DEF CON 34

Unofficial consolidated DEF CON 34 schedule covering talks, workshops, labs, villages, contests, parties, and community events.

Upcoming events

The Unofficial DEF CON Shoot

Social Gatherings/Events - Other / See Description · Social Gatherings/Events - Other / See Description

'Title: The Unofficial DEF CON Shoot Tags: Event When: Wednesday, Aug 5, 11:00 - 17:15 PDT Where: Other / See Description Description: The Unofficial DEF CON Shoot is a public event that happens just prior to the DEF CON hacker conference in Las Vegas, Nevada. It is an opportunity to see and shoot some of the guns belonging to your friends while taking pride in showing and firing your own steel, as well, in a relaxed and welcoming atmosphere. We choose a spot, then we rent tables, canopies, and bring all the necessary safety equipment and amenities. All you need to bring yourself and (optionally) your firearms. New shooters and veterans both attend regularly. You can attend with your firearms, of course, but folk without guns of their own in Vegas may have the opportunity to try gear from others in attendance. Pro Gun Vegas - 12801 Old US 95 Boulder City, NV 89005 '

DC713 and DC281 - 8th Annual DEF CON Texas Groups Meetup

Social Gatherings/Events - Other / See Description · Social Gatherings/Events - Other / See Description

'Title: DC713 and DC281 - 8th Annual DEF CON Texas Groups Meetup Tags: Meetup When: Wednesday, Aug 5, 18:30 - 21:30 PDT Where: Other / See Description Description: We are back hacker fam! The Texas Crew welcomes all DEF CON friends to our 8th annual meetup. Hosted by The Cornish Pasty 10 E Charleston Blvd, Las Vegas, NV 89104 Come for the friends. Stay for the pasties. See you there! '

Defcon.run

Social Gatherings/Events - LVCCW Level 1 North Entrance · Social Gatherings/Events - LVCCW Level 1 North Entrance

'Title: Defcon.run Tags: Event When: Thursday, Aug 6, 06:00 - 07:59 PDT Where: LVCCW Level 1 North Entrance - [1]Map Description: Defcon.run, formerly the DEF CON 4x5K, is a community-driven tradition where hackers gather for morning runs and rucks across Las Vegas. Participants can choose from various routes, from 5Ks to longer distances. For DEF CON 34, meet at "The Spot" near the North Entrance of the Las Vegas Convention Center West Hall. Activities start at 06:00, Thursday through Sunday; arrive early for safety briefings and community hype. Whether you are an experienced runner or a newcomer, visit defcon.run to sign up and connect with the community. ' 1. #LVCCW_Level1_Hall4

Ham In A Day Class

Social Gatherings/Events - LVCCW Level 3 W314 (Ham Radio Meeting) · Social Gatherings/Events - LVCCW Level 3 W314 (Ham Radio Meeting)

'Title: Ham In A Day Class Tags: Event | Ham Radio Village When: Thursday, Aug 6, 10:00 - 16:59 PDT Where: LVCCW Level 3 W314 (Ham Radio Meeting) - [1]Map Description: The HRV Ham In A Day class returns again for its fourth year, taught again by Dan Romencheck, KB6NU, author of the No-Nonsense Study Guides for the amateur radio license exams. Always been interested in getting your ham license but never had the time to study? Now's your chance! The Ham Radio Village is offering a one-day class where you can learn all the required knowledge to pass the exam. Topics include: - Electrical Principles - Electronic principles and components - Radio and electromagnetic wave properties - Antennas and Feedlines - Amateur Radio Signals - Safety - Station Setup and Operation -Operating Procedures - Rules and Regulations The class will run from 10 A.M. to 5 P.M. A lunch break will be provided. Best of all, this class is completely free, thanks to a grant from the Amateur Radio Digital Communications. Last year, we sold out of capacity and had to turn folks away. We highly recommend placing a deposit to reserve your seat. The deposit will be refunded upon attendance of the class. Register by following the attached link. ' 1. #LVCCW_Level3_North

Friends of Bill W

Social Gatherings/Events - LVCCW Level 3 W301 (Misc Meeting Room) · Social Gatherings/Events - LVCCW Level 3 W301 (Misc Meeting Room)

'Title: Friends of Bill W Tags: Meetup When: Thursday, Aug 6, 12:00 - 12:59 PDT Where: LVCCW Level 3 W301 (Misc Meeting Room) - [1]Map Description: We know DEF CON and Vegas can be a lot. If you're a friend of Bill W who's looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday. ' 1. #LVCCW_Level3_South

Toxic BBQ

Social Gatherings/Events - Other / See Description · Social Gatherings/Events - Other / See Description

'Title: Toxic BBQ Tags: Event When: Thursday, Aug 6, 15:00 - 20:59 PDT Where: Other / See Description Description: Join the humans of Vegas at the unofficial opener of DEF CON. This Thursday Meat-Up is in the shade of Sunset Park, a quick ride from the LVCC. We stock the larder with burgers, dogs, and fixin’s. We rely on you for everything else: sides, drinks, volunteering, and donations. With over 50 sq ft of heat, we have plenty of room on the grill for your personal creations. Contribute food and drinks, staff the grill, join supply runs, or donate to help cover cost. Everything left goes to the EFF. Be a part of what makes this cookout something to remember year after year. The only question is: What are you bringing to Toxic BBQ? Check out toxicbbq.org , find a flyer at an NFO Node, and watch for #ToxicBBQ on the socials for the latest news. Sunset Park, Foxtail Pavilion (Lat: 36.0636, Long: -115.1178) '

Friends of Bill W

Social Gatherings/Events - LVCCW Level 3 W301 (Misc Meeting Room) · Social Gatherings/Events - LVCCW Level 3 W301 (Misc Meeting Room)

