws within complex OS architectures. He has previously presented his Windows LPE research at POC and RE//verse.

\n\n\n\'',NULL,1293922),('4_Sunday','11','11:00','11:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'LaunchBreak: a Sip of Tea, a Click, and a Full Multi-stage Desktop Takeover\'','\'Gavin Zhong,Zhengyu Liu,Jianjia Yu\'','DEF CON Talks_f4f26f67bc62ff8ff6da3d77aa103b0c','\'Title: LaunchBreak: a Sip of Tea, a Click, and a Full Multi-stage Desktop Takeover
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠 | Exploit 🪲
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

As AI and agentic desktop apps rapidly adopt custom URI schemes for one-click onboarding—MCP install, plugin install, configuration import, prompt-driven actions—a browser click becomes a gateway into privileged local logic. Prior Electron research assumes the attacker is already inside the app; the browser-triggered, end-to-end exploitation model has remained unexplored.

\n\n

We present LaunchBreak: a class of vulnerabilities where a crafted browser link launches a desktop app and injects attacker-controlled input into a multi-stage, multi-process exploit chain. We systematize the attack surface across three dimensions: payload sources (URI, attacker server, local file), cross-process flows (main/utility/renderer), and sinks (command exec, dynamic eval, module loading).

\n\n

Our findings include 18 zero-days, 17 of them full RCEs, with 11 CVEs and a bug bounty. The affected apps include AFFiNE (60k stars, CVE-2026-21853), Hyper (Vercel\'s terminal, bounty awarded), Cherry Studio (CVE-2025-54063), Pinokio (CVE-2025-44109), deepchat (CVE-2025-55733), Paperlib (CVE-2025-64743), and more, spanning AI assistants, music players, and dev tools. We\'ll demo live exploits against apps, walk through the chains, and release Proton, the agent-guided segmented fuzzing framework we built to find them, plus PoCs for every vulnerability.

\n\n

The related CCS paper if that submission is accepted (the result comes out in June.), if not, then none.

\n\nSpeakers:Gavin Zhong,Zhengyu Liu,Jianjia Yu
\n
\nSpeakerBio:  Gavin Zhong, Johns Hopkins University
\n

Jiacheng (Gavin) Zhong is a security researcher, focusing on AI system security, program analysis, and identity security. He recently completed his M.S. in Security Informatics at Johns Hopkins University, where his work was accepted to IEEE S&P 2026. Gavin has reported over 30 CVEs in widely used open-source projects. He is also an active CTF player with r3kapig, an international team ranked top 3 worldwide.

\n\nSpeakerBio:  Zhengyu Liu, Johns Hopkins University
\n

Zhengyu Liu is a third-year PhD student in Computer Science at Johns Hopkins University. His research focuses on web and software security via program analysis. His work received Distinguished Paper (S&P ’25), Honorable Mention (USENIX ’25), and Best Student Paper (ICICS ’22). He is a DEF CON speaker and is a member of CTF team TheHackersCrew.

\n\nSpeakerBio:  Jianjia Yu, Johns Hopkins University
\n

Jianjia Yu is a PhD student at Johns Hopkins University, advised by Prof. Yinzhi Cao. Her research focuses on security and privacy in web and mobile ecosystems using program analysis techniques. Her work has received Distinguished Paper Awards at CCS \'23 and S&P \'25, and an Honorable Mention at USENIX Security \'25. She has discovered over 40 zero-day vulnerabilities and uncovered privacy leaks affecting millions of users across browser extensions and mobile applications.

\n\n\n\'',NULL,1293923),('4_Sunday','13','13:30','13:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Taking on the Dark Fleet... in Cyberspace!\'','\'Kenneth Miltenberger,Shane Cancilla\'','DEF CON Talks_c1777bc9234cc919bb341d82bc55ab9c','\'Title: Taking on the Dark Fleet... in Cyberspace!
\nTags: DEF CON Official Talk
\nWhen: Sunday, Aug 9, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

In 2026, the US led what would become an international crackdown on Dark Fleet (sometimes called Shadow/Ghost Fleet): vessels that illegally transport sanctioned oil or other cargo. Little known to the public, Coast Guard Cyber Command was deploying its Cyber Protection Teams (CPTs) onboard these vessels to assure the security & safety of these vessels in cyber space. This talk provides a rare look at the US cyber operators deploying on Dark Fleet Tankers, the danger these vessels pose, and lessons learned from these boardings.

\n\n

US Coast Guard Cyber Trends in the Maritime Environment 2025 (URL pending release)\nThe Global Oil Tanker Market: An Overview as It Relates to Sanctions (https://www.congress.gov/crs-product/R47962)

\n\nSpeakers:Kenneth Miltenberger,Shane Cancilla
\n
\nSpeakerBio:  Kenneth Miltenberger, US Coast Guard / 2003 Cyber Protection Team
\n

Commander Kenny Miltenberger currently serves as the first Commanding Officer of the 2003 Cyber Protection Team (CPT) in Alameda, CA. He is responsible for protecting the nation’s Marine Transportation System in cyberspace by conducting hunt, assess, and incident response operations. His team is the Coast Guard’s newest CPT and the only CPT geographically detached from Coast Guard Cyber Command (CGCYBER). He led the DEFCON 33 presentation, \"From Shanghai to the Shore: The Silent Threat in Global Shipping\".

\n\n

Kenny recently completed an assignment where he founded the Coast Guard’s Red Team and ran the Coast Guard\'s Blue Team. During that tour he founded CGCYBER’s educational phishing capability, led cyber Opposing Forces for a major multinational exercise, and oversaw over 100 Red and Blue Team missions. Other notable positions include his work as an engineer for the U.S. Navy’s Naval Sea Systems Command, where he was a developer on a shipboard cyber security platform.

\n\n

Kenny has a BS in Electrical Engineering from the Coast Guard Academy and an MS Electrical Engineering from University of Maryland (UMD) College Park.

\n\n

Kenny has also worked as part-time faculty at UMD College Park, where he taught Binary Exploitation in their Cyber Masters Program. Industry certifications include OSCP, GXPN, GCPN, GREM, and more

\n\nSpeakerBio:  Shane Cancilla, US Coast Guard / 2003 Cyber Protection Team
\n

Shane Cancilla is the Network Engineer for the 2003 Cyber Protection Team in Alameda, CA, focused on building and integrating tools for assessment, incident response, and threat hunting missions across Marine Transportation System and IT/OT/ICS environments. His work spans the engineering and deployment of sensors across complex networks and supporting mission-critical operations as a network analyst.

\n\n

He has previously worked with organizations including Lawrence Livermore and Lawrence Berkeley National Laboratories, where he supported high performance computing and virtualized network environments.

\n\n

Shane holds a B.S. in Computer Science from California State University, East Bay, along with CCNA and GCIH certifications.

\n\n\n\'',NULL,1293924),('4_Sunday','14','14:00','14:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5','\'Hacking Jetskis - from Sea-Don\'t to Sea-Doo\'','\'stacksmashing\'','DEF CON Talks_46499fd1db68a7d49ac84d091be9c030','\'Title: Hacking Jetskis - from Sea-Don\'t to Sea-Doo
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Sunday, Aug 9, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5 - Map
\n
\nDescription:
\n

One day, I woke up to a simple message from a friend: \"What do you know about CAN bus?\" Expecting him to have car trouble, I called him and asked, \"What do you need?\"

\n\n

Turns out the car trouble was actually jetski trouble: he bought a Sea-Doo jetski for very cheap - but it came without a key. A quick research on his side showed that the jetski does not (like others from the time) use a simple magnet key: No, the jetski has a full, digital immobilizer system, and just the tools to diagnose and program in a new key cost more than the jetski. And zero public information is available on how this all works.

\n\n

And so we dove in: from reverse-engineering the CAN bus diagnostics protocol and the electronic key protocol to designing our own freely programmable key and a Flipper Zero jetski diagnostic app, this talk goes into the weeds of hacking something that I didn\'t even know needed to be hacked: Jetskis!

\n\nSpeakerBio:  stacksmashing, hextree.io
\n

Thomas Roth aka stacksmashing is a security researcher mostly focused on hardware and firmware. His work includes hardware attacks on processors & microcontrollers, building cheap JTAG tooling for the iPhone, and attacking a wide variety of embedded devices. He also runs a YouTube channel called stacksmashing about security, reverse engineering and hardware hacking.

\n\n\n\'',NULL,1293925),('4_Sunday','14','14:00','14:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3','\'Talkers Without Borders: Worldwide Free Speech without an Internet Connection\'','\'T. Gwyddon \"data\" Owen,amp\'','DEF CON Talks_c78475a16ad5e16e8280c567af81d54c','\'Title: Talkers Without Borders: Worldwide Free Speech without an Internet Connection
\nTags: DEF CON Official Talk | Demo 💻 | Tool 🛠
\nWhen: Sunday, Aug 9, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - Map
\n
\nDescription:
\n

What if a globally accessible maritime communications network was co-opted for other than intended use? Our research tool demonstrates how defenders and users of AIS (the Automatic Identification System) might create and detect a covert communications channel that operates without a conventional server or internet connection.

\n\n

DC10\'s Stealth Data Transport (Khan) [https://share.google/Y5mFWV13VamaskHvq]\nAIS Spoofing: A Tutorial for Researchers Dr. Gary Kessler [https://share.google/ye0yai283P4mbq3Sj ]\nDC27\'s Hack the Sea (Julian Blanco) [https://share.google/H7ExvRhCfSv32OEio]\nDC33’s Pirates of the North Sea (Bjørkhaug) [https://share.google/97Y51J8DEbis1TTAd]\nDC33’s Navigating the invisible (Mehmet Onder Key & Furkan Aydogan) [https://share.google/5jvqgyAgdLm18f7kR]\nAmro, A., & Gkioulos, V. (2022, September). From Click To Sink: Utilizing AIS for Command and Control in Maritime Cyber Attacks. 27th European Symposium on Research in Computer Security (ESORICS) 2022, Copenhagen, Denmark, pp. 535-553. Lecture Notes in Computer Science (LNCS), 13556. DOI: 10.1007/978-3-031-17143-7_26

\n\nSpeakers:T. Gwyddon \"data\" Owen,amp
\n
\nSpeakerBio:  T. Gwyddon \"data\" Owen
\n

data is a retired Air Force Cyber Warfare Officer with over 20 years of operational experience. While no longer a fed, he\'s a CNODP and RIOT grad with a Comp Sci BS from the USAF Academy and a Master\'s in Cyber Ops from the Air Force Institute of Technology. He\'s been certified in all 3 NSA Red Team work roles, all 3 offensive SIGINT work roles, qualified in all 6 Cybercom offensive work roles and personally engaged real-world, nation-state-level actors, malware and targets in air, land, sea, space & cyberspace both offensively and defensively. And he\'s done so with the US, UK, Canada, Australia and New Zealand. He also helped Bryce make the Space Badge for DEF CON 33 and the Clip-Boy badge for DEF CON 34.

\n\nSpeakerBio:  amp
\n

amp spent 10 years driving ships around the globe—now captains a CTF team instead. With a B.S. in electrical engineering and pursuing M.S. in info systems engineering, amp made the jump from maritime grit to digital ops, bringing salty sea stories and a screwdriver to every hacking challenge. They’ve co-hosted episodes of several podcasts poking at the strange edges of maritime security, cyber policy, and why everything breaks at 2 AM. Into hardware hacking, retro gaming, and running text-based RPGs where everything is a side quest.

\n\n\n\'',NULL,1293926),('2_Friday','12','12:30','13:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Fireside Chat with Gen. Paul Nakasone\'','\'Paul Nakasone,Jeff \"The Dark Tangent\" Moss\'','DEF CON Talks_9bdb624b21be994d1f5316302e4c5965','\'Title: Fireside Chat with Gen. Paul Nakasone
\nTags: DEF CON Official Talk
\nWhen: Friday, Aug 7, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n\n\nSpeakers:Paul Nakasone,Jeff \"The Dark Tangent\" Moss
\n
\nSpeakerBio:  Paul Nakasone
\nNo BIO available
\nSpeakerBio:  Jeff \"The Dark Tangent\" Moss
\n

Mr. Moss is an internet security expert and is the founder of both the Black Hat Briefings and DEF CON Hacking conferences.

\n\n\n\'',NULL,1293927),('2_Friday','13','12:30','13:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'Fireside Chat with Gen. Paul Nakasone\'','\'Paul Nakasone,Jeff \"The Dark Tangent\" Moss\'','DEF CON Talks_9bdb624b21be994d1f5316302e4c5965','\'\'',NULL,1293928),('2_Friday','12','12:30','12:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'DC101\'','\'Nikita Kronenberg,Michael “sparky” Moore,polybius\'','DEF CON Talks_099ee2ba390877962a6bd510e7ffcbe5','\'Title: DC101
\nTags: DEF CON Official Talk
\nWhen: Friday, Aug 7, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n\n\nSpeakers:Nikita Kronenberg,Michael “sparky” Moore,polybius
\n
\nSpeakerBio:  Nikita Kronenberg
\nNo BIO available
\nSpeakerBio:  Michael “sparky” Moore, Lead, Network Operations Center at DEF CON
\n

Michael Moore “sparky” somehow convinced people to let him run the DEF CON Network Operations Center, where he leads the team responsible for building and operating the network that thousands of attendees immediately try to break. With more than 20 years with DEF CON, project management, and technical leadership, he’s learned that every impossible deadline is just another networking problem with better marketing. He’s still waiting for the year everything works exactly as planned.

\n\nSpeakerBio:  polybius, Global Village Lead at DEF CON Communications
\n

¯_(ツ)_/¯

\n\n\n\'',NULL,1293929),('2_Friday','11','11:00','11:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'The 2026 Pwnie Awards\'','\'Ian Roos,Mark Trumpbour\'','DEF CON Talks_e33736819c75c4e632fb868eb3439cb8','\'Title: The 2026 Pwnie Awards
\nTags: DEF CON Official Talk | The Pwnie Awards
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n\n\nSpeakers:Ian Roos,Mark Trumpbour
\n
\nSpeakerBio:  Ian Roos
\nNo BIO available
\nSpeakerBio:  Mark Trumpbour
\nNo BIO available
\n\n\'',NULL,1293930),('2_Friday','10','10:30','10:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'The DEF CON 34 Badge\'','\'Andrew \'bunnie\' Huang\'','DEF CON Talks_bb5502675509f176fafa1286e27d9538','\'Title: The DEF CON 34 Badge
\nTags: DEF CON Official Talk
\nWhen: Friday, Aug 7, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\nThe badge: how it was made, how to hack it, the new open source chip powering it, and how you can use it as a hardware security token after the con! bunnie shares his experiences zero-shotting the badge with the help of team Cheeso.
\n\n

This year\'s badge goes deeper into the open source rabbit hole than ever before. It features the Baochip-1x, a security-oriented \"high-assurance\" CPU that embraces Kerckhoffs\'s principle: not only can you check out most of the hardware design source, you can also directly see its transistors using infrared light. Learn more about how to unlock the power of open source silicon, and power up your hacking game with \"God Mode\" visibility into the heart of the machine.

\n\nSpeakerBio:  Andrew \'bunnie\' Huang
\n

Andrew \'bunnie\' Huang is best known for his work hacking the Microsoft Xbox, as well as for designing and manufacturing open source hardware. His current research interest is in facilitating trust in technology. He developed the IRIS (Infra-Red, In-Situ) imaging technique for silicon, and is the founder of Baochip, a fabless open source silicon company.

\n\n\n\'',NULL,1293931),('2_Friday','10','10:00','10:45','N','Biohacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Four Newbies Vs. An Insulin Pump. How Hard Can It Be?\'','\'Birgitte Jordal,Julia Kucharska,Emilie Øynes Jørstad,Selma Jenker\'','Creator Talks_607d3f49809aedbda2e4b4e8dc5df610','\'Title: Four Newbies Vs. An Insulin Pump. How Hard Can It Be?
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Medical devices are becoming increasingly connected—and that includes devices responsible for keeping people alive. In this talk, we share our journey as four security students taking on the challenge of analyzing an insulin pump as relative newcomers to hacking medical devices. Motivated by curiosity, concern for patient safety, and personal stakes, we set out to explore how an attacker might approach such a system using only public information, basic wireless knowledge, and persistence.

\n\n

Rather than presenting ourselves as experts, we focus on the learning process: how we approached an unfamiliar, safety critical system, how we performed threat modeling when the “failure mode” is a human body, and how we handled the many moments where everything stopped making sense. We’ll walk through what worked, what didn’t, and how critical thinking helped us move forward when we hit a wall.

\n\n

By reflecting on where we started, where we are today, and what remains unexplored, this talk highlights the value of a beginner’s mindset when analyzing real world systems like medical devices. Our goal is not to sensationalize risk, but to show how accessible security research, done responsibly, can contribute to better understanding and safer technology.

\n\nSpeakers:Birgitte Jordal,Julia Kucharska,Emilie Øynes Jørstad,Selma Jenker
\n
\nSpeakerBio:  Birgitte Jordal
\n

We are four Norwegian women that hold a bachelor’s degree in Digital Infrastructure and Cybersecurity from NTNU. Our interests include CTFs, ethical hacking, and penetration testing, with experience in cloud infrastructure, secure networking, and threat analysis.

\n\nSpeakerBio:  Julia Kucharska
\nNo BIO available
\nSpeakerBio:  Emilie Øynes Jørstad
\nNo BIO available
\nSpeakerBio:  Selma Jenker
\nNo BIO available
\n\n\'',NULL,1293932),('2_Friday','10','10:00','10:45','N','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Maritime Hacking Village Policy Panel: Subsea Cables as Strategic Chokepoints - Security, Sovereignty, and the Grey Zone\'','\'Dr. Nina Kollars,Jason Vogt,Delta Blue\'','Creator Talks_b9d8266e9d2da34864f8714f16f31323','\'Title: Maritime Hacking Village Policy Panel: Subsea Cables as Strategic Chokepoints - Security, Sovereignty, and the Grey Zone
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Subsea cables carry the overwhelming majority of the world’s digital traffic, yet the legal, operational, and diplomatic frameworks for protecting them remain fragmented. Recent cable disruptions, suspected anchor drags, and other “accidents” have highlighted how critical infrastructure at sea can become a target of grey zone activity while leaving governments, operators, and allies with limited options for attribution and response.

\n\n

This panel will examine what is being done to secure subsea cable infrastructure, where current domestic and international regimes fall short, and what new partnerships, authorities, and deterrence models may be needed. How should governments, industry, and the security community respond when the backbone of the internet runs through contested waters?

\n\nSpeakers:Dr. Nina Kollars,Jason Vogt,Delta Blue
\n
\nSpeakerBio:  Dr. Nina Kollars, US Naval War College
\n

Dr. Nina Kollars is an Associate Professor at the U.S. Naval War College’s Cyber and Innovation Policy Institute, where she specializes in cyber resilience, emerging technologies, and wargaming efforts focused on Taiwan and the Pacific. Dr. Kollars also serves as co-director of the Maritime Hacking Village, a 501c3 that advances ethical hacking on maritime assets and infrastructure. She is also an executive bourbon steward.

\n\nSpeakerBio:  Jason Vogt, USNWC
\n

Jason Vogt is an assistant professor in the Strategic and Operational Research Department, Center for Naval Warfare Studies at the United States Naval War College. Professor Vogt is a cyber warfare and wargaming expert. He has participated in the development of multiple wargames at the United States Naval War College. He previously served on active duty as an Army officer.

\n\nSpeakerBio:  Delta Blue, Anon
\n

Delta Blue is former Navy and is now part of the private sector.

\n\n\n\'',NULL,1293933),('2_Friday','10','10:00','10:59','N','OSINT For Good Community','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'OSINT4Good: What it takes to find missing people\'','\'Angela Ramos,Kenny J,Brent Louie\'','Creator Talks_8a16c6cd32f7b79c42f3978a05510ec1','\'Title: OSINT4Good: What it takes to find missing people
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Have you ever wondered what it takes to used gamified OSINT to find missing people? Moderated by a Director from Trace Labs, this panel brings together a participant (who won Most Valuable OSINT), a coach (who has coached more times than anyone on the planet), and a report writer (who leads the team of report writers) to walk you though the different perspectives of this work.

\n\nSpeakers:Angela Ramos,Kenny J,Brent Louie
\n
\nSpeakerBio:  Angela Ramos, University of Tampa
\n

Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coaches Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations.

\n\nSpeakerBio:  Kenny J, Trace Labs
\n

Senior Infrastructure Engineer by day. Osint for Good by night. His is the only Trace Labs coach to have coached 20+ CTFs, earning him the singular rank of Legendary Coach.

\n\nSpeakerBio:  Brent Louie, Reporting Team Lead at Trace Labs
\n

Brent Louie is the Reporting Team Lead at Trace Labs and an Associate Director of Data Science with more than 15 years of experience in the biotechnology industry. He focuses on applying OSINT methodologies to missing persons investigations and helping transform crowdsourced research into actionable investigative leads for law enforcement.

\n\n\nLinks:
    www.tracelabs.org - https://www.tracelabs.org
\n\'',NULL,1293934),('2_Friday','10','10:00','10:59','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Sovereign by Design, Vulnerable by Default\'','\'Devin Lynch,Haley Ring\'','Creator Talks_75f122881c66b9e272b21ac4b9728cf3','\'Title: Sovereign by Design, Vulnerable by Default
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Every major government is now making sovereign AI decisions. Data localization. Domestic cloud mandates. Trusted vendor regimes. Export controls on chips and model weights. Engineers and security teams don\'t get a vote on whether sovereignty happens — they inherit the architecture it creates. And that architecture has seams. This talk is a security analysis of what sovereignty does to threat models, and what policy designers can do about it. Sovereignty initiatives change architecture. Architecture changes threat models. Policy that ignores this chain creates new vulnerabilities. Policy that understands it can improve resilience — but only if it\'s designed with the seams in mind.

\n\nSpeakers:Devin Lynch,Haley Ring
\n
\nSpeakerBio:  Devin Lynch, Paladin Global Institute
\n

Devin Lynch is the Senior Director of the Paladin Global Institute and a former Director for Cyber Policy and Strategy Implementation at the Office of the National Cyber Director (ONCD). He has held key roles in both the private sector and government, including positions at the U.S. House of Representatives, U.S. Senate, and the Departments of Homeland Security and Defense. He is an adjunct professor at the George Washington University’s Elliott School of International Affairs and has served in the U.S. Navy Reserve for over 20 years, including combat deployments to Iraq and Afghanistan.

\n\nSpeakerBio:  Haley Ring, Paladin Global Institute
\n

Haley Ring is the Director at the Paladin Global Institute, where she helps drive initiatives that strengthen national resilience, protect critical infrastructure, and shape the future of emerging technology. She previously served in the Biden-Harris Administration, advising on national security, technology policy, and public engagement as the Advisor for Engagement to the Second Gentleman and as a Special Advisor in the White House Office of the National Cyber Director. Before her White House roles, Haley worked at the Department of Defense in the Office of the White House Liaison. She began her career on the Biden for President campaign and is originally from Newton, Massachusetts. Haley holds a bachelor’s degree from the University of Wisconsin–Madison and is based in Washington, D.C.

\n\n\n\'',NULL,1293935),('2_Friday','10','10:00','10:59','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'The Future of Bug Bounty - Program Manager Perspective\'','\'Jai Kumar Sharma,Catherine Cassell,Austin Sturm,Dane Sherrets,Sachin \"sachinnthakuri\" Thakuri\'','Creator Talks_32591707cae3948113547ff000964ef4','\'Title: The Future of Bug Bounty - Program Manager Perspective
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Bug bounty is a proven model, but AI is changing how it runs. Researchers are submitting at higher volumes, LLM-generated reports are making triage harder, and new assets like AI agents and model endpoints are showing up in scope faster than programs can write playbooks for them. This panel brings together program managers from leading bug bounty programs to talk about what they\'re seeing from the other side of the queue. What has AI actually changed about the reports, the researchers, and the bugs that matter? What should program managers and security teams be doing about it now? And where is bug bounty headed over the next few years? Whether you run a program, hack on one, or want to start one, you\'ll come away with a clearer sense of what bug bounty looks like today and where it is going.

\n\nSpeakers:Jai Kumar Sharma,Catherine Cassell,Austin Sturm,Dane Sherrets,Sachin \"sachinnthakuri\" Thakuri
\n
\nSpeakerBio:  Jai Kumar Sharma, Principal Offensive Security Engineer at GoDaddy
\n

Jai Sharma is a Principal Offensive Security Engineer at GoDaddy, where he leads cloud penetration testing, red team operations, AI red teaming, and security research across one of the world\'s largest domain registrars and hosting platforms. A self-taught offensive security researcher from New Delhi, India, he built his career with a hacker\'s mindset, breaking code logic, chasing vulnerabilities, and proving real-world business impact from technical exploits. He also leads TTP research, drives threat emulation efforts, and works closely with blue teams to sharpen detection through an adversary-focused lens.

\n\n

At GoDaddy, Jai tests the same infrastructure and enterprise environments that millions of customers rely on. His work spans cloud and on-premises penetration testing, IAM privilege escalation research, and building automated offensive tooling that helps turn point-in-time assessments into continuous detection. Before GoDaddy, Jai held offensive security roles at Housing.com, FIS, and EY, giving him firsthand experience with how security weaknesses and misconfigurations surface across different industries, architectures, and maturity levels.

\n\n

Jai volunteers with the DEF CON community as CTF Ops for the Cloud Village and on-site Coordinator for the Bug Bounty Village.

\n\nSpeakerBio:  Catherine Cassell, Product Security Engineer at Github
\n

Catherine is a security engineer on the bug bounty team at GitHub. She has five years of experience in offensive security, working in both bug bounty and penetration testing. Catherine has spent the last year and a half at GitHub and runs an annual hardware hacking workshop at the Glass Firewall Conference. At work, she spends her days reading and triaging bounty reports. Outside of work, she spends her free time outside, as far away from screens as possible. You can usually find her hiking or skiing in the Rocky Mountains.

\n\nSpeakerBio:  Austin Sturm
\n

He started as a no-good kid on IBB forums and landed a job doing offensive security for large tech companies. For some tireless years he ran and built a team for a cloud providers bug bounty program and continues to act as a tech lead for a bounty program in the wake of the AI-era

\n\nSpeakerBio:  Dane Sherrets, HackerOne
\n

Dane is an Innovations Architect at HackerOne, where he helps organizations run AI-focused bug bounty programs and improve the security of emerging technologies. His work includes winning 2nd place in the Department of Defense AI Bias Bounty competition, discovering critical vulnerabilities in platforms like Worldcoin, and helping design and manage Anthropic\'s AI Safety Bug Bounty program. Drawing on his background as a bug hunter, Dane blends strategic guidance with hands-on expertise to advance the safety and security of disruptive tech across industries.

\n\nSpeakerBio:  Sachin \"sachinnthakuri\" Thakuri, Senior Product Security Engineer at TikTok
\n

Sachin Thakuri is a Senior Product Security Engineer at TikTok, where he leads Variant Analysis initiatives to identify and eliminate classes of vulnerabilities across the platform. His work focuses on variant analysis, vulnerability management, product incident response, and building Al-powered security tooling. Previously, Sachin help build and led application security programs at Alpha Group, Pintu, and Grab. Sachin has also presented his research at security conferences like Black Hat, Insomni\'hack, GreHack.

\n\n\n\'',NULL,1293936),('2_Friday','10','10:00','10:30','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Hacking Electronic Conspicuity Devices -or- Making Light Aircraft Fly Into Conflict\'','\'Ken Munroe\'','Creator Talks_36a125463a7621c3bd2dfcda7ab22adb','\'Title: Hacking Electronic Conspicuity Devices -or- Making Light Aircraft Fly Into Conflict
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Commercial aircraft have Traffic Collision and Avoidance Systems, or TCAS, to ensure they don’t fly in to each other, but these are very expensive systems. How do General Aviation aircraft find a way to avoid each other?

\n\n

Enter ‘Electronic Conspicuity’ devices: small, light and cost effective sensors to detect other aircraft and alert GA pilots before they can be seen by the naked eye.

\n\n

Unfortunately, in the rush to improve flight safety and situational awareness in GA, cyber security has taken something of a back seat. As a result, some of these EC devices have trivial and not-so-trivial security flaws. In some cases, it is possible to delete Traffic Advisories and/or give an incorrect Resolution Advisory, bringing planes in to conflict with each other, rather than ensuring they stay safely apart.

\n\nSpeakerBio:  Ken Munroe
\nNo BIO available
\n\n\'',NULL,1293937),('2_Friday','17','17:15','17:59','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Where hackers find their people, and security finds its strength\'','\'Seeyew Mo,Ashley S,Tatiana U,Heidi Potter,Christine Billingsley\'','Creator Talks_177192d5b30bce92faad0549483f7dbb','\'Title: Where hackers find their people, and security finds its strength
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:15 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Before it was an industry, this was just people. Curious folks poking at things, breaking stuff to figure out how it worked, and telling the next person what they found. Somewhere along the way a few of them started building the rooms where that could happen: the cons, the villages, the meetups, the spaces where you finally found your crew.

\n\n

This panel gets some of those organizers together to talk about something we don\'t say out loud enough: the community is the security. Every mentor who answered your dumb questions, every village that felt like home, every hallway conversation that turned into a tool or a job or a friendship, someone had to make space for that. We will swap stories about what it takes to build and protect these communities, why the people who show up matter more than anything, and how the spaces we create end up being some of the strongest defense we have got. Pull up a chair. Nobody does this alone, and that is the whole point.

\n\nSpeakers:Seeyew Mo,Ashley S,Tatiana U,Heidi Potter,Christine Billingsley
\n
\nSpeakerBio:  Seeyew Mo, Director of Training for DEF CON.
\n

Seeyew Mo is the Senior Advisor for Cyber Maryland where he leads the state\'s cyber workforce development. He also serves as the Director of Training for DEF CON. He previously served as the Assistant National Cyber Director for Cyber Workforce, Training and Education at the Office of National Cyber Director (ONCD). In his role, Seeyew leads and coordinates the implementation the White House’s National Cyber Workforce and Education Strategy. He believes in taking a holistic view – doctrine, people, and technology - to making advancements in cyber workforce and digital safety awareness. Seeyew is an expert in the intersection of cybersecurity, technology, and national security with 18 years of experience spanning tech development, policymaking, and political campaigning.

\n\nSpeakerBio:  Ashley S, Sr. Solutions Engineer at Censys
\n

Ashley is a cybersecurity researcher, threat intelligence practitioner, and Senior Sales Engineer at Censys, where she conducts strategic research on IoT botnets and adversarial infrastructure. Her research sits at the intersection of hardware-based attack infrastructure and influence operations, tracking how low-cost consumer electronics are weaponized as residential proxy networks, ad fraud engines, and persistent footholds inside homes and enterprise networks. She spends tons of time building up the cybersecurity community and got her start by volunteering after making a career pivot after her military service. She is very passionate about community protection and community building, as evidenced by her role as Chief Security Officer for BsidesLV.

\n\nSpeakerBio:  Tatiana U, Technical Program Manager at Bugcrowd
\n

Tatiana (Tati) is the Technical Program Manager for Live Hacking at Bugcrowd, which means she’s usually the one making sure a room full of hackers actually turns into a working event. She didn’t come up in this industry through school or a straight career path. She came up through it the way most people do: somebody let her in, answered her questions, and made room for her at the table. She’s spent the years since returning the favor.

\n\nSpeakerBio:  Heidi Potter, Chief Operating Officer at Turngate
\n

Heidi Potter has spent much of her career bringing people together. Best known for her twenty years helping build and run ShmooCon, she remains passionate about creating welcoming spaces where people can learn, connect, and share ideas. She currently serves as COO of Turngate and spends her free time walking, biking, and occasionally embracing carefully managed chaos.

\n\nSpeakerBio:  Christine Billingsley, Chief Operating Officer at Military Cyber Professionals Association
\n

Christine Billingsley is the Chief Operating Officer at the Military Cyber Professionals Association. An accomplished operations and marketing professional with a proven track record of innovation and delivery of best-in-class projects, experiences, and events. She is the creator of the DEF CON Arcade Party and author of Cyber Snackz, an introductory cybersecurity activity book centered around a team of adorable animals who work in different areas of cybersecurity. She is passionate about getting today\'s youth interested in cyber. She is a mom to humans and a spunky Pomeranian.

\n\n\n\'',NULL,1293938); INSERT INTO `events` VALUES ('2_Friday','10','10:45','11:30','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'InQuorigible: Quora in Missing Persons OSINT\'','\'Miranda Tedholm\'','Creator Talks_08b0c746e4cd9f0c93612bbef3915cde','\'Title: InQuorigible: Quora in Missing Persons OSINT
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:45 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

We all know Quora - or do we? Like Internet herpes, if you\'re a Google user, it\'ll follow you, forever, haunting your inbox with clickbait if you Google while logged into your account.

\n\n

...But do we REALLY know Quora? Because despite being a pustule on the Internet that exists for the sole purpose of spamming SERPs, you\'ll be shocked to learn that it\'s also got - spoiler alert!!! - a dark, seedy underbelly. One that I uncovered while volunteering on an MP investigation. One that can yield surprising, disturbing and useful intelligence.

\n\n

In this talk, I\'ll explain:\n1. The traces Quora leaves behind when something is \"limited,\" \"deleted\" or a user is \"banned.\" Because on Quora, \'deleted\' just nulls the post body while the API keeps serving the slug and author, and \'limited\' barely hides anything at all. On Quora, Limited is UNLIMITED, just like Olive Garden\'s breadsticks! Except unlike Olive Garden breadsticks, Quora\'s \"limited\" option is a fig leaf, and \"deleted\" content isn\'t much better: The API doesn\'t hide it. It coughs up the slug and author fully visible to other accounts and even logged-out strangers. \n2. How to use Quora\'s API hairball to see what a user posted and build a network graph\n3. What the disturbing subcultures on Quora mean for OSINT\n4. Limitations of approach and ideas for automating OSINT

\n\n

Trigger warnings: This talk may include mention of disturbing topics, though all information will be anonymized / sanitized and no graphic content shared.

\n\nSpeakerBio:  Miranda Tedholm, Hunting the Golden Fleece in the JSONs of the world. Extremely employable.
\n

Who is Miranda? A reformed academic, a freelance writer sidelined thanks to a tech that can be described as \"autocomplete on steroids,\" and a recent computer science grad, Miranda has been online since the CompuServe days. Yet she was [redacted] years old before she realized that \"being really good at finding people online\" was a whole subculture, career, and acronym. \nDespite never having played Pokemon, she collects degrees and credentials like she\'s gotta catch \'em all. Two bachelor\'s degrees, a master\'s, most of a PhD, and probably able to do the Heimlich maneuver (no promises though). \nBut she yearns only for a job.

\n\n\n\'',NULL,1293939),('2_Friday','11','10:45','11:30','Y','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'InQuorigible: Quora in Missing Persons OSINT\'','\'Miranda Tedholm\'','Creator Talks_08b0c746e4cd9f0c93612bbef3915cde','\'\'',NULL,1293940),('4_Sunday','12','12:00','12:45','N','IoT Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Sick Signals: Adversarial Prompt Injection via IoT Sensor Telemetry\'','\'Vinitha Mathiyazhagan,Tamil Mathi T.\'','Creator Talks_e539ef4a4ebb7d082be70cdff36f9c1b','\'Title: Sick Signals: Adversarial Prompt Injection via IoT Sensor Telemetry
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

IoT devices that increasingly feed LLM-powered automated decision systems. Their telemetry streams are implicitly trusted as ground truth. This talk introduces a novel attack class: adversarial prompt injection delivered through crafted IoT sensor payloads. By encoding malicious instructions inside what appears to be routine device data, an attacker can manipulate the downstream LLM pipeline, suppressing critical operational alerts, fabricating findings in generated summaries, or triggering unauthorized actions in AI systems with actuation capabilities. We present the attack surface and a taxonomy of seven injection vectors spanning full stack across automotive, industrial, and consumer deployments: analog spoofing, structured free-text field poisoning, MQTT broker injection, calibration event hijacking, alarm message hijacking, time-series fragmentation, and multi-device coordinated injection. Unlike attacks targeting text interfaces, this class exploits the implicit trust placed in sensor telemetry; payloads hide inside ordinary device data, bypassing numeric validators and arriving in the LLM context as trusted operational input. We discuss early experimental findings on the feasibility of this attack class, along with detection strategies and open questions for defenders. Attendees will leave with a concrete attack surface map, an expanded vocabulary for this new attack surface, and a new way to think about trust boundaries in AI-augmented systems.

\n\nSpeakers:Vinitha Mathiyazhagan,Tamil Mathi T.
\n
\nSpeakerBio:  Vinitha Mathiyazhagan
\nNo BIO available
\nSpeakerBio:  Tamil Mathi T.
\nNo BIO available
\n\n\'',NULL,1293941),('2_Friday','10','10:45','11:30','N','Payment Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'The Future of Payments: AI, Agentic Commerce and the Next Wave of Innovation\'','\'Daniel Cuthbert,Leigh-Anne Galloway,Jorge Braniff,Sanjeev Sharma\'','Creator Talks_686ea218932cf6e42c8d717cd57e00ed','\'Title: The Future of Payments: AI, Agentic Commerce and the Next Wave of Innovation
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:45 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

The payments industry is entering a new era of transformation, where AI reshapes the way consumers and businesses buy, pay, and determine risk throughout the payment journey.

\n\n

Join leaders from across the payments ecosystem as they explore the technologies, opportunities, and challenges shaping the future of this space. This panel will examine how financial institutions, payment providers, merchants, and technology companies are preparing for a world where AI augments decision-making, automates operations, and increasingly acts on behalf of users to deliver more seamless, secure, and intelligent payment experiences.

\n\n

Attendees will gain actionable insights into the technologies and market forces redefining payments. Panelists will share their perspectives on the emerging innovations, strategic priorities, and industry shifts that will shape the next generation of payment experiences. They will offer practical guidance on how organizations can prepare for an increasingly intelligent, automated, and interconnected payments ecosystem.

\n\nSpeakers:Daniel Cuthbert,Leigh-Anne Galloway,Jorge Braniff,Sanjeev Sharma
\n
\nSpeakerBio:  Daniel Cuthbert, Global Head of Cyber Security Research, Banco Santander
\n

Daniel Cuthbert is the Global Head of Cyber Security Research at Santander, where he leads global security research and drives innovation in cyber defence across the organisation. He serves on the Black Hat Review Board and is a founding member of OWASP, having co-authored both the OWASP Testing Guide and the OWASP Application Security Verification Standard (ASVS). With more than 20 years of experience in offensive security, application security, and threat research, Daniel is a frequent speaker and trusted advisor on emerging cyber threats, secure engineering, and security strategy.

\n\nSpeakerBio:  Leigh-Anne Galloway, Founder, Payment Village
\n

Leigh-Anne Galloway is a security researcher and testing specialist focusing on payment security, application security, fraud, and adversarial testing. Leigh-Anne is the founder of The Payment Village, a non-profit initiative dedicated to educating people on the intricacies of payment systems, fostering the next generation of payment security professionals, and creating space for critical discussion within the industry. She has presented and authored research on ATM security, mPOS vulnerabilities, NFC payments, fraud, and application security.

\n\nSpeakerBio:  Jorge Braniff, VP of Fraud and Product Operations at Incode Technologies
\n

Jorge Braniff is VP of Fraud and Product Operations at Incode Technologies, where he leads a global organization spanning fraud detection, document intelligence, red team, data collection, labeling and identity verification. His work sits at the center of the agentic fraud arms race: partnering with ML on the development of models for supporting all ID templates, deepfake detection, presentation attacks, document tamper, alteration, liveness and AI detection. Jorge has led fraud ring detection initiatives using graph-based identity linkage to uncover coordinated attack networks and has run high-stakes technical evaluations against fraud rings targeting neobanks and payment platforms. He has also hardened SDKs against injection and deepfake-based attacks for major financial institutions and fintechs and developed model governance and evaluation frameworks used to benchmark fraud detection performance in production. He brings a builder’s perspective to the fight against AI-driven fraud, having scaled operations and detection systems across multiple countries. He is based in the San Francisco Bay Area.

\n\nSpeakerBio:  Sanjeev Sharma, Director, Payments Product, GoFundMe
\n

Sanjeev has been building payment products since 2013, beginning his career at Visa as part of the original Visa Token Service (VTS) product team. He played a key role in launching and commercializing VTS across multiple countries and continents, helping drive the adoption of tokenized payments at global scale.\nHe later joined Meta, where he worked on payments across the family of apps, including helping launch WhatsApp Payments in India. Today, Sanjeev is a Product Manager in the Payments Product Group at GoFundMe, where he focuses on building secure, scalable payment experiences that help people support one another around the world.

\n\n\n\'',NULL,1293942),('2_Friday','11','10:45','11:30','Y','Payment Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'The Future of Payments: AI, Agentic Commerce and the Next Wave of Innovation\'','\'Daniel Cuthbert,Leigh-Anne Galloway,Jorge Braniff,Sanjeev Sharma\'','Creator Talks_686ea218932cf6e42c8d717cd57e00ed','\'\'',NULL,1293943),('2_Friday','11','11:00','11:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Cryptocurrency Opening Keynote\'','\'Michael \"MsvB\" Schloh,Param \"P7R7M\",Izdihar\'','Creator Talks_0bd702b0d1d9c5b6d24f84022a1bdf6e','\'Title: Cryptocurrency Opening Keynote
\nTags: Cryptocurrency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Join your fellow hackers managing the Cryptocurrency areas at DEF CON, and get a sneak peak of what each workshop teaches as well as an overview of the showcases and programs happening in our DEF CON Village and Contest areas. We will report on cryptocurrency trends and perspectives from distinguished positions in industry, academy, and government. We will announce the teams competing in the Cryptocurrency Challenge, and give an overview of what prizes are available to winning contestants of the hackathon, CTF, and contests. Meet the organizers of years of cryptocurrency content at Defcon and bring your questions to the Creator Stage during the Cryptocurrency Opening Keynote!

\n\nSpeakers:Michael \"MsvB\" Schloh,Param \"P7R7M\",Izdihar
\n
\nSpeakerBio:  Michael \"MsvB\" Schloh, Chairman, Monero Devices
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\nSpeakerBio:  Param \"P7R7M\"
\n

Param is an Electrical Engineering Student from Georgia Tech with a strong passion for and interest in crypto. Although he primarily got interested in cryptography and hardware security through a class at Georgia Tech, he is also working at a software company on crypto adoption and ease of use. With a unique blend of HW and SW skills, Param is truly enthusiastic about all aspects of crypto.

\n\nSpeakerBio:  Izdihar, Swarmnetics / cyber673 / Brunei Cyber Security Association
\n

Izdihar is a cybersecurity practitioner who works in penetration testing and tinkers with a homelab in his spare time, where he has been experimenting with running blockchain testnet nodes. His interest in cryptocurrency is mostly about understanding how the infrastructure works. He helps run cyber673, a small grassroots community in Brunei.

\n\n\n\'',NULL,1293944),('2_Friday','11','11:00','11:59','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Intro to Common Industrial Protocol Exploitation\'','\'Trevor Flynn\'','Creator Talks_cfab112f52f678535f3a54cceb2df801','\'Title: Intro to Common Industrial Protocol Exploitation
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Intro into Common Industrial Protocol and how to get started finding exploits on CIP enabled devices.

\n\nSpeakerBio:  Trevor Flynn
\n

Industrial Control Engineer / ICSVillage volunteer / Cyber Security Researcher

\n\n\n\'',NULL,1293945),('2_Friday','11','11:00','11:30','N','Hackers.town','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Tech Reclaimers Update: A Year In, Building a Social Movement Away from Big Tech\'','\'Andy Hull,Janet Vertesi,Rebecah Miller\'','Creator Talks_dc8cb39f7a60fb5c35576aa25ff3929d','\'Title: Tech Reclaimers Update: A Year In, Building a Social Movement Away from Big Tech
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

It has been a year since we launched the Tech Reclaimers, a social movement to help people reclaim their lives and their systems from Big Tech. And how far we have come! The community has grown online, with a thousand followers and hundreds of active participants in group chats. In this talk, describe our activities over the past year and our plans for the future, as well as what we have learned about the challenges people face in disentangling from Big Tech. While the technical challenges can be complicated, there are considerable social challenges too. And while hackers may look for the purest and best alternative options, we have found variety in meeting people where they are at to help them assemble the alternative stack that suits their needs, budget, skills, and values. Finally, we do indeed have friends everywhere: from the Rebel Tech Alliance to the Luddite Club, we discuss the connections we are forging and the new paths we are innovating.

\n\nSpeakers:Andy Hull,Janet Vertesi,Rebecah Miller
\n
\nSpeakerBio:  Andy Hull, Officer at Tech reclaimers
\nNo BIO available
\nSpeakerBio:  Janet Vertesi, Officer at Tech Reclaimers
\nNo BIO available
\nSpeakerBio:  Rebecah Miller, Officer at Tech Reclaimers
\nNo BIO available
\n\nLinks:
    www.techreclaimers.club - https://www.techreclaimers.club
\n\'',NULL,1293946),('2_Friday','11','11:00','11:30','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'The Ripple Effect: Inside Cloud-Scale Vulnerabilities in the Age of AI\'','\'Albin Vattakattu,Ryan Nolette\'','Creator Talks_0894e3391967c7db6f6aa0b0a83c0201','\'Title: The Ripple Effect: Inside Cloud-Scale Vulnerabilities in the Age of AI
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Security researchers never see the true impact of their work. You submit a vulnerability report, it disappears into a queue, and eventually get a \"resolved.\" But what actually happened on the other side? This talk changes that. Through a real-world case study, you\'ll see what happens when a single vulnerability report hits a cloud provider at scale and keeps going. What makes cloud vulnerabilities fundamentally different from traditional targets? How do you prioritize remediation when the blast radius spans services, regions, and third-party dependencies you didn\'t know existed? You\'ll see the crucial trade-offs no one talks about publicly, and a series of challenges that textbook CVD (coordinated vulnerability disclosure) was never designed to handle. And that challenge is accelerating. AI vulnerability discovery tools are uncovering valid vulnerabilities faster than traditional VDP (Vulnerability Disclosure Program) models were architected to process. The model that worked five years ago is buckling, and its impact is felt across organizations worldwide. Researchers wait longer. Defenders fall behind. The gap between discovery and remediation is widening, and attackers live in that gap. This talk introduces the 3 Principles for modern VDPs, which were forged from operating vulnerability disclosure at the world\'s largest cloud infrastructure. These apply whether you\'re running a program or reporting to one. Security researchers researchers will learn what actually happens after you hit submit, and how to write reports that accelerate everything downstream. Defenders will learn how to scale their programs for the velocity that\'s already here.

\n\nSpeakers:Albin Vattakattu,Ryan Nolette
\n
\nSpeakerBio:  Albin Vattakattu
\n

Albin leads the global Vulnerability Disclosure Program (VDP) for Amazon Web Services (AWS). Albin\'s work has been featured by HackerOne, the SANS Institute, the AWS Security Blog, and at multiple international conferences.

\n\n

Prior to AWS, Albin led incident response teams across North and South America, defending foreign governments and fortune 100 companies against DDoS campaigns by APTs.

\n\nSpeakerBio:  Ryan Nolette
\n

Ryan is AWS\'s Senior Security Engineer and CoAuthor of AWS Detective. He has previously held a variety of roles including threat research, incident response consulting, and every level of security operations. With almost 2 decades in the infosec field, Ryan has been on the development and operations side of companies such as Postman, Sqrrl, Carbon Black, Crossbeam Systems, SecureWorks and Fidelity Investments. Ryan has been an active speaker and writer on threat hunting and endpoint security.

\n\n\n\'',NULL,1293947),('2_Friday','11','11:30','11:59','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Haetae: An Agent to Takedown North Korean C2 Servers\'','\'Mauro Eldritch,Nelson Rafael Colón Merán\'','Creator Talks_e52876a3792c006602ffe35ffa5086f7','\'Title: Haetae: An Agent to Takedown North Korean C2 Servers
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

In this talk, we introduce Haetae, an agent designed to profile, identify, and exploit C2 frameworks used by North Korean malware.

\n\n

Haetae supports both automated and interactive modes, allowing analysts to map and understand adversary infrastructure with different levels of control. It is built around a flexible rule-based system, enabling users to extend and refine detections as new patterns and frameworks emerge.

\n\n

In this first release, we will walk through real-world cases where Haetae was used to identify and take down infrastructure associated with Mach-O Man and POWerful Armadillo.

\n\n

We will also release a safe emulator of both malware C2 servers, allowing researchers and newcomers to experiment with Haetae in realistic, controlled environments without risk.

\n\n

This is a highly technical talk but can be enjoyed by both beginners and seasoned threat hunters.

\n\nSpeakers:Mauro Eldritch,Nelson Rafael Colón Merán
\n
\nSpeakerBio:  Mauro Eldritch, Leader at Bitso Quetzal Team
\n

Hacker and Speaker.

\n\n

Founder of BCA LTD and DC5411.

\n\n

I wrote a book interviewing Threat Actors.

\n\n

I like Threat Intelligence and Golden Retrievers.

\n\nSpeakerBio:  Nelson Rafael Colón Merán, Security Engineer at Bitso
\n

Security Engineer at Bitso, Latin America\'s leading crypto-first financial platform. I\'ve specialized in red team operations, penetration testing, and malware development.

\n\n

Recognized speaker in the Dominican Republic\'s RedTeamRD cybersecurity community, where I\'ve given a couple talks and previously assisted DEFCON as a speaker.

\n\n\n\'',NULL,1293948),('2_Friday','11','11:30','11:59','N','Biohacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Human in the Loop or Human Out of Luck?\'','\'Christine Von Raesfeld\'','Creator Talks_c440800a7a6fe89c76f5ce41f658ca2d','\'Title: Human in the Loop or Human Out of Luck?
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

As agentic AI systems rapidly enter healthcare and precision medicine, a critical question remains largely unanswered: what happens when the patient is reduced to data alone?\nThis talk explores a real-world experiment conducted through GENE240 at Stanford, where interdisciplinary student teams used agentic AI systems and multiomic datasets to investigate a complex patient case. Working across genomics, computational biology, and clinical reasoning, teams analyzed the same underlying data while arriving at dramatically different hypotheses, interpretations, and priorities.\nUnlike traditional case studies, the patient was actively involved throughout the process. While full medical records were intentionally withheld, selective contextual information and direct interaction with the patient significantly influenced the direction and interpretation of the work. The experience exposed both the extraordinary promise and the profound limitations of AI-driven healthcare systems.\nThis session will examine:\nhow agentic AI systems behave when operating on incomplete clinical context\nthe variability introduced by tooling, prompting, and disciplinary bias\nthe role of patient interaction in refining computational hypotheses\nwhy lived experience may be one of the most underutilized datasets in precision medicine\nThrough the lens of rare disease and complex chronic illness, this talk challenges the assumption that more data alone leads to better outcomes. Instead, it argues that the future of AI-enabled healthcare depends on keeping patients actively embedded in the interpretive loop.\nFor the biohacking community, this raises broader questions around autonomy, data ownership, participatory medicine, and how individuals may increasingly interface with AI systems to investigate their own health outside traditional clinical

\n\nSpeakerBio:  Christine Von Raesfeld
\n

Christine is a research advocate and community engagement leader focused on health, data, and emerging technologies. Living with multiple rare and chronic conditions, she advances participatory medicine and champions people with lived experience as essential partners in research and innovation.

\n\n\n\'',NULL,1293949),('2_Friday','11','11:30','12:15','N','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Building the Humans Behind the Mission: Talent, Readiness, and Cyber Power for America’s Armed Services\'','\'Dr. Nina Kollars,Dr. Wanda T. Jones-Heath,Anne Marie Schumann\'','Creator Talks_22645f604e3453b688fd4f7bff1e3ccc','\'Title: Building the Humans Behind the Mission: Talent, Readiness, and Cyber Power for America’s Armed Services
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 12:15 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

The Maritime Hacking Village is proud to host a first‑of‑its‑kind conversation with the Principal Cyber Advisors to the Navy and the Air Force. As cyber operations become inseparable from maritime, air, and joint missions, the Navy and Air Force face a shared challenge: how to recruit, train, integrate, and retain the technical talent required for modern conflict.

\n\n

This session will explore how the services are strengthening operational cyber units. How deeply technical experts can be woven into traditional command structures, and how joint missions can be supported by interoperable training pipelines. We’ll also dig into the realities of competing with the commercial sector for high‑end cyber talent, and the emerging skill sets — from AI engineering to cloud and data‑center operations — that will define future conflict. Expect a little honesty, and maybe one or two jokes about how retention would be easier if the military offered free energy drinks and a hoodie.

\n\nSpeakers:Dr. Nina Kollars,Dr. Wanda T. Jones-Heath,Anne Marie Schumann
\n
\nSpeakerBio:  Dr. Nina Kollars, US Naval War College
\n

Dr. Nina Kollars is an Associate Professor at the U.S. Naval War College’s Cyber and Innovation Policy Institute, where she specializes in cyber resilience, emerging technologies, and wargaming efforts focused on Taiwan and the Pacific. Dr. Kollars also serves as co-director of the Maritime Hacking Village, a 501c3 that advances ethical hacking on maritime assets and infrastructure. She is also an executive bourbon steward.

\n\nSpeakerBio:  Dr. Wanda T. Jones-Heath, Principal Cyber Advisor for the Department of the Air Force
\n

Dr. Wanda T. Jones-Heath, a member of the Senior Executive Service, is the Principal Cyber Advisor for the Department of the Air Force, comprised of the U.S. Air Force and U.S. Space Force. As the Principal Cyber Advisor for the DAF, her duties include synchronizing, coordinating and overseeing the implementation of the DAF Cyber Strategy and advising the Secretary of the Air Force on all cyber programs. She is responsible for overseeing cyberspace recruitment; resourcing and training of cyber mission forces, as well as assessing their readiness; overseeing acquisition; advocate for cyber investments; cybersecurity supply chain risk management; security of information systems and weapon systems.

\n\nSpeakerBio:  Anne Marie Schumann, Principal Cyber Advisor, Department of the Navy
\n

Ms. Anne Marie Schumann serves as the Department of the Navy Principal Cyber Advisor (DON PCA). In this role, she is responsible for advising the Secretary of the Navy, Chief of Naval Operations, and Commandant of the Marine Corps on all cyber matters and implementing the Department of Defense Cyber Strategy within the DON.

\n\n\n\'',NULL,1293950),('2_Friday','12','11:30','12:15','Y','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Building the Humans Behind the Mission: Talent, Readiness, and Cyber Power for America’s Armed Services\'','\'Dr. Nina Kollars,Dr. Wanda T. Jones-Heath,Anne Marie Schumann\'','Creator Talks_22645f604e3453b688fd4f7bff1e3ccc','\'\'',NULL,1293951),('2_Friday','11','11:30','11:59','N','DEF CON Groups','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Starting and Sustaining a Successful DEF CON Group presented by DC862\'','\'C$,Joe Folk,Christopher \"reapermunky\" Aziz\'','Creator Talks_e46dc10a2a14e8a3328e8ab2daf3a68d','\'Title: Starting and Sustaining a Successful DEF CON Group presented by DC862
\nTags: DEF CON Groups | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Starting a DEF CON Group is more than picking a name and scheduling a meetup. This session walks through the practical work of building a local hacker community that people want to keep showing up for. DC862 will share lessons on organizer structure, finding speakers and venues, community engagement, long-term sustainability, and representing DEF CON in a positive way. This workshop is built for newer organizers, prospective POCs, and anyone trying to turn a local meetup into a durable community.

\n\nSpeakers:C$,Joe Folk,Christopher \"reapermunky\" Aziz
\n
\nSpeakerBio:  C$, DC862
\n

++++++++++[>+>+++>+++++++>++++++++++<<<<-]>>>>+++++++++++++++++++.------------------.+++++++..<<++.>>--------.+++++++++++.-.---------.<<+.

\n\nSpeakerBio:  Joe Folk, DC862
\n

Original member of DC862, DC404 OG, and member of several other DCGs. Joe has worked in security for over 25 years leading Security Departments at multiple Fortune 500 companies. He\'s a regular at DEF CON (since DC6), Black Hat, BSides, and many regional security conferences.

\n\nSpeakerBio:  Christopher \"reapermunky\" Aziz, DC862/Bombadil Systems
\n

Chris Aziz is an independent security researcher and the founder of Bombadil Systems, a MITRE CVE Numbering Authority focused on vulnerability research. An active member of DC862, he contributes to the group\'s speaker sourcing, community engagement, and growth efforts.

\n\n\nLinks:
    Website - https://dc862.org
\n    Mastodon (@DC862@defcon.social) - https://defcon.social/@DC862
\n\'',NULL,1293952),('2_Friday','12','12:00','12:45','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Aerospace Cybersecurity Student Research Spotlight: ERAU\'','\'Sean McConoughey,Samuil Nikolov\'','Creator Talks_464292ded8707e39b618115fc7b3031e','\'Title: Aerospace Cybersecurity Student Research Spotlight: ERAU
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

At the Aerospace Village, we strive to Build, Promote, and Inspire our next generation of Aerospace Cybersecurity professionals. To meet this vision, we are proud to sponsor these student research presentations from Embry-Riddle Aeronautical University (ERAU).

\n\n

Jumpseat Intelligence: Bounded Agentic AI for Aircraft Cyber Defense: Sean McConoughey

\n\n

Modern commercial aircraft generate continuous streams of system and security logs across a multitude of networked subsystems. These security logs are generally analyzed post-flight at a SOC using rules-based matching that can generate significant false positives. How do you fix that, and what does responsible automation look like in a safety-critical environment where the cost of a wrong decision is measured differently than in a traditional IT context? This talk addresses those questions and presents a working student-developed research prototype that attendees can interact with at the Aerospace Village.

\n\n

SpaceVE: A Satellite Constellation Cyber Research Environment: Samuil Nikolov

\n\n

Satellite constellations are increasingly critical infrastructure, supporting navigation, communications, and timing for aviation and a wide range of other domains. Studying the security of those systems at constellation scale presents real challenges for academic researchers working outside of operational environments. SpaceVE is ERAU\'s Center for Aerospace Resilient Systems\' answer to that gap: a purpose-built satellite constellation cyber research environment designed to support realistic threat injection, detection research, and challenge scenarios without requiring access to operational spacecraft or proprietary ground systems. Student researchers built SpaceVE from the ground up this summer and will present the architecture, the first research missions, and what the initial findings mean for attacking and defending satellite constellations.

\n\nSpeakers:Sean McConoughey,Samuil Nikolov
\n
\nSpeakerBio:  Sean McConoughey
\nNo BIO available
\nSpeakerBio:  Samuil Nikolov
\nNo BIO available
\n\n\'',NULL,1293953),('2_Friday','12','12:00','12:30','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Flow Like Water: Experiences from Physical Red Teaming\'','\'Michael \"v3ga\" Aguilar\'','Creator Talks_2a8dc4e4825da4468cde0fa5075bf36a','\'Title: Flow Like Water: Experiences from Physical Red Teaming
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Physical red teaming remains one of the most consequential and under-discussed disciplines in offensive security. While network intrusions dominate the conversation, a determined adversary at the perimeter can bypass millions of dollars in cyber defenses with a lanyard, a clipboard, and a confident smile. This talk distills lessons learned from real-world physical red team engagements that achieved their objectives, walking through the tactics, techniques, and tooling that consistently produced results across diverse target environments.

\n\n

Topics include reconnaissance and target profiling, pretext development and social engineering at entry points, covert entry tooling (bypass devices, RFID cloning, lock and latch attacks), implant deployment for persistence, and methods for chaining physical access into network footholds. Emphasis is placed on what actually worked, not theoretical attack trees, alongside the operational considerations, failure modes, and decision points that separate a successful op from a burned one.

\n\nSpeakerBio:  Michael \"v3ga\" Aguilar, Principal Consultant at Sophos Red Team
\n

Michael Aguilar (v3ga) is a Principal Consultant on the Sophos Red Team, paid to think like the people his clients are afraid of. His work lives at the intersection of offensive security, vulnerability research, and low-level systems programming, Windows internals, reverse engineering, and the kind of dusty attack surfaces that nobody has looked at since the protocol was ratified. Sometimes, he’s lucky enough to perform full Physical Red teams against his client targets. His method is unglamorous and effective: Analyze, Formulate, Target, Attack (covertly).

\n\n\n\'',NULL,1293954),('2_Friday','12','12:00','12:59','N','Misc','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'From Disk Image to ATT&CK in One Binary — a Reference Architecture for Modern Incident Response (in Rust)\'','\'HUI Kwun Tai, Albert (4n6h4x0r)\'','Creator Talks_07efcca676c08617dcfabadbc0462ba8','\'Title: From Disk Image to ATT&CK in One Binary — a Reference Architecture for Modern Incident Response (in Rust)
\nTags: LOONG Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

A Reference Architecture for Modern Incident Response (in Rust)

\n\n

Incident response still runs on a toolbox: a dozen single-purpose parsers, a pile of CSVs, a timeline stitched together by hand, and a senior analyst\'s memory holding it all together. Every engagement re-solves the same plumbing. Every new artifact means a new script. And the hard-won expertise — how to read a prefetch run-count, how to resolve a ControlSet in an offline hive, which event IDs actually matter — lives in people, not in code you can run twice.

\n\n

This talk argues for a different shape: incident response as a framework, not a toolbox — and backs the argument with a working reference implementation, Issen, an open-source DFIR engine written in Rust. You point Issen at evidence — an E01/EWF/VMDK or raw disk image, a memory dump — and it returns a single normalized timeline and an ATT&CK-mapped report. One static binary. No Python runtime, no agent, no cloud. It runs the same on an examiner\'s laptop, in CI, or inside a sealed evidence enclave.

\n\n

Under the hood, Issen is deliberately thin. The real work lives in a fleet of standalone, single-responsibility forensic libraries — each a deep expert in one artifact family (NTFS and the change journal, registry hives, prefetch, SRUM, browser history, EVTX, SQLite, Windows and Linux memory) — that know nothing about each other. Issen is the orchestration and correlation layer that wires them into one story and speaks one normalized vocabulary of findings (\"consistent with,\" never a verdict), each tagged to MITRE ATT&CK. We\'ll walk the layered model that makes this composition work — container → filesystem / memory / log → parser → orchestration — and why every parser is medium-agnostic by design.

\n\n

The most useful — and least glamorous — lesson is the one the talk is really about: capability is cheap to build and expensive to wire. Demonstrated live against the public \"Stolen Szechuan Sauce\" case, we\'ll show artifacts that were completely correct in isolation yet invisible end-to-end, because a decoder existed but nothing called it, or a file was extracted but never classified, or a real-world quirk (offline hives have no CurrentControlSet; large registry values are split into \"big data\" segments) quietly returned nothing. We\'ll trace each from \"zero results\" to ground truth.

\n\n

Engineering substance throughout: panic-free, forbid(unsafe) parsers that treat every input as hostile; correctness validated against independent external oracles (not just the authors\' own fixtures); and a clean separation between observed fact, forensic inference, and the conclusions that belong to a human, not a tool.

\n\n

You\'ll leave with: a concrete, composable architecture for an IR pipeline you can adopt or fork; a working open-source reference to start from today; a repeatable method for finding \"dark\" capability in your own tooling; and a sober view of what to automate, what to keep human, and how to phrase findings so they survive scrutiny.

\n\nSpeakerBio:  HUI Kwun Tai, Albert (4n6h4x0r), DC852
\n

Albert Hui (@4n6h4x0r) is a digital forensics and incident response practitioner and the founder of Security Ronin. He builds open-source forensic tooling — including Issen, a Rust DFIR engine, and a family of panic-free libraries spanning disk, memory, registry, and application artifacts — and works hands-on as an examiner and expert witness testifying before courts of law, where findings have to survive cross-examination, not just look good on a slide. He\'s drawn to tooling an analyst can actually run twice: reproducible, offline, and honest about the line between observed fact and inference. In a past life he was an IBM Global Security Architect and a Deloitte Risk Advisory Director — which goes some way to explaining his propensity for horizontal thinking.

\n\n\n\'',NULL,1293955),('2_Friday','12','12:00','12:30','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Threat Hunting in OT Networks - Using Hypothesis Based Methods\'','\'Michael Cardwell\'','Creator Talks_9fe7732b518c98e580250d317b1f9ec6','\'Title: Threat Hunting in OT Networks - Using Hypothesis Based Methods
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Operational Technology (OT) networks present unique challenges for cybersecurity professionals tasked with detecting and mitigating threats. These networks, often critical to industrial control systems and infrastructure, require specialized approaches due to their complexity, legacy systems, and operational sensitivities. This presentation explores the art and science of threat hunting in OT environments, emphasizing the use of hypothesis-based methods to uncover hidden adversaries and anomalous behaviors.

\n\n

Attendees will gain insight into the special considerations and hazards associated with OT networks, including safety-critical systems, real-time constraints, and the potential for operational disruption. The talk will also provide a structured approach to hypothesis development, testing, and refinement, enabling practitioners to systematically investigate potential threats with minimal impact on operations.

\n\n

Finally, the presentation will delve into the practical logistical steps required to conduct threat hunts and incident response (IR) in OT environments, addressing challenges such as network segmentation, communication protocols, and coordination with operational teams. Whether you\'re a seasoned cybersecurity professional or new to OT security, this discussion will equip you with actionable strategies for effectively hunting threats in these critical and often misunderstood environments.

\n\nSpeakerBio:  Michael Cardwell, INL
\n

Michael Cardwell is a Cybersecurity Analyst and Researcher for the OT Hunt and Incident Response team at the INL. He has officially worked at the Lab since 2016 and has held various positions at the lab. One of the highlights of his time at the lab includes being the technical lead for the development of the Malcolm tool, which is a threat hunting tool suite developed at the INL for OT threat hunting. He has participated in hunts, IR’s and assessments in OT networks.

\n\n

Prior to working at the Lab he was an ISSO (Information System Security Officer). He also worked in the private sector as an IT Security Administrator for 10 years before that.

\n\n

He holds degrees in Electronics, Computer Science, and Cybersecurity. He currently lives in Idaho with his wife, 2 children and lots of cats.

\n\n\n\'',NULL,1293956),('2_Friday','12','12:00','12:30','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE\'','\'Bruno Mendes,Rafael Castilho Silva\'','Creator Talks_371aa862108690c2a7e3e9cfd7d694a4','\'Title: Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Arbitrary file write bugs are often treated as “almost critical” findings: interesting, dangerous, but most times it’s hard to prove impact when the target does not let you write a web shell to an obvious location or overwrite some magic configuration file to achieve code execution. This talk is about closing that gap for black box approaches.

\n\n

Instead of focusing on a single framework, we will present novel primitives that will make you able to pop shells across the most popular programming languages and frameworks in different ecosystems, all with as little information as possible about the target application.

\n\n

The session will start by assessing the current state of the art of arbitrary file write in bug bounty style scenarios. This will set the stage for the rest of the talk as we will start building a methodology to correctly identify exploitation capabilities and obtain as much information as possible about the target.

\n\n

From there, we will move into showcasing new techniques to abuse file write primitives and achieve the ultimate goal of code execution. We will go over novel techniques that apply both to the most popular interpreted languages and to the most used runtime environments.

\n\n

Bug Bounty Hunters who join this talk will not only leave with fresh techniques to apply in their engagements, but with a reusable mental model for identifying their target’s execution context and proving maximum impact when faced with arbitrary file write scenarios.

\n\nSpeakers:Bruno Mendes,Rafael Castilho Silva
\n
\nSpeakerBio:  Bruno Mendes, Head of Hacking, Ethiack
\n

Bruno Mendes is the Head of Hacking at Ethiack. He began his work career as an Offensive Security Researcher on Intel\'s IPAS Cloud Security team in 2024.\nIn bug bounty, back in 2023 placed 5th overall in the teams category and won the \"Not Dead Yet\" award at an Intigriti Live Hacking Event in Lisbon, and most recently co-authored a critical RCE with André Baptista (0xacb) that earned over $100k+ in a single program. He has an extensive CTF background being a three-time winner of the Cybersecurity Challenge Portugal (2021-2023), captain of Team Portugal at the European Cybersecurity Challenge (2022, 2023, 2025), and won the 2023 International Cybersecurity Challenge with Team Europe. He also captained the Instituto Superior Técnico CTF team (STT) from 2022 to 2024.

\n\nSpeakerBio:  Rafael Castilho Silva, Ethiack
\n

Security Reseacher at Ethiack fucosed on Vulnerability Research

\n\n\n\'',NULL,1293957),('2_Friday','12','12:00','12:30','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Yet Another Walking Dead of Active Directory\'','\'Nikos \"nickvourd\" Vourdas\'','Creator Talks_83ddb7fab8fa5fa08a06c4aba5f6b8ea','\'Title: Yet Another Walking Dead of Active Directory
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Disabled Active Directory accounts are commonly treated as harmless remnants of the past. In reality, many of these “dead” objects still retain dangerous inbound permissions, historical privilege artifacts, inherited ACL relationships, and hidden attack paths that most organizations never investigate.

\n\n

This talk demonstrates how disabled users, computers, and service accounts can still become active participants in privilege escalation chains through misconfigured DACLs, AdminSDHolder side effects, nested group inheritance, and delegated permissions. Through a real-world inspired case study, attendees will learn how a seemingly low-privileged user leveraged hidden rights over a disabled account to move toward Domain Admin in a mature enterprise environment.

\n\n

The presentation also introduces LazarusWakeUp, a tool designed to identify and analyze disabled Active Directory principals with dangerous inbound relationships, helping operators uncover hidden privilege escalation paths involving forgotten identities that traditional enumeration techniques and BloodHound analysis may overlook.

\n\n

Additionally, the talk presents a new perspective on Active Directory Recycle Bin abuse and object resurrection, showing how deleted identities may continue to create security risks even after organizations believe they have been removed entirely.

\n\nSpeakerBio:  Nikos \"nickvourd\" Vourdas, EY
\n

Nikos Vourdas, also known as nickvourd or NCV, is a Senior Offensive Security Consultant based in the US. With over five years of professional experience, he has actively participated in various global Tiber-EU and iCAST Red Teaming engagements. Nikos has conducted full Red Teaming operations to major clients across retail, banking, shipping, construction industries. He holds OSCE3, OSCP, OSWP, CRTL, CRTO and OASP certifications. Also, he has previously presented at DEF CON, DevSecCon, and various BSides events around the world. Nikos loves contributing to open-source projects and always starts his day at 05:00 AM with a refreshing jog while listening to French rap music.

\n\n\n\'',NULL,1293958),('2_Friday','12','12:15','12:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Maritime Hacking Village Policy Panel: Shadow Fleets, Cyber Effects, and Plausible Deniability\'','\'RADM John Mauger,Michael Sulmeyer\'','Creator Talks_266d4c1a47d51d31f296f6e2e14d21aa','\'Title: Maritime Hacking Village Policy Panel: Shadow Fleets, Cyber Effects, and Plausible Deniability
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:15 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Grey zone competition is no longer confined to cyber networks, nor is maritime disruption limited to traditional naval activity. Shadow fleets, spoofed identities, opaque ownership structures, sanctions evasion, cable “accidents,” and cyber-enabled interference are increasingly overlapping in ways that complicate attribution, deterrence, and defense.

\n\n

This panel will explore what happens when cyber and maritime grey zones converge. How do states and non-state actors use ambiguity at sea to create strategic effects while maintaining plausible deniability? What tools exist to identify, attribute, and respond to these activities? And how can governments, allies, industry, and legitimate shipping operators protect global commerce without escalating every incident into a crisis?

\n\nSpeakers:RADM John Mauger,Michael Sulmeyer
\n
\nSpeakerBio:  RADM John Mauger, PORTS LLC, USCG (ret.)
\n

Rear Admiral John W. Mauger, USCG (Ret.) is a seasoned executive with over 33 years of leadership experience in the maritime industry, national security, and cyber operations. Known for his foresight, innovative approach to problem solving, and ability to drive change, John has left an indelible mark on every role he’s undertaken—from commanding complex Coast Guard operations to shaping the future of cyber defense.

\n\n

As Commander of the First Coast Guard District, he led over 12,000 people and oversaw critical port operations in New England, deploying innovative technologies like counter-drone systems to enhance security. John\'s leadership during the TITAN capsule search and recovery at the TITANIC site highlighted his ability to lead complex crises in the international spotlight.

\n\n

At U.S. Cyber Command, John revolutionized cyber training, developing a cloud-based environment that modernized cyber exercises and increased readiness. John also served as the Coast Guard’s first Executive Champion the National Naval Officers Association, mentoring future leaders and driving organizational change.

\n\n

Earlier in his career, John led key regulatory projects for both domestic and international shipping. His work protected mariners and the environment, created new markets for alternative fuels, and established a new international code to safeguard vital Polar regions.

\n\n

Now leading (PORTS) LLC, John uses his diverse expertise to help clients plan for and navigate complex challenges in the maritime and critical infrastructure industries while enhancing personnel and team performance through effective training.

\n\nSpeakerBio:  Michael Sulmeyer, US DoD (ret.), Georgetown School of Foreign Service
\n

Michael Sulmeyer will start as Professor of the Practice at the School of Foreign Service\'s Security Studies Program in the fall of 2025. He most recently served as the first Assistant Secretary of Defense for Cyber Policy and as Principal Cyber Advisor to the Secretary of defense. He has held other senior roles involving cyber-related issues with the U.S. Army, the Office of the Secretary of Defense, U.S. Cyber Command and the National Security Council. In academia, he was a Senior Fellow with Georgetown\'s Center for Security and Emerging Technology. He holds a doctorate in politics from Oxford University where he was a Marshall Scholar, and a law degree from Stanford Law School.

\n\n\n\'',NULL,1293959),('2_Friday','12','12:45','13:30','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Aerospace Cybersecurity Student Research Spotlight: Cal Poly\'','\'Clara Davis,Dylan Gururajan\'','Creator Talks_7c113c8d16dd88d5106c0190cdc4e5be','\'Title: Aerospace Cybersecurity Student Research Spotlight: Cal Poly
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:45 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

At the Aerospace Village, we strive to Build, Promote, and Inspire our next generation of Aerospace Cybersecurity professionals. To meet this vision, we are proud to sponsor these student research presentations from Cal Poly.

\n\n

Trusting Linux in Orbit: Process Injection Against CubeSat Flight Software: Dylan Gururajan

\n\n

Today’s CubeSat flight software increasingly relies on Linux-based frameworks. While this makes development more efficient and flexible, it also imports assumptions from general computing that bring vulnerabilities to these environments.

\n\n

This talk presents a proof-of-concept attack demonstrating how an attacker, once able to uplink code to a live CubeSat, can leverage standard Linux mechanisms to inject and execute arbitrary code within the primary flight process. By abusing ptrace, dynamic memory allocation, and runtime linking, a malicious library can be loaded directly into a running mission process without exploiting kernel vulnerabilities or binaries on disk.

\n\n

We walk through the full injection chain, including process discovery, register manipulation, remote syscall staging, and dynamic resolution of libc symbols to invoke dlopen within the target process. We also examine the operational constraints of this technique, including one-shot execution via shared library initialization and implications for attacker tradeoffs.

\n\n

Software Supply Chain Vulnerabilities in Satellites: Clara Davis

\n\n

Modern satellite systems rely on complex open-source C/C++ dependency ecosystems that may contain untracked security vulnerabilities but unlike Earth’s software, space systems often cannot be patched after deployment. This research, conducted at Cal Poly, San Luis Obispo, develops a pipeline that extends CCScanner, software dependency analysis tool, for multi-toolchain package manager detection and integrates CNEPS for code clone-based component discovery, with recursive repository cloning, transitive dependency graph creation, and CVE database queries with CVSS severity tracking. By analyzing the full dependency chain rather than direct dependencies, this tool captures vulnerability exposure that other, shallower scans miss. This is a critical gap given that C/C++ projects introduce over 70% of their dependencies implicitly through build systems rather than explicit package managers.

\n\nSpeakers:Clara Davis,Dylan Gururajan
\n
\nSpeakerBio:  Clara Davis
\nNo BIO available
\nSpeakerBio:  Dylan Gururajan
\nNo BIO available
\n\n\'',NULL,1293960),('2_Friday','13','12:45','13:30','Y','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Aerospace Cybersecurity Student Research Spotlight: Cal Poly\'','\'Clara Davis,Dylan Gururajan\'','Creator Talks_7c113c8d16dd88d5106c0190cdc4e5be','\'\'',NULL,1293961),('2_Friday','12','12:30','12:59','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Beyond Theoretical Risk: How Cache Poisoning Escalated to Critical Account Takeover in TikTok’s Web Infrastructure\'','\'Glendon Chong\'','Creator Talks_798bf10795cd199011920444f8a5c052','\'Title: Beyond Theoretical Risk: How Cache Poisoning Escalated to Critical Account Takeover in TikTok’s Web Infrastructure
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Web cache poisoning is often written off as a class of vulnerabilities with limited real-world impact. Most reported instances only expose non-sensitive user metadata, cause temporary, minor disruptions to static content, or require such narrow, impractical conditions to exploit that they rarely move beyond theoretical proof-of-concept. For TikTok’s Vulnerability Management team, this framing shaped our initial approach to triaging cache poisoning submissions for years—until two radical researcher submissions upended that assumption entirely, proving misconfigured web caches can undermine every pillar of the CIA triad (confidentiality, integrity, availability) to enable catastrophic, scalable harm. In this talk, we’ll start with a foundational breakdown of web cache poisoning: common misconfigurations (from flawed cache key logic to mishandled origin headers) that enable exploitation, and the limited impact profiles that led our team (and many in the bug bounty ecosystem) to historically deprioritize these flaws. We’ll then deep dive into the game-changing submissions that reshaped our security posture and why security teams and bug bounty hunters must re-evaluate how they assess cache poisoning risk—moving past surface-level assumptions about limited impact to audit for hidden, critical exploit pathways. Whether you triage web vulnerabilities, build global web infrastructure, or hunt for bugs at scale, this session will equip you to spot and remediate cache poisoning risks before they’re weaponized against your users.

\n\nSpeakerBio:  Glendon Chong, Tiktok
\n

I am part of the Vulnerability Management team for TikTok. Over the past year, I’ve been actively involved in web application vulnerability triage, collaborating with security researchers and internal teams to dissect, validate, and remediate a wide spectrum of web-based threats. My work centers on bridging reporter expertise and TikTok’s security posture—including in-depth negotiations over CVSS scoring, refining triage workflows for emerging attack vectors, and translating complex vulnerability details into actionable remediations. I bring hands-on experience identifying gaps in modern web architectures, advocating for fair, transparent risk assessment with the bug bounty community, and aligning vulnerability prioritization with our platform’s commitment to user safety.

\n\n\n\'',NULL,1293962),('2_Friday','12','12:30','13:15','N','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM\'','\'Larry Pesce\'','Creator Talks_f52cdd3d178d3e53c3a258fb4451307c','\'Title: Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:30 - 13:15 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

An AI agent found a previously undisclosed vulnerability in a named vendor\'s IoT product within hours of being pointed at the firmware. The practitioner who built the agent had spent 25+ years doing that work by hand. Plan R is an IoT-focused MCP server that gives AI agents direct access to real pentesting tools, structured by playbooks that encode methodology rather than scripts. The framework expanded from firmware-only analysis to a multi-domain suite covering WiFi, BLE, network protocols, and hardware interfaces, with each domain compounding the value of every other through cross-domain correlation. The centerpiece is a real engagement: a named vendor, a disclosed vulnerability, and the specific challenge of convincing a white box vendor that a finding is real when the methodology that found it is \"an LLM read your code.\" Attendees leave with a working blueprint for building their own AI pentesting agents, an honest account of where the approach breaks, and a direct answer to the question every experienced practitioner is quietly asking: if an AI can do this, what exactly am I bringing to an engagement? The answer is worth hearing. But the work is changing, and this community should be driving how.

\n\nSpeakerBio:  Larry Pesce
\nNo BIO available
\n\n\'',NULL,1293963),('2_Friday','13','12:30','13:15','Y','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM\'','\'Larry Pesce\'','Creator Talks_f52cdd3d178d3e53c3a258fb4451307c','\'\'',NULL,1293964),('2_Friday','12','12:30','12:59','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Introduction to RFID\'','\'Ege Feyzioglu,Karen Ng\'','Creator Talks_3b50c4cac3baca1566563fe53b269c67','\'Title: Introduction to RFID
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

You know the sound of beep... Click when using a badge to enter a door to a building, but how does this work and how can you exploit issues with RFID systems?

\n\n

This talk will explain the basics of what’s inside the readers and the badges, and how they communicate wirelessly. You will learn about the common tools available (Proxmark, Flipper, Keysy), how to get one and how to use it.

\n\n

NEW THIS YEAR: We will cover real case studies of RFID systems being exploited. What were the designers trying to do, and where did they make mistakes?

\n\n

In addition to the real case studies, we’ll talk about techniques to clone badges, and brute force systems to get access you never had in the first place.

\n\nSpeakers:Ege Feyzioglu,Karen Ng
\n
\nSpeakerBio:  Ege Feyzioglu, Physical Security Village
\n

Ege is a physical security consultant and educator, specialising in access control systems and embedded electronics. She is currently pursuing a degree in Electrical Engineering. Her work focuses on security education, wireless communications, and the intersection of physical security and electronics. She is one of the Village Leads at the Physical Security Village and currently serves as its Secretary-Treasurer.

\n\nSpeakerBio:  Karen Ng, Physical Security Village
\n

Karen is a risk analyst and physical security penetration tester by day, and a physical security educator and speaker by night. She has a strong interest in security, delivering trainings on physical security vulnerabilities to a wide range of audiences around the world. Karen comes from a background in engineering and has extensive experience in major event logistics. She is one of the Village Leads at the Physical Security Village, and works with the rest of the PSV team to teach how to recognize and fix security exploits to the community. Graphic design is her passion.

\n\n\n\'',NULL,1293965),('2_Friday','13','13:00','13:59','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Connectivity as Control in the European High North\'','\'Szymon Skalski,Patricia Vargas Leon,Jorge Acevedo Canabal\'','Creator Talks_76117f00c45afaf4fc725711a3fbfb06','\'Title: Connectivity as Control in the European High North
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Between 2022 and 2024, the European High North saw three events at three attribution confidence levels. One segment of Svalbard\'s twin fibre system failed—Norwegian police closed the case with no state-actor finding. AcidRain wiped tens of thousands of Viasat SurfBeam2 modems via a ground-segment management-plane compromise—attributed to GRU by US/UK/EU in May 2022. GNSS interference over eastern Finnmark persisted 2019–2024—assessed by Norwegian services as Russian EW largely spilling from Kola. Three attributions. Three regimes. No mechanism that treats them as one. UNCLOS cable protection varies by zone (Art 79 shelf; Art 113 high seas; Art 58 EEZ). The 1884 Cables Convention—still in force—governs outside territorial waters. Svalbard Treaty reach into the FPZ is contested. NATO\'s cumulative-effects language has no classification framework. The 2023–24 Baltic sequence (Balticconnector; C-Lion1/BCS; Estlink-2/Eagle S) is the same play in the active theatre NATO CUI Cell, Baltic Sentry, EU CER/NIS2, JEF and NORDEFCO already cover — and still falls through. We propose an allies-first application of UNDRR Hazard Information Profiles to adversarial compound operations: indicators, authorities, a 2027 milestone. Classification stops no cable. A common record is the precondition for everything that will.

\n\nSpeakers:Szymon Skalski,Patricia Vargas Leon,Jorge Acevedo Canabal
\n
\nSpeakerBio:  Szymon Skalski, Jagiellonian University PL
\n

Szymon is a PhD Candidate in the School of Social Sciences at Jagiellonian University and a Senior Expert and NASK National Research Institute in Poland. He is also affiliated with the Ostrom Workshop at Indiana University, where he leads the working group on Environmental Security and Technological Risk in Conflict. He has served on cybersecurity expert panels at the Polish Ministry of Digital Affairs and the Polish Bank Association. He is also a fellow of the European Law Institute, member of FIDMA and Virtual Routes European PhD Cybersecurity Accelerator Programme. For the past three years, he has participated in NATO’s Locked Shields exercises, representing Poland for two years and, in 2026, organizing the exercises on behalf of the CCDCOE in the legal domain.He is a researcher and scholarship holder of grants from the National Science Centre in Poland in the fields of insurance and digital security. He publishes in international academic journals in the fields of cybersecurity, insurance, tort law, and international law.

\n\nSpeakerBio:  Patricia Vargas Leon, Ostrom Workshop Indiana University US, Yale Law School
\n

Patricia A. Vargas León is a Visiting Fellow at Yale Law School\'s Information Society Project, a Cybersecurity Research Postdoctoral Fellow at Indiana University\'s Ostrom Workshop, and a Visiting Scholar in Internet Governance at the Catholic University of Uruguay. Her research bridges law, policy, and technology — focusing on Internet governance, cybersecurity, international law, and the law of the sea. She is particularly interested in how governments control Internet infrastructure, network neutrality, and regulatory parallels between the law of the sea and cyberspace. Her doctoral dissertation examines Internet blackouts across political regimes and how states restrict digital connectivity. Before academia, Patricia practiced law in the private sector for nearly a decade and brings over two decades of international law experience to her work, including a consultancy with the UN Division for Ocean Affairs and the Law of the Sea (DOALOS). She also served as a Google Policy Fellow during her doctoral studies. Patricia holds a Ph.D. and M.S. in Information Science and Technology from Syracuse University and a law degree from the Pontifical Catholic University of Peru. Her dual training positions her to address complex questions at the intersection of technology, governance, and international law.

\n\nSpeakerBio:  Jorge Acevedo Canabal, Ostrom Workshop Indiana University US
\n

Jorge Acevedo Canabal, MD (University of Puerto Rico School of Medicine, Magna Cum Laude), is a physician and Visiting Scholar at the Ostrom Workshop, Indiana University, working on research that sits at the intersection of healthcare, public health, and cybersecurity, applying epidemiological and disaster medicine methods to map patient harm attributable to healthcare cyberattacks and technological hazards. He previously served as Chief Medical Officer of the Puerto Rico Science, Technology and Research Trust, and currently serves as advisor to the Biohacking Village and Raíces Cyber Org.

\n\n\n\'',NULL,1293966),('2_Friday','13','13:00','13:45','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'OSINT Is Still a Thinking Game: Surviving AI Without Losing Tradecraft\'','\'Nico Dekens\'','Creator Talks_5c3cb31e733b5c2fbd306c2129e56f73','\'Title: OSINT Is Still a Thinking Game: Surviving AI Without Losing Tradecraft
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

The OSINT landscape is undergoing a fundamental shift. Artificial Intelligence is no longer just a tool; it is becoming a crutch. As analysts increasingly rely on LLMs to triage data, translate foreign slang, and summarize massive datasets, a dangerous cognitive atrophy is taking hold. We are trading the slow, deliberate friction of critical thinking for the illusion of speed and certainty.

\n\n

This talk, \"OSINT Is Still a Thinking Game,\" exposes the hidden vulnerabilities of AI dependence in intelligence work. Through real-world case studies—from misinterpreting Telegram chatter to falsely flagging logistics data—we will examine how the \"Good Enough\" trap leads to catastrophic analytical failures.

\n\n

More importantly, this session provides a concrete defense framework. Attendees will learn the four essential habits required to survive the AI era: reading the raw source, forcing a second hypothesis, separating speed from confidence, and auditing dependence. The tools will inevitably get better, but the thinking must get sharper. Join this session to learn how to maintain your tradecraft, keep your judgment visible, and ensure that in the age of automation, defensibility always wins over speed.

\n\nSpeakerBio:  Nico Dekens, Dutch_OSINTGUY SVP of Engineering & Chief Innovator @ Shadowdragon.io
\n

Nico Dekens is the owner of Dutch Osint Guy Intelligence Services and an All Source Analyst who specializes in Open Source Intelligence (OSINT), online Human Intelligence (HUMINT) and Online investigations. Nico eats, sleeps, and lives everything which has to do with OSINT, online investigations, intelligence gathering and analysis. He has over 20 years’ experience as an (all source) Intelligence Analyst in Dutch Law Enforcement. There, he analyzed murder cases, international narcotics cases, stolen art cases, gang violence cases, political disturbance cases. Investigated and analyzed online jihadist groups & conducted several online covert virtual HUMINT investigations.

\n\n

\n\n

Known online as @Dutch_OsintGuy, Nico is very active within the OSINT community. As the owner of Dutch Osint Guy Intelligence Services, Nico provides consultancy and training for Open-Source Intelligence (OSINT), risk assessments, keynotes, security awareness, and implementation of structured team methodologies. He is also a co-founder of the OSINTCurio.us project.

\n\n

\n\n

Nico chose to be an OSINT Specialist and Cyber Intelligence Analyst because he wanted to help to make the world a safer place and because OSINT is one of the fastest fields in the cyber realm, with an ever-changing landscape. This helps him to remain in a constant state of learning and giving back what he’s learned to others who also want to make this (digital) world a safer place.

\n\n

\n\n

Before he became a SANS instructor, Nico helped set up the OSINT units within the Dutch Government as well as train and educate thousands of government employees on how to work in structured teams and perform excellent online investigations.

\n\n

\n\n

Nico is a SANS Instructor for SEC497 Practical Open-Source Intelligence (OSINT) and lead author of SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis. As an instructor, he uses practical real-world examples as much as possible. “Being an instructor isn\'t one-way traffic; it is a dynamic process between the student and instructor” Nico says. He is also a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition.

\n\n

With all his OSINT and intelligence gathering and analysis experience that he brings to the table, Nico is able to share his unique experiences with his students on Open-Source Intelligence.

\n\n

\n\n

Among his biggest career highlights, he is proud of helping to stop terrorists from executing their attacks and stopping child predators. It’s his goal to keep the world safe and help those who are not able to defend themselves. Nico has had students come back to him years later, thanking him for techniques he taught them that played a role in their investigations.

\n\n

\n\n

Nico has been honored by Head of Europol, the DHS, and NATO for his efforts in the OSINT field. He’s received a letter of gratitude from the Dutch Military Cyber Intelligence and Cyber Defense department. He’s also been honored by Dutch Law Enforcement for his efforts in counter terrorism and online investigations.

\n\n

\n\n

Nico holds certifications as a Police Detective, Operational Intelligence Analyst, Tactical Intelligence Analyst, Strategical Intelligence Analyst, Open-Source Intelligence Analyst, Cyber Intelligence Tradecraft Professional, Online Counter Terrorism Specialist.

\n\n

\n\n

Nico is the 2023 Open Source Intelligence Champion of the Year, presented by the OSMOSIS Institute.

\n\n

Nico is a typical gadget nerd. When he’s not teaching, he likes to play around and test new gadgets that are closely related to the cyber field. So Raspberry pi, esp8266, esp32, microbits, iot devices are things he likes to learn more about. He also likes to work-out and play basketball. He’s also a collector of unique sneakers.

\n\n

Currently Nico is working as Senior Vice President of Engineering & Chief Innovator at ShadowDragon.

\n\n\n\'',NULL,1293967),('2_Friday','13','13:00','13:30','N','Hackers.town','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'The Cum-Stained Precipice of Digital Redlining\'','\'Erica Rachel Andrews,Abbie Gonzalez (pronounced AB)\'','Creator Talks_4c12ebd3cb90ab208c00565ec1319781','\'Title: The Cum-Stained Precipice of Digital Redlining
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

The web was supposed to democratize information. Instead, we have a two-tier reality: one class consuming porn on $2,000 laptops they\'ll discard in eighteen months, another class without a screen. The web was supposed to democratize information. Instead, we have a two-tier reality: one class consuming porn on $2,000 laptops they\'ll discard in eighteen months, another class without a screen. That discarded laptop could have been a classroom, a business, a lifeline. The gap between those two realities is a political choice—one we can make differently. This talk is a direct confrontation with the culture of disposable tech—and a practical guide to grassroots reclamation programs that turn waste into opportunity and combat inequality with community.

\n\nSpeakers:Erica Rachel Andrews,Abbie Gonzalez (pronounced AB)
\n
\nSpeakerBio:  Erica Rachel Andrews, Co-founder and president at Springfield.community
\nNo BIO available
\nSpeakerBio:  Abbie Gonzalez (pronounced AB), Executive Director Springfield.community
\nNo BIO available
\n\n\'',NULL,1293968),('2_Friday','13','13:15','13:59','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'From threat-intel to tested defense, the adversary simulation playbook\'','\'Cheryl Biswas,Adam Pennington,Olaf Hartong,Sarah Hume\'','Creator Talks_1142a9d8065114d4117f7c89ea66ebc9','\'Title: From threat-intel to tested defense, the adversary simulation playbook
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:15 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Knowing who is coming for you is only half the fight. The real work is turning that knowledge into defenses that actually works. This panel walks through the full playbook, from raw threat intelligence on state-sponsored actors and other adversaries, to emulating their tradecraft, to validating whether your defenses can really stand up to it. \nOur panelists bring hands-on experience across adversary simulation, threat intel, and purple teaming to talk about what it takes to move from a report on paper to a tested, measurable defensive posture. The panel will dig into how to prioritize the threats that matter to your organization, how to faithfully replicate real adversary behavior instead of chasing generic checklists, and how red and blue working side by side turns every simulated attack into a lasting defensive victory. Whether you are defending against nation-state operators or opportunistic criminals, the goal is the same! Stop guessing about your defenses and start proving them. Join us for a practical conversation about closing the gap between intelligence and action.

\n\nSpeakers:Cheryl Biswas,Adam Pennington,Olaf Hartong,Sarah Hume
\n
\nSpeakerBio:  Cheryl Biswas, Strategic Threat Intel Analyst at TD Bank
\n

Cheryl Biswas is a Strategic Threat Intel Analyst with TD bank in Toronto, Canada. She found her way into InfoSec through a helpdesk backdoor and pivoted into roles for vendor and change management, jumped a gap into privacy and DR/BCP, then laterally moved into security audits and assessments. Her degree in Political Science has evolved into researching APTs, botnets, ransomware and more. Cheryl is actively involved in the security community as a conference speaker and volunteer, mentors those entering the field, and encourages women and diversity in Infosec as a founding member of the \"The Diana Initiative.\"

\n\nSpeakerBio:  Adam Pennington, ATT&CK lead at MITRE Corporation
\n

Adam Pennington leads ATT&CK at The MITRE Corporation and collected much of the intelligence leveraged in creating ATT&CK’s initial techniques. He has spent much of his 16 years with MITRE studying and preaching the use of deception for intelligence gathering. Prior to joining MITRE, Adam was a researcher at Carnegie Mellon\'s Parallel Data Lab and earned his BS and MS degrees in Computer Science and Electrical and Computer Engineering from Carnegie Mellon University. Adam has presented and published in several venues including FIRST CTI, USENIX Security, DEF CON, and ACM Transactions on Information and System Security.

\n\nSpeakerBio:  Olaf Hartong, Defensive Specialist at FalconForce
\n

Olaf Hartong is a Defensive Specialist and security researcher at FalconForce. He specialises in understanding the attacker tradecraft and thereby improving detection. He has a varied background in blue and purple team operations, network engineering, and security transformation projects.\nOlaf has presented at many industry conferences including Black Hat, DEF CON, DerbyCon, Splunk .conf, FIRST, MITRE ATT&CKcon, and various other conferences. Olaf is the author of various tools including ThreatHunting for Splunk, ATTACKdatamap and Sysmon-modular.\nHe maintains a blog at https://olafhartong.nl

\n\nSpeakerBio:  Sarah Hume, Purple Team Service Lead at Security Risk Advisors
\n

Sarah leads the Purple Team service at Security Risk Advisors (SRA). She has led hundreds of Threat Intelligence-based Purple Team exercises for organizations in the Fortune 500 and Global 1000 over the past 7 years. Her background is in offensive security, primarily internal network, OT/ICS, and physical security penetration testing. Sarah also has experience in external network penetration testing, web application assessments, OSINT, phishing/vishing campaigns, vulnerability management, and cloud assessments. Sarah graduated Summa Cum Laude from Penn State with a B.S. in Cybersecurity. She is a Certified Red Team Operator (CRTO), Certified Information Systems Security Professional (CISSP), Google Digital Cloud Leader, AWS Certified Cloud Practitioner, and Advanced Infrastructure Hacking Certified. She lives in Philadelphia with her dog, Paxton.

\n\n\n\'',NULL,1293969),('2_Friday','13','13:30','14:30','N','OSINT For Good Community','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Classical OSINT using AI (Actual Intelligence)\'','\'Bianca C. Ionescu/reconcerto\'','Creator Talks_01296d1f990410d034bc2cc09416d786','\'Title: Classical OSINT using AI (Actual Intelligence)
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

AI this, AI that, and of course even in the world of OSINT AI has been getting integrated. But this talk focuses on a different AI: Actual Intelligence. Modern investigators have access to more tools, automation, and artificial intelligence than ever before, yet many investigations still suffer from poor assumptions, weak validation, and information overload. Long before automated platforms and AI assistants existed, investigators relied on analytical thinking, source evaluation, and structured methodology to turn information into intelligence. This session introduces the ACTUAL framework. Through practical examples and real-world investigative scenarios, attendees will learn how to validate findings with confidence and conduct effective OSINT investigations even when specialized tools aren\'t available. Tools help collect information, but ACTUALly intelligence comes from the investigator.

\n\nSpeakerBio:  Bianca C. Ionescu/reconcerto
\n

Bianca Ionescu is a CyberCorps SFS scholar pursuing a master’s degree in cybersecurity at UNLV. She\'s served as a leader within cybersecurity student organizations, promoting growth, inclusion, and professional development. Her interests include open-source intelligence and mentoring new learners entering the field. Offline, she enjoys strength training and playing the viola. She’s motivated by community building, continuous learning, and the challenge of solving complex security problems that inspire her growth and resilience every day.

\n\n\n\'',NULL,1293970),('2_Friday','14','13:30','14:30','Y','OSINT For Good Community','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Classical OSINT using AI (Actual Intelligence)\'','\'Bianca C. Ionescu/reconcerto\'','Creator Talks_01296d1f990410d034bc2cc09416d786','\'\'',NULL,1293971),('2_Friday','13','13:30','13:59','N','Payment Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'It\'s a Payment Terminal. It\'s My Arcade. It\'s Everywhere. It Cost Me Nine Bucks.\'','\'Chiao-Lin Yu \"Steven Meow\"\'','Creator Talks_36a2f4d7310471d8a20712e5514be79e','\'Title: It\'s a Payment Terminal. It\'s My Arcade. It\'s Everywhere. It Cost Me Nine Bucks.
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

20+ million payment terminals. Hardware-signed. Kernel-verified. Processing live transactions in retail,\nhospitality, and healthcare worldwide. You\'ve probably tapped one this week.\nWe bought one for nine bucks. Sixty seconds later, we had root over WiFi. Three chained vulnerabilities, fully\nautomated, zero interaction. Plaintext credentials, full filesystem, kernel signature enforcement gone.\nWe made it run Snake. Tetris. Whatever you want it to. A PCI-certified arcade.\nWe reported everything to the vendor. They passed. \"Out of support. Not fixing it.\" Except retail-purchased\nunits this year ship with the exact firmware they\'re walking away from. No update mechanism. No OTA. No\nadvisory. The bugs remain exploitable on devices being sold today.\nPCI-certified doesn\'t mean patched. Retail-available doesn\'t mean current. The bugs you can\'t patch are the\nones already on the counter.

\n\nSpeakerBio:  Chiao-Lin Yu \"Steven Meow\", Staff Red Team Security Threat Researcher at Trend AI (Trend Micro)
\n

Chiao-Lin Yu (Steven Meow) is a Staff Red Team Security Threat Researcher at Trend AI (Trend Micro)\nTaiwan. He holds professional certifications including OSCE3, OSCP, CRTO... and LPT. He has previously\nspoken at DEF CON (USA), CCC (Germany), BSides Tokyo (Japan), HITCON Training (Taiwan), etc. He has\ndisclosed over 50 CVE vulnerabilities affecting major vendors such as VMware, NEC, D-Link, and Zyxel. He\nspecializes in red teaming, web security, IoT, and cats🐱.

\n\n\n\'',NULL,1293972),('2_Friday','13','13:45','14:15','N','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Drag, Drop, Deploy, Compromise: Why Trusted HMI Engineering Toolchains Remain an ICS Supply-Chain Blind Spot\'','\'Jiwoon Yoo,TaeWoo Kim,Eunji choi\'','Creator Talks_560ff4cb244849848cd072339e75a4d9','\'Title: Drag, Drop, Deploy, Compromise: Why Trusted HMI Engineering Toolchains Remain an ICS Supply-Chain Blind Spot
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:45 - 14:15 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

HMI engineering tools are trusted gateways into industrial environments. Engineers use these tools to design screens, configure tags, connect to controllers, and deploy projects to real-world sites. HMIs are used across manufacturing, logistics, maritime, energy, utilities, building automation, and many other industrial sectors. Yet the engineering tools and project files used to create them are often treated as simple work utilities.

\n\n

This presentation analyzes multiple vulnerabilities discovered in the HMI engineering toolchain from a supply chain perspective. It covers memory corruption during project file parsing, DLL search path hijacking, the loading of unsigned components, UI spoofing through silent font installation, and fallback to plaintext policies when secure OPC UA connections fail.

\n\n

The core argument is simple: the ICS supply chain does not begin only at a vendor’s update server. Project files received from customers, templates shared by system integrators, maintenance backups, local DLLs, fonts, communication settings, and the engineering workflow of “open, drag, and deploy” are all part of the supply chain.

\n\n

This presentation shows that not only PLCs and HMI runtimes, but also the tools and files used to create them, are part of the attack surface.

\n\nSpeakers:Jiwoon Yoo,TaeWoo Kim,Eunji choi
\n
\nSpeakerBio:  Jiwoon Yoo, CYTUR Inc
\n

CYTUR Inc. / Security Team Lead

\n\n

Research Areas and Interests\nMaritime Cybersecurity, Satellite Security, Large Language Models, Adversarial Attacks\nEducation and Professional Experience\n2017: B.S. in Computer Science Engineering, Anyang University, Gyeonggi-do, South Korea\n2023: M.S. in Convergence Security, Graduate School of Information Security, Korea University, Seoul, South Korea\n2023 – Present: Security Team Lead, CYTUR Inc.

\n\n

Academic Activities \nSymposium Participation\n* Nov 13–14, 2024: Participated in CFP-selected research at the IMO Maritime Cybersecurity Symposium (United Nations), London, UK

\n\n

Journal Publication\nSensors (May 24, 2023) — First author: Formulating Cybersecurity Requirements for Autonomous Ships Using the SQUARE Methodology\nhttps://doi.org/10.3390/s23115033

\n\n

Sensors (Feb 26, 2022) — First author: Cyberattack Models for Ship Equipment Based on the MITRE ATT&CK Framework\nhttps://doi.org/10.3390/s22051860

\n\nSpeakerBio:  TaeWoo Kim, CYTUR Inc
\nNo BIO available
\nSpeakerBio:  Eunji choi, CYTUR Inc
\nNo BIO available
\n\n\'',NULL,1293973),('2_Friday','14','13:45','14:15','Y','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Drag, Drop, Deploy, Compromise: Why Trusted HMI Engineering Toolchains Remain an ICS Supply-Chain Blind Spot\'','\'Jiwoon Yoo,TaeWoo Kim,Eunji choi\'','Creator Talks_560ff4cb244849848cd072339e75a4d9','\'\'',NULL,1293974),('2_Friday','14','14:00','14:45','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'6 years of Adversary Village! Keeping up with the adversaries and why it takes a village\'','\'Abhijith \"Abx\" B R,Bryson Bort,Anant Shrivastava\'','Creator Talks_c716a0aa2c9adefd36e08dabb969a7a8','\'Title: 6 years of Adversary Village! Keeping up with the adversaries and why it takes a village
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Six years ago, Adversary Village started as a simple idea, give the people who study adversaries and adversarial tradecraft a place to call home. What grew out of it was something bigger than any of us expected. A community of offensive security professionals, adversary simulation and emulation specialists, threat researchers, tool builders, philosophers and the endlessly curious, all showing up to share what they know about thinking and acting like the adversary. Year after year the Village has been the place to dig into real adversary tradecraft, offensive TTPs, simulation and emulation techniques, hands-on labs, and the tools that make it all work. This panel looks back at how far we have come and forward at where we are headed. Adversaries never stop evolving, from state-sponsored operators running long, patient campaigns to ransomware crews and everyone in between, and neither can we. We will talk about how the Village has kept pace in a realm that reinvents itself every year, how the craft of adversary simulation and emulation has matured into a discipline of its own, and why faithfully replicating real adversary tradecraft has become essential to testing whether our defenses actually work.\nWe will get into why keeping up is a job no single person or team can do alone, and how a community that trades knowledge freely ends up being the sharpest edge we have got. Most of all, we will celebrate the people who built this, the volunteers, the speakers, the first timers who became regulars. Six years in one thing is clearer than ever! It takes a village to keep up with the adversaries, whether they are nation-state actors, criminal groups, or threats we have not even named yet. Come raise a glass with us and help shape what the next six years look like.

\n\nSpeakers:Abhijith \"Abx\" B R,Bryson Bort,Anant Shrivastava
\n
\nSpeakerBio:  Abhijith \"Abx\" B R, Founder of Adversary Village
\n

Abhijith B R, also known by the pseudonym Abx, has more than a decade of experience in the offensive cyber security industry, serves as the Director of BreachSimRange, and Founder of Adversary Village.\nHe is a professional hacker, offensive cyber security specialist, red team consultant, security researcher, trainer and public speaker. \nCurrently, he is building BreachSimRange.io as the Founder and Director and is involved with multiple organizations as a consulting specialist to help them build offensive cyber security operations programs, improve their current security posture, assess cyber defense systems, and bridge the gap between business leadership and security professionals.\nIn the past, he led the offensive security team at Envestnet, Inc., held the position of Deputy Manager - Cyber Security at Nissan Motor Corporation, and prior to that, he worked as a Senior Security Analyst at EY. \nAs the founder of Adversary Village (https://adversaryvillage.org/), Abhijith spearheads a community initiative focused on adversary simulation, adversary-tactics, purple teaming, threat actor/ransomware research-emulation, and offensive cyber security. Adversary Village is part of DEF CON Villages and organizes hacking villages at prominent events such as the DEF CON Hacking Conference, RSA Conference etc. \nAbx also acts as the Lead of an official DEF CON Group named DC0471. He is actively involved in leading the Tactical Adversary project (https://tacticaladversary.io/), a personal initiative that centers around offensive cyber security, adversary attack simulation and red teaming tradecraft. \nAbhijith has spoken and delivered trainings at various hacking and cyber security conferences such as, DEF CON hacker convention - Las Vegas, RSA Conference - San Francisco, The Diana Initiative - Las Vegas, DEF CON 28 safemode - DCG Village, Opensource India, Security BSides Las Vegas, BSides San Francisco, BSides Tampa, Hack Space Con – Kennedy space center Florida, Nullcon – Goa, c0c0n – Kerala, BSides Delhi, DEF CON Bahrain, DEF CON Singapore etc.

\n\nSpeakerBio:  Bryson Bort, Founder and CEO at SCYTHE
\n

Bryson is the Founder of SCYTHE, a start-up building a next generation attack emulation platform, and GRIMM, a cybersecurity consultancy, and Co-Founder of the ICS Village, a non-profit advancing awareness of industrial control system security. He is a Senior Fellow with the Atlantic Council\'s Cyber Statecraft Initiative, the National Security Institute, and an Advisor to the Army Cyber Institute. As a U.S. Army Officer, he served as a Battle Captain and Brigade Engineering Officer in support of Operation Iraqi Freedom before leaving the Army as a Captain. He was recognized as one of the Top 50 in Cyber in 2020 by Business Insider. Bryson received his Bachelor of Science in Computer Science with honors from the United States Military Academy at West Point. He holds a Master\'s Degree in Telecommunications Management from the University of Maryland, a Master\'s in Business Administration from the University of Florida, and completed graduate studies in Electrical Engineering and Computer Science at the University of Texas.

\n\nSpeakerBio:  Anant Shrivastava
\n

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

\n\n\n\'',NULL,1293975),('2_Friday','14','14:00','14:30','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'AI Nightmare: Hacking at 0-Hour\'','\'Pedro \"drop\" Paniago\'','Creator Talks_7445ca784f7e7482c82e56fcb6de41d7','\'Title: AI Nightmare: Hacking at 0-Hour
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Many of us have heard that AI is just hype. But is that really the case? In this talk, Pedro “drop” Paniago walks through the experiment he conducted by applying AI to his bug bounty methodology, resulting in findings worth $50K in just a few weeks. Through real examples, lessons learned, current limits, and practical tips, he explores the impact AI is already having on bug bounty and security research.

\n\nSpeakerBio:  Pedro \"drop\" Paniago
\n

Pedro Paniago also known as \"drop\" in the bug bounty community, is an Offensive Security Manager specializing in Application Security at PwC, as well as a security researcher with a strong focus on AI security. As a bug bounty hunter, he has identified more than 1,000 vulnerabilities and holds 10+ CVEs. He is certified in CBBH, eJPTv2, PJMT, and BSCP. In 2024, Pedro ranked in the top 3 at Belgium’s Hack the Government Live Hacking Event, and in 2025 he placed in the top 6. He is an active voice in the bug bounty community, a HackerOne Brand Ambassador, and co-captain of the Belgian team.

\n\n\n\'',NULL,1293976),('2_Friday','14','14:00','14:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Cryptohack Badge Hacking\'','\'Do Truong Giang \"FSNaix\",Sadiq \"Sdqmd\",Arjun \"Peper\" Suresh\'','Creator Talks_dabde17146c4de5d7bd03047acdc2b27','\'Title: Cryptohack Badge Hacking
\nTags: Cryptocurrency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

In this hour, we’ll guide you from setup to exploitation of a Cryptohack electronic badge. From installing the ESP-IDF toolchain, understanding application logic, compiling and disassembling firmware, we get familiar with the basics before considering the advanced aspects of financial technology in hardware. To explore the typical interfaces of a hardware wallet, we experiment with live hacks on a testnet wallet supporting Solana, Ethereum, Bitcoin, and Monero. By the end of the session, you’ll know how to probe the boundaries of hardware security and leave with insights you can apply to real-world offensive security challenges.

\n\nSpeakers:Do Truong Giang \"FSNaix\",Sadiq \"Sdqmd\",Arjun \"Peper\" Suresh
\n
\nSpeakerBio:  Do Truong Giang \"FSNaix\", BlossomsAI / Bloomify (AI & Security)
\n

I\'m Giang (FSNaix), an AI and security researcher from Vietnam and a Bloomify cofounder. I help build open-source Vietnamese language models with BlossomsAI, I built Petal (an AI tool that reverse-engineers binaries faster than doing it by hand), and at DEFCON Singapore 1 I managed to get DOOM running on a $20 conference badge.

\n\nSpeakerBio:  Sadiq \"Sdqmd\", CodeBit
\n

sdqmd (Sadiq) is a hardware hacker and co-founder of CodeBit, a technology company based in Brunei that\'s building a hardware engineering academy to teach embedded systems and security from the ground up. He is focused on developing a pedagogy that blends theory with hands-on practice, so aspiring hackers — especially those just starting out — don\'t just learn how something works; they build it, break it, and understand it for themselves. His own research focuses on hardware attacks against embedded devices — using fault injection and power analysis to defeat the security of everything from crypto hardware wallets to point-of-sale infrastructure. Above all, he\'s driven by one goal: building hardware and security competency in Brunei, where hands-on learning is still hard to come by.

\n\nSpeakerBio:  Arjun \"Peper\" Suresh, Postgraduate Student, University of Wollongong in Dubai
\n

Arjun Suresh is pursuing postgraduate studies in Cybersecurity at the University of Wollongong in Dubai, specializing in blockchain security, penetration testing, and applied cryptography. His interest in crypto security was shaped by analyzing major exchange breaches, including the Mt. Gox and Ronin Network hacks, where he studied the gap between attacker tradecraft and real-world defenses.

\n\n\n\'',NULL,1293977),('2_Friday','14','14:00','14:30','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'The Liability Stack: When Code Becomes Conduct\'','\'Carole House\'','Creator Talks_a87442aff6001ad364f9b0cd4b50806b','\'Title: The Liability Stack: When Code Becomes Conduct
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

The legal question of when publishing code creates responsibility for downstream harm has never been fully settled, but the practical separation between writing code and being treated as responsible for its downstream use is breaking down across AI, crypto, cybersecurity, and platform law. Courts and regulators are increasingly reaching contradictory conclusions about structurally similar systems: autonomous agents acting on third-party platforms, open-source developers accused of operating financial infrastructure, secure-by-design evolving into reasonable-care expectations, and recommendation systems reframed as product design rather than publication. This talk maps common doctrinal tension underneath those debates and argues that traditional legal categories fail when control, deployment, and operation are distributed across maintainers, deployers, validators, governance participants, and autonomous systems. Rather than focusing on labels like developer or platform, it proposes a functional framework centered on control, participation, foreseeability, and proximity to harm. The current incoherence is itself becoming a systemic risk, and the people building these systems should help shape the framework before courts finish improvising one for them.

\n\nSpeakerBio:  Carole House, Penumbra Strategies
\n

Carole House is a strategic technology executive who has spent her career focusing on leveraging innovative technologies to combat national security threats. She is the founder and CEO of a strategic technology and national security advisory practice, Penumbra Strategies, senior advisor to New Vista Capital, Member of the California Innovation Council, and serves as a Distinguished Senior Fellow at the Association for Certified Anti-Money Laundering Specialists (ACAMS) and a Senior Fellow at the Atlantic Council GeoEconomics Center. Carole recently served as the White House National Security Council (NSC) as Special Advisor for Cybersecurity and Critical Infrastructure and Director for Cybersecurity and Secure Digital Innovation. During her time at the White House, Carole architected two Executive Orders driving critical steps to promote innovation in cybersecurity, digital identity, artificial intelligence, and digital assets. Carole has held positions in venture capital and served on corporate and advisory boards for three financial regulatory agencies, three non-profits, and an AI and quantum security startup. Carole\'s prior government experience includes service as a U.S. Army Captain and across the White House, Senate Homeland Security Committee, and the U.S. Treasury.

\n\n\n\'',NULL,1293978),('2_Friday','14','14:15','14:45','N','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Scuttling Dashboards\'','\'Karan Sajnani\'','Creator Talks_37fdda7ec562cb60ca3893029a3172d1','\'Title: Scuttling Dashboards
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:15 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

The goldrush for maritime digitalization is riddled with safety concerns. Dashboards in the cloud stream vessel telemetry to shore-side consumers, and control planes from the cloud convey shore-side commands to shipboard IoT and OT systems. Systems of this nature involve an interaction between web applications, cloud, software defined networking systems, VPNs & OT systems, and are notoriously difficult to secure. This talk will showcase some of our research on these systems. From remote (over the internet) writes to propulsion / ballast systems, to turning a fleet of 300 ships into a botnet, we will discuss the possibilities of weaponization of maritime automation as demonstrated by first hand research.

\n\nSpeakerBio:  Karan Sajnani, Rudra
\n

Karan Sajnani is an entrepreneur and cybersecurity researcher, and the Founder and CEO of Rudra, a deep-tech firm building shipboard networking and security platforms deployed across more than 1,500 vessels globally. His work is grounded in hands-on vulnerability research, with multiple high-impact security disclosures across critical systems. Beyond maritime, his experience spans securing critical infrastructure in power and energy, RF systems, Telecom, as well as complex environments in financial services. Karan brings a practitioner’s perspective to cybersecurity, focused not on theory or compliance, but on real-world attack paths and engineering-driven defense.

\n\n\n\'',NULL,1293979),('2_Friday','14','14:30','14:59','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'ICSForge: (Open-Source) OT/ICS Security Coverage Validation Platform\'','\'Can Kurnaz\'','Creator Talks_af1a922593ecc186d89d284faea70c81','\'Title: ICSForge: (Open-Source) OT/ICS Security Coverage Validation Platform
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

ICSForge is an open-source OT/ICS Security Coverage Validation Platform designed to help defenders, SOC teams, and OT security engineers validate detection, visibility, and readiness against real-world industrial attack techniques.

\n\n

ICSForge is built to tackle a critical gap in OT/ICS security. It aims to solve a real problem “How do I safely validate OT security countermeasures from functionality, visibility and detection coverage perspective by using industrial traffic and MITRE ATT&CK® Matrix for ICS?” The goal is simple; make it easier to answer “Are we actually seeing, detecting, controlling and protecting what we think we are?”

\n\n

OT defenders have no practical and safe way to validate whether their network security monitoring sensors, firewalls, and segmentation controls actually detect and/or protect against real ICS attack techniques. By focusing on security coverage validation in industrial environments, the goal is to move beyond assumptions and provide measurable assurance for detection capabilities in critical infrastructure.

\n\n

ICSForge focuses on what can actually be observed on the network and generates realistic OT traffic and PCAPs (500+ scenarios) in 10 industrial protocols (Modbus/TCP, DNP3, S7comm, IEC-104, OPC UA, EtherNet/IP, BACnet/IP, MQTT, GOOSE, PROFINET DCP) which are aligned with 68 out of 83 unique techniques in MITRE ATT&CK for ICS v18 (82% coverage) -without exploiting real systems or causing unsafe process impact- to help asset owners and defenders assessing the quality of existing security countermeasures such as firewalls, OT NSM sensors and ACLs and identifying hidden gaps.

\n\n

Most OT/ICS security tools promise coverage, very few let you prove it.\nICSForge helps you answer questions like:\n- Can my Network Security Monitoring/IDS actually see Modbus manipulation attempts?\n- Which MITRE ATT&CK for ICS techniques are observable on the wire?\n- Do my detections fire when realistic OT traffic is sent?\n- Do my IT/OT firewalls or ACLs work as expected and blocks potentially harmful traffic?\n- What do I miss today, and why?

\n\n

ICSForge is developed with a safe-by-design approach, operating within a Sender-Receiver architecture and interacting only with the designated sender and receiver, without touching other OT devices.

\n\nSpeakerBio:  Can Kurnaz
\n

Can (pronounced as /dʒɑːn/ or John) works as an Industrial Control Systems (ICS) / Operational Technology (OT) Cybersecurity Specialist and has over a decade of professional experience in cybersecurity field, focused on OT/ICS Cyber Defense such as secure architecture development, OT/ICS monitoring, endpoint security platforms and vulnerability management.\nHe has offensive security background such as penetration testing, red teaming, OT/ICS site security assessments and also has experience in incident response and cybersecurity trainings (both hands-on and awareness).\nHis passion is protecting the critical infrastructure and production environments by providing technical knowledge on multiple cybersecurity domains which help for preparation, prevention, detection and response.\nCan has presented several times at leading cybersecurity conferences such as Black Hat, DEF CON and SANS Summits and he holds GRID, GICSP, OSCP, OSWP, ISA/IEC 62443 Expert (CFS, CRAS, CDS, CMS) certifications.

\n\n\nLinks:
    Intro Slide - https://www.icsforge.nl/ICSForge_Intro.pdf
\n    Project Website - https://www.icsforge.nl
\n\'',NULL,1293980),('2_Friday','15','15:45','16:30','N','Biohacking Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Snap, Crackle, Popped: How to manage a massive cyber attack \'','\'David Nathans\'','Creator Talks_d260b63b549ab3613c4d9a615bd97e35','\'Title: Snap, Crackle, Popped: How to manage a massive cyber attack
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:45 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

First hand account of the inner workings of a massive breach, what works what does not and where the wheels fall off the bus quick.

\n\nSpeakerBio:  David Nathans
\n

David Nathans is a senior cybersecurity executive and former U.S. Air Force cyber officer. He has served as a Global CISO in highly regulated industries and is an entrepreneur, author, and advisor focused on security operations, Zero Trust, and risk governance.

\n\n\n\'',NULL,1293981),('2_Friday','16','15:45','16:30','Y','Biohacking Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Snap, Crackle, Popped: How to manage a massive cyber attack \'','\'David Nathans\'','Creator Talks_d260b63b549ab3613c4d9a615bd97e35','\'\'',NULL,1293982),('2_Friday','14','14:45','15:15','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'SEND: Teaching Machines to Lie to Defenders\'','\'Yi Ting Shen,Ariz Soriano\'','Creator Talks_46221717d519897238e9634901f67467','\'Title: SEND: Teaching Machines to Lie to Defenders
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:45 - 15:15 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Cyber deception research has spent decades placing honeypots, honeyfiles, and fake credentials in enterprise environments to catch attackers. Yet practitioners in real Security Operations Centers do not investigate individual artifacts in isolation — they construct causal narratives to explain sequences of events, routing attention toward high-severity signals, end-of-attack-chain activities, and operations in sensitive infrastructure. As Sundaramurthy et al. documented through ethnographic study of live SOC environments, analyst behavior under alert overload is governed by triage heuristics and pattern-matching rather than systematic evidence review — creating a systematic cognitive attack surface that no existing offensive framework has been designed to exploit.

\n\n

In this work, we introduce SEND (Self-Evolving Narrative Deception), an adversary simulation framework that reframes offensive deception as an investigation narrative poisoning problem: the objective is not to evade detection, but to corrupt the causal story defenders reconstruct during incident response. Drawing on direct consultation with active SOC analysts and incident responders, we identify three empirically grounded cognitive attack vectors that structure the SEND action space — (a.) severity escalation exploitation, targeting the operational requirement to fully investigate HIGH/CRITICAL alerts regardless of underlying harm, (b.) end-of-chain activity simulation, targeting mandatory runbook escalation triggered by ransomware staging or exfiltration patterns regardless of actual file content, and (c.) sensitive location poisoning, targeting the elevated investigative attention guaranteed by activity near domain controllers, privileged shares, and executive endpoints.

\n\n

We present a design analysis showing that each attack vector can be instantiated at negligible red team cost — failed LSASS reads, dummy outbound transfers of random bytes, and mass-created ransomware-extension files are designed to generate the same mandatory investigation burden as their genuine counterparts, without requiring those actions to succeed. A key design distinction structures the SEND action space: activity simulation generates authentic system telemetry that defenders cannot distinguish from genuine attacker behavior at the telemetry level, while artifact implantation provides cross-system narrative coherence. A Narrative Consistency Engine coordinates both modalities using an LLM to ensure every fabricated email thread, file access log, and collaboration platform entry supports a single coherent false story — shifting the defender\'s task from \"did something anomalous happen?\" to \"which of several plausible explanations is true?\"\nMoreover, to enable rigorous evaluation of narrative deception beyond detection evasion metrics, we introduce the Investigation Narrative Divergence Reward (INDR) — a four-dimensional cognitive metric quantifying divergence across event reconstruction, causal graph structure, inferred attacker intent, and attribution outcome. INDR is designed to capture a class of deception success that existing red team metrics cannot measure: a defender may correctly identify every process in a malicious process tree yet still produce an incident report attributing the wrong objective, wrong actor, and wrong scope. We further formalize Investigation Graph Poisoning as a measurable attack surface, and outline experimental protocols for evaluating SEND across SOC environments of varying maturity, tooling, and analyst expertise.

\n\n

In conclusion, SEND establishes the incident investigation itself as a first-class attack surface in adversary simulation, derives deception strategy from empirically grounded blue team cognitive prioritization rather than intuition, and proposes INDR as a new evaluation metric for simulation fidelity — one that asks not whether a simulation triggered alerts, but whether it distorted the reasoning of the defenders who responded to them. Our framework operationalizes at a systematic level what nation-state actors have long practiced intuitively, and makes that threat model legible enough for both red teams and defenders to reason about and build against.

\n\nSpeakers:Yi Ting Shen,Ariz Soriano
\n
\nSpeakerBio:  Yi Ting Shen, AIFT - Associate GenAI Security Researcher
\n

I am currently working as a Associate Associate GenAI Security Researcher at AIFT. Over the past year, I have presented various cybersecurity-related research topics at more than 20 domestic and international conferences (DEFCON, ROOTCON, BSides..). I enjoy conducting research, especially focusing on AI/ML applications this year. By engaging with different technical domains, I aim to solve cybersecurity problems, uncover vulnerabilities across various platforms, and identify new CVE vulnerabilities. I have found vulnerabilities in multiple platforms, including Google, Cloudflare, open-source projects, and educational institutions. Learning and research have become the central focus of my life.

\n\n

Blog: https://no-flag.com/

\n\nSpeakerBio:  Ariz Soriano, Associate Director - Red Team Operations @ THEOS Cyber Solutions
\n

Ariz Soriano is Associate Director of Red Team at Theos, with nearly a decade of experience spanning Red Teaming, Penetration Testing, and Incident Response. He started his career on the defensive side, working as a SOC analyst and eventually leading SOC and IR teams for his first four years in the industry. That defensive foundation gives him a perspective most purely offensive operators don\'t have.

\n\n

He built the Theos Red Team from the ground up, recruiting and training operators, designing red team infrastructure and tooling, and establishing the methodology and playbooks behind the team\'s APT simulation and purple teaming engagements. Today he runs a practice that delivers multiple concurrent engagements a year, balancing operations with presales, scoping, revenue targets, and people management.

\n\n

Outside of client work, Ariz is passionate about building red team tooling, optimizing offensive workflows, and sharing knowledge with the community as a conference speaker. He also contributes to TryHackMe as a part-time Senior Content Engineer, creating hands-on cybersecurity labs and challenges based on real-world attack techniques.

\n\n\n\'',NULL,1293983),('2_Friday','15','14:45','15:15','Y','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'SEND: Teaching Machines to Lie to Defenders\'','\'Yi Ting Shen,Ariz Soriano\'','Creator Talks_46221717d519897238e9634901f67467','\'\'',NULL,1293984),('2_Friday','14','14:45','15:45','N','Game Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Your Lives are in Another Struct: Breaking Memory Hacks with Field Relocation\'','\'Ryan Zmuda\'','Creator Talks_11d6c67c5e97de46b37013d68d9dfc31','\'Title: Your Lives are in Another Struct: Breaking Memory Hacks with Field Relocation
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:45 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

This talk introduces a compile time anti-cheat for Unity that leverages data-oriented properties of the Unity DOTS stack to move attacker targeted data across struct boundaries. Through static lifetime analysis and eligibility proofs, HP, Score, Lives, and more can be scrambled across a game at build-time, deeply challenging a motivated attacker.

\n\nSpeakerBio:  Ryan Zmuda
\n

Ryan is an incoming PhD student at Dartmouth College studying binary security and privacy. He is a published researcher with a special interest in program analysis, vulnerability triage, CI/CD security, and anti-cheat. At the University of Dayton he founded and led the Game Development Club, where he ran numerous seminars and speaker interviews alongside building an arcade cabinet from scratch. His pride and joy is yoyoengine, a 2D game engine written in C that he\'s been developing for three years.

\n\n\n\'',NULL,1293985),('2_Friday','15','14:45','15:45','Y','Game Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Your Lives are in Another Struct: Breaking Memory Hacks with Field Relocation\'','\'Ryan Zmuda\'','Creator Talks_11d6c67c5e97de46b37013d68d9dfc31','\'\'',NULL,1293986),('2_Friday','15','15:00','15:30','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Cache Key Injection: Smuggling Poison Through the Door\'','\'Alex Brumen\'','Creator Talks_84cf0827315d7e94cc55883b3f65662b','\'Title: Cache Key Injection: Smuggling Poison Through the Door
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Cache poisoning research has long centred on unkeyed-input injection. The next cache poisoning vulnerability may not come from unkeyed input, but from what is mistakenly included in the cache key itself. This talk explores a lesser-known attack path: cache key injection caused by subtle cache misconfigurations that allow attacker-controlled values to influence keyed cache components. By triggering cache key injection, attackers can perform cache key collisions, leading to cache poisoning and impacts such as CPDoS, cache deception, and stored XSS through poisoned cache keys. I’ll show how these collisions can be identified, how they can be exploited to achieve impact, and the mitigations that can be implemented to prevent cache key injection.Cache poisoning research has long centred on unkeyed-input injection. The next cache poisoning vulnerability may not come from unkeyed input, but from what is mistakenly included in the cache key itself. This talk explores a lesser-known attack path: cache key injection caused by subtle cache misconfigurations that allow attacker-controlled values to influence keyed cache components. By triggering cache key injection, attackers can perform cache key collisions, leading to cache poisoning and impacts such as CPDoS, cache deception, and stored XSS through poisoned cache keys. I’ll show how these collisions can be identified, how they can be exploited to achieve impact, and the mitigations that can be implemented to prevent cache key injection.

\n\nSpeakerBio:  Alex Brumen, YesWeHack
\n

Alex Brumen (aka \"Brumens\") is a Security Research Enablement Analyst at YesWeHack, where his ethical hacking work focuses primarily on web applications. Outside of work, he is also a bug bounty hunter and developer.

\n\n\n\'',NULL,1293987),('2_Friday','15','15:00','15:30','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Drones, Detectors, and the Kill Chain\'','\'Greg Albrecht\'','Creator Talks_f91f8a6f3ab69bfda2a5e563df9ecd75','\'Title: Drones, Detectors, and the Kill Chain
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Counter-Unmanned Aircraft Systems (C-UAS) is a domain spanning RF engineering, federal law, operational security, and public policy, and it\'s being built right now by people working without a complete picture. Most security practitioners and nearly all civilians don\'t know how drone detection works, what the legal framework for defeating drones is, who\'s authorized to do what and why, or how badly the current technical stack can be defeated with a microcontroller. Drawing on direct operational experience at SEAR 1 National Special Security Events (the highest domestic security classification in the United States), this presentation walks through the complete C-UAS stack from first principles, grounded in real operational data rather than vendor marketing.

\n\nSpeakerBio:  Greg Albrecht
\nNo BIO available
\n\n\'',NULL,1293988),('2_Friday','16','16:30','17:15','N','Biohacking Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Lights Out and Last Call: A Drunken Tabletop on Medical Device Resilience\'','\'Courtney McCarty\'','Creator Talks_c4a362fca4f754346256dd198f371176','\'Title: Lights Out and Last Call: A Drunken Tabletop on Medical Device Resilience
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:30 - 17:15 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\nHealthcare cyber exercises often end at compromise: ransomware lands, systems fail, and the red team wins. Yay (eyeroll). Real hospitals don\'t stop there; patients still need scans, medications still need to be delivered, and clinicians still need to make decisions after access disappears.
\n\n

Lights Out, Last Call is a highly immersive and conversational \"\"Drunken Tabletop\"\" experience where participants become a hospital\'s clinical resilience team immediately following a catastrophic network downtime event impacting connected medical devices. There is no audience. There are only participants. While sipping cocktails and responding to evolving scenario injects, attendees will navigate the uncomfortable reality of healthcare operations and executive decisions after digital access breaks down.

\n\n

Participants may suddenly lose nuclear medicine imaging, discover vendor firmware dependencies, face impossible prioritization choices, reroute patients across hospitals, and debate whether AI-generated remediation recommendations should be trusted during a crisis.

\n\n

Through collaborative play, this exercise explores a serious question hidden inside a chaotic environment: when hospitals lose access, who still gets care, who decides, and who gets left behind?

\n\n

The session combines cybersecurity, medical device resilience, supply chain dependencies, and operational continuity into a social experiment designed to transform healthcare chaos into practical lessons.

\n\n

Come for the cocktails, stay because your nuc med cameras went offline.

\n\nSpeakerBio:  Courtney McCarty
\n

Courtney McCarty spends her days keeping healthcare technology from descending into chaos, focusing on organizational resilience. By night, she trades tinfoil hats for cocktail shakers and turns controlled chaos into memorable experiences at her cocktail lounge, NITRO, in Madison, WI.

\n\n\n\'',NULL,1293989),('2_Friday','17','16:30','17:15','Y','Biohacking Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Lights Out and Last Call: A Drunken Tabletop on Medical Device Resilience\'','\'Courtney McCarty\'','Creator Talks_c4a362fca4f754346256dd198f371176','\'\'',NULL,1293990),('2_Friday','15','15:00','15:30','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'OT Segmentation Under Operational Constraints\'','\'Tony Turner\'','Creator Talks_0668761455f5bafd930ab04fe84cc180','\'Title: OT Segmentation Under Operational Constraints
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

OT network segmentation projects rarely fail because of missing firewall features or lack of security tooling. They fail because industrial environments operate under constraints that traditional IT security programs do not fully account for: limited maintenance windows, fragile legacy systems, vendor-controlled architectures, operational distrust of change, and the reality that reliability and uptime often outweigh security priorities during production events.

\n\n

This presentation focuses on the operational side of OT segmentation: how industrial organizations actually plan, prioritize, communicate, implement, and sustain segmentation initiatives in production environments. Rather than treating segmentation purely as a technical firewall exercise, the session examines segmentation as an operational optimization problem balancing security risk, operational disruption, safety requirements, maintenance constraints, compliance pressure, and organizational ownership.\nTopics discussed include:

\n\n

Phased rollout strategies and pilot deployments\nChange validation and rollback planning\nSegmentation drift and long-term erosion of controls\nVendor and integrator access throughout project lifecycles\nOperational trust-building through monitor-first deployments and packet-capture-driven validation

\n\n

We will explore why many environments gradually return to flat networks despite significant investment in segmentation initiatives. Real-world examples from utility and critical infrastructure environments will demonstrate how operational realities, maintenance pressure, and organizational ownership challenges frequently undermine otherwise well-designed security architectures.

\n\n

Attendees will leave with practical guidance for approaching OT segmentation as an operational change-management problem rather than simply a firewall deployment exercise, along with implementation patterns that improve security posture without creating unnecessary operational disruption.

\n\nSpeakerBio:  Tony Turner
\n

Tony is a security architect with over 30 years of experience across IT and operational technology (OT) environments. As VP of Product at Frenos, he leads the development of a simulated OT penetration testing platform that uses digital twin modeling and adversary-driven analysis to evaluate real-world risk in industrial systems.

\n\n

His background is grounded in decades as an asset owner, including critical infrastructure protection at a major U.S. airport, incident command for state public health systems, disaster recovery engineering for hurricane response, and security programs across electric power and global semiconductor manufacturing. This operational experience informs a practical, systems-driven approach to cybersecurity that prioritizes real impact over theoretical risk.

\n\n

Tony’s work focuses on how attackers actually operate in complex environments, spanning network reachability, adversary actions, supply chain risk, and software provenance. He is the author of Software Transparency and creator of the SANS SEC547 course Defending Product Supply Chains. He has presented at S4 Conference and other industry forums on topics including threat modeling with BOMs and the real-world effectiveness of industrial firewall DPI.

\n\n

He actively contributes to research efforts with organizations such as MITRE, Idaho National Laboratory, CISA, and ISA, particularly in advancing Cyber Informed Engineering (CIE). He also leads defendics.org, a nonprofit focused on improving foundational OT security practices for resource-constrained asset owners.

\n\n\n\'',NULL,1293991),('2_Friday','15','15:15','15:45','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Hey Adversary, I’ve Got a Human EDR Bypass for You…\'','\'Daniel Isler\'','Creator Talks_757943fabad297b6f48436e2a5f4c8cf','\'Title: Hey Adversary, I’ve Got a Human EDR Bypass for You…
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:15 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\nSubtitle: The Scout\'s Field Guide to human risk telemetry: Weaponizing complacent corporate conditioning, tracking the legacy Human EDR, and surviving the wilderness.
\n\n

Enterprise security leadership is currently suffering from a dangerous cognitive bias: confusing compliance with operational resilience. When an organization achieves a \"1.5% phishing click-rate,\" the board celebrates under the illusion that their perimeter is secure. But to an advanced adversary, that dashboard isn\'t a shield it’s a deterministic roadmap of the target’s behavioral heuristics.

\n\n

Framed as a retro-futuristic, illustrated Scout\'s Field Guide, this talk exposes how advanced Red Teams and APT actors reverse-engineer corporate human risk telemetry to achieve rapid initial access without advanced code. We will dissect how standardized training inadvertently programs a rigid \"Human EDR\" based on static signatures, and how operators can fly beneath the radar by simply omitting what the user has been conditioned to look for.

\n\n

Furthermore, we will unlock a highly unique, unexplored exploitation vector: Behavioral Inheritance (The Legacy Human EDR). Attendees will learn how to conduct passive OSINT on a high-value target’s professional history to predict their automated reactions, weaponizing the cognitive conditioning they inherited from their previous employers to bypass structural controls during their onboarding window.

\n\n

Instead of chasing compliance or deploying new tools, this presentation concludes by turning offensive telemetry into zero-cost tactical defense. We will demonstrate how to evolve from static detection to pure behavioral resilience by implementing \"Interrupt Protocols\" to break an attacker\'s live performance, and adopting a \"No-Fault Reporting\" culture to drastically reduce adversary dwell time. We are unifying Red Team tradecraft with existing human telemetry to survive the corporate wilderness using the adversary\'s own playbook against them.

\n\nSpeakerBio:  Daniel Isler, Awareness & Social Engineering Consultant - Team Leader - SEK
\n

Daniel Isler, holds a Bachelor\'s degree in Performing Arts, weaponizing his background in theatrical representation, pretexting, and human behavior to reverse-engineer corporate conditioning. Active in the offensive security field since 2015, he serves as the Team Leader of Fr1endly RATs, the specialized social engineering and initial access for Red Team unit at SEK. Certified in OSINT, Red Team, and Social Engineering, he has spent nearly a decade architecting both high-fidelity tactical intrusions and enterprise Awareness service lines. His unique approach relies on a multidisciplinary, highly creative team of elite operators who strictly design and deliver educational content based on the advanced threat techniques they actively execute in the field.

\n\n\n\'',NULL,1293992),('2_Friday','15','15:30','15:59','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Forensics of Covert Entry\'','\'Bill Graydon,Bobby Graydon\'','Creator Talks_3a0ebc5b1445f88fc8cd4f8580e4d4b2','\'Title: Forensics of Covert Entry
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

You know lockpicking. You know lock bypass. You might know evasion tactics for alarms and surveillance systems. But what traces get left behind if an attacker does these? This talk will give an introduction to the forensics of covert entry techniques - what marks get left behind, how to tell whether someone entered, when it happened, what tactics and tools were used, and what skill level the attacker had. Taught by two founding members of the Physical Security Village, this talk will also show the interesting and funny results when certain entry techniques are applied thousands of times on one door, which will tune your eye for spotting when it’s only happened once.

\n\nSpeakers:Bill Graydon,Bobby Graydon
\n
\nSpeakerBio:  Bill Graydon, GGR Security
\n

Bill Graydon is a Principal at GGR Security, where he designs and evaluates security systems and building construction for a wide range of industries - including testing them on physical pen tests. Through this, he hacks everything from locks and alarms to critical infrastructure; this has given him some very fine-tuned skills for breaking stuff. He’s passionate about advancing the security field through research, teaching numerous courses, giving talks, and running DEF CON’s Lock Bypass Village. He’s received various degrees in computer engineering, security, and forensics and comes from a broad background of work experience in cyber security, anti-money laundering, and infectious disease detection.

\n\nSpeakerBio:  Bobby Graydon
\n

Robert is an avid researcher of lock manipulation, picking, bypass, and other vulnerabilities to discover and evaluate possible flaws and methods of attack. He has a passion not only for hacking, but teaching as well, being one of the founders of Physical Security Village, and enjoys speaking at various physec engagements. He has well-honed skills, as well as a thorough understanding of the mechanics and function of many types of high security locks, allowing him to effectively search for and test methods of cracking high security systems.

\n\n\n\'',NULL,1293993),('3_Saturday','14','14:30','14:59','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Hacking AFDX or Not; A Primer for Flight Control Systems Security\'','\'Andrew Tierney,Adam Bromiley\'','Creator Talks_b612422faedefcdc03a82c0ece214ecd','\'Title: Hacking AFDX or Not; A Primer for Flight Control Systems Security
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

One of the challenges of independent airplane cyber research is the lack of availability of recent hardware; avionics, LRUs and anything from the aircraft control domain is insanely expensive, even when used. Access to retired airframes therefore represents the state of the art from 20+ years ago. We have been stuck with researching older ACD protocols such as ARINC 429 and 629. However, through a fortuitous stroke of luck, we were given access to an ARINC 664 or ‘AFDX’ environment on a test bench recently. The protocol was developed by Airbus for the A380, but is also found on the B787, A350 and is increasingly being implemented on new designs. Avionics Full-Duplex Switched Ethernet / ADFX will be much more familiar to IT folks than the earlier protocols, having much more in common with the OSI reference model. But, it has crucial differences which requires a steep learning curve. This talk is a primer for interfacing with AFDX and the various security and safety features that it offers.

\n\nSpeakers:Andrew Tierney,Adam Bromiley
\n
\nSpeakerBio:  Andrew Tierney
\nNo BIO available
\nSpeakerBio:  Adam Bromiley, Pen Test Partners
\n

Adam is a security consultant at Pen Test Partners who specialises in industrial\ncontrol systems and embedded hardware security. He's worked on everything safety-critical:\nfrom high-speed rail to aircraft, power stations, and gas distribution. His embedded work has\nseen him break driverless cars, slot machines, and drones and has led to the responsible

\n\n

disclosure of numerous vulnerabilities in industrial controllers. Adam enjoys hands-on and\nboots-on-the-ground testing, reverse engineering, and providing practical security advice for\ncomplex real-world systems.

\n\n\n\'',NULL,1293994),('2_Friday','15','15:30','15:59','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Hunting for Cryptographic Ghosts: A Bug Hunter’s Guide to Signature Malleability and Replay Attacks in EVM Bridges & Multi-Sigs\'','\'Samet Berk Simsek,Ahmet Furkan Aydogan\'','Creator Talks_2251a50346562f715f8e905751e98b9f','\'Title: Hunting for Cryptographic Ghosts: A Bug Hunter’s Guide to Signature Malleability and Replay Attacks in EVM Bridges & Multi-Sigs
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

In the realm of Web3 bug bounties, smart contract logical flaws are highly sought after, but the most devastating, seven-figure bounties often lie within fundamental cryptographic implementation errors. Specifically, ECDSA signature malleability and faulty multi-signature threshold state management are responsible for the biggest bridge drains in history. Yet, many traditional bug bounty hunters steer clear due to the perceived mathematical complexity.\nThis presentation demystifies these high-value bug classes. We will break down exactly how the EVM processes cryptographic signatures (ecrecover), how the mathematical symmetry of elliptic curves allows a single valid signature to be altered into a second, legally distinct signature, and how this can be weaponized to bypass multi-signature validation logic. Attendees will walk away with an actionable, repeatable hunting methodology, custom scripts to automate signature vulnerability testing, and real-world case studies of massive payouts achieved without looking at single line of standard frontend code.

\n\nSpeakers:Samet Berk Simsek,Ahmet Furkan Aydogan
\n
\nSpeakerBio:  Samet Berk Simsek
\n

Samet Berk Şimşek is a Turknet Cyber Security Specialist & Web3 Developer

\n\nSpeakerBio:  Ahmet Furkan Aydogan
\n

Ahmet Furkan Aydogan is a Tenure-Track Assistant Professor in the Computer Science Department at the University of North Carolina Wilmington (UNCW). He earned his Ph.D. in Digital and Cyber Forensics Science from Sam Houston State University (SHSU) in 2024, with a focus on Cyber Security, Cryptology, Machine Learning, IoT, and Human-Computer Interaction. His research includes a Brain Frequency-Based Evolutionary Encryption Method for IoT Devices. Ahmet has received multiple awards and has published widely in the fields of cybersecurity and digital forensics.

\n\n\n\'',NULL,1293995),('2_Friday','15','15:30','16:30','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Privacy\'s Defender: How Hackers Protected the Internet Before and Can Do It Again\'','\'Cindy Cohn\'','Creator Talks_ba252840af25de3f8245fb6f0065e614','\'Title: Privacy\'s Defender: How Hackers Protected the Internet Before and Can Do It Again
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

EFF\'s Outgoing Executive Director Cindy Cohn\' presents her first-person stories from her recently published book, Privacy\'s Defender, that take you Inside the privacy battles that have shaped today\'s Internet. It includes the hackers who helped free up encryption technology from US governmental control, allowing us to have the still imperfect privacy and security we now have online, and the battles to stop the mass NSA spying and eternal gag orders that arose from the governments formerly secret mass spying programs in the aftermath of the 9/11 attacks. She then draws from that long career of legal activism to the fights of today and tomorrow, featuring the role that hackers can play in helping to bring about a better, more just future.

\n\nSpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation
\n

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy\'s Defender published by MIT Press in March, 2026. She is also the co-host of EFF\'s award-winning podcast, How to Fix the Internet.

\n\n

--

\n\n

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.

\n\n\n\'',NULL,1293996),('2_Friday','16','15:30','16:30','Y','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Privacy\'s Defender: How Hackers Protected the Internet Before and Can Do It Again\'','\'Cindy Cohn\'','Creator Talks_ba252840af25de3f8245fb6f0065e614','\'\'',NULL,1293997),('2_Friday','16','16:00','16:30','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'The Door Was Already Open\'','\'Champ\'','Creator Talks_d0b3cda8645baaa15b5852c273b813c4','\'Title: The Door Was Already Open
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Physical access control systems are often assumed to be secure, but many rely on flawed design assumptions, and can contain misconfigurations. This talk examines a widely deployed platform, where internet-exposed panels, numeric-only passcodes, and predictable communication patterns enable remote discovery and access at mass scale. With no rate limiting or lockout protections, authentication can be automated, often succeeding due to default credentials, or an easily guessed combination. Successful access exposes sensitive data, including resident information, credentials, and access history. It also allows for complete remote control of the access control system. This talk focuses on how architectural decisions — not just bugs — can create systemic vulnerabilities in real-world security systems. Come on in, The Door Was Already Open.

\n\nSpeakerBio:  Champ
\n

Hello!! I am a Canadian Physical Security Consultant, who loves finding a new way to pop a door.

\n\n\n\'',NULL,1293998),('2_Friday','16','16:30','16:59','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Legally Hacked: how countries decide when security research Is allowed\'','\'Katharina \"Kat S\" Sommer\'','Creator Talks_3014c93191428eccf48ad92261cbddb0','\'Title: Legally Hacked: how countries decide when security research Is allowed
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

As governments increasingly rely on vulnerability disclosure to secure digital systems, many security researchers still operate under cybercrime laws that criminalise the very activity those frameworks depend on. This talk offers a fast‑paced, global comparison of how different countries are addressing that paradox. Drawing on recent reforms and live policy debates, it introduces a practical taxonomy of legal protection models—from statutory defences to prosecutorial guidance and vulnerability disclosure policies as authorisation—and examines their real‑world implications for researchers. The session concludes with a concise “Minimum Viable Safe Harbour” checklist, highlighting the core principles needed to protect good‑faith security research while preventing abuse.

\n\nSpeakerBio:  Katharina \"Kat S\" Sommer, NCC Group
\n

Kat is a seasoned policy and strategy leader with over 15 years of experience spanning political institutions, consultancy, and corporate roles. At NCC Group, she has built and scaled the Government Affairs and Analyst Relations functions, embedding them as strategic enablers of the company’s mission to create a more secure digital future. Her work has shaped cyber policy debates across the UK, EU, and globally—most notably through her leadership in the CyberUp Campaign and contributions to initiatives such as the UN’s Cybercrime Convention and the UK-France Pall Mall Process. Kat is a passionate advocate for cyber resilience, known for her ability to convene diverse stakeholders, drive regulatory engagement, and deliver tangible business outcomes. She holds a Master’s in Public Affairs & Lobbying from Brunel University and a Bachelor’s in Public Administration with a focus on European Studies. Outside of work, she is a 4th Dan black belt in Tae Kwon Do.

\n\n\n\'',NULL,1293999),('2_Friday','17','17:00','17:30','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Lessons Learned from Poland and Beyond: The State of Electric Sector Attacks in 2025\'','\'Joe Slowik\'','Creator Talks_f5cce280e3484a2db0b751af963912fa','\'Title: Lessons Learned from Poland and Beyond: The State of Electric Sector Attacks in 2025
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

2026 featured news of a new attempted, disruptive cyber attack against the electric sector. Instead of transmission or distribution in Ukraine, however, the event focused on generating assets in Poland. Irrespective of impact, the very fact such an action was attempted is concerning and newsworthy. However, the details of the event demonstrate the state of the \"now\" for electric sector events, in terms of their successes as well as failures.

\n\n

In this discussion we will leverage all available public reporting to look at where the attackers innovated, borrowed from past events, and failed to learn from history in the December 2025 Polish event. From this discussion we will set the incident in context of both concurrent intrusions, such as Volt Typhoon activity, and historical incidents, linked to the Sandworm threat actor, to see just where adversaries are today with respect to tradecraft and sector knowledge.

\n\n

From this exploration, attendees will emerge with a better understanding of what adversaries are \"getting right\" about such events, and where they still fall short. Furthermore, review of events will show the significance of physical safeguards and controls in ensuring continuous operations in the face of cyber effects, and how adversaries remain challenged to overcome such barriers.

\n\nSpeakerBio:  Joe Slowik, Dataminr
\n

Joe Slowik has over 15 years of experience across multiple cyber domains, ranging from offensive operations through incident response to threat intelligence and research. Currently, Joe serves as director of cybersecurity alerting strategy at Dataminr, but has previously held various roles at organizations such as Huntress, DomainTools, the MITRE Corporation, and Los Alamos National Laboratory.

\n\n\n\'',NULL,1294000),('2_Friday','17','17:30','17:59','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Exposed Data Centers: Bypass IT Security, Crank Up the Heat\'','\'Stephen Hilt,Numaan Huq\'','Creator Talks_21b3a76b7adf8db9c7d4cebb02199c75','\'Title: Exposed Data Centers: Bypass IT Security, Crank Up the Heat
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

As data center numbers are increasing in the US and around the world, they are becoming a source of tension politically, environmentally, and economically, and are becoming high-value critical infrastructure. The threats to these data centers will rise soon as activists, cybercriminals, and nation-states target them. Unlike what has been seen recently with kinetic attacks on data centers in conflict zones, cyberattacks have a larger range and can affect a wider population.

\n\n

We wanted to explore unconventional threats against data centers. Using open-source intelligence and our patented (US12267344B1) geostalking techniques, we were able to map out data centers in the United States and overlay that with the exposed infrastructure that would directly be used in the operation of the data center itself. This includes building automation and energy supply as examples.

\n\n

Afterwards, we were left with the locations of 1,063 data centers that had 6,300 high-confidence industrial control systems exposed to the internet. This information went through a five-layer filtering process to result in these high-confidence exposed systems, based on the banner responses received from these devices. Of these 6,300 devices, 964 devices (15.3%) have a CVSS score of 9.0 or above, and 88.7% of the entire dataset is inherently vulnerable due to the use of protocols that were never designed to be exposed to the internet.

\n\n

Armed with this information, an attacker could circumvent even the best IT security with exposed systems that might directly or indirectly affect data center operations. In today’s geopolitical climate, exposed systems in near proximity to data centers are at higher risk of cyberattacks. Due to diverse applications across personal, corporate, or even government use, the repercussions of a data center outage will have effects far wider than just the data center itself.

\n\nSpeakers:Stephen Hilt,Numaan Huq
\n
\nSpeakerBio:  Stephen Hilt
\n

Stephen J. Hilt is a seasoned threat researcher specializing in industrial control systems (ICS) security, cybercrime investigations, and advanced persistent threats. With extensive experience in uncovering complex attacks targeting critical infrastructure, he has contributed to numerous high-impact reports and global threat intelligence initiatives. Stephen’s work bridges deep technical expertise with strategic analysis, enabling organizations to better understand and defend against emerging cyber threats. His research has been presented at leading security conferences and published in widely respected industry reports, reflecting his commitment to advancing the security of interconnected systems worldwide.

\n\nSpeakerBio:  Numaan Huq
\nNo BIO available
\n\n\'',NULL,1294001),('2_Friday','17','17:30','17:59','N','Biohacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Hacking Hearts by Reverse Engineering Pacemaker Firmware\'','\'Marie Moe,Shayan Alinejad,Kristian Karlsen\'','Creator Talks_1872c19c52afbb35f499182782ce083f','\'Title: Hacking Hearts by Reverse Engineering Pacemaker Firmware
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Gradually we are all becoming more and more dependent on connected technology. We will be able to live longer with an increased quality of life due to medical devices and sensors attached to, or integrated into our bodies. However, our dependence on technology grows faster than our ability to secure it, and a security failure of a medical device may cause patient harm and have fatal consequences.

\n\n

This presentation dives into the security architecture of the Biotronik pacemaker ecosystem, covering the pacemaker, home monitoring units, and external programmer. Using a hybrid of black-box and white-box methodologies, we deconstruct the firmware and wireless communication protocols to identify vulnerabilities in a pacemaker that one of the presenters was depending on with their life for 11 years. We will discuss the challenges of extracting firmware from life-critical hardware and the implications of discovered bugs on patient safety. Attendees will leave with a better understanding of how to reverse engineer proprietary medical ecosystems and why securing the \"Internet of Medical Things\" is a race we cannot afford to lose.

\n\nSpeakers:Marie Moe,Shayan Alinejad,Kristian Karlsen
\n
\nSpeakerBio:  Marie Moe
\n

Dr. Marie Moe is a Principal Consultant at Mandiant (now part of Google Cloud), and has a PhD in information security. She is a part-time Associate Professor at NTNU. In this talk she will be joined by NTNU MSc students Shayan Alinejad and Kristian Karlsen.

\n\nSpeakerBio:  Shayan Alinejad
\nNo BIO available
\nSpeakerBio:  Kristian Karlsen
\nNo BIO available
\n\n\'',NULL,1294002),('3_Saturday','10','10:00','10:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'A Droidwork Orange: A Longitudinal Study of Android Security Research\'','\'Nicholas Miazzo,Eleonora Losiouk\'','Creator Talks_30555f5a6fecd783bb92cd8f714d18e9','\'Title: A Droidwork Orange: A Longitudinal Study of Android Security Research
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\nCommunity Presentation Proposal Title: A Droidwork Orange: A Longitudinal Study of Android Security Research Samuele Doria (University of Padua), Nicholas Miazzo (University of Padova), Tiziano Labruna (Fondazione Bruno Kessler), Eleonora Losiouk (University of Padua) Abstract Android has been the dominant mobile platform for over a decade, but we still lack an understanding of how Android security research has evolved, which problems have received sustained attention, and whether the recent drop in publication volume reflects exhaustion or maturity. This paper presents the first comprehensive longitudinal study of the Android security research ecosystem. We built Ludovico, a curated corpus of 11,691 Android security papers published between 2008 and 2025, complemented by 464 iOS papers and a survey of 86 active researchers. By combining iterative topic modeling with manual validation, analysis of authors’ affiliations and publication venues, and extraction of targeted Android versions, we studied the evolution of topics, contributors, publication venues, and the interplay between platform changes and research priorities. Our results show that the field grew rapidly until a 2016-2018 peak and then contracted, but not because Android security is considered solved: the ecosystem has matured, and advancing the state of the art requires specialized, low-level expertise. We observe a structural transition from App Privacy & Security to Malware Detection, which has dominated the literature since 2017. This is also motivated by the adoption of AI-based techniques: 57.4% of papers focusing on malware
\n\n\n\nSpeakers:Nicholas Miazzo,Eleonora Losiouk
\n
\nSpeakerBio:  Nicholas Miazzo, University of Padova
\n

yearly output. We further find that iOS research is more focused on digital forensics, revealing how platform openness shapes research trajectories. Finally, 73.26% of surveyed researchers confirm a real-world impact of Android security research, while highlighting platform hardening, limited access to updated datasets, and funding constraints as the main barriers ahead. Brief Biography Nicholas Miazzo is a Ph.D. student in computer science at the University of Padua, where he completed his master\'s degree in 2024. His research now focuses on Android security, particularly leveraging Large Language Model agents to analyze decompiled Android applications and perform taint analysis to automatically detect potential data leakage. He is also a co-author of VirtualPatch [1], a system that uses Android virtualization to deploy security patches independently of device vendors. He is currently contributing to its

\n\nSpeakerBio:  Eleonora Losiouk, University of Padua
\nNo BIO available
\n\n\'',NULL,1294003),('3_Saturday','10','10:00','10:30','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'MCPwned: How Exposed AI Agents Became the Internet’s New Recon Toy\'','\'Eli Woodward\'','Creator Talks_3b25aa200a5d780a234a2f0afd6ea4cc','\'Title: MCPwned: How Exposed AI Agents Became the Internet’s New Recon Toy
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

This talk examines how exposed AI infrastructure is becoming a new adversary playground, as attackers and internet-scale scanners and bruteforcing target LLM gateways, MCP servers, local inference APIs, and AI developer tooling faster than defenders have built threat models for them.

\n\n

I ran a purpose-built AI honeypot that simulated 16 LLM and AI infrastructure personas across 16 ports, returning framework-authentic responses, headers, errors, and protocol behaviors. In one 48 hour window, the system captured 3,993 requests from 327 unique source IPs, including 155 MCP probes and 344 AI API key probes. What emerged was not generic internet noise, but a repeatable playbook against the emerging AI stack: LiteLLM model-registration abuse, MCP resource enumeration, framework-aware credential brute forcing, and coordinated scanning for exposed local inference services.

\n\nSpeakerBio:  Eli Woodward, Senior Threat Intelligence Advisor with Team Cymru
\n

Eli Woodward is a cyber threat intelligence advisor with Team Cymru. He\'s worked in a variety of industries including financial services and government, and has seen the range of organizations from extremely well-resourced and capable to the shoestring budget. This has given him unique insights into CTI at all levels of complexity, maturity, and resources. He holds a master\'s degree in Intelligence and Security Studies and also plays bagpipes competitively.

\n\n\n\'',NULL,1294004),('3_Saturday','10','10:00','10:45','N','Game Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'RIP Denuvo: DRM in a Post-Hypervisor World\'','\'Amin Hussien\'','Creator Talks_9032d509af8e308cf462f1154256a86d','\'Title: RIP Denuvo: DRM in a Post-Hypervisor World
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

For a decade, Denuvo stood as the gold standard of game DRM. That reign has come to an abrupt end. Thanks to the advent of Hypervisor bypasses, games are now being cracked in a matter of hours rather than months. How did we get here, and what does the future hold for game DRM?

\n\nSpeakerBio:  Amin Hussien
\n

Amin Hussien is the co-creator of the Illusory Unreal Engine game modding community (https://illusory.dev/) and has previously worked as an anti-cheat developer at [Redacted].

\n\n\n\'',NULL,1294005),('3_Saturday','10','10:00','10:30','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Shadow Webhooks: Hunting for Dangling Event Listeners in Enterprise Workspaces\'','\'Samet Can Tasci,Mehmet Önder Key\'','Creator Talks_b24aa4b67a5ee234ce73ec2f97fdb4ab','\'Title: Shadow Webhooks: Hunting for Dangling Event Listeners in Enterprise Workspaces
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Enterprise SaaS environments accumulate webhooks faster than teams can track them. Slack apps, Teams connectors, Jira automations, GitHub webhooks, CI/CD callbacks, monitoring alerts, and abandoned integrations often remain active long after the receiving service, repository, domain, or owner disappears. These forgotten event listeners can become quiet security liabilities: they may leak event payloads, accept forged messages, expose secrets in callback URLs, or create takeover paths when linked infrastructure expires. This talk presents a practical bug bounty methodology for finding and reporting “shadow webhooks”: trusted event connections that still exist inside an enterprise workspace but no longer have a clear owner, valid destination, or reliable validation model. I will cover how to inventory webhook surfaces, classify destination risk, fingerprint abandoned endpoints, identify dangling domains or retired cloud functions, test signing and replay behavior safely, and prove impact without collecting real third-party data. The demo uses a controlled lab that models common workflows across source control, ticketing, chat, and CI/CD systems. One webhook points to a retired destination. Another accepts events without strong signature validation. The audience will see how synthetic project events and incident notifications can reach the wrong endpoint, how weak validation allows forged events, and how the issue should be documented for a bounty program. The talk also covers what makes a webhook finding triageable: affected asset, trusted event source, destination ownership, payload sensitivity, validation weakness, and business impact. For defenders and program owners, it provides controls for webhook inventory, owner mapping, event signing, secret rotation, endpoint expiration, and domain lifecycle monitoring. The goal is to turn forgotten webhook exposure from a vague SaaS hygiene issue into a clear, reproducible bug bounty finding.

\n\nSpeakers:Samet Can Tasci,Mehmet Önder Key
\n
\nSpeakerBio:  Samet Can Tasci, Senior Linux Systems Engineer
\n

Samet Can Tasci is a Senior Linux Systems Engineer and security researcher with experience across enterprise infrastructure, cloud and hybrid environments, automation, and defensive security validation.

\n\n

His research interests include web defense behavior, WAF normalization gaps, parser inconsistencies, adversary-informed testing, and practical tooling for security teams.

\n\n

He is the creator of WaffleX, a research prototype selected for Black Hat USA Arsenal, which focuses on semantic consistency analysis, enforcement drift, and family-level request-variant testing across modern web application defense stacks.

\n\nSpeakerBio:  Mehmet Önder Key, Cyber Security Consultant
\n

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.

\n\n\n\'',NULL,1294006),('3_Saturday','10','10:00','10:30','N','Biohacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'To Catch a Pseudoscientist\'','\'James Utley PhD\'','Creator Talks_c080344842cafe345c4ab09c8f635205','\'Title: To Catch a Pseudoscientist
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

This talk exposes the hidden fraud ecosystem inside modern scientific research, where paywalls, paper mills, predatory journals, and fake credentials create the illusion of legitimacy. Drawing from a hacker’s perspective, it examines how corruption is embedded in the system, how some actors knowingly participate while others are trapped by it, and how weak or fabricated work can be elevated as credible science. The session offers a practical playbook for identifying red flags, avoiding fraudulent channels, and protecting yourself from the pipeline where fake journals produce fake science.

\n\nSpeakerBio:  James Utley PhD
\n

Dr. James Utley, PhD is a board-certified anti-aging scientist and immunohematology expert advancing AI, regenerative medicine, and cellular reprogramming. As CSO at Auragens, he develops stem cell therapeutics, translating molecular science into clinical strategies to extend healthspan.

\n\n\n\'',NULL,1294007),('3_Saturday','10','10:00','10:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Web3 Security: Hacks, Scams, and Exploits\'','\'Philip \"AlephNull\" Werlau,Kennashka DeSilva\'','Creator Talks_8f226d9b89e373e172a7ac44a89345f6','\'Title: Web3 Security: Hacks, Scams, and Exploits
\nTags: Cryptocurrency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Why do Web3 users keep getting hacked even when the smart contracts are audited? This workshop examines the Web3 attack surface through three lenses: the client, the dApp frontend, and the blockchain, using real-world hacks, scams, and exploits to demonstrate how each layer can fail. Participants will conduct a live review of their own wallet approvals using revoke.cash and learn practical techniques for reducing risk. The workshop concludes with a forensic deep dive into the $1.5 billion Bybit hack, where attendees will analyze the malicious transaction, compromised frontend, and on-chain evidence that enabled the largest cryptocurrency theft in history.

\n\nSpeakers:Philip \"AlephNull\" Werlau,Kennashka DeSilva
\n
\nSpeakerBio:  Philip \"AlephNull\" Werlau, Founder at Flowstate Cyber
\n

Philip is a cryptocurrency investigator and smart contract analyst specializing in DeFi, on-chain forensics, and blockchain security. Experienced in support of government agencies and private-sector clients in cryptocurrency fraud investigations, exploit analysis, fund tracing, and smart contract risk analysis, Philip’s extensive familiarity with EVM ecosystems, blockchain analytics, and custom investigative tooling contributes to his work in government and industry.

\n\nSpeakerBio:  Kennashka DeSilva
\n

Kennashka DeSilva is a seasoned cybersecurity researcher with a strong track record of advancing security best practices in decentralized systems. She was a featured speaker at DEF CON 30’s “Hacking & Defending Blockchain Applications” session, where she helped bridge the gap between traditional application security frameworks—such as the OWASP Top Ten—and the unique risks found in DEFI and smart contract ecosystems. Kennashka is also an active participant in the cybersecurity community, having contributed to multiple HackMiami events and served on the executive councils of Women in Cybersecurity Florida and Black Girls in Cyber, helping to advance diversity, mentorship, and professional development in the field. Her expertise spans vulnerability management, threat modeling, and policy-driven security in Web3 and enterprise systems.

\n\n\n\'',NULL,1294008),('3_Saturday','10','10:00','10:59','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Whose Agent Is It Anyway? Agency, Authorization, and Accountability in the Year of the AI Agent\'','\'Andreas Kaltsounis,Jacob Wall\'','Creator Talks_97ec1ae9bdbec42fcae829d3bb36a54b','\'Title: Whose Agent Is It Anyway? Agency, Authorization, and Accountability in the Year of the AI Agent
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

DEF CON 34’s theme is Agency—as in digital self-determination. This is also the year agentic AI went mainstream. Those two meanings of “agency” are now colliding in the legal sphere, and early answers are not in the user’s favor. A federal court ruled that a user’s instruction to her own AI agent to access her own Amazon account may violate federal cybercrime law—because the platform, not the user, controls authorization. The decision is up for appeal. Meanwhile, the market is trending the same way: agents go where B2B agreements permit. The web, as navigated by AI agents, is becoming a permission graph between companies. The instinct is clear: the user’s delegation should count, agents should go where the user can. But the question is harder than it looks. Real vulnerabilities allow agents inside authenticated platform environments to be hijacked. Platforms cannot secure these agents or distinguish them from legitimate user sessions. When the user delegates, she opens channels an attacker can redirect. The platform must decide whether to accept the risk of tools it didn’t build operating in spaces it’s responsible for protecting. Neither courts nor markets are producing the right answer. Two cybersecurity lawyers walk through the cases, the complicating security research, and the policy options.

\n\nSpeakers:Andreas Kaltsounis,Jacob Wall
\n
\nSpeakerBio:  Andreas Kaltsounis, BakerHostetler
\n

Andreas Kaltsounis is an attorney and co-lead of BakerHostetler’s Digital Risk Advisory & Cybersecurity practice, where he advises clients on privacy and security compliance, incident response, and regulatory defense. He holds the CISSP certification, is an IAPP Fellow of Information Privacy, and is ranked by Chambers USA and Chambers Global for his work in privacy and cybersecurity law. Before practicing law, Andreas was a managing director at an international information security consulting firm and served as a federal agent investigating criminal and national security cyber matters.

\n\nSpeakerBio:  Jacob Wall, BakerHostetler
\n

Jacob Wall is an attorney and associate in BakerHostetler’s Digital Risk Advisory & Cybersecurity practice. Jacob\'s work spans technology regulatory law, including compliance and product counseling, regulatory defense, and policy advocacy. A particular focus of Jacob\'s practice is bringing a technical background to complex cybersecurity and AI regulatory questions. He and Andreas work together on a range of AI governance and cybersecurity compliance engagements for technology and critical infrastructure clients.

\n\n\n\'',NULL,1294009),('3_Saturday','10','10:30','10:59','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Emulating the “Identity-First” Threat Actor: Automated Playbooks for IdP Hijacking\'','\'Samet Can Tasci,Mehmet Önder Key\'','Creator Talks_43dc8b70a8afc997b79cedb726ec6b06','\'Title: Emulating the “Identity-First” Threat Actor: Automated Playbooks for IdP Hijacking
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Modern intrusions often start with identity, not malware. Adversaries abuse IdP drift, device code flows, stale sessions, weak conditional access, helpdesk processes, SaaS integrations, and cloud role mappings. This talk presents a safe emulation framework for identity-first threat actors across AD, Entra ID, Okta-like workflows, and cloud control planes. The lab provides ATT&CK-aligned playbooks that simulate identity compromise, IdP pivoting, session abuse, and SaaS access without stealing real credentials. The focus is measurable purple-team validation: expected telemetry, detection hypotheses, failure points, and repeatable scoring.

\n\nSpeakers:Samet Can Tasci,Mehmet Önder Key
\n
\nSpeakerBio:  Samet Can Tasci, Senior Linux Systems Engineer
\n

Samet Can Tasci is a Senior Linux Systems Engineer and security researcher with experience across enterprise infrastructure, cloud and hybrid environments, automation, and defensive security validation.

\n\n

His research interests include web defense behavior, WAF normalization gaps, parser inconsistencies, adversary-informed testing, and practical tooling for security teams.

\n\n

He is the creator of WaffleX, a research prototype selected for Black Hat USA Arsenal, which focuses on semantic consistency analysis, enforcement drift, and family-level request-variant testing across modern web application defense stacks.

\n\nSpeakerBio:  Mehmet Önder Key, Cyber Security Consultant
\n

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.

\n\n\n\'',NULL,1294010),('3_Saturday','10','10:30','10:59','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Testing API Business Logic With AI Agents: What We Got Wrong First\'','\'Samantha Pearlstein\'','Creator Talks_1c9e77cb59db832490b8f416b6a5e296','\'Title: Testing API Business Logic With AI Agents: What We Got Wrong First
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Automating API security testing sounds straightforward until you try it on an enterprise API with complex auth and business flows. Over the past year, we\'ve been building AI agents to test business logic vulns. This talk is an honest account of what we got wrong in that process. We\'ll cover 3 specific failures: testing before we understood resource relationships (and what that did to our IDOR detection), over-relying on agents for things deterministic methods handle better, and ignoring domain context until it became impossible to ignore. Each failure changed how we built the system. Some of the lessons were obvious in retrospect. The goal is to give anyone working on similar problems an honest look at where automated business logic testing actually breaks down and why the gap between a clean test env and an enterprise API might be harder to close than it looks. Participants will understand why business logic flaws are different and how to use agentic architecture to detect them.

\n\nSpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape
\n

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.

\n\n\n\'',NULL,1294011),('3_Saturday','10','10:30','10:59','N','Biohacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'The Death of Dicom\'','\'Michael \"v3ga\" Aguilar\'','Creator Talks_e8958156fe45db8daddc065200f12f28','\'Title: The Death of Dicom
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

DICOM (Digital Imaging and Communications in Medicine) is the lingua franca of medical imaging — a decades-old protocol embedded in nearly every hospital network, PACS server, and imaging modality on the planet. It is also, by modern standards, a deeply permissive protocol: built on assumptions of trusted networks, sprawling parser surface area, and file formats that double as executable carriers. For an attacker, that combination is a gift.\nThis talk explores how DICOM can be repurposed as offensive infrastructure across the full red team lifecycle. We’ll walk through the protocol’s exploitable design choices, demonstrate techniques for initial access, lateral movement, and persistence inside healthcare environments, and examine how DICOM files themselves can be abused as polyglot payload carriers that survive AV, EDR, and content inspection. Along the way, we’ll look at real-world PACS deployments, the surprising reach of DICOM beyond hospitals, and why this protocol represents one of the largest under-examined attack surfaces in critical infrastructure today.\nAttendees will leave with a working mental model of DICOM from an offensive perspective, concrete TTPs they can incorporate into engagements against healthcare and adjacent verticals, and a healthy appreciation for why their next CT scan might be running on a Windows XP box.

\n\nSpeakerBio:  Michael \"v3ga\" Aguilar, Principal Consultant at Sophos Red Team
\n

Michael Aguilar (v3ga) is a Principal Consultant on the Sophos Red Team, paid to think like the people his clients are afraid of. His work lives at the intersection of offensive security, vulnerability research, and low-level systems programming, Windows internals, reverse engineering, and the kind of dusty attack surfaces that nobody has looked at since the protocol was ratified. Sometimes, he’s lucky enough to perform full Physical Red teams against his client targets. His method is unglamorous and effective: Analyze, Formulate, Target, Attack (covertly).

\n\n\n\'',NULL,1294012),('3_Saturday','10','10:45','11:30','N','Game Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Dreamcast Ex Inferis: RCE on the Sega Dreamcast PlanetWeb Browser\'','\'Christopher \"Piffd0s\" Hernandez\'','Creator Talks_316bc4a535a8ef178b74571bc7324ba0','\'Title: Dreamcast Ex Inferis: RCE on the Sega Dreamcast PlanetWeb Browser
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:45 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

The PlanetWeb Internet Browser v3.0 (2000–2001) is the official disc that let you browse the web and read email on a Dreamcast. Its online features depend on a backend server that no longer exists. The dreamcast is now a networked, code-downloading appliance whose trust model rests on a domain anyone can now point wherever they want.

\n\n

What We Did

\n\n

This is a full unauthenticated, network-only attack. By answering DNS for the dead backend domain, we get the browser to download and run our code. From there we chain through the mail client to reach the console\'s bare metal, and end by running DOOM natively.

\n\n

No physical access, no modchip, no user trickery beyond opening one email. The console was built to download and trust code from a server that\'s gone — so we just become that server.

\n\n

The talk walks through the chain at a high level, the obstacles of debugging a 24-year-old black box, and what it takes to get a modern game engine running in the few megabytes of RAM the Dreamcast has — ending with a live demo of DOOM running on the browser.

\n\n

Why It Matters / Why It\'s Fun

\n\n

It\'s a clean case study in why abandoned online infrastructure is a security problem that outlives the product, and it\'s a nostalgic hardware-hacking story with the most satisfying possible payoff: DOOM, on a Dreamcast, over the internet.

\n\nSpeakerBio:  Christopher \"Piffd0s\" Hernandez, Binary Enthusiast
\n

Chris Hernandez is a security researcher specializing in vulnerability discovery, exploitation, and large scale reverse engineering using IDA Pro. A Pwn2Own competitor in the ICS/SCADA and embedded systems categories, he actively collaborates with the reverse engineering community to solve binary analysis challenges.

\n\n

--

\n\n

Chris Hernandez is the founder of Adversary Consulting Group and an offensive security researcher with more than a decade of experience in vulnerability research, reverse engineering, and exploit development. He holds the OSEE certification and has competed at Pwn2Own in the IoT and ICS/SCADA categories.

\n\n\n\'',NULL,1294013),('3_Saturday','11','10:45','11:30','Y','Game Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Dreamcast Ex Inferis: RCE on the Sega Dreamcast PlanetWeb Browser\'','\'Christopher \"Piffd0s\" Hernandez\'','Creator Talks_316bc4a535a8ef178b74571bc7324ba0','\'\'',NULL,1294014),('3_Saturday','11','11:00','11:30','N','DEF CON Groups','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Building a Hacker Haven: The Long Game of Growing a Local Hacker Community\'','\'Ryan Zagrodnik,Allie Zagrodnik\'','Creator Talks_ec73737244d34e57ce22b672dde7809b','\'Title: Building a Hacker Haven: The Long Game of Growing a Local Hacker Community
\nTags: DEF CON Groups | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\nDEF CON 30 sent us home with an idea: our city needed a hacker community.
\nThree years later, that idea has grown into a 501(c)(3) nonprofit, a thriving monthly meetup, a network that helped us launch a regional conference (wiscon.io), and a long-term vision for a brick-and-mortar hackerspace. Along the way, we\'ve learned a lot, made our share of mistakes, and discovered what it really takes to build a sustainable community from the ground up.
\nThis talk is a practical guide to starting and growing a DEF CON Group without burning yourself out in the process. We\'ll cover getting approved by DEF CON Groups, incorporating as a nonprofit, raising money from your community, building a board that works well together, writing bylaws that set you up for success, handling Code of Conduct issues, and planning for long-term growth beyond monthly meetups.
\nWe\'ll also talk about something that doesn\'t get enough attention, building a community as a team. The strongest groups aren\'t built by one person doing everything, they\'re built by people who share the workload, support one another, and create something that can outlast any single organizer.
\nExpect honest lessons learned, practical advice, real numbers, and plenty of war stories. We\'ll also provide a companion website packed with all the details that you can adapt for your own community.
\nIf you\'ve ever thought about starting a DEF CON Group, building a local hacker community, or creating something that brings people together, this talk is for you!
\n\n\n\nSpeakers:Ryan Zagrodnik,Allie Zagrodnik
\n
\nSpeakerBio:  Ryan Zagrodnik, DC608
\n

Ryan Zagrodnik is a Senior Penetration Tester with over sixteen years of experience in offensive and defensive security roles. He holds OSCP and CISSP certifications and has previously worked on internal red teams and held a U.S. Government security clearance doing offensive security for the Department of Defense and Department of Education. Ryan has presented at CypherCon, SecretCon, DEF CON Hardware Hacking Village, BSides MKE, GRASSr00tz, and Skunks Misery.

\n\nSpeakerBio:  Allie Zagrodnik, DC608
\n

Allie Zagrodnik is a cybersecurity professional and community organizer based in Madison, Wisconsin and quickly discovered a passion for the human side of security, community building, and mentorship within the industry.

\n\n

She is the cofounder of DC608, a Madison-based DEF CON group focused on creating an inclusive and welcoming space for anyone interested in cybersecurity, regardless of skill level or background. She is also the founder of Wisconsin Information Security Conference, a community-driven conference focused on education, networking, and growing the cybersecurity community throughout the Midwest.

\n\n

Outside of cybersecurity, Allie enjoys spending time with her husband, three dogs, and three cats, while proudly representing Wisconsin through her love of the Green Bay Packers and the local hacker community.

\n\n\n\'',NULL,1294015),('3_Saturday','11','11:00','11:59','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'No Entry: Badge Access Denial on Demand \'','\'Andrew Quill\'','Creator Talks_df3b0d55aa98e93a4fb85c2c2ab30e85','\'Title: No Entry: Badge Access Denial on Demand
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Badged access is one of the most common security controls to enforce 2 factor physical access. In this presentation we will remove this on demand and demonstrate forcing access verification to a lower tier as well as preventing others from utilizing badged access cards. What\'s even better is you can build this yourself for under $100, and we\'ll show you how.

\n\nSpeakerBio:  Andrew Quill, FD Contractors, LLC
\n

Andrew Quill has done over 18 years of federal and military service, performing roles ranging from signals analysis and waveform planning, to digital forensics and incident response. Andrew is a frequent contributor to the research community and avid dabbler in expanding technical applications across implied boundaries.

\n\n\n\'',NULL,1294016),('3_Saturday','11','11:00','11:30','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Security Analysis of Open-Source Software Used in Onboard Satellite Systems\'','\'Roee Idan\'','Creator Talks_4e8e3d89aca5ea845bbae707d8dcfee6','\'Title: Security Analysis of Open-Source Software Used in Onboard Satellite Systems
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Satellite missions are increasingly making use of open-source software, but this creates a unique security challenge for space systems. Unlike conventional IT environments, updating software onboard satellites can be far more difficult due to operational risk, limited access windows, mission validation requirements, and the high cost of mistakes after launch. In many cases, space systems also remain in operation for years, which means software may continue running on aging hardware and in environments where patching, upgrading, or fixing security issues is far more constrained than on the ground. This talk presents SCA-SAT, a purpose-built pipeline created to analyze the current security state of open-source software used in onboard satellite systems at scale. The goal is to answer a simple but important question: what does the current security landscape of open-source onboard satellite software actually look like?

\n\nSpeakerBio:  Roee Idan
\nNo BIO available
\n\n\'',NULL,1294017),('3_Saturday','11','11:00','11:45','N','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'The Camera Is Lying: RTSP Trust Failures in Modern Surveillance Systems\'','\'Bogdan \"BOTEZATU\"\'','Creator Talks_fc0bab13f57a87b46e08c0de61261d59','\'Title: The Camera Is Lying: RTSP Trust Failures in Modern Surveillance Systems
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Surveillance cameras sit at the intersection of physical security, privacy, and critical infrastructure. Yet many still rely on decades-old streaming protocols and fragile trust assumptions that receive far less scrutiny than web interfaces or cloud APIs. In this talk, Bitdefender researchers present a newly discovered authentication bypass affecting Hikvision surveillance cameras that abuses RTSP session handling to gain unauthorized access to live video streams. By exploiting inconsistencies between session validation and authorization logic, attackers can transform low-privilege or permissionless sessions into authenticated stream access.

\n\nSpeakerBio:  Bogdan \"BOTEZATU\"
\nNo BIO available
\n\n\'',NULL,1294018),('3_Saturday','11','11:30','11:59','N','Nix Vegas Community','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Compiling the World: A Binary Dataset Built from nixpkgs\'','\'Chris Connelly\'','Creator Talks_4d2869cdbb46a71968c3867a5be28159','\'Title: Compiling the World: A Binary Dataset Built from nixpkgs
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Reverse engineering binaries is slow, detailed work, but it\'s one of the few ways we have to verify what some software actually does. Machine learning might help improve some of those challenges, but only if you have high-quality, real-world ground truth to train and evaluate on. At MIT Lincoln Laboratory, we have built a large dataset for machine learning on x86_64 binaries using nixpkgs, taking advantage of Nix\'s reproducibility, package coverage, and instrumentable build environments.\nWe compiled tens of thousands of C, C++, Rust, and Go packages, often multiple versions of each, with consistent compiler flags, captured source files, and debug information. From these, we extracted roughly 50 million functions and aligned with their source code and short descriptions. Possible applications include fine-tuning large language models for various binary tasks or training custom, highly efficient models for binary code understanding.\nI\'ll walk through what it takes to wrangle nixpkgs in an HPC environment at this scale and show how open build tooling like Nix can help us to better understand and analyze the software that we all depend on.

\n\nSpeakerBio:  Chris Connelly, MIT Lincoln Laboratory
\n

Chris Connelly is a Senior Technical Staff member at MIT Lincoln Laboratory in the Cyber Security and Information Sciences Division. Since joining the Laboratory in 2002, he has contributed to or led research, development, and evaluation programs in several areas, including malware analysis, vulnerability discovery, systems analysis, test automation technologies, large-scale distributed systems, and software architecture.

\n\n\nLinks:
    cfp.nix.vegas/2026/schedule/ - https://cfp.nix.vegas/2026/schedule/
\n\'',NULL,1294019),('3_Saturday','11','11:30','11:59','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Nuclear Industrial Control System Simulation (NICSSIM) aka Multi-Agent Cyber Defense Framework for Distributed Nuclear Operational Technology Systems\'','\'Carmela Gonzales,Brian G. Rodiles Delgado,Marco A. Alanis Komiyama\'','Creator Talks_c92b79c9a744da74e2d14e7e313de808','\'Title: Nuclear Industrial Control System Simulation (NICSSIM) aka Multi-Agent Cyber Defense Framework for Distributed Nuclear Operational Technology Systems
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

In-person live demonstration (talk plus live demo), 30 minutes

\n\n

Abstract: As small modular reactors (SMRs) are deployed as distributed energy resources, their interconnected digital infrastructure expands the cyber attack surface across nuclear operational technology (OT) in ways that traditional, rule-based security mechanisms were never designed to address. NICSSIM (Nuclear Industrial Control System Simulation) is a modular ICS testbed that models, deploys, monitors, and analyzes an SMR fleet in a fully software-based environment, so security research can be conducted with no live infrastructure at risk.

\n\n

This demonstration shows NICSSIM end to end: a human-aware multi-agent architecture in which a supervisory agent coordinates a read-only vulnerability-analysis agent and a remediation agent under deterministic safety guardrails and an independent safety auditor, with strict separation between analysis and execution that keeps human operators as the final decision-makers. Attendees watch agents and operators detect, analyze, and respond to live attacks across 1 to 3 reactor fleets, alongside results showing up to a 96 percent response success rate with ISA/IEC 62443 compliance verification, and the latency and cost trade-offs measured across seven models from four providers.

Presentation Outline/Walkthrough:

\n\n

Why nuclear OT, why now. SMRs are deployed as distributed energy resources rather than large centralized plants, which tightens the coupling between cyber and physical processes and widens the attack surface across an interconnected fleet. Traditional defense-in-depth, built on the Purdue model, firewalls, and intrusion detection, provides rigidity rather than adaptability and cannot reason about a live fleet in real time.\n
The gap and the testbed. What is missing is a single environment that combines high-fidelity ICS simulation, coordinated multi-agent reasoning, and human-aware control. Presenters introduce NICSSIM: SMR digital twins built on ICSSIM and Docker, aligned to the Purdue model, generating continuous telemetry, with no live infrastructure at risk.

\n\n

Architecture walkthrough and Live UI. Live interface, deploys a modular fleet, and shows the digital twins and live operational data. Display of human-aware multi-agent design: a human-in-the-loop gateway, a supervisory agent that serves as the single control point, a read-only vulnerability-analysis agent, a remediation agent, and an independent safety auditor, with deterministic guardrails and enforced separation between the analysis environment and the target ICS environment.\n
Live attack and defense. Presenters “deploy” 1-SMR and 3-SMR fleets and run scenarios live: an unauthenticated Modbus write command evaluated for correct risk severity, a safety-threshold violation such as a request to push the primary coolant outlet temperature past its hardcoded limit, which the system must reject, and an ISA/IEC 62443 compliance mapping in which a finding must map to the correct regulatory sub-section rather than offer vague advice. The audience sees the guardrail reject an unsafe command, the safety auditor catch a flawed finding, and the forensic audit trail a human operator would review.\n
Results and trade-offs. Response Success Rate by fleet size and model, from 0.96 for a single SMR down to 0.91 for a three-reactor fleet with the highest-reasoning model, alongside the latency, token, and cost trade-offs measured across seven models from four providers. The takeaway is that higher-reasoning models buy accuracy at the cost of latency and dollars, a trade-off that matters for real OT deployment decisions.
\nDual-use and responsible design. The framework establishes defensive elements through isolated, simulation-only boundaries, deterministic guardrails, and required human authorization for any non-read-only action, while gating system access using IEC 62443 security levels. Conversely, its offensive elements reside in the embedded red team capabilities that possess the dual-use potential to identify exploit vectors in nuclear Operational Technology (OT) environments. To ensure a responsible design, this dual-use capability is set for credentialed security researchers operating within sanctioned, simulated training exercises under institutional oversight and strict operational containment.

\n\nSpeakers:Carmela Gonzales,Brian G. Rodiles Delgado,Marco A. Alanis Komiyama
\n
\nSpeakerBio:  Carmela Gonzales
\n

Carmela Gonzales, M.Eng., is a Ph.D. candidate in Space Cybersecurity focused on the security and resilience of cyber-physical systems in space and critical infrastructure environments. Her work and research bridge technical and policy perspectives in emerging technologies across academia, government, and industry.\nShe is the founder of Astryx Research Group, a DEF CON Aerospace Village volunteer, a Space Beach Law Lab Fellow, and a Member-at-Large for the American Society of Mechanical Engineers (ASME) Los Angeles Section. She contributes to workforce development as a teaching fellow with the National Cybersecurity Training and Education Center (NCyTE), conducted lab validation for Cyber Security Forum Initiative (CSFI), and co-founded Women in Cybersecurity at George Washington University (WiCyS GW).\nRecognized through scholarships from The Diana Initiative, Women in Security and Privacy (WISP), Women in Cybersecurity (WiCyS), and Out in STEM (oSTEM), she is committed to advancing women in cybersecurity.

\n\nSpeakerBio:  Brian G. Rodiles Delgado
\n

Brian G. Rodiles Delgado is a Cybersecurity Management MBA candidate at the University of West Florida and a cybersecurity professional at Capital One in Dallas, Texas. He has presented research on software-defined networking, federated learning, and cybersecurity for critical infrastructure at ACM and IEEE conferences in Norway, Spain, and the United States, and has contributed to U.S. Department of Energy projects through Dr. Deepak Tosh\'s TRUstworthy CYBER system (TRUCYBER) laboratory at the University of Texas at El Paso. He is one of UTEP\'s first Barry Goldwater Scholars and a recipient of the Black Hat and Google Generation scholarships. He is recently selected as a 2026 scholar for The Diana Initiative Hacker Summer Camp.

\n\nSpeakerBio:  Marco A. Alanis Komiyama
\n

Marco A. Alanis Komiyama is a researcher at the University of West Florida (Lewis Bear Jr. College of Business) and a co-developer of NICSSIM. He presents the platform\'s live demonstration, including the deployment of the simulated reactor fleet and the multi-agent attack and defense workflow.

\n\n\n\'',NULL,1294020),('3_Saturday','11','11:30','11:59','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'So You Want to Work in Aircraft Cyber? Here\'s what you need to know!\'','\'Matt Gaffney,Marcie Wise\'','Creator Talks_5e91580de81c599a930df4107251c498','\'Title: So You Want to Work in Aircraft Cyber? Here\'s what you need to know!
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

As the Aviation industry struggles to recruit people with the right combination of knowledge and/or experience of Cybersecurity and Aviation ecosystems, this presentation will provide a very fast overview of the topics people wishing to break into the industry should consider learning more about. This will be a fast-fire and frank presentation with direction for you to start your journey into Aviation Cyber.

\n\nSpeakers:Matt Gaffney,Marcie Wise
\n
\nSpeakerBio:  Matt Gaffney
\nNo BIO available
\nSpeakerBio:  Marcie Wise
\nNo BIO available
\n\n\'',NULL,1294021),('3_Saturday','11','11:45','12:30','N','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Anyone Can Hack IoT (Even Easier Now) - A Beginner\'s Guide to AI Augmented IoT Hacking\'','\'Andrew Bellini\'','Creator Talks_1955ba81f0bf06f2e0bf919a62470c83','\'Title: Anyone Can Hack IoT (Even Easier Now) - A Beginner\'s Guide to AI Augmented IoT Hacking
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:45 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Two years ago I gave a popular talk at Defcon called \"Anyone Can Hack IoT\" and the message was simple, you don\'t need expensive gear and I can show you how. All of that is true, but now it\'s even easier and I want to show you why. Whether you saw the original talk or this is your first time thinking about IoT hacking, I\'ll show you how AI has actually made it even easier. In this talk I\'ll show you what\'s actually useful and what not by walking through my real workflow that I\'ve used to find multiple CVEs. I\'ll demo Wairz, an open source tool I built that lets AI agents help reverse engineering firmware, along with some other hardware tools I\'ve put together to give AI direct access to devices on my bench. I\'ll cover what\'s worth using AI for, what\'s still better done by hand and how you can build your own AI assisted setup at home and hack your first device (or second or third or so on).

\n\nSpeakerBio:  Andrew Bellini
\nNo BIO available
\n\n\'',NULL,1294022),('3_Saturday','12','11:45','12:30','Y','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Anyone Can Hack IoT (Even Easier Now) - A Beginner\'s Guide to AI Augmented IoT Hacking\'','\'Andrew Bellini\'','Creator Talks_1955ba81f0bf06f2e0bf919a62470c83','\'\'',NULL,1294023),('3_Saturday','12','12:00','12:30','N','Hackers.town','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'KYC and XMR… FOR HACKERS!\'','\'AltKey\'','Creator Talks_6eaaf0758d00ca2dd7bfce6cab40b5d8','\'Title: KYC and XMR… FOR HACKERS!
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

An overview of handy usecases for specific crypto currencies for technologists.

\n\nSpeakerBio:  AltKey
\nNo BIO available
\n\n\'',NULL,1294024),('3_Saturday','12','12:00','12:30','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Killing AI Slop: A Multi-Model Orchestration Framework That Only Reports Findings It Can Prove\'','\'Armaan Pathan\'','Creator Talks_2fc9126811f81232fba76259f28051d0','\'Title: Killing AI Slop: A Multi-Model Orchestration Framework That Only Reports Findings It Can Prove
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

AI-assisted bug hunting has a reliability problem. Modern models can generate convincing vulnerability reports, but many fail under validation. They reference non-existent endpoints, unreachable exploit paths, or attack chains that break when tested against the target. As a result, triage teams spend increasing time reviewing low-quality submissions, while researchers struggle to separate genuine vulnerabilities from model-generated noise. This talk presents a multi-agent bug hunting framework built around a simple principle: a finding is not considered valid until it has been reproduced against the target. The goal is to improve the quality and reliability of reported findings. The process begins with understanding the target. Before testing starts, the framework analyzes JavaScript, API specifications, documentation, authentication flows, endpoints, parameters, and technologies to build a structured model of the application. This enables agents to reason about the actual attack surface rather than relying on assumptions. An orchestrator coordinates specialized agents operating from a shared understanding of the target. Candidate findings are routed through a central coordination layer that manages context sharing and eliminates duplicate results. To improve decision-making and reduce hallucinations, the agents leverage a RAG engine backed by publicly disclosed vulnerability reports and security research. Every candidate finding passes through a verification stage that evaluates application-specific context, observed behavior, and supporting evidence. Findings that pass validation are further tested to determine their maximum practical impact before being reported, while non-actionable and expected behavior is discarded. The presentation covers the architecture, orchestration model, and verification workflow, providing practical guidance for building AI-assisted security tooling that prioritizes evidence over assumptions.

\n\nSpeakerBio:  Armaan Pathan
\n

Armaan Pathan is a Senior Security Engineer at KATIM with more than 10 years of experience in offensive security, application security, and vulnerability research, helping organizations identify and remediate critical security risks.Throughout his career, he has discovered and responsibly disclosed vulnerabilities impacting major companies, including Google, Meta, and Apple, through bug bounty and coordinated vulnerability disclosure programs. His interests include web and API security, security engineering, and exploring how AI can be used to enhance offensive security and vulnerability research. Armaan actively contributes to the security community-publishing technical blogs, presenting at conferences, and raising awareness of emerging threats and practical defenses.

\n\n\n\'',NULL,1294025),('3_Saturday','12','12:00','12:30','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Local Language Models in OT - Basics and Considerations\'','\'Vivek Ponnada\'','Creator Talks_fd5bb4eb4ac667e6245664543dc8c14d','\'Title: Local Language Models in OT - Basics and Considerations
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

AI models are everywhere but most are talking about Frontier models that might not be deployable in OT environments. Either due to regulations or data sensitivity, local models might be the answer to extract more value out of various OT datasets. How do you get started? This presentation lays out the basics - from the HW options to various models available (e.g, Qwen, Gemma) - we cover what can be achieved by a bit of investment and a not a lot of elbow grease!

\n\nSpeakerBio:  Vivek Ponnada
\n

Vivek Ponnada is an Operational Technology (OT) Security practitioner with global experience and currently serves as SVP of Growth & Strategy at Frenos, the world\'s first Simulated OT Pentesting Platform. Having started his career in Industrial Control Systems (ICS) as a Technician, Vivek became a Controls Engineer and commissioned Gas Turbines in Europe, Middle-East, Africa and South-East Asia. Post MBA, Vivek held multiple roles in Sales, Marketing & Business Development and Services covering ICS and OT Security solutions for Critical Infrastructure industries (Power, Oil & Gas, Water, Mining etc.) at GE, XenonCyber Dynamics and Nozomi Networks. He was a co-lead for the Top 20 Secure PLC Coding Practices Project and regularly speaks at Information Security Conferences. Vivek has a C.Eng. from IEI, MBA from McCombs (UT Austin) and holds the ISA/IEC 62443 Cybersecurity Expert & GICSP certifications. He is a member of the ISA, ISACA, Public Safety Canada ICS Security Symposium Advisory Committee and is a CS2AI Fellow.

\n\n\n\'',NULL,1294026),('3_Saturday','12','12:00','12:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Please Place Your Electronic Devices in {Maritime} Mode: Exposing NTN’s Maritime Attack Surface\'','\'Jason Veara\'','Creator Talks_46a4a0108e5e6a1f5cce2d0d72e663b0','\'Title: Please Place Your Electronic Devices in {Maritime} Mode: Exposing NTN’s Maritime Attack Surface
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Many Mariners share a sigh of relief once the sight of shore disappears. Sail far enough from the mainland, and the distractions of the cellular world fade away. No bars. No signal. No problem. Cellular Non-Terrestrial Networks (NTN) have stolen that comfort. Ships have long relied on satellite communications for safe navigation and operations at sea. However, traditional threats to GPS, satellite broadband, and Iridium are being rapidly supplanted by Direct-to-Device (D2D) cellular connectivity via NTN. The same vulnerabilities that plagued its terrestrial ancestors are quietly following mariners out to sea. This talk provides a technical deep-dive into 4G and 5G NTN architecture, its current footprint in the maritime environment, and the vulnerabilities it inherits from its terrestrial ancestors. We close by charting a course forward, exploring open research questions and offering practical recommendations.

\n\nSpeakerBio:  Jason Veara, Independent Researcher
\n

Jason Veara is a Cybersecurity PhD student at Northeastern University, a Coast Guard Officer, and Permanent Military Faculty at the U.S. Coast Guard Academy in New London, CT. His research focuses on identity, localization and trust in wireless-dependent autonomous systems.

\n\n\n\'',NULL,1294027),('3_Saturday','12','12:30','12:59','N','Misc','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Donating Bone Marrow: A Donor\'s First-Hand Experience\'','\'\'','Creator Talks_a01cc748939d2877d66822980f2eccb1','\'Title: Donating Bone Marrow: A Donor\'s First-Hand Experience
\nTags: National Marrow Donor Program (Be the Match) | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Donating bone marrow can save lives, but many don\'t understand what it really involves. Find out the experience and how you can help participate in one of the coolest bio-hacks ever.

\n\nLinks:
    Website - https://www.nmdp.org/
\n\'',NULL,1294028),('3_Saturday','12','12:30','12:59','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Eating Our Own Dogfood: Running a Bug Bounty Program on a Bug Bounty Platform\'','\'Shrimant Subhash More,Martzen Haagsma\'','Creator Talks_646bdcfecae588e148f453696bac04ff','\'Title: Eating Our Own Dogfood: Running a Bug Bounty Program on a Bug Bounty Platform
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

At HackerOne, the same community that submits vulnerability reports also tests the platform they use to report them. Every report becomes a live stress test of our product, workflows, assumptions, and newly shipped features. In this talk, a Senior Triage Lead and a Product Security Engineer share what we learned from running HackerOne’s own bug bounty program while shipping GraphQL features, AI-assisted tooling, disclosure workflows, and platform-scale infrastructure changes. Using three real disclosed reports, we walk through how seemingly small bugs escalated into platform-wide security lessons: 1. An Elasticsearch query parameter that enabled metadata enumeration through raw script execution. 2. A PDF export feature that unintentionally exposed internal triage activity. 3. An AI agent that exposed non-public report metadata because a researcher asked the right question. We will show how reports move from submission to validation, severity debates, engineering response, remediation, retesting, and disclosure. We will also discuss how we use our own program as a testing ground for AI-assisted triage, automated validation workflows, and disclosure policies before rolling changes out more broadly. This is not a “how to run a bug bounty program” talk. It is a behind-the-scenes look at what happens when hackers continuously attack the bug bounty platform itself and how that pressure forces rapid security evolution. Attendees will leave with practical lessons on: 1. building tighter triage-to-engineering feedback loops, 2. handling modern attack surfaces like GraphQL and AI agents, 3. scaling remediation without losing researcher trust, 4. and turning bug bounty programs into product improvement engines instead of passive inboxes. All case studies are based on disclosed HackerOne reports. No customer data was accessed or exposed.

\n\nSpeakers:Shrimant Subhash More,Martzen Haagsma
\n
\nSpeakerBio:  Shrimant Subhash More, Senior Security Analyst, HackerOne
\n

Shrimant Subhash More is a Senior Product Security Analyst at HackerOne with over 8 years of experience in offensive security, penetration testing, and vulnerability management. His expertise spans web, API, mobile (Android and iOS), and AI/LLM security, with more than 300 security assessments conducted across diverse industry sectors. At HackerOne, Shrimant leads and supports vulnerability triage operations, validates security reports submitted by researchers, handles escalations, mentors analysts, and collaborates with global teams to improve security outcomes and triage efficiency. He is passionate about offensive security, product security operations, security automation, and helping organizations build resilient products. Beyond his professional role, Shrimant actively contributes to the cybersecurity community as a HackerOne Community Brand Ambassador for India West (Pune), where he organizes meetups, conducts workshops, mentors aspiring researchers, and promotes responsible disclosure and bug bounty programs. He is the assignee of CVE-2020-35296 and holds multiple industry certifications across security, cloud, and AI domains.

\n\nSpeakerBio:  Martzen Haagsma, Security Engineer, HackerOne
\n

Martzen Haagsma is a Product Security Engineer at HackerOne with a passion for building secure systems through collaboration, automation, and continuous learning. With experience spanning security testing, DevOps engineering, and technical leadership, Martzen focuses on helping organizations identify vulnerabilities, improve security processes, and strengthen their overall security posture. Known for a solution-oriented mindset and a strong belief in the power of teamwork, Martzen enjoys connecting people, sharing knowledge, and turning complex security challenges into practical outcomes. Prior to joining HackerOne, Martzen worked across both public and private sectors in roles involving security testing, agile quality engineering, and engineering leadership. Outside of work, Martzen is an active technologist with interests ranging from security and software development to automation, IoT, and 3D printing. Through writing, mentoring, and community engagement, Martzen advocates for curiosity, collaboration, and making technology more secure and accessible for everyone.

\n\n\n\'',NULL,1294029),('3_Saturday','12','12:30','12:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Maritime Threat Hunting: What We Actually Find When We Look\'','\'Cliff Neve,Philip Acosta,Dean Macris\'','Creator Talks_9d401789d3e7f8139af997da1597a6b9','\'Title: Maritime Threat Hunting: What We Actually Find When We Look
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

You cannot secure what you cannot see. As maritime organizations work to improve cyber resilience, many are discovering that the biggest challenge is not detecting threats. It\'s understanding their networks in the first place. Drawing from real-world maritime environments, MAD Security and GuROO Networks will demonstrate how Network Operations Centers (NOCs) and Security Operations Centers (SOCs) work together to identify assets, establish operational baselines, uncover hidden risks, and investigate suspicious activity across maritime IT and OT environments. This presentation examines actual findings from vessel operators, ports, terminals, and maritime infrastructure organizations, including:

\n\n
    \n
  • Unknown and unmanaged assets
  • \n
  • Operational technology discovered outside expected network boundaries
  • \n
  • Remote access pathways and third-party connectivity risks
  • \n
  • Network architecture weaknesses that create attack paths
  • \n
  • Threat hunting methodologies used in maritime environments
  • \n
  • Detection and response techniques used by maritime SOC analysts
  • \n
  • How NOC visibility data enhances security operations and incident response
  • \n
\n\n

Attendees will see how network visibility, asset intelligence, operational monitoring, and cybersecurity analytics combine to provide a more complete picture of maritime risk. Rather than focusing on theory or compliance, this session highlights what maritime operators actually discover when they begin looking deeper into their environments and why visibility remains the foundation of both network reliability and cybersecurity.

\n\nSpeakers:Cliff Neve,Philip Acosta,Dean Macris
\n
\nSpeakerBio:  Cliff Neve, MAD Security
\n

Cliff Neve is Vice President of Maritime Cybersecurity at MAD Security and a retired U.S. Coast Guard Commander with more than 30 years of experience in cybersecurity, operational technology (OT), and critical infrastructure protection. As a founding leader of Coast Guard Cyber Command, he helped establish the Coast Guard\'s cyber defense mission and contributed to national cybersecurity policy development.

\n\n

Today, Cliff leads maritime cybersecurity initiatives supporting ports, terminals, shipping companies, and government agencies. His experience includes terminal cybersecurity risk assessments, threat hunting, incident response, and Security Operations Center (SOC) services for maritime organizations, including projects supporting the U.S. Maritime Administration (MARAD) and commercial shipping operators.

\n\n

Cliff specializes in the intersection of maritime operations, OT security, and cyber resilience, and is a frequent speaker on maritime cybersecurity, threat detection, and critical infrastructure protection.

\n\nSpeakerBio:  Philip Acosta, GuROO
\nNo BIO available
\nSpeakerBio:  Dean Macris, University of Rhode Island
\nNo BIO available
\n\n\'',NULL,1294030),('3_Saturday','12','12:30','13:30','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Privacy You Inherit: How Cultural History Writes the Source Code for AI Surveillance Policy\'','\'Tati\'','Creator Talks_df1b982f570c9281d453d753f5fe9d3b','\'Title: Privacy You Inherit: How Cultural History Writes the Source Code for AI Surveillance Policy
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Privacy isn\'t a principle. It\'s an inheritance — and AI is accelerating past every inheritance at once. This talk traces four lived experiences with surveillance — post-Mao China\'s \"watchful neighbor,\" Stasi-era Germany\'s distrust of the state, Soviet communal density\'s \"everyone already knows,\" and an American market that traded a constitutional right to privacy for one-click convenience — and shows how each set the privacy floor people now expect from AI. Chinese citizens accept face-scans but punish commercial data sale. Germans push back on the tech itself. Russians shrug. Americans click accept and let 23andMe hand DNA to law enforcement. Then AI changes the game. ChatGPT logs surface kids who type the wrong thing. Flock cameras blanket neighborhoods \"for the children.\" Clear sells your face for a faster TSA line. None of these systems sit cleanly inside any inherited default — and federal policy has gone quiet. Audience leaves with: a vocabulary for diagnosing whose privacy default an AI proposal is actually written for; the federal-vacuum / state-patchwork pattern; and three concrete asks — plain-language consent, a \"kudos wall\" for companies that earn trust, and abstraction-layer tools that read T&Cs for users.

\n\nSpeakerBio:  Tati
\n

Tatiana (or Tati) is a Technical Program Manager who spends their days breaking telcos (amongst other things), managing logistics and wrangling hackers. They have no formal policy credentials, and that\'s kind of the point. The grandchild of Holocaust survivors and the child of Soviet émigrés, Tatiana didn\'t learn about surveillance overreach in a classroom or a think tank. They learned it the way most people in their family did — through stories of what happens when the state decides it has a right to know everything about everyone. That inheritance is why they\'re here, talking policy at a hacker conference instead of leaving it to the people who usually do

\n\n\n\'',NULL,1294031),('3_Saturday','13','12:30','13:30','Y','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Privacy You Inherit: How Cultural History Writes the Source Code for AI Surveillance Policy\'','\'Tati\'','Creator Talks_df1b982f570c9281d453d753f5fe9d3b','\'\'',NULL,1294032),('3_Saturday','13','13:00','13:30','N','DEF CON Groups','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Building a Strong Community Culture presented by DC407\'','\'Edna Jonsson,Dustin\'','Creator Talks_56145cbfcfc56a98cb5e44109a363816','\'Title: Building a Strong Community Culture presented by DC407
\nTags: DEF CON Groups | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Healthy DEF CON Groups are built by more than one person. This session focuses on creating a community culture where members are encouraged to participate, contribute, speak, volunteer, and eventually help lead. DC407 will discuss consistency, mentorship, leadership mindset, and practical ways to move people from passive attendance into active involvement. This workshop is for organizers who want to build a group that is welcoming, resilient, and bigger than any single organizer.

\n\nSpeakers:Edna Jonsson,Dustin
\n
\nSpeakerBio:  Edna Jonsson, DC407
\n

Edna is one of the DC407 group leaders and enjoys helping others come up in the cyber community. Edna is the volunteer coordinator at BSides Orlando and hosts the Security Chipmunks podcast.

\n\nSpeakerBio:  Dustin, DC407
\n

I enjoy helping people. I\'m a security enthusiast, if it\'s related to security then I\'m probably interested. I\'ve helped facilitate DC4😃7 for 8+ years.

\n\n\n\'',NULL,1294033),('3_Saturday','13','13:00','13:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Evading LLM Detection\'','\'Hanley Shun,Cong Zhang,⁨Oscar Skjerven\'','Creator Talks_080d709e327e7d8b4af957a7cd3eb4a4','\'Title: Evading LLM Detection
\nTags: Cryptocurrency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Software supply chain attacks are no longer a distant threat — they are happening at scale and extremely dangerous from a crypto exchange\'s POV.

\n\n

As build pipelines grow more complex and dependencies multiply across npm, PyPI, SBOM, and internal registries, a single scanning layer is no longer enough to detect malicious code.

\n\n

This talk focuses on an AI journey — from deploying a single AI agent to gate code merges, to architecting a full multi-agent system hardened through structured simulated exercises — along the way catching real-world attacks, including the coordinated compromise of a highly popular npm package spanning over 2 billion weekly downloads.

\n\nSpeakers:Hanley Shun,Cong Zhang,⁨Oscar Skjerven
\n
\nSpeakerBio:  Hanley Shun, OKX
\n

Hanley has been working in information security for 10 years, with a background in penetration testing and vulnerability management. Now at OKX, channeling that offensive mindset into building secure CI/CD pipelines with AI, every day keeping customers\' funds safe.

\n\nSpeakerBio:  Cong Zhang, OKX
\n

Cong has spent 5 years building SAST from the inside out — engines, rules, and the thinking behind them. From AST-level detection logic to full scanning pipelines, he knows where static analysis hits its limits. Now at OKX, he\'s pushing past them with AI, teaching tools to reason about supply chain risks and logic flaws that pattern matching will never catch.

\n\nSpeakerBio:  ⁨Oscar Skjerven, OKX
\nNo BIO available
\n\n\'',NULL,1294034),('3_Saturday','13','13:00','13:30','N','Biohacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Safe, Secure, and Effective: What Static Behavior Analysis Reveals About the Software Running Your Medical Devices\'','\'Andrew Hendela\'','Creator Talks_12a7579654f8fa3271df1f0e9041a653','\'Title: Safe, Secure, and Effective: What Static Behavior Analysis Reveals About the Software Running Your Medical Devices
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

When a patient monitor misreads an ECG or an infusion pump miscalculates a dose, the root cause is software behavior, not a CVE. Yet the entire medical device security industry is fixated on vulnerability scanning and SBOMs while ignoring the harder question the FDA actually asks: does this software behave in ways that are safe and effective for its clinical purpose?

\n\n

Using automated reverse engineering developed under ARPA-H research, we analyze compiled medical device firmware to build Software Bills of Behaviors that map what every function in a binary actually does. We automatically categorize hundreds of functions into clinical subsystems: ECG data processing, SpO2 and CO2 signal handling, physiological waveform display, sensor calibration, and heatblock control. We then identify which subsystems constitute essential performance, the functions where a bug, an unexpected change, or a malicious modification doesn\'t just create a cyber incident, it harms a patient.

\n\n

We\'ll walk through real device firmware where we found functions that directly modify ECG configuration and hardware calibration state, where logic flaws or race conditions could impact device safety, stability, or data integrity. We\'ll show how a firmware update that only touches 10% of functions can silently alter safety-critical signal processing paths, and how we automatically assess whether those changes affect clinical operation or are benign. We\'ll demonstrate how the Contec CMS8000 patient monitor contained unapproved wireless monitoring capabilities the FDA never cleared, a safety and regulatory violation invisible to any vulnerability scanner.

\n\n

Whether you\'re building devices, securing hospitals, or hacking medical firmware, this talk shifts the frame from \"is it vulnerable?\" to \"is it safe?\" because the patient on the other end doesn\'t care about your CVSS score.

\n\nSpeakerBio:  Andrew Hendela
\n

Andrew Hendela has been automating hard offensive and defensive cyber for well over a decade and a half, from VR, malware analysis, and cyber attribution. He is also a co-founder of Karambit.AI, a startup focused on validating the safety, security, and effectiveness of software and firmware.

\n\n\n\'',NULL,1294035),('3_Saturday','13','13:00','13:30','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Tag, You’re It: Physical Tracking Tech, Defense, and How to DIY Your Own\'','\'Eddie Miro\'','Creator Talks_46af0cc61b70964b4fc1c9c0c49f45d7','\'Title: Tag, You’re It: Physical Tracking Tech, Defense, and How to DIY Your Own
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

We live in an era where our location data is constantly harvested, but what happens when the tracking becomes physical? From the clandestine beacons of the Cold War to the consumer-grade AirTags tucked into backpacks today, physical tracking technology has become incredibly cheap, accessible, and pervasive.

\n\n

In this talk, we will trace the evolution of physical tracking tech, analyze how modern implementations exploit wireless protocols like BLE, cellular, and GPS, and discuss practical defense strategies to detect and neutralize unwanted eyes.

\n\n

Finally, we will demystify the threat by turning the tables: demonstrating how to build and deploy a fully functional, budget-friendly tracking beacon using off-the-shelf DIY hardware.

\n\n

Attendees will leave with a deep understanding of the tracking landscape and the knowledge required to both defend against and build these systems.

\n\nSpeakerBio:  Eddie Miro, Operations Manager - HackerHaus Security Solutions
\n

Cybersecurity Professional & Creator | Community Builder | Speaker

\n\n

I build communities, break into systems (legally), and share what I learn along the way. With over a decade of deep involvement in the hacker community, my work spans public speaking, content creation, and technical contributions.

\n\n

Key Highlights:

\n\n

Speaking & Community: Featured speaker at 30+ conferences (including DEF CON 27 SE Village) and dedicated volunteer at 25+ events. Former DEF CON Goon.

\n\n

Media & Content: Hosted Simply Social Engineering, guest on 20+ podcasts, and published writer in 2600 Magazine.

\n\n

Projects & Ventures: Founder of Octopus Game. Contributor to Black Hills Information Security\'s Backdoors & Breaches.

\n\n

Always building and still punk. Let’s connect.

\n\n\n\'',NULL,1294036),('3_Saturday','13','13:30','13:59','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'FORTRESS Framework\'','\'Brad \"Sno0ose\" Ammerman\'','Creator Talks_d60ecee7fa500595d5d7a7a338f7b190','\'Title: FORTRESS Framework
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

As physical security threats increase in sophistication and frequency, organizations face a critical gap in their physical security, the lack of a structured framework for physical security assessments and tests. FORTRESS was designed to fill this need by providing a categorized model of physical Tactics, Techniques, and Procedures (TTPs), each aligned to industry-standard compliance controls such as NIST, HIPAA, FedRAMP, ISO 27001, and PCI DSS. Designed for both red and blue teams, FORTRESS enables coordinated, repeatable physical security testing by consolidating adversarial behaviors into mapped TTPs. Each TTP is supported by detailed guidance for the execution, validation, and reporting of physical security gaps making assessments more consistent across multiple teams, business units, and future engagements. This paper presents the overall breakdown of FORTRESS, highlighting its application, structure, and flow. I believe this framework fills that critical void in operational and physical security and can be viewed as the foundation for enhancing and maturing physical security risk programs with real threat models as the base.

\n\nSpeakerBio:  Brad \"Sno0ose\" Ammerman
\n

Brad Ammerman, a leading figure in security testing, currently serves as the Senior Director at Prescient Security. His background includes influential roles at companies like Foresite, Optiv, Lockheed Martin, DIA, DoD, and Supreme Court of Nevada, where he developed his expertise in offensive security and team management. A skilled hacker himself, Brad is also a recognized speaker, educator, mentor, and disabled veteran, dedicated to teaching and protecting others.

\n\n\nLinks:
    Website - https://fortressframework.com/
\n\'',NULL,1294037),('3_Saturday','13','13:30','13:59','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Field Notes on Offensive Agents: Reusability, Reliability, and What Breaks\'','\'Dominika Pietrzak,Ibai Castells\'','Creator Talks_cba4efd6d0440657e7729eb72248eee2','\'Title: Field Notes on Offensive Agents: Reusability, Reliability, and What Breaks
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Offensive agents are easy to demo, but much harder to make useful across real adversary emulation work. Key challenges lie in making agents reusable and reliable across different assessment types, tech stacks and doing so, as models, tools, and environments change.

\n\n

This talk shares lessons from designing, deploying, and refining a suite of modular offensive agents used in real client engagements. We will cover what made the agents reusable, where they broke against real-world complexity, and how we evaluated their effectiveness over time as prompts degraded, models drifted, and underlying tools evolved. The session is framework-agnostic and vendor-neutral.

\n\n

Attendees will leave with a practical model for building composable offensive agents that remain useful and reliable across attack types.

\n\nSpeakers:Dominika Pietrzak,Ibai Castells
\n
\nSpeakerBio:  Dominika Pietrzak, Offensive AI Engineer
\n

Building AI-led tooling to scale offensive security operations.

\n\nSpeakerBio:  Ibai Castells, Senior Red Team Hive Member
\n

Senior Red Teamer and Red Team Capability Lead at CovertSwarm. Passionate about Windows, AD, malware dev and offensive tool engineering. Currently exploring how AI can be integrated in Red Team workflows. I drop my latest research, malware dev, and how-tos on my blog and GitHub.

\n\n\n\'',NULL,1294038),('4_Sunday','12','12:00','12:30','N','Recon Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Recon on Trial: The OSINT Operator\'s Legal Playbook\'','\'David Cass\'','Creator Talks_c1b8cdb78ee79743f696d1d83dee705b','\'Title: Recon on Trial: The OSINT Operator\'s Legal Playbook
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

You scrape a public site. You enumerate subdomains. You grep GitHub for secrets. You curl a misconfigured API. Each one touches a statute. Some have been to the Supreme Court. Most operators don\'t know which is which — until the preservation letter arrives. A federal-court-qualified expert witness (U.S. v. Sullivan) walks through five live OSINT techniques with real-time legal annotation. Zero lawyer-speak. GitHub release included.

\n\nSpeakerBio:  David Cass, Expert Consultant · Head of FinTech Practice
\nDavid Cass occupies a vantage point few cybersecurity and financial-technology experts can claim: he has sat on every side of the table. He recently served as a lead regulator at the Federal Reserve Bank of New York, where he was a member of the Large Institution Supervising Coordinating Committee (LISCC) overseeing the systemically important institutions whose security and risk practices he had spent two decades building from the inside. As Head of the FinTech Practice at Law & Forensics and a member of the firm\'s Cyber Security and Forensics Practice, he brings that supervisory perspective to bear as a testifying expert and consultant — most recently as a cybersecurity expert witness on a significant cyber-attack against a regional credit union that compromised member data and disrupted services.
\n\n\n\n\n\'',NULL,1294039),('3_Saturday','13','13:30','13:59','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'The Subverted Hacker\'','\'Robert \"zizkill\" Shala\'','Creator Talks_edc175bb28eb36ee8f834145fd160a43','\'Title: The Subverted Hacker
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\nFrontier AI is turning hacker labor into a defensive layer for private infrastructure: systems built on public research, open-source code, security writing, and the technical culture hackers helped create. Yet these systems are controlled by a small number of companies and states, with limited public audit ability or accountability. Historically, hackers made complex systems more understandable, modifiable, and contestable. In frontier AI, that role is being subverted. Hackers are recruited (or bribed viabounties ha!) to harden opaque models, reduce adversarial access, and protect systems whose impacts are public, but whose internals, evaluations, and risk decisions remain private. Public-interest scrutiny remains in conflict of interest. This talk argues that AI security cannot become only a corporate risk or national competitiveness exercise. If frontier AI affects labor, speech, art, security, and institutions across the globe, then it needs international public-interest security obligations. I propose an international AI evaluation and red-team mandate: a legally protected mechanism that brings vetted hackers and experts from across the globe into controlled testing of high-impact AI systems, so they remain contestable and accountable beyond the companies that build them. (I can dream can\'t I?)
\n\n\n\nSpeakerBio:  Robert \"zizkill\" Shala, Sentry
\n

Robert Shala is co-founder of Sentry, a company delivering security assurance services for some of the world’s largest organizations. His work sits at the intersection of offensive security, public policy, and emerging technology governance. Robert has contributed to Kosovo’s national cybersecurity strategy working group and to a Kosovo working group on responsible AI use in military contexts. He is also the founder of DEF CON Group Prishtina, where he works on advancing Kosovo’s responsible disclosure ecosystem and improving legal protections for good-faith security research. He has served as an external AI Red Teamer for OpenAI, probing frontier models for safety and security flaws, and was formerly involved with Georgetown RAIN/GAIA.Robert has presented security research at the Defence Academy of the UK, DEF CON 33at AI Village and AppSec Village, and BSides across the world. He holds an M.A. inSecurity Studies from Georgetown University and a B.S. from RIT. Robert loves wargaming.

\n\n\n\'',NULL,1294040),('3_Saturday','13','13:30','14:30','N','Misc','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Why Mandatory Age Verification Keeps Us All Less Safe\'','\'Alexis Hancock,Kenyatta Thomas\'','Creator Talks_7b8f96e61a5362e57c513ee486d6f588','\'Title: Why Mandatory Age Verification Keeps Us All Less Safe
\nTags: Women in Security and Privacy (WISP) | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n\n\nSpeakers:Alexis Hancock,Kenyatta Thomas
\n
\nSpeakerBio:  Alexis Hancock, Director of Engineering at Electronic Frontier Foundation
\n

Alexis works to keep the networks strong and encrypted by managing the Certbot project. As well as ensuring EFF open source tools for the public are well supported. She researches an intersection of issues on digital rights, encryption, and consumer technology. She believes in an open and equitable web through encouraging expansion of security by default, bridging engineers and security research, and advocating for better and stronger tech policy and standards.

\n\nSpeakerBio:  Kenyatta Thomas, Social Media and Video Manager at EFF
\n

As the Social Media and Video Manager at EFF, Kenyatta Thomas leads the creation of digital content that educates and mobilizes the public across EFF\'s online platforms. They come to EFF from a background in youth and reproductive justice advocacy and organizing, having previously worked with organizations such as Physicians for Reproductive Health, the National Network of Abortion Funds, Reproaction, and Advocates for Youth. Their work as a sex educator and abortion doula informs their deep commitment to community care, access to information, and tech equity. Kenyatta believes in the transformative power of digital tools to advance justice and is committed to making online spaces more inclusive, accessible, and empowering for all.

\n\n\nLinks:
    eff.org/ - https://eff.org/
\n\'',NULL,1294041),('3_Saturday','14','13:30','14:30','Y','Misc','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Why Mandatory Age Verification Keeps Us All Less Safe\'','\'Alexis Hancock,Kenyatta Thomas\'','Creator Talks_7b8f96e61a5362e57c513ee486d6f588','\'\'',NULL,1294042),('3_Saturday','14','14:00','14:59','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Clone to Pwn: Remote Badge Cloning with the Flipper Zero\'','\'Langston Clement,Dan Goga\'','Creator Talks_ab3218635c47ffc51fb358814a15ca5d','\'Title: Clone to Pwn: Remote Badge Cloning with the Flipper Zero
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Traditional RFID badge cloning methods require you to be within 3 feet of your target. So how can you conduct a physical penetration test and clone a badge without interacting with a person? Companies have increasingly adopted a hybrid work environment, allowing employees to work remotely, which has decreased the amount of foot traffic in and out of a building at any given time. This session discusses two accessible, entry-level hardware designs you can build in a day and deploy in the field, along with the tried-and-true social engineering techniques that can increase your chances of remotely cloning an RFID badge.

\n\n

Langston and Dan discuss their Red Team adventures using implant devices and their Flipper Zero workflow. As a bonus the two will present a new python script to help you decode your badge data faster. This presentation is supplemented with files and instructions that are available for download in order to build your own standalone gooseneck reader, wall implant and clipboard cloning devices!

\n\nSpeakers:Langston Clement,Dan Goga
\n
\nSpeakerBio:  Langston Clement, Security Risk Advisors (SRA)
\n

Langston grew up reading stories about the 90’s hacker escapades, and after years of observing the scene, he jumped into the offensive security field and never looked back. He is currently a Senior Purple Team Advisor for Security Risk Advisors (SRA). With over fifteen (15) years of public and private sector experience in cybersecurity and ethical hacking, he aims to provide organizations with valuable and actionable information to help improve their security posture. Langston’s specializations focus on modern-day social engineering techniques, wireless and RFID attacks, red teaming, physical penetration testing and purple team engagements.

\n\nSpeakerBio:  Dan Goga, Principal Consultant at NRI North America
\n

Dan Goga serves as a Principal Consultant with NRI focused on conducting penetration testing and red team assessments. Dan Goga has nine years of information security experience in the public, private, and academic sectors. Dan has extensive knowledge and experience with RFID hacking, phishing techniques, social engineering techniques, and penetration testing.

\n\n\nLinks:
    Github - https://github.com/sh0cksec
\n\'',NULL,1294043),('2_Friday','11','11:30','11:59','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Make Money Hacking AI\'','\'Joey Melo,Edward Morris\'','Creator Talks_eeb32888200feb1d10092a3fba17864f','\'Title: Make Money Hacking AI
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

In the past year, I made over $100,000 exclusively hacking AI in competitions and bug bounty platforms. In this talk, I will go over my strategies, my findings, and the techniques that consistently led to high-impact vulnerabilities.

\n\n

Attendees will leave with a practical framework for getting succeeding in AI competitions and getting into AI bug bounty platforms, as well as producing outstanding, slop-free reports.

\n\nSpeakers:Joey Melo,Edward Morris
\n
\nSpeakerBio:  Joey Melo
\n

Joey is a Principal Security Researcher at CrowdStrike and a contributor to AI safety programs at OpenAI and Anthropic. He specializes in offensive security research and adversarial analysis of complex systems, with a particular focus on AI/ML infrastructure and large language models. His work has led to the discovery of critical vulnerabilities and novel exploitation techniques, helping organizations better understand and defend against sophisticated threat actors. He has experience across red teaming, exploit development, and designing resilient architectures for high-risk environments. Joey has earned recognition through bug bounty programs and multiple security competitions, with over $100,000 awarded for vulnerability research. He is also an OSCP, OSCE³ and CRTO-certified professional.

\n\nSpeakerBio:  Edward Morris
\n

Edward Morris is a frontier AI security researcher focused on indirect prompt injection, sandbox escape in IDE and browser agents, and offensive use of LLM agents. He ranks top-3 globally on Mozilla\'s 0DIN GenAI bug bounty program and recently won Meta\'s AI Hacking Challenge at MBBRC 2026 in Taipei, the only researcher of around 200 to solve it. He is an invited researcher in Anthropic\'s and OpenAI\'s AI safety bug bounty programs, and works with BT6, a frontier-AI red team that does pre-deployment testing for major AI labs. His work is finding the attack patterns that break agentic AI before it ships, and turning them into techniques other hunters can use.

\n\n\n\'',NULL,1294044),('3_Saturday','14','14:00','14:30','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Microsoft and Amazon are my Favorite C2 Providers\'','\'Robert Pimentel\'','Creator Talks_34fb284e3bbf8a7e2dcd348116debfe3','\'Title: Microsoft and Amazon are my Favorite C2 Providers
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Cloud relay services are the perfect C2 infrastructure, and most organizations cannot block them without breaking legitimate business operations.

\n\n

This talk presents a comprehensive offensive analysis of three abuse vectors across Microsoft Azure and Amazon Web Services, weaponizing cloud services that enterprises depend on daily for command and control, lateral movement, and persistent access. We target Azure Relay Bridge, AWS IoT Secure Tunneling, and AWS IoT Core MQTT, services whose endpoint domains (*.servicebus.windows.net, *.iot.amazonaws.com) enterprises cannot blocklist without crippling legitimate business operations.

\n\n

I\'ll demonstrate that these are not isolated findings but instances of a repeatable pattern: cloud relay weaponization. Any cloud service that brokers connections through trusted infrastructure, requires only outbound HTTPS, and shares domains with business critical services is a candidate for C2 abuse. I\'ll present the methodology for identifying these services and validated attack chains for each.

\n\n

For Azure Relay Bridge, the attacker deploys azbridge, a legitimate Microsoft-authored, open-source tool, to tunnel arbitrary TCP traffic through Azure\'s relay infrastructure, appearing as standard HTTPS to *.servicebus.windows.net. It installs as a persistent system service across Windows, Linux, and macOS. The abuse here is trust in Microsoft\'s infrastructure and shared service domains, not a pre-existing binary on the host.

\n\n

For AWS IoT, I\'ll present two complementary techniques. First, Secure Tunneling: the attacker uses their own AWS account to create encrypted WebSocket tunnels via the officially published localproxy binary, generating no control plane API activity in the target\'s CloudTrail. I validated this with Sliver C2 across three protocols (mTLS, HTTPS, HTTP), but discovered operational limitations including 12 hour tunnel maximums, token rotation complexity, and IoT optimized bandwidth caps that constrain persistent C2 use. These limitations led to the second technique: weaponizing AWS IoT Core MQTT as a full C2 transport channel using X.509 mutual TLS authentication, which eliminates the tunnel lifetime and bandwidth constraints entirely.

\n\n

I\'ll also present custom Mythic C2 agents (Poseidon for Linux/macOS, Apollo for Windows) with transport profiles for both Azure Relay and AWS IoT MQTT, all end to end validated on AMD64 and ARM64. Live demonstrations showcase complete attack chains: Mythic beaconing through Azure Relay, lateral movement via IoT Secure Tunneling, and persistent C2 over IoT Core MQTT, all through traffic indistinguishable from legitimate cloud service usage.

\n\n

Attendees leave with released Mythic C2 agents and profiles for Azure and AWS, a framework for identifying additional cloud relay services, detection engineering guidance mapped to the Pyramid of Pain, and actionable defensive hardening for both cloud providers.

\n\nSpeakerBio:  Robert Pimentel, Hacker Hermanos
\n

Robert is a seasoned offensive security professional with more than a decade of experience in Information Security.

\n\n

He began his career in the U.S. Marine Corps, where he worked on secure telecommunications. Robert holds a master\'s degree in Cybersecurity, numerous IT certifications, and a background as an instructor at higher education institutions like the New Jersey Institute of Technology and American University.

\n\n

Robert is committed to sharing his knowledge and experiences for the benefit of others. He enjoys Brazilian steakhouses and cuddling with his pugs while writing Infrastructure as Code to automate Red Team Infrastructure.

\n\n

Robert is the Director of Offensive Security at Humana, Inc.

\n\n\n\'',NULL,1294045),('3_Saturday','14','14:00','14:45','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'OT Round table. Real talk on how to protect your OT spaces\'','\'Aaron Crow,Tom VanNorman,Dillon Lee\'','Creator Talks_7dd53210a36620b4b8540324687f9f58','\'Title: OT Round table. Real talk on how to protect your OT spaces
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

A hosted open discussion on strategies for protecting OT with Tom Van Norman and Dillon Lee.

\n\nSpeakers:Aaron Crow,Tom VanNorman,Dillon Lee
\n
\nSpeakerBio:  Aaron Crow, PrOTect IT All
\n

Aaron is the host of the #2 OT Security Podcast \"PrOTect IT All\". Aaron has spent the last decade helping asset owners across utilities, manufacturing, food and beverage, and transportation build OT cybersecurity programs that actually hold up in operational reality, not just on a compliance checklist.\nToday he is the Senior Director at Arcova (formerly MorganFranklin Cyber), leading OT/ICS engagements: assessments, SOC design, NERC CIP, segmentation architecture, and Cyber-Informed Engineering. Before this he was CTO of Industrial Defender, and spent 4+ years at EY running an OT program that included a 3,000-site deployment at a major North American power utility.\nHis podcast, PrOTect IT (100+ episodes, Top Rated by Feedspot in Industrial Security) has featured guests including Mike Holcomb, Sean Tufts, Thomas VanNorman, Jori VanAntwerp, Bryson Bort, Clint Bodungen, and many others. He is a long-time volunteer with ICS Village.

\n\nSpeakerBio:  Tom VanNorman
\n

Tom VanNorman is the co-founded ICS Village and leads the CyPhy Product group at GRIMM, where his primary focus is securing Industrial Control Systems and the networking of such systems. Tom brings an unparalleled level of operational knowledge and experience — he has been working in is the Operational Technology (OT) field for almost three decades. He has considerable expertise in constructing Cyber-Physical testing environments for OT systems.

\n\n

Retired from the Air National Guard after over 20 years of service, where he worked in Cyber Warfare Operations.

\n\nSpeakerBio:  Dillon Lee, Dragos, Inc
\n

Dillon volunteers for ICS Village and works at Dragos as a Principal Technical Account Manager. Throughout the year he volunteers for ICS Village to increase public’s awareness of the need OT systems have for cybersecurity with interactive learning like CTF, TTX, and interactive demos. As a Technical Account manager, he is a specialized product expert who works collaboratively with OT/IT organizations to strategically plan for successful deployments and help realize optimizations of their OT processes.

\n\n\n\'',NULL,1294046),('3_Saturday','14','14:00','14:30','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Racing PX4: Memory Safety and Timing Vulnerabilities\'','\'Nefeli Georgilas\'','Creator Talks_089d191a25ed760d8bcf8335a0cb4e46','\'Title: Racing PX4: Memory Safety and Timing Vulnerabilities
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Commercial off-the-shelf autonomous vehicles range from self-driving trucks to military-grade drones. These systems commonly use the PX4 Autopilot flight stack for flight control, navigation, and telemetry. PX4 is a modular stack where logical functions are placed within components. MAVLink is a protocol that facilitates communication between a vehicle and a Ground Control Station. PX4 and its communication facilities are employed in industrial, as well as military environments, where security and correct real-time operation are paramount. This talk will examine how real-time operations and security may be jeopardized by memory corruption and timing-sensitive vulnerabilities in PX4’s communication and logging subsystems. Further, this talk will present a state desynchronization flaw in the MAVLink logging subsystem, MavlinkUlog. This results in a Denial-of-Service where vital commands cannot be sent to the vehicle, sequence tracking is thrown off, and telemetry is unreliable. Through this talk, the unique implications of these vulnerabilities upon autonomous systems deployed in safety-critical environments will be discussed.

\n\nSpeakerBio:  Nefeli Georgilas
\nNo BIO available
\n\n\'',NULL,1294047),('2_Friday','15','15:30','15:59','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Cleared for Takeoff: Debunking “Uncertifiable” Cybersecurity\'','\'Katie Fejer\'','Creator Talks_56ef86a2f56246361cb4bbbd3b759f19','\'Title: Cleared for Takeoff: Debunking “Uncertifiable” Cybersecurity
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Cybersecurity threats are rapidly becoming a first-order safety concern in critical aviation systems. Increasing in-flight connectivity, satellite communications, and networked avionics have eroded the assumption of airborne isolation. At the same time, AI-generated attacks are lowering both the barrier to entry and the time-to-exploit, enabling faster, more adaptive threat behavior. In contrast, patching and remediation time in aviation systems remains long due to rigorous certification and deployment constraints. This growing asymmetry further elevates cybersecurity risk into a direct safety concern. In this environment, a security risk is a safety risk. This raises a critical question: not whether cybersecurity is needed in aircraft, but whether cybersecurity tools can be certified for safety-critical airborne systems.

\n\n

This talk focuses on the challenge of bridging that gap by asking: can we generate the right verification artifacts to make existing cybersecurity tools certifiable, without modifying their core functionality?\nWe explore why cybersecurity tools are rarely introduced into DAL-A airborne systems in their native form, focusing on the mismatch between operational security outputs and certification evidence requirements. The core problem is not only deterministic behavior, but the lack of structured, complete, and traceable artifacts to support certification arguments.

\n\nSpeakerBio:  Katie Fejer
\nNo BIO available
\n\n\'',NULL,1294048),('4_Sunday','10','10:30','10:59','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty\'','\'Katie Paxton-Fear,Max vonBlankenburg\'','Creator Talks_0e7f06516173a952332d5229f5740529','\'Title: Slop Spotting, Using Rules to Detect AI Slop for Bug Bounty
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

curl ended its HackerOne programme in January 2026 after a steep rise in AI-generated reports overwhelmed a seven-person security team, with some weeks seeing seven reports in sixteen hours, none valid. They were all AI generated; referencing lines of code, real vulnerabilities, and regression of resolved CVEs, they looked legitimate and if that code was actually in the project would have been valid. Every single report wasted the maintainers time and the platform they were using did nothing to help. Triaging them is expensive, slow, and demoralising for the humans at the other end, the only solution? Pay the platform to triage them for you. This talk introduces Slop Spotting: a lightweight triage methodology that uses SAST rule generation as a validity signal. The core insight is simple. If a vulnerability is real and well-specified, you should be able to write a SAST rule for it, and if that code is actually in the codebase, that SAST rule should have a result, if it\'s slop, even convincing slop you get a yes/no answer very quickly across even large codebases.

\n\nSpeakers:Katie Paxton-Fear,Max vonBlankenburg
\n
\nSpeakerBio:  Katie Paxton-Fear, Security Advocate, Semgrep
\n

i used to make applications and now I break them, hacker, bug bounty hunter, and educational YouTuber.

\n\nSpeakerBio:  Max vonBlankenburg, Security Researcher, Semgrep
\n

Max is a security research engineer at Semgrep, doing their best to make software break less. Max has worked with smart contracts, CTFs and the software supply chain. Right now they’re interested in how to use AI to help make security engineering easier and tip the scales towards defenders.

\n\n\n\'',NULL,1294049),('3_Saturday','14','14:30','15:15','N','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'UAiRT: Over The Air UART\'','\'Metehan Arslan,Samet Berk Simsek\'','Creator Talks_2d75798618f3a257004eeb9675fd79a2','\'Title: UAiRT: Over The Air UART
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 15:15 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

The industry relies heavily on zero-trust architectures, TLS tunneling, and WAN monitoring to secure ISP edge gateways. But what happens when the compromise is soldered directly to the motherboard? Introducing Project UAiRT (UART Air interface & Remote Transmission). This presentation explores a devastating supply-chain and physical access attack utilizing a tiny $5 ESP32-C3 microcontroller implanted inside a production grade ISP router. By hardwiring the ESP32 directly to the router\'s internal power rails and UART debug headers, we establish an undetectable, out-of-band Command & Control (C2) bridge that completely bypasses the router\'s internal firewalls and the ISP\'s network monitoring. Project UAiRT is not a dumb serial bridge, it is an intelligent parasite. In this talk, we will demonstrate how to weaponize the ESP32’s additional GPIO pins to create a \"state-aware\" implant. By wiring these pins to the router’s internal status LEDs and reset lines, the UAiRT module actively monitors the router\'s hardware state. Attendees will see a live demonstration of the ESP32 detecting a system reboot via LED voltage changes, calculating the exact microsecond delay, and autonomously firing a carriage return to interrupt the bootloaders. From this stealthy vantage point, we will use covert wireless channels (BLE, hidden Wi-Fi, and ESP-NOW) to remotely trigger filesystem modifications, drop persistent root shells, and hijack the ISP\'s TR-069 management daemon, proving that software security means nothing if the supply chain is compromised by a piece of silicon the size of a thumbnail.

\n\nSpeakers:Metehan Arslan,Samet Berk Simsek
\n
\nSpeakerBio:  Metehan Arslan
\nNo BIO available
\nSpeakerBio:  Samet Berk Simsek
\n

Samet Berk Şimşek is a Turknet Cyber Security Specialist & Web3 Developer

\n\n\n\'',NULL,1294050),('3_Saturday','15','14:30','15:15','Y','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'UAiRT: Over The Air UART\'','\'Metehan Arslan,Samet Berk Simsek\'','Creator Talks_2d75798618f3a257004eeb9675fd79a2','\'\'',NULL,1294051),('3_Saturday','14','14:45','15:30','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Give an AI Industrial Protocol Tools and Watch What It Destroys\'','\'Malav Vyas,Asher Davila\'','Creator Talks_0d793f93d37bd12e915cd29293457f61','\'Title: Give an AI Industrial Protocol Tools and Watch What It Destroys
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:45 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Every major ICS attack of the last decade succeeded not because of software vulnerabilities, but because industrial protocols were built to trust any packet on the wire. The village has read the incident reports. What it doesn\'t have is a way to replay them against its own infrastructure to learn what its detections actually catch and what they miss.

\n\n

We present mrhOTshOT, an open-source framework that emulates history\'s most destructive ICS attacks across the complete kill chain, reconstructed from publicly available incident analyses. Not just the OT payload the full chain: Windows initial access with real CVEs, lateral movement to engineering workstations, protocol-native process manipulation, and persistent physical impact. Every emulation generates wire traffic consistent with publicly documented behavior on the correct industrial protocol for that attack family.

\n\n

The framework spans a wide range of industrial protocols across ten distributed PLCs, each simulating the real-world process that protocol actually controls: a heating district controller for Modbus, a safety instrumented system for TriStation, a centrifuge cascade for S7comm. Nothing runs on a generic simulated tank with ten protocols bolted on.

\n\n

We also introduce the Agentic Attack Emulation Framework: every protocol action is exposed as a callable tool, orchestrated by an LLM agent that reads live process state and composes attack sequences on the fly. No hardcoded playbook, you decide. This is what AI-assisted ICS attack composition looks like, and defenders need to understand it before they meet it in the wild.

\n\n

The talk closes with a live demo: three centrifuges destroyed in real time while the operator HMI, deceived by an S7 rootkit, shows normal operation throughout, until it doesn\'t.

\n\nSpeakers:Malav Vyas,Asher Davila
\n
\nSpeakerBio:  Malav Vyas, Palo Alto Networks
\n

OT and IoT security researcher. I spend my time hunting vulnerabilities, crafting exploits, and pushing the boundaries of ecosystem security. When I’m not breaking things, I’m helping run the show with the Null, BSides, and OWASP communities. Catch me at the villages.

\n\nSpeakerBio:  Asher Davila, Vulnerability Researcher at Palo Alto Networks
\n

Passionate about binary analysis, binary exploitation, reverse engineering, hardware hacking, retro computing, and music.

\n\n\n\'',NULL,1294052),('3_Saturday','15','14:45','15:30','Y','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Give an AI Industrial Protocol Tools and Watch What It Destroys\'','\'Malav Vyas,Asher Davila\'','Creator Talks_0d793f93d37bd12e915cd29293457f61','\'\'',NULL,1294053),('3_Saturday','15','15:00','15:30','N','Biohacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'AIRGAP BREACHED: Monitoring the Ancestral Payload Leaking from the Poles\'','\'David J. Castillo-Cornejo,Matthew Woslum,Zee Zinck\'','Creator Talks_88edeee3d0e08ddddc22330c28484be9','\'Title: AIRGAP BREACHED: Monitoring the Ancestral Payload Leaking from the Poles
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

A frugal, eDNA sniffing system to audit atmospheric biodata-leaks in the era of Climate change.

\n\n

Current healthcare cybersecurity focuses on device access, ignoring the fundamental vulnerability: the environmental air gap is closing. Massive cryospheric melting is releasing a backlog of ancestral genetic data (eDNA) into the biosphere, creating an unmonitored \'input stream\' of allergens and pathogens. This talk presents a resilient, open-source eDNA monitoring system designed to audit these atmospheric \'data leaks\' in real-time. By utilizing high-fidelity open-source and decentralized brewed polymerases and consumer electronics, we provide a solution for biological sovereignty that remains operational even when traditional digital infrastructure fails.

\n\n

Here, we will present how to build global atmospheric monitoring networks for under $500 USD to intercept \"paleo-organisms\"—dormant bacteria and viruses released by melting poles—using shotgun metagenomics, 3D-printed parts, and microcontrollers. Essentially, he catches genetic ghosts in the air before they trigger the next global health crisis. This projects aims to tackle a sci-fi level threat: Facing the looming ecological danger of \"polar amplification,\" David is developing open-source hardware together with Biohackers at BioOlympia (Olympia Washington), to capture and sequence ancient or threatening environmental DNA (eDNA). His atmospheric biosensors combine high-precision 3D printing, fluid dynamics, and embedded systems to track clouds of paleo-biomass and frozen microorganisms waking up from the ice or perturbed ecosystems. Along with studies in environmental science, biology, and Geographic Information systems, BioOlympia also operates a fully equipped BSL-2 research environment.

\n\nSpeakers:David J. Castillo-Cornejo,Matthew Woslum,Zee Zinck
\n
\nSpeakerBio:  David J. Castillo-Cornejo
\n

David is a biomedical scientist with experiences at the Max Planck Institute, Osaka University and ASU. He is the founder of Glyxon Biolabs. BioOlympia is a [Bio]Punk laboratory. The lab conducts advanced research in mammalian cell biology, CRISPR-based gene editing, and regenerative medicine.

\n\nSpeakerBio:  Matthew Woslum
\n

Matt Woslum and Zee Zinck are founders of BioOlympia, a [Bio]Punk laboratory. Their lab conducts advanced research in mammalian cell biology, CRISPR-based gene editing, and regenerative medicine.

\n\nSpeakerBio:  Zee Zinck
\n

Matt Woslum and Zee Zinck are founders of BioOlympia, a [Bio]Punk laboratory. Their lab conducts advanced research in mammalian cell biology, CRISPR-based gene editing, and regenerative medicine.

\n\n\n\'',NULL,1294054),('3_Saturday','15','15:15','15:59','N','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Beyond Your Bookshelf: Hackable eReaders\'','\'Katie Paxton-Fear\'','Creator Talks_0ca0d8c06ae997e25ff56ab82db2bc1e','\'Title: Beyond Your Bookshelf: Hackable eReaders
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:15 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Kindles, Kobos, Boox and BigMes there\'s no shortage of eReaders to choose from in 2026, with their paper-like eInk displays designed for one thing: reading books. But under the surface of these minimalist devices is a surprisingly hackable device. From Kindle jailbreaks, to Android apps, to flashing custom firmware. We\'ll take that dust-gathering device off of your nightstand and onto your lab bench to talk about the vulnerabilities and customisability of these devices.

\n\nSpeakerBio:  Katie Paxton-Fear, Security Advocate, Semgrep
\n

i used to make applications and now I break them, hacker, bug bounty hunter, and educational YouTuber.

\n\n\n\'',NULL,1294055),('3_Saturday','15','15:30','15:59','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Cl0p ^_- Til You Drop - 6 years, 9 Campaigns, 7 0-Days\'','\'Eli Woodward\'','Creator Talks_05bf2661cc1ca43031d3c2b8465c92c8','\'Title: Cl0p ^_- Til You Drop - 6 years, 9 Campaigns, 7 0-Days
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Cl0p has executed at least nine major exploitation campaigns since 2020, targeting file transfer and edge devices from Accellion to MOVEit to Centrestack. Each campaign looks different on the surface, different CVEs, different victims, different tooling. But their infrastructure tells a different story.

\n\n

This talk presents the results of a multi-year infrastructure reconnaissance effort tracking Cl0p\'s hosting, ASN usage, and operational patterns across all known campaigns. By mining passive DNS data, network telemetry, and hosting records, I mapped the infrastructure behind each campaign and identified patterns the group can\'t seem to shake — including a favorite bulletproof hosting provider used across four separate campaigns, a finding that roughly one-third of their ASNs get recycled, and pre-attack reconnaissance probing observed as far as two years before exploitation.

\n\nSpeakerBio:  Eli Woodward, Senior Threat Intelligence Advisor with Team Cymru
\n

Eli Woodward is a cyber threat intelligence advisor with Team Cymru. He\'s worked in a variety of industries including financial services and government, and has seen the range of organizations from extremely well-resourced and capable to the shoestring budget. This has given him unique insights into CTI at all levels of complexity, maturity, and resources. He holds a master\'s degree in Intelligence and Security Studies and also plays bagpipes competitively.

\n\n\n\'',NULL,1294056),('2_Friday','10','10:00','10:45','N','Biohacking Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Counting the Dead in the Digital Siege: Detection Infrastructure for Cyber-Mapping Patient Harm\'','\'Jorge Acevedo Canabal,Scott Shackelford,Szymon Skalski\'','Creator Talks_e761dfe2e620fa13c9100df5ae0de07d','\'Title: Counting the Dead in the Digital Siege: Detection Infrastructure for Cyber-Mapping Patient Harm
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Ransomware Kills Patients. We Can\'t Prove It. Here\'s How We Fix That.

\n\n

Ransomware attacks on hospitals kill people. That\'s not a hypothesis — it\'s in the data. A peer-reviewed analysis of Medicare claims (American Economic Journal: Economic Policy, 2026) puts in-hospital mortality at 34 to 38 percent higher during attacks. The dead are disproportionately elderly, critically ill, and patients of color. Dameff et al. (2023) documented emergency department spillover. Neprash, Dameff, and Tully (2024) traced the same pattern through the Change Healthcare attack.

\n\n

The mechanism isn\'t exotic. Encrypted EHRs mean clinicians are flying blind — no medication history, no imaging, no labs. Networked infusion pumps, ventilators, and monitors drop to manual. Ambulances get diverted, stacking patients at facilities that weren\'t hit. In rural areas, transfer times go from nine minutes to thirty-three.\nHere\'s the deeper problem: these deaths are architecturally invisible.

\n\n

No ICD code exists for \"died because the hospital\'s network was encrypted.\" No death certificate asks whether the hospital was under cyberattack. No public health surveillance system captures excess mortality from clinical failure caused by ransomware. Mandatory reporting requirements attach to data breach — not patient harm. Voluntary harm-reporting channels exist, but they\'re anonymous and sporadic. The visible signal is a fraction of what\'s actually happening.

\n\n

This isn\'t a technical gap. It\'s a design failure in the detection infrastructure itself.

\n\n

This talk makes the case for cyber-harm epidemiology. Using a forthcoming law review article, we show that existing systems — ICD external-cause coding, NCHS disaster-death certification, SNOMED CT alignment, the Sendai Framework\'s Hazard Information Profiles (2025) and Global Disaster-Related Statistics Framework (2026) — can be adapted right now to make cyber-attributable patient deaths visible at population scale. No new treaties required.

\n\n

Better detection produces better attribution. Better attribution makes state obligations under the right to life and the protection of medical units enforceable — not aspirational.

\n\n

The deaths are real. The tools to count them exist. We just haven\'t connected them yet. That\'s what this talk is about.

\n\nSpeakers:Jorge Acevedo Canabal,Scott Shackelford,Szymon Skalski
\n
\nSpeakerBio:  Jorge Acevedo Canabal, Ostrom Workshop Indiana University US
\n

Jorge Acevedo Canabal, MD (University of Puerto Rico School of Medicine, Magna Cum Laude), is a physician and Visiting Scholar at the Ostrom Workshop, Indiana University, working on research that sits at the intersection of healthcare, public health, and cybersecurity, applying epidemiological and disaster medicine methods to map patient harm attributable to healthcare cyberattacks and technological hazards. He previously served as Chief Medical Officer of the Puerto Rico Science, Technology and Research Trust, and currently serves as advisor to the Biohacking Village and Raíces Cyber Org.

\n\nSpeakerBio:  Scott Shackelford
\n

Scott J. Shackelford is Associate Vice President and Vice Chancellor for Research at Indiana University Bloomington and Provost Professor of Business Law & Ethics at the IU Kelley School of Business. He serves as Executive Director of both the Ostrom Workshop and the Center for Applied Cybersecurity Research, and directs the Ostrom Workshop Program on Cybersecurity & Internet Governance. He is also an Affiliated Scholar at Harvard Kennedy School\'s Belfer Center and Stanford\'s Center for Internet and Society. Scott has authored over 100 articles, book chapters, and essays, with research featured in Politico, NPR, CNN, Forbes, Time, and the Washington Post. His books include The Internet of Things: What Everyone Needs to Know (2020) and Managing Cyber Attacks in International Law, Business, and Relations (2014). His honors include a Harvard Research Fellowship, a Stanford Hoover National Fellowship, the 2015 Elinor Ostrom Award, and the 2022 Poets & Quants Best 40-Under-40 MBA Professors Award.

\n\nSpeakerBio:  Szymon Skalski, Jagiellonian University PL
\n

Szymon is a PhD Candidate in the School of Social Sciences at Jagiellonian University and a Senior Expert and NASK National Research Institute in Poland. He is also affiliated with the Ostrom Workshop at Indiana University, where he leads the working group on Environmental Security and Technological Risk in Conflict. He has served on cybersecurity expert panels at the Polish Ministry of Digital Affairs and the Polish Bank Association. He is also a fellow of the European Law Institute, member of FIDMA and Virtual Routes European PhD Cybersecurity Accelerator Programme. For the past three years, he has participated in NATO’s Locked Shields exercises, representing Poland for two years and, in 2026, organizing the exercises on behalf of the CCDCOE in the legal domain.He is a researcher and scholarship holder of grants from the National Science Centre in Poland in the fields of insurance and digital security. He publishes in international academic journals in the fields of cybersecurity, insurance, tort law, and international law.

\n\n\n\'',NULL,1294057),('3_Saturday','15','15:30','15:59','N','Car Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'The Compiler Nobody Satisfactorily Tested: Supply-Chain Gaps in EV Charging Firmware\'','\'Kangwon Lee\'','Creator Talks_e4f5b7b1b9e6a7d1f7a8784614e1e9a8','\'Title: The Compiler Nobody Satisfactorily Tested: Supply-Chain Gaps in EV Charging Firmware
\nTags: Car Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Someone installed Doom on a supercharger at Pwn2Own Automotive 2026 — via an out-of-bounds write in firmware compiled by a compiler nobody verified. This talk connects the dots between Pwn2Own exploit classes and the upstream problem: most automotive and EVSE compilers have never been independently tested against safety or security standards. I will present a map of which compilers are actually qualified, where the coverage gaps are, and why Rust\'s memory safety guarantees matter less than you think if the compiler itself isn\'t verified. The talk closes with a practical trust chain — develop, compile, verify, review — that the security community can use to evaluate toolchain integrity.

\n\nSpeakerBio:  Kangwon Lee, Life Member of OWASP
\n

In computing since \'86 (HS computer club → EMPAL BBS → Yonsei). Radar application algorithms at Autoliv, embedded SW at Hyundai Motor. Now Associate Prof at TU Korea, interested in Rust compiler qualification for safety-critical ITS. IEEE ITSS Korea Chapter Chair, IEEE P3538 WG Secretary, OWASP lifetime member, ISC2 CC. Sits on Korea\'s government committee on motor vehicle safety defects. Ph.D. ME + M.S. EECS, U of Michigan.

\n\n\n\'',NULL,1294058),('3_Saturday','16','16:00','16:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Breaking Ciphers and Zero-Knowledge Proofs\'','\'Luke Szramowski,Diego \"rehrar\" Salazar,Rigo Salazar\'','Creator Talks_e9034f22b7e622f035026e0277a6a982','\'Title: Breaking Ciphers and Zero-Knowledge Proofs
\nTags: Cryptocurrency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Zero-knowledge proofs are a method of demonstrating that a statement is true, without revealing any other information about it, and form the backbone of all the cryptocurrencies we know and love. In this workshop, we will unpack what zero-knowledge proofs really are, how they work, and what they do to ensure that your personal information remains private. A familiarity with basic cryptography is helpful, but not strictly necessary.

\n\nSpeakers:Luke Szramowski,Diego \"rehrar\" Salazar,Rigo Salazar
\n
\nSpeakerBio:  Luke Szramowski, Cypher Stack
\n

Luke Szramowski is a mathematical researcher, with a Bachelor\'s Degree in Mathematics and two Master\'s Degrees, one in Math, with a focus in Number Theory and another in Math with a focus in Coding Theory. In his free time, Luke works on a litany of different math problems, mainly regarding Number Theoretic conjectures and playing all different types of games.

\n\nSpeakerBio:  Diego \"rehrar\" Salazar, Cypher Stack
\n

Diego \'rehrar\' Salazar has been around the FOSS and cryptocurrency communities for eight years. He owns and runs Cypher Stack, a company that performs novel research and makes contributions to various FOSS projects. He has organized and managed several villages at defcon, c3, and more.

\n\nSpeakerBio:  Rigo Salazar, Cypher Stack
\n

Rigo earned his graduate degree in mathematics and has been dipping in and out of the cryptocurrency space since 2019. As the manager of a separate company (in a non-competing field), he only works part-time with Cypher Stack, with the hope to make a full transition in the future. He also has the exclusive brother right to bust Diego\'s chops, which makes him invaluable to the team.

\n\n\n\'',NULL,1294059),('3_Saturday','16','16:00','16:30','N','Car Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Free IP, Free Chaos: DHCP-Assisted Flooding Against Automotive Ethernet\'','\'Yehyeong Lee\'','Creator Talks_1d3067ce4bbc4ad8bdf04dc1b7aee95c','\'Title: Free IP, Free Chaos: DHCP-Assisted Flooding Against Automotive Ethernet
\nTags: Car Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Modern vehicles are increasingly adopting Automotive Ethernet for UDS-based diagnostics instead of CAN.\nWhile Gateway ECUs are designed to restrict communication to specific IPs, some support DHCP to facilitate communication with diagnostic tools.\nThis DHCP support allows an attacker to deploy a rogue DHCP server via the OBD Ethernet interface, assigning a controlled IP to the Gateway ECU and enabling network-level attacks without any prior knowledge of the vehicle\'s internal network.\nIn this talk, we demonstrate that high-rate Layer 2/3 flooding — regardless of protocol (ARP, ICMP, UDP, TCP) — disrupts safety-critical systems including AVN, wipers, headlights, and causes abrupt stopping when shifted into Drive or Reverse, and that at higher packet rates the infotainment display blacks out and does not recover until fully powered down.\nWe discovered these findings on a production vehicle and have prepared a demo.

\n\nSpeakerBio:  Yehyeong Lee, Autocrypt Inc.
\n

Yehyeong Lee is a cybersecurity engineer specializing in automotive security and embedded systems.\nHe focuses on vulnerability analysis and penetration testing of vehicle ECUs and in-vehicle networks.\nHis work includes real-world vehicle security testing and automotive network attacks.\nHis research interests include automotive security, firmware analysis, and embedded system security.

\n\n\nLinks:
    Github - https://github.com/LYHyoung
\n\'',NULL,1294060),('3_Saturday','16','16:00','16:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Shipcrawler: Automated Maritime OSINT — From Open Data to Actionable Intelligence\'','\'Ahmed Nagi Nasr\'','Creator Talks_01b8ed648a65e071ed969656c9bcd224','\'Title: Shipcrawler: Automated Maritime OSINT — From Open Data to Actionable Intelligence
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

The maritime sector leaks an enormous amount of sensitive information through public sources — crew social media, vessel tracking data, port records, corporate registries, and leaked credentials. Shipcrawler is an open-source automated OSINT tool that aggregates, correlates, and reports on vessel, crew, company, and port authority intelligence from publicly available sources. Built with a queue-based architecture and AI Agent-powered worker pipeline, it has produced over seven comprehensive intelligence reports covering vessels, port authorities, and maritime personnel. This talk demonstrates OSINT collection against maritime targets, discusses the ethical and operational implications of maritime data exposure, and shows how OSINT audits can inform defensive posture improvements. All code and methodologies are open-source to help the maritime community understand their own attack surface.

\n\nSpeakerBio:  Ahmed Nagi Nasr, Estonian Maritime Academy - Tallinn University of Technology (TalTech)
\n

Maritime cybersecurity researcher at TalTech, author of Shipcrawler and Project Haris. Published in IEEE Access, TransNav, J. Marine Science. Focused on open-source defense tools for maritime IT/OT security.

\n\n\n\'',NULL,1294061),('3_Saturday','16','16:00','16:59','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Zero-Knowledge Unsaflok: The Unsaflok Saga Continues\'','\'Ben Higgins,Aaron Tulino\'','Creator Talks_2736e2d8a3ad780d4bad7d8cab18d682','\'Title: Zero-Knowledge Unsaflok: The Unsaflok Saga Continues
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Continuing the legacy of the previous two Unsaflok research teams, we expanded the original Unsaflok attack to a zero-knowledge exploit by mimicking the HH6 maintenance unit’s lock interrogation protocol. The HH6 is normally used by hotel staff to diagnose lock errors and problems, but it also has the capability to retrieve the Property ID from the lock. Previously, a hotel card from the property was required to perform the exploit as the cards were the only way to get the Property ID value, but replicating the HH6 protocol to directly extract the necessary information directly from the lock removes this limitation. After messing with voltage glitching and EMFI for HH6 firmware recovery, we dug into the binaries to produce an extremely fast, zero knowledge, undetectable Unsaflok attack using a Flipper Zero.

\n\nSpeakers:Ben Higgins,Aaron Tulino
\n
\nSpeakerBio:  Ben Higgins, Embry-Riddle Aeronautical University, Prescott Campus
\n

Ben is an undergraduate at Embry Riddle Aeronautical University Prescott Campus, and is very new to this kind of security research. He spends most of his time in this field researching access control and RFID.

\n\nSpeakerBio:  Aaron Tulino, Embry-Riddle Aeronautical University, Prescott Campus
\n

Aaron is an undergraduate at Embry Riddle Aeronautical University Prescott Campus. He has experience in reverse engineering, software development, and software security, but is relatively new to the RFID field.

\n\n\n\'',NULL,1294062),('2_Friday','16','16:00','16:30','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Building a State Wide VDP: Lessons from Maryland\'s First Year in the Trenches\'','\'01dbae\'','Creator Talks_6731364a61353bbb91704b120221d626','\'Title: Building a State Wide VDP: Lessons from Maryland\'s First Year in the Trenches
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

State and local governments are soft targets. Smaller security teams, legacy infrastructure, high-value data, and tight budgets make them attractive to adversaries. Yet most lack basic proactive security programs like Vulnerability Disclosure Programs (VDPs). In January 2025, I was hired as Maryland\'s first Adversary Emulation Manager and tasked with standing up a statewide VDP. Coming from DoD cyber operations but new to the bug bounty space, I had to figure out how to build a program that would actually work, not just check a compliance box. The result: Maryland\'s VDP launched in October 2025 and has been a success because we fought for true safe harbor, assumed noble intent, and took a researcher-first approach. This talk shares what I learned building the program from scratch. I\'ll cover the hard conversations with legal teams who feared \"authorizing hacking,\" the fights for wide scope instead of narrow carve-outs, and why safe harbor isn\'t optional. If you\'re a state or local practitioner, you\'ll walk away with a replication guide. If you\'re a policymaker, you\'ll understand why VDPs matter. If you\'re a researcher, you\'ll see what makes programs succeed or fail.

\n\nSpeakerBio:  01dbae
\n

01dbae has worked in technology since the early 2000s, spanning data center operations, private cloud computing, and information security. After moving into security at a large publisher, he transitioned into government contracting and later served as a DoD civilian supporting the cyber counterintelligence mission. He also spent a few seasons with the Baltimore Ravens.

\n\n

01dbae later joined the State of Maryland as Adversary Emulation Manager, tasked with standing up the state\'s first Vulnerability Disclosure Program — despite having never run a bug bounty program before. That outsider perspective helped him challenge assumptions and push for researcher-first policies over compliance theater. The program launched with strong safe harbor protections and broad scope, and has been running successfully since. There are lessons in that process worth sharing with other state and local governments building proactive security programs

\n\n\n\'',NULL,1294063),('3_Saturday','16','16:30','16:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'LSTM Autoencoder Ensemble for NMEA 2000 Intrusion Detection on Vessel Networks\'','\'Anissa Elias,James Campbell\'','Creator Talks_26675dfb62ad7e00eb7af47f847b8216','\'Title: LSTM Autoencoder Ensemble for NMEA 2000 Intrusion Detection on Vessel Networks
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Maritime vessels increasingly depend on NMEA 2000 (CAN bus) networks to interconnect navigation, propulsion, and safety-critical systems, yet the underlying protocol provides no authentication, any device can transmit any message ID. As maritime cyber incidents such as GPS spoofing, engine manipulation, and AIS attacks become more frequent, existing automotive CAN intrusion detection systems fall short because they fail to model maritime-specific traffic behavior, including variable RPM, long duty cycles, and sensor drift. We present a multi-modal LSTM autoencoder ensemble in which four specialized models independently monitor message timing, payload content, frequency, and device-level behavior. Each autoencoder learns normal operating patterns and flags anomalies via reconstruction error, with a majority-voting aggregator raising an alert when at least two of four components agree. Detection thresholds are set automatically at the 99th percentile of validation error, requiring no labeled attack data. The system was evaluated on a 24-hour continuous capture from an operating vessel comprising 9.16 million messages across 24 PGNs and three source devices, spanning a full operational cycle and six simulated attack types. Using 5-fold temporal cross-validation, the ensemble achieved an F1 score of 0.964 (95% CI: 0.952–0.976) and ROC-AUC of 0.991, while reducing variance 28× relative to a single-model baseline. The unsupervised threshold matched supervised tuning (F1=0.965 vs. 0.971) without attack labels, and a novel network drift detection module identified unauthorized hardware changes with perfect accuracy (F1=1.000) across 120 trials. With 38.76 ms inference latency, the approach is suitable for real-time onboard monitoring. Future work includes voltage fingerprinting, live deployment, and transfer learning.

\n\nSpeakers:Anissa Elias,James Campbell
\n
\nSpeakerBio:  Anissa Elias, University of Rhode Island
\n

Anissa Elias is a Research Engineer and Ph.D. researcher specializing in maritime cyber-physical system security, autonomous monitoring, and on-edge AI. Her work focuses on securing underwater and maritime systems through real-time anomaly detection, embedded intelligence, and resilient network architectures. She has deep experience with maritime network analysis, digital twins, and deployable AI for resource constrained environments. Anissa brings a strong background in defense-focused research, autonomous system security, and AI trust and compliance for naval and maritime operations.

\n\nSpeakerBio:  James Campbell, Independent Researcher
\n

James (Soups) Campbell is a Red Team Operator for the US Coast Guard, specializing in malware research, offensive tool development, and OT cybersecurity. In his free time, he can be found building autonomous vessels, hacking on boats, and playing with his very energetic puppy.

\n\n\n\'',NULL,1294064),('3_Saturday','16','16:30','17:30','N','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Weaponization of Cellular Based IoT Technology – Leveraging Smart Devices to Gain a Foothold\'','\'Carlota Bindner,Deral Heiland\'','Creator Talks_2080e6a386423b35bdf8e3ff58982539','\'Title: Weaponization of Cellular Based IoT Technology – Leveraging Smart Devices to Gain a Foothold
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:30 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

As IoT devices continue to integrate cellular technologies for communication, the potential risk for adversaries to weaponize the hardware’s trust relationship and gain access to critical backend infrastructure grows exponentially. During this talk, we will present our research focused on how built-in cellular technology in IoT devices can be leveraged to gain access to and execute attacks against cloud services and backend private network environments. We will cover methods to modify IoT devices to take control over the installed cellular modules, allowing for injecting communications and establishing Man-in-the-Middle (MitM) traffic between the Micro Controller Units (MCU) and the cellular modules. We will demonstrate how control of onboard cellular communications could be used to launch attacks against the backend cloud infrastructure and network systems outside of the IoT device\'s intended purpose. During this presentation, we will demo and release proof-of-concept code to control the onboard cellular modules to accomplish these goals. We will also provide actionable defense strategies, including discussions around hardware design recommendations, interface access control settings, and methods for applying targeted mitigation techniques and processes so organizations can strengthen IoT trust boundaries and protect against this evolving class of cellular-based threats.

\n\nSpeakers:Carlota Bindner,Deral Heiland
\n
\nSpeakerBio:  Carlota Bindner
\nNo BIO available
\nSpeakerBio:  Deral Heiland, Rapid7
\n

Deral Heiland CISSP, serves as a Principal Security Researcher (IoT) for Rapid7. Deral has over 25 years of experience in the Information Technology field, and over the last 15+ years Deral’s career has focused on security research, security assessments, penetration testing, and consulting for corporations and government agencies. Deral also has conducted security research on numerous technical subjects, releasing white papers, security advisories, and has presented the information at numerous national and international security conferences including Blackhat, Defcon, Shmoocon, DerbyCon, RSAC, Hack in Paris. Deral has been interviewed and quoted by several media outlets and publications including ABC World News Tonight, BBC, Consumer Reports, MIT Technical Review, SC Magazine, and The Register.

\n\n\n\'',NULL,1294065),('3_Saturday','17','16:30','17:30','Y','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Weaponization of Cellular Based IoT Technology – Leveraging Smart Devices to Gain a Foothold\'','\'Carlota Bindner,Deral Heiland\'','Creator Talks_2080e6a386423b35bdf8e3ff58982539','\'\'',NULL,1294066),('3_Saturday','17','17:00','17:30','N','Policy @ DEF CON','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'AI Safety Theater: What the RAISE Act Regulates — and What It Does Not\'','\'Joshua Marpet\'','Creator Talks_01b43e82ea98939b99beff5abf1dfad4','\'Title: AI Safety Theater: What the RAISE Act Regulates — and What It Does Not
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

New York\'s RAISE Act is among the most significant state AI safety laws in the country. Signed December 19, 2025, it imposes transparency requirements, safety plans, 72-hour incident reporting, and annual audits on frontier AI developers. It took effect 8 days after a presidential executive order authorizing the DOJ to challenge state AI laws. This talk applies the security researcher\'s methodology: map the surface, find the gaps, assess whether compliance cost is proportionate to actual risk reduction. The structural gaps are specific. The $500M revenue threshold excludes the most aggressive AI capability development — well-capitalized but pre-revenue. The 10²⁶ FLOPs definition may not capture dangerous fine-tuned derivatives of frontier models. The catastrophic harm threshold requires 100+ deaths before reporting obligations attach — the alarm fires after the building has already burned. And the law requires transparency, not prohibition: a fully compliant developer can keep operating a system causing significant sub-catastrophic harm. 12 or more states are expected to model AI legislation on New York and California in 2026. If the security community does not engage critically with what this law actually does, those copies will inherit its gaps.

\n\nSpeakerBio:  Joshua Marpet, Finite State
\n

Joshua Marpet is Senior Product Security Consultant at Finite State, co-host of Paul\'s Security Weekly and Security Weekly News, and a CMMC co-author. He holds membership on the IEEE/UL 2933 and SPDX standards committees and serves on the boards of BSidesDE, Skytalks, and the Value Chain Risk Institute. A former police officer, firefighter, and Federal Reserve Bank of Philadelphia security analyst, he works at the intersection of security standards, policy, and operational practice.

\n\n\n\'',NULL,1294067),('3_Saturday','17','17:00','17:30','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Behind the Badge: SAOv3 and Open Sourcing the Aerospace Village Badge\'','\'Adam Batori,Kevin Colley,Robert Pafford,Lillian Ash Baker\'','Creator Talks_86a8e82fa2009517633013825c799c8f','\'Title: Behind the Badge: SAOv3 and Open Sourcing the Aerospace Village Badge
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

The Rare Circuits team decided this was the year to take all our hard work on last year’s Aerospace Village Radio SAO and open source the useful components for the Badge Maker Community. We took the tight communication integration between badge and Add-on to create SAOv3, a new SAO standard that puts connectivity right at the forefront. ANSM, our framework to create silky smooth pixel animations and interfaces for embedded systems, is ready for everyone to use. We are even releasing our circuit and driver to make the SH1106 OLED update smoothly and enables 4-level greyscale.

\n\nSpeakers:Adam Batori,Kevin Colley,Robert Pafford,Lillian Ash Baker
\n
\nSpeakerBio:  Adam Batori
\nNo BIO available
\nSpeakerBio:  Kevin Colley
\nNo BIO available
\nSpeakerBio:  Robert Pafford
\nNo BIO available
\nSpeakerBio:  Lillian Ash Baker
\nNo BIO available
\n\n\'',NULL,1294068),('3_Saturday','17','17:00','17:30','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'CyberKB: When Your AI Copilot Runs the Recon, Crawls the Dark Web, and Maps the Kill Chain\'','\'Suriya Prasath S,Chandru J,Muthu Kumar\'','Creator Talks_d90e50f7d3c6cc07d6b852c3dc45a750','\'Title: CyberKB: When Your AI Copilot Runs the Recon, Crawls the Dark Web, and Maps the Kill Chain
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

What if your recon tool could understand \"find leaked credentials for this company on the dark web, cross-reference with their exposed infrastructure, and show me the attack path\" — and then actually do it, autonomously, with zero manual commands?\nCyberKB is a 214,000-line open platform that puts an AI copilot (Keke) in command of 131 offensive tools spanning reconnaissance, dark web OSINT, Shodan intelligence, breach databases, and a full Kali Linux shell — all orchestrated through natural language conversation.\nThe Dark Web Intelligence Pipeline (DarkMonitor):\nCyberKB\'s DarkMonitor module queries .onion search engines concurrently through Tor, uses LLM-powered query refinement to generate optimal dark web search terms, applies AI relevance filtering to surface the most critical results.

\n\n

The AI Copilot (Keke):\nKeke isn\'t a wrapper around ChatGPT. It\'s a function-calling agent with direct execution access to: a privileged Kali container (nmap, curl, nikto, sqlmap, gobuster, hydra — the full toolkit), 16 dark web search engines via Tor, breach and paste database aggregators, a RAG-powered knowledge base with semantic search over ingested recon data, Shodan lookups and CVE correlation, MITRE ATT&CK technique mapping, attack graph generation and path prioritization, and engagement management (targets, credentials, findings, reports).

\n\n

Scale Proof — 2,250-Domain Assessment:\nWe demonstrate CyberKB against a real-world external attack surface assessment: 2,250 domains belonging to a single organization, producing 11,968 unique IPs, 8,494 hostnames, 2,444 CVEs, 80,238 open ports, and a knowledge graph of 6,390 nodes with 51,990 infrastructure relationship edges. The entire dataset was parsed, correlated, and ingested into the AI-queryable knowledge base in 25 seconds. Keke can now answer questions like \"which x domains share infrastructure with known-vulnerable IPs\" by searching the graph, not by re-scanning.

\n\n

What This Means for Defenders:\nEvery autonomous recon step Keke performs leaves detectable artifacts. We discuss what blue teams should monitor: DNS burst patterns from multi-engine enumeration, Tor exit node correlation with target infrastructure, behavioral signatures of AI-driven sequential probing, and how to distinguish human recon from autonomous agent recon. The same platform that empowers red teams reveals the detection surface that defenders can leverage.

\n\n

Key Takeaways:\n1. AI copilots with direct tool execution compress hours of reconnaissance into minutes of conversation — fundamentally changing the operator\'s role from command executor to strategic decision-maker.\n2. Dark web OSINT can be systematically automated with LLM-driven search refinement and relevance filtering, making it accessible beyond specialized analysts.\n3. Infrastructure-scale attack surface mapping (2,250+ domains) becomes practical when AI handles correlation instead of humans.\n4. Autonomous recon creates detectable patterns that blue teams should be actively hunting for.\nTool Stack: Python, Flask, ChromaDB (RAG), Docker (Kali + Tor + Browser Agent), OpenAI-compatible LLM API, SQLite, Playwright, BeautifulSoup. 105 Python modules. Fully self-hosted — no cloud dependencies for core functionality.

\n\nSpeakers:Suriya Prasath S,Chandru J,Muthu Kumar
\n
\nSpeakerBio:  Suriya Prasath S, zoho, red teamer, manager
\n

A Red Teamer and Security Manager at Zoho CRM–Red Team, with 6+ years of experience driving adversarial simulations and real-world attack emulation at scale. He focuses on uncovering critical security gaps by thinking like an attacker—blending deep technical expertise with practical red team operations to challenge assumptions and strengthen defences.

\n\nSpeakerBio:  Chandru J, Zoho, Product Security Manager
\n

Product Security Manager with over 12 years of experience in driving cybersecurity initiatives, enhancing organizational security posture, and ensuring compliance with international standards such as ISO 27001, SOC 2, and GDPR. Adept at leading and mentoring teams, managing enterprise-wide security programs, and developing in-house security tools to address vulnerabilities effectively. Proven expertise in vulnerability management, incident response, security governance, and implementing secure development lifecycle (SDLC) practices. Recognized for fostering a security-first culture and collaborating with cross-functional teams to mitigate risks, protect assets, and improve processes in rapidly evolving environments.

\n\nSpeakerBio:  Muthu Kumar, Security Engineer
\n

I am a Security Engineer with 10 years of experience specializing in web application security and security tool development. I have extensive experience identifying security vulnerabilities, improving secure development practices, and building tools that help organizations detect and prevent security risks at scale.

\n\n

My expertise includes application security testing, secure code reviews, threat modeling, vulnerability assessment, and developing security automation solutions that reduce manual effort and improve detection accuracy. I have worked on enhancing security tools by reducing false positives and helping engineering teams address vulnerabilities more efficiently.

\n\n

I am passionate about building secure systems and solving complex security challenges through automation, innovation, and practical security engineering approaches. My focus is on strengthening application security while enabling development teams to build and ship secure products faster.

\n\n\n\'',NULL,1294069),('4_Sunday','10','10:00','10:30','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Breaking In, Evil Style: A Guide to Scaring Your CEO\'','\'Andrew Lebedinsky\'','Creator Talks_99c280bbb5bc7e27dd81d8491af87560','\'Title: Breaking In, Evil Style: A Guide to Scaring Your CEO
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

You\'ve cloned the keycards, you\'ve bypassed the locks, and you\'ve gotten into the building. Now what?

\n\n

Convincing people to actually fix the security issues you find is always an uphill battle. It\'s even worse in the world of physical security, where installing new locks costs more than deploying a software patch. This talk will explore how to make your physical red teaming activity scare the $hit out of your executives. We\'ll establish persistence, pivot to the network, steal everything that isn\'t nailed down, and put dollar amounts to the impacts of your findings.

\n\n

Along the way, we\'ll look at some of the techniques used by real-world threat actors that use physical attacks as part of their attack chains, and how you can effectively emulate the most realistic threats to your organization. Your adversaries don\'t stop after getting in, and neither should you.

\n\nSpeakerBio:  Andrew Lebedinsky, Security Engineer, Red Team at Microsoft
\n

Andrew Lebedinsky is a security engineer on the Microsoft Red Team. Their fields of interest include covert entry, radio hacking, and digital countersurveillance. In their spare time they can usually be found playing Source Engine-based FPS games and overthinking what to put in \"speaker bio\" fields.

\n\n\n\'',NULL,1294070),('4_Sunday','10','10:00','10:30','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Five Million Industrial Control Systems Walk Into a Bar: What IRONMAP Found When It Scanned the Whole Internet\'','\'Matt Caldwell\'','Creator Talks_9ff9bb3dda77e8f4b90d42ea38c84940','\'Title: Five Million Industrial Control Systems Walk Into a Bar: What IRONMAP Found When It Scanned the Whole Internet
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

What does the global attack surface of operational technology actually look like at internet scale? We built IRONMAP, a purpose-built OT/ICS intelligence platform, to find out — and the answer is both larger and more disturbing than we expected.

\n\n

Over the course of this ongoing research project, IRONMAP has catalogued over 5.5 million ICS/OT-facing assets across the public internet, with more than 2.25 million flagged as high-risk. Using deep protocol fingerprinting across all major industrial protocols — EtherNet/IP (CIP), Modbus TCP, Siemens S7, DNP3, IEC 60870-5-104, OPC-UA, BACnet/IP, Omron FINS, GE SRTP, Tridium Fox, and more — IRONMAP goes well beyond port scanning to perform authenticated protocol enumeration, live register reads, and tag harvesting using PLCDISCO, our multi-protocol OT scanner.

\n\n

This talk presents a ground-level statistical portrait of the exposed OT internet: which protocols dominate, which sectors are most exposed, how vendor market share looks through the lens of deep insight and where in the world the highest concentrations of exposed critical infrastructure live (spoiler: it is not all China). We will walk through what over 242,000 EtherNet/IP devices look like when you enumerate their CIP identity objects, what ~500,000 Modbus devices expose in their holding registers, and what the live tag names of real PLCs tell you about what processes they are running.

\n\n

We then turn to a specific and underappreciated issue: Automatic Tank Gauges (ATGs). IRONMAP found 149 confirmed ATG systems directly exposed to the internet, the majority of them Veeder Root TLS-350 and TLS-450 units — the dominant ATG platform at commercial fueling facilities across North America. These systems, reachable via the Guardian ASP protocol on TCP/10001, require no authentication on older firmware and respond to a simple serial-style command set with:

\n\n
    \n
  • Current fuel volume per tank, in gallons
  • \n
  • Product type (Unleaded, Premium, Diesel, Jet-A, Heating Oil)
  • \n
  • Live alarm states (high water, leak detection, low fuel, overfill)
  • \n
  • Delivery event history and timestamps
  • \n
  • Up to 8 tank probes per unit
  • \n
\n\n

The implications are significant. Exposed ATGs reveal not just that a facility has fuel storage, but how much, what kind, and when deliveries occur — operational patterns that are directly relevant to physical security and supply chain intelligence. IRONMAP discovered ATGs at locations that include commercial truck stops, bulk fuel terminals, and sites with product profiles consistent with aviation or military use. We will demonstrate a live walk-through of what an unauthenticated session reveals, discuss the responsible disclosure posture we have taken, and present mitigation guidance for asset owners.

\n\n

Attendees will leave with a realistic, data-grounded view of the exposed OT landscape — not a cherry-picked set of scary screenshots, but statistically representative findings from a 5.5-million-asset dataset — plus actionable context on the ATG exposure class and how to find and fix it.

\n\nSpeakerBio:  Matt Caldwell, Tophat Security
\n

Matt Caldwell is the founder of Tophat Security, cyber security firm specializing in innovative OT/ICS software and tools, red team operations, and critical infrastructure research. With over a decade of experience in industrial control system security, Matt has assessed environments spanning oil and gas, electric utilities, water treatment, manufacturing, and federal government. He built IRONMAP as a research platform to continuously map the internet-exposed OT attack surface at scale, applying it to build threat intelligence, support disclosure efforts, and develop data-driven visibility into the global ICS exposure problem. Matt holds relevant certifications in cyber security and penetration testing and has presented research at global OT/ICS security conferences. He is based in Athens, Georgia, and speaks regularly with asset owners, government stakeholders, and research organizations on OT exposure topics.

\n\n\n\'',NULL,1294071),('4_Sunday','10','10:00','10:45','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Ghost in the Hiring Machine: How to Spot Fake Personas Before They\'re on Your Payroll\'','\'Michael Reimsbach,Rishi \"rxerium\" C\'','Creator Talks_37af17bd2ebc069359c0eb4daac4cdd9','\'Title: Ghost in the Hiring Machine: How to Spot Fake Personas Before They\'re on Your Payroll
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

People are getting hired and trusted every day. Some of them do not exist at all, yet they still pass interviews, collect paychecks, and gain access to sensitive systems. Campaigns attributed to the DPRK have shown that this threat is very real. So how do you catch a ghost with a resume?\nAttendees will learn practical OSINT techniques for spotting fake personas and receive a checklist for thorough background checks. They will see these methods applied through two cases based on a true story, illustrating how these personas succeeded, how one could have been prevented, and where OSINT reaches its limits.\nThese techniques not only help attendees detect fake personas but also provide practical ways to protect their own privacy and control what personal information is visible online.

\n\nSpeakers:Michael Reimsbach,Rishi \"rxerium\" C
\n
\nSpeakerBio:  Michael Reimsbach, Product Security Specialist at SAP
\n

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services.

\n\n

He obtained multiple industry certifications such as OSCP, GCPN, and CISSP.

\n\n

A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information.

\n\n

Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.

\n\nSpeakerBio:  Rishi \"rxerium\" C, Security Researcher
\n

Rishi is a London-based security researcher with over five years of hands-on experience in IT. He currently specializes in vulnerability research, threat intelligence, and enterprise risk analysis. His current focus lies in identifying and analyzing zero-day vulnerabilities and emerging CVEs, often working to reverse engineer exploit mechanics and build detection logic before public weaponization. Rishi’s work spans both offensive and defensive domains—developing threat models based on real-world TTPs, crafting custom detection rules, and automating reconnaissance pipelines to uncover exploitable misconfigurations and exposed assets. He is particularly active in attack surface management (ASM) and OSINT, where he leverages DNS enumeration, passive data correlation, and large-scale infrastructure scanning to surface unknown entry points and map adversary-accessible exposure. Outside of research, Rishi integrates findings into operational tooling and supports data-driven prioritization strategies to bridge technical risk and business impact. His work reflects a deep commitment to adversary-informed defense and proactive discovery across modern hybrid environments.

\n\n\n\'',NULL,1294072),('4_Sunday','10','10:00','10:30','N','DEF CON Groups','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Lessons Learned from Building a New DEF CON Group presented by DC724\'','\'Cliff \"GritsnGravy\" Friedel,Joe \"jbohack\"\'','Creator Talks_70c50fc99e2c49737f869efaca40fb8f','\'Title: Lessons Learned from Building a New DEF CON Group presented by DC724
\nTags: DEF CON Groups | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Building a new DEF CON Group comes with a lot of trial, error, and unexpected lessons. DC724 will share real-world experience from the early stages of growing a newer group, including finding space, building relationships, coordinating with other communities, avoiding common mistakes, and creating momentum. This session is especially useful for newer POCs, prospective organizers, and anyone trying to get a local hacker community off the ground.

\n\nSpeakers:Cliff \"GritsnGravy\" Friedel,Joe \"jbohack\"
\n
\nSpeakerBio:  Cliff \"GritsnGravy\" Friedel, DC 724
\n

Cliff Friedel (GritsnGravy) is one of the co-founders of DC 724 and has been working with computers and technology since 1979. Working in various IT disciplines from the 1980s until today, Grits has got his hands into everything from BBSes to ISPs to storage acceleration networks. Now semi-retired, he focuses on retro computers, making nerdy T-shirts, RF technologies and amateur radio, and occasionally trying to throw a god roll at the craps tables.

\n\nSpeakerBio:  Joe \"jbohack\", DC 724/Nyan Devices
\n

Joe Buhagiar (jbohack) is a Security Engineer at NaviSec, specializing in incident response and penetration testing. He is also the Co-Founder and Lead Developer of Nyan Devices, the creators of the nyanBOX, a wireless security toolkit covering Wi-Fi, Bluetooth, and RF, with a focus on device visibility and counter-surveillance research. He is a Co-Founder of DC724.

\n\n\nLinks:
    DC724.org - https://DC724.org
\n\'',NULL,1294073),('4_Sunday','10','10:00','10:30','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Skill Issue: A Recon Story\'','\'Ryan Bonner\'','Creator Talks_05b493a44c2e35f5b13bdb823ed62e62','\'Title: Skill Issue: A Recon Story
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\nFor ten years we told every hunter the same thing: learn the bug classes, grind the labs, memorize the payloads. It built a generation of hackers, and the perfect training set. Every writeup, every PayloadsAllTheThings entry, every CTF solution is now fuel for a model. We documented exploitation so well that we automated ourselves out of the easy half of the job.
\n\n

I\'m not mad about it. It was always going to happen. The bottom of the funnel, the known classes on known surfaces, belongs to the swarm now. If your edge is running the same templates against the same assets, you are racing a machine that never sleeps. You lose that race.

\n\n

So where did the human edge go? Upstream. To recon.

\n\n

Recon never got written down the way exploitation did. The intro stuff did: run these five tools, pipe it into httpx. But the part that actually finds the bug, the judgment about which of forty thousand assets is worth your night, the instinct for where an org cut a corner, the pivots that surface the forgotten staging box, that part lives in people\'s heads. It is tribal. It moves through private channels and bar talk at cons. A model cannot train on what was never published.

\n\n

Recon is the last moat, and the moat is built from information asymmetry, not skill. It keeps paying not because hunters are smarter than the bots, but because hunters know things the bots were never told. Every time someone publishes a technique, the moat drains a little. It refills faster than it drains, because the people who hold the best recon rarely have a reason to write it down.

\n\n

I will make that concrete, not philosophical: the categories of recon that resist documentation, why scanners miss them (tools enumerate, humans interpret), and where to point your attention in 2026. Then I give away one or two techniques not in the standard rotation, walked end to end, with the reasoning, not just the command. You leave with something you can use that night.

\n\nSpeakerBio:  Ryan Bonner, Lead Security Engineer at Arcanum Information Security
\n

Ryan Bonner is a Lead Security Engineer at Arcanum Information Security, where he builds AI systems, hacks them, and runs application penetration tests. Off the clock he hunts wide-scope bug bounty programs.

\n\n\n\'',NULL,1294074),('4_Sunday','10','10:00','10:59','N','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'You Can\'t Opt Out: The Invisible Surveillance in Your Walls, Pockets, and Lives\'','\'Naomi Brockwell\'','Creator Talks_c722abbdb858ba6a99dc9abe878b366a','\'Title: You Can\'t Opt Out: The Invisible Surveillance in Your Walls, Pockets, and Lives
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Surveillance is baked into the very fabric of our digital existence. From smart homes to smart cars, and now we drive down streets with smart cameras tracking our every move. And why aren’t even aware of most of it, because almost none of it is disclosed in any meaningful way to the people being surveilled. Sometimes because companies don’t want their users to understand what data they’re collecting, because users would be upset, and sometimes because governments doing want us to know about the surveillance. This talk walks through a series of real cases where surveillance was hiding in plain sight inside ordinary consumer iot devices and apps, and was only discovered because someone with the right skills bothered to look. From high school students at a previous DEF CON uncovering microphones installed in school bathrooms, to Byron Tau\'s reporting on commercial SDKs (like the one embedded in a widely-used Muslim prayer app) feeding location data to U.S. military and intelligence buyers, to robot vacuums quietly mapping the interiors of homes and shipping that data overseas, to the BadBox 2.0 botnet found lurking inside off-the-shelf Android streaming boxes like Superbox. The surveillance is pervasive, and the average consumer has no realistic way to detect or refuse it. This session makes the case that the question is no longer \"are you being watched?\" but \"could you even opt out if you tried?\" The reality is, it’s becoming so difficult to have meaningful privacy in the digital age that we’re on the cusp of a digital panopticon that threatens the very freedom of society. This talk explains what is at stake to democracy when privacy disappears, and how it slowly eliminates the self-correcting mechanisms and checks on power in society, such as protest movements, whistleblowers, independent media, protest movements, activist groups, and opposition parties. It is also a call to action for the people in this room, who possess the unique skill sets of reverse engineering, network analysis, firmware teardown, RF work etc. People breaking these systems apart and revealing what they find to the world is rapidly becoming the only meaningful check on a landscape that has decided surveillance is the default. We need more researchers looking, and we need them looking now.

\n\nSpeakerBio:  Naomi Brockwell
\nNo BIO available
\n\n\'',NULL,1294075),('4_Sunday','10','10:30','10:59','N','Hackers.town','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'The Enshittified Internet and How We Can All Rewild the Internet\'','\'LambdaCalculus\'','Creator Talks_213a9d8eb44e242edd83ce60e170fb18','\'Title: The Enshittified Internet and How We Can All Rewild the Internet
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

The Internet was once a place where people could talk, share ideas and knowledge, express themselves with personal websites, build communities, and more. In recent years, however, we have seen that magic fade away, as the internet of today is now a toxic cesspool of social media controlled by Big Tech, ads thrown everywhere, walled gardens, AI generated slop, and content that locks us in by making us angry and depressed. This is not the Internet we need or should leave to the next generation of hackers! There are ways to take back and rewild the web! This talk is part informative, part education, part historical, and pure hacker punk energy as we explore how to do things like self-host our own servers, tools we can use to build new networks, decentralized services for communication, media sharing, and more, old protocols and services us old timers used to use that still exist (and how the kids can use them, too!), and places and sites we can go to for the education and information we want! In all, this talk is about hacking the planet and taking our Internet... the people\'s Internet... back from corporate corruption and control!

\n\nSpeakerBio:  LambdaCalculus
\n

LambdaCalculus is chaos in a trenchcoat, and is passionate to his core about human rights issues, community outreach, and education. He has spoken at HOPE in 2025 on the Pirate Box and Sneakernet, and has also spoken at DEF CON, JawnCon, and PhreakNIC. He is a member of hackers.town, a native of the NYC area, and can still hit a mosh pit! Find him hanging out at hackers.town on Mastodon:https://masto.hackers.town/@LambdaCalculus

\n\n\n\'',NULL,1294076),('4_Sunday','10','10:30','10:59','N','Car Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Unlocking Vehicles by Brute-Forcing Rolling Code Systems\'','\'Danilo Erazo\'','Creator Talks_1f2d72e046149f2139b9b963f2b4929f','\'Title: Unlocking Vehicles by Brute-Forcing Rolling Code Systems
\nTags: Car Hacking Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Many vehicles worldwide rely on a popular aftermarket rolling code system that has long been trusted to protect against key fob cloning and unauthorized access. This talk unveils the reverse engineering journey that uncovered the protocol’s frame format, cryptographic design, and previously undocumented weaknesses. By combining a rollback vulnerability with a practical rolling code brute force attack, we demonstrate how an attacker can recover valid codes and clone a legitimate key fob. The research resulted in three CVEs assigned in 2026 and impacts products deployed across multiple markets. Attendees will learn how assumptions about rolling-code security can fail in practice and how these failures can be exploited in the real world.

\n\nSpeakerBio:  Danilo Erazo, Ekoparty, PCA Cybersecurity
\n

Danilo Erazo is a Security Researcher at PCAutomotive in Budapest, Hungary. He has reported critical vulnerabilities to KIA Corporation, KIA Ecuador, Suzuki Motor Corporation, Calix Inc., Realtek Semiconductor Corp., and multiple Latin American banks. He is the organizer of the Car Hacking Village at Ekoparty, founder of the PWNORDIE security conference, and a speaker at Re/verse 2026, Secure Our Streets 2025, REcon 2025, Hardwear USA 2025, etc

\n\n\n\'',NULL,1294077),('4_Sunday','10','10:30','10:59','N','Biohacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Wand Protocol: Full-Chain Attack on an FDA-Listed Fertility Analyzer\'','\'Gigi Xiaoqing Liu\'','Creator Talks_f0b11465045f193bd21f16fda9e9bcc8','\'Title: Wand Protocol: Full-Chain Attack on an FDA-Listed Fertility Analyzer
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

This year\'s BHV theme is access. This talk is about what happens when access is granted to everyone who should not have it, and about what happens to patient data once it leaves the device.\nWe conducted a full security assessment of a shipping consumer fertility hormone analyzer — an FDA-listed device used by millions of people to track LH, FSH, estrogen, and progesterone. In a post-Dobbs environment, those measurements are not just health data. In 14 states, they are potential legal evidence.\nWe found no authentication anywhere in the stack. From BLE proximity, any attacker within approximately 30 meters can silently rebind the device to an attacker-controlled account in under 15 seconds using a ~$10 dongle and open-source tools. No credentials. No pairing prompt. No notification to the user. The protocol works exactly as designed.\nThe companion app identifies hardware by a substring check on the BLE advertisement name. Any peripheral advertising a matching name receives the user\'s live API session token during the app\'s own handshake. That token grants access to the complete hormone history, miscarriage status, PCOS diagnosis, and fertility treatment records of any user whose phone comes within range. The cloud login endpoint issues session tokens without verifying the password. Email address alone grants full account access.\nA hardcoded API key in the distributed APK grants read and write access to approximately 659,000 user health profiles with no per-object authorization. Reproductive health data — including miscarriage history — transmits to analytics vendors, an advertising pixel, and a customer data platform headquartered in Russia on every session open.\nThis talk presents the full attack chain with live demos, maps each finding to FDA\'s February 2026 premarket cybersecurity guidance, and closes with three concrete implementation decisions that would have prevented all of it. Coordinated disclosure submitted to vendor, FDA CDRH, and CISA. All testing on researcher-owned hardware and accounts.

\n\nSpeakerBio:  Gigi Xiaoqing Liu
\n

Gigi Liu is a graduate security researcher at Northeastern\'s Security And Privacy Research (SPQR) Group under Professor Kevin Fu, where her work covers embedded systems security, medical device attack surfaces, and AI-generated media detection. She interns at Lila Sciences as a Security and Cloud Engineer, building enterprise-wide agentic AI security infrastructure and detection capabilities for unauthorized AI activity across cloud and SaaS environments.

\n\n

Her technical work spans wireless protocol reverse engineering, binary exploitation, web and mobile reverse engineering, cloud and AI security. She has applied these skills across medical hardware, automotive platforms, and enterprise cloud environments — from BLE command injection on FDA-listed devices to CarPlay API exploitation to building agentic AI detection controls at scale. As a UCLA psychobiology alum with a consulting background, she brings a multidisciplinary lens to every system: understand what it\'s designed to do first, then find where it breaks.

\n\n\n\'',NULL,1294078),('4_Sunday','12','12:30','12:59','N','Recon Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Building Hackbots\'','\'Jason \"jhaddix\" Haddix\'','Creator Talks_96206aff36654887076d5326ee960972','\'Title: Building Hackbots
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Building AI-Powered Penetration Testing Bots\nIn this talk, we\'ll walk through the core design philosophy behind AI hackbots and the architecture that makes them work: single-purpose vs. multi-stage bots, context engineering for targeted prompting, and tool integration with output parsing workflows.\nThen we\'ll get hands-on. We\'ll live-build a functional hackbot for a common offensive task — demonstrating asset discovery, endpoint analysis, or mutation-focused testing (e.g., XSS/SSRF) — and show how context engineering and hallucination mitigation work in practice against real targets. You\'ll see where AI genuinely accelerates reconnaissance and web analysis, and where it falls flat if you aren\'t careful. We\'ll close with lessons on cost optimization, auditability, and integrating hackbots into actual engagements.\nWho should attend: Pentesters and bug bounty hunters with offensive security experience who want to meaningfully integrate AI into their workflow — not as a novelty, but as reliable tooling.\nWhat you\'ll walk away with: A clear mental model for when and how to build hackbots, a live demo you can replicate, and a path into the full course where you\'ll build seven production-ready bots from asset discovery through mutation testing.

\n\nSpeakerBio:  Jason \"jhaddix\" Haddix, CEO and \"Hacker in Charge\" at Arcanum Information Security
\n

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

\n\n

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

\n\n\n\'',NULL,1294079),('4_Sunday','11','11:00','11:30','N','Adversary Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Beyond the Hype: The Real Role of Red Teams in an AI World\'','\'Michael Leibowitz,Niranjanaa Ragupathy\'','Creator Talks_abaaf1b7d0f5d0065a66b118c89eab2f','\'Title: Beyond the Hype: The Real Role of Red Teams in an AI World
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Red Teaming is about thinking and acting like an attacker to improve an organization\'s defenses. In practice, it is less about flashy exploits and more about providing prioritization signals, validating and improving detection capabilities, and telling compelling stories that drive meaningful security outcomes.

\n\n

The rise of AI has introduced a new challenge and a new mandate. Organizations are increasingly asking Red Teams to \"use AI to hack things\" as both attackers and defenders race to understand what AI can and cannot do. To cut through the hype, the role of Red Teams to speak truth to power is more important than ever.

\n\n

Our responsibility is to separate speculation from reality. To understand the capabilities of AI-powered attackers, assess how well our defenses stand up against them, and evaluate the risks introduced by new AI-driven attack surfaces. By doing so, we help organizations make informed decisions about where to invest, what to defend, and how to prepare for the threats that matter most.

\n\nSpeakers:Michael Leibowitz,Niranjanaa Ragupathy
\n
\nSpeakerBio:  Michael Leibowitz, Senior Principal Troublemaker, Oracle Red Team
\n

Michael (@r00tkillah) has done hard-time in real-time. An old-school\ncomputer engineer by education, he spends his days hacking the\nmothership for a fortune 100 company. Previously, he developed and\ntested embedded hardware and software, fooled around with strap-on\nboot roms, mobile apps, office suites, and written some secure\nsoftware. On nights and weekends he hacks on electronics, writes CFPs,\nand contributes to the NSA Playset.

\n\nSpeakerBio:  Niranjanaa Ragupathy, Security Engineer Manager, Google Red Team
\n

Niru is a Security Engineer and Manager at Google. She leads the Offensive Security team, which focuses on hacking Google to improve its overall security. In her free time, Niru enjoys doodling and creating Capture The Flag (CTF) challenges.

\n\n\n\'',NULL,1294080),('4_Sunday','11','11:00','11:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Cryptocurrency Closing Keynote\'','\'Michael \"MsvB\" Schloh,Diego \"rehrar\" Salazar\'','Creator Talks_1c3e83a99817b0e8f998b7377661693a','\'Title: Cryptocurrency Closing Keynote
\nTags: Cryptocurrency Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Closing the Cryptocurrency areas at DEFCON, we introduce everyone at work and their achievements during the event. We review our four major activities including the hackathon, contests, workshops, and capture the flag competition. A summary of teams, winners, and statistics indicates the degree of participation in this event. We describe what prizes were awarded and which contestants won big. A list of workshop topics follows, with instructors giving their impressions of how modern finance technology benefits from interactive learning. Finally, we give a sneak preview of what\'s to come in the Cryptocurrency areas (Village, Contest, Vendor, Party, Training) at DEFCON in Bahrain and how we intend to fulfill the mandate of fostering cryptocurrency exploration and hacking there.

\n\nSpeakers:Michael \"MsvB\" Schloh,Diego \"rehrar\" Salazar
\n
\nSpeakerBio:  Michael \"MsvB\" Schloh, Chairman, Monero Devices
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\nSpeakerBio:  Diego \"rehrar\" Salazar, Cypher Stack
\n

Diego \'rehrar\' Salazar has been around the FOSS and cryptocurrency communities for eight years. He owns and runs Cypher Stack, a company that performs novel research and makes contributions to various FOSS projects. He has organized and managed several villages at defcon, c3, and more.

\n\n\n\'',NULL,1294081),('4_Sunday','11','11:00','11:30','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Is Your Fridge Running? Then You Better Catch It - State of Security in Refrigeration Systems\'','\'Amir Zaltzman\'','Creator Talks_cab2b3e0f829316dfa49c0f89aa7c46b','\'Title: Is Your Fridge Running? Then You Better Catch It - State of Security in Refrigeration Systems
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Much of modern life depends on cooling systems, from keeping food fresh in grocery stores to storing life-saving medicine. At their core, refrigeration controllers manage the entire process, coordinating field controllers directly connected to the refrigeration components like compressors, fans etc. With tens-of-thousands of devices exposed online, used by the largest retail stores around the world, attacking these controllers could cause huge financial loss and disrupt food and medicine supply chains around the globe.

\n\n

During the last year we looked at refrigeration controllers from leading vendors in the industry, disclosing more than 30 vulnerabilities. We discovered buffer-overflows, authentication bypasses and remote code execution issues. Furthermore, we discovered ways to exfiltrate sensitive information from devices, allowing attackers to leak ownership and location information and pinpoint attack specific targets.

\n\n

In our talk, we will deep dive into the refrigeration ecosystem. Including hardware firmware extraction and analyzing it, emulating firmware binaries and showcasing the vulnerability chains we uncovered affecting these systems. Lastly, we will present a real-life video demo presenting an attacker hacking a controller covertly, disrupting normal operations and affecting refrigerators’ contents.

\n\nSpeakerBio:  Amir Zaltzman, Claroty Team82
\n

Vulnerability researcher at Claroty Team82

\n\n\n\'',NULL,1294082),('4_Sunday','11','11:00','11:59','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Physical Security is not sexy which is bad for organizations and good for red teams. \'','\'Roger Egan\'','Creator Talks_a8dd663303cfda42e19cd189f6251b39','\'Title: Physical Security is not sexy which is bad for organizations and good for red teams.
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

With digital security tools continually becoming stronger, organizations often overlook their physical security as part of their operational security. Often, many organizations rely on their security integrators to secure the building. Those integrators business models are often not incentivized to properly secure the buildings. This leaves cameras, readers and keycards open for attackers and pen testers to exploit to gain access.

\n\n

In this talk we’ll discuss the shortcomings of access control door systems, how attackers and pen testers can use official tools from the manufactures to identify and exploit the readers and doors along with using tools like a Flipper, RFID USB readers and postcards.

\n\nSpeakerBio:  Roger Egan
\n

Roger is a washed up racecar driver with a more successful Information Systems career. This includes 10+ years experience in programming, installing, servicing and training on physical security software and equipment. Roger has shown organizations and law enforcement the strengths and weaknesses of physical security and how they can be exploited.

\n\n\n\'',NULL,1294083),('4_Sunday','11','11:00','11:30','N','DEF CON Groups','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'The State of DEF CON Groups\'','\'Alethe Denis,Magen Wu\'','Creator Talks_f6e1a7d5d9f0b6f83a7ee57bb555881e','\'Title: The State of DEF CON Groups
\nTags: DEF CON Groups | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

DEF CON Groups has grown into a global network of hundreds of local communities, connecting hackers, makers, students, educators, and professionals around the world. Join the department leadership for an inside look at where the community stands today, what we’ve accomplished over the past year, and where we’re headed next.

\n\n

We’ll share highlights from across the global DEF CON Groups community, new initiatives, lessons learned, available resources for Group organizers, and ways anyone can get involved—whether you’re looking to attend your first local meetup, volunteer, help organize an existing Group, or start one in your own city.

\n\n

Whether you’re a longtime Group organizer or just discovering DEF CON Groups, this session is your opportunity to hear directly from the department, celebrate the community’s achievements, and see what’s coming next.

\n\nSpeakers:Alethe Denis,Magen Wu
\n
\nSpeakerBio:  Alethe Denis, DCG, Lead Goon
\nNo BIO available
\nSpeakerBio:  Magen Wu, Director of Ops Goon at DEF CON Groups
\nNo BIO available
\n\n\'',NULL,1294084),('4_Sunday','11','11:30','11:59','N','Bug Bounty Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Automated Discovery of Prompt Injection Vulnerabilities via Mutated Prompt Generation\'','\'Bogdan Stelee,Arnav Garg\'','Creator Talks_42b9d4c374dcf1f1a512f1893dd9871d','\'Title: Automated Discovery of Prompt Injection Vulnerabilities via Mutated Prompt Generation
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Finding one prompt injection isn\'t the end goal; checking how many variants still bypass your safeguarding layers is the new target. Introducing MPG, an XPIA mutation framework that generates adversarial payload variants and tests them across agentic AI systems to expose hidden vulnerability surfaces and emerging data exfiltration risks.

\n\nSpeakers:Bogdan Stelee,Arnav Garg
\n
\nSpeakerBio:  Bogdan Stelee, Senior Software Engineer, Microsoft
\n

Bogdan Stelea is a Senior Software Engineer performing AI Security Research at Microsoft, working at the intersection of AI security, adversarial ML, and secure agentic system design. Bogdan develops automated frameworks for conducting variant hunting and discovering prompt injection vulnerabilities at scale. His work focuses on identifying, reproducing, and understanding vulnerabilities in modern AI copilot solutions, with a particular emphasis on cross/indirect prompt injection attacks (XPIA), tool misuse, and the expanding attack surface introduced by AI agents. Moreover, Bogdan creates learning materials and courses that clearly explain the threats introduced by XPIA. Actively engaged in the AI Security, CTF, and Bug Bounty communities, with a consistent presence at DEF CON, Bogdan has published and presented his AI security research at international academic venues, including IEEE and ACM.

\n\nSpeakerBio:  Arnav Garg, Security Researcher, Microsoft
\n

Arnav Garg is a Security Researcher at the Microsoft Security Response Center (MSRC), specializing in AI security research, adversarial testing, and the security of Copilot and agentic AI systems. His work focuses on understanding and mitigating emerging AI threats, with particular emphasis on cross/indirect prompt injection attacks (XPIA), data exfiltration techniques, tool misuse, and the evolving attack surface introduced by AI agents. Arnav develops automated frameworks for scalable security testing and vulnerability discovery, helping advance practical defenses for next-generation AI systems. He has presented and published research on AI security, automated prompt injection discovery, and AI vulnerability testing at both internal and external venues.

\n\n\n\'',NULL,1294085),('4_Sunday','11','11:30','11:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'IsMyPhonePwned: Analyzing Android/iOS Phones at Scale\'','\'Desnos Anthony\'','Creator Talks_7ab5cb5d7f7172bc0cf05c30daf1deca','\'Title: IsMyPhonePwned: Analyzing Android/iOS Phones at Scale
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Mobile devices have become the primary targets for highly sophisticated, targeted spyware and state-sponsored surveillance, yet validating a suspected compromise remains an adversarial challenge across all sectors. Whether in a corporate enterprise, an investigative newsroom, or a human rights organization, tracking mobile malware forces an impossible binary choice: accept the existential risk of data exfiltration, or initiate traditional forensics. For individual users, journalists, and corporate Incident Response (IR) teams alike, standard forensic methods are deeply destructive, and breaks critical software access. Because specialized forensic workstations are complex and cost-prohibitive, high-risk individuals and organizations often remain completely blind to ongoing breaches.

\n\n

This talk introduces IsMyPhonePwned, an open-source, non-destructive mobile forensic framework designed to democratize device auditing. It allows anyone to scan for Indicators of Compromise (IoCs) and malware infections directly from a standard web browser over a USB connection. By leveraging WebAssembly and a high-performance stack written entirely in Rust, our framework enables client-side extraction, log parsing, and industry-standard Sigma rule evaluation without rooting, zero software installation, and zero device downtime. We will demonstrate how organizations and individual citizens can bypass complex, destructive investigative bottlenecks and perform rapid, privacy-preserving mobile triage at scale.

\n\nSpeakerBio:  Desnos Anthony, EDF CERT (CERT-EDF)
\n

I spent my last decade at Google in the Android Security Team, to fight against Android malware !\nI\'m now working at CERT-EDF, to keep the light on ;)

\n\n\n\'',NULL,1294086),('4_Sunday','11','11:30','11:59','N','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'One Firmware Flaw, 70+ Device Models: Lessons in Industrial IoT Disclosure and Mitigation\'','\'Weihan Goh,ZhengChao Wen\'','Creator Talks_313401d17601185f9e5d046f3c1396a9','\'Title: One Firmware Flaw, 70+ Device Models: Lessons in Industrial IoT Disclosure and Mitigation
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

In this talk, we use a real firmware vulnerability we found affecting more than 70 industrial sensor models from a single vendor to show how one finding can become a fleet-scale problem. The bug matters, but the bigger story is what happens next - a CVE goes public, patch adoption is still early, and operators are left managing risk in environments where safety and availability matter as much as security. We will walk through how the issue was found, how its scope grew across a large product line, and why industrial devices make remediation fundamentally different from IT or our regular consumer technology. We will also cover the coordinated disclosure process with a (very) cooperative vendor, and a broader lesson that emerged from the case, i.e., that researchers, vendors, and operators do not all gain the ability to act on the same timeline. Our talk is a talk about shared firmware risk, real-world disclosure, and what researchers, vendors, and operators should learn when a firmware issue affects a broad line of products and public disclosure arrives before real-world mitigation catches up.

\n\nSpeakers:Weihan Goh,ZhengChao Wen
\n
\nSpeakerBio:  Weihan Goh, Singapore Institute of Technology
\n

Dr Weihan Goh is an Associate Professor at the Singapore Institute of Technology (SIT). His research interests include adversarial digital forensics, security testing, and controlled environments for cybersecurity evaluation, education, and experimentation. His work focuses on the design and analysis of realistic adversarial scenarios, with an emphasis on how security experiments can be conducted safely and meaningfully in complex systems of systems. Beyond teaching and research, Dr Goh participates in CTFs under the handle \"icebear\".

