BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: C(2)YA: Inside the Adversary's Inbox\n   Tags: DEF C
 ON Official Talk | Demo 💻 | Exploit 🪲\n   When: Saturday\, Aug 8\, 1
 2:00 - 12:59 PDT\n   Where: LVCCW Level 1 Hall 3 903 (Main Track 5) and DC
 TV-5 - [1]Map\n\n   Description:\n\n   85 findings exploitable from the in
 ternet with zero prior access. 28\n   takedown chains. Crypto failures tha
 t let you decrypt all C2 traffic\n   with one recovered key.\n\n   Here's 
 how I got there. I'd been using coding agents to find bugs in\n   software
 . Then I thought: what if I did this from the defender's side\,\n   agains
 t the tools that threat actors actually use? I pointed\n   LLM-assisted re
 search at five C2 frameworks: Havoc\, Mythic\, Sliver\,\n   Covenant\, Ada
 ptixC2. Six months later\, 251 design flaws\, behavioral\n   weaknesses\, 
 and vulnerabilities. Validated every finding in realistic\n   lab environm
 ents. Then passively tapped 35 live servers via Shodan and\n   Censys\, an
 d found operators running campaigns against victims in\n   education\, man
 ufacturing\, legal\, and biotech across eight countries.\n\n   Eight bug c
 lasses recur across all five codebases. Findings rated on a\n   defender-w
 eighted scale\, because CVSS doesn't tell you which bug finds\n   the serv
 er. Havoc\, the most-deployed framework in the dataset\, was\n   archived 
 on February 21\, 2026. No patches coming. Defenders carry the\n   load now
 .\n\n   AI isn't just for protecting systems. Defenders can point it at th
 e\n   attackers' own tools and find real ways to fight back. All findings\
 n   for maintained projects disclosed through proper channels. Every demo\
 n   against realistic lab environments I control.\n\n   SpeakerBio:  Vital
 y Simonovich\, Cato Networks\n\n   Vitaly Simonovich is a Senior Security 
 Researcher at Cato Networks on\n   the CTRL threat research team\, followi
 ng over ten years in\n   cybersecurity across Cato CTRL and Imperva\, wher
 e he focused on DDoS\n   and botnet research from 2019 to 2023.\n\n   He c
 oined HashJack\, the first indirect prompt injection weaponizing\n   URL f
 ragments against AI browser assistants\, and LAMEHUG\, the first\n   LLM-p
 owered malware publicly linked to APT28. He documented the\n   Immersive W
 orld jailbreak against Microsoft Copilot and introduced the\n   Zero-Knowl
 edge Threat Actor concept. His research has driven ten\n   coordinated sec
 urity disclosures across Open WebUI\, MongoDB\, Jenkins\,\n   BIND\, Moodl
 e\, TYPO3\, Perplexity\, Microsoft\, and others.\n\n   His work has been c
 overed by Forbes\, The Economist\, Business Insider\,\n   VentureBeat\, Th
 e Register\, The Hacker News\, and CyberScoop.\n\n   Conference talks: RSA
  Conference 2026\, Botconf 2022\, BSidesTLV 2025 AI\n   Hacking Village\, 
 Qubit 2025 Prague\, RootedCon 2026.\n\n   vitalysim.com\n\n   '\n\n   1. #
 LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T195900Z
DTSTART:20260808T190000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:C(2)YA: Inside the Adversary's Inbox
END:VEVENT
END:VCALENDAR