'Title: Friends of Bill W Tags: Meetup When: Thursday, Aug 6, 17:00 - 17:59 PDT Where: LVCCW Level 3 W301 (Misc Meeting Room) - [1]Map Description: We know DEF CON and Vegas can be a lot. If you're a friend of Bill W who's looking for a meeting or just a place to collect yourself, DEF CON 34 has you covered. Join us throughout the conference in room W301. Meetings will be Thursday, Friday, Saturday, and Sunday. ' 1. #LVCCW_Level3_South

Operator, Please Hold - DCG Social

Social Gatherings/Events - LVCCW Level 2 W238 (DEF CON Groups) · Social Gatherings/Events - LVCCW Level 2 W238 (DEF CON Groups)

'Title: Operator, Please Hold - DCG Social Tags: Party | DEF CON Groups (DCG) When: Thursday, Aug 6, 18:00 - 19:59 PDT Where: LVCCW Level 2 W238 (DEF CON Groups) - [1]Map Description: Operator, Please Hold is the official DEF CON Groups party at DEF CON 34 - a social for hackers, DCG organizers, and community builders from around the world. This is where DEF CON Groups converge off the mailing lists and out of Discord. Expect familiar faces, new connections, and conversations that jump from local meetups to global chaos in about five minutes. No talks. No agenda. Just hackers who actually show up for their communities, in one room, at the same time. Whether you run a group, help keep one alive, or are looking to plug into your local hacker scene, this is your stop. Come say hi, compare notes, and meet the humans behind the handles. Operator, please hold. Your people are on the line. ' 1. #LVCCW_Level2_North

Welcome Party at The Industrial

Social Gatherings/Events - The Industrial · Social Gatherings/Events - The Industrial

'Title: Welcome Party at The Industrial Tags: Party When: Thursday, Aug 6, 18:30 - 23:30 PDT Where: The Industrial Description: Kick off DEF CON at our official Welcome Party! We'll meet at [1]The Industrial at 18:30. Standby for details about shuttles from LVCC to The Industrial. ' 1. https://www.theindustrialvegas.com

DC702 Meetup

Social Gatherings/Events - LVCCW Level 3 W327 (Misc Meeting Room) · Social Gatherings/Events - LVCCW Level 3 W327 (Misc Meeting Room)

'Title: DC702 Meetup Tags: Meetup When: Thursday, Aug 6, 19:00 - 21:59 PDT Where: LVCCW Level 3 W327 (Misc Meeting Room) - [1]Map Description: Join the local DC702 Group in this year's official DEF CON Meetup! The meetup will be casual and include typical meetup activities (e.g., socializing, "challenges," lockpicking, music, etc.) and maybe a few little surprises. ' 1. #LVCCW_Level3_South

Conference Planners Meetup

Social Gatherings/Events - LVCCW Level 2 W212 (Misc Meeting Room) · Social Gatherings/Events - LVCCW Level 2 W212 (Misc Meeting Room)

'Title: Conference Planners Meetup Tags: Meetup When: Thursday, Aug 6, 21:00 - 23:59 PDT Where: LVCCW Level 2 W212 (Misc Meeting Room) - [1]Map Description: Are you a conference planner, manager, technologist, etc.? Feel like chatting about what we do, trading contact info, or just grabbing a few drinks with colleagues? This will be a meetup for those of us involved in conference planning and management. There won't be any kind of schedule or agenda. Informal conversation is the name of the game. At least one person from the Hacker Tracker (and ConfMgr) team will be here. You're welcome to ask questions, leave feedback (good or bad), ask for help with some problem you're having, etc. ' 1. #LVCCW_Level2_West

Defcon.run

Social Gatherings/Events - LVCCW Level 1 North Entrance · Social Gatherings/Events - LVCCW Level 1 North Entrance

'Title: Defcon.run Tags: Event When: Friday, Aug 7, 06:00 - 07:59 PDT Where: LVCCW Level 1 North Entrance - [1]Map Description: Defcon.run, formerly the DEF CON 4x5K, is a community-driven tradition where hackers gather for morning runs and rucks across Las Vegas. Participants can choose from various routes, from 5Ks to longer distances. For DEF CON 34, meet at "The Spot" near the North Entrance of the Las Vegas Convention Center West Hall. Activities start at 06:00, Thursday through Sunday; arrive early for safety briefings and community hype. Whether you are an experienced runner or a newcomer, visit defcon.run to sign up and connect with the community. ' 1. #LVCCW_Level1_Hall4

15th Cycleoverride Bike Ride at DEF CON

Social Gatherings/Events - Other / See Description · Social Gatherings/Events - Other / See Description

'Title: 15th Cycleoverride Bike Ride at DEF CON Tags: Event When: Friday, Aug 7, 06:00 - 10:59 PDT Where: Other / See Description Description: At 6am on Friday, the @cycle_override crew will be hosting the 15th DEF CON Bikeride. We'll meet at a local bikeshop, get some rental bicycles, and about 7am will make the ride out to Red Rocks. It's about a 15 mile ride, all downhill on the return journey. So, if you are crazy enough to join us, get some water, and head over to cycleoverride.org for more info. See you at 6am Friday! '

Social Engineering Community Village - Open Hours

Social Engineering Community Village - LVCCW Level 3 W317-319 (Social Engineering Community Village) · Social Engineering Community Village - LVCCW Level 3 W317-319 (Social Engineering Community Village)