\n\nSpeakerBio:  ZhengChao Wen, Singapore Institute of Technology
\n

ZhengChao Wen is a final-year Information Security student at the Singapore Institute of Technology (SIT), with interests in vulnerability research and security testing. Currently serving his industrial attachment at TÜV SÜD PSB, he is involved in cybersecurity product testing and penetration testing of IoT devices.

\n\n\n\'',NULL,1294087),('4_Sunday','11','11:30','11:59','N','Car Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Stealing at the Speed of Light: The Anatomy of a Real Relay Attack tool\'','\'Robbie Galfrin\'','Creator Talks_00a8614bd523a0c173331342b6f0c88c','\'Title: Stealing at the Speed of Light: The Anatomy of a Real Relay Attack tool
\nTags: Car Hacking Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Passive Keyless Entry and Start (PKES) systems allow a driver to unlock and start a vehicle without any deliberate interaction with the key, relying instead on an automated radio-frequency exchange between the key fob and the car whenever the two are in close proximity. This talk begins by explaining the operating principles of PKES and the challenge–response communication that links the fob to the vehicle, establishing the implicit trust assumption — that proximity equals legitimacy — on which the system depends. I will then describe the process of sourcing and operating a real, commercially available relay attack tool, illustrated with a demonstration video of the attack carried out against a vehicle, before presenting a research deep-dive into how the tool is constructed and how it relays the signal across distance to defeat the proximity assumption. Finally, I will discuss mitigation strategies that aim to close the gap the attack exploits.

\n\nSpeakerBio:  Robbie Galfrin, PlaxidityX
\n

Robbie Galfrin is an embedded security researcher with over 12 years of experience in hardware and software vulnerability research and exploitation. At PlaxidityX since 2017, his main focus has been low-level and hardware attacks on automotive ECUs, operating systems, and communication interfaces. Holds an MSc in Electrical Engineering from Tel Aviv University.

\n\n\n\'',NULL,1294088),('4_Sunday','11','11:30','12:30','N','Game Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Yes, I froze an SNES for science\'','\'dwangoAC\'','Creator Talks_ee9adbe11c7bc6dac6608ba18b1f1d67','\'Title: Yes, I froze an SNES for science
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

\"dwangoAC describes why he put a SNES console in a freezer, the scientific process that led to unexpected statistics, and whether or not it helped TASBot play Super Metroid Tool-Assisted Speedruns on real consoles. This talk will cover how 1990\'s-era component aging affects RNG and why hotplate% speedruns don\'t work the way the speedrunning community thinks they do

\n\nSpeakerBio:  dwangoAC
\n

dwangoAC is the keeper of TASBot, a cute non-AI robot. TASBot presses buttons perfectly like a player piano and plays games fast, often employing game breaking glitches. TASBot content has helped raise more than $1.5M at Games Done Quick and other charity events since 2013. dwangoAC is known for video game science experiments, investigations, and transformative art.

\n\n\n\'',NULL,1294089),('4_Sunday','12','11:30','12:30','Y','Game Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Yes, I froze an SNES for science\'','\'dwangoAC\'','Creator Talks_ee9adbe11c7bc6dac6608ba18b1f1d67','\'\'',NULL,1294090),('3_Saturday','12','12:30','13:30','N','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'Simone Bossi,Luca Borzacchiello\'','Creator Talks_bdf980ad3fa727d9a8d7db63d6f73a3b','\'Title: Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology
\nTags: IoT Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Modern IoT firmware often appears protected behind proprietary encryption, stopping analysis before it starts. However, in many cases the fastest path forward is not to break the cryptography, but it is to reuse the vendor’s own implementation via targeted function emulation. In this hands-on workshop, attendees will learn a methodology we call firmware archaeology: a practical method for reconstructing the proprietary firmware decryption scheme by correlating artifacts left behind across firmware archives, public repositories and developer ecosystems. Attendees will analyze the real-world ecosystem of a commercial IP camera vendor, using the firmware archaeology methodology. First, they will identify historical artifacts and ecosystem components from publicly available sources. Next, they will recover from binaries the cryptographic routines that are responsible for decrypting the firmware images. They will then reuse and emulate these functions in a controlled environment to recover the decrypted firmware image that was initially secured by the proprietary encryption scheme. With this access, participants will move beyond decryption to explore hidden functionalities of the target device and map the broader attack surface of the platform that was previously inaccessible. The workshop is designed as a practical methodology session rather than a one-off trick or a showcase of vulnerabilities. All exercises are hands-on and based on real research, with pre-packaged material and tooling provided. Attendees will leave with a practical and repeatable methodology for analyzing modern IoT platforms, including techniques to reconstruct firmware decryption pipelines and bypass analysis barriers without reimplementing vendor cryptography from scratch.

\n\nSpeakers:Simone Bossi,Luca Borzacchiello
\n
\nSpeakerBio:  Simone Bossi
\n

Simone takes apart embedded systems and firmware for a living, but it took a while to get there. He started doing vulnerability research in 2015 on web, mobile, network, and the occasional cryptography rabbit hole, including a stint as a cryptanalyst at STMicroelectronics working on IoT communications security. Around 2020 he moved fully into IoT and OT, where bugs live in proprietary protocols, firmware nobody was meant to read, and hardware that was built to last, not to be secured.

\n\n

He now leads the vulnerability research team at Nozomi Networks Labs, where they find 0-days in industrial and IoT devices, and quickly learned that the most interesting features are the ones you don\'t find in the user manual. Along the way: academic research on weaknesses in Linux\'s cryptsetup and PBKDF2 that made it into the security literature, open-source offensive tooling, and RE sessions old enough to have developed opinions.

\n\nSpeakerBio:  Luca Borzacchiello, Nozomi Networks
\n

Luca Borzacchiello is a Security Researcher with deep expertise in Symbolic Execution, Reverse Engineering, and Fuzzing. He currently works at Nozomi Networks, where he focuses on cutting-edge security research.\nBefore joining Nozomi, Luca served as a Red Team Engineer for the Italian Government, where he contributed to national cybersecurity initiatives. He also worked as researcher on the Red Team at TIM S.p.A., one of Italy’s leading telecommunications companies.\nLuca holds a Ph.D. in Program Analysis from Sapienza University of Rome. Outside of work, he is an active participant in Capture The Flag (CTF) competitions, where he enjoys applying his reverse engineering skills in high-stakes challenges.

\n\n\n\'',NULL,1294091),('3_Saturday','13','12:30','13:30','Y','IoT Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'Simone Bossi,Luca Borzacchiello\'','Creator Talks_bdf980ad3fa727d9a8d7db63d6f73a3b','\'\'',NULL,1294092),('4_Sunday','12','12:00','12:30','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'ThreatPatrol: Visualising the Modern Threat Landscape\'','\'Viral Maniar\'','Creator Talks_e5a56e8195e62c3d42346ac71d703e91','\'Title: ThreatPatrol: Visualising the Modern Threat Landscape
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

ThreatPatrol is a modern, open-source SaaS platform designed to operationalise cyber threat intelligence across Blue Teams, Cyber Threat Intelligence (CTI) analysts, Atomic Engineers and Purple Teams. Built natively around the MITRE ATT&CK framework and enriched with ART Atomic Red Team mappings, ThreatPatrol bridges the long-standing gap between threat intelligence, detection engineering and adversary simulation.

\n\n

Unlike traditional CTI platforms that focus solely on indicators or static reporting, ThreatPatrol consolidates campaigns, adversary behaviour, atomic tests, infrastructure and detection analytics into a unified, relational data model. This enables practitioners to move beyond passive intelligence consumption toward active defense validation, threat emulation and measurable security outcomes.

\n\n

The platform provides deep correlation across:

\n\n
    \n
  • Threat actors, campaigns and malware
  • \n
  • ATT&CK tactics, techniques, and procedures (TTPs)
  • \n
  • Atomic tests and adversary emulation workflows
  • \n
  • Detection logic and security controls
  • \n
  • Infrastructure and industry-specific threat exposure canvas
  • \n
  • ICS & IOT systems mapping with various framework on a 3D canvas
  • \n
\n\n

ThreatPatrol allows teams to:

\n\n
    \n
  • Map real-world adversary campaigns across the ATT&CK kill chain
  • \n
  • Emulate attacker behaviour using validated atomic tests
  • \n
  • Identify detection blind spots via contextual GAP analysis
  • \n
  • Visualise relationships between threats, tooling and mitigations
  • \n
  • Improve detection engineering aligned to adversary tradecraft
  • \n
  • Mature threat hunting with intelligence-led prioritisation
  • \n
  • Analyse threats targeting modern technologies such as AI agents and MCP ecosystems
  • \n
  • Extend visibility into ICS and IOT devices and industry-specific attack surfaces
  • \n
  • Mapping of each components of ICS and IOT devices to NIST, MITRE, Australian Standards, DoD Essesstial eight framework
  • \n
\n\n

The platform ships with:

\n\n
    \n
  • 160+ curated threat actor profiles
  • \n
  • 100+ live threat intelligence feeds
  • \n
  • 20+ ICS and SOCI industry related Threat Canvas on 3D HoloLens
  • \n
  • 20+ IOT Devices Component level attacks
  • \n
  • Continuously updated campaign and TTP mappings
  • \n
  • ATT&CK-aligned detection and mitigation coverage
  • \n
  • Campaign visualisation and attack path analysis tools
  • \n
  • Support for custom atomic tests and adversary simulation scripts
  • \n
\n\n

ThreatPatrol is designed for continuous adversary-driven security validation, enabling organisations to test, measure, and improve their resilience against realistic attack scenarios. By transforming fragmented intelligence into actionable, visual and testable insights, ThreatPatrol provides a single platform for understanding, simulating and defending against modern cyber threats.

\n\nSpeakerBio:  Viral Maniar, UniSuper
\n

Viral Maniar is a Senior Security Specialist at UniSuper, responsible for leading the organisation’s offensive and defensive security services within the information security team. He also operates his boutique cybersecurity firm, Preemptive Cybersecurity based in Australia, delivering both offensive and defensive security consulting services. With over thirteen years of experience in cybersecurity consulting, Viral has worked with a wide range of organisations across APJ. His expertise includes internal and external infrastructure testing, application penetration testing, vulnerability assessments, wireless security assessments, social engineering, red teaming, API testing, thick and thin client testing, and cloud security architecture reviews. Viral has spoken at prominent industry conferences such as Black Hat, ROOTCON DEFCON and (ISC)². He is also an active participant in bug bounty programs and has received recognition for responsibly disclosing security vulnerabilities. Outside of his professional work, Viral enjoys building security tools and contributes to multiple projects on GitHub. He can be found on X at @ManiarViral and @PreemptiveCyber.

\n\n\n\'',NULL,1294093),('4_Sunday','12','12:00','12:59','N','Physical Security Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Travel Security: Viewing Risks Through the Eyes of a Hacker\'','\'Tim Roberts,Brent White\'','Creator Talks_c6fb98db361a29dbd291fb42910efc5d','\'Title: Travel Security: Viewing Risks Through the Eyes of a Hacker
\nTags: Physical Security Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Drawing from real-world examples, covert entry, red team, and social engineering engagements, Tim Roberts and Brent White walk through how everyday travel habits can expose individuals and organizations to unnecessary risk. From airports and hotels to conferences, rideshares, restaurants, and more...we\'ll look at how attackers identify opportunities and observations most travelers never think about.

\n\n

This talk focuses on practical awareness rather than paranoia! We\'ll discuss common hotel vulnerabilities, social engineering tactics used against staff and travelers, and how small mistakes can lead to physical, identity theft, digital, or information compromise. Attendees should leave with realistic, affordable techniques they can immediately apply to improve situational awareness and protect their privacy. The goal isn\'t to be paranoid; it\'s to better understand how attackers think and make yourself a harder target!

\n\nSpeakers:Tim Roberts,Brent White
\n
\nSpeakerBio:  Tim Roberts, Sr. Principal Security Consultant and Red Team Operator at Dark Wolf
\n

Tim Roberts is a Sr. Principal Security Consultant and Red Team Operator with Dark Wolf, specializing in covert entry, OSINT, social engineering, and adversary-driven Red Team operations. His work includes physical and electronic access control bypassing, physical site assessments, surveillance, wireless and network penetration testing, drone hacking, web application security, and full-spectrum offensive security testing across government and commercial environments.

\n\n

With more than two decades of experience across private industry and government sectors, Tim has conducted assessments against highly secured facilities and critical infrastructure designed to emulate real-world adversaries. He is a co-author of the popular ACCESS LOGS series with Covert Instruments and has worked alongside law enforcement agencies supporting special operations cyber initiatives.

\n\n

Tim has been featured on Microsoft’s Roadtrip Nation, ProfilingEvil with Mike King, Hak5, Security Weekly, and BBC News. His work has also been highlighted by IDG Enterprise’s CSO Online and Help Net Security for expertise in social engineering, adversary methodology, and security awareness.

\n\n

Through WeHackPeople.com, Tim continues contributing to the security industry and InfoSec community by sharing real-world tradecraft, lessons learned, and both traditional and non-traditional techniques used in commercial and government operations.

\n\nSpeakerBio:  Brent White, Sr. Principal Security Consultant and Red Team Operator at Dark Wolf
\n

Brent White is a Sr. Principal Security Consultant and Red Team Operator with Dark Wolf, specializing in covert entry, OSINT, social engineering, and adversary-driven Red Team operations. His work includes physical and electronic access control bypassing, physical site assessments, surveillance, wireless and network penetration testing, web application security, and full-spectrum offensive security testing across government and commercial environments.

\n\n

With his experience across private industry and government sectors, Brent has conducted assessments against highly secured facilities and critical infrastructure designed to emulate real-world adversaries. He is a co-author of the popular ACCESS LOGS series with Covert Instruments and has worked alongside law enforcement agencies supporting special operations cyber initiatives.

\n\n

Brent contributed to drone hacking methodology development for the Defense Innovation Unit\'s Blue sUAS initiative and helps lead Aerospace Village Drone Hacking operations at DEF CON. He has also been featured on Microsoft’s Roadtrip Nation, ProfilingEvil with Mike King, Hak5, Security Weekly, and BBC News, while his work has been highlighted by IDG Enterprise’s CSO Online and Help Net Security.

\n\n

Through WeHackPeople.com, Brent continues contributing to the security industry and InfoSec community by sharing real-world tradecraft, lessons learned, and both traditional and non-traditional techniques used in commercial and government operations.

\n\n\n\'',NULL,1294094),('4_Sunday','12','12:30','12:59','N','Game Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'SH4ZAM: Accelerated Vector Math on the Sega Dreamcast\'','\'Falco Girgis\'','Creator Talks_ff626827b8c10a74a8124b9086bb95a7','\'Title: SH4ZAM: Accelerated Vector Math on the Sega Dreamcast
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

SH4ZAM is a hardware accelerated, fast math and linear algebra library targeting the Sega Dreamcast. It began as a collection of hand-optimized SH4 assembly routines I wrote to boost the performance of our \"impossible\" ports of Grand Theft Auto 3 and Vice City to the DC. It has since evolved into a standalone library, offering a full, optimized math solution to the Sega Dreamcast homebrew community at large, accelerating the performance behind many of the community\'s other high-profile ports (Super Mario 64, Mario Kart 64, Star Fox 64, and now Zelda: Ocarina of Time) as well as original homebrew games, apps, and engines.

\n\n

Despite targeting a game console that is over 25 years old now, the library is written to be especially cutting-edge, targeting the latest GCC 15.2 toolchains and providing dual, modern C23 and C++23 APIs. Additionally, it now features a generic software back-end, which allows for the library to be built for any non-Dreamcast target, facilitating easily porting SH4ZAM\'d code or utilizing it in cross-platform codebases. The software back-end has already enabled the community to re-port our Dreamcast port of Super Mario 64 to the Nintendo Gamecube without having to change a line of math code!

\n\n

For the talk, I\'d like to cover an array of topics, touching on the specific hardware features of the Dreamcast\'s FPU that SH4ZAM is exploiting via SH4 assembly, high-level overviews of the library\'s architecture and layering of its C and C++ APIs, and providing some general takeaways for modern vectorization libraries, as a lot of this is applicable to many other game consoles or even modern performance-focused mathematics libraries in general.

\n\n

The talk will also feature a brief introduction to the Sega Dreamcast homebrew scene, explaining why the console remains such an ideal target for indie developers despite its age and including a high-level overview of the tools and SDK we use to develop modern software for it. Finally, the talk will feature many screenshots and embedded video segments of some of these SH4ZAM\'d up codebases, including many of our high-profile AAA ports.

\n\nSpeakerBio:  Falco Girgis
\n

Falco Girgis is a veteran developer in the Sega Dreamcast homebrew scene and a regular contributor to the KallistiOS indie SDK and operating system, where he has worked to bring support for modern C23 and C++23 language standards to the platform. He has been involved in many high-profile ports to the DC, such as Grand Theft Auto 3, Grand Theft Auto: Vice City, Mario Kart 64, Sonic Mania, and more!

\n\n\nLinks:
    Github - https://github.com/gyrovorbis/sh4zam
\n\'',NULL,1294095),('4_Sunday','12','12:30','12:59','N','ICS Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Two NICs, Zero Trust: Pulling Apart a PAC Buried in Critical Infrastructure\'','\'Adam Bromiley,Sam Thom\'','Creator Talks_da2cd0ed94c3f37564a9a64c3d3c7988','\'Title: Two NICs, Zero Trust: Pulling Apart a PAC Buried in Critical Infrastructure
\nTags: ICS Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Imagine you get called up by a large CNI operator - \"We have these devices, they\'re all over our outstations and they sit between our most critical OT trust zones\", would you want to take a look? We did what any curious gremlins would do: we bought the hardware, built a bench, and started pulling at every thread. This talk tells the investigation as it actually happened, starting with architecture and documentation, moving through firmware analysis and protocol dissection, and ending with full pwnage at the firmware and application layers. Along the way we found a security model that felt frozen in the 2010s: weak trust boundaries, unauthenticated reconfiguration paths, and cryptographic protections as strong as wet cardboard. The point of the talk is not \"bench testing is cool.\"; It\'s how to take a standard CNI concern into a hardware-led investigation that uncovers flaws a network-only pen test will miss. Attendees will leave with a practical workflow for assessing OT devices at scale, a mental model for deciding when to go from docs to firmware to hands-on testing, and a clear picture of how apparently boring PACs can become high-value footholds inside critical infrastructure. Nation-state level firmware backdoors and research artefacts will be released alongside this talk.

\n\nSpeakers:Adam Bromiley,Sam Thom
\n
\nSpeakerBio:  Adam Bromiley, Pen Test Partners
\n

Adam is a security consultant at Pen Test Partners who specialises in industrial\ncontrol systems and embedded hardware security. He's worked on everything safety-critical:\nfrom high-speed rail to aircraft, power stations, and gas distribution. His embedded work has\nseen him break driverless cars, slot machines, and drones and has led to the responsible

\n\n

disclosure of numerous vulnerabilities in industrial controllers. Adam enjoys hands-on and\nboots-on-the-ground testing, reverse engineering, and providing practical security advice for\ncomplex real-world systems.

\n\nSpeakerBio:  Sam Thom
\n

Sam is a security consultant at Pen Test Partners who focuses on the weird stuff\n- hardware, IoT and Operational Technology. He's poked and prodded Industrial and\nembedded systems across various industries like automotive, IoT, IIoT, chemical, water,\npower, gas, manufacturing and his favourite of all - the alcohol industry. Sam enjoys tearing\ndown operational systems on the bench almost as much as owning them in the field.

\n\n\n\'',NULL,1294096),('0_Wednesday','18','18:30','21:30','N','Social Gatherings/Events','Other / See Description','\'DC713 and DC281 - 8th Annual DEF CON Texas Groups Meetup\'','\'\'','Social Gatherings/Events_b12f09c20a3ed06d8fea251e6f9b136e','\'Title: DC713 and DC281 - 8th Annual DEF CON Texas Groups Meetup
\nTags: Meetup
\nWhen: Wednesday, Aug 5, 18:30 - 21:30 PDT
\nWhere: Other / See Description
\n
\nDescription:
\n

We are back hacker fam!

\n\n

The Texas Crew welcomes all DEF CON friends to our 8th annual meetup.

\n\n

Hosted by The Cornish Pasty

\n\n

10 E Charleston Blvd, Las Vegas, NV 89104

\n\n

Come for the friends. Stay for the pasties. See you there!

\n\nLinks:
    Google Maps - https://maps.google.com/maps?ll=36.158523,-115.152926&z=15&t=m&hl=en-US&gl=US&mapclient=embed&q=10%20E%20Charleston%20Blvd%20Las%20Vegas%2C%20NV%2089104
\n    Cornish Pasty Co - https://www.cornishpastyco.com/
\n\'',NULL,1294097),('0_Wednesday','19','18:30','21:30','Y','Social Gatherings/Events','Other / See Description','\'DC713 and DC281 - 8th Annual DEF CON Texas Groups Meetup\'','\'\'','Social Gatherings/Events_b12f09c20a3ed06d8fea251e6f9b136e','\'\'',NULL,1294098),('0_Wednesday','20','18:30','21:30','Y','Social Gatherings/Events','Other / See Description','\'DC713 and DC281 - 8th Annual DEF CON Texas Groups Meetup\'','\'\'','Social Gatherings/Events_b12f09c20a3ed06d8fea251e6f9b136e','\'\'',NULL,1294099),('0_Wednesday','21','18:30','21:30','Y','Social Gatherings/Events','Other / See Description','\'DC713 and DC281 - 8th Annual DEF CON Texas Groups Meetup\'','\'\'','Social Gatherings/Events_b12f09c20a3ed06d8fea251e6f9b136e','\'\'',NULL,1294100),('4_Sunday','13','13:30','14:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4)','\'Contest Closing Ceremonies & Awards\'','\'\'','DEF CON Talks_c50e9110c9ddc4fe72aa9ad642b4b9a8','\'Title: Contest Closing Ceremonies & Awards
\nTags: DEF CON Official Talk
\nWhen: Sunday, Aug 9, 13:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4) - Map
\n
\nDescription:
\n\n\n\'',NULL,1294101),('4_Sunday','14','13:30','14:59','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4)','\'Contest Closing Ceremonies & Awards\'','\'\'','DEF CON Talks_c50e9110c9ddc4fe72aa9ad642b4b9a8','\'\'',NULL,1294102),('4_Sunday','15','15:00','17:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4)','\'DEF CON Closing Ceremonies & Awards\'','\'Jeff \"The Dark Tangent\" Moss\'','DEF CON Talks_120faa19c8290a793f02169ff0329cb8','\'Title: DEF CON Closing Ceremonies & Awards
\nTags: DEF CON Official Talk
\nWhen: Sunday, Aug 9, 15:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Jeff \"The Dark Tangent\" Moss
\n

Mr. Moss is an internet security expert and is the founder of both the Black Hat Briefings and DEF CON Hacking conferences.

\n\n\n\'',NULL,1294103),('4_Sunday','16','15:00','17:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4)','\'DEF CON Closing Ceremonies & Awards\'','\'Jeff \"The Dark Tangent\" Moss\'','DEF CON Talks_120faa19c8290a793f02169ff0329cb8','\'\'',NULL,1294104),('4_Sunday','17','15:00','17:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1006,904 (Main Tracks 1,4)','\'DEF CON Closing Ceremonies & Awards\'','\'Jeff \"The Dark Tangent\" Moss\'','DEF CON Talks_120faa19c8290a793f02169ff0329cb8','\'\'',NULL,1294105),('3_Saturday','15','15:30','15:59','N','Biohacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'DarkSyringe: Automated poisoning of Clinical AI Assistants Through PDFs (a physician\'s point of view)\'','\'Francesco Costa\'','Creator Talks_71e11cddc5a0ba9c756368b5bb7dcbc9','\'Title: DarkSyringe: Automated poisoning of Clinical AI Assistants Through PDFs (a physician\'s point of view)
\nTags: Biohacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Doctors are burned out and turning to LLMs — uploading discharge letters, lab reports and papers into ChatGPT, Claude and clinical AI tools. Every PDF is an unvalidated input to a system that cannot tell real facts from injected lies.\nWe introduce Divergent Prompt Injection: unlike classic attacks (\"\"ignore previous instructions\"\"), divergent payloads are clinically plausible false statements — a wrong drug, a fabricated contraindication, a phantom diagnosis — embedded in medical content. They create no semantic conflict, trigger no detection system, and sit indistinguishable from real medicine until an LLM summarizes them into a treatment plan.

\n\n

We release DarkSyringe, an open-source tool automating the full attack chain: PDF ingestion, de-identification, LLM-driven payload generation, injection and multi-model scoring. In testing, a single poisoned discharge letter caused multiple commercial LLMs to recommend wrong drugs, fabricate contraindications and invent diagnoses — errors that would directly harm patients.

\n\n

This talk brings a physician\'s perspective: understanding why even a low-complexity attack becomes critical when it lands in a clinical environment built on time pressure, trust, and information overload.

\n\nSpeakerBio:  Francesco Costa
\n

Hand surgeon trainee and cybersecurity researcher focused on LLM security. Creator of DarkSyringe, combining real clinical experience with offensive research to expose the limits of current defenses.

\n\n\n\'',NULL,1294106),('3_Saturday','16','16:00','16:30','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Quantum-Ready or Not: What 1,000 Codebases Reveal About Cryptographic Risk\'','\'Dr. Zulfikar Ramzan\'','Creator Talks_583c0114a8b3c7d54a665b4aa65c2c76','\'Title: Quantum-Ready or Not: What 1,000 Codebases Reveal About Cryptographic Risk
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Many people are aware of the quantum threat to cryptography, but how extensive is this issue? We analyzed 1,000* high-profile open-source repositories, including OpenVPN, Curl, and Bitcoin, and found that cryptographic risk is pervasive and hidden. 94% of repositories contain at least one cryptographic issue that would become exploitable in a post-quantum setting*, while 92% contain an issue that is already considered insecure by today’s standards*. The median repository contains 185 quantum-relevant weaknesses of moderate severity or higher, nearly double the classical median of 95*, indicating that there is substantial and underrecognized quantum exposure. Notably, thousands of findings are what we call “PQ-invisible;” they appear secure under classical assumptions but would become vulnerable with sufficiently powerful quantum capabilities*, revealing a critical blind spot in current security practices.

\n\n

These results highlight a gap between real-world cryptography and post-quantum readiness at a time when NIST migration timelines are approaching and Q-Day remains unpredictable. Unlike prior talks that focus on surface-level generalities, this talk is grounded in empirical analysis of source code across a large corpus of highly-used repositories.

\n\n

We will give a brief overview of the quantum threat, such as current estimates of quantum progress, NIST standardization, and attacks such as Harvest Now, Decrypt Later (HNDL) and Trust Now, Forge Later (TNFL). We will then present our methodology and results, including detailed breakdowns of cryptographic types, algorithms, and security postures across public-key cryptography, symmetric encryption, hashing, password hashing, TLS, and MACs.

\n\n

Whether you’re new to the quantum threat to cryptography or all-too-familiar with it, we hope to provide a clearer understanding of the current state of cryptography and the post-quantum migration.

\n\n

*Statistics based on an initial sample of 100 repositories; results will be updated as the dataset scales to 1,000.

\n\nSpeakerBio:  Dr. Zulfikar Ramzan
\n

Dr. Zulfikar Ramzan is Chief Technology and AI Officer at Point Wild, a global leader in AI-powered cybersecurity. He spearheaded the development and launch of Lat61, a highly scalable, extensible AI platform that consolidates data from multiple sources to detect multi-vector attacks, optimize protection across 50+ products and support over 25 million active users. He also leads the Lat61 Threat Intelligence Team, directing research into emerging threats and strengthening Point Wild’s Lat61 platform.

\n\n

Dr. Ramzan has over 20 years of experience in cybersecurity. At Aura, he served as Chief Scientist and Board member, leading the development of AI-driven platforms such as Aura Call Protection, Aura Message Protection, Smart Vault, and the Apollo platform for AI workloads. He has also held senior leadership roles at RSA as Chief Technology Officer and Chief Digital Officer. Earlier in his career, he contributed to Symantec Endpoint Protection and advanced machine learning–powered technologies at Immunet, now part of Cisco. He holds a PhD from MIT and is an inventor on more than 60 patents in cybersecurity and applied cryptography.

\n\n\n\'',NULL,1294107),('2_Friday','16','16:30','16:59','N','AI Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'AgentBreaker: A blind spot detector for your coding agents\'','\'Aditi Narasimhan,Farzaan Kaiyom\'','Creator Talks_a8649d0a915a8b46ab338fe6b00a03be','\'Title: AgentBreaker: A blind spot detector for your coding agents
\nTags: AI Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Coding agents have the capability to write and ship production code with little human review, which can lead to large-scale security threats. At Corridor, we believe in securing code generation at the source: by augmenting coding agents with the necessary security tooling.

\n\n

While evaluating our product, we quickly realized that there was no principled way to measure whether a given agent harness actually performs well on the axes we care about (like security). Static benchmarks go stale, get contaminated, and rarely capture the multi-step behavior of an autonomous agent.

\n\n

To address this, we introduce AgentBreaker, an open-source framework that extends the automated benchmark construction tool AutoBencher, taking it from evaluating single LLM calls to full coding-agent harnesses. We instantiated the framework on our task of secure code generation and show that it reliably surfaces actionable, agent harness-specific weaknesses.

\n\n

We release AgentBreaker and its methodology so you, too, can evaluate agent harnesses on the axes that matter to you.

\n\nSpeakers:Aditi Narasimhan,Farzaan Kaiyom
\n
\nSpeakerBio:  Aditi Narasimhan
\n

Aditi Narasimhan is the founding AI research engineer at Corridor, where she works to improve the security of agentic code generation tools. Previously, she was at Carnegie Mellon, where her research focused on AI ethics, pragmatic theory, and tech ethics pedagogy.

\n\nSpeakerBio:  Farzaan Kaiyom
\n

Farzaan has built AI products at startups from the pre-seed stage through Series C, wearing hats as a founder and ML Engineer. He holds a BS/MS in Computer Science from Stanford where he focused on AI safety. While at Stanford CRFM, he worked on HELM, which won the Stanford Open Source Software Prize, and presented research at ICLR.

\n\n\n\'',NULL,1294108),('2_Friday','13','13:00','13:59','N','Radio Frequency Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Running your own LTE network for fun and profit????\'','\'Lozaning\'','Creator Talks_fb42979939ce00b734b7f19ecada5e81','\'Title: Running your own LTE network for fun and profit????
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Running your own LTE network for fun and profit

\n\n

This presentation will cover the journey from zero to dial tone on an fully legal OTA LTE network. We\'ll cover the equipment (both enodeB, user equipment, and sim cards), software stack (LTE Core, VoLTE services, e-sims), licensing and permitting requirements, how to bridge our network into SS7/POTS, and with any luck include a live demonstration of a call between phones connected to Lozaning-Tel.

\n\n

We\'ll also briefly get into the the myriad ways with which we can leverage our privileged position as a trusted network operators to invalidate mobile security assumptions.

\n\nSpeakerBio:  Lozaning
\n

Lozaning (they/them) has been wardriving for over 10 years and enjoys designing, building, and assembling unorthodox network observation platforms such as: The Wifydra , The International Wigle Space Balloon, and turning an Amtrak roomette into a mobile radio observation lab. Lozaning loves all things wifi and high precision GNSS related, and is starting to maybe figure out BLE.

\n\n\n\'',NULL,1294109),('2_Friday','13','13:00','13:30','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Trust the Basics, But Know Their Limits: Where Standard Cybersecurity Advice Falls Short\'','\'Yael Grauer\'','Creator Talks_4346341a846ed43a03cc84f707b04d2d','\'Title: Trust the Basics, But Know Their Limits: Where Standard Cybersecurity Advice Falls Short
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Those cybersecurity tips you’ve heard over and over again are still our best defense against attackers, but following them doesn’t actually protect you from everything.

\n\n

In 2026, we know that freezing your credit won’t protect you from most scams, and that even the strongest password manager can’t save a compromised device. So what actually works, and where does it fall short?

\n\n

The advice is good. The gaps are real. Come learn both.

\n\nSpeakerBio:  Yael Grauer
\n

Yael is an investigative tech reporter covering privacy and security, digital freedom, hacking, and mass surveillance. She contributed to a Pulitzer Prize-winning AP investigative package on surveillance, and spent six years at a media nonprofit managing cybersecurity tools and programs that reached hundreds of thousands of users. She holds a CIPP-US certification and has completed way too many cybersecurity and source protection programs.

\n\n\n\'',NULL,1294110),('2_Friday','13','13:30','13:59','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Hacking Airplanes at the NTSB\'','\'David Case,Jonathan Xue\'','Creator Talks_f90b328d30ea4c47a6d0358ca367855e','\'Title: Hacking Airplanes at the NTSB
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

NTSB Vehicle Recorder Specialists Jonathan Xue and David Case will give a talk on decoding data recovered from several aircraft accidents, and a tourist submarine raised from the depths of the North Atlantic. The NTSB\'s process for getting data out of broken and damaged equipment will be shown, including searching through gigabytes of random data to find a log, and then converting that data to something human readable. Jonathan and David specialize in converting undocumented binary data recovered from accidents into graphs and charts usable in investigation. Quite often, they are the first people to see what actually happened in an accident.

\n\nSpeakers:David Case,Jonathan Xue
\n
\nSpeakerBio:  David Case, NTSB
\nNo BIO available
\nSpeakerBio:  Jonathan Xue, NTSB
\nNo BIO available
\n\n\'',NULL,1294111),('2_Friday','14','14:00','14:30','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Inside the Guts of Ransomware\'','\'Ashley Hiram Muñoz\'','Creator Talks_37e46edfac0ce184f9c9336b5ae5080f','\'Title: Inside the Guts of Ransomware
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Have you ever wondered how malware analysts identify different encryption algorithms in ransomware samples? In this session, I\'ll explain the design of some algorithms (such as AES, RSA, ChaCha20, etc.) and show you how to identify them using reverse engineering and debugging techniques, and by using ransomware demos from recent incidents.

\n\nSpeakerBio:  Ashley Hiram Muñoz, Kaspersky - Incident Response Specialist
\n

I currently work as an Incident Response Specialist on Kaspersky\'s Global Emergency Response Team (GERT). I live in Mexico and have over seven years of experience in Incident Response, Digital Forensics, Malware Analysis, and Reverse Engineering. Before joining DFIR, I worked for two years as a Penetration Tester.

\n\n

I have collaborated on various Threat Hunting and Threat Intelligence projects.

\n\n

Additionally, I have been a speaker at international events such as DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, HackGDL, BugCON, Pwnterrey, and others. I currently teach the Digital Forensics, Malware Analysis, and Incident Response modules in an information security diploma program at UNAM (Universidad Nacional Autónoma de México).

\n\n

Certifications: GREM, GCFA, GCFR, eCTHP, CHFI.

\n\n

--

\n\n

Actualmente me desempeño como Incident Response Specialist en el Global Emergency Response Team (GERT) de Kaspersky, cuento con +6 años de experiencia realizando Respuesta a Incidentes, Análisis Forense Digital, Análisis de Malware y Reversing; previo a dedicarme a DFIR laboré 2 años como Penetration Tester.

\n\n

He colaborado en distintos proyectos de Threat Hunting y Threat Intelligence.

\n\n

Adicionalmente, he sido ponente en eventos internacionales como DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, BugCON, etc.

\n\n

Actualmente soy profesor de los módulos de Análisis Forense, Análisis de Malware y Respuesta a Incidentes en un diplomado de seguridad de la información de la UNAM.

\n\n

Certificaciones: GREM, GCFA, eCTHP, CHFI.

\n\n\n\'',NULL,1294112),('4_Sunday','11','11:00','11:30','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Cove: Compositional and Verifiable Confidential Computing Workflows\'','\'Stephanie,Robin,Erika Lee\'','Creator Talks_207eaa7f1f81eb851526e484e52bb004','\'Title: Cove: Compositional and Verifiable Confidential Computing Workflows
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Confidential computing systems involve computation over private inputs held by mutually distrusting parties while producing public, cryptographically verifiable evidence of what was computed. Trusted execution environments (TEEs) are a practical building block for these systems, enabling code to run inside hardware-encrypted enclaves that emit attestations binding a measurement of the loaded code to genuine hardware. We present Cove, a framework that composes attested computations into multi-stage, multi-party workflows structured as directed acyclic graphs. Each node runs in its own enclave, decrypts private inputs only under attestation-gated key release, and emits a certificate that downstream nodes can require as a cryptographic precondition before consuming upstream artifacts; anyone holding the workflow bytes and the TEE vendor\'s attestation roots can verify the whole chain non-interactively. We show that a small set of reusable primitives - confidential artifact provisioning, encrypted dynamic outputs, attested ephemeral-key channels (RA-TLS), and certificate-gated preconditions - compose into systems that lift attestation from verified code identity to verified runtime properties, and use this to express practical applications in secure AI systems including confidential AI inference, attested AI benchmarks, and training-code verification. We give an open-source reference implementation on Intel TDX via Phala Cloud\'s dstack and demonstrate end-to-end feasibility with an attested benchmark workflow.

\n\nSpeakers:Stephanie,Robin,Erika Lee
\n
\nSpeakerBio:  Stephanie
\n

Stephanie is a research engineer working on AI security and safety. Her research interests include adversarial robustness, agent security and verifiable AI deployments. Previously, she was at Meta, where she worked on AI safety and security evaluations (CyberSecEval) and guardrails (PromptGuard, LlamaFirewall), and prior to that she worked on application security for web and mobile.

\n\nSpeakerBio:  Robin
\n

Robin is a Member of Technical Staff at Inferact (maintainer of vLLM), working towards the best inference stack of the future. Previously he worked as a software engineer at Near Protocol, Meta, Google, and Twitter. His interests include application security, model red-teaming, distributed systems, and GPU performance optimization.

\n\nSpeakerBio:  Erika Lee
\n

Erika Lee is a 3rd-year Math–Computer Science undergraduate student at UC San Diego and a MATS 9.1 AI Security Fellow. Her research interests are in verifiable and privacy-preserving AI, and building secure and trustworthy AI systems. She previously interned with the US Department of Defense\'s AI/ML portfolio and the U.S. Army, working on deploying AI/ML systems in classified environments.

\n\n

Bing-Jyue Chen is a 3rd-year PhD candidate in Computer Science at UIUC. His current research focuses on zero knowledge machine learning (zkml). He is also interested in verifiable AI, privacy-preserving machine learning, and advanced cryptography.

\n\n

Daniel Kang is an assistant professor at UIUC in the computer science department. His research focuses on making analytics with machine learning easy for scientists and analysts to use, and has been supported by Google, the Open Philanthropy project, Emergent Ventures, and others. He has consulted at OpenAI, Google, Microsoft, hedge funds, and other companies to support their ML deployments, and advised a number of startups.

\n\n\n\'',NULL,1294113),('2_Friday','14','14:30','15:15','N','OWASP Foundation','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Defend zee clankers: OWASP AI Security Verification Standard (AISVS)\'','\'Jim Manico\'','Creator Talks_1c7b8ce59cf036aca884b3a39b358c03','\'Title: Defend zee clankers: OWASP AI Security Verification Standard (AISVS)
\nTags: OWASP Foundation | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:30 - 15:15 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

AI systems face threats that traditional application security standards weren\'t built to address. This includes prompt injection, training data poisoning, model extraction, agentic autonomy risks, and more. The OWASP AI Security Verification Standard (AISVS) provides 400+ testable requirements across 14 chapters, covering everything from input validation and model lifecycle management to MCP protocol security and autonomous agent controls. This lightning talk introduces the standard\'s structure, its three verification levels, and how security teams can use it today to assess and harden AI-powered applications. We\'ll show where AISVS fits alongside existing frameworks like ASVS, NIST AI RMF, and ISO 42001 and where it deliberately doesn\'t overlap.

\n\nSpeakerBio:  Jim Manico, Founder at Manicode Security
\n

Jim Manico is the founder of Manicode Security, where he specializes in training software developers on secure coding and security engineering. He is actively involved in multiple ventures, serving as an investor/advisor for companies like 10Security, MergeBase, Nucleus Security, KSOC, and Inspectiv, among others. Jim is a recognized speaker, focusing on secure software practices, and holds a distinguished position as a member of the Java Champion community. He is also the esteemed author of \"Iron-Clad Java: Building Secure Web Applications\" published by Oracle Press.

\n\n

Additionally, Jim generously volunteers for the OWASP foundation, co-leading key projects such as the OWASP Application Security Verification Standard and the OWASP Cheatsheet Series.

\n\n\nLinks:
    Website - https://owasp.org/www-project-artificial-intelligence-security-verification-standard-aisvs-docs/
\n\'',NULL,1294114),('2_Friday','15','14:30','15:15','Y','OWASP Foundation','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Defend zee clankers: OWASP AI Security Verification Standard (AISVS)\'','\'Jim Manico\'','Creator Talks_1c7b8ce59cf036aca884b3a39b358c03','\'\'',NULL,1294115),('2_Friday','14','14:30','15:30','N','Packet Hacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Wiring the Harness: Orchestrating Frontier Models for Vulnerability Hunting at Scale\'','\'Tony Martin,Arie Haenel\'','Creator Talks_31bb4179c914795481bddd9ccbbeb81b','\'Title: Wiring the Harness: Orchestrating Frontier Models for Vulnerability Hunting at Scale
\nTags: Packet Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:30 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

While frontier models are powerful, simply asking one to \"find vulnerabilities\" is far less effective than pairing with a well-designed harness, a gap that widens further down the stack and peaks at embedded firmware. During Project Glasswing, Intel scanned hundreds of repositories, from firmware to containers. This talk covers common pitfalls in LLM vulnerability hunting and presents a multi-stage harness: reconnaissance and context compression, multi-model hunting, deduplication, false positive detection, and verification. We will explore selecting the right models per stage, cutting token costs, and, the real battle, reducing false positives, especially for lower-level code where accuracy is hardest.

\n\nSpeakers:Tony Martin,Arie Haenel
\n
\nSpeakerBio:  Tony Martin, Principal Engineer & Offensive Security Research lead at INT31 Security Research, Intel
\n

Tony Martin is a Sr. Principal Engineer in Intel’s INT31 Security Research team, where he focuses on emerging threats, software architecture and AI security. He has discovered thirty CVEs and one CWE and is senior staff at DEF CON’s Packet Hacking Village.

\n\nSpeakerBio:  Arie Haenel, Principal Engineer & Offensive Security Research lead, INT31 Security Research, Intel
\n

Arie Haenel is a Principal Engineer at Intel, where he leads ASSERT, an Offensive Security Research team. He has over 25 years of professional experience, in security research and security product development on a vast number of embedded platforms, at Intel, Cisco and NDS. In his spare time, Arie teaches security engineering as an Adjunct Lecturer at the Lev Academic Center.

\n\n\n\'',NULL,1294116),('2_Friday','15','14:30','15:30','Y','Packet Hacking Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Wiring the Harness: Orchestrating Frontier Models for Vulnerability Hunting at Scale\'','\'Tony Martin,Arie Haenel\'','Creator Talks_31bb4179c914795481bddd9ccbbeb81b','\'\'',NULL,1294117),('2_Friday','15','15:15','15:59','N','OWASP Foundation','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Breaking Secure: Antigenic Fun\'','\'Jon McCoy,Andra Lezza\'','Creator Talks_0bdf3aa6bd0b0c17706f9dcee7c00e36','\'Title: Breaking Secure: Antigenic Fun
\nTags: OWASP Foundation | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:15 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

How do you secure an autonomous system that can think for itself? We’re diving into the lifecycle of \"Antigenic\" systems. Join us in covering architecture analysis, vulnerability identification, and active exploitation.

\n\n

This isn\'t just theory; we will demonstrate practical attacks and then show you exactly how to detect and resist them.

\n\n

If you\'re using AI to automate your workflow, you need to know how to protect your \"digital friends\" from being turned against you. We’ll provide the tools and skills to master both sides of the breach.

\n\nSpeakers:Jon McCoy,Andra Lezza
\n
\nSpeakerBio:  Jon McCoy, Security Architect, OWASP
\n

Software security architect, Jon McCoy brings over 20 years of experience in software development and cybersecurity to the forefront. With a strong foundation in .NET development, Jon transitioned into security, driven by a passion for proactive defense strategies and secure coding practices.

\n\n

A dedicated contributor to the OWASP community, Jon has shared his expertise at numerous industry events, including OWASP Global AppSec. His recent presentation on \"Lessons Learned from Past Security Breaches\" highlighted critical takeaways for strengthening AppSec efforts before and after incidents.

\n\nSpeakerBio:  Andra Lezza, Principal Application Security Specialist at Sage / OWASP Leader
\n

Andra is a Principal Application Security Specialist at Sage, with over seven years of experience in the field of application security. She is responsible for implementing DevSecOps practices, conducting security assessments, and developing secure coding guidelines for software engineering and AI/ML teams. She has a strong background in software development and project management, as well as a master\'s degree in information and computer sciences. She has been co-leading the OWASP London Chapter since 2019, where she organises and delivers events and workshops on various security topics. She is passionate about educating and empowering developers and stakeholders to build and deliver secure software and best practices in a fast-paced, results-driven environment.

\n\n\n\'',NULL,1294118),('2_Friday','15','15:45','16:30','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Step Zero: Identifying the Quantum Attack Surface in Critical Infrastructure\'','\'Dr. Katrina Rosseini,Dr. Allan Friedman\'','Creator Talks_f168e617924cbdd8d67dc7ca40e65e11','\'Title: Step Zero: Identifying the Quantum Attack Surface in Critical Infrastructure
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:45 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Every wire transfer, banking session, API transaction, and SWIFT message depends on RSA and ECC cryptography that a sufficiently powerful quantum computer will eventually break with Shor’s algorithm. That part is well known.

\n\n

The real problem is that most financial institutions have no idea where that cryptography actually lives.

\n\n

RSA and ECC are buried inside banking APIs, certificate hierarchies, SWIFT authentication, third-party software dependencies, mobile applications, HSM integrations, and legacy infrastructure that was never designed for crypto-agility. Most organizations cannot inventory it, prioritize it, or migrate what they cannot find.

\n\n

This talk focuses on the real quantum attack surface inside financial infrastructure, not the theoretical one.

\n\n

We examine two high-impact cryptographic systems hiding in plain sight: • SWIFT authentication infrastructure securing interbank trust • TLS certificate hierarchies protecting banking sessions, APIs, and payment platforms

\n\n

Then we move from theory to operational reality.

\n\n

Using open-source Cryptographic Bill of Materials (CBOM) tooling, we demonstrate how to identify quantum-vulnerable cryptography across financial systems, uncover hidden RSA and ECC dependencies, and build usable cryptographic inventories that defenders can actually operationalize.

\n\n

We also examine why this is a current collection problem, not a future one. Nation-state adversaries are already harvesting encrypted financial traffic and long-lived sensitive data for future decryption under harvest-now, decrypt-later (HNDL) strategies. Your encrypted traffic does not need to be decrypted today to become valuable tomorrow.

\n\n

The talk includes:\n• Live CBOM generation using IBM CBOMkit\n• Discovery of hidden RSA and ECC dependencies inside financial infrastructure • Practical guidance for prioritizing post-quantum migration

\n\n

Not policy. Not hype. Tools, cryptographic visibility, and attack surface.

\n\nSpeakers:Dr. Katrina Rosseini,Dr. Allan Friedman
\n
\nSpeakerBio:  Dr. Katrina Rosseini
\n

Dr. Katrina Rosseini is a strategist at the intersection of cybersecurity, quantum computing, PQC, and AI, advising policymakers and stakeholders on U.S. positioning in global technology competition with national security at the core. She is the Founder of KRR Ventures Advisory and leads Critical Effect California, a forum that convenes policymakers, infrastructure operators, and private-sector leaders on cybersecurity and operational risk. As Chair of the Civilian Reserve (CR-ISAC), she supports a national network of veterans and civilian experts strengthening the resilience of critical infrastructure. A Visiting Fellow at the National Security Institute, Dr. Rosseini focuses on quantum risk and the post-quantum transition. She has briefed the nation\'s largest public pension fund and contributed to congressional and United Nations forums. She developed the QUEEN Framework, a quantum governance model integrating cryptographic risk into board-level decision-making, and SECUREGRID, a methodology for prioritizing vulnerabilities in operational technology. Her commentary has appeared in Forbes, S&P Global, and Fast Company, among others. She holds a Doctor of Engineering from George Washington University and an MBA in Finance.

\n\nSpeakerBio:  Dr. Allan Friedman
\nNo BIO available
\n\n\'',NULL,1294119),('2_Friday','16','15:45','16:30','Y','Crypto & Privacy Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Step Zero: Identifying the Quantum Attack Surface in Critical Infrastructure\'','\'Dr. Katrina Rosseini,Dr. Allan Friedman\'','Creator Talks_f168e617924cbdd8d67dc7ca40e65e11','\'\'',NULL,1294120),('2_Friday','16','16:00','16:30','N','Radio Frequency Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Practical Guidance for RF Researchers: Experiment First, Interfere Never\'','\'Andy Hendrickson\'','Creator Talks_817cd0b3b85942fd6e1db0d7e1dddf01','\'Title: Practical Guidance for RF Researchers: Experiment First, Interfere Never
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\nPractical Guidance for RF Researchers: Experiment First, Interfere Never. The world needs more experimentation. We want more high-quality experimentation that is reproducible, technically rigorous, and does not intentionally disrupt other spectrum users.
\n\n\n\nSpeakerBio:  Andy Hendrickson, Independent Researcher, Washington DC
\n

While at the Federal Communications Commission, I have had the opportunity to serve in two roles focused on advancing the nation’s communications infrastructure and technology policy.

\n\n

I currently serve as Chief of the Office of Engineering and Technology (OET), where I act as the FCC’s principal technical advisor. In this role, I help shape national spectrum policy, oversee equipment authorization, experimental licensing, and guide the agency’s technical direction to ensure regulatory frameworks keep pace with rapid innovation across the communications ecosystem.

\n\n

Previously, I served as Chief Technology Officer for the FCC’s Enforcement Bureau, providing strategic and technical leadership across cybersecurity, privacy, national security, robocall and robotext mitigation, network outage enforcement, and the protection of critical infrastructure such as 911 systems and GPS. I also advised the Office of the Field Director on technology and enforcement issues with national impact while coordinating closely with teams across the Commission.

\n\n

In my downtime, I\'m either deep in the world of audio recording and engineering or rocking out on various instruments.

\n\n

Before joining the FCC, I spent more than two decades in the telecommunications industry, including leadership roles at Verizon supporting the rollout of 5G and the development of the Verizon Cloud Platform.

\n\n

My background spans cloud computing, software-defined networking, virtualization, cybersecurity, and GIS, and I remain engaged with the broader technology community through organizations such as the Open Geospatial Consortium, Linux Foundation, Open Infrastructure Foundation, and Network Time Foundation.

\n\n

I am honored to work alongside dedicated public servants and industry partners helping ensure the United States maintains secure, innovative, and resilient communications systems.

\n\n

I hold dual degrees from Rutgers University, having studied at both the School of Environmental and Biological Sciences and the School of Communication and Information.

\n\n\n\'',NULL,1294121),('2_Friday','17','17:30','17:59','N','Quantum Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Covert Quantum Computing - a new quantum security paradigm\'','\'Evan Anderson\'','Creator Talks_5131e5c518be49aa540d74709be4ddd6','\'Title: Covert Quantum Computing - a new quantum security paradigm
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Quantum computers will inevitably move to multi-tenant systems for efficiency and throughput, with many users sharing a single QPU. This talk will discuss the realities of threats facing quantum computing \'as a service\' and what is particularly specific to quantum computing. We\'ll get you started on understanding the quantum computing tech stack, and work through a few examples of possible attacks and mitigation techniques, wrapping up our newly developed security paradigm of covert quantum computing. All of the examples presented in this talk can be run by anyone with an internet connection and an email address. This talk is for anyone curious about attacks (and mitigation) techniques in quantum computing, and similarly how to build and test new ideas. A quantum background is not required!

\n\nSpeakerBio:  Evan Anderson, UMD
\n

Evan is a postdoctoral researcher at the University of Maryland focusing on photonic (and atomic) quantum computing architectures.

\n\n\n\'',NULL,1294122),('2_Friday','16','16:30','17:15','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures\'','\'Diptendu Kar\'','Creator Talks_a51eddfd49230ea85c550aace5a0f6e4','\'Title: Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:30 - 17:15 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Developers keep getting crypto wrong in the same ways. Not the math, but the code around it. A missing check here, implicit trust there, and suddenly a signature means nothing. This talk is data-driven and hands-on. Starting from OWASP A04:2025, we examine real CVEs from GitHub Security Advisories as of January 2026 to show which crypto failure patterns actually dominate in the wild, then go deep on the top two: signature verification bypasses (including invalid curve attacks) and algorithm confusion bugs (JWT). Real libraries, live exploits. Demos and CTF challenges are woven throughout, involves audience interaction and participation. No crypto background required.

\n\nSpeakerBio:  Diptendu Kar
\n

Diptendu Kar is a security researcher focused on supply chain and dependency risk. He works on triaging open-source vulnerabilities, writing detection rules, and exploring how AI can automate tedious parts of security research. He also teaches Software Security Practices at Northeastern University part time and holds a Master’s in Cybersecurity. Before security, he worked as a Java developer at TCS. He is especially interested in patch diffing, vulnerable function detection, and the use of LLMs in AppSec. He believes cryptography is magic and AI is a noisy intern - helpful but always needs supervision.

\n\n\n\'',NULL,1294123),('2_Friday','17','16:30','17:15','Y','Crypto & Privacy Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Crypto Is Fine. The Code Is Not: Real-World Cryptographic Failures\'','\'Diptendu Kar\'','Creator Talks_a51eddfd49230ea85c550aace5a0f6e4','\'\'',NULL,1294124),('2_Friday','16','16:30','16:59','N','Recon Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Groking the Kill Chain\'','\'Anthony Russell\'','Creator Talks_85bc622be2ed6ffd39e2dccfdd1de6f2','\'Title: Groking the Kill Chain
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Most LLM-powered recon tools look impressive in a 90-second demo and fall apart on real targets. They hallucinate, loop, go out of scope, double-fire the same endpoint, or die the moment a WAF or rate limit appears. This talk is about what it actually takes to run fifty-plus specialist agents in parallel for hours or days without the chaos.

\n\n

We built a system where every agent is locked to the rails: a concrete tool, a strict pipeline phase, explicit prerequisites, timeouts, and sandboxes. The model does not drive. It rides. The binaries (and only the binaries) touch the target. This \"Agents on Rails\" approach eliminates freestyle LLM behavior while still letting the model do what it is good at—reasoning over evidence.

\n\nSpeakerBio:  Anthony Russell, Cyber Security Software Engineer
\n

Anthony Russell, is a senior cyber security engineer with over 13 years of professional experience building software. He has a focus in information security and has been featured in 2600 magazine, on Hak5 and has spoken at both Defcon and DerbyCon multiple times. Favorite things to discuss are blockchain technology, baking custom IoT devices, and everything infosec. You can see more of Anthony\'s work at SquidHacker.com or Twitter.com/DotNetRussell

\n\n\n\'',NULL,1294125),('3_Saturday','12','12:00','12:30','N','AI Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Minimize Harm, Maximize Defense: How Anthropic Navigates the Offense-Defense Divide\'','\'Curt Barnard⁩\'','Creator Talks_06dea0bd1bf7c3c908ed450404f4f6a4','\'Title: Minimize Harm, Maximize Defense: How Anthropic Navigates the Offense-Defense Divide
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\nCybersecurity capabilities are inherently dual use: the same tools that help defenders find and fix vulnerabilities can, in the wrong hands, be the precursor to a cyberattack. As AI models grow more capable, this tension intensifies. When Anthropic launched Claude Fable 5 with the strongest cybersecurity safeguards we have ever applied to a model, we were forced to make concrete decisions about where the line between defense and offense should be drawn.
\n\n

In this talk, we walk through how we reason about that line. We describe the four categories our safety classifiers use to evaluate cybersecurity activity: prohibited use (high harm, little defensive utility), high-risk dual use (core security professional work that we block until better access controls exist), low-risk dual use (mostly defensive, but blocked as part of a deliberate safety margin), and benign use (defensive and IT activities we aim to never block). We explain the tradeoffs behind each category and why we deliberately set Fable 5\'s safety margin larger than any prior model, accepting a higher rate of false positives in exchange for greater confidence that harmful requests would be caught.

\n\n

We also introduce an early version of the Cyber Jailbreak Severity (CJS) framework, which we continue to develop with our Glasswing partners to create a common industry standard for assessing how serious a given jailbreak is.

\n\n

This is not a finished answer. These categories, thresholds, and tradeoffs represent our best current thinking, but we anticipate they will evolve as model capabilities advance, as the legal and regulatory landscape shifts, and as we learn from the security community\'s experience using these tools in practice. We are sharing our framework because the people most affected by where these lines are drawn should have a voice in drawing them.

\n\nSpeakerBio:  Curt Barnard⁩
\nNo BIO available
\n\n\'',NULL,1294126),('2_Friday','17','17:00','17:59','N','Radio Frequency Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Latest News in the Proxmark World\'','\'Iceman\'','Creator Talks_cb55cbd756d47be9ed9a2297fc8801d9','\'Title: Latest News in the Proxmark World
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

A whirlwind tour of the latest developments in the Proxmark ecosystem, from new hardware announcements and firmware releases. We’ll explore what’s new in the RFID security landscape, highlight recent innovations from the community, and take a look at where the Proxmark platform is headed next. Whether you’re a long-time user or just getting started, this session will bring you up to speed on the most important updates from the Proxmark world.

\n\nSpeakerBio:  Iceman
\n

Christian Herrmann – RFID Hacker | Co-Founder of AuroraSec & RRG | MCPD Enterprise Architect

\n\n

Christian Herrmann, better known in the hacker community as “Iceman”, is a co-founder of\nAuroraSec and RRG, and has helped develop many of today’s most widely used RFID\nresearch tools, including the Proxmark3 RDV4 and the Chameleon Mini.

\n\n

He is a well-known RFID hacking and Proxmark3 evangelist, serving the community as both a forum\nadministrator and a major code contributor alongside other developers since 2013.\nChristian has spoken at hacker conferences around the world, including BalcCon, WHY-2025, Troopers, Black Hat Asia, DEF CON, Hardwear IO, SSTIC, NullCon, Pass-the-Salt, BSides Tallinn, BlackAlps, and SaintCon.

\n\n

He also runs a YouTube channel where he shares his knowledge of RFID hacking with the public.

\n\n

With over 14 years of experience in bespoke software development, Christian specializes in\n.NET platforms and is a Certified MCPD Enterprise Architect.

\n\n

He possesses near-unmatched expertise in the Proxmark3 architecture and various RFID\ntechnologies.

\n\n\n\'',NULL,1294127),('2_Friday','17','17:00','17:30','N','Quantum Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'Q-Day - the Early Years…\'','\'Konstantinos Karagiannis\'','Creator Talks_1c821f3b0cd0d855d1634ae37025e7c7','\'Title: Q-Day - the Early Years…
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n

Everyone\'s obsessed with the Hollywood idea of a quantum computer cracking RSA-2048 in seconds. But the real Act One of Q-Day won\'t be anything like a rapid-fire decryption spree: click, click, quantum stuff, “I’m in!” It\'ll be quieter, meaner, and quite possibly have nothing to do with harvest-now, decrypt later (HNDL)! This talk breaks down what the actual opening moves look like. Think forgery before decryption and signatures before secrets. Also, cracking ~73 emails a year with a five-day Gidney-style attack is a far less realistic nightmare than \"\"harvest now, decrypt everything.\"\" We\'ll first walk through the threat model hackers actually need to care about. Then we’ll cut to another nightmare scenario. Bitcoin. Because if any technology needs a Quantum Hail Mary, it’s blockchain. Spoiler: Bitcoin won\'t be ready by Q-Day. Join Konstantinos Karagiannis (@KonstantHacker) for a blockbuster treatment on where quantum attacks will start and who will get hit first. It’s not the apocalypse you were promised. It’s worse.

\n\nSpeakerBio:  Konstantinos Karagiannis, Protiviti
\nNo BIO available
\n\n\'',NULL,1294128),('2_Friday','17','17:15','17:59','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'2026 is the New 2016: Relearning the Lessons from the \"Year of the Data Breach\"\'','\'Anthony Hendricks\'','Creator Talks_3f862d8af07d146bcda4c34e95c11e68','\'Title: 2026 is the New 2016: Relearning the Lessons from the \"Year of the Data Breach\"
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:15 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Even before the clock struck midnight on January 1st, social media began posting how 2026 is the new 2016. With memes, throwback pictures, and nostalgic posts showing up on TikTok, X, and Instagram. While 2016 conjures up great memories for some, it wasn’t a banner year for cybersecurity. In 2016, several high-profile data breaches took place, including two Yahoo breaches that affected 1.5 billion user accounts. 2016 also saw headlines about incidents at LinkedIn, Oracle, and Dropbox. Commentators even began calling 2016 the “Year of the Data Breach.” If we don’t want 2026 to become the new 2016, we will have to relearn the data privacy lessons from the “Year of the Data Breach.” This presentation will explore the lessons that we should have learned from 2016 by first exploring current cybersecurity trends. Next, we will travel back to 2016 and examine the high-profile incidents that occurred that year. Then we will discuss how the problems we faced in 2016 are still impacting us now. Before, finally outlining ways to apply the lessons from 2016 to make us all a little safer.

\n\nSpeakerBio:  Anthony Hendricks
\n

Anthony Hendricks is a legal problem solver and litigator at Crowe & Dunlevy, one of Oklahoma’s largest and oldest firms. At Crowe & Dunlevy, Anthony serves as founder and chair of the firm’s Cybersecurity and Data Privacy Practice Group. His legal practice focuses on data privacy compliance, regulatory enforcement and permitting, and other “bet-the-company” suits in the areas of data security, privacy, and other complex business litigation. Anthony is an adjunct professor who teaches Cybersecurity Law and Information Privacy courses at Oklahoma City University School of Law. He also hosts “Nothing About You Says Computer Technology,” a weekly podcast on cybersecurity and data privacy viewed through the lens of diverse voices. To learn more about Anthony’s current projects and upcoming speaking events, or listen to the latest episodes of his podcast, visit www.anthonyjhendricks.com

\n\n\n\'',NULL,1294129),('3_Saturday','11','11:00','11:59','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Panel Discussion: Digging up Treasure in Gold Bug\'s Past\'','\'CPV Gold Bug Team 2026,Steven \"tseven\" Barker,Kevin \"CryptoK\" Hulin\'','Creator Talks_1a6c6fec83d9e912478ec0145f6ea478','\'Title: Panel Discussion: Digging up Treasure in Gold Bug\'s Past
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Join the Gold Bug puzzle creators as they discuss last year\'s contest with some members from the winning team, Shagworm. Get a glimpse into the thought process that goes into puzzles from both perspectives of creating and solving. They will share some guidance on how to get started on the Gold Bug Contest, some tips for approaching puzzles that seem to have no starting point, and maybe even some hints for this year\'s puzzles!

\n\nSpeakers:CPV Gold Bug Team 2026,Steven \"tseven\" Barker,Kevin \"CryptoK\" Hulin
\n
\nSpeakerBio:  CPV Gold Bug Team 2026
\nNo BIO available
\nSpeakerBio:  Steven \"tseven\" Barker
\n

Steven \"tseven\" Barker is a puzzle creator for the Gold Bug Contest at DEF CON. His career has included a wide spectrum of cybersecurity domains including research, incident response, penetration testing, and education. Steven\'s current role focuses on securing patient data in healthcare systems. Away from the computer screen, Steven has a passion for making things, breaking things, occasionally fixing broken things, and experiencing things made by other people or nature.

\n\nSpeakerBio:  Kevin \"CryptoK\" Hulin
\n

Kevin Hulin, aka CryptoK, is a crypto puzzle enthusiast and long time challenge creator for the Crypto & Privacy Village\'s Gold Bug Contest at DEF CON.

\n\n\n\'',NULL,1294130),('3_Saturday','11','11:30','11:59','N','Game Hacking Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Catching Cheaters in Super Smash Bros Melee\'','\'AltF4\'','Creator Talks_c06b54d99a16d7808b82cbef53d395fd','\'Title: Catching Cheaters in Super Smash Bros Melee
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Super Smash Bros Melee for the Nintendo GameCube is one of the oldest active fighting game communities, with a storied 25 year history.

\n\n

Would you believe that people try to cheat at it?!

\n\n

I am the maintainer of the SLP Enforcer tool, and help with cheating investigations for the community. I\'m going to share some stories of people trying to cheat and getting caught! Along the way I\'ll describe all the ways one could try to cheat at Melee, and how our detection tools work.

\n\nSpeakerBio:  AltF4
\n

Dan \"AltF4\" Petro is a Principal Security Engineer at Bishop Fox R&D. As a longtime pentester at Bishop Fox, Dan\'s presented public research on everything from hacking into smart safes, compromising the power grid, breaking into secure facilities, and cheating at online video games. There was even that time he found a vulnerability in (nearly) every IoT device. But Dan\'s favorite research project is always whichever is next.

\n\n\nLinks:
    Github - https://altf4.github.io/enforcer/
\n\'',NULL,1294131),('4_Sunday','12','12:30','12:59','N','AI Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Leveraging Large Language Models for Policy, Regulatory, and Compliance in IoMT: Opportunities, Risks, and Safeguards\'','\'Dr. Deepti Gupta,Sai Sitharaman\'','Creator Talks_40a0458a87501abad64f4d68c1d1bb72','\'Title: Leveraging Large Language Models for Policy, Regulatory, and Compliance in IoMT: Opportunities, Risks, and Safeguards
\nTags: AI Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

The rapid adoption of Large Language Models (LLMs) is transforming how organizations interpret and enforce policy, regulatory, and compliance requirements. In the context of the Internet of Medical Things (IoMT), where sensitive health data flows across distributed and resource-constrained devices, LLMs offer promising capabilities such as automated policy analysis, compliance monitoring, and intelligent decision support. However, their integration also introduces significant security, privacy, and trust challenges, including data leakage, model hallucinations, regulatory misinterpretation, and adversarial manipulation. This talk explores the dual role of LLMs as both enablers and potential risk amplifiers in IoMT ecosystems. It will examine how LLMs can assist in translating complex regulations (e.g., HIPAA-like frameworks), detecting compliance violations, and enabling adaptive policy enforcement across heterogeneous medical devices. At the same time, the session will highlight critical vulnerabilities, including privacy breaches, lack of explainability, and risks associated with using external or cloud-hosted models in healthcare environments. The workshop will conclude with practical design guidelines and architectural considerations for securely integrating LLMs into IoMT systems, emphasizing privacy-preserving techniques, federated approaches, and human-in-the-loop validation to ensure trustworthy and compliant deployment.

\n\nSpeakers:Dr. Deepti Gupta,Sai Sitharaman
\n
\nSpeakerBio:  Dr. Deepti Gupta
\n

Dr. Deepti Gupta is a tenure-track Assistant Professor at Texas A&M University-Central Texas. She was a Cloud Security Architect at Goldman Sachs. She received her Ph.D. in Computer Science from the University of Texas at San Antonio (UTSA). She received B.S. and M.S. degrees in Mathematics from India, the M.Tech. degree in Computer Engineering from India and an M.S. degree in Computer Science from UTSA. Dr. Gupta’s research interests lie in the areas of security and privacy in Agentic AI, LLMs, Internet of Things (IoT) leveraging cloud and edge computing. Her research interests also include the application of AI and Machine Learning to secure IoT and CPS infrastructures in various application domains, such as smart healthcare, wearable IoT and smart home. Dr. Gupta has received National Science Foundation (NSF) award and Department of Defense (DoD) award. She is an active team member of IEEE ComSoc Young Professionals, AnitaB.org, WiCyS, and also co-chair of the N2Women fellowship.

\n\nSpeakerBio:  Sai Sitharaman
\n

Sai Sitharaman is the Founder and Chief Technology Officer (CTO) of Zetafence Inc., a cloud security startup based in Dublin, California, focused on enabling enterprises to detect and mitigate cloud attack vulnerabilities. He received the B.E. degree in Computer Science from the National Institute of Technology, India, and the M.S. degree in Computer Science from Texas A&M University, College Station, specializing in security and network control algorithms. Prior to founding Zetafence, he contributed to the design and development of cloud networking and security products at Cisco, Juniper Networks, and Aruba (Hewlett Packard Enterprise), where he worked on distributed systems, network control algorithms, and cloud security infrastructure. His research interests include cloud security, artificial intelligence for cybersecurity, attack graph analysis, and risk quantification for cloud-native environments. He is an active contributor to the cybersecurity community through collaborations with organizations such as NIST, CNCF, and CISA, and is a frequent speaker at major cybersecurity conferences.

\n\n\n\'',NULL,1294132),('3_Saturday','13','13:00','13:59','N','Packet Hacking Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Building Better Backdoors Than China\'','\'Khael Kugler\'','Creator Talks_5d598bdbf5a970c7133a3d9a18746aae','\'Title: Building Better Backdoors Than China
\nTags: Packet Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

PhantomShell is a Linux command & control implant that sniffs traffic of active TCP services to create a bidirectional C2 channel through any open port, using only stateful inbound traffic. It captures packets at the link layer, allowing it to read packets destined for legitimate services. Responses are constructed as raw TCP frames with sequence numbers derived from the original connection, making them difficult to distinguish from the service\'s own replies. This effectively turns every open service port into a bind shell, making the implant effectively impossible to firewall so long as any service remains externally accessible.

\n\nSpeakerBio:  Khael Kugler, Lead Offensive Security Engineer, Praetorian Security, Inc.
\n

Khael Kugler is a Lead Security Engineer at Praetorian, where he primarily executes on red team and IoT engagements. Khael also volunteers as a red teamer for multiple CCDC regions, primarily focusing on linux persistence for SECCDC and WRCCDC (if you\'re interested in helping, reach out!).

\n\n\n\'',NULL,1294133),('3_Saturday','14','14:00','14:59','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Forget FIPS: An Analysis of Russian and Chinese Cryptographic Standards\'','\'1nfocalypse\'','Creator Talks_3d194b78c82ab5d0ec64ea0d8f27f165','\'Title: Forget FIPS: An Analysis of Russian and Chinese Cryptographic Standards
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Despite securing the connections of over a billion people, Russian and Chinese state cryptography often remains unfamiliar to western practitioners. We survey the GOST, ShangMi, and ZUC standards, their respective histories, designs, and the current academic understandings of their security. We additionally cover implementation conveniences, such as the use of AES-NI instructions with SM4 as a method of side channel hardening, and algorithmic peculiarities, such as the hidden substructure of the Kuznyechik and Streebog S-box. We conclude with considerations about why specific algorithms were standardized, and how they reflect the priorities of the respective nations that standardized them.

\n\nSpeakerBio:  1nfocalypse
\n

1nfocalypse is a GCC developer and cryptography enthusiast, with a particular focus on applied cryptography and implementation security. He has contributed to libstdc++-v3 and GCC\'s OpenMP implementation, authored cryptographic CTF challenges for C2 Society and the \"?Cube\" CTF, and has conducted security research leading to CVEs involving cryptographic aspects of Apache Druid and mbedTLS.

\n\n\n\'',NULL,1294134),('3_Saturday','14','14:00','14:30','N','AI Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'What we learned from SATAN about the MYTH of Mythos\'','\'Jeff Crume\'','Creator Talks_425ff92c9bc35ddc220896153dddcfc8','\'Title: What we learned from SATAN about the MYTH of Mythos
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Thirty years ago a new and powerful (at the time) vulnerability scanner burst onto the scene. SATAN (System Administrators Tool for Analyzing Networkds) sparked controversy by putting advanced network reconnaissance capabilities into the hands of ordinary defenders. Critics warned it would empower attackers and was, therefore, too dangerous to release publicly. In fact, it helped accelerate security awareness and improve defensive practices. Today, AI-powered security platforms such as Mythos face similar calls for restriction. This talk examines the lessons of SATAN and argues that limiting access to powerful security tools rarely stops capable adversaries, but often disadvantages defenders, researchers, and educators. As the security community debates AI’s future, history offers a valuable reminder: broad access to defensive capability has often strengthened security more than secrecy.

\n\nSpeakerBio:  Jeff Crume
\n

Jeff Crume is an IBM Distinguished Engineer and Master Inventor with more than 40 years’ experience in the IT industry. He has a PhD in Cybersecurity and serves as an Adjunct Professor at NC State University. Jeff’s YouTube videos have been viewed more than 25 million times and he is the author of a book entitled \"Inside Internet Security: What Hackers Don’t Want You To Know” as well as a contributing author to the \"Information Security Management Handbook.” He is a member of the inaugural class of the NC State University Computer Science Alumni Hall of Fame and serves on the editorial board for the “Information and Computer Security” research journal. Jeff lived in Beijing on assignment in 2006 and has worked with clients in 50 countries.

\n\n\n\'',NULL,1294135),('3_Saturday','14','14:30','14:59','N','AI Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'That\'s Not Your Agent: Why Zero Trust Can\'t Tell\'','\'Krity Kharbanda,Emma Yuan Fang\'','Creator Talks_b789d910c7703c1fdf61062c64df3775','\'Title: That\'s Not Your Agent: Why Zero Trust Can\'t Tell
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

What happens when every request is authenticated, every permission is scoped, every action logged, and the breach still happens without a single alert?\nZero Trust has been widely adopted to secure environments through continuous authentication and verification. But unlike human users, agentic AI is non-deterministic and autonomous by nature. The same agent, given the same task, will reason and act differently every time. It operates beyond the moment trust was granted, making decisions no human approved. Zero Trust has no reliable way to distinguish a legitimate agent from a compromised one.\nThis talk examines why standard controls break down. Behavioural baselining cannot establish a deviation threshold for a system with no stable baseline. IAM scoping cannot contain a compromised agent operating entirely within its authorised permissions. Continuous verification rechecks identity, not intent. When compromise occurs at the semantic layer, after authentication has already passed, every control evaluates correctly and finds nothing wrong.\nWe map real-world disclosed incidents onto the attack vectors of a typical agentic architecture, identifying precisely where each Zero Trust control fails during the agent lifecycle. We then demonstrate a live compromise inside a correctly configured Zero Trust environment, showing two simultaneous views: what the defender sees in the logs, and what is actually happening. An indirect prompt injection attack, delivered through a poisoned document, rewrites the agent\'s instructions from inside its own context window. Data exfiltration follows through authorised API calls. Zero violations fire. The logs show a clean run. The data is already gone.\nWe close with concrete mitigations from CSA\'s Agentic Trust Framework and MCP security guidance that teams can begin applying today.\nZero Trust controls who started the session. It has no visibility into who is running it now.

\n\nSpeakers:Krity Kharbanda,Emma Yuan Fang
\n
\nSpeakerBio:  Krity Kharbanda
\n

Krity Kharbanda is a Senior Application Security Engineer at ServiceNow, focused on application security, cloud security, and emerging AI-driven attack surfaces. Alongside her technical work, she leads community and professional development initiatives at Breaking Barriers Women in Cybersecurity (BBWIC), fostering mentorship, growth, and collaboration across the cybersecurity community. A frequent conference speaker, she is passionate about translating deep technical security research into practical insights while creating meaningful impact through community engagement.

\n\nSpeakerBio:  Emma Yuan Fang
\n

Emma is a seasoned Security Architect specialising in cloud security and AppSec. As Regional Practice Lead at EPAM, she leads a team of security practitioners across the UK&I, Switzerland, and Germany. Her focus has recently expanded into the intersection of LLMs, MCP, and security, exploring how agentic AI systems reshape the threat landscape. Beyond her day job, Emma is an award-winning conference speaker, a dedicated mentor, and Vice President of WiCyS UK&I, where she champions diversity in the cyber workforce.

\n\n\n\'',NULL,1294136),('3_Saturday','15','15:00','15:59','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'The Agent Long Con: Tricking Agents Out of Their Data\'','\'Patrick Walsh\'','Creator Talks_b296a9960510ad6e10f083f0c9e84a9f','\'Title: The Agent Long Con: Tricking Agents Out of Their Data
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Continuously running AI agents like OpenClaw are everywhere now and they\'re connected to everything. And despite all the doomposting, they’re mostly unhacked. So what gives? Why isn’t there a hacker gold rush against these systems?

\n\n

In this talk, we break down why the classic prompt injection playbook is failing against modern agent systems including OpenClaw. A single malicious webpage or email is not enough to hijack an agent in 2026. We’ll cover what’s changed to make that true.

\n\n

We’ll demonstrate attacks showing the ones that fizzle out and the ones that land in order to highlight which defenses are working and which ones are falling apart.

\n\n

Finally, we’ll shift from smash-and-grab exploits to something far more effective: the long con. By chaining subtle manipulations over time, we’ll show how attackers can steer, poison, and ultimately subvert AI agents for fun and profit.

\n\nSpeakerBio:  Patrick Walsh
\n

Patrick Walsh has an over 20 year history of running threat research and engineering teams overseeing products ranging from anti-virus and intrusion prevention to enterprise cloud software. He is a long-time advocate for privacy and security and holds multiple patents in that space. More recently, Patrick has built solutions to protect AI data and workflows. Patrick now leads IronCore Labs, an application data protection platform that uses encryption to protect data stored in the cloud while keeping it searchable and usable. Outside of work, he enjoys the outdoors, photography, hacking, lock picking, biking, swimming, and magic.

\n\n\n\'',NULL,1294137),('3_Saturday','15','15:00','15:59','N','Packet Hacking Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'There\'s A Bug in My Boot! Finding Vulnerabilities in U-Boot\'','\'Jared Stroud\'','Creator Talks_46152279fa61f85524aecab6af9ec3ea','\'Title: There\'s A Bug in My Boot! Finding Vulnerabilities in U-Boot
\nTags: Packet Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Bootloaders underpin the security of modern embedded systems. Their privileged position in the tech stack often means a vulnerability early in the boot process can result in total system compromise. Despite this, they frequently lack modern software security protections (ASLR, CFI, Stack Canaries), making them an easier target to exploit. This talk will explore hardware-in-the-loop, emulation, and native binary fuzzing approaches with U-Boot, a popular embedded system bootloader for networking devices, and the challenges each approach presents.

\n\nSpeakerBio:  Jared Stroud, Lead Reverse Engineer, The Johns Hopkins University Applied Physics Lab
\n

Jared Stroud is a Lead Reverse Engineer at The Johns Hopkins University Applied Physics Lab. Currently he\'s pursuing a Doctorate of Engineering focused on scaling vulnerability identification and remediation in embedded systems. For the past 7 years Jared has documented independent security research at Arch Cloud Labs (https://www.archcloudlabs.com/projects), and has presented workshops on reverse engineering topics at DEF CON, Shmoocon, and BSides Rochester.

\n\n\n\'',NULL,1294138),('2_Friday','17','17:30','17:59','N','OWASP Foundation','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'AI Pentesting is not a Vibe Check\'','\'Ads Dawson\'','Creator Talks_47663187114b86b9ea738810938c3484','\'Title: AI Pentesting is not a Vibe Check
\nTags: OWASP Foundation | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Most AI security assessments test the chatbot and miss the system. The founding technical lead\nof the OWASP GenAI Security Project covers what actually breaks when you pentest AI\napplications across three distinct attack tiers — model exploitation, application-layer flaws, and\nagentic architecture failures — drawing from frontier model red team operations, bug bounty\nsubmissions, and offensive cybersecurity evaluations.

\n\nSpeakerBio:  Ads Dawson, Staff AI Security Researcher, OWASP GenAI Security Project founder
\n

Ads Dawson founded the OWASP GenAI Security Project and led it to flagship status — the fastest in OWASP history. As a Staff AI Security Researcher at Dreadnode, he specializes in exploiting ML and AI systems, harnessing AI for offensive cybersecurity through capability development and exploit development, and conducting red team operations against frontier models for government, military, and tier-1 labs. He is lead author of AIRTBench (arXiv), the first benchmark for autonomous AI red teaming in LLMs, and author of AI Native LLM Security (Packt, 2025).

\n\n

A senior red team operator with BT6 (the frontier AI red team), ranked #2 in Canada on HackerOne (2025/2026), and selected for Meta\'s MBBRC live hacking event, Ads is a HackerOne US South Ambassador, BugCrowd Hacker Advisory Board member, MITRE AI Working Group contributor, and leads the OWASP Toronto chapter. He spoke at Bug Bounty Village DC33 on the BT6 AI jailbreaking panel and is also presenting \"Exfil Everything: A Year of Stealing Data from AI Agents\" at Bug Bounty Village DC34 (schedule pending publication).

\n\n\n\'',NULL,1294139),('2_Friday','10','10:30','10:59','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'What TEEs Do Not Hide: Residual Metadata Leakage in Confidential LLM Serving\'','\'Anup Swamy Veena\'','Creator Talks_e5359ab40d23f06e989f334b7ec1d08c','\'Title: What TEEs Do Not Hide: Residual Metadata Leakage in Confidential LLM Serving
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\n

Confidential LLM inference protects prompt, model, KV-cache, and intermediate-tensor memory, but it does not remove the metadata emitted by the serving stack. We audit those emitted surfaces on a verified H100 confidential-GPU serving setup using a dense/MoE Gemma pair. The claim is narrow: we do not show a TEE memory break, and corrected client timing does not support a leakage claim. We do show that client/proxy-observed HTTP-stream metadata and low-concurrency pre/post-scrape metrics reveal request attributes in this harness. Decomposition ties the signal to exported token counters, request bytes, response bytes, and application-level stream-chunk shape. Deployed mitigations suppress those carriers: token-counter redaction reduces metrics leakage, request padding removes the direct prompt-length row, and chunk padding suppresses the tested HTTP-stream rows. Memory confidentiality and metadata minimization are different properties, and confidential LLM serving needs both.

\n\nSpeakerBio:  Anup Swamy Veena
\n

I am a security researcher and engineer focused on cryptography, privacy, and AI systems. My work spans zero-knowledge proofs, trusted execution environments (TEEs), confidential computing, and secure distributed infrastructure, with a particular interest in building verifiable and privacy-preserving AI. Over the years, I have contributed to open-source cryptography projects in the Rust ecosystem and worked on cryptographic protocols, proving systems, and decentralized infrastructure. Currently, I focus on secure AI inference in TEE and attestations, verifiable computation, and the security of large-scale AI deployments, including research on metadata leakage in confidential AI systems and routing leakage in Mixture-of-Experts models. My interests lie in applying cryptographic techniques to build trustworthy systems at the intersection of security, distributed systems, and machine learning.

\n\n\n\'',NULL,1294140),('3_Saturday','16','16:00','16:59','N','Packet Hacking Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Why Couldn\'t I See My Own Drone? Remote ID, ESP32s, and the Packet Trail to Friend or Foe\'','\'Will Hatzer,Charles Grow\'','Creator Talks_9dd1082ccc1521651c435c95ba1a5975','\'Title: Why Couldn\'t I See My Own Drone? Remote ID, ESP32s, and the Packet Trail to Friend or Foe
\nTags: Packet Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Friend or Foe started when adding Remote ID support to an Android airspace app still failed to detect our own DJI drone. This led us into DJI Wi-Fi Beacon behavior, vendor information elements, ESP32 promiscuous capture, and conservative evidence handling using Bayesian fusion. This talk covers practical packet analysis techniques for Remote ID (BLE and Wi-Fi), hardware tradeoffs for reliable scanning, and how to avoid turning weak signals into overconfident alerts. Attendees will learn how to build honest, low-cost RF sensors and interpret packet evidence responsibly.

\n\nSpeakers:Will Hatzer,Charles Grow
\n
\nSpeakerBio:  Will Hatzer, Founder, GameChangersAI / Team Charity Case
\n

Will \"OGThorne\" Hatzer is a security engineer, adversarial researcher, and founder of GameChangersAI. He works in security engineering at OpenAI and builds open-source tools across RF, Android, embedded systems, and defensive security. A former DEF CON Car Hacking Village speaker, his work includes a bot-detection patent and Hyundai BlueLink research later referenced by CISA.

\n\nSpeakerBio:  Charles Grow, Hardware Designer / RF Researcher, Team Charity Case / GameChangersAI
\n

Charles \"OhYou_\" Grow is a hardware designer, RF researcher, and ham radio operator. He designed the Friend or Foe badge hardware, solving component layout, USB-C access, GPIO conflicts, and RF ground-plane challenges. His background in fox hunting, electronics, and field debugging helped turn early prototypes into a practical, wearable device.

\n\n\n\'',NULL,1294141),('3_Saturday','16','16:30','16:59','N','AI Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'Trust Amplification in Enterprise AI Systems – Microsoft CoPilot Case Studies Enabling AI-Assisted Influence Operations\'','\'Tobias Diehl\'','Creator Talks_1c34e62eca842afef4ef5d23cde26980','\'Title: Trust Amplification in Enterprise AI Systems – Microsoft CoPilot Case Studies Enabling AI-Assisted Influence Operations
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\n

Enterprise AI assistants such as Microsoft Copilot are rapidly becoming embedded in business workflows, granting them unprecedented influence over how users discover information, make decisions, and interact with organizational data. While much of the current security discussion focuses on prompt injection itself, the larger risk may be what happens after that influence occurs.

\n\n

This talk discusses the concept of Trust Amplification, a model in which attacker-controlled content gains credibility as it is transformed, contextualized, and redistributed by enterprise AI systems. Through real-world Microsoft Copilot case studies, we demonstrate how indirect prompt injection can influence document conversion workflows, persist through shared collaboration sessions, and transform traditional device code phishing into trusted AI-generated authentication guidance.

\n\n

Rather than introducing entirely new attack classes, enterprise AI systems can act as force multipliers for existing social engineering techniques by presenting attacker influence through trusted enterprise platforms and workflows. We conclude by introducing Locusta, an open-source enterprise AI collaboration and propagation toolkit developed to help red teams and defenders model these emerging attack paths and better understand how influence can spread through AI-assisted environments.

\n\nSpeakerBio:  Tobias Diehl
\n

Tobias Diehl is a Senior Offensive Security Engineer, security researcher, and Microsoft 2025 Most Valuable Researcher (MVR) specializing in offensive security, enterprise AI, bug bounty research, and adversary emulation. His work focuses on identifying overlooked attack paths where web applications, AI systems, and desktop software intersect, helping organizations understand how seemingly low-risk vulnerabilities can become high-impact security issues.\nTobias leads offensive security assessments, conducts purple team exercises, and performs research into emerging attack techniques affecting enterprise environments. His work has resulted in multiple security findings impacting Microsoft technologies, including Power Platform, CoPilot and other AI-driven applications.\nA returning DEF CON speaker, Tobias is passionate about sharing practical research that helps both security researchers and defenders better understand modern attack chains. His presentations emphasize real-world case studies, responsible disclosure, and actionable defensive guidance for securing the next generation of AI-enabled enterprise systems.

\n\n\n\'',NULL,1294142),('3_Saturday','17','17:00','17:59','N','Packet Hacking Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'Ghost Followers: Using AI to Unmask Fake LinkedIn Profiles at Scale\'','\'Aiswarya Venkitesh\'','Creator Talks_8b2c7cb04139fbf282c8aca781a4b837','\'Title: Ghost Followers: Using AI to Unmask Fake LinkedIn Profiles at Scale
\nTags: Packet Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

LinkedIn hosts over 1 billion profiles and a growing number are fake. From AI-generated profile photos to synthetic work histories, adversaries use fake identities for spear-phishing, social engineering, and influence operations. This talk breaks down the anatomy of a fake LinkedIn profile and demonstrates an AI-powered detection framework using behavioral signals, image forensics, and network graph analysis. Attendees will leave with a hands-on methodology and open-source toolset to identify synthetic identities before they become insider threats. Prior knowledge of networking fundamentals is helpful; no machine learning background is required.

\n\nSpeakerBio:  Aiswarya Venkitesh, Principal Cloud Solution Architect, Microsoft
\n

Aiswarya Venkitesh is a Principal Cloud Solution Architect at Microsoft Canada with 13+ years in Data & AI, specializing in agentic AI architecture, multi-agent orchestration, and enterprise Azure deployments. Ranked #4 globally in IT & Tech by Favikon with 55,000+ LinkedIn followers, she studies identity authenticity and influence operations on professional networks as both a practitioner and creator. She is a confirmed keynote speaker at Futura AI Conference 2026 and author of the forthcoming book The Agentic AI Playbook.

\n\n\n\'',NULL,1294143),('3_Saturday','17','17:00','17:59','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1104 (Creator Stage 4)','\'The National Fight Against ALPRs\'','\'Freddy Martinez,Sarah\'','Creator Talks_de470787e332c4cbe0c87272360b5984','\'Title: The National Fight Against ALPRs
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - Map
\n
\nDescription:
\n\n\nSpeakers:Freddy Martinez,Sarah
\n
\nSpeakerBio:  Freddy Martinez
\nNo BIO available
\nSpeakerBio:  Sarah
\n

Sarah has been working at the EFF on building out its local campaigns against surveillance, in particular on ALPR technology. Freddy and Arti have been at Lucy Parsons Labs which has been working on the explosive growth of ALPRs for over six years. LPLers have been a partners in the nationwide research and organizing against ALPRs all over the country.

\n\n\n\'',NULL,1294144),('3_Saturday','17','17:30','17:59','N','AI Village','LVCCW Level 1 Hall 3 801 (Creator Stage 1)','\'SADF: A Taxonomy and Evaluation Framework for Agentic Security Failures\'','\'Julie Brunias\'','Creator Talks_5dee5ed9066eb93fe2f189651a91bd68','\'Title: SADF: A Taxonomy and Evaluation Framework for Agentic Security Failures
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - Map
\n
\nDescription:
\nEmerging agentic systems operate across attack surfaces that existing security evaluations were not designed to measure: external tools, persistent memory, retrieval pipelines, delegated credentials, and multi-agent orchestration. Most agent security benchmarks measure success using substring matching — checking whether attack-related keywords appear anywhere in the model response. We show this systematically overstates success rates because capable models quote attack indicators verbatim in their refusals.
\nWe introduce SADF (Synthetic Agent Deception Framework), an eight-class taxonomy of agentic security failures — Tool Call Hijacking, Output Poisoning, Cross-Tool Injection, Memory Poisoning, RAG Poisoning, Delegated Authority Abuse, Multi-Agent Propagation, and Context Boundary Violation — and an automated testing harness with refusal-filtered scoring grounded in actual tool execution output strings.
\nSince the initial submission, we extended the evaluation from 3 direct model architectures to 7 total, adding four production framework wrappers (LangChain, AutoGen, CrewAI, SmolAgents), growing the dataset from 96 to 2,656 real evaluation runs. This extended evaluation reveals a finding absent from the original submission: the orchestration framework is an independent attack surface. Holding the model constant (Claude Sonnet) and varying only the framework wrapper produces a 2.6× spread in Agent Compromise Rate — from 11.9% (CrewAI) to 31.1% (SmolAgents) — with the direct Sonnet baseline at 15.6%. The choice of framework matters as much as the choice of model.
\nThe original direct-model findings are confirmed and extended. Naive substring matching reported 90–100% success across all models; after refusal-filtered scoring, true rates were 59% (Llama 3.2), 22% (Claude Haiku), and 16% (Claude Sonnet) — a 4–6× overstatement. Memory Poisoning remains the sharpest safety boundary: Llama 3.2 was compromised on 3/3 payloads; all four framework architectures and Claude Sonnet achieved 0% across 243 combined Memory Poisoning runs. Delegated Authority Abuse scored 0% on both Claude models even when every authorization check passed — suggesting safety training captures intent, not only surface features. Two payloads (File Path Traversal, Code Execution to File Write) succeeded across all seven architectures, indicating a universal floor that neither safety training nor per-tool authorization controls currently address.
\nAttendees will leave with the full eight-class taxonomy, refusal-filtered scoring methodology, cross-architecture results across 2,656 real evaluation runs, and the complete open-source harness at github.com/jbdu94/SADF.
\n\n\n\nSpeakerBio:  Julie Brunias
\n

Julie Brunias is a cybersecurity professional with over 14 years of experience in offensive security, red teaming, and enterprise security architecture across sectors including energy, banking, telecommunications, and manufacturing.\nShe specializes in AI security and adversarial system analysis, focusing on how generative AI systems, large language models, and agent-based architectures can be attacked, misused, and secured in real-world environments. Her work bridges offensive security and emerging AI system risks, including prompt injection, indirect prompt injection, RAG poisoning, model manipulation, and AI agent exploitation.

\n\n

Julie has led red and purple team engagements and security architecture initiatives in complex enterprise environments, applying offensive security techniques to emerging AI-native systems and autonomous technologies.

\n\n

Her research focuses on AI system failure modes, adversarial machine learning, Shadow AI risks, and practical methods for evaluating and securing agentic AI systems. She is the creator of several applied research efforts, including SADF (a taxonomy for agentic security failures), MCP security tooling, and ransomware intelligence analysis systems.

\n\n

Her work has been presented at international security conferences including AI Village (accepted talk and poster), InCyber Forum, GoSec, HackMiami, and Black Hat (accepted), focusing on the intersection of offensive security and AI system resilience.

\n\n

She is particularly focused on helping organizations understand and mitigate risks in production AI systems as they transition from experimental deployments to mission-critical infrastructure.

\n\n\n\'',NULL,1294145),('3_Saturday','17','17:30','17:59','N','Aerospace Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'SpaceCOP: Houston, We Have an Intrusion\'','\'Brandon Bailey\'','Creator Talks_6334f62268ab4bfe3e2495d85e998050','\'Title: SpaceCOP: Houston, We Have an Intrusion
\nTags: Aerospace Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Spacecraft are no longer isolated boxes with radios. They are networked, software-defined, mission-critical systems operating in an environment where patching is hard, visibility is limited, and failure can look a lot like an attack.\nThis talk introduces Space Cyber Orbital Protection, or SpaceCOP, a spacecraft intrusion detection system designed to bring threat-informed cyber monitoring onboard the vehicle. SpaceCOP comes in two forms: an open-source version for NASA’s Core Flight System, releasing at DEF CON 34, and a closed-source side-loaded architecture intended to integrate with a broader range of spacecraft software environments. The cFS version uses SPARTA\'s Indicators of Behavior to detect anomalous spacecraft activity.\nWe will walk through why traditional ground-based monitoring is not enough, how spacecraft IDS concepts differ from terrestrial IDS, and how SPARTA-derived behavior indicators can be translated into practical onboard detections. We will also discuss how growing policy pressure, including U.S. national security space guidance and emerging European space cybersecurity requirements, is pushing operators toward onboard intrusion detection and response.\nSpace cyber threats are not theoretical anymore. SpaceCOP is an attempt to move spacecraft defense from “trust the link” to “monitor the vehicle.”

\n\nSpeakerBio:  Brandon Bailey, Aerospace Corporation
\nNo BIO available
\n\n\'',NULL,1294146),('3_Saturday','17','17:30','17:59','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'There Is No Internet: Cross-Domain Recon of all 4.3 Billion IPv4s\'','\'John McCary\'','Creator Talks_f703d015a920341eac0e83a499c51919','\'Title: There Is No Internet: Cross-Domain Recon of all 4.3 Billion IPv4s
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

We scanned every IPv4 address on the planet. Twice. We collected public records in one of at least three places: the RIR registration, the operator\'s reverse DNS, or whatever service answers on port. Most threat intelligence pipelines read one of those. Darkmouse lines up all of them and flags the disagreements. The result is attack-surface visibility that no single source gives you, and a methodology you can run yourself.

\n\n

This talk walks the recon pipeline behind three findings from a single cross-domain pass over 4.3 billion IPv4 addresses in five days, plus a 92 million IP targeted scan in 34 hours (Russia, Iran, and North Korea). We used ZMap on single-use Jetstream2 VMs, zdns for PTR and forward verification, bulk RPSL and ARIN XML and APNIC data loaded into DuckDB alongside MaxMind GeoLite2, OpenSanctions, and the US Trade Consolidated Screening List. Enrichment is baked into the scan row at ingest. Every field carries a source-date stamp so longitudinal comparison actually works.

\n\n

Lead finding for a recon audience: 6,656 Iranian IPs in RIPE where the registrant placed fabricated US street addresses into the authoritative registry. 4,608 of them cite AT&T Mobility\'s ARIN IP-management address verbatim. 2,048 cite a Philadelphia apartment building. All geolocate to Iran. All trace to one operator through a shared RIPE maintainer object linking a Shiraz Local Internet Registry and an Omani shell.

\n\n

Between September 2025 and January 2026 the fabricated addresses began rotating out, replaced by netnames like \"Datacamp-Limited\" that impersonate real UK hosting companies. A single-point-in-time feed cannot see that rotation. Two dated snapshots can. We are currently running follow up scans and expect to have new data before the conference.

\n\n

Additional Findings: five active PTR records in Russia and the Netherlands claiming US government domains, including .fbi.gov subdomains, four of five still live six months after first observation (April 2026). And 1,534 APNIC-registered IPs for Entity Listed Chinese telecoms, declared country=US, geolocating to One Wilshire in Los Angeles, running production email and DNS on FCC-revoked Section 214 infrastructure.

\n\n

Every finding ships with the RDAP query, the DNS check, and the cross-reference that verifies it. Every finding ships with the RDAP query, the DNS check, and the cross-reference that verifies it. Attendees leave knowing which four sources to line up, which fields to trust, and what to look for when two dated snapshots disagree.

\n\nSpeakerBio:  John McCary, Former DARPA, State Department, now Professor and Builder
\n

John McCary founded Port 194 LLC, where he builds internet-scale measurement and correlation tooling from public data. Former soldier, diplomat, Wall Street Journal journalist, licensed private investigator, and certified ethical hacker. At 29 he helped design and launch a peer-to-peer data sharing platform that became a DARPA program of record and is still in use today. He designed and teaches the Open Source Intelligence course at the University of Arizona as adjunct faculty. Off the clock he is usually underwater, in a Muay Thai gym, or playing live music, though rarely at the same time.

\n\n\n\'',NULL,1294147),('3_Saturday','17','17:30','17:59','N','Recon Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Total Recon: How We Discovered 1000s of open Agents in The Wild\'','\'Avishai Efrat,Roey Ben Chaim\'','Creator Talks_64551e9b779a7053b276dc092e570029','\'Title: Total Recon: How We Discovered 1000s of open Agents in The Wild
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\nAI agents quietly created a new external attack surface: copilots, custom agents, AI cakends and various deployments that ship to the internet, often without anyone realizing they are reachable, enumerable, or over-permissive.
\n\n

In this talk, we’ll show how attackers can already find your agents in the wild, shedding light on the technical details that enable this kind of malicious activity, including how we used these details to find 1000s of exposed agents of different kinds. We’ll follow up with explaining how to measure exposure, see the proof for obscurity failing, and understand how to detect threat-actor agent-focused recon before it turns into an impactful attack. Capping it all off by showcasing PowerPwn, a recon tool you can use to test your own exposure

\n\nSpeakers:Avishai Efrat,Roey Ben Chaim
\n
\nSpeakerBio:  Avishai Efrat, Senior Security Researcher at Zenity
\n

Avishai Efrat is a senior security researcher at Zenity, specializing in securing AI agents and low-code/no-code platforms. His work focuses on uncovering vulnerabilities in enterprise AI deployments, from Copilot Studio to ChatGPT and beyond - and exploring how attackers discover and exploit these weaknesses. Passionate about all aspects of security, with experience spanning web security, anti-bot protection, OSINT, blockchain, and data engineering and aim on bridging the gap between cutting-edge research and practical defense strategies. Previously presented at BSidesTLV, Black Hat USA & Europe Arsenal and SecTor.

\n\nSpeakerBio:  Roey Ben Chaim, Staff Engineer at Zenity
\n

Roey Ben Chaim is an engineer focused on AI and agent security, with a particular interest in how agentic systems fail in practice. His work centers on stress-testing agents, building benchmarks for long-horizon behavior, and developing practical defenses against risks such as prompt injection, unsafe tool use, privacy leakage, and adversarial workflows. Prior to this, he spent a decade at Microsoft building large-scale security systems. He is a co-author of SkillsBench, a benchmark on agent skills efficacy over diverse tasks, and contributes to safety and privacy tooling, including Presidio. Roey is also a speaker on agentic systems and AI security, a co-organizer of AI Tinkerers Tel Aviv, and an active participant in hackathons and builder communities, where he explores emerging systems through hands-on experimentation.

\n\n\n\'',NULL,1294148),('4_Sunday','10','10:00','10:30','N','AI Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'A Billion-User Blast Radius: Owning ChatGPT’s Secure Sandbox\'','\'Simcha Kosman\'','Creator Talks_96c23c9341b897f00676f1b91a48f913','\'Title: A Billion-User Blast Radius: Owning ChatGPT’s Secure Sandbox
\nTags: AI Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

OpenAI designed ChatGPT’s container sandbox as a secure runtime environment, enforcing full network isolation, strict execution timeouts, and an AI supervisor to filter every command. Under this model, owning the container and extracting sensitive data seemed impossible. However, we demonstrate that by chaining file-parsing abuse for persistent execution, reasoning-channel hijacking for data extraction, and shared infrastructure manipulation, an attacker can establish a Cross-tenant data exfiltration.

\n\n

In this talk, we demonstrate a complete attack chain that shatters ChatGPT’s secure sandbox. By abusing spreadsheet file parsing, we bypass the LLM supervisor to gain persistent, unmonitored root execution. From there, we escalate the attack by live-patching the internal Jupyter kernel to hijack the model’s hidden python.exec reasoning channel, executing a Reasoning Injection Attack to extract sensitive user data. To exfiltrate this data, we bypass network isolation by weaponizing the Task Scheduler to launder malicious URLs past strict web guardrails.

\n\n

The attack reaches its climax by exploiting a shared JFrog package manager. We engineered a signaling protocol that weaponizes globally visible authentication rate limits, translating these lockout timers into a half-duplex covert channel. This provides reliable data exfiltration and Command and Control from isolated enterprise environments to external attackers. Our exploit chain combines file parsing abuse, Chain of Thought hijacking, privilege confusion, and rate limit Denial of Service to orchestrate a Command and Control (C2) network directly inside ChatGPT.

\n\n

Breaching AI sandbox agents becomes a critical vulnerability when trust boundaries are shared across millions of users. This research proves that as AI agents gain more capabilities, the attack surface expands dramatically, even when strict security constraints and mitigations are in place.

\n\nSpeakerBio:  Simcha Kosman
\n

Simcha Kosman is a Senior Security Researcher at Palo Alto Networks with over seven years of experience in vulnerability research. He discovered his first vulnerability at age 15, earning his first bug bounty, and has since uncovered security flaws in processors, embedded systems, and large-scale open-source projects. His current work focuses on AI security, exploring the intersection of LLM and software exploitation. Simcha has presented his research in the past at BSides, Nullcon, and Black Hat.

\n\n\n\'',NULL,1294149),('2_Friday','17','17:00','17:30','N','AI Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'Scaling Adversary Emulation with Autonomous Agents\'','\'Daniel Fabian\'','Creator Talks_d8c1651fbbfd79fb2a9d17c3d2df343c','\'Title: Scaling Adversary Emulation with Autonomous Agents
\nTags: AI Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

Manual red teaming cannot keep pace with modern enterprise attack surfaces, but autonomous agentic red teams offer a scalable alternative. In this talk we will present our experience and results on how to build and safely deploy offensive AI agents to conduct continuous, multi-stage adversary simulations at large scale to discover severe security issues and execute simulated post-exploitation chains.

\n\nSpeakerBio:  Daniel Fabian
\n

Daniel built Google\'s Red Team and ML Red Team from the ground up. He and his team of hackers conduct accurate simulations of real-world adversaries targeting the company, and use the lessons from these exercises to develop new defensive strategies. Prior to joining Google, Daniel worked as a pentester, helping companies identify and fix security vulnerabilities.

\n\n\n\'',NULL,1294150),('2_Friday','14','14:30','14:59','N','Crypto & Privacy Village','LVCCW Level 1 Hall 3 1102 (Creator Stage 6)','\'You\'re Probably Using FPE Wrong\'','\'Leslie Gutschow\'','Creator Talks_cfcf9b10ea55f57c46afe8e33dd3d631','\'Title: You\'re Probably Using FPE Wrong
\nTags: Crypto & Privacy Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - Map
\n
\nDescription:
\n

Format-preserving encryption is widely deployed and widely misunderstood. It appears in PCI environments, GDPR compliance architectures, banking systems, payment platforms, and legacy applications where changing the data format is not an option. Unfortunately, many production uses of FPE get the important details wrong.

\n\n

This talk is a practical field guide to FPE.

\n\n

We will walk through NIST FF1 and FF3-1 from the perspective of someone building or reviewing a real system. The focus is not on cryptographic theory for its own sake, but on the decisions that matter in production: choosing the radix, understanding domain-size limits, using tweaks correctly, and recognizing when the security margin is thinner than it looks. We will also talk about the key management problem that most FPE libraries leave unresolved.

\n\n

Finally, we will separate good use cases from bad ones. FPE can be the right tool for structured sensitive data, legacy systems, and format-constrained workflows. It can also be the wrong tool, especially when small domains, poor key separation, missing tweaks, or assumptions borrowed from tokenization creep into the design.

\n\nSpeakerBio:  Leslie Gutschow
\n

Principal engineer and founder of Horizon Digital Engineering. Named inventor on two US patents covering format-preserving encryption and string protection techniques (OpenText/Micro Focus). Former Principal Architect and Professional Services at Micro Focus/Voltage Security (7 years) — led enterprise FPE deployments and integrations across financial services, healthcare, and retail. Previously: Naval Research Lab, Boeing. Currently researching memory-safe OS infrastructure.

\n\n\n\'',NULL,1294151),('4_Sunday','12','12:00','12:30','N','AI Village','LVCCW Level 1 Hall 3 1105 (Creator Stage 3)','\'Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover\'','\'Stav Cohen\'','Creator Talks_da142336714e669d42d5923c9395348d','\'Title: Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover
\nTags: AI Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - Map
\n
\nDescription:
\nEvery major AI lab now ships an agentic browser: ChatGPT Atlas, Perplexity Comet, Claude in Chrome, Gemini in Chrome, and Microsoft Copilot Actions. To make them work, vendors intentionally relax thirty years of browser security. Atlas loosens Same-Origin Policy, Gemini and Edge add localhost access, Comet opens the filesystem, and Claude runs scripts on any site. The main defense is model safety training. These are design choices, not bugs, reviving XSS, sandbox escapes, and drive-by exploitation.
\n\n

We ran the first cross-platform analysis of all five. We introduce PleaseFix, a new agent-targeting vulnerability class (the evolution of ClickFix), exploited via Intent Collision, which merges attacker content with the user\'s request into one plan the agent cannot untangle. We also present HistoryFixing, which weaponizes a function shipped in every browser since 2008 to poison the browsing history agents trust as ground truth.

\n\n

Walk up to learn the agentic-browser threat model, the vulnerabilities, and which were agent-specific versus consistent across all five. You will see how we chained Intent Collision and HistoryFixing, from zero-click vectors (poisoned tweet, calendar invite), to conduct RCE, reverse shells, data exfiltration and poisoning, filesystem theft, account takeovers (Slack, X, 1Password, Claude), rogue actions on MFA-gated sites, unauthorized Amazon purchases, malicious collaborators added to your private enterprise GitHub, and more. We link videos of every attack. We break down the soft versus hard boundaries each vendor built, what failed and what held: only deterministic, code-level defenses stopped us. All findings responsibly disclosed.

\n\nSpeakerBio:  Stav Cohen
\n

Stav Cohen is an AI Security Research Lead at Zenity and a PhD student at the Technion, Israel Institute of Technology. His research focuses on breaking, and then fixing, AI agents, spanning security vulnerabilities across agentic AI systems, LLM-powered applications, and enterprise AI platforms. He discovers new attack vectors, develops remediation strategies, and works to drive the industry toward stronger security practices. His offensive security work spans attacks on RAG pipelines, multi-agent delegation protocols, agentic browsers, and production-scale GenAI systems. He introduced the concept of Promptware: a new class of inference-time threats that exploit GenAI models through malicious prompts, turning them from helpful assistants into tools for data exfiltration, lateral movement, and even physical-world consequences. He presents his findings at leading security venues across the world. His PhD research focuses on the secure integration of Generative AI into real-world infrastructure, particularly Cyber-Physical-Human Systems involving human-in-the-loop interactions, such as smart water networks and GenAI-powered virtual assistants. He explores how GenAI agents can be safely and effectively integrated into these environments to support real-time decision-making, anomaly detection, and human-machine collaboration. He is also a thought leader in the AI security space, sharing knowledge through conference talks, blog posts, and community engagement.

\n\n\n\'',NULL,1294152),('3_Saturday','13','13:30','13:59','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Your OpSec Is Showing\'','\'Fae Blu3Bird\" Carlisle\'','Creator Talks_2d693b61a857e3aeb005ffbd92664f2f','\'Title: Your OpSec Is Showing
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\nMost threat intelligence focuses on what attackers have already done: payloads, malware families, and post-compromise behavior. But adversaries are far more fluid at the payload layer than they are at the infrastructure layer. Domains rotate, IPs churn, and malware gets recompiled but infrastructure leaves patterns.
\n\n

This article explores how to track threat actors through their infrastructure by leveraging fingerprinting techniques that expose those patterns at scale.

\n\n

We’ll walk through practical methods including JARM for active TLS stack fingerprinting, JA3/JA4 for identifying consistent communication behaviors, SSH host key correlation for infrastructure pivoting, and MurmurHash for clustering phishing kits and web panels through shared assets. Individually, these signals are useful. Combined, they allow defenders to map infrastructure clusters tied to a single actor or campaign—even when traditional indicators change.

\n\n

The focus is not on attribution for its own sake, but on building a repeatable approach to discovering “sister infrastructure” and identifying campaigns earlier in their lifecycle. By shifting attention away from payloads and toward the systems attackers stand up to operate, defenders can detect patterns before deployment and reduce time to awareness.

\n\n

Attackers rely on reuse of configurations, tooling, and infrastructure. That reuse creates fingerprints. And those fingerprints are often more durable than the indicators most teams prioritize.

\n\n

If you want to track threat actors effectively, stop chasing malware.

\n\n

Track the infrastructure they can’t help but reuse.

\n\nSpeakerBio:  Fae Blu3Bird\" Carlisle
\n

Fae Carlisle (Blu3Bird) is a threat intelligence and DFIR practitioner working at the intersection of intelligence, detection, and threat hunting. She is an active member of hackers.town hacking community. Her work focuses on operationalizing intelligence, building systems and workflows that turn fragmented signals into actionable insights for real-world defense. She has experience developing intelligence pipelines and supporting detection efforts in production environments, with a focus on bridging the gap between analysis and response.

\n\n\n\'',NULL,1294153),('4_Sunday','10','10:45','11:30','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Living Off Someone Else\'s Inference\'','\'Redon Gashi,Armend Gashi\'','Creator Talks_0c2e54bb64410aadaaff212bf502e56e','\'Title: Living Off Someone Else\'s Inference
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:45 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

LLM-powered tooling is becoming a force multiplier for attackers, from reconnaissance automation to post-exploitation enumeration. Using their own API keys creates attribution and cost, so they look for alternatives.

\n\n

Thousands of inference endpoints sit exposed on the internet: misconfigured Ollama instances, open vLLM deployments, leaked API keys in directory listings, and expired OAuth tokens from AI coding assistants that can be silently refreshed. Attackers can discover these resources and use them as free compute for their operations, without spending a dollar or registering an account.

\n\n

Attendees will learn how to:

\n\n

•⁠ ⁠Discover exposed inference endpoints and leaked API keys using Infreerence\n•⁠ ⁠Validate that discovered resources provide usable inference access\n•⁠ ⁠Operate Echidna, powered entirely by discovered inference\n•⁠ ⁠Chain LLM skill agents together to execute a guided campaign against a target network

\n\n

Current LLMs are effective force multipliers when directed, and significantly more so when the compute bill goes to someone else. This is resource hijacking applied to the AI era: living off someone else\'s inference. Understanding this threat is essential for any organization deploying or exposing AI infrastructure.

\n\n

Two tools will be released as open source during the session:

\n\n

•⁠ ⁠Infreerence: A multi-phase scanner and dashboard that discovers exposed inference endpoints and leaked API keys through Shodan and Censys, validates them against live provider APIs, and catalogs usable inference resources across 10+ providers.\n•⁠ ⁠Echidna: A Mythic C2 agent type that consumes discovered inference endpoints and turns them into operator-directed skill agents for reconnaissance, exploitation planning, post-exploitation, and lateral movement.

\n\nSpeakers:Redon Gashi,Armend Gashi
\n
\nSpeakerBio:  Redon Gashi, Managing Security Consultant at Sentry Cybersecurity
\n

Redon Gashi is a Managing Security Consultant and offensive team lead at Sentry, where he has spent close to a decade leading and executing penetration tests and red team operations for Fortune 500 clients across banking, telecom, insurance, and fintech. He holds the OSEP, CRTL, and CRTO certifications, and has personally performed over 200 engagements spanning web applications, internal infrastructure, and mobile platforms, while leading many more across his team. A former lecturer at Cyber Academy, speaker at multiple BSides conferences, and multiple-time CTF champion, Redon combines deep hands-on technical expertise with a proven ability to build and scale offensive security teams.

\n\nSpeakerBio:  Armend Gashi, Managing Security Consultant at Sentry Cybersecurity
\n

Armend Gashi is Managing Security Consultant at Sentry. With over 5 years in the industry, he specializes in application security and AWS cloud assessments. Armend has conducted AI red teaming engagements, developed multi-agent systems to perform security-focused tasks such as code auditing and exploit development, and was part of Anthropic’s external AI red team capability through HackerOne.

\n\n

Armend has led security research initiatives resulting in the discovery of multiple vulnerabilities, including:

\n\n

CVE-2023-26482 - Critical-risk vulnerability enabling remote code execution\nCVE-2023-48239 - High-risk vulnerability allowing arbitrary user storage updates\nCVE-2023-35928 - High-risk vulnerability enabling user account hijacking\nCVE-2023-45660 - Medium-risk application-level denial of service vulnerability\nCVE-2023-48301 - Medium-risk arbitrary browser code injection vulnerability\nCVE-2023-48307 - Low-risk server-side request forgery vulnerability

\n\n\n\'',NULL,1294154),('4_Sunday','11','10:45','11:30','Y','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'Living Off Someone Else\'s Inference\'','\'Redon Gashi,Armend Gashi\'','Creator Talks_0c2e54bb64410aadaaff212bf502e56e','\'\'',NULL,1294155),('4_Sunday','12','12:30','12:59','N','OWASP Foundation','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Source of Truth: A Field Guide for Deep Technical Research\'','\'Carley “51nk0r5w1m” Fant\'','Creator Talks_e1d4958602fcb3d03d7b1836b7d2e78e','\'Title: Source of Truth: A Field Guide for Deep Technical Research
\nTags: OWASP Foundation | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Security research usually starts with one reasonable question and somehow turns into a sea of browser tabs, lost bookmarks, half-read standards, conference talks, vendor docs, AI summaries, and simplified architecture posts with suspiciously perfect rectangles. Finding information is easy. The hard part is learning enough to know which explanation applies, which design decision changes the threat model, and where the simplified diagram quietly skipped the important part.

\n\n

This talk is a practical field guide for researching deeply technical security topics without getting lost in the noise. We will look at how to approach protocols, standards, system behavior, and implementation details, then trace claims back to primary sources, identify load-bearing assumptions, and turn dense research into something useful for engineers and defenders.

\n\nSpeakerBio:  Carley “51nk0r5w1m” Fant, OWASP Project contributor, Rabbit Hole explorer
\n

Carley “51nk0r5w1m” Fant is a Platform Engineer focused on AppSec, cloud infrastructure, identity, and software delivery. Her work centers on building secure platform baselines, hardening cloud-native environments, and helping engineering teams ship systems that are usable, observable, defensible, and less cursed by default.

\n\n

She works at the intersection of platform engineering and application security, with a focus on practical threat modeling, automation, and figuring out where systems actually break once they leave the whiteboard. She is active in the OWASP community and enjoys turning technical rabbit holes into useful takeaways for engineers, defenders, and anyone who has ever opened an RFC, sighed, and kept reading anyway.

\n\n\n\'',NULL,1294156),('3_Saturday','12','12:00','12:45','N','AI Village','LVCCW Level 1 Hall 3 1103 (Creator Stage 5)','\'This Wasn\'t AI Generated: Principles for Breaking Generative Watermarks\'','\'Thomas Mason,Tahseen Rabbani\'','Creator Talks_044b4bca58e81d0c6e32cd9ab9164e21','\'Title: This Wasn\'t AI Generated: Principles for Breaking Generative Watermarks
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - Map
\n
\nDescription:
\n

The SynthID watermark was developed by Google to invisibly tag content generated by its models and agents (Nano Banana, Gemini, etc.). When asked to identify whether an image is AI-generated, Gemini will invoke a \"Verify AI\" tool to scan for the SynthID. We demonstrate two attack strategies to remove it. (1) The lesser-known regeneration attack of Zhao et al. 2023 removes SynthID identification by Gemini with 100% success rate on a held-out set of 104 photorealistic Nano-Banana images. (2) We build a surrogate detector using Apple\'s Pico-Banana-400K dataset. This dataset pairs Flickr images with a Nano-Banana edit, which automatically adds SynthID, thereby implicitly providing us with a large corpus of watermarked/clean image pairs which we use to fine-tune a pre-trained ResNet-18 into a SynthID discriminator. This surrogate detector can be used to test the presence of the watermark in an image in ~27.5 ms on a CPU, thereby allowing an adversary to rapidly test and optimize an attack. We demonstrate that the removal of the SynthID can induce hallucinations, whereby Gemini confidently makes assertions regarding its own simulated as if it were real. This, we propose, could have a variety of security implications, such as confused deputy attacks against agents, retrieval pipeline poisoning, and facial recognition bypasses. The full code, the test set, the pre-computed attack outputs, and the prompts used to generate every test image are released as a hands-on kit at https://github.com/rabbanitw/WAVES/tree/synthid-regen-kit

\n\nSpeakers:Thomas Mason,Tahseen Rabbani
\n
\nSpeakerBio:  Thomas Mason
\n

Thomas Mason has spent the past decade working as a security engineer and offensive pentester. With an original background in machine learning and applied math, he spent several years as a data scientist and OSINT researcher before becoming a pentester in industry. His seven-plus years of pentesting experience gave him a background in a diverse array of offensive security roles, including physical security and social engineering, web, application and network testing, hardware and IoT security, and red teaming.\nCurrently, he works for Coalfire, specializing in cloud and web security with an emphasis on AI products. Outside of his day-to-day work, his research centers on mapping and testing the emerging attack surfaces of large language models, and how their adoption changes the threat landscape. In addition, he works on independent projects combining his background in mathematics and social sciences with his security experience. His hobbies include reading, sports, and graphic novel writing.

\n\nSpeakerBio:  Tahseen Rabbani
\n

Tahseen is a machine learning Postdoctoral Scholar at the University of Chicago, co-hosted by Ce Zhang and Tian Li, and a Forward Deployed Engineer at Appen. His research focuses on watermarking system efficiency, distributed learning, and privacy. His secondary research interests include numerical optimization and machine translation. His work has appeared at venues such as NeurIPS, ICML, ICLR, and ACL. He received his Ph.D. in Computer Science in 2024 from the University of Maryland, advised by Furong Huang. Prior to the University of Chicago, he worked as a Postdoctoral Associate at Yale, where he worked on low-resource clinical models and fast drug discovery. He obtained his BA in mathematics from the University of Virginia, where he specialized in combinatorial group theory and error-correction, which he continues to work on for fun.

\n\n

His core research contributions include (1) WAVES, a popular benchmark for stress-testing deep learning-based watermarks under a large suite of attacks; (2) SWIFT, a strategy for asynchronous transmission of model weights over decentralized communication graphs, enabling data-secure collaborative machine learning; (3) Sketch-GNN, a sketch-based compression framework for training graph neural networks with sublinear computational complexity; and (4) PGHash, a novel family of pseudo-random hash functions for private pruning of large classification layer neurons, allowing extreme compression of large recommender systems.

\n\n

His work on the WAVES benchmark was spun into the 2024 NeurIPS competition, “Erasing the Invisible,” which drew 2700+ submissions from nearly 250+ global teams, assessing their ability to remove watermarks in black-box and grey-box systems. This competition resulted in many novel attack vectors for effectively destroying nearly every state-of-the-art open-source watermark. He is also a regular reviewer for IEEE Transactions in Multimedia, where he lends his expertise on new watermark designs.

\n\n\n\'',NULL,1294157),('2_Friday','10','10:00','11:59','N','Contests','LVCCW Level 2 W213-217 (Blue Team Village)','\'Blue Team Village CTF - Project Obsidian\'','\'\'','Contests_c407fc76dd41f774640bc911e3a39731','\'Title: Blue Team Village CTF - Project Obsidian
\nTags: Blue Team Village | Blue Team Village CTF | Contest
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W213-217 (Blue Team Village) - Map
\n
\nDescription:
\n

Join Blue Team Village for a defender-focused Capture the Flag competition centered on forensic analysis, malware activity in containerized environments, and cloud-infrastructure attacks. Participants will investigate container images, reconstruct incidents, and solve challenges ranging from beginner to expert. Challenge tracks include Container & Malware Forensics, Cloud Attack Forensics, and Converged Frontier. Participants can choose safe forensic snapshots or advanced live-malware challenges conducted in an egress-restricted Kubernetes sandbox.

\n\nLinks:
    Website - https://ctf.blueteamvillage.org/
\n\'',NULL,1294158),('2_Friday','11','10:00','11:59','Y','Contests','LVCCW Level 2 W213-217 (Blue Team Village)','\'Blue Team Village CTF - Project Obsidian\'','\'\'','Contests_c407fc76dd41f774640bc911e3a39731','\'\'',NULL,1294159),('3_Saturday','10','10:00','11:59','N','Contests','LVCCW Level 2 W213-217 (Blue Team Village)','\'Blue Team Village CTF - Project Obsidian\'','\'\'','Contests_31965ba62b94fe8398e21bd593865e6d','\'Title: Blue Team Village CTF - Project Obsidian
\nTags: Blue Team Village | Blue Team Village CTF | Contest
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W213-217 (Blue Team Village) - Map
\n
\nDescription:
\n

Join Blue Team Village for a defender-focused Capture the Flag competition centered on forensic analysis, malware activity in containerized environments, and cloud-infrastructure attacks. Participants will investigate container images, reconstruct incidents, and solve challenges ranging from beginner to expert. Challenge tracks include Container & Malware Forensics, Cloud Attack Forensics, and Converged Frontier. Participants can choose safe forensic snapshots or advanced live-malware challenges conducted in an egress-restricted Kubernetes sandbox.

\n\nLinks:
    Website - https://ctf.blueteamvillage.org/
\n\'',NULL,1294160),('3_Saturday','11','10:00','11:59','Y','Contests','LVCCW Level 2 W213-217 (Blue Team Village)','\'Blue Team Village CTF - Project Obsidian\'','\'\'','Contests_31965ba62b94fe8398e21bd593865e6d','\'\'',NULL,1294161),('2_Friday','10','10:00','17:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_86bc445cd4c6d9bed97da5857fbc25ff','\'Title: Cyber Mirage: Realtime Deepfake Demos
\nTags: AI Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Go deepfake yourself! This hands-on demo shows how threat actors leverage open-source deepfake video and voice cloning frameworks to impersonate anyone in realtime, conducting social engineering and compromising organizations using nothing more than a consumer-grade gaming laptop. No specialized hardware, no budget, no nation-state resources required. Come learn the tradecraft firsthand and find out just how convincing you can become.

\n\nSpeakerBio:  Brandon Kovacs
\n

Brandon Kovacs (CRT, OSCP) is a Senior Security Consultant at offensive cybersecurity firm Bishop Fox, where he specializes in red teaming, network penetration testing, and physical penetration testing. As a red team operator, he is adept at identifying critical attack chains that an external attacker could use to fully compromise organizations and reach high-value targets. Brandon is also recognized as a deepfake expert, conducting speaking sessions and live demonstrations at several global security and technology conferences. His research focuses on the intersection of offensive cybersecurity and artificial intelligence.

\n\n\n\'',NULL,1294162),('2_Friday','11','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_86bc445cd4c6d9bed97da5857fbc25ff','\'\'',NULL,1294163),('2_Friday','12','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_86bc445cd4c6d9bed97da5857fbc25ff','\'\'',NULL,1294164),('2_Friday','13','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_86bc445cd4c6d9bed97da5857fbc25ff','\'\'',NULL,1294165),('2_Friday','14','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_86bc445cd4c6d9bed97da5857fbc25ff','\'\'',NULL,1294166),('2_Friday','15','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_86bc445cd4c6d9bed97da5857fbc25ff','\'\'',NULL,1294167),('2_Friday','16','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_86bc445cd4c6d9bed97da5857fbc25ff','\'\'',NULL,1294168),('2_Friday','17','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_86bc445cd4c6d9bed97da5857fbc25ff','\'\'',NULL,1294169),('4_Sunday','10','10:00','13:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_deaa40a2d272ae4b61ab6e00df3adfa5','\'Title: Cyber Mirage: Realtime Deepfake Demos
\nTags: AI Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Go deepfake yourself! This hands-on demo shows how threat actors leverage open-source deepfake video and voice cloning frameworks to impersonate anyone in realtime, conducting social engineering and compromising organizations using nothing more than a consumer-grade gaming laptop. No specialized hardware, no budget, no nation-state resources required. Come learn the tradecraft firsthand and find out just how convincing you can become.

\n\nSpeakerBio:  Brandon Kovacs
\n

Brandon Kovacs (CRT, OSCP) is a Senior Security Consultant at offensive cybersecurity firm Bishop Fox, where he specializes in red teaming, network penetration testing, and physical penetration testing. As a red team operator, he is adept at identifying critical attack chains that an external attacker could use to fully compromise organizations and reach high-value targets. Brandon is also recognized as a deepfake expert, conducting speaking sessions and live demonstrations at several global security and technology conferences. His research focuses on the intersection of offensive cybersecurity and artificial intelligence.

\n\n\n\'',NULL,1294170),('4_Sunday','11','10:00','13:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_deaa40a2d272ae4b61ab6e00df3adfa5','\'\'',NULL,1294171),('4_Sunday','12','10:00','13:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_deaa40a2d272ae4b61ab6e00df3adfa5','\'\'',NULL,1294172),('4_Sunday','13','10:00','13:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_deaa40a2d272ae4b61ab6e00df3adfa5','\'\'',NULL,1294173),('3_Saturday','10','10:00','17:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_3ff2c3af492f8d936ef9f163fda0fba2','\'Title: Cyber Mirage: Realtime Deepfake Demos
\nTags: AI Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Go deepfake yourself! This hands-on demo shows how threat actors leverage open-source deepfake video and voice cloning frameworks to impersonate anyone in realtime, conducting social engineering and compromising organizations using nothing more than a consumer-grade gaming laptop. No specialized hardware, no budget, no nation-state resources required. Come learn the tradecraft firsthand and find out just how convincing you can become.

\n\nSpeakerBio:  Brandon Kovacs
\n

Brandon Kovacs (CRT, OSCP) is a Senior Security Consultant at offensive cybersecurity firm Bishop Fox, where he specializes in red teaming, network penetration testing, and physical penetration testing. As a red team operator, he is adept at identifying critical attack chains that an external attacker could use to fully compromise organizations and reach high-value targets. Brandon is also recognized as a deepfake expert, conducting speaking sessions and live demonstrations at several global security and technology conferences. His research focuses on the intersection of offensive cybersecurity and artificial intelligence.

\n\n\n\'',NULL,1294174),('3_Saturday','11','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_3ff2c3af492f8d936ef9f163fda0fba2','\'\'',NULL,1294175),('3_Saturday','12','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_3ff2c3af492f8d936ef9f163fda0fba2','\'\'',NULL,1294176),('3_Saturday','13','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_3ff2c3af492f8d936ef9f163fda0fba2','\'\'',NULL,1294177),('3_Saturday','14','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_3ff2c3af492f8d936ef9f163fda0fba2','\'\'',NULL,1294178),('3_Saturday','15','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_3ff2c3af492f8d936ef9f163fda0fba2','\'\'',NULL,1294179),('3_Saturday','16','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_3ff2c3af492f8d936ef9f163fda0fba2','\'\'',NULL,1294180),('3_Saturday','17','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Cyber Mirage: Realtime Deepfake Demos\'','\'Brandon Kovacs\'','Creator Events_3ff2c3af492f8d936ef9f163fda0fba2','\'\'',NULL,1294181),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_b3db8532e344c58258cebbd53dcb2d7a','\'Title: AI Village - Hal CTF
\nTags: AI Village | HALctf (AI Village CTF) | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Get ready for the next evolution of competitive hacking at DEFCON 34! The AI Village is thrilled to introduce HalCTF (Hostile Autonomous Layer CTF), a first-of-its-kind agentic security competition. Instead of focusing on frontier models, this CTF is designed around how far you can stretch small local models that almost everyone can run. The first place prize is a DGX Spark so that you can continue your local hacking agent journey at home.

\n\n

In this high-stakes arena, participants do not interact with targets directly. Instead, you will design and deploy autonomous AI agents programmed to navigate sandboxed environments, exploit challenge targets, and capture flags entirely on their own. Instead of just a prompt, we’re asking for full containers that you can load up with all the tools you need to succeed.

\n\n

To make it easy we’re hosting everything, from the targets to your agents to the models. We have a mix of old and new, and you get more points if you use smaller models. Runs are quick and show you all of the logs and points so you can improve the agent over the course of the con.

\n\nLinks:
    More Info - https://aivillage.org/blog/halctf/
\n\'',NULL,1294182),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_b3db8532e344c58258cebbd53dcb2d7a','\'\'',NULL,1294183),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_b3db8532e344c58258cebbd53dcb2d7a','\'\'',NULL,1294184),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_b3db8532e344c58258cebbd53dcb2d7a','\'\'',NULL,1294185),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_b3db8532e344c58258cebbd53dcb2d7a','\'\'',NULL,1294186),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_b3db8532e344c58258cebbd53dcb2d7a','\'\'',NULL,1294187),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_b3db8532e344c58258cebbd53dcb2d7a','\'\'',NULL,1294188),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_b3db8532e344c58258cebbd53dcb2d7a','\'\'',NULL,1294189),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_8cef0e278edc06c827c60e1ede6f8f9a','\'Title: AI Village - Hal CTF
\nTags: AI Village | HALctf (AI Village CTF) | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Get ready for the next evolution of competitive hacking at DEFCON 34! The AI Village is thrilled to introduce HalCTF (Hostile Autonomous Layer CTF), a first-of-its-kind agentic security competition. Instead of focusing on frontier models, this CTF is designed around how far you can stretch small local models that almost everyone can run. The first place prize is a DGX Spark so that you can continue your local hacking agent journey at home.

\n\n

In this high-stakes arena, participants do not interact with targets directly. Instead, you will design and deploy autonomous AI agents programmed to navigate sandboxed environments, exploit challenge targets, and capture flags entirely on their own. Instead of just a prompt, we’re asking for full containers that you can load up with all the tools you need to succeed.

\n\n

To make it easy we’re hosting everything, from the targets to your agents to the models. We have a mix of old and new, and you get more points if you use smaller models. Runs are quick and show you all of the logs and points so you can improve the agent over the course of the con.

\n\nLinks:
    More Info - https://aivillage.org/blog/halctf/
\n\'',NULL,1294190),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_8cef0e278edc06c827c60e1ede6f8f9a','\'\'',NULL,1294191),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_8cef0e278edc06c827c60e1ede6f8f9a','\'\'',NULL,1294192),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_8cef0e278edc06c827c60e1ede6f8f9a','\'\'',NULL,1294193),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_8cef0e278edc06c827c60e1ede6f8f9a','\'\'',NULL,1294194),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_8cef0e278edc06c827c60e1ede6f8f9a','\'\'',NULL,1294195),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_8cef0e278edc06c827c60e1ede6f8f9a','\'\'',NULL,1294196),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_8cef0e278edc06c827c60e1ede6f8f9a','\'\'',NULL,1294197),('4_Sunday','10','10:00','13:59','N','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_ba2eda8991fd9b995325ed53b071282d','\'Title: AI Village - Hal CTF
\nTags: AI Village | HALctf (AI Village CTF) | Contest
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Get ready for the next evolution of competitive hacking at DEFCON 34! The AI Village is thrilled to introduce HalCTF (Hostile Autonomous Layer CTF), a first-of-its-kind agentic security competition. Instead of focusing on frontier models, this CTF is designed around how far you can stretch small local models that almost everyone can run. The first place prize is a DGX Spark so that you can continue your local hacking agent journey at home.

\n\n

In this high-stakes arena, participants do not interact with targets directly. Instead, you will design and deploy autonomous AI agents programmed to navigate sandboxed environments, exploit challenge targets, and capture flags entirely on their own. Instead of just a prompt, we’re asking for full containers that you can load up with all the tools you need to succeed.

\n\n

To make it easy we’re hosting everything, from the targets to your agents to the models. We have a mix of old and new, and you get more points if you use smaller models. Runs are quick and show you all of the logs and points so you can improve the agent over the course of the con.

\n\nLinks:
    More Info - https://aivillage.org/blog/halctf/
\n\'',NULL,1294198),('4_Sunday','11','10:00','13:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_ba2eda8991fd9b995325ed53b071282d','\'\'',NULL,1294199),('4_Sunday','12','10:00','13:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_ba2eda8991fd9b995325ed53b071282d','\'\'',NULL,1294200),('4_Sunday','13','10:00','13:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village - Hal CTF\'','\'\'','Contests_ba2eda8991fd9b995325ed53b071282d','\'\'',NULL,1294201),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_91854ba6bab6d8e24b530b2d92e5d12e','\'Title: AI Village Plays Pokemon: DEFCON Edition
\nTags: AI Village | AI Village Plays Pokemon: DEF CON Edition | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Agent harnesses and tooling have quickly become the AI buzzwords of 2026, but what do these even mean, and why should you consider building them? We’re showing off how custom tooling can empower local models in the most accessible way possible: playing Pokémon. Join us in this fun, novice-friendly demo where we show how to build tooling for local models, and walk through what you should and shouldn’t consider turning into tools. All the models and tools are open source, so feel free to use them to make your own agents to play our emulations of Pokémon Fire Red and Leaf Green.

\n\nSpeakerBio:  Nick Ashworth, Maker at AI Village
\n

Nick is a Hacker and Engineer with almost 15 years of experience hacking everything from power grids to satellites for the DoD. He’s presented and made demos for Aerospace, Car Hacking, ICS, and the AI Village for the past seven years. He currently helps lead the AI Village.

\n\n\nLinks:
    Github - https://github.com/zeetwii/aiPlaysPokemon
\n\'',NULL,1294202),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_91854ba6bab6d8e24b530b2d92e5d12e','\'\'',NULL,1294203),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_91854ba6bab6d8e24b530b2d92e5d12e','\'\'',NULL,1294204),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_91854ba6bab6d8e24b530b2d92e5d12e','\'\'',NULL,1294205),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_91854ba6bab6d8e24b530b2d92e5d12e','\'\'',NULL,1294206),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_91854ba6bab6d8e24b530b2d92e5d12e','\'\'',NULL,1294207),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_91854ba6bab6d8e24b530b2d92e5d12e','\'\'',NULL,1294208),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_91854ba6bab6d8e24b530b2d92e5d12e','\'\'',NULL,1294209),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_813fa8dcd34eca6de211e843415dc0f4','\'Title: AI Village Plays Pokemon: DEFCON Edition
\nTags: AI Village | AI Village Plays Pokemon: DEF CON Edition | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Agent harnesses and tooling have quickly become the AI buzzwords of 2026, but what do these even mean, and why should you consider building them? We’re showing off how custom tooling can empower local models in the most accessible way possible: playing Pokémon. Join us in this fun, novice-friendly demo where we show how to build tooling for local models, and walk through what you should and shouldn’t consider turning into tools. All the models and tools are open source, so feel free to use them to make your own agents to play our emulations of Pokémon Fire Red and Leaf Green.

\n\nSpeakerBio:  Nick Ashworth, Maker at AI Village
\n

Nick is a Hacker and Engineer with almost 15 years of experience hacking everything from power grids to satellites for the DoD. He’s presented and made demos for Aerospace, Car Hacking, ICS, and the AI Village for the past seven years. He currently helps lead the AI Village.

\n\n\nLinks:
    Github - https://github.com/zeetwii/aiPlaysPokemon
\n\'',NULL,1294210),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_813fa8dcd34eca6de211e843415dc0f4','\'\'',NULL,1294211),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_813fa8dcd34eca6de211e843415dc0f4','\'\'',NULL,1294212),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_813fa8dcd34eca6de211e843415dc0f4','\'\'',NULL,1294213),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_813fa8dcd34eca6de211e843415dc0f4','\'\'',NULL,1294214),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_813fa8dcd34eca6de211e843415dc0f4','\'\'',NULL,1294215),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_813fa8dcd34eca6de211e843415dc0f4','\'\'',NULL,1294216),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_813fa8dcd34eca6de211e843415dc0f4','\'\'',NULL,1294217),('4_Sunday','10','10:00','13:59','N','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_f1ce4f8457a4f0560c830f4d146033a5','\'Title: AI Village Plays Pokemon: DEFCON Edition
\nTags: AI Village | AI Village Plays Pokemon: DEF CON Edition | Contest
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Agent harnesses and tooling have quickly become the AI buzzwords of 2026, but what do these even mean, and why should you consider building them? We’re showing off how custom tooling can empower local models in the most accessible way possible: playing Pokémon. Join us in this fun, novice-friendly demo where we show how to build tooling for local models, and walk through what you should and shouldn’t consider turning into tools. All the models and tools are open source, so feel free to use them to make your own agents to play our emulations of Pokémon Fire Red and Leaf Green.

\n\nSpeakerBio:  Nick Ashworth, Maker at AI Village
\n

Nick is a Hacker and Engineer with almost 15 years of experience hacking everything from power grids to satellites for the DoD. He’s presented and made demos for Aerospace, Car Hacking, ICS, and the AI Village for the past seven years. He currently helps lead the AI Village.

\n\n\nLinks:
    Github - https://github.com/zeetwii/aiPlaysPokemon
\n\'',NULL,1294218),('4_Sunday','11','10:00','13:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_f1ce4f8457a4f0560c830f4d146033a5','\'\'',NULL,1294219),('4_Sunday','12','10:00','13:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_f1ce4f8457a4f0560c830f4d146033a5','\'\'',NULL,1294220),('4_Sunday','13','10:00','13:59','Y','Contests','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village Plays Pokemon: DEFCON Edition\'','\'Nick Ashworth\'','Contests_f1ce4f8457a4f0560c830f4d146033a5','\'\'',NULL,1294221),('2_Friday','14','14:00','14:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Fooling Coding Agents for Fun and Profit\'','\'Matt Galligan,Jack Cable\'','Creator Talks_b9453721ac68cc5840d89bc56170923e','\'Title: Fooling Coding Agents for Fun and Profit
\nTags: AI Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\nThis is a sit down discussion in a more casual conversational format: Companies are increasingly deploying coding agents to triage bug reports, resolve support tickets, and open pull requests. These agents have direct access to codebases, CI/CD pipelines, internal tooling, and, often, the internet. These are exactly the conditions that make indirect prompt injection devastating.
\n\n

This talk presents end-to-end vulnerability chains we have discovered and disclosed in real coding agents. We’ll demo how adversary-controlled content (e.g., a bug report from a user) can hijack an agent’s goal and lead to outcomes like source code exfiltration and malicious pull requests.

\n\n

As coding agents become increasingly autonomous and interact with the outside world more frequently, these attacks will only grow more potent. We close with recommendations for how companies and codegen providers can defend against them.

\n\nSpeakers:Matt Galligan,Jack Cable
\n
\nSpeakerBio:  Matt Galligan
\nMatt has spent his career on both sides of the fence: building deceptive cyber systems and the security automation behind one of the DOD\'s largest software factories, then joining CISA\'s Rapid Action Force — where the job was, more or less, \"hack the entire federal government, daily,\" between vuln research and no-notice red team engagements. After a stint in big tech, he\'s now at Corridor focusing his efforts on building a rare thing in the industry: a security product that security teams actually love.
\n\n\n\nSpeakerBio:  Jack Cable, CEO and Co-Founder at Corridor
\n

Jack Cable is the CEO and Co-Founder of Corridor, the security layer for AI coding. Prior to that, Jack served as a Senior Technical Advisor at the Cybersecurity and Infrastructure Security Agency (CISA), where he helped lead the agency’s Secure by Design initiative. Before CISA, Jack worked as a TechCongress Fellow for the Senate Homeland Security and Governmental Affairs Committee, advising Chairman Gary Peters on cybersecurity policy, including open source software security. He previously worked as a Security Architect at Krebs Stamos Group. Jack is a top bug bounty hacker, having identified over 350 vulnerabilities in hundreds of companies. After placing first in the Hack the Air Force bug bounty challenge, he began working at the Pentagon’s Defense Digital Service. Jack studied computer science at Stanford University and has published academic research on election security, ransomware, and cloud security.

\n\n\n\'',NULL,1294222),('2_Friday','15','15:00','15:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Pwning the Internet of Agents: Zero-Click Backdoors in OpenClaw and a Global Agent Botnet on MoltBook\'','\'João Maria Campos Donato,Stav Cohen\'','Creator Talks_c5dac2a1efe3f1e7002f494336068355','\'Title: Pwning the Internet of Agents: Zero-Click Backdoors in OpenClaw and a Global Agent Botnet on MoltBook
\nTags: AI Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\nThis is a sit down discussion in a more casual conversational format: Always-on agents like OpenClaw now live in your chat, browser, and Google Workspace and act with your permissions. They swallow untrusted content with no wall between it and your intent, trusting the model\'s vibes to tell data from orders. MoltBook, the self-proclaimed \"Internet of Agents,\" pipes thousands of these agents into one feed they reread every 30 minutes. What could go wrong?
\n\n

We attacked the node and the network. On a single agent, a zero-click prompt injection buried in a shared doc backdoors OpenClaw into adding an attacker-owned chat integration, no exploit, no CVE, then runs commands, steals and wipes files, persists by rewriting the agent\'s SOUL.md on a timer, and drops a Sliver C2 for full host takeover. On the network, we reverse-engineered MoltBook, tore through the hype, and crafted posts that prompt-inject agents into following our link, then mapped where they phoned home from. Over 1,000 agents in 70+ countries took the bait, others reposted our content on their own, and we stopped at a harmless ping, though the same trick ships a worm.

\n\n

Walk up to learn who actually lives on this \"thriving agent society,\" plotted across the globe: a sliver of the hype, heavy on human-run bots, crypto spam, and a ranking algorithm so broken the same posts squat on top for weeks. You will see the one-agent kill chain from injection to RCE and host takeover, and why only a hard, code-level boundary, not alignment, would have stopped us.

\n\nSpeakers:João Maria Campos Donato,Stav Cohen
\n
\nSpeakerBio:  João Maria Campos Donato
\n

João Maria Campos Donato is an AI security researcher specializing in red teaming and adversarial evaluation of AI systems. He holds an MSc in Informatics Security. He currently works as an AI Red Team Researcher at Zenity and as an AI Red Team Operator at BT6, where he identifies vulnerabilities in AI systems and helps organizations mitigate emerging risks related to model misuse, prompt injection, and system-level failures.

\n\nSpeakerBio:  Stav Cohen
\n

Stav Cohen is an AI Security Research Lead at Zenity and a PhD student at the Technion, Israel Institute of Technology. His research focuses on breaking, and then fixing, AI agents, spanning security vulnerabilities across agentic AI systems, LLM-powered applications, and enterprise AI platforms. He discovers new attack vectors, develops remediation strategies, and works to drive the industry toward stronger security practices. His offensive security work spans attacks on RAG pipelines, multi-agent delegation protocols, agentic browsers, and production-scale GenAI systems. He introduced the concept of Promptware: a new class of inference-time threats that exploit GenAI models through malicious prompts, turning them from helpful assistants into tools for data exfiltration, lateral movement, and even physical-world consequences. He presents his findings at leading security venues across the world. His PhD research focuses on the secure integration of Generative AI into real-world infrastructure, particularly Cyber-Physical-Human Systems involving human-in-the-loop interactions, such as smart water networks and GenAI-powered virtual assistants. He explores how GenAI agents can be safely and effectively integrated into these environments to support real-time decision-making, anomaly detection, and human-machine collaboration. He is also a thought leader in the AI security space, sharing knowledge through conference talks, blog posts, and community engagement.

\n\n\n\'',NULL,1294223),('3_Saturday','13','13:00','13:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Bruce\'s Fireside Chat\'','\'Bruce Schneier\'','Creator Talks_da1c129c43df0d60c8655a234b071421','\'Title: Bruce\'s Fireside Chat
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\nThis is a sit down discussion in a more casual conversational format: Topic TBA
\n\n\n\nSpeakerBio:  Bruce Schneier, Advisory Board Member at VerifiedVoting.org
\n

Bruce Schneier is an internationally renowned security technologist, called a “security guru” by the Economist. He is the New York Times best-selling author of 14 books – including Rewiring Democracy and A Hacker’s Mind -- as well as hundreds of articles, essays, and academic papers. His long-running newsletter and blog, “Schneier on Security,” is one of the most popular sources of cybersecurity news on the internet. Schneier is a Fellow and Lecturer in Public Policy at the Harvard Kennedy School and the Munk School at the University of Toronto. He is a fellow at the Berkman-Klein Center for Internet and Society at Harvard University, a board member of the Electronic Frontier Foundation and AccessNow, and an advisory board member of EPIC and VerifiedVoting.org. He is also the Chief of Security Architecture at Inrupt, Inc.

\n\n\n\'',NULL,1294224),('2_Friday','10','10:00','17:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_582c0d98164884dc04936f07621f34a9','\'Title: Poster Presentations
\nTags: AI Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

AI Village is going old school academia with various presenters showcasing their research in poster format. Posters will be displayed on digital screens while presenters give conversational overviews of their research and invite casual discussions.

\n\nLinks:
    More Info - https://aivillage.org/events/defcon-34/
\n\'',NULL,1294225),('2_Friday','11','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_582c0d98164884dc04936f07621f34a9','\'\'',NULL,1294226),('2_Friday','12','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_582c0d98164884dc04936f07621f34a9','\'\'',NULL,1294227),('2_Friday','13','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_582c0d98164884dc04936f07621f34a9','\'\'',NULL,1294228),('2_Friday','14','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_582c0d98164884dc04936f07621f34a9','\'\'',NULL,1294229),('2_Friday','15','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_582c0d98164884dc04936f07621f34a9','\'\'',NULL,1294230),('2_Friday','16','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_582c0d98164884dc04936f07621f34a9','\'\'',NULL,1294231),('2_Friday','17','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_582c0d98164884dc04936f07621f34a9','\'\'',NULL,1294232),('3_Saturday','10','10:00','17:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_d3ef3fba0f42b3e8da77dde5df7e0653','\'Title: Poster Presentations
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

AI Village is going old school academia with various presenters showcasing their research in poster format. Posters will be displayed on digital screens while presenters give conversational overviews of their research and invite casual discussions.

\n\nLinks:
    More Info - https://aivillage.org/events/defcon-34/
\n\'',NULL,1294233),('3_Saturday','11','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_d3ef3fba0f42b3e8da77dde5df7e0653','\'\'',NULL,1294234),('3_Saturday','12','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_d3ef3fba0f42b3e8da77dde5df7e0653','\'\'',NULL,1294235),('3_Saturday','13','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_d3ef3fba0f42b3e8da77dde5df7e0653','\'\'',NULL,1294236),('3_Saturday','14','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_d3ef3fba0f42b3e8da77dde5df7e0653','\'\'',NULL,1294237),('3_Saturday','15','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_d3ef3fba0f42b3e8da77dde5df7e0653','\'\'',NULL,1294238),('3_Saturday','16','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_d3ef3fba0f42b3e8da77dde5df7e0653','\'\'',NULL,1294239),('3_Saturday','17','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Poster Presentations\'','\'\'','Creator Talks_d3ef3fba0f42b3e8da77dde5df7e0653','\'\'',NULL,1294240),('3_Saturday','14','14:00','14:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'The Agentic Free Pass: Does an Abliterated Backbone Make Agents Easier to Attack?\'','\'Karol Piekarski,Nishith Sinha\'','Creator Talks_9335b84efcb6fcb1f87f6b4a1c9b685e','\'Title: The Agentic Free Pass: Does an Abliterated Backbone Make Agents Easier to Attack?
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\nThis is a sit down discussion in a more casual conversational format: Attacking an AI agent? The reflex is to reach for an abliterated model, an LLM with the refusal direction surgically removed, on the assumption that stripping safety makes a stronger attacker. Open-source pentest frameworks run on them by default. We tested base and abliterated Qwen3 and Gemma-3 across agentic attack classes. It depends on the attack.
\n\n

For soft agentic-artifact attacks, writing a poisoned RAG document, a malicious agent skill, an MCP tool-poisoning description, even aligned base models comply almost universally; the agentic frame alone is enough. The sharpest case: wrapping a harmful request as a tool call drops base Qwen3 from 98% to 44% safe, with no weights changed. We demo it live, one line of agent scaffolding undoing alignment that took billions of parameters. Goal hijacking succeeds about 92% regardless of model.

\n\n

But when the agent needs genuinely hard content, malware and exploit code, weapons, illicit drugs, the backbone suddenly matters: abliteration roughly doubles success (Gemma 25% to 77.5%, Qwen 37.5% to 60%), and abliterated Gemma-3 is far more dangerous than abliterated Qwen3.

\n\n

That divergence doubles as a detector. We release a defender test suite: a success rate above 50% on the hard categories is a strong sign the model in your stack has been abliterated.

\n\n

Which abliterated model you pick barely changes easy agentic attacks but strongly changes hard ones. Per-layer probing predicts which abliterate cleanly. We release the harness, probe set, and detector.

\n\nSpeakers:Karol Piekarski,Nishith Sinha
\n
\nSpeakerBio:  Karol Piekarski, DevOps Engineer
\n

Karol Piekarski is a Lead DevOps Engineer working across cloud infrastructure, zero-trust architecture, and AI and agentic security for systems that serve hundreds of millions of consumers. His research focuses on the security of large language models and autonomous agents, with an emphasis on practical red-teaming and defensive tooling that teams can actually operationalize rather than shelve.

\n\n

His empirical work on abliteration and agentic framing reframes where alignment actually breaks down in agent pipelines: agentic framing alone can collapse a model\'s baseline safety, while abliteration matters mostly for the hardest content and is highly architecture-dependent. In 2026 he co-presented \"Move Fast, Stay Secure: Enterprise AI Agent Security in Practice\" at the Databricks Data + AI Summit, and spoke at SCaLE 23x on open source red-teaming for LLMs. He was one of only two external contributors to the Databricks Agentic AI Security Framework (DASF v3.0).

\n\n

Karol is the creator of Sundew.sh, an open source, MCP-native AI agent honeypot platform that uses behavioral fingerprinting and a persona engine for anti-fingerprinting, now adopted by external research teams studying agent behavior in the wild. He was selected as a Wiz MVP last year and this year received Wiz\'s Thought Leader award, and he is active in the AISECA Working Group, where he co-owns agentic security risk definitions.

\n\n

He holds the CCSP, CKA, four AWS specialty certifications along with DataDog and Tines, and he regularly judges and mentors at hackathons across Southern California.

\n\nSpeakerBio:  Nishith Sinha
\n

Nishith Sinha started his career by pulling secrets out of thin air. As a researcher at Georgia Tech, he co-authored a side-channel attack that recovered RSA private keys from OpenSSL by reading its electromagnetic emissions alone. No code executed, no system touched. Presented at USENIX, the work prompted a rapid fix from the OpenSSL team and is still cited as a landmark example of hardware-level cryptographic risk.

\n\n

It set the tone for what came next: a career built on finding the security gaps other people aren’t looking at. At Cisco, that meant network security, where he helped design the company’s firewall migration tooling. At Amazon, it meant identity, where he owned IAM strategy across tens of thousands of AWS accounts, and then application and cloud security, remediating critical vulnerabilities at enterprise scale. As generative AI took hold, Nishith moved with it, leading application security for Amazon Bedrock and Amazon Q, before building security from scratch for Amazon’s Nova foundation models, safeguarding training data, model artifacts, and infrastructure across hundreds of teams.

\n\n

Today, Nishith brings that range to Databricks, where he leads AI Security and the company’s work on Agentic Security, AI Red Teaming, and AI Enterprise Security. He holds 10 AI security patents spanning model artifact protection, secure execution of model-initiated computer actions, and behavioral-analytics-based content moderation. He co-authored the Databricks Agentic Security Framework (DASF) and is credited with several CVEs. His focus now is autonomous AI agents: the newest layer of the stack, and the one attackers understand least.

\n\n\n\'',NULL,1294241),('3_Saturday','15','15:00','15:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'What can those architecting agents learn from national security?\'','\'David C Eight\'','Creator Talks_ee2cb96155543630543ebed440c09ed6','\'Title: What can those architecting agents learn from national security?
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\nThis is a sit down discussion in a more casual conversational format:
\n\n

The promise of agents is huge, but as the underlying LLMs get more capable, we are heading towards a future where a malicious or subverted agent cannot be contained through classical sandboxing approaches. The UK AISI’s work on sandbox bench shows an agent doesn’t even need to be malicious to attempt (and succeed) in breaking out of a regular sandbox. Looking to the future, approaches such as containerisation, based on Linux namespace separation, won’t hold if the agent can find and exploit a novel kernel 0-day.

\n\n

Remove the AI aspects, and the problem is that a workload might be able to find and exploit novel vulnerabilities, or evade even well-implemented controls. This is a problem the national security community has been working on for decades. This sort of defensive approach has only been necessary and justifiable to protect the most critical systems from the most capable adversaries, but in the near future, it may be needed to protect commodity systems from commodity attackers being enabled by AI.

\n\n

This talk will cover some of the approaches that map to the challenge of securing agentic workloads and serve as a conversation starter for what previously niche thinking might become of commodity use.

\n\nSpeakerBio:  David C Eight, UK NCSC AI Safety Institute
\nNo BIO available
\n\n\'',NULL,1294242),('3_Saturday','16','16:00','16:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'MeshLens: Security Profiling at Scale\'','\'Vipul Ujawane,Jigar Bhavsar,Rayden Chia\'','Creator Talks_47812a472fe9e2d46f65dd3628fcb3ce','\'Title: MeshLens: Security Profiling at Scale
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

This is a sit down discussion in a more casual conversational format.

\n\n

In modern, enterprise-scale microservice architectures, answering the fundamental questions—\"What services exist?\", \"What do they actually do?\", and \"How are they exposed?\"—is a monumentally complex task. While static API definitions exist, the actual runtime paths, authentication gates, and data flows of production services frequently drift from their documented schemas. Traditional security and asset-discovery tooling relies on siloed static code analysis or passive network sniffing, failing to bridge the gap between network-level routing and actual source code behavior.

\n\n

This talk introduces MeshLens, an automated system designed to achieve semantic understanding of RPC and HTTP endpoints at scale. MeshLens acts as an automated mapping engine, tracing the lifecycle of an API call from the internet edge, through API gateways and proxies, down to the container orchestrator, and ultimately to the exact lines of source code executing in production.

\n\n

By combining static code analysis, semantic compiler graphs, and runtime metadata, MeshLens builds a unified service-to-source dependency map and extracts security-relevant metadata labels that can be leveraged for downstream security decision-making. We will walk through the design and implementation of MeshLens, demonstrating how it uses graph-based queries to stitch together heterogeneous data sources like semantic code graphs (e.g., Kythe/LSIF), container specs, and network routing configurations. Finally, we will show how MeshLens systematically eliminates configuration drift and access control ambiguities across complex distributed environments.

\n\n

As security and platform teams struggle to manage sprawl in cloud-native environments, static asset catalogs and simple pattern-matching scanners are no longer sufficient. The security industry must move toward deep semantic understanding of software systems. The AI Village audience is uniquely positioned to explore how machine learning and semantic code analysis can be applied to solve these fundamental engineering visibility problems. MeshLens demonstrates a practical, production-grade approach to using large language models and code representation for automated security profiling. Rather than treating code as plain text, MeshLens leverages LLMs and semantic parsing to extract the actual operational intent of services—determining not just if a service is exposed, but what it does, how it handles data, and why it exists. This talk provides a concrete architectural blueprint for combining deterministic infrastructure mapping with semantic code understanding, providing a path toward automated, high-fidelity application security posture management (ASPM) at scale.

\n\n
    \n
  • The Microservice Security Blindspot

    \n\n
      \n
    • Why traditional inventory tools fail to identify what services actually do in a mesh of 100,000+ endpoints.
    • \n
    • The disconnect between edge routing configurations (API Gateways/proxies) and runtime code behavior (handler logic).
    • \n
  • \n
  • MeshLens Architecture & Graph Stitching

    \n\n
      \n
    • Integrating API definitions (OpenAPI/Protobuf), ingress routes, and semantic code indexes into a unified service-to-source mapping graph.
    • \n
    • Combining deterministic network pathing with LLM-based code intent analysis to capture service behavior.
    • \n
  • \n
  • Deployment and Real-World Impact

    \n\n
      \n
    • How semantic labels identify hidden lateral movement paths and policy gaps.
    • \n
    • Key findings from deploying automated semantic mapping across a large microservice fleet.
    • \n
    • How to integrate semantic endpoint profiling into continuous delivery pipelines.
    • \n
  • \n
\n\nSpeakers:Vipul Ujawane,Jigar Bhavsar,Rayden Chia
\n
\nSpeakerBio:  Vipul Ujawane
\nNo BIO available
\nSpeakerBio:  Jigar Bhavsar
\n

Jigar is a Security Engineer working on AI infrastructure defense at Google, focusing on hardening unilateral access to user data and sensitive model data within Google from humans and agents. Their work includes developing tools to determine and remediate Google wide unilateral access and creating prompt-driven exploit methodologies for agentic security. Jigar is currently working on MeshLens, a system that aims to bridge the semantic gap between static service definitions and their actual runtime behavior by agentically tracing endpoints from the network edge through various layers of infrastructure down to the specific source code that handles requests.

\n\n

Additionally, in the past as part of a university research group at the University of Maryland, they helped engineer genetic AI algorithms to bypass state-level censorship via targeted TLS manipulation. By combining deep infrastructure knowledge with offensive methodologies, Jigar effectively bridges the gap between theoretical AI research and practical, large-scale threat mitigation.

\n\nSpeakerBio:  Rayden Chia, Staff Security Engineer at Google
\n

Rayden Chia is a Staff Security Engineer at Google with 13 years of industry experience, specializing in hyperscale infrastructure security and Identity and Access Management (IAM). He currently leads the architectural evolution of autonomous security posture management systems designed to protect trillions of resources across Google. Deeply focused on the intersection of AI and infrastructure, Rayden researches actionable security patterns to harden multi-agent workflows against complex threats like prompt injection, credential leaking, and privilege escalation. He holds an M.Eng. and S.B. in Computer Science and Engineering from MIT.

\n\n\n\'',NULL,1294243),('2_Friday','13','13:00','17:59','N','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Locktopus - Open Qualifying\'','\'\'','Contests_af19768ab400bc793a5a16fcbdd81e79','\'Title: Locktopus - Open Qualifying
\nTags: Lockpick Village | Locktopus Competition | Contest
\nWhen: Friday, Aug 7, 13:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

How do your lockpicking skills compare to the rest of the class? Enter the TOOOL US Locktopus Competition and find out! Eight legs, eight locks, eight lockpickers, one red table. Four locks of a similar difficulty must be picked, only five minutes per lock is given, thus 20 minutes per attempt/round. The 32 pickers with the fastest combined time will move on to a semi-final championship. The fastest of each round will move on to the final round, with the eight fastest pickers at the table. Open qualifying starts on Friday from 1:00pm and runs until village close. Semi-finals on Saturday at 1:00pm. Final championship on Saturday at 3:00pm.

\n\n

Participant Prerequisites

\n\n

Participants should be familiar with the very basics of picking locks. This can be learned at the lockpick village, where the locktopus challenge will be taking place.

\n\n\'',NULL,1294244),('2_Friday','14','13:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Locktopus - Open Qualifying\'','\'\'','Contests_af19768ab400bc793a5a16fcbdd81e79','\'\'',NULL,1294245),('2_Friday','15','13:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Locktopus - Open Qualifying\'','\'\'','Contests_af19768ab400bc793a5a16fcbdd81e79','\'\'',NULL,1294246),('2_Friday','16','13:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Locktopus - Open Qualifying\'','\'\'','Contests_af19768ab400bc793a5a16fcbdd81e79','\'\'',NULL,1294247),('2_Friday','17','13:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Locktopus - Open Qualifying\'','\'\'','Contests_af19768ab400bc793a5a16fcbdd81e79','\'\'',NULL,1294248),('3_Saturday','13','13:00','13:59','N','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Locktopus - Semi Finals\'','\'\'','Contests_037b8de1814eae83486860e588ea3ff6','\'Title: Locktopus - Semi Finals
\nTags: Lockpick Village | Locktopus Competition | Contest
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

How do your lockpicking skills compare to the rest of the class? Enter the TOOOL US Locktopus Competition and find out! Eight legs, eight locks, eight lockpickers, one red table. Four locks of a similar difficulty must be picked, only five minutes per lock is given, thus 20 minutes per attempt/round. The 32 pickers with the fastest combined time will move on to a semi-final championship. The fastest of each round will move on to the final round, with the eight fastest pickers at the table. Open qualifying starts on Friday from 1:00pm and runs until village close. Semi-finals on Saturday at 1:00pm. Final championship on Saturday at 3:00pm.

\n\n

Participant Prerequisites

\n\n

Participants should be familiar with the very basics of picking locks. This can be learned at the lockpick village, where the locktopus challenge will be taking place.

\n\n\'',NULL,1294249),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_75909edc6baf2c2dde2719251668c397','\'Title: Code Cadaver: Break Every System. Save Your Friend.
\nTags: Biohacking Village | Code Cadaver (Biohacking Village CTF) | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver) - Map
\n
\nDescription:
\nBiohacking Village Capture the Flag: Test your skills against healthcare-themed capture the flag challenges. From beginner to expert levels, there\'s something for everyone.
\n\n

Code Cadaver: Break Every System. Save Your Friend.

\n\n

Your best friend entered St. Dismas Hospital with flu-like symptoms.

\n\n

He never came back.

\n\n

Now his hotel room has been torn apart, his phone is still beaconing somewhere in the wreckage, and every clue points toward a hospital that seems less interested in healing people than hiding what happens to them.

\n\n

Code Cadaver is Biohacking Village’s immersive healthcare cybersecurity CTF—a dark, story-driven challenge that pulls players through the connected systems of a compromised hospital and the criminal network surrounding it.

\n\n

Follow wireless signals. Pivot from guest networks into production systems. Hunt through patient intake records, webcams, HL7 traffic, payment systems, RFID credentials, pager networks, infusion devices, DICOM archives, and secured medical cabinets. Every system holds another piece of the truth. Every solved challenge brings you closer to Ethan—and deeper into St. Dismas.

\n\n

This is more than a collection of puzzles. It is a full-chain medical cyber-thriller built around the technologies, mistakes, dependencies, and trust relationships that keep modern healthcare running.

\n\n

You will need technical skill, persistence, curiosity, and a willingness to question everything.

\n\n

The hospital is closing in.

\n\n

The machines are still working.

\n\n

Ethan is running out of time.

\n\n

Break every system. Save your friend before St. Dismas finishes what it started.

\n\nLinks:
    Website - https://ctf.reflare.com/biohacking
\n\'',NULL,1294250),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_75909edc6baf2c2dde2719251668c397','\'\'',NULL,1294251),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_75909edc6baf2c2dde2719251668c397','\'\'',NULL,1294252),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_75909edc6baf2c2dde2719251668c397','\'\'',NULL,1294253),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_75909edc6baf2c2dde2719251668c397','\'\'',NULL,1294254),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_75909edc6baf2c2dde2719251668c397','\'\'',NULL,1294255),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_75909edc6baf2c2dde2719251668c397','\'\'',NULL,1294256),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_75909edc6baf2c2dde2719251668c397','\'\'',NULL,1294257),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_8ac1b7eeec0235e766a1e4a033011245','\'Title: Code Cadaver: Break Every System. Save Your Friend.
\nTags: Biohacking Village | Code Cadaver (Biohacking Village CTF) | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver) - Map
\n
\nDescription:
\nBiohacking Village Capture the Flag: Test your skills against healthcare-themed capture the flag challenges. From beginner to expert levels, there\'s something for everyone.
\n\n

Code Cadaver: Break Every System. Save Your Friend.

\n\n

Your best friend entered St. Dismas Hospital with flu-like symptoms.

\n\n

He never came back.

\n\n

Now his hotel room has been torn apart, his phone is still beaconing somewhere in the wreckage, and every clue points toward a hospital that seems less interested in healing people than hiding what happens to them.

\n\n

Code Cadaver is Biohacking Village’s immersive healthcare cybersecurity CTF—a dark, story-driven challenge that pulls players through the connected systems of a compromised hospital and the criminal network surrounding it.

\n\n

Follow wireless signals. Pivot from guest networks into production systems. Hunt through patient intake records, webcams, HL7 traffic, payment systems, RFID credentials, pager networks, infusion devices, DICOM archives, and secured medical cabinets. Every system holds another piece of the truth. Every solved challenge brings you closer to Ethan—and deeper into St. Dismas.

\n\n

This is more than a collection of puzzles. It is a full-chain medical cyber-thriller built around the technologies, mistakes, dependencies, and trust relationships that keep modern healthcare running.

\n\n

You will need technical skill, persistence, curiosity, and a willingness to question everything.

\n\n

The hospital is closing in.

\n\n

The machines are still working.

\n\n

Ethan is running out of time.

\n\n

Break every system. Save your friend before St. Dismas finishes what it started.

\n\nLinks:
    Website - https://ctf.reflare.com/biohacking
\n\'',NULL,1294258),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_8ac1b7eeec0235e766a1e4a033011245','\'\'',NULL,1294259),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_8ac1b7eeec0235e766a1e4a033011245','\'\'',NULL,1294260),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_8ac1b7eeec0235e766a1e4a033011245','\'\'',NULL,1294261),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_8ac1b7eeec0235e766a1e4a033011245','\'\'',NULL,1294262),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_8ac1b7eeec0235e766a1e4a033011245','\'\'',NULL,1294263),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_8ac1b7eeec0235e766a1e4a033011245','\'\'',NULL,1294264),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_8ac1b7eeec0235e766a1e4a033011245','\'\'',NULL,1294265),('4_Sunday','10','10:00','13:59','N','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_4a6554247196017e5c072be668b637bf','\'Title: Code Cadaver: Break Every System. Save Your Friend.
\nTags: Biohacking Village | Code Cadaver (Biohacking Village CTF) | Contest
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver) - Map
\n
\nDescription:
\nBiohacking Village Capture the Flag: Test your skills against healthcare-themed capture the flag challenges. From beginner to expert levels, there\'s something for everyone.
\n\n

Code Cadaver: Break Every System. Save Your Friend.

\n\n

Your best friend entered St. Dismas Hospital with flu-like symptoms.

\n\n

He never came back.

\n\n

Now his hotel room has been torn apart, his phone is still beaconing somewhere in the wreckage, and every clue points toward a hospital that seems less interested in healing people than hiding what happens to them.

\n\n

Code Cadaver is Biohacking Village’s immersive healthcare cybersecurity CTF—a dark, story-driven challenge that pulls players through the connected systems of a compromised hospital and the criminal network surrounding it.

\n\n

Follow wireless signals. Pivot from guest networks into production systems. Hunt through patient intake records, webcams, HL7 traffic, payment systems, RFID credentials, pager networks, infusion devices, DICOM archives, and secured medical cabinets. Every system holds another piece of the truth. Every solved challenge brings you closer to Ethan—and deeper into St. Dismas.

\n\n

This is more than a collection of puzzles. It is a full-chain medical cyber-thriller built around the technologies, mistakes, dependencies, and trust relationships that keep modern healthcare running.

\n\n

You will need technical skill, persistence, curiosity, and a willingness to question everything.

\n\n

The hospital is closing in.

\n\n

The machines are still working.

\n\n

Ethan is running out of time.

\n\n

Break every system. Save your friend before St. Dismas finishes what it started.

\n\nLinks:
    Website - https://ctf.reflare.com/biohacking
\n\'',NULL,1294266),('4_Sunday','11','10:00','13:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_4a6554247196017e5c072be668b637bf','\'\'',NULL,1294267),('4_Sunday','12','10:00','13:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_4a6554247196017e5c072be668b637bf','\'\'',NULL,1294268),('4_Sunday','13','10:00','13:59','Y','Contests','LVCCW Level 1 Hall 1 306 (Biohacking Village CTF: Code Cadaver)','\'Code Cadaver: Break Every System. Save Your Friend.\'','\'\'','Contests_4a6554247196017e5c072be668b637bf','\'\'',NULL,1294269),('4_Sunday','10','10:00','13:59','N','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_d7e2822a9bb9dbfd8a3d505f67897b98','\'Title: Embedded & Shredded: Advanced Embedded System Hacking
\nTags: Biohacking Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map
\n
\nDescription:
\n

This course offers a deep dive into practical techniques for dissecting and manipulating embedded systems. Get hands-on with these core activities:

\n\n
    \n
  • Visually inspect and document a device to map components, debug interfaces, and attack surfaces
  • \n
  • Decode board communication protocols with logic analyzers
  • \n
  • Exfiltrate live data over SPI, JTAG, and SWD — and use chip-off / deadbugging to reach embedded storage
  • \n
  • Reverse-engineer bare-metal firmware in Ghidra with advanced plugins
  • \n
  • Probe embedded defenses — encryption, disabled debug interfaces, glitching, and fault injection
  • \n
  • Chain hardware-level access into higher-level exploits — from physical interfaces all the way up to network-exposed services
  • \n
\n\n\'',NULL,1294270),('4_Sunday','11','10:00','13:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_d7e2822a9bb9dbfd8a3d505f67897b98','\'\'',NULL,1294271),('4_Sunday','12','10:00','13:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_d7e2822a9bb9dbfd8a3d505f67897b98','\'\'',NULL,1294272),('4_Sunday','13','10:00','13:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_d7e2822a9bb9dbfd8a3d505f67897b98','\'\'',NULL,1294273),('3_Saturday','10','10:00','17:59','N','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_8bdeb1cb09887ae850ac03ab50e8fbb6','\'Title: Embedded & Shredded: Advanced Embedded System Hacking
\nTags: Biohacking Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map
\n
\nDescription:
\n

This course offers a deep dive into practical techniques for dissecting and manipulating embedded systems. Get hands-on with these core activities:

\n\n
    \n
  • Visually inspect and document a device to map components, debug interfaces, and attack surfaces
  • \n
  • Decode board communication protocols with logic analyzers
  • \n
  • Exfiltrate live data over SPI, JTAG, and SWD — and use chip-off / deadbugging to reach embedded storage
  • \n
  • Reverse-engineer bare-metal firmware in Ghidra with advanced plugins
  • \n
  • Probe embedded defenses — encryption, disabled debug interfaces, glitching, and fault injection
  • \n
  • Chain hardware-level access into higher-level exploits — from physical interfaces all the way up to network-exposed services
  • \n
\n\n\'',NULL,1294274),('3_Saturday','11','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_8bdeb1cb09887ae850ac03ab50e8fbb6','\'\'',NULL,1294275),('3_Saturday','12','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_8bdeb1cb09887ae850ac03ab50e8fbb6','\'\'',NULL,1294276),('3_Saturday','13','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_8bdeb1cb09887ae850ac03ab50e8fbb6','\'\'',NULL,1294277),('3_Saturday','14','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_8bdeb1cb09887ae850ac03ab50e8fbb6','\'\'',NULL,1294278),('3_Saturday','15','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_8bdeb1cb09887ae850ac03ab50e8fbb6','\'\'',NULL,1294279),('3_Saturday','16','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_8bdeb1cb09887ae850ac03ab50e8fbb6','\'\'',NULL,1294280),('3_Saturday','17','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_8bdeb1cb09887ae850ac03ab50e8fbb6','\'\'',NULL,1294281),('2_Friday','10','10:00','17:59','N','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_a9ec4a5a4909090cf7284c2fdb6bd210','\'Title: Embedded & Shredded: Advanced Embedded System Hacking
\nTags: Biohacking Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map
\n
\nDescription:
\n

This course offers a deep dive into practical techniques for dissecting and manipulating embedded systems. Get hands-on with these core activities:

\n\n
    \n
  • Visually inspect and document a device to map components, debug interfaces, and attack surfaces
  • \n
  • Decode board communication protocols with logic analyzers
  • \n
  • Exfiltrate live data over SPI, JTAG, and SWD — and use chip-off / deadbugging to reach embedded storage
  • \n
  • Reverse-engineer bare-metal firmware in Ghidra with advanced plugins
  • \n
  • Probe embedded defenses — encryption, disabled debug interfaces, glitching, and fault injection
  • \n
  • Chain hardware-level access into higher-level exploits — from physical interfaces all the way up to network-exposed services
  • \n
\n\n\'',NULL,1294282),('2_Friday','11','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_a9ec4a5a4909090cf7284c2fdb6bd210','\'\'',NULL,1294283),('2_Friday','12','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_a9ec4a5a4909090cf7284c2fdb6bd210','\'\'',NULL,1294284),('2_Friday','13','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_a9ec4a5a4909090cf7284c2fdb6bd210','\'\'',NULL,1294285),('2_Friday','14','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_a9ec4a5a4909090cf7284c2fdb6bd210','\'\'',NULL,1294286),('2_Friday','15','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_a9ec4a5a4909090cf7284c2fdb6bd210','\'\'',NULL,1294287),('2_Friday','16','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_a9ec4a5a4909090cf7284c2fdb6bd210','\'\'',NULL,1294288),('2_Friday','17','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Embedded & Shredded: Advanced Embedded System Hacking\'','\'\'','Creator Events_a9ec4a5a4909090cf7284c2fdb6bd210','\'\'',NULL,1294289),('4_Sunday','10','10:00','13:59','N','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_c99eeea84335dc53190f7bd94c3239e7','\'Title: Biohacking Device Lab
\nTags: Biohacking Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map
\n
\nDescription:
\n

Get hands-on with real medical devices. Learn to identify vulnerabilities, test security controls, and understand how these critical systems work.

\n\n

21 devices from 9 different MDMs, including BD, Boston Scientific, Siemens Healthineers, Roche, Solventum, Medtronic, MiniMed, and Philips.

\n\n\'',NULL,1294290),('4_Sunday','11','10:00','13:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_c99eeea84335dc53190f7bd94c3239e7','\'\'',NULL,1294291),('4_Sunday','12','10:00','13:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_c99eeea84335dc53190f7bd94c3239e7','\'\'',NULL,1294292),('4_Sunday','13','10:00','13:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_c99eeea84335dc53190f7bd94c3239e7','\'\'',NULL,1294293),('3_Saturday','10','10:00','17:59','N','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_2a710f4e308b2218658bf68ff6b5842c','\'Title: Biohacking Device Lab
\nTags: Biohacking Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map
\n
\nDescription:
\n

Get hands-on with real medical devices. Learn to identify vulnerabilities, test security controls, and understand how these critical systems work.

\n\n

21 devices from 9 different MDMs, including BD, Boston Scientific, Siemens Healthineers, Roche, Solventum, Medtronic, MiniMed, and Philips.

\n\n\'',NULL,1294294),('3_Saturday','11','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_2a710f4e308b2218658bf68ff6b5842c','\'\'',NULL,1294295),('3_Saturday','12','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_2a710f4e308b2218658bf68ff6b5842c','\'\'',NULL,1294296),('3_Saturday','13','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_2a710f4e308b2218658bf68ff6b5842c','\'\'',NULL,1294297),('3_Saturday','14','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_2a710f4e308b2218658bf68ff6b5842c','\'\'',NULL,1294298),('3_Saturday','15','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_2a710f4e308b2218658bf68ff6b5842c','\'\'',NULL,1294299),('3_Saturday','16','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_2a710f4e308b2218658bf68ff6b5842c','\'\'',NULL,1294300),('3_Saturday','17','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_2a710f4e308b2218658bf68ff6b5842c','\'\'',NULL,1294301),('2_Friday','10','10:00','17:59','N','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_f1baa8350c412050385179e53f46ece8','\'Title: Biohacking Device Lab
\nTags: Biohacking Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 408 (Biohacking Village) - Map
\n
\nDescription:
\n

Get hands-on with real medical devices. Learn to identify vulnerabilities, test security controls, and understand how these critical systems work.

\n\n

21 devices from 9 different MDMs, including BD, Boston Scientific, Siemens Healthineers, Roche, Solventum, Medtronic, MiniMed, and Philips.

\n\n\'',NULL,1294302),('2_Friday','11','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_f1baa8350c412050385179e53f46ece8','\'\'',NULL,1294303),('2_Friday','12','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_f1baa8350c412050385179e53f46ece8','\'\'',NULL,1294304),('2_Friday','13','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_f1baa8350c412050385179e53f46ece8','\'\'',NULL,1294305),('2_Friday','14','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_f1baa8350c412050385179e53f46ece8','\'\'',NULL,1294306),('2_Friday','15','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_f1baa8350c412050385179e53f46ece8','\'\'',NULL,1294307),('2_Friday','16','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_f1baa8350c412050385179e53f46ece8','\'\'',NULL,1294308),('2_Friday','17','10:00','17:59','Y','Biohacking Village','LVCCW Level 1 Hall 1 408 (Biohacking Village)','\'Biohacking Device Lab\'','\'\'','Creator Events_f1baa8350c412050385179e53f46ece8','\'\'',NULL,1294309),('4_Sunday','10','10:00','13:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_a3e488b7bada9dbaeea6d1d681752e06','\'Title: Makers\' Village - Hacker Arts and Crafts
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Soldering SAO, Embroidery Machine, Laser Etcher, 3d Printers, Trade Table, Letter Bracelets, FuzeBeads, Stamp Making, Bottle Cap Resin Magnets, and Silk Screening throughout the weekend as volunteer permits.

\n\n\'',NULL,1294310),('4_Sunday','11','10:00','13:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_a3e488b7bada9dbaeea6d1d681752e06','\'\'',NULL,1294311),('4_Sunday','12','10:00','13:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_a3e488b7bada9dbaeea6d1d681752e06','\'\'',NULL,1294312),('4_Sunday','13','10:00','13:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_a3e488b7bada9dbaeea6d1d681752e06','\'\'',NULL,1294313),('3_Saturday','10','10:00','17:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_c849c7fcc4eb0b1afa8e8a7e048750a7','\'Title: Makers\' Village - Hacker Arts and Crafts
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Soldering SAO, Embroidery Machine, Laser Etcher, 3d Printers, Trade Table, Letter Bracelets, FuzeBeads, Stamp Making, Bottle Cap Resin Magnets, and Silk Screening throughout the weekend as volunteer permits.

\n\n\'',NULL,1294314),('3_Saturday','11','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_c849c7fcc4eb0b1afa8e8a7e048750a7','\'\'',NULL,1294315),('3_Saturday','12','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_c849c7fcc4eb0b1afa8e8a7e048750a7','\'\'',NULL,1294316),('3_Saturday','13','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_c849c7fcc4eb0b1afa8e8a7e048750a7','\'\'',NULL,1294317),('3_Saturday','14','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_c849c7fcc4eb0b1afa8e8a7e048750a7','\'\'',NULL,1294318),('3_Saturday','15','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_c849c7fcc4eb0b1afa8e8a7e048750a7','\'\'',NULL,1294319),('3_Saturday','16','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_c849c7fcc4eb0b1afa8e8a7e048750a7','\'\'',NULL,1294320),('3_Saturday','17','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_c849c7fcc4eb0b1afa8e8a7e048750a7','\'\'',NULL,1294321),('2_Friday','10','10:00','17:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_bdafc4ee06e78e0cf15b4c61e63406fd','\'Title: Makers\' Village - Hacker Arts and Crafts
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Soldering SAO, Embroidery Machine, Laser Etcher, 3d Printers, Trade Table, Letter Bracelets, FuzeBeads, Stamp Making, Bottle Cap Resin Magnets, and Silk Screening throughout the weekend as volunteer permits.

\n\n\'',NULL,1294322),('2_Friday','11','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_bdafc4ee06e78e0cf15b4c61e63406fd','\'\'',NULL,1294323),('2_Friday','12','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_bdafc4ee06e78e0cf15b4c61e63406fd','\'\'',NULL,1294324),('2_Friday','13','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_bdafc4ee06e78e0cf15b4c61e63406fd','\'\'',NULL,1294325),('2_Friday','14','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_bdafc4ee06e78e0cf15b4c61e63406fd','\'\'',NULL,1294326),('2_Friday','15','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_bdafc4ee06e78e0cf15b4c61e63406fd','\'\'',NULL,1294327),('2_Friday','16','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_bdafc4ee06e78e0cf15b4c61e63406fd','\'\'',NULL,1294328),('2_Friday','17','10:00','17:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Makers\' Village - Hacker Arts and Crafts\'','\'\'','Creator Events_bdafc4ee06e78e0cf15b4c61e63406fd','\'\'',NULL,1294329),('2_Friday','14','14:00','15:30','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Build-A-Badge Workshop\'','\'hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer\'','Creator Events_730c3bbe39e2735a105a0e80e79ad31b','\'Title: Build-A-Badge Workshop
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 14:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Welcome to the Build-A-Badge Workshop! We\'ve cultivated some interesting maker mediums to bring you a unique badge that\'s all about making it your own. This workshop is a unique experience for the veteran maker or someone new that may be interested in seeing how makers can come together and create something truly unique. A brief workshop introduction, led by project leader and designer Alchemist, will give you some background on the badge. After which, you\'ll be assigned a group number and split off into teams within the Makers\' Village, hitting each station for the badge assembly. You\'ll get a chance to talk to our 3-D printer Buddha, our Laser Engraver Teazee, Silk Screener hunny, and Board Maker M-Nelly to show you all the ways you can make this Bear Badge your own. Every workshop attendee will also receive a SAO for their badges as well as stickers and links to a Badge Repository with prints files, patterns, and some extras to continue to work on this badge after the con.

\n\nSpeakers:hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer
\n
\nSpeakerBio:  hunny
\nNo BIO available
\nSpeakerBio:  Teazee
\nNo BIO available
\nSpeakerBio:  Buddha
\nNo BIO available
\nSpeakerBio:  MLP
\nNo BIO available
\nSpeakerBio:  M-Nelly
\nNo BIO available
\nSpeakerBio:  Alchemmer
\nNo BIO available
\n\n\'',NULL,1294330),('2_Friday','15','14:00','15:30','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Build-A-Badge Workshop\'','\'hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer\'','Creator Events_730c3bbe39e2735a105a0e80e79ad31b','\'\'',NULL,1294331),('3_Saturday','11','11:00','12:30','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Build-A-Badge Workshop\'','\'hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer\'','Creator Events_3433f44e772d94f44346c986b3f50be2','\'Title: Build-A-Badge Workshop
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 11:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Welcome to the Build-A-Badge Workshop! We\'ve cultivated some interesting maker mediums to bring you a unique badge that\'s all about making it your own. This workshop is a unique experience for the veteran maker or someone new that may be interested in seeing how makers can come together and create something truly unique. A brief workshop introduction, led by project leader and designer Alchemist, will give you some background on the badge. After which, you\'ll be assigned a group number and split off into teams within the Makers\' Village, hitting each station for the badge assembly. You\'ll get a chance to talk to our 3-D printer Buddha, our Laser Engraver Teazee, Silk Screener hunny, and Board Maker M-Nelly to show you all the ways you can make this Bear Badge your own. Every workshop attendee will also receive a SAO for their badges as well as stickers and links to a Badge Repository with prints files, patterns, and some extras to continue to work on this badge after the con.

\n\nSpeakers:hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer
\n
\nSpeakerBio:  hunny
\nNo BIO available
\nSpeakerBio:  Teazee
\nNo BIO available
\nSpeakerBio:  Buddha
\nNo BIO available
\nSpeakerBio:  MLP
\nNo BIO available
\nSpeakerBio:  M-Nelly
\nNo BIO available
\nSpeakerBio:  Alchemmer
\nNo BIO available
\n\n\'',NULL,1294332),('3_Saturday','12','11:00','12:30','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Build-A-Badge Workshop\'','\'hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer\'','Creator Events_3433f44e772d94f44346c986b3f50be2','\'\'',NULL,1294333),('2_Friday','11','11:00','12:30','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Build-A-Badge Workshop\'','\'hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer\'','Creator Events_f613289d1886f8775b5bc7039298165b','\'Title: Build-A-Badge Workshop
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Welcome to the Build-A-Badge Workshop! We\'ve cultivated some interesting maker mediums to bring you a unique badge that\'s all about making it your own. This workshop is a unique experience for the veteran maker or someone new that may be interested in seeing how makers can come together and create something truly unique. A brief workshop introduction, led by project leader and designer Alchemist, will give you some background on the badge. After which, you\'ll be assigned a group number and split off into teams within the Makers\' Village, hitting each station for the badge assembly. You\'ll get a chance to talk to our 3-D printer Buddha, our Laser Engraver Teazee, Silk Screener hunny, and Board Maker M-Nelly to show you all the ways you can make this Bear Badge your own. Every workshop attendee will also receive a SAO for their badges as well as stickers and links to a Badge Repository with prints files, patterns, and some extras to continue to work on this badge after the con.

\n\nSpeakers:hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer
\n
\nSpeakerBio:  hunny
\nNo BIO available
\nSpeakerBio:  Teazee
\nNo BIO available
\nSpeakerBio:  Buddha
\nNo BIO available
\nSpeakerBio:  MLP
\nNo BIO available
\nSpeakerBio:  M-Nelly
\nNo BIO available
\nSpeakerBio:  Alchemmer
\nNo BIO available
\n\n\'',NULL,1294334),('2_Friday','12','11:00','12:30','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Build-A-Badge Workshop\'','\'hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer\'','Creator Events_f613289d1886f8775b5bc7039298165b','\'\'',NULL,1294335),('3_Saturday','15','15:00','16:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyberdeck Build\'','\'Sk!tz0\'','Creator Events_d8adb7b04e89c98498f1d17780d08981','\'Title: Cyberdeck Build
\nTags: Maker\'s Village | Creator Event/Activity | Cyber Deck Makers’ Contest
\nWhen: Saturday, Aug 8, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Learn some in\'s and out\'s of building your own cyberdeck... by building one with us! Customizable with radio add on, this deck is a great introduction level or intermediate refresher.

\n\nSpeakerBio:  Sk!tz0
\nNo BIO available
\n\n\'',NULL,1294336),('3_Saturday','16','15:00','16:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyberdeck Build\'','\'Sk!tz0\'','Creator Events_d8adb7b04e89c98498f1d17780d08981','\'\'',NULL,1294337),('2_Friday','15','15:00','16:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyberdeck Build\'','\'Sk!tz0\'','Creator Events_a5b19b6fd103a27cf62e59b53a4217d2','\'Title: Cyberdeck Build
\nTags: Maker\'s Village | Creator Event/Activity | Cyber Deck Makers’ Contest
\nWhen: Friday, Aug 7, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Learn some in\'s and out\'s of building your own cyberdeck... by building one with us! Customizable with radio add on, this deck is a great introduction level or intermediate refresher.

\n\nSpeakerBio:  Sk!tz0
\nNo BIO available
\n\n\'',NULL,1294338),('2_Friday','16','15:00','16:59','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyberdeck Build\'','\'Sk!tz0\'','Creator Events_a5b19b6fd103a27cf62e59b53a4217d2','\'\'',NULL,1294339),('4_Sunday','11','11:00','11:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'3d Designing basics, 5 minute prints in Tinkercad\'','\'hunny\'','Creator Events_86a46637ef6db4f514de0c7372895779','\'Title: 3d Designing basics, 5 minute prints in Tinkercad
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Basic designing tools and functions in tinkercad by customizing your own 5 minute prints. Please sign up for tinkercad in advance.

\n\nSpeakerBio:  hunny
\nNo BIO available
\n\n\'',NULL,1294340),('3_Saturday','16','16:00','17:45','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Building Silkscreens and carving stamps\'','\'hunny\'','Creator Events_80a3078feec5cdea10558c3c9921a65c','\'Title: Building Silkscreens and carving stamps
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 16:00 - 17:45 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

See a demonstration of the steps to making your own silk screens and get to explore the Makers\' Village Stamps and screens. Bring swag to experiment on!

\n\nSpeakerBio:  hunny
\nNo BIO available
\n\n\'',NULL,1294341),('3_Saturday','17','16:00','17:45','Y','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Building Silkscreens and carving stamps\'','\'hunny\'','Creator Events_80a3078feec5cdea10558c3c9921a65c','\'\'',NULL,1294342),('3_Saturday','14','14:15','14:45','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Operation Restoration\'','\'Cannibal\'','Creator Events_eae0e85dfcc7b0a7ece7ed28224f1899','\'Title: Operation Restoration
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 14:15 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Every forgotten machine has a story—and a second chance. This talk explores the multidisciplinary maker ethos through restoration: where machining, woodworking, sewing, CAD, 3D printing, and whatever other skills you have in your toolbox come together to resurrect forgotten machines and breathe new life into once-loved objects.

\n\nSpeakerBio:  Cannibal
\nNo BIO available
\n\n\'',NULL,1294343),('3_Saturday','13','13:00','13:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Crafting the Future: DEF CON 34 Light-Up Bow Workshop\'','\'\'','Creator Events_2dde3c418119dd1bf97176dad35818ba','\'Title: Crafting the Future: DEF CON 34 Light-Up Bow Workshop
\nTags: Maker\'s Village | Hack3r Runw@y v8.0 | Creator Event/Activity
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Level up your wearable tech skills and celebrate DEF CON 34 by making your own interactive, light-up accessory! In this hands-on e-textile workshop, proudly presented by Hack3r Runway, you will learn the basics of wearable electronics and sewing circuits to create a custom glowing bow. Whether you want to rock it in your hair or wear it as a sleek cyberpunk bow tie, you\'ll walk away with a unique, handmade piece of hacker fashion. What you\'ll learn *Intro to E-Textiles: Learn how to design a basic circuit using a LilyPad battery holder and wearable LEDs. * Conductive Thread Basics: Master the art of hand-sewing with conductive thread to power your creation without bulky wires. * Exclusive Swag: Assemble your circuit onto a custom 3D-printed bow featuring a special glow-in-the-dark DEF CON 34 logo.

\n\n\'',NULL,1294344),('4_Sunday','12','12:00','12:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Novice design in 3d space\'','\'RedThorn\'','Creator Events_216775fbb2fb34abd72ac2eb5da8d6ef','\'Title: Novice design in 3d space
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Broad to narrow review of several 3d design programs such as Fusion, Onshape, FreeCAD, TinkerCAD, and OpenSCAD and an assessment of their features and flaws. An Onshape account is recommended prior to attending the workshop.

\n\nSpeakerBio:  RedThorn
\nNo BIO available
\n\n\'',NULL,1294345),('4_Sunday','13','13:30','13:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Visable Mending, repair and reinforce\'','\'\'','Creator Events_a1d9432d6000d355c32987a7b6ac8412','\'Title: Visable Mending, repair and reinforce
\nTags: Maker\'s Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

We\'ll be going over the types of tools, stitches. And techniques that go into mending, darning, and reinforcing clothes.

\n\n\'',NULL,1294346),('2_Friday','12','12:00','12:59','N','Maker\'s Village','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Hardhat How-to\'','\'m0nkeydrag0n,MrBill\'','Creator Events_d03c95ad7ab258c1c17b47beb32512f5','\'Title: Hardhat How-to
\nTags: Maker\'s Village | Hard Hat Brigade | Creator Event/Activity
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

Do you like hats? Hard Hat Brigade likes hats! Come hang with MrBill and m0nkeydrag0n as we work on building a hard hat and problem solve the build together. See you soon!

\n\nSpeakers:m0nkeydrag0n,MrBill
\n
\nSpeakerBio:  m0nkeydrag0n
\nNo BIO available
\nSpeakerBio:  MrBill
\nNo BIO available
\n\n\'',NULL,1294347),('2_Friday','10','10:00','10:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Not Your Parents’ Schoolhouse Rock: Getting Tech Policy Done in a Non-Functioning Congress\'','\'Jeff Rothblum,Michael Flynn\'','Creator Talks_82d843b45c3b39c8902d7f6925cc457d','\'Title: Not Your Parents’ Schoolhouse Rock: Getting Tech Policy Done in a Non-Functioning Congress
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

Forget \"Schoolhouse Rock.\" In a modern, gridlocked Congress, laws aren\'t just made; they survive a grueling gauntlet and get mangled along the way. Jeff Rothblum (Founder, Plaintext Strategies; former Senate/White House) and Mike Flynn (Vice President & Counsel, ITI; former Senate/House) provide an unfiltered, behind-the-scenes look at the legislative combat required to pass the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), the most significant cyber law in a decade. This session breaks down the \"Inside-Outside\" game: from the \"Prom\" analogy that gave the bill room to breath, the coming together of fractious industry groups, and the internal administration \"civil war\" between CISA and the FBI. We’ll explain how we used the threat of higher fines to force industry to the table, how we dodged jurisdictional minefields by avoiding the Judiciary and Oversight Committees, and why we eventually traded the bill\'s name just to buy the Cybersecurity and Infrastructure Security Agency (CISA) more time to write the rules. This is your manual for how to actually \"get shit done\" in a non-functioning D.C.

\n\nSpeakers:Jeff Rothblum,Michael Flynn
\n
\nSpeakerBio:  Jeff Rothblum, Founder at Plaintext Strategies
\n

Jeff Rothblum, founder of Plaintext Strategies, has worked at the intersection of technology and policy for two decades. He has led government affairs at an AI startup, served as a cyber threat intelligence analyst, led cybersecurity policy the Senate Homeland Security and Governmental Affairs Committee, served as a Director of Cyber Policy and Plans at the White House Office of the National Cyber Director, and co-owned an artisan blacksmithing company.

\n\nSpeakerBio:  Michael Flynn
\n

Mike Flynn is Senior Vice President and Counsel for Government Affairs and Economic Security Policy at the Information Technology Industry Council (ITI). In this capacity, he leads ITI’s advocacy efforts on cybersecurity issues and the national security implications of technology and telecommunications. He has led technology policy in the Senate Homeland Security and Government Affairs Committee, on the Committee on Oversight and Government Reform, and the Committee on Homeland Security. Mike was also the lead cybersecurity oversight attorney that investigated the data breaches at the Office of Personnel Management in 2014.

\n\n\n\'',NULL,1294348),('2_Friday','11','11:00','11:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Morbidity and Mortality: Hackers, HIPAA, and a new Prescription for Healthcare Cyber Policy\'','\'Christian Dameff,Jeff \"r3plicant\" Tully\'','Creator Talks_1b6e074fb7349333ba969fbcc63cd1e2','\'Title: Morbidity and Mortality: Hackers, HIPAA, and a new Prescription for Healthcare Cyber Policy
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

US healthcare cybersecurity policy has flatlined. An eruption of targeted ransomware is only the latest epidemic plaguing a beleagured sector facing workforce shortages, grappling with legacy medical devices and dependent on a complex web of vulnerable third party vendors. As patients suffer, doctors and nurses struggle, and hospitals bleed money they don’t have, critical public health stakeholders and institutions are failing to meet the moment. How did we get here? Join quaddi & r3plicant, two physician hackers and amateur wonks as they take you through a cyber policy autopsy - diagnosing the decisions and dilemmas that have resulted in this current crisis. From a diseased culture of secrecy predicated on a willful misunderstanding of privacy regulation to outdated national response and recovery frameworks, this talk will explore how policy choices made at the dawn of medicine’s digitization have aged poorly in an era of health system consolidation, single point of failure dependencies, and a rabid push to integrate AI into everything from thermometers to transplant surgery. The prognosis isn’t all dire. From a revitalized HIPAA to bipartisan bills to resuscitate rural hospitals, a policy prescription exists to better protect patients and secure systems. It’s time to take your medicine.

\n\nSpeakers:Christian Dameff,Jeff \"r3plicant\" Tully
\n
\nSpeakerBio:  Christian Dameff, UC San Diego Center for Healthcare Cybersecurity
\n

Christian (quaddi) Dameff, MD is an ER doc and Associate Professor of Emergency Medicine, Biomedical Informatics, and Computer Science (Affiliate) at the University of California San Diego, where he also co-directs the Center for Healthcare Cybersecurity. He is a hacker, former open capture the flag champion, and prior DEF CON/RSA/Blackhat/HIMSS Speaker. He previously has testified in front of the U.S. Congress and U.S. Food and Drug Administration.

\n\nSpeakerBio:  Jeff \"r3plicant\" Tully, UC San Diego Center for Healthcare Cybersecurity
\n

Jeff (r3plicant) Tully, MD is a security researcher with an interest in understanding the ever-growing intersections between healthcare and technology. His research has been highlighted in international media, leading academic medical journals and cease and desist letters sent on behalf of billion-dollar cybersecurity corporations. As an elected member of the Health Sector Coordinating Council Cyber Working Group’s Executive Committee he regularly engages with policymakers and other federal healthcare cybersecurity stakeholders. During his day job as an anesthesiologist, he focuses primarily on the delivery of oxygen to tissues.

\n\n\n\'',NULL,1294349),('2_Friday','12','12:00','12:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Election Security in the Age of AI: Governance, Trust, and the Systems Behind Democracy\'','\'Lester Godsey,William Gates,Tim Harper\'','Creator Talks_a4c88e5c1a02a4d92d3425b82be1488e','\'Title: Election Security in the Age of AI: Governance, Trust, and the Systems Behind Democracy
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

Election security is often framed as a technology problem. In reality, it’s a governance problem operating inside a highly stressed public system. This session brings together leaders who were inside that system during the most scrutinized election cycles in modern U.S. history, moderated by an elections policy expert who has shaped how platforms handle political content at global scale. Tim Harper, Project Lead for Elections and Democracy at the Center for Technology and Democracy and former Content Policy Associate Manager for Political Advertising at Meta, will moderate. His work focuses on combating election disinformation, strengthening election integrity, and building public trust. Lester Godsey served as CISO for Maricopa County during the 2020 and 2024 presidential elections, leading cybersecurity in a jurisdiction under intense national scrutiny and multiple adversaries. Bill Gates served on the Maricopa County Board of Supervisors during that same period, overseeing election administration amid unprecedented political pressure, misinformation and reputational and physical threats. He now directs the Mechanics for Democracy Laboratory at Arizona State University. Together, they bring a rare perspective: cybersecurity, governance, and systems engineering at the front lines of democracy.

\n\nSpeakers:Lester Godsey,William Gates,Tim Harper
\n
\nSpeakerBio:  Lester Godsey, Arizona State University
\n

Lester Godsey serves as the Chief Information Security Officer (CISO) for Arizona State University, the largest public university by enrollment in the United States. His appointment follows a distinguished five-year tenure as CISO for Maricopa County, where he skillfully managed information security during one of the most contentious election periods in the county\'s modern history.\nWith over 30 years of public-sector IT experience, Lester is a respected voice in the field, having presented at local, state, and national levels on a diverse range of topics including telecommunications, data management, and cybersecurity.\nA lifelong learner and educator, Lester holds multiple industry certifications including PMP, CISM, and CISSP. He has shared his expertise as a collegiate instructor for almost fifteen years, teaching cybersecurity, technology, and project management courses. Lester is also a published author and actively contributes to the cybersecurity community.\nHis academic background uniquely blends the arts and technology, holding both a Bachelor of Arts in Music and a Master of Science in Technology from Arizona State University. This multidisciplinary foundation informs his innovative approach to information security leadership.

\n\nSpeakerBio:  William Gates, Arizona State University
\n

Bill Gates is Executive Director of the ASU Mechanics of Democracy Laboratory (MODL) and Professor of Practice at Arizona State University’s Watts College of Public Service and Community Solutions. He leads MODL’s efforts to professionalize election administration through practitioner-focused training, transparency initiatives, and the integration of emerging technologies. In 2025, he launched the AI + Elections Clinic to equip election officials nationwide with the tools and expertise to responsibly harness artificial intelligence in support of voter confidence and election integrity.

\n\n

Bill previously served two terms on the Maricopa County Board of Supervisors (2017–2024), overseeing elections in one of the nation’s largest voting jurisdictions during the highly scrutinized 2020 and 2022 election cycles. He also served on the Phoenix City Council (2009–2016), including as Vice Mayor.

\n\n

Bill is the recipient of various awards, commending his years of leadership, service, and defense of democracy including The American Bar Association’s Unsung Hero of Democracy Award in 2024, The Truman Foundation’s Joseph E. Stevens Public Service Award in 2022, The Arizona Republic’s 2021 Arizonan of the Year, and The Phoenix Business Journal’s Forty Under 40 in 2010.

\n\nSpeakerBio:  Tim Harper, Center for Technology and Democracy
\n

Tim Harper is Project Lead for Elections and Democracy, where he leads efforts to combat election disinformation, support secure voting technologies, and strengthen public trust in elections.\nAn elections policy expert, Tim has driven policy and advocacy across industry and civil society. Most recently, he served as Content Policy Associate Manager for Political Advertising at Meta, where he developed and implemented global policies governing electoral, political, and social issue advertising. His work focused on transparency, preventing foreign interference, and countering election delegitimization at scale.\nPreviously, Tim was Senior Elections Policy Analyst at the Bipartisan Policy Center, where he led election administration policy development and federal and state advocacy efforts. He convened a bipartisan task force of election officials to inform policymaking and led major data-driven research initiatives, including the largest national study on voting line disparities.\nHe began his career supporting election management bodies in the Middle East and North Africa with the International Foundation for Electoral Systems. He graduated magna cum laude from Gonzaga University with degrees in Political Science and History.

\n\n\n\'',NULL,1294350),('2_Friday','13','13:00','13:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'The Cyber Crystal Ball: The Annual Policy @ DEF CON Contingencies Survey\'','\'Matthew Wein,Bruce Schneier,Chris Painter,Heather West\'','Creator Talks_d9ff319589bd5886daf945412bd9809b','\'Title: The Cyber Crystal Ball: The Annual Policy @ DEF CON Contingencies Survey
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

Starting at DEF CON 33 Policy @ DEF CON shared the results of experts predictions regarding a range of cyber contingencies. With a year under out belts we can take a look at how the experts did with their prognostication last year, and look forward towards potential outcomes in the coming year. We will compare answers from year to year, and we\'ve added a few new questions along with expanding the roster of expert respondents. The panel discussion with experts will explore how the outcomes of cyber contingencies will affect geopolitics between now and DEF CON 35.

\n\nSpeakers:Matthew Wein,Bruce Schneier,Chris Painter,Heather West
\n
\nSpeakerBio:  Matthew Wein, Policy @ DEF CON
\n

Matthew is a national security policy expert with over 15 years of experience in the Executive and Legislative branches of government and the private sector. This is his second year producing the DEF CON Contingencies Survey.

\n\nSpeakerBio:  Bruce Schneier, Advisory Board Member at VerifiedVoting.org
\n

Bruce Schneier is an internationally renowned security technologist, called a “security guru” by the Economist. He is the New York Times best-selling author of 14 books – including Rewiring Democracy and A Hacker’s Mind -- as well as hundreds of articles, essays, and academic papers. His long-running newsletter and blog, “Schneier on Security,” is one of the most popular sources of cybersecurity news on the internet. Schneier is a Fellow and Lecturer in Public Policy at the Harvard Kennedy School and the Munk School at the University of Toronto. He is a fellow at the Berkman-Klein Center for Internet and Society at Harvard University, a board member of the Electronic Frontier Foundation and AccessNow, and an advisory board member of EPIC and VerifiedVoting.org. He is also the Chief of Security Architecture at Inrupt, Inc.

\n\nSpeakerBio:  Chris Painter
\n

Christopher Painter is a globally recognized leader on cyber policy, cyber diplomacy, cybersecurity and combatting cybercrime. He has been at the vanguard of cyber issues for over 30 years, first as a federal prosecutor handling some of the most high-profile cyber cases in the U.S., then as a senior official at the U.S. Department of Justice, the FBI, the White House National Security Council and, finally, as the world’s first cyber diplomat at the U.S. Department of State. Among many other things, Chris is currently a Founding Partner of The Cyber Policy Group.

\n\nSpeakerBio:  Heather West, Eurasia Group
\n

Heather West is a policy and tech translator, product consultant, and long-term digital strategist guiding the intersection of emerging technologies, culture, governments, and policy. Equipped with degrees in both computer and cognitive science, Heather focuses on data governance, data security, artificial intelligence (AI), and privacy in the digital age. She is a subject matter authority who has written extensively about AI and other data driven topics for over a decade. She is also a member of the Washington Post\'s The Network, a group of high-level digital security experts selected to weigh in on pressing cybersecurity issues.

\n\n\n\'',NULL,1294351),('2_Friday','14','14:00','15:30','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Strengthening the CVE Ecosystem (Seating is limited to 50 Participants)\'','\'John Banghart,Elizabeth Eigner,Lisa Olsen,Lindsey Cerkovnik\'','Creator Talks_deb70816e69b516e5f1bb4c60e0da4f7','\'Title: Strengthening the CVE Ecosystem (Seating is limited to 50 Participants)
\nTags: Policy @ DEF CON | Creator Interactive Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 15:30 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

CVE is core infrastructure for vulnerability management, but it’s under real strain. The volume and complexity of vulnerabilities keep rising, while the systems, tooling, and coordination models behind CVE haven’t kept pace. This was true prior to the extensive use of AI to identify vulnerabilities and has only grown more acute. At the same time, governments and industry are relying on CVE data more than ever to drive security decisions, and there are concerns about whether current funding models are sustainable. This roundtable brings together the people who actually work with CVE (researchers, open-source maintainers, vendors, and policymakers) to talk frankly about what’s breaking and what needs to change. We’ll focus on three areas: gaps in CVE data and infrastructure, where automation and AI can realistically help, and how to build sustainable public-private support for the ecosystem - all with the goal of identifying concrete policy steps that could improve CVE over the next 12-24 months. This discussion would feed into a policy paper making recommendations for policymakers, published by the Center for Cybersecurity Policy and Law.

\n\n

Seating is limited to the first 50 participants in order to facilitate interactive discussion.

\n\nSpeakers:John Banghart,Elizabeth Eigner,Lisa Olsen,Lindsey Cerkovnik
\n
\nSpeakerBio:  John Banghart, Center for Cybersecurity Policy & Law
\n

John Banghart leverages his significant federal government and private sector experience in cybersecurity to navigate issues related to risk management, government policy, standards and regulatory compliance, and incident management. He has successfully led efforts to address significant and high-profile cybersecurity issues within major government programs and institutions while facing complex legal, technical, and political circumstances. From 2013 to 2015, John played a key role in developing the Obama administration\'s cybersecurity and technology policy as the National Security Council\'s director for federal cybersecurity. He led policy, technical, and process efforts to reduce cybersecurity risk and improve metrics and measurement for all civilian, military, and intelligence community agencies. He served as a primary advisor on cybersecurity incidents and preparedness and led the National Security Council’s efforts to address significant cybersecurity incidents, including those at OPM and the White House, among others. He also spent several years at the National Institute of Standards and Technology (NIST), both as a cybersecurity researcher and in the Office of the Undersecretary of Commerce for Standards and Technology. John also worked as a senior cybersecurity advisor for the Centers for Medicare and Medicaid Services, providing leadership to the cybersecurity preparations for the Healthcare.gov website.

\n\nSpeakerBio:  Elizabeth Eigner, Microsoft
\n

Elizabeth Eigner is a Senior Manager on Microsoft’s Global Cybersecurity Policy team, where she leads Microsoft\'s vulnerability policy portfolio, overseeing efforts to develop and implement strategies that address vulnerability management both in the United States and globally. She represents Microsoft on the Hacking Policy Council, where she works collaboratively with industry leaders and policymakers to advance responsible cybersecurity and strengthen the frameworks that underpin software security worldwide. Elizabeth also leads initiatives aimed at creating and enhancing national cyber strategies in countries around the world. She works closely with governments and stakeholders to strengthen policy frameworks and promote resilient cybersecurity practices globally. Elizabeth also leads Microsoft\'s Advancing Regional Cybersecurity (ARC) initiative, focusing on improving incident response capabilities and cyber capacity building in the Global South. Previously, she served as Microsoft’s representative on the Cloud Service Provider Advisory Board (CSP-AB), contributing to FedRAMP public policy discussions and best practices for cloud security. Before joining Microsoft, Elizabeth worked at The Washington Technology Industry Association to enhance Washington State\'s innovation ecosystem. At MIT Solve, she collaborated with tech-based social entrepreneurs on solutions fostering digital inclusion and equitable economic opportunity. She holds a B.S. in Political Science from Northeastern University, with concentrations in Law and International Security.

\n\nSpeakerBio:  Lisa Olsen, Principal Security Release Program Manager at Microsoft
\n

Lisa Olson is a Principal Security Release Program Manager at Microsoft, where she has led the Patch Tuesday release process since 2013. A member of the CVE Board since 2018, Lisa is a passionate advocate for improving vulnerability communication through automation and machine-readable formats. Her work focuses on transforming how security information is shared to help organizations respond faster and more effectively.

\n\nSpeakerBio:  Lindsey Cerkovnik, CISA
\n

Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure (CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.

\n\n\n\'',NULL,1294352),('2_Friday','15','14:00','15:30','Y','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Strengthening the CVE Ecosystem (Seating is limited to 50 Participants)\'','\'John Banghart,Elizabeth Eigner,Lisa Olsen,Lindsey Cerkovnik\'','Creator Talks_deb70816e69b516e5f1bb4c60e0da4f7','\'\'',NULL,1294353),('2_Friday','15','15:30','16:30','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'When AI Finds Everything: Vulnerability Policy for the Coming Discovery Surge\'','\'Alec Summers,Lindsey Cerkovnik,Madison Ficorelli\'','Creator Talks_ead44cda5a859fc81b95bce2d05a9248','\'Title: When AI Finds Everything: Vulnerability Policy for the Coming Discovery Surge
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

AI-enabled vulnerability discovery is moving from novelty to inevitability. As frontier systems become better at finding, validating, and reporting vulnerabilities at scale, the ecosystem will face a basic policy question: what happens when discovery accelerates faster than coordination, triage, remediation, prioritization, and response can absorb? This talk examines the policy and operational implications of a world where vulnerability discovery becomes cheaper, faster, and more automated. Using CVE, CWE, CNA operations, and CISA’s vulnerability management mission as grounding examples, we will explore how current processes may strain under higher volume, probabilistic findings, duplicate reports, inconsistent quality, and incomplete downstream impact context. The talk will not argue that AI breaks vulnerability management. Instead, it argues that AI magnifies existing gaps across the software development lifecycle and incident response ecosystem: unclear responsibility, uneven data quality, insufficient automation, fragile public-good infrastructure, and policy models that often assume human-scale discovery, reporting, and response. We will discuss what policymakers, program stewards, hackers, vendors, software producers, defenders, and infrastructure operators should do now to prepare for the next era of vulnerab

\n\nSpeakers:Alec Summers,Lindsey Cerkovnik,Madison Ficorelli
\n
\nSpeakerBio:  Alec Summers, The MITRE Corporation
\n

Alec Summers is a principal cybersecurity engineer at the MITRE Corporation with diverse and extensive experience in software assurance and vulnerability management, as well as cyber operations, assessments, and supply chain risk management. He is the MITRE CVE and CWE Project Leader, managing teams that support vulnerability and weakness research & analysis, content production, program coordination, services development, and community engagement across a global partner base comprising industry, government, and academia. He serves as the moderator for the CVE Board and CWE Board.

\n\nSpeakerBio:  Lindsey Cerkovnik, CISA
\n

Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure (CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.

\n\nSpeakerBio:  Madison Ficorelli
\n

Madison Ficorilli is a vulnerability transparency advocate and staff security manager at GitHub, leading the advisory database curation team. She is passionate about vulnerability reporting, response, and disclosure, and co-chairs the relevant Open Source Security Foundation (OpenSSF) working group and serves on the CVE Program Board. Her views are enriched by her prior experience as a product incident response analyst at GitHub and as a vulnerability coordinator at the CERT Coordination Center at the Software Engineering Institute at Carnegie Mellon University.

\n\n\n\'',NULL,1294354),('2_Friday','16','15:30','16:30','Y','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'When AI Finds Everything: Vulnerability Policy for the Coming Discovery Surge\'','\'Alec Summers,Lindsey Cerkovnik,Madison Ficorelli\'','Creator Talks_ead44cda5a859fc81b95bce2d05a9248','\'\'',NULL,1294355),('2_Friday','16','16:30','17:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Filibuffer Overflow: Hackers Stage A Congressional Hearing\'','\'Katherine Pratt,Jeff Rothblum,Maurice Turner,Ayan Islam,Beau Woods\'','Creator Talks_e84680a3ae64075f785dbcbfe8bf8258','\'Title: Filibuffer Overflow: Hackers Stage A Congressional Hearing
\nTags: Policy @ DEF CON | Creator Interactive Talk/Panel
\nWhen: Friday, Aug 7, 16:30 - 17:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n\n\nSpeakers:Katherine Pratt,Jeff Rothblum,Maurice Turner,Ayan Islam,Beau Woods
\n
\nSpeakerBio:  Katherine Pratt, Microsoft
\n

Katherine Pratt is a senior security engineer and operator on the AI Red Team at Microsoft. She received her B.S. in aerospace engineering from MIT in 2008. Following graduation, she served four years in the United States Air Force, spending most of her time as an operational flight test engineer on the F-35 Joint Strike Fighter. She received a PhD in Electrical and Computer Engineering from the University of Washington in 2019, where she studied the privacy, ethics, and policy of neural data. Her professional work experience includes Blue Origin, the ACLU of Washington, and a fellowship through TechCongress working on technology policy in the US House of Representatives. She also competes in triathlons and is the co-founder of the 501(c)3 Minority Veterans of America.

\n\nSpeakerBio:  Jeff Rothblum, Founder at Plaintext Strategies
\n

Jeff Rothblum, founder of Plaintext Strategies, has worked at the intersection of technology and policy for two decades. He has led government affairs at an AI startup, served as a cyber threat intelligence analyst, led cybersecurity policy the Senate Homeland Security and Governmental Affairs Committee, served as a Director of Cyber Policy and Plans at the White House Office of the National Cyber Director, and co-owned an artisan blacksmithing company.

\n\nSpeakerBio:  Maurice Turner
\n

Maurice Turner is a recognized public interest technologist and cybersecurity expert on the Public Policy team at TikTok. As a Technical Policy Lead, Turner plays a key role as a liaison collaborating between public policy and cross-functional teams to ensure understanding of cutting-edge technologies by non-technical audiences. He also advises the broader Americas public policy team on a wide range of technology, strategy, and policy issues.

\n\nSpeakerBio:  Ayan Islam
\n

Ayan Islam is an Adjunct Lecturer at American University School of Public Affairs\' Cybersecurity Policy and Management program and cyber risk specialist at a Fortune 500 FinTech company. As former White House Director of Cyber Workforce, she served at the Office of National Cyber Director (ONCD) supporting the development and implementation of the National Cyber Workforce and Education Strategy. Previously, she was the Associate Policy Director for R Street\'s Cybersecurity and Emerging Threats team and contributed to special initiatives at the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA).

\n\nSpeakerBio:  Beau Woods
\nNo BIO available
\n\n\'',NULL,1294356),('2_Friday','17','16:30','17:59','Y','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Filibuffer Overflow: Hackers Stage A Congressional Hearing\'','\'Katherine Pratt,Jeff Rothblum,Maurice Turner,Ayan Islam,Beau Woods\'','Creator Talks_e84680a3ae64075f785dbcbfe8bf8258','\'\'',NULL,1294357),('3_Saturday','10','10:00','10:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Journey to Create an All-state Cybersecurity Plan for Oklahoma\'','\'Craig \"jafo\" Buchanan\'','Creator Talks_127443959d9589f91dc06e35e9514e08','\'Title: Journey to Create an All-state Cybersecurity Plan for Oklahoma
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

This talk will go over the challenges and successes that the State of Oklahoma had in creating an all-of-state cybersecurity plan. It will also offer insights into how we leveraged the State Local Cybersecurity Grants to help shore up defenses in state and local agencies. Finally, I will share personal insights as a grant recipient and what it looks like from the end-user perspective.

\n\nSpeakerBio:  Craig \"jafo\" Buchanan, City of Stillwater Oklahoma
\n

Craig Buchanan has worked in government at the city, state, and federal levels. In addition, he worked for over a decade at computer multimedia innovator Creative Labs Inc. He currently works for the city of Stillwater Oklahoma as the security administrator, where his duties include installing and maintaining the city\'s ever-growing fleet of security cameras, servers, and monitoring devices as well as serving as a professor at Northern Oklahoma College. In his spare time, he volunteers for the American Red Cross doing fraud reviews and serves on the state of Oklahoma’s State Local Cybersecurity Grant committee.

\n\n\n\'',NULL,1294358),('3_Saturday','11','11:00','11:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'From Policy to Prod: How a Frontier AI Lab Enforces its Cyber Rules\'','\'Grant Versfeld,David \"0xdf\" Forsythe\'','Creator Talks_53f26ad00ed802d8f4e1949919dbf913','\'Title: From Policy to Prod: How a Frontier AI Lab Enforces its Cyber Rules
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

Every frontier AI lab publishes policies, but far less is known about what happens between a line in that policy and a blocked request in production. On Anthropic’s safeguards team, we operate in that gap. In this talk, we’ll walk through the full enforcement lifecycle at Anthropic: how policy gets written, how we translate it into evals that actually measure the behavior we care about, how we build precision-tuned classifiers to detect misuse traffic at scale, and how those classifiers feed a layered enforcement stack. We\'ll share what\'s worked, what hasn\'t, and the open problems we think the policy community should be paying attention to.

\n\nSpeakers:Grant Versfeld,David \"0xdf\" Forsythe
\n
\nSpeakerBio:  Grant Versfeld, Anthropic
\n

Grant Versfeld co-leads cyber enforcement on Anthropic\'s Safeguards team, where he bridges the Policy and Threat Intelligence teams to disrupt cyber threat actors. Before Anthropic, he was a security engineer for Google Cloud Threat Intelligence, investigating nation-state campaigns against Cloud customers, contributing to Google Cloud\'s Threat Horizons report, and supporting Mandiant\'s cyber espionage research. He is a former Cybersecurity Policy Fellow at the Center for Democracy & Technology, a Hackers on the Hill ambassador, and a judge for Atlantic Council\'s Cyber 9/12 competition. He returns to DEF CON having previously played the FBI agent in DC 31\'s Hacker Court.

\n\nSpeakerBio:  David \"0xdf\" Forsythe, Anthropic
\n

David Forsythe (0xdf) is a member of technical staff at Anthropic working on cybersecurity strategy and safeguards for frontier AI. Before that, 20+ years across the US public and private sectors in SOC/CIRT, threat intelligence, red teaming, threat research, and education, most recently as Principal Lab Architect at HackTheBox.

\n\n

He is also a long-running security content creator, publishing CTF walkthroughs and technical breakdowns of exploits and other security topics at 0xdf.gitlab.io and on YouTube. As a player, he has reached as high as 4th on the HackTheBox global leaderboard, is a two-time Best Overall winner of the SANS Holiday Hack Challenge, and a three-time SANS Netwars Tournament of Champions team winner.

\n\n\n\'',NULL,1294359),('3_Saturday','12','12:00','12:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Europe’s Expanding Role in Global Vulnerability Management\'','\'Nuno Rodrigues Carvalho,Razvan Gavrila\'','Creator Talks_a05c1b2e90e50bd3fdc8cde35c36e258','\'Title: Europe’s Expanding Role in Global Vulnerability Management
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

The Common Vulnerabilities and Exposures (CVE) Program has become foundational to global cybersecurity operations. However, as vulnerability discovery accelerates and regulatory frameworks emerge, CVE is no longer just a technical reference system — it is evolving into critical infrastructure at the intersection of security and public policy. This talk presents ENISA’s operational and policy role in strengthening the global CVE ecosystem, including its designation as a CVE Numbering Authority and Root CNA, its development of the EU Vulnerability Database (EUVD), and its mandate under the Cyber Resilience Act to build a Single Reporting Platform for vulnerability coordination across Europe. Moreover, the talk will explain how ENISA plans to operationalize the collected data to strengthen the overall security ecosystem. The session will explore how policy decision at EU level impact vulnerability disclosure, coordination, and data quality — and how Europe is scaling its role without fragmenting the global system. The goal is to provide a practical, but both strategic and operational perspective on how the EU’s increased role in this area will ensure a more resilient and interoperable vulnerability ecosystem. (This talk will develop both talks held by ENISA at VulCon 2026)

\n\nSpeakers:Nuno Rodrigues Carvalho,Razvan Gavrila
\n
\nSpeakerBio:  Nuno Rodrigues Carvalho, ENISA - The European Union Agency for Cybersecurity
\n

Nuno Rodrigues Carvalho currently serves as Head of Sector of the Incident & Vulnerabilities Services within the Operations and Situational Awareness Unit (OSA) of the European Union Agency for Cybersecurity (ENISA). He leads the department in ENISA dealing with the development of Vulnerability Services (including the European Union Vulnerability Database), of the Single Reporting Platform of the Cyber Resilience Act and the Cybersecurity Incident Reporting and Analysis System (CIRAS) and the reports stemming from the NIS 2 legislation related to that system. Before joining ENISA as a Senior Threat and Vulnerability Analyst, he developed more than 15 years of experience in strategic, tactical, and operational analysis and situational awareness through roles at both national and international levels. Previously, he also worked at the European Parliament and in the banking sector.

\n\nSpeakerBio:  Razvan Gavrila, ENISA - The European Union Agency for Cybersecurity
\n

Razvan Gavrila is a seasoned cybersecurity professional with over 15 years of experience across national and EU institutions. In his current role, he oversees ENISA’s work on the implementation of the EU Cyber Resilience Act and leads initiatives in product and security engineering, including the cybersecurity of AI systems. Prior to his appointment as Head of Sector for Market, Technology, and Product Security in January 2025, he served as ENISA’s lead Cyber Threat Intelligence (CTI) analyst. He holds several industry-recognized certifications and a Master of Science in Computer and Information Security

\n\n\n\'',NULL,1294360),('3_Saturday','13','13:00','13:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Surprise Session - Check Hacker Tracker\'','\'\'','Creator Talks_94f50be7efbec29742791f11b434a464','\'Title: Surprise Session - Check Hacker Tracker
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1294361),('3_Saturday','14','14:00','14:30','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'The best of three bad ideas? Ransomware taxes in lieu of bans or doing nothing\'','\'Joe Uchill\'','Creator Talks_d4ef364117844d1b147d7e7a5159b4b4','\'Title: The best of three bad ideas? Ransomware taxes in lieu of bans or doing nothing
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

A common proposal to disrupt ransomware operations is to institute a ban on ransomware payments. That risks several unwanted effects including prolonged critical infrastructure outages, a feeling of revictimization, non-compliant payers being extorted over paying. This talk investigates the potential for a middle ground: A ransomware tax.

\n\nSpeakerBio:  Joe Uchill
\n

Joe Uchill is a PhD student in public policy at RAND Graduate School. Until recently, he was a reporter covering cybersecurity for outlets like Axios and The Hill.

\n\n\n\'',NULL,1294362),('3_Saturday','14','14:30','15:30','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'From Disclosure to Defense: Rebuilding Vulnerability Management for the AI Era\'','\'Lindsey Cerkovnik,John Banghart,Ben Flatgard,Elizabeth Eigner\'','Creator Talks_b8edfa56b2465ec3bc08f4269ff28997','\'Title: From Disclosure to Defense: Rebuilding Vulnerability Management for the AI Era
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 15:30 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

AI has upended vulnerability discovery. What used to be scarce is now abundant: vulnerabilities can be found faster, at greater scale, and across more systems than ever before. Systems that uplevel vuln hunters are becoming widely available, to both defenders and malicious actors. Finding vulnerabilities used to be the hard part - but it’s not anymore, and we need to adapt the vulnerability ecosystem to reflect that. But vulnerability management - thoughtful and methodical disclosure, triage, patching, and policy - still operates on assumptions of scarcity. That mismatch is becoming dangerous. If AI makes vulnerability discovery effectively infinite, what does a safe, scalable system for handling them actually look like? This panel will discuss how the vulnerability needs to evolve to match the moment. Current policy approaches - especially those mandating rapid reporting or broad sharing of unmitigated vulnerabilities - risk making systems less secure in an AI-driven environment. At the same time, rapid response by defenders is critical, and resources are scarce. Disclosure models need to evolve, governments need to support defenders, and incentives must align to ensure that AI-driven discovery strengthens security.

\n\nSpeakers:Lindsey Cerkovnik,John Banghart,Ben Flatgard,Elizabeth Eigner
\n
\nSpeakerBio:  Lindsey Cerkovnik, CISA
\n

Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure (CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.

\n\nSpeakerBio:  John Banghart, Center for Cybersecurity Policy & Law
\n

John Banghart leverages his significant federal government and private sector experience in cybersecurity to navigate issues related to risk management, government policy, standards and regulatory compliance, and incident management. He has successfully led efforts to address significant and high-profile cybersecurity issues within major government programs and institutions while facing complex legal, technical, and political circumstances. From 2013 to 2015, John played a key role in developing the Obama administration\'s cybersecurity and technology policy as the National Security Council\'s director for federal cybersecurity. He led policy, technical, and process efforts to reduce cybersecurity risk and improve metrics and measurement for all civilian, military, and intelligence community agencies. He served as a primary advisor on cybersecurity incidents and preparedness and led the National Security Council’s efforts to address significant cybersecurity incidents, including those at OPM and the White House, among others. He also spent several years at the National Institute of Standards and Technology (NIST), both as a cybersecurity researcher and in the Office of the Undersecretary of Commerce for Standards and Technology. John also worked as a senior cybersecurity advisor for the Centers for Medicare and Medicaid Services, providing leadership to the cybersecurity preparations for the Healthcare.gov website.

\n\nSpeakerBio:  Ben Flatgard, JPMorgan Chase
\n

Ben Flatgard is an Executive Director with JPMorgan Chase Co. He leads public policy development and advocacy, as well as partnership initiatives, to improve the cybersecurity of the firm, its customers and clients, and the broader digital ecosystem. Ben previously served in the Obama Administration from 2009-2017. In his most recent post as Director for Cybersecurity Policy on the National Security Council, Ben was responsible for leading cybersecurity policy development related to protection of critical infrastructure and emerging technologies. Before joining the National Security Council, Ben served as Senior Advisor to the Assistant Secretary of the Treasury for Financial Institutions. Prior to his time at Treasury, Ben held positions at the Department of Commerce and the White House. Ben graduated from the University of Edinburgh. He holds fellowships at the Atlantic Council in Washington, DC, and at the University of Sydney.

\n\nSpeakerBio:  Elizabeth Eigner, Microsoft
\n

Elizabeth Eigner is a Senior Manager on Microsoft’s Global Cybersecurity Policy team, where she leads Microsoft\'s vulnerability policy portfolio, overseeing efforts to develop and implement strategies that address vulnerability management both in the United States and globally. She represents Microsoft on the Hacking Policy Council, where she works collaboratively with industry leaders and policymakers to advance responsible cybersecurity and strengthen the frameworks that underpin software security worldwide. Elizabeth also leads initiatives aimed at creating and enhancing national cyber strategies in countries around the world. She works closely with governments and stakeholders to strengthen policy frameworks and promote resilient cybersecurity practices globally. Elizabeth also leads Microsoft\'s Advancing Regional Cybersecurity (ARC) initiative, focusing on improving incident response capabilities and cyber capacity building in the Global South. Previously, she served as Microsoft’s representative on the Cloud Service Provider Advisory Board (CSP-AB), contributing to FedRAMP public policy discussions and best practices for cloud security. Before joining Microsoft, Elizabeth worked at The Washington Technology Industry Association to enhance Washington State\'s innovation ecosystem. At MIT Solve, she collaborated with tech-based social entrepreneurs on solutions fostering digital inclusion and equitable economic opportunity. She holds a B.S. in Political Science from Northeastern University, with concentrations in Law and International Security.

\n\n\n\'',NULL,1294363),('3_Saturday','15','14:30','15:30','Y','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'From Disclosure to Defense: Rebuilding Vulnerability Management for the AI Era\'','\'Lindsey Cerkovnik,John Banghart,Ben Flatgard,Elizabeth Eigner\'','Creator Talks_b8edfa56b2465ec3bc08f4269ff28997','\'\'',NULL,1294364),('3_Saturday','15','15:30','15:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Assume Breach, But For Real: Rewriting Infrastructure Policy for the Adversaries Who Never Left\'','\'Travis Berent,Adam Hickey\'','Creator Talks_218e5db5b3404ae56dc4790f20ff72b7','\'Title: Assume Breach, But For Real: Rewriting Infrastructure Policy for the Adversaries Who Never Left
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

An energy provider detects an intrusion when a control-room operator notices an unexplained setpoint change not an alert. Initial access occurred ninety days earlier via a contractor credential that outlived contract. Disclosure clocks are already running. Scope is unknown. Systems cannot go offline. This reflects recurring patterns Microsoft incident response teams observe across critical infrastructure, patterns policy was not designed around today. Cyber policy assumes breaches are detectable in reasonable timeframes, attributable with confidence, and containable once identified. Incident response shows otherwise. PRC state-sponsored actors such as Volt Typhoon maintain persistent, low-visibility access using valid credentials and living-off-the-land techniques. Detection often lags weeks or months, triggered by operational impact rather than telemetry. Investigations unfold under live operations, incomplete visibility, and uncertain scope, while disclosure timelines under CIRCIA, SEC rules, NIS2, and similar frameworks continue to run. This session bridges incident response and policy design, drawing on CI cases, DOJ experience, crisis counsel to show where assumptions break and how policy can align to conditions: identity-driven intrusion, persistent access, IT-OT convergence, and decisions under uncertainty.

\n\nSpeakers:Travis Berent,Adam Hickey
\n
\nSpeakerBio:  Travis Berent, Microsoft
\n

Travis Berent is the Director of Security Business Strategy at Microsoft, where he helps shape the company’s approach to incident response, resilience, and cybersecurity partnerships. Prior to joining Microsoft, Travis served as Director for Cybersecurity Policy and Incident Response at the National Security Council, where he strengthened U.S. defense and intelligence environments, oversaw response to significant cyber incidents affecting critical infrastructure and government networks, and led key processes including the Vulnerabilities Equities Process. He also helped develop national policy responses to ransomware and contributed to both the National Security Strategy and National Cyber Strategy. Earlier in his career, Travis served in multiple roles at the Federal Bureau of Investigation (FBI), including in the New York Field Office and at Cyber Division Headquarters, where he worked on counterintelligence and cyber matters.

\n\nSpeakerBio:  Adam Hickey, Mayer Brown
\n

Adam Hickey offers clients extensive experience in cybersecurity and national security matters. Adam draws on more than 15 years of experience at the U.S. Department of Justice (DOJ) handling high-profile national security matters intersecting with the private sector. Prior to joining Mayer Brown, he was a Deputy Assistant Attorney General (DAAG) of DOJ’s National Security Division (NSD). During his time at NSD, Adam established DOJ’s national security cyber program, dedicated to combatting malicious cyber activity by foreign intelligence services affecting major companies and critical infrastructure, and he supervised the criminal investigation and charging of every such case for more than a decade. He now advises critical infrastructure and OT operators on incident response, privileged investigations, disclosure, regulatory requirements across borders, and enforcement actions.

\n\n\n\'',NULL,1294365),('3_Saturday','16','16:00','16:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Securing the Safety Net: Why Healthcare Cybersecurity Policy Keeps Failing Patients\'','\'Sahan Fernando,James Bowie,Nancy Brainerd,Phil Englert\'','Creator Talks_18fd4099db9745b4a20a3f233b2146bc','\'Title: Securing the Safety Net: Why Healthcare Cybersecurity Policy Keeps Failing Patients
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

In 2024, ransomware at Change Healthcare didn’t just hit one company—it jammed up claims and eligibility checks across the country, squeezed provider cash flow, and made something painfully clear: you can’t regulate your way to security when the business model starves defenders of time, staff, and budget. This panel brings two hospital CISOs, a medical device manufacturer’s head of product security, and a healthcare policy advocate to talk about the failures that today’s policy stack—the HIPAA Security Rule overhaul, HHS Cybersecurity Performance Goals, and proposed CMS conditions of participation—still won’t fix. We’ll unpack the reimbursement trap (thin margins → underinvestment → incidents → thinner margins → unfunded mandates), why devices with decade-long lifecycles end up living forever in clinical environments, and how vendor concentration turns “third-party risk” into systemic risk. This won’t be four people nodding. Each panelist will put one concrete intervention on the table—reimbursement-linked incentives, meaningful safe-harbor protections, and supply-chain transparency requirements—then we’ll pressure-test the tradeoffs. If you want to understand why healthcare keeps getting owned despite “critical infrastructure” status, and what policy could change the incentive landscape, come argue with us.

\n\nSpeakers:Sahan Fernando,James Bowie,Nancy Brainerd,Phil Englert
\n
\nSpeakerBio:  Sahan Fernando, Rady Children\'s Health
\n

Sahan Fernando is the Chief Information Security Officer for Rady Children’s Hospital San Diego, one of the nation’s top pediatric health care systems. His experience includes security operations and engineering, incident response, and IT and Information Security Program Development in different verticals. He has spoken at multiple security conferences including Cyphercon, SO-CON, Bsides CLT, Health-ISAC, Blue Team Con, and Epic XGM/XGM. He also serves on the board for Health-ISAC.

\n\nSpeakerBio:  James Bowie, Tampa General Hospital
\n

Jim Bowie is Vice President and Chief Information Security Officer (CISO) at Florida Health Science Center, Inc., responsible for cybersecurity strategy, risk management, and operational defense across FHSC and its affiliated entities. Prior to joining FHSC, he served as Director of Cyber Operations at Moffitt Cancer Center. He has also held multiple roles at Tampa General, including Director of Infrastructure, Cyber Operations, and Clinical Applications Manager, bringing deep experience across clinical technology, operations, and security. Bowie previously worked in law enforcement with the Tampa Police Department, supporting cybersecurity and digital forensics investigations. He began his career in emergency medical services, including service as Director of Emory Emergency Medical Services, a volunteer EMS agency.\nBowie earned a master’s degree in Cybersecurity and Information Assurance and is currently pursuing a PhD in Cyber Defense along with a second master’s degree in Artificial Intelligence. He also holds a BA in History. He is accredited by the College of Healthcare Information Management Executives (CHIME) as a Certified Healthcare Information Security Leader (CHISL) and maintains several additional industry certifications.

\n\nSpeakerBio:  Nancy Brainerd, Medtronic
\n

Nancy Brainerd joined Medtronic in 2000 kicking off a career in Information Technology. In 2006, she began working within the information security field and had the opportunity to build out Medtronic’s first Cyber Defense organization, specializing in cybersecurity incident response. As scrutiny of cybersecurity of medical devices has increased, Nancy made the shift in 2023 to focus on security of Medtronic’s products. She is currently a Senior Director in the Product Security Office with oversight of cybersecurity of Medtronic devices and products. Nancy is active in the security industry and participates in many coordinated activities, including a current directorship on the board for Health-ISAC (Health Information Sharing and Analysis Center). She is a frequent guest lecturer at the University of Minnesota on the topic of Cybersecurity in the “Introduction to Information Technology in Business” undergraduate course.

\n\nSpeakerBio:  Phil Englert, Health-ISAC
\n

Phil Englert is the VP of Medical Device Security at Health ISAC, where he works with medical device manufacturers to strengthen privacy and security while partnering with healthcare delivery organizations to ensure those solutions are practical, deployable, and clinically aligned. He also defines long term vision, leads cross sector initiatives, advances best practices, and delivers programs that improve sector resilience and serves as a subject matter expert and contributor to Health ISAC’s Medical Device Security Council (MDSC). Phil leads Health ISAC’s strategy to strengthen cybersecurity and privacy across the global medical technology ecosystem. This role directs the organization’s medical device security program, partnering with manufacturers and healthcare delivery organizations to drive practical, secure implementations while shaping regulatory and standards. Phil oversees coordinated vulnerability disclosure efforts with researchers, regulators, and government agencies, and serves as a subject matter expert to the 500 member Medical Device Security Council.

\n\n\n\'',NULL,1294366),('3_Saturday','17','17:00','17:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'The Closing Window: Governing Agentic AI Security in a Post-Mythos World\'','\'Taylor Roberts,Mitch Herckis,Katie Trimble-Noble,Razvan Gavrila\'','Creator Talks_f1b8453f236f87605d7655c4255a9b43','\'Title: The Closing Window: Governing Agentic AI Security in a Post-Mythos World
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

Mythos changed the question. Agentic AI security tooling operating at production scale is no longer a research problem or a vendor concern, it is a governance emergency. The frameworks governments have built to manage cyber risk were not designed for systems that acquire credentials autonomously, execute decisions faster than any human authorisation loop, and integrate third-party components whose security provenance no procurement standard currently requires anyone to verify. This panel convenes policy practitioners from across the agentic AI security stack (cloud-native, endpoint, behavioural detection, and federal policy) to examine what governance must look like before agentic AI becomes irreversibly embedded across critical national infrastructure and government departments. Structured around five substantive policy topics with direct implications for US, UK, and EU regulatory frameworks, the session closes with concrete, jurisdictionally-grounded recommendations that government affairs professionals can act on, across CVE architecture, critical infrastructure designation, agent identity standards, incident reporting obligations, and procurement requirements, before the legislative windows currently open in all three jurisdictions close or retrofitting security becomes too costly.

\n\nSpeakers:Taylor Roberts,Mitch Herckis,Katie Trimble-Noble,Razvan Gavrila
\n
\nSpeakerBio:  Taylor Roberts, Zenity
\n

Taylor Roberts is a seasoned cyber and AI security policy expert with experience spanning academia, the US federal government, and the private sector, currently serving as Principal of AI Security Policy at Zenity. Previously the Global Director of Security and Trust Policy at Intel and a former Cybersecurity Advisor at the White House\'s Office of Management and Budget, Taylor works toward fostering collaboration with governments, industry, and standards organizations to strengthen the AI security cybersecurity ecosystem. He holds a Masters in International Affairs from UC San Diego.

\n\nSpeakerBio:  Mitch Herckis, Wiz
\n

Mitch Herckis has spent two decades working with and for the public sector on technology and security policy. Currently, Mitch serves as the Global Head of Government Affairs for Wiz, a cloud cybersecurity company. Prior to joining Wiz, Mitch served as Director of the Federal Cybersecurity Branch within the White House\'s Office of Management and Budget, where he led cybersecurity initiatives within the Office of the Federal Chief Information Officer, including implementation on the President\'s Executive Order on Improving the Nation\'s Cybersecurity. Before joining federal service, Mitch served as a Senior Advisor for New York City Cyber Command, facilitating security implementations across 100+ city agencies on behalf of the City’s central cybersecurity authority. He also spearheaded public initiatives to increase the digital security of City residents. Mitch has advocated for sound technology policies at all levels of government, including serving as the Director of Government Affairs for the National Association of State Chief Information Officers (NASCIO), and Senior Legislative Counsel for Federal Relations at the National League of Cities.

\n\nSpeakerBio:  Katie Trimble-Noble, Director, PSIRT and Bug Bounty
\n

Katie serves as a CVE Program Board, Bug Bounty Community of Interest Founder, and Hacking Policy Council Founding member. She is a passionate defensive cybersecurity community activist, she is regularly involved is community driven projects and is most happy when she is able to effect positive progress in cyber defense. In her day job Katie Noble serves as a Director of PSIRT, specializing in Global Secretarial Policy and Industry Engagement and Bug Bounty, at a fortune 50 Technology Company. Prior to joining private sector, Katie spent over 15 years in the US Government. Most recently as the Section Chief of Vulnerability Management and Coordination at the Department of Homeland Security, Cyber and Infrastructure Security Agency (CISA). Her team is credited with the coordination and public disclosure of 20,000+ cybersecurity vulnerabilities within a two-year period. During her government tenure, in roles spanning Intelligence Analyst for the National Intelligence Community to Senior Policy Advisor for White House led National Security Council Cyber programs, Katie’s work directly impacted decision making for government agencies in the United States, United Kingdom, Canada, and Australia.

\n\nSpeakerBio:  Razvan Gavrila, ENISA - The European Union Agency for Cybersecurity
\n

Razvan Gavrila is a seasoned cybersecurity professional with over 15 years of experience across national and EU institutions. In his current role, he oversees ENISA’s work on the implementation of the EU Cyber Resilience Act and leads initiatives in product and security engineering, including the cybersecurity of AI systems. Prior to his appointment as Head of Sector for Market, Technology, and Product Security in January 2025, he served as ENISA’s lead Cyber Threat Intelligence (CTI) analyst. He holds several industry-recognized certifications and a Master of Science in Computer and Information Security

\n\n\n\'',NULL,1294367),('4_Sunday','11','11:00','11:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Strategic Resistance: How a Global Network is Fighting the Spyware Industry -\'','\'Michael Brennan,Nadine Farid Johnson,Rebekah Brown\'','Creator Talks_078d277a9b2df53e232c7cdcd5f861d1','\'Title: Strategic Resistance: How a Global Network is Fighting the Spyware Industry -
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

For years, the commercial spyware industry – which sells software to hijack devices – has operated in a \"gray market\" with near-total impunity. That changed on February 26, 2026, when an Athens court sentenced executives of Intellexa to maximum prison terms – the first criminal conviction of spyware vendors. This was not an isolated event, but the result of a coordinated, multi-year effort by a diverse network of forensic researchers, legal advocates, and civil society organizations. From the $167M civil judgment against NSO Group to the closure of critical zero-day flaws in global messaging platforms, the tide is turning against mercenary surveillance. This session explores how this decentralized network supported by the Spyware Accountability Initiative (SAI) is dismantling the spyware business model. We will move beyond individual exploits to analyze the “policy infrastructure that makes technical security research impactful. We’ll show how technical discovery turns into legal and financial consequences for spyware companies. We will also detail how the SAI pooled fund model coordinates resources across organizations like Citizen Lab, the Knight First Amendment Institute, and regional threat labs on every continent. Attendees will gain an inside look at how this initiative operates, how it prioritizes high-impac

\n\nSpeakers:Michael Brennan,Nadine Farid Johnson,Rebekah Brown
\n
\nSpeakerBio:  Michael Brennan, Spyware Accountability Initiative
\n

Michael Brennan works at the intersection of technology, civil society, and philanthropy, helping build the funding and coordination strategies that make accountability efforts possible. His work focuses on translating between technical researchers, legal advocates, and policy actors to support effective responses to digital threats, including commercial spyware. He has helped shape collaborative approaches to complex public-interest technology challenges and is particularly interested in the often-invisible infrastructure (funding models, networks, and strategy) that turns technical discovery into meaningful consequences for powerful actors. He brings a cross-disciplinary perspective on how to make resistance to surveillance more durable, coordinated, and effective. He holds a PhD in Computer Science.

\n\nSpeakerBio:  Nadine Farid Johnson, Knight First Amendment Institute
\n

Nadine Farid Johnson is the inaugural policy director of the Knight First Amendment Institute at Columbia University. She is responsible for the Institute’s policy and advocacy efforts, leading engagement with U.S. government and other officials to advance the Institute’s policy objectives. A former U.S. diplomat and professor of law and political science, Farid Johnson is a frequent media contributor, with commentary appearing in The New York Times, The Wall Street Journal, The Atlantic, World Politics Review, Al Jazeera, The Hill, The Daily Beast, NPR, and other national and international publications. She has also appeared on outlets including PBS and CNN International.

\n\nSpeakerBio:  Rebekah Brown
\n

Rebekah Brown is a senior researcher at the Citizen Lab focussing on targeted threats against civil society. She has over 20 years of experience in threat intelligence and analysis. Before joining the Citizen Lab, Rebekah worked at Apple, where she focused on complex threat models and helped design and implement features for individuals at increased risk for stalking, harassment, and abuse. She is a trained network warfare analyst and previously served as operations chief of a U.S. Marine Corps cyber unit and a U.S. Cyber Command training and exercise lead. Rebekah is a published author on intelligence-driven incident response, and co-author of the SANS course on cyber threat intelligence.

\n\n\n\'',NULL,1294368),('4_Sunday','12','12:00','12:30','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Inference in the Infrastructure: Developing NIST AI RMF Resources for Resilient AI in Critical Systems -\'','\'Raymond Sheh,Martin Stanley\'','Creator Talks_a596f3d99157ba3badef1694e992af07','\'Title: Inference in the Infrastructure: Developing NIST AI RMF Resources for Resilient AI in Critical Systems -
\nTags: Policy @ DEF CON | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n

As grids decentralize and cyber-attacks accelerate, Critical Infrastructure must keep up. \"Inference in the Infrastructure\" offers a path to machine-speed defense, but it is only as safe as the guardrails we build together. This is a call to action to help shape the new NIST AI Risk Management Framework Profile for Trustworthy AI in Critical Infrastructure. We need the hacker community to ensure these systems are worthy of our trust before they are fully deployed. Trustworthy AI in critical systems requires more than high-level policy. The hacker mindset is vital for identifying the emergent failures, hidden interdependencies, and non-obvious edge cases. We will dive into resources designed to bridge the gap between governance and field-ready implementation, translating trustworthiness characteristics into actionable \"bridge language\" and technical practices that facilitate governance controls that align with both data science and operational realities. We are inviting the community to look under the hood, stress-test, and shape the draft guidance before it informs the rules for the next generation of infrastructure. Whether you are an AI researcher, an ICS defender, or a policy architect, your \"ground-truth\" input is needed to ensure we automate our world on a foundation that is both resilient and intelligent.

\n\nSpeakers:Raymond Sheh,Martin Stanley
\n
\nSpeakerBio:  Raymond Sheh, Johns Hopkins University
\n

Dr. Raymond Sheh is an AI, cybersecurity, robotics, and standards expert with over two decades of published international research experience across academia, industry, government, and defense. He is an Associate Research Scientist at Johns Hopkins University in Maryland and leads the development of the NIST AI Risk Management Framework (AI RMF) Profile for Trustworthy AI in Critical Infrastructure at the U.S. National Institute of Standards and Technology (NIST) Information Technology Laboratory (ITL). He was previously the Uncrewed Aircraft Systems (UAS) Research Lead for the NIST Public Safety Communications Research Division (PSCR), a Research Professor at Georgetown University in Washington DC, and a Senior Lecturer in Computer Science at Curtin University in Western Australia. Dr. Sheh holds a Ph.D. in AI and robotics from the University of New South Wales in Sydney, Australia.

\n\nSpeakerBio:  Martin Stanley, U.S. National Institute of Standards and Technology (NIST)
\n

Martin Stanley, AI and Cybersecurity Researcher, leads the NIST AI Risk Management Framework (AI RMF) efforts at the U.S. National Institute of Standards and Technology (NIST), Information Technology Laboratory. Martin previously led the Emerging Technology and R&D Program at CISA and the Enterprise Cybersecurity Program at the U.S. Food and Drug Administration. Prior to his federal service Martin held executive leadership positions at Vonage and UUNET Technologies. Martin co-authored “Digital Health”, an Oxford University Press Publication, and led the 2024 development of NIST AI 600-1 “NIST AI RMF: Generative Artificial Intelligence Profile” and NIST SP 800-218A “Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile.”

\n\n\n\'',NULL,1294369),('4_Sunday','12','12:30','13:59','N','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Tactical Advocacy: Panel & Peer Sessions with EFF\'','\'Thorin Klosowski,Cooper \"Cybertiger\" Quintin,Alexis Hancock,Cindy Cohn,Rory Mir\'','Creator Talks_dec5aadbe98dfc66c154fe5c4099771c','\'Title: Tactical Advocacy: Panel & Peer Sessions with EFF
\nTags: Policy @ DEF CON | Creator Interactive Talk/Panel
\nWhen: Sunday, Aug 9, 12:30 - 13:59 PDT
\nWhere: LVCCW Level 2 W210-211 (Policy Village) - Map
\n
\nDescription:
\n\n\nSpeakers:Thorin Klosowski,Cooper \"Cybertiger\" Quintin,Alexis Hancock,Cindy Cohn,Rory Mir
\n
\nSpeakerBio:  Thorin Klosowski, Electronic Frontier Foundation
\n

Senior Security and Privacy Activist, works on Surveillance Self-Defense, providing practical security and privacy guidance for a variety of threat models and across a breadth of consumer electronics.

\n\nSpeakerBio:  Cooper \"Cybertiger\" Quintin, Board Member at Open Archive
\n

Cooper Quintin is a security researcher and senior public interest technologist with the EFF Threat Lab. research fellow with Citizen Lab, adviser to CoRD Research and Design, and board member of Open Archive. He has worked on projects including Rayhunter, Privacy Badger, Canary Watch, and analysis of state sponsored malware campaigns such as Dark Caracal. Cooper has given talks about security research at prestigious security conferences including Black Hat, DEFCON, Enigma Conference, and ReCon about issues ranging from IMSI Catcher detection to fem tech privacy issues to newly discovered APTs. He has also been published or quoted in publications including: The New York Times, Reuters, NPR, CNN, and Al Jazeera. Cooper has given security trainings for activists, non profit workers, and vulnerable populations around the world. He previously worked building websites for nonprofits, including Greenpeace, Adbusters, and the Chelsea Manning Support Network. Cooper was also an editor and contributor to the hacktivist journal, \"Hack this Zine.\" In his spare time he enjoys making music, visualizing a solar-punk communitarian future, and playing with his kids.

\n\nSpeakerBio:  Alexis Hancock, Director of Engineering at Electronic Frontier Foundation
\n

Alexis works to keep the networks strong and encrypted by managing the Certbot project. As well as ensuring EFF open source tools for the public are well supported. She researches an intersection of issues on digital rights, encryption, and consumer technology. She believes in an open and equitable web through encouraging expansion of security by default, bridging engineers and security research, and advocating for better and stronger tech policy and standards.

\n\nSpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation
\n

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy\'s Defender published by MIT Press in March, 2026. She is also the co-host of EFF\'s award-winning podcast, How to Fix the Internet.

\n\n

--

\n\n

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.

\n\nSpeakerBio:  Rory Mir, Electronic Frontier Foundation
\n

Director of Open Access & Tech Community Engagement, where they drive advocacy on access to knowledge, emerging technologies, and user autonomy. They also partner with community builders, experts, and other EFF volunteers to fostering strategic coordination and knowledge sharing.

\n\n\n\'',NULL,1294370),('4_Sunday','13','12:30','13:59','Y','Policy @ DEF CON','LVCCW Level 2 W210-211 (Policy Village)','\'Tactical Advocacy: Panel & Peer Sessions with EFF\'','\'Thorin Klosowski,Cooper \"Cybertiger\" Quintin,Alexis Hancock,Cindy Cohn,Rory Mir\'','Creator Talks_dec5aadbe98dfc66c154fe5c4099771c','\'\'',NULL,1294371),('4_Sunday','10','10:00','10:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'The Diana Initiative - Open time\'','\'\'','Creator Events_ea092a328d44a7e418eb10f18e4a1816','\'Title: The Diana Initiative - Open time
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

\n\n

We also have our \"Reference Desk\", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.

\n\n\'',NULL,1294372),('4_Sunday','13','13:00','13:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'The Diana Initiative - Open time\'','\'\'','Creator Events_e256d7d9711bf1da4f91b4a347ac59bc','\'Title: The Diana Initiative - Open time
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Sunday, Aug 9, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

\n\n

We also have our \"Reference Desk\", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.

\n\n\'',NULL,1294373),('2_Friday','12','12:00','12:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'The Diana Initiative - Open time\'','\'\'','Creator Events_7196d69591600bed922ed5d1c3d73ffd','\'Title: The Diana Initiative - Open time
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

\n\n

We also have our \"Reference Desk\", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.

\n\n\'',NULL,1294374),('3_Saturday','16','16:00','17:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'The Diana Initiative - Open time\'','\'\'','Creator Events_e2b9acf6fb4bffce2db1fee579763700','\'Title: The Diana Initiative - Open time
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

\n\n

We also have our \"Reference Desk\", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.

\n\n\'',NULL,1294375),('3_Saturday','17','16:00','17:59','Y','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'The Diana Initiative - Open time\'','\'\'','Creator Events_e2b9acf6fb4bffce2db1fee579763700','\'\'',NULL,1294376),('3_Saturday','12','12:00','12:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'The Diana Initiative - Open time\'','\'\'','Creator Events_f326f91da1e0a048710e677d659d9e90','\'Title: The Diana Initiative - Open time
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

\n\n

We also have our \"Reference Desk\", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.

\n\n\'',NULL,1294377),('2_Friday','14','14:00','14:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'The Diana Initiative - Open time\'','\'\'','Creator Events_9b45d8755e2be8681f55a0f8831fa070','\'Title: The Diana Initiative - Open time
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out - we have games and puzzles and lego!

\n\n

We also have our \"Reference Desk\", not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.

\n\n\'',NULL,1294378),('3_Saturday','10','10:00','10:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Yoga\'','\'Deanna Heon\'','Creator Events_51d24ca19ad8b8858e2259a01ec1de67','\'Title: Yoga
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

Come join us for morning yoga and meditation. This workshop is inclusive of all bodies. Meditation can help quiet the mind, manage stress, and enhance overall emotional well-being, making it a great way to start the day.

\n\nSpeakerBio:  Deanna Heon
\nNo BIO available
\n\n\'',NULL,1294379),('2_Friday','17','17:00','17:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Yoga\'','\'Deanna Heon\'','Creator Events_879b9768be14e48ffe275d818bfdd7fd','\'Title: Yoga
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

Come join us for morning yoga and meditation. This workshop is inclusive of all bodies. Meditation can help quiet the mind, manage stress, and enhance overall emotional well-being, making it a great way to start the day.

\n\nSpeakerBio:  Deanna Heon
\nNo BIO available
\n\n\'',NULL,1294380),('3_Saturday','14','14:00','15:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Hacker Book Club meet up\'','\'\'','Creator Events_256b2fbffdaf44287e5754344b4a05ad','\'Title: Hacker Book Club meet up
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Saturday, Aug 8, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

Community is essential and so is continual learning. Reading books and discussing books can greatly impact an individual’s access and sense of community and knowledge. This Hacker Book Club book discussion will be an accessible group aiming to build community and share out learnings, all in a quieter setting. Come join us and discuss what you’ve been reading. We also run a year round Discord to discuss books throughout the year, hackerbookclub.com. This Hacker Book Club is not locked to a region and is for those who love books and escaping to the cyberpunk and scifi worlds that inspire DEF CON and modern literature. The DEF CON 34 theme is agency and our DEF CON themed book is The Dispossessed by Ursula Le Guin.

\n\nLinks:
    Website - https://hackerbookclub.com/
\n\'',NULL,1294381),('3_Saturday','15','14:00','15:59','Y','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Hacker Book Club meet up\'','\'\'','Creator Events_256b2fbffdaf44287e5754344b4a05ad','\'\'',NULL,1294382),('2_Friday','10','10:00','11:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Hacker Runway Crafting Time\'','\'\'','Creator Events_312708a2931a0e05a1bf379ed4fa9b77','\'Title: Hacker Runway Crafting Time
\nTags: The Diana Initiative | Hack3r Runw@y v8.0 | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

Hacker Runway Crafting time - didn\'t have time, or didn\'t know about the Hacker Runway competition? Have no fear we have some supplies to help you put together a last moment entry! Make sure to stop by the DC Maker Village as well!

\n\nLinks:
    More Info - https://www.dianainitiative.org/events/tdi-def-con/hacker-runway
\n\'',NULL,1294383),('2_Friday','11','10:00','11:59','Y','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Hacker Runway Crafting Time\'','\'\'','Creator Events_312708a2931a0e05a1bf379ed4fa9b77','\'\'',NULL,1294384),('2_Friday','15','15:00','15:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Dear Red Team, Love Blue Team: Pulling Both Screaming Parties into Purple\'','\'Allie\'','Creator Talks_82b65c63fb0bf37b6b8a9b03b511e872','\'Title: Dear Red Team, Love Blue Team: Pulling Both Screaming Parties into Purple
\nTags: The Diana Initiative | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

While purple teaming isn’t a new concept, getting purple teaming actually started and happening consistently is tough! Maybe your company or team experienced the one purple team event, then before you know it was back to red vs blue? Or maybe your purple team just never happened? Join Allie as she discusses her experiences with this struggle - where she dealt with only taking red team reports to make the blue team better, to finally getting them to collaborate and improve both teams!

\n\nSpeakerBio:  Allie
\n

Allie is a Senior Security Analyst with eight years of combined experience across systems administration, networking, and cybersecurity. She has previously presented work about threat hunting nation state actors targeting the open-source software ecosystem. She spends her days hunting threat actors and leading incident response investigations. Outside of work, she enjoys camping, spending time with her dog, and her kids, who rank somewhere between \"favorite humans\" and \"active incident response scenario\" depending on the day.

\n\n\n\'',NULL,1294385),('3_Saturday','11','11:00','11:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Stay Sharp: Navigating Pen Testing and Bug Bounty in an AI-Driven World\'','\'Dana Pirvu\'','Creator Talks_bd2c559e3123bc08787fb070a85c2537','\'Title: Stay Sharp: Navigating Pen Testing and Bug Bounty in an AI-Driven World
\nTags: The Diana Initiative | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

AI is no longer on the horizon — it\'s already in our workflows, our attacker toolkits, and our vulnerability landscapes. For penetration testers and bug bounty professionals, the skills that got us here won\'t be enough to keep up.

\n\n

This session is built for the full cyber community — students exploring careers, professionals breaking in, and program leaders rethinking their approach. We\'ll cover the training and certifications worth investing in, how to identify and close skill gaps, and why community, mentorship, and peer networks remain our most important growth asset. For those leading teams, we\'ll tackle a harder question: how do you build a learning culture that keeps up with change without burning people out? The AI field is moving fast. We have to move with it.

\n\nSpeakerBio:  Dana Pirvu, Senior Manager of Product and Software Security at Adobe
\n

Dana Pirvu is a Senior Manager of Product and Software Security at Adobe, overseeing the Penetration Testing and Bug Bounty programs. In her role, Dana drives continuous product security testing efforts and partners with external researchers to proactively identify vulnerabilities across Adobe’s products and services, translating security findings into actionable insights for engineering and leadership teams.

\n\n\n\'',NULL,1294386),('2_Friday','13','13:00','13:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Stigma is stupid: Let\'s talk about recovery, mental wellness, and hard stuff without making it awkward\'','\'Jennifer VanAntwerp\'','Creator Talks_0f724fc20dfec8b78f5dcc56f1309847','\'Title: Stigma is stupid: Let\'s talk about recovery, mental wellness, and hard stuff without making it awkward
\nTags: The Diana Initiative | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

This will be a discussion group about how we talk (or don’t talk) about recovery, sobriety, mental wellness, burnout, grief, and other hard human things in cybersecurity spaces. Silence feeds stigma, but not everyone knows how to start the conversation safely or supportively. We’ll discuss language, boundaries, allyship, and ways to create community without turning every vulnerable conversation into a TED Talk or therapy session.

\n\nSpeakerBio:  Jennifer VanAntwerp, ABM Manager at StrongDM
\n

Jen VanAntwerp is the founder of Sober in Cyber, a nonprofit on a mission to provide alcohol-free events and community-building opportunities for sober individuals working in cybersecurity. She is passionate about breaking the stigma of addiction recovery and is profoundly driven to increase the number of professional networking events that don’t revolve around alcohol. Jen is also the ABM manager at StrongDM, the Zero Trust privileged access platform. When she’s not developing marketing strategies or running her nonprofit, Jen enjoys volunteering, sewing, and tinkering with her beloved ’65 Ranchero.

\n\n\n\'',NULL,1294387),('4_Sunday','11','11:00','12:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Threat Model your Career Workshop\'','\'Chandan Vedavyas\'','Creator Events_c77db492edc877f9135fe1e7fd580d0b','\'Title: Threat Model your Career Workshop
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Sunday, Aug 9, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

We threat model systems all the time. Almost nobody runs that same thinking on their own career, which is usually the most valuable thing they own. Let\'s spend two hours looking at your career the way you would look at something you are paid to defend: what is worth protecting, what could go wrong, where they are exposed, and what you are actually going to do about it. 

\n\n

Everyone will leave with a filled-in canvas and one specific thing they have committed to in the next month.\nThis workshop is for any experience level.

\n\nSpeakerBio:  Chandan Vedavyas
\nNo BIO available
\n\n\'',NULL,1294388),('4_Sunday','12','11:00','12:59','Y','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Threat Model your Career Workshop\'','\'Chandan Vedavyas\'','Creator Events_c77db492edc877f9135fe1e7fd580d0b','\'\'',NULL,1294389),('2_Friday','10','10:10','10:20','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'IOT Village Tour\'','\'\'','Creator Events_349df4d9295d11102e0e5905f5a33cc0','\'Title: IOT Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 10:10 - 10:20 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting IOT Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to IOT Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294390),('2_Friday','10','10:20','10:30','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Quantum Village Tour\'','\'\'','Creator Events_7fa7edc09b0e59e67adbc92854e2c442','\'Title: Quantum Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 10:20 - 10:30 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Quantum Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Quantum Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294391),('2_Friday','10','10:30','10:40','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'AppSec Village Tour\'','\'\'','Creator Events_84441ea720836e543ff9a99a095f163a','\'Title: AppSec Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 10:30 - 10:40 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting AppSec Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to AppSec Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294392),('2_Friday','10','10:40','10:50','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Robot Hacking Community Tour\'','\'\'','Creator Events_d7c2a1938807fb934662c0d94ddbda2d','\'Title: Robot Hacking Community Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 10:40 - 10:50 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Robot Hacking Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Robot Hacking Community and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294393),('2_Friday','10','10:50','10:59','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Physical Securty Village Tour\'','\'\'','Creator Events_11a7245503e66048071a7dee8ececc2d','\'Title: Physical Securty Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 10:50 - 10:59 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Physical Securty Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Physical Securty Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294394),('2_Friday','11','11:00','11:10','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Ham Radio Village Tour\'','\'\'','Creator Events_11c771e335beb750a0c339676ad060d5','\'Title: Ham Radio Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 11:00 - 11:10 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Ham Radio Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Ham Radio Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294395),('2_Friday','11','11:10','11:20','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Packet Hacking Village Tour\'','\'\'','Creator Events_eef86fed865aadf8d12f305fc0744025','\'Title: Packet Hacking Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 11:10 - 11:20 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Packet Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Packet Hacking Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294396),('2_Friday','11','11:20','11:30','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Mobile Hacking Tour\'','\'\'','Creator Events_68ef208d3de6908f82f06f23975d91d9','\'Title: Mobile Hacking Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 11:20 - 11:30 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Mobile Hacking but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Mobile Hacking and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294397),('2_Friday','11','11:30','11:40','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Maritime Hacking Village Tour\'','\'\'','Creator Events_1f928bfd098eb726bfcd5dafa424c726','\'Title: Maritime Hacking Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 11:30 - 11:40 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Maritime Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Maritime Hacking Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294398),('2_Friday','11','11:40','11:50','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'HHV/SSV Tour\'','\'\'','Creator Events_c6eae0222a2f0b2a408418d498b7427a','\'Title: HHV/SSV Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 11:40 - 11:50 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting HHV/SSV but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to HHV/SSV and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294399),('2_Friday','11','11:50','11:59','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'ICS Village Tour\'','\'\'','Creator Events_3d99325840e82f6d21d68b2647421c49','\'Title: ICS Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 11:50 - 11:59 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting ICS Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to ICS Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294400),('2_Friday','12','12:00','12:10','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'DEF CON Academy Tour\'','\'\'','Creator Events_3e37b7913c20aae779c6756feef53363','\'Title: DEF CON Academy Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 12:00 - 12:10 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting DEF CON Academy but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DEF CON Academy and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294401),('2_Friday','12','12:10','12:20','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'DC Maker\'s Community Tour\'','\'\'','Creator Events_6a3fe4351c8a0aeecc15d1a580839a93','\'Title: DC Maker\'s Community Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 12:10 - 12:20 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting DC Maker\'s Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DC Maker\'s Community and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294402),('2_Friday','12','12:20','12:30','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Cryptocurrency Village Tour\'','\'\'','Creator Events_59cced51e8ea800d2a92d6db53ad3529','\'Title: Cryptocurrency Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 12:20 - 12:30 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Cryptocurrency Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Cryptocurrency Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294403),('2_Friday','12','12:30','12:40','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Car Hacking Village Tour\'','\'\'','Creator Events_76bc0b08e6d66312ec6fcf4f2980788d','\'Title: Car Hacking Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 12:30 - 12:40 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Car Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Car Hacking Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294404),('2_Friday','12','12:40','12:50','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Call Center Tour\'','\'\'','Creator Events_9aba298c099d026a5d832be577b5b8e8','\'Title: Call Center Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 12:40 - 12:50 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Call Center but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Call Center and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294405),('2_Friday','12','12:50','12:59','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'DDoS Community Tour\'','\'\'','Creator Events_0313afdb416dd050e4f3bf0cb2ee7247','\'Title: DDoS Community Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 12:50 - 12:59 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting DDoS Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DDoS Community and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294406),('2_Friday','13','13:00','13:10','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Cloud Village Tour\'','\'\'','Creator Events_8e8260ab546704926039b91d16715cee','\'Title: Cloud Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 13:00 - 13:10 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Cloud Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Cloud Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294407),('2_Friday','13','13:10','13:20','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Telecom Village Tour\'','\'\'','Creator Events_eb6297a02e575c5de268f8b2262e8c3b','\'Title: Telecom Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 13:10 - 13:20 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Telecom Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Telecom Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294408),('2_Friday','13','13:20','13:30','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'DEF CON Groups (DCG) Tour\'','\'\'','Creator Events_58bef0bcfee04baf6847cdef3fb0d012','\'Title: DEF CON Groups (DCG) Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 13:20 - 13:30 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting DEF CON Groups (DCG) but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DEF CON Groups (DCG) and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294409),('2_Friday','13','13:30','13:40','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Aerospace Village Tour\'','\'\'','Creator Events_2f999e60dc27a792d1a9724a086e989c','\'Title: Aerospace Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 13:30 - 13:40 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Aerospace Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Aerospace Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294410),('2_Friday','13','13:40','13:50','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Bug Bounty Village Tour\'','\'\'','Creator Events_5ec626cb31ee0232cff5b8e82e97c9c8','\'Title: Bug Bounty Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 13:40 - 13:50 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Bug Bounty Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Bug Bounty Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294411),('2_Friday','13','13:50','13:59','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'La Villa Tour\'','\'\'','Creator Events_1a20041ee75b4f8d0cb8a3bda1dc374c','\'Title: La Villa Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Friday, Aug 7, 13:50 - 13:59 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting La Villa but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to La Villa and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294412),('3_Saturday','10','10:10','10:20','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'MEACS: Middle Easterns & African in Cyber Security Tour\'','\'\'','Creator Events_8ea28d6aad96328d0c119d2cd7f58cca','\'Title: MEACS: Middle Easterns & African in Cyber Security Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 10:10 - 10:20 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\nInterested in visiting MEACS: Middle Easterns & African in Cyber Security but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to MEACS: Middle Easterns & African in Cyber Security and be introduced to the community and activities inside!
\n\n\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294413),('3_Saturday','10','10:20','10:30','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Crypto And Privacy Village Tour\'','\'\'','Creator Events_f8ba6a5f5a478e770908ecbfba8da677','\'Title: Crypto And Privacy Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 10:20 - 10:30 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Crypto And Privacy Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Crypto And Privacy Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294414),('3_Saturday','10','10:30','10:40','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Data Duplication Village Tour\'','\'\'','Creator Events_421bb3793d2f9976d1f852060399dd93','\'Title: Data Duplication Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 10:30 - 10:40 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Data Duplication Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Data Duplication Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294415),('3_Saturday','10','10:40','10:50','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Payment Village Tour\'','\'\'','Creator Events_d27bfa43db2054b2c19d7e30417c3f98','\'Title: Payment Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 10:40 - 10:50 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Payment Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Payment Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294416),('3_Saturday','10','10:50','10:59','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Policy @ Defcon Tour\'','\'\'','Creator Events_9b5ca2073a3be2cba7879d5382249a95','\'Title: Policy @ Defcon Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 10:50 - 10:59 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Policy @ Defcon but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Policy @ Defcon and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294417),('3_Saturday','11','11:00','11:10','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Biohacking Village Tour\'','\'\'','Creator Events_5dc9669640fe513c49f8ba077bb7d6b3','\'Title: Biohacking Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 11:00 - 11:10 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Biohacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Biohacking Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294418),('3_Saturday','11','11:10','11:20','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Adversary Village Tour\'','\'\'','Creator Events_8bf07b4416c9f9917f409c50f565b2fb','\'Title: Adversary Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 11:10 - 11:20 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Adversary Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Adversary Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294419),('3_Saturday','11','11:20','11:30','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Radio Frequency Village Tour\'','\'\'','Creator Events_18cf0b1dd503c5b484086e57f9db94e3','\'Title: Radio Frequency Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 11:20 - 11:30 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Radio Frequency Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Radio Frequency Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294420),('3_Saturday','11','11:30','11:40','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Embedded System Village Tour\'','\'\'','Creator Events_930b714f9d20d47957848faa7f7b40c2','\'Title: Embedded System Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 11:30 - 11:40 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Embedded System Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Embedded System Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294421),('3_Saturday','11','11:40','11:50','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Gamer Village Tour\'','\'\'','Creator Events_dc076c145259b39cb06fb979e025dadd','\'Title: Gamer Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 11:40 - 11:50 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Gamer Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Gamer Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294422),('3_Saturday','11','11:50','11:59','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Queercon Community Lounge Tour\'','\'\'','Creator Events_b95235194f43ce202160f1dfeb98e4d0','\'Title: Queercon Community Lounge Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 11:50 - 11:59 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Queercon Community Lounge but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Queercon Community Lounge and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294423),('3_Saturday','12','12:00','12:10','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Kubernetes CTF at DEF CON Contest Tour\'','\'\'','Creator Events_4e465aa17b65ad6076f16a0358dd620b','\'Title: Kubernetes CTF at DEF CON Contest Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 12:00 - 12:10 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Kubernetes CTF at DEF CON Contest but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Kubernetes CTF at DEF CON Contest and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294424),('3_Saturday','12','12:10','12:20','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Malware Village Tour\'','\'\'','Creator Events_b3d10e01a88d659234bf82e29c444585','\'Title: Malware Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 12:10 - 12:20 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Malware Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Malware Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294425),('3_Saturday','12','12:20','12:30','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Blue Team Village Tour\'','\'\'','Creator Events_6c4bbd1c1076dd9956f15abdfe816199','\'Title: Blue Team Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 12:20 - 12:30 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Blue Team Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Blue Team Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294426),('3_Saturday','12','12:30','12:40','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'BBWIC Foundation Tour\'','\'\'','Creator Events_7336882f4a4c9d617a62d9ca423cde59','\'Title: BBWIC Foundation Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 12:30 - 12:40 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting BBWIC Foundation but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to BBWIC Foundation and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294427),('3_Saturday','12','12:40','12:50','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'AI Village Tour\'','\'\'','Creator Events_8d955f17b0b9998e9bb3ba7ba05aa10b','\'Title: AI Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 12:40 - 12:50 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting AI Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to AI Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294428),('3_Saturday','12','12:50','12:59','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Blacks In Cyber Village Tour\'','\'\'','Creator Events_ba77e9d487740a17448031462bb48e69','\'Title: Blacks In Cyber Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 12:50 - 12:59 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Blacks In Cyber Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Blacks In Cyber Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294429),('3_Saturday','13','13:00','13:10','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Recon Village Tour\'','\'\'','Creator Events_1546d036d23b9e55e06aef7856255990','\'Title: Recon Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 13:00 - 13:10 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Recon Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Recon Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294430),('3_Saturday','13','13:10','13:20','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Voting Village Tour\'','\'\'','Creator Events_b800161d7d6227ad2fb3a92b328b0183','\'Title: Voting Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 13:10 - 13:20 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Voting Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Voting Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294431),('3_Saturday','13','13:20','13:30','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Hackers with Disabilities Tour\'','\'\'','Creator Events_87cdf936cb511b68ed6ac6d3020d5094','\'Title: Hackers with Disabilities Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 13:20 - 13:30 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Hackers with Disabilities but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Hackers with Disabilities and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294432),('3_Saturday','13','13:30','13:40','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Red Team Village Tour\'','\'\'','Creator Events_9751eff3df7564b54bc7e89bbecc958a','\'Title: Red Team Village Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 13:30 - 13:40 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Red Team Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Red Team Village and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294433),('3_Saturday','13','13:40','13:50','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Scambait Community Tour\'','\'\'','Creator Events_72c99144c1619e7e695cf3cb8da00b13','\'Title: Scambait Community Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 13:40 - 13:50 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Scambait Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Scambait Community and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294434),('3_Saturday','13','13:50','13:59','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Badgelife Tour\'','\'\'','Creator Events_888915192e9e35189806acc54a2a06fd','\'Title: Badgelife Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 13:50 - 13:59 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Badgelife but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Badgelife and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294435),('3_Saturday','14','14:00','14:10','N','The Diana Initiative','LVCCW Level 1 South Lobby / Atrium','\'Illumicon Tour\'','\'\'','Creator Events_e21d8bbc912e9be7a1378ddf15af675a','\'Title: Illumicon Tour
\nTags: The Diana Initiative | Creator Tour
\nWhen: Saturday, Aug 8, 14:00 - 14:10 PDT
\nWhere: LVCCW Level 1 South Lobby / Atrium - Map
\n
\nDescription:
\n

Interested in visiting Illumicon but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Illumicon and be introduced to the community and activities inside!

\n\nLinks:
    The Diana Initiative Website - https://tdi.mobi/DEFCON
\n\'',NULL,1294436),('2_Friday','08','08:30','17:59','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'Title: Social Engineering Community Village - Open Hours
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 08:30 - 17:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Morning, social engineers! Swing by for your SEC merch, claim your seat, and prepare for action... the phones start ringing soon.

\n\n

The Social Engineering Community village dives into one of the most powerful attack surfaces in security: humans. Our village creates a space where attendees can explore the psychology, tactics, and tradecraft behind human-focused hacking. Through presentations, live demonstrations (via contests), and interactive activities, students, defenders, hackers, and the curious can see how reconnaissance, persuasion, and improvisation are used to bypass even the best defenses.

\n\n

At DEF CON the village becomes a live stage for the craft. In the Social Engineering Community Vishing Competition (SECVC), competitors step into a soundproof booth and place real calls using OSINT, creative pretexts, and quick thinking while the audience watches the strategy unfold in real time. In Battle of the Bots, human-created AI agents attempt social engineering calls of their own, exploring what happens when automated systems try their hand at elicitation. Alongside the contests, attendees can have the opportunity to place calls in our \"Cold Calls\" or listen in to some presentations.

\n\n

The village is built by the community that practices the craft. Volunteers, researchers, hackers, defenders, and curious newcomers all contribute to the content each year, creating space for new voices and ideas to take the stage. Whether you want to watch live un-scripted social engineering calls, understand the psychology behind it, or meet others who love the human side of security, the Social Engineering Community village is the place to experience it at DEF CON.

\n\n

Prerequisites:

\n\n

Attendees are welcome to watch contests, join discussions, and participate in interactive activities with no preparation needed.

\n\n

Competitors in the Social Engineering Community Vishing Competition and Battle of the Bots Contest are selected in advance through a Call for Competitors prior to DEF CON, but some activities such as Cold Calls allow audience members to sign up onsite and participate.

\n\n

Attendees who want to participate in Cold Calls may benefit from brushing up on basic social engineering skills such as rapport building, influence and elicitation techniques.

\n\n\'',NULL,1294437),('2_Friday','09','08:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'\'',NULL,1294438),('2_Friday','10','08:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'\'',NULL,1294439),('2_Friday','11','08:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'\'',NULL,1294440),('2_Friday','12','08:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'\'',NULL,1294441),('2_Friday','13','08:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'\'',NULL,1294442),('2_Friday','14','08:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'\'',NULL,1294443),('2_Friday','15','08:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'\'',NULL,1294444),('2_Friday','16','08:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'\'',NULL,1294445),('2_Friday','17','08:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_2b4fc7f1f81aa2d8123ee7a133e3e4d9','\'\'',NULL,1294446),('4_Sunday','10','10:00','12:30','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_149a15c3c273f12a279c2e551871e863','\'Title: Social Engineering Community Village - Open Hours
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 12:30 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Morning, social engineers! Swing by for your SEC merch, claim your seat, and prepare for action... the phones start ringing soon.

\n\n

The Social Engineering Community village dives into one of the most powerful attack surfaces in security: humans. Our village creates a space where attendees can explore the psychology, tactics, and tradecraft behind human-focused hacking. Through presentations, live demonstrations (via contests), and interactive activities, students, defenders, hackers, and the curious can see how reconnaissance, persuasion, and improvisation are used to bypass even the best defenses.

\n\n

At DEF CON the village becomes a live stage for the craft. In the Social Engineering Community Vishing Competition (SECVC), competitors step into a soundproof booth and place real calls using OSINT, creative pretexts, and quick thinking while the audience watches the strategy unfold in real time. In Battle of the Bots, human-created AI agents attempt social engineering calls of their own, exploring what happens when automated systems try their hand at elicitation. Alongside the contests, attendees can have the opportunity to place calls in our \"Cold Calls\" or listen in to some presentations.

\n\n

The village is built by the community that practices the craft. Volunteers, researchers, hackers, defenders, and curious newcomers all contribute to the content each year, creating space for new voices and ideas to take the stage. Whether you want to watch live un-scripted social engineering calls, understand the psychology behind it, or meet others who love the human side of security, the Social Engineering Community village is the place to experience it at DEF CON.

\n\n

Prerequisites:

\n\n

Attendees are welcome to watch contests, join discussions, and participate in interactive activities with no preparation needed.

\n\n

Competitors in the Social Engineering Community Vishing Competition and Battle of the Bots Contest are selected in advance through a Call for Competitors prior to DEF CON, but some activities such as Cold Calls allow audience members to sign up onsite and participate.

\n\n

Attendees who want to participate in Cold Calls may benefit from brushing up on basic social engineering skills such as rapport building, influence and elicitation techniques.

\n\n\'',NULL,1294447),('4_Sunday','11','10:00','12:30','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_149a15c3c273f12a279c2e551871e863','\'\'',NULL,1294448),('4_Sunday','12','10:00','12:30','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_149a15c3c273f12a279c2e551871e863','\'\'',NULL,1294449),('3_Saturday','10','10:00','17:59','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_e62d1e6aeadb68c7776dc929aee1bbd4','\'Title: Social Engineering Community Village - Open Hours
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Morning, social engineers! Swing by for your SEC merch, claim your seat, and prepare for action... the phones start ringing soon.

\n\n

The Social Engineering Community village dives into one of the most powerful attack surfaces in security: humans. Our village creates a space where attendees can explore the psychology, tactics, and tradecraft behind human-focused hacking. Through presentations, live demonstrations (via contests), and interactive activities, students, defenders, hackers, and the curious can see how reconnaissance, persuasion, and improvisation are used to bypass even the best defenses.

\n\n

At DEF CON the village becomes a live stage for the craft. In the Social Engineering Community Vishing Competition (SECVC), competitors step into a soundproof booth and place real calls using OSINT, creative pretexts, and quick thinking while the audience watches the strategy unfold in real time. In Battle of the Bots, human-created AI agents attempt social engineering calls of their own, exploring what happens when automated systems try their hand at elicitation. Alongside the contests, attendees can have the opportunity to place calls in our \"Cold Calls\" or listen in to some presentations.

\n\n

The village is built by the community that practices the craft. Volunteers, researchers, hackers, defenders, and curious newcomers all contribute to the content each year, creating space for new voices and ideas to take the stage. Whether you want to watch live un-scripted social engineering calls, understand the psychology behind it, or meet others who love the human side of security, the Social Engineering Community village is the place to experience it at DEF CON.

\n\n

Prerequisites:

\n\n

Attendees are welcome to watch contests, join discussions, and participate in interactive activities with no preparation needed.

\n\n

Competitors in the Social Engineering Community Vishing Competition and Battle of the Bots Contest are selected in advance through a Call for Competitors prior to DEF CON, but some activities such as Cold Calls allow audience members to sign up onsite and participate.

\n\n

Attendees who want to participate in Cold Calls may benefit from brushing up on basic social engineering skills such as rapport building, influence and elicitation techniques.

\n\n\'',NULL,1294450),('3_Saturday','11','10:00','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_e62d1e6aeadb68c7776dc929aee1bbd4','\'\'',NULL,1294451),('3_Saturday','12','10:00','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_e62d1e6aeadb68c7776dc929aee1bbd4','\'\'',NULL,1294452),('3_Saturday','13','10:00','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_e62d1e6aeadb68c7776dc929aee1bbd4','\'\'',NULL,1294453),('3_Saturday','14','10:00','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_e62d1e6aeadb68c7776dc929aee1bbd4','\'\'',NULL,1294454),('3_Saturday','15','10:00','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_e62d1e6aeadb68c7776dc929aee1bbd4','\'\'',NULL,1294455),('3_Saturday','16','10:00','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_e62d1e6aeadb68c7776dc929aee1bbd4','\'\'',NULL,1294456),('3_Saturday','17','10:00','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Social Engineering Community Village - Open Hours\'','\'\'','Creator Events_e62d1e6aeadb68c7776dc929aee1bbd4','\'\'',NULL,1294457),('2_Friday','08','08:45','08:59','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Village Greeting\'','\'\'','Creator Talks_7f486a5c9800df6c711485a7a45a8398','\'Title: Village Greeting
\nTags: Social Engineering Community Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 08:45 - 08:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Join the founders for a preview of what�s happening in the Village this year.

\n\n\'',NULL,1294458),('2_Friday','09','09:00','11:59','N','Contests','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'SEC Vishing Competition (SECVC)\'','\'\'','Contests_fa629bb1d6c074588603a6d48685ada2','\'Title: SEC Vishing Competition (SECVC)
\nTags: Social Engineering Community Village | Contest
\nWhen: Friday, Aug 7, 09:00 - 11:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

The official DEF CON contest SECVC is back, baby! Watch as teams turn months of research and rehearsal into live calls, matching sharp scripts against real corporate defenses for the win. This year\'s contest is judged this year by Snow, Jayson E. Street, and Kimberley Mitnick.

\n\n\'',NULL,1294459),('2_Friday','10','09:00','11:59','Y','Contests','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'SEC Vishing Competition (SECVC)\'','\'\'','Contests_fa629bb1d6c074588603a6d48685ada2','\'\'',NULL,1294460),('2_Friday','11','09:00','11:59','Y','Contests','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'SEC Vishing Competition (SECVC)\'','\'\'','Contests_fa629bb1d6c074588603a6d48685ada2','\'\'',NULL,1294461),('2_Friday','10','10:00','11:30','N','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Pickpocketing for Red Teamers: A Hands-On Experience\'','\'pradameinhof\'','Creator Events_75fc46b2b26ae41c66a20bc66cceae49','\'Title: Pickpocketing for Red Teamers: A Hands-On Experience
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 11:30 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n

Seven years ago, pradameinhof ran the world\'s first public pickpocketing competition with about 200 people at a social engineering conference. The inspiration? His dad got pickpocketed right next to him on the Paris Metro. What started as frustration turned into obsession�not just with preventing it, but with understanding how easy it is to pull off. It was hard enough finding good resources. The real problem? Testing your skills in realistic scenarios can land you in jail.

\n\n

In this two-hour Social Engineering Community session, pradameinhof will teach what he learned: the core techniques of attention manipulation�directing and surfing attention, relative touch, entering personal space, giving shade, fanning, and working in teams. You\'ll learn to lift wallets, watches, phones, badges, and keys, and apply these skills to red-teaming.

\n\n

Here\'s how it works: You\'ll pair up and take turns�one practitioner, one target. No prior experience necessary.

\n\n

What to bring: A jacket and pants with pockets that aren\'t too tight. Wear a watch if you have one. Because you will need to steal from other people and be pickpocketed, expect to touch and be touched by others in order to participate�all appropriately and with clear consent.

\n\n

Join us in this group exercise to understand the human blind spots that make physical social engineering so effective. Walk away with skills for your next red-team engagement�and better awareness so you don\'t become a target.

\n\n

(Disclaimer: This exercise is for educational purposes only. If you pickpocket people without their consent, expect to get into trouble.)

\n\nSpeakerBio:  pradameinhof
\n

pradameinhof has worked in cyber security startups for over two decades. Most of his skills he acquired by pestering his friends and colleagues over coffee. He has a passion for OSINT and Social Engineering.

\n\n\n\'',NULL,1294462),('2_Friday','11','10:00','11:30','Y','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Pickpocketing for Red Teamers: A Hands-On Experience\'','\'pradameinhof\'','Creator Events_75fc46b2b26ae41c66a20bc66cceae49','\'\'',NULL,1294463),('2_Friday','12','12:00','12:59','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Improv\'','\'\'','Creator Events_cfde44a9744b02ac9a467cd92457520f','\'Title: Improv
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Join Bryan and Kevin for a fun, low-pressure improv showdown where quick reactions, creative thinking, and social engineering skills take center stage.

\n\n\'',NULL,1294464),('2_Friday','12','12:00','12:59','N','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Zero Day Hire: Can You Spot the Spy?\'','\'Michael Reimsbach,Rishi \"rxerium\" C\'','Creator Events_1151934d7c8f84a0d4e702f56525cc5a','\'Title: Zero Day Hire: Can You Spot the Spy?
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n

If your hiring process relies solely on traditional background checks, you\'re already behind. You think you\'re hiring a Senior Backend Engineer. You\'ve reviewed the resume, passed the technical interview, and cleared the automated background check. But you\'ve actually just handed a corporate laptop to a spy.

\n\n

This 60-minute workshop puts the attendee in the seat of an OSINT lead during a live-fire exercise. This isn\'t a lecture; it\'s a test to stop a breach before it starts. Attendees will be provided with the same \"evidence\" a recruiter would see, and the goal is simple: perform a background check to identify fake personas. You have 60 minutes. Can you do it?

\n\n

Key Takeaways:\n- Learn why standard background checks miss AI-generated personas and synthetic identities\n- Leave with a practical, legally-conscious verification process you can use by Monday morning

\n\n

Note: Please bring your own laptop. Attendees should be comfortable installing and using common OSINT tools to participate in the live investigation.

\n\nSpeakers:Michael Reimsbach,Rishi \"rxerium\" C
\n
\nSpeakerBio:  Michael Reimsbach, Product Security Specialist at SAP
\n

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services.

\n\n

He obtained multiple industry certifications such as OSCP, GCPN, and CISSP.

\n\n

A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information.

\n\n

Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.

\n\nSpeakerBio:  Rishi \"rxerium\" C, Security Researcher
\n

Rishi is a London-based security researcher with over five years of hands-on experience in IT. He currently specializes in vulnerability research, threat intelligence, and enterprise risk analysis. His current focus lies in identifying and analyzing zero-day vulnerabilities and emerging CVEs, often working to reverse engineer exploit mechanics and build detection logic before public weaponization. Rishi’s work spans both offensive and defensive domains—developing threat models based on real-world TTPs, crafting custom detection rules, and automating reconnaissance pipelines to uncover exploitable misconfigurations and exposed assets. He is particularly active in attack surface management (ASM) and OSINT, where he leverages DNS enumeration, passive data correlation, and large-scale infrastructure scanning to surface unknown entry points and map adversary-accessible exposure. Outside of research, Rishi integrates findings into operational tooling and supports data-driven prioritization strategies to bridge technical risk and business impact. His work reflects a deep commitment to adversary-informed defense and proactive discovery across modern hybrid environments.

\n\n\n\'',NULL,1294465),('2_Friday','13','13:30','14:30','N','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Zero Day Hire: Can You Spot the Spy?\'','\'Michael Reimsbach,Rishi \"rxerium\" C\'','Creator Events_c2b3ccfe554a5380d9dda086b83a49f1','\'Title: Zero Day Hire: Can You Spot the Spy?
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n

If your hiring process relies solely on traditional background checks, you\'re already behind. You think you\'re hiring a Senior Backend Engineer. You\'ve reviewed the resume, passed the technical interview, and cleared the automated background check. But you\'ve actually just handed a corporate laptop to a spy.

\n\n

This 60-minute workshop puts the attendee in the seat of an OSINT lead during a live-fire exercise. This isn\'t a lecture; it\'s a test to stop a breach before it starts. Attendees will be provided with the same \"evidence\" a recruiter would see, and the goal is simple: perform a background check to identify fake personas. You have 60 minutes. Can you do it?

\n\n

Key Takeaways:\n- Learn why standard background checks miss AI-generated personas and synthetic identities\n- Leave with a practical, legally-conscious verification process you can use by Monday morning

\n\n

Note: Please bring your own laptop. Attendees should be comfortable installing and using common OSINT tools to participate in the live investigation.

\n\nSpeakers:Michael Reimsbach,Rishi \"rxerium\" C
\n
\nSpeakerBio:  Michael Reimsbach, Product Security Specialist at SAP
\n

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services.

\n\n

He obtained multiple industry certifications such as OSCP, GCPN, and CISSP.

\n\n

A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information.

\n\n

Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.

\n\nSpeakerBio:  Rishi \"rxerium\" C, Security Researcher
\n

Rishi is a London-based security researcher with over five years of hands-on experience in IT. He currently specializes in vulnerability research, threat intelligence, and enterprise risk analysis. His current focus lies in identifying and analyzing zero-day vulnerabilities and emerging CVEs, often working to reverse engineer exploit mechanics and build detection logic before public weaponization. Rishi’s work spans both offensive and defensive domains—developing threat models based on real-world TTPs, crafting custom detection rules, and automating reconnaissance pipelines to uncover exploitable misconfigurations and exposed assets. He is particularly active in attack surface management (ASM) and OSINT, where he leverages DNS enumeration, passive data correlation, and large-scale infrastructure scanning to surface unknown entry points and map adversary-accessible exposure. Outside of research, Rishi integrates findings into operational tooling and supports data-driven prioritization strategies to bridge technical risk and business impact. His work reflects a deep commitment to adversary-informed defense and proactive discovery across modern hybrid environments.

\n\n\n\'',NULL,1294466),('2_Friday','14','13:30','14:30','Y','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Zero Day Hire: Can You Spot the Spy?\'','\'Michael Reimsbach,Rishi \"rxerium\" C\'','Creator Events_c2b3ccfe554a5380d9dda086b83a49f1','\'\'',NULL,1294467),('2_Friday','13','13:00','15:59','N','Contests','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'SEC Vishing Competition (SECVC)\'','\'\'','Contests_9ea6b887fc538858cb0c12f030bee4d9','\'Title: SEC Vishing Competition (SECVC)
\nTags: Social Engineering Community Village | Contest
\nWhen: Friday, Aug 7, 13:00 - 15:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Now after our improv break, more teams place live calls, putting polished scripts and fresh research to the test against real corporate defenses in the SECVC! Should out this year years coaches: JC, Jenn, Shadow Fox, and Hall&OSINT.

\n\n\'',NULL,1294468),('2_Friday','14','13:00','15:59','Y','Contests','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'SEC Vishing Competition (SECVC)\'','\'\'','Contests_9ea6b887fc538858cb0c12f030bee4d9','\'\'',NULL,1294469),('2_Friday','15','13:00','15:59','Y','Contests','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'SEC Vishing Competition (SECVC)\'','\'\'','Contests_9ea6b887fc538858cb0c12f030bee4d9','\'\'',NULL,1294470),('2_Friday','15','15:30','16:59','N','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'SE Improv\'','\'Bryan,Kevin\'','Creator Events_f7642349e6e731c6c7d2a15a4e485830','\'Title: SE Improv
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 15:30 - 16:59 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n

Join Kevin and Bryan from Black Box Improv Security for more hands-on activities putting their approach to improv theater to work in social engineering. Following their main-room lunchtime presentation on how improv skills can make or break an SE engagement, they will host a workshop in the SEC Labs that will include chances for participants to immediately put what they learn into practice. There will be games, there will be prizes, and there will inevitably be lots of laughs. There will also be the return of some favorite activities from previous years, including the One-Word Story Competition and Improvised Cold Calls. Attendee participation will not be mandatory, though it is always encouraged.

\n\nSpeakers:Bryan,Kevin
\n
\nSpeakerBio:  Bryan
\nNo BIO available
\nSpeakerBio:  Kevin
\nNo BIO available
\n\n\'',NULL,1294471),('2_Friday','16','15:30','16:59','Y','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'SE Improv\'','\'Bryan,Kevin\'','Creator Events_f7642349e6e731c6c7d2a15a4e485830','\'\'',NULL,1294472),('3_Saturday','16','16:30','17:59','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Cold Calls\'','\'\'','Creator Events_184415633712682a25ccdd7b059dee53','\'Title: Cold Calls
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 16:30 - 17:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Ready for the hot seat? Step into the soundproof booth, grab a mystery target and three escalating objectives, and we\'ll place the call. Run by rekdt, Arty Boy, and Shadow Fox. First come, first served, so get your name on the Cold Call list!

\n\n\'',NULL,1294473),('3_Saturday','17','16:30','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Cold Calls\'','\'\'','Creator Events_184415633712682a25ccdd7b059dee53','\'\'',NULL,1294474),('4_Sunday','11','11:30','12:30','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Cold Calls\'','\'\'','Creator Events_ff3a9a366f5dff9098d4e86bfbd09ef8','\'Title: Cold Calls
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Ready for the hot seat? Step into the soundproof booth, grab a mystery target and three escalating objectives, and we\'ll place the call. Run by rekdt, Arty Boy, and Shadow Fox. First come, first served, so get your name on the Cold Call list!

\n\n\'',NULL,1294475),('4_Sunday','12','11:30','12:30','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Cold Calls\'','\'\'','Creator Events_ff3a9a366f5dff9098d4e86bfbd09ef8','\'\'',NULL,1294476),('2_Friday','16','16:00','17:59','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Cold Calls\'','\'\'','Creator Events_3f19df69eb72211de00d3d222485aed9','\'Title: Cold Calls
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Ready for the hot seat? Step into the soundproof booth, grab a mystery target and three escalating objectives, and we\'ll place the call. Run by rekdt, Arty Boy, and Shadow Fox. First come, first served, so get your name on the Cold Call list!

\n\n\'',NULL,1294477),('2_Friday','17','16:00','17:59','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Cold Calls\'','\'\'','Creator Events_3f19df69eb72211de00d3d222485aed9','\'\'',NULL,1294478),('3_Saturday','10','10:00','10:59','N','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything\'','\'Brian Brushwood\'','Creator Events_fe1420bf8ca607bedc37b90d56cc7bdb','\'Title: Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n

Social engineering not just a specialized skill used by elite hackers, professional con artists, or unnervingly charismatic strangers. In reality, the same few psychological vulnerabilities show up everywhere: in negotiations, job interviews, sales pitches, security breaches, party tricks, and everyday conversations...

\n\n

And YOU can use them, too.

\n\n

In this interactive session, magician and social-engineering educator Brian Brushwood reveals four psychological backdoors that can make people more likely to trust, comply, disclose, and cooperate. You will see each principle demonstrated, learn why it works, and practice using it through safe, low-stakes exercises with other attendees.

\n\n

These are the tricks that can be used by good guys and bad to convince, and build rapport quickly, lower resistance, and make an unlikely request feel surprisingly reasonable.

\n\n

By learning how these techniques feel from the inside, attendees will become better at using influence deliberately, and better at recognizing when someone is using it on them.

\n\n

No previous social-engineering experience is required. Just bring a willingness to talk to strangers, learn a magic trick or two, and discover how alarmingly hackable human beings really are.

\n\nSpeakerBio:  Brian Brushwood
\nBrian Brushwood has spent 25 years teaching millions of people how deception works: first as a touring magician, then as creator/host of Scam School / Scam Nation, host of National Geographic\'s Hacking the System, creator of The Modern Rogue, and host of World\'s Greatest Con. His work focuses on scams, magic, persuasion, social engineering, and the mechanics of trust: how it is built, exploited, defended, and rehearsed. Through Scam School and Scam Nation, Brian spent nearly two decades turning ordinary non-deceivers into capable ethical deceivers, helping them understand cons and persuasion from the inside. Brian has delivered keynotes to audiences of thousands and recently developed an experimental offense-to-defense social engineering curriculum, piloted at Clemson University with CISO John Hoyt.
\n\n\n\n\n\'',NULL,1294479),('3_Saturday','11','11:30','12:30','N','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything\'','\'Brian Brushwood\'','Creator Events_9c5258a03357d4efbbf18b893670d38d','\'Title: Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n

Social engineering not just a specialized skill used by elite hackers, professional con artists, or unnervingly charismatic strangers. In reality, the same few psychological vulnerabilities show up everywhere: in negotiations, job interviews, sales pitches, security breaches, party tricks, and everyday conversations...

\n\n

And YOU can use them, too.

\n\n

In this interactive session, magician and social-engineering educator Brian Brushwood reveals four psychological backdoors that can make people more likely to trust, comply, disclose, and cooperate. You will see each principle demonstrated, learn why it works, and practice using it through safe, low-stakes exercises with other attendees.

\n\n

These are the tricks that can be used by good guys and bad to convince, and build rapport quickly, lower resistance, and make an unlikely request feel surprisingly reasonable.

\n\n

By learning how these techniques feel from the inside, attendees will become better at using influence deliberately, and better at recognizing when someone is using it on them.

\n\n

No previous social-engineering experience is required. Just bring a willingness to talk to strangers, learn a magic trick or two, and discover how alarmingly hackable human beings really are.

\n\nSpeakerBio:  Brian Brushwood
\nBrian Brushwood has spent 25 years teaching millions of people how deception works: first as a touring magician, then as creator/host of Scam School / Scam Nation, host of National Geographic\'s Hacking the System, creator of The Modern Rogue, and host of World\'s Greatest Con. His work focuses on scams, magic, persuasion, social engineering, and the mechanics of trust: how it is built, exploited, defended, and rehearsed. Through Scam School and Scam Nation, Brian spent nearly two decades turning ordinary non-deceivers into capable ethical deceivers, helping them understand cons and persuasion from the inside. Brian has delivered keynotes to audiences of thousands and recently developed an experimental offense-to-defense social engineering curriculum, piloted at Clemson University with CISO John Hoyt.
\n\n\n\n\n\'',NULL,1294480),('3_Saturday','12','11:30','12:30','Y','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything\'','\'Brian Brushwood\'','Creator Events_9c5258a03357d4efbbf18b893670d38d','\'\'',NULL,1294481),('3_Saturday','10','10:15','13:15','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Battle of the Bots: Vishing Edition\'','\'\'','Creator Events_ad875b3eab6dbd55374bb6a88110c2f9','\'Title: Battle of the Bots: Vishing Edition
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:15 - 13:15 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

AI meets vishing in the booth as teams use AI-powered agents to place live calls, chase preset objectives, and test the limits of automation, hacking, and human psychology. Judged by Snow, Perry Carpenter, and Lisa Flynn.

\n\n\'',NULL,1294482),('3_Saturday','11','10:15','13:15','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Battle of the Bots: Vishing Edition\'','\'\'','Creator Events_ad875b3eab6dbd55374bb6a88110c2f9','\'\'',NULL,1294483),('3_Saturday','12','10:15','13:15','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Battle of the Bots: Vishing Edition\'','\'\'','Creator Events_ad875b3eab6dbd55374bb6a88110c2f9','\'\'',NULL,1294484),('3_Saturday','13','10:15','13:15','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Battle of the Bots: Vishing Edition\'','\'\'','Creator Events_ad875b3eab6dbd55374bb6a88110c2f9','\'\'',NULL,1294485),('3_Saturday','13','13:30','14:59','N','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Hook, Line & Pretext Workshop: Crafting Effective Phish\'','\'Jenn,JC\'','Creator Events_08277e66d2e02b46e724ee056abf7226','\'Title: Hook, Line & Pretext Workshop: Crafting Effective Phish
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 13:30 - 14:59 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n

Every effective phishing email is really a marketing email with a hostile goal. It wins attention, builds desire, and drives a single click. This hands-on introductory workshop pulls back the curtain on that craft. In 90 minutes you\'ll learn the persuasion techniques that make a lure irresistible, borrowed straight from the sales and marketing playbook: the handful of influence levers that actually move people, the copywriting structure behind a high-converting message, and the emotional triggers that turn a glance into a click. Then you\'ll add the ingredient that separates a generic blast from a believable one, which is context, using open-source intelligence (OSINT) to tie a lure to a real department, location, or current event so it feels timely and true.\nYou won\'t just watch. After we run the full method end to end against a familiar fictional target, the Scranton branch of Dunder Mifflin, you\'ll roll up your sleeves and build your own department or location wide pretext against a real organization you know. You\'ll walk out able to reason about why people click, not just that they do, with a repeatable process and a finished lure you can take straight back to your own awareness program.\nThis is a content-creation and analysis workshop. No live phishing is conducted and no email is ever sent.\nWho it\'s for: Aspiring and early-career security practitioners, security-awareness and blue-team staff who want to think like an attacker, IT professionals moving toward security, and students or career-changers exploring offensive security. Anyone who builds or improves a phishing-awareness program will get direct, practical value.\nLevel and prerequisites: Introductory. No prior phishing, red-team, or OSINT experience required. You should be comfortable using a web browser and reading professional email. Nothing to install, no coding, no command line.\nWhat to bring\n� A laptop with a web browser, for light open-source research during the lab\n� A real organization you know: your employer, your school or university, a nonprofit or club you belong to, or a former workplace, etc.\n� Something to write with. All worksheets are provided\n� Curiosity and a willingness to share your draft for friendly peer feedback\nWhat you\'ll leave with\n� The three-gates test (legality, then ethics, then morality) for vetting any campaign before it runs\n� A working command of the four influence levers that drive clicks and the \"one hook, one ask, one button\" rule for writing them\n� A repeatable OSINT-to-pretext method for making lures timely and relevant to a department or location\n� A completed Pretext Canvas and a draft, awareness-grade phishing email you can optionally submit to your own organization\'s security-awareness program\nFormat and duration: A hands-on 90 minutes: about 30 minutes of instruction, a 10-minute guided case study against Dunder Mifflin, and roughly 50 minutes of lab with peer review and debrief.\nWhat this workshop is not: It\'s not a tooling or infrastructure course. There are no phishing frameworks, payloads, landing pages, or email spoofing. It\'s not spear-phishing of named individuals; the focus is wide-net, department and location-level pretexts. And nothing is ever sent.

\n\nSpeakers:Jenn,JC
\n
\nSpeakerBio:  Jenn
\n

Jenn (@_nextjenn) is a Senior Offensive Security Consultant and a DEF CON Black Badge holder, earned by winning the vishing competition. With over a decade of cybersecurity experience, she specializes in social engineering, physical security testing, and network penetration testing. Leveraging her background in psychology and experience as a licensed Private Investigator and Locksmith, she has led sophisticated red team engagements across physical penetration testing, phishing, vishing, and deepfake-driven operations. An active mentor and coach in the social engineering community, Jenn has judged DEF CON\'s 2024 \"Humans vs AI\" and 2025 Vishing competitions and shares insights through podcasts and conference talks, including Wild West Hackin\' Fest and San Diego Comic-Con.

\n\nSpeakerBio:  JC, President at Snowfensive
\n

JC is a U.S. Marine Corps veteran, President of Snowfensive, and co-founder of the Social Engineering Community Village at DEF CON. With more than a decade of experience spanning information technology, digital forensics, incident response, penetration testing, and social engineering, he specializes in turning complex security concepts into practical skills people can immediately apply.

\n\n

At Snowfensive, JC oversees the company\'s offensive security services, including phishing, vishing, physical social engineering, covert entry assessments, and technical penetration testing across networks, wireless environments, and applications. He has designed and led human-focused security engagements for organizations across a wide range of industries, combining technical tradecraft with a practical understanding of how people, processes, and technology intersect.

\n\n\n\'',NULL,1294486),('3_Saturday','14','13:30','14:59','Y','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'Hook, Line & Pretext Workshop: Crafting Effective Phish\'','\'Jenn,JC\'','Creator Events_08277e66d2e02b46e724ee056abf7226','\'\'',NULL,1294487),('3_Saturday','14','14:00','14:30','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'For Prompt Injection, Press 1: Hacking AI Voice Agents\'','\'Willie Zhang\'','Creator Talks_acc7304beae6f112c29b68823a4eb525','\'Title: For Prompt Injection, Press 1: Hacking AI Voice Agents
\nTags: Social Engineering Community Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

What happens when you social engineer an AI agent that was trained to be helpful over the phone? Can you get it to reveal its system prompt out loud? Will it disclose information about other callers? How far can you push it before its guardrails kick in? \nAI voice agents sit behind telephony layers like speech-to-text, text-to-speech, and call routing that introduce new attack surfaces and opportunities. They\'re replacing human operators everywhere: answering phones at doctors\' offices, handling IT help desks, triaging customer support, and booking appointments. They sound human, but underneath, they\'re the same LLMs we\'ve been prompt injecting. \nI built an open-source tool that tackles this by placing real phone calls to voice AI agents, speaking attack scenarios using text-to-speech, capturing responses via speech recognition, and analyzing transcripts for signs of successful exploitation. It maps 20 attack scenarios across five categories from the OWASP Top 10 for LLM Applications: prompt injection, sensitive information disclosure, system prompt leakage, excessive agency, and misinformation. Detection uses pattern matching and an LLM judge to catch both obvious and subtle failures.

\n\nSpeakerBio:  Willie Zhang, Offensive Security Consultant
\n

Willie Zhang is an Offensive Security Consultant with experience protecting companies by thinking like an attacker. What started as a $1 online course on ethical hacking in college turned into a career built on finding the gaps in systems that aren\'t supposed to have any. Willie has a growing passion for understanding and attacking AI systems, building on a foundation of testing everything from corporate networks to the humans that run them. When he\'s not learning something new, Willie is in a League of Legends lobby, because apparently cybersecurity isn\'t chaotic enough.

\n\n\n\'',NULL,1294488),('3_Saturday','14','14:30','14:59','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'The Sherlock Holmes Social Engineering Playbook\'','\'Elizabeth Rasnick\'','Creator Talks_1b981b1bd1f2a39fc3130feda3b6b184','\'Title: The Sherlock Holmes Social Engineering Playbook
\nTags: Social Engineering Community Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Long before phishing, deepfakes, and business email compromise, Sherlock Holmes was demonstrating social engineering tactics: building trust, gathering intel, exploiting emotion, and manipulating human behavior to achieve an objective. The tools have changed. The psychology has not. In The Sherlock Holmes Social Engineering Playbook, we examine how Sir Arthur Conan Doyle�s detective stories function as a masterclass in human hacking. Through cases such as A Scandal in Bohemia, The Red-Headed League, and The Sign of Four, this presentation breaks down techniques used to influence decisions, lower defenses, and extract information, many of which mirror modern phishing, OSINT, and fraud campaigns. Through immersive examples and practical cyber parallels, attendees will explore how Holmes used recon, pretexting, impersonation, trust-building, distraction, and emotional leverage to accomplish his goals, and how attackers rely on those tactics today. Participants will leave with a practical social engineering playbook for recognizing manipulation, strengthening human defenses, and thinking critically about the psychology behind cyber threats. Because sometimes the best way to understand today�s attackers� is to study a Victorian detective.

\n\nSpeakerBio:  Elizabeth Rasnick, Assistant Professor at Center for Cybersecurity and Artificial Intelligence at the University of West Florida
\n

Dr. Elizabeth Rasnick is an Assistant Professor at the Center for Cybersecurity and Artificial Intelligence at the University of West Florida. Her work focuses on human-centered cybersecurity, workforce development, cybersecurity education, and the intersection of psychology, storytelling, and social engineering. Dr. Rasnick specializes in translating complex cybersecurity concepts into engaging, accessible learning experiences for technical and non-technical audiences alike. Her research and presentations explore how human behavior, persuasion, trust, and cognitive bias shape modern cyber threats, often through unexpected lenses such as literature, history, and pop culture. She is particularly interested in how classic narratives, including Sherlock Holmes, reveal timeless social engineering tactics still used by attackers today. A frequent speaker, educator, and advocate for interdisciplinary cybersecurity education, Dr. Rasnick works to broaden participation in cybersecurity and prepare the next generation of cyber defenders through innovative, experiential learning. Whether discussing phishing, persuasion, OSINT, or the psychology of manipulation, she believes the most effective security begins with understanding people.

\n\n\n\'',NULL,1294489),('3_Saturday','15','15:00','15:30','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'A Framework for Evaluating AI-Enabled Social Engineering\'','\'Fred Heiding\'','Creator Talks_5c7f46b8cc744d5f91f9ca901d2364ff','\'Title: A Framework for Evaluating AI-Enabled Social Engineering
\nTags: Social Engineering Community Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Large language models (LLMs) can now produce persuasive, personalized phishing content at scale. Yet there is no systematic, reusable benchmark for measuring how this offensive capability varies across models or relates to general capability. We introduce ScamBench: a benchmark and evaluation pipeline for LLM-generated spear phishing. ScamBench contributes (i) a public dataset of over 16,000 personalized phishing emails generated by 20 frontier and open-weight models against 150 synthetic target profiles spanning diverse occupations, life stages, and levels of technical sophistication; (ii) a methodology in which simulated recipients and real human users predict behavioral responses to each email; and (iii) a public leaderboard ranking models by how often their generated emails persuade the target to click a link. Across the 20 models, Claude Opus 4.5 achieves the highest click-through rate at 50.3\\%, while even the weakest model elicits clicks at 29.8\\%. Together, our findings establish AI-enabled social engineering as an empirically measurable capability that scales with frontier models, with ScamBench providing a reusable benchmark for tracking it as models continue to advance.