'Title: Social Engineering Community Village - Open Hours Tags: Social Engineering Community Village | Creator Event/Activity When: Friday, Aug 7, 08:30 - 17:59 PDT Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - [1]Map Description: Morning, social engineers! Swing by for your SEC merch, claim your seat, and prepare for action... the phones start ringing soon. The Social Engineering Community village dives into one of the most powerful attack surfaces in security: humans. Our village creates a space where attendees can explore the psychology, tactics, and tradecraft behind human-focused hacking. Through presentations, live demonstrations (via contests), and interactive activities, students, defenders, hackers, and the curious can see how reconnaissance, persuasion, and improvisation are used to bypass even the best defenses. At DEF CON the village becomes a live stage for the craft. In the Social Engineering Community Vishing Competition (SECVC), competitors step into a soundproof booth and place real calls using OSINT, creative pretexts, and quick thinking while the audience watches the strategy unfold in real time. In Battle of the Bots, human-created AI agents attempt social engineering calls of their own, exploring what happens when automated systems try their hand at elicitation. Alongside the contests, attendees can have the opportunity to place calls in our "Cold Calls" or listen in to some presentations. The village is built by the community that practices the craft. Volunteers, researchers, hackers, defenders, and curious newcomers all contribute to the content each year, creating space for new voices and ideas to take the stage. Whether you want to watch live un-scripted social engineering calls, understand the psychology behind it, or meet others who love the human side of security, the Social Engineering Community village is the place to experience it at DEF CON. Prerequisites: Attendees are welcome to watch contests, join discussions, and participate in interactive activities with no preparation needed. Competitors in the Social Engineering Community Vishing Competition and Battle of the Bots Contest are selected in advance through a Call for Competitors prior to DEF CON, but some activities such as Cold Calls allow audience members to sign up onsite and participate. Attendees who want to participate in Cold Calls may benefit from brushing up on basic social engineering skills such as rapport building, influence and elicitation techniques. ' 1. #LVCCW_Level3_North

Village Greeting

Social Engineering Community Village - LVCCW Level 3 W317-319 (Social Engineering Community Village) · Social Engineering Community Village - LVCCW Level 3 W317-319 (Social Engineering Community Village)

'Title: Village Greeting Tags: Social Engineering Community Village | Creator Talk/Panel When: Friday, Aug 7, 08:45 - 08:59 PDT Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - [1]Map Description: Join the founders for a preview of what�s happening in the Village this year. ' 1. #LVCCW_Level3_North

SEC Vishing Competition (SECVC)

Contests - LVCCW Level 3 W317-319 (Social Engineering Community Village) · Contests - LVCCW Level 3 W317-319 (Social Engineering Community Village)

'Title: SEC Vishing Competition (SECVC) Tags: Social Engineering Community Village | Contest When: Friday, Aug 7, 09:00 - 11:59 PDT Where: LVCCW Level 3 W317-319 (Social Engineering Community Village) - [1]Map Description: The official DEF CON contest SECVC is back, baby! Watch as teams turn months of research and rehearsal into live calls, matching sharp scripts against real corporate defenses for the win. This year's contest is judged this year by Snow, Jayson E. Street, and Kimberley Mitnick. ' 1. #LVCCW_Level3_North

Offensive Packet Wizardry with Scapy

DEF CON Workshops - LVCCW Level 2 W222 (Workshops) · DEF CON Workshops - LVCCW Level 2 W222 (Workshops)

'Title: Offensive Packet Wizardry with Scapy Tags: DEF CON Workshop | DEF CON Workshops When: Friday, Aug 7, 09:00 - 12:59 PDT Where: LVCCW Level 2 W222 (Workshops) - [1]Map Description: Offensive Packet Wizardry with Scapy is a four-hour, 100% hands-on workshop that teaches attendees to build offensive networking tools from scratch in Python using Scapy, the packet crafting library used by red teams, malware analysts, and vulnerability researchers worldwide. Starting from first principles, raw packet construction, layer stacking, and send/receive mechanics, the workshop moves progressively through active reconnaissance, ARP cache poisoning with live credential interception, TCP/IP stack abuse (session injection, SYN flood, RST killing), protocol fuzzing against an intentionally vulnerable binary service, and full covert channel implementation (ICMP C2 shell, DNS file exfiltration, TCP header steganography). Every technique is implemented live in Python against an isolated lab network. Students leave with a working, importable red team toolkit, a Python package with a unified CLI, that they built themselves and can adapt for future engagements. The workshop concludes with "Silent Pivot", a scored capstone scenario that chains all techniques into a realistic kill chain: stealth discovery, service identification, fuzzer- triggered crash, ICMP command execution, DNS exfiltration of /etc/shadow, and network cleanup, all subject to an IDS alert budget. SpeakerBio: Mike "Chicolinux" Guirao Mike “Chicolinux” Guirao began his journey in the security field roughly 25 years ago while completing a master's degree. Since then, they have developed both broad and deep expertise across this incredible discipline. Currently, they are pursuing a PhD at New Mexico State University, where their research intersects Cybersecurity and Machine Learning/Artificial Intelligence. In addition to their academic pursuits, Mike serves on the organizing team for the Crypto & Privacy Village. This marks their third time teaching a workshop at DEF CON since DEF CON 24. They also hold several notable industry certifications, including the SANS GCIH, ISC2 CC, and Linux+, and they are excited to share their wealth of experience and knowledge. ' 1. #LVCCW_Level2_North

Hands-on IoT firmware extraction and flash forensics

DEF CON Workshops - LVCCW Level 2 W225 (Workshops) · DEF CON Workshops - LVCCW Level 2 W225 (Workshops)

'Title: Hands-on IoT firmware extraction and flash forensics Tags: DEF CON Workshop | DEF CON Workshops When: Friday, Aug 7, 09:00 - 12:59 PDT Where: LVCCW Level 2 W225 (Workshops) - [1]Map Description: Did you ever wanted to hack an IoT device but did not know how to start? Having UART is nice, but does not help in many cases. For a complete analysis of an IoT device, it is required to look at the firmware itself. In most cases this means that the firmware, data or encryption keys need to be extracted from the device memory. Many researchers are hesitant to do that as there is a high risk of destroying the device or leaving it in an inoperable state. In this workshop we will look at different flash memory types (EEPROM, SPI flash, NAND flash, eMMC flash) and how to extract the information from them. We will show that you do not need very expensive hardware to archive your goal and that it is not as complicated as everyone believes. See which tools might be useful for your own lab! Participants will have the opportunity to work in groups and being provided different kinds of IoT devices (e.g. smart speakers). After a tear-down, you can use different chip-off methods (e.g. Hot air, IR soldering) to remove the flash chip and read it out. Optionally, the tools re-ball and re-solder the IC will be available after the workshop. In the end, each team should have the data and a functional device again. Bonus: If you brick the device, you can keep the parts as a souvenir or can wear them as badges. Speakers:Dennis Giese,Braelynn Luedtke,Arnold Wey,Harsha Potu SpeakerBio: Dennis Giese Dennis Giese is a researcher with the focus on the security and privacy of IoT devices. While being interested in physical security and lockpicking, he enjoys applied research and reverse engineering malware and all kinds of devices. His most known projects are the documentation and hacking of various vacuum robots. He calls himself a "robot collector" and his current vacuum robot army consists of over 95 different models from various vendors. He talked about his research at the Chaos Communication Congress, REcon, HITCON, NULLCON, and DEFCON. SpeakerBio: Braelynn Luedtke Hacker and tomato farmer. Enjoys researching the security of anything that piques her curiosity. She has previously presented this research at conferences such as Chaos Communication Congress, HITCON and DEFCON. SpeakerBio: Arnold Wey Arnold Wey is an electronics security researcher. His recent work includes security testing of virtual GPU implementations, robot arm communication protocols, and repurposing a 3D printer for fault injection research. SpeakerBio: Harsha Potu Harsha has been taking things apart since he could get his hands on a screwdriver for fun and profit. Nowadays he is a cybersecurity researcher with a decade of experience in embedded security. He loves to reverse boards + firmware and regularly finds vulnerabilities at various layers of execution. Especially interested in breaking secure boot chain designs! ' 1. #LVCCW_Level2_North

AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover

DEF CON Workshops - LVCCW Level 2 W228 (Workshops) · DEF CON Workshops - LVCCW Level 2 W228 (Workshops)

'Title: AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover Tags: DEF CON Workshop | DEF CON Workshops When: Friday, Aug 7, 09:00 - 12:59 PDT Where: LVCCW Level 2 W228 (Workshops) - [1]Map Description: The shortest path from a marketing-site SSRF to production root often runs through AWS, and most defenders can’t see it happening. This workshop teaches you to walk that path yourself. Working whitebox in provided lab accounts, you’ll move through eight hands-on modules: reading IAM policies for privilege escalation gadgets, turning a single SSRF into a working CLI session via IMDS, abusing cross-account trust, exploiting resource policies across S3/KMS/Lambda, compromising serverless functions, and evading CloudTrail. The workshop closes with a full-chain challenge: build a Python exploit that goes from external SSRF to administrative access in one script. Prerequisites: Basic AWS familiarity (console + CLI), comfort reading JSON policies, Python. Bring a laptop with AWS CLI v2 and Python 3.10+ installed. No prior offensive cloud experience required. Speakers:zeta,Rafa "bane" Gutierrez SpeakerBio: zeta zeta is an internet plumber and computer toucher. he spends his days reading IAM policies and his nights wondering why anyone wrote them that way. SpeakerBio: Rafa "bane" Gutierrez "Rafael (bane) is the founder of Secure Origin, where he helps organizations doing public-interest work improve their security, infrastructure, and operational resilience. His work spans vulnerability research, security architecture, detection engineering, adversary emulation, infrastructure operations, and targeted technical engagements. He is also a researcher and technical lead for The Southlander, a local Los Angeles newsroom. He volunteers with Lucy Parsons Lab and conducts independent research on surveillance technology, supporting reporting on how these systems affect journalists, activists, and local communities." ' 1. #LVCCW_Level2_North

Web Hacking 101

DEF CON Workshops - LVCCW Level 2 W229 (Workshops) · DEF CON Workshops - LVCCW Level 2 W229 (Workshops)

'Title: Web Hacking 101 Tags: DEF CON Workshop | DEF CON Workshops When: Friday, Aug 7, 09:00 - 12:59 PDT Where: LVCCW Level 2 W229 (Workshops) - [1]Map Description: Most security training starts with slides. This workshop starts with a target. Students spend the majority of the course attacking a purpose-built web application across progressive labs covering the vulnerability classes that define modern web security. Each module follows a difficulty curve. Entry-level labs present classic, unfiltered vulnerabilities for students to exploit independently. Difficulty escalates as filters and defenses appear, requiring adaptation and creative problem-solving. Failed payloads, broken assumptions, and dead ends are not setbacks. They are the learning journey. The frustration of a blocked payload and the persistence to find the bypass is how offensive intuition is built. A final exploit chaining challenge ties everything together, combining findings across vulnerability classes to demonstrate how moderate issues chain into critical impact, the way real attacks work. Students attack, fail, adapt, and break through. Hands-on exploitation and the willingness to struggle is the foundation of any security career. It starts here. All you need is a laptop and persistence. Speakers:cale "calebot" smith,Ruchik Dave,Young Seuk Kim,Luke Cycon SpeakerBio: cale "calebot" smith Cale Smith has spent his entire life obsessed with one question: "Yeah, but how does it actually work?" He started out building things, then realized breaking them was more fun, and has been doing exactly that across web, cloud, binary, IoT, and mobile ever since. He now manages a device-focused security team at Amazon, where his "what if I just..." instincts are finally considered a job qualification. SpeakerBio: Ruchik Dave Ruchik Samir Dave is a software engineer and security specialist with nearly 20 years of experience at the intersection of complex systems security and emerging threat landscapes. Ruchik has contributed to security frameworks for aviation systems and privacy-compliant architectures for large consumer IoT ecosystems, bringing safety-critical systems expertise to emerging technology platforms. His current research explores cloud security paradigms, security compliance, AI-assisted threat detection systems, and the novel attack surfaces introduced by machine learning implementations in embedded environments, areas that represent the cutting edge of adversarial research and defensive innovation. With a passion for building secure, large-scale software systems, Ruchik’s work addresses the evolving security challenges where traditional cybersecurity meets artificial intelligence, IoT proliferation, and safety-critical infrastructure. SpeakerBio: Young Seuk Kim Husband, father, hacker, gamer. Young’s path into security started like a good game exploit—he wanted to win, bent the rules, and discovered a passion for hacking. He began as a web app security consultant, moved into penetration testing and red teaming, and now works in application security engineering, helping teams build secure systems (and still breaking things for fun). He also dives into all kinds of games and stories, especially fantasy with Eastern martial arts, and loves dissecting media with the same curiosity he brings to code. SpeakerBio: Luke Cycon Luke is a former builder turned security engineer at Amazon, focused on web, cloud, and embedded device security. He came up building things before he discovered that breaking them taught him more about how they really work. These days he likes to poke at things until they misbehave, then help the builders make sure it doesn't happen twice. Off the clock, you'll find him tinkering with hardware, firing lasers at something, and celebrating each fixed bug with a bit too much whisky. ' 1. #LVCCW_Level2_North