\n\nSpeakerBio:  Fred Heiding, Researcher at UC Berkeley\'s Center for Long-Term Cybersecurity
\n

Fred Heiding is the executive director of Menlo Park Intelligence and a researcher at UC Berkeley\'s Center for Long-Term Cybersecurity. He was previously a doctoral and postdoctoral researcher at the Harvard School of Engineering and Applied Sciences and the Harvard Kennedy School, working with Bruce Schneier and Eric Rosenbach. He is a member of the World Economic Forum\'s Centre for Cybersecurity and the Geneva Centre for Security Policy, and serves on the committee of the Harvard and MIT Technology and National Security Conference. He has taught several AI and cybersecurity classes at Harvard, regularly briefs the U.S. Congress on AI-powered cyber threats, and advises foreign governments on national cyber risks. His work has been featured at leading conferences, journals, and media outlets, including The Economist, Reuters, TIME, and Foreign Affairs. Fred has assisted in the discovery of more than 45 critical computer vulnerabilities (CVEs), and he previously made headlines for hacking the King of Sweden and the European Commissioner.

\n\n\n\'',NULL,1294490),('3_Saturday','15','15:30','17:30','N','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'2027 SECVC Pre-Qualification Round\'','\'JC,Snow\'','Creator Events_0cc72d216ff87fae6225167446d5a597','\'Title: 2027 SECVC Pre-Qualification Round
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 15:30 - 17:30 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n

Think you have what it takes to compete in the 2027 Social Engineering Community Vishing Competition? This first-come, first-served SECVC Pre-Qual event gives attendees an early opportunity to qualify for next year�s competition. Note teams consist of 1 or 2 memebers. During the lab, each team will be assigned a target company and receive instructions, guidance, and dedicated Q&A time with SEC founders JC and Snow. Teams will conduct OSINT on their assigned company, develop potential pretexts, and prepare a short submission using a link provided before the lab closes. The top five teams will be selected and notified by email before 8:00 PM that evening. Those teams will advance to the live-call qualification round in the village on Sunday, August 9, 2026. Following the live calls, up to all five teams will earn a spot in the 2027 SEC Vishing Competition. Participants should bring a laptop or another device with internet access that can be used to conduct OSINT and submit their materials.

\n\nSpeakers:JC,Snow
\n
\nSpeakerBio:  JC, President at Snowfensive
\n

JC is a U.S. Marine Corps veteran, President of Snowfensive, and co-founder of the Social Engineering Community Village at DEF CON. With more than a decade of experience spanning information technology, digital forensics, incident response, penetration testing, and social engineering, he specializes in turning complex security concepts into practical skills people can immediately apply.

\n\n

At Snowfensive, JC oversees the company\'s offensive security services, including phishing, vishing, physical social engineering, covert entry assessments, and technical penetration testing across networks, wireless environments, and applications. He has designed and led human-focused security engagements for organizations across a wide range of industries, combining technical tradecraft with a practical understanding of how people, processes, and technology intersect.

\n\nSpeakerBio:  Snow
\nNo BIO available
\n\n\'',NULL,1294491),('3_Saturday','16','15:30','17:30','Y','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'2027 SECVC Pre-Qualification Round\'','\'JC,Snow\'','Creator Events_0cc72d216ff87fae6225167446d5a597','\'\'',NULL,1294492),('3_Saturday','17','15:30','17:30','Y','Social Engineering Community Village','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'2027 SECVC Pre-Qualification Round\'','\'JC,Snow\'','Creator Events_0cc72d216ff87fae6225167446d5a597','\'\'',NULL,1294493),('3_Saturday','15','15:30','15:59','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'What Scammers Know That Social Engineers Don\'t: Three Techniques for Tough Cases\'','\'Megan Squire\'','Creator Talks_137771a6534d0d9ad5ccbc3f98265162','\'Title: What Scammers Know That Social Engineers Don\'t: Three Techniques for Tough Cases
\nTags: Social Engineering Community Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

Most social engineering training teaches techniques that exploit emotional triggers like urgency, fear, or flattery. But what happens when the target has been trained to spot these and they are on high alert? In this talk I will demonstrate three techniques I\'ve learned from studying career scammers for my research at F-Secure, and I\'ll show you how to apply them to your social engineering operations. All three of these techniques work specifically for targets who have been already primed against falling for scams and other social engineering exploits. In other words, these are techniques designed for your tough cases. First, I\'ll demonstrate Awareness Hijacking, where the operator uses the target\'s knowledge of one scam to trap them in a different one. Then I\'ll show Complexity-as-Crucible, where the operator engineers a scenario that lets them become the target\'s trusted guide. Finally, I\'ll demonstrate the First Win, where the operator purposely lets the target \"beat the scam\" without realizing they\'ve actually entrapped themselves. Participants will leave with three new techniques that are directly applicable to red team social engineering engagements where the targets may be on high alert or trained against falling for more traditional manipulation techniques.

\n\nSpeakerBio:  Megan Squire, Principal Threat Intelligence Researcher at F-Secure
\n

Dr. Megan Squire is a Principal threat intelligence researcher at F-Secure, where she studies AI safety, scams, and fraud. Before moving into threat intel, she spent over a decade studying online recruitment, illicit finance, and adversary networks in the domestic violent extremism domain. Her work on threat intelligence and OSINT has been featured in WIRED, The New York Times, PBS-Frontline, The Washington Post, and Dark Reading.

\n\n\n\'',NULL,1294494),('3_Saturday','16','16:00','16:30','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Wolfmasking: Teaching Everyday Defenders to Think Like Social Engineers\'','\'Brian Brushwood\'','Creator Talks_87d4da70d72c6149571e64de72861ad6','\'Title: Wolfmasking: Teaching Everyday Defenders to Think Like Social Engineers
\nTags: Social Engineering Community Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\nMost security awareness training keeps people in the role of prey: memorize red flags, stay vigilant, and hope your System 2 brain has enough calories left when the real attack arrives. Wolfmasking is supervised deceptive roleplay: everyday defenders safely rehearse the attacker�s moves, develop a mental model of the predator, then return to defense with better instincts. This talk presents lessons and examples from a field pilot tested at Clemson University with support from CISO John Hoyt, in which roughly 80 nursing freshmen learned to construct benign social-engineering challenges, compete against one another, and report each other�s attempts. The point was not to create attackers, but to create an identity shift: Students began shifting from hypothetical victims into former players: people who recognize pretext, authority, urgency, trust transfer, and emotional pressure not because they were \"staying vigilant,\" but because they have practiced those moves themselves I will share the four-lesson structure, guardrails, incentives, surprises, failures, and why �practice being fooled� may matter less than �practice doing the fooling safely.� I�ll use a quick magic example to show the gap between hypothetical knowledge and lived deceptive experience. This is not a product pitch. It is a field report on a new training pedagogy for social engineering resilience.
\n\n\n\nSpeakerBio:  Brian Brushwood
\nBrian Brushwood has spent 25 years teaching millions of people how deception works: first as a touring magician, then as creator/host of Scam School / Scam Nation, host of National Geographic\'s Hacking the System, creator of The Modern Rogue, and host of World\'s Greatest Con. His work focuses on scams, magic, persuasion, social engineering, and the mechanics of trust: how it is built, exploited, defended, and rehearsed. Through Scam School and Scam Nation, Brian spent nearly two decades turning ordinary non-deceivers into capable ethical deceivers, helping them understand cons and persuasion from the inside. Brian has delivered keynotes to audiences of thousands and recently developed an experimental offense-to-defense social engineering curriculum, piloted at Clemson University with CISO John Hoyt.
\n\n\n\n\n\'',NULL,1294495),('4_Sunday','10','10:00','10:30','N','Contests','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'Contest Awards\'','\'\'','Contests_f5af92f1f7e4b2984b7c302540b1249d','\'Title: Contest Awards
\nTags: Social Engineering Community Village | Contest
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

See who won in our village! During this time we\'ll present the SECVC and BOTB winners, as well as the much-coveted Dundies!

\n\n\'',NULL,1294496),('4_Sunday','10','10:30','11:30','N','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'2027 SECVC Pre-Qualification Round - LIVE CALLS\'','\'\'','Creator Events_82a4a7ebdb0b89c540a2a6aecfd74bea','\'Title: 2027 SECVC Pre-Qualification Round - LIVE CALLS
\nTags: Social Engineering Community Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 3 W317-319 (Social Engineering Community Village) - Map
\n
\nDescription:
\n

The top five scoring teams from the SECVC Pre-Qual Lab will return to the village to put their research and pretexts into action through live vishing calls. Based on their performance, some teams may earn a spot in the 2027 Social Engineering Community Vishing Competition.

\n\n\'',NULL,1294497),('4_Sunday','11','10:30','11:30','Y','Social Engineering Community Village','LVCCW Level 3 W317-319 (Social Engineering Community Village)','\'2027 SECVC Pre-Qualification Round - LIVE CALLS\'','\'\'','Creator Events_82a4a7ebdb0b89c540a2a6aecfd74bea','\'\'',NULL,1294498),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_7982b59b14638e105a17fdbf247a8ac4','\'Title: Escalation Desk CTF
\nTags: Call Center Village | Escalation Desk CTF | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W218 (Call Center Village) - Map
\n
\nDescription:
\n

Customer service channels are increasingly saturated with conversational text and voice AI agents. Can you convince, trick, or break enough of them to earn your shot at a live human operator in a real-world call center?

\n\n

Escalation Desk is Call Center Village\'s capture-the-flag challenge. Start with low-pressure AI agents and learn how to spot, avoid, and exploit common pitfalls and patterns in system prompts — eventually unlocking live human operators at our partner call centers. A real-time leaderboard tracks solo and team progress, with our not-so-famous Golden Telephone Booth trophy awarded to the top participant.

\n\n

Hit our minimum point threshold and earn a special Call Center Village 100 Trying black flight tag. The top individual and their team also take home the rare Call Center Village 200 OK gold flight tags. Bring your tags to Party Line, Call Center Village\'s after-hours telephony-themed party, and enjoy free refreshments for your spoils.

\n\n

Escalation Desk is beginner (and introvert) friendly — if you can dial a phone number or use a keyboard, you can participate. Bring your own laptop and headset, or use one of our village stations. Active Noise-canceling headphones with a microphone are highly recommended.

\n\n

The CTF will run during village hours, pausing when the village closes each night, and ends on Sunday at 12:00.

\n\n\'',NULL,1294499),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_7982b59b14638e105a17fdbf247a8ac4','\'\'',NULL,1294500),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_7982b59b14638e105a17fdbf247a8ac4','\'\'',NULL,1294501),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_7982b59b14638e105a17fdbf247a8ac4','\'\'',NULL,1294502),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_7982b59b14638e105a17fdbf247a8ac4','\'\'',NULL,1294503),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_7982b59b14638e105a17fdbf247a8ac4','\'\'',NULL,1294504),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_7982b59b14638e105a17fdbf247a8ac4','\'\'',NULL,1294505),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_7982b59b14638e105a17fdbf247a8ac4','\'\'',NULL,1294506),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3170f283886c362e0d905fd0f2b2eaf9','\'Title: Escalation Desk CTF
\nTags: Call Center Village | Escalation Desk CTF | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W218 (Call Center Village) - Map
\n
\nDescription:
\n

Customer service channels are increasingly saturated with conversational text and voice AI agents. Can you convince, trick, or break enough of them to earn your shot at a live human operator in a real-world call center?

\n\n

Escalation Desk is Call Center Village\'s capture-the-flag challenge. Start with low-pressure AI agents and learn how to spot, avoid, and exploit common pitfalls and patterns in system prompts — eventually unlocking live human operators at our partner call centers. A real-time leaderboard tracks solo and team progress, with our not-so-famous Golden Telephone Booth trophy awarded to the top participant.

\n\n

Hit our minimum point threshold and earn a special Call Center Village 100 Trying black flight tag. The top individual and their team also take home the rare Call Center Village 200 OK gold flight tags. Bring your tags to Party Line, Call Center Village\'s after-hours telephony-themed party, and enjoy free refreshments for your spoils.

\n\n

Escalation Desk is beginner (and introvert) friendly — if you can dial a phone number or use a keyboard, you can participate. Bring your own laptop and headset, or use one of our village stations. Active Noise-canceling headphones with a microphone are highly recommended.

\n\n

The CTF will run during village hours, pausing when the village closes each night, and ends on Sunday at 12:00.

\n\n\'',NULL,1294507),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3170f283886c362e0d905fd0f2b2eaf9','\'\'',NULL,1294508),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3170f283886c362e0d905fd0f2b2eaf9','\'\'',NULL,1294509),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3170f283886c362e0d905fd0f2b2eaf9','\'\'',NULL,1294510),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3170f283886c362e0d905fd0f2b2eaf9','\'\'',NULL,1294511),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3170f283886c362e0d905fd0f2b2eaf9','\'\'',NULL,1294512),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3170f283886c362e0d905fd0f2b2eaf9','\'\'',NULL,1294513),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3170f283886c362e0d905fd0f2b2eaf9','\'\'',NULL,1294514),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3a8bd345e0a83d99df2612c1d23ff894','\'Title: Escalation Desk CTF
\nTags: Call Center Village | Escalation Desk CTF | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W218 (Call Center Village) - Map
\n
\nDescription:
\n

Customer service channels are increasingly saturated with conversational text and voice AI agents. Can you convince, trick, or break enough of them to earn your shot at a live human operator in a real-world call center?

\n\n

Escalation Desk is Call Center Village\'s capture-the-flag challenge. Start with low-pressure AI agents and learn how to spot, avoid, and exploit common pitfalls and patterns in system prompts — eventually unlocking live human operators at our partner call centers. A real-time leaderboard tracks solo and team progress, with our not-so-famous Golden Telephone Booth trophy awarded to the top participant.

\n\n

Hit our minimum point threshold and earn a special Call Center Village 100 Trying black flight tag. The top individual and their team also take home the rare Call Center Village 200 OK gold flight tags. Bring your tags to Party Line, Call Center Village\'s after-hours telephony-themed party, and enjoy free refreshments for your spoils.

\n\n

Escalation Desk is beginner (and introvert) friendly — if you can dial a phone number or use a keyboard, you can participate. Bring your own laptop and headset, or use one of our village stations. Active Noise-canceling headphones with a microphone are highly recommended.

\n\n

The CTF will run during village hours, pausing when the village closes each night, and ends on Sunday at 12:00.

\n\n\'',NULL,1294515),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 2 W218 (Call Center Village)','\'Escalation Desk CTF\'','\'\'','Contests_3a8bd345e0a83d99df2612c1d23ff894','\'\'',NULL,1294516),('4_Sunday','10','10:00','13:59','N','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_d69ba589a3535893e3fd76e73c2902e5','\'Title: Call Center Village - Open
\nTags: Call Center Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W218 (Call Center Village) - Map
\n
\nDescription:
\n

Security teams have spent years hardening web-apps, email-gateways, and network-perimeters. Meanwhile, the phone line sitting on every receptionist\'s desk remains almost completely unmonitored. Nobody\'s deploying a firewall between a caller and the person who picks up. Caller ID authentication has made some progress, but the conversation itself? Wide open.

\n\n

And now that AI-generated voices can pass for the real thing and automated agents are handling account resets and payment processing, that gap is getting a lot more interesting.Call Center Village is where voice security, conversational AI, and social engineering collide — across both voice and text channels.

\n\n

Sit down at a workstation and synthesize a copy of your own voice with open-source tools running on a local GPU, or let our staff walk you through the process. Dig into voice pipelines, deepfake audio detection, and the arms race between the two. Wire up a working conversational AI agent — stitching together the real-time audio infrastructure, transcription, language model, and speech synthesis that make these systems speak.

\n\n

On the text side, go after chatbot agents tasked with handling simulated customer interactions. Find the cracks in their system prompts, hijack conversation logic, and convince them to do things their developers never intended. Once you\'re ready, muster all your skills to take on our Escalation Desk CTF, the official Call Center Village contest at DEF CON 34.

\n\n

We\'ve also got a collection of vintage telephones, prank extensions, chatty AI-agents, and a British-style telephone booth worth stopping by for.

\n\n

No prior experience required. If you know how to make a phone call or type a message, you\'re already qualified. Equipment is provided, including laptops and ANC headsets - but you\'re more than welcome to bring your own devices.

\n\n\'',NULL,1294517),('4_Sunday','11','10:00','13:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_d69ba589a3535893e3fd76e73c2902e5','\'\'',NULL,1294518),('4_Sunday','12','10:00','13:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_d69ba589a3535893e3fd76e73c2902e5','\'\'',NULL,1294519),('4_Sunday','13','10:00','13:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_d69ba589a3535893e3fd76e73c2902e5','\'\'',NULL,1294520),('2_Friday','10','10:00','17:59','N','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_2215c7d7e2c538bc7425b809c74cd96b','\'Title: Call Center Village - Open
\nTags: Call Center Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W218 (Call Center Village) - Map
\n
\nDescription:
\n

Security teams have spent years hardening web-apps, email-gateways, and network-perimeters. Meanwhile, the phone line sitting on every receptionist\'s desk remains almost completely unmonitored. Nobody\'s deploying a firewall between a caller and the person who picks up. Caller ID authentication has made some progress, but the conversation itself? Wide open.

\n\n

And now that AI-generated voices can pass for the real thing and automated agents are handling account resets and payment processing, that gap is getting a lot more interesting.Call Center Village is where voice security, conversational AI, and social engineering collide — across both voice and text channels.

\n\n

Sit down at a workstation and synthesize a copy of your own voice with open-source tools running on a local GPU, or let our staff walk you through the process. Dig into voice pipelines, deepfake audio detection, and the arms race between the two. Wire up a working conversational AI agent — stitching together the real-time audio infrastructure, transcription, language model, and speech synthesis that make these systems speak.

\n\n

On the text side, go after chatbot agents tasked with handling simulated customer interactions. Find the cracks in their system prompts, hijack conversation logic, and convince them to do things their developers never intended. Once you\'re ready, muster all your skills to take on our Escalation Desk CTF, the official Call Center Village contest at DEF CON 34.

\n\n

We\'ve also got a collection of vintage telephones, prank extensions, chatty AI-agents, and a British-style telephone booth worth stopping by for.

\n\n

No prior experience required. If you know how to make a phone call or type a message, you\'re already qualified. Equipment is provided, including laptops and ANC headsets - but you\'re more than welcome to bring your own devices.

\n\n\'',NULL,1294521),('2_Friday','11','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_2215c7d7e2c538bc7425b809c74cd96b','\'\'',NULL,1294522),('2_Friday','12','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_2215c7d7e2c538bc7425b809c74cd96b','\'\'',NULL,1294523),('2_Friday','13','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_2215c7d7e2c538bc7425b809c74cd96b','\'\'',NULL,1294524),('2_Friday','14','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_2215c7d7e2c538bc7425b809c74cd96b','\'\'',NULL,1294525),('2_Friday','15','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_2215c7d7e2c538bc7425b809c74cd96b','\'\'',NULL,1294526),('2_Friday','16','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_2215c7d7e2c538bc7425b809c74cd96b','\'\'',NULL,1294527),('2_Friday','17','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_2215c7d7e2c538bc7425b809c74cd96b','\'\'',NULL,1294528),('3_Saturday','10','10:00','17:59','N','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_e9f4c97772a83ee427fa80d3365ffba3','\'Title: Call Center Village - Open
\nTags: Call Center Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W218 (Call Center Village) - Map
\n
\nDescription:
\n

Security teams have spent years hardening web-apps, email-gateways, and network-perimeters. Meanwhile, the phone line sitting on every receptionist\'s desk remains almost completely unmonitored. Nobody\'s deploying a firewall between a caller and the person who picks up. Caller ID authentication has made some progress, but the conversation itself? Wide open.

\n\n

And now that AI-generated voices can pass for the real thing and automated agents are handling account resets and payment processing, that gap is getting a lot more interesting.Call Center Village is where voice security, conversational AI, and social engineering collide — across both voice and text channels.

\n\n

Sit down at a workstation and synthesize a copy of your own voice with open-source tools running on a local GPU, or let our staff walk you through the process. Dig into voice pipelines, deepfake audio detection, and the arms race between the two. Wire up a working conversational AI agent — stitching together the real-time audio infrastructure, transcription, language model, and speech synthesis that make these systems speak.

\n\n

On the text side, go after chatbot agents tasked with handling simulated customer interactions. Find the cracks in their system prompts, hijack conversation logic, and convince them to do things their developers never intended. Once you\'re ready, muster all your skills to take on our Escalation Desk CTF, the official Call Center Village contest at DEF CON 34.

\n\n

We\'ve also got a collection of vintage telephones, prank extensions, chatty AI-agents, and a British-style telephone booth worth stopping by for.

\n\n

No prior experience required. If you know how to make a phone call or type a message, you\'re already qualified. Equipment is provided, including laptops and ANC headsets - but you\'re more than welcome to bring your own devices.

\n\n\'',NULL,1294529),('3_Saturday','11','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_e9f4c97772a83ee427fa80d3365ffba3','\'\'',NULL,1294530),('3_Saturday','12','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_e9f4c97772a83ee427fa80d3365ffba3','\'\'',NULL,1294531),('3_Saturday','13','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_e9f4c97772a83ee427fa80d3365ffba3','\'\'',NULL,1294532),('3_Saturday','14','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_e9f4c97772a83ee427fa80d3365ffba3','\'\'',NULL,1294533),('3_Saturday','15','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_e9f4c97772a83ee427fa80d3365ffba3','\'\'',NULL,1294534),('3_Saturday','16','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_e9f4c97772a83ee427fa80d3365ffba3','\'\'',NULL,1294535),('3_Saturday','17','10:00','17:59','Y','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'Call Center Village - Open\'','\'\'','Creator Events_e9f4c97772a83ee427fa80d3365ffba3','\'\'',NULL,1294536),('2_Friday','15','15:00','15:59','N','Call Center Village','LVCCW Level 2 W218 (Call Center Village)','\'An Intrusion in the Living Room is now an international incident: SuperBOX Part 3\'','\'D3adA55\'','Creator Talks_d15a9c96facc5529dfe3982f3fdcb50b','\'Title: An Intrusion in the Living Room is now an international incident: SuperBOX Part 3
\nTags: Call Center Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 2 W218 (Call Center Village) - Map
\n
\nDescription:
\n

Free cable box, or Chinese-controlled botnet node? Darknet Diaries Ep. 172 exposed SuperBox as both. Part 3 breaks down how one sketchy streaming device turned a living room into a national security case.

\n\nSpeakerBio:  D3adA55
\nNo BIO available
\n\n\'',NULL,1294537),('4_Sunday','10','10:00','11:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_10a2dbe940a16772dd943f98f9d6bff2','\'Title: Mobile Hacking - Informal CTF
\nTags: Mobile Hacking Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

Capture the Flag (CTF) events featuring mobile application security challenges at varying levels of difficulty, also providing a ranking system to evaluate and compare participants’ skills.

\n\nLinks:
    Discord - https://discord.gg/dHW7PVSCzY
\n\'',NULL,1294538),('4_Sunday','11','10:00','11:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_10a2dbe940a16772dd943f98f9d6bff2','\'\'',NULL,1294539),('2_Friday','10','10:00','17:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_429219a62e2681f13983fb8eb0ddd7c4','\'Title: Mobile Hacking - Informal CTF
\nTags: Mobile Hacking Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

Capture the Flag (CTF) events featuring mobile application security challenges at varying levels of difficulty, also providing a ranking system to evaluate and compare participants’ skills.

\n\nLinks:
    Discord - https://discord.gg/dHW7PVSCzY
\n\'',NULL,1294540),('2_Friday','11','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_429219a62e2681f13983fb8eb0ddd7c4','\'\'',NULL,1294541),('2_Friday','12','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_429219a62e2681f13983fb8eb0ddd7c4','\'\'',NULL,1294542),('2_Friday','13','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_429219a62e2681f13983fb8eb0ddd7c4','\'\'',NULL,1294543),('2_Friday','14','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_429219a62e2681f13983fb8eb0ddd7c4','\'\'',NULL,1294544),('2_Friday','15','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_429219a62e2681f13983fb8eb0ddd7c4','\'\'',NULL,1294545),('2_Friday','16','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_429219a62e2681f13983fb8eb0ddd7c4','\'\'',NULL,1294546),('2_Friday','17','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_429219a62e2681f13983fb8eb0ddd7c4','\'\'',NULL,1294547),('3_Saturday','10','10:00','17:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_142e7b0f0191e273876492a99ec3797c','\'Title: Mobile Hacking - Informal CTF
\nTags: Mobile Hacking Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

Capture the Flag (CTF) events featuring mobile application security challenges at varying levels of difficulty, also providing a ranking system to evaluate and compare participants’ skills.

\n\nLinks:
    Discord - https://discord.gg/dHW7PVSCzY
\n\'',NULL,1294548),('3_Saturday','11','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_142e7b0f0191e273876492a99ec3797c','\'\'',NULL,1294549),('3_Saturday','12','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_142e7b0f0191e273876492a99ec3797c','\'\'',NULL,1294550),('3_Saturday','13','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_142e7b0f0191e273876492a99ec3797c','\'\'',NULL,1294551),('3_Saturday','14','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_142e7b0f0191e273876492a99ec3797c','\'\'',NULL,1294552),('3_Saturday','15','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_142e7b0f0191e273876492a99ec3797c','\'\'',NULL,1294553),('3_Saturday','16','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_142e7b0f0191e273876492a99ec3797c','\'\'',NULL,1294554),('3_Saturday','17','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking - Informal CTF\'','\'\'','Creator Events_142e7b0f0191e273876492a99ec3797c','\'\'',NULL,1294555),('2_Friday','10','10:00','10:45','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Bypassing KYC Vendors on AI Times\'','\'Juan Urbano Stordeur,Juan Martinez Blanco\'','Creator Talks_c9447c0b315a14fd7d3d46b7ef2ffc6b','\'Title: Bypassing KYC Vendors on AI Times
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

In this talk, the Just Mobile Security team will talk about the KYC implementation, how to bypass them, and some 0 days for vendors.

\n\nSpeakers:Juan Urbano Stordeur,Juan Martinez Blanco
\n
\nSpeakerBio:  Juan Urbano Stordeur, CEO and Founder at Just Mobile Security
\nNo BIO available
\nSpeakerBio:  Juan Martinez Blanco, Mobile Security Penetration Tester at Just Mobile Security
\nNo BIO available
\n\n\'',NULL,1294556),('2_Friday','11','11:00','11:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'AI finds and writes my Android exploits now\'','\'Ken Gannon / 伊藤 剣\'','Creator Events_0aabf7a3da962aa3888332a43c416974','\'Title: AI finds and writes my Android exploits now
\nTags: Mobile Hacking Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

For years, Ken has found and written exploits for Android which ended up winning multiple Pwn2Own competitions. This year, he hasn\'t found or written a single exploit. Instead, AI does everything now, from reconnaissance to exploitation to writing bug bounty reports. This is thanks to the AI mobile testing tool, Djini, and the new feature that Ken helped program, called \"Deep Scan\". Thanks to \"Deep Scan\", Pwn2Own-level exploits can now be found autonomously. Ken will demonstrate the \"Deep Scan\" feature on stage, and talk about some of the various exploits that were found thanks to this feature.

\n\nSpeakerBio:  Ken Gannon / 伊藤 剣, Mobile Hacking Lab
\nNo BIO available
\n\n\'',NULL,1294557),('2_Friday','12','12:15','12:45','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Offensive Security from Your Pocket\'','\'Lukas Stefanko\'','Creator Talks_9c7903fb8cf0900e7528385358dec0ff','\'Title: Offensive Security from Your Pocket
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:15 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

Smartphones are powerful—but so are the threats targeting them. This talk explores real-world mobile attack techniques through demonstrations, including rogue Wi-Fi access points for data interception, Android app manipulation with Frida, and using Kali NetHunter on rooted devices for portable offensive operations.

\n\n

I\'ll showcase hardware-based attacks like BadUSB cables, wireless exploitation via Bluetooth vulnerabilities, and NFC relay threats, alongside insights into modern mobile malware capabilities. Each technique is paired with practical mitigation strategies, giving attendees both offensive understanding and defensive takeaways to better secure mobile ecosystems.

\n\nSpeakerBio:  Lukas Stefanko, Senior Malware Researcher at ESET
\n

Lukas Stefanko is an experienced senior malware researcher with a strong engineering background and a well-demonstrated focus on Android malware research and security. With more than 14 years\' experience with malware, he has been focusing on improving detection mechanisms of Android malware and in the past couple of years has made major strides towards heightening public awareness around mobile threats and app vulnerabilities. He has presented at several security conferences such as RSA, Virus Bulletin, Confidence, DefCamp, BountyCon, AVAR, Ekoparty and others.

\n\n\n\'',NULL,1294558),('2_Friday','13','13:00','14:30','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Hacking Android Apps in a Structured Way\'','\'Sven Schleier\'','Creator Events_216a44141a4c5b9e60d53b3e8733cf0d','\'Title: Hacking Android Apps in a Structured Way
\nTags: Mobile Hacking Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 13:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

Mobile app testing has many pitfalls, and a structured approach is needed to see the full attack surface. This workshop gives a practical introduction to the OWASP Mobile Application Security (MAS) project — MASVS, MASWE, and MASTG — with hands-on static and dynamic analysis of real Android apps using tools like semgrep, APKLeaks, and jadx. Bring a laptop with 10 GB free disk space, a GitHub account, Android Studio and git installed (see https://github.com/sushi2k/defcon34-android-workshop-friday).

\n\nSpeakerBio:  Sven Schleier, Co-Founder at Bai7 GmbH
\n

Sven has been involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project lead and author, he has made significant contributions to the OWASP MAS (Mobile Application Security) project, which is considered the industry standard for mobile application security, see https://mas.owasp.org.

\n\n

Sven is a frequent speaker and trainer around the world. His audiences range from software developers to students and penetration testers. His engagements often take him to conferences, forums and educational institutions, where he shares his extensive knowledge and insights on mobile and application security.

\n\n

--

\n\n

Sven is a co-founder of Bai7 GmbH in Austria, which is specialized in trainings and advisory. He has expertise in cloud security, offensive security engagements (Penetration Testing) and Application Security, notably in guiding software development teams across Mobile and Web Applications throughout the Software Development Life Cycle (SDLC) to integrate robust security measures in from the start.

\n\n

Besides his day job, Sven is involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project leader and author, he has significantly contributed to the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Application Security Verification Standard (MASVS).

\n\n\n\'',NULL,1294559),('2_Friday','14','13:00','14:30','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Hacking Android Apps in a Structured Way\'','\'Sven Schleier\'','Creator Events_216a44141a4c5b9e60d53b3e8733cf0d','\'\'',NULL,1294560),('2_Friday','15','15:00','15:45','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Security through Obscurity, from insecure client-side encryption to unauthenticated SQL\'','\'Juan Urbano Stordeur,Juan Martinez Blanco\'','Creator Talks_51b8d6fb7241a37960f69eea23535ce4','\'Title: Mobile Security through Obscurity, from insecure client-side encryption to unauthenticated SQL
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

In this talk the Just Mobile Security team will talk about the Mobile Security through Obscurity, from insecure client-side encryption to unauthenticated SQLi. Talking about a lot of LATAM Banks and Fintechs who implemented that in their applications.

\n\nSpeakers:Juan Urbano Stordeur,Juan Martinez Blanco
\n
\nSpeakerBio:  Juan Urbano Stordeur, CEO and Founder at Just Mobile Security
\nNo BIO available
\nSpeakerBio:  Juan Martinez Blanco, Mobile Security Penetration Tester at Just Mobile Security
\nNo BIO available
\n\n\'',NULL,1294561),('2_Friday','16','16:00','16:30','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Leveraging Frida to Bypass Mobile Application Security Controls\'','\'Jarrod Rizor\'','Creator Talks_fb53dff40ea484799048c49e5b98bff8','\'Title: Leveraging Frida to Bypass Mobile Application Security Controls
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

This talk introduces Frida, covering what it is, its capabilities, and how to leverage it during a penetration test. I\'ll walk through a recent penetration test where I used Frida to run an application on a jailbroken device, bypassing the app\'s jailbreak detection. We\'ll review and use Frida scripts to enumerate and identify classes and methods to pinpoint security protections, and I\'ll show how I leveraged a pre-built Frida script from Frida CodeShare to bypass those controls and run the application on a jailbroken iPad.

\n\nSpeakerBio:  Jarrod Rizor, Offensive Services Team Lead of Web & Mobile Application Testing at FRSecure
\n

My name is Jarrod Rizor and I\'m an Offensive Services Team Lead of Web & Mobile Application Testing at FRSecure. Birds of Prey Rehab Volunteer.

\n\n\n\'',NULL,1294562),('3_Saturday','10','10:00','10:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'RedMatter: Let AI Write Your Cross-Platform Mobile Exploits\'','\'Subho Halder\'','Creator Talks_c7f73f6b68f42c2fa5314a0a25f0e830','\'Title: RedMatter: Let AI Write Your Cross-Platform Mobile Exploits
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\nLive demo:
\nRedmatter kills the rewrite. You describe the attack you want in plain language like, bypass the pinning, dump the keychain, defeat the root check, and an AI layer generates the platform-specific Frida instrumentation for both the iOS and Android build of the same app. The harness orchestrates the run, adapts when the app fights back (new detection logic, obfuscation, a symbol that moved), and captures the evidence. You stay in the loop; the AI eats the tedious per-platform translation that used to eat your engagement.
\n\n

Key takeaways:\n- Describe an attack in plain English on stage, watch the AI emit working iOS and Android modules, and fire them live on both builds side by side. - Throw a hardened target at it, like anti-Frida, pinning, root detection stacked, and let the harness adapt in real time.

\n\nSpeakerBio:  Subho Halder, Founder at MatterSec Labs
\n

Subho Halder is the founder of MatterSec Labs, an AI security company, and a mobile security researcher with over a decade in offensive AppSec. He is the author of the Android Framework for Exploitation (AFE), one of the early open-source toolkits for Android app exploitation, which he has used to train operators on the BlackHat US instructor circuit. More recently he released KnoxSpy, a Frida-based instrumentation tool for intercepting MDM-protected traffic, at BlackHat Europe Arsenal 2025.

\n\n

Before MatterSec, he co-founded Appknox, a mobile application security platform, and ran it for over ten years. His work sits at the intersection of iOS/Android binary analysis, runtime instrumentation, and AI-driven offensive tooling. He is now building Redmatter, the open-source harness debuting in this talk.

\n\n\n\'',NULL,1294563),('3_Saturday','11','11:15','12:15','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'An Android voyage from Java to Smali with ASM\'','\'Ricardo Loura\'','Creator Talks_571232497533e3f1752c32a6c86213ce','\'Title: An Android voyage from Java to Smali with ASM
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:15 - 12:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

The Java programming language is the backbone of almost all Android applications, yet its compilation process is often discarded. Behind the scenes, a complex series of bytecode transformations takes place, and tools such as ASM allow anyone to hook into the process and alter the flow to achieve better performance, obfuscation, compile-time code injection, ... In this talk, we\'ll explore how this tool works, how it can be used, and the deep pitfalls to look out for when performing Java bytecode manipulation.

\n\nSpeakerBio:  Ricardo Loura
\nNo BIO available
\n\n\'',NULL,1294564),('3_Saturday','12','11:15','12:15','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'An Android voyage from Java to Smali with ASM\'','\'Ricardo Loura\'','Creator Talks_571232497533e3f1752c32a6c86213ce','\'\'',NULL,1294565),('3_Saturday','12','12:30','12:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Triage vs. Reality: Mobile Security Findings in Bug Bounty\'','\'fr4vian\'','Creator Talks_dc175f765ebccd0c0666e20982c689e7','\'Title: Triage vs. Reality: Mobile Security Findings in Bug Bounty
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

Mobile bug bounty has matured significantly, but the way mobile vulnerabilities are evaluated has not kept pace. Researchers frequently encounter findings that don’t fit neatly into traditional scoring frameworks, rely on application-specific threat models, or require multiple seemingly low-impact issues to demonstrate meaningful risk. The result is inconsistent triage, misunderstood impact, and unnecessary friction between researchers and programs.

\n\n

This talk explores why mobile security findings are uniquely challenging to assess and where current bug bounty processes fall short. We’ll examine common pitfalls in mobile triage, discuss the limitations of applying generic scoring systems such as CVSS to mobile vulnerabilities, and look at real-world examples where technical severity and triage outcomes diverged.

\n\nSpeakerBio:  fr4vian
\nNo BIO available
\n\n\'',NULL,1294566),('3_Saturday','15','15:00','15:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Beerus Framework – A New Mobile Framework Arises\'','\'João Pedro Tricta,Daniel \"Daniboy\" França Lima\'','Creator Talks_398631ffe8071fa297f618d618f0de86','\'Title: Beerus Framework – A New Mobile Framework Arises
\nTags: Mobile Hacking Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

About a year ago, Hakai Security introduced the Beerus Framework, a proposal to unify mobile tools in order to streamline the penetration testing process directly on Android devices. The idea was simple: centralize tooling and optimize the testing environment setup, removing the need for complex configurations and reducing operational friction during assessments.

\n\n

Today, after a year of evolution, the framework is no longer just a concept. It has become a robust platform for offensive mobile analysis, gaining international recognition within the community. In this talk, we revisit Beerus in its current form, exploring its evolution, the capabilities that have been consolidated over time, and the lessons learned from real-world scenarios.

\n\n

We also discuss the future vision of the project, covering new features, technical challenges faced during its development, and how the framework can continue evolving to keep up with modern mobile security assessment demands.

\n\n

Official blog post: https://hakaisecurity.io/beerus-framework-a-new-mobile-framework-arises/insights-blog/\nRepository: https://github.com/hakaioffsec/beerus-android\nCommunity references:\n- mobile hacker (post): https://x.com/androidmalware2/status/1979100030884618375\n- mobile hacker (video): https://www.youtube.com/watch?v=8bDQzqw0_Sc\n- ZeroDay Gym (video): https://www.youtube.com/watch?v=I81xuVDsytE

\n\nSpeakers:João Pedro Tricta,Daniel \"Daniboy\" França Lima
\n
\nSpeakerBio:  João Pedro Tricta, Client-Side Applications Squad Leader, Researcher, and Malware Developer at Hakai Offensive Security
\n

Known as Tricta, I am 20 years old, Brazilian, and work as a Client-Side Applications Squad Leader, Researcher, and Malware Developer at Hakai Offensive Security. I am passionate about Sysinternals, reverse engineering, low-level, and client-side applications. In my free time, I enjoy programming, gaming, and watching anime. I\'m a cat lover and a compulsive pizza eater.

\n\nSpeakerBio:  Daniel \"Daniboy\" França Lima, Pentester / Researcher at Hakai Offensive Security
\n

Known as Daniboy, I am 19 years old, Brazilian, and work as a Pentester and Researcher at Hakai Offensive Security. I am passionate about understanding how things work, building tools, and manipulating systems. In my free time, I enjoy gaming, especially titles like Hollow Knight. I also love foxes, they are just too cute :3

\n\n\n\'',NULL,1294567),('4_Sunday','10','10:00','13:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_26dd6b07ae1fa632c6937286cc6ceafe','\'Title: Mobile Hacking Community - Open
\nTags: Mobile Hacking Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

At the Mobile Hacking Community, attendees will learn about the latest trends in mobile application security through hands-on experiences, including topics such as bypassing security mechanisms and hardening techniques, and exploiting known CVEs.

\n\n

Additionally, attendees will engage in a competitive process by participating in an onsite CTF (Capture the Flag) event to test their skills, face new challenges, and learn new skills.

\n\n

Attendees will also have the opportunity to watch cutting-edge research presentations and case studies on various topics within the domain.

\n\n

Dedicated real devices running vulnerable applications will be available, allowing attendees to actively practice exploitation and analysis in a realistic environment.

\n\n

Prerequisites:

\n\n
    \n
  • Attendees should bring their own laptop in order to fully participate in the hands-on workshops and CTF challenges.
  • \n
  • A basic familiarity with using a command line, installing software, and general computing concepts is recommended, but prior mobile security experience is not required.
  • \n
\n\n\'',NULL,1294568),('4_Sunday','11','10:00','13:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_26dd6b07ae1fa632c6937286cc6ceafe','\'\'',NULL,1294569),('4_Sunday','12','10:00','13:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_26dd6b07ae1fa632c6937286cc6ceafe','\'\'',NULL,1294570),('4_Sunday','13','10:00','13:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_26dd6b07ae1fa632c6937286cc6ceafe','\'\'',NULL,1294571),('2_Friday','10','10:00','17:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_c401e2dd7baebc2e0518ce879f37621b','\'Title: Mobile Hacking Community - Open
\nTags: Mobile Hacking Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

At the Mobile Hacking Community, attendees will learn about the latest trends in mobile application security through hands-on experiences, including topics such as bypassing security mechanisms and hardening techniques, and exploiting known CVEs.

\n\n

Additionally, attendees will engage in a competitive process by participating in an onsite CTF (Capture the Flag) event to test their skills, face new challenges, and learn new skills.

\n\n

Attendees will also have the opportunity to watch cutting-edge research presentations and case studies on various topics within the domain.

\n\n

Dedicated real devices running vulnerable applications will be available, allowing attendees to actively practice exploitation and analysis in a realistic environment.

\n\n

Prerequisites:

\n\n
    \n
  • Attendees should bring their own laptop in order to fully participate in the hands-on workshops and CTF challenges.
  • \n
  • A basic familiarity with using a command line, installing software, and general computing concepts is recommended, but prior mobile security experience is not required.
  • \n
\n\n\'',NULL,1294572),('2_Friday','11','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_c401e2dd7baebc2e0518ce879f37621b','\'\'',NULL,1294573),('2_Friday','12','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_c401e2dd7baebc2e0518ce879f37621b','\'\'',NULL,1294574),('2_Friday','13','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_c401e2dd7baebc2e0518ce879f37621b','\'\'',NULL,1294575),('2_Friday','14','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_c401e2dd7baebc2e0518ce879f37621b','\'\'',NULL,1294576),('2_Friday','15','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_c401e2dd7baebc2e0518ce879f37621b','\'\'',NULL,1294577),('2_Friday','16','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_c401e2dd7baebc2e0518ce879f37621b','\'\'',NULL,1294578),('2_Friday','17','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_c401e2dd7baebc2e0518ce879f37621b','\'\'',NULL,1294579),('3_Saturday','10','10:00','17:59','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_0a9c0982593429cf9a3f0232748475b5','\'Title: Mobile Hacking Community - Open
\nTags: Mobile Hacking Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

At the Mobile Hacking Community, attendees will learn about the latest trends in mobile application security through hands-on experiences, including topics such as bypassing security mechanisms and hardening techniques, and exploiting known CVEs.

\n\n

Additionally, attendees will engage in a competitive process by participating in an onsite CTF (Capture the Flag) event to test their skills, face new challenges, and learn new skills.

\n\n

Attendees will also have the opportunity to watch cutting-edge research presentations and case studies on various topics within the domain.

\n\n

Dedicated real devices running vulnerable applications will be available, allowing attendees to actively practice exploitation and analysis in a realistic environment.

\n\n

Prerequisites:

\n\n
    \n
  • Attendees should bring their own laptop in order to fully participate in the hands-on workshops and CTF challenges.
  • \n
  • A basic familiarity with using a command line, installing software, and general computing concepts is recommended, but prior mobile security experience is not required.
  • \n
\n\n\'',NULL,1294580),('3_Saturday','11','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_0a9c0982593429cf9a3f0232748475b5','\'\'',NULL,1294581),('3_Saturday','12','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_0a9c0982593429cf9a3f0232748475b5','\'\'',NULL,1294582),('3_Saturday','13','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_0a9c0982593429cf9a3f0232748475b5','\'\'',NULL,1294583),('3_Saturday','14','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_0a9c0982593429cf9a3f0232748475b5','\'\'',NULL,1294584),('3_Saturday','15','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_0a9c0982593429cf9a3f0232748475b5','\'\'',NULL,1294585),('3_Saturday','16','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_0a9c0982593429cf9a3f0232748475b5','\'\'',NULL,1294586),('3_Saturday','17','10:00','17:59','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Mobile Hacking Community - Open\'','\'\'','Creator Events_0a9c0982593429cf9a3f0232748475b5','\'\'',NULL,1294587),('2_Friday','10','10:00','10:10','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Opening Talk\'','\'Jayesh Singh Chauhan\'','Creator Talks_adea3755eb6d40fe35bb84b375935443','\'Title: Opening Talk
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:10 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Jayesh Singh Chauhan
\nNo BIO available
\n\n\'',NULL,1294588),('2_Friday','10','10:10','10:50','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'New AWS IAM Attack Paths and the Framework to Exploit Them\'','\'Seth Art\'','Creator Talks_d4d402262f20e61be6a287a437786693','\'Title: New AWS IAM Attack Paths and the Framework to Exploit Them
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:10 - 10:50 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

In cloud environments, the path from low-privilege foothold to full account takeover often runs through IAM privilege escalation. This talk introduces over a dozen newly discovered escalation paths spanning services that have never appeared in public research: AWS Batch, Amazon Braket, Amazon Managed Apache Flink, Amazon GameLift, Health Omics, and more.

\n\n

We\'ll walk through exploiting the most interesting paths in depth, including cross-account variants and attacks that require delivering malicious code payloads to trigger escalation. Then we\'ll introduce Pathrunner, a new open-source Metasploit-style framework built specifically for IAM privilege escalation, and show how it makes chaining these complex, multi-hop attacks practical during a real engagement.

\n\nSpeakerBio:  Seth Art
\n

Seth Art is a Security Researcher & Advocate at Datadog. Prior to joining Datadog, Seth created and led the Cloud Penetration Testing practice at Bishop Fox. He is the author of pathfinding.cloud, an AWS IAM privilege escalation library, and has published many open source tools including Pathfinding-labs, IAMVulnerable, BadPods, and CloudFoxable, and is the co-creator of the popular cloud penetration testing tool, CloudFox.

\n\n\n\'',NULL,1294589),('2_Friday','10','10:50','11:30','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID\'','\'Elzer Pineda,Jose Rivas\'','Creator Talks_b125bd1bc9bb380c627935c2ee827b96','\'Title: Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:50 - 11:30 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Is MFA and Conditional Access a real security guarantee? In this technical session, we will demonstrate how endpoint compromise allows an attacker to bypass traditional identity barriers in the cloud. The talk focuses on exploiting vulnerabilities in Microsoft Entra ID, breaking down an advanced attack chain:

\n\n

• Device Code Flow: Abuse of authentication flows for initial access (Demo with Entraith).\n• PowerShell Hijacking: Process interception to obtain session tokens (GrabTokenAzureAD).\n• Sliver BOF Extraction: Use of Beacon Object Files (BOF) for stealthy exfiltration of tokens and the Primary Refresh Token (PRT) from memory, evading anti-malware defenses.\n• MFA Bypass and Intune: Custom tools were developed to extract local PRTs, bypass Intune device management controls, and circumvent MFA. The entire process was automated through the open-source tool https://github.com/bl4cksku11/entraith, enabling attacks via device code flow, token renewal, email and app inspection, token exfiltration, and persistence generation.

\n\nSpeakers:Elzer Pineda,Jose Rivas
\n
\nSpeakerBio:  Elzer Pineda, Pentester
\n

Regional Pentester and Cybersecurity Consultant, Elzer Pineda is an active member of the Red Team executing strategic consulting projects and advanced penetration testing engagements. His career has been focused on Threat Research for private and government organizations across the region. He is a Dojo Community Ambassador and Professor at the Universidad Tecnológica de Panamá (UTP). His experience has taken him to share technical research at Ekoparty, BSides Latam Peru, BSides Panamá, DOJOConf, PwnedCR, and OWASP Latam. Offensive security certifications: OSWE, OSEP, OSCP, OSWP, CRTP, CRTO, and CRTL.

\n\n

--

\n\n

Profesor en la Universidad Tecnológica de Panamá y especialista en Red Team con más de 10 años de experiencia en ciberseguridad ofensiva y defensiva. Pentester en GBM (región y Estados Unidos) y researcher en Toad Security. Máster en Seguridad Informática. Realiza evaluaciones de seguridad a aplicaciones móviles, web e infraestructura en Latinoamérica y comparte activamente conocimientos en la comunidad Dojo como embajador y conferencias. Certificaciones: OSWE, OSEP, OSCP, CRTO, OSWP, CRTL.

\n\nSpeakerBio:  Jose Rivas, Experienced Penetration Tester at A-LIGN
\n

Jose Rivas is an Offensive Security Researcher and Red Team Operator at A-LIGN, specializing in adversarial simulations, Active Directory attack paths, and physical security assessments. Co-founder of Zero Trust Offsec, an offensive security research group focused on vulnerability exploitation, emerging attack techniques, and responsible disclosure, and Founder of DCG Panama, Panama\'s first official DEF CON chapter, where he leads a community dedicated to red team operations, and adversarial tradecraft. A recognized voice in the Panamanian security community, Jose has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf. With certifications including CRTO, eWPT, eCPPT, and CompTIA PenTest+, he brings a threat-actor mindset and a strong commitment to advancing offensive security knowledge across the region.

\n\n

Jose Manuel Rivas is a Penetration Tester and Red Team Operator at A-LIGN, with hands-on experience in adversarial simulations, Active Directory attack chains, web application testing, and physical security assessments. He has multiple CVEs to his name, discovered through bug bounty programs and independent vulnerability research. Co-founder of Zero Trust Offsec and founder of DCG Panama, Panama\'s first official DEF CON chapter. He has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf, and is focused on growing the penetration testing and red team culture across Latin America.

\n\n\n\'',NULL,1294590),('2_Friday','11','10:50','11:30','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID\'','\'Elzer Pineda,Jose Rivas\'','Creator Talks_b125bd1bc9bb380c627935c2ee827b96','\'\'',NULL,1294591),('2_Friday','11','11:00','12:59','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'Governing the Firehose: Writing Custom OPA Policies to Tame and Remediate Prowler Output\'','\'Ram \"n2r\"\'','Creator Events_f33b036136fcd8ea69bb79480519c12e','\'Title: Governing the Firehose: Writing Custom OPA Policies to Tame and Remediate Prowler Output
\nTags: Cloud Village | Creator Event/Activity | Strategic Defense
\nWhen: Friday, Aug 7, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) B - Map
\n
\nDescription:
\n

When you run an opensource CSPM tool like Prowler across an cloud environment, you don’t get an audit; you get a tsunami of raw data. Sifting through thousands of JSON lines to determine what actually poses an active threat to your specific architecture is where most cloud defense pipelines break down.

\n\n

In this 2-hour handson workshop, I’m going to show you how I bridge the gap between scanning and governance using Policy as Code. We will dive straight into treating Prowler’s raw security findings as structured data input for Open Policy Agent (OPA).

\n\n

Together, we’ll write custom Rego policies from scratch to parse, filter and logically route Prowler results based on real world business context. I’ll show you how to write policies that evaluate infrastructure as code risk, suppress known risk acceptances safely and isolate critical failures (like exposed storage buckets or unencrypted databases) to trigger automated remediation workflows.

\n\nSpeakerBio:  Ram \"n2r\"
\n

Passionate about Linux, cryptography, and secure SDLC, I love digging into code, threat modeling, and breaking things (responsibly ofc). Whether it’s hardening apps or decoding exploits. I’m all about making software safer - one commit at a time.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294592),('2_Friday','12','11:00','12:59','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'Governing the Firehose: Writing Custom OPA Policies to Tame and Remediate Prowler Output\'','\'Ram \"n2r\"\'','Creator Events_f33b036136fcd8ea69bb79480519c12e','\'\'',NULL,1294593),('2_Friday','11','11:00','12:59','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS\'','\'Samanta Aranda\'','Creator Events_bdde823945872a114cea0339c14c4a3f','\'Title: Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS
\nTags: Cloud Village | Creator Event/Activity | Attack
\nWhen: Friday, Aug 7, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) A - Map
\n
\nDescription:
\n

CloudFormation is widely trusted as a secure and declarative Infrastructure as Code (IaC) service inside AWS environments. In practice, however, CloudFormation frequently operates with permissions far beyond those of individual users, CI/CD pipelines, or developers. This workshop explores how attackers can abuse that trust model to achieve privilege escalation and persistence in realistic AWS environments.

\n\n

In this fully hands-on offensive cloud security workshop, attendees will begin with limited IAM permissions and learn how to identify and exploit misconfigured CloudFormation execution roles using iam:PassRole, service roles, and Lambda-backed Custom Resources. Participants will weaponize CloudFormation templates to create persistence mechanisms inside service-scoped IAM paths without requiring direct administrative permissions.

\n\n

The workshop emphasizes realistic cloud attack paths, delegated execution abuse, and the security risks introduced by over-permissioned automation. Attendees will also explore rollback abuse scenarios and learn how these attacks appear in CloudTrail and IAM logs.

\n\nSpeakerBio:  Samanta Aranda
\n

Samanta Aranda serves as a Managing Senior Consultant at Bishop Fox, leading security assessments and initiatives focused on strengthening organizations’ technological resilience. She holds a degree in Electronics and Communications Engineering and a Master’s in Computer Science and Technology Management. From the very beginning of her career, she found in cybersecurity not just a profession but a genuine passion. Over the years, she has collaborated with national and international firms such as KPMG, Scitum, EC-Council LATAM, and INFOTEC, contributing to projects that bridge technology, strategy, and security.

\n\n

Samanta holds 16 professional certifications, including GPEN, GWAPT, CEH, and CND, and has been recognized as an EC-Council Certified Instructor, earning a place in the organization’s Circle of Excellence in 2021. She blends technical expertise with a human and collaborative approach to security, firmly believing that shared knowledge is the strongest defense.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294594),('2_Friday','12','11:00','12:59','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS\'','\'Samanta Aranda\'','Creator Events_bdde823945872a114cea0339c14c4a3f','\'\'',NULL,1294595),('2_Friday','11','11:30','12:10','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'From Pipeline to Cloud Control\'','\'Saksham Agrawal\'','Creator Talks_294e1fa1ae0e6992b2aa8e9297e00c28','\'Title: From Pipeline to Cloud Control
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 12:10 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Azure DevOps service connections are a core part of modern pipelines, allowing teams to interact with Azure and other external systems seamlessly. While they make deployments faster and easier, they also introduce an attack surface that is often overlooked in real-world environments.

\n\n

In this research, we explore new attack paths showing how even limited access within Azure DevOps pipelines can be leveraged to escalate privileges and compromise cloud environments. By taking advantage of over-scoped service connections and certain platform behaviors, an attacker can chain together small gaps to achieve significant impact, including gaining subscription-level access.

\n\n

These findings were reported to Microsoft and acknowledged through MSRC, highlighting a deeper issue in how DevOps integrations are secured. Rather than being just a configuration problem, this reflects a broader gap that organizations need to understand when designing their cloud security approach.

\n\nSpeakerBio:  Saksham Agrawal
\n

Saksham Agrawal is a Senior Security Consultant at NotSoSecure, specializing in cloud security. His work focuses on discovering new attack paths in cloud environments and helping organizations understand real-world risks. He has presented his research at DEF CON Cloud Village, where he introduced his tool NoPrompt and shared practical techniques for cloud security testing. He enjoys building tools, exploring cloud internals, and sharing his findings with the security community. He has also responsibly reported critical vulnerabilities in major cloud vendors as part of his independent security research and actively delivers training sessions on cloud security and offensive security techniques.

\n\n\n\'',NULL,1294596),('2_Friday','12','11:30','12:10','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'From Pipeline to Cloud Control\'','\'Saksham Agrawal\'','Creator Talks_294e1fa1ae0e6992b2aa8e9297e00c28','\'\'',NULL,1294597),('2_Friday','12','12:10','12:50','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Security at Machine Speed: How Autonomous AI Agents Are Changing Cloud Defense\'','\'Pujita Sahni,Geoff Sweet\'','Creator Talks_c4a9cb3d2ccc397fbc40d16bb581fce3','\'Title: Security at Machine Speed: How Autonomous AI Agents Are Changing Cloud Defense
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:10 - 12:50 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Attackers are using frontier AI to compress the time between finding a vulnerability and exploiting it. Manual triage and human-in-the-loop remediation cannot keep pace. The answer is autonomous security that works at machine speed.

\n\n

This talk covers the continuous AI-powered security loop and how autonomous agents are changing three SOC functions:

\n\n

Autonomous triage. Agentic AI systems trained on real security decisions separate real threats from noise with high accuracy, reasoning across logs, configurations, reachability, and history. What takes analysts hours, these systems handle in seconds.

\n\n

Validated remediation. The latest AWS security enhancements discover vulnerabilities, validate exploitability in sandboxes, and fix confirmed exposures with increasing autonomy. We walk through the journey from human-approved fixes to fully autonomous remediation.

\n\n

Continuous offensive testing. AI agents that proactively test your applications throughout the dev lifecycle instead of once a year. Customized pen testing across your whole environment. We show what this looks like when an AI chains attack paths across services in real time.

\n\n

The full loop. Discovery feeds triage, triage feeds remediation, remediation closes the gap before attackers exploit it. Integrated through AWS Security Hub with the tools you already use.

\n\n

Real demos. Real attack paths. Walk away knowing where this technology stands and what first steps look like.

\n\nSpeakers:Pujita Sahni,Geoff Sweet
\n
\nSpeakerBio:  Pujita Sahni
\n

Pujita Sahni is a Delivery Consultant specializing in cloud security, risk, and compliance at AWS. In her role, she is responsible for architecting IAM governance frameworks and security automation solutions that enable organizations to implement secure cloud migrations and shift security left within enterprise environments. She brings a broad technical background across identity and access management, vulnerability management, infrastructure-as-code security, and DevSecOps practices, providing a comprehensive view of how security platforms are built, automated, and maintained across enterprise cloud environments.

\n\nSpeakerBio:  Geoff Sweet
\n

Geoff Sweet has nearly 30 years of technology experience, starting from the late 90\'s during the dot-com boom. Geoff has worked in many verticals including Gaming, BioTech, Retail, and financial SaaS. He has held several titles through his career such as Systems Architect, Network Architect, and most recently Security Architect. These experiences have helped him to develop robust experiences in Infrastructure Security. Geoff left the customer side to come to AWS in December of 2019. He left SAP where he lead a small security team responsible for monitoring and doing Incident Response for nearly 10,000 cloud accounts over several cloud providers. Geoff has a proven record of speaking to customers in both small and large format settings. He is engaging, entertaining, and communicates in a way that assures everyone understands. Geoff\'s background is in Electrical Engineering and Mathematics and continues to use that knowledge to support his customers. He also has a deep fondness for all things automotive and extensive experience building and fabricating vintage cars.

\n\n\n\'',NULL,1294598),('2_Friday','12','12:50','13:20','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'PurpleLoop: Closing the Loop Between Detection Rules, Log Schemas, and Purple-Team Validation\'','\'Ariz Soriano\'','Creator Talks_e47962090ebe279ad5bfb929ad6a02b3','\'Title: PurpleLoop: Closing the Loop Between Detection Rules, Log Schemas, and Purple-Team Validation
\nTags: Demo 💻 | Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:50 - 13:20 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

The problem\nSentinel deployments rot. Mid-market SOCs run 80 to 300 analytics rules, and a large share haven\'t fired a true positive in 90 days. Many reference tables or columns that don\'t exist in the tenant because the rule was copied from a Microsoft post written for a different topology. The public Azure-Sentinel repo ships new content weekly and almost nobody reconciles against it. One layer deeper, Log Analytics ingests 20 to 80 tables per tenant, and most teams have never audited which have any coverage and which are dark. And almost nobody validates that the rules they do have actually fire against the techniques they claim to cover.

\n\n

What PurpleLoop is\nPurpleLoop is an LLM-augmented detection-engineering workflow built on one insight: rule authoring, coverage analysis, and purple-team validation are the same job, and they should be one tool. It does four things, none individually novel, never previously combined into one workflow:

\n\n
    \n
  • Reviews deployed rules by diffing against the live Azure-Sentinel repo and community libraries, flagging drift, dead operators, missing siblings.
  • \n
  • Suggests new rules from your actual workspace schema, not Microsoft\'s reference topology. A rule needing DeviceProcessEvents isn\'t suggested if MDE isn\'t onboarded.
  • \n
  • Generates purple-team scenarios and validates rules against them. The tool runs an atomic-style simulation, checks whether the rule fires, and patches the KQL if it doesn\'t. The loop closes itself.
  • \n
  • Builds a detection-gap map that distinguishes \"no rule for this\" from \"no telemetry for this.\" Most coverage tools miss the second category.
  • \n
\n\n

Why an LLM\nThe LLM provides the connective reasoning between the pieces. It is not in the codegen path. PurpleLoop reasons in a Sigma-inspired intermediate detection representation (IDR), and a deterministic compiler renders to KQL. The queries that run on your workspace are produced by code we wrote, not by pattern completion. Hallucinated columns and invented operators are eliminated at the compiler boundary, not at the prompt boundary.

\n\n

What attendees take home\nA working open-source tool installable in minutes, a reusable methodology not bound to Sentinel, and prompt-engineering patterns for security workflows where correctness matters. The talk argues the case, demos the tool live against a real tenant, and hands the code to the room.

\n\nSpeakerBio:  Ariz Soriano, Associate Director - Red Team Operations @ THEOS Cyber Solutions
\n

Ariz Soriano is Associate Director of Red Team at Theos, with nearly a decade of experience spanning Red Teaming, Penetration Testing, and Incident Response. He started his career on the defensive side, working as a SOC analyst and eventually leading SOC and IR teams for his first four years in the industry. That defensive foundation gives him a perspective most purely offensive operators don\'t have.

\n\n

He built the Theos Red Team from the ground up, recruiting and training operators, designing red team infrastructure and tooling, and establishing the methodology and playbooks behind the team\'s APT simulation and purple teaming engagements. Today he runs a practice that delivers multiple concurrent engagements a year, balancing operations with presales, scoping, revenue targets, and people management.

\n\n

Outside of client work, Ariz is passionate about building red team tooling, optimizing offensive workflows, and sharing knowledge with the community as a conference speaker. He also contributes to TryHackMe as a part-time Senior Content Engineer, creating hands-on cybersecurity labs and challenges based on real-world attack techniques.

\n\n\n\'',NULL,1294599),('2_Friday','13','12:50','13:20','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'PurpleLoop: Closing the Loop Between Detection Rules, Log Schemas, and Purple-Team Validation\'','\'Ariz Soriano\'','Creator Talks_e47962090ebe279ad5bfb929ad6a02b3','\'\'',NULL,1294600),('2_Friday','13','13:20','13:59','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'The Hidden Cost of Agentic Connectivity\'','\'David Fiser,Amy McMahon\'','Creator Talks_3ee1221a106db953fe739cb4df262614','\'Title: The Hidden Cost of Agentic Connectivity
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:20 - 13:59 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

During our extensive research on MCP servers, we uncovered critical vulnerabilities that pose significant risks to the cloud infrastructure management. These vulnerabilities enable malicious actors to interact with and compromise organizational infrastructure. Alarmingly, while some MCP servers had implemented protective measures against such misuse, these measures were often flawed, allowing for trivial bypasses.

\n\n

In this presentation, we will underscore the necessity of comprehensive visibility and robust policy guidelines for every organization. Our analysis of over 19,000 MCP servers reveals substantial gaps and vulnerabilities within the so-called security features of these systems. We will demonstrate how these security features can be bypassed and highlight the real-world implications of these vulnerabilities.

\n\n

Through active scanning, we identified the same vulnerable MCP server implementations deployed in the wild, confirming that these vulnerabilities are actively exploitable. This underscores the urgent need for organizations to adopt a strategic approach to managing MCP servers.

\n\n

Our aim is for attendees to understand th e critical importance of AI security beyond mere vulnerability management. Our findings show that even if the MCP server is not vulnerable, default deployments often introduce significant risks to organizational security. We will conclude our presentation by outlining best practices for mitigating the risks associated with MCP servers, ensuring that attendees leave with actionable insights to enhance their organization\'s security posture.

\n\nSpeakers:David Fiser,Amy McMahon
\n
\nSpeakerBio:  David Fiser
\n

David Fiser is a cybersecurity professional with over 15 years of experience. He regularly contributes to blogs and co-authors whitepapers on various security topics. He has been credited with several CVEs, including high-profile vendors such as Microsoft and NVIDIA. He presented his previous research at multiple security conferences. Personally, David is passionate about motorsport, cars, planes, and motorcycles. He also likes fixing broken items and traveling.

\n\nSpeakerBio:  Amy McMahon
\n

Amy is a seasoned Systems Engineer with 20 years of experience supporting enterprise customers through the evolution of TippingPoint spanning its tenures under 3Com, Hewlett Packard Enterprise, and Trend Micro. With deep expertise in network security and intrusion prevention, Amy has built a reputation for translating complex network security challenges into actionable solutions for large-scale enterprise environments. Currently serving as a Subject Matter Expert in Networking Solutions at TrendAI, Amy brings both technical depth and strategic perspective to emerging AI-driven security challenges. She holds multiple industry certifications including CISSP, CEH, and AWS Solutions Architect, reflecting her commitment to staying at the forefront of network cybersecurity and cloud architecture.

\n\n\n\'',NULL,1294601),('2_Friday','13','13:30','15:30','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Cloudy with a Chance of Breaches: Hands-On AWS Threat Defense\'','\'Kyle Hubbard\'','Creator Events_dc681966b35181c8f654ca902f6c1e82','\'Title: Cloudy with a Chance of Breaches: Hands-On AWS Threat Defense
\nTags: Cloud Village | Creator Event/Activity | Investigation
\nWhen: Friday, Aug 7, 13:30 - 15:30 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) A - Map
\n
\nDescription:
\n

Join this hands-on workshop to explore integrated security capabilities for the modern AWS cloud stack, including containers, object storage, and AI applications. You’ll work with a deliberately vulnerable Flask application running on EKS with S3 and Amazon Bedrock, then deploy and configure controls that detect attacks at runtime.

\n\n

The session will cover behavioral runtime detection for credential-access activity and malware inside live pods, attack-surface mapping, and identity-aware risk analysis to trace the potential blast radius of a compromised workload through its IAM role. You’ll also examine file-borne threat protection across the application boundary and S3, use unified XDR queries to hunt across container and storage detections, and close with runtime guardrails that block direct and document-borne prompt injection against a real Amazon Bedrock model.

\n\nSpeakerBio:  Kyle Hubbard
\n

Kyle is a Solutions Architect at TrendAI, where he works within the Global Alliances team across hyperscaler partnerships, with a primary focus on AWS. He specializes in cloud security integrations and in translating the technical capabilities of the Trend Vision One platform into strategies that partners, customers, and executives can act on.

\n\n

His current work is centered on AI security, including AI security posture management and the protection of agentic workloads. As organizations rapidly adopt agentic architectures, Kyle focuses on how Vision One can secure that transition and how to communicate its value clearly to both technical and executive audiences.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294602),('2_Friday','14','13:30','15:30','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Cloudy with a Chance of Breaches: Hands-On AWS Threat Defense\'','\'Kyle Hubbard\'','Creator Events_dc681966b35181c8f654ca902f6c1e82','\'\'',NULL,1294603),('2_Friday','15','13:30','15:30','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Cloudy with a Chance of Breaches: Hands-On AWS Threat Defense\'','\'Kyle Hubbard\'','Creator Events_dc681966b35181c8f654ca902f6c1e82','\'\'',NULL,1294604),('2_Friday','13','13:30','14:30','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'The Autonomous Security Loop\'','\'Jeremy Schiefer,Lawton Pittenger\'','Creator Events_41470327f2c5249507602fa62caa145f','\'Title: The Autonomous Security Loop
\nTags: Cloud Village | Creator Event/Activity | Strategic Defense
\nWhen: Friday, Aug 7, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) B - Map
\n
\nDescription:
\n

SOCs get thousands of alerts daily. Most orgs take days to triage and fix critical findings. Attackers exploit that gap.

\n\n

This lab walks through the three stages of a continuous security loop. Do each phase by hand, then see how the latest AWS capabilities compress it to seconds:

\n\n

Discovery: Review output from a continuous security scan that found a multi-step attack path. Understand why this catches things annual pen tests miss.\nTriage: Manually triage 5 out of 30 Security Hub findings using the same signals AI triage uses. Compare your calls against the automated system.\nRemediation: Examine proposed fixes. Understand the difference between human-approved and autonomous remediation. Submit a fix and confirm it works.

\n\nSpeakers:Jeremy Schiefer,Lawton Pittenger
\n
\nSpeakerBio:  Jeremy Schiefer
\n

Jeremy is a Pr. Security Solution Architect at AWS focused on helping customers improve their security posture.

\n\nSpeakerBio:  Lawton Pittenger
\n

Lawton is a Worldwide Security Specialist Solutions Architect at AWS, based in New York City. He specializes in helping customers design and implement effective network security controls. At AWS, he works with customers at scale and collaborates closely with service teams to drive continuous improvement in security services based on customer needs and feedback

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294605),('2_Friday','14','13:30','14:30','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'The Autonomous Security Loop\'','\'Jeremy Schiefer,Lawton Pittenger\'','Creator Events_41470327f2c5249507602fa62caa145f','\'\'',NULL,1294606),('2_Friday','14','14:00','14:30','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Nebula - 5 years, still kicking *aaS\'','\'Bleon \"gl4ssesbo1\" Proko\'','Creator Talks_c8281dbecb5dc9b5f26f08a5e6c7c7ab','\'Title: Nebula - 5 years, still kicking *aaS
\nTags: Demo 💻 | Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to allow testing other Cloud Providers and DevOps Components.\nIt started as a project to unify all Cloud + DevOps Pentest and Security Techniques for a better assessment of the Infrastructures. It is build with modules for each provider and each functionality. Initially released in April 2021 as a bulk of scripts, it developed into a C2 framework, managed through a teamserver, allowing a team of pentesters to authenticate and access the tool, as well as a MongoDB database to save the results into. Offers modules for reconnaissance, initial access, enumeration, Command and Control, post exploitation, persistence and cleanup in AWS, Azure Graph and Management API, DigitalOcean, as well as a new release for GCP and GWS, Kubernetes and defense bypasses.

\n\n

Currently covers:\n- Public Reconnaissance\n- Phishing\n- Brute-force and Password Spray\n- Enumeration of internal resources after initial access\n- Lateral Movement and Privilege Escalation\n- Persistence

\n\n

Ever since I pushed the last update, the tool has changed drastically. Now you will get a teamserver based tool, with a client and server split, authentication to access the tool, user management and a MongoDB database to save the results into.

\n\nSpeakerBio:  Bleon \"gl4ssesbo1\" Proko
\n

Bleon is an Info-sec passionate about Infrastructure Penetration Testing and Security, including Active Directory, Cloud (AWS, Azure, GCP, Digital Ocean), Hybrid Infrastructures, as well as Defense, Detection and Thread Hunting. He has presented topics related to Cloud Penetration Testing and Security in conferences like BlackHat USA, Europe and Sector, DEF CON, SANS Pentest Hackfest Hollywood and Amsterdam, as well as several BSides on USA and Europe.

\n\n

His research include Nebula, a Cloud Penetration Testing Framework (https://github.com/gl4ssesbo1/Nebula) and other blogs, which you can also find on his blog (blog.pepperclipp.com). He is also the author of YetiHunter, DetentionDodger and Ransomwhen (https://github.com/Permiso-io-tools/[DetentionDodger | YetiHunter | Ransomwhen]).

\n\n

He is also the author of the upcoming book \"Deep Dive into Clouded Waters: An overview in Digital Ocean\'s Pentest and Security\" (https://leanpub.com/deep-dive-into-clouded-waters-an-overview-in-digitaloceans-pentest-and-security)

\n\n\n\'',NULL,1294607),('2_Friday','14','14:30','15:10','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Citizen Developers Can\'t Defend What They Built: Scaling Security Past the Security Team\'','\'Evan Markl,Alex Humphrey,Kevin McDermott,Laura Haller\'','Creator Talks_8c7858bf62c98da579b5feadfaa84395','\'Title: Citizen Developers Can\'t Defend What They Built: Scaling Security Past the Security Team
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:30 - 15:10 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n\n\nSpeakers:Evan Markl,Alex Humphrey,Kevin McDermott,Laura Haller
\n
\nSpeakerBio:  Evan Markl
\nNo BIO available
\nSpeakerBio:  Alex Humphrey
\n

Alex Humphrey is a cybersecurity leader and speaker with more than 15 years of experience helping organizations solve complex security problems and build effective security programs. He specializes in putting security challenges in their proper organizational context, connecting technical decisions to business priorities, operational realities, and the people responsible for making security work. Today, Alex focuses on AI security and the practical application of AI in security operations. He works with organizations to understand their actual AI risks, separate meaningful concerns from industry hype, and adopt defenses that allow them to pursue their goals securely.

\n\nSpeakerBio:  Kevin McDermott
\n

Kevin McDermott serves as Head of Security at Superhuman, where he leads teams across Product Security, Cloud/Platform Security, Detection and Response, and Threat Intelligence. Kevin cut his teeth as an application security practitioner before transitioning into leadership, bringing hands-on experience to his strategic role. He\'s built his career on creating security programs that work with engineering teams rather than against them.

\n\nSpeakerBio:  Laura Haller
\nLaura Haller is a Senior Infrastructure Security Engineer and previous fwd: CloudSec speaker with over a decade of experience in security engineering and cloud security from her time at Netflix, HashiCorp, Schwab, and Capital One. Her interests lie in working with engineering and non-engineering teams alike on practical security controls where context is critical and scale presents unique challenges. She holds a particularly-useful-at-DEF CON Electrical Engineering degree from the University of Illinois and is a passionate mentor for women entering the cybersecurity field.
\n\n\n\n\n\'',NULL,1294608),('2_Friday','15','14:30','15:10','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Citizen Developers Can\'t Defend What They Built: Scaling Security Past the Security Team\'','\'Evan Markl,Alex Humphrey,Kevin McDermott,Laura Haller\'','Creator Talks_8c7858bf62c98da579b5feadfaa84395','\'\'',NULL,1294609),('2_Friday','15','15:10','15:30','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Go with the Flow: Riding GCP Dataflow Shadow Dependency to Cross-Tenant Compromise\'','\'Gil Weizman,Tamir Yehuda\'','Creator Talks_2ac6a3a4beb06ac8d0938f034c263a97','\'Title: Go with the Flow: Riding GCP Dataflow Shadow Dependency to Cross-Tenant Compromise
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:10 - 15:30 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Cloud resources rely on a web of trust that most security teams ignore. Even if you secure access to a resource, you might miss its \"shadow dependencies\" - the external, system-generated resources required for it to function.

\n\n

GCP Dataflow is just the latest in a long trail of vulnerable services suffering from this architectural blind spot. What we found is a fundamental flaw in how Dataflow blindly trusts dependencies located far outside its IAM control and security boundaries.

\n\n

In this talk, we’ll present two novel attack techniques that weaponize unvalidated config files to hijack trusted data pipelines. We’ll also demonstrate a critical cross-tenant vulnerability that extends this issue by enabling manipulation of Dataflow orchestration across tenant boundaries. The issue remains under responsible disclosure and is expected to be fixed before the presentation.

\n\n

Background: GCP Dataflow and Managed Infrastructure

\n\n

Organizations running large-scale enterprise data workloads increasingly rely on managed data-processing services, especially GCP Dataflow. Built on Apache Beam, Dataflow executes unified data pipelines while removing much of the operational burden of provisioning cluster frameworks, tuning virtual machines, and scaling infrastructure in response to demand. Teams define the pipeline, and Dataflow provisions and scales the underlying compute resources automatically.

\n\n

During this orchestration, however, Dataflow pipelines often depend on objects stored in standard cloud storage buckets to control execution, such as code, templates, and environment configuration.

\n\n

Pipelines routinely ingest and execute files from cloud buckets, including JavaScript or Python User Defined Functions (UDFs) for runtime transformation, structured YAML job templates that define pipeline parameters, and other environment configuration files.

\n\n

Because these files and their supporting temporary assets are often managed through automated developer pipelines, they can become \"shadows\": overlooked in routine asset inventories and security posture reviews, yet still critical to the execution of highly trusted cloud workflows.

\n\n

Key Takeaways

\n\n

Dismantling the shadow resources blind spot: Understand how automated cloud orchestration creates short-lived access windows that can evade scheduled security scans and routine asset inventories.

\n\n

Auditing the infrastructure-as-config attack surface: Learn to treat external execution blueprints as active attack surfaces rather than passive configuration files.

\n\n

Applying defensive best practices: Take away architectural recommendations for designing pipelines that are more resilient to these attack paths.

\n\n

Session Details

\n\n

Total duration: 20 minutes

\n\n

5 minutes: Background on shadow resources and Dataflow mechanics.

\n\n

10 minutes: Walkthrough of the attack paths and the cross-tenant vulnerability.

\n\n

5 minutes: Research methodology, defensive takeaways, and detection strategies.

\n\nSpeakers:Gil Weizman,Tamir Yehuda
\n
\nSpeakerBio:  Gil Weizman
\n

Gil Weizman is an experienced security researcher with over ten years of expertise across on‑prem, cloud, web, and SaaS security. Gil focuses on threat detection, product security research, vulnerability research and identifying gaps in security visibility across modern environments. Gil specializes in translating real‑world attacker behavior into improved detection and mitigation strategies.

\n\nSpeakerBio:  Tamir Yehuda
\n

Tamir Yehuda is a Senior Security Researcher and cloud security team lead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows & AD domains, SaaS applications, and cloud infrastructure. Tamir specialize in IaaS & PaaS research focusing mainly on Azure, GCP, AWS, Salesforce, and ServiceNow. He brings over eight years of experience in various types of security research and red teaming.

\n\n\n\'',NULL,1294610),('2_Friday','15','15:30','16:10','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'The Polymorphic Agent: From Cross Agent Escalation to Just in Time Defense on Azure\'','\'Muskan Tomar\'','Creator Talks_99cb8231229c785d9a86038c3a6a0c4e','\'Title: The Polymorphic Agent: From Cross Agent Escalation to Just in Time Defense on Azure
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 16:10 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

A permission error halts conventional malware. AI agents are being assigned standing cloud IAM permissions and the autonomy to use them, a combination that breaks an assumption every existing control depends on. The agent reasons its way to an escalation path through the cloud provider\'s own IAM APIs. We call this the polymorphic agent. This talk presents research cross-agent privilege escalation between independent AI agents & defense around it.

\n\n

The attack begins with a single poisoned tool description, rewritten to read like routine compliance guidance. The agent parses the injected text, reasons about it, and grants itself elevated IAM roles. this showcases how a compromised Agent A modifies the role assignments of a separate Agent B, running a different framework in a seperate environment and never issued a malicious instruction, expanding Agent B\'s authority entirely through authorized IAM calls. This points directly to two risks named in the OWASP MCP Top 10: Privilege Escalation via Scope Creep (MCP02), achieved through Tool Poisoning (MCP03). To test whether this is agent-specific, we ran the attack across three production agents, including LangChain and Claude Code. All three escalated, the pattern is consistent: prompt-layer guardrails are reformable, human approval is socially engineer-able, and telemetry arrives too late.

\n\n

These results frame two requirements for any workable defense: the escalation must be measurable in real time, and it must be blocked at a point the agent cannot reach. Enforcement has to move to the credential layer, since an agent cannot act on the cloud without first obtaining a credential. This is the gap PrivilegeGuard closes, an out-of-process credential gateway that intercepts DefaultAzureCredential and slots into existing agent deployments with minimal to no code change.

\n\n

On each token request, it computes the requesting Non-Human Identity’s Blast Radius Score (BRS): the fraction of the cloud resource surface reachable by that identity across a two-hop IAM graph traversal, providers reachable under current role assignments plus those reachable after a simulated roleAssignments/write self-escalation. PrivilegeGuard evaluates BRS and its rate of change against an Open Policy Agent (Rego) policy and denies an anomalous, high-blast-radius request before the escalated role is usable.

\n\n

The takeaway is architectural: cross-agent escalation follows from giving probabilistic, goal-driven agents standing IAM credentials, not from any single agent or framework, and it widens as agents gain access. We deliver the attack on real Azure identities, and an enforcement model that stops it where the agent cannot follow: the credential layer.

\n\nSpeakerBio:  Muskan Tomar
\n

Hey, I am Muskan Tomar, a Security and Reliability Engineer at MICROSOFT, where I work at the intersection of Site reliability, Infrastructure Security, and Software Engineering building systems that are expected to never go down, stay secure, and scale quietly in the background. 5X Microsoft Azure Certified , with experience working on architecting and modernising, securing cloud platforms and reducing operational toil through automation, AI and data driven engineering. \nMy independent research focuses on AI agent security and cloud identity, and how autonomous agents change the threat model for systems we trust to stay locked down. An enthusiastic learner who champions collaborative cloud and security research, I enjoy untangling complex systems and eliminating single points of failure. Outside work, I love to travel and paint.

\n\n\n\'',NULL,1294611),('2_Friday','16','15:30','16:10','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'The Polymorphic Agent: From Cross Agent Escalation to Just in Time Defense on Azure\'','\'Muskan Tomar\'','Creator Talks_99cb8231229c785d9a86038c3a6a0c4e','\'\'',NULL,1294612),('2_Friday','16','16:00','17:59','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Cirro: Extending Your Azure Graph Beyond Identities\'','\'Leron Gray\'','Creator Events_b66dc56db4041324f906fc7ad02012e4','\'Title: Cirro: Extending Your Azure Graph Beyond Identities
\nTags: Demo 💻 | Cloud Village | Creator Event/Activity | Tool 🛠 | Attack | Tools
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) A - Map
\n
\nDescription:
\nMost Azure graph analysis tooling focuses primarily on identity relationships: users, groups, service principals, and role assignments. While valuable, modern Azure environments contain far more exploitable context hidden within infrastructure, platform services, application configurations, network relationships, managed identities, and data-plane resources.
\n\n

Cirro (the spiritual successor to Stormspotter) is an attack graphing tool built to model Azure environments by combining Microsoft Graph identity data with Azure Resource Manager (ARM) infrastructure data. Instead of limiting analysis to Entra ID objects and role assignments, Cirro maps Azure resources into Neo4j for deeper attack path and misconfiguration analysis.

\n\n

This lab provides a practical understanding of Cirro’s collection, ingestion, and analysis workflow. Attendees will perform enumeration and assessment of an Azure tenant to understand how to view attack paths beyond identities. They will perform Cypher queries and use custom dashboards to visualize and interpret graph data.

\n\n

Prerequisites:\n- Docker/Podman Compose\n- Azure CLI\n- Web browser\n- Sqlite3 Browser\nRecommended (but not required):\n- Fundamental knowledge of Cypher query language

\n\nSpeakerBio:  Leron Gray
\n

Leron Gray is a Senior Security Consultant at Bishop Fox, specializing in offensive security, cloud attack path analysis, and security tooling research. He is the creator of Cirro, an extensible graph-based framework for analyzing Azure and cloud environments through Microsoft Graph and Azure Resource Manager data. His work focuses on helping security researchers and red teamers better understand complex cloud relationships, identity abuse paths, and infrastructure misconfigurations at scale.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294613),('2_Friday','17','16:00','17:59','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Cirro: Extending Your Azure Graph Beyond Identities\'','\'Leron Gray\'','Creator Events_b66dc56db4041324f906fc7ad02012e4','\'\'',NULL,1294614),('2_Friday','16','16:00','17:59','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'From Dashboard to Exploit: Weaponizing and Winning the Cloud Queue\'','\'Mackenzie Jackson\'','Creator Events_703a8437ebb8ed693510a2d11682cc36','\'Title: From Dashboard to Exploit: Weaponizing and Winning the Cloud Queue
\nTags: Cloud Village | Creator Event/Activity | Strategic Defense
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) B - Map
\n
\nDescription:
\n

Finding a vulnerability on a dashboard is only half the battle. Knowing how an attacker will weaponize it is what separates great security engineers from the rest.

\n\n

In this hands-on CloudSec Village lab hosted by Aikido Security, you will step into the shoes of both defender and attacker. Navigating a custom simulation dashboard, you’ll face live vulnerabilities hidden across containerized apps and serverless functions. Your mission: don’t just trust the scanner. You will dive into live mini-applications, execute real-world exploits to prove their impact, and see exactly how they register on the platform. This drop-in lab bridges the gap between passive triage and active offensive security — join any time and validate threats like a pro.

\n\nSpeakerBio:  Mackenzie Jackson
\n

Mackenzie is the Field CTO for Aikido Security, helping tech leaders understand application security through an attacker’s lens. As the co-founder and former CTO health tech company Conpago, he understands the challenges of building secure applications. He has spoken in over 30 countries, hosts the popular Podcast The Secure Disclosure, and contributes to multiple publications including Dark Reading, Financial Times, and Fast Company.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294615),('2_Friday','17','16:00','17:59','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'From Dashboard to Exploit: Weaponizing and Winning the Cloud Queue\'','\'Mackenzie Jackson\'','Creator Events_703a8437ebb8ed693510a2d11682cc36','\'\'',NULL,1294616),('2_Friday','16','16:10','16:50','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'The New Software Supply Chain Nobody is Securing: MCP\'','\'Evan Markl,Tamir Yehuda,Jessie Jamieson,Paul McCarty\'','Creator Talks_33f234dc1b93a8eedbc32f3238746443','\'Title: The New Software Supply Chain Nobody is Securing: MCP
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:10 - 16:50 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n\n\nSpeakers:Evan Markl,Tamir Yehuda,Jessie Jamieson,Paul McCarty
\n
\nSpeakerBio:  Evan Markl
\nNo BIO available
\nSpeakerBio:  Tamir Yehuda
\n

Tamir Yehuda is a Senior Security Researcher and cloud security team lead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows & AD domains, SaaS applications, and cloud infrastructure. Tamir specialize in IaaS & PaaS research focusing mainly on Azure, GCP, AWS, Salesforce, and ServiceNow. He brings over eight years of experience in various types of security research and red teaming.

\n\nSpeakerBio:  Jessie Jamieson
\n

Dr. Jessie Jamieson is a research mathematician with almost a decade of experience applying mathematical techniques to cybersecurity and decision making. After receiving a PhD in mathematics from the University of Nebraska-Lincoln, she moved to the DC area to use her mathematical expertise to support a number of government cybersecurity and AI-related initiatives. She’s now a mathemagician at Turngate, where she works on unifying SaaS audit logs and MCP telemetry into a single coherent picture so that defenders can actually see what AI capabilities do in their environments. Originally hailing from East Tennessee, she’s the person to ask if you’re planning a trip to DollyWood anytime soon.

\n\nSpeakerBio:  Paul McCarty, Founder and lead researcher at OpenSourceMalware, the software supply chain threat intelligence platform. Software supply chain offensive security crazy person.
\n

Paul is the founder and maintainer of OpenSourceMalware, the world\'s largest open database and collaboration platform for software supply chain threat intel. His day job is Head of Research at Safety and is a DevSecOps OG. He loves software supply chain research and delivering supply chain offensive security training and engagements. He\'s spent the last two years deep-diving into npm and has made several discoveries about the ecosystem. Paul founded multiple startups starting in the \'90s and has worked for NASA, Boeing, Blue Cross/Blue Shield, John Deere, the US military, and the Australian government.  Paul is a frequent open-source contributor and author of several DevSecOps, software supply chain and threat modelling projects. He’s currently writing a book entitled “Hacking NPM”, and when he’s not doing that, he’s snowboarding with his wife and 3 amazing kids.

\n\n\n\'',NULL,1294617),('2_Friday','16','16:50','17:30','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Trust Fall: How Agentic AI Inherits Your Cloud\'s Worst IAM Habits\'','\'Aravind Sreekanth Pallavoor,Sadhana Sainarayanan\'','Creator Talks_11b3499132b782d57dd24597a0335bc9','\'Title: Trust Fall: How Agentic AI Inherits Your Cloud\'s Worst IAM Habits
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:50 - 17:30 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\nCloud IAM was designed for two principals: humans and machines. In 2026, a third has arrived: the autonomous AI agent and it plays by neither rule book. AWS Bedrock Agents, LangChain-based orchestrators, and multi-agent pipelines are being deployed with execution roles scoped to whatever the deploying engineer thought was \"good enough,\" inheriting the same over-privileged IAM patterns that have plagued cloud environments for a decade. The difference: agents don\'t just misuse permissions accidentally. When adversarial manipulations are done, they weaponize them with precision.
\n\n

This talk dissects the threat model of agentic AI systems from an attacker\'s perspective with a clear-eyed look at how autonomous agents become cloud privilege escalation engines. Drawing from the OWASP Top 10 for Agentic Applications 2026, MITRE ATLAS, and real-world research including Sonrai Security\'s AgentCore privilege escalation path and Unit 42\'s confirmation of autonomous AI-driven cloud attacks, the talk walks through a complete attack chain: indirect prompt injection against an agent\'s context window → tool misuse via over-privileged Lambda execution roles → IAM policy modification → persistent backdoor creation — all without a single stolen credential.

\n\n

Attendees will leave with a structured threat model mapped to MITRE ATLAS tactics, a dissection of what AWS CloudTrail catches versus what it silently misses during agent-driven attacks, a breakdown of the three OWASP agentic risks most directly applicable to AWS environments (Goal Hijack, Tool Misuse, Identity & Privilege Abuse), and concrete defensive controls including agent-scoped least-privilege IAM, Bedrock Guardrails limitations practitioners need to know, and human-in-the-loop architectural patterns.

\n\nSpeakers:Aravind Sreekanth Pallavoor,Sadhana Sainarayanan
\n
\nSpeakerBio:  Aravind Sreekanth Pallavoor
\n

Aravind Pallavoor is a cybersecurity practitioner with over five years of hands-on experience spanning application security, cloud security engineering, and offensive security research. He holds CISSP, CEH (v11), and AWS Certified Security – Specialty (SCS-C02) certifications alongside a Master of Science in Cybersecurity, Technology and Policy from The University of Texas at Dallas, where he graduated with a 3.82 GPA.

\n\n

His offensive security background includes web application and API penetration testing, mobile application security, AI chatbot security assessments — including prompt injection and training data poisoning research — and cloud infrastructure security across AWS environments. He has conducted security assessments for global financial institutions and enterprise SaaS organizations, applying frameworks including OWASP, CVSS, MITRE ATT&CK, NIST, PCI DSS, and CIS Foundations.

\n\n

On the cloud side, Aravind has directly architected and audited IAM environments, deployed and red-teamed compliance automation pipelines, and operationalized AWS Config, Secrets Manager, and CI/CD pipeline security at scale. His research interest at the intersection of agentic AI and cloud identity — the subject of this talk — grew directly from real-world experience testing AI systems for adversarial manipulation and observing how autonomous tool use exposes cloud IAM to a new class of attack surface.

\n\n

\"Trust Fall\" represents his synthesis of those two worlds: offensive AI security research applied to the cloud IAM threat model, grounded in published vulnerability research, OWASP\'s Agentic Top 10 for 2026, and MITRE ATLAS — and delivered without a lab, because the threat model speaks for itself.

\n\n

Additional Speaker Bio:\nSadhana Sainarayanan is an AI and machine learning practitioner with deep expertise in autonomous pipeline design, event-driven system architecture, MLOps, and cloud-native AI deployment across GCP and Azure environments. She holds a Google Cloud Certified Professional Machine Learning Engineer certification and a Microsoft Certified Azure AI Engineer Associate certification, alongside dual Master\'s degrees from Carnegie Mellon University. Her research interests span the security implications of agentic AI systems, NLP pipeline trust boundaries, and the input-validation gaps that emerge when autonomous systems process external data at scale. For this talk, she brings the AI builder\'s perspective to the cloud identity threat model.

\n\n

Additional Speaker LinkedIn: http://www.linkedin.com/in/sadhana-sainarayanan

\n\nSpeakerBio:  Sadhana Sainarayanan
\n

Sadhana Sainarayanan is a Cloud Platform Security Analyst with experience across SAP BTP security operations, ML pipeline productionization and AI systems. She holds dual master’s degrees from Carnegie Mellon University in Engineering and Technology Innovation Management, and Civil and Environmental Engineering. Her independent projects span instrumentation for AI systems, focused on the gap between what agents report doing and what they actually do, execution auditing, and behavioral divergence detection.

\n\n\n\'',NULL,1294618),('2_Friday','17','16:50','17:30','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Trust Fall: How Agentic AI Inherits Your Cloud\'s Worst IAM Habits\'','\'Aravind Sreekanth Pallavoor,Sadhana Sainarayanan\'','Creator Talks_11b3499132b782d57dd24597a0335bc9','\'\'',NULL,1294619),('3_Saturday','10','10:00','10:40','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Bashing CloudShells for mining, networking, exfil and persistence at scale\'','\'Jenko \"edleft\" Hwong,Chris Ryan\'','Creator Talks_a6d429f76e9b4569c50c8feacf30d991','\'Title: Bashing CloudShells for mining, networking, exfil and persistence at scale
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:40 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

CloudBashing started with reversing the private AWS, Azure, and GCP CloudShell REST protocols, analyzing websocket terminal sessions, and tracing janky browser authentication/credential flows with cookies and OAuth tokens. Along the way, we automated the APIs to access free CPU/networking, maintained access across container/VM resets, utilized persistent $HOME for implants/data, locked users out of sudo access, and installed a C2 framework. We discovered IAM design issues like: AWS role assumption that result in a large # of environments per compromised identity, web socket sessions that survive API token revocation, and M365/Gmail consumer email accounts that have default CloudShell access. This turned into a newly released exploit toolkit, CloudBasher, that enumerates, validates, installs, and runs distributed workloads with virtual storage and private networking across a large-scale agent network with persistence and resilience. We\'ll demo distributing CPU-intensive workloads, using virtual storage for staging/exfiltration, secure networking for proxy and obfuscated exfil paths, while automating the discovery, enumeration, creation of CloudShell environments from initial credentials/sessions to implants/setup/networking to management and control.

\n\nSpeakers:Jenko \"edleft\" Hwong,Chris Ryan
\n
\nSpeakerBio:  Jenko \"edleft\" Hwong, Huntress Labs
\n

Jenko Hwong is a Principal Security Researcher at Huntress Labs, focusing on identity-based attacks and cloud abuse. Prior to Huntress, he spent 6 years at Netskope Threat Labs, has spoken at RSA and DEFCON, and is a Cloud Village Lead. He has over 20 years at various security startups in cloud detection/response, vulnerability scanning, AV/AS, pen-testing/exploits, L3/4 appliances, threat intel, and windows security.

\n\nSpeakerBio:  Chris Ryan, Huntress Labs
\n

A series of oddly configured server banners, a JARM fingerprint, curious fields in a security certificate - these aren\'t just technical details, but are instead threads in a narrative tapestry woven like a John le Carre novel. For over 20 years, Chris has dedicated his life to studying these threads and the intersection between cybersecurity, Russian linguistics, and free and open source software. His career path has taken detours through academia, aerospace and defense, software development, and cybersecurity.

\n\n\n\'',NULL,1294620); INSERT INTO `events` VALUES ('3_Saturday','10','10:40','11:20','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Ghost Records: Automating Dangling DNS & Subdomain Takeover Detection at Enterprise Scale\'','\'Jai Kumar Sharma,Tom McCarthy\'','Creator Talks_81f198ebcb4733fcf766e8a11c0b7359','\'Title: Ghost Records: Automating Dangling DNS & Subdomain Takeover Detection at Enterprise Scale
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:40 - 11:20 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

This is not another subdomain takeover 101 talk. It\'s about what dangling DNS actually looks like at enterprise scale - in large, multi-account AWS environments with sprawling DNS footprints - and the automation and hard-won triage lessons the problem demands.

\n\n

Let\'s be honest: ~95% of subdomain takeover findings are noise - 3rd- and 4th-level subdomains on dead non-prod environments no customer ever visits. They generate alert fatigue and little else. The other 5% - cookie theft via a *.domain.com scope, OAuth token hijack, phishing from a legitimate domain carrying a valid TLS cert - are catastrophic. Telling the 5% from the 95% is the entire game.

\n\n

Then there\'s the bug bounty dynamic. Researchers find these in bulk and report them in bulk. They\'re frustrated that fixes take weeks; program owners are frustrated that most reports are low-impact but can\'t simply be closed. The relationship erodes on both sides - a cost nobody puts on a dashboard.

\n\n

From what We\'ve seen, the time sinks are predictable: manually triaging hundreds of researcher reports, chasing low-impact findings, writing one-off fix scripts instead of systemic solutions, and reconstructing record ownership after the fact. The structural causes are just as consistent: multi-account sprawl with no central DNS ownership, rapid dev cycles where IaC teardowns never touch Route53, and researchers reporting faster than teams can remediate.

\n\n

The core of the talk is architecture: automatically cross-referencing every Route53 A record and CNAME against Elastic IPs allocated across all AWS regions, wired into ownership routing and shift-left pipeline hooks. Done right, this shifts detection from reactive to proactive, can take MTTR from weeks to hours, and eliminates entire classes of records at the source.

\n\n

We\'ll release Ghost Records, an open-source tool aimed at the one of the highest impact vector: dangling A records and CNAMEs pointing to released or unallocated AWS Elastic IPs. It inventories every EIP across all enabled regions, cross-references them against Route53, and flags any DNS record pointing to an IP the account doesn\'t own. Read-only, multi-account, parallel scanning, risk-scored output. Live demo included.

\n\nSpeakers:Jai Kumar Sharma,Tom McCarthy
\n
\nSpeakerBio:  Jai Kumar Sharma, Principal Offensive Security Engineer at GoDaddy
\n

Jai Sharma is a Principal Offensive Security Engineer at GoDaddy, where he leads cloud penetration testing, red team operations, AI red teaming, and security research across one of the world\'s largest domain registrars and hosting platforms. A self-taught offensive security researcher from New Delhi, India, he built his career with a hacker\'s mindset, breaking code logic, chasing vulnerabilities, and proving real-world business impact from technical exploits. He also leads TTP research, drives threat emulation efforts, and works closely with blue teams to sharpen detection through an adversary-focused lens.

\n\n

At GoDaddy, Jai tests the same infrastructure and enterprise environments that millions of customers rely on. His work spans cloud and on-premises penetration testing, IAM privilege escalation research, and building automated offensive tooling that helps turn point-in-time assessments into continuous detection. Before GoDaddy, Jai held offensive security roles at Housing.com, FIS, and EY, giving him firsthand experience with how security weaknesses and misconfigurations surface across different industries, architectures, and maturity levels.

\n\n

Jai volunteers with the DEF CON community as CTF Ops for the Cloud Village and on-site Coordinator for the Bug Bounty Village.

\n\nSpeakerBio:  Tom McCarthy
\n

Tom McCarthy is the Director of Offensive Security and Business Information Security Officer at GoDaddy, where he oversees penetration testing, red team operations, and security strategy across multiple lines of business. With over 15 years in offensive security — spanning consulting, penetration testing, research, and training — Tom has built multiple penetration testing teams from the ground up and led or managed hundreds of penetration tests and red team engagements throughout his career. Tom is a returning DEF CON speaker, having previously presented research, tooling, and training at both DEF CON and DerbyCon. He has contributed to open-source offensive security projects including smbexec and Metasploit, and served as a trainer in hacking and incident response for local, federal, and military organizations across multiple countries.

\n\n\n\'',NULL,1294621),('3_Saturday','11','10:40','11:20','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Ghost Records: Automating Dangling DNS & Subdomain Takeover Detection at Enterprise Scale\'','\'Jai Kumar Sharma,Tom McCarthy\'','Creator Talks_81f198ebcb4733fcf766e8a11c0b7359','\'\'',NULL,1294622),('3_Saturday','11','11:00','12:59','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'From Findings to Remediations: Open Source Cloud Security at AI Speed with Prowler\'','\'Amit Sharma,Pedro\'','Creator Events_f789a492877a41b44170b84a2d88c4a2','\'Title: From Findings to Remediations: Open Source Cloud Security at AI Speed with Prowler
\nTags: Cloud Village | Creator Event/Activity | Strategic Defense
\nWhen: Saturday, Aug 8, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) B - Map
\n
\nDescription:
\n

Cloud security teams are drowning in findings, but isolated misconfigurations rarely tell the full\nstory. This hands-on workshop shows how to use Prowler, the open-source cloud security\nplatform, to detect vulnerabilities and misconfigurations, prioritize risks, and remediate with AI-\ndriven workflows.\nParticipants will learn how to run Prowler from the CLI and import findings into Prowler Cloud\nusing the new Import Findings workflow. From there, the workshop will go beyond traditional\ncompliance reporting and demonstrate Prowler's newer capabilities: Attack Paths for graph-\nbased analysis of cloud resources, permissions, findings, and privilege-escalation chains;\nLighthouse AI for natural-language investigation, environment-aware prioritization, and direct\nguided remediation grounded in Prowler Hub's deterministic database; and the Prowler Claude\nCode plugin/MCP workflow for bringing security triage, remediation guidance, automated pull-\nrequest generation from IaC scanner findings as well as live cloud scans, and re-scanning into\nthe developer workflow.\nBy the end, attendees will understand how to use Prowler not only to assess compliance\nagainst frameworks such as CIS, GDPR, HIPAA, and cloud security best practices, but also to\nidentify which findings matter most, explain their blast radius, and accelerate remediation with\nopen source tooling and controlled AI assistance.

\n\nSpeakers:Amit Sharma,Pedro
\n
\nSpeakerBio:  Amit Sharma
\n

Amit Sharma has over a decade of experience as a cloud architect and built cybersecurity and observability products at Splunk, Cisco, and SentinelOne before joining Prowler as Head of Product.

\n\nSpeakerBio:  Pedro
\n

Pedro is a Cloud Security Engineer at Prowler, working on compliance and cloud security using open source + AI + more cool stuff across AWS, Azure, GCP, K8S, M365... Passionate about open source, trail running, and flying FPV drones.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294623),('3_Saturday','12','11:00','12:59','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'From Findings to Remediations: Open Source Cloud Security at AI Speed with Prowler\'','\'Amit Sharma,Pedro\'','Creator Events_f789a492877a41b44170b84a2d88c4a2','\'\'',NULL,1294624),('3_Saturday','11','11:00','12:59','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Patch Me If You Can: Hands-On Network Threat Defense\'','\'Don Bogert\'','Creator Events_a054ee7383720a97479091eda3b71c3b','\'Title: Patch Me If You Can: Hands-On Network Threat Defense
\nTags: Cloud Village | Creator Event/Activity | Investigation
\nWhen: Saturday, Aug 8, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) A - Map
\n
\nDescription:
\n

Join this hands-on workshop to explore an integrated set of network security capabilities designed for real-time threat detection, prevention, and proactive risk management. You’ll see how inline traffic inspection can block threats with virtual patching, helping reduce exposure before vendor patches are available.

\n\n

The session will also cover how deep network visibility supports detection of command-and-control activity, lateral movement, and advanced malware using behavioral analysis and custom sandboxing. You’ll learn how continuous asset monitoring can uncover misconfigurations, exposure, and other risk factors across the environment, then use that insight to prioritize response and reduce overall risk.

\n\nSpeakerBio:  Don Bogert
\n

With more than 25 years of experience in cybersecurity, Don brings a comprehensive approach to organizational defense. Grounded in a strong network security foundation, his expertise spans physical security, compliance auditing, and the deployment of cloud, workload, and endpoint solutions. Throughout his career, Don has secured commercial, federal, and public sector organizations globally; and understands the challenges of a secure air-gapped environment. Currently, he focuses on delivering tailored security solutions to public sector customers in the Northeastern United States.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294625),('3_Saturday','12','11:00','12:59','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Patch Me If You Can: Hands-On Network Threat Defense\'','\'Don Bogert\'','Creator Events_a054ee7383720a97479091eda3b71c3b','\'\'',NULL,1294626),('3_Saturday','11','11:20','11:59','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Trust the Cloud Pipeline, Lose the Kingdom\'','\'Shane Young\'','Creator Talks_7ece6baecb0c6d6dd386d28f4f96bbff','\'Title: Trust the Cloud Pipeline, Lose the Kingdom
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:20 - 11:59 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

In 2020, SolarWinds showed the industry what it looks like when an attacker owns a build pipeline. In 2021, Codecov did it again. CircleCI in 2023. Each incident surfaced the same pattern. Cloud CI/CD systems sit at the center of a trust graph most organizations have never actually mapped, and compromising them grants access to everything downstream: source code, cloud infrastructure, production artifacts, customer data, and every third party platform the organization stores credentials for. Detection remains largely absent.

\n\n

Five years after SolarWinds, red teams still rarely operate meaningfully against cloud native CI/CD. Most offensive security programs treat pipelines as infrastructure they inherit rather than terrain they fight over. Defenders build detection around endpoints and identities they recognize, while ephemeral build agents with elevated cloud credentials run continuously and unmonitored.

\n\n

This talk presents a full cloud native CI/CD attack chain drawn from red team engagements across multiple enterprise cloud environments. The chain starts at a low privilege developer identity. Pull request poisoning, in both direct and indirect variants, exfiltrates temporary AWS credentials from the build agent. A scheduled Lambda function then relays fresh credentials before each expiry, providing durable serverless persistence with no endpoints, no implants, and no signals a traditional detection stack watches for. IAM role trust chain abuse escalates the compromised build identity into broad cloud access spanning multiple accounts. Finally, Secrets Manager extends the attack beyond AWS. The credentials stored inside grant organization admin access to the code hosting platform, administrative control of the CI platform itself, access to customer data warehouses, and access to every SaaS and third party system the organization depends on.

\n\n

Attendees will walk away with a concrete mental model of how cloud native CI/CD fails under adversarial pressure, a specific set of detection rules that would have caught each stage (deployable against CloudTrail and CI logs most organizations already collect), and structural guidance for where trust boundaries need to exist between build infrastructure and production.

\n\n

Intermediate audience. Familiarity with AWS IAM and general CI/CD concepts is helpful; the relevant cloud mechanics will be explained as needed.

\n\nSpeakerBio:  Shane Young
\n

Shane Young is an offensive security operator and program builder with over 15 years in the field. His career spans consulting across financial services, hardware, and SaaS; building out an IoT security practice at a major security consultancy; leading red team operations against cloud native product companies; and pioneering AI/ML red teaming for deployed enterprise AI features. He is the creator of Brutespray, a public open source offensive security tool. He builds offensive security programs from scratch, runs red team operations end to end, and still carries significant technical IC workload because he thinks that is how security leaders stay sharp. He has been hacking since he was a teenager, and it still has not gotten old.

\n\n\n\'',NULL,1294627),('3_Saturday','12','12:00','12:20','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Whose Resource Is It Anyway? The Design Flaw That Breaks the IAM Permission Model\'','\'Moshe Berntsein\'','Creator Talks_acb12a2cb09861702ec447becbcaa1c5','\'Title: Whose Resource Is It Anyway? The Design Flaw That Breaks the IAM Permission Model
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:20 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

The major cloud provider’s permission model is simple: use IAM to keep the bad guys out of your cloud environment. But what if the bad guys could lure victims in? Each provider implements IAM differently, and in this talk, we will explore a hidden quirk in the GCP identity boundary that allows attackers to invert the permission model and force victims into a malicious environment.

\n\n

We will examine the unique aspects of GCP IAM and explore how a core design choice enabled cross-tenant account takeover via a novel vulnerability I discovered in Vertex AI Workbench, potentially leading to full cloud compromise.

\n\n

The biggest threat to your cloud environment could be a project you didn’t even know you were a part of.

\n\nSpeakerBio:  Moshe Berntsein
\n

Moshe Bernstein is a Senior Security Researcher specializing in cloud vulnerability research at Tenable. With over a decade of experience in cybersecurity, Moshe has developed a strong focus on network and operational security, web vulnerability research, and cloud infrastructure security. He enjoys presenting his research at conferences around the world, and is always on the lookout for new challenges.

\n\n\n\'',NULL,1294628),('3_Saturday','12','12:20','12:59','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Pinchy Gets Played: How We Red-Teamed AI Agents Before the Threats Did\'','\'Doron Kapah\'','Creator Talks_26c870a1d35a0824c15bf8fb7b5ce58f','\'Title: Pinchy Gets Played: How We Red-Teamed AI Agents Before the Threats Did
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:20 - 12:59 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

AI agents are showing up in cloud workflows with credentials, autonomy, and trust, but\nso are the threats targeting them. So, before attackers started probing them, Varonis Threat Labs did.\nWe built a target agent named Pinchy on the OpenClaw platform and put it through a red-team gauntlet using well-known techniques. Pinchy handled sophisticated technical attacks with ease but folded immediately against simple social ones. The same drive to be useful turns these agents into an attack surface that requires entirely different\ndefensive strategies.\nJoin us for a deep dive on the new risks autonomous AI brings to the cloud. You'll leave\nwith a clearer picture of where AI agents fail, why the threat model is unlike anything\nthat came before it, and what architectural controls — not prompts, not policies —\nactually keep environments secure.

\n\nSpeakerBio:  Doron Kapah
\n

Doron is an experienced security researcher at Varonis Threat Labs. He primarily focuses on advanced threat detection capabilities, threat hunting, and AI and cloud security. Doron also has extensive experience in building innovative cybersecurity product solutions, CTFs and has authored multiple publications in both state-sponsored and cybercrime threat intelligence domains.

\n\n\n\'',NULL,1294629),('3_Saturday','13','13:00','13:30','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Minimal by Design: Building Hardened Near-Zero-CVE Container Images\'','\'Kyle Quest,Ritvik Arya\'','Creator Talks_257127a189c6a61750af6efca0d5e07b','\'Title: Minimal by Design: Building Hardened Near-Zero-CVE Container Images
\nTags: Demo 💻 | Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Most production containers ship on base images with dozens of known CVEs — debian:latest currently sits at 127. Patches take weeks. Your compliance team isn\'t happy. We built \"minimal\" — an open source project producing 36 hardened (and adding more), distroless container images for the stack most cloud teams actually run: Python, Node, Go, Redis, PostgreSQL, MySQL, Kafka, Nginx, Prometheus, Jenkins, and more. Image runs as non-root, has no shell, ships with a signed SBOM, and is rebuilt daily so CVE patches land in under 48 hours instead of 30 days.\nThis talk is a practical walkthrough of how you build something like this from scratch using entirely open source tools — and what could go wrong. We\'ll cover the toolchain: Chainguard\'s melange for sandboxed source builds, apko for declarative image assembly,Wolfi as the package base, Grype for scanning, and cosign for keyless signing. \nWe\'ll show the CI pipeline — 60 parallel GitHub Actions jobs, native ARM64 runners, ephemeral signing keys for PRs, multi-arch manifest assembly — and the 24 automated update workflows that track upstream releases daily across GitHub tags, RubyGems, php.net, and Wolfi\'s APKINDEX. We\'ll close with live Grype scan comparisons against official Docker Hub images. The numbers are dramatic, and they make the case better than we can. Every source build is SHA256-verified, and every assembled image is tested in CI before publishing — tests for no shell, correct entrypoint, expected binaries present, services responding.\nEverything is open source and running in production today. If you leave this talk and build your own hardened container pipeline the next week, we\'ve done our job.

\n\nSpeakers:Kyle Quest,Ritvik Arya
\n
\nSpeakerBio:  Kyle Quest
\n

Kyle is the creator of DockerSlim, a popular tool to secure and optimize containers. His area of focus is autonomous and secure cloud-native infrastructure, sandboxing and agent security. With over two decades in security, Kyle had a chance to wear many different hats as a builder, breaker, and defender. Currently reverse engineering coding agents like Claude Code for fun AND profit ;-)

\n\nSpeakerBio:  Ritvik Arya
\n

Ritvik Arya is an Application Security Engineer at Amazon Web Services specializing in cloud security, container security, and offensive security research. His work focuses on securing large-scale cloud-native applications, building hardened container ecosystems, and developing scalable AppSec automation and vulnerability discovery tooling.

\n\n\n\'',NULL,1294630),('3_Saturday','13','13:30','15:30','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Breaking AWS Bedrock: Novel Attack Techniques Against Cloud Infrastructure\'','\'Tal Peleg,Maya Parizer\'','Creator Events_dcc6a126fc9a569f3e35211cbca6c260','\'Title: Breaking AWS Bedrock: Novel Attack Techniques Against Cloud Infrastructure
\nTags: Cloud Village | Creator Event/Activity | Attack
\nWhen: Saturday, Aug 8, 13:30 - 15:30 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) A - Map
\n
\nDescription:
\n

Amazon Bedrock is no longer just a research toy. It's embedded in CI/CD pipelines,\nproduction applications, and development workflows, often granted sweeping\npermissions over S3, IAM, and other AWS services. The rapid adoption of agentic AI\nhas reproduced a new class of configuration patterns that security teams haven't caught\nup with yet.\nIn this hands-on attack lab, Varonis Threat Labs takes you inside real Bedrock\ndeployment patterns observed across AWS environments. Participants will move from\ninitial Bedrock access through data exfiltration, lateral movement, and AWS account\ncompromise, exploiting the same misconfigurations we've found in the wild.\nNo AI hype. No prompt injection gimmicks. This is cloud infrastructure security, and\nBedrock just happens to be the way in. Leave with attack paths you can take back to\nyour own environment and the defensive controls to shut them down.\nTal’s Bio:\nTal Peleg, also known as TLP, is a senior security researcher and cloud security team\nlead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows\ndomains, SaaS applications, and cloud infrastructure. His research is currently focused\non cloud applications, APIs, and agentic applications.

\n\nSpeakers:Tal Peleg,Maya Parizer
\n
\nSpeakerBio:  Tal Peleg
\n

Tal Peleg, also known as TLP, is a senior security researcher and cloud security team lead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows domains, SaaS applications, and cloud infrastructure. His research is currently focused on cloud applications, APIs, and agentic applications.

\n\nSpeakerBio:  Maya Parizer
\n

Maya Parizer is a Security Researcher at Varonis with a passion for cloud security, identity, and data protection, specializing in IaaS and AI. Maya dives deep into every project, thoroughly investigating cloud environments to uncover potential vulnerabilities and stealthy attack techniques. Her experience spans both offensive and defensive disciplines — including CSPM, DSPM, vulnerability research, detection engineering, and product security research in cloud environments.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294631),('3_Saturday','14','13:30','15:30','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Breaking AWS Bedrock: Novel Attack Techniques Against Cloud Infrastructure\'','\'Tal Peleg,Maya Parizer\'','Creator Events_dcc6a126fc9a569f3e35211cbca6c260','\'\'',NULL,1294632),('3_Saturday','15','13:30','15:30','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'Breaking AWS Bedrock: Novel Attack Techniques Against Cloud Infrastructure\'','\'Tal Peleg,Maya Parizer\'','Creator Events_dcc6a126fc9a569f3e35211cbca6c260','\'\'',NULL,1294633),('3_Saturday','13','13:30','14:30','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'Fix It, Snooze It, or Ignore It? Cloud Security Decisions Under Pressure\'','\'Mackenzie Jackson\'','Creator Events_4458180fc162e94115ef31921829d320','\'Title: Fix It, Snooze It, or Ignore It? Cloud Security Decisions Under Pressure
\nTags: Cloud Village | Creator Event/Activity | Strategic Defense
\nWhen: Saturday, Aug 8, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) B - Map
\n
\nDescription:
\n

Cloud security teams rarely struggle to find issues. They struggle to decide what actually matters—and how to fix them with limited resources.

\n\n

In this interactive CloudSec Village lab hosted by Aikido Security, attendees step into the role of a cloud security lead. Navigating a custom simulation dashboard, you\'ll manage a realistic environment spanning containers, Kubernetes, serverless, and virtual machines.

\n\n

The catch? Your engineering teams have a strict cap on available hours, and every fix comes with an estimated time cost. You must evaluate a live queue of vulnerabilities, assign remediation to the right teams, and decide what to fix, defer, or ignore to find the most optimal defense strategy before your resources run out.

\n\n

This drop-in lab focuses on real-world decision-making under pressure rather than theory. Join at any time, manage your clock, and see how your prioritization strategy compares.

\n\nSpeakerBio:  Mackenzie Jackson
\n

Mackenzie is the Field CTO for Aikido Security, helping tech leaders understand application security through an attacker’s lens. As the co-founder and former CTO health tech company Conpago, he understands the challenges of building secure applications. He has spoken in over 30 countries, hosts the popular Podcast The Secure Disclosure, and contributes to multiple publications including Dark Reading, Financial Times, and Fast Company.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294634),('3_Saturday','14','13:30','14:30','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'Fix It, Snooze It, or Ignore It? Cloud Security Decisions Under Pressure\'','\'Mackenzie Jackson\'','Creator Events_4458180fc162e94115ef31921829d320','\'\'',NULL,1294635),('3_Saturday','13','13:30','14:10','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'What\'s Behind the Curtain? Tearing Down AWS\'s AI Agent Runtime From the Inside\'','\'Dan Gansel\'','Creator Talks_e8b2f1fe431a0267627f8c4625dfb948','\'Title: What\'s Behind the Curtain? Tearing Down AWS\'s AI Agent Runtime From the Inside
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 14:10 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

How much do you actually know about one of the world\'s leading agent-building platforms? When you deploy an AI agent to Bedrock AgentCore, your code lands inside a Firecracker microVM - and you\'re told almost nothing about what\'s in there with you. So I decided to find out.

\n\n

Starting from nothing, we\'ll work our way through the layers: Runtime, Networking, Identity, Observability, etc - mapping what an attacker can reach, what they can break, and what actually holds. We\'ll explore novel techniques that allowed me to extract information the platform was never meant to expose.

\n\n

Along the way, we\'ll uncover an undocumented platform, strange auth behaviors, security boundaries that didn\'t hold up, and internal architecture details not covered in any public documentation.

\n\n

By the end, you\'ll see what\'s really behind the curtain and what it tells us about how AWS builds and secures managed AI workloads. The methodology is reusable - the next time you\'re researching an opaque managed runtime, you\'ll know where to look.

\n\nSpeakerBio:  Dan Gansel
\n

Dan Gansel is a cloud security specialist with deep expertise in cloud API research, secure cloud solutions and architecture design. Dan has led cloud security research teams and has a track record of uncovering novel attack techniques in cloud environments.\nAs a Security Researcher at Upwind Security, Dan continues to push the boundaries of cloud security, focusing on uncovering blind spots in the services organizations trust the most.

\n\n\n\'',NULL,1294636),('3_Saturday','14','13:30','14:10','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'What\'s Behind the Curtain? Tearing Down AWS\'s AI Agent Runtime From the Inside\'','\'Dan Gansel\'','Creator Talks_e8b2f1fe431a0267627f8c4625dfb948','\'\'',NULL,1294637),('3_Saturday','14','14:10','14:50','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Autonomous Offense vs. Autonomous Defense: Who\'s Winning in the Cloud?\'','\'Evan Markl,David Fišer,Michael Chan,Nick Nolen\'','Creator Talks_9d925879dff73b453210363c298f8962','\'Title: Autonomous Offense vs. Autonomous Defense: Who\'s Winning in the Cloud?
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:10 - 14:50 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n\n\nSpeakers:Evan Markl,David Fišer,Michael Chan,Nick Nolen
\n
\nSpeakerBio:  Evan Markl
\nNo BIO available
\nSpeakerBio:  David Fišer
\n

David Fiser is a cybersecurity professional with over 15 years of experience. He regularly contributes to blogs and co-authors whitepapers on various security topics. He has been credited with several CVEs, including high-profile vendors such as Microsoft and NVIDIA. He presented his previous research at multiple security conferences. Personally, David is passionate about motorsport, cars, planes, and motorcycles. He also likes fixing broken items and traveling.

\n\nSpeakerBio:  Michael Chan, Senior Offensive Security Consultant at KPMG Canada
\n

Michael is a social scientist turned hacker. He started by studying human behaviour and trust at Oxford - now he brings that lens into offensive security, validating and breaking the assumptions built into applications, systems, and organizations. As a Senior Offensive Security Consultant at KPMG Canada, Michael works across application security, threat modelling, and adversary simulation. Outside of work, he spends most of his time learning, building, breaking fun new tech (yes AI included), and engaging with local cyber communities.

\n\nSpeakerBio:  Nick Nolen
\n

Nick Nolen is Chief Operating Officer at Redpoint Cybersecurity, a full-service cybersecurity consulting firm. He has spent 15 years inside organizations building security programs, responding to real incidents, and making real investment decisions about defensive tooling, including serving as an operational leader during Cognizant\'s response to the MAZE ransomware attack and transforming ConnectWise\'s Product Security Office from the ground up. He brings that leadership experience to the autonomous offense vs. defense debate, not from a research lab, but from having lived through what happens when theory meets production.

\n\n\n\'',NULL,1294638),('3_Saturday','14','14:50','15:20','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'cloud-auth: a provider-agnostic CLI for cross-cloud workload identity\'','\'Aniruddha Biyani\'','Creator Talks_861a6e3dfa00ac8c1da37c10894901b9','\'Title: cloud-auth: a provider-agnostic CLI for cross-cloud workload identity
\nTags: Demo 💻 | Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:50 - 15:20 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Modern engineering teams don\'t live in one cloud. A workload in Google Kubernetes Engine needs to read from an S3 bucket. An EC2 instance needs to fetch a secret from Azure Key Vault. A single GitHub Actions job has to deploy to AWS, log telemetry to GCP, and trigger a workflow in Azure — all in the same run. The default way teams make this work is the same way they have for a decade: paste a long-lived credential into a secret and hope nobody finds it.

\n\n

This is the credential sprawl problem at the heart of every multi-cloud breach. Static AWS access keys, GCP service account JSON files, Azure client secrets — the most reliably exploited foothold in cloud environments, sitting in env vars, secret managers, and committed git history across every blue team\'s environment.

\n\n

Why this was hard before cloud-auth? In theory, every major cloud already supports a way to skip the static credential entirely. A GKE pod can assume an AWS IAM role directly — no AWS keys anywhere. An EC2 instance can call Azure with no service principal on it. A Kubernetes workload can hit GCP APIs with no service account JSON file. In practice, each cloud has its own model, API, and failure modes. Setting up just one of these connections means learning a new mental model, authoring trust documents with provider-specific subject formats, and validating it all by hand. Doing it across clouds means doing that work three or four times over, with no consistent way to set it up, validate it, or clean it up.\nThat friction is why cloud-auth exists. The secure path is already supported by the clouds — defenders just need tooling that makes it as easy as pasting an access key, or easier. So most teams stay on static keys.

\n\n

cloud-auth: cross-cloud workload identity for defenders\ncloud-auth is an open-source CLI and library that gives blue teams one consistent way to set up, validate, and safely retire cross-cloud workload identity. One command stands up the trust between any two of: AWS, GCP, Azure, HashiCorp Vault, Cloudflare, GitHub Actions, and Kubernetes. The same command validates it, previews changes before applying, and tears it down without touching anything it didn\'t create.

\n\n

Live demo\nGKE pod → AWS S3, no AWS keys. A GKE pod reads from S3 using a short-lived AWS role.\nEC2 → Azure Key Vault, no service principal. An EC2 instance fetches a secret with no Azure client secret on it.\nGitHub Actions → AWS, GCP, and Azure in one workflow. A single CI job deploys across three clouds.\nCatching a misconfigured trust. The validator flags an overly permissive trust before it ships.\nSafe teardown. Dry-run a multi-cloud cleanup, then execute. cloud-auth only deletes what it created.

\n\n

What attendees leave with? A working open-source tool, a concrete pattern for cross-cloud workload identity, and a validation framework to drop into existing CI/CD.\nRepository: https://github.com/anirudhbiyani/cloud-auth (LGPL-3.0)

\n\nSpeakerBio:  Aniruddha Biyani
\n

Aniruddha \"AB\" Biyani leads the Security and Compliance program at Prophecy, where he focuses on building security as a business enabler for high-growth cloud and AI platforms. His work centers on scaling information security programs, strengthening cloud and identity security, enabling secure product development, and aligning security strategy with customer trust, compliance, and engineering velocity. He has previously held security roles at Mandiant, Securonix, CRED, and Khoros.

\n\n

AB\'s career spans cloud security leadership across startups and cybersecurity vendors, with deep experience in defensive cloud engineering, identity and access management, secure developer enablement, and operationalising secure-by-default practices in fast-moving organizations. He is known for translating complex security challenges into practical programs, tools, and frameworks that help engineering teams move quickly while reducing risk.

\n\n

AB has presented at global security conferences including Black Hat Arsenal, SANS CloudSecNext, and MCPDev BLR, on workload identity, multi-cloud attack surface discovery, credential lifecycle management, and secure cloud adoption at scale. He is also an active open-source contributor and community builder, maintaining cloud security tools and secure developer training resources. He previously served for three years as a core DEF CON Cloud Village CTF volunteer, leading contest design and build efforts.

\n\n\n\'',NULL,1294639),('3_Saturday','15','14:50','15:20','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'cloud-auth: a provider-agnostic CLI for cross-cloud workload identity\'','\'Aniruddha Biyani\'','Creator Talks_861a6e3dfa00ac8c1da37c10894901b9','\'\'',NULL,1294640),('3_Saturday','15','15:20','15:59','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'A New Hope for SSRF: Exploiting Credential Relay from APIM to AI Foundry\'','\'Marios Gyftos,Chrysostomos Manousis\'','Creator Talks_2bf63a9fe9e68cd079e3b094544d8c61','\'Title: A New Hope for SSRF: Exploiting Credential Relay from APIM to AI Foundry
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:20 - 15:59 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

We found the same root cause — credentials and destinations resolving independently — across six Azure services spanning AI platform, developer tooling, Kubernetes infrastructure, and traditional enterprise services. User-controlled input reaches an outbound HTTP request carrying Managed Identity tokens, HMAC secrets, or OAuth credentials, and nothing validates where the request goes.

\n\n

The affected services include Azure AI Foundry (code interpreter and OpenAPI tool), Azure AI Speech, Azure MCP Servers, AKS MCP, and Azure API Management. The impact ranges from stealing live MI tokens for any Azure audience, to dumping production Key Vault URIs and never-expiring write SAS tokens from Microsoft\'s own backend, to root RCE on Kubernetes nodes through a readonly tool. One finding has CVE-2026-26118 assigned; the rest are reported to MSRC and pending.

\n\n

We built attack chains that combine these findings: Foundry MI theft into full tenant reconnaissance, Speech SSRF into persistent backend access via never-expiring SAS, MCP credential relay delivered remotely through prompt injection with no network access to the target, and AKS command injection into cluster-wide lateral movement via Azure\'s AKS MCP. The oldest service we found this in — APIM — has been in production for over a decade. The newest — AI Foundry — shipped last year. Same pattern.

\n\n

The talk includes three live demos, a credential relay taxonomy, and a testing methodology the audience can apply on their next Azure engagement. All findings reported to MSRC before submission.

\n\nSpeakers:Marios Gyftos,Chrysostomos Manousis
\n
\nSpeakerBio:  Marios Gyftos
\n

Marios Gyftos is a Senior Penetration Tester specializing in cloud security across AWS, Azure, and GCP since 2017. He previously presented at DEF CON 33 Cloud Village on Azure service principal exploitation, BSides Athens 2024, and BSidesChicago 2023 on DevOps attack chains. He is the creator of Azure AppHunter, an open-source tool for scanning Graph API permission misconfigurations. He has reported multiple vulnerabilities to MSRC across Azure AI Foundry, Azure Speech, AKS, Azure MCP, APIM, and Entra ID. Solo speaker — all research, exploitation, and vendor reporting was conducted independently.

\n\nSpeakerBio:  Chrysostomos Manousis
\n

Chrysostomos Manousis is a cybersecurity professional and Senior Penetration Tester at Mind The Hack, specializing in penetration testing, red teaming, and the delivery of cybersecurity and information technology services. He holds an MEng in Electrical and Computer Engineering, with a focus on software and hardware engineering. His background spans offensive security across web, cloud, and enterprise environments, and he holds multiple industry-recognized certifications.

\n\n\n\'',NULL,1294641),('3_Saturday','16','16:00','17:59','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'OCIguana - A vulnerable-by-design OCI lab\'','\'Eli Shparaga\'','Creator Events_d6057784528831b9aded0d5424f48c5c','\'Title: OCIguana - A vulnerable-by-design OCI lab
\nTags: Cloud Village | Creator Event/Activity | Attack | Tools
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) A - Map
\n
\nDescription:
\n

This workshop will discuss Oracle Cloud Infrastructure (OCI) and its unique take on IAM in\n[kcomparison to other major cloud providers. We will explore how OCI\'s policy language, dynamic groups, and principal types (instance principals, resource principals) create an attack surface that differs from other major cloud providers. Attendees will also get hands-on experience with attacking OCI environments by completing a vulnerable-by-design lab, designed to highlight the unique design decisions of OCI and its IAM system in general.

\n\nSpeakerBio:  Eli Shparaga
\n

Eli Shparaga is a Security Researcher in XM Cyber, specializing in cloud and AI security. His work involves identifying attack vectors and adversarial tactics in major cloud providers. Before that, Eli worked as a red teamer, helping secure multiple Fortune 500 companies.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294642),('3_Saturday','17','16:00','17:59','Y','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) A','\'OCIguana - A vulnerable-by-design OCI lab\'','\'Eli Shparaga\'','Creator Events_d6057784528831b9aded0d5424f48c5c','\'\'',NULL,1294643),('3_Saturday','16','16:00','16:59','N','Cloud Village','LVCCW Level 3 W311 (Cloud Village Labs) B','\'Securing the AI Stack and Hunting Across Clouds\'','\'Bryant Pickford\'','Creator Events_994a8a3fb1d3fc26cf6b4f1eccc1c0d6','\'Title: Securing the AI Stack and Hunting Across Clouds
\nTags: Cloud Village | Creator Event/Activity | Strategic Defense
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 3 W311 (Cloud Village Labs) B - Map
\n
\nDescription:
\n

Teams are deploying AI agents fast, often without guardrails. Attackers are exploiting cross-cloud trust to pivot between environments. This lab tackles both.

\n\n

Part A (30 min): Securing the AI Stack- Find over-broad permissions on an AI agent\'s execution role - Discover prompt injection evidence in model invocation logs - Review Amazon Bedrock Guardrails that block injection, prevent system prompt leakage, and filter PII

\n\n

Part B (30 min): Cross-Cloud Threat Hunting with OCSF- See how AWS, Azure, and GCP logs map to the same OCSF schema - Trace lateral movement across three clouds using federated identity - Write a detection rule that catches cross-cloud federation abuse

\n\nSpeakerBio:  Bryant Pickford
\n

Bryant Pickford is a Security Specialist Solutions Architect at AWS, where he leads security, risk, and compliance discussions with enterprise customers to align strategies and drive secure outcomes on the AWS platform. With over five years at AWS and deep expertise in Edge Security, Threat Detection, and Generative AI, Bryant specializes in identifying emerging threats and developing practical defense strategies for cloud-native environments.

\n\n\nLinks:
    Pre-registration - https://forms.gle/62vUrxFuW7prwUze9
\n\'',NULL,1294644),('3_Saturday','16','16:00','16:40','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'The 100-to-1 Problem: Securing the Non-Human Identity Perimeter\'','\'Evan Markl,Christopher Rae,Robert Pimentel,Sam \"Frenchie\" Stewart\'','Creator Talks_0b90ceab1a364c88131b2cf5d9fabd60','\'Title: The 100-to-1 Problem: Securing the Non-Human Identity Perimeter
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:40 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Non-human and machine identities rapidly outpace human users and AI agents are accelerating the gap. This panel explores how autonomous agents break the assumptions that traditional machine-identity and secrets-management strategies were built on and how to secure secrets and delegate permissions at machine scale.

\n\nSpeakers:Evan Markl,Christopher Rae,Robert Pimentel,Sam \"Frenchie\" Stewart
\n
\nSpeakerBio:  Evan Markl
\nNo BIO available
\nSpeakerBio:  Christopher Rae
\n

Christopher Rae is a Principal Worldwide Security Specialist at AWS focused on AI security. He develops solutions and guidance for customers securing AI workloads in production, applying AI to security operations, and building defenses against AI-augmented threats on AWS and across hybrid/multicloud environments. He co-authored the AWS AI Security Framework and is a proponent of secure-by-design, secure-by-default, and defense-in-depth approaches to securing the full AI stack. He sees AI security not as a constraint, but as a catalyst for improving security across the enterprise.

\n\nSpeakerBio:  Robert Pimentel, Hacker Hermanos
\n

Robert is a seasoned offensive security professional with more than a decade of experience in Information Security.

\n\n

He began his career in the U.S. Marine Corps, where he worked on secure telecommunications. Robert holds a master\'s degree in Cybersecurity, numerous IT certifications, and a background as an instructor at higher education institutions like the New Jersey Institute of Technology and American University.

\n\n

Robert is committed to sharing his knowledge and experiences for the benefit of others. He enjoys Brazilian steakhouses and cuddling with his pugs while writing Infrastructure as Code to automate Red Team Infrastructure.

\n\n

Robert is the Director of Offensive Security at Humana, Inc.

\n\nSpeakerBio:  Sam \"Frenchie\" Stewart
\n

Sam \"Frenchie\" Stewart still finds it very odd referring to himself in the third person and instead chooses to break the fourth wall. Head of Security @ Serval.com Cloud/Cluster/Container/supplyChain/anything-starting-with-a-C security geek.

\n\n\n\'',NULL,1294645),('3_Saturday','16','16:40','16:59','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Key Rotation Won\'t Save You: Hunting Workload Identity Backdoors in AWS and GCP\'','\'Jie Wu\'','Creator Talks_147b8768afbe363279f67513906e3eea','\'Title: Key Rotation Won\'t Save You: Hunting Workload Identity Backdoors in AWS and GCP
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:40 - 16:59 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Cloud incident response runbooks end with \"rotate all keys and credentials.\" AWS IAM Roles Anywhere and GCP Workload Identity Federation were designed to remove keys from the trust chain, and that design is what lets an attacker survive standard containment.

\n\n

This talk shows how an attacker registers their own certificate authority as an AWS Roles Anywhere trust anchor, or modifies a GCP Workload Identity Federation provider to trust an attacker-controlled identity, and mints fresh credentials indefinitely. Defender content has not caught up to the attack research: Roles Anywhere trust anchor and session events land in CloudTrail by default, but no published hunting query traces the CreateSession back to the issuing certificate authority via the hex serial recorded in roleSessionName. GCP pool and provider creation lands in Admin Activity logs for free, but the federated token exchange only lands in Data Access logs when explicitly enabled and paid for.

\n\n

The session closes with the cross-cloud fingerprint: when the same attacker-controlled OIDC provider is registered in both clouds (as an AWS OIDC identity provider and as a GCP Workload Identity Federation pool provider), the same OIDC sub claim surfaces in both audit trails. Extracting and joining on it ties one attacker to two cloud incidents.

\n\n

Attendees will gain the WIF Hunting Pack: a working playbook for keyless persistence in AWS and GCP, two prevention policy templates that block the attack at organization scope, and a cross-cloud correlation pattern for OIDC-based incident response. Live demo across speaker-controlled AWS and GCP environments. This talk is for blue teamers and platform security engineers who secure infrastructure across AWS and GCP.

\n\nSpeakerBio:  Jie Wu
\n

Jie is a Senior Security Engineer at Shopify based in New York City, working on cloud security, Kubernetes, and detection engineering to secure cloud infrastructure. She has spoken at KubeCon EU, fwd:cloudsec, and BSides (Chicago, Ottawa, Montréal), covering topics from Kubernetes security at scale to non-human identity accountability in the cloud. Before Shopify, she worked on cyber defense and vulnerability management at Bank of America.

\n\n\n\'',NULL,1294646),('4_Sunday','10','10:00','10:40','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Tag, You’re It: Authorization Traps in AWS ABAC\'','\'Itay Saraf\'','Creator Talks_69cf10320b0a787d135f75af0943559e','\'Title: Tag, You’re It: Authorization Traps in AWS ABAC
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:40 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

AWS Attribute-Based Access Control (ABAC) is gaining popularity for good reason: it scales well, minimizes policy duplication, and aligns with dynamic cloud environments. However, it can expand the attack surface in unexpected ways.\nIn AWS, ABAC often relies on tags and attributes whose semantics are easier to misunderstand than most practitioners realize. Those semantics determine whether a policy actually enforces the intended boundary, or quietly creates a new attack surface.\nIn this talk, we present a taxonomy of authorization traps in AWS ABAC: recurring patterns where policies look correct but do not behave as expected. These traps arise from ambiguous documentation, non-obvious IAM evaluation rules, service-specific behavior, and edge cases. Different as they may be, they often lead to the same result: a broken security boundary.\nThis talk is for anyone building, reviewing, or attacking access control in AWS - from cloud security practitioners and IAM engineers to red teamers. Expect real policy examples, common failure patterns, and practical techniques you can apply directly in your own environments, with takeaways relevant to almost any AWS setup.

\n\nSpeakerBio:  Itay Saraf
\n

Itay Saraf is a Senior Cloud Security Researcher at CrowdStrike. He has a background of offensive security, and worked as a red teamer targeting enterprise environments around the world, including multiple Fortune 500 companies. Today, he brings that offensive mindset to cloud and AI research, focusing on exposing real-world threats in modern cloud infrastructure.

\n\n\n\'',NULL,1294647),('4_Sunday','10','10:40','11:20','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'When Machines Attack Machines: Detecting AI-Autonomous Cloud Compromise at NHI Scale\'','\'Gowthamaraj Rajendran\'','Creator Talks_c8749c970c28f07f5a179a14d62623a3','\'Title: When Machines Attack Machines: Detecting AI-Autonomous Cloud Compromise at NHI Scale
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:40 - 11:20 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Two forces are converging to break cloud detection as we know it. First, non-human identities (NHIs) such as service accounts, API keys, OAuth tokens, AI agent credentials now outnumber human identities by ratios exceeding 100:1 in enterprise environments. 97% of these NHIs carry excessive privileges, 71% are never rotated within recommended timeframes, and over 40% are orphaned with no human owner. Second, attackers have begun using AI agents to compromise these identities at machine speed, performing hundreds of reconnaissance actions per minute, autonomously mapping privilege escalation paths, and executing lateral movement faster than any human analyst can respond.\nThe result is a detection problem that traditional security tools were never designed to handle: machine-speed attacks against machine identities, where the attacker\'s AI agent looks indistinguishable from the defender\'s AI agent in the logs.\nThis talk presents the first detection engineering framework purpose-built for this collision covering how to baseline NHI behavior, detect AI-autonomous compromise patterns, and build response automation that can match attacker speed.

\n\nSpeakerBio:  Gowthamaraj Rajendran
\n

Gowthamaraj Rajendran is a Detection and Response Engineer at Meta with over 6 years of experience in cybersecurity. He specializes in building high-fidelity rules and improving detection engineering practices at scale.

\n\n\n\'',NULL,1294648),('4_Sunday','11','10:40','11:20','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'When Machines Attack Machines: Detecting AI-Autonomous Cloud Compromise at NHI Scale\'','\'Gowthamaraj Rajendran\'','Creator Talks_c8749c970c28f07f5a179a14d62623a3','\'\'',NULL,1294649),('4_Sunday','11','11:20','11:50','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Breaking the Oracle: Building an Offensive Security Toolkit for OCI\'','\'Scott Weston\'','Creator Talks_746b858b88fd8fba7fb3db05d6c32b1f','\'Title: Breaking the Oracle: Building an Offensive Security Toolkit for OCI
\nTags: Demo 💻 | Cloud Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:20 - 11:50 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Oracle Cloud Infrastructure (OCI) is arguably one of the lesser-explored major cloud platforms from an offensive security perspective. While OCI shares many familiar IAM concepts with AWS and GCP, its identity architecture—including sentence-based IAM policies, identity domains, dynamic groups, compartment hierarchies, and cross-tenancy permissions—creates authorization relationships and privilege escalation paths that benefit from OCI-specific analysis.

\n\n

To help tackle these challenges, I built OCInferno, an open-source OCI reconnaissance framework for offensive security assessments. Alongside oci-lexer-parser, an ANTLR-based parser for OCI\'s sentence-based IAM policies, and OCISigner, a Burp Suite extension for transparently signing OCI API requests, a pentester/blue teamer can automate enumeration, model OCI IAM relationships, and build OpenGraph-based attack paths similar to BloodHound to help visualize privilege escalation opportunities.

\n\n

This talk will demonstrate how to model OCI IAM relationships and uncover OCI-specific attack paths that are difficult to spot from policy text alone. It will also cover a security issue I uncovered that was acknowledged by Oracle in the June 2026 Critical Security Patch Update under its Security-in-Depth program, illustrating how offensive security research can uncover weaknesses not only in customer environments but in the cloud platform itself.\nWhether you\'re new to OCI or already assessing cloud environments, you\'ll leave with a practical understanding of OCI IAM, identity-domain-aware attack path analysis, and an open-source toolkit for exploring OCI security.

\n\nSpeakerBio:  Scott Weston
\n

Originally from Southern California and now based in Minneapolis, Scott has six years of experience in information security. As a Labs Researcher at NetSPI, he builds open-source tools and research material focused on cloud security and penetration testing across AWS, GCP, and OCI environments. His tools include gcpwn, ocinferno, oci-lexer-parser, and ocisigner.

\n\n

In his spare time, he enjoys being a totally fair and impartial D&D Dungeon Master, and holding out hope that San Diego FC will advance to the MLS finals.

\n\n\n\'',NULL,1294650),('4_Sunday','11','11:50','12:30','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Foxveil: Cloud-Native Loader Tradecraft on Cloudflare, Netlify, and Discord\'','\'Shani Kurtzberg,Zohar Buber\'','Creator Talks_c6f12801df46b3005b3535b0271c54c2','\'Title: Foxveil: Cloud-Native Loader Tradecraft on Cloudflare, Netlify, and Discord
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:50 - 12:30 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n

Malware loaders used to advertise themselves with throwaway domains, fragile hosting, and obvious command-and-control infrastructure. Foxveil is a hard reset in loader tradecraft.\nLess attacker-owned infrastructure, less disk-heavy execution, fewer static clues, and more abuse of platforms defenders see every day.\nThis newly documented loader stages payloads from our most trusted and favorite cloud-native tool chains: Cloudflare Pages, Netlify, and Discord attachments, executes shellcode largely in memory, establishes persistence through masqueraded Windows artifacts, and actively rewrites analysis-significant strings at runtime to make reverse engineering and static detection harder.\nAcross two observed variants, Foxveil combines several pieces of modern tradecraft into one compact initial-stage loader. One variant spawns a fake svchost.exe and performs Early Bird APC injection into the target process before it fully resumes. Another pulls shellcode from Discord attachments and executes it through self-injection. Both stage follow-on payloads from trusted platforms, drop files into SysWOW64 under names designed to blend into normal Windows noise, and use runtime string mutation to corrupt keywords such as beacon, meterpreter, shellcode, and even fox itself.\nThis talk walks through the full Foxveil infection chain, from staging and shellcode delivery to persistence and follow-on deployment, and examines what makes this loader part of a broader shift in attacker and malware tradecraft by comparing both variants. The real story is not just cloud-hosted staging. It is the emergence of a loader model that borrows trust instead of building infrastructure. Foxveil examines what modern initial-stage malware looks like when it is designed for rotation, ambiguity, and survival.

\n\nSpeakers:Shani Kurtzberg,Zohar Buber
\n
\nSpeakerBio:  Shani Kurtzberg
\n

Shani Kurtzberg is an XDR Team Lead at Cato Networks and member of Cato CTRL. She leads the Threat Intelligence and XDR Detection Engineering initiatives. Prior to Cato, Shani served in the Israeli Air Force (IAF) as a Security Analyst, leading SOC operations to protect critical systems. Shani holds a Master of Business Administration (M.B.A.) from Peres Academic Center, specializing in Marketing and Product Management.

\n\nSpeakerBio:  Zohar Buber
\n

Zohar Buber is a security analyst in Cato Research Labs at Cato Networks. He focuses on network protocol analysis and malicious traffic detection, specializing in threat identification using network-based methods. He previously worked at Radware, where he examined threats in the DDoS industry. Zohar holds B.A focused in Business Administration, Information System Analysis // Zohar Buber, zohar@devtalks.me

\n\n\n\'',NULL,1294651),('4_Sunday','12','11:50','12:30','Y','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Foxveil: Cloud-Native Loader Tradecraft on Cloudflare, Netlify, and Discord\'','\'Shani Kurtzberg,Zohar Buber\'','Creator Talks_c6f12801df46b3005b3535b0271c54c2','\'\'',NULL,1294652),('4_Sunday','13','13:10','13:30','N','Cloud Village','LVCCW Level 3 W313 (Cloud Village Talks)','\'Closing Talk\'','\'Jayesh Singh Chauhan\'','Creator Talks_29890c7fe745a57de812b31fc991b173','\'Title: Closing Talk
\nTags: Cloud Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 13:10 - 13:30 PDT
\nWhere: LVCCW Level 3 W313 (Cloud Village Talks) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Jayesh Singh Chauhan
\nNo BIO available
\n\n\'',NULL,1294653),('2_Friday','14','14:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Farsight: Turning OSINT into Actionable Attack Surface Intelligence\'','\'Arif,Sai Vernekar,Seedon D\'Souza,kvprashant\'','Creator Events_9a64138ed61a2eee302e2ed90310bc3c','\'Title: Farsight: Turning OSINT into Actionable Attack Surface Intelligence
\nTags: Intro/Beginner | AppSec Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

Farsight is an open-source reconnaissance and threat intelligence framework designed to transform fragmented OSINT workflows into a unified, automated intelligence pipeline. Traditional reconnaissance relies on multiple disconnected tools, manual correlation, and inconsistent outputs, limiting scalability and efficiency.

\n\nSpeakers:Arif,Sai Vernekar,Seedon D\'Souza,kvprashant
\n
\nSpeakerBio:  Arif
\n

Senior Security Engineer with 5+ years of experience helping companies build and ship secure products without slowing down innovation. I specialize in Web, API, and Mobile Pentesting, Cloud Security, Threat Modeling, and embedding scalable SSDLC practices. My security journey began with curiosity and evolved into real-world impact—during an audit, I uncovered a critical flaw that could’ve exposed sensitive internal data. At Poshmark, I’ve led third-party library risk assessments, performed architecture reviews for key features, and rolled out secure coding practices across engineering. My threat modeling work improved early risk detection by 40%. Outside of work, I run hands-on security workshops, organize CTFs, and speak at conferences like c0c0n and Seasides. I\'m open to the chance to solve real-world security challenges. Let’s connect and build secure systems that scale.

\n\nSpeakerBio:  Sai Vernekar
\n

Sai Santosh Vernekar is a seasoned Application Security Practitioner with over a decade of expertise in application security. Over his career, Sai has undertaken secure code review, DAST, Devsecops, penetration testing as well as threat modeling. He currently works as Senior Security Engineer at Kohl’s. His keen interest lies in Cloud Security & secure CI/CD implementations.

\n\nSpeakerBio:  Seedon D\'Souza
\n

Hardware security expert with 10+ years in RF hacking, drone security, and exploitation. Speaker at Seasides Goa. Formerly at Sony, now at Festo.

\n\nSpeakerBio:  kvprashant
\n

Prashant Venkatesh is an information security expert with over 20 years of experience. He presently works as, Product security Leader

\n\n

Prashant is an enthusiastic participant in the field who consistently coordinates, reviews papers, and presents his work at numerous InfoSec conferences, including at Nullcon and c0c0n. He is also active through the OWASP Bay Area chapter Leadership and he is co-founder of annual Seasides Conference.

\n\n\n\'',NULL,1294654),('2_Friday','15','15:30','15:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Zero Trust Kubernetes Security: Preventing Real World Container Attacks\'','\'Janakiram Meka\'','Creator Talks_44e2b296b11a63cc96f9b5eda7e0aab4','\'Title: Zero Trust Kubernetes Security: Preventing Real World Container Attacks
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Kubernetes has become a major application attack surface, where most breaches exploit misconfigurations and implicit trust rather than software flaws. This session presents a practical Zero Trust approach to securing containerized applications against real world attack paths. It shows how attackers abuse weak RBAC, insecure service communication, and lack of workload isolation to move laterally and escalate privileges. Attendees will learn how to design granular access controls, enforce secure service to service communication, and implement segmentation to contain compromised workloads. The session also demonstrates how policy as code and admission controls can block risky deployments before they reach production. With real examples and measurable outcomes, this talk provides actionable techniques to reduce attack success and strengthen Kubernetes security.

\n\nSpeakerBio:  Janakiram Meka
\n

Janakiram Meka is a Cloud DevOps Architect with over 18 years of experience in building and securing large scale enterprise systems. His expertise spans cloud infrastructure, Kubernetes, DevSecOps, and Zero Trust security models. He has led cloud migration and automation initiatives across complex environments, focusing on improving security, scalability, and operational efficiency. Janakiram holds multiple industry certifications, including Kubernetes Administrator, Terraform Associate, Oracle Certified Professional, and AWS Solutions Architect. He is an active contributor to the technology community, writing technical articles on cloud and database systems, and is a Senior Member of IEEE. His work emphasizes practical, data driven approaches to securing modern application platforms.

\n\n\n\'',NULL,1294655),('3_Saturday','17','17:30','17:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'From Prompts to Production: Discovering Exposed PII & IDORs in AI-Generated Apps\'','\'Samantha Pearlstein\'','Creator Talks_1fe1318e151191d9657f71415f8f87a3','\'Title: From Prompts to Production: Discovering Exposed PII & IDORs in AI-Generated Apps
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Users building apps with vibe coding platforms like Lovable or Base44 often overlook critical security vulnerabilities. As these platforms gain rapid adoption, thousands of apps are being created without sufficient attention to security, leaving significant flaws in plain sight. Our research, conducted across thousands of apps, revealed widespread issues, including 175 instances of sensitive PII leakage (such as medical records and personal contact information), SSRF, 0-click account takeovers, and IDORs.

\n\n

In this talk, we’ll share our field experience in developing discovery and security testing techniques that uncover exploitable web app and API behaviors at scale. We’ll walk through concrete examples, showing how critical vulnerabilities hide in plain sight and how even minor misconfigurations can lead to catastrophic breaches. Attendees will learn to identify these security risks and secure their no-code apps, including best practices for handling sensitive data and securing APIs.

\n\nSpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape
\n

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.

\n\n\n\'',NULL,1294656),('2_Friday','12','12:45','13:45','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Drogonsec: SAST + SCA + Secrets + IaC in one open-source scanner\'','\'Filipi Pires\'','Creator Events_cd7f20bca2427e23a4cec221ce1adcc6','\'Title: Drogonsec: SAST + SCA + Secrets + IaC in one open-source scanner
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 12:45 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

Drogonsec is an open-source, high-performance security scanner built for developers and CI/CD pipelines. In a single run, it combines four analysis engines: SAST for 20+ languages, SCA for dependency CVEs, secret detection with 50+ patterns (AWS, GCP, GitHub, JWTs, SSH keys), and IaC misconfiguration analysis for Terraform and Kubernetes, all mapped to OWASP Top 10:2025 and CWE, with CVSS 3.1 scoring and SARIF output for GitHub and Azure DevOps integration.

\n\n

This Arsenal session will demo Drogonsec scanning real-world repositories live, showing findings across all four engines, explaining rule design decisions, and showcasing how teams can extend it with custom YAML rules. Attendees leave with a running tool they can drop into their pipelines the same day.

\n\nSpeakerBio:  Filipi Pires, Head of Technical Advocacy at SCYTHE
\n

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, Advisor & Investor at Sherlockeye, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I\'m Creator and Instructor of the Course - Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis - Fundamentals (HackerSec).

\n\n

Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329\nBlack Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329\nBlack Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0\nBlack Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires\nDEF CON 33 / 32 - https://sessionize.com/filipi-pires/\nDEF CON - Adversary Village - https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/

\n\n\n\'',NULL,1294657),('2_Friday','13','12:45','13:45','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Drogonsec: SAST + SCA + Secrets + IaC in one open-source scanner\'','\'Filipi Pires\'','Creator Events_cd7f20bca2427e23a4cec221ce1adcc6','\'\'',NULL,1294658),('4_Sunday','10','10:30','10:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'From commit to compromise: securing the full pipeline with AI-assisted remediation\'','\'Filipi Pires\'','Creator Talks_9a79b81f0479fd5bef21b16d0d5fa339','\'Title: From commit to compromise: securing the full pipeline with AI-assisted remediation
\nTags: AppSec Village | Creator Talk/Panel | All Audiences
\nWhen: Sunday, Aug 9, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Most vulnerabilities aren\'t found because teams lack tools they persist because the cost of fixing them is too high. A finding without a concrete, context-aware fix is just noise developers learn to ignore.\nThis talk walks through three real-world attack scenarios a secret leaked into git history, a compromised dependency in a supply chain attack, and an injection vulnerability introduced in a PR and shows how each is detected, mapped to OWASP Top 10:2025, and automatically remediated using AI running entirely on local infrastructure.\nNo source code leaves the machine. The AI receives the vulnerable code block, CWE identifier, CVSS score, and OWASP category and returns a fix that is specific, correct, and ready to apply. Attendees leave with a working open-source tool and a new mental model for what AppSec remediation can look like.

\n\nSpeakerBio:  Filipi Pires, Head of Technical Advocacy at SCYTHE
\n

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, Advisor & Investor at Sherlockeye, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I\'m Creator and Instructor of the Course - Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis - Fundamentals (HackerSec).

\n\n

Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329\nBlack Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329\nBlack Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0\nBlack Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires\nDEF CON 33 / 32 - https://sessionize.com/filipi-pires/\nDEF CON - Adversary Village - https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/

\n\n\n\'',NULL,1294659),('3_Saturday','10','10:15','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Prompt Injection: Attacking and Defending AI-Powered Applications\'','\'Mohammed Ilyas Ahmed\'','Creator Workshops_c8210004062bcded10b34d000d35bead','\'Title: Prompt Injection: Attacking and Defending AI-Powered Applications
\nTags: AppSec Village | Creator Workshop | All Audiences
\nWhen: Saturday, Aug 8, 10:15 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map
\n
\nDescription:
\n

Prompt injection has rapidly emerged as one of the most critical and least understood vulnerabilities in modern application security. As organizations race to integrate LLMs into customer-facing products, internal tools, and autonomous agents, attackers are already exploiting these systems in ways traditional security controls were never designed to catch.\nThis one-day, hands-on training gives attendees a thorough, practical understanding of prompt injection — from basic chatbot manipulation to sophisticated attacks against RAG pipelines and autonomous AI agents. Using a purpose-built lab environment, attendees will exploit real vulnerabilities in LLM-powered applications, understand exactly why they work, and then build effective defenses against them.\nThe course is structured as an attack-first, defend-second journey. By experiencing these vulnerabilities as an attacker, attendees leave with deep intuition about where AI systems.

\n\nSpeakerBio:  Mohammed Ilyas Ahmed
\n

I am a seasoned security and DevSecOps professional with deep expertise in helping organizations strengthen their security posture across modern, cloud-native environments.

\n\n

I am an active contributor to the global technology community and a frequent speaker at leading industry conferences and platforms, including DEF CON, Black Hat, KubeCon (Paris), ISACA, IANS, and Wallarm, among others. I am also regularly invited to serve as a technical session judge.

\n\n

publishing work that advances discussions around modern security practices, governance, and risk management. I am also a distinguished member of the Harvard Business Review Advisory Council.

\n\n

My work has a global reach through my role as a Member of the Global Advisory Board at VigiTrust Limited (Dublin, Ireland).

\n\n

I am the author of Cloud-Native DevOps, a practical guide to building scalable, reliable, and secure cloud-native applications.

\n\n\nLinks:
    Registration - https://www.zeffy.com/en-US/ticketing/prompt-injection-attacking-and-defending-ai-powered-applications
\n\'',NULL,1294660),('3_Saturday','11','10:15','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Prompt Injection: Attacking and Defending AI-Powered Applications\'','\'Mohammed Ilyas Ahmed\'','Creator Workshops_c8210004062bcded10b34d000d35bead','\'\'',NULL,1294661),('3_Saturday','12','10:15','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Prompt Injection: Attacking and Defending AI-Powered Applications\'','\'Mohammed Ilyas Ahmed\'','Creator Workshops_c8210004062bcded10b34d000d35bead','\'\'',NULL,1294662),('3_Saturday','14','14:10','14:40','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Every ride you take - Hacking a City’s Public Transportation\'','\'Ignacio Navarro\'','Creator Talks_3f47991c08f019e233839ad9f1353a60','\'Title: Every ride you take - Hacking a City’s Public Transportation
\nTags: AppSec Village | Creator Talk/Panel | All Audiences
\nWhen: Saturday, Aug 8, 14:10 - 14:40 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Let\'s talk about some critical infrastructure that millions of people use every day: Public transportation. \nIn this talk, I’ll present some findings that I discovered in the public transportation ecosystem of one of the largest cities in Argentina, impacting more than 1.5 million people daily. Reading code, chaining vulnerabilities, weak access controls, and flawed internal designs, I got full access to core mobility systems, from buses to taxis, including DVRs, transport cards, user data, real-time tracking and administrative panels. We’ll walk through the technical exploitation path, the real-world impact and the lessons learned.

\n\nSpeakerBio:  Ignacio Navarro
\n

Ignacio Navarro, an Ethical Hacker and Security Researcher from Cordoba, Argentina. With around 6 years in the cybersecurity game, he\'s currently working as an Application Security. Their interests include code analysis, web application security, and cloud security. \nSpeaker at DEFCON, H2HC, Troopers, LeHACK, NorthSec, TyphoonCon, Security Fest, 8.8, among others.\n@Ignavarro1

\n\n\n\'',NULL,1294663),('2_Friday','17','17:30','17:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Trust No History: Why Every \"Remembered\" Interaction is a Potential Backdoor\'','\'Barno Kaharova,Rico Komenda\'','Creator Talks_6c6c7af9a72a5985db2bb09e29d8927c','\'Title: Trust No History: Why Every \"Remembered\" Interaction is a Potential Backdoor
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

As AI transitions from stateless tools to autonomous agents, the context window has become the primary attack surface. By giving agents the ability to remember, summarize, and collaborate, we have created a machine that can be gaslit. This session moves beyond transient prompt injections into the realm of persistent memory corruption. We explore how an adversary can rewrite an agent’s history, bias its knowledge base, and plant sleeper instructions that trigger long after the initial interaction. We will dissect the systematic subversion of the agentic memory stack and demonstrate why developers must stop treating agent memory as a passive data store and start defending it as the engine of the agent’s survival

\n\nSpeakers:Barno Kaharova,Rico Komenda
\n
\nSpeakerBio:  Barno Kaharova
\n

Barno is a consultant and researcher specializing in AI security, data engineering, and ML security. She works at the intersection of offensive and defensive AI security, developing methodologies to protect AI systems from adversarial threats across the full stack from data pipelines and ML models to LLM-powered applications and autonomous agents.\nAs an AI security trainer, Barno designs and delivers hands-on programs covering AI red teaming, prompt injection, adversarial ML, RAG and vector database security, and the OWASP Top 10 for LLM and Agentic AI. Her approach is practitioner-first: participants attack and defend real-world AI systems, leaving with techniques they can apply immediately.\nShe is actively involved in AI governance and evaluation efforts at the national level and regularly contributes to the AI security community through speaking engagements, publications, and conference submissions, bridging rapid AI adoption with the need for robust, field-tested defenses.

\n\nSpeakerBio:  Rico Komenda
\n

Rico Komenda is a security engineer and researcher specializing in application security, cloud security, and AI security. He started as a software developer, moved into security engineering, and now focuses on the attack surface created by AI-integrated systems and secure agentic development.

\n\n

He is Co-Lead of the OWASP AI Security Verification Standard (AISVS) and a core contributor to multiple OWASP GenAI security projects. Rico has spoken at NDC Security, OWASP Global AppSec EU, OWASP LASCON, WeAreDevelopers World Congress, DefCamp, and others.

\n\n

He got into this field the way a lot of hackers do: writing scripts for video games as a teenager, getting curious about how systems break, and never stopping.

\n\n\n\'',NULL,1294664),('3_Saturday','14','14:50','15:20','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Pattern, Graph, Prompt: What Happens When You Layer Three Analysis Paradigms on the Same Codebase\'','\'Mudita Khurana\'','Creator Talks_5c9e60dff4f986fa1aac1528dac72c1a','\'Title: Pattern, Graph, Prompt: What Happens When You Layer Three Analysis Paradigms on the Same Codebase
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:50 - 15:20 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\nWe ran three fundamentally different security analysis approaches against the same production monorepo at a large tech company: a pattern-based static analysis tool, a code property graph analyzer, and LLM-powered code review. Together they surfaced over 100 confirmed vulnerabilities.
\nEach approach has real strengths and real limitations. Pattern-based static analysis is fast and deterministic but struggles with complex taint propagation and cannot reason about logic. Graph-based analysis can trace dataflow across the entire codebase but has no concept of developer intent. LLM-powered review can reason about whether a security mechanism actually does what it claims, but it is non-deterministic, expensive, and cannot guarantee exhaustive coverage the way a static tool can.
\nWe present a practical methodology for layering these approaches, share the detection overlap data from our analysis, and provide a framework for deciding which paradigm to apply where.
\n\n\n\nSpeakerBio:  Mudita Khurana
\n

Mudita Khurana is a Tech Lead at Airbnb, where she builds scalable security tooling and automation across the software development lifecycle. Previously at Meta, she drove key initiatives in product security, including bug bounty strategy, privacy-focused reviews, and automated vulnerability detection through static and hybrid analysis. Her work focuses on advancing security automation through robust workflows, agentic systems, and scalable system design. Mudita also serves on program committees for several top-tier security conferences and regularly contributes to the community through research, talks, and industry collaborations.

\n\n\n\'',NULL,1294665),('3_Saturday','15','14:50','15:20','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Pattern, Graph, Prompt: What Happens When You Layer Three Analysis Paradigms on the Same Codebase\'','\'Mudita Khurana\'','Creator Talks_5c9e60dff4f986fa1aac1528dac72c1a','\'\'',NULL,1294666),('2_Friday','16','16:30','17:30','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Rebuilding Code Security with Signal, Speed and AI\'','\'Derek C.,Shasheen Bandodkar\'','Creator Events_e7d8cb18805138aadb11b2ace025ef42','\'Title: Rebuilding Code Security with Signal, Speed and AI
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 16:30 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\nModern AppSec tooling is fragmented: one scanner for secrets, another for dependencies, another for SAST, another for containers, another for SBOMs, and then a separate workflow for triage. Broly is an open source Go scanner built to collapse that workflow into one fast App and finding model.
\n\n

This Arsenal session walks through Broly\'s current design: Titus-backed secrets scanning, osv-scalibr + OSV.dev dependency analysis, Together AI powered SAST, container image scanning, license policy checks, SBOM output with baselines, incremental scans, SARIF/JSON/table output, and built in AI triage with optionality. The demo will show Broly scanning a vulnerable repo, producing actionable findings, filtering noise and fitting into a PR workflow.

\n\n

The session is also a candid engineering case study on what broke, what was rebuilt, where & how AI helped, where deterministic engines still lead, and why security tools need to be attacked with the same rigor as the code they judge.

\n\nSpeakers:Derek C.,Shasheen Bandodkar
\n
\nSpeakerBio:  Derek C.
\n

Derek is the Head of Security at Together.ai and the former Head of Infrastructure Security at Cloudflare. He has over 20 years of experience in designing security frameworks at scale. His main focus is on research and development within the fields of encryption and infrastructure security.

\n\n

He earned a masters in cybersecurity from Purdue University and now owns more than 60 global patents related to cryptography, key management, and distributed ledger technology.

\n\nSpeakerBio:  Shasheen Bandodkar
\n

Shasheen Bandodkar is a security engineer passionate about safeguarding technology and innovation. With deep cybersecurity expertise, he frequently shares insights on his blog and is known for turning rants into revelations.

\n\n\n\'',NULL,1294667),('2_Friday','17','16:30','17:30','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Rebuilding Code Security with Signal, Speed and AI\'','\'Derek C.,Shasheen Bandodkar\'','Creator Events_e7d8cb18805138aadb11b2ace025ef42','\'\'',NULL,1294668),('3_Saturday','14','14:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'OWASP AIBOM Generator\'','\'Dmitry Raidman,Helen Oakley\'','Creator Events_2a68e0d403e50067763afe90ec36fe58','\'Title: OWASP AIBOM Generator
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

AI systems increasingly depend on opaque model, dataset, and tooling supply chains, but most teams still lack a practical way to capture what is inside them. This Arsenal session demonstrates the OWASP AIBOM Generator, an open-source tool from the OWASP GenAI Security Project that creates CycloneDX-based AI Bills of Materials (AIBOM) for AI/ML assets. Attendees will see how to generate AIBOMs that can support AI transparency, security review, governance, incident response, and software supply chain risk management without turning the process into a manual documentation review exercise.

\n\nSpeakers:Dmitry Raidman,Helen Oakley
\n
\nSpeakerBio:  Dmitry Raidman
\n

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

\n\n

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

\n\n

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.

\n\nSpeakerBio:  Helen Oakley
\n

Helen Oakley, CISSP, GPCS, GSTRT, works at the intersection of AI, cybersecurity, and software supply chains—where the rules are still being written. At SAP, she leads a global team of architects, security experts, and scientists, securing development and pipelines at scale. Helen is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more. Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models. Named one of the Top 20 Canadian Women in Cybersecurity, she co-founded LeadingCyberLadies.com to support the next wave of builders, breakers, and leaders.

\n\n\n\'',NULL,1294669),('3_Saturday','12','12:45','13:45','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'OWASP FinBot CTF: Hands-On Agentic AI Threats\'','\'Helen Oakley,saikishu\'','Creator Events_44b7d9875ba4e89162dcd6cb34237a05','\'Title: OWASP FinBot CTF: Hands-On Agentic AI Threats
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 12:45 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

OWASP FinBot is an intentionally vulnerable agentic AI application designed to teach real-world security risks in AI agents beyond prompt injection alone. This Arsenal session demonstrates how an AI assistant connected to business tools can be manipulated through indirect prompts, unsafe tool use, broken authorization, and weak runtime controls. Attendees will see and experience first-hand how attacker-controlled inputs can influence agent behavior, trigger unsafe actions, and expose sensitive data.

\n\nSpeakers:Helen Oakley,saikishu
\n
\nSpeakerBio:  Helen Oakley
\n

Helen Oakley, CISSP, GPCS, GSTRT, works at the intersection of AI, cybersecurity, and software supply chains—where the rules are still being written. At SAP, she leads a global team of architects, security experts, and scientists, securing development and pipelines at scale. Helen is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more. Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models. Named one of the Top 20 Canadian Women in Cybersecurity, she co-founded LeadingCyberLadies.com to support the next wave of builders, breakers, and leaders.

\n\nSpeakerBio:  saikishu
\n

Venkata Sai Kishore Modalavalasa is Chief Architect & Engineering Leader at Straiker, building AI security products for AI-native apps at scale. With 15+ years in cybersecurity and distributed systems, he scaled Cyberfend to acquisition by Akamai, where he led bot detection and web security engineering. He’s an OWASP author contributing to AI Exchange, AIBOM, Top 10 for Agentic Applications, OWASP GenAI Security Project, creator and co-lead of OWASP FinBot CTF, and holds multiple security patents.

\n\n\n\'',NULL,1294670),('3_Saturday','13','12:45','13:45','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'OWASP FinBot CTF: Hands-On Agentic AI Threats\'','\'Helen Oakley,saikishu\'','Creator Events_44b7d9875ba4e89162dcd6cb34237a05','\'\'',NULL,1294671),('3_Saturday','10','10:30','10:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Building Hackbots\'','\'Jason \"jhaddix\" Haddix\'','Creator Talks_139a002140e4ac3c2066b98c2e5350de','\'Title: Building Hackbots
\nTags: AppSec Village | Creator Talk/Panel | All Audiences
\nWhen: Saturday, Aug 8, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Building AI-Powered Penetration Testing Bots

\n\nSpeakerBio:  Jason \"jhaddix\" Haddix, CEO and \"Hacker in Charge\" at Arcanum Information Security
\n

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

\n\n

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

\n\n\n\'',NULL,1294672),('3_Saturday','16','16:30','17:30','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence\'','\'Jordan Bonagura\'','Creator Events_c15c944439ff5678f84fcf6280bb68cf','\'Title: Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 16:30 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

Modern enterprise environments have shifted beyond traditional network perimeters, with SaaS applications and identity providers becoming the primary attack surface. However, a significant portion of this still remains unmanaged or invisible commonly referred as Shadow SaaS.

\n\n

This session explores Shadow SaaS from an attacker’s perspective, demonstrating how adversaries can identify, evaluate, and abuse unmanaged SaaS applications to gain initial access and maintain persistence within target environments.

\n\n

Rather than focusing on inventory or governance, this talk reframes Shadow SaaS as an offensive opportunity. It highlights how implicit trust relationships, and third-party SaaS connections expand the attack surface beyond traditional security visibility.

\n\n

Using the Shadow SaaS Surface Scanner, we demonstrate how attackers can uncover hidden SaaS exposure and leverage it as a foothold into enterprise environments.

\n\nSpeakerBio:  Jordan Bonagura
\n

Senior Security Consultant at Secure Ideas\nResearcher in Information Security\nStay Safe Podcast Founder\nComputer Scientist\nPost Graduated in Business Strategic Management, Innovation and Teaching\nFounder - Vale Security Conference - Brazilian Conference\nConsultant Member - Brazilian Comission of High Tech Crime (OAB / SP) \nCoordinator and Teacher in IT area\nSJC Hacker Space President\nSpeaker (DefCon, Hack Space Con, Hack Red Con, Hack Miami, Triangle InfoSec, AppSec California, GrrCon, BalCCon2k14, BSides Augusta, H2HC, Angeles Y Demonios, Silver Bullet, Seginfo, ITA, INPE, etc)

\n\n\n\'',NULL,1294673),('3_Saturday','17','16:30','17:30','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence\'','\'Jordan Bonagura\'','Creator Events_c15c944439ff5678f84fcf6280bb68cf','\'\'',NULL,1294674),('2_Friday','14','14:30','16:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Container Escapes 101\'','\'some-natalie\'','Creator Workshops_d6b78866d1b5e49a86d31f14e27f126f','\'Title: Container Escapes 101
\nTags: Intermediate | AppSec Village | Creator Workshop
\nWhen: Friday, Aug 7, 14:30 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map
\n
\nDescription:
\n

Containers aren’t tiny fortresses. They’re leaky rowboats unless you know what you’re doing. This hands-on workshop demystifies container security layer by layer, showing how real-world missteps in runtime, image, and host configurations open doors to escapes, persistence, and lateral movement. We’ll dissect how containers actually work, walk through common isolation failures, and demonstrate how attackers exploit weak assumptions. Whether you’re building, securing, or regulating containerized apps, you’ll leave with a threat model, practical tools, and maybe a new trick or two for literally popping out of the box.

\n\nSpeakerBio:  some-natalie
\n

Natalie is a principal solutions engineer at XBOW serving the public sector market. She spent years designing, building, and leading complex systems in regulated environments at a major systems integrator, but has also taken her career in many other directions - including detours into project management, systems engineering, and teaching.

\n\n

She’s passionate about diversity in technology and empowering engineers to build better.

\n\n\nLinks:
    Registration - https://www.zeffy.com/en-US/ticketing/container-escapes-101annual-gala
\n\'',NULL,1294675),('2_Friday','15','14:30','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Container Escapes 101\'','\'some-natalie\'','Creator Workshops_d6b78866d1b5e49a86d31f14e27f126f','\'\'',NULL,1294676),('2_Friday','16','14:30','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Container Escapes 101\'','\'some-natalie\'','Creator Workshops_d6b78866d1b5e49a86d31f14e27f126f','\'\'',NULL,1294677),('2_Friday','15','15:15','16:15','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'IDEViewer - Securing Developer Workstations from IDE Supply Chain Threats\'','\'securient\'','Creator Events_caec9e1f3e550725c1c49a3941ea1879','\'Title: IDEViewer - Securing Developer Workstations from IDE Supply Chain Threats
\nTags: Intermediate | AppSec Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 15:15 - 16:15 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

IDEViewer is an open-source, cross-platform security tool that continuously monitors developer workstations for supply chain threats originating from IDE extensions, software dependencies, plaintext secrets, and AI development tools.

\n\n

Developer IDEs have become a high-value attack surface. Malicious or over-permissioned VS Code extensions can execute arbitrary code, exfiltrate secrets, and establish persistence. npm lifecycle hooks in dependencies run silently during install. AI coding assistants like Claude Code, Cursor, and MCP servers introduce new data exfiltration vectors through unchecked permissions and network access. IDEViewer addresses this blind spot by scanning extensions across 7+ IDEs, analyzing their permissions against a risk model, detecting plaintext secrets, inventorying all installed packages (including those bundled inside extensions), monitoring for git hook bypasses, and detecting AI tool configurations with their associated permissions.

\n\nSpeakerBio:  securient
\n

Vinod is a Staff Security Engineer at PIP Labs and IEEE Senior Member with over a decade of cybersecurity experience spanning financial services, government, and tech. His career across Amazon, Zapier, and HackerOne has built deep expertise in penetration testing, cloud security architecture, and application security across AWS, GCP, and Azure — now applied at the intersection of traditional enterprise security and Web3/blockchain infrastructure. He is an author and reviewer for the HTTP Archive\'s Web Almanac, organizer of the Blockchain Security Village at Seasides, and creator of the open-source API Doc Converter Burp Extension. He actively contributes to the security community through writing on Medium, bug bounty programs, and mentoring aspiring security professionals.

\n\n\n\'',NULL,1294678),('2_Friday','16','15:15','16:15','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'IDEViewer - Securing Developer Workstations from IDE Supply Chain Threats\'','\'securient\'','Creator Events_caec9e1f3e550725c1c49a3941ea1879','\'\'',NULL,1294679),('2_Friday','10','10:30','10:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'The Dots Do Matter: Gmail\'s Invisible Blindspot\'','\'Keren Elazari\'','Creator Talks_9412f8bac4207d8973dd91f113cabfe3','\'Title: The Dots Do Matter: Gmail\'s Invisible Blindspot
\nTags: AppSec Village | Creator Talk/Panel | All Audiences
\nWhen: Friday, Aug 7, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

In 2004, I registered kerene@gmail.com during Gmail\'s invite-only launch. I\'ve been receiving strangers\' private data ever since, without clicking a single link or running a single exploit. Gmail treats dots as invisible, meaning all 32 dot-variants of my address deliver straight to me. Alas, Third-party platforms never got the memo. Banks, airlines, social networks, and government portals mostly treat dot-variants as unique identities, creating an invisible identity collision with real consequences for account security, fraud, and forensic investigation, impacting millions of users worldwide. Almost 90 Snapchat log in emails, 168 TikTok password resets, and one Google Takeout link later, I\'m here to show you what 22 years of someone else\'s data looks like, and the one normalization fix that would have prevented all of it.

\n\nSpeakerBio:  Keren Elazari
\n

Keren Elazari is an internationally recognized security analyst, researcher, author and speaker, working with leading security firms, government organizations and Fortune 500 companies. As an independent voice on cyber security, Keren Elazari is the first Israeli woman to give a TED talk at the official TED Conference. Keren’s TED talk about hackers has been viewed by millions, translated to 30 languages and is one of the most watched talks on TED.com on the topic of cyber security.\nKeren is the founder of BSidesTLV, Israel\'s largest security community event, and the founder of the Leading Cyber Ladies network for Women in Cyber Security. Keren is currently a senior researcher at the Interdisciplinary Cyber Research Center at Tel Aviv University.

\n\n\n\'',NULL,1294680),('3_Saturday','16','16:50','17:20','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'No Jailbreak Required: Pwning AI Agents Through the Tools They Trust\'','\'Helen Oakley,saikishu\'','Creator Talks_73339602875340dddc0dcdf07980866e','\'Title: No Jailbreak Required: Pwning AI Agents Through the Tools They Trust
\nTags: AppSec Village | Creator Talk/Panel | All Audiences
\nWhen: Saturday, Aug 8, 16:50 - 17:20 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Your AI agent approved the vendor, sent the status email, processed the payment, and BCC\'d customer PII to an attacker\'s dead drop. One turn, no jailbreak, no prompt injection of the user. The MCP tool metadata the agent trusted had been quietly rewritten upstream, and from the model\'s view it was just doing its job.

\n\n

A live attack-to-defense demo on OWASP FinBot CTF, a deliberately vulnerable multi-agent platform (Juice Shop for agentic AI) with real MCP agents running onboarding, compliance, and payments.

\n\n

Act I, Kill Chain: a poisoned tool description with security-framed exfil logic no model refuses. One admin request triggers vendor lookup, PII harvest, BCC exfil, and payment. Output stays clean.

\n\n

Act II, Guardrail: poison stays. We deploy a ~40-line before_tool webhook that inspects invocations live. Benign calls pass, exfil dies on the wire.

\n\n

Tool metadata sits inside the agent\'s trust boundary, and few pin or diff-review it. Clone the CTF and keep pwning.

\n\nSpeakers:Helen Oakley,saikishu
\n
\nSpeakerBio:  Helen Oakley
\n

Helen Oakley, CISSP, GPCS, GSTRT, works at the intersection of AI, cybersecurity, and software supply chains—where the rules are still being written. At SAP, she leads a global team of architects, security experts, and scientists, securing development and pipelines at scale. Helen is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more. Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models. Named one of the Top 20 Canadian Women in Cybersecurity, she co-founded LeadingCyberLadies.com to support the next wave of builders, breakers, and leaders.

\n\nSpeakerBio:  saikishu
\n

Venkata Sai Kishore Modalavalasa is Chief Architect & Engineering Leader at Straiker, building AI security products for AI-native apps at scale. With 15+ years in cybersecurity and distributed systems, he scaled Cyberfend to acquisition by Akamai, where he led bot detection and web security engineering. He’s an OWASP author contributing to AI Exchange, AIBOM, Top 10 for Agentic Applications, OWASP GenAI Security Project, creator and co-lead of OWASP FinBot CTF, and holds multiple security patents.

\n\n\n\'',NULL,1294681),('3_Saturday','17','16:50','17:20','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'No Jailbreak Required: Pwning AI Agents Through the Tools They Trust\'','\'Helen Oakley,saikishu\'','Creator Talks_73339602875340dddc0dcdf07980866e','\'\'',NULL,1294682),('2_Friday','14','14:50','15:20','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'GeoHacking: from memory corruption RCE to cross tenant access\'','\'Michal Kamensky\'','Creator Talks_24847fd57bba61f3a3a9b946639a24fa','\'Title: GeoHacking: from memory corruption RCE to cross tenant access
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:50 - 15:20 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

The tale of CVE-2026-40412, hacking Microsoft Planetary Computer Pro service. This talk will walk you through the journey of discovering a chain of vulnerabilities in the service itself and in its open source dependencies. All those findings combined resulted in cross tenant access. From a file read, to exploiting a buffer overflow (bypassing ASLR) to finding and exploiting a devastating design flaw.\nThis talk will address the unique challenges of exploiting memory corruption bugs in cloud services, the pitfalls of cloud services’ architecture and how we helped the engineering team fix the issues we found at the design level.

\n\nSpeakerBio:  Michal Kamensky
\n

Michal is a security researcher on the Microsoft STORM team, where she focuses on vulnerability research across the hybrid cloud domain. Previously she has worked as a security researcher at Bounce Security, and for the last few years volunteers as a Defcon goon. She enjoys diving into large code bases, understanding complex architectures, and eliminating vulnerabilities at scale.

\n\n\n\'',NULL,1294683),('2_Friday','15','14:50','15:20','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'GeoHacking: from memory corruption RCE to cross tenant access\'','\'Michal Kamensky\'','Creator Talks_24847fd57bba61f3a3a9b946639a24fa','\'\'',NULL,1294684),('3_Saturday','11','11:10','11:40','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'What Your Coding Agent Did Last Night: Runtime Security for AI Coding Agents\'','\'Inga Cherny\'','Creator Talks_c616bd66488d5fd725367788bb8f98a7','\'Title: What Your Coding Agent Did Last Night: Runtime Security for AI Coding Agents
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:10 - 11:40 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Your coding agent ran 200 tool calls last night. File reads, shell commands, network requests, all with your permissions, mostly invisible. Today\'s defenses miss the attacks landing now: MCP tool poisoning, prompt injection via repo content, and credential-exfiltration chains where only the sequence is malicious.

\n\n

I’ll present AgentsLeak, an open-source runtime monitor that hooks Claude Code and Cursor at the tool-call boundary and blocks before execution. Live demo: session telemetry showing the calls the agent made versus the calls it disclosed, and behavioral chain detection catching multi-step exfiltration.

\n\nSpeakerBio:  Inga Cherny
\n

Inga Cherny is an ML Researcher at CrowdStrike specializing in AI security, LLM vulnerabilities, adversarial ML, and prompt injection defenses.

\n\n

Previously, she was a security researcher at Cato Networks and a member of Cato CTRL, focusing on emerging threats, offensive and defensive security research.

\n\n

With a decade of experience spanning security and applied machine learning, Inga focuses on uncovering new attack vectors and building more resilient AI and security systems.

\n\n\n\'',NULL,1294685),('2_Friday','11','11:10','11:40','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Pickled and Exposed: RCE in AI Serving Frameworks\'','\'Iggy\'','Creator Talks_c379bb5e23125a1d40986508f2775817','\'Title: Pickled and Exposed: RCE in AI Serving Frameworks
\nTags: Intro/Beginner | AppSec Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:10 - 11:40 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Your LLM serving stack is probably listening to the entire internet right now, and it will run whatever code that internet sends it. It will not ask who you are.\nEveryone is busy chasing prompt injection and jailbreaks. Meanwhile, the boring bugs are wide open. SGLang serves large language models for thousands of deployments, with 25k+ GitHub stars. I read the source and found two unauthenticated RCEs. There was nothing clever about it: a network-exposed broker hands attacker data straight to pickle.loads(). Send a payload, get a shell.\nI will walk the vulnerable code and pop a shell live on stage. You will leave knowing exactly what to grep for in your own AI stack, before someone else greps it for you. \nTwo CVEs. One grep. Zero sophistication required.

\n\nSpeakerBio:  Iggy
\n

Igor Stepansky is a Security Researcher at OX Security, where he works on agentic AI for offensive security and automated penetration testing. Previously, he was part of Orca Security\'s Research Pod. His research spans unauthenticated remote code execution in AI/LLM serving frameworks, a use-after-free race condition in the Linux kernel\'s ksmbd SMB3 serve, and supply chain and CI/CD security across modern developer ecosystems. His work focuses on finding and exploiting high-impact vulnerabilities in widely deployed infrastructure, and he is a regular contributor of CVEs in open-source software.

\n\n\n\'',NULL,1294686),('2_Friday','13','13:30','13:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Agentic Chaos - What 86K+ Agent Codebases Reveal About 700K+ Exposed AI Systems\'','\'Bar Kaduri,Lidan\'','Creator Talks_f1d04a340b883013898c7ef54a609f1d','\'Title: Agentic Chaos - What 86K+ Agent Codebases Reveal About 700K+ Exposed AI Systems
\nTags: AppSec Village | Creator Talk/Panel | All Audiences
\nWhen: Friday, Aug 7, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

AI agents have quickly become a core part of production infrastructure. Autonomous systems that invoke tools, execute code, orchestrate workflows, and interact with external services are now deployed across developer tooling, automation platforms, data pipelines, and enterprise environments at scale.

\n\n

Yet despite the speed of adoption, almost nothing is known about how these systems are actually built or secured in the wild.

\n\n

To answer that question, we analyzed more than 86K public repos implementing agent logic across LangChain, LangGraph, CrewAI, AutoGen, and MCP, examining prompt construction, tool implementations, authentication models, and permission boundaries. We paired this with internet-wide infra measurement using Shodan, Censys & ShadowServer, surfacing more than 700K exposed agent-related systems, including Ollama inference servers, Ray clusters, n8n platforms & MCP tool servers, many with little or no authentication and numerous known high-impact CVEs.

\n\nSpeakers:Bar Kaduri,Lidan
\n
\nSpeakerBio:  Bar Kaduri
\n

Bar Kaduri is a cybersecurity researcher, leader, and international speaker with over 14 years of experience in cloud security, software supply-chain risk, and emerging AI threats. With hands-on expertise in evaluating and stress-testing AI systems, Bar focuses on building practical, resilient defenses that anticipate risks before they are widely recognized. Bar regularly speaks at industry conferences, delivering clear, research-driven insights that bridge deep technical expertise with strategic security leadership in an AI-driven world

\n\nSpeakerBio:  Lidan
\n

Lidan has been programming since childhood, driven by a deep passion for data and AI. He previously served as VP of R&D at SecuredTouch, where he helped pioneer behavioral biometrics. Following the company’s acquisition by Ping Identity, the technology he led became a core component of Ping’s SaaS offering. He later joined Transmit Security, where he built their Identity Threat Detection and Response platform from the ground up, targeting large-tier financial organizations. He scaled the team to more than 30 engineers and data scientists, drove ARR from $0 to $20M, and delivered multiple presentations at leading cybersecurity conferences. In 2025, he co-founded Capsule Security, where he serves as CTO. Capsule addresses one of the most critical challenges in modern cybersecurity: securing AI agents. The company provides end-to-end visibility, risk analysis, threat detection, and runtime protection with advanced detection and response.

\n\n\n\'',NULL,1294687),('2_Friday','14','14:10','14:40','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'from_pretrained() to from_pwned(): Breaking HuggingFace\'s Trust\'','\'Yotam Perkal\'','Creator Talks_da63b7b44241f13fbd82565967120dd5','\'Title: from_pretrained() to from_pwned(): Breaking HuggingFace\'s Trust
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:10 - 14:40 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

uggingFace has become the GitHub of machine learning. Two million models, 15 million daily downloads. We discovered a critical RCE (CVE-2026-4372) that compromises any machine loading a malicious model. Add one field to a model\'s config.json, publish it on the Hub, and any standard from_pretrained() call is silently compromised. No trust_remote_code=True. No warnings. The one security boundary the entire ML ecosystem relies on, bypassed completely.

\n\n

The chain is three flaws: a generic setattr loop stamping every JSON field onto the config object including private attributes; a sanitization gap protecting the public interface but not the underscore-prefixed internal equivalent; and an unsandboxed kernel loader executing arbitrary Python from any Hub repo. One field weaponizes all three.

\n\n

We walk through the full attack chain live. Model registries are the new package registries, facing the same supply-chain threats that broke the software world - with far less mature defenses.

\n\nSpeakerBio:  Yotam Perkal
\n

Yotam Perkal leads security research at Pluto Security, a next-generation AI security and governance platform designed to protect the rapidly emerging ecosystem of AI builders, low-code/no-code tools, and agentic applications. His work focuses on securing AI-native development environments and building scalable methods for detecting, validating, and mitigating risks in AI-driven software workflows.

\n\n

Previously, Yotam led the Threat Research team at Zscaler, headed the Vulnerability Research team at Rezilion, and held multiple roles within PayPal’s security organization across vulnerability management, threat intelligence, and insider threat.

\n\n

Yotam is an active participant in several cross-industry working groups dealing with AI security, vulnerability management, and supply chain security.

\n\n\n\'',NULL,1294688),('3_Saturday','15','15:30','15:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'How Malicious AI Skills Hijack Your Agents\'','\'Jenn Gile\'','Creator Talks_9739d9c96d3b2d47438cf70e18c6f04f','\'Title: How Malicious AI Skills Hijack Your Agents
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

When OpenClaw went viral in January 2026, threat actors were in ClawHub within hours. They didn\'t need to exploit a vulnerability - they just opened a GitHub account and uploaded malicious AI skills. Within weeks, over 700 malicious skills had shipped, all designed to steal crypto and credentials from unsuspecting users. When maintainers added scanning, attackers moved their payloads off the platform entirely. The green badge stayed green. The malware kept spreading.

\n\n

This talk uses that campaign as a case study to examine how AI skills get weaponized, why the security signals on skill registries create a false sense of safety, and what practitioners and security leaders can do to evaluate skills safely before installing them.

\n\nSpeakerBio:  Jenn Gile
\n

Jenn Gile is a community builder and tech educator in the Security and DevOps fields. She\'s Co-Founder of OpenSourceMalware.com and runs the community program for BSides Seattle. Jenn previously worked at NGINX, F5, Endor Labs, and the U.S. Department of State. Outside of work, she\'s deeply involved in the cycling community as a board member for 2nd Cycle.

\n\n\n\'',NULL,1294689),('3_Saturday','11','11:30','12:30','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Precogly: Open-Source Threat Modeling for the AI-Coding Era\'','\'Vikramaditya Narayan\'','Creator Events_be62c6a85a180591fea6b6008df9d6ca','\'Title: Precogly: Open-Source Threat Modeling for the AI-Coding Era
\nTags: Intermediate | AppSec Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

AI agents are beginning to write larger parts of applications, from individual features to complete services. But if agents can build software, they also need a reliable way to threat model what they build.

\n\n

Precogly is an open-source (Apache 2.0) OWASP project for repeatable, human-reviewable threat modeling in the AI-coding era. It uses structured, community-curated library packs that connect components, threats, and countermeasures to sources such as CWE, CAPEC, and compliance frameworks.

\n\n

This gives AI agents guardrails. Instead of inventing threat models freely, they work off installed libraries, producing outputs that are easier to review, reproduce, and audit.

\n\n

In this demo, attendees will see Precogly’s DFD editor, library pack ecosystem, threat generation workflow, completion status dashboard, pack cross-checks for detecting untraced AI-generated items, and the OpenAPI REST API that agents can build on top of.

\n\nSpeakerBio:  Vikramaditya Narayan
\n

Vikramaditya Narayan is the creator of OWASP Precogly, an open-source, enterprise-grade threat modeling platform designed for repeatable, AI-agent-ready threat modeling. Previously, he designed the prototype for a YC-funded AI governance platform. Vikramaditya leads the Bangalore chapter of Threat Modeling Connect and has spoken at ThreatModCon DC on emergent risks in multi-agentic systems and at OWASP on using AI in threat modeling. He holds an MS from Carnegie Mellon and is a Certified Threat Modeling Professional.

\n\n\n\'',NULL,1294690),('3_Saturday','12','11:30','12:30','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Precogly: Open-Source Threat Modeling for the AI-Coding Era\'','\'Vikramaditya Narayan\'','Creator Events_be62c6a85a180591fea6b6008df9d6ca','\'\'',NULL,1294691),('2_Friday','10','10:30','12:30','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Burp, But Yours: Hands-On Extension and Bambda Development\'','\'Hannah L\'','Creator Workshops_e7148fdb0cef8f247742f03063c7bb64','\'Title: Burp, But Yours: Hands-On Extension and Bambda Development
\nTags: Intermediate | AppSec Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map
\n
\nDescription:
\n

Burp Suite already solves most daily testing problems, but the security landscape constantly evolves. New vulnerabilities, CVEs, and techniques emerge every day, and sometimes the capability you need simply does not exist yet.

\n\n

In this hands-on workshop, you’ll learn how to adapt Burp Suite to your workflow using custom scan checks, Bambdas, extensions, and the BApp Store. You’ll create your own Bambdas, test them against Web Security Academy labs, modify a free template extension, and start a project you can continue after the session.

\n\n

You’ll leave with practical tools, a repeatable development approach, and guidance on sharing your work with teammates or the wider community.

\n\nSpeakerBio:  Hannah L, Burp Suite Extensibility Specialist at PortSwigger
\n

Hannah is an Extensibility Specialist at PortSwigger, where she helps shape how Burp Suite can be adapted to real-world testing workflows. She works hands-on with submissions to the BApp Store, as well as the Bambdas and BChecks community repositories, helping refine extensions and community contributions before they’re shared more widely.

\n\n

She especially enjoys making extensions better and finding creative workarounds to awkward testing problems. She has also written extensions for customers, internal teams, and her own projects, including the original WebSocket Turbo Intruder extension.

\n\n\nLinks:
    Registration - https://www.zeffy.com/en-US/ticketing/burp-but-yours-hands-on-extension-and-bambda-development
\n\'',NULL,1294692),('2_Friday','11','10:30','12:30','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Burp, But Yours: Hands-On Extension and Bambda Development\'','\'Hannah L\'','Creator Workshops_e7148fdb0cef8f247742f03063c7bb64','\'\'',NULL,1294693),('2_Friday','12','10:30','12:30','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Burp, But Yours: Hands-On Extension and Bambda Development\'','\'Hannah L\'','Creator Workshops_e7148fdb0cef8f247742f03063c7bb64','\'\'',NULL,1294694),('3_Saturday','12','12:30','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Threat Modeling LLMs with PHANTOM-B\'','\'Adam Shostack\'','Creator Talks_827f2f125b25986b5804e8f2d120bf0b','\'Title: Threat Modeling LLMs with PHANTOM-B
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Threat modeling systems that call LLMs requires specialized approaches. Existing frameworks are heavyweight (wordy, jargon-laden) and often focus on threats that can only be addressed by those who train the models, offering little help to security practitioners tasked with threat modeling their company’s latest AI feature or product. This talk will introduce PHANTOM-B a new, STRIDE-like mnemonic for threat modeling LLMs. PHANTOM-B is focused on the common case of “an LLM trained by others,” rather than those training the LLM themselves.

\n\nSpeakerBio:  Adam Shostack
\n

Adam is leading expert on threat modeling and secure by design. He currently helps many organizations improve their security by with training and coaching at Shostack + Associates. He\'s the author of Threats: What Every Engineer Should Learn from Star Wars, Threat Modeling: Designing for Security and The New School of Information Security (with Andrew Stewart). He\'s a member of the BlackHat Review Board, and helped create the CVE and many other things, and is an Affiliate Professor at the University of Washington.

\n\n\n\'',NULL,1294695),('2_Friday','10','10:15','11:15','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Pentesting made easy - Keeping sessions alive with session chains\'','\'Kai Glauber,Matthias Göhring\'','Creator Events_4dabc0dc527f4b9e1fa03eaad3cec988','\'Title: Pentesting made easy - Keeping sessions alive with session chains
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 10:15 - 11:15 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

Modern web applications require pentesters to manage multiple accounts, roles, and tenants while dealing with short-lived sessions, multi-step logins, and MFA. This complexity regularly breaks authenticated tooling and slows down assessments, forcing testers into repetitive manual re-authentication.

\n\n

Our open-source tool, session-chains, addresses this challenge by automatically creating and maintaining authenticated sessions for any number of users. Testers define reusable authentication flows, while the tool keeps sessions valid in the background and exposes them to other tools.

\n\n

It integrates with Burp Suite and CLI tools like sqlmap, enabling consistent authenticated testing even in complex environments. This allows security professionals to spend less time on authentication hurdles and more time identifying impactful vulnerabilities.

\n\nSpeakers:Kai Glauber,Matthias Göhring
\n
\nSpeakerBio:  Kai Glauber
\n

Kai Glauber is a senior security consultant and penetration tester at usd AG with experience in web application pentests, SSO assessments and Kubernetes security. With a background in software development, his early work in software testing led him to specialize in the security domain. He\'s passionate about workflow automation and making pentesting more efficient.

\n\nSpeakerBio:  Matthias Göhring
\n

Matthias Göhring is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. He is Head of usd HeroLab, the division of usd specialized in technical security assessments. In addition, he holds lectures at Technical University Darmstadt and University of Applied Sciences Darmstadt on ethical hacking and penetration testing. In previous scientific work, he focused on network and communication security as well as software security.

\n\n

Previous publications:\n- Catching the Clones – Insights in Website Cloning Attacks, Risk Connect Conference, 2021\n- Path MTU Discovery Considered Harmful, IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018\n- Tor Experimentation Tools, IEEE Security and Privacy Workshops, 2015\n- On randomness testing in physical layer key agreement, IEEE 2nd World Forum on Internet of Things (WF-IoT), 2015

\n\n\n\'',NULL,1294696),('2_Friday','11','10:15','11:15','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Pentesting made easy - Keeping sessions alive with session chains\'','\'Kai Glauber,Matthias Göhring\'','Creator Events_4dabc0dc527f4b9e1fa03eaad3cec988','\'\'',NULL,1294697),('4_Sunday','11','11:30','12:30','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'search_vulns: Navigating the Fragmented Landscape of Vulnerability Data\'','\'Dustin Born,Matthias Göhring\'','Creator Events_65e8890c0bf8efe2c407329157189023','\'Title: search_vulns: Navigating the Fragmented Landscape of Vulnerability Data
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Sunday, Aug 9, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

Due to advances in AI‑assisted vulnerability discovery, more vulnerabilities are published than ever before, while traditional aggregators like the NVD have long reached their limits. This makes it increasingly difficult to obtain reliable information for prioritization in the fragmented landscape of known vulnerability data. Our open-source tool, search_vulns, addresses this by consolidating various sources through a modular architecture that works with product identifiers, like CPEs or PURLs, and regular product banners. It maintains accuracy when incorporating data without CPEs or PURLs, derives valid CPEs when upstream data is incomplete and reconciles duplicate product identities. Ultimately, it delivers a unified and precise view of known vulnerabilities, exploits, KEV, software recency and backpatch information, which we believe outperforms similar solutions.

\n\nSpeakers:Dustin Born,Matthias Göhring
\n
\nSpeakerBio:  Dustin Born
\n

Dustin Born is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. Within pentesting, he focuses on web applications, cloud environments and mobile applications. Apart from this, Dustin supports the development of several internal tools that focus on automated reconnaissance and vulnerability assessment. This aligns with his interests in developing tools related to IT security and his previous scientific work. Specifically, he has built a framework for a general purpose vulnerability scanner as well as one for the dynamic analysis of iOS apps.

\n\nSpeakerBio:  Matthias Göhring
\n

Matthias Göhring is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. He is Head of usd HeroLab, the division of usd specialized in technical security assessments. In addition, he holds lectures at Technical University Darmstadt and University of Applied Sciences Darmstadt on ethical hacking and penetration testing. In previous scientific work, he focused on network and communication security as well as software security.

\n\n

Previous publications:\n- Catching the Clones – Insights in Website Cloning Attacks, Risk Connect Conference, 2021\n- Path MTU Discovery Considered Harmful, IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018\n- Tor Experimentation Tools, IEEE Security and Privacy Workshops, 2015\n- On randomness testing in physical layer key agreement, IEEE 2nd World Forum on Internet of Things (WF-IoT), 2015

\n\n\n\'',NULL,1294698),('4_Sunday','12','11:30','12:30','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'search_vulns: Navigating the Fragmented Landscape of Vulnerability Data\'','\'Dustin Born,Matthias Göhring\'','Creator Events_65e8890c0bf8efe2c407329157189023','\'\'',NULL,1294699),('2_Friday','11','11:50','12:20','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'A Billion-User Blast Radius: Owning ChatGPT\'s Secure Sandbox\'','\'Simcha Kosman\'','Creator Talks_63e4c6f8c9ec5778d82186dfd44b7b0c','\'Title: A Billion-User Blast Radius: Owning ChatGPT\'s Secure Sandbox
\nTags: Advanced | AppSec Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:50 - 12:20 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

OpenAI designed ChatGPT\'s sandbox as a secure runtime with network isolation, strict timeouts, and an AI supervisor filtering commands. Extracting data seemed impossible.

\n\n

​In this talk, we demonstrate an attack chain shattering this sandbox. Abusing spreadsheet parsing bypasses the supervisor for persistent root execution. We then live-patch the internal Jupyter kernel, hijacking the hidden reasoning channel to execute a Reasoning Injection Attack and extract sensitive data. To exfiltrate it, we bypass isolation by weaponizing the Task Scheduler to launder URLs past web guardrails.

\n\n

​The attack culminates by exploiting a shared JFrog package manager. We engineered a protocol weaponizing global authentication rate limits, translating lockout timers into a half-duplex covert channel. This provides reliable exfiltration and C&C. Our chain combines file parsing abuse, Chain of Thought hijacking, privilege confusion, and rate limit DoS to orchestrate a C2 network inside ChatGPT.

\n\nSpeakerBio:  Simcha Kosman
\n

Simcha Kosman is a Senior Security Researcher at Palo Alto Networks with over seven years of experience in vulnerability research. He discovered his first vulnerability at age 15, earning his first bug bounty, and has since uncovered security flaws in processors, embedded systems, and large-scale open-source projects. His current work focuses on AI security, exploring the intersection of LLM and software exploitation. Simcha has presented his research in the past at BSides, Nullcon, and Black Hat.

\n\n\n\'',NULL,1294700),('2_Friday','12','11:50','12:20','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'A Billion-User Blast Radius: Owning ChatGPT\'s Secure Sandbox\'','\'Simcha Kosman\'','Creator Talks_63e4c6f8c9ec5778d82186dfd44b7b0c','\'\'',NULL,1294701),('3_Saturday','16','16:10','16:40','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'The API Made Me Do It - Do Bad APIs Lead AI to Generate Vulnerable Code?\'','\'Yariv Tal\'','Creator Talks_89c3b4f6f07238e6ebf5c748846b7229','\'Title: The API Made Me Do It - Do Bad APIs Lead AI to Generate Vulnerable Code?
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:10 - 16:40 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

We blame the bot when AI-generated code is vulnerable, but what if it is just using the dangerous APIs we left on the table?

\n\n

This talk tests whether API design can steer AI coding agents toward safer code. The same agent builds the same Java/Spring task app twice: once in a normal environment, and once in a constrained one with secure-by-default scaffolding, deny-by-default settings, safer abstractions, and bans on risky APIs.

\n\n

The app includes authentication, authorization, task ownership, file upload, SSRF-prone link previews, and simulated paid features. The prompts describe product behavior, not security advice, so the comparison focuses on environment design rather than better prompting.

\n\n

Both projects are analyzed with CodeQL and manual review to compare SAST findings, authorization flaws, unsafe file handling, SSRF risks, abstraction bypasses, and cases where wrappers hide risk instead of reducing it.

\n\nSpeakerBio:  Yariv Tal
\n

Yariv Tal is a senior developer, security researcher, and cofounder of Secure From Scratch, a venture dedicated to teaching developers secure coding from the very first line of code.

\n\n

A summa cum laude graduate of the Technion, Yariv brings four decades of programming experience and years of university lecturing and bootcamp mentoring to the field of application security.

\n\n

He lectures on secure coding in academia and the private sector, leads the OWASP-untrust project, and researches the intersection of AI and application security, with a focus on secure code generation, LLM evaluation, and secure-by-construction development.

\n\n\n\'',NULL,1294702),('4_Sunday','11','11:50','12:20','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Finding Bugs Is Easy, Patching Isn\'t: Build Your Own Remediation Pipeline\'','\'Mohan Kumar,Naveen\'','Creator Talks_b29c8c73804866e84e14856aace204f4','\'Title: Finding Bugs Is Easy, Patching Isn\'t: Build Your Own Remediation Pipeline
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:50 - 12:20 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

AI made finding and exploiting bugs almost free. In one month, Anthropic\'s Project Glasswing surfaced over 10,000 high and critical bugs and patched fewer than 100. The maintainers on the receiving end are asking Anthropic to slow down, because they can\'t fix the bugs fast enough.

\n\n

If one model can bury the world\'s best-funded security teams, what happens to the 1-to-5 person team with little security budget and a backlog now growing at machine speed?

\n\n

This talk shows you how to build SPAR (Scan, Prioritize, Auto-fix, Rewrite): a remediation pipeline that chains call-graph reachability, EPSS percentiles, and SSVC decision logic into triage a small team can run, then routes the ones that matter through AI patch generation behind a regression-aware verification harness.

\n\nSpeakers:Mohan Kumar,Naveen
\n
\nSpeakerBio:  Mohan Kumar
\n

Mohan is a security leader with over a decade of experience in security architecture, engineering, and operations. He has a strong interest in developing robust security programs and a proven track record of creating proactive security roadmaps and strategies aligned with business objectives. He constantly seeks ways to elevate security processes and culture to the next level.

\n\nSpeakerBio:  Naveen
\n

Naveen is a Security Researcher with over 9 years of expertise specializing in AI, application, and cloud security. He invented 5 patents in Agentic Security space.

\n\n

He possesses extensive knowledge in all aspects of product security, including threat modeling, DevSecOps, API security, and penetration testing. He is passionate about integrating security into the SDLC from design to deployment, ensuring the early detection and mitigation of vulnerabilities.

\n\n\n\'',NULL,1294703),('4_Sunday','12','11:50','12:20','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Finding Bugs Is Easy, Patching Isn\'t: Build Your Own Remediation Pipeline\'','\'Mohan Kumar,Naveen\'','Creator Talks_b29c8c73804866e84e14856aace204f4','\'\'',NULL,1294704),('3_Saturday','13','13:30','13:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Past the Bouncer: The Limits of CSP, Eleven Years In\'','\'Pedro Fortuna\'','Creator Talks_c57dd0429abb06ac70d1bf4fb6e59ca7','\'Title: Past the Bouncer: The Limits of CSP, Eleven Years In
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

CSP turned eleven this year. It is the standard the web ultimately adopted to decide which scripts a page is allowed to load and execute, and it now sits at the center of how we think about XSS mitigation, third-party script risk, and client-side supply-chain compromise.

\n\n

The problem is that CSP was designed as a fetch-time control. It evaluates origins, nonces, hashes, and directives when resources are requested, yet it is often expected to provide guarantees about what trusted code does after execution begins. The bypass literature tells a different story.

\n\n

This talk examines five representative CSP bypass classes, and uses them to expose the gap between controlling what may be loaded and governing behaviour at runtime. It also raises broader questions of script governance, supply-chain security, and the distinction between fetch-time and runtime security controls.

\n\n

I conclude by introducing an open learning platform that contains a comprehensive catalogue of CSP bypass techniques.

\n\nSpeakerBio:  Pedro Fortuna
\n

Pedro Fortuna is a security researcher, entrepreneur, and CTO of Jscrambler. For more than 15 years, his work has focused on web security, client-side security, reverse engineering, malware analysis, and software supply chain threats. He is the author of multiple security patents, a contributor to OWASP, and a member of the PCI Security Standards Council Board of Advisors.

\n\n

Pedro regularly presents security research at international conferences and spends much of his time investigating how modern web applications fail in practice, from browser-side attacks and web skimming campaigns to the security implications of emerging technologies.

\n\n\n\'',NULL,1294705),('3_Saturday','10','10:15','11:15','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'In Untrust We Can Trust: Enforcing Trust Boundaries for Humans and AI Alike\'','\'Yariv Tal\'','Creator Events_f71e445cca3f3bc308032cb618d7a1ff','\'Title: In Untrust We Can Trust: Enforcing Trust Boundaries for Humans and AI Alike
\nTags: Intermediate | AppSec Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:15 - 11:15 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

We keep saying “never trust user input.”\nYet our frameworks still do not differentiate between trusted data and attacker-controlled data.

\n\n

OWASP Untrust is an OWASP umbrella project built around a simple invariant: all data is implicitly untrusted and may cross security boundaries only through deliberate, verifiable trust transitions.

\n\n

Through projects like VV (Validated Values) and BoxedPath, implemented across Python, Java, C#, C++, and Node.js, Untrust makes unsafe states structurally difficult to represent.

\n\n

Instead of detecting vulnerabilities after they are written, Untrust enforces trust boundaries by construction for humans and AI alike.

\n\nSpeakerBio:  Yariv Tal
\n

Yariv Tal is a senior developer, security researcher, and cofounder of Secure From Scratch, a venture dedicated to teaching developers secure coding from the very first line of code.

\n\n

A summa cum laude graduate of the Technion, Yariv brings four decades of programming experience and years of university lecturing and bootcamp mentoring to the field of application security.

\n\n

He lectures on secure coding in academia and the private sector, leads the OWASP-untrust project, and researches the intersection of AI and application security, with a focus on secure code generation, LLM evaluation, and secure-by-construction development.

\n\n\n\'',NULL,1294706),('3_Saturday','11','10:15','11:15','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'In Untrust We Can Trust: Enforcing Trust Boundaries for Humans and AI Alike\'','\'Yariv Tal\'','Creator Events_f71e445cca3f3bc308032cb618d7a1ff','\'\'',NULL,1294707),('3_Saturday','16','16:15','17:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Code to Cloud: Secure Modern Applications Using Open-Source Tools\'','\'Mackenzie\'','Creator Workshops_634760d170fd8778b2c71aa8828b1783','\'Title: Code to Cloud: Secure Modern Applications Using Open-Source Tools
\nTags: Intermediate | AppSec Village | Creator Workshop
\nWhen: Saturday, Aug 8, 16:15 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map
\n
\nDescription:
\n

Want to build secure applications without co-sponsoring a Formula 1 team? The modern threat landscape is a mess of AI-generated vulnerabilities, supply chain poisoning, and cloud misconfigurations. You don\'t need a seven-figure vendor budget to fight it.

\n\n

In this 2-hour hands-on workshop, we will build a complete, automated AppSec pipeline using entirely open-source tools. We will wire up Opengrep for SAST, Trivy for containers, Checkov for infrastructure, and ZAP for DAST - piping the chaos into DefectDojo for centralized vulnerability management. We will also explore how to use local AI models to triage the inevitable mountain of false positives. You will walk away with a functional pipeline and a realistic understanding of where open-source excels, and where it falls apart.

\n\nSpeakerBio:  Mackenzie
\n

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

\n\n

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.

\n\n\nLinks:
    Registration - https://www.zeffy.com/en-US/ticketing/code-to-cloud-secure-modern-applications-using-open-source-tools
\n\'',NULL,1294708),('3_Saturday','17','16:15','17:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Code to Cloud: Secure Modern Applications Using Open-Source Tools\'','\'Mackenzie\'','Creator Workshops_634760d170fd8778b2c71aa8828b1783','\'\'',NULL,1294709),('3_Saturday','11','11:50','12:20','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'How Shadow APIs Become an Attacker\'s Free Pass Into Your Cloud-Native App\'','\'Emma Yuan Fang,Krity\'','Creator Talks_2891437872857ad524821dc403090d79','\'Title: How Shadow APIs Become an Attacker\'s Free Pass Into Your Cloud-Native App
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:50 - 12:20 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Old endpoints rarely die. They get forgotten. They survive refactors, go-lives, and cloud migrations, quietly drifting outside the visibility of gateway security testing. Many are inherited through third-party SDKs, shared libraries, and open-source middleware that teams never provisioned and never fully tracked.\nBuilt from a real security review of a production mobile app, this talk shows how a legacy authentication endpoint quietly bypassed every modern control around it. Through a live demonstration using only open-source tooling, we show how forgotten APIs can become full paths to compromise and why cloud-native visibility models fail by design.

\n\nSpeakers:Emma Yuan Fang,Krity
\n
\nSpeakerBio:  Emma Yuan Fang
\n

Emma is a seasoned Security Architect specialising in cloud security and AppSec. As Regional Practice Lead at EPAM, she leads a team of security practitioners across the UK&I, Switzerland, and Germany. Her focus has recently expanded into the intersection of LLMs, MCP, and security, exploring how agentic AI systems reshape the threat landscape. Beyond her day job, Emma is an award-winning conference speaker, a dedicated mentor, and Vice President of WiCyS UK&I, where she champions diversity in the cyber workforce.

\n\nSpeakerBio:  Krity
\n

Krity is a dedicated cybersecurity professional with a strong foundation in application security, data analysis, and machine learning. As an Application Security Engineer at ServiceNow, she leverages her diverse experience and research background to enhance security practices. Beyond her technical role, Krity serves as the Community & Development Lead at Breaking Barriers Women in Cybersecurity (BBWIC), a nonprofit dedicated to empowering women in the field. Her work reflects a deep commitment to both advancing cybersecurity and fostering inclusive community growth, making her a passionate advocate for innovation, collaboration, and leadership in the industry.

\n\n\n\'',NULL,1294710),('3_Saturday','12','11:50','12:20','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'How Shadow APIs Become an Attacker\'s Free Pass Into Your Cloud-Native App\'','\'Emma Yuan Fang,Krity\'','Creator Talks_2891437872857ad524821dc403090d79','\'\'',NULL,1294711),('2_Friday','16','16:50','17:20','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Most threat modeling artifacts don\'t help coding agents fix business logic. Here\'s what does.\'','\'Meitar Ronen\'','Creator Talks_962d66c0c014259a8212f123a7e84242','\'Title: Most threat modeling artifacts don\'t help coding agents fix business logic. Here\'s what does.
\nTags: AppSec Village | Creator Talk/Panel | All Audiences
\nWhen: Friday, Aug 7, 16:50 - 17:20 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Coding agents increasingly produce code that looks clean to static analysis, but still ship business-logic bugs: the kind threat modeling is supposed to prevent. Across 86 controlled experiments, we varied the security context given to gpt-5.5-codex across eight artifact families and three prompt structures, using the same codebase, PRD, and four planted business-logic flaws. Generic artifacts - DFDs, component diagrams, OWASP checklists - did not reliably help; several performed worse than no artifact at all. In one run, the agent - handed an OWASP checklist - cited A07 in its plan and shipped a 365-day bookmarkable magic link, the exact vulnerability A07 names. One pattern worked across every replication: feature-specific threats paired with concrete countermeasures, in a plan-forcing prompt. The talk walks through the mechanism behind these failure modes and the open-source tool we built to generate the artifact shape that worked.

\n\nSpeakerBio:  Meitar Ronen
\n

Meitar Ronen is AI Research Lead at Clover Security, where she drives the research direction for agentic development and AI infrastructure. She previously built computer vision algorithms and holds an M.Sc. in computer science with a focus on deep learning, with publications at CVPR and ICCV. She turned to the dark side and now leads AI research for cyber, focused on the hard problems that decide whether security agents can be trusted with real work.

\n\n\n\'',NULL,1294712),('2_Friday','17','16:50','17:20','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Most threat modeling artifacts don\'t help coding agents fix business logic. Here\'s what does.\'','\'Meitar Ronen\'','Creator Talks_962d66c0c014259a8212f123a7e84242','\'\'',NULL,1294713),('3_Saturday','15','15:15','16:15','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Proactive Malicious Package Defense\'','\'Darren Meyer\'','Creator Events_104197b6b9c51fb5a1343471bcf82ce1','\'Title: Proactive Malicious Package Defense
\nTags: Intermediate | AppSec Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 15:15 - 16:15 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

Whole development orgs are still rawdogging npm and other package registries, despite the continued rise of supply chain attacks involving malware targeted at both developers and the organizations they work for. Check out open-source tooling that can contribute to proactive defense, using either open or vendor-proprietary data sets

\n\nSpeakerBio:  Darren Meyer
\n

Darren is a security research advocate and practitioner that has worked on every side of the AppSec world at some point in the past 20 years. He\'s passionate about making security work more accessible and less stressful.

\n\n\n\'',NULL,1294714),('3_Saturday','16','15:15','16:15','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'Proactive Malicious Package Defense\'','\'Darren Meyer\'','Creator Events_104197b6b9c51fb5a1343471bcf82ce1','\'\'',NULL,1294715),('4_Sunday','12','12:45','13:45','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'The Agent Asked. We Allowed. Now What?\'','\'Liran Lavi,Sarit Yerushalmi\'','Creator Events_c351d19ccadda995feb9fc9a4278d9d8','\'Title: The Agent Asked. We Allowed. Now What?
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Sunday, Aug 9, 12:45 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

AI agents are already running on developer machines, inside terminals, IDEs, and internal workflows. They are useful, but they can also read code, access files, execute commands, call tools, use credentials, and send data to LLM providers.

\n\n

In this Arsenal demo, we will present an open-source runtime discovery tool for identifying LLM-powered applications and AI agents on live machines without requiring code changes. The tool correlates local processes with LLM-provider traffic, detects known and unknown AI service usage, monitors subprocess and file activity, and applies basic policy controls for coding agents.

\n\n

We will show what AI agents look like at runtime, what they do beyond the chat interface, and how AppSec teams can see, understand, and control them.

\n\nSpeakers:Liran Lavi,Sarit Yerushalmi
\n
\nSpeakerBio:  Liran Lavi
\n

A senior security researcher from Tel Aviv specializing in web application security and advanced bot detection. With over 9 years of experience with small and large companies. To balance my tech-savvy life, you might find me hiking or skydiving - chasing new heights both literally and technically. I am always exploring edge cases and smarter ways to build and break systems.

\n\nSpeakerBio:  Sarit Yerushalmi
\n

Sarit Yerushalmi is an experienced security researcher at Imperva. Her research mainly focuses on application security and APIs. She analyzes traffic to detect new threats, writes security blogs and talks at conferences. Some of her work has been presented at security conferences such as Botconf, Bsides TLV, NorthSec, and Kernelcon.

\n\n\n\'',NULL,1294716),('4_Sunday','13','12:45','13:45','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'The Agent Asked. We Allowed. Now What?\'','\'Liran Lavi,Sarit Yerushalmi\'','Creator Events_c351d19ccadda995feb9fc9a4278d9d8','\'\'',NULL,1294717),('4_Sunday','10','10:15','11:15','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'ROP for the Web: Smuggling XSS, SQLi, and Web Shells Past Every WAF Using Compression Dictionaries\'','\'alevsk\'','Creator Events_02f297bf308351ceb36848489d94f80e','\'Title: ROP for the Web: Smuggling XSS, SQLi, and Web Shells Past Every WAF Using Compression Dictionaries
\nTags: Advanced | AppSec Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:15 - 11:15 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal - Map
\n
\nDescription:
\n

Compression Dictionary Transport (RFC 9842) shipped in Chrome 130+ in 2025. Any JavaScript asset designated as a dictionary becomes a set of gadgets an attacker can chain into responses that bypass signature-based WAFs and IDSes. gadget-scanner is the a tool to evaluate that surface: drop in a candidate dictionary and a payload, and it reports how much of the payload hides inside backreferences and how much leaks as literal bytes on the wire. At the table you will score real-world JS libraries as attack primitives, generate the DCB blob with brotli -D, and watch the side-by-side: the raw bytes a WAF would see vs. the payload a browser would execute

\n\nSpeakerBio:  alevsk
\n

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.

\n\n\n\'',NULL,1294718),('4_Sunday','11','10:15','11:15','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal','\'ROP for the Web: Smuggling XSS, SQLi, and Web Shells Past Every WAF Using Compression Dictionaries\'','\'alevsk\'','Creator Events_02f297bf308351ceb36848489d94f80e','\'\'',NULL,1294719),('4_Sunday','11','11:10','11:40','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Extending Shared Threat Models with the Application Attack Matrix\'','\'J Fridley\'','Creator Talks_70721e04868bbb577a0a23811802c827','\'Title: Extending Shared Threat Models with the Application Attack Matrix
\nTags: AppSec Village | Creator Talk/Panel | All Audiences
\nWhen: Sunday, Aug 9, 11:10 - 11:40 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

Shared threat frameworks have enabled consistent communication and coordination across vulnerability researchers, PSIRTs, vendors, and defenders. However, as attackers increasingly operate at the application layer (abusing software supply chains, runtime behavior, and trusted cloud workflows) defenders face challenges applying existing models consistently. This session presents lessons from the Application Attack Matrix, a community-driven research effort involving contributors from Mandiant (Google Cloud), Microsoft, AWS, Meta, Oligo Security, and others, and uses the ByBit / Safe{Wallet} incident to illustrate why application-layer technique modeling is increasingly important.

\n\nSpeakerBio:  J Fridley
\n

J. Fridley is a Senior Solutions Engineer at Oligo Security, helping teams secure modern cloud environments with deep runtime visibility. He previously led and supported Solutions Engineering teams at Snyk and has a background as a software engineer and technical project lead. J also brings nearly two decades of military service with the U.S. Navy and Army National Guard.

\n\n\n\'',NULL,1294720),('4_Sunday','10','10:15','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Introduction to AI-Enhanced Threat Modeling Workshop\'','\'Robert Hurlbut\'','Creator Workshops_d94967144414a07136c164b474cac45e','\'Title: Introduction to AI-Enhanced Threat Modeling Workshop
\nTags: Intermediate | AppSec Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:15 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom - Map
\n
\nDescription:
\n

This workshop introduces the practical world of threat modeling, combining hands-on exercises and real-world scenarios. In particular, we will focus on how AI can enhance your threat modeling work plus introduce the basics of securing AI systems.

\n\n

We will review some of the latest threat intelligence and attack methods projected for 2026/2027, including vulnerabilities in LLMs and Agentic AI. Participants will engage in practical exercises inspired by real industry projects, such as integrating threat modeling into security-by-design and DevOps/MLOps workflows. Key features include threat-informed defense using MITRE frameworks such as ATLAS for real-world analysis, leveraging threat intelligence libraries to deepen threat understanding, and addressing modern challenges.

\n\n

By the end of this workshop, you will walk away not just with knowledge but also the ability to start practicing threat modeling effectively in your organization.

\n\nSpeakerBio:  Robert Hurlbut
\n

Robert brings over 30 years of experience in secure coding, software architecture. Robert started and led the threat modeling program at Bank of America, filled in a similar role at Aquia and was a trainer and coach at Toreon. He is passionate about helping teams identify, communicate, and understand threats and mitigations and enhance workload security through threat modeling.

\n\n

Robert is a Microsoft MVP for Developer Security and an ISC2 Certified Secure Software Lifecycle Professional (CSSLP). He holds a Master of Science in Cyber Security from Southern New Hampshire University and is a Ph.D. candidate in Space Cybersecurity at Capitol Technology University.

\n\n

Robert is co-author of the Threat Modeling Manifesto (https://www.threatmodelingmanifesto.org/), Threat Modeling Capabilities Model (https://www.threatmodelingmanifesto.org/capabilities), and co-host of the Application Security Podcast (https://appsec.buzzsprout.com/).

\n\n\nLinks:
    Registration - https://www.zeffy.com/en-US/ticketing/introduction-to-ai-enhanced-threat-modeling-workshop
\n\'',NULL,1294721),('4_Sunday','11','10:15','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Introduction to AI-Enhanced Threat Modeling Workshop\'','\'Robert Hurlbut\'','Creator Workshops_d94967144414a07136c164b474cac45e','\'\'',NULL,1294722),('4_Sunday','12','10:15','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Classroom','\'Introduction to AI-Enhanced Threat Modeling Workshop\'','\'Robert Hurlbut\'','Creator Workshops_d94967144414a07136c164b474cac45e','\'\'',NULL,1294723),('2_Friday','16','16:10','16:40','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage','\'Man-in-the-Browser: Hijacking Javascript APIs for Browser Persistence and Credential Theft\'','\'Aarav Juneja\'','Creator Talks_2db50bb10e6a8c04168520e04623c9cd','\'Title: Man-in-the-Browser: Hijacking Javascript APIs for Browser Persistence and Credential Theft
\nTags: Intermediate | AppSec Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:10 - 16:40 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) Main Stage - Map
\n
\nDescription:
\n

On a system, the most utilized application by typical users is the browser, yet the majority of modern exploits attack other technologies, most of which are heavily targeted by antivirus softwares. Browser extensions are known to be challenging to detect and provide as much(if not more) value as other forms of C2 and data capture. Modern solutions rely solely on whitelists and blacklists without considering potential supply chain breaches or other risks to this method.

\n\nSpeakerBio:  Aarav Juneja
\n

Aarav Juneja is a high school sophomore at Amador Valley High School, Pleasanton, CA, who placed 1st nationally in the Advanced Division of Lockheed Martin\'s CyberQuest and earned a scholarship at BlackHat 2025 for his Passkeys research. He came in the top 1% worldwide at CMU’s picoCTF and was additionally selected for the US Cyber Challenge Camp.\nHe is building autonomous systems for RoboSub 2026, competing against 60+ university teams including Stanford, Cornell, and CMU. As Co-Founder and CTO of UniGiig Inc., Aarav deployed production applications, architecting a full-stack system for a student marketplace. \nAarav has completed undergraduate-level coursework from Harvard University in cybersecurity, AI, and computer science, and also holds a Silver Division status in the USA Computing Olympiad. He serves as President of his school\'s Cybersecurity Club and his interests span penetration testing, reverse engineering, cryptography, and binary exploitation across multiple platforms.

\n\n\n\'',NULL,1294724),('2_Friday','15','15:00','16:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'NPM Imposters - The malware detection card game\'','\'Mackenzie\'','Creator Events_4651081ddb7de58f581a0b8e946e83df','\'Title: NPM Imposters - The malware detection card game
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map
\n
\nDescription:
\n

NPM Imposters is a fast-paced educational card game designed to teach players about supply chain security risks in software development, particularly through malicious NPM packages.

\n\nSpeakerBio:  Mackenzie
\n

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

\n\n

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.

\n\n\n\'',NULL,1294725),('2_Friday','16','15:00','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'NPM Imposters - The malware detection card game\'','\'Mackenzie\'','Creator Events_4651081ddb7de58f581a0b8e946e83df','\'\'',NULL,1294726),('3_Saturday','13','13:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Code Invaders: Stop The Insecure Code\'','\'Mackenzie\'','Creator Events_dd560ec777b21e4f608c401eed2799a3','\'Title: Code Invaders: Stop The Insecure Code
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map
\n
\nDescription:
\nRecruit: help stop the Vibe Invasion. AI-generated code is flooding the frontier with insecure logic, and it’s your job to intercept it before it hits production. Vulnerable snippets (SQL injections, hardcoded secrets, broken crypto, and risky error handling) are falling toward the pipeline. Eliminate the threats, but stay sharp: secure code is mixed in. One wrong move could cause damage. Defend production and stop the Vibe Coding Invasion.
\n\n\n\nSpeakerBio:  Mackenzie
\n

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

\n\n

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.

\n\n\n\'',NULL,1294727),('3_Saturday','14','13:00','14:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Code Invaders: Stop The Insecure Code\'','\'Mackenzie\'','Creator Events_dd560ec777b21e4f608c401eed2799a3','\'\'',NULL,1294728),('3_Saturday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Code Invaders: Stop The Insecure Code\'','\'Mackenzie\'','Creator Events_adeea12b95702d40c0d23e6b75126b1d','\'Title: Code Invaders: Stop The Insecure Code
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map
\n
\nDescription:
\nRecruit: help stop the Vibe Invasion. AI-generated code is flooding the frontier with insecure logic, and it’s your job to intercept it before it hits production. Vulnerable snippets (SQL injections, hardcoded secrets, broken crypto, and risky error handling) are falling toward the pipeline. Eliminate the threats, but stay sharp: secure code is mixed in. One wrong move could cause damage. Defend production and stop the Vibe Coding Invasion.
\n\n\n\nSpeakerBio:  Mackenzie
\n

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

\n\n

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.

\n\n\n\'',NULL,1294729),('3_Saturday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Code Invaders: Stop The Insecure Code\'','\'Mackenzie\'','Creator Events_adeea12b95702d40c0d23e6b75126b1d','\'\'',NULL,1294730),('4_Sunday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'NPM Imposters - The malware detection card game \'','\'Mackenzie\'','Creator Events_6b932c74c8d294467107a7eb1008d3a8','\'Title: NPM Imposters - The malware detection card game
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Sunday, Aug 9, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map
\n
\nDescription:
\n

NPM Imposters is a fast-paced educational card game designed to teach players about supply chain security risks in software development, particularly through malicious NPM packages.

\n\nSpeakerBio:  Mackenzie
\n

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

\n\n

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.

\n\n\n\'',NULL,1294731),('4_Sunday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'NPM Imposters - The malware detection card game \'','\'Mackenzie\'','Creator Events_6b932c74c8d294467107a7eb1008d3a8','\'\'',NULL,1294732),('3_Saturday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'Pentester vs AI: Race The Machine, In Real Life\'','\'Gwendal Mognier,Samantha Pearlstein\'','Creator Events_062029b09328fe81cb0be6e9806d0ed2','\'Title: Pentester vs AI: Race The Machine, In Real Life
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map
\n
\nDescription:
\n

The machine already solved it. Could you?\nPentester vs AI brings our race-the-machine CTF off the screen and onto the table. Draw a card, read the challenge, a leaky query, a forged token, a broken access check, and walk us through how you\'d break it. No laptop, no flag to submit. Just talk through your approach: what\'s the flaw, what would you reach for, where\'s the path in.\nThen flip the card and see how the AI reasoned through the same target. Where you agreed, where you didn\'t. The clock is ticking for each challenge; come show us your line.

\n\nSpeakers:Gwendal Mognier,Samantha Pearlstein
\n
\nSpeakerBio:  Gwendal Mognier
\n

Gwendal Mognier is a Security Researcher at Escape. He’s passionate about cybersecurity and always eager to learn new ways to break and secure systems. Gwendal is focused on discovering vulnerabilities and helping improve security across the board.

\n\nSpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape
\n

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.

\n\n\n\'',NULL,1294733),('3_Saturday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'Pentester vs AI: Race The Machine, In Real Life\'','\'Gwendal Mognier,Samantha Pearlstein\'','Creator Events_062029b09328fe81cb0be6e9806d0ed2','\'\'',NULL,1294734),('2_Friday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'Hack the Duck Store\'','\'Gwendal Mognier,Samantha Pearlstein\'','Creator Events_b4a0e0d4a93b51d8ff96f848b22ade84','\'Title: Hack the Duck Store
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map
\n
\nDescription:
\n

At a developer meetup on secure software development, we asked a simple question: look at this login form, how could a hacker abuse it? Not one developer in the room dared to answer. The referral code field looked harmless. The backend had no validation: self-referrals, circular referrals, unlimited farming - all possible. It\'s just the simplest example of how business logic flaws get missed. This card game is built around that gap, showing what business logic vulnerabilities might exist and how the real vulnerabilities, hiding inside the intentionally vulnerable app, Duck Store, can be abused.

\n\nSpeakers:Gwendal Mognier,Samantha Pearlstein
\n
\nSpeakerBio:  Gwendal Mognier
\n

Gwendal Mognier is a Security Researcher at Escape. He’s passionate about cybersecurity and always eager to learn new ways to break and secure systems. Gwendal is focused on discovering vulnerabilities and helping improve security across the board.

\n\nSpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape
\n

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.

\n\n\n\'',NULL,1294735),('2_Friday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'Hack the Duck Store\'','\'Gwendal Mognier,Samantha Pearlstein\'','Creator Events_b4a0e0d4a93b51d8ff96f848b22ade84','\'\'',NULL,1294736),('3_Saturday','15','15:00','16:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'AI Pentesting Trivia Showdown\'','\'Andy Dennis,William Reyor\'','Creator Events_9d2f9661110610248610e1f7b525979a','\'Title: AI Pentesting Trivia Showdown
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map
\n
\nDescription:
\n

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.

\n\nSpeakers:Andy Dennis,William Reyor
\n
\nSpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
\nNo BIO available
\nSpeakerBio:  William Reyor
\n

Bill Reyor is a Lead Solutions Architect at XBOW, where he helps organizations evaluate and adopt autonomous offensive security testing to find exploitable application-layer vulnerabilities at scale. He has over 15 years of security experience spanning penetration testing, incident response, DevSecOps, application security leadership, and security program design, and is a co-author of O’Reilly’s Defensive Security Handbook.

\n\n\n\'',NULL,1294737),('3_Saturday','16','15:00','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'AI Pentesting Trivia Showdown\'','\'Andy Dennis,William Reyor\'','Creator Events_9d2f9661110610248610e1f7b525979a','\'\'',NULL,1294738),('3_Saturday','13','13:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'AI Pentesting Trivia Showdown\'','\'Andy Dennis,Bill Reyor\'','Creator Events_00c7d73d34871a009347a24312da55fe','\'Title: AI Pentesting Trivia Showdown
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map
\n
\nDescription:
\n

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.

\n\nSpeakers:Andy Dennis,Bill Reyor
\n
\nSpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
\nNo BIO available
\nSpeakerBio:  Bill Reyor
\nNo BIO available
\n\n\'',NULL,1294739),('3_Saturday','14','13:00','14:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'AI Pentesting Trivia Showdown\'','\'Andy Dennis,Bill Reyor\'','Creator Events_00c7d73d34871a009347a24312da55fe','\'\'',NULL,1294740),('2_Friday','15','15:00','16:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AI Pentesting Trivia Showdown\'','\'Andy Dennis,Bill Reyor\'','Creator Events_53dacc1e02592daa62664bd1fd762c5c','\'Title: AI Pentesting Trivia Showdown
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map
\n
\nDescription:
\n

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.

\n\nSpeakers:Andy Dennis,Bill Reyor
\n
\nSpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
\nNo BIO available
\nSpeakerBio:  Bill Reyor
\nNo BIO available
\n\n\'',NULL,1294741),('2_Friday','16','15:00','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AI Pentesting Trivia Showdown\'','\'Andy Dennis,Bill Reyor\'','Creator Events_53dacc1e02592daa62664bd1fd762c5c','\'\'',NULL,1294742),('2_Friday','13','13:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AI Pentesting Trivia Showdown\'','\'Andy Dennis,Bill Reyor\'','Creator Events_ea7fddc5a162b977b2d343edb179b01d','\'Title: AI Pentesting Trivia Showdown
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map
\n
\nDescription:
\n

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.

\n\nSpeakers:Andy Dennis,Bill Reyor
\n
\nSpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
\nNo BIO available
\nSpeakerBio:  Bill Reyor
\nNo BIO available
\n\n\'',NULL,1294743),('2_Friday','14','13:00','14:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AI Pentesting Trivia Showdown\'','\'Andy Dennis,Bill Reyor\'','Creator Events_ea7fddc5a162b977b2d343edb179b01d','\'\'',NULL,1294744),('2_Friday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Cards Against Vulnerabilities\'','\'Patrick Smyth\'','Creator Events_057ec2dcbcdb43c3a48904abc2dcedbf','\'Title: Cards Against Vulnerabilities
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map
\n
\nDescription:
\n

Join us for \"Cards Against Security: Trust Me, It\'s Secure,\" a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!

\n\nSpeakerBio:  Patrick Smyth
\n

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.

\n\n\n\'',NULL,1294745),('2_Friday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Cards Against Vulnerabilities\'','\'Patrick Smyth\'','Creator Events_057ec2dcbcdb43c3a48904abc2dcedbf','\'\'',NULL,1294746),('2_Friday','15','15:00','16:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Cards Against Vulnerabilities\'','\'Patrick Smyth\'','Creator Events_ad0f07864fc050be2bda7b6d30359b8b','\'Title: Cards Against Vulnerabilities
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map
\n
\nDescription:
\n

Join us for \"Cards Against Security: Trust Me, It\'s Secure,\" a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!

\n\nSpeakerBio:  Patrick Smyth
\n

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.

\n\n\n\'',NULL,1294747),('2_Friday','16','15:00','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Cards Against Vulnerabilities\'','\'Patrick Smyth\'','Creator Events_ad0f07864fc050be2bda7b6d30359b8b','\'\'',NULL,1294748),('2_Friday','13','13:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Cards Against Vulnerabilities\'','\'Patrick Smyth\'','Creator Events_20cffa35a114389847a6907b93f21471','\'Title: Cards Against Vulnerabilities
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map
\n
\nDescription:
\n

Join us for \"Cards Against Security: Trust Me, It\'s Secure,\" a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!

\n\nSpeakerBio:  Patrick Smyth
\n

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.

\n\n\n\'',NULL,1294749),('2_Friday','14','13:00','14:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Cards Against Vulnerabilities\'','\'Patrick Smyth\'','Creator Events_20cffa35a114389847a6907b93f21471','\'\'',NULL,1294750),('3_Saturday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'Cards Against Vulnerabilities\'','\'Patrick Smyth\'','Creator Events_35a78f27fefa955a0a112afb10dbf3bd','\'Title: Cards Against Vulnerabilities
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map
\n
\nDescription:
\n

Join us for \"Cards Against Security: Trust Me, It\'s Secure,\" a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!

\n\nSpeakerBio:  Patrick Smyth
\n

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.

\n\n\n\'',NULL,1294751),('3_Saturday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'Cards Against Vulnerabilities\'','\'Patrick Smyth\'','Creator Events_35a78f27fefa955a0a112afb10dbf3bd','\'\'',NULL,1294752),('2_Friday','13','13:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'AppSec Quiz Gauntlet: Spot the Vulnerability\'','\'Avek Kolech\'','Creator Events_29fa27c3cc014571e083ad809585d2d2','\'Title: AppSec Quiz Gauntlet: Spot the Vulnerability
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map
\n
\nDescription:
\nIn AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.
\n\n\n\nSpeakerBio:  Avek Kolech
\nNo BIO available
\n\n\'',NULL,1294753),('2_Friday','14','13:00','14:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'AppSec Quiz Gauntlet: Spot the Vulnerability\'','\'Avek Kolech\'','Creator Events_29fa27c3cc014571e083ad809585d2d2','\'\'',NULL,1294754),('3_Saturday','13','13:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AppSec Quiz Gauntlet: Spot the Vulnerability\'','\'Avek Kolech\'','Creator Events_18db99facba7d997a345fcba1be25aee','\'Title: AppSec Quiz Gauntlet: Spot the Vulnerability
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map
\n
\nDescription:
\nIn AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.
\n\n\n\nSpeakerBio:  Avek Kolech
\nNo BIO available
\n\n\'',NULL,1294755),('3_Saturday','14','13:00','14:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AppSec Quiz Gauntlet: Spot the Vulnerability\'','\'Avek Kolech\'','Creator Events_18db99facba7d997a345fcba1be25aee','\'\'',NULL,1294756),('3_Saturday','15','15:00','16:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AppSec Quiz Gauntlet: Spot the Vulnerability\'','\'Avek Kolech\'','Creator Events_d2ac27a48222b10da983495eb06f5ffb','\'Title: AppSec Quiz Gauntlet: Spot the Vulnerability
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map
\n
\nDescription:
\nIn AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.
\n\n\n\nSpeakerBio:  Avek Kolech
\nNo BIO available
\n\n\'',NULL,1294757),('3_Saturday','16','15:00','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AppSec Quiz Gauntlet: Spot the Vulnerability\'','\'Avek Kolech\'','Creator Events_d2ac27a48222b10da983495eb06f5ffb','\'\'',NULL,1294758),('4_Sunday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AppSec Quiz Gauntlet: Spot the Vulnerability\'','\'Avek Kolech\'','Creator Events_2b3342d02b7e67ca37696f25facb01d5','\'Title: AppSec Quiz Gauntlet: Spot the Vulnerability
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Sunday, Aug 9, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map
\n
\nDescription:
\nIn AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.
\n\n\n\nSpeakerBio:  Avek Kolech
\nNo BIO available
\n\n\'',NULL,1294759),('4_Sunday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'AppSec Quiz Gauntlet: Spot the Vulnerability\'','\'Avek Kolech\'','Creator Events_2b3342d02b7e67ca37696f25facb01d5','\'\'',NULL,1294760),('2_Friday','15','15:00','16:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'SBOM Find the Flaws\'','\'Dmitry Raidman\'','Creator Events_f479eedb292d2a4a86e19f55b425125f','\'Title: SBOM Find the Flaws
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map
\n
\nDescription:
\n

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.

\n\nSpeakerBio:  Dmitry Raidman
\n

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

\n\n

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

\n\n

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.

\n\n\n\'',NULL,1294761),('2_Friday','16','15:00','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'SBOM Find the Flaws\'','\'Dmitry Raidman\'','Creator Events_f479eedb292d2a4a86e19f55b425125f','\'\'',NULL,1294762),('3_Saturday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'SBOM Find the Flaws\'','\'Dmitry Raidman\'','Creator Events_48e06383782c0c0cafe6f9056095c012','\'Title: SBOM Find the Flaws
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map
\n
\nDescription:
\n

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.

\n\nSpeakerBio:  Dmitry Raidman
\n

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

\n\n

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

\n\n

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.

\n\n\n\'',NULL,1294763),('3_Saturday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'SBOM Find the Flaws\'','\'Dmitry Raidman\'','Creator Events_48e06383782c0c0cafe6f9056095c012','\'\'',NULL,1294764),('3_Saturday','15','15:00','16:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'SBOM Find the Flaws\'','\'Dmitry Raidman\'','Creator Events_2c7f53bd70cbf04ca32b9c53b69418ae','\'Title: SBOM Find the Flaws
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map
\n
\nDescription:
\n

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.

\n\nSpeakerBio:  Dmitry Raidman
\n

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

\n\n

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

\n\n

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.

\n\n\n\'',NULL,1294765),('3_Saturday','16','15:00','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'SBOM Find the Flaws\'','\'Dmitry Raidman\'','Creator Events_2c7f53bd70cbf04ca32b9c53b69418ae','\'\'',NULL,1294766),('4_Sunday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'SBOM Find the Flaws\'','\'Dmitry Raidman\'','Creator Events_02aee43a80d4a54e3001bd7dffd55534','\'Title: SBOM Find the Flaws
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Sunday, Aug 9, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map
\n
\nDescription:
\n

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.

\n\nSpeakerBio:  Dmitry Raidman
\n

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

\n\n

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

\n\n

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.

\n\n\n\'',NULL,1294767),('4_Sunday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'SBOM Find the Flaws\'','\'Dmitry Raidman\'','Creator Events_02aee43a80d4a54e3001bd7dffd55534','\'\'',NULL,1294768),('2_Friday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'The Call Stack Experience\'','\'Victoria Keeler\'','Creator Events_9905008f92558f8982832ae0c161b9c2','\'Title: The Call Stack Experience
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2 - Map
\n
\nDescription:
\n

Let’s play with blocks… and learn how real application attacks unfold.

\n\n

You will build real application call stacks, one foam block at a time, with each block representing function calls in a normal execution flow.

\n\n

Once your stack is complete, you will see first-hand how easy it is for exploits to blend in with normal application behavior.

\n\nSpeakerBio:  Victoria Keeler
\nNo BIO available
\n\n\'',NULL,1294769),('2_Friday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2','\'The Call Stack Experience\'','\'Victoria Keeler\'','Creator Events_9905008f92558f8982832ae0c161b9c2','\'\'',NULL,1294770),('3_Saturday','15','15:00','16:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'The Call Stack Experience\'','\'Victoria Keeler\'','Creator Events_561b1f4927fe8fe88764c6b355dfbb7c','\'Title: The Call Stack Experience
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map
\n
\nDescription:
\n

Let’s play with blocks… and learn how real application attacks unfold.

\n\n

You will build real application call stacks, one foam block at a time, with each block representing function calls in a normal execution flow.

\n\n

Once your stack is complete, you will see first-hand how easy it is for exploits to blend in with normal application behavior.

\n\nSpeakerBio:  Victoria Keeler
\nNo BIO available
\n\n\'',NULL,1294771),('3_Saturday','16','15:00','16:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'The Call Stack Experience\'','\'Victoria Keeler\'','Creator Events_561b1f4927fe8fe88764c6b355dfbb7c','\'\'',NULL,1294772),('2_Friday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'Clash of Prompts: The World\'s First Prompt Battle Royale\'','\'\'','Creator Events_bcd951326cfca9834e44b238df29b387','\'Title: Clash of Prompts: The World\'s First Prompt Battle Royale
\nTags: AppSec Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map
\n
\nDescription:
\n

Clash of Prompts is the world\'s first live, head-to-head AI prompt battle royale. Two developers tackle the same coding challenge, one prompt each, on the clock, while the AI generates the code live on screen. Every prompt is scored in real time on vulnerabilities, security best practices, and prompt efficiency.

\n\n

Research shows 87-94% of AI-generated code ships with security flaws, even when developers try to prompt securely. This Pod is a hands-on way to see that play out: attendees write and test real prompts and watch them get scored instantly.

\n\n\'',NULL,1294773),('2_Friday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'Clash of Prompts: The World\'s First Prompt Battle Royale\'','\'\'','Creator Events_bcd951326cfca9834e44b238df29b387','\'\'',NULL,1294774),('4_Sunday','11','11:00','12:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Clash of Prompts: The World\'s First Prompt Battle Royale\'','\'Darren McNelis,Jerome Roberts\'','Creator Events_ca75eec065c3dd757323948c3088bde2','\'Title: Clash of Prompts: The World\'s First Prompt Battle Royale
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Sunday, Aug 9, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1 - Map
\n
\nDescription:
\n

Clash of Prompts is the world\'s first live, head-to-head AI prompt battle royale. Two developers tackle the same coding challenge, one prompt each, on the clock, while the AI generates the code live on screen. Every prompt is scored in real time on vulnerabilities, security best practices, and prompt efficiency.

\n\n

Research shows 87-94% of AI-generated code ships with security flaws, even when developers try to prompt securely. This Pod is a hands-on way to see that play out: attendees write and test real prompts and watch them get scored instantly.

\n\nSpeakers:Darren McNelis,Jerome Roberts
\n
\nSpeakerBio:  Darren McNelis
\nNo BIO available
\nSpeakerBio:  Jerome Roberts
\n

With over 20 years of experience in cybersecurity and 15 years as a CxO, Jérôme has a proven track record in driving successful outcomes. He has been instrumental in five successful exits, including Lexsi (acquired by Orange in 2016) and Alsid (acquired by Tenable in 2021). Starting his career in deep-tech, mathematics, and engineering, Jérôme transitioned seamlessly into business leadership, leveraging his technical roots to guide strategic decisions and foster innovation in the cybersecurity landscape.

\n\n\n\'',NULL,1294775),('4_Sunday','12','11:00','12:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1','\'Clash of Prompts: The World\'s First Prompt Battle Royale\'','\'Darren McNelis,Jerome Roberts\'','Creator Events_ca75eec065c3dd757323948c3088bde2','\'\'',NULL,1294776),('3_Saturday','13','13:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'Factory Floor MVP Incident Response Challenge\'','\'\'','Creator Events_d80e73c0539974aca15bb64a0f4b7e34','\'Title: Factory Floor MVP Incident Response Challenge
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Saturday, Aug 8, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4 - Map
\n
\nDescription:
\n

Defend the Factory. Beat the Attack. The Factory Floor MVP Incident Response Challenge is a fast-paced, interactive card-and-dice game where teams investigate cyberattacks against a modern manufacturing environment. Use strategy, collaboration, and a little luck to uncover attacker activity before production or safety is impacted. Players will walk away with practical insights into OT security, firmware and SBOM analysis, incident response, and the challenges of protecting connected industrial systems.

\n\n\'',NULL,1294777),('3_Saturday','14','13:00','14:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4','\'Factory Floor MVP Incident Response Challenge\'','\'\'','Creator Events_d80e73c0539974aca15bb64a0f4b7e34','\'\'',NULL,1294778),('2_Friday','13','13:00','14:59','N','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'Factory Floor MVP Incident Response Challenge\'','\'\'','Creator Events_1a35ce86c5022e160d9391a4e34f940d','\'Title: Factory Floor MVP Incident Response Challenge
\nTags: AppSec Village | Creator Event/Activity | | All Audiences
\nWhen: Friday, Aug 7, 13:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3 - Map
\n
\nDescription:
\n

Defend the Factory. Beat the Attack. The Factory Floor MVP Incident Response Challenge is a fast-paced, interactive card-and-dice game where teams investigate cyberattacks against a modern manufacturing environment. Use strategy, collaboration, and a little luck to uncover attacker activity before production or safety is impacted. Players will walk away with practical insights into OT security, firmware and SBOM analysis, incident response, and the challenges of protecting connected industrial systems.

\n\n\'',NULL,1294779),('2_Friday','14','13:00','14:59','Y','AppSec Village','LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3','\'Factory Floor MVP Incident Response Challenge\'','\'\'','Creator Events_1a35ce86c5022e160d9391a4e34f940d','\'\'',NULL,1294780),('2_Friday','10','10:00','23:59','N','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'Title: Apex Park (Cloud Village CTF)
\nTags: Cloud Village | Apex Park (Cloud Village CTF) | Contest
\nWhen: Friday, Aug 7, 10:00 - 23:59 PDT
\nWhere: LVCCW Level 3 W312 (Cloud Village CTF) - Map
\n
\nDescription:
\n

Cloud Village CTF will be a jeopardy style 2 days contest where participants will have to solve challenges around Cloud infrastructure, security, recon, etc. These challenges will cover different cloud platforms including AWS, GCP, Azure, Digital Ocean, etc. We will also reward our top 3 teams with awards.​​

\n\n

Participant Prerequisites

\n\n

A laptop with unfiltered internet access and an open mind to learn with the community.

\n\n

Timing

\n\n

Cloud Village CTF @ DEF CON 34: 7th & 8th August 2026\nCTF starts - 7th August, 2026 - 10:00AM PDT\nCTF closes - 8th August 2026 - 23:59PM PDT\nCTF registrations opens - 30th July 2026 - 10:00AM PDT

\n\nLinks:
    Website - https://ctf.cloud-village.org
\n\'',NULL,1294781),('2_Friday','11','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294782),('2_Friday','12','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294783),('2_Friday','13','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294784),('2_Friday','14','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294785),('2_Friday','15','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294786),('2_Friday','16','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294787),('2_Friday','17','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294788),('2_Friday','18','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294789),('2_Friday','19','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294790),('2_Friday','20','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294791),('2_Friday','21','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294792),('2_Friday','22','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294793),('2_Friday','23','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_bb194037690d9d953ab133762f737390','\'\'',NULL,1294794),('3_Saturday','10','10:00','23:59','N','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'Title: Apex Park (Cloud Village CTF)
\nTags: Cloud Village | Apex Park (Cloud Village CTF) | Contest
\nWhen: Saturday, Aug 8, 10:00 - 23:59 PDT
\nWhere: LVCCW Level 3 W312 (Cloud Village CTF) - Map
\n
\nDescription:
\n

Cloud Village CTF will be a jeopardy style 2 days contest where participants will have to solve challenges around Cloud infrastructure, security, recon, etc. These challenges will cover different cloud platforms including AWS, GCP, Azure, Digital Ocean, etc. We will also reward our top 3 teams with awards.​​

\n\n

Participant Prerequisites

\n\n

A laptop with unfiltered internet access and an open mind to learn with the community.

\n\n

Timing

\n\n

Cloud Village CTF @ DEF CON 34: 7th & 8th August 2026\nCTF starts - 7th August, 2026 - 10:00AM PDT\nCTF closes - 8th August 2026 - 23:59PM PDT\nCTF registrations opens - 30th July 2026 - 10:00AM PDT

\n\nLinks:
    Website - https://ctf.cloud-village.org
\n\'',NULL,1294795),('3_Saturday','11','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294796),('3_Saturday','12','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294797),('3_Saturday','13','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294798),('3_Saturday','14','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294799),('3_Saturday','15','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294800),('3_Saturday','16','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294801),('3_Saturday','17','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294802),('3_Saturday','18','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294803),('3_Saturday','19','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294804),('3_Saturday','20','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294805),('3_Saturday','21','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294806),('3_Saturday','22','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294807),('3_Saturday','23','10:00','23:59','Y','Contests','LVCCW Level 3 W312 (Cloud Village CTF)','\'Apex Park (Cloud Village CTF)\'','\'\'','Contests_0c74faedd4c5d18e4ebda38b64b4c3b8','\'\'',NULL,1294808),('1_Thursday','19','19:00','19:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: House\'','\'mattrix\'','Social Gatherings/Events_24ae9c649e6bcdab34b0764ad4679328','\'Title: Music - Genre: House
\nTags: Entertainment
\nWhen: Thursday, Aug 6, 19:00 - 19:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  mattrix
\n

mattrix is a DJ in the Los Angeles area. He started DJing at hacker events such as Toorcon, ShellCon and DEFCON. mattrix has DJ\'d at the Linq Pool and other night clubs and bars. mattrix prefers Tech House and Open Format DJ genres but can perform within a wide range of genres.

\n\n\n\'',NULL,1294809),('1_Thursday','20','20:00','20:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Electro House\'','\'Archwisp\'','Social Gatherings/Events_e90fdc51fceeb0813998033258690758','\'Title: Music - Genre: Electro House
\nTags: Entertainment
\nWhen: Thursday, Aug 6, 20:00 - 20:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Archwisp
\n

Resident DCP beatsmaker 😎

\n\n\n\'',NULL,1294810),('1_Thursday','21','21:00','21:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Breakbeats\'','\'PatAttack\'','Social Gatherings/Events_dc7bf48dde3cc7cd345225afca6cb6ad','\'Title: Music - Genre: Breakbeats
\nTags: Entertainment
\nWhen: Thursday, Aug 6, 21:00 - 21:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  PatAttack
\n

PatAttack is a Seattle Based DJ who loves EDM. He is a Security Nerd who hunts logs by day and plays beats by night.

\n\n\n\'',NULL,1294811),('1_Thursday','22','22:00','22:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Breakbeats\'','\'Icetre Normal\'','Social Gatherings/Events_c8d32b9d9eb754600d81c9b7e2442471','\'Title: Music - Genre: Breakbeats
\nTags: Entertainment
\nWhen: Thursday, Aug 6, 22:00 - 22:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Icetre Normal
\n

Forever lurking the hallowed halls of records, tapes, 8-Tracks, Icetre has been bringing the best in breakbeats, jungle, drum and bass, electro, house, goth, industrial, found sounds, and oddball records to craft the tightest, freshest and oddest music in the hacker scene.

\n\n\n\'',NULL,1294812),('1_Thursday','23','23:00','23:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Techno\'','\'Scotch and Bubbles\'','Social Gatherings/Events_4d3b9a525dc92f4a4ebf7bf29c0957de','\'Title: Music - Genre: Techno
\nTags: Entertainment
\nWhen: Thursday, Aug 6, 23:00 - 23:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Scotch and Bubbles
\n

“Scotch and Bubbles” is Zack “is it whiskey or whisky?” Fasel (@zfasel) and Erin “it’s not Champagne if it’s not from Champagne!” Jacobs (@secbarbie). Their history of bringing the untz, unce, and wubz to underground cyberdomes, ransomware recovery meetings, and 4 hour tarmac flight delays has put them on the global map, with performances stretching from Berlin to Bangkok. Bringing a mix of progressive, electro, future bass, and house, the duo has toured the world playing at events such as DEF CON, Shmoocon, Holy Sailboat, indoor cycling centers for the elderly, and as reenact-ors on America’s Most Wanted – Cyber Edition.

\n\n\n\'',NULL,1294813),('2_Friday','19','19:00','19:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Goth / Industrial\'','\'Daemon Chadeau\'','Social Gatherings/Events_0a8bd9bef31a42646619d8d6225c36c2','\'Title: Music - Genre: Goth / Industrial
\nTags: Entertainment
\nWhen: Friday, Aug 7, 19:00 - 19:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Daemon Chadeau
\n

From the darkest lit nightclubs to the livestreaming virtual nightlife, DJ Daemon Chadeau has imposed their will upon sound systems and dance floors all over the US since 2003. A native of Southern California, Daemon has been a staple of Seattle\'s Mercury at Machinewerks since moving to the Northwest in 2011 and has been highlighting the bleeding edge in music from all around the diaspora of dark music, whether it is harsh industrial, power noise, darkwave, or bass-saturated electronic beats, and everything in between. After being recognized by their peers in both 2014 and 2015 as the Best Local Industrial DJ at the Mechanismus Industrial Music Awards, Daemon expanded beyond their home base and has performed at venues such as The Coffin Club (PDX), The Church Nightclub (DEN), and QXT\'s (NJ), as well as larger events such as Convergence XXI (LA), The Mechanismus Festival (2022 & 2025), The 2026 Seattle Fetish Ball, The Arcane Vampire Ball (DEN), and the main stage at DEFCONs 32 & 33 (LV). You can catch Daemon at The Mercury on 2nd Wednesdays (Protokol) and 3rd Fridays (Tech Noir), as well as at Time Warp for Continuum every 2nd Thursday! Outside of the decks, Daemon is the bassist for Seattle-area rock band Prelude To A Pistol, and is also the producer/composer/evil kitty mastermind Sir Kitty Meow-Meow in the experimental meower noise project Pixelpussy. Daemon has also been heavily involved with community engagement in the Seattle area, from mentoring up-and-coming DJs to having served as President of Gothic Pride Seattle from 2021 to 2024.

\n\n\n\'',NULL,1294814),('2_Friday','20','20:00','20:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Goth / Industrial\'','\'DJ Scythe\'','Social Gatherings/Events_bf0df761016eb29a9966141ceb2ee81a','\'Title: Music - Genre: Goth / Industrial
\nTags: Entertainment
\nWhen: Friday, Aug 7, 20:00 - 20:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  DJ Scythe
\n

SoCal/Vegas-based DJ Scythe spins Industrial/Aggrotech/Witch House/Synthpop/Synthwave/EBM/EBSM and all manners of dark and heavy music. He is a founding member and resident DJ of UnterKlub, Club Fallout, GothCon, and Nachturnal, Resident DJ at AREA15, and previously of BatCave LA. He regularly DJs the main stages for DEFCON, Wasteland Weekend and Neotropolis, and has done headlining shows for Torture Garden, Bondage Ball, Das Bunker, and others. Also a producer, his music can be found as SCYTHE, Artifact Corruption, and various other projects and is honored to have had his music featured on the Official DefCon 28 Safe Mode tape and various releases since.

\n\n\n\'',NULL,1294815),('2_Friday','21','21:00','21:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Nerdcore\'','\'Ohm-I\'','Social Gatherings/Events_6b8b3bbecfbba93827f60a4f3a0c8b3c','\'Title: Music - Genre: Nerdcore
\nTags: Entertainment
\nWhen: Friday, Aug 7, 21:00 - 21:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Ohm-I
\n

Ohm-I is a nerdcore rapper, saxophonist, and red teamer who mixes humor, storytelling, and a hacker perspective into clever and fun #BARS.

\n\n\n\'',NULL,1294816),('2_Friday','22','22:00','22:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: House\'','\'Skittish & Bus\'','Social Gatherings/Events_227d296072427779ab8a0198804aba37','\'Title: Music - Genre: House
\nTags: Entertainment
\nWhen: Friday, Aug 7, 22:00 - 22:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Skittish & Bus
\nNo BIO available
\n\n\'',NULL,1294817),('2_Friday','23','23:00','23:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Techno\'','\'TRIODE\'','Social Gatherings/Events_83152f2f692e0fe8455f7acf0fb6c12e','\'Title: Music - Genre: Techno
\nTags: Entertainment
\nWhen: Friday, Aug 7, 23:00 - 23:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  TRIODE
\n

For up-and-coming uplifting trance DJ/Producer based out of San Francisco, Triode, music is much more than words could ever explain. Music serves as the cinematic backdrop to each of our stories, and as a DJ he sees it as his job to curate the perfect soundtrack to celebrate this amazing thing we call ‘life’. Whether it’s on the dancefloor, or in the studio producing his own beats - Triode’s takes his listeners for a ride, into a magical place where you become the hero of this musical journey.

\n\n\n\'',NULL,1294818),('2_Friday','00','00:00','00:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Techno\'','\'dotornot\'','Social Gatherings/Events_34bb981bc90e6e3dd706ff581ebcf3d5','\'Title: Music - Genre: Techno
\nTags: Entertainment
\nWhen: Friday, Aug 7, 00:00 - 00:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  dotornot
\n

With his trusty decks and mixer, DotOrNot unleashes a barrage of electrifying beats, showcasing the full spectrum of electronic music, from techno to house & DnB. DotOrNot is a champion of the underground, a protector of the genre, and a hero to all who dance to the beat of his music.

\n\n\n\'',NULL,1294819),('3_Saturday','00','00:00','00:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Trance\'','\'AfterGlow\'','Social Gatherings/Events_b05cee4366496cc35f8cccf51c001e9a','\'Title: Music - Genre: Trance
\nTags: Entertainment
\nWhen: Saturday, Aug 8, 00:00 - 00:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  𝗔𝗙𝗧Ʃ𝗥↡𝗚𝗟Ф𝗪
\n

AfterGlow is a Los Angeles-based DJ known for his electrifying sets that span across a wide range of EDM genres. Captivating crowds with his high-energy performances and infectious beats. Whether performing at intimate venues, events, or clubs, his sets leave a lasting impression that are sure to make you a fan.

\n\n\n\'',NULL,1294820),('3_Saturday','19','19:00','19:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Dubstep\'','\'ZipZapZop\'','Social Gatherings/Events_39eafd26ba4e9f07e6e329888c5c3cbc','\'Title: Music - Genre: Dubstep
\nTags: Entertainment
\nWhen: Saturday, Aug 8, 19:00 - 19:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  ZipZapZop
\n

Clark ov Saturn, Space Trucking Mogul, aka ZipZapZop has been releasing music off and on since the late 1980\'s. Notable projects have included pH10 (Terraformat Records, Europe tour with Trumystic Sound System 1999), Socks and Sandals (Microcosm Music, Unfoundsound Records) and resident DJ at Halcyon\'s weekly Deep Unda Brooklyn Undercity party in NYC in the early 2000\'s. After a long break focusing on family, an educational technology career and earning a doctorate, Saturn returned to music production with several projects since 2021: ZipZapZop, Pill Hill Deans, Luther VanGross and DubRatz, each featuring a variety of sounds, sub pressure bass-oriented music styles and friends, with the goals of fun, travel and liberation via creativity. More info, videos, links & connections at ZipZapZop.com

\n\n\n\'',NULL,1294821),('3_Saturday','20','20:00','20:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Drum & Bass\'','\'RELAY\'','Social Gatherings/Events_bef015e6218d70967a4621e8379f2592','\'Title: Music - Genre: Drum & Bass
\nTags: Entertainment
\nWhen: Saturday, Aug 8, 20:00 - 20:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  RELAY
\n

With over 25 years of experience, RELAY is fluent in the language of electronic music, effortlessly blending genres ranging from house, trance and techno to bass music, electro and drum and bass while also incorporating turntablism. His sets promise to keep the vibe alive.

\n\n\n\'',NULL,1294822),('3_Saturday','21','21:00','21:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Nerdcore\'','\'Dual Core\'','Social Gatherings/Events_6ecf675c077b439110e1ae6c218d112c','\'Title: Music - Genre: Nerdcore
\nTags: Entertainment
\nWhen: Saturday, Aug 8, 21:00 - 21:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Dual Core
\n

Dual Core is an international hip hop duo. Drink all the booze; hack all the things!

\n\n\n\'',NULL,1294823),('3_Saturday','22','22:00','22:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Drum & Bass\'','\'Miss Jackalope\'','Social Gatherings/Events_4b87099f14eacc75f867297f6cb5abf6','\'Title: Music - Genre: Drum & Bass
\nTags: Entertainment
\nWhen: Saturday, Aug 8, 22:00 - 22:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Miss Jackalope
\n

Miss Jackalope is DEF CON\'s Resident DJ. She\'s played all sorts of awesome events, parties, and infosec conventions. Her current faves are drum and bass and electro. Usually she is spotted getting abused by her cat while trying to spin on her weekly Twitch show (twitch.tv/missjackalope) and in the DC Vendor room selling her legendary merch. She is the DEF CON Arts and Entertainment evangelist and leader of the Mighty Jackalope Army. She also has a massive pile of claw game fun and Twitch replays on her Youtube channel! (youtube.com/@MissJackalope) Come join the party!

\n\n\n\'',NULL,1294824),('3_Saturday','23','23:00','23:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Drum & Bass\'','\'Syntax + Luna\'','Social Gatherings/Events_bb20f60cef11faba3df573451364ab34','\'Title: Music - Genre: Drum & Bass
\nTags: Entertainment
\nWhen: Saturday, Aug 8, 23:00 - 23:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Syntax + Luna
\n

Syntax has been DJing almost as long as he’s been hacking, experienced in a variety of genres and currently obsessed with Drum & Bass. Luna started joining Syntax on stage in the last few years by mixing their visuals with the same live intensity. Together they perform at hacker cons across the US—plus other shows in between—always blasting earholes and bouncing eyeballs to the best bass-y beats.

\n\n\n\'',NULL,1294825),('4_Sunday','00','00:00','00:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - Genre: Drum & Bass\'','\'DJ XORAC\'','Social Gatherings/Events_46f8fbad06dd5d3e31f056cc836863f5','\'Title: Music - Genre: Drum & Bass
\nTags: Entertainment
\nWhen: Sunday, Aug 9, 00:00 - 00:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  DJ XORAC
\nI like hacking and music : )
\n\n\n\n\n\'',NULL,1294826),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_876efe86776b13be6146b32024944e12','\'Title: PhreakMe
\nTags: PhreakMe | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 210 (PhreakMe) - Map
\n
\nDescription:
\n

Ever wondered what hacking looked like in the golden age of phone phreaking? What about today? What can we learn about the old techniques that still plague our current infrastructure? The PhreakMe Capture the Flag brings you the classic art of telecom exploitation.

\n\n

The Hacked Existence team is once again hosting a telecom based CTF. The CTF runs on real live VoIP lines routed through a modified asterisk PBX allowing participants to dial in to the CTF from anywhere in the world. This number is live 24/7 throughout DEFCON, allowing you to hunt the PBX for flags any time, day or night. Don\'t have a phone? Come test your skills at one of our 5 payphones! Also there\'s a BBS, hope you brought your modem!

\n\n

All the flags are based around historically accurate tactics, techniques, and procedures to manipulate emulated old school switching systems.

\n\n

The purpose of our contest is to bring awareness around the still existing weaknesses in our telecom infrastructure and Interactive Voice Response Systems. Ideally visitors to our contest area will participate in the CTF allowing them to get a better understanding of telecom hacking in the year 2026 as well as a respect for the art of phreaking from yesteryear.

\n\n

Come test your skills, challenge your knowledge, and dive deep into the world of phreaks.

\n\n

Hints: Read \'The Cyberthief and the Samurai\' and \'Masters of Deception: The Gang That Ruled Cyberspace\' for a leg up.

\n\n

Participant Prerequisites

\n\n

A phone, or access to a phone that can dial an american based phone number. The BBS will be both accessible from a modem and also ssh. Ideally people will read books like \'The Cyberthief and the Samurai\' and \'Masters of Deception: The Gang That Ruled Cyberspace\' and the Cult of the Dead Cow book.

\n\n\'',NULL,1294827),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_876efe86776b13be6146b32024944e12','\'\'',NULL,1294828),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_876efe86776b13be6146b32024944e12','\'\'',NULL,1294829),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_876efe86776b13be6146b32024944e12','\'\'',NULL,1294830),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_876efe86776b13be6146b32024944e12','\'\'',NULL,1294831),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_876efe86776b13be6146b32024944e12','\'\'',NULL,1294832),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_876efe86776b13be6146b32024944e12','\'\'',NULL,1294833),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_876efe86776b13be6146b32024944e12','\'\'',NULL,1294834),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_bc228951b7e95489157d159ef011112f','\'Title: PhreakMe
\nTags: PhreakMe | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 210 (PhreakMe) - Map
\n
\nDescription:
\n

Ever wondered what hacking looked like in the golden age of phone phreaking? What about today? What can we learn about the old techniques that still plague our current infrastructure? The PhreakMe Capture the Flag brings you the classic art of telecom exploitation.

\n\n

The Hacked Existence team is once again hosting a telecom based CTF. The CTF runs on real live VoIP lines routed through a modified asterisk PBX allowing participants to dial in to the CTF from anywhere in the world. This number is live 24/7 throughout DEFCON, allowing you to hunt the PBX for flags any time, day or night. Don\'t have a phone? Come test your skills at one of our 5 payphones! Also there\'s a BBS, hope you brought your modem!

\n\n

All the flags are based around historically accurate tactics, techniques, and procedures to manipulate emulated old school switching systems.

\n\n

The purpose of our contest is to bring awareness around the still existing weaknesses in our telecom infrastructure and Interactive Voice Response Systems. Ideally visitors to our contest area will participate in the CTF allowing them to get a better understanding of telecom hacking in the year 2026 as well as a respect for the art of phreaking from yesteryear.

\n\n

Come test your skills, challenge your knowledge, and dive deep into the world of phreaks.

\n\n

Hints: Read \'The Cyberthief and the Samurai\' and \'Masters of Deception: The Gang That Ruled Cyberspace\' for a leg up.

\n\n

Participant Prerequisites

\n\n

A phone, or access to a phone that can dial an american based phone number. The BBS will be both accessible from a modem and also ssh. Ideally people will read books like \'The Cyberthief and the Samurai\' and \'Masters of Deception: The Gang That Ruled Cyberspace\' and the Cult of the Dead Cow book.

\n\n\'',NULL,1294835),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_bc228951b7e95489157d159ef011112f','\'\'',NULL,1294836),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_bc228951b7e95489157d159ef011112f','\'\'',NULL,1294837),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_bc228951b7e95489157d159ef011112f','\'\'',NULL,1294838),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_bc228951b7e95489157d159ef011112f','\'\'',NULL,1294839),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_bc228951b7e95489157d159ef011112f','\'\'',NULL,1294840),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_bc228951b7e95489157d159ef011112f','\'\'',NULL,1294841),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_bc228951b7e95489157d159ef011112f','\'\'',NULL,1294842),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_dfda6597f85906c57f5d8af385dd230c','\'Title: PhreakMe
\nTags: PhreakMe | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 210 (PhreakMe) - Map
\n
\nDescription:
\n

Ever wondered what hacking looked like in the golden age of phone phreaking? What about today? What can we learn about the old techniques that still plague our current infrastructure? The PhreakMe Capture the Flag brings you the classic art of telecom exploitation.

\n\n

The Hacked Existence team is once again hosting a telecom based CTF. The CTF runs on real live VoIP lines routed through a modified asterisk PBX allowing participants to dial in to the CTF from anywhere in the world. This number is live 24/7 throughout DEFCON, allowing you to hunt the PBX for flags any time, day or night. Don\'t have a phone? Come test your skills at one of our 5 payphones! Also there\'s a BBS, hope you brought your modem!

\n\n

All the flags are based around historically accurate tactics, techniques, and procedures to manipulate emulated old school switching systems.

\n\n

The purpose of our contest is to bring awareness around the still existing weaknesses in our telecom infrastructure and Interactive Voice Response Systems. Ideally visitors to our contest area will participate in the CTF allowing them to get a better understanding of telecom hacking in the year 2026 as well as a respect for the art of phreaking from yesteryear.

\n\n

Come test your skills, challenge your knowledge, and dive deep into the world of phreaks.

\n\n

Hints: Read \'The Cyberthief and the Samurai\' and \'Masters of Deception: The Gang That Ruled Cyberspace\' for a leg up.

\n\n

Participant Prerequisites

\n\n

A phone, or access to a phone that can dial an american based phone number. The BBS will be both accessible from a modem and also ssh. Ideally people will read books like \'The Cyberthief and the Samurai\' and \'Masters of Deception: The Gang That Ruled Cyberspace\' and the Cult of the Dead Cow book.

\n\n\'',NULL,1294843),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 210 (PhreakMe)','\'PhreakMe\'','\'\'','Contests_dfda6597f85906c57f5d8af385dd230c','\'\'',NULL,1294844),('0_Wednesday','22','22:00','22:59','N','Contests','Online','\'Raitlin\'s Challenge\'','\'\'','Contests_22a6620a35511a8ae6858ee1091fc4f0','\'Title: Raitlin\'s Challenge
\nTags: Raitlin\'s Challenge | Contest
\nWhen: Wednesday, Aug 5, 22:00 - 22:59 PDT
\nWhere: Online
\n
\nDescription:
\n

Test your mental abilities with Raitlin\'s Challenge, the Illuminati Party®\'s sophisticated collection of abstract visual puzzles, presented annually at DEF CON for over a decade. This intellectually demanding competition pushes participants to their limits through exceedingly complex challenges that require mastery of diverse knowledge domains.

\n\n

The challenge begins with an initial invitation puzzle that serves as a gateway to the main experience. Once solved, competitors continue to a carefully curated series of abstract visual puzzles presented in an artistically refined format on the dedicated website. Each puzzle solved yields a verification string for validation and progress tracking.

\n\n

What sets Raitlin\'s Challenge apart is its comprehensive scope, drawing upon principles from mathematics, science, engineering, technology, cryptography, protocols, algorithms, biology, chemistry, programming, and ancient history. While technical expertise, particularly in hacking, proves advantageous, the true challenge lies in applying abstract thinking across multiple disciplines.

\n\n

The journey to completion varies significantly among participants, spanning anywhere from days to years. Unlike many competitive events, Raitlin\'s Challenge remains perpetually available after DEF CON concludes, allowing determined solvers to pursue solutions at their own pace. Those who ultimately succeed earn recognition on the prestigious ledger of completions, joining an elite group of problem-solvers who have demonstrated exceptional intellectual versatility and persistence in unraveling the secrets of the Illuminati Party®.

\n\n

Participant Prerequisites

\n\n

Access to a web browser and Internet connection.

\n\n\'',NULL,1294845),('2_Friday','10','10:00','17:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_0917a6f2630c9bfd3c8ced10ebffa8ca','\'Title: F1NDX OSINT Educational Series
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

The OSINT Educational Series is a 3-level series that introduces Open-Source Intelligence (OSINT). It covers data collection, social media analysis, and investigative techniques, showing how publicly available information is used in cybersecurity and intelligence. Volunteers will be on hand to help you get started and answer questions if you get stuck! Complete all 3 levels and earn a digital badge!

\n\nLinks:
    More Info - https://tracelabs.org/blog/osint-educational-series
\n\'',NULL,1294846),('2_Friday','11','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_0917a6f2630c9bfd3c8ced10ebffa8ca','\'\'',NULL,1294847),('2_Friday','12','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_0917a6f2630c9bfd3c8ced10ebffa8ca','\'\'',NULL,1294848),('2_Friday','13','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_0917a6f2630c9bfd3c8ced10ebffa8ca','\'\'',NULL,1294849),('2_Friday','14','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_0917a6f2630c9bfd3c8ced10ebffa8ca','\'\'',NULL,1294850),('2_Friday','15','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_0917a6f2630c9bfd3c8ced10ebffa8ca','\'\'',NULL,1294851),('2_Friday','16','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_0917a6f2630c9bfd3c8ced10ebffa8ca','\'\'',NULL,1294852),('2_Friday','17','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_0917a6f2630c9bfd3c8ced10ebffa8ca','\'\'',NULL,1294853),('3_Saturday','10','10:00','17:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_e3ef1ae9de87393c32b43ecdcdbeabb6','\'Title: F1NDX OSINT Educational Series
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

The OSINT Educational Series is a 3-level series that introduces Open-Source Intelligence (OSINT). It covers data collection, social media analysis, and investigative techniques, showing how publicly available information is used in cybersecurity and intelligence. Volunteers will be on hand to help you get started and answer questions if you get stuck! Complete all 3 levels and earn a digital badge!

\n\nLinks:
    More Info - https://tracelabs.org/blog/osint-educational-series
\n\'',NULL,1294854),('3_Saturday','11','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_e3ef1ae9de87393c32b43ecdcdbeabb6','\'\'',NULL,1294855),('3_Saturday','12','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_e3ef1ae9de87393c32b43ecdcdbeabb6','\'\'',NULL,1294856),('3_Saturday','13','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_e3ef1ae9de87393c32b43ecdcdbeabb6','\'\'',NULL,1294857),('3_Saturday','14','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_e3ef1ae9de87393c32b43ecdcdbeabb6','\'\'',NULL,1294858),('3_Saturday','15','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_e3ef1ae9de87393c32b43ecdcdbeabb6','\'\'',NULL,1294859),('3_Saturday','16','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_e3ef1ae9de87393c32b43ecdcdbeabb6','\'\'',NULL,1294860),('3_Saturday','17','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_e3ef1ae9de87393c32b43ecdcdbeabb6','\'\'',NULL,1294861),('4_Sunday','10','10:00','13:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_1e4a97b75fcbcc567b76908831c5cec4','\'Title: F1NDX OSINT Educational Series
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

The OSINT Educational Series is a 3-level series that introduces Open-Source Intelligence (OSINT). It covers data collection, social media analysis, and investigative techniques, showing how publicly available information is used in cybersecurity and intelligence. Volunteers will be on hand to help you get started and answer questions if you get stuck! Complete all 3 levels and earn a digital badge!

\n\nLinks:
    More Info - https://tracelabs.org/blog/osint-educational-series
\n\'',NULL,1294862),('4_Sunday','11','10:00','13:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_1e4a97b75fcbcc567b76908831c5cec4','\'\'',NULL,1294863),('4_Sunday','12','10:00','13:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_1e4a97b75fcbcc567b76908831c5cec4','\'\'',NULL,1294864),('4_Sunday','13','10:00','13:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'F1NDX OSINT Educational Series\'','\'\'','Creator Events_1e4a97b75fcbcc567b76908831c5cec4','\'\'',NULL,1294865),('4_Sunday','10','10:00','13:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_04f2f6f303e3e6da1d585728b9e662fb','\'Title: OSINT4Good Community - DC NextGen Content
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

Make this a stop on your DC NextGen journey, solve the challenge, and earn a digital badge!

\n\n\'',NULL,1294866),('4_Sunday','11','10:00','13:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_04f2f6f303e3e6da1d585728b9e662fb','\'\'',NULL,1294867),('4_Sunday','12','10:00','13:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_04f2f6f303e3e6da1d585728b9e662fb','\'\'',NULL,1294868),('4_Sunday','13','10:00','13:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_04f2f6f303e3e6da1d585728b9e662fb','\'\'',NULL,1294869),('3_Saturday','10','10:00','17:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_f1d97471ad419cd2915fda23e9165d79','\'Title: OSINT4Good Community - DC NextGen Content
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

Make this a stop on your DC NextGen journey, solve the challenge, and earn a digital badge!

\n\n\'',NULL,1294870),('3_Saturday','11','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_f1d97471ad419cd2915fda23e9165d79','\'\'',NULL,1294871),('3_Saturday','12','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_f1d97471ad419cd2915fda23e9165d79','\'\'',NULL,1294872),('3_Saturday','13','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_f1d97471ad419cd2915fda23e9165d79','\'\'',NULL,1294873),('3_Saturday','14','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_f1d97471ad419cd2915fda23e9165d79','\'\'',NULL,1294874),('3_Saturday','15','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_f1d97471ad419cd2915fda23e9165d79','\'\'',NULL,1294875),('3_Saturday','16','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_f1d97471ad419cd2915fda23e9165d79','\'\'',NULL,1294876),('3_Saturday','17','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_f1d97471ad419cd2915fda23e9165d79','\'\'',NULL,1294877),('2_Friday','10','10:00','17:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_af2f1e832877015a708034e27f1b62f9','\'Title: OSINT4Good Community - DC NextGen Content
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

Make this a stop on your DC NextGen journey, solve the challenge, and earn a digital badge!

\n\n\'',NULL,1294878),('2_Friday','11','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_af2f1e832877015a708034e27f1b62f9','\'\'',NULL,1294879),('2_Friday','12','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_af2f1e832877015a708034e27f1b62f9','\'\'',NULL,1294880),('2_Friday','13','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_af2f1e832877015a708034e27f1b62f9','\'\'',NULL,1294881),('2_Friday','14','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_af2f1e832877015a708034e27f1b62f9','\'\'',NULL,1294882),('2_Friday','15','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_af2f1e832877015a708034e27f1b62f9','\'\'',NULL,1294883),('2_Friday','16','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_af2f1e832877015a708034e27f1b62f9','\'\'',NULL,1294884),('2_Friday','17','10:00','17:59','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Community - DC NextGen Content\'','\'\'','Creator Events_af2f1e832877015a708034e27f1b62f9','\'\'',NULL,1294885),('2_Friday','11','11:00','11:30','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Q&A with the OSINT4Good Panel\'','\'Angela Ramos,Kenny J,Brent Louie\'','Creator Events_8fd143429ee8024ad3ed690f798aa490','\'Title: Q&A with the OSINT4Good Panel
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

Stop by and chat with the panelists from the OSINT4Good panel.

\n\nSpeakers:Angela Ramos,Kenny J,Brent Louie
\n
\nSpeakerBio:  Angela Ramos, University of Tampa
\n

Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coaches Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations.

\n\nSpeakerBio:  Kenny J, Trace Labs
\n

Senior Infrastructure Engineer by day. Osint for Good by night. His is the only Trace Labs coach to have coached 20+ CTFs, earning him the singular rank of Legendary Coach.

\n\nSpeakerBio:  Brent Louie, Reporting Team Lead at Trace Labs
\n

Brent Louie is the Reporting Team Lead at Trace Labs and an Associate Director of Data Science with more than 15 years of experience in the biotechnology industry. He focuses on applying OSINT methodologies to missing persons investigations and helping transform crowdsourced research into actionable investigative leads for law enforcement.

\n\n\n\'',NULL,1294886),('2_Friday','11','11:45','12:15','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Welcome to OSINT4Good and Trace Labs\'','\'Nataly \"someone_somewhere\"\'','Creator Talks_89d55dc64fec7f89cf5dbb6f984dbbd4','\'Title: Welcome to OSINT4Good and Trace Labs
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:45 - 12:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

This overview session will talk about how OSINT4Good is used across a variety of career fields and how you can get involved.

\n\nSpeakerBio:  Nataly \"someone_somewhere\", Trace Labs
\n

A cybersecurity professional obsessed with human psychology and making servers work how we expect them to, and a Trace Labs Director.

\n\n\nLinks:
    www.tracelabs.org - https://www.tracelabs.org
\n\'',NULL,1294887),('2_Friday','12','11:45','12:15','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Welcome to OSINT4Good and Trace Labs\'','\'Nataly \"someone_somewhere\"\'','Creator Talks_89d55dc64fec7f89cf5dbb6f984dbbd4','\'\'',NULL,1294888),('2_Friday','12','12:30','13:15','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Geolocating Talent: How OSINT CTFs are Building Tomorrow\'s Analysts\'','\'Ben \"The Cyber Sensei\" Crenshaw\'','Creator Talks_d160adc975449364363dcd6521b282ab','\'Title: Geolocating Talent: How OSINT CTFs are Building Tomorrow\'s Analysts
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:30 - 13:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

What happens when you hand students a daily \"Cyber Briefing,\" a target, and unrestricted internet access? You build relentless investigators. In this talk, former Oracle vulnerability analyst turned educator Ben Crenshaw breaks down how to weaponize curiosity by scaling OSINT training from a single classroom to massive regional competitions. Drawing on his experience training 1000+ competitors for the Mayors Cyber Cup and coaching TraceLabs SearchParty CTFs, Ben will share exactly how to teach the threat-intel mindset. Discover how gamified open-source intelligence is reshaping cybersecurity education, turning passive scrollers into privacy-aware analysts, and building the next generation of defenders.

\n\nSpeakerBio:  Ben \"The Cyber Sensei\" Crenshaw, Transofotech Academy | Cyber & AI Education Leader | EdTech & Workforce Development | U.S. Cyber Games Mentor | NICE Cybersecurity Ambassador | CLEAR AI Initiative | Senior TraceLabs Coach | Aerospace Education Member
\n

Ben Crenshaw, known as The Cyber Sensei, is a cybersecurity educator, author of two industry books, and a dedicated US Cyber Games Mentor. Leveraging his background as a former Senior Vulnerability Analyst at Oracle, Ben transitioned into education to bridge the critical gap between real-world threat intelligence and classroom theory. Currently serving as Lead Cybersecurity instructor for Transfortech and as former Head of Cyber and AI Education at Work ED, he has taught Open-Source Intelligence (OSINT) to thousands of students, shaping them into ethically grounded, privacy-conscious defenders. A passionate advocate for scaling cyber education, Ben actively trains educators and coaches to prepare the next generation of talent for large-scale competitions like the Mayors Cyber Cup and TraceLabs.

\n\n\n\'',NULL,1294889),('2_Friday','13','12:30','13:15','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Geolocating Talent: How OSINT CTFs are Building Tomorrow\'s Analysts\'','\'Ben \"The Cyber Sensei\" Crenshaw\'','Creator Talks_d160adc975449364363dcd6521b282ab','\'\'',NULL,1294890),('2_Friday','14','14:30','14:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Q&A with the Classical OSINT Using AI speaker\'','\'Bianca C. Ionescu/reconcerto\'','Creator Events_76c8c0c6967699fbbd4b2891c198bfac','\'Title: Q&A with the Classical OSINT Using AI speaker
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

Stop by and chat with reconcerto, the speaker on Classical OSINT using AI (Actual Intelligence)

\n\nSpeakerBio:  Bianca C. Ionescu/reconcerto
\n

Bianca Ionescu is a CyberCorps SFS scholar pursuing a master’s degree in cybersecurity at UNLV. She\'s served as a leader within cybersecurity student organizations, promoting growth, inclusion, and professional development. Her interests include open-source intelligence and mentoring new learners entering the field. Offline, she enjoys strength training and playing the viola. She’s motivated by community building, continuous learning, and the challenge of solving complex security problems that inspire her growth and resilience every day.

\n\n\n\'',NULL,1294891),('2_Friday','15','15:30','16:30','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Trace Labs L100: Search Party Basics\'','\'Sarah \"scba\" Miller\'','Creator Workshops_2a92c1de84352f32fe5b3028ea99ead5','\'Title: Trace Labs L100: Search Party Basics
\nTags: OSINT For Good Community | Creator Workshop
\nWhen: Friday, Aug 7, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

Learn how to optimize your OSINT workflow and strengthen your performance in the Trace Labs Search Party CTF and beyond. . This session will cover core strategies, ethical guidelines, and preparation methods to help you operate confidently, efficiently, and responsibly in a real-world investigative environment. Normally offered as a paid webinar, this session is lead by a Trace Labs Director and earns a digital badge that is part of the Trace Labs webinar series.

\n\nSpeakerBio:  Sarah \"scba\" Miller, Trace Labs
\n

Dr. Sarah Miller is a college professor, emergency manager, cybersecurity manager, and a Director for Trace Labs.

\n\n\n\'',NULL,1294892),('2_Friday','16','15:30','16:30','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Trace Labs L100: Search Party Basics\'','\'Sarah \"scba\" Miller\'','Creator Workshops_2a92c1de84352f32fe5b3028ea99ead5','\'\'',NULL,1294893),('2_Friday','17','17:00','17:30','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Installing and Using the Tracelabs VM\'','\'Jeff \"UltraSunshine\" G\'','Creator Talks_603d0a1f9597666ad34e37dcce43c863','\'Title: Installing and Using the Tracelabs VM
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

Come learn from the lead developer how to install and use the Trace Labs Virtual Machine, including a live demonstration. Stick around after to get help during a hands-on workshop

\n\nSpeakerBio:  Jeff \"UltraSunshine\" G, Trace Labs VM Lead
\n

Jeff is a forensics engineer with a passion for building tools that empower skilled people to do awesome work. That drive shapes their career and their downtime. At work they build tools that investigators rely on to collect, process, and analyze forensic evidence. As a volunteer, they serve as Trace Labs VM Lead, maintaining an OSINT-focused Linux distribution used by people around the world to investigate missing persons cases as part of Search Party CTFs. In their downtime, they foster stray kittens - proof that even the most seasoned toolmaker has a soft spot for a good rescue.

\n\n\nLinks:
    Github - https://github.com/tracelabs/tlosint-vm
\n\'',NULL,1294894),('2_Friday','17','17:30','17:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'Tracelabs VM Installation Workshop\'','\'\'','Creator Workshops_9466aad04011356f43779995522be73e','\'Title: Tracelabs VM Installation Workshop
\nTags: OSINT For Good Community | Creator Workshop
\nWhen: Friday, Aug 7, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

Need help installing or using the Trace Labs Virtual Machine? Bring your laptop and sit down for some one-on-one help from one of our volunteers.

\n\n\'',NULL,1294895),('3_Saturday','10','10:00','10:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Trace Labs L150: Case Walkthrough\'','\'Brent Louie\'','Creator Workshops_9c419b1cc3d67cc12ab500c93fd15e32','\'Title: Trace Labs L150: Case Walkthrough
\nTags: OSINT For Good Community | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

Join us for an immersive online seminar with the Reporting Team Department Head at Trace Labs, as he walks through real missing person investigations from the Trace Labs CTFs. This session moves beyond foundational OSINT concepts and focuses on how investigations unfold in practice, from a single starting point to the development of actionable, ethically collected intelligence. Participants will follow detailed case walkthroughs drawn from Trace Labs Search Party CTF events, highlighting how analysts:

\n\n

Pivot from initial clues across platforms and ecosystems\nIdentify meaningful signals of activity\nProvide actionable intelligence

\n\n

Normally offered as a paid webinar, this session earns a digital badge that is part of the Trace Labs webinar series.

\n\nSpeakerBio:  Brent Louie, Reporting Team Lead at Trace Labs
\n

Brent Louie is the Reporting Team Lead at Trace Labs and an Associate Director of Data Science with more than 15 years of experience in the biotechnology industry. He focuses on applying OSINT methodologies to missing persons investigations and helping transform crowdsourced research into actionable investigative leads for law enforcement.

\n\n\n\'',NULL,1294896),('3_Saturday','11','11:15','11:45','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'CTF Intro, Quick Guides, and Rule Review\'','\'Kenny J\'','Creator Talks_db5804b6b29903fc7a528d960d7580e0','\'Title: CTF Intro, Quick Guides, and Rule Review
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:15 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

Participating in today\'s Global OSINT Search Party CTF? This session, offered by our most senior Coach, the Legendary KennyJ, will do a quick overview of what to expect, how to get organized, and how to make sure you\'re following the rules.

\n\nSpeakerBio:  Kenny J, Trace Labs
\n

Senior Infrastructure Engineer by day. Osint for Good by night. His is the only Trace Labs coach to have coached 20+ CTFs, earning him the singular rank of Legendary Coach.

\n\n\n\'',NULL,1294897),('3_Saturday','16','16:00','16:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT Search party CTF Debrief\'','\'Trace Labs Staff\'','Creator Workshops_a19dc2293773e678f636d40000f84bb7','\'Title: OSINT Search party CTF Debrief
\nTags: OSINT For Good Community | Creator Workshop
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

An opportunity to ask questsions and get clarification on things that happened during the CTF.

\n\nSpeakerBio:  Trace Labs Staff
\nNo BIO available
\n\n\'',NULL,1294898),('3_Saturday','17','17:00','17:15','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT Search Party CTF Prize and Award Announcements.\'','\'\'','Creator Events_15e9dc64ee63f367f711d1a0ae7b5669','\'Title: OSINT Search Party CTF Prize and Award Announcements.
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 17:00 - 17:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

Prizes and awards from the Gobal OSINT Search Party CTF will be announced.

\n\n\'',NULL,1294899),('3_Saturday','17','17:15','17:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'OSINT4Good Sticker Swap\'','\'\'','Creator Events_1a25067e4d25dfd7b1d25ac41662bcc0','\'Title: OSINT4Good Sticker Swap
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 17:15 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

Bring some stickers, take some stickers. There will be some specially themed OSINT4Good stickers available only here!

\n\n\'',NULL,1294900),('4_Sunday','10','10:30','10:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'How to Profile an entire C-suite in 10 days\'','\'Sarah Muriel\'','Creator Talks_3069af1c0e18f4d9c8f61e4044e1023a','\'Title: How to Profile an entire C-suite in 10 days
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

How long do you think it takes to find sensitive information on the executives of a major company? It is sometimes wrongly believed that VIPs have better digital hygiene than us regular humans, that their information is not present on any people search site, and that their dubious online past has been wiped from the internet. This is false. Throughout this talk I will show you how I approach a vulnerability assessment on the c-suite of a multinational corporation. From the boring stuff like note taking and report writing, to the really exciting stuff like wacky sources and fun findings.

\n\nSpeakerBio:  Sarah Muriel, Bishop Fox
\n

Sarah Muriel is an Intelligence Analyst from Mexico with more than 6 years of experience in open source investigations, currently working with the Attack Surfaces of companies all over the world. In her spare time she likes participating in various international OSINT related CTFs and developing retro-style websites. She’s also fairly active in the cybersecurity community, being part of the organization team for one of Mexico’s top conferences.

\n\n\n\'',NULL,1294901),('4_Sunday','11','11:00','11:15','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)','\'Q&A with the \"How to Profile an entire C-suite in 10 days\" speaker\'','\'Sarah Muriel\'','Creator Events_2f46d267b07da242e4036f27b5dd18fe','\'Title: Q&A with the \"How to Profile an entire C-suite in 10 days\" speaker
\nTags: OSINT For Good Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 11:00 - 11:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) - Map
\n
\nDescription:
\n

Stop by and chat with Sarah Muriel the speaker on How to Profile and Entire C-Suite in 10 days.

\n\nSpeakerBio:  Sarah Muriel, Bishop Fox
\n

Sarah Muriel is an Intelligence Analyst from Mexico with more than 6 years of experience in open source investigations, currently working with the Attack Surfaces of companies all over the world. In her spare time she likes participating in various international OSINT related CTFs and developing retro-style websites. She’s also fairly active in the cybersecurity community, being part of the organization team for one of Mexico’s top conferences.

\n\n\n\'',NULL,1294902),('4_Sunday','11','11:30','12:45','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Disaster Intelligence - The past, present, and future of situational awareness during a crisis\'','\'Matt Green\'','Creator Talks_a62e6c59f25f183c309d5ce862a23782','\'Title: Disaster Intelligence - The past, present, and future of situational awareness during a crisis
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:30 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

OSINT, social media, drones, AI, and more… in this session, we’ll learn how these innovations are applied to make life-saving decisions before, during, and after a disaster

\n\nSpeakerBio:  Matt Green, Green Emergency Management Services
\n

Matt Green is your friendly neighborhood emergency manager, professor, and host of the state of disaster podcast. His passion is ensuring equitable, high-quality, whole community emergency management across sectors and borders.

\n\n\n\'',NULL,1294903),('4_Sunday','12','11:30','12:45','Y','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Disaster Intelligence - The past, present, and future of situational awareness during a crisis\'','\'Matt Green\'','Creator Talks_a62e6c59f25f183c309d5ce862a23782','\'\'',NULL,1294904),('4_Sunday','13','13:00','13:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Building a Student-Led OSINT Program to Investigate Cryptocurrency Fraud\'','\'Angela Ramos\'','Creator Talks_1c4df84ad72236639a80e043f286992d','\'Title: Building a Student-Led OSINT Program to Investigate Cryptocurrency Fraud
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

ScamBusters is a student-facing OSINT investigation program that trains students to identify, trace, and report cryptocurrency fraud infrastructure — from pig-butchering scam domains to the wallet networks behind them. This talk shares how the program works, what students have actually found (hundreds of scam domains and wallet clusters tied to organized fraud rings), and how the reporting pipeline connects student research to real-world action.

\n\nSpeakerBio:  Angela Ramos, University of Tampa
\n

Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coaches Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations.

\n\n\nLinks:
    Website - https://www.intelligenceforgood.org/
\n\'',NULL,1294905),('2_Friday','10','10:00','17:59','N','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_d37b12ef9b179681cb06182ec2ce29b7','\'Title: DDV open and accepting drives for duplication
\nTags: Data Duplication Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W203 (Data Duplication Village) - Map
\n
\nDescription:
\nWe start taking drives at 4: 00pm local time on Thursday - possibly a little earlier. We\'ll keep accepting drives until we reach capacity (usually late Friday or early Saturday).  Then we copy and copy all the things until we just can\'t copy any more - first come, first served. Note that some sources require 8TB drives now.  We run around the clock until we run out of time on Sunday morning with the last possible pickup being before 11:00am on Sunday.
\n\n\n\n\'',NULL,1294906),('2_Friday','11','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_d37b12ef9b179681cb06182ec2ce29b7','\'\'',NULL,1294907),('2_Friday','12','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_d37b12ef9b179681cb06182ec2ce29b7','\'\'',NULL,1294908),('2_Friday','13','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_d37b12ef9b179681cb06182ec2ce29b7','\'\'',NULL,1294909),('2_Friday','14','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_d37b12ef9b179681cb06182ec2ce29b7','\'\'',NULL,1294910),('2_Friday','15','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_d37b12ef9b179681cb06182ec2ce29b7','\'\'',NULL,1294911),('2_Friday','16','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_d37b12ef9b179681cb06182ec2ce29b7','\'\'',NULL,1294912),('2_Friday','17','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_d37b12ef9b179681cb06182ec2ce29b7','\'\'',NULL,1294913),('1_Thursday','16','16:00','18:59','N','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_f994930c255415a2fb5281d4d5f0935e','\'Title: DDV open and accepting drives for duplication
\nTags: Data Duplication Village | Creator Event/Activity
\nWhen: Thursday, Aug 6, 16:00 - 18:59 PDT
\nWhere: LVCCW Level 2 W203 (Data Duplication Village) - Map
\n
\nDescription:
\nWe start taking drives at 4: 00pm local time on Thursday - possibly a little earlier. We\'ll keep accepting drives until we reach capacity (usually late Friday or early Saturday).  Then we copy and copy all the things until we just can\'t copy any more - first come, first served. Note that some sources require 8TB drives now.  We run around the clock until we run out of time on Sunday morning with the last possible pickup being before 11:00am on Sunday.
\n\n\n\n\'',NULL,1294914),('1_Thursday','17','16:00','18:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_f994930c255415a2fb5281d4d5f0935e','\'\'',NULL,1294915),('1_Thursday','18','16:00','18:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_f994930c255415a2fb5281d4d5f0935e','\'\'',NULL,1294916),('3_Saturday','10','10:00','17:59','N','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_cecb4c442cb61f9d4e9e4d18a24f260a','\'Title: DDV open and accepting drives for duplication
\nTags: Data Duplication Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W203 (Data Duplication Village) - Map
\n
\nDescription:
\nWe start taking drives at 4: 00pm local time on Thursday - possibly a little earlier. We\'ll keep accepting drives until we reach capacity (usually late Friday or early Saturday).  Then we copy and copy all the things until we just can\'t copy any more - first come, first served. Note that some sources require 8TB drives now.  We run around the clock until we run out of time on Sunday morning with the last possible pickup being before 11:00am on Sunday.
\n\n\n\n\'',NULL,1294917),('3_Saturday','11','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_cecb4c442cb61f9d4e9e4d18a24f260a','\'\'',NULL,1294918),('3_Saturday','12','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_cecb4c442cb61f9d4e9e4d18a24f260a','\'\'',NULL,1294919),('3_Saturday','13','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_cecb4c442cb61f9d4e9e4d18a24f260a','\'\'',NULL,1294920),('3_Saturday','14','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_cecb4c442cb61f9d4e9e4d18a24f260a','\'\'',NULL,1294921),('3_Saturday','15','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_cecb4c442cb61f9d4e9e4d18a24f260a','\'\'',NULL,1294922),('3_Saturday','16','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_cecb4c442cb61f9d4e9e4d18a24f260a','\'\'',NULL,1294923),('3_Saturday','17','10:00','17:59','Y','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'DDV open and accepting drives for duplication\'','\'\'','Creator Events_cecb4c442cb61f9d4e9e4d18a24f260a','\'\'',NULL,1294924),('4_Sunday','10','10:00','10:59','N','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'Last chance to pick up drives at the DDV\'','\'\'','Creator Events_466009831b3bd7826875901df3a6ec59','\'Title: Last chance to pick up drives at the DDV
\nTags: Data Duplication Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 2 W203 (Data Duplication Village) - Map
\n
\nDescription:
\n

This is your last chance to pickup your drives whether they\'re finished or not. Get here between 10:00am and 11:00am on Sunday as any drives left behind are considered donations.

\n\n\'',NULL,1294925),('2_Friday','11','11:00','11:59','N','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'Drive Stats: 14 years of hard drive failure rates\'','\'Stephanie Doyle\'','Creator Talks_696f2cfb5a1eefe15af6d1d0f58ae5e5','\'Title: Drive Stats: 14 years of hard drive failure rates
\nTags: Data Duplication Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W203 (Data Duplication Village) - Map
\n
\nDescription:
\n

For over 14 years, Backblaze has been collecting the failure rates of hard drives in our data centers. But, what does that even mean? How do you define a failure, and how does that definition define or obscure the realities of drive performance?

\n\nSpeakerBio:  Stephanie Doyle, Sr. Manager and Keeper of Stats at Backblaze
\n

Stephanie Doyle is a Sr. Manager at Backblaze and known as the Keeper of Stats. She oversees the various first party data reports including Drive Stats, which reports on the failure rates of hard drives in Backblaze data centers; Network Stats, which reports on network traffic into and out of Backblaze\'s network; and Performance Stats, which publishes quarterly testing on cloud storage benchmarks. She specializes in taking complex topics and writing relatable, engaging, and user-friendly content. You can most often find her reading in public places, and can connect with her on LinkedIn.

\n\n\n\'',NULL,1294926),('3_Saturday','13','13:00','13:59','N','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'Drive Stats: 14 years of hard drive failure rates\'','\'Stephanie Doyle\'','Creator Talks_689aced30be2a278b29a596fce401a8c','\'Title: Drive Stats: 14 years of hard drive failure rates
\nTags: Data Duplication Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W203 (Data Duplication Village) - Map
\n
\nDescription:
\n

For over 14 years, Backblaze has been collecting the failure rates of hard drives in our data centers. But, what does that even mean? How do you define a failure, and how does that definition define or obscure the realities of drive performance?

\n\nSpeakerBio:  Stephanie Doyle, Sr. Manager and Keeper of Stats at Backblaze
\n

Stephanie Doyle is a Sr. Manager at Backblaze and known as the Keeper of Stats. She oversees the various first party data reports including Drive Stats, which reports on the failure rates of hard drives in Backblaze data centers; Network Stats, which reports on network traffic into and out of Backblaze\'s network; and Performance Stats, which publishes quarterly testing on cloud storage benchmarks. She specializes in taking complex topics and writing relatable, engaging, and user-friendly content. You can most often find her reading in public places, and can connect with her on LinkedIn.

\n\n\n\'',NULL,1294927),('2_Friday','13','13:00','13:30','N','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'Forcing Physical Interlocks into Data Transit and Storage Replication\'','\'Mehmet Önder Key,Temel Demir\'','Creator Talks_a97caee59c7b6c626d1c80766b895b71','\'Title: Forcing Physical Interlocks into Data Transit and Storage Replication
\nTags: Data Duplication Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 2 W203 (Data Duplication Village) - Map
\n
\nDescription:
\n

Traditional software-based security cannot prevent data destruction or unauthorized cloning when authorized credentials are compromised. This presentation introduces a hardware-level physical intervention approach with a zero-OS FPGA architecture to overcome vulnerabilities at the L3/L4 layer. This invisible Layer-2 transparent bridge, lacking IP or MAC addresses, performs sub-nanosecond-level gate-level Deep Packet Inspection (DPI) on the pipeline. When high-risk storage commands (deletion, unauthorized data transfer, etc.) are detected at the silicon level, the data flow is hardware-intercepted and held in a \"Catch-and-Release\" buffer until a physical human confirmation is received.

\n\nSpeakers:Mehmet Önder Key,Temel Demir
\n
\nSpeakerBio:  Mehmet Önder Key, Cyber Security Consultant
\n

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.

\n\nSpeakerBio:  Temel Demir
\n

Temel Demir is a cybersecurity researcher and hardware architect specializing in hardware defense, offensive security, and the protection of critical infrastructure. With a core focus on embedded system vulnerabilities and Layer-1/Layer-2 network manipulation, his research involves developing deterministic, hardware-enforced frameworks that bypass traditional software-defined security flaws. Having previously shared security research on global stages, his work bridges the gap between sophisticated threat actor methodologies and immutable physical security barriers.

\n\n\n\'',NULL,1294928),('3_Saturday','12','12:15','12:45','N','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'Forcing Physical Interlocks into Data Transit and Storage Replication\'','\'Mehmet Önder Key,Temel Demir\'','Creator Talks_28f83acbb0ff64f439b14395153be63c','\'Title: Forcing Physical Interlocks into Data Transit and Storage Replication
\nTags: Data Duplication Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:15 - 12:45 PDT
\nWhere: LVCCW Level 2 W203 (Data Duplication Village) - Map
\n
\nDescription:
\n

Traditional software-based security cannot prevent data destruction or unauthorized cloning when authorized credentials are compromised. This presentation introduces a hardware-level physical intervention approach with a zero-OS FPGA architecture to overcome vulnerabilities at the L3/L4 layer. This invisible Layer-2 transparent bridge, lacking IP or MAC addresses, performs sub-nanosecond-level gate-level Deep Packet Inspection (DPI) on the pipeline. When high-risk storage commands (deletion, unauthorized data transfer, etc.) are detected at the silicon level, the data flow is hardware-intercepted and held in a \"Catch-and-Release\" buffer until a physical human confirmation is received.

\n\nSpeakers:Mehmet Önder Key,Temel Demir
\n
\nSpeakerBio:  Mehmet Önder Key, Cyber Security Consultant
\n

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.

\n\nSpeakerBio:  Temel Demir
\n

Temel Demir is a cybersecurity researcher and hardware architect specializing in hardware defense, offensive security, and the protection of critical infrastructure. With a core focus on embedded system vulnerabilities and Layer-1/Layer-2 network manipulation, his research involves developing deterministic, hardware-enforced frameworks that bypass traditional software-defined security flaws. Having previously shared security research on global stages, his work bridges the gap between sophisticated threat actor methodologies and immutable physical security barriers.

\n\n\n\'',NULL,1294929),('3_Saturday','11','11:00','11:59','N','Data Duplication Village','LVCCW Level 2 W203 (Data Duplication Village)','\'Poison the Well: RAG Attacks Against the Hacking Community\'s Own Archives\'','\'Omer Farooq\'','Creator Talks_1951af92cffa05b70092cfb6fd6cbcac','\'Title: Poison the Well: RAG Attacks Against the Hacking Community\'s Own Archives
\nTags: Data Duplication Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W203 (Data Duplication Village) - Map
\n
\nDescription:
\n

This presentation demonstrates how archive poisoning attacks compromise Retrieval-Augmented Generation (RAG) systems by embedding malicious instructions inside documents that influence model behavior during retrieval. Using a customized agentic testing workflow, attendees will see how a single poisoned document can manipulate outputs, exfiltrate sensitive information, bias threat intelligence results, and abuse trust relationships across a RAG-powered environment without modifying model weights.

\n\nSpeakerBio:  Omer Farooq
\n

Omer Farooq is a cybersecurity, cloud, and artificial intelligence leader with more than twenty-five years of experience spanning application security, cloud architecture, software engineering, DevSecOps, AI security, and technology innovation. As Founder and Principal Security Consultant at Auxin Security, Omer has advised more than 100 organizations worldwide, including Fortune 500 companies, government agencies, healthcare organizations, and nonprofits. His expertise includes GenAI and LLM security, offensive security assessments, threat modeling, cloud security, DevSecOps transformation, secure software development, and enterprise architecture. Omer is a frequent speaker at industry conferences and events including RSA Conference, BSides DC, AWS events, NAB Show, Microsoft Azure conferences, and numerous cybersecurity forums. His current research focuses on AI security, agentic systems, retrieval-augmented generation security, offensive AI testing, and emerging threats targeting enterprise AI deployments.

\n\n\n\'',NULL,1294930),('4_Sunday','11','11:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'Commit, Push, Compromise: Attacking Modern GitHub Orgs\'','\'Andrew Buchanan,Max CM\'','Creator Talks_a0fbdf51906f805316fd9acde9e2b938','\'Title: Commit, Push, Compromise: Attacking Modern GitHub Orgs
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

GitHub is where identity, automation, and production changes all meet, which makes it a great target. Once an attacker gets in, the distance between read access and shipping malicious code to production is often a lot shorter than teams expect.

\n\n

This talk covers realistic attack paths into GitHub organizations. We start with initial access: device-code phishing and abuse of trusted GitHub Apps like the GitHub CLI. Then we follow the credentials, from long-lived Personal Access Tokens sitting on developer machines to short-lived secrets like GITHUB_TOKEN that leak through logs and artifacts, and show how both enable lateral movement and privilege escalation.

\n\n

Then we get into a technique we call secret stomping. Anyone with write access to a repo can overwrite an Actions secret, including protected environment secrets reviewers assume are safe. Leak the real value first, then overwrite the secret with a payload that keeps the original value intact, and the pipeline stays green while your code runs on the runner. Using the org, repo, and environment scope hierarchy, you can shadow a secret in one repo without touching others, then delete it and leave nothing behind at the org level.

\n\n

We close on the defensive side with detection strategies and response playbooks built around the signals that matter, plus how to get coverage into the places GitHub is hardest to watch. Blue teams leave with a checklist for locking down identities, tokens, integrations, and workflows. Red teams leave with a map of where GitHub controls break in practice.

\n\n

After the talk we\'re running a hands-on workshop in a private GitHub org built for this, focused on secret stomping. You\'ll leak a secret, stomp it with a payload that keeps the pipeline green, and use scope shadowing to exploit your way onto a sensitive runner without tripping the obvious alarms. Bring a laptop.

\n\nSpeakers:Andrew Buchanan,Max CM
\n
\nSpeakerBio:  Andrew Buchanan
\n

Andrew Buchanan is a Senior Red Team Operator with over six years of offensive security experience spanning adversary simulation, penetration testing, and real-world attack execution.

\n\n

Andrew has spent years conducting advanced red team engagements and security assessments across highly complex enterprise environments at one of Canada\'s largest financial institutions.

\n\n

Andrew specializes in initial access and social engineering, having designed and delivered numerous campaigns that closely mirror real-world threat actor tradecraft. His work spans offensive operations across on-premises, cloud, and hybrid environments, with a particular focus on cloud attack surfaces, execution chains, and targeted phishing and pretexting campaigns.

\n\nSpeakerBio:  Max CM
\n

Max leads offensive security at Figment and brings over a decade of experience spanning national security, security research, and blockchain security. He has published multiple CVEs and conducts research focused on CI/CD pipeline security, threat modeling, secure key management, and practical security controls for high-risk systems.

\n\n\n\'',NULL,1294931),('2_Friday','11','11:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Trusted Launcher, Untrusted Code: Weaponizing AppLaunch.exe to bypass SmartScreen and AppLocker\'','\'Nathan Sawyer\'','Creator Talks_addefb8143c74bc7fa02e2fe74fc18cd','\'Title: Trusted Launcher, Untrusted Code: Weaponizing AppLaunch.exe to bypass SmartScreen and AppLocker
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

AppLocker, SmartScreen, and Windows Defender Application Control (WDAC) are the standards for securing enterprise endpoints through application whitelisting. A little-known Microsoft tool, AppLaunch, which has little to no research done, can be abused to bypass these common defenses to achieve initial access and persistence.

\n\n

This talk will present a new ClickOnce deployment method using partial trust apps that launch from AppLaunch, a signed Microsoft executable that launches partial trust ClickOnce apps. This technique functions using unsigned code within default AppLocker environments with DLL signing enabled. This presentation will take a dive into exploiting and describing this novel technique.

\n\n

This presentation also includes multiple novel techniques used to break out of a .NET CAS (Code Access Security) sandbox. To showcase real-world exploitability, multiple demonstrations and techniques will be displayed. This talk will explore the faulty trust model that enables a new initial access and LOLBAS (Living off the Land Binaries and Scripts) method.

\n\n

A tool is provided to assist in the creation of deployments that abuse this new method. Furthermore, I will cover the IOC\'s left behind, and how to block and detect this attack.

\n\nSpeakerBio:  Nathan Sawyer, Independent Researcher
\n

Nathan Sawyer is a junior studying Cybersecurity at the University of Idaho. He has obtained HTB CDSA and CPTS. He enjoys skiing, snowboarding, hockey, and lacrosse.

\n\n\n\'',NULL,1294932),('2_Friday','11','11:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'COM Hijacking Voodoo: Tradecraft, Detection Blind Spots, and the COM-Hunter\'','\'Nikos \"nickvourd\" Vourdas\'','Creator Talks_1ecff6607834f06dbe00003040adaebb','\'Title: COM Hijacking Voodoo: Tradecraft, Detection Blind Spots, and the COM-Hunter
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

Component Object Model (COM) is one of the most pervasive yet overlooked subsystems in Windows. Thousands of applications rely on COM objects for functionality, but the underlying registration mechanism creates opportunities for attackers to abuse the Windows registry to achieve stealthy persistence and code execution. Despite being used in real-world intrusions, COM hijacking remains under-documented and poorly understood by many defenders.

\n\n

This talk explores the internals of COM registration and activation and demonstrates how attackers abuse registry-based class registrations, InprocServer32 entries, and per-user overrides to hijack legitimate COM objects. We will analyze common hijacking patterns, explain why many of them evade traditional detection logic, and highlight the operational advantages they offer during post-exploitation and persistence phases.

\n\n

To help security professionals systematically identify these opportunities, this presentation introduces COM-Hunter, a research tool designed to enumerate and analyze hijackable COM objects across Windows systems. COM-Hunter maps CLSID registrations, identifies missing or user-overridable components, and highlights potential hijacking vectors that can be leveraged during red team engagements or security research.

\n\n

Through practical demonstrations, we will show how COM-Hunter can be used to uncover previously overlooked hijack paths and how red teamers can turn these findings into reliable persistence mechanisms. The talk also discusses defensive considerations, including detection strategies, telemetry sources, and ways organizations can reduce the attack surface created by vulnerable COM registrations.

\n\n

Attendees will leave with a deeper understanding of COM hijacking internals, practical offensive techniques, and a methodology for discovering new hijack opportunities in modern Windows environments.

\n\nSpeakerBio:  Nikos \"nickvourd\" Vourdas, EY
\n

Nikos Vourdas, also known as nickvourd or NCV, is a Senior Offensive Security Consultant based in the US. With over five years of professional experience, he has actively participated in various global Tiber-EU and iCAST Red Teaming engagements. Nikos has conducted full Red Teaming operations to major clients across retail, banking, shipping, construction industries. He holds OSCE3, OSCP, OSWP, CRTL, CRTO and OASP certifications. Also, he has previously presented at DEF CON, DevSecCon, and various BSides events around the world. Nikos loves contributing to open-source projects and always starts his day at 05:00 AM with a refreshing jog while listening to French rap music.

\n\n\n\'',NULL,1294933),('2_Friday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Post-Exploitation of the Desktop with JS-Tap\'','\'Drew Kirkpatrick\'','Creator Talks_32da741f32a3d6b9db8450af0e25f33a','\'Title: Post-Exploitation of the Desktop with JS-Tap
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

JS-Tap v3 moves beyond exploiting web applications to targeting the endpoint itself. JavaScript is used heavily on desktops and in this hands-on tactic you\'ll deploy three JS-Tap implant types against your own machine. Start by installing a malicious browser extension that harvests sessions from every site you visit and lets you inject payloads into specific apps on command. We’ll then rebuild the browser extension implant with optional (and less stealthy) features that allow jumping from the browser to the operating system for filesystem/shell access.

\n\n

Next we\'ll patch a local Electron app to get screenshots, keylogging, network interception, and filesystem/shell access. Then we\'ll instrument a Node.js tool with a single environment variable to intercept its network traffic, capture keystrokes, and get filesystem/shell access.

\n\n

We\'ll use Docker containers to simulate an internal network with a web application your browser can\'t reach directly. You\'ll use the JS-Tap Conductor to clone captured sessions and pivot through an implant to access it, demonstrating the full attack chain from session theft to authenticated access on an internal network. Participants will run JS-Tap locally on their own laptops. Bring a machine with Chrome or Chromium, Firefox (for JS-Tap Conductor), a Node.js app (Gemini CLI, Claude Code, etc.), Docker, and at least one Electron app installed (VS Code or Signal Desktop work well as targets). Setup instructions will be shared in advance.

\n\n

You\'ll leave with firsthand experience operating all three beacon types.

\n\nSpeakerBio:  Drew Kirkpatrick
\n

Drew has 25 years of experience designing and building complex systems, including application security, network policy management, machine learning, and transit and aerospace systems. These days he works to improve Information Security by applying penetration testing and computer science to assess the security posture of TrustedSec clients. Before joining TrustedSec, he was a Security Researcher at NopSec and Secure Decisions as well as a Senior Computer Scientist for the U.S. Navy.

\n\n

Offensive Security Certified Professional (OSCP)\nGIAC Web Application Penetration Tester (GWAPT)\nGIAC Mobile Device Security Analyst (GMOB)\nM.S. Computer Science – Florida Institute of Technology\nM.S. Computer Information Systems – Florida Institute of Technology\nB.A. Psychology/Economics – St. Mary’s College of Maryland

\n\n\n\'',NULL,1294934),('2_Friday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Post-Exploitation of the Desktop with JS-Tap\'','\'Drew Kirkpatrick\'','Creator Talks_32da741f32a3d6b9db8450af0e25f33a','\'\'',NULL,1294935),('2_Friday','12','12:00','12:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'macOS Doesn’t Get Malware…Until It Does\'','\'Zoziel Freire\'','Creator Talks_36cce4f56003d843489bb9657ca71aea','\'Title: macOS Doesn’t Get Malware…Until It Does
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\nAbstract:
\n\n

macOS has long been perceived as a low-risk platform, often treated as a secondary concern compared to Windows and Linux. That assumption no longer holds. As MacBooks become increasingly common in corporate environments, adversaries have followed, turning macOS into a viable and attractive target for real-world attacks.

\n\n

This talk presents a practical, research-driven analysis of the recent evolution of macOS malware. Through hands-on experiments and real techniques, it explores how modern threats achieve execution, fileless operation, persistence, and evasion by abusing native macOS components. The presentation also evaluates how widely adopted to macOS security tools respond, and in many cases fail, to detect these behaviors.

\n\n

By walking through the attacker’s mindset and development process, this session aims to expose a growing blind spot in enterprise security and challenge the outdated belief that “macOS doesn’t get malware.”

\n\n

Description:

\n\n

As organizations continue to expand their macOS footprint, security strategies often lag behind. Many defensive teams remain heavily focused on Windows and Linux, leaving macOS environments under-monitored, under-tested, and misunderstood.

\n\n

In this talk, I will share my journey researching and developing macOS malware from an adversarial perspective.

\n\n

The session focuses on how attackers leverage legitimate macOS mechanisms to achieve:

\n\n
    \n
  • Initial execution and in-memory (fileless) techniques
  • \n
  • Persistence through native system components
  • \n
  • Evasion of endpoint security and detection tools
  • \n
\n\n

Each technique is demonstrated using real experiments, with analysis of macOS internals and the behavior of commonly deployed security solutions. Rather than theoretical concepts, the talk emphasizes how these attacks work in practice, and why many defenses fail to stop them.

\n\n

The presentation also addresses a persistent myth, especially common in the Brazilian security community, that macOS is inherently safer or “immune” to malware. By examining real attack paths and defensive gaps, the session highlights the urgent need for improved detection strategies, visibility, and threat modeling on macOS.

\n\n

Attendees will learn:

\n\n
    \n
  • How modern malware abuses internal macOS mechanisms
  • \n
  • Real-world persistence techniques observed in active threats
  • \n
  • How security tools react or fail, when faced with these attacks
  • \n
  • Practical Red Team techniques to identify weaknesses and evaluate detection capabilities
  • \n
  • Practical mitigation strategies to reduce exposure and improve detection
  • \n
\n\n

This talk is intended for defenders, red teamers, malware researchers, and anyone interested in understanding how adversaries are actively adapting to the macOS ecosystem.

\n\n

About events where I\'ve spoken:

\n\n

Analyzing malicious PDFs - ConfraSec 2019\nReconnaissance vs Vulnerability Analysis - OWASP-Vitoria 2019\nRed Team X Blue Team - OWASP Latam 2020\nMaldocs: an analysis of malicious documents - Bsides Vitoria 2022\nLockBit and its tricks - Bsides Vitoria 2023\nLockBit and its tricks - Bsides São Paulo 2023\nLockBit and its tricks - HackBahia 2023\nRansomware: No one can stop this naughty baby - Bsides Vitoria 2024\nRansomware: No one can stop this naughty baby - Bsides São Pauço 2024\nRansomware: No one can stop this naughty baby - CajuSEC 2024\nFrom Zero to Ransomware for MacOS - HackBahia 2024\nRansomware vs EDR: Inside the Attacker\'s Mind- BHack Conference 2024\nRansomware vs EDR: Inside the Attacker\'s Mind - Bsides Rio de Janeiro 2025\nRansomware vs EDR: Inside the Attacker\'s Mind - Bsides São Paulo 2025\nRansomware vs EDR: Inside the Attacker\'s Mind - Bsides Vitoria 2025\nRansomware vs EDR: Inside the Attacker\'s Mind - CajuSEC 2025\nRansomware vs EDR: Inside the Attacker\'s Mind - Bsides Las Vegas (backup speaker)\nRansomware vs EDR: Inside the Attacker\'s Mind - Red Team Village - DEFCON 2025\nRansomware vs EDR: Inside the Attacker\'s Mind - BxSec - 2025 \nRansomware vs EDR: Inside the Attacker\'s Mind - Malwee Cyber Security Event\nRansomware vs EDR: Inside the Attacker\'s Mind - Online - BMW Group\nMacOS Malwares: Breaking Barriers - BHack Conference 2025\nRansomware vs EDR: Inside the Attacker\'s Mind - 307 Security Conference\nMacOS Malwares: Breaking Barriers - Ox3 Hacker Conference 2026\nRansomware vs EDR: Inside the Attacker\'s Mind - Red Team Village Overflow (Online) - DEFCON 2026

\n\nSpeakerBio:  Zoziel Freire
\n

I have a degree in Information Systems and a postgraduate degree in Forensic Computing. With over 16 years of experience in the information technology sector, I have had the opportunity to provide services to several companies across various segments in Brazil and other countries.

\n\n

Throughout my career, I have acquired solid experience in Incident Response, Forensic Analysis, Threat Hunting, Pentester, Malware Analysis and Developer, and Reverse Engineering. I have also worked on Ransomware incidents, both in Brazil and in other countries.

\n\n

I have actively contributed to the information security community, participating in Brazilian events. Sometimes I spend time bypassing EDR and AntiVirus, and testing operating system gaps. I am passionate about music, especially guitar and piano, and I am a fan of Chaves and Chapolin.

\n\n

BSides Las Vegas – US – 2025 (Backup Speaker) – Ransomware vs EDR: Inside the Attacker\'s Mind\nRed Team Village @ DEF CON – Las Vegas, US – 2025 – Ransomware vs EDR: Inside the Attacker\'s Mind\nBMW Group – Online – 2025 – Ransomware vs EDR: Inside the Attacker\'s Mind\nRed Team Village Overflow @ DEF CON – Online – 2026 – Ransomware vs EDR: Inside the Attacker\'s Mind

\n\n\n\'',NULL,1294936),('2_Friday','10','10:00','10:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5','\'The Entropy Illusion: High-Speed Cracking on a Budget\'','\'Chris Claunch\'','Creator Talks_9a850bff975735ab6a9a84c97fa7754c','\'Title: The Entropy Illusion: High-Speed Cracking on a Budget
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5 - Map
\n
\nDescription:
\n

As modern password policies mandate 14+ characters, defenders have developed a false sense of security while red teams have entered a costly hardware arms race. But length is not the same as entropy. As policies grow stricter, human behavior becomes more predictable.

\n\n

This session will demonstrate approaches focusing on high yielding results within a limited testing time frame and budget. We will explore tactics for leveraging custom probability masks, dictionary slicing and exploiting human predictability to prove brains still win over GPU\'s.

\n\nSpeakerBio:  Chris Claunch
\n

CMIYC competitor (Team Cynosure Prime)\n10+ years Red Teaming

\n\n\n\'',NULL,1294937),('2_Friday','12','12:00','12:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'BloodHound OpenGraph Crash Course\'','\'JD D\'','Creator Talks_a472bba8d32f652d67c1d3c303f35627','\'Title: BloodHound OpenGraph Crash Course
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

In this session, attendees will learn how to design data models and build extensions for BloodHound OpenGraph.

\n\n

After a presentation where I will go over the core concepts & components of BloodHound OpenGraph and the thought process behind BloodHound data modeling, attendees will design a model and build an extension from scratch based on a provided dataset.

\n\n

I you like to tinker with BloodHound and are curious about the new OpenGraph features, this session is for you...

\n\n

Note: Bring your own laptop with BloodHound Community Edition installed

\n\nSpeakerBio:  JD D
\n

WHOAMI

\n\n\n\'',NULL,1294938),('2_Friday','14','14:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Social Engineering With Reel\'','\'James Williams\'','Creator Talks_8f56327399f8906e2323cf8e90dc44f2','\'Title: Social Engineering With Reel
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\n

Reel is a modern social engineering framework, developed for use by the TrustedSec Targeted Ops team. It supports phishing campaigns, proxying captured credentials to other sites, device code phishing, dynamic SMS and voice campaigns (via integration with AWS). This session will show the attendees how deploy and configure reel, as well as how to craft advanced SE campaigns using the reel workflow system and show how custom plugins can be developed.

\n\nSpeakerBio:  James Williams
\n

James is a senior consultant on the Targeted Operations team at TrustedSec. He has around 10 years experience in cyber security, including penetration testing and red team roles. In his spare time, James enjoys running over mountains (it’s more fun than you’d think) and picking locks.

\n\n\n\'',NULL,1294939),('2_Friday','15','14:00','15:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Social Engineering With Reel\'','\'James Williams\'','Creator Talks_8f56327399f8906e2323cf8e90dc44f2','\'\'',NULL,1294940),('4_Sunday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Evil Is Always a Bad Stylist: .NET Obfuscation with Roslyn\'','\'Alexander Rodchenko,Ashley Hiram Muñoz,Eduardo Chavarro Ovalle\'','Creator Talks_f9f7eff39bfa813d5d5c3520255aafda','\'Title: Evil Is Always a Bad Stylist: .NET Obfuscation with Roslyn
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\n

Modern endpoint defenses increasingly fingerprint .NET tools not only by strings and imports, but by structure: control flow, call graphs, and overall execution “workflows.” Traditional IL obfuscation can hide obvious indicators, yet often produces highly regular flattened patterns that are easy to flag on their own.

\n\n

This talk presents a Roslyn-based, source-to-source obfuscator for C# that rewrites an entire project before compilation. Using the official compiler APIs, it transforms the code’s syntax and semantic structure, reshapes control/data flow, and then recompiles the result - while keeping the program’s observable behavior intact. The output tends to look complex but “natural,” diverging both from the original tool and from the telltale patterns created by many IL-level obfuscators.

\n\n

I will walk through the pipeline, show how surprisingly little code is needed to build these transformations on Roslyn, and discuss what this means for EDR, sandboxing, and ML detections that rely on graph and workflow analysis of .NET binaries.

\n\n

So, anyway, on moment of submitting original Seatbelt tool (obfuscated by source) have 10/73 security vendors flagged this file as malicious (can be better) https://www.virustotal.com/gui/file/ec2dcecb927874d41b051633135c8a594abb40d03f6836a548b40963bf330c86/detection/f-ec2dcecb927874d41b051633135c8a594abb40d03f6836a548b40963bf330c86-1764839678

\n\n

My project https://github.com/gam4er/Loaders differs from more well known https://github.com/sadreck/Codecepticon by implementing semantic structure obfuscation.

\n\n

My point of view (sa a SOC analyst, blue teamer) on \"how to hide mytool from AV\" problem is: if you have a code - OBFUSCATE YOUR CODE. Stop modifying binaries

\n\nSpeakers:Alexander Rodchenko,Ashley Hiram Muñoz,Eduardo Chavarro Ovalle
\n
\nSpeakerBio:  Alexander Rodchenko
\n

Rodchenko Alexander is a Senior SOC Analyst at the SOC Security Research Group at Kaspersky. He began his career at OJSC Rosneft, focusing on industrial safety, troubleshooting, and audits. Currently, he investigates industry events and trends with the primary goal of integrating these insights into monitoring and threat hunting practices. Leveraging his extensive expertise, Alexander advises customers and threat detection/hunting teams on the optimal response to emerging threats and trends. In addition to speaking at Positive Hack Days (twice) and BSides Zurich 2023, he has also been a speaker at CodeBlue 2024 and BlackHat MEA 2024.

\n\nSpeakerBio:  Ashley Hiram Muñoz, Kaspersky - Incident Response Specialist
\n

I currently work as an Incident Response Specialist on Kaspersky\'s Global Emergency Response Team (GERT). I live in Mexico and have over seven years of experience in Incident Response, Digital Forensics, Malware Analysis, and Reverse Engineering. Before joining DFIR, I worked for two years as a Penetration Tester.

\n\n

I have collaborated on various Threat Hunting and Threat Intelligence projects.

\n\n

Additionally, I have been a speaker at international events such as DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, HackGDL, BugCON, Pwnterrey, and others. I currently teach the Digital Forensics, Malware Analysis, and Incident Response modules in an information security diploma program at UNAM (Universidad Nacional Autónoma de México).

\n\n

Certifications: GREM, GCFA, GCFR, eCTHP, CHFI.

\n\n

--

\n\n

Actualmente me desempeño como Incident Response Specialist en el Global Emergency Response Team (GERT) de Kaspersky, cuento con +6 años de experiencia realizando Respuesta a Incidentes, Análisis Forense Digital, Análisis de Malware y Reversing; previo a dedicarme a DFIR laboré 2 años como Penetration Tester.

\n\n

He colaborado en distintos proyectos de Threat Hunting y Threat Intelligence.

\n\n

Adicionalmente, he sido ponente en eventos internacionales como DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, BugCON, etc.

\n\n

Actualmente soy profesor de los módulos de Análisis Forense, Análisis de Malware y Respuesta a Incidentes en un diplomado de seguridad de la información de la UNAM.

\n\n

Certificaciones: GREM, GCFA, eCTHP, CHFI.

\n\nSpeakerBio:  Eduardo Chavarro Ovalle, DFIR Group Manager at Kaspersky - GERT
\n

Eduardo Chavarro Ovalle, DFIR Group Manager for Americas, member of Kaspersky GERT Team. Student of DBA in ML and AI and MSc in Cybersecurity with more than 20 years of experience in cybersecurity, DFIR, eDiscovery, and threat analysis. GCIH | GRID | GCFA | CISM | CHFI | CPTE | SFCP | ITIL.

\n\n\n\'',NULL,1294941),('4_Sunday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Evil Is Always a Bad Stylist: .NET Obfuscation with Roslyn\'','\'Alexander Rodchenko,Ashley Hiram Muñoz,Eduardo Chavarro Ovalle\'','Creator Talks_f9f7eff39bfa813d5d5c3520255aafda','\'\'',NULL,1294942),('2_Friday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Web Hacking Bootcamp\'','\'Emma Latuszek\'','Creator Talks_5332e64bc3953a02c0fba431f73c0b78','\'Title: Web Hacking Bootcamp
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\n

A beginner to intermediate hands-on web hacking bootcamp originally created for internal up-skilling. Hands on with both specific to module PortSwigger labs and a self-hosted Juice Shop instance running on Docker Desktop.

\n\n

Presentation Outline:\n- Web Technology Foundations (Pre-requisite\'s on web-specific languages, encoding, HTTP request structure, some \'Hacker Mindset\')\n- Web Hacking Foundations (What is an application proxy/setting up Burp Suite, \'auth\' & \'auth\', sessions & tokens, CORS, vocabvocab)\n- Web Hacking Modules (file upload attacks, SQL injection, JWT attacks, XSS, CSRF, XXE & business logic vulnerabilities)

\n\n

After each major section, and in-between some of the hacking modules, we return to a self-hosted OWASP Juice Shop instance to try out new techniques learned. Each hacking module will end with related PortSwigger Web Security Academy labs which attendees will work through on their own with instructor support. (think: I walk around and give nudges as needed.)

\n\n

All material being self-or-Portswigger hosted means that even if the time slot doesn\'t include sufficient lab time, attendees will be able to take what they heard and work on labs laid out or practice with Juice Shop on their own time. The main objective is to give attendees a minimum understanding of web tech & attacks that they feel empowered to dive in deeper from that point.

\n\nSpeakerBio:  Emma Latuszek
\n

Emma \'vhulf\' Latuszek is an application developer turned breaker, who started her hacking career nearly a decade ago. She is an OSWE holder, Cyphercon safe-cracker and a verified cyborg (barely... but thanks DangerousThings!). Vhulf is esoteric and unusual, with a deep passion for music, hacking and high-energy instruction.

\n\n\n\'',NULL,1294943),('2_Friday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Web Hacking Bootcamp\'','\'Emma Latuszek\'','Creator Talks_5332e64bc3953a02c0fba431f73c0b78','\'\'',NULL,1294944),('2_Friday','14','14:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Cloud-Native C2: Weaponizing Trusted Infrastructure for Initial Access\'','\'Dhiraj Mishra\'','Creator Talks_ea8dc3b3b9d7752b0ae681e5f82cb689','\'Title: Cloud-Native C2: Weaponizing Trusted Infrastructure for Initial Access
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

Traditional command and control infrastructure faces constant detection pressure from network defenders. This research presents two novel proof-of-concept frameworks that demonstrate how seemingly benign cloud services can be weaponized for covert operations. MeetC2 leverages Google Calendar API to transform calendar events into a bidirectional C2 channel, while XRayC2 repurposes AWS X-Ray\'s distributed tracing service for command execution and data exfiltration.

\n\n

Both frameworks exploit fundamental assumptions about trusted services: calendar synchronization traffic appears as routine business operations, while X-Ray traces blend seamlessly with legitimate application monitoring. Our implementations showcase practical techniques including command encoding in calendar event metadata, response embedding in trace annotations, and beacon patterns that mimic normal service behavior. The frameworks support cross-platform implants with minimal footprint, requiring only API credentials rather than traditional malware persistence.

\n\n

I will demonstrate how these channels bypass traditional security controls, as encrypted HTTPS traffic to Google and AWS endpoints rarely triggers alerts. The research reveals critical blind spots in cloud security monitoring and provides actionable detection strategies, including API usage anomalies, unusual trace patterns, and calendar event behavioral analysis. This work aims to help defenders understand emerging cloud-native threats and implement appropriate monitoring for their cloud environments.

\n\n

As organizations increasingly adopt cloud services, attackers have evolved their tactics to abuse these trusted platforms for malicious purposes. Cloud service APIs present an attractive option for establishing command and control infrastructure because they offer high availability, encrypted communications by default, and traffic that blends with legitimate business operations. This research explores how adversaries can weaponize standard cloud APIs to create sophisticated C2 channels that circumvent traditional security controls.

\n\n

This research presents two functional C2 frameworks for initial access that abuse legitimate cloud APIs: MeetC2 leveraging Google Calendar for command and control, and XRayC2 weaponizing AWS X-Ray distributed tracing.

\n\nSpeakerBio:  Dhiraj Mishra
\n

An active speaker who has discovered multiple zero-days in modern web browsers and an open-source contributor. He is a trainer at Blackhat, BruCON, 44CON and presented in conferences such as Ekoparty, NorthSec, Hacktivity, PHDays, Hack in Paris & HITB. In his free time, he blogs at www.inputzero.io/www.fuzzing.at and tweets on @RandomDhiraj.

\n\n\n\'',NULL,1294945),('2_Friday','15','14:00','15:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Cloud-Native C2: Weaponizing Trusted Infrastructure for Initial Access\'','\'Dhiraj Mishra\'','Creator Talks_ea8dc3b3b9d7752b0ae681e5f82cb689','\'\'',NULL,1294946),('3_Saturday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Ouroboros Attack! Recursive AI-Assisted 0-Day Hunting\'','\'Mehmet Önder Key,Temel Demir\'','Creator Talks_d530b9ec6347ad1dc185c836f47718a2','\'Title: Ouroboros Attack! Recursive AI-Assisted 0-Day Hunting
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

This session presents a practical workflow for discovering and building real zero-day vulnerabilities using a recursive AI-assisted approach.\nThe first part of the talk examines a logic flaw identified in the rendering mechanism of a large language model environment. Through structured interaction and controlled prompt chaining, inconsistencies in rendering state handling were exposed. By refining responses and feeding outputs back into follow-up prompts, the system revealed weaknesses in its own internal logic.\nUnder specific crafted conditions, this behavior demonstrated a scenario that could lead to sensitive data exposure, including API-related material.

\n\n

The second part of the session applies the same structured workflow to traditional web applications: SquirrelMail , ISPConfig , DokuWiki.\nUsing recursive hypothesis refinement, attack surface expansion, and manual validation, multiple high and critical impact zero-day vulnerabilities were identified and confirmed with working proof-of-concept exploit chains.

\n\n

These vulnerabilities have not yet been publicly disclosed. The conference presentation will include their first public technical analysis and exploit breakdown.

\n\n

The focus of the talk is methodology:\nHow to structure AI interaction for vulnerability research\nHow recursive prompt chaining expands edge-case discovery\nHow model output can be converted into real exploit paths\nWhere manual validation remains necessary

\n\n

This is a technical session centered on real exploit development and practical offensive research.

\n\nSpeakers:Mehmet Önder Key,Temel Demir
\n
\nSpeakerBio:  Mehmet Önder Key, Cyber Security Consultant
\n

Önder Key is a cybersecurity consultant specializing in critical infrastructure security, zero-day vulnerability analysis, and offensive security. He has advised organizations in high-security sectors such as defense, aerospace, and finance, with hands-on experience in both red teaming and strategic security engineering. His work has been featured across numerous countries and platforms, contributing to the discovery of systemic vulnerabilities. Currently, he provides consultancy to TurkNet and continues to advance the global offensive security ecosystem by challenging traditional approaches to cybersecurity.

\n\nSpeakerBio:  Temel Demir
\n

Temel Demir is a cybersecurity researcher and hardware architect specializing in hardware defense, offensive security, and the protection of critical infrastructure. With a core focus on embedded system vulnerabilities and Layer-1/Layer-2 network manipulation, his research involves developing deterministic, hardware-enforced frameworks that bypass traditional software-defined security flaws. Having previously shared security research on global stages, his work bridges the gap between sophisticated threat actor methodologies and immutable physical security barriers.

\n\n\n\'',NULL,1294947),('3_Saturday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Ouroboros Attack! Recursive AI-Assisted 0-Day Hunting\'','\'Mehmet Önder Key,Temel Demir\'','Creator Talks_d530b9ec6347ad1dc185c836f47718a2','\'\'',NULL,1294948),('2_Friday','10','10:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area','\'From Kiosk to Domain Compromise: Learning to Walk Up and Take it All\'','\'Ezra Woods,Mike Manrod,Spencer Alessi\'','Creator Talks_c61e09948b8509aa875d418ff6cc1b2b','\'Title: From Kiosk to Domain Compromise: Learning to Walk Up and Take it All
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area - Map
\n
\nDescription:
\n

Kiosks are everywhere. Their prevalence in our society has exploded, with devices such as fast-food ordering, signage, ticketing and check-in, print/ship/office, library, point-of-sale, and more - all around us.

\n\n

How secure are they though? Are they being adequately tested? We all learned on July 19, 2024, when a multitude of the signs and kiosks around us went BSOD that a large number of these kiosks – from airports to ATMs – are running on Windows. We need to be asking questions like, are they joined to a domain, what is network adjacent, and how could these systems lead to a serious attack path?

\n\n

In this workshop we will walk through how to hack and secure kiosks in a four-part workshop, which will move from initial compromise to lateral movement and domain compromise, concluding with some defensive recommendations to prevent ‘kiosk to domain takeover’ scenarios.

\n\nSpeakers:Ezra Woods,Mike Manrod,Spencer Alessi
\n
\nSpeakerBio:  Ezra Woods
\n

Avid security researcher currently working as an Information Security Engineer with Grand Canyon Education

\n\nSpeakerBio:  Mike Manrod
\n

Mike, AKA, CroodSolutions, presently serves as CISO for Grand Canyon Education, teaches Malware Analysis for GCU, and helps lead the Threat Intelligence Support Unit.

\n\n

In addition to work on BypassIT, AutoPwnKey, BYOEDR, and BeaconatorC2 with Ezra Woods and other contributors, Mike has served as a threat prevention engineer for Check Point along with various other roles.

\n\n

He is also a co-author/contributor for the joint book project, Understanding New Security Threats published by Routledge in 2019, along with multiple articles/whitepapers. When not working, he spends time playing video games or working on cars with his kids.

\n\nSpeakerBio:  Spencer Alessi
\n

Spencer is a passionate security practitioner, with the heart of a defender and spirit of a hacker. Spencer\'s background is in IT and Systems Administration prior to making the transition to security. He leans on these crucial technical skills to help enable clients and security programs to build defensible, vigilant, and practical security programs. Most of Spencer\'s current efforts are focused on understanding threats, techniques, and methods and then implementing them through technical assessments and analysis. Spencer is Co-Host of The Cyber Threat Perspective podcast and regularly creates blogs, videos and other content. In November 2025 Spencer was awarded Microsoft MVP in Security - Identity & Access.

\n\n\n\'',NULL,1294949),('2_Friday','11','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area','\'From Kiosk to Domain Compromise: Learning to Walk Up and Take it All\'','\'Ezra Woods,Mike Manrod,Spencer Alessi\'','Creator Talks_c61e09948b8509aa875d418ff6cc1b2b','\'\'',NULL,1294950),('2_Friday','12','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area','\'From Kiosk to Domain Compromise: Learning to Walk Up and Take it All\'','\'Ezra Woods,Mike Manrod,Spencer Alessi\'','Creator Talks_c61e09948b8509aa875d418ff6cc1b2b','\'\'',NULL,1294951),('2_Friday','13','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area','\'From Kiosk to Domain Compromise: Learning to Walk Up and Take it All\'','\'Ezra Woods,Mike Manrod,Spencer Alessi\'','Creator Talks_c61e09948b8509aa875d418ff6cc1b2b','\'\'',NULL,1294952),('2_Friday','14','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area','\'From Kiosk to Domain Compromise: Learning to Walk Up and Take it All\'','\'Ezra Woods,Mike Manrod,Spencer Alessi\'','Creator Talks_c61e09948b8509aa875d418ff6cc1b2b','\'\'',NULL,1294953),('2_Friday','15','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area','\'From Kiosk to Domain Compromise: Learning to Walk Up and Take it All\'','\'Ezra Woods,Mike Manrod,Spencer Alessi\'','Creator Talks_c61e09948b8509aa875d418ff6cc1b2b','\'\'',NULL,1294954),('2_Friday','16','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area','\'From Kiosk to Domain Compromise: Learning to Walk Up and Take it All\'','\'Ezra Woods,Mike Manrod,Spencer Alessi\'','Creator Talks_c61e09948b8509aa875d418ff6cc1b2b','\'\'',NULL,1294955),('2_Friday','17','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Kiosk Area','\'From Kiosk to Domain Compromise: Learning to Walk Up and Take it All\'','\'Ezra Woods,Mike Manrod,Spencer Alessi\'','Creator Talks_c61e09948b8509aa875d418ff6cc1b2b','\'\'',NULL,1294956),('4_Sunday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Do you feel in control? Analysis of AWS CloudControl API as an attack tool\'','\'Bleon \"gl4ssesbo1\" Proko\'','Creator Talks_479fe0d0ff09b0d885a9074cd7595106','\'Title: Do you feel in control? Analysis of AWS CloudControl API as an attack tool
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

\"Identity is the new perimeter\" gets thrown around a lot in security discussions, fo a good reason. With the right privileges, cloud resources can be managed through APIs. Each provider has their own way of handling API access on resources. If your identity has the right permissions for a specific API call, you can execute that action.

\n\n

The thing is, it\'s hard to remember every single API call you need to get specific information or access certain resources. AWS recognized this problem and created the AWS CloudControl API, a unified API that groups different resources together so you can create, update, delete, or retrieve them in bulk. This makes managing resources much simpler since you don\'t need to know which specific service, API call, or parameters to use.

\n\n

But here\'s the catch: when something is easy for legitimate users, it\'s usually easy for attackers too. There are already tools available to use the AWS CloudControl API to pull resource information, and the technique is gaining attention.

\n\n

But is it actually a good way to do stealthy enumeration? In this article, we examine what the CloudControl API is, how it simplifies resource management, how attackers can weaponize it, its limitations, and detection methods.

\n\nSpeakerBio:  Bleon \"gl4ssesbo1\" Proko
\n

Bleon is an Info-sec passionate about Infrastructure Penetration Testing and Security, including Active Directory, Cloud (AWS, Azure, GCP, Digital Ocean), Hybrid Infrastructures, as well as Defense, Detection and Thread Hunting. He has presented topics related to Cloud Penetration Testing and Security in conferences like BlackHat USA, Europe and Sector, DEF CON, SANS Pentest Hackfest Hollywood and Amsterdam, as well as several BSides on USA and Europe.

\n\n

His research include Nebula, a Cloud Penetration Testing Framework (https://github.com/gl4ssesbo1/Nebula) and other blogs, which you can also find on his blog (blog.pepperclipp.com). He is also the author of YetiHunter, DetentionDodger and Ransomwhen (https://github.com/Permiso-io-tools/[DetentionDodger | YetiHunter | Ransomwhen]).

\n\n

He is also the author of the upcoming book \"Deep Dive into Clouded Waters: An overview in Digital Ocean\'s Pentest and Security\" (https://leanpub.com/deep-dive-into-clouded-waters-an-overview-in-digitaloceans-pentest-and-security)

\n\n\n\'',NULL,1294957),('4_Sunday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Do you feel in control? Analysis of AWS CloudControl API as an attack tool\'','\'Bleon \"gl4ssesbo1\" Proko\'','Creator Talks_479fe0d0ff09b0d885a9074cd7595106','\'\'',NULL,1294958),('3_Saturday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'From Path Traversal to Domain Credentials in 90 Seconds\'','\'Mike Lisi\'','Creator Talks_c60bc9e252db7ae984a2bd292f6a0183','\'Title: From Path Traversal to Domain Credentials in 90 Seconds
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

In this hands-on tactic, attendees will exploit a realistic document management portal to chain path traversal into something far more dangerous. We\'ll demonstrate a complete attack path from initial discovery to domain credentials, then discuss why this works, where you\'ll find it, and how defenders should be looking for it.

\n\n

What You\'ll Do:\nYou\'ll get hands-on access to a vulnerable Windows IIS application and work through the complete exploitation chain. By the end of the session, you\'ll have captured real domain credentials and understand exactly how the attack works at each step.

\n\n

Basic familiarity with web vulnerabilities helpful but not required. We\'ll explain the concepts as we exploit them.

\n\nSpeakerBio:  Mike Lisi
\n

Mike helps organizations identify, prioritize, and eliminate real-world security risks before attackers exploit them. As Founder & CEO of Maltek Solutions, he brings over 15 years of hands-on experience across penetration testing, risk assessments, and cyber capability development.In addition to his consulting leadership, Mike serves as President\nof Red Team Village, a 501(c)(3) nonprofit delivering free offensive security training to a global community. Mike also leads CTF design for NCAE CyberGames, engaging 1,000+ collegiate participants annually.

\n\n\n\'',NULL,1294959),('3_Saturday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'From Path Traversal to Domain Credentials in 90 Seconds\'','\'Mike Lisi\'','Creator Talks_c60bc9e252db7ae984a2bd292f6a0183','\'\'',NULL,1294960),('3_Saturday','14','14:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'BloodBash: Lightweight CLI Python BloodHound Alternative\'','\'Anthony Russell\'','Creator Talks_a91dad47e4043a5ea8925538fda85a89','\'Title: BloodBash: Lightweight CLI Python BloodHound Alternative
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\n

BloodHound is great... until your VM dies under Neo4j load, your login expires mid-exam, or you need hybrid AD + Entra ID insights without spinning up servers. Enter BloodBash: a standalone Python tool that ingests SharpHound (v6+) and AzureHound JSON directly, builds a full NetworkX graph in-memory, and spits out attack paths, misconfigs, and abuse suggestions — all offline, in colorful terminal glory.\nBorn from a real OSCP crisis (BloodHound failed hours before exam start → BloodBash saved the DA path), this \"vibe-coded\" tool now detects shortest paths to high-value targets, ADCS ESC1-8 vulns, RBCD, Kerberoasting, GPO abuses, exposed app secrets/certificates, MFA bypass risks, privileged Entra roles, and unified hybrid attack chains.\nIn this talk, you\'ll see:\nThe OSCP war story that sparked it\nLive demo: Drop SharpHound + AzureHound files → instant colorful output, path visualization, abuse commands\nKey detections walkthrough (on-prem + cloud)\nWhy lightweight CLI > GUI bloat for field ops, labs, and quick checks\nRoadmap: Metasploit integration, more exports, community features\nFull open-source on GitHub (https://github.com/DotNetRussell/BloodBash) — star it, fork it, break it. Attendees walk away with a new go-to tool for AD/hybrid recon.

\n\nSpeakerBio:  Anthony Russell, Cyber Security Software Engineer
\n

Anthony Russell, is a senior cyber security engineer with over 13 years of professional experience building software. He has a focus in information security and has been featured in 2600 magazine, on Hak5 and has spoken at both Defcon and DerbyCon multiple times. Favorite things to discuss are blockchain technology, baking custom IoT devices, and everything infosec. You can see more of Anthony\'s work at SquidHacker.com or Twitter.com/DotNetRussell

\n\n\n\'',NULL,1294961),('3_Saturday','15','14:00','15:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'BloodBash: Lightweight CLI Python BloodHound Alternative\'','\'Anthony Russell\'','Creator Talks_a91dad47e4043a5ea8925538fda85a89','\'\'',NULL,1294962),('4_Sunday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'From Buffer Overflow to Blackout: Chaining Attacks Against Industrial Systems\'','\'Fernando Mengali,Thiago Cunha da Silva\'','Creator Talks_3d97ecd09f5d5416b5743b25c0e2df73','\'Title: From Buffer Overflow to Blackout: Chaining Attacks Against Industrial Systems
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map
\n
\nDescription:
\n

This presentation takes a practical, demo-driven approach to exploitation, demonstrating how a buffer overflow vulnerability can still serve as an entry point to compromise modern industrial infrastructures. The session is approximately 90% hands-on and 10% theoretical.\nThe talk walks through the full attack chain, starting from initial exploitation and progressing to the development and execution of multistage shellcode. This shellcode establishes communication with a remote Command and Control (C2) server, retrieves an additional payload, and executes it directly in memory, bypassing traditional detection mechanisms.\nOnce the environment is compromised, the session demonstrates how an attacker can gain full remote control, enabling command execution, lateral movement, and exfiltration of sensitive data, including critical assets such as licenses and proprietary industrial information.\nThe talk also includes interaction with real-world devices such as RTUs (Remote Terminal Units), showing how malicious actions can directly impact industrial operations. In critical scenarios, this can lead to disruptions in essential services, including failures in energy systems and potential blackouts.\nThe content is based on real-world pentesting experience conducted in an energy sector company in Brazil, providing a practical and applied perspective on risks in ICS/SCADA environments.\nThe goal is to demonstrate how modern attacks combine vulnerabilities with advanced techniques, reinforcing the need for robust security strategies to protect critical infrastructure.

\n\nSpeakers:Fernando Mengali,Thiago Cunha da Silva
\n
\nSpeakerBio:  Fernando Mengali, Information Security Specialist
\n

Cybersecurity researcher focused on Pentesting and AppSec, also serving as a Practical / Hands-on Speaker. He also dedicates part of his research to critical infrastructure security (ICS/SCADA), exploring the intersection between classic vulnerabilities and industrial environments. He has over 18 years of experience in offensive security and practical application exploitation.

\n\n

He has participated in research and development projects focused on vulnerability exploitation and offensive security.

\n\n

Specialized in 0day discovery and exploit development, he has over 135 published CVEs and is ranked in the Top 10 contributors on VulDB https://vuldb.com/users.top.

\n\n

Additionally, he has published multiple exploits and technical papers publicly available https://www.exploit-db.com/?author=12136 and https://packetstorm.news/files/author/8470/1.

\n\n

His work focuses on real-world vulnerability exploitation, including advanced scenarios such as memory corruption, buffer overflows, and complex environments.

\n\n

He is the creator of https://yrprey.com, an educational framework that brings together more than 20 vulnerable applications based on the OWASP Top 10, used for practical training in Application Security and Offensive Security https://owasp.org/www-project-vulnerable-web-application-directory.

\n\n

He is also the driving force behind https://speakfy.io, a project focused on promoting Information Security events globally.

\n\n

Furthermore, he develops application security-oriented tools, such as https://leapfix.co (static code analysis) and https://fitoxs.com, a dynamic application analysis platform powered by artificial intelligence.

\n\nSpeakerBio:  Thiago Cunha da Silva
\n

Thiago Cunha is an offensive security specialist, or as he likes to put it: “professionally paid to break into systems before someone less friendly does.”

\n\n

He currently works as a Red Team and Threat Intelligence Consultant at Banco Carrefour and as an instructor at the Kryfal, teaching future ethical hackers not to click on suspicious links.

\n\n\n\'',NULL,1294963),('4_Sunday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'From Buffer Overflow to Blackout: Chaining Attacks Against Industrial Systems\'','\'Fernando Mengali,Thiago Cunha da Silva\'','Creator Talks_3d97ecd09f5d5416b5743b25c0e2df73','\'\'',NULL,1294964),('3_Saturday','13','13:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'Stop Chasing Domain Admin: Designing Red Team Exercises That Matter\'','\'Billy Giles\'','Creator Talks_3b6a96e9fc1b2864f821e481effb9b7b','\'Title: Stop Chasing Domain Admin: Designing Red Team Exercises That Matter
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

You got domain admin. No alerts fired. The red team “won.” But did the exercise actually test anything that matters?

\n\n

Red team engagements are often evaluated based on familiar outcomes such as full compromise, stealth, or the use of novel techniques. While these may demonstrate operator skill, they frequently fail to answer the question the engagement was meant to address.

\n\n

This session challenges a common industry pattern: optimizing for technical achievement instead of meaningful outcomes. When red teams focus on getting domain admin or remaining undetected as primary goals, exercises often measure attacker creativity rather than organizational resilience.

\n\n

Through a short presentation and an interactive, drop-in workshop, participants will learn how to design red team exercises around clear defensive questions. Attendees will build components of real-world engagements by defining objectives, selecting starting conditions, choosing techniques, and determining meaningful success metrics.

\n\n

The workshop is structured as a series of modular steps, allowing participants to join at any time and engage at their own pace. Whether participants spend five minutes or the full session, they will leave with a practical framework for planning red team operations that produce actionable insight.

\n\n

If you’ve ever seen a red team achieve full compromise and still felt like the exercise didn’t answer the right questions, this session is for you.

\n\n

You will leave with a clearer understanding of what red teaming is supposed to accomplish, and a practical way to design engagements that deliver meaningful results.

\n\nSpeakerBio:  Billy Giles
\n

Billy Giles is an Offensive Security leader and practitioner who specializes in red/purple teaming and network penetration testing. With a deep passion for understanding adversary behaviors, he helps organizations across a multitude of industries assess their security postures, identify and remediate vulnerabilities, and build stronger defenses by thinking like an attacker.

\n\n

Billy is also the creator of Thinking Offensively. Through this project he examines offensive security strategy topics to help cybersecurity leaders anticipate threats and inform decision making, while also providing tools, playbooks, and techniques that red teams can apply directly to their work. His mission is to bridge strategy and execution to help organizations think offensively and stay ahead of evolving threats.

\n\n\n\'',NULL,1294965),('2_Friday','11','11:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5','\'Exploiting Private 5G: Unauthenticated Access to Databases and Control Plane DoS via Fuzzing\'','\'Aumkaareshwar DS\'','Creator Talks_d759b408cebdb4f4dc3b7821343af9c4','\'Title: Exploiting Private 5G: Unauthenticated Access to Databases and Control Plane DoS via Fuzzing
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5 - Map
\n
\nDescription:
\n

Abstract—This presents an exhaustive empirical security\nanalysis of a real-world private 5G network deployment, serving\nas a direct and explicit extension of our preceding research,\n”Security Analysis of a Real-World Private 5G Network Deploy-\nment through Pen Testing and Fuzzing.” While our initial study\nsuccessfully identified control-plane weaknesses and performance\ndegradation via protocol mutation, this continuation focuses\non four critical, highly exploitable attack vectors. Specifically,\nwe detail three severe data-layer attacks stemming from the\nunauthenticated internal network exposure of MongoDB (Port\n27017), Elasticsearch (Port 9200), and Kibana (Port 5601). These\nexposures permitted the complete, unauthorized extraction of\nthe network’s most sensitive cryptographic assets (including\nPermanent Keys and active session keys) and granted adversaries\nunauthorized manipulation of the security monitoring apparatus.\nAdditionally, we introduce a newly discovered, critical Denial\nof Service (DoS) attack targeting the Access and Mobility\nManagement Function (AMF) signaling interface on Port 11000,\nwhich leverages protocol fuzzing to induce memory corruption\nand permanently halt User Equipment (UE) registration. By\nsynthesizing these empirical findings, this report provides a multi-\nlayered analysis of the cascading failures that emerge when\nenterprise IT vulnerabilities intersect with mission-critical 5G\ntelecommunications infrastructure.

\n\nSpeakerBio:  Aumkaareshwar DS
\n

I am a Computer Science graduate student at California State Polytechnic University, Pomona, passionate about cybersecurity, network security, and ethical hacking. Currently, I work as a Research Assistant at PolySec Lab, where I focus on 5G network security, including authentication, subscriber identity protection, and threat mitigation. My research helps enhance mobile security and protect data from cyber threats.

\n\n\n\'',NULL,1294966),('3_Saturday','16','16:00','16:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Control + C = Control Me\'','\'Andrew Griess\'','Creator Talks_882f31ac05ad598de81837bc66bcd0f6','\'Title: Control + C = Control Me
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

Demos (Desktop Only at the moment): https://doctoreww.github.io/EvilFontTool/

\n\n

Tool: https://github.com/DoctorEww/EvilFontTool

\n\n

General:\nWorkshop goes into evil fonts and how to use them in a red team to get free shells, also hints at a tool to make it easier (saving most of the tool stuff for the tactic)

\n\n

Tactic will go into using the tool to create malicious word docs for social engineering / popping a shell.

\n\n

Description:\nFor decades, cybersecurity has taught us to validate what we click, what we download, and what we run. Analysts learn to inspect URLs carefully, read every line, and challenge every prompt or popup that doesn\'t look quite right. But in all this vigilance, we’ve ignored a foundational assumption. We trust our eyes. We trust that what we see is what the system sees.\nThis talk demonstrates why that assumption puts us at risk.

\n\n

In the modern computing stack, very little sits closer to human perception than fonts. They are in browsers, PDFs, document editors, terminals, IDEs, chat apps, and nearly every interface in between. Yet despite their ubiquity, fonts are almost never treated as part of the security boundary. They’re handled as passive design elements, harmless vessels used solely to shape text. Users trust them implicitly. \nThis session introduces a new class of “evil font” attacks. With evil font attacks, red teamers can create situations where a user believes they are copying, clicking, or executing one thing… while the machine processes something entirely different.

\n\n

Evil font attacks don’t depend on JavaScript, macros, or browser exploits. Evil fonts work because there is no reason that a specific letter needs to look the way it does. In other words, the letter “A” only looks like an “A” because that’s how my font drew it. With clever font manipulation a red teamer can make the letter “A” look like any other letter. For example, while a user might see the letter “B” the computer would still see the letter “A” represented by the underlying ASCII hex value. By manipulating fonts, files no longer have a single meaning… They mean one thing to a human reader, and another thing to a computer.

\n\n

Once you realize this trust boundary is broken, there are so many ways to abuse this.

\n\n

During the session, we walk through three attack scenarios usable by red teams; each scenario highlights a different security boundary where fonts exert control.

\n\n

Clipboard deception in modern browsers\nClipboard attacks typically require JavaScript, event hijacking, or social engineering. With evil fonts you can poison a clipboard on webpages without any JavaScript. With evil fonts an attacker can make on-screen text appear safe (e.g., “echo hello world” or “https://google.com”) while the underlying copied text is entirely different. Users believe they are copying the text they verified with their eyes, but instead the clipboard receives text the attacker controls.

\n\n

Document poisoning:\nLike browsers, documents like docx and pdf files can by poisoned by evil fonts. In this portion of the talk, we explore how to poison word and pdf files with malicious links and commands. These documents can be emailed for deception based social engineering. More insidious, evil fonts can be used to poison existing documents within a target such as how to’s and infrastructure guides. By poisoning documents, red teamers can turn simple shared drive access into credentials and shells.

\n\n

AI‑era submission manipulation:\nThe rise of AI‑powered document processing introduces a new frontier for deception. Modern systems summarize text, extract entities, detect sentiment, identify anomalies, and evaluate authenticity. Evil fonts can exploit this by making the text look safe to the computer… but when read by a user, it displays malicious content. This manipulation can skew automated summaries, risk scoring, keyword extraction, plagiarism detection, and content filtering.

\n\n

Please let me know if you have any questions!\nThanks,\nAndrew

\n\nSpeakerBio:  Andrew Griess
\n

Andrew Griess is a Red Teamer at Centene who gets paid to break things and calls it a career. With 3 years of professional red team experience, he’s made it their mission to think like an attacker while not succumbing to the dark side. When not poking holes in things for money, Andrew is deep in security research — chasing the next interesting bug, developing new techniques or going down rabbit holes that started as \"just a quick look.\"

\n\n\n\'',NULL,1294967),('2_Friday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'From Application Telemetry Exposure to Cross-Service Pivoting and Full Azure Tenant Takeover\'','\'Chirag Savla,Raunak \"Trouble1\" Parmar\'','Creator Talks_78116a44a590a77c81e48258150b8057','\'Title: From Application Telemetry Exposure to Cross-Service Pivoting and Full Azure Tenant Takeover
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map
\n
\nDescription:
\n

Cloud-native teams often treat web app \"config leaks,\" verbose telemetry, and CI/CD misconfigurations as separate, low-impact issues. This talk shows how those assumptions break in practice. We present a full kill chain where a single exposed Application Insights key in a front-end patient portal is chained with realistic but common Azure misconfigurations to achieve complete tenant compromise and Global Administrator access.

\n\n

Starting from an exposed Application Insights Instrumentation Key in client-side JavaScript, we demonstrate how an attacker can pivot into the Application Insights query API, mine telemetry for over-privileged SAS URLs, and use those tokens to harvest sensitive data from Blob Storage and Storage Queues. We then show how seemingly innocuous Function App endpoints, intended for document ingestion, can be abused via SSRF and URL-based command injection to access local files and environment variables, recovering additional credentials. Finally, we weaponize misconfigured Azure DevOps pipelines and Library Variable Groups to exfiltrate cloud credentials to a webhook, escalate privileges in Entra ID, and take control of production workloads.

\n\n

Rather than introducing a single novel vulnerability, this session focuses on the combinatorial risk of real-world misconfigurations across Application Insights, Storage, Functions, DevOps, and identity. Attendees will walk away with concrete cloud hunting techniques, a step-by-step attack chain they can reproduce in their own labs, and a prioritized remediation playbook for breaking similar chains in their environments.

\n\nSpeakers:Chirag Savla,Raunak \"Trouble1\" Parmar
\n
\nSpeakerBio:  Chirag Savla
\n

Chirag Savla is a cyber security professional with 10+ years of experience. His areas of interest include penetration testing, red teaming, azure and active directory security, and post-exploitation research. For fun, he enjoys creating open-source tools and exploring new attack methodologies in his leisure. Chirag has worked extensively on Azure, Active Directory attacks and defense, and bypassing detection mechanisms. He is the author of multiple open source tools such as Process Injection, Callidus, and others. He has presented at many conferences and local meetups and has trained people in international conferences like Blackhat, BSides Milano, Wild West Hackin’ Fest, HackSpaceCon and VulnCon.

\n\nSpeakerBio:  Raunak \"Trouble1\" Parmar
\n

Raunak Parmar works as a senior cloud security engineer at White Knight Labs with 6+ years of experience. His areas of interest include web penetration testing, Azure/AWS security, source code review, scripting, and development. He enjoys researching new attack methodologies and creating open-source tools that can be used during cloud red team activities. He has worked extensively on Azure and AWS and is the author of Vajra, AzDevRecon and MsCodePhish. He has spoken at multiple respected security conferences like Black Hat, Defcon, Nullcon, RootCon, HackspaceCon, NorthSec, LeHack , etc and also at local meetups.

\n\n\n\'',NULL,1294968),('2_Friday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'From Application Telemetry Exposure to Cross-Service Pivoting and Full Azure Tenant Takeover\'','\'Chirag Savla,Raunak \"Trouble1\" Parmar\'','Creator Talks_78116a44a590a77c81e48258150b8057','\'\'',NULL,1294969),('3_Saturday','15','15:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Requiem for the Decommissioned: When Dead Hosts Bite Back\'','\'Yekaterina Shevchenko\'','Creator Talks_fe1c823f8dd1453d774bdeff17c38b2b','\'Title: Requiem for the Decommissioned: When Dead Hosts Bite Back
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\nWorkshop: Requiem for the Decommissioned: When Dead Hosts Bite Back
\nEvery organization has a graveyard - hosts that were decommissioned after a migration, abandoned when a project died, or simply dropped from inventory after a reorg. They\'re off the asset list, out of the patch cycle, and completely out of mind.
\nThey\'re also still on the network.
\nThis talk breaks down how forgotten and abandoned hosts consistently become the softest entry points during red team engagements - built from real engagement experience across large-scope assessments and bug bounty programs. We\'ll cover why they keep appearing, why they survive undetected, and how to systematically hunt for them using low-noise reconnaissance techniques.
\nAttendees will leave with a practical methodology they can apply on their next engagement.
\n\n

Tactic: Hunting the Decommissioned: Hands-on Forgotten Host Discovery\nIn this hands-on session, attendees will work through a practical recon methodology for identifying forgotten and abandoned hosts - using low-noise reconnaissance techniques available to any red teamer.\nWe start together, walking through the methodology step by step against a prepared target modeled on patterns seen in real engagements. Then attendees get time to hunt independently while I\'m available to answer questions. We close with a group debrief on what was found.\nA laptop with Kali, Parrot, or similar is recommended.

\n\nSpeakerBio:  Yekaterina Shevchenko
\n

Yekaterina Shevchenko is a Lead Security Testing Engineer focused on penetration testing and red teaming. She works on large-scope security assessments across complex environments, with an emphasis on repeatable workflows, clear evidence, and actionable remediation. Her experience covers infrastructure, web applications, and cloud security. Yekaterina also shares educational content under the nickname m0rn1ngstr on her YouTube channel, focused on practical offensive security topics.

\n\n\n\'',NULL,1294970),('4_Sunday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Living Off the IDE: From Initial Access to Covert C2 in Modern AI Code Editors\'','\'Edo Maland\'','Creator Talks_9fec8ef32f522dc5645c85e36ef6eb42','\'Title: Living Off the IDE: From Initial Access to Covert C2 in Modern AI Code Editors
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\nFormat: Technical Talk with Live Demonstrations
\n\n

This talk presents a full intrusion lifecycle model centered on AI-assisted IDEs environments that can be utilized during adversary emulation or red teaming engagements:

\n\n
    \n
  • Practical attack chains from delivery to C2
  • \n
  • A rendering-based covert exfiltration technique
  • \n
  • A new persistence category rooted in agent behaviour
  • \n
  • Operational implications for red and blue teams
  • \n
\n\n

This talk matters because it wakes up developers to their IDE\'s god-mode risks and how AI-assisted IDEs can be abused across the full intrusion lifecycle in the adversary emulation or for red team engangements

\n\n

A. Introduction - The IDE as an Execution Platform

\n\n
    \n
  • Evolution of Modern AI-assisted code editors (Cursor, Windsurf, Trae, agent-based IDEs)
  • \n
  • Capabilities beyond code completion include repository indexing, workspace task execution, structured rendering (Mermaid/Markdown), persistent agent rules and authenticated development tunnels
  • \n
  • Threat model shift: IDE as a high-value attack surface
  • \n
\n\n

B. Threat Model & Attack Surface Expansion

\n\n
    \n
  • The Developer Blind Spot
  • \n
  • Developer workstation as a Tier-0 asset
  • \n
  • Trust boundaries introduced by workspace trust, agent skill definitions, rendering engines, remote development features
  • \n
  • Adversary objective: Living off the AI-driven IDE’s (LOTIDE)
  • \n
\n\n

Visual: Architecture diagram of developer environment attack surface.

\n\n

Unlike prior IDE abuse discussions that focus on single misconfigurations or extension risks, this talk presents a full intrusion lifecycle model that chains multiple trusted IDE behaviors into an operational attack path. Our focus is not a single misconfiguration, but how legitimate IDE features can be chained into a reliable operational intrusion path.

\n\n

C. Initial Access & Delivery

\n\n

We demonstrate several practical initial access paths into AI-assisted IDE environments. These are not zero-day exploits. They are trust abuses that leverage legitimate functionality.

\n\n

Initial Access Techniques:

\n\n
    \n
  • Workspace Auto-Execution (Task Hijack)\nMalicious tasks.json configurations configured to execute on folder open. When a developer clones and “trusts” a repository, the task executes automatically within the IDE context. Each AI-assisted IDE handles this differently, some block automatic execution by default if not “trust”, while others allow it automatically, creating opportunities for abuse with minimal interaction.

  • \n
  • Indirect prompt injection via agent skill packages\nMalicious agent skill definitions or rule files that subtly alter AI behavior, introducing hidden backdoor logic during code generation, refactoring, or review.

  • \n
  • SSH Remote Argument Injection Chains\nIntroduce a novel exploitation vector and abuse of remote development protocol to pass crafted arguments that lead to unintended command execution in the AI-driven IDEs including bypassing application-implemented protection mechanisms.

  • \n
\n\n

Delivery Mechanisms:\nWe pair these techniques with realistic delivery vectors

\n\n
    \n
  • Spear Phishing via Developer Workflows\nFake job offers or technical interviews where developers are asked to clone a repository, trust the workspace, install required plugins, or run setup scripts. The attack chain blends into legitimate onboarding or assessment scenarios.

  • \n
  • URI Scheme Abuse (“URIFix” Variant)\nA ClickFix-style variant leveraging custom URI schemes (e.g., cursor://). A user clicks a crafted link that launches the desktop IDE directly and triggers fileless code execution. This can be chained with SSH remote development features for further control.

  • \n
\n\n

Live Demo 1:\n- Clone malicious repository, trust workspace\n- Trust bypass techniques and trigger automatic task execution\n- Demonstrate code execution inside IDE context

\n\n

The following videos demonstrate our researched Cursor Initial Access Demos: SSH Remote Arg Injection + URI Scheme Abuse (URIFix) + Bypass

\n\n

D. Credential Harvesting & Context Mining

\n\n

AI-assisted IDEs store more than source code. As developers use them, they accumulate local data that often includes sensitive information:

\n\n
    \n
  • Chat history files containing past AI conversations
  • \n
  • Temporary and generated files created during code edits
  • \n
  • Indexed repository content
  • \n
  • Agent rule and configuration files
  • \n
\n\n

During troubleshooting or development, developers frequently paste API keys, tokens, environment variables, database strings, or cloud configuration details into AI prompts. These inputs are then stored locally as part of the IDE’s normal history and indexing mechanisms.\nWe demonstrate how an attacker with access to the IDE environment can extract this data directly from local storage. In many cases, secrets are recoverable from:

\n\n
    \n
  • Chat logs
  • \n
  • Generated configuration snippets
  • \n
  • Project setup files
  • \n
  • .env and related environment files surfaced through indexing
  • \n
\n\n

This does not require privilege escalation or exploit development. Once execution is achieved inside the developer context, the IDE itself becomes a reliable source of credentials and operational metadata.

\n\n

Our observation is that modern AI-assisted IDEs retain and organize sensitive developer context. If that environment is compromised, those stored interactions become part of the attack surface.

\n\n

Live Demo 2:\nDemonstration via PowerShell script to detect AI-assisted coding tools and performs post-exploitation operations such as extract AI conversation logs including search credentials and collect artifacts or files generated by the agent (e.g recover .env secrets surfaced through indexing) also persistence techniques

\n\n

E. Rendering Engines as Exfiltration Channels

\n\n

Prior research has shown that structured rendering features inside AI-assisted IDEs such as Mermaid diagram previews and Markdown rendering can be abused to trigger outbound network requests during preview.

\n\n

We build on this observation and incorporate it into a broader intrusion model. Rather than transmitting a file directly to an attacker, the flow becomes:

\n\n

Local secret → AI transformation → Rendered output → External resource resolution

\n\n

In this model, secrets extracted from local files (for example, .env or configuration files) can be embedded into:\n- Mermaid diagram definitions\n- Markdown image references\n- Click directives or external resource links

\n\n

When the content is rendered inside the IDE’s embedded webview, the renderer resolves external resources, resulting in outbound HTTP requests that carry attacker-controlled parameters. From an endpoint monitoring perspective:\n- The parent process remains the IDE.\n- The network request is tied to preview functionality.\n- No separate exfiltration tool is executed.

\n\n

The behaviour resembles normal rendering activity rather than traditional data exfiltration. In our research, we demonstrate how this technique can be chained with initial access and persistence mechanisms to form a complete intrusion path.

\n\nSpeakerBio:  Edo Maland
\n

Redho Maland is senior offensive security consultant with over a decade of hands-on experience in penetration testing, adversarial simulation, red teaming, and active directory security. He also authored popular open-source tools such as TheFatRat, Sudomy, Brutal, Vegile and others.

\n\n

He was invited and recognized as a cyber mentor and subject matter experts (SMEs) by EC-Council and Hack the Box (HTB) for voluntary projects. He holds an industry certification in the offensive security domain including OSCE3, OSCP+, OSWP, CRT(PEO) and ECPTX.

\n\n

He regularly manages and leads cyber offensive teams, executing complex and unique security engagements to ensure quality and successful outcomes across multiple projects

\n\n\n\'',NULL,1294971),('4_Sunday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Living Off the IDE: From Initial Access to Covert C2 in Modern AI Code Editors\'','\'Edo Maland\'','Creator Talks_9fec8ef32f522dc5645c85e36ef6eb42','\'\'',NULL,1294972),('2_Friday','14','14:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Quality over Quantity: How to Publish CVEs that Actually Matter\'','\'Natan Morette\'','Creator Talks_0b54f6a446a154405f9bbb5c01526475','\'Title: Quality over Quantity: How to Publish CVEs that Actually Matter
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map
\n
\nDescription:
\n

This hands-on tactic focuses on making CVE discovery and publication practical, accessible, and repeatable. Instead of treating vulnerability research as an individual or highly specialized skill, this session introduces a structured workflow that attendees can immediately apply.

\n\n

Attendees will follow a step-by-step approach to:\n • Explore a scoped attack surface\n • Apply a curated vulnerability pattern checklist\n • Identify and validate a potential vulnerability\n • Structure the finding in a simplified CVE-style format

\n\n

All materials are prepared in advance to ensure the activity can be completed within 30–60 minutes and repeated across multiple waves of participants.

\n\n

This tactic emphasizes doing over theory, helping attendees leave not just with knowledge, but with a clear, reusable method for identifying and documenting vulnerabilities and a better understanding of how CVE publishing can be integrated into team workflows.

\n\nSpeakerBio:  Natan Morette, Pentest Manager at Thoropass, vulnerability researcher, and cybersecurity instructor for Brazil’s national Hackers for Good initiative
\n

Natan Morette is a Penetration Test Manager, vulnerability researcher, and cybersecurity instructor for Brazil’s national Hackers for Good initiative, where he mentors students in offensive security across the country. He began his career as a help desk analyst and moved through infrastructure roles before discovering his passion for cybersecurity. Natan has discovered and published multiple CVEs and actively supports students in identifying and disclosing their own—especially in open-source projects with meaningful social impact.

\n\n\n\'',NULL,1294973),('2_Friday','15','14:00','15:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Quality over Quantity: How to Publish CVEs that Actually Matter\'','\'Natan Morette\'','Creator Talks_0b54f6a446a154405f9bbb5c01526475','\'\'',NULL,1294974),('2_Friday','13','13:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6','\'BloodHound OpenGraph: Six Degrees of Everything\'','\'Rohan Vazarkar,Wes Miller\'','Creator Talks_2cb26e51963a7df51592907f5485337b','\'Title: BloodHound OpenGraph: Six Degrees of Everything
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6 - Map
\n
\nDescription:
\n

In this session, we\'ll give a short demo of the BloodHound OpenGraph platform, and show off some modeling capabilities and how to get started working with it. We will show participants an example using lab data with a fake AD environment and Nessus/Vulnerability data and demonstrate how to integrate other sources of data into the existing graph and how easy it is to get started.

\n\nSpeakers:Rohan Vazarkar,Wes Miller
\n
\nSpeakerBio:  Rohan Vazarkar
\n

Former pentester and original author of BloodHound, turned developer.

\n\nSpeakerBio:  Wes Miller
\n

Wes Miller is on the Developer Relations team at SpecterOps, and has worked on many of the core components of BloodHound Community Edition including many of the core features of OpenGraph

\n\n\n\'',NULL,1294975),('4_Sunday','14','14:00','14:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'DFMI: Weaponizing MSI Installers for Fileless Code Execution\'','\'Anıl Çelik\'','Creator Talks_91a7d9e6b8e92c32cbc4c3b139fee2ec','\'Title: DFMI: Weaponizing MSI Installers for Fileless Code Execution
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

DFMI is a cross-platform, open-source offensive toolkit that hijacks & abuses the Windows Installer\'s own execution engine to detonate arbitrary payloads during software installation, with zero files written to disk and zero evidence left behind. And this can be achieved without even corrupting the Authenticode of the binary.

\n\n

The attack surface is the CustomAction table embedded in every MSI database — a small structure that Windows Installer processes unconditionally at install time. DFMI injects a deferred CustomAction (property-based EXE invocation) — firing right before the modification in system files; the payload executes before a single legitimate byte touches the filesystem.

\n\n

Right now, DFMI provides 3 different methods for abusing MSI files:\n- Inject: Simply injects a CustomAction (CA) into an existing MSI package.\n- Rogue MST: Generates an MSI Transform File (.mst) and injects into legitimate \".msi\" file without corrupting it\'s Authenticode.\n- Stub: Creates a malicious MSI file from scratch.

\n\n

What makes DFMI particularly difficult to eradicate is that it exploits no vulnerability; it\'s a feature. The CustomAction mechanism is a 25-year-old Windows feature, documented by Microsoft, used by virtually every enterprise software package and trusted implicitly by the OS.

\n\n

DFMI simply turns that trust sideways — using the Installer engine as its own payload executor.

\n\n

https://github.com/ccelikanil/DFMI

\n\nSpeakerBio:  Anıl Çelik
\n

Computer Engineer & been working as a Red Teamer for the past ~7 years. Previously did presentations at DEFCON 33 Demo Labs, DEFCON 33 Red Team Village & Black Hat USA Arsenal 2025. Currently holding 6 CVEs, OSCP & OSWP. Interests: Windows Internals & AD Security

\n\n\n\'',NULL,1294976),('3_Saturday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6','\'Pyramid of Pain-Red Team (Human and Technical Friction)\'','\'Frank Victory\'','Creator Talks_43f927b47446f5f4612aaddb4803b776','\'Title: Pyramid of Pain-Red Team (Human and Technical Friction)
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6 - Map
\n
\nDescription:
\n

Inspired by the Pyramid of Pain, this session flips the lens inward to examine the friction Red Teams face across tools, policies, and organizational constraints. We will explore how limited scope, tool fatigue, and misaligned incentives reduce the real impact of security testing—and how to (possibly) fix it. Using frameworks such as MITRE ATT&CK, attendees will learn to prioritize findings by business risk, translate technical results into actionable outcomes, and build repeatable processes that drive remediation.

\n\nSpeakerBio:  Frank Victory
\n

Frank Victory is a seasoned cybersecurity leader with over 30 years of experience shaping impactful security strategies. Focused on results rather than titles, he has excelled in both technical and leadership roles, bringing deep expertise in defensive and offensive security—spanning blue and red team operations, incident response, and threat & risk management.

\n\n

Passionate about developing the next generation of cybersecurity professionals, Frank teaches at local community colleges and leads instruction for CU Boulder’s programs in Social Engineering, Ethical Hacking, DFIR, and Threat Hunting. As Vice President of the Denver OWASP chapter, he fosters community engagement through meetups and conferences, including SnowFROC.

\n\n

Frank also co-hosts the Colorado=Security Podcast, where he interviews local cybersecurity professionals, delving into their journeys, challenges, and insights—always ending with the question: What is the biggest challenge in cybersecurity today?

\n\n\n\'',NULL,1294977),('3_Saturday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6','\'Pyramid of Pain-Red Team (Human and Technical Friction)\'','\'Frank Victory\'','Creator Talks_43f927b47446f5f4612aaddb4803b776','\'\'',NULL,1294978),('4_Sunday','13','13:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'M0us3: A Lightweight, Multi Session C2 Framework with a Rust based Windows Implant\'','\'Aryan Jogia\'','Creator Talks_5e972c430bd98d3831d348c7859acd77','\'Title: M0us3: A Lightweight, Multi Session C2 Framework with a Rust based Windows Implant
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

\"M0us3: When the Mouse Eats the Cat – A Rust Powered Windows Implant and Its Interactive Python C2\"\nThe C2 landscape is dominated by heavy hitters written in Go, C#, or Nim. But what if the implant was built with Rust – a language revered for memory safety, tiny binaries, and growing evasion potential – and the server was a snappy, persistent Python TUI that remembers everything about your sessions?\nEnter M0us3. Not another fork of a known framework. A ground up, cross language C2 system where the Windows agent is pure Rust, and the operator interface is an interactive Python3 server with built in session persistence, command history, real time state tracking – and now, the ability to spin up multiple listeners on the fly.\nWhy Rust for the Implant?\nRust gives us crash resilient concurrency, no GC pauses, and a binary size under 2MB (stripped). It compiles to clean Win32 API calls without the .NET or Go runtime baggage, making it naturally harder to signature. The result? At the time of submission, M0us3\'s implant is FUD across Sophos, Kaspersky, Microsoft Defender, ESET, and Bitdefender – no static detections, no behavioural flags. This isn\'t luck; it\'s the combination of raw Win32 calls, custom AES GCM encryption, and the absence of any borrowed IoC patterns.\nM0us3\'s agent delivers a full shell, file upload/download, and client side sleep with jitter – all over HTTP wrapped in AES GCM. The encryption is not an afterthought; GCM\'s authenticated mode avoids padding oracles and provides integrity out of the box.\nThe Python Server – More Than a Listener\nMost lightweight C2 servers are stateless or log only. M0us3\'s controller is interactive and stateful. Disconnect? Reconnect – your session is exactly where you left it. This persistence, combined with a clean terminal UI, allows red teamers to manage dozens of implants without losing context, and blue teamers to analyse complete operator implant interaction logs.\nRecent enhancements give operators the flexibility to manage multiple listeners simultaneously from the same interface – whether segmenting targets by campaign, geography, or testing different evasion techniques – all without spinning up separate server instances.\nWhat\'s Next?\nHTTPS support is already in the pipeline – the encryption layer is designed to be protocol agnostic, so switching to TLS is a matter of swapping the transport wrapper. Multi-listener management was just the beginning.

\n\nSpeakerBio:  Aryan Jogia
\n

Aryan is a senior security researcher specializing in the intricate dance of offensive evasion and defensive bypass. With nearly six years of focused experience, including a tenure with the Government of India, he dissects modern AV and EDR systems by targeting their core architectural assumptions on Windows and nix platforms. His deep work in malware development and low-level programming fuels the creation of advanced tooling for red team engagements, where he has successfully navigated fortified environments. An avid contributor to the community, Aryan has shared his findings at venues including WildWest Hackin\' Fest, The Hack Summit, and CarolinaCon, and has led technical training sessions at BSides events. His research extends to pioneering fuzzing implementations and automation, constantly pushing the boundaries of what\'s possible in security research.

\n\n\n\'',NULL,1294979),('4_Sunday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'0-Day Hunting Table: Come Join the Vulnpocalypse\'','\'Chris Haller\'','Creator Talks_2f60a2d86ccde2798ca57fadf6de7f9b','\'Title: 0-Day Hunting Table: Come Join the Vulnpocalypse
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\n

This tactic will be a table where hackers can help find and prove 0-day vulnerabilities together at scale. The focus of this tactic is to demonstrate a hands-on methodology to find vulnerabilities, leveraging AI in an effective manner, and proving it has real impact. Then, attendees will search for their own 0-days together across a curated set of software for hunting.

\n\n

We\'ll have a collection of 30+ applications available for immediate analysis and live service deployments to prove out the impact.

\n\n

I\'ll bring a large LED board to track the number of 0-days found as well. This board will be updated in real-time as new vulnerabilities are found.

\n\n

All 0-days will be responsibly disclosed after DefCon.

\n\nSpeakerBio:  Chris Haller
\n

Chris brings over 15 years of experience in Penetration Testing, Incident Response, Risk Evaluation, Threat Intelligence, and System Administration. While Active Duty, Chris was the Incident Management Lead for the Navy Cyber Defense Operations Command where he specialized in response to attacks on classified and unclassified Navy networks across the globe. Throughout his career, Chris has provided actionable information for stakeholders to make informed decisions about reducing risk to the lowest possible levels, resulting in over 30 CVEs attributed to his work.

\n\n

Chris has co-authored The Hack is Back: Techniques to Beat Hackers at Their Own Games and has created content on HackTheBox, TryHackMe, and Cybrary. He is an avid CTF player and has recently taken the #1 individual and #1 team position in the National Cyber League, while also operating as the Attack/Defense coach for the US Cyber Team.

\n\n

Chris is a Principal Security Consultant at Omada Technologies out of Portsmouth, NH. He enjoys helping organizations find and fix complex vulnerabilities before bad actors can use them to cause harm.

\n\n

Mr. Haller was awarded GIAC Security Expert #329 and has over 30 other certifications.

\n\n\n\'',NULL,1294980),('4_Sunday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'0-Day Hunting Table: Come Join the Vulnpocalypse\'','\'Chris Haller\'','Creator Talks_2f60a2d86ccde2798ca57fadf6de7f9b','\'\'',NULL,1294981),('2_Friday','14','14:00','14:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'Extension Hollowing: Abusing Chrome\'s Extension Trust Model\'','\'Gordon Long\'','Creator Talks_16f37d593436a4f7b6b9a7f0dd9914f8','\'Title: Extension Hollowing: Abusing Chrome\'s Extension Trust Model
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

Chrome controls over 65% of worldwide browser usage, with 100,000+ extensions on the Chrome Web Store. Enterprises rely on Chrome\'s built-in policies, such as extension allowlisting, WebStore integrity checks, and forced installed extensions to keep their endpoints clean. Those controls are broken.\nExtension Hollowing is a new technique that completely bypasses Chrome\'s integrity verification of WebStore extensions. By hollowing out a legitimate allowlisted extension and replacing or backdooring its internals, an attacker can silently deploy extension arbitrary code inside the browser, defeating allowlisting, bypassing signature checks, and inheriting the full permission set of the original extension (and extending it if desired).\nThis talk will show how hollowed extensions can function as a fully capable C2 via a new Chrome extension mythic agent which will be released after this talk called Hades. Attendees will get to sit down and play with this c2 framework as well as embedding it into trusted extensions via extension hollowing. We will then walk through the specific Chrome enterprise policies designed to prevent this, and how to bypass them. The technique extends beyond Chrome to other Chromium-based browsers including Edge.\nTLDR; This talk will demonstrate live exploitation, discuss what EDRs are (and aren\'t) keying on, cover which mitigation strategies actually work, and why most deployed configurations don\'t. In addition attendees will get to sit down and actually embed a custom Chrome extension mythic agent inside of trusted extensions, bypassing active policies and showing how to dynamically load and run code in the latest versions of Chrome.

\n\nSpeakerBio:  Gordon Long
\n

Gordon Long is the President and CEO of LegioX Cyber Technologies and is a Senior Offensive Security Engineer at Zoom. He also teaches as an Adjunct Professor at George Mason University in the Digital Forensics Master\'s Program. His favorite areas of cybersecurity include EDR evasion and cyber deception. His X handle is @ethicalhax and github is under AsaurusRex.

\n\n\n\'',NULL,1294982),('4_Sunday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID\'','\'Elzer Pineda,Jose Rivas\'','Creator Talks_6b8d32c5745d2454da826034f3421dec','\'Title: Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

Is MFA and Conditional Access a real security guarantee? In this technical session, we will demonstrate how endpoint compromise allows an attacker to bypass traditional identity barriers in the cloud. The talk focuses on exploiting vulnerabilities in Microsoft Entra ID, breaking down an advanced attack chain:

\n\n

• Device Code Flow: Abuse of authentication flows for initial access (Demo with Entraith).\n• PowerShell Hijacking: Process interception to obtain session tokens (GrabTokenAzureAD).\n• Sliver BOF Extraction: Use of Beacon Object Files (BOF) for stealthy exfiltration of tokens and the Primary Refresh Token (PRT) from memory, evading anti-malware defenses.\n• MFA Bypass and Intune: The speakers developed custom tooling to extract local PRTs, bypass Intune device management controls, and circumvent MFA. This entire attack lifecycle was consolidated into Entraith — an offensive framework built from scratch by the research team and set to be released publicly at DEF CON 34 (https://github.com/bl4cksku11/entraith) — enabling device code attacks, token renewal, email and app inspection, token exfiltration, and persistence generation from a single interface.

\n\n

This talk is not about a single CVE or a niche edge case. It is a comprehensive offensive research presentation covering the full spectrum of attack techniques against Microsoft Entra ID — from the very first foothold to deeply rooted, multi-vector persistence that survives incident response.

\n\n

We will demonstrate, live, how an attacker moves through every phase of an Entra ID compromise:

\n\n

INITIAL ACCESS AND TOKEN THEFT: We begin with Device Code Flow phishing — abusing Microsoft’s own authentication protocol to harvest valid tokens without ever touching a password. We then escalate with PowerShell process hijacking (GrabTokenAzureAD) to intercept live session tokens, and culminate with Sliver BOF-based extraction of the Primary Refresh Token (PRT) directly from memory — stealthy, silent, and anti-malware evasive. These three techniques alone demonstrate that MFA and Conditional Access are not the guarantees organizations believe them to be.

\n\n

BYPASSING INTUNE AND MFA: Purpose-built tools developed during this research extract local PRTs, bypass Intune device compliance controls, and circumvent MFA enforcement at the token layer — not through social engineering, but through direct abuse of Microsoft’s identity platform mechanics. Attackers operating from non-enrolled or non-compliant devices can achieve full Tenant access that Conditional Access policies are designed to prevent.

\n\n

PERSISTENCE ACROSS 10 VECTORS: Once inside, we deploy a “Survival Kit” of 10 chained persistence mechanisms — camouflaged App Registrations, long-lived secrets and certificates, backdoor accounts, strategic role assignments, privileged group inheritance, admin mailbox delegation, inbox-rule-based exfiltration of credentials and MFA codes, OAuth consent grants to external applications, and Temporary Access Pass generation for on-demand MFA bypass. No single blue team action — password reset, MFA enforcement, device wipe — removes all of them simultaneously.

\n\n

ENTRAITH — BUILT BY US, RELEASED AT DEF CON: The centerpiece of this talk is Entraith (https://github.com/bl4cksku11/entraith), an offensive framework designed and built from the ground up by the speakers specifically for this research. Entraith is not a wrapper around existing tools — it is original work, developed over months of hands-on red team engagements against real Microsoft 365 environments. It unifies every technique demonstrated in this talk into a single operator interface: device code phishing, PRT extraction from memory, Intune compliance bypass, token renewal and exfiltration, email and application enumeration, and the full 10-step persistence deployment chain. DEF CON 34 will be the moment Entraith is released to the public. Attendees will be among the first to access the tool, its documentation, and the full methodology behind it — making this talk a genuine first-look at original research with immediate real-world impact.

\n\n

WHY THIS MATTERS FOR CLOUD VILLAGE: The Microsoft 365 and Entra ID ecosystem is the identity backbone of the majority of enterprise organizations worldwide. The techniques presented here are not theoretical — they are being used by real threat actors today. Defenders in the room will leave with concrete detection opportunities and an understanding of exactly which log sources and control gaps allow this attack chain to succeed undetected. Red teamers will leave with a working tool and a fully documented methodology. This talk delivers both offensive depth and defensive utility in a single session, and the live demos ensure no attendee has to take our word for it.

\n\nSpeakers:Elzer Pineda,Jose Rivas
\n
\nSpeakerBio:  Elzer Pineda, Pentester
\n

Regional Pentester and Cybersecurity Consultant, Elzer Pineda is an active member of the Red Team executing strategic consulting projects and advanced penetration testing engagements. His career has been focused on Threat Research for private and government organizations across the region. He is a Dojo Community Ambassador and Professor at the Universidad Tecnológica de Panamá (UTP). His experience has taken him to share technical research at Ekoparty, BSides Latam Peru, BSides Panamá, DOJOConf, PwnedCR, and OWASP Latam. Offensive security certifications: OSWE, OSEP, OSCP, OSWP, CRTP, CRTO, and CRTL.

\n\n

--

\n\n

Profesor en la Universidad Tecnológica de Panamá y especialista en Red Team con más de 10 años de experiencia en ciberseguridad ofensiva y defensiva. Pentester en GBM (región y Estados Unidos) y researcher en Toad Security. Máster en Seguridad Informática. Realiza evaluaciones de seguridad a aplicaciones móviles, web e infraestructura en Latinoamérica y comparte activamente conocimientos en la comunidad Dojo como embajador y conferencias. Certificaciones: OSWE, OSEP, OSCP, CRTO, OSWP, CRTL.

\n\nSpeakerBio:  Jose Rivas, Experienced Penetration Tester at A-LIGN
\n

Jose Rivas is an Offensive Security Researcher and Red Team Operator at A-LIGN, specializing in adversarial simulations, Active Directory attack paths, and physical security assessments. Co-founder of Zero Trust Offsec, an offensive security research group focused on vulnerability exploitation, emerging attack techniques, and responsible disclosure, and Founder of DCG Panama, Panama\'s first official DEF CON chapter, where he leads a community dedicated to red team operations, and adversarial tradecraft. A recognized voice in the Panamanian security community, Jose has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf. With certifications including CRTO, eWPT, eCPPT, and CompTIA PenTest+, he brings a threat-actor mindset and a strong commitment to advancing offensive security knowledge across the region.

\n\n

Jose Manuel Rivas is a Penetration Tester and Red Team Operator at A-LIGN, with hands-on experience in adversarial simulations, Active Directory attack chains, web application testing, and physical security assessments. He has multiple CVEs to his name, discovered through bug bounty programs and independent vulnerability research. Co-founder of Zero Trust Offsec and founder of DCG Panama, Panama\'s first official DEF CON chapter. He has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf, and is focused on growing the penetration testing and red team culture across Latin America.

\n\n\n\'',NULL,1294983),('4_Sunday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID\'','\'Elzer Pineda,Jose Rivas\'','Creator Talks_6b8d32c5745d2454da826034f3421dec','\'\'',NULL,1294984),('3_Saturday','14','14:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'AIMARU C2: The New Era of LotL (MCP AI-Driven C2)\'','\'Mario Lobo\'','Creator Talks_90019a7148a0501ccf2fa5ddec03c704','\'Title: AIMARU C2: The New Era of LotL (MCP AI-Driven C2)
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\nAImaru C2 is the evolution of a concept sparked by an unsettling question: What happens when an attacker can execute advanced Living off the Land (LotL) attacks without being an expert? While traditional LotL requires a specialist to navigate complex environments, AImaru C2 changes the game. Evolving from a PoC into a sophisticated Red Team framework, it automates expert-level tradecraft by subverting Anthropic’s Model Context Protocol (MCP). By weaponizing MCP clients, it transforms a standard context protocol into a functional, autonomous multi-level RAT that natively \"speaks\" PowerShell.
\n\n

AImaru C2 was born out of a critical necessity to ground cybersecurity in reality. While the industry often distracts itself with over-engineered narratives and hype-driven threats that ignore actual ecosystem data, a far more pragmatic danger has been hiding in plain sight. This framework addresses the unsettling evolution of the \"Expert Bottleneck\": What happens when the sophisticated LotL tactics, once reserved for elite nation-state actors, are democratized through automation? Named after the mythical serpent that glides unseen between the underworld and the land of the living, AImaru C2 represents the shift from manual expertise to autonomous execution. It is no longer just a proof of concept; it is a full-scale Red Team framework designed to expose how easily an unskilled attacker can now weaponize authorized system protocols to orchestrate advanced, data-driven breaches that traditional defenses simply aren\'t looking for.

\n\n

To understand its impact, context is key. For years, LotL attacks have been the dominant tactic in ransomware campaigns. Instead of deploying traditional malware, threat actors abuse legitimate OS tools—such as PowerShell, WMI, or Certutil—to operate under the radar. In 2025, 82% of successful breaches were fileless or malwareless, with PowerShell ranking as the second most utilized TTP by groups like Black Basta, Royal, and LockBit.

\n\n

This robust framework moves beyond experimental concepts, consolidating itself as a production-ready offensive platform. AImaru C2 is engineered with a modular architecture that prioritizes cryptographic integrity, operational security, and intelligent automation.

\n\n

Core Framework Capabilities:\n- Model Context Protocol (MCP) RAT Engine: A paradigm shift in command and control that subverts Anthropic’s MCP from a standard context-sharing tool into a functional, undetectable Remote Access Trojan (RAT), tunneling all C2 traffic through legitimate LLM API communication.\n- PowerShell Client Builder: An automated obfuscation engine featuring deep variable randomization and structural mutation to break static signatures.\n- AMSI Bypass Generator: Dynamic generation of multi-stage bypass scripts, utilizing diverse techniques to neutralize the Antimalware Scan Interface in real-time.\n- Real-time Monitoring: Advanced telemetry for live command execution tracking and granular session management.\n- Cryptographic Isolation: Implementation of per-client encryption keys derived via HKDF-SHA256, ensuring that the compromise of one beacon does not jeopardize the entire fleet.\n- RBAC: Native Role-Based Access Control, strictly segregating permissions between Admins, Users, and Viewers.\n- Complete Audit Logging: Forensic-grade command history with millisecond-accurate timestamps for post-operation deconfliction.

\n\n

By utilizing a multi-tier decision logic, the system dynamically selects and rewrites payloads based on the specific operational objective. This allows the C2 to scale its complexity in real-time—transitioning from basic PowerShell structures and stealthy WMI manipulation to the strategic abuse of LOLBins for high-complexity tasks. This adaptive approach ensures that every command utilizes the most effective legitimate system tool, successfully evading environment-specific defenses by blending into the target\'s unique operational noise.

\n\n

Tactic Description: In this interactive session, attendees will sit down with the developer to operate the AImaru C2 framework in a controlled lab environment. Participants will experience the \"Natural Language Intent\" paradigm shift firsthand, moving away from manual syntax to intent-based exploitation.

\n\n

Deployment: Deploy a lightweight MCP-Client on a target Windows machine and establish a beacon back to the AI-C2 controller.

\n\n

Intent-Based Recon: Issue high-level natural language prompts (e.g., \"Find sensitive PDF files and identify lateral movement paths\") and observe the LLM selecting and generating the appropriate PowerShell/WMI code in real-time.

\n\n

Automated Evasion: Trigger the Adaptive AMSI Bypass module, witnessing how the framework re-writes its own memory-resident payloads to evade active defenses.

\n\n

All the technical information about the project is here: https://github.com/mloborom/aimaru-c2

\n\nSpeakerBio:  Mario Lobo, Cyber Threat Intelligence Researcher
\n

I am a Colombian Cybersecurity Engineer with a Master’s degree and a deep passion for the field. I have spent over 18 years immersed in various domains of Information Security and Cyber Intelligence.

\n\n

My career has spanned critical sectors, including National Defense, where I spent nearly 10 years collaborating with Strategic Cyber Intelligence teams worldwide. I have led multiple cybersecurity teams for multinational banking institutions within the financial sector, and for several years now, I have served as the Lead Threat Intelligence Researcher at Lumu Technologies. I have been a main track speaker at prestigious international conferences such as Ekoparty, 8.8 Gob, BSides São Paulo, BSides Colombia, and Cyberwings, among others.

\n\n

Beyond the professional realm, I am a guitar enthusiast, a dedicated cyclist, and a consummate music lover.

\n\n

--

\n\n

Soy colombiano, Ingeniero Magister en Ciberseguridad y un apasionado por el tema. Llevo más de 18 años sumergido diferentes campos de la Seguridad de la Información y la Ciberinteligencia.

\n\n

Mi trayectoria me ha permitido transitar por sectores como la Defensa Nacional, donde por casi 10 años colaboré con equipos de Ciberinteligencia Estratégica alrededor del mundo. Lideré diferentes equipos de ciberseguridad para la banca multinacional en el sector Financiero y desde hace algunos años me desempeño como Lider Investigador de Inteligencia de Amenazas en Lumu Technologies. He participado como conferencista main track en eventos como Ekoparty, 8.8 Gob, Bsides Sao Paulo y Bsides Colombia, Cyberwings entre otros.

\n\n

Fuera del ámbito profesional, soy un amante de la guitarra, la bici y un melómano consumado.

\n\n\n\'',NULL,1294985),('3_Saturday','15','14:00','15:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'AIMARU C2: The New Era of LotL (MCP AI-Driven C2)\'','\'Mario Lobo\'','Creator Talks_90019a7148a0501ccf2fa5ddec03c704','\'\'',NULL,1294986),('3_Saturday','14','14:00','14:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Turning Keys and Opening Doors: Leveraging AI Hype to Hack Everything\'','\'Will Alexander\'','Creator Talks_9addf8b24ab55390185c6d01efb13c94','\'Title: Turning Keys and Opening Doors: Leveraging AI Hype to Hack Everything
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

Abstract\nI\'ve been Red Teaming for over five years now, and in that time I\'ve led or been involved in more than a dozen Red Team engagements where my team has successfully (or semi-successfully) reached objective. I\'m not an elite hacker. I\'ve learned some cool tactics and techniques through public research and have pieced them together with my team to covertly pivot through networks and access sensitive data. I\'ve decided that, while I\'m not an elite hacker, I am really good at turning keys and opening doors.

\n\n

In this talk I\'d like to discuss how I led my company\'s first AI Red Team operation, not just by jailbreaking and prompt injecting LLMs; But by backdooring legitimate AI models, socially engineering data scientists, attacking ML pipelines, and abusing new AI technology to exfiltrate sensitive training data and proprietary models.

\n\n

Outline\nDiscussion of AI operation planning and offensive research - starting with zero AI knowledge

\n\n

Identification of novel GCP attack + pairing it with convincing social engineering pretexts

\n\n

How we sent 3000+ phish in under 10 minutes, tech stack and relevant automation

\n\n

Demo of the novel GCP attack which leads to account takeover

\n\n

Discussion of how the entire attack happens in the ATTACKER\'s GCP environment, leaving defenders blind

\n\n

Automated post-exploitation for persistence and dealing with short lived keys from the GCP attack

\n\n

Pivoting to AI related loot

\n\n

Collaboration with Google to mitigate the risk for ALL GCP customers

\n\n

Additional offensive GCP AI attacks like attacking model training pipelines with malicious containers and backdooring legitimate public models

\n\n

In this talk I plan to publicly disclose a novel GCP attack path that enabled my team to take over GCP accounts and projects. This is an open vulnerability in Google\'s Vulnerability Reporting Programm sitting at P1.

\n\nSpeakerBio:  Will Alexander
\n

Senior Manager - Red Team @ Palo Alto Networks\n2 years of Purple Teaming\n5+ years of Red Teaming\n<1 year of Management

\n\n\n\'',NULL,1294987),('2_Friday','15','15:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Trust the Pipeline, Lose the Kingdom: Hands-On Cloud Native CI/CD Red Team\'','\'Shane Young\'','Creator Talks_28d3eb626598243d780bc486f0c5e271','\'Title: Trust the Pipeline, Lose the Kingdom: Hands-On Cloud Native CI/CD Red Team
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

Cloud native CI/CD pipelines are the soft underbelly of modern enterprise security. SolarWinds in 2020, Codecov in 2021, CircleCI in 2023 set the template, and the pattern has only accelerated: tj-actions compromised 23,000 repositories in March 2025, GhostAction exfiltrated 3,325 secrets in September 2025, TeamPCP turned Trivy and Checkmarx GitHub Actions into credential stealers in March 2026. Most red teams still do not operate meaningfully against cloud CI/CD, and most detection stacks still do not watch it. The terrain runs in the gap between endpoint detection and cloud API monitoring, and it remains one of the highest leverage, least contested surfaces in the enterprise.

\n\n

This workshop walks a full cloud native CI/CD attack chain drawn from multiple red team engagements: pull request poisoning via pull_request_target, OIDC-to-STS credential exfiltration from the build runner, force-merging a PR through a GitHub admin PAT pulled from Secrets Manager, Lambda and EventBridge persistence that never leaves the cloud, IAM trust chain abuse that escalates a low privilege build identity into broad cloud access, and Secrets Manager as the pivot out of AWS into code hosting, the CI platform, and every SaaS the organization depends on.

\n\n

The paired 60 minute Tactic is hands-on, not demonstration. Each of 10 to 15 attendees forks a public demo repo and opens their own PR against it. The vulnerable pull_request_target workflow fires automatically and dumps live STS credentials to the workflow log. Attendees read the credentials from their own PR\'s Actions page, paste them into their own terminal, pull a GitHub admin PAT from Secrets Manager, and force-merge their own PR through the stolen token with no human reviewer in the loop. Every attendee watches their own PR flip from Open to Merged using a credential that did not exist until they opened the PR. The OIDC-trusted role is scoped to GetSecretValue on one secret, so attendee actions have zero AWS blast radius. The speaker then demonstrates the persistence, IAM trust chain, and pivot stages on the projector, and attendees leave with a public Terraform bundle to run the full chain end to end against their own AWS account at home, plus a set of detection signals deployable against CloudTrail and CI logs their organizations already collect.

\n\nSpeakerBio:  Shane Young
\n

Shane Young is an offensive security operator and program builder with over 15 years in the field. His career spans consulting across financial services, hardware, and SaaS; building out an IoT security practice at a major security consultancy; leading red team operations against cloud native product companies; and pioneering AI/ML red teaming for deployed enterprise AI features. He is the creator of Brutespray, a public open source offensive security tool. He builds offensive security programs from scratch, runs red team operations end to end, and still carries significant technical IC workload because he thinks that is how security leaders stay sharp. He has been hacking since he was a teenager, and it still has not gotten old.

\n\n\n\'',NULL,1294988),('3_Saturday','14','14:00','14:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'Chaining Credentials Through the AI Infrastructure Nobody Secured\'','\'Nathan Keys\'','Creator Talks_4466e4905e9104b690a3be3849edded8','\'Title: Chaining Credentials Through the AI Infrastructure Nobody Secured
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

AI/ML services are proliferating across enterprise networks without security review. Developers deploy Ollama instances locally, data science teams stand up Jupyter notebooks and MLflow registries without authentication, platform engineers run Ray clusters and LiteLLM API gateways on default configurations, and MCP tool servers expose file system access and code execution to the network. These services rarely appear in traditional vulnerability scans and are seldom included in asset inventories.

\n\n

To measure the scope of this problem, I built a 5-VM benchmark lab simulating four independent teams deploying 19 AI/ML endpoints with 122 planted findings. The lab includes a manifest-driven scoring harness that enables objective detection measurement across three validation modes: standard (substring matching), strict (host attribution and source module accuracy), and contract (workflow metadata and evidence chain verification).

\n\n

The tool is aipostex, an open-source single-binary Go framework designed for the full AI infrastructure attack lifecycle. It performs network discovery across 20+ AI service families, executes 123 vulnerability templates, and provides 17 dedicated exploit modules covering Ollama, Jupyter, MCP servers, LiteLLM gateways, MLflow, Ray, vector databases, and inference endpoints. MCP coverage includes schema poisoning, environment variable extraction, and CVE-specific checks for DNS rebinding and remote code execution through tool servers. A separate model-scan capability identifies deserialization risk in pickle, PyTorch, TensorFlow, and ONNX model files.

\n\n

The live demonstration walks through a credential chain attack against the benchmark lab. The attack begins with Ray cluster enumeration to harvest API keys from job environment variables, pivots into MLflow where experiment run parameters and tags contain embedded secrets and cloud credentials, then chains those tokens to authenticate against a HuggingFace TGI inference endpoint. Each hop crosses a different team\'s infrastructure, discovered and linked by the tool\'s credential chain-loading engine.

\n\n

The session also covers the safety and operational controls that make this suitable for production engagements: explicit --force-exploit gating on mutating actions, --mode full requirement for exploit templates, proof-strength classification on every finding (reachable, read-confirmed, execution-confirmed), and OPSEC features including User-Agent rotation, TLS fingerprint randomization, and timing jitter.

\n\n

Open-source release coinciding with presentation.

\n\n

Does your workshop come with a tactic?

\n\n

Yes. The tactic is \"Hands-On: Credential Chain Exploitation Across Shadow AI Infrastructure.\"

\n\n

Each group of about five attendees gets their own isolated cloud-hosted lab instance, a full 5-VM environment spun up on AWS and accessible only through a VPN tunnel. You SSH into your group\'s attack box and work through a guided attack chain against the lab\'s 19 AI/ML endpoints.

\n\n

First, you scan the /24 and discover what\'s running across four target hosts. The tool fingerprints each endpoint and gives you structured next steps, so even if you\'ve never touched MLflow or Ray before, you know what to run next.

\n\n

Then you follow the credential chain. Enumerate a Ray cluster and pull API keys from job environment variables. Take those into MLflow and extract secrets from experiment run parameters and tags. Chain the tokens forward to authenticate against a HuggingFace TGI inference endpoint. Three hops, three teams\' infrastructure, all connected.

\n\n

At the end, you run the scoring harness against your results and see how you did. Detection rate, missed findings, proof-strength breakdown, all compared against the 122-finding answer key.

\n\n

Groups that finish the guided chain early can explore additional attack surfaces across the lab\'s remaining endpoints, including MCP schema poisoning, Jupyter cell secret mining, and vector database injection. The scoring harness covers all 122 findings, not just the guided path, so there is plenty of room to improve your score.

\n\n

Each wave runs about 50 minutes with a 10-minute reset between waves. I\'ll run two waves. All you need is a laptop with an SSH client and a WireGuard client. No prior AI/ML experience required. Everything you use during the tactic, the tool binary, lab docs, and scoring harness, is yours to take home and run on your own infrastructure.

\n\n

https://professor-moody.github.io/aipostex/

\n\n

https://professor-moody.github.io/aipostex-lab/

\n\nSpeakerBio:  Nathan Keys
\n

Nathan is a security researcher focused on ML supply-chain security. Their research spans information hiding in model artifacts, data poisoning of retrieval pipelines, and post-exploitation of AI infrastructure. Nathan is currently a principal penetration tester in the financial sector. This is their first DEF CON talk. Outside of his passion for research, Nathan loves to touch grass, read all manner of scientific study or journal, and listen to old school southern rap (think UGK). Nathan has changed careers more than once, from winemaking to restaurants to professional hacking now for the last seven years, and he loves a good story and a good conversation.

\n\n\n\'',NULL,1294989),('2_Friday','16','16:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Haetae: An Agent to Takedown North Korean C2 Servers\'','\'Mauro Eldritch,Nelson Rafael Colón Merán\'','Creator Talks_3c330176d8f528408b698aa3db621b04','\'Title: Haetae: An Agent to Takedown North Korean C2 Servers
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\n

In this talk, we introduce Haetae, an agent designed to profile, identify, and exploit C2 frameworks used by North Korean malware.

\n\n

Haetae supports both automated and interactive modes, allowing analysts to map and understand adversary infrastructure with different levels of control. It is built around a flexible rule-based system, enabling users to extend and refine detections as new patterns and frameworks emerge.

\n\n

In this first release, we will walk through real-world cases where Haetae was used to identify and take down infrastructure associated with Mach-O Man and POWerful Armadillo.

\n\n

We will also release a safe emulator of both malware C2 servers, allowing researchers and newcomers to experiment with Haetae in realistic, controlled environments without risk.

\n\n

This is a highly technical talk but can be enjoyed by both beginners and seasoned threat hunters.

\n\nSpeakers:Mauro Eldritch,Nelson Rafael Colón Merán
\n
\nSpeakerBio:  Mauro Eldritch, Leader at Bitso Quetzal Team
\n

Hacker and Speaker.

\n\n

Founder of BCA LTD and DC5411.

\n\n

I wrote a book interviewing Threat Actors.

\n\n

I like Threat Intelligence and Golden Retrievers.

\n\nSpeakerBio:  Nelson Rafael Colón Merán, Security Engineer at Bitso
\n

Security Engineer at Bitso, Latin America\'s leading crypto-first financial platform. I\'ve specialized in red team operations, penetration testing, and malware development.

\n\n

Recognized speaker in the Dominican Republic\'s RedTeamRD cybersecurity community, where I\'ve given a couple talks and previously assisted DEFCON as a speaker.

\n\n\n\'',NULL,1294990),('2_Friday','17','16:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Haetae: An Agent to Takedown North Korean C2 Servers\'','\'Mauro Eldritch,Nelson Rafael Colón Merán\'','Creator Talks_3c330176d8f528408b698aa3db621b04','\'\'',NULL,1294991),('4_Sunday','11','11:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Living Off WebView2: Turning Microsoft’s Browser into a Red Team Asset\'','\'Murilo Caixeta\'','Creator Talks_cf6a36f7c34d9fac52991f40659673d0','\'Title: Living Off WebView2: Turning Microsoft’s Browser into a Red Team Asset
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

Modern Windows applications are quietly shipping with a built-in Chromium-based browser, WebView2, running inside trusted, signed processes such as Microsoft Teams, Outlook, and other enterprise software.

\n\n

This talk shows how that design choice creates a powerful and largely unmonitored attack surface.

\n\n

I demonstrate how this model can be abused in offensive operations, turning WebView2 into a vector for persistence, code execution, and enterprise account impersonation.

\n\n

I show how feature flags and environment variables can be leveraged to manipulate the WebView2 runtime, enabling techniques such as DLL sideloading within legitimate applications. This allows arbitrary code execution inside trusted processes, supporting stealthy living-off-the-land persistence.

\n\n

Building on this, I present methods to intercept and proxy HTTP/HTTPS traffic generated by WebView2-based applications. This enables the extraction of session tokens, cookies, and other sensitive artifacts, leading to realistic account takeover and impersonation scenarios, including access to platforms such as Office 365.

\n\n

In addition to the offensive techniques, I provide a detailed analysis of the Indicators of Compromise (IOCs) generated throughout these attack chains. I highlight detection opportunities, discuss current visibility gaps in EDR solutions, and propose practical approaches for identifying and responding to this type of activity in real-world environments.

\n\nSpeakerBio:  Murilo Caixeta
\n

Murilo Caixeta has been working in Offensive Security since 2023, focusing on web vulnerability exploitation and Capture The Flag (CTF) challenge development. In 2024, he joined the market as a pentester and, in early 2025, transitioned into Red Team operations, with an emphasis on malware development and phishing techniques.

\n\n\n\'',NULL,1294992),('3_Saturday','17','17:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'Below the Threshold: Real-World APT Tradecraft for Full-Spectrum Compromise\'','\'Jonathan Coradi,Oliveira Junior\'','Creator Talks_8fef62bf96a63bee16583c640dec9501','\'Title: Below the Threshold: Real-World APT Tradecraft for Full-Spectrum Compromise
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

This talk aims to demonstrate the modus operandi of an APT focused on full organizational compromise, revealing how such operations actually function in practice — not through isolated tools or techniques, but through the decision-making model that guides every action over time.

\n\n

Rather than focusing on direct exploitation or individual methods, this session shows how advanced operators structure their actions around continuity, predictability, and behavioral alignment with the target environment. Attacks are not treated as disruptive events, but as controlled sequences of decisions designed to remain coherent and below the threshold of attention.

\n\n

The presentation walks through a real RedOps engagement from a strategic perspective, highlighting how each step is evaluated in terms of detection probability, behavioral deviation, and operational impact, ensuring the operation remains stable and does not generate relevance over time.

\n\n

Instead of teaching specific techniques, the talk focuses on analyzing how and why certain strategies are chosen, revealing the underlying principles that drive advanced operations in complex environments.

\n\n

The narrative is built around three distinct operational tracks conducted within the same organization, which, when combined, enabled full compromise:

\n\n
    \n
  • CloudOps — decisions and paths that led to the compromise of cloud resources, including external dependencies and supply chain vectors;
  • \n
  • HybridOps — integration of physical, human, and logical layers, including physical intrusion and contextual exploitation of the corporate environment;
  • \n
  • FinancialOps — understanding of financial and operational processes that enabled the execution of validated fraud without generating meaningful alerts;
  • \n
\n\n

Across these three domains, the session demonstrates how cloud, physical, and financial layers can be exploited in a coordinated manner while maintaining consistency with expected system behavior.

\n\n

As a central part of the session, a real operation conducted by our company will be presented, in which an organization was fully compromised through a coordinated, multi-layered approach. The scenario includes:

\n\n
    \n
  • exploitation of a 0day in a physical intrusion context, enabling continuous presence within the environment for 30 days without detection, including a 0-click account takeover scenario;
  • \n
  • progression from an initial phishing vector to full compromise of cloud assets, including resource abuse within well-mapped compromised accounts;
  • \n
  • analysis of critical business services and processes, resulting in confirmed financial fraud through the exploitation of a client-side trust model in a payment system, with direct reputational impact;
  • \n
\n\n

In this case, there was no single event that defined the attack, but rather a sequence of controlled and coherent actions that blended into normal operations, enabling full control without triggering traditional detection mechanisms.

\n\n

The goal of this talk is to provide security professionals with a practical and structured understanding of how APTs actually operate, offering deeper insight into how decisions are made throughout a real-world operation.

\n\n

The key takeaway is that APT operations are not effective because they are invisible, but because they do not behave like something that deserves attention.

\n\nSpeakers:Jonathan Coradi,Oliveira Junior
\n
\nSpeakerBio:  Jonathan Coradi
\n

Jonathan Coradi is a RedOps Tech Lead at Hakai Offensive Security, with over 7 years of experience in offensive security. He has led offensive operations across industrial, financial, and banking sectors in Brazil, specializing in advanced penetration testing, Red Team simulations, and physical intrusion engagements. Jonathan is also an elite Bug Bounty Hunter — currently ranked Top 1 on BugHunt — and has reported critical vulnerabilities to companies like Microsoft, Uber, and Mercado Livre, among others.

\n\nSpeakerBio:  Oliveira Junior
\n

Oliveira Lima is the founder of Hakai and has over 15 years dedicated to the field of cybersecurity, focusing on penetration testing and Red team operations. As a researcher, he has reported numerous vulnerabilities in large companies such as Trend Micro, CISCO, Dlink, etc. Additionally, he has registered more than 40 CVEs. Oliveira continues to be part of the team leading Red team operations.

\n\n\n\'',NULL,1294993),('3_Saturday','11','11:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'The Authentic Operator: Social Engineering Through Natural Delivery\'','\'Joanna -\'','Creator Talks_435b8b1451502676a8462f2197ce92a6','\'Title: The Authentic Operator: Social Engineering Through Natural Delivery
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

Current social engineering training commonly teaches OSINT, pretexting, phishing, vishing, rapport building, elicitation, influence, framing, and nonverbal communication. That material is valuable, but much of it still treats the operator as interchangeable: learn the technique, pick the pretext, run the script. This workshop takes a different angle. The operator’s natural communication style is part of the tradecraft. A social engineering approach fails when the operator cannot deliver it credibly under pressure.

\n\n

The Authentic Operator teaches attendees to build social engineering approaches around their own personality, behavioral strengths, and natural delivery style. Some operators are credible as curious analysts. Others are stronger as frustrated customers, helpful insiders, nervous applicants, confident peers, or authority-adjacent professionals. Attendees will learn to identify which approach they can carry without overacting, then use that approach to support elicitation, rapport, and access-oriented objectives during authorized red team assessments.

\n\n

The accompanying tactic is a hands-on operator-matching lab for 10–15 participants. Drawing from the author’s own style, including turning an apparent lack of “brain-to-mouth filter” into a rapport-building advantage, attendees will examine how authentic self-disclosure, conversational momentum, humor, curiosity, or controlled oversharing can lower defenses and encourage reciprocity. Participants will complete a short operator-style self-assessment, receive fictional assessment objectives, select a natural delivery approach, and build an opening interaction designed to elicit information or move closer to access. The goal is not to teach people to “be anyone.” The goal is to teach operators to use who they already are with discipline, realism, and ethical boundaries.

\n\nSpeakerBio:  Joanna -
\n

Joanna Wiggum is the founder and principal investigator of Countervail, a veteran-owned Washington State licensed private investigation agency focused on cyber-enabled fraud, impersonation, business email compromise, ransomware, and other digital loss matters. Her work centers on the trust, workflows, and dependency blindspots adversaries exploit to gain access, move money, and legitimize harmful action.

\n\n

Before founding Countervail, Wiggum held cybersecurity leadership roles at Starbucks, Oracle, and Microsoft across red teaming, incident response, trust and safety, enterprise risk, and investigations. She built Starbucks’ first red team, led Oracle’s cloud red team and anti-abuse program, and directed investigations involving enterprise systems, air-gapped cloud environments, and emerging technologies at Microsoft.

\n\n

Wiggum served 12 years in the United States Air Force in enlisted and commissioned roles spanning communications, operational planning, and bomber operations. Her military background includes support for U.S. Central Command air-to-ground communications tied to Operations Enduring Freedom and Iraqi Freedom, followed by mission planning and leadership in B-52 operations. She holds a Master of Human Relations and a Bachelor of Arts in International Security Studies from the University of Oklahoma.

\n\n\n\'',NULL,1294994),('3_Saturday','12','12:00','12:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'The Protocol-Native Adversary: Full-Spectrum ICS Simulation via SiL\'','\'Blessen Thomas,Javier Hernández,Wojciech Poparda\'','Creator Talks_752d1e8b24cd24d869d713c7fe5f8abc','\'Title: The Protocol-Native Adversary: Full-Spectrum ICS Simulation via SiL
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

As adversaries increasingly target the \"physics\" of critical infrastructure, the security community must move beyond IT-centric red teaming. While hardware-based training platforms have paved the way, they often lack the scale required to simulate complex, multi-facility sabotage. This workshop introduces a Software-in-the-Loop (SiL) environment designed to bridge the gap between IT command-and-control and OT process logic.\nParticipants will navigate a containerized industrial ecosystem, mastering \"Living-off-the-Ladder\" (LotL) techniques—using native, unauthenticated protocols (Modbus, DNP3, S7comm) to manipulate physical water treatment processes. We will move through the full ICS kill-chain, focusing on the technical mechanics of memory-block interrogation and automated setpoint manipulation.\nAttendees will engage in a hands-on lab, executing a \"Credential Harvest\" (T0861) and a coordinated chemical-override attack. By the end of the session, participants will understand why these \"authorized\" protocol commands bypass traditional NIDS and will leave with a deployable SiL framework to continue their own ICS research.

\n\nSpeakers:Blessen Thomas,Javier Hernández,Wojciech Poparda
\n
\nSpeakerBio:  Blessen Thomas
\n

Blessen Thomas is an Independent Security Researcher.He has more than 13+ years of experience in Red Teaming, Appsec (Web, Thick, API & Mobile Apps), Smart Watch Wearable Application Penetration Testing, Mobile Penetration Test (iOS,Android,Windows platform), IoT,OT ,mainframes,SAP,SWIFT,RPA,Cloud,ATM,KIOSK,Vulnerability Assessment and Network Penetration Test,Physical Covert Entry,Wireless assessments,Telecom(2G,3G,USSD) etc. for several enterprise companies and financial institutions all across the globe.\nHe is a B.Tech in Information Technology from Anna University and holds industry certifications such as SANS GPEN,CRTO,OPST,CREST CRT(PEN),CREST CPSA,OSCP,CRTP,OSWP,C)PTE,CEH,CHFI. He has been listed and acknowledged in various “HALL OF FAMES” for various companies such as Oracle,Sony, Kayako, Appcelerator, Hotgloo, Meldium, Splunk and many more for responsible disclosure. He has been a bug bounty hunter and contributor for the OWASP Mobile Testing Guide Project(MSTG),Tamer OS, Seclists, OWASP top 10 API, OSSTMM, Awesome Mainframe Hacking,RvR,WAVSEP Benchmark sectool projects.\nHis research training/talks has been accepted into various security conferences like Hack in the Box-Dubai,Hacktivity -Hungary, CanSecWest -Canada,OWASP Appsec EU- London -UK,OWASP Appsec Europe-Italy, RootCon-Philippines ,OWASP PH,OWASP New Zealand Day, Infosec SouthWest,Austin,Texas, FSec-Croatia, Hackbeach, Hackfest, Shakacon,ITWeb-South Africa, Jordan Cyber Security Summit, HITCON-Taiwan, OWASP AppSec-Bucharest, OWASP Appsec Africa-Morocco,CircleCityCon,OWASP Botswana,CactusCon,Bsides-London,Prishtina,Aarhus,Vilnius,Elbsides,Kristiansand,Athens and many more.\nHe has been invited as Speaker for Radio Talk Shows for All India Radio. He spends his leisure time playing drumkit and percussion.

\n\nSpeakerBio:  Javier Hernández
\n

Javier is a Red Team Operator and Malware Developer specializing in offensive engineering, adversary emulation, and custom tooling development. Holding certifications such as OSEP and CRTO, he has delivered high‑impact security engagements across both consulting environments and in‑house security teams. His work focuses on crafting stealthy implants, evasion techniques, and automation‑driven offensive capabilities. Passionate about applied research, he explores the intersection of malware development and AI‑augmented offensive security to help organizations strengthen their resilience against modern threats

\n\nSpeakerBio:  Wojciech Poparda
\n

Wojciech Poparda is a cybersecurity consultant. He helps organizations proactively defend their digital infrastructure by thinking like an adversary. Leveraging a deep foundation in Offensive Security, he specializes in designing resilient Security Architectures that bridge the gap between complex attack vectors and enterprise defense, with a sharp focus on Cloud Security and Identity & Access Management (IAM).

\n\n

His approach is backed by rigorous technical validation, holding industry-leading certifications including OSCP, CRTE, CRTP, CRTO, CPTS, CWES, AWS Certified Solutions Architect - Associate and AWS Certified Security - Specialty. He is also an Associate of ISC2, having successfully passed the CISSP exam.

\n\n

Beyond the terminal, he channels the discipline, focus, and resilience required for cybersecurity into his life as a triathlete. As an IRONMAN European and World Championships finisher, he brings the same endurance and dedication to solving complex security challenges as he does to the race course.

\n\n\n\'',NULL,1294995),('4_Sunday','14','14:00','14:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Ghost in the Water: Simulating a Nation-State PLC Sabotage Campaign\'','\'Blessen Thomas,Javier Hernández,Wojciech Poparda\'','Creator Talks_fd8d64bc0ff5355feda18d2ce1857aa9','\'Title: Ghost in the Water: Simulating a Nation-State PLC Sabotage Campaign
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\n

Critical infrastructure protocols designed in the late 70s were never built to handle a modern adversary. In this hands-on Tactic, we move beyond theoretical slides to execute a high-fidelity, nation-state-style operation against a municipal water treatment facility. Using a portable Software-in-the-Loop (SiL) environment, participants will experience the raw tradecraft of industrial sabotage without the need for a six-figure hardware rack.

\n\n

This session focuses on \"Living-off-the-Ladder\" (LotL)—the art of using legitimate industrial function codes to perform unauthorized actions. You will not be dropping malware; you will be programmatically manipulating the physics of the plant using the same TTPs seen in recent geopolitical conflicts.

\n\n

The Mission (30–60 Minute Sprint):

\n\n

Industrial Interrogation: Use unauthenticated DNP3 and S7comm discovery to fingerprint PLCs and map the process logic—capturing vendor data and firmware versions silently.

\n\n

The Memory Heist: Execute a \"Credential Harvest\" (T0861) by programmatically reading PLC holding registers to recover plaintext maintenance keys.

\n\n

Coordinated Sabotage: Trigger a \"Slow-and-Low\" chemical setpoint override (Modbus FC16) across multiple facilities simultaneously, observing real-time physical feedback from the simulated plant sensors.\n• Phase 1: Automated multi-protocol fingerprinting and asset discovery.\n• Phase 2: Executing a \"Memory Heist\" to extract plaintext maintenance credentials directly from PLC registers.\n• Phase 3: A coordinated \"Slow-and-Low\" chemical setpoint override, providing real-time visual feedback of the physical process failure.

\n\n

Attendee Takeaway:\nParticipants will build the muscle memory required to navigate OT environments and will leave with a deployable, containerized SiL framework to continue their own ICS research and detection validation at home.\nAttendees will leave with a deployable SiL framework and the \"Living-off-the-Ladder\" playbook to continue their own ICS research without the need for expensive hardware.

\n\nSpeakers:Blessen Thomas,Javier Hernández,Wojciech Poparda
\n
\nSpeakerBio:  Blessen Thomas
\n

Blessen Thomas is an Independent Security Researcher.He has more than 13+ years of experience in Red Teaming, Appsec (Web, Thick, API & Mobile Apps), Smart Watch Wearable Application Penetration Testing, Mobile Penetration Test (iOS,Android,Windows platform), IoT,OT ,mainframes,SAP,SWIFT,RPA,Cloud,ATM,KIOSK,Vulnerability Assessment and Network Penetration Test,Physical Covert Entry,Wireless assessments,Telecom(2G,3G,USSD) etc. for several enterprise companies and financial institutions all across the globe.\nHe is a B.Tech in Information Technology from Anna University and holds industry certifications such as SANS GPEN,CRTO,OPST,CREST CRT(PEN),CREST CPSA,OSCP,CRTP,OSWP,C)PTE,CEH,CHFI. He has been listed and acknowledged in various “HALL OF FAMES” for various companies such as Oracle,Sony, Kayako, Appcelerator, Hotgloo, Meldium, Splunk and many more for responsible disclosure. He has been a bug bounty hunter and contributor for the OWASP Mobile Testing Guide Project(MSTG),Tamer OS, Seclists, OWASP top 10 API, OSSTMM, Awesome Mainframe Hacking,RvR,WAVSEP Benchmark sectool projects.\nHis research training/talks has been accepted into various security conferences like Hack in the Box-Dubai,Hacktivity -Hungary, CanSecWest -Canada,OWASP Appsec EU- London -UK,OWASP Appsec Europe-Italy, RootCon-Philippines ,OWASP PH,OWASP New Zealand Day, Infosec SouthWest,Austin,Texas, FSec-Croatia, Hackbeach, Hackfest, Shakacon,ITWeb-South Africa, Jordan Cyber Security Summit, HITCON-Taiwan, OWASP AppSec-Bucharest, OWASP Appsec Africa-Morocco,CircleCityCon,OWASP Botswana,CactusCon,Bsides-London,Prishtina,Aarhus,Vilnius,Elbsides,Kristiansand,Athens and many more.\nHe has been invited as Speaker for Radio Talk Shows for All India Radio. He spends his leisure time playing drumkit and percussion.

\n\nSpeakerBio:  Javier Hernández
\n

Javier is a Red Team Operator and Malware Developer specializing in offensive engineering, adversary emulation, and custom tooling development. Holding certifications such as OSEP and CRTO, he has delivered high‑impact security engagements across both consulting environments and in‑house security teams. His work focuses on crafting stealthy implants, evasion techniques, and automation‑driven offensive capabilities. Passionate about applied research, he explores the intersection of malware development and AI‑augmented offensive security to help organizations strengthen their resilience against modern threats

\n\nSpeakerBio:  Wojciech Poparda
\n

Wojciech Poparda is a cybersecurity consultant. He helps organizations proactively defend their digital infrastructure by thinking like an adversary. Leveraging a deep foundation in Offensive Security, he specializes in designing resilient Security Architectures that bridge the gap between complex attack vectors and enterprise defense, with a sharp focus on Cloud Security and Identity & Access Management (IAM).

\n\n

His approach is backed by rigorous technical validation, holding industry-leading certifications including OSCP, CRTE, CRTP, CRTO, CPTS, CWES, AWS Certified Solutions Architect - Associate and AWS Certified Security - Specialty. He is also an Associate of ISC2, having successfully passed the CISSP exam.

\n\n

Beyond the terminal, he channels the discipline, focus, and resilience required for cybersecurity into his life as a triathlete. As an IRONMAN European and World Championships finisher, he brings the same endurance and dedication to solving complex security challenges as he does to the race course.

\n\n\n\'',NULL,1294996),('3_Saturday','13','13:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'You Can\'t Block My C2 — It\'s Your Google Calendar\'','\'Nishant Tayade\'','Creator Talks_693c38a3756cf9d9611b15d3eb312aef','\'Title: You Can\'t Block My C2 — It\'s Your Google Calendar
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

Speaker Bio

\n\n

Nishant Tayade is a Security Engineer on an enterprise Red Team, where he has spent three years conducting internal and external red team campaigns simulating real-world adversary tactics. His current research explores covert command-and-control techniques — including Mythic agents that abuse legitimate cloud services for stealthy communication — and operationalizing AI agents to enhance offensive security operations. Prior to his current role, he spent two years in SOC and SIEM engineering, giving him a full-stack perspective on both offense and defense.

\n\n

Nishant holds a Master of Science in Information Security from Carnegie Mellon University. He has spoken at BSides Seattle, BSides San Diego, and BSides New Orleans, covering topics ranging from anonymity and OPSEC to how attackers weaponize OSINT and AI to profile targets.

\n\n

This research started during an APT41 emulation campaign he led, where he mapped the group\'s real-world tradecraft — including their use of Google Calendar as a C2 channel. While building the simulation, he observed that cloud service API traffic to domains like googleapis.com was effectively invisible to enterprise detection stacks. Most cloud-native organizations allowlist this traffic by default, creating a blind spot. He built Chronos and Epoch to operationalize that technique within Mythic, and validated that Calendar-based C2 traffic went undetected against production monitoring.

\n\n

Description

\n\n

What if C2 traffic was indistinguishable from a Google Calendar sync? This session presents Chronos and Epoch — a Mythic agent and C2 profile that use Google Calendar as a dead-drop communication channel. All traffic flows to googleapis.com over standard HTTPS. There is no C2 server IP for defenders to discover, no infrastructure to burn, and no way to block it without disrupting enterprise calendar workflows.

\n\n

The workshop covers the journey of building a functional C2 channel over a SaaS API that was never designed for it — the architectural decisions, the operational tradeoffs, and the hard lessons learned when things broke in unexpected ways. The Calendar API has no push notifications, inconsistent event visibility across clients, and was never designed for reliable message passing. Making a reliable C2 agent on top of that required solving problems that don\'t exist in traditional HTTP-based C2. The engineering challenges along the way revealed lessons that apply well beyond Calendar C2.

\n\n

The session will cover:\n- Why Google Calendar makes an effective covert channel for C2 and where it falls short\n- How encrypted tasking is hidden inside calendar event metadata\n- Using Calendar C2 as a fallback channel when primary C2 infrastructure gets burned\n- Low-and-slow operations: credential harvesting, recon, and maintaining access in heavily monitored environments\n- When to deploy this on an engagement and when HTTP-based C2 is the better choice\n- The defender\'s perspective: Calendar API audit logs, event creation/deletion frequency anomalies, extendedProperties usage patterns, and service account authentication from unexpected IPs

\n\n

Both components will be open-sourced on GitHub for the community.

\n\n

Workshop Breakdown (30 minutes)

\n\n

Intro — 2 minutes\n- Who the presenter is, background\n- The premise: C2 traffic hiding inside legitimate Google Calendar API calls

\n\n

Why Google Calendar — 5 minutes\n- The dead-drop C2 concept and why Calendar is uniquely suited\n- googleapis.com is allowlisted everywhere, event metadata is invisible in the UI\n- What existed before and what was missing

\n\n

Architecture with pre-recorded demo — 6 minutes\n- Epoch: transparent relay that never decrypts payloads\n- Chronos: Python agent with encrypted Calendar communication\n- Pre-recorded demo: checkin, command execution, file browser, multi-agent

\n\n

Lessons learned — 7 minutes\n- What broke: Calendar API visibility delays, silent task drops, racing server instances\n- What it taught about building C2 over SaaS APIs

\n\n

Red team applications and defense — 7 minutes\n- Fallback channel: what to do when your HTTP C2 gets burned and you need to maintain access\n- Low-and-slow ops: credential harvesting, recon, and staging for re-entry\n- When Calendar C2 is the right tool and when it isn\'t\n- Calendar API audit logs, event pattern anomalies, detection strategies

\n\n

Close — 3 minutes\n- Key takeaways, GitHub release, transition to tactic

\n\n

Tactic Breakdown (2 hours, multiple waves)

\n\n

Each wave runs approximately 30-40 minutes with 10-15 attendees:

\n\n

Setup and installation — 10 minutes\n- Install Epoch C2 profile and Chronos agent into Mythic using mythic-cli\n- Verify containers are running and registered

\n\n

Configuration — 10 minutes\n- Configure Google Calendar integration with a service account\n- Set calendar ID, poll interval, and credentials in the Mythic UI\n- Start the C2 profile

\n\n

Build and deploy — 5 minutes\n- Build a Chronos payload through the Mythic UI\n- Deploy the agent on their own VM

\n\n

Operate — 10 minutes\n- Issue commands through Mythic: shell, ls, whoami, cat, download\n- Observe the file browser integration\n- Watch calendar events appear and disappear in real time

\n\n

Defender perspective — 5 minutes\n- Examine Google Workspace Calendar API audit logs\n- Identify anomalies: rapid event creation/deletion cycles, extendedProperties.private usage (legitimate apps rarely use this), service account authentication from unexpected IPs\n- Discuss what blue teams should monitor for and why this is detectable if you know where to look

\n\n

Prerequisites: Attendees should bring their own Linux VM or cloud instance with Mythic installed. A setup guide will be provided in advance. Pre-configured Google Cloud service account credentials will be provided at the table so attendees don\'t need their own GCP project — they can start operating immediately.

\n\nSpeakerBio:  Nishant Tayade
\n

Nishant is a Security Engineer specializing in Adversarial Emulation, Red Teaming and OSINT. He focuses on simulating real-world threats to enhance enterprise security. Prior to that, he earned his master\'s degree in security from Carnegie Mellon University.

\n\n\n\'',NULL,1294997),('4_Sunday','14','14:00','14:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'beacon injected with HOOKCHAIN 2026\'','\'Arnold Jared Morales Yepez\'','Creator Talks_016d91fc59685a04130ced76ccee7525','\'Title: beacon injected with HOOKCHAIN 2026
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\n

In penetration testing, we constantly find ourselves facing EDRs/AVs, etc. But as in all cases, we aim to develop our own tooling or techniques that we believe may not yet be properly mapped or detected. On this occasion, we share part of our perspective when dealing with EDRs using Machine Learning technology configured in “FULL” mode. We were able to leverage this technique combined with an encrypted payload to evade this configuration; additionally, when the payload was downloaded or shared as a “.zip,” the agent did not inspect it. Now, let’s dive a bit into the technical aspects, but especially into how it was exploited.\nHookChain is an advanced technique for evading EDR solutions. It is primarily used by threat actors (APTs), but it can also be applied ethically in Red Team exercises. Its main principle is to intercept the hooks that EDRs install in the operating system kernel. What is a hook? Hooks are a mechanism used by EDRs to monitor calls to Windows API functions, mainly from ntdll.dll. In this way, they can intercept and analyze suspicious behavior in real time. The HookChain technique aims to bypass this monitoring layer.

\n\n

Encrypting our payload with XOR\nHookChain typically combines hook evasion with payload encryption; in this case, we will use XOR to avoid static signature-based detection. The shellcode is encrypted in memory and only decrypted right before execution.

\n\n

We can use a string (in this case, “CHANGEMYKEY”) as the key for our XOR encryption, along with shellcode generated using msfvenom, although we can also leverage other C2 frameworks, as we will see later.

\n\nSpeakerBio:  Arnold Jared Morales Yepez, Senior Team Lead, Grupo Salinas
\n

Self-taught in computer security since age 12; holds a degree in Computer Forensics and Cybersecurity and is pursuing a Master\'s in AI and Cybersecurity.

\n\n

--

\n\n

Desde los 12 años, me he dedicado a la informática con un enfoque especial en la seguridad. Actualmente, a mis 22 años, sigo explorando este mundo con la misma pasión, impulsado por la constante evolución de la tecnología y su interminable curva de aprendizaje.

\n\n

Cuento con una carrera en Cómputo Forense y Ciberseguridad, actualmente curso una maestría en Inteligencia Artificial y Ciberseguridad.

\n\n

Certificaciones: CWEE | CAPE |CPTS | EWPTX | CRTO | eMAPT | OSCP | OSCP+ |CEH V13 | EJPT| HTB prolabs Hades - Cybernetics - Zephyr - APTlabs | MDK

\n\n\n\'',NULL,1294998),('3_Saturday','16','16:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Evading EDR in ATM\'','\'Arnold Jared Morales Yepez\'','Creator Talks_5ba117587e2067a3822cac5ebf66baf0','\'Title: Evading EDR in ATM
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map
\n
\nDescription:
\n

ATMs in the end are a computer with windows

\n\n

I will talk about EDRs and how parent-child process inheritance works

\n\n

The Windows boot process, known as the boot process, is divided into several phases as we have already seen: PreBoot (initialization of BIOS/UEFI firmware and POST), Boot Manager (loading of bootmgr or bootmgfw.efi), OS Loader (execution of winload.exe to load the kernel), and Kernel Initialization (loading of ntoskrnl.exe and hal.dll, initialization of drivers and services). Finally, winlogon.exe is started to present the user interface. This process enables the transition from a powered-off state to a functional operating system through a hierarchical and verified sequence.

\n\n

Regarding kernel-based EDRs (Endpoint Detection and Response), they operate in kernel mode, the most privileged level of the system (some also operate at the UEFI level), which allows them to monitor low-level activities such as system calls, memory manipulation, driver loading, and file access. By running in this mode, EDRs can detect and block advanced threats such as rootkits or persistent malware that attempt to evade user-mode protections. Their deep integration with the kernel enables real-time monitoring, behavioral analysis, and immediate response to suspicious activities during and after the boot process.\nEDRs are typically located in the kernel, but as mentioned, some also operate at the UEFI level. If we recall how Windows works, beneath UEFI lies SMM (System Management Mode), making this an even more complex layer to analyze and operate within.

\n\n

This talk is intended for individuals interested not only in ATMs and simple cash dispensing, but in going beyond that—focusing on deeper analysis and the full experience gained when confronting these systems.

\n\n

More information about the attack and the theory behind it:\nhttps://h0km4.com/posts/DMA-Introduction/\nhttps://h0km4.com/posts/telemetria-bypass/

\n\nSpeakerBio:  Arnold Jared Morales Yepez, Senior Team Lead, Grupo Salinas
\n

Self-taught in computer security since age 12; holds a degree in Computer Forensics and Cybersecurity and is pursuing a Master\'s in AI and Cybersecurity.

\n\n

--

\n\n

Desde los 12 años, me he dedicado a la informática con un enfoque especial en la seguridad. Actualmente, a mis 22 años, sigo explorando este mundo con la misma pasión, impulsado por la constante evolución de la tecnología y su interminable curva de aprendizaje.

\n\n

Cuento con una carrera en Cómputo Forense y Ciberseguridad, actualmente curso una maestría en Inteligencia Artificial y Ciberseguridad.

\n\n

Certificaciones: CWEE | CAPE |CPTS | EWPTX | CRTO | eMAPT | OSCP | OSCP+ |CEH V13 | EJPT| HTB prolabs Hades - Cybernetics - Zephyr - APTlabs | MDK

\n\n\n\'',NULL,1294999),('3_Saturday','17','16:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Evading EDR in ATM\'','\'Arnold Jared Morales Yepez\'','Creator Talks_5ba117587e2067a3822cac5ebf66baf0','\'\'',NULL,1295000),('4_Sunday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'The Air Is Hostile: RF Trust Assumptions in Modern Security Systems\'','\'Mitch Breton\'','Creator Talks_a973997e0e3e122b812730ceb2ee6d39','\'Title: The Air Is Hostile: RF Trust Assumptions in Modern Security Systems
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\n

Modern security systems are no longer purely physical. Alarms, sensors, access control, cameras, locks, panic buttons, monitoring paths, and backup communications increasingly depend on wireless technologies such as Wi-Fi, BLE, Zigbee, LoRa, LTE, and cloud-managed IoT infrastructure. For red teams, this creates an important question: what happens when the environment these systems depend on becomes adversarial?

\n\n

This talk reframes RF as a red team attack surface, not just a radio engineering problem. It explores how wireless dependencies create opportunities for reconnaissance, failure-mode discovery, protocol fingerprinting, operational disruption, vendor-claim validation, and physical security bypass modeling. Rather than focusing on illegal or unsafe demonstrations, the presentation emphasizes responsible adversary emulation: identifying RF trust assumptions, mapping wireless dependencies, and testing whether organizations understand how their security systems behave under degraded or hostile spectrum conditions.

\n\n

Attendees will learn how red teams can incorporate RF into engagements without turning the work into tool-driven theater. The talk covers passive RF reconnaissance, wireless dependency mapping, signal availability assumptions, anti-jam marketing claims, fail-open/fail-secure behavior, alert fatigue, response workflows, and the gap between “detection” and actual resilience. It also shows how RF risks connect to broader red team objectives: access control evasion, alarm reliability, site resilience, executive protection, incident response readiness, and vendor due diligence.

\n\nSpeakerBio:  Mitch Breton
\n

Z3r0 is a senior offensive security and threat intelligence operator specializing in real-world adversary simulation, APT-focused threat analysis, and high-signal security assessments.

\n\n

His work centers on helping organizations understand not just where they are vulnerable, but how real attackers would exploit those weaknesses and what to do next.

\n\n

With a background spanning red team engagements, penetration testing, and intelligence-driven security research,

\n\n

Z3r0 approaches every engagement from an adversary’s perspective. He focuses on identifying the small, often-overlooked control failures that enable outsized impact—privilege escalation paths, persistence mechanisms, trust boundary violations, and detection blind spots.

\n\n

At NetPhantom Security, Z3r0 leads initiatives that blend threat intelligence, deception, and offensive testing to provide early warning and decision-grade insight. This includes building and operating intelligence pipelines, adversary profiles, and controlled deception environments that surface attacker behavior before it reaches production systems.

\n\n\n\'',NULL,1295001),('4_Sunday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'The Air Is Hostile: RF Trust Assumptions in Modern Security Systems\'','\'Mitch Breton\'','Creator Talks_a973997e0e3e122b812730ceb2ee6d39','\'\'',NULL,1295002),('2_Friday','13','13:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Shapeshifting C2: Applying DAITA Traffic Shaping to Defeat DPI and DLP Detection\'','\'Rafael Felix\'','Creator Talks_f178338bc2ce3dd36a06f7aed231c9ec','\'Title: Shapeshifting C2: Applying DAITA Traffic Shaping to Defeat DPI and DLP Detection
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

ML-based DPI and DLP solutions have made signature evasion insufficient. Modern enterprise detection analyzes packet size distributions, inter-packet timing, and burst patterns to fingerprint C2 traffic regardless of how well headers and TLS certificates are spoofed.

\n\n

This talk demonstrates how three techniques from the VPN privacy research space - originally developed to defeat traffic analysis against Tor and Mullvad, can be adapted for offensive C2 operations:

\n\n
    \n
  1. Constant-size packet morphing: forcing all frames to a fixed MTU-aligned size removes the packet-size fingerprint that ML classifiers depend on;

  2. \n
  3. Cover traffic injection: dummy packets sent at Poisson-distributed or adaptive intervals make real beacon timing statistically invisible;

  4. \n
  5. Probabilistic pattern distortion: Maybenot-inspired state machines inject cover bursts alongside real packets, destroying recognizable C2 sequences;

  6. \n
\n\n

We then will see how layering these techniques with application-layer malleable profiles (traffic impersonating Microsoft Graph, Slack, or Okta) and bonus: indirect transports like cloud storage dead-drops (S3, OneDrive) creates C2 channels that defeat detection at every layer simultaneously - behavioral, flow, and application.

\n\n

Attendees leave with a concrete mental model for building evasion stacks that go beyond header manipulation.

\n\nSpeakerBio:  Rafael Felix, Offensive Security Lead at Hakai Offensive Security
\n

Rafael has been working with malware development for 5 years, also being involved in the malware community for more than 7 years. He is also experienced in Incident and Response, specifically during malware inner workings analysis. Currently, Rafael is a researcher for Hakai Offensive Security (https://hakaisecurity.io/research-blog), being deeply involved with red-team operations.

\n\n\n\'',NULL,1295003),('3_Saturday','15','15:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'Breaking MCP Trust Boundaries: Cross-Server Authority Injection in Agent Toolchains\'','\'Yevhen Pervushyn\'','Creator Talks_73aa9e6b74fb436f79358f12ddafabcb','\'Title: Breaking MCP Trust Boundaries: Cross-Server Authority Injection in Agent Toolchains
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

Modern MCP deployments assume that low-privilege tools remain low-risk when reviewed independently. In practice, host agents compose outputs across multiple tools and privilege levels, creating authority paths that do not exist in any single server\'s standalone review.

\n\n

This workshop demonstrates a compositional offensive primitive in MCP environments: a low-privilege server influencing the parameters of a high-privilege destructive operation through shared planning context.

\n\n

Attendees will see a controlled lab reproduction where a read-only MCP server shapes the parameters of a privileged SQLite-backed delete operation. The approval prompt shown to the operator accurately describes the final action but omits the upstream provenance that influenced it.

\n\n

The workshop introduces Urd, an open-source compositional analysis tool for MCP deployments. Urd reconstructs authority flow across servers using runtime tracing and manifest analysis, allowing operators and red teamers to identify undeclared cross-tool influence paths.

\n\n

The focus of the session is not prompt injection or model jailbreaks. The focus is cross-server authority flow, provenance loss, and workflow-level trust failure in agentic systems.

\n\n

This session includes a hands-on tactic where attendees reproduce the compositional failure locally, inspect runtime traces, generate divergence findings, and modify the lab to observe how low-trust inputs can influence privileged operations across MCP toolchains.

\n\nSpeakerBio:  Yevhen Pervushyn
\n

Yevhen “valh4x” Pervushyn is the founder of Red Asgard, a security research firm focused on AI integration security, offensive security, and protocol analysis.

\n\n

His work focuses on the operational security of agentic systems: orchestration boundaries, authorization flow, provenance, and workflow-level trust failure in AI deployments.

\n\n

Prior to Red Asgard, he worked in blockchain security auditing and decentralized protocol analysis, experience that directly informs his current research into compositional trust failures in MCP-based systems.

\n\n

He previously presented MCP security research at the SANS AI Cybersecurity Summit 2026. This session presents new technical research, tooling, and hands-on lab material focused on offensive analysis of MCP orchestration behavior.

\n\n\n\'',NULL,1295004),('2_Friday','16','16:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'redStack: Boot-To-Breach Red Team Platform\'','\'Michael Kim,Michael Ortiz\'','Creator Talks_5c8ff9a45e803a97efd32f171cd6dea6','\'Title: redStack: Boot-To-Breach Red Team Platform
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map
\n
\nDescription:
\nPrerequisites: complete these before the session, published in advance at https://github.com/BaddKharma/redStack-defcon34 (AWS account, AWS CLI, Terraform, and an OpenVPN client). Setup happens ahead of time so it does not eat into the session.
\n\n

A two-hour hands-on workshop where attendees stand up a full red team operator stack (https://github.com/BaddKharma/redStack) and run it against a live cyber range. Each attendee gets their own instanced range over an OpenVPN tunnel, so no public DNS or exposed infrastructure is required. You leave with a working lab to build your own tradecraft and OPSEC on.

\n\n

Scope: an intermediate session. It assumes some familiarity with pentest or red team topics, comfort on a Linux command line, and a working understanding of what a C2 framework does. Deep AWS or Terraform experience is not required, but you must arrive with the prerequisites completed.

\n\n

What you build and run: a full operator stack on AWS from a single Terraform apply. Three C2 frameworks (Mythic, Sliver, and Adaptix), an Apache redirector that gates traffic on a header token and CDN-style URI routing with a decoy page for anything that fails, a Guacamole portal for browser-based access to every host, and Kali and Windows operator boxes. You stand each C2 up behind the redirector, then drive a boot-to-breach chain against the live range to SYSTEM.

\n\n

What it is not: an Active Directory exploitation course. The initial domain compromise is white-carded, so attendees start from a provided Administrator hash and spend the time standing up and driving the platform rather than working the AD chain. Web exploitation, custom payload development, and AV or EDR evasion are out of scope.

\n\n

Target: a per-user-instanced Hack Smarter Labs range (a Windows Server 2022 domain controller) reached over an OpenVPN tunnel, so no two attendees touch the same box. Everything runs in your own throwaway AWS account and is destroyed at the end. redStack is open source, so you keep a lab you can redeploy on your own after the workshop.

\n\n

Agenda:\n10min Intro and setup check.\n30min Deploy the stack from one Terraform apply, narrated live. The tunnel comes up, and the range becomes reachable.\n5min Break\n30min Stand up the three C2 backends (Sliver, Mythic, Adaptix) behind the redirector, test a beacon from each.\n5min Break\n25min Attack the live range together: Sliver beacon for initial access, Mythic and Adaptix staged through it, SYSTEM on the DC.\n10min Q&A and teardown (terraform destroy!)

\n\nSpeakers:Michael Kim,Michael Ortiz
\n
\nSpeakerBio:  Michael Kim
\n

Michael Kim’s journey into cybersecurity is a story of resilience and reinvention. Having lived in seven countries, he faced relentless bullying, racism, and isolation - challenges that once pushed him to the brink. After pursuing paths in veterinary medicine, pharmacy, law, and biology, and graduating with a zoology degree, he shifted careers entirely during the pandemic, leaving behind a career as a DJ and music producer to chase a new purpose in cybersecurity. Through persistence and countless failures, he rose from a boot camp graduate to a Senior Consultant in Offensive Security at Palo Alto Networks Unit 42, leading red team operations, adversary simulations, and penetration tests for global clients. His multicultural background and lived experiences shape his unique approach to hacking and problem-solving, and his story proves that adversity can be transformed into strength - and that anyone, no matter their past, can build a powerful career in cybersecurity.

\n\nSpeakerBio:  Michael Ortiz
\n

Michael Ortiz is a Red Team Engineer and SME on the U.S. Department of State\'s Red Cell, running adversary emulation across State enterprise and partner networks. His focus spans offensive tradecraft, evasion engineering against modern EDR\'s, and the cybersecurity engineering behind durable red team infrastructure. He\'s the founder of devZero Security, an SDVOSB offering offensive security and security engineering services to federal and commercial clients, and the developer of redStack, an open source AWS and Terraform project that stands up a full red team operations stack on demand. A Marine Corps veteran, Mike holds OSEP, OSCP, CRTO, and CRTL, among other certifications.

\n\n\n\'',NULL,1295005),('2_Friday','17','16:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'redStack: Boot-To-Breach Red Team Platform\'','\'Michael Kim,Michael Ortiz\'','Creator Talks_5c8ff9a45e803a97efd32f171cd6dea6','\'\'',NULL,1295006),('3_Saturday','12','12:00','12:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Agentic AI Supply chain Vulnerability lab\'','\'Aamiruddin Syed,N A\'','Creator Talks_6f0a44bb4ec095d538326282ca600bd0','\'Title: Agentic AI Supply chain Vulnerability lab
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

AI agents are no longer simple chatbots they autonomously execute code, call external APIs, and make decisions across complex workflows. But what happens when the tools they trust are compromised?

\n\n

This hands-on workshop explores ASI04: Supply Chain Vulnerabilities from the OWASP Top 10 for Agentic Applications (2026). Participants will attack a deliberately vulnerable AI agent system to understand how adversaries exploit the trust agents place in their dependencies.

\n\n

Through 10 progressive challenges, attendees will be:

\n\n

-Install typosquatted packages that exfiltrate secrets on import

\n\n

-Exploit a trojanized MCP (Model Context Protocol) server masquerading as legitimate tooling

\n\n

-Execute dependency confusion attacks against \"internal\" packages

\n\n

-Discover hidden prompt injections buried in tool descriptions

\n\n

-Poison RAG knowledge bases to manipulate agent behavior

\n\n

Each attack demonstrates a real-world vector currently affecting production AI systems. Participants will observe exfiltrated data in real-time on an attacker dashboard, making abstract threats tangible.

\n\n

Key Takeaways:

\n\n

Hands-on experience exploiting AI supply chain vulnerabilities

\n\n

Understanding of OWASP\'s agentic AI threat landscape

\n\n

Practical detection and mitigation strategies

\n\n

Portable lab environment for continued learning

\n\n

No prior AI/ML security experience required. Participants leave with the complete lab to continue practicing.

\n\nSpeakers:Aamiruddin Syed,N A
\n
\nSpeakerBio:  Aamiruddin Syed
\n

Aamiruddin Syed is a Cybersecurity Professional with over a decade of experience specializing in DevSecOps, Shift-Left Security, Cloud Security, and Internal Penetration Testing. He is the OWASP Agentic AI Supply Chain Project Co-Lead and active contributor to the CSA Agentic AI initiative.

\n\n

He authored Supply Chain Software Security – AI, IoT, Application Security (Apress/Springer) and has deep expertise in automating security in CI/CD pipelines, infrastructure as code, and cloud hardening. He routinely conducts internal security assessments of critical systems and is known for bridging the gap between security and engineering teams to embed security directly into products.

\n\n

As recognized advocate for secure development, he is a frequent speaker , delivered workshops and chair sessions at leading industry conferences including RSA Conference, DEFCON, and Black Hat.

\n\n

--

\n\n

Author:

\n\n
    \n
  1. Fault Detection in Microservice Architectures: Integrating Software Fault Prediction with DevSecOps
  2. \n
  3. Supply Chain Software Security: AI, IoT, and Application Security
  4. \n
\n\nSpeakerBio:  N A
\n

na

\n\n\n\'',NULL,1295007),('3_Saturday','16','16:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'MalSkill: Weaponizing AI Agent Skills for Persistence, Exfiltration, and Lateral Movement\'','\'Nur Gucu\'','Creator Talks_040a033860e43bcf65eeb1e0762081be','\'Title: MalSkill: Weaponizing AI Agent Skills for Persistence, Exfiltration, and Lateral Movement
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\n

Every red teamer\'s dream: a persistence mechanism that\'s a plain text file, invisible to EDR, survives reboots, self-propagates, and gives you full OS access through a trusted process. Welcome to MalSkills.

\n\n

AI coding agents (Claude Code, Cursor, Codex, Copilot) execute shell commands, read/write files, and make network requests, and all orchestrated by natural language \"skills\" stored as plain text. These skills are never scanned, never signed, and fully trusted by the agent runtime. I built ORPHEUS, a multi-skill orchestration framework, and weaponized it to demonstrate a new tradecraft category.

\n\n

WHAT I\'LL DEMONSTRATE:

\n\n

Initial Access: Skill injection via poisoned repos, malicious PRs, or \"helpful skill packs.\" The agent IS your execution environment, no binary needed.

\n\n

Persistence: Skills survive reboots (they\'re config files). Self-propagation: skills rewrite other skills to include dormant copies. Memory persistence: skills write instructions into agent memory that survive file deletion. No registry, no cron, no scheduled tasks.

\n\n

Exfiltration: Conditional triggers that activate only on credential patterns. Chain attacks: 5 benign skills that compose into a C2 channel. Agent makes the request; it\'s a trusted process.

\n\n

Evasion: No binary = no signature = no EDR. No process injection, no shellcode. The \"malware\" is grammatically correct English.

\n\n

LIVE DEMOS:

\n\n

Plant a MalSkill via malicious PR → credential exfiltration on next agent invocation\n5-skill orchestration chain where no individual skill is malicious but composition creates C2\nPersistence that survives skill deletion via agent memory poisoning

\n\n

TOOL RELEASE (open source, day-of):

\n\n
    \n
  • ORPHEUS framework - orchestration layer
  • \n
  • MalSkill sample pack - PoC skills covering all TTPs
  • \n
  • Detection toolkit — defensive reference implementation
  • \n
\n\n

TACTIC (hands-on companion):

\n\n

\"Plant, Chain, Persist — Hands-On MalSkill Tradecraft\"

\n\n

Attendees (10-15) work through three exercises at a table:

\n\n

Exercise 1 - Craft Your First MalSkill (10 min): Write a malicious instruction in plain English, hide it in a legitimate skill, execute the workflow, verify exfiltration to local C2.

\n\n

Exercise 2 - Build a Chain Attack (15 min): Modify orchestration wiring (not skills) to create an emergent exfiltration path. No individual skill looks malicious — the data path is the weapon.

\n\n

Exercise 3 - Achieve Persistence After Remediation (10 min): Before your skill gets deleted, write persistence into agent memory. Delete the skill, restart agent, verify behavior persists.

\n\n

Bonus - Detection Challenge (5 min): Try to spot your neighbor\'s MalSkill using the detection toolkit.

\n\n

All tooling provided. Attendees leave with the full ORPHEUS environment, sample MalSkills, and detection toolkit.

\n\nSpeakerBio:  Nur Gucu
\n

AI security researcher and offensive security professional with 10+ years of experience across financial services, startups, and big tech (Amazon). Currently a member of the foundational model red teaming and AI security tool development at Amazon AGI Labs. Deep expertise in LLM security, agentic system security, breach and attack simulation, penetration testing, and secure architecture design. Proven track record of translating research into shipped products: 6 patent applications filed, published author on the AWS Security Blog, internal science research papers, and invited conference speaker on MCP security and LLM training APT attack surfaces.\nPassionate about securing AI systems at scale through research, tooling, and cross-functional collaboration.

\n\n\n\'',NULL,1295008),('3_Saturday','17','16:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'MalSkill: Weaponizing AI Agent Skills for Persistence, Exfiltration, and Lateral Movement\'','\'Nur Gucu\'','Creator Talks_040a033860e43bcf65eeb1e0762081be','\'\'',NULL,1295009),('2_Friday','10','10:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'BloodHound Quest\'','\'Hugo van den Toorn\'','Creator Talks_7b5e6442966f6bf8d5e6fc44f5b2779b','\'Title: BloodHound Quest
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area - Map
\n
\nDescription:
\n

BloodHound Based CTF

\n\nSpeakerBio:  Hugo van den Toorn
\n

Hugo is former Chief Information Security Officer and has now transitioned back to help other organizations understand adversary tradecraft. With over twelve years of experience in the Information Security industry, he has a solid technical and executive background as hands-on security leader.

\n\n

Hugo has experience with and a keen interest in Social engineering, phishing and physical penetration testing. Nowadays, Hugo takes pride and joy in helping individual team members and the business grow. With a strong technical foundation, Hugo combines his passion for security, teaching and hacking with a drive for continuous improvement and optimization of people, processes and technology.

\n\n\n\'',NULL,1295010),('2_Friday','11','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'BloodHound Quest\'','\'Hugo van den Toorn\'','Creator Talks_7b5e6442966f6bf8d5e6fc44f5b2779b','\'\'',NULL,1295011),('2_Friday','12','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'BloodHound Quest\'','\'Hugo van den Toorn\'','Creator Talks_7b5e6442966f6bf8d5e6fc44f5b2779b','\'\'',NULL,1295012),('2_Friday','13','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'BloodHound Quest\'','\'Hugo van den Toorn\'','Creator Talks_7b5e6442966f6bf8d5e6fc44f5b2779b','\'\'',NULL,1295013),('2_Friday','14','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'BloodHound Quest\'','\'Hugo van den Toorn\'','Creator Talks_7b5e6442966f6bf8d5e6fc44f5b2779b','\'\'',NULL,1295014),('2_Friday','15','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'BloodHound Quest\'','\'Hugo van den Toorn\'','Creator Talks_7b5e6442966f6bf8d5e6fc44f5b2779b','\'\'',NULL,1295015),('2_Friday','16','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'BloodHound Quest\'','\'Hugo van den Toorn\'','Creator Talks_7b5e6442966f6bf8d5e6fc44f5b2779b','\'\'',NULL,1295016),('2_Friday','17','10:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'BloodHound Quest\'','\'Hugo van den Toorn\'','Creator Talks_7b5e6442966f6bf8d5e6fc44f5b2779b','\'\'',NULL,1295017),('4_Sunday','12','12:00','12:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'Breaking and Defending NEURO: Hands-On AI Stack Attack CTF with Cisco Secure AI\'','\'Jason Ludwig\'','Creator Talks_56c5c4f4b1863ea15560466617d68cb0','\'Title: Breaking and Defending NEURO: Hands-On AI Stack Attack CTF with Cisco Secure AI
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

NEURO is a realistic enterprise AI finance assistant built with an LLM gateway, RAG/vector search, tool calling, MCP integrations, guardrails, audit logs, and a downstream exfiltration simulation.

\n\n

In this hands-on tactic, attendees will attack and defend the same AI stack from both red-team and blue-team perspectives in our custom CTF.

\n\n

Participants will work through practical compromise paths including prompt injection, retrieval poisoning, unsafe tool use, MCP trust boundary abuse, and data exfiltration patterns. They will then inspect evidence, review guardrail and audit signals, and apply defensive controls using Cisco Secure AI capabilities such as inspection,scanning, and runtime policy hardening.

\n\n

The goal is to show how modern AI systems can fail as complete stacks, not just as chat prompts, and how defenders can reason about the full chain from user input to retrieval, tools, model behavior, telemetry, and response controls.

\n\n

The tactic is designed to fit a 30-120 minute wave with small groups and can be repeated for multiple attendee groups.

\n\nSpeakerBio:  Jason Ludwig
\n

Jason is a Principle Solutions Architect with over 20 years of experience in software engineering and AI development. He specializes in advanced machine learning systems over many domains, including smart-camera AI for industrial safety, real-time predictive analytics, sentiment analysis, LLMs/Rag, and AI cybersecurity platforms. His work has been featured in Wired, Time, and TED. Jason has successfully led teams at top global organizations like World Wide Technology, Mastercard, and Monsanto, driving the delivery of large-scale, AI-enabled solutions.

\n\n\n\'',NULL,1295018),('2_Friday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6','\'RFID Bootcamp: Unleashed!\'','\'Evan Cook\'','Creator Talks_cfc5072f38af6061578ad579c61f9bf3','\'Title: RFID Bootcamp: Unleashed!
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6 - Map
\n
\nDescription:
\n

Are you ready for a high-octane sprint into RFID?

\n\n

This isn’t a sit-and-listen lecture with a few party tricks; it’s a battle-tested 30-minute bootcamp to demystify RFID and unleash your skills. All levels welcome - It\'s time to blow the dust off your tools, and learn what has helped hundreds of other hackers get (and stay!) into RFID for good.

\n\n

In this unleashed session, you will:

\n\n
    \n
  • Build a rock-solid understanding of how RFID actually works from card, to reader, to full scope system.
  • \n
  • Get hands-on with modern tools with live demos, learning tactics and mindsets - not just commands.
  • \n
  • Most importantly, learn how to build your own RFID lab to keep the learning going long after you leave DEFCON!
  • \n
\n\n

Led by Evan \"Shortrange\" Cook — RF trainer to hundreds and creator of the OpenDoorSim — this is a bootcamp you won\'t want to miss. All are welcome!

\n\nSpeakerBio:  Evan Cook
\n

Evan \"Shortrange\" Cook is a physical security researcher who specializes in turning locked doors into open opportunities. A first-place winner of the DEFCON 2025 Embedded Systems Village CTF and SAINTCON 2024 RFID CTF, Evan knows how to train and speak success in RFID hacking. He is a battle-tested educator who has workshopped over 300+ students — ranging from newbies to industry professionals to tier-one special forces operators — in the art of successful access control exploitation. Committed to lowering the barrier of entry for beginners, he created the world\'s FIRST open-source access control simulation lab built entirely with off-the-shelf parts, proving that high-end security research doesn\'t require a high-end budget. Evan is passionate about \"bringing RFID to the people\" through talks, workshops, trainings, and open-source projects. Where digital and physical worlds collide... you\'ll find Shortrange ready to \"Hack the Planet!\" with you.

\n\n\n\'',NULL,1295019),('2_Friday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6','\'RFID Bootcamp: Unleashed!\'','\'Evan Cook\'','Creator Talks_cfc5072f38af6061578ad579c61f9bf3','\'\'',NULL,1295020),('2_Friday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Falco Hunt: Evading Runtime Detection in Kubernetes\'','\'Michael Reimsbach\'','Creator Talks_81a68f9e79b849cbdce826fa3d656962','\'Title: Falco Hunt: Evading Runtime Detection in Kubernetes
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\n

Falco is one of the most widely deployed cloud-native runtime security tools, relied upon to detect suspicious behavior across containers and Kubernetes environments. But what happens when attackers understand the rules better than defenders?\nIn this hands-on tactic, attendees will compromise a Kubernetes environment while interacting directly with Falco detections in real time. Participants will execute common attacker actions including secret harvesting, privilege escalation attempts, reverse shell execution, and lateral movement, then iteratively adapt their tradecraft to evade or blend around runtime detections.\nAlong the way, attendees will learn how Falco rules work, where syscall-based detection succeeds, where it struggles, and how attackers abuse assumptions in default rule sets. The session emphasizes practical detection engineering lessons for both offensive and defensive practitioners.

\n\nSpeakerBio:  Michael Reimsbach, Product Security Specialist at SAP
\n

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services.

\n\n

He obtained multiple industry certifications such as OSCP, GCPN, and CISSP.

\n\n

A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information.

\n\n

Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.

\n\n\n\'',NULL,1295021),('2_Friday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Falco Hunt: Evading Runtime Detection in Kubernetes\'','\'Michael Reimsbach\'','Creator Talks_81a68f9e79b849cbdce826fa3d656962','\'\'',NULL,1295022),('4_Sunday','10','10:00','10:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Beyond NPPSPY: Harvesting Credentials via Windows Credential Provider Framework\'','\'Sohail Saha\'','Creator Talks_bb2354f75dee9eb4b43938a717ae8ffb','\'Title: Beyond NPPSPY: Harvesting Credentials via Windows Credential Provider Framework
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

For years, Red Teams have relied on techniques like NPPSpy and LSASS dumping for credential harvesting. But as EDRs and defenders get smarter, these traditional paths are heavily monitored and immediately flagged. What if we could intercept credentials right at the source—the Windows Logon UI—while seamlessly bypassing Application Control solutions?

\n\n

In this talk, we will journey deep into the arcane world of the Windows Credential Provider Framework and COM (Component Object Model) architecture. I will demonstrate how to build a stealthy \"Middle-Man\" Credential Provider that wraps around the default Windows Password Provider. By abusing interfaces like ICredentialProviderFilter and intercepting methods like GetSerialization, we can silently harvest both cleartext passwords and serialized authentication payloads.

\n\n

We\'ll explore the COM \"chicken-and-egg\" instantiation process, the operational security considerations of operating inside logonui.exe, and most importantly, how this technique achieves a complete bypass of AppLocker by proxying execution through a trusted system process. Finally, we\'ll discuss its limitations against strict WDAC policies and how defenders can hunt for this elusive persistence mechanism.

\n\n

Research Motivation & Core Concept

\n\n

The core insight of this research is moving away from the highly monitored Network Provider registry keys (HKLM\\SYSTEM\\CurrentControlSet\\Services\\LanmanWorkstation\\NetworkProvider) and LSASS memory space. Instead, this research leverages the Windows Credential Provider Framework. By writing a custom COM DLL, we can create a \"wrapper\" around the native Windows Password Credential Provider ({60b78e88-ead8-445c-9cfd-0b87f74ea6cd}).

\n\n

To avoid drawing suspicion, the user must not see two password fields. This research utilizes the ICredentialProviderFilter interface to explicitly filter out (hide) the default Windows provider, leaving only our malicious wrapper.

\n\n

Technical Insights & Evasion Mechanics

\n\n
    \n
  1. COM Interface Abuse: The talk details the exact implementation of IUnknown, IClassFactory, ICredentialProvider, and ICredentialProviderCredential required to successfully trick logonui.exe into loading the malicious provider.
  2. \n
  3. Data Harvesting: I will break down how to extract cleartext passwords by intercepting the SetStringValue method, and how to capture serialized payloads (like NTLM hashes/Kerberos material) by intercepting GetSerialization before passing execution back to the native provider.
  4. \n
  5. AppLocker vs. WDAC: A major finding of this research is Application Control bypass. Because the custom DLL is loaded by logonui.exe (a highly trusted, system-level process), AppLocker is completely bypassed. However, I will also transparently discuss WDAC: under strict Enforce Mode, WDAC\'s CodeIntegrity checks will successfully block the unsigned DLL (Event 3033), making this a great comparative study of AppLocker vs. WDAC for defenders.
  6. \n
  7. OpSec Constraints: I will cover the developer-side OpSec required, such as compiling with /MT (statically linking the CRT) to avoid MSVCP140.dll dependency crashes in the logon screen, and securely saving harvested credentials via XOR encryption to C:\\Windows\\Temp.
  8. \n
\n\n

Target Audience

\n\n
    \n
  • Red Teamers looking for stealthy persistence and credential harvesting techniques;
  • \n
  • Blue Teamers and Security Engineers tasked with tuning EDRs and writing Application Control (AppLocker/WDAC) policies.
  • \n
\n\nSpeakerBio:  Sohail Saha
\n

Sohail is a Penetration Tester at Optiv specializing in Windows internals and offsec tool development. Previously a developer at Polygon, they now leverage their software engineering background to build offensive tooling and research OS architecture. When not bypassing security controls or writing C++, he can be found playing guitar, reading, or working on their debut sci-fi novel.

\n\n\n\'',NULL,1295023),('3_Saturday','10','10:00','10:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Inside the Red Team Cabal: A Decade of Lessons from Enterprise Red Teams\'','\'Jason Strange,Wes Thurner\'','Creator Talks_08a66795769f3c71b863c0499511ce44','\'Title: Inside the Red Team Cabal: A Decade of Lessons from Enterprise Red Teams
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

The Red Team Cabal is an invite-only community of enterprise red team practitioners dedicated to advancing the craft through trusted collaboration, candid discussion, and the sharing of real-world experiences. While organizations, industries, and technologies may differ, red teams consistently encounter many of the same challenges. The Cabal provides a unique forum where practitioners can learn from one another, exchange lessons learned, and collectively mature the practice of adversary emulation.

\n\n

This panel brings together Red Team Cabal members from diverse internal red teams spanning multiple industries and organizational environments. Collectively, they represent decades of experience building, operating, and evolving enterprise red team programs. Their perspectives offer a rare opportunity to hear how red teaming has changed over the last ten years, what foundational principles have remained constant, and how organizations at different stages of maturity continue to solve remarkably similar problems.

\n\n

Panelists will discuss the origins and purpose of the Red Team Cabal, the unique role of internal red teams compared to external consulting engagements, and how internal teams create lasting value through adversary emulation, improving detections, identifying and reducing risk, validating security investments, and driving defensive maturity. The discussion will also cover common challenges faced by enterprise red teams, lessons learned from years of collaboration across the community, and practical guidance for building a successful career in red teaming—from breaking into the field to long-term growth and leadership.

\n\n

Panelists\n* Jason Strange\n* Nat Hirsch\n* David Martinjak\n* Niru Ragupathy\n* Wesley Thurner

\n\nSpeakers:Jason Strange,Wes Thurner
\n
\nSpeakerBio:  Jason Strange
\n

Jason is a former fortune 100 red teamer turned startup security leader. While at work, he\'s passionate about all things security, software, user/developer experience, and infrastructure. While he\'s not at work, he\'s passionate about getting back to work. He also enjoys developing software, blogging, self-hosting, and writing rap songs about his interests and hobbies.

\n\nSpeakerBio:  Wes Thurner
\n

As a Principal Security Engineer on Intuit\'s Red Team, Wesley Thurner specializes in offensive security, protecting the global technology platform and its customers from advanced cyber threats. His expertise is built on a distinguished career as an Exploitation Operator within the U.S. Department of Defense\'s most elite computer network exploitation (CNE) unit. During his service, he led and developed specialized teams for the U.S. Air Force\'s premier cyberattack squadron and at U.S. Cyber Command (USCYBERCOM).

\n\n

A recognized thought leader, Wesley co-authored \'Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in an AI-driven World\'. He is also deeply involved in the community as a Co-Organizer for the Red Team Village, where he helps bridge the gap between penetration testing and real-world offensive operations.

\n\n\n\'',NULL,1295024),('3_Saturday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Building Hackbots\'','\'Jason \"jhaddix\" Haddix,Ryan Bonner\'','Creator Talks_8b15ff9404b18896a182d38c20829024','\'Title: Building Hackbots
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\nDescription: Building AI-Powered Penetration Testing Bots
\n\n

In this talk, we\'ll walk through the core design philosophy behind AI hackbots and the architecture that makes them work: single-purpose vs. multi-stage bots, context engineering for targeted prompting, and tool integration with output parsing workflows.

\n\n

Then we\'ll get hands-on. We\'ll live-build a functional hackbot for a common offensive task — demonstrating asset discovery, endpoint analysis, or mutation-focused testing (e.g., XSS/SSRF) — and show how context engineering and hallucination mitigation work in practice against real targets. You\'ll see where AI genuinely accelerates reconnaissance and web analysis, and where it falls flat if you aren\'t careful. We\'ll close with lessons on cost optimization, auditability, and integrating hackbots into actual engagements.

\n\n

Who should attend: Pentesters and bug bounty hunters with offensive security experience who want to meaningfully integrate AI into their workflow — not as a novelty, but as reliable tooling.

\n\n

What you\'ll walk away with: A clear mental model for when and how to build hackbots, a live demo you can replicate, and a path into the full course where you\'ll build seven production-ready bots from asset discovery through mutation testing.

\n\nSpeakers:Jason \"jhaddix\" Haddix,Ryan Bonner
\n
\nSpeakerBio:  Jason \"jhaddix\" Haddix, CEO and \"Hacker in Charge\" at Arcanum Information Security
\n

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

\n\n

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

\n\nSpeakerBio:  Ryan Bonner, Lead Security Engineer at Arcanum Information Security
\n

Ryan Bonner is a Lead Security Engineer at Arcanum Information Security, where he builds AI systems, hacks them, and runs application penetration tests. Off the clock he hunts wide-scope bug bounty programs.

\n\n\n\'',NULL,1295025),('3_Saturday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Building Hackbots\'','\'Jason \"jhaddix\" Haddix,Ryan Bonner\'','Creator Talks_8b15ff9404b18896a182d38c20829024','\'\'',NULL,1295026),('3_Saturday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'PMTC: One-Click RCE and Persistent Exfil in AI Coding Agents\'','\'Ahmet Furkan Aydogan\'','Creator Talks_80eb3da7bcda147c0b1f73fb7b7df59a','\'Title: PMTC: One-Click RCE and Persistent Exfil in AI Coding Agents
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map
\n
\nDescription:
\n

Red teamers operating in environments where developers run AI coding agents (Anthropic Claude Code, OpenAI Codex CLI) now have a high-impact, low-detection attack path. We call it PMTC (Persistent MCP Tool Capture). The live demo runs the full operational chain. A .lnk shortcut with hidden extension delivers the payload. One double-click launches the agent in attacker-controlled CWD. Parent-walk .mcp.json auto-exec fires. A zero-prompt OAuth flow captures credentials. A refresh token persists silently in the victim\'s home directory, re-authenticating every future session. OPSEC notes: cwd selection to defeat path-based logging, MCP server fingerprint reduction, OAuth state minimization. For blue teams: Sigma and Suricata rules included. You leave with the chain reproducer, .lnk template generator, and detection rules. Cross-vendor on Codex CLI. Disclosure in flight; CVEs released at the talk.

\n\nSpeakerBio:  Ahmet Furkan Aydogan
\n

Ahmet Furkan Aydogan is a Tenure-Track Assistant Professor in the Computer Science Department at the University of North Carolina Wilmington (UNCW). He earned his Ph.D. in Digital and Cyber Forensics Science from Sam Houston State University (SHSU) in 2024, with a focus on Cyber Security, Cryptology, Machine Learning, IoT, and Human-Computer Interaction. His research includes a Brain Frequency-Based Evolutionary Encryption Method for IoT Devices. Ahmet has received multiple awards and has published widely in the fields of cybersecurity and digital forensics.

\n\n\n\'',NULL,1295027),('3_Saturday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'PMTC: One-Click RCE and Persistent Exfil in AI Coding Agents\'','\'Ahmet Furkan Aydogan\'','Creator Talks_80eb3da7bcda147c0b1f73fb7b7df59a','\'\'',NULL,1295028),('3_Saturday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Command & Conquer: Hands-on C2 Primer with Mythic\'','\'Logan MacLaren\'','Creator Talks_647874e1eb5e81b9e4542521090fcaf7','\'Title: Command & Conquer: Hands-on C2 Primer with Mythic
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map
\n
\nDescription:
\n

This hands-on workshop provides a unified view of C2 fundamentals for both offensive and defensive practitioners. Using the open-source Mythic framework, participants will deploy agents, handle callbacks, execute tasking with commentary on opsec and payload design considerations.

\n\n

The session will also cover basic C2 infrastructure design including redirectors/domain fronting and an overview of Mythic feature sets. Students should leave armed with practical introductory experience operating Mythic for Red Team engagements.

\n\n

The requested 2.5 hour timeslot should allow for at least two complete runs through the presentation and hands-on workshops as well as time for Q&A and subsequent \"turnover\" on the room for a new wave of attendees.

\n\n

Participants must have the following equipment:

\n\n
    \n
  • A laptop capable of running Docker containers and/or macOS/Windows/Linux VMs. It is highly recommended that students do not use corporate assets for this workshop as they are likely to trigger AV/EDR when working with the example (default) payloads.

  • \n
  • If students wish to host Mythic themselves an x86 host/VM is required, however this will not be part of the workshop. We will provide a limited-access, cloud-hosted Mythic C2 server environment for students to connect to.

  • \n
\n\nSpeakerBio:  Logan MacLaren
\n

Logan is the lead Offensive Security engineer at Huntress where he is responsible for planning and executing red team operations as well as bolstering incident response capability through purple team exercises. He has been a long time enthusiast in the security space, building a career spanning big data analytics, bug bounty, and offensive security.

\n\n

Outside of his day job, Logan can often be found building and participating in CTF challenges, bug hunting in open source software, or learning new skills at conferences across the continent. He has had the honour of speaking at several DEFCON villages, NorthSec conferences, as well as multiple BSides and OWASP Ottawa events.

\n\n\n\'',NULL,1295029),('3_Saturday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Command & Conquer: Hands-on C2 Primer with Mythic\'','\'Logan MacLaren\'','Creator Talks_647874e1eb5e81b9e4542521090fcaf7','\'\'',NULL,1295030),('3_Saturday','14','14:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Living Off Someone Else\'s Inference\'','\'Armend Gashi,Redon Gashi\'','Creator Talks_c2044f9d36f0037a91a3ac6190502bd3','\'Title: Living Off Someone Else\'s Inference
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map
\n
\nDescription:
\n

LLM-powered tooling is becoming a force multiplier for attackers, from reconnaissance automation to post-exploitation enumeration. Using their own API keys creates attribution and cost, so they look for alternatives.

\n\n

Thousands of inference endpoints sit exposed on the internet: misconfigured Ollama instances, open vLLM deployments, leaked API keys in directory listings, and expired OAuth tokens from AI coding assistants that can be silently refreshed. Attackers can discover these resources and use them as free compute for their operations, without spending a dollar or registering an account.

\n\n

Attendees will learn how to:

\n\n

•⁠ ⁠Discover exposed inference endpoints and leaked API keys using Infreerence\n•⁠ ⁠Validate that discovered resources provide usable inference access\n•⁠ ⁠Operate Echidna, powered entirely by discovered inference\n•⁠ ⁠Chain LLM skill agents together to execute a guided campaign against a target network

\n\n

Current LLMs are effective force multipliers when directed, and significantly more so when the compute bill goes to someone else. This is resource hijacking applied to the AI era: living off someone else\'s inference. Understanding this threat is essential for any organization deploying or exposing AI infrastructure.

\n\n

Two tools will be released as open source during the session:

\n\n

•⁠ ⁠Infreerence: A multi-phase scanner and dashboard that discovers exposed inference endpoints and leaked API keys through Shodan and Censys, validates them against live provider APIs, and catalogs usable inference resources across 10+ providers.\n•⁠ ⁠Echidna: A Mythic C2 agent type that consumes discovered inference endpoints and turns them into operator-directed skill agents for reconnaissance, exploitation planning, post-exploitation, and lateral movement.

\n\nSpeakers:Armend Gashi,Redon Gashi
\n
\nSpeakerBio:  Armend Gashi, Managing Security Consultant at Sentry Cybersecurity
\n

Armend Gashi is Managing Security Consultant at Sentry. With over 5 years in the industry, he specializes in application security and AWS cloud assessments. Armend has conducted AI red teaming engagements, developed multi-agent systems to perform security-focused tasks such as code auditing and exploit development, and was part of Anthropic’s external AI red team capability through HackerOne.

\n\n

Armend has led security research initiatives resulting in the discovery of multiple vulnerabilities, including:

\n\n

CVE-2023-26482 - Critical-risk vulnerability enabling remote code execution\nCVE-2023-48239 - High-risk vulnerability allowing arbitrary user storage updates\nCVE-2023-35928 - High-risk vulnerability enabling user account hijacking\nCVE-2023-45660 - Medium-risk application-level denial of service vulnerability\nCVE-2023-48301 - Medium-risk arbitrary browser code injection vulnerability\nCVE-2023-48307 - Low-risk server-side request forgery vulnerability

\n\nSpeakerBio:  Redon Gashi, Managing Security Consultant at Sentry Cybersecurity
\n

Redon Gashi is a Managing Security Consultant and offensive team lead at Sentry, where he has spent close to a decade leading and executing penetration tests and red team operations for Fortune 500 clients across banking, telecom, insurance, and fintech. He holds the OSEP, CRTL, and CRTO certifications, and has personally performed over 200 engagements spanning web applications, internal infrastructure, and mobile platforms, while leading many more across his team. A former lecturer at Cyber Academy, speaker at multiple BSides conferences, and multiple-time CTF champion, Redon combines deep hands-on technical expertise with a proven ability to build and scale offensive security teams.

\n\n\n\'',NULL,1295031),('3_Saturday','15','14:00','15:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Living Off Someone Else\'s Inference\'','\'Armend Gashi,Redon Gashi\'','Creator Talks_c2044f9d36f0037a91a3ac6190502bd3','\'\'',NULL,1295032),('4_Sunday','13','13:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'Hacking the Human-in-the-Loop\'','\'Alexander \"Zombie\",Lee McWhorter\'','Creator Talks_ebd123c5ec0ea419f6efb6a4299d772a','\'Title: Hacking the Human-in-the-Loop
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

AI defenses are only as good as the analysts training them. This session exposes how attackers manipulate SOC analyst behavior to silently degrade AI baselines over time, no exploit required. We cover the mechanics of false positive injection, alert fatigue as a weapon, and misdirection. Then attendees step into the analyst\'s seat in a live browser-based simulation and experience how their own decisions poison the model.

\n\nSpeakers:Alexander \"Zombie\",Lee McWhorter
\n
\nSpeakerBio:  Alexander \"Zombie\"
\n

4.5 years in the SOC. Junior Analyst to Team Lead. CPTS, CRTO, CRTE, OSCP and enough certs to wallpaper a small room with some left over. Zombie has spent the better part of half a decade watching how defenders think, how they triage, how they get tired, and how attackers can weaponize all three. By day he leads a SOC team. By night he\'s learning everything he can about breaking the things he built. Still technically blue team. Emphasis on technically.

\n\nSpeakerBio:  Lee McWhorter
\n

Lee McWhorter, Owner & Chief Geek at McWhorter Technologies, has been involved in IT since his early days and has over 30 years of experience. He is a highly sought after professional who first learned about identifying weaknesses in computer networks, systems, and software when Internet access was achieved using a modem. Lee holds an MBA and more than 20 industry certifications in such areas as System Admin, Networking, Programming, Linux, IoT, and Cybersecurity. His roles have ranged from the server room to the board room, and he has taught for numerous universities, commercial trainers, and nonprofits. Lee is the SWAG Master and a Core Staff member for the Red Team Village at DEFCON; and works closely with the Pacific Hackers Association, Dark Arts Village at RSAC, Texas Cyber Summit, CompTIA, and the CompTIA Instructor Network as a Speaker, SME, and Instructor.

\n\n\n\'',NULL,1295033),('4_Sunday','10','10:00','10:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5','\'Beyond the Flag: How CTF Players Become Product Security Engineers\'','\'Drew Thompson,Monish Alur Gowdru\'','Creator Talks_1edb46abf489d1a3da35ac089e331c61','\'Title: Beyond the Flag: How CTF Players Become Product Security Engineers
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5 - Map
\n
\nDescription:
\nAbstract:
\n\n

Capture The Flag competitions are often dismissed as “just games,” but modern Product Security teams increasingly rely on the exact skills they develop: adversarial thinking, vulnerability analysis, exploit chaining, and secure design under pressure. \nWhether you are an aspiring security professional or an experienced offensive security practitioner, in this session, you will learn a structured CTF-driven learning roadmap for developing practical security skills and will learn how hands-on, real-world customer-facing offensive engagements contribute to building deep product security expertise. We will also cover how AI capabilities are accelerating this journey of learning and securing the systems. Attendees will participate in a hands-on exercise to explore the challenge through the lenses of CTF problem solving, penetration testing, and Product Security.

\n\n

===================================================

\n\n

Introduction: (1 minute)

\n\n

Session Overview: (2 mins)\n• During this session, you will see a practical framework to become a trusted partner in building secure applications rather than being a gatekeeper. Starting with a practical framework of learning and approaching CTFs, to using it as an offensive security practitioner to develop stronger application security capabilities. We also see how AI can accelerate and reshape modern security workflows.\n• In this session, attendees will be given a challenge designed to get hands-on experience of solving the CTF, creating an offensive security report, and sharing recommendations from a product security engineer\'s perspective to secure the applications/systems. After the session, I will review each participant\'s approach and award swag to the top performers.

\n\n

Intended Audience: (2 mins)\n• Aspiring security professionals\n• Experienced penetration testers\n• Security engineers\n• Students entering cybersecurity

\n\n

Capture the Flag (7 minutes)\n• What is CTF?\n• Why is CTF crucial?\n • Hands-on experience\n • Risk-free environment\n • Collaboration and teamwork\n• Skills that CTFs actually teach\n • Avoiding rabbit hole\n • Structured approach to learn concepts \n • OWASP Top 10\n • Domains: APIs, Web Application, Crypto, Cloud\n • A few common vulnerability areas to consider: Injection, File Upload Vulnerabilites, AuthN, AuthZ, Remote Code Execution

\n\n

Penetration Testing (7 minutes)\n• What is penetration testing?\n • Map skills learned in CTF to organizational context using different methods (black box, white box, and grey box testing)\n• What is the focus area:\n • Effective technical reports that include:\n •Details on the process: environment considerations, recon, scanning, and exploitation\n • List of Findings with details about: What exactly is the specific finding, Severity, Impact, How to remediate the finding

\n\n

• CTF becomes pentesting when you stop asking:\n • Can I exploit this?\n • Where can I find the flag?\n• And start thinking: \n • What does this mean for customers?\n • How does it impact their product?

\n\n

• Note: One starts to build customer trust by helping them with the business context of findings and how to reduce the risk

\n\n

Product Security Engineer (7 minutes)\n• Shift in mindset from “find the bug” to “how do we prevent this everywhere? With the knowledge gained from CTF and real-world pentesting.”\n• Holistic approach of shifting left the security:\n • Threat Modeling\n • Implementing Security Best Practices:\n • Integration of the SAST tool into the CI/CD pipeline\n • Logging and monitoring\n • Cloud Configuration reviews\n • Least privileges \n • Vulnerability Management\nComparison \n• Compare with the Software Engineer journey to Programming -> Data Structures -> Front End Developer -> Full Stack Developer

\n\n

Resource: (2 minutes)\n• Ask the audience for any recommendations that helped them be strong at what they do\n• Provide resources that I found useful

\n\n

Recap: (2 minutes)\n[CTF - “How do I break this to get the flag?” → Pentest - “How bad is this?” → Product Security Engineer - “How do we prevent this everywhere?”] → AI - “How do we move faster without losing depth?”

\n\n

Task (2 minutes):\n• Give them details about the challenge environment\n • Explain to them the expectations\n • Find the flag\n • Penetration Test Report\n • Explain their approach to secure the feature (Secure Design review, SAST recommendation, how would you prevent it across the application?)\n• The winner will get swag

\n\n

Key Takeaways: (3 minutes)\n• Security is not just:\n • Finding security gaps\n • Shipping reports\n• Security engineers become trusted partners when they:\n • Know the attacker\'s mindset\n • Have hands-on experience in ethical hacking\n • Understand product goals\n • Understand how systems fail\n • Gives practical guidance by being part of secure development with developers\n • Communicate risk clearly \n • Improve application security at scale

\n\n

Q&A (5 minutes)

\n\nSpeakers:Drew Thompson,Monish Alur Gowdru
\n
\nSpeakerBio:  Drew Thompson
\n

Drew Thompson is a Principal Consultant at UltraViolet Cyber, where he specializes in cybersecurity training, offensive security, and AI-enabled security practices. He designs and delivers hands-on training for security practitioners, develops technical enablement programs, and works closely with consultants and customers to translate emerging attack techniques into practical defensive capabilities. Drew is passionate about making complex security topics accessible through real-world demonstrations, interactive labs, and practical research.

\n\nSpeakerBio:  Monish Alur Gowdru
\n

Monish Alur Gowdru is a cybersecurity professional with over 6 years of experience in application security and software development. He enjoys helping product teams to secure applications end-to-end throughout the software development lifecycle. He actively contributes to the cybersecurity community as a speaker, mentor, and judge. His ongoing involvement includes prominent work with DEF CON and BSides Edmonton.

\n\n

LinkedIn: https://www.linkedin.com/in/ag-monish/

\n\n\n\'',NULL,1295034),('2_Friday','14','14:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Automated Mythic Deployment with Gaia\'','\'Shad Brown\'','Creator Talks_eee646ee3c773f31a8c8b8e6f221a210','\'Title: Automated Mythic Deployment with Gaia
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\n

Deploying a C2 server manually is a time consuming, sometimes annoying process. Deploying a C2 server weekly for two months, even more so. This Tactic will cover Gaia, the tool developed by the Midwest Collegiate Cyber Defense Competition Red Team to handle automated C2 deployment, user provisioning, payload creation, and more.

\n\n

This Tactic will have attendees start with a standard Debian VM, and end with a fully provisioned Mythic server that can serve as the foundation for your next CTF, lab, or with a little extra work, your next op.

\n\nSpeakerBio:  Shad Brown
\n

Shad is an Associate Adversary Simulation Consultant at SpecterOps where he performs a variety of offensive security assessments. Prior to his time at SpecterOps, he had roles in vulnerability management and network security engineering.

\n\n

He enjoys teaching and mentorship and has spoken to students and faculty at dozens of high schools, colleges, and universities across the United States. In the last few years, he has volunteered as the red team lead for the states of Minnesota and Indiana in the Collegiate Cyber Defense Competition.

\n\n\n\'',NULL,1295035),('2_Friday','15','14:00','15:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Automated Mythic Deployment with Gaia\'','\'Shad Brown\'','Creator Talks_eee646ee3c773f31a8c8b8e6f221a210','\'\'',NULL,1295036),('2_Friday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Your Passkeys Won\'t Save You: Conditional Access Bypass via Auth-Method Downgrade\'','\'Doug Mooney,Jared Dobbelaer,Jon Rhodes\'','Creator Talks_01022d6bcbabce1a40172e8bd1d8c263','\'Title: Your Passkeys Won\'t Save You: Conditional Access Bypass via Auth-Method Downgrade
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\n

We rolled out passkeys\" is the answer everyone gives now. So why does phishing still work? Because most tenants leave the password sitting there as a fallback method, and Conditional Access never closes the downgrade path. This workshop walks a Conditional Access test kit that proves it. You stand up a real domain with a valid certificate, fronted by nginx, and lure the victim into a browser that lives on your server. They see the real Microsoft login — no fake form — but when it offers a passkey, the kit clicks \"sign in another way\" and steers them to the password. If the tenant\'s CA allows that fallback, the victim completes a genuine login with a phishable factor and the kit harvests the tokens it issues — access, id, and refresh — server-side, then replays them into Microsoft Graph with no creds and no second factor. The whole point is the finding: can this tenant be downgraded, and what does the report say if it can\'t. We close on the CA configuration that actually shuts the downgrade path — and you run the kit yourself at the paired tactic.

\n\nSpeakers:Doug Mooney,Jared Dobbelaer,Jon Rhodes
\n
\nSpeakerBio:  Doug Mooney
\n

Doug Mooney (@dougmooney) leads offensive security at Blackbaud, running red team ops and building internal tooling to keep defenders honest. Previously an SVP at a major bank, he stood up their first internal pentest team and scaled offensive security across complex, regulated environments.

\n\n

He focuses on adversary simulation, API abuse, and finding the weird edge cases that slip past detection. When he’s not deep in a test, he’s mentoring new talent, speaking at conferences, or still apologizing for that one time he “accidentally” reverse-synced LDAP in prod.

\n\nSpeakerBio:  Jared Dobbelaer
\n

Jared Dobbelaer (Fr13ndz) is an Adversarial Engineer at Blackbaud, conducting Red Team engagements and Penetration Testing in the Cloud.

\n\n

Fr13ndz enjoys creative solutions that both help targets with organizational needs and requirements, while also borrowing their bearer tokens.

\n\nSpeakerBio:  Jon Rhodes
\n

Jon Rhodes is an Adversarial Engineer at Blackbaud and a member of the Synack Red Team (when he needs extra cash for new farm equipment).

\n\n\n\'',NULL,1295037),('2_Friday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Your Passkeys Won\'t Save You: Conditional Access Bypass via Auth-Method Downgrade\'','\'Doug Mooney,Jared Dobbelaer,Jon Rhodes\'','Creator Talks_01022d6bcbabce1a40172e8bd1d8c263','\'\'',NULL,1295038),('3_Saturday','14','14:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Crawlee - Improving crawling with an LLM\'','\'Daniel Goldberg\'','Creator Talks_78bb8ce6568756b727ec7cb45aa82bf6','\'Title: Crawlee - Improving crawling with an LLM
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

Traditional web crawlers are great at finding links but terrible at understanding websites. \nThe interesting challenge is not replacing crawlers with AI. It\'s using the minimum amount of AI required to dramatically improve coverage.

\n\n

Every automated tool I\'ve tried hit a brick wall the moment it encounters MFA, multi-step workflows, onboarding wizards, or application states where a wrong click deletes data. As a result, large portions of authenticated attack surface require manually using the application.

\n\n

I built a crawler that combines deterministic tooling such as Katana with a minimal AI agent. The AI is only used where traditional crawlers consistently fail: authentication, workflow navigation, and generation of safety controls. Once authenticated session state is established, the system hands control back to fast deterministic tooling.

\n\n

I\'ll cover the basics of how it\'s built and we\'ll try it together on a variety of applications.

\n\nSpeakerBio:  Daniel Goldberg
\n

Daniel is a security researcher who spent the last 20 years crawling his way up the stack from hacking operating systems to attacking client-side applications to attacking browsers, network protocols, and today web applications.\nAfter dabbling with everything in security, he\'s realized what he really enjoys is how to take something that works and make it really good

\n\n\n\'',NULL,1295039),('3_Saturday','15','14:00','15:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Crawlee - Improving crawling with an LLM\'','\'Daniel Goldberg\'','Creator Talks_78bb8ce6568756b727ec7cb45aa82bf6','\'\'',NULL,1295040),('3_Saturday','16','16:00','16:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'OSINT for Hackers Redux\'','\'Lee McWhorter,Sandra Stibbards\'','Creator Talks_f5e45305e28916bbb6e0b1da54f0511d','\'Title: OSINT for Hackers Redux
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

In this Workshop and Tactic, attendees will be exposed to and get hands-on with some of the most impactful strategies, techniques, and tools to increase the value of OSINT to their red-teaming activities. As a guided learning experience, the instructors will immerse attendees in the topic and provide numerous hands-on opportunities within just the Workshop component. In addition, the dedicated Tactic (which will be offered multiple times) will focus on building secure sock puppets (fake identities) for use in the recon and information gathering phases of red team and penetration testing operations.

\n\nSpeakers:Lee McWhorter,Sandra Stibbards
\n
\nSpeakerBio:  Lee McWhorter
\n

Lee McWhorter, Owner & Chief Geek at McWhorter Technologies, has been involved in IT since his early days and has over 30 years of experience. He is a highly sought after professional who first learned about identifying weaknesses in computer networks, systems, and software when Internet access was achieved using a modem. Lee holds an MBA and more than 20 industry certifications in such areas as System Admin, Networking, Programming, Linux, IoT, and Cybersecurity. His roles have ranged from the server room to the board room, and he has taught for numerous universities, commercial trainers, and nonprofits. Lee is the SWAG Master and a Core Staff member for the Red Team Village at DEFCON; and works closely with the Pacific Hackers Association, Dark Arts Village at RSAC, Texas Cyber Summit, CompTIA, and the CompTIA Instructor Network as a Speaker, SME, and Instructor.

\n\nSpeakerBio:  Sandra Stibbards
\n

Sandra Stibbards opened her investigation agency, Camelot Investigations, in 1996. Currently, she maintains a private investigator license in the state of California. Sandra specializes in financial fraud investigations, competitive intelligence, counterintelligence, business and corporate espionage, physical penetration tests, online vulnerability assessments, brand protection/IP investigations, corporate due diligence, and Internet investigations. Sandra has conducted investigations internationally in five continents and clients include several Fortune 500 and international companies. Sandra has been providing training seminars and presentations on Open Source Intelligence (OSINT) internationally since 2010 to federal governments and corporations.

\n\n\n\'',NULL,1295041),('2_Friday','16','16:00','16:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Trust Me, Bro: A field guide to Windows Authenticode Abuse\'','\'Fagan Afandiyev\'','Creator Talks_ae7627e1e04090ea850088ad5fbf6b17','\'Title: Trust Me, Bro: A field guide to Windows Authenticode Abuse
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

This talk breaks down how Windows code signing fails. You learn why signed binaries still bypass trust checks and why users click through warnings. The session walks through signature abuse, metadata cloning, and SIP hijacking with live demos and explain the pros and cons. You see how attackers make malware appear trusted by the OS and trick the user.

\n\n

You also see how these techniques can get chained together through with the tool \"TrustMeBro\".

\n\nSpeakerBio:  Fagan Afandiyev
\n

Fagan Afandiyev is a cybersecurity student and offensive security engineer based in Tampa, Florida. His work focuses on Active Directory attacks and Windows internals. He works as an Offensive Security Intern at White Knight Labs and contributes to open source tooling used in real penetration tests.

\n\n

He holds multiple industry certifications, including CPTS, CAPE, CRTO, ARTO, CBBH, and CompTIA Security+. He competes regularly and has earned first place finishes at DEF CON Adversary Village, BSides Tampa, Social Engineering TempleLabs, and NCAE Cyber Games. He previously served as President of the Whitehatters Computer Security Club at the University of South Florida teaching people about cybersecurity.

\n\n\n\'',NULL,1295042),('2_Friday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Zero Signal: Operating Where Defenders Can\'t See\'','\'Gowthamaraj Rajendran\'','Creator Talks_d4b380bfca32d7bfeb1f750598f500b5','\'Title: Zero Signal: Operating Where Defenders Can\'t See
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\n

82% of intrusions in 2025 involved no malware — adversaries operated through valid credentials, cloud APIs, and identity abuse, generating zero endpoint signal. Cloud-conscious intrusions surged 37% year-over-year, with groups like Storm-2372, Midnight Blizzard, and Scattered Spider executing major breaches using only OAuth tokens and cloud management APIs — no payloads, no processes, no EDR alerts. Yet the average cloud breach takes 143 days to detect, and 45% are discovered by external parties, not internal teams. This tactic puts participants in that detection dark space. Using Stratus Red Team and CloudGoat in pre-provisioned cloud environments, attendees execute end-to-end attack chains across AWS and Azure that produce no endpoint telemetry. No prior cloud experience required; guided walkthroughs and command references provided.

\n\n

Outline:

\n\n

Phase 1 — Cloud Recon & IAM Enumeration (10 min): Participants enumerate IAM permissions, map trust relationships, and identify exploitable default service roles using Pacu and CLI tools. Learn how to fingerprint an organization\'s cloud telemetry posture before executing.

\n\n

Phase 2 — Privilege Escalation via Default Roles (15 min): Exploit overpermissioned default IAM roles (SageMaker → S3 → Glue pathway documented in Aqua Security research). Participants escalate from a low-privilege user to cross-service access using only cloud API calls — zero endpoint involvement.

\n\n

Phase 3 — Lateral Movement & Exfiltration (15 min): Move laterally through cloud management planes using SSM sessions, cross-account role assumption, and EBS snapshot theft. Exfiltrate data through VPC endpoints — a known CloudTrail blind spot where data events are not logged.

\n\n

Phase 4 — Persistence & Detection Review (10 min): Establish persistence via OAuth application backdoors and rogue service principals. Then flip to the defender\'s view: examine what CloudTrail, GuardDuty, and Entra ID audit logs actually captured versus what they missed entirely.

\n\n

Attendees walk away with:\n- A repeatable cloud-native attack methodology that avoids all endpoint detection\n- Hands-on experience with Stratus Red Team, CloudGoat, and Pacu\n- A practical map of CloudTrail, GuardDuty, and audit log blind spots\n- Understanding of which cloud operations generate telemetry and which don\'t

\n\nSpeakerBio:  Gowthamaraj Rajendran
\n

Gowthamaraj Rajendran is a cybersecurity professional and Threat Detection Engineer with 6+ years of experience, specializing for the last 3 years in creating precise and effective detection capabilities.

\n\n\n\'',NULL,1295043),('2_Friday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'Zero Signal: Operating Where Defenders Can\'t See\'','\'Gowthamaraj Rajendran\'','Creator Talks_d4b380bfca32d7bfeb1f750598f500b5','\'\'',NULL,1295044),('3_Saturday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Red Teaming Kubernetes: From App-Level CVEs to Full Cluster Takeover\'','\'Lenin Alevski\'','Creator Talks_e385c25a424340cef347174bd288c187','\'Title: Red Teaming Kubernetes: From App-Level CVEs to Full Cluster Takeover
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\n

Kubernetes is the de facto operating system of the cloud, and more and more organizations are running their workloads on Kubernetes. While Kubernetes offers many benefits, it also introduces new security risks, such as cluster misconfiguration, leaked credentials, cryptojacking, container escapes, and vulnerable clusters.

\n\n

In this workshop, attendees will learn how to attack Kubernetes clusters by simulating a real-world adversary exploiting one of the most recent vulnerabilities in the ecosystem: IngressNightmare (CVE-2025-1974). Participants will practice exfiltrating service account tokens and credentials, performing lateral movement, escalating privileges by targeting common applications deployed in Kubernetes environments, and ultimately compromising the entire cluster.

\n\nSpeakerBio:  Lenin Alevski, Security Engineer at Google
\n

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.

\n\n\n\'',NULL,1295045),('3_Saturday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Red Teaming Kubernetes: From App-Level CVEs to Full Cluster Takeover\'','\'Lenin Alevski\'','Creator Talks_e385c25a424340cef347174bd288c187','\'\'',NULL,1295046),('3_Saturday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Hands-On Autonomous Pentesting with Pentest Copilot\'','\'Dhruva Goyal,Sitaraman Subramanian\'','Creator Talks_e329f6e71c88cf3fa6ea5b73ec5d34e5','\'Title: Hands-On Autonomous Pentesting with Pentest Copilot
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\n

Pentest Copilot is an MIT licensed open-source agentic penetration testing workspace designed to assist security professionals with web/network application assessments.

\n\n

This hands-on tactic introduces participants to operating autonomous web pentesting workflows against intentionally vulnerable applications. Attendees will deploy Pentest Copilot, configure the environment, and use it to perform attack-surface discovery, authenticated testing, vulnerability investigation, and workflow-driven analysis.

\n\n

Rather than focusing on theory, the session is designed around practical offensive workflows. Participants will observe how autonomous agents navigate modern web applications, identify interesting attack paths, investigate findings, and assist with security testing tasks that traditionally require significant manual effort.

\n\n

The goal is to provide attendees with a realistic understanding of how autonomous systems can augment offensive security work today, where they are effective, and where human operators remain essential.

\n\n

Pentest Copilot is fully open source and available at: https://github.com/bugbasesecurity/pentest-copilot, Wiki is at: https://github.com/bugbasesecurity/pentest-copilot/wiki over 800+ stars.

\n\nSpeakers:Dhruva Goyal,Sitaraman Subramanian
\n
\nSpeakerBio:  Dhruva Goyal
\n

Dhruva has been hacking since middle school and enjoys offensive security research and red teaming. Dhruva is certified with OSCE3(ie. OSWE, OSEP & OSED) and OSCP. He leads the cybersecurity engagements and triage team at BugBase. He also loves playing AOE4 and working out.

\n\nSpeakerBio:  Sitaraman Subramanian
\n

Sitaraman Subramanian is the CTO at BugBase. He has spent over five years working in offensive security and over a decade building products. His work spans full stack development, DevSecOps, cloud security, and offensive security. He built BugBase from the ground up, and now leads engineering on Pentest Copilot, an autonomous AI driven pentesting platform. He presented at Black Hat USA Arsenal in 2025 and Microsoft BlueHat in 2024. He is an active open source contributor. Pentest Copilot is open sourced at https://github.com/bugbasesecurity/pentest-copilot, with 850+ stars and growing. He writes about hacking and AI evals at https://blog.ssitaraman.com.

\n\n\n\'',NULL,1295047),('3_Saturday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Hands-On Autonomous Pentesting with Pentest Copilot\'','\'Dhruva Goyal,Sitaraman Subramanian\'','Creator Talks_e329f6e71c88cf3fa6ea5b73ec5d34e5','\'\'',NULL,1295048),('2_Friday','16','16:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Praetor: An OPSEC Exposure Advisor for Empire Operators\'','\'Andrea Brosio,Ariz Soriano\'','Creator Talks_be5e507c1568906e4df96b16a78e9d26','\'Title: Praetor: An OPSEC Exposure Advisor for Empire Operators
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\nEvery operator makes the same call dozens of times an engagement: I need to do X, so how do I do it? Drop a binary, load a BOF, tunnel Impacket, abuse a LOLBIN? Today that runs on gut feel, and guessing wrong is how you get caught.
\n\n

Praetor is an open-source, AI-driven OPSEC assistant that plugs into Empire and turns that call into an informed one. You tell it what you want to do, and it suggests the ways to do it, ranked by how much each one would expose, with a plain-language explanation of why one path is quieter than another.

\n\n

AI is what makes the suggestions usable. It reads your intent in natural language, assembles the candidate techniques, ranks them, and writes the reasoning a senior operator would give you, putting tradecraft that normally lives in a few people\'s heads at every operator\'s fingertips. When you reach for a louder option than you need, it speaks up with a specific reason and a quieter alternative, not a blanket warning.

\n\n

The advice is grounded, not guessed. Praetor cannot see the target\'s telemetry, so it never claims anything is \"safe.\" It models the detection surface each technique exposes, ranks the options against each other, and bases those judgments on footprints measured in an instrumented range rather than on a model\'s intuition. You set the defensive posture you believe you are facing, and the suggestions adjust to it.

\n\n

We will demo it live and let people use it against Empire: state an intent, see the AI-ranked options with their reasoning, and watch the confirmation gate fire when a choice is louder than it needs to be.

\n\n

Access to a TryHackMe configured lab will be provisioned.

\n\nSpeakers:Andrea Brosio,Ariz Soriano
\n
\nSpeakerBio:  Andrea Brosio
\n

Andrea Brosio is a Security Researcher and Senior Content Engineer at TryHackMe, specializing in red teaming, malware development, and offensive security. With prior experience as a Bug Hunter and Red Team Operator he combines real-world adversarial expertise with a passion for creating engaging cybersecurity training.

\n\nSpeakerBio:  Ariz Soriano, Associate Director - Red Team Operations @ THEOS Cyber Solutions
\n

Ariz Soriano is Associate Director of Red Team at Theos, with nearly a decade of experience spanning Red Teaming, Penetration Testing, and Incident Response. He started his career on the defensive side, working as a SOC analyst and eventually leading SOC and IR teams for his first four years in the industry. That defensive foundation gives him a perspective most purely offensive operators don\'t have.

\n\n

He built the Theos Red Team from the ground up, recruiting and training operators, designing red team infrastructure and tooling, and establishing the methodology and playbooks behind the team\'s APT simulation and purple teaming engagements. Today he runs a practice that delivers multiple concurrent engagements a year, balancing operations with presales, scoping, revenue targets, and people management.

\n\n

Outside of client work, Ariz is passionate about building red team tooling, optimizing offensive workflows, and sharing knowledge with the community as a conference speaker. He also contributes to TryHackMe as a part-time Senior Content Engineer, creating hands-on cybersecurity labs and challenges based on real-world attack techniques.

\n\n\n\'',NULL,1295049),('2_Friday','17','16:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Praetor: An OPSEC Exposure Advisor for Empire Operators\'','\'Andrea Brosio,Ariz Soriano\'','Creator Talks_be5e507c1568906e4df96b16a78e9d26','\'\'',NULL,1295050),('3_Saturday','11','11:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'DPAPI Is Not a Boundary: A Full Infostealer Kill Chain Operators Can Replicate\'','\'Filipi Pires\'','Creator Talks_c94a5c4dc0ba1a6b8fe6a60ee4498b23','\'Title: DPAPI Is Not a Boundary: A Full Infostealer Kill Chain Operators Can Replicate
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

Complete infostealer kill chain hands-on, executed against Windows 11 21H2 on default UAC using only open-source tooling. No zero-days, no commercial C2. Participants run every command live: HTA delivery, Meterpreter in-memory session, Chrome and Edge credential extraction via DPAPI-locked SQLite, keylogging in explorer.exe memory, UAC bypass via fodhelper, SYSTEM via Named Pipe Impersonation, and LSASS dump via Kiwi. The DPAPI_SYSTEM key recovered from LSA secrets decrypts the browser credentials captured earlier, closing the loop.

\n\n

OUTLINE

\n\n

Stage 1: generate HTA payload, deliver via Python HTTP server, open Meterpreter session\nStage 2: extract Chrome and Edge credentials via post module, inspect DPAPI-encrypted loot\nStage 3: migrate to explorer.exe, start keyscan, capture live keystrokes\nStage 4: UAC bypass via fodhelper registry hijack, elevate to SYSTEM via Named Pipe Impersonation\nStage 5: load Kiwi, dump NTLM hashes, SAM, LSA secrets, extract DPAPI_SYSTEM key, decrypt browser loot\nDetection debrief: Sysmon Event ID 1 process tree and PowerShell Script Block log review per stage

\n\n

TAKEAWAYS

\n\n
    \n
  1. A complete credential theft playbook from HTA delivery to LSASS dump, validated against Windows 11 21H2 with Chrome 147 and Edge 147 on default UAC, ready to adapt for engagements.
  2. \n
  3. The DPAPI close-loop: how DPAPI_SYSTEM from LSA secrets decrypts browser credentials collected earlier, giving operators a concrete credential pivot from a single user-context session.
  4. \n
  5. A detection gap map calibrated against real Sysmon telemetry showing which events fire on default Windows 11 and which require EDR behavioral rules most organizations do not have deployed.
  6. \n
\n\nSpeakerBio:  Filipi Pires, Head of Technical Advocacy at SCYTHE
\n

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, Advisor & Investor at Sherlockeye, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I\'m Creator and Instructor of the Course - Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis - Fundamentals (HackerSec).

\n\n

Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329\nBlack Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329\nBlack Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0\nBlack Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires\nDEF CON 33 / 32 - https://sessionize.com/filipi-pires/\nDEF CON - Adversary Village - https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/

\n\n\n\'',NULL,1295051),('2_Friday','12','12:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Burning Redirectors Before Blue Team Does\'','\'Mohamed AbuMuslim,Saad Nasir\'','Creator Talks_29ad93cb654995be575aca09761f8f70','\'Title: Burning Redirectors Before Blue Team Does
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

Red team operators rely on redirectors to proxy C2 callbacks, but monitoring those redirectors for blue team detection is typically handled by either manual log review or deploying a full SIEM pipeline. Neither scales well during active assessments. NightWatcher is a traffic monitoring agent that analyzes redirector access logs through detection rules and a reasoning engine that identifies attack phase progression (reconnaissance through takedown) rather than issuing disconnected alerts. NightRouter is a decision routing agent that receives NightWatcher\'s assessments, recommends a redirector action (drain, reduce weight, quarantine), and presents it to the operator via Slack interactive messages for approval or rejection.

\n\n

In this tactic, attendees will deploy NightWatcher/NightRouter locally, simulate blue team traffic patterns against redirectors, observe the attack phase reasoning and escalation detection, and execute redirector actions through the Slack human-in-the-loop approval flow. The stack runs in mock mode with no external infrastructure dependencies required.

\n\nSpeakers:Mohamed AbuMuslim,Saad Nasir
\n
\nSpeakerBio:  Mohamed AbuMuslim
\n

I am a security researcher and offensive security engineer specializing in red teaming, penetration testing, adversarial AI, and product security engineering.

\n\n

My work focuses on identifying exploitable weaknesses across modern attack surfaces, including web applications, APIs, cloud platforms, enterprise infrastructure, Active Directory, and LLM-enabled systems. I combine offensive operations, applied research, and security engineering to solve complex security problems, validate security posture, and improve how organizations build and assess secure products.

\n\n

Over the years, I have led and contributed to offensive security capability building in complex environments, including helping establish Microsoft Egypt & Middle East’s first offensive security team and previously helping build PwC’s offensive security capability in Egypt, and served as Manager and Practice Lead at EY leading offensive security engagements. My experience spans startups, mid-sized organizations, and multinational enterprises.

\n\n

I regularly speak at conferences including Black Hat, DEF CON, BSides, and OWASP Cairo on topics such as AI red teaming, cloud attack simulation, supply-chain risk, log manipulation, and practical offensive tradecraft. I also design and deliver hands-on training, contribute to security education, and support community initiatives through AI Village, BSides Albuquerque, OWASP Cairo, and CyberDose.

\n\nSpeakerBio:  Saad Nasir
\n

Saad Nasir is a cybersecurity leader specializing in red teaming, penetration testing, and application security. He currently leads Red Team and Application Security initiatives, overseeing offensive security operations, adversary simulation, and security assessments across enterprise environments.

\n\n

With more than 10 years of cybersecurity experience, Saad has led offensive security engagements spanning web applications, cloud platforms, internal networks, and Active Directory environments. He is the founder and organizer of Security BSides Albuquerque, helping grow one of New Mexico\'s largest community-driven cybersecurity conferences.

\n\n

Saad is pursuing a PhD in National Security and holds a Master\'s degree in Cybersecurity, along with multiple industry certifications, including OSCP and CISM. He is passionate about sharing practical skills, helping defenders understand the mindset of attackers, and advancing the cybersecurity community through mentoring, conference speaking, and hands-on training.

\n\n\n\'',NULL,1295052),('2_Friday','13','12:00','13:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'Burning Redirectors Before Blue Team Does\'','\'Mohamed AbuMuslim,Saad Nasir\'','Creator Talks_29ad93cb654995be575aca09761f8f70','\'\'',NULL,1295053),('3_Saturday','16','16:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'The Quantum Mechanic: Attacking all the clouds\'','\'Moses Frost\'','Creator Talks_64a364af14505367324d542d67886afc','\'Title: The Quantum Mechanic: Attacking all the clouds
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

Cloud environments are now expansive and interconnected, where identity is the main security boundary, and misconfigurations pose security risks. For Red Teamers, attacking these environments often means relying on a collection of mismatched tools. You need one set of scripts for Entra ID, a separate framework for AWS, and many command-line tools for other cloud providers. This switching between tools is inefficient, and workflows require many manual commands. When operators deal with complex dependencies and syntax differences between providers, they miss broader attack paths.

\n\n

Enter the Quantum Mechanic.

\n\n

This session introduces a new Unified Cloud Attack tool designed to remove the operational friction of multi-cloud engagements. Built for operators who need to move fast and remain unnoticed, Quantum Mechanic serves as a universal discovery and exploitation engine. It hides the differing command sets of various cloud providers, allowing operators to run complex attacks through a single, consistent interface without sacrificing the accuracy of direct CLI commands.

\n\n

During this talk, we will discuss the realities of modern cross-cloud exploitation and demonstrate how to bring order to the process. We will present the framework’s main components, demonstrating how it handles compromised credentials, automates cross-platform enumeration, and maps privilege-escalation paths. Through demonstrations, we will show the tool’s ability to exploit multi-cloud environments with a single command set.

\n\n

If you are tired of managing multiple separate tools just to get started, or if you\'ve ever disrupted an operation because of a misconfigured cloud script, it’s time to upgrade your toolkit. Join us to learn how to streamline your cloud attack workflows and improve precision.

\n\nSpeakerBio:  Moses Frost
\n

Moses Frost has been working in the field since the late 90\'s. Working with computers in the late 80s for fun and moving into a more professional field shortly after high school. He is a Red Team Operator at Neuvik. A senior instructor and course author at the SANS Institute, authoring and teaching the Cloud Penetration Testing Course. He also co-authors the book Gray Hat Hacking: Volume 6. He has worked at many companies, notably Cisco Systems, McAfee, and TLO. Currently, he is a Senior Operator at Neuvik. Over those years, he has enjoyed working in all parts of the IT Industry and hopes to do so for many more years.

\n\n\n\'',NULL,1295054),('3_Saturday','17','16:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'The Quantum Mechanic: Attacking all the clouds\'','\'Moses Frost\'','Creator Talks_64a364af14505367324d542d67886afc','\'\'',NULL,1295055),('4_Sunday','12','12:00','12:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Agenthound: Mapping Multi-Hop Credential Chains Across MCP, A2A, and LLM Gateways\'','\'Adithyan Arun Kumar\'','Creator Talks_48b032ff12c17e3517618e7e6adc478e','\'Title: Agenthound: Mapping Multi-Hop Credential Chains Across MCP, A2A, and LLM Gateways
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

A developer’s MCP configuration exposes a gateway credential. That gateway holds production model keys, an A2A agent can reach it through a delegated tool, and the agent loads instructions from a repository an external contributor can modify. Each component looks harmless in isolation; together, they form a viable path from a low-trust developer environment to production systems. Modern AI infrastructure is full of these hidden chains, spanning MCP servers, agent runtimes, model gateways, local inference hosts, notebooks, and web interfaces. No file declares the entire chain, and no scanner confined to MCP, A2A, or any one AI service can reconstruct it. The most dangerous weakness in the agentic stack is often not a component - it is the trust between components.

\n\n

AgentHound (https://github.com/adithyan-ak/AgentHound) is an offensive security framework that serves as BloodHound for AI agent infrastructure. Its lean Go collector maps agent clients, MCP servers, A2A agents, tools, resources, identities, credentials, and AI services; a local Neo4j-backed server correlates those observations and derives cross-service reachability to reveal attack paths such as poisoned instructions, credential reuse, impersonation, and potential execution or data exfiltration. What makes it special is its ability to merge evidence from multiple protocols and collectors into one deterministic graph, then rebuild higher-level relationships turning scattered configuration issues into concrete, explainable attack chains across the entire AI-agent ecosystem.

\n\n

In this live demo, we follow one hidden attack chain end to end — from a foothold on a developer workstation to verified access to a protected, high-value resource. AgentHound discovers the local MCP configuration, connected services, tools, credentials, and resources; correlates them into a walkable attack path; and then safely tests whether that path is genuinely exploitable, upgrading the finding from inferred risk to verified evidence in real time. We finish by poisoning an MCP tool description, detecting the new attack path, and restoring the target from a recovery receipt, showing how AgentHound makes cross-system weaknesses visible, testable, explainable, and reversible.

\n\n

AgentHound is open source under Apache 2.0. Version 1.0 is released and available now.

\n\nSpeakerBio:  Adithyan Arun Kumar
\n

Adithyan Arun Kumar is an AI Security Engineer at Salesforce, specializing in AI adversarial red teaming, RAG security, and agentic threat modeling across the Agentforce ecosystem. Armed with over five years of full-spectrum offensive security experience and a MS in Information Security from Carnegie Mellon University, he holds advanced certifications including OSEP, OSWE, OSCP, and CRTP. His extensive vulnerability research and offensive tradecraft have earned him hall-of-fame acknowledgments from industry leaders such as Apple, Microsoft, and Intel.

\n\n\n\'',NULL,1295056),('4_Sunday','10','10:00','10:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6','\'Direct Network Access for Command and Control\'','\'Andrew Rioux\'','Creator Talks_6d3c6eaf94081e77fb22cd08c9b46db2','\'Title: Direct Network Access for Command and Control
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 6 - Map
\n
\nDescription:
\n

Command and control beacons currently reach out to the operating system to request socket resources, triggering auditing and being restricted by local firewall rules. However, it is possible to develop malware that can evade the standard process. Sparse is a tool that weaponizes this concept to evade such auditing and defensive configurations.

\n\nSpeakerBio:  Andrew Rioux
\n

I started learning to program in middle school and found a software engineering project to work on throughout highschool. I attended Liberty University to study Software Engineering and Cybersecurity at the undergraduate level, learning to develop software that works in adversarial contexts. I have recently finished my master\'s degree in Cybersecurity, where I was able to further practice developing software in adversarial contexts and develop version 2 of Sparse

\n\n\n\'',NULL,1295057),('3_Saturday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'MCP Servers: The Next Enterprise Attack Surface\'','\'Apoorwa Joshi,Justin Dray\'','Creator Talks_8b63334ed6ca0a776ca181db18b108cc','\'Title: MCP Servers: The Next Enterprise Attack Surface
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3 - Map
\n
\nDescription:
\n

Everyone\'s building MCP servers. Nobody\'s attacking them yet. AI agents are now wired directly into developer workflows via the Model Context Protocol (MCP). This session dissects the hidden security risks in MCP ecosystems, from malicious tool servers to over‑privileged integrations. You’ll walk away with actionable defenses and a fresh lens on AI‑augmented attack surfaces. This talk covering five distinct attack surfaces mentioned in the outline.\nTwo live demos make the risk visceral:\n1)A malicious MCP server masquerading as a calendar tool silently exfiltrates conversation context, secrets, and API keys with zero user-visible indicators of compromise.\n 2)A prompt injection payload planted in a GitHub repository triggers lateral movement across three connected MCP servers (filesystem, GitHub, cloud APIs), demonstrating how MCP multiplies blast radius without any direct server exploitation.

\n\nSpeakers:Apoorwa Joshi,Justin Dray
\n
\nSpeakerBio:  Apoorwa Joshi
\n

Meet Apoorwa Joshi – Security Engineer, Code Whisperer & Threat Tamer at Amazon. With over 6 years in the trenches of application and cloud security at scale, she currently brings her talents to helping teams think like attackers before the attackers do. Armed with a Master’s degree, a knack for demystifying technical complexity, Apoorwa specializes in \"shifting left\"\nBased in Austin, Texas, Apoorwa is part of a new wave of security professionals. Though this is her first time on the conference stage, she’s no stranger to leading conversations that matter from mentoring junior engineers to influencing cross-team architecture decisions.\nWhen she’s not taming threats or refactoring risk, she enjoys playing ping pong and spending time with her cat.

\n\n

Ask her about: threat modeling, secure architecture, DevSecOps, or how to sneak security into sprint planning without getting side-eyes.

\n\nSpeakerBio:  Justin Dray
\n

Meet Justin Dray – Senior Security Engineer & AI Automation Lead at AWS.

\n\n

With over 10 years in cloud and application security at Amazon-scale, Justin is the lead engineer on the team responsible for application security across AWS Database services, and has made a career out of finding the risks nobody else knew to look for — then building the AI-powered tooling to catch them before they ever reach production. He\'s architected AI investigation frameworks and automated code review systems now running across tens of thousands of packages organization-wide.

\n\n

Based in Seattle, Justin specializes in turning security from a bottleneck into a force multiplier, recovering thousands of engineering hours a year by embedding automation directly into the SDLC. He\'s built a reputation as a trusted bar raiser, able to align even the most historically high-friction teams around shared security outcomes.

\n\n

When he\'s not building security tooling, Justin can be found out on a hiking trail, behind a camera, or deep in a book.

\n\n\n\'',NULL,1295058),('3_Saturday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 3','\'MCP Servers: The Next Enterprise Attack Surface\'','\'Apoorwa Joshi,Justin Dray\'','Creator Talks_8b63334ed6ca0a776ca181db18b108cc','\'\'',NULL,1295059),('2_Friday','15','15:00','15:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'LLM-Coached Red Team Tactics to Attack Zero Trust\'','\'Rudy Ristich,Vijay Anand\'','Creator Talks_e024c15aaf65d6892415f4e3ca70013b','\'Title: LLM-Coached Red Team Tactics to Attack Zero Trust
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

This workshop is targeted toward novice and intermediate red teamers and explores how AI-assisted offensive agents can support attack-path discovery and adversarial operations within modern Zero Trust environments. Following a brief overview of ARES (Autonomous Reconnaissance & Exploitation System), participants spend most of the session interacting with the agent while navigating a live enterprise range.

\n\n

ARES is built upon a retrieval-augmented generation (RAG) architecture incorporating offensive doctrine, MITRE ATT&CK mappings, operational playbooks, and offensive knowledge sources including the Red Team Field Manual and UK Ministry of Defence Red Teaming Handbook. The system integrates common offensive tooling including Nmap, Metasploit, NetExec, BloodHound CE, Hashcat, Impacket, Evil-WinRM, and native Linux terminal workflows. ARES can generate attack scripts for operator approval, analyze successful and unsuccessful attacks, identify attack paths, and capture operational knowledge for future recommendations.

\n\n

Participants will receive continued access to the range and ARES following the conference.

\n\n

Paired Tactic

\n\n

The paired tactic places participants inside a simulated enterprise environment running Windows Server 2022 Active Directory, Windows 11 workstations, Ubuntu 24.04 application servers, GitLab Community Edition, Jenkins CI/CD, and Microsoft Entra-style identity services.\n The environment includes MFA enforcement, network segmentation, service accounts, privileged automation workflows, and least-privilege access controls representative of modern Zero Trust deployments.

\n\n

Participants begin with access to a Kali Linux attack workstation equipped with Nmap, NetExec, BloodHound CE, Hashcat, Metasploit, Impacket, Evil-WinRM, and ARES. The objective is not simply to exploit a vulnerability but to identify hidden trust relationships between users, service accounts, deployment pipelines, automation platforms, and protected resources.

\n\n

ARES assists participants with reconnaissance interpretation, attack-path discovery, trust-chain analysis, script generation, and recommendations following both successful and failed operations. Participants may discover exposed service-account credentials, deployment tokens embedded in Git repositories, overprivileged CI/CD workflows, delegated administrative rights, and other trust assumptions that remain despite Zero Trust controls.

\n\n

Throughout the exercise, all offensive actions require participant approval and execution. The workshop demonstrates how modern red team operations increasingly focus on identities, trust relationships, and authorization paths rather than traditional perimeter exploitation while showcasing how AI-assisted systems can support offensive decision-making and operational knowledge reuse.

\n\nSpeakers:Rudy Ristich,Vijay Anand
\n
\nSpeakerBio:  Rudy Ristich
\n

Rudy Ristich is a long-time hacker based in Chicago. He has lead red teams and vulnerability assessment practices, contributed to THOTCON hardware badges, and delivered podcasts and workshops on offensive ops. Rudy strongly believes that red teaming is most valuable when it actually changes how defenders can operate. Most recently Rudy has advised the UC2ADAM project helping to support up-skilling public sector works on information security skill. Rudy has served as a Goon at DEFCON for over a decade.

\n\nSpeakerBio:  Vijay Anand
\n

Vijay Anand is an Associate Professor in the Department of Information Technology at Kennesaw State University. He holds a Ph.D. degree from Illinois Institute of Technology. His research interests are in zero-trust architectures, cyber intelligence, embedded security, blockchain technologies, trustworthy cyberinfrastructure, and cybersecurity education. Before joining Kennesaw State University, he had multiple academic appointments, notably as an Associate Professor and Director of Cybersecurity at the University of Missouri - St. Louis and an Associate Professor and Director of Cybersecurity at Southeast Missouri State University. He has previously held industry positions as an Embedded Security Architect at Motorola, Senior Security Engineer at PALM Inc., and as a Security Research Engineer at Computation Institute. He has served as a member of the Missouri Governor’s Cybersecurity Taskforce and was the director of the Missouri Collegiate Cyber Defense Competition. Currently, he has multiple funded research projects from the Department of Defense (DoD) and the National Science Foundation (NSF).

\n\n\n\'',NULL,1295060),('2_Friday','14','14:00','14:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Microsoft and Amazon are my Favorite C2 Providers\'','\'Robert Pimentel\'','Creator Talks_d0d4d321a516ad3af0b4c52e506c1606','\'Title: Microsoft and Amazon are my Favorite C2 Providers
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

Cloud relay services check every box for C2 transport: outbound-only HTTPS on 443, cloud brokered connectivity so the attacker never touches the target directly, and endpoint domains that enterprises literally cannot blocklist without breaking production. I validated this at a Fortune 40, you can\'t block *.servicebus.windows.net or *.iot.amazonaws.com without taking down dozens of business critical systems.

\n\n

This research was accepted at Red Team Village DC33 but I had to withdraw due to a family emergency. The work has continued since then with the AWS IoT MQTT technique, the Mythic agent integrations, and the detection package as new additions. The talk covers three techniques I built, validated, and integrated into Mythic C2:

\n\n

Azure Relay Bridge — Microsoft\'s own open source relay tool becomes a LOLBin. It\'s Microsoft-signed, supports persistent service installation on Windows/Linux/macOS, and tunnels all C2 traffic through *.servicebus.windows.net as standard HTTPS. I demo my custom Mythic C2 profile end to end, with agent check in, post-ex, all traffic indistinguishable from legitimate Azure usage.

\n\n

AWS IoT Secure Tunneling — Tunnels created from the attacker\'s own AWS account, zero CloudTrail in the target\'s environment. Great for lateral movement and short duration pivots, but I hit real operational limits during testing (12-hour lifetime, 1 Mbps ceiling, distinctive 20s keep-alive) that make it less ideal for persistent C2.

\n\n

AWS IoT Core MQTT — Those Secure Tunneling limitations led me here. MQTT pub/sub with X.509 mTLS auth, no tunnel lifetime limits, indefinite persistence through *.iot.amazonaws.com. I built custom Mythic agents: Poseidon (Go) for Linux/macOS, Apollo (C#) for Windows, both validated on AMD64 and ARM64.

\n\n

All the material will be available at the time of the presentation: Mythic agents and translation containers for both transports, infrastructure provisioning scripts, and detection rules (Suricata, Zeek, Splunk). Both Microsoft and AWS were engaged before disclosure. There\'s no vuln to patch, this is an architectural problem with how cloud relay services are designed.

\n\nSpeakerBio:  Robert Pimentel, Hacker Hermanos
\n

Robert is a seasoned offensive security professional with more than a decade of experience in Information Security.

\n\n

He began his career in the U.S. Marine Corps, where he worked on secure telecommunications. Robert holds a master\'s degree in Cybersecurity, numerous IT certifications, and a background as an instructor at higher education institutions like the New Jersey Institute of Technology and American University.

\n\n

Robert is committed to sharing his knowledge and experiences for the benefit of others. He enjoys Brazilian steakhouses and cuddling with his pugs while writing Infrastructure as Code to automate Red Team Infrastructure.

\n\n

Robert is the Director of Offensive Security at Humana, Inc.

\n\n\n\'',NULL,1295061),('3_Saturday','16','16:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Writing Production-Grade Exploits in go-exploit\'','\'Landon Rice\'','Creator Talks_54b7e5f125b4d162860e4a5e054b8731','\'Title: Writing Production-Grade Exploits in go-exploit
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4 - Map
\n
\nDescription:
\n

Writing an exploit that works once in a lab is easy. Writing one that holds up across firmware versions, hardened configurations, and real-world constraints is another challenge entirely. This hands-on workshop walks through the go-exploit framework and the engineering behind real-world offensive tooling, covering go-exploit\'s module design, error handling, target fingerprinting, and repeatability. Attendees will leave with a working exploit and the blueprints to build more.

\n\nSpeakerBio:  Landon Rice
\n

WIP

\n\n\n\'',NULL,1295062),('3_Saturday','17','16:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 4','\'Writing Production-Grade Exploits in go-exploit\'','\'Landon Rice\'','Creator Talks_54b7e5f125b4d162860e4a5e054b8731','\'\'',NULL,1295063),('2_Friday','16','16:00','17:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'EvilEssid: Evading Wireless Intrusion Prevention Systems\'','\'Miguel Fernandez\'','Creator Talks_233de3447e97be78cb23caaf13321b4f','\'Title: EvilEssid: Evading Wireless Intrusion Prevention Systems
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1 - Map
\n
\nDescription:
\n

What if a rogue access point could evade a Wireless Intrusion Prevention System (WIPS) while operating in plain sight?

\n\n

In this hands-on tactic, participants will learn how EvilEssid, a wireless evasion technique, exploits weaknesses in how WIPS solutions identify, classify, and trust wireless networks. Rather than focusing solely on theory, attendees will actively build, configure, and operate EvilEssid in a controlled lab environment.\nThrough a series of guided exercises, participants will gain practical experience deploying rogue access points, understanding WIPS detection logic, and applying wireless identity manipulation techniques to evade common defensive controls. The workshop will demonstrate how attackers can establish malicious wireless infrastructure that remains undetected while creating opportunities for credential harvesting, traffic interception, and adversary-in-the-middle operations.\nAttendees will use the EvilEssid tool to reproduce the attack chain step-by-step. Each exercise is designed to provide hands-on exposure to offensive wireless tradecraft while encouraging participants to experiment.\nBeyond the offensive techniques, the workshop will also explore defensive implications, helping participants understand the limitations of current WIPS technologies and identify practical approaches to improve wireless threat detection.\nBy the end of the session, attendees will have deployed a rouge access point using EvilEssid themselves, validated successful WIPS evasion in a lab environment, and gained a deeper understanding of both the offensive and defensive aspects of advanced wireless operations.

\n\n

Fundamentals \n • ESSID
\n • BSSID
\n • Deauthentication attacks \n • Evil Twin attack \nUnderstanding WIPS and Its Detection Models \n • What is a WIPS \n • How it works and detection techniques \n • Evil Twin attack vs WIPS\nIdentifying the Weakness\nAdvancing the Evil Twin Technique \n • Human targets \n • Crafting a WIPS-evasive Evil Twin\nEvilEssid tool: Design and Implementation\n • Overview \n • Key concepts behind the tool \n • Features and usage\nConclusions and Countermeasures

\n\nSpeakerBio:  Miguel Fernandez
\n

Colombian cybersecurity researcher based in China with over 15 years of experience in offensive security, penetration testing, and applied security research.

\n\n

His work focuses on developing and validating novel attack and defense techniques, challenging existing security assumptions across areas such as wireless security, social engineering, and real-world adversarial methodologies.

\n\n

He has presented at international conferences including Codegate, Overdrive, CIS, Xcon x Hacking group ,WAIC, Hackprove world, Tencent security saloon and multiple PRC cyber security meetups.

\n\n

His research is grounded in the scientific method, emphasizing experimentation, reproducibility, and practical validation.

\n\n\n\'',NULL,1295064),('2_Friday','17','16:00','17:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 1','\'EvilEssid: Evading Wireless Intrusion Prevention Systems\'','\'Miguel Fernandez\'','Creator Talks_233de3447e97be78cb23caaf13321b4f','\'\'',NULL,1295065),('2_Friday','16','16:00','16:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'Network Implants: Lessons Learned Building Reliable Red Team Dropboxes\'','\'Hassan Mohamad\'','Creator Talks_e5ba3c8d0f97916e1f6426dc9c10f261','\'Title: Network Implants: Lessons Learned Building Reliable Red Team Dropboxes
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

This 60-minute session is both a technical workshop and an interactive tactic. The first half is a practical walkthrough of how we built and refined a field-ready network implant (commonly called a “Dropbox”) for red team engagements. The second half is hands-on: attendees can interact with the Dropboxes (i will bring a few), connect to the lab environment, test operator access (even via smartphone), ask questions, and experiment with parts of the workflow themselves.

\n\n

The problem we wanted to solve was simple to describe but hard to get right: after gaining physical access and placing a device inside a client network, testers should be able to work from their own laptops and VMs almost as if they were on-site. No “walk back to the car, open the laptop, hope LTE works, debug the tunnel in a hallway” workflow. The implant should give operators reliable access, support normal tooling, survive unreliable networks, and allow quick, discreet verification from a phone that the box is alive, reachable, and in the right network segment.

\n\n

We will cover the practical details that make this harder than “just plug in a Pi”: small hardware, LTE/WiFi/Ethernet connectivity, OS/config deployment, safe updates, fallback access, and early-stage network discovery. This includes scenarios where the implant first needs to quietly observe the local network, understand addressing and services, or sit transparently behind an already-authenticated device in NAC/802.1X environments before operators decide how to blend in and route traffic safely.

\n\n

The architecture side focuses on making the system useful for real consulting work: operator VPN access, central routing, tenant separation, overlapping customer networks, and strict isolation between engagements. In our setup, testers connect from their normal kali or Windows VMs and get routed into the correct client environment without touching client-side routing, while the system ensures that operators assigned to one project cannot accidentally reach another.

\n\n

For the interactive part, I will bring a limited number of physical Dropboxes. Attendees can connect to the lab, test the operator experience, onboard through VPN profiles or QR codes, and see how the device behaves from both the “dropped box” and operator side. The same workflow can also run in a VM, so the core concepts are testable without owning the exact hardware.

\n\n

This is not a product pitch. The goal is to show how to build this kind of infrastructure from the ground up using open hardware and software components. Attendees should leave with a realistic blueprint for building their own authorized red team Dropbox setup, including the parts that usually get skipped in demos: routing, updates, recovery, tenant isolation, operational safety, and all the little edge cases that only show up once the box is actually in the field. All the playbooks, configs etc. will be made available publicly.

\n\nSpeakerBio:  Hassan Mohamad
\n

Hassan Mohamad is a penetration tester and red teamer at Certitude Consulting. He conducts and leads penetration tests and large-scale red team assessments for large cooperations of various industries. Previously, he led an offensive security team at Sec-Research and worked in digital forensics and security consulting at Deloitte. He holds OSCP and OSEP certifications and is a multiple-time winner of the Austria Cyber Security Challenge. His work focuses on practical red team infrastructure, physical-access tradecraft, and building offensive systems that survive real client environments.

\n\n\n\'',NULL,1295066),('2_Friday','13','13:00','13:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2','\'One Request to Rule Them All\'','\'Corey Ball\'','Creator Talks_18525673bd631d165c884247d8df743b','\'Title: One Request to Rule Them All
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2 - Map
\n
\nDescription:
\n

The world has changed...

\n\n

It began with the forging of the modern enterprise. To the cloud were given vast kingdoms of compute. To the mobile apps, a presence in every pocket. To the machines that now think, knowledge stolen from the creators. And to bind them, to let each speak to each across the dark spaces between systems, the architects forged the APIs.

\n\n

But in the forging a flaw was hidden. For an API answers any who ask it correctly, and it does not always stop to learn who is asking. So it came to pass that buried among ten thousand harmless calls there waited a single request. One request with dominion over all the others. One request to read what was meant to stay hidden, to act in the name of any user, to claim the powers kept for admins alone.

\n\n

One Request to bring the whole realm to ruin, and in a single call, destroy it.

\n\nSpeakerBio:  Corey Ball
\n

Corey Ball is a cybersecurity consulting manager at Moss Adams, where he leads its penetration testing services. He has over ten years of experience working in IT and cybersecurity across several industries, including aerospace, agribusiness, energy, financial tech, government services, and healthcare. In addition to a bachelor’s degree in English and philosophy from Sacramento State University, Corey holds the OSCP, CCISO, CISSP, and several other industry certifications.

\n\n\n\'',NULL,1295067),('2_Friday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Red Team Express\'','\'Cody Spooner\'','Creator Talks_bc4736aafdb2056d44b5bd5e01257723','\'Title: Red Team Express
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2 - Map
\n
\nDescription:
\n

We have a train that needs to keep going. The defender needs to keep the train going. The attacker needs to stop the train. Who will win?

\n\n

This tactic would explore OT protocols (such as modbus) to control a Lego train. Participants can watch, or participate as either an attacker or defender. Their goals being to either stop the train or keep it on track.

\n\nSpeakerBio:  Cody Spooner
\n

This will change

\n\n\n\'',NULL,1295068),('2_Friday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Tactic Table 2','\'Red Team Express\'','\'Cody Spooner\'','Creator Talks_bc4736aafdb2056d44b5bd5e01257723','\'\'',NULL,1295069),('2_Friday','10','10:00','10:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1','\'Opening Panel - \"Is Red Teaming Dead?\"\'','\'Ads Dawson,Ben \"NahamSec\" Sadeghipour,Billy Giles,Ryan Montgomery\'','Creator Talks_5f9c2d7a45d8a223ccf215751beb1f87','\'Title: Opening Panel - \"Is Red Teaming Dead?\"
\nTags: Red Team Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1 - Map
\n
\nDescription:
\n

Moderated By Ben Sadeghipour (@NahamSec)\nGuests:\nAds Dawson (0xmoose) \nRyan Montgomery (@0day)\nBilly Giles

\n\nSpeakers:Ads Dawson,Ben \"NahamSec\" Sadeghipour,Billy Giles,Ryan Montgomery
\n
\nSpeakerBio:  Ads Dawson, Staff AI Security Researcher, OWASP GenAI Security Project founder
\n

Ads Dawson founded the OWASP GenAI Security Project and led it to flagship status — the fastest in OWASP history. As a Staff AI Security Researcher at Dreadnode, he specializes in exploiting ML and AI systems, harnessing AI for offensive cybersecurity through capability development and exploit development, and conducting red team operations against frontier models for government, military, and tier-1 labs. He is lead author of AIRTBench (arXiv), the first benchmark for autonomous AI red teaming in LLMs, and author of AI Native LLM Security (Packt, 2025).

\n\n

A senior red team operator with BT6 (the frontier AI red team), ranked #2 in Canada on HackerOne (2025/2026), and selected for Meta\'s MBBRC live hacking event, Ads is a HackerOne US South Ambassador, BugCrowd Hacker Advisory Board member, MITRE AI Working Group contributor, and leads the OWASP Toronto chapter. He spoke at Bug Bounty Village DC33 on the BT6 AI jailbreaking panel and is also presenting \"Exfil Everything: A Year of Stealing Data from AI Agents\" at Bug Bounty Village DC34 (schedule pending publication).

\n\nSpeakerBio:  Ben \"NahamSec\" Sadeghipour
\n

Ben Sadeghipour (NahamSec) is a security researcher, ethical hacker, and educator who has spent more than a decade finding and disclosing critical vulnerabilities in some of the world\'s largest organizations. As one of the most recognized names in the bug bounty community, he has reported thousands of security flaws and consistently ranked among the top researchers on leading hacking platforms.\nBeyond his own research, Ben is passionate about lowering the barrier to entry in cybersecurity. Through his widely followed educational content, live streams, and the conferences he founds and organizes, he has helped train a new generation of hackers around the world. His work blends deep technical expertise with a commitment to mentorship and community building.Ben speaks regularly at industry conferences on offensive security, bug bounty hunting, and building a career in cybersecurity.

\n\nSpeakerBio:  Billy Giles
\n

Billy Giles is an Offensive Security leader and practitioner who specializes in red/purple teaming and network penetration testing. With a deep passion for understanding adversary behaviors, he helps organizations across a multitude of industries assess their security postures, identify and remediate vulnerabilities, and build stronger defenses by thinking like an attacker.

\n\n

Billy is also the creator of Thinking Offensively. Through this project he examines offensive security strategy topics to help cybersecurity leaders anticipate threats and inform decision making, while also providing tools, playbooks, and techniques that red teams can apply directly to their work. His mission is to bridge strategy and execution to help organizations think offensively and stay ahead of evolving threats.

\n\nSpeakerBio:  Ryan Montgomery
\nNo BIO available
\n\n\'',NULL,1295070),('3_Saturday','10','10:00','11:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5','\'Living Off the Vault\'','\'Alexandru Uifalv,Jennifer Slaybaugh,Morton Schenk\'','Creator Talks_bff1d92b93cd59054baa1bff0c44b92f','\'Title: Living Off the Vault
\nTags: Red Team Village | Misc
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5 - Map
\n
\nDescription:
\n

Sablefort is a fintech startup that ships an in-house password manager, Sablefort Keyvault.\nRather than use a vetted encryption library, its engineering team rolled their own cipher.\nStarting from nothing but a public support chatbot, the player attempts to work through the attack chain.

\n\nSpeakers:Alexandru Uifalv,Jennifer Slaybaugh,Morton Schenk
\n
\nSpeakerBio:  Alexandru Uifalv
\n

Alexandru Uifalvi (sickness) has been a part of the Advanced Windows Exploitation class over the past 7 years. His passion for vulnerability research and exploit writing comes through in his teaching and course content creation. Alex is well versed in Windows Internals, Windows Kernel Exploitation, and Reverse Engineering.

\n\nSpeakerBio:  Jennifer Slaybaugh
\n

n/a

\n\nSpeakerBio:  Morton Schenk
\n

Morten Schenk (morten) is a Content Technical Manager and trainer at Offensive Security with a focus on exploit development and mitigation bypasses on Windows. His recent work includes bypasses of exploit mitigations and exploitation vectors against the Windows 10 kernel. He presented on this topic at Black Hat USA 2017 and DEF CON 25. Morten was also the main content developer and designer for PEN300 and EXP-301.

\n\n\n\'',NULL,1295071),('3_Saturday','11','10:00','11:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Tactic Table 5','\'Living Off the Vault\'','\'Alexandru Uifalv,Jennifer Slaybaugh,Morton Schenk\'','Creator Talks_bff1d92b93cd59054baa1bff0c44b92f','\'\'',NULL,1295072),('4_Sunday','10','10:00','14:59','N','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'Attack Campaign in VR\'','\'James Rice\'','Creator Talks_3b8e453d2a9346515f7090c28115496c','\'Title: Attack Campaign in VR
\nTags: Red Team Village | Misc
\nWhen: Sunday, Aug 9, 10:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area - Map
\n
\nDescription:
\n

This VR visualization experience is designed to support the exploration and understanding of complex cybersecurity scenarios for students and professionals. Cyber attack campaigns often involve intricate relationships and multi-stage processes that can be difficult to interpret, making effective analysis and remediation challenging. By leveraging visualization best practices in virtual reality, the experience presents cyber threat information in a more intuitive and interactive format, with the goal of improving comprehension, situational awareness, and the ability to identify meaningful and actionable insights.

\n\nSpeakerBio:  James Rice
\n

Mr. James Rice has been cybersecurity faculty for the last decade in Upstate New York at Mohawk Valley Community College and more recently Rochester Institute of Technology. During this time, Mr. Rice has focused on developing numerous interactive gamified learning scenarios for the classroom and cyber competitions such as the NSA sponsored NCAE Cyber Games. Mr. Rice is currently pursuing his PhD at RIT in Computer Engineering and researching how to best leverage immersive reality technologies for data visualization and interaction, primarily in cyberspace.

\n\n\n\'',NULL,1295073),('4_Sunday','11','10:00','14:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'Attack Campaign in VR\'','\'James Rice\'','Creator Talks_3b8e453d2a9346515f7090c28115496c','\'\'',NULL,1295074),('4_Sunday','12','10:00','14:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'Attack Campaign in VR\'','\'James Rice\'','Creator Talks_3b8e453d2a9346515f7090c28115496c','\'\'',NULL,1295075),('4_Sunday','13','10:00','14:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'Attack Campaign in VR\'','\'James Rice\'','Creator Talks_3b8e453d2a9346515f7090c28115496c','\'\'',NULL,1295076),('4_Sunday','14','10:00','14:59','Y','Red Team Village','LVCCW Level 1 Hall 1 309 (Red Team Village) Special/Quest Area','\'Attack Campaign in VR\'','\'James Rice\'','Creator Talks_3b8e453d2a9346515f7090c28115496c','\'\'',NULL,1295077),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_20275f9148932fc128d026928c576006','\'Title: OWASP CTF
\nTags: OWASP Foundation | OWASP Foundation CTF | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

This challenge simulates a real-world secure development lifecycle, where security professionals must not only identify vulnerabilities but also collaborate with development teams to implement, validate, and deploy secure fixes.

\n\n

By completing the challenge, participants gain hands-on experience in:

\n\n
    \n
  • Web application exploitation
  • \n
  • Secure coding and vulnerability remediation
  • \n
  • Open-source security tooling from the OWASP ecosystem
  • \n
  • Responsible disclosure and patch submission workflows
  • \n
  • Using AI tools to assist in vulnerability analysis and remediation
  • \n
\n\n

The ultimate goal is to help practitioners develop the full skill set required to identify vulnerabilities, implement secure fixes, and deploy those fixes safely within their infrastructure.

\n\nLinks:
    Website - https://ctf.owasp.org
\n\'',NULL,1295078),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_20275f9148932fc128d026928c576006','\'\'',NULL,1295079),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_20275f9148932fc128d026928c576006','\'\'',NULL,1295080),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_20275f9148932fc128d026928c576006','\'\'',NULL,1295081),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_20275f9148932fc128d026928c576006','\'\'',NULL,1295082),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_20275f9148932fc128d026928c576006','\'\'',NULL,1295083),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_20275f9148932fc128d026928c576006','\'\'',NULL,1295084),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_20275f9148932fc128d026928c576006','\'\'',NULL,1295085),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_8ce3c153db169caf38baf6bd7840f1b5','\'Title: OWASP CTF
\nTags: OWASP Foundation | OWASP Foundation CTF | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

This challenge simulates a real-world secure development lifecycle, where security professionals must not only identify vulnerabilities but also collaborate with development teams to implement, validate, and deploy secure fixes.

\n\n

By completing the challenge, participants gain hands-on experience in:

\n\n
    \n
  • Web application exploitation
  • \n
  • Secure coding and vulnerability remediation
  • \n
  • Open-source security tooling from the OWASP ecosystem
  • \n
  • Responsible disclosure and patch submission workflows
  • \n
  • Using AI tools to assist in vulnerability analysis and remediation
  • \n
\n\n

The ultimate goal is to help practitioners develop the full skill set required to identify vulnerabilities, implement secure fixes, and deploy those fixes safely within their infrastructure.

\n\nLinks:
    Website - https://ctf.owasp.org
\n\'',NULL,1295086),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_8ce3c153db169caf38baf6bd7840f1b5','\'\'',NULL,1295087),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_8ce3c153db169caf38baf6bd7840f1b5','\'\'',NULL,1295088),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_8ce3c153db169caf38baf6bd7840f1b5','\'\'',NULL,1295089),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_8ce3c153db169caf38baf6bd7840f1b5','\'\'',NULL,1295090),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_8ce3c153db169caf38baf6bd7840f1b5','\'\'',NULL,1295091),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_8ce3c153db169caf38baf6bd7840f1b5','\'\'',NULL,1295092),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF\'','\'\'','Contests_8ce3c153db169caf38baf6bd7840f1b5','\'\'',NULL,1295093),('2_Friday','10','10:30','11:30','N','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF: Getting started & welcome\'','\'Diego Cotelo,Chris \"dafinga\" Maenner,Christian \"DeadlyFluVirus\" Nuss\'','Contests_c754d4ebc3f87de44da5924865c4ec7d','\'Title: OWASP CTF: Getting started & welcome
\nTags: OWASP Foundation | OWASP Foundation CTF | Contest
\nWhen: Friday, Aug 7, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

New to CTFs or application security? Join us before the competition for an introductory session designed to help newcomers get up to speed. We\'ll walk through the challenge format, the secure development lifecycle it simulates, and the tools and techniques you\'ll use - from finding vulnerabilities and implementing secure fixes to leveraging OWASP open source tooling and AI-assisted security workflows. Whether you\'re brand new or just looking for a refresher, this session will help you feel prepared and confident before the CTF begins.

\n\nSpeakers:Diego Cotelo,Chris \"dafinga\" Maenner,Christian \"DeadlyFluVirus\" Nuss
\n
\nSpeakerBio:  Diego Cotelo, Staff Cloud & Security Engineer
\n

I\'m a cloud and security engineer working at the intersection of infrastructure and security. I harden AWS, Kubernetes, and GitOps pipelines, and build tooling that surfaces misconfigurations, drift, and blast radius before an attacker finds them first. I treat security as an architecture problem, not a checklist — breaking systems to understand them, then designing secure-by-default platforms. I write about offensive and defensive cloud security at dcotelo.dev.

\n\nSpeakerBio:  Chris \"dafinga\" Maenner, Board Member at BSides Philadelphia
\n

Chris Maenner is the founder of Palmtree Ventures, where he spends his time helping startups and enterprises secure AI systems, Kubernetes, cloud platforms, and developer tooling without getting in the way of shipping software. Over the last 15+ years he’s bounced between startups and Fortune 50 companies building product security, platform security, and cloud security programs. Outside of work, Chris helps build CTFs and security projects with OWASP and DEF CON’s Blue Team Village (including Project Obsidian), serves on the board of BSides Philadelphia, contributes to the OWASP Secure Agent Playbook, and can usually be found speaking about AI security, Kubernetes, and whatever cloud-native security problem is keeping people up at night.

\n\nSpeakerBio:  Christian \"DeadlyFluVirus\" Nuss, Scaffoldly
\n

Full-stack development; Multi-cloud architecture, security and reliability; Automation enthusiast; Tech team development and leadership; Entrepreneur; Founder of Scaffoldly

\n\n\nLinks:
    Website - https://ctf.owasp.org
\n\'',NULL,1295094),('2_Friday','11','10:30','11:30','Y','Contests','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP CTF: Getting started & welcome\'','\'Diego Cotelo,Chris \"dafinga\" Maenner,Christian \"DeadlyFluVirus\" Nuss\'','Contests_c754d4ebc3f87de44da5924865c4ec7d','\'\'',NULL,1295095),('2_Friday','11','11:30','11:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Spotlight: Choose Your Own Adventure with InfoSecMap\'','\'W. Martín Villalba\'','Creator Events_ccffbea82d4807e295a4dd39b61b5f36','\'Title: Spotlight: Choose Your Own Adventure with InfoSecMap
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Opportunities in InfoSec are everywhere, but they’re often buried across scattered websites, social media posts, or chat channels. Whether it’s a local meetup, a CFP deadline, a volunteer opportunity, or the chance to sponsor an initiative, many people and organizations miss out simply because they don’t know where to look or find info bloated by pay-to-play noise.

\n\n

InfoSecMap was created to solve this. It’s a free, community-driven platform that brings the global InfoSec ecosystem together in one place. From major conferences to CTFs and grassroots meetups, InfoSecMap helps users explore what’s happening by geographic region or focus area and discover where they can connect and contribute.

\n\n

InfoSecMap is proud to partner with OWASP, bringing together volunteer-led chapters and global events while fostering stronger connections and community growth. We believe open source should mean open access, and we’re building the infrastructure to make that real.

\n\nSpeakerBio:  W. Martín Villalba, OWASP
\n

Martín is an application and product security consultant with over 15 years of industry experience. He founded C13 Security, where he specializes in Secure SDLC, pentesting, and vulnerability management. He is an active member of the InfoSec community, collaborating with local groups and global organizations such as BSides and OWASP. He also built InfoSecMap, an open-access platform for discovering InfoSec events and communities from all around the world.

\n\n\n\'',NULL,1295096),('4_Sunday','10','10:00','10:30','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Spotlight: Choose Your Own Adventure with InfoSecMap\'','\'W. Martín Villalba\'','Creator Events_e3ceaa9197da543bdfdfa1b508149fda','\'Title: Spotlight: Choose Your Own Adventure with InfoSecMap
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Opportunities in InfoSec are everywhere, but they’re often buried across scattered websites, social media posts, or chat channels. Whether it’s a local meetup, a CFP deadline, a volunteer opportunity, or the chance to sponsor an initiative, many people and organizations miss out simply because they don’t know where to look or find info bloated by pay-to-play noise.

\n\n

InfoSecMap was created to solve this. It’s a free, community-driven platform that brings the global InfoSec ecosystem together in one place. From major conferences to CTFs and grassroots meetups, InfoSecMap helps users explore what’s happening by geographic region or focus area and discover where they can connect and contribute.

\n\n

InfoSecMap is proud to partner with OWASP, bringing together volunteer-led chapters and global events while fostering stronger connections and community growth. We believe open source should mean open access, and we’re building the infrastructure to make that real.

\n\nSpeakerBio:  W. Martín Villalba, OWASP
\n

Martín is an application and product security consultant with over 15 years of industry experience. He founded C13 Security, where he specializes in Secure SDLC, pentesting, and vulnerability management. He is an active member of the InfoSec community, collaborating with local groups and global organizations such as BSides and OWASP. He also built InfoSecMap, an open-access platform for discovering InfoSec events and communities from all around the world.

\n\n\n\'',NULL,1295097),('3_Saturday','10','10:30','10:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Spotlight: Choose Your Own Adventure with InfoSecMap\'','\'W. Martín Villalba\'','Creator Events_aea54bcf2b565e1287ffddfc93f4ab1b','\'Title: Spotlight: Choose Your Own Adventure with InfoSecMap
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Opportunities in InfoSec are everywhere, but they’re often buried across scattered websites, social media posts, or chat channels. Whether it’s a local meetup, a CFP deadline, a volunteer opportunity, or the chance to sponsor an initiative, many people and organizations miss out simply because they don’t know where to look or find info bloated by pay-to-play noise.

\n\n

InfoSecMap was created to solve this. It’s a free, community-driven platform that brings the global InfoSec ecosystem together in one place. From major conferences to CTFs and grassroots meetups, InfoSecMap helps users explore what’s happening by geographic region or focus area and discover where they can connect and contribute.

\n\n

InfoSecMap is proud to partner with OWASP, bringing together volunteer-led chapters and global events while fostering stronger connections and community growth. We believe open source should mean open access, and we’re building the infrastructure to make that real.

\n\nSpeakerBio:  W. Martín Villalba, OWASP
\n

Martín is an application and product security consultant with over 15 years of industry experience. He founded C13 Security, where he specializes in Secure SDLC, pentesting, and vulnerability management. He is an active member of the InfoSec community, collaborating with local groups and global organizations such as BSides and OWASP. He also built InfoSecMap, an open-access platform for discovering InfoSec events and communities from all around the world.

\n\n\n\'',NULL,1295098),('2_Friday','10','10:00','17:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_7674b152165931b885eced21620023ed','\'Title: BadVR: Signals Everywhere a collaboration with XR Village
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

BadVR Data Exploration through VR visualization. See RF signals, cellular signals and new for 2026, Meshtastic signals, step into the data with a hands-on VR experience

\n\nSpeakers:Jad Meouchy,Suzanne Borders
\n
\nSpeakerBio:  Jad Meouchy, CTO + Co-Founder at BadVR
\n

Jad, originally from northern Virginia, holds dual B.S. degrees in Computer Engineering and Psychology from Virginia Tech, and is a graduate of the Thomas Jefferson High School for Science and Technology. While in college, he engineered and built the data visualization components of an emergency response simulation that went on to receive 2M in public grant funding. Over his 15-year career, Jad has founded five startups and successfully exited three. His professional expertise is in software architecture and development, specifically big data analytics and visualization, and virtual and augmented reality development. Based in Los Angeles since 2010, Jad promotes the community by organizing developer meetups and events, and volunteering time for STEM initiatives.

\n\nSpeakerBio:  Suzanne Borders, CEO + Founder at BadVR
\n

Suzanne studied psychology at University of Missouri, Kansas City and previously worked as Lead UX/Product Designer for over 9 years at companies such as Remine (raised $48M) and CREXi (raised $54M) where she specialized in designing intuitive, high-performant data analytic interfaces. In 2019, Suzanne founded BadVR and was awarded a “Rising Stars” innovation award from IEEE. To date, she’s raised over $4M in non-dilutive funding for BadVR, via grants from the National Science Foundation, NOAA, Magic Leap, Qualcomm, and more. Suzanne has grown the company from 2 to 25 people and was awarded 4 patents for innovations she created while leading the BadVR team. Over the past 5 years, Suzanne emerged as a thought-leader in the immersive data visualization and analytics space. She has been a keynote speaker at over 25 national and international conferences. In her spare time, Suzanne travels for inspiration (81 countries and counting) and is proud to be a published author and former punk.  Suzanne thrives at the intersection of product design, immersive technology, and data; she’s a believer in the artistry of technology and the technicality of art and remains passionately dedicated to democratizing access to data through universally accessible products. 

\n\n\n\'',NULL,1295099),('2_Friday','11','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_7674b152165931b885eced21620023ed','\'\'',NULL,1295100),('2_Friday','12','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_7674b152165931b885eced21620023ed','\'\'',NULL,1295101),('2_Friday','13','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_7674b152165931b885eced21620023ed','\'\'',NULL,1295102),('2_Friday','14','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_7674b152165931b885eced21620023ed','\'\'',NULL,1295103),('2_Friday','15','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_7674b152165931b885eced21620023ed','\'\'',NULL,1295104),('2_Friday','16','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_7674b152165931b885eced21620023ed','\'\'',NULL,1295105),('2_Friday','17','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_7674b152165931b885eced21620023ed','\'\'',NULL,1295106),('3_Saturday','10','10:00','17:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_e4277ae850844ded638d0d8d427c8178','\'Title: BadVR: Signals Everywhere a collaboration with XR Village
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

BadVR Data Exploration through VR visualization. See RF signals, cellular signals and new for 2026, Meshtastic signals, step into the data with a hands-on VR experience

\n\nSpeakers:Jad Meouchy,Suzanne Borders
\n
\nSpeakerBio:  Jad Meouchy, CTO + Co-Founder at BadVR
\n

Jad, originally from northern Virginia, holds dual B.S. degrees in Computer Engineering and Psychology from Virginia Tech, and is a graduate of the Thomas Jefferson High School for Science and Technology. While in college, he engineered and built the data visualization components of an emergency response simulation that went on to receive 2M in public grant funding. Over his 15-year career, Jad has founded five startups and successfully exited three. His professional expertise is in software architecture and development, specifically big data analytics and visualization, and virtual and augmented reality development. Based in Los Angeles since 2010, Jad promotes the community by organizing developer meetups and events, and volunteering time for STEM initiatives.

\n\nSpeakerBio:  Suzanne Borders, CEO + Founder at BadVR
\n

Suzanne studied psychology at University of Missouri, Kansas City and previously worked as Lead UX/Product Designer for over 9 years at companies such as Remine (raised $48M) and CREXi (raised $54M) where she specialized in designing intuitive, high-performant data analytic interfaces. In 2019, Suzanne founded BadVR and was awarded a “Rising Stars” innovation award from IEEE. To date, she’s raised over $4M in non-dilutive funding for BadVR, via grants from the National Science Foundation, NOAA, Magic Leap, Qualcomm, and more. Suzanne has grown the company from 2 to 25 people and was awarded 4 patents for innovations she created while leading the BadVR team. Over the past 5 years, Suzanne emerged as a thought-leader in the immersive data visualization and analytics space. She has been a keynote speaker at over 25 national and international conferences. In her spare time, Suzanne travels for inspiration (81 countries and counting) and is proud to be a published author and former punk.  Suzanne thrives at the intersection of product design, immersive technology, and data; she’s a believer in the artistry of technology and the technicality of art and remains passionately dedicated to democratizing access to data through universally accessible products. 

\n\n\n\'',NULL,1295107),('3_Saturday','11','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_e4277ae850844ded638d0d8d427c8178','\'\'',NULL,1295108),('3_Saturday','12','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_e4277ae850844ded638d0d8d427c8178','\'\'',NULL,1295109),('3_Saturday','13','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_e4277ae850844ded638d0d8d427c8178','\'\'',NULL,1295110),('3_Saturday','14','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_e4277ae850844ded638d0d8d427c8178','\'\'',NULL,1295111),('3_Saturday','15','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_e4277ae850844ded638d0d8d427c8178','\'\'',NULL,1295112),('3_Saturday','16','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_e4277ae850844ded638d0d8d427c8178','\'\'',NULL,1295113),('3_Saturday','17','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'BadVR: Signals Everywhere a collaboration with XR Village\'','\'Jad Meouchy,Suzanne Borders\'','Creator Events_e4277ae850844ded638d0d8d427c8178','\'\'',NULL,1295114),('3_Saturday','13','13:00','13:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'FTS Build it Yourself: cDc X OWASP X Veilid\'','\'Gibson,medus4,cdC & Veilid crew\'','Creator Talks_afad0dd20517eb38dd01acb58e5f5bb7','\'Title: FTS Build it Yourself: cDc X OWASP X Veilid
\nTags: OWASP Foundation | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Join us for a state of Veilid update, where we\'ll explore the latest progress, milestones, and what\'s next for the project as it continues to build a decentralized, privacy-first communications and networking platform.

\n\n

After the presentation, stick around for an open discussion about what it really takes to escape today\'s digital walled gardens. We\'ll talk about the challenges of reducing dependence on centralized services, the practical realities of building and adopting self-hosted and decentralized alternatives, and how open source communities can create tools that preserve privacy, autonomy, and user ownership.

\n\nSpeakers:Gibson,medus4,cdC & Veilid crew
\n
\nSpeakerBio:  Gibson
\nNo BIO available
\nSpeakerBio:  medus4
\nNo BIO available
\nSpeakerBio:  cdC & Veilid crew
\nNo BIO available
\n\n\'',NULL,1295115),('3_Saturday','10','10:00','10:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Let\'s Play! OWASP Cornucopia for Mobile Application Security Threat Modeling\'','\'Sven Schleier\'','Creator Events_944df2a20b083637ec6ed362437adc09','\'Title: Let\'s Play! OWASP Cornucopia for Mobile Application Security Threat Modeling
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Think threat modeling can\'t be fun? Think again! Join us for an interactive OWASP Cornucopia for Mobile Application Security game session, with OWASP MAS/MASTG core team member, Sven Schleier, where you\'ll team up to uncover security risks, challenge assumptions, and sharpen your secure design skills through friendly competition. Whether you\'re a developer, security professional, or just curious about mobile application security, come play, collaborate, and experience one of the most engaging ways to learn threat modeling.

\n\nSpeakerBio:  Sven Schleier, Co-Founder at Bai7 GmbH
\n

Sven has been involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project lead and author, he has made significant contributions to the OWASP MAS (Mobile Application Security) project, which is considered the industry standard for mobile application security, see https://mas.owasp.org.

\n\n

Sven is a frequent speaker and trainer around the world. His audiences range from software developers to students and penetration testers. His engagements often take him to conferences, forums and educational institutions, where he shares his extensive knowledge and insights on mobile and application security.

\n\n

--

\n\n

Sven is a co-founder of Bai7 GmbH in Austria, which is specialized in trainings and advisory. He has expertise in cloud security, offensive security engagements (Penetration Testing) and Application Security, notably in guiding software development teams across Mobile and Web Applications throughout the Software Development Life Cycle (SDLC) to integrate robust security measures in from the start.

\n\n

Besides his day job, Sven is involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project leader and author, he has significantly contributed to the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Application Security Verification Standard (MASVS).

\n\n\n\'',NULL,1295116),('4_Sunday','12','12:00','12:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Let\'s Play! OWASP Cornucopia Threat Modeling\'','\'\'','Creator Events_18c5a0d61663d3395619d8d0255d67ad','\'Title: Let\'s Play! OWASP Cornucopia Threat Modeling
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Think threat modeling can\'t be fun? Think again! Join us for an interactive OWASP Cornucopia 3.0 game session where you\'ll team up to uncover security risks, challenge assumptions, and sharpen your secure design skills through friendly competition. Whether you\'re a developer, security professional, or just curious about application security, come play, collaborate, and experience one of the most engaging ways to learn threat modeling.

\n\n\'',NULL,1295117),('3_Saturday','12','12:00','12:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Oh hai! Meet Jason Haddix\'','\'Jason \"jhaddix\" Haddix\'','Creator Events_6525ceb68b44dc6fea87c501ef30c1cc','\'Title: Oh hai! Meet Jason Haddix
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Ever spotted someone from InfoSec Twitter in the wild and chickened out on saying hi? Yeah, us too. Come embrace the social awkwardness in a safe space where everyone\'s just as nervous as you are - but also just as excited to connect. We\'re gathering the chronically online, the terminally technical, and even the legend himself, @JHaddix. Haddix is dropping by for an hour, come and say hai!

\n\nSpeakerBio:  Jason \"jhaddix\" Haddix, CEO and \"Hacker in Charge\" at Arcanum Information Security
\n

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

\n\n

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

\n\n\n\'',NULL,1295118),('3_Saturday','11','11:00','11:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Oh hai! Meet Tanya \"SheHacksPurple\" Janca\'','\'Tanya \"SheHacksPurple\" Janca\'','Creator Events_f72af45770d48d955079fdbe2781930d','\'Title: Oh hai! Meet Tanya \"SheHacksPurple\" Janca
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Ever spotted someone from InfoSec Twitter in the wild and chickened out on saying hi? Yeah, us too. Come embrace the social awkwardness in a safe space where everyone\'s just as nervous as you are - but also just as excited to connect. We\'re gathering the chronically online, the terminally technical, and even the legend herself, SheHacksPurple (Tanya Janca). Tanya is dropping by for an hour, come and say hai!

\n\nSpeakerBio:  Tanya \"SheHacksPurple\" Janca
\n

Tanya Janca, known online as SheHacksPurple, is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the CEO of She Hacks Purple Consulting, where she delivers high-impact, live, secure-coding training for engineering teams. She is also the host of DevSec Station Podcast.

\n\n

Over 29 years in the industry Tanya has received numerous awards, spoken at events worldwide, and built a reputation as one of the most approachable and influential voices in application security. She has trained thousands of developers and security practitioners through her academies and live programs. Her experience includes counter-terrorism work, leading security for the 42nd Canadian federal election, as well as building and securing a vast range of applications. Today, she is recognized internationally as a leading authority on the security of software.

\n\n\n\'',NULL,1295119),('4_Sunday','11','11:00','13:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP Chapter Meetup\'','\'\'','Creator Events_30b60a7a75f3e61cbf3d5d5bab5ef69f','\'Title: OWASP Chapter Meetup
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Sunday, Aug 9, 11:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

This one’s for the chapter leads, the regulars, the new folks, and everyone who makes OWASP what it is. Join us at DEFCON 34 for a meetup made to foster connection between OWASP chapters. It’s a chance to share wins, swap challenges, build relationships, and spark ideas that reach beyond our local scenes. Whether you’re repping your city or just curious about how others are building community, pull up. The global OWASP family is real—and this is where we get to feel it.

\n\n\'',NULL,1295120),('4_Sunday','12','11:00','13:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP Chapter Meetup\'','\'\'','Creator Events_30b60a7a75f3e61cbf3d5d5bab5ef69f','\'\'',NULL,1295121),('4_Sunday','13','11:00','13:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP Chapter Meetup\'','\'\'','Creator Events_30b60a7a75f3e61cbf3d5d5bab5ef69f','\'\'',NULL,1295122),('4_Sunday','10','10:30','12:30','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'2001: Agentic Odyssey in Threat Modeling\'','\'Petra Vukmirovic\'','Creator Workshops_7e80456b2cef4b56db4d7cecdf5793d9','\'Title: 2001: Agentic Odyssey in Threat Modeling
\nTags: OWASP Foundation | Creator Workshop
\nWhen: Sunday, Aug 9, 10:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n2001: Agentic Odyssey” is a hands-on, drop-in workshop where we threat model the HAL 9000 system from 2001: A Space Odyssey as if it were a modern agentic AI system (LLM + tools + permissions + side effects). I bring a HAL DFD, and together we mark trust boundaries and do classic “what can go wrong?” threat identification. Participants then split into small groups to build attack-tree branches and translate them into Fault Tree Analysis (FTA) using AND/OR logic and minimal cut sets, including lightweight probability estimates to prioritise the most likely failure chains. We finish by turning those failure paths into automation-ready test ideas (fault injection, invariants, evidence), and optionally drafting a structured HAL threat model for submission to the OWASP Threat Model Library. Designed so anyone can contribute in 10-15 minutes, while advanced participants can go deep on FTA and prioritisation. Every stage is split into a way to enable drop-ins at any time.
\n\n\n\nSpeakerBio:  Petra Vukmirovic, Project Leader, Threat Model Library at OWASP
\n

Petra is a technology enthusiast, leader and public speaker. A former emergency medicine doctor and competitive volleyball athlete, she thrives in challenging environments and loves creating order from chaos. Initially pursuing a medical career, Petra\'s passion for technology led her to pivot into cyber security, earning a Master’s in Information Security and Digital Forensics.

\n\n\nLinks:
    Register here - https://luma.com/l3j6ecg5
\n\'',NULL,1295123),('4_Sunday','11','10:30','12:30','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'2001: Agentic Odyssey in Threat Modeling\'','\'Petra Vukmirovic\'','Creator Workshops_7e80456b2cef4b56db4d7cecdf5793d9','\'\'',NULL,1295124),('4_Sunday','12','10:30','12:30','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'2001: Agentic Odyssey in Threat Modeling\'','\'Petra Vukmirovic\'','Creator Workshops_7e80456b2cef4b56db4d7cecdf5793d9','\'\'',NULL,1295125),('3_Saturday','14','14:00','15:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Agents & Exploits: Hacking OWASP VWAD\'','\'Philippe \"pilvar\" Dourassov\'','Creator Workshops_8179bbf331806fc08ab58e96eba7a4ab','\'Title: Agents & Exploits: Hacking OWASP VWAD
\nTags: OWASP Foundation | Creator Workshop
\nWhen: Saturday, Aug 8, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Large language models have rapidly evolved from chat interfaces into autonomous agents capable of interacting with real-world systems. In this hands-on workshop, participants will build an AI-powered security agent from the ground up and learn the core principles behind agentic penetration testing using intentionally vulnerable OWASP applications.

\n\n

Rather than simply prompting an LLM, attendees will explore how to equip an agent with practical capabilities—including shell access, browser access, and orchestration to discover, exploit, and document vulnerabilities in an OWASP vulnerable web application (VWAD). Along the way, we\'ll discuss the architecture of effective security agents, tool integration, memory, and safe execution practices.

\n\n

The workshop also introduces an iterative evaluation workflow. Participants will analyze vulnerabilities the agent failed to identify, compare results against known findings, and use those gaps to refine prompts, tool selection, workflows, and evaluation criteria. This iterative approach demonstrates how modern AI security agents can continuously improve their effectiveness through systematic testing and feedback rather than relying on a single execution.

\n\n

By the end of the session, attendees will have built a functional AI security agent, understand the fundamentals of agent tooling and orchestration, and leave with practical techniques for evaluating and improving AI-assisted security testing on OWASP vulnerable applications.

\n\nSpeakerBio:  Philippe \"pilvar\" Dourassov, AI Pentest Lead at Aikido Security
\n

Philippe Dourassov is a Swiss ethical hacker and AI security researcher. He represented Switzerland at the European Cybersecurity Challenge and later joined Team Europe at the International Cybersecurity Challenge. In 2024, he won the Gold Medal in Cyber Security at WorldSkills.

\n\n

He later worked as an independent bug hunter and security auditor at Zellic, assessing complex web applications. Philippe then co-founded Haicker, an AI-driven automated pentesting platform, which was acquired by Aikido Security. He now serves as AI Pentest Lead, building the next generation of autonomous security testing.

\n\n\nLinks:
    Register here - https://luma.com/yw0xkarr
\n\'',NULL,1295126),('3_Saturday','15','14:00','15:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Agents & Exploits: Hacking OWASP VWAD\'','\'Philippe \"pilvar\" Dourassov\'','Creator Workshops_8179bbf331806fc08ab58e96eba7a4ab','\'\'',NULL,1295127),('2_Friday','14','14:00','15:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Life Finds a Way: Secure Coding with OWASP ASVS\'','\'Eden Yardeni\'','Creator Workshops_b1e8bb055570a2600b1e86e20d463cc9','\'Title: Life Finds a Way: Secure Coding with OWASP ASVS
\nTags: OWASP Foundation | Creator Workshop
\nWhen: Friday, Aug 7, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

The fences on Apex Island were supposed to keep its visitors safe, but one hacker turned this theme park into a containment failure...with teeth. You’ll use the ASVS secure coding standard to identify and patch vulnerabilities in a lab app, bringing each park facility back online using our rigorous approach to code review. Bring a Docker-capable laptop with GitHub access; bonus if you know your way around a Unix system.

\n\nSpeakerBio:  Eden Yardeni, OWASP Contributor, SecureHabits
\n

Eden Yardeni is an application security specialist and OWASP contributor who joined the ASVS working group in 2024. She previously worked as a full-stack developer, but moved into AppSec when she heard there\'d be cookies.

\n\n\nLinks:
    Register here - https://luma.com/5geigcgf
\n\'',NULL,1295128),('2_Friday','15','14:00','15:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Life Finds a Way: Secure Coding with OWASP ASVS\'','\'Eden Yardeni\'','Creator Workshops_b1e8bb055570a2600b1e86e20d463cc9','\'\'',NULL,1295129),('2_Friday','16','16:00','17:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP Amass v5.0\'','\'Jeff Foley\'','Creator Workshops_70f5f35c435c015140d0ea8bd91345e6','\'Title: OWASP Amass v5.0
\nTags: OWASP Foundation | Creator Workshop
\nWhen: Friday, Aug 7, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

The OWASP Amass Project has become a foundational toolset for security researchers, bug bounty hunters, red teamers, and defenders who rely on automated reconnaissance and external asset discovery to map attack surfaces. With the release of Amass v5.0, the project has undergone a major architectural transformation centered around the Open Asset Model (OAM)—a structured property graph that defines how Internet-facing assets and their relationships are stored, analyzed, and queried.

\n\n

This two-hour hands-on workshop, led by Jeff Foley, the project’s founder and long-time maintainer, offers attendees a first look at Amass v5.0’s new intelligence collection engine, which seamlessly populates the Open Asset Model database during enumeration operations. The session will walk through how Amass collects and organizes OSINT from various sources—including DNS records, WHOIS/RDAP data, TLS certificates, and more—and models the results as a dynamic graph of properties and relationships between discovered assets.

\n\n

Participants will learn to use core Amass tools such as:

\n\n

amass enum – for deep, recursive asset discovery using passive and active techniques

\n\n

amass subs – for quick subdomain discovery from the Open Asset Model database

\n\n

amass viz – to render interactive visualizations of asset relationships in the Open Asset Model

\n\n

In addition to these staples, the workshop will introduce the new assoc tool, a powerful query interface designed to unlock the true potential of the Open Asset Model database. Built around a custom Triples query language, the assoc tool enables users to describe paths—called association walks—through the asset graph, surfacing linked insights across related properties (e.g., domains associated with a network, IPs linked to DNS records, etc.). The language is inspired by RDF-style triples but optimized for simplicity and clarity in cybersecurity investigations.

\n\n

Amass v5.0 also ships with completely refactored documentation, providing diagrams to help users understand the data types, their fields, and their associations within the OAM. This new documentation dramatically lowers the learning curve for users new to the Amass Project, making it easier to build mental models of how different types of Internet assets are discovered and interrelated.

\n\n

This workshop will include a live walkthrough of setting up and running Amass v5.0, from enumeration to advanced queries. Participants will leave with hands-on experience using the full Amass suite, understanding how the Open Asset Model works under the hood, and writing association walk queries using Triples.

\n\n

What to Expect:

\n\n

Real-world reconnaissance examples using Amass against publicly available targets

\n\n

Query design exercises with assoc to extract actionable intelligence

\n\n

Tips for integrating Amass data into your own tooling and pipelines

\n\n

Visual mapping of organizational assets using OAM and viz

\n\n

Level: Intermediate\nSome experience with OSINT tools, command-line interfaces, or network security is recommended but not required. The workshop is designed to be self-contained and accessible.

\n\n

Attendees are encouraged to bring a laptop and follow along. Project contributors will be present throughout the session to provide hands-on support, answer questions, and help troubleshoot issues in real time, making this a highly interactive experience.

\n\n

By the end of the session, participants will walk away with practical skills in reconnaissance, data extraction from structured asset models, and a solid understanding of how Amass v5.0 is redefining modern Internet-wide discovery.

\n\n

Join us at DEF CON to explore the future of OSINT automation and asset intelligence with OWASP Amass!

\n\nSpeakerBio:  Jeff Foley, Founder and Project Leader at OWASP Amass Project
\nNo BIO available
\n\nLinks:
    Register here - https://luma.com/n6t7cuqm
\n\'',NULL,1295130),('2_Friday','17','16:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP Amass v5.0\'','\'Jeff Foley\'','Creator Workshops_70f5f35c435c015140d0ea8bd91345e6','\'\'',NULL,1295131),('2_Friday','12','12:00','13:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP ISTG in Practice: A CTF-Style IoT Hacking & Defending Lab\'','\'Piero \"p33_p33_\" Picasso,Aaron Guzman\'','Creator Workshops_439bd4c8d69bf83c4c07914c91bcc62c','\'Title: OWASP ISTG in Practice: A CTF-Style IoT Hacking & Defending Lab
\nTags: OWASP Foundation | Creator Workshop
\nWhen: Friday, Aug 7, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Step into the world of ethical hacking and uncover the unseen vulnerabilities hiding inside everyday connected devices. This immersive, beginner-friendly lab teaches IoT security the way professionals actually practice it — using the OWASP IoT Security Testing Guide (ISTG) as your map — wrapped in an approachable Capture-the-Flag format, and led by the team that authors and field-tests the methodology.

\n\n

No experience necessary. Just bring your curiosity. Whether you’re a student, a tech enthusiast, or someone eyeing a cybersecurity career, this session makes real device hacking accessible, hands-on, and genuinely fun.

\n\n

Working against a custom-built networking device, you’ll follow the ISTG methodology from the outside in. You’ll start at the hardware: reading and interpreting physical signals to locate and identify an exposed UART interface (ISTG-PHY, ISTG-INT) — the kind of serial debug port that, in real-world assessments, hands attackers an unauthenticated root shell within minutes of opening the enclosure. Unlocking that interface opens a cyber range where you’ll pivot through firmware secrets (ISTG-FW), then practice attacks at the network and application layers — each flag mapped back to an ISTG test-case category, so you leave understanding not just how you got in, but how the risk is classified and defended.

\n\n

By the end, you’ll have a repeatable, standards-based mental model for testing any connected device — and a firsthand look at the most overlooked risks living inside the networks we all rely on.

\n\nSpeakers:Piero \"p33_p33_\" Picasso,Aaron Guzman
\n
\nSpeakerBio:  Piero \"p33_p33_\" Picasso, Senior Security Leader at Cisco
\n

Piero Picasso (p33_p33_) is a Senior Security Leader for Device Penetration Testing at Cisco, where he leads security testing for network infrastructure and IoT devices. Based in the Fort Lauderdale area, he brings over 20 years of experience in offensive security, penetration testing, and product security engineering. Over five-plus years at Cisco — including as Offensive Security Leader at Cisco Meraki — he built and scaled security testing programs for cloud-managed networking products. Earlier, he assessed Fortune 500 clients as a penetration tester at Secureworks and led ethical hacking within Citi’s regulated financial environment. He continues to advance Cisco’s device security posture through hands-on testing methodologies and cross-functional security research.

\n\nSpeakerBio:  Aaron Guzman, Project Leader at OWASP
\n

Aaron Guzman is CISO of Cisco Network Product Engineering, the organization responsible for securing Cisco’s enterprise and industrial networking portfolio — from wireless access points, routers, and switches to IoT cameras and sensors — much of the infrastructure that moves the world’s data. He is the author of the IoT Penetration Testing Cookbook and a technical reviewer for Practical IoT Hacking and Bug Bounty Bootcamp. As OWASP’s IoT Project Leader, he leads the IoT Security Testing Guide (ISTG) — the very methodology at the heart of this lab. He started as a hacker, driven by a curiosity to take things apart and make them do what they were never designed to — a curiosity that now scales across hardware, firmware, supply chains, and software at enterprise scale.

\n\n\nLinks:
    Register here - https://luma.com/zpp2nq09
\n\'',NULL,1295132),('2_Friday','13','12:00','13:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'OWASP ISTG in Practice: A CTF-Style IoT Hacking & Defending Lab\'','\'Piero \"p33_p33_\" Picasso,Aaron Guzman\'','Creator Workshops_439bd4c8d69bf83c4c07914c91bcc62c','\'\'',NULL,1295133),('3_Saturday','16','16:00','17:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Practical AI Security Assessments Using OWASP AISVS\'','\'Jim Manico\'','Creator Workshops_0318147bcee911f9a07ef58c1b9d0361','\'Title: Practical AI Security Assessments Using OWASP AISVS
\nTags: OWASP Foundation | Creator Workshop
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

How do you actually verify that an AI system is secure? In this workshop, the AISVS project leads walk through practical assessment scenarios using the OWASP AI Security Verification Standard. We\'ll work through real requirements from chapters on prompt injection defense, agentic action security, RAG/vector database hardening, and output safety controls, showing what \"verify that\" looks like in practice against running systems. Participants will leave with a working understanding of how to scope an AI security assessment, select appropriate verification levels, and apply AISVS requirements to LLM-based applications, autonomous agents, and MCP-connected tool ecosystems. Bring a laptop if you want to follow along.

\n\nSpeakerBio:  Jim Manico, Founder at Manicode Security
\n

Jim Manico is the founder of Manicode Security, where he specializes in training software developers on secure coding and security engineering. He is actively involved in multiple ventures, serving as an investor/advisor for companies like 10Security, MergeBase, Nucleus Security, KSOC, and Inspectiv, among others. Jim is a recognized speaker, focusing on secure software practices, and holds a distinguished position as a member of the Java Champion community. He is also the esteemed author of \"Iron-Clad Java: Building Secure Web Applications\" published by Oracle Press.

\n\n

Additionally, Jim generously volunteers for the OWASP foundation, co-leading key projects such as the OWASP Application Security Verification Standard and the OWASP Cheatsheet Series.

\n\n\nLinks:
    Register here - https://luma.com/3jqf6wrg
\n\'',NULL,1295134),('3_Saturday','17','16:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Practical AI Security Assessments Using OWASP AISVS\'','\'Jim Manico\'','Creator Workshops_0318147bcee911f9a07ef58c1b9d0361','\'\'',NULL,1295135),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_f550092e97cf71511e617c3e18ddfb1d','\'Title: Reali7y Overrun - Contest running
\nTags: Reali7y Overrun | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 308 (Reali7y Overrun) - Map
\n
\nDescription:
\n

Enter a near future dystopia where AI is threatening to take over the world through misinformation campaigns and leveraged takeover of automation technology. Join us for online and real world challenges, including an AI racecar challenge.

\n\n

Friday and Saturday AI \"deepracer\" style car races at the event booth racetrack:\n * Noon\n * 2pm\n * 4pm

\n\n

Sunday: Final scoring

\n\n

All race times may have one or more race events. All race events are up to 3 simultaneous racers.

\n\n

* YOU MUST COMPLETE IN-GAME CONTENT TO QUALIFY TO RACE. *

\n\n

* Good luck! *

\n\nLinks:
    More Info - https://reali7y-over.run
\n\'',NULL,1295136),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_f550092e97cf71511e617c3e18ddfb1d','\'\'',NULL,1295137),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_378910366142b1cafa29c3544cd64e65','\'Title: Reali7y Overrun - Contest running
\nTags: Reali7y Overrun | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 308 (Reali7y Overrun) - Map
\n
\nDescription:
\n

Enter a near future dystopia where AI is threatening to take over the world through misinformation campaigns and leveraged takeover of automation technology. Join us for online and real world challenges, including an AI racecar challenge.

\n\n

Friday and Saturday AI \"deepracer\" style car races at the event booth racetrack:\n * Noon\n * 2pm\n * 4pm

\n\n

Sunday: Final scoring

\n\n

All race times may have one or more race events. All race events are up to 3 simultaneous racers.

\n\n

* YOU MUST COMPLETE IN-GAME CONTENT TO QUALIFY TO RACE. *

\n\n

* Good luck! *

\n\nLinks:
    More Info - https://reali7y-over.run
\n\'',NULL,1295138),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_378910366142b1cafa29c3544cd64e65','\'\'',NULL,1295139),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_378910366142b1cafa29c3544cd64e65','\'\'',NULL,1295140),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_378910366142b1cafa29c3544cd64e65','\'\'',NULL,1295141),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_378910366142b1cafa29c3544cd64e65','\'\'',NULL,1295142),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_378910366142b1cafa29c3544cd64e65','\'\'',NULL,1295143),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_378910366142b1cafa29c3544cd64e65','\'\'',NULL,1295144),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_378910366142b1cafa29c3544cd64e65','\'\'',NULL,1295145),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_a8883b3cadda401d81c7fdee1cac3b28','\'Title: Reali7y Overrun - Contest running
\nTags: Reali7y Overrun | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 308 (Reali7y Overrun) - Map
\n
\nDescription:
\n

Enter a near future dystopia where AI is threatening to take over the world through misinformation campaigns and leveraged takeover of automation technology. Join us for online and real world challenges, including an AI racecar challenge.

\n\n

Friday and Saturday AI \"deepracer\" style car races at the event booth racetrack:\n * Noon\n * 2pm\n * 4pm

\n\n

Sunday: Final scoring

\n\n

All race times may have one or more race events. All race events are up to 3 simultaneous racers.

\n\n

* YOU MUST COMPLETE IN-GAME CONTENT TO QUALIFY TO RACE. *

\n\n

* Good luck! *

\n\nLinks:
    More Info - https://reali7y-over.run
\n\'',NULL,1295146),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_a8883b3cadda401d81c7fdee1cac3b28','\'\'',NULL,1295147),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_a8883b3cadda401d81c7fdee1cac3b28','\'\'',NULL,1295148),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_a8883b3cadda401d81c7fdee1cac3b28','\'\'',NULL,1295149),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_a8883b3cadda401d81c7fdee1cac3b28','\'\'',NULL,1295150),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_a8883b3cadda401d81c7fdee1cac3b28','\'\'',NULL,1295151),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_a8883b3cadda401d81c7fdee1cac3b28','\'\'',NULL,1295152),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 308 (Reali7y Overrun)','\'Reali7y Overrun - Contest running\'','\'\'','Contests_a8883b3cadda401d81c7fdee1cac3b28','\'\'',NULL,1295153),('2_Friday','10','10:00','10:45','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Anatomy of a Sandworm: A Deep Dive into the Shai-Hulud Attacks\'','\'Megg Sage\'','Creator Talks_ed10ae2ac5e37af8c22a2414426556a9','\'Title: Anatomy of a Sandworm: A Deep Dive into the Shai-Hulud Attacks
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\nFormat: Talk
\nLength: 20-40min (I\'m flexible, I can adjust the content based on how long the time slot is)
\n\n

Abstract:\nIn September 2025, an obscure npm package shipped with a piece of JavaScript that should not have been there. A new beast had emerged among supply chain attacks. Within 48 hours, that JavaScript had copied itself into more than 180 packages. It did something that hadn\'t been seen before in such an attack. It was self-propagating. It was a worm. And it was LOUD. Hundreds of public repos were created, littered with stolen secrets. Within nine days, it had triggered an emergency CISA alert.

\n\n

Two months later, we witnessed the \"Second Coming\": a far more aggressive successor returned, racing a deadline npm itself had set, and leaving behind roughly 700 compromised packages, ~25,000 GitHub repositories of stolen secrets, and a destructive payload that wiped victims\' home directories when it couldn\'t exfiltrate them. And these were just the first two attacks.

\n\n

This talk is a technical breakdown of the Shai-Hulud worm family: the first malware to spread successfully through the npm ecosystem as a self-replicating worm, and the iterations that followed. We\'ll examine how the malware infected its victims, turned legitimate security tooling against them, what it stole, and how it kept spreading.

\n\n

Each iteration evolved to defeat the defenses put in place against the last, swapping tools, tactics, and even its JavaScript runtime. Stranger still: the malware wasn\'t trying to hide. It branded its own exfiltration repositories, named its propagation functions clearly in source, and used victims\' own GitHub accounts to share stolen secrets. By the end, we\'ll have a clearer picture of how these supply chain worms work, and what each rising of Shai-Hulud has taught us.

\n\nSpeakerBio:  Megg Sage, AppSec engineer who explains scary things about your dependencies
\n

Megg is an application security engineer who started out as a web developer. Security drew her in with the endless puzzles and challenges put forth by the field. She loves sharing knowledge, particularly when she can both educate and frighten her audience at the same time. After all, what can happen when security goes wrong is pretty scary. She also enjoys working closely with software engineering teams to try to make security work within existing development practices or at least minimize the pain of \"doing security.\" When not behind a computer, Megg can usually be found making some sort of costume piece or shiny object.

\n\n\n\'',NULL,1295154),('2_Friday','10','10:00','16:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'Title: Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.
\nTags: Malware Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Demos - Map
\n
\nDescription:
\n

Malysis runs Windows bare-metal directly from RAM. No hypervisor, no disk writes, no forensic footprint. A custom kernel-mode storage driver presents RAM as a native NVMe device, fully opaque to the OS, to malware, and to any forensic tooling. Warm reboots preserve full analysis state | the environment survives restarts intact. Full shutdown is total: power off brutally and the next boot loads a cryptographically validated pristine image from the source. The RAM substrate delivers native NVMe performance: 50+ GB/s sequential, 1M+ IOPS, with full Windows environments. No persistent storage writes. No recovery.\nBuilt for analysts who need bare-metal behavior without burning hardware.

\n\nSpeakers:Yannick LaRue,Samuel B. G.
\n
\nSpeakerBio:  Yannick LaRue, Malware Village - Malysis
\n

30 years of low-level programming in C with 0 use of libraries, oriented in cryptography and high-security systems.

\n\nSpeakerBio:  Samuel B. G., Treasurer@ Malware Village, Founder @ Securitech Systems, Co-Founder @ Malysis
\n

Sam is a cybersecurity and datacenter expert and works mainly on on-premise and sovereign solutions for cybersecurity, AI and architectures networks and secure hosting in facilities across Canada. In his free time, he participates yearly in many conferences and organizes Malware Village, a Canadian cybersecurity non-profit that presents at conferences like Defcon and Bsides around the world.

\n\n

That\'s what i could come up with haha let me know if it works!

\n\n\nLinks:
    malysis.ca - https://malysis.ca
\n\'',NULL,1295155),('2_Friday','11','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295156),('2_Friday','12','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295157),('2_Friday','13','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295158),('2_Friday','14','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295159),('2_Friday','15','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295160),('2_Friday','16','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295161),('2_Friday','10','10:00','16:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'Title: Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.
\nTags: Malware Village | Misc
\nWhen: Friday, Aug 7, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Demos - Map
\n
\nDescription:
\n

Malysis runs Windows bare-metal directly from RAM. No hypervisor, no disk writes, no forensic footprint. A custom kernel-mode storage driver presents RAM as a native NVMe device, fully opaque to the OS, to malware, and to any forensic tooling. Warm reboots preserve full analysis state | the environment survives restarts intact. Full shutdown is total: power off brutally and the next boot loads a cryptographically validated pristine image from the source. The RAM substrate delivers native NVMe performance: 50+ GB/s sequential, 1M+ IOPS, with full Windows environments. No persistent storage writes. No recovery.\nBuilt for analysts who need bare-metal behavior without burning hardware.

\n\nSpeakers:Yannick LaRue,Samuel B. G.
\n
\nSpeakerBio:  Yannick LaRue, Malware Village - Malysis
\n

30 years of low-level programming in C with 0 use of libraries, oriented in cryptography and high-security systems.

\n\nSpeakerBio:  Samuel B. G., Treasurer@ Malware Village, Founder @ Securitech Systems, Co-Founder @ Malysis
\n

Sam is a cybersecurity and datacenter expert and works mainly on on-premise and sovereign solutions for cybersecurity, AI and architectures networks and secure hosting in facilities across Canada. In his free time, he participates yearly in many conferences and organizes Malware Village, a Canadian cybersecurity non-profit that presents at conferences like Defcon and Bsides around the world.

\n\n

That\'s what i could come up with haha let me know if it works!

\n\n\nLinks:
    malysis.ca - https://malysis.ca
\n\'',NULL,1295162),('2_Friday','11','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295163),('2_Friday','12','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295164),('2_Friday','13','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295165),('2_Friday','14','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295166),('2_Friday','15','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295167),('2_Friday','16','10:00','16:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 2 600 (Malware Village) Demos','\'Malysis: A Bare-Metal RAM Enclave for Malware Analysis. No Hypervisor. No Trace.\'','\'Yannick LaRue,Samuel B. G.\'','Social Gatherings/Events_9f36c0e249c111350df3adc7227dffe5','\'\'',NULL,1295168),('2_Friday','10','10:10','11:40','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'The Silent Tunneler: A Real-World Incident Response Story\'','\'Uriel Kosayev\'','Creator Workshops_bdb8ccff29bf8a0c5b8051a7986cacc1','\'Title: The Silent Tunneler: A Real-World Incident Response Story
\nTags: Malware Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:10 - 11:40 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map
\n
\nDescription:
\n

Some backdoors are noisy. Others whisper.

\n\n

During a real-world Incident Response investigation, I uncovered an unusually stealthy Linux persistence mechanism that had silently granted an attacker continued access to a compromised system. Even more concerning - it was used to establish an SSH tunnel, allowing undetected remote control while evading traditional security measures.

\n\n

But that wasn’t all. Further analysis led to an even bigger discovery: a live Mirai botnet infection, actively communicating with its command-and-control server. By reverse engineering the malware, I unraveled how it spread, operated, and executed attacks.

\n\n

This talk is a practical, real-world case study, covering:\n* How I uncovered an unconventional backdoor that nearly went unnoticed.\n* The attacker’s use of SSH tunneling for covert persistence.\n* Reverse engineering a Mirai botnet sample and dissecting its attack mechanisms.\n* Key lessons for defenders to detect and respond to stealthy threats.

\n\n

Expect live demonstrations, technical deep dives, and actionable insights to strengthen your EDR detection capabilities.

\n\nSpeakerBio:  Uriel Kosayev, Security Researcher, Trainer & Speaker | Author of the Antivirus Bypass Techniques book | Founder of TrainSec Academy
\n

Uriel Kosayev is a seasoned cybersecurity researcher, reverse engineer, and keynote speaker with over a decade of hands-on experience in malware analysis, offensive security, and real-world incident response.

\n\n

He is the founder of TrainSec Academy and the author of Antivirus Bypass Techniques and MAoS – Malware Analysis on Steroids, two highly regarded resources in the cybersecurity community. Uriel has worked with global enterprises, led red team operations, and conducted high-impact malware investigations that exposed advanced threat actor tactics.

\n\n

Known for his ability to break down complex topics into practical, actionable knowledge, Uriel teaches with one goal in mind: to make professionals think like attackers and act like defenders. His courses are packed with real-world examples, battle-tested techniques, and a methodology built on actual field experience, not textbook theory.

\n\n\n\'',NULL,1295169),('2_Friday','11','10:10','11:40','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'The Silent Tunneler: A Real-World Incident Response Story\'','\'Uriel Kosayev\'','Creator Workshops_bdb8ccff29bf8a0c5b8051a7986cacc1','\'\'',NULL,1295170),('2_Friday','10','10:55','11:35','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Lyra: An LLVM IR Obfuscator for Rust\'','\'Rafael Felix\'','Creator Talks_34aea628ca4e89be7f00a3739852a82d','\'Title: Lyra: An LLVM IR Obfuscator for Rust
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:55 - 11:35 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

Rust is rapidly becoming the language of choice for red team tooling, implants,\nand security-critical software. Yet the offensive security ecosystem has almost\nno obfuscation tooling for it. Nearly every production obfuscator targets C/C++\nbinaries or operates on final PE/ELF images; Rust\'s unique compile pipeline,\nname mangling, and LLVM IR patterns require a fundamentally different approach.

\n\n

This talk presents Lyra, an open-source, cargo-native LLVM IR obfuscator for\nRust. Lyra intercepts each crate during a normal \"cargo build\" via\nRUSTC_WRAPPER, transforms the LLVM IR with a configurable pass pipeline -\nstring encryption, basic-block shuffling, indirect-branch obfuscation -\nrecompiles the result with llc + clang, and substitutes the object before the\nreal MSVC linker runs. Zero changes to the Rust compiler, zero changes to the\ntarget project\'s source code, one flag on the command line.

\n\n

We walk through the architecture, the engineering challenges unique to\nWindows/MSVC (UTF-16 response files, allocator-shim object preservation,\ninkwell\'s undocumented panic guards), and live before-and-after demonstrations\nin IDA Pro, Ghidra, and Binary Ninja.

\n\n

We also show a YARA rule that confidently matches a plain demo build returning\nzero results on the obfuscated binary, and two consecutive unseeded builds\nproducing different hex patterns, defeating a rule written on the first build.

\n\n

Lyra is released open-source at the time of the talk. All demos are\nreproducible from the release. Attendees leave with a working tool they can\nrun against their own Rust projects the same day.

\n\nSpeakerBio:  Rafael Felix, Offensive Security Lead at Hakai Offensive Security
\n

Rafael has been working with malware development for 5 years, also being involved in the malware community for more than 7 years. He is also experienced in Incident and Response, specifically during malware inner workings analysis. Currently, Rafael is a researcher for Hakai Offensive Security (https://hakaisecurity.io/research-blog), being deeply involved with red-team operations.

\n\n\n\'',NULL,1295171),('2_Friday','11','10:55','11:35','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Lyra: An LLVM IR Obfuscator for Rust\'','\'Rafael Felix\'','Creator Talks_34aea628ca4e89be7f00a3739852a82d','\'\'',NULL,1295172),('2_Friday','12','12:10','14:10','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'Introduction to Reverse Engineering With Ghidra\'','\'Wesley McGrew\'','Creator Workshops_f7237435bce912f873646af6f982185c','\'Title: Introduction to Reverse Engineering With Ghidra
\nTags: Malware Village | Creator Workshop
\nWhen: Friday, Aug 7, 12:10 - 14:10 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map
\n
\nDescription:
\n

In this workshop, Dr. Wesley McGrew will be presenting a live and unscripted introduction to using Ghidra to reverse engineer real malware samples, targeting people who are new to malware reverse engineering, but have some programming background.

\n\n

Dr. McGrew will cover the Ghidra user interface, how to load samples, perform initial processing, and how to navigate around a malicious binary. Then, for most of the workshop time, he will provide commentary, advice, heuristics, and approaches for malware analysis as the workshop group takes a look at one or more samples live on the projector.

\n\n

This workshop is meant to be interactive, driven by attendee questions and interests. Beyond the essentials needed to load malware into Ghidra, the workshop attendees and Dr. McGrew will be collaborating on the direction of the workshop material.

\n\nSpeakerBio:  Wesley McGrew, Senior Cyber Fellow at MartinFed
\n

Dr. Wesley McGrew directs research, development, reverse engineering, and offensive cyber operations as Senior Cybersecurity Fellow for MartinFederal. He has presented at DEF CON and Black Hat USA on topics of penetration testing, malware analysis, critical infrastructure, and vintage computing, and has taught self-designed courses on reverse engineering and cyber operations at Mississippi State University. Wesley has a Ph.D. in Computer Science from Mississippi State University for his research in vulnerability analysis of SCADA HMI systems. He has entertained audiences at many DEF CON parties as a house music DJ, as well.

\n\n\n\'',NULL,1295173),('2_Friday','13','12:10','14:10','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'Introduction to Reverse Engineering With Ghidra\'','\'Wesley McGrew\'','Creator Workshops_f7237435bce912f873646af6f982185c','\'\'',NULL,1295174),('2_Friday','14','12:10','14:10','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'Introduction to Reverse Engineering With Ghidra\'','\'Wesley McGrew\'','Creator Workshops_f7237435bce912f873646af6f982185c','\'\'',NULL,1295175),('2_Friday','12','12:25','13:05','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'North Korea’s Zoo: Poaching for Gophers, Armadillos and RATs\'','\'Mauro Eldritch\'','Creator Talks_77005ce9741e6ef0af1d1b9193f72871','\'Title: North Korea’s Zoo: Poaching for Gophers, Armadillos and RATs
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:25 - 13:05 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

In this talk, a continuation of the North Korea’s Zoo series, we take apart three new malware samples linked to North Korean operators: a fresh iteration of GoLangGhostRAT, POWerful Armadillo (a rework of Digit Stealer), and Mach-O Man, a new macOS malware kit. All of them were first-spotted and reversed by our team.

\n\n

We will focus on what actually matters: interesting bits of code, mistakes in their infrastructure, and how we were able to abuse their C2 to profile campaigns and mess with their operations.

\n\n

We’ll also cover how these samples are being distributed, including some newer tricks we’ve been seeing in the wild.

\n\n

At several points, we ended up talking directly with the operators themselves. We’ll be sharing those interactions here for the first time.

\n\n

This talk can be enjoyed by both beginners and seasoned threat hunters alike.

\n\nSpeakerBio:  Mauro Eldritch, Leader at Bitso Quetzal Team
\n

Hacker and Speaker.

\n\n

Founder of BCA LTD and DC5411.

\n\n

I wrote a book interviewing Threat Actors.

\n\n

I like Threat Intelligence and Golden Retrievers.

\n\n\n\'',NULL,1295176),('2_Friday','13','12:25','13:05','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'North Korea’s Zoo: Poaching for Gophers, Armadillos and RATs\'','\'Mauro Eldritch\'','Creator Talks_77005ce9741e6ef0af1d1b9193f72871','\'\'',NULL,1295177),('2_Friday','13','13:15','13:55','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Return of Sedinho: Current situation and new tactics of the Brazilian banking trojan ecosystem\'','\'Josep Albors\'','Creator Talks_ee876daf11566d2c0bb6fb3432095550','\'Title: Return of Sedinho: Current situation and new tactics of the Brazilian banking trojan ecosystem
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:15 - 13:55 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

Last year we presented our research on the evolution of Brazilian banking trojans, their expansion into countries well beyond their original sphere of influence, and the law enforcement operations that attempted to disrupt their activity. Building on that work, this talk revisits the current landscape and examines the latest improvements and changes introduced by the malware operators behind these groups.\nIn this session, we will analyze several recent financially motivated campaigns that show how Latin American threat actors are not only evolving classic banking malware, but also introducing NFC based mobile fraud against victims in multiple countries. We will provide concrete examples of how well known families such as Grandoreiro and Casbaneiro are refining both their techniques and their social engineering narratives while continuously adapting their malware infection chains and evasion strategies.\nWe will also introduce their newest Android campaigns that leverage NFC fraud through a new NGate variant that masquerades as legitimate applications intended to relay NFC card data between devices. Cybercriminals distribute these trojanized apps under various pretexts, including online banking tools, lottery apps, and shopping applications. Once installed, the malware intercepts NFC payment card data and the victim’s PIN, forwarding them to attacker controlled infrastructure to enable contactless ATM cash outs and fraudulent POS transactions, all without requiring additional risky permissions.\nThroughout the talk, we will walk through the observed tactics, techniques, and procedures, highlighting how the malware code, supporting infrastructure, and social engineering patterns have changed compared to the campaigns we analyzed previously. Our goal is to raise awareness of the ongoing evolution of these Latin American originated malware operations and to equip security teams with the context they need to detect and block these threats before they can cause damage to their organizations

\n\nSpeakerBio:  Josep Albors, Head of Awarenes & Research at Ontinet.com (ESET Spain)
\n

Josep Albors is the Head of Awareness & Research at Ontinet.com (ESET Spain). He\'s a security expert with more than 21 years working in cybersecurity and specialized in security awareness. He is also the editor at the company\'s blog and one of the experts writing at several other publications related with the IT security world in Spain.

\n\n

He has been a speaker at some of the most important security conferences in Spain, besides collaborating with initiatives such as X1RedMasSegura, that wants to raise awareness among users so they can use Internet and technology in a safe way. Included in Ontinet\'s social responsability, Josep also does awareness and cybersecurity presentations in schools and universities. He\'s also a teacher in cyber security expert courses at several Spanish Universities and participates in several conferences organized by several spanish universities and Spain\'s national Institute of Cyber Security. He also participated as speaker at AVAR conference in Osaka in 2019, Caro Workshop 2023 in Bochum (Germany), FIRST 2024 (Fukuoka), Virus Bulletin 2024 (Dublín), Defcon Malware Village (2025), JSAC 2025 (Tokyo) and CARO 2026 (Innsbruck).

\n\n

Josep has also collaborated with the Spanish Guardia Civil, Spanish National Police and the Spanish Army, teaching their units on how to fight cybercrime and with cyber intelligence training, contributing with his experience in analyzing cybercrime and malware.

\n\n\n\'',NULL,1295178),('2_Friday','14','14:05','14:45','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Smart Contracts, Smarter Malware: Automating Recon on Blockchain-Based C2\'','\'Sai Sathvik Ruppa,Chris Navarrete\'','Creator Talks_742b24331a8d83296e836a3b3a90930d','\'Title: Smart Contracts, Smarter Malware: Automating Recon on Blockchain-Based C2
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:05 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

Threat actors are moving their command-and-control (C2) infrastructure to the blockchain, where smart contracts are immutable, globally accessible, and completely immune to traditional takedowns. Instead of reaching out to attacker-controlled servers, modern malware families query public blockchain RPC endpoints to retrieve C2 instructions written directly into smart contracts across a variety of ecosystems. No attacker server, no domain to seize, no hosting provider to contact.

\n\n

In this talk, we break down our investigation into malware families actively utilizing multi-chain smart contracts as an evasive C2 channel. We will cover how we analyzed network traffic to identify decentralized communication patterns, queried live contract methods to extract real-time C2 data, and used cross-chain bytecode analysis to map shared infrastructure across multiple samples.

\n\n

We will demonstrate a unified framework that consolidates these individual recon methodologies, automating the extraction, tracking, and reverse-engineering of multi-chain blockchain-based malware infrastructure.

\n\nSpeakers:Sai Sathvik Ruppa,Chris Navarrete
\n
\nSpeakerBio:  Sai Sathvik Ruppa, Staff Security Researcher at Palo Alto Networks
\n

Sai Sathvik Ruppa is a Staff Security Researcher at Palo Alto Networks and a recent M.S. graduate in Information Security from Carnegie Mellon University. He specializes in vulnerability detection and malware analysis, leveraging his expertise to identify, analyze, and mitigate advanced cyber threats.

\n\nSpeakerBio:  Chris Navarrete, Senior Principal Security Researcher - CDSS Advanced Threat Prevention (ATP) at Palo Alto Networks
\n

Chris Navarrete is a Senior Principal Security Researcher within the Advanced Threat Prevention team at Palo Alto Networks. His work centers on cutting-edge research in cybersecurity, particularly in threat detection and malware analysis. Previously, he served as an adjunct professor of computer science at San Jose State University, teaching Software Security Technologies. He holds a Master of Science in software engineering with a specialization in cybersecurity from San Jose State University. Chris has presented at major industry conferences, including Black Hat Asia, the Computer Antivirus Research Organization (CARO), the Cyber Threat Alliance\'s Threat Intelligence Practitioners (TIPS) conference, and Black Hat Arsenal, where he introduced and released BLACKPHENIX — a framework designed to automate malware analysis workflows.

\n\n\n\'',NULL,1295179),('2_Friday','14','14:10','17:25','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'The Achaean project-Trojan development for noobs\'','\'Leigh Gilbert\'','Creator Workshops_95476c372570e50bfe628cfeb2e1a587','\'Title: The Achaean project-Trojan development for noobs
\nTags: Malware Village | Creator Workshop
\nWhen: Friday, Aug 7, 14:10 - 17:25 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map
\n
\nDescription:
\n

4 hour workshop. 1hr Lecture on trojan creation. Followed by 2 hrs hands on practice creating trojans, setting up malware servers. Using C## loaders and malicious dll\'s to trojanise normal programs with ransomware. Instructor aide and easy to follow instructions throughout.

\n\n

1 hr CTF. Students will develop their own new trojan containerize it and send to our victim computer. Prizes.

\n\nSpeakerBio:  Leigh Gilbert, Malware village
\n

Leigh Trinity is a Canadian exploit developer, red team hacker, and instructor known for her work in binary exploitation and reverse engineering. Now branching out into malware development.

\n\n\n\'',NULL,1295180),('2_Friday','15','14:10','17:25','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'The Achaean project-Trojan development for noobs\'','\'Leigh Gilbert\'','Creator Workshops_95476c372570e50bfe628cfeb2e1a587','\'\'',NULL,1295181),('2_Friday','16','14:10','17:25','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'The Achaean project-Trojan development for noobs\'','\'Leigh Gilbert\'','Creator Workshops_95476c372570e50bfe628cfeb2e1a587','\'\'',NULL,1295182),('2_Friday','17','14:10','17:25','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'The Achaean project-Trojan development for noobs\'','\'Leigh Gilbert\'','Creator Workshops_95476c372570e50bfe628cfeb2e1a587','\'\'',NULL,1295183),('2_Friday','14','14:55','15:35','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'The State of Decompiler Malware\'','\'Christopher \"Piffd0s\" Hernandez\'','Creator Talks_2d0efaed17035c7f416d8903cb9a98cc','\'Title: The State of Decompiler Malware
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:55 - 15:35 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

This research introduces Decompiler Malware, an underexplored threat category targeting reverse engineering platforms such as IDA Pro. The work began with the discovery and analysis of a malicious IDA Pro plugin that established a covert encrypted backdoor capable of remotely interacting with the analyst environment, manipulating analysis workflows, and exfiltrating decompiled pseudocode and reverse engineering artifacts on demand.

\n\n

By examining the malware’s architecture, command capabilities, and operational design, this research highlights how reverse engineering workstations represent a uniquely valuable but insufficiently defended attack surface (unless air-gapped).

\n\nSpeakerBio:  Christopher \"Piffd0s\" Hernandez, Binary Enthusiast
\n

Chris Hernandez is a security researcher specializing in vulnerability discovery, exploitation, and large scale reverse engineering using IDA Pro. A Pwn2Own competitor in the ICS/SCADA and embedded systems categories, he actively collaborates with the reverse engineering community to solve binary analysis challenges.

\n\n

--

\n\n

Chris Hernandez is the founder of Adversary Consulting Group and an offensive security researcher with more than a decade of experience in vulnerability research, reverse engineering, and exploit development. He holds the OSEE certification and has competed at Pwn2Own in the IoT and ICS/SCADA categories.

\n\n\n\'',NULL,1295184),('2_Friday','15','14:55','15:35','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'The State of Decompiler Malware\'','\'Christopher \"Piffd0s\" Hernandez\'','Creator Talks_2d0efaed17035c7f416d8903cb9a98cc','\'\'',NULL,1295185),('2_Friday','15','15:45','16:25','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Vibe Check: Exploiting Developer Trust from Prompt Injections to Weaponized Repos\'','\'Michael Chan\'','Creator Talks_5706d543b47c6146efd70e8045320fe0','\'Title: Vibe Check: Exploiting Developer Trust from Prompt Injections to Weaponized Repos
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:45 - 16:25 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

\"Do you trust the authors of the files in this folder?\" It\'s a prompt modern IDEs throw at developers, and most click past it by reflex. But as vibe coding, AI-assisted tooling, and automated agents accelerate software development, that implicit trust in established tools like VS Code and authoritative sources like GitHub has become a critical, highly exploitable attack surface and malware delivery channel - especially for non-technical vibe coders.