Malware Development 101 - From Zero to Hero: Adapt your payload to your environment

DEF CON Workshops - LVCCW Level 2 W230 (Workshops) · DEF CON Workshops - LVCCW Level 2 W230 (Workshops)

'Title: Malware Development 101 - From Zero to Hero: Adapt your payload to your environment Tags: DEF CON Workshop | DEF CON Workshops When: Friday, Aug 7, 09:00 - 12:59 PDT Where: LVCCW Level 2 W230 (Workshops) - [1]Map Description: This workshop will give an initiation to offensive malware development in C/C++ and how it is possible to adapt the approach depending on the security solution that must be tackled down. Different methods such as ModuleStomping, DLL Injection, Threadless Injection and Hardware Breakpoint for dehooking will be seen. The idea is to start with a basic malware performing process injection and apply additional techniques to start evading EDR. At each step, some analysis on the malware will be performed to understand the differences at the system level and the IOC detected by the EDR. At the end of this workshop, you will have all the knowledge needed to develop your own malware and adapt it to the targeted environment to escape from the basic pattern and spawn your beacons as if EDR didn't exist. SpeakerBio: Yoann "OtterHacker" DEQUEKER Yoann Dequeker (@OtterHacker) is a red team operator at Wavestone entitle with OSCP and CRTO certification. Aside from his RedTeam engagements and his contributions to public projects such as Impacket, he spends time working on Malware Developpement to ease beacon deployment and EDR bypass during engagements and is currently developing a fully custom C2. His research leads him to present his results on several conferences such as LeHack (Paris), Insomni'hack (Swiss) or even through a 4-hour malware workshop at Defcon31,32 and 33 (Las Vegas). All along the year, he publishes several white papers on the techniques he discovered or upgraded and the vulnerabilities he found on public products. ' 1. #LVCCW_Level2_North

Long Live Empire: A C2 Workshop for Modern Red Teaming

DEF CON Workshops - LVCCW Level 2 W231 (Workshops) · DEF CON Workshops - LVCCW Level 2 W231 (Workshops)

'Title: Long Live Empire: A C2 Workshop for Modern Red Teaming Tags: DEF CON Workshop | DEF CON Workshops When: Friday, Aug 7, 09:00 - 12:59 PDT Where: LVCCW Level 2 W231 (Workshops) - [1]Map Description: Behind every breach report from the last decade is a Command and Control (C2) framework. C2 is how operators reach into a compromised network, move sideways, harvest credentials, and stay invisible. This 4-hour, hands-on workshop puts you in the operator's chair. You set up your own Empire team server, learn the listener-stager-agent model from scratch, and run seven exercises that take you from "never touched a C2" to dumping credentials off a box you compromised yourself. You'll spin up an HTTP listener, deploy a .NET agent to a Windows target, and run post-exploitation tradecraft: Rubeus for credentials, SharpHound for AD enumeration, port-forward pivots to internal hosts, and privesc modules that turn a foothold into full control. You'll even build a custom Empire plugin that auto-runs on every new agent. The capstone is a mini-CTF on a cloud-hosted range we keep open all weekend, with a prize for the winners. You leave with the mental model most operators take years to build: how modern C2 actually works, what it assumes about the target, and where defenders most often catch it. No VMs to download. No setup before class. Bring a laptop, get on WiFi, and we'll have agents running before the first break. Speakers:Jake "Hubbl3" Krasnov,Vincent "Vinnybod" Rose,Anthony "Coin" Rose,Dan Niefeld SpeakerBio: Jake "Hubbl3" Krasnov Jake "Hubble" Krasnov is the Red Team Operations Lead at BC Security, with a distinguished career spanning engineering and cybersecurity. A U.S. Air Force veteran, Jake began his career as an Astronautical Engineer overseeing rocket modifications, leading test and evaluation efforts for the F-22, and conducting red team operations with the 57th Information Aggressors. He later served as a Technical Lead Engineer at Boeing Phantom Works, where he focused on embedded security for aviation and space defense projects. A seasoned speaker and trainer, Jake has presented at DEF CON, Black Hat, HackRedCon, HackSpaceCon, and HackMiami, and has previously taught Empire and offensive PowerShell at DEF CON. SpeakerBio: Vincent "Vinnybod" Rose Vincent "Vinnybod" Rose is the Lead Developer for Empire and Starkiller. He is a software engineer with a decade of expertise in building highly scalable cloud services, improving developer operations, and automation. Recently, his focus has been on the reliability and stability of the Empire C2 server. Vinnybod has presented at Black Hat and has taught courses at DEF CON on Red Teaming and Offensive PowerShell. He currently maintains a cybersecurity blog focused on offensive security at https://bcsecurity.io/blog/. SpeakerBio: Anthony "Coin" Rose Dr. Anthony "Coin" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference. SpeakerBio: Dan Niefeld Dan Niefeld is the founder of several Cyber Security and Technology organizations. An accomplished social engineer his career has spanned from program management to organizing conferences like Hack Space Con, Dan has spent his career, educating, mentoring and developing disrupting technologies with a focus of Mission and Community Development. ' 1. #LVCCW_Level2_North