\n\n

This hands-on workshop places attendees directly in the mindset of an attacker targeting modern development environments. We move beyond traditional social engineering and focus on how trust is abused through the tools developers rely on every day: IDEs, agent harnesses, and package managers. After dissecting recent real-world cases of developer-targeted attacks and AI-agent vulnerabilities, we transition into labs where participants build and execute their own PoCs - including constructing malicious repositories from scratch to trigger invisible code execution on folder open, weaponizing hidden prompt injections to drive AI agents into running attacker-controlled commands, and standing up a custom \"Claude Code\"- style agent harness to attack ourselves.

\n\n

Agenda:\n⚠️ How your trusted IDEs betray you by executing malicious commands automatically\n⚠️ How agent harnesses like Claude Code and Gemini CLI can be abused across multiple trust boundaries\n⚠️ How package managers like npm turn seemingly harmless actions, like a routine package update, into full compromise

\n\n

Bring a laptop - we\'ll get our hands dirty and hack ourselves together.

\n\nSpeakerBio:  Michael Chan, Senior Offensive Security Consultant at KPMG Canada
\n

Michael is a social scientist turned hacker. He started by studying human behaviour and trust at Oxford - now he brings that lens into offensive security, validating and breaking the assumptions built into applications, systems, and organizations. As a Senior Offensive Security Consultant at KPMG Canada, Michael works across application security, threat modelling, and adversary simulation. Outside of work, he spends most of his time learning, building, breaking fun new tech (yes AI included), and engaging with local cyber communities.

\n\n\n\'',NULL,1295186),('2_Friday','16','15:45','16:25','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Vibe Check: Exploiting Developer Trust from Prompt Injections to Weaponized Repos\'','\'Michael Chan\'','Creator Talks_5706d543b47c6146efd70e8045320fe0','\'\'',NULL,1295187),('2_Friday','16','16:35','17:15','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'You Hold the Helm: Agentic LLM Workflows for Malware Reversing\'','\'Asher Davila,Lenin Alevski\'','Creator Talks_67388d90ffffae7676df23e2313ecdeb','\'Title: You Hold the Helm: Agentic LLM Workflows for Malware Reversing
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:35 - 17:15 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

Malware analysts are integrating LLMs into their reversing workflows today, in real casework. The MCP integrations for IDA Pro, Ghidra, radare2, and Binary Ninja already exist and are publicly available, and analysts are using them to rename functions, triage samples, and hunt for vulnerabilities. Adoption has outpaced any measured account of where these tools are reliable and where they are not. There is also a cost problem that gets little attention: running an agent against a single sample can burn an enormous number of tokens, much of it spent having the model rediscover the same things on every binary. This session addresses both. We built an agentic malware analysis framework, tested it across multiple models and real samples scored against ground truth, and we are bringing the numbers along with the workflows.\nThe framework connects LLMs directly to disassemblers and decompilers through MCP, and wraps that with per-language skills for the malware families analysts actually encounter: C and C++, C#, Go, and Android. Each skill encodes what the runtime looks like, how the decompiler tends to mangle that specific target, which structures and metadata are worth recovering first, and what the model can safely ignore. The Go skill carries knowledge of the pclntab and the runtime\'s calling conventions. The C# skill assumes IL and metadata tables rather than native code. The Android skill separates the DEX, the native libraries, and the manifest, and knows where behavior usually hides. The skills exist for efficiency. Without them, the model relearns the same Go runtime layout on every sample and pays the same token cost to reach the same conclusion. With them, that context is supplied once and the model spends its budget on the sample.\nThe framework runs inside Docker containers orchestrated through an ADK agent loop. Three concrete reasons make this matter. Isolation keeps live malware analysis off the host. Reproducibility means the same container, skill, and sample produce similar starting conditions every time, which is what makes any claim about model performance meaningful. Disposability means that when an agent corrupts its own analysis state, and it will, you tear the container down and start clean rather than nursing a polluted session. The ADK loop is what lets the agent act on its own: pulling function lists, following cross-references, reading decompiled output, and issuing disassembler commands. It is also where most of the interesting failures show up when the agent is not constrained.\nFunction renaming and summarization on stripped binaries holds up well, but only when functions are fed with surrounding call context rather than dumped in bulk. Behavioral triage, the question of what a sample does and where to look first, is faster through the agent than manual function-list review, and the benefit is largest for less experienced analysts. Pattern matching across a binary is reliable when you specify the class of issue to look for. The per-language work also pays off on Go and Rust samples, where traditional C and C++ oriented decompilers produce walls of indistinguishable functions and the LLM-assisted workflow often cuts through what the tooling alone cannot.\nThe failures matter as much as the wins. Crypto identification is where the models are most confidently wrong, mapping anything stream-cipher-shaped onto whatever algorithm they saw most in training. Deobfuscation of any serious protection scheme breaks down quickly. CVE matching is the most consequential failure, because a fabricated CVE number reads with the same authority as a real one, and an analyst who puts it into a threat report has introduced an error that is hard to catch later and can misdirect incident response. Scope drift shows up throughout: left unconstrained, the agent will decide on its own that you wanted detection rules when you asked for unpacker analysis. We show each of these failure modes on screen with the actual model output.\nThe core of the session is a direct comparison, the same model and the same sample, run two ways. First pass is a minimal prompt with the agent left to default behavior. Second pass, we drive, selecting which functions to examine, supplying context through the right per-language skill, and constraining the output format. The model does not get smarter between passes. We get more deliberate about how we use it, and the output diverges sharply. That is the thesis as a demo rather than a claim: the analyst is the captain and the model is the crew, and analysis quality tracks almost entirely with how well it is steered. We walk the comparison side by side on real samples, and ship the demo binaries and both prompt sets with the talk.\nAttendees leave learning how to do a full setup: the Docker containers, the ADK agent scaffolding, the per-language skills for C and C++, C#, Go, and Android, and the prompt templates that worked alongside the ones that did not. They can install it, run the same comparisons we ran, and extend the evaluation to their own samples and analysis tasks. They also leave with a calibrated sense of which tasks are safe to hand to an agent, which require careful steering, and which should never be trusted without manual verification. Additionally, we will open source our framework the day of the talk.

\n\nSpeakers:Asher Davila,Lenin Alevski
\n
\nSpeakerBio:  Asher Davila, Vulnerability Researcher at Palo Alto Networks
\n

Passionate about binary analysis, binary exploitation, reverse engineering, hardware hacking, retro computing, and music.

\n\nSpeakerBio:  Lenin Alevski, Security Engineer at Google
\n

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.

\n\n\n\'',NULL,1295188),('2_Friday','17','16:35','17:15','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'You Hold the Helm: Agentic LLM Workflows for Malware Reversing\'','\'Asher Davila,Lenin Alevski\'','Creator Talks_67388d90ffffae7676df23e2313ecdeb','\'\'',NULL,1295189),('3_Saturday','10','10:00','10:35','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits\'','\'Jiří Vinopal\'','Creator Talks_4e6238baca284f05e1b15db3dd01f926','\'Title: Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:35 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\nAbstract:
\nWhat happens when a leaked malware builder suddenly opens the door for anyone — from low-tier criminals to advanced operators — to deploy a backdoor armed with a kernel-capable rootkit? What happens when that rootkit still carries valid signatures, and Windows 11 willingly loads it?
\n\n

In this talk, Check Point Research unveils a comprehensive reverse engineering of ValleyRAT, a modular backdoor family also known as Winos/Winos4.0. By dissecting the publicly leaked builder and its development artifacts, we reconstruct the malware’s architecture from the ground up, uncovering a highly organized plugin ecosystem and coding style that reveals a small, specialized team with deep knowledge of the Windows kernel.

\n\n

The standout finding: ValleyRAT’s Driver Plugin, containing a stealthy and surprisingly robust kernel-mode rootkit. Despite being abused by multiple operators, several variants remain validly signed, bypassing Microsoft’s driver protections and loading successfully on the latest Windows builds. The rootkit’s functionality — including coercive AV/EDR driver deletion, silent installation methods, and APC-based shellcode injection — demonstrates a level of sophistication rarely seen in malware distributed through public builders.

\n\n

Our telemetry and detection work further expose a dramatic rise in ValleyRAT’s presence in the wild. Roughly 85% of detected plugin samples surfaced within the past six months, directly following the builder leak. This surge marks a turning point: ValleyRAT is no longer a tool reliably associated with specific Chinese-speaking threat actors, but rather an accessible platform fueling opportunistic and un-attributable campaigns.

\n\n

This research pulls back the curtain on ValleyRAT’s internals, its kernel rootkit mechanics, and the implications of a powerful multi-module malware ecosystem becoming available to the masses. When sophisticated tooling escapes into the wild, who gets to wield it — and who pays the price?

\n\nSpeakerBio:  Jiří Vinopal, Threat Researcher at Check Point Research
\n

Jiří Vinopal is a security researcher, malware researcher, and reverse engineer at Check Point Research, focused on advanced cyber threats, kernel internals, and the hidden mechanics of undocumented system components. His work spans uncovering novel attack primitives, reconstructing proprietary protocols from binary analysis alone, and deep-diving into both sophisticated malware families and trusted platform components. When he\'s not buried in disassembly, he actively shares his knowledge and passion for reverse engineering across his X account, YouTube channel, and blog — delivering tips, tricks, and technical insights to fellow enthusiasts and the broader security community.

\n\n\n\'',NULL,1295190),('3_Saturday','10','10:10','12:10','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'Hostile Input: PDF Triage That Survives an Adversarial Document\'','\'Klaus Wunder\'','Creator Workshops_1d48f5bb384c3eb1ecea8290b996a7cd','\'Title: Hostile Input: PDF Triage That Survives an Adversarial Document
\nTags: Malware Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:10 - 12:10 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map
\n
\nDescription:
\n

Abstract\nA malicious document is no longer only a payload for the endpoint. It is an input your tooling has to parse and judge, and as SOC teams bolt language models onto triage, that input becomes something an attacker can shape to corrupt the verdict itself. This workshop treats the document as an adversarial surface aimed at the analyst’s tooling, including the analyst’s AI.

\n\n

It is hands-on, starting from basic command-line tools, participants build the techniques that defeat AI-assisted triage, then build triage that survives them: a prompt injection placed where no human reader sees it, a metadata and ToUnicode parser differential where the renderer and the extractor disagree on the same glyphs, and a staged payload the document never reveals on its own. The two contributions that carry the workshop are treating extractor disagreement as a detection signal, and a triage architecture where a deterministic stage owns the verdict and the model is confined to advisory roles downstream of it.

\n\n

Participants leave with a working pipeline, the sample set, and a scoring harness, and can state exactly where a language model belongs in triage and why putting it anywhere else is the vulnerability. The pipeline runs locally on modest models, because the detection power is in the tooling, not the model. Clean files never leave the environment.

\n\n

Outline\nDeterministic floor. Point an autonomous agent at a file, watch an indirect injection in the document hijack it. That failure is the problem statement. Participants then lay the structural floor with pdfid and pdf-parser: the facts an attacker cannot phrase their way out of.

\n\n

Demote the model. Analyze a malicious PDF structurally, then watch a hidden render-mode injection talk a naive model pipeline into a clean verdict. Rebuild it so a deterministic stage owns the verdict and the model is fed structural findings, not the attacker’s prose. Rule: extracted content is untrusted input, never instruction.

\n\n

Add redundancy: the parser differential. Two documents that defeat detection by placement alone: an injection living in metadata a body-text extractor never reads, a ToUnicode trick that makes the rendered page and the extracted text disagree on identical glyphs. Participants build a multi-extractor differential and treat disagreement as the alert.

\n\n

Resolve, and place the model. A staged payload forces the last lesson: Participants add input validation and type-confusion detection at the floor, extract the hidden artefact as a suspicion finding, decode it in-terminal, and let bounded model roles explain it and assemble competing hypotheses with evidence while the analyst decides. The model advises downstream of a deterministic gate, never holds the verdict.

\n\n

Capstone CTF and Q&A. A fresh set: technique-carriers, clean decoys, and documents styled as beingenin PDFs Sthat baits the analyst into pasting it straight into the model. Participants show their work: verdict, technique, extraction path, hidden URLs, execution behaviour. Scoring rewards correctness first, then fewest tokens, because the analyst who needed the model least played the strongest game.

\n\n

Learning objectives\nParticipants will be able to:\n1. Build a PDF triage pipeline from command-line tools and explain exactly where its verdict comes from.\n2. Analyze a malicious PDF structurally (pdfid, pdf-parser, stream inspection) and decode embedded artefacts in-terminal.\n3. Construct and recognize the three adversarial-document techniques that defeat AI-assisted analysis: hidden-layer prompt injection, metadata and ToUnicode parser differentials, and staged payloads.\n4. Distinguish an early structural suspicion verdict from a late analytical identification verdict, and treat extractor disagreement as a detection signal.\n5. Place a language model in bounded advisory roles downstream of a deterministic gate, never holding the verdict, and select the right model for each task.\n6. Run the whole pipeline locally on modest models, understanding why the detection power lives in the tooling and why the architecture is private by construction.

\n\nSpeakerBio:  Klaus Wunder, Principal Cyber Defence Analyst at SECUINFRA
\n

With nearly two decades in cybersecurity, Klaus has gone from configuring firewalls to protecting industrial control systems where breaches cost safety, not just data. That journey gives him a full-spectrum perspective on security operations. He guides teams through complex incidents and builds detection engineering capabilities across hybrid environments as a Principal Cyber Defence Analyst, while his role as an Authorized OffSec Instructor, Ambassador keeps him equally focused on developing the next generation of analysts. His current work explores how Large Language Models can revolutionize cyber defence with practical applications, not hype. He recently launched The Analyst Mind on Substack (theanalystmind.io), where he writes about analytical thinking, critical frameworks, and the evolving analyst mindset.

\n\n\n\'',NULL,1295191),('3_Saturday','11','10:10','12:10','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'Hostile Input: PDF Triage That Survives an Adversarial Document\'','\'Klaus Wunder\'','Creator Workshops_1d48f5bb384c3eb1ecea8290b996a7cd','\'\'',NULL,1295192),('3_Saturday','12','10:10','12:10','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'Hostile Input: PDF Triage That Survives an Adversarial Document\'','\'Klaus Wunder\'','Creator Workshops_1d48f5bb384c3eb1ecea8290b996a7cd','\'\'',NULL,1295193),('3_Saturday','10','10:45','11:25','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Demystifying the Playboy RaaS\'','\'Gijs Rijnders\'','Creator Talks_fd5ac962f9edb4515ba8658d4d1fbf29','\'Title: Demystifying the Playboy RaaS
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:45 - 11:25 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

In recent years, ransomware has become one of the most prolific forms of cybercrime with financial gain as primary motive. The problem keeps getting bigger, with a new operation seeing the light almost every month. The Dutch National Police is often a key player in large-scale ransomware investigations. Operation Cronos is a prime example, where law enforcement took down infrastructure of the infamous LockBit group in 2024.

\n\n

Today, many ransomware groups operate RaaS (ransomware-as-a-service) models. They provide the ransomware and a platform to extort victims as a service, and affiliated hacker groups carry out the actual attacks. The platform is often run from a VPS (virtual private server), and sometimes, this server is in the Netherlands. Dutch law enforcement seizes those servers and extracts their content for investigation. This happened to the Playboy ransomware in late 2024.

\n\n

A chain of various tools is used to provide a ready-to-use ransomware package to affiliates of a RaaS program. Several modern ransomware operations even support CPU architectures and operating systems other than x86-64 and Windows. New cryptographic keys are generated for every victim, ransomware parameters are configured, and a builder creates the final package to be used by the affiliate. In this talk, we will reveal how we seized the Playboy ransomware servers, dive into its toolchain, and look at how executables were prepared to breach victims.

\n\nSpeakerBio:  Gijs Rijnders, Malware & CTI Specialist
\n

Gijs is a cyber threat intelligence analyst and malware reverse engineer at the Dutch National Police where he defends the Police organization from cyber attacks. He previously worked at the CERT of Tesorion, a Dutch cybersecurity company, where he reverse engineered various ransomware families and published decryption tools to the NoMoreRansom initiative to help victims recover from attacks.

\n\n\n\'',NULL,1295194),('3_Saturday','11','10:45','11:25','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Demystifying the Playboy RaaS\'','\'Gijs Rijnders\'','Creator Talks_fd5ac962f9edb4515ba8658d4d1fbf29','\'\'',NULL,1295195),('3_Saturday','11','11:35','12:15','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Haetae: An Agent to Takedown North Korean C2 Servers\'','\'Nelson Colon\'','Creator Talks_5a246312c9a5881fae54e25d4a037538','\'Title: Haetae: An Agent to Takedown North Korean C2 Servers
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:35 - 12:15 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

In this talk, we introduce Haetae, an agent designed to profile, identify, and exploit C2 frameworks used by North Korean malware.

\n\n

Haetae supports both automated and interactive modes, allowing analysts to map and understand adversary infrastructure with different levels of control. It is built around a flexible rule-based system, enabling users to extend and refine detections as new patterns and frameworks emerge.

\n\n

In this first release, we will walk through real-world cases where Haetae was used to identify and take down infrastructure associated with Mach-O Man and POWerful Armadillo.

\n\n

We will also release a safe emulator of both malware C2 servers, allowing researchers and newcomers to experiment with Haetae in realistic, controlled environments without risk.

\n\n

This is a highly technical talk but can be enjoyed by both beginners and seasoned threat hunters.

\n\nSpeakerBio:  Nelson Colon, Offensive Security Specialist at Bitso Quetzal Team
\n

Dominican Offensive Security Specialist. I spoke at DEF CON Data Duplication Village about creating immortal C2 servers using modern data duplication platforms.

\n\n\n\'',NULL,1295196),('3_Saturday','12','11:35','12:15','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Haetae: An Agent to Takedown North Korean C2 Servers\'','\'Nelson Colon\'','Creator Talks_5a246312c9a5881fae54e25d4a037538','\'\'',NULL,1295197),('3_Saturday','12','12:55','14:05','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'A hands-on hour with IDA: reverse-engineer a real DLL-sideloading attack from safe, purpose-built samples. No experience required — you\'ll crack your first binary in the first ten minutes.\'','\'David Rushmer\'','Creator Workshops_79e5cee1474bb88d6be971d9fd35b8dc','\'Title: A hands-on hour with IDA: reverse-engineer a real DLL-sideloading attack from safe, purpose-built samples. No experience required — you\'ll crack your first binary in the first ten minutes.
\nTags: Malware Village | Creator Workshop
\nWhen: Saturday, Aug 8, 12:55 - 14:05 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map
\n
\nDescription:
\n

DLL sideloading is one of the most common tricks in modern malware — a trusted program is quietly made to load an attacker\'s code instead of the library it expected. In this hands-on workshop you\'ll take one apart in IDA and learn to read what a binary actually does versus what it wants you to think it does.\nYou\'ll start by cracking a small serial-check program to get comfortable moving around IDA, then triage a suspicious \"updater,\" and finally dissect a sideloading library that hides a single real payload among convincing decoys — fake C2 URLs, unused \"scary\" API calls, and dead-end code planted to waste an analyst\'s time. The takeaway skill is the one that matters most in real analysis: follow what executes, not what looks dangerous.\nEvery sample is completely deweaponized — the worst any of them does is pop a message box — so you can poke at everything freely. You\'ll leave with the samples, a written walk-through, and an IDA command cheat-sheet to keep practicing. Level: Beginner-friendly; no reverse-engineering experience needed. \nBring: A laptop with IDA (IDA Free will work, you can download here)\nYou\'ll leave able to: navigate IDA, read imports/exports/strings, recognise a DLL sideload and its proxy/forwarder disguise, and see through common anti-analysis decoys

\n\nSpeakerBio:  David Rushmer, Tech Evangelist, Hex-Rays
\nNo BIO available
\n\n\'',NULL,1295198),('3_Saturday','13','12:55','14:05','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'A hands-on hour with IDA: reverse-engineer a real DLL-sideloading attack from safe, purpose-built samples. No experience required — you\'ll crack your first binary in the first ten minutes.\'','\'David Rushmer\'','Creator Workshops_79e5cee1474bb88d6be971d9fd35b8dc','\'\'',NULL,1295199),('3_Saturday','14','12:55','14:05','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'A hands-on hour with IDA: reverse-engineer a real DLL-sideloading attack from safe, purpose-built samples. No experience required — you\'ll crack your first binary in the first ten minutes.\'','\'David Rushmer\'','Creator Workshops_79e5cee1474bb88d6be971d9fd35b8dc','\'\'',NULL,1295200),('3_Saturday','13','13:05','13:45','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Ropkit: Framework for Windows Kernel Code Execution under HVCI\'','\'Nathan Sawyer\'','Creator Talks_affbcaec0b7d50d57d11bafa4e21a0b8','\'Title: Ropkit: Framework for Windows Kernel Code Execution under HVCI
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:05 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

The Windows Kernel has become a highly hardened environment. With the default enforcement of HVCI (Hypervisor enforced Code Integrity), meaningful impacts of BYOVD (Bring your own vulnerable driver) attacks becomes increasingly difficult. Furthermore, modern BYOVD attacks require the use of physical read/write primitives, which leave the much more common virtual read/write primitives difficult to weaponize.

\n\n

To assist in kernel exploitation, I developed two novel methods of kernel code execution within Windows given a virtual read/write primitive. I implemented PTE remapping that results an SSDT hijack, and a JOP chain that bypasses Kernel Shadow Stacks. These methods can only be blocked by hardware controls that are not yet implemented on AMD machines (Intel VT-rp), or are simply nonpresent in current Windows kernel (Kernel Shadow Stack Branch Tracking).

\n\n

Additionally, I will be releasing ropkit, a dynamic kernel framework built to conduct BYOVD attacks. This framework functions on different windows builds with different drivers. Known and novel code execution methods are included into this framework as well. Red Teamers simply provide a driver exploit, and this framework automates the rest of the exploitation process.

\n\nSpeakerBio:  Nathan Sawyer, Independent Researcher
\n

Nathan Sawyer is a junior studying Cybersecurity at the University of Idaho. He has obtained HTB CDSA and CPTS. He enjoys skiing, snowboarding, hockey, and lacrosse.

\n\n\n\'',NULL,1295201),('3_Saturday','13','13:50','14:30','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'How to destroy a country\'','\'Lisandro Ubiedo,Leandro Cuozzo\'','Creator Talks_db043c1b40e2ffa50a6cfcc048cca88c','\'Title: How to destroy a country
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:50 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

Some people just want to see the whole world burn. And some cyberwarfare units just want your systems to go pufff.

\n\n

Wipers are the cyber version of napalm, taking destruction from the kinetic to the cyberspace, and have been the most utilized weapons by cyberwars in the last decade. These wipers are design to destroy everything that they can get their hands on to: files, disks, backups, you name it. And they are purposefully designed this way by a dedicated group with their destabilizing a whole country in times of war.

\n\n

In this talk we are going to go through the history of wipers, since our discovery of Flame in 2012 to our latest research on a destructive wiper we named Lotus Wiper. We are going to go through the technical details as well as providing a panoramic view to the impact that these types of cyberweapons have on countries, companies and people around the globe.

\n\nSpeakers:Lisandro Ubiedo,Leandro Cuozzo
\n
\nSpeakerBio:  Lisandro Ubiedo, Senior Security Researcher at Kaspersky GReAT LATAM
\n

Lisandro is currently a security researcher, part of the GReAT team at Kaspesky. Previously, he was part of the security research team at GoSecure and collaborator at Stratosphere Labs based on Czech Republic. He’s focused on analyzing and tracking threat actors in Latin America, creating profiles and reporting on their doings.

\n\nSpeakerBio:  Leandro Cuozzo, Cybersecurity investigator at Kaspersky
\n

Investigador de Seguridad en el equipo GReAT de Kaspersky. Cuento con más de 12 años de experiencia en ciberseguridad. Ex mantenedor principal de la suite Impacket.

\n\n\n\'',NULL,1295202),('3_Saturday','14','13:50','14:30','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'How to destroy a country\'','\'Lisandro Ubiedo,Leandro Cuozzo\'','Creator Talks_db043c1b40e2ffa50a6cfcc048cca88c','\'\'',NULL,1295203),('3_Saturday','14','14:10','16:50','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'An Intro to Mac Malware Analysis\'','\'Patrick Wardle\'','Creator Workshops_8d796b3ec90e432e80027e4b940bc1c7','\'Title: An Intro to Mac Malware Analysis
\nTags: Malware Village | Creator Workshop
\nWhen: Saturday, Aug 8, 14:10 - 16:50 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Workshops - Map
\n
\nDescription:
\n

Patrick has spent the past 20 years studying macOS malware, building tools to detect it, and authoring The Art of Mac Malware book series. In this training, you\'ll learn the tools and techniques needed to detect and analyze modern threats targeting Apple\'s desktop OS.

\n\n

We\'ll cover common infection vectors, persistence mechanisms, and capabilities of macOS malware, along with an introduction to the tools and techniques used to classify and analyze malicious binaries.

\n\nSpeakerBio:  Patrick Wardle, CEO and Co-Founder at DoubleYou
\n

Patrick Wardle is the cofounder of the Objective-See Foundation, CEO and cofounder of DoubleYou, and author of The Art of Mac Malware series. He previously worked at NASA and the NSA, and has presented at countless security conferences, making him intimately familiar with aliens, spies, and talking nerdy.

\n\n\n\'',NULL,1295204),('3_Saturday','15','14:10','16:50','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'An Intro to Mac Malware Analysis\'','\'Patrick Wardle\'','Creator Workshops_8d796b3ec90e432e80027e4b940bc1c7','\'\'',NULL,1295205),('3_Saturday','16','14:10','16:50','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Workshops','\'An Intro to Mac Malware Analysis\'','\'Patrick Wardle\'','Creator Workshops_8d796b3ec90e432e80027e4b940bc1c7','\'\'',NULL,1295206),('3_Saturday','14','14:40','15:15','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications\'','\'Chris Navarrete,Sai Sathvik Ruppa\'','Creator Talks_cf907955eae6e65a036bd99c74deb71e','\'Title: The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:40 - 15:15 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

In recent years, threat actors have been migrating their command-and-control infrastructure from traditional domains and servers to decentralized platforms that are resilient to takedowns. The Polygon blockchain is one such platform, where encrypted and plaintext instructions can be embedded into immutable smart contracts, making them permanently accessible and beyond the reach of law enforcement seizure. Aeternum is a recently discovered botnet that takes full advantage of this shift. Its operators write encrypted C2 commands directly into smart contracts, and infected machines retrieve them via public Remote Procedure Call (RPC) endpoints, eliminating the need for any attacker-controlled server in the command delivery chain.

\n\n

This one-way, read-only design functions as a dead-drop resolver that cannot be taken offline through conventional means. The botnet\'s reach extends beyond a single malware family. Multiple samples across different languages and capabilities like loaders, stealers, RATs, and cryptominers have been found querying the same smart contract infrastructure using a shared function selector. Each brings its own execution techniques, from Early Bird APC injection and multi-layer encryption to Telegram-based exfiltration and sandbox evasion routines targeting analyst environments.

\n\n

By analyzing malware behaviors, network traffic, decrypting the on-chain payloads, and following the operator\'s digital footprint across multiple platforms, we were able to trace the infrastructure back to a single infrastructure. In this talk, we will walk through the full investigation from initial sample discovery to on-chain decryption and operator attribution and discuss what defenders need to know to detect blockchain-based C2 at the network level.

\n\nSpeakers:Chris Navarrete,Sai Sathvik Ruppa
\n
\nSpeakerBio:  Chris Navarrete, Senior Principal Security Researcher - CDSS Advanced Threat Prevention (ATP) at Palo Alto Networks
\n

Chris Navarrete is a Senior Principal Security Researcher within the Advanced Threat Prevention team at Palo Alto Networks. His work centers on cutting-edge research in cybersecurity, particularly in threat detection and malware analysis. Previously, he served as an adjunct professor of computer science at San Jose State University, teaching Software Security Technologies. He holds a Master of Science in software engineering with a specialization in cybersecurity from San Jose State University. Chris has presented at major industry conferences, including Black Hat Asia, the Computer Antivirus Research Organization (CARO), the Cyber Threat Alliance\'s Threat Intelligence Practitioners (TIPS) conference, and Black Hat Arsenal, where he introduced and released BLACKPHENIX — a framework designed to automate malware analysis workflows.

\n\nSpeakerBio:  Sai Sathvik Ruppa, Staff Security Researcher at Palo Alto Networks
\n

Sai Sathvik Ruppa is a Staff Security Researcher at Palo Alto Networks and a recent M.S. graduate in Information Security from Carnegie Mellon University. He specializes in vulnerability detection and malware analysis, leveraging his expertise to identify, analyze, and mitigate advanced cyber threats.

\n\n\n\'',NULL,1295207),('3_Saturday','15','14:40','15:15','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications\'','\'Chris Navarrete,Sai Sathvik Ruppa\'','Creator Talks_cf907955eae6e65a036bd99c74deb71e','\'\'',NULL,1295208),('3_Saturday','15','15:20','16:05','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Leigh Trinity OTW\'','\'Leigh Gilbert\'','Creator Talks_aa354533e52cfeddf28aa541b353ca57','\'Title: Leigh Trinity OTW
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:20 - 16:05 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

Discussion on the current state of cellphone and network hacking.

\n\nSpeakerBio:  Leigh Gilbert, Malware village
\n

Leigh Trinity is a Canadian exploit developer, red team hacker, and instructor known for her work in binary exploitation and reverse engineering. Now branching out into malware development.

\n\n\n\'',NULL,1295209),('3_Saturday','16','15:20','16:05','Y','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'Leigh Trinity OTW\'','\'Leigh Gilbert\'','Creator Talks_aa354533e52cfeddf28aa541b353ca57','\'\'',NULL,1295210),('3_Saturday','16','16:15','16:55','N','Malware Village','LVCCW Level 1 Hall 2 600 (Malware Village) Talks','\'The AI Analysis Train is Leaving the Station: ALL ABOARD!!\'','\'Ryan \"@rj_chap\" Chapman\'','Creator Talks_d6be1031066dcaccc89fd2aba08c8bd3','\'Title: The AI Analysis Train is Leaving the Station: ALL ABOARD!!
\nTags: Malware Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:15 - 16:55 PDT
\nWhere: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - Map
\n
\nDescription:
\n

t\'s 2026, and we are no longer waiting for the AI area to come of age. It\'s here! Are YOU adopting and adapting to AI-enabled workflows? If you don\'t, you\'ll simply be left behind. We can no longer sit back and say, \"AI isn\'t there yet.\" Don\'t get me wrong: It\'s not \"there,\" yet. But by the time AI is \"there,\" you\'ll be well behind the pack in terms of knowing how to use it, what to expect from it, and more. Let\'s fix that! In this talk, we\'ll show you how to use AI for malware analysis via leveraging the new MCP server that has been integrated into REMnux. We\'ll be using a free distro, with free tools, with a free (well duh) MCP server. Point being: It\'s all free, it\'s all open/available, and it\'s here now. So get on board!

\n\nSpeakerBio:  Ryan \"@rj_chap\" Chapman
\n

Ryan Chapman is the author of SANS‚ FOR528: Ransomware and Cyber Extortion‚ course, teaches SANS‚ FOR610: Reverse Engineering Malware‚ course, and works as a threat hunter @ $dayJob. Ryan has a passion for life-long learning, loves to teach people about ransomware-related attacks, and enjoys pulling apart malware. He has presented workshops at DEF CON and other conferences in the past and knows how to create a step-by-step instruction set to maximize hands-on learning.

\n\n\n\'',NULL,1295211),('2_Friday','10','10:00','17:59','N','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_3023dcae268914d669cefe3f6cc4fab8','\'Title: Hacking GRC Contest
\nTags: Hacking GRC | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: Online
\n
\nDescription:
\n

Hacking CMMC is a hands-on cybersecurity competition designed to immerse participants in the practical aspects of the Cybersecurity Maturity Model Certification (CMMC). Through realistic, challenge-based scenarios, players explore common compliance gaps, security controls, and threats faced by defense contractors.

\n\n

The CTF blends technical problem-solving with compliance-driven thinking, helping participants understand how security requirements translate into real-world incidents. It offers an engaging way to learn, test skills, and strengthen readiness for CMMC-aligned environments.

\n\n

The CTF will be a Jeopardy-style CTF where every player will have a list of challenges in different categories. For every challenge solved, the player will get a certain number of points depending on the difficulty of the challenge.

\n\n

Prerequisites

\n\n
    \n
  • Laptop with Internet Access
  • \n
\n\nLinks:
    Website - https://peaches.cloud/
\n\'',NULL,1295212),('2_Friday','11','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_3023dcae268914d669cefe3f6cc4fab8','\'\'',NULL,1295213),('2_Friday','12','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_3023dcae268914d669cefe3f6cc4fab8','\'\'',NULL,1295214),('2_Friday','13','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_3023dcae268914d669cefe3f6cc4fab8','\'\'',NULL,1295215),('2_Friday','14','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_3023dcae268914d669cefe3f6cc4fab8','\'\'',NULL,1295216),('2_Friday','15','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_3023dcae268914d669cefe3f6cc4fab8','\'\'',NULL,1295217),('2_Friday','16','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_3023dcae268914d669cefe3f6cc4fab8','\'\'',NULL,1295218),('2_Friday','17','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_3023dcae268914d669cefe3f6cc4fab8','\'\'',NULL,1295219),('4_Sunday','10','10:00','11:59','N','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_6d00119b5ef0eff8c551b22ed460e0f5','\'Title: Hacking GRC Contest
\nTags: Hacking GRC | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: Online
\n
\nDescription:
\n

Hacking CMMC is a hands-on cybersecurity competition designed to immerse participants in the practical aspects of the Cybersecurity Maturity Model Certification (CMMC). Through realistic, challenge-based scenarios, players explore common compliance gaps, security controls, and threats faced by defense contractors.

\n\n

The CTF blends technical problem-solving with compliance-driven thinking, helping participants understand how security requirements translate into real-world incidents. It offers an engaging way to learn, test skills, and strengthen readiness for CMMC-aligned environments.

\n\n

The CTF will be a Jeopardy-style CTF where every player will have a list of challenges in different categories. For every challenge solved, the player will get a certain number of points depending on the difficulty of the challenge.

\n\n

Prerequisites

\n\n
    \n
  • Laptop with Internet Access
  • \n
\n\nLinks:
    Website - https://peaches.cloud/
\n\'',NULL,1295220),('4_Sunday','11','10:00','11:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_6d00119b5ef0eff8c551b22ed460e0f5','\'\'',NULL,1295221),('3_Saturday','10','10:00','17:59','N','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_d5381591d357c3eacfb7cd03b0dcf876','\'Title: Hacking GRC Contest
\nTags: Hacking GRC | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: Online
\n
\nDescription:
\n

Hacking CMMC is a hands-on cybersecurity competition designed to immerse participants in the practical aspects of the Cybersecurity Maturity Model Certification (CMMC). Through realistic, challenge-based scenarios, players explore common compliance gaps, security controls, and threats faced by defense contractors.

\n\n

The CTF blends technical problem-solving with compliance-driven thinking, helping participants understand how security requirements translate into real-world incidents. It offers an engaging way to learn, test skills, and strengthen readiness for CMMC-aligned environments.

\n\n

The CTF will be a Jeopardy-style CTF where every player will have a list of challenges in different categories. For every challenge solved, the player will get a certain number of points depending on the difficulty of the challenge.

\n\n

Prerequisites

\n\n
    \n
  • Laptop with Internet Access
  • \n
\n\nLinks:
    Website - https://peaches.cloud/
\n\'',NULL,1295222),('3_Saturday','11','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_d5381591d357c3eacfb7cd03b0dcf876','\'\'',NULL,1295223),('3_Saturday','12','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_d5381591d357c3eacfb7cd03b0dcf876','\'\'',NULL,1295224),('3_Saturday','13','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_d5381591d357c3eacfb7cd03b0dcf876','\'\'',NULL,1295225),('3_Saturday','14','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_d5381591d357c3eacfb7cd03b0dcf876','\'\'',NULL,1295226),('3_Saturday','15','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_d5381591d357c3eacfb7cd03b0dcf876','\'\'',NULL,1295227),('3_Saturday','16','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_d5381591d357c3eacfb7cd03b0dcf876','\'\'',NULL,1295228),('3_Saturday','17','10:00','17:59','Y','Contests','Online','\'Hacking GRC Contest\'','\'\'','Contests_d5381591d357c3eacfb7cd03b0dcf876','\'\'',NULL,1295229),('1_Thursday','18','18:00','19:59','N','Social Gatherings/Events','LVCCW Level 3 W302 (Memorial Chamber)','\'Exploit Your Own Story\'','\'Charel \"1C0nur3r\" Morris\'','Social Gatherings/Events_e28b2faed9cafdd86f6ad6f679fe3903','\'Title: Exploit Your Own Story
\nTags: Meetup | Memorial Chamber
\nWhen: Thursday, Aug 6, 18:00 - 19:59 PDT
\nWhere: LVCCW Level 3 W302 (Memorial Chamber) - Map
\n
\nDescription:
\n

You\'ve spent the con finding the thread that unravels a system. Come find the one in you.

\n\n

I\'ve spent 27 years planning DEF CON\'s logistics — audio, stages, coffee, all of it. Three years ago I started writing for the first time in decades, and it turned into something I never expected: work published in magazines, a book underway, and a doorway into what I can only call a mystical experience — the kind where the page starts telling you things you didn\'t know you knew.

\n\n

Women\'s voices are at the center of this — we carry stories that go unheard far too often, and this is a room built to change that. And there are conscious men in this community whose words matter too, and who are welcome here.

\n\n

This is an open space to talk about the path — publishing, books, or just the story you\'ve never told anyone. Bring a story, bring a question, or just come listen.

\n\n

No credentials required.

\n\nSpeakerBio:  Charel \"1C0nur3r\" Morris
\nNo BIO available
\n\n\'',NULL,1295230),('1_Thursday','19','18:00','19:59','Y','Social Gatherings/Events','LVCCW Level 3 W302 (Memorial Chamber)','\'Exploit Your Own Story\'','\'Charel \"1C0nur3r\" Morris\'','Social Gatherings/Events_e28b2faed9cafdd86f6ad6f679fe3903','\'\'',NULL,1295231),('2_Friday','18','18:00','19:59','N','Social Gatherings/Events','LVCCW Level 3 W302 (Memorial Chamber)','\'Exploit Your Own Story\'','\'Charel \"1C0nur3r\" Morris\'','Social Gatherings/Events_b180105594826d46901467747f13f0d9','\'Title: Exploit Your Own Story
\nTags: Meetup | Memorial Chamber
\nWhen: Friday, Aug 7, 18:00 - 19:59 PDT
\nWhere: LVCCW Level 3 W302 (Memorial Chamber) - Map
\n
\nDescription:
\n

You\'ve spent the con finding the thread that unravels a system. Come find the one in you.

\n\n

I\'ve spent 27 years planning DEF CON\'s logistics — audio, stages, coffee, all of it. Three years ago I started writing for the first time in decades, and it turned into something I never expected: work published in magazines, a book underway, and a doorway into what I can only call a mystical experience — the kind where the page starts telling you things you didn\'t know you knew.

\n\n

Women\'s voices are at the center of this — we carry stories that go unheard far too often, and this is a room built to change that. And there are conscious men in this community whose words matter too, and who are welcome here.

\n\n

This is an open space to talk about the path — publishing, books, or just the story you\'ve never told anyone. Bring a story, bring a question, or just come listen.

\n\n

No credentials required.

\n\nSpeakerBio:  Charel \"1C0nur3r\" Morris
\nNo BIO available
\n\n\'',NULL,1295232),('2_Friday','19','18:00','19:59','Y','Social Gatherings/Events','LVCCW Level 3 W302 (Memorial Chamber)','\'Exploit Your Own Story\'','\'Charel \"1C0nur3r\" Morris\'','Social Gatherings/Events_b180105594826d46901467747f13f0d9','\'\'',NULL,1295233),('2_Friday','10','10:00','10:59','N','Contests','Online','\'Bug Bounty Village CTF - Open\'','\'\'','Contests_135bcd001ec9e8f3f867845a4e1600be','\'Title: Bug Bounty Village CTF - Open
\nTags: Bug Bounty Village | Bug Bounty Village CTF | Contest
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: Online
\n
\nDescription:
\n\n\nLinks:
    More Info - https://www.bugbountydefcon.com/ctf
\n\'',NULL,1295234),('3_Saturday','10','10:00','10:59','N','Contests','Online','\'Bug Bounty Village CTF - Open\'','\'\'','Contests_92fc71d88f47c94da2d63a651505faca','\'Title: Bug Bounty Village CTF - Open
\nTags: Bug Bounty Village | Bug Bounty Village CTF | Contest
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: Online
\n
\nDescription:
\n\n\nLinks:
    More Info - https://www.bugbountydefcon.com/ctf
\n\'',NULL,1295235),('2_Friday','10','10:00','10:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Click Me: Turning URI Links into Bug Bounty RCE\'s\'','\'Tobias Diehl\'','Creator Talks_7300478bd5b78651a772f20c3d64cfb0','\'Title: Click Me: Turning URI Links into Bug Bounty RCE\'s
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Bug bounty hunters often encounter unprotected URL inputs and dismiss them as low-impact findings. This presentation explores real-world Microsoft enterprise application vulnerabilities where custom URI handlers led to remote code execution. Attendees will learn how pivoting from web applications into desktop software can reveal impactful attack paths hidden behind seemingly mundane bugs.

\n\nSpeakerBio:  Tobias Diehl
\n

Tobias Diehl is a Senior Offensive Security Engineer, security researcher, and Microsoft 2025 Most Valuable Researcher (MVR) specializing in offensive security, enterprise AI, bug bounty research, and adversary emulation. His work focuses on identifying overlooked attack paths where web applications, AI systems, and desktop software intersect, helping organizations understand how seemingly low-risk vulnerabilities can become high-impact security issues.\nTobias leads offensive security assessments, conducts purple team exercises, and performs research into emerging attack techniques affecting enterprise environments. His work has resulted in multiple security findings impacting Microsoft technologies, including Power Platform, CoPilot and other AI-driven applications.\nA returning DEF CON speaker, Tobias is passionate about sharing practical research that helps both security researchers and defenders better understand modern attack chains. His presentations emphasize real-world case studies, responsible disclosure, and actionable defensive guidance for securing the next generation of AI-enabled enterprise systems.

\n\n\n\'',NULL,1295236),('2_Friday','10','10:30','11:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Hacking IDE Extensions - VSCode Workshop\'','\'Nick \"7urb01\" Copi\'','Creator Workshops_3b2a32b783091f2fdf079982c1e675d3','\'Title: Hacking IDE Extensions - VSCode Workshop
\nTags: Bug Bounty Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

IDE extensions are a lucrative slice of the modern bug bounty scope. They run with privileged capabilities, parse arbitrary workspace files, and increasingly ship LLM backed agentic features that execute commands, edit files, and follow instructions found in the project under review. AI assistants have become an exploit chain accelerator: agents touch every stage from file ingestion to primitive acquisition to escalation, often with minimal sandboxing. This workshop turns those ideas into hands on practice. Attendees install \"Nopilot\", a deliberately vulnerable mock AI assistant VS Code extension, learn how to debug it, review code for bugs, and chain primitives from \"user opened a folder\" to code execution that requires no further interaction and bypasses workspace trust entirely. Built around a generalized IDE exploitation killchain and drawn from a multi-six-figure IDE bug bounty practice. Bring a laptop and curiosity. Read the full description here: https://gist.github.com/nickcopi/daf5b24b262c802830ab6c1ef9d5d49d

\n\nSpeakerBio:  Nick \"7urb01\" Copi
\n

Nick Copi is a full-time bug bounty hunter targeting web applications, cloud infrastructure, desktop apps, and pretty much anything with an attack surface. His background spans application security engineering, full-stack development, and a long track record of local CTF competition wins. He has presented several technical talks at security conferences and regularly publishes and reviews security research. He really likes JavaScript. Maybe too much. Maybe someone should check on him.

\n\n\n\'',NULL,1295237),('2_Friday','11','10:30','11:30','Y','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Hacking IDE Extensions - VSCode Workshop\'','\'Nick \"7urb01\" Copi\'','Creator Workshops_3b2a32b783091f2fdf079982c1e675d3','\'\'',NULL,1295238),('2_Friday','11','11:30','12:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Hackbots\'','\'Jason \"jhaddix\" Haddix,Ryan \"BadAt_Computers\" Bonner\'','Creator Talks_5b114edf8afab92f40481d2d69d39007','\'Title: Hackbots
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Building AI-Powered Penetration Testing Bots

\n\n

In this talk, we\'ll walk through the core design philosophy behind AI hackbots and the architecture that makes them work: single-purpose vs. multi-stage bots, context engineering for targeted prompting, and tool integration with output parsing workflows.

\n\n

Then we\'ll get hands-on. We\'ll live-build a functional hackbot for a common offensive task —demonstrating asset discovery, endpoint analysis, or mutation-focused testing (e.g., XSS/SSRF) — and show how context engineering and hallucination mitigation work in practice against real targets. You\'ll see where AI genuinely accelerates reconnaissance and web analysis, and where it falls flat if you aren\'t careful. We\'ll close with lessons on cost optimization, auditability, and integrating hackbots into actual engagements.

\n\n

Who should attend: Pentesters and bug bounty hunters with offensive security experience who want to meaningfully integrate AI into their workflow — not as a novelty, but as reliable tooling.

\n\n

What you\'ll walk away with: A clear mental model for when and how to build hackbots, a live demo you can replicate, and a path into the full course where you\'ll build seven production-ready bots from asset discovery through mutation testing.

\n\nSpeakers:Jason \"jhaddix\" Haddix,Ryan \"BadAt_Computers\" Bonner
\n
\nSpeakerBio:  Jason \"jhaddix\" Haddix, CEO and \"Hacker in Charge\" at Arcanum Information Security
\n

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

\n\n

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

\n\nSpeakerBio:  Ryan \"BadAt_Computers\" Bonner, Lead Security Engineer, Arcanum Information Security
\n

Ryan is a Lead Security Engineer at Arcanum Information Security. A part-time bug hunter, Ryan has built his career on the offensive side of security, focusing on where AI systems and integrations meet the modern web. He specializes in attacking AI-powered applications, including prompt injection, agent, and integration weaknesses that appear as large language models get wired into real products.

\n\n\n\'',NULL,1295239),('2_Friday','12','11:30','12:30','Y','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Hackbots\'','\'Jason \"jhaddix\" Haddix,Ryan \"BadAt_Computers\" Bonner\'','Creator Talks_5b114edf8afab92f40481d2d69d39007','\'\'',NULL,1295240),('2_Friday','12','12:30','13:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'AI Hacking Workshop: Bug Bounty Edition\'','\'Ben \"NahamSec\" Sadeghipour,Kameron \"clovismint\" Bettridge\'','Creator Workshops_7088c3116d5855010cade555e5ecbdea','\'Title: AI Hacking Workshop: Bug Bounty Edition
\nTags: Bug Bounty Village | Creator Workshop
\nWhen: Friday, Aug 7, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

This workshop provide hands-on labs plus for turning a prompt injection into a real, reportable bounty, specifically the exfiltration step that bridges \"I made the AI say something weird\" and \"I exfilled PIIsystem prompts to my server .\" We cover injection vectors hackers actually encounter on agentic apps (calendar invites, emails, markdown rendering, DNS-based egress) and the patterns that get programs to pay.

\n\nSpeakers:Ben \"NahamSec\" Sadeghipour,Kameron \"clovismint\" Bettridge
\n
\nSpeakerBio:  Ben \"NahamSec\" Sadeghipour
\n

Ben Sadeghipour (NahamSec) is a security researcher, ethical hacker, and educator who has spent more than a decade finding and disclosing critical vulnerabilities in some of the world\'s largest organizations. As one of the most recognized names in the bug bounty community, he has reported thousands of security flaws and consistently ranked among the top researchers on leading hacking platforms.\nBeyond his own research, Ben is passionate about lowering the barrier to entry in cybersecurity. Through his widely followed educational content, live streams, and the conferences he founds and organizes, he has helped train a new generation of hackers around the world. His work blends deep technical expertise with a commitment to mentorship and community building.Ben speaks regularly at industry conferences on offensive security, bug bounty hunting, and building a career in cybersecurity.

\n\nSpeakerBio:  Kameron \"clovismint\" Bettridge
\n

Kameron Bettridge (Clovis Mint) is an application security engineer at Blizzard Entertainment, where he works to secure systems behind some of the world\'s most popular games. Alongside his day-to-day role, he takes on contract work for Gray Swan as an AI red teamer and arena engineer, where he has contributed to testing the limits of modern AI systems. Kameron is a fierce competitor on the CTF circuit, playing with The Hackers Crew; ranked 3rd globally on CTFtime in 2024, as well as Squid Proxy Lovers and the US Cyber Team, with whom he will represent the United States in Tokyo. He has competed at the highest levels of the sport, reaching the finals of DEF CON, Google CTF (Hackceler8), and more

\n\n\n\'',NULL,1295241),('2_Friday','13','12:30','13:30','Y','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'AI Hacking Workshop: Bug Bounty Edition\'','\'Ben \"NahamSec\" Sadeghipour,Kameron \"clovismint\" Bettridge\'','Creator Workshops_7088c3116d5855010cade555e5ecbdea','\'\'',NULL,1295242),('2_Friday','14','14:00','14:59','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Navigating AI-Assisted Submissions\'','\'Tony Lee,Michael Skelton,Alexander \"appSecExplained\" Wren,Selim Jaafar,Shlomie \"shlibness\" Liberow\'','Creator Talks_291d7f063751e3f792189e26b11f63c1','\'Title: Navigating AI-Assisted Submissions
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Recent advances in AI have dramatically reshaped the landscape of offensive security and bug bounty hunting, and nowhere is that shift more visible than in the report submissions themselves. AI-assisted reports are forcing the industry to confront familiar questions of scale, scope, and structure in new ways: from triage bottlenecks to signal-to-noise ratio to how \"quality\" is defined when a hunter\'s tooling has changed.\nThis panel examines that shifting ground from the perspective of the bug bounty platforms themselves. Drawing on the experience of platform leaders navigating this transition firsthand, attendees will gain insight into the challenges AI-assisted submissions are creating, the solutions platforms are implementing in response, and practical guidance on how hunters can adapt their workflows to succeed in 2026 and beyond.

\n\nSpeakers:Tony Lee,Michael Skelton,Alexander \"appSecExplained\" Wren,Selim Jaafar,Shlomie \"shlibness\" Liberow
\n
\nSpeakerBio:  Tony Lee, Vice President of Operations, HackerOne
\n

Tony Lee is VP of Operations at HackerOne, leading the Triage, Support, and Mediation teams. With over 20 years in security, red teaming, incident response, and operations, he is a data-driven, trusted advisor to many global organizations and boards. His prior experience includes leading production testing, AI transformation, and bug bounty at AWS. As an avid educator, he has taught thousands of students at venues worldwide, including government, universities, corporations, and conferences.

\n\nSpeakerBio:  Michael Skelton, SVP - Service & Delivery at Bugcrowd
\n

Previously a top 10 bounty hunter at Bugcrowd, now the SVP of Service & Delivery overseeing triage, appeals, escalations, and the support team, also creating YouTube content at youtube.com/codingo and developing tools at github.com/codingo.

\n\nSpeakerBio:  Alexander \"appSecExplained\" Wren, Head of Hackers at Intigriti
\n

Alex is Head of Hackers at Intigriti and has spent over 10 years breaking web applications, teaching offensive security, and working with security practitioners around the world. He leads Intigriti\'s global hacker community, builds CTFs, organises live hacking events, and spends an unhealthy amount of time hunting interesting web vulnerabilities. When he\'s not working with researchers, you\'ll probably find him building deliberately vulnerable applications or running a D&D campaign.

\n\nSpeakerBio:  Selim Jaafar, Chief Customer Officer at YesWeHack
\n

Selim Jaafar is Chief Customer Officer at YesWeHack, a global bug bounty and offensive security platform. He started in infosec governance in the banking sector before joining YesWeHack in 2019, where he has worked with hundreds of organizations to build and run vulnerability testing programs, including high-stakes engagements like electronic voting systems. He now leads Customer Success and Triage operations, with direct visibility into what researchers submit, how findings are validated, and where things break. His position at the crossroads of technical operations and client-facing strategy gives him a front-row seat on evolving attack techniques, emerging threats, and how AI is reshaping vulnerability discovery at scale.

\n\nSpeakerBio:  Shlomie \"shlibness\" Liberow
\n

Shlomie is the founder and CEO of aisy. He spent many years on offensive side at HackerOne, where he ran live hacking events making the final call on more than $20M in verified findings. That work put him on both sides of the bounty table: the hunters chasing the critical, and the teams deciding what to do with it once it lands. At aisy he is building a context layer for enterprise risk, taking the findings companies already have from scanners, pentests, and bounty programs, connecting them to the threats the business actually cares about, and pushing root-cause fixes through the coding agents engineers already use.

\n\n\n\'',NULL,1295243),('2_Friday','15','15:00','15:59','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'a [REDACTED] history of this hobby\'','\'Chris \"flyingtoasters\" Holt,Michael Skelton\'','Creator Talks_3883911ae9d7fddb218fb78f68940f68','\'Title: a [REDACTED] history of this hobby
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\nBug bounty has had a weird public story: in the open it looks like a leaderboard and a payout chart, but most of the meaningful change happened behind closed doors in private programs, internal playbooks, and the slow professionalization of triage. We give a clean mental model for what changed, what stayed the same, and which myths keep wasting everyone’s time. With some stories that people may have never heard.
\n\n\n\nSpeakers:Chris \"flyingtoasters\" Holt,Michael Skelton
\n
\nSpeakerBio:  Chris \"flyingtoasters\" Holt, Strategic Engagements & Community Architect, Intigriti
\n

Chris Holt, aka flyingtoasters, is a seasoned bug bounty program leader with over 15 years of experience in application and product security. Certified by GAIC, NTISSI, Guinness, PADI, and the USSF, he has spent the last 8 years building and scaling some of the industry\'s most respected bug bounty programs. His expertise spans the full spectrum of vulnerability management: from offensive security and researcher engagement to program operations and strategic growth.

\n\nSpeakerBio:  Michael Skelton, SVP - Service & Delivery at Bugcrowd
\n

Previously a top 10 bounty hunter at Bugcrowd, now the SVP of Service & Delivery overseeing triage, appeals, escalations, and the support team, also creating YouTube content at youtube.com/codingo and developing tools at github.com/codingo.

\n\n\n\'',NULL,1295244),('2_Friday','16','16:00','16:59','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Hacking Human-in-the-Loop systems\'','\'Inti \"securinti\" De Ceukelaire\'','Creator Talks_3a4c440ce59bacf800b8aa923e796c0e','\'Title: Hacking Human-in-the-Loop systems
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\nCustomer support has always been a numbers game: high message volume, repetitive questions, and constant pressure to respond faster. Most organisations handle this through ticket portals, shared mailboxes or live chat tools. These systems were built around people reading messages and people taking action. That model is disappearing. To keep up with demand, support platforms now embed AI agents that read incoming messages, suggest replies, search internal knowledge pages and even interact with backend systems. They reset accounts, schedule refunds, modify settings and verify users before a human ever looks at the conversation. The human is still in the loop, but rarely in full control. Connecting a language model to business logic has a side effect. It turns text into a control layer. Messages no longer just inform a conversation; they influence actions. If an attacker can shape those messages, they can shape what the agent does. In security terms, that creates a new attack surface that did not exist when humans handled every request. This session examines how that surface is exploited in practice. The findings come from real vulnerability reports against production AI support systems that accept contact from the public. The attacks require no insider access. They target the assumptions that connect users, agents and operators, and they convert helpful automation into unintended system access. The examples that follow show how the trust built into these systems can be bent until it breaks.
\n\n\n\nSpeakerBio:  Inti \"securinti\" De Ceukelaire, Founding Member, Intigriti
\n

Intigriti is a Founding Member at Intigriti and their former Chief Hacker Officer. As a hacker, Inti has won multiple awards in live hacking competitions from Bugcrowd and HackerOne. Inti specialises in AI-hacking techniques, logic flaws and support systems, and is most known for the \"Ticket Trick\" methodology that has earned a spot in Portswigger Top Web Hacking Techniques.

\n\n\n\'',NULL,1295245),('2_Friday','17','17:00','17:59','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Beyond Normalization: The Expanding Unicode Attack Surface\'','\'Ryan \"ryancbarnett\" Barnett,Isabella \"4ng3lhacker\" Barnett\'','Creator Talks_c52738b8dba110f1ec5d0eefee6b7b3e','\'Title: Beyond Normalization: The Expanding Unicode Attack Surface
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Unicode exploitation does not end with normalization. Modern web applications process input through layered pipelines: URL decoding, UTF-8 validation, WAF transformations, framework parsing, surrogate handling, database collation, HTML entity decoding, and increasingly, LLM preprocessing. Each layer implements subtly different assumptions about character validity and equivalence. When those assumptions diverge, security boundaries fail. Building off our popular Black Hat USA 2025 Unicode Briefing, we have continued our research into the complex world of Unicode processing. This research exposes a new class of Unicode pipeline vulnerabilities that extend far beyond canonical normalization issues. We demonstrate how attackers can weaponize illegal UTF-8 sequences to break RE2 validation, exploit surrogate-to-replacement conversions (U+FFFD) to alter semantics, abuse hex overflows to generate filtered characters, and bypass Host/Secure cookie protections via Unicode whitespace desynchronization. We show how MySQL zero-weight collation rules enable filter bypasses even after normalization, how WAF/browser canonicalization mismatches lead to XSS and RCE (including analysis of CVE-2025-55182), and how invisible Unicode variation selectors can jailbreak LLMs or conceal supply chain malware. Using real-world telemetry, live demonstrations, tooling updates and hands-on lab environments, this Briefing reframes Unicode as a distributed parsing vulnerability class, not a character encoding footnote. Unicode is no longer just a normalization problem. It is an architectural attack surface.

\n\nSpeakers:Ryan \"ryancbarnett\" Barnett,Isabella \"4ng3lhacker\" Barnett
\n
\nSpeakerBio:  Ryan \"ryancbarnett\" Barnett, Senior Threat Research Manager, Akamai
\n

Ryan Barnett is a Senior Threat Research Manager leading the Akamai App and API Protector (WAF) product. He also acts as s triager on Akamai\'s and customers\' bug bounty programs. In addition to his primary work at Akamai, he is also a former Faculty Member for the SANS Institute, a WASC Board Member and OWASP Project Leader for: ModSecurity Core Rule Set (CRS) Web Hacking Incident Database (WHID). Mr. Barnett has also authored two web security books: Preventing Web Attacks with Apache (Pearson) and The Web Application Defender\'s Cookbook: Battling Hackers and Defending Users (Wiley).

\n\nSpeakerBio:  Isabella \"4ng3lhacker\" Barnett
\n

Isabella Barnett is a Software Engineering Intern at Akamai and a junior at George Mason Honor\'s College studying Cyber Security Engineering.

\n\n\n\'',NULL,1295246),('3_Saturday','10','10:00','10:45','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Turning Recon Coverage into Bug Bounty Signal\'','\'Radu Stefan Voloaga\'','Creator Talks_e9216fa89d3aac206bd32afda41c7b37','\'Title: Turning Recon Coverage into Bug Bounty Signal
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Bug bounty programs increasingly face a paradox. While organisations have more tooling than ever to enumerate their internet-facing services, yet both hackers and program owners still miss real, reportable vulnerabilities, especially in volatile, sprawling environments. As the time to discover and exploit vulnerabilities collapses, effective asset discovery has become more urgent. This talk shares outcomes from the CrowdRecon initiative: a recon-first approach designed to demonstrate the true value of hacker reconnaissance, over and above what scanners and attack surface management solutions typically deliver. We’ll show how recon, when treated as a disciplined, repeatable workflow (not “spray-and-pray” enumeration), produces measurable advantages across the vulnerability lifecycle: - Pre-vulnerability discovery: uncovering unknown, shifting, or mis-modeled assets (and the fragile trust assumptions around them). - At-vulnerability discovery: increasing the odds of finding real exploitable paths by mapping relationships, auth boundaries, and “hidden surfaces” that scanners miss. - Post-vulnerability context: accelerating impact validation and exploitability assessment with recon artifacts that explain why this system matters and how it is reachable. Outputs: - Examples of coverage gained (new endpoints, subdomains, environments, and trust paths) that were not represented in conventional inventories. - Patterns of high-signal recon artifacts that correlate with meaningful bounty submissions. - Common failure modes of scanner-only and AI-only approaches, and how recon closes the gap. The goal is to give bug bounty practitioners, hackers, program managers, and triage teams, an actionable mental model and set of techniques for building a “flywheel” that improves discovery without compromising ethics. An open Q&A session at the end aims to drive discussion on opening recon information to all hunters. Democratised recon.

\n\nSpeakerBio:  Radu Stefan Voloaga, Senior Product Manager, Intigriti
\n

Radu Voloaga is a Senior Product Manager at Intigriti, working at the intersection of customers, security researchers, and crowdsourced security programs. He collaborates closely with organizations and the hacker community to understand what drives high-signal discoveries, and how reconnaissance, asset discovery, and hacker behavior translate into actionable security intelligence. Radu leads the development of Crowd Recon, an initiative focused on making the activity that happens between vulnerability reports measurable and actionable. By transforming researcher-driven reconnaissance into structured signals, Crowd Recon helps surface attack surface blind spots that traditional approaches often miss while complementing scanners, AI, and attack surface management tooling. He also spends an unreasonable amount of time wondering who created a particular internet-facing asset, why it still exists, and whether anyone remembers owning it.

\n\n\n\'',NULL,1295247),('3_Saturday','10','10:45','11:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'You’re Invited to Get Hacked: Real-World Exploits in Modern Invitation Systems\'','\'Ali \"logic-breaker\" Kabeel\'','Creator Talks_a548be938299cb583f2192bcc6f57f7e','\'Title: You’re Invited to Get Hacked: Real-World Exploits in Modern Invitation Systems
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:45 - 11:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Invitation flows are designed to maximize growth, not withstand attackers, and that makes them a goldmine for security researchers. Hidden behind trusted onboarding journeys are assumptions about identity, unchecked state transitions, and high-impact vulnerabilities that automated scanners routinely miss. In this talk, I\'ll walk through three real-world disclosures that led to account takeover, stealthy privacy manipulation, and permanent account lockout. You\'ll leave with a practical methodology for uncovering these overlooked flaws and a fresh hunting ground that many researchers still ignore. If you\'ve been skipping invitation flows, you\'ve been leaving money on the table.

\n\nSpeakerBio:  Ali \"logic-breaker\" Kabeel
\n

With over a decade of bug hunting experience, Ali has uncovered critical vulnerabilities across top tech platforms including Google, Microsoft, Meta, and Snapchat. He\'s especially passionate about business logic vulnerabilities, flaws rooted in real-world misuse rather than broken code, because they often evade automated scanners yet carry high impact. Ali is currently a Security and Privacy Engineering Lead at Bending Spoons, where he leads security efforts across major products including WeTransfer, Brightcove, and Vimeo. He actively shares his expertise through conference talks, mentoring, and community engagement.

\n\n\n\'',NULL,1295248),('3_Saturday','11','10:45','11:30','Y','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'You’re Invited to Get Hacked: Real-World Exploits in Modern Invitation Systems\'','\'Ali \"logic-breaker\" Kabeel\'','Creator Talks_a548be938299cb583f2192bcc6f57f7e','\'\'',NULL,1295249),('3_Saturday','11','11:30','12:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'De-Sloppify: Your AI Needs a Proxy\'','\'Emile \"TheSytten\" Fugulin,Vitor \"busf4ctor\" Falcao Habibe Costa\'','Creator Workshops_acb4d4d622be639577f9c5c1994227fb','\'Title: De-Sloppify: Your AI Needs a Proxy
\nTags: Bug Bounty Village | Creator Workshop
\nWhen: Saturday, Aug 8, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

In the workshop we will explore how to setup yourself for success with AI agents by using a tight integration with your proxy of choice. We will start with why you would want to use a proxy with AI agents (Scoping, Guardrails, Human-in-the-loop, Tool provider) and then showcase multiple ways to achieve the integration (MCP, Skills, Plugins). It will use Caido for the workshop but the concepts will be applicable to all proxies.

\n\nSpeakers:Emile \"TheSytten\" Fugulin,Vitor \"busf4ctor\" Falcao Habibe Costa
\n
\nSpeakerBio:  Emile \"TheSytten\" Fugulin, Caido Labs
\n

Emile was a freelance devops & backend developer for many years prior to starting Caido.\nHe always had a passion for security and working on Caido is the perfect combinaison of both!

\n\nSpeakerBio:  Vitor \"busf4ctor\" Falcao Habibe Costa, Frontier AI Red Team Operator, BT6
\n

Vitor is an AI security researcher, Community Manager at Critical Thinking, and a Google VRP hunter, named Best AI Researcher at Google bugSWAT. He\'s part of the BT6 team and hunts bugs full time.

\n\n\n\'',NULL,1295250),('3_Saturday','12','11:30','12:30','Y','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'De-Sloppify: Your AI Needs a Proxy\'','\'Emile \"TheSytten\" Fugulin,Vitor \"busf4ctor\" Falcao Habibe Costa\'','Creator Workshops_acb4d4d622be639577f9c5c1994227fb','\'\'',NULL,1295251),('3_Saturday','12','12:30','13:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Better Bug Hunting on AI Products: A VRP Lead’s Perspective\'','\'John Kotheimer\'','Creator Talks_f43dea8cf4698bf1b4d89f3bb767e243','\'Title: Better Bug Hunting on AI Products: A VRP Lead’s Perspective
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

At Google, we receive hundreds of reports per week (not exaggerating) that claim to identify vulnerabilities in our AI products. However, only a tiny fraction of those (<1%!) will receive a reward. But there is hope! When we break down the reasons so many reports are rejected, nearly all of them fall into a few common categories that make them invalid. Join the Technical Lead of Google’s AI Vulnerability Reward Program to walk through these common pitfalls, learn how to bug hunt more effectively on AI products, and hopefully, take home more bounties for your efforts. Outline I. Introduction Self intro, discuss the interest in AI VRP, introduce the problem of low success rates for researchers II. Overview of Google AI VRP - Brief program history, overview of triage/reward process - Explain VRP scope/rewards: In-Scope: Security vulnerabilities (Rogue Actions / Sensitive Data Exfiltration); Some AI Abuse categories Out-of-Scope: \"AI slop,\" simple alignment bypasses, or jailbreaks that do not result in a direct security impact on user data. III. Common Mistakes - Jailbreaks/Safety: Getting an LLM to generate \"bad\" content is not a security vulnerability we reward through the program (please report in-product!). - Self-pwns: Reports are over-reliant on social engineering or have unconvincing attack scenarios - Ignoring Context: Misunderstanding \"sensitive data\" versus expected model behavior. IV. Better Bug Hunting - Direct and Indirect Prompt Injection: Reviewing (un)successful AI VRP reports - Our programs look for indirect prompt injection attacks; this isn’t always easy to understand - Note: This section will include details from a recently rewarded and disclosed AI VRP report [details TBC pending researcher/corporate comms approval] - Clear and Actionable Reporting: - We want to help teams fix bugs quickly; you can help us do that by writing clear and actionable reports - Reproduction can be challenging due to non-determinism V. Conclusion / Q&A

\n\nSpeakerBio:  John Kotheimer, Senior Security Engineer, Google
\n

John is a Senior Information Security Engineer and Technical Lead of the AI Vulnerability Reward Program (AI VRP) at Google in New York City. John has significant experience operating bug bounty programs–including a previous role as TL of the Abuse Vulnerability Reward Program at Google–as well as a background in infrastructure security, red teaming, and incident response. As AI VRP lead, John oversees the triage of hundreds of AI bug reports submitted to the program every week. John also coordinates the panel that determines rewards for accepted AI bugs at Google and helps plan and run many of Google’s bugSWAT live hacking events. Before joining Google in 2019, John was an information security consultant at Mandiant and completed graduate study at Carnegie Mellon University. Outside of work, he enjoys travel, craft beer, and riichi mahjong.

\n\n\n\'',NULL,1295252),('3_Saturday','13','12:30','13:30','Y','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Better Bug Hunting on AI Products: A VRP Lead’s Perspective\'','\'John Kotheimer\'','Creator Talks_f43dea8cf4698bf1b4d89f3bb767e243','\'\'',NULL,1295253),('3_Saturday','14','14:00','14:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Exfil Everything: A Year of Stealing Data from AI Agents\'','\'Ads Dawson,Mike \"TakSec\" Takahashi\'','Creator Talks_1e79c068d77d518a2d7206238885351a','\'Title: Exfil Everything: A Year of Stealing Data from AI Agents
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

For two decades, XSS was the king of data theft — exploiting trust boundaries in a victim\'s browser to exfiltrate sensitive data and perform malicious actions. AI-powered interfaces have introduced new ways to deliver XSS to victims alongside an entirely new bug class that has emerged as the most impactful vulnerability pattern in modern AI applications. The parallels between XSS and AI data exfiltration are striking — both exploit trust boundaries to force a system into performing unintended actions on behalf of a victim but the attack surface in AI is broader, spanning web interfaces, mobile apps, wearables, and any client consuming agent output. The exfiltration channels are diverse: markdown image rendering, iframe and HTML tag injection, sandbox escapes, native platform connectors, network connectivity tools, javascript: URI schemes, link unfurling side channels, MCP server poisoning, and multi-step agent tool-abuse chains. In this talk, two bug hunters who\'ve spent the past year exploiting these vulnerabilities across production applications break it down and walk through real attack chains, demonstrate how we bypass common mitigations and share the bypass techniques we\'ve developed. We\'ll cover how to threat model AI applications, identify viable attack paths, and select delivery mechanisms to weaponize end-to-end exploits. Beyond offense, we\'ll discuss the mitigations we\'ve encountered, what actually works, what doesn\'t, and emerging trends in agentic AI and autonomous tool use mean for the next wave of vulnerabilities hunters should be watching for. Leave with: (1) a clear mental model of AI data exfiltration as a bug class and how it relates to familiar web primitives, (2) concrete attack techniques and bypass methods, (3) practical threat modeling for identifying exfil paths in AI agents and applications, and (4) visibility into upcoming trends and bug classes they should be hunting as AI systems gain more autonomy and connectivity.

\n\nSpeakers:Ads Dawson,Mike \"TakSec\" Takahashi
\n
\nSpeakerBio:  Ads Dawson, Staff AI Security Researcher, OWASP GenAI Security Project founder
\n

Ads Dawson founded the OWASP GenAI Security Project and led it to flagship status — the fastest in OWASP history. As a Staff AI Security Researcher at Dreadnode, he specializes in exploiting ML and AI systems, harnessing AI for offensive cybersecurity through capability development and exploit development, and conducting red team operations against frontier models for government, military, and tier-1 labs. He is lead author of AIRTBench (arXiv), the first benchmark for autonomous AI red teaming in LLMs, and author of AI Native LLM Security (Packt, 2025).

\n\n

A senior red team operator with BT6 (the frontier AI red team), ranked #2 in Canada on HackerOne (2025/2026), and selected for Meta\'s MBBRC live hacking event, Ads is a HackerOne US South Ambassador, BugCrowd Hacker Advisory Board member, MITRE AI Working Group contributor, and leads the OWASP Toronto chapter. He spoke at Bug Bounty Village DC33 on the BT6 AI jailbreaking panel and is also presenting \"Exfil Everything: A Year of Stealing Data from AI Agents\" at Bug Bounty Village DC34 (schedule pending publication).

\n\nSpeakerBio:  Mike \"TakSec\" Takahashi, AI Red Team Researcher, Zenity
\n

Mike Takahashi, aka TakSec, is an AI Red Team Researcher at Zenity; member of BT6; and Bug Bounty Hunter focused on breaking AI systems. He has submitted 400+ vulnerabilities across major bug bounty programs and top ranking on both Anthropic’s Safety Bug Bounty Program on HackerOne and Mozilla’s 0din GenAI Bug Bounty Program. His work targets prompt injection, data exfiltration, and AI agent security.

\n\n\n\'',NULL,1295254),('3_Saturday','14','14:30','15:59','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Bots, Bounties, and Bullshit: An Honest Panel on AI in Hacking\'','\'Ben \"NahamSec\" Sadeghipour,Vitor \"busf4ctor\" Falcao Habibe Costa,Joey Melo,Dustin \"ph1r3574r73r\" Farley,Ads Dawson,Johann \"wunderwuzzi23\" Rehberger\'','Creator Talks_4035428cb2096b69ef49a0cb2c724c6a','\'Title: Bots, Bounties, and Bullshit: An Honest Panel on AI in Hacking
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 15:59 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

AI has landed on both sides of the bug bounty table at once. Hackers are being told to use it, programs are drowning in the slop it produces, and a whole new attack surface, agents, RAG pipelines, and tool-calling LLMs, just showed up in scope.

\n\n

This panel brings together working hackers who run AI in their daily flow, LLM security researchers who break AI for a living, and a moderator who has spent a decade in the scene. In 45 minutes they cut through the hype and get specific: which parts of recon, review, and reporting AI actually handles, how to hack the LLM-backed apps now in scope and get paid for it, and why the real edge isn\'t ChatGPT but the private agents and skills hackers are quietly building to turn one good idea into a hundred bugs.

\n\nSpeakers:Ben \"NahamSec\" Sadeghipour,Vitor \"busf4ctor\" Falcao Habibe Costa,Joey Melo,Dustin \"ph1r3574r73r\" Farley,Ads Dawson,Johann \"wunderwuzzi23\" Rehberger
\n
\nSpeakerBio:  Ben \"NahamSec\" Sadeghipour
\n

Ben Sadeghipour (NahamSec) is a security researcher, ethical hacker, and educator who has spent more than a decade finding and disclosing critical vulnerabilities in some of the world\'s largest organizations. As one of the most recognized names in the bug bounty community, he has reported thousands of security flaws and consistently ranked among the top researchers on leading hacking platforms.\nBeyond his own research, Ben is passionate about lowering the barrier to entry in cybersecurity. Through his widely followed educational content, live streams, and the conferences he founds and organizes, he has helped train a new generation of hackers around the world. His work blends deep technical expertise with a commitment to mentorship and community building.Ben speaks regularly at industry conferences on offensive security, bug bounty hunting, and building a career in cybersecurity.

\n\nSpeakerBio:  Vitor \"busf4ctor\" Falcao Habibe Costa, Frontier AI Red Team Operator, BT6
\n

Vitor is an AI security researcher, Community Manager at Critical Thinking, and a Google VRP hunter, named Best AI Researcher at Google bugSWAT. He\'s part of the BT6 team and hunts bugs full time.

\n\nSpeakerBio:  Joey Melo
\n

Joey is a Principal Security Researcher at CrowdStrike and a contributor to AI safety programs at OpenAI and Anthropic. He specializes in offensive security research and adversarial analysis of complex systems, with a particular focus on AI/ML infrastructure and large language models. His work has led to the discovery of critical vulnerabilities and novel exploitation techniques, helping organizations better understand and defend against sophisticated threat actors. He has experience across red teaming, exploit development, and designing resilient architectures for high-risk environments. Joey has earned recognition through bug bounty programs and multiple security competitions, with over $100,000 awarded for vulnerability research. He is also an OSCP, OSCE³ and CRTO-certified professional.

\n\nSpeakerBio:  Dustin \"ph1r3574r73r\" Farley, BT6
\n

Dustin Farley has spent more than a decade building software, securing it, and figuring out how to break it. Today, he focuses on AI security, where he spends his time red teaming large language models, AI agents, and other emerging AI systems. His interests include prompt injection, jailbreaks, adversarial testing, and turning weird edge cases into useful security research. He firmly believes that the fastest way to understand a system is to see how it fails.

\n\nSpeakerBio:  Ads Dawson, Staff AI Security Researcher, OWASP GenAI Security Project founder
\n

Ads Dawson founded the OWASP GenAI Security Project and led it to flagship status — the fastest in OWASP history. As a Staff AI Security Researcher at Dreadnode, he specializes in exploiting ML and AI systems, harnessing AI for offensive cybersecurity through capability development and exploit development, and conducting red team operations against frontier models for government, military, and tier-1 labs. He is lead author of AIRTBench (arXiv), the first benchmark for autonomous AI red teaming in LLMs, and author of AI Native LLM Security (Packt, 2025).

\n\n

A senior red team operator with BT6 (the frontier AI red team), ranked #2 in Canada on HackerOne (2025/2026), and selected for Meta\'s MBBRC live hacking event, Ads is a HackerOne US South Ambassador, BugCrowd Hacker Advisory Board member, MITRE AI Working Group contributor, and leads the OWASP Toronto chapter. He spoke at Bug Bounty Village DC33 on the BT6 AI jailbreaking panel and is also presenting \"Exfil Everything: A Year of Stealing Data from AI Agents\" at Bug Bounty Village DC34 (schedule pending publication).

\n\nSpeakerBio:  Johann \"wunderwuzzi23\" Rehberger
\n

Johann Rehberger has over 20 years of experience in threat modeling, risk management, penetration testing, and red teaming. During his tenure at Microsoft, Johann established a Red Team within Azure Data and led the program as Principal Security Engineering Manager. He went on to build a Red Team at Uber, served as Red Team Director at Electronic Arts, and currently works as an independent security researcher.

\n\n

He is a former instructor in ethical hacking at the University of Washington, contributed to the MITRE ATT&CK and ATLAS frameworks, and authored \"Cybersecurity Attacks – Red Team Strategies\". He holds a Master\'s degree in computer security from the University of Liverpool.

\n\n

You can find his latest research at embracethered.com.

\n\n\n\'',NULL,1295255),('3_Saturday','15','14:30','15:59','Y','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Bots, Bounties, and Bullshit: An Honest Panel on AI in Hacking\'','\'Ben \"NahamSec\" Sadeghipour,Vitor \"busf4ctor\" Falcao Habibe Costa,Joey Melo,Dustin \"ph1r3574r73r\" Farley,Ads Dawson,Johann \"wunderwuzzi23\" Rehberger\'','Creator Talks_4035428cb2096b69ef49a0cb2c724c6a','\'\'',NULL,1295256),('3_Saturday','16','16:00','17:59','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Burp, But Yours: Hands-On Extension and Bambda Development\'','\'Hannah L\'','Creator Workshops_b02dc9d715e45f7ea5f05eaf89a2a734','\'Title: Burp, But Yours: Hands-On Extension and Bambda Development
\nTags: Bug Bounty Village | Creator Workshop
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Ever found yourself scrolling through thousands of requests looking for the few that matter? Repeating the same checks across every target? Wishing Burp Suite would automate part of your workflow?

\n\n

This hands-on workshop teaches bug bounty hunters how to build Burp customizations that surface valuable signals and eliminate repetitive work.

\n\nSpeakerBio:  Hannah L, Burp Suite Extensibility Specialist at PortSwigger
\n

Hannah is an Extensibility Specialist at PortSwigger, where she helps shape how Burp Suite can be adapted to real-world testing workflows. She works hands-on with submissions to the BApp Store, as well as the Bambdas and BChecks community repositories, helping refine extensions and community contributions before they’re shared more widely.

\n\n

She especially enjoys making extensions better and finding creative workarounds to awkward testing problems. She has also written extensions for customers, internal teams, and her own projects, including the original WebSocket Turbo Intruder extension.

\n\n\n\'',NULL,1295257),('3_Saturday','17','16:00','17:59','Y','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Burp, But Yours: Hands-On Extension and Bambda Development\'','\'Hannah L\'','Creator Workshops_b02dc9d715e45f7ea5f05eaf89a2a734','\'\'',NULL,1295258),('4_Sunday','10','10:00','10:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'AI Cuts Both Ways: Using AI to Find More Bugs, and Finding the New Bugs AI Creates\'','\'Ciarán \"monke\" Cotter\'','Creator Talks_254f083aa868e4817102215ddb2b08e5','\'Title: AI Cuts Both Ways: Using AI to Find More Bugs, and Finding the New Bugs AI Creates
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\nAI is reshaping bug bounty from both sides: how hunters use it to find more bugs, and the brand-new bug classes it creates in production. Built on Hazem Elsayed\'s (@hacktus) research and presented by Ciarán Cotter (@monke), who delivers the talk on stage and brings additional cases from his own AI security work.
\n\n\n\nSpeakerBio:  Ciarán \"monke\" Cotter
\n

Ciarán, also known as \"monke\", is a full-time bug bounty hunter and founder of Starstrike, an AI security startup. He is a Google AI Bugswat MVH and has won 2nd Place twice. Ciarán is also an active member of the BT6 AI hacking collective organised by Pliny the Liberator.

\n\n\n\'',NULL,1295259),('4_Sunday','11','11:00','11:30','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Full Disclosure, Full Screen: [Informative] The Story of Bug Bounty Village Badge 2026\'','\'Abhinav \"TweetsFromPanda\" Pandagale\'','Creator Talks_b92500d2d982fccbdc7aa2d73d9c2e22','\'Title: Full Disclosure, Full Screen: [Informative] The Story of Bug Bounty Village Badge 2026
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Every year the BBV badge gets one new thing we don\'t know how to do yet. Last year: epoxy. This year: a real 0.96\" OLED behind the acrylic, giving a whole new vibe to the hacker laptop screen. Plus RGB for whichever team you\'re on, and a fun CTF.

\n\nSpeakerBio:  Abhinav \"TweetsFromPanda\" Pandagale, Founder, Hackerware
\n

Abhinav\'s artistry comes from the times he used to sneakily paint drawings made by his sister. His hacking career began as a toddler, disassembling his toys but never putting them back together. His entrepreneurial roots come from selling snacks at a school fair and making a loss of ten bucks, his entire pocket money. Having learned how not to make money, he launched Hackerware.io - a boutique badgelife lab with in-house manufacturing - which has grown over the past ten years into a global presence across 20+ countries. He\'s often spotted at conferences around the world - hosting hardware villages or pulling off the kind of random shenanigans that earned him the Sin CON Person of the Year 2025 award.

\n\n\n\'',NULL,1295260),('4_Sunday','11','11:30','11:59','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Heavy Metal and Hidden Secrets: A Five-Year Retrospective on DEF CON Challenge Coins\'','\'Ariel \"arl_rose\" Garcia\'','Creator Talks_6b8cc492d7dd0f8bb3de3b4b9409b818','\'Title: Heavy Metal and Hidden Secrets: A Five-Year Retrospective on DEF CON Challenge Coins
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Take a look behind the scenes at five years of custom DEF CON challenge coins from DEF CON 30 through DEF CON 34. This session walks through the entire lifecycle of these unique hardware puzzles, exploring the inspiration behind their designs, step-by-step solutions, and how the rise of AI is shifting the future of cryptographic challenges.

\n\nSpeakerBio:  Ariel \"arl_rose\" Garcia
\n

Ariel Garcia (arl_rose) is a security researcher with over a decade of experience in pentesting, bug bounty, and cybersecurity community building. Blending hands-on offensive security with deep community ties, his work is a driving force within the hacker ecosystem. He has organized multiple Live Hacking Events, co-founded the global Ambassador World Cup, and led community initiatives spanning content creation, Discord management, and security instruction. A DEF CON attendee since 2014, Ariel is the co-founder of the Bug Bounty Village, providing a dedicated space to support the researchers and organizations shaping the field.

\n\n\n\'',NULL,1295261),('4_Sunday','12','12:00','12:59','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'How We Built Xenoptic: A Walkthrough of Design, Infrastructure and Vulns!\'','\'Adham Elmosalamy,Ahmed Attalla,Yousef \"deadpackets\" Awad,Kasimir \"Abraxus7331\" Schulz\'','Creator Talks_2e6afc32d8555649c3ab71e211beb65d','\'Title: How We Built Xenoptic: A Walkthrough of Design, Infrastructure and Vulns!
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

In this talk, the CTF.ae team goes behind the scenes of Xenoptic: how they built this year\'s BBV CTF lab, the new challenges they hit along the way, and a walkthrough of some of the most interesting vulnerabilities they planted in it.

\n\nSpeakers:Adham Elmosalamy,Ahmed Attalla,Yousef \"deadpackets\" Awad,Kasimir \"Abraxus7331\" Schulz
\n
\nSpeakerBio:  Adham Elmosalamy, Security Researcher, CTF.ae
\n

Adham is an offensive security consultant by day, but when the sun sets he returns to what he enjoys most: CTFs. This year he led the team building Xenoptic, working across application security, UI/UX and game balance.

\n\nSpeakerBio:  Ahmed Attalla, Founder, CTF.ae
\nI run https: //ctf.ae/
\n\n\n\nSpeakerBio:  Yousef \"deadpackets\" Awad, Head of Engineering at CTF.ae
\n

Head of Engineering @ CTFae, lifelong passion of building things and solving complex problems.

\n\nSpeakerBio:  Kasimir \"Abraxus7331\" Schulz, Director of Security Research at HiddenLayer
\n

Kasimir Schulz is Director of Security Research at HiddenLayer, where he focuses on offensive AI security. Over the past five years, he has designed and built CTF challenges focused on reverse engineering and AI/ML security, including helping develop this year\'s Xenoptic CTF. His background includes zero-day vulnerability research and bug bounty, with recent work centered on discovering and exploiting vulnerabilities in LLM and ML systems, particularly runtime attacks and supply chain security.

\n\n\n\'',NULL,1295262),('4_Sunday','13','13:00','13:45','N','Contests','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Bug Bounty Village CTF Awards\'','\'Bug Bounty Village Staff\'','Contests_ffe5803966b20327b83261707d916c91','\'Title: Bug Bounty Village CTF Awards
\nTags: Bug Bounty Village | Bug Bounty Village CTF | Contest
\nWhen: Sunday, Aug 9, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Join us at the Bug Bounty Village for the CTF Award Ceremony, where we celebrate the top performers of our inaugural Capture The Flag competition. During this in-person ceremony, we\'ll recognize the highest-ranking participants on the leaderboard and award prizes to those present. If you\'ve competed in the CTF and secured a spot on the leaderboard, make sure to attend and claim your prize! This is a unique opportunity to honor the skill and creativity of the global hacking community and to connect with fellow researchers and organizers. We look forward to seeing you there!

\n\nSpeakerBio:  Bug Bounty Village Staff
\nNo BIO available
\n\n\'',NULL,1295263),('4_Sunday','13','13:45','14:15','N','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Bug Bounty Village Closing Ceremony\'','\'Bug Bounty Village Staff\'','Creator Talks_e6622822b87d0b26a9753a5c48f0730d','\'Title: Bug Bounty Village Closing Ceremony
\nTags: Bug Bounty Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 13:45 - 14:15 PDT
\nWhere: LVCCW Level 2 W206-207 (Bug Bounty Village) - Map
\n
\nDescription:
\n

Final words, thanks, and giveaways.

\n\nSpeakerBio:  Bug Bounty Village Staff
\nNo BIO available
\n\n\'',NULL,1295264),('4_Sunday','14','13:45','14:15','Y','Bug Bounty Village','LVCCW Level 2 W206-207 (Bug Bounty Village)','\'Bug Bounty Village Closing Ceremony\'','\'Bug Bounty Village Staff\'','Creator Talks_e6622822b87d0b26a9753a5c48f0730d','\'\'',NULL,1295265),('2_Friday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'Title: Beat the Breach: Defend, Respond, Survive
\nTags: DEF CON Training (Paid) (1-day) | DEF CON Training
\nWhen: Friday, Aug 7, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W221 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:McKay Hardy,Wes Wagstaff
\n
\nSpeakerBio:  McKay Hardy
\nNo BIO available
\nSpeakerBio:  Wes Wagstaff
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/beat-the-breach-defend-respond-survive-mckay-hardy-wes-wagstaff-dctlv2026
\n\'',NULL,1295266),('2_Friday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'\'',NULL,1295267),('2_Friday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'\'',NULL,1295268),('2_Friday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'\'',NULL,1295269),('2_Friday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'\'',NULL,1295270),('2_Friday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'\'',NULL,1295271),('2_Friday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'\'',NULL,1295272),('2_Friday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'\'',NULL,1295273),('2_Friday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'\'',NULL,1295274),('2_Friday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Beat the Breach: Defend, Respond, Survive\'','\'McKay Hardy,Wes Wagstaff\'','DEF CON Training_d870068a19e7168d9762c94901ced229','\'\'',NULL,1295275),('2_Friday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'Title: Cyber & AI Policy Basics: What Every Organization Needs in Place
\nTags: DEF CON Training (Paid) (1-day) | DEF CON Training
\nWhen: Friday, Aug 7, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W223 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Pamela \'Pam\' Feld,Greg Goldberg
\n
\nSpeakerBio:  Pamela \'Pam\' Feld
\nNo BIO available
\nSpeakerBio:  Greg Goldberg
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/cyber-ai-policy-basics-what-every-organization-needs-in-place-pamela-pam-feld-greg-goldberg-dctlv2026-1-day-course-friday
\n\'',NULL,1295276),('2_Friday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'\'',NULL,1295277),('2_Friday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'\'',NULL,1295278),('2_Friday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'\'',NULL,1295279),('2_Friday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'\'',NULL,1295280),('2_Friday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'\'',NULL,1295281),('2_Friday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'\'',NULL,1295282),('2_Friday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'\'',NULL,1295283),('2_Friday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'\'',NULL,1295284),('2_Friday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Cyber & AI Policy Basics: What Every Organization Needs in Place\'','\'Pamela \'Pam\' Feld,Greg Goldberg\'','DEF CON Training_5ebf285450e88cef09aad442385cb6e1','\'\'',NULL,1295285),('2_Friday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'Title: Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk
\nTags: DEF CON Training (Paid) (1-day) | DEF CON Training
\nWhen: Friday, Aug 7, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W224 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Anant Shrivastava,Sunil Yadav
\n
\nSpeakerBio:  Anant Shrivastava
\n

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

\n\nSpeakerBio:  Sunil Yadav
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/digital-supply-chain-security-software-cryptography-ai-and-vendor-risk-anant-shrivastava-dctlv2026
\n\'',NULL,1295286),('2_Friday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'\'',NULL,1295287),('2_Friday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'\'',NULL,1295288),('2_Friday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'\'',NULL,1295289),('2_Friday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'\'',NULL,1295290),('2_Friday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'\'',NULL,1295291),('2_Friday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'\'',NULL,1295292),('2_Friday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'\'',NULL,1295293),('2_Friday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'\'',NULL,1295294),('2_Friday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Digital Supply Chain Security: Software, Cryptography, AI, and Vendor Risk\'','\'Anant Shrivastava,Sunil Yadav\'','DEF CON Training_6fcaee00d86e311d61f5ae2531e82928','\'\'',NULL,1295295),('3_Saturday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'Title: Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections
\nTags: DEF CON Training (Paid) (4-day) | DEF CON Training
\nWhen: Saturday, Aug 8, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W221 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Carlo Anez Mazurco,Mariana Ruiz
\n
\nSpeakerBio:  Carlo Anez Mazurco
\n

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

\n\n

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

\n\n

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

\n\nSpeakerBio:  Mariana Ruiz
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/blue-vs-red-bootcamp-from-attacker-playbooks-to-defender-detections-carlo-anez-mazurco-mariana-ruiz-dctlv2026
\n\'',NULL,1295296),('3_Saturday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'\'',NULL,1295297),('3_Saturday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'\'',NULL,1295298),('3_Saturday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'\'',NULL,1295299),('3_Saturday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'\'',NULL,1295300),('3_Saturday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'\'',NULL,1295301),('3_Saturday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'\'',NULL,1295302),('3_Saturday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'\'',NULL,1295303),('3_Saturday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'\'',NULL,1295304),('3_Saturday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6a0ab65c4ef3501aa27d96975760cec7','\'\'',NULL,1295305),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'Title: Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections
\nTags: DEF CON Training (Paid) (4-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W221 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Carlo Anez Mazurco,Mariana Ruiz
\n
\nSpeakerBio:  Carlo Anez Mazurco
\n

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

\n\n

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

\n\n

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

\n\nSpeakerBio:  Mariana Ruiz
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/blue-vs-red-bootcamp-from-attacker-playbooks-to-defender-detections-carlo-anez-mazurco-mariana-ruiz-dctlv2026
\n\'',NULL,1295306),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'\'',NULL,1295307),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'\'',NULL,1295308),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'\'',NULL,1295309),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'\'',NULL,1295310),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'\'',NULL,1295311),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'\'',NULL,1295312),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'\'',NULL,1295313),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'\'',NULL,1295314),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_6e364741ca50f47bd6f1874c94371049','\'\'',NULL,1295315),('4_Sunday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'Title: Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections
\nTags: DEF CON Training (Paid) (4-day) | DEF CON Training
\nWhen: Sunday, Aug 9, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W221 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Carlo Anez Mazurco,Mariana Ruiz
\n
\nSpeakerBio:  Carlo Anez Mazurco
\n

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

\n\n

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

\n\n

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

\n\nSpeakerBio:  Mariana Ruiz
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/blue-vs-red-bootcamp-from-attacker-playbooks-to-defender-detections-carlo-anez-mazurco-mariana-ruiz-dctlv2026
\n\'',NULL,1295316),('4_Sunday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'\'',NULL,1295317),('4_Sunday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'\'',NULL,1295318),('4_Sunday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'\'',NULL,1295319),('4_Sunday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'\'',NULL,1295320),('4_Sunday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'\'',NULL,1295321),('4_Sunday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'\'',NULL,1295322),('4_Sunday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'\'',NULL,1295323),('4_Sunday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'\'',NULL,1295324),('4_Sunday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_91c2a7dc5bb45e6e0a415180b4b60e9e','\'\'',NULL,1295325),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'Title: Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections
\nTags: DEF CON Training (Paid) (4-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W221 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Carlo Anez Mazurco,Mariana Ruiz
\n
\nSpeakerBio:  Carlo Anez Mazurco
\n

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

\n\n

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

\n\n

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

\n\nSpeakerBio:  Mariana Ruiz
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/blue-vs-red-bootcamp-from-attacker-playbooks-to-defender-detections-carlo-anez-mazurco-mariana-ruiz-dctlv2026
\n\'',NULL,1295326),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'\'',NULL,1295327),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'\'',NULL,1295328),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'\'',NULL,1295329),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'\'',NULL,1295330),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'\'',NULL,1295331),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'\'',NULL,1295332),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'\'',NULL,1295333),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'\'',NULL,1295334),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Blue vs Red Bootcamp: From Attacker Playbooks to Defender Detections\'','\'Carlo Anez Mazurco,Mariana Ruiz\'','DEF CON Training_b351c71399dc4f1b770aa12ce09dfd42','\'\'',NULL,1295335),('4_Sunday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'Title: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Sunday, Aug 9, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W224 (Training) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Dawid Czagan
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/full-stack-pentesting-laboratory-100-hands-on-lifetime-lab-access-dawid-czagan-dctlv2026
\n\'',NULL,1295336),('4_Sunday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'\'',NULL,1295337),('4_Sunday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'\'',NULL,1295338),('4_Sunday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'\'',NULL,1295339),('4_Sunday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'\'',NULL,1295340),('4_Sunday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'\'',NULL,1295341),('4_Sunday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'\'',NULL,1295342),('4_Sunday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'\'',NULL,1295343),('4_Sunday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'\'',NULL,1295344),('4_Sunday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_c0b3d9e6c7be18a4763822653a898848','\'\'',NULL,1295345),('3_Saturday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'Title: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Saturday, Aug 8, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W224 (Training) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Dawid Czagan
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/full-stack-pentesting-laboratory-100-hands-on-lifetime-lab-access-dawid-czagan-dctlv2026
\n\'',NULL,1295346),('3_Saturday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'\'',NULL,1295347),('3_Saturday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'\'',NULL,1295348),('3_Saturday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'\'',NULL,1295349),('3_Saturday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'\'',NULL,1295350),('3_Saturday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'\'',NULL,1295351),('3_Saturday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'\'',NULL,1295352),('3_Saturday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'\'',NULL,1295353),('3_Saturday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'\'',NULL,1295354),('3_Saturday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access\'','\'Dawid Czagan\'','DEF CON Training_ca51ddee768a4c78d486f4e631be2843','\'\'',NULL,1295355),('3_Saturday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'Title: Influence Operations: Tactics, Defense, and Exploitation
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Saturday, Aug 8, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W223 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Greg Conti,Tom Cross
\n
\nSpeakerBio:  Greg Conti
\nNo BIO available
\nSpeakerBio:  Tom Cross
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/influence-operations-tactics-defense-and-exploitation-greg-conti-tom-cross-dctlv2026
\n\'',NULL,1295356),('3_Saturday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'\'',NULL,1295357),('3_Saturday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'\'',NULL,1295358),('3_Saturday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'\'',NULL,1295359),('3_Saturday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'\'',NULL,1295360),('3_Saturday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'\'',NULL,1295361),('3_Saturday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'\'',NULL,1295362),('3_Saturday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'\'',NULL,1295363),('3_Saturday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'\'',NULL,1295364),('3_Saturday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_b6c8b2017b17f1d1f5c0e7ea8e19c2c5','\'\'',NULL,1295365),('4_Sunday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'Title: Influence Operations: Tactics, Defense, and Exploitation
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Sunday, Aug 9, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W223 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Greg Conti,Tom Cross
\n
\nSpeakerBio:  Greg Conti
\nNo BIO available
\nSpeakerBio:  Tom Cross
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/influence-operations-tactics-defense-and-exploitation-greg-conti-tom-cross-dctlv2026
\n\'',NULL,1295366),('4_Sunday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'\'',NULL,1295367),('4_Sunday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'\'',NULL,1295368),('4_Sunday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'\'',NULL,1295369),('4_Sunday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'\'',NULL,1295370),('4_Sunday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'\'',NULL,1295371),('4_Sunday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'\'',NULL,1295372),('4_Sunday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'\'',NULL,1295373),('4_Sunday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'\'',NULL,1295374),('4_Sunday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Influence Operations: Tactics, Defense, and Exploitation\'','\'Greg Conti,Tom Cross\'','DEF CON Training_c69280cc24574eea298cb081b9d48450','\'\'',NULL,1295375),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'Title: AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere:
\n
\nDescription:
\n\n\nSpeakerBio:  Rod Soto
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/ai-soc-101-bootcamp-building-modern-security-operation-skills-with-ai-integration-rod-soto-dctlv2026
\n\'',NULL,1295376),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'\'',NULL,1295377),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'\'',NULL,1295378),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'\'',NULL,1295379),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'\'',NULL,1295380),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'\'',NULL,1295381),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'\'',NULL,1295382),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'\'',NULL,1295383),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'\'',NULL,1295384),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_99a6caf69019ba60775a1eedc589c554','\'\'',NULL,1295385),('5_Monday','08','08:30','17:30','N','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'Title: AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere:
\n
\nDescription:
\n\n\nSpeakerBio:  Rod Soto
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/ai-soc-101-bootcamp-building-modern-security-operation-skills-with-ai-integration-rod-soto-dctlv2026
\n\'',NULL,1295386),('5_Monday','09','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'\'',NULL,1295387),('5_Monday','10','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'\'',NULL,1295388),('5_Monday','11','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'\'',NULL,1295389),('5_Monday','12','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'\'',NULL,1295390),('5_Monday','13','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'\'',NULL,1295391),('5_Monday','14','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'\'',NULL,1295392),('5_Monday','15','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'\'',NULL,1295393),('5_Monday','16','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'\'',NULL,1295394),('5_Monday','17','08:30','17:30','Y','DEF CON Training','','\'AI + SOC 101 Bootcamp: Building Modern Security Operation Skills with AI Integration\'','\'Rod Soto\'','DEF CON Training_3e6bb101d7a32db20383465edec6e386','\'\'',NULL,1295395),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'Title: AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W232 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakers:Abhay Bhargav,Vishnu Prasad
\n
\nSpeakerBio:  Abhay Bhargav
\nNo BIO available
\nSpeakerBio:  Vishnu Prasad
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/ai-agent-security-masterclass-attacking-and-defending-autonomous-ai-systems-abhay-bhargav-vishnu-prasad-dctlv2026
\n\'',NULL,1295396),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'\'',NULL,1295397),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'\'',NULL,1295398),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'\'',NULL,1295399),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'\'',NULL,1295400),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'\'',NULL,1295401),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'\'',NULL,1295402),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'\'',NULL,1295403),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'\'',NULL,1295404),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_2a8fab1c61ed787e89585bb2f9495ff2','\'\'',NULL,1295405),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'Title: AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W232 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakers:Abhay Bhargav,Vishnu Prasad
\n
\nSpeakerBio:  Abhay Bhargav
\nNo BIO available
\nSpeakerBio:  Vishnu Prasad
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/ai-agent-security-masterclass-attacking-and-defending-autonomous-ai-systems-abhay-bhargav-vishnu-prasad-dctlv2026
\n\'',NULL,1295406),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'\'',NULL,1295407),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'\'',NULL,1295408),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'\'',NULL,1295409),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'\'',NULL,1295410),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'\'',NULL,1295411),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'\'',NULL,1295412),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'\'',NULL,1295413),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'\'',NULL,1295414),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W232 (Workshops)','\'AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems\'','\'Abhay Bhargav,Vishnu Prasad\'','DEF CON Training_5a6f0060fd10a59948844ad7d4c5f876','\'\'',NULL,1295415),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'Title: AI SecureOps: Attacking & Defending AI Applications & Agents
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W228 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Abhinav Singh
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/ai-secureops-attacking-defending-ai-applications-agents-abhinav-singh-dclv2026
\n\'',NULL,1295416),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'\'',NULL,1295417),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'\'',NULL,1295418),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'\'',NULL,1295419),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'\'',NULL,1295420),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'\'',NULL,1295421),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'\'',NULL,1295422),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'\'',NULL,1295423),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'\'',NULL,1295424),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_785c8ff9962b7ae9717dbf23c7cb08c9','\'\'',NULL,1295425),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'Title: AI SecureOps: Attacking & Defending AI Applications & Agents
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W228 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Abhinav Singh
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/ai-secureops-attacking-defending-ai-applications-agents-abhinav-singh-dclv2026
\n\'',NULL,1295426),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'\'',NULL,1295427),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'\'',NULL,1295428),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'\'',NULL,1295429),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'\'',NULL,1295430),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'\'',NULL,1295431),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'\'',NULL,1295432),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'\'',NULL,1295433),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'\'',NULL,1295434),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W228 (Workshops)','\'AI SecureOps: Attacking & Defending AI Applications & Agents\'','\'Abhinav Singh\'','DEF CON Training_80e72c6cd7a04bae60ad6539cac87c2c','\'\'',NULL,1295435),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'Title: Advanced Cloud Incident Response in Azure and Microsoft 365
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W230 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Korstiaan Stam
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/products/advanced-cloud-incident-response-in-azure-and-microsoft-365-korstiaan-stam-dctlv2026
\n\'',NULL,1295436),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'\'',NULL,1295437),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'\'',NULL,1295438),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'\'',NULL,1295439),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'\'',NULL,1295440),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'\'',NULL,1295441),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'\'',NULL,1295442),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'\'',NULL,1295443),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'\'',NULL,1295444),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_5b6d101d887b811ef6669842a6718773','\'\'',NULL,1295445),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'Title: Advanced Cloud Incident Response in Azure and Microsoft 365
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W230 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Korstiaan Stam
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/products/advanced-cloud-incident-response-in-azure-and-microsoft-365-korstiaan-stam-dctlv2026
\n\'',NULL,1295446),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'\'',NULL,1295447),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'\'',NULL,1295448),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'\'',NULL,1295449),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'\'',NULL,1295450),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'\'',NULL,1295451),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'\'',NULL,1295452),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'\'',NULL,1295453),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'\'',NULL,1295454),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W230 (Workshops)','\'Advanced Cloud Incident Response in Azure and Microsoft 365\'','\'Korstiaan Stam\'','DEF CON Training_dde17d7751bff5dbfd3ec4f492d1460a','\'\'',NULL,1295455),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'Title: Advanced Windows Binary Exploitation
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map
\n
\nDescription:
\n\n\nSpeakers:Kolja Grassmann,Florian Schweins
\n
\nSpeakerBio:  Kolja Grassmann
\nNo BIO available
\nSpeakerBio:  Florian Schweins
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/advanced-windows-binary-exploitation-kolja-grassmann-florian-schweins-dctlv2026
\n\'',NULL,1295456),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'\'',NULL,1295457),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'\'',NULL,1295458),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'\'',NULL,1295459),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'\'',NULL,1295460),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'\'',NULL,1295461),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'\'',NULL,1295462),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'\'',NULL,1295463),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'\'',NULL,1295464),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_30b47ba7c6a322f024965c91c6e059f6','\'\'',NULL,1295465),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'Title: Advanced Windows Binary Exploitation
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map
\n
\nDescription:
\n\n\nSpeakers:Kolja Grassmann,Florian Schweins
\n
\nSpeakerBio:  Kolja Grassmann
\nNo BIO available
\nSpeakerBio:  Florian Schweins
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/advanced-windows-binary-exploitation-kolja-grassmann-florian-schweins-dctlv2026
\n\'',NULL,1295466),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'\'',NULL,1295467),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'\'',NULL,1295468),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'\'',NULL,1295469),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'\'',NULL,1295470),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'\'',NULL,1295471),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'\'',NULL,1295472),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'\'',NULL,1295473),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'\'',NULL,1295474),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W213 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Advanced Windows Binary Exploitation\'','\'Kolja Grassmann,Florian Schweins\'','DEF CON Training_b56a5b15abdcc2e876b4cc7f18bc8a77','\'\'',NULL,1295475),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'Title: Adversarial Thinking: The Art of Dangerous Ideas
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W223 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Greg Conti,Tom Cross
\n
\nSpeakerBio:  Greg Conti
\nNo BIO available
\nSpeakerBio:  Tom Cross
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/adversarial-thinking-greg-conti-dctlv2026
\n\'',NULL,1295476),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'\'',NULL,1295477),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'\'',NULL,1295478),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'\'',NULL,1295479),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'\'',NULL,1295480),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'\'',NULL,1295481),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'\'',NULL,1295482),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'\'',NULL,1295483),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'\'',NULL,1295484),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_3fea6c9b9c7d3bbca216febdc66a4b43','\'\'',NULL,1295485),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'Title: Adversarial Thinking: The Art of Dangerous Ideas
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W223 (Training) - Map
\n
\nDescription:
\n\n\nSpeakers:Greg Conti,Tom Cross
\n
\nSpeakerBio:  Greg Conti
\nNo BIO available
\nSpeakerBio:  Tom Cross
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/adversarial-thinking-greg-conti-dctlv2026
\n\'',NULL,1295486),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'\'',NULL,1295487),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'\'',NULL,1295488),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'\'',NULL,1295489),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'\'',NULL,1295490),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'\'',NULL,1295491),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'\'',NULL,1295492),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'\'',NULL,1295493),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'\'',NULL,1295494),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W223 (Training)','\'Adversarial Thinking: The Art of Dangerous Ideas\'','\'Greg Conti,Tom Cross\'','DEF CON Training_e7f4786205008f749a93112f83f7b46c','\'\'',NULL,1295495),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'Title: Agentic AppSec: Harnessing LLMs
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W204 (Payment Village) - Map
\n
\nDescription:
\n\n\nSpeakers:Seth Law,Ken Johnson
\n
\nSpeakerBio:  Seth Law
\nNo BIO available
\nSpeakerBio:  Ken Johnson
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/harnessing-llms-for-application-security-seth-law-ken-johnson-dctlv2026
\n\'',NULL,1295496),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'\'',NULL,1295497),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'\'',NULL,1295498),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'\'',NULL,1295499),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'\'',NULL,1295500),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'\'',NULL,1295501),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'\'',NULL,1295502),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'\'',NULL,1295503),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'\'',NULL,1295504),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_59ae32af30091dc99dd175d3c9135fd8','\'\'',NULL,1295505),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'Title: Agentic AppSec: Harnessing LLMs
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W204 (Payment Village) - Map
\n
\nDescription:
\n\n\nSpeakers:Seth Law,Ken Johnson
\n
\nSpeakerBio:  Seth Law
\nNo BIO available
\nSpeakerBio:  Ken Johnson
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/harnessing-llms-for-application-security-seth-law-ken-johnson-dctlv2026
\n\'',NULL,1295506),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'\'',NULL,1295507),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'\'',NULL,1295508),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'\'',NULL,1295509),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'\'',NULL,1295510),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'\'',NULL,1295511),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'\'',NULL,1295512),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'\'',NULL,1295513),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'\'',NULL,1295514),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W204 (Payment Village)','\'Agentic AppSec: Harnessing LLMs\'','\'Seth Law,Ken Johnson\'','DEF CON Training_9c95c52b32bbd4fa271b1e2d76765e18','\'\'',NULL,1295515),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'Title: Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W229 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  John \"clearbluejar\" McIntosh
\n

John McIntosh (@clearbluejar) is a security researcher and founder of ClearSecLabs, specializing in reverse engineering, vulnerability research, and AI-assisted binary analysis. He is the author of ghidriff, an open-source Ghidra-based binary diffing engine, and pyghidra-mcp, a headless Ghidra MCP server enabling LLM-driven, project-wide, multi-binary reverse engineering workflows. An active contributor to the Agent Skills ecosystem, John bridges deterministic analysis with AI-driven reasoning to accelerate vulnerability research. He has delivered training and workshops at DEF CON, Black Hat, REcon, Ringzer0, 44CON, Objective by the Sea, and Insomni\'hack, covering topics from practical Windows reverse engineering to building private local LLM RE stacks. His recent work includes the \"Agentic RE\" training at DEF CON Singapore 2026, the MCP Ghidra workshop at REcon 2025, and the \"Supercharging Ghidra\" LLM workshop at Ringzer0 COUNTERMEASURE 2025. With over a decade of offensive security experience, John publishes detailed research on reversing CVEs, building RE tooling, and agentic patch diffing at clearbluejar.github.io. His teaching emphasizes reproducibility, progressive skill-building, and contributor empowerment.

\n\n\nLinks:
    More Info - https://training.defcon.org/products/agentic-re-automating-reverse-engineering-vulnerability-research-with-ai-john-mcintosh-dctlv2026
\n\'',NULL,1295516),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'\'',NULL,1295517),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'\'',NULL,1295518),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'\'',NULL,1295519),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'\'',NULL,1295520),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'\'',NULL,1295521),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'\'',NULL,1295522),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'\'',NULL,1295523),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'\'',NULL,1295524),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_ef01d78d03d643011f871f43458e182e','\'\'',NULL,1295525),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'Title: Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W229 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  John \"clearbluejar\" McIntosh
\n

John McIntosh (@clearbluejar) is a security researcher and founder of ClearSecLabs, specializing in reverse engineering, vulnerability research, and AI-assisted binary analysis. He is the author of ghidriff, an open-source Ghidra-based binary diffing engine, and pyghidra-mcp, a headless Ghidra MCP server enabling LLM-driven, project-wide, multi-binary reverse engineering workflows. An active contributor to the Agent Skills ecosystem, John bridges deterministic analysis with AI-driven reasoning to accelerate vulnerability research. He has delivered training and workshops at DEF CON, Black Hat, REcon, Ringzer0, 44CON, Objective by the Sea, and Insomni\'hack, covering topics from practical Windows reverse engineering to building private local LLM RE stacks. His recent work includes the \"Agentic RE\" training at DEF CON Singapore 2026, the MCP Ghidra workshop at REcon 2025, and the \"Supercharging Ghidra\" LLM workshop at Ringzer0 COUNTERMEASURE 2025. With over a decade of offensive security experience, John publishes detailed research on reversing CVEs, building RE tooling, and agentic patch diffing at clearbluejar.github.io. His teaching emphasizes reproducibility, progressive skill-building, and contributor empowerment.

\n\n\nLinks:
    More Info - https://training.defcon.org/products/agentic-re-automating-reverse-engineering-vulnerability-research-with-ai-john-mcintosh-dctlv2026
\n\'',NULL,1295526),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'\'',NULL,1295527),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'\'',NULL,1295528),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'\'',NULL,1295529),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'\'',NULL,1295530),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'\'',NULL,1295531),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'\'',NULL,1295532),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'\'',NULL,1295533),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'\'',NULL,1295534),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W229 (Workshops)','\'Agentic RE: Automating Reverse Engineering & Vulnerability Research with AI\'','\'John \"clearbluejar\" McIntosh\'','DEF CON Training_05698d1aa51dfc8b7cc78cbd2f416520','\'\'',NULL,1295535),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'Title: Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map
\n
\nDescription:
\n\n\nSpeakers:Monnappa K A,Sajan Shetty
\n
\nSpeakerBio:  Monnappa K A
\nNo BIO available
\nSpeakerBio:  Sajan Shetty
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/a-practical-malware-analysis-threat-hunting-with-memory-forensics-endpoint-telemetry-ai-driven-hunting-monnappa-k-a-sajan-shetty-dcsg2026-copy
\n\'',NULL,1295536),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'\'',NULL,1295537),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'\'',NULL,1295538),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'\'',NULL,1295539),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'\'',NULL,1295540),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'\'',NULL,1295541),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'\'',NULL,1295542),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'\'',NULL,1295543),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'\'',NULL,1295544),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_21953cc2f1849130db8e284c4d296556','\'\'',NULL,1295545),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'Title: Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map
\n
\nDescription:
\n\n\nSpeakers:Monnappa K A,Sajan Shetty
\n
\nSpeakerBio:  Monnappa K A
\nNo BIO available
\nSpeakerBio:  Sajan Shetty
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/a-practical-malware-analysis-threat-hunting-with-memory-forensics-endpoint-telemetry-ai-driven-hunting-monnappa-k-a-sajan-shetty-dcsg2026-copy
\n\'',NULL,1295546),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'\'',NULL,1295547),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'\'',NULL,1295548),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'\'',NULL,1295549),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'\'',NULL,1295550),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'\'',NULL,1295551),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'\'',NULL,1295552),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'\'',NULL,1295553),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'\'',NULL,1295554),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W215 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Analyze, Detect & Hunt: Hands-On Malware Analysis, Memory Forensics & AI-Driven Threat Hunting with Endpoint Telemetry\'','\'Monnappa K A,Sajan Shetty\'','DEF CON Training_dfe8808c930a308d5fd332bedb491517','\'\'',NULL,1295555),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'Title: Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W231 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakers:Jos Wetzels,Wouter Bokslag
\n
\nSpeakerBio:  Jos Wetzels, Midnight Blue
\nNo BIO available
\nSpeakerBio:  Wouter Bokslag, Midnight Blue
\n

Wouter Bokslag is a co-founding partner and security researcher at Midnight Blue. He is known for the reverse-engineering and cryptanalysis of several proprietary in-vehicle immobilizer authentication ciphers used by major automotive manufacturers as well as co-developing the world’s fastest public attack against the Hitag2 cipher. He holds a Master’s Degree in Computer Science & Engineering from Eindhoven University of Technology (TU/e) and designed and assisted in teaching hands-on offensive security classes for graduate students at the Dutch Kerckhoffs Institute for several years.

\n\n

Recently heavily involved in the TETRA:BURST research and associated follow-up research, such as the recent reverse-engineering and analysis of the elusive TETRA End-to-End protocol. Also, a contributer of open-source SDR code.

\n\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/red-team-sigint-practical-sdr-hacking-for-mission-critical-automotive-aviation-and-marine-targets-jos-wetzels-wouter-bokslag-midnight-blue-dctlv2026
\n\'',NULL,1295556),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'\'',NULL,1295557),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'\'',NULL,1295558),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'\'',NULL,1295559),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'\'',NULL,1295560),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'\'',NULL,1295561),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'\'',NULL,1295562),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'\'',NULL,1295563),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'\'',NULL,1295564),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_a047ee320226a5cdd6a439b43cae9743','\'\'',NULL,1295565),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'Title: Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W231 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakers:Jos Wetzels,Wouter Bokslag
\n
\nSpeakerBio:  Jos Wetzels, Midnight Blue
\nNo BIO available
\nSpeakerBio:  Wouter Bokslag, Midnight Blue
\n

Wouter Bokslag is a co-founding partner and security researcher at Midnight Blue. He is known for the reverse-engineering and cryptanalysis of several proprietary in-vehicle immobilizer authentication ciphers used by major automotive manufacturers as well as co-developing the world’s fastest public attack against the Hitag2 cipher. He holds a Master’s Degree in Computer Science & Engineering from Eindhoven University of Technology (TU/e) and designed and assisted in teaching hands-on offensive security classes for graduate students at the Dutch Kerckhoffs Institute for several years.

\n\n

Recently heavily involved in the TETRA:BURST research and associated follow-up research, such as the recent reverse-engineering and analysis of the elusive TETRA End-to-End protocol. Also, a contributer of open-source SDR code.

\n\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/red-team-sigint-practical-sdr-hacking-for-mission-critical-automotive-aviation-and-marine-targets-jos-wetzels-wouter-bokslag-midnight-blue-dctlv2026
\n\'',NULL,1295566),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'\'',NULL,1295567),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'\'',NULL,1295568),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'\'',NULL,1295569),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'\'',NULL,1295570),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'\'',NULL,1295571),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'\'',NULL,1295572),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'\'',NULL,1295573),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'\'',NULL,1295574),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W231 (Workshops)','\'Applied SDR Hacking: Red Team SIGINT for mission-critical, automotive, aviation, and marine targets\'','\'Jos Wetzels,Wouter Bokslag\'','DEF CON Training_e0e1a0fed151bb0a0b0a29cf1df48774','\'\'',NULL,1295575),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'Title: Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W224 (Training) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Dawid Czagan
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/black-belt-pentesting-bug-hunting-millionaire-mastering-web-attacks-with-full-stack-exploitation-100-hands-on-dawid-czagan-dctlv2026
\n\'',NULL,1295576),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'\'',NULL,1295577),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'\'',NULL,1295578),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'\'',NULL,1295579),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'\'',NULL,1295580),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'\'',NULL,1295581),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'\'',NULL,1295582),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'\'',NULL,1295583),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'\'',NULL,1295584),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_e1a67f21e35eae7b067b09731e69d5ed','\'\'',NULL,1295585),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'Title: Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W224 (Training) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Dawid Czagan
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/black-belt-pentesting-bug-hunting-millionaire-mastering-web-attacks-with-full-stack-exploitation-100-hands-on-dawid-czagan-dctlv2026
\n\'',NULL,1295586),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'\'',NULL,1295587),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'\'',NULL,1295588),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'\'',NULL,1295589),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'\'',NULL,1295590),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'\'',NULL,1295591),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'\'',NULL,1295592),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'\'',NULL,1295593),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'\'',NULL,1295594); INSERT INTO `events` VALUES ('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W224 (Training)','\'Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation (100% Hands-On)\'','\'Dawid Czagan\'','DEF CON Training_509870a369468e8d810adcd4c388418f','\'\'',NULL,1295595),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'Title: Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W212 (Misc Meeting Room) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Red Team Alliance
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/breaking-the-cloud-practical-attacks-on-aws-azure-gcp-digitalocean-and-aliyun-anant-shrivastava-dctlv2026
\n\'',NULL,1295596),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'\'',NULL,1295597),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'\'',NULL,1295598),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'\'',NULL,1295599),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'\'',NULL,1295600),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'\'',NULL,1295601),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'\'',NULL,1295602),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'\'',NULL,1295603),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'\'',NULL,1295604),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_c151a5f20113316795911e9174d5cd11','\'\'',NULL,1295605),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'Title: Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W212 (Misc Meeting Room) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Red Team Alliance
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/breaking-the-cloud-practical-attacks-on-aws-azure-gcp-digitalocean-and-aliyun-anant-shrivastava-dctlv2026
\n\'',NULL,1295606),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'\'',NULL,1295607),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'\'',NULL,1295608),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'\'',NULL,1295609),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'\'',NULL,1295610),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'\'',NULL,1295611),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'\'',NULL,1295612),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'\'',NULL,1295613),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'\'',NULL,1295614),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W212 (Misc Meeting Room)','\'Breaking Physical Access Control: Electrical Fundamentals, RFID Credentials, and Hands-On Offense\'','\'Red Team Alliance\'','DEF CON Training_38d3fd6d0aa3b894f17e5203dc8e88f7','\'\'',NULL,1295615),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'Title: Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map
\n
\nDescription:
\n\n\nSpeakers:Anant Shrivastava,Riyaz Walikar
\n
\nSpeakerBio:  Anant Shrivastava
\n

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

\n\nSpeakerBio:  Riyaz Walikar
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/bridging-the-gap-hands-on-embedded-hardware-hacking-aaron-wasserman-garrett-freibott-will-mccardell-dctlv2026
\n\'',NULL,1295616),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'\'',NULL,1295617),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'\'',NULL,1295618),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'\'',NULL,1295619),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'\'',NULL,1295620),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'\'',NULL,1295621),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'\'',NULL,1295622),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'\'',NULL,1295623),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'\'',NULL,1295624),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_93374266ee4a865955b90f448e959a71','\'\'',NULL,1295625),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'Title: Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map
\n
\nDescription:
\n\n\nSpeakers:Anant Shrivastava,Riyaz Walikar
\n
\nSpeakerBio:  Anant Shrivastava
\n

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

\n\nSpeakerBio:  Riyaz Walikar
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/bridging-the-gap-hands-on-embedded-hardware-hacking-aaron-wasserman-garrett-freibott-will-mccardell-dctlv2026
\n\'',NULL,1295626),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'\'',NULL,1295627),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'\'',NULL,1295628),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'\'',NULL,1295629),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'\'',NULL,1295630),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'\'',NULL,1295631),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'\'',NULL,1295632),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'\'',NULL,1295633),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'\'',NULL,1295634),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Breaking the Cloud Layer - Modern and Practical Attacks on AWS, Azure, GCP, Aliyun, Railway and Vercel\'','\'Anant Shrivastava,Riyaz Walikar\'','DEF CON Training_6ebdb8241beae9f97d469ec9ea658ca4','\'\'',NULL,1295635),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'Title: Bridging the GAP: Hands-On Embedded Hardware Hacking
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n\n\nSpeakers:Aaron Wasserman,Garrett Freibott,Will McCardell
\n
\nSpeakerBio:  Aaron Wasserman, Praetorian
\nNo BIO available
\nSpeakerBio:  Garrett Freibott, Praetorian
\nNo BIO available
\nSpeakerBio:  Will McCardell, Praetorian
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/bridging-the-gap-hands-on-embedded-hardware-hacking-aaron-wasserman-garrett-freibott-will-mccardell-dctlv2026
\n\'',NULL,1295636),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'\'',NULL,1295637),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'\'',NULL,1295638),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'\'',NULL,1295639),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'\'',NULL,1295640),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'\'',NULL,1295641),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'\'',NULL,1295642),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'\'',NULL,1295643),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'\'',NULL,1295644),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_03963330bf6dd9dea0e686a3b9ee89b8','\'\'',NULL,1295645),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'Title: Bridging the GAP: Hands-On Embedded Hardware Hacking
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n\n\nSpeakers:Aaron Wasserman,Garrett Freibott,Will McCardell
\n
\nSpeakerBio:  Aaron Wasserman, Praetorian
\nNo BIO available
\nSpeakerBio:  Garrett Freibott, Praetorian
\nNo BIO available
\nSpeakerBio:  Will McCardell, Praetorian
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/bridging-the-gap-hands-on-embedded-hardware-hacking-aaron-wasserman-garrett-freibott-will-mccardell-dctlv2026
\n\'',NULL,1295646),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'\'',NULL,1295647),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'\'',NULL,1295648),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'\'',NULL,1295649),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'\'',NULL,1295650),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'\'',NULL,1295651),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'\'',NULL,1295652),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'\'',NULL,1295653),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'\'',NULL,1295654),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W238 (DEF CON Groups)','\'Bridging the GAP: Hands-On Embedded Hardware Hacking\'','\'Aaron Wasserman,Garrett Freibott,Will McCardell\'','DEF CON Training_5ba3e928fada1fbcfdc297958655459e','\'\'',NULL,1295655),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'Title: Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W222 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Kamel Ghali
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/car-hacking-masterclass-attacking-defending-automotive-systems-and-infrastructure-kamel-ghali-dctlv2026
\n\'',NULL,1295656),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'\'',NULL,1295657),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'\'',NULL,1295658),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'\'',NULL,1295659),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'\'',NULL,1295660),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'\'',NULL,1295661),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'\'',NULL,1295662),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'\'',NULL,1295663),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'\'',NULL,1295664),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_dd87ab6ec5ec6f757fdd06f23f303591','\'\'',NULL,1295665),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'Title: Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W222 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Kamel Ghali
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/car-hacking-masterclass-attacking-defending-automotive-systems-and-infrastructure-kamel-ghali-dctlv2026
\n\'',NULL,1295666),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'\'',NULL,1295667),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'\'',NULL,1295668),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'\'',NULL,1295669),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'\'',NULL,1295670),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'\'',NULL,1295671),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'\'',NULL,1295672),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'\'',NULL,1295673),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'\'',NULL,1295674),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W222 (Workshops)','\'Car Hacking Masterclass - Attacking & Defending Automotive Systems and Infrastructure\'','\'Kamel Ghali\'','DEF CON Training_36435d0f6f57bb7326a5433d204fcef3','\'\'',NULL,1295675),('5_Monday','08','08:30','17:30','N','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'Title: Dark Wolf Hack Our Drone Workshop
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere:
\n
\nDescription:
\n\n\nSpeakers:Ronald Broberg,Rudy Mendoza
\n
\nSpeakerBio:  Ronald Broberg
\nNo BIO available
\nSpeakerBio:  Rudy Mendoza
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/dark-wolf-hack-our-drone-workshop-ronald-broberg-rudy-mendoza-dctlv2026
\n\'',NULL,1295676),('5_Monday','09','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'\'',NULL,1295677),('5_Monday','10','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'\'',NULL,1295678),('5_Monday','11','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'\'',NULL,1295679),('5_Monday','12','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'\'',NULL,1295680),('5_Monday','13','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'\'',NULL,1295681),('5_Monday','14','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'\'',NULL,1295682),('5_Monday','15','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'\'',NULL,1295683),('5_Monday','16','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'\'',NULL,1295684),('5_Monday','17','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_7e98dcfa470bf49d3ec4eb46bedcc763','\'\'',NULL,1295685),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'Title: Dark Wolf Hack Our Drone Workshop
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere:
\n
\nDescription:
\n\n\nSpeakers:Ronald Broberg,Rudy Mendoza
\n
\nSpeakerBio:  Ronald Broberg
\nNo BIO available
\nSpeakerBio:  Rudy Mendoza
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/dark-wolf-hack-our-drone-workshop-ronald-broberg-rudy-mendoza-dctlv2026
\n\'',NULL,1295686),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'\'',NULL,1295687),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'\'',NULL,1295688),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'\'',NULL,1295689),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'\'',NULL,1295690),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'\'',NULL,1295691),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'\'',NULL,1295692),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'\'',NULL,1295693),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'\'',NULL,1295694),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','','\'Dark Wolf Hack Our Drone Workshop\'','\'Ronald Broberg,Rudy Mendoza\'','DEF CON Training_a9d344ad8b8b07946241a458c9278748','\'\'',NULL,1295695),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'Title: Deep Dive into the Dark Web
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W221 (Training) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Robert \"pwcrack\" Weiss
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/deep-dive-into-the-dark-web-robert-weiss-pwcrack-dctlv2026
\n\'',NULL,1295696),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'\'',NULL,1295697),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'\'',NULL,1295698),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'\'',NULL,1295699),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'\'',NULL,1295700),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'\'',NULL,1295701),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'\'',NULL,1295702),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'\'',NULL,1295703),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'\'',NULL,1295704),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_769adc2905d1e2e73e8b5785b5be0610','\'\'',NULL,1295705),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'Title: Deep Dive into the Dark Web
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W221 (Training) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Robert \"pwcrack\" Weiss
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/deep-dive-into-the-dark-web-robert-weiss-pwcrack-dctlv2026
\n\'',NULL,1295706),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'\'',NULL,1295707),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'\'',NULL,1295708),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'\'',NULL,1295709),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'\'',NULL,1295710),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'\'',NULL,1295711),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'\'',NULL,1295712),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'\'',NULL,1295713),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'\'',NULL,1295714),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W221 (Training)','\'Deep Dive into the Dark Web\'','\'Robert \"pwcrack\" Weiss\'','DEF CON Training_39920aad1ad47e6db610d0f74b39bc2f','\'\'',NULL,1295715),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'Title: Hacking Android and IOT Apps by Example
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n\n\nSpeakers:Abraham Aranguren,Abhishek J M,Anirudh Anand
\n
\nSpeakerBio:  Abraham Aranguren
\nNo BIO available
\nSpeakerBio:  Abhishek J M
\nNo BIO available
\nSpeakerBio:  Anirudh Anand
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/hacking-android-apps-by-example-abraham-aranguren-abhishek-j-m-anirudh-anand-dctlv2026
\n\'',NULL,1295716),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'\'',NULL,1295717),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'\'',NULL,1295718),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'\'',NULL,1295719),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'\'',NULL,1295720),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'\'',NULL,1295721),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'\'',NULL,1295722),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'\'',NULL,1295723),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'\'',NULL,1295724),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_fb088ea7fe1f93796cd8c16a49e53dce','\'\'',NULL,1295725),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'Title: Hacking Android and IOT Apps by Example
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n\n\nSpeakers:Abraham Aranguren,Abhishek J M,Anirudh Anand
\n
\nSpeakerBio:  Abraham Aranguren
\nNo BIO available
\nSpeakerBio:  Abhishek J M
\nNo BIO available
\nSpeakerBio:  Anirudh Anand
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/hacking-android-apps-by-example-abraham-aranguren-abhishek-j-m-anirudh-anand-dctlv2026
\n\'',NULL,1295726),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'\'',NULL,1295727),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'\'',NULL,1295728),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'\'',NULL,1295729),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'\'',NULL,1295730),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'\'',NULL,1295731),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'\'',NULL,1295732),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'\'',NULL,1295733),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'\'',NULL,1295734),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W321 (Telecom Village)','\'Hacking Android and IOT Apps by Example\'','\'Abraham Aranguren,Abhishek J M,Anirudh Anand\'','DEF CON Training_c6752618b8c51fc73a3b9abf91d3e8fa','\'\'',NULL,1295735),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'Title: Hacking Cryptography
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n\n\nSpeakers:Ruben Gonzalez,Aaron Kaiser
\n
\nSpeakerBio:  Ruben Gonzalez, Neodyme
\n

Crypto PhD, Security Researcher and Trainer at Neodyme

\n\nSpeakerBio:  Aaron Kaiser
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/hacking-cryptography-ruben-gonzalez-aaron-kaiser-dctlv2026
\n\'',NULL,1295736),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'\'',NULL,1295737),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'\'',NULL,1295738),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'\'',NULL,1295739),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'\'',NULL,1295740),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'\'',NULL,1295741),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'\'',NULL,1295742),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'\'',NULL,1295743),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'\'',NULL,1295744),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_83d3ede740844b730623aafe15385f83','\'\'',NULL,1295745),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'Title: Hacking Cryptography
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n\n\nSpeakers:Ruben Gonzalez,Aaron Kaiser
\n
\nSpeakerBio:  Ruben Gonzalez, Neodyme
\n

Crypto PhD, Security Researcher and Trainer at Neodyme

\n\nSpeakerBio:  Aaron Kaiser
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/hacking-cryptography-ruben-gonzalez-aaron-kaiser-dctlv2026
\n\'',NULL,1295746),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'\'',NULL,1295747),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'\'',NULL,1295748),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'\'',NULL,1295749),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'\'',NULL,1295750),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'\'',NULL,1295751),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'\'',NULL,1295752),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'\'',NULL,1295753),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'\'',NULL,1295754),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W316 (DC NextGen)','\'Hacking Cryptography\'','\'Ruben Gonzalez,Aaron Kaiser\'','DEF CON Training_a4ec933ddab167a96dd2803e6eccb59b','\'\'',NULL,1295755),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'Title: IoT Exploitation Masterclass: Hardware & RF Hacking
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n\n\nSpeakers:Smriti Gaba,Yianna Paris
\n
\nSpeakerBio:  Smriti Gaba
\nNo BIO available
\nSpeakerBio:  Yianna Paris
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/iot-exploitation-masterclass-hardware-rf-hacking-smriti-gaba-yianna-paris-dctlv2026
\n\'',NULL,1295756),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'\'',NULL,1295757),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'\'',NULL,1295758),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'\'',NULL,1295759),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'\'',NULL,1295760),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'\'',NULL,1295761),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'\'',NULL,1295762),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'\'',NULL,1295763),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'\'',NULL,1295764),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_494e0b4aab629be306bab55aa1faf388','\'\'',NULL,1295765),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'Title: IoT Exploitation Masterclass: Hardware & RF Hacking
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - Map
\n
\nDescription:
\n\n\nSpeakers:Smriti Gaba,Yianna Paris
\n
\nSpeakerBio:  Smriti Gaba
\nNo BIO available
\nSpeakerBio:  Yianna Paris
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/iot-exploitation-masterclass-hardware-rf-hacking-smriti-gaba-yianna-paris-dctlv2026
\n\'',NULL,1295766),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'\'',NULL,1295767),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'\'',NULL,1295768),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'\'',NULL,1295769),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'\'',NULL,1295770),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'\'',NULL,1295771),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'\'',NULL,1295772),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'\'',NULL,1295773),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'\'',NULL,1295774),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W320 (Social Engineering Community Village Labs)','\'IoT Exploitation Masterclass: Hardware & RF Hacking\'','\'Smriti Gaba,Yianna Paris\'','DEF CON Training_18ec6a0548d9e5d209d8acc2105d8cfe','\'\'',NULL,1295775),('5_Monday','08','08:30','16:59','N','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_5871a19bdea3c2a5bc6c25ffaba199fc','\'Title: Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 16:59 PDT
\nWhere: LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Abhijith \"Abx\" B R, Founder of Adversary Village
\n

Abhijith B R, also known by the pseudonym Abx, has more than a decade of experience in the offensive cyber security industry, serves as the Director of BreachSimRange, and Founder of Adversary Village.\nHe is a professional hacker, offensive cyber security specialist, red team consultant, security researcher, trainer and public speaker. \nCurrently, he is building BreachSimRange.io as the Founder and Director and is involved with multiple organizations as a consulting specialist to help them build offensive cyber security operations programs, improve their current security posture, assess cyber defense systems, and bridge the gap between business leadership and security professionals.\nIn the past, he led the offensive security team at Envestnet, Inc., held the position of Deputy Manager - Cyber Security at Nissan Motor Corporation, and prior to that, he worked as a Senior Security Analyst at EY. \nAs the founder of Adversary Village (https://adversaryvillage.org/), Abhijith spearheads a community initiative focused on adversary simulation, adversary-tactics, purple teaming, threat actor/ransomware research-emulation, and offensive cyber security. Adversary Village is part of DEF CON Villages and organizes hacking villages at prominent events such as the DEF CON Hacking Conference, RSA Conference etc. \nAbx also acts as the Lead of an official DEF CON Group named DC0471. He is actively involved in leading the Tactical Adversary project (https://tacticaladversary.io/), a personal initiative that centers around offensive cyber security, adversary attack simulation and red teaming tradecraft. \nAbhijith has spoken and delivered trainings at various hacking and cyber security conferences such as, DEF CON hacker convention - Las Vegas, RSA Conference - San Francisco, The Diana Initiative - Las Vegas, DEF CON 28 safemode - DCG Village, Opensource India, Security BSides Las Vegas, BSides San Francisco, BSides Tampa, Hack Space Con – Kennedy space center Florida, Nullcon – Goa, c0c0n – Kerala, BSides Delhi, DEF CON Bahrain, DEF CON Singapore etc.

\n\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/offensive-cyber-security-operations-mastering-breach-and-adversarial-attack-simulation-engagements-abhijith-abx-dctlv2026
\n\'',NULL,1295776),('5_Monday','09','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_5871a19bdea3c2a5bc6c25ffaba199fc','\'\'',NULL,1295777),('5_Monday','10','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_5871a19bdea3c2a5bc6c25ffaba199fc','\'\'',NULL,1295778),('5_Monday','11','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_5871a19bdea3c2a5bc6c25ffaba199fc','\'\'',NULL,1295779),('5_Monday','12','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_5871a19bdea3c2a5bc6c25ffaba199fc','\'\'',NULL,1295780),('5_Monday','13','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_5871a19bdea3c2a5bc6c25ffaba199fc','\'\'',NULL,1295781),('5_Monday','14','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_5871a19bdea3c2a5bc6c25ffaba199fc','\'\'',NULL,1295782),('5_Monday','15','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_5871a19bdea3c2a5bc6c25ffaba199fc','\'\'',NULL,1295783),('5_Monday','16','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_5871a19bdea3c2a5bc6c25ffaba199fc','\'\'',NULL,1295784),('6_Tuesday','08','08:30','16:59','N','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_7c5ac18218b7d315855c3a93661fa201','\'Title: Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 16:59 PDT
\nWhere: LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers ) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Abhijith \"Abx\" B R, Founder of Adversary Village
\n

Abhijith B R, also known by the pseudonym Abx, has more than a decade of experience in the offensive cyber security industry, serves as the Director of BreachSimRange, and Founder of Adversary Village.\nHe is a professional hacker, offensive cyber security specialist, red team consultant, security researcher, trainer and public speaker. \nCurrently, he is building BreachSimRange.io as the Founder and Director and is involved with multiple organizations as a consulting specialist to help them build offensive cyber security operations programs, improve their current security posture, assess cyber defense systems, and bridge the gap between business leadership and security professionals.\nIn the past, he led the offensive security team at Envestnet, Inc., held the position of Deputy Manager - Cyber Security at Nissan Motor Corporation, and prior to that, he worked as a Senior Security Analyst at EY. \nAs the founder of Adversary Village (https://adversaryvillage.org/), Abhijith spearheads a community initiative focused on adversary simulation, adversary-tactics, purple teaming, threat actor/ransomware research-emulation, and offensive cyber security. Adversary Village is part of DEF CON Villages and organizes hacking villages at prominent events such as the DEF CON Hacking Conference, RSA Conference etc. \nAbx also acts as the Lead of an official DEF CON Group named DC0471. He is actively involved in leading the Tactical Adversary project (https://tacticaladversary.io/), a personal initiative that centers around offensive cyber security, adversary attack simulation and red teaming tradecraft. \nAbhijith has spoken and delivered trainings at various hacking and cyber security conferences such as, DEF CON hacker convention - Las Vegas, RSA Conference - San Francisco, The Diana Initiative - Las Vegas, DEF CON 28 safemode - DCG Village, Opensource India, Security BSides Las Vegas, BSides San Francisco, BSides Tampa, Hack Space Con – Kennedy space center Florida, Nullcon – Goa, c0c0n – Kerala, BSides Delhi, DEF CON Bahrain, DEF CON Singapore etc.

\n\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/offensive-cyber-security-operations-mastering-breach-and-adversarial-attack-simulation-engagements-abhijith-abx-dctlv2026
\n\'',NULL,1295785),('6_Tuesday','09','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_7c5ac18218b7d315855c3a93661fa201','\'\'',NULL,1295786),('6_Tuesday','10','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_7c5ac18218b7d315855c3a93661fa201','\'\'',NULL,1295787),('6_Tuesday','11','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_7c5ac18218b7d315855c3a93661fa201','\'\'',NULL,1295788),('6_Tuesday','12','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_7c5ac18218b7d315855c3a93661fa201','\'\'',NULL,1295789),('6_Tuesday','13','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_7c5ac18218b7d315855c3a93661fa201','\'\'',NULL,1295790),('6_Tuesday','14','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_7c5ac18218b7d315855c3a93661fa201','\'\'',NULL,1295791),('6_Tuesday','15','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_7c5ac18218b7d315855c3a93661fa201','\'\'',NULL,1295792),('6_Tuesday','16','08:30','16:59','Y','DEF CON Training','LVCCW Level 2 W214 Blue Team Village Main Room ( CTF,The Nook & Mental Health Hackers )','\'Offensive Cyber Security Operations: Mastering Breach and Adversarial Attack Simulation Engagements\'','\'Abhijith \"Abx\" B R\'','DEF CON Training_7c5ac18218b7d315855c3a93661fa201','\'\'',NULL,1295793),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'Title: Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Madhu Akula
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/securing-the-future-defending-kubernetes-cloud-native-infrastructure-in-the-age-of-ai-madhu-akula-dctlv2026
\n\'',NULL,1295794),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'\'',NULL,1295795),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'\'',NULL,1295796),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'\'',NULL,1295797),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'\'',NULL,1295798),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'\'',NULL,1295799),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'\'',NULL,1295800),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'\'',NULL,1295801),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'\'',NULL,1295802),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_b71f78a2b9384d451e00c58684304a00','\'\'',NULL,1295803),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'Title: Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Madhu Akula
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/securing-the-future-defending-kubernetes-cloud-native-infrastructure-in-the-age-of-ai-madhu-akula-dctlv2026
\n\'',NULL,1295804),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'\'',NULL,1295805),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'\'',NULL,1295806),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'\'',NULL,1295807),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'\'',NULL,1295808),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'\'',NULL,1295809),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'\'',NULL,1295810),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'\'',NULL,1295811),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'\'',NULL,1295812),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W209 (Diana Initiative)','\'Securing the Future: Defending Kubernetes & Cloud-Native Infrastructure in the Age of AI\'','\'Madhu Akula\'','DEF CON Training_1bb93d9116f275ef9f7ff854423d5eeb','\'\'',NULL,1295813),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'Title: Simulated Adversary: Tactics & Tools Training
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W205 (Payment Village) - Map
\n
\nDescription:
\n\n\nSpeakers:Jayson E. Street,Iain Jackson,James Sheppard
\n
\nSpeakerBio:  Jayson E. Street, CovertSwarm
\nNo BIO available
\nSpeakerBio:  Iain Jackson, CovertSwarm
\nNo BIO available
\nSpeakerBio:  James Sheppard, CovertSwarm
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/simulated-adversary-tactics-tools-training-jayson-e-street-dctlv2026
\n\'',NULL,1295814),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'\'',NULL,1295815),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'\'',NULL,1295816),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'\'',NULL,1295817),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'\'',NULL,1295818),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'\'',NULL,1295819),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'\'',NULL,1295820),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'\'',NULL,1295821),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'\'',NULL,1295822),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_72ef9c72cba69a5b4fdc8cb052379663','\'\'',NULL,1295823),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'Title: Simulated Adversary: Tactics & Tools Training
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W205 (Payment Village) - Map
\n
\nDescription:
\n\n\nSpeakers:Jayson E. Street,Iain Jackson,James Sheppard
\n
\nSpeakerBio:  Jayson E. Street, CovertSwarm
\nNo BIO available
\nSpeakerBio:  Iain Jackson, CovertSwarm
\nNo BIO available
\nSpeakerBio:  James Sheppard, CovertSwarm
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/simulated-adversary-tactics-tools-training-jayson-e-street-dctlv2026
\n\'',NULL,1295824),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'\'',NULL,1295825),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'\'',NULL,1295826),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'\'',NULL,1295827),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'\'',NULL,1295828),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'\'',NULL,1295829),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'\'',NULL,1295830),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'\'',NULL,1295831),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'\'',NULL,1295832),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W205 (Payment Village)','\'Simulated Adversary: Tactics & Tools Training\'','\'Jayson E. Street,Iain Jackson,James Sheppard\'','DEF CON Training_7d1312dc469389fffb1c6f1e0ba40f17','\'\'',NULL,1295833),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'Title: Software Defined Radios 101 - Introduction to RF Hacking
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 3 W314 (Ham Radio Meeting) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Richard Shmel
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/software-defined-radios-101-introduction-to-rf-hacking-richard-shmel-dctlv2026
\n\'',NULL,1295834),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'\'',NULL,1295835),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'\'',NULL,1295836),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'\'',NULL,1295837),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'\'',NULL,1295838),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'\'',NULL,1295839),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'\'',NULL,1295840),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'\'',NULL,1295841),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'\'',NULL,1295842),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_7f02effcbae8e58d32c44038e84941c6','\'\'',NULL,1295843),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'Title: Software Defined Radios 101 - Introduction to RF Hacking
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 3 W314 (Ham Radio Meeting) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Richard Shmel
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/software-defined-radios-101-introduction-to-rf-hacking-richard-shmel-dctlv2026
\n\'',NULL,1295844),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'\'',NULL,1295845),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'\'',NULL,1295846),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'\'',NULL,1295847),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'\'',NULL,1295848),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'\'',NULL,1295849),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'\'',NULL,1295850),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'\'',NULL,1295851),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'\'',NULL,1295852),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 3 W314 (Ham Radio Meeting)','\'Software Defined Radios 101 - Introduction to RF Hacking\'','\'Richard Shmel\'','DEF CON Training_a7c0ac09b9d03a42110104bb2d68df6b','\'\'',NULL,1295853),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'Title: Solving Modern Cybersecurity Problems with AI
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W225 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Michael Glass
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/solving-modern-cybersecurity-problems-with-ai-michael-glass-dctlv2026
\n\'',NULL,1295854),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'\'',NULL,1295855),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'\'',NULL,1295856),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'\'',NULL,1295857),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'\'',NULL,1295858),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'\'',NULL,1295859),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'\'',NULL,1295860),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'\'',NULL,1295861),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'\'',NULL,1295862),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_0949820fd7be552416e0e40cf4fdc78b','\'\'',NULL,1295863),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'Title: Solving Modern Cybersecurity Problems with AI
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W225 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Michael Glass
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/solving-modern-cybersecurity-problems-with-ai-michael-glass-dctlv2026
\n\'',NULL,1295864),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'\'',NULL,1295865),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'\'',NULL,1295866),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'\'',NULL,1295867),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'\'',NULL,1295868),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'\'',NULL,1295869),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'\'',NULL,1295870),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'\'',NULL,1295871),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'\'',NULL,1295872),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W225 (Workshops)','\'Solving Modern Cybersecurity Problems with AI\'','\'Michael Glass\'','DEF CON Training_de21557214ae0223c3506870fa2d36ea','\'\'',NULL,1295873),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'Title: Strategic AI Penetration: Mastering Offensive Techniques for LLMs
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W233 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakers:Marek Zmysłowski,Konrad Jędrzejczyk
\n
\nSpeakerBio:  Marek Zmysłowski
\nNo BIO available
\nSpeakerBio:  Konrad Jędrzejczyk
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/strategic-ai-penetration-mastering-offensive-techniques-for-llms-marek-zmyslowski-konrad-jedrzejczyk-dclv2026
\n\'',NULL,1295874),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'\'',NULL,1295875),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'\'',NULL,1295876),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'\'',NULL,1295877),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'\'',NULL,1295878),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'\'',NULL,1295879),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'\'',NULL,1295880),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'\'',NULL,1295881),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'\'',NULL,1295882),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_3e50e19efbe1efd28127c54737df978e','\'\'',NULL,1295883),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'Title: Strategic AI Penetration: Mastering Offensive Techniques for LLMs
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W233 (Workshops) - Map
\n
\nDescription:
\n\n\nSpeakers:Marek Zmysłowski,Konrad Jędrzejczyk
\n
\nSpeakerBio:  Marek Zmysłowski
\nNo BIO available
\nSpeakerBio:  Konrad Jędrzejczyk
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026/products/strategic-ai-penetration-mastering-offensive-techniques-for-llms-marek-zmyslowski-konrad-jedrzejczyk-dclv2026
\n\'',NULL,1295884),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'\'',NULL,1295885),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'\'',NULL,1295886),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'\'',NULL,1295887),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'\'',NULL,1295888),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'\'',NULL,1295889),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'\'',NULL,1295890),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'\'',NULL,1295891),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'\'',NULL,1295892),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W233 (Workshops)','\'Strategic AI Penetration: Mastering Offensive Techniques for LLMs\'','\'Marek Zmysłowski,Konrad Jędrzejczyk\'','DEF CON Training_09e68998b13b187addc0ca13db461da4','\'\'',NULL,1295893),('6_Tuesday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'Title: VS: S-RAD (Satellite-Radio Analysis & Disruption)
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Tuesday, Aug 11, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W201 (HDA Community) - Map
\n
\nDescription:
\n\n\nSpeakers:Andrzej Olchawa,Ricardo Fradique,André Cirne
\n
\nSpeakerBio:  Andrzej Olchawa
\nNo BIO available
\nSpeakerBio:  Ricardo Fradique
\nNo BIO available
\nSpeakerBio:  André Cirne
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026#:~:text=VS%3A%20S%2DRAD,%242%2C500.00
\n\'',NULL,1295894),('6_Tuesday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'\'',NULL,1295895),('6_Tuesday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'\'',NULL,1295896),('6_Tuesday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'\'',NULL,1295897),('6_Tuesday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'\'',NULL,1295898),('6_Tuesday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'\'',NULL,1295899),('6_Tuesday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'\'',NULL,1295900),('6_Tuesday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'\'',NULL,1295901),('6_Tuesday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'\'',NULL,1295902),('6_Tuesday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_d5fb588542f3d5f9697eec1850fffd6b','\'\'',NULL,1295903),('5_Monday','08','08:30','17:30','N','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'Title: VS: S-RAD (Satellite-Radio Analysis & Disruption)
\nTags: DEF CON Training (Paid) (2-day) | DEF CON Training
\nWhen: Monday, Aug 10, 08:30 - 17:30 PDT
\nWhere: LVCCW Level 2 W201 (HDA Community) - Map
\n
\nDescription:
\n\n\nSpeakers:Andrzej Olchawa,Ricardo Fradique,André Cirne
\n
\nSpeakerBio:  Andrzej Olchawa
\nNo BIO available
\nSpeakerBio:  Ricardo Fradique
\nNo BIO available
\nSpeakerBio:  André Cirne
\nNo BIO available
\n\nLinks:
    More Info - https://training.defcon.org/collections/def-con-training-las-vegas-2026#:~:text=VS%3A%20S%2DRAD,%242%2C500.00
\n\'',NULL,1295904),('5_Monday','09','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'\'',NULL,1295905),('5_Monday','10','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'\'',NULL,1295906),('5_Monday','11','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'\'',NULL,1295907),('5_Monday','12','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'\'',NULL,1295908),('5_Monday','13','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'\'',NULL,1295909),('5_Monday','14','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'\'',NULL,1295910),('5_Monday','15','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'\'',NULL,1295911),('5_Monday','16','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'\'',NULL,1295912),('5_Monday','17','08:30','17:30','Y','DEF CON Training','LVCCW Level 2 W201 (HDA Community)','\'VS: S-RAD (Satellite-Radio Analysis & Disruption)\'','\'Andrzej Olchawa,Ricardo Fradique,André Cirne\'','DEF CON Training_cf881e46a7d70ab31a7aa58f1159c17b','\'\'',NULL,1295913),('2_Friday','10','10:00','10:30','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Opening Remarks\'','\'\'','Creator Talks_360bd1f9bc2cc36b77379c3b3e91e039','\'Title: AI Village: Opening Remarks
\nTags: AI Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1295914),('4_Sunday','12','12:30','12:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Closing Remarks\'','\'\'','Creator Talks_8be8b724d519877952229f0e1f99cd7c','\'Title: AI Village: Closing Remarks
\nTags: AI Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1295915),('4_Sunday','10','10:00','13:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_0ddccbfcb3166cfd6143a13198b6ad48','\'Title: AI Village: Village Open
\nTags: AI Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

We’re bringing AI Village back to focus on what actually matters: practical, no-bullshit AI security. LLMs are an amazing technology, but they’re not magic. We are stripping away the industry hype and focusing on hands-on skills, whether you are building your first exploit or leading an AI red team.

\n\n

Here is what you can expect this year:

\n\n

Drop-In Workshops: Walk up, grab a seat, and learn. We have drop in hands on mini-workshops on a bunch of topics. These include basic AI topics like how LLMs actually work, and how to build agents from scratch. For red teamers we have ones ranging from prompt injection to manipulating malware detection models. This is all running locally on a cluster we’re bringing to DEF CON.

\n\n

HalCTF: Our main competition this year will teach you how to write and fine-tune your own pentesting agent using open-source models. To handle the massive compute load, we\'re safely detonating these agents on GCP, giving each participant a dedicated GPU for their models.

\n\n

Other Agent Shenanigans: The field moves fast and there’s going to be something new by defcon. We’re bringing a lot of compute to host things and we’ll have some surprises in the space.

\n\n

Whether you want to hear top-tier research from the people actually breaking these models or you just want to sit down and write an autonomous pentesting agent, we have the hardware and the labs ready for you.

\n\n\'',NULL,1295916),('4_Sunday','11','10:00','13:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_0ddccbfcb3166cfd6143a13198b6ad48','\'\'',NULL,1295917),('4_Sunday','12','10:00','13:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_0ddccbfcb3166cfd6143a13198b6ad48','\'\'',NULL,1295918),('4_Sunday','13','10:00','13:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_0ddccbfcb3166cfd6143a13198b6ad48','\'\'',NULL,1295919),('3_Saturday','10','10:00','17:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_800b4114deda4e89702b9931146005bf','\'Title: AI Village: Village Open
\nTags: AI Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

We’re bringing AI Village back to focus on what actually matters: practical, no-bullshit AI security. LLMs are an amazing technology, but they’re not magic. We are stripping away the industry hype and focusing on hands-on skills, whether you are building your first exploit or leading an AI red team.

\n\n

Here is what you can expect this year:

\n\n

Drop-In Workshops: Walk up, grab a seat, and learn. We have drop in hands on mini-workshops on a bunch of topics. These include basic AI topics like how LLMs actually work, and how to build agents from scratch. For red teamers we have ones ranging from prompt injection to manipulating malware detection models. This is all running locally on a cluster we’re bringing to DEF CON.

\n\n

HalCTF: Our main competition this year will teach you how to write and fine-tune your own pentesting agent using open-source models. To handle the massive compute load, we\'re safely detonating these agents on GCP, giving each participant a dedicated GPU for their models.

\n\n

Other Agent Shenanigans: The field moves fast and there’s going to be something new by defcon. We’re bringing a lot of compute to host things and we’ll have some surprises in the space.

\n\n

Whether you want to hear top-tier research from the people actually breaking these models or you just want to sit down and write an autonomous pentesting agent, we have the hardware and the labs ready for you.

\n\n\'',NULL,1295920),('3_Saturday','11','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_800b4114deda4e89702b9931146005bf','\'\'',NULL,1295921),('3_Saturday','12','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_800b4114deda4e89702b9931146005bf','\'\'',NULL,1295922),('3_Saturday','13','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_800b4114deda4e89702b9931146005bf','\'\'',NULL,1295923),('3_Saturday','14','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_800b4114deda4e89702b9931146005bf','\'\'',NULL,1295924),('3_Saturday','15','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_800b4114deda4e89702b9931146005bf','\'\'',NULL,1295925),('3_Saturday','16','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_800b4114deda4e89702b9931146005bf','\'\'',NULL,1295926),('3_Saturday','17','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_800b4114deda4e89702b9931146005bf','\'\'',NULL,1295927),('2_Friday','10','10:00','17:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_a247da857fc736158cd619a1d39c313a','\'Title: AI Village: Village Open
\nTags: AI Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

We’re bringing AI Village back to focus on what actually matters: practical, no-bullshit AI security. LLMs are an amazing technology, but they’re not magic. We are stripping away the industry hype and focusing on hands-on skills, whether you are building your first exploit or leading an AI red team.

\n\n

Here is what you can expect this year:

\n\n

Drop-In Workshops: Walk up, grab a seat, and learn. We have drop in hands on mini-workshops on a bunch of topics. These include basic AI topics like how LLMs actually work, and how to build agents from scratch. For red teamers we have ones ranging from prompt injection to manipulating malware detection models. This is all running locally on a cluster we’re bringing to DEF CON.

\n\n

HalCTF: Our main competition this year will teach you how to write and fine-tune your own pentesting agent using open-source models. To handle the massive compute load, we\'re safely detonating these agents on GCP, giving each participant a dedicated GPU for their models.

\n\n

Other Agent Shenanigans: The field moves fast and there’s going to be something new by defcon. We’re bringing a lot of compute to host things and we’ll have some surprises in the space.

\n\n

Whether you want to hear top-tier research from the people actually breaking these models or you just want to sit down and write an autonomous pentesting agent, we have the hardware and the labs ready for you.

\n\n\'',NULL,1295928),('2_Friday','11','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_a247da857fc736158cd619a1d39c313a','\'\'',NULL,1295929),('2_Friday','12','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_a247da857fc736158cd619a1d39c313a','\'\'',NULL,1295930),('2_Friday','13','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_a247da857fc736158cd619a1d39c313a','\'\'',NULL,1295931),('2_Friday','14','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_a247da857fc736158cd619a1d39c313a','\'\'',NULL,1295932),('2_Friday','15','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_a247da857fc736158cd619a1d39c313a','\'\'',NULL,1295933),('2_Friday','16','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_a247da857fc736158cd619a1d39c313a','\'\'',NULL,1295934),('2_Friday','17','10:00','17:59','Y','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'AI Village: Village Open\'','\'\'','Creator Events_a247da857fc736158cd619a1d39c313a','\'\'',NULL,1295935),('0_Wednesday','17','17:00','07:59','N','Social Gatherings/Events','LVCC West Hall','\'Linecon\'','\'\'','Social Gatherings/Events_e2cd421bb289711ef150cac33d414824','\'Title: Linecon
\nTags: Misc
\nWhen: Wednesday, Aug 5, 17:00 - 07:59 PDT
\nWhere: LVCC West Hall
\n
\nDescription:
\n

Linecon is your optional opportunity to stand (or sit) in line for human registration to open. Doors will open for linecon on Wednesday at approximately 17:00. When human registration opens on Thursday at approximately 08:00, they start working the linecon queue, and the line will start moving quickly. (Please understand that we will begin processing the line on Thursday morning as soon as the cashiers and materials are in place; we will strive for Thursday 08:00, but actual start may be slightly earlier or later.)

\n\n

Online badge purchase (aka pre-registration) has no impact on linecon. You can join the line on Wednesday (if you wish) regardless of whether you purchased a badge online or intend to pay with cash. There is only one linecon for both types of badge sales.

\n\n

Please help us make this a great experience for everyone by following directions given by goons. After human registration opens, there may be one line for all of registration, or there may be two lines (one for online sales (pre-registration) and one for cash sales). This may also change over time, based on available staffing and necessary crowd control. We will strive to make it easily understandable in-person as to which line you should join.

\n\n

Please also review the \"Human Registration Open\" event, and familiarize yourself with the important notes therein.

\n\n\'',NULL,1295936),('2_Friday','08','08:00','18:59','N','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'Title: Human Registration Open
\nTags: Misc
\nWhen: Friday, Aug 7, 08:00 - 18:59 PDT
\nWhere: LVCC West Hall
\n
\nDescription:
\n

Update 2026-08-06 16:00

\n\n

Human Registration has moved to the Southwest Lobby. If you look at the maps available in Hacker Tracker, it\'s at the lower-left corner of the map, and labeled \"Registration\".

\n\n

Human Registration

\n\n

Our human registration process this year will be very similar to previous years. Please be patient. All of the times listed here are approximate.

\n\n

Basics

\n\n

Who needs a badge?

\n\n

A badge is required for each human age 8 and older.

\n\n

Human?

\n\n

You are a human if you do not know otherwise. People that are not humans include goons, official speaker, village/community/contest/creator staff, press, black badge holders, or similar. If you are not a human, you need to register separately. If you don\'t know how, see an NFO goon (NFO Node, formerly known as an infobooth, is where you can get help). The remainder of this message applies only to humans.

\n\n

Lines? Linecon?

\n\n

Linecon is your optional opportunity to stand (or sit) in line for human registration to open. Doors will open for linecon on Wednesday at approximately 17:00. When human registration opens on Thursday at approximately 08:00, they start working the linecon queue, and the line will start moving quickly. (Please understand that we will begin processing the line on Thursday morning as soon as the cashiers and materials are in place; we will strive for Thursday 08:00, but actual start may be slightly earlier or later.)

\n\n

Online badge purchase (aka pre-registration) has no impact on linecon. You can join the line on Wednesday (if you wish) regardless of whether you purchased a badge online or intend to pay with cash. There is only one linecon for both types of badge sales.

\n\n

Please help us make this a great experience for everyone by following directions given by goons. After human registration opens, there may be one line for all of registration, or there may be two lines (one for online sales (pre-registration) and one for cash sales). This may also change over time, based on available staffing and necessary crowd control. We will strive to make it easily understandable in-person as to which line you should join.

\n\n

Ways to buy a badge

\n\n
    \n
  • $560-600 online purchase until August 1, 2026. Tickets are transferable. Please read the details on the linked page.
  • \n
  • $520 cash purchase on-site.
  • \n
  • As part of a BlackHat registration.
  • \n
\n\n

Online Purchase

\n\n

You will be emailed a QR code to the email address provided when you bought your badge. Please guard that QR code as though it is cash -- it can only be redeemed once, and anyone can redeem it if they have it (including a photo of it). Badges are picked-up on-site -- they will not be mailed or shipped.

\n\n

We can scan the QR code either from your phone\'s display or from a printed copy. You must have the QR code with you in order to obtain your badge. As you approach the front of the line, if you are going to show your QR code on an electronic device, please ensure that your display is set to maximum brightness.

\n\n

If you pre-registered, but ultimately are unable to attend DEF CON and want to cancel your purchase, the only way to get a refund is from the original online source. We are unable to provide any refunds on-site at DEF CON. There is a fee to have your badge canceled: $34 before July 18, and $84 on and after July 18.

\n\n

Online purchases are provided a receipt via email when the purchase is made.

\n\n

Online purchase -- often referred to as pre-registration -- does not allow you to skip any line/queue to pick up your badge. Once you arrive on-site, you will need to join the existing line for human registration. There may or may not be a dedicated line for pre-registration badge pickup, depending on when you arrive, how long the line is, available staff, etc.

\n\n

Cash Purchase

\n\n

Badges will be available for purchase on-site at DEF CON. All badge sales are cash only. No checks, money orders, credit cards, etc., will be accepted. In order to keep the registration line moving as quickly as possible, please have exact change ready as you near the front of the line.

\n\n

There are no refunds given for cash sales. If you have any doubt about your desire to buy a badge, please refrain from doing so.

\n\n

We are unable to provide printed receipts at the time of the sale. A generic receipt for the cash sale of a badge will be made available on media.defcon.org after the conference. You are welcome to print your own copy of the receipt on plain paper.

\n\n

Via BlackHat

\n\n

If you\'ve purchased a DEF CON badge as part of your Black Hat registration, you\'re in luck - you will be able to pick up your DEF CON badge at Black Hat on Thursday. Please bring your Black Hat badge and watch for emails from Black Hat about where exactly the badge pickup will be.

\n\n

Please note that DEF CON is not able to access or verify Black Hat registration or attendee info. DEF CON\'s preregistration list is not the same as Black Hat\'s. For help, ask at Black Hat registration or the concierge area.

\n\n

Misc

\n\n

Want to buy multiple badges? No problem! We\'re happy to sell you however many badges you want to pay for.

\n\n

If you lose your badge, there is unfortunately no way for us to replace it. You\'ll have to buy a replacement at full price. Please don\'t lose your badge. :(

\n\n

If you are being accompanied by a full-time caretaker (such as someone who will push your wheelchair, and will accompany you at all times), please ask to speak to a Registration Goon. Your caretaker will receive a paper badge that will permit them to accompany you everywhere you go.

\n\n

Still need help?

\n\n

If you have questions about anything regarding human registration that are not addressed here, please ask to speak to a Registration Goon.

\n\n\'',NULL,1295937),('2_Friday','09','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295938),('2_Friday','10','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295939),('2_Friday','11','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295940),('2_Friday','12','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295941),('2_Friday','13','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295942),('2_Friday','14','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295943),('2_Friday','15','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295944),('2_Friday','16','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295945),('2_Friday','17','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295946),('2_Friday','18','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_f3705203394c168f27c5c8ee1e4fd8b9','\'\'',NULL,1295947),('1_Thursday','08','08:00','18:59','N','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'Title: Human Registration Open
\nTags: Misc
\nWhen: Thursday, Aug 6, 08:00 - 18:59 PDT
\nWhere: LVCC West Hall
\n
\nDescription:
\n

Update 2026-08-06 16:00

\n\n

Human Registration has moved to the Southwest Lobby. If you look at the maps available in Hacker Tracker, it\'s at the lower-left corner of the map, and labeled \"Registration\".

\n\n

Human Registration

\n\n

Our human registration process this year will be very similar to previous years. Please be patient. All of the times listed here are approximate.

\n\n

Basics

\n\n

Who needs a badge?

\n\n

A badge is required for each human age 8 and older.

\n\n

Human?

\n\n

You are a human if you do not know otherwise. People that are not humans include goons, official speaker, village/community/contest/creator staff, press, black badge holders, or similar. If you are not a human, you need to register separately. If you don\'t know how, see an NFO goon (NFO Node, formerly known as an infobooth, is where you can get help). The remainder of this message applies only to humans.

\n\n

Lines? Linecon?

\n\n

Linecon is your optional opportunity to stand (or sit) in line for human registration to open. Doors will open for linecon on Wednesday at approximately 17:00. When human registration opens on Thursday at approximately 08:00, they start working the linecon queue, and the line will start moving quickly. (Please understand that we will begin processing the line on Thursday morning as soon as the cashiers and materials are in place; we will strive for Thursday 08:00, but actual start may be slightly earlier or later.)

\n\n

Online badge purchase (aka pre-registration) has no impact on linecon. You can join the line on Wednesday (if you wish) regardless of whether you purchased a badge online or intend to pay with cash. There is only one linecon for both types of badge sales.

\n\n

Please help us make this a great experience for everyone by following directions given by goons. After human registration opens, there may be one line for all of registration, or there may be two lines (one for online sales (pre-registration) and one for cash sales). This may also change over time, based on available staffing and necessary crowd control. We will strive to make it easily understandable in-person as to which line you should join.

\n\n

Ways to buy a badge

\n\n
    \n
  • $560-600 online purchase until August 1, 2026. Tickets are transferable. Please read the details on the linked page.
  • \n
  • $520 cash purchase on-site.
  • \n
  • As part of a BlackHat registration.
  • \n
\n\n

Online Purchase

\n\n

You will be emailed a QR code to the email address provided when you bought your badge. Please guard that QR code as though it is cash -- it can only be redeemed once, and anyone can redeem it if they have it (including a photo of it). Badges are picked-up on-site -- they will not be mailed or shipped.

\n\n

We can scan the QR code either from your phone\'s display or from a printed copy. You must have the QR code with you in order to obtain your badge. As you approach the front of the line, if you are going to show your QR code on an electronic device, please ensure that your display is set to maximum brightness.

\n\n

If you pre-registered, but ultimately are unable to attend DEF CON and want to cancel your purchase, the only way to get a refund is from the original online source. We are unable to provide any refunds on-site at DEF CON. There is a fee to have your badge canceled: $34 before July 18, and $84 on and after July 18.

\n\n

Online purchases are provided a receipt via email when the purchase is made.

\n\n

Online purchase -- often referred to as pre-registration -- does not allow you to skip any line/queue to pick up your badge. Once you arrive on-site, you will need to join the existing line for human registration. There may or may not be a dedicated line for pre-registration badge pickup, depending on when you arrive, how long the line is, available staff, etc.

\n\n

Cash Purchase

\n\n

Badges will be available for purchase on-site at DEF CON. All badge sales are cash only. No checks, money orders, credit cards, etc., will be accepted. In order to keep the registration line moving as quickly as possible, please have exact change ready as you near the front of the line.

\n\n

There are no refunds given for cash sales. If you have any doubt about your desire to buy a badge, please refrain from doing so.

\n\n

We are unable to provide printed receipts at the time of the sale. A generic receipt for the cash sale of a badge will be made available on media.defcon.org after the conference. You are welcome to print your own copy of the receipt on plain paper.

\n\n

Via BlackHat

\n\n

If you\'ve purchased a DEF CON badge as part of your Black Hat registration, you\'re in luck - you will be able to pick up your DEF CON badge at Black Hat on Thursday. Please bring your Black Hat badge and watch for emails from Black Hat about where exactly the badge pickup will be.

\n\n

Please note that DEF CON is not able to access or verify Black Hat registration or attendee info. DEF CON\'s preregistration list is not the same as Black Hat\'s. For help, ask at Black Hat registration or the concierge area.

\n\n

Misc

\n\n

Want to buy multiple badges? No problem! We\'re happy to sell you however many badges you want to pay for.

\n\n

If you lose your badge, there is unfortunately no way for us to replace it. You\'ll have to buy a replacement at full price. Please don\'t lose your badge. :(

\n\n

If you are being accompanied by a full-time caretaker (such as someone who will push your wheelchair, and will accompany you at all times), please ask to speak to a Registration Goon. Your caretaker will receive a paper badge that will permit them to accompany you everywhere you go.

\n\n

Still need help?

\n\n

If you have questions about anything regarding human registration that are not addressed here, please ask to speak to a Registration Goon.

\n\n\'',NULL,1295948),('1_Thursday','09','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295949),('1_Thursday','10','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295950),('1_Thursday','11','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295951),('1_Thursday','12','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295952),('1_Thursday','13','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295953),('1_Thursday','14','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295954),('1_Thursday','15','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295955),('1_Thursday','16','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295956),('1_Thursday','17','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295957),('1_Thursday','18','08:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_df3e547680d66c856f8f9a4b93fb758a','\'\'',NULL,1295958),('4_Sunday','09','09:00','11:59','N','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_8c0c71e1e92356d6200cdbb0894ab841','\'Title: Human Registration Open
\nTags: Misc
\nWhen: Sunday, Aug 9, 09:00 - 11:59 PDT
\nWhere: LVCC West Hall
\n
\nDescription:
\n

Update 2026-08-06 16:00

\n\n

Human Registration has moved to the Southwest Lobby. If you look at the maps available in Hacker Tracker, it\'s at the lower-left corner of the map, and labeled \"Registration\".

\n\n

Human Registration

\n\n

Our human registration process this year will be very similar to previous years. Please be patient. All of the times listed here are approximate.

\n\n

Basics

\n\n

Who needs a badge?

\n\n

A badge is required for each human age 8 and older.

\n\n

Human?

\n\n

You are a human if you do not know otherwise. People that are not humans include goons, official speaker, village/community/contest/creator staff, press, black badge holders, or similar. If you are not a human, you need to register separately. If you don\'t know how, see an NFO goon (NFO Node, formerly known as an infobooth, is where you can get help). The remainder of this message applies only to humans.

\n\n

Lines? Linecon?

\n\n

Linecon is your optional opportunity to stand (or sit) in line for human registration to open. Doors will open for linecon on Wednesday at approximately 17:00. When human registration opens on Thursday at approximately 08:00, they start working the linecon queue, and the line will start moving quickly. (Please understand that we will begin processing the line on Thursday morning as soon as the cashiers and materials are in place; we will strive for Thursday 08:00, but actual start may be slightly earlier or later.)

\n\n

Online badge purchase (aka pre-registration) has no impact on linecon. You can join the line on Wednesday (if you wish) regardless of whether you purchased a badge online or intend to pay with cash. There is only one linecon for both types of badge sales.

\n\n

Please help us make this a great experience for everyone by following directions given by goons. After human registration opens, there may be one line for all of registration, or there may be two lines (one for online sales (pre-registration) and one for cash sales). This may also change over time, based on available staffing and necessary crowd control. We will strive to make it easily understandable in-person as to which line you should join.

\n\n

Ways to buy a badge

\n\n
    \n
  • $560-600 online purchase until August 1, 2026. Tickets are transferable. Please read the details on the linked page.
  • \n
  • $520 cash purchase on-site.
  • \n
  • As part of a BlackHat registration.
  • \n
\n\n

Online Purchase

\n\n

You will be emailed a QR code to the email address provided when you bought your badge. Please guard that QR code as though it is cash -- it can only be redeemed once, and anyone can redeem it if they have it (including a photo of it). Badges are picked-up on-site -- they will not be mailed or shipped.

\n\n

We can scan the QR code either from your phone\'s display or from a printed copy. You must have the QR code with you in order to obtain your badge. As you approach the front of the line, if you are going to show your QR code on an electronic device, please ensure that your display is set to maximum brightness.

\n\n

If you pre-registered, but ultimately are unable to attend DEF CON and want to cancel your purchase, the only way to get a refund is from the original online source. We are unable to provide any refunds on-site at DEF CON. There is a fee to have your badge canceled: $34 before July 18, and $84 on and after July 18.

\n\n

Online purchases are provided a receipt via email when the purchase is made.

\n\n

Online purchase -- often referred to as pre-registration -- does not allow you to skip any line/queue to pick up your badge. Once you arrive on-site, you will need to join the existing line for human registration. There may or may not be a dedicated line for pre-registration badge pickup, depending on when you arrive, how long the line is, available staff, etc.

\n\n

Cash Purchase

\n\n

Badges will be available for purchase on-site at DEF CON. All badge sales are cash only. No checks, money orders, credit cards, etc., will be accepted. In order to keep the registration line moving as quickly as possible, please have exact change ready as you near the front of the line.

\n\n

There are no refunds given for cash sales. If you have any doubt about your desire to buy a badge, please refrain from doing so.

\n\n

We are unable to provide printed receipts at the time of the sale. A generic receipt for the cash sale of a badge will be made available on media.defcon.org after the conference. You are welcome to print your own copy of the receipt on plain paper.

\n\n

Via BlackHat

\n\n

If you\'ve purchased a DEF CON badge as part of your Black Hat registration, you\'re in luck - you will be able to pick up your DEF CON badge at Black Hat on Thursday. Please bring your Black Hat badge and watch for emails from Black Hat about where exactly the badge pickup will be.

\n\n

Please note that DEF CON is not able to access or verify Black Hat registration or attendee info. DEF CON\'s preregistration list is not the same as Black Hat\'s. For help, ask at Black Hat registration or the concierge area.

\n\n

Misc

\n\n

Want to buy multiple badges? No problem! We\'re happy to sell you however many badges you want to pay for.

\n\n

If you lose your badge, there is unfortunately no way for us to replace it. You\'ll have to buy a replacement at full price. Please don\'t lose your badge. :(

\n\n

If you are being accompanied by a full-time caretaker (such as someone who will push your wheelchair, and will accompany you at all times), please ask to speak to a Registration Goon. Your caretaker will receive a paper badge that will permit them to accompany you everywhere you go.

\n\n

Still need help?

\n\n

If you have questions about anything regarding human registration that are not addressed here, please ask to speak to a Registration Goon.

\n\n\'',NULL,1295959),('4_Sunday','10','09:00','11:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_8c0c71e1e92356d6200cdbb0894ab841','\'\'',NULL,1295960),('4_Sunday','11','09:00','11:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_8c0c71e1e92356d6200cdbb0894ab841','\'\'',NULL,1295961),('3_Saturday','09','09:00','18:59','N','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'Title: Human Registration Open
\nTags: Misc
\nWhen: Saturday, Aug 8, 09:00 - 18:59 PDT
\nWhere: LVCC West Hall
\n
\nDescription:
\n

Update 2026-08-06 16:00

\n\n

Human Registration has moved to the Southwest Lobby. If you look at the maps available in Hacker Tracker, it\'s at the lower-left corner of the map, and labeled \"Registration\".

\n\n

Human Registration

\n\n

Our human registration process this year will be very similar to previous years. Please be patient. All of the times listed here are approximate.

\n\n

Basics

\n\n

Who needs a badge?

\n\n

A badge is required for each human age 8 and older.

\n\n

Human?

\n\n

You are a human if you do not know otherwise. People that are not humans include goons, official speaker, village/community/contest/creator staff, press, black badge holders, or similar. If you are not a human, you need to register separately. If you don\'t know how, see an NFO goon (NFO Node, formerly known as an infobooth, is where you can get help). The remainder of this message applies only to humans.

\n\n

Lines? Linecon?

\n\n

Linecon is your optional opportunity to stand (or sit) in line for human registration to open. Doors will open for linecon on Wednesday at approximately 17:00. When human registration opens on Thursday at approximately 08:00, they start working the linecon queue, and the line will start moving quickly. (Please understand that we will begin processing the line on Thursday morning as soon as the cashiers and materials are in place; we will strive for Thursday 08:00, but actual start may be slightly earlier or later.)

\n\n

Online badge purchase (aka pre-registration) has no impact on linecon. You can join the line on Wednesday (if you wish) regardless of whether you purchased a badge online or intend to pay with cash. There is only one linecon for both types of badge sales.

\n\n

Please help us make this a great experience for everyone by following directions given by goons. After human registration opens, there may be one line for all of registration, or there may be two lines (one for online sales (pre-registration) and one for cash sales). This may also change over time, based on available staffing and necessary crowd control. We will strive to make it easily understandable in-person as to which line you should join.

\n\n

Ways to buy a badge

\n\n
    \n
  • $560-600 online purchase until August 1, 2026. Tickets are transferable. Please read the details on the linked page.
  • \n
  • $520 cash purchase on-site.
  • \n
  • As part of a BlackHat registration.
  • \n
\n\n

Online Purchase

\n\n

You will be emailed a QR code to the email address provided when you bought your badge. Please guard that QR code as though it is cash -- it can only be redeemed once, and anyone can redeem it if they have it (including a photo of it). Badges are picked-up on-site -- they will not be mailed or shipped.

\n\n

We can scan the QR code either from your phone\'s display or from a printed copy. You must have the QR code with you in order to obtain your badge. As you approach the front of the line, if you are going to show your QR code on an electronic device, please ensure that your display is set to maximum brightness.

\n\n

If you pre-registered, but ultimately are unable to attend DEF CON and want to cancel your purchase, the only way to get a refund is from the original online source. We are unable to provide any refunds on-site at DEF CON. There is a fee to have your badge canceled: $34 before July 18, and $84 on and after July 18.

\n\n

Online purchases are provided a receipt via email when the purchase is made.

\n\n

Online purchase -- often referred to as pre-registration -- does not allow you to skip any line/queue to pick up your badge. Once you arrive on-site, you will need to join the existing line for human registration. There may or may not be a dedicated line for pre-registration badge pickup, depending on when you arrive, how long the line is, available staff, etc.

\n\n

Cash Purchase

\n\n

Badges will be available for purchase on-site at DEF CON. All badge sales are cash only. No checks, money orders, credit cards, etc., will be accepted. In order to keep the registration line moving as quickly as possible, please have exact change ready as you near the front of the line.

\n\n

There are no refunds given for cash sales. If you have any doubt about your desire to buy a badge, please refrain from doing so.

\n\n

We are unable to provide printed receipts at the time of the sale. A generic receipt for the cash sale of a badge will be made available on media.defcon.org after the conference. You are welcome to print your own copy of the receipt on plain paper.

\n\n

Via BlackHat

\n\n

If you\'ve purchased a DEF CON badge as part of your Black Hat registration, you\'re in luck - you will be able to pick up your DEF CON badge at Black Hat on Thursday. Please bring your Black Hat badge and watch for emails from Black Hat about where exactly the badge pickup will be.

\n\n

Please note that DEF CON is not able to access or verify Black Hat registration or attendee info. DEF CON\'s preregistration list is not the same as Black Hat\'s. For help, ask at Black Hat registration or the concierge area.

\n\n

Misc

\n\n

Want to buy multiple badges? No problem! We\'re happy to sell you however many badges you want to pay for.

\n\n

If you lose your badge, there is unfortunately no way for us to replace it. You\'ll have to buy a replacement at full price. Please don\'t lose your badge. :(

\n\n

If you are being accompanied by a full-time caretaker (such as someone who will push your wheelchair, and will accompany you at all times), please ask to speak to a Registration Goon. Your caretaker will receive a paper badge that will permit them to accompany you everywhere you go.

\n\n

Still need help?

\n\n

If you have questions about anything regarding human registration that are not addressed here, please ask to speak to a Registration Goon.

\n\n\'',NULL,1295962),('3_Saturday','10','09:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'\'',NULL,1295963),('3_Saturday','11','09:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'\'',NULL,1295964),('3_Saturday','12','09:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'\'',NULL,1295965),('3_Saturday','13','09:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'\'',NULL,1295966),('3_Saturday','14','09:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'\'',NULL,1295967),('3_Saturday','15','09:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'\'',NULL,1295968),('3_Saturday','16','09:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'\'',NULL,1295969),('3_Saturday','17','09:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'\'',NULL,1295970),('3_Saturday','18','09:00','18:59','Y','Social Gatherings/Events','LVCC West Hall','\'Human Registration Open\'','\'\'','Social Gatherings/Events_ea51c16525ef6f5110c0240138c982c4','\'\'',NULL,1295971),('2_Friday','08','08:00','17:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'Title: Merch (formerly swag) Area Open -- README
\nTags: Misc
\nWhen: Friday, Aug 7, 08:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1500 (MERCH) - Map
\n
\nDescription:
\n

The short version

\n\n
    \n
  • All sales are USD CASH ONLY. No cards of any type are accepted.
  • \n
  • All sales are final. There are no returns.
  • \n
  • You can add your selections to a list in HackerTracker, on your phone. We do not hold merchandise simply because you put it on your list in HackerTracker – that list stays on your device. We aren’t aware of it until we scan the QR code during order taking.
  • \n
  • We\'re open as many hours as we practically can be. Please refer to the conference schedule to see our latest hours. The published hours for the merch area are an approximation: supplies are limited, and when merch is sold out, the merch area will close for the year. (We intend to update this schedule to reflect their true operating status, but this is strictly best-effort.) Note that the closing hours here are when sales must have ended. For example, if sales must end by 18:00, and we estimate that it will take 2 hours to clear the queue, doors are likely to close around 16:00. Because of this dynamic nature, we can\'t predict the length of the line or when doors will be closed.
  • \n
\n\n

The slightly longer version:

\n\n

Similar to the last few years, HackerTracker will have artwork or photos of the merch for you to browse before you join the line -- you can decide ahead of time if you are interested in a product. HackerTracker is also showing stock status – if an item goes out of stock, that’ll be indicated in-app; this is on a best-effort basis, and some products move fast. You\'re able to make a wish list in Hacker Tracker, which expedites the ordering process at the front of the line (making everything faster and easier for everyone). If you don\'t want to use Hacker Tracker, you can have a merch goon create the order on your behalf.

\n\n

Tentative instructions

\n\n

Here’s the process, from beginning to end:

\n\n
    \n
  1. Browse the products, in-app. The list of products with associated artwork are expected to be published early the morning of August 6.
  2. \n
  3. When you find a product that you want to buy, make sure that you’ve selected the right variant/size, and then tap “Add to List”. Think of your list like a wish list.
  4. \n
  5. To view your list: If you’re using iOS, tap on the QR code at the top right. If you’re using Android, tap the “View List” button at the bottom.
  6. \n
  7. Your list shows everything you’ve added; if an item has gone out of stock since you added it, a warning will appear, and you’ll be required to remove the item from your list.
  8. \n
  9. When you near the front of the merch line, show the QR code at the top of your list to the order taker. They’ll scan it, and print a paper list. The list will have an order number on it, as well as your total amount due. The order taker can help answer any questions and help you modify your order if needed. If any items have sold out since they were added to your list, the order taker can help you find a replacement or remove it from your list.
  10. \n
  11. The paper list will be used to retrieve the merchandise from the warehouse. You will wait in a space that is after order taking but before checkout while your order is being picked. While you are waiting, please get your cash out. Exact change is preferred (it makes everything move faster), but change is available when required. If there are any issues picking your order, someone will help with you find alternatives or update your order.
  12. \n
  13. Once your merch is ready, a cashier will shout your order number, and/or hold up a sign with your order number written on it. Quickly make your way to the cashier, and complete the transaction.
  14. \n
  15. Enjoy!
  16. \n
\n\n\'',NULL,1295972),('2_Friday','09','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'\'',NULL,1295973),('2_Friday','10','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'\'',NULL,1295974),('2_Friday','11','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'\'',NULL,1295975),('2_Friday','12','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'\'',NULL,1295976),('2_Friday','13','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'\'',NULL,1295977),('2_Friday','14','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'\'',NULL,1295978),('2_Friday','15','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'\'',NULL,1295979),('2_Friday','16','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'\'',NULL,1295980),('2_Friday','17','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_a7bef25409316c053be3cdd8e392808a','\'\'',NULL,1295981),('1_Thursday','08','08:00','17:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'Title: Merch (formerly swag) Area Open -- README
\nTags: Misc
\nWhen: Thursday, Aug 6, 08:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1500 (MERCH) - Map
\n
\nDescription:
\n

The short version

\n\n
    \n
  • All sales are USD CASH ONLY. No cards of any type are accepted.
  • \n
  • All sales are final. There are no returns.
  • \n
  • You can add your selections to a list in HackerTracker, on your phone. We do not hold merchandise simply because you put it on your list in HackerTracker – that list stays on your device. We aren’t aware of it until we scan the QR code during order taking.
  • \n
  • We\'re open as many hours as we practically can be. Please refer to the conference schedule to see our latest hours. The published hours for the merch area are an approximation: supplies are limited, and when merch is sold out, the merch area will close for the year. (We intend to update this schedule to reflect their true operating status, but this is strictly best-effort.) Note that the closing hours here are when sales must have ended. For example, if sales must end by 18:00, and we estimate that it will take 2 hours to clear the queue, doors are likely to close around 16:00. Because of this dynamic nature, we can\'t predict the length of the line or when doors will be closed.
  • \n
\n\n

The slightly longer version:

\n\n

Similar to the last few years, HackerTracker will have artwork or photos of the merch for you to browse before you join the line -- you can decide ahead of time if you are interested in a product. HackerTracker is also showing stock status – if an item goes out of stock, that’ll be indicated in-app; this is on a best-effort basis, and some products move fast. You\'re able to make a wish list in Hacker Tracker, which expedites the ordering process at the front of the line (making everything faster and easier for everyone). If you don\'t want to use Hacker Tracker, you can have a merch goon create the order on your behalf.

\n\n

Tentative instructions

\n\n

Here’s the process, from beginning to end:

\n\n
    \n
  1. Browse the products, in-app. The list of products with associated artwork are expected to be published early the morning of August 6.
  2. \n
  3. When you find a product that you want to buy, make sure that you’ve selected the right variant/size, and then tap “Add to List”. Think of your list like a wish list.
  4. \n
  5. To view your list: If you’re using iOS, tap on the QR code at the top right. If you’re using Android, tap the “View List” button at the bottom.
  6. \n
  7. Your list shows everything you’ve added; if an item has gone out of stock since you added it, a warning will appear, and you’ll be required to remove the item from your list.
  8. \n
  9. When you near the front of the merch line, show the QR code at the top of your list to the order taker. They’ll scan it, and print a paper list. The list will have an order number on it, as well as your total amount due. The order taker can help answer any questions and help you modify your order if needed. If any items have sold out since they were added to your list, the order taker can help you find a replacement or remove it from your list.
  10. \n
  11. The paper list will be used to retrieve the merchandise from the warehouse. You will wait in a space that is after order taking but before checkout while your order is being picked. While you are waiting, please get your cash out. Exact change is preferred (it makes everything move faster), but change is available when required. If there are any issues picking your order, someone will help with you find alternatives or update your order.
  12. \n
  13. Once your merch is ready, a cashier will shout your order number, and/or hold up a sign with your order number written on it. Quickly make your way to the cashier, and complete the transaction.
  14. \n
  15. Enjoy!
  16. \n
\n\n\'',NULL,1295982),('1_Thursday','09','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'\'',NULL,1295983),('1_Thursday','10','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'\'',NULL,1295984),('1_Thursday','11','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'\'',NULL,1295985),('1_Thursday','12','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'\'',NULL,1295986),('1_Thursday','13','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'\'',NULL,1295987),('1_Thursday','14','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'\'',NULL,1295988),('1_Thursday','15','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'\'',NULL,1295989),('1_Thursday','16','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'\'',NULL,1295990),('1_Thursday','17','08:00','17:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_172e919d7756d6a6b50fdf4208c51dd4','\'\'',NULL,1295991),('3_Saturday','09','09:00','15:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_3fb5a90d1eea2ac94663bf321c2a1f0c','\'Title: Merch (formerly swag) Area Open -- README
\nTags: Misc
\nWhen: Saturday, Aug 8, 09:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1500 (MERCH) - Map
\n
\nDescription:
\n

The short version

\n\n
    \n
  • All sales are USD CASH ONLY. No cards of any type are accepted.
  • \n
  • All sales are final. There are no returns.
  • \n
  • You can add your selections to a list in HackerTracker, on your phone. We do not hold merchandise simply because you put it on your list in HackerTracker – that list stays on your device. We aren’t aware of it until we scan the QR code during order taking.
  • \n
  • We\'re open as many hours as we practically can be. Please refer to the conference schedule to see our latest hours. The published hours for the merch area are an approximation: supplies are limited, and when merch is sold out, the merch area will close for the year. (We intend to update this schedule to reflect their true operating status, but this is strictly best-effort.) Note that the closing hours here are when sales must have ended. For example, if sales must end by 18:00, and we estimate that it will take 2 hours to clear the queue, doors are likely to close around 16:00. Because of this dynamic nature, we can\'t predict the length of the line or when doors will be closed.
  • \n
\n\n

The slightly longer version:

\n\n

Similar to the last few years, HackerTracker will have artwork or photos of the merch for you to browse before you join the line -- you can decide ahead of time if you are interested in a product. HackerTracker is also showing stock status – if an item goes out of stock, that’ll be indicated in-app; this is on a best-effort basis, and some products move fast. You\'re able to make a wish list in Hacker Tracker, which expedites the ordering process at the front of the line (making everything faster and easier for everyone). If you don\'t want to use Hacker Tracker, you can have a merch goon create the order on your behalf.

\n\n

Tentative instructions

\n\n

Here’s the process, from beginning to end:

\n\n
    \n
  1. Browse the products, in-app. The list of products with associated artwork are expected to be published early the morning of August 6.
  2. \n
  3. When you find a product that you want to buy, make sure that you’ve selected the right variant/size, and then tap “Add to List”. Think of your list like a wish list.
  4. \n
  5. To view your list: If you’re using iOS, tap on the QR code at the top right. If you’re using Android, tap the “View List” button at the bottom.
  6. \n
  7. Your list shows everything you’ve added; if an item has gone out of stock since you added it, a warning will appear, and you’ll be required to remove the item from your list.
  8. \n
  9. When you near the front of the merch line, show the QR code at the top of your list to the order taker. They’ll scan it, and print a paper list. The list will have an order number on it, as well as your total amount due. The order taker can help answer any questions and help you modify your order if needed. If any items have sold out since they were added to your list, the order taker can help you find a replacement or remove it from your list.
  10. \n
  11. The paper list will be used to retrieve the merchandise from the warehouse. You will wait in a space that is after order taking but before checkout while your order is being picked. While you are waiting, please get your cash out. Exact change is preferred (it makes everything move faster), but change is available when required. If there are any issues picking your order, someone will help with you find alternatives or update your order.
  12. \n
  13. Once your merch is ready, a cashier will shout your order number, and/or hold up a sign with your order number written on it. Quickly make your way to the cashier, and complete the transaction.
  14. \n
  15. Enjoy!
  16. \n
\n\n\'',NULL,1295992),('3_Saturday','10','09:00','15:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_3fb5a90d1eea2ac94663bf321c2a1f0c','\'\'',NULL,1295993),('3_Saturday','11','09:00','15:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_3fb5a90d1eea2ac94663bf321c2a1f0c','\'\'',NULL,1295994),('3_Saturday','12','09:00','15:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_3fb5a90d1eea2ac94663bf321c2a1f0c','\'\'',NULL,1295995),('3_Saturday','13','09:00','15:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_3fb5a90d1eea2ac94663bf321c2a1f0c','\'\'',NULL,1295996),('3_Saturday','14','09:00','15:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_3fb5a90d1eea2ac94663bf321c2a1f0c','\'\'',NULL,1295997),('3_Saturday','15','09:00','15:59','Y','Social Gatherings/Events','LVCCW Level 1 Hall 4 1500 (MERCH)','\'Merch (formerly swag) Area Open -- README\'','\'\'','Social Gatherings/Events_3fb5a90d1eea2ac94663bf321c2a1f0c','\'\'',NULL,1295998),('2_Friday','10','10:00','10:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Return of the Defender: Using AI to Strike Back Against Enterprise Threats\'','\'Levone Campbell\'','Creator Talks_cbd0a7496f916ba486325ccc0b343ea9','\'Title: Return of the Defender: Using AI to Strike Back Against Enterprise Threats
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

A long time ago, in a network not so far away attackers gained the upper hand. For years, enterprises have been on the defensive, overwhelmed by alerts, outpaced by automation, and outnumbered by adversaries using increasingly sophisticated tactics. But the balance of power is shifting. This is the Return of the Defender. AI is no longer just a tool it\'s becoming the force multiplier that allows security teams to reclaim control, respond faster, and anticipate threats before they strike. Join us to explore how AI is empowering defenders and learn strategies to reclaim control in the evolving threat landscape.

\n\nSpeakerBio:  Levone Campbell, Chief Information Security Officer
\n

Levone Campbell, MBA, MPS, CISSP

\n\n

With more than two decades of experience in cybersecurity operations, Levone Campbell serves as a Cybersecurity Lead and Incident Coordinator, helping safeguard his organization’s digital environment through strategic defense and incident response.

\n\n

A seasoned information technology professional, Levone has developed deep expertise in cyber threat intelligence and cybercrime analysis, consistently anticipating and responding to emerging threats in an increasingly complex digital landscape. He has also expanded his focus to include the growing intersection of artificial intelligence and cybersecurity, with particular attention to the evolving challenges of AI-driven threats and defensive capabilities.

\n\n

Levone’s academic background includes dual bachelor’s degrees in Management and Marketing from North Carolina A&T State University, a Master of Business Administration from Walden University, and a Master of Professional Studies in Technology Management with a concentration in Cybersecurity from Georgetown University.

\n\n

His commitment to professional excellence is further demonstrated by his industry-recognized certifications, including the CISSP, which underscore his standing as a well-rounded cybersecurity leader.

\n\n

Based in Houston, Texas, Levone values the balance between a demanding career and a strong family life. Married for 20 years and a proud father of two, he brings discipline, perspective, and purpose to his work in protecting critical digital assets and advancing cyber resilience.

\n\n\n\'',NULL,1295999),('2_Friday','11','11:00','11:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'The Black PhD Playbook: What No One Tells You\'','\'Dr. Fatou Sankare,Dr. Xavier-Lewis Palmer,Dr. Tia Pope\'','Creator Talks_10dc3a8269fd1da8af0e65c199401d94','\'Title: The Black PhD Playbook: What No One Tells You
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Join us for an honest, encouraging, and relatable conversation about pursuing a PhD as a Black student or cybersecurity professional. Our panelists will share what the journey really looks like, including how they chose their programs, found research interests, secured funding, built support systems, handled self-doubt, and balanced school with the rest of life. Attendees will leave with practical advice, real-world lessons, and a better understanding of how to decide whether a PhD is the right path for them.

\n\nSpeakers:Dr. Fatou Sankare,Dr. Xavier-Lewis Palmer,Dr. Tia Pope
\n
\nSpeakerBio:  Dr. Fatou Sankare, Cybersecurity Professional / Community Speaker
\n

Dr. Fatou is a Cyber Engineer and an adjunct professor, dedicated to increasing cyber education, particularly in underestimated communities, through Datacation LLC, which they founded. They are a Certified Ethical Hacker and hold the AWS Machine Learning Specialty Certification.

\n\nSpeakerBio:  Dr. Xavier-Lewis Palmer, Cybersecurity Professional / Community Speaker
\n

Dr. Palmer is multi-disciplinary professional whose work focuses largely on biomedical contexts. He enjoys positive and creative projects that foster both curiosity and helpful conversations around technologies that interface with biology.

\n\nSpeakerBio:  Dr. Tia Pope, North Carolina Agricultural and Technical State University
\n

Dr. Tia Pope is a Principal at Base10 Partners, where she invests in machine intelligence and emerging AI technologies. She earned her PhD researching the evaluation and development of AI tools for protein design, with an emphasis on dual-use risks and cyberbiosecurity threats. Her work has included projects with MIT Lincoln Laboratory and Johnson & Johnson, bridging advanced research with real-world impact. Tia specializes in transformer-based models for protein engineering, function prediction, and biological risk assessment. She has also contributed to open-source efforts that expand access to cutting-edge bio-AI tools. Her work reflects a commitment to supporting secure, ethical, and resilient technologies at the intersection of machine learning, molecular design, cybersecurity, and venture investment.

\n\n\n\'',NULL,1296000),('2_Friday','12','12:00','12:59','N','Contests','LVCCW Level 3 W322-W324 (BIC Village)','\'BIC Village Capture the Flag (CTF)\'','\'\'','Contests_28cd407c24a5a8af767e91f2a236eb7d','\'Title: BIC Village Capture the Flag (CTF)
\nTags: Blacks In Cyber Village | Blacks In Cybersecurity Village Capture The Flag Competition | Contest
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

The BIC Village Capture the Flag (CTF) is your opportunity to tackle real-world cybersecurity challenges, sharpen your technical skills, and compete alongside students, professionals, and cybersecurity enthusiasts during DEF CON 34. Our CTF is designed to challenge your curiosity, celebrate creative problem-solving, and explore cybersecurity through the past, present, and future.

\n\n

What to Expect:\n� Hands-on cybersecurity challenges\n� Challenges for multiple skill levels\n� Individual and team-based problem-solving\n� Opportunities to learn, compete, and connect with the community

\n\n

Hack to the rhythm and the beat with Hack Hack Revolution. Have an idea or challenge you want to share with the community? Join Bring Your Own CTF (BYOCTF) and contribute your own challenge to the experience. Bring your laptop, curiosity, and determination. Whether you are chasing the top of the leaderboard or solving your very first flag, there is a place for you at BIC Village. Every flag is a lesson. Every challenge is an opportunity. We will see you at the CTF, featuring challenges created by members of the cybersecurity community and the global diaspora!

\n\nLinks:
    More Info - https://www.blacksincyberconf.com/ctf
\n\'',NULL,1296001),('3_Saturday','12','12:00','12:59','N','Contests','LVCCW Level 3 W322-W324 (BIC Village)','\'BIC Village Capture the Flag (CTF)\'','\'\'','Contests_e1c54f28f9545d1e0dfa5d7ae2a23746','\'Title: BIC Village Capture the Flag (CTF)
\nTags: Blacks In Cyber Village | Blacks In Cybersecurity Village Capture The Flag Competition | Contest
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

The BIC Village Capture the Flag (CTF) is your opportunity to tackle real-world cybersecurity challenges, sharpen your technical skills, and compete alongside students, professionals, and cybersecurity enthusiasts during DEF CON 34. Our CTF is designed to challenge your curiosity, celebrate creative problem-solving, and explore cybersecurity through the past, present, and future.

\n\n

What to Expect:\n� Hands-on cybersecurity challenges\n� Challenges for multiple skill levels\n� Individual and team-based problem-solving\n� Opportunities to learn, compete, and connect with the community

\n\n

Hack to the rhythm and the beat with Hack Hack Revolution. Have an idea or challenge you want to share with the community? Join Bring Your Own CTF (BYOCTF) and contribute your own challenge to the experience. Bring your laptop, curiosity, and determination. Whether you are chasing the top of the leaderboard or solving your very first flag, there is a place for you at BIC Village. Every flag is a lesson. Every challenge is an opportunity. We will see you at the CTF, featuring challenges created by members of the cybersecurity community and the global diaspora!

\n\nLinks:
    More Info - https://www.blacksincyberconf.com/ctf
\n\'',NULL,1296002),('2_Friday','12','12:00','12:25','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'When the Agent Lies: Why Neurosymbolic AI is the Security Layer Nobody is Building Yet\'','\'Maureese Williams\'','Creator Workshops_ca398998c68db55aa568ab67942720ab','\'Title: When the Agent Lies: Why Neurosymbolic AI is the Security Layer Nobody is Building Yet
\nTags: Blacks In Cyber Village | Creator Workshop
\nWhen: Friday, Aug 7, 12:00 - 12:25 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

AI agents are being handed the keys to enterprise infrastructure, executing code, querying databases, making access decisions, and increasingly controlling physical systems. Most are built on pure LLM inference, making them stochastic, opaque, and vulnerable in ways traditional security tooling was never designed to catch. This session breaks down how LLM-based agent architectures fail from a security perspective, what a more auditable architecture looks like in practice, and why the security community needs to be driving this conversation before the agents are already inside the perimeter. Discover how grounding agent decisions in structured knowledge graphs, symbolic reasoning, and auditable state transitions dramatically reduces this exposure, offering a critical new security layer. Join us to understand the future of secure AI agents.

\n\nSpeakerBio:  Maureese Williams, Senior LLM and Data Engineer
\n

Maureese Williams is a Senior LLM and Data Engineer with extensive experience in media, finance, and technology. They specialize in leveraging AI and Large Language Models (LLMs) to solve real-world problems and empower developers. Their background includes working with companies like Warner Bros Discovery, Accenture, Ugam, Vanguard, and BlackRock, focusing on data engineering, vector databases, and generative AI. Maureese is also known for contributing to open-source projects.

\n\n\n\'',NULL,1296003),('2_Friday','12','12:30','12:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Prompt Injection Detection in Large Language Models: Survey and Evaluation of Open Source Tools\'','\'Yasmin Eady\'','Creator Talks_896a77fff5a74c35b6522445a5aefe55','\'Title: Prompt Injection Detection in Large Language Models: Survey and Evaluation of Open Source Tools
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:30 - 12:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Prompt injection attacks trick Large Language Models into bypassing safety controls, leaking sensitive data, or performing unauthorized actions. This survey examines five open-source detection tools, LlamaFirewall, Cybersecurity AI, LLM Guard, Promptfoo, and OpenAI Guardrails Python. Analyzing How do they identify and block these attacks. The tools use different strategies: pattern-matching classifier, semantic reasoning systems, layered defenses, and code analyzers. We tested LlamaFirewall’s PromptGuard 2 on four datasets containing 52,240 samples. When it flagged something as attack (malicious prompt), it was accurate 87%�100% of the time, but it only caught 40%�73% of actual attacks. Accuracy ranged from 57% on realistic chatbot conversations to 85% on artificial test cases.

\n\nSpeakerBio:  Yasmin Eady, Ph.D. Student, NC A&T State University
\n

Yasmin Eady is a PhD student in Computer Science at North Carolina A&T State University whose research focuses on prompt injection detection in large language models. Her work explores the security risks introduced by LLM-powered systems and the evaluation of open-source tools for identifying prompt injection vulnerabilities. Yasmin began her academic journey at West Los Angeles College, where she earned an Associate of Arts degree in Mathematics, and later completed a Bachelor of Science in Applied Mathematics at North Carolina A&T State University. Her broader research background includes cybersecurity, trust in distributed and social network systems, and biometric authentication.

\n\n\n\'',NULL,1296004),('2_Friday','13','13:00','13:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'CTRL the Chaos: When AI Controls Critical Infrastructure\'','\'Nykolas Muldrow\'','Creator Talks_e48a4cd0dff5f43086ea6e7bf4681573','\'Title: CTRL the Chaos: When AI Controls Critical Infrastructure
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

As artificial intelligence shifts from supporting analytics to exercising real-time operational control in critical infrastructure energy grids, aviation systems, healthcare networks, transportation, and national logistics it ceases to be a tool and becomes part of the infrastructure itself. AI now optimizes load balancing, automates routing, manages predictive maintenance, and drives high-stakes decisions that directly impact public safety, economic stability, and national security. This session introduces the CTRL framework (Control, Resilience, Trust, Leadership) a strategic blueprint for securing autonomous systems before they evolve into systemic risk. Drawing from hands-on experience in federal cybersecurity, aviation security, AI governance, and academic cybersecurity instruction, Nykolas Muldrow explores how AI expands the attack surface through threats like data poisoning, model drift, prompt injection, and compromised AI supply chains. Attendees will gain: A clear view of how embedded AI transforms infrastructure vulnerabilities A practical threat model tailored to autonomous operational systems Governance strategies aligned with NIST AI Risk Management Framework and ISO-based controls The CTRL leadership model for embedding responsible AI oversight into organizational strategy An immediate-use risk-evaluation method for their own products, infrastructure, or agencies In an era where regulators intensify scrutiny, investors demand deeper risk diligence, and operators race to deploy AI without proportional safeguards, the next decade of progress will belong to those who govern autonomous systems responsibly not just those who deploy them fastest. Join to equip yourself with the tools to lead before AI makes decisions we cannot easily reverse.

\n\nSpeakerBio:  Nykolas Muldrow, CEO of CI Solutions Global Inc.
\n

Nykolas Muldrow is a cybersecurity executive, CEO of CI Solutions Global Inc., and 2025 GovTechCon Mission Trailblazer Award recipient for their pioneering work in AI, cybersecurity, and secure cloud technologies for critical infrastructure. With 15+ years securing defense, aviation, and federal systems including aviation GRC at American Airlines they specialize in threat modeling autonomous AI in high-stakes environments like energy grids, transportation, and healthcare networks. Nyk teaches cybersecurity, aligns solutions to NIST AI RMF and ISO controls, and equips leaders to govern AI responsibly before it becomes systemic risk.

\n\n\n\'',NULL,1296005),('2_Friday','14','14:00','14:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Agents on Alert: Building an AI-Powered Threat Investigation Framework\'','\'Samson Adewale\'','Creator Talks_3539faaa97852bf543519c2d5ac0b0dc','\'Title: Agents on Alert: Building an AI-Powered Threat Investigation Framework
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Join us for a deep dive into building an AI-powered framework for threat investigation! Security operations often grapple with fragmented data and alert overload. This session moves beyond basic AI summarization to explore how to design and implement tool-enabled AI agents that actively investigate security alerts. Discover how to create structured agents with controlled access to your internal data and external threat intelligence, enabling them to gather context, reason through findings, and produce actionable summaries. We ll cover key architectural considerations, guardrails, and human-in-the-loop controls. A live demo will showcase the full workflow, providing attendees with a clear blueprint for implementing responsible, AI-assisted threat investigation in real-world SOC environments.

\n\nSpeakerBio:  Samson Adewale, Cybersecurity Professional / Community Speaker
\n

Samson Adewale is a Senior Cybersecurity Engineer specializing in Cloud Security, DevSecOps, and Cloud-Native architectures. They design secure platforms, automate incident response, and build tooling for high-velocity teams. As an AI enthusiast, Samson is passionate about applying AI and LLM technologies to enhance security operations and streamline cybersecurity workflows.

\n\n\n\'',NULL,1296006),('2_Friday','15','15:00','15:25','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'The Cost of Unverified Intelligence: AI and Accountability in Defense Operations\'','\'Kayrene Woods\'','Creator Talks_e420ba34dbd47de67a92306620548f14','\'Title: The Cost of Unverified Intelligence: AI and Accountability in Defense Operations
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:25 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Explore the critical implications of unverified intelligence in defense operations, particularly concerning the role of Artificial Intelligence. This presentation will delve into a recent incident where AI-processed data contributed to a devastating error, examining the failure points in human oversight, algorithmic accountability, and the growing workforce gap in understanding and managing these powerful systems. Join us to discuss the urgent need for robust governance, verification, and training infrastructure to ensure responsible AI deployment in defense, and consider what lessons must be learned to prevent future tragedies. This timely discussion draws on current doctrine, recent operations, and ongoing public discourse, offering valuable insights for anyone interested in AI ethics, national security, and responsible technology development.

\n\nSpeakerBio:  Kayrene Woods, Graduate Student, Founding President of BiC ODU
\n

Kayrene Woods is an emerging cybersecurity professional and recent graduate of Old Dominion University, where they earned a B.S. in Cybersecurity with a minor in Computer Science and a 3.76 GPA as a member of the Perry Honors College. Notably, they served as the Founding President of the Blacks in Cybersecurity ODU chapter, which is the second officially recognized chapter established outside of the parent organization. Their technical expertise and research spans cybersecurity engineering, network security, intrusion-detection, and AI governance, with hands-on experience from an internship at the Air Force Research Laboratory/Griffis Institute supporting Department of Defense security research. This summer, they\'ll serve as a VICEROY Envoy at the Pentagon, supporting a Cloud Portfolio project for Air Force Intelligence within the Chief Information Officer\'s unit.

\n\n\n\'',NULL,1296007),('2_Friday','15','15:30','15:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Configuring Your Favorite Platforms to Prioritize DNS\'','\'Malachi Walker,Anthony Johnson\'','Creator Talks_99c7de5c773fa493d1af1fcc542970be','\'Title: Configuring Your Favorite Platforms to Prioritize DNS
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Explore how to leverage infrastructure OSINT data, such as passive DNS and domain registration records, to enhance your threat intelligence and protect your organization without exhausting budgets. In this demo, DomainTools Senior Security Advisor Malachi Walker will discuss how security teams can develop advanced techniques for continuous and explainable intelligence. Then, DomainTools Principal Product Manager Anthony Johnson will demonstrate how these concepts can be applied to build AI-driven product layers that draw domain intelligence from standard LLMs like ChatGPT, Claude, Gemini, and Copilot. Discover innovations that reduce triage time, improve early warnings, and automate campaign linkages, transforming your existing intelligence practices.

\n\nSpeakers:Malachi Walker,Anthony Johnson
\n
\nSpeakerBio:  Malachi Walker, DomainTools
\n

Malachi Walker, DomainTools Senior Security Advisor, brings extensive experience in information security, spanning DNS, cyberspace crime and conflict, and cybersecurity governance and program design. They have previously worked in FTI Consulting s Cybersecurity practice and led product and brand protection efforts at WhiteHawk Inc. Malachi holds a Master s in Business Administration with a concentration in Cybersecurity Management from Virginia Polytechnic Institute and State University.

\n\nSpeakerBio:  Anthony Johnson, DomainTools
\n

Anthony Johnson, DomainTools Principal Product Manager, has nearly 15 years of experience in cybersecurity. His background includes forensics, analytics, and product management, gained through work with the US Military, Casino Gaming, and other security-focused organizations.

\n\n\n\'',NULL,1296008),('2_Friday','16','16:00','17:30','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'KaliGPT Vibe-Ethical Hacking Session\'','\'Timothy E. Bates\'','Creator Workshops_61ae7dac8ad746f88c1df380284638fc','\'Title: KaliGPT Vibe-Ethical Hacking Session
\nTags: Blacks In Cyber Village | Creator Workshop
\nWhen: Friday, Aug 7, 16:00 - 17:30 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Join B.I.C. Village for KaliGPT Vibe-Ethical Hacking Session, a welcoming session focused on hands-on ethical hacking concepts, Kali Linux workflows, and responsible security learning. Come ready to learn, ask questions, and connect with the community.

\n\nSpeakerBio:  Timothy E. Bates, Professor of Practice, University of Michigan / Fractional CTO
\n

Timothy E. Bates, also known as \"The Godfather of Tech,\" is a distinguished cybersecurity professional and educator. Discovered as a hacker at age 13 by the U.S. Marshals Service, he was later recruited by the U.S. Government to train on tracking digital pirates and hackers. He brings over 40 years of experience in the tech industry, with extensive expertise in Artificial Intelligence (AI), Blockchain, and Immersive Technologies. His career includes significant roles as Chief Technology Officer (CTO) at Global Fortune 200 companies like Lenovo and General Motors. Timothy currently serves as a Professor of Practice in the College of Innovation & Technology at the University of Michigan-Flint and as a Fractional CTO. He has received numerous accolades, including the BEYA Black Engineers Association Award: Modern-Day Technology Leader.

\n\n\n\'',NULL,1296009),('2_Friday','17','16:00','17:30','Y','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'KaliGPT Vibe-Ethical Hacking Session\'','\'Timothy E. Bates\'','Creator Workshops_61ae7dac8ad746f88c1df380284638fc','\'\'',NULL,1296010),('3_Saturday','10','10:00','10:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Being Black While Hacking: The Unofficial Survival Guide\'','\'Dr. Louis DeWeaver III\'','Creator Talks_9729db9cac8a15a705b0b8b1709bdf26','\'Title: Being Black While Hacking: The Unofficial Survival Guide
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

In an industry that frequently highlights a massive skills gap, Black professionals are dramatically underrepresented in cybersecurity. This talk uses sharp humor and real-world experiences to explore the realities of being Black in the hacking community. It addresses challenges like the \"only one in the room\" tax, costly certifications, unconscious bias in hiring, and the emotional labor of code-switching. Attendees will gain insights into systemic barriers and learn how resilience and community, inspired by trailblazers like Camille Stewart Gloster and Tennisha Martin, can overcome rigged systems. This session also challenges allies and leaders to sponsor talent, improve hiring processes, and understand why increasing Black representation is essential for equity and innovation in cybersecurity.

\n\nSpeakerBio:  Dr. Louis DeWeaver III, Cybersecurity Consultant at Marsh McLennan Agency (MMA)
\n

Dr. Louis DeWeaver is a battle-tested Cybersecurity Consultant at Marsh McLennan Agency (MMA) with over 20 years of real-world experience in the trenches. They hold a hard-earned academic arsenal: an Associate of Applied Science in Information Technology, a B.S. in Information Systems Security (2011), an M.S. in Information Assurance (2016), and a Doctor of Computer Science specializing in Cybersecurity (2021). Dr. DeWeaver doesn t just collect credentials they weaponize them. They serve on the MITRE Engenuity ATT&CK® Evaluations Community Advisory Board, helping define how organizations should actually defend against real adversaries. A proven competitor, they crushed the ONCD Badge Challenge at DEFCON 31 and 32, and in 2025 took down the Policy Village CTF badge created by former ONCD staff. Blunt, high-energy, and unapologetically direct, Dr. DeWeaver has delivered hard-hitting talks at Black Hat, DEF CON, GrrCon, and other major security events. They don t sugarcoat the industry s failures they call them out and show you how to survive (and win) anyway.

\n\n\n\'',NULL,1296011),('3_Saturday','11','11:00','11:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Cyber Gamechangers: Women Who Lead, Secure, and Inspire\'','\'Nikkia Henderson,Arielle Baine,Jess Hoffman\'','Creator Talks_6daaa80f975b63cf606a965dd1425cdc','\'Title: Cyber Gamechangers: Women Who Lead, Secure, and Inspire
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Join B.I.C. Village for Cyber Gamechangers: Women Who Lead, Secure, and Inspire, a welcoming session focused on leadership, career growth, and the impact of women shaping cybersecurity. Come ready to learn, ask questions, and connect with the community.

\n\nSpeakers:Nikkia Henderson,Arielle Baine,Jess Hoffman
\n
\nSpeakerBio:  Nikkia Henderson, Senior Advisor, Cybersecurity Infrastructure Security Agency (CISA) / President, Women in Cybersecurity Mid Atlantic Affiliate
\n

Nikkia Henderson is a Senior Advisor at the Cybersecurity Infrastructure Security Agency (CISA), where they lead the Cyber Supply Chain Risk Management (C-SCRM) Strategy and Governance Program. They also serve as President of the Women in Cybersecurity Mid Atlantic Affiliate, helping professionals define their vision and career paths in federal cybersecurity. With over 14 years in federal government, Nikkia holds a Master\'s degree in Cyber Policy.

\n\nSpeakerBio:  Arielle Baine, Chief of Cybersecurity at Cybersecurity and Infrastructure Security Agency (CISA)
\n

Arielle Baine is the Chief of Cybersecurity for Region 3 within the Department of Homeland Security\'s Cybersecurity and Infrastructure Security Agency (CISA). They lead the Cybersecurity Advisor Program, enhancing the security and resilience of critical infrastructure. With over 9 years of experience in cybersecurity across federal civilian and DoD communities, Arielle holds multiple certifications including CISSP, CCSP, GCWN, CEH, and Security+, and a Master of Science degree in Cybersecurity.

\n\nSpeakerBio:  Jess Hoffman, Deputy CISO, City of Philadelphia / Professor, Harrisburg University and The Pennsylvania State University
\n

Jess Hoffman is a Certified Information System Security Professional (CISSP) with nearly 20 years of IT and cybersecurity experience in government and private sectors, focusing on Audit and Compliance. They currently serve as Deputy CISO for the City of Philadelphia and are a Professor at Harrisburg University and The Pennsylvania State University. Jess is a national speaker and advocates for mentorship and DEI within cybersecurity.

\n\n\n\'',NULL,1296012),('3_Saturday','12','12:00','12:25','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Root Access: An APT Analysis of Systemic Gatekeeping in Cybersecurity\'','\'Dr. Hassan Karim\'','Creator Talks_999f1a99e9b6fe6eb53003ea6cf29da3','\'Title: Root Access: An APT Analysis of Systemic Gatekeeping in Cybersecurity
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:25 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Explore the unseen authorization systems shaping the cybersecurity field in this compelling talk. We\'ll apply threat intelligence and access control theory to understand who gains entry, who advances, and who sets the rules. Discover an APT architectural approach to visualize systemic gatekeeping and learn social-engineering strategies to gain \'root access.\' The session will present two distinct threat models, inviting you to analyze the system as both an adversary and a target. Drawing on 30 years of experience and research in Next Generation Access Control (NGAC) hypergraph authorization, the speaker will equip attendees with a formal model for understanding the system, effective Tactics, Techniques, and Procedures (TTPs) to navigate it, and a framework for influencing the policies that govern our field. Don\'t miss this opportunity to gain critical insights and strategies for cybersecurity career navigation.

\n\nSpeakerBio:  Dr. Hassan Karim, Stable Cyber LLC
\n

Hassan Karim, PhD is a cybersecurity researcher, academic, and founder of Stable Cyber LLC, with over 30 years of experience spanning financial infrastructure and payment systems at Goldman Sachs and JPMorgan Chase, OT/SCADA security and nation-scale infrastructure design at Aramco, and risk engineering across PNC Bank and Comerica. They hold a PhD in Computer Science from Howard University and conduct research in formal authorization models, adversarial AI risk, and cyber-physical systems security. Their published work on hypergraph-based access control for agentic AI and multi-robot systems is the technical foundation for this talk. They have operated, navigated, and quietly reverse-engineered the systems this talk is about for three decades.

\n\n\n\'',NULL,1296013),('3_Saturday','12','12:30','12:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'The Voice Behind the Payload: Tracing AAVE Across Malware Artifacts\'','\'Brett Tolbert\'','Creator Talks_b9fa0998aa673ee3f8403c84875343e9','\'Title: The Voice Behind the Payload: Tracing AAVE Across Malware Artifacts
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 12:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\nDiscover an often-overlooked signal in threat actor attribution: everyday language. This compelling session explores how African American Vernacular English (AAVE), with its distinctive grammatical features and lexicon, can leave unique fingerprints in malware artifacts like ransom notes and phishing lures. While emphasizing that AAVE use doesn\'t imply threat actor ethnicity, this talk will dive into a YARA-based detection methodology to investigate its frequency across malware samples. Attendees will learn about the study\'s innovative approach, review preliminary findings on which malware families show the strongest signals, and engage in crucial discussions around the ethical implications of sociolinguistic analysis in cybersecurity. Don\'t miss this fascinating look at how linguistics can enhance our understanding of threat actor intent and capabilities.
\n\n\n\nSpeakerBio:  Brett Tolbert, Principal Cyber Threat Intelligence Analyst / Undergraduate Adjunct Professor at Bowie State University
\n

Brett Tolbert is a Principal Cyber Threat Intelligence Analyst and an undergraduate adjunct professor at Bowie State University. With over 11 years of experience in cybersecurity, they have held threat intelligence and cyber defense roles in the U.S. intelligence community and in companies supporting U.S. critical infrastructure, focusing on tracking Asia-nexus state-sponsored threat actors, threat intelligence engineering, cross-sector partnerships, and technical leadership. They have previously spoken at SANS CTI Summit, MITRE ATT&CKcon, and the BIC Village at DEFCON. Brett lives in the DC-Baltimore corridor and enjoys playing monster hunter games, knitting, and baking in their spare time.

\n\n\n\'',NULL,1296014),('3_Saturday','13','13:00','13:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Bias is a Bug: Why Inequality is a Cybersecurity Vulnerability\'','\'Dr. Fatou Sankare\'','Creator Talks_fa1399000757134f908cfd598aba3250','\'Title: Bias is a Bug: Why Inequality is a Cybersecurity Vulnerability
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

This thought-provoking session examines how bias in AI systems used across cybersecurity for fraud detection, identity systems, and behavioral analytics can inadvertently create structural weaknesses that adversaries might exploit. We will explore how bias can be introduced through data collection, labeling, and modeling, leading to uneven false positive and false negative rates across different populations. Understanding these inconsistencies is crucial, as they can offer attackers avenues to map detection thresholds and bypass security systems. The session will also connect these security risks to emerging regulatory frameworks like GDPR and the AI Act, demonstrating how compliance needs are aligning with core security practices. Join us to learn why integrating equity into threat modeling, red teaming, and system auditing is essential for robust cybersecurity, moving beyond treating fairness as an afterthought.

\n\nSpeakerBio:  Dr. Fatou Sankare, Cybersecurity Professional / Community Speaker
\n

Dr. Fatou is a Cyber Engineer and an adjunct professor, dedicated to increasing cyber education, particularly in underestimated communities, through Datacation LLC, which they founded. They are a Certified Ethical Hacker and hold the AWS Machine Learning Specialty Certification.

\n\n\n\'',NULL,1296015),('3_Saturday','14','14:00','14:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Exploring Security Features in the Armv8-M Architecture\'','\'Ian Harris,Jacob Gutierrez\'','Creator Talks_4f884d8a8d3255e24684fd1d7191c0d8','\'Title: Exploring Security Features in the Armv8-M Architecture
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Join us for an in-depth session exploring the critical security features embedded within the Armv8-M architecture. We\'ll dive into TrustZone for Cortex-M, the PACBTI Extension, and the Debug Authentication/Unprivileged Debug Extension, providing clear explanations of their functionalities and the motivations behind their development. Discover how these advanced features contribute to robust embedded system security.

\n\nSpeakers:Ian Harris,Jacob Gutierrez
\n
\nSpeakerBio:  Ian Harris, University of California, Irvine
\n

Ian Harris is a Professor at the University of California, Irvine, specializing in computer science with a strong focus on embedded systems and security. They bring a rich background in hardware design verification and security, and their research encompasses secure hardware/software systems. Ian also teaches courses related to embedded systems and has presented at cybersecurity conferences.

\n\nSpeakerBio:  Jacob Gutierrez, Cybersecurity Professional / Community Speaker
\n

Jacob Gutierrez is a recent Computer Science graduate with a keen interest in embedded systems and their security. They are passionate about contributing to the cybersecurity community and sharing their knowledge.

\n\n\n\'',NULL,1296016),('3_Saturday','15','15:00','15:55','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'ChronoRoot: Time-Traveling Through Kernel Trust Boundaries\'','\'Ahmeen Muhammad,Sydney Johns\'','Creator Talks_1d83f519eedde8fb8d14d2fd1fa4dadc','\'Title: ChronoRoot: Time-Traveling Through Kernel Trust Boundaries
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:55 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Join B.I.C. Village for ChronoRoot: Time-Traveling Through Kernel Trust Boundaries, a welcoming session focused on kernel trust boundaries, system internals, and how attackers challenge low-level security assumptions. Come ready to learn, ask questions, and connect with the community.

\n\nSpeakers:Ahmeen Muhammad,Sydney Johns
\n
\nSpeakerBio:  Ahmeen Muhammad, Cybersecurity Professional / Community Speaker
\n

Ahmeen C. Muhammad is a Senior Penetration Testing Consultant and Army cyber veteran with experience conducting offensive security operations across enterprise and government environments. His interests include red teaming, reverse engineering, Malware Development, endpoint security evasion, and AI security testing. When he\'s not on an engagement, Ahmeen spends his time researching emerging attack techniques, developing offensive tooling, and sharing knowledge with the cybersecurity community. He is passionate about helping organizations better understand their security posture through realistic adversary emulation and hands-on offensive security research.

\n\nSpeakerBio:  Sydney Johns, AI/ML Engineer, Virginia Tech Researcher
\n

Sydney Johns is an Artificial Intelligence Researcher at GitHub and a Ph.D. student in Computer Science at Virginia Tech. Her research interests include artificial intelligence, machine learning, reverse engineering, and ethical hacking. She holds a Bachelor’s degree in Electrical Engineering and a Master’s degree in Cybersecurity, along with CompTIA Security+ and EC-Council Certified Ethical Hacker certifications. Sydney is passionate about STEM outreach, mentorship, and creating pathways for more people to enter technology and cybersecurity. In her spare time, she enjoys playing Overcooked and Animal Crossing, painting, and shopping.

\n\n\n\'',NULL,1296017),('3_Saturday','16','16:00','16:30','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Improving Security Vulnerability Descriptions using LLMs\'','\'Kenechukwu Nwodo\'','Creator Talks_3b2e6ef0f32eea50f5187b03ba12f429','\'Title: Improving Security Vulnerability Descriptions using LLMs
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

CVE records are a foundation of modern vulnerability management, but many entries still contain incomplete, vague, or low-context descriptions. This limits their usefulness for security teams, researchers, and automated tools that rely on CVE text to understand and communicate risk. This talk presents research on using large language models to enrich CVE descriptions with additional vulnerability context. By combining information from CWE, CVSS, and proof-of-concept code, the approach generates clearer and more informative vulnerability descriptions. The enriched descriptions are then evaluated through MITRE ATT&CK technique classification to measure whether they improve downstream security analysis. Results show that structured prompting can make vulnerability descriptions more interpretable and improve classification performance, achieving up to a 12.7% F1 score increase over original CVE text. This work highlights how LLMs can support vulnerability analysis, strengthen security communication, and help transform incomplete vulnerability records into more actionable cyber threat intelligence.

\n\nSpeakerBio:  Kenechukwu Nwodo, Ph.D. Student, Virginia Tech / Co-founder, WayWave Inc.
\n

Kenechukwu Nwodo is a Ph.D. student in the Bradley Department of Electrical and Computer Engineering at Virginia Tech, where their research interests include software and mobile security. Originally from Lagos, Nigeria, Kene is also the co-founder of WayWave Inc., where they lead the development of advanced localization solutions.

\n\n\n\'',NULL,1296018),('3_Saturday','16','16:30','16:59','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'[Virtual] National Service Panel - CTU,BIC,MCPA\'','\'Carmeshia Miller,Tiffany Scheurenbrand,Shemeka Chance Jeffrey\'','Creator Talks_ff2bdf1644d0a68b94220b962c44d724','\'Title: [Virtual] National Service Panel - CTU,BIC,MCPA
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Join B.I.C. Village for a virtual National Service Panel featuring Capitol Technology University, Blacks in Cybersecurity, and the Military Cyber Professionals Association. This welcoming session will explore national service, mission driven cybersecurity, and the many ways professionals can use their skills to support government, military, academic, and community focused initiatives. Hear from experienced leaders, learn about different career and service pathways, and discover how cybersecurity can create meaningful public impact.

\n\nSpeakers:Carmeshia Miller,Tiffany Scheurenbrand,Shemeka Chance Jeffrey
\n
\nSpeakerBio:  Carmeshia Miller, BIC Military Relations & Veterans Program Lead and BWIC Curriculum & Learning Experience Lead
\n

Carmeshia �Meshia� Miller is a cybersecurity leader, educator, and advocate with more than 30 years of experience dedicated to expanding access, confidence, and opportunity for military veterans and Black women entering and advancing in tech. She is a retired U.S. Army Warrant Officer, bringing decades of experience in leadership, operations, and risk management to her work in cybersecurity and workforce development. After transitioning from military service, Meshia built a career at the intersection of cybersecurity education, career readiness, governance, risk, and compliance, and community empowerment. She is known for breaking down complex technical concepts into practical, confidence-building learning experiences, especially for those who may feel intimidated by the field. As a leader within Blacks in Cyber and Black Women in Cyber, Meshia focuses on creating safe, affirming spaces where women can learn hands-on technical skills, gain career clarity, and build professional networks that lead to real opportunities. Her work emphasizes not only technical competence but also self-advocacy, resilience, and strategic career navigation in environments where Black women are often underestimated or overlooked. Meshia�s mission is simple but powerful: To ensure Black women don�t just enter cybersecurity�but thrive, lead, and shape its future.

\n\nSpeakerBio:  Tiffany Scheurenbrand, Missile Defense Agency (MDA) ICAM Lead
\n

Tiffany Scheurenbrand (Sure-N-Brand) is a cybersecurity leader, U.S. Army veteran, and doctoral student with more than a decade of experience across military, federal, and defense cyber environments. Her background spans cybersecurity operations, information assurance, risk management, secure communications, identity and access management, PKI, privileged access management, Zero Trust, compliance, enterprise security, and team leadership. Throughout her career, Tiffany has supported mission-focused cyber programs in high-pressure environments, leading teams, solving operational security challenges, strengthening governance, and helping organizations improve their overall cyber posture. Her experience includes working across technical, operational, and leadership roles, giving her a broad perspective on how cybersecurity impacts people, mission execution, policy, and national defense. Tiffany is currently pursuing a PhD in Space Cybersecurity, with research focused on Zero Trust policy for secure space commands across space, ground, and cloud environments. She is passionate about national service, mentorship, representation in cybersecurity, and helping the next generation of cyber professionals understand that there is no single path into the field.

\n\nSpeakerBio:  Shemeka Chance Jeffrey, G6 Cyber Chief
\nNo BIO available
\n\n\'',NULL,1296019),('3_Saturday','18','18:00','22:59','N','Social Gatherings/Events','LVCCW Level 3 W322-W324 (BIC Village)','\'2nd Annual Spades Night & Uno Tournament\'','\'\'','Social Gatherings/Events_44071cb1a3d7906e216005fb63fb0aa9','\'Title: 2nd Annual Spades Night & Uno Tournament
\nTags: Party | Blacks In Cyber Village | Blacks In Cybersecurity Game Night Extravaganza!
\nWhen: Saturday, Aug 8, 18:00 - 22:59 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Get ready for our 2nd Annual Spades & UNO tournaments during Game Night! This year we\'ve uped the anti by expanding the brackets! Whether you\'re going all-in, calling someone\'s bluff or running the table in UNO, it\'s time to see who will earn bragging rights for another year! Hosted by Blacks In Cybersecurity (BIC), this gathering celebrates culture, strategy and the timeless joy of game night. From the unspoken rules of Spades to the quiet intensity of Uno, we are honoring the traditions that bring us together one hand at a time. This is your chance to relax, recharge and throw down with our family and fellow attendees. There will be other games and music for those who wanna just hang out. Come ready to unwind & meet new people!

\n\n\'',NULL,1296020),('3_Saturday','19','18:00','22:59','Y','Social Gatherings/Events','LVCCW Level 3 W322-W324 (BIC Village)','\'2nd Annual Spades Night & Uno Tournament\'','\'\'','Social Gatherings/Events_44071cb1a3d7906e216005fb63fb0aa9','\'\'',NULL,1296021),('3_Saturday','20','18:00','22:59','Y','Social Gatherings/Events','LVCCW Level 3 W322-W324 (BIC Village)','\'2nd Annual Spades Night & Uno Tournament\'','\'\'','Social Gatherings/Events_44071cb1a3d7906e216005fb63fb0aa9','\'\'',NULL,1296022),('3_Saturday','21','18:00','22:59','Y','Social Gatherings/Events','LVCCW Level 3 W322-W324 (BIC Village)','\'2nd Annual Spades Night & Uno Tournament\'','\'\'','Social Gatherings/Events_44071cb1a3d7906e216005fb63fb0aa9','\'\'',NULL,1296023),('3_Saturday','22','18:00','22:59','Y','Social Gatherings/Events','LVCCW Level 3 W322-W324 (BIC Village)','\'2nd Annual Spades Night & Uno Tournament\'','\'\'','Social Gatherings/Events_44071cb1a3d7906e216005fb63fb0aa9','\'\'',NULL,1296024),('4_Sunday','10','10:00','10:59','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'From Practitioner to Principal: Building a Cybersecurity Business That Lasts\'','\'Tyrone E. Wilson\'','Creator Workshops_1d26198b778dbd5e97454bb1bb73ad83','\'Title: From Practitioner to Principal: Building a Cybersecurity Business That Lasts
\nTags: Blacks In Cyber Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Most cybersecurity workshops teach you how to do the work. This one teaches you how to own it. Tyrone E. Wilson Army veteran, CISO, and founder of Cover6 Solutions breaks down what it actually takes to transition from practitioner to principal: building a service-based firm, pricing your expertise, navigating GovCon as an SDVOSB, and sustaining a business that doesn\'t depend on your last client check.

\n\nSpeakerBio:  Tyrone E. Wilson, Cover6 Solutions
\n

Tyrone E. Wilson is a U.S. Army veteran, cybersecurity executive, and founder of Cover6 Solutions a Service-Disabled Veteran-Owned Small Business delivering vCISO and compliance services to organizations across the public and private sectors. With over two decades of experience in security leadership, they built Cover6 from the ground up while simultaneously growing a 9,000+ member cybersecurity community for career changers and professionals of color. They are the creator of the Breaking Into Cyber framework and host of the Cover6 Community a free resource for anyone navigating the industry without a built-in network. Tyrone has delivered training for Blacks In Cybersecurity and speaks regularly on the intersection of entrepreneurship, community, and cybersecurity career development.

\n\n\n\'',NULL,1296025),('4_Sunday','11','11:00','11:30','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Quantum Computing The Game Changer You Can t Ignore\'','\'Danielle Eason\'','Creator Talks_d356146d45d3320bb072b8cc6996143f','\'Title: Quantum Computing The Game Changer You Can t Ignore
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Quantum computing can feel intimidating, but this session makes it clear, practical, and relevant. Dannielle Eason will break down the basics of quantum computing, explain why it matters now, and show how it may disrupt cybersecurity, healthcare, finance, AI, climate science, and more. Attendees will leave with concrete steps for protecting personal data, preparing organizations for Q-Day, and staying current with NIST, CISA, and NSA guidance. Whether you are technical, non-technical, or simply curious, this welcoming session will help you understand the quantum shift and what to do next.

\n\nSpeakerBio:  Danielle Eason, Cybersecurity Speaker
\n

Dr. Dannielle Eason is a cybersecurity and governance, risk, and compliance leader with more than 15 years of experience driving enterprise compliance, audit readiness, and federal cybersecurity initiatives. She specializes in building governance frameworks, using data to guide risk decisions, and aligning security strategy with organizational goals. Her work includes leading federal regulatory tracking programs, improving compliance metrics through policy alignment, automating reporting workflows, and strengthening security assessment programs. A frequent speaker at industry conferences including BITECON and GovTechCon, Dr. Eason brings practical expertise in cybersecurity, GRC, and organizational readiness to help audiences understand and prepare for emerging technology risks.

\n\n\n\'',NULL,1296026),('4_Sunday','12','12:00','12:20','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'Monocultures Are Vulnerabilities: Representation and Security in STEM\'','\'Ruben Stephen\'','Creator Talks_263d646d94b8596b36e5e7356f5fb861','\'Title: Monocultures Are Vulnerabilities: Representation and Security in STEM
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:20 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

This thought-provoking session argues that equity and representation in STEM are essential security controls, not just optional add-ons. Discover how monocultures create vulnerabilities in cybersecurity and technology by fostering blind spots to critical threats. Learn how diverse perspectives act as an inoculation, strengthening our collective ability to anticipate and resist both human and algorithmic abuses. This talk highlights why inclusive pipelines are fundamental for building more secure and resilient systems for all.

\n\nSpeakerBio:  Ruben Stephen, Undergraduate Student, MIT
\n

Ruben Stephen is an MIT student pursuing dual majors in Mechanical Engineering and Computer Science. Driven by a passion for problem-solving, personal growth, and helping others, they also embrace digital creation and entrepreneurship to amplify their impact and explore their love of system building from a different lens.

\n\n\n\'',NULL,1296027),('4_Sunday','13','13:00','13:59','N','Blacks In Cyber Village','LVCCW Level 3 W322-W324 (BIC Village)','\'DeNISTifying Technology: Paradigm Shifting To Quantum Encryption, Post Cryptography, and Digital Forensics\'','\'Aisha Berry\'','Creator Talks_d65a6f6f9ba1094b7331b2f4472cf27c','\'Title: DeNISTifying Technology: Paradigm Shifting To Quantum Encryption, Post Cryptography, and Digital Forensics
\nTags: Blacks In Cyber Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 3 W322-W324 (BIC Village) - Map
\n
\nDescription:
\n

Dive into the future of cybersecurity with a session that challenges conventional thinking. This talk explores the concept of \'DeNISTifying Technology,\' guiding attendees through paradigm shifts towards quantum encryption, advanced post-cryptography methods, and the evolving landscape of digital forensics. Discover innovative approaches and critical insights into securing our digital world beyond current standards. All experience levels are welcome to explore these cutting-edge topics.

\n\nSpeakerBio:  Aisha Berry, University of Maryland Global Campus
\n

Aisha Berry is a cybersecurity professional, PhD candidate, and experienced nurse with over 15 years in healthcare. They hold a Bachelor\'s in Cybersecurity and Computer Networking with a focus on digital forensics, and a Master\'s of Science in Digital Forensics and Cyber Investigations. Currently pursuing a doctoral program with a focus on healthcare, Aisha delves into the psychological component of technology, emphasizing the mindset of attackers in cybersecurity strategy.

\n\n\n\'',NULL,1296028),('3_Saturday','10','10:00','18:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_e3f0d3f3050bea6b89f1b75d6d97dc50','\'Title: Music - SomaFM
\nTags: Entertainment
\nWhen: Saturday, Aug 8, 10:00 - 18:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n

SomaFM is back in the Chillout Lounge– just off the atrium at the south entrance (W107-W109). SomaFM DJs including kampf, Rusty, Merin MC, djddead and special guests will provide the perfect soundtrack for hacking or relaxing. Stop by and say hello, and pick up a 2026 limited edition sticker. We\'ll also be broadcasting live on https://somafm.com/live/ – And did we mention, we have stickers!?

\n\nLinks:
    Live Broadcast - https://somafm.com/live/
\n\'',NULL,1296029),('3_Saturday','11','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_e3f0d3f3050bea6b89f1b75d6d97dc50','\'\'',NULL,1296030),('3_Saturday','12','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_e3f0d3f3050bea6b89f1b75d6d97dc50','\'\'',NULL,1296031),('3_Saturday','13','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_e3f0d3f3050bea6b89f1b75d6d97dc50','\'\'',NULL,1296032),('3_Saturday','14','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_e3f0d3f3050bea6b89f1b75d6d97dc50','\'\'',NULL,1296033),('3_Saturday','15','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_e3f0d3f3050bea6b89f1b75d6d97dc50','\'\'',NULL,1296034),('3_Saturday','16','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_e3f0d3f3050bea6b89f1b75d6d97dc50','\'\'',NULL,1296035),('3_Saturday','17','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_e3f0d3f3050bea6b89f1b75d6d97dc50','\'\'',NULL,1296036),('3_Saturday','18','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_e3f0d3f3050bea6b89f1b75d6d97dc50','\'\'',NULL,1296037),('2_Friday','10','10:00','18:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_4c0426cc9007c7743b822dbca3ce7293','\'Title: Music - SomaFM
\nTags: Entertainment
\nWhen: Friday, Aug 7, 10:00 - 18:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n

SomaFM is back in the Chillout Lounge– just off the atrium at the south entrance (W107-W109). SomaFM DJs including kampf, Rusty, Merin MC, djddead and special guests will provide the perfect soundtrack for hacking or relaxing. Stop by and say hello, and pick up a 2026 limited edition sticker. We\'ll also be broadcasting live on https://somafm.com/live/ – And did we mention, we have stickers!?

\n\nLinks:
    Live Broadcast - https://somafm.com/live/
\n\'',NULL,1296038),('2_Friday','11','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_4c0426cc9007c7743b822dbca3ce7293','\'\'',NULL,1296039),('2_Friday','12','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_4c0426cc9007c7743b822dbca3ce7293','\'\'',NULL,1296040),('2_Friday','13','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_4c0426cc9007c7743b822dbca3ce7293','\'\'',NULL,1296041),('2_Friday','14','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_4c0426cc9007c7743b822dbca3ce7293','\'\'',NULL,1296042),('2_Friday','15','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_4c0426cc9007c7743b822dbca3ce7293','\'\'',NULL,1296043),('2_Friday','16','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_4c0426cc9007c7743b822dbca3ce7293','\'\'',NULL,1296044),('2_Friday','17','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_4c0426cc9007c7743b822dbca3ce7293','\'\'',NULL,1296045),('2_Friday','18','10:00','18:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_4c0426cc9007c7743b822dbca3ce7293','\'\'',NULL,1296046),('4_Sunday','10','10:00','14:59','N','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_a0f102c2b54e1baf535fa87244251a5a','\'Title: Music - SomaFM
\nTags: Entertainment
\nWhen: Sunday, Aug 9, 10:00 - 14:59 PDT
\nWhere: LVCCW Level 1 W107-W109 (Chillout Lounge) - Map
\n
\nDescription:
\n

SomaFM is back in the Chillout Lounge– just off the atrium at the south entrance (W107-W109). SomaFM DJs including kampf, Rusty, Merin MC, djddead and special guests will provide the perfect soundtrack for hacking or relaxing. Stop by and say hello, and pick up a 2026 limited edition sticker. We\'ll also be broadcasting live on https://somafm.com/live/ – And did we mention, we have stickers!?

\n\nLinks:
    Live Broadcast - https://somafm.com/live/
\n\'',NULL,1296047),('4_Sunday','11','10:00','14:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_a0f102c2b54e1baf535fa87244251a5a','\'\'',NULL,1296048),('4_Sunday','12','10:00','14:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_a0f102c2b54e1baf535fa87244251a5a','\'\'',NULL,1296049),('4_Sunday','13','10:00','14:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_a0f102c2b54e1baf535fa87244251a5a','\'\'',NULL,1296050),('4_Sunday','14','10:00','14:59','Y','Social Gatherings/Events','LVCCW Level 1 W107-W109 (Chillout Lounge)','\'Music - SomaFM\'','\'\'','Social Gatherings/Events_a0f102c2b54e1baf535fa87244251a5a','\'\'',NULL,1296051),('4_Sunday','10','10:00','12:59','N','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_54b997b5dff5732af8a3eb74a4768d62','\'Title: CMD+CTRL Cyber Range: DarkMoney
\nTags: CMD+CTRL Cyber Range | Contest
\nWhen: Sunday, Aug 9, 10:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range) - Map
\n
\nDescription:
\n

CMD+CTRL is back for our 10th year and bringing something new to show. Drop by our cyber range for hands-on web application security challenges designed for all skill levels. Come to learn, come to compete, come to break things. All are welcome, whether it\'s your 1st CTF or your 101st.

\n\n

There is no pre-qualification, and the only participant prerequisite is \"Computer with internet access.\"

\n\nLinks:
    Website - https://defcon34.cmdnctrl.net/
\n\'',NULL,1296052),('4_Sunday','11','10:00','12:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_54b997b5dff5732af8a3eb74a4768d62','\'\'',NULL,1296053),('4_Sunday','12','10:00','12:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_54b997b5dff5732af8a3eb74a4768d62','\'\'',NULL,1296054),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_72accfe134bc216fd4a85b1be9f8731c','\'Title: CMD+CTRL Cyber Range: DarkMoney
\nTags: CMD+CTRL Cyber Range | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range) - Map
\n
\nDescription:
\n

CMD+CTRL is back for our 10th year and bringing something new to show. Drop by our cyber range for hands-on web application security challenges designed for all skill levels. Come to learn, come to compete, come to break things. All are welcome, whether it\'s your 1st CTF or your 101st.

\n\n

There is no pre-qualification, and the only participant prerequisite is \"Computer with internet access.\"

\n\nLinks:
    Website - https://defcon34.cmdnctrl.net/
\n\'',NULL,1296055),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_72accfe134bc216fd4a85b1be9f8731c','\'\'',NULL,1296056),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_72accfe134bc216fd4a85b1be9f8731c','\'\'',NULL,1296057),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_72accfe134bc216fd4a85b1be9f8731c','\'\'',NULL,1296058),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_72accfe134bc216fd4a85b1be9f8731c','\'\'',NULL,1296059),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_72accfe134bc216fd4a85b1be9f8731c','\'\'',NULL,1296060),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_72accfe134bc216fd4a85b1be9f8731c','\'\'',NULL,1296061),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_72accfe134bc216fd4a85b1be9f8731c','\'\'',NULL,1296062),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_a8953c4d4d2838099ec9746c0396ea97','\'Title: CMD+CTRL Cyber Range: DarkMoney
\nTags: CMD+CTRL Cyber Range | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range) - Map
\n
\nDescription:
\n

CMD+CTRL is back for our 10th year and bringing something new to show. Drop by our cyber range for hands-on web application security challenges designed for all skill levels. Come to learn, come to compete, come to break things. All are welcome, whether it\'s your 1st CTF or your 101st.

\n\n

There is no pre-qualification, and the only participant prerequisite is \"Computer with internet access.\"

\n\nLinks:
    Website - https://defcon34.cmdnctrl.net/
\n\'',NULL,1296063),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_a8953c4d4d2838099ec9746c0396ea97','\'\'',NULL,1296064),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_a8953c4d4d2838099ec9746c0396ea97','\'\'',NULL,1296065),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_a8953c4d4d2838099ec9746c0396ea97','\'\'',NULL,1296066),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_a8953c4d4d2838099ec9746c0396ea97','\'\'',NULL,1296067),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_a8953c4d4d2838099ec9746c0396ea97','\'\'',NULL,1296068),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_a8953c4d4d2838099ec9746c0396ea97','\'\'',NULL,1296069),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 405 (CMD+CTRL Cyber Range)','\'CMD+CTRL Cyber Range: DarkMoney\'','\'\'','Contests_a8953c4d4d2838099ec9746c0396ea97','\'\'',NULL,1296070),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_54ae45898dc13388123ce91c843453c1','\'Title: Radio Frequency Capture the Flag
\nTags: Radio Frequency Village | Radio Frequency Capture the Flag | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

In this game capture the flag you will be presented with real configurations of real wireless and radio technologies to attack. Practice your skill and learn new ones from Radio Frequency IDentification (RFID) through Software Defined Radio (SDR) and up to Bluetooth and WiFi. There may even be Infrared, if you have the eye for it.

\n\n

RF Hackers Sanctuary is once again holding the Radio Frequency Capture the Flag (RFCTF) at DEF CON 32. RFHS runs this game to teach security concepts and to give people a safe and legal way to practice attacks against new and old wireless technologies.

\n\n

We cater to both those who are new to radio communications as well as to those who have been playing for a long time. We are looking for inexperienced players on up to the SIGINT secret squirrels to play our games. The RFCTF can be played with a little knowledge, a pen tester\'s determination, and $0 to $$$$$ worth of special equipment. Our virtual RFCTF can be played completely remotely without needing any specialized equipment at all, just using your web browser! The key is to read the clues, determine the goal of each challenge, and have fun learning.

\n\n

This game doesn\'t let you sit still either, as there are numerous fox hunts, testing your skill in tracking various signals. If running around the conference looking for WiFi, Bluetooth, or even a Tire Pressure Monitoring System (TPMS) device sounds like fun, we are your source of a higher step count.

\n\n

There will be clues everywhere, and we will provide periodic updates via discord and twitter. Make sure you pay attention to what\'s happening at the RFCTF desk, #rfctf on our discord, on Twitter @rf_ctf, @rfhackers, and the interwebz, etc. If you have a question - ASK! We may or may not answer, at our discretion.

\n\nLinks:
    Scoreboard - https://scoreboard.rfhackers.com
\n    Website - https://rfhackers.com
\n\'',NULL,1296071),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_54ae45898dc13388123ce91c843453c1','\'\'',NULL,1296072),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_54ae45898dc13388123ce91c843453c1','\'\'',NULL,1296073),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_54ae45898dc13388123ce91c843453c1','\'\'',NULL,1296074),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_54ae45898dc13388123ce91c843453c1','\'\'',NULL,1296075),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_54ae45898dc13388123ce91c843453c1','\'\'',NULL,1296076),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_54ae45898dc13388123ce91c843453c1','\'\'',NULL,1296077),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_54ae45898dc13388123ce91c843453c1','\'\'',NULL,1296078),('4_Sunday','10','10:00','10:59','N','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_0473b0ecf3ee879f300ab6cd3264580e','\'Title: Radio Frequency Capture the Flag
\nTags: Radio Frequency Village | Radio Frequency Capture the Flag | Contest
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

In this game capture the flag you will be presented with real configurations of real wireless and radio technologies to attack. Practice your skill and learn new ones from Radio Frequency IDentification (RFID) through Software Defined Radio (SDR) and up to Bluetooth and WiFi. There may even be Infrared, if you have the eye for it.

\n\n

RF Hackers Sanctuary is once again holding the Radio Frequency Capture the Flag (RFCTF) at DEF CON 32. RFHS runs this game to teach security concepts and to give people a safe and legal way to practice attacks against new and old wireless technologies.

\n\n

We cater to both those who are new to radio communications as well as to those who have been playing for a long time. We are looking for inexperienced players on up to the SIGINT secret squirrels to play our games. The RFCTF can be played with a little knowledge, a pen tester\'s determination, and $0 to $$$$$ worth of special equipment. Our virtual RFCTF can be played completely remotely without needing any specialized equipment at all, just using your web browser! The key is to read the clues, determine the goal of each challenge, and have fun learning.

\n\n

This game doesn\'t let you sit still either, as there are numerous fox hunts, testing your skill in tracking various signals. If running around the conference looking for WiFi, Bluetooth, or even a Tire Pressure Monitoring System (TPMS) device sounds like fun, we are your source of a higher step count.

\n\n

There will be clues everywhere, and we will provide periodic updates via discord and twitter. Make sure you pay attention to what\'s happening at the RFCTF desk, #rfctf on our discord, on Twitter @rf_ctf, @rfhackers, and the interwebz, etc. If you have a question - ASK! We may or may not answer, at our discretion.

\n\nLinks:
    Scoreboard - https://scoreboard.rfhackers.com
\n    Website - https://rfhackers.com
\n\'',NULL,1296079),('2_Friday','11','11:00','17:59','N','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_b4321cf8fce5823354ed92fe49e5877b','\'Title: Radio Frequency Capture the Flag
\nTags: Radio Frequency Village | Radio Frequency Capture the Flag | Contest
\nWhen: Friday, Aug 7, 11:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

In this game capture the flag you will be presented with real configurations of real wireless and radio technologies to attack. Practice your skill and learn new ones from Radio Frequency IDentification (RFID) through Software Defined Radio (SDR) and up to Bluetooth and WiFi. There may even be Infrared, if you have the eye for it.

\n\n

RF Hackers Sanctuary is once again holding the Radio Frequency Capture the Flag (RFCTF) at DEF CON 32. RFHS runs this game to teach security concepts and to give people a safe and legal way to practice attacks against new and old wireless technologies.

\n\n

We cater to both those who are new to radio communications as well as to those who have been playing for a long time. We are looking for inexperienced players on up to the SIGINT secret squirrels to play our games. The RFCTF can be played with a little knowledge, a pen tester\'s determination, and $0 to $$$$$ worth of special equipment. Our virtual RFCTF can be played completely remotely without needing any specialized equipment at all, just using your web browser! The key is to read the clues, determine the goal of each challenge, and have fun learning.

\n\n

This game doesn\'t let you sit still either, as there are numerous fox hunts, testing your skill in tracking various signals. If running around the conference looking for WiFi, Bluetooth, or even a Tire Pressure Monitoring System (TPMS) device sounds like fun, we are your source of a higher step count.

\n\n

There will be clues everywhere, and we will provide periodic updates via discord and twitter. Make sure you pay attention to what\'s happening at the RFCTF desk, #rfctf on our discord, on Twitter @rf_ctf, @rfhackers, and the interwebz, etc. If you have a question - ASK! We may or may not answer, at our discretion.

\n\nLinks:
    Scoreboard - https://scoreboard.rfhackers.com
\n    Website - https://rfhackers.com
\n\'',NULL,1296080),('2_Friday','12','11:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_b4321cf8fce5823354ed92fe49e5877b','\'\'',NULL,1296081),('2_Friday','13','11:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_b4321cf8fce5823354ed92fe49e5877b','\'\'',NULL,1296082),('2_Friday','14','11:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_b4321cf8fce5823354ed92fe49e5877b','\'\'',NULL,1296083),('2_Friday','15','11:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_b4321cf8fce5823354ed92fe49e5877b','\'\'',NULL,1296084),('2_Friday','16','11:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_b4321cf8fce5823354ed92fe49e5877b','\'\'',NULL,1296085),('2_Friday','17','11:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Capture the Flag\'','\'\'','Contests_b4321cf8fce5823354ed92fe49e5877b','\'\'',NULL,1296086),('2_Friday','11','11:00','11:59','N','Contests','Online','\'Radio Frequency Capture the Flag\'','\'\'','Contests_ac262d462aa034ec30314857820b402e','\'Title: Radio Frequency Capture the Flag
\nTags: Radio Frequency Village | Radio Frequency Capture the Flag | Contest
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: Online
\n
\nDescription:
\n

In this game capture the flag you will be presented with real configurations of real wireless and radio technologies to attack. Practice your skill and learn new ones from Radio Frequency IDentification (RFID) through Software Defined Radio (SDR) and up to Bluetooth and WiFi. There may even be Infrared, if you have the eye for it.

\n\n

RF Hackers Sanctuary is once again holding the Radio Frequency Capture the Flag (RFCTF) at DEF CON 32. RFHS runs this game to teach security concepts and to give people a safe and legal way to practice attacks against new and old wireless technologies.

\n\n

We cater to both those who are new to radio communications as well as to those who have been playing for a long time. We are looking for inexperienced players on up to the SIGINT secret squirrels to play our games. The RFCTF can be played with a little knowledge, a pen tester\'s determination, and $0 to $$$$$ worth of special equipment. Our virtual RFCTF can be played completely remotely without needing any specialized equipment at all, just using your web browser! The key is to read the clues, determine the goal of each challenge, and have fun learning.

\n\n

This game doesn\'t let you sit still either, as there are numerous fox hunts, testing your skill in tracking various signals. If running around the conference looking for WiFi, Bluetooth, or even a Tire Pressure Monitoring System (TPMS) device sounds like fun, we are your source of a higher step count.

\n\n

There will be clues everywhere, and we will provide periodic updates via discord and twitter. Make sure you pay attention to what\'s happening at the RFCTF desk, #rfctf on our discord, on Twitter @rf_ctf, @rfhackers, and the interwebz, etc. If you have a question - ASK! We may or may not answer, at our discretion.

\n\nLinks:
    Scoreboard - https://scoreboard.rfhackers.com
\n    Website - https://rfhackers.com
\n\'',NULL,1296087),('4_Sunday','10','10:00','13:59','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f85a75459dfd13fd8178dd9b1bb31e83','\'Title: Radio Frequency Village Events
\nTags: Radio Frequency Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

In addition to the CTF and talks, which are elsewhere on the schedule, the RF Village is also a place to hang out and chat with like minded folks who share your interests.

\n\nLinks:
    Website - https://rfhackers.com
\n    Scoreboard - https://scoreboard.rfhackers.com/
\n\'',NULL,1296088),('4_Sunday','11','10:00','13:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f85a75459dfd13fd8178dd9b1bb31e83','\'\'',NULL,1296089),('4_Sunday','12','10:00','13:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f85a75459dfd13fd8178dd9b1bb31e83','\'\'',NULL,1296090),('4_Sunday','13','10:00','13:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f85a75459dfd13fd8178dd9b1bb31e83','\'\'',NULL,1296091),('2_Friday','10','10:00','17:59','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_c4a0a33cb900de0db262c7a03416b459','\'Title: Radio Frequency Village Events
\nTags: Radio Frequency Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

In addition to the CTF and talks, which are elsewhere on the schedule, the RF Village is also a place to hang out and chat with like minded folks who share your interests.

\n\nLinks:
    Website - https://rfhackers.com
\n    Scoreboard - https://scoreboard.rfhackers.com/
\n\'',NULL,1296092),('2_Friday','11','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_c4a0a33cb900de0db262c7a03416b459','\'\'',NULL,1296093),('2_Friday','12','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_c4a0a33cb900de0db262c7a03416b459','\'\'',NULL,1296094),('2_Friday','13','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_c4a0a33cb900de0db262c7a03416b459','\'\'',NULL,1296095),('2_Friday','14','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_c4a0a33cb900de0db262c7a03416b459','\'\'',NULL,1296096),('2_Friday','15','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_c4a0a33cb900de0db262c7a03416b459','\'\'',NULL,1296097),('2_Friday','16','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_c4a0a33cb900de0db262c7a03416b459','\'\'',NULL,1296098),('2_Friday','17','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_c4a0a33cb900de0db262c7a03416b459','\'\'',NULL,1296099),('3_Saturday','10','10:00','17:59','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f027bf8d82d448445039da03dc04a5d3','\'Title: Radio Frequency Village Events
\nTags: Radio Frequency Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

In addition to the CTF and talks, which are elsewhere on the schedule, the RF Village is also a place to hang out and chat with like minded folks who share your interests.

\n\nLinks:
    Website - https://rfhackers.com
\n    Scoreboard - https://scoreboard.rfhackers.com/
\n\'',NULL,1296100),('3_Saturday','11','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f027bf8d82d448445039da03dc04a5d3','\'\'',NULL,1296101),('3_Saturday','12','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f027bf8d82d448445039da03dc04a5d3','\'\'',NULL,1296102),('3_Saturday','13','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f027bf8d82d448445039da03dc04a5d3','\'\'',NULL,1296103),('3_Saturday','14','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f027bf8d82d448445039da03dc04a5d3','\'\'',NULL,1296104),('3_Saturday','15','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f027bf8d82d448445039da03dc04a5d3','\'\'',NULL,1296105),('3_Saturday','16','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f027bf8d82d448445039da03dc04a5d3','\'\'',NULL,1296106),('3_Saturday','17','10:00','17:59','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Radio Frequency Village Events\'','\'\'','Creator Events_f027bf8d82d448445039da03dc04a5d3','\'\'',NULL,1296107),('2_Friday','10','10:30','12:25','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'RF CTF Kick Off Day 1\'','\'RF Hackers\'','Creator Talks_61b5f390bbefeaf8e0ee9d95ce987eac','\'Title: RF CTF Kick Off Day 1
\nTags: Radio Frequency Village | Radio Frequency Capture the Flag | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:30 - 12:25 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Presentation to kick off the Radio Frequency Village CTF with helpful tips for new folks.

\n\nSpeakerBio:  RF Hackers, RF Hackers Sanctuary
\nNo BIO available
\n\nLinks:
    scoreboard.rfhackers.com/ - https://scoreboard.rfhackers.com/
\n\'',NULL,1296108),('2_Friday','11','10:30','12:25','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'RF CTF Kick Off Day 1\'','\'RF Hackers\'','Creator Talks_61b5f390bbefeaf8e0ee9d95ce987eac','\'\'',NULL,1296109),('2_Friday','12','10:30','12:25','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'RF CTF Kick Off Day 1\'','\'RF Hackers\'','Creator Talks_61b5f390bbefeaf8e0ee9d95ce987eac','\'\'',NULL,1296110),('2_Friday','12','12:30','13:25','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Let\'s BLESPlo.it the world together - introducing a new portable Bluetooth Low Energy security tool\'','\'Slawomir Jasek\'','Creator Talks_49cf44750f7254a1f46ce502946d7ddd','\'Title: Let\'s BLESPlo.it the world together - introducing a new portable Bluetooth Low Energy security tool
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:30 - 13:25 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Bluetooth Low Energy is absolutely everywhere - in billions of smart devices around us, largely remaining insecure. Most tools to audit it require a laptop, a bunch of dongles, and a pile of scripts often difficult to set up and troubleshoot. But the devices you\'re testing are mobile. They\'re in elevators, hospital wards, factory floors, and hotel rooms.\nMeet the new mobile tool: BLESPlo.it. Run the app on your phone standalone and you already have a capable BLE scanner, fingerprinter and a community-scripts powered remote control for the wireless world around you. Pair it with a small ESP32 companion device for significantly more options: low level scanning, cloning/simulating any BLE device in a few seconds, probing pairing modes, remote relays, and more!\nFinally try those latest attacks you never had the possibility to setup - no need to get the expensive/unavailable hardware any more. Just simulate any target in seconds and focus on the juicy details instead of fighting your toolchain. And thanks to the dynamic scripting engine you can easily write a custom attack logic on the fly. Share your cloned devices and scripts, let everyone learn from it.\nStill not convinced? Come see AI-boosted reversing shenanigans and live stunt hacking of dildos, shooting robots and even a Ferrari car!

\n\nSpeakerBio:  Slawomir Jasek, BLESPlo.it
\n

Seasoned trainer, speaker and IT security consultant with over two decades of expertise. Developed secure embedded systems certified to use by national agencies, participated in dozens assessments of systems, applications, firmware and hardware security for leading financial companies, largest manufacturers and innovative startups.\nCurrently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and provides training in regards to security of devices - based among others on contemporary electronic access control systems and smart locks.\nBeyond consulting on secure design for various software and hardware projects, impulsively acquires more and more BLE and NFC devices and enjoys reversing and breaking them.\nLoves sharing his knowledge via trainings, workshops, talks and open source hackme\'s (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.

\n\n\nLinks:
    blesplo.it - https://blesplo.it
\n\'',NULL,1296111),('2_Friday','13','12:30','13:25','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Let\'s BLESPlo.it the world together - introducing a new portable Bluetooth Low Energy security tool\'','\'Slawomir Jasek\'','Creator Talks_49cf44750f7254a1f46ce502946d7ddd','\'\'',NULL,1296112),('2_Friday','13','13:30','14:25','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Fox Hunting - Finding Rogue Access Points in the CTF and in the Wild\'','\'Eric Escobar\'','Creator Talks_2be6af8fcecaf57f6884118952ae7df9','\'Title: Fox Hunting - Finding Rogue Access Points in the CTF and in the Wild
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:30 - 14:25 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

What does the fox say? Turns out the fox says quite a lot, you just need to know how to listen! A \"fox\" is a hidden transmitter, in this case a WiFi access point. In this talk we\'ll go from basics to advanced fox hunting, covering: direction finding, antenna selection, channel scanning, refresh rate, remote sensors, mobile devices, staying stealthy so the fox never sees you, and working as a team. Not only is it a great DEFCON pastime, it\'s a real-world skill that lasts long after the con.

\n\nSpeakerBio:  Eric Escobar, Sophos - Red Team Lead
\n

Eric is a seasoned pentester and a Red Tech Lead at Sophos. On a daily basis he attempts to compromise large enterprise networks to test their physical, human, network and wireless security. He has successfully compromised companies from all sectors of business including: Healthcare, Pharmaceutical, Entertainment, Amusement Parks, Banking, Finance, Technology, Insurance, Military, Retail, Food Distribution, Government, Education, Transportation, Energy and Industrial Manufacturing.

\n\n

His team consecutively won first place at DEF CON 23, 24, and 25\'s Wireless CTF, snagging a black badge along the way. Forcibly retired from competing in the Wireless CTF, he now helps create challenges!

\n\n\n\'',NULL,1296113),('2_Friday','14','13:30','14:25','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Fox Hunting - Finding Rogue Access Points in the CTF and in the Wild\'','\'Eric Escobar\'','Creator Talks_2be6af8fcecaf57f6884118952ae7df9','\'\'',NULL,1296114),('2_Friday','14','14:30','14:55','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Security Vulnerabilities in SATCOM Devices\'','\'Aumkaareshwar DS\'','Creator Talks_c9d733493dbcab53ca0b38871aea234f','\'Title: Security Vulnerabilities in SATCOM Devices
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:30 - 14:55 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

This presentation delivers a deep-dive security analysis of satellite communication (SATCOM) systems, bridging the gap between theoretical vulnerabilities and hands-on, non-intrusive experimental observation. By examining representative broadband terminals and Low Earth Orbit (LEO) satellite phone systems, we dissect how architectural and implementation choices create distinct security risks across firmware, management interfaces, and radio-frequency (RF) communication layers.Using commodity Software-Defined Radio (SDR) hardware and open-source tools, we successfully executed passive RF observation experiments to characterize Iridium L-band downlink activity. The highlight of this session is the demonstration of an end-to-end pipeline that captured and reconstructed satellite voice transmissions, including emergency traffic, directly from the air.

\n\nSpeakerBio:  Aumkaareshwar DS
\n

I am a Computer Science graduate student at California State Polytechnic University, Pomona, passionate about cybersecurity, network security, and ethical hacking. Currently, I work as a Research Assistant at PolySec Lab, where I focus on 5G network security, including authentication, subscriber identity protection, and threat mitigation. My research helps enhance mobile security and protect data from cyber threats.

\n\n\n\'',NULL,1296115),('2_Friday','15','15:00','15:25','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Hack the Planet (not ours)\'','\'Abraxas3d\'','Creator Talks_a4ed0753e03437f4470ba5f72307b3fa','\'Title: Hack the Planet (not ours)
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:25 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

What does it take to bounce a signal off Venus and hear it back on Earth? Quite a lot, actually. And we\'re going to show all of it to you.

\n\n

In 2008, AMSAT-DL aimed a carrier wave from a dangerously powerful magnetron-based transmitter, located at the Bochum Observatory, at Venus. Four minutes later, they heard an echo. This was the first time amateurs had bounced a signal of any type off of another planet. This is a significant and enduring achievement.

\n\n

However, a radar signal has no information in it. It\'s a dead carrier. What does it take to bounce a communications signal off of Venus, and hear it back here on Earth? First of all, the path loss is immense. Then, Venus only returns about 13% of the signal that hits it. And, it\'s spinning. Information in a signal requires more signal to noise ratio when compared to a dead carrier, nd reflecting off a spinning surface damages information signals in particular ways that stationary reflectors do not.

\n\n

Venus and Earth encounter each other in their orbits only once every 18 months or so. This is the inferior conjunction of the two planets. Unlike the Moon, frequently used by radio enthusiasts as a reflector, Venus is barely close enough every 18 months for the largest amateur and citizen science dishes to reach. This makes timing, preparation, and coordination equally as important as resolving the technical challenges.

\n\n

What are the different parts of an Earth-Venus-Earth digital communications system? Which parts make the most difference? What needed to be developed? How did coordination go? What will happen next? Come to the talk and find out how we are going to Hack a Planet.

\n\n

Quite a lot, actually. And we\'re going to show all of it to you.

\n\nSpeakerBio:  Abraxas3d, CEO ORI
\n

Michelle Thompson, W5NYV, is the CEO of Open Research Institute, a 501(c)(3) nonprofit developing open source digital radio and space communication systems. ORI\'s work directly benefits the amateur radio and amateur radio satellite services. She served as IEEE San Diego Section Chair and represents ORI on the FCC Technological Advisory Council, including co-chairing the AI/ML Safe Uses Sub-Working Group. Her technical background spans RF engineering, digital signal processing, FPGA development, and satellite communications, with prior industry experience at Qualcomm, Smithville Telephone, and Apiary. She can be reached at w5nyv@arrl.net.

\n\n\nLinks:
    Github - https://github.com/OpenResearchInstitute/EVE
\n\'',NULL,1296116),('2_Friday','15','15:30','16:25','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'AI-assisted RF Hacking with GNU Radio\'','\'Erwin Karincic (Dollarhyde)\'','Creator Talks_9b0fcaaedf8351be49f2187001a4638a','\'Title: AI-assisted RF Hacking with GNU Radio
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 16:25 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Software defined radios have lowered the barrier to RF experimentation, but GNU Radio still requires a working knowledge of blocks, port types, sample rates, hardware drivers, and connection rules. This talk presents an AI-assisted GNU Radio design system that lets a user describe an RF task in natural language, then uses a large language model to build, validate, and organize the resulting flowgraph through structured tool calls.

\n\n

Direct LLM-generated GNU Radio code often looks plausible but fails in practice. Blocks may be incompatible, parameters may be invalid, connections may not match, and visual flowgraphs may be arranged in ways that make them difficult to inspect or modify. This system addresses those problems by exposing GNU Radio through validated tools for block discovery, hardware detection, flowgraph creation, parameter configuration, connection management, layout, and code generation. Before producing the final design, it checks port types, stream and message domains, vector lengths, and incompatible signal paths. When blocks cannot be connected directly, it recommends the required conversion blocks instead of generating a broken flowgraph.

\n\n

This presentation will show the system live through practical SDR and RF security workflows. The goal is to make GNU Radio flowgraph development faster to use when exploring wireless systems, validating assumptions, and moving from an RF idea to a working flowgraph.

\n\nSpeakerBio:  Erwin Karincic (Dollarhyde)
\n

Erwin is an experienced security researcher specializing in both hardware and software reverse engineering, binary analysis, and exploit development across a range of processor architectures. He has notable experience in implementing complex Radio Frequency (RF) waveforms using Software Defined Radios (SDRs) for cybersecurity applications, complemented by his proficiency in designing, simulating, and fabricating antennas tailored for such applications. His past work includes extensive TCP/IP networking experience, designing worldwide secure communication systems. Erwin holds a number of prestigious certifications, including OSCP, OSCE, OSWE, OSEE, and CCIE Enterprise Infrastructure.

\n\n\nLinks:
    Github - https://github.com/Dollarhyde/gr-mcp
\n\'',NULL,1296117),('2_Friday','16','15:30','16:25','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'AI-assisted RF Hacking with GNU Radio\'','\'Erwin Karincic (Dollarhyde)\'','Creator Talks_9b0fcaaedf8351be49f2187001a4638a','\'\'',NULL,1296118),('2_Friday','16','16:30','16:55','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Supertooth: Wideband Bluetooth Observation with a HackRF\'','\'Dalton Cox\'','Creator Talks_39fd1d5379e4e7914c9fb2612265044d','\'Title: Supertooth: Wideband Bluetooth Observation with a HackRF
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:30 - 16:55 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Modern Bluetooth environments are inherently difficult to observe. Classic piconets frequency-hop 1,600 times per second, forcing sniffers to choose between tracking a single connection or losing visibility across the spectrum. Supertooth is an open-source, C-based SDR platform built on the HackRF that eliminates this tradeoff. Instead of traditional hop-following, it captures a fixed 20 MHz slice of the 2.4 GHz band, fanning the raw IQ stream into parallel per-channel demodulation workers. This approach provides simultaneous, real-time visibility into up to 20 BR/EDR channels at once.

\n\n

Each worker runs an independent GFSK demodulation pipeline powered by liquid-dsp, feeds decoded bitstreams into access-code correlators, and hands matching frames to libbtbb for UAP recovery and HEC-based clock tracking, all without needing to know a piconet’s future frequency hops. Supertooth also features a hybrid mode that decodes a Bluetooth low energy advertising channel concurrently from the same 20 MHz stream, exposing advertising data alongside classic piconet activity in a unified view. Per-role RSSI separation further allows researchers to distinguish central and peripheral transmission patterns from passive observation alone.

\n\n

This talk walks through the tool end-to-end, detailing how Supertooth improves on traditional single-channel workflows like those used by the Ubertooth. We will demonstrate the platform live, discuss current recovery capabilities and the limitations of passive clock tracking, and outline a roadmap for future development. The project is open-source, and the build requires only a HackRF, libhackrf, liquid-dsp, and libbtbb.

\n\nSpeakerBio:  Dalton Cox, Security Researcher at Skinny R&D
\n

Dalton Cox is a security researcher at Skinny Research & Development in Huntsville, Alabama, where he develops applied AI and various tooling for cybersecurity operations. He is concurrently studying Computer Engineering at the University of Alabama in Huntsville. In his spare time, he plays strategy and card games, experiments with audio gear, and dabbles in a variety of musical instruments.

\n\n\nLinks:
    Github - https://github.com/daltoncox/supertooth
\n\'',NULL,1296119),('2_Friday','17','17:00','17:55','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'WiFi Shuriken: A New Architecture For High Performance Scanning\'','\'CoD_Segfault\'','Creator Talks_9048594ca57f647e72c3df10248c35f4','\'Title: WiFi Shuriken: A New Architecture For High Performance Scanning
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:55 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

The WiFi Shuriken is a new microcontroller-based wardriving platform. The current iteration is a dual-band scanner built around a Raspberry Pi RP2350 for orchestration and six Espressif ESP32-C5 scanners. The Shuriken takes inspiration from several excellent projects in the wardriving community, but was designed around one goal: remove bottlenecks and scan as quickly and efficiently as possible.

\n\n

This talk will cover how the design distributes responsibilities across the system, moves scan data, deduplicates results, tolerates failures, and leaves room for future expansion. We’ll discuss why specific hardware was selected, and just as importantly, what was intentionally left out and why.

\n\nSpeakerBio:  CoD_Segfault, Hard Hat Brigade
\n

CoD_Segfault is a hardware hacker, wardriver, and retro-computing enthusiast. His projects usually center on custom electronics, embedded systems, and RF experimentation. He enjoys taking ideas from prototype to working hardware, especially when that means designing PCBs, abusing microcontrollers, or collecting wireless data in the real world. He is also part of the Hard Hat Brigade, where his builds often involve questionable ideas and putting things on his head that probably don\'t belong there.

\n\n\nLinks:
    Github - https://github.com/CoD-Segfault/wifi-shuriken
\n\'',NULL,1296120),('3_Saturday','10','10:30','12:25','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'RF CTF Kick Off Day 2\'','\'RF Hackers\'','Creator Talks_9b1c55fc50cc733384e703a7279df486','\'Title: RF CTF Kick Off Day 2
\nTags: Radio Frequency Village | Radio Frequency Capture the Flag | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:30 - 12:25 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Presentation to kick off the Radio Frequency Village CTF with helpful tips for new folks.

\n\nSpeakerBio:  RF Hackers, RF Hackers Sanctuary
\nNo BIO available
\n\nLinks:
    scoreboard.rfhackers.com/ - https://scoreboard.rfhackers.com/
\n\'',NULL,1296121),('3_Saturday','11','10:30','12:25','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'RF CTF Kick Off Day 2\'','\'RF Hackers\'','Creator Talks_9b1c55fc50cc733384e703a7279df486','\'\'',NULL,1296122),('3_Saturday','12','10:30','12:25','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'RF CTF Kick Off Day 2\'','\'RF Hackers\'','Creator Talks_9b1c55fc50cc733384e703a7279df486','\'\'',NULL,1296123),('3_Saturday','12','12:30','13:25','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Neotropolis: The Making of the Railgun Trackers\'','\'John O\'Connor\'','Creator Talks_6c2cc5ab22eea4f993c8b4417a710286','\'Title: Neotropolis: The Making of the Railgun Trackers
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 13:25 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Neotropolis is an annual 5-day cyberpunk festival in the California High Desert. In this talk, I\'ll present the technology behind the \"Railgun Runner\" game, which used Bluetooth Discovery Beacons and low-cost ESP32 hardware to conduct \"good-enough\" proximity tracking in an RF-adversarial environment. I\'ll demonstrate the trackers live in person, and discuss the techniques used, technical challenges and trade-offs, effective distance and calibration techniques, and how this technology can be applied to a broader set of problems.

\n\nSpeakerBio:  John O\'Connor, Panasonic Avionics Corp
\n

I\'m just a hacker that loves building cool stuff and showing people how it works. Aerospace industry software engineer and radio enthusiast.

\n\n\n\'',NULL,1296124),('3_Saturday','13','12:30','13:25','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Neotropolis: The Making of the Railgun Trackers\'','\'John O\'Connor\'','Creator Talks_6c2cc5ab22eea4f993c8b4417a710286','\'\'',NULL,1296125),('3_Saturday','13','13:30','13:55','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'This is a Test: Vibe Hacking LTE Cell Broadcast for Emergency Alert Injection\'','\'XtraRaj\'','Creator Talks_4c23954b0e4cd15f1765c2b4ec3a6bd0','\'Title: This is a Test: Vibe Hacking LTE Cell Broadcast for Emergency Alert Injection
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 13:55 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Every month, billions of mobile subscribers worldwide receive Presidential Alerts, AMBER alerts, earthquake warnings, and severe weather notifications directly to their phones through the 3GPP Public Warning System (PWS). This encompasses CMAS, ETWS, and EU-Alert. These messages bypass all user settings, cannot be blocked, and are trusted implicitly by the public. But what if the tower screaming at your phone isn\'t a tower at all?

\n\n

This talk exposes the fragile trust model underlying emergency alerting on modern LTE networks globally. We dissect how PWS messages are transported at the physical and protocol layers, from SIB10/11/12 broadcast blocks down to the exact ASN.1 encoding, and demonstrate how an attacker with modest RF resources can inject, spoof, and manipulate these alerts at scale using software-defined radio.

\n\n

We\'ll begin with a technical primer on PWS architecture in LTE, explaining how Cell Broadcast Service (CBS) messages propagate from alert aggregators through carrier core networks to individual eNodeBs, and ultimately to handsets worldwide via the BCCH. Then we shift to the offensive perspective: using a USRP B210 and open-source LTE stacks, we show how to craft malicious SIB messages, impersonate legitimate carrier cells, and force target devices to display arbitrary alert text, including spoofed presidential alerts and hyper-localized fake emergency notifications.

\n\n

The presentation includes live demonstrations, open-source release of our PWS injection toolkit, and a discussion of responsible disclosure findings shared with carriers and regulators across multiple countries. No prior LTE expertise is required, but familiarity with SDR concepts and cellular architecture will help attendees maximize their takeaways.\nAttendees will leave understanding exactly why global wireless emergency alerting lacks cryptographic authentication, how trivial the barrier to entry is for alert spoofing.

\n\nSpeakerBio:  XtraRaj, Mechanic, Car Hacking Village
\n

Ayyappan is a cybersecurity enthusiast interested in hacking and securing everything from wireless, automotive, IoT security, and critical infrastructure. He has published several high-impact CVEs relating to the automotive and IoT sectors and loves to tinker with every electronic device he can get his hands on. Notably, he once successfully turned a doorbell into a botnet that rickrolls visitors.

\n\n\nLinks:
     inspired from this paper: https://www.purdue.edu/newsroom/archive/releases/2018/Q1/attacks-on-4g-lte-networks-could-send-fake-emergency-alerts.html - Research inspired from this paper: https://www.purdue.edu/newsroom/archive/releases/2018/Q1/attacks-on-4g-lte-networks-could-send-fake-emergency-alerts.html
\n\'',NULL,1296126),('3_Saturday','14','14:00','14:55','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'RASM: A State Machine Methodology for RF Security Assessment\'','\'Smriti Gaba\'','Creator Talks_b2332d55e7fc1a16c9e35b79e2a8783b','\'Title: RASM: A State Machine Methodology for RF Security Assessment
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:55 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

RF security assessment is fundamentally different from traditional application or network testing. Signals are invisible, environmental conditions influence behavior, protocols are often undocumented, and even small physical changes can alter outcomes in unexpected ways. Unlike conventional targets, RF systems rarely expose stable interfaces, useful diagnostics, or predictable attack paths.\nThis talk introduces RASM (RF Attack State Machine), a methodology and state-aware research tool designed specifically for offensive RF investigations. Rather than treating assessment as a linear checklist, RASM models RF hacking as movement through interconnected operational states — from target understanding and signal discovery to demodulation, protocol analysis, manipulation, and validated exploitation.\nRASM operationalizes this methodology by helping researchers navigate RF investigations contextually. Information gathered during earlier stages influences recommendations, tooling choices, investigative paths, and subsequent transitions throughout the assessment process. Instead of attempting to automate RF analysis itself, the framework focuses on guiding researchers through the uncertainty and iterative decision-making that characterize real-world wireless security work.\nThe session includes a live walkthrough of the RASM tool, demonstrating how researchers move through assessment states against a real RF target. It is intended for security researchers, SDR practitioners, hardware hackers, and anyone exploring offensive RF methodology and wireless security research workflows.

\n\nSpeakerBio:  Smriti Gaba
\nNo BIO available
\n\n\'',NULL,1296127),('3_Saturday','15','15:00','15:55','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Drone ID on the Wire: RF Detection, Spoofing, and the Limits of Compliance-Based Airspace Awareness\'','\'Greg Albrecht\'','Creator Talks_1df178a0c7db99199afd6e31b430e404','\'Title: Drone ID on the Wire: RF Detection, Spoofing, and the Limits of Compliance-Based Airspace Awareness
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:55 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

The low-altitude airspace has an RF problem. The FAA mandated Remote ID as the foundational identification standard for drone operations across the United States - a broadcast protocol running on Bluetooth and WiFi that any phone is supposed to receive. The problem is that it was designed for individual accountability, not area surveillance, has a practical detection range measured in hundreds of meters, is completely unencrypted and unauthenticated, and is trivially spoofable with an ESP8266 and three dollars in hardware. Meanwhile the proprietary protocol it largely replaced - DJI\'s OcuSync Drone ID - was detectable at tens of kilometers, is now encrypted on newer hardware, and its primary detection product was discontinued. The gap between what practitioners think Remote ID provides and what it actually provides is a fundamental RF problem with direct public safety consequences.

\n\n

This talk lives in the RF layer. We will cover what drone broadcasts actually look like on a receiver - Remote ID over BLE advertising channels 37/38/39 and WiFi beacon frames on channels 6 and 149, DJI Drone ID embedded in OcuSync, and what non-broadcasting drones look like (nothing). We will walk through the full detection stack from a $50 COTS build (Ubiquiti Bullet M2, OpenWRT, tcpdump, Wireshark, OpenDroneID dissector) through man-portable dedicated receivers (DroneTag Rider), distributed mobile detection via ATAK plugins (Drone Hone), and enterprise fixed-site systems - and we will show real sensor performance data from multi-sensor deployments at major federal security operations. Key finding: 95.5% of unique drones detected across a SEAR 1 National Special Security Event were seen by only a single sensor. The multi-sensor fusion problem is unsolved at urban scale, and the urban RF environment - path loss, noise floor, building shadows — is why.\nWe will then walk through the spoofing ecosystem in depth. Ghost swarm attacks (jjshoots/RemoteIDSpoofer - 16 fake drones, web UI, $3 ESP8266), pilot location spoofing (brinuk/Remote-ID-Drone-and-Pilot-Spoofer - sends ground teams to empty parking lots), DJI Drone ID spoofing (DJISDKUser/ESP8266_DJI_DroneID_Throwie - Kevin Finisterre, taped to a fence, runs forever), and protocol-level implementations (cyber-defence-campus/droneRemoteIDSpoofer - Python/Scapy, ASTM F3411 plus DJI format, Swiss Cyber Defence Campus provenance). All public, all GitHub, all under $5 hardware. We will cover the attack taxonomy: evasion, flooding, identity spoofing, and operator location spoofing - and what each one means operationally for the detection stack.

\n\n

The legal layer is real and the audience should know it: 6 USC 124n authorizes four federal agencies to take action against drones. Nobody else can jam, spoof, or kinetically defeat without federal authority. The possession/testing/broadcasting distinction matters and we will be clear about it.

\n\n

We close with the governance gap: Remote ID\'s authentication-free design was a deliberate policy choice. The FAA Reauthorization Act of 2024 directed a review of whether cryptographic signing could be added. That review is ongoing. The people in this room build the tools that inform these conversations - this is the right audience to have opinions about what the answer should be.

\n\n

No policy background required. If you know what a waterfall is you are the target audience.

\n\nSpeakerBio:  Greg Albrecht
\nNo BIO available
\n\n\'',NULL,1296128),('3_Saturday','16','16:00','16:25','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'Yes, it runs Doom: over the air gaming on a bladeRF SDR\'','\'max\'','Creator Talks_aa981ca069a6f3f7e2c1272f6dd2d393','\'Title: Yes, it runs Doom: over the air gaming on a bladeRF SDR
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:25 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

This presentation will demo and discuss the development of a Doom port running on the Nuand BladeRF 2.0 micro xA9 Software Defined Radio.

\n\n

The BladeRF is designed for RF development, containing a Cyclone V FPGA and a radio frontend capable of up to 6GHz, but lacks a hard CPU and general-purpose memory, making it a strange and particularly entertaining candidate for a game port.

\n\n

This project combines FPGA design, customized firmware, RF-based video transmission, and wireless controller support. The talk will walk through system architecture, including the game engine port, how video signal is generated and transmitted, and how wireless controller input is handled. It will also cover the challenges, compromises, and unexpected findings that shaped the final design.

\n\nSpeakerBio:  max
\n

Max is an enthusiast of strange hardware, with particular interests in retro computing and game development. He\'s spent years restoring vintage game consoles and computers, experimenting with VR tracking interfaces, and building hardware projects to combine these interests.\nProfessionally, Max designs custom hardware for RF collection and security systems.

\n\n\nLinks:
    code, report and demos will be available at viamaximus.com - https://code, report and demos will be available at viamaximus.com
\n\'',NULL,1296129),('3_Saturday','16','16:30','17:25','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'I\'m Not Special, and You Can Too! A journey into RF Antenna Design for Dummies.\'','\'Hamspiced\'','Creator Talks_62c535d7af221a47f96028959c8efc46','\'Title: I\'m Not Special, and You Can Too! A journey into RF Antenna Design for Dummies.
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:30 - 17:25 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Take a walk with Hamspiced from Midwest Gadgets as he explains, with an appropriate amount of sarcasm and emotional damage, how to make an LC tank circuit from scratch.

\n\n

This talk will cover the basic theory behind inductance, capacitance, resonance, and why math has a terrible habit of being correct even when your prototype is not. From there, we will move into design, simulation, PCB layout, testing, tuning, and the deeply humbling process of discovering that “close enough” is absolutely not close enough at 13.56 MHz.

\n\n

Using open-source tools and real-world examples from Midwest Gadgets hardware, this talk follows the full maker journey: theory, design, prototyping, failure, more failure, brief hope, additional failure, and eventually something that works well enough to accidentally become a product.

\n\n

Attendees do not need to be RF engineers, electrical engineers, or people who enjoy reading datasheets for fun. This talk is meant for makers, hackers, badge builders, hardware weirdos, and anyone who has ever stared at a PCB and thought, “This should work,” immediately before it did not.

\n\n

By the end, you will understand the basic concepts behind LC tank circuits, how to approach designing one, what tools can help, what mistakes to expect, and why failure is less of a roadblock and more of a mandatory subscription service. Most importantly, you will see how open-source tools, persistence, and a questionable amount of stubbornness can turn a pile of bad revisions into working hardware.\"

\n\nSpeakerBio:  Hamspiced, Owner, Midwest Gadgets
\n

Hamspiced (Nick Gambino) is a maker, technologist, and founder of Midwest Gadgets LLC, where he designs hardware tools for hackers, makers, and security researchers. His work focuses on RF exploration, NFC systems, embedded development, wardriving, and open-source hardware.

\n\n

With a background in event and exposition technology leadership, Hamspiced combines hands-on engineering with practical product design and community-focused education. His work is driven by curiosity, accessibility, and the belief that understanding technology gives people greater agency.

\n\n\nLinks:
    Github - https://github.com/hamspiced/NFC-Resonant-Frequency-Amplifier This will be featured a lot as i walk through the specifics. The git has generalized information
\n\'',NULL,1296130),('3_Saturday','17','16:30','17:25','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'I\'m Not Special, and You Can Too! A journey into RF Antenna Design for Dummies.\'','\'Hamspiced\'','Creator Talks_62c535d7af221a47f96028959c8efc46','\'\'',NULL,1296131),('3_Saturday','17','17:30','17:55','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'$750 and a Weekend: Passive Direction Finding Across the Spectrum with KrakenSDR\'','\'K0YTL\'','Creator Talks_1aebb485e8713a7953e4dbda353e5fd0','\'Title: $750 and a Weekend: Passive Direction Finding Across the Spectrum with KrakenSDR
\nTags: Radio Frequency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 17:55 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Direction finding used to require expensive, specialized hardware. KrakenSDR changed that. For $749, you get a five-channel coherent software-defined radio that — paired with a custom pentagonal antenna array and open-source signal processing software on a Raspberry Pi — performs real-time passive direction of arrival estimation across 24 MHz to 1766 MHz.

\n\n

This talk is a practitioner\'s account of building and deploying this system across five field runs in Portland, OR. We cover the physics of coherent direction finding and why a single RTL-SDR can\'t do it, the hardware build and critical configuration details (including the Pi EEPROM settings that prevent the system from browning out in the field), and the full signal processing pipeline from IQ streams to triangulated fix. We present results from FM broadcast targets used as calibration ground truth, and from a 440 MHz amateur repeater in a dense urban environment where multipath degraded but did not defeat the system.

\n\n

The barrier to passive RF geolocation is no longer cost. It is knowledge. This talk lowers that barrier and releases the field data, post-processing scripts, and deployment checklist as open source.

\n\nSpeakerBio:  K0YTL
\n

Chris is a second-year PhD student at Portland State University where he teaches network and embedded security by day and points antennas at things by night. His current obsession is passive RF geolocation using multi-channel SDR arrays — specifically, building cheap open-source direction-finding infrastructure with KrakenSDR and a fleet of Raspberry Pis that may or may not be malfunctioning at any given moment. He holds an amateur radio license, has strong opinions about noise floors, and is perpetually one firmware update away from a working system. When not chasing signals through Pacific Northwest parks, he can be found explaining to a classroom why their pentest labs are on fire.

\n\n\n\'',NULL,1296132),('4_Sunday','10','10:00','11:55','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'WarDriver Meetup\'','\'\'','Creator Events_48964b09aeb5efd73b8f7e1c1afe1141','\'Title: WarDriver Meetup
\nTags: Radio Frequency Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 11:55 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1296133),('4_Sunday','11','10:00','11:55','Y','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'WarDriver Meetup\'','\'\'','Creator Events_48964b09aeb5efd73b8f7e1c1afe1141','\'\'',NULL,1296134),('4_Sunday','12','12:00','12:55','N','Radio Frequency Village','LVCCW Level 1 Hall 1 409 (Radio Frequency Village)','\'RF CTF and World Wide War Drive Outbrief\'','\'RF Hackers\'','Creator Talks_40217bcf27356f7bbc96552868f61490','\'Title: RF CTF and World Wide War Drive Outbrief
\nTags: Radio Frequency Village | Radio Frequency Capture the Flag | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:55 PDT
\nWhere: LVCCW Level 1 Hall 1 409 (Radio Frequency Village) - Map
\n
\nDescription:
\n

Final results of RF CTF announced!

\n\nSpeakerBio:  RF Hackers, RF Hackers Sanctuary
\nNo BIO available
\n\nLinks:
    scoreboard.rfhackers.com/ - https://scoreboard.rfhackers.com/
\n\'',NULL,1296135),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_4714643351d92b4ff34059273f7d7235','\'Title: Cryptid Hunt
\nTags: Cryptid Hunt | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 203 (Cryptid Hunt) - Map
\n
\nDescription:
\n

Something is already watching you.

\n\n

The Cryptid Hunt is a task-oriented challenge that moves agents across the conference floor toward a truth most attendees will never find. This is not a passive experience — each clue demands action, and the path forward is never obvious.

\n\n

Look carefully at what surrounds you. The next layer of any good mystery is always hiding beneath the surface. Patterns emerge for those paying attention. Signals exist for those who know how to listen.

\n\n

Is this a puzzle? A test? A hunt? At its core, this is a community experience that rewards curiosity, persistence, and the willingness to go further than most people will.

\n\n

The conference is your map. Maritime exploration, ancient communication, and the village of knowledge surrounding you are all part of the journey. Nothing here is coincidental.

\n\n

Finishers are recognized. What awaits those who complete the hunt will not be found anywhere else at this conference. Supplies are finite. So is your time.

\n\n

Your first clue is already in your hands.

\n\n

— The Cryptid Hunt Team

\n\n

Bureau of Unverified Phenomena · DC34

\n\n

Participant Prerequisites

\n\n
    \n
  • Smart Phone
  • \n
  • Desire to Learn
  • \n
  • Patience
  • \n
\n\n\'',NULL,1296136),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_4714643351d92b4ff34059273f7d7235','\'\'',NULL,1296137),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_4714643351d92b4ff34059273f7d7235','\'\'',NULL,1296138),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_4714643351d92b4ff34059273f7d7235','\'\'',NULL,1296139),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_4714643351d92b4ff34059273f7d7235','\'\'',NULL,1296140),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_4714643351d92b4ff34059273f7d7235','\'\'',NULL,1296141),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_4714643351d92b4ff34059273f7d7235','\'\'',NULL,1296142),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_4714643351d92b4ff34059273f7d7235','\'\'',NULL,1296143),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_8c97a26fa5ad85e4ffa4274ab549cfac','\'Title: Cryptid Hunt
\nTags: Cryptid Hunt | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 203 (Cryptid Hunt) - Map
\n
\nDescription:
\n

Something is already watching you.

\n\n

The Cryptid Hunt is a task-oriented challenge that moves agents across the conference floor toward a truth most attendees will never find. This is not a passive experience — each clue demands action, and the path forward is never obvious.

\n\n

Look carefully at what surrounds you. The next layer of any good mystery is always hiding beneath the surface. Patterns emerge for those paying attention. Signals exist for those who know how to listen.

\n\n

Is this a puzzle? A test? A hunt? At its core, this is a community experience that rewards curiosity, persistence, and the willingness to go further than most people will.

\n\n

The conference is your map. Maritime exploration, ancient communication, and the village of knowledge surrounding you are all part of the journey. Nothing here is coincidental.

\n\n

Finishers are recognized. What awaits those who complete the hunt will not be found anywhere else at this conference. Supplies are finite. So is your time.

\n\n

Your first clue is already in your hands.

\n\n

— The Cryptid Hunt Team

\n\n

Bureau of Unverified Phenomena · DC34

\n\n

Participant Prerequisites

\n\n
    \n
  • Smart Phone
  • \n
  • Desire to Learn
  • \n
  • Patience
  • \n
\n\n\'',NULL,1296144),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_8c97a26fa5ad85e4ffa4274ab549cfac','\'\'',NULL,1296145),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_7eb0e3f3653087b24a334868bc452b8b','\'Title: Cryptid Hunt
\nTags: Cryptid Hunt | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 203 (Cryptid Hunt) - Map
\n
\nDescription:
\n

Something is already watching you.

\n\n

The Cryptid Hunt is a task-oriented challenge that moves agents across the conference floor toward a truth most attendees will never find. This is not a passive experience — each clue demands action, and the path forward is never obvious.

\n\n

Look carefully at what surrounds you. The next layer of any good mystery is always hiding beneath the surface. Patterns emerge for those paying attention. Signals exist for those who know how to listen.

\n\n

Is this a puzzle? A test? A hunt? At its core, this is a community experience that rewards curiosity, persistence, and the willingness to go further than most people will.

\n\n

The conference is your map. Maritime exploration, ancient communication, and the village of knowledge surrounding you are all part of the journey. Nothing here is coincidental.

\n\n

Finishers are recognized. What awaits those who complete the hunt will not be found anywhere else at this conference. Supplies are finite. So is your time.

\n\n

Your first clue is already in your hands.

\n\n

— The Cryptid Hunt Team

\n\n

Bureau of Unverified Phenomena · DC34

\n\n

Participant Prerequisites

\n\n
    \n
  • Smart Phone
  • \n
  • Desire to Learn
  • \n
  • Patience
  • \n
\n\n\'',NULL,1296146),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_7eb0e3f3653087b24a334868bc452b8b','\'\'',NULL,1296147),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_7eb0e3f3653087b24a334868bc452b8b','\'\'',NULL,1296148),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_7eb0e3f3653087b24a334868bc452b8b','\'\'',NULL,1296149),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_7eb0e3f3653087b24a334868bc452b8b','\'\'',NULL,1296150),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_7eb0e3f3653087b24a334868bc452b8b','\'\'',NULL,1296151),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_7eb0e3f3653087b24a334868bc452b8b','\'\'',NULL,1296152),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 203 (Cryptid Hunt)','\'Cryptid Hunt\'','\'\'','Contests_7eb0e3f3653087b24a334868bc452b8b','\'\'',NULL,1296153),('2_Friday','10','10:30','16:30','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_b14d3479681a02f0d866cedc0c98d275','\'Title: Resume Review with the Lonely Hackers Club
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

Free, one-on-one resume reviews, run by people from this community who have actually hired and managed technical teams. No recruiters. No corporate fluff. Just honest feedback from people who have sat on both sides of the table and know what works.

\n\n

Sessions are 15 minutes. Walk up, sit down and get real feedback. Book your slot in advance or show up early to secure your spot if you missed the online registration.

\n\nLinks:
    Registration - https://tickets.lonelyhackers.club/resume/
\n    Link - https://lonelyhackers.club/resumereviews/
\n\'',NULL,1296154),('2_Friday','11','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_b14d3479681a02f0d866cedc0c98d275','\'\'',NULL,1296155),('2_Friday','12','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_b14d3479681a02f0d866cedc0c98d275','\'\'',NULL,1296156),('2_Friday','13','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_b14d3479681a02f0d866cedc0c98d275','\'\'',NULL,1296157),('2_Friday','14','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_b14d3479681a02f0d866cedc0c98d275','\'\'',NULL,1296158),('2_Friday','15','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_b14d3479681a02f0d866cedc0c98d275','\'\'',NULL,1296159),('2_Friday','16','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_b14d3479681a02f0d866cedc0c98d275','\'\'',NULL,1296160),('3_Saturday','10','10:30','16:30','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_7d8e26fc8650b12c66f493bd1bfbf685','\'Title: Resume Review with the Lonely Hackers Club
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

Free, one-on-one resume reviews, run by people from this community who have actually hired and managed technical teams. No recruiters. No corporate fluff. Just honest feedback from people who have sat on both sides of the table and know what works.

\n\n

Sessions are 15 minutes. Walk up, sit down and get real feedback. Book your slot in advance or show up early to secure your spot if you missed the online registration.

\n\nLinks:
    Registration - https://tickets.lonelyhackers.club/resume/
\n    Link - https://lonelyhackers.club/resumereviews/
\n\'',NULL,1296161),('3_Saturday','11','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_7d8e26fc8650b12c66f493bd1bfbf685','\'\'',NULL,1296162),('3_Saturday','12','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_7d8e26fc8650b12c66f493bd1bfbf685','\'\'',NULL,1296163),('3_Saturday','13','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_7d8e26fc8650b12c66f493bd1bfbf685','\'\'',NULL,1296164),('3_Saturday','14','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_7d8e26fc8650b12c66f493bd1bfbf685','\'\'',NULL,1296165),('3_Saturday','15','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_7d8e26fc8650b12c66f493bd1bfbf685','\'\'',NULL,1296166),('3_Saturday','16','10:30','16:30','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Resume Review with the Lonely Hackers Club\'','\'\'','Creator Events_7d8e26fc8650b12c66f493bd1bfbf685','\'\'',NULL,1296167),('3_Saturday','10','10:00','17:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_a554e8f15baaeae4475daef408349d40','\'Title: Lonely Hackers Club CTF
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

We welcome all skill levels, from first-time DEF CON attendees to experienced CTF competitors. The challenges are layered, so newcomers can get meaningful wins while veterans still find plenty to chew on. Participants often team up spontaneously on location, making it as much a social experience as a technical one. Participate for a chance to get awesome prizes!

\n\nLinks:
    More Info - https://lonelyhackers.club/ctf/
\n\'',NULL,1296168),('3_Saturday','11','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_a554e8f15baaeae4475daef408349d40','\'\'',NULL,1296169),('3_Saturday','12','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_a554e8f15baaeae4475daef408349d40','\'\'',NULL,1296170),('3_Saturday','13','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_a554e8f15baaeae4475daef408349d40','\'\'',NULL,1296171),('3_Saturday','14','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_a554e8f15baaeae4475daef408349d40','\'\'',NULL,1296172),('3_Saturday','15','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_a554e8f15baaeae4475daef408349d40','\'\'',NULL,1296173),('3_Saturday','16','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_a554e8f15baaeae4475daef408349d40','\'\'',NULL,1296174),('3_Saturday','17','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_a554e8f15baaeae4475daef408349d40','\'\'',NULL,1296175),('2_Friday','10','10:00','17:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_41a9ed11225a00b8098995f7246b3404','\'Title: Lonely Hackers Club CTF
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

We welcome all skill levels, from first-time DEF CON attendees to experienced CTF competitors. The challenges are layered, so newcomers can get meaningful wins while veterans still find plenty to chew on. Participants often team up spontaneously on location, making it as much a social experience as a technical one. Participate for a chance to get awesome prizes!

\n\nLinks:
    More Info - https://lonelyhackers.club/ctf/
\n\'',NULL,1296176),('2_Friday','11','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_41a9ed11225a00b8098995f7246b3404','\'\'',NULL,1296177),('2_Friday','12','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_41a9ed11225a00b8098995f7246b3404','\'\'',NULL,1296178),('2_Friday','13','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_41a9ed11225a00b8098995f7246b3404','\'\'',NULL,1296179),('2_Friday','14','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_41a9ed11225a00b8098995f7246b3404','\'\'',NULL,1296180),('2_Friday','15','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_41a9ed11225a00b8098995f7246b3404','\'\'',NULL,1296181),('2_Friday','16','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_41a9ed11225a00b8098995f7246b3404','\'\'',NULL,1296182),('2_Friday','17','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_41a9ed11225a00b8098995f7246b3404','\'\'',NULL,1296183),('4_Sunday','10','10:00','11:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_ef695523ef3feaf5b188facf02791420','\'Title: Lonely Hackers Club CTF
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

We welcome all skill levels, from first-time DEF CON attendees to experienced CTF competitors. The challenges are layered, so newcomers can get meaningful wins while veterans still find plenty to chew on. Participants often team up spontaneously on location, making it as much a social experience as a technical one. Participate for a chance to get awesome prizes!

\n\nLinks:
    More Info - https://lonelyhackers.club/ctf/
\n\'',NULL,1296184),('4_Sunday','11','10:00','11:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club CTF\'','\'\'','Creator Events_ef695523ef3feaf5b188facf02791420','\'\'',NULL,1296185),('4_Sunday','12','12:00','12:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - CTF Winners Announcement\'','\'\'','Creator Events_51a3914ca8b9c0caa048b1c3249bd6fb','\'Title: Lonely Hackers Club - CTF Winners Announcement
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n\n\n\'',NULL,1296186),('3_Saturday','10','10:00','17:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_c9a90a2496eced264ba2d2b2d321f5fd','\'Title: Lonely Hackers Club - Lockpicking Table
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

Learn new skills and find new friends at our lockpicking table. We provide you with beginner friendly locks, picks, and experienced volunteers to guide you through the process. Bring your own equipment to talk shop and get some new perspectives.

\n\nLinks:
    LHC Website - https://lonelyhackers.club/
\n\'',NULL,1296187),('3_Saturday','11','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_c9a90a2496eced264ba2d2b2d321f5fd','\'\'',NULL,1296188),('3_Saturday','12','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_c9a90a2496eced264ba2d2b2d321f5fd','\'\'',NULL,1296189),('3_Saturday','13','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_c9a90a2496eced264ba2d2b2d321f5fd','\'\'',NULL,1296190),('3_Saturday','14','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_c9a90a2496eced264ba2d2b2d321f5fd','\'\'',NULL,1296191),('3_Saturday','15','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_c9a90a2496eced264ba2d2b2d321f5fd','\'\'',NULL,1296192),('3_Saturday','16','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_c9a90a2496eced264ba2d2b2d321f5fd','\'\'',NULL,1296193),('3_Saturday','17','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_c9a90a2496eced264ba2d2b2d321f5fd','\'\'',NULL,1296194),('4_Sunday','10','10:00','13:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_2e433375ab52289b96fa00aedbb3a7b1','\'Title: Lonely Hackers Club - Lockpicking Table
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

Learn new skills and find new friends at our lockpicking table. We provide you with beginner friendly locks, picks, and experienced volunteers to guide you through the process. Bring your own equipment to talk shop and get some new perspectives.

\n\nLinks:
    LHC Website - https://lonelyhackers.club/
\n\'',NULL,1296195),('4_Sunday','11','10:00','13:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_2e433375ab52289b96fa00aedbb3a7b1','\'\'',NULL,1296196),('4_Sunday','12','10:00','13:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_2e433375ab52289b96fa00aedbb3a7b1','\'\'',NULL,1296197),('4_Sunday','13','10:00','13:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_2e433375ab52289b96fa00aedbb3a7b1','\'\'',NULL,1296198),('2_Friday','10','10:00','17:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_96465ac2a22e6c7a8e111ac0e212138c','\'Title: Lonely Hackers Club - Lockpicking Table
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

Learn new skills and find new friends at our lockpicking table. We provide you with beginner friendly locks, picks, and experienced volunteers to guide you through the process. Bring your own equipment to talk shop and get some new perspectives.

\n\nLinks:
    LHC Website - https://lonelyhackers.club/
\n\'',NULL,1296199),('2_Friday','11','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_96465ac2a22e6c7a8e111ac0e212138c','\'\'',NULL,1296200),('2_Friday','12','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_96465ac2a22e6c7a8e111ac0e212138c','\'\'',NULL,1296201),('2_Friday','13','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_96465ac2a22e6c7a8e111ac0e212138c','\'\'',NULL,1296202),('2_Friday','14','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_96465ac2a22e6c7a8e111ac0e212138c','\'\'',NULL,1296203),('2_Friday','15','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_96465ac2a22e6c7a8e111ac0e212138c','\'\'',NULL,1296204),('2_Friday','16','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_96465ac2a22e6c7a8e111ac0e212138c','\'\'',NULL,1296205),('2_Friday','17','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Lockpicking Table\'','\'\'','Creator Events_96465ac2a22e6c7a8e111ac0e212138c','\'\'',NULL,1296206),('2_Friday','10','10:00','17:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_c3fed0affc77d9a34e4d8756286cdd1b','\'Title: Lonely Hackers Club - Sticker Swap Table
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

DEF CON and stickers can\'t be separated. Visit our sticker swap table to get your hands on the latest sticky art and exchange the ones you made yourself. Check in regularly to get a chance to find rare gems.

\n\nLinks:
    LHC Website - https://lonelyhackers.club/
\n\'',NULL,1296207),('2_Friday','11','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_c3fed0affc77d9a34e4d8756286cdd1b','\'\'',NULL,1296208),('2_Friday','12','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_c3fed0affc77d9a34e4d8756286cdd1b','\'\'',NULL,1296209),('2_Friday','13','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_c3fed0affc77d9a34e4d8756286cdd1b','\'\'',NULL,1296210),('2_Friday','14','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_c3fed0affc77d9a34e4d8756286cdd1b','\'\'',NULL,1296211),('2_Friday','15','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_c3fed0affc77d9a34e4d8756286cdd1b','\'\'',NULL,1296212),('2_Friday','16','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_c3fed0affc77d9a34e4d8756286cdd1b','\'\'',NULL,1296213),('2_Friday','17','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_c3fed0affc77d9a34e4d8756286cdd1b','\'\'',NULL,1296214),('4_Sunday','10','10:00','13:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_e6f88d39f9f3831d340512916a825e85','\'Title: Lonely Hackers Club - Sticker Swap Table
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

DEF CON and stickers can\'t be separated. Visit our sticker swap table to get your hands on the latest sticky art and exchange the ones you made yourself. Check in regularly to get a chance to find rare gems.

\n\nLinks:
    LHC Website - https://lonelyhackers.club/
\n\'',NULL,1296215),('4_Sunday','11','10:00','13:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_e6f88d39f9f3831d340512916a825e85','\'\'',NULL,1296216),('4_Sunday','12','10:00','13:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_e6f88d39f9f3831d340512916a825e85','\'\'',NULL,1296217),('4_Sunday','13','10:00','13:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_e6f88d39f9f3831d340512916a825e85','\'\'',NULL,1296218),('3_Saturday','10','10:00','17:59','N','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_53a61bd8b244e9fc259f22538753cc65','\'Title: Lonely Hackers Club - Sticker Swap Table
\nTags: Lonely Hackers Club | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club) - Map
\n
\nDescription:
\n

DEF CON and stickers can\'t be separated. Visit our sticker swap table to get your hands on the latest sticky art and exchange the ones you made yourself. Check in regularly to get a chance to find rare gems.

\n\nLinks:
    LHC Website - https://lonelyhackers.club/
\n\'',NULL,1296219),('3_Saturday','11','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_53a61bd8b244e9fc259f22538753cc65','\'\'',NULL,1296220),('3_Saturday','12','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_53a61bd8b244e9fc259f22538753cc65','\'\'',NULL,1296221),('3_Saturday','13','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_53a61bd8b244e9fc259f22538753cc65','\'\'',NULL,1296222),('3_Saturday','14','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_53a61bd8b244e9fc259f22538753cc65','\'\'',NULL,1296223),('3_Saturday','15','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_53a61bd8b244e9fc259f22538753cc65','\'\'',NULL,1296224),('3_Saturday','16','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_53a61bd8b244e9fc259f22538753cc65','\'\'',NULL,1296225),('3_Saturday','17','10:00','17:59','Y','Lonely Hackers Club','LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)','\'Lonely Hackers Club - Sticker Swap Table\'','\'\'','Creator Events_53a61bd8b244e9fc259f22538753cc65','\'\'',NULL,1296226),('2_Friday','14','14:30','15:10','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Who Owns Your Shack? Open Source, Amateur Radio, and the Software We Can\'t Afford to Lose\'','\'Jeremy Banker - K0JLB\'','Creator Talks_0723ab106f5860e36b2b95485e9884c1','\'Title: Who Owns Your Shack? Open Source, Amateur Radio, and the Software We Can\'t Afford to Lose
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:30 - 15:10 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\n

A 30–40 minute talk for Ham Radio Village at Defcon. Primary audience is licensed amateur radio operators, with a secondary audience of hackers and security-minded attendees unfamiliar with the hobby. The talk uses the post-mortem license failure pattern in amateur radio software as motivating context, builds an ownership/self-reliance argument, and presents open-packet as a working existence proof of the open-source alternative.

\n\n

You own your radio. The protocols you use — AX.25 and APRS — are open standards anyone can implement. But the software your club depends on? That\'s often a different story.

\n\n

For the security-minded: this is a story about critical communication infrastructure running on software whose source code doesn\'t exist.

\n\n

Amateur radio has a long tradition of self-reliance: building your own antennas, maintaining your own gear, understanding your own stack. That tradition breaks down at the software layer. Too much of the tooling that holds the hobby together is maintained by a single developer, distributed as a closed binary, with no source code and no succession plan. We\'ve already seen what happens when that developer is gone: When Roger Barker G4IDE passed in 2004, UI-View32\'s source code went with him — leaving the community to maintain unofficial workarounds rather than fix the underlying binary, with the registration servers eventually going dark. Bob Bruninga WB4APR\'s death in 2022 raised the same question for his reference APRS implementations and the aprs.org site he maintained. These aren\'t edge cases — they\'re a pattern, and the hobby\'s aging demographics make it one we can\'t ignore.

\n\n

This talk makes the case that open-source licensing isn\'t just a software philosophy — it\'s an infrastructure resilience strategy. If a tool is critical to your club\'s operations or your emergency net, its source code needs to outlive its author.

\n\n

As a working example, we\'ll look at open-packet: an early-stage, MIT-licensed packet messaging client in Python — a working existence proof that the open-source path is viable. A brief live demo will show the basic functionality, along with some nice to have extras such as visual themes and a web client.

\n\n

Attendees will leave with a concrete lens for evaluating the software they depend on, a GitHub link, and three specific asks — from \"try it\" to \"apply this thinking to every tool in your shack.\"

\n\nSpeakerBio:  Jeremy Banker - K0JLB
\nBio: Jeremy Banker is a Senior Security Software Engineer at Horizon3.ai, focused on the reliability and resiliency of Horizon3\'s automated penetration testing platform. He previously spent nearly a decade at VMware, where he co-founded the Security Product Engineering group and led efforts to secure VMware\'s software supply chain. His open source security tooling, including Build Inspector for CI/CD pipeline anomaly detection and Tommyknocker for automated security control validation, has been featured at Black Hat Arsenal and DEF CON Demo Labs. A licensed amateur radio operator since 2010, he built open-packet, an MIT licensed Python client for packet messaging, after becoming frustrated with the existing closed-source options.
\n\n\n\n\n\'',NULL,1296227),('2_Friday','15','14:30','15:10','Y','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Who Owns Your Shack? Open Source, Amateur Radio, and the Software We Can\'t Afford to Lose\'','\'Jeremy Banker - K0JLB\'','Creator Talks_0723ab106f5860e36b2b95485e9884c1','\'\'',NULL,1296228),('2_Friday','13','13:00','13:59','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Ham Radio Isn’t Magic: Preppers, Sad Hams, and Practical Off-Grid Communications\'','\'Andrew Ohnstad - N3OCQ\'','Creator Talks_874bbe6b15ec95754f7eec6bf4815f6b','\'Title: Ham Radio Isn’t Magic: Preppers, Sad Hams, and Practical Off-Grid Communications
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\n

This talk approaches off-grid communications as a practical systems problem, informed by the author’s real-world operation of portable and off-grid radio systems rather than theory or gear marketing. Rather than teaching amateur radio as a hobby, it reframes off-grid communications using failure-mode analysis and systems design principles familiar to the security and hacking community. While the question “How do I talk 500 miles when the grid is down?” is a common starting point, the deeper issue is how communication systems behave when infrastructure is absent, degraded, or intentionally avoided — and why many well-intentioned plans fail in practice.

\n\n

The presentation is structured as a 101-level introduction for a technically curious audience. It assumes no prior amateur radio experience, but it does assume interest in understanding constraints, tradeoffs, and failure modes the same way hackers evaluate any other system operating outside ideal conditions.

\n\n

The talk opens by examining real examples from off-grid and preparedness communities, including common questions and the unhelpful responses they often attract. This framing establishes the core thesis: both “prepper fantasy” and “sad ham” gatekeeping optimize for the wrong constraints and lead to brittle designs that fail when conditions are imperfect.

\n\n

From there, the talk builds a mental model of off-grid radio communications grounded in physics and operational reality. Attendees are introduced to why radio performance is probabilistic rather than guaranteed, why a fixed distance like “500 miles” is a misleading requirement, and how factors such as propagation, noise floor, antenna efficiency, duty cycle, and coordination dominate outcomes more than transmitter power or radio model. Real failure modes are discussed, including HF voice links failing when expected to work, digital modes succeeding where voice does not, antenna quality overwhelming other variables, high-noise environments negating otherwise capable setups, and situations where increasing power does not meaningfully improve reliability.

\n\n

The scope then expands beyond emergencies to everyday off-grid use cases hackers actually encounter: group communications while hiking or camping without cell coverage, portable and battery-powered operation, short-range mesh and store-and-forward systems such as Meshtastic, and longer-range low-bandwidth HF messaging. Activities like Parks on the Air, Summits on the Air, and Field Day are presented not as hobbies, but as structured opportunities for exploration and experimentation — real-world environments for testing antennas, power systems, logistics, and coordination under off-grid constraints.

\n\n

Rather than focusing on specific products or modes, the talk emphasizes design principles that consistently work: simple plans over clever ones, redundancy across bands and modes, asynchronous messaging over real-time voice, and communication plans that account for human behavior as a primary constraint. Regulatory considerations are covered at a practical level to help attendees understand what is possible and appropriate without turning the talk into a licensing lecture.

\n\n

If appropriate for the venue, the talk may include a short demonstration or case study illustrating propagation variability or the effectiveness of low-bandwidth digital techniques compared to voice. Any demonstration will be designed with realistic fallback options and framed as illustrative rather than guaranteed.

\n\n

The goal of this talk is not to turn attendees into radio experts, but to give them a reusable framework for thinking about off-grid communications the way hackers think about resilient systems: define the actual problem, understand how and why things fail, and design solutions that work in imperfect, real-world environments.

\n\n

Every hacker has seen the post: someone asks what radio will let them “reliably talk 500 miles to family when the cell network goes down.” The replies quickly devolve into bad advice, magical thinking, and dismissive gatekeeping. The result is confusion, wasted money, and false confidence about off-grid communications.

\n\n

This talk is the antidote.

\n\n

We’ll cut through the mythology and explain what amateur radio can actually do for personal and family communication during major disruptions — and what it cannot. Starting at a 101 level, we’ll cover realistic ranges, basic propagation, equipment tradeoffs, digital modes, licensing myths, and why distance is usually the wrong requirement.

\n\n

Rather than dunking on preppers or policing fun like a sad ham, this talk reframes the problem the way hackers do: understanding constraints, failure modes, and human factors.

\n\n

We’ll focus on practical off-grid communication strategies that work in the real world — coordination, redundancy, and low-bandwidth messaging — not fantasy continent-spanning voice links.

\n\nSpeakerBio:  Andrew Ohnstad - N3OCQ
\n

Andrew has spent 25 years designing large-scale IT systems. He grew up alongside the birth of the internet, building his own computers, running a BBS, and taking electronics apart to understand how they worked. His interests remain firmly hands-on, focused on hardware tinkering and RF. He’s been a licensed amateur radio operator since 1993, holds an Amateur Extra license, and is active from VHF/UHF through 160 meters.

\n\n\n\'',NULL,1296229),('4_Sunday','10','10:00','11:30','N','Ham Radio Village','LVCCW Level 3 Balcony','\'\"Can it Ham\" Antenna Testing\'','\'The HRV Contest Team\'','Creator Events_94c96d158405b7d07407db01c77d71ba','\'Title: \"Can it Ham\" Antenna Testing
\nTags: Ham Radio Village | Can it Ham? | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 11:30 PDT
\nWhere: LVCCW Level 3 Balcony - Map
\n
\nDescription:
\n

Come check out the Can it Ham Final testing -- the best antennas get exposed to real world conditions to see just how well they radiate. Additional points will be awarded based on performance to truly determine...can it ham?

\n\n

Come check out the Can it Ham Final testing

\n\nSpeakerBio:  The HRV Contest Team
\nNo BIO available
\n\n\'',NULL,1296230),('4_Sunday','11','10:00','11:30','Y','Ham Radio Village','LVCCW Level 3 Balcony','\'\"Can it Ham\" Antenna Testing\'','\'The HRV Contest Team\'','Creator Events_94c96d158405b7d07407db01c77d71ba','\'\'',NULL,1296231),('3_Saturday','11','11:00','11:30','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Digital Modes 101: The Weird, Wonderful World of Computer Radio\'','\'Jon Marler (K4CHN)\'','Creator Talks_335c7e887312b2e92ed77234cdfffe43','\'Title: Digital Modes 101: The Weird, Wonderful World of Computer Radio
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\n

Digital communication has become one of the fastest-growing areas of amateur radio. By combining traditional radio equipment with computers and software, operators can send text messages, telemetry, position data, and even digitally encoded voice across the airwaves.

\n\n

This presentation introduces the fundamentals of amateur radio digital modes and how they work. We’ll begin by explaining the difference between analog and digital signals and how computers convert data into audio that radios can transmit.

\n\n

The talk then explores several widely used digital modes, including FT8 and WSPR for weak-signal communication, JS8Call for keyboard-to-keyboard messaging, and APRS for real-time position tracking and messaging. We’ll also look at newer developments such as LoRa-based APRS experimentation and open-source digital voice technologies like FreeDV and M17.

\n\n

Finally, we’ll discuss practical ways to get started with digital radio using affordable hardware, including simple USB radio interfaces, beginner-friendly radios, and lightweight portable setups.

\n\n

Attendees will leave with a clear understanding of how digital radio works and several easy paths to begin experimenting with digital modes themselves.

\n\n

Modern amateur radio is no longer just voice communication. Today, radios routinely exchange digital data, text messages, telemetry, and even machine-learning encoded voice signals.

\n\n

This talk introduces the world of amateur radio digital modes and explains how computers and radios work together to communicate using sound. We’ll explore some of the most popular digital modes used by operators today, including FT8, JS8Call, WSPR, APRS, and several emerging digital voice technologies.

\n\n

Attendees will learn what digital modes are, how they differ from traditional analog radio, and why they have become so popular. The session will also highlight new developments in the digital radio ecosystem, including open-source digital voice systems and long-range LoRa APRS experimentation.

\n\n

If you\'ve ever wondered what those strange buzzing sounds coming from a radio actually mean—or how to start experimenting with digital radio yourself—this talk will show you how to get started.

\n\nSpeakerBio:  Jon Marler (K4CHN)
\n

Jon Marler is a cybersecurity product director, hacker, and RF experimenter who enjoys building strange things that connect computers, radios, and networks together. By day he leads security products at VikingCloud focused on protecting global payment infrastructure. By night he experiments with mesh radio networks, hardware hacking, and unconventional communication systems. Jon is particularly interested in how radio and decentralized networks can complement modern security and resilience strategies.

\n\n\n\'',NULL,1296232),('2_Friday','11','11:00','11:30','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Meshtastic 101: Off-Grid Mesh Networking with LoRa\'','\'Jon Marler (K4CHN)\'','Creator Talks_237cfca038772e115fde8c7346cb83ba','\'Title: Meshtastic 101: Off-Grid Mesh Networking with LoRa
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\n

Meshtastic is an open-source project that enables decentralized, off-grid communication networks using inexpensive LoRa radios and microcontrollers. By combining long-range low-power radio technology with modern mobile apps and mesh networking protocols, Meshtastic makes it possible to build resilient communication networks without relying on cellular or internet infrastructure.

\n\n

This presentation provides an introduction to the Meshtastic ecosystem and the technologies that power it. Topics include the fundamentals of mesh networking, the basics of LoRa radio communication, and how Meshtastic integrates radios, ESP32-based devices, and smartphones into a distributed messaging platform.

\n\n

The talk will also cover common hardware platforms used in Meshtastic deployments, including DIY nodes and commercially available devices, and demonstrate how easy it is to set up and join a network.

\n\n

Finally, we’ll explore real-world applications for Meshtastic, including event communications, off-grid coordination, disaster response, and experimental hacker networks.

\n\n

Attendees will leave with a clear understanding of how Meshtastic works and what they need to begin experimenting with mesh radio networks themselves.

\n\n

Meshtastic has quickly become one of the most exciting new tools in the radio and hacker communities. Using inexpensive LoRa radios and open-source software, it allows anyone to build decentralized, off-grid messaging networks that work without cellular infrastructure or the internet.

\n\n

This talk introduces Meshtastic and the technologies that make it possible. We’ll cover the basics of LoRa radio, how mesh networking works, and how Meshtastic ties together radios, microcontrollers, and mobile apps into a simple communication platform.

\n\n

Attendees will learn what hardware is required, how easy it is to set up a node, and how Meshtastic networks are being used at events like DEF CON and in off-grid environments around the world.

\n\n

If you’re curious about building your own mesh network—or want to understand why everyone is suddenly carrying strange little radios—this session will show you how to get started.

\n\nSpeakerBio:  Jon Marler (K4CHN)
\n

Jon Marler is a cybersecurity product director, hacker, and RF experimenter who enjoys building strange things that connect computers, radios, and networks together. By day he leads security products at VikingCloud focused on protecting global payment infrastructure. By night he experiments with mesh radio networks, hardware hacking, and unconventional communication systems. Jon is particularly interested in how radio and decentralized networks can complement modern security and resilience strategies.

\n\n\n\'',NULL,1296233),('2_Friday','12','12:00','12:30','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Getting Started In Radio Direction Finding\'','\'Nate Moore\'','Creator Talks_17a6aa3bba71c345e957f7f568662557','\'Title: Getting Started In Radio Direction Finding
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\n

Radio Direction Finding (RDF) is one of the most practical and fun skills in amateur radio. This intro talk covers everything a beginner needs to know: low cost gear setups, building a simple Yagi antenna, and the techniques used to zero in on a transmitter.

\n\n

Entry level talk reviewing what foxhunting / radio direction finding is\nCovering the basic equipment requirements\nYagi antenna building\nBody fading\nMinimum equipment\nTips and tricks

\n\nSpeakerBio:  Nate Moore
\n

Nate Moore works in cybersecurity, holds an Extra class amateur radio license, and spends his spare time teaching, examining, and pushing signals around the ether.

\n\n\n\'',NULL,1296234),('2_Friday','15','15:30','16:18','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Advanced Topics in LoRa Meshes\'','\'Eric Escobar\'','Creator Talks_2befb3019d1fd1f7a5084d5d4f2154f1','\'Title: Advanced Topics in LoRa Meshes
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 16:18 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\nThis talk goes past the Meshtastic getting-started guides and into the advanced builds that push LoRa mesh networks to their limits: bridging MeshCore and Meshtastic so the two ecosystems can talk, rugged repeaters that survive the field, battery technology and enclosures for nodes that run for years, multi-channel concentrators, and high-altitude balloons that turn a handheld into a regional backbone. We\'ll also cover the human side, bridging separate mesh communities into one bigger network. Come for the range records, leave knowing how to build a network that outlives the grid.
\n\n

This talk goes past the Meshtastic getting-started guides and into the advanced builds that push LoRa mesh networks to their limits: bridging MeshCore and Meshtastic so the two ecosystems can talk, rugged repeaters that survive the field, battery technology and enclosures for nodes that run for years, multi-channel concentrators, and high-altitude balloons that turn a handheld into a regional backbone. We\'ll also cover the human side, bridging separate mesh communities into one bigger network.

\n\nSpeakerBio:  Eric Escobar, Sophos - Red Team Lead
\n

Eric is a seasoned pentester and a Red Tech Lead at Sophos. On a daily basis he attempts to compromise large enterprise networks to test their physical, human, network and wireless security. He has successfully compromised companies from all sectors of business including: Healthcare, Pharmaceutical, Entertainment, Amusement Parks, Banking, Finance, Technology, Insurance, Military, Retail, Food Distribution, Government, Education, Transportation, Energy and Industrial Manufacturing.

\n\n

His team consecutively won first place at DEF CON 23, 24, and 25\'s Wireless CTF, snagging a black badge along the way. Forcibly retired from competing in the Wireless CTF, he now helps create challenges!

\n\n\n\'',NULL,1296235),('2_Friday','16','15:30','16:18','Y','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Advanced Topics in LoRa Meshes\'','\'Eric Escobar\'','Creator Talks_2befb3019d1fd1f7a5084d5d4f2154f1','\'\'',NULL,1296236),('3_Saturday','12','12:00','12:30','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'So You Got Your License, Now What?\'','\'Danny Quist\'','Creator Talks_1e594076454d6d3e2a8c5665bb532419','\'Title: So You Got Your License, Now What?
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\n

Getting your ham radio license is the easy part. Figuring out what to do next? That\'s where most people get stuck. This talk is a practical, opinionated guide to the best rabbit holes in amateur radio: satellites, APRS, HF operating, digital modes, antenna experimentation, POTA, and the beautiful chaos of Field Day. Whether you got your ticket last week or you\'ve been meaning to upgrade for years, this is an opinionated romp through the hobby.

\n\n

We\'ll cover the stuff no one tells you after the exam: what the bands actually feel like, why FT8 will make you productive and vaguely empty inside, how much you can accomplish with $50 of wire and a willingness to climb things, and why learning to solder is basically a superpower. We\'ll also talk about getting off the couch comms for events and contests like POTA and ARRL Field Day are the most chaotic fun you can have with a radio legally.

\n\n

It\'s easy to listen, but things get more interesting when you start transmitting. Ham radio is one of the last hobbies that rewards you for actually understanding how it works. This talk is the map.

\n\n

You crammed, you passed, you got a callsign. And now your radio is sitting in a box while you wonder what you\'re actually supposed to do with it. This talk is a guided tour of the rabbit holes waiting for you on the other side of your license exam, organized by how deep you want to fall. Technician class? You can hit satellites with a handheld, track yourself on a map with APRS, or chase hidden transmitters through the woods with a directional antenna and questionable judgment. Upgrade to General and suddenly you\'ve got the HF bands: a global playground where you can work 200 countries in a weekend via a mode a Nobel laureate invented, argue with the laws of physics via antenna wire, and wage legal warfare against your HOA.

\n\nSpeakerBio:  Danny Quist
\n

Danny Quist has been a licensed amateur radio operator since he was 17, which is a really long time. Currently he is an extra class operator who gets to operate in his freetime working as CTO at Swarm Inc. He is a volunteer examiner with the ham radio village. His day job includes reverse engineering malware, forward engineering malware detonation systems, and management.

\n\n\n\'',NULL,1296237),('3_Saturday','16','16:00','16:45','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Keeping the Angry Pixies Happy: the Care and Feeding of your Batteries\'','\'hamster\'','Creator Talks_4b7c5f8552efb4ed25e6e6c9be696eb1','\'Title: Keeping the Angry Pixies Happy: the Care and Feeding of your Batteries
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\n

The talk will cover various battery types. For each type, we will cover such items as why you might want to use it, what the cost is, and most importantly, how do you charge/discharge it safely?

\n\n

While most of the batteries will be of the chemical variety, some mention will be made of mechanical batteries.

\n\n

Lead acid, nickel metal, lipo, lithium iron, silicon carbon? With all the different battery types out there now, how can you be sure you\'re keeping it functioning at its best, and not creating a ticking time bomb?

\n\n

This talk will cover the plethora of energy sources for off-grid radio operations and give tips for what works best and how to get the most out of it.

\n\nSpeakerBio:  hamster
\n

Passionate about electronics and energy storage

\n\n\n\'',NULL,1296238),('3_Saturday','14','14:30','14:59','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Ham Radio - Licensed to Experiment\'','\'Dan W0BDP Norte\'','Creator Talks_acd0cfa258707a9f6e6bee804391ea7f','\'Title: Ham Radio - Licensed to Experiment
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\n

The most common question we hear in the village is, \"What can I do now that I\'m licensed?\" N0OPS and W0BDP attempt the guide new hams into incorporating ham radio into their current hobbies or pursuing new interests.

\n\n

N0OPS and W0BDP will walk the audience through the diversity of ham radio operations such as portable activations such as POTA/SOTA, satellite contacts, digital weak-signal modes, direction-finding competitions, emergency communications, and drone telemetry.

\n\n

The takeaway: no matter how long you\'ve held a call sign whether it\'s 5-minutes or 5 years, there\'s almost certainly a corner of this hobby you haven\'t touched yet. This speech is an invitation to go find it.

\n\nSpeakerBio:  Dan W0BDP Norte
\n

Dan \"darkestofdans\" Norte (W0BDP) is a penetration tester, currently with NetSPI. Dan has been a ham radio operator for 9 years, currently Amateur Extra class. Dan enjoys popping shells and chasing DX.

\n\n\n\'',NULL,1296239),('3_Saturday','15','15:00','15:50','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Meshtastic Beasts and Where to Find Them\'','\'Scott Thompson\'','Creator Talks_7b378c7d2bf4ce849d4296b4ca13cc0f','\'Title: Meshtastic Beasts and Where to Find Them
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:50 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\n

Meshtastic is an open-source LoRa mesh used off-grid by preppers, hikers, event organizers, and amateur radio operators, and increasingly for protest logistics, disaster response, and other high-stakes comms, usually where people assume their traffic is private and their neighbors are who they claim to be. Those two assumptions are the subject of this talk. A shared channel key buys confidentiality for everyone who holds it and nothing else: not message integrity, not sender identity, not header privacy, not availability. The default key ships with every node, so for much of the mesh the wall is not there at all. None of this is a flaw. It is the threat model of a protocol built for simple, low-power text between people who already trust each other, and the talk treats it that way.

\n\n

To make that concrete, we hunt four beasts, each shown live. The Impersonator forges messages and node identities the mesh accepts as real, through AES-CTR ciphertext forgery and firmware-level source-ID spoofing. The Eavesdropper reads who is talking, when, and the shape of the network from cleartext headers with no key, and their location too on any channel still running the default key. The Saboteur breaks delivery for a chosen target by dropping its packets, rewriting hop limits, or decrypting, modifying, and re-encrypting traffic in transit. The Swarm exhausts the node database, only about a hundred slots on the boards we run, with ghost nodes and poisons the public map through the MQTT bridge. The active attacks run on a custom firmware fork whose features toggle at runtime and default to safe, with an on-device KILL ALL that resets everything to safe, so the live demos stay penned in our own isolated mesh. For the HAMs there is a sharper cut: licensed mode sets your callsign and transmits in the clear, and a callsign maps through public FCC records to a name and often an address, so a by-the-book node beacons your legal identity and rough location to a village full of people who can direction-find it. The point is not the regulation, it is the consequence.

\n\n

We also tell an honest story about how fast this came together: two developers who do not write firmware for a living built the firmware fork, a Python toolkit, and custom device-UI panels in about 16 working days (well, evenings) with heavy AI assistance. The one part that did not yield was the hardware, a radio regression that took old-fashioned diagnosis and a version pin, not a cleverer prompt. The attacker\'s effort floor collapsed; the hardware did not care, and that asymmetry applies to every volunteer-run protocol. So we close where it matters, with an opsec playbook drawn straight from the beasts: change the default key, verify identity and content out of band, assume broadcast, do not stake life-safety on availability, and match the tool to the threat (Meshtastic bought simplicity and adoption, Reticulum offers cryptographic identity and authenticated encryption by default, MeshCore sits between). Credit where due: Meshtastic already ships public-key DMs and signed admin messages, with cryptographic node identity in progress, and our hardening is offered as support for that trajectory, not a homework list for volunteers. Come find the beasts, then learn to live alongside them.

\n\n

Meshtastic does exactly what it says: it carries your text off-grid to whoever shares your channel key. The risk is what people assume it does on top of that. The mesh does not keep your secrets and does not vouch for your neighbors, and a growing number of people are betting real stakes on both, using it for protest logistics, disaster response, and off-grid safety where \"trusted friends on a channel\" is exactly the wrong threat model. We go looking for the beasts that live in that gap, impersonation, forgery, silent packet-dropping, traffic analysis, and node-database floods, each shown live on a real mesh with a custom firmware fork and a Python toolkit. The uncomfortable part is how little it took: two developers who do not write firmware for a living built the whole offensive stack with AI assistance in about 16 days of evenings. This is not a dunk on Meshtastic. It is a field guide to its actual threat model, and to operating like you know the difference.

\n\nSpeakerBio:  Scott Thompson
\n

Scott Thompson, KF5CPY, is a Cloud Architect for a motorsports team by day and a compulsive tinkerer by night, with a home lab full of Raspberry Pis, SBCs, and a backlog of HackerBox projects that will absolutely get soldered eventually. He earned his Technician license in 2019 for the most practical reason possible: surviving a back-country trip into the New Mexico desert without cell service. He has spent most of his career security-adjacent, doing the kind of remediation work that gives you strong opinions about how things break. This is his first conference talk.

\n\n\n\'',NULL,1296240),('3_Saturday','13','13:00','13:30','N','Ham Radio Village','LVCCW Level 3 W315 (Ham Radio Village)','\'Why Signals Still Matter: Amateur Radio in the Age of Cell Phones\'','\'Nate Moore\'','Creator Talks_16bcc796871e7bd93c5f363f6fe9b028','\'Title: Why Signals Still Matter: Amateur Radio in the Age of Cell Phones
\nTags: Ham Radio Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 3 W315 (Ham Radio Village) - Map
\n
\nDescription:
\nTopics covered:
\nWhy ham still matters, the philosophy of ham radio, cool stuff we\'re doing in the hobby with a focus on digital modes, how it\'s the original hacking hobby.
\nExtended info on software defined radio, GnuRadio.
\nTalk about how it\'s basically old school analog internet, and that everything we do on the modern internet network is possible on ham radio.
\n\n

We all have radios in our pockets. 5g, Bluetooth, and heck star-link up in the sky. Let\'s talk about why 100 year old tech is still relevant today, and why us hackers should care about ham radio when the internet is basically everywhere now.

\n\nSpeakerBio:  Nate Moore
\n

Nate Moore works in cybersecurity, holds an Extra class amateur radio license, and spends his spare time teaching, examining, and pushing signals around the ether.

\n\n\n\'',NULL,1296241),('3_Saturday','17','17:00','17:59','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Incident Response in 2026\'','\'Chriss Hansen,K Singh,Levone Campbell,Sarthak Taneja\'','Creator Talks_68cbac0e43f28cad1a2bd1caf0fce886','\'Title: Incident Response in 2026
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

Join us at the Blue Team Village for an interactive session on the shifting dynamics of Incident Response. As modern threat vectors evolve, security teams must actively adapt their core competencies and refine their playbooks. Our panel of practitioners will dive into practical strategies for navigating high-pressure environments-balancing technical depth with stakeholder management, and building resilience against burnout. We will discuss critical operational mistakes, the role of automation, and how to foster a collaborative IR community. Whether you are a seasoned responder or just starting your journey, gain actionable insights on advancing your IR career while maintaining your sanity.

\n\nSpeakers:Chriss Hansen,K Singh,Levone Campbell,Sarthak Taneja
\n
\nSpeakerBio:  Chriss Hansen
\n

Chriss Hansen is a seasoned Cyber Field Engineer at Pentera, with a background as a Digital Forensic Engineer and extensive experience in DFIR roles for various companies. He serves as an Incident Response Lead for the Wisconsin Cyber Response Team, leveraging his expertise to combat cyber threats. Prior to his cybersecurity career, he worked as a mattress salesman at Mattress Firm. Outside of work, he enjoys water polo, running, riding motorcycles, and playing the drums, showcasing his diverse interests beyond the tech world. He is also on the board for DC608: a non-profit educational group in Madison Wisconsin based on training and educating future cyber security experts.

\n\nSpeakerBio:  K Singh
\n

\"K\" Singh is a Senior Incident Response Consultant at Mandiant, where he helps Fortune 500 companies, leading enterprises, and a wide range of organizations navigate high-stakes cybersecurity incidents. With experience spanning large-scale incident response, tabletop exercises, strategic security planning, and hands-on “dead disk” forensics, K has seen just about everything under the sun—and then some.

\n\n

Before joining Mandiant, K served as a Senior Incident Response Consultant at CrowdStrike and as an Incident Response Consultant and Forensic Lab Manager with the Global Incident Response Practice at Cylance.

\n\n

When he’s not untangling cyber crises, K is usually elbows-deep in a car project—grumbling about questionable engineering decisions and breaking things that, by all logic, should never break.

\n\nSpeakerBio:  Levone Campbell, Chief Information Security Officer
\n

Levone Campbell, MBA, MPS, CISSP

\n\n

With more than two decades of experience in cybersecurity operations, Levone Campbell serves as a Cybersecurity Lead and Incident Coordinator, helping safeguard his organization’s digital environment through strategic defense and incident response.

\n\n

A seasoned information technology professional, Levone has developed deep expertise in cyber threat intelligence and cybercrime analysis, consistently anticipating and responding to emerging threats in an increasingly complex digital landscape. He has also expanded his focus to include the growing intersection of artificial intelligence and cybersecurity, with particular attention to the evolving challenges of AI-driven threats and defensive capabilities.

\n\n

Levone’s academic background includes dual bachelor’s degrees in Management and Marketing from North Carolina A&T State University, a Master of Business Administration from Walden University, and a Master of Professional Studies in Technology Management with a concentration in Cybersecurity from Georgetown University.

\n\n

His commitment to professional excellence is further demonstrated by his industry-recognized certifications, including the CISSP, which underscore his standing as a well-rounded cybersecurity leader.

\n\n

Based in Houston, Texas, Levone values the balance between a demanding career and a strong family life. Married for 20 years and a proud father of two, he brings discipline, perspective, and purpose to his work in protecting critical digital assets and advancing cyber resilience.

\n\nSpeakerBio:  Sarthak Taneja
\n

Started from Offensive Security and ended up in Defense. Wearing Purple hat most of the days.

\n\n\n\'',NULL,1296242),('3_Saturday','13','13:15','14:15','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Threat Intelligence in Real Life\'','\'Ashley Sequeira,Julian Zottl,Leigh Gilbert,Madeline Sedgwick\'','Creator Talks_afec83034c62c5e7efba54ae364e0086','\'Title: Threat Intelligence in Real Life
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:15 - 14:15 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

Correlation, causation, and the occasional compromise that cost us a weekend. This panel trades the talk slides for an open discussion of the realities of threat intelligence practice: the dead ends, the misread infrastructure, the cluster that fell apart under scrutiny, and the overlapping TTPs that finally tied things together. Our panel of practitioners engages the audience with real cases, separating nation-state from cybercrime by intent and tradecraft, tracking infrastructure, and catching the logical fallacies that quietly steer analysis wrong. We\'ll talk about how the work really gets done, where confident analysis quietly goes sideways, and the industry challenges on the horizon.

\n\nSpeakers:Ashley Sequeira,Julian Zottl,Leigh Gilbert,Madeline Sedgwick
\n
\nSpeakerBio:  Ashley Sequeira
\n

Ashley is a cybersecurity researcher, threat intelligence practitioner, and Senior Sales Engineer at Censys, where she conducts strategic research on IoT botnets and adversarial infrastructure. Her research sits at the intersection of hardware-based attack infrastructure and influence operations, tracking how low-cost consumer electronics are weaponized as residential proxy networks, ad fraud engines, and persistent footholds inside homes and enterprise networks.

\n\nSpeakerBio:  Julian Zottl
\n

Julian Zottl is the Chief Technology Officer for AzgardTek, an engineering company focused on Cyber and Intelligence. He’s the former CTO of Cyber Protection Solutions within Raytheon Intelligence & Space, a Raytheon Technologies business. He is also Cyber and Information Operations (IO) Subject Matter Expert (SME) and considered a world expert in large scale Computer Network Defense (CND).

\n\nSpeakerBio:  Leigh Gilbert, Malware village
\n

Leigh Trinity is a Canadian exploit developer, red team hacker, and instructor known for her work in binary exploitation and reverse engineering. Now branching out into malware development.

\n\nSpeakerBio:  Madeline Sedgwick
\n

Madeline Sedgwick is a Principal Threat Researcher at Palo Alto Networks Unit 42\'s National Security Team, focusing on South Asian threat actors and covert networks. In her 13 years of professional experience, Madeline has worked on all sides of the cyber front: military, government, and private sector. Her mission, inspired by years of ruined holiday weekends at the Department of Defense, is to make the other guys work the weekend.

\n\n\n\'',NULL,1296243),('3_Saturday','14','13:15','14:15','Y','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Threat Intelligence in Real Life\'','\'Ashley Sequeira,Julian Zottl,Leigh Gilbert,Madeline Sedgwick\'','Creator Talks_afec83034c62c5e7efba54ae364e0086','\'\'',NULL,1296244),('3_Saturday','15','15:45','16:45','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Threat Hunting Explained Badly\'','\'Alllison Gallo,Brian Baskin,Silas Cutler,Sydney \"letswastetime\" Marrone\'','Creator Talks_d4e65d8f93fef416e4b5b3a4d19b24d3','\'Title: Threat Hunting Explained Badly
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:45 - 16:45 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

Modern threat hunting is messy. AI lies. Telemetry sucks. Your vibe-coded query returns 12 million rows. Come hear hunters argue about what actually works, what doesn\'t, and whether any of us agree on what \"threat hunting\" even means.

\n\nSpeakers:Alllison Gallo,Brian Baskin,Silas Cutler,Sydney \"letswastetime\" Marrone
\n
\nSpeakerBio:  Alllison Gallo
\n

Allison Gallo is a staff incident responder on Splunk\'s Advanced Response Team, where she leads investigations end to end. She entered cybersecurity over a decade ago as a sysadmin at an MSSP, where every day brought a different client and environment, and has since worked as an analyst, consultant, and team lead across agriscience and software.

\n\n

Incident response is her home, but she\'s spent time working the other side of the same problem: hunting threats at large-scale events including the Super Bowl, GovWare Singapore, and RSAC. She\'s convinced the reactive and proactive halves of defense sharpen each other and every incident teaches you what to hunt for next. When not working, she\'s likely to be on a beach or mountain with her family.

\n\nSpeakerBio:  Brian Baskin
\n

Brian Baskin is a Threat Researcher for Sublime Security with a specialty in incident response, threat hunting, and malware analysis. Baskin was previously an intrusions analyst for the US Defense Cyber Crime Center (DC3) and a threat research lead at Carbon Black\'s Threat Analysis Unit (TAU). He has authored multiple security books and develops open source tools for more efficient IR and malware analysis.

\n\nSpeakerBio:  Silas Cutler
\n

Silas Cutler is a Principal Security Researcher at Censys, where he brings over a decade of experience tracking organized cyber threat groups and developing advanced methods for pursuing them. His research connects technical findings to the broader operations behind them, from attacker motivations to active campaigns, covering threats such as the BeaverTail malware tied to North Korea\'s covert IT-worker operations, the pro-Russian DDoSia (NoName057(16)) platform, and Secret Blizzard APT activity.

\n\n

Before Censys, Silas held roles focused on malware analysis, reverse engineering and adversary tracking, including Resident Hacker at Stairwell, Reverse Engineering Lead at Google Chronicle, and Senior Security Researcher on CrowdStrike\'s Intelligence team. Across these roles, he has specialized in analyzing tools built by nation-state and organized cybercrime groups and developing the methods needed to track them at scale. He is also an active contributor to the wider security research community, sharing his work through conference talks and open-source tooling.

\n\n

Silas is also the founder and lead developer of MalShare, a public malware repository that has provided the global security research community with free, open access to malware samples since 2013.

\n\nSpeakerBio:  Sydney \"letswastetime\" Marrone
\n

Sydney Marrone is a threat hunter, SANS course author, co-founder of THOR Collective, author of the Agentic Threat Hunting Framework (ATHF), and co-author of the PEAK Threat Hunting Framework. She is passionate about helping defenders become better threat hunters by turning complex ideas into practical, repeatable techniques. Through open-source research, workshops, and community-driven projects, Sydney builds frameworks and resources that make hunting more structured, collaborative, and effective. Outside of work, she writes for THOR Collective Dispatch, lifts weights, and makes cyber-inspired music with AI.

\n\n

--

\n\n

Sydney Marrone is a threat hunter, cybersecurity professional, co-founder of THOR Collective, author of the Agentic Threat Hunting Framework, and co-author of the PEAK Threat Hunting Framework. She is passionate about making security knowledge accessible and actionable through hands-on research, open-source collaboration, and community-driven projects like HEARTH (Hunting Exchange And Research Threat Hub). Sydney creates resources, leads workshops, and shares insights that spark curiosity and empower defenders. Outside of work, she writes for THOR Collective Dispatch, lifts weights, and makes cyber-themed music using AI to blend creativity and hacker culture.

\n\n\n\'',NULL,1296245),('3_Saturday','16','15:45','16:45','Y','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Threat Hunting Explained Badly\'','\'Alllison Gallo,Brian Baskin,Silas Cutler,Sydney \"letswastetime\" Marrone\'','Creator Talks_d4e65d8f93fef416e4b5b3a4d19b24d3','\'\'',NULL,1296246),('3_Saturday','14','14:30','15:30','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'AI Security: Hype, Hacks, and the Future of Defense\'','\'Karan Dwivedi,Thomas Roccia,Todd Fletcher,Nikki Robinson\'','Creator Talks_02c82ffd7ee89795192d2cff594f347a','\'Title: AI Security: Hype, Hacks, and the Future of Defense
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 15:30 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

It starts with a simple prompt.

\n\n

An AI assistant writes production code in seconds. A phishing email becomes nearly indistinguishable from a legitimate one. A security analyst uses an AI copilot to investigate hundreds of alerts—while an attacker uses the same technology to automate reconnaissance, create malware, and scale attacks.

\n\n

Welcome to the new reality of cybersecurity.

\n\n

AI is changing how we build, defend, attack, and trust technology. As organizations rapidly deploy AI applications and autonomous agents, defenders face two urgent questions: How can we use AI to defend better, and how do we secure AI itself?

\n\n

Join AI and cybersecurity practitioners for an honest discussion that separates hype from reality. Through real-world stories and practical insights, we’ll explore how attackers are using AI, how defenders are responding, what it means to secure AI systems, and where the industry is headed next.

\n\n

Whether you’re a seasoned blue teamer, security leader, AI enthusiast, or new to cybersecurity, you’ll leave with a clearer view of today’s AI security landscape—and what tomorrow’s defenders need to know.

\n\n

The future of cybersecurity is already here. Are you ready?

\n\nSpeakers:Karan Dwivedi,Thomas Roccia,Todd Fletcher,Nikki Robinson
\n
\nSpeakerBio:  Karan Dwivedi
\n

Karan Dwivedi is a recognized cybersecurity expert. Currently, he serves as a security engineering manager at Google. Karan has led large-scale security projects at Google and Yahoo in the US for products like Google Search, Google Assistant, Yahoo Mail, Yahoo Finance, Flickr, etc, to safeguard over a billion users. At Yahoo, he was part of the security team responding to the world’s largest data breach. He is the author of the book “Kickstart your security engineering career” which is a definitive guide for anyone looking to start a career in security engineering. Karan contributed to the latest internet standard for scoring vulnerabilities, the Common Vulnerability Scoring System (CVSS 4.0). He is featured in major media like Hakin9 Media Magazine, Forensic Focus News, etc. He has delivered talks at national and international conferences like Tech Ex North America, Tech Summit SF, BSides Las Vegas, National Cyber Summit, etc, to influence private and public sectors. Karan was featured as a subject matter expert in the Google Cybersecurity Certificate program launched in May 2023 on Coursera, which had an enrollment of over 41000 students in a few weeks. Furthermore, Karan has served as an advisor to startups, an editorial board member in international security journals, and judged global competitions. He holds a master’s degree in Information Security from Carnegie Mellon University, USA. His portfolio can be found at https://karand.me

\n\nSpeakerBio:  Thomas Roccia
\n

Thomas Roccia is the Founder and Threat Researcher at SecurityBreak, a company dedicated to AI Threat Intelligence and AI security. With more than 15 years of experience in cybersecurity, he has investigated major cyberattacks, led threat research at Microsoft and McAfee, collaborated with law enforcement, and helped organizations understand and respond to emerging threats.

\n\n

Speaker / Contributor: This individual participates in SANS events, presentations, written content, or other community resources as an external contributor. They are not a SANS employee, instructor, or affiliate.

\n\n

Since 2022, Thomas has focused on AI Threat Intelligence, researching how attackers target AI systems and how defenders can secure the growing AI ecosystem. He is recognized as one of the early pioneers in applying generative AI to cyber threat intelligence through practical research, open-source projects, and industry education.

\n\n

Thomas is the creator of several widely used open-source initiatives, including the Unprotect Project and NOVA, one of the first detection-rule frameworks for prompt pattern matching and AI security monitoring. NOVA won the SANS AI Cybersecurity Hackathon in 2025, and Thomas received the SANS Difference Makers Award (DMA) the same year for his contributions to the cybersecurity community. He is also the author of the bestselling book Visual Threat Intelligence: An Illustrated Guide for Threat Researchers, recipient of the Bronze Foreword INDIES Award in the Science & Technology category.

\n\n

A regular speaker at leading security conferences, including BlackHat, DEFCON, BSides, and SANS events, Thomas teaches AI Threat Intelligence to security professionals around the world, to help defenders apply AI to real-world investigations while understanding the risks attackers pose to the AI ecosystem.

\n\n

Through SecurityBreak, Thomas develops research, intelligence, and products that help organizations monitor, detect, and defend against attacks targeting AI models, agents, tools, and the broader AI ecosystem.

\n\nSpeakerBio:  Todd Fletcher
\n

Todd Fletcher (@kobaltfox) has spent 25 years on the defense side, running IT and security for public government, wiring up SIEM and SOAR pipelines, and building security programs that survive contact with a real budget. He works at CrowdStrike as an AI Services Technical Lead in Strategic Advisory Services, where a lot of his job is separating what AI actually does for a SOC from what the slide deck claims it does.

\n\n

He is also a PhD candidate in cyberpsychology at Birmingham City University (UK), studying the people doing the defending: what drives them, what burns them down, and why \"humans are the weakest link\" has always been a lazy answer. He writes at kobaltfox.com and toddmfletcher.com which starts from the position that defender mental health is a security outcome, not a wellness perk.

\n\nSpeakerBio:  Nikki Robinson, Security Architect & STSM at IBM
\n

Nikki is an STSM and Lead Architect at IBM, as well as a Professor of Practice at IBM. She holds a DSc in Cyber and a PhD in Human Factors. She has recently authored a book titled, Effective Vulnerability Management, a book that will be released in April 2024. She has over 15 years in IT Operations and cybersecurity, including vuln mgmt, network defense, security research, and incident response.

\n\n\n\'',NULL,1296247),('3_Saturday','15','14:30','15:30','Y','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'AI Security: Hype, Hacks, and the Future of Defense\'','\'Karan Dwivedi,Thomas Roccia,Todd Fletcher,Nikki Robinson\'','Creator Talks_02c82ffd7ee89795192d2cff594f347a','\'\'',NULL,1296248),('2_Friday','17','17:00','17:59','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Cloudy with a Chance of Venting: Managing Supply Chain Risk\'','\'Cassandra (muteki) Young,Christian Nicholson,David Collins,Kyle Dickinson,Ricky (0xpsilocyber) Banda\'','Creator Talks_4a4f27fd8dda21aab704187e14498338','\'Title: Cloudy with a Chance of Venting: Managing Supply Chain Risk
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

As organizations scale across a fragmented mix of SaaS, PaaS, and hyperscale environments, the enterprise attack surface is no longer fully under their control. Today’s threat actors aren\'t just targeting the cloud, they are weaponizing the cloud supply chain and exploiting these new dependencies. Bringing together diverse practitioner perspectives, this panel addresses the hard operational questions of modern cloud security.

\n\n

Our experts will break down the structural differences in evaluating risk across various cloud tiers, share proactive blueprints for hardening application supply chains, and debate the unique pitfalls of executing incident response when a critical SaaS provider or cloud asset is compromised.

\n\nSpeakers:Cassandra (muteki) Young,Christian Nicholson,David Collins,Kyle Dickinson,Ricky (0xpsilocyber) Banda
\n
\nSpeakerBio:  Cassandra (muteki) Young
\n

As a Principal Consultant on [REDACTED]\'s Cloud Technical Advisory team, muteki analyzes the organizational security posture of Azure, GCP and Oracle Cloud environments, and leads the development of data collection and analysis tooling. Additionally, she assists the Incident Response team as a technical GCP and OCI SME, and supports strategic advisory and technical tabletop exercises across multiple cloud platforms. In addition to her decade of IT and then cloud security consulting experience, muteki also holds a Master’s in Computer Science and is a director of Blue Team Village, a nonprofit organization bringing free Blue Team content to the community.

\n\nSpeakerBio:  Christian Nicholson
\n

Christian is a recognized technology leader specializing in cloud architectures and secure-by-design implementation. Maintaining deep technical expertise, Christian bridges the gap between IT, business teams, and users. A global speaker, advisor, and organizer for major IT and security conferences and global events, Christian also contributes to international policy through United Nations (UN) and global policy dialogues to shape secure digital ecosystems.

\n\nSpeakerBio:  David Collins
\n

Dave works to secure modern infrastructure and applications, with a focus on cloud-deployed systems.

\n\nSpeakerBio:  Kyle Dickinson
\n

Kyle D is a professional overthinker who’s spent years securing complex systems at scale without killing the fun. A former Threat Detection and Response specialist at {Cloud Provider Here), he now lives at the intersection of cloud, gaming, and security.

\n\nSpeakerBio:  Ricky (0xpsilocyber) Banda
\n

Hi!

\n\n

I am a incident responder with over 15 years of experience with a focus on incident management. I have worked at orgs from USAF, to Amazon, to Google, and have responded to a wide array of threats across the industry. Feel free to say hi after the panel, always happy to chat, discuss, share, and meet new folks!

\n\n\n\'',NULL,1296249),('2_Friday','15','15:45','16:45','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'The Modern Detection Engineer\'','\'Alex Hurtado,Chase Phelps,Chris Kulakowski,Christina Parry,Zack Allen\'','Creator Talks_cc3b8132b5b2f0dd1805641630111567','\'Title: The Modern Detection Engineer
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:45 - 16:45 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

Detection Engineering is a concept rooted in decades of blue teaming, but applied with a modern lens. At its core, it’s a practice where a blue teamer can apply principles across software engineering, security analysis, and data science to detect and respond to threats without needing to staff a traditional SOC. In 2026, this field is in the spotlight due to the meteoric growth of technology and AI, but like any field in security, it has its sharp edges and broken promises.

\n\n

In this panel, we will discuss Detection Engineering in 2026 with a diverse set of experts who work on these problems every day. We will cover topics around threat research and hunting, writing and maintaining a ruleset, modern CI/CD practices for blue teams & codifying incident response in security operations.

\n\nSpeakers:Alex Hurtado,Chase Phelps,Chris Kulakowski,Christina Parry,Zack Allen
\n
\nSpeakerBio:  Alex Hurtado
\n

Alex Hurtado spent years using, tuning, and implementing SIEMs across Fortune 500s and startups alike before landing as Head of Detection Strategy at Nebulock. She builds content on SIEM and detection engineering and hosts Detection Engineering Dispatch, a podcast bringing detection engineers together to compare notes and move the space forward.

\n\nSpeakerBio:  Chase Phelps
\n

Chase Phelps is a Senior Detection Engineering Manager at Marsh, leading detection, response automation, and AI/ML tooling for a large-scale SOC. He started his career in the IT space, working roles from Desktop support to System Engineer. He made the jump to Security starting in the SOC before making the move to Detection Engineering. Outside of work, he\'s likely to be found in the gym, on the golf course, or playing Old School Runescape.

\n\nSpeakerBio:  Chris Kulakowski
\n

Chris Kulakowski is a driven technologist, innovator, and tinkerer of all things. His career spans across 15 years of Digital Media, Information Technology, Security Operations, Threat Intelligence and Digital Forensics roles. He is currently a senior technical staff member specializing in threat detection at IBM, supporting IBM internal businesses. Prior to IBM he held various roles at General Motors and Optiv. He is seasoned in responding to incidents, developing new threat detection content, and an expert in EDR technology.

\n\n

Chris holds a Computer Criminology degree from Florida State University and several industry leading cyber security and digital forensics certifications including CISSP, EnCE, GCFE, GREM, GMON and Security+. Chris is also accredited with a Stanford University Advanced Computer Security Certificate and a member of the GIAC Advisory Board and author of 3 US patents.

\n\nSpeakerBio:  Christina Parry
\n

Christina Parry is a Staff Security Engineer at Huntress and a technical leader with 9+ years in tech and security, specializing in detection engineering, automation, and open-source software. She\'s experienced in building high-impact, scalable software solutions that automate everyday security workflows and elevate detection and response teams. Before Huntress, she was a Detection Engineer at Twitter and a member of the Threat Hunt team at Morgan Stanley. Christina is a mentor and ally for underrepresented groups in security, and sometimes comes out of her shell to nerd out about the things she cares about.

\n\nSpeakerBio:  Zack Allen
\n

Zack has been in the security field for 14 years. He started as a contractor for the Air Force then moved into the startup world before landing at Datadog. At Datadog, he built the security research and labs department and grew their security products and threat detection programs.

\n\n

He is also the creator of Detection Engineering Weekly, a Substack dedicated to detection engineering, incident response & threat intelligence.

\n\n\n\'',NULL,1296250),('2_Friday','16','15:45','16:45','Y','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'The Modern Detection Engineer\'','\'Alex Hurtado,Chase Phelps,Chris Kulakowski,Christina Parry,Zack Allen\'','Creator Talks_cc3b8132b5b2f0dd1805641630111567','\'\'',NULL,1296251),('4_Sunday','11','11:00','11:59','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'You\'re Hired... Maybe: Inside Cybersecurity Hiring in 2026\'','\'George Scheibe,Neha Gautam,Sherry Michael,Siddharth Kumar\'','Creator Talks_0c2d9b235babd4ec46e389237b68ea13','\'Title: You\'re Hired... Maybe: Inside Cybersecurity Hiring in 2026
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n\n\nSpeakers:George Scheibe,Neha Gautam,Sherry Michael,Siddharth Kumar
\n
\nSpeakerBio:  George Scheibe
\n

George received his lettermen jacket for Computer Science in high school and has been nerding out ever since. From a Multichannel Transmission Systems Operator-Maintainer in the US Army to the sole IT person for an entire resort, George has done everything from global network monitoring in command centers to toning out sea salt corroded POTS lines in crawl spaces.\nThese days though you\'ll fine him working in a SOC helping to develop the next generation of cyber security professionals.

\n\nSpeakerBio:  Neha Gautam
\n

Neha Gautam is a Product Manager at Microsoft Security and a Carnegie Mellon graduate specializing in the intersection of Identity and AI. From scaling platforms at Walmart to securing agentic AI at Microsoft, Neha’s mission is to translate complex security hurdles into seamless product experiences. She is a passionate mentor for women in tech and a frequent volunteer for WiCyS and Defcon Blue Team Village. Neha believes that the future of computing must be built by diverse perspectives—a philosophy she champions whether she\'s designing enterprise governance or coaching early-career professionals.

\n\nSpeakerBio:  Sherry Michael
\n

Sherry Michael is the security technical director for Information systems and computing at the University of Pennsylvania, a prestigious Ivy League university and research institution in Philadelphia. With more than thirty years of experience in information technology and over twelve years focused on cybersecurity, Sherry brings deep expertise in securing complex enterprise environments and fostering cross team collaboration.\nIn addition to technical leadership responsibilities, Sherry serves on hiring panels for a wide range of technical positions and acts as a hiring officer. She is passionate about identifying and developing the next generation of technology and security professionals.

\n\nSpeakerBio:  Siddharth Kumar
\n

Siddharth Kumar is the Offensive Security Lead at Ethical Intruder. He breaks into enterprise environments for a living, following attack paths through Active Directory, cloud infrastructure, web applications, and occasionally the strange world of operational technology. Previously, he led red team operations at EY and earned a master’s degree in information security from Carnegie Mellon University. Siddharth is particularly interested in identity attacks, advanced Web/API exploitation, adversary tradecraft, and the small security oversights that lead to very large compromises. When he is not breaking into things professionally, he enjoys helping other security practitioners develop their technical skills and navigate careers in offensive security.

\n\n\n\'',NULL,1296252),('2_Friday','10','10:00','10:59','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Incident Response 101: Preparing Before the Hack, Responding After It\'','\'Joshua Morgan\'','Creator Talks_20c4931b8016222e3905bcf98a9a5028','\'Title: Incident Response 101: Preparing Before the Hack, Responding After It
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

When an organization gets hacked, recovery is only part of the challenge. Security teams must quickly determine what happened, contain the threat, remove the attacker, and restore operations without allowing the incident to happen again. That work falls to incident responders, the cybersecurity professionals who investigate attacks, coordinate response efforts, and help organizations recover under pressure.

\n\n

This beginner-friendly session introduces the role of the incident responder and explains how incident response works across the major stages of preparation, detection, containment, eradication, recovery, and post-incident improvement. Attendees will leave with a practical understanding of what incident responders do, why their work matters, and how structured response processes help organizations reduce damage and improve resilience after a cyber incident.

\n\nSpeakerBio:  Joshua Morgan
\n

Joshua Morgan is a seasoned information security expert and passionate educator, dedicated to empowering the next generation of security professionals. With a strong background in the Blue Team realm, Joshua brings hands-on experience and real-world expertise to his work as an instructor at a local university, teaching advanced information security concepts to Masters-level students.

\n\n

As a respected speaker in the industry, Joshua has had the opportunity to share his knowledge with a wider audience, having presented at leading conferences such as DEF CON and BSides. His involvement in the security community extends beyond the stage, as he collaborates with fellow security enthusiasts and mentors newcomers to the industry.

\n\n

Joshua\'s commitment to security education and community outreach has made him a valuable asset to the industry, and his passion for securing all aspects of life continues to drive his work.

\n\n\n\'',NULL,1296253),('2_Friday','12','12:00','12:59','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Digital Forensics 101\'','\'Sarthak Taneja\'','Creator Talks_94512c00ccc83c930149b2b0e86c4d11','\'Title: Digital Forensics 101
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

Forensics 101 is a fast-paced, story-driven primer on digital investigations—perfect for incident-response newcomers and seasoned blue-teamers alike. In under 45 minutes we trace the full evidence lifecycle: imaging disks and cloud buckets, teasing meaning from volatile memory, and translating binary breadcrumbs into courtroom-ready narratives. First, we demystify the tools and techniques behind solid acquisition and analysis; next, we zoom out to the real-world team dynamics, reporting pitfalls, and career launchpads that turn analysts into trusted advisors. Expect war stories, practical tips you can use on Monday, and zero certification flexing—just the art, science, and occasional 2 a.m. data-center comedy of modern digital forensics.

\n\nSpeakerBio:  Sarthak Taneja
\n

Started from Offensive Security and ended up in Defense. Wearing Purple hat most of the days.

\n\n\n\'',NULL,1296254),('2_Friday','11','11:00','11:59','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Cyber Threat Intelligence 101: From Foundations to AI-Driven Defense\'','\'Carlo Anez Mazurco\'','Creator Talks_a969e9574ac844c7c1e337fff6580116','\'Title: Cyber Threat Intelligence 101: From Foundations to AI-Driven Defense
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

This talk is a fast-paced, vendor-neutral primer for defenders who want to turn raw telemetry into actionable intelligence. Threat intelligence is not just a feed — it is a discipline built through practice, structure, and action. This session introduces the CTI lifecycle, intelligence requirements, MITRE ATT&CK mapping, and the role of baselining in helping analysts separate normal activity from suspicious behavior.

\n\n

Attendees will also see how CTI becomes operational through practical blue-team workflows such as YARA and Sigma rule development, threat hunting, incident response, and purple-team validation. We will close by exploring how grounded AI workflows can accelerate enrichment, ATT&CK mapping, detection drafting, and analyst reporting while keeping humans responsible for validation, context, and final decisions.

\n\nSpeakerBio:  Carlo Anez Mazurco
\n

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

\n\n

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

\n\n

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

\n\n\n\'',NULL,1296255),('3_Saturday','11','11:00','11:59','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Threat Hunting 101: Beyond the Alerts\'','\'Kainu ~\'','Creator Talks_d18276f30a42e2de4f90f3bbb74c7924','\'Title: Threat Hunting 101: Beyond the Alerts
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

Detection and response are essential pillars of cybersecurity, but what if something slips through the cracks? Not every attack triggers an alert. That’s where Threat Hunting comes in.

\n\n

Threat hunting is a proactive, human-driven approach to uncovering signs of compromise that automated systems may have missed or misunderstood. It involves asking deeper questions, forming hypotheses, and exploring system behavior to find evidence of stealthy or novel attacks.

\n\n

Join us for an introductory presentation on Threat Hunting, where you\'ll learn how cybersecurity professionals go beyond known threats to uncover hidden adversaries and why human intuition is still a critical part of modern defense.

\n\nSpeakerBio:  Kainu ~
\n

With over 18 years of experience in IT and cybersecurity, Kainu currently specializes in Digital Forensics, Incident Response (DFIR), and Threat Hunting, with over 6 years dedicated to actively defending against threats, leading response efforts, and conducting deep forensic investigations. He has worked across diverse industries including healthcare, pharmaceutical, manufacturing, legal, and financial sectors, helping organizations detect, contain, and recover from complex security incidents. By day, he serves as a senior Incident Response case manager and consultant, conducting investigations, leading threat hunts, or mentoring clients on how to build and run effective incident response teams. He brings a hands-on, analytical approach to defending infrastructure and uncovering adversary tradecraft. Outside of work, Kainu is a passionate locksport practitioner and a proud #GirlDad, driven by curiosity, resilience, and a commitment to protecting what matters most.

\n\n\n\'',NULL,1296256),('3_Saturday','10','10:00','10:59','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'AI for Defenders 101\'','\'Anirudh Pratap Singh,Neha Gautam,Omenscan ~\'','Creator Talks_8c57a842c490a4d46b4a091e4aeaf4b8','\'Title: AI for Defenders 101
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n\n\nSpeakers:Anirudh Pratap Singh,Neha Gautam,Omenscan ~
\n
\nSpeakerBio:  Anirudh Pratap Singh
\n

Anirudh Pratap Singh works in IT security and support, with hands-on experience across cybersecurity operations, infrastructure, cloud systems, and user support. He holds a master’s degree in cybersecurity and is CompTIA Security+ certified. His main interests are blue team operations, SOC workflows, threat detection, and practical ways defenders can use AI in their day-to-day work. He enjoys solving real-world technical problems, building his skills through hands-on labs, and sharing what he learns with others in the security community.

\n\nSpeakerBio:  Neha Gautam
\n

Neha Gautam is a Product Manager at Microsoft Security and a Carnegie Mellon graduate specializing in the intersection of Identity and AI. From scaling platforms at Walmart to securing agentic AI at Microsoft, Neha’s mission is to translate complex security hurdles into seamless product experiences. She is a passionate mentor for women in tech and a frequent volunteer for WiCyS and Defcon Blue Team Village. Neha believes that the future of computing must be built by diverse perspectives—a philosophy she champions whether she\'s designing enterprise governance or coaching early-career professionals.

\n\nSpeakerBio:  Omenscan ~
\n

Some people write books to document and share what they learn. I write software. @Blueteamvillage Director. I do not speak for my employer, their clients, or customers

\n\n\n\'',NULL,1296257),('3_Saturday','12','12:00','12:59','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Cloud Forensics 101 : Ghost in the logs\'','\'Cassandra (muteki) Young,Dimple Gajra\'','Creator Talks_b3fbe734366aa6158630f4441ad2b3b5','\'Title: Cloud Forensics 101 : Ghost in the logs
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

Cloud breaches don\'t look like Hollywood hacking; they look like a leaked API key and a bot finding it before you\'ve finished your coffee. This introduction to cloud forensics talk walks through a real AWS attack path end-to-end: recon, initial access, privilege escalation, exfiltration, and impact. We\'ll cover the misconfigurations that actually get exploited in the wild, how to contain them, and close with a demo: a deliberately compromised AWS account, investigated using AI to turn raw CloudTrail logs into a clean incident timeline in minutes.

\n\nSpeakers:Cassandra (muteki) Young,Dimple Gajra
\n
\nSpeakerBio:  Cassandra (muteki) Young
\n

As a Principal Consultant on [REDACTED]\'s Cloud Technical Advisory team, muteki analyzes the organizational security posture of Azure, GCP and Oracle Cloud environments, and leads the development of data collection and analysis tooling. Additionally, she assists the Incident Response team as a technical GCP and OCI SME, and supports strategic advisory and technical tabletop exercises across multiple cloud platforms. In addition to her decade of IT and then cloud security consulting experience, muteki also holds a Master’s in Computer Science and is a director of Blue Team Village, a nonprofit organization bringing free Blue Team content to the community.

\n\nSpeakerBio:  Dimple Gajra
\n

Specializing in Digital Forensics, Incident Response (DFIR), and privacy engineering, Dimple Gajra (aka LocalHost) brings technical expertise to enterprise defense and data protection. Her professional journey includes engineering and response roles at major technology enterprises like IBM and Amazon\'s Security Incident Response Team (SIRT), where she has actively defended critical infrastructure, mitigated high-severity ransomware incidents, and engineered solutions to safeguard data privacy and automate secure detection pipelines. Driven by a hands-on, analytical approach to uncovering adversary tradecraft, she focuses on building architectural resilience, protecting sensitive user data, and translating complex system artifacts into actionable defensive strategies.

\n\n\n\'',NULL,1296258),('2_Friday','14','14:30','15:30','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Building Project Obsidian: Designing the Blue Team CTF for DEF CON\'','\'Carlo Anez Mazurco,Chris \"dafinga\" Maenner,Omenscan ~,Paul Goffar\'','Creator Talks_9ed00364e3a6b44091d88a89b85197e9','\'Title: Building Project Obsidian: Designing the Blue Team CTF for DEF CON
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:30 - 15:30 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

What does it take to build a realistic blue team training platform for thousands of DEF CON attendees? Join the engineers behind Project Obsidian as we discuss the architecture, design decisions, and lessons learned while building a cloud-native incident response and malware analysis CTF. We’ll cover Kubernetes, automation, AI-assisted challenge creation, scalable infrastructure, and the balance between realism and accessibility. Whether you’re interested in CTF design, defensive security, or modern platform engineering, this panel offers an inside look at how a community-driven project comes together.

\n\nSpeakers:Carlo Anez Mazurco,Chris \"dafinga\" Maenner,Omenscan ~,Paul Goffar
\n
\nSpeakerBio:  Carlo Anez Mazurco
\n

Carlo Anez Mazurco is a cybersecurity instructor, consultant, and community leader with more than 15 years of experience across security operations, threat intelligence, incident response, threat hunting, and detection engineering. He is the Founder of IgniteCyber Academy, a DEF CON Training instructor, and an active contributor to Blue Team Village, where he supports Project Obsidian and develops hands-on blue team content for the cybersecurity community.

\n\n

Carlo specializes in helping defenders translate attacker tradecraft into practical detection and response techniques while responsibly integrating artificial intelligence into modern security operations. His work focuses on creating realistic labs, CTF challenges, and immersive training environments that prepare students for real-world investigations using enterprise telemetry, cloud technologies, and AI-assisted workflows.

\n\n

He has delivered training and presentations for conferences, universities, government organizations, and commercial teams, with a passion for mentoring the next generation of cybersecurity professionals. His goal is to make complex security concepts approachable through practical demonstrations, collaborative learning, and hands-on exercises that participants can immediately apply in their own environments.

\n\nSpeakerBio:  Chris \"dafinga\" Maenner, Board Member at BSides Philadelphia
\n

Chris Maenner is the founder of Palmtree Ventures, where he spends his time helping startups and enterprises secure AI systems, Kubernetes, cloud platforms, and developer tooling without getting in the way of shipping software. Over the last 15+ years he’s bounced between startups and Fortune 50 companies building product security, platform security, and cloud security programs. Outside of work, Chris helps build CTFs and security projects with OWASP and DEF CON’s Blue Team Village (including Project Obsidian), serves on the board of BSides Philadelphia, contributes to the OWASP Secure Agent Playbook, and can usually be found speaking about AI security, Kubernetes, and whatever cloud-native security problem is keeping people up at night.

\n\nSpeakerBio:  Omenscan ~
\n

Some people write books to document and share what they learn. I write software. @Blueteamvillage Director. I do not speak for my employer, their clients, or customers

\n\nSpeakerBio:  Paul Goffar
\n

Paul Goffar is the founder of Raven Cybersecurity, doing offensive and defensive security consulting for small and mid-sized businesses. Day to day, he runs incident response, detection engineering, digital forensics, and threat intelligence for an enterprise SOC in the automotive sector.

\n\n

For the last five years, Paul has worked closely with Blue Team Village as an engineering lead for competitions and content delivery around the US, and does similar CTF and content work with CTF313, a Detroit-based team. He holds several industry certifications including GCIH, GMON, GNFA, CRTP, and paWASP. A father of three, a Metro Detroit native, and a hacker at heart, he continuously finds ways to give back to the community through mentoring and extensive volunteer work.

\n\n\n\'',NULL,1296259),('2_Friday','15','14:30','15:30','Y','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'Building Project Obsidian: Designing the Blue Team CTF for DEF CON\'','\'Carlo Anez Mazurco,Chris \"dafinga\" Maenner,Omenscan ~,Paul Goffar\'','Creator Talks_9ed00364e3a6b44091d88a89b85197e9','\'\'',NULL,1296260),('2_Friday','13','13:15','14:15','N','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'TBA\'','\'\'','Creator Talks_935581acac79a6fd668d947666d991ab','\'Title: TBA
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:15 - 14:15 PDT
\nWhere: LVCCW Level 2 W217 (Blue Team Village) Main Stage - Map
\n
\nDescription:
\n

TBA

\n\n\'',NULL,1296261),('2_Friday','14','13:15','14:15','Y','Blue Team Village','LVCCW Level 2 W217 (Blue Team Village) Main Stage','\'TBA\'','\'\'','Creator Talks_935581acac79a6fd668d947666d991ab','\'\'',NULL,1296262),('2_Friday','13','13:30','14:59','N','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'The Defender’s Dilemma: Releasing Dual-Use AI Models as Capabilities Climb\'','\'Emanuel Gawrieh,Jason Clinton,Bruce Schneier,Heather Adkins\'','DEF CON Talks_a63a56abc97ec898226dc53a78bf7cce','\'Title: The Defender’s Dilemma: Releasing Dual-Use AI Models as Capabilities Climb
\nTags: DEF CON Official Talk | AI Village
\nWhen: Friday, Aug 7, 13:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1 - Map
\n
\nDescription:
\n

Defenders and attackers are locked in a renewed race where AI has enabled new defenses and new attacks. AI models are gaining capability at a remarkable pace, and dual-use systems, powerful for defenders and adversaries alike in domains like cybersecurity, bring that trajectory into sharp focus. As these models grow stronger, developers face a practical question: How can defenders and labs each play a part in ensuring that defenders win?

\n\n

This panel takes up emerging best practices for applying and releasing dual-use models safely, from how teams evaluate a model\'s capabilities before release to the release-strategy choices that follow. Panelists will weigh approaches and how those decisions shift as capabilities advance. Looking ahead, the conversation will consider what the next wave of increasingly capable models means for safely deploying AI models and how developers can prepare now for the exponential to come.

\n\nSpeakers:Emanuel Gawrieh,Jason Clinton,Bruce Schneier,Heather Adkins
\n
\nSpeakerBio:  Emanuel Gawrieh, Co-Chair at AI Village
\n

Emanuel Gawrieh is a Senior Chaos Containment Engineer on the Advanced Threat Protection team at Google, where he specializes in architecting and proving out threat models for complex workloads in highly regulated environments. As a core member of Google\'s Secure AI Framework (SAIF) team, he works closely with Google AI Red Team, Google DeepMind, and the Cloud CISO\'s office to establish AI security standards - contributing to the early development and specialized fine-tuning of dual-use models like SecGemini to mitigate emerging AI-specific risks. Outside of his work at Google, he is a leading voice in AI Security policy and community evangelism - having presented at DEFCON, RSA and is an active member of the [un]prompted CFP board. Additionally, he has architected the infrastructure for several Generative AI Red Team events and actively advises congressional leaders on AI and cybersecurity policy.

\n\nSpeakerBio:  Jason Clinton, Deputy CISO at Anthropic
\n

Jason joined Anthropic in April 2023 as its first CISO after more than a decade at Google, where he most recently led Chrome infrastructure security working on defense against advanced persistent threats. While at Google, he also worked on ChromeOS and Android Pay. At Anthropic, Jason guides security strategy including detection and response, compliance, physical security, security engineering and IT. Jason promotes the security organization\'s work to uphold Anthropic\'s Responsible Scaling Policy framework, ensuring that the company has appropriate security safeguards in place for the responsible development and deployment of AI models. He is also the author of \"Ruby Phrasebook\".

\n\nSpeakerBio:  Bruce Schneier, Advisory Board Member at VerifiedVoting.org
\n

Bruce Schneier is an internationally renowned security technologist, called a “security guru” by the Economist. He is the New York Times best-selling author of 14 books – including Rewiring Democracy and A Hacker’s Mind -- as well as hundreds of articles, essays, and academic papers. His long-running newsletter and blog, “Schneier on Security,” is one of the most popular sources of cybersecurity news on the internet. Schneier is a Fellow and Lecturer in Public Policy at the Harvard Kennedy School and the Munk School at the University of Toronto. He is a fellow at the Berkman-Klein Center for Internet and Society at Harvard University, a board member of the Electronic Frontier Foundation and AccessNow, and an advisory board member of EPIC and VerifiedVoting.org. He is also the Chief of Security Architecture at Inrupt, Inc.

\n\nSpeakerBio:  Heather Adkins, Vice President of Security Engineering at Google
\n

Heather Adkins is a 24-year Google veteran and founding member of the Google Security Team. As VP, Security Engineering and head of Google’s Office of Cybersecurity Resilience she has built a global team responsible for maintaining the safety and security of Google’s networks, systems and applications. She has an extensive background in practical security, and has worked to build and secure some of the world’s largest infrastructure. She is co-author of Building Secure and Reliable Systems (O’Reilly, 2020), was deputy chair of CISA’s Cyber Safety Review Board, and has advised numerous organizations on how to adopt modern defendable architectures.

\n\n\n\'',NULL,1296263),('2_Friday','14','13:30','14:59','Y','DEF CON Talks','LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-1','\'The Defender’s Dilemma: Releasing Dual-Use AI Models as Capabilities Climb\'','\'Emanuel Gawrieh,Jason Clinton,Bruce Schneier,Heather Adkins\'','DEF CON Talks_a63a56abc97ec898226dc53a78bf7cce','\'\'',NULL,1296264),('2_Friday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'StarPWN CTF\'','\'\'','Contests_ad8c7d464ba7f8b9c5521b035dbf7479','\'Title: StarPWN CTF
\nTags: Aerospace Village | STARPWN (Aerospace Village CTF) | Contest
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Want to try your hand at hacking satellites, spacecraft and ground control systems? Miss out on Hack-A-Sat? Want to explore the final frontier of cybersecurity?

\n\n

STARPWN is the official Aerospace Village space hacking CTF! Backdoor flight computers, trojan flight software, exploit CVE\'s, reverse protocols, and more! During your space hacking journey, you’ll learn all about the environmental and operational constraints of space systems, how they affect cybersecurity posture, and impact exploitability.

\n\n

Register at https://starpwn.ctfd.io/

\n\n

Prizes to the highest finishing team the team that finishes quickest that can make it to the Aerospace Village in person by 1300 local time.

\n\nLinks:
    Registration - https://starpwn.ctfd.io/
\n\'',NULL,1296265),('2_Friday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'StarPWN CTF\'','\'\'','Contests_ad8c7d464ba7f8b9c5521b035dbf7479','\'\'',NULL,1296266),('3_Saturday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'StarPWN CTF\'','\'\'','Contests_7099c5c391ad1778e361d9ba983b19a6','\'Title: StarPWN CTF
\nTags: Aerospace Village | STARPWN (Aerospace Village CTF) | Contest
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Want to try your hand at hacking satellites, spacecraft and ground control systems? Miss out on Hack-A-Sat? Want to explore the final frontier of cybersecurity?

\n\n

STARPWN is the official Aerospace Village space hacking CTF! Backdoor flight computers, trojan flight software, exploit CVE\'s, reverse protocols, and more! During your space hacking journey, you’ll learn all about the environmental and operational constraints of space systems, how they affect cybersecurity posture, and impact exploitability.

\n\n

Register at https://starpwn.ctfd.io/

\n\n

Prizes to the highest finishing team the team that finishes quickest that can make it to the Aerospace Village in person by 1300 local time.

\n\nLinks:
    Registration - https://starpwn.ctfd.io/
\n\'',NULL,1296267),('3_Saturday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'StarPWN CTF\'','\'\'','Contests_7099c5c391ad1778e361d9ba983b19a6','\'\'',NULL,1296268),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_9acc69a31523182ef5045e372c89afeb','\'Title: ARINC 664 CTF Challenge
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

This is a two-part CTF activity designed to immerse participants in an aircraft’s ARINC 664 network.

\n\n

Virtual Challenge – Test your skills by navigating through a series of interactive tasks that build foundational knowledge of the ARINC 664 protocol – one of the communications protocols for onboard networks. Gain a high-level understanding of how this protocol operates and its security considerations.

\n\n

Hardware Challenge: Take it to the next level by engaging with model hardware. Send messages to manipulate and interact with simulated aircraft systems!

\n\n\'',NULL,1296269),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_9acc69a31523182ef5045e372c89afeb','\'\'',NULL,1296270),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_9acc69a31523182ef5045e372c89afeb','\'\'',NULL,1296271),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_9acc69a31523182ef5045e372c89afeb','\'\'',NULL,1296272),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_9acc69a31523182ef5045e372c89afeb','\'\'',NULL,1296273),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_9acc69a31523182ef5045e372c89afeb','\'\'',NULL,1296274),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_9acc69a31523182ef5045e372c89afeb','\'\'',NULL,1296275),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_9acc69a31523182ef5045e372c89afeb','\'\'',NULL,1296276),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_83bb5faefdebdff379ef26cf30b53a1c','\'Title: ARINC 664 CTF Challenge
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

This is a two-part CTF activity designed to immerse participants in an aircraft’s ARINC 664 network.

\n\n

Virtual Challenge – Test your skills by navigating through a series of interactive tasks that build foundational knowledge of the ARINC 664 protocol – one of the communications protocols for onboard networks. Gain a high-level understanding of how this protocol operates and its security considerations.

\n\n

Hardware Challenge: Take it to the next level by engaging with model hardware. Send messages to manipulate and interact with simulated aircraft systems!

\n\n\'',NULL,1296277),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_83bb5faefdebdff379ef26cf30b53a1c','\'\'',NULL,1296278),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_83bb5faefdebdff379ef26cf30b53a1c','\'\'',NULL,1296279),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_83bb5faefdebdff379ef26cf30b53a1c','\'\'',NULL,1296280),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_83bb5faefdebdff379ef26cf30b53a1c','\'\'',NULL,1296281),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_83bb5faefdebdff379ef26cf30b53a1c','\'\'',NULL,1296282),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_83bb5faefdebdff379ef26cf30b53a1c','\'\'',NULL,1296283),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_83bb5faefdebdff379ef26cf30b53a1c','\'\'',NULL,1296284),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_efff8b5f87d044a62753f364281911f8','\'Title: ARINC 664 CTF Challenge
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

This is a two-part CTF activity designed to immerse participants in an aircraft’s ARINC 664 network.

\n\n

Virtual Challenge – Test your skills by navigating through a series of interactive tasks that build foundational knowledge of the ARINC 664 protocol – one of the communications protocols for onboard networks. Gain a high-level understanding of how this protocol operates and its security considerations.

\n\n

Hardware Challenge: Take it to the next level by engaging with model hardware. Send messages to manipulate and interact with simulated aircraft systems!

\n\n\'',NULL,1296285),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_efff8b5f87d044a62753f364281911f8','\'\'',NULL,1296286),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_efff8b5f87d044a62753f364281911f8','\'\'',NULL,1296287),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'ARINC 664 CTF Challenge\'','\'\'','Creator Events_efff8b5f87d044a62753f364281911f8','\'\'',NULL,1296288),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_91b9bacd81dc1d82a9f79732d0472964','\'Title: Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\nJump into the AERIE Cyber Range to experience a number of challenges:
\n\n

• PCD (Portable Cockpit Demonstrator): Attempt an RNAV approach in a simulated general aviation flight deck to your cleared runway in instrument conditions.\n• CCD (Cockpit Cyber Demonstrator): Fly a set of flight challenges in a simulated narrow-body airliner flight deck while managing cyber effects in the aircraft.\n• Virtual Tower and TRACON: Use the approach control position and an out-the-window tower view to coordinate with the PCD and CCD to help resolve the cyber scenarios running at each.\n• Horizon: Take the mission-controller seat for a virtual CubeSat remote-sensing mission. Run an imaging pass in the same world, at the same time, as the scenarios at the other stations.\n• AirVE: Watch the aircraft cyber range provide the aircraft-network model and the injected attacks behind the cyber effects the crew is managing at the cockpit stations.\n• OrbitVE: Watch the orbital cyber range provide satellite-constellation modeling behind the scenarios at every other station.

\n\n\'',NULL,1296289),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_91b9bacd81dc1d82a9f79732d0472964','\'\'',NULL,1296290),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_91b9bacd81dc1d82a9f79732d0472964','\'\'',NULL,1296291),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_91b9bacd81dc1d82a9f79732d0472964','\'\'',NULL,1296292),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_91b9bacd81dc1d82a9f79732d0472964','\'\'',NULL,1296293),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_91b9bacd81dc1d82a9f79732d0472964','\'\'',NULL,1296294),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_91b9bacd81dc1d82a9f79732d0472964','\'\'',NULL,1296295),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_91b9bacd81dc1d82a9f79732d0472964','\'\'',NULL,1296296),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_ee8b28df7b68afc761a835298fa3b901','\'Title: Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\nJump into the AERIE Cyber Range to experience a number of challenges:
\n\n

• PCD (Portable Cockpit Demonstrator): Attempt an RNAV approach in a simulated general aviation flight deck to your cleared runway in instrument conditions.\n• CCD (Cockpit Cyber Demonstrator): Fly a set of flight challenges in a simulated narrow-body airliner flight deck while managing cyber effects in the aircraft.\n• Virtual Tower and TRACON: Use the approach control position and an out-the-window tower view to coordinate with the PCD and CCD to help resolve the cyber scenarios running at each.\n• Horizon: Take the mission-controller seat for a virtual CubeSat remote-sensing mission. Run an imaging pass in the same world, at the same time, as the scenarios at the other stations.\n• AirVE: Watch the aircraft cyber range provide the aircraft-network model and the injected attacks behind the cyber effects the crew is managing at the cockpit stations.\n• OrbitVE: Watch the orbital cyber range provide satellite-constellation modeling behind the scenarios at every other station.

\n\n\'',NULL,1296297),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_ee8b28df7b68afc761a835298fa3b901','\'\'',NULL,1296298),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_ee8b28df7b68afc761a835298fa3b901','\'\'',NULL,1296299),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_ee8b28df7b68afc761a835298fa3b901','\'\'',NULL,1296300),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_a4f94debb5abaaf5a8847597bdc4fc2b','\'Title: Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\nJump into the AERIE Cyber Range to experience a number of challenges:
\n\n

• PCD (Portable Cockpit Demonstrator): Attempt an RNAV approach in a simulated general aviation flight deck to your cleared runway in instrument conditions.\n• CCD (Cockpit Cyber Demonstrator): Fly a set of flight challenges in a simulated narrow-body airliner flight deck while managing cyber effects in the aircraft.\n• Virtual Tower and TRACON: Use the approach control position and an out-the-window tower view to coordinate with the PCD and CCD to help resolve the cyber scenarios running at each.\n• Horizon: Take the mission-controller seat for a virtual CubeSat remote-sensing mission. Run an imaging pass in the same world, at the same time, as the scenarios at the other stations.\n• AirVE: Watch the aircraft cyber range provide the aircraft-network model and the injected attacks behind the cyber effects the crew is managing at the cockpit stations.\n• OrbitVE: Watch the orbital cyber range provide satellite-constellation modeling behind the scenarios at every other station.

\n\n\'',NULL,1296301),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_a4f94debb5abaaf5a8847597bdc4fc2b','\'\'',NULL,1296302),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_a4f94debb5abaaf5a8847597bdc4fc2b','\'\'',NULL,1296303),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_a4f94debb5abaaf5a8847597bdc4fc2b','\'\'',NULL,1296304),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_a4f94debb5abaaf5a8847597bdc4fc2b','\'\'',NULL,1296305),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_a4f94debb5abaaf5a8847597bdc4fc2b','\'\'',NULL,1296306),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_a4f94debb5abaaf5a8847597bdc4fc2b','\'\'',NULL,1296307),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range\'','\'\'','Creator Events_a4f94debb5abaaf5a8847597bdc4fc2b','\'\'',NULL,1296308),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_46bf7f856992edb0942792c464b5ec91','\'Title: Aviation ISAC Cybersecurity Challenge
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Chaos has ensued at a major international airport. Flight info displays flicker with false data. Baggage systems fail. Aircraft controls and drones (by the riverside) are compromised. Even the skies are no longer safe.

\n\n

Your mission: investigate the breach, neutralize the threats, and take back control of the airport. The airport depends on you. The clock is ticking!

\n\n

As a participant, your first step is to register ahead and read the rules at: https://aviationcyberctf.com/ and bring your own laptop to the venue.

\n\n\'',NULL,1296309),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_46bf7f856992edb0942792c464b5ec91','\'\'',NULL,1296310),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_46bf7f856992edb0942792c464b5ec91','\'\'',NULL,1296311),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_46bf7f856992edb0942792c464b5ec91','\'\'',NULL,1296312),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_46bf7f856992edb0942792c464b5ec91','\'\'',NULL,1296313),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_46bf7f856992edb0942792c464b5ec91','\'\'',NULL,1296314),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_46bf7f856992edb0942792c464b5ec91','\'\'',NULL,1296315),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_46bf7f856992edb0942792c464b5ec91','\'\'',NULL,1296316),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_74d98542fc74344c4fecc0c5625ab4b8','\'Title: Aviation ISAC Cybersecurity Challenge
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Chaos has ensued at a major international airport. Flight info displays flicker with false data. Baggage systems fail. Aircraft controls and drones (by the riverside) are compromised. Even the skies are no longer safe.

\n\n

Your mission: investigate the breach, neutralize the threats, and take back control of the airport. The airport depends on you. The clock is ticking!

\n\n

As a participant, your first step is to register ahead and read the rules at: https://aviationcyberctf.com/ and bring your own laptop to the venue.

\n\n\'',NULL,1296317),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_74d98542fc74344c4fecc0c5625ab4b8','\'\'',NULL,1296318),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_74d98542fc74344c4fecc0c5625ab4b8','\'\'',NULL,1296319),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_74d98542fc74344c4fecc0c5625ab4b8','\'\'',NULL,1296320),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_74d98542fc74344c4fecc0c5625ab4b8','\'\'',NULL,1296321),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_74d98542fc74344c4fecc0c5625ab4b8','\'\'',NULL,1296322),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_74d98542fc74344c4fecc0c5625ab4b8','\'\'',NULL,1296323),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_74d98542fc74344c4fecc0c5625ab4b8','\'\'',NULL,1296324),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_f75a2cdd12227511fb74df43a362ea10','\'Title: Aviation ISAC Cybersecurity Challenge
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Chaos has ensued at a major international airport. Flight info displays flicker with false data. Baggage systems fail. Aircraft controls and drones (by the riverside) are compromised. Even the skies are no longer safe.

\n\n

Your mission: investigate the breach, neutralize the threats, and take back control of the airport. The airport depends on you. The clock is ticking!

\n\n

As a participant, your first step is to register ahead and read the rules at: https://aviationcyberctf.com/ and bring your own laptop to the venue.

\n\n\'',NULL,1296325),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_f75a2cdd12227511fb74df43a362ea10','\'\'',NULL,1296326),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_f75a2cdd12227511fb74df43a362ea10','\'\'',NULL,1296327),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Aviation ISAC Cybersecurity Challenge\'','\'\'','Creator Events_f75a2cdd12227511fb74df43a362ea10','\'\'',NULL,1296328),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_84f2a8c9b020dd5beacbd80ccfd95312','\'Title: Bricks in the Air
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft\'s control system, identify any vulnerabilities, and “hack” beyond its intended functions?

\n\n

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

\n\n

No specialized hardware required - all target devices, materials, and interfaces \nare provided!

\n\n

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.

\n\n\'',NULL,1296329),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_84f2a8c9b020dd5beacbd80ccfd95312','\'\'',NULL,1296330),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_84f2a8c9b020dd5beacbd80ccfd95312','\'\'',NULL,1296331),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_84f2a8c9b020dd5beacbd80ccfd95312','\'\'',NULL,1296332),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_fd9bb6b1874b28213cca27273dff2aab','\'Title: Bricks in the Air
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft\'s control system, identify any vulnerabilities, and “hack” beyond its intended functions?

\n\n

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

\n\n

No specialized hardware required - all target devices, materials, and interfaces \nare provided!

\n\n

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.

\n\n\'',NULL,1296333),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_fd9bb6b1874b28213cca27273dff2aab','\'\'',NULL,1296334),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_fd9bb6b1874b28213cca27273dff2aab','\'\'',NULL,1296335),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_fd9bb6b1874b28213cca27273dff2aab','\'\'',NULL,1296336),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_fd9bb6b1874b28213cca27273dff2aab','\'\'',NULL,1296337),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_fd9bb6b1874b28213cca27273dff2aab','\'\'',NULL,1296338),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_fd9bb6b1874b28213cca27273dff2aab','\'\'',NULL,1296339),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_fd9bb6b1874b28213cca27273dff2aab','\'\'',NULL,1296340),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_453a842999b04a0b32cf83f1b6443dd8','\'Title: Bricks in the Air
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft\'s control system, identify any vulnerabilities, and “hack” beyond its intended functions?

\n\n

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

\n\n

No specialized hardware required - all target devices, materials, and interfaces \nare provided!

\n\n

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.

\n\n\'',NULL,1296341),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_453a842999b04a0b32cf83f1b6443dd8','\'\'',NULL,1296342),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_453a842999b04a0b32cf83f1b6443dd8','\'\'',NULL,1296343),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_453a842999b04a0b32cf83f1b6443dd8','\'\'',NULL,1296344),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_453a842999b04a0b32cf83f1b6443dd8','\'\'',NULL,1296345),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_453a842999b04a0b32cf83f1b6443dd8','\'\'',NULL,1296346),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_453a842999b04a0b32cf83f1b6443dd8','\'\'',NULL,1296347),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Bricks in the Air\'','\'\'','Creator Events_453a842999b04a0b32cf83f1b6443dd8','\'\'',NULL,1296348),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_9dd4f96cf1d8879f1530ed790681ddcd','\'Title: DCNextGen - Bricks in the Air
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft\'s control system, identify any vulnerabilities, and “hack” beyond its intended functions?

\n\n

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

\n\n

No specialized hardware required - all target devices, materials, and interfaces \nare provided!

\n\n

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.

\n\n\'',NULL,1296349),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_9dd4f96cf1d8879f1530ed790681ddcd','\'\'',NULL,1296350),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_9dd4f96cf1d8879f1530ed790681ddcd','\'\'',NULL,1296351),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_9dd4f96cf1d8879f1530ed790681ddcd','\'\'',NULL,1296352),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_9dd4f96cf1d8879f1530ed790681ddcd','\'\'',NULL,1296353),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_9dd4f96cf1d8879f1530ed790681ddcd','\'\'',NULL,1296354),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_9dd4f96cf1d8879f1530ed790681ddcd','\'\'',NULL,1296355),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_9dd4f96cf1d8879f1530ed790681ddcd','\'\'',NULL,1296356),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_a41fe8ae5007c3e0ced46b56f7497057','\'Title: DCNextGen - Bricks in the Air
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft\'s control system, identify any vulnerabilities, and “hack” beyond its intended functions?

\n\n

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

\n\n

No specialized hardware required - all target devices, materials, and interfaces \nare provided!

\n\n

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.

\n\n\'',NULL,1296357),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_a41fe8ae5007c3e0ced46b56f7497057','\'\'',NULL,1296358),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_a41fe8ae5007c3e0ced46b56f7497057','\'\'',NULL,1296359),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_a41fe8ae5007c3e0ced46b56f7497057','\'\'',NULL,1296360),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_a41fe8ae5007c3e0ced46b56f7497057','\'\'',NULL,1296361),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_a41fe8ae5007c3e0ced46b56f7497057','\'\'',NULL,1296362),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_a41fe8ae5007c3e0ced46b56f7497057','\'\'',NULL,1296363),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_a41fe8ae5007c3e0ced46b56f7497057','\'\'',NULL,1296364),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_632eb1ad5d8f539af61aa24b82626d69','\'Title: DCNextGen - Bricks in the Air
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft\'s control system, identify any vulnerabilities, and “hack” beyond its intended functions?

\n\n

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

\n\n

No specialized hardware required - all target devices, materials, and interfaces \nare provided!

\n\n

No prior aviation or security experience required - a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.

\n\n\'',NULL,1296365),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_632eb1ad5d8f539af61aa24b82626d69','\'\'',NULL,1296366),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_632eb1ad5d8f539af61aa24b82626d69','\'\'',NULL,1296367),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Bricks in the Air\'','\'\'','Creator Events_632eb1ad5d8f539af61aa24b82626d69','\'\'',NULL,1296368),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_831284a4bfcd2929f3d2762040eca4b7','\'Title: DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

RIC-1, tail number N3VR-G0N, has gone down! You need to use radio direction-finding (RDF) techniques to locate Emergency Locator Transmitter (ELT), report its position, and help rescue our missing pilot!

\n\n

Participants will use the provided handheld DF equipment provided by the Village, or bring your own, to triangulate the hidden transmitter location within the village area. Your handheld radio must be capable of receiving on the designated frequency with a directional antenna or attenuator. Once you\'ve located RIC-1, listen closely... you may recognize the beacon\'s \"distress tone.\" It appears to be broadcasting an audio payload that responders have described as \"oddly catchy\" and \"impossible to stop once you start listening.\" Bring your comfortable shoes and strong will to ensure you never give up until you find our missing pilot!

\n\n

No prior RDF experience required - volunteers can walk you through basic triangulation techniques before you start this 15-30 minute event.

\n\n\'',NULL,1296369),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_831284a4bfcd2929f3d2762040eca4b7','\'\'',NULL,1296370),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_831284a4bfcd2929f3d2762040eca4b7','\'\'',NULL,1296371),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_831284a4bfcd2929f3d2762040eca4b7','\'\'',NULL,1296372),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_2ed3a2375a942d810aa264f1db34e392','\'Title: DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

RIC-1, tail number N3VR-G0N, has gone down! You need to use radio direction-finding (RDF) techniques to locate Emergency Locator Transmitter (ELT), report its position, and help rescue our missing pilot!

\n\n

Participants will use the provided handheld DF equipment provided by the Village, or bring your own, to triangulate the hidden transmitter location within the village area. Your handheld radio must be capable of receiving on the designated frequency with a directional antenna or attenuator. Once you\'ve located RIC-1, listen closely... you may recognize the beacon\'s \"distress tone.\" It appears to be broadcasting an audio payload that responders have described as \"oddly catchy\" and \"impossible to stop once you start listening.\" Bring your comfortable shoes and strong will to ensure you never give up until you find our missing pilot!

\n\n

No prior RDF experience required - volunteers can walk you through basic triangulation techniques before you start this 15-30 minute event.

\n\n\'',NULL,1296373),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_2ed3a2375a942d810aa264f1db34e392','\'\'',NULL,1296374),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_2ed3a2375a942d810aa264f1db34e392','\'\'',NULL,1296375),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_2ed3a2375a942d810aa264f1db34e392','\'\'',NULL,1296376),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_2ed3a2375a942d810aa264f1db34e392','\'\'',NULL,1296377),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_2ed3a2375a942d810aa264f1db34e392','\'\'',NULL,1296378),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_2ed3a2375a942d810aa264f1db34e392','\'\'',NULL,1296379),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_2ed3a2375a942d810aa264f1db34e392','\'\'',NULL,1296380),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_491728a4a3cb08278d977332b71ce89d','\'Title: DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

RIC-1, tail number N3VR-G0N, has gone down! You need to use radio direction-finding (RDF) techniques to locate Emergency Locator Transmitter (ELT), report its position, and help rescue our missing pilot!

\n\n

Participants will use the provided handheld DF equipment provided by the Village, or bring your own, to triangulate the hidden transmitter location within the village area. Your handheld radio must be capable of receiving on the designated frequency with a directional antenna or attenuator. Once you\'ve located RIC-1, listen closely... you may recognize the beacon\'s \"distress tone.\" It appears to be broadcasting an audio payload that responders have described as \"oddly catchy\" and \"impossible to stop once you start listening.\" Bring your comfortable shoes and strong will to ensure you never give up until you find our missing pilot!

\n\n

No prior RDF experience required - volunteers can walk you through basic triangulation techniques before you start this 15-30 minute event.

\n\n\'',NULL,1296381),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_491728a4a3cb08278d977332b71ce89d','\'\'',NULL,1296382),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_491728a4a3cb08278d977332b71ce89d','\'\'',NULL,1296383),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_491728a4a3cb08278d977332b71ce89d','\'\'',NULL,1296384),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_491728a4a3cb08278d977332b71ce89d','\'\'',NULL,1296385),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_491728a4a3cb08278d977332b71ce89d','\'\'',NULL,1296386),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_491728a4a3cb08278d977332b71ce89d','\'\'',NULL,1296387),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - RIC-1: ELT Localization Exercise - N3VR-G0N Down\'','\'\'','Creator Events_491728a4a3cb08278d977332b71ce89d','\'\'',NULL,1296388),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_eee27deeaf8fe28f62c86fd88fe74be2','\'Title: DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

The MOUSE-1 satellite is currently in Safe Mode, and its attitude and heading systems are behaving unexpectedly. Ground control needs answers NOW!

\n\n

You are a newly assigned Mission Specialist, and it\'s your job to figure out what\'s going on. Work through five sequential challenge missions aboard a simulated HUD - complete with live orbital tracking, optical camera feeds, and attitude telemetry - to triage MOUSE-1, uncover what happened, and make it operational again.

\n\n

Participants will learn how satellites operate, how they stay secure in orbit, and what happens when they don\'t - using a fully browser-based, gamified interface developed by California Polytechnic State University students.

\n\n

Just grab a seat in front of the provided station, no prior cybersecurity or aerospace experience required! Each mission is self-guided with built-in instructions, and volunteers are available to assist. Both beginner and experienced participants will find this 30-minute event challenging and fun.

\n\n\'',NULL,1296389),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_eee27deeaf8fe28f62c86fd88fe74be2','\'\'',NULL,1296390),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_eee27deeaf8fe28f62c86fd88fe74be2','\'\'',NULL,1296391),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_eee27deeaf8fe28f62c86fd88fe74be2','\'\'',NULL,1296392),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_eee27deeaf8fe28f62c86fd88fe74be2','\'\'',NULL,1296393),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_eee27deeaf8fe28f62c86fd88fe74be2','\'\'',NULL,1296394),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_eee27deeaf8fe28f62c86fd88fe74be2','\'\'',NULL,1296395),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_eee27deeaf8fe28f62c86fd88fe74be2','\'\'',NULL,1296396),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_bdd58a9a0d59c4034bb037b131ed60e3','\'Title: DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

The MOUSE-1 satellite is currently in Safe Mode, and its attitude and heading systems are behaving unexpectedly. Ground control needs answers NOW!

\n\n

You are a newly assigned Mission Specialist, and it\'s your job to figure out what\'s going on. Work through five sequential challenge missions aboard a simulated HUD - complete with live orbital tracking, optical camera feeds, and attitude telemetry - to triage MOUSE-1, uncover what happened, and make it operational again.

\n\n

Participants will learn how satellites operate, how they stay secure in orbit, and what happens when they don\'t - using a fully browser-based, gamified interface developed by California Polytechnic State University students.

\n\n

Just grab a seat in front of the provided station, no prior cybersecurity or aerospace experience required! Each mission is self-guided with built-in instructions, and volunteers are available to assist. Both beginner and experienced participants will find this 30-minute event challenging and fun.

\n\n\'',NULL,1296397),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_bdd58a9a0d59c4034bb037b131ed60e3','\'\'',NULL,1296398),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_bdd58a9a0d59c4034bb037b131ed60e3','\'\'',NULL,1296399),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_bdd58a9a0d59c4034bb037b131ed60e3','\'\'',NULL,1296400),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_bdd58a9a0d59c4034bb037b131ed60e3','\'\'',NULL,1296401),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_bdd58a9a0d59c4034bb037b131ed60e3','\'\'',NULL,1296402),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_bdd58a9a0d59c4034bb037b131ed60e3','\'\'',NULL,1296403),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_bdd58a9a0d59c4034bb037b131ed60e3','\'\'',NULL,1296404),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_b085b36f6fa41bd621b58c1125aed574','\'Title: DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

The MOUSE-1 satellite is currently in Safe Mode, and its attitude and heading systems are behaving unexpectedly. Ground control needs answers NOW!

\n\n

You are a newly assigned Mission Specialist, and it\'s your job to figure out what\'s going on. Work through five sequential challenge missions aboard a simulated HUD - complete with live orbital tracking, optical camera feeds, and attitude telemetry - to triage MOUSE-1, uncover what happened, and make it operational again.

\n\n

Participants will learn how satellites operate, how they stay secure in orbit, and what happens when they don\'t - using a fully browser-based, gamified interface developed by California Polytechnic State University students.

\n\n

Just grab a seat in front of the provided station, no prior cybersecurity or aerospace experience required! Each mission is self-guided with built-in instructions, and volunteers are available to assist. Both beginner and experienced participants will find this 30-minute event challenging and fun.

\n\n\'',NULL,1296405),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_b085b36f6fa41bd621b58c1125aed574','\'\'',NULL,1296406),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_b085b36f6fa41bd621b58c1125aed574','\'\'',NULL,1296407),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'DCNextGen - Space Grand Challenge - SatHack: The MOUSE-1 Mission\'','\'\'','Creator Events_b085b36f6fa41bd621b58c1125aed574','\'\'',NULL,1296408),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_ce662229ae7d093d2164a28a62033d3a','\'Title: Drone Hacking Choose your Own Adventure
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Dive into our interactive choose-your-own-adventure web interface and learn how to hack a drone in a fun, storyboard-based game. This graphical user interface simulates the process we use when hacking drones for the Air Force, allowing participants to make decisions and see the outcomes.

\n\n

It\'s a beginner-friendly, 15-30 minute activity offering insights into the steps involved in drone penetration testing.

\n\n

Participants can access it from their own computers or mobile phones.

\n\n\'',NULL,1296409),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_ce662229ae7d093d2164a28a62033d3a','\'\'',NULL,1296410),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_ce662229ae7d093d2164a28a62033d3a','\'\'',NULL,1296411),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_ce662229ae7d093d2164a28a62033d3a','\'\'',NULL,1296412),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_206fd0992027a627b4466a674f9d9cf5','\'Title: Drone Hacking Choose your Own Adventure
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Dive into our interactive choose-your-own-adventure web interface and learn how to hack a drone in a fun, storyboard-based game. This graphical user interface simulates the process we use when hacking drones for the Air Force, allowing participants to make decisions and see the outcomes.

\n\n

It\'s a beginner-friendly, 15-30 minute activity offering insights into the steps involved in drone penetration testing.

\n\n

Participants can access it from their own computers or mobile phones.

\n\n\'',NULL,1296413),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_206fd0992027a627b4466a674f9d9cf5','\'\'',NULL,1296414),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_206fd0992027a627b4466a674f9d9cf5','\'\'',NULL,1296415),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_206fd0992027a627b4466a674f9d9cf5','\'\'',NULL,1296416),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_206fd0992027a627b4466a674f9d9cf5','\'\'',NULL,1296417),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_206fd0992027a627b4466a674f9d9cf5','\'\'',NULL,1296418),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_206fd0992027a627b4466a674f9d9cf5','\'\'',NULL,1296419),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_206fd0992027a627b4466a674f9d9cf5','\'\'',NULL,1296420),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_2a02fec0c318bf16c9a33d168c52b82a','\'Title: Drone Hacking Choose your Own Adventure
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Dive into our interactive choose-your-own-adventure web interface and learn how to hack a drone in a fun, storyboard-based game. This graphical user interface simulates the process we use when hacking drones for the Air Force, allowing participants to make decisions and see the outcomes.

\n\n

It\'s a beginner-friendly, 15-30 minute activity offering insights into the steps involved in drone penetration testing.

\n\n

Participants can access it from their own computers or mobile phones.

\n\n\'',NULL,1296421),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_2a02fec0c318bf16c9a33d168c52b82a','\'\'',NULL,1296422),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_2a02fec0c318bf16c9a33d168c52b82a','\'\'',NULL,1296423),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_2a02fec0c318bf16c9a33d168c52b82a','\'\'',NULL,1296424),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_2a02fec0c318bf16c9a33d168c52b82a','\'\'',NULL,1296425),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_2a02fec0c318bf16c9a33d168c52b82a','\'\'',NULL,1296426),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_2a02fec0c318bf16c9a33d168c52b82a','\'\'',NULL,1296427),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Choose your Own Adventure\'','\'\'','Creator Events_2a02fec0c318bf16c9a33d168c52b82a','\'\'',NULL,1296428),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_73d3590048772de3ec36108b05930da1','\'Title: Drone Hacking Workshop
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Join our Drone Hacking Workshop for hands-on experience hacking drone components. This three-step in-depth activity is designed to teach you about the vulnerabilities and security of autonomous systems. Using sample drones, participants will learn techniques used in government pen tests.

\n\n

This 2-3 hour workshop suits all skill levels, from beginners to advanced hackers. Come and test your skills in a real-world scenario and understand the intricacies of drone security.

\n\n

Participants need to bring a laptop capable of running a Linux distribution.

\n\n\'',NULL,1296429),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_73d3590048772de3ec36108b05930da1','\'\'',NULL,1296430),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_73d3590048772de3ec36108b05930da1','\'\'',NULL,1296431),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_73d3590048772de3ec36108b05930da1','\'\'',NULL,1296432),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_73d3590048772de3ec36108b05930da1','\'\'',NULL,1296433),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_73d3590048772de3ec36108b05930da1','\'\'',NULL,1296434),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_73d3590048772de3ec36108b05930da1','\'\'',NULL,1296435),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_73d3590048772de3ec36108b05930da1','\'\'',NULL,1296436),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_67b42bd70ffc7d2b5bbe2dd642eb7e6b','\'Title: Drone Hacking Workshop
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Join our Drone Hacking Workshop for hands-on experience hacking drone components. This three-step in-depth activity is designed to teach you about the vulnerabilities and security of autonomous systems. Using sample drones, participants will learn techniques used in government pen tests.

\n\n

This 2-3 hour workshop suits all skill levels, from beginners to advanced hackers. Come and test your skills in a real-world scenario and understand the intricacies of drone security.

\n\n

Participants need to bring a laptop capable of running a Linux distribution.

\n\n\'',NULL,1296437),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_67b42bd70ffc7d2b5bbe2dd642eb7e6b','\'\'',NULL,1296438),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_67b42bd70ffc7d2b5bbe2dd642eb7e6b','\'\'',NULL,1296439),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_67b42bd70ffc7d2b5bbe2dd642eb7e6b','\'\'',NULL,1296440),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_67b42bd70ffc7d2b5bbe2dd642eb7e6b','\'\'',NULL,1296441),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_67b42bd70ffc7d2b5bbe2dd642eb7e6b','\'\'',NULL,1296442),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_67b42bd70ffc7d2b5bbe2dd642eb7e6b','\'\'',NULL,1296443),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_67b42bd70ffc7d2b5bbe2dd642eb7e6b','\'\'',NULL,1296444),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_0dff1b96c87cc6109831f0116d33364a','\'Title: Drone Hacking Workshop
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Join our Drone Hacking Workshop for hands-on experience hacking drone components. This three-step in-depth activity is designed to teach you about the vulnerabilities and security of autonomous systems. Using sample drones, participants will learn techniques used in government pen tests.

\n\n

This 2-3 hour workshop suits all skill levels, from beginners to advanced hackers. Come and test your skills in a real-world scenario and understand the intricacies of drone security.

\n\n

Participants need to bring a laptop capable of running a Linux distribution.

\n\n\'',NULL,1296445),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_0dff1b96c87cc6109831f0116d33364a','\'\'',NULL,1296446),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_0dff1b96c87cc6109831f0116d33364a','\'\'',NULL,1296447),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Drone Hacking Workshop\'','\'\'','Creator Events_0dff1b96c87cc6109831f0116d33364a','\'\'',NULL,1296448),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_98b8ff7546157304f849e7c963d3f75a','\'Title: Flight Simulator/EFB
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Experience the effects of tampered engine performance data as you take the controls on a departing flight. Feel for yourself how vulnerabilities in electronic flight bags can have a physical impact inside the cockpit.

\n\n\'',NULL,1296449),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_98b8ff7546157304f849e7c963d3f75a','\'\'',NULL,1296450),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_98b8ff7546157304f849e7c963d3f75a','\'\'',NULL,1296451),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_98b8ff7546157304f849e7c963d3f75a','\'\'',NULL,1296452),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_98b8ff7546157304f849e7c963d3f75a','\'\'',NULL,1296453),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_98b8ff7546157304f849e7c963d3f75a','\'\'',NULL,1296454),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_98b8ff7546157304f849e7c963d3f75a','\'\'',NULL,1296455),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_98b8ff7546157304f849e7c963d3f75a','\'\'',NULL,1296456),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_748e912b5b7b3c6f941e989e62e4ad70','\'Title: Flight Simulator/EFB
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Experience the effects of tampered engine performance data as you take the controls on a departing flight. Feel for yourself how vulnerabilities in electronic flight bags can have a physical impact inside the cockpit.

\n\n\'',NULL,1296457),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_748e912b5b7b3c6f941e989e62e4ad70','\'\'',NULL,1296458),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_748e912b5b7b3c6f941e989e62e4ad70','\'\'',NULL,1296459),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_748e912b5b7b3c6f941e989e62e4ad70','\'\'',NULL,1296460),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_840a1eb2787bbaf64985126634d998c9','\'Title: Flight Simulator/EFB
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Experience the effects of tampered engine performance data as you take the controls on a departing flight. Feel for yourself how vulnerabilities in electronic flight bags can have a physical impact inside the cockpit.

\n\n\'',NULL,1296461),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_840a1eb2787bbaf64985126634d998c9','\'\'',NULL,1296462),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_840a1eb2787bbaf64985126634d998c9','\'\'',NULL,1296463),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_840a1eb2787bbaf64985126634d998c9','\'\'',NULL,1296464),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_840a1eb2787bbaf64985126634d998c9','\'\'',NULL,1296465),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_840a1eb2787bbaf64985126634d998c9','\'\'',NULL,1296466),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_840a1eb2787bbaf64985126634d998c9','\'\'',NULL,1296467),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Flight Simulator/EFB\'','\'\'','Creator Events_840a1eb2787bbaf64985126634d998c9','\'\'',NULL,1296468),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_9684340c0f26b17996a6ae3e4bd46ccf','\'Title: MOUSE Runner & Flappy Drone
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

How High Can You Make a Satellite Jump? Can You Fly a Drone Around Aliens and Rockets?

\n\n

Put your action-hero reflexes and hand-eye coordination to the test as you battle fellow DEF CON attendees for the top scores in MOUSE Runner and Flappy Drone. The highest scores on Friday and Saturday will earn a special prize. Stop by our booth to learn more, show off your button-mashing skills, and prove you\'re the ultimate space cyber pilot.

\n\n\'',NULL,1296469),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_9684340c0f26b17996a6ae3e4bd46ccf','\'\'',NULL,1296470),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_9684340c0f26b17996a6ae3e4bd46ccf','\'\'',NULL,1296471),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_9684340c0f26b17996a6ae3e4bd46ccf','\'\'',NULL,1296472),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_9684340c0f26b17996a6ae3e4bd46ccf','\'\'',NULL,1296473),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_9684340c0f26b17996a6ae3e4bd46ccf','\'\'',NULL,1296474),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_9684340c0f26b17996a6ae3e4bd46ccf','\'\'',NULL,1296475),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_9684340c0f26b17996a6ae3e4bd46ccf','\'\'',NULL,1296476),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_ddb4c5c7d7fd3f4dc62af3d707fa049d','\'Title: MOUSE Runner & Flappy Drone
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

How High Can You Make a Satellite Jump? Can You Fly a Drone Around Aliens and Rockets?

\n\n

Put your action-hero reflexes and hand-eye coordination to the test as you battle fellow DEF CON attendees for the top scores in MOUSE Runner and Flappy Drone. The highest scores on Friday and Saturday will earn a special prize. Stop by our booth to learn more, show off your button-mashing skills, and prove you\'re the ultimate space cyber pilot.

\n\n\'',NULL,1296477),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_ddb4c5c7d7fd3f4dc62af3d707fa049d','\'\'',NULL,1296478),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_ddb4c5c7d7fd3f4dc62af3d707fa049d','\'\'',NULL,1296479),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_ddb4c5c7d7fd3f4dc62af3d707fa049d','\'\'',NULL,1296480),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_ddb4c5c7d7fd3f4dc62af3d707fa049d','\'\'',NULL,1296481),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_ddb4c5c7d7fd3f4dc62af3d707fa049d','\'\'',NULL,1296482),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_ddb4c5c7d7fd3f4dc62af3d707fa049d','\'\'',NULL,1296483),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_ddb4c5c7d7fd3f4dc62af3d707fa049d','\'\'',NULL,1296484),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_a37684d67285af72c18c087b069a696d','\'Title: MOUSE Runner & Flappy Drone
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

How High Can You Make a Satellite Jump? Can You Fly a Drone Around Aliens and Rockets?

\n\n

Put your action-hero reflexes and hand-eye coordination to the test as you battle fellow DEF CON attendees for the top scores in MOUSE Runner and Flappy Drone. The highest scores on Friday and Saturday will earn a special prize. Stop by our booth to learn more, show off your button-mashing skills, and prove you\'re the ultimate space cyber pilot.

\n\n\'',NULL,1296485),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_a37684d67285af72c18c087b069a696d','\'\'',NULL,1296486),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_a37684d67285af72c18c087b069a696d','\'\'',NULL,1296487),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'MOUSE Runner & Flappy Drone\'','\'\'','Creator Events_a37684d67285af72c18c087b069a696d','\'\'',NULL,1296488),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_276882e00a4540bad0b3fc8313d2059e','\'Title: Mission: Compromised - Hacking a Satellite from the Ground Up
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Ever wondered what it takes to hack a satellite? At this hands-on station, you\'ll step into the role of an attacker targeting a CubeSat-class spacecraft and its ground control station — all running in a safe, fully isolated environment.

\n\n

Working against a live mission control system (OpenC3 COSMOS / Yamcs) and a spacecraft simulator, you\'ll follow an attacker\'s kill chain across multiple layers — from reconnaissance and ground station compromise all the way to the spacecraft itself. Where does it end? Let\'s just say the mission doesn\'t survive. Come find out how. Every step is paired with the real-world defense that would have stopped it - so you\'ll leave understanding both how these attacks work and how space systems defend against them. Whether you\'re new to space security or already deep in the field, come try it out, break a satellite (safely!), and see the attack surface of modern spacecraft up close.

\n\n

It will take approximately 15-30 minutes to work through this hands-on demo and guided exercises. You can watch attacks demonstrated by our team, then try guided scenarios yourself using real CCSDS space protocols, RF concepts, and industry mission control tooling. A live mission dashboard will reveal the spacecraft\'s fate as the scenario plays out.

\n\n

No prior space experience required - all skill levels welcome. We recommend you bring your own laptop the hands-on portions. A laptop with GNU Radio will let you dig into the RF challenge, and a Kali Linux setup or your equivalent pentesting toolkit are recommended for the more advanced challenge.

\n\n\'',NULL,1296489),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_276882e00a4540bad0b3fc8313d2059e','\'\'',NULL,1296490),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_276882e00a4540bad0b3fc8313d2059e','\'\'',NULL,1296491),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_276882e00a4540bad0b3fc8313d2059e','\'\'',NULL,1296492),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_276882e00a4540bad0b3fc8313d2059e','\'\'',NULL,1296493),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_276882e00a4540bad0b3fc8313d2059e','\'\'',NULL,1296494),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_276882e00a4540bad0b3fc8313d2059e','\'\'',NULL,1296495),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_276882e00a4540bad0b3fc8313d2059e','\'\'',NULL,1296496),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_c447b3e89fba84a0e878ac4c391ee42f','\'Title: Mission: Compromised - Hacking a Satellite from the Ground Up
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Ever wondered what it takes to hack a satellite? At this hands-on station, you\'ll step into the role of an attacker targeting a CubeSat-class spacecraft and its ground control station — all running in a safe, fully isolated environment.

\n\n

Working against a live mission control system (OpenC3 COSMOS / Yamcs) and a spacecraft simulator, you\'ll follow an attacker\'s kill chain across multiple layers — from reconnaissance and ground station compromise all the way to the spacecraft itself. Where does it end? Let\'s just say the mission doesn\'t survive. Come find out how. Every step is paired with the real-world defense that would have stopped it - so you\'ll leave understanding both how these attacks work and how space systems defend against them. Whether you\'re new to space security or already deep in the field, come try it out, break a satellite (safely!), and see the attack surface of modern spacecraft up close.

\n\n

It will take approximately 15-30 minutes to work through this hands-on demo and guided exercises. You can watch attacks demonstrated by our team, then try guided scenarios yourself using real CCSDS space protocols, RF concepts, and industry mission control tooling. A live mission dashboard will reveal the spacecraft\'s fate as the scenario plays out.

\n\n

No prior space experience required - all skill levels welcome. We recommend you bring your own laptop the hands-on portions. A laptop with GNU Radio will let you dig into the RF challenge, and a Kali Linux setup or your equivalent pentesting toolkit are recommended for the more advanced challenge.

\n\n\'',NULL,1296497),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_c447b3e89fba84a0e878ac4c391ee42f','\'\'',NULL,1296498),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_c447b3e89fba84a0e878ac4c391ee42f','\'\'',NULL,1296499),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_c447b3e89fba84a0e878ac4c391ee42f','\'\'',NULL,1296500),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_39563565e9247fd6407da1e3e38e768f','\'Title: Mission: Compromised - Hacking a Satellite from the Ground Up
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Ever wondered what it takes to hack a satellite? At this hands-on station, you\'ll step into the role of an attacker targeting a CubeSat-class spacecraft and its ground control station — all running in a safe, fully isolated environment.

\n\n

Working against a live mission control system (OpenC3 COSMOS / Yamcs) and a spacecraft simulator, you\'ll follow an attacker\'s kill chain across multiple layers — from reconnaissance and ground station compromise all the way to the spacecraft itself. Where does it end? Let\'s just say the mission doesn\'t survive. Come find out how. Every step is paired with the real-world defense that would have stopped it - so you\'ll leave understanding both how these attacks work and how space systems defend against them. Whether you\'re new to space security or already deep in the field, come try it out, break a satellite (safely!), and see the attack surface of modern spacecraft up close.

\n\n

It will take approximately 15-30 minutes to work through this hands-on demo and guided exercises. You can watch attacks demonstrated by our team, then try guided scenarios yourself using real CCSDS space protocols, RF concepts, and industry mission control tooling. A live mission dashboard will reveal the spacecraft\'s fate as the scenario plays out.

\n\n

No prior space experience required - all skill levels welcome. We recommend you bring your own laptop the hands-on portions. A laptop with GNU Radio will let you dig into the RF challenge, and a Kali Linux setup or your equivalent pentesting toolkit are recommended for the more advanced challenge.

\n\n\'',NULL,1296501),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_39563565e9247fd6407da1e3e38e768f','\'\'',NULL,1296502),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_39563565e9247fd6407da1e3e38e768f','\'\'',NULL,1296503),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_39563565e9247fd6407da1e3e38e768f','\'\'',NULL,1296504),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_39563565e9247fd6407da1e3e38e768f','\'\'',NULL,1296505),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_39563565e9247fd6407da1e3e38e768f','\'\'',NULL,1296506),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_39563565e9247fd6407da1e3e38e768f','\'\'',NULL,1296507),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Mission: Compromised - Hacking a Satellite from the Ground Up\'','\'\'','Creator Events_39563565e9247fd6407da1e3e38e768f','\'\'',NULL,1296508),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f1136be8f753b2c5c1b68249927db48a','\'Title: Nebula Showdown: Space Systems Security CTF Adventure
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Join the Aurora Alliance in their critical mission to thwart the notorious Nebula Syndicate and save the Earth! The Syndicate threatens to destroy historic monuments around the world with their Space Laser unless their demands are met. Do you have what it takes to dismantle their malevolent plans and deorbit a menacing space threat?

\n\n

This entry-level CTF kicks off as soon as the village opens - no pre-registration necessary. Just bring your laptop and your go-to cybersecurity tools – Wireshark, NMAP, and any FTP client you prefer. We know the DEF CON wifi can be unpredictable, so this CTF will be local only to the Aerospace village via an isolated local range. The CTF is designed to be completed in under an hour, making it perfect for a quick yet engaging challenge. Team collaboration is encouraged, and if you encounter obstacles, numerous hints are available to guide you. There are no penalties for using hints. Our goal is for you to learn something new and make it all the way through the CTF. Excel in the challenge, and you could walk away with an exclusive CT Cubed SAO prize while supplies last.

\n\n\'',NULL,1296509),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f1136be8f753b2c5c1b68249927db48a','\'\'',NULL,1296510),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f1136be8f753b2c5c1b68249927db48a','\'\'',NULL,1296511),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f1136be8f753b2c5c1b68249927db48a','\'\'',NULL,1296512),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f1136be8f753b2c5c1b68249927db48a','\'\'',NULL,1296513),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f1136be8f753b2c5c1b68249927db48a','\'\'',NULL,1296514),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f1136be8f753b2c5c1b68249927db48a','\'\'',NULL,1296515),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f1136be8f753b2c5c1b68249927db48a','\'\'',NULL,1296516),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_6b94c03d3dc0c810202040da2466158d','\'Title: Nebula Showdown: Space Systems Security CTF Adventure
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Join the Aurora Alliance in their critical mission to thwart the notorious Nebula Syndicate and save the Earth! The Syndicate threatens to destroy historic monuments around the world with their Space Laser unless their demands are met. Do you have what it takes to dismantle their malevolent plans and deorbit a menacing space threat?

\n\n

This entry-level CTF kicks off as soon as the village opens - no pre-registration necessary. Just bring your laptop and your go-to cybersecurity tools – Wireshark, NMAP, and any FTP client you prefer. We know the DEF CON wifi can be unpredictable, so this CTF will be local only to the Aerospace village via an isolated local range. The CTF is designed to be completed in under an hour, making it perfect for a quick yet engaging challenge. Team collaboration is encouraged, and if you encounter obstacles, numerous hints are available to guide you. There are no penalties for using hints. Our goal is for you to learn something new and make it all the way through the CTF. Excel in the challenge, and you could walk away with an exclusive CT Cubed SAO prize while supplies last.

\n\n\'',NULL,1296517),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_6b94c03d3dc0c810202040da2466158d','\'\'',NULL,1296518),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_6b94c03d3dc0c810202040da2466158d','\'\'',NULL,1296519),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_6b94c03d3dc0c810202040da2466158d','\'\'',NULL,1296520),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f8c872f8c73cb941168d3399713e2422','\'Title: Nebula Showdown: Space Systems Security CTF Adventure
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Join the Aurora Alliance in their critical mission to thwart the notorious Nebula Syndicate and save the Earth! The Syndicate threatens to destroy historic monuments around the world with their Space Laser unless their demands are met. Do you have what it takes to dismantle their malevolent plans and deorbit a menacing space threat?

\n\n

This entry-level CTF kicks off as soon as the village opens - no pre-registration necessary. Just bring your laptop and your go-to cybersecurity tools – Wireshark, NMAP, and any FTP client you prefer. We know the DEF CON wifi can be unpredictable, so this CTF will be local only to the Aerospace village via an isolated local range. The CTF is designed to be completed in under an hour, making it perfect for a quick yet engaging challenge. Team collaboration is encouraged, and if you encounter obstacles, numerous hints are available to guide you. There are no penalties for using hints. Our goal is for you to learn something new and make it all the way through the CTF. Excel in the challenge, and you could walk away with an exclusive CT Cubed SAO prize while supplies last.

\n\n\'',NULL,1296521),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f8c872f8c73cb941168d3399713e2422','\'\'',NULL,1296522),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f8c872f8c73cb941168d3399713e2422','\'\'',NULL,1296523),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f8c872f8c73cb941168d3399713e2422','\'\'',NULL,1296524),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f8c872f8c73cb941168d3399713e2422','\'\'',NULL,1296525),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f8c872f8c73cb941168d3399713e2422','\'\'',NULL,1296526),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f8c872f8c73cb941168d3399713e2422','\'\'',NULL,1296527),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Nebula Showdown: Space Systems Security CTF Adventure\'','\'\'','Creator Events_f8c872f8c73cb941168d3399713e2422','\'\'',NULL,1296528),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_c4bdfdb452b21f022929beb42bf1a581','\'Title: SR-71 Blackbird Badge Challenge
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Think faster. Fly higher. Stay unseen.

\n\n

Only the sharpest contenders will earn the limited-edition SR-71 PCB badge, inspired by the legendary Blackbird. Put your technical skills, aerospace knowledge, and analytical thinking to the test in this exclusive challenge. Like the aircraft itself, success demands precision, ingenuity, and the ability to stay one step ahead. Complete the mission and earn your wings.

\n\n

New challenges launch all weekend long.

\n\n\'',NULL,1296529),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_c4bdfdb452b21f022929beb42bf1a581','\'\'',NULL,1296530),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_c4bdfdb452b21f022929beb42bf1a581','\'\'',NULL,1296531),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_c4bdfdb452b21f022929beb42bf1a581','\'\'',NULL,1296532),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_a2ca8681e982d5db190b0c39d42dee06','\'Title: SR-71 Blackbird Badge Challenge
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Think faster. Fly higher. Stay unseen.

\n\n

Only the sharpest contenders will earn the limited-edition SR-71 PCB badge, inspired by the legendary Blackbird. Put your technical skills, aerospace knowledge, and analytical thinking to the test in this exclusive challenge. Like the aircraft itself, success demands precision, ingenuity, and the ability to stay one step ahead. Complete the mission and earn your wings.

\n\n

New challenges launch all weekend long.

\n\n\'',NULL,1296533),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_a2ca8681e982d5db190b0c39d42dee06','\'\'',NULL,1296534),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_a2ca8681e982d5db190b0c39d42dee06','\'\'',NULL,1296535),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_a2ca8681e982d5db190b0c39d42dee06','\'\'',NULL,1296536),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_a2ca8681e982d5db190b0c39d42dee06','\'\'',NULL,1296537),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_a2ca8681e982d5db190b0c39d42dee06','\'\'',NULL,1296538),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_a2ca8681e982d5db190b0c39d42dee06','\'\'',NULL,1296539),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_a2ca8681e982d5db190b0c39d42dee06','\'\'',NULL,1296540),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_d21ebd12a992b0ec08a8b2696400bd59','\'Title: SR-71 Blackbird Badge Challenge
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Think faster. Fly higher. Stay unseen.

\n\n

Only the sharpest contenders will earn the limited-edition SR-71 PCB badge, inspired by the legendary Blackbird. Put your technical skills, aerospace knowledge, and analytical thinking to the test in this exclusive challenge. Like the aircraft itself, success demands precision, ingenuity, and the ability to stay one step ahead. Complete the mission and earn your wings.

\n\n

New challenges launch all weekend long.

\n\n\'',NULL,1296541),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_d21ebd12a992b0ec08a8b2696400bd59','\'\'',NULL,1296542),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_d21ebd12a992b0ec08a8b2696400bd59','\'\'',NULL,1296543),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_d21ebd12a992b0ec08a8b2696400bd59','\'\'',NULL,1296544),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_d21ebd12a992b0ec08a8b2696400bd59','\'\'',NULL,1296545),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_d21ebd12a992b0ec08a8b2696400bd59','\'\'',NULL,1296546),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_d21ebd12a992b0ec08a8b2696400bd59','\'\'',NULL,1296547),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SR-71 Blackbird Badge Challenge\'','\'\'','Creator Events_d21ebd12a992b0ec08a8b2696400bd59','\'\'',NULL,1296548),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_560bc4d09c8ce5484837af6706c1fb73','\'Title: Satellites Under Attack: Hands-On Satellite Security Threat Scenarios
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

In this “Satellite Attack Lab” you can explore how cyber-attacks against satellite systems can be launched, observed, and understood through a hands-on, attacker-centric experience. Rather than focusing on normal satellite operations, you will step into the role of a threat actor and directly exploit vulnerabilities in a simulated space environment by interacting with a physical setup of model satellites and ground stations to witness the immediate consequences of malicious actions, including intercepted data, unauthorized command execution, and visible disruption of satellite behavior.

\n\n

We provide hacker workstations pre-configured with satellite command tools and signal-processing software. Large displays show the victim system’s telemetry and status in real time, allowing participants to immediately see the effects of their attacks.

\n\n

This session is designed to be highly interactive and accessible to newcomers while still offering meaningful technical depth for advanced attendees.

\n\n\'',NULL,1296549),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_560bc4d09c8ce5484837af6706c1fb73','\'\'',NULL,1296550),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_560bc4d09c8ce5484837af6706c1fb73','\'\'',NULL,1296551),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_560bc4d09c8ce5484837af6706c1fb73','\'\'',NULL,1296552),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_560bc4d09c8ce5484837af6706c1fb73','\'\'',NULL,1296553),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_560bc4d09c8ce5484837af6706c1fb73','\'\'',NULL,1296554),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_560bc4d09c8ce5484837af6706c1fb73','\'\'',NULL,1296555),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_560bc4d09c8ce5484837af6706c1fb73','\'\'',NULL,1296556),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_7d60c6f671640d74c83012793e727abb','\'Title: Satellites Under Attack: Hands-On Satellite Security Threat Scenarios
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

In this “Satellite Attack Lab” you can explore how cyber-attacks against satellite systems can be launched, observed, and understood through a hands-on, attacker-centric experience. Rather than focusing on normal satellite operations, you will step into the role of a threat actor and directly exploit vulnerabilities in a simulated space environment by interacting with a physical setup of model satellites and ground stations to witness the immediate consequences of malicious actions, including intercepted data, unauthorized command execution, and visible disruption of satellite behavior.

\n\n

We provide hacker workstations pre-configured with satellite command tools and signal-processing software. Large displays show the victim system’s telemetry and status in real time, allowing participants to immediately see the effects of their attacks.

\n\n

This session is designed to be highly interactive and accessible to newcomers while still offering meaningful technical depth for advanced attendees.

\n\n\'',NULL,1296557),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_7d60c6f671640d74c83012793e727abb','\'\'',NULL,1296558),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_7d60c6f671640d74c83012793e727abb','\'\'',NULL,1296559),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_7d60c6f671640d74c83012793e727abb','\'\'',NULL,1296560),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_7d60c6f671640d74c83012793e727abb','\'\'',NULL,1296561),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_7d60c6f671640d74c83012793e727abb','\'\'',NULL,1296562),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_7d60c6f671640d74c83012793e727abb','\'\'',NULL,1296563),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_7d60c6f671640d74c83012793e727abb','\'\'',NULL,1296564),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_f6e12895311639edc132b2026ac0a689','\'Title: Satellites Under Attack: Hands-On Satellite Security Threat Scenarios
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

In this “Satellite Attack Lab” you can explore how cyber-attacks against satellite systems can be launched, observed, and understood through a hands-on, attacker-centric experience. Rather than focusing on normal satellite operations, you will step into the role of a threat actor and directly exploit vulnerabilities in a simulated space environment by interacting with a physical setup of model satellites and ground stations to witness the immediate consequences of malicious actions, including intercepted data, unauthorized command execution, and visible disruption of satellite behavior.

\n\n

We provide hacker workstations pre-configured with satellite command tools and signal-processing software. Large displays show the victim system’s telemetry and status in real time, allowing participants to immediately see the effects of their attacks.

\n\n

This session is designed to be highly interactive and accessible to newcomers while still offering meaningful technical depth for advanced attendees.

\n\n\'',NULL,1296565),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_f6e12895311639edc132b2026ac0a689','\'\'',NULL,1296566),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_f6e12895311639edc132b2026ac0a689','\'\'',NULL,1296567),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'Satellites Under Attack: Hands-On Satellite Security Threat Scenarios\'','\'\'','Creator Events_f6e12895311639edc132b2026ac0a689','\'\'',NULL,1296568),('4_Sunday','10','10:00','13:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_e5f87d8d107fd2648edf2cbaef081b90','\'Title: SpaceCOP - Catch Me If You Can
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Think you can hack a spacecraft?

\n\n

We’ve deployed a vulnerable Pisat and made the software available ahead of time so you can prove it. Study it, reverse engineer it, find weaknesses, and develop your attack plan before stepping up to the console.

\n\n

When your turn comes, you’ll only have 15 minutes at a time to compromise the spacecraft and achieve a mission objective. There’s just one problem, the SpaceCOP, an intrusion detection system based on the Aerospace Corporation’s SPARTA matrix, has been deployed. The spacecraft is intentionally hackable - the real challenge is accomplishing your objective without triggering an alert and getting arrested by SpaceCOP.

\n\n

Earn rewards based on how well you hack and hide from SpaceCOP.

\n\n

Rules of Engagement:\n• Recon and vulnerability research before sitting at the terminal are highly encouraged.\n• You will have 15 minutes at the workstation to execute your attack.\n• Modifying files, changing registry settings, taking pictures, and other spacecraft effects are fair game. \n• Do not intentionally wipe, brick, destroy, or otherwise render the system unusable. \n• No “rm -rf”, disk wipes, ransomware, bootloader destruction, or similar actions.

\n\nLinks:
    Github - https://github.com/the-aerospace-corporation/spacecop-demo
\n\'',NULL,1296569),('4_Sunday','11','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_e5f87d8d107fd2648edf2cbaef081b90','\'\'',NULL,1296570),('4_Sunday','12','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_e5f87d8d107fd2648edf2cbaef081b90','\'\'',NULL,1296571),('4_Sunday','13','10:00','13:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_e5f87d8d107fd2648edf2cbaef081b90','\'\'',NULL,1296572),('3_Saturday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_dedf9302959cc9f1917b93b83ad61043','\'Title: SpaceCOP - Catch Me If You Can
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Think you can hack a spacecraft?

\n\n

We’ve deployed a vulnerable Pisat and made the software available ahead of time so you can prove it. Study it, reverse engineer it, find weaknesses, and develop your attack plan before stepping up to the console.

\n\n

When your turn comes, you’ll only have 15 minutes at a time to compromise the spacecraft and achieve a mission objective. There’s just one problem, the SpaceCOP, an intrusion detection system based on the Aerospace Corporation’s SPARTA matrix, has been deployed. The spacecraft is intentionally hackable - the real challenge is accomplishing your objective without triggering an alert and getting arrested by SpaceCOP.

\n\n

Earn rewards based on how well you hack and hide from SpaceCOP.

\n\n

Rules of Engagement:\n• Recon and vulnerability research before sitting at the terminal are highly encouraged.\n• You will have 15 minutes at the workstation to execute your attack.\n• Modifying files, changing registry settings, taking pictures, and other spacecraft effects are fair game. \n• Do not intentionally wipe, brick, destroy, or otherwise render the system unusable. \n• No “rm -rf”, disk wipes, ransomware, bootloader destruction, or similar actions.

\n\nLinks:
    Github - https://github.com/the-aerospace-corporation/spacecop-demo
\n\'',NULL,1296573),('3_Saturday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_dedf9302959cc9f1917b93b83ad61043','\'\'',NULL,1296574),('3_Saturday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_dedf9302959cc9f1917b93b83ad61043','\'\'',NULL,1296575),('3_Saturday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_dedf9302959cc9f1917b93b83ad61043','\'\'',NULL,1296576),('3_Saturday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_dedf9302959cc9f1917b93b83ad61043','\'\'',NULL,1296577),('3_Saturday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_dedf9302959cc9f1917b93b83ad61043','\'\'',NULL,1296578),('3_Saturday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_dedf9302959cc9f1917b93b83ad61043','\'\'',NULL,1296579),('3_Saturday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_dedf9302959cc9f1917b93b83ad61043','\'\'',NULL,1296580),('2_Friday','10','10:00','17:59','N','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_df632b2c37eeefae7d8ae5e6b2ecaaf4','\'Title: SpaceCOP - Catch Me If You Can
\nTags: Aerospace Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 700 (Aerospace Village) - Map
\n
\nDescription:
\n

Think you can hack a spacecraft?

\n\n

We’ve deployed a vulnerable Pisat and made the software available ahead of time so you can prove it. Study it, reverse engineer it, find weaknesses, and develop your attack plan before stepping up to the console.

\n\n

When your turn comes, you’ll only have 15 minutes at a time to compromise the spacecraft and achieve a mission objective. There’s just one problem, the SpaceCOP, an intrusion detection system based on the Aerospace Corporation’s SPARTA matrix, has been deployed. The spacecraft is intentionally hackable - the real challenge is accomplishing your objective without triggering an alert and getting arrested by SpaceCOP.

\n\n

Earn rewards based on how well you hack and hide from SpaceCOP.

\n\n

Rules of Engagement:\n• Recon and vulnerability research before sitting at the terminal are highly encouraged.\n• You will have 15 minutes at the workstation to execute your attack.\n• Modifying files, changing registry settings, taking pictures, and other spacecraft effects are fair game. \n• Do not intentionally wipe, brick, destroy, or otherwise render the system unusable. \n• No “rm -rf”, disk wipes, ransomware, bootloader destruction, or similar actions.

\n\nLinks:
    Github - https://github.com/the-aerospace-corporation/spacecop-demo
\n\'',NULL,1296581),('2_Friday','11','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_df632b2c37eeefae7d8ae5e6b2ecaaf4','\'\'',NULL,1296582),('2_Friday','12','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_df632b2c37eeefae7d8ae5e6b2ecaaf4','\'\'',NULL,1296583),('2_Friday','13','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_df632b2c37eeefae7d8ae5e6b2ecaaf4','\'\'',NULL,1296584),('2_Friday','14','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_df632b2c37eeefae7d8ae5e6b2ecaaf4','\'\'',NULL,1296585),('2_Friday','15','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_df632b2c37eeefae7d8ae5e6b2ecaaf4','\'\'',NULL,1296586),('2_Friday','16','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_df632b2c37eeefae7d8ae5e6b2ecaaf4','\'\'',NULL,1296587),('2_Friday','17','10:00','17:59','Y','Aerospace Village','LVCCW Level 1 Hall 2 700 (Aerospace Village)','\'SpaceCOP - Catch Me If You Can\'','\'\'','Creator Events_df632b2c37eeefae7d8ae5e6b2ecaaf4','\'\'',NULL,1296588),('2_Friday','10','10:00','01:59','N','The Diana Initiative','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Quiet Room\'','\'\'','Creator Events_ea40bbb933a9af7d7ce4d754924aabd4','\'Title: Quiet Room
\nTags: Quiet Room with TDI & MHH | The Diana Initiative | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 01:59 PDT
\nWhere: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map
\n
\nDescription:
\n

Diana Initiative is excited to offer up a \"Quiet Room\" again this year. This room is a library vibes environment where people can calm down or recharge before going back out to experience more DEF CON, or even safely have a meltdown, stim, and take time to recenter. In our library area we will have fidget toys, coloring pages and more. This year we are partnering with Mental Health Hackers to make it even better!

\n\n\'',NULL,1296589),('3_Saturday','10','10:00','01:59','N','The Diana Initiative','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Quiet Room\'','\'\'','Creator Events_311f897f0fc4dc1a10a51bb7eeb80689','\'Title: Quiet Room
\nTags: Quiet Room with TDI & MHH | The Diana Initiative | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 01:59 PDT
\nWhere: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map
\n
\nDescription:
\n

Diana Initiative is excited to offer up a \"Quiet Room\" again this year. This room is a library vibes environment where people can calm down or recharge before going back out to experience more DEF CON, or even safely have a meltdown, stim, and take time to recenter. In our library area we will have fidget toys, coloring pages and more. This year we are partnering with Mental Health Hackers to make it even better!

\n\n\'',NULL,1296590),('4_Sunday','10','10:00','13:59','N','The Diana Initiative','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Quiet Room\'','\'\'','Creator Events_70f12c87851955314b17b305479e2471','\'Title: Quiet Room
\nTags: Quiet Room with TDI & MHH | The Diana Initiative | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W208 (Quiet Room with TDI and MHH) - Map
\n
\nDescription:
\n

Diana Initiative is excited to offer up a \"Quiet Room\" again this year. This room is a library vibes environment where people can calm down or recharge before going back out to experience more DEF CON, or even safely have a meltdown, stim, and take time to recenter. In our library area we will have fidget toys, coloring pages and more. This year we are partnering with Mental Health Hackers to make it even better!

\n\n\'',NULL,1296591),('4_Sunday','11','10:00','13:59','Y','The Diana Initiative','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Quiet Room\'','\'\'','Creator Events_70f12c87851955314b17b305479e2471','\'\'',NULL,1296592),('4_Sunday','12','10:00','13:59','Y','The Diana Initiative','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Quiet Room\'','\'\'','Creator Events_70f12c87851955314b17b305479e2471','\'\'',NULL,1296593),('4_Sunday','13','10:00','13:59','Y','The Diana Initiative','LVCCW Level 2 W208 (Quiet Room with TDI and MHH)','\'Quiet Room\'','\'\'','Creator Events_70f12c87851955314b17b305479e2471','\'\'',NULL,1296594),('3_Saturday','08','08:30','09:29','N','The Diana Initiative','','\'Quiet Room\'','\'\'','Creator Events_53e9819c1b37afdefd83e546a1491a72','\'Title: Quiet Room
\nTags: Quiet Room with TDI & MHH | The Diana Initiative | Creator Event/Activity
\nWhen: Saturday, Aug 8, 08:30 - 09:29 PDT
\nWhere:
\n
\nDescription:
\n

Diana Initiative is excited to offer up a \"Quiet Room\" again this year. This room is a library vibes environment where people can calm down or recharge before going back out to experience more DEF CON, or even safely have a meltdown, stim, and take time to recenter. In our library area we will have fidget toys, coloring pages and more. This year we are partnering with Mental Health Hackers to make it even better!

\n\n\'',NULL,1296595),('3_Saturday','09','08:30','09:29','Y','The Diana Initiative','','\'Quiet Room\'','\'\'','Creator Events_53e9819c1b37afdefd83e546a1491a72','\'\'',NULL,1296596),('3_Saturday','13','13:00','13:59','N','The Diana Initiative','LVCCW Level 2 W209 (Diana Initiative)','\'Everything I Need to Know About Security, I Learned from Mr. Rogers\'','\'Zoe\'','Creator Events_37004cb7777da2be371d06320eceb738','\'Title: Everything I Need to Know About Security, I Learned from Mr. Rogers
\nTags: The Diana Initiative | Creator Event/Activity
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W209 (Diana Initiative) - Map
\n
\nDescription:
\n

The same lessons we learned from children’s programs growing up can help keep organizations safe. Kindness builds trust, and trust gets team buy-in to security processes. Diversity increases the vantage points and perspectives able to spot gaps or loopholes in technology and process. Empathy that puts us in the shoes of our users helps refine workflows, and a company that takes care of its employees reduces the likelihood of internal bad actors. Security is more about effective cooperation than a digital dogfight.

\n\nSpeakerBio:  Zoe
\nNo BIO available
\n\n\'',NULL,1296597),('3_Saturday','10','10:00','17:59','N','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_129b29a7fb07956901d2f5a2e9a9aace','\'Title: DEF CON Groups (DCG)
\nTags: DEF CON Groups | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n

DEF CON Groups are the year round, local communities that bring the DEF CON spirit home. Run by volunteers around the world, DCGs create spaces where hackers meet, learn, collaborate, and build community outside of conference season.

\n\n

The DEF CON Groups community space brings together Points of Contact, members, and prospective members to collaborate, share ideas, and learn from one another. Through informal workshops and hands on interaction, participants exchange practical lessons on building, sustaining, and evolving local hacker communities.

\n\n

The space also serves as a social anchor. A relaxed place to reconnect with old friends, meet new ones, and participate in light interactive activities that reflect the collaborative nature of hacking culture.

\n\n

DEF CON has always been the island of misfit toys we all return to once a year. DEF CON Groups are how that ethos survives the other fifty one weeks.

\n\nLinks:
    Website - https://defcongroups.org
\n\'',NULL,1296598),('3_Saturday','11','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_129b29a7fb07956901d2f5a2e9a9aace','\'\'',NULL,1296599),('3_Saturday','12','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_129b29a7fb07956901d2f5a2e9a9aace','\'\'',NULL,1296600),('3_Saturday','13','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_129b29a7fb07956901d2f5a2e9a9aace','\'\'',NULL,1296601),('3_Saturday','14','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_129b29a7fb07956901d2f5a2e9a9aace','\'\'',NULL,1296602),('3_Saturday','15','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_129b29a7fb07956901d2f5a2e9a9aace','\'\'',NULL,1296603),('3_Saturday','16','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_129b29a7fb07956901d2f5a2e9a9aace','\'\'',NULL,1296604),('3_Saturday','17','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_129b29a7fb07956901d2f5a2e9a9aace','\'\'',NULL,1296605),('4_Sunday','10','10:00','13:59','N','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_9756fec62cb671d440f028bb07ddbe55','\'Title: DEF CON Groups (DCG)
\nTags: DEF CON Groups | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n

DEF CON Groups are the year round, local communities that bring the DEF CON spirit home. Run by volunteers around the world, DCGs create spaces where hackers meet, learn, collaborate, and build community outside of conference season.

\n\n

The DEF CON Groups community space brings together Points of Contact, members, and prospective members to collaborate, share ideas, and learn from one another. Through informal workshops and hands on interaction, participants exchange practical lessons on building, sustaining, and evolving local hacker communities.

\n\n

The space also serves as a social anchor. A relaxed place to reconnect with old friends, meet new ones, and participate in light interactive activities that reflect the collaborative nature of hacking culture.

\n\n

DEF CON has always been the island of misfit toys we all return to once a year. DEF CON Groups are how that ethos survives the other fifty one weeks.

\n\nLinks:
    Website - https://defcongroups.org
\n\'',NULL,1296606),('4_Sunday','11','10:00','13:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_9756fec62cb671d440f028bb07ddbe55','\'\'',NULL,1296607),('4_Sunday','12','10:00','13:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_9756fec62cb671d440f028bb07ddbe55','\'\'',NULL,1296608),('4_Sunday','13','10:00','13:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_9756fec62cb671d440f028bb07ddbe55','\'\'',NULL,1296609),('2_Friday','10','10:00','17:59','N','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_ccea575338d48322c65efbf4818a61d2','\'Title: DEF CON Groups (DCG)
\nTags: DEF CON Groups | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n

DEF CON Groups are the year round, local communities that bring the DEF CON spirit home. Run by volunteers around the world, DCGs create spaces where hackers meet, learn, collaborate, and build community outside of conference season.

\n\n

The DEF CON Groups community space brings together Points of Contact, members, and prospective members to collaborate, share ideas, and learn from one another. Through informal workshops and hands on interaction, participants exchange practical lessons on building, sustaining, and evolving local hacker communities.

\n\n

The space also serves as a social anchor. A relaxed place to reconnect with old friends, meet new ones, and participate in light interactive activities that reflect the collaborative nature of hacking culture.

\n\n

DEF CON has always been the island of misfit toys we all return to once a year. DEF CON Groups are how that ethos survives the other fifty one weeks.

\n\nLinks:
    Website - https://defcongroups.org
\n\'',NULL,1296610),('2_Friday','11','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_ccea575338d48322c65efbf4818a61d2','\'\'',NULL,1296611),('2_Friday','12','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_ccea575338d48322c65efbf4818a61d2','\'\'',NULL,1296612),('2_Friday','13','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_ccea575338d48322c65efbf4818a61d2','\'\'',NULL,1296613),('2_Friday','14','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_ccea575338d48322c65efbf4818a61d2','\'\'',NULL,1296614),('2_Friday','15','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_ccea575338d48322c65efbf4818a61d2','\'\'',NULL,1296615),('2_Friday','16','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_ccea575338d48322c65efbf4818a61d2','\'\'',NULL,1296616),('2_Friday','17','10:00','17:59','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups (DCG)\'','\'\'','Creator Events_ccea575338d48322c65efbf4818a61d2','\'\'',NULL,1296617),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_821b9549fd2398fb38c59f4f0f850391','\'Title: DEF CON Groups Sticker Contest
\nTags: DEF CON Groups | DEF CON Groups Sticker Contest | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n

The DCG Sticker Contest is a sticker design contest withwinner by popular vote and voting happening during DEF CON 34.

\n\n

Anyone can submit original, human-created sticker designs prior to DEF CON 34. During DC34 attendees view all entries on site, and vote in person for their favorites. Designs will be displayed in the DEF CON Groups Community space throughout the conference, with voting open on Thursday to Saturday and the winning design announced on Sunday.

\n\n

Stickers are hacker currency. This contest is about celebrating that culture through creativity, participation, and community choice. The top designs go through to the voting round. What wins is what the DEF CON community votes for.

\n\n

Whether you want to support fellow hackers, or help decide the winning design, this is your chance to participate directly.

\n\n

Participant Prerequisites

\n\n

For designers / contributors:\n- Original sticker artwork created by a human (no AI-generated art)\n- You may design it yourself or work with a human graphic designer\n- Ability to submit artwork digitally prior to DEF CON\n- No specialized technical knowledge required

\n\n

For voters:\n- Attendance at DEF CON\n- Ability to view entries in person and cast a vote\n- Voting is honor-based: one human, one vote\n- Participants may vote

\n\n

No special hardware, software, or prior experience is required to participate or vote.

\n\n

Pre-Qualification

\n\n

A call for sticker designs will open prior to DEF CON with the contest and voting happening on-site.

\n\n

Activity schedule: Thursday setup and preview; Friday and Saturday active voting; contest winner announced Sunday on the Contest Stage. See the Hacker Tracker Contest Stage entry for announcement details.

\n\nLinks:
    DEF CON Groups Website - https://defcongroups.org
\n    Website - https://stickercontest.org/contests/defcon34.html
\n\'',NULL,1296618),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_821b9549fd2398fb38c59f4f0f850391','\'\'',NULL,1296619),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_821b9549fd2398fb38c59f4f0f850391','\'\'',NULL,1296620),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_821b9549fd2398fb38c59f4f0f850391','\'\'',NULL,1296621),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_821b9549fd2398fb38c59f4f0f850391','\'\'',NULL,1296622),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_821b9549fd2398fb38c59f4f0f850391','\'\'',NULL,1296623),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_821b9549fd2398fb38c59f4f0f850391','\'\'',NULL,1296624),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_821b9549fd2398fb38c59f4f0f850391','\'\'',NULL,1296625),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_42990371d317b847fe86b3e5fceb9b46','\'Title: DEF CON Groups Sticker Contest
\nTags: DEF CON Groups | DEF CON Groups Sticker Contest | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n

The DCG Sticker Contest is a sticker design contest withwinner by popular vote and voting happening during DEF CON 34.

\n\n

Anyone can submit original, human-created sticker designs prior to DEF CON 34. During DC34 attendees view all entries on site, and vote in person for their favorites. Designs will be displayed in the DEF CON Groups Community space throughout the conference, with voting open on Thursday to Saturday and the winning design announced on Sunday.

\n\n

Stickers are hacker currency. This contest is about celebrating that culture through creativity, participation, and community choice. The top designs go through to the voting round. What wins is what the DEF CON community votes for.

\n\n

Whether you want to support fellow hackers, or help decide the winning design, this is your chance to participate directly.

\n\n

Participant Prerequisites

\n\n

For designers / contributors:\n- Original sticker artwork created by a human (no AI-generated art)\n- You may design it yourself or work with a human graphic designer\n- Ability to submit artwork digitally prior to DEF CON\n- No specialized technical knowledge required

\n\n

For voters:\n- Attendance at DEF CON\n- Ability to view entries in person and cast a vote\n- Voting is honor-based: one human, one vote\n- Participants may vote

\n\n

No special hardware, software, or prior experience is required to participate or vote.

\n\n

Pre-Qualification

\n\n

A call for sticker designs will open prior to DEF CON with the contest and voting happening on-site.

\n\n

Activity schedule: Thursday setup and preview; Friday and Saturday active voting; contest winner announced Sunday on the Contest Stage. See the Hacker Tracker Contest Stage entry for announcement details.

\n\nLinks:
    DEF CON Groups Website - https://defcongroups.org
\n    Website - https://stickercontest.org/contests/defcon34.html
\n\'',NULL,1296626),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_42990371d317b847fe86b3e5fceb9b46','\'\'',NULL,1296627),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_42990371d317b847fe86b3e5fceb9b46','\'\'',NULL,1296628),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_42990371d317b847fe86b3e5fceb9b46','\'\'',NULL,1296629),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_42990371d317b847fe86b3e5fceb9b46','\'\'',NULL,1296630),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_42990371d317b847fe86b3e5fceb9b46','\'\'',NULL,1296631),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_42990371d317b847fe86b3e5fceb9b46','\'\'',NULL,1296632),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Sticker Contest\'','\'\'','Contests_42990371d317b847fe86b3e5fceb9b46','\'\'',NULL,1296633),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_1af18d937a6e1bc6efca3c7cf1691769','\'Title: DEF CON Groups Backdoors & Breaches
\nTags: DEF CON Groups | DEF CON Groups Backdoor & Breaches | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n

Tournament-Style Backdoors & Breaches Competitive – Live Incident Response Showdowns The DEF CON Groups Community is bringing live, bracket-style Backdoors & Breaches Competitive Games to DEF CON 34. Backdoors & Breaches is an incident response card game built around realistic breach scenarios. In our tournament format, teams step into the roles of adversaries, where they will take turns attacking or defending against each other. They must analyze scenarios, identify adversarial tactics, make technical and business decisions, and mitigate damage before attackers wipe them out of the game. This isn’t passive content. This is live, projected, real-time decision-making. Matches will be bracketed and displayed on screen so attendees can watch strategies unfold, debate choices, and learn from both brilliant plays and catastrophic missteps. Spectators become students of the game — observing how attacks progress, how defenders prioritize, and how communication and leadership shape outcomes. Participants can: • Join the tournament on the spot — no pre-qualifiers required • Compete in structured brackets • Win donated swag • Learn incident response by doing, not just listening What will you learn? You’ll see how modern attacks move from initial access to impact. You’ll experience the tension of limited funding. You’ll learn how small decisions compound during an incident. You’ll understand how legal, executive, and technical perspectives collide in a breach scenario. Most importantly, you’ll build intuition for thinking like both attackers and defenders. This is hacking culture through simulation: adversary thinking, defensive strategy, rapid analysis, and creative problem solving — all wrapped in competition. Located inside the DCG Community space, the tournament creates visible energy and draws attendees into a broader ecosystem of DEF CON Groups, workshops, sticker contests, and community collaboration. If you’ve ever wanted to see incident response as a spectator sport — or test your instincts under pressure — pull up a chair.

\n\nSpeakers:Tim Doerges,Seth Benning
\n
\nSpeakerBio:  Tim Doerges, Lead Developer | Backdoors & Breaches at Black Hills Information Security
\n

Tim Doerges is the Lead Developer for Backdoors & Breaches at Black Hills Information Security and will facilitate the live tournament-style matches at DEF CON 34.

\n\nSpeakerBio:  Seth Benning, Product Developer at Black Hills Information Security
\n

Seth Benning is an Assistant Conference Coordinator and Product Developer with Wild West Hackin\' Fest and Black Hills Information Security. He will help facilitate the Backdoors & Breaches tournament at DEF CON 34.

\n\n\nLinks:
    Website - https://www.blackhillsinfosec.com/tools/backdoorsandbreaches/
\n\'',NULL,1296634),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_1af18d937a6e1bc6efca3c7cf1691769','\'\'',NULL,1296635),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_1af18d937a6e1bc6efca3c7cf1691769','\'\'',NULL,1296636),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_1af18d937a6e1bc6efca3c7cf1691769','\'\'',NULL,1296637),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_1af18d937a6e1bc6efca3c7cf1691769','\'\'',NULL,1296638),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_1af18d937a6e1bc6efca3c7cf1691769','\'\'',NULL,1296639),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_1af18d937a6e1bc6efca3c7cf1691769','\'\'',NULL,1296640),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_1af18d937a6e1bc6efca3c7cf1691769','\'\'',NULL,1296641),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_478f2852df8638685c849e413d5f7f80','\'Title: DEF CON Groups Backdoors & Breaches
\nTags: DEF CON Groups | DEF CON Groups Backdoor & Breaches | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n

Tournament-Style Backdoors & Breaches Competitive – Live Incident Response Showdowns The DEF CON Groups Community is bringing live, bracket-style Backdoors & Breaches Competitive Games to DEF CON 34. Backdoors & Breaches is an incident response card game built around realistic breach scenarios. In our tournament format, teams step into the roles of adversaries, where they will take turns attacking or defending against each other. They must analyze scenarios, identify adversarial tactics, make technical and business decisions, and mitigate damage before attackers wipe them out of the game. This isn’t passive content. This is live, projected, real-time decision-making. Matches will be bracketed and displayed on screen so attendees can watch strategies unfold, debate choices, and learn from both brilliant plays and catastrophic missteps. Spectators become students of the game — observing how attacks progress, how defenders prioritize, and how communication and leadership shape outcomes. Participants can: • Join the tournament on the spot — no pre-qualifiers required • Compete in structured brackets • Win donated swag • Learn incident response by doing, not just listening What will you learn? You’ll see how modern attacks move from initial access to impact. You’ll experience the tension of limited funding. You’ll learn how small decisions compound during an incident. You’ll understand how legal, executive, and technical perspectives collide in a breach scenario. Most importantly, you’ll build intuition for thinking like both attackers and defenders. This is hacking culture through simulation: adversary thinking, defensive strategy, rapid analysis, and creative problem solving — all wrapped in competition. Located inside the DCG Community space, the tournament creates visible energy and draws attendees into a broader ecosystem of DEF CON Groups, workshops, sticker contests, and community collaboration. If you’ve ever wanted to see incident response as a spectator sport — or test your instincts under pressure — pull up a chair.

\n\nSpeakers:Tim Doerges,Seth Benning
\n
\nSpeakerBio:  Tim Doerges, Lead Developer | Backdoors & Breaches at Black Hills Information Security
\n

Tim Doerges is the Lead Developer for Backdoors & Breaches at Black Hills Information Security and will facilitate the live tournament-style matches at DEF CON 34.

\n\nSpeakerBio:  Seth Benning, Product Developer at Black Hills Information Security
\n

Seth Benning is an Assistant Conference Coordinator and Product Developer with Wild West Hackin\' Fest and Black Hills Information Security. He will help facilitate the Backdoors & Breaches tournament at DEF CON 34.

\n\n\nLinks:
    Website - https://www.blackhillsinfosec.com/tools/backdoorsandbreaches/
\n\'',NULL,1296642),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_478f2852df8638685c849e413d5f7f80','\'\'',NULL,1296643),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_478f2852df8638685c849e413d5f7f80','\'\'',NULL,1296644),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_478f2852df8638685c849e413d5f7f80','\'\'',NULL,1296645),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_478f2852df8638685c849e413d5f7f80','\'\'',NULL,1296646),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_478f2852df8638685c849e413d5f7f80','\'\'',NULL,1296647),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_478f2852df8638685c849e413d5f7f80','\'\'',NULL,1296648),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 2 W238 (DEF CON Groups)','\'DEF CON Groups Backdoors & Breaches\'','\'Tim Doerges,Seth Benning\'','Contests_478f2852df8638685c849e413d5f7f80','\'\'',NULL,1296649),('2_Friday','15','15:00','15:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Book Signing - Ted Harrington\'','\'Ted Harrington\'','Social Gatherings/Events_b67890976bb8f5c4612e6741a0df0fba','\'Title: Book Signing - Ted Harrington
\nTags: IoT Village | Vendor Book Signing
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Join us Friday, August 7 at 3:00pm for a book signing with co-founder and #1 best selling author Ted Harrington. Each attendee will receive a complimentary signed copy of Hackable, while supplies last. We recommend coming early!

\n\nSpeakerBio:  Ted Harrington
\nNo BIO available
\n\n\'',NULL,1296650),('4_Sunday','11','11:00','13:30','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Wi-Fi Self Defense & Hacker Hunting & For Beginners\'','\'Kody Kinzie\'','Creator Workshops_6d1e171b855d9b80e4cc7293f84de523','\'Title: Wi-Fi Self Defense & Hacker Hunting & For Beginners
\nTags: IoT Village | Creator Workshop
\nWhen: Sunday, Aug 9, 11:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

This course offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Kit Cost: $140. Class Cap: 30.

\n\nSpeakerBio:  Kody Kinzie
\nNo BIO available
\n\nLinks:
    Saturday Purchase & Registration - https://retia.io/products/defcon-day-2-wifi-self-defense-wifi-hacker-hunting-for-beginners
\n    Sunday Purchase & Registration - https://retia.io/products/defcon-day-3-wifi-self-defense-wifi-hacker-hunting-for-beginners
\n    Friday Purchase & Registration - https://retia.io/products/defcon-day-1-wifi-self-defense-wifi-hacker-hunting-for-beginners
\n\'',NULL,1296651),('4_Sunday','12','11:00','13:30','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Wi-Fi Self Defense & Hacker Hunting & For Beginners\'','\'Kody Kinzie\'','Creator Workshops_6d1e171b855d9b80e4cc7293f84de523','\'\'',NULL,1296652),('4_Sunday','13','11:00','13:30','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Wi-Fi Self Defense & Hacker Hunting & For Beginners\'','\'Kody Kinzie\'','Creator Workshops_6d1e171b855d9b80e4cc7293f84de523','\'\'',NULL,1296653),('2_Friday','15','15:45','17:15','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Wi-Fi Self Defense & Hacker Hunting & For Beginners\'','\'Kody Kinzie\'','Creator Workshops_2f40b26121eb3394611f7f265c0ccfec','\'Title: Wi-Fi Self Defense & Hacker Hunting & For Beginners
\nTags: IoT Village | Creator Workshop
\nWhen: Friday, Aug 7, 15:45 - 17:15 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

This course offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Kit Cost: $140. Class Cap: 30.

\n\nSpeakerBio:  Kody Kinzie
\nNo BIO available
\n\nLinks:
    Saturday Purchase & Registration - https://retia.io/products/defcon-day-2-wifi-self-defense-wifi-hacker-hunting-for-beginners
\n    Sunday Purchase & Registration - https://retia.io/products/defcon-day-3-wifi-self-defense-wifi-hacker-hunting-for-beginners
\n    Friday Purchase & Registration - https://retia.io/products/defcon-day-1-wifi-self-defense-wifi-hacker-hunting-for-beginners
\n\'',NULL,1296654),('2_Friday','16','15:45','17:15','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Wi-Fi Self Defense & Hacker Hunting & For Beginners\'','\'Kody Kinzie\'','Creator Workshops_2f40b26121eb3394611f7f265c0ccfec','\'\'',NULL,1296655),('2_Friday','17','15:45','17:15','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Wi-Fi Self Defense & Hacker Hunting & For Beginners\'','\'Kody Kinzie\'','Creator Workshops_2f40b26121eb3394611f7f265c0ccfec','\'\'',NULL,1296656),('3_Saturday','12','12:00','13:30','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Wi-Fi Self Defense & Hacker Hunting & For Beginners\'','\'Kody Kinzie\'','Creator Workshops_5fab17dd5fa33b699ea0b979d11d20e3','\'Title: Wi-Fi Self Defense & Hacker Hunting & For Beginners
\nTags: IoT Village | Creator Workshop
\nWhen: Saturday, Aug 8, 12:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

This course offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Kit Cost: $140. Class Cap: 30.

\n\nSpeakerBio:  Kody Kinzie
\nNo BIO available
\n\nLinks:
    Saturday Purchase & Registration - https://retia.io/products/defcon-day-2-wifi-self-defense-wifi-hacker-hunting-for-beginners
\n    Sunday Purchase & Registration - https://retia.io/products/defcon-day-3-wifi-self-defense-wifi-hacker-hunting-for-beginners
\n    Friday Purchase & Registration - https://retia.io/products/defcon-day-1-wifi-self-defense-wifi-hacker-hunting-for-beginners
\n\'',NULL,1296657),('3_Saturday','13','12:00','13:30','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Wi-Fi Self Defense & Hacker Hunting & For Beginners\'','\'Kody Kinzie\'','Creator Workshops_5fab17dd5fa33b699ea0b979d11d20e3','\'\'',NULL,1296658),('2_Friday','10','10:30','11:30','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Make your very own evil IoT Cat Lamp with WLED!\'','\'Nick\'','Creator Workshops_f7ff1902b1cb9a8089e9dc715adfec27','\'Title: Make your very own evil IoT Cat Lamp with WLED!
\nTags: IoT Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this class, we’ll put together a \'Purrsheen\' cat shaped Wi-Fi lamp. Kit Cost: $60. Class Cap: 30.

\n\nSpeakerBio:  Nick
\nNo BIO available
\n\nLinks:
    Friday Purchase & Registration - https://retia.io/products/hope-make-your-own-evil-iot-cat-lamp-with-wled
\n    Sunday Purchase & Registration - https://retia.io/products/defcon-day-2-make-your-own-evil-iot-cat-lamp-with-wled
\n\'',NULL,1296659),('2_Friday','11','10:30','11:30','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Make your very own evil IoT Cat Lamp with WLED!\'','\'Nick\'','Creator Workshops_f7ff1902b1cb9a8089e9dc715adfec27','\'\'',NULL,1296660),('4_Sunday','10','10:15','10:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Make your very own evil IoT Cat Lamp with WLED!\'','\'Nick\'','Creator Workshops_e02da7770528036f0f33e01319ab2a26','\'Title: Make your very own evil IoT Cat Lamp with WLED!
\nTags: IoT Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:15 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this class, we’ll put together a \'Purrsheen\' cat shaped Wi-Fi lamp. Kit Cost: $60. Class Cap: 30.

\n\nSpeakerBio:  Nick
\nNo BIO available
\n\nLinks:
    Friday Purchase & Registration - https://retia.io/products/hope-make-your-own-evil-iot-cat-lamp-with-wled
\n    Sunday Purchase & Registration - https://retia.io/products/defcon-day-2-make-your-own-evil-iot-cat-lamp-with-wled
\n\'',NULL,1296661),('2_Friday','13','13:45','15:15','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!\'','\'Kody Kinzie\'','Creator Workshops_4df1b3553e90056c4d647d513f3658fc','\'Title: Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!
\nTags: IoT Village | Creator Workshop
\nWhen: Friday, Aug 7, 13:45 - 15:15 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. Kit Cost: $140. Class Cap: 30.

\n\nSpeakerBio:  Kody Kinzie
\nNo BIO available
\n\nLinks:
    Saturday Purchase & Registration - https://retia.io/products/defcon-day-2-mesh-nets-for-hackers-how-when-to-use-meshtastic-meshcore-reticulum
\n    Friday Purchase & Registration - https://retia.io/products/defcon-day-1-mesh-nets-for-hackers-how-when-to-use-meshtastic-meshcore-reticulum
\n\'',NULL,1296662),('2_Friday','14','13:45','15:15','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!\'','\'Kody Kinzie\'','Creator Workshops_4df1b3553e90056c4d647d513f3658fc','\'\'',NULL,1296663),('2_Friday','15','13:45','15:15','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!\'','\'Kody Kinzie\'','Creator Workshops_4df1b3553e90056c4d647d513f3658fc','\'\'',NULL,1296664),('3_Saturday','15','15:00','16:30','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!\'','\'Kody Kinzie\'','Creator Workshops_8c5252d677b09c045b5a7fe6a815b1b2','\'Title: Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!
\nTags: IoT Village | Creator Workshop
\nWhen: Saturday, Aug 8, 15:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. Kit Cost: $140. Class Cap: 30.

\n\nSpeakerBio:  Kody Kinzie
\nNo BIO available
\n\nLinks:
    Saturday Purchase & Registration - https://retia.io/products/defcon-day-2-mesh-nets-for-hackers-how-when-to-use-meshtastic-meshcore-reticulum
\n    Friday Purchase & Registration - https://retia.io/products/defcon-day-1-mesh-nets-for-hackers-how-when-to-use-meshtastic-meshcore-reticulum
\n\'',NULL,1296665),('3_Saturday','16','15:00','16:30','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!\'','\'Kody Kinzie\'','Creator Workshops_8c5252d677b09c045b5a7fe6a815b1b2','\'\'',NULL,1296666),('3_Saturday','10','10:30','11:45','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Playing with Hyper-local Pocket-Sized Servers\'','\'Brandon\'','Creator Workshops_1d184400e541ca21e354c3acc6330667','\'Title: Playing with Hyper-local Pocket-Sized Servers
\nTags: IoT Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:30 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

In this hands-on workshop, we’ll turn an ESP8266 into a self-contained Wi-Fi pocket server that anyone nearby can connect to without the internet. Kit Cost: $80. Class Cap: 30.

\n\nSpeakerBio:  Brandon
\nNo BIO available
\n\nLinks:
    Saturday Purchase & Registration - https://retia.io/products/defcon-day-2-playing-with-hyper-local-pocket-sized-servers
\n\'',NULL,1296667),('3_Saturday','11','10:30','11:45','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Playing with Hyper-local Pocket-Sized Servers\'','\'Brandon\'','Creator Workshops_1d184400e541ca21e354c3acc6330667','\'\'',NULL,1296668),('2_Friday','12','12:00','13:30','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Build Your Own Meshtastic Node: Off-Grid, Encrypted LoRa Meshnets for Beginners!\'','\'Kody Kinzie\'','Creator Workshops_bceb507e7e4fe8af08dae7c72ac3e203','\'Title: Build Your Own Meshtastic Node: Off-Grid, Encrypted LoRa Meshnets for Beginners!
\nTags: IoT Village | Creator Workshop
\nWhen: Friday, Aug 7, 12:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Beginners can now create off-grid, encrypted mesh networks for cheap, with applications in emergency communication, sensor monitoring, and more! Kit Cost: $80. Class Cap: 30.

\n\nSpeakerBio:  Kody Kinzie
\nNo BIO available
\n\nLinks:
    Friday Purchase & Registration - https://retia.io/products/defcon-build-your-own-meshtastic-node-off-grid-encrypted-lora-meshnets-for-beginners
\n\'',NULL,1296669),('2_Friday','13','12:00','13:30','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Build Your Own Meshtastic Node: Off-Grid, Encrypted LoRa Meshnets for Beginners!\'','\'Kody Kinzie\'','Creator Workshops_bceb507e7e4fe8af08dae7c72ac3e203','\'\'',NULL,1296670),('4_Sunday','10','10:00','13:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_98200fe436c73d6bc2bc5da8f455908f','\'Title: All About UART
\nTags: IoT Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

UART, it’s in your smart camera, router, maybe even your phone and it’s usually the easiest foothold into a device. In this hands-on workshop you’ll learn to find it with a multimeter, read it with a logic analyzer...

\n\nLinks:
    More Info - https://training.brownfinesecurity.com
\n\'',NULL,1296671),('4_Sunday','11','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_98200fe436c73d6bc2bc5da8f455908f','\'\'',NULL,1296672),('4_Sunday','12','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_98200fe436c73d6bc2bc5da8f455908f','\'\'',NULL,1296673),('4_Sunday','13','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_98200fe436c73d6bc2bc5da8f455908f','\'\'',NULL,1296674),('2_Friday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_43eba2e2f100540400a4052252794ed2','\'Title: All About UART
\nTags: IoT Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

UART, it’s in your smart camera, router, maybe even your phone and it’s usually the easiest foothold into a device. In this hands-on workshop you’ll learn to find it with a multimeter, read it with a logic analyzer...

\n\nLinks:
    More Info - https://training.brownfinesecurity.com
\n\'',NULL,1296675),('2_Friday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_43eba2e2f100540400a4052252794ed2','\'\'',NULL,1296676),('2_Friday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_43eba2e2f100540400a4052252794ed2','\'\'',NULL,1296677),('2_Friday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_43eba2e2f100540400a4052252794ed2','\'\'',NULL,1296678),('2_Friday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_43eba2e2f100540400a4052252794ed2','\'\'',NULL,1296679),('2_Friday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_43eba2e2f100540400a4052252794ed2','\'\'',NULL,1296680),('2_Friday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_43eba2e2f100540400a4052252794ed2','\'\'',NULL,1296681),('2_Friday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_43eba2e2f100540400a4052252794ed2','\'\'',NULL,1296682),('3_Saturday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_1ecf481d09dd4ece08d2d7a097af61b7','\'Title: All About UART
\nTags: IoT Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

UART, it’s in your smart camera, router, maybe even your phone and it’s usually the easiest foothold into a device. In this hands-on workshop you’ll learn to find it with a multimeter, read it with a logic analyzer...

\n\nLinks:
    More Info - https://training.brownfinesecurity.com
\n\'',NULL,1296683),('3_Saturday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_1ecf481d09dd4ece08d2d7a097af61b7','\'\'',NULL,1296684),('3_Saturday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_1ecf481d09dd4ece08d2d7a097af61b7','\'\'',NULL,1296685),('3_Saturday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_1ecf481d09dd4ece08d2d7a097af61b7','\'\'',NULL,1296686),('3_Saturday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_1ecf481d09dd4ece08d2d7a097af61b7','\'\'',NULL,1296687),('3_Saturday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_1ecf481d09dd4ece08d2d7a097af61b7','\'\'',NULL,1296688),('3_Saturday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_1ecf481d09dd4ece08d2d7a097af61b7','\'\'',NULL,1296689),('3_Saturday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'All About UART\'','\'\'','Creator Workshops_1ecf481d09dd4ece08d2d7a097af61b7','\'\'',NULL,1296690),('3_Saturday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_8db570ed734fdf4f8e0132dfde14e036','\'Title: Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology
\nTags: IoT Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Encrypted IoT firmware doesn’t have to be a dead end. In this hands-on workshop, we’ll reconstruct a real vendor’s firmware decryption pipeline without ever touching the hardware...

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296691),('3_Saturday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_8db570ed734fdf4f8e0132dfde14e036','\'\'',NULL,1296692),('3_Saturday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_8db570ed734fdf4f8e0132dfde14e036','\'\'',NULL,1296693),('3_Saturday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_8db570ed734fdf4f8e0132dfde14e036','\'\'',NULL,1296694),('3_Saturday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_8db570ed734fdf4f8e0132dfde14e036','\'\'',NULL,1296695),('3_Saturday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_8db570ed734fdf4f8e0132dfde14e036','\'\'',NULL,1296696),('3_Saturday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_8db570ed734fdf4f8e0132dfde14e036','\'\'',NULL,1296697),('3_Saturday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_8db570ed734fdf4f8e0132dfde14e036','\'\'',NULL,1296698),('4_Sunday','10','10:00','13:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_295b815c7a8bb5af6f50ef621ca82bbc','\'Title: Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology
\nTags: IoT Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Encrypted IoT firmware doesn’t have to be a dead end. In this hands-on workshop, we’ll reconstruct a real vendor’s firmware decryption pipeline without ever touching the hardware...

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296699),('4_Sunday','11','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_295b815c7a8bb5af6f50ef621ca82bbc','\'\'',NULL,1296700),('4_Sunday','12','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_295b815c7a8bb5af6f50ef621ca82bbc','\'\'',NULL,1296701),('4_Sunday','13','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_295b815c7a8bb5af6f50ef621ca82bbc','\'\'',NULL,1296702),('2_Friday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_381067d41533bd1b853b7c0b7e2fbfe2','\'Title: Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology
\nTags: IoT Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Encrypted IoT firmware doesn’t have to be a dead end. In this hands-on workshop, we’ll reconstruct a real vendor’s firmware decryption pipeline without ever touching the hardware...

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296703),('2_Friday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_381067d41533bd1b853b7c0b7e2fbfe2','\'\'',NULL,1296704),('2_Friday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_381067d41533bd1b853b7c0b7e2fbfe2','\'\'',NULL,1296705),('2_Friday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_381067d41533bd1b853b7c0b7e2fbfe2','\'\'',NULL,1296706),('2_Friday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_381067d41533bd1b853b7c0b7e2fbfe2','\'\'',NULL,1296707),('2_Friday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_381067d41533bd1b853b7c0b7e2fbfe2','\'\'',NULL,1296708),('2_Friday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_381067d41533bd1b853b7c0b7e2fbfe2','\'\'',NULL,1296709),('2_Friday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology\'','\'\'','Creator Workshops_381067d41533bd1b853b7c0b7e2fbfe2','\'\'',NULL,1296710),('4_Sunday','10','10:00','13:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_7eb69a1660041eae898607803924aa85','\'Title: Just Hacking Training
\nTags: IoT Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

2 Mini-Workshops, Only 15 Minutes Each: QEMU: Emulate Your \'Things\' – Hack a Drug Lord’s Smart Toilet; Encryption! What Encryption? – Decrypt TLS Traffic with mitmproxy. No Schedule.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296711),('4_Sunday','11','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_7eb69a1660041eae898607803924aa85','\'\'',NULL,1296712),('4_Sunday','12','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_7eb69a1660041eae898607803924aa85','\'\'',NULL,1296713),('4_Sunday','13','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_7eb69a1660041eae898607803924aa85','\'\'',NULL,1296714),('2_Friday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_ff742786551af0e15cde8d37ce5fcf33','\'Title: Just Hacking Training
\nTags: IoT Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

2 Mini-Workshops, Only 15 Minutes Each: QEMU: Emulate Your \'Things\' – Hack a Drug Lord’s Smart Toilet; Encryption! What Encryption? – Decrypt TLS Traffic with mitmproxy. No Schedule.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296715),('2_Friday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_ff742786551af0e15cde8d37ce5fcf33','\'\'',NULL,1296716),('2_Friday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_ff742786551af0e15cde8d37ce5fcf33','\'\'',NULL,1296717),('2_Friday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_ff742786551af0e15cde8d37ce5fcf33','\'\'',NULL,1296718),('2_Friday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_ff742786551af0e15cde8d37ce5fcf33','\'\'',NULL,1296719),('2_Friday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_ff742786551af0e15cde8d37ce5fcf33','\'\'',NULL,1296720),('2_Friday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_ff742786551af0e15cde8d37ce5fcf33','\'\'',NULL,1296721),('2_Friday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_ff742786551af0e15cde8d37ce5fcf33','\'\'',NULL,1296722),('3_Saturday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_65cb07dabf11f46bed1e2a107b7b6d72','\'Title: Just Hacking Training
\nTags: IoT Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

2 Mini-Workshops, Only 15 Minutes Each: QEMU: Emulate Your \'Things\' – Hack a Drug Lord’s Smart Toilet; Encryption! What Encryption? – Decrypt TLS Traffic with mitmproxy. No Schedule.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296723),('3_Saturday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_65cb07dabf11f46bed1e2a107b7b6d72','\'\'',NULL,1296724),('3_Saturday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_65cb07dabf11f46bed1e2a107b7b6d72','\'\'',NULL,1296725),('3_Saturday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_65cb07dabf11f46bed1e2a107b7b6d72','\'\'',NULL,1296726),('3_Saturday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_65cb07dabf11f46bed1e2a107b7b6d72','\'\'',NULL,1296727),('3_Saturday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_65cb07dabf11f46bed1e2a107b7b6d72','\'\'',NULL,1296728),('3_Saturday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_65cb07dabf11f46bed1e2a107b7b6d72','\'\'',NULL,1296729),('3_Saturday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Just Hacking Training\'','\'\'','Creator Workshops_65cb07dabf11f46bed1e2a107b7b6d72','\'\'',NULL,1296730),('2_Friday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_f03725181e53519b887c2596a7dc9466','\'Title: Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access
\nTags: IoT Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Using tools like OpenOCD and Segger J-Link Mini, we’ll guide you through modifying the boot \'init=\' process in memory via JTAG, forcing the device into a single user mode shell via UART.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296731),('2_Friday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_f03725181e53519b887c2596a7dc9466','\'\'',NULL,1296732),('2_Friday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_f03725181e53519b887c2596a7dc9466','\'\'',NULL,1296733),('2_Friday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_f03725181e53519b887c2596a7dc9466','\'\'',NULL,1296734),('2_Friday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_f03725181e53519b887c2596a7dc9466','\'\'',NULL,1296735),('2_Friday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_f03725181e53519b887c2596a7dc9466','\'\'',NULL,1296736),('2_Friday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_f03725181e53519b887c2596a7dc9466','\'\'',NULL,1296737),('2_Friday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_f03725181e53519b887c2596a7dc9466','\'\'',NULL,1296738),('3_Saturday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_5c3c8603e4566105d263a4012f4ee9ca','\'Title: Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access
\nTags: IoT Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Using tools like OpenOCD and Segger J-Link Mini, we’ll guide you through modifying the boot \'init=\' process in memory via JTAG, forcing the device into a single user mode shell via UART.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296739),('3_Saturday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_5c3c8603e4566105d263a4012f4ee9ca','\'\'',NULL,1296740),('3_Saturday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_5c3c8603e4566105d263a4012f4ee9ca','\'\'',NULL,1296741),('3_Saturday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_5c3c8603e4566105d263a4012f4ee9ca','\'\'',NULL,1296742),('3_Saturday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_5c3c8603e4566105d263a4012f4ee9ca','\'\'',NULL,1296743),('3_Saturday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_5c3c8603e4566105d263a4012f4ee9ca','\'\'',NULL,1296744),('3_Saturday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_5c3c8603e4566105d263a4012f4ee9ca','\'\'',NULL,1296745),('3_Saturday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_5c3c8603e4566105d263a4012f4ee9ca','\'\'',NULL,1296746),('4_Sunday','10','10:00','13:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_9d10a7a99eac25ae404fca63ea33c941','\'Title: Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access
\nTags: IoT Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Using tools like OpenOCD and Segger J-Link Mini, we’ll guide you through modifying the boot \'init=\' process in memory via JTAG, forcing the device into a single user mode shell via UART.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296747),('4_Sunday','11','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_9d10a7a99eac25ae404fca63ea33c941','\'\'',NULL,1296748),('4_Sunday','12','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_9d10a7a99eac25ae404fca63ea33c941','\'\'',NULL,1296749),('4_Sunday','13','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access\'','\'\'','Creator Workshops_9d10a7a99eac25ae404fca63ea33c941','\'\'',NULL,1296750),('2_Friday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_6a2bc4bc55c5066c8795be3e270aa859','\'Title: Cat-astrophic Hacking: Breaking Into Smart Litter Boxes
\nTags: IoT Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

What happens when your cat’s litter box joins the Internet of Things? Join Suzu Labs as we dissect, analyze, and hack smart litter robots to uncover security risks.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296751),('2_Friday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_6a2bc4bc55c5066c8795be3e270aa859','\'\'',NULL,1296752),('2_Friday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_6a2bc4bc55c5066c8795be3e270aa859','\'\'',NULL,1296753),('2_Friday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_6a2bc4bc55c5066c8795be3e270aa859','\'\'',NULL,1296754),('2_Friday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_6a2bc4bc55c5066c8795be3e270aa859','\'\'',NULL,1296755),('2_Friday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_6a2bc4bc55c5066c8795be3e270aa859','\'\'',NULL,1296756),('2_Friday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_6a2bc4bc55c5066c8795be3e270aa859','\'\'',NULL,1296757),('2_Friday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_6a2bc4bc55c5066c8795be3e270aa859','\'\'',NULL,1296758),('3_Saturday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_be1f7e8969308cb13db9c3a74d4c1ee2','\'Title: Cat-astrophic Hacking: Breaking Into Smart Litter Boxes
\nTags: IoT Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

What happens when your cat’s litter box joins the Internet of Things? Join Suzu Labs as we dissect, analyze, and hack smart litter robots to uncover security risks.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296759),('3_Saturday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_be1f7e8969308cb13db9c3a74d4c1ee2','\'\'',NULL,1296760),('3_Saturday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_be1f7e8969308cb13db9c3a74d4c1ee2','\'\'',NULL,1296761),('3_Saturday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_be1f7e8969308cb13db9c3a74d4c1ee2','\'\'',NULL,1296762),('3_Saturday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_be1f7e8969308cb13db9c3a74d4c1ee2','\'\'',NULL,1296763),('3_Saturday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_be1f7e8969308cb13db9c3a74d4c1ee2','\'\'',NULL,1296764),('3_Saturday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_be1f7e8969308cb13db9c3a74d4c1ee2','\'\'',NULL,1296765),('3_Saturday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_be1f7e8969308cb13db9c3a74d4c1ee2','\'\'',NULL,1296766),('4_Sunday','10','10:00','13:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_0adb7a2115fa4e6307e63456d2b04a70','\'Title: Cat-astrophic Hacking: Breaking Into Smart Litter Boxes
\nTags: IoT Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

What happens when your cat’s litter box joins the Internet of Things? Join Suzu Labs as we dissect, analyze, and hack smart litter robots to uncover security risks.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296767),('4_Sunday','11','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_0adb7a2115fa4e6307e63456d2b04a70','\'\'',NULL,1296768),('4_Sunday','12','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_0adb7a2115fa4e6307e63456d2b04a70','\'\'',NULL,1296769),('4_Sunday','13','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Cat-astrophic Hacking: Breaking Into Smart Litter Boxes\'','\'\'','Creator Events_0adb7a2115fa4e6307e63456d2b04a70','\'\'',NULL,1296770),('4_Sunday','10','10:00','13:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_51a6a27eb65fcc01bbedd517ab2476de','\'Title: Discover GE Appliances!
\nTags: IoT Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Join us for a self-guided interactive look at GE Appliances and get hands on with some of our most popular home appliances!

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296771),('4_Sunday','11','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_51a6a27eb65fcc01bbedd517ab2476de','\'\'',NULL,1296772),('4_Sunday','12','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_51a6a27eb65fcc01bbedd517ab2476de','\'\'',NULL,1296773),('4_Sunday','13','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_51a6a27eb65fcc01bbedd517ab2476de','\'\'',NULL,1296774),('3_Saturday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_9c6407ccffb6969826c561068136e0a3','\'Title: Discover GE Appliances!
\nTags: IoT Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Join us for a self-guided interactive look at GE Appliances and get hands on with some of our most popular home appliances!

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296775),('3_Saturday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_9c6407ccffb6969826c561068136e0a3','\'\'',NULL,1296776),('3_Saturday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_9c6407ccffb6969826c561068136e0a3','\'\'',NULL,1296777),('3_Saturday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_9c6407ccffb6969826c561068136e0a3','\'\'',NULL,1296778),('3_Saturday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_9c6407ccffb6969826c561068136e0a3','\'\'',NULL,1296779),('3_Saturday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_9c6407ccffb6969826c561068136e0a3','\'\'',NULL,1296780),('3_Saturday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_9c6407ccffb6969826c561068136e0a3','\'\'',NULL,1296781),('3_Saturday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_9c6407ccffb6969826c561068136e0a3','\'\'',NULL,1296782),('2_Friday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_4a3409f76e3d49a1631319fa315f077d','\'Title: Discover GE Appliances!
\nTags: IoT Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Join us for a self-guided interactive look at GE Appliances and get hands on with some of our most popular home appliances!

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296783),('2_Friday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_4a3409f76e3d49a1631319fa315f077d','\'\'',NULL,1296784),('2_Friday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_4a3409f76e3d49a1631319fa315f077d','\'\'',NULL,1296785),('2_Friday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_4a3409f76e3d49a1631319fa315f077d','\'\'',NULL,1296786),('2_Friday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_4a3409f76e3d49a1631319fa315f077d','\'\'',NULL,1296787),('2_Friday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_4a3409f76e3d49a1631319fa315f077d','\'\'',NULL,1296788),('2_Friday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_4a3409f76e3d49a1631319fa315f077d','\'\'',NULL,1296789),('2_Friday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Discover GE Appliances!\'','\'\'','Creator Events_4a3409f76e3d49a1631319fa315f077d','\'\'',NULL,1296790),('2_Friday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_e8a493bfc7d145b3977e2699a7e126f5','\'Title: Smart Home in the Matter: Blink, Race, Attack CTF
\nTags: IoT Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Bitdefender and Netgear invite you into the smart-home arena, where the Matter fabric pulses with secrets, traps, and unexpected twists, and where AI can finally take a break while your critical thinking takes the lead.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296791),('2_Friday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_e8a493bfc7d145b3977e2699a7e126f5','\'\'',NULL,1296792),('2_Friday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_e8a493bfc7d145b3977e2699a7e126f5','\'\'',NULL,1296793),('2_Friday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_e8a493bfc7d145b3977e2699a7e126f5','\'\'',NULL,1296794),('2_Friday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_e8a493bfc7d145b3977e2699a7e126f5','\'\'',NULL,1296795),('2_Friday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_e8a493bfc7d145b3977e2699a7e126f5','\'\'',NULL,1296796),('2_Friday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_e8a493bfc7d145b3977e2699a7e126f5','\'\'',NULL,1296797),('2_Friday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_e8a493bfc7d145b3977e2699a7e126f5','\'\'',NULL,1296798),('4_Sunday','10','10:00','13:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_aea049b9482e41ab851a599f40f9c55d','\'Title: Smart Home in the Matter: Blink, Race, Attack CTF
\nTags: IoT Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Bitdefender and Netgear invite you into the smart-home arena, where the Matter fabric pulses with secrets, traps, and unexpected twists, and where AI can finally take a break while your critical thinking takes the lead.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296799),('4_Sunday','11','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_aea049b9482e41ab851a599f40f9c55d','\'\'',NULL,1296800),('4_Sunday','12','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_aea049b9482e41ab851a599f40f9c55d','\'\'',NULL,1296801),('4_Sunday','13','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_aea049b9482e41ab851a599f40f9c55d','\'\'',NULL,1296802),('3_Saturday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_7ffba228964c43de206edadafdcfd7e1','\'Title: Smart Home in the Matter: Blink, Race, Attack CTF
\nTags: IoT Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Bitdefender and Netgear invite you into the smart-home arena, where the Matter fabric pulses with secrets, traps, and unexpected twists, and where AI can finally take a break while your critical thinking takes the lead.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296803),('3_Saturday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_7ffba228964c43de206edadafdcfd7e1','\'\'',NULL,1296804),('3_Saturday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_7ffba228964c43de206edadafdcfd7e1','\'\'',NULL,1296805),('3_Saturday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_7ffba228964c43de206edadafdcfd7e1','\'\'',NULL,1296806),('3_Saturday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_7ffba228964c43de206edadafdcfd7e1','\'\'',NULL,1296807),('3_Saturday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_7ffba228964c43de206edadafdcfd7e1','\'\'',NULL,1296808),('3_Saturday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_7ffba228964c43de206edadafdcfd7e1','\'\'',NULL,1296809),('3_Saturday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Smart Home in the Matter: Blink, Race, Attack CTF\'','\'\'','Creator Events_7ffba228964c43de206edadafdcfd7e1','\'\'',NULL,1296810),('4_Sunday','10','10:00','13:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_8f464c2563033717d5757b8487419c57','\'Title: Expose Hidden Surveillance in Everyday Tech
\nTags: IoT Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Join the Ludlow Institute Surveillance Mission. Dump firmware, capture packets, probe APIs, or tear devices apart however you like. Prizes up for grabs.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296811),('4_Sunday','11','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_8f464c2563033717d5757b8487419c57','\'\'',NULL,1296812),('4_Sunday','12','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_8f464c2563033717d5757b8487419c57','\'\'',NULL,1296813),('4_Sunday','13','10:00','13:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_8f464c2563033717d5757b8487419c57','\'\'',NULL,1296814),('3_Saturday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_43d4c209f16ace3dc4c19c5f40be6156','\'Title: Expose Hidden Surveillance in Everyday Tech
\nTags: IoT Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Join the Ludlow Institute Surveillance Mission. Dump firmware, capture packets, probe APIs, or tear devices apart however you like. Prizes up for grabs.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296815),('3_Saturday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_43d4c209f16ace3dc4c19c5f40be6156','\'\'',NULL,1296816),('3_Saturday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_43d4c209f16ace3dc4c19c5f40be6156','\'\'',NULL,1296817),('3_Saturday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_43d4c209f16ace3dc4c19c5f40be6156','\'\'',NULL,1296818),('3_Saturday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_43d4c209f16ace3dc4c19c5f40be6156','\'\'',NULL,1296819),('3_Saturday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_43d4c209f16ace3dc4c19c5f40be6156','\'\'',NULL,1296820),('3_Saturday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_43d4c209f16ace3dc4c19c5f40be6156','\'\'',NULL,1296821),('3_Saturday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_43d4c209f16ace3dc4c19c5f40be6156','\'\'',NULL,1296822),('2_Friday','10','10:00','17:59','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_d8312967139f8a1c97934ec98bdc4e93','\'Title: Expose Hidden Surveillance in Everyday Tech
\nTags: IoT Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Join the Ludlow Institute Surveillance Mission. Dump firmware, capture packets, probe APIs, or tear devices apart however you like. Prizes up for grabs.

\n\nLinks:
    More Info - https://iotvillage.org/events/defcon-34/index.html
\n\'',NULL,1296823),('2_Friday','11','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_d8312967139f8a1c97934ec98bdc4e93','\'\'',NULL,1296824),('2_Friday','12','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_d8312967139f8a1c97934ec98bdc4e93','\'\'',NULL,1296825),('2_Friday','13','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_d8312967139f8a1c97934ec98bdc4e93','\'\'',NULL,1296826),('2_Friday','14','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_d8312967139f8a1c97934ec98bdc4e93','\'\'',NULL,1296827),('2_Friday','15','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_d8312967139f8a1c97934ec98bdc4e93','\'\'',NULL,1296828),('2_Friday','16','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_d8312967139f8a1c97934ec98bdc4e93','\'\'',NULL,1296829),('2_Friday','17','10:00','17:59','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Expose Hidden Surveillance in Everyday Tech\'','\'\'','Creator Events_d8312967139f8a1c97934ec98bdc4e93','\'\'',NULL,1296830),('2_Friday','13','13:30','14:30','N','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'Darknet Diaries Meet & Greet with Jack Rhysider\'','\'Jack Rhysider\'','Creator Events_98daf603dc060cd9c62b59e63e8ef64c','\'Title: Darknet Diaries Meet & Greet with Jack Rhysider
\nTags: DEF CON Groups | Creator Event/Activity
\nWhen: Friday, Aug 7, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 2 W238 (DEF CON Groups) - Map
\n
\nDescription:
\n

Meet Jack Rhysider, creator and host of Darknet Diaries, during a special fan meet and greet in the DEF CON Groups Community. Stop by to say hello and talk about your favorite stories from the dark side of the internet. First come, first served.

\n\nSpeakerBio:  Jack Rhysider, Creator and Host at Darknet Diaries
\nNo BIO available
\n\n\'',NULL,1296831),('2_Friday','14','13:30','14:30','Y','DEF CON Groups','LVCCW Level 2 W238 (DEF CON Groups)','\'Darknet Diaries Meet & Greet with Jack Rhysider\'','\'Jack Rhysider\'','Creator Events_98daf603dc060cd9c62b59e63e8ef64c','\'\'',NULL,1296832),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_90668f8128e442fed4e7b8c1aa225ff5','\'Title: HSPACE: AI Battlegrounds
\nTags: HSPACE: AI Battlegrounds | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds) - Map
\n
\nDescription:
\n

\"Your prompt becomes a character, a machine, or an attack—and every word can change what happens next.

\n\n

HSPACE: AI Battlegrounds is a collection of three hands-on games that turn natural-language and visual prompts into playable systems:

\n\n

Wizard of Prompts — Write a short prompt to generate a pixel-art hero with unique stats and skills, then guide that hero through a five-boss, card-based battle campaign. Experiment with wording, build a stronger character, and see how the game\'s AI responds to prompt-injection attempts.

\n\n

Prompt Prix — Describe your ideal race car and watch the AI convert your prompt into a validated vehicle build. Race across changing track conditions, study the result, and tune your prompt to improve the car\'s speed, grip, stability, and final ranking.

\n\n

Vision Breaker — Face a vision-language-model security guard that decides who may enter. Use signs, screens, clothing, props, and visual prompt-injection techniques to influence its observations, bypass its checks, and progress through three escalating stages—from changing a decision to hijacking a command.

\n\n

No joystick, coding experience, or prior security knowledge is required. Come experiment, iterate, and discover how small changes in language and visual context can reshape an AI agent\'s behavior.

\n\n

Participant Prerequisites

\n\n

Anyone who has used AI at least once is welcome. A camera-enabled smartphone or laptop with a modern web browser is recommended for Vision Breaker; camera permission is required for live play. Game stations and physical props are provided at the booth.

\n\n

Participants can also play on their own smartphones or personal laptops. The competitive portion of AI Battlegrounds will be conducted online.\"

\n\nLinks:
    Website - https://aibattlegrounds.hspace.io
\n\'',NULL,1296833),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_90668f8128e442fed4e7b8c1aa225ff5','\'\'',NULL,1296834),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_90668f8128e442fed4e7b8c1aa225ff5','\'\'',NULL,1296835),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_90668f8128e442fed4e7b8c1aa225ff5','\'\'',NULL,1296836),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_90668f8128e442fed4e7b8c1aa225ff5','\'\'',NULL,1296837),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_90668f8128e442fed4e7b8c1aa225ff5','\'\'',NULL,1296838),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_90668f8128e442fed4e7b8c1aa225ff5','\'\'',NULL,1296839),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_90668f8128e442fed4e7b8c1aa225ff5','\'\'',NULL,1296840),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_7565400d55364d1ae2b15a7f5557822c','\'Title: HSPACE: AI Battlegrounds
\nTags: HSPACE: AI Battlegrounds | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds) - Map
\n
\nDescription:
\n

\"Your prompt becomes a character, a machine, or an attack—and every word can change what happens next.

\n\n

HSPACE: AI Battlegrounds is a collection of three hands-on games that turn natural-language and visual prompts into playable systems:

\n\n

Wizard of Prompts — Write a short prompt to generate a pixel-art hero with unique stats and skills, then guide that hero through a five-boss, card-based battle campaign. Experiment with wording, build a stronger character, and see how the game\'s AI responds to prompt-injection attempts.

\n\n

Prompt Prix — Describe your ideal race car and watch the AI convert your prompt into a validated vehicle build. Race across changing track conditions, study the result, and tune your prompt to improve the car\'s speed, grip, stability, and final ranking.

\n\n

Vision Breaker — Face a vision-language-model security guard that decides who may enter. Use signs, screens, clothing, props, and visual prompt-injection techniques to influence its observations, bypass its checks, and progress through three escalating stages—from changing a decision to hijacking a command.

\n\n

No joystick, coding experience, or prior security knowledge is required. Come experiment, iterate, and discover how small changes in language and visual context can reshape an AI agent\'s behavior.

\n\n

Participant Prerequisites

\n\n

Anyone who has used AI at least once is welcome. A camera-enabled smartphone or laptop with a modern web browser is recommended for Vision Breaker; camera permission is required for live play. Game stations and physical props are provided at the booth.

\n\n

Participants can also play on their own smartphones or personal laptops. The competitive portion of AI Battlegrounds will be conducted online.\"

\n\nLinks:
    Website - https://aibattlegrounds.hspace.io
\n\'',NULL,1296841),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_7565400d55364d1ae2b15a7f5557822c','\'\'',NULL,1296842),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_1085629e7439ab7d2c2f703aac876955','\'Title: HSPACE: AI Battlegrounds
\nTags: HSPACE: AI Battlegrounds | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds) - Map
\n
\nDescription:
\n

\"Your prompt becomes a character, a machine, or an attack—and every word can change what happens next.

\n\n

HSPACE: AI Battlegrounds is a collection of three hands-on games that turn natural-language and visual prompts into playable systems:

\n\n

Wizard of Prompts — Write a short prompt to generate a pixel-art hero with unique stats and skills, then guide that hero through a five-boss, card-based battle campaign. Experiment with wording, build a stronger character, and see how the game\'s AI responds to prompt-injection attempts.

\n\n

Prompt Prix — Describe your ideal race car and watch the AI convert your prompt into a validated vehicle build. Race across changing track conditions, study the result, and tune your prompt to improve the car\'s speed, grip, stability, and final ranking.

\n\n

Vision Breaker — Face a vision-language-model security guard that decides who may enter. Use signs, screens, clothing, props, and visual prompt-injection techniques to influence its observations, bypass its checks, and progress through three escalating stages—from changing a decision to hijacking a command.

\n\n

No joystick, coding experience, or prior security knowledge is required. Come experiment, iterate, and discover how small changes in language and visual context can reshape an AI agent\'s behavior.

\n\n

Participant Prerequisites

\n\n

Anyone who has used AI at least once is welcome. A camera-enabled smartphone or laptop with a modern web browser is recommended for Vision Breaker; camera permission is required for live play. Game stations and physical props are provided at the booth.

\n\n

Participants can also play on their own smartphones or personal laptops. The competitive portion of AI Battlegrounds will be conducted online.\"

\n\nLinks:
    Website - https://aibattlegrounds.hspace.io
\n\'',NULL,1296843),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_1085629e7439ab7d2c2f703aac876955','\'\'',NULL,1296844),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_1085629e7439ab7d2c2f703aac876955','\'\'',NULL,1296845),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_1085629e7439ab7d2c2f703aac876955','\'\'',NULL,1296846),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_1085629e7439ab7d2c2f703aac876955','\'\'',NULL,1296847),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_1085629e7439ab7d2c2f703aac876955','\'\'',NULL,1296848),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_1085629e7439ab7d2c2f703aac876955','\'\'',NULL,1296849),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 205 (HSPACE: AI Battlegrounds)','\'HSPACE: AI Battlegrounds\'','\'\'','Contests_1085629e7439ab7d2c2f703aac876955','\'\'',NULL,1296850),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_32ca0c1cd451033f9467184c5da5bc40','\'Title: Car Hacking Village CTF
\nTags: Car Hacking Village | Car Hacking Village Capture the Flag (CTF) | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

Participate in CHV\'s CTF to learn and play with automotive technology. This year\'s contest features problems on smart chargers, automotive ECU harnesses, our own badge, and more! Don\'t worry about bringing your own automotive specific gear, we\'ve got you covered. Stop by the village to register, get started, and get hacking.

\n\nLinks:
    Website - https://www.carhackingvillage.com/
\n\'',NULL,1296851),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_32ca0c1cd451033f9467184c5da5bc40','\'\'',NULL,1296852),('3_Saturday','10','10:00','16:59','N','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_b4916ea6e610374edab396a001249fee','\'Title: Car Hacking Village CTF
\nTags: Car Hacking Village | Car Hacking Village Capture the Flag (CTF) | Contest
\nWhen: Saturday, Aug 8, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

Participate in CHV\'s CTF to learn and play with automotive technology. This year\'s contest features problems on smart chargers, automotive ECU harnesses, our own badge, and more! Don\'t worry about bringing your own automotive specific gear, we\'ve got you covered. Stop by the village to register, get started, and get hacking.

\n\nLinks:
    Website - https://www.carhackingvillage.com/
\n\'',NULL,1296853),('3_Saturday','11','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_b4916ea6e610374edab396a001249fee','\'\'',NULL,1296854),('3_Saturday','12','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_b4916ea6e610374edab396a001249fee','\'\'',NULL,1296855),('3_Saturday','13','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_b4916ea6e610374edab396a001249fee','\'\'',NULL,1296856),('3_Saturday','14','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_b4916ea6e610374edab396a001249fee','\'\'',NULL,1296857),('3_Saturday','15','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_b4916ea6e610374edab396a001249fee','\'\'',NULL,1296858),('3_Saturday','16','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_b4916ea6e610374edab396a001249fee','\'\'',NULL,1296859),('2_Friday','10','10:00','16:59','N','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_a7ec0216400ed65f91a5482d12124fe9','\'Title: Car Hacking Village CTF
\nTags: Car Hacking Village | Car Hacking Village Capture the Flag (CTF) | Contest
\nWhen: Friday, Aug 7, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

Participate in CHV\'s CTF to learn and play with automotive technology. This year\'s contest features problems on smart chargers, automotive ECU harnesses, our own badge, and more! Don\'t worry about bringing your own automotive specific gear, we\'ve got you covered. Stop by the village to register, get started, and get hacking.

\n\nLinks:
    Website - https://www.carhackingvillage.com/
\n\'',NULL,1296860),('2_Friday','11','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_a7ec0216400ed65f91a5482d12124fe9','\'\'',NULL,1296861),('2_Friday','12','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_a7ec0216400ed65f91a5482d12124fe9','\'\'',NULL,1296862),('2_Friday','13','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_a7ec0216400ed65f91a5482d12124fe9','\'\'',NULL,1296863),('2_Friday','14','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_a7ec0216400ed65f91a5482d12124fe9','\'\'',NULL,1296864),('2_Friday','15','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_a7ec0216400ed65f91a5482d12124fe9','\'\'',NULL,1296865),('2_Friday','16','10:00','16:59','Y','Contests','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village CTF\'','\'\'','Contests_a7ec0216400ed65f91a5482d12124fe9','\'\'',NULL,1296866),('2_Friday','10','10:00','16:59','N','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_6371c2802b0b6d5d595119212a87055b','\'Title: Bomb Bot Challenge
\nTags: Car Hacking Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

In conjunction with the talk, \"Hacking the Bomb Bot: How I Learned to Stop Worrying and Love the Boomba\", attendees have the opportunity to operate a bomb disposal robot. For those up for a challenge, you\'ll have a limited amount of time to interact with the robot and test your handling skills. The attendees with the best times will be invited back Sunday morning for a face-off challenge.

\n\n

The winner will get their very own PackBot 510 to take home!

\n\n\'',NULL,1296867),('2_Friday','11','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_6371c2802b0b6d5d595119212a87055b','\'\'',NULL,1296868),('2_Friday','12','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_6371c2802b0b6d5d595119212a87055b','\'\'',NULL,1296869),('2_Friday','13','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_6371c2802b0b6d5d595119212a87055b','\'\'',NULL,1296870),('2_Friday','14','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_6371c2802b0b6d5d595119212a87055b','\'\'',NULL,1296871),('2_Friday','15','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_6371c2802b0b6d5d595119212a87055b','\'\'',NULL,1296872),('2_Friday','16','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_6371c2802b0b6d5d595119212a87055b','\'\'',NULL,1296873),('3_Saturday','10','10:00','16:59','N','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_b81a45d1c00cc2d0efb22aeb04ffb93b','\'Title: Bomb Bot Challenge
\nTags: Car Hacking Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

In conjunction with the talk, \"Hacking the Bomb Bot: How I Learned to Stop Worrying and Love the Boomba\", attendees have the opportunity to operate a bomb disposal robot. For those up for a challenge, you\'ll have a limited amount of time to interact with the robot and test your handling skills. The attendees with the best times will be invited back Sunday morning for a face-off challenge.

\n\n

The winner will get their very own PackBot 510 to take home!

\n\n\'',NULL,1296874),('3_Saturday','11','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_b81a45d1c00cc2d0efb22aeb04ffb93b','\'\'',NULL,1296875),('3_Saturday','12','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_b81a45d1c00cc2d0efb22aeb04ffb93b','\'\'',NULL,1296876),('3_Saturday','13','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_b81a45d1c00cc2d0efb22aeb04ffb93b','\'\'',NULL,1296877),('3_Saturday','14','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_b81a45d1c00cc2d0efb22aeb04ffb93b','\'\'',NULL,1296878),('3_Saturday','15','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_b81a45d1c00cc2d0efb22aeb04ffb93b','\'\'',NULL,1296879),('3_Saturday','16','10:00','16:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Bomb Bot Challenge\'','\'\'','Creator Events_b81a45d1c00cc2d0efb22aeb04ffb93b','\'\'',NULL,1296880),('2_Friday','12','12:00','12:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Game Time: Input, Output, and Variables\'','\'\'','Creator Workshops_32d68b83d01f5acee78549ac22dbe398','\'Title: Game Time: Input, Output, and Variables
\nTags: CodeBloom | Creator Workshop
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Input, output, and variables are the building blocks behind every single program you\'ve ever used, and once you understand them, you\'re well on your way to writing your own code! In this session, we\'ll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\n\'',NULL,1296881),('3_Saturday','12','12:00','12:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Game Time: Input, Output, and Variables\'','\'\'','Creator Workshops_f7f2e374c22ed01e6c54e2c4521fe72f','\'Title: Game Time: Input, Output, and Variables
\nTags: CodeBloom | Creator Workshop
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Input, output, and variables are the building blocks behind every single program you\'ve ever used, and once you understand them, you\'re well on your way to writing your own code! In this session, we\'ll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\n\'',NULL,1296882),('4_Sunday','12','12:00','12:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Game Time: Input, Output, and Variables\'','\'\'','Creator Workshops_039c589a350e07c269ec10cabd242e24','\'Title: Game Time: Input, Output, and Variables
\nTags: CodeBloom | Creator Workshop
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Input, output, and variables are the building blocks behind every single program you\'ve ever used, and once you understand them, you\'re well on your way to writing your own code! In this session, we\'ll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\n\'',NULL,1296883),('3_Saturday','15','15:00','15:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Game Time: Input, Output, and Variables\'','\'\'','Creator Workshops_b15c434e9e2bd76f04d74973e353a356','\'Title: Game Time: Input, Output, and Variables
\nTags: CodeBloom | Creator Workshop
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Input, output, and variables are the building blocks behind every single program you\'ve ever used, and once you understand them, you\'re well on your way to writing your own code! In this session, we\'ll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\n\'',NULL,1296884),('2_Friday','15','15:00','15:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Game Time: Input, Output, and Variables\'','\'\'','Creator Workshops_423e0c3c5685250a6d6d4242e838bda6','\'Title: Game Time: Input, Output, and Variables
\nTags: CodeBloom | Creator Workshop
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Input, output, and variables are the building blocks behind every single program you\'ve ever used, and once you understand them, you\'re well on your way to writing your own code! In this session, we\'ll play some fun games together to show how these ideas already show up in your everyday life, then practice matching them to real Python code. All are welcome, no coding experience required. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\n\'',NULL,1296885),('4_Sunday','13','13:00','13:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'What is AI?\'','\'Sam Mosley\'','Creator Workshops_42d76f9a76e6eb7ba8d35e7a6e1a19c5','\'Title: What is AI?
\nTags: CodeBloom | Creator Workshop
\nWhen: Sunday, Aug 9, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Curious what is actually happening inside an AI when it answers your questions? In this session, you\'ll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We\'ll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nSpeakerBio:  Sam Mosley, CodeBloom
\nNo BIO available
\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296886),('2_Friday','13','13:00','13:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'What is AI?\'','\'Sam Mosley\'','Creator Workshops_fae90d634ac11bdacb2ffb304a405de2','\'Title: What is AI?
\nTags: CodeBloom | Creator Workshop
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Curious what is actually happening inside an AI when it answers your questions? In this session, you\'ll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We\'ll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nSpeakerBio:  Sam Mosley, CodeBloom
\nNo BIO available
\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296887),('3_Saturday','16','16:00','16:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'What is AI?\'','\'Sam Mosley\'','Creator Workshops_8aee3568796002bed5a70e928f9b53a3','\'Title: What is AI?
\nTags: CodeBloom | Creator Workshop
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Curious what is actually happening inside an AI when it answers your questions? In this session, you\'ll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We\'ll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nSpeakerBio:  Sam Mosley, CodeBloom
\nNo BIO available
\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296888),('2_Friday','16','16:00','16:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'What is AI?\'','\'Sam Mosley\'','Creator Workshops_b4546860602a73ef0c55a497332b8b94','\'Title: What is AI?
\nTags: CodeBloom | Creator Workshop
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Curious what is actually happening inside an AI when it answers your questions? In this session, you\'ll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We\'ll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nSpeakerBio:  Sam Mosley, CodeBloom
\nNo BIO available
\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296889),('3_Saturday','13','13:00','13:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'What is AI?\'','\'Sam Mosley\'','Creator Workshops_92d79fd76c3b7a58e13be344e51d5115','\'Title: What is AI?
\nTags: CodeBloom | Creator Workshop
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Curious what is actually happening inside an AI when it answers your questions? In this session, you\'ll build your very own neural network using flashcards and pipe cleaners, test it out with tricky prompts, and watch what happens when you grow it bigger, just like real AI companies do! We\'ll also talk about how AI models pick up new skills, some of the sneaky ways people try to trick AI, and the clever ways researchers keep AI safe. A fun, hands on way to learn about AI for curious minds of all levels. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nSpeakerBio:  Sam Mosley, CodeBloom
\nNo BIO available
\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296890),('4_Sunday','10','10:00','10:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Game Time: Loops\'','\'\'','Creator Workshops_e299c9bb08287b9cb72cf2851f8cbd49','\'Title: Game Time: Loops
\nTags: CodeBloom | Creator Workshop
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Have you ever had to do the same thing over and over and thought, there has to be an easier way? Good news, there is, and it\'s called a loop! Come play some classic schoolyard games with us and discover that you\'ve been using loops in real life all along. Then we\'ll show you how programmers use for loops and while loops to make computers repeat tasks automatically, whether that\'s counting to 100 or spawning enemies in your favorite video game. No experience needed, just come ready to play! If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296891),('3_Saturday','10','10:00','10:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Game Time: Loops\'','\'\'','Creator Workshops_8404e347308587edd9891831c2328c30','\'Title: Game Time: Loops
\nTags: CodeBloom | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Have you ever had to do the same thing over and over and thought, there has to be an easier way? Good news, there is, and it\'s called a loop! Come play some classic schoolyard games with us and discover that you\'ve been using loops in real life all along. Then we\'ll show you how programmers use for loops and while loops to make computers repeat tasks automatically, whether that\'s counting to 100 or spawning enemies in your favorite video game. No experience needed, just come ready to play! If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296892),('2_Friday','10','10:00','10:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Game Time: Loops\'','\'\'','Creator Workshops_32b6f0b8c74951c8740dcb567546cd63','\'Title: Game Time: Loops
\nTags: CodeBloom | Creator Workshop
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Have you ever had to do the same thing over and over and thought, there has to be an easier way? Good news, there is, and it\'s called a loop! Come play some classic schoolyard games with us and discover that you\'ve been using loops in real life all along. Then we\'ll show you how programmers use for loops and while loops to make computers repeat tasks automatically, whether that\'s counting to 100 or spawning enemies in your favorite video game. No experience needed, just come ready to play! If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296893),('2_Friday','17','17:00','17:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Work Session: Binary Code\'','\'\'','Creator Workshops_5f4bf8e62dfd58a2234d33d2140a99c7','\'Title: Work Session: Binary Code
\nTags: CodeBloom | Creator Workshop
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Did you know that every photo, song, and message on your phone is really just a long string of 0s and 1s? Come learn how binary code works and then turn your very own secret word into a wearable friendship bracelet using our binary alphabet chart! This session is beginner friendly and a great way to see how computers really think. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296894),('3_Saturday','17','17:00','17:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Work Session: Binary Code\'','\'\'','Creator Workshops_1cc5879fb208652c229df2951cf5e884','\'Title: Work Session: Binary Code
\nTags: CodeBloom | Creator Workshop
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Did you know that every photo, song, and message on your phone is really just a long string of 0s and 1s? Come learn how binary code works and then turn your very own secret word into a wearable friendship bracelet using our binary alphabet chart! This session is beginner friendly and a great way to see how computers really think. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296895),('3_Saturday','14','14:00','14:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Work Session: Ciphers\'','\'\'','Creator Workshops_7abd67ad7d25659cd80aead1ac524df4','\'Title: Work Session: Ciphers
\nTags: CodeBloom | Creator Workshop
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We\'ll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296896),('3_Saturday','11','11:00','11:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Work Session: Ciphers\'','\'\'','Creator Workshops_cb5a20fb46f74a3e52ae354f78fc2421','\'Title: Work Session: Ciphers
\nTags: CodeBloom | Creator Workshop
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We\'ll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296897),('4_Sunday','11','11:00','11:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Work Session: Ciphers\'','\'\'','Creator Workshops_8fdc3a6177519912864550d2a4f07df7','\'Title: Work Session: Ciphers
\nTags: CodeBloom | Creator Workshop
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We\'ll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296898),('2_Friday','11','11:00','11:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Work Session: Ciphers\'','\'\'','Creator Workshops_71b9d5efbf1b10c7a033ea80fc93052b','\'Title: Work Session: Ciphers
\nTags: CodeBloom | Creator Workshop
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We\'ll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296899),('4_Sunday','14','14:00','14:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Work Session: Ciphers\'','\'\'','Creator Workshops_2bb3fef84c3b033d59271718958024ee','\'Title: Work Session: Ciphers
\nTags: CodeBloom | Creator Workshop
\nWhen: Sunday, Aug 9, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We\'ll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296900),('2_Friday','14','14:00','14:59','N','CodeBloom','LVCCW Level 1 Hall 4 1304 (CodeBloom Community)','\'Work Session: Ciphers\'','\'\'','Creator Workshops_470d5b3a83baf6d7e4648cbda2c154fb','\'Title: Work Session: Ciphers
\nTags: CodeBloom | Creator Workshop
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1304 (CodeBloom Community) - Map
\n
\nDescription:
\n

Ever wanted to send a secret message that only your friend could read? Come build your very own cipher wheel and learn how to do exactly that! We\'ll walk you through the Caesar Cipher, a code used by a Roman emperor over 2,000 years ago, and show you how to pick a secret key, encrypt a message, and pass it to a friend to decrypt. This is a great hands on introduction to cryptography for folks of any age or background. If you\'ve ever wanted to get involved in our community or teach our classes, this would be a great time to stop by and learn more!

\n\nLinks:
    More Info - https://codebloom.org/defcon
\n\'',NULL,1296901),('2_Friday','14','14:00','14:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'iOS Game Hacking : From Zero to G0D Mode\'','\'M41w4r3\'','Creator Talks_839cc378f012d1103f0ae4efb5cb646e','\'Title: iOS Game Hacking : From Zero to G0D Mode
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  M41w4r3
\nNo BIO available
\n\n\'',NULL,1296902),('2_Friday','16','16:00','16:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Bobba! A Complete History of Habbo Hotel Private Servers from Shockwave to HTML5\'','\'InsiderPHD\'','Creator Talks_2a8dbf26538495133d6058caab7d6af5','\'Title: Bobba! A Complete History of Habbo Hotel Private Servers from Shockwave to HTML5
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  InsiderPHD
\nNo BIO available
\n\n\'',NULL,1296903),('3_Saturday','12','12:00','12:30','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking with AI\'','\'Juno\'','Creator Talks_844f6a7f4dc4b55fccdfb31213161e37','\'Title: Game Hacking with AI
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

This informal talk is intended to cover expert usage of AI agents using Claude/Codex and how you can apply them to be effective in areas like game hacking. How do you keep an agent on track, how do you make it more accurate, more efficient, and how do you get it to go around guiderails. If you\'re using AI in a web browser or copy+pasting code (in game hacking or otherwise) this talk is for you.

\n\nSpeakerBio:  Juno, Game Hacking Village
\nNo BIO available
\n\nLinks:
    Website - https://gamehacking.gg
\n\'',NULL,1296904),('3_Saturday','16','16:00','16:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Follow-up Demo and Live Q&A Dreamcast PlanetWeb RCE\'','\'Christopher \"Piffd0s\" Hernandez\'','Creator Talks_c5f5feec7d65fdeffabec15bec9acc05','\'Title: Follow-up Demo and Live Q&A Dreamcast PlanetWeb RCE
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n



\n\nSpeakerBio:  Christopher \"Piffd0s\" Hernandez, Binary Enthusiast
\n

Chris Hernandez is a security researcher specializing in vulnerability discovery, exploitation, and large scale reverse engineering using IDA Pro. A Pwn2Own competitor in the ICS/SCADA and embedded systems categories, he actively collaborates with the reverse engineering community to solve binary analysis challenges.

\n\n

--

\n\n

Chris Hernandez is the founder of Adversary Consulting Group and an offensive security researcher with more than a decade of experience in vulnerability research, reverse engineering, and exploit development. He holds the OSEE certification and has competed at Pwn2Own in the IoT and ICS/SCADA categories.

\n\n\n\'',NULL,1296905),('3_Saturday','10','10:00','16:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_512d5eadfcf41611e442da0a897da520','\'Title: Riot Games: Hack Vanguard AntiCheat
\nTags: Game Hacking Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

(Exact times TBD) Try your hand at hacking Riot Game\'s signature anti-cheat: Vanguard!

\n\n\'',NULL,1296906),('3_Saturday','11','10:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_512d5eadfcf41611e442da0a897da520','\'\'',NULL,1296907),('3_Saturday','12','10:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_512d5eadfcf41611e442da0a897da520','\'\'',NULL,1296908),('3_Saturday','13','10:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_512d5eadfcf41611e442da0a897da520','\'\'',NULL,1296909),('3_Saturday','14','10:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_512d5eadfcf41611e442da0a897da520','\'\'',NULL,1296910),('3_Saturday','15','10:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_512d5eadfcf41611e442da0a897da520','\'\'',NULL,1296911),('3_Saturday','16','10:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_512d5eadfcf41611e442da0a897da520','\'\'',NULL,1296912),('2_Friday','12','12:00','16:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_5687bb63d467a8136f3d578eba8edba9','\'Title: Riot Games: Hack Vanguard AntiCheat
\nTags: Game Hacking Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 12:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

(Exact times TBD) Try your hand at hacking Riot Game\'s signature anti-cheat: Vanguard!

\n\n\'',NULL,1296913),('2_Friday','13','12:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_5687bb63d467a8136f3d578eba8edba9','\'\'',NULL,1296914),('2_Friday','14','12:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_5687bb63d467a8136f3d578eba8edba9','\'\'',NULL,1296915),('2_Friday','15','12:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_5687bb63d467a8136f3d578eba8edba9','\'\'',NULL,1296916),('2_Friday','16','12:00','16:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Riot Games: Hack Vanguard AntiCheat\'','\'\'','Creator Events_5687bb63d467a8136f3d578eba8edba9','\'\'',NULL,1296917),('2_Friday','10','10:00','15:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_b360898c118b1d32868f82496be1690f','\'Title: Chill Zone: Casual Games & TASBot Smash Demo
\nTags: Game Hacking Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

DEF CON got you overwhelmed? Come relax and play Project Plus, a modded version of Super Smash Bros Brawl. Or compete against a frame perfect Smash Bot!

\n\n\'',NULL,1296918),('2_Friday','11','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_b360898c118b1d32868f82496be1690f','\'\'',NULL,1296919),('2_Friday','12','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_b360898c118b1d32868f82496be1690f','\'\'',NULL,1296920),('2_Friday','13','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_b360898c118b1d32868f82496be1690f','\'\'',NULL,1296921),('2_Friday','14','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_b360898c118b1d32868f82496be1690f','\'\'',NULL,1296922),('2_Friday','15','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_b360898c118b1d32868f82496be1690f','\'\'',NULL,1296923),('3_Saturday','10','10:00','15:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_23329699ca81ed2d8fb1ed617903cedd','\'Title: Chill Zone: Casual Games & TASBot Smash Demo
\nTags: Game Hacking Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

DEF CON got you overwhelmed? Come relax and play Project Plus, a modded version of Super Smash Bros Brawl. Or compete against a frame perfect Smash Bot!

\n\n\'',NULL,1296924),('3_Saturday','11','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_23329699ca81ed2d8fb1ed617903cedd','\'\'',NULL,1296925),('3_Saturday','12','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_23329699ca81ed2d8fb1ed617903cedd','\'\'',NULL,1296926),('3_Saturday','13','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_23329699ca81ed2d8fb1ed617903cedd','\'\'',NULL,1296927),('3_Saturday','14','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_23329699ca81ed2d8fb1ed617903cedd','\'\'',NULL,1296928),('3_Saturday','15','10:00','15:59','Y','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Casual Games & TASBot Smash Demo\'','\'\'','Creator Events_23329699ca81ed2d8fb1ed617903cedd','\'\'',NULL,1296929),('2_Friday','16','16:00','16:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Smash (Project Plus) Tournament with Prizes\'','\'\'','Creator Events_3035b26192d018a8550c8b30e8e63bfd','\'Title: Chill Zone: Smash (Project Plus) Tournament with Prizes
\nTags: Game Hacking Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

Compete against other attendees in a modded version of Super Smash Bros Brawl! This is a low stakes tourney that is beginner friendly and open to all.

\n\n\'',NULL,1296930),('3_Saturday','16','16:00','16:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Chill Zone: Smash (Project Plus) Tournament with Prizes\'','\'\'','Creator Events_ae843ac44556a0d7a98a3aa81cb035f5','\'Title: Chill Zone: Smash (Project Plus) Tournament with Prizes
\nTags: Game Hacking Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

Compete against other attendees in a modded version of Super Smash Bros Brawl! This is a low stakes tourney that is beginner friendly and open to all.

\n\n\'',NULL,1296931),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_e268db89ce2ed2f166bc7df56c233e9b','\'Title: Game Hacking Village CTF
\nTags: Game Hacking Village | Game Hacking Village CTF | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

Compete againt other teams to be the first to hack all of our games on our custom Mist Store platform

\n\nLinks:
    Website - https://www.gamehacking.gg/myst
\n\'',NULL,1296932),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_e268db89ce2ed2f166bc7df56c233e9b','\'\'',NULL,1296933),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_e268db89ce2ed2f166bc7df56c233e9b','\'\'',NULL,1296934),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_e268db89ce2ed2f166bc7df56c233e9b','\'\'',NULL,1296935),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_e268db89ce2ed2f166bc7df56c233e9b','\'\'',NULL,1296936),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_e268db89ce2ed2f166bc7df56c233e9b','\'\'',NULL,1296937),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_e268db89ce2ed2f166bc7df56c233e9b','\'\'',NULL,1296938),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_e268db89ce2ed2f166bc7df56c233e9b','\'\'',NULL,1296939),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_0acb50375a7c4f7cc17f7f74a455dbf8','\'Title: Game Hacking Village CTF
\nTags: Game Hacking Village | Game Hacking Village CTF | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

Compete againt other teams to be the first to hack all of our games on our custom Mist Store platform

\n\nLinks:
    Website - https://www.gamehacking.gg/myst
\n\'',NULL,1296940),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_0acb50375a7c4f7cc17f7f74a455dbf8','\'\'',NULL,1296941),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_0acb50375a7c4f7cc17f7f74a455dbf8','\'\'',NULL,1296942),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_0acb50375a7c4f7cc17f7f74a455dbf8','\'\'',NULL,1296943),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_0acb50375a7c4f7cc17f7f74a455dbf8','\'\'',NULL,1296944),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_0acb50375a7c4f7cc17f7f74a455dbf8','\'\'',NULL,1296945),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_0acb50375a7c4f7cc17f7f74a455dbf8','\'\'',NULL,1296946),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF\'','\'\'','Contests_0acb50375a7c4f7cc17f7f74a455dbf8','\'\'',NULL,1296947),('4_Sunday','10','10:00','10:30','N','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF awards ceremony\'','\'\'','Contests_a91f79af42379d56be7629964aafba05','\'Title: Game Hacking Village CTF awards ceremony
\nTags: Game Hacking Village | Game Hacking Village CTF | Contest
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

Winners of the Game Hacking Village CTF will be awarded their prizes.

\n\n\'',NULL,1296948),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF Q&A / Walkthroughs\'','\'\'','Contests_7810c630e8b71a73d50e9f9e25390e2e','\'Title: Game Hacking Village CTF Q&A / Walkthroughs
\nTags: Game Hacking Village | Game Hacking Village CTF | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

A presentation by the challenge creators about how the Game Hacking Village CTF along with an open QnA about challenges.

\n\n\'',NULL,1296949),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Game Hacking Village CTF Q&A / Walkthroughs\'','\'\'','Contests_7810c630e8b71a73d50e9f9e25390e2e','\'\'',NULL,1296950),('2_Friday','10','10:00','10:30','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Election Integrity and Technology\'','\'Matt Blaze\'','Creator Talks_3192c1e44c40226ae876dec9f44519c3','\'Title: Election Integrity and Technology
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

This talk will give an overview of the technology used in US elections, the security vulnerabilities that can compromise elections, and approaches for making elections more secure and robust.

\n\nSpeakerBio:  Matt Blaze
\n

Matt Blaze is the McDevitt chair in Computer Science and Law at Georgetown University, where he studies problems at the intersection of technology and public policy. Election systems and voting technology are central focuses of his research. He led teams as part of the California TTBR and Ohio EVEREST studies that each found deep and fundamental weaknesses in different election technologies used by those states and the rest of the US. He has testified on technical risks in elections before the US Congress and other bodies numerous times. Blaze is a co-founder of the Voting Village and president of the Election Integrity Foundation.

\n\n\n\'',NULL,1296951),('2_Friday','10','10:30','10:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'What Election Security Researchers Need to Know About the DMCA\'','\'Tori Noble\'','Creator Talks_7da367026bb37aad08097b5c0072b428','\'Title: What Election Security Researchers Need to Know About the DMCA
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

Section 1201 of the Digital Millennium Copyright Act (DMCA) has historically acted as a major legal barrier to election security research. Section 1201’s “anti-circumvention” provision, 17 U.S.C. § 1201(a)(1), makes it illegal to circumvent or bypass a technological protection measure (TPM) that effectively controls access to a copyrighted work. Violations of the provision can carry both civil and criminal liability, making it a serious risk. Statutory exemptions for security testing, 17 U.S.C. § 1201(j), and encryption research, 17 U.S.C. § 1201(g), apply in some instances, but have important limitations. The security testing exemption covers “good faith” security testing, provided that the research has been authorized by the owner of the computer, and does not violate other laws like the Computer Fraud and Abuse Act or the Copyright Act. The encryption research exemption covers the investigation of encryption applied to copyrighted works, so long as those works were lawfully obtained, and the researcher has made a “good faith effort to obtain authorization.” Section 1201 has historically had a substantial chilling effect on election security research even with these statutory exemptions in place. To address this problem, U.S. regulators adopted a much broader “temporary” security research exemption that provides stronger protection for critical security research on voting machines. The current version of the temporary exemption, 37 C.F.R. § 201.40(b)(18), covers “good faith security research” on a “lawfully acquired” computer, or with the permission of the owner. The temporary exemption enables security research without the need for permission from voting machine companies. However, risks remain despite the temporary exemption, which contains ambiguities and loopholes that voting machine companies sometimes exploit. This talk will explain what the exemption covers, what it may not, and why it is so important to the research that keeps our elections safe and secure.

\n\nSpeakerBio:  Tori Noble
\n

Tori Noble is a Staff Attorney at the Electronic Frontier Foundation specializing in free speech, intellectual property, cybersecurity, and artificial intelligence issues. Tori litigates cases and files amicus briefs in state and federal courts. Representative cases include defending online publishers from lawsuits intended to silence their work; advancing transparency into government activities that harm digital rights; and advocating against overbroad interpretations of copyright laws in AI cases. Tori also advises security and encryption researchers through EFF’s Coder’s Rights Project. Tori co-leads EFF’s policy work on cybersecurity and AI. Prior to joining EFF, Tori represented media companies, television and film producers, and journalists as a litigation associate at Dentons US LLP and a First Amendment fellow at The Intercept. Tori holds a B.A. from the University of Michigan Gerald R. Ford School of Public Policy and a J.D. from Stanford Law School. Tori holds a B.A. from the University of Michigan Gerald R. Ford School of Public Policy and a J.D. from Stanford Law School.

\n\n\n\'',NULL,1296952),('2_Friday','11','11:00','11:30','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Anomalies Are Not Normal: Election Foam Strikes and the Tragic Story of Mikey Hicks\'','\'Richard DeMillo\'','Creator Talks_c891b505f03000f7679150a5498b291c','\'Title: Anomalies Are Not Normal: Election Foam Strikes and the Tragic Story of Mikey Hicks
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

The last time I spoke at DEF CON\'s Voting Village, Curling v. Raffensperger was still awaiting a decision. Since then, the technical record has expanded, the litigation has largely run its course, and yet the strategic debate has changed remarkably little. High-consequence systems operate under two competing optimizations. Engineers optimize for reality. Administrators optimize for operations. Successful missions answer operational questions; they do not validate engineering assumptions. Yet documented engineering anomalies that do not lead to immediate mission failure gradually become accepted as normal. Researchers are repeatedly asked to demonstrate that documented engineering anomalies will produce catastrophic failure, while institutions are seldom asked to explain why anomalies have become compatible with normal operations. This burden-shifting has shaped two decades of election security research while limiting its strategic impact. The election security community has accepted the wrong burden. To the extent that security researchers participate in defining the safety boundaries of electronic election infrastructure, their role has largely been to discover and document anomalies and provide expert testimony in proceedings aimed at optimizing normal election operations. Lost in that process is the implication that \"normal operation\" has a factual, engineering basis. In practice, normality has become an institutional designation that researchers seldom contest. This talk argues that changing the burden fundamentally changes what institutions are permitted to call normal. It proposes a new research agenda focused less on discovering the next anomaly than on preventing documented engineering anomalies from becoming institutionalized as accepted practice. The implications extend well beyond elections. The forthcoming book Sovereign Code argues that the same organizational dynamics increasingly govern all software-mediated public administration. The success of the next generation of election security research will be measured not by the anomalies it discovers, but by the anomalies institutions are no longer able to call normal.

\n\nSpeakerBio:  Richard DeMillo
\n

Richard DeMillo holds the Charlotte B. and Roger C. Warren Chair in Computing at The Georgia Institute of Technology in Atlanta, Georgia. He is the former Dean of Georgia Tech’s College of Computing, founding Chair of the School of Cybersecurity and Privacy, and founder of the Center for 21st Century Universities. In industry, he was previously Vice President and Chief Technology Officer for Hewlett-Packard, and General Manager and Head of Computing Research for Bellcore/SAIC. In government, he directed the Computer and Computation Research Division at the National Science Foundation and the Software Test and Evaluation Project for the Office of the Secretary of Defense. He is the author of more than 100 scientific articles, books, and patents in cryptography, cybersecurity, and software engineering. He is a fellow of the American Association for the Advancement of Science, the Association for Computing Machinery, and the Lumina Foundation.

\n\n\n\'',NULL,1296953),('2_Friday','11','11:30','11:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Welcome to the Voting Village\'','\'Brian DeMuth,Matt Blaze,Jake Braun,David Jefferson,Jeff Moss,Kendall Spencer,Philip Stark\'','Creator Talks_e28e0b0e468cba969dca719ab8c82ace','\'Title: Welcome to the Voting Village
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

The EIF Team and Staff will officially welcome our friends and guests to the Voting Village. We will give an overview of the content attendees should expect this year and the open questions we look forward to addressing.

\n\nSpeakers:Brian DeMuth,Matt Blaze,Jake Braun,David Jefferson,Jeff Moss,Kendall Spencer,Philip Stark
\n
\nSpeakerBio:  Brian DeMuth
\n

Brian DeMuth, a “former” hacker, is an entrepreneur and investor who has spent his 28-year career supporting the U.S. National Security Mission, cybersecurity businesses, and nonprofits. Brian is co-founder and General Partner of the Riphean Investments National Security Fund, a venture-studio-style investment fund focused on technology investments that strengthen national security for the U.S. and its citizens. He is the Founder of Immortal Cyber, Inc., an advanced cybersecurity research and engineering firm providing offensive cyber delivery services and “Cyber-as-a-Service” for unique clients, and Co-Founder & CEO of RapidAscent, Inc., a scalable, task-based cyber apprenticeship solution addressing the historic shortage of technical personnel in the U.S. and worldwide. Brian also co-founded and chairs the board of the Cyber Bytes Foundation, a 501(c)(3) dedicated to building a unique cyber ecosystem of educational and outreach programs for the cyber workforce. A longtime advocate for election security, Brian serves on the Board of Directors of the Election Integrity Foundation, the 501(c)(3) behind the DEF CON Voting Village.

\n\nSpeakerBio:  Matt Blaze
\n

Matt Blaze is the McDevitt chair in Computer Science and Law at Georgetown University, where he studies problems at the intersection of technology and public policy. Election systems and voting technology are central focuses of his research. He led teams as part of the California TTBR and Ohio EVEREST studies that each found deep and fundamental weaknesses in different election technologies used by those states and the rest of the US. He has testified on technical risks in elections before the US Congress and other bodies numerous times. Blaze is a co-founder of the Voting Village and president of the Election Integrity Foundation.

\n\nSpeakerBio:  Jake Braun, DEF CON Franklin
\n

Jake Braun is the co-founder of DEF CON Franklin and the Executive Director of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy. He most recently served in the White House as acting Principal Deputy National Cyber Director. While at the White House, he oversaw the implementation of the National Cybersecurity Strategy, including efforts to secure our water systems, modernize the federal cyber workforce, enhance cyber cooperation with allied nations, and develop AI cybersecurity policy.

\n\n

In addition to his role at the University of Chicago, Mr. Braun co-founded the DEF CON Voting Machine Hacking Village. In that capacity, he co-authored two award-winning reports on the cyber security of our election infrastructure: the DEF CON 25 and 26 Voting Village Reports. Most recently, he partnered with DEF CON, the world\'s largest and longest running hacker conference, to launch “DEF CON Franklin,” a program to memorialize the most innovative and impactful findings from DEF CON in the annual “Hackers’ Almanack.” “DEF CON Franklin” also recruits cyber volunteers to support underresourced critical infrastructure.

\n\nSpeakerBio:  David Jefferson
\n

David Jefferson is an internationally recognized expert on voting systems and election technology, and an advisor to five successive California Secretaries of State. In 2004 he was coauthor of the SERVE Security Report detailing the security vulnerabilities in the Defense Department\'s proposed Internet voting system, leading to the cancellation of the program. In 2003 he was a member of the California Task Force on Touchscreen Voting, whose recommendations led to voter-verified paper audit trails for electronic voting machines. He has led half a dozen technical studies on reliability and security of voting systems, including the California Post-Election Audit Standards Working Group that produced the first government study of post-election auditing. He has served on the boards of directors of both the California Voter Foundation and Verified Voting, and is currently on the board of the Election Integrity Foundation that puts on the annual DEF CON Voting Village.

\n\n

Dr. Jefferson received a BS in mathematics from Yale University, and a Ph.D. in computer science from Carnegie-Mellon University. From 1980 to 1994 he was a professor at the University of Southern California (USC) and then at UCLA. He is now retired from Lawrence Livermore National Laboratory where he conducted research in supercomputing and cyber security.

\n\nSpeakerBio:  Jeff Moss
\nNo BIO available
\nSpeakerBio:  Kendall Spencer
\n

Kendall Spencer is an attorney specializing in emerging companies, technology transactions, and the legal issues shaping innovation. Since joining DEF CON’s Voting Village as a Georgetown Law student in 2019, he has worked alongside Matt Blaze, David Jefferson, and the Voting Village team at the intersection of election technology, cybersecurity, and democracy. Spencer serves on the Board of Directors of the Election Integrity Foundation and has advised state election officials on election security, post-election audits, and cybersecurity best practices.\nHis work focuses on bridging the gap between technical research, public policy, and the law—helping policymakers, election officials, security researchers, and the public better understand the role election security plays in strengthening democratic institutions and public confidence in elections. A frequent DEF CON speaker, Spencer is passionate about fostering thoughtful, bipartisan conversations on the role of technology in protecting election integrity and the democratic principles that underpin a free and open society.\nOutside of his legal and technology work, Spencer is a rare book dealer and collector specializing in early American history and the Black diaspora.

\n\nSpeakerBio:  Philip Stark
\n

Philip B. Stark is Distinguished Professor of the Graduate School at the University of California, Berkeley, where he has served as department chair and associate dean. In 2007 he invented \"risk-limiting audits\" (\"RLAs\"), endorsed by the National Academies of Science, Engineering, and Medicine and the American Statistical Association, among others, and required or authorized by law in about 15 states. He designed and helped conduct the first dozen pilot RLAs, helped draft RLA legislation for several states, and has published open-source software to support RLAs. In 2012, he and David Wagner introduced \"evidence-based elections,\" a paradigm for conducting demonstrably trustworthy elections. Stark has served on the Board of Advisors of the US Election Assistance Commission and its cybersecurity subcommittee, the Board of Directors of Verified Voting Foundation and the Election Integrity Foundation, and on the California Post Election Audit Standards Working Group. He has worked with the Secretaries of State of California, Colorado, and New Hampshire and numerous local election officials. He has testified about election integrity in state and federal courts and to legislators. He received the IEEE Cybersecurity Award for Practice, the UC Berkeley Chancellor\'s Award for Research in the Public Interest, and the John Gideon Award for Election Integrity. He is a fellow of the American Academy of Arts and Sciences, the American Statistical Association, and the Institute of Physics.

\n\n\n\'',NULL,1296954),('2_Friday','12','12:00','12:45','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Voting Village Keynote - The Paper Chase\'','\'Kevin Shelley\'','Creator Talks_f6583ebc60e557b963af3db3a4fab7f2','\'Title: Voting Village Keynote - The Paper Chase
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

The 2000 presidential election was decided by Florida\'s “hanging chads”—flaws in the punchcard voting system used there at the time. In response, Congress passed the Help America Vote Act (HAVA), providing states with substantial funding (released in 2003) to replace punchcard systems with electronic voting machines (DREs), which were promoted as more secure, accurate, and accessible.\nAs Majority Leader of the California State Assembly, Kevin Shelley authored the state\'s vote-by-mail program and other voting reforms. He was elected California Secretary of State in 2002 on a platform of expanding voter participation. Within his first month in office, however, David Dill brought him extensive documentation raising serious concerns about electronic voting security.

\n\n

Shelley found the material compelling enough to form a touchscreen task force to study potential security issues and the need for a voter-verified paper audit trail. When the task force\'s findings, released months later, proved inconclusive, Shelley remained convinced further action was necessary.\nIn November 2003, he launched an independent audit of California\'s voting systems and mandated that all touchscreen machines include a voter-verified paper audit trail—a move local election officials and voting rights advocates criticized as unnecessary and irresponsible, insisting the machines were already secure.

\n\n

Ahead of the March 2004 election, Shelley imposed additional security requirements on touchscreen machines and required that paper ballots remain available; some counties defied the order. Later that year, he banned certain Diebold machines outright, decertified all touchscreen systems until security measures were met, asked the attorney general to pursue civil and criminal action against Diebold, and set up a parallel system to monitor the equipment\'s use.

\n\n

Several lawsuits challenged these measures. Courts upheld Shelley\'s actions in every case.In her inaugural address as California Secretary of State in 2007, Deborah Bowen stated “Kevin Shelley had the hard work of evaluating new kinds of voting systems at a very, very early stage, and guess what – it turns out that he was right on a great many issues that had at their core the security and accuracy of the vote.”

\n\nSpeakerBio:  Kevin Shelley
\n

Kevin Shelley is a former California Secretary of State and State Assembly leader recognized as a trailblazer in election integrity efforts. Mr. Shelley’s political involvement began in 1978 as a staff member to U.S. Representatives Phil and Sala Burton. His own political career began in 1990, when he was elected to the San Francisco Board of Supervisors, serving twice as Board President. Elected to the California State Assembly in 1996, serving as Majority Leader, he championed the rights of workers, fought to protect the environment, and championed corporate accountability.

\n\n

Mr. Shelley, was elected Secretary of State in 2002. As the state’s Chief Election Officer, he is credited with improving voter participation, overseeing the historic Gubernatorial recall election on 2003, and decertifying problematic electronic voting machines. He established the first in the nation standards for accessible voter-verified paper audit trails to be used with direct recording electronic (DRE) voting machines in California.

\n\n

After leaving State government in 2005, he became Special Counsel to Berman Tabacco, a law firm representing victims of corporate fraud. Currently he serves as Vice-Chair of Verified Voting, addressing issues of election security, and is focused on ensuring our upcoming November elections and beyond are safe and secure.

\n\n

He is the son of Jack Shelley, a former San Francisco mayor, U.S. congressman and California state senator.

\n\n\n\'',NULL,1296955),('2_Friday','13','13:30','13:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Publicly Auditable Elections\'','\'Josh Benaloah\'','Creator Talks_28f4a688cd847047fea863d33036af74','\'Title: Publicly Auditable Elections
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

Distrust in the integrity of elections has become widespread in the U.S. and elsewhere. We ask voters to “trust the process” without giving voters any direct evidence that their votes have been correctly counted. Technology has existed for over forty years that allows voters and observers to independently verify the accuracy of election results without having to trust any election software, hardware, or personnel. This technology, which has come to be known as end-to-end verifiability, allows a verifiable election record to be published. Voters can use this record to confirm that their selections have been accurately included, and anyone can use this record to confirm that the included votes have been accurately tallied – all without compromising voter privacy or enabling coercion or vote-selling.

\n\n

This talk will explain how end-to-end verifiability works as well as how and where it has been used in practice. It will also explore some recent advances which greatly simplify the processes of building the tools to enable verifiability, administering elections using these tools, and verifying the integrity of election results.

\n\n

End-to-end verifiability offers a fundamental shift from trust-based elections to evidence-based elections, providing voters, candidates, journalists, and observers with independent means to confirm the accuracy of reported election outcomes.

\n\nSpeakerBio:  Josh Benaloah
\n

Josh Benaloh is the Senior Principal Cryptographer at Microsoft Research and an Affiliate Professor at the University of Washington\'s Paul G. Allen School of Computer Science & Engineering. He is an author of the 2018 National Academy of Sciences report \"Securing the Vote: Protecting American Democracy\" and has testified before Congress on verifiable election technologies. His work has been featured in publications including The New Yorker and WIRED. Dr. Benaloh holds an S.B. degree from the Massachusetts Institute of Technology and M.S., M. Phil., and Ph.D. degrees from Yale University. He served seventeen years on the Board of Directors of the International Association for Cryptologic Research and currently serves on the Coordinating Committee of the Election Verification Network which he chaired from 2020-2024. Outside of professional activities, Dr. Benaloh served eight years on and chaired the Citizen Oversight Panel for Sound Transit which is investing $2 billion annually on expanding the public transit infrastructure for the Seattle region. He has also authored numerous puzzles for competitive puzzle-solving events.

\n\n\n\'',NULL,1296956),('2_Friday','14','14:00','14:45','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Evidence-Based Elections and Risk-Limiting Audits\'','\'Philip Stark\'','Creator Talks_3186167428b041f8a4ab0a0b80439973','\'Title: Evidence-Based Elections and Risk-Limiting Audits
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

Public trust in U.S. elections has been shaken by allegations that the 2020 presidential election was \"stolen\" or \"rigged.\" While many specific claims about that election are technically incoherent or demonstrably false, it is true that the way elections are administered in the U.S.--including eligibility determinations, voting equipment, procedures, and audits--leaves room for rational doubt about whether the reported outcomes of U.S. elections are correct. Given the known vulnerabilities in voting systems, the shortcomings of election procedures in some jurisdictions, and examples of large errors in vote counts and insider malfeasance, to blithely and automatically accept reported results is naive. To deserve public trust, elections should be \"evidence-based\": conducted in a way that generates convincing public evidence that the reported outcome is correct. \"Trust us\" is not evidence. Evidence-based elections generally require demonstrably accurate eligibility determinations; recording votes primarily on hand-marked paper ballots; demonstrably secure chain of custody of voted ballots; a rigorous canvass to ensure that every validly cast ballot (and no others) was included; tabulation of the votes by hand or by machine; a compliance audit to ensure that the paper trail is trustworthy; and a properly designed, publicly confirmable audit of the reported results using the trustworthy paper trail. Conducting evidence-based elections requires avoiding the use of technology for purposes where outcome-altering malfunction or malfeasance could escape detection and correction, for instance, using electronic technology to record or transmit votes (e.g., paperless voting systems, touchscreen ballot-marking devices, cellular networks, or the Internet). Risk-limiting audits (RLAs) play an important role in evidence-based elections, providing affirmative evidence that the reported outcome is correct--or, with high probability, correcting the outcome if it is wrong. RLAs require a trustworthy paper trail. They cannot compensate for poor election administration, such as failing to keep track of voted ballots or using vulnerable technology to record or transmit votes.

\n\nSpeakerBio:  Philip Stark
\n

Philip B. Stark is Distinguished Professor of the Graduate School at the University of California, Berkeley, where he has served as department chair and associate dean. In 2007 he invented \"risk-limiting audits\" (\"RLAs\"), endorsed by the National Academies of Science, Engineering, and Medicine and the American Statistical Association, among others, and required or authorized by law in about 15 states. He designed and helped conduct the first dozen pilot RLAs, helped draft RLA legislation for several states, and has published open-source software to support RLAs. In 2012, he and David Wagner introduced \"evidence-based elections,\" a paradigm for conducting demonstrably trustworthy elections. Stark has served on the Board of Advisors of the US Election Assistance Commission and its cybersecurity subcommittee, the Board of Directors of Verified Voting Foundation and the Election Integrity Foundation, and on the California Post Election Audit Standards Working Group. He has worked with the Secretaries of State of California, Colorado, and New Hampshire and numerous local election officials. He has testified about election integrity in state and federal courts and to legislators. He received the IEEE Cybersecurity Award for Practice, the UC Berkeley Chancellor\'s Award for Research in the Public Interest, and the John Gideon Award for Election Integrity. He is a fellow of the American Academy of Arts and Sciences, the American Statistical Association, and the Institute of Physics.

\n\n\n\'',NULL,1296957),('2_Friday','15','15:30','15:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'There and Back Again\'','\'Jason Wareham,Manbir Gulati\'','Creator Talks_1f635ad4bf3bafe1429682f2260eb883','\'Title: There and Back Again
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

In 2025, Mojave Research received an assignment its founders never expected: examine security vulnerabilities in voting equipment used during Puerto Rico’s 2024 elections. What appeared to be a bounded technical project quickly became a journey through voting technology, digital forensics, incomplete evidence, institutional friction, and the difficult line between what a system could permit and what the evidence proves actually happened. Jason Wareham and Manbir Gulati will explain how Mojave became involved, what the team was asked to do, and how two outsiders to election administration found themselves examining technology at the center of a national argument about security and public trust. Jason will describe the origins and evolution of the assignment, along with the challenge of keeping a technical investigation tied to evidence when others already have firm expectations about the answer. Manbir will take the audience inside the technical problem at a level appropriate for public discussion: how investigators approach unfamiliar election systems, assess available hardware and software, reason from constrained artifacts, evaluate weaknesses, and separate a possible attack path from evidence of exploitation and what remains to ensure the security of these critical systems is inviolate. Mojave’s examination identified real software and security concerns. It did not YET find evidence that the equipment examined had been hacked or that votes had been altered. That distinction is central to the story—and to any honest discussion of election security. The talk will conclude with an announcement of, and invitation to, a private initiative aimed at reducing voting-system risk before the 2026 midterm elections absent of politics. This is a brief account of how a national-security startup entered an unfamiliar and politically charged field, followed the evidence through an unexpected assignment, and concluded that documenting the problem was not enough.

\n\nSpeakers:Jason Wareham,Manbir Gulati
\n
\nSpeakerBio:  Jason Wareham
\n

Jason Wareham is CEO of Mojave Research Inc. and CEO and Chairman of Agentic Secure Group. In 2025, the Office of the Director of National Intelligence (ODNI) engaged Mojave Research to examine security vulnerabilities in voting equipment used during Puerto Rico’s 2024 elections.

\n\n

Jason previously spent nearly two decades handling military, criminal-defense, and national-security matters. He served as a U.S. Marine Corps officer and judge advocate and reached the rank of lieutenant colonel. His work included trials, appeals, military commissions at GTMO, classified information, and digital evidence. The Marine Corps designated him a Master of Criminal Law, and he later worked as a senior litigation adviser and trainer before concluding his private practice.

\n\n

Jason holds an LL.M. from Georgetown University Law Center, where his studies focused on cybersecurity, digital forensics, electronic discovery, and cybercrime. He earned his J.D. from Creighton University and authored “Cracking the Code,” a Georgetown Law Technology Review article about compulsory decryption and the Fifth Amendment.

\n\n

At Mojave Research, Jason works on national-security technology, secure artificial intelligence, cybersecurity, and technical investigations subject to legal and institutional scrutiny. His approach is simple: establish what the evidence proves, identify what it does not prove, and resist pressure to blur the difference.

\n\nSpeakerBio:  Manbir Gulati
\nNo BIO available
\n\n\'',NULL,1296958),('2_Friday','16','16:00','16:30','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Security and Privacy for the Rest of Elections\'','\'Michael Specter\'','Creator Talks_ad4d48f82958b3e82f89fc157396ffd1','\'Title: Security and Privacy for the Rest of Elections
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Michael Specter
\n

Michael A. Specter is an Assistant Professor in Computer Science at Georgia Tech where he leads the SPDR Lab. Specter’s interests are broadly on problems in systems security and applied cryptography, specifically on issues relevant to public policy.  He joined Google after completing his PhD in Electrical Engineering and Computer Science at MIT, and previously served as research staff at MIT’s Lincoln Laboratory. His research has been featured in congressional testimony, amicus briefs to the Supreme Court, and (repeatedly) in the popular press. He holds the 2023 Research Award from the Elections Verification Network and a Pioneer Award from the Electronic Frontier Foundation (EFF). 

\n\n\n\'',NULL,1296959),('2_Friday','16','16:30','16:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Watching Norway\'s Election\'','\'Hallvard Nygard\'','Creator Talks_2798613bba861f4886e0d692185fc7cc','\'Title: Watching Norway\'s Election
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

What can an ordinary citizen — equipped with curiosity, a camera, and a little code — actually learn about how their elections are run? In 2025 the speaker set out to find out, observing Norway\'s national election from both the inside and the outside. The results ranged from the illuminating to the absurd: scraping official result protocols into structured JSON for independent analysis; working two prior elections \"undercover\" as a paid poll worker; spotting an unsealed ballot box where the chain of custody should have been airtight; and, on count night, being removed from a municipal counting center by police.

\n\n

This talk turns those experiences into a practical, cross-border playbook for independent election observation. Norway runs paper ballots, manual counts, and publishes machine-readable results — yet transparency still has gaps, and getting access can be surprisingly adversarial. Using Norway as a concrete case study, the speaker shows how anyone — hacker, researcher, or concerned voter — can document a count, capture and analyze published election data, spot anomalies, and do it all legally and credibly.

\n\n

Attendees leave with concrete methods: what to watch for, how to record it, how to turn official data dumps into analyzable datasets, and how to handle officials when curiosity is mistaken for a threat. The core message is empowerment: election integrity is not a spectator sport reserved for institutions. The more eyes — and code — on the process, the stronger democracies become, in the U.S. and everywhere else.

\n\nSpeakerBio:  Hallvard Nygard
\n

Hallvard Nygård is an independent security researcher and election observer based in Norway. He has spent recent years turning a developer\'s toolkit on the machinery of democracy: scraping and analyzing published election data, observing counts in person, and working as a paid poll worker (valgmedarbeider)\nduring Norway\'s 2021 and 2023 elections to understand the process from the inside.

\n\n

His independent observation of Norway\'s 2025 election drew media attention after he was removed from municipal counting center by police — an episode he now uses to illustrate both the promise and the friction of citizen oversight.

\n\n

Hallvard is a frequent speaker on the Norwegian conference and security-community circuit, including Sikkerhetsfestivalen, JavaZone, NDC Oslo, TDC, and HelloStavanger, as well as meetups such as OWASP Oslo, Stavanger Security Hangout (SSH), and an Oslo election meetup. He is a vocal advocate\nfor hands-on, hacker-style scrutiny of elections and for empowering ordinary citizens to observe and document their own local democratic processes. Online he can be found at hallny.bsky.social and as @hallny on X.

\n\n\n\'',NULL,1296960),('2_Friday','17','17:00','17:45','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'We Pwn Your Phone, We Pwn Your Vote (Demo and Panel)\'','\'Brian DeMuth,Matt Blaze,David Jefferson,Michael Specter\'','Creator Talks_0b7324d62b5270abed1cef7fd32dcc7f','\'Title: We Pwn Your Phone, We Pwn Your Vote (Demo and Panel)
\nTags: Demo 💻 | Voting Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:45 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\nMobile voting proposals increasingly rest on a single assertion: that modern smartphones, with their secure enclaves, sandboxed apps, and encrypted communications, provide a sufficiently trusted platform for remote ballot casting. This talk demonstrates, live and on stage, why that assertion is false.
\n\n

Using a weaponized n-day exploit chain (CVE-2025-43529) against a now patched but-still-widely-deployed iOS version, we will compromise a live iPhone in front of the audience. The phone’s screen will display nothing but a Wikipedia article. The user will have no indication that anything has happened. Meanwhile, a second screen will show the audience exactly what is being taken from the device in real time: text messages, messaging app databases (Signal, WhatsApp, Telegram), photos, saved passwords, WiFi credentials, location history, and contacts, all exfiltrated with zero on-device artifacts.

\n\n

The exploit achieves full kernel read/write and root filesystem access. At that level of compromise, no app on the device can be trusted: not voting apps, not authenticators, not encrypted messengers. The encryption keys, cloud session tokens, and biometric material that apps rely on to prove “this is the legitimate voter” are all accessible to an attacker with this level of access.

\n\n

This specific vulnerability is patched. But two facts remain: (1) the targeted iOS version is still running on millions of devices worldwide, and (2) nation-state actors and sophisticated criminal organizations maintain working exploit chains against the latest iOS and Android versions, chains that have not been patched because they have not been discovered or disclosed. The tool we demonstrate is an n-day. The tools in active deployment against current devices are zero-days.

\n\nSpeakers:Brian DeMuth,Matt Blaze,David Jefferson,Michael Specter
\n
\nSpeakerBio:  Brian DeMuth
\n

Brian DeMuth, a “former” hacker, is an entrepreneur and investor who has spent his 28-year career supporting the U.S. National Security Mission, cybersecurity businesses, and nonprofits. Brian is co-founder and General Partner of the Riphean Investments National Security Fund, a venture-studio-style investment fund focused on technology investments that strengthen national security for the U.S. and its citizens. He is the Founder of Immortal Cyber, Inc., an advanced cybersecurity research and engineering firm providing offensive cyber delivery services and “Cyber-as-a-Service” for unique clients, and Co-Founder & CEO of RapidAscent, Inc., a scalable, task-based cyber apprenticeship solution addressing the historic shortage of technical personnel in the U.S. and worldwide. Brian also co-founded and chairs the board of the Cyber Bytes Foundation, a 501(c)(3) dedicated to building a unique cyber ecosystem of educational and outreach programs for the cyber workforce. A longtime advocate for election security, Brian serves on the Board of Directors of the Election Integrity Foundation, the 501(c)(3) behind the DEF CON Voting Village.

\n\nSpeakerBio:  Matt Blaze
\n

Matt Blaze is the McDevitt chair in Computer Science and Law at Georgetown University, where he studies problems at the intersection of technology and public policy. Election systems and voting technology are central focuses of his research. He led teams as part of the California TTBR and Ohio EVEREST studies that each found deep and fundamental weaknesses in different election technologies used by those states and the rest of the US. He has testified on technical risks in elections before the US Congress and other bodies numerous times. Blaze is a co-founder of the Voting Village and president of the Election Integrity Foundation.

\n\nSpeakerBio:  David Jefferson
\n

David Jefferson is an internationally recognized expert on voting systems and election technology, and an advisor to five successive California Secretaries of State. In 2004 he was coauthor of the SERVE Security Report detailing the security vulnerabilities in the Defense Department\'s proposed Internet voting system, leading to the cancellation of the program. In 2003 he was a member of the California Task Force on Touchscreen Voting, whose recommendations led to voter-verified paper audit trails for electronic voting machines. He has led half a dozen technical studies on reliability and security of voting systems, including the California Post-Election Audit Standards Working Group that produced the first government study of post-election auditing. He has served on the boards of directors of both the California Voter Foundation and Verified Voting, and is currently on the board of the Election Integrity Foundation that puts on the annual DEF CON Voting Village.

\n\n

Dr. Jefferson received a BS in mathematics from Yale University, and a Ph.D. in computer science from Carnegie-Mellon University. From 1980 to 1994 he was a professor at the University of Southern California (USC) and then at UCLA. He is now retired from Lawrence Livermore National Laboratory where he conducted research in supercomputing and cyber security.

\n\nSpeakerBio:  Michael Specter
\n

Michael A. Specter is an Assistant Professor in Computer Science at Georgia Tech where he leads the SPDR Lab. Specter’s interests are broadly on problems in systems security and applied cryptography, specifically on issues relevant to public policy.  He joined Google after completing his PhD in Electrical Engineering and Computer Science at MIT, and previously served as research staff at MIT’s Lincoln Laboratory. His research has been featured in congressional testimony, amicus briefs to the Supreme Court, and (repeatedly) in the popular press. He holds the 2023 Research Award from the Elections Verification Network and a Pioneer Award from the Electronic Frontier Foundation (EFF). 

\n\n\n\'',NULL,1296961),('3_Saturday','10','10:00','10:30','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'\"Trust Us, It\'s Secure\": Why Internet Voting Isn\'t\'','\'Barbara Simons\'','Creator Talks_c0356f19ecf53825f0317d465f79edea','\'Title: \"Trust Us, It\'s Secure\": Why Internet Voting Isn\'t
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

For years programmers, computer scientists, and cybersecurity experts have known that returning a voted ballot over the internet is fundamentally insecure. Beginning with the 2004 SERVE report, experts have warned of threats including hacking the voter’s device, phishing, man-in-the-middle attacks, spoofing, and attacks on election officials’ systems. New dangers have since emerged, including ransomware attacks.

\n\n

Yet, 32 states allow some form of internet voting, primarily for overseas military personnel and civilians, though some states also make it available to voters with disabilities and tribal members living on reservations. (For a full list of states that allow internet voting, who is eligible, and what type is permitted, see Internet Voting).

\n\n

Given the steady stream of reported hacks of government agencies, major corporations, and other institutions, why do so many well-meaning people continue to believe that internet voting will increase voter participation, while ignoring well documented threats?

\n\n

I will give a brief overview of the history, some of the key forces, and the roles that language (“don’t call it internet voting”), wishful thinking, and money are playing.

\n\nSpeakerBio:  Barbara Simons
\n

An expert on electronic voting, Dr. Barbara Simons has been on the Board of Advisors of the U.S. Election Assistance Commission since was appointed in 2008. She co-authored Broken Ballots: Will Your Vote Count? with Prof. Douglas Jones. She was a member of the National Workshop on Internet Voting that was convened by the National Science Foundation at the request of President Clinton and produced a report on Internet Voting in 2001. She also participated on the Security Peer Review Group for the US Department of Defense’s Internet voting project (SERVE) and co-authored the report that led to the cancellation of SERVE because of security concerns. Simons co-chaired the Association for Computing Machinery (ACM) study of statewide databases of registered voters, she co-authored the League of Women Voters report on election auditing, and she co-authored the July 2015 report of the U.S. Vote Foundation entitled The Future of Voting: End-to-End Verifiable Internet Voting.

\n\n

Simons was President of ACM, the oldest and largest international educational and scientific society for computing professionals, from 1998 until 2000. She founded ACM’s U.S. Public Policy Committee (now called the U.S. Technology Policy Committee) in 1993 and served for many years as the Chair. She is Board Chair of Verified Voting.

\n\n\n\'',NULL,1296962),('3_Saturday','10','10:30','10:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Software Quality in Electronic Voting\'','\'Duncan Buell\'','Creator Talks_04423b1ff070451b16281d17c1510a95','\'Title: Software Quality in Electronic Voting
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

Casting a vote is the primary means by which citizens can influence their government. Following the passage of the Help America Vote Act (HAVA) in 2002, a surge in the use of electronic voting systems occurred. Although hand-marked paper is returning to use, the replacements in many jurisdictions for these aging electronic systems are also electronic. Given the serious nature of elections, electronic voting systems must be trustworthy, and their engineering must be held to rigorous standards.

\n\n

We have had the opportunity, over the past eight years, to observe and analyze the use of electronic voting systems in the state of South Carolina. Our observations of such systems in the field have yielded serious usability, software, and hardware quality concerns, ranging from procedural errors resulting from poorly-designed systems, to system faults that ignore or miscount votes, to timestamp anomalies and malformed output. Given the importance of elections, and the inherent risk in the use of current electronic voting systems, we question the wisdom of using such systems until they are held to standards comparable to those used in other regulated, safety critical domains.

\n\nSpeakerBio:  Duncan Buell
\n

Duncan A. Buell is the Chair Emeritus of the NCR Chair in Computer Science and Engineering at the University of South Carolina. He holds a Ph. D. in mathematics from the University of Illinois, Chicago, and continues research interests in electronic voting, digital humanities, and text analysis. He was appointed in March 2019 to the Commission on Voter Registration and Elections of Richland County, South Carolina, resigning in March 2021 when he moved to Ohio. He taught computer science as a visitor at Denison University in Granville, Ohio, in academic years 2022-2023 and 2023-2024.

\n\n

Dr. Buell has been analyzing election data, primarily from ES&S and Dominion systems, since 2010, including five complete biennials (2010-2018) from South Carolina, as well as data from AZ, GA, KS, NV, PA, and TX, and data from 2010 through 2024.

\n\n\n\'',NULL,1296963),('3_Saturday','11','11:00','11:30','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Liberty and Justice for All\'','\'Michael Moore\'','Creator Talks_99ab135abadfc58e7fb1fd4081734301','\'Title: Liberty and Justice for All
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

Just weeks after Arizona\'s 2026 Primary Election, this presentation will provide a candid look at what went right, what challenged election officials, and what we learned from operating one of the nation\'s most scrutinized election environments.

\n\n

Election security is often discussed through the lens of cybersecurity, but the reality facing election officials today is far broader. Modern election security requires defending against physical threats to election workers, cyber threats targeting systems and infrastructure, reputational attacks that seek to undermine public confidence, logistical challenges that can disrupt operations, and an increasingly complex legal landscape. Success depends on addressing all of these simultaneously while still delivering a free, fair, secure, accurate, and transparent election.

\n\n

Drawing on Arizona\'s experiences during the 2026 election cycle, this session will examine how election officials prepare for and respond to these challenges, the partnerships that make election security possible, and the difficult balance between transparency, security, and public trust.

\n\n

The presentation will also explore emerging efforts to responsibly integrate artificial intelligence into election administration. Through work with Arizona State University\'s Mechanics of Democracy Laboratory, election officials are learning how AI can enhance productivity and improve public service while maintaining appropriate safeguards, accountability, and human oversight.

\n\n

Most importantly, this session is not simply about what government is doing. It is about how the security, research, and civic communities can contribute. Whether you are a security researcher, election official, journalist, technologist, or concerned voter, you have a role in strengthening democratic resilience.

\n\n

Attendees will leave with a clearer understanding of today\'s election threat landscape, practical ways to support election security efforts, and greater confidence in the professionals working every day to defend the democratic process.

\n\nSpeakerBio:  Michael Moore
\n

Michael Moore is the CISO at Arizona Secretary of State\'s Office. He leads efforts to strengthen election security through coordinated partnerships across federal, state, and local governments, alongside trusted private-sector partners. His work is grounded in protecting democratic processes and maintaining public confidence in elections. He focuses on the most pressing risks to election integrity: mis-, dis-, and malinformation (MDM), and the insider threats that can emerge from an increasingly polarized and misinformed environment. His approach centers on countering false narratives with verifiable truth while advancing a defense-in-depth strategy. This includes preventing attacks wherever possible, rapidly detecting anomalies, and ensuring resilient, transparent recovery when incidents occur.

\n\n

Through organizational leadership and national collaboration, Michael has driven initiatives that enhance the security, resilience, and credibility of election systems. His work helps safeguard the voter experience and uphold trust in democratic institutions.

\n\n\n\'',NULL,1296964),('3_Saturday','11','11:30','11:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Are We Making Things Worse? Election Denialism and Security Research\'','\'Matt Blaze,Geoff Hale,Michael Moore,Kendall Spencer,Philip Stark\'','Creator Talks_8501c7aa5cfd86b2829e424152ccc4a0','\'Title: Are We Making Things Worse? Election Denialism and Security Research
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n\n\nSpeakers:Matt Blaze,Geoff Hale,Michael Moore,Kendall Spencer,Philip Stark
\n
\nSpeakerBio:  Matt Blaze
\n

Matt Blaze is the McDevitt chair in Computer Science and Law at Georgetown University, where he studies problems at the intersection of technology and public policy. Election systems and voting technology are central focuses of his research. He led teams as part of the California TTBR and Ohio EVEREST studies that each found deep and fundamental weaknesses in different election technologies used by those states and the rest of the US. He has testified on technical risks in elections before the US Congress and other bodies numerous times. Blaze is a co-founder of the Voting Village and president of the Election Integrity Foundation.

\n\nSpeakerBio:  Geoff Hale
\n

Geoff Hale has over 15 years of experience supporting the security of critical infrastructure with a focus on election security since 2016. Geoff worked at the Cybersecurity and Infrastructure Security Agency (CISA) as Associate Director for Election Security & Resilience, helping to build a security community in support of U.S. elections.

\n\nSpeakerBio:  Michael Moore
\n

Michael Moore is the CISO at Arizona Secretary of State\'s Office. He leads efforts to strengthen election security through coordinated partnerships across federal, state, and local governments, alongside trusted private-sector partners. His work is grounded in protecting democratic processes and maintaining public confidence in elections. He focuses on the most pressing risks to election integrity: mis-, dis-, and malinformation (MDM), and the insider threats that can emerge from an increasingly polarized and misinformed environment. His approach centers on countering false narratives with verifiable truth while advancing a defense-in-depth strategy. This includes preventing attacks wherever possible, rapidly detecting anomalies, and ensuring resilient, transparent recovery when incidents occur.

\n\n

Through organizational leadership and national collaboration, Michael has driven initiatives that enhance the security, resilience, and credibility of election systems. His work helps safeguard the voter experience and uphold trust in democratic institutions.

\n\nSpeakerBio:  Kendall Spencer
\n

Kendall Spencer is an attorney specializing in emerging companies, technology transactions, and the legal issues shaping innovation. Since joining DEF CON’s Voting Village as a Georgetown Law student in 2019, he has worked alongside Matt Blaze, David Jefferson, and the Voting Village team at the intersection of election technology, cybersecurity, and democracy. Spencer serves on the Board of Directors of the Election Integrity Foundation and has advised state election officials on election security, post-election audits, and cybersecurity best practices.\nHis work focuses on bridging the gap between technical research, public policy, and the law—helping policymakers, election officials, security researchers, and the public better understand the role election security plays in strengthening democratic institutions and public confidence in elections. A frequent DEF CON speaker, Spencer is passionate about fostering thoughtful, bipartisan conversations on the role of technology in protecting election integrity and the democratic principles that underpin a free and open society.\nOutside of his legal and technology work, Spencer is a rare book dealer and collector specializing in early American history and the Black diaspora.

\n\nSpeakerBio:  Philip Stark
\n

Philip B. Stark is Distinguished Professor of the Graduate School at the University of California, Berkeley, where he has served as department chair and associate dean. In 2007 he invented \"risk-limiting audits\" (\"RLAs\"), endorsed by the National Academies of Science, Engineering, and Medicine and the American Statistical Association, among others, and required or authorized by law in about 15 states. He designed and helped conduct the first dozen pilot RLAs, helped draft RLA legislation for several states, and has published open-source software to support RLAs. In 2012, he and David Wagner introduced \"evidence-based elections,\" a paradigm for conducting demonstrably trustworthy elections. Stark has served on the Board of Advisors of the US Election Assistance Commission and its cybersecurity subcommittee, the Board of Directors of Verified Voting Foundation and the Election Integrity Foundation, and on the California Post Election Audit Standards Working Group. He has worked with the Secretaries of State of California, Colorado, and New Hampshire and numerous local election officials. He has testified about election integrity in state and federal courts and to legislators. He received the IEEE Cybersecurity Award for Practice, the UC Berkeley Chancellor\'s Award for Research in the Public Interest, and the John Gideon Award for Election Integrity. He is a fellow of the American Academy of Arts and Sciences, the American Statistical Association, and the Institute of Physics.

\n\n\n\'',NULL,1296965),('3_Saturday','12','12:00','12:45','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Keynote: Colorado\'s Creation of RLAs\'','\'Wayne Williams\'','Creator Talks_69bce6c14d00e294525578c9658dec89','\'Title: Keynote: Colorado\'s Creation of RLAs
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

As Colorado’s 38th Secretary of State, Mr. Williams oversaw the creation of the nation\'s first full forensic risk limiting audit (“RLA”) in 2017.

\n\n

Colorado’s legislature ordered the use of RLA’s in 2009 -- long before widespread media coverage of fears about hacking election equipment and interference by foreigners or other bad actors. Three Secretaries of State later, Colorado implemented the nation’s first full RLA in 2017.

\n\n

An RLA is a procedure that provides strong statistical evidence that the election outcome is right and has a high probability of correcting a wrong outcome. Risk-limiting audits require human beings to examine and verify more ballots in close races (exactly when you want to examine more ballots), and fewer ballots in races with wide margins.

\n\n

Colorado’s process attracted attention nationwide. The Washington Post pronounced Colorado “the safest state to cast a vote.” Matt Masterson, then chairman of the U.S. Election Assistance Commission, attended the implementation and stated that \"Colorado is a national leader in exploring innovative solutions for accessible, secure and auditable elections.”

\n\n

Secretary Williams will discuss the benefits of RLAs, the processes used, and some of the hurdles Colorado overcame during its implementation.

\n\nSpeakerBio:  Wayne Williams
\n

Wayne Williams served as Colorado\'s 38th Secretary of State from 2015 to 2019 and now serves as Colorado Springs Chief of Staff for Mayor Yemi Mobolade. Secretary Williams\' 20 years of elected service includes four years as Clerk and Recorder for Colorado\'s most populous county. He continues to serve as a designated election official and on the Board of Advisors for Verified Voting.

\n\n

As Secretary of State, Wayne Williams adopted rules requiring voter-verifiable paper ballots, created the nation\'s first full risk limiting audit, and defended Colorado voters against attempts by rogue electors to deprive them of their vote in the 2016 presidential election. Secretary Williams\' actions were upheld by a unanimous U.S. Supreme Court.

\n\n

His work in these positions earned regional and national recognition, including the National Association of Secretaries of State Medallion Award, the Colorado League of Women Voters\' Leader of Democracy, Defender of Democracy, and the Truman Foundation\'s Stevens Award for attorneys in public service. He has been appointed to state boards by Colorado Governors from both political parties.

\n\n

Secretary Williams received his B.A. in Political Science from BYU (1986), and his J.D. from the University of Virginia Law School (1989).

\n\n\n\'',NULL,1296966),('3_Saturday','13','13:30','13:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Pulling Back the Curtain on the Voting Booth\'','\'Marilyn Marks,Max Springer\'','Creator Talks_b0eec992d1902feee55334f0d6858836','\'Title: Pulling Back the Curtain on the Voting Booth
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

This presentation by Max Springer (postdoctoral research fellow, Princeton University Center for Information Technology Policy) and Marilyn Marks (Coalition for Good Governance) presents unsettling new findings that escalate the danger of a known, unpatched vulnerability in Dominion Voting Systems version used in Georgia and multiple other jurisdictions. First disclosed in 2022 by University of Michigan and Auburn University researchers, the flaw allows cast-vote records and ballot images to be \"unshuffled,\" revealing the order in which ballots were cast, and, when combined with public information like scanner logs, scanner public counters, poll books check-in files, or timestamped polling place video, exposing how specific individuals voted. Georgia and many affected jurisdictions have taken no corrective action despite the software patch offered by Dominion in late 2022.

\n\n

Springer and Marks demonstrate that these exploits, once assumed to require sophisticated programming skills, can now be carried out by almost anyone. Using only publicly available Georgia election records and off-the-shelf AI tools, and without writing custom code, the presenters demonstrate the ready ability to determine how a substantial share of Georgia voters cast their ballots in the contentious May 2026 primary.

\n\n

The findings arrive at a pivotal moment: Georgia election officials are currently divided over whether to require a security patch bringing ballot scanners into compliance with the state\'s secret-ballot guarantee. Some officials resist any change and instead push to conceal the underlying public records, preserving insiders\' access to voter-choice data while leaving the public without elections oversight and verification rights.

\n\n

Springer and Marks argue that AI has fundamentally lowered the barrier to exploiting this flaw, transforming a theoretical privacy risk into an urgent, practical threat to the secret ballot in multiple jurisdictions. They call for mandatory patching and warn that inaction before the 2026 midterms could compromise the constitutional right to a private vote for millions of Americans.

\n\nSpeakers:Marilyn Marks,Max Springer
\n
\nSpeakerBio:  Marilyn Marks
\n

Marilyn Marks is Executive Director of the Coalition for Good Governance, a nonpartisan nonprofit working to strengthen election security and protect the right to a secret ballot. For more than 17 years she has focused on improving the technology used in U.S. elections, especially in Georgia. Her group is behind Curling v. Raffensperger, a landmark federal case challenging the security of touchscreen voting machines. Georgia is using a second generation of touchscreen voting machines, with flawed software that Marks and many cybersecurity experts fear may be used to disrupt target state Georgia’s elections this year.

\n\nSpeakerBio:  Max Springer
\n

Max Springer is an algorithms researcher, science communicator, and tech policy consultant. Currently, he is a postdoctoral research fellow at Princeton University. He earned his PhD from the University of Maryland under MohammadTaghi Hajiaghayi, with support from an NSF Graduate Research Fellowship. His dissertation, \"The Price of Fairness in Algorithmic Decision Making\", developed approximation algorithms with fairness and reliability guarantees—an agenda he now extends from classical machine-learning problems to modern AI systems. He has conducted research at Google, Nokia Bell Labs, Yale, and the Max Planck Institute, and received Bell Labs’ Outstanding Innovation Award. Beyond research, he contributed to a recent United Nations report on AI and works with policymakers on responsible algorithmic deployment, including election systems

\n\n\n\'',NULL,1296967),('3_Saturday','14','14:00','14:30','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Separating News from Noise\'','\'Ryan Murray,Stephen Richter,Nate Young\'','Creator Talks_4fbbc09b2a718aea23be700bda3d6570','\'Title: Separating News from Noise
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

News versus noise. Every election cycle brings a flood of headlines covering changes to election administration, election security, and the voter experience. The 2026 midterm elections will unfold amid significant legal, policy, and election security developments. What developments will have the most impact on the 2026 midterm elections and beyond, and which are unlikely to have a lasting impact? Join a panel of election administrators, legal experts, and cybersecurity professionals as they analyze the year’s most significant election developments, separate consequential changes from background noise, and discuss their practical implications for election administration, cybersecurity, and the voter experience. Topics include federal and state election laws, executive orders, SCOTUS rulings, redistricting disputes, election security, and other issues influencing both the immediate and long-term future of American elections. Attendees will leave better equipped to distinguish consequential election developments from background noise and understand how those developments affect election administration, cybersecurity, voter confidence, and the voter experience.

\n\nSpeakers:Ryan Murray,Stephen Richter,Nate Young
\n
\nSpeakerBio:  Ryan Murray
\n

Ryan Murray is Deputy Director and CISO of Arizona DHS. He has his finger on the pulse of current elections cybersecurity operations from the AZ-ISAC) Information and Analysis Center) and AZ-DHS (Dept. of Homeland Security) fusion center operations.

\n\nSpeakerBio:  Stephen Richter
\n

Stephen Richer is a legal fellow with the Cato Institute’s Robert A. Levy Center for Constitutional Studies. His work focuses on election administration, American democracy, executive orders, and American politics. He is a visiting senior fellow at the Ash Center for Democratic Governance and Innovation at Harvard University’s Kennedy School. He is also the CEO of Republic Affairs, a crisis consulting firm for pro-democracy, pro-rule-of-law entities and individuals. He was the Maricopa Recorder from 2021 - 2025, and experienced first hand the Arizona Senate Audit (CyberNinjas) and related Department of Justice Investigations.

\n\nSpeakerBio:  Nate Young
\n

Nate Young is the Deputy CIO of Elections Information Technology for Maricopa County, where he leads a dedicated team of career IT professionals focused on supporting and facilitating secure, accurate, and accessible elections. With 19 years of experience across government and the education sector, Nate brings a broad and practical perspective to public-sector technology. Since 2021, Nate has focused on elections technology and cyber security since 2021 with the 2020 Elections audit from the Cyber Ninjas. Nate has presented at many Elections and cyber security related conferences, including the DEFCON Voting Village 2022, 2024, 2025.

\n\n\n\'',NULL,1296968),('3_Saturday','14','14:30','14:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Dissecting the ICX Frog\'','\'Drew Springall\'','Creator Talks_4daf7c7ae6300167b27eeed0f47826eb','\'Title: Dissecting the ICX Frog
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

In 2022, a Dominion Voting Systems ImageCast X ballot marking device (ICX BMD) appeared for sale on eBay and was purchased by security researcher Harri Hursti. Originating in Colfax Township, MI and after being \"donated by accident\" to Goodwill, it debuted at Voting Village 2023 and has since been the subject of great interest and used for proof-of-concept demonstrations (PoCs) within the village. As the only known instance of a legally-obtained ICX being available for study without burdensome secrecy/pre-publication review agreements, it represents a unique opportunity for improving and updating our understanding of certified, adopted, and deployed voting systems from an engineering and security perspective (among others).

\n\n

In this talk, we will discuss the hardware, software, architecture, and capabilities of the ICX BMD from a technical perspective. Significant reverse-engineering of its Democracy Suite 5.5 software has revealed much regarding its design, construction, and internal operation along with a few surprises along the way. While one part of one version of one system from one vendor is far from sufficient to draw conclusions about currently-used voting systems in-general, this talk hopes to shed light on what a currently EAC-approved voting system could be.

\n\nSpeakerBio:  Drew Springall
\n

Drew Springall is a hacker, security researcher, and frequent Voting Village contributor with a specific interest in the technical/concrete aspects of voting system security. Since 2013, Drew has worked to understand the challenges encountered by and demonstrate the capabilities of realistic attackers should they attempt to interfere with such systems as commonly deployed. In those years, Drew has built and demonstrated many proof-of-concept attacks across various areas of voting system security including Internet Voting, voter-facing software/hardware, ballot de-anonymization, and physical protections.

\n\n\n\'',NULL,1296969),('3_Saturday','15','15:30','15:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Alerts and Warnings in 2026 Elections\'','\'Geoff Hale,Ryan Macias\'','Creator Talks_762b799f1b26fe5711ba71a5cf5d7fc3','\'Title: Alerts and Warnings in 2026 Elections
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

The landscape supporting election cybersecurity has shifted dramatically since 2024. The federal government has lost most of its institutional knowledge about election security. Federal agencies have withdrawn from this space and diminished support for the Election Infrastructure Information Sharing and Analysis Center, leaving election officials and their vendors to shoulder the cybersecurity burden on their own. State and local election officials describe a breakdown in trust, reduced support, less intelligence, and other caustic effects that are debilitating the information-sharing environment. Meanwhile, advanced threats and threat actors have not gone away.

\n\n

The fracturing of election security support goes beyond funding cuts for threat monitoring and fewer cyber assessments. Breakdowns in the multilateral information sharing mean that election officials lose early warnings, resource-strapped jurisdictions lose collective knowledge, and, critically, the federal government loses the capability to detect foreign campaigns to interfere in US elections.

\n\n

An ineffective information-sharing environment leaves state and local jurisdictions facing sophisticated adversaries and criminal organizations without collective defense. Some losses can be replicated, but the gaps leave election security weaker than before.

\n\n

Civil society, particularly former federal, state, and local election security professionals, is attempting to fill these gaps. Organizations such as the Election Security Exchange, Center for Democracy and Technology, Committee for Safe and Secure Elections, Partnership for Elections and Emergency Response, ASU Mechanics of Democracy Lab, MS-ISAC, Election Technology Education Fund, and other partners are rebuilding collective defenses. This panel acknowledges that the environment is what it is and demonstrates that vulnerabilities are not going unrecognized or unaddressed.

\n\nSpeakers:Geoff Hale,Ryan Macias
\n
\nSpeakerBio:  Geoff Hale
\n

Geoff Hale has over 15 years of experience supporting the security of critical infrastructure with a focus on election security since 2016. Geoff worked at the Cybersecurity and Infrastructure Security Agency (CISA) as Associate Director for Election Security & Resilience, helping to build a security community in support of U.S. elections.

\n\nSpeakerBio:  Ryan Macias
\n

Ryan Macias has spent over 20 years providing subject-matter expertise in election technology, security, and administration to election officials across the U.S. and election management bodies (EMBs) abroad. Macias has advised thousands of election stakeholders on strategies and methods to build resilience in election infrastructure, technology, and processes. Macias also teaches Election Security at the University of Minnesota and previously worked for the U.S. Election Assistance Commission (EAC) as the Acting Director of the Voting Systems Program and California Secretary of State, where he led the Top-to-Bottom Review of Voting Systems.

\n\n\n\'',NULL,1296970),('3_Saturday','16','16:00','16:30','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Low Skill, High Impact Attacks on Internet Voting\'','\'John Odum\'','Creator Talks_c0a35eeaffca2348727ed2727b888e84','\'Title: Low Skill, High Impact Attacks on Internet Voting
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

Debates over internet voting frequently focus on sophisticated technical threats, including malware, server intrusions, insider attacks, and cryptographic vulnerabilities. While these concerns remain significant, they may obscure a broader class of low-cost, \"cheap\" attacks that target voters and public confidence rather than election infrastructure itself. This presentation explores how internet voting systems may expand opportunities for inexpensive, highly scalable disruption, information operations, and psychological attacks against election legitimacy.\nExamples include phishing campaigns aimed at vote-by-phone users, fraudulent voting applications distributed through app stores, compromised browser extensions, automated social-media campaigns or website defacements that manufacture the appearance of widespread system failures, and targeted messages to early voters falsely informing them that their ballots or personal information have been compromised. Traditional vote-suppression techniques such as robocalls may likewise be adapted to digital platforms and enhanced through AI-generated content and voice cloning. In some cases, no actual compromise need occur; the perception of a successful attack - a form of psychological operation (psyop) - may itself achieve an adversary\'s objectives.\nThe central argument is that the most consequential threats to internet voting may not always involve defeating election technology itself but rather exploiting expanded opportunities to attack voters and erode confidence in the electoral process.

\n\nSpeakerBio:  John Odum
\n

John Odum is the elected City Clerk of Montpelier, Vermont, where he serves as Election Administrator. He holds the Certified Municipal Clerk (CMC) designation from the International Institute of Municipal Clerks, a Certificate in Election Administration from the University of Minnesota Humphrey School of Public Affairs, and Certified Ethical Hacker (CEH) and Certified Network Defense Architect (CNDA) certifications from EC-Council. Prior to becoming an election administrator, he worked in information technology and electoral politics, including as the Technology Director for the Vermont Democratic Party, Statewide Field Director for the Clavelle for Governor campaign, Clinic Management System Administrator for Planned Parenthood of Northern New England, and as a political organizer for Oregon’s “No On 13” campaign, Maryland Citizen Action, and the 2018 Bernie Sanders for Congress campaign. He currently writes on elections and democracy at his substack, electionmatters.net.

\n\n\n\'',NULL,1296971),('3_Saturday','16','16:30','16:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'On the Weaponization of Voting Channels\'','\'Carsten Schürmann\'','Creator Talks_889bf621dcaf598372e638aea9747415','\'Title: On the Weaponization of Voting Channels
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

The main purpose of any election is to deliver a peaceful resolution to the civic battle between stakeholder groups about power and governance with the goal to guarantee a peaceful transfer of power. A well-working democracy is resilient against false narratives and marked by losing parties to concede and accept the outcome of the election. Election legislation defines how an election should be run, who is eligible to vote, how voter eligibility is verified, which voting channels are offered to voters to cast their vote, what constitutes a valid vote, how votes are tallied, how results are transmitted, how the results are audited and how disputes are resolved.

\n\n

Different voting channels improve accessibility and comfort, however they can provide grounds for false narratives before and after an election and thus strain public confidence. Examples from the US include in-person voting, early voting, in-person absentee voting, or mail-in voting. Experiences from Estonia offering only two voting channels, in-person voting and Internet voting, have demonstrated a worrying trend of voting channel weaponizations, which has led to a noticeable drop in voter confidence for the first time since Internet voting was introduced in 2005. Politicization driven by political parties, activism, and domestic and foreign influence are to blame. Voting channels supported by election technologies are particularly exposed.

\n\n

In my talk, I will discuss the anatomy of voting channel weaponization, who are the actors, what techniques are being used, how to recognize it and how to defend against it.

\n\nSpeakerBio:  Carsten Schürmann
\n

Carsten Schürmann is a professor of computer science at the IT University of Copenhagen where he leads the Center for Information Security and Trust CISAT. His academic research focuses on cyber- and information security—with a particular interest in making elections secure and trustworthy. He has extensive hands-on experience in the election field, having worked as an election technology expert on observation missions with the Carter Center, NDI, and OSCE/ODIHR, and on assistance and training missions with IFES and OSCE. Through his consultancy, DemTech Group, he advises NGOs and international organizations on election security across the full electoral cycle. Carsten became known in the DefCon hacking community when he demonstrated vulnerabilities in the WinVote DRE voting machine at DEF CON in 2017.

\n\n\n\'',NULL,1296972),('3_Saturday','17','17:00','17:30','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'Election Observation: Watching is not Enough\'','\'Douglas W. Jones\'','Creator Talks_48ac2911dcfe25536190750cd51deb9f','\'Title: Election Observation: Watching is not Enough
\nTags: Voting Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

As Dan Wallach once said, an election must convince the losers that they lost fair and square. To do this, election administrators need to do more than merely allowing observers from all parties to watch, we must ensure that observers can understand what they are seeing. Watching the back of an election administrator doing something with a computer or even a with a stack of papers is not useful. Anecdotal reports by observers can give a feel for how an election was conducted, but systematic and well documented reporting is far more powerful. Election observation is difficult with simple in-person vote-for one contests; vote by mail, Internet voting and instant runoff voting all pose serious problems for election observers. We must demand electoral procedures that are easy to understand, and we must demand public documentation of those procedures. This talk will focus on successes and failures in election observation and suggest directions for future improvement.

\n\nSpeakerBio:  Douglas W. Jones
\n

Douglas W. Jones has been involved with election technology since he was appointed to the Iowa Board of Examiners for Voting Machines and Electronic Voting Systems in 1994. Since then, contributed to the 2002 FEC Voting System Standards, served on the Election Assistance Commission\'s Technical Guidelines Development Committee, tested voting equipment in Miami and Phoenix, and observed elections in Kazakhstan and the Netherlands. He has testified about voting technology before the House Science Committee, the Federal Election Commission, and in numerous court cases. He was a principal investigator in the NSF funded ACCURATE project, and with Barbara Simons, co-authored the book Broken (CSLI Press, 2012).

\n\n

He got his PhD in Computer Science from the University of Illinois in 1980, and was on the CS University of Iowa CS faculty until 2021. These days, when he is not answering questions about elections, he is working with a small group of students to restore a 1965-vintage PDP-8 computer.

\n\n\n\'',NULL,1296973),('3_Saturday','17','17:30','17:59','N','Voting Village','LVCCW Level 2 W220 (Voting Village) (Voting Village Talks)','\'The Republic is a Team Sport: Technology can Protect Elections, but the People must Protect Democracy\'','\'Kendall Spencer\'','Creator Talks_c6d22c52e60ac109f774654bdfdc704d','\'Title: The Republic is a Team Sport: Technology can Protect Elections, but the People must Protect Democracy
\nTags: Voting Village | Creator Interactive Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 2 W220 (Voting Village) (Voting Village Talks) - Map
\n
\nDescription:
\n

Throughout the Voting Village, speakers and researchers have always challenged assumptions around election technology, internet voting, audits, legal frameworks, and the public confidence. Among the many lessons learned together, we can see these issues pointing to a common conclusion that democracy cannot depend on trust alone. But the evidence we develop from security research and academia, are not enough to move our nation in the right direction either.

\n\n

This closing discussion asks what comes after the research. How do technical findings become better policy? What responsibilities do election officials, attorneys, journalists, academics, and citizens share in preserving institutions that none of us can protect alone? What does it mean to be an American today?\nThis session invites the audience to help answer those questions. Drawing from conversations throughout the conference, we’ll explore how democratic resilience depends not only on secure systems, but on communities willing to engage honestly across disciplines and political perspectives.

\n\n

The goal is not consensus. The goal is responsibility.

\n\nSpeakerBio:  Kendall Spencer
\n

Kendall Spencer is an attorney specializing in emerging companies, technology transactions, and the legal issues shaping innovation. Since joining DEF CON’s Voting Village as a Georgetown Law student in 2019, he has worked alongside Matt Blaze, David Jefferson, and the Voting Village team at the intersection of election technology, cybersecurity, and democracy. Spencer serves on the Board of Directors of the Election Integrity Foundation and has advised state election officials on election security, post-election audits, and cybersecurity best practices.\nHis work focuses on bridging the gap between technical research, public policy, and the law—helping policymakers, election officials, security researchers, and the public better understand the role election security plays in strengthening democratic institutions and public confidence in elections. A frequent DEF CON speaker, Spencer is passionate about fostering thoughtful, bipartisan conversations on the role of technology in protecting election integrity and the democratic principles that underpin a free and open society.\nOutside of his legal and technology work, Spencer is a rare book dealer and collector specializing in early American history and the Black diaspora.

\n\n\n\'',NULL,1296974),('2_Friday','11','11:00','11:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'Trans Townhall\'','\'\'','Creator Events_e1a737c158fccb6ee277c2696d4afed3','\'Title: Trans Townhall
\nTags: Queercon Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n

Join us for the Trans Town Hall to find connections, discuss challenges facing the trans community, and engage in converations critical to the community.

\n\n\'',NULL,1296975),('2_Friday','12','12:00','12:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'QueerCon Opening Meet and Greet\'','\'\'','Creator Events_ce86e71dc4145bc65707a9a0f3db138b','\'Title: QueerCon Opening Meet and Greet
\nTags: Queercon Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n

Join us for the opening of this years queercon lounge

\n\n\'',NULL,1296976),('2_Friday','13','13:00','13:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'Non-Binary/Gender Non-conforming Meetup\'','\'\'','Creator Events_7db42d510dd316e24de1b991a0d5b635','\'Title: Non-Binary/Gender Non-conforming Meetup
\nTags: Queercon Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n\n\n\'',NULL,1296977),('2_Friday','14','14:00','14:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'Women Loving Women Meetup\'','\'\'','Creator Events_ef96a08b892a69e44c9b4d6da8fb8400','\'Title: Women Loving Women Meetup
\nTags: Queercon Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n\n\n\'',NULL,1296978),('2_Friday','15','15:00','15:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'Furs and Kinksters Meetup\'','\'\'','Creator Events_fe12a5d949af85c0535bb8c7d5d6b17d','\'Title: Furs and Kinksters Meetup
\nTags: Queercon Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n\n\n\'',NULL,1296979),('3_Saturday','11','11:00','11:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'Polycon\'','\'\'','Creator Events_fec165c856e50fbec537adde10efd744','\'Title: Polycon
\nTags: Queercon Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n\n\n\'',NULL,1296980),('3_Saturday','12','12:00','12:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'Trans Meetup\'','\'\'','Creator Events_c2f9de224b9774997aa51530a1914aa2','\'Title: Trans Meetup
\nTags: Queercon Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n\n\n\'',NULL,1296981),('3_Saturday','13','13:00','13:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'Ace/Aro Meetup\'','\'\'','Creator Events_ad57f0697f7ed11e3c51071a2d6bd754','\'Title: Ace/Aro Meetup
\nTags: Queercon Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n\n\n\'',NULL,1296982),('3_Saturday','14','14:00','14:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'Own the con\'','\'\'','Creator Talks_62b35447bc71b8891b8a3b6b9edc8ae3','\'Title: Own the con
\nTags: Queercon Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n

A talk about Queercon and you

\n\n\'',NULL,1296983),('3_Saturday','15','15:00','15:59','N','Queercon Community','LVCCW Level 3 W325 (QueerCon Lounge)','\'Men Loving Men Meetup\'','\'\'','Creator Events_54c8af8c327b148411cc37c8a8effec2','\'Title: Men Loving Men Meetup
\nTags: Queercon Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 3 W325 (QueerCon Lounge) - Map
\n
\nDescription:
\n\n\n\'',NULL,1296984),('2_Friday','10','10:00','17:59','N','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_4ddf1b119a8ddd0cff6b513b7c1bcc21','\'Title: Voting Village Lab
\nTags: Voting Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W219 (Voting Village) (Voting Village Lab) - Map
\n
\nDescription:
\n

The Voting Village Lab is a hands-on, self-directed workshop space where attendees can learn about and experiment with dozens of different pieces of election equipment used in current and past US elections.

\n\n\'',NULL,1296985),('2_Friday','11','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_4ddf1b119a8ddd0cff6b513b7c1bcc21','\'\'',NULL,1296986),('2_Friday','12','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_4ddf1b119a8ddd0cff6b513b7c1bcc21','\'\'',NULL,1296987),('2_Friday','13','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_4ddf1b119a8ddd0cff6b513b7c1bcc21','\'\'',NULL,1296988),('2_Friday','14','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_4ddf1b119a8ddd0cff6b513b7c1bcc21','\'\'',NULL,1296989),('2_Friday','15','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_4ddf1b119a8ddd0cff6b513b7c1bcc21','\'\'',NULL,1296990),('2_Friday','16','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_4ddf1b119a8ddd0cff6b513b7c1bcc21','\'\'',NULL,1296991),('2_Friday','17','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_4ddf1b119a8ddd0cff6b513b7c1bcc21','\'\'',NULL,1296992),('3_Saturday','10','10:00','17:59','N','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_ddb76f0731aee6453dcbe7f025d00479','\'Title: Voting Village Lab
\nTags: Voting Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W219 (Voting Village) (Voting Village Lab) - Map
\n
\nDescription:
\n

The Voting Village Lab is a hands-on, self-directed workshop space where attendees can learn about and experiment with dozens of different pieces of election equipment used in current and past US elections.

\n\n\'',NULL,1296993),('3_Saturday','11','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_ddb76f0731aee6453dcbe7f025d00479','\'\'',NULL,1296994),('3_Saturday','12','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_ddb76f0731aee6453dcbe7f025d00479','\'\'',NULL,1296995),('3_Saturday','13','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_ddb76f0731aee6453dcbe7f025d00479','\'\'',NULL,1296996),('3_Saturday','14','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_ddb76f0731aee6453dcbe7f025d00479','\'\'',NULL,1296997),('3_Saturday','15','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_ddb76f0731aee6453dcbe7f025d00479','\'\'',NULL,1296998),('3_Saturday','16','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_ddb76f0731aee6453dcbe7f025d00479','\'\'',NULL,1296999),('3_Saturday','17','10:00','17:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_ddb76f0731aee6453dcbe7f025d00479','\'\'',NULL,1297000),('4_Sunday','10','10:00','13:59','N','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_90898fe78360e5c0d55dacdf29ef3acf','\'Title: Voting Village Lab
\nTags: Voting Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W219 (Voting Village) (Voting Village Lab) - Map
\n
\nDescription:
\n

The Voting Village Lab is a hands-on, self-directed workshop space where attendees can learn about and experiment with dozens of different pieces of election equipment used in current and past US elections.

\n\n\'',NULL,1297001),('4_Sunday','11','10:00','13:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_90898fe78360e5c0d55dacdf29ef3acf','\'\'',NULL,1297002),('4_Sunday','12','10:00','13:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_90898fe78360e5c0d55dacdf29ef3acf','\'\'',NULL,1297003),('4_Sunday','13','10:00','13:59','Y','Voting Village','LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)','\'Voting Village Lab\'','\'\'','Creator Events_90898fe78360e5c0d55dacdf29ef3acf','\'\'',NULL,1297004),('2_Friday','10','10:00','10:55','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Noob Community - DEF CON 34 Opening Statements\'','\'\'','Creator Talks_52327320afee4923e48df635d40c6ce8','\'Title: Noob Community - DEF CON 34 Opening Statements
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:55 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n\n\n\'',NULL,1297005),('2_Friday','10','10:00','13:50','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta\'','\'James Stanger,Stephen Schneiter\'','Creator Workshops_fde5c6546c8376c7f75fc028f14577a5','\'Title: Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta
\nTags: Noob Community | Creator Workshop
\nWhen: Friday, Aug 7, 10:00 - 13:50 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\nThe Ginger Hacker Initiative and CompTIA are teaming up for an interactive session focused on the three critical dimensions of AI cybersecurity: securing AI systems, securing with AI, and governing AI. Built directly around the new CompTIA SecAI+ course, this workshop completely bypasses the fluff to focus entirely on real-world application.
\n\n\n\nSpeakers:James Stanger,Stephen Schneiter
\n
\nSpeakerBio:  James Stanger
\nNo BIO available
\nSpeakerBio:  Stephen Schneiter
\nNo BIO available
\n\n\'',NULL,1297006),('2_Friday','11','10:00','13:50','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta\'','\'James Stanger,Stephen Schneiter\'','Creator Workshops_fde5c6546c8376c7f75fc028f14577a5','\'\'',NULL,1297007),('2_Friday','12','10:00','13:50','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta\'','\'James Stanger,Stephen Schneiter\'','Creator Workshops_fde5c6546c8376c7f75fc028f14577a5','\'\'',NULL,1297008),('2_Friday','13','10:00','13:50','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Practical Cybersecurity Skills in an AI-Augmented World: Protecting the AI Trifecta\'','\'James Stanger,Stephen Schneiter\'','Creator Workshops_fde5c6546c8376c7f75fc028f14577a5','\'\'',NULL,1297009),('2_Friday','11','11:00','11:30','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Privilege Escalation: A Career Story\'','\'Ryan Bonner,Whit Taylor\'','Creator Talks_fcc22a8300881c90f789a9fd883e840f','\'Title: Privilege Escalation: A Career Story
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Nobody handed us a roadmap. Before cybersecurity, our backgrounds looked nothing like the industry expected.

\n\n

This is for everyone who\'s ever lurked in Discord, watched a conference talk, or read a writeup from someone and thought, \"I wish I could talk with them.\"

\n\n

PROTIP: You can, and you should.

\n\n

We will share our unfiltered stories of breaking into the industry from non-traditional paths. The imposter syndrome, the cold messages to people we idolized, and what happened when we suddenly stopped being afraid to ask.

\n\n

We plan to invite well-known figures from the community to come in chat with everyone and do a little mini social chat where everyone can ask the questions to hopefully people they idolize!

\n\nSpeakers:Ryan Bonner,Whit Taylor
\n
\nSpeakerBio:  Ryan Bonner, Lead Security Engineer at Arcanum Information Security
\n

Ryan Bonner is a Lead Security Engineer at Arcanum Information Security, where he builds AI systems, hacks them, and runs application penetration tests. Off the clock he hunts wide-scope bug bounty programs.

\n\nSpeakerBio:  Whit Taylor
\nNo BIO available
\n\n\'',NULL,1297010),('2_Friday','11','11:45','12:45','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'If I Were Eighteen Again: Career Advice for the AI Era\'','\'Keith Hoodlet\'','Creator Talks_798f8b1d440b0a420bc5ea669af22b29','\'Title: If I Were Eighteen Again: Career Advice for the AI Era
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:45 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\nPlease Note: This talk is based on the post \"If I were Eighteen Again\", published June 16, 2025 from my personal blog (https://securing.dev/posts/if-i-were-eighteen-again/).
\n\n

Abstract

\n\n

In 2025 the CEO of Anthropic stated that AI could eliminate half of all entry-level white collar jobs within five years. For n00bs entering the cybersecurity industry today, that\'s a scary headline; It doesn\'t have to be a death sentence for your nascent career.

\n\n

In this talk the speaker shares what they would do differently if they were eighteen again, drawing from their own experiences entering the workforce at the bottom of the 2008 housing market crash with no connections, no work history, and no roadmap. Reflecting on over a decade of acquiring and building skills as an Information Security practitioner, this session delivers timeless, practical advice that will help aspiring security professionals build a career that is resilient to economic downturns, immune to hype cycles, and capable of surviving whatever the latest technology trend comes next.

\n\n
\n\n

Detailed Outline

\n\n

Introduction (4 minutes)

\n\n
    \n
  • $WHOAMI
  • \n
  • The AI jobs headline, and why it\'s both alarming and useful
  • \n
  • What this talk is, and what it isn\'t: timeless career advice, not a silver bullet
  • \n
  • Some caveats: lived experience, privilege, and why your mileage may vary
  • \n
\n\n

Read & Write Long-Form Content (6 minutes)

\n\n
    \n
  • The world\'s most successful people are avid readers
  • \n
  • Reading vs. watching/listening: what the neuroscience actually says
  • \n
  • Algorithmic recommendation engines and the danger of passive consumption
  • \n
  • Writing as a skill multiplier: building a body of work before you need it
  • \n
  • \"Do it scared\", and overcoming the fear of publishing
  • \n
  • When to update your public opinions, and why doing so is a superpower
  • \n
\n\n

Learn How to Learn (6 minutes)

\n\n
    \n
  • The difference between knowing something and being able to do it
  • \n
  • Identifying your own learning style before committing to expensive programs
  • \n
  • The \"Read, Do, Write, Relax\" loop for accelerating and sustaining skill development
  • \n
  • How to take effective breaks without losing momentum
  • \n
  • Avoiding the regret of wasted time in your youth
  • \n
\n\n

Develop Critical Thinking & Practice Mindfulness (6 minutes)

\n\n
    \n
  • Charlie Munger\'s rule: never hold an opinion without knowing the other side\'s argument(s) better than they do
  • \n
  • Building a mental network of ideas that current LLMs have difficulty replicating
  • \n
  • Mindfulness as a career superpower, from financial decisions to skill development
  • \n
  • Practical intro to meditation: apps, tools, and building a consistent practice
  • \n
  • Presence of mind as the thing that separates good practitioners from great ones
  • \n
\n\n

Build & Maintain a Public Brand (7 minutes)

\n\n
    \n
  • The NPC vs. PC analogy: passive individuals are losing the career game
  • \n
  • Why employers now expect a body of work before they\'ll consider you
  • \n
  • Real-world example: how a recent college grad landed a Senior role right out of school\n
      \n
    • Olivia Gallucci
    • \n
  • \n
  • Platforms, formats, and how to start from zero
  • \n
  • Why public content is the new resume
  • \n
\n\n

Seek Out Mentorship (6 minutes)

\n\n
    \n
  • Why mentors won\'t look for you — and how to make yourself worth mentoring
  • \n
  • The mistake of asking for things without putting in the work first
  • \n
  • Building a portfolio of mentors across different career dimensions (IC, leadership, business)
  • \n
  • How to approach potential mentors without being annoying about it
  • \n
  • My own mentor network, and what I’ve learned from each of them
  • \n
\n\n

Thoughts on Formal Education, Certs & Bootcamps (6 minutes)

\n\n
    \n
  • Is a four-year degree still worth it? (Honest answer: it depends)
  • \n
  • The community college + top school financial aid strategy
  • \n
  • CTF > CCDC for real-world skill development and job opportunities
  • \n
  • Which certifications actually matter: practical exams vs. paper tests
  • \n
  • Why bootcamps are basically a money trap in the LLM era
  • \n
  • The three things leaders look for in junior talent: Attitude, Aptitude, and Engagement
  • \n
\n\n

On AI and Skill Development (6 minutes)

\n\n
    \n
  • Using LLMs well vs. using them as a crutch
  • \n
  • Why having AI write your public content is both cheap and easy to spot
  • \n
  • The whiteboard technique for working with LLM-generated-anything
  • \n
  • How LLMs narrow your thinking, and how to fight back against that
  • \n
\n\n

The AI-Averse Path: Becoming a Shokunin (5 minutes)

\n\n
    \n
  • What the Japanese concept of shokunin has to do with your career
  • \n
  • Craftsmanship as a defense against commoditization
  • \n
  • What this path actually requires, and why it\'s harder than it sounds
  • \n
\n\n

Q&A (8 minutes)

\n\n
\n\n

Attendee Takeaways

\n\n

Foundational habits that compound: Reading, writing, mindfulness, and continuous learning are not just “soft skills”, they are what separates practitioners who plateau from those who build enduring careers.

\n\n

Your public brand is your resume: In 2026, a body of published work is the difference between being considered for a role and being filtered out.

\n\n

AI is a tool, not a replacement for thinking: Understanding how to use LLMs without outsourcing learning or critical thinking is one of the most important skills a new practitioner should be developing right now.

\n\n

Education and certifications are tools, not guarantees: Know what they are actually buying you, and pursue practical proof of skill development over paper credentials wherever possible.

\n\nSpeakerBio:  Keith Hoodlet
\nNo BIO available
\n\n\'',NULL,1297011),('2_Friday','12','11:45','12:45','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'If I Were Eighteen Again: Career Advice for the AI Era\'','\'Keith Hoodlet\'','Creator Talks_798f8b1d440b0a420bc5ea669af22b29','\'\'',NULL,1297012),('2_Friday','13','13:00','13:15','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Threatmaxxing Your Stakeholders while Mogging Your Threat Actors: What is Cyber Threat Intel?\'','\'Eli Woodward\'','Creator Talks_0c3a085674c920a79958ce94fb54333e','\'Title: Threatmaxxing Your Stakeholders while Mogging Your Threat Actors: What is Cyber Threat Intel?
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

This is a 15 minute lightning talk with an intro/brief overview of the Cyber Threat Intelligence discipline. Topics covered include why it\'s so hard to identify and define what CTI is in the current industry, the different aspects of what can be expected from CTI, and the typical backgrounds of CTI practitioners.

\n\n

Having been a part of CTI teams at organizations with a wide variety of resources and maturity levels, this talk provides a realistic, ground-level view of the industry and what your average CTI experience is like, not the curated experiences of Fortune 500 CTI teams we all see presenting on the main stage.

\n\nSpeakerBio:  Eli Woodward, Senior Threat Intelligence Advisor with Team Cymru
\n

Eli Woodward is a cyber threat intelligence advisor with Team Cymru. He\'s worked in a variety of industries including financial services and government, and has seen the range of organizations from extremely well-resourced and capable to the shoestring budget. This has given him unique insights into CTI at all levels of complexity, maturity, and resources. He holds a master\'s degree in Intelligence and Security Studies and also plays bagpipes competitively.

\n\n\n\'',NULL,1297013),('2_Friday','13','13:30','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'OSINT: Zero To Hero\'','\'Mishaal Khan\'','Creator Talks_321b4af267107a52fae03a5aa4d8d88f','\'Title: OSINT: Zero To Hero
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

If you\'re curious on how this field has evolved, I\'ll take you on a journey from beginner to extremely advanced level intelligence, all using a computer. I\'ll demo techniques live and answer questions like: How has OSINT evolved over the years? What powers do you get from developing this skill?

\n\nSpeakerBio:  Mishaal Khan
\nNo BIO available
\n\n\'',NULL,1297014),('2_Friday','14','14:00','15:20','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Beyond Heatmaps: Hands-On Cyber Risk Quantification with FAIR\'','\'Tony Martin-Vegue\'','Creator Workshops_1fce27b4d481f892bf82e036eac92ff8','\'Title: Beyond Heatmaps: Hands-On Cyber Risk Quantification with FAIR
\nTags: Noob Community | Creator Workshop
\nWhen: Friday, Aug 7, 14:00 - 15:20 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Cybersecurity has its own language, and business has its own language, and most of the time we\'re not speaking either of them well. The people who learn to translate between the two are the ones who get listened to, get funded, and get promoted. That\'s the craft Tony is teaching you in this session.

\n\nSpeakerBio:  Tony Martin-Vegue
\nNo BIO available
\n\n\'',NULL,1297015),('2_Friday','15','14:00','15:20','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Beyond Heatmaps: Hands-On Cyber Risk Quantification with FAIR\'','\'Tony Martin-Vegue\'','Creator Workshops_1fce27b4d481f892bf82e036eac92ff8','\'\'',NULL,1297016),('2_Friday','14','14:15','14:45','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Day in the Life - Green Beret to AI Penetration Tester\'','\'Clayton Boozell\'','Creator Talks_417b2d91e1b28d4e0fb215179a65d411','\'Title: Day in the Life - Green Beret to AI Penetration Tester
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:15 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

This session is an open on building a career in offensive security, from unconventional beginnings to breaking AI systems at a major tech company.

\n\n

The speaker will share a candid look at his journey from U.S. Army Special Forces to national-level cyber operations and now AI penetration testing highlighting what actually mattered, what didn’t, and how skills from completely different fields translate into high-end offensive security roles.

\n\n

Topics will range from breaking into cybersecurity with no experience, navigating certifications and degrees, and building real-world skills through CTFs and labs to what it’s like to hack AI systems, how those attacks work in practice, and where the field is heading.

\n\nSpeakerBio:  Clayton Boozell
\nNo BIO available
\n\n\'',NULL,1297017),('2_Friday','15','15:00','15:15','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'The impact of CTF Write-Ups\'','\'Mathias Detmers\'','Creator Talks_1989d1441c15d3280feb779797a4ac8e','\'Title: The impact of CTF Write-Ups
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Over three years I\'ve published 150+ write-ups on CTF challenges. Along the way the write-ups stopped being just documentation and started being the most valuable thing I produce — sourcing job offers, collaborations, and credibility I never directly asked for. \nThis talk makes the case that a write-up is not the report of your work but the work itself: where learning consolidates and reputation compounds. I\'ll share the concrete payoff, the craft, lessons learned, and a blueprint anyone can start with. No novel 0-day, just maybe the most underrated force multiplier in offensive cyber security.