Learning to Hack Bluetooth Low Energy with BLE CTF

DEF CON Workshops - LVCCW Level 2 W232 (Workshops) · DEF CON Workshops - LVCCW Level 2 W232 (Workshops)

'Title: Learning to Hack Bluetooth Low Energy with BLE CTF Tags: DEF CON Workshop | DEF CON Workshops When: Friday, Aug 7, 09:00 - 12:59 PDT Where: LVCCW Level 2 W232 (Workshops) - [1]Map Description: BLE CTF is a series of Bluetooth Low Energy challenges in a capture-the-flag format, created to teach the fundamentals of interacting with and hacking BLE services. Each flag interactively introduces a new concept. Over the years, BLE CTF has expanded across platforms and skill levels. Books, workshops, trainings, and conferences have adopted it as both an educational platform and CTF. As an open source, low-cost, extensible solution, it has helped advance Bluetooth security research. This workshop teaches the fundamentals of hacking BLE through hands-on exercises that introduce beginners to new concepts while giving experienced users a chance to try new tools and techniques. After completing it, you will have a solid understanding of how to hack BLE devices in the wild. New for DEF CON 34: the workshop uses a brand new variant of BLE CTF built specifically for this event. Returning students will face fresh challenges they have not seen before, and the new exercises are designed to resist online walkthroughs and LLM-assisted shortcuts. We will also introduce new client tools, including gratttool, a modern replacement for gatttool (which has been deprecated from most Linux distributions). Whether this is your first BLE CTF or your eighth, you will leave with new skills and tools. Speakers:Ryan "Hackgnar" Holeman,Alek Amrani SpeakerBio: Ryan "Hackgnar" Holeman Ryan Holeman resides in Austin, Texas, where he works as the CISO for Stability AI. He holds a Ph.D. in cyber defense from Dakota State University and has spoken at respected venues such as Black Hat, DEF CON, Lockdown, BSides, Ruxcon, Notacon, and Shmoocon. You can keep up with his current activity, open source contributions, and general news on his blog. His spare time is mostly spent digging into various network protocols, random hacking, creating art, surfing, and shredding local skateparks. SpeakerBio: Alek Amrani Alek Amrani runs the security team at Cape. ' 1. #LVCCW_Level2_North

Agentic Threat Hunting: Building AI That Remembers What You Hunted

DEF CON Workshops - LVCCW Level 2 W233 (Workshops) · DEF CON Workshops - LVCCW Level 2 W233 (Workshops)

'Title: Agentic Threat Hunting: Building AI That Remembers What You Hunted Tags: DEF CON Workshop | DEF CON Workshops When: Friday, Aug 7, 09:00 - 12:59 PDT Where: LVCCW Level 2 W233 (Workshops) - [1]Map Description: Attendees hunt a supply chain compromise in real telemetry. Not a walkthrough - a hunt. A trojanized developer tool has been backdoored. The artifacts are seeded across a shared Splunk instance at layered difficulty: some obvious, some buried. Over four hours, attendees progress through the Five Levels of Agentic Hunting using the open-source Agentic Threat Hunting Framework (ATHF). Each maturity level unlocks new capabilities — structure, searchability, AI research agents, and full agentic workflows — that help them find what they couldn't find before. The first hunt is manual. By the last module, AI agents are surfacing hypotheses, identifying coverage gaps, and pointing hunters toward artifacts they missed. The human decides what to chase. The framework remembers what they found. This is not a tool demo. Attendees will make real analytical decisions, write real SPL queries, hit dead ends, and use AI agents to recover. They leave with a working ATHF workspace, documented hunts from a real investigation, and the experience of hunting with an agentic system. SpeakerBio: Sydney "letswastetime" Marrone Sydney Marrone is a threat hunter, cybersecurity professional, co-founder of THOR Collective, author of the Agentic Threat Hunting Framework, and co-author of the PEAK Threat Hunting Framework. She is passionate about making security knowledge accessible and actionable through hands-on research, open-source collaboration, and community-driven projects like HEARTH (Hunting Exchange And Research Threat Hub). Sydney creates resources, leads workshops, and shares insights that spark curiosity and empower defenders. Outside of work, she writes for THOR Collective Dispatch, lifts weights, and makes cyber-themed music using AI to blend creativity and hacker culture. ' 1. #LVCCW_Level2_North

Hacking Electronic Conspicuity Devices -or- Making Light Aircraft Fly Into Conflict

Aerospace Village - LVCCW Level 1 Hall 3 1103 (Creator Stage 5) · Aerospace Village - LVCCW Level 1 Hall 3 1103 (Creator Stage 5)

'Title: Hacking Electronic Conspicuity Devices -or- Making Light Aircraft Fly Into Conflict Tags: Aerospace Village | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 10:30 PDT Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - [1]Map Description: Standard Operating Procedures should mitigate many of the security issues we found in earlier EFBs, but there's no place for vendor and/or OEM complacency in the industry. This panel will discuss EFBs more fully between the developers and the researchers to educate our audience on this commonly overlooked part of the flight deck. AV Note: This abstract needs an update with one of the presenters that had to pull out. SpeakerBio: Ken Munroe No BIO available ' 1. #LVCCW_Level1_Hall3

Poster Presentations

AI Village - LVCCW Level 1 Hall 2-603 (AI Village) · AI Village - LVCCW Level 1 Hall 2-603 (AI Village)

'Title: Poster Presentations Tags: AI Village | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 2-603 (AI Village) - [1]Map Description: AI Village is going old school academia with various presenters showcasing their research in poster format. Posters will be displayed on digital screens while presenters give conversational overviews of their research and invite casual discussions. ' 1. #LVCCW_Level1_Hall2

Cyber Mirage: Realtime Deepfake Demos

AI Village - LVCCW Level 1 Hall 2-603 (AI Village) · AI Village - LVCCW Level 1 Hall 2-603 (AI Village)