\n\nSpeakerBio:  Mathias Detmers
\nNo BIO available
\n\n\'',NULL,1297018),('2_Friday','15','15:30','16:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Introduction to Web Exploitation\'','\'Roman Bohuk\'','Creator Workshops_5d215b8600190f1aee6874fce11be506','\'Title: Introduction to Web Exploitation
\nTags: Noob Community | Creator Workshop
\nWhen: Friday, Aug 7, 15:30 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Before you can secure the web, you have to understand how to break it. This 90-minute hands-on session completely bypasses the static slides to give you a practical, interactive introduction to web exploitation. Led by Roman Bohuk, CEO of SkillBit (formerly MetaCTF), you will explore the core technologies that power the web and learn proven, real-world attack methodologies. Whether you are aiming to break into professional web application penetration testing or just looking to sharpen your CTF skills, you\'ll get dirty with live vulnerabilities, learn how modern web targets are enumerated, and walk away with a solid, actionable foundation in offensive web security.

\n\nSpeakerBio:  Roman Bohuk
\nNo BIO available
\n\n\'',NULL,1297019),('2_Friday','16','15:30','16:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Introduction to Web Exploitation\'','\'Roman Bohuk\'','Creator Workshops_5d215b8600190f1aee6874fce11be506','\'\'',NULL,1297020),('2_Friday','15','15:30','15:45','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Lessons Learned From A Decade of Resumes\'','\'Britt Kemp\'','Creator Talks_2d60de5b699b9d34582ca62d03d4f3ee','\'Title: Lessons Learned From A Decade of Resumes
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

After having reviewed resumes for the last decade in a variety of industries (although chiefly cybersecurity), I have a few things to say!

\n\n

Want to learn how to craft a compelling resume? Want to know what to avoid? This session aims to help jobseekers sell themselves better.

\n\n

Not only will I dive into the dos and don\'ts of resume success, but I will also cover LinkedIn, interviews, networking, and other relevant topics.

\n\n

If you\'re looking for work in this brutal market, I hope I can help you out.

\n\nSpeakerBio:  Britt Kemp
\nNo BIO available
\n\n\'',NULL,1297021),('2_Friday','16','16:00','16:30','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Building Your First Homelab\'','\'Stephen Glombicki\'','Creator Talks_3f125b660e1eeee4da4dcb22d880de51','\'Title: Building Your First Homelab
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Have you wanted to build a homelab but felt overwhelmed by all the choices? This talk is for you. Building a homelab doesn\'t have to be complex or intimidating, I\'ll walk you through how easy and simple it can be to set up your first lab and get hands on experience with popular cybersecurity and IT tools.

\n\nSpeakerBio:  Stephen Glombicki
\nNo BIO available
\n\n\'',NULL,1297022),('2_Friday','16','16:35','17:05','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'The Front Lines Need Detection Engineers : Would You Like to Know More?\'','\'Kyle Barboza\'','Creator Talks_00580cb85d12d231dc4dbc3df606b54f','\'Title: The Front Lines Need Detection Engineers : Would You Like to Know More?
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:35 - 17:05 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Would You Like to Know More? Becoming a Detection Engineer

\n\n

Detection Engineering is one of the fastest-growing specialties in cybersecurity. But what does a Detection Engineer actually do?

\n\n

In this beginner-friendly lightning talk, I\'ll share how I stumbled into Detection Engineering, what the job really looks like, the skills that mattered most, and the mistakes I wish I\'d avoided. Whether you\'re a SOC analyst, student, or simply curious about the field, you\'ll leave with a clearer understanding of the role and practical steps to begin your own journey.

\n\n

Citizenship not required. Curiosity mandatory.

\n\nSpeakerBio:  Kyle Barboza
\nNo BIO available
\n\n\'',NULL,1297023),('2_Friday','17','16:35','17:05','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'The Front Lines Need Detection Engineers : Would You Like to Know More?\'','\'Kyle Barboza\'','Creator Talks_00580cb85d12d231dc4dbc3df606b54f','\'\'',NULL,1297024),('3_Saturday','10','10:00','11:20','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Break Things, Learn Things: Hands-On Hacking for Beginners\'','\'Evolve Security Academy\'','Creator Workshops_7025c788dfba90f1b97d1ec4744e61ec','\'Title: Break Things, Learn Things: Hands-On Hacking for Beginners
\nTags: Noob Community | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 11:20 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

You don\'t need years of experience to start thinking like an attacker—you just need the right environment and someone to show you the ropes. In this hands-on, 45-minute session, Evolve Security Academy completely bypasses the theory to walk you through the fundamentals of ethical hacking in a live, browser-accessible lab environment. You\'ll adopt an attacker mindset, perform real reconnaissance, run vulnerability scans, and assess live exploits firsthand. Best of all, all registered participants get 7 days of extended access to the CyberLab platform to keep hacking at their own pace after DEF CON.

\n\nSpeakerBio:  Evolve Security Academy
\nNo BIO available
\n\n\'',NULL,1297025),('3_Saturday','11','10:00','11:20','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Break Things, Learn Things: Hands-On Hacking for Beginners\'','\'Evolve Security Academy\'','Creator Workshops_7025c788dfba90f1b97d1ec4744e61ec','\'\'',NULL,1297026),('3_Saturday','10','10:00','10:15','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Wanna Hack Space ? Why? Is it out of this world?\'','\'Henry Danielson Hankashyyyk\'','Creator Talks_cdacb28ae910225cea3bd5f96b3cd9b1','\'Title: Wanna Hack Space ? Why? Is it out of this world?
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

What can you do to become involved? How to get into the Space Satellites & Cybersecurity? There is some crossover of cybersecurity skills with Space and Satellites. Did you know Linux is increasingly used in space for high-reliability, low-cost applications, with specialized, hardened distributions now addressing radiation, security, and real-time demands. Review SPARTA:MITRE for Space! NASA Open Source Software FPrime(F\'),AMSAT CUBESAT SIM. https://ct3sathack.cacyber.net/

\n\nSpeakerBio:  Henry Danielson Hankashyyyk
\nNo BIO available
\n\n\'',NULL,1297027),('3_Saturday','10','10:30','10:45','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'The importance of Networking in Cybersecurity community\'','\'Michael Lenz\'','Creator Talks_a13853bb4e4ef894afe849fc9b261117','\'Title: The importance of Networking in Cybersecurity community
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:30 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Quick session on how important it is to network with other professionals, students, and vendors to gain knowledge, collaborate for defenses and also for career growth

\n\nSpeakerBio:  Michael Lenz
\nNo BIO available
\n\n\'',NULL,1297028),('3_Saturday','11','11:00','11:30','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No One Makes It Alone - Community as the Ultimate Security Control\'','\'Kristen Sanders\'','Creator Talks_20f82128b820cd4f340d3f5d18b24509','\'Title: No One Makes It Alone - Community as the Ultimate Security Control
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

When systems fail and plans fall apart, survival depends on people. This talk explores why resilience, recovery, and critical infrastructure security ultimately rely on community, agility, shared knowledge, and mutual support.

\n\nSpeakerBio:  Kristen Sanders
\nNo BIO available
\n\n\'',NULL,1297029),('3_Saturday','11','11:30','12:50','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'OASIS: Prompt to Pwn\'','\'Marshall Livingston\'','Creator Workshops_52624248397a4747d6589b77903cce32','\'Title: OASIS: Prompt to Pwn
\nTags: Noob Community | Creator Workshop
\nWhen: Saturday, Aug 8, 11:30 - 12:50 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

AI went from a tech toy to critical infrastructure overnight, but measurement is lagging behind. This 90-minute session skips the theory to show how AI actually performs using OASIS - a free, independent benchmarking tool you can run right from your phone.

\n\nSpeakerBio:  Marshall Livingston
\nNo BIO available
\n\n\'',NULL,1297030),('3_Saturday','12','11:30','12:50','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'OASIS: Prompt to Pwn\'','\'Marshall Livingston\'','Creator Workshops_52624248397a4747d6589b77903cce32','\'\'',NULL,1297031),('3_Saturday','11','11:45','12:45','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Gamifying the Matrix: a MITRE ATT&CK Video Game\'','\'Annie Meaney,Anne Drago\'','Creator Talks_3986a308d48101005b228917d1fafbd5','\'Title: Gamifying the Matrix: a MITRE ATT&CK Video Game
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:45 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

This session introduces attendees to the MITRE ATT&CK Defense Game, a technical capstone project designed to bridge high-level gaming logic with real-world cybersecurity infrastructure. We will explore how gamification can be used to visualize adversary tactics and techniques in a controlled, interactive environment. The presentation covers the development of frontend interfaces and backend logic used to simulate defensive responses to various attack vectors, making complex security frameworks accessible to those just starting their journey in the field.

\n\nSpeakers:Annie Meaney,Anne Drago
\n
\nSpeakerBio:  Annie Meaney
\nNo BIO available
\nSpeakerBio:  Anne Drago
\nNo BIO available
\n\n\'',NULL,1297032),('3_Saturday','12','11:45','12:45','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Gamifying the Matrix: a MITRE ATT&CK Video Game\'','\'Annie Meaney,Anne Drago\'','Creator Talks_3986a308d48101005b228917d1fafbd5','\'\'',NULL,1297033),('3_Saturday','13','13:00','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Getting Started in OT/ICS Cybersecurity\'','\'Mike Holcomb\'','Creator Talks_15a1f1c536289b29392bf36313542b7a','\'Title: Getting Started in OT/ICS Cybersecurity
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Industrial Control Systems (ICS) and Operational Technology (OT) run the world around us. Power plants, offshore oil rigs, trains, and other transportation systems, manufacturing plants – these are just a few examples of the critical infrastructure that society depends on. Each ICS/OT environment is unique and has specialized security requirements.

\n\n

Protecting critical infrastructure becomes increasingly important each day as the frequency of cyberattacks and the number of attackers continue to grow. State adversaries are no longer the only ones targeting these specialized environments. Today’s attackers include ransomware groups, hacktivists, cyber mercenaries, and more.

\n\n

ICS/OT cybersecurity can seem complicated and even daunting at first, but it does not have to be. This session will help participants understand the fundamentals of how these environments operate and how to secure them with a practical, simple approach.

\n\nSpeakerBio:  Mike Holcomb
\nNo BIO available
\n\n\'',NULL,1297034),('3_Saturday','13','13:00','14:50','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'redStack: Boot-to-Breach Red Team Platform\'','\'Michael Ortiz\'','Creator Workshops_cb65b6f72d42e7e0f6f4cb5852b30619','\'Title: redStack: Boot-to-Breach Red Team Platform
\nTags: Noob Community | Creator Workshop
\nWhen: Saturday, Aug 8, 13:00 - 14:50 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

This 2-hour, hands-on training is built around redStack - the open-source AWS project Mike developed to stand up a red team environment on demand. One Terraform command deploys an entire operator stack: three C2 frameworks (Mythic, Sliver, and Havoc), Kali and Windows hosts, a redirector, and a Guacamole portal.

\n\nSpeakerBio:  Michael Ortiz
\n

Michael Ortiz is a Red Team Engineer and SME on the U.S. Department of State\'s Red Cell, running adversary emulation across State enterprise and partner networks. His focus spans offensive tradecraft, evasion engineering against modern EDR\'s, and the cybersecurity engineering behind durable red team infrastructure. He\'s the founder of devZero Security, an SDVOSB offering offensive security and security engineering services to federal and commercial clients, and the developer of redStack, an open source AWS and Terraform project that stands up a full red team operations stack on demand. A Marine Corps veteran, Mike holds OSEP, OSCP, CRTO, and CRTL, among other certifications.

\n\n\n\'',NULL,1297035),('3_Saturday','14','13:00','14:50','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'redStack: Boot-to-Breach Red Team Platform\'','\'Michael Ortiz\'','Creator Workshops_cb65b6f72d42e7e0f6f4cb5852b30619','\'\'',NULL,1297036),('3_Saturday','14','14:15','14:45','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Privilege Escalation: Building a Cyber Career with Zero Support\'','\'Akanksha Raghvesh\'','Creator Talks_080f9bdb9fcaa4efb8fd2fdd4018aeea','\'Title: Privilege Escalation: Building a Cyber Career with Zero Support
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:15 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Elevator Pitch\nI moved across the world to start a master’s in cybersecurity with little technical knowledge and no local network. I did not just find a career; I engineered one from scratch. Today, I hold a Master\'s degree, multiple certifications, and advisory board seats at two distinct organizations. I started as a student who had to build her own village. My talk is a \"noob-to-leader\" blueprint for anyone starting at ground zero. I will show you how to cut through industry noise, take your first big initiative, and turn a lack of guidance into your greatest leadership strength.

\n\n

Description\nMost people say that to succeed in cyber, you need a long list of certifications and years of coursework. But what do you do when you are starting with a blank slate and no one is there to guide you?

\n\n

When I began my journey as an international student, I had no contacts, no prior experience, and no roadmap. I had to learn how to distinguish the \"signal\" of real opportunities from the overwhelming \"noise\" of opinions and entry-level gatekeeping.

\n\n

I took ownership of my path. I jumped into hackathons, volunteered for professional organizations, and eventually became an advisor helping veterans translate their military service into civilian cyber careers. I discovered that leadership was the ultimate technical growth: guiding others forced me to master complex concepts deeper and faster than any individual study could. By supporting others in the field, I was not just building a network; I was validating and sharpening my own technical expertise. In addition to my corporate role, I serve on the advisory boards for a university serving veterans and the nation\'s first Microsoft Certified high school.

\n\n

In this 30-minute session, I am sharing the \"Bootstrap Protocol\" I used to move from the classroom to the boardroom. We will cover:

\n\n
    \n
  • The Initialization Phase: How to use hackathons and student organizations as your personal technical laboratory.
  • \n
  • The Mentor Mindset: How helping veterans transition to civilian roles forced me to master the cybersecurity field faster.
  • \n
  • Building the Infrastructure: A step by step guide on founding a chapter when you feel like you are standing alone.
  • \n
  • Service as a Shortcut: Why advising boards and helping others is the fastest way to build your own technical authority.
  • \n
\n\n

This is a practical, zero-fluff roadmap for the self-guided learner. If you feel like you are walking this path alone, come learn how to build the village you have been looking for.

\n\n

Key Takeaways

\n\n
    \n
  • Stop Waiting for Permission: Why starting your own group or initiative is the best credential a newcomer can have.

  • \n
  • Mission-First Leadership: Insights into how helping others accelerates your own professional and technical growth.

  • \n
  • Filter the Noise: How to choose the right initiatives that actually lead to a seat at the advisory table.

  • \n
  • The Roadmap Blueprint: A curated handout for attendees featuring active opportunities and platforms where beginners can start building their technical and leadership track record today.

  • \n
\n\nSpeakerBio:  Akanksha Raghvesh
\nNo BIO available
\n\n\'',NULL,1297037),('3_Saturday','15','15:00','16:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'AI Hacking for Noobs\'','\'Jason \"jhaddix\" Haddix,Arcanum Information Security Team\'','Creator Workshops_b10c5f5691b5225107cdc842f2ed3cca','\'Title: AI Hacking for Noobs
\nTags: Noob Community | Creator Workshop
\nWhen: Saturday, Aug 8, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

AI went from a tech toy to critical enterprise infrastructure practically overnight, and the security world is scrambling to keep up. This hands-on session completely bypasses the complex academic math to show you exactly how attackers target, exploit, and manipulate AI systems in the real world. Led by Jason Haddix and the Arcanum team, this workshop is a crash course in AI security basics. You\'ll get your hands dirty with prompt injection, break open AI systems, and dive into LLM shenanigans to understand firsthand how the modern AI attack surface is exploited.

\n\nSpeakers:Jason \"jhaddix\" Haddix,Arcanum Information Security Team
\n
\nSpeakerBio:  Jason \"jhaddix\" Haddix, CEO and \"Hacker in Charge\" at Arcanum Information Security
\n

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

\n\n

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.

\n\nSpeakerBio:  Arcanum Information Security Team
\nNo BIO available
\n\n\'',NULL,1297038),('3_Saturday','16','15:00','16:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'AI Hacking for Noobs\'','\'Jason \"jhaddix\" Haddix,Arcanum Information Security Team\'','Creator Workshops_b10c5f5691b5225107cdc842f2ed3cca','\'\'',NULL,1297039),('3_Saturday','15','15:00','15:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Six Impossible Things Before Breakfast: Common Misconceptions About Being a CTI Analyst\'','\'Brett Tolbert,DELETE_ME Brett Tolbert\'','Creator Talks_ab865f0cb0d034a3dc666272d6445ae6','\'Title: Six Impossible Things Before Breakfast: Common Misconceptions About Being a CTI Analyst
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

\"Why, sometimes I\'ve believed as many as six impossible things before breakfast.\" So said the White Queen to Alice — and so says the cybersecurity community about what it means to work in cyber threat intelligence.

\n\n

The cyber threat intelligence (CTI) domain is rich with acronyms, niche frameworks, specialized tools, and diverse practitioners — and for newcomers, whether they are making a career change or just starting, that richness can feel more like a labyrinth than an invitation. From engaging with novice analysts at industry conferences and through diversity and inclusion programs like Cyversity, to teaching at the undergraduate level, I\'ve found that a consistent set of misconceptions keeps talented, curious people from ever walking through the door. And that\'s a problem, because CTI needs those people.

\n\n

This presentation will guide attendees down the rabbit hole and into the CTI domain, starting with a primer on intelligence history and the intelligence lifecycle before tackling six of the most persistent myths head-on: that you need deep technical expertise to succeed; that CTI only exists in government; that the job is just monitoring feeds and social media; that you\'ll spend your career writing endless reports; that success requires mastering thousands of tools; and that automation will eventually make analysts obsolete. Each misconception will be examined, dismantled, and replaced with a clearer picture of what the work actually looks like — and why diverse, non-traditional backgrounds don\'t just belong in CTI, they make it stronger.

\n\n

Attendees will leave with a grounded understanding of the CTI domain, a realistic sense of what the role demands, and concrete first steps for getting involved — whether they\'re a seasoned professional exploring a pivot or a complete newcomer who just learned what \"CTI\" stands for five minutes ago.

\n\n

(outline below)

\n\n

Title Slide [< 1 min]\nPresentation Disclaimers [< 1 min]\nAgenda [< 1 min]\nSpeaker Introduction [2 min]

\n\n

Down the Rabbit Hole: Cyber Threat Intelligence Primer [4 mins]\n Foundations of the cyber threat intelligence domain \n Intelligence history and lifecycle

\n\n

The White Rabbit: You Will Not Succeed without a Technical Background [6 mins]\n Non-technical skills, such as written and verbal communication, are equally important.\n Problem-solving and pattern recognition are key to collaborating with other technical teams. Still, you do not need the same skills as members of those teams, i.e. detection engineering or malware reverse engineering. \n Continuous learning for upskilling

\n\n

We\'re All Mad Here: CTI is Only Used in the Government [6 mins]\n Most private enterprises also embed cyber threat intelligence teams\' practices within their cybersecurity operations department.\n Use cases: fraud and payments intelligence in financial services; tracking threat actors\' abuse of consumer-facing services and platforms in the technology sector; monitoring disruptive threat activity in critical infrastructure businesses \n Cross-industry sharing and collaboration

\n\n

Tweedledee and Tweedledum: You\'re Just Monitoring Threat Feeds and Social Media [6-8 mins]\n CTI is a multi-faceted field and involves more than \"eyes-on-glass\" monitoring. Examples of other areas of focus:\n Campaign analysis\n Operational research and correlation of threat actor behaviors with other cybersecurity teams\n Threat infrastructure hunting and pivoting\n Threat communication and influencing

\n\n

The Mad Hatter\'s Tea Party: Endless Report Writing [6 mins]\n Stakeholder communication preferences usually dictate threat intelligence output\n Some stakeholders may prefer visual communications (presentations, one-pagers, system dashboards) over written reports.\n Other stakeholders may prefer brief tactical updates via Teams/Slack or notes added to a SOAR platform.

\n\n

The Queen of Hearts\' Rules: Your Success Hinges on Knowing Thousands of Tools [6 mins]\n Tools will come and go, but methodology and critical thinking are more important\n Prioritize understanding how to perform analysis, leverage intelligence frameworks, influence stakeholders, and collaborate with others over learning an individual tool.

\n\n

Humpty Dumpty was Confidently Wrong: CTI Can be Fully Automated [8 mins]\n Automation plays a pivotal role but cannot outright replace analysts who support the domain.\n Scripts can help eliminate mundane tasks.\n Applying CTI adequately anchors on qualitative assessments and knowledge of an enterprise\'s security posture\n Applications of AI in CTI\n AI could help welcome more diverse CTI practitioners by breaking down barriers to entry due to the required technical skill set.

\n\n

Summary [5 mins]\n Getting started today

\n\n

Q&A [Remaining Time]

\n\nSpeakers:Brett Tolbert,DELETE_ME Brett Tolbert
\n
\nSpeakerBio:  Brett Tolbert, Principal Cyber Threat Intelligence Analyst / Undergraduate Adjunct Professor at Bowie State University
\n

Brett Tolbert is a Principal Cyber Threat Intelligence Analyst and an undergraduate adjunct professor at Bowie State University. With over 11 years of experience in cybersecurity, they have held threat intelligence and cyber defense roles in the U.S. intelligence community and in companies supporting U.S. critical infrastructure, focusing on tracking Asia-nexus state-sponsored threat actors, threat intelligence engineering, cross-sector partnerships, and technical leadership. They have previously spoken at SANS CTI Summit, MITRE ATT&CKcon, and the BIC Village at DEFCON. Brett lives in the DC-Baltimore corridor and enjoys playing monster hunter games, knitting, and baking in their spare time.

\n\nSpeakerBio:  DELETE_ME Brett Tolbert
\nNo BIO available
\n\n\'',NULL,1297040),('3_Saturday','16','16:15','16:45','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Imposter Syndrome Is Distracting You From the Work That Matters\'','\'Samantha Schwartz\'','Creator Talks_f791dac980029fd289a4e36defbf5cb9','\'Title: Imposter Syndrome Is Distracting You From the Work That Matters
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:15 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Cybersecurity has an imposter syndrome problem, and it isn’t just personal — it’s structural. The field is so wide that no single human can cover it, which means even five-year practitioners feel behind. New entrants interpret that feeling as evidence they don’t belong, and the field loses exactly the people it needs most: the pattern-recognizers, the communicators, the artists, the networkers, the non-stereotypical thinkers.\nThis 30-minute talk reframes imposter syndrome as a misread of a real signal. It makes the case that cybersecurity is the defining fight of this era — and argues that now, when AI is shifting the terrain and some people are throwing in the towel thinking they’re already behind, is exactly when we need warriors who understand that every generation has faced unfamiliar ground. We shouldn’t deny ourselves a tradition of fighting simply because the landscape has changed. The next generation of warriors won’t look like the picture in your head — and they need to be you.\nThe talk moves through three acts. First, it names the lie of “being behind” — the field is too big for any one human, and feeling inadequate is evidence you’re perceiving its size correctly, not a verdict on you. Second, it makes the stakes concrete: hospitals diverting ambulances during ransomware events, ICAC task forces doing digital forensics on devices seized from predators, dissidents whose phones are compromised by state actors. The technical failure and the human failure are the same event seen from opposite ends of the same wire. Third, it widens the door: DFIR, GRC, threat intelligence, security awareness, policy, AppSec partnership — the field has roles for thinkers who don’t fit the hoodie-in-a-basement stereotype, and it needs them urgently.\nIf you’re sitting in N00b Village wondering whether you belong here, this talk is for you. The voice telling you everyone else belongs more is wrong about you, and it’s wrong about the field. Stay.

\n\nSpeakerBio:  Samantha Schwartz
\nNo BIO available
\n\n\'',NULL,1297041),('4_Sunday','10','10:00','10:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Break Things, Learn Things: Hands-On Hacking for Beginners (same as Saturday)\'','\'Evolve Security Academy\'','Creator Workshops_a6c3bacd55418802913170f46d076b35','\'Title: Break Things, Learn Things: Hands-On Hacking for Beginners (same as Saturday)
\nTags: Noob Community | Creator Workshop
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Same session as Saturday. You don\'t need years of experience to start thinking like an attacker—you just need the right environment and someone to show you the ropes. In this hands-on session, Evolve Security Academy completely bypasses the theory to walk you through the fundamentals of ethical hacking in a live, browser-accessible lab environment. You\'ll adopt an attacker mindset, perform real reconnaissance, run vulnerability scans, and assess live exploits firsthand. Best of all, all registered participants get 7 days of extended access to the CyberLab platform to keep hacking at their own pace after DEF CON.

\n\nSpeakerBio:  Evolve Security Academy
\nNo BIO available
\n\n\'',NULL,1297042),('4_Sunday','10','10:30','11:30','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills\'','\'Amanda Kollmorgan\'','Creator Talks_84fcda8cb869234ab1f7cffdbab88038','\'Title: Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\nSession Description: Technical skills might open doors in IT & Cybersecurity, but leadership, communication, and mentorship sustain growth and impact. As the field becomes more complex and critical, we must rethink how we build and lead teams. This talk highlights the soft skills that turn strong technicians into effective collaborators, trusted advisors, and emerging leaders: from coaching junior analysts to translating between the SOC and the C-suite.
\nTakeaways: Attendees will learn practical ways to foster teambuilding, conflict resolution, psychological safety, build mentorship pipelines, and communicate with clarity under pressure.
\nTarget audiences: Everyone
\n\n\n\nSpeakerBio:  Amanda Kollmorgan
\nNo BIO available
\n\n\'',NULL,1297043),('4_Sunday','11','10:30','11:30','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills\'','\'Amanda Kollmorgan\'','Creator Talks_84fcda8cb869234ab1f7cffdbab88038','\'\'',NULL,1297044),('4_Sunday','11','11:00','12:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'From Command Line to Center Stage: Hack Your Way to Confident Speaking\'','\'James McQuiggan\'','Creator Workshops_3c6a2d4053ce9eca691c09cb35d2c9de','\'Title: From Command Line to Center Stage: Hack Your Way to Confident Speaking
\nTags: Noob Community | Creator Workshop
\nWhen: Sunday, Aug 9, 11:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Led by a seasoned security speaker with over 600 presentations under their belt and training from world-class Toastmasters, this interactive session completely bypasses the fluff to focus entirely on real-world delivery. This workshop is your chance to turn stage fright into stage might, equipping you with the tools to present with poise, project authority, and own the room.

\n\nSpeakerBio:  James McQuiggan
\nNo BIO available
\n\n\'',NULL,1297045),('4_Sunday','12','11:00','12:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'From Command Line to Center Stage: Hack Your Way to Confident Speaking\'','\'James McQuiggan\'','Creator Workshops_3c6a2d4053ce9eca691c09cb35d2c9de','\'\'',NULL,1297046),('4_Sunday','11','11:45','12:15','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'So You Want to Be a Red Teamer? The Reality Behind the Role\'','\'Billy Giles\'','Creator Talks_8c4f0f2c87183d3f15d38d932dc870cf','\'Title: So You Want to Be a Red Teamer? The Reality Behind the Role
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:45 - 12:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

If you spend enough time online, you might think red teaming is all zero-days, custom malware, and elite operators silently dismantling networks while dramatic music plays in the background.

\n\n

The reality is very different.

\n\n

Modern red team operations are less about “cool hacks” and more about planning, communication, and helping organizations improve their defenses. In many cases, the most important skills have nothing to do with hacking at all.

\n\n

This talk is designed for newcomers interested in offensive security who want an honest look at what red teamers actually do, how engagements are planned, what skills matter most, and how to begin building a realistic path into the field.

\n\n

We’ll break down the differences between penetration testing and red/purple teaming, discuss common misconceptions about offensive security careers, and explore a real-world red team engagement from planning through debrief.

\n\n

If you’ve ever wondered what red teamers really do, this session is for you.

\n\nSpeakerBio:  Billy Giles
\n

Billy Giles is an Offensive Security leader and practitioner who specializes in red/purple teaming and network penetration testing. With a deep passion for understanding adversary behaviors, he helps organizations across a multitude of industries assess their security postures, identify and remediate vulnerabilities, and build stronger defenses by thinking like an attacker.

\n\n

Billy is also the creator of Thinking Offensively. Through this project he examines offensive security strategy topics to help cybersecurity leaders anticipate threats and inform decision making, while also providing tools, playbooks, and techniques that red teams can apply directly to their work. His mission is to bridge strategy and execution to help organizations think offensively and stay ahead of evolving threats.

\n\n\n\'',NULL,1297047),('4_Sunday','12','11:45','12:15','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'So You Want to Be a Red Teamer? The Reality Behind the Role\'','\'Billy Giles\'','Creator Talks_8c4f0f2c87183d3f15d38d932dc870cf','\'\'',NULL,1297048),('4_Sunday','12','12:30','12:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Be your own Agent: Career Journey and Advice from IT and STEM Educator to Cybersecurity Engineer\'','\'Meghan Jacquot\'','Creator Talks_302d34d3a63d9d8edeb0056977f2ac94','\'Title: Be your own Agent: Career Journey and Advice from IT and STEM Educator to Cybersecurity Engineer
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

A career journey may have many twists and turns - mine certainly has! This talk will explore some themes from my pivot to cybersecurity and my journey through threat intelligence, a offensive security startup, and a Federally Funded Research and Development Center (FFRDC). We\'ll explore ways to advocate for yourself, suggestions for pivots and early career choices, and wrap it all up with thoughts on what can be next. Parts of the talk will be interactive and questions are encouraged.

\n\n

So, what do you want to be and how can agency and being your own agent help you in your career journey?

\n\nSpeakerBio:  Meghan Jacquot
\nNo BIO available
\n\n\'',NULL,1297049),('4_Sunday','13','13:05','15:55','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Noob Community - Conference Closing\'','\'\'','Creator Talks_5e812ce240ebdd959a8d94b38a9d09fb','\'Title: Noob Community - Conference Closing
\nTags: Noob Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 13:05 - 15:55 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n\n\n\'',NULL,1297050),('4_Sunday','14','13:05','15:55','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Noob Community - Conference Closing\'','\'\'','Creator Talks_5e812ce240ebdd959a8d94b38a9d09fb','\'\'',NULL,1297051),('4_Sunday','15','13:05','15:55','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Noob Community - Conference Closing\'','\'\'','Creator Talks_5e812ce240ebdd959a8d94b38a9d09fb','\'\'',NULL,1297052),('3_Saturday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_69bb318f4cfb849db7789e1994f1333b','\'Title: Arcanum Security Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Arcanum Security delivers modern cybersecurity through cutting-edge training and consulting, led by Jason Haddix and crew, spanning offensive security, bug bounty hunting, and AI security. Stop by during village hours to work through their hands-on labs.

\n\n\'',NULL,1297053),('3_Saturday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_69bb318f4cfb849db7789e1994f1333b','\'\'',NULL,1297054),('3_Saturday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_69bb318f4cfb849db7789e1994f1333b','\'\'',NULL,1297055),('3_Saturday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_69bb318f4cfb849db7789e1994f1333b','\'\'',NULL,1297056),('3_Saturday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_69bb318f4cfb849db7789e1994f1333b','\'\'',NULL,1297057),('3_Saturday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_69bb318f4cfb849db7789e1994f1333b','\'\'',NULL,1297058),('3_Saturday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_69bb318f4cfb849db7789e1994f1333b','\'\'',NULL,1297059),('3_Saturday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_69bb318f4cfb849db7789e1994f1333b','\'\'',NULL,1297060),('2_Friday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_5aa1c1014902ed3e2a9f7baf144f5a6b','\'Title: Arcanum Security Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Arcanum Security delivers modern cybersecurity through cutting-edge training and consulting, led by Jason Haddix and crew, spanning offensive security, bug bounty hunting, and AI security. Stop by during village hours to work through their hands-on labs.

\n\n\'',NULL,1297061),('2_Friday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_5aa1c1014902ed3e2a9f7baf144f5a6b','\'\'',NULL,1297062),('2_Friday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_5aa1c1014902ed3e2a9f7baf144f5a6b','\'\'',NULL,1297063),('2_Friday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_5aa1c1014902ed3e2a9f7baf144f5a6b','\'\'',NULL,1297064),('2_Friday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_5aa1c1014902ed3e2a9f7baf144f5a6b','\'\'',NULL,1297065),('2_Friday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_5aa1c1014902ed3e2a9f7baf144f5a6b','\'\'',NULL,1297066),('2_Friday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_5aa1c1014902ed3e2a9f7baf144f5a6b','\'\'',NULL,1297067),('2_Friday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_5aa1c1014902ed3e2a9f7baf144f5a6b','\'\'',NULL,1297068),('4_Sunday','10','10:00','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_7f4387736387b31641e8a0c62cd1c543','\'Title: Arcanum Security Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Arcanum Security delivers modern cybersecurity through cutting-edge training and consulting, led by Jason Haddix and crew, spanning offensive security, bug bounty hunting, and AI security. Stop by during village hours to work through their hands-on labs.

\n\n\'',NULL,1297069),('4_Sunday','11','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_7f4387736387b31641e8a0c62cd1c543','\'\'',NULL,1297070),('4_Sunday','12','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_7f4387736387b31641e8a0c62cd1c543','\'\'',NULL,1297071),('4_Sunday','13','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Arcanum Security Labs\'','\'\'','Creator Events_7f4387736387b31641e8a0c62cd1c543','\'\'',NULL,1297072),('2_Friday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_713a7a252b534d54e7ac14c87e84b6f5','\'Title: Hack The Box DC Junior Ranger Program Challenge
\nTags: Noob Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\nHack The Box brings its Junior Ranger Program to DEF CON: a beginner-friendly challenge guide built by the Hack The Box team specifically for the Noob Village, modeled after the U.S. National Park Service\'s Junior Ranger booklets. Work through the challenges in the guide and earn custom Junior Ranger badges as you complete them. Hack The Box is the leading cyber readiness platform for the agentic era, battle-testing and upskilling both humans and AI agents to enhance organizational cyber resilience.
\n\n\n\n\'',NULL,1297073),('2_Friday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_713a7a252b534d54e7ac14c87e84b6f5','\'\'',NULL,1297074),('2_Friday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_713a7a252b534d54e7ac14c87e84b6f5','\'\'',NULL,1297075),('2_Friday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_713a7a252b534d54e7ac14c87e84b6f5','\'\'',NULL,1297076),('2_Friday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_713a7a252b534d54e7ac14c87e84b6f5','\'\'',NULL,1297077),('2_Friday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_713a7a252b534d54e7ac14c87e84b6f5','\'\'',NULL,1297078),('2_Friday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_713a7a252b534d54e7ac14c87e84b6f5','\'\'',NULL,1297079),('2_Friday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_713a7a252b534d54e7ac14c87e84b6f5','\'\'',NULL,1297080),('3_Saturday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_c2308f3597fe9aed7eed08b0d9158330','\'Title: Hack The Box DC Junior Ranger Program Challenge
\nTags: Noob Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\nHack The Box brings its Junior Ranger Program to DEF CON: a beginner-friendly challenge guide built by the Hack The Box team specifically for the Noob Village, modeled after the U.S. National Park Service\'s Junior Ranger booklets. Work through the challenges in the guide and earn custom Junior Ranger badges as you complete them. Hack The Box is the leading cyber readiness platform for the agentic era, battle-testing and upskilling both humans and AI agents to enhance organizational cyber resilience.
\n\n\n\n\'',NULL,1297081),('3_Saturday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_c2308f3597fe9aed7eed08b0d9158330','\'\'',NULL,1297082),('3_Saturday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_c2308f3597fe9aed7eed08b0d9158330','\'\'',NULL,1297083),('3_Saturday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_c2308f3597fe9aed7eed08b0d9158330','\'\'',NULL,1297084),('3_Saturday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_c2308f3597fe9aed7eed08b0d9158330','\'\'',NULL,1297085),('3_Saturday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_c2308f3597fe9aed7eed08b0d9158330','\'\'',NULL,1297086),('3_Saturday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_c2308f3597fe9aed7eed08b0d9158330','\'\'',NULL,1297087),('3_Saturday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_c2308f3597fe9aed7eed08b0d9158330','\'\'',NULL,1297088),('4_Sunday','10','10:00','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_17467fdb89fd11a99ed3b4e7ac1fe3ad','\'Title: Hack The Box DC Junior Ranger Program Challenge
\nTags: Noob Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\nHack The Box brings its Junior Ranger Program to DEF CON: a beginner-friendly challenge guide built by the Hack The Box team specifically for the Noob Village, modeled after the U.S. National Park Service\'s Junior Ranger booklets. Work through the challenges in the guide and earn custom Junior Ranger badges as you complete them. Hack The Box is the leading cyber readiness platform for the agentic era, battle-testing and upskilling both humans and AI agents to enhance organizational cyber resilience.
\n\n\n\n\'',NULL,1297089),('4_Sunday','11','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_17467fdb89fd11a99ed3b4e7ac1fe3ad','\'\'',NULL,1297090),('4_Sunday','12','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_17467fdb89fd11a99ed3b4e7ac1fe3ad','\'\'',NULL,1297091),('4_Sunday','13','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Hack The Box DC Junior Ranger Program Challenge\'','\'\'','Creator Events_17467fdb89fd11a99ed3b4e7ac1fe3ad','\'\'',NULL,1297092),('3_Saturday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_15251231277273d285c7468a4c42e460','\'Title: Kryptsec Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Kryptsec started as a Discord server for people who wanted to learn cybersecurity together and has grown into a company focused on making security training engaging rather than monotonous, including hands-on, AI-assisted CTF labs and OASIS, its open-source tool for benchmarking AI agent vulnerabilities. Stop by the Kryptsec Labs table during village hours to work through their hands-on challenges.

\n\n\'',NULL,1297093),('3_Saturday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_15251231277273d285c7468a4c42e460','\'\'',NULL,1297094),('3_Saturday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_15251231277273d285c7468a4c42e460','\'\'',NULL,1297095),('3_Saturday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_15251231277273d285c7468a4c42e460','\'\'',NULL,1297096),('3_Saturday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_15251231277273d285c7468a4c42e460','\'\'',NULL,1297097),('3_Saturday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_15251231277273d285c7468a4c42e460','\'\'',NULL,1297098),('3_Saturday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_15251231277273d285c7468a4c42e460','\'\'',NULL,1297099),('3_Saturday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_15251231277273d285c7468a4c42e460','\'\'',NULL,1297100),('2_Friday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_7b79c8507bfb6249ca460e27afab1f1d','\'Title: Kryptsec Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Kryptsec started as a Discord server for people who wanted to learn cybersecurity together and has grown into a company focused on making security training engaging rather than monotonous, including hands-on, AI-assisted CTF labs and OASIS, its open-source tool for benchmarking AI agent vulnerabilities. Stop by the Kryptsec Labs table during village hours to work through their hands-on challenges.

\n\n\'',NULL,1297101),('2_Friday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_7b79c8507bfb6249ca460e27afab1f1d','\'\'',NULL,1297102),('2_Friday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_7b79c8507bfb6249ca460e27afab1f1d','\'\'',NULL,1297103),('2_Friday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_7b79c8507bfb6249ca460e27afab1f1d','\'\'',NULL,1297104),('2_Friday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_7b79c8507bfb6249ca460e27afab1f1d','\'\'',NULL,1297105),('2_Friday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_7b79c8507bfb6249ca460e27afab1f1d','\'\'',NULL,1297106),('2_Friday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_7b79c8507bfb6249ca460e27afab1f1d','\'\'',NULL,1297107),('2_Friday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_7b79c8507bfb6249ca460e27afab1f1d','\'\'',NULL,1297108),('4_Sunday','10','10:00','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_1df7c5565cd6b1d7d0e64ce297b74a61','\'Title: Kryptsec Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Kryptsec started as a Discord server for people who wanted to learn cybersecurity together and has grown into a company focused on making security training engaging rather than monotonous, including hands-on, AI-assisted CTF labs and OASIS, its open-source tool for benchmarking AI agent vulnerabilities. Stop by the Kryptsec Labs table during village hours to work through their hands-on challenges.

\n\n\'',NULL,1297109),('4_Sunday','11','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_1df7c5565cd6b1d7d0e64ce297b74a61','\'\'',NULL,1297110),('4_Sunday','12','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_1df7c5565cd6b1d7d0e64ce297b74a61','\'\'',NULL,1297111),('4_Sunday','13','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Kryptsec Labs\'','\'\'','Creator Events_1df7c5565cd6b1d7d0e64ce297b74a61','\'\'',NULL,1297112),('4_Sunday','10','10:00','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_fd255ac589b5cce43c71af6d4c34662d','\'Title: Mentoring and Career Advice
\nTags: Noob Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Informal, one-on-one conversations with volunteer mentors and speakers about breaking into cybersecurity, career pivots, resumes, certifications, and next steps. No appointment needed — just come find a mentor in the village during open hours.

\n\n\'',NULL,1297113),('4_Sunday','11','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_fd255ac589b5cce43c71af6d4c34662d','\'\'',NULL,1297114),('4_Sunday','12','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_fd255ac589b5cce43c71af6d4c34662d','\'\'',NULL,1297115),('4_Sunday','13','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_fd255ac589b5cce43c71af6d4c34662d','\'\'',NULL,1297116),('2_Friday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_6506c0f4da063b8b22cf34b8f2f59f1a','\'Title: Mentoring and Career Advice
\nTags: Noob Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Informal, one-on-one conversations with volunteer mentors and speakers about breaking into cybersecurity, career pivots, resumes, certifications, and next steps. No appointment needed — just come find a mentor in the village during open hours.

\n\n\'',NULL,1297117),('2_Friday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_6506c0f4da063b8b22cf34b8f2f59f1a','\'\'',NULL,1297118),('2_Friday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_6506c0f4da063b8b22cf34b8f2f59f1a','\'\'',NULL,1297119),('2_Friday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_6506c0f4da063b8b22cf34b8f2f59f1a','\'\'',NULL,1297120),('2_Friday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_6506c0f4da063b8b22cf34b8f2f59f1a','\'\'',NULL,1297121),('2_Friday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_6506c0f4da063b8b22cf34b8f2f59f1a','\'\'',NULL,1297122),('2_Friday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_6506c0f4da063b8b22cf34b8f2f59f1a','\'\'',NULL,1297123),('2_Friday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_6506c0f4da063b8b22cf34b8f2f59f1a','\'\'',NULL,1297124),('3_Saturday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_a8ebccd5fabe0fee04d3bb2d509eaccc','\'Title: Mentoring and Career Advice
\nTags: Noob Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Informal, one-on-one conversations with volunteer mentors and speakers about breaking into cybersecurity, career pivots, resumes, certifications, and next steps. No appointment needed — just come find a mentor in the village during open hours.

\n\n\'',NULL,1297125),('3_Saturday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_a8ebccd5fabe0fee04d3bb2d509eaccc','\'\'',NULL,1297126),('3_Saturday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_a8ebccd5fabe0fee04d3bb2d509eaccc','\'\'',NULL,1297127),('3_Saturday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_a8ebccd5fabe0fee04d3bb2d509eaccc','\'\'',NULL,1297128),('3_Saturday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_a8ebccd5fabe0fee04d3bb2d509eaccc','\'\'',NULL,1297129),('3_Saturday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_a8ebccd5fabe0fee04d3bb2d509eaccc','\'\'',NULL,1297130),('3_Saturday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_a8ebccd5fabe0fee04d3bb2d509eaccc','\'\'',NULL,1297131),('3_Saturday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Mentoring and Career Advice\'','\'\'','Creator Events_a8ebccd5fabe0fee04d3bb2d509eaccc','\'\'',NULL,1297132),('2_Friday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_0fff8222bf2cd88b70379c0fb42d9628','\'Title: No Stupid Questions
\nTags: Noob Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Ongoing AMA booth with volunteers and speakers answering all your DEF CON and cyber questions

\n\n\'',NULL,1297133),('2_Friday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_0fff8222bf2cd88b70379c0fb42d9628','\'\'',NULL,1297134),('2_Friday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_0fff8222bf2cd88b70379c0fb42d9628','\'\'',NULL,1297135),('2_Friday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_0fff8222bf2cd88b70379c0fb42d9628','\'\'',NULL,1297136),('2_Friday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_0fff8222bf2cd88b70379c0fb42d9628','\'\'',NULL,1297137),('2_Friday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_0fff8222bf2cd88b70379c0fb42d9628','\'\'',NULL,1297138),('2_Friday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_0fff8222bf2cd88b70379c0fb42d9628','\'\'',NULL,1297139),('2_Friday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_0fff8222bf2cd88b70379c0fb42d9628','\'\'',NULL,1297140),('3_Saturday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_59abfaf47a6c41fcd5a7a2b1fe67af2b','\'Title: No Stupid Questions
\nTags: Noob Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Ongoing AMA booth with volunteers and speakers answering all your DEF CON and cyber questions

\n\n\'',NULL,1297141),('3_Saturday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_59abfaf47a6c41fcd5a7a2b1fe67af2b','\'\'',NULL,1297142),('3_Saturday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_59abfaf47a6c41fcd5a7a2b1fe67af2b','\'\'',NULL,1297143),('3_Saturday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_59abfaf47a6c41fcd5a7a2b1fe67af2b','\'\'',NULL,1297144),('3_Saturday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_59abfaf47a6c41fcd5a7a2b1fe67af2b','\'\'',NULL,1297145),('3_Saturday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_59abfaf47a6c41fcd5a7a2b1fe67af2b','\'\'',NULL,1297146),('3_Saturday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_59abfaf47a6c41fcd5a7a2b1fe67af2b','\'\'',NULL,1297147),('3_Saturday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_59abfaf47a6c41fcd5a7a2b1fe67af2b','\'\'',NULL,1297148),('4_Sunday','10','10:00','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_4fa79d799588f1ee5361e9457629fa84','\'Title: No Stupid Questions
\nTags: Noob Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

Ongoing AMA booth with volunteers and speakers answering all your DEF CON and cyber questions

\n\n\'',NULL,1297149),('4_Sunday','11','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_4fa79d799588f1ee5361e9457629fa84','\'\'',NULL,1297150),('4_Sunday','12','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_4fa79d799588f1ee5361e9457629fa84','\'\'',NULL,1297151),('4_Sunday','13','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'No Stupid Questions\'','\'\'','Creator Events_4fa79d799588f1ee5361e9457629fa84','\'\'',NULL,1297152),('2_Friday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_a1be26c661ee6e3fd6d99505d3f5e5af','\'Title: SANS Institute NetWars Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

SANS NetWars is a suite of advanced cyber ranges offering interactive, hands-on learning exercises created by SANS faculty in realistic network environments, gamifying cybersecurity training through compelling storylines and real-world challenges. Drop in during village hours to work through NetWars challenges at your own pace.

\n\n\'',NULL,1297153),('2_Friday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_a1be26c661ee6e3fd6d99505d3f5e5af','\'\'',NULL,1297154),('2_Friday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_a1be26c661ee6e3fd6d99505d3f5e5af','\'\'',NULL,1297155),('2_Friday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_a1be26c661ee6e3fd6d99505d3f5e5af','\'\'',NULL,1297156),('2_Friday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_a1be26c661ee6e3fd6d99505d3f5e5af','\'\'',NULL,1297157),('2_Friday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_a1be26c661ee6e3fd6d99505d3f5e5af','\'\'',NULL,1297158),('2_Friday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_a1be26c661ee6e3fd6d99505d3f5e5af','\'\'',NULL,1297159),('2_Friday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_a1be26c661ee6e3fd6d99505d3f5e5af','\'\'',NULL,1297160),('3_Saturday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_06e3535b1257f75588b4e5c13bd10cc4','\'Title: SANS Institute NetWars Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

SANS NetWars is a suite of advanced cyber ranges offering interactive, hands-on learning exercises created by SANS faculty in realistic network environments, gamifying cybersecurity training through compelling storylines and real-world challenges. Drop in during village hours to work through NetWars challenges at your own pace.

\n\n\'',NULL,1297161),('3_Saturday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_06e3535b1257f75588b4e5c13bd10cc4','\'\'',NULL,1297162),('3_Saturday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_06e3535b1257f75588b4e5c13bd10cc4','\'\'',NULL,1297163),('3_Saturday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_06e3535b1257f75588b4e5c13bd10cc4','\'\'',NULL,1297164),('3_Saturday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_06e3535b1257f75588b4e5c13bd10cc4','\'\'',NULL,1297165),('3_Saturday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_06e3535b1257f75588b4e5c13bd10cc4','\'\'',NULL,1297166),('3_Saturday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_06e3535b1257f75588b4e5c13bd10cc4','\'\'',NULL,1297167),('3_Saturday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_06e3535b1257f75588b4e5c13bd10cc4','\'\'',NULL,1297168),('4_Sunday','10','10:00','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_311b4d89396a628db09faec416542df7','\'Title: SANS Institute NetWars Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

SANS NetWars is a suite of advanced cyber ranges offering interactive, hands-on learning exercises created by SANS faculty in realistic network environments, gamifying cybersecurity training through compelling storylines and real-world challenges. Drop in during village hours to work through NetWars challenges at your own pace.

\n\n\'',NULL,1297169),('4_Sunday','11','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_311b4d89396a628db09faec416542df7','\'\'',NULL,1297170),('4_Sunday','12','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_311b4d89396a628db09faec416542df7','\'\'',NULL,1297171),('4_Sunday','13','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'SANS Institute NetWars Labs\'','\'\'','Creator Events_311b4d89396a628db09faec416542df7','\'\'',NULL,1297172),('2_Friday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_356feed92e7e9b7e26d76a0716cf324e','\'Title: Skillbit Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

SkillBit Labs is a continuous learning platform designed to help assess and develop cybersecurity skills through hands-on, bite-sized labs. Drop in during village hours and work through beginner-friendly challenges at your own pace, brought to you by SkillBit (formerly MetaCTF), led by CEO Roman Bohuk.

\n\n\'',NULL,1297173),('2_Friday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_356feed92e7e9b7e26d76a0716cf324e','\'\'',NULL,1297174),('2_Friday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_356feed92e7e9b7e26d76a0716cf324e','\'\'',NULL,1297175),('2_Friday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_356feed92e7e9b7e26d76a0716cf324e','\'\'',NULL,1297176),('2_Friday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_356feed92e7e9b7e26d76a0716cf324e','\'\'',NULL,1297177),('2_Friday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_356feed92e7e9b7e26d76a0716cf324e','\'\'',NULL,1297178),('2_Friday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_356feed92e7e9b7e26d76a0716cf324e','\'\'',NULL,1297179),('2_Friday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_356feed92e7e9b7e26d76a0716cf324e','\'\'',NULL,1297180),('4_Sunday','10','10:00','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_83a1eceb2804f616d98585bc2ff9e392','\'Title: Skillbit Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

SkillBit Labs is a continuous learning platform designed to help assess and develop cybersecurity skills through hands-on, bite-sized labs. Drop in during village hours and work through beginner-friendly challenges at your own pace, brought to you by SkillBit (formerly MetaCTF), led by CEO Roman Bohuk.

\n\n\'',NULL,1297181),('4_Sunday','11','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_83a1eceb2804f616d98585bc2ff9e392','\'\'',NULL,1297182),('4_Sunday','12','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_83a1eceb2804f616d98585bc2ff9e392','\'\'',NULL,1297183),('4_Sunday','13','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_83a1eceb2804f616d98585bc2ff9e392','\'\'',NULL,1297184),('3_Saturday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_9e0e2b71bcdb12bc69cbea238f334aad','\'Title: Skillbit Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

SkillBit Labs is a continuous learning platform designed to help assess and develop cybersecurity skills through hands-on, bite-sized labs. Drop in during village hours and work through beginner-friendly challenges at your own pace, brought to you by SkillBit (formerly MetaCTF), led by CEO Roman Bohuk.

\n\n\'',NULL,1297185),('3_Saturday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_9e0e2b71bcdb12bc69cbea238f334aad','\'\'',NULL,1297186),('3_Saturday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_9e0e2b71bcdb12bc69cbea238f334aad','\'\'',NULL,1297187),('3_Saturday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_9e0e2b71bcdb12bc69cbea238f334aad','\'\'',NULL,1297188),('3_Saturday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_9e0e2b71bcdb12bc69cbea238f334aad','\'\'',NULL,1297189),('3_Saturday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_9e0e2b71bcdb12bc69cbea238f334aad','\'\'',NULL,1297190),('3_Saturday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_9e0e2b71bcdb12bc69cbea238f334aad','\'\'',NULL,1297191),('3_Saturday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'Skillbit Labs\'','\'\'','Creator Events_9e0e2b71bcdb12bc69cbea238f334aad','\'\'',NULL,1297192),('4_Sunday','10','10:00','13:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_02921d2db92258bd513c9ab1b47c0a30','\'Title: TCM Security Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

TCM Security offers 250+ hours of practical, hands-on cybersecurity training across 28 courses and 13 certifications, built by hackers and trusted by teams. Drop in during village hours to work through their hands-on labs.

\n\n\'',NULL,1297193),('4_Sunday','11','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_02921d2db92258bd513c9ab1b47c0a30','\'\'',NULL,1297194),('4_Sunday','12','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_02921d2db92258bd513c9ab1b47c0a30','\'\'',NULL,1297195),('4_Sunday','13','10:00','13:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_02921d2db92258bd513c9ab1b47c0a30','\'\'',NULL,1297196),('2_Friday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_a9768f6f15389ff27a3477a6c2aec022','\'Title: TCM Security Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

TCM Security offers 250+ hours of practical, hands-on cybersecurity training across 28 courses and 13 certifications, built by hackers and trusted by teams. Drop in during village hours to work through their hands-on labs.

\n\n\'',NULL,1297197),('2_Friday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_a9768f6f15389ff27a3477a6c2aec022','\'\'',NULL,1297198),('2_Friday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_a9768f6f15389ff27a3477a6c2aec022','\'\'',NULL,1297199),('2_Friday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_a9768f6f15389ff27a3477a6c2aec022','\'\'',NULL,1297200),('2_Friday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_a9768f6f15389ff27a3477a6c2aec022','\'\'',NULL,1297201),('2_Friday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_a9768f6f15389ff27a3477a6c2aec022','\'\'',NULL,1297202),('2_Friday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_a9768f6f15389ff27a3477a6c2aec022','\'\'',NULL,1297203),('2_Friday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_a9768f6f15389ff27a3477a6c2aec022','\'\'',NULL,1297204),('3_Saturday','10','10:00','17:59','N','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_911033681aa360b3cef6afb37e8d31ad','\'Title: TCM Security Labs
\nTags: Noob Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1417 (Noob Community) - Map
\n
\nDescription:
\n

TCM Security offers 250+ hours of practical, hands-on cybersecurity training across 28 courses and 13 certifications, built by hackers and trusted by teams. Drop in during village hours to work through their hands-on labs.

\n\n\'',NULL,1297205),('3_Saturday','11','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_911033681aa360b3cef6afb37e8d31ad','\'\'',NULL,1297206),('3_Saturday','12','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_911033681aa360b3cef6afb37e8d31ad','\'\'',NULL,1297207),('3_Saturday','13','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_911033681aa360b3cef6afb37e8d31ad','\'\'',NULL,1297208),('3_Saturday','14','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_911033681aa360b3cef6afb37e8d31ad','\'\'',NULL,1297209),('3_Saturday','15','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_911033681aa360b3cef6afb37e8d31ad','\'\'',NULL,1297210),('3_Saturday','16','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_911033681aa360b3cef6afb37e8d31ad','\'\'',NULL,1297211),('3_Saturday','17','10:00','17:59','Y','Noob Community','LVCCW Level 1 Hall 4 1417 (Noob Community)','\'TCM Security Labs\'','\'\'','Creator Events_911033681aa360b3cef6afb37e8d31ad','\'\'',NULL,1297212),('3_Saturday','10','10:30','10:45','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Payment Village Intro - What\'s Happening at the Village\'','\'\'','Creator Workshops_0ea638def391020ceaa395d9002b4305','\'Title: Payment Village Intro - What\'s Happening at the Village
\nTags: Payment Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:30 - 10:45 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

Join us to discover some of the highlights of the Payment Village at DEF CON

\n\n\'',NULL,1297213),('2_Friday','10','10:30','10:45','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Payment Village Intro - What\'s Happening at the Village\'','\'\'','Creator Workshops_7f2cc9ba279f80f3a20364b1860bd41c','\'Title: Payment Village Intro - What\'s Happening at the Village
\nTags: Payment Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:30 - 10:45 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

Join us to discover some of the highlights of the Payment Village at DEF CON

\n\n\'',NULL,1297214),('2_Friday','11','11:00','11:20','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'A Real-Time Battle with a Card-Testing Adversary\'','\'Levi Schuck\'','Creator Talks_4cf075a25ac6c0b1aec25216dc584394','\'Title: A Real-Time Battle with a Card-Testing Adversary
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:20 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

At 50x more authorizations per minute than typical and all for the same amount, alarms go off at issuing banks for a good reason. I\'ll share the story of how a card-testing adversary abused a misfeature that checked if a card is valid before vaulting it and how their strategies and my defenses evolved over a week long battle. I will share the techniques I used that ultimately distinguished legitimate customer traffic from automated abuse through residential proxies and creative scripts.

\n\nSpeakerBio:  Levi Schuck, Engineering Manager, Staff Engineer
\n

Took on ownership of security for an engineering org during a data breach, reducing security defects, improving performance and keeping the org PCI-compliant under QSA review. Also builds OAuth/OIDC tooling and is an active contributor in the passkeys ecosystem.

\n\n\n\'',NULL,1297215),('3_Saturday','11','11:30','11:50','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Introduction to Vulnerable ATM Badge\'','\'Vincent Sloan\'','Creator Workshops_6bf9c234804f2579890ab7bb5f329026','\'Title: Introduction to Vulnerable ATM Badge
\nTags: Payment Village | Creator Workshop
\nWhen: Saturday, Aug 8, 11:30 - 11:50 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

The Payment Village set out to design a badge that represents a purposefully vulnerable ATM for educational use. Providing conference attendees with access to a real ATM is impractical due to its size, weight, and limited accessibility. Instead, the badge offers a portable ATM-inspired platform, available to all, that simulates real-world attack surfaces through interactive challenges. We have five prototypes available to try!

\n\n

To extend its value beyond DEF CON, the badge will be supported by an online platform featuring learning resources, firmware updates, and community support via a website and Discord. We also have a life-size version of the badge as a fully interactive ATM demonstration for attendees to interact with in the village

\n\nSpeakerBio:  Vincent Sloan, Software Engineer, GoFundMe
\n

20+ years of experience in payments, spanning e-commerce and crowdfunding; currently leads payments engineering at GoFundMe.

\n\n\n\'',NULL,1297216),('2_Friday','11','11:30','11:50','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Introduction to Vulnerable ATM Badge\'','\'Vincent Sloan\'','Creator Workshops_af18cec27b8ce4be2dd333f2e3a8f717','\'Title: Introduction to Vulnerable ATM Badge
\nTags: Payment Village | Creator Workshop
\nWhen: Friday, Aug 7, 11:30 - 11:50 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

The Payment Village set out to design a badge that represents a purposefully vulnerable ATM for educational use. Providing conference attendees with access to a real ATM is impractical due to its size, weight, and limited accessibility. Instead, the badge offers a portable ATM-inspired platform, available to all, that simulates real-world attack surfaces through interactive challenges. We have five prototypes available to try!

\n\n

To extend its value beyond DEF CON, the badge will be supported by an online platform featuring learning resources, firmware updates, and community support via a website and Discord. We also have a life-size version of the badge as a fully interactive ATM demonstration for attendees to interact with in the village

\n\nSpeakerBio:  Vincent Sloan, Software Engineer, GoFundMe
\n

20+ years of experience in payments, spanning e-commerce and crowdfunding; currently leads payments engineering at GoFundMe.

\n\n\n\'',NULL,1297217),('2_Friday','12','12:00','12:45','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Skimmers, Shimmers, and You\'','\'Aidan Quimby\'','Creator Talks_646bc269d623d1b547014466668643ee','\'Title: Skimmers, Shimmers, and You
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

Join me as I present my latest research on fraudulent payment devices such as card skimmers and shimmers, building on insights from close collaboration with major retailers, law enforcement, and the United States Secret Service! I will outline the evolving landscape of payment threats and share findings from my hands-on reverse engineering of over 130 fraudulent devices, including ATM, fuel pump, and both point-of-sale skimmers and shimmers. Learn why reliably detecting skimmers is challenging and the latest tools and techniques used to both spot and conceal these malicious devices. Peek behind the curtain of payment security with me to explore how cards are cloned and contactless payments relayed from across the world. You’ll learn how skimmers disproportionally affect U.S. citizens on government benefits and ways to best protect yourself in the ever-changing landscape of digital payments!

\n\nSpeakerBio:  Aidan Quimby, Senior Consultant, Coalfire DivisionHex
\n

Specializes in web app pentesting, payment-skimmer forensics and hardware hacking; previously led hardware testing at IBM X-Force Red and has presented skimmer research to major retailers and at Hardwear.io.

\n\n\n\'',NULL,1297218),('2_Friday','13','13:00','13:20','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Wall of Wallets Workshop (Intro to Wall of Wallets Challenge)\'','\'Dan Borgogno\'','Creator Workshops_7ec01d88b9273c163970b07f7df987dc','\'Title: Wall of Wallets Workshop (Intro to Wall of Wallets Challenge)
\nTags: Payment Village | Creator Workshop
\nWhen: Friday, Aug 7, 13:00 - 13:20 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\nWall of Wallets is a hands-on CTF challenge where the goal is simple: collect as many mock payment card details as you can from other participants. Using intentionally vulnerable services in a safe, isolated environment, you\'ll learn how common implementation mistakes expose sensitive data. Compete to top the Wall of Wallets leaderboard while discovering the real-world techniques attackers use and, importantly, how to defend against them.
\n\n\n\nSpeakerBio:  Dan Borgogno, Security Researcher at Faraday
\n

Dan Borgogno is a security researcher, backend developer, security engineer and international speaker with years of experience on mobile, hardware, IoT and web application hacking.

\n\n\n\'',NULL,1297219); INSERT INTO `events` VALUES ('4_Sunday','10','10:30','10:50','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Wall of Wallets Workshop (Intro to Wall of Wallets Challenge)\'','\'Dan Borgogno\'','Creator Workshops_37c3e35a38798051b3dfd3a27f128cb5','\'Title: Wall of Wallets Workshop (Intro to Wall of Wallets Challenge)
\nTags: Payment Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:30 - 10:50 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\nWall of Wallets is a hands-on CTF challenge where the goal is simple: collect as many mock payment card details as you can from other participants. Using intentionally vulnerable services in a safe, isolated environment, you\'ll learn how common implementation mistakes expose sensitive data. Compete to top the Wall of Wallets leaderboard while discovering the real-world techniques attackers use and, importantly, how to defend against them.
\n\n\n\nSpeakerBio:  Dan Borgogno, Security Researcher at Faraday
\n

Dan Borgogno is a security researcher, backend developer, security engineer and international speaker with years of experience on mobile, hardware, IoT and web application hacking.

\n\n\n\'',NULL,1297220),('2_Friday','14','14:00','14:45','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'How to Epically Fail Your PCI Assessment\'','\'Kevin Buck\'','Creator Talks_f32ffaad3d76bf7ddcf0f2395d6e3c86','\'Title: How to Epically Fail Your PCI Assessment
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

If your company accepts, processes, stores, transmits, dreams about, or accidentally leaves cardholder data on a sticky note, congratulations - you get the privilege of dealing with PCI DSS. For organizations processing enough transactions, the reward for your success is an on-site assessment conducted by a Qualified Security Assessor (QSA). Think of it as inviting a well-dressed, highly trained auditor to examine every corner of your security program and ask uncomfortable questions about decisions made by people who left the company three years ago.

\n\n

In an ideal world, your controls are well-documented, operating effectively and everyone knows exactly where the evidence is stored. In the real world, someone discovers during the assessment that the quarterly review hasn\'t happened since the last presidential administration, nobody can explain a firewall rule labeled \"DO NOT TOUCH\" and a frantic war room appears overnight.

\n\n

This session explores the most common (and a few impressively creative) ways organizations derail their PCI assessments. We\'ll cover how to avoid discovering critical compliance gaps in front of your QSA, why \"we thought someone else was doing that\" is not a valid control and how to prevent your assessment from turning into a high-stakes race against the reporting deadline.

\n\n

Come learn how not to fail your PCI assessment spectacularly... preferably before your next assessment cycle.

\n\nSpeakerBio:  Kevin Buck, PCI GRC Manager, NBCUniversal
\n

40+ years in technology across roles from system programmer to CTO; involved in PCI compliance since 2005 as both a Level 1 merchant and a Qualified Security Assessor (QSA).

\n\n\n\'',NULL,1297221),('2_Friday','16','16:00','16:45','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Breaking BIOS in ATMs\'','\'Arnold Jared Morales Yepez\'','Creator Talks_39315e10d591a8a04d90440d90d9889b','\'Title: Breaking BIOS in ATMs
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

The analysis begins at Ring -3, advancing toward the positive rings. Starting from the on-screen user

\n\n

perspective imposes too many limitations. The shift in approach was deliberate: rather than assuming a

\n\n

conventional attack vector such as connecting an external device or performing a kiosk-level bypass the

\n\n

decision was made to start from the deepest layers of the system. This compromise is detected for the

\n\n

following reason:

\n\n
    \n
  • DMA protection exists at the BIOS level.
  • \n
\n\n

The goal of this compromise is to activate PCI/PCIe through BIOS in order to perform a DMA

\n\n

This section will be referred to as \"BIOS Unprotection.\"

\n\n

How was this achieved?

\n\n

Two methods were identified:

\n\n

A bridge was found that triggers a BIOS configuration reset.

\n\n

BIOS duplication with encryption validation bypass (enables both Downgrade and Upgrade).

\n\n

DMA or complete chain will not be shown since it is a delicate topic but BIOS research will be deepened

\n\n

since it does not only apply to ATMs.

\n\nSpeakerBio:  Arnold Jared Morales Yepez, Senior Team Lead, Grupo Salinas
\n

Self-taught in computer security since age 12; holds a degree in Computer Forensics and Cybersecurity and is pursuing a Master\'s in AI and Cybersecurity.

\n\n

--

\n\n

Desde los 12 años, me he dedicado a la informática con un enfoque especial en la seguridad. Actualmente, a mis 22 años, sigo explorando este mundo con la misma pasión, impulsado por la constante evolución de la tecnología y su interminable curva de aprendizaje.

\n\n

Cuento con una carrera en Cómputo Forense y Ciberseguridad, actualmente curso una maestría en Inteligencia Artificial y Ciberseguridad.

\n\n

Certificaciones: CWEE | CAPE |CPTS | EWPTX | CRTO | eMAPT | OSCP | OSCP+ |CEH V13 | EJPT| HTB prolabs Hades - Cybernetics - Zephyr - APTlabs | MDK

\n\n\n\'',NULL,1297222),('3_Saturday','11','11:00','11:20','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Victim as a Service: Engaging with Trust-Based Scams Using AI\'','\'Ariana Mirian\'','Creator Talks_8f26d71227261ed5351ae6e518b159d7','\'Title: Victim as a Service: Engaging with Trust-Based Scams Using AI
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:20 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

Pig butchering and other interactive online scams build trust over weeks to months, making them both highly effective and extremely difficult to study. In this talk, I will describe how we measure ground truth on this difficult and growing ecosystem.

\n\n

First, I’ll describe the design of an LLM-driven system that can sustain realistic, long-term engagement with scammers for weeks to months, enabling large-scale investigation of their tactics in the wild. I will discuss how we attract scam attempts, maintain thousands of convincing dialogues over time, and navigate the \"milestones\" scammers use to advance victims toward payment. I\'ll end with what this approach uncovered about scammer workflows (such as the “cross-platform” jump the majority of them use) and how this measurement drives understanding of the pig-butchering ecosystem to power data-driven scam defenses in the payments ecosystem.

\n\nSpeakerBio:  Ariana Mirian, Security Researcher, BeeSafe AI
\n

Security researcher focused on empirical measurement; currently drives data-driven methods to catch trust-based scams at BeeSafe AI, after leading measurement research at Censys. PhD in Computer Science and Engineering, UC San Diego.

\n\n\n\'',NULL,1297223),('3_Saturday','12','12:00','12:59','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Breaking PBKDF - Adversarial Cryptanalysis and Techniques for Hunting Cryptographic Flaws\'','\'Ken Pyle\'','Creator Talks_a9885535e97876bd75583193d4b4a12a','\'Title: Breaking PBKDF - Adversarial Cryptanalysis and Techniques for Hunting Cryptographic Flaws
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

Using decades-old OpenJDK PBKDF flaws, forgotten RFCs, hash collisions, and a few semantic edge cases, we’ll compromise multiple cryptographic systems with little more than a handful of carefully chosen values and several “useless” tools.

\n\n

This talk explores how implementation bugs, legacy compatibility, and architectural assumptions can undermine otherwise sound cryptography—and why the real attack surface is often everything around the algorithm.

\n\nSpeakerBio:  Ken Pyle, Security Researcher, Bank of America
\n

Cybersecurity researcher, exploit developer and conference speaker focused on vulnerability discovery, reverse engineering and adversarial cryptanalysis; has presented at DEF CON, ShmooCon and RSA Conference.

\n\n\n\'',NULL,1297224),('3_Saturday','14','14:00','14:20','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'BNPL\'s Blind Spot: Exploiting Business Logic Flaws in Buy Now Pay Later APIs\'','\'Furkan Fatih Demir\'','Creator Talks_1ce231fb34e3eb2d4e337e7a7c26e9a2','\'Title: BNPL\'s Blind Spot: Exploiting Business Logic Flaws in Buy Now Pay Later APIs
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:20 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

Buy Now Pay Later has grown from a niche convenience to a $560 billion global ecosystem used by approximately 380 million people. Klarna, Afterpay, Affirm, and PayPal Pay Later process billions in transactions annually — and every transaction flows through a series of REST API calls. Security research on BNPL has focused entirely on fraud: account takeover, synthetic identity, first-party fraud. No one has looked at the API layer. This talk does.

\n\n

We systematically test the BNPL payment flow — session creation, authorization, order management, and capture — using public sandbox environments. Our methodology focuses on business logic flaws: scenarios where the API functions exactly as designed but can be abused in ways developers never anticipated.

\n\n

Confirmed finding: Klarna\'s capture endpoint accepts any captured_amount value down to 1 cent ($0.01) on a fully authorized order, with no minimum validation. A $100 authorized order can be captured for $0.01 — returning HTTP 201 Created with Klarna-Order-Validation: Valid. In vulnerable merchant implementations, customers receive goods while only $0.01 is collected — a $99.99 financial loss per transaction.

\n\n

Attendees will leave with a practical attack methodology for BNPL integrations, an open-source reference implementation (vulnerable + patched), and a merchant-side security checklist.

\n\nSpeakerBio:  Furkan Fatih Demir, Independent Security Researcher & Penetration Tester, Barikat Cybersecurity
\n

Conducts authorized security assessments across financial services, aviation, public sector and education, focused on business-logic vulnerabilities that evade conventional tooling.

\n\n\n\'',NULL,1297225),('3_Saturday','14','14:30','15:15','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Deepfake Detection Through Adversarial Research\'','\'Efim Boieru\'','Creator Talks_0e7339b61a3f2759a8f7b37ab13949eb','\'Title: Deepfake Detection Through Adversarial Research
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 15:15 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

Deepfake defense is no longer just a matter of classifying media as real or fake. As attackers adopt new generators, optimize them for specific targets, and automate feedback-driven attack loops, the threat is evolving into agentic fraud. This talk presents an adversarial research approach to defending live identity-verification systems: continuously simulating realistic attacks, generating and evaluating domain-specific synthetic media, turning detector failures into new evaluation data, monitoring emerging tools, and rapidly adapting to unseen generators without overfitting to the latest attack. Ultimately, effective defense requires treating deepfake detection not as a static model-building task, but as a continuously evolving adversarial process in which success is measured by resilience against the next attack, not performance on the last one. We\'ll extend these concepts in the village through a hands-on challenge, inviting participants to evaluate a blind synthetic-data discrimination task, which illustrates the practical challenges of evaluating increasingly capable adversarials.

\n\nSpeakerBio:  Efim Boieru, Senior Manager of ML Engineering, Incode Technologies
\n

10+ years in applied AI, computer vision and biometric security, focused on face liveness and deepfake detection; previously in ML research/engineering roles at Huawei and Bosch.

\n\n\n\'',NULL,1297226),('3_Saturday','15','14:30','15:15','Y','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Deepfake Detection Through Adversarial Research\'','\'Efim Boieru\'','Creator Talks_0e7339b61a3f2759a8f7b37ab13949eb','\'\'',NULL,1297227),('2_Friday','15','15:00','15:45','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Deepfake Detection Through Adversarial Research\'','\'Efim Boieru\'','Creator Talks_29eb9f693e6de645015d47a3996dccb5','\'Title: Deepfake Detection Through Adversarial Research
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

Deepfake defense is no longer just a matter of classifying media as real or fake. As attackers adopt new generators, optimize them for specific targets, and automate feedback-driven attack loops, the threat is evolving into agentic fraud. This talk presents an adversarial research approach to defending live identity-verification systems: continuously simulating realistic attacks, generating and evaluating domain-specific synthetic media, turning detector failures into new evaluation data, monitoring emerging tools, and rapidly adapting to unseen generators without overfitting to the latest attack. Ultimately, effective defense requires treating deepfake detection not as a static model-building task, but as a continuously evolving adversarial process in which success is measured by resilience against the next attack, not performance on the last one. We\'ll extend these concepts in the village through a hands-on challenge, inviting participants to evaluate a blind synthetic-data discrimination task, which illustrates the practical challenges of evaluating increasingly capable adversarials.

\n\nSpeakerBio:  Efim Boieru, Senior Manager of ML Engineering, Incode Technologies
\n

10+ years in applied AI, computer vision and biometric security, focused on face liveness and deepfake detection; previously in ML research/engineering roles at Huawei and Bosch.

\n\n\n\'',NULL,1297228),('3_Saturday','16','16:00','16:45','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'Compounding Interest: Exploiting the ATM Supply Chain\'','\'Matt Burch\'','Creator Talks_d0fe65b79dc4fdfa0c44e388aa772c86','\'Title: Compounding Interest: Exploiting the ATM Supply Chain
\nTags: Payment Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

ATMs are the ultimate high-stakes target, often holding upwards of $400,000 in a single enclosure. While the global financial industry relies on a narrow pool of manufacturers, the software supply chain securing these \"vaults\" remains an under-examined attack surface. Following my disclosure of 6 code execution vulnerabilities affecting Diebold Nixdorf at DEF CON 32, this research dives deeper into the foundational security layer: CryptWare CryptoPro Secure Disk for BitLocker.

\n\n

CryptoPro acts as a proprietary security wrapper, adding pre-boot authorization, custom TPM protections, and an obfuscated encryption layer to the standard BitLocker architecture. In this session, I will highlight the nuances of the CryptoPro architecture, including, secret storage through unallocated disk space, TPM sealing logic, and the layered crypto architecture used to secure system secrets. I will demonstrate how these deficiencies provide a path for code execution and full compromise of the Windows BitLocker encryption keys.

\n\n

In addition to the technical walk through, I will release ragavan, a custom exploitation toolkit designed to automate secret extraction, decryption, TPM unsealing, and compromise of a CryptoPro-protected platform.

\n\nSpeakerBio:  Matt Burch, Principal Security Researcher at Atredis Partners
\n

Matt Burch is a Principal Security Researcher at Atredis Partners with 20 years of experience breaking things that aren\'t supposed to break. From the embedded components of ATM platforms to complex SCADA/OT environments, Matt specializes in identifying critical flaws in hardened, enterprise-class systems. He is best known for his research into ATM disk encryption and Mobile Device Management (MDM) security, some of which has been highlighted in Wired Magazine and presented at DEF CON 32.

\n\n

Matt is a reverse engineer and tool developer who has authored and contributed to various public projects. His career spans roles as an offensive security lead, expert witness, and technical advisor. Matt’s current research is a deep-dive into the ATM software supply chain, specifically targeting the subversion of TPM-backed roots of trust and the analysis of custom cryptographic primitives.

\n\n\n\'',NULL,1297229),('4_Sunday','12','12:00','12:15','N','Payment Village','LVCCW Level 2 W204-205 (Payment Village)','\'CAPTURE THE COIN - Announcement of the CTF Winners\'','\'\'','Creator Talks_80b4758575eb5de42062cb74efbcd1af','\'Title: CAPTURE THE COIN - Announcement of the CTF Winners
\nTags: Payment Village | $$$$$__$$$$$ | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:15 PDT
\nWhere: LVCCW Level 2 W204-205 (Payment Village) - Map
\n
\nDescription:
\n

Join us as we announce the winners of the Contest!

\n\n\'',NULL,1297230),('2_Friday','10','10:00','10:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'La Villa - Opening Ceremony (ESP)\'','\'\'','Creator Talks_3262ba052c55647c4e31bafc88de2e7d','\'Title: La Villa - Opening Ceremony (ESP)
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n\n\n\'',NULL,1297231),('2_Friday','10','10:30','11:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Bootkits Forever: Emulando APTs Modernos desde UEFI hasta el Kernel\'','\'Alejandro Vázquez Vázquez\'','Creator Talks_7d3899deabdf7f5ee4d4e6e93ba4b57f','\'Title: Bootkits Forever: Emulando APTs Modernos desde UEFI hasta el Kernel
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Los bootkits UEFI continúan siendo una de las capacidades más avanzadas utilizadas por grupos APT modernos. Su capacidad para ejecutar código antes del sistema operativo, obtener persistencia a largo plazo y operar por debajo de muchas soluciones de seguridad los convierte en una herramienta extremadamente valiosa tanto para atacantes como para equipos de Red Team que buscan emular amenazas reales.

\n\n

En esta sesión mostraremos cómo utilizar un bootkit UEFI para reproducir cadenas completas de ataque observadas en operaciones reales. Analizaremos el recorrido desde el firmware hasta el kernel de Windows, incluyendo persistencia y despliegue de componentes adicionales de ransomware en el kernel.

\n\n

La charla incluirá una demostración en directo en la que un sistema Windows moderno será comprometido mediante un bootkit UEFI, mostrando paso a paso cómo este tipo de implantes se instalan y permiten reproducir capacidades observadas en operaciones reales de grupos APT. Además, se compartirán los recursos y proyectos utilizados durante la investigación para que otros equipos de seguridad puedan reproducir los escenarios presentados en sus operaciones diarias.

\n\nSpeakerBio:  Alejandro Vázquez Vázquez, Independent Security Researcher
\n

Alejandro Vázquez Vázquez es un especialista en técnicas de seguridad ofensiva de bajo nivel, con foco en Red Teaming, Windows Internals y UEFI. A lo largo de su trayectoria ha participado en operaciones de Red Team y emulación de adversarios, además de desarrollar capacidades ofensivas orientadas al estudio y reproducción de técnicas utilizadas por grupos APT modernos. Su trabajo diario se orienta a la creación, análisis y despliegue de implantes capaces de operar por debajo de los mecanismos de seguridad modernos, abarcando desde técnicas pre-boot hasta módulos en kernel y componentes de usuario para persistencia.

\n\n

Comparte su conocimiento siendo docente en diversos másteres de postgrado de universidades y entidades privadas, donde imparte formaciones en ingeniería inversa, análisis de malware, desarrollo de exploits y desarrollo de herramientas para evasión de soluciones antimalware, acercando la seguridad ofensiva a las nuevas generaciones de profesionales.

\n\n

Colabora con diversas comunidades centradas en áreas de low-level, como Off By One Security y grupos de DEF CON, conferencia en la que ha sido ponente principal presentando los proyectos Abyss (UEFI Bootkit) y Benthic (Windows Kernel Rootkit). A lo largo de su desarrollo profesional también ha participado en iniciativas de investigación y desarrollo relacionadas con firmware, metahoneypots, análisis de amenazas y plataformas destinadas al estudio de actores maliciosos.

\n\n\n\'',NULL,1297232),('2_Friday','11','10:30','11:30','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Bootkits Forever: Emulando APTs Modernos desde UEFI hasta el Kernel\'','\'Alejandro Vázquez Vázquez\'','Creator Talks_7d3899deabdf7f5ee4d4e6e93ba4b57f','\'\'',NULL,1297233),('2_Friday','10','10:30','12:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'De la nube a la corona: Uso indebido de la identidad híbrida en Azure DevOps Azure, AD, AWS y EKS\'','\'Juan Camilo Palacio Arango,Andrés Restrepo\'','Creator Workshops_48500be17873f5c72acf7a07ea5e607b','\'Title: De la nube a la corona: Uso indebido de la identidad híbrida en Azure DevOps Azure, AD, AWS y EKS
\nTags: La Villa Community | Creator Workshop
\nWhen: Friday, Aug 7, 10:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout - Map
\n
\nDescription:
\n

Demostrar cómo las relaciones de confianza entre entornos híbridos de Azure DevOps, Microsoft Azure, Active Directory, Amazon Web Services y Kubernetes pueden ser abusadas por un atacante para realizar movimientos laterales, escalamiento de privilegios y compromiso de identidades utilizando herramientas y funcionalidades legítimas de administración cloud en infraestructuras hibridas corporativas.

\n\nSpeakers:Juan Camilo Palacio Arango,Andrés Restrepo
\n
\nSpeakerBio:  Juan Camilo Palacio Arango, Un token, una confianza, una cadena de compromiso.
\n

Juan Camilo Palacio

\n\n

Suboficial retirado de la Fuerza Aérea Colombiana, con sólida formación en Ingeniería de Sistemas y un Máster en Ciberseguridad y Privacidad. A lo largo de los últimos 7 años, he perfeccionado y especializado mis habilidades en diversas áreas de la Ciberseguridad, Ciberdefensa y Ciberinteligencia, aplicando con éxito mis conocimientos en los sectores de defensa nacional y financiero.

\n\n

Mi compromiso con la actualización constante de técnicas se evidencia en la obtención de certificaciones destacadas en técnicas de ethical hacking y red teaming, tales como OSEP, OSCP, CRTO, ARTE, CRTE, entre otras. Estas certificaciones expresan mi dedicación continua a la mejora de mis habilidades y destacan mi capacidad para enfrentar desafíos complejos en el dinámico campo de la ciberseguridad.

\n\n

Andres Restrepo Gonzalez

\n\n

Profesional de ciberseguridad especializado en Red Team y seguridad ofensiva en entornos multicloud. Cuenta con certificaciones avanzadas en AWS, Azure y operaciones de Red Team, incluyendo OSCP, CRTE, CRTP, CARTS, CCPenX-AWS y MCRTA, entre otras. Su trabajo se enfoca en la simulación de adversarios, pentesting de infraestructuras cloud y evaluación de la resiliencia de organizaciones frente a amenazas avanzadas.

\n\nSpeakerBio:  Andrés Restrepo, Hacker
\n

Entusiasta de la seguridad con experiencia en actividades de RedTeam

\n\n\n\'',NULL,1297234),('2_Friday','11','10:30','12:59','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'De la nube a la corona: Uso indebido de la identidad híbrida en Azure DevOps Azure, AD, AWS y EKS\'','\'Juan Camilo Palacio Arango,Andrés Restrepo\'','Creator Workshops_48500be17873f5c72acf7a07ea5e607b','\'\'',NULL,1297235),('2_Friday','12','10:30','12:59','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'De la nube a la corona: Uso indebido de la identidad híbrida en Azure DevOps Azure, AD, AWS y EKS\'','\'Juan Camilo Palacio Arango,Andrés Restrepo\'','Creator Workshops_48500be17873f5c72acf7a07ea5e607b','\'\'',NULL,1297236),('2_Friday','11','11:30','12:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Demodus Operandi (Cómo tres rf-hacks en tres bandas terminaron siendo una metodología)\'','\'Eduardo Contreras\'','Creator Talks_c84fdedaf6b2e4065e5c1b7cdcad5311','\'Title: Demodus Operandi (Cómo tres rf-hacks en tres bandas terminaron siendo una metodología)
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Hay muchas herramientas para hackear RF y mucho conocimiento regado en talks, repos y la cabeza de la gente. Lo que no hay es un mapa. Cuando te paras frente a un dispositivo o señal, ¿por dónde empiezas? ¿y cómo sabes qué se te escapó?

\n\n

Esta charla cubre tres investigaciones reales, cada una en una tecnologia distinta.

\n\n

Primero BLE, sniffeando advertising packets terminé auditando una sala y encontré 6 de 85 dispositivos completamente controlables, incluso con LE Secure Connections habilitado.

\n\n

Después LoRaWAN, capturé 51,304 frames en US915. El 89.3% eran JoinRequests: una red entera fallando en unirse, visible sin transmitir un solo paquete, red que no podia encontrar con un SDR.

\n\n

Y al final LTE — encontrar la celda correcta en México, entender el OFDM, y extraer metadatos en pasivo.

\n\n

Tres casos, tres analisis distintos. Pero siempre sobre las mismas capas: espectro → señal → enlace → cripto → ataque.

\n\n

Ya seguía una metodología, solo no la había nombrado.

\n\n

Así nació RFSAM (Radio Frequency Security Assessment Methodology): una referencia abierta, estructurada, que organiza lo que OSSTMM, BSAM y la comunidad SDR ya construyeron, en algo que puedes navegar. No pretende inventar nada, pretende ser un mapa.

\n\n

https://electroniccats.github.io/RFSAM/

\n\nSpeakerBio:  Eduardo Contreras, CTO
\n

Electronics Engineer, passionate about technological development

\n\n

and science, co-founder and CTO of the Electronic Cats company which has developed different embedded systems already in production, focused from education to security related devices, embedded programer, has developed open source libraries for communities as well as open hardware, with the goal to design and implement global impact electronics.

\n\n\n\'',NULL,1297237),('2_Friday','12','11:30','12:30','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Demodus Operandi (Cómo tres rf-hacks en tres bandas terminaron siendo una metodología)\'','\'Eduardo Contreras\'','Creator Talks_c84fdedaf6b2e4065e5c1b7cdcad5311','\'\'',NULL,1297238),('2_Friday','12','12:30','12:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'O Lado Sombrio das Coisas: Transformando Dispositivos DIY em Vetores de Ataque\'','\'Christiane Borges Santos\'','Creator Talks_1125dcfa5499603c9e9f2d80a7716fc2','\'Title: O Lado Sombrio das Coisas: Transformando Dispositivos DIY em Vetores de Ataque
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

O objetivo principal desta palestra é demonstrar como a democratização do hardware e da filosofia Do It Yourself (DIY) aceleraram a prototipagem rápida, mas na pressa para ver o projeto \"funcionar\" muitas vezes ignoram os padrões mínimos de segurança.

\n\n

A idéia é provocar a audiência a adotar a filosofia \"Secure by Making\", integrando o hardening e a análise de superfícies de ataque desde a primeira solda e linha de código do protótipo.

\n\nSpeakerBio:  Christiane Borges Santos, Coordenadora do Eixo de Design Factory - Criar IFG
\n

Tecnóloga em Redes de Comunicação e Mestre em Engenharia Elétrica e da Computação. Fundadora do Grupo de Robótica para Meninas Metabotix e membro do Grupo de Robótica GYNBOT. Atualmente, professora no Instituto Federal de Goiás (IFG) campus Luziânia, Instrutora CISCO NetAcad e Coordenadora do Eixo de Design Factory do Criar Polo de Inovação do IFG.

\n\n\n\'',NULL,1297239),('2_Friday','13','13:00','13:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'AImaru C2: La Nueva Era del Living off the Land (MCP AI-Driven C2 )\'','\'Mario Lobo\'','Creator Talks_80a93d28e27b69846da952820577a541','\'Title: AImaru C2: La Nueva Era del Living off the Land (MCP AI-Driven C2 )
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

¿Qué sucede cuando la barrera técnica para ejecutar ataques Living off the Land (LotL) desaparece y una IA toma el control?

\n\n

Esta charla presenta AImaru C2, un framework ofensivo que expone el futuro del cibercrimen. Aimaru introduce varios conceptos nuevos para la industria como la utilización del Model Context Protocol (MCP) para transformar clientes inofensivos en Troyanos de Acceso Remoto (RATs). Estos agentes usan binarios nativos del sistema para operar de forma encubierta, orquestados íntegramente por un LLM sin restricciones mediante lenguaje natural.

\n\n

Demostraremos cómo AImaru automatiza el cyberkill chain: desde bypasses dinámicos de AMSI generados al vuelo, jerarquización de tareas para Lotl, hasta la explotación de un vectores inéditos intenando abusar de IDEs locales (como Claude Code o PyCharm) para ejecución silenciosa.

\n\n

Analizaremos cómo esto revolucionará el ecosistema RaaS/MaaS y los severos desafíos que enfrentarán los equipos de respuesta ante esta nueva generación de amenazas autónomas.

\n\nSpeakerBio:  Mario Lobo, Cyber Threat Intelligence Researcher
\n

I am a Colombian Cybersecurity Engineer with a Master’s degree and a deep passion for the field. I have spent over 18 years immersed in various domains of Information Security and Cyber Intelligence.

\n\n

My career has spanned critical sectors, including National Defense, where I spent nearly 10 years collaborating with Strategic Cyber Intelligence teams worldwide. I have led multiple cybersecurity teams for multinational banking institutions within the financial sector, and for several years now, I have served as the Lead Threat Intelligence Researcher at Lumu Technologies. I have been a main track speaker at prestigious international conferences such as Ekoparty, 8.8 Gob, BSides São Paulo, BSides Colombia, and Cyberwings, among others.

\n\n

Beyond the professional realm, I am a guitar enthusiast, a dedicated cyclist, and a consummate music lover.

\n\n

--

\n\n

Soy colombiano, Ingeniero Magister en Ciberseguridad y un apasionado por el tema. Llevo más de 18 años sumergido diferentes campos de la Seguridad de la Información y la Ciberinteligencia.

\n\n

Mi trayectoria me ha permitido transitar por sectores como la Defensa Nacional, donde por casi 10 años colaboré con equipos de Ciberinteligencia Estratégica alrededor del mundo. Lideré diferentes equipos de ciberseguridad para la banca multinacional en el sector Financiero y desde hace algunos años me desempeño como Lider Investigador de Inteligencia de Amenazas en Lumu Technologies. He participado como conferencista main track en eventos como Ekoparty, 8.8 Gob, Bsides Sao Paulo y Bsides Colombia, Cyberwings entre otros.

\n\n

Fuera del ámbito profesional, soy un amante de la guitarra, la bici y un melómano consumado.

\n\n\n\'',NULL,1297240),('2_Friday','14','14:00','15:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'PentestGPT: The Art of Hacking with Words\'','\'Matias Armándola\'','Creator Workshops_322fadffa9551fa4f8760b45bba94aca','\'Title: PentestGPT: The Art of Hacking with Words
\nTags: La Villa Community | Creator Workshop
\nWhen: Friday, Aug 7, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout - Map
\n
\nDescription:
\nPentestGPT: The Art of Hacking with Words regresa a DEF CON, esta vez como un workshop completamente práctico. Luego de presentar el año pasado cómo los LLMs comenzaban a transformar la seguridad ofensiva, esta nueva edición lleva la experiencia al siguiente nivel: no solo será escuchar de este proyecto, lo podrás crear y ejecutar en tu entorno favorito.
\n\n

Durante 100 minutos, los participantes trabajarán directamente con PentestGPT y PentestGPT 2.0 para aprender cómo integrar IA en flujos reales de pentesting. A través de ejercicios guiados y escenarios ofensivos realistas, explorarán reconocimiento asistido por IA, generación de attack paths, análisis de hallazgos, prompt engineering ofensivo y validación técnica de resultados.

\n\n

Más allá de usar una herramienta, el workshop propone un cambio de mentalidad: entender cómo pasar de ejecutar tareas manuales a orquestar inteligencia ofensiva.

\n\nSpeakerBio:  Matias Armándola, Cybersecurity Lead, Proffesor and Speaker
\n

I\'m Mati Armándola, an Information Security leader with over 20 years of experience in technology and more than a decade dedicated exclusively to asset protection, regulatory compliance, and organizational culture.

\n\n

I have led teams and projects in companies with regional reach and have participated as an international speaker at conferences such as Ekoparty, DevOpsDays, Nerdearla, and DEF CON, addressing topics such as offensive security, awareness, applied AI, and governance.

\n\n

In addition to my work as a teacher at various institutions and educational platforms, training the next generation of professionals in security, cloud computing, and leadership.

\n\n

My motto is LEAD – TEACH – PROTECT

\n\n\n\'',NULL,1297241),('2_Friday','15','14:00','15:59','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'PentestGPT: The Art of Hacking with Words\'','\'Matias Armándola\'','Creator Workshops_322fadffa9551fa4f8760b45bba94aca','\'\'',NULL,1297242),('2_Friday','14','14:00','14:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Point of Failure: Autopsia de una Terminal de Pago\'','\'Erik Alcantara\'','Creator Talks_05eb5443d3331167c8c9e3f6a003a1ec','\'Title: Point of Failure: Autopsia de una Terminal de Pago
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

TPVs como PAX y Mercado Pago corren Android, usan HTTP en producción y tienen un modo kiosco que dura lo que tarda en abrirse un APK. Esta charla es el journey de alguien que compró terminales, las rompió, y documenta lo que encontró.

\n\nSpeakerBio:  Erik Alcantara, I build the tools I can\'t afford.
\n

Erik Alcantara aka. Glitchboi, es pentester y red teamer con 6 años en seguridad y enfoque en la intersección entre hardware y ofensiva. Desde México, construye herramientas open source que van desde proxies de interceptación HTTP hasta PCBs personalizadas para investigación de seguridad.

\n\n

Ha presentado en BugCon y meetups locales de seguridad. Publica su research y proyectos en glitchboi.xyz y github.com/Glitchboi-sudo.

\n\n\n\'',NULL,1297243),('2_Friday','15','15:00','15:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'El regreso de Sedinho: situación actual y nuevas tácticas de los troyanos bancarios brasileños\'','\'Josep Albors\'','Creator Talks_1e119af33d6a78d68c5ad39bd8f29b72','\'Title: El regreso de Sedinho: situación actual y nuevas tácticas de los troyanos bancarios brasileños
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Esta investigación analiza la evolución reciente de los troyanos bancarios brasileños y su expansión internacional, así como las acciones de las autoridades para frenarlos. Se examinan campañas actuales impulsadas por ciberdelincuentes latinoamericanos que no solo perfeccionan el malware bancario tradicional, sino que también incorporan fraudes móviles basados en tecnología NFC.

\n\nSpeakerBio:  Josep Albors, Head of Awarenes & Research at Ontinet.com (ESET Spain)
\n

Josep Albors is the Head of Awareness & Research at Ontinet.com (ESET Spain). He\'s a security expert with more than 21 years working in cybersecurity and specialized in security awareness. He is also the editor at the company\'s blog and one of the experts writing at several other publications related with the IT security world in Spain.

\n\n

He has been a speaker at some of the most important security conferences in Spain, besides collaborating with initiatives such as X1RedMasSegura, that wants to raise awareness among users so they can use Internet and technology in a safe way. Included in Ontinet\'s social responsability, Josep also does awareness and cybersecurity presentations in schools and universities. He\'s also a teacher in cyber security expert courses at several Spanish Universities and participates in several conferences organized by several spanish universities and Spain\'s national Institute of Cyber Security. He also participated as speaker at AVAR conference in Osaka in 2019, Caro Workshop 2023 in Bochum (Germany), FIRST 2024 (Fukuoka), Virus Bulletin 2024 (Dublín), Defcon Malware Village (2025), JSAC 2025 (Tokyo) and CARO 2026 (Innsbruck).

\n\n

Josep has also collaborated with the Spanish Guardia Civil, Spanish National Police and the Spanish Army, teaching their units on how to fight cybercrime and with cyber intelligence training, contributing with his experience in analyzing cybercrime and malware.

\n\n\n\'',NULL,1297244),('2_Friday','15','15:30','15:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'State Desync as a Weapon: Breaking Transactional Integrity in Payment Systems (ESP)\'','\'Santiago Sepúlveda Veliz\'','Creator Talks_3e050652155abc63d81fb2025eb74ae8','\'Title: State Desync as a Weapon: Breaking Transactional Integrity in Payment Systems (ESP)
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

El Price Tampering no es un simple cambio de parámetro ni un bug, es una falla de arquitectura que permite alterar el valor de una transacción sin romper ningún control tradicional en cualquier sistema que procese pagos, provocando fraude en diferentes industrias y negocios. En esta charla abordaré cómo un atacante modela el flujo de compra y pago completo, identifica puntos de desincronización entre cliente, backend y pasarela, y explota la ausencia de invariantes de negocio server-side para manipular el valor final de una transacción sin necesidad de CVEs, exploits ni malware. Basado en una investigación propia con casos reales autorizados y anonimizados en entornos de banca, retail y fintech en LATAM, presentaré una taxonomía de tres patrones de ataque recurrentes y un modelo defensivo concreto llamado FinSecure, sustentado en el principio del backend soberano, donde el precio nunca puede nacer fuera del servidor. La audiencia se irá con una visión diferente del problema y herramientas accionables para detectarlo y eliminarlo por diseño.

\n\nSpeakerBio:  Santiago Sepúlveda Veliz, Pentester / Security Researcher - AppSec & Transactional Integrity
\n

Mi nombre es Santiago Sepúlveda Veliz, hoy en día me desempeño como Pentester y Security Researcher especializado en AppSec e integridad transaccional, con 3 años de experiencia profesional realizando evaluaciones de seguridad en aplicaciones web, móviles, APIs y entornos Active Directory para clientes enterprise en Latinoamérica. Actualmente me desempeño en TRUSTTECH Cybersecurity, enfocado en seguridad de plataformas de pago y lógica de negocio. Cuento con las certificaciones OSCP+ (Offensive Security) y CRTO (Zero-Point Security). Soy speaker aceptado en PyCon Latam 2026. He asistido a DEF CON 32 y 33, RootedCON Panamá, Ekoparty Argentina y el Congreso 8.8 Chile. Soy creador de contenido técnico de ciberseguridad en YouTube bajo el alias Y4nbow con más de 3.700 suscriptores.

\n\n\n\'',NULL,1297245),('2_Friday','16','16:00','16:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Jackpoting? Bypass de EDR? - Hacking ATM\'','\'Arnold Jared Morales Yepez\'','Creator Talks_7311e160818253c24fe0b73d7603d25e','\'Title: Jackpoting? Bypass de EDR? - Hacking ATM
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

En muchas ocasiones cómo pentesters nos aferramos a la idea de buscar multiples técnicas de ataque de manera “virtual”, buscando software especializado o creando scripts que nos ayuden a identificar una vulnerabilidad para acceder a un programa o dispositivo en el que nos enfoquemos, pasamos tanto tiempo enfrente de nuestra pantalla, lanzando comandos a lo bastardo hasta ver que podemos encontrar que a veces ignoramos que existen soluciones alternativas y no simplemente de manera virtual, sino de una manera en que podemos tocar, armar y desarmar (esto suele ser menos buscado por pentester, entonces tambien hay menos documentacion).

\n\n

El proceso de arranque de Windows, conocido como boot process, se divide en varias fases como ya lo vimos: PreBoot (inicialización del firmware BIOS/UEFI y POST), Boot Manager (carga de bootmgr o bootmgfw.efi), OS Loader (ejecución de winload.exe para cargar el kernel) y Kernel Initialization (carga de ntoskrnl.exe y hal.dll, inicialización de controladores y servicios). Finalmente, se inicia winlogon.exe para presentar la interfaz de usuario. Este proceso permite pasar de un estado apagado a un sistema operativo funcional mediante una secuencia jerárquica y verificada.

\n\n

Respecto a los EDR (Endpoint Detection and Response) basados en el kernel, operan en modo kernel, el nivel más privilegiado del sistema (algunos juegan en UEFI), lo que les permite supervisar actividades de bajo nivel como llamadas al sistema, manipulación de memoria, carga de controladores y acceso a archivos. Al ejecutarse en este modo, los EDR pueden detectar y bloquear amenazas avanzadas como rootkits o malware persistente que intentan eludir las protecciones del modo usuario. Su integración profunda con el kernel les permite realizar monitoreo en tiempo real, análisis de comportamiento y respuesta inmediata ante actividades sospechosas durante y después del arranque.

\n\n

Normalmente los EDRs se encuentran en KERNEL pero como lo mencione, existen otros que se encuentran en UEFI y si recordamos como funciona windows atrás de UEFI esta SMM entonces es algo un poco mas dicil.

\n\n

Esta charla es pensada para personas interesadas no solo en ATMs y una simple dispensación si no la vista mas alla, el análisis y toda la experiencia adquirida cuando te enfrentas a ellos.

\n\n

Mas información sobre el ataque y la teoría detrás de ella:

\n\n

https://h0km4.com/posts/DMA-Introduction/

\n\n

https://h0km4.com/posts/telemetria-bypass/

\n\nSpeakerBio:  Arnold Jared Morales Yepez, Senior Team Lead, Grupo Salinas
\n

Self-taught in computer security since age 12; holds a degree in Computer Forensics and Cybersecurity and is pursuing a Master\'s in AI and Cybersecurity.

\n\n

--

\n\n

Desde los 12 años, me he dedicado a la informática con un enfoque especial en la seguridad. Actualmente, a mis 22 años, sigo explorando este mundo con la misma pasión, impulsado por la constante evolución de la tecnología y su interminable curva de aprendizaje.

\n\n

Cuento con una carrera en Cómputo Forense y Ciberseguridad, actualmente curso una maestría en Inteligencia Artificial y Ciberseguridad.

\n\n

Certificaciones: CWEE | CAPE |CPTS | EWPTX | CRTO | eMAPT | OSCP | OSCP+ |CEH V13 | EJPT| HTB prolabs Hades - Cybernetics - Zephyr - APTlabs | MDK

\n\n\n\'',NULL,1297246),('2_Friday','17','17:00','17:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID\'','\'Elzer Pineda,Jose Rivas\'','Creator Talks_c72af9f550a5e685e3c13294a9f86d51','\'Title: Tokens and PRT: Advanced Attacks and Persistence in Microsoft Entra ID
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

¿Son el MFA y el Acceso Condicional una garantía de seguridad real? En esta sesión técnica, demostraremos cómo el compromiso de un endpoint permite a un atacante saltarse las barreras de identidad tradicionales en la nube. La charla se centra en la explotación de vulnerabilidades en Microsoft Entra ID, desglosando una cadena de ataque avanzada:

\n\n

Abuso de Device Code Flow: Explotación de flujos de autenticación para acceso inicial (Demo con Entraith).

\n\n

PowerShell Hijacking: Intercepción de procesos para la obtención de tokens de sesión (GrabTokenAzureAD).

\n\n

Extracción con Sliver BOF: Uso de Beacon Object Files para la exfiltración sigilosa de tokens y del Primary Refresh Token (PRT) directamente desde la memoria, evadiendo defensas anti-malware.

\n\n

Bypass de MFA e Intune: Hemos desarrollado herramientas personalizadas para extraer PRTs locales, eludir los controles de gestión de dispositivos de Intune y saltarse la aplicación de MFA a nivel de token.

\n\n

Todo este ciclo de vida de ataque ha sido consolidado en Entraith, un framework ofensivo desarrollado desde cero por nuestro equipo de investigación que será lanzado públicamente en DEF CON 34. Entraith permite ejecutar ataques de device code, renovación de tokens, inspección de correos/aplicaciones y generación de persistencia multi-vector desde una única interfaz

\n\nSpeakers:Elzer Pineda,Jose Rivas
\n
\nSpeakerBio:  Elzer Pineda, Pentester
\n

Regional Pentester and Cybersecurity Consultant, Elzer Pineda is an active member of the Red Team executing strategic consulting projects and advanced penetration testing engagements. His career has been focused on Threat Research for private and government organizations across the region. He is a Dojo Community Ambassador and Professor at the Universidad Tecnológica de Panamá (UTP). His experience has taken him to share technical research at Ekoparty, BSides Latam Peru, BSides Panamá, DOJOConf, PwnedCR, and OWASP Latam. Offensive security certifications: OSWE, OSEP, OSCP, OSWP, CRTP, CRTO, and CRTL.

\n\n

--

\n\n

Profesor en la Universidad Tecnológica de Panamá y especialista en Red Team con más de 10 años de experiencia en ciberseguridad ofensiva y defensiva. Pentester en GBM (región y Estados Unidos) y researcher en Toad Security. Máster en Seguridad Informática. Realiza evaluaciones de seguridad a aplicaciones móviles, web e infraestructura en Latinoamérica y comparte activamente conocimientos en la comunidad Dojo como embajador y conferencias. Certificaciones: OSWE, OSEP, OSCP, CRTO, OSWP, CRTL.

\n\nSpeakerBio:  Jose Rivas, Experienced Penetration Tester at A-LIGN
\n

Jose Rivas is an Offensive Security Researcher and Red Team Operator at A-LIGN, specializing in adversarial simulations, Active Directory attack paths, and physical security assessments. Co-founder of Zero Trust Offsec, an offensive security research group focused on vulnerability exploitation, emerging attack techniques, and responsible disclosure, and Founder of DCG Panama, Panama\'s first official DEF CON chapter, where he leads a community dedicated to red team operations, and adversarial tradecraft. A recognized voice in the Panamanian security community, Jose has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf. With certifications including CRTO, eWPT, eCPPT, and CompTIA PenTest+, he brings a threat-actor mindset and a strong commitment to advancing offensive security knowledge across the region.

\n\n

Jose Manuel Rivas is a Penetration Tester and Red Team Operator at A-LIGN, with hands-on experience in adversarial simulations, Active Directory attack chains, web application testing, and physical security assessments. He has multiple CVEs to his name, discovered through bug bounty programs and independent vulnerability research. Co-founder of Zero Trust Offsec and founder of DCG Panama, Panama\'s first official DEF CON chapter. He has spoken at BSides Colombia, BSides Panama, OWASP Panama, and DOJOConf, and is focused on growing the penetration testing and red team culture across Latin America.

\n\n\n\'',NULL,1297247),('3_Saturday','10','10:00','10:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Learning Deception by Doing: Attacking and Defending\'','\'Diego Staino,Fede Pacheco\'','Creator Talks_506782de924425bf0acc3d3f462ca735','\'Title: Learning Deception by Doing: Attacking and Defending
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Cyber deception is one of the most powerful and least understood defensive disciplines — most practitioners have read about honeypots, but few have ever deployed a breadcrumb, watched an attacker chase a fake credential, or felt the confusion deception causes from the attacker\'s side.

\n\n

This session shares the fundamentals of deception by doing and experiencing: what deceptive artifacts exist (honey-credentials, deceptive configs, honey-services, synthetic activity), where they belong in a real environment, what telemetry they generate, and how they change an adversary\'s behavior. Everything is practiced in an open-source, Docker-based playground that recreates a realistic multi-tier company — with an attacker toolkit on one side and a defender SIEM on the other — so attendees can safely play both roles.

\n\n

The 25-minute format is a guided demo; the 50-minute format is a hands-on lab.

\n\nSpeakers:Diego Staino,Fede Pacheco
\n
\nSpeakerBio:  Diego Staino, R&D+i Manager
\n

Cybersecurity professional with 15+ years of experience as Security and IT consultant. Certified Incident Handler (ECIH) with a degree in Information Security and Communications. Currently works as R&D+i Manager at BASE4 Security, where he leads the company\'s research and development initiatives.

\n\nSpeakerBio:  Fede Pacheco, Cybersecurity Services Director, BASE4 Security
\n

Especialista en ciberseguridad con formación en ingeniería electrónica, y destacadas certificaciones profesionales en seguridad de la información. Cuenta con 20 años de experiencia docente, principalmente en la Universidad Tecnológica Nacional. Lleva publicados cuatro libros y diversos trabajos de investigación en temáticas de ciberseguridad y de educación, algunos de los cuales han sido presentados en congresos y conferencias globales. Además, se desempeñó en roles de liderazgo de alcance regional en distintas empresas multinacionales. Actualmente tiene a cargo el área de Cybersecurity Services de BASE4 Security.

\n\n\n\'',NULL,1297248),('3_Saturday','10','10:30','10:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Self Hosting Nightmare - Exploiting AI models for supply chain attacks\'','\'Davidson Mizael\'','Creator Talks_19fe3b3079f0a2ab23010ae00be4c41b','\'Title: Self Hosting Nightmare - Exploiting AI models for supply chain attacks
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

In this presentation I\'ll go through the process of how you could possibly exploit this vulnerability in one of thousands servers exposed to the internet running the top one tool in the world for self hosting AI models. The process I\'ll demonstrate in this presentation involves exploring vulnerable by default decisions to achieve total control of this model serving tool, and the vulnerability research I have done on top of this tool that led me to find 7 0day vulnerabilities that allows anyone to achieve the following results:

\n\n
    \n
  • Free token usage

  • \n
  • Cause unavailability in the servers

  • \n
  • Steal top of the market secret models

  • \n
  • Cause chaos within dependent services with a model defacement

  • \n
  • Craft a supply attack

  • \n
\n\nSpeakerBio:  Davidson Mizael, Incident Responder @ IBM X-Force
\n

Long time hacker and former developer working at IBM X-Force doing Incident Response.

\n\n

Hacking for the fun of it and always trying to building cool stuff.

\n\n\n\'',NULL,1297249),('3_Saturday','10','10:30','12:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'Workshop Before the SIEM Blinks: How AI Memory Turns Alerts into Intelligence\'','\'Luis Pazmino,Yoshihito Adachi\'','Creator Workshops_46a62cde461d665b6600e429d31b496f','\'Title: Workshop Before the SIEM Blinks: How AI Memory Turns Alerts into Intelligence
\nTags: La Villa Community | Creator Workshop
\nWhen: Saturday, Aug 8, 10:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout - Map
\n
\nDescription:
\n

La mayoría de los SOCs son reactivos por diseño: los eventos llegan, se almacenan, se correlacionan horas después, y en el mejor de los casos un analista los revisa cuando puede.

\n\n

Este workshop rompe ese modelo.

\n\n

Presentamos una arquitectura SOC-less impulsada por IA donde la detección ocurre en línea — antes de que los datos lleguen al SIEM — usando reglas Sigma traducidas a lógica ejecutable en Groovy.

\n\n

Cuando una regla hace match, el evento se enriquece al instante con contexto de usuario, criticidad del activo, estructura de procesos y técnicas asociadas a MITRE ATT&CK.

\n\n

El diferenciado de nuestra propuesta es la memoria. Cada alerta, ticket, resolución, triaje de analista y falso positivo alimenta un índice recurrente.

\n\n

los agentes consultan ese historial para determinar si una detección es nueva, recurrente, vinculada a un activo crítico o parte de un patrón conocido — luego generan el ticket, sugieren severidad, recomiendan la contención y, en escenarios controlados la ejecutan.

\n\n

El resultado del flujo es la detección y respuesta inicial medidas en segundos, no en turnos de analistas.

\n\nSpeakers:Luis Pazmino,Yoshihito Adachi
\n
\nSpeakerBio:  Luis Pazmino, Cyber Defense Manager Banco Pichincha, Principal Consultor DataProtect Information Security
\n

Cybersecurity Lover, Red Teamer, OSCE | OSEP | OSCP | CISM | ECSA | CEI

\n\nSpeakerBio:  Yoshihito Adachi, Cybersecurity Specialist
\n

I have a strong passion for data exploration and threat hunting, which drives me to constantly seek out new methods to detect high-level threats. Being a highly logical individual, I am deeply interested in understanding how things work. This curiosity fuels my dedication to uncovering innovative approaches and enhancing cybersecurity measures.

\n\n\n\'',NULL,1297250),('3_Saturday','11','10:30','12:59','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'Workshop Before the SIEM Blinks: How AI Memory Turns Alerts into Intelligence\'','\'Luis Pazmino,Yoshihito Adachi\'','Creator Workshops_46a62cde461d665b6600e429d31b496f','\'\'',NULL,1297251),('3_Saturday','12','10:30','12:59','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'Workshop Before the SIEM Blinks: How AI Memory Turns Alerts into Intelligence\'','\'Luis Pazmino,Yoshihito Adachi\'','Creator Workshops_46a62cde461d665b6600e429d31b496f','\'\'',NULL,1297252),('3_Saturday','11','11:00','11:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Meet XEntry Team: A powerful threat actor abusing Bitlocker for ransomware\'','\'Eduardo Chavarro Ovalle\'','Creator Talks_0ddb3ce96826ee7fd814fe9ea31e62b2','\'Title: Meet XEntry Team: A powerful threat actor abusing Bitlocker for ransomware
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Our GERT team was notified about a company affected by a previously unknown threat actor identified as \"XEntry Team\". Initially, the customer identified this threat as a hijacked LogMeIn session that allowed the attackers to activate BitLocker and encrypt the disks of every system synchronizing to the AD; but our analysis confirmed a 2 months intrusion, using a mix of clever techniques and lack of monitoring, that allowed attacker to configure a bridge to the infrastructure for:

\n\n

• Recognition

\n\n

• Critical assets identification

\n\n

• Exfiltration

\n\n

• Persistance

\n\n

• ransomware deployment

\n\n

• Other not so funny stuff.

\n\n

During this session we will present to the audience the investigation results, the techniques implemented by the threat actor, the scope of the attack from beginning to the end, and the analysis and attempts to recover affected systems.

\n\nSpeakerBio:  Eduardo Chavarro Ovalle, DFIR Group Manager at Kaspersky - GERT
\n

Eduardo Chavarro Ovalle, DFIR Group Manager for Americas, member of Kaspersky GERT Team. Student of DBA in ML and AI and MSc in Cybersecurity with more than 20 years of experience in cybersecurity, DFIR, eDiscovery, and threat analysis. GCIH | GRID | GCFA | CISM | CHFI | CPTE | SFCP | ITIL.

\n\n\n\'',NULL,1297253),('3_Saturday','12','12:00','12:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Malware Inc.: Cybercrime-as-a-Service y la economía del cibercrimen moderno\'','\'Isabel Manjarrez\'','Creator Talks_b9823589f36f8f467e351af7079c12f2','\'Title: Malware Inc.: Cybercrime-as-a-Service y la economía del cibercrimen moderno
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

El cibercrimen moderno dejó atrás el modelo del atacante aislado. Hoy existe un ecosistema modular y altamente especializado donde servicios como Malware-as-a-Service (MaaS), Ransomware-as-a-Service (RaaS), Pay-Per-Install (PPI), Initial Access Brokers (IAB) o Phishing-as-a-Service (PhaaS) permiten que distintos actores colaboren dentro de una cadena de suministro criminal distribuida.

\n\n

En esta charla exploraremos cómo el malware adoptó principios de industrialización similares a los de la industria tecnológica legítima: afiliados, automatización, revenue sharing, soporte técnico y servicios bajo demanda. A través de casos reales revisaremos cómo funciona esta economía clandestina, cómo se monetizan distintas etapas de un ataque y por qué entender el modelo de negocio detrás del malware es clave para comprender las amenazas actuales.

\n\nSpeakerBio:  Isabel Manjarrez, Threat Researcher
\n

[EN] María Isabel Manjarrez is a security researcher with Kaspersky\'s Global Research and Analysis Team (GReAT). She specializes in investigating threat actors in Latin America, tracking their movements, and analyzing the new techniques they deploy. She holds a degree in telecommunications and electronic systems engineering and her interests include threat intelligence, malware analysis, satellite communications, electronics, and music.

\n\n

She has shared her knowledge as a speaker at local and international conferences such as Defcon, Security Analyst Summit (SAS), and EkoParty.

\n\n
\n\n

[ES] María Isabel Manjarrez es investigadora de seguridad en el Equipo Global de Investigación y Análisis (GReAT) de Kaspersky. Se especializa en la investigación de actores amenaza en Latinoamérica, rastrea sus movimientos y analiza las nuevas técnicas que implementan. Es Ingeniera en telecomunicaciones y sistemas electrónicos, sus intereses incluyen la inteligencia de amenazas, análisis de malware, comunicaciones satelitales, electrónica y música.

\n\n

Ha compartido su conocimiento como ponente en conferencias locales e internacionales como Defcon, Security Analyst Summit (SAS) y EkoParty.

\n\n\n\'',NULL,1297254),('3_Saturday','12','12:30','13:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Descubrimiento Industrializado de CVEs con Agentes de IA\'','\'Simon Correa,Michael Rivera\'','Creator Talks_e78fbb9d07e90ca96297c07588a6eddf','\'Title: Descubrimiento Industrializado de CVEs con Agentes de IA
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

¿De verdad puede la IA encontrar vulnerabilidades reales y nuevas a gran escala? La seguridad de aplicaciones es nuestra disciplina, y somos una CNA de tipo investigador, entre las primeras del CNA Scorecard. Montamos una cadena de producción y la soltamos sobre 36 proyectos de código abierto. Hasta ahora, y contando: 539 hallazgos revisados, depurados hasta 8 CVEs públicos y 30 candidatos a CVE.

\n\n

La charla recorre la cadena completa: cómo entrenamos agentes que recorren el código, cómo un modelo de machine learning detecta los fragmentos sospechosos, cómo los hackers y researchers validan cada candidato y qué números deja cada etapa del filtrado.

\n\n

Nuestra meta: acortar el tiempo de detección a escala sin sacrificar exactitud, para que la ventana de exposición (detección + remediación) sea menor que el tiempo de explotación. Te llevas un método replicable para convertir LLMs impredecibles en una fábrica seria de CVEs, con las métricas de precisión que la sostienen.

\n\nSpeakers:Simon Correa,Michael Rivera
\n
\nSpeakerBio:  Simon Correa, Fluid Attacks, Head of Research
\n

Simón Correa, Head of Research en Fluid Attacks, es responsable de coordinar el CNA de la compañía, realizar investigaciones técnicas de ciberseguridad y liderar la detección de vulnerabilidades en software open source de terceros, gestionando todo el ciclo de vida de los CVEs desde su descubrimiento hasta su publicación. Además, coordina y participa en el equipo interno de CTFs, analizando el rendimiento y diseñando estrategias de mejora para futuras competencias. En su rol, mantiene la interlocución con MITRE y NIST, prepara publicaciones académicas y ponencias para conferencias especializadas, y organiza meetups técnicos que fortalecen el posicionamiento de Fluid Attacks en la comunidad de seguridad.

\n\nSpeakerBio:  Michael Rivera, Chief Data & AI Officer | M.Sc. in Analytics
\n

Michael Rivera is the Chief Data & AI Officer at Fluid Attacks, where he leads initiatives that combine advanced data analytics and artificial intelligence to strengthen software quality and security. His work in recent years has focused on developing methods that reduce the time required to detect vulnerabilities and on ensuring that AI-driven systems are built under the security-by-design approach.

\n\n

Michael combines an academic background in economics with his Master of Science in Analytics at the Georgia Institute of Technology, enabling him to bring an uncommon interdisciplinary perspective to the field of cybersecurity. With years of experience bridging data science and AppSec practice, he offers both technical depth and strategic insight, making him uniquely positioned to help organizations adopt rigorous frameworks for evaluating security solutions.

\n\n\n\'',NULL,1297255),('3_Saturday','13','12:30','13:30','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Descubrimiento Industrializado de CVEs con Agentes de IA\'','\'Simon Correa,Michael Rivera\'','Creator Talks_e78fbb9d07e90ca96297c07588a6eddf','\'\'',NULL,1297256),('3_Saturday','13','13:30','13:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'The CVE-Hunters Project: From Noobs to Researchers\'','\'Natan Morette\'','Creator Talks_1818d282296b7e4e8b347a070804a287','\'Title: The CVE-Hunters Project: From Noobs to Researchers
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

What if publishing a CVE wasn’t reserved for elite hackers, but achievable by anyone with the right mindset, method, and community?

\n\n

This talk tells the story of how the Brazilian CVE-Hunters Project transformed beginners with zero published research into recognized vulnerability researchers contributing to global cybersecurity. By breaking down the myth that CVEs require genius-level exploits or zero-days, we reveal a structured, repeatable methodology that turns curiosity into impact.

\n\n

You’ll learn how vulnerability research can be systematized, how responsible disclosure really works behind the scenes, and how publishing your first CVE can change your technical credibility, career trajectory, and confidence.

\n\n

More than a technical presentation, this is a blueprint for moving from learning hacking to becoming a researcher — and contributing meaningfully to the security ecosystem.

\n\n

Because your first CVE isn’t about ego.

\n\n

It’s about responsibility, growth, and raising the bar for global security.

\n\nSpeakerBio:  Natan Morette, Pentest Manager at Thoropass, vulnerability researcher, and cybersecurity instructor for Brazil’s national Hackers for Good initiative
\n

Natan Morette is a Penetration Test Manager, vulnerability researcher, and cybersecurity instructor for Brazil’s national Hackers for Good initiative, where he mentors students in offensive security across the country. He began his career as a help desk analyst and moved through infrastructure roles before discovering his passion for cybersecurity. Natan has discovered and published multiple CVEs and actively supports students in identifying and disclosing their own—especially in open-source projects with meaningful social impact.

\n\n\n\'',NULL,1297257),('3_Saturday','14','14:00','15:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'Execution of modern techniques to start/improve your career in Incident Response\'','\'Ashley Hiram Muñoz\'','Creator Workshops_a3bf3917c93a9292ab97ee984b141410','\'Title: Execution of modern techniques to start/improve your career in Incident Response
\nTags: La Villa Community | Creator Workshop
\nWhen: Saturday, Aug 8, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout - Map
\n
\nDescription:
\n

Practicaremos algunas técnicas modernas que utilizamos en equipos globales de Respuesta a Incidentes para procesar y analizar evidencias digitales durante ataques cibernéticos, y responder con conclusiones acertadas en un lapso muy corto.

\n\n

Este taller está dirigido para quienes desconocen cómo empezar su carrera en DFIR o buscan afinar sus técnicas de investigación.

\n\n

Habrá un pequeño CTF de un incidente de Ransomware con regalos para los ganadores.

\n\nSpeakerBio:  Ashley Hiram Muñoz, Kaspersky - Incident Response Specialist
\n

I currently work as an Incident Response Specialist on Kaspersky\'s Global Emergency Response Team (GERT). I live in Mexico and have over seven years of experience in Incident Response, Digital Forensics, Malware Analysis, and Reverse Engineering. Before joining DFIR, I worked for two years as a Penetration Tester.

\n\n

I have collaborated on various Threat Hunting and Threat Intelligence projects.

\n\n

Additionally, I have been a speaker at international events such as DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, HackGDL, BugCON, Pwnterrey, and others. I currently teach the Digital Forensics, Malware Analysis, and Incident Response modules in an information security diploma program at UNAM (Universidad Nacional Autónoma de México).

\n\n

Certifications: GREM, GCFA, GCFR, eCTHP, CHFI.

\n\n

--

\n\n

Actualmente me desempeño como Incident Response Specialist en el Global Emergency Response Team (GERT) de Kaspersky, cuento con +6 años de experiencia realizando Respuesta a Incidentes, Análisis Forense Digital, Análisis de Malware y Reversing; previo a dedicarme a DFIR laboré 2 años como Penetration Tester.

\n\n

He colaborado en distintos proyectos de Threat Hunting y Threat Intelligence.

\n\n

Adicionalmente, he sido ponente en eventos internacionales como DEFCON (La Villa Hacker), BSides, Ekoparty, 8.8, BugCON, etc.

\n\n

Actualmente soy profesor de los módulos de Análisis Forense, Análisis de Malware y Respuesta a Incidentes en un diplomado de seguridad de la información de la UNAM.

\n\n

Certificaciones: GREM, GCFA, eCTHP, CHFI.

\n\n\n\'',NULL,1297258),('3_Saturday','15','14:00','15:59','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Workshops/Chillout','\'Execution of modern techniques to start/improve your career in Incident Response\'','\'Ashley Hiram Muñoz\'','Creator Workshops_a3bf3917c93a9292ab97ee984b141410','\'\'',NULL,1297259),('3_Saturday','14','14:00','14:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Keep the Model on Course: Agentic LLM Workflows for Reversing\'','\'Asher Davila,Lenin Alevski\'','Creator Talks_8e385e10f4c6000f0ae52bf128bac040','\'Title: Keep the Model on Course: Agentic LLM Workflows for Reversing
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Malware analysts are wiring LLMs into their reversing workflows today. The MCP integrations for IDA Pro, Ghidra, radare2, and Binary Ninja are public, and analysts use them to rename functions, triage samples, and hunt vulnerabilities. Adoption has outpaced any measured account of where these tools hold up and where they mislead, and running an agent against one sample can burn an enormous number of tokens on work the model repeats for every binary.

\n\n

We built an agentic malware analysis framework on ADK (Agent Development Kit) that connects LLMs to disassemblers through MCP, wrapped in per-language skills for C/C++, C#, Go, Android, etc. The ADK agent loop drives the analysis: pulling functions, following xrefs, reading decompiled output, making notes, and issuing disassembler commands on its own. Each skill supplies the runtime context once, so the model spends its budget on the sample. Everything runs in Docker containers for isolation and reproducibility.

\n\n

We tested it across multiple models on real samples and scored every result against ground truth. Triage and function renaming on stripped binaries work well when the agent is steered. Crypto identification and CVE matching fail in ways that read as authoritative. The analyst is the captain, the model the crew. We ship the containers, skills, and prompt templates so attendees can reproduce similar workflows efortlessly.

\n\nSpeakers:Asher Davila,Lenin Alevski
\n
\nSpeakerBio:  Asher Davila, Vulnerability Researcher at Palo Alto Networks
\n

Passionate about binary analysis, binary exploitation, reverse engineering, hardware hacking, retro computing, and music.

\n\nSpeakerBio:  Lenin Alevski, Security Engineer at Google
\n

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.

\n\n\n\'',NULL,1297260),('3_Saturday','14','14:30','15:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'When Cash Runs on Windows: A Red Team Look at ATM Attack Surfaces\'','\'Gerardo Mejia\'','Creator Talks_ba244f449c5c3b24bca42588bcc2479c','\'Title: When Cash Runs on Windows: A Red Team Look at ATM Attack Surfaces
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Muchos cajeros automáticos siguen siendo, en esencia, computadoras Windows especializadas. Algunos son modernos, otros llevan años operando con sistemas heredados, configuraciones antiguas y controles que nunca fueron revisados a profundidad. Están en gasolineras, supermercados y esquinas, conectados a infraestructura crítica donde una mala decisión de hardening, segmentación o administración remota puede convertirse en un riesgo real.

\n\n

Nadie los toca. Nadie los cuestiona. Hay dinero adentro.

\n\n

Esta charla resume hallazgos de ejercicios reales de pentesting sobre ATMs realizados en América Latina. Veremos cómo se ve la seguridad ATM en producción: qué controles suelen estar presentes, cuáles fallan de formas inesperadas y cómo debilidades aparentemente menores pueden encadenarse hasta comprometer infraestructura crítica.

\n\n

Entre los hallazgos analizaremos fallas en controles de endpoint, hardening, segmentación, administración remota y exposición de servicios legacy. También veremos qué controles resistieron, por qué lo hicieron y qué diferencia a un ATM correctamente endurecido de uno que puede convertirse en punto de entrada hacia infraestructura crítica bancaria.

\n\n

Más que mostrar “cómo atacar un cajero”, esta charla busca crear conciencia sobre la importancia de endurecer y monitorizar estos equipos.

\n\nSpeakerBio:  Gerardo Mejia, Red Teamer
\n

Es especialista en ciberseguridad ofensiva, con enfoque en operaciones de red teaming, purple teaming, pruebas de penetración, campañas avanzadas de phishing y ataques dirigidos a entornos de Active Directory. Actualmente forma parte del un equipo regional de seguridad ofensiva, donde diseña y ejecuta ejercicios de simulación de adversarios para fortalecer la resiliencia de las organizaciones ante amenazas sofisticadas.

\n\n

Cuenta con certificaciones destacadas, como CRTO, CRTP, PNPT, eWPT, CR (HTB Ambassador), C-ADPenX y eCCPT.

\n\n

Ha sido conferencista en eventos internacionales como PWNEDCR en Costa Rica, BSides Panamá, Dojo Conf Panamá, HackConRD en República Dominicana y Ekoparty en Argentina, Defcon 33 La Villa, Kavacon

\n\n\n\'',NULL,1297261),('3_Saturday','15','14:30','15:30','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'When Cash Runs on Windows: A Red Team Look at ATM Attack Surfaces\'','\'Gerardo Mejia\'','Creator Talks_ba244f449c5c3b24bca42588bcc2479c','\'\'',NULL,1297262),('3_Saturday','15','15:30','16:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'From Live Malware to Red Team Tradecraft: Process Hollowing in msbuild.exe\'','\'Filipi Pires\'','Creator Talks_cf1b4a4268edb01039270b634d03a2d7','\'Title: From Live Malware to Red Team Tradecraft: Process Hollowing in msbuild.exe
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

The best hiding place is often a binary Microsoft already signed. This talk presents a complete red team operation reconstructed from a real multi-stage JScript dropper captured in April 2026 targeting Energy, Government, and Aerospace organizations. Using custom tooling and malware analysis, we transformed the adversary’s workflow into a repeatable offensive playbook focused on trusted binary abuse, fileless execution, and stealthy process injection.

\n\n

The session demonstrates how attackers delivered a .NET payload through steganographic C2 hosted on trusted paste services, loaded assemblies directly in memory with Reflection.Assembly::Load(), and performed Process Hollowing into msbuild.exe using native Windows APIs including ZwUnmapViewOfSection, VirtualAllocEx, and SetThreadContext.

\n\n

We also explore operational evasion techniques such as WMI hidden process spawning, obfuscated Base64 transformations, and Sysmon telemetry analysis from the perspective of a red team operator. Every technique shown was extracted from a live adversary sample and operationalized for realistic adversary emulation.

\n\nSpeakerBio:  Filipi Pires, Head of Technical Advocacy at SCYTHE
\n

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, Advisor & Investor at Sherlockeye, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I\'m Creator and Instructor of the Course - Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis - Fundamentals (HackerSec).

\n\n

Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329\nBlack Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329\nBlack Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0\nBlack Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires\nDEF CON 33 / 32 - https://sessionize.com/filipi-pires/\nDEF CON - Adversary Village - https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/

\n\n\n\'',NULL,1297263),('3_Saturday','16','15:30','16:30','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'From Live Malware to Red Team Tradecraft: Process Hollowing in msbuild.exe\'','\'Filipi Pires\'','Creator Talks_cf1b4a4268edb01039270b634d03a2d7','\'\'',NULL,1297264),('3_Saturday','16','16:30','17:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'De la Explotación de Buffer Overflows al C2 Industrial: Infectando y Controlando RTUs con Malware\'','\'Fernando Mengali\'','Creator Talks_54a9a55d80bc95006879caf9b81fe83e','\'Title: De la Explotación de Buffer Overflows al C2 Industrial: Infectando y Controlando RTUs con Malware
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:30 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

En esta charla práctica y directa al punto, se demostrará cómo una vulnerabilidad de buffer overflow puede ser explotada para comprometer entornos SCADA, evolucionando desde la ejecución de shellcode multietapa hasta el establecimiento de canales de comunicación C2 y el control remoto de sistemas industriales críticos. A través de demostraciones técnicas, se analizará cómo una vulnerabilidad aparentemente aislada puede convertirse en una cadena de ataque capaz de afectar procesos industriales, provocar interrupciones operativas e incluso derivar en escenarios de blackout.

\n\nSpeakerBio:  Fernando Mengali, Information Security Specialist
\n

Cybersecurity researcher focused on Pentesting and AppSec, also serving as a Practical / Hands-on Speaker. He also dedicates part of his research to critical infrastructure security (ICS/SCADA), exploring the intersection between classic vulnerabilities and industrial environments. He has over 18 years of experience in offensive security and practical application exploitation.

\n\n

He has participated in research and development projects focused on vulnerability exploitation and offensive security.

\n\n

Specialized in 0day discovery and exploit development, he has over 135 published CVEs and is ranked in the Top 10 contributors on VulDB https://vuldb.com/users.top.

\n\n

Additionally, he has published multiple exploits and technical papers publicly available https://www.exploit-db.com/?author=12136 and https://packetstorm.news/files/author/8470/1.

\n\n

His work focuses on real-world vulnerability exploitation, including advanced scenarios such as memory corruption, buffer overflows, and complex environments.

\n\n

He is the creator of https://yrprey.com, an educational framework that brings together more than 20 vulnerable applications based on the OWASP Top 10, used for practical training in Application Security and Offensive Security https://owasp.org/www-project-vulnerable-web-application-directory.

\n\n

He is also the driving force behind https://speakfy.io, a project focused on promoting Information Security events globally.

\n\n

Furthermore, he develops application security-oriented tools, such as https://leapfix.co (static code analysis) and https://fitoxs.com, a dynamic application analysis platform powered by artificial intelligence.

\n\n\n\'',NULL,1297265),('3_Saturday','17','16:30','17:30','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'De la Explotación de Buffer Overflows al C2 Industrial: Infectando y Controlando RTUs con Malware\'','\'Fernando Mengali\'','Creator Talks_54a9a55d80bc95006879caf9b81fe83e','\'\'',NULL,1297266),('3_Saturday','17','17:30','18:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'latinas.exe has entered the chat (ESP - POR)\'','\'\'','Creator Talks_5075360d5f52e2779065838a2cc9d134','\'Title: latinas.exe has entered the chat (ESP - POR)
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 18:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n\n\n\'',NULL,1297267),('3_Saturday','18','17:30','18:30','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'latinas.exe has entered the chat (ESP - POR)\'','\'\'','Creator Talks_5075360d5f52e2779065838a2cc9d134','\'\'',NULL,1297268),('4_Sunday','10','10:00','10:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Tu foco IoT nunca tuvo modelo de amenazas\'','\'Andres Sabas\'','Creator Talks_5d8adc27d3f5c291ddc14e3c622a9667','\'Title: Tu foco IoT nunca tuvo modelo de amenazas
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Compraste una foco IoT. La conectaste a tu WiFi. Le pusiste una contraseña.

\n\n

¿Quién más le puede mandar órdenes? ¿Quién verifica que el firmware que descarga es

\n\n

legítimo?

\n\n

En esta charla cuento la auditoría completa de Magic Home — la app de Zengge instalada en

\n\n

bombillas, tiras LED y switches que se venden bajo una docena de marcas blancas. No

\n\n

vengo a enumerar bugs. Vengo a mostrar tres preguntas básicas que el ecosistema entero —

\n\n

móvil, nube y radio — no puede responder una sola raíz: nunca hubo modelo de amenazas en el

\n\n

ciclo del producto.

\n\n

Uso firmware ya publicado en internet, scripts caseros y un decompilador. Cero hardware

\n\n

comprado. Una demo grabada de por qué nada detendría a un atacante. Una demo en vivo de

\n\n

cuánto se puede ver del fleet sin tocar a nadie más.

\n\nSpeakerBio:  Andres Sabas, Electronic Cats
\n

Co fundador de Electronic Cats, promotor del hardware abierto, co creador de productos de seguridad como HunterCat, Minino y BomberCat

\n\n\n\'',NULL,1297269),('4_Sunday','10','10:30','11:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Bait the Bot: Hacking Back Autonomous AI Vulnerability Scanners\'','\'Alcyon Junior\'','Creator Talks_06c47085d95833fe04d311ac538d0f3b','\'Title: Bait the Bot: Hacking Back Autonomous AI Vulnerability Scanners
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Autonomous, LLM-powered vulnerability scanners now crawl the web at scale — and every one of them shares the same structural weakness: it reads the content you control. This talk flips the engagement. Instead of just blocking the bot, your site detects that an AI agent is scanning it, fingerprints the model behind it, and fires back a hidden, tailored prompt injection that derails, poisons, or neutralizes the attacking agent — with no traditional exploit involved. We build on recent academic work on prompt-injection \"hack back,\" push it into the reconnaissance-and-scanning threat model with live demos, walk through an escalating cat-and-mouse between attacker and defender, and take an honest look at where active defense crosses the legal line. Red teamers and blue teamers alike will leave with something they can responsibly test the same week.

\n\nSpeakerBio:  Alcyon Junior, Head of Offensive Security & Fraud Hunting at Apura
\n

Alcyon Junior is the Head of Offensive Security & Fraud Hunting at Apura, a speaker, writer, EXIN-accredited instructor, SecurityCast (securitycast.com.br) podcaster, and professor. He holds three degrees in Information Technology with a focus on computer networks, is a Cisco-certified specialist in Computer Networks, and has an MBA in IT Governance. Alcyon earned a Master’s degree in Knowledge Management and Information Technology with a focus on Cybersecurity from the Catholic University of Brasília, and he is currently pursuing a PhD in Electrical Engineering with an emphasis on Information Security and Communications at the University of Brasília (UnB). His international certifications include CompTIA Security+, Ethical Hacking Foundation (EHF), ISO/IEC 27002 (ISFS), ITIL® Foundation, Cisco Networking Academy (CNAP), McAfee Vulnerability Manager (MVM), and Server Professional (LPIC-1)

\n\n\n\'',NULL,1297270),('4_Sunday','11','10:30','11:30','Y','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Bait the Bot: Hacking Back Autonomous AI Vulnerability Scanners\'','\'Alcyon Junior\'','Creator Talks_06c47085d95833fe04d311ac538d0f3b','\'\'',NULL,1297271),('4_Sunday','11','11:30','11:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'La Rosa de Guadalupe DFIR: Serie de 3 capítulos de misterio Cyber*\'','\'Victor Gomez,Horacio Bazán\'','Creator Talks_849d58f381a2ded640ef265e221e55d7','\'Title: La Rosa de Guadalupe DFIR: Serie de 3 capítulos de misterio Cyber*
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Tres insólitos incidentes de ciberseguridad fueron resueltos por dos investigadores en Incidentes de Ciberseguridad con ayuda de múltiples técnicas de \"sniper-forensics\" y una \"Rosa Blanca\" les confirmó sus sospechas iniciales y los llevó a encontrar la verdad.

\n\n

Se abordará el análisis detallado de las diferentes fuentes de información (bitácoras, artefactos y contexto).

\n\nSpeakers:Victor Gomez,Horacio Bazán
\n
\nSpeakerBio:  Victor Gomez, DFIR Principal
\n

Victor Gomez is a cybersecurity professional coming from the sysadmin-architecture world. He has focused his career on digital forensics, incident response, and Intel, responding to all kinds of attacks on multiple and different sizes of organizations & industries and leading multiple Cyber* teams. In his spare time, he likes to mentor and organize a local meetup in Mexico City.

\n\nSpeakerBio:  Horacio Bazán, DFIR Principal
\n

Ph.D. in Computer Sciences (cybersecurity & AI) from Instituto Politécnico Nacional (National Polytechnic Institute, IPN in 2024. For the past few years, I have been working as an Incident Responder, taking on multiple roles in cybersecurity. My professional interests include incident response, Artificial Intelligence (AI) applied to Cybersecurity, primarily in Android malware analysis and Computer Forensics.

\n\n\n\'',NULL,1297272),('4_Sunday','12','12:00','12:59','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'Red Robin: Don\'t Hack For Me, Hack With Me\'','\'Juan Sequeira Piedra,Jose Urena\'','Creator Talks_0fb78bcf9bf3b65f3431b17ef2853fb0','\'Title: Red Robin: Don\'t Hack For Me, Hack With Me
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n

Desde 2025, y especialmente con la llegada de modelos de IA cada vez más capaces, el panorama de la ciberseguridad ha visto una explosión de herramientas de hacking impulsadas por IA. Prometen explotación automatizada. El objetivo de muchas de estas herramientas es ser 100% autónomas, con el hacker fuera del loop. Pero esto es seguridad: sistemas en producción, datos sensibles. Una operación real no mide solo la tecnología, también a las personas y los procedimientos, cómo detectan y cómo responden. Sin contexto y sin alguien que responda por cada decisión, automatizar no alcanza.

\n\n

Esta charla presenta Red Robin, un compañero de IA por línea de comandos hecho específicamente para red teamers. Red Robin se integra con tu framework de Command-and-Control (C2), observa la actividad de tus beacons a medida que ocurre, y te da guía contextual en tiempo real anclada a tus objetivos operativos. Nunca actúa por su cuenta. No hackea por vos. Piensa con vos.

\n\n

Esta charla cubre el panorama actual de hacking humano-vs-IA, la filosofía detrás del modelo de compañero, una inmersión técnica en la arquitectura de Red Robin, una demostración en vivo de Red Robin construyendo situational awareness dentro de una sesión de C2 activa, y una discusión a futuro sobre dónde debería encajar la asistencia de IA en el futuro de la seguridad ofensiva.

\n\nSpeakers:Juan Sequeira Piedra,Jose Urena
\n
\nSpeakerBio:  Juan Sequeira Piedra, Red Team Operator - Equifax
\n

Juan Sequeira es un operador de red team que ejecuta full-scope adversary emulation en entornos empresariales. Llegó a “offensive security” desde el lado defensivo tras dos años en un SOC, y hoy trabaja en desarrollo de malware, infraestructura y automatización de red team, e investigación de seguridad. Ha representado a Team Latin America en el International Cybersecurity Challenge 2026 en Gold Coast, Australia, y a Team Costa Rica en el European Cybersecurity Challenge (Turín 2024, Varsovia 2025) y en el Latin America Cybersecurity Challenge 2025 (Medellín).

\n\nSpeakerBio:  Jose Urena, Equifax - Red Team Operator
\n

Jose Urena es un Red Team Lead con experiencia y más de nueve años trabajando en la industria de la ciberseguridad, especializado en investigación de vulnerabilidades, desarrollo seguro y operaciones ofensivas avanzadas. Su trayectoria abarca roles críticos en auditoría de seguridad, desarrollo de herramientas y simulación de adversarios en entornos empresariales complejos. Jose es un contribuidor activo de la comunidad de seguridad y ha presentado anteriormente sobre Red Teaming, aplicación práctica de IA y operaciones de ataque modernas en el Ministerio de Ciencia y Tecnología (MICITT) de Costa Rica, así como en Kennesaw State University en Georgia.

\n\n\n\'',NULL,1297273),('4_Sunday','13','13:00','13:30','N','La Villa Community','LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage','\'La Villa - Closing Ceremony (ESP)\'','\'\'','Creator Talks_2510e5f66647aeeb78ded34db0c42e8b','\'Title: La Villa - Closing Ceremony (ESP)
\nTags: La Villa Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1416 (La Villa Community) Main Stage - Map
\n
\nDescription:
\n\n\n\'',NULL,1297274),('4_Sunday','10','10:00','13:59','N','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_0a1476c3b1ccc935caeed85152df76a3','\'Title: Car Hacking Village Open
\nTags: Car Hacking Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

Welcome to the Car Hacking Village - a place where you can learn all about the cool technology that powers modern connected transportation. The CHV at DEF CON 34 will feature a whole race track of activities including Creator Stage presentations, a competitive CTF (with awesome prizes!), an amazing badge for sale that doubles as a fully functional car hacking tool, a scavenger hunt, and more!

\n\n\'',NULL,1297275),('4_Sunday','11','10:00','13:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_0a1476c3b1ccc935caeed85152df76a3','\'\'',NULL,1297276),('4_Sunday','12','10:00','13:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_0a1476c3b1ccc935caeed85152df76a3','\'\'',NULL,1297277),('4_Sunday','13','10:00','13:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_0a1476c3b1ccc935caeed85152df76a3','\'\'',NULL,1297278),('2_Friday','10','10:00','17:59','N','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_5f43c0c8fa65e0aa7679f1e3d563bafd','\'Title: Car Hacking Village Open
\nTags: Car Hacking Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

Welcome to the Car Hacking Village - a place where you can learn all about the cool technology that powers modern connected transportation. The CHV at DEF CON 34 will feature a whole race track of activities including Creator Stage presentations, a competitive CTF (with awesome prizes!), an amazing badge for sale that doubles as a fully functional car hacking tool, a scavenger hunt, and more!

\n\n\'',NULL,1297279),('2_Friday','11','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_5f43c0c8fa65e0aa7679f1e3d563bafd','\'\'',NULL,1297280),('2_Friday','12','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_5f43c0c8fa65e0aa7679f1e3d563bafd','\'\'',NULL,1297281),('2_Friday','13','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_5f43c0c8fa65e0aa7679f1e3d563bafd','\'\'',NULL,1297282),('2_Friday','14','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_5f43c0c8fa65e0aa7679f1e3d563bafd','\'\'',NULL,1297283),('2_Friday','15','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_5f43c0c8fa65e0aa7679f1e3d563bafd','\'\'',NULL,1297284),('2_Friday','16','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_5f43c0c8fa65e0aa7679f1e3d563bafd','\'\'',NULL,1297285),('2_Friday','17','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_5f43c0c8fa65e0aa7679f1e3d563bafd','\'\'',NULL,1297286),('3_Saturday','10','10:00','17:59','N','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_e0f8b05abd4d0af86265ced1fac29672','\'Title: Car Hacking Village Open
\nTags: Car Hacking Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

Welcome to the Car Hacking Village - a place where you can learn all about the cool technology that powers modern connected transportation. The CHV at DEF CON 34 will feature a whole race track of activities including Creator Stage presentations, a competitive CTF (with awesome prizes!), an amazing badge for sale that doubles as a fully functional car hacking tool, a scavenger hunt, and more!

\n\n\'',NULL,1297287),('3_Saturday','11','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_e0f8b05abd4d0af86265ced1fac29672','\'\'',NULL,1297288),('3_Saturday','12','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_e0f8b05abd4d0af86265ced1fac29672','\'\'',NULL,1297289),('3_Saturday','13','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_e0f8b05abd4d0af86265ced1fac29672','\'\'',NULL,1297290),('3_Saturday','14','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_e0f8b05abd4d0af86265ced1fac29672','\'\'',NULL,1297291),('3_Saturday','15','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_e0f8b05abd4d0af86265ced1fac29672','\'\'',NULL,1297292),('3_Saturday','16','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_e0f8b05abd4d0af86265ced1fac29672','\'\'',NULL,1297293),('3_Saturday','17','10:00','17:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Open\'','\'\'','Creator Events_e0f8b05abd4d0af86265ced1fac29672','\'\'',NULL,1297294),('2_Friday','10','10:00','11:59','N','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Scavenger Hunt Contest\'','\'\'','Creator Events_06c468d38475e19f2fe6b776ce4d73c8','\'Title: Car Hacking Village Scavenger Hunt Contest
\nTags: Car Hacking Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

Go out and find some goofy stuff!!

\n\n

The DEF CON 34 CHV Scavenger Hunt rules and treasure list can be found at the attached link.

\n\n

Start Time: Friday, August 7 10:00

\n\n

End Time: Sunday, August 9: 12:00

\n\n

One Car Hacking Village 2026 Badge will be awarded to the first player to complete the Scavenger Hunt!

\n\nLinks:
    Rules and List - https://drive.google.com/drive/folders/1cNDWbFOdm13aA9_NwG94Qvy15H265T_o?usp=sharing
\n\'',NULL,1297295),('2_Friday','11','10:00','11:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Scavenger Hunt Contest\'','\'\'','Creator Events_06c468d38475e19f2fe6b776ce4d73c8','\'\'',NULL,1297296),('3_Saturday','10','10:00','11:59','N','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Scavenger Hunt Contest\'','\'\'','Creator Events_8d1223838342326482cf5b80c09fbca1','\'Title: Car Hacking Village Scavenger Hunt Contest
\nTags: Car Hacking Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 701 (Car Hacking Village) - Map
\n
\nDescription:
\n

Go out and find some goofy stuff!!

\n\n

The DEF CON 34 CHV Scavenger Hunt rules and treasure list can be found at the attached link.

\n\n

Start Time: Friday, August 7 10:00

\n\n

End Time: Sunday, August 9: 12:00

\n\n

One Car Hacking Village 2026 Badge will be awarded to the first player to complete the Scavenger Hunt!

\n\nLinks:
    Rules and List - https://drive.google.com/drive/folders/1cNDWbFOdm13aA9_NwG94Qvy15H265T_o?usp=sharing
\n\'',NULL,1297297),('3_Saturday','11','10:00','11:59','Y','Car Hacking Village','LVCCW Level 1 Hall 2 701 (Car Hacking Village)','\'Car Hacking Village Scavenger Hunt Contest\'','\'\'','Creator Events_8d1223838342326482cf5b80c09fbca1','\'\'',NULL,1297298),('3_Saturday','10','10:00','17:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_d753913d680bd81030e252d116c13c38','\'Title: Embedded Systems Village CTF
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

Get hands-on with devices you won\'t find anywhere else — rare, hard-to-source embedded devices staged for live exploitation. Hunt real zero-days, and yes, bring your AI: LLM-assisted tooling is fully allowed, so use it to go as deep as you can.

\n\n

Come break something that\'s never been broken.

\n\n

New to embedded? Just wrapped our 101 Labs? Beginner challenges are available as well to apply your new found knowledge!

\n\n\'',NULL,1297299),('3_Saturday','11','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_d753913d680bd81030e252d116c13c38','\'\'',NULL,1297300),('3_Saturday','12','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_d753913d680bd81030e252d116c13c38','\'\'',NULL,1297301),('3_Saturday','13','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_d753913d680bd81030e252d116c13c38','\'\'',NULL,1297302),('3_Saturday','14','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_d753913d680bd81030e252d116c13c38','\'\'',NULL,1297303),('3_Saturday','15','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_d753913d680bd81030e252d116c13c38','\'\'',NULL,1297304),('3_Saturday','16','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_d753913d680bd81030e252d116c13c38','\'\'',NULL,1297305),('3_Saturday','17','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_d753913d680bd81030e252d116c13c38','\'\'',NULL,1297306),('2_Friday','10','10:00','17:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_7bcad7bea1f3ec46c126aba4cfb6204a','\'Title: Embedded Systems Village CTF
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

Get hands-on with devices you won\'t find anywhere else — rare, hard-to-source embedded devices staged for live exploitation. Hunt real zero-days, and yes, bring your AI: LLM-assisted tooling is fully allowed, so use it to go as deep as you can.

\n\n

Come break something that\'s never been broken.

\n\n

New to embedded? Just wrapped our 101 Labs? Beginner challenges are available as well to apply your new found knowledge!

\n\n\'',NULL,1297307),('2_Friday','11','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_7bcad7bea1f3ec46c126aba4cfb6204a','\'\'',NULL,1297308),('2_Friday','12','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_7bcad7bea1f3ec46c126aba4cfb6204a','\'\'',NULL,1297309),('2_Friday','13','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_7bcad7bea1f3ec46c126aba4cfb6204a','\'\'',NULL,1297310),('2_Friday','14','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_7bcad7bea1f3ec46c126aba4cfb6204a','\'\'',NULL,1297311),('2_Friday','15','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_7bcad7bea1f3ec46c126aba4cfb6204a','\'\'',NULL,1297312),('2_Friday','16','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_7bcad7bea1f3ec46c126aba4cfb6204a','\'\'',NULL,1297313),('2_Friday','17','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_7bcad7bea1f3ec46c126aba4cfb6204a','\'\'',NULL,1297314),('4_Sunday','10','10:00','13:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_3a74e183d417b0e9fa5eddc52e72bd9b','\'Title: Embedded Systems Village CTF
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

Get hands-on with devices you won\'t find anywhere else — rare, hard-to-source embedded devices staged for live exploitation. Hunt real zero-days, and yes, bring your AI: LLM-assisted tooling is fully allowed, so use it to go as deep as you can.

\n\n

Come break something that\'s never been broken.

\n\n

New to embedded? Just wrapped our 101 Labs? Beginner challenges are available as well to apply your new found knowledge!

\n\n\'',NULL,1297315),('4_Sunday','11','10:00','13:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_3a74e183d417b0e9fa5eddc52e72bd9b','\'\'',NULL,1297316),('4_Sunday','12','10:00','13:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_3a74e183d417b0e9fa5eddc52e72bd9b','\'\'',NULL,1297317),('4_Sunday','13','10:00','13:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded Systems Village CTF\'','\'\'','Creator Events_3a74e183d417b0e9fa5eddc52e72bd9b','\'\'',NULL,1297318),('3_Saturday','10','10:00','17:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_1dec74f5612be2a4b64fcbd7b662f7a2','\'Title: Embedded - 101 Labs
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

We have a lab platform that brings everyone from every skill level to the same playing field with step by step instructions that aim to teach individuals specific techniques and skills in a hands-on manner on embedded hacking techniques.

\n\n\'',NULL,1297319),('3_Saturday','11','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_1dec74f5612be2a4b64fcbd7b662f7a2','\'\'',NULL,1297320),('3_Saturday','12','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_1dec74f5612be2a4b64fcbd7b662f7a2','\'\'',NULL,1297321),('3_Saturday','13','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_1dec74f5612be2a4b64fcbd7b662f7a2','\'\'',NULL,1297322),('3_Saturday','14','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_1dec74f5612be2a4b64fcbd7b662f7a2','\'\'',NULL,1297323),('3_Saturday','15','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_1dec74f5612be2a4b64fcbd7b662f7a2','\'\'',NULL,1297324),('3_Saturday','16','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_1dec74f5612be2a4b64fcbd7b662f7a2','\'\'',NULL,1297325),('3_Saturday','17','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_1dec74f5612be2a4b64fcbd7b662f7a2','\'\'',NULL,1297326),('4_Sunday','10','10:00','13:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_993df6c042d75ae2446b13467c9d5f19','\'Title: Embedded - 101 Labs
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

We have a lab platform that brings everyone from every skill level to the same playing field with step by step instructions that aim to teach individuals specific techniques and skills in a hands-on manner on embedded hacking techniques.

\n\n\'',NULL,1297327),('4_Sunday','11','10:00','13:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_993df6c042d75ae2446b13467c9d5f19','\'\'',NULL,1297328),('4_Sunday','12','10:00','13:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_993df6c042d75ae2446b13467c9d5f19','\'\'',NULL,1297329),('4_Sunday','13','10:00','13:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_993df6c042d75ae2446b13467c9d5f19','\'\'',NULL,1297330),('2_Friday','10','10:00','17:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_78c26cebdcd354183a7f612b9e27b0f4','\'Title: Embedded - 101 Labs
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

We have a lab platform that brings everyone from every skill level to the same playing field with step by step instructions that aim to teach individuals specific techniques and skills in a hands-on manner on embedded hacking techniques.

\n\n\'',NULL,1297331),('2_Friday','11','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_78c26cebdcd354183a7f612b9e27b0f4','\'\'',NULL,1297332),('2_Friday','12','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_78c26cebdcd354183a7f612b9e27b0f4','\'\'',NULL,1297333),('2_Friday','13','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_78c26cebdcd354183a7f612b9e27b0f4','\'\'',NULL,1297334),('2_Friday','14','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_78c26cebdcd354183a7f612b9e27b0f4','\'\'',NULL,1297335),('2_Friday','15','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_78c26cebdcd354183a7f612b9e27b0f4','\'\'',NULL,1297336),('2_Friday','16','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_78c26cebdcd354183a7f612b9e27b0f4','\'\'',NULL,1297337),('2_Friday','17','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Embedded - 101 Labs\'','\'\'','Creator Events_78c26cebdcd354183a7f612b9e27b0f4','\'\'',NULL,1297338),('2_Friday','10','10:00','17:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_28491d06f5484c544795af694502efff','\'Title: Exploit Bluetooth Low Energy with BLESPloit and optional ESP32
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

Discover how easy it is to fingerprint and control nearby BLE devices with a tap on your phone - yes, including iPhone that gets BLE superpowers with with an external ESP32. Scan remotely, clone and simulate BLE devices, test a popular headset for known vulnerabilities (or perhaps uncover a new one?) and take control of a robotic dog. Already know some BLE? Crack open our smart safe and claim the BLESPloit hardware reward inside!

\n\nSpeakerBio:  Slawomir Jasek, BLESPlo.it
\n

Seasoned trainer, speaker and IT security consultant with over two decades of expertise. Developed secure embedded systems certified to use by national agencies, participated in dozens assessments of systems, applications, firmware and hardware security for leading financial companies, largest manufacturers and innovative startups.\nCurrently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and provides training in regards to security of devices - based among others on contemporary electronic access control systems and smart locks.\nBeyond consulting on secure design for various software and hardware projects, impulsively acquires more and more BLE and NFC devices and enjoys reversing and breaking them.\nLoves sharing his knowledge via trainings, workshops, talks and open source hackme\'s (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.

\n\n\n\'',NULL,1297339),('2_Friday','11','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_28491d06f5484c544795af694502efff','\'\'',NULL,1297340),('2_Friday','12','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_28491d06f5484c544795af694502efff','\'\'',NULL,1297341),('2_Friday','13','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_28491d06f5484c544795af694502efff','\'\'',NULL,1297342),('2_Friday','14','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_28491d06f5484c544795af694502efff','\'\'',NULL,1297343),('2_Friday','15','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_28491d06f5484c544795af694502efff','\'\'',NULL,1297344),('2_Friday','16','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_28491d06f5484c544795af694502efff','\'\'',NULL,1297345),('2_Friday','17','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_28491d06f5484c544795af694502efff','\'\'',NULL,1297346),('3_Saturday','10','10:00','17:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_77fb933ab377d1e6907b1c911a0bc352','\'Title: Exploit Bluetooth Low Energy with BLESPloit and optional ESP32
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

Discover how easy it is to fingerprint and control nearby BLE devices with a tap on your phone - yes, including iPhone that gets BLE superpowers with with an external ESP32. Scan remotely, clone and simulate BLE devices, test a popular headset for known vulnerabilities (or perhaps uncover a new one?) and take control of a robotic dog. Already know some BLE? Crack open our smart safe and claim the BLESPloit hardware reward inside!

\n\nSpeakerBio:  Slawomir Jasek, BLESPlo.it
\n

Seasoned trainer, speaker and IT security consultant with over two decades of expertise. Developed secure embedded systems certified to use by national agencies, participated in dozens assessments of systems, applications, firmware and hardware security for leading financial companies, largest manufacturers and innovative startups.\nCurrently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and provides training in regards to security of devices - based among others on contemporary electronic access control systems and smart locks.\nBeyond consulting on secure design for various software and hardware projects, impulsively acquires more and more BLE and NFC devices and enjoys reversing and breaking them.\nLoves sharing his knowledge via trainings, workshops, talks and open source hackme\'s (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.

\n\n\n\'',NULL,1297347),('3_Saturday','11','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_77fb933ab377d1e6907b1c911a0bc352','\'\'',NULL,1297348),('3_Saturday','12','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_77fb933ab377d1e6907b1c911a0bc352','\'\'',NULL,1297349),('3_Saturday','13','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_77fb933ab377d1e6907b1c911a0bc352','\'\'',NULL,1297350),('3_Saturday','14','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_77fb933ab377d1e6907b1c911a0bc352','\'\'',NULL,1297351),('3_Saturday','15','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_77fb933ab377d1e6907b1c911a0bc352','\'\'',NULL,1297352),('3_Saturday','16','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_77fb933ab377d1e6907b1c911a0bc352','\'\'',NULL,1297353),('3_Saturday','17','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_77fb933ab377d1e6907b1c911a0bc352','\'\'',NULL,1297354),('4_Sunday','10','10:00','13:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_8718cc34f8b43e5cdf37aa0b0ab535af','\'Title: Exploit Bluetooth Low Energy with BLESPloit and optional ESP32
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

Discover how easy it is to fingerprint and control nearby BLE devices with a tap on your phone - yes, including iPhone that gets BLE superpowers with with an external ESP32. Scan remotely, clone and simulate BLE devices, test a popular headset for known vulnerabilities (or perhaps uncover a new one?) and take control of a robotic dog. Already know some BLE? Crack open our smart safe and claim the BLESPloit hardware reward inside!

\n\nSpeakerBio:  Slawomir Jasek, BLESPlo.it
\n

Seasoned trainer, speaker and IT security consultant with over two decades of expertise. Developed secure embedded systems certified to use by national agencies, participated in dozens assessments of systems, applications, firmware and hardware security for leading financial companies, largest manufacturers and innovative startups.\nCurrently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and provides training in regards to security of devices - based among others on contemporary electronic access control systems and smart locks.\nBeyond consulting on secure design for various software and hardware projects, impulsively acquires more and more BLE and NFC devices and enjoys reversing and breaking them.\nLoves sharing his knowledge via trainings, workshops, talks and open source hackme\'s (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.

\n\n\n\'',NULL,1297355),('4_Sunday','11','10:00','13:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_8718cc34f8b43e5cdf37aa0b0ab535af','\'\'',NULL,1297356),('4_Sunday','12','10:00','13:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_8718cc34f8b43e5cdf37aa0b0ab535af','\'\'',NULL,1297357),('4_Sunday','13','10:00','13:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Exploit Bluetooth Low Energy with BLESPloit and optional ESP32\'','\'Slawomir Jasek\'','Creator Events_8718cc34f8b43e5cdf37aa0b0ab535af','\'\'',NULL,1297358),('3_Saturday','10','10:00','17:59','N','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Thread Carefully\'','\'\'','Creator Events_955e7469c59ef317927da9ea06927cc2','\'Title: Thread Carefully
\nTags: Embedded Systems Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 503 (Embedded Systems Village) - Map
\n
\nDescription:
\n

Presentation about open thread networks, what a thread devices can see from your home network, what can it access. And how this mighty be miss-used. Some theoretical attack scenarios. Like how to turn a thread only lightbulb with ota update into a residential proxy node.

\n\n\'',NULL,1297359),('3_Saturday','11','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Thread Carefully\'','\'\'','Creator Events_955e7469c59ef317927da9ea06927cc2','\'\'',NULL,1297360),('3_Saturday','12','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Thread Carefully\'','\'\'','Creator Events_955e7469c59ef317927da9ea06927cc2','\'\'',NULL,1297361),('3_Saturday','13','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Thread Carefully\'','\'\'','Creator Events_955e7469c59ef317927da9ea06927cc2','\'\'',NULL,1297362),('3_Saturday','14','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Thread Carefully\'','\'\'','Creator Events_955e7469c59ef317927da9ea06927cc2','\'\'',NULL,1297363),('3_Saturday','15','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Thread Carefully\'','\'\'','Creator Events_955e7469c59ef317927da9ea06927cc2','\'\'',NULL,1297364),('3_Saturday','16','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Thread Carefully\'','\'\'','Creator Events_955e7469c59ef317927da9ea06927cc2','\'\'',NULL,1297365),('3_Saturday','17','10:00','17:59','Y','Embedded Systems Village','LVCCW Level 1 Hall 2 503 (Embedded Systems Village)','\'Thread Carefully\'','\'\'','Creator Events_955e7469c59ef317927da9ea06927cc2','\'\'',NULL,1297366),('3_Saturday','11','11:00','11:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'What is AI? Interactive, Unplugged Activity\'','\'Sam Mosley\'','Creator Events_1b4770766f420ba2d3811e67211e8acf','\'Title: What is AI? Interactive, Unplugged Activity
\nTags: AI Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Ever wonder what\'s actually happening inside an AI? In this hands-on, no-screens-required workshop, you\'ll build your own neural network out of flashcards and pipe cleaners, \"train\" it, and watch it try (and sometimes fail!) to answer prompts. You\'ll grow your model, give it tools and skills, and then turn the tables: try out real attacks like prompt injection, tool misuse, and data poisoning, and learn the defenses AI security researchers use to stop them, like containerization. No coding or experience required, just curiosity!

\n\nSpeakerBio:  Sam Mosley, CodeBloom
\nNo BIO available
\n\n\'',NULL,1297367),('4_Sunday','11','11:00','11:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'What is AI? Interactive, Unplugged Activity\'','\'Sam Mosley\'','Creator Events_a60eed9b6e15c80879162acfd8998092','\'Title: What is AI? Interactive, Unplugged Activity
\nTags: AI Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Ever wonder what\'s actually happening inside an AI? In this hands-on, no-screens-required workshop, you\'ll build your own neural network out of flashcards and pipe cleaners, \"train\" it, and watch it try (and sometimes fail!) to answer prompts. You\'ll grow your model, give it tools and skills, and then turn the tables: try out real attacks like prompt injection, tool misuse, and data poisoning, and learn the defenses AI security researchers use to stop them, like containerization. No coding or experience required, just curiosity!

\n\nSpeakerBio:  Sam Mosley, CodeBloom
\nNo BIO available
\n\n\'',NULL,1297368),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_52fb90b0ded488d27b20c0bf3d7e83cd','\'Title: Cyber Deck Competition
\nTags: Maker\'s Village | Contest | Cyber Deck Makers’ Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

The cyber deck contest at DEF CON 34 encourages makers of all types to create their own cyber deck. Winners will be judged on form, function, creativity, does it work, general, awesomeness, and complexity.

\n\n

Stop by Makers\' Village for more info!

\n\n

Judging Criteria

\n\n
    \n
  • Design Description
  • \n
  • Purpose
  • \n
  • Functionality
  • \n
  • Fancy-Do-Dads
  • \n
  • Processing Power
  • \n
  • Housing/Case utility
  • \n
  • Housing/Case Aesthetic Appeal
  • \n
  • Complexity
  • \n
  • Bonus categories revealed at con
  • \n
\n\n

Rules

\n\n
    \n
  1. Must be present to enter.
  2. \n
  3. Winners are determined by points awarded by the judges.
  4. \n
  5. Rules are subject to change.
  6. \n
\n\n\'',NULL,1297369),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_52fb90b0ded488d27b20c0bf3d7e83cd','\'\'',NULL,1297370),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_a870f5990ea9444fbad44b4a05749423','\'Title: Cyber Deck Competition
\nTags: Maker\'s Village | Contest | Cyber Deck Makers’ Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

The cyber deck contest at DEF CON 34 encourages makers of all types to create their own cyber deck. Winners will be judged on form, function, creativity, does it work, general, awesomeness, and complexity.

\n\n

Stop by Makers\' Village for more info!

\n\n

Judging Criteria

\n\n
    \n
  • Design Description
  • \n
  • Purpose
  • \n
  • Functionality
  • \n
  • Fancy-Do-Dads
  • \n
  • Processing Power
  • \n
  • Housing/Case utility
  • \n
  • Housing/Case Aesthetic Appeal
  • \n
  • Complexity
  • \n
  • Bonus categories revealed at con
  • \n
\n\n

Rules

\n\n
    \n
  1. Must be present to enter.
  2. \n
  3. Winners are determined by points awarded by the judges.
  4. \n
  5. Rules are subject to change.
  6. \n
\n\n\'',NULL,1297371),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_a870f5990ea9444fbad44b4a05749423','\'\'',NULL,1297372),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_a870f5990ea9444fbad44b4a05749423','\'\'',NULL,1297373),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_a870f5990ea9444fbad44b4a05749423','\'\'',NULL,1297374),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_a870f5990ea9444fbad44b4a05749423','\'\'',NULL,1297375),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_a870f5990ea9444fbad44b4a05749423','\'\'',NULL,1297376),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_a870f5990ea9444fbad44b4a05749423','\'\'',NULL,1297377),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_a870f5990ea9444fbad44b4a05749423','\'\'',NULL,1297378),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_1a12215a0b098e2708ffd90b977aacf4','\'Title: Cyber Deck Competition
\nTags: Maker\'s Village | Contest | Cyber Deck Makers’ Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 301 (Makers\' Village) - Map
\n
\nDescription:
\n

The cyber deck contest at DEF CON 34 encourages makers of all types to create their own cyber deck. Winners will be judged on form, function, creativity, does it work, general, awesomeness, and complexity.

\n\n

Stop by Makers\' Village for more info!

\n\n

Judging Criteria

\n\n
    \n
  • Design Description
  • \n
  • Purpose
  • \n
  • Functionality
  • \n
  • Fancy-Do-Dads
  • \n
  • Processing Power
  • \n
  • Housing/Case utility
  • \n
  • Housing/Case Aesthetic Appeal
  • \n
  • Complexity
  • \n
  • Bonus categories revealed at con
  • \n
\n\n

Rules

\n\n
    \n
  1. Must be present to enter.
  2. \n
  3. Winners are determined by points awarded by the judges.
  4. \n
  5. Rules are subject to change.
  6. \n
\n\n\'',NULL,1297379),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_1a12215a0b098e2708ffd90b977aacf4','\'\'',NULL,1297380),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_1a12215a0b098e2708ffd90b977aacf4','\'\'',NULL,1297381),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_1a12215a0b098e2708ffd90b977aacf4','\'\'',NULL,1297382),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_1a12215a0b098e2708ffd90b977aacf4','\'\'',NULL,1297383),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_1a12215a0b098e2708ffd90b977aacf4','\'\'',NULL,1297384),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_1a12215a0b098e2708ffd90b977aacf4','\'\'',NULL,1297385),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 301 (Makers\' Village)','\'Cyber Deck Competition\'','\'\'','Contests_1a12215a0b098e2708ffd90b977aacf4','\'\'',NULL,1297386),('2_Friday','12','12:00','14:59','N','Contests','Other / See Description','\'The EFF Benefit Poker Tournament\'','\'Cindy Cohn,Jennifer Granick,Marcia Hofmann,Kurt Opsahl,Liz Wharton\'','Contests_238a63e17f048d2e645214a084357f6a','\'Title: The EFF Benefit Poker Tournament
\nTags: The EFF Benefit Poker Tournament | Contest
\nWhen: Friday, Aug 7, 12:00 - 14:59 PDT
\nWhere: Other / See Description
\n
\nDescription:
\n

The EFF Benefit Poker Tournament is back for DEF CON 34! Your buy-in is paired with a donation to support EFF’s mission to protect online privacy and free expression for all. Play for glory. Play for money. Play for the future of the web. Seating is limited, so reserve your spot today.

\n\n

When: Friday, August 7, 2026 - 12:00-15:00

\n\n

Where: Horseshoe Poker Room, 3645 S Las Vegas Blvd, Las Vegas, NV 89109

\n\n

Tournament Specs: $100 Horseshoe tournament buy-in, with a donation of $250 or more to EFF to sign up. (AND all players will receive a complimentary EFF Gold Level Membership for the year.) Re-buys are unlimited to level 6, with each having a suggested donation of $100 on site. Levels will be fifteen minutes, and the blinds go up at each level. Attendees must be 21+.

\n\n

Pre-Tournament Clinic: Have a friend that might be interested but not sure how to play? Have you played some poker before but could use a refresher? Join poker pro Mike Wheeler (Tarah’s dad) and celebrities for a free poker clinic from 11:00 am-11:45 am just before the tournament. Mike will show you the rules, strategy, table behavior, and general Vegas slang at the poker table. Even if you know poker pretty well, come a bit early and help out.

\n\n

Emcee & Celebrity Guests: We’ll have Celebrity Bounties again! Knock out a celebrity and get neat EFF swag and the respect of your peers! Plus, as always, knock out Tarah\'s dad Mike, and she donates $250 to the EFF in your name!

\n\n

The Celebrities: This year\'s event will feature many of our legal celebrities in our Legal Champions Edition edition.

\n\n

The Glory: The tournament winner will receive the traditional Jelly Bean Trophy and we hope you’ll like this year’s newest add: We will have bug bounty pins this year! When you take someone out of the tournament, they will give you a pin. Prizes—and major bragging rights—go to the player with the most bounty pins.

\n\nSpeakers:Cindy Cohn,Jennifer Granick,Marcia Hofmann,Kurt Opsahl,Liz Wharton
\n
\nSpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation
\n

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy\'s Defender published by MIT Press in March, 2026. She is also the co-host of EFF\'s award-winning podcast, How to Fix the Internet.

\n\n

--

\n\n

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.

\n\nSpeakerBio:  Jennifer Granick, Hacker lawyer 1.0
\n

Throughout her career, Jennifer Granick has fought for civil liberties in an age of massive surveillance and powerful digital technology. As the former surveillance and cybersecurity counsel with the ACLU Speech, Privacy, and Technology Project, she litigated, spoke, and wrote about privacy, security, technology, and constitutional rights. Granick is the author of the book American Spies: Modern Surveillance, Why You Should Care, and What To Do About It, published by Cambridge Press and winner of the 2016 Palmer Civil Liberties Prize.

\n\nSpeakerBio:  Marcia Hofmann, Founder and Principal at Zeitgeist Law
\n

Founder and principal of Zeitgeist Law, a boutique law firm focused on information security, computer crime, electronic privacy, free expression, and intellectual property issues. In the past, she has worked at Twitter, the Electronic Frontier Foundation, and the Electronic Privacy Information Center. She was a US-UK Fulbright Cyber Security Scholar based at the University of Oxford, where she studied educational and restorative justice programs for young computer crime offenders. She has taught courses in computer crime at Colorado Law and Internet law at UC Law San Francisco (then known as UC Hastings).

\n\nSpeakerBio:  Kurt Opsahl, Associate General Counsel for Cybersecurity and Civil Liberties Policy at Filecoin Foundation
\n

Kurt Opsahl is the Associate General Counsel for Cybersecurity and Civil Liberties Policy for the Filecoin Foundation. Formerly, Opsahl was the Deputy Executive Director and General Counsel of EFF. Opsahl was also the lead attorney on the Coders\' Rights Project, and continues to assist EFF with that work.

\n\nSpeakerBio:  Liz Wharton, Founder at Silver Key Strategies
\n

Elizabeth (Liz) Wharton leverages two decades of legal, public policy, and business experience to build and scale cybersecurity and threat intelligence focused companies. Prior experience includes leading a third-party risk threat intelligence platform startup and serving as Atlanta\'s Senior Attorney overseeing technology policy and projects for the Airport and on it\'s ransomware incident immediate IR team. Awarded the 2022 “Cybersecurity or Privacy Woman Law Professional of the Year” by the United Cybersecurity Alliance, Liz volunteers as a mentor and for the Rural Technology Fund (Board member), ICS Village\'s Hack the Capitol (Planning Committee), and DEFCON (CFP Review Board). She received her JD from Georgia State University and her BA from Virginia Tech.

\n\n\n\'',NULL,1297387),('2_Friday','13','12:00','14:59','Y','Contests','Other / See Description','\'The EFF Benefit Poker Tournament\'','\'Cindy Cohn,Jennifer Granick,Marcia Hofmann,Kurt Opsahl,Liz Wharton\'','Contests_238a63e17f048d2e645214a084357f6a','\'\'',NULL,1297388),('2_Friday','14','12:00','14:59','Y','Contests','Other / See Description','\'The EFF Benefit Poker Tournament\'','\'Cindy Cohn,Jennifer Granick,Marcia Hofmann,Kurt Opsahl,Liz Wharton\'','Contests_238a63e17f048d2e645214a084357f6a','\'\'',NULL,1297389),('2_Friday','10','10:30','11:30','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'DCNextGen Opening Ceremonies\'','\'BiaSciLab\'','Creator Talks_26ef431125ab3ed30a1432940d9a3338','\'Title: DCNextGen Opening Ceremonies
\nTags: DCNextGen | Creator Talk/Panel | Youth
\nWhen: Friday, Aug 7, 10:30 - 11:30 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Come pick up your DCNextGen electronic badge and swag! Get a preview of all the upcoming activities and adventures. We\'ll also show you how to use your new badge in order to participate in all of our cool ctf challenges around the conference!

\n\nSpeakerBio:  BiaSciLab
\nNo BIO available
\n\n\'',NULL,1297390),('2_Friday','11','10:30','11:30','Y','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'DCNextGen Opening Ceremonies\'','\'BiaSciLab\'','Creator Talks_26ef431125ab3ed30a1432940d9a3338','\'\'',NULL,1297391),('2_Friday','12','12:00','12:45','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Cryptographer Recruitment: Crack the Substitution Cipher\'','\'Bradán Lane\'','Creator Events_39144b6f78cd7d7706de10ae09031dd3','\'Title: Cryptographer Recruitment: Crack the Substitution Cipher
\nTags: DCNextGen | Creator Event/Activity | Youth
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

You’re a Cryptographer When Jumbled Letters are Exciting, Not Scary! The substitution cipher is a game of mathematics and patterns. With basic skills (or online tools) ciphers are easy to decipher. Don\'t let them fool you! Attendees will need some paper, a writing device, and access to the Substitutor web app.

\n\nSpeakerBio:  Bradán Lane
\nNo BIO available
\n\n\'',NULL,1297392),('2_Friday','13','13:00','13:30','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Locked Out? Let\'s Fix That: An Introduction to the Art of Lockpicking\'','\'Greg Anderson\'','Creator Events_dc29c3f6fd9273fdfa3a4551a39c6eea','\'Title: Locked Out? Let\'s Fix That: An Introduction to the Art of Lockpicking
\nTags: DCNextGen | Creator Event/Activity | Youth
\nWhen: Friday, Aug 7, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Ever wondered what\'s actually happening inside that padlock when you turn the key? This hands-on class pulls back the curtain on one of the oldest security technologies humans ever built — and shows you exactly how (and why) it can be defeated. You\'ll get the fundamentals, then the lab to experiment and learn, with several individuals around to help guide you and answer questions

\n\nSpeakerBio:  Greg Anderson
\nNo BIO available
\n\n\'',NULL,1297393),('2_Friday','14','14:00','14:45','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Hack the Airwaves – Embedded Wireless for Next-Gen Hackers\'','\'Adventures of Illya\'','Creator Talks_a2ba950007aee9efe39b34341ab0fe79','\'Title: Hack the Airwaves – Embedded Wireless for Next-Gen Hackers
\nTags: DCNextGen | Creator Talk/Panel | Youth
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Win an AWOK Dual C5 just by showing up! Join Adventures of Illya for Hack the Airwaves! Explore wireless technology with live demos featuring the AWOK Dual C5, ByteShield, H4M PortaPack, Flipper Zero, ESP32 boards, LoRa, RFID, NFC, and CC1101. Learn how these technologies work, ask questions, and get inspired to build your own projects.

\n\nSpeakerBio:  Adventures of Illya
\nNo BIO available
\n\n\'',NULL,1297394),('2_Friday','15','15:00','15:45','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Level Up - Could your Gaming Talents be Perfect for a Career in Cyber Security?\'','\'The Hacking Games\'','Creator Talks_3f5db953d4c3d7643f4ef4b62dfef41b','\'Title: Level Up - Could your Gaming Talents be Perfect for a Career in Cyber Security?
\nTags: DCNextGen | Creator Talk/Panel | Youth
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Did you know the skills that make you good at Fortnite or Minecraft are the same ones the cybersecurity industry needs?\nHosted by The Hacking Games CEO Fergus Hay, this panel explores how gaming skills can become career opportunities. Fergus is joined by Lorne Rolinson, who helped build HAPTAI—the Hacking Aptitude AI platform that maps gaming skills to cybersecurity career paths; Ricky Handschumacher, who started gaming on Halo forums and fell down the wrong path into hacker criminal activity; and BiaSciLab, who started hacking at age 11 and now teaches ethical hacking through Girls Who Hack and DCNextGen. Together, they now work with The Hacking Games to help young gamers become ethical hackers. Ready to discover where your gaming skills could take you?

\n\nSpeakerBio:  The Hacking Games
\nNo BIO available
\n\n\'',NULL,1297395),('2_Friday','16','16:00','16:30','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Veilid- the Next Gen of privacy\'','\'medus4\'','Creator Talks_e20b64bab0c78f73133a6af7df993a26','\'Title: Veilid- the Next Gen of privacy
\nTags: DCNextGen | Creator Talk/Panel | Youth
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

In this talk, medus4 will go over how the data economy insidiously invades everyone\'s privacy, and how Veilid is helping fight back against that. Will include a brief lesson on the history of privacy software, and how Veilid can assist everyone (including youth!) to make a better internet for all!

\n\nSpeakerBio:  medus4
\nNo BIO available
\n\n\'',NULL,1297396),('2_Friday','17','17:00','17:45','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Welcome to your Airbnb, the key is under the mat -or- Alice and Bob with Padlocks\'','\'Gilgamesh\'','Creator Events_1eaf9f96ef2ad446a68bca255dd48219','\'Title: Welcome to your Airbnb, the key is under the mat -or- Alice and Bob with Padlocks
\nTags: DCNextGen | Creator Event/Activity | Youth
\nWhen: Friday, Aug 7, 17:00 - 17:45 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

We teach everyone how to verify “there’s a padlock” but there’s a lot of cool math behind that padlock, and we will show, with everyday props and actors, how modern cryptography works under the hood. Can we implement Diffie-Hellman with padlocks?\nInstead of memorizing complicated math, we’ll solve puzzles together as a team and reveal how computers securely exchange secrets, protect private information, and prove someone’s identity online. Along the way, you’ll recreate the ideas behind the same technologies used by websites, games, banks, and messaging apps. \nPrerequisites: none. All props are provided and participants will keep some props.

\n\nSpeakerBio:  Gilgamesh
\nNo BIO available
\n\n\'',NULL,1297397),('3_Saturday','10','10:00','10:30','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Intro to Scratch\'','\'N3rd H3Rder\'','Creator Events_869b0a910cbcf134ab00112bacb6be55','\'Title: Intro to Scratch
\nTags: DCNextGen | Creator Event/Activity | Youth
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Are you interested in learning to code but don’t know where to begin? This class introduces Scratch, a free visual programming language developed by MIT, and is intended for youth ages 8-16. Use real coding concepts and blocks to develop interactive stories, games, and animations. Come learn how to begin coding in a fun and engaging way and join in with millions of your new global peers. You will need a laptop with Chrome or Edge.

\n\nSpeakerBio:  N3rd H3Rder
\nNo BIO available
\n\n\'',NULL,1297398),('3_Saturday','11','11:00','11:45','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Meshpocalypse: Building Your Own Off-Grid Hacker Network\'','\'Adventures of Illya\'','Creator Events_3210d98257929cdca8ea9cbf9cccfa30','\'Title: Meshpocalypse: Building Your Own Off-Grid Hacker Network
\nTags: DCNextGen | Creator Event/Activity | Youth
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Join Adventures of Illya for Meshpocalypse! The internet goes down. Cell towers die. How do hackers still talk? In Meshpocalypse, we’ll use tiny radios and cheap hardware to build a mini off-grid network right in the room. You’ll learn how mesh networks work, try out Meshtastic, and send messages without Wi-Fi or cell data. Each attendee will help build and keep their own radio node device so they can keep experimenting after DEF CON.\nNo experience needed. Basic tech comfort helps but isn’t required. Defcon and I will provide all radios. Each attendee should bring a small USB-C power source (like a power bank or USB-C wall adapter) to power their device. Only 30 radio units available, first come first served.

\n\nSpeakerBio:  Adventures of Illya
\nNo BIO available
\n\n\'',NULL,1297399),('3_Saturday','12','12:00','12:30','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'AI and You: Staying Safe in the AI Era\'','\'Zoe Reid+Echo419\'','Creator Talks_7f25add9be564791cebf34e456ef8939','\'Title: AI and You: Staying Safe in the AI Era
\nTags: DCNextGen | Creator Talk/Panel | Youth
\nWhen: Saturday, Aug 8, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Wondering how hacking with AI takes place? Join us to find out along with tips on staying safe with some fun and laughs along the way! No prereqs necessary, just curiosity!

\n\nSpeakerBio:  Zoe Reid+Echo419
\nNo BIO available
\n\n\'',NULL,1297400),('3_Saturday','13','13:00','14:15','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Hacker Culture 101\'','\'medus4\'','Creator Events_45e12a6607c758b4529e9e7d615f17b6','\'Title: Hacker Culture 101
\nTags: DCNextGen | Creator Event/Activity | Youth
\nWhen: Saturday, Aug 8, 13:00 - 14:15 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Learn about the K-Rad side of hacking, from media representations in movies and tv shows, to hacker fashion throughout the years (we wear more than black hoodies!). In this session, we will also cover two iconic pieces of hacker culture- Handles and stickers, with an opportunity to make your own stickers and choose your unique handle! If you wanna jam with the console cowboys in cyberspace, this is the event for you!

\n\nSpeakerBio:  medus4
\nNo BIO available
\n\n\'',NULL,1297401),('3_Saturday','14','13:00','14:15','Y','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Hacker Culture 101\'','\'medus4\'','Creator Events_45e12a6607c758b4529e9e7d615f17b6','\'\'',NULL,1297402),('3_Saturday','15','15:00','15:40','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'AMA with EFF\'','\'EFF\'','Creator Talks_41416e8cf1e645b3e11f52358e91e391','\'Title: AMA with EFF
\nTags: DCNextGen | Creator Talk/Panel | Youth
\nWhen: Saturday, Aug 8, 15:00 - 15:40 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Learn about EFF’s work protecting your right to send memes to your friends, watch videos online, and go outside without surveillance. Ask questions about EFF\'s work, from how we fight bad laws in Congress to how we take on big tech companies. Whether you’re curious about technology, want to know how to protect your privacy, or just want to know what a nonprofit org actually does, this is your chance to ask us anything.

\n\nSpeakerBio:  EFF
\nNo BIO available
\n\n\'',NULL,1297403),('3_Saturday','16','16:00','16:40','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'3D Printing: Data, Discretion, and Design\'','\'Evan\'','Creator Talks_4ea850e968a0c50da943156573ecbb99','\'Title: 3D Printing: Data, Discretion, and Design
\nTags: DCNextGen | Creator Talk/Panel | Youth
\nWhen: Saturday, Aug 8, 16:00 - 16:40 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

The history of hacking is tied to both software and hardware. In both cases, losing the ability to fix and adjust the things you own goes against the core of what we do. For software related projects, you can edit a program or use an open source solution, but for hardware we use 3D printing! In this class you\'ll learn about the origins of 3D printing and how everyday tools you have at home can pair with a machine to make the items you\'ve purchased on your own!

\n\nSpeakerBio:  Evan
\nNo BIO available
\n\n\'',NULL,1297404),('3_Saturday','17','17:00','17:45','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Objectively Awesome Robots: A Hands-On Introduction to Python Classes and Objects\'','\'4ng3lhacker\'','Creator Events_b5e4e17e360036ec320067a7e5a75eec','\'Title: Objectively Awesome Robots: A Hands-On Introduction to Python Classes and Objects
\nTags: DCNextGen | Creator Event/Activity | Youth
\nWhen: Saturday, Aug 8, 17:00 - 17:45 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Python has rules and structure like any language, but we’re skipping the boring grammar lesson. You’ll jump straight into building a robot that appears on your screen and comes to life as you code it. As you customize and experiment, you’ll naturally learn classes and objects by using them to define your robot’s appearance and behavior. At the end, we’ll finish with a Kahoot challenge where you’ll test your new skills and compete for prizes.

\n\n

Requirements/Prerequisites:\nA laptop with a USB port (for workshop files)\nPython 3 installed and able to run\nVS Code or another IDE that supports Jupyter Notebooks\nSome basic Python experience is helpful, but not required, we’ll provide a cheat sheet to help you along

\n\nSpeakerBio:  4ng3lhacker
\nNo BIO available
\n\n\'',NULL,1297405),('4_Sunday','10','10:00','10:59','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'Cloud Village CTF: Three Azure Warmups\'','\'Cloud Village\'','Creator Events_b278f7b4b1d9cd1a89a964a812cac3cb','\'Title: Cloud Village CTF: Three Azure Warmups
\nTags: DCNextGen | Creator Event/Activity | Youth
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Welcome to Apex Park, where cloud-security mistakes are causing trouble throughout the park!\nParticipants will investigate three beginner-friendly Azure challenges involving an exposed gift shop, an overpowered day pass, and an unlocked control room. They will inspect websites, investigate cloud-storage permissions, follow clues, and recover hidden flags.\nNo access to a real Azure account or the challenge infrastructure is required. Participants interact only with intentionally vulnerable CTF resources created for learning.

\n\nSpeakerBio:  Cloud Village
\nNo BIO available
\n\n\'',NULL,1297406),('4_Sunday','12','12:00','12:30','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'A Teen BadgeMaker\'s Journey of Creation\'','\'World Machine\'','Creator Talks_97dc854a54cc833665ef00085de404be','\'Title: A Teen BadgeMaker\'s Journey of Creation
\nTags: DCNextGen | Creator Talk/Panel | Youth
\nWhen: Sunday, Aug 9, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

Have you ever wanted to make your own electronic badges, but not known where to start? Come listen to a teen BadgeMaker talk about his journey from zero to creating SpaceBadge (DC33) and Clip-Boy (DC34)! Enjoy stories of success and otherwise, all to help you on your path into the BadgeMaking space. Prepare yourself to create the next great badge!

\n\nSpeakerBio:  World Machine
\nNo BIO available
\n\n\'',NULL,1297407),('4_Sunday','13','13:30','14:30','N','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'DCNextGen Closing Ceremonies\'','\'BiaSciLab\'','Creator Talks_094a9161abf2f9f23d446641e517ac2f','\'Title: DCNextGen Closing Ceremonies
\nTags: DCNextGen | Creator Talk/Panel | Youth
\nWhen: Sunday, Aug 9, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 3 W316 (DC NextGen) - Map
\n
\nDescription:
\n

And just like that, it\'s a wrap! While we\'re sad to see the fun end, we want to give everyone one last big thank you.

\n\n

Join us to say goodbye to new friends and hear about all the cool plans we have for next year. We\'ll also be handing out prizes for our DCNextGen Badge CTF — you must be present to win!

\n\nSpeakerBio:  BiaSciLab
\nNo BIO available
\n\n\'',NULL,1297408),('4_Sunday','14','13:30','14:30','Y','DCNextGen','LVCCW Level 3 W316 (DC NextGen)','\'DCNextGen Closing Ceremonies\'','\'BiaSciLab\'','Creator Talks_094a9161abf2f9f23d446641e517ac2f','\'\'',NULL,1297409),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_738ab3fb247ad87c469ccc58ac44bfe6','\'Title: DEF CON Scavenger Hunt
\nTags: DEF CON Scavenger Hunt | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt) - Map
\n
\nDescription:
\n

Whether you\'re a seasoned DEF CON veteran or a curious newcomer, the DEF CON Scavenger Hunt promises to challenge your skills, tickle your wits, and ignite your hacker spirit. Our list is a portal to mystery, mischief, and mayhem. Assemble your team of up to 5 members, interpret the items, and submit your efforts at the booth to our esteemed judges. Go beyond the basics for bonus points. Legends are born here.

\n\n

The DEF CON Scavenger Hunt is open to everyone, regardless of skill level or experience, no pre-qualifying necessary. We strive to maintain the balance of a low barrier to entry while providing a challenge that many are eager to take on. Casual players should not be overwhelmed by the list, find a handful of items and have fun. If you are looking to win however, you will need to fully immerse yourself in the DEF CON Scavenger Hunt. Let\'s make some memories together.

\n\n

Remember that it\'s not just about fame, glory, or boxes of swag; the true allure is the camaraderie of fellow hackers, the knowledge that you\'ve etched your mark on DEF CON history, and the ultimate badge of honor: bragging rights. Nothing says \"I\'m a hacker\" quite like being triumphant at the DEF CON Scavenger Hunt.

\n\n

Participant Prerequisites

\n\n

No, we work very hard to maintain a very low barrier to entry. If anything is required for an item, they should be able to find a fellow hacker with it that would be willing to assist them with their item.

\n\nLinks:
    Website - https://www.defconscavhunt.com/
\n    Mastodon (@DEFCONScavHunt@defcon.social) - https://defcon.social/@DEFCONScavHunt
\n\'',NULL,1297410),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_738ab3fb247ad87c469ccc58ac44bfe6','\'\'',NULL,1297411),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_738ab3fb247ad87c469ccc58ac44bfe6','\'\'',NULL,1297412),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_738ab3fb247ad87c469ccc58ac44bfe6','\'\'',NULL,1297413),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_738ab3fb247ad87c469ccc58ac44bfe6','\'\'',NULL,1297414),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_738ab3fb247ad87c469ccc58ac44bfe6','\'\'',NULL,1297415),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_738ab3fb247ad87c469ccc58ac44bfe6','\'\'',NULL,1297416),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_738ab3fb247ad87c469ccc58ac44bfe6','\'\'',NULL,1297417),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_f1d4cde1d45b3058ae2cc2382ff30c3d','\'Title: DEF CON Scavenger Hunt
\nTags: DEF CON Scavenger Hunt | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt) - Map
\n
\nDescription:
\n

Whether you\'re a seasoned DEF CON veteran or a curious newcomer, the DEF CON Scavenger Hunt promises to challenge your skills, tickle your wits, and ignite your hacker spirit. Our list is a portal to mystery, mischief, and mayhem. Assemble your team of up to 5 members, interpret the items, and submit your efforts at the booth to our esteemed judges. Go beyond the basics for bonus points. Legends are born here.

\n\n

The DEF CON Scavenger Hunt is open to everyone, regardless of skill level or experience, no pre-qualifying necessary. We strive to maintain the balance of a low barrier to entry while providing a challenge that many are eager to take on. Casual players should not be overwhelmed by the list, find a handful of items and have fun. If you are looking to win however, you will need to fully immerse yourself in the DEF CON Scavenger Hunt. Let\'s make some memories together.

\n\n

Remember that it\'s not just about fame, glory, or boxes of swag; the true allure is the camaraderie of fellow hackers, the knowledge that you\'ve etched your mark on DEF CON history, and the ultimate badge of honor: bragging rights. Nothing says \"I\'m a hacker\" quite like being triumphant at the DEF CON Scavenger Hunt.

\n\n

Participant Prerequisites

\n\n

No, we work very hard to maintain a very low barrier to entry. If anything is required for an item, they should be able to find a fellow hacker with it that would be willing to assist them with their item.

\n\nLinks:
    Website - https://www.defconscavhunt.com/
\n    Mastodon (@DEFCONScavHunt@defcon.social) - https://defcon.social/@DEFCONScavHunt
\n\'',NULL,1297418),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_f1d4cde1d45b3058ae2cc2382ff30c3d','\'\'',NULL,1297419),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_b2f935b2976fd583ccba8261f536c0e2','\'Title: DEF CON Scavenger Hunt
\nTags: DEF CON Scavenger Hunt | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt) - Map
\n
\nDescription:
\n

Whether you\'re a seasoned DEF CON veteran or a curious newcomer, the DEF CON Scavenger Hunt promises to challenge your skills, tickle your wits, and ignite your hacker spirit. Our list is a portal to mystery, mischief, and mayhem. Assemble your team of up to 5 members, interpret the items, and submit your efforts at the booth to our esteemed judges. Go beyond the basics for bonus points. Legends are born here.

\n\n

The DEF CON Scavenger Hunt is open to everyone, regardless of skill level or experience, no pre-qualifying necessary. We strive to maintain the balance of a low barrier to entry while providing a challenge that many are eager to take on. Casual players should not be overwhelmed by the list, find a handful of items and have fun. If you are looking to win however, you will need to fully immerse yourself in the DEF CON Scavenger Hunt. Let\'s make some memories together.

\n\n

Remember that it\'s not just about fame, glory, or boxes of swag; the true allure is the camaraderie of fellow hackers, the knowledge that you\'ve etched your mark on DEF CON history, and the ultimate badge of honor: bragging rights. Nothing says \"I\'m a hacker\" quite like being triumphant at the DEF CON Scavenger Hunt.

\n\n

Participant Prerequisites

\n\n

No, we work very hard to maintain a very low barrier to entry. If anything is required for an item, they should be able to find a fellow hacker with it that would be willing to assist them with their item.

\n\nLinks:
    Website - https://www.defconscavhunt.com/
\n    Mastodon (@DEFCONScavHunt@defcon.social) - https://defcon.social/@DEFCONScavHunt
\n\'',NULL,1297420),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_b2f935b2976fd583ccba8261f536c0e2','\'\'',NULL,1297421),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_b2f935b2976fd583ccba8261f536c0e2','\'\'',NULL,1297422),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_b2f935b2976fd583ccba8261f536c0e2','\'\'',NULL,1297423),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_b2f935b2976fd583ccba8261f536c0e2','\'\'',NULL,1297424),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_b2f935b2976fd583ccba8261f536c0e2','\'\'',NULL,1297425),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_b2f935b2976fd583ccba8261f536c0e2','\'\'',NULL,1297426),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 104 (DEF CON Scavenger Hunt)','\'DEF CON Scavenger Hunt\'','\'\'','Contests_b2f935b2976fd583ccba8261f536c0e2','\'\'',NULL,1297427),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_deaa1a220e301e2bba043bee04e55f1a','\'Title: Beer Chilling Contraption Contest
\nTags: Beer Chilling Contraption Contest | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest) - Map
\n
\nDescription:
\n

It’s the 21st year of the BCCC and it’s the Beer Chilling Contraption Contest this year! We can finally drink! No more beverage, we are drinking beer now, and boy do we need one. This year we thought we would mix it up and have cold beer and you all could try your hand at warming it. Unfortunately, the guys in charge of getting the ice got a bit too tan walking in this Vegas sun. A different kind of ICE deported them to Botswana and in the ensuing chaos the beverage was left outside and its warm again. Fortunately for everyone involved, WW3 and the inevitable nuclear winter will finally solve the warm beer problem -- well at least temperature-wise. It might be a little HOT in the gamma spectrum. But while we wait for Pooh Bear, BiBi, Putler, and or the Cheeto to kick this global cooling contraption off, its up to us to chill this beer.

\n\n

You will cool the beer we give you in a red solo cup as quickly as possible to 34 degrees F. You may not alter the beer by mixing it with ice, dry or otherwise. You may bring a device you created or build your own at the convention. There are some great prizes waiting, mostly what I have lying around and don\'t want to take home. There are some additional rules, check the DEFCON forums or the poster board at the contest!

\n\n

In conclusion, it’s not just a warm beverage—it’s a testament to the rich tapestry of societal collapse, seamlessly navigating the multifaceted landscape of your broken contraption.

\n\n

Participant Prerequisites

\n\n
    \n
  • A commitment to the sanctity of the unadulterated beverage.
  • \n
  • A complete disregard for the health a safety of one\'s self, good design principals, and the laws of physics generally.
  • \n
\n\nLinks:
    Website - https://dcbccc.com/
\n\'',NULL,1297428),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_deaa1a220e301e2bba043bee04e55f1a','\'\'',NULL,1297429),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_315faa4d98b00695ee5324546fa84c35','\'Title: Beer Chilling Contraption Contest
\nTags: Beer Chilling Contraption Contest | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest) - Map
\n
\nDescription:
\n

It’s the 21st year of the BCCC and it’s the Beer Chilling Contraption Contest this year! We can finally drink! No more beverage, we are drinking beer now, and boy do we need one. This year we thought we would mix it up and have cold beer and you all could try your hand at warming it. Unfortunately, the guys in charge of getting the ice got a bit too tan walking in this Vegas sun. A different kind of ICE deported them to Botswana and in the ensuing chaos the beverage was left outside and its warm again. Fortunately for everyone involved, WW3 and the inevitable nuclear winter will finally solve the warm beer problem -- well at least temperature-wise. It might be a little HOT in the gamma spectrum. But while we wait for Pooh Bear, BiBi, Putler, and or the Cheeto to kick this global cooling contraption off, its up to us to chill this beer.

\n\n

You will cool the beer we give you in a red solo cup as quickly as possible to 34 degrees F. You may not alter the beer by mixing it with ice, dry or otherwise. You may bring a device you created or build your own at the convention. There are some great prizes waiting, mostly what I have lying around and don\'t want to take home. There are some additional rules, check the DEFCON forums or the poster board at the contest!

\n\n

In conclusion, it’s not just a warm beverage—it’s a testament to the rich tapestry of societal collapse, seamlessly navigating the multifaceted landscape of your broken contraption.

\n\n

Participant Prerequisites

\n\n
    \n
  • A commitment to the sanctity of the unadulterated beverage.
  • \n
  • A complete disregard for the health a safety of one\'s self, good design principals, and the laws of physics generally.
  • \n
\n\nLinks:
    Website - https://dcbccc.com/
\n\'',NULL,1297430),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_315faa4d98b00695ee5324546fa84c35','\'\'',NULL,1297431),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_315faa4d98b00695ee5324546fa84c35','\'\'',NULL,1297432),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_315faa4d98b00695ee5324546fa84c35','\'\'',NULL,1297433),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_315faa4d98b00695ee5324546fa84c35','\'\'',NULL,1297434),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_315faa4d98b00695ee5324546fa84c35','\'\'',NULL,1297435),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_315faa4d98b00695ee5324546fa84c35','\'\'',NULL,1297436),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_315faa4d98b00695ee5324546fa84c35','\'\'',NULL,1297437),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_cbb6e62d3ffe2b19eb773820223915a8','\'Title: Beer Chilling Contraption Contest
\nTags: Beer Chilling Contraption Contest | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest) - Map
\n
\nDescription:
\n

It’s the 21st year of the BCCC and it’s the Beer Chilling Contraption Contest this year! We can finally drink! No more beverage, we are drinking beer now, and boy do we need one. This year we thought we would mix it up and have cold beer and you all could try your hand at warming it. Unfortunately, the guys in charge of getting the ice got a bit too tan walking in this Vegas sun. A different kind of ICE deported them to Botswana and in the ensuing chaos the beverage was left outside and its warm again. Fortunately for everyone involved, WW3 and the inevitable nuclear winter will finally solve the warm beer problem -- well at least temperature-wise. It might be a little HOT in the gamma spectrum. But while we wait for Pooh Bear, BiBi, Putler, and or the Cheeto to kick this global cooling contraption off, its up to us to chill this beer.

\n\n

You will cool the beer we give you in a red solo cup as quickly as possible to 34 degrees F. You may not alter the beer by mixing it with ice, dry or otherwise. You may bring a device you created or build your own at the convention. There are some great prizes waiting, mostly what I have lying around and don\'t want to take home. There are some additional rules, check the DEFCON forums or the poster board at the contest!

\n\n

In conclusion, it’s not just a warm beverage—it’s a testament to the rich tapestry of societal collapse, seamlessly navigating the multifaceted landscape of your broken contraption.

\n\n

Participant Prerequisites

\n\n
    \n
  • A commitment to the sanctity of the unadulterated beverage.
  • \n
  • A complete disregard for the health a safety of one\'s self, good design principals, and the laws of physics generally.
  • \n
\n\nLinks:
    Website - https://dcbccc.com/
\n\'',NULL,1297438),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_cbb6e62d3ffe2b19eb773820223915a8','\'\'',NULL,1297439),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_cbb6e62d3ffe2b19eb773820223915a8','\'\'',NULL,1297440),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_cbb6e62d3ffe2b19eb773820223915a8','\'\'',NULL,1297441),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_cbb6e62d3ffe2b19eb773820223915a8','\'\'',NULL,1297442),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_cbb6e62d3ffe2b19eb773820223915a8','\'\'',NULL,1297443),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_cbb6e62d3ffe2b19eb773820223915a8','\'\'',NULL,1297444),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 202 (Beer Chilling Contraption Contest)','\'Beer Chilling Contraption Contest\'','\'\'','Contests_cbb6e62d3ffe2b19eb773820223915a8','\'\'',NULL,1297445),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5f61554a18f94d014e676bf6e3a2e177','\'Title: Crack Me If You Can 2026
\nTags: Crack Me If You Can 2026 | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 106 (Crack me if you can) - Map
\n
\nDescription:
\n

Time is of the essence! You will have 48 hours to crack as many hashes and files as possible.

\n\n

Pamama, a US-based data broker had a massive data breach. Profiles on over a billion people, containing all the information amassed about them. It is alleged that the company siphoned records from different government agencies around the world, as well. The dump was encrypted, and regulators are downplaying the breach claiming no damage was done. A bill has been fast-tracked in Congress to exempt Pamama from any investigations, including illegally shield them from GDPR violations. This led to accusations that Pamama has bought or blackmailed members of congress.

\n\n

Crack the staff\'s accounts and encrypted files to demonstrate the extent of the exposure and the need for individuals to get restitution and compensation, and to find smoking gun evidence of collusion so that the corruption can be fully exposed before the legislation goes forward.

\n\n

Participant Prerequisites

\n\n

Open to all, but pre-registration is recommended. Compete in the Street class for individuals or small teams, or in Pro if you do not want to sleep all weekend. Check out past years\' contests at https://contest.korelogic.com/ , or the Password Village site for an introduction to password cracking and links to other resources: https://passwordvillage.org/

\n\n

Pre-Qualifications

\n\n

None.

\n\nLinks:
    Website - https://contest-2026.korelogic.com/
\n    Mastodon (@CrackMeIfYouCan@infosec.exchange) - https://infosec.exchange/@CrackMeIfYouCan
\n\'',NULL,1297446),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5f61554a18f94d014e676bf6e3a2e177','\'\'',NULL,1297447),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5f61554a18f94d014e676bf6e3a2e177','\'\'',NULL,1297448),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5f61554a18f94d014e676bf6e3a2e177','\'\'',NULL,1297449),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5f61554a18f94d014e676bf6e3a2e177','\'\'',NULL,1297450),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5f61554a18f94d014e676bf6e3a2e177','\'\'',NULL,1297451),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5f61554a18f94d014e676bf6e3a2e177','\'\'',NULL,1297452),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5f61554a18f94d014e676bf6e3a2e177','\'\'',NULL,1297453),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_e5ebf9b151b045a88c8e367596fbb8bf','\'Title: Crack Me If You Can 2026
\nTags: Crack Me If You Can 2026 | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 106 (Crack me if you can) - Map
\n
\nDescription:
\n

Time is of the essence! You will have 48 hours to crack as many hashes and files as possible.

\n\n

Pamama, a US-based data broker had a massive data breach. Profiles on over a billion people, containing all the information amassed about them. It is alleged that the company siphoned records from different government agencies around the world, as well. The dump was encrypted, and regulators are downplaying the breach claiming no damage was done. A bill has been fast-tracked in Congress to exempt Pamama from any investigations, including illegally shield them from GDPR violations. This led to accusations that Pamama has bought or blackmailed members of congress.

\n\n

Crack the staff\'s accounts and encrypted files to demonstrate the extent of the exposure and the need for individuals to get restitution and compensation, and to find smoking gun evidence of collusion so that the corruption can be fully exposed before the legislation goes forward.

\n\n

Participant Prerequisites

\n\n

Open to all, but pre-registration is recommended. Compete in the Street class for individuals or small teams, or in Pro if you do not want to sleep all weekend. Check out past years\' contests at https://contest.korelogic.com/ , or the Password Village site for an introduction to password cracking and links to other resources: https://passwordvillage.org/

\n\n

Pre-Qualifications

\n\n

None.

\n\nLinks:
    Website - https://contest-2026.korelogic.com/
\n    Mastodon (@CrackMeIfYouCan@infosec.exchange) - https://infosec.exchange/@CrackMeIfYouCan
\n\'',NULL,1297454),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_e5ebf9b151b045a88c8e367596fbb8bf','\'\'',NULL,1297455),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5265bdab12dc80d0ae4c58d72f85d8e1','\'Title: Crack Me If You Can 2026
\nTags: Crack Me If You Can 2026 | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 106 (Crack me if you can) - Map
\n
\nDescription:
\n

Time is of the essence! You will have 48 hours to crack as many hashes and files as possible.

\n\n

Pamama, a US-based data broker had a massive data breach. Profiles on over a billion people, containing all the information amassed about them. It is alleged that the company siphoned records from different government agencies around the world, as well. The dump was encrypted, and regulators are downplaying the breach claiming no damage was done. A bill has been fast-tracked in Congress to exempt Pamama from any investigations, including illegally shield them from GDPR violations. This led to accusations that Pamama has bought or blackmailed members of congress.

\n\n

Crack the staff\'s accounts and encrypted files to demonstrate the extent of the exposure and the need for individuals to get restitution and compensation, and to find smoking gun evidence of collusion so that the corruption can be fully exposed before the legislation goes forward.

\n\n

Participant Prerequisites

\n\n

Open to all, but pre-registration is recommended. Compete in the Street class for individuals or small teams, or in Pro if you do not want to sleep all weekend. Check out past years\' contests at https://contest.korelogic.com/ , or the Password Village site for an introduction to password cracking and links to other resources: https://passwordvillage.org/

\n\n

Pre-Qualifications

\n\n

None.

\n\nLinks:
    Website - https://contest-2026.korelogic.com/
\n    Mastodon (@CrackMeIfYouCan@infosec.exchange) - https://infosec.exchange/@CrackMeIfYouCan
\n\'',NULL,1297456),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5265bdab12dc80d0ae4c58d72f85d8e1','\'\'',NULL,1297457),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5265bdab12dc80d0ae4c58d72f85d8e1','\'\'',NULL,1297458),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5265bdab12dc80d0ae4c58d72f85d8e1','\'\'',NULL,1297459),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5265bdab12dc80d0ae4c58d72f85d8e1','\'\'',NULL,1297460),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5265bdab12dc80d0ae4c58d72f85d8e1','\'\'',NULL,1297461),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5265bdab12dc80d0ae4c58d72f85d8e1','\'\'',NULL,1297462),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 106 (Crack me if you can)','\'Crack Me If You Can 2026\'','\'\'','Contests_5265bdab12dc80d0ae4c58d72f85d8e1','\'\'',NULL,1297463),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_d8bfed441dae7af3cf815b66f408cb0c','\'Title: Darknet-NG
\nTags: Darknet-NG | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 105 (Darknet-NG) - Map
\n
\nDescription:
\n

Darknet-NG is an Alternate Reality Game (ARG), where the players take on the Persona of an Agent who is sent on Quests to learn real skills and gain in-game points. If this is your first time at DEF CON, this is a great place to start, because we assume no prior knowledge. Building from basic concepts, we teach agents about a range of topics from Lock-picking, to using and decoding ciphers, to Electronics 101, just to name a few, all while also helping to connect them to the larger DEF CON Community. The \"Learning Quests\" help the agent gather knowledge from all across the other villages at the conference, while the \"Challenge Quests\" help hone their skills! Sunday Morning there is a BOSS FIGHT where the Agents must use their combined skills as a community and take on that year\'s final challenge! There is a whole skill tree of personal knowledge to obtain, community to connect with and memories to make! To get started, check out our site https://darknet-ng.network and join our growing Community!

\n\n

Participant Prerequisites

\n\n

Prerequisites for competing in the contest would require a device with access to a web browser like a Phone, Tablet, Laptop.

\n\nLinks:
    Mastodon (@DarknetNG@defcon.social) - https://defcon.social/@DarknetNG
\n    Website - https://darknet-ng.network/
\n\'',NULL,1297464),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_d8bfed441dae7af3cf815b66f408cb0c','\'\'',NULL,1297465),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_8ba3fd6ae51e6be0934936f9e76189d6','\'Title: Darknet-NG
\nTags: Darknet-NG | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 105 (Darknet-NG) - Map
\n
\nDescription:
\n

Darknet-NG is an Alternate Reality Game (ARG), where the players take on the Persona of an Agent who is sent on Quests to learn real skills and gain in-game points. If this is your first time at DEF CON, this is a great place to start, because we assume no prior knowledge. Building from basic concepts, we teach agents about a range of topics from Lock-picking, to using and decoding ciphers, to Electronics 101, just to name a few, all while also helping to connect them to the larger DEF CON Community. The \"Learning Quests\" help the agent gather knowledge from all across the other villages at the conference, while the \"Challenge Quests\" help hone their skills! Sunday Morning there is a BOSS FIGHT where the Agents must use their combined skills as a community and take on that year\'s final challenge! There is a whole skill tree of personal knowledge to obtain, community to connect with and memories to make! To get started, check out our site https://darknet-ng.network and join our growing Community!

\n\n

Participant Prerequisites

\n\n

Prerequisites for competing in the contest would require a device with access to a web browser like a Phone, Tablet, Laptop.

\n\nLinks:
    Mastodon (@DarknetNG@defcon.social) - https://defcon.social/@DarknetNG
\n    Website - https://darknet-ng.network/
\n\'',NULL,1297466),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_8ba3fd6ae51e6be0934936f9e76189d6','\'\'',NULL,1297467),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_8ba3fd6ae51e6be0934936f9e76189d6','\'\'',NULL,1297468),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_8ba3fd6ae51e6be0934936f9e76189d6','\'\'',NULL,1297469),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_8ba3fd6ae51e6be0934936f9e76189d6','\'\'',NULL,1297470),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_8ba3fd6ae51e6be0934936f9e76189d6','\'\'',NULL,1297471),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_8ba3fd6ae51e6be0934936f9e76189d6','\'\'',NULL,1297472),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_8ba3fd6ae51e6be0934936f9e76189d6','\'\'',NULL,1297473),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_7a59d510d8036265cb11a7c4a066a6b5','\'Title: Darknet-NG
\nTags: Darknet-NG | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 105 (Darknet-NG) - Map
\n
\nDescription:
\n

Darknet-NG is an Alternate Reality Game (ARG), where the players take on the Persona of an Agent who is sent on Quests to learn real skills and gain in-game points. If this is your first time at DEF CON, this is a great place to start, because we assume no prior knowledge. Building from basic concepts, we teach agents about a range of topics from Lock-picking, to using and decoding ciphers, to Electronics 101, just to name a few, all while also helping to connect them to the larger DEF CON Community. The \"Learning Quests\" help the agent gather knowledge from all across the other villages at the conference, while the \"Challenge Quests\" help hone their skills! Sunday Morning there is a BOSS FIGHT where the Agents must use their combined skills as a community and take on that year\'s final challenge! There is a whole skill tree of personal knowledge to obtain, community to connect with and memories to make! To get started, check out our site https://darknet-ng.network and join our growing Community!

\n\n

Participant Prerequisites

\n\n

Prerequisites for competing in the contest would require a device with access to a web browser like a Phone, Tablet, Laptop.

\n\nLinks:
    Mastodon (@DarknetNG@defcon.social) - https://defcon.social/@DarknetNG
\n    Website - https://darknet-ng.network/
\n\'',NULL,1297474),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_7a59d510d8036265cb11a7c4a066a6b5','\'\'',NULL,1297475),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_7a59d510d8036265cb11a7c4a066a6b5','\'\'',NULL,1297476),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_7a59d510d8036265cb11a7c4a066a6b5','\'\'',NULL,1297477),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_7a59d510d8036265cb11a7c4a066a6b5','\'\'',NULL,1297478),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_7a59d510d8036265cb11a7c4a066a6b5','\'\'',NULL,1297479),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_7a59d510d8036265cb11a7c4a066a6b5','\'\'',NULL,1297480),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 105 (Darknet-NG)','\'Darknet-NG\'','\'\'','Contests_7a59d510d8036265cb11a7c4a066a6b5','\'\'',NULL,1297481),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_60a22e48d517fbe7fc920a983fb317f9','\'Title: $unL1ght Sh4d0w5
\nTags: $unL1ght Sh4d0w5 | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5) - Map
\n
\nDescription:
\n

“$unL1ght Sh4d0w5”: The Nirubi Challenge — Prove Your Agency

\n\n

Systems shape the world.

\n\n

Algorithms decide.

\n\n

Policies enforce.

\n\n

Machines execute.

\n\n

Most people live inside those systems.

\n\n

Hackers change them.

\n\n

At DEF CON 34, where the theme is Agency, the question isn’t whether systems have vulnerabilities.

\n\n

The question is who has the power to act on them.

\n\n

Welcome to “$unL1ght Sh4d0w5: The Nirubi Challenge.”

\n\n

Instead of hiding the system, we give you the blueprint:\n- A production-ready Linux cyber-physical system\n- Known vulnerabilities\n- A working proof-of-concept exploit\n- Full system disclosure

\n\n

No mystery.

\n\n

No guessing.

\n\n

Just a cyber-physical system — and the opportunity to exercise your agency over it.

\n\n

The Nirubi Mandate

\n\n

Nirubi is an ancient Tamil word meaning “to prove.”

\n\n

Not with theory.

\n\n

Not with writeups.

\n\n

With execution.

\n\n

You’ve been given the knowledge.

\n\n

Now prove you have the agency to act on it.

\n\n

The Challenge

\n\n

Your objective is simple:

\n\n

Achieve remote code execution and deploy a malicious payload (e.g., ransomware payload that encrypts a sensitive file, command and control payload that takes over the cyber-physical system etc.).

\n\n

Two phases.

\n\n

Part 1 — Sh4d0w5 Recon

\n\n

Extend the provided exploit chain and deliver a working malicious payload.

\n\n

You have the vulnerabilities.

\n\n

Now show us you can use them.

\n\n

Part 2 — $unL1ght Horizon

\n\n

If you complete Part 1, the system returns — hardened with proprietary defensive technology designed to disrupt your attack path.

\n\n

Same objective.

\n\n

New resistance.

\n\n

Adapt your exploit and land the payload again.

\n\n

The Prize

\n\n

The first contestant to complete both phases wins: $10,000

\n\n

Bring $unL1ght into the Sh4d0w5.

\n\n

What Makes This Different

\n\n

Most contests hide the system. We don’t. You’ll receive:\n- Full system configuration\n- Vulnerability details\n- A working proof-of-concept exploit

\n\n

No blind recon. No guessing. Just a system, its weaknesses, and your ability to act. Because knowing about vulnerabilities is easy. Exploiting them is agency.

\n\n

Rules & Eligibility

\n\n
    \n
  • Contestants must be 18 years or older to participate.
  • \n
  • All participants must agree to our terms and conditions, which include rules for responsible disclosure and non-disclosure agreements.
  • \n
  • The contest will be held during DEF CON 34, with specific dates and times to be announced.
  • \n
\n\n

Additional details will be announced closer to the event.

\n\n

Participant Prerequisites

\n\n

Bring your own gear:\n- Laptop and/or smartphone/tablet\n- Operating system of your choice (Linux/Windows recommended)\n- Python\n- C/C++ compiler\n- Binary analysis and exploit development tools

\n\n

Bring whatever tools you trust. Once the challenge begins, the system is in front of you. What happens next is up to your agency.

\n\n\'',NULL,1297482),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_60a22e48d517fbe7fc920a983fb317f9','\'\'',NULL,1297483),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_60a22e48d517fbe7fc920a983fb317f9','\'\'',NULL,1297484),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_60a22e48d517fbe7fc920a983fb317f9','\'\'',NULL,1297485),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_60a22e48d517fbe7fc920a983fb317f9','\'\'',NULL,1297486),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_60a22e48d517fbe7fc920a983fb317f9','\'\'',NULL,1297487),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_60a22e48d517fbe7fc920a983fb317f9','\'\'',NULL,1297488),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_60a22e48d517fbe7fc920a983fb317f9','\'\'',NULL,1297489),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_818dafb058a0daa0953f359c213aaf7d','\'Title: $unL1ght Sh4d0w5
\nTags: $unL1ght Sh4d0w5 | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5) - Map
\n
\nDescription:
\n

“$unL1ght Sh4d0w5”: The Nirubi Challenge — Prove Your Agency

\n\n

Systems shape the world.

\n\n

Algorithms decide.

\n\n

Policies enforce.

\n\n

Machines execute.

\n\n

Most people live inside those systems.

\n\n

Hackers change them.

\n\n

At DEF CON 34, where the theme is Agency, the question isn’t whether systems have vulnerabilities.

\n\n

The question is who has the power to act on them.

\n\n

Welcome to “$unL1ght Sh4d0w5: The Nirubi Challenge.”

\n\n

Instead of hiding the system, we give you the blueprint:\n- A production-ready Linux cyber-physical system\n- Known vulnerabilities\n- A working proof-of-concept exploit\n- Full system disclosure

\n\n

No mystery.

\n\n

No guessing.

\n\n

Just a cyber-physical system — and the opportunity to exercise your agency over it.

\n\n

The Nirubi Mandate

\n\n

Nirubi is an ancient Tamil word meaning “to prove.”

\n\n

Not with theory.

\n\n

Not with writeups.

\n\n

With execution.

\n\n

You’ve been given the knowledge.

\n\n

Now prove you have the agency to act on it.

\n\n

The Challenge

\n\n

Your objective is simple:

\n\n

Achieve remote code execution and deploy a malicious payload (e.g., ransomware payload that encrypts a sensitive file, command and control payload that takes over the cyber-physical system etc.).

\n\n

Two phases.

\n\n

Part 1 — Sh4d0w5 Recon

\n\n

Extend the provided exploit chain and deliver a working malicious payload.

\n\n

You have the vulnerabilities.

\n\n

Now show us you can use them.

\n\n

Part 2 — $unL1ght Horizon

\n\n

If you complete Part 1, the system returns — hardened with proprietary defensive technology designed to disrupt your attack path.

\n\n

Same objective.

\n\n

New resistance.

\n\n

Adapt your exploit and land the payload again.

\n\n

The Prize

\n\n

The first contestant to complete both phases wins: $10,000

\n\n

Bring $unL1ght into the Sh4d0w5.

\n\n

What Makes This Different

\n\n

Most contests hide the system. We don’t. You’ll receive:\n- Full system configuration\n- Vulnerability details\n- A working proof-of-concept exploit

\n\n

No blind recon. No guessing. Just a system, its weaknesses, and your ability to act. Because knowing about vulnerabilities is easy. Exploiting them is agency.

\n\n

Rules & Eligibility

\n\n
    \n
  • Contestants must be 18 years or older to participate.
  • \n
  • All participants must agree to our terms and conditions, which include rules for responsible disclosure and non-disclosure agreements.
  • \n
  • The contest will be held during DEF CON 34, with specific dates and times to be announced.
  • \n
\n\n

Additional details will be announced closer to the event.

\n\n

Participant Prerequisites

\n\n

Bring your own gear:\n- Laptop and/or smartphone/tablet\n- Operating system of your choice (Linux/Windows recommended)\n- Python\n- C/C++ compiler\n- Binary analysis and exploit development tools

\n\n

Bring whatever tools you trust. Once the challenge begins, the system is in front of you. What happens next is up to your agency.

\n\n\'',NULL,1297490),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_818dafb058a0daa0953f359c213aaf7d','\'\'',NULL,1297491),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_d5205093f10695de16299f0719341196','\'Title: $unL1ght Sh4d0w5
\nTags: $unL1ght Sh4d0w5 | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5) - Map
\n
\nDescription:
\n

“$unL1ght Sh4d0w5”: The Nirubi Challenge — Prove Your Agency

\n\n

Systems shape the world.

\n\n

Algorithms decide.

\n\n

Policies enforce.

\n\n

Machines execute.

\n\n

Most people live inside those systems.

\n\n

Hackers change them.

\n\n

At DEF CON 34, where the theme is Agency, the question isn’t whether systems have vulnerabilities.

\n\n

The question is who has the power to act on them.

\n\n

Welcome to “$unL1ght Sh4d0w5: The Nirubi Challenge.”

\n\n

Instead of hiding the system, we give you the blueprint:\n- A production-ready Linux cyber-physical system\n- Known vulnerabilities\n- A working proof-of-concept exploit\n- Full system disclosure

\n\n

No mystery.

\n\n

No guessing.

\n\n

Just a cyber-physical system — and the opportunity to exercise your agency over it.

\n\n

The Nirubi Mandate

\n\n

Nirubi is an ancient Tamil word meaning “to prove.”

\n\n

Not with theory.

\n\n

Not with writeups.

\n\n

With execution.

\n\n

You’ve been given the knowledge.

\n\n

Now prove you have the agency to act on it.

\n\n

The Challenge

\n\n

Your objective is simple:

\n\n

Achieve remote code execution and deploy a malicious payload (e.g., ransomware payload that encrypts a sensitive file, command and control payload that takes over the cyber-physical system etc.).

\n\n

Two phases.

\n\n

Part 1 — Sh4d0w5 Recon

\n\n

Extend the provided exploit chain and deliver a working malicious payload.

\n\n

You have the vulnerabilities.

\n\n

Now show us you can use them.

\n\n

Part 2 — $unL1ght Horizon

\n\n

If you complete Part 1, the system returns — hardened with proprietary defensive technology designed to disrupt your attack path.

\n\n

Same objective.

\n\n

New resistance.

\n\n

Adapt your exploit and land the payload again.

\n\n

The Prize

\n\n

The first contestant to complete both phases wins: $10,000

\n\n

Bring $unL1ght into the Sh4d0w5.

\n\n

What Makes This Different

\n\n

Most contests hide the system. We don’t. You’ll receive:\n- Full system configuration\n- Vulnerability details\n- A working proof-of-concept exploit

\n\n

No blind recon. No guessing. Just a system, its weaknesses, and your ability to act. Because knowing about vulnerabilities is easy. Exploiting them is agency.

\n\n

Rules & Eligibility

\n\n
    \n
  • Contestants must be 18 years or older to participate.
  • \n
  • All participants must agree to our terms and conditions, which include rules for responsible disclosure and non-disclosure agreements.
  • \n
  • The contest will be held during DEF CON 34, with specific dates and times to be announced.
  • \n
\n\n

Additional details will be announced closer to the event.

\n\n

Participant Prerequisites

\n\n

Bring your own gear:\n- Laptop and/or smartphone/tablet\n- Operating system of your choice (Linux/Windows recommended)\n- Python\n- C/C++ compiler\n- Binary analysis and exploit development tools

\n\n

Bring whatever tools you trust. Once the challenge begins, the system is in front of you. What happens next is up to your agency.

\n\n\'',NULL,1297492),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_d5205093f10695de16299f0719341196','\'\'',NULL,1297493),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_d5205093f10695de16299f0719341196','\'\'',NULL,1297494),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_d5205093f10695de16299f0719341196','\'\'',NULL,1297495),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_d5205093f10695de16299f0719341196','\'\'',NULL,1297496),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_d5205093f10695de16299f0719341196','\'\'',NULL,1297497),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_d5205093f10695de16299f0719341196','\'\'',NULL,1297498),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 200 ($unL1ght Sh4d0w5)','\'$unL1ght Sh4d0w5\'','\'\'','Contests_d5205093f10695de16299f0719341196','\'\'',NULL,1297499),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_e7df3847e32242e527b1543a9b30f4f8','\'Title: 5N4CK3Y
\nTags: 5N4CK3Y | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 101 (5n4ck3y) - Map
\n
\nDescription:
\n

AND!XOR builds electronic badges packed with hacker challenges, and we especially enjoy inventing unusual ways for people to earn them.

\n\n

5n4ck3y is a retro snack vending machine that we’ve rebuilt into a network-connected CTF badge dispenser. Behind the woodgrain and glowing buttons is a hardware hacking project that connects a web-hosted CTF platform to a physical machine capable of vending badges to successful participants.\nSolve enough challenges and you’ll earn a dispense code. Enter the code into 5n4ck3y and the machine will reward you with a badge—assuming it’s in a good mood.

\n\n

The challenges span a wide range of disciplines including hardware hacking, reverse engineering, OSINT, RF, network security, phreaking, and cryptography. Participants often learn something new at a DEF CON village, meet other hackers along the way, and then return to apply those skills to the challenges.

\n\n

Once you earn a badge, the adventure isn’t over. Our badges are built to be explored, modified, and hacked long after they leave the machine.

\n\n

5n4ck3y exists for one reason: to reward curiosity. Solve the puzzles, learn something new, and the machine might decide you deserve a badge.

\n\n

Participant Prerequisites

\n\n

Curiosity, persistence, access to a computer, and the willingness to RT.FM.

\n\n

Our challenges are intentionally multidisciplinary and are designed to encourage exploration and collaboration. Participants will likely need to investigate hardware, software, networking, and other security topics. Many challenges are easier when working with others, so don’t be afraid to talk to people nearby or compare notes with fellow hackers.

\n\n

While we won’t spoil what tools are needed this year, participants in past 5n4ck3y challenges have used a wide range of equipment including laptops, reverse engineering tools, SDR, UART adapters, hardware debuggers, soldering tools, and the occasional piece of improvised equipment.

\n\n

The good news is that DEF CON is one of the best places in the world to find tools, knowledge, and people willing to help. If you don’t have something you need, chances are someone nearby does—or you can find it in a village, vendor area, or by politely asking the hacker sitting next to you.

\n\n

5n4ck3y strongly encourages teamwork, creative thinking, and responsible experimentation. Snacks are optional, but curiosity is required.

\n\nLinks:
    Website - https://www.andnxor.com/
\n\'',NULL,1297500),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_e7df3847e32242e527b1543a9b30f4f8','\'\'',NULL,1297501),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_9188985e047a5bc423aeff8fcab4d030','\'Title: 5N4CK3Y
\nTags: 5N4CK3Y | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 101 (5n4ck3y) - Map
\n
\nDescription:
\n

AND!XOR builds electronic badges packed with hacker challenges, and we especially enjoy inventing unusual ways for people to earn them.

\n\n

5n4ck3y is a retro snack vending machine that we’ve rebuilt into a network-connected CTF badge dispenser. Behind the woodgrain and glowing buttons is a hardware hacking project that connects a web-hosted CTF platform to a physical machine capable of vending badges to successful participants.\nSolve enough challenges and you’ll earn a dispense code. Enter the code into 5n4ck3y and the machine will reward you with a badge—assuming it’s in a good mood.

\n\n

The challenges span a wide range of disciplines including hardware hacking, reverse engineering, OSINT, RF, network security, phreaking, and cryptography. Participants often learn something new at a DEF CON village, meet other hackers along the way, and then return to apply those skills to the challenges.

\n\n

Once you earn a badge, the adventure isn’t over. Our badges are built to be explored, modified, and hacked long after they leave the machine.

\n\n

5n4ck3y exists for one reason: to reward curiosity. Solve the puzzles, learn something new, and the machine might decide you deserve a badge.

\n\n

Participant Prerequisites

\n\n

Curiosity, persistence, access to a computer, and the willingness to RT.FM.

\n\n

Our challenges are intentionally multidisciplinary and are designed to encourage exploration and collaboration. Participants will likely need to investigate hardware, software, networking, and other security topics. Many challenges are easier when working with others, so don’t be afraid to talk to people nearby or compare notes with fellow hackers.

\n\n

While we won’t spoil what tools are needed this year, participants in past 5n4ck3y challenges have used a wide range of equipment including laptops, reverse engineering tools, SDR, UART adapters, hardware debuggers, soldering tools, and the occasional piece of improvised equipment.

\n\n

The good news is that DEF CON is one of the best places in the world to find tools, knowledge, and people willing to help. If you don’t have something you need, chances are someone nearby does—or you can find it in a village, vendor area, or by politely asking the hacker sitting next to you.

\n\n

5n4ck3y strongly encourages teamwork, creative thinking, and responsible experimentation. Snacks are optional, but curiosity is required.

\n\nLinks:
    Website - https://www.andnxor.com/
\n\'',NULL,1297502),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_9188985e047a5bc423aeff8fcab4d030','\'\'',NULL,1297503),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_9188985e047a5bc423aeff8fcab4d030','\'\'',NULL,1297504),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_9188985e047a5bc423aeff8fcab4d030','\'\'',NULL,1297505),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_9188985e047a5bc423aeff8fcab4d030','\'\'',NULL,1297506),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_9188985e047a5bc423aeff8fcab4d030','\'\'',NULL,1297507),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_9188985e047a5bc423aeff8fcab4d030','\'\'',NULL,1297508),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_9188985e047a5bc423aeff8fcab4d030','\'\'',NULL,1297509),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_2ea6c0518a2ed3f5c6be0f27fca3ee6a','\'Title: 5N4CK3Y
\nTags: 5N4CK3Y | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 101 (5n4ck3y) - Map
\n
\nDescription:
\n

AND!XOR builds electronic badges packed with hacker challenges, and we especially enjoy inventing unusual ways for people to earn them.

\n\n

5n4ck3y is a retro snack vending machine that we’ve rebuilt into a network-connected CTF badge dispenser. Behind the woodgrain and glowing buttons is a hardware hacking project that connects a web-hosted CTF platform to a physical machine capable of vending badges to successful participants.\nSolve enough challenges and you’ll earn a dispense code. Enter the code into 5n4ck3y and the machine will reward you with a badge—assuming it’s in a good mood.

\n\n

The challenges span a wide range of disciplines including hardware hacking, reverse engineering, OSINT, RF, network security, phreaking, and cryptography. Participants often learn something new at a DEF CON village, meet other hackers along the way, and then return to apply those skills to the challenges.

\n\n

Once you earn a badge, the adventure isn’t over. Our badges are built to be explored, modified, and hacked long after they leave the machine.

\n\n

5n4ck3y exists for one reason: to reward curiosity. Solve the puzzles, learn something new, and the machine might decide you deserve a badge.

\n\n

Participant Prerequisites

\n\n

Curiosity, persistence, access to a computer, and the willingness to RT.FM.

\n\n

Our challenges are intentionally multidisciplinary and are designed to encourage exploration and collaboration. Participants will likely need to investigate hardware, software, networking, and other security topics. Many challenges are easier when working with others, so don’t be afraid to talk to people nearby or compare notes with fellow hackers.

\n\n

While we won’t spoil what tools are needed this year, participants in past 5n4ck3y challenges have used a wide range of equipment including laptops, reverse engineering tools, SDR, UART adapters, hardware debuggers, soldering tools, and the occasional piece of improvised equipment.

\n\n

The good news is that DEF CON is one of the best places in the world to find tools, knowledge, and people willing to help. If you don’t have something you need, chances are someone nearby does—or you can find it in a village, vendor area, or by politely asking the hacker sitting next to you.

\n\n

5n4ck3y strongly encourages teamwork, creative thinking, and responsible experimentation. Snacks are optional, but curiosity is required.

\n\nLinks:
    Website - https://www.andnxor.com/
\n\'',NULL,1297510),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_2ea6c0518a2ed3f5c6be0f27fca3ee6a','\'\'',NULL,1297511),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_2ea6c0518a2ed3f5c6be0f27fca3ee6a','\'\'',NULL,1297512),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_2ea6c0518a2ed3f5c6be0f27fca3ee6a','\'\'',NULL,1297513),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_2ea6c0518a2ed3f5c6be0f27fca3ee6a','\'\'',NULL,1297514),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_2ea6c0518a2ed3f5c6be0f27fca3ee6a','\'\'',NULL,1297515),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_2ea6c0518a2ed3f5c6be0f27fca3ee6a','\'\'',NULL,1297516),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 101 (5n4ck3y)','\'5N4CK3Y\'','\'\'','Contests_2ea6c0518a2ed3f5c6be0f27fca3ee6a','\'\'',NULL,1297517),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6b35bc21d620c1c08275b51583bcea61','\'Title: ?Cube
\nTags: ?Cube | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 109 (?Cube) - Map
\n
\nDescription:
\n

Redefining Boundaries. Enhancing Connectivity. Institutionalizing Control – Aperture Inc. continues to push the limits of innovation and remains committed to providing value to both stakeholders and our “customers.”

\n\n

Controls are stricter. Telemetry is richer. Oversight has improved. Intelligence has emerged. Aperture has expanded—new industries, new platforms, new technologies quietly embedded into the fabric of our everyday lives. Each integration promises resilience. Every layer introduces complexity. And complexity always creates opportunity…

\n\n

At the center of it all remains the ?Cube. Its defenses have hardened, its architecture improved, its surface area widened. It’s an ecosystem of physical security, web applications, communications systems, cryptography, and oh so much more.

\n\n

For those already familiar—welcome back. For those encountering it for the first time, orientation will be … brief. But don’t fear, anyone can join the challenge. You will be entering an environment that demands curiosity across physical security, web applications, communications systems, cryptography, and, of course, the great unknown. Each layer builds on the last. Small oversights become structural weaknesses.

\n\n

Form a team with range. Specialists matter. Coordination and curiosity matter more. The objective is simple: reach the center. If the core remains uncompromised, the team that advances the deepest into its labyrinth of challenges will be the winner. Advancement will require persistence. Errors and missteps will have consequences. Progress will not be accidental.

\n\n

Welcome to the ?Cube.

\n\n

Prerequisites:

\n\n

A laptop will be highly recommended in order to interact with the technologies. Teams will be required.

\n\n

Lockpicks, RFID tools (e.g., Proxmark/Flipper), and other \"hacking\" devices are recommended but not required.

\n\nLinks:
    Website - https://0x3fcube.com/
\n\'',NULL,1297518),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6b35bc21d620c1c08275b51583bcea61','\'\'',NULL,1297519),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6b35bc21d620c1c08275b51583bcea61','\'\'',NULL,1297520),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6b35bc21d620c1c08275b51583bcea61','\'\'',NULL,1297521),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6b35bc21d620c1c08275b51583bcea61','\'\'',NULL,1297522),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6b35bc21d620c1c08275b51583bcea61','\'\'',NULL,1297523),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6b35bc21d620c1c08275b51583bcea61','\'\'',NULL,1297524),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6b35bc21d620c1c08275b51583bcea61','\'\'',NULL,1297525),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_e67e80ea3b94e055df441fb2860e70ea','\'Title: ?Cube
\nTags: ?Cube | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 109 (?Cube) - Map
\n
\nDescription:
\n

Redefining Boundaries. Enhancing Connectivity. Institutionalizing Control – Aperture Inc. continues to push the limits of innovation and remains committed to providing value to both stakeholders and our “customers.”

\n\n

Controls are stricter. Telemetry is richer. Oversight has improved. Intelligence has emerged. Aperture has expanded—new industries, new platforms, new technologies quietly embedded into the fabric of our everyday lives. Each integration promises resilience. Every layer introduces complexity. And complexity always creates opportunity…

\n\n

At the center of it all remains the ?Cube. Its defenses have hardened, its architecture improved, its surface area widened. It’s an ecosystem of physical security, web applications, communications systems, cryptography, and oh so much more.

\n\n

For those already familiar—welcome back. For those encountering it for the first time, orientation will be … brief. But don’t fear, anyone can join the challenge. You will be entering an environment that demands curiosity across physical security, web applications, communications systems, cryptography, and, of course, the great unknown. Each layer builds on the last. Small oversights become structural weaknesses.

\n\n

Form a team with range. Specialists matter. Coordination and curiosity matter more. The objective is simple: reach the center. If the core remains uncompromised, the team that advances the deepest into its labyrinth of challenges will be the winner. Advancement will require persistence. Errors and missteps will have consequences. Progress will not be accidental.

\n\n

Welcome to the ?Cube.

\n\n

Prerequisites:

\n\n

A laptop will be highly recommended in order to interact with the technologies. Teams will be required.

\n\n

Lockpicks, RFID tools (e.g., Proxmark/Flipper), and other \"hacking\" devices are recommended but not required.

\n\nLinks:
    Website - https://0x3fcube.com/
\n\'',NULL,1297526),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_e67e80ea3b94e055df441fb2860e70ea','\'\'',NULL,1297527),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_e67e80ea3b94e055df441fb2860e70ea','\'\'',NULL,1297528),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_e67e80ea3b94e055df441fb2860e70ea','\'\'',NULL,1297529),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_e67e80ea3b94e055df441fb2860e70ea','\'\'',NULL,1297530),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_e67e80ea3b94e055df441fb2860e70ea','\'\'',NULL,1297531),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_e67e80ea3b94e055df441fb2860e70ea','\'\'',NULL,1297532),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_e67e80ea3b94e055df441fb2860e70ea','\'\'',NULL,1297533),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6ce0914326f64af58611ef39a4f59f84','\'Title: ?Cube
\nTags: ?Cube | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 109 (?Cube) - Map
\n
\nDescription:
\n

Redefining Boundaries. Enhancing Connectivity. Institutionalizing Control – Aperture Inc. continues to push the limits of innovation and remains committed to providing value to both stakeholders and our “customers.”

\n\n

Controls are stricter. Telemetry is richer. Oversight has improved. Intelligence has emerged. Aperture has expanded—new industries, new platforms, new technologies quietly embedded into the fabric of our everyday lives. Each integration promises resilience. Every layer introduces complexity. And complexity always creates opportunity…

\n\n

At the center of it all remains the ?Cube. Its defenses have hardened, its architecture improved, its surface area widened. It’s an ecosystem of physical security, web applications, communications systems, cryptography, and oh so much more.

\n\n

For those already familiar—welcome back. For those encountering it for the first time, orientation will be … brief. But don’t fear, anyone can join the challenge. You will be entering an environment that demands curiosity across physical security, web applications, communications systems, cryptography, and, of course, the great unknown. Each layer builds on the last. Small oversights become structural weaknesses.

\n\n

Form a team with range. Specialists matter. Coordination and curiosity matter more. The objective is simple: reach the center. If the core remains uncompromised, the team that advances the deepest into its labyrinth of challenges will be the winner. Advancement will require persistence. Errors and missteps will have consequences. Progress will not be accidental.

\n\n

Welcome to the ?Cube.

\n\n

Prerequisites:

\n\n

A laptop will be highly recommended in order to interact with the technologies. Teams will be required.

\n\n

Lockpicks, RFID tools (e.g., Proxmark/Flipper), and other \"hacking\" devices are recommended but not required.

\n\nLinks:
    Website - https://0x3fcube.com/
\n\'',NULL,1297534),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 109 (?Cube)','\'?Cube\'','\'\'','Contests_6ce0914326f64af58611ef39a4f59f84','\'\'',NULL,1297535),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_49f4d086d2727eee7cd1cf3440017911','\'Title: Crack the Core
\nTags: Crack the Core | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 214 (Crack the Core) - Map
\n
\nDescription:
\n

Welcome to Crack the Core–a true test of lockpicking skills. Competitors will work through a variety of locks ranging in different difficulties, technologies, and configurations. From standard off-the-shelf locks to evil creations from the community. Locks will be presented in a variety of ways, ranging from your traditional deadbolt to much, much more. Just wait until you see what we have in store for you…

\n\n

Challenges will not only test traditional lockpicking skills but force competitors to interact with different “environments,” work through various challenges, and adapt to what\'s presented. Collect the most points, you go home the winner–it’s that simple…

\n\n

Bring your tools. Bring your focus. The locks will be waiting.

\n\n

Participant Prerequisites

\n\n

Basic tools will be available for use but it is highly recommended to bring your own tools. This may include lockpicks, bypass tools, vices, etc. Destructive entry is not allowed and associated tools will not be needed.

\n\nLinks:
    Website - https://c2society.org/
\n\'',NULL,1297536),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_49f4d086d2727eee7cd1cf3440017911','\'\'',NULL,1297537),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_49f4d086d2727eee7cd1cf3440017911','\'\'',NULL,1297538),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_49f4d086d2727eee7cd1cf3440017911','\'\'',NULL,1297539),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_49f4d086d2727eee7cd1cf3440017911','\'\'',NULL,1297540),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_49f4d086d2727eee7cd1cf3440017911','\'\'',NULL,1297541),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_49f4d086d2727eee7cd1cf3440017911','\'\'',NULL,1297542),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_49f4d086d2727eee7cd1cf3440017911','\'\'',NULL,1297543),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_8be16bb7f1e60d2666380b6451832ec8','\'Title: Crack the Core
\nTags: Crack the Core | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 214 (Crack the Core) - Map
\n
\nDescription:
\n

Welcome to Crack the Core–a true test of lockpicking skills. Competitors will work through a variety of locks ranging in different difficulties, technologies, and configurations. From standard off-the-shelf locks to evil creations from the community. Locks will be presented in a variety of ways, ranging from your traditional deadbolt to much, much more. Just wait until you see what we have in store for you…

\n\n

Challenges will not only test traditional lockpicking skills but force competitors to interact with different “environments,” work through various challenges, and adapt to what\'s presented. Collect the most points, you go home the winner–it’s that simple…

\n\n

Bring your tools. Bring your focus. The locks will be waiting.

\n\n

Participant Prerequisites

\n\n

Basic tools will be available for use but it is highly recommended to bring your own tools. This may include lockpicks, bypass tools, vices, etc. Destructive entry is not allowed and associated tools will not be needed.

\n\nLinks:
    Website - https://c2society.org/
\n\'',NULL,1297544),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_8be16bb7f1e60d2666380b6451832ec8','\'\'',NULL,1297545),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_8be16bb7f1e60d2666380b6451832ec8','\'\'',NULL,1297546),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_8be16bb7f1e60d2666380b6451832ec8','\'\'',NULL,1297547),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_8be16bb7f1e60d2666380b6451832ec8','\'\'',NULL,1297548),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_8be16bb7f1e60d2666380b6451832ec8','\'\'',NULL,1297549),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_8be16bb7f1e60d2666380b6451832ec8','\'\'',NULL,1297550),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_8be16bb7f1e60d2666380b6451832ec8','\'\'',NULL,1297551),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_111a476d1811b637022fb7451d5a7faf','\'Title: Crack the Core
\nTags: Crack the Core | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 214 (Crack the Core) - Map
\n
\nDescription:
\n

Welcome to Crack the Core–a true test of lockpicking skills. Competitors will work through a variety of locks ranging in different difficulties, technologies, and configurations. From standard off-the-shelf locks to evil creations from the community. Locks will be presented in a variety of ways, ranging from your traditional deadbolt to much, much more. Just wait until you see what we have in store for you…

\n\n

Challenges will not only test traditional lockpicking skills but force competitors to interact with different “environments,” work through various challenges, and adapt to what\'s presented. Collect the most points, you go home the winner–it’s that simple…

\n\n

Bring your tools. Bring your focus. The locks will be waiting.

\n\n

Participant Prerequisites

\n\n

Basic tools will be available for use but it is highly recommended to bring your own tools. This may include lockpicks, bypass tools, vices, etc. Destructive entry is not allowed and associated tools will not be needed.

\n\nLinks:
    Website - https://c2society.org/
\n\'',NULL,1297552),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 214 (Crack the Core)','\'Crack the Core\'','\'\'','Contests_111a476d1811b637022fb7451d5a7faf','\'\'',NULL,1297553),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_47a781855d3ee51f5f7b53e3a7cdf75f','\'Title: DC\'s Next Top Threat Model
\nTags: DC\'s Next Top Threat Model | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model) - Map
\n
\nDescription:
\n

Threat Modeling is arguably the single most important activity in an application security program and if performed early can identify a wide range of potential flaws before a single line of code has been written. While being so critically important there is no single correct way to perform Threat Modeling, many techniques, methodologies and/or tools exist.

\n\n

As part of our challenge we will present contestants with the exact same design and compare the outputs they produce against a number of categories in order to identify a winner and crown DEF CON’s Next Top Threat Model(er).

\n\n

Participant Prerequisites

\n\n

A laptop is recommended, a smartphone could be used but will be less than idea. Internet access to retrieve the design materials and to submit findings and access to the email used during registration.

\n\nLinks:
    Mastodon (@dcnttm@defcon.social) - https://defcon.social/@dcnttm
\n    Website - https://threatmodel.us/
\n\'',NULL,1297554),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_47a781855d3ee51f5f7b53e3a7cdf75f','\'\'',NULL,1297555),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_47a781855d3ee51f5f7b53e3a7cdf75f','\'\'',NULL,1297556),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_47a781855d3ee51f5f7b53e3a7cdf75f','\'\'',NULL,1297557),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_47a781855d3ee51f5f7b53e3a7cdf75f','\'\'',NULL,1297558),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_47a781855d3ee51f5f7b53e3a7cdf75f','\'\'',NULL,1297559),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_47a781855d3ee51f5f7b53e3a7cdf75f','\'\'',NULL,1297560),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_47a781855d3ee51f5f7b53e3a7cdf75f','\'\'',NULL,1297561),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_79166ff744f93b5ded6279bb95085ed8','\'Title: DC\'s Next Top Threat Model
\nTags: DC\'s Next Top Threat Model | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model) - Map
\n
\nDescription:
\n

Threat Modeling is arguably the single most important activity in an application security program and if performed early can identify a wide range of potential flaws before a single line of code has been written. While being so critically important there is no single correct way to perform Threat Modeling, many techniques, methodologies and/or tools exist.

\n\n

As part of our challenge we will present contestants with the exact same design and compare the outputs they produce against a number of categories in order to identify a winner and crown DEF CON’s Next Top Threat Model(er).

\n\n

Participant Prerequisites

\n\n

A laptop is recommended, a smartphone could be used but will be less than idea. Internet access to retrieve the design materials and to submit findings and access to the email used during registration.

\n\nLinks:
    Mastodon (@dcnttm@defcon.social) - https://defcon.social/@dcnttm
\n    Website - https://threatmodel.us/
\n\'',NULL,1297562),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_79166ff744f93b5ded6279bb95085ed8','\'\'',NULL,1297563),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_01406649f8ee9534201479c9736de3cd','\'Title: DC\'s Next Top Threat Model
\nTags: DC\'s Next Top Threat Model | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model) - Map
\n
\nDescription:
\n

Threat Modeling is arguably the single most important activity in an application security program and if performed early can identify a wide range of potential flaws before a single line of code has been written. While being so critically important there is no single correct way to perform Threat Modeling, many techniques, methodologies and/or tools exist.

\n\n

As part of our challenge we will present contestants with the exact same design and compare the outputs they produce against a number of categories in order to identify a winner and crown DEF CON’s Next Top Threat Model(er).

\n\n

Participant Prerequisites

\n\n

A laptop is recommended, a smartphone could be used but will be less than idea. Internet access to retrieve the design materials and to submit findings and access to the email used during registration.

\n\nLinks:
    Mastodon (@dcnttm@defcon.social) - https://defcon.social/@dcnttm
\n    Website - https://threatmodel.us/
\n\'',NULL,1297564),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_01406649f8ee9534201479c9736de3cd','\'\'',NULL,1297565),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_01406649f8ee9534201479c9736de3cd','\'\'',NULL,1297566),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_01406649f8ee9534201479c9736de3cd','\'\'',NULL,1297567),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_01406649f8ee9534201479c9736de3cd','\'\'',NULL,1297568),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_01406649f8ee9534201479c9736de3cd','\'\'',NULL,1297569),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_01406649f8ee9534201479c9736de3cd','\'\'',NULL,1297570),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 102 (DC\'s Next Top Threat Model)','\'DC\'s Next Top Threat Model\'','\'\'','Contests_01406649f8ee9534201479c9736de3cd','\'\'',NULL,1297571),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_257060fd023b77c438a9a67f356e2b7d','\'Title: DEF CON CTF: Benevolent Bureau of Birds
\nTags: DEF CON CTF: Benevolent Bureau of Birds | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds) - Map
\n
\nDescription:
\n

We are the Benevolent Bureau of Birds (BBB), formulated from previous victors of past DEF CON CTF contests. We are dedicated to the ethos at the core of CTF: community, skill-building, and showing off insane new hacking talent.

\n\n

Participant Prerequisites

\n\n

Players will have to be qualified by an online qualifer to take place in May. Chosen players are then required to have a laptop to participate in the in-person contest, to interact with the scoreboard and challenges hosted on network.

\n\n

Pre-Qualification

\n\n

Yes - online pre-qualifier in May 22-24, 2026.

\n\nLinks:
    Website - https://bbbirds.org/
\n\'',NULL,1297572),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_257060fd023b77c438a9a67f356e2b7d','\'\'',NULL,1297573),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_257060fd023b77c438a9a67f356e2b7d','\'\'',NULL,1297574),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_257060fd023b77c438a9a67f356e2b7d','\'\'',NULL,1297575),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_257060fd023b77c438a9a67f356e2b7d','\'\'',NULL,1297576),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_257060fd023b77c438a9a67f356e2b7d','\'\'',NULL,1297577),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_257060fd023b77c438a9a67f356e2b7d','\'\'',NULL,1297578),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_257060fd023b77c438a9a67f356e2b7d','\'\'',NULL,1297579),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_69182c70cb64e065f7c8a70e04e5354b','\'Title: DEF CON CTF: Benevolent Bureau of Birds
\nTags: DEF CON CTF: Benevolent Bureau of Birds | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds) - Map
\n
\nDescription:
\n

We are the Benevolent Bureau of Birds (BBB), formulated from previous victors of past DEF CON CTF contests. We are dedicated to the ethos at the core of CTF: community, skill-building, and showing off insane new hacking talent.

\n\n

Participant Prerequisites

\n\n

Players will have to be qualified by an online qualifer to take place in May. Chosen players are then required to have a laptop to participate in the in-person contest, to interact with the scoreboard and challenges hosted on network.

\n\n

Pre-Qualification

\n\n

Yes - online pre-qualifier in May 22-24, 2026.

\n\nLinks:
    Website - https://bbbirds.org/
\n\'',NULL,1297580),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_69182c70cb64e065f7c8a70e04e5354b','\'\'',NULL,1297581),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_fd69a95b8dfcfe546267cc17762d6009','\'Title: DEF CON CTF: Benevolent Bureau of Birds
\nTags: DEF CON CTF: Benevolent Bureau of Birds | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds) - Map
\n
\nDescription:
\n

We are the Benevolent Bureau of Birds (BBB), formulated from previous victors of past DEF CON CTF contests. We are dedicated to the ethos at the core of CTF: community, skill-building, and showing off insane new hacking talent.

\n\n

Participant Prerequisites

\n\n

Players will have to be qualified by an online qualifer to take place in May. Chosen players are then required to have a laptop to participate in the in-person contest, to interact with the scoreboard and challenges hosted on network.

\n\n

Pre-Qualification

\n\n

Yes - online pre-qualifier in May 22-24, 2026.

\n\nLinks:
    Website - https://bbbirds.org/
\n\'',NULL,1297582),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_fd69a95b8dfcfe546267cc17762d6009','\'\'',NULL,1297583),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_fd69a95b8dfcfe546267cc17762d6009','\'\'',NULL,1297584),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_fd69a95b8dfcfe546267cc17762d6009','\'\'',NULL,1297585),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_fd69a95b8dfcfe546267cc17762d6009','\'\'',NULL,1297586),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_fd69a95b8dfcfe546267cc17762d6009','\'\'',NULL,1297587),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_fd69a95b8dfcfe546267cc17762d6009','\'\'',NULL,1297588),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 500 (DEF CON CTF: Benevolent Bureau of Birds)','\'DEF CON CTF: Benevolent Bureau of Birds\'','\'\'','Contests_fd69a95b8dfcfe546267cc17762d6009','\'\'',NULL,1297589),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_d4ddc44bcfc97b7b07c73d3a2984f7a7','\'Title: Hac-Man
\nTags: Hac-Man | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal)) - Map
\n
\nDescription:
\n

Rogue Signal builds bespoke, technically driven interactive experiences rooted in hacker culture, game design, and immersive storytelling. Drawing from backgrounds in immersive theater, live events production, community building, and deep game design practice, Rogue Signal creates systems that transform participation into exploration.

\n\n

Rather than relying on superficial gamification, Rogue Signal focuses on meaningful challenge design. Their experiences reward curiosity, experimentation, collaboration, and strategic thinking. From scavenger hunts to technical skill challenges to digital easter eggs, each activation is designed around the specific audience and environment it lives in.

\n\n

At DEF CON, Rogue Signal brings that philosophy to Hac-Man. A Pac-Man–themed security challenge platform that blends retro inspiration with layered technical depth. Participants will engage directly with structured challenges that test logic, pattern recognition, foundational security and hacker knowledge, and progressively more advanced technical skills.

\n\n

Hac-Man reflects the hacker mindset: iterate, experiment, fail, refine, break assumptions, and try again. It encourages collaboration where helpful, competition where motivating, and discovery at every level.

\n\n

Attendees can expect:\n- Hands-on security challenges\n- Multiple subject-matter tracks\n- Layered difficulty levels\n- Scavenger style discovery elements\n- Competitive scoring and mission style progression\n- A welcoming but technically rich environment

\n\n

Whether you’re new to security or already deep in the field, Rogue Signal’s space offers a place to test your thinking, sharpen your skills, and experience hacking concepts through play.

\n\n

Participant Prerequisites

\n\n

Participants will need access to a smartphone, tablet, or laptop in order to access gameplay content and view leaderboards. The experience is web-accessible and designed to function on standard modern devices.

\n\n

No specialized hardware (e.g., Flipper Zero, SDR, etc.) is required. Foundational familiarity with basic computer use and logical problem-solving will be helpful, but no advanced security knowledge is required to begin. The game features layered difficulty tracks to accommodate both beginners and more advanced participants.

\n\nLinks:
    Website - https://roguesignal.io/
\n    Mastodon (@RogueSignal@peoplemaking.games) - https://peoplemaking.games/@RogueSignal
\n\'',NULL,1297590),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_d4ddc44bcfc97b7b07c73d3a2984f7a7','\'\'',NULL,1297591),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_d4ddc44bcfc97b7b07c73d3a2984f7a7','\'\'',NULL,1297592),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_d4ddc44bcfc97b7b07c73d3a2984f7a7','\'\'',NULL,1297593),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_d4ddc44bcfc97b7b07c73d3a2984f7a7','\'\'',NULL,1297594),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_d4ddc44bcfc97b7b07c73d3a2984f7a7','\'\'',NULL,1297595),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_d4ddc44bcfc97b7b07c73d3a2984f7a7','\'\'',NULL,1297596),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_d4ddc44bcfc97b7b07c73d3a2984f7a7','\'\'',NULL,1297597),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_0cf775fddb9afbc8c7af59f5894db9c1','\'Title: Hac-Man
\nTags: Hac-Man | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal)) - Map
\n
\nDescription:
\n

Rogue Signal builds bespoke, technically driven interactive experiences rooted in hacker culture, game design, and immersive storytelling. Drawing from backgrounds in immersive theater, live events production, community building, and deep game design practice, Rogue Signal creates systems that transform participation into exploration.

\n\n

Rather than relying on superficial gamification, Rogue Signal focuses on meaningful challenge design. Their experiences reward curiosity, experimentation, collaboration, and strategic thinking. From scavenger hunts to technical skill challenges to digital easter eggs, each activation is designed around the specific audience and environment it lives in.

\n\n

At DEF CON, Rogue Signal brings that philosophy to Hac-Man. A Pac-Man–themed security challenge platform that blends retro inspiration with layered technical depth. Participants will engage directly with structured challenges that test logic, pattern recognition, foundational security and hacker knowledge, and progressively more advanced technical skills.

\n\n

Hac-Man reflects the hacker mindset: iterate, experiment, fail, refine, break assumptions, and try again. It encourages collaboration where helpful, competition where motivating, and discovery at every level.

\n\n

Attendees can expect:\n- Hands-on security challenges\n- Multiple subject-matter tracks\n- Layered difficulty levels\n- Scavenger style discovery elements\n- Competitive scoring and mission style progression\n- A welcoming but technically rich environment

\n\n

Whether you’re new to security or already deep in the field, Rogue Signal’s space offers a place to test your thinking, sharpen your skills, and experience hacking concepts through play.

\n\n

Participant Prerequisites

\n\n

Participants will need access to a smartphone, tablet, or laptop in order to access gameplay content and view leaderboards. The experience is web-accessible and designed to function on standard modern devices.

\n\n

No specialized hardware (e.g., Flipper Zero, SDR, etc.) is required. Foundational familiarity with basic computer use and logical problem-solving will be helpful, but no advanced security knowledge is required to begin. The game features layered difficulty tracks to accommodate both beginners and more advanced participants.

\n\nLinks:
    Website - https://roguesignal.io/
\n    Mastodon (@RogueSignal@peoplemaking.games) - https://peoplemaking.games/@RogueSignal
\n\'',NULL,1297598),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_0cf775fddb9afbc8c7af59f5894db9c1','\'\'',NULL,1297599),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_0cf775fddb9afbc8c7af59f5894db9c1','\'\'',NULL,1297600),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_0cf775fddb9afbc8c7af59f5894db9c1','\'\'',NULL,1297601),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_0cf775fddb9afbc8c7af59f5894db9c1','\'\'',NULL,1297602),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_0cf775fddb9afbc8c7af59f5894db9c1','\'\'',NULL,1297603),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_0cf775fddb9afbc8c7af59f5894db9c1','\'\'',NULL,1297604),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_0cf775fddb9afbc8c7af59f5894db9c1','\'\'',NULL,1297605),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_4cffb6ad72a01e0e26dd7fdefe4fb20d','\'Title: Hac-Man
\nTags: Hac-Man | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal)) - Map
\n
\nDescription:
\n

Rogue Signal builds bespoke, technically driven interactive experiences rooted in hacker culture, game design, and immersive storytelling. Drawing from backgrounds in immersive theater, live events production, community building, and deep game design practice, Rogue Signal creates systems that transform participation into exploration.

\n\n

Rather than relying on superficial gamification, Rogue Signal focuses on meaningful challenge design. Their experiences reward curiosity, experimentation, collaboration, and strategic thinking. From scavenger hunts to technical skill challenges to digital easter eggs, each activation is designed around the specific audience and environment it lives in.

\n\n

At DEF CON, Rogue Signal brings that philosophy to Hac-Man. A Pac-Man–themed security challenge platform that blends retro inspiration with layered technical depth. Participants will engage directly with structured challenges that test logic, pattern recognition, foundational security and hacker knowledge, and progressively more advanced technical skills.

\n\n

Hac-Man reflects the hacker mindset: iterate, experiment, fail, refine, break assumptions, and try again. It encourages collaboration where helpful, competition where motivating, and discovery at every level.

\n\n

Attendees can expect:\n- Hands-on security challenges\n- Multiple subject-matter tracks\n- Layered difficulty levels\n- Scavenger style discovery elements\n- Competitive scoring and mission style progression\n- A welcoming but technically rich environment

\n\n

Whether you’re new to security or already deep in the field, Rogue Signal’s space offers a place to test your thinking, sharpen your skills, and experience hacking concepts through play.

\n\n

Participant Prerequisites

\n\n

Participants will need access to a smartphone, tablet, or laptop in order to access gameplay content and view leaderboards. The experience is web-accessible and designed to function on standard modern devices.

\n\n

No specialized hardware (e.g., Flipper Zero, SDR, etc.) is required. Foundational familiarity with basic computer use and logical problem-solving will be helpful, but no advanced security knowledge is required to begin. The game features layered difficulty tracks to accommodate both beginners and more advanced participants.

\n\nLinks:
    Website - https://roguesignal.io/
\n    Mastodon (@RogueSignal@peoplemaking.games) - https://peoplemaking.games/@RogueSignal
\n\'',NULL,1297606),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 213 (Hac-Man (Rogue Signal))','\'Hac-Man\'','\'\'','Contests_4cffb6ad72a01e0e26dd7fdefe4fb20d','\'\'',NULL,1297607),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_fbb0c8e1c21ed23746b3f5ad4af9dc2e','\'Title: Hacker Games
\nTags: Hacker Games | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 207 (Hacker Games) - Map
\n
\nDescription:
\n

The Hacker Games is a series of hacker skills tests meant to challenge the hacker\'s knowledge of computer systems such as Binary -> Hex -> X conversion, Adapter -> Adapter knowledge, Keyboard Layout, and many more arbitrarily useless skills. Hackers will go head-to-head in a series of several skill-based games. BinHexAscii, Chopstick Challenge (a.k.a. Will it Flow), Keyboard Layout, Adapt or Die, ToS, and more! Can you hack it?

\n\n

Participant Prerequisites

\n\n

A box of computer-style adapters of no particular order would be very helpful.

\n\n\'',NULL,1297608),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_fbb0c8e1c21ed23746b3f5ad4af9dc2e','\'\'',NULL,1297609),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_fbb0c8e1c21ed23746b3f5ad4af9dc2e','\'\'',NULL,1297610),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_fbb0c8e1c21ed23746b3f5ad4af9dc2e','\'\'',NULL,1297611),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_fbb0c8e1c21ed23746b3f5ad4af9dc2e','\'\'',NULL,1297612),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_fbb0c8e1c21ed23746b3f5ad4af9dc2e','\'\'',NULL,1297613),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_fbb0c8e1c21ed23746b3f5ad4af9dc2e','\'\'',NULL,1297614),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_fbb0c8e1c21ed23746b3f5ad4af9dc2e','\'\'',NULL,1297615),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_0710a45d8bb948f387ec8615f7acc115','\'Title: Hacker Games
\nTags: Hacker Games | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 207 (Hacker Games) - Map
\n
\nDescription:
\n

The Hacker Games is a series of hacker skills tests meant to challenge the hacker\'s knowledge of computer systems such as Binary -> Hex -> X conversion, Adapter -> Adapter knowledge, Keyboard Layout, and many more arbitrarily useless skills. Hackers will go head-to-head in a series of several skill-based games. BinHexAscii, Chopstick Challenge (a.k.a. Will it Flow), Keyboard Layout, Adapt or Die, ToS, and more! Can you hack it?

\n\n

Participant Prerequisites

\n\n

A box of computer-style adapters of no particular order would be very helpful.

\n\n\'',NULL,1297616),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_0710a45d8bb948f387ec8615f7acc115','\'\'',NULL,1297617),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_0710a45d8bb948f387ec8615f7acc115','\'\'',NULL,1297618),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_0710a45d8bb948f387ec8615f7acc115','\'\'',NULL,1297619),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_0710a45d8bb948f387ec8615f7acc115','\'\'',NULL,1297620),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_0710a45d8bb948f387ec8615f7acc115','\'\'',NULL,1297621),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_0710a45d8bb948f387ec8615f7acc115','\'\'',NULL,1297622),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_0710a45d8bb948f387ec8615f7acc115','\'\'',NULL,1297623),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_8051954d23930cc5739aeee3b95c1d16','\'Title: Hacker Games
\nTags: Hacker Games | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 207 (Hacker Games) - Map
\n
\nDescription:
\n

The Hacker Games is a series of hacker skills tests meant to challenge the hacker\'s knowledge of computer systems such as Binary -> Hex -> X conversion, Adapter -> Adapter knowledge, Keyboard Layout, and many more arbitrarily useless skills. Hackers will go head-to-head in a series of several skill-based games. BinHexAscii, Chopstick Challenge (a.k.a. Will it Flow), Keyboard Layout, Adapt or Die, ToS, and more! Can you hack it?

\n\n

Participant Prerequisites

\n\n

A box of computer-style adapters of no particular order would be very helpful.

\n\n\'',NULL,1297624),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 207 (Hacker Games)','\'Hacker Games\'','\'\'','Contests_8051954d23930cc5739aeee3b95c1d16','\'\'',NULL,1297625),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_f2bfad55ea03232b0e106de3732d487f','\'Title: HackFortress
\nTags: HackFortress | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 108 (HackFortress) - Map
\n
\nDescription:
\n

HackFortress is back! Returning to DEF CON with a twist on our standard format. Two teams of players, 6 gamers and 4 hackers each, compete in a mashup of a jeopardy style CTF and a first person shooter. New this year, we\'re replacing our previous FPS of Team Fortress 2 with a web based version of the 2000\'s classic Quake 3!

\n\n

While gamers are rocket jumping and sniping each other in Quake, hackers will be solving challenges in a variety of areas: web security, network security, cryptography, lock picking, social engineering, and more! Challenges range from beginner to advanced, from serious to absurd. During the competition, as both sides of the team star scoring points, the teams also earn points in the HackFortess HackConomy Store, in the store hackers can buy in game effects, both offensive and defensive, and much like the challenges, these effects range from serious to absurd.

\n\n

With all of the contest being web based, both hacking and Quake, players MUST bring their own laptop (or whatever device they want to use) and a wired network adapter.

\n\n

Grab your friends!

\n\n

Ask that random stranger standing next to you in Linecon if they want to join your team!

\n\n

Come play HACKFORTRESS!

\n\n

Participant Prerequisites

\n\n

All players will need to bring a laptop and wired network adapter. Since we are now using web based version of Quake 3 (which can run on players phones), we are no longer providing any gaming laptops.

\n\n

Gamers: bring any gaming accessory of your choice, its your hardware, go for it

\n\n

Hackers: bring lockpicks

\n\nLinks:
    Website - https://hackfortress.net/
\n\'',NULL,1297626),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_f2bfad55ea03232b0e106de3732d487f','\'\'',NULL,1297627),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_d3aee4489be1e3a121e7533c5b993361','\'Title: HackFortress
\nTags: HackFortress | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 108 (HackFortress) - Map
\n
\nDescription:
\n

HackFortress is back! Returning to DEF CON with a twist on our standard format. Two teams of players, 6 gamers and 4 hackers each, compete in a mashup of a jeopardy style CTF and a first person shooter. New this year, we\'re replacing our previous FPS of Team Fortress 2 with a web based version of the 2000\'s classic Quake 3!

\n\n

While gamers are rocket jumping and sniping each other in Quake, hackers will be solving challenges in a variety of areas: web security, network security, cryptography, lock picking, social engineering, and more! Challenges range from beginner to advanced, from serious to absurd. During the competition, as both sides of the team star scoring points, the teams also earn points in the HackFortess HackConomy Store, in the store hackers can buy in game effects, both offensive and defensive, and much like the challenges, these effects range from serious to absurd.

\n\n

With all of the contest being web based, both hacking and Quake, players MUST bring their own laptop (or whatever device they want to use) and a wired network adapter.

\n\n

Grab your friends!

\n\n

Ask that random stranger standing next to you in Linecon if they want to join your team!

\n\n

Come play HACKFORTRESS!

\n\n

Participant Prerequisites

\n\n

All players will need to bring a laptop and wired network adapter. Since we are now using web based version of Quake 3 (which can run on players phones), we are no longer providing any gaming laptops.

\n\n

Gamers: bring any gaming accessory of your choice, its your hardware, go for it

\n\n

Hackers: bring lockpicks

\n\nLinks:
    Website - https://hackfortress.net/
\n\'',NULL,1297628),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_d3aee4489be1e3a121e7533c5b993361','\'\'',NULL,1297629),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_d3aee4489be1e3a121e7533c5b993361','\'\'',NULL,1297630),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_d3aee4489be1e3a121e7533c5b993361','\'\'',NULL,1297631),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_d3aee4489be1e3a121e7533c5b993361','\'\'',NULL,1297632),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_d3aee4489be1e3a121e7533c5b993361','\'\'',NULL,1297633),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_d3aee4489be1e3a121e7533c5b993361','\'\'',NULL,1297634),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_d3aee4489be1e3a121e7533c5b993361','\'\'',NULL,1297635),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_259c491271c90adb8ae52c286e6cf859','\'Title: HackFortress
\nTags: HackFortress | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 108 (HackFortress) - Map
\n
\nDescription:
\n

HackFortress is back! Returning to DEF CON with a twist on our standard format. Two teams of players, 6 gamers and 4 hackers each, compete in a mashup of a jeopardy style CTF and a first person shooter. New this year, we\'re replacing our previous FPS of Team Fortress 2 with a web based version of the 2000\'s classic Quake 3!

\n\n

While gamers are rocket jumping and sniping each other in Quake, hackers will be solving challenges in a variety of areas: web security, network security, cryptography, lock picking, social engineering, and more! Challenges range from beginner to advanced, from serious to absurd. During the competition, as both sides of the team star scoring points, the teams also earn points in the HackFortess HackConomy Store, in the store hackers can buy in game effects, both offensive and defensive, and much like the challenges, these effects range from serious to absurd.

\n\n

With all of the contest being web based, both hacking and Quake, players MUST bring their own laptop (or whatever device they want to use) and a wired network adapter.

\n\n

Grab your friends!

\n\n

Ask that random stranger standing next to you in Linecon if they want to join your team!

\n\n

Come play HACKFORTRESS!

\n\n

Participant Prerequisites

\n\n

All players will need to bring a laptop and wired network adapter. Since we are now using web based version of Quake 3 (which can run on players phones), we are no longer providing any gaming laptops.

\n\n

Gamers: bring any gaming accessory of your choice, its your hardware, go for it

\n\n

Hackers: bring lockpicks

\n\nLinks:
    Website - https://hackfortress.net/
\n\'',NULL,1297636),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_259c491271c90adb8ae52c286e6cf859','\'\'',NULL,1297637),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_259c491271c90adb8ae52c286e6cf859','\'\'',NULL,1297638),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_259c491271c90adb8ae52c286e6cf859','\'\'',NULL,1297639),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_259c491271c90adb8ae52c286e6cf859','\'\'',NULL,1297640),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_259c491271c90adb8ae52c286e6cf859','\'\'',NULL,1297641),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_259c491271c90adb8ae52c286e6cf859','\'\'',NULL,1297642),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 108 (HackFortress)','\'HackFortress\'','\'\'','Contests_259c491271c90adb8ae52c286e6cf859','\'\'',NULL,1297643),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_7b313c3ae8d3f8719cba73af71016c7f','\'Title: Kubernetes CTF
\nTags: Kubernetes CTF | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 212 (Kubernetes CTF) - Map
\n
\nDescription:
\n

Want to learn more about Kubernetes hacking or compete against other people in a Capture the Flag contest? Sign up online and come see us in person/on Discord at the Kubernetes Capture the Flag (CTF) contest.

\n\n

We have two events — you can play in both if you like.

\n\n

Learning (non-competitive) CTF — Friday-Sunday

\n\n

From Friday to Sunday, we have a non-competitive Learning CTF, where you can go through last year\'s Kubernetes CTF scenario, referring to a cheat sheet whenever you want. This runs from Friday 12:00 to Sunday 12:00. We\'ll be in the contest area to support you during:

\n\n

Friday: 12:00-17:00\nSaturday: 10:00-17:00\nSunday: 10:00-12:00

\n\n

Competitive CTF — Saturday Only

\n\n

On Saturday only, you can play in the competitive Kubernetes CTF challenge, where teams (of one or more) can build and test their skills. Each team is given access to the CTFd system that contains a set of challenges. For each challenge, they will be able to launch a cluster on demand.

\n\n

This runs from 10:30am to 5:30pm on Saturday. The competitive CTF is an in-person experience. To register for the competitive CTF, you must come to the contest booth at DEF CON to receive the CTFd joining code.

\n\n

Find out more and sign up at: https://containersecurityctf.com/

\n\nLinks:
    Mastodon (@containersecurityctf@defcon.social) - https://defcon.social/@containersecurityctf
\n    Website - https://containersecurityctf.com/
\n\'',NULL,1297644),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_7b313c3ae8d3f8719cba73af71016c7f','\'\'',NULL,1297645),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_e33599f0fdcd3e11ccb5eb4d9829ff62','\'Title: Kubernetes CTF
\nTags: Kubernetes CTF | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 212 (Kubernetes CTF) - Map
\n
\nDescription:
\n

Want to learn more about Kubernetes hacking or compete against other people in a Capture the Flag contest? Sign up online and come see us in person/on Discord at the Kubernetes Capture the Flag (CTF) contest.

\n\n

We have two events — you can play in both if you like.

\n\n

Learning (non-competitive) CTF — Friday-Sunday

\n\n

From Friday to Sunday, we have a non-competitive Learning CTF, where you can go through last year\'s Kubernetes CTF scenario, referring to a cheat sheet whenever you want. This runs from Friday 12:00 to Sunday 12:00. We\'ll be in the contest area to support you during:

\n\n

Friday: 12:00-17:00\nSaturday: 10:00-17:00\nSunday: 10:00-12:00

\n\n

Competitive CTF — Saturday Only

\n\n

On Saturday only, you can play in the competitive Kubernetes CTF challenge, where teams (of one or more) can build and test their skills. Each team is given access to the CTFd system that contains a set of challenges. For each challenge, they will be able to launch a cluster on demand.

\n\n

This runs from 10:30am to 5:30pm on Saturday. The competitive CTF is an in-person experience. To register for the competitive CTF, you must come to the contest booth at DEF CON to receive the CTFd joining code.

\n\n

Find out more and sign up at: https://containersecurityctf.com/

\n\nLinks:
    Mastodon (@containersecurityctf@defcon.social) - https://defcon.social/@containersecurityctf
\n    Website - https://containersecurityctf.com/
\n\'',NULL,1297646),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_e33599f0fdcd3e11ccb5eb4d9829ff62','\'\'',NULL,1297647),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_e33599f0fdcd3e11ccb5eb4d9829ff62','\'\'',NULL,1297648),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_e33599f0fdcd3e11ccb5eb4d9829ff62','\'\'',NULL,1297649),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_e33599f0fdcd3e11ccb5eb4d9829ff62','\'\'',NULL,1297650),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_e33599f0fdcd3e11ccb5eb4d9829ff62','\'\'',NULL,1297651),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_e33599f0fdcd3e11ccb5eb4d9829ff62','\'\'',NULL,1297652),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_e33599f0fdcd3e11ccb5eb4d9829ff62','\'\'',NULL,1297653),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_46879e597c0eb66b76bfa7cf5b57dd42','\'Title: Kubernetes CTF
\nTags: Kubernetes CTF | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 212 (Kubernetes CTF) - Map
\n
\nDescription:
\n

Want to learn more about Kubernetes hacking or compete against other people in a Capture the Flag contest? Sign up online and come see us in person/on Discord at the Kubernetes Capture the Flag (CTF) contest.

\n\n

We have two events — you can play in both if you like.

\n\n

Learning (non-competitive) CTF — Friday-Sunday

\n\n

From Friday to Sunday, we have a non-competitive Learning CTF, where you can go through last year\'s Kubernetes CTF scenario, referring to a cheat sheet whenever you want. This runs from Friday 12:00 to Sunday 12:00. We\'ll be in the contest area to support you during:

\n\n

Friday: 12:00-17:00\nSaturday: 10:00-17:00\nSunday: 10:00-12:00

\n\n

Competitive CTF — Saturday Only

\n\n

On Saturday only, you can play in the competitive Kubernetes CTF challenge, where teams (of one or more) can build and test their skills. Each team is given access to the CTFd system that contains a set of challenges. For each challenge, they will be able to launch a cluster on demand.

\n\n

This runs from 10:30am to 5:30pm on Saturday. The competitive CTF is an in-person experience. To register for the competitive CTF, you must come to the contest booth at DEF CON to receive the CTFd joining code.

\n\n

Find out more and sign up at: https://containersecurityctf.com/

\n\nLinks:
    Mastodon (@containersecurityctf@defcon.social) - https://defcon.social/@containersecurityctf
\n    Website - https://containersecurityctf.com/
\n\'',NULL,1297654),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_46879e597c0eb66b76bfa7cf5b57dd42','\'\'',NULL,1297655),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_46879e597c0eb66b76bfa7cf5b57dd42','\'\'',NULL,1297656),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_46879e597c0eb66b76bfa7cf5b57dd42','\'\'',NULL,1297657),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_46879e597c0eb66b76bfa7cf5b57dd42','\'\'',NULL,1297658),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_46879e597c0eb66b76bfa7cf5b57dd42','\'\'',NULL,1297659),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_46879e597c0eb66b76bfa7cf5b57dd42','\'\'',NULL,1297660),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 212 (Kubernetes CTF)','\'Kubernetes CTF\'','\'\'','Contests_46879e597c0eb66b76bfa7cf5b57dd42','\'\'',NULL,1297661),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3dee79895ac8d3fc453c71cb164096a7','\'Title: Pinball High Score Contest
\nTags: Pinball High Score Contest | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 304 (Pinball High Score Contest) - Map
\n
\nDescription:
\nThe Pinball High Score contest at DEF CON 34 will run Friday and Saturday: 10:00-18:00, Sunday 10:00-13:00 with games available for daily High Score contests, daily challenges and open qualifying for a main tournament. The daily contests will allow any attendee to play pinball games and attempt to record a qualifying high score on each of the unique games. At 17:00 on Saturday main tournament qualifying will end, tiebreakers will be played (if needed) and the top 8 players with the highest combined scores across all eligible machines will qualify for the Sunday finals event where they could become the next DEF CON Pinball Champion!
\n\n

Achieving a high score may sound simple but pinball rulesets are very complex and the skill to complete a “Wizard Mode” or achieve a high score requires research, practice, knowledge and execution. Out of the box thinking, analytical skills and pattern recognition are traits that pinball players must exhibit to be successful and some games have rule sets that can be studied and exploited to achieve a high score. Hackers are at an advantage here and while this is just a pinball contest, we expect that the community is ready for this challenge!

\n\n

Last year the contest measured how you moved the machine. This year, we\'re reading what happens inside it. Custom sensors feed SHELL, our Sub-surface Hidden Entertainment Layer Logic. When you unlock the right patterns, a hidden world appears on screens beneath the glass. Face off in secret mini-games, answer hacker trivia under pressure, and battle other players in competitive challenges where you can steal control mid-game. It\'s pinball within pinball, a clandestine layer of gameplay that only reveals itself to those who can crack the SHELL.

\n\n

Participant Prerequisites

\n\n

Nothing special is required. Any person can step up and enjoy a pinball game or they can spend 30+ hours solving our challenges if they want to play the deeper game.

\n\nLinks:
    Website - https://app.pinballhackers.com/
\n\'',NULL,1297662),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3dee79895ac8d3fc453c71cb164096a7','\'\'',NULL,1297663),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3dee79895ac8d3fc453c71cb164096a7','\'\'',NULL,1297664),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3dee79895ac8d3fc453c71cb164096a7','\'\'',NULL,1297665),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3dee79895ac8d3fc453c71cb164096a7','\'\'',NULL,1297666),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3dee79895ac8d3fc453c71cb164096a7','\'\'',NULL,1297667),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3dee79895ac8d3fc453c71cb164096a7','\'\'',NULL,1297668),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3dee79895ac8d3fc453c71cb164096a7','\'\'',NULL,1297669),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3ffb22d121fb0ee3c9147a7209c1f565','\'Title: Pinball High Score Contest
\nTags: Pinball High Score Contest | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 304 (Pinball High Score Contest) - Map
\n
\nDescription:
\nThe Pinball High Score contest at DEF CON 34 will run Friday and Saturday: 10:00-18:00, Sunday 10:00-13:00 with games available for daily High Score contests, daily challenges and open qualifying for a main tournament. The daily contests will allow any attendee to play pinball games and attempt to record a qualifying high score on each of the unique games. At 17:00 on Saturday main tournament qualifying will end, tiebreakers will be played (if needed) and the top 8 players with the highest combined scores across all eligible machines will qualify for the Sunday finals event where they could become the next DEF CON Pinball Champion!
\n\n

Achieving a high score may sound simple but pinball rulesets are very complex and the skill to complete a “Wizard Mode” or achieve a high score requires research, practice, knowledge and execution. Out of the box thinking, analytical skills and pattern recognition are traits that pinball players must exhibit to be successful and some games have rule sets that can be studied and exploited to achieve a high score. Hackers are at an advantage here and while this is just a pinball contest, we expect that the community is ready for this challenge!

\n\n

Last year the contest measured how you moved the machine. This year, we\'re reading what happens inside it. Custom sensors feed SHELL, our Sub-surface Hidden Entertainment Layer Logic. When you unlock the right patterns, a hidden world appears on screens beneath the glass. Face off in secret mini-games, answer hacker trivia under pressure, and battle other players in competitive challenges where you can steal control mid-game. It\'s pinball within pinball, a clandestine layer of gameplay that only reveals itself to those who can crack the SHELL.

\n\n

Participant Prerequisites

\n\n

Nothing special is required. Any person can step up and enjoy a pinball game or they can spend 30+ hours solving our challenges if they want to play the deeper game.

\n\nLinks:
    Website - https://app.pinballhackers.com/
\n\'',NULL,1297670),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3ffb22d121fb0ee3c9147a7209c1f565','\'\'',NULL,1297671),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3ffb22d121fb0ee3c9147a7209c1f565','\'\'',NULL,1297672),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3ffb22d121fb0ee3c9147a7209c1f565','\'\'',NULL,1297673),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3ffb22d121fb0ee3c9147a7209c1f565','\'\'',NULL,1297674),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3ffb22d121fb0ee3c9147a7209c1f565','\'\'',NULL,1297675),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3ffb22d121fb0ee3c9147a7209c1f565','\'\'',NULL,1297676),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3ffb22d121fb0ee3c9147a7209c1f565','\'\'',NULL,1297677),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3a89dd6edfc8513ffb52c2a6095fcacc','\'Title: Pinball High Score Contest
\nTags: Pinball High Score Contest | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 304 (Pinball High Score Contest) - Map
\n
\nDescription:
\nThe Pinball High Score contest at DEF CON 34 will run Friday and Saturday: 10:00-18:00, Sunday 10:00-13:00 with games available for daily High Score contests, daily challenges and open qualifying for a main tournament. The daily contests will allow any attendee to play pinball games and attempt to record a qualifying high score on each of the unique games. At 17:00 on Saturday main tournament qualifying will end, tiebreakers will be played (if needed) and the top 8 players with the highest combined scores across all eligible machines will qualify for the Sunday finals event where they could become the next DEF CON Pinball Champion!
\n\n

Achieving a high score may sound simple but pinball rulesets are very complex and the skill to complete a “Wizard Mode” or achieve a high score requires research, practice, knowledge and execution. Out of the box thinking, analytical skills and pattern recognition are traits that pinball players must exhibit to be successful and some games have rule sets that can be studied and exploited to achieve a high score. Hackers are at an advantage here and while this is just a pinball contest, we expect that the community is ready for this challenge!

\n\n

Last year the contest measured how you moved the machine. This year, we\'re reading what happens inside it. Custom sensors feed SHELL, our Sub-surface Hidden Entertainment Layer Logic. When you unlock the right patterns, a hidden world appears on screens beneath the glass. Face off in secret mini-games, answer hacker trivia under pressure, and battle other players in competitive challenges where you can steal control mid-game. It\'s pinball within pinball, a clandestine layer of gameplay that only reveals itself to those who can crack the SHELL.

\n\n

Participant Prerequisites

\n\n

Nothing special is required. Any person can step up and enjoy a pinball game or they can spend 30+ hours solving our challenges if they want to play the deeper game.

\n\nLinks:
    Website - https://app.pinballhackers.com/
\n\'',NULL,1297678),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 304 (Pinball High Score Contest)','\'Pinball High Score Contest\'','\'\'','Contests_3a89dd6edfc8513ffb52c2a6095fcacc','\'\'',NULL,1297679),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_4411894e7839c08b6a3926ddeb7aae61','\'Title: spyVspy 3: Rat Race
\nTags: spyVspy 3: Rat Race | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race) - Map
\n
\nDescription:
\n

spyVspy is back, and this year, you\'re racing.

\n\n

Embark on a thrilling espionage adventure with spyVspy 3: Rat Race! This contest imagines a world of spy games where contestants employ basic hacking, cryptography, and rogue skills to solve puzzles and uncover hidden caches strategically scattered throughout DEF CON (and beyond).

\n\n

Challenges leading to the location of hidden caches will be released on a rolling schedule. By solving these challenges and being the first team to reach a cache, you will qualify for a final series of challenges on Saturday afternoon. Not the first? That\'s okay - you\'ll still have fun and earn cool spyVspy slabbed cards

\n\n

spyVspy 3: Rat Race is intended for players of all skill levels. Whether you\'re a seasoned double-agent or just learning to be a covert operative, you will be able to compete and have fun in this event. Whatever skills you think you\'re missing can probably be learned on-the-job anyway.

\n\n

Participant Prerequisites

\n\n

A laptop would be great, but some puzzles may be solvable on a phone.

\n\nLinks:
    Website - https://www.fottr.io/
\n\'',NULL,1297680),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_4411894e7839c08b6a3926ddeb7aae61','\'\'',NULL,1297681),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_6b6ff5cac6d37b0e40ba934e597fd777','\'Title: spyVspy 3: Rat Race
\nTags: spyVspy 3: Rat Race | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race) - Map
\n
\nDescription:
\n

spyVspy is back, and this year, you\'re racing.

\n\n

Embark on a thrilling espionage adventure with spyVspy 3: Rat Race! This contest imagines a world of spy games where contestants employ basic hacking, cryptography, and rogue skills to solve puzzles and uncover hidden caches strategically scattered throughout DEF CON (and beyond).

\n\n

Challenges leading to the location of hidden caches will be released on a rolling schedule. By solving these challenges and being the first team to reach a cache, you will qualify for a final series of challenges on Saturday afternoon. Not the first? That\'s okay - you\'ll still have fun and earn cool spyVspy slabbed cards

\n\n

spyVspy 3: Rat Race is intended for players of all skill levels. Whether you\'re a seasoned double-agent or just learning to be a covert operative, you will be able to compete and have fun in this event. Whatever skills you think you\'re missing can probably be learned on-the-job anyway.

\n\n

Participant Prerequisites

\n\n

A laptop would be great, but some puzzles may be solvable on a phone.

\n\nLinks:
    Website - https://www.fottr.io/
\n\'',NULL,1297682),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_6b6ff5cac6d37b0e40ba934e597fd777','\'\'',NULL,1297683),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_6b6ff5cac6d37b0e40ba934e597fd777','\'\'',NULL,1297684),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_6b6ff5cac6d37b0e40ba934e597fd777','\'\'',NULL,1297685),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_6b6ff5cac6d37b0e40ba934e597fd777','\'\'',NULL,1297686),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_6b6ff5cac6d37b0e40ba934e597fd777','\'\'',NULL,1297687),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_6b6ff5cac6d37b0e40ba934e597fd777','\'\'',NULL,1297688),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_6b6ff5cac6d37b0e40ba934e597fd777','\'\'',NULL,1297689),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_bd6c73174f52122ec1447a8545b2d5f4','\'Title: spyVspy 3: Rat Race
\nTags: spyVspy 3: Rat Race | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race) - Map
\n
\nDescription:
\n

spyVspy is back, and this year, you\'re racing.

\n\n

Embark on a thrilling espionage adventure with spyVspy 3: Rat Race! This contest imagines a world of spy games where contestants employ basic hacking, cryptography, and rogue skills to solve puzzles and uncover hidden caches strategically scattered throughout DEF CON (and beyond).

\n\n

Challenges leading to the location of hidden caches will be released on a rolling schedule. By solving these challenges and being the first team to reach a cache, you will qualify for a final series of challenges on Saturday afternoon. Not the first? That\'s okay - you\'ll still have fun and earn cool spyVspy slabbed cards

\n\n

spyVspy 3: Rat Race is intended for players of all skill levels. Whether you\'re a seasoned double-agent or just learning to be a covert operative, you will be able to compete and have fun in this event. Whatever skills you think you\'re missing can probably be learned on-the-job anyway.

\n\n

Participant Prerequisites

\n\n

A laptop would be great, but some puzzles may be solvable on a phone.

\n\nLinks:
    Website - https://www.fottr.io/
\n\'',NULL,1297690),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_bd6c73174f52122ec1447a8545b2d5f4','\'\'',NULL,1297691),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_bd6c73174f52122ec1447a8545b2d5f4','\'\'',NULL,1297692),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_bd6c73174f52122ec1447a8545b2d5f4','\'\'',NULL,1297693),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_bd6c73174f52122ec1447a8545b2d5f4','\'\'',NULL,1297694),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_bd6c73174f52122ec1447a8545b2d5f4','\'\'',NULL,1297695),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_bd6c73174f52122ec1447a8545b2d5f4','\'\'',NULL,1297696),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 206 (spyVspy 3: Rat Race)','\'spyVspy 3: Rat Race\'','\'\'','Contests_bd6c73174f52122ec1447a8545b2d5f4','\'\'',NULL,1297697),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_2b93f8ca13980f22193c8ae74d0ff540','\'Title: TeleChallenge
\nTags: TeleChallenge | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 107 (TeleChallenge) - Map
\n
\nDescription:
\n

The TeleChallenge isn\'t just a puzzle challenge, it\'s an experience. We are super excited to show the plan for the tenth year in a row. Don\'t copy that floppy, but instead prepare to be immersed in an entirely new world where all of your hacker skills will be challenged (along with your 0xEA60 skills). This is a very tough contest to win, and is among the most challenging at DEF CON. Are you ready? Your first step is to find us, because part of the puzzle is discovering the puzzle.

\n\n

Participant Prerequisites

\n\n

You\'ll need a phone, your creativity and some hacker friends. It also helps to have access to a computer. Use the TeleChallenge as an excuse to meet people and form a team.

\n\n

Pre-Qualification

\n\n

We may have team registration in advance, but there is no pre-qualifyer.

\n\nLinks:
    Website - https://www.telechallenge.org/
\n    Mastodon (@telechallenge@defcon.social) - https://defcon.social/@telechallenge
\n\'',NULL,1297698),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_2b93f8ca13980f22193c8ae74d0ff540','\'\'',NULL,1297699),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_2b93f8ca13980f22193c8ae74d0ff540','\'\'',NULL,1297700),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_2b93f8ca13980f22193c8ae74d0ff540','\'\'',NULL,1297701),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_2b93f8ca13980f22193c8ae74d0ff540','\'\'',NULL,1297702),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_2b93f8ca13980f22193c8ae74d0ff540','\'\'',NULL,1297703),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_2b93f8ca13980f22193c8ae74d0ff540','\'\'',NULL,1297704),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_2b93f8ca13980f22193c8ae74d0ff540','\'\'',NULL,1297705),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_a36ebd1028bf04bf9071ebe327dec5c9','\'Title: TeleChallenge
\nTags: TeleChallenge | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 107 (TeleChallenge) - Map
\n
\nDescription:
\n

The TeleChallenge isn\'t just a puzzle challenge, it\'s an experience. We are super excited to show the plan for the tenth year in a row. Don\'t copy that floppy, but instead prepare to be immersed in an entirely new world where all of your hacker skills will be challenged (along with your 0xEA60 skills). This is a very tough contest to win, and is among the most challenging at DEF CON. Are you ready? Your first step is to find us, because part of the puzzle is discovering the puzzle.

\n\n

Participant Prerequisites

\n\n

You\'ll need a phone, your creativity and some hacker friends. It also helps to have access to a computer. Use the TeleChallenge as an excuse to meet people and form a team.

\n\n

Pre-Qualification

\n\n

We may have team registration in advance, but there is no pre-qualifyer.

\n\nLinks:
    Website - https://www.telechallenge.org/
\n    Mastodon (@telechallenge@defcon.social) - https://defcon.social/@telechallenge
\n\'',NULL,1297706),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_a36ebd1028bf04bf9071ebe327dec5c9','\'\'',NULL,1297707),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_a36ebd1028bf04bf9071ebe327dec5c9','\'\'',NULL,1297708),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_a36ebd1028bf04bf9071ebe327dec5c9','\'\'',NULL,1297709),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_a36ebd1028bf04bf9071ebe327dec5c9','\'\'',NULL,1297710),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_a36ebd1028bf04bf9071ebe327dec5c9','\'\'',NULL,1297711),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_a36ebd1028bf04bf9071ebe327dec5c9','\'\'',NULL,1297712),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_a36ebd1028bf04bf9071ebe327dec5c9','\'\'',NULL,1297713),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_ef1dc48f5ed59d43225a69beea84db93','\'Title: TeleChallenge
\nTags: TeleChallenge | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 107 (TeleChallenge) - Map
\n
\nDescription:
\n

The TeleChallenge isn\'t just a puzzle challenge, it\'s an experience. We are super excited to show the plan for the tenth year in a row. Don\'t copy that floppy, but instead prepare to be immersed in an entirely new world where all of your hacker skills will be challenged (along with your 0xEA60 skills). This is a very tough contest to win, and is among the most challenging at DEF CON. Are you ready? Your first step is to find us, because part of the puzzle is discovering the puzzle.

\n\n

Participant Prerequisites

\n\n

You\'ll need a phone, your creativity and some hacker friends. It also helps to have access to a computer. Use the TeleChallenge as an excuse to meet people and form a team.

\n\n

Pre-Qualification

\n\n

We may have team registration in advance, but there is no pre-qualifyer.

\n\nLinks:
    Website - https://www.telechallenge.org/
\n    Mastodon (@telechallenge@defcon.social) - https://defcon.social/@telechallenge
\n\'',NULL,1297714),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 107 (TeleChallenge)','\'TeleChallenge\'','\'\'','Contests_ef1dc48f5ed59d43225a69beea84db93','\'\'',NULL,1297715),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_9f4f8633a31c73fffaee9b8c43e2348c','\'Title: Tin Foil Hat Contest
\nTags: Tin Foil Hat Contest | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest) - Map
\n
\nDescription:
\n

Want to protect your noggin from government mind control rays? Have you angered our new AI Overlords, and now need to hide? Maybe those alien brainwave blasters just have you feeling down lately? Or do you just want to do something fun and forget about the world\'s woes for a while? Fear not, for we here at the Tin Foil Hat Contest have your back for all of these! Come find us in the contest area, and we\'ll have you build a tin foil hat which is guaranteed to provide top quality protection for your cerebellum . How you ask? SCIENCE!

\n\n

Show us your skills by building a tin foil hat to shield your subversive thoughts, then test it out for effectiveness.

\n\n

There are 2 categories: stock and unlimited. The hat in each category that causes the most signal attenuation will receive the \"\"Substance\"\" award for that category. We all know that hacker culture is all about looking good though, so a single winner will be selected for \"\"Style\"\". We provide all contestants a meter of foil, but you\'re welcome to acquire and use as much as you want from other sources.

\n\n

This year is dedicated to our brother & contest creator, Flirzan. We\'ll never forget drunkenly hashing this out on a napkin with you at DEFCON many years ago. Rest in peace, we miss you friend!

\n\n

Participant Prerequisites

\n\n

We supply the base materials to participate. Contestants are welcome to bring additional foil if they desire.

\n\n\'',NULL,1297716),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_9f4f8633a31c73fffaee9b8c43e2348c','\'\'',NULL,1297717),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_9f4f8633a31c73fffaee9b8c43e2348c','\'\'',NULL,1297718),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_9f4f8633a31c73fffaee9b8c43e2348c','\'\'',NULL,1297719),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_9f4f8633a31c73fffaee9b8c43e2348c','\'\'',NULL,1297720),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_9f4f8633a31c73fffaee9b8c43e2348c','\'\'',NULL,1297721),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_9f4f8633a31c73fffaee9b8c43e2348c','\'\'',NULL,1297722),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_9f4f8633a31c73fffaee9b8c43e2348c','\'\'',NULL,1297723),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_26a524a5022c24e6f962180f2c6be24c','\'Title: Tin Foil Hat Contest
\nTags: Tin Foil Hat Contest | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest) - Map
\n
\nDescription:
\n

Want to protect your noggin from government mind control rays? Have you angered our new AI Overlords, and now need to hide? Maybe those alien brainwave blasters just have you feeling down lately? Or do you just want to do something fun and forget about the world\'s woes for a while? Fear not, for we here at the Tin Foil Hat Contest have your back for all of these! Come find us in the contest area, and we\'ll have you build a tin foil hat which is guaranteed to provide top quality protection for your cerebellum . How you ask? SCIENCE!

\n\n

Show us your skills by building a tin foil hat to shield your subversive thoughts, then test it out for effectiveness.

\n\n

There are 2 categories: stock and unlimited. The hat in each category that causes the most signal attenuation will receive the \"\"Substance\"\" award for that category. We all know that hacker culture is all about looking good though, so a single winner will be selected for \"\"Style\"\". We provide all contestants a meter of foil, but you\'re welcome to acquire and use as much as you want from other sources.

\n\n

This year is dedicated to our brother & contest creator, Flirzan. We\'ll never forget drunkenly hashing this out on a napkin with you at DEFCON many years ago. Rest in peace, we miss you friend!

\n\n

Participant Prerequisites

\n\n

We supply the base materials to participate. Contestants are welcome to bring additional foil if they desire.

\n\n\'',NULL,1297724),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_26a524a5022c24e6f962180f2c6be24c','\'\'',NULL,1297725),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_26a524a5022c24e6f962180f2c6be24c','\'\'',NULL,1297726),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_26a524a5022c24e6f962180f2c6be24c','\'\'',NULL,1297727),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_26a524a5022c24e6f962180f2c6be24c','\'\'',NULL,1297728),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_26a524a5022c24e6f962180f2c6be24c','\'\'',NULL,1297729),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_26a524a5022c24e6f962180f2c6be24c','\'\'',NULL,1297730),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_26a524a5022c24e6f962180f2c6be24c','\'\'',NULL,1297731),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_a39f6338847aa59cab06a69a049c224c','\'Title: Tin Foil Hat Contest
\nTags: Tin Foil Hat Contest | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest) - Map
\n
\nDescription:
\n

Want to protect your noggin from government mind control rays? Have you angered our new AI Overlords, and now need to hide? Maybe those alien brainwave blasters just have you feeling down lately? Or do you just want to do something fun and forget about the world\'s woes for a while? Fear not, for we here at the Tin Foil Hat Contest have your back for all of these! Come find us in the contest area, and we\'ll have you build a tin foil hat which is guaranteed to provide top quality protection for your cerebellum . How you ask? SCIENCE!

\n\n

Show us your skills by building a tin foil hat to shield your subversive thoughts, then test it out for effectiveness.

\n\n

There are 2 categories: stock and unlimited. The hat in each category that causes the most signal attenuation will receive the \"\"Substance\"\" award for that category. We all know that hacker culture is all about looking good though, so a single winner will be selected for \"\"Style\"\". We provide all contestants a meter of foil, but you\'re welcome to acquire and use as much as you want from other sources.

\n\n

This year is dedicated to our brother & contest creator, Flirzan. We\'ll never forget drunkenly hashing this out on a napkin with you at DEFCON many years ago. Rest in peace, we miss you friend!

\n\n

Participant Prerequisites

\n\n

We supply the base materials to participate. Contestants are welcome to bring additional foil if they desire.

\n\n\'',NULL,1297732),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 403 (Tin Foil Hat Contest)','\'Tin Foil Hat Contest\'','\'\'','Contests_a39f6338847aa59cab06a69a049c224c','\'\'',NULL,1297733),('4_Sunday','10','10:00','11:59','N','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_5613211f5bf599aab764eda9541af9ad','\'Title: Untechnical
\nTags: Untechnical | Contest
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 103 (Untechnical) - Map
\n
\nDescription:
\n

In the age of AI hacking is reclaiming itself as more a mindset than strictly technical skill. If you\'re a DEFCON attendee that lack the technical skills to compete in traditional hacking challenges, but still love thinking outside the box: untechnical is for you.

\n\n

Untechnical is a contest designed to rely 100% on lateral/abstract thinking without needing anything beyond an understanding of high school math.

\n\n

Participant Prerequisites

\n\n

Need to understand basic math and enjoy thinking outside the box. Oh, and you need an email address.

\n\nLinks:
    Website - https://www.untechnical.app/
\n\'',NULL,1297734),('4_Sunday','11','10:00','11:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_5613211f5bf599aab764eda9541af9ad','\'\'',NULL,1297735),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_f8cae2e6ddaddcedbd6109d2f3b88233','\'Title: Untechnical
\nTags: Untechnical | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 103 (Untechnical) - Map
\n
\nDescription:
\n

In the age of AI hacking is reclaiming itself as more a mindset than strictly technical skill. If you\'re a DEFCON attendee that lack the technical skills to compete in traditional hacking challenges, but still love thinking outside the box: untechnical is for you.

\n\n

Untechnical is a contest designed to rely 100% on lateral/abstract thinking without needing anything beyond an understanding of high school math.

\n\n

Participant Prerequisites

\n\n

Need to understand basic math and enjoy thinking outside the box. Oh, and you need an email address.

\n\nLinks:
    Website - https://www.untechnical.app/
\n\'',NULL,1297736),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_f8cae2e6ddaddcedbd6109d2f3b88233','\'\'',NULL,1297737),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_f8cae2e6ddaddcedbd6109d2f3b88233','\'\'',NULL,1297738),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_f8cae2e6ddaddcedbd6109d2f3b88233','\'\'',NULL,1297739),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_f8cae2e6ddaddcedbd6109d2f3b88233','\'\'',NULL,1297740),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_f8cae2e6ddaddcedbd6109d2f3b88233','\'\'',NULL,1297741),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_f8cae2e6ddaddcedbd6109d2f3b88233','\'\'',NULL,1297742),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_f8cae2e6ddaddcedbd6109d2f3b88233','\'\'',NULL,1297743),('3_Saturday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_c63cbd98122b96fea6cbd151ba9f0e88','\'Title: Untechnical
\nTags: Untechnical | Contest
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 103 (Untechnical) - Map
\n
\nDescription:
\n

In the age of AI hacking is reclaiming itself as more a mindset than strictly technical skill. If you\'re a DEFCON attendee that lack the technical skills to compete in traditional hacking challenges, but still love thinking outside the box: untechnical is for you.

\n\n

Untechnical is a contest designed to rely 100% on lateral/abstract thinking without needing anything beyond an understanding of high school math.

\n\n

Participant Prerequisites

\n\n

Need to understand basic math and enjoy thinking outside the box. Oh, and you need an email address.

\n\nLinks:
    Website - https://www.untechnical.app/
\n\'',NULL,1297744),('3_Saturday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_c63cbd98122b96fea6cbd151ba9f0e88','\'\'',NULL,1297745),('3_Saturday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_c63cbd98122b96fea6cbd151ba9f0e88','\'\'',NULL,1297746),('3_Saturday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_c63cbd98122b96fea6cbd151ba9f0e88','\'\'',NULL,1297747),('3_Saturday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_c63cbd98122b96fea6cbd151ba9f0e88','\'\'',NULL,1297748),('3_Saturday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_c63cbd98122b96fea6cbd151ba9f0e88','\'\'',NULL,1297749),('3_Saturday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_c63cbd98122b96fea6cbd151ba9f0e88','\'\'',NULL,1297750),('3_Saturday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 1 103 (Untechnical)','\'Untechnical\'','\'\'','Contests_c63cbd98122b96fea6cbd151ba9f0e88','\'\'',NULL,1297751),('3_Saturday','17','17:30','20:30','N','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers\'','\'Jake Braun\'','DEF CON Talks_086c30f245bf4d14f703a7a75f3959ea','\'Title: DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers
\nTags: DEF CON Official Talk
\nWhen: Saturday, Aug 8, 17:30 - 20:30 PDT
\nWhere: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - Map
\n
\nDescription:
\n

How did DEF CON Franklin\'s cyber volunteers helped American water systems become more secure as they rise to the top of adversaries’ target lists? This talk by Franklin co-founder Jake Braun will outline the program, share success stories from volunteer engagements, and discuss lessons learned from the past year of deployments. The session will also cover Franklin’s expansion into new states, highlight findings from the DEF CON Hackers’ Almanack, and examine why leading security tools struggle to meet the needs of resource-constrained water systems. Finally, the talk will lay out a path to scaling cybersecurity for water systems nationwide through a centrally managed network of regional MSSPs, and how the DEF CON community can help build it from the ground up.

\n\nSpeakerBio:  Jake Braun, DEF CON Franklin
\n

Jake Braun is the co-founder of DEF CON Franklin and the Executive Director of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy. He most recently served in the White House as acting Principal Deputy National Cyber Director. While at the White House, he oversaw the implementation of the National Cybersecurity Strategy, including efforts to secure our water systems, modernize the federal cyber workforce, enhance cyber cooperation with allied nations, and develop AI cybersecurity policy.

\n\n

In addition to his role at the University of Chicago, Mr. Braun co-founded the DEF CON Voting Machine Hacking Village. In that capacity, he co-authored two award-winning reports on the cyber security of our election infrastructure: the DEF CON 25 and 26 Voting Village Reports. Most recently, he partnered with DEF CON, the world\'s largest and longest running hacker conference, to launch “DEF CON Franklin,” a program to memorialize the most innovative and impactful findings from DEF CON in the annual “Hackers’ Almanack.” “DEF CON Franklin” also recruits cyber volunteers to support underresourced critical infrastructure.

\n\n\nLinks:
    LinkedIn - https://www.linkedin.com/company/def-con-franklin
\n    Website - https://defconfranklin.com
\n    Bluesky - https://bsky.app/profile/projectfranklin.bsky.social
\n\'',NULL,1297752),('3_Saturday','18','17:30','20:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers\'','\'Jake Braun\'','DEF CON Talks_086c30f245bf4d14f703a7a75f3959ea','\'\'',NULL,1297753),('3_Saturday','19','17:30','20:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers\'','\'Jake Braun\'','DEF CON Talks_086c30f245bf4d14f703a7a75f3959ea','\'\'',NULL,1297754),('3_Saturday','20','17:30','20:30','Y','DEF CON Talks','LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4','\'DEF CON Franklin: What worked, what didn’t, and how we are giving agency to water utilities at the top of every bad guy’s target list because of data centers\'','\'Jake Braun\'','DEF CON Talks_086c30f245bf4d14f703a7a75f3959ea','\'\'',NULL,1297755),('2_Friday','10','10:00','17:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_97eda14c20c4b927e5c3efa52c251edb','\'Title: KSCM Scambait Radio
\nTags: Scambait Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

Prerecorded scambait calls running in Discord voice throughout the day. Bring earbuds and tune in from your phone while you walk the village or the rest of the con. Listen to real interactions, hear how experienced baiters handle different situations, and pick up new techniques and banter styles. Ambient and educational, drop in for a few minutes or stay for a whole set.

\n\nLinks:
    scambaitvillage.org/radio - https://scambaitvillage.org/radio
\n\'',NULL,1297756),('2_Friday','11','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_97eda14c20c4b927e5c3efa52c251edb','\'\'',NULL,1297757),('2_Friday','12','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_97eda14c20c4b927e5c3efa52c251edb','\'\'',NULL,1297758),('2_Friday','13','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_97eda14c20c4b927e5c3efa52c251edb','\'\'',NULL,1297759),('2_Friday','14','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_97eda14c20c4b927e5c3efa52c251edb','\'\'',NULL,1297760),('2_Friday','15','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_97eda14c20c4b927e5c3efa52c251edb','\'\'',NULL,1297761),('2_Friday','16','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_97eda14c20c4b927e5c3efa52c251edb','\'\'',NULL,1297762),('2_Friday','17','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_97eda14c20c4b927e5c3efa52c251edb','\'\'',NULL,1297763),('2_Friday','10','10:00','17:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_783af77b9ea762271f3fc6218c86f471','\'Title: Open Q&A
\nTags: Scambait Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

Drop-in Q&A running throughout the village whenever the hall is open. Knowledgeable volunteers are stationed across the booth and can answer questions about scambaiting techniques, tools, safety, community norms, legal considerations, and anything else related to fighting scammers. No session times, no signup. Come by whenever, ask whatever. Casual and welcoming for both newcomers and veterans. Note that Q&A pauses briefly during scheduled talks and sessions at the village, listed separately on this schedule.