'Title: Cyber Mirage: Realtime Deepfake Demos Tags: AI Village | Creator Event/Activity When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 2-603 (AI Village) - [1]Map Description: Go deepfake yourself! This hands-on demo shows how threat actors leverage open-source deepfake video and voice cloning frameworks to impersonate anyone in realtime, conducting social engineering and compromising organizations using nothing more than a consumer-grade gaming laptop. No specialized hardware, no budget, no nation-state resources required. Come learn the tradecraft firsthand and find out just how convincing you can become. ' 1. #LVCCW_Level1_Hall2

AI Village - Hal CTF

AI Village - LVCCW Level 1 Hall 2-603 (AI Village) · AI Village - LVCCW Level 1 Hall 2-603 (AI Village)

'Title: AI Village - Hal CTF Tags: AI Village | Creator Event/Activity When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 2-603 (AI Village) - [1]Map Description: ' 1. #LVCCW_Level1_Hall2

Biohacking Device Lab

Biohacking Village - LVCCW Level 1 Hall 1-408 (Biohacking Village) · Biohacking Village - LVCCW Level 1 Hall 1-408 (Biohacking Village)

'Title: Biohacking Device Lab Tags: Biohacking Village | Creator Event/Activity When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 1-408 (Biohacking Village) - [1]Map Description: Get hands-on with real medical devices. Learn to identify vulnerabilities, test security controls, and understand how these critical systems work. 21 devices from 9 different MDMs, including BD, Boston Scientific, Siemens Healthineers, Roche, Solventum, Medtronic, MiniMed, and Philips. ' 1. #LVCCW_Level1_Hall1

Embedded & Shredded: Advanced Embedded System Hacking

Biohacking Village - LVCCW Level 1 Hall 1-408 (Biohacking Village) · Biohacking Village - LVCCW Level 1 Hall 1-408 (Biohacking Village)

'Title: Embedded & Shredded: Advanced Embedded System Hacking Tags: Biohacking Village | Creator Event/Activity When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 1-408 (Biohacking Village) - [1]Map Description: This course offers a deep dive into practical techniques for dissecting and manipulating embedded systems. Get hands-on with these core activities: * Visually inspect and document a device to map components, debug interfaces, and attack surfaces * Decode board communication protocols with logic analyzers * Exfiltrate live data over SPI, JTAG, and SWD — and use chip-off / deadbugging to reach embedded storage * Reverse-engineer bare-metal firmware in Ghidra with advanced plugins * Probe embedded defenses — encryption, disabled debug interfaces, glitching, and fault injection * Chain hardware-level access into higher-level exploits — from physical interfaces all the way up to network-exposed services ' 1. #LVCCW_Level1_Hall1

Four Newbies Vs. An Insulin Pump. How Hard Can It Be?

Biohacking Village - LVCCW Level 1 Hall 3 1104 (Creator Stage 4) · Biohacking Village - LVCCW Level 1 Hall 3 1104 (Creator Stage 4)

'Title: Four Newbies Vs. An Insulin Pump. How Hard Can It Be? Tags: Biohacking Village | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - [1]Map Description: Medical devices are becoming increasingly connected—and that includes devices responsible for keeping people alive. In this talk, we share our journey as four security students taking on the challenge of analyzing an insulin pump as relative newcomers to hacking medical devices. Motivated by curiosity, concern for patient safety, and personal stakes, we set out to explore how an attacker might approach such a system using only public information, basic wireless knowledge, and persistence. Rather than presenting ourselves as experts, we focus on the learning process: how we approached an unfamiliar, safety critical system, how we performed threat modeling when the “failure mode” is a human body, and how we handled the many moments where everything stopped making sense. We’ll walk through what worked, what didn’t, and how critical thinking helped us move forward when we hit a wall. By reflecting on where we started, where we are today, and what remains unexplored, this talk highlights the value of a beginner’s mindset when analyzing real world systems like medical devices. Our goal is not to sensationalize risk, but to show how accessible security research, done responsibly, can contribute to better understanding and safer technology. Speakers:Birgitte Jordal,Julia Kucharska,Emilie Jørstad,Selma Jenker SpeakerBio: Birgitte Jordal We are four Norwegian women that hold a bachelor’s degree in Digital Infrastructure and Cybersecurity from NTNU. Our interests include CTFs, ethical hacking, and penetration testing, with experience in cloud infrastructure, secure networking, and threat analysis. SpeakerBio: Julia Kucharska No BIO available SpeakerBio: Emilie Jørstad No BIO available SpeakerBio: Selma Jenker No BIO available ' 1. #LVCCW_Level1_Hall3

Counting the Dead in the Digital Siege: Detection Infrastructure for Cyber-Mapping Patient Harm

Biohacking Village - LVCCW Level 1 Hall 3 1105 (Creator Stage 3) · Biohacking Village - LVCCW Level 1 Hall 3 1105 (Creator Stage 3)