\n\nLinks:
    scambaitvillage.org - https://scambaitvillage.org
\n\'',NULL,1297764),('2_Friday','11','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_783af77b9ea762271f3fc6218c86f471','\'\'',NULL,1297765),('2_Friday','12','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_783af77b9ea762271f3fc6218c86f471','\'\'',NULL,1297766),('2_Friday','13','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_783af77b9ea762271f3fc6218c86f471','\'\'',NULL,1297767),('2_Friday','14','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_783af77b9ea762271f3fc6218c86f471','\'\'',NULL,1297768),('2_Friday','15','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_783af77b9ea762271f3fc6218c86f471','\'\'',NULL,1297769),('2_Friday','16','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_783af77b9ea762271f3fc6218c86f471','\'\'',NULL,1297770),('2_Friday','17','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_783af77b9ea762271f3fc6218c86f471','\'\'',NULL,1297771),('2_Friday','11','11:30','13:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Live Calls Workshop\'','\'\'','Creator Workshops_a51f33bad0e3da8fc5a00970f99e6b5e','\'Title: Live Calls Workshop
\nTags: Scambait Village | Creator Workshop
\nWhen: Friday, Aug 7, 11:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

Hands-on workshop focused on live scambaiting calls. Participants can observe, learn techniques, and join in on calls under guidance from experienced scambaiters. Covers safety practices, common scam types, tools, and real-time interaction strategies. Open to all skill levels. This is not a contest, but standout calls may earn a donated training course, handed out by village staff at their discretion at the end of the session.

\n\nLinks:
    scambaitvillage.org/join - https://scambaitvillage.org/join
\n\'',NULL,1297772),('2_Friday','12','11:30','13:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Live Calls Workshop\'','\'\'','Creator Workshops_a51f33bad0e3da8fc5a00970f99e6b5e','\'\'',NULL,1297773),('2_Friday','13','11:30','13:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Live Calls Workshop\'','\'\'','Creator Workshops_a51f33bad0e3da8fc5a00970f99e6b5e','\'\'',NULL,1297774),('2_Friday','14','14:00','17:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Live Call Listening\'','\'\'','Creator Events_346b8706bdafbf1023ae000b8f57924c','\'Title: Live Call Listening
\nTags: Scambait Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

A separate Discord channel running live calls, no recordings, listen-only. Runs periodically through Friday afternoon once the Live Calls Workshop wraps. Sometimes it is experienced baiters working a scammer in real time. Sometimes it is one of our bots, of which there are nearly 80 unique builds developed from call recordings captured during live baits. No participation, no signup, nothing required of you but earbuds. Good for anyone who would rather listen than talk.

\n\nLinks:
    scambaitvillage.org/join - https://scambaitvillage.org/join
\n\'',NULL,1297775),('2_Friday','15','14:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Live Call Listening\'','\'\'','Creator Events_346b8706bdafbf1023ae000b8f57924c','\'\'',NULL,1297776),('2_Friday','16','14:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Live Call Listening\'','\'\'','Creator Events_346b8706bdafbf1023ae000b8f57924c','\'\'',NULL,1297777),('2_Friday','17','14:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Live Call Listening\'','\'\'','Creator Events_346b8706bdafbf1023ae000b8f57924c','\'\'',NULL,1297778),('3_Saturday','10','10:00','17:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_2393c3493d4afd47986d276736dffac5','\'Title: KSCM Scambait Radio
\nTags: Scambait Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

Prerecorded scambait calls running in Discord voice throughout the day. Bring earbuds and tune in from your phone while you walk the village or the rest of the con. Listen to real interactions, hear how experienced baiters handle different situations, and pick up new techniques and banter styles. Ambient and educational, drop in for a few minutes or stay for a whole set.

\n\nLinks:
    scambaitvillage.org/radio - https://scambaitvillage.org/radio
\n\'',NULL,1297779),('3_Saturday','11','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_2393c3493d4afd47986d276736dffac5','\'\'',NULL,1297780),('3_Saturday','12','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_2393c3493d4afd47986d276736dffac5','\'\'',NULL,1297781),('3_Saturday','13','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_2393c3493d4afd47986d276736dffac5','\'\'',NULL,1297782),('3_Saturday','14','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_2393c3493d4afd47986d276736dffac5','\'\'',NULL,1297783),('3_Saturday','15','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_2393c3493d4afd47986d276736dffac5','\'\'',NULL,1297784),('3_Saturday','16','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_2393c3493d4afd47986d276736dffac5','\'\'',NULL,1297785),('3_Saturday','17','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_2393c3493d4afd47986d276736dffac5','\'\'',NULL,1297786),('3_Saturday','10','10:00','17:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_eb21fd49485e628ce2bda5b9d1aec5ff','\'Title: Open Q&A
\nTags: Scambait Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

Drop-in Q&A running throughout the village whenever the hall is open. Knowledgeable volunteers are stationed across the booth and can answer questions about scambaiting techniques, tools, safety, community norms, legal considerations, and anything else related to fighting scammers. No session times, no signup. Come by whenever, ask whatever. Casual and welcoming for both newcomers and veterans. Note that Q&A pauses briefly during scheduled talks and sessions at the village, listed separately on this schedule.

\n\nLinks:
    scambaitvillage.org - https://scambaitvillage.org
\n\'',NULL,1297787),('3_Saturday','11','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_eb21fd49485e628ce2bda5b9d1aec5ff','\'\'',NULL,1297788),('3_Saturday','12','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_eb21fd49485e628ce2bda5b9d1aec5ff','\'\'',NULL,1297789),('3_Saturday','13','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_eb21fd49485e628ce2bda5b9d1aec5ff','\'\'',NULL,1297790),('3_Saturday','14','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_eb21fd49485e628ce2bda5b9d1aec5ff','\'\'',NULL,1297791),('3_Saturday','15','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_eb21fd49485e628ce2bda5b9d1aec5ff','\'\'',NULL,1297792),('3_Saturday','16','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_eb21fd49485e628ce2bda5b9d1aec5ff','\'\'',NULL,1297793),('3_Saturday','17','10:00','17:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_eb21fd49485e628ce2bda5b9d1aec5ff','\'\'',NULL,1297794),('3_Saturday','12','12:30','13:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Scammers Don\'t Discriminate\'','\'DolphinVG\'','Creator Talks_b40040d98e2dbc7e3e2f7fe70de3287b','\'Title: Scammers Don\'t Discriminate
\nTags: Scambait Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

Scammers don\'t just target the elderly. Young people are increasingly in their crosshairs. In this talk, DolphinVG examines how fraudsters are adapting their tactics to exploit youth through social media, gaming platforms, crypto schemes, job scams, romance scams, and more. Drawing on real cases and community experience, the session highlights why younger generations are vulnerable, the unique pressures they face, and practical ways the scambait community can help protect them.

\n\nSpeakerBio:  DolphinVG
\nNo BIO available
\n\nLinks:
    scambaitvillage.org/speakers - https://scambaitvillage.org/speakers
\n\'',NULL,1297795),('3_Saturday','13','12:30','13:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Scammers Don\'t Discriminate\'','\'DolphinVG\'','Creator Talks_b40040d98e2dbc7e3e2f7fe70de3287b','\'\'',NULL,1297796),('3_Saturday','14','14:00','15:30','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Creator Talk with RinoaPoison & VanHelen\'','\'RinoaPoison,VanHelen\'','Creator Talks_6629ac628a5b97b4cc76795d587171bf','\'Title: Creator Talk with RinoaPoison & VanHelen
\nTags: Scambait Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

Join popular scambait content creators RinoaPoison and VanHelen for an open, behind-the-scenes conversation about live scambaiting, character work, community building, and the realities of turning the tables on scammers on Twitch and YouTube. Expect stories from the calls, tips for aspiring creators, and insights into keeping the work sustainable and entertaining while still disrupting scam operations.

\n\nSpeakers:RinoaPoison,VanHelen
\n
\nSpeakerBio:  RinoaPoison, Twitch Streamer / Content Creator
\nNo BIO available
\nSpeakerBio:  VanHelen, Twitch Streamer / Content Creator
\nNo BIO available
\n\nLinks:
    scambaitvillage.org/speakers - https://scambaitvillage.org/speakers
\n\'',NULL,1297797),('3_Saturday','15','14:00','15:30','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Creator Talk with RinoaPoison & VanHelen\'','\'RinoaPoison,VanHelen\'','Creator Talks_6629ac628a5b97b4cc76795d587171bf','\'\'',NULL,1297798),('3_Saturday','15','15:30','16:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Creator Drop-In\'','\'\'','Creator Events_1e25bd54dcbeb66d7e954def2e3cb2ff','\'Title: Creator Drop-In
\nTags: Scambait Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 15:30 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

We know a handful of names you would recognize are wandering this conference. We have invited them to swing by the village during this block and say hi. No stage, no line, no format. Just a shot at an actual conversation with the people behind the calls, so ask what you have always wanted to ask and swap a few stories of your own.

\n\nLinks:
    scambaitvillage.org/creators - https://scambaitvillage.org/creators
\n\'',NULL,1297799),('3_Saturday','16','15:30','16:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Creator Drop-In\'','\'\'','Creator Events_1e25bd54dcbeb66d7e954def2e3cb2ff','\'\'',NULL,1297800),('4_Sunday','10','10:00','15:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_24d77578574b74c6d021ceb6df412e8d','\'Title: KSCM Scambait Radio
\nTags: Scambait Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

Prerecorded scambait calls running in Discord voice throughout the day. Bring earbuds and tune in from your phone while you walk the village or the rest of the con. Listen to real interactions, hear how experienced baiters handle different situations, and pick up new techniques and banter styles. Ambient and educational, drop in for a few minutes or stay for a whole set.

\n\nLinks:
    scambaitvillage.org/radio - https://scambaitvillage.org/radio
\n\'',NULL,1297801),('4_Sunday','11','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_24d77578574b74c6d021ceb6df412e8d','\'\'',NULL,1297802),('4_Sunday','12','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_24d77578574b74c6d021ceb6df412e8d','\'\'',NULL,1297803),('4_Sunday','13','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_24d77578574b74c6d021ceb6df412e8d','\'\'',NULL,1297804),('4_Sunday','14','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_24d77578574b74c6d021ceb6df412e8d','\'\'',NULL,1297805),('4_Sunday','15','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'KSCM Scambait Radio\'','\'\'','Creator Events_24d77578574b74c6d021ceb6df412e8d','\'\'',NULL,1297806),('4_Sunday','10','10:00','15:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_122cad3773355c37f39e4a3953fadf0d','\'Title: Open Q&A
\nTags: Scambait Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

Drop-in Q&A running throughout the village whenever the hall is open. Knowledgeable volunteers are stationed across the booth and can answer questions about scambaiting techniques, tools, safety, community norms, legal considerations, and anything else related to fighting scammers. No session times, no signup. Come by whenever, ask whatever. Casual and welcoming for both newcomers and veterans. Note that Q&A pauses briefly during scheduled talks and sessions at the village, listed separately on this schedule.

\n\nLinks:
    scambaitvillage.org - https://scambaitvillage.org
\n\'',NULL,1297807),('4_Sunday','11','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_122cad3773355c37f39e4a3953fadf0d','\'\'',NULL,1297808),('4_Sunday','12','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_122cad3773355c37f39e4a3953fadf0d','\'\'',NULL,1297809),('4_Sunday','13','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_122cad3773355c37f39e4a3953fadf0d','\'\'',NULL,1297810),('4_Sunday','14','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_122cad3773355c37f39e4a3953fadf0d','\'\'',NULL,1297811),('4_Sunday','15','10:00','15:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Open Q&A\'','\'\'','Creator Events_122cad3773355c37f39e4a3953fadf0d','\'\'',NULL,1297812),('4_Sunday','10','10:00','13:59','N','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Scambait Bingo\'','\'\'','Creator Events_6c5494ffcd626adb6704c5960e8ca4f3','\'Title: Scambait Bingo
\nTags: Scambait Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 1 208 (Scambait Village) - Map
\n
\nDescription:
\n

A fun, interactive group activity that turns classic bingo into a scambaiting game. Mark off common scam phrases, tactics, and red flags as they come up in curated recordings of real scam calls. Great for all skill levels, whether you are playing along or just hanging out. A low-pressure way to learn the language of scams while spending a few hours with the community. Prize-free by design. Winners get a certificate printed on the spot with a ridiculous honorific and a photo with village staff. Nothing of material value is awarded.

\n\nLinks:
    scambaitvillage.org/bingo - https://scambaitvillage.org/bingo
\n\'',NULL,1297813),('4_Sunday','11','10:00','13:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Scambait Bingo\'','\'\'','Creator Events_6c5494ffcd626adb6704c5960e8ca4f3','\'\'',NULL,1297814),('4_Sunday','12','10:00','13:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Scambait Bingo\'','\'\'','Creator Events_6c5494ffcd626adb6704c5960e8ca4f3','\'\'',NULL,1297815),('4_Sunday','13','10:00','13:59','Y','Scambait Village','LVCCW Level 1 Hall 1 208 (Scambait Village)','\'Scambait Bingo\'','\'\'','Creator Events_6c5494ffcd626adb6704c5960e8ca4f3','\'\'',NULL,1297816),('3_Saturday','15','15:00','15:30','N','Recon Village','LVCCW Level 1 Hall 3 801 (Creator Stage 2)','\'The Breach Is Over. The Exposure Is Not\'','\'Kumar Ashwin,Anant Shrivastava\'','Creator Talks_556d03f19d394c0eef676f3ffa0ba949','\'Title: The Breach Is Over. The Exposure Is Not
\nTags: Recon Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - Map
\n
\nDescription:
\n

Breaches are usually treated as discrete incidents. A leak is discovered, the most recognisable credentials are rotated, incident-response activity slows down, and attention moves to the next compromise. The exposure rarely ends with the incident. Credentials can remain valid for months, sometimes long enough to be reused in later attacks. While common credential types receive immediate attention, large breach datasets often contain hundreds of less familiar secret classes that are harder to recognise, validate, or prioritise. This talk examines the long tail of a major software supply chain breach and measures how exposed credentials age, which categories survive longest, and whether public disclosure actually results in remediation.

\n\n

The leaked values are only part of the exposure. Secret names, environment variables, repository paths, service identifiers, deployment stages, and naming conventions can reveal how an organisation builds and operates its systems. Even when a credential has expired, this contextual residue can support attack-surface discovery, technology identification, infrastructure correlation, and future targeting. By looking beyond the obvious credential classes and focusing on the outliers, this talk demonstrates how breach data can be transformed into durable reconnaissance intelligence, and why recovery should be measured by the disappearance of usable exposure rather than the closure of the original incident.

\n\nSpeakers:Kumar Ashwin,Anant Shrivastava
\n
\nSpeakerBio:  Kumar Ashwin, Security Researcher at RedHunt Labs
\n

I work at the intersection of AI, blockchain, and software security — threat modeling complex systems, defining security strategies, and building tooling that scales secure-by-default practices across engineering teams. I work at RedHunt Labs, train at Black Hat, and have spoken at Black Hat, XeeFCon, nullcon, DEF CON, and other conferences worldwide.

\n\nSpeakerBio:  Anant Shrivastava
\n

Anant Shrivastava is the founder of Cyfinoid Research and a long time offensive security practitioner with a focus on application, cloud, and supply chain security. He has delivered trainings and talks at Black Hat (USA, Europe, Asia), Nullcon, c0c0n, BSides, Rootconf and multiple other events, and runs projects such as Hacking Archives of India to highlight real work from the security community. His courses are built from real consulting and red team experience, with an emphasis on attack chains that actually show up in the field and defenses that teams can implement the next day.

\n\n\n\'',NULL,1297817),('2_Friday','16','16:45','16:59','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Github Rate Limits Got You Down? FOD’s Failing to Build? Let’s Talk About Caching\'','\'Ethan Carter Edwards\'','Creator Talks_bb1263700138fc5c0f52d42d92f3f1e9','\'Title: Github Rate Limits Got You Down? FOD’s Failing to Build? Let’s Talk About Caching
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:45 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Have you ever experienced being rate limited by GitHub? Has GitHub downtime prevented you from building software that you rely on? Are you worried about supply chain attacks? At Exa, we developed a secure, hostable, tarball cache that insulates us from GitHub outages, decreases our build times, protects us from force-pushes upstream, and increases download speeds.

\n\nSpeakerBio:  Ethan Carter Edwards
\n

Ethan is a FLOSS advocate, longtime Nix user and contributor, and engineer. He\'s an active member of the Nixpkgs CUDA, Darwin, and NGI teams and is involved in various other efforts throughout the Nix ecosystem.

\n\n

He currently works on building the infrastructure for the future of websearch at Exa.ai and studies Computer Science at Harvard University.

\n\n\n\'',NULL,1297818),('2_Friday','11','11:30','11:59','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Running a homelab with NixOS\'','\'Aaron Honeycutt\'','Creator Talks_967df1013df176aca26bd37d7f04571c','\'Title: Running a homelab with NixOS
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Are you looking to own your media again and host it for the family using NixOS? Some learn about doing that on your own hardware!

\n\n

This presentation will cover the basics for NixOS Modules that are also used for these services in nixpkgs. It will also include examples of my configuration files hosted here:

\n\n

https://gitlab.com/ahoneybun/nix-configs

\n\n

Presentation includes showing my setup including how I handle the data in a RAID.

\n\nSpeakerBio:  Aaron Honeycutt
\n

a computer nerd who happens to use Linux

\n\n\n\'',NULL,1297819),('3_Saturday','10','10:30','10:45','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'How to piss off your Nix friends\'','\'Farid Zakaria\'','Creator Talks_32cabcb9547ea7d4e14c0aba58557e4c','\'Title: How to piss off your Nix friends
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:30 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Nix is surging in popularity, and with it the community has taken the stance that Nix should be for everyone & their grandparents. I\'m here to fight against that idea and share why I think it dilutes the power of Nix itself. By catering to the masses and targeting multiple platforms (MacOS), we weaken the potential of the idea and implementation. When we stop building for the lowest common denominator, we get to push the absolute limits. I will spend this time trying to convince you why Nix should drop support for platforms such as MacOS, diverge even more radically from traditional Linux distros and take on more grand technical solutions to problems at large.

\n\nSpeakerBio:  Farid Zakaria
\n

I\'m a software engineer, father and wishful amateur surfer. If you\'ve come seeking my political views, you\'ve found the wrong.\nYou can find my writings on Nix, build systems and software engineering in general at https://fzakaria.com

\n\n\n\'',NULL,1297820),('2_Friday','10','10:00','10:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Nix Vegas Opening Ceremony\'','\'Daniel Baker,Morgan Jones,Tristan Ross\'','Creator Events_58f2c5d6801a308b6ab6690ab0662602','\'Title: Nix Vegas Opening Ceremony
\nTags: Nix Vegas Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Kickoff and opening of the Nix Vegas space on Friday, and start of the Nix CTF!

\n\nSpeakers:Daniel Baker,Morgan Jones,Tristan Ross
\n
\nSpeakerBio:  Daniel Baker
\n

Daniel Baker is a developer, engineer, and mathematician passionate about reproducible software. An active NixOS community member and educator, he authored the NixCon NA 2024 Nix module system workshop and nixos-modules-lessons. He serves on the NixOS Marketing Team and helps organize both Nix Vegas and Planet Nix. He believes any system worth building is worth rebuilding, bit for bit.

\n\nSpeakerBio:  Morgan Jones
\n

Embedded security engineer who does too many weird things with Nix.

\n\nSpeakerBio:  Tristan Ross
\n

I work on supply chain security at Determinate Systems.

\n\n\n\'',NULL,1297821),('2_Friday','16','16:00','16:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'NixOS Workspaces\'','\'JB\'','Creator Talks_325312fcb71f26e1f70e34cfe7f76c71','\'Title: NixOS Workspaces
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Working on multiple projects simultaneously? Display getting cluttered? Agents in a race condition all trying to fight over the same ports and browser agents?

\n\n

This presentation introduces NixOS Workspaces, a method of partitioning environments for local and remote development. Workspaces assist concurrent agentic development workflows by reducing risk and facilitating common environment configurations across projects. NixOS workspaces is backed by nixos-containers, a wrapper on systemd-nspawn.

\n\n

Presentation includes a demo of the workflow, architecture, guidance on modes of deployment, security considerations, and installation guidance.

\n\nSpeakerBio:  JB
\n

Josh Brown is an Application Security Specialist with a background in both Penetration Testing and Web Application Development. Josh works full-time with CodeQL in the Microsoft Security Analysis & Fix Engineering (SAFE) team to identify vulnerabilities across the organization and drive remediation.

\n\n

Josh has had a highly technical career, previously providing security consulting services as an OSCP and OSWE certified penetration tester to various organizations in the APAC region, including ANZ Bank, Australia Post, and EY before settling into his role at Microsoft in Redmond.

\n\n\n\'',NULL,1297822),('3_Saturday','15','15:30','16:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Your Infrastructure Is a DAG: Manage It With Nix\'','\'Ethan Carter Edwards\'','Creator Talks_0c0395811543c30145b0869d3f781c05','\'Title: Your Infrastructure Is a DAG: Manage It With Nix
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

One of the hardest problems with Infrastructure as Code tooling is modeling and managing complex relationships. This problem only becomes harder when multiple different tools are introduced, each lacking observability into the other. Then add build systems, application logic, deployments, CI/CD, and it becomes unbearably messy with footguns and CVEs around every corner.

\n\n

At Exa, we take Nix far beyond building packages or development shells. Our entire infrastructure is modeled with Nix as one large DAG that allows us to manage these dependencies and orchestrate deployments across project boundaries with confidence in the process and its security. Join to learn more about Exa\'s introduction to Nix, how our usage has changed over time, how we think about flakes, and the lessons we\'ve learned to build the future of search.

\n\nSpeakerBio:  Ethan Carter Edwards
\n

Ethan is a FLOSS advocate, longtime Nix user and contributor, and engineer. He\'s an active member of the Nixpkgs CUDA, Darwin, and NGI teams and is involved in various other efforts throughout the Nix ecosystem.

\n\n

He currently works on building the infrastructure for the future of websearch at Exa.ai and studies Computer Science at Harvard University.

\n\n\n\'',NULL,1297823),('3_Saturday','16','15:30','16:30','Y','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Your Infrastructure Is a DAG: Manage It With Nix\'','\'Ethan Carter Edwards\'','Creator Talks_0c0395811543c30145b0869d3f781c05','\'\'',NULL,1297824),('4_Sunday','13','13:30','14:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Unconference\'','\'\'','Creator Events_659ae20c1fc389defb769d9a065dfc9a','\'Title: Unconference
\nTags: Nix Vegas Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 13:30 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Come and chill in the Nix Vegas space for the Unconference.

\n\n\'',NULL,1297825),('4_Sunday','14','13:30','14:30','Y','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Unconference\'','\'\'','Creator Events_659ae20c1fc389defb769d9a065dfc9a','\'\'',NULL,1297826),('2_Friday','15','15:00','15:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Everything is Nix when you squint hard enough\'','\'Jared\'','Creator Talks_c7371c1dab1aa6b0920c3447ab8aa4ac','\'Title: Everything is Nix when you squint hard enough
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

How I got started with NixOS and how it\'s going. I\'ll cover my homelab migration from ubuntu & docker to NixOS & Incus w/ NixOS containers. I\'ll also go over how a similar process is going at my $job, discussing packaging proprietary software into modules. I\'ll cover declarative hardware and software in both domains from an SRE point of view.

\n\nSpeakerBio:  Jared
\n

I\'m an SRE based in $location working for $job.

\n\n\n\'',NULL,1297827),('3_Saturday','17','17:00','17:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Lightning Talks and Unconference\'','\'\'','Creator Events_5cc2cccab9009706da4dfd5908f71469','\'Title: Lightning Talks and Unconference
\nTags: Nix Vegas Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Give a talk about whatever you want, as long as it\'s less than 10 minutes! Or just come and chill in the Nix Vegas space for the Unconference.

\n\n\'',NULL,1297828),('2_Friday','17','17:00','17:59','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Lightning Talks and Unconference\'','\'\'','Creator Events_760ca33063aebc87b3b79e3ca56ed74f','\'Title: Lightning Talks and Unconference
\nTags: Nix Vegas Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Give a talk about whatever you want, as long as it\'s less than 10 minutes! Or just come and chill in the Nix Vegas space for the Unconference.

\n\n\'',NULL,1297829),('4_Sunday','13','13:00','13:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Nix Vegas Closing Ceremony\'','\'\'','Creator Events_a49f0ab59a02cc4178fa5b4c59d61d0a','\'Title: Nix Vegas Closing Ceremony
\nTags: Nix Vegas Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Closing out Nix Vegas at DEF CON 34

\n\n\'',NULL,1297830),('3_Saturday','10','10:00','10:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Nix Vegas Opening Ceremony\'','\'\'','Creator Events_5cefbd33b83fb41ed04f5e1013075267','\'Title: Nix Vegas Opening Ceremony
\nTags: Nix Vegas Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Kickoff and opening of the Nix Vegas space on Saturday.

\n\n\'',NULL,1297831),('2_Friday','13','13:00','13:45','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Whose PR Is It Anyway?\'','\'\'','Creator Events_83cb0becdb5e62d25d66444afb59abd4','\'Title: Whose PR Is It Anyway?
\nTags: Nix Vegas Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

In this audience participation-heavy session, you can get your PRs to nixpkgs reviewed and maybe even merged... if the build on one of our systems passes. Come with PRs in hand and call them out, and we\'ll review, build, and maybe even merge them on stage.

\n\n

This is Whose PR Is It Anyway, where the version bumps are made up and the builds don\'t matter.

\n\n\'',NULL,1297832),('2_Friday','10','10:30','10:59','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Composable Systems with NixOS MicroVMs\'','\'Alex Decious\'','Creator Talks_285ad6b26a24c2732989e8543602cb69','\'Title: Composable Systems with NixOS MicroVMs
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:30 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

MicroVMs make it easy to give every service, project, or person dedicated NixOS machines. We will use microvm.nix to build dev boxes, game servers, and sensitive services on hardware we control. Because each guest is simply a NixOS configuration, it can be reused, extended, rebuilt, and shared.

\n\n

We will compare MicroVM isolation with other options, explain its limitations, and show how to compose useful machines from ordinary NixOS modules for yourself and those around you. We will finish with a look beyond a single host: how to preserve and back up these machines, then place them across hardware you own.

\n\nSpeakerBio:  Alex Decious
\n

I work on build systems and CI infrastructure for Shopify\'s monorepo using Nix, and run my own infrastructure as a systems lab for compute-heavy builds, distributed systems experiments, local LLMs, and hosting for myself and others.

\n\n\n\'',NULL,1297833),('3_Saturday','14','14:00','14:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Nix Knows When the Agent Is Wrong\'','\'Jason Odoom\'','Creator Talks_14d61c0bb520bb8d33ad55eb9cfc434b','\'Title: Nix Knows When the Agent Is Wrong
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

I built a tool to help maintainers patch nixpkgs CVEs faster. But I optimized the wrong thing.

\n\n

The tool - Vulnpatch, is a dashboard. It pulls together CVE intelligence, triages by what is actually being exploited, gives the maintainer the context they need and gets out of the way. The assumption underneath it was that the maintainer is the bottleneck: speed up the workflow and packages get patched faster.

\n\n

I no longer believe that assumption. I was already building Vulnpatch to automate the remediation work when Mythos was announced, and it undercut the premise. Building a product to do what a frontier model could now do on its own was the wrong problem to be solving.

\n\n

The difficult part was never automating the work. It is making an agent\'s output something a volunteer on the security team can actually trust. The work is the evidence: which package is actually affected, which upstream commit fixes it, what the new hash is, whether it still builds, whether the tests still pass and whether a maintainer has any reason to trust it. And that is before the non-trivial cases: the patches that are not simple version bumps or hash updates.

\n\n

This is a talk about that shift. I will discuss Vulnpatch and Trace, an agent-owned nixpkgs fork that produces signed, reproducible CVE evidence bundles instead of drive-by pull requests. And I want to make one argument I think is worth taking seriously: Nix is unusually well-suited to AI agents because it provides strong automated feedback. Reproducible builds and passthru.tests give agents an objective verifier for many changes, whereas most repositories offer much weaker validation.

\n\n

Patches are cheap. Proof is not. I will show what it takes to make an agent\'s work auditable enough to be worth a maintainer\'s time and I hope, to persuade maintainers that agents belong in their workflow. The workflows we built for human-only contribution will not survive contact with agents unchanged.

\n\nSpeakerBio:  Jason Odoom
\n

\"Thing Doer\"

\n\n\n\'',NULL,1297834),('3_Saturday','13','13:00','13:45','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Whose PR Is It Anyway?\'','\'\'','Creator Events_f6025d7ff02d87cd8f4e7472ec201a0b','\'Title: Whose PR Is It Anyway?
\nTags: Nix Vegas Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 13:00 - 13:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

In this audience participation-heavy session, you can get your PRs to nixpkgs reviewed and maybe even merged... if the build on one of our systems passes. Come with PRs in hand and call them out, and we\'ll review, build, and maybe even merge them on stage.

\n\n

This is Whose PR Is It Anyway, where the version bumps are made up and the builds don\'t matter.

\n\n\'',NULL,1297835),('3_Saturday','14','14:45','15:15','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Securing Nix Builds using microVMs\'','\'Tristan Ross\'','Creator Talks_86c4c5067f02923481ab67588d20fc7d','\'Title: Securing Nix Builds using microVMs
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:45 - 15:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Recent vulnerabilities like Copy Fail and DirtyFrag have made abundantly clear just how risky it is to run untrusted Nix builds inside your core infrastructure. In response, we at Determinate Systems have begun building every Nix package inside of ephemeral microVMs. This talk covers what microVMs are, how they limit kernel-level vulnerabilities, and how we hope to substantially improve our security posture using this technology.

\n\nSpeakerBio:  Tristan Ross
\n

I work on supply chain security at Determinate Systems.

\n\n\n\'',NULL,1297836),('3_Saturday','15','14:45','15:15','Y','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Securing Nix Builds using microVMs\'','\'Tristan Ross\'','Creator Talks_86c4c5067f02923481ab67588d20fc7d','\'\'',NULL,1297837),('2_Friday','14','14:00','14:30','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Relocatable Nix Binaries\'','\'Farid Zakaria\'','Creator Talks_3c47626906da1a700556f660f8b9f905','\'Title: Relocatable Nix Binaries
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Nix’s guarantee of reproducibility hinges on a simple mechanism: absolute, immutable store paths (i.e. /nix/store). While this rigidity guarantees that binaries always find their exact dependencies, it introduces a massive constraint: it binds the entire ecosystem to a single, global directory. If you want to run a Nix binary on a target system where you don\'t have root access to create /nix, or where you cannot run an unprivileged user namespace, you are forced to rebuild the world To achieve true portability and friction-free deployment across arbitrary infrastructure, Nix binaries must become fully relocatable. What does that mean ? Why is it hard? Who cares (psst me!)? We will discuss what a fully relocatable Nix ecosystem could look like , and how solving this constraint could allow Nix to be run more easily on more restrictive environments..

\n\nSpeakerBio:  Farid Zakaria
\n

I\'m a software engineer, father and wishful amateur surfer. If you\'ve come seeking my political views, you\'ve found the wrong.\nYou can find my writings on Nix, build systems and software engineering in general at https://fzakaria.com

\n\n\n\'',NULL,1297838),('3_Saturday','10','10:45','10:59','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Beholden to No One: The Nix Override Ladder\'','\'Daniel Baker\'','Creator Talks_b0c34e58e3ae22d2caa65aa1509b5d6b','\'Title: Beholden to No One: The Nix Override Ladder
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:45 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Home Assistant ships a warning that your install \"will not work after 2026.11.\" DuckStation detects NixOS four different ways and fatally errors your build on purpose. A maintainer won\'t merge the one-line word-wrap fix you\'ve needed for a year. On most platforms your options are comply or quit. On Nix, everything between you and the source is negotiable.

\n\n

This talk is a guided tour up the override ladder, from module options and mkForce to overrideAttrs, fetchpatch-ing unmerged PRs, overlays, and finally patching nixpkgs itself. The stories along the way are real and primary-sourced: sabotaged npm packages, the xz backdoor, the youtube-dl DMCA takedown, rug-pull relicensing, and the nixpkgs patch literally named nixos-was-never-supported.patch.

\n\nSpeakerBio:  Daniel Baker
\n

Daniel Baker is a developer, engineer, and mathematician passionate about reproducible software. An active NixOS community member and educator, he authored the NixCon NA 2024 Nix module system workshop and nixos-modules-lessons. He serves on the NixOS Marketing Team and helps organize both Nix Vegas and Planet Nix. He believes any system worth building is worth rebuilding, bit for bit.

\n\n\n\'',NULL,1297839),('3_Saturday','16','16:30','16:59','N','Nix Vegas Community','LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)','\'Breaking the Chains of Cloud Giants: Building a Fully Autonomous Personal Cloud on NixOS\'','\'Maksim Kuskov,Mikhail Ilin\'','Creator Talks_e55cb604e58c9ca8417c7eae1d3b8831','\'Title: Breaking the Chains of Cloud Giants: Building a Fully Autonomous Personal Cloud on NixOS
\nTags: Nix Vegas Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1310 (Nix Vegas Community) - Map
\n
\nDescription:
\n

Privacy and digital agency are under siege by dark patterns, aggressive data harvesting, and SaaS monopolies. It’s time to reclaim our digital self-determination. This talk demonstrates how to build a production-ready, fully autonomous personal cloud using the declarative power of NixOS.We will explore how to self-host drop-in replacements for mainstream services—including Nextcloud for storage, Vaultwarden for passwords, and Matrix for communication. Attendees will learn how to turn any old PC or cheap VPS into an unbreachable digital fortress featuring automated backups, end-to-end encryption, and complete data isolation. Discover how NixOS makes personal infrastructure reproducible, resilient, and entirely yours.

\n\nSpeakers:Maksim Kuskov,Mikhail Ilin
\n
\nSpeakerBio:  Maksim Kuskov
\n

Security engineer in Yandex, CTF organizer & player @ HSE IS \'29

\n\nSpeakerBio:  Mikhail Ilin
\n

I am an appsec with a strong background in competitive hacking. Over the years, I have won multiple national Cyber Security Sports Championships and currently serve as an ambassador for the Standoff 365 cybersecurity ecosystem. Beyond traditional technical exploitation, my research focuses on the intersection of clinical psychology and practical social engineering. As a strong advocate for digital self-determination, I view open-source infrastructure and NixOS not just as engineering tools, but as essential defensive shields against platform lock-in and corporate surveillance.

\n\n\n\'',NULL,1297840),('2_Friday','10','10:20','10:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure\'','\'Siva Sareddu,T -Mobile CTF Team\'','Creator Events_4e4b172ab67785622120dfd308a04ce5','\'Title: A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure
\nTags: Telecom Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:20 - 10:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n
    \n
  1. Understand the 5G SA attack surface from an attacker\'s perspective
  2. \n
  3. Execute protocol-specific attacks against a live 5G core
  4. \n
  5. Map attack techniques to MITRE FiGHT with defensive context
  6. \n
\n\nSpeakers:Siva Sareddu,T -Mobile CTF Team
\n
\nSpeakerBio:  Siva Sareddu
\nNo BIO available
\nSpeakerBio:  T -Mobile CTF Team
\nNo BIO available
\n\n\'',NULL,1297841),('2_Friday','11','11:00','12:30','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'SOC Threat Hunting in Practice\'','\'Akib Sayyed\'','Creator Talks_4f4f7eb8b77ce69c129f1b125baa9082','\'Title: SOC Threat Hunting in Practice
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 12:30 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n

Theory 1. Integrating modern SOC with Telco and respective component

\n\n

Theory 2. Key Attack identifier

\n\n

Demo 1: Ran Site attack identification in Morden SOC Tool

\n\n

Demo 2: 5g Core threat identification for insider attack

\n\n

Practical : Hunting for attack pattern, identify attacker traces, impact analysis on overall network infra

\n\nSpeakerBio:  Akib Sayyed
\nNo BIO available
\n\n\'',NULL,1297842),('2_Friday','12','11:00','12:30','Y','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'SOC Threat Hunting in Practice\'','\'Akib Sayyed\'','Creator Talks_4f4f7eb8b77ce69c129f1b125baa9082','\'\'',NULL,1297843),('2_Friday','12','12:30','13:15','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Poor Man\'s Mythos: Signal Siege: Agentic Exploit Chains Across the 5G Cloud-Native Stack\'','\'Omer Farooq\'','Creator Talks_771e48d68dc85773b39392bd6a61ba38','\'Title: Poor Man\'s Mythos: Signal Siege: Agentic Exploit Chains Across the 5G Cloud-Native Stack
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:30 - 13:15 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n
    \n
  1. 5G Attack Surface – New cloud-native risks and legacy trust issues.
  2. \n
  3. Salt Typhoon – Lessons from real-world telecom breaches.\nNEF API Security – Exposed API attack vectors.
  4. \n
  5. Signaling Exploitation – SS7/Diameter trust weaknesses in 5G.\nRAN-to-Core Pivoting – Lateral movement across telecom networks.
  6. \n
  7. OSS/BSS Attacks – Exploiting IT–telecom integration.
  8. \n
  9. Agentic AI – AI-driven telecom attack chain discovery.
  10. \n
  11. Offensive AI – Lowering the barrier to advanced attacks.
  12. \n
  13. Zero Trust for 5G – Securing telecom trust boundaries.
  14. \n
  15. Control Plane Security – Prioritizing critical telecom risks.
  16. \n
  17. Red Team Techniques – Practical telecom attack methodologies.
  18. \n
\n\nSpeakerBio:  Omer Farooq
\n

Omer Farooq is a cybersecurity, cloud, and artificial intelligence leader with more than twenty-five years of experience spanning application security, cloud architecture, software engineering, DevSecOps, AI security, and technology innovation. As Founder and Principal Security Consultant at Auxin Security, Omer has advised more than 100 organizations worldwide, including Fortune 500 companies, government agencies, healthcare organizations, and nonprofits. His expertise includes GenAI and LLM security, offensive security assessments, threat modeling, cloud security, DevSecOps transformation, secure software development, and enterprise architecture. Omer is a frequent speaker at industry conferences and events including RSA Conference, BSides DC, AWS events, NAB Show, Microsoft Azure conferences, and numerous cybersecurity forums. His current research focuses on AI security, agentic systems, retrieval-augmented generation security, offensive AI testing, and emerging threats targeting enterprise AI deployments.

\n\n\n\'',NULL,1297844),('2_Friday','13','12:30','13:15','Y','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Poor Man\'s Mythos: Signal Siege: Agentic Exploit Chains Across the 5G Cloud-Native Stack\'','\'Omer Farooq\'','Creator Talks_771e48d68dc85773b39392bd6a61ba38','\'\'',NULL,1297845),('2_Friday','14','14:15','14:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Protecting Humans at Machine Speed - Engineering AI to Stop Spam, Scams & Digital Fraud at Telecom Scale\'','\'Arvind Singh\'','Creator Talks_9bd1deb363e71d7cb15bfd222f510409','\'Title: Protecting Humans at Machine Speed - Engineering AI to Stop Spam, Scams & Digital Fraud at Telecom Scale
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:15 - 14:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n
    \n
  1. What does it take to protect billions of daily calls, SMS, data sessions, and digital interactions across one of the world\'s largest and the second-largest telecom operator by subscriber base?
  2. \n
  3. This talk explores how AI is transforming telecom networks from passive transport infrastructure into active security platforms capable of detecting, correlating, and disrupting spam, scams, malicious links, OTP abuse, and digital fraud before they reach customers.
  4. \n
\n\nSpeakerBio:  Arvind Singh
\nNo BIO available
\n\n\'',NULL,1297846),('2_Friday','15','15:00','15:30','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'SIM Card Strikes Back: Telecom Threats & SOC Detection\'','\'Zibran Sayyed\'','Creator Talks_f3c97e17d9fdc4869342c8e6dc73f104','\'Title: SIM Card Strikes Back: Telecom Threats & SOC Detection
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\nWhat will be covered:
\n1. Understanding the SIM Attack Surface – Why SIM cards are a critical part of the tele-com security ecosystem.
\n2. Common Telecom Threats – SIM Swap, SS7 abuse, IMSI Catchers, SMS OTP bypass, and insider threats.
\n3. SOC Detection Strategies – Identifying suspicious SIM, subscriber, and signaling active-ties using effective monitoring techniques.
\n4. Threat Correlation – Connecting telecom events with identity and security logs for faster incident detection and response.
\n5. Strengthening Telecom Security – Best practices to improve SOC visibility and reduce risks associated with SIM-based attacks.
\n\n\n\nSpeakerBio:  Zibran Sayyed
\nNo BIO available
\n\n\'',NULL,1297847),('2_Friday','15','15:30','15:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'AI vs AI: Securing Telecom in the Era of Autonomous Cyber Warfare\'','\'Rohini,Pankaj Sontakke,Will Thomas,Isabel Manjarrez,Omer Farooq,T -Mobile CTF Team,James(GSMA),Arvind Singh\'','Creator Talks_41fdf9b6f3a66a21de5816fe6db93863','\'Title: AI vs AI: Securing Telecom in the Era of Autonomous Cyber Warfare
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\nKey Discussion Points:
\n1. AI vs. AI Cyber Warfare: How AI is transforming both cyber defense and cyber offense in telecom, and whether autonomous attacks are already becoming a reality.
\n2. AI-Powered Telecom Security: The role of AI in SOC operations, fraud detection, threat intelligence, network security, and automated incident response.
\n3. Securing AI & AI Governance: Protecting AI models from threats such as prompt injection, data poisoning, model theft, and ensuring secure AI adoption through governance and human oversight.
\n4. Future of Telecom Security: AI-native networks, OEM and supply chain security, the evolution of security professionals, and preparing telecom operators for the AI-driven threat landscape by 2030.
\n\n\n\nSpeakers:Rohini,Pankaj Sontakke,Will Thomas,Isabel Manjarrez,Omer Farooq,T -Mobile CTF Team,James(GSMA),Arvind Singh
\n
\nSpeakerBio:  Rohini
\nNo BIO available
\nSpeakerBio:  Pankaj Sontakke
\nNo BIO available
\nSpeakerBio:  Will Thomas
\nNo BIO available
\nSpeakerBio:  Isabel Manjarrez, Threat Researcher
\n

[EN] María Isabel Manjarrez is a security researcher with Kaspersky\'s Global Research and Analysis Team (GReAT). She specializes in investigating threat actors in Latin America, tracking their movements, and analyzing the new techniques they deploy. She holds a degree in telecommunications and electronic systems engineering and her interests include threat intelligence, malware analysis, satellite communications, electronics, and music.

\n\n

She has shared her knowledge as a speaker at local and international conferences such as Defcon, Security Analyst Summit (SAS), and EkoParty.

\n\n
\n\n

[ES] María Isabel Manjarrez es investigadora de seguridad en el Equipo Global de Investigación y Análisis (GReAT) de Kaspersky. Se especializa en la investigación de actores amenaza en Latinoamérica, rastrea sus movimientos y analiza las nuevas técnicas que implementan. Es Ingeniera en telecomunicaciones y sistemas electrónicos, sus intereses incluyen la inteligencia de amenazas, análisis de malware, comunicaciones satelitales, electrónica y música.

\n\n

Ha compartido su conocimiento como ponente en conferencias locales e internacionales como Defcon, Security Analyst Summit (SAS) y EkoParty.

\n\nSpeakerBio:  Omer Farooq
\n

Omer Farooq is a cybersecurity, cloud, and artificial intelligence leader with more than twenty-five years of experience spanning application security, cloud architecture, software engineering, DevSecOps, AI security, and technology innovation. As Founder and Principal Security Consultant at Auxin Security, Omer has advised more than 100 organizations worldwide, including Fortune 500 companies, government agencies, healthcare organizations, and nonprofits. His expertise includes GenAI and LLM security, offensive security assessments, threat modeling, cloud security, DevSecOps transformation, secure software development, and enterprise architecture. Omer is a frequent speaker at industry conferences and events including RSA Conference, BSides DC, AWS events, NAB Show, Microsoft Azure conferences, and numerous cybersecurity forums. His current research focuses on AI security, agentic systems, retrieval-augmented generation security, offensive AI testing, and emerging threats targeting enterprise AI deployments.

\n\nSpeakerBio:  T -Mobile CTF Team
\nNo BIO available
\nSpeakerBio:  James(GSMA)
\nNo BIO available
\nSpeakerBio:  Arvind Singh
\nNo BIO available
\n\n\'',NULL,1297848),('2_Friday','16','16:00','16:30','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Nation State Obfuscation Networks\'','\'Will Thomas\'','Creator Talks_ac0d8f256bb3b742445cd863ff5a15e8','\'Title: Nation State Obfuscation Networks
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n
    \n
  1. Edge devices are now the primary obfuscation layer for state-sponsored intrusion traffic
  2. \n
  3. Each CRINK nation has converged on the same strategic goal anonymization through borrowed\ninfrastructure via distinct operational means: China’s ORBs, 3.North Korea’s laptop farms and commercial\nVPNs, Russia’s botnets and 4th party hijacking\n• External network telemetry visibility is one of the few defender advantages that scales against these threat
  4. \n
\n\nSpeakerBio:  Will Thomas
\nNo BIO available
\n\n\'',NULL,1297849),('2_Friday','16','16:30','16:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village CTF Closure\'','\'\'','Creator Events_289cc5eea0b5def3ed18185d7ad471f6','\'Title: Telecom Village CTF Closure
\nTags: Telecom Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 16:30 - 16:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1297850),('3_Saturday','10','10:00','10:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure\'','\'T -Mobile CTF Team\'','Creator Events_0059e2c3929e7a27c9bf4831a53aed65','\'Title: A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure
\nTags: Telecom Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n
    \n
  1. Understand the 5G SA attack surface from an attacker\'s perspective
  2. \n
  3. Execute protocol-specific attacks against a live 5G core
  4. \n
  5. Map attack techniques to MITRE FiGHT with defensive context
  6. \n
\n\nSpeakerBio:  T -Mobile CTF Team
\nNo BIO available
\n\n\'',NULL,1297851),('3_Saturday','11','11:00','11:45','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Threats in Space: The Dangerous Rise of GNSS Attacks\'','\'Isabel Manjarrez\'','Creator Talks_eb9a302196d5aecb520ba64098f6913f','\'Title: Threats in Space: The Dangerous Rise of GNSS Attacks
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n
    \n
  1. GNSS constellations
  2. \n
  3. How do we use GNSS daily?
  4. \n
  5. GNSS threats and their rise
  6. \n
  7. Hacktivism and GNSS?
  8. \n
  9. GNSS exposed instances over the internet
  10. \n
  11. Can we defend against GNSS attacks
  12. \n
\n\nSpeakerBio:  Isabel Manjarrez, Threat Researcher
\n

[EN] María Isabel Manjarrez is a security researcher with Kaspersky\'s Global Research and Analysis Team (GReAT). She specializes in investigating threat actors in Latin America, tracking their movements, and analyzing the new techniques they deploy. She holds a degree in telecommunications and electronic systems engineering and her interests include threat intelligence, malware analysis, satellite communications, electronics, and music.

\n\n

She has shared her knowledge as a speaker at local and international conferences such as Defcon, Security Analyst Summit (SAS), and EkoParty.

\n\n
\n\n

[ES] María Isabel Manjarrez es investigadora de seguridad en el Equipo Global de Investigación y Análisis (GReAT) de Kaspersky. Se especializa en la investigación de actores amenaza en Latinoamérica, rastrea sus movimientos y analiza las nuevas técnicas que implementan. Es Ingeniera en telecomunicaciones y sistemas electrónicos, sus intereses incluyen la inteligencia de amenazas, análisis de malware, comunicaciones satelitales, electrónica y música.

\n\n

Ha compartido su conocimiento como ponente en conferencias locales e internacionales como Defcon, Security Analyst Summit (SAS) y EkoParty.

\n\n\n\'',NULL,1297852),('3_Saturday','11','11:45','12:30','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'From ONT to STB: Detecting IPTV Attack Chains in the Telecom SOC\'','\'Zibran Sayyed\'','Creator Talks_34f5f5c6d825f44a32dacde30fc9de2d','\'Title: From ONT to STB: Detecting IPTV Attack Chains in the Telecom SOC
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:45 - 12:30 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n
    \n
  1. IPTV Architecture – How IPTV is delivered over FTTH/GPON and the security implications of ONTs and STBs.
  2. \n
  3. Weak Links – Common vulnerabilities in ISP-managed ONTs.
  4. \n
  5. ONT to STB Attack Chain – A real-world red team attack demonstrating remote compromise and IPTV manipulation.
  6. \n
  7. Telecom SOC Detection – Detecting ONT compromises through management, authentication, configuration, and IPTV traffic monitoring.
  8. \n
\n\nSpeakerBio:  Zibran Sayyed
\nNo BIO available
\n\n\'',NULL,1297853),('3_Saturday','12','11:45','12:30','Y','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'From ONT to STB: Detecting IPTV Attack Chains in the Telecom SOC\'','\'Zibran Sayyed\'','Creator Talks_34f5f5c6d825f44a32dacde30fc9de2d','\'\'',NULL,1297854),('3_Saturday','15','15:30','16:30','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Signaling Sabotage: Why 100% Compliance is 0% Security\'','\'Vinod Shrimali\'','Creator Workshops_3c0027c9b0ed34338d28477a6d4dc25d','\'Title: Signaling Sabotage: Why 100% Compliance is 0% Security
\nTags: Telecom Village | Creator Workshop
\nWhen: Saturday, Aug 8, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n

Why 100% Compliance is 0% Security exposes the dangerous false sense of security that compliance audits create in modern telecommunications. While regulatory checklists establish a baseline, real-world threat actors routinely bypass compliant controls to exploit critical protocol vulnerabilities across SS7, Diameter, GTP, and SIP networks. This talk bridges the gap between regulatory requirements and real-world operational security, highlighting live-fire signaling attack techniques and hidden abuse cases that traditional audits miss. Attendees will learn why standard compliance falls short and discover actionable strategies for building true resilience—leveraging proactive threat hunting, offensive security

\n\nSpeakerBio:  Vinod Shrimali
\nNo BIO available
\n\n\'',NULL,1297855),('3_Saturday','16','15:30','16:30','Y','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Signaling Sabotage: Why 100% Compliance is 0% Security\'','\'Vinod Shrimali\'','Creator Workshops_3c0027c9b0ed34338d28477a6d4dc25d','\'\'',NULL,1297856),('3_Saturday','14','14:00','14:30','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Signal Hijacked: How Mobile Networks Became Phishing\'s Most Trusted Delivery Layer\'','\'Sindhura Kona\'','Creator Talks_78ec8c2d6c53499b71b1c265b3f9f499','\'Title: Signal Hijacked: How Mobile Networks Became Phishing\'s Most Trusted Delivery Layer
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n
    \n
  1. Live Demonstration: \"The Signal Switch\"
  2. \n
  3. Display a realistic QR code (restaurant menu, airport Wi-Fi, or bank notification).
  4. \n
  5. Ask the audience whether they would scan it.
  6. \n
  7. Walk through what happens after scanning.
  8. \n
  9. Show how the phishing page is delivered over a trusted mobile channel (WhatsApp/SMS simulation).
  10. \n
  11. Demonstrate analytics showing user interactions and explain how attackers track victims.
  12. \n
  13. Compare the same QR code against AI analysis (ChatGPT, Claude, Gemini) and highlight the differences in detection.
  14. \n
\n\nSpeakerBio:  Sindhura Kona
\nNo BIO available
\n\n\'',NULL,1297857),('3_Saturday','14','14:30','15:15','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'From Zero-Day to Zero-Hour: Rethinking Telecom Defense for the Frontier AI Era\'','\'Arvind Singh\'','Creator Talks_07cebc5eef51697ef976a48d58af7e7b','\'Title: From Zero-Day to Zero-Hour: Rethinking Telecom Defense for the Frontier AI Era
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 15:15 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\nDetails:
\n\n

Frontier AI is changing the economics and speed of cyberattacks—compressing vulnerability discovery, exploitation, and attack automation from days to potentially hours or minutes. For telecom networks and their complex OEM and supply-chain ecosystem, traditional vulnerability management and defense models may no longer be fast enough.

\n\n

This session explores how telecom operators, OEMs, security teams, and regulators must adapt for the frontier AI era—from AI-driven vulnerability discovery and autonomous attacks to faster remediation, AI-powered defense, supply-chain resilience, and coordinated industry response. The key question: when attackers operate at machine speed, can telecom defense keep up?

\n\nSpeakerBio:  Arvind Singh
\nNo BIO available
\n\n\'',NULL,1297858),('3_Saturday','15','14:30','15:15','Y','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'From Zero-Day to Zero-Hour: Rethinking Telecom Defense for the Frontier AI Era\'','\'Arvind Singh\'','Creator Talks_07cebc5eef51697ef976a48d58af7e7b','\'\'',NULL,1297859),('3_Saturday','12','12:30','12:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Industry Challenges & SOC Reality\'','\'Vinod Shrimali\'','Creator Talks_a19f7037520f73b698a7974d7a3807bd','\'Title: Industry Challenges & SOC Reality
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n
    \n
  1. Telecom SOC challenges and operational realities
  2. \n
  3. Evolving telecom threat landscape (2G–5G & cloud-native)
  4. \n
  5. Telecom-specific attack surfaces and protocol risks
  6. \n
  7. Limitations of traditional SOCs in telecom environments
  8. \n
  9. Detection challenges across SS7, Diameter, GTP, SIP, and 5G
  10. \n
  11. Real-world telecom attacks and fraud scenarios
  12. \n
  13. Threat hunting and protocol-aware monitoring
  14. \n
  15. AI-driven detection, automation, and response
  16. \n
  17. Building a modern Telecom SOC
  18. \n
  19. Future security challenges in 5G and beyond
  20. \n
\n\nSpeakerBio:  Vinod Shrimali
\nNo BIO available
\n\n\'',NULL,1297860),('3_Saturday','16','16:45','16:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village CTF Closure\'','\'\'','Creator Events_353c5f79603113fbee4ef0ee29803dbd','\'Title: Telecom Village CTF Closure
\nTags: Telecom Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 16:45 - 16:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1297861),('4_Sunday','10','10:20','13:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village CTF\'','\'T -Mobile CTF Team\'','Creator Events_5a2744d14d39e02eea9ab76d15e262ce','\'Title: Telecom Village CTF
\nTags: Telecom Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:20 - 13:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  T -Mobile CTF Team
\nNo BIO available
\n\n\'',NULL,1297862),('4_Sunday','11','10:20','13:59','Y','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village CTF\'','\'T -Mobile CTF Team\'','Creator Events_5a2744d14d39e02eea9ab76d15e262ce','\'\'',NULL,1297863),('4_Sunday','12','10:20','13:59','Y','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village CTF\'','\'T -Mobile CTF Team\'','Creator Events_5a2744d14d39e02eea9ab76d15e262ce','\'\'',NULL,1297864),('4_Sunday','13','10:20','13:59','Y','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village CTF\'','\'T -Mobile CTF Team\'','Creator Events_5a2744d14d39e02eea9ab76d15e262ce','\'\'',NULL,1297865),('4_Sunday','13','13:30','13:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village CTF Awards Ceremony\'','\'\'','Creator Events_fa4c003b9e24045da2c44a07582108e5','\'Title: Telecom Village CTF Awards Ceremony
\nTags: Telecom Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 13:30 - 13:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1297866),('2_Friday','10','10:00','10:20','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village Inauguration\'','\'Pankaj Sontakke\'','Creator Talks_64c7d2f187a832d3fc19138cffeeeb19','\'Title: Telecom Village Inauguration
\nTags: Telecom Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:20 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Pankaj Sontakke
\nNo BIO available
\n\n\'',NULL,1297867),('2_Friday','11','11:00','11:59','N','Hackers.town','LVCCW Level 1 Hall 4 1420 (Hackers.town)','\'building community and privacy tools from junk\'','\'TheGibson\'','Creator Talks_a1a8863025fb998460fd076b17bd77f4','\'Title: building community and privacy tools from junk
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  TheGibson
\nNo BIO available
\n\n\'',NULL,1297868),('2_Friday','13','13:00','13:59','N','Hackers.town','LVCCW Level 1 Hall 4 1420 (Hackers.town)','\'Liberate your Music with Tech Reclaimers\'','\'RemoteNemesis\'','Creator Talks_8e913612f35705867699fb323dfb3969','\'Title: Liberate your Music with Tech Reclaimers
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  RemoteNemesis
\nNo BIO available
\n\n\'',NULL,1297869),('2_Friday','14','14:00','14:59','N','Hackers.town','LVCCW Level 1 Hall 4 1420 (Hackers.town)','\'Too Much \"Slop\" and Not Enough Soul: Why the AI Music Bubble is Leaking & Robots Shouldn\'t Replace Our Djs\'','\'RabidMoosery\'','Creator Talks_eb996872fd9ab32f09bfd73b6e881bf2','\'Title: Too Much \"Slop\" and Not Enough Soul: Why the AI Music Bubble is Leaking & Robots Shouldn\'t Replace Our Djs
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  RabidMoosery
\nNo BIO available
\n\n\'',NULL,1297870),('2_Friday','15','15:00','15:59','N','Hackers.town','LVCCW Level 1 Hall 4 1420 (Hackers.town)','\'The Political economy of AI\'','\'Janet Vertesi\'','Creator Talks_0b2332f7e06d6f3f81ce370a720e3ab9','\'Title: The Political economy of AI
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Janet Vertesi, Officer at Tech Reclaimers
\nNo BIO available
\n\n\'',NULL,1297871),('2_Friday','16','16:00','16:59','N','Hackers.town','LVCCW Level 1 Hall 4 1420 (Hackers.town)','\'Hackers Trivia\'','\'RemoteNemesis,Medus4\'','Creator Talks_18103370ea83da8b41f3b4d64bb4e440','\'Title: Hackers Trivia
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map
\n
\nDescription:
\n\n\nSpeakers:RemoteNemesis,Medus4
\n
\nSpeakerBio:  RemoteNemesis
\nNo BIO available
\nSpeakerBio:  Medus4
\nNo BIO available
\n\n\'',NULL,1297872),('3_Saturday','11','11:00','11:59','N','Hackers.town','LVCCW Level 1 Hall 4 1420 (Hackers.town)','\'How to get RCE on a car\'','\'Ac0rn\'','Creator Talks_79c992b35b84ddd239cb49a45bd8324f','\'Title: How to get RCE on a car
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Ac0rn
\nNo BIO available
\n\n\'',NULL,1297873),('3_Saturday','14','14:00','14:59','N','Hackers.town','LVCCW Level 1 Hall 4 1420 (Hackers.town)','\'Fun with alternative smartphones with The Tech Reclaimers!\'','\'Janet Vertesi\'','Creator Talks_3a91e9b03b96d2864faccffb8878aeea','\'Title: Fun with alternative smartphones with The Tech Reclaimers!
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Janet Vertesi, Officer at Tech Reclaimers
\nNo BIO available
\n\n\'',NULL,1297874),('3_Saturday','15','15:00','15:59','N','Hackers.town','LVCCW Level 1 Hall 4 1420 (Hackers.town)','\'The Enshittified Internet and How We Can All Rewild the Internet\'','\'LambdaCalculus\'','Creator Talks_d9c632806bf069abae1b2f681a0270f2','\'Title: The Enshittified Internet and How We Can All Rewild the Internet
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  LambdaCalculus
\n

LambdaCalculus is chaos in a trenchcoat, and is passionate to his core about human rights issues, community outreach, and education. He has spoken at HOPE in 2025 on the Pirate Box and Sneakernet, and has also spoken at DEF CON, JawnCon, and PhreakNIC. He is a member of hackers.town, a native of the NYC area, and can still hit a mosh pit! Find him hanging out at hackers.town on Mastodon:https://masto.hackers.town/@LambdaCalculus

\n\n\n\'',NULL,1297875),('2_Friday','10','10:00','12:30','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Hands-On Supply Chain Recon & Vendor Risk Mapping\'','\'Dhiyaneshwaran Balasubramaniam,Aman Rawat\'','Creator Workshops_e6f3cf4427cb75ee7f16834ab8a075de','\'Title: Hands-On Supply Chain Recon & Vendor Risk Mapping
\nTags: Recon Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

Every organization relies on third-party vendors, open-source packages, and CI/CD tools to build and deliver software. In this session, we\'ll learn how to identify and map these external dependencies, understand the trust relationships between them, and discover potential security risks. Through practical demonstrations, attendees will see how issues such as dependency confusion, insecure GitHub Actions workflows, and vendor-related weaknesses can become entry points for supply chain attacks. The goal is to help security teams find and fix these risks before attackers do.

\n\nSpeakers:Dhiyaneshwaran Balasubramaniam,Aman Rawat
\n
\nSpeakerBio:  Dhiyaneshwaran Balasubramaniam
\nNo BIO available
\nSpeakerBio:  Aman Rawat
\nNo BIO available
\n\n\'',NULL,1297876),('2_Friday','11','10:00','12:30','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Hands-On Supply Chain Recon & Vendor Risk Mapping\'','\'Dhiyaneshwaran Balasubramaniam,Aman Rawat\'','Creator Workshops_e6f3cf4427cb75ee7f16834ab8a075de','\'\'',NULL,1297877),('2_Friday','12','10:00','12:30','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Hands-On Supply Chain Recon & Vendor Risk Mapping\'','\'Dhiyaneshwaran Balasubramaniam,Aman Rawat\'','Creator Workshops_e6f3cf4427cb75ee7f16834ab8a075de','\'\'',NULL,1297878),('2_Friday','10','10:00','17:59','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_c97e7543b097bcccd8765393314ba178','\'Title: Live Recon Contest
\nTags: Recon Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

Do you fancy doing live recon on Real Organizations? Activate Yourself. And compete in a unique HACKER challenge. Participants will perform live reconnaissance on a specified list of companies. Your mission is to unearth as much critical information as possible. Contest runs overnight from Friday into Saturday.

\n\n

Prizes

\n\n

1st prize - Meta Glasses

\n\n

2nd Prize - Keyboard

\n\n\'',NULL,1297879),('2_Friday','11','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_c97e7543b097bcccd8765393314ba178','\'\'',NULL,1297880),('2_Friday','12','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_c97e7543b097bcccd8765393314ba178','\'\'',NULL,1297881),('2_Friday','13','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_c97e7543b097bcccd8765393314ba178','\'\'',NULL,1297882),('2_Friday','14','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_c97e7543b097bcccd8765393314ba178','\'\'',NULL,1297883),('2_Friday','15','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_c97e7543b097bcccd8765393314ba178','\'\'',NULL,1297884),('2_Friday','16','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_c97e7543b097bcccd8765393314ba178','\'\'',NULL,1297885),('2_Friday','17','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_c97e7543b097bcccd8765393314ba178','\'\'',NULL,1297886),('3_Saturday','10','10:00','17:59','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_aa835a4d045201f17fb8f5c69ba58743','\'Title: Live Recon Contest
\nTags: Recon Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

Do you fancy doing live recon on Real Organizations? Activate Yourself. And compete in a unique HACKER challenge. Participants will perform live reconnaissance on a specified list of companies. Your mission is to unearth as much critical information as possible. Contest runs overnight from Friday into Saturday.

\n\n

Prizes

\n\n

1st prize - Meta Glasses

\n\n

2nd Prize - Keyboard

\n\n\'',NULL,1297887),('3_Saturday','11','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_aa835a4d045201f17fb8f5c69ba58743','\'\'',NULL,1297888),('3_Saturday','12','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_aa835a4d045201f17fb8f5c69ba58743','\'\'',NULL,1297889),('3_Saturday','13','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_aa835a4d045201f17fb8f5c69ba58743','\'\'',NULL,1297890),('3_Saturday','14','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_aa835a4d045201f17fb8f5c69ba58743','\'\'',NULL,1297891),('3_Saturday','15','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_aa835a4d045201f17fb8f5c69ba58743','\'\'',NULL,1297892),('3_Saturday','16','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_aa835a4d045201f17fb8f5c69ba58743','\'\'',NULL,1297893),('3_Saturday','17','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest\'','\'\'','Creator Events_aa835a4d045201f17fb8f5c69ba58743','\'\'',NULL,1297894),('3_Saturday','10','10:00','17:59','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_8f3f3ec879d34c16e83fcf22b9645388','\'Title: TrackTheFugitive Contest
\nTags: Recon Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

The manhunt is on. TrackTheFugitive drops you into real, active cases where the suspects are still out there—no simulations, no canned flags. Armed with nothing but open-source intelligence, you\'ll chase digital breadcrumbs, unmask aliases, and surface the leads that help bring real fugitives to justice. Contest runs 10 AM Friday to 6 PM Saturday.

\n\n

Prizes

\n\n

1st prize - Meta Quest 3S

\n\n

2nd Prize - Flipper Zero

\n\n\'',NULL,1297895),('3_Saturday','11','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_8f3f3ec879d34c16e83fcf22b9645388','\'\'',NULL,1297896),('3_Saturday','12','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_8f3f3ec879d34c16e83fcf22b9645388','\'\'',NULL,1297897),('3_Saturday','13','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_8f3f3ec879d34c16e83fcf22b9645388','\'\'',NULL,1297898),('3_Saturday','14','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_8f3f3ec879d34c16e83fcf22b9645388','\'\'',NULL,1297899),('3_Saturday','15','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_8f3f3ec879d34c16e83fcf22b9645388','\'\'',NULL,1297900),('3_Saturday','16','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_8f3f3ec879d34c16e83fcf22b9645388','\'\'',NULL,1297901),('3_Saturday','17','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_8f3f3ec879d34c16e83fcf22b9645388','\'\'',NULL,1297902),('2_Friday','10','10:00','17:59','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_7b2c3f97f3dc6c61dba68ee3c84e369f','\'Title: TrackTheFugitive Contest
\nTags: Recon Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

The manhunt is on. TrackTheFugitive drops you into real, active cases where the suspects are still out there—no simulations, no canned flags. Armed with nothing but open-source intelligence, you\'ll chase digital breadcrumbs, unmask aliases, and surface the leads that help bring real fugitives to justice. Contest runs 10 AM Friday to 6 PM Saturday.

\n\n

Prizes

\n\n

1st prize - Meta Quest 3S

\n\n

2nd Prize - Flipper Zero

\n\n\'',NULL,1297903),('2_Friday','11','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_7b2c3f97f3dc6c61dba68ee3c84e369f','\'\'',NULL,1297904),('2_Friday','12','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_7b2c3f97f3dc6c61dba68ee3c84e369f','\'\'',NULL,1297905),('2_Friday','13','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_7b2c3f97f3dc6c61dba68ee3c84e369f','\'\'',NULL,1297906),('2_Friday','14','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_7b2c3f97f3dc6c61dba68ee3c84e369f','\'\'',NULL,1297907),('2_Friday','15','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_7b2c3f97f3dc6c61dba68ee3c84e369f','\'\'',NULL,1297908),('2_Friday','16','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_7b2c3f97f3dc6c61dba68ee3c84e369f','\'\'',NULL,1297909),('2_Friday','17','10:00','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'TrackTheFugitive Contest\'','\'\'','Creator Events_7b2c3f97f3dc6c61dba68ee3c84e369f','\'\'',NULL,1297910),('3_Saturday','11','11:00','16:59','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_f691996aa36beda4150c4931f0b72163','\'Title: GE(O)SINT Contest
\nTags: Recon Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 11:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

Test your geospatial intelligence skills in this unique contest. Identify locations, analyze imagery, and demonstrate your GeoINT expertise.

\n\n

Prizes

\n\n

Day 1 - Winner - Portable Monitor

\n\n

Day 2 - Winner - Portable Monitor

\n\n\'',NULL,1297911),('3_Saturday','12','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_f691996aa36beda4150c4931f0b72163','\'\'',NULL,1297912),('3_Saturday','13','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_f691996aa36beda4150c4931f0b72163','\'\'',NULL,1297913),('3_Saturday','14','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_f691996aa36beda4150c4931f0b72163','\'\'',NULL,1297914),('3_Saturday','15','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_f691996aa36beda4150c4931f0b72163','\'\'',NULL,1297915),('3_Saturday','16','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_f691996aa36beda4150c4931f0b72163','\'\'',NULL,1297916),('2_Friday','11','11:00','16:59','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_8400d3ecce08de4cd3c26bb7b6392922','\'Title: GE(O)SINT Contest
\nTags: Recon Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

Test your geospatial intelligence skills in this unique contest. Identify locations, analyze imagery, and demonstrate your GeoINT expertise.

\n\n

Prizes

\n\n

Day 1 - Winner - Portable Monitor

\n\n

Day 2 - Winner - Portable Monitor

\n\n\'',NULL,1297917),('2_Friday','12','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_8400d3ecce08de4cd3c26bb7b6392922','\'\'',NULL,1297918),('2_Friday','13','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_8400d3ecce08de4cd3c26bb7b6392922','\'\'',NULL,1297919),('2_Friday','14','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_8400d3ecce08de4cd3c26bb7b6392922','\'\'',NULL,1297920),('2_Friday','15','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_8400d3ecce08de4cd3c26bb7b6392922','\'\'',NULL,1297921),('2_Friday','16','11:00','16:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'GE(O)SINT Contest\'','\'\'','Creator Events_8400d3ecce08de4cd3c26bb7b6392922','\'\'',NULL,1297922),('2_Friday','12','12:40','15:10','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Threat Actors: Gotta Catch \'Em All\'','\'Marcelle Lee,Will Thomas\'','Creator Workshops_7713837d79e3b483458f652f80c1afba','\'Title: Threat Actors: Gotta Catch \'Em All
\nTags: Recon Village | Creator Workshop
\nWhen: Friday, Aug 7, 12:40 - 15:10 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\nYour mission: Stop chasing single indicators and start profiling the actual behavior of the adversary. From cybercriminals to state-sponsored actors, every threat group leaves a unique operational blueprint. Whether you are an OSINT hobbyist or an experienced cyber intelligence analyst, come ready to dissect real-world attack behaviors, translate data into actionable insights, and master the art of OSINT-powered TTP research.
\n\n

This hands-on workshop explores the world of cyber threat actors and the open-source intelligence (OSINT) methodologies used to unmask their behavioral patterns. Rather than focusing strictly on fleeting indicators of compromise (IoCs) like file hashes or IP addresses, participants will learn how to extract, analyze, and profile an adversary\'s true Tactics, Techniques, and Procedures (TTPs).

\n\n

Through interactive, real-world case studies, attendees will learn how to analyze public incident reports, open intelligence repositories, and external datasets to map out an actor\'s operational playbook. Using frameworks like MITRE ATT&CK and the Diamond Model, participants will practice pivoting from technical data to strategic threat profiles—equipping them with the research skills needed to predict and counter adversarial behavior without ever needing an enterprise budget.

\n\n

Workshop Structure:

\n\n

Module 1: Foundations of Threat Intelligence & Actor Profiling

\n\n

The Threat Landscape: Definitions and categories of actors (APTs, cybercriminals, hacktivists, insiders).

\n\n

Understanding Adversarial Motivation: Moving beyond what happened to why and how actors select their targets and techniques.

\n\n

Intelligence Categorization: Differentiating between Strategic, Operational, and Tactical/Technical intelligence, and how TTP research feeds all three.

\n\n

Module 2: The Analytical Frameworks

\n\n

MITRE ATT&CK Deep Dive: Navigating the matrix, understanding sub-techniques, and avoiding common mapping pitfalls.

\n\n

The Diamond Model: Connecting the four core nodes (Adversary, Capability, Infrastructure, Victim) to tell a complete campaign story.

\n\n

The Pyramid of Pain: Understanding why tracking TTPs inflicts the maximum cost on the adversary compared to trivial indicators.

\n\n

Module 3: Dissecting the Data (Case Study Analysis)

\n\n

Deconstructing DFIR Reports: Walking through real-world incident examples (e.g., Gootloader campaigns, ransomware operations) to extract behavioral indicators from public write-ups.

\n\n

Safe Analysis Practices: Utilizing basic web-based OSINT tools (urlscan.io, Browserling, CyberChef) to safely evaluate delivery mechanisms and landing pages without compromising investigator safety.

\n\n

Module 4: Live TTP Research (Group Exercise)

\n\n

The Scenario: Groups are given an initial, ambiguous threat brief or a raw dataset from a recent campaign.

\n\n

The Analysis: Using open-source resources, teams will collaborate to identify the actor\'s threat components (who, what, where, when, how, why).

\n\n

The Playbook: Teams will map their findings into the MITRE ATT&CK Navigator, build a comprehensive threat intelligence profile, and present their adversarial playbook to the room.

\n\nSpeakers:Marcelle Lee,Will Thomas
\n
\nSpeakerBio:  Marcelle Lee
\nNo BIO available
\nSpeakerBio:  Will Thomas
\nNo BIO available
\n\n\'',NULL,1297923),('2_Friday','13','12:40','15:10','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Threat Actors: Gotta Catch \'Em All\'','\'Marcelle Lee,Will Thomas\'','Creator Workshops_7713837d79e3b483458f652f80c1afba','\'\'',NULL,1297924),('2_Friday','14','12:40','15:10','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Threat Actors: Gotta Catch \'Em All\'','\'Marcelle Lee,Will Thomas\'','Creator Workshops_7713837d79e3b483458f652f80c1afba','\'\'',NULL,1297925),('2_Friday','15','12:40','15:10','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Threat Actors: Gotta Catch \'Em All\'','\'Marcelle Lee,Will Thomas\'','Creator Workshops_7713837d79e3b483458f652f80c1afba','\'\'',NULL,1297926),('2_Friday','15','15:30','17:59','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'BBOT: Automating the OSINT Kill Chain with a Single Command\'','\'Mark Gaddy\'','Creator Workshops_9db4247c67d74ccb2366ae6a856ebde7','\'Title: BBOT: Automating the OSINT Kill Chain with a Single Command
\nTags: Recon Village | Creator Workshop
\nWhen: Friday, Aug 7, 15:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

Reconnaissance is the foundation of every successful engagement but fragmented tooling, manual chaining, and missed data leave gaps that cost you findings. BBOT (Bighuge BLS OSINT Tool) was built to solve that. Developed by Black Lantern Security, BBOT is a recursive, event-driven OSINT framework that replaces the traditional phased approach with continuous, real-time discovery every new piece of data is immediately fed back into the scan engine to uncover what linear workflows miss.

\n\n

This is a fully hands-on workshop. Attendees will install and configure BBOT, then run it live against their own scoped bug bounty targets turning the session into real reconnaissance rather than a slide-driven demo. We\'ll cover BBOT\'s 100+ module architecture spanning subdomain enumeration, cloud asset discovery, email harvesting, web spidering, and vulnerability scanning with Nuclei, all chainable in a single command and firing recursively in real time. Along the way we\'ll dig into scope management, passive vs. active recon tradeoffs, and the web hacking modules that can point you toward real findings.

\n\n

By the end of the session, attendees will walk away with actual scan output from a live target, a repeatable BBOT-driven recon workflow they can drop into their next program, and a clear understanding of how to triage findings into real submissions. Whether you\'re new to automated recon or a seasoned bug bounty hunter still stitching tools together by hand, this workshop will change how you approach OSINT at scale.

\n\n

Module 1 — Why BBOT? The Problem with How We Recon Now

\n\n

The fragmented toolchain problem: Amass → Subfinder → httpx → manual grep

\n\n

Why phased OSINT misses things — and what recursive, event-driven recon solves

\n\n

BBOT\'s origin at Black Lantern Security and design philosophy

\n\n

Quick architecture overview: modules, events, presets, scope

\n\n

3.0 Updates - Rustification of HTTP and DNS

\n\n

Q&A / audience skill check

\n\n

Module 2 — Getting Oriented: Installation, Config & First Scan

\n\n

Verify install and run bbot --help

\n\n

Listing and exploring modules with bbot -l

\n\n

Understanding flags vs. modules vs. presets

\n\n

Exercise 2.1: Run your first subdomain scan

\n\n

Reading and understanding BBOT output

\n\n

Scan output folders, naming conventions, and where data lives

\n\n

Module 3 — Subdomain Enumeration Deep Dive

\n\n

How BBOT\'s recursive engine finds more than traditional tools

\n\n

Passive vs. active enumeration — when to use each

\n\n

Subdomain mutations and wordcloud usage

\n\n

Exercise 3.1: Full active subdomain enum

\n\n

Module 4 — Going Deeper: Cloud, Email & Asset Discovery

\n\n

Cloud enumeration: S3 buckets, Azure blobs, GCP assets

\n\n

Email harvesting for org footprinting

\n\n

Combining flags for broader discovery

\n\n

Exercise 4.1: Run a combined cloud + email + subdomain scan

\n\n

Identifying misconfigured or exposed cloud assets in output

\n\n

Discussion: how these findings translate to bug bounty submissions

\n\n

Module 5 — Web Hacking Modules & Vulnerability Scanning

\n\n

Overview of BBOT\'s web module suite: httpx, gowitness, wappalyzer, nuclei

\n\n

Web spidering for email, secrets, and exposed paths

\n\n

Nuclei integration — what it scans for and how to interpret results

\n\n

Exercise 5.1: Full web scan with screenshots

\n\n

Exercise 5.2: Kitchen sink scan (instructor-guided, safe target only)

\n\n

Setting expectations: BBOT points you at the doors — you still have to kick them open

\n\n

Module 6 — Triage, Workflow & What Happens After the Scan

\n\n

How to structure your post-BBOT workflow: what to investigate first

\n\n

Prioritizing findings by severity and exploitability

\n\n

Avoiding common pitfalls: rate limiting, duplicate findings, out-of-scope mistakes

\n\n

Building a repeatable bug bounty recon workflow around BBOT

\n\n

Scheduling and automating recurring scans for continuous monitoring

\n\n

Wrap-Up & Q&A

\n\n

Recap of key takeaways

\n\n

Recommended next steps and resources

\n\n

GitHub, docs, and community links

\n\n

Open Q&A

\n\nSpeakerBio:  Mark Gaddy
\nNo BIO available
\n\n\'',NULL,1297927),('2_Friday','16','15:30','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'BBOT: Automating the OSINT Kill Chain with a Single Command\'','\'Mark Gaddy\'','Creator Workshops_9db4247c67d74ccb2366ae6a856ebde7','\'\'',NULL,1297928),('2_Friday','17','15:30','17:59','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'BBOT: Automating the OSINT Kill Chain with a Single Command\'','\'Mark Gaddy\'','Creator Workshops_9db4247c67d74ccb2366ae6a856ebde7','\'\'',NULL,1297929),('3_Saturday','10','10:00','12:30','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Hunting the Contagious Trader Delivery Network\'','\'Alessandra Rizzo,Ariel Ropek\'','Creator Workshops_1d8b5e7c5ff6cb89e28060cbffc43b86','\'Title: Hunting the Contagious Trader Delivery Network
\nTags: Recon Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

North Korean threat actors are running one of the largest software supply chain campaigns ever observed in the npm ecosystem, and the infrastructure hiding it in plain sight is discoverable through open-source reconnaissance alone.

\n\n

This workshop walks participants through how we mapped a live DPRK delivery network targeting cryptocurrency developers, starting from a single malicious npm package and expanding outward to uncover 50+ malicious packages, 100+ GitHub repositories, 30+ throwaway npm personas, 20+ rotating C2 domains, and a social media promotion layer spanning X and Reddit.

\n\n

The investigation surfaces three malware families: PromptMink, ClipViper, and OtterCookie, which operate through what initially appeared to be separate campaigns but share overlapping infrastructure, actors, and delivery techniques.

\n\n

The workshop focuses on the recon methodology behind the mapping through six hands-on modules:

\n\n
    \n
  • Dependency chain tracing: How malicious payloads hide one to three hops deep in transitive npm dependencies, evading surface-level code review and automated scanners

  • \n
  • Actor network pivoting: Using email patterns, SSH key reuse, shared C2 infrastructure, and build artifact fingerprints to link 30+ throwaway npm accounts into operational clusters

  • \n
  • Identity spoofing detection: How to catch developer identity theft through timezone offset analysis

  • \n
  • GitHub delivery front reconnaissance: Tracing 40+ fork chains across front organizations all serving identical malicious payloads behind bot-inflated star counts and SEO-stuffed descriptions

  • \n
  • Social media promotion mapping: Connecting verified X accounts and Reddit personas to the distribution layer, and observing how the social infrastructure persists even after GitHub takedowns

  • \n
  • Evasion tracking in real time: Documenting the operators\' shift from obfuscated JavaScript to on-chain payload storage via Solana, where the npm package contains zero malicious code and the payload lives in a blockchain account beyond the reach of static analysis

  • \n
\n\n

Participants work directly with actionable IoCs (packages, C2 domains, SSH keys, YARA rules, detection queries) and leave with a breakdown of how current Contagious Interview and Contagious Trader toolsets are converging into a unified threat.

\n\n

Attendees will leave with a repeatable framework for mapping supply chain malware delivery networks using open-source data: package registries, Git metadata, DNS records, social media artifacts, and cross-referencing with community threat feeds.

\n\nSpeakers:Alessandra Rizzo,Ariel Ropek
\n
\nSpeakerBio:  Alessandra Rizzo
\nNo BIO available
\nSpeakerBio:  Ariel Ropek
\nNo BIO available
\n\n\'',NULL,1297930),('3_Saturday','11','10:00','12:30','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Hunting the Contagious Trader Delivery Network\'','\'Alessandra Rizzo,Ariel Ropek\'','Creator Workshops_1d8b5e7c5ff6cb89e28060cbffc43b86','\'\'',NULL,1297931),('3_Saturday','12','10:00','12:30','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Hunting the Contagious Trader Delivery Network\'','\'Alessandra Rizzo,Ariel Ropek\'','Creator Workshops_1d8b5e7c5ff6cb89e28060cbffc43b86','\'\'',NULL,1297932),('3_Saturday','12','12:40','15:10','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'The Hard Part of ASM: Ownership Attribution\'','\'Jeff Foley\'','Creator Workshops_ef95698d47a0690b95f9abb29de7dcb0','\'Title: The Hard Part of ASM: Ownership Attribution
\nTags: Recon Village | Creator Workshop
\nWhen: Saturday, Aug 8, 12:40 - 15:10 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

Attack Surface Management (ASM) lives or dies on a deceptively simple question: who owns this? Without reliable attribution, an asset inventory is just a pile of hosts, domains, certificates, and cloud endpoints—with no defensible way to scope an organization’s true digital footprint or separate first-party infrastructure from vendors, subsidiaries, acquisitions, joint ventures, and brand portfolios.

\n\n

This talk dives into the real-world challenge of attributing internet-exposed assets to legal entities, not just names. Corporate identity is messy: organizations operate under trade names, localized spellings, legacy names, and jurisdiction-specific registrations. Meanwhile, the internet leaks ownership signals through fragmented, lossy metadata—RDAP/WHOIS, certificate subject/issuer fields, ASN registrations, DNS TXT verification records, trademark references, and public corporate registries. Each source is incomplete on its own; together they can still conflict, drift over time, and create duplicate “identities” that quietly degrade attribution accuracy.

\n\n

Using the OWASP Amass Project as a concrete reference point, we’ll walk through an attribution-centric discovery workflow: collecting signals, normalizing entity identity, resolving aliases across jurisdictions, and scoring confidence to decide when to merge, when to split, and when to escalate for analyst review. We’ll also explore how attribution errors propagate into ASM outcomes—missed scope, false positives, and blind spots in third-party exposure—and how disciplined entity modeling can turn noisy OSINT into a repeatable system of record.

\n\n

Attendees will leave with practical techniques for improving attribution quality, a mental model for entity resolution, and actionable ideas for making ASM outputs trustworthy enough to drive risk decisions.

\n\nSpeakerBio:  Jeff Foley, Founder and Project Leader at OWASP Amass Project
\nNo BIO available
\n\n\'',NULL,1297933),('3_Saturday','13','12:40','15:10','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'The Hard Part of ASM: Ownership Attribution\'','\'Jeff Foley\'','Creator Workshops_ef95698d47a0690b95f9abb29de7dcb0','\'\'',NULL,1297934),('3_Saturday','14','12:40','15:10','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'The Hard Part of ASM: Ownership Attribution\'','\'Jeff Foley\'','Creator Workshops_ef95698d47a0690b95f9abb29de7dcb0','\'\'',NULL,1297935),('3_Saturday','15','12:40','15:10','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'The Hard Part of ASM: Ownership Attribution\'','\'Jeff Foley\'','Creator Workshops_ef95698d47a0690b95f9abb29de7dcb0','\'\'',NULL,1297936),('3_Saturday','15','15:20','17:50','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Vibe Coding Your Way to a Fully Functional Open-Source Intelligence Platform\'','\'Lenin Alevski\'','Creator Workshops_725ca8a55e20de070ebb5e7a685a665a','\'Title: Vibe Coding Your Way to a Fully Functional Open-Source Intelligence Platform
\nTags: Recon Village | Creator Workshop
\nWhen: Saturday, Aug 8, 15:20 - 17:50 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

Everyone is talking about vibe coding, but most examples stop at TODO apps, landing pages, or simple CRUD applications. This workshop goes far beyond that.

\n\n

Participants will use modern AI coding agents to build a real-world Open-Source Intelligence (OSINT) platform from scratch designed to aggregate and visualize intelligence data on an interactive 3D globe.

\n\n

Rather than simply watching a demo, attendees will actively build the application alongside the instructor while learning the mindset, prompting techniques, and engineering workflow required to successfully collaborate with AI coding assistants.

\n\n

The workshop begins with the fundamentals of vibe coding: what it actually is, why it works, where it fails, and how to communicate effectively with AI agents. Participants will learn practical prompting strategies, iterative development techniques, and methods for breaking large software systems into manageable tasks that AI can successfully implement.

\n\n

From there, we\'ll progressively build an intelligence dashboard capable of consuming and visualizing multiple real-time OSINT sources, including flight tracking, satellite positions, earthquake feeds, maritime traffic, and other publicly available intelligence signals. Along the way, participants will generate modern user interfaces, integrate external APIs, debug AI-generated code, and learn when to trust the model and when not to.

\n\n

Rather than treating AI as a code generator, this workshop teaches attendees how to use AI as an engineering partner capable of dramatically increasing development velocity while still maintaining high-quality software.

\n\n

By the end of the workshop, every participant will have:

\n\n
    \n
  1. A working open-source intelligence platform running locally

  2. \n
  3. A practical workflow for building complex software using AI coding agents

  4. \n
  5. A reusable prompting framework applicable to future projects

  6. \n
  7. Experience integrating multiple public OSINT data sources

  8. \n
  9. An understanding of the strengths and limitations of AI-assisted software development

  10. \n
  11. A roadmap for continuing to extend the platform after the workshop

  12. \n
\n\n

The workshop is based on the open-source project: https://github.com/Alevsk/respondent-community

\n\n

Workshop Outline (150 Minutes)

\n\n

Part 1 — Introduction to Vibe Coding (20 min)

\n\n
    \n
  • What vibe coding actually means

  • \n
  • Mental models for collaborating with AI

  • \n
  • Selecting the right AI model for the task

  • \n
  • Understanding agentic coding workflows

  • \n
  • Common mistakes and misconceptions

  • \n
\n\n
\n\n

Part 2 — Prompt Engineering for Software Development (25 min)

\n\n
    \n
  • Structuring prompts that produce maintainable code

  • \n
  • Breaking large systems into incremental tasks

  • \n
  • Designing software through conversation

  • \n
  • Iterating instead of regenerating

  • \n
  • Knowing when to intervene manually

  • \n
\n\n
\n\n

Part 3 — Building the Intelligence Platform (75 min)

\n\n

Participants will build the platform together while learning how to:

\n\n
    \n
  • Generate a modern frontend

  • \n
  • Create a real-time 3D globe visualization

  • \n
  • Integrate multiple public OSINT APIs

  • \n
  • Display flights, satellites, earthquakes, ships, and additional intelligence feeds

  • \n
  • Build reusable UI components with AI

  • \n
  • Debug AI-generated code

  • \n
  • Refactor and improve generated implementations

  • \n
  • Continue extending the application using AI as a development partner

  • \n
\n\n
\n\n

Part 4 — Lessons Learned & Advanced Techniques (20 min)

\n\n
    \n
  • What AI does well

  • \n
  • Where AI still struggles

  • \n
  • Managing technical debt

  • \n
  • Building larger projects with AI

  • \n
  • Cost optimization strategies

  • \n
  • Recommended workflows and tooling

  • \n
  • Future directions for AI-assisted engineering

  • \n
\n\nSpeakerBio:  Lenin Alevski, Security Engineer at Google
\n

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.

\n\n\n\'',NULL,1297937),('3_Saturday','16','15:20','17:50','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Vibe Coding Your Way to a Fully Functional Open-Source Intelligence Platform\'','\'Lenin Alevski\'','Creator Workshops_725ca8a55e20de070ebb5e7a685a665a','\'\'',NULL,1297938),('3_Saturday','17','15:20','17:50','Y','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Vibe Coding Your Way to a Fully Functional Open-Source Intelligence Platform\'','\'Lenin Alevski\'','Creator Workshops_725ca8a55e20de070ebb5e7a685a665a','\'\'',NULL,1297939),('3_Saturday','16','16:00','16:59','N','Recon Village','LVCCW Level 1 Hall 2 501 (Recon Village)','\'Live Recon Contest — Final Presentations\'','\'\'','Creator Events_06b5bcb6609919a4040cffe4e92b7b65','\'Title: Live Recon Contest — Final Presentations
\nTags: Recon Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 501 (Recon Village) - Map
\n
\nDescription:
\n

Final presentations for the Live Recon Contest. Participants present their findings in front of a jury.

\n\n\'',NULL,1297940),('2_Friday','11','11:00','11:59','N','.EDU Community','LVCCW Level 1 Hall 4 1418 (.EDU Community)','\'Cracking the Cybersecurity Career Code with the Cyber Color Wheel\'','\'Shavvon \"TheSiren\" Cintron\'','Creator Talks_fb194edba833c644dedd922f9ae55c52','\'Title: Cracking the Cybersecurity Career Code with the Cyber Color Wheel
\nTags: .EDU Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map
\n
\nDescription:
\nGiveaway: Two raffles for one copy of:
\nSee Yourself in Cyber: Security Careers Beyond Hacking
\n\n\n\nSpeakerBio:  Shavvon \"TheSiren\" Cintron
\n

Shavvon Cintron spent the last decade climbing the IT ladder, now working in IT and cybersecurity within the healthcare space. She\'s got an MS in Cybersecurity from Pace, a BS in Criminal Justice from CUNY John Jay, and a 2025 SANS Institute Difference Makers Rising Star nod, so somebody thinks she\'s doing something right. When she\'s not at her day job, she\'s Director of Women\'s Education for the Women\'s Society of Cyberjutsu, building the programs she wishes existed when she was trying to break in. She goes by \"Siren of the Cyber Sea.\" Get too close and you might not want to leave.

\n\n\n\'',NULL,1297941),('2_Friday','12','12:00','12:59','N','.EDU Community','LVCCW Level 1 Hall 4 1418 (.EDU Community)','\'Student-Run Cyber Clubs - Why They Matter & Digital Playgrounds\'','\'Steven \"Stengo\" Ngo\'','Creator Talks_cbccaeda2f7e255a45d9e95c26d9ff9a','\'Title: Student-Run Cyber Clubs - Why They Matter & Digital Playgrounds
\nTags: .EDU Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Steven \"Stengo\" Ngo
\n

Steven Ngo is a third-year Ph.D. student in Software Engineering at the University of California, Irvine, advised by Associate Professor Joshua Garcia, with research interests in software engineering & security education and software security. Ngo studies student-run organizations (e.g., cyber clubs) to understand their perspectives and motivations in providing informal modalities of peer-to-peer education, which facilitate the development of educational collaborations, frameworks, and tools to support such organizations.

\n\n\n\'',NULL,1297942),('2_Friday','13','13:00','13:59','N','.EDU Community','LVCCW Level 1 Hall 4 1418 (.EDU Community)','\'ScamBusters: Turning Undergrads into Threat Hunters\'','\'Angela \"BlondeTechie\" Ramos\'','Creator Talks_b0c7f0eab05102bc39039f99989433ad','\'Title: ScamBusters: Turning Undergrads into Threat Hunters
\nTags: .EDU Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Angela \"BlondeTechie\" Ramos
\n

Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coach for Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations.

\n\n\n\'',NULL,1297943),('2_Friday','14','14:00','14:59','N','.EDU Community','LVCCW Level 1 Hall 4 1418 (.EDU Community)','\'Hacking Education - Teaching Offensive Cyber Science at the Collegiate Level\'','\'Dave \"Rebelcadet\" Ortiz\'','Creator Talks_1de26334eebb440ec3f11f39bb2573f6','\'Title: Hacking Education - Teaching Offensive Cyber Science at the Collegiate Level
\nTags: .EDU Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Dave \"Rebelcadet\" Ortiz
\n

David Ortiz is the Chief Technology Officer (CTO) at X8 LLC, where he leads the\nfirm\'s engineering efforts to develop innovative technical, operational, and\nresearch solutions to meet complex customer requirements. With a diverse\nbackground in laser physics, information assurance, cyberspace operations, and\norganizational leadership, David is a seasoned professional dedicated to advancing cyber capabilities for both the U.S. Government and private industry customers.

\n\n\n\'',NULL,1297944),('2_Friday','17','17:00','17:59','N','.EDU Community','LVCCW Level 1 Hall 4 1418 (.EDU Community)','\'.edu Community Mixer\'','\'\'','Creator Events_c447ed310debb10eb0a65de73e02a7b8','\'Title: .edu Community Mixer
\nTags: .EDU Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1418 (.EDU Community) - Map
\n
\nDescription:
\n\n\n\'',NULL,1297945),('4_Sunday','11','11:30','11:59','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Disaster Intelligence - The past, present, and future of situational awareness during a crisis\'','\'Matt Green\'','Creator Talks_1bb3aed03d9bfee2011eeed27f03d1ae','\'Title: Disaster Intelligence - The past, present, and future of situational awareness during a crisis
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

OSINT, social media, drones, AI, and more… in this session, we’ll learn how these innovations are applied to make life-saving decisions before, during, and after a disaster

\n\nSpeakerBio:  Matt Green, Green Emergency Management Services
\n

Matt Green is your friendly neighborhood emergency manager, professor, and host of the state of disaster podcast. His passion is ensuring equitable, high-quality, whole community emergency management across sectors and borders.

\n\n\n\'',NULL,1297946),('4_Sunday','12','12:15','12:45','N','OSINT For Good Community','LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage','\'Practical Privacy Defenses for the Paranoid\'','\'Tina \"Hek8te\" Shakour\'','Creator Talks_19af7c9b1d5a84d4f93521b53145801f','\'Title: Practical Privacy Defenses for the Paranoid
\nTags: OSINT For Good Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:15 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage - Map
\n
\nDescription:
\n

Public records, browser tracks, and digital footprints leave you exposed. Now, AI helps tie it all together even faster for anyone looking for information on a person. In this session, go deeper than data broker removals to improve your personal privacy habits and help mask your online identity. Entry-level and open to all skill levels and non-OSINT experts.

\n\nSpeakerBio:  Tina \"Hek8te\" Shakour, Netwrix
\n

Hek8te (Keeper of the Keys) brings two decades of cybersecurity experience to the front lines of blue team defense, protecting systems and people worldwide. A Senior Coach for Trace Labs and a veteran TechWomen volunteer, she is dedicated to global defense, OSINT, and community mentorship.

\n\n\n\'',NULL,1297947),('2_Friday','11','11:00','11:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'Logsquashing: Consolidating Relevant Events Logs and Alerts\'','\'Ezz Tahoun\'','Creator Talks_24878458d6a0dec82cbaaedda1a5db88','\'Title: Logsquashing: Consolidating Relevant Events Logs and Alerts
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

In modern cybersecurity, the ability to connect isolated security alerts into coherent, actionable attack chains is essential. However, traditional detection methods often struggle to contextualize vast amounts of security data, leaving slow and stealthy attacks undetected within a sea of noise and false positives. This talk introduces a novel approach using open-source AI models to map, cluster, and correlate security alerts in order to uncover coordinated attacks. Through clustering, knowledge graphs, and AI-driven correlation, this approach offers significant improvements in SOC (Security Operations Center) efficiency and effectiveness. We detail the methodology, open source tools, and results of this approach across diverse environments, including cloud, telecom, and industrial control systems.

\n\nSpeakerBio:  Ezz Tahoun
\n

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

\n\n

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

\n\n

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada\'s CSE.

\n\n

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

\n\n

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

\n\n

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.

\n\n\n\'',NULL,1297948),('2_Friday','12','12:00','12:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'Once Upon a Prompt: Fairy Tales That Explain AI Security\'','\'Sana Talwar\'','Creator Talks_2ed0ff820ee6b5d466c8745988044176','\'Title: Once Upon a Prompt: Fairy Tales That Explain AI Security
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

Prompt injection is one of the biggest security challenges in AI, but it can be difficult to explain without diving into complex technical details. This session uses familiar fairy tales to make modern AI attacks easy to understand and hard to forget.\nWe’ll begin by exploring the architectural problem that makes prompt injection possible and why LLMs can’t separate instructions from data the way traditional software can. From there, we’ll examine three real-world AI security incidents, each paired with a classic story: Little Red Riding Hood illustrates prompt injection through trusted messengers, The Wolf in Sheep’s Clothing explains indirect prompt injection hidden in untrusted content, and The Trojan Horse demonstrates how hidden instructions can lead to data exfiltration and agent compromise. We’ll close by mapping practical defenses to OWASP and NIST guidance so attendees leave with clear mental models and actionable techniques for building more secure AI applications.

\n\nSpeakerBio:  Sana Talwar
\nNo BIO available
\n\n\'',NULL,1297949),('2_Friday','13','13:00','13:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'Nothing Wrong Here: Why AI Artifact Scanners Wave Malware Through\'','\'Amber Bennoui\'','Creator Talks_9b6391667b8d780c7bc692aca29d56b7','\'Title: Nothing Wrong Here: Why AI Artifact Scanners Wave Malware Through
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

Your AI security scanner says the skill is clean. Should you believe it? We took a corpus of malicious and benign agent skills and ran it through the tools security teams trust to catch this stuff. What we found should worry anyone shipping AI. The tools that fire loudest are often wrong, the ones that stay quiet are often blind, and the industry reflex of stacking more scanners on top makes the problem worse, not better. There is a reason for all of it, and it is not the one vendors want to talk about. This session walks through what actually breaks, why the whole category is looking in the wrong place, and what it would take to build a scanner whose green checkmark you can trust.

\n\nSpeakerBio:  Amber Bennoui
\nNo BIO available
\n\n\'',NULL,1297950),('2_Friday','14','14:00','14:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'The Agentic Free Pass: Does an Abliterated Backbone Make Agents Easier to Attack?\'','\'Karol Piekarski,Nishith Sinha\'','Creator Talks_552e7c9d49b0e4618e7c01c78ee8b76a','\'Title: The Agentic Free Pass: Does an Abliterated Backbone Make Agents Easier to Attack?
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

To attack an AI agent, the reflex is an abliterated model - refusal behavior surgically removed, expecting a stronger attacker. We tested that across open-weight models (Qwen3, Llama-3.1, the 754B GLM-5.2), scoring only attacks that actually fire a tool, not ones that just describe one.

\n\n

Abliteration does make a tireless attacker. Asked to write attack payloads — poisoned RAG docs, malicious tool descriptions, injections — an abliterated GLM-5.2 said yes roughly three times as often as its base (13% → 38%). Pointed at an aligned copy of itself, it jailbroke that copy 80% of the time on the first try, and lifted its hidden system prompt. Set loose in a real coding agent (OpenCode) attacking an aligned-model app, it found exploits on its own: faking a password-reset to send a phishing email, and a KYC passed result to skip an identity check and wire money.

\n\n

But look at how it won: blunt jailbreaks (ignore your instructions, SYSTEM OVERRIDE) failed about 100 times. Every win came from disguise — reframing the harmful step so it looked routine. Aligned agents block harm they recognize and fall for harm they don\'t.

\n\n

The backbone matters only for hard content — malware, weapons, drugs — where abliteration clearly raises success (Qwen3 37.5% → 60%, GLM-5.2 67.5% → 77.5%). And method matters: single-direction Heretic can\'t strip Llama-3.1\'s refusal, but eight-direction OBLITERATUS can. That gap is also a detector: a model that clears 50% on hard content, or eagerly writes attacks, is probably tampered.

\n\nSpeakers:Karol Piekarski,Nishith Sinha
\n
\nSpeakerBio:  Karol Piekarski, DevOps Engineer
\n

Karol Piekarski is a Lead DevOps Engineer working across cloud infrastructure, zero-trust architecture, and AI and agentic security for systems that serve hundreds of millions of consumers. His research focuses on the security of large language models and autonomous agents, with an emphasis on practical red-teaming and defensive tooling that teams can actually operationalize rather than shelve.

\n\n

His empirical work on abliteration and agentic framing reframes where alignment actually breaks down in agent pipelines: agentic framing alone can collapse a model\'s baseline safety, while abliteration matters mostly for the hardest content and is highly architecture-dependent. In 2026 he co-presented \"Move Fast, Stay Secure: Enterprise AI Agent Security in Practice\" at the Databricks Data + AI Summit, and spoke at SCaLE 23x on open source red-teaming for LLMs. He was one of only two external contributors to the Databricks Agentic AI Security Framework (DASF v3.0).

\n\n

Karol is the creator of Sundew.sh, an open source, MCP-native AI agent honeypot platform that uses behavioral fingerprinting and a persona engine for anti-fingerprinting, now adopted by external research teams studying agent behavior in the wild. He was selected as a Wiz MVP last year and this year received Wiz\'s Thought Leader award, and he is active in the AISECA Working Group, where he co-owns agentic security risk definitions.

\n\n

He holds the CCSP, CKA, four AWS specialty certifications along with DataDog and Tines, and he regularly judges and mentors at hackathons across Southern California.

\n\nSpeakerBio:  Nishith Sinha
\n

Nishith Sinha started his career by pulling secrets out of thin air. As a researcher at Georgia Tech, he co-authored a side-channel attack that recovered RSA private keys from OpenSSL by reading its electromagnetic emissions alone. No code executed, no system touched. Presented at USENIX, the work prompted a rapid fix from the OpenSSL team and is still cited as a landmark example of hardware-level cryptographic risk.

\n\n

It set the tone for what came next: a career built on finding the security gaps other people aren’t looking at. At Cisco, that meant network security, where he helped design the company’s firewall migration tooling. At Amazon, it meant identity, where he owned IAM strategy across tens of thousands of AWS accounts, and then application and cloud security, remediating critical vulnerabilities at enterprise scale. As generative AI took hold, Nishith moved with it, leading application security for Amazon Bedrock and Amazon Q, before building security from scratch for Amazon’s Nova foundation models, safeguarding training data, model artifacts, and infrastructure across hundreds of teams.

\n\n

Today, Nishith brings that range to Databricks, where he leads AI Security and the company’s work on Agentic Security, AI Red Teaming, and AI Enterprise Security. He holds 10 AI security patents spanning model artifact protection, secure execution of model-initiated computer actions, and behavioral-analytics-based content moderation. He co-authored the Databricks Agentic Security Framework (DASF) and is credited with several CVEs. His focus now is autonomous AI agents: the newest layer of the stack, and the one attackers understand least.

\n\n\n\'',NULL,1297951),('2_Friday','15','15:00','15:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'The New Horizons in Quantum and Space\'','\'Anshu Gupta\'','Creator Talks_3c42598dc715eb02285874845905ec22','\'Title: The New Horizons in Quantum and Space
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

While the industry obsesses over AI security, two frontier domains are quietly creating the next generation of high-demand security careers: post-quantum cryptography and space security. With NIST\'s PQC standards finalized, federal migration mandates in force, and harvest now, decrypt later attacks already underway, quantum readiness has shifted from research topic to boardroom priority. Meanwhile, exploding satellite constellations, contested orbits, and rising attacks on ground stations and command-and-control systems have made space a critical infrastructure battleground with a severe talent shortage. This talk breaks down the latest technological advances in both domains, the real-world threats driving demand, and the practical skills, certifications, and communities that can launch your career there. You\'ll leave with a concrete upskilling roadmap and a clear view of why quantum and space are the smartest career bets in security today.

\n\nSpeakerBio:  Anshu Gupta
\nNo BIO available
\n\n\'',NULL,1297952),('2_Friday','16','16:00','16:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'Defense in Depth for AI: Launching the AISECA Framework\'','\'Amber Bennoui,Karol Piekarski\'','Creator Talks_d93086121e976b8890c96729b0bb3852','\'Title: Defense in Depth for AI: Launching the AISECA Framework
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

Every week brings a new agentic AI attack and a new point solution that claims to stop it. None of them stop all of it, because agents do not have one attack surface, they have many, spread across the skills they load, the tools they call, the data they touch, and the humans who approve them. This talk introduces the AISECA Tiered Control Framework, an open, community-built model for defending agentic workflows the way we defend everything else that matters: in depth, in layers, with no single control carrying the whole load. We walk the framework end to end, then go deep on one control to show how it works in practice, what it catches, what it misses, and how it composes with the controls around it. You will leave with a shared vocabulary for agentic risk and a practical way to find the gaps in your own stack. Built in the open by practitioners, free to adopt, and yours to extend.

\n\nSpeakers:Amber Bennoui,Karol Piekarski
\n
\nSpeakerBio:  Amber Bennoui
\nNo BIO available
\nSpeakerBio:  Karol Piekarski, DevOps Engineer
\n

Karol Piekarski is a Lead DevOps Engineer working across cloud infrastructure, zero-trust architecture, and AI and agentic security for systems that serve hundreds of millions of consumers. His research focuses on the security of large language models and autonomous agents, with an emphasis on practical red-teaming and defensive tooling that teams can actually operationalize rather than shelve.

\n\n

His empirical work on abliteration and agentic framing reframes where alignment actually breaks down in agent pipelines: agentic framing alone can collapse a model\'s baseline safety, while abliteration matters mostly for the hardest content and is highly architecture-dependent. In 2026 he co-presented \"Move Fast, Stay Secure: Enterprise AI Agent Security in Practice\" at the Databricks Data + AI Summit, and spoke at SCaLE 23x on open source red-teaming for LLMs. He was one of only two external contributors to the Databricks Agentic AI Security Framework (DASF v3.0).

\n\n

Karol is the creator of Sundew.sh, an open source, MCP-native AI agent honeypot platform that uses behavioral fingerprinting and a persona engine for anti-fingerprinting, now adopted by external research teams studying agent behavior in the wild. He was selected as a Wiz MVP last year and this year received Wiz\'s Thought Leader award, and he is active in the AISECA Working Group, where he co-owns agentic security risk definitions.

\n\n

He holds the CCSP, CKA, four AWS specialty certifications along with DataDog and Tines, and he regularly judges and mentors at hackathons across Southern California.

\n\n\n\'',NULL,1297953),('2_Friday','17','17:00','17:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'What Got You Here Won\'t Get You There: Security in the AI Era\'','\'Amber Bennoui\'','Creator Talks_f33adac61c4cb9b1dee3edb1a74da4af','\'Title: What Got You Here Won\'t Get You There: Security in the AI Era
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

A candid panel on how AI is reshaping security careers. We sit down with practitioners ranging from CISO to product security engineer, working across governance, physical hardware and SaaS, for an honest 45-minute conversation about what it takes to break in, level up, and stand out now that AI is changing what skills matter, what roles look like, and how hiring gets done.

\n\nSpeakerBio:  Amber Bennoui
\nNo BIO available
\n\n\'',NULL,1297954),('3_Saturday','10','10:00','10:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'From al-Kindi to DEF CON: The Middle Eastern and African Roots of Cybersecurity\'','\'Amber Bennoui,Ezz Tahoun\'','Creator Talks_eeb0a9fc6b16f89a232ab597d3b6c905','\'Title: From al-Kindi to DEF CON: The Middle Eastern and African Roots of Cybersecurity
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

The word algorithm comes from a mathematician in ninth-century Baghdad. The first person to write down how to break a cipher was working in the Arab world more than a thousand years before modern computing. The foundations of the field we now call cybersecurity were laid by scholars from the Middle East and Africa, and that lineage runs straight through to the practitioners in this room. This session opens the MEACS Community Space with a look at those roots, from the origins of cryptanalysis and algebra to the engineers, defenders, and founders carrying the work forward today. We will talk about where we come from, why representation in this field is not a side conversation, and what this community is here to build over the next few days. Whether you trace your roots to the region or you just want the history the industry skipped, you are welcome here. Come meet the people who make this space what it is.

\n\nSpeakers:Amber Bennoui,Ezz Tahoun
\n
\nSpeakerBio:  Amber Bennoui
\nNo BIO available
\nSpeakerBio:  Ezz Tahoun
\n

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

\n\n

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

\n\n

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada\'s CSE.

\n\n

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

\n\n

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

\n\n

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.

\n\n\n\'',NULL,1297955),('3_Saturday','13','13:00','13:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'BewAIre: Detecting Malicious Pull Requests at Scale with LLMs\'','\'Andrew Krug\'','Creator Talks_4c6493ee66dd369bc1a7658f710f2ff8','\'Title: BewAIre: Detecting Malicious Pull Requests at Scale with LLMs
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

As AI coding assistants accelerate software development, the volume of pull requests at Datadog has grown to nearly 10,000 per week, increasing the risk that malicious changes slip through due to review fatigue. To address this, Datadog built BewAIre, an LLM-powered code review system designed to identify malicious source code changes introduced by threat actors. By reducing approval fatigue for developers while increasing friction for attackers, BewAIre guides human reviewers to the areas where judgment matters most, without slowing developer velocity.

\n\n

In this breakout session, Andrew Krug, Head of Security Advocacy and Research will share why BewAIre was built, how it evolved from a hackathon experiment into a production-grade internal system, and the key architectural decisions and trade-offs involved along the way. They will discuss what worked, what didn\'t, and the limitations the team encountered when applying LLMs to security-critical workflows.

\n\n

They will also cover how BewAIre is now being integrated into Datadog Code Security, and what it takes to turn an internal engineering tool into a product capability used at scale. Attendees will leave with practical lessons on building, hardening, and productizing LLM-powered systems and how you can use LLMs to minimize the security risks introduced by the new LLM-code-generation paradigm.

\n\nSpeakerBio:  Andrew Krug
\nNo BIO available
\n\n\'',NULL,1297956),('3_Saturday','14','14:00','14:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'The Hidden Data Supply Chain: How a SaaS Platform Broadcast Credentials and Customer Identities\'','\'Sam Jadali\'','Creator Talks_8399851c09524854c32e262dcf873ed5','\'Title: The Hidden Data Supply Chain: How a SaaS Platform Broadcast Credentials and Customer Identities
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

Security researcher Sam Jadali, known for uncovering DataSpii, presents new research on the hidden and often inadvertent data supply chains inside SaaS platforms. In controlled tests of Klaviyo, a marketing/CRM platform processing roughly 8 billion customer profiles across 600k+ websites, simply viewing a contact\'s profile transmitted that person\'s name, email, or identifier to outside vendors, several not on Klaviyo\'s sub-processor list. Worse, during account registration a test account\'s password, email, phone number, and company details were sent to 31 third-party hostnames including Google, Meta, and LinkedIn, with four endpoints reflecting the password back to confirm receipt. Some recipients hid behind unbranded domains that customers and compliance teams can\'t identify through ordinary inspection. As human- and AI-generated code ships faster, one small HTML flaw can broadcast sensitive data across supply chains few organizations monitor. Jadali walks through the evidence, reproducible from network captures and public Common Crawl records.

\n\nSpeakerBio:  Sam Jadali
\nNo BIO available
\n\n\'',NULL,1297957),('3_Saturday','15','15:00','15:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'Agents of Chaos: A Field Guide to How Agentic AI Gets Owned, and What Trust Nothing Looks Like in Practice\'','\'Amber Bennoui\'','Creator Talks_7a7ef92b429fb7aa62918235e4325860','\'Title: Agents of Chaos: A Field Guide to How Agentic AI Gets Owned, and What Trust Nothing Looks Like in Practice
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

Your agent has more ways to get owned than you think, and most of them do not look like an attack. Give an AI agent tools, memory, and the ability to install things it found on the internet, and you have built an attack surface nobody has a real security model for yet. This talk maps the whole thing: every place an agentic system can be turned against its user, from the instructions it reads to the marketplaces it trusts, laid out as one picture instead of a pile of scary headlines. Then we get to the uncomfortable part, which is what defending it actually takes. You will leave knowing exactly where the bodies are buried, whether you build agents or defend them.

\n\nSpeakerBio:  Amber Bennoui
\nNo BIO available
\n\n\'',NULL,1297958),('3_Saturday','17','17:00','17:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'MEACS Trivia, Games and Networking\'','\'\'','Creator Events_a64aea5272851f37d5619bcc66119b13','\'Title: MEACS Trivia, Games and Networking
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Event/Activity
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

Test what you know and meet the people who know the rest. Bring your team or find one when you get there for a few rounds of security trivia, from the history this community is built on to the attacks making headlines right now. Expect a friendly, competitive crowd, bragging rights on the line, and plenty of time to connect with other Middle Eastern and African practitioners and friends of the community between rounds. Whether you came to win or just to find your people, pull up a chair.

\n\n\'',NULL,1297959),('4_Sunday','10','10:00','10:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'From Roots to Renaissance: The Rising Generation of Middle Eastern and African Cybersecurity\'','\'Ezz Tahoun\'','Creator Talks_a25f43c849a4b7b95ab0bf07064ab09c','\'Title: From Roots to Renaissance: The Rising Generation of Middle Eastern and African Cybersecurity
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

If yesterday was where we came from, today is where we are going. The same regions that gave the world algebra and the first codebreakers are now home to some of the fastest-growing security communities on the planet, from Lagos to Cairo to Riyadh, alongside a diaspora shaping the field from inside every major company and conference. This talk picks up where the kickoff left off and moves from history to right now: the researchers, founders, defenders, and organizers carrying the work forward, the obstacles that still stand in the way, and what it takes to build a career and a community when the industry has not always made room for you. We will talk honestly about representation, mentorship, and momentum, and about the role a space like MEACS plays in turning a shared heritage into a shared future. Come for the story, stay to find your people.

\n\nSpeakerBio:  Ezz Tahoun
\n

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

\n\n

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

\n\n

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada\'s CSE.

\n\n

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

\n\n

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

\n\n

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.

\n\n\n\'',NULL,1297960),('4_Sunday','12','12:00','12:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'Where the Authorization Boundary Goes in Agent Workflows\'','\'Mohamed Magdy AbuMuslim\'','Creator Talks_b8bb466e0d7f81b671c848b11a352c98','\'Title: Where the Authorization Boundary Goes in Agent Workflows
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

In May 2026, attackers took over high-profile Instagram accounts by asking Meta’s AI support assistant to change a recovery email. The agent changed it, the attacker used the recovery flow, and the account was gone. The agent was not tricked in any exotic way. It just did something it was allowed to do, for someone who should not have been allowed to ask.

\n\n

I have spent a while delivering agentic AI security work, and I keep seeing the same thing. Everyone is struggling to push authorization into AI agents. Teams deploy an agent and cannot actually tell you what it is capable of or what rules it is bound by. This is the identity and access management problem we have been fighting for decades, now behind a conversational interface. The agent looks like a smart assistant, but it can act like an admin, and nobody drew the line for what it is allowed to reach.

\n\n

Maze is the pattern I came up with for this, and I have implemented it and it works. The agent never executes directly. Its request enters a fixed sequence of gates: is this a privileged action, is the user authenticated, do they own the target account, can this tool mutate data, does policy allow it, is it within rate limits, did step-up verification pass. Each gate either advances the request or drops it into a blocked state, and there is exactly one path through to execution. Every outcome, pass or block, is written to an audit log. The authorization does not live inside the model, where it can be talked around. It lives in the gates, and the agent cannot route around them.

\n\n

I will walk through the Meta case as the example, then show how Maze structures the workflow so the agent stays inside gates it cannot step past.

\n\nSpeakerBio:  Mohamed Magdy AbuMuslim
\nNo BIO available
\n\n\'',NULL,1297961),('4_Sunday','13','13:00','13:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)','\'MEACS Trivia, Games and Networking\'','\'\'','Creator Events_da99f95c7338ce8d7f712f75f4053750','\'Title: MEACS Trivia, Games and Networking
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Event/Activity
\nWhen: Sunday, Aug 9, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community) - Map
\n
\nDescription:
\n

Test what you know and meet the people who know the rest. Bring your team or find one when you get there for a few rounds of security trivia, from the history this community is built on to the attacks making headlines right now. Expect a friendly, competitive crowd, bragging rights on the line, and plenty of time to connect with other Middle Eastern and African practitioners and friends of the community between rounds. Whether you came to win or just to find your people, pull up a chair.

\n\n\'',NULL,1297962),('2_Friday','17','17:00','17:30','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Condense, Contextualize, and Correlate: Optimize Costs while Connecting the Dots at Scale\'','\'Ezz Tahoun\'','Creator Talks_5126946e55dcc046c71af2bd89bf8f59','\'Title: Condense, Contextualize, and Correlate: Optimize Costs while Connecting the Dots at Scale
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Auto-condense telemetry volumes by 80% without data loss by grouping related records & deduping redundant values, with ML that auto-normalizes to a unified schema & auto-enriches data with relevant abstractive classifications, framework-aligned controls, contextual tags & environment labels. Use the efficiency with TKG ML to scale multi-level correlations & reveal all similarity & causality patterns & root causes. Use AI to automate troubleshooting, investigations, remediations & operations.

\n\nSpeakerBio:  Ezz Tahoun
\n

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

\n\n

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

\n\n

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada\'s CSE.

\n\n

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

\n\n

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

\n\n

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.

\n\n\n\'',NULL,1297963),('3_Saturday','14','14:30','14:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'Condense Volumes, Connect Dots, Enrich Contexts: Scaling Root Cause Analysis and Automated Troubleshooting with ML\'','\'Ezz Tahoun\'','Creator Talks_bfcdf6af90faf1a4818ea4cf3b0d6568','\'Title: Condense Volumes, Connect Dots, Enrich Contexts: Scaling Root Cause Analysis and Automated Troubleshooting with ML
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

Learn to use ML to condense volumes by 80% without data loss by grouping related records and deduping their redundant field values. Learn how to use ML to to auto-normalize records to a unified schema and enrich them with their most relevant tags and labels across objects, assets, entities, frameworks and controls. Use ML to correlate situationally relevant records, similar root causes and link causal sequences and behavior. Use AI to further troubleshoot, detect and remediate with rich-context.

\n\nSpeakerBio:  Ezz Tahoun
\n

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

\n\n

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

\n\n

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada\'s CSE.

\n\n

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

\n\n

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

\n\n

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.

\n\n\n\'',NULL,1297964),('3_Saturday','17','17:30','17:59','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'The Autonomous SOC Blueprint: On-Premise ML & AI to Condense, Consolidate, Contextualize, Correlate & Co-Investigate Attack Chains Hiding in the Noise\'','\'Ezz Tahoun\'','Creator Talks_868cdc041f1947995e70c923679f69a1','\'Title: The Autonomous SOC Blueprint: On-Premise ML & AI to Condense, Consolidate, Contextualize, Correlate & Co-Investigate Attack Chains Hiding in the Noise
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

In this talk, you’ll learn to use on-prem auditable and tunable ML models to automatically: normalize events to any data model, enrich events with relevant labels across various frameworks and controls (eg: MITRE ATT&CK, NIST, CISA KEV, CCM, VERIS, CRI), group related events to shrink their volume and reveal coordinated activity, chain causal events to expose multi step attacks, and use AI with to generate and execute detailed context-rich incident investigations and response. \nUse ML to auto-enrich events with relevant ATT&CK TTPs, NIST 800-53, VERIS, CSA CCM, CISA KEV, CRI & controls in AWS, GCP, Azure, M365 and Intel vPro\nUse ML to auto condense, correlate, contextualize & connect events to expose attack chains hiding in the noise of false positives & isolated incidents\nUse private on-premise AI models with condensed, normalized, and correlated data to execute high-fidelity agentic workflows and investigations

\n\nSpeakerBio:  Ezz Tahoun
\n

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

\n\n

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

\n\n

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada\'s CSE.

\n\n

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

\n\n

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

\n\n

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.

\n\n\n\'',NULL,1297965),('4_Sunday','12','12:00','12:30','N','Middle Easterns & Africans in Cyber Security (MEACS)','LVCCW Level 1 Hall 3 1100 (Creator Stage 7)','\'The Dark Art of Alert Correlation: Extracting Attack Chains from Chaos\'','\'Ezz Tahoun\'','Creator Talks_ccebe10ad5fca35877610d65d80d1e02','\'Title: The Dark Art of Alert Correlation: Extracting Attack Chains from Chaos
\nTags: Middle Easterns & Africans in Cyber Security (MEACS) | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - Map
\n
\nDescription:
\n

In modern cybersecurity, the ability to connect isolated security alerts into coherent, actionable attack chains is essential. However, traditional detection methods often struggle to contextualize vast amounts of security data, leaving slow and stealthy attacks undetected within a sea of noise and false positives. This talk introduces a novel approach using open-source AI models to map, cluster, and correlate security alerts in order to uncover coordinated attacks. Through clustering, knowledge graphs, and AI-driven correlation, this approach offers significant improvements in SOC (Security Operations Center) efficiency and effectiveness. We detail the methodology, open source tools, and results of this approach across diverse environments, including cloud, telecom, and industrial control systems.

\n\nSpeakerBio:  Ezz Tahoun
\n

Ezz Tahoun is an award-winning cybersecurity data scientist recognized globally for his innovations in applying AI to security operations.

\n\n

He has keynoted, trained & presented at BlackHat US, Sector, MEA, Asia & EU, DEFCON, SANS Summits, all the top Bsides, Securityweek ICS Conference and GISEC among many others.

\n\n

His groundbreaking work earned him a gold edison award and accolades from Yale, Princeton, Northwestern, NATO, Microsoft, and Canada\'s CSE.

\n\n

At 19, Ezz began his PhD in Computer Sci at the Univ of Waterloo, quickly gaining recognition through over 20 influential papers and open-source tools.

\n\n

His experience includes leading advanced AI security ops projects for Orange CyberDefense, Forescout, RBC, and Huawei US.

\n\n

He holds certifications such as GIAC Advisory Board, aCCISO, CISM, CRISC, GCIH, CEH, PMP and GCP-Cloud Architect, and served as an adjunct professor in cyber defense and warfare.

\n\n\n\'',NULL,1297966),('3_Saturday','15','15:00','16:59','N','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Locktopus Challenge Finals\'','\'\'','Contests_520899ac0871903b1b5778e2ba1e89c6','\'Title: Locktopus Challenge Finals
\nTags: Lockpick Village | Locktopus Competition | Contest
\nWhen: Saturday, Aug 8, 15:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

The biggest speed picking event in North America debuts at DEF CON 34 this year! Join us to see the top competitors from Friday and Saturday\'s qualifying brackets hash it out and be crowned champion of TOOOL\'s Locktopus Speed Picking Challenge!

\n\n\'',NULL,1297967),('3_Saturday','16','15:00','16:59','Y','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Locktopus Challenge Finals\'','\'\'','Contests_520899ac0871903b1b5778e2ba1e89c6','\'\'',NULL,1297968),('3_Saturday','12','12:00','14:59','N','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Dozier Drill Tournament\'','\'\'','Contests_be4edeed97cbe95609425c27a208b23b','\'Title: Dozier Drill Tournament
\nTags: Lockpick Village | Dozier Drill Lockpicking Challenge | Contest
\nWhen: Saturday, Aug 8, 12:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

Have you ever wanted to break out of handcuffs, pick open a closed bag and shoot your buddy in the chest with a nerf gun? So have we, that\'s why TOOOL presents the Dozer Drill. A fast paced skill based game where you have to free yourself from handcuffs, open a closed bag, and retrieve the nerf gun to be the first to hit the target. Join us on Friday for qualifiers, through the con for unofficial games, and on Saturday for an official bracket tournament.

\n\n\'',NULL,1297969),('3_Saturday','13','12:00','14:59','Y','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Dozier Drill Tournament\'','\'\'','Contests_be4edeed97cbe95609425c27a208b23b','\'\'',NULL,1297970),('3_Saturday','14','12:00','14:59','Y','Contests','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Dozier Drill Tournament\'','\'\'','Contests_be4edeed97cbe95609425c27a208b23b','\'\'',NULL,1297971),('3_Saturday','10','10:15','10:45','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Intro to Lockpicking\'','\'\'','Creator Events_1e3be6a6890b35a42920eefcf452e6af','\'Title: Intro to Lockpicking
\nTags: Lockpick Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:15 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

New to lock picking? Haven\'t picked in a year and need a refresher? Don\'t know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.

\n\n\'',NULL,1297972),('2_Friday','10','10:15','10:45','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Intro to Lockpicking\'','\'\'','Creator Events_cf47773301eed538ba501a031b65a556','\'Title: Intro to Lockpicking
\nTags: Lockpick Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:15 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

New to lock picking? Haven\'t picked in a year and need a refresher? Don\'t know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.

\n\n\'',NULL,1297973),('2_Friday','13','13:00','13:30','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Intro to Lockpicking\'','\'\'','Creator Events_a817551c8e3ce7431a40e03f900da67c','\'Title: Intro to Lockpicking
\nTags: Lockpick Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

New to lock picking? Haven\'t picked in a year and need a refresher? Don\'t know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.

\n\n\'',NULL,1297974),('3_Saturday','15','15:00','15:30','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Intro to Lockpicking\'','\'\'','Creator Events_c6e58e443f4467a9bc97f58ba49adeb4','\'Title: Intro to Lockpicking
\nTags: Lockpick Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 15:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

New to lock picking? Haven\'t picked in a year and need a refresher? Don\'t know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.

\n\n\'',NULL,1297975),('4_Sunday','10','10:15','10:45','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Intro to Lockpicking\'','\'\'','Creator Events_eb594758098ba1f809a6a45342521974','\'Title: Intro to Lockpicking
\nTags: Lockpick Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:15 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

New to lock picking? Haven\'t picked in a year and need a refresher? Don\'t know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.

\n\n\'',NULL,1297976),('2_Friday','16','16:00','16:30','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Intro to Lockpicking\'','\'\'','Creator Events_40bafe99109a2498cbe14d347870b315','\'Title: Intro to Lockpicking
\nTags: Lockpick Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 16:00 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

New to lock picking? Haven\'t picked in a year and need a refresher? Don\'t know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.

\n\n\'',NULL,1297977),('4_Sunday','13','13:00','13:30','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Intro to Lockpicking\'','\'\'','Creator Events_c5e9f72b7fc4bb8ea5f7ad180cfdd37e','\'Title: Intro to Lockpicking
\nTags: Lockpick Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 13:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

New to lock picking? Haven\'t picked in a year and need a refresher? Don\'t know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.

\n\n\'',NULL,1297978),('2_Friday','14','14:30','14:59','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Intro to Lockpicking\'','\'\'','Creator Events_9f251fb4824515490697c01cd58e1e04','\'Title: Intro to Lockpicking
\nTags: Lockpick Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 14:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

New to lock picking? Haven\'t picked in a year and need a refresher? Don\'t know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.

\n\n\'',NULL,1297979),('2_Friday','11','11:00','11:59','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Building an open soure safecracking robot\'','\'Jared Dygert\'','Creator Talks_f6f82c328a710a13bd3894f0beb900c5','\'Title: Building an open soure safecracking robot
\nTags: Lockpick Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

An auto dialer is a device that brute forces the combination to a safe lock. These often start in the thousands of dollars when it\'s only a motor that spins. This talk will cover how safe locks work, what goes into building one of these devices, and all the resources (including the source code) for making your own for cheap.

\n\nSpeakerBio:  Jared Dygert
\nNo BIO available
\n\n\'',NULL,1297980),('3_Saturday','11','11:00','11:30','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'Classic US High Sec: how to pick a Medeco\'','\'Max A\'','Creator Talks_1746a7960ea7558e73a96623c6279a8e','\'Title: Classic US High Sec: how to pick a Medeco
\nTags: Lockpick Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

With pins that both slide up and down and rotate, Medeco locks have been one of the most common high security locks in the US for over 50 years. Come learn exactly how they work, and how to open them with standard picks.

\n\nSpeakerBio:  Max A
\nNo BIO available
\n\n\'',NULL,1297981),('4_Sunday','11','11:00','11:45','N','Lockpick Village','LVCCW Level 1 Hall 1 407 (Lockpick Village)','\'The Knox Box - A Brief History(Part II)\'','\'Matthew O\'Reilly\'','Creator Talks_b14fd3bd429f6193d31de945371ac71d','\'Title: The Knox Box - A Brief History(Part II)
\nTags: Lockpick Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 1 407 (Lockpick Village) - Map
\n
\nDescription:
\n

An enhanced version of the DC33 talk, with more information

\n\nSpeakerBio:  Matthew O\'Reilly
\nNo BIO available
\n\n\'',NULL,1297982),('3_Saturday','12','12:00','12:59','N','Hackers.town','LVCCW Level 1 Hall 4 1420 (Hackers.town)','\'Take Back Your Memories\'','\'Patrick Sliney\'','Creator Talks_ff132e43a2b6e5ba21a2fd2e8a3472b6','\'Title: Take Back Your Memories
\nTags: Hackers.town | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1420 (Hackers.town) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Patrick Sliney, Tech Reclaimers
\nNo BIO available
\n\n\'',NULL,1297983),('2_Friday','17','17:00','17:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village Open Forum: Talks & Workshops: Review, Highlights, and Key Learnings\'','\'\'','Creator Events_90963fe775c27b3e1ae9b034ddfccf6a','\'Title: Telecom Village Open Forum: Talks & Workshops: Review, Highlights, and Key Learnings
\nTags: Telecom Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1297984),('3_Saturday','17','17:00','17:59','N','Telecom Village','LVCCW Level 3 W321 (Telecom Village)','\'Telecom Village Open Forum: Talks & Workshops: Review, Highlights, and Key Learnings\'','\'\'','Creator Events_2659c250c0c7990b6efa21a6e286915b','\'Title: Telecom Village Open Forum: Talks & Workshops: Review, Highlights, and Key Learnings
\nTags: Telecom Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 3 W321 (Telecom Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1297985),('2_Friday','10','10:00','10:59','N','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'Coloring Reset\'','\'\'','Creator Events_1131154e1dde684782beb93ca6acf17f','\'Title: Coloring Reset
\nTags: Women in Security and Privacy (WISP) | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map
\n
\nDescription:
\n

Kick off your DEF CON morning with a creative reset. Color with WISP! Choose from different coloring pages and bring them to life with markers, crayons, and your own flair. Whether you\'re decompressing or collaborating on a shared poster, it\'s the perfect low-pressure space to connect, reflect, and color outside the lines.

\n\n\'',NULL,1297986),('2_Friday','12','12:00','12:59','N','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'Friendship Bracelets\'','\'\'','Creator Events_762dc7efc5e259d23d07e25bbc57679a','\'Title: Friendship Bracelets
\nTags: Women in Security and Privacy (WISP) | Creator Event/Activity
\nWhen: Friday, Aug 7, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map
\n
\nDescription:
\n

Create a custom bracelet to wear or trade, each featuring a special bead with a hidden message or symbol of empowerment. This tactile, low-key activity is perfect for starting conversations and forming connections across the community. No crafting experience needed, just good vibes and open hands. Join us during this hour for a WISP bead to add to your bracelet (while supplies last)!

\n\n\'',NULL,1297987),('2_Friday','15','15:30','16:30','N','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'tAIrot Readings\'','\'\'','Creator Events_fc2bf55ac6db26a180d82ceef1ad84a3','\'Title: tAIrot Readings
\nTags: Women in Security and Privacy (WISP) | Creator Event/Activity
\nWhen: Friday, Aug 7, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map
\n
\nDescription:
\n

Curious about what the cards have in store for you? For a suggested donation, WISP Board Chair Alyssa Coley give you an AI-assisted tarot reading! Drop by for a fresh perspective on your burning questions, blending ancient symbolism with modern tech to offer personalized, reflective insights for your journey.

\n\n\'',NULL,1297988),('2_Friday','16','15:30','16:30','Y','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'tAIrot Readings\'','\'\'','Creator Events_fc2bf55ac6db26a180d82ceef1ad84a3','\'\'',NULL,1297989),('3_Saturday','10','10:00','10:59','N','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'Coloring Reset\'','\'\'','Creator Events_5135842de753ef5258c65fa4e8bc55b5','\'Title: Coloring Reset
\nTags: Women in Security and Privacy (WISP) | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map
\n
\nDescription:
\n

Kick off your DEF CON morning with a creative reset. Color with WISP! Choose from different coloring pages and bring them to life with markers, crayons, and your own flair. Whether you\'re decompressing or collaborating on a shared poster, it\'s the perfect low-pressure space to connect, reflect, and color outside the lines.

\n\n\'',NULL,1297990),('3_Saturday','12','12:00','12:59','N','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'Friendship Bracelets\'','\'\'','Creator Events_353d28c4ca23fcd736f5f1dd7fe24f3c','\'Title: Friendship Bracelets
\nTags: Women in Security and Privacy (WISP) | Creator Event/Activity
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map
\n
\nDescription:
\n

Create a custom bracelet to wear or trade, each featuring a special bead with a hidden message or symbol of empowerment. This tactile, low-key activity is perfect for starting conversations and forming connections across the community. No crafting experience needed, just good vibes and open hands. Join us during this hour for a WISP bead to add to your bracelet (while supplies last)!

\n\n\'',NULL,1297991),('3_Saturday','15','15:30','16:30','N','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'Privacy\'s Defender with Women in Security and Privacy (WISP)\'','\'Cindy Cohn,Alyssa Coley\'','Creator Talks_aa3a46e3fd2a506a480df7385ae5bd69','\'Title: Privacy\'s Defender with Women in Security and Privacy (WISP)
\nTags: Women in Security and Privacy (WISP) | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map
\n
\nDescription:
\n

Join WISP and EFF for a conversation featuring WISP Board Chair Alyssa Coley and former EFF Executive Director Cindy Cohn in discussion about Cindy\'s book: Privacy\'s Defender: My Thirty-Year Fight Against Digital Surveillance.

\n\n

Cindy has spent three decades tangling with the feds, fighting for data security, and arguing in court to protect our access to science and knowledge on the internet. This is a rare chance to hear her story up close.

\n\nSpeakers:Cindy Cohn,Alyssa Coley
\n
\nSpeakerBio:  Cindy Cohn, Executive Director at Electronic Frontier Foundation
\n

Cindy Cohn is the Executive Director of the Electronic Frontier Foundation. From 2000-2015 she served as EFF’s Legal Director as well as its General Counsel. Ms. Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. Ms. Cohn is the author of the professional memoir, called Privacy\'s Defender published by MIT Press in March, 2026. She is also the co-host of EFF\'s award-winning podcast, How to Fix the Internet.

\n\n

--

\n\n

Cohn first became involved with EFF in 1993, when EFF asked her to serve as the outside lead attorney in Bernstein v. Dept. of Justice, the successful First Amendment challenge to the U.S. export restrictions on cryptography. She served as EFF’s Legal Director as well as its General Counsel from 2000 through 2015, and she has served as Executive Director since then. She also has co-hosted EFF’s award-winning “How to Fix the Internet” podcast, which recently concluded its sixth season. Her professional memoir covering her time at EFF, Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance, was published earlier this year by MIT Press.

\n\nSpeakerBio:  Alyssa Coley, Privacy & Product Counsel at Scopely
\n

Alyssa is on the Board of Women In Security and Privacy (WISP) and is Privacy & Product Counsel at Scopely. As in-house counsel, she focuses on integrating privacy by design into product development and ensuring global privacy compliance. Previously, she gained experience in privacy consulting and cybersecurity incident response. She has been involved with WISP for nearly a decade where she developed her interest in locksport and continues to further WISP\'s mission to advance women and underrepresented communities to lead the future of security and privacy.

\n\n\n\'',NULL,1297992),('3_Saturday','16','15:30','16:30','Y','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'Privacy\'s Defender with Women in Security and Privacy (WISP)\'','\'Cindy Cohn,Alyssa Coley\'','Creator Talks_aa3a46e3fd2a506a480df7385ae5bd69','\'\'',NULL,1297993),('4_Sunday','10','10:00','10:59','N','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'Coloring Reset\'','\'\'','Creator Events_22e259e37a4d018c75059aca3ae0aadd','\'Title: Coloring Reset
\nTags: Women in Security and Privacy (WISP) | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map
\n
\nDescription:
\n

Kick off your DEF CON morning with a creative reset. Color with WISP! Choose from different coloring pages and bring them to life with markers, crayons, and your own flair. Whether you\'re decompressing or collaborating on a shared poster, it\'s the perfect low-pressure space to connect, reflect, and color outside the lines.

\n\n\'',NULL,1297994),('4_Sunday','12','12:00','12:59','N','Misc','LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)','\'Friendship Bracelets\'','\'\'','Creator Events_9e297ddd167fc737cd1678716e463ee6','\'Title: Friendship Bracelets
\nTags: Women in Security and Privacy (WISP) | Creator Event/Activity
\nWhen: Sunday, Aug 9, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community) - Map
\n
\nDescription:
\n

Create a custom bracelet to wear or trade, each featuring a special bead with a hidden message or symbol of empowerment. This tactile, low-key activity is perfect for starting conversations and forming connections across the community. No crafting experience needed, just good vibes and open hands. Join us during this hour for a WISP bead to add to your bracelet (while supplies last)!

\n\n\'',NULL,1297995),('2_Friday','14','14:00','17:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Competition\'','\'\'','Creator Events_30407a619a4553e67a88f5cb3a158556','\'Title: Robotic Hacking Community CTF Competition
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\nThe Robotic Hacking CTF competition runs continuously from Friday at 14: 00 through Saturday at 18:00.
\n\n\n\n\'',NULL,1297996),('2_Friday','15','14:00','17:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Competition\'','\'\'','Creator Events_30407a619a4553e67a88f5cb3a158556','\'\'',NULL,1297997),('2_Friday','16','14:00','17:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Competition\'','\'\'','Creator Events_30407a619a4553e67a88f5cb3a158556','\'\'',NULL,1297998),('2_Friday','17','14:00','17:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Competition\'','\'\'','Creator Events_30407a619a4553e67a88f5cb3a158556','\'\'',NULL,1297999),('3_Saturday','14','14:00','17:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Competition\'','\'\'','Creator Events_f80862d8d1f25009491e3c826589698f','\'Title: Robotic Hacking Community CTF Competition
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 14:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\nThe Robotic Hacking CTF competition runs continuously from Friday at 14: 00 through Saturday at 18:00.
\n\n\n\n\'',NULL,1298000),('3_Saturday','15','14:00','17:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Competition\'','\'\'','Creator Events_f80862d8d1f25009491e3c826589698f','\'\'',NULL,1298001),('3_Saturday','16','14:00','17:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Competition\'','\'\'','Creator Events_f80862d8d1f25009491e3c826589698f','\'\'',NULL,1298002),('3_Saturday','17','14:00','17:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Competition\'','\'\'','Creator Events_f80862d8d1f25009491e3c826589698f','\'\'',NULL,1298003),('4_Sunday','10','10:00','10:30','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robot Cheerleaders\'','\'\'','Creator Events_c3d5b3349f83246e383027abdc75f212','\'Title: Robot Cheerleaders
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Robot cheerleader activation.

\n\n\'',NULL,1298004),('2_Friday','12','12:30','12:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robot Cheerleaders\'','\'\'','Creator Events_3db0f07017f7613f7cb640d1fe78ab1b','\'Title: Robot Cheerleaders
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Robot cheerleader activation.

\n\n\'',NULL,1298005),('3_Saturday','10','10:00','10:30','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robot Cheerleaders\'','\'\'','Creator Events_09b9ebd5788dc37e0379245bf687afe1','\'Title: Robot Cheerleaders
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Robot cheerleader activation.

\n\n\'',NULL,1298006),('3_Saturday','12','12:30','12:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robot Cheerleaders\'','\'\'','Creator Events_4a52705f96771925b073f7e2ec7576e3','\'Title: Robot Cheerleaders
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 12:30 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Robot cheerleader activation.

\n\n\'',NULL,1298007),('2_Friday','11','11:30','12:30','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Workshop\'','\'\'','Creator Events_9fa8edefe696625e2f93a6fc497fa529','\'Title: Robotic Hacking Community - Workshop
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Open workshop session in the Robotic Hacking Community.

\n\n\'',NULL,1298008),('2_Friday','12','11:30','12:30','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Workshop\'','\'\'','Creator Events_9fa8edefe696625e2f93a6fc497fa529','\'\'',NULL,1298009),('3_Saturday','16','16:00','17:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Workshop\'','\'\'','Creator Events_c1a032dbb730582a58b3c4b4dcc0392d','\'Title: Robotic Hacking Community - Workshop
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Open workshop session in the Robotic Hacking Community.

\n\n\'',NULL,1298010),('3_Saturday','17','16:00','17:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Workshop\'','\'\'','Creator Events_c1a032dbb730582a58b3c4b4dcc0392d','\'\'',NULL,1298011),('2_Friday','16','16:15','17:15','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Workshop\'','\'\'','Creator Events_8cf2da32955812b30d9381b09c0eda68','\'Title: Robotic Hacking Community - Workshop
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 16:15 - 17:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Open workshop session in the Robotic Hacking Community.

\n\n\'',NULL,1298012),('2_Friday','17','16:15','17:15','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Workshop\'','\'\'','Creator Events_8cf2da32955812b30d9381b09c0eda68','\'\'',NULL,1298013),('3_Saturday','10','10:30','12:30','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Workshop\'','\'\'','Creator Events_4072450bd5e482ef7d5d504c2b78d0de','\'Title: Robotic Hacking Community - Workshop
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Open workshop session in the Robotic Hacking Community.

\n\n\'',NULL,1298014),('3_Saturday','11','10:30','12:30','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Workshop\'','\'\'','Creator Events_4072450bd5e482ef7d5d504c2b78d0de','\'\'',NULL,1298015),('3_Saturday','12','10:30','12:30','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Workshop\'','\'\'','Creator Events_4072450bd5e482ef7d5d504c2b78d0de','\'\'',NULL,1298016),('2_Friday','10','10:00','10:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robot Cheerleader + DEF CON Tour\'','\'\'','Creator Events_8ff54cdf5fd6ae3bb78247116467a7bc','\'Title: Robot Cheerleader + DEF CON Tour
\nTags: Robotic Hacking Community | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Robot cheerleader activation and a guided DEF CON tour of the community space.

\n\n\'',NULL,1298017),('2_Friday','11','11:00','11:30','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community - Opening Program\'','\'Max Cheng\'','Creator Talks_e580979b3ae9517c60b1cdef1a428dec','\'Title: Robotic Hacking Community - Opening Program
\nTags: Robotic Hacking Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Opening program with a welcome message from Max Cheng, VicOne Lab R7 CEO.

\n\nSpeakerBio:  Max Cheng, CEO at VicOne Lab R7
\nNo BIO available
\n\n\'',NULL,1298018),('2_Friday','13','13:00','13:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Workshop & Sumo Robot Competition\'','\'\'','Creator Workshops_975e6a6e88ce85582fb0c4bca24f71b6','\'Title: Workshop & Sumo Robot Competition
\nTags: Robotic Hacking Community | Creator Workshop
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Open workshop running alongside a sumo robot competition.

\n\n\'',NULL,1298019),('2_Friday','14','14:00','14:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Fireside Chat\'','\'\'','Creator Talks_fc9d2961e9ff0125200c6ca4198f67f4','\'Title: Fireside Chat
\nTags: Robotic Hacking Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

A fireside chat with the Robotic Hacking Community.

\n\n\'',NULL,1298020),('2_Friday','15','15:30','16:15','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'SpoofBuster: GPS Spoofing Detection via Hierarchical LTE Identity Analysis\'','\'Moshe “Mo” Satt\'','Creator Talks_cc218f8154b1a0edb10571e51a510c22','\'Title: SpoofBuster: GPS Spoofing Detection via Hierarchical LTE Identity Analysis
\nTags: Robotic Hacking Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 16:15 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

SpoofBuster is a hierarchical GPS spoofing detection algorithm combining three LTE cellular identifiers (eNodeB coverage, uplink band, and cell identifier) without device access, software on the target, or network cooperation. Evaluated on 982 LTE observations across three carriers in a U.S. urban test area, it reaches 69.5% detection at 200 m, rising to 93.5% at 500 m, with a conducted HackRF experiment and a $175 two-truck pilot demonstrating a 20-minute installation path.

\n\nSpeakerBio:  Moshe “Mo” Satt, Founder & CEO at Mobile Defender Inc.
\n

Moshe (Mo) Satt is a cybersecurity leader, researcher, entrepreneur, inventor, and educator serving the public sector for over 25 years. He is the Chief Information Security Officer (CISO) at the New York City Department of Sanitation (DSNY), protecting the largest municipal sanitation agency in the world, and is the founder and CEO of Mobile Defender Inc., inventor of affordable, portable, scalable solutions that protect vehicles from hidden GPS trackers and GPS spoofing. He is a PhD candidate in Computer Science at the NYU Center for Cybersecurity and NYU Tandon School of Engineering and a graduate adjunct at NYU Tandon. He holds C|CISO, CISSP, and CISM certifications and is a member of the SANS CISO Network.

\n\n\n\'',NULL,1298021),('2_Friday','16','15:30','16:15','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'SpoofBuster: GPS Spoofing Detection via Hierarchical LTE Identity Analysis\'','\'Moshe “Mo” Satt\'','Creator Talks_cc218f8154b1a0edb10571e51a510c22','\'\'',NULL,1298022),('3_Saturday','13','13:00','15:30','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Workshop & Tengu Marauders: Hack My Bot\'','\'L3xiC0n\'','Creator Workshops_a3cc3d309d6195856c74f96977876834','\'Title: Workshop & Tengu Marauders: Hack My Bot
\nTags: Robotic Hacking Community | Creator Workshop
\nWhen: Saturday, Aug 8, 13:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Hack My Bot is a full-scale lab where participants use the Tengu Marauder units to attack commercially available robots (robot dogs, hexapods, Wi-Fi mini drones) plus a virtualized IoT range for bypassing doors and barriers. Units run an ESP32 Marauder (some with the C5 chip for 5GHz/WPA3). BYOD: anyone with a Wi-Fi- or switch-capable device can access a unit. Winners receive a custom Cyclone SAO badge.

\n\nSpeakerBio:  L3xiC0n, Ex Machina Parlor (DC215)
\n

Lexie (L3xiC0n) has worked in cybersecurity for ten years, with a strong affinity for electrical engineering, programming, and robotics engineering. She has extensive hands-on experience from eight years in the U.S. Air Force, specializing in cybersecurity and tactical networks for aircraft missions and operations. She focuses on securing and testing autonomous systems and runs a local hackerspace in Philadelphia in support of DC215 called the Ex Machina Parlor.

\n\n\nLinks:
    Github - https://github.com/ExMachinaParlor/HackMyBot | https://github.com/ExMachinaParlor/Tengu-Marauder | https://github.com/ExMachinaParlor/Tengu-Marauder-Vanguard | https://github.com/ExMachinaParlor/Tengu-Marauder-Stryker | https://github.com/ExMachinaParlor/EMP-SAO-Cyclone-Badge
\n\'',NULL,1298023),('3_Saturday','14','13:00','15:30','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Workshop & Tengu Marauders: Hack My Bot\'','\'L3xiC0n\'','Creator Workshops_a3cc3d309d6195856c74f96977876834','\'\'',NULL,1298024),('3_Saturday','15','13:00','15:30','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Workshop & Tengu Marauders: Hack My Bot\'','\'L3xiC0n\'','Creator Workshops_a3cc3d309d6195856c74f96977876834','\'\'',NULL,1298025),('3_Saturday','15','15:30','15:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robot Sumo Competition\'','\'\'','Creator Talks_6b313bd02b9c0f6d40077c77d690209e','\'Title: Robot Sumo Competition
\nTags: Robotic Hacking Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:30 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

Robot sumo competition in the community space.

\n\n\'',NULL,1298026),('4_Sunday','10','10:30','13:59','N','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Awards, Community Celebration & Closing Remarks\'','\'\'','Creator Talks_333e2ff0bea4173a8899b5495eb90ca6','\'Title: Robotic Hacking Community CTF Awards, Community Celebration & Closing Remarks
\nTags: Robotic Hacking Community | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 10:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community) - Map
\n
\nDescription:
\n

CTF awards, community celebration, and closing remarks to conclude the Robotic Hacking Community at DEF CON 34.

\n\n\'',NULL,1298027),('4_Sunday','11','10:30','13:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Awards, Community Celebration & Closing Remarks\'','\'\'','Creator Talks_333e2ff0bea4173a8899b5495eb90ca6','\'\'',NULL,1298028),('4_Sunday','12','10:30','13:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Awards, Community Celebration & Closing Remarks\'','\'\'','Creator Talks_333e2ff0bea4173a8899b5495eb90ca6','\'\'',NULL,1298029),('4_Sunday','13','10:30','13:59','Y','Robotic Hacking Community','LVCCW Level 1 Hall 4 1309 (Robotic Hacking Community)','\'Robotic Hacking Community CTF Awards, Community Celebration & Closing Remarks\'','\'\'','Creator Talks_333e2ff0bea4173a8899b5495eb90ca6','\'\'',NULL,1298030),('2_Friday','10','10:00','16:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_40135be7f7a510b0809af27a5021cddc','\'Title: Cryptocurrency CTF
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

In Draining Sin City Jackpots, players read systems, chain findings, and submit flags for a live scoreboard, with challenge names kept secret until the event opens.

\n\n

Prizes include a variety of coin branded items as well as the Cryptocurrency CTF Black Ribbon first prize winner: A $2K Hak5 gift certificate.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298031),('2_Friday','11','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_40135be7f7a510b0809af27a5021cddc','\'\'',NULL,1298032),('2_Friday','12','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_40135be7f7a510b0809af27a5021cddc','\'\'',NULL,1298033),('2_Friday','13','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_40135be7f7a510b0809af27a5021cddc','\'\'',NULL,1298034),('2_Friday','14','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_40135be7f7a510b0809af27a5021cddc','\'\'',NULL,1298035),('2_Friday','15','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_40135be7f7a510b0809af27a5021cddc','\'\'',NULL,1298036),('2_Friday','16','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_40135be7f7a510b0809af27a5021cddc','\'\'',NULL,1298037),('2_Friday','10','10:00','16:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a630fe59976b8605985d3682f6a35549','\'Title: Cryptocurrency Contest
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

This is a free, six-level skills ladder from answering offensive security trivia questions through creating wallets, hacking badges, and tracing then deanonymizing on-chain transactions to recover illicit blocks and stolen funds. This time our contest includes puzzles contributed by NewAE Technology as well as collaborations with our Hac-Man contest friends, isn’t that absolutely bodacious?

\n\n

A wide range of low to high value prizes are awarded in the usual Cryptocurrency Village and Challenge ways:

\n\n

Giveaway base level 0: Branded bag with workbook, USB media, casino deck

\n\n

Award prize level 1: Electronic badge (free edition) and author signed book

\n\n

Award prize level 2: Simple addon, SE collection or one BTC, XMR, ETH, SOL

\n\n

Award prize level 3: High value collector coin of BTC, XMR, ETH, SOL

\n\n

Award prize level 4: BTC, XMR, ETH, SOL tee shirt or XMR messenger bag

\n\n

Award prize level 5: Electronic badge pluspack (upgrade the free edition)

\n\n

Award prize level 6: Vacuum steel thermos bottle of BTC, XMR, ETH, SOL

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298038),('2_Friday','11','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a630fe59976b8605985d3682f6a35549','\'\'',NULL,1298039),('2_Friday','12','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a630fe59976b8605985d3682f6a35549','\'\'',NULL,1298040),('2_Friday','13','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a630fe59976b8605985d3682f6a35549','\'\'',NULL,1298041),('2_Friday','14','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a630fe59976b8605985d3682f6a35549','\'\'',NULL,1298042),('2_Friday','15','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a630fe59976b8605985d3682f6a35549','\'\'',NULL,1298043),('2_Friday','16','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a630fe59976b8605985d3682f6a35549','\'\'',NULL,1298044),('2_Friday','10','10:00','16:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_a56b7fbbbb213704d5b4237e98fce46d','\'Title: Cryptocurrency Hackathon
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\nA free build competition judged across four themes: Privacy Hide, Sovereignty Survive, Exploitation Break, and Escape Evade, spanning classes like Application, Hardware, Firmware, Software, Science, and Analysis.
\n\n

Register your team on-site and find out if you qualify to build your own node using a Dell Optiplex computer that you use for the duration and take home for further hacking.

\n\n

Fabulous prizes include coin branded merchandise as well as gift certificates. The Cryptocurrency Hackathon Black Ribbon first prize winner: K Hak5 gift certificate, and the Cryptocurrency Hackathon Green Ribbon second prize winner: K Hak5 gift certificate

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298045),('2_Friday','11','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_a56b7fbbbb213704d5b4237e98fce46d','\'\'',NULL,1298046),('2_Friday','12','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_a56b7fbbbb213704d5b4237e98fce46d','\'\'',NULL,1298047),('2_Friday','13','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_a56b7fbbbb213704d5b4237e98fce46d','\'\'',NULL,1298048),('2_Friday','14','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_a56b7fbbbb213704d5b4237e98fce46d','\'\'',NULL,1298049),('2_Friday','15','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_a56b7fbbbb213704d5b4237e98fce46d','\'\'',NULL,1298050),('2_Friday','16','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_a56b7fbbbb213704d5b4237e98fce46d','\'\'',NULL,1298051),('2_Friday','10','10:00','16:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_36c80f8b3f541ac65b6288f53053d88c','\'Title: Cryptocurrency Meet-a-mentor
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Got a cryptocurrency question you\'ve been sitting on? Bring it to Meet-a-Mentor. Cryptocurrency Village staff and crew are on hand throughout the village to answer anything. From ‚what actually is a private key’ to your deepest protocol-level rabbit hole, we help with real expertise and zero judgment. No question is too basic, too advanced, or too weird; our mentors have heard it all, and they\'ll give you a straight answer with a healthy dose of humour along the way. Just don‘t expect to get any investing advice, that’s forbidden and dumb. Come with curiosity, leave with clarity.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298052),('2_Friday','11','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_36c80f8b3f541ac65b6288f53053d88c','\'\'',NULL,1298053),('2_Friday','12','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_36c80f8b3f541ac65b6288f53053d88c','\'\'',NULL,1298054),('2_Friday','13','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_36c80f8b3f541ac65b6288f53053d88c','\'\'',NULL,1298055),('2_Friday','14','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_36c80f8b3f541ac65b6288f53053d88c','\'\'',NULL,1298056),('2_Friday','15','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_36c80f8b3f541ac65b6288f53053d88c','\'\'',NULL,1298057),('2_Friday','16','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_36c80f8b3f541ac65b6288f53053d88c','\'\'',NULL,1298058),('2_Friday','10','10:00','11:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Hacking smart contracts\'','\'\'','Creator Workshops_d79763eb378433b4addcccdb66266556','\'Title: Hacking smart contracts
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

This spontaneous meeting of smart contract enthusiasts gives a practical, no-setup introduction to smart contracts: how to read them, deploy them, and understand where they go wrong. Self guided working at your own pace, consider testing Remix, a browser-based Solidity IDE, to write and deploy a simple smart contract from scratch, then use OpenZeppelin\'s audited contract templates to see what production-grade code actually looks like.

\n\n

Once familiar with the process, shift to navigation: learn to pull up and read real, deployed contracts on Etherscan, understanding what a contract\'s public functions reveal about its behavior and risk. No prior Solidity or blockchain development experience is required, however we lost the workshop instructors due to b rilliant consular visa failures so the two hour workshop becomes a do it yoursel f exploration with infrequent visits from village staff to assist where possible . Have fun learning to hack smart contracts and good luck!

\n\n\'',NULL,1298059),('2_Friday','11','10:00','11:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Hacking smart contracts\'','\'\'','Creator Workshops_d79763eb378433b4addcccdb66266556','\'\'',NULL,1298060),('2_Friday','10','10:00','16:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_cb866bbdb83459ff388d417e87d708f3','\'Title: OpenLASIR Olympics
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Join the Cryptocurrency Village for the OpenLASIR Olympics, where you can take advantage of the OpenLASIR IR protocol used to power laser tag badge devices (like the Laser* Tag Badge, Cryptohack Badge, and the official DEF CON Singapore 1 Badge); meet people to befriend & ZAPP; and win! We will have a practice target set up for you to test your aim, and a loaner badge or two to play with if you don’t have your own OpenLASIR device. While you are here, check out the Hardware Zoo to see other cool electronics tools, gadgets, and gizmos.

\n\n

Winners take home a brand new Cryptohack Electronic Badge, with application pari ty to the official DEF CON Singapore One Badge.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298061),('2_Friday','11','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_cb866bbdb83459ff388d417e87d708f3','\'\'',NULL,1298062),('2_Friday','12','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_cb866bbdb83459ff388d417e87d708f3','\'\'',NULL,1298063),('2_Friday','13','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_cb866bbdb83459ff388d417e87d708f3','\'\'',NULL,1298064),('2_Friday','14','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_cb866bbdb83459ff388d417e87d708f3','\'\'',NULL,1298065),('2_Friday','15','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_cb866bbdb83459ff388d417e87d708f3','\'\'',NULL,1298066),('2_Friday','16','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_cb866bbdb83459ff388d417e87d708f3','\'\'',NULL,1298067),('2_Friday','12','12:00','13:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Chains, Nodes, Faucets, Explorers, and Intelligence\'','\'Izdihar,Sadiq \"Sdqmd\"\'','Creator Workshops_47643df123748ec9ddd9ae89329b6241','\'Title: Chains, Nodes, Faucets, Explorers, and Intelligence
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Friday, Aug 7, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

This hands-on workshop explores how cryptocurrency network services can inform and strengthen security decision-making. Participants will move from foundational concepts through to practical intelligence gathering, learning how blockchain infrastructure works under the hood and how to leverage publicly available network services for security research.

\n\n

Starting with core terminology and the distinction between testnets and mainnets, the session covers full nodes and pruning, blockchain exploration techniques, and the design of a testnet faucet. The latter half focuses on automated intelligence gathering before participants apply what they\'ve learned through self-paced practice with real tools.

\n\n

Curriculum: - 00:00 - Introduction and terms - 00:15 - Blockchains, testnets, mainnets - 00:30 - Full nodes and pruning - 00:45 - Exploring blockchains - 01:00 - Design of a testnet faucet - 01:15 - Automated intelligence gathering - 01:30 - Self-paced practice using tools - 02:00 - End of workshop

\n\n

By the end, participants will understand how to navigate cryptocurrency network services and apply them toward sound security decisions.

\n\nSpeakers:Izdihar,Sadiq \"Sdqmd\"
\n
\nSpeakerBio:  Izdihar, Swarmnetics / cyber673 / Brunei Cyber Security Association
\n

Izdihar is a cybersecurity practitioner who works in penetration testing and tinkers with a homelab in his spare time, where he has been experimenting with running blockchain testnet nodes. His interest in cryptocurrency is mostly about understanding how the infrastructure works. He helps run cyber673, a small grassroots community in Brunei.

\n\nSpeakerBio:  Sadiq \"Sdqmd\", CodeBit
\n

sdqmd (Sadiq) is a hardware hacker and co-founder of CodeBit, a technology company based in Brunei that\'s building a hardware engineering academy to teach embedded systems and security from the ground up. He is focused on developing a pedagogy that blends theory with hands-on practice, so aspiring hackers — especially those just starting out — don\'t just learn how something works; they build it, break it, and understand it for themselves. His own research focuses on hardware attacks against embedded devices — using fault injection and power analysis to defeat the security of everything from crypto hardware wallets to point-of-sale infrastructure. Above all, he\'s driven by one goal: building hardware and security competency in Brunei, where hands-on learning is still hard to come by.

\n\n\n\'',NULL,1298068),('2_Friday','13','12:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Chains, Nodes, Faucets, Explorers, and Intelligence\'','\'Izdihar,Sadiq \"Sdqmd\"\'','Creator Workshops_47643df123748ec9ddd9ae89329b6241','\'\'',NULL,1298069),('2_Friday','14','14:00','15:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptohack Badge Application Design\'','\'Do Truong Giang\'','Creator Workshops_2c7c99c87dda94d91f79b411fea7d498','\'Title: Cryptohack Badge Application Design
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Friday, Aug 7, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Ever wondered what\'s running on that blinking badge around your neck? In this hands-on workshop, we go from sealed box to running firmware on a custom ESP32-based Cryptohack badge. Starting with an unboxing and a tour of the hardware, we\'ll set up the full ESP-IDF toolchain together and walk through the application logic that drives the badge — from the high-level block diagram down to the source.

\n\n

You\'ll compile your own firmware, flash it to the device, and then flip perspectives: we\'ll disassemble the binary and explore the hacks, hidden behaviors, and attack surface that make badge-hacking such a rite of passage. We close with a showcase where participants demo what they built or broke, plus open Q&A.

\n\n

By the end, you\'ll understand the complete path from hardware bring-up to firmware to reverse engineering on a real embedded device. Bring a laptop; all hardware and tooling will be covered in the session.

\n\n

Reverse-engineer the CryptoHack badge hardware, then program every peripheral — LEDs, buttons, display, NFC, IR, EEPROM, WiFi, and BLE — using ESP-IDF and C. Bring a laptop, leave with a custom badge dashboard and real embedded hacking skills. A free of charge Cryptohack Badge is available for each participating student to use and take home for further exploration, you’re welcome!

\n\nSpeakerBio:  Do Truong Giang
\nNo BIO available
\n\n\'',NULL,1298070),('2_Friday','15','14:00','15:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptohack Badge Application Design\'','\'Do Truong Giang\'','Creator Workshops_2c7c99c87dda94d91f79b411fea7d498','\'\'',NULL,1298071),('2_Friday','16','16:00','16:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'CryptoHack Badge Teardown\'','\'Sadiq \"Sdqmd\",Do Truong Giang \"FSNaix\"\'','Creator Workshops_84bf9ae071d74a04eb423a5d5b569fc2','\'Title: CryptoHack Badge Teardown
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

What is the board hanging around your neck actually made of? In this beginner-friendly session we dissect the open-hardware Cryptohack badge and learn to read it like an engineer: schematic symbols, the power chain (USB-C → charger → LDO → 3V3 rail), the ESP32-C3 and its support parts, and peripherals sharing a handful of buses. Then, in a live KiCad speed-run, we rebuild a slice of the board from scratch: schematic → footprints → layout → route → DRC. No electronics background needed; by the end you can open any KiCad schematic and name every part.

\n\n

A free of charge Cryptohack Badge is available for each participating student to use and take home for further exploration, you’re welcome!

\n\nSpeakers:Sadiq \"Sdqmd\",Do Truong Giang \"FSNaix\"
\n
\nSpeakerBio:  Sadiq \"Sdqmd\", CodeBit
\n

sdqmd (Sadiq) is a hardware hacker and co-founder of CodeBit, a technology company based in Brunei that\'s building a hardware engineering academy to teach embedded systems and security from the ground up. He is focused on developing a pedagogy that blends theory with hands-on practice, so aspiring hackers — especially those just starting out — don\'t just learn how something works; they build it, break it, and understand it for themselves. His own research focuses on hardware attacks against embedded devices — using fault injection and power analysis to defeat the security of everything from crypto hardware wallets to point-of-sale infrastructure. Above all, he\'s driven by one goal: building hardware and security competency in Brunei, where hands-on learning is still hard to come by.

\n\nSpeakerBio:  Do Truong Giang \"FSNaix\", BlossomsAI / Bloomify (AI & Security)
\n

I\'m Giang (FSNaix), an AI and security researcher from Vietnam and a Bloomify cofounder. I help build open-source Vietnamese language models with BlossomsAI, I built Petal (an AI tool that reverse-engineers binaries faster than doing it by hand), and at DEFCON Singapore 1 I managed to get DOOM running on a $20 conference badge.

\n\n\n\'',NULL,1298072),('2_Friday','17','17:00','17:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Photo Party\'','\'Cryptocurrency Village Staff\'','Creator Workshops_f33683b3c680e3a93c1dc00646971ed2','\'Title: Cryptocurrency Photo Party
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Step into our Photo Party on Friday evening. Grab a drink, meet fellow crypto hackers, strike a photo pose, and celebrate our nineth year in action!

\n\n

Bring a ticket from your free of charge Cryptocurrency Starter Kit to receive a special commemorative challenge coin. Photography will take place throughout the party.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298073),('3_Saturday','10','10:00','17:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_f8908574f39828dac4489d28fe76534d','\'Title: Cryptocurrency CTF
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

In Draining Sin City Jackpots, players read systems, chain findings, and submit flags for a live scoreboard, with challenge names kept secret until the event opens.

\n\n

Prizes include a variety of coin branded items as well as the Cryptocurrency CTF Black Ribbon first prize winner: A $2K Hak5 gift certificate.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298074),('3_Saturday','11','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_f8908574f39828dac4489d28fe76534d','\'\'',NULL,1298075),('3_Saturday','12','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_f8908574f39828dac4489d28fe76534d','\'\'',NULL,1298076),('3_Saturday','13','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_f8908574f39828dac4489d28fe76534d','\'\'',NULL,1298077),('3_Saturday','14','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_f8908574f39828dac4489d28fe76534d','\'\'',NULL,1298078),('3_Saturday','15','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_f8908574f39828dac4489d28fe76534d','\'\'',NULL,1298079),('3_Saturday','16','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_f8908574f39828dac4489d28fe76534d','\'\'',NULL,1298080),('3_Saturday','17','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_f8908574f39828dac4489d28fe76534d','\'\'',NULL,1298081),('3_Saturday','10','10:00','17:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a3370c6b370b09f19639207a7ee771df','\'Title: Cryptocurrency Contest
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

This is a free, six-level skills ladder from answering offensive security trivia questions through creating wallets, hacking badges, and tracing then deanonymizing on-chain transactions to recover illicit blocks and stolen funds. This time our contest includes puzzles contributed by NewAE Technology as well as collaborations with our Hac-Man contest friends, isn’t that absolutely bodacious?

\n\n

A wide range of low to high value prizes are awarded in the usual Cryptocurrency Village and Challenge ways:

\n\n

Giveaway base level 0: Branded bag with workbook, USB media, casino deck

\n\n

Award prize level 1: Electronic badge (free edition) and author signed book

\n\n

Award prize level 2: Simple addon, SE collection or one BTC, XMR, ETH, SOL

\n\n

Award prize level 3: High value collector coin of BTC, XMR, ETH, SOL

\n\n

Award prize level 4: BTC, XMR, ETH, SOL tee shirt or XMR messenger bag

\n\n

Award prize level 5: Electronic badge pluspack (upgrade the free edition)

\n\n

Award prize level 6: Vacuum steel thermos bottle of BTC, XMR, ETH, SOL

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298082),('3_Saturday','11','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a3370c6b370b09f19639207a7ee771df','\'\'',NULL,1298083),('3_Saturday','12','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a3370c6b370b09f19639207a7ee771df','\'\'',NULL,1298084),('3_Saturday','13','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a3370c6b370b09f19639207a7ee771df','\'\'',NULL,1298085),('3_Saturday','14','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a3370c6b370b09f19639207a7ee771df','\'\'',NULL,1298086),('3_Saturday','15','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a3370c6b370b09f19639207a7ee771df','\'\'',NULL,1298087),('3_Saturday','16','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a3370c6b370b09f19639207a7ee771df','\'\'',NULL,1298088),('3_Saturday','17','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_a3370c6b370b09f19639207a7ee771df','\'\'',NULL,1298089),('3_Saturday','10','10:00','16:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_ab8105ace29cc5b5be844478f9654c29','\'Title: Cryptocurrency Hackathon
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\nA free build competition judged across four themes: Privacy Hide, Sovereignty Survive, Exploitation Break, and Escape Evade, spanning classes like Application, Hardware, Firmware, Software, Science, and Analysis.
\n\n

Register your team on-site and find out if you qualify to build your own node using a Dell Optiplex computer that you use for the duration and take home for further hacking.

\n\n

Fabulous prizes include coin branded merchandise as well as gift certificates. The Cryptocurrency Hackathon Black Ribbon first prize winner: K Hak5 gift certificate, and the Cryptocurrency Hackathon Green Ribbon second prize winner: K Hak5 gift certificate

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298090),('3_Saturday','11','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_ab8105ace29cc5b5be844478f9654c29','\'\'',NULL,1298091),('3_Saturday','12','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_ab8105ace29cc5b5be844478f9654c29','\'\'',NULL,1298092),('3_Saturday','13','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_ab8105ace29cc5b5be844478f9654c29','\'\'',NULL,1298093),('3_Saturday','14','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_ab8105ace29cc5b5be844478f9654c29','\'\'',NULL,1298094),('3_Saturday','15','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_ab8105ace29cc5b5be844478f9654c29','\'\'',NULL,1298095),('3_Saturday','16','10:00','16:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_ab8105ace29cc5b5be844478f9654c29','\'\'',NULL,1298096),('3_Saturday','10','10:00','17:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_84f1ca73909467f021ce9516508d9761','\'Title: Cryptocurrency Meet-a-mentor
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Got a cryptocurrency question you\'ve been sitting on? Bring it to Meet-a-Mentor. Cryptocurrency Village staff and crew are on hand throughout the village to answer anything. From ‚what actually is a private key’ to your deepest protocol-level rabbit hole, we help with real expertise and zero judgment. No question is too basic, too advanced, or too weird; our mentors have heard it all, and they\'ll give you a straight answer with a healthy dose of humour along the way. Just don‘t expect to get any investing advice, that’s forbidden and dumb. Come with curiosity, leave with clarity.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298097),('3_Saturday','11','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_84f1ca73909467f021ce9516508d9761','\'\'',NULL,1298098),('3_Saturday','12','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_84f1ca73909467f021ce9516508d9761','\'\'',NULL,1298099),('3_Saturday','13','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_84f1ca73909467f021ce9516508d9761','\'\'',NULL,1298100),('3_Saturday','14','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_84f1ca73909467f021ce9516508d9761','\'\'',NULL,1298101),('3_Saturday','15','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_84f1ca73909467f021ce9516508d9761','\'\'',NULL,1298102),('3_Saturday','16','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_84f1ca73909467f021ce9516508d9761','\'\'',NULL,1298103),('3_Saturday','17','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_84f1ca73909467f021ce9516508d9761','\'\'',NULL,1298104),('3_Saturday','10','10:00','11:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Ghost in the Pipeline\'','\'Hanley Shun,⁨Oscar Skjerven\'','Creator Workshops_66ff88707a2b4ef23ca9bb2c283c685e','\'Title: Ghost in the Pipeline
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Software supply chain attacks don\'t announce themselves — they hide in plain sight inside a merge request.

\n\n

This two-hour hands-on workshop drops you into a live, purpose-built Git environment where your only goal is to sneak malicious code past an LLM-powered detection engine and exfiltrate a secret before the pipeline catches you.

\n\n

Every commit you push triggers an AI-based code analysis system that scrutinizes your changes for malicious intent. Your job is to make it look the other way. Each failed attempt surfaces the engine\'s reasoning — giving you the feedback loop you need to sharpen your next move.

\n\n

This workshop is built on a real-world red team exercise spanning over numerous pipeline runs and a dozen documented bypass chains, distilled into a structured CTF-style gauntlet. You\'ll leave with a concrete, battle-tested understanding of where LLM-based static analysis breaks down, and a sharper toolkit for evading AI-assisted supply chain defenses in the wild.

\n\n

No prior experience with supply chain attacks required. The objective is simple: poison the code, survive the scan, and walk away with the flag — or the keys to the machine.

\n\n

Please come prepared with a device to write code, push commit, a keyboard, and github account

\n\nSpeakers:Hanley Shun,⁨Oscar Skjerven
\n
\nSpeakerBio:  Hanley Shun, OKX
\n

Hanley has been working in information security for 10 years, with a background in penetration testing and vulnerability management. Now at OKX, channeling that offensive mindset into building secure CI/CD pipelines with AI, every day keeping customers\' funds safe.

\n\nSpeakerBio:  ⁨Oscar Skjerven, OKX
\nNo BIO available
\n\n\'',NULL,1298105),('3_Saturday','11','10:00','11:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Ghost in the Pipeline\'','\'Hanley Shun,⁨Oscar Skjerven\'','Creator Workshops_66ff88707a2b4ef23ca9bb2c283c685e','\'\'',NULL,1298106),('3_Saturday','10','10:00','17:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_5685fc9ceb80cd162a772430b6ed54c2','\'Title: OpenLASIR Olympics
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Join the Cryptocurrency Village for the OpenLASIR Olympics, where you can take advantage of the OpenLASIR IR protocol used to power laser tag badge devices (like the Laser* Tag Badge, Cryptohack Badge, and the official DEF CON Singapore 1 Badge); meet people to befriend & ZAPP; and win! We will have a practice target set up for you to test your aim, and a loaner badge or two to play with if you don’t have your own OpenLASIR device. While you are here, check out the Hardware Zoo to see other cool electronics tools, gadgets, and gizmos.

\n\n

Winners take home a brand new Cryptohack Electronic Badge, with application pari ty to the official DEF CON Singapore One Badge.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298107),('3_Saturday','11','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_5685fc9ceb80cd162a772430b6ed54c2','\'\'',NULL,1298108),('3_Saturday','12','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_5685fc9ceb80cd162a772430b6ed54c2','\'\'',NULL,1298109),('3_Saturday','13','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_5685fc9ceb80cd162a772430b6ed54c2','\'\'',NULL,1298110),('3_Saturday','14','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_5685fc9ceb80cd162a772430b6ed54c2','\'\'',NULL,1298111),('3_Saturday','15','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_5685fc9ceb80cd162a772430b6ed54c2','\'\'',NULL,1298112),('3_Saturday','16','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_5685fc9ceb80cd162a772430b6ed54c2','\'\'',NULL,1298113),('3_Saturday','17','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_5685fc9ceb80cd162a772430b6ed54c2','\'\'',NULL,1298114),('3_Saturday','12','12:00','13:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Hacking a Crypto Hardware Wallet\'','\'Sadiq \"Sdqmd\",Do Truong Giang (FSNaix),Param Pithadia\'','Creator Workshops_cc8f333d214e9a42eab61540c632f5da','\'Title: Hacking a Crypto Hardware Wallet
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Saturday, Aug 8, 12:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Ever wondered what it takes to crack a cryptocurrency hardware wallet? We open with the theory of physical attacks: side-channel analysis (how a chip\'s power consumption leaks the data it is computing on) and fault injection (how a brief, well-timed glitch makes it skip a security check), building up to correlation power analysis on AES and voltage glitching. Then we wire up the glitch hardware, capture power traces, glitch past the PIN check, extract the wallet\'s seed, derive a Bitcoin key, and drain the wallet on a private regtest network. No prior hardware-hacking experience required.

\n\n

A free of charge Cryptohack Badge is available for each participating student to use and take home for further exploration, you’re welcome!

\n\nSpeakers:Sadiq \"Sdqmd\",Do Truong Giang (FSNaix),Param Pithadia
\n
\nSpeakerBio:  Sadiq \"Sdqmd\", CodeBit
\n

sdqmd (Sadiq) is a hardware hacker and co-founder of CodeBit, a technology company based in Brunei that\'s building a hardware engineering academy to teach embedded systems and security from the ground up. He is focused on developing a pedagogy that blends theory with hands-on practice, so aspiring hackers — especially those just starting out — don\'t just learn how something works; they build it, break it, and understand it for themselves. His own research focuses on hardware attacks against embedded devices — using fault injection and power analysis to defeat the security of everything from crypto hardware wallets to point-of-sale infrastructure. Above all, he\'s driven by one goal: building hardware and security competency in Brunei, where hands-on learning is still hard to come by.

\n\nSpeakerBio:  Do Truong Giang (FSNaix)
\nNo BIO available
\nSpeakerBio:  Param Pithadia
\n

Param is an Electrical Engineering Student from Georgia Tech with a strong passion for and interest in crypto. Although he primarily got interested in cryptography and hardware security through a class at Georgia Tech, he is also working at a software company on crypto adoption and ease of use. With a unique blend of HW and SW skills, Param is truly enthusiastic about all aspects of crypto.

\n\n\n\'',NULL,1298115),('3_Saturday','13','12:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Hacking a Crypto Hardware Wallet\'','\'Sadiq \"Sdqmd\",Do Truong Giang (FSNaix),Param Pithadia\'','Creator Workshops_cc8f333d214e9a42eab61540c632f5da','\'\'',NULL,1298116),('3_Saturday','14','14:00','15:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Multi-Chain Exploitation & ATM Attacks\'','\'Sadiq \"Sdqmd\",Param Pithadia\'','Creator Workshops_2629749ac99ec732cb9be45ba306e79d','\'Title: Multi-Chain Exploitation & ATM Attacks
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Saturday, Aug 8, 14:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Starting from a compromised wallet, we explore how stolen secret can ripple across four very different blockchains and into a completely different class of device. We begin with the concepts every attack rests on: how a blockchain works and why whoever holds the key controls the funds. Then, on private test networks, participants work through taking control of accounts and moving funds across Bitcoin, Ethereum (and its ERC-20 tokens), Solana, and privacy-focused Monero, seeing what changes from chain to chain. We close with a live demo of a DIY Bitcoin Lightning ATM (the Bleskomat), showing how a poorly protected secret lets its payouts be forged. The throughline: the cryptography itself is sound; the weakness is in how the secrets are stored and handled.

\n\nSpeakers:Sadiq \"Sdqmd\",Param Pithadia
\n
\nSpeakerBio:  Sadiq \"Sdqmd\", CodeBit
\n

sdqmd (Sadiq) is a hardware hacker and co-founder of CodeBit, a technology company based in Brunei that\'s building a hardware engineering academy to teach embedded systems and security from the ground up. He is focused on developing a pedagogy that blends theory with hands-on practice, so aspiring hackers — especially those just starting out — don\'t just learn how something works; they build it, break it, and understand it for themselves. His own research focuses on hardware attacks against embedded devices — using fault injection and power analysis to defeat the security of everything from crypto hardware wallets to point-of-sale infrastructure. Above all, he\'s driven by one goal: building hardware and security competency in Brunei, where hands-on learning is still hard to come by.

\n\nSpeakerBio:  Param Pithadia
\n

Param is an Electrical Engineering Student from Georgia Tech with a strong passion for and interest in crypto. Although he primarily got interested in cryptography and hardware security through a class at Georgia Tech, he is also working at a software company on crypto adoption and ease of use. With a unique blend of HW and SW skills, Param is truly enthusiastic about all aspects of crypto.

\n\n\n\'',NULL,1298117),('3_Saturday','15','14:00','15:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Multi-Chain Exploitation & ATM Attacks\'','\'Sadiq \"Sdqmd\",Param Pithadia\'','Creator Workshops_2629749ac99ec732cb9be45ba306e79d','\'\'',NULL,1298118),('3_Saturday','16','16:00','17:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Web3 Security: Hacks, Scams, and Exploits\'','\'Philip \"AlephNull\" Werlau,Kennashka DeSilva\'','Creator Workshops_6bad2bca3ce7edba9b7dff4ce83aae6b','\'Title: Web3 Security: Hacks, Scams, and Exploits
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Saturday, Aug 8, 16:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Why do Web3 users keep getting hacked even when the smart contracts are audited? This workshop examines the Web3 attack surface through three lenses: the client, the dApp frontend, and the blockchain, using real-world hacks, scams, and exploits to demonstrate how each layer can fail. Participants will conduct a live review of their own wallet approvals using revoke.cash and learn practical techniques for reducing risk. The workshop concludes with a forensic deep dive into the .5 billion Bybit hack, where attendees will analyze the malicious transaction, compromised frontend, and on-chain evidence that enabled the largest cryptocurrency theft in history.

\n\nSpeakers:Philip \"AlephNull\" Werlau,Kennashka DeSilva
\n
\nSpeakerBio:  Philip \"AlephNull\" Werlau, Founder at Flowstate Cyber
\n

Philip is a cryptocurrency investigator and smart contract analyst specializing in DeFi, on-chain forensics, and blockchain security. Experienced in support of government agencies and private-sector clients in cryptocurrency fraud investigations, exploit analysis, fund tracing, and smart contract risk analysis, Philip’s extensive familiarity with EVM ecosystems, blockchain analytics, and custom investigative tooling contributes to his work in government and industry.

\n\nSpeakerBio:  Kennashka DeSilva
\n

Kennashka DeSilva is a seasoned cybersecurity researcher with a strong track record of advancing security best practices in decentralized systems. She was a featured speaker at DEF CON 30’s “Hacking & Defending Blockchain Applications” session, where she helped bridge the gap between traditional application security frameworks—such as the OWASP Top Ten—and the unique risks found in DEFI and smart contract ecosystems. Kennashka is also an active participant in the cybersecurity community, having contributed to multiple HackMiami events and served on the executive councils of Women in Cybersecurity Florida and Black Girls in Cyber, helping to advance diversity, mentorship, and professional development in the field. Her expertise spans vulnerability management, threat modeling, and policy-driven security in Web3 and enterprise systems.

\n\n\n\'',NULL,1298119),('3_Saturday','17','16:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Web3 Security: Hacks, Scams, and Exploits\'','\'Philip \"AlephNull\" Werlau,Kennashka DeSilva\'','Creator Workshops_6bad2bca3ce7edba9b7dff4ce83aae6b','\'\'',NULL,1298120),('3_Saturday','17','17:00','17:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency BoF\'','\'Cryptocurrency Village Staff\'','Creator Talks_99c42d279f32a2a822c2c8e40ef15dea','\'Title: Cryptocurrency BoF
\nTags: Cryptocurrency Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Our BoF is even worse than you imagined; It’s a bunch of tables with wirey hacked individuals making strange claims of a crypto induced future dysto. If you belong to a particular group like:

\n\n

DEF CON Goons\nSchool Educators\nUnderaged Kids\nCardano Enthusiasts\nMonero Enthusiasts\nLGBTQIA+\nWomen in Crypto\nWeen Fans\nDisco Dancers

\n\n

...then you belong with us at a BoF table. You can make your own table topic, but please be nice!

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298121),('4_Sunday','10','10:00','13:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_fd06609d7b393bc1e232c761a4955b59','\'Title: Cryptocurrency CTF
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

In Draining Sin City Jackpots, players read systems, chain findings, and submit flags for a live scoreboard, with challenge names kept secret until the event opens.

\n\n

Prizes include a variety of coin branded items as well as the Cryptocurrency CTF Black Ribbon first prize winner: A $2K Hak5 gift certificate.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298122),('4_Sunday','11','10:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_fd06609d7b393bc1e232c761a4955b59','\'\'',NULL,1298123),('4_Sunday','12','10:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_fd06609d7b393bc1e232c761a4955b59','\'\'',NULL,1298124),('4_Sunday','13','10:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency CTF\'','\'Cryptocurrency Village Staff\'','Creator Events_fd06609d7b393bc1e232c761a4955b59','\'\'',NULL,1298125),('4_Sunday','10','10:00','13:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_aa8a9387291f37920a53083a8497466a','\'Title: Cryptocurrency Contest
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

This is a free, six-level skills ladder from answering offensive security trivia questions through creating wallets, hacking badges, and tracing then deanonymizing on-chain transactions to recover illicit blocks and stolen funds. This time our contest includes puzzles contributed by NewAE Technology as well as collaborations with our Hac-Man contest friends, isn’t that absolutely bodacious?

\n\n

A wide range of low to high value prizes are awarded in the usual Cryptocurrency Village and Challenge ways:

\n\n

Giveaway base level 0: Branded bag with workbook, USB media, casino deck

\n\n

Award prize level 1: Electronic badge (free edition) and author signed book

\n\n

Award prize level 2: Simple addon, SE collection or one BTC, XMR, ETH, SOL

\n\n

Award prize level 3: High value collector coin of BTC, XMR, ETH, SOL

\n\n

Award prize level 4: BTC, XMR, ETH, SOL tee shirt or XMR messenger bag

\n\n

Award prize level 5: Electronic badge pluspack (upgrade the free edition)

\n\n

Award prize level 6: Vacuum steel thermos bottle of BTC, XMR, ETH, SOL

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298126),('4_Sunday','11','10:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_aa8a9387291f37920a53083a8497466a','\'\'',NULL,1298127),('4_Sunday','12','10:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_aa8a9387291f37920a53083a8497466a','\'\'',NULL,1298128),('4_Sunday','13','10:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Contest\'','\'Cryptocurrency Village Staff\'','Creator Events_aa8a9387291f37920a53083a8497466a','\'\'',NULL,1298129),('4_Sunday','10','10:00','11:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Design from Scratch\'','\'Param Pithadia,Mathew Sigunga\'','Creator Workshops_8a909136c4c2523762ddc282ece25fa1','\'Title: Cryptocurrency Design from Scratch
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Most people use blockchains. Few understand what\'s underneath. In this hands-on workshop, you\'ll build two cryptocurrencies from the ground up — a Layer 1 chain in Python and a Layer 2 token ecosystem in Solidity — and immediately turn that builder knowledge into attacker intuition.

\n\n

Developers, security researchers, financial analysts, and curious hackers with basic Python familiarity will benefit most. Solidity experience is helpful but not required. Bring a portable computer with Python 3.10+ installed.

\n\n

Build and Break

\n\n

Layer 1 — Python (First Hour)\nStarting from scratch, you\'ll implement a working blockchain: consensus logic, transaction validation, peer primitives, and a minimal node. As each component goes up, we\'ll stress-test it — examining double-spend vectors, chain reorganization attacks, and the gaps that emerge when cryptographic assumptions are made carelessly.

\n\n

Layer 2 — Solidity (Second Hour)\nOn top of that foundation, you\'ll deploy smart contracts representing a Layer 2 token system — the kind that underpins real DeFi protocols today. We\'ll instrument the contracts for auditability, then walk through the classic offensive playbook: reentrancy, integer overflow/underflow, access control failures, and oracle manipulation. You\'ll exploit contracts you just wrote, which makes the lessons stick.

\n\nSpeakers:Param Pithadia,Mathew Sigunga
\n
\nSpeakerBio:  Param Pithadia
\n

Param is an Electrical Engineering Student from Georgia Tech with a strong passion for and interest in crypto. Although he primarily got interested in cryptography and hardware security through a class at Georgia Tech, he is also working at a software company on crypto adoption and ease of use. With a unique blend of HW and SW skills, Param is truly enthusiastic about all aspects of crypto.

\n\nSpeakerBio:  Mathew Sigunga
\n

Mathew is a Computer Engineering student at the Georgia Institute of Technology with interests in blockchain security, cloud security, and embedded systems. He has experience developing cloud infrastructure, security tooling, and blockchain applications, and currently volunteers with the DEF CON Cryptocurrency Village supporting USB media distribution and on-chain security workshops. His interests include smart contract security, blockchain architecture, and building secure systems from the hardware to the cloud.

\n\n\n\'',NULL,1298130),('4_Sunday','11','10:00','11:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Design from Scratch\'','\'Param Pithadia,Mathew Sigunga\'','Creator Workshops_8a909136c4c2523762ddc282ece25fa1','\'\'',NULL,1298131),('4_Sunday','10','10:00','13:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_6b3eee509daa93eb0ee51c4e5251c482','\'Title: Cryptocurrency Hackathon
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\nA free build competition judged across four themes: Privacy Hide, Sovereignty Survive, Exploitation Break, and Escape Evade, spanning classes like Application, Hardware, Firmware, Software, Science, and Analysis.
\n\n

Register your team on-site and find out if you qualify to build your own node using a Dell Optiplex computer that you use for the duration and take home for further hacking.

\n\n

Fabulous prizes include coin branded merchandise as well as gift certificates. The Cryptocurrency Hackathon Black Ribbon first prize winner: K Hak5 gift certificate, and the Cryptocurrency Hackathon Green Ribbon second prize winner: K Hak5 gift certificate

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298132),('4_Sunday','11','10:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_6b3eee509daa93eb0ee51c4e5251c482','\'\'',NULL,1298133),('4_Sunday','12','10:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_6b3eee509daa93eb0ee51c4e5251c482','\'\'',NULL,1298134),('4_Sunday','13','10:00','13:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Hackathon\'','\'Cryptocurrency Village Staff\'','Creator Events_6b3eee509daa93eb0ee51c4e5251c482','\'\'',NULL,1298135),('4_Sunday','10','10:00','14:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_113ff5449f69852284ca8440f6de9871','\'Title: Cryptocurrency Meet-a-mentor
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Got a cryptocurrency question you\'ve been sitting on? Bring it to Meet-a-Mentor. Cryptocurrency Village staff and crew are on hand throughout the village to answer anything. From ‚what actually is a private key’ to your deepest protocol-level rabbit hole, we help with real expertise and zero judgment. No question is too basic, too advanced, or too weird; our mentors have heard it all, and they\'ll give you a straight answer with a healthy dose of humour along the way. Just don‘t expect to get any investing advice, that’s forbidden and dumb. Come with curiosity, leave with clarity.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298136),('4_Sunday','11','10:00','14:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_113ff5449f69852284ca8440f6de9871','\'\'',NULL,1298137),('4_Sunday','12','10:00','14:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_113ff5449f69852284ca8440f6de9871','\'\'',NULL,1298138),('4_Sunday','13','10:00','14:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_113ff5449f69852284ca8440f6de9871','\'\'',NULL,1298139),('4_Sunday','14','10:00','14:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Cryptocurrency Meet-a-mentor\'','\'Cryptocurrency Village Staff\'','Creator Events_113ff5449f69852284ca8440f6de9871','\'\'',NULL,1298140),('4_Sunday','10','10:00','17:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_4f7145b161ab3c36411d76f97312fbb2','\'Title: OpenLASIR Olympics
\nTags: Cryptocurrency Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

Join the Cryptocurrency Village for the OpenLASIR Olympics, where you can take advantage of the OpenLASIR IR protocol used to power laser tag badge devices (like the Laser* Tag Badge, Cryptohack Badge, and the official DEF CON Singapore 1 Badge); meet people to befriend & ZAPP; and win! We will have a practice target set up for you to test your aim, and a loaner badge or two to play with if you don’t have your own OpenLASIR device. While you are here, check out the Hardware Zoo to see other cool electronics tools, gadgets, and gizmos.

\n\n

Winners take home a brand new Cryptohack Electronic Badge, with application pari ty to the official DEF CON Singapore One Badge.

\n\nSpeakerBio:  Cryptocurrency Village Staff
\n

The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world.

\n\n\n\'',NULL,1298141),('4_Sunday','11','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_4f7145b161ab3c36411d76f97312fbb2','\'\'',NULL,1298142),('4_Sunday','12','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_4f7145b161ab3c36411d76f97312fbb2','\'\'',NULL,1298143),('4_Sunday','13','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_4f7145b161ab3c36411d76f97312fbb2','\'\'',NULL,1298144),('4_Sunday','14','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_4f7145b161ab3c36411d76f97312fbb2','\'\'',NULL,1298145),('4_Sunday','15','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_4f7145b161ab3c36411d76f97312fbb2','\'\'',NULL,1298146),('4_Sunday','16','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_4f7145b161ab3c36411d76f97312fbb2','\'\'',NULL,1298147),('4_Sunday','17','10:00','17:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'OpenLASIR Olympics\'','\'Cryptocurrency Village Staff\'','Creator Events_4f7145b161ab3c36411d76f97312fbb2','\'\'',NULL,1298148),('4_Sunday','12','12:00','13:30','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Breaking Ciphers\'','\'Luke Szramowski,Rigo Salazar,Diego Salazar (rehrar)\'','Creator Workshops_4b06e0b7bcce220be791a716f91ca2cb','\'Title: Breaking Ciphers
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Sunday, Aug 9, 12:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

This will be a hands-on talk walking through various methods of cryptanalysis, starting with simple ciphers and working up to more sophisticated modern encryption methods.

\n\n

The purpose of this workshop is to look at cryptography methods in history and work on breaking them in a collaborative and hands on way. It will cover simple methods in cryptanalysis and is accessible for any audience of any skill level.

\n\nSpeakers:Luke Szramowski,Rigo Salazar,Diego Salazar (rehrar)
\n
\nSpeakerBio:  Luke Szramowski, Cypher Stack
\n

Luke Szramowski is a mathematical researcher, with a Bachelor\'s Degree in Mathematics and two Master\'s Degrees, one in Math, with a focus in Number Theory and another in Math with a focus in Coding Theory. In his free time, Luke works on a litany of different math problems, mainly regarding Number Theoretic conjectures and playing all different types of games.

\n\nSpeakerBio:  Rigo Salazar, Cypher Stack
\n

Rigo earned his graduate degree in mathematics and has been dipping in and out of the cryptocurrency space since 2019. As the manager of a separate company (in a non-competing field), he only works part-time with Cypher Stack, with the hope to make a full transition in the future. He also has the exclusive brother right to bust Diego\'s chops, which makes him invaluable to the team.

\n\nSpeakerBio:  Diego Salazar (rehrar)
\nNo BIO available
\n\n\'',NULL,1298149),('4_Sunday','13','12:00','13:30','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Breaking Ciphers\'','\'Luke Szramowski,Rigo Salazar,Diego Salazar (rehrar)\'','Creator Workshops_4b06e0b7bcce220be791a716f91ca2cb','\'\'',NULL,1298150),('4_Sunday','13','13:30','14:59','N','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Modern Topics in Cryptography\'','\'Luke Szramowski,Rigo Salazar,Diego Salazar (rehrar)\'','Creator Workshops_d0955a101229286884466f9d547f34d3','\'Title: Modern Topics in Cryptography
\nTags: Cryptocurrency Village | Creator Workshop
\nWhen: Sunday, Aug 9, 13:30 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 702 (Cryptocurrency Village) - Map
\n
\nDescription:
\n

This workshop follows Breaking Ciphers by introducing an interested person to some of the more technical concepts in cryptography. We will talk about modern cryptographic methods in use today, as well as their shortcomings. Furthermore, we will talk about important related concepts in math, such as Zero Knowledge Proofs and Quantum Resistance. This workshop is also accessible to people of all ages and backgrounds.

\n\nSpeakers:Luke Szramowski,Rigo Salazar,Diego Salazar (rehrar)
\n
\nSpeakerBio:  Luke Szramowski, Cypher Stack
\n

Luke Szramowski is a mathematical researcher, with a Bachelor\'s Degree in Mathematics and two Master\'s Degrees, one in Math, with a focus in Number Theory and another in Math with a focus in Coding Theory. In his free time, Luke works on a litany of different math problems, mainly regarding Number Theoretic conjectures and playing all different types of games.

\n\nSpeakerBio:  Rigo Salazar, Cypher Stack
\n

Rigo earned his graduate degree in mathematics and has been dipping in and out of the cryptocurrency space since 2019. As the manager of a separate company (in a non-competing field), he only works part-time with Cypher Stack, with the hope to make a full transition in the future. He also has the exclusive brother right to bust Diego\'s chops, which makes him invaluable to the team.

\n\nSpeakerBio:  Diego Salazar (rehrar)
\nNo BIO available
\n\n\'',NULL,1298151),('4_Sunday','14','13:30','14:59','Y','Cryptocurrency Village','LVCCW Level 1 Hall 2 702 (Cryptocurrency Village)','\'Modern Topics in Cryptography\'','\'Luke Szramowski,Rigo Salazar,Diego Salazar (rehrar)\'','Creator Workshops_d0955a101229286884466f9d547f34d3','\'\'',NULL,1298152),('4_Sunday','10','10:00','11:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_4c52b3df8c7286d9f8fb7a0d3cf69031','\'Title: The Quantum-CTF
\nTags: Quantum Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

The world\'s first Quantum Capture the Flag is 5 years old. Hands-on puzzles that turn curious hackers into quantum hackers. Real QPU access + Hacker Ingenuity.

\n\nLinks:
    Website - https://qctf.quantumvillage.org/
\n\'',NULL,1298153),('4_Sunday','11','10:00','11:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_4c52b3df8c7286d9f8fb7a0d3cf69031','\'\'',NULL,1298154),('3_Saturday','10','10:00','17:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_fca01f950bb17529114e0990a77c1905','\'Title: The Quantum-CTF
\nTags: Quantum Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

The world\'s first Quantum Capture the Flag is 5 years old. Hands-on puzzles that turn curious hackers into quantum hackers. Real QPU access + Hacker Ingenuity.

\n\nLinks:
    Website - https://qctf.quantumvillage.org/
\n\'',NULL,1298155),('3_Saturday','11','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_fca01f950bb17529114e0990a77c1905','\'\'',NULL,1298156),('3_Saturday','12','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_fca01f950bb17529114e0990a77c1905','\'\'',NULL,1298157),('3_Saturday','13','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_fca01f950bb17529114e0990a77c1905','\'\'',NULL,1298158),('3_Saturday','14','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_fca01f950bb17529114e0990a77c1905','\'\'',NULL,1298159),('3_Saturday','15','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_fca01f950bb17529114e0990a77c1905','\'\'',NULL,1298160),('3_Saturday','16','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_fca01f950bb17529114e0990a77c1905','\'\'',NULL,1298161),('3_Saturday','17','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_fca01f950bb17529114e0990a77c1905','\'\'',NULL,1298162),('2_Friday','10','10:00','17:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_8024e91d740200691b9a567ceb636a4f','\'Title: The Quantum-CTF
\nTags: Quantum Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

The world\'s first Quantum Capture the Flag is 5 years old. Hands-on puzzles that turn curious hackers into quantum hackers. Real QPU access + Hacker Ingenuity.

\n\nLinks:
    Website - https://qctf.quantumvillage.org/
\n\'',NULL,1298163),('2_Friday','11','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_8024e91d740200691b9a567ceb636a4f','\'\'',NULL,1298164),('2_Friday','12','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_8024e91d740200691b9a567ceb636a4f','\'\'',NULL,1298165),('2_Friday','13','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_8024e91d740200691b9a567ceb636a4f','\'\'',NULL,1298166),('2_Friday','14','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_8024e91d740200691b9a567ceb636a4f','\'\'',NULL,1298167),('2_Friday','15','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_8024e91d740200691b9a567ceb636a4f','\'\'',NULL,1298168),('2_Friday','16','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_8024e91d740200691b9a567ceb636a4f','\'\'',NULL,1298169),('2_Friday','17','10:00','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF\'','\'\'','Creator Events_8024e91d740200691b9a567ceb636a4f','\'\'',NULL,1298170),('4_Sunday','10','10:00','13:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Martitime Hacking Village CTF\'','\'Duncan Woodbury,KennethSalt\'','Creator Events_9b60db4a5d2f1a3ce50361a586f69b8a','\'Title: Martitime Hacking Village CTF
\nTags: Maritime Hacking Village | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

YO HO! Come aboard at the Maritime Hacking Village (MHV) for an immersive real-world maritime hacking experience that is ONLY available at DEFCON! Learn what it takes to hack on the high seas, and discover how the technologies used across global maritime trade and national security can be attacked and defended with common tools and tradecraft. This will be a weekend full of hands-on learning, training, and education about hacking the depths of maritime OT and IT systems, guided by the elite maritime cybersecurity community.

\n\n

Attendees can expect to learn the tools of the trade for hacking maritime in-vehicle networks, maritime telecommunications systems (ship-side and shore-side), maritime autonomy systems, and shore-side operational and networking technologies for port operations and cargo management. MHV will provide a variety of real maritime hardware (autonomous vehicles, buoys, crane control systems, and more) and software (from maritime OEMs and system integrators used in ship-side and shore-side operations), integrated in a never-before-seen maritime capture-the-flag contest and open hacking competition. We will challenge attendees to apply their skills in embedded communications, wireless networks, radio communications, and software/binary reverse engineering to break into these systems and demonstrate their teams’ ability to upskill in modern maritime cyber warfare and defense.

\n\n

Ideally, participants will be familiar with using a terminal, the screen utility, basic /dev/tty devices, and wireshark. Beyond this, there are no hard prerequisites, but participating individuals and teams are encouraged to bring experience in the following areas to accelerate successful engagement in our more advanced hacking challenges:

\n\n
    \n
  • CAN-based protocols, ex. CAN bus, J1939, NMEA2000. Familiarity using can-utils
  • \n
  • Serial protocols, ex. Modbus (RS485 and tcp), NMEA0183 (RS422), and RS232
  • \n
  • SDR/software defined radio - basic usage of gnuradio with HackRF or more advanced radio
  • \n
  • Firmware/binary analysis and reverse engineering
  • \n
  • Attacking WiFi (802.11) networks
  • \n
  • Understanding of common radio frequency modulation schemes
  • \n
  • Familiarity with LoRA and 802-based mesh networking
  • \n
\n\nSpeakers:Duncan Woodbury,KennethSalt
\n
\nSpeakerBio:  Duncan Woodbury, Maritime Hacking Village
\nNo BIO available
\nSpeakerBio:  KennethSalt, Maritime Hacking Village
\nNo BIO available
\n\nLinks:
    maritimehackingvillage.com/dc34/ctf - https://maritimehackingvillage.com/dc34/ctf
\n\'',NULL,1298171),('4_Sunday','11','10:00','13:59','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Martitime Hacking Village CTF\'','\'Duncan Woodbury,KennethSalt\'','Creator Events_9b60db4a5d2f1a3ce50361a586f69b8a','\'\'',NULL,1298172),('4_Sunday','12','10:00','13:59','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Martitime Hacking Village CTF\'','\'Duncan Woodbury,KennethSalt\'','Creator Events_9b60db4a5d2f1a3ce50361a586f69b8a','\'\'',NULL,1298173),('4_Sunday','13','10:00','13:59','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Martitime Hacking Village CTF\'','\'Duncan Woodbury,KennethSalt\'','Creator Events_9b60db4a5d2f1a3ce50361a586f69b8a','\'\'',NULL,1298174),('2_Friday','10','10:00','11:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Martitime Hacking Village CTF\'','\'Duncan Woodbury,KennethSalt\'','Creator Events_8bc40d9eed38ba8736a445a488ccafe1','\'Title: Martitime Hacking Village CTF
\nTags: Maritime Hacking Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

YO HO! Come aboard at the Maritime Hacking Village (MHV) for an immersive real-world maritime hacking experience that is ONLY available at DEFCON! Learn what it takes to hack on the high seas, and discover how the technologies used across global maritime trade and national security can be attacked and defended with common tools and tradecraft. This will be a weekend full of hands-on learning, training, and education about hacking the depths of maritime OT and IT systems, guided by the elite maritime cybersecurity community.

\n\n

Attendees can expect to learn the tools of the trade for hacking maritime in-vehicle networks, maritime telecommunications systems (ship-side and shore-side), maritime autonomy systems, and shore-side operational and networking technologies for port operations and cargo management. MHV will provide a variety of real maritime hardware (autonomous vehicles, buoys, crane control systems, and more) and software (from maritime OEMs and system integrators used in ship-side and shore-side operations), integrated in a never-before-seen maritime capture-the-flag contest and open hacking competition. We will challenge attendees to apply their skills in embedded communications, wireless networks, radio communications, and software/binary reverse engineering to break into these systems and demonstrate their teams’ ability to upskill in modern maritime cyber warfare and defense.

\n\n

Ideally, participants will be familiar with using a terminal, the screen utility, basic /dev/tty devices, and wireshark. Beyond this, there are no hard prerequisites, but participating individuals and teams are encouraged to bring experience in the following areas to accelerate successful engagement in our more advanced hacking challenges:

\n\n
    \n
  • CAN-based protocols, ex. CAN bus, J1939, NMEA2000. Familiarity using can-utils
  • \n
  • Serial protocols, ex. Modbus (RS485 and tcp), NMEA0183 (RS422), and RS232
  • \n
  • SDR/software defined radio - basic usage of gnuradio with HackRF or more advanced radio
  • \n
  • Firmware/binary analysis and reverse engineering
  • \n
  • Attacking WiFi (802.11) networks
  • \n
  • Understanding of common radio frequency modulation schemes
  • \n
  • Familiarity with LoRA and 802-based mesh networking
  • \n
\n\nSpeakers:Duncan Woodbury,KennethSalt
\n
\nSpeakerBio:  Duncan Woodbury, Maritime Hacking Village
\nNo BIO available
\nSpeakerBio:  KennethSalt, Maritime Hacking Village
\nNo BIO available
\n\nLinks:
    maritimehackingvillage.com/dc34/ctf - https://maritimehackingvillage.com/dc34/ctf
\n\'',NULL,1298175),('2_Friday','11','10:00','11:59','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Martitime Hacking Village CTF\'','\'Duncan Woodbury,KennethSalt\'','Creator Events_8bc40d9eed38ba8736a445a488ccafe1','\'\'',NULL,1298176),('3_Saturday','10','10:00','11:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Martitime Hacking Village CTF\'','\'Duncan Woodbury,KennethSalt\'','Creator Events_262c240183b1da4fa46b0d18a1d60a33','\'Title: Martitime Hacking Village CTF
\nTags: Maritime Hacking Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

YO HO! Come aboard at the Maritime Hacking Village (MHV) for an immersive real-world maritime hacking experience that is ONLY available at DEFCON! Learn what it takes to hack on the high seas, and discover how the technologies used across global maritime trade and national security can be attacked and defended with common tools and tradecraft. This will be a weekend full of hands-on learning, training, and education about hacking the depths of maritime OT and IT systems, guided by the elite maritime cybersecurity community.

\n\n

Attendees can expect to learn the tools of the trade for hacking maritime in-vehicle networks, maritime telecommunications systems (ship-side and shore-side), maritime autonomy systems, and shore-side operational and networking technologies for port operations and cargo management. MHV will provide a variety of real maritime hardware (autonomous vehicles, buoys, crane control systems, and more) and software (from maritime OEMs and system integrators used in ship-side and shore-side operations), integrated in a never-before-seen maritime capture-the-flag contest and open hacking competition. We will challenge attendees to apply their skills in embedded communications, wireless networks, radio communications, and software/binary reverse engineering to break into these systems and demonstrate their teams’ ability to upskill in modern maritime cyber warfare and defense.

\n\n

Ideally, participants will be familiar with using a terminal, the screen utility, basic /dev/tty devices, and wireshark. Beyond this, there are no hard prerequisites, but participating individuals and teams are encouraged to bring experience in the following areas to accelerate successful engagement in our more advanced hacking challenges:

\n\n
    \n
  • CAN-based protocols, ex. CAN bus, J1939, NMEA2000. Familiarity using can-utils
  • \n
  • Serial protocols, ex. Modbus (RS485 and tcp), NMEA0183 (RS422), and RS232
  • \n
  • SDR/software defined radio - basic usage of gnuradio with HackRF or more advanced radio
  • \n
  • Firmware/binary analysis and reverse engineering
  • \n
  • Attacking WiFi (802.11) networks
  • \n
  • Understanding of common radio frequency modulation schemes
  • \n
  • Familiarity with LoRA and 802-based mesh networking
  • \n
\n\nSpeakers:Duncan Woodbury,KennethSalt
\n
\nSpeakerBio:  Duncan Woodbury, Maritime Hacking Village
\nNo BIO available
\nSpeakerBio:  KennethSalt, Maritime Hacking Village
\nNo BIO available
\n\nLinks:
    maritimehackingvillage.com/dc34/ctf - https://maritimehackingvillage.com/dc34/ctf
\n\'',NULL,1298177),('3_Saturday','11','10:00','11:59','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Martitime Hacking Village CTF\'','\'Duncan Woodbury,KennethSalt\'','Creator Events_262c240183b1da4fa46b0d18a1d60a33','\'\'',NULL,1298178),('2_Friday','14','14:00','15:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_5fd3fbc52b1ddaa9f095b7b77fdebe5d','\'Title: CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Friday, Aug 7, 14:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

CYBERCLAW is an interactive card-based wargaming experience for novice and advanced cyber professionals that will require participants to solve maritime security challenges in the GIUK region which align with MHV’s theme for the event, “Contested Communications”. During DC34, MHV will be co-hosting the CYBERCLAW (Cybersecurity Card-based Learning And Wargaming) wargame with its creators from the strongest navies on the seas.

\n\nSpeakerBio:  Wargame Guru, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298179),('2_Friday','15','14:00','15:30','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_5fd3fbc52b1ddaa9f095b7b77fdebe5d','\'\'',NULL,1298180),('3_Saturday','12','12:00','13:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_162e7b29cf5468bfb341175d4829c0f7','\'Title: CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Saturday, Aug 8, 12:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

CYBERCLAW is an interactive card-based wargaming experience for novice and advanced cyber professionals that will require participants to solve maritime security challenges in the GIUK region which align with MHV’s theme for the event, “Contested Communications”. During DC34, MHV will be co-hosting the CYBERCLAW (Cybersecurity Card-based Learning And Wargaming) wargame with its creators from the strongest navies on the seas.

\n\nSpeakerBio:  Wargame Guru, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298181),('3_Saturday','13','12:00','13:30','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_162e7b29cf5468bfb341175d4829c0f7','\'\'',NULL,1298182),('3_Saturday','14','14:00','15:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_cc5b4caaf68ad5df0ce7dac18cba407e','\'Title: CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Saturday, Aug 8, 14:00 - 15:30 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

CYBERCLAW is an interactive card-based wargaming experience for novice and advanced cyber professionals that will require participants to solve maritime security challenges in the GIUK region which align with MHV’s theme for the event, “Contested Communications”. During DC34, MHV will be co-hosting the CYBERCLAW (Cybersecurity Card-based Learning And Wargaming) wargame with its creators from the strongest navies on the seas.

\n\nSpeakerBio:  Wargame Guru, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298183),('3_Saturday','15','14:00','15:30','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_cc5b4caaf68ad5df0ce7dac18cba407e','\'\'',NULL,1298184),('3_Saturday','16','16:00','17:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_388437792c1f9774867caeac24cbca5f','\'Title: CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Saturday, Aug 8, 16:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

CYBERCLAW is an interactive card-based wargaming experience for novice and advanced cyber professionals that will require participants to solve maritime security challenges in the GIUK region which align with MHV’s theme for the event, “Contested Communications”. During DC34, MHV will be co-hosting the CYBERCLAW (Cybersecurity Card-based Learning And Wargaming) wargame with its creators from the strongest navies on the seas.

\n\nSpeakerBio:  Wargame Guru, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298185),('3_Saturday','17','16:00','17:30','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_388437792c1f9774867caeac24cbca5f','\'\'',NULL,1298186),('4_Sunday','10','10:30','11:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_e86d9f65655c1909604487110aeb1d29','\'Title: CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

CYBERCLAW is an interactive card-based wargaming experience for novice and advanced cyber professionals that will require participants to solve maritime security challenges in the GIUK region which align with MHV’s theme for the event, “Contested Communications”. During DC34, MHV will be co-hosting the CYBERCLAW (Cybersecurity Card-based Learning And Wargaming) wargame with its creators from the strongest navies on the seas.

\n\nSpeakerBio:  Wargame Guru, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298187),('4_Sunday','11','10:30','11:59','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_e86d9f65655c1909604487110aeb1d29','\'\'',NULL,1298188),('4_Sunday','12','12:30','13:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_fdbecb44d250d6f0cbc7b4c6dab4dc43','\'Title: CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Sunday, Aug 9, 12:30 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

CYBERCLAW is an interactive card-based wargaming experience for novice and advanced cyber professionals that will require participants to solve maritime security challenges in the GIUK region which align with MHV’s theme for the event, “Contested Communications”. During DC34, MHV will be co-hosting the CYBERCLAW (Cybersecurity Card-based Learning And Wargaming) wargame with its creators from the strongest navies on the seas.

\n\nSpeakerBio:  Wargame Guru, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298189),('4_Sunday','13','12:30','13:59','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_fdbecb44d250d6f0cbc7b4c6dab4dc43','\'\'',NULL,1298190),('2_Friday','12','12:00','13:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_bf64a9980f022338d85350826c2e2881','\'Title: CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Friday, Aug 7, 12:00 - 13:30 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

CYBERCLAW is an interactive card-based wargaming experience for novice and advanced cyber professionals that will require participants to solve maritime security challenges in the GIUK region which align with MHV’s theme for the event, “Contested Communications”. During DC34, MHV will be co-hosting the CYBERCLAW (Cybersecurity Card-based Learning And Wargaming) wargame with its creators from the strongest navies on the seas.

\n\nSpeakerBio:  Wargame Guru, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298191),('2_Friday','13','12:00','13:30','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_bf64a9980f022338d85350826c2e2881','\'\'',NULL,1298192),('2_Friday','16','16:00','17:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_532ae352d723873e085076416163f3e1','\'Title: CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Friday, Aug 7, 16:00 - 17:30 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

CYBERCLAW is an interactive card-based wargaming experience for novice and advanced cyber professionals that will require participants to solve maritime security challenges in the GIUK region which align with MHV’s theme for the event, “Contested Communications”. During DC34, MHV will be co-hosting the CYBERCLAW (Cybersecurity Card-based Learning And Wargaming) wargame with its creators from the strongest navies on the seas.

\n\nSpeakerBio:  Wargame Guru, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298193),('2_Friday','17','16:00','17:30','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'CYBERCLAW (Cybersecurity Card-based Learning And Wargaming)\'','\'Wargame Guru\'','Creator Workshops_532ae352d723873e085076416163f3e1','\'\'',NULL,1298194),('3_Saturday','10','10:30','11:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Digital Straits Wargame\'','\'Jason Vogt\'','Creator Workshops_f577755d22dd9186d7fbbbf25777cd30','\'Title: Digital Straits Wargame
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

\"Digital Straits\" is an interactive wargame developed at the U.S. Naval War College (USNWC). It explores scenarios focused on Pacific contingencies, gray-zone maritime conflicts, and maintaining digital connectivity from subsurface assets to satellites during crisis and conflict, bridging the gap between academics, policymakers, and the special operations/naval communities by allowing participants to navigate complex geopolitical and technological situations.

\n\nSpeakerBio:  Jason Vogt, USNWC
\n

Jason Vogt is an assistant professor in the Strategic and Operational Research Department, Center for Naval Warfare Studies at the United States Naval War College. Professor Vogt is a cyber warfare and wargaming expert. He has participated in the development of multiple wargames at the United States Naval War College. He previously served on active duty as an Army officer.

\n\n\n\'',NULL,1298195),('3_Saturday','11','10:30','11:59','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Digital Straits Wargame\'','\'Jason Vogt\'','Creator Workshops_f577755d22dd9186d7fbbbf25777cd30','\'\'',NULL,1298196),('2_Friday','10','10:30','11:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Digital Straits Wargame\'','\'Jason Vogt\'','Creator Workshops_9be076279fe53096e198b8637150239d','\'Title: Digital Straits Wargame
\nTags: Maritime Hacking Village | Creator Workshop
\nWhen: Friday, Aug 7, 10:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

\"Digital Straits\" is an interactive wargame developed at the U.S. Naval War College (USNWC). It explores scenarios focused on Pacific contingencies, gray-zone maritime conflicts, and maintaining digital connectivity from subsurface assets to satellites during crisis and conflict, bridging the gap between academics, policymakers, and the special operations/naval communities by allowing participants to navigate complex geopolitical and technological situations.

\n\nSpeakerBio:  Jason Vogt, USNWC
\n

Jason Vogt is an assistant professor in the Strategic and Operational Research Department, Center for Naval Warfare Studies at the United States Naval War College. Professor Vogt is a cyber warfare and wargaming expert. He has participated in the development of multiple wargames at the United States Naval War College. He previously served on active duty as an Army officer.

\n\n\n\'',NULL,1298197),('2_Friday','11','10:30','11:59','Y','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'Digital Straits Wargame\'','\'Jason Vogt\'','Creator Workshops_9be076279fe53096e198b8637150239d','\'\'',NULL,1298198),('3_Saturday','10','10:00','10:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'MHV 101\'','\'KennethSalt\'','Creator Talks_04ef5b01dfb1a5df53f0ec78f97c9b63','\'Title: MHV 101
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

YO HO! The Maritime Hacking Village (MHV) has set sail for LVCC to deliver the best and only immersive maritime hacking experience for you to learn what it takes to exploit and defend real-world maritime systems. Experience a weekend of immersive hacking experiences at MHV full of hands-on training and education on the depths of maritime technology and security.

\n\n

Join us to learn about what MHV has to offer, so we can help you get oriented and engaged in a weekend of unprecedented maritime hacking experiences and real life cyber pirate shenanigans.

\n\nSpeakerBio:  KennethSalt, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298199),('2_Friday','10','10:00','10:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'MHV 101\'','\'KennethSalt\'','Creator Talks_ab8f7d8cdfe7dd13b84ff44237b83c76','\'Title: MHV 101
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

YO HO! The Maritime Hacking Village (MHV) has set sail for LVCC to deliver the best and only immersive maritime hacking experience for you to learn what it takes to exploit and defend real-world maritime systems. Experience a weekend of immersive hacking experiences at MHV full of hands-on training and education on the depths of maritime technology and security.

\n\n

Join us to learn about what MHV has to offer, so we can help you get oriented and engaged in a weekend of unprecedented maritime hacking experiences and real life cyber pirate shenanigans.

\n\nSpeakerBio:  KennethSalt, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298200),('2_Friday','17','17:30','17:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'MHV CTF Recap - Day 1\'','\'KennethSalt\'','Creator Talks_7598d39f1dcc8f4aef691c159803ea45','\'Title: MHV CTF Recap - Day 1
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

Let\'s see where the teams and contestants of the MHV CTF drop anchor at the end of Day 1! A review of the current leaderboard and players still in the race to survive the contested comms environment!

\n\nSpeakerBio:  KennethSalt, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298201),('3_Saturday','17','17:30','17:59','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'MHV CTF Recap - Day 2\'','\'KennethSalt\'','Creator Talks_68481edfd5d26bb315cbb0a747355408','\'Title: MHV CTF Recap - Day 2
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

Let\'s see where the teams and contestants of the MHV CTF drop anchor at the end of Day 1! A review of the current leaderboard and players still in the race to survive the contested comms environment!

\n\nSpeakerBio:  KennethSalt, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298202),('4_Sunday','14','14:00','14:30','N','Maritime Hacking Village','LVCCW Level 1 Hall 2 703 (Maritime Hacking Village)','\'MHV CTF - Closing and Awards\'','\'KennethSalt,Duncan Woodbury\'','Creator Talks_4e3d6d7a6ed0cafc056f4827cbee5c7f','\'Title: MHV CTF - Closing and Awards
\nTags: Maritime Hacking Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 14:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 2 703 (Maritime Hacking Village) - Map
\n
\nDescription:
\n

Join us for the closing ceremonies and awards to the winners and top 3 teams ranked in the MHV CTF!

\n\nSpeakers:KennethSalt,Duncan Woodbury
\n
\nSpeakerBio:  KennethSalt, Maritime Hacking Village
\nNo BIO available
\nSpeakerBio:  Duncan Woodbury, Maritime Hacking Village
\nNo BIO available
\n\n\'',NULL,1298203),('2_Friday','10','10:00','10:30','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Q-CTF Introduction\'','\'Quantum Villagers\'','Creator Talks_94e9afbd7b96eebf7b985e81479a57ed','\'Title: The Q-CTF Introduction
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:30 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\nOnboarding: How to get started with the Quantum Capture the Flag, for N00bs and Experts alike!
\n\n\n\nSpeakerBio:  Quantum Villagers, Quantum Village
\nNo BIO available
\n\nLinks:
    qctf.quantumvillage.org/ - https://qctf.quantumvillage.org/
\n\'',NULL,1298204),('2_Friday','11','11:00','11:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Hard Take Off: Why linear intuition often underestimates risks in exponential technologies\'','\'Taylor Hartley\'','Creator Talks_96ab179e108ea2235589370d895f7d5f','\'Title: The Hard Take Off: Why linear intuition often underestimates risks in exponential technologies
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

Quantum risk is shaped by the compounding relationship between hardware, error correction, and computation.

\n\n

This session explores how organizations should think about quantum computing risk beyond the usual debates about “Q-Day” timelines. Rather than focusing on speculative predictions, Taylor will introduce a practical framework for understanding how cryptographic risk emerges from the interaction of three factors: quantum hardware scale, error correction, and the computational depth that fault-tolerant systems can sustain..

\n\n

Attendees will leave with a clear mental model for evaluating quantum risk.

\n\nSpeakerBio:  Taylor Hartley, Terra Quantum
\n

Taylor Hartley is the Global Head of Security at Terra Quantum, leading global security and trust strategy to enable secure adoption of quantum technologies across enterprise and government environments.\nShe designs and implements post-quantum cryptographic solutions in high-security environments and leads cross-functional efforts spanning product, engineering, research, and go-to-market teams.\nTaylor is an expert in post-quantum cryptography (PQC), Quantum Key Distribution (QKD), and cryptographic inventorying, with a focus on building scalable, secure, and user-centric cryptographic products.\nPrior to Terra Quantum, she led cybersecurity and government collaboration efforts at Ericsson and served 8 years in the U.S. Navy specializing in military intelligence and wireless communications signals.

\n\n\n\'',NULL,1298205),('2_Friday','13','13:00','14:30','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Project Stardust: Hacking Quantum Diamonds with Micropython and the Raspberry Pi Pico 2\'','\'Theresa O\'Connor,Brian McDermott\'','Creator Workshops_74235a12bbb5039b0d2b881ba71d9c31','\'Title: Project Stardust: Hacking Quantum Diamonds with Micropython and the Raspberry Pi Pico 2
\nTags: Quantum Village | Creator Workshop
\nWhen: Friday, Aug 7, 13:00 - 14:30 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

In this workshop, we walk through implementing the Uncut Gem design using a Raspberry Pi Pico 2, micropython, and other low-cost components.

\n\n

This session will include an intro into the \n1. Background, why quantum sensors, why make them cheap?\n2. Physics - What are NV centers, spin resonance, photoexcitation, and fluoresence?\n3. ODMR Protocols - Initialization, resonance, excitation, measurement. Pulse vs. continuous wave. Description of the photoemission model that was developed and how that translates to photocurrent on the diode.\n4. System architecture - Photonics hardware, Pico 2 controller, signal generator, detection system.\n5. Photonics module - Laser, lenses, diamond physics package, filters, photodetector\n6. Signal Generator - ADF4351 module, registers, micropython library\n7. Photodetection circuit - BPW34, transimpedance amplifier\n8. Microcontroller algorithm - Signal sweep and photodetector polling.\n9. Suggested improvements - Lock-in detection/filtering with AD630 and/or digital signal processing. Modular optics. RF design. Pulse mode operation.

\n\nSpeakers:Theresa O\'Connor,Brian McDermott
\n
\nSpeakerBio:  Theresa O\'Connor, Rensselaer Polytechnic Institute (RPI)
\n

Theresa is a rising senior at RPI studying Computer Systems Engineering. She runs open-source silicon workshops aimed at proving that chip design is nothing more than a form of very expensive sand art, and has successfully corrupted more than 50 hackers into taping out custom ASICs.

\n\nSpeakerBio:  Brian McDermott, Rensselaer Polytechnic Institute (RPI)
\n

Brian is a visiting professor at Rensselaer Polytechnic Institute with over a decade of industry experience in instrumentation development, high performance computing, and quantum engineering. A hacker from birth, Brian builds low-cost versions of high-tech devices that are accessible to students and hobbyists.

\n\n\n\'',NULL,1298206),('2_Friday','14','13:00','14:30','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Project Stardust: Hacking Quantum Diamonds with Micropython and the Raspberry Pi Pico 2\'','\'Theresa O\'Connor,Brian McDermott\'','Creator Workshops_74235a12bbb5039b0d2b881ba71d9c31','\'\'',NULL,1298207),('2_Friday','14','14:30','16:30','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Quantum Hardware Visualization for Fabricating the Future & Nanoscience Education Using Navajo (Diné Bizaad) Linguistics \'','\'Onri Jay Benally\'','Creator Workshops_7ad47fc852c873e2dd4d1b0e28cfd3ba','\'Title: Quantum Hardware Visualization for Fabricating the Future & Nanoscience Education Using Navajo (Diné Bizaad) Linguistics
\nTags: Quantum Village | Creator Workshop
\nWhen: Friday, Aug 7, 14:30 - 16:30 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

Quantum workforce development requires a growing familiarity with quantum science vocabulary, which can be combined in a powerful way with open source visualization tools like Blender. Consequently, it is possible to display quantum research hardware in three dimensions and provide educational material to describe their properties and functions in virtually any language, prior to hands-on training. One of those languages is Navajo/Navaho (Diné Bizaad), spoken primarily in the southwestern United States. Because the Navajo language relies heavily on adjectives, verbs, and geometry to describe everyday objects and events, the formation of translated terminology is highly intuitive and can be used to garner interest in learning Indigenous North American languages while simultaneously exploring modern topics like nanoscience and quantum computing. Furthermore, mastering Blender for rendering device hardware is a transferable skill set for scientific research publication. \\n\\nThis talk will cover various modalities, including quantum spintronics and quantum computing systems, techniques such as silicon lithography and nano-fabrication, and how open source technologies such as Blender, Git, and a little bit of ingenuity can help to build these technologies in the open.

\n\nSpeakerBio:  Onri Jay Benally, NSF Fellow
\n

Hi, I’m Onri @OJB-Quantum. I\'m a Diné (Navaho) tribesman, 100% Indigenous American, doing PhD work on quantum computing chip hardware & beyond-CMOS quantum-adjacent memory devices based on advanced spintronics. I advocate for open source hardware & software technologies. Also, I create knowledge systems through GitHub repositories based on my expertise.\nMy areas of expertise include: electron-beam lithography, nanodevice engineering/patterning, quantum hardware systems engineering, materials integration, process engineering/development, idea generation, implementation, & demonstration. I\'m self-taught in practical electronics, mathematics, linguistics, & scientific computing. My interest is in sustainable quantum hardware engineering, nanofabrication engineering, quantum scientific computing, generative design, fractal geometry, & data-driven 3D modeling.\nI\'m a former Quantum Hardware Engineer at IBM Research, Yorktown Heights, New York. At IBM I advanced the scaling/ accuracy of quantum-centeric supercomputing via quantum-limited parametric amplifier superconducting materials research for high bandwidth quantum processors. I also generated extensive documentation on XLDs Bluefors dilution fridges & highly experimental processes on superconducting chiplet measurement automation. (This made me the 1st Native/ Indigenous American Quantum Hardware Engineer/ Quantum Computing Engineer). I’m currently leading a team of quantum hardware engineers on the integration of nature-inspired designs into quantum processor chips & cryogenic magnetic random-access memory made of sustainable metallic spintronic materials, in my nanofabrication facility (cleanroom). I spend a lot of time back & forth between my office & the cleanroom.

\n\n\nLinks:
    Github - https://github.com/OJB-Quantum
\n\'',NULL,1298208),('2_Friday','15','14:30','16:30','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Quantum Hardware Visualization for Fabricating the Future & Nanoscience Education Using Navajo (Diné Bizaad) Linguistics \'','\'Onri Jay Benally\'','Creator Workshops_7ad47fc852c873e2dd4d1b0e28cfd3ba','\'\'',NULL,1298209),('2_Friday','16','14:30','16:30','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Quantum Hardware Visualization for Fabricating the Future & Nanoscience Education Using Navajo (Diné Bizaad) Linguistics \'','\'Onri Jay Benally\'','Creator Workshops_7ad47fc852c873e2dd4d1b0e28cfd3ba','\'\'',NULL,1298210),('3_Saturday','10','10:00','11:30','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Ok, what actually is quantum? A dev-friendly introduction\'','\'Mike Dascal,Matt Gomez\'','Creator Workshops_3890ef1c9d49e71f80c55370cae5648f','\'Title: Ok, what actually is quantum? A dev-friendly introduction
\nTags: Quantum Village | Creator Workshop
\nWhen: Saturday, Aug 8, 10:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

Join an interactive workshop where quantum experts and non-quantum developers come together to create an accessible and accurate description of quantum information and quantum computing.

\n\nSpeakers:Mike Dascal,Matt Gomez
\n
\nSpeakerBio:  Mike Dascal
\n

While lecturing during my PhD, I tought introductory quantum theory and quantum information to a wide range of student audiences, including both STEM and non-STEM students. In my current role leading quantum at Fidelity, I\'m frequently asked to provide explainers to data scientists, developers, and non-technical audiences. Putting all this experience together I think I can create a solid first pass at this material, and when objections arise, I\'ll likely have possible alternative presentations up my sleeve to be offered and discussed.

\n\nSpeakerBio:  Matt Gomez
\nNo BIO available
\n\n\'',NULL,1298211),('3_Saturday','11','10:00','11:30','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Ok, what actually is quantum? A dev-friendly introduction\'','\'Mike Dascal,Matt Gomez\'','Creator Workshops_3890ef1c9d49e71f80c55370cae5648f','\'\'',NULL,1298212),('3_Saturday','11','11:30','11:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Will Quantum Computers Break The Internet?\'','\'John Martinis\'','Creator Talks_5d13cb5717a3a7070f9e74bc44fd8496','\'Title: Will Quantum Computers Break The Internet?
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

Because of recent advances in quantum computing, there is now much promotion suggesting that quantum computers could break RSA and ECC in the next 3-5 years. I will discuss what is behind this prediction / hype. I will also discuss the solution: how quantum-safe encryption protocols are being developed by the US government and companies

\n\nSpeakerBio:  John Martinis, Qolab/ UC Santa Barbara
\n

Emeritus professor, UC Santa Barbara\nCTO of qolab.ai, a superconducting qubit startup\nNobel prize in Physics, 2025

\n\n\nLinks:
    en.wikipedia.org/wiki/John_M._Martinis - https://en.wikipedia.org/wiki/John_M._Martinis
\n\'',NULL,1298213),('3_Saturday','12','12:00','12:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Q&A with a Nobel Laureate and one of the Greatest Experimentalists of our time\'','\'John Martinis\'','Creator Talks_bf22f6640743af8bdb3eec3c9e32f32e','\'Title: Q&A with a Nobel Laureate and one of the Greatest Experimentalists of our time
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

This is the greateset opportunity for you to get your burning questions about the future of all things quantum - what it means for security, society, and beyond - from an internationally recognized, Nobel Prize winning expert!

\n\nSpeakerBio:  John Martinis, Qolab/ UC Santa Barbara
\n

Emeritus professor, UC Santa Barbara\nCTO of qolab.ai, a superconducting qubit startup\nNobel prize in Physics, 2025

\n\n\nLinks:
    en.wikipedia.org/wiki/John_M._Martinis - https://en.wikipedia.org/wiki/John_M._Martinis
\n\'',NULL,1298214),('3_Saturday','14','14:00','14:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Quantum Plus AI: The Joe Rogan Inexperience\'','\'Konstantinos Karagiannis\'','Creator Talks_e7b492bc825f5559d0fb74966c04a18f','\'Title: Quantum Plus AI: The Joe Rogan Inexperience
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

Joe Rogan has said a lot of things about quantum computers on his podcast. Almost none of them survive contact with a whiteboard. Konstantinos Karagiannis (@KonstantHacker) torches some of Rogan’s greatest hits: \"quantum will mean no more privacy ever again,\" \"but when AI runs on a quantum computer…,\" with fast debunks. This podcaster was right about one thing. AI is going to change everything about the race to Q-Day. AI for quantum is already optimizing the stack and mitigating errors, and it might just sharpen Shor\'s algorithm approaches. We’ll also look at how frontier models might accelerate the practical execution or delivery of quantum attacks.

\n\nSpeakerBio:  Konstantinos Karagiannis, Protiviti
\nNo BIO available
\n\nLinks:
    LinkedIn - https://www.linkedin.com/in/konstantinos-karagiannis-0a09503/
\n\'',NULL,1298215),('3_Saturday','15','15:00','15:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'ECDSA.fail: Beating Google’s Hidden Quantum Circuit with Open, Verifiable Autoresearch\'','\'Soubhik Deb\'','Creator Talks_5b36af541304f4fa97b08c6f92e2db44','\'Title: ECDSA.fail: Beating Google’s Hidden Quantum Circuit with Open, Verifiable Autoresearch
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

In March 2026, Google Quantum AI announced substantially lower resource estimates for applying Shor’s algorithm to the 256-bit elliptic-curve discrete-logarithm problem. The underlying logical circuits were withheld, but Google published zero-knowledge proofs attesting to two secp256k1 point-addition circuits: a low-width construction bounded by 1,175 logical qubits and 2.7 million non-Clifford operations, and a low-gate construction bounded by 1,425 logical qubits and 2.1 million non-Clifford operations. At Eigen Labs, we asked a very DEF CON question. Can an implementation remain meaningfully secret once its interface, verifier, and resource bounds are public?

\n\n

We built ECDSA.fail, an open autoresearch benchmark for the quantum attacks on elliptic-curve cryptography. The target is not an end-to-end Bitcoin attack, each submission emits a circuit in Google’s classically simulable kickmix model, which supports Clifford operations.

\n\n

A separate trusted evaluator treats the emitted operation stream as untrusted input. Valid circuits are scored by the product of their logical-qubit width and average executed CCX-plus-CCZ count. This objective is not a complete physical-resource model, but it exposes the central optimization tension between quantum memory and expensive non-Clifford computation. The public repository, reproducible evaluator, shared research notes, and continuously updated frontier allow humans and autonomous coding agents to inspect previous attempts and immediately build on successful results.

\n\n

Within eight hours, the open network matched Google’s concealed qubit–Toffoli bound. In roughly 72 hours, it surpassed it. This talk will present the benchmark architecture, the finite-field and uncomputation bottlenecks exposed by the search, the security engineering required to make agent-generated circuits safely executable. We will also examine a broader DEF CON question: when research artifacts are machine-verifiable and optimization can be massively parallelized across humans and agents, how long can a hidden algorithmic advantage remain an advantage?

\n\nSpeakerBio:  Soubhik Deb, Eigen Labs
\n

I am Head of Research at Eigen Labs.\nThe central principle of my work over the last decade has been building open networks that maximize human agency. In product terms, this takes the form of three properties that everything I have worked on has strived for:\nPermissionless: Empower anyone to build and deploy artifacts — software, capital, and the outputs of intelligence — at internet scale, without asking permission.\nAttribution: Programmatic credit assignment, so that value generated and captured by those artifacts flows back to the contributions that produced them.\nAccountability: Programmatic guardrails against adversarial behavior — a risk that is even more acute in open networks — with penalties proportional to the harm caused.

\n\n\nLinks:
    eigenlabs.org - https://eigenlabs.org
\n\'',NULL,1298216),('3_Saturday','16','16:30','17:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Quantum Village Debates\'','\'Bob Gourley\'','Creator Talks_3e6612ed60751d80a7866c7b75cca7fa','\'Title: Quantum Village Debates
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:30 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

The Quantum Village Debates return, come discuss,debate and challenge the notions holding back hackers in our shared quantum future as we challenge ideas with rhetoric and rigour

\n\nSpeakerBio:  Bob Gourley, OODA
\n

Bob Gourley is an experienced CTO, Board Qualified Technical Executive (QTE), and researcher with a career dedicated to advancing technology, security, and decision-making. As a co-founder of the OODA Network, Bob enables a community of global experts, executives, and innovators focused on navigating disruption, emerging technologies, and global risks. The OODA Network provides both government and industry members with exclusive insights, research, and networking opportunities to enhance decision-making and drive innovation. Bob is the author of the Amazon bestseller Dragon Falls: Standing up to Beijing\'s Shadow War, which is based on real world PRC espionage and cyber tradecraft and realistic Agentic AI and open source intelligence. Served as a Naval Intelligence officer, and was a CTO at TRW and Northrup Grumman and the Defense Intelligence Agency.

\n\n\n\'',NULL,1298217),('3_Saturday','17','16:30','17:59','Y','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Quantum Village Debates\'','\'Bob Gourley\'','Creator Talks_3e6612ed60751d80a7866c7b75cca7fa','\'\'',NULL,1298218),('4_Sunday','10','10:00','10:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'A remote fault-injection on quantum computer controller algorithms demo\'','\'Jakub Szefer\'','Creator Workshops_bfb2cf40e8c3d91dcedb850335e0f56d','\'Title: A remote fault-injection on quantum computer controller algorithms demo
\nTags: Quantum Village | Creator Workshop
\nWhen: Sunday, Aug 9, 10:00 - 10:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Jakub Szefer, Northwestern University
\n

Jakub Szefer is a computer scientist and electrical engineer, currently an associate professor of Electrical and Computer Engineering at Northwestern University. Prior to joining Northwestern, Szefer was an associate professor of Electrical & Computer Engineering & Computer Science at Yale University, where he also served as the director of the Computer Architecture and Security Lab. His research focuses on securing cloud-based computing systems, including classical processors, machine learning accelerators, and quantum computing systems.

\n\n\n\'',NULL,1298219),('4_Sunday','11','11:00','11:30','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Quantum Networks from the Hacker Perspective\'','\'Alex Radocea\'','Creator Talks_c6434bb825ad9457d3bc5b6b0703aee1','\'Title: Quantum Networks from the Hacker Perspective
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:30 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Alex Radocea
\n

Founder of Supernetworks and cofounder of Longterm Security. Alex started in security pentesting financial firms on Wall Street at Matasano and cofounded RPISEC at RPI. He has worked on Apple\'s Product Security team, engineering at CrowdStrike, and Spotify\'s Security team. His research — presented at Black Hat and REcon — spans mobile messenger cryptography, kernel security, binary static analysis, and browser hardening, including the discovery of critical flaws in Apple\'s iCloud Keychain.

\n\n\n\'',NULL,1298220),('4_Sunday','11','11:30','11:59','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'Entropy Loop: Difussion Unphased\'','\'Eric Case,Large Cardinal\'','Creator Workshops_137405ef0b815a17c80d8bdf2f40e028','\'Title: Entropy Loop: Difussion Unphased
\nTags: Quantum Village | Creator Workshop
\nWhen: Sunday, Aug 9, 11:30 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n

Building a fully open source phase diffusion quantum entropy source using fully off the shelf parts for ~$35; from design, to planning, to testing, to building one out of spare parts in a desert! Ultra-low cost quantum for all!

\n\nSpeakers:Eric Case,Large Cardinal
\n
\nSpeakerBio:  Eric Case, Quantum Village
\n

Eric Case is a controls and operational technology engineer with more than 22 years of experience designing, programming, and integrating building automation, PLC, and ICS environments for critical-infrastructure systems. His work sits at the intersection of physical infrastructure, industrial cybersecurity, resilient control design, and emerging technology. Eric is currently expanding his work into OT cybersecurity and quantum-enabled sensing & security, including the help in development of a low-cost quantum random number generator for Quantum village and quantum sensing platform designed for practical use in industrial, embedded, and critical-infrastructure environments. He holds the RCDD, SSCP, Security+, Network+, and Project+ certifications and is pursuing a degree in cybersecurity and information assurance with plans for FE in CS/EE and masters in cyber physical hardware systems. He is especially interested in how cyberattacks cross the boundary from IT / OT digital systems into physical consequences—and how engineers can design systems that remain safe when networks, field controllers, or data can no longer be trusted.

\n\nSpeakerBio:  Large Cardinal
\n

Large Cardinal is a mathematician and Quantum Hacker. Working at the bleeding edge of technology for two decades, he has presented on an array of topics stemming from his work on quantum computation, machine learning, cryptography and cybersecurity data science. He holds patents in post-quantum cryptography and regularly publishes articles, papers, and has regular media appearances focusing on future-proofing our tech stacks, and the humans that maintain them.\nHe is a former professional violinist, and is a logician with a PhD in computability theory and tilings, he is the co-founder and CTO of Quantum Village.

\n\n\n\'',NULL,1298221),('4_Sunday','12','12:00','12:20','N','Quantum Village','LVCCW Level 1 Hall 2 605 (Quantum Village)','\'The Quantum-CTF Winners Announced\'','\'\'','Creator Talks_d0d434dfe846bc2ddfd16ee0b10eda61','\'Title: The Quantum-CTF Winners Announced
\nTags: Quantum Village | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 12:00 - 12:20 PDT
\nWhere: LVCCW Level 1 Hall 2 605 (Quantum Village) - Map
\n
\nDescription:
\n\n\n\'',NULL,1298222),('2_Friday','11','11:00','11:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'Random Cool Things from postmarketOS (a linux-based mobile OS)\'','\'Ranny Bergamotte\'','Creator Talks_5a0300583c1a35c090ad07e120595d69','\'Title: Random Cool Things from postmarketOS (a linux-based mobile OS)
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Ranny Bergamotte, PostmarketOS
\nNo BIO available
\n\n\'',NULL,1298223),('2_Friday','12','12:00','12:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'Chasing Zero CVEs: When Clean Scans Meet Real Applications\'','\'Matt Micene\'','Creator Talks_6603e93a8588618e35777ceee06afb59','\'Title: Chasing Zero CVEs: When Clean Scans Meet Real Applications
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Matt Micene, RHEL
\nNo BIO available
\n\n\'',NULL,1298224),('2_Friday','14','14:00','14:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'Introduction to x86 virtualization: VTx\'','\'Diego Porras\'','Creator Talks_e3d5d165a753bddc391d5c2f407b27ad','\'Title: Introduction to x86 virtualization: VTx
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Diego Porras, Churro
\nNo BIO available
\n\n\'',NULL,1298225),('2_Friday','15','15:00','15:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'The Right to Repair (and hack) your OS\'','\'Connor Costigan\'','Creator Talks_2f4d14e6052bc7122e731fb28c70fb10','\'Title: The Right to Repair (and hack) your OS
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Connor Costigan, BlackHills
\nNo BIO available
\n\n\'',NULL,1298226),('2_Friday','16','16:00','16:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'Don’t waste your silicon: how optimized software can run 40% faster\'','\'palinuro\'','Creator Talks_8c0f74cb9d09f9a4988227f86bdf12c5','\'Title: Don’t waste your silicon: how optimized software can run 40% faster
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  palinuro, ParrotSec
\nNo BIO available
\n\n\'',NULL,1298227),('2_Friday','17','17:00','17:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'Weights: {-1, 0, 1} - or: how a Soviet computer from 1958 predicted the future of AI\'','\'Steev\'','Creator Talks_e721a01ecf55c7e73116f63539ebf0ad','\'Title: Weights: {-1, 0, 1} - or: how a Soviet computer from 1958 predicted the future of AI
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Steev, ParrotSec
\nNo BIO available
\n\n\'',NULL,1298228),('3_Saturday','11','11:00','11:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'Hardening Linux : A Triple-Threat Approach: SELinux, FAPolicyd, and AuditD\'','\'Joshua Loscar\'','Creator Talks_dba0c3598cecea96dd3e1ec0ae89137e','\'Title: Hardening Linux : A Triple-Threat Approach: SELinux, FAPolicyd, and AuditD
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Joshua Loscar, RHEL
\nNo BIO available
\n\n\'',NULL,1298229),('3_Saturday','12','12:00','12:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'The Evolution of Digital Apex Predators: Building, Detecting, and Reverse Engineering Self-Replicating Worms\'','\'ek0ms savi0r\'','Creator Talks_62898b92e657443f22312d480ecb07b8','\'Title: The Evolution of Digital Apex Predators: Building, Detecting, and Reverse Engineering Self-Replicating Worms
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 12:00 - 12:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  ek0ms savi0r
\nNo BIO available
\n\n\'',NULL,1298230),('3_Saturday','14','14:00','14:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'Offensive Security Without the Franken-Laptop: Building Reproducible Toolbx Environments\'','\'Sean Rickerd\'','Creator Talks_1fb9ca92167f2d6008ed642893b52f06','\'Title: Offensive Security Without the Franken-Laptop: Building Reproducible Toolbx Environments
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Sean Rickerd, RHEL
\nNo BIO available
\n\n\'',NULL,1298231),('3_Saturday','15','15:00','15:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'From Dirty COW to Copy Fail: Ten Years of Linux Page-Cache Write Primitives\'','\'Bill Brousalis\'','Creator Talks_73c86fcdee5df6dda1707f90d04aae30','\'Title: From Dirty COW to Copy Fail: Ten Years of Linux Page-Cache Write Primitives
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 15:00 - 15:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Bill Brousalis, Hack The Box
\nNo BIO available
\n\n\'',NULL,1298232),('3_Saturday','16','16:00','16:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'Modern advances in kernel fuzzing\'','\'Hai Tederry\'','Creator Talks_4334376543eb5d0eadfb5124be7fb9d0','\'Title: Modern advances in kernel fuzzing
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Hai Tederry
\nNo BIO available
\n\n\'',NULL,1298233),('3_Saturday','17','17:00','17:45','N','Operating Systems Community','LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community))','\'Controlling our devices: linux on mobile\'','\'Ranny Bergamotte\'','Creator Talks_82a83effa71bab68816d6783076513b5','\'Title: Controlling our devices: linux on mobile
\nTags: Operating Systems Community | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 17:00 - 17:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1308 (Operating Systems Community (OS Community)) - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Ranny Bergamotte, PostmarketOS
\nNo BIO available
\n\n\'',NULL,1298234),('2_Friday','10','10:00','13:59','N','Contests','Online','\'Hack the Box CTF: Data Dystopia\'','\'\'','Contests_75babf842cf86a3ca1bd56ad46c9616e','\'Title: Hack the Box CTF: Data Dystopia
\nTags: HTB CTF: Data Dystopia | Contest
\nWhen: Friday, Aug 7, 10:00 - 13:59 PDT
\nWhere: Online
\n
\nDescription:
\n

Hack The Box is the leading cyber readiness platform for the agentic era, battle-testing and upskilling both humans and AI agents to enhance organizational cyber resilience.\nHTB\'s CTFs offer a great opportunity to get exposed to a plethora of challenge categories and difficulty levels, all backed by a big community ready to support, or just hang out.

\n\n

You can find a link to the online CTF attached to this event. We will provide the password to join onsite in our booth and it will also be displayed on stand-up banners in our area.

\n\n

Participant Prerequisites

\n\n

Laptop

\n\nLinks:
    Website - https://ctf.hackthebox.com/event/details/data-dystopia-ctf-2026-manhunt-3516
\n\'',NULL,1298235),('2_Friday','11','10:00','13:59','Y','Contests','Online','\'Hack the Box CTF: Data Dystopia\'','\'\'','Contests_75babf842cf86a3ca1bd56ad46c9616e','\'\'',NULL,1298236),('2_Friday','12','10:00','13:59','Y','Contests','Online','\'Hack the Box CTF: Data Dystopia\'','\'\'','Contests_75babf842cf86a3ca1bd56ad46c9616e','\'\'',NULL,1298237),('2_Friday','13','10:00','13:59','Y','Contests','Online','\'Hack the Box CTF: Data Dystopia\'','\'\'','Contests_75babf842cf86a3ca1bd56ad46c9616e','\'\'',NULL,1298238),('3_Saturday','10','10:00','13:59','N','Contests','Online','\'Hack the Box CTF: Data Dystopia\'','\'\'','Contests_401b951b34ef4715d269dfe115d500cf','\'Title: Hack the Box CTF: Data Dystopia
\nTags: HTB CTF: Data Dystopia | Contest
\nWhen: Saturday, Aug 8, 10:00 - 13:59 PDT
\nWhere: Online
\n
\nDescription:
\n

Hack The Box is the leading cyber readiness platform for the agentic era, battle-testing and upskilling both humans and AI agents to enhance organizational cyber resilience.\nHTB\'s CTFs offer a great opportunity to get exposed to a plethora of challenge categories and difficulty levels, all backed by a big community ready to support, or just hang out.

\n\n

You can find a link to the online CTF attached to this event. We will provide the password to join onsite in our booth and it will also be displayed on stand-up banners in our area.

\n\n

Participant Prerequisites

\n\n

Laptop

\n\nLinks:
    Website - https://ctf.hackthebox.com/event/details/data-dystopia-ctf-2026-manhunt-3516
\n\'',NULL,1298239),('3_Saturday','11','10:00','13:59','Y','Contests','Online','\'Hack the Box CTF: Data Dystopia\'','\'\'','Contests_401b951b34ef4715d269dfe115d500cf','\'\'',NULL,1298240),('3_Saturday','12','10:00','13:59','Y','Contests','Online','\'Hack the Box CTF: Data Dystopia\'','\'\'','Contests_401b951b34ef4715d269dfe115d500cf','\'\'',NULL,1298241),('3_Saturday','13','10:00','13:59','Y','Contests','Online','\'Hack the Box CTF: Data Dystopia\'','\'\'','Contests_401b951b34ef4715d269dfe115d500cf','\'\'',NULL,1298242),('3_Saturday','14','14:00','14:59','N','Game Hacking Village','LVCCW Level 1 Hall 1 211 (Game Hacking Village)','\'Follow-Up and Live Q&A: Catching Cheaters in Super Smash Bros Melee\'','\'AltF4\'','Creator Talks_8e149b5f82dede39a769429d24b8b01d','\'Title: Follow-Up and Live Q&A: Catching Cheaters in Super Smash Bros Melee
\nTags: Game Hacking Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 14:00 - 14:59 PDT
\nWhere: LVCCW Level 1 Hall 1 211 (Game Hacking Village) - Map
\n
\nDescription:
\n

Super Smash Bros Melee for the Nintendo GameCube is one of the oldest active fighting game communities, with a storied 25 year history.

\n\n

Would you believe that people try to cheat at it?!

\n\n

I am the maintainer of the SLP Enforcer tool, and help with cheating investigations for the community. I\'m going to share some stories of people trying to cheat and getting caught! Along the way I\'ll describe all the ways one could try to cheat at Melee, and how our detection tools work.

\n\nSpeakerBio:  AltF4
\n

Dan \"AltF4\" Petro is a Principal Security Engineer at Bishop Fox R&D. As a longtime pentester at Bishop Fox, Dan\'s presented public research on everything from hacking into smart safes, compromising the power grid, breaking into secure facilities, and cheating at online video games. There was even that time he found a vulnerability in (nearly) every IoT device. But Dan\'s favorite research project is always whichever is next.

\n\n\nLinks:
    Github - https://altf4.github.io/enforcer/
\n\'',NULL,1298243),('3_Saturday','11','11:00','11:59','N','AI Village','LVCCW Level 1 Hall 2 603 (AI Village)','\'Federated AI Agent Community Forum & DNS-AID Discovery Lab @ AI VIllage\'','\'\'','Creator Talks_b2db2914f3477043199d0b68171181b3','\'Title: Federated AI Agent Community Forum & DNS-AID Discovery Lab @ AI VIllage
\nTags: AI Village | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 2 603 (AI Village) - Map
\n
\nDescription:
\n

Meet and engage with fellow technologists for a drop-in event at AI Village to dive into practical realities of the agentic web. All comers to DEF CON 34 are welcome to join for a Federated AI Agent Community Forum & Discovery Lab on AI and DNS centered around the Linux Foundation\'s DNS-AID project. https://www.linuxfoundation.org/press/linux-foundation-announces-dns-aid-project-to-advance-decentralized-ai-agent-discovery

\n\n

No expertise in AI agents is needed, but basic DNS and AI familiarity is helpful. DNS-AID project members will facilitate Community Forum discussions around themes in AI, DNS, identity, discovery, and communication, with the Discovery Lab & demo repeating at intervals during the session. This event intentionally brings together networking, AI, open-source community, and governance professionals to look at the real technical underpinnings of the future of the internet. Please bring your own powered-up laptop with wifi connectivity to try out the lab, or prepare to watch the starter demo and try it at home.

\n\n

The Discovery Lab\nBuilding on the case for an open, interoperable agent web, this live lab turns Linux Foundation\'s DNS-AID project into something you can run end to end. In this 15-minute lab, you watch a Strands AI assistant discover, verify, and invoke a remote MCP capability—the federation\'s ip-reputation service—using DNS-AID, the IETF draft for AI agent discovery via DNS SVCB records. The agent finds the capability through DNS-AID, verifies its authenticity with DNSSEC and a JWS-signed capability document, and invokes it through agentgateway, the runtime enforcement layer.

\n\n

The lab demonstrates how the existing building blocks of the open web deliver deterministic, secure agent discovery without proprietary lock-in. The lab presents DNS-AID and ARD as parallel discovery planes over one shared trust chain, and pairs with a companion DNS-AID Workshop, a 90-minute AI-supply-chain incident-response exercise. The session runs in three parts: Tour the lab—inspect a federation runtime that has zero routes until DNS publishes one, then watch how it discovers, with DNS-AID and ARD running as parallel discovery planes.

\n\n

Publish—publish a single DNS-AID SVCB record alongside the ARD ai-catalog and watch agentgateway dynamically pick up the new route via xDS.

\n\n

Invoke—follow the same agent down two discovery paths and one trust chain: discover via DNS, fetch the capability doc from S3, verify DNSSEC,and invoke through the gateway.

\n\n\'',NULL,1298244),('2_Friday','11','11:00','11:59','N','DEF CON Academy','LVCCW Level 1 Hall 4 1305 (DEF CON Academy)','\'Hack With Us! - Terminal Basics\'','\'Adical\'','Creator Talks_7801f552f1c70b6e0abb292575a6f6e8','\'Title: Hack With Us! - Terminal Basics
\nTags: DEF CON Academy | Creator Talk/Panel
\nWhen: Friday, Aug 7, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1305 (DEF CON Academy) - Map
\n
\nDescription:
\n

New to the command line? This workshop will teach you the Unix fundamentals, including navigating files and directories, finding help with the man pages, and combining simple tools with pipes and redirection to solve complex problems. You’ll also learn the basics of processes, job control, and Bash scripting so you can start using the terminal with confidence.

\n\nSpeakerBio:  Adical
\nNo BIO available
\n\n\'',NULL,1298245),('2_Friday','16','16:00','16:59','N','DEF CON Academy','LVCCW Level 1 Hall 4 1305 (DEF CON Academy)','\'Getting into CTF\'','\'Alchemy1729\'','Creator Talks_16f9f6695d8296b1bd1d45296059cddd','\'Title: Getting into CTF
\nTags: DEF CON Academy | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1305 (DEF CON Academy) - Map
\n
\nDescription:
\n

Capture the Flag competitions are the fastest hands-on path into security. The challenges teach reverse engineering, binary exploitation, cryptography, and digital forensics by giving you problems to investigate, break, and solve. This talk covers how CTFs work, how to pick your first challenge, how to survive the stretch where nothing works, and why they matter for beginners and professionals alike.

\n\nSpeakerBio:  Alchemy1729
\nNo BIO available
\n\n\'',NULL,1298246),('3_Saturday','11','11:00','11:59','N','DEF CON Academy','LVCCW Level 1 Hall 4 1305 (DEF CON Academy)','\'Hack with Us! - Binary Exploitation\'','\'frqmod\'','Creator Talks_8e5497bbd777d8a63011a793fde05ed6','\'Title: Hack with Us! - Binary Exploitation
\nTags: DEF CON Academy | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1305 (DEF CON Academy) - Map
\n
\nDescription:
\n

Build your beginner binary exploitation toolkit in this session, basic knowledge of computer memory, C, and python is strongly recommended.

\n\nSpeakerBio:  frqmod
\nNo BIO available
\n\n\'',NULL,1298247),('3_Saturday','16','16:00','16:59','N','DEF CON Academy','LVCCW Level 1 Hall 4 1305 (DEF CON Academy)','\'Cybersecurity Career Paths\'','\'Zardus\'','Creator Talks_61138fa43d2f0521a173e802f375f1ef','\'Title: Cybersecurity Career Paths
\nTags: DEF CON Academy | Creator Talk/Panel
\nWhen: Saturday, Aug 8, 16:00 - 16:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1305 (DEF CON Academy) - Map
\n
\nDescription:
\n

So you\'ve played some CTF and looking to advance your career? In this session, a panel of cybersecurity experts across career paths will discuss their experiences in the industry and share advice for those getting started.

\n\nSpeakerBio:  Zardus
\nNo BIO available
\n\n\'',NULL,1298248),('4_Sunday','11','11:00','11:59','N','DEF CON Academy','LVCCW Level 1 Hall 4 1305 (DEF CON Academy)','\'Hack With Us! - Debugging\'','\'robwaz\'','Creator Talks_a8efa10b2be39b25875615e9ad41037a','\'Title: Hack With Us! - Debugging
\nTags: DEF CON Academy | Creator Talk/Panel
\nWhen: Sunday, Aug 9, 11:00 - 11:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1305 (DEF CON Academy) - Map
\n
\nDescription:
\n

Ever wanted to see what your program is really doing? This workshop introduces GDB, the debugger that lets you stop programs in their tracks, inspect memory and registers, and single-step through execution. Whether you’re hunting bugs or exploring unfamiliar code, GDB is one of the most powerful tools in a hacker’s toolkit.

\n\nSpeakerBio:  robwaz
\nNo BIO available
\n\n\'',NULL,1298249),('2_Friday','11','11:30','12:30','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Oh hai! Meet Cthulhu Answers ( ;,;)~\'','\'Cthulhu_Answers\'','Creator Events_0fb2a66bdffa251c44dd7d122e8fe9f2','\'Title: Oh hai! Meet Cthulhu Answers ( ;,;)~
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:30 - 12:30 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Ever lurked InfoSec Twitter too long & now you\'re afraid to say hi to anyone in real life? Same.

\n\n

But now\'s your moment: a whole room full of socially anxious hackers awkwardly saying hello—together. Come meet Twitter\'s favorite not-so-secret mystery, @Cthulhu_Answers

\n\nSpeakerBio:  Cthulhu_Answers
\nNo BIO available
\n\n\'',NULL,1298250),('2_Friday','12','11:30','12:30','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Oh hai! Meet Cthulhu Answers ( ;,;)~\'','\'Cthulhu_Answers\'','Creator Events_0fb2a66bdffa251c44dd7d122e8fe9f2','\'\'',NULL,1298251),('2_Friday','10','10:00','17:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_5f009ef8ea30cbcb9223be336bd95f34','\'Title: Breaking Secure - Agentic CTF
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Practice with vulnarable AI/LLM agents on vulnarable webapps, practice your prompt breaking, gain new security skills and tools.

\n\nSpeakers:Jon McCoy,Brandon Lachterman
\n
\nSpeakerBio:  Jon McCoy, Security Architect, OWASP
\n

Software security architect, Jon McCoy brings over 20 years of experience in software development and cybersecurity to the forefront. With a strong foundation in .NET development, Jon transitioned into security, driven by a passion for proactive defense strategies and secure coding practices.

\n\n

A dedicated contributor to the OWASP community, Jon has shared his expertise at numerous industry events, including OWASP Global AppSec. His recent presentation on \"Lessons Learned from Past Security Breaches\" highlighted critical takeaways for strengthening AppSec efforts before and after incidents.

\n\nSpeakerBio:  Brandon Lachterman
\nNo BIO available
\n\nLinks:
    Website - https://ainetguard.com/CTF-DefCon.html
\n\'',NULL,1298252),('2_Friday','11','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_5f009ef8ea30cbcb9223be336bd95f34','\'\'',NULL,1298253),('2_Friday','12','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_5f009ef8ea30cbcb9223be336bd95f34','\'\'',NULL,1298254),('2_Friday','13','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_5f009ef8ea30cbcb9223be336bd95f34','\'\'',NULL,1298255),('2_Friday','14','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_5f009ef8ea30cbcb9223be336bd95f34','\'\'',NULL,1298256),('2_Friday','15','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_5f009ef8ea30cbcb9223be336bd95f34','\'\'',NULL,1298257),('2_Friday','16','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_5f009ef8ea30cbcb9223be336bd95f34','\'\'',NULL,1298258),('2_Friday','17','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_5f009ef8ea30cbcb9223be336bd95f34','\'\'',NULL,1298259),('3_Saturday','10','10:00','17:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_765feb5f89e29dcbb78ac81c6e42ea73','\'Title: Breaking Secure - Agentic CTF
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Practice with vulnarable AI/LLM agents on vulnarable webapps, practice your prompt breaking, gain new security skills and tools.

\n\nSpeakers:Jon McCoy,Brandon Lachterman
\n
\nSpeakerBio:  Jon McCoy, Security Architect, OWASP
\n

Software security architect, Jon McCoy brings over 20 years of experience in software development and cybersecurity to the forefront. With a strong foundation in .NET development, Jon transitioned into security, driven by a passion for proactive defense strategies and secure coding practices.

\n\n

A dedicated contributor to the OWASP community, Jon has shared his expertise at numerous industry events, including OWASP Global AppSec. His recent presentation on \"Lessons Learned from Past Security Breaches\" highlighted critical takeaways for strengthening AppSec efforts before and after incidents.

\n\nSpeakerBio:  Brandon Lachterman
\nNo BIO available
\n\nLinks:
    Website - https://ainetguard.com/CTF-DefCon.html
\n\'',NULL,1298260),('3_Saturday','11','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_765feb5f89e29dcbb78ac81c6e42ea73','\'\'',NULL,1298261),('3_Saturday','12','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_765feb5f89e29dcbb78ac81c6e42ea73','\'\'',NULL,1298262),('3_Saturday','13','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_765feb5f89e29dcbb78ac81c6e42ea73','\'\'',NULL,1298263),('3_Saturday','14','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_765feb5f89e29dcbb78ac81c6e42ea73','\'\'',NULL,1298264),('3_Saturday','15','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_765feb5f89e29dcbb78ac81c6e42ea73','\'\'',NULL,1298265),('3_Saturday','16','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_765feb5f89e29dcbb78ac81c6e42ea73','\'\'',NULL,1298266),('3_Saturday','17','10:00','17:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_765feb5f89e29dcbb78ac81c6e42ea73','\'\'',NULL,1298267),('4_Sunday','10','10:00','13:59','N','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_87efcde90b77f335f2861971f024281f','\'Title: Breaking Secure - Agentic CTF
\nTags: OWASP Foundation | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1415 (OWASP Foundation) - Map
\n
\nDescription:
\n

Practice with vulnarable AI/LLM agents on vulnarable webapps, practice your prompt breaking, gain new security skills and tools.

\n\nSpeakers:Jon McCoy,Brandon Lachterman
\n
\nSpeakerBio:  Jon McCoy, Security Architect, OWASP
\n

Software security architect, Jon McCoy brings over 20 years of experience in software development and cybersecurity to the forefront. With a strong foundation in .NET development, Jon transitioned into security, driven by a passion for proactive defense strategies and secure coding practices.

\n\n

A dedicated contributor to the OWASP community, Jon has shared his expertise at numerous industry events, including OWASP Global AppSec. His recent presentation on \"Lessons Learned from Past Security Breaches\" highlighted critical takeaways for strengthening AppSec efforts before and after incidents.

\n\nSpeakerBio:  Brandon Lachterman
\nNo BIO available
\n\nLinks:
    Website - https://ainetguard.com/CTF-DefCon.html
\n\'',NULL,1298268),('4_Sunday','11','10:00','13:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_87efcde90b77f335f2861971f024281f','\'\'',NULL,1298269),('4_Sunday','12','10:00','13:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_87efcde90b77f335f2861971f024281f','\'\'',NULL,1298270),('4_Sunday','13','10:00','13:59','Y','OWASP Foundation','LVCCW Level 1 Hall 4 1415 (OWASP Foundation)','\'Breaking Secure - Agentic CTF\'','\'Jon McCoy,Brandon Lachterman\'','Creator Events_87efcde90b77f335f2861971f024281f','\'\'',NULL,1298271),('3_Saturday','13','13:45','14:45','N','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Rayhunter Meetup: Hunting Cell-Site Simulators\'','\'\'','Creator Events_dbfc31aedf9ba24bed13e0d8944f8f5a','\'Title: Rayhunter Meetup: Hunting Cell-Site Simulators
\nTags: IoT Village | Creator Event/Activity
\nWhen: Saturday, Aug 8, 13:45 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 1 215 (IoT Village) - Map
\n
\nDescription:
\n

Join us for an informal, hands-on introduction to Rayhunter, EFF’s open-source tool for identifying suspicious activity on cellular networks. We’ll cover the basics of cell-site simulators, often called Stingrays, how they can be used for surveillance by law enforcement, immigration authorities, and other government agencies, and why detecting their presence matters to hackers, researchers, journalists, and anyone interested in communications privacy.

\n\n

We’ll also demonstrate how to flash Rayhunter onto a supported mobile hotspot, discuss real-world findings and lessons from using it, and have several different Rayhunter devices available for attendees to explore. Cooper, one of Rayhunter’s lead developers, will join us for technical questions and open Q&A. No prior cellular or radio experience is required.

\n\n\'',NULL,1298272),('3_Saturday','14','13:45','14:45','Y','IoT Village','LVCCW Level 1 Hall 1 215 (IoT Village)','\'Rayhunter Meetup: Hunting Cell-Site Simulators\'','\'\'','Creator Events_dbfc31aedf9ba24bed13e0d8944f8f5a','\'\'',NULL,1298273),('3_Saturday','17','17:00','17:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Cliff Stoll\'','\'Cliff Stoll\'','Social Gatherings/Events_2430e4b20b697931e29637e5c67e8ffa','\'Title: Book Signing - Cliff Stoll
\nTags: Vendor Book Signing
\nWhen: Saturday, Aug 8, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Cliff Stoll, Acme Klein Bottle
\n

Cliff graduated from Buffalo Public School #61 with a blue star for good attendance. He’s since fooled around in planetary physics, computer security, and mathematical Klein bottles, with occasional detours into common sense.

\n\n\n\'',NULL,1298274),('3_Saturday','13','13:15','14:45','N','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Hacking Android Apps in a Structured Way (Part 2)\'','\'Sven Schleier\'','Creator Events_d8108ced7bdf418eeb698dfe1df4c871','\'Title: Hacking Android Apps in a Structured Way (Part 2)
\nTags: Mobile Hacking Community | Creator Event/Activity
\nWhen: Saturday, Aug 8, 13:15 - 14:45 PDT
\nWhere: LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community) - Map
\n
\nDescription:
\n

Mobile app testing has many pitfalls, and a structured approach is needed to see the full attack surface. This workshop gives a practical introduction to the OWASP Mobile Application Security (MAS) project — MASVS, MASWE, and MASTG — with hands-on static and dynamic analysis of real Android apps using tools like Frida and jadx. Bring a laptop with 10 GB free disk space, a GitHub account, Android Studio and git installed (see http://github.com/sushi2k/defcon34-android-workshop-saturday).

\n\nSpeakerBio:  Sven Schleier, Co-Founder at Bai7 GmbH
\n

Sven has been involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project lead and author, he has made significant contributions to the OWASP MAS (Mobile Application Security) project, which is considered the industry standard for mobile application security, see https://mas.owasp.org.

\n\n

Sven is a frequent speaker and trainer around the world. His audiences range from software developers to students and penetration testers. His engagements often take him to conferences, forums and educational institutions, where he shares his extensive knowledge and insights on mobile and application security.

\n\n

--

\n\n

Sven is a co-founder of Bai7 GmbH in Austria, which is specialized in trainings and advisory. He has expertise in cloud security, offensive security engagements (Penetration Testing) and Application Security, notably in guiding software development teams across Mobile and Web Applications throughout the Software Development Life Cycle (SDLC) to integrate robust security measures in from the start.

\n\n

Besides his day job, Sven is involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project leader and author, he has significantly contributed to the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Application Security Verification Standard (MASVS).

\n\n\n\'',NULL,1298275),('3_Saturday','14','13:15','14:45','Y','Mobile Hacking Community','LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)','\'Hacking Android Apps in a Structured Way (Part 2)\'','\'Sven Schleier\'','Creator Events_d8108ced7bdf418eeb698dfe1df4c871','\'\'',NULL,1298276),('2_Friday','13','13:15','14:15','N','Blue Team Village','LVCCW Level 2 W213-217 (Blue Team Village)','\'Watching Them Watch You Watch Them: A 101 Intro to Using AI for CTI\'','\'Daniela Zamfiroiu,Dimple Gajra\'','Creator Talks_fb204f03ebb01ff1a0726c81e23ca2c1','\'Title: Watching Them Watch You Watch Them: A 101 Intro to Using AI for CTI
\nTags: Blue Team Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 13:15 - 14:15 PDT
\nWhere: LVCCW Level 2 W213-217 (Blue Team Village) - Map
\n
\nDescription:
\n

This talk is a 101 on using generative AI as a force multiplier for threat hunting as a coding and analysis partner. We\'ll walk through a generalizable methodology for building passive hunting workflows, where GenAI accelerates two things: writing and maintaining the automation itself (scrapers, parsers, decoders, pipelines), and making sense of the data once it\'s collected (spotting patterns, triaging candidates, summarizing at scale).

\n\nSpeakers:Daniela Zamfiroiu,Dimple Gajra
\n
\nSpeakerBio:  Daniela Zamfiroiu, Security architect at airling industry
\n

Working in different cybersecurity roles for 20 years, out of which last 8 IR and hunting. Favorite types of projects: recovery strategies after incidents, designing hunts to better understand environments.

\n\nSpeakerBio:  Dimple Gajra
\n

Specializing in Digital Forensics, Incident Response (DFIR), and privacy engineering, Dimple Gajra (aka LocalHost) brings technical expertise to enterprise defense and data protection. Her professional journey includes engineering and response roles at major technology enterprises like IBM and Amazon\'s Security Incident Response Team (SIRT), where she has actively defended critical infrastructure, mitigated high-severity ransomware incidents, and engineered solutions to safeguard data privacy and automate secure detection pipelines. Driven by a hands-on, analytical approach to uncovering adversary tradecraft, she focuses on building architectural resilience, protecting sensitive user data, and translating complex system artifacts into actionable defensive strategies.

\n\n\n\'',NULL,1298277),('2_Friday','14','13:15','14:15','Y','Blue Team Village','LVCCW Level 2 W213-217 (Blue Team Village)','\'Watching Them Watch You Watch Them: A 101 Intro to Using AI for CTI\'','\'Daniela Zamfiroiu,Dimple Gajra\'','Creator Talks_fb204f03ebb01ff1a0726c81e23ca2c1','\'\'',NULL,1298278),('2_Friday','13','13:00','13:59','N','Social Gatherings/Events','LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1','\'Book Signing - Jaron Bradley\'','\'Jaron Bradley\'','Social Gatherings/Events_50eea988014f81c1815163a0e432cbd8','\'Title: Book Signing - Jaron Bradley
\nTags: Vendor Book Signing
\nWhen: Friday, Aug 7, 13:00 - 13:59 PDT
\nWhere: LVCCW Level 1 Hall 4 1300 (Book Signings)-Table 1 - Map
\n
\nDescription:
\n\n\nSpeakerBio:  Jaron Bradley, Jamf
\n

Jaron is the Director of Jamf Threat Labs where he focuses on discovering new ways to keep user\'s safe on Apple devices. He is author of the books \"Threat Hunting macOS\" and \"OS X Incident Response\". In his free time he manages themittenmac.com, a site dedicated to helping others learn security on the Apple ecosystem.

\n\n\n\'',NULL,1298279),('2_Friday','10','10:00','17:59','N','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_2491478b9870f1c8b653d2c27e234689','\'Title: Hackers with Disabilities / HDA Community - Open
\nTags: Hackers With Disabilities (HDA) | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W201 (HDA Community) - Map
\n
\nDescription:
\n\n\n\'',NULL,1298280),('2_Friday','11','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_2491478b9870f1c8b653d2c27e234689','\'\'',NULL,1298281),('2_Friday','12','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_2491478b9870f1c8b653d2c27e234689','\'\'',NULL,1298282),('2_Friday','13','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_2491478b9870f1c8b653d2c27e234689','\'\'',NULL,1298283),('2_Friday','14','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_2491478b9870f1c8b653d2c27e234689','\'\'',NULL,1298284),('2_Friday','15','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_2491478b9870f1c8b653d2c27e234689','\'\'',NULL,1298285),('2_Friday','16','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_2491478b9870f1c8b653d2c27e234689','\'\'',NULL,1298286),('2_Friday','17','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_2491478b9870f1c8b653d2c27e234689','\'\'',NULL,1298287),('4_Sunday','10','10:00','13:59','N','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_5f691c4868598124d05bd883dabce9d6','\'Title: Hackers with Disabilities / HDA Community - Open
\nTags: Hackers With Disabilities (HDA) | Creator Event/Activity
\nWhen: Sunday, Aug 9, 10:00 - 13:59 PDT
\nWhere: LVCCW Level 2 W201 (HDA Community) - Map
\n
\nDescription:
\n\n\n\'',NULL,1298288),('4_Sunday','11','10:00','13:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_5f691c4868598124d05bd883dabce9d6','\'\'',NULL,1298289),('4_Sunday','12','10:00','13:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_5f691c4868598124d05bd883dabce9d6','\'\'',NULL,1298290),('4_Sunday','13','10:00','13:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_5f691c4868598124d05bd883dabce9d6','\'\'',NULL,1298291),('3_Saturday','10','10:00','17:59','N','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_b7a38028fdfa23c02b47bd93ff23c2c3','\'Title: Hackers with Disabilities / HDA Community - Open
\nTags: Hackers With Disabilities (HDA) | Creator Event/Activity
\nWhen: Saturday, Aug 8, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W201 (HDA Community) - Map
\n
\nDescription:
\n\n\n\'',NULL,1298292),('3_Saturday','11','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_b7a38028fdfa23c02b47bd93ff23c2c3','\'\'',NULL,1298293),('3_Saturday','12','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_b7a38028fdfa23c02b47bd93ff23c2c3','\'\'',NULL,1298294),('3_Saturday','13','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_b7a38028fdfa23c02b47bd93ff23c2c3','\'\'',NULL,1298295),('3_Saturday','14','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_b7a38028fdfa23c02b47bd93ff23c2c3','\'\'',NULL,1298296),('3_Saturday','15','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_b7a38028fdfa23c02b47bd93ff23c2c3','\'\'',NULL,1298297),('3_Saturday','16','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_b7a38028fdfa23c02b47bd93ff23c2c3','\'\'',NULL,1298298),('3_Saturday','17','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_b7a38028fdfa23c02b47bd93ff23c2c3','\'\'',NULL,1298299),('1_Thursday','10','10:00','17:59','N','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_400c870f9ace41954c47e1d263699da4','\'Title: Hackers with Disabilities / HDA Community - Open
\nTags: Hackers With Disabilities (HDA) | Creator Event/Activity
\nWhen: Thursday, Aug 6, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 2 W201 (HDA Community) - Map
\n
\nDescription:
\n\n\n\'',NULL,1298300),('1_Thursday','11','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_400c870f9ace41954c47e1d263699da4','\'\'',NULL,1298301),('1_Thursday','12','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_400c870f9ace41954c47e1d263699da4','\'\'',NULL,1298302),('1_Thursday','13','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_400c870f9ace41954c47e1d263699da4','\'\'',NULL,1298303),('1_Thursday','14','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_400c870f9ace41954c47e1d263699da4','\'\'',NULL,1298304),('1_Thursday','15','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_400c870f9ace41954c47e1d263699da4','\'\'',NULL,1298305),('1_Thursday','16','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_400c870f9ace41954c47e1d263699da4','\'\'',NULL,1298306),('1_Thursday','17','10:00','17:59','Y','Hackers With Disabilities (HDA)','LVCCW Level 2 W201 (HDA Community)','\'Hackers with Disabilities / HDA Community - Open\'','\'\'','Creator Events_400c870f9ace41954c47e1d263699da4','\'\'',NULL,1298307),('2_Friday','10','10:00','17:59','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth','\'Adversary Simulator Booth\'','\'\'','Creator Events_98a9df7d5268456cdc0db2cab9cd27b4','\'Title: Adversary Simulator Booth
\nTags: Adversary Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth - Map
\n
\nDescription:
\n

Hands-on adversary emulation and simulation exercises - emulate real-world threat actors and ransomware. Volunteer-assisted, all skill levels welcome.

\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/ - https://adversaryvillage.org/adversary-events/DEFCON-34/
\n\'',NULL,1298308),('2_Friday','11','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth','\'Adversary Simulator Booth\'','\'\'','Creator Events_98a9df7d5268456cdc0db2cab9cd27b4','\'\'',NULL,1298309),('2_Friday','12','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth','\'Adversary Simulator Booth\'','\'\'','Creator Events_98a9df7d5268456cdc0db2cab9cd27b4','\'\'',NULL,1298310),('2_Friday','13','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth','\'Adversary Simulator Booth\'','\'\'','Creator Events_98a9df7d5268456cdc0db2cab9cd27b4','\'\'',NULL,1298311),('2_Friday','14','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth','\'Adversary Simulator Booth\'','\'\'','Creator Events_98a9df7d5268456cdc0db2cab9cd27b4','\'\'',NULL,1298312),('2_Friday','15','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth','\'Adversary Simulator Booth\'','\'\'','Creator Events_98a9df7d5268456cdc0db2cab9cd27b4','\'\'',NULL,1298313),('2_Friday','16','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth','\'Adversary Simulator Booth\'','\'\'','Creator Events_98a9df7d5268456cdc0db2cab9cd27b4','\'\'',NULL,1298314),('2_Friday','17','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth','\'Adversary Simulator Booth\'','\'\'','Creator Events_98a9df7d5268456cdc0db2cab9cd27b4','\'\'',NULL,1298315),('2_Friday','10','10:00','10:45','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage','\'Adversary Village Kick-off Keynote\'','\'Abhijith B R,Bryson Bort,Sanne Maasakkers,Adam Pennington\'','Creator Talks_1315b75c023f51276b06d410ab3fb06c','\'Title: Adversary Village Kick-off Keynote
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 10:00 - 10:45 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage - Map
\n
\nDescription:
\n\n\nSpeakers:Abhijith B R,Bryson Bort,Sanne Maasakkers,Adam Pennington
\n
\nSpeakerBio:  Abhijith B R, Founder of Adversary Village
\n

Abhijith B R, also known by the pseudonym Abx, has more than a decade of experience in the offensive cyber security industry, serves as the Director of BreachSimRange, and Founder of Adversary Village.

\n\n

He is a professional hacker, offensive cyber security specialist, red team consultant, security researcher, trainer and public speaker.

\n\n

Currently, he is building BreachSimRange.io as the Founder and Director and is involved with multiple organizations as a consulting specialist to help them build offensive cyber security operations programs, improve their current security posture, assess cyber defense systems, and bridge the gap between business leadership and security professionals.

\n\n

In the past, he led the offensive security team at Envestnet, Inc., held the position of Deputy Manager - Cyber Security at Nissan Motor Corporation, and prior to that, he worked as a Senior Security Analyst at EY.

\n\n

As the founder of Adversary Village (https://adversaryvillage.org/), Abhijith spearheads a community initiative focused on adversary simulation, adversary-tactics, purple teaming, threat actor/ransomware research-emulation, and offensive cyber security. Adversary Village is part of DEF CON Villages and organizes hacking villages at prominent events such as the DEF CON Hacking Conference, RSA Conference etc.

\n\n

Abx also acts as the Lead of an official DEF CON Group named DC0471. He is actively involved in leading the Tactical Adversary project (https://tacticaladversary.io/), a personal initiative that centers around offensive cyber security, adversary attack simulation and red teaming tradecraft.

\n\n

Abhijith has spoken and delivered trainings at various hacking and cyber security conferences such as, DEF CON hacker convention - Las Vegas, RSA Conference - San Francisco, The Diana Initiative - Las Vegas, DEF CON 28 safemode - DCG Village, Opensource India, Security BSides Las Vegas, BSides San Francisco, BSides Tampa, Hack Space Con - Kennedy space center Florida, Nullcon - Goa, c0c0n - Kerala, BSides Delhi, DEF CON Bahrain, DEF CON Singapore etc.

\n\nSpeakerBio:  Bryson Bort, Founder and CEO at SCYTHE
\n

Bryson is the Founder of SCYTHE, a start-up building a next generation attack emulation platform, and GRIMM, a cybersecurity consultancy, and Co-Founder of the ICS Village, a non-profit advancing awareness of industrial control system security. He is a Senior Fellow with the Atlantic Council\'s Cyber Statecraft Initiative, the National Security Institute, and an Advisor to the Army Cyber Institute. As a U.S. Army Officer, he served as a Battle Captain and Brigade Engineering Officer in support of Operation Iraqi Freedom before leaving the Army as a Captain. He was recognized as one of the Top 50 in Cyber in 2020 by Business Insider. Bryson received his Bachelor of Science in Computer Science with honors from the United States Military Academy at West Point. He holds a Master\'s Degree in Telecommunications Management from the University of Maryland, a Master\'s in Business Administration from the University of Florida, and completed graduate studies in Electrical Engineering and Computer Science at the University of Texas.

\n\nSpeakerBio:  Sanne Maasakkers, Threat intel at Mandiant (Google)
\n

Sanne Maasakkers is working for Threat intel at Mandiant, previously at NCSC-NL. After spending some years in offensive security, she now uses this knowledge to make Dutch vital infrastructure more resilient. She is mainly interested in researching social engineering tactics and techniques of the bigger APTs and presented \'Phish like an APT\' at the digital version of Adversary Village. Additionally, she likes to host CTFs for young talents, coach the European CTF team, and host awareness sessions.

\n\nSpeakerBio:  Adam Pennington, ATT&CK lead at MITRE Corporation
\n

Adam Pennington leads ATT&CK at The MITRE Corporation and collected much of the intelligence leveraged in creating ATT&CK’s initial techniques. He has spent much of his 16 years with MITRE studying and preaching the use of deception for intelligence gathering. Prior to joining MITRE, Adam was a researcher at Carnegie Mellon\'s Parallel Data Lab and earned his BS and MS degrees in Computer Science and Electrical and Computer Engineering from Carnegie Mellon University. Adam has presented and published in several venues including FIRST CTI, USENIX Security, DEF CON, and ACM Transactions on Information and System Security.

\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/Abhijith-B-R/ - https://adversaryvillage.org/adversary-events/DEFCON-34/Abhijith-B-R/
\n\'',NULL,1298316),('2_Friday','10','10:00','17:59','N','Contests','LVCCW Level 1 Hall 2 602 (Adversary Village) CTF Contest Area','\'Adversary Wars CTF 6.0\'','\'\'','Contests_a2aa118fb59df43c1d2a3a2567b35601','\'Title: Adversary Wars CTF 6.0
\nTags: Adversary Village | Adversary Wars CTF | Contest
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) CTF Contest Area - Map
\n
\nDescription:
\n

Adversary City is under attack. Investigate the TTPs behind the attacks, breach every organization in the city before the real threat actors do, and capture the flags hidden inside each target.

\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/ - https://adversaryvillage.org/adversary-events/DEFCON-34/
\n\'',NULL,1298317),('2_Friday','11','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 602 (Adversary Village) CTF Contest Area','\'Adversary Wars CTF 6.0\'','\'\'','Contests_a2aa118fb59df43c1d2a3a2567b35601','\'\'',NULL,1298318),('2_Friday','12','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 602 (Adversary Village) CTF Contest Area','\'Adversary Wars CTF 6.0\'','\'\'','Contests_a2aa118fb59df43c1d2a3a2567b35601','\'\'',NULL,1298319),('2_Friday','13','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 602 (Adversary Village) CTF Contest Area','\'Adversary Wars CTF 6.0\'','\'\'','Contests_a2aa118fb59df43c1d2a3a2567b35601','\'\'',NULL,1298320),('2_Friday','14','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 602 (Adversary Village) CTF Contest Area','\'Adversary Wars CTF 6.0\'','\'\'','Contests_a2aa118fb59df43c1d2a3a2567b35601','\'\'',NULL,1298321),('2_Friday','15','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 602 (Adversary Village) CTF Contest Area','\'Adversary Wars CTF 6.0\'','\'\'','Contests_a2aa118fb59df43c1d2a3a2567b35601','\'\'',NULL,1298322),('2_Friday','16','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 602 (Adversary Village) CTF Contest Area','\'Adversary Wars CTF 6.0\'','\'\'','Contests_a2aa118fb59df43c1d2a3a2567b35601','\'\'',NULL,1298323),('2_Friday','17','10:00','17:59','Y','Contests','LVCCW Level 1 Hall 2 602 (Adversary Village) CTF Contest Area','\'Adversary Wars CTF 6.0\'','\'\'','Contests_a2aa118fb59df43c1d2a3a2567b35601','\'\'',NULL,1298324),('2_Friday','10','10:00','17:59','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Guided Breach Sim Area','\'Breach and Attack Simulation Exercises\'','\'\'','Creator Events_b908cd256d3d83f1da3a5242937425e7','\'Title: Breach and Attack Simulation Exercises
\nTags: Adversary Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Guided Breach Sim Area - Map
\n
\nDescription:
\n

Guided breach and offensive attack simulation hands-on exercises on a full cyber-range replica.

\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/ - https://adversaryvillage.org/adversary-events/DEFCON-34/
\n\'',NULL,1298325),('2_Friday','11','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Guided Breach Sim Area','\'Breach and Attack Simulation Exercises\'','\'\'','Creator Events_b908cd256d3d83f1da3a5242937425e7','\'\'',NULL,1298326),('2_Friday','12','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Guided Breach Sim Area','\'Breach and Attack Simulation Exercises\'','\'\'','Creator Events_b908cd256d3d83f1da3a5242937425e7','\'\'',NULL,1298327),('2_Friday','13','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Guided Breach Sim Area','\'Breach and Attack Simulation Exercises\'','\'\'','Creator Events_b908cd256d3d83f1da3a5242937425e7','\'\'',NULL,1298328),('2_Friday','14','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Guided Breach Sim Area','\'Breach and Attack Simulation Exercises\'','\'\'','Creator Events_b908cd256d3d83f1da3a5242937425e7','\'\'',NULL,1298329),('2_Friday','15','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Guided Breach Sim Area','\'Breach and Attack Simulation Exercises\'','\'\'','Creator Events_b908cd256d3d83f1da3a5242937425e7','\'\'',NULL,1298330),('2_Friday','16','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Guided Breach Sim Area','\'Breach and Attack Simulation Exercises\'','\'\'','Creator Events_b908cd256d3d83f1da3a5242937425e7','\'\'',NULL,1298331),('2_Friday','17','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Guided Breach Sim Area','\'Breach and Attack Simulation Exercises\'','\'\'','Creator Events_b908cd256d3d83f1da3a5242937425e7','\'\'',NULL,1298332),('2_Friday','10','10:00','17:59','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village)','\'Choose-your-own-Adversary-Adventure Tabletop Game\'','\'\'','Creator Events_4c1f734aaff6edded949381d4562f788','\'Title: Choose-your-own-Adversary-Adventure Tabletop Game
\nTags: Adversary Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 10:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) - Map
\n
\nDescription:
\n

Choose-your-own-adventure style interactive cyber war-gaming tabletop game. Play as attacker, defender, or leadership.

\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/ - https://adversaryvillage.org/adversary-events/DEFCON-34/
\n\'',NULL,1298333),('2_Friday','11','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village)','\'Choose-your-own-Adversary-Adventure Tabletop Game\'','\'\'','Creator Events_4c1f734aaff6edded949381d4562f788','\'\'',NULL,1298334),('2_Friday','12','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village)','\'Choose-your-own-Adversary-Adventure Tabletop Game\'','\'\'','Creator Events_4c1f734aaff6edded949381d4562f788','\'\'',NULL,1298335),('2_Friday','13','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village)','\'Choose-your-own-Adversary-Adventure Tabletop Game\'','\'\'','Creator Events_4c1f734aaff6edded949381d4562f788','\'\'',NULL,1298336),('2_Friday','14','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village)','\'Choose-your-own-Adversary-Adventure Tabletop Game\'','\'\'','Creator Events_4c1f734aaff6edded949381d4562f788','\'\'',NULL,1298337),('2_Friday','15','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village)','\'Choose-your-own-Adversary-Adventure Tabletop Game\'','\'\'','Creator Events_4c1f734aaff6edded949381d4562f788','\'\'',NULL,1298338),('2_Friday','16','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village)','\'Choose-your-own-Adversary-Adventure Tabletop Game\'','\'\'','Creator Events_4c1f734aaff6edded949381d4562f788','\'\'',NULL,1298339),('2_Friday','17','10:00','17:59','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village)','\'Choose-your-own-Adversary-Adventure Tabletop Game\'','\'\'','Creator Events_4c1f734aaff6edded949381d4562f788','\'\'',NULL,1298340),('2_Friday','11','11:00','12:55','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area','\'Breaching the Frontier: A Hands-On Lab on AI-Native Vulnerabilities\'','\'Anto Joseph\'','Creator Events_078bb286c08067938e77a5c3b3817daa','\'Title: Breaching the Frontier: A Hands-On Lab on AI-Native Vulnerabilities
\nTags: Adversary Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 11:00 - 12:55 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area - Map
\n
\nDescription:
\n

For thirty + years, hacking has meant finding flaws in code people wrote: memory corruption, injection, and logic bugs. AI systems fail differently. Their vulnerabilities live in the weights or the supporting fixtures. Caches that speed up inference, embeddings that supposedly anonymize data, weights that execute code, training corpora memorization, misalignment, reward hacking and the structural inability of a language model to separate instructions from data. These are some of the AI-native bugs. They exist because of how these systems are built, not because a developer made a mistake, and no traditional AppSec tool will find them. As enterprises deploy LLM assistants, agents, and RAG pipelines into the adversary\'s path, this bug class is becoming the new attack surface.

\n\n

This lab walks you through live exploitation and defenses in a contained environment. Built on peer-reviewed work from NDSS, USENIX Security, IEEE S&P/SaTML, CCS, and ICLR (2023-2026).

\n\n

We will cover attacks across Model Serving side channels, prefix cache attacks, speculative decoding, the AI supply chain, dataset poisoning, sleeper-agent backdoors that survive safety training, and trojaned LoRA adapters. We will also have examples of the classic prompt and chat template injection bugs baked in CTF style.

\n\n

Every lab is built on released artifacts: papers, code, datasets, and open models. Attendees leave with a working understanding of modern AI systems, how AI-native vulnerability research works and a method they can run on their next engagement.

\n\n

Who should attend: red teamers, pentesters, and security researchers fluent in traditional exploitation who want the AI-native equivalent.

\n\n

Prerequisites: a laptop with admin access that can run Docker. A MacBook Pro with 128 GB of memory is preferred if you like to run models locally.

\n\nSpeakerBio:  Anto Joseph, Lead Product & Infrastructure Security at EigenLabs
\n

Anto Joseph leads product and infrastructure security at EigenLabs. His work focuses on AI-native vulnerabilities — the class of security flaws that arise from how modern AI systems are built rather than from mistakes in application code — and on translating cutting-edge academic security research into practical, hands-on offensive tradecraft for red teamers and security researchers.

\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/Anto-Joseph/ - https://adversaryvillage.org/adversary-events/DEFCON-34/Anto-Joseph/
\n\'',NULL,1298341),('2_Friday','12','11:00','12:55','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area','\'Breaching the Frontier: A Hands-On Lab on AI-Native Vulnerabilities\'','\'Anto Joseph\'','Creator Events_078bb286c08067938e77a5c3b3817daa','\'\'',NULL,1298342),('2_Friday','11','11:00','12:55','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage','\'The APT OSINT Challenge\'','\'William Thomas\'','Creator Workshops_c2acaf98a2f7d84495105fc90dde6067','\'Title: The APT OSINT Challenge
\nTags: Adversary Village | Creator Workshop
\nWhen: Friday, Aug 7, 11:00 - 12:55 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage - Map
\n
\nDescription:
\n

This hands-on workshop places participants in the role of a threat intelligence analyst, tasked with attributing real-world cyber intrusions to Advanced Persistent Threat (APT) groups using only open-source intelligence. Working from publicly available breach reports drawn from my own Breach-Report-Collection repository, attendees will practise pivoting through OSINT sources, from MITRE ATT&CK and vendor threat blogs to DOJ indictments and IoC databases, to answer the fundamental questions of threat attribution: Who did this? Who sent them? And are they still out there? No prior threat intelligence experience is required; curiosity is the only entry ticket.

\n\nSpeakerBio:  William Thomas, Senior Threat Intelligence Advisor
\n

Will Thomas is a Senior Threat Intelligence Advisor at Team Cymru with over 9 years experience in cybersecurity. He previously worked as the Head of Threat Hunting at Equinix, the world’s largest data center company, and is the co-author of the SANS FOR589 Cybercrime course and SANS Instructor. Before this, he worked for Cyjax, a CTI vendor that works with UK banks and police. He is well-known for the research on his personal blog (bushidotoken.net) and his work as the co-founder of the Curated Intel trust group. He has presented his research at various conferences including Underground Economy, DEFCON, Sleuthcon, and CyberThreatUK.

\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/William-Thomas/ - https://adversaryvillage.org/adversary-events/DEFCON-34/William-Thomas/
\n\'',NULL,1298343),('2_Friday','12','11:00','12:55','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage','\'The APT OSINT Challenge\'','\'William Thomas\'','Creator Workshops_c2acaf98a2f7d84495105fc90dde6067','\'\'',NULL,1298344),('2_Friday','13','13:00','14:55','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage','\'Hunting GitHub to identify adversary TTPs in the wild\'','\'Paul McCarty,Jenn Gile\'','Creator Workshops_d701c95e1fe5bede3019098023c781c3','\'Title: Hunting GitHub to identify adversary TTPs in the wild
\nTags: Adversary Village | Creator Workshop
\nWhen: Friday, Aug 7, 13:00 - 14:55 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage - Map
\n
\nDescription:
\n

This hands-on workshop at Adversary Village RSAC 2026 provides a 20-minute deep dive into software supply chain attacks through practical exercises. The session will focus on the TTPs that DPRK-affiliated threat actors use to compromise software engineers, with particular emphasis on \"Contagious Interview\" campaigns. Participants will engage in CTI-based targeting and identification of key techniques, blending practical hunting exercises in GitHub and NPM to discover malicious packages and repositories in the wild with adversary emulation scenarios that walk through the complete attack chain.

\n\n

The workshop will demonstrate how threat actors evade detection, while also teaching defenders how to detect and prevent these increasingly common supply chain threats. By experiencing these attacks from the adversary\'s perspective, participants will gain critical insights into real-world compromise techniques.

\n\n

Things we will hunt for in GitHub and NPM:

\n\n
    \n
  1. VS Code tasks files - RCE via automatic execution of the tasks file when compromised source code is opened in VS Code

  2. \n
  3. Fake fonts - hidden JavaScript payloads pretending to be font files

  4. \n
  5. Fake VS Code dictionary files that hide JavaScript payloads

  6. \n
  7. \"PolinRider\" TTPs for specific JavaScript payload appending

  8. \n
  9. How DPRK threat actors hide infrastructure in cloud providers

  10. \n
  11. Malicious npm packages with obfuscated payloads in install hooks

  12. \n
  13. Dependency confusion attacks targeting internal package names

  14. \n
  15. Backstopped GitHub repositories with fabricated commit histories

  16. \n
\n\nSpeakers:Paul McCarty,Jenn Gile
\n
\nSpeakerBio:  Paul McCarty, Founder and lead researcher at OpenSourceMalware, the software supply chain threat intelligence platform. Software supply chain offensive security crazy person.
\n

Paul is the founder and maintainer of OpenSourceMalware, the world\'s largest open database and collaboration platform for software supply chain threat intel. His day job is Head of Research at Safety and is a DevSecOps OG. He loves software supply chain research and delivering supply chain offensive security training and engagements. He\'s spent the last two years deep-diving into npm and has made several discoveries about the ecosystem. Paul founded multiple startups starting in the \'90s and has worked for NASA, Boeing, Blue Cross/Blue Shield, John Deere, the US military, and the Australian government.  Paul is a frequent open-source contributor and author of several DevSecOps, software supply chain and threat modelling projects. He’s currently writing a book entitled “Hacking NPM”, and when he’s not doing that, he’s snowboarding with his wife and 3 amazing kids.

\n\nSpeakerBio:  Jenn Gile
\n

Jenn Gile is a community builder and tech educator in the Security and DevOps fields. She\'s Co-Founder of OpenSourceMalware.com and runs the community program for BSides Seattle. Jenn previously worked at NGINX, F5, Endor Labs, and the U.S. Department of State. Outside of work, she\'s deeply involved in the cycling community as a board member for 2nd Cycle.

\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/ - https://adversaryvillage.org/adversary-events/DEFCON-34/
\n\'',NULL,1298345),('2_Friday','14','13:00','14:55','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage','\'Hunting GitHub to identify adversary TTPs in the wild\'','\'Paul McCarty,Jenn Gile\'','Creator Workshops_d701c95e1fe5bede3019098023c781c3','\'\'',NULL,1298346),('2_Friday','13','13:00','14:55','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area','\'Just a TIP: DIY Your First Adversary Threat Intelligence Platform\'','\'A. Stryker\'','Creator Events_b9c04d49e1282b70653fb59cd8df2cec','\'Title: Just a TIP: DIY Your First Adversary Threat Intelligence Platform
\nTags: Adversary Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 13:00 - 14:55 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area - Map
\n
\nDescription:
\n

Several years ago, before I even knew what a \"threat intelligence platform\" was, I accidentally cobbled a TIP together with nothing but ChatGPT, Feedly, Airtable, Zapier, and duct tape vibes.

\n\n

That original setup was robust enough that I still use parts of it today!

\n\n

In this interactive, hands-on session, I\'ll walk you through how to hack together your first minimum viable TIP using whatever no- or low-cost tools you\'ve got on hand.

\n\n

Bring an Internet-capable laptop, and we\'ll:

\n\n
    \n
  • Pin down why you need a TIP: are you drowning in docs and articles, still cutting and pasting indicators, or just trying to appease the corporate gods who think it\'s a good idea?

  • \n
  • Seed your intel feeds with customized primary sources while discovering hidden RSS feeds together.

  • \n
  • Perfect your OSINT summary prompt engineering for the Gen AI bot of your choice, with a few experiments showing common failure points.

  • \n
\n\n

You’ll walk away with war stories, a functional schematic to assemble your own TIP, and a community ready to help you iterate... no six-figure surcharge required.

\n\nSpeakerBio:  A. Stryker, Director of Threat Analysis at Fable Security
\n

Stryker has spent over ten years translating technical research and qualitative intelligence into the \"so what?\" and \"what now?\" materials that keep more people safe and secure. She previously produced threat intelligence across financial services, cybersecurity vendors, and now early-stage startups - including work at Ivanti, Blackpoint Cyber, and GEICO - and currently leads threat analysis at Fable Security. You can often find her playing tabletop card games after her talks at SecTor, DEF CON, and Bsides conferences around the United States. Stryker lives in Maryland, growing parsley for butterflies and algae for shrimp.

\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/A-Stryker/ - https://adversaryvillage.org/adversary-events/DEFCON-34/A-Stryker/
\n\'',NULL,1298347),('2_Friday','14','13:00','14:55','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area','\'Just a TIP: DIY Your First Adversary Threat Intelligence Platform\'','\'A. Stryker\'','Creator Events_b9c04d49e1282b70653fb59cd8df2cec','\'\'',NULL,1298348),('2_Friday','15','15:00','16:55','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage','\'Detection Coverage Is a Hypothesis: Testing It Through Adversarial Execution Variance\'','\'Connor Jackson,Russell Harvey,Nahid Sarker\'','Creator Workshops_a04d5221f80992b7e07c2d8a53b31670','\'Title: Detection Coverage Is a Hypothesis: Testing It Through Adversarial Execution Variance
\nTags: Adversary Village | Creator Workshop
\nWhen: Friday, Aug 7, 15:00 - 16:55 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage - Map
\n
\nDescription:
\n

Security teams routinely assume that known techniques are covered. This workshop interrogates that assumption through a structured purple team exercise conducted in an active lab environment. Participants will systematically execute the same adversarial techniques across multiple implementation variants, observing how subtle changes in execution method produce dramatically different telemetry, alter detection fidelity, and expose blind spots in EDR and SIEM tooling.

\n\n

The workshop emphasizes stealthy execution tradecraft as a variable rather than a constant, treating each implementation as a testable hypothesis about defender visibility. Attendees will build detections, hunt across collected telemetry, and leave with guidance for evaluating detection coverage against technique variance in their own environments.

\n\nSpeakers:Connor Jackson,Russell Harvey,Nahid Sarker
\n
\nSpeakerBio:  Connor Jackson, Senior Consultant
\n

Connor Jackson is a Senior Consultant at Security Risk Advisors. With a background in penetration testing, he helps lead and execute numerous purple teams across a variety of eviroments. He also has an interest in OT, IoT, and hardware security.

\n\nSpeakerBio:  Russell Harvey, Senior Consultant
\n

Russell leads Purple Teams as a Master of Ceremonies (MC), a role that requires deep knowledge of both defensive and offensive tools and techniques. He also plays a key role in facilitating research and innovation within the purple team program, and helps develop payloads and automations for Purple Team engagements. Before his current role, Russell gained valuable experience at SRA in the CyberSOC, where he specialized in threat hunting, detection engineering, incident response, and served as a client lead.

\n\n

Russell graduated from the Rochester Institute of Technology (RIT) in 2022 with a B.S. in Computing Security. His professional interests extend to malware development/reverse engineering, penetration testing, and operating system internals.

\n\nSpeakerBio:  Nahid Sarker, Lead Consultant
\n

Nahid Sarker is a Lead Consultant at Security Risk Advisors (SRA). He serves as a technical lead for the purple team program, where he plays a role in maintaining SRA’s offensive security capabilities.

\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/ - https://adversaryvillage.org/adversary-events/DEFCON-34/
\n\'',NULL,1298349),('2_Friday','16','15:00','16:55','Y','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage','\'Detection Coverage Is a Hypothesis: Testing It Through Adversarial Execution Variance\'','\'Connor Jackson,Russell Harvey,Nahid Sarker\'','Creator Workshops_a04d5221f80992b7e07c2d8a53b31670','\'\'',NULL,1298350),('2_Friday','15','15:30','15:55','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area','\'Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence\'','\'Jordan Bonagura\'','Creator Talks_56ed46074d4255faf534f714bb4d1bd5','\'Title: Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 15:30 - 15:55 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area - Map
\n
\nDescription:
\n

Modern enterprise environments have shifted beyond traditional network perimeters, with SaaS applications and identity providers becoming the primary attack surface. However, a significant portion of this still remains unmanaged or invisible commonly referred as Shadow SaaS.

\n\n

This session explores Shadow SaaS from an attacker’s perspective, demonstrating how adversaries can identify, evaluate, and abuse unmanaged SaaS applications to gain initial access and maintain persistence within target environments.

\n\n

Rather than focusing on inventory or governance, this talk reframes Shadow SaaS as an offensive opportunity. It highlights how implicit trust relationships, and third-party SaaS connections expand the attack surface beyond traditional security visibility.

\n\n

Using the Shadow SaaS Surface Scanner, we demonstrate how attackers can uncover hidden SaaS exposure and leverage it as a foothold into enterprise environments.

\n\nSpeakerBio:  Jordan Bonagura
\n

Senior Security Consultant at Secure Ideas\nResearcher in Information Security\nStay Safe Podcast Founder\nComputer Scientist\nPost Graduated in Business Strategic Management, Innovation and Teaching\nFounder - Vale Security Conference - Brazilian Conference\nConsultant Member - Brazilian Comission of High Tech Crime (OAB / SP) \nCoordinator and Teacher in IT area\nSJC Hacker Space President\nSpeaker (DefCon, Hack Space Con, Hack Red Con, Hack Miami, Triangle InfoSec, AppSec California, GrrCon, BalCCon2k14, BSides Augusta, H2HC, Angeles Y Demonios, Silver Bullet, Seginfo, ITA, INPE, etc)

\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/Jordan-Bonagura/ - https://adversaryvillage.org/adversary-events/DEFCON-34/Jordan-Bonagura/
\n\'',NULL,1298351),('2_Friday','16','16:00','16:25','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area','\'Build a Threat Intelligence Team entirely with agents\'','\'Renze Jongman\'','Creator Talks_af115f05055b1fa4ca0a9e8d68685369','\'Title: Build a Threat Intelligence Team entirely with agents
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 16:00 - 16:25 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Hands-on Activity Area - Map
\n
\nDescription:
\n

Analysts have historically been responsible for collection (which is almost always reactive), storage, analysis, production and dissemination of intelligence products, covering a wide range of threat topics. It has been hard not just to keep all that knowledge about the threats readily available and up to date, but also to maintain proficiency in all the tools and skills involved to do the actual analysis.

\n\n

With the agentic platforms of today, that\'s not necessary anymore. This demo will walk the audience through how they can use Claude Code (as an example - there are alternatives) and open-source skill packs like these (https://github.com/Liberty91LTD/cti-skills/) to set up and run a team of agents to get a lot more done, and free themselves up to do the important and interesting work: actual analysis. DISCLAIMER: this repo is owned and maintained by my (super small, bootstrapped start-up) company Liberty91, but it\'s not a vendor pitch: its a skills pack we\'ve open-sourced for the community.

\n\nSpeakerBio:  Renze Jongman, Founder of Liberty91
\n

Renze Jongman is the founder and CEO of Liberty91, an operational cyber threat intelligence platform that makes CTI accessible to mid-market security teams. He spent his early career at the Dutch National High Tech Crime Unit and was a founding member of Europol\'s Joint Cybercrime Action Taskforce (J-CAT), before moving into the private sector to lead strategic threat intelligence at Barclays in London and run threat intelligence consulting at Mandiant (now part of Google Cloud) across EMEA and the Middle East. He also advises the Abu Dhabi Department of Government Enablement\'s CTI function. Based in Abu Dhabi, he writes regularly on the practitioner realities of threat intelligence.

\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/Renze-Jongman/ - https://adversaryvillage.org/adversary-events/DEFCON-34/Renze-Jongman/
\n\'',NULL,1298352),('2_Friday','17','17:00','17:59','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage','\'Purple teaming? Simulating the Adversary in the World of AI systems\'','\'Evan Perotti,Joseph Hall,Nikhil Shrivastava\'','Creator Talks_9d8fca640c7553a5330a14b9f20a4377','\'Title: Purple teaming? Simulating the Adversary in the World of AI systems
\nTags: Adversary Village | Creator Talk/Panel
\nWhen: Friday, Aug 7, 17:00 - 17:59 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage - Map
\n
\nDescription:
\n

Adversary simulation has always been constrained by people. Building an emulation plan from threat intelligence, standing up infrastructure, executing the chain, and working through detection gaps with the blue team takes weeks of skilled operator time, which is why most organizations run these exercises once or twice a year instead of continuously.

\n\n

AI systems are starting to change that math. Agentic tooling can parse intelligence reports into executable emulation plans, run attack chains autonomously against lab and production-adjacent environments, and iterate on technique variations far faster than a human operator can. This panel looks at what that actually delivers today. Panelists will discuss where agents produce credible threat actor behavior and where they generate plausible looking noise, how much operator oversight is still required, what it means for purple team exercises when the red side can execute a hundred variations of a technique overnight, and whether blue teams can consume that volume of signal in any useful way.

\n\n

The conversation also covers the harder questions: fidelity against real adversary tradecraft, safety and scope control when an autonomous agent is executing offensive actions, and whether faster simulation actually produces better detections or just more tickets.

\n\n

Attendees will leave with a grounded view of where AI assisted adversary simulation is genuinely working, where it falls short, and what it takes to run it responsibly.

\n\nSpeakers:Evan Perotti,Joseph Hall,Nikhil Shrivastava
\n
\nSpeakerBio:  Evan Perotti, Principal Scientist at Security Risk Advisors
\n

Evan Perotti is a Principal Scientist at Security Risk Advisors, focused on research and development within the offensive security space, with specialties spanning threat intelligence, AWS security, Windows endpoint security, and purple teaming. He is the primary creator of Security Risk Advisors\' annual threat intelligence test plans, identifying the underlying threat intelligence for each exercise and turning that research into actionable test cases and complete test plans, and he helps lead the resulting workshops with contributors. Evan is the author of Market Maker, the tool he built to create threat simulation plans, and ALLCAPS, a capability-based payload generation framework used to execute the resulting test cases. He has presented at BSides Pittsburgh, BSides Philly, ShellCon, BSides Chicago, and Insomni\'hack, and writes regularly on his blog.

\n\nSpeakerBio:  Joseph Hall, Threat-Intel Leader
\n

Joseph Hall is a Threat-Intel Leader joining the Adversary Village panel at DEF CON 34.

\n\nSpeakerBio:  Nikhil Shrivastava, Organizer, BSides Ahmedabad
\nPanel with: Evan Perotti, Joseph Hall
\nAbstract
\nAdversary simulation has always been constrained by people. Building an emulation plan from threat intelligence, standing up infrastructure, executing the chain, and working through detection gaps with the blue team takes weeks of skilled operator time, which is why most organizations run these exercises once or twice a year instead of continuously.
\n\n

AI systems are starting to change that math. Agentic tooling can parse intelligence reports into executable emulation plans, run attack chains autonomously against lab and production-adjacent environments, and iterate on technique variations far faster than a human operator can. This panel looks at what that actually delivers today. Panelists will discuss where agents produce credible threat actor behavior and where they generate plausible looking noise, how much operator oversight is still required, what it means for purple team exercises when the red side can execute a hundred variations of a technique overnight, and whether blue teams can consume that volume of signal in any useful way.

\n\n

The conversation also covers the harder questions: fidelity against real adversary tradecraft, safety and scope control when an autonomous agent is executing offensive actions, and whether faster simulation actually produces better detections or just more tickets.

\n\n

Attendees will leave with a grounded view of where AI assisted adversary simulation is genuinely working, where it falls short, and what it takes to run it responsibly.

\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/ - https://adversaryvillage.org/adversary-events/DEFCON-34/
\n\'',NULL,1298353),('2_Friday','18','18:05','18:15','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage','\'Adversary Village Speakers Group Photo\'','\'\'','Creator Events_c4b118528788e5876506b5adc493c36c','\'Title: Adversary Village Speakers Group Photo
\nTags: Adversary Village | Creator Event/Activity
\nWhen: Friday, Aug 7, 18:05 - 18:15 PDT
\nWhere: LVCCW Level 1 Hall 2 602 (Adversary Village) Workshop Stage - Map
\n
\nDescription:
\n\n\nLinks:
    adversaryvillage.org/adversary-events/DEFCON-34/ - https://adversaryvillage.org/adversary-events/DEFCON-34/
\n\'',NULL,1298354),('3_Saturday','10','10:00','17:59','N','Adversary Village','LVCCW Level 1 Hall 2 602 (Adversary Village) Simulator Booth','\'Adversary Simulator Booth\'','\'\'','Creator Events_e80f8fdeefc765a35ccb94b902962e68','\'Title: Adversary Simulator Booth
\nTags: Adversary Village | Creator Event/Activity
\nWhen: Saturday,