'Title: Counting the Dead in the Digital Siege: Detection Infrastructure for Cyber-Mapping Patient Harm Tags: Biohacking Village | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - [1]Map Description: Ransomware Kills Patients. We Can't Prove It. Here's How We Fix That. Ransomware attacks on hospitals kill people. That's not a hypothesis — it's in the data. A peer-reviewed analysis of Medicare claims (American Economic Journal: Economic Policy, 2026) puts in-hospital mortality at 34 to 38 percent higher during attacks. The dead are disproportionately elderly, critically ill, and patients of color. Dameff et al. (2023) documented emergency department spillover. Neprash, Dameff, and Tully (2024) traced the same pattern through the Change Healthcare attack. The mechanism isn't exotic. Encrypted EHRs mean clinicians are flying blind — no medication history, no imaging, no labs. Networked infusion pumps, ventilators, and monitors drop to manual. Ambulances get diverted, stacking patients at facilities that weren't hit. In rural areas, transfer times go from nine minutes to thirty-three. Here's the deeper problem: these deaths are architecturally invisible. No ICD code exists for "died because the hospital's network was encrypted." No death certificate asks whether the hospital was under cyberattack. No public health surveillance system captures excess mortality from clinical failure caused by ransomware. Mandatory reporting requirements attach to data breach — not patient harm. Voluntary harm-reporting channels exist, but they're anonymous and sporadic. The visible signal is a fraction of what's actually happening. This isn't a technical gap. It's a design failure in the detection infrastructure itself. This talk makes the case for cyber-harm epidemiology. Using a forthcoming law review article, we show that existing systems — ICD external-cause coding, NCHS disaster-death certification, SNOMED CT alignment, the Sendai Framework's Hazard Information Profiles (2025) and Global Disaster-Related Statistics Framework (2026) — can be adapted right now to make cyber-attributable patient deaths visible at population scale. No new treaties required. Better detection produces better attribution. Better attribution makes state obligations under the right to life and the protection of medical units enforceable — not aspirational. The deaths are real. The tools to count them exist. We just haven't connected them yet. That's what this talk is about. Speakers:Jorge Acevedo Canabal,Scott Shackelford,Szymon Skalski SpeakerBio: Jorge Acevedo Canabal, Ostrom Workshop Indiana University US Jorge Acevedo Canabal, MD (University of Puerto Rico School of Medicine, Magna Cum Laude), is a physician and Visiting Scholar at the Ostrom Workshop, Indiana University, working on research that sits at the intersection of healthcare, public health, and cybersecurity, applying epidemiological and disaster medicine methods to map patient harm attributable to healthcare cyberattacks and technological hazards. He previously served as Chief Medical Officer of the Puerto Rico Science, Technology and Research Trust, and currently serves as advisor to the Biohacking Village and Ra�ces Cyber Org. SpeakerBio: Scott Shackelford Scott J. Shackelford is Associate Vice President and Vice Chancellor for Research at Indiana University Bloomington and Provost Professor of Business Law & Ethics at the IU Kelley School of Business. He serves as Executive Director of both the Ostrom Workshop and the Center for Applied Cybersecurity Research, and directs the Ostrom Workshop Program on Cybersecurity & Internet Governance. He is also an Affiliated Scholar at Harvard Kennedy School's Belfer Center and Stanford's Center for Internet and Society. Scott has authored over 100 articles, book chapters, and essays, with research featured in Politico, NPR, CNN, Forbes, Time, and the Washington Post. His books include The Internet of T

The Future of Bug Bounty - Program Manager Perspective

Bug Bounty Village - LVCCW Level 1 Hall 3 1102 (Creator Stage 6) · Bug Bounty Village - LVCCW Level 1 Hall 3 1102 (Creator Stage 6)

'Title: The Future of Bug Bounty - Program Manager Perspective Tags: Bug Bounty Village | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 10:59 PDT Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - [1]Map Description: Bug bounty is a proven model, but AI is changing how it runs. Researchers are submitting at higher volumes, LLM-generated reports are making triage harder, and new assets like AI agents and model endpoints are showing up in scope faster than programs can write playbooks for them. This panel brings together program managers from leading bug bounty programs to talk about what they're seeing from the other side of the queue. What has AI actually changed about the reports, the researchers, and the bugs that matter? What should program managers and security teams be doing about it now? And where is bug bounty headed over the next few years? Whether you run a program, hack on one, or want to start one, you'll come away with a clearer sense of what bug bounty looks like today and where it is going. Speakers:Jai Kumar Sharma,Catherine Cassell,Austin Sturm,Hui Yi Loke SpeakerBio: Jai Kumar Sharma, Principal Offensive Security Engineer at GoDaddy Jai Sharma is a Principal Offensive Security Engineer at GoDaddy, where he manages the company's bug bounty program. He comes to that role from both sides of the table; a longtime bug hunter who has also run bug bounty programs in the past, giving him a rare view of how the relationship works (and breaks down) from each perspective. He cares about making bug bounty work better for hunters and programs alike. Jai also gives back to the community as a DEF CON volunteer, serving as Coordinator for the Bug Bounty Village and CTF Ops for the Cloud Village. SpeakerBio: Catherine Cassell, Product Security Engineer at Github Catherine is a security engineer on the bug bounty team at GitHub. She has five years of experience in offensive security, working in both bug bounty and penetration testing. Catherine has spent the last year and a half at GitHub and runs an annual hardware hacking workshop at the Glass Firewall Conference. At work, she spends her days reading and triaging bounty reports. Outside of work, she spends her free time outside, as far away from screens as possible. You can usually find her hiking or skiing in the Rocky Mountains. SpeakerBio: Austin Sturm He started as a no-good kid on IBB forums and landed a job doing offensive security for large tech companies. For some tireless years he ran and built a team for a cloud providers bug bounty program and continues to act as a tech lead for a bounty program in the wake of the AI-era SpeakerBio: Hui Yi Loke, Tiktok Hui Yi (@angelystor) runs Vulnerability Management at TikTok, where her team triages HackerOne submissions, validates impact, and decides bounties. Before she was on the receiving end of your reports, she was writing them: her earlier career was spent on red teams building malware and C2 systems and doing vulnerability research at GovTech Singapore. She has presented at conferences including Black Hat Asia and SINCON, and sits on the Black Hat Asia Review Board. In her spare time she plays the 古琴 (Guqin) and vibe codes games. ' 1. #LVCCW_Level1_Hall3

Call Center Village - Open

Call Center Village - LVCCW Level 2 W218 (Call Center Village) · Call Center Village - LVCCW Level 2 W218 (Call Center Village)

'Title: Call Center Village - Open Tags: Call Center Village | Creator Event/Activity When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 2 W218 (Call Center Village) - [1]Map Description: Security teams have spent years hardening web-apps, email-gateways, and network-perimeters. Meanwhile, the phone line sitting on every receptionist's desk remains almost completely unmonitored. Nobody's deploying a firewall between a caller and the person who picks up. Caller ID authentication has made some progress, but the conversation itself? Wide open. And now that AI-generated voices can pass for the real thing and automated agents are handling account resets and payment processing, that gap is getting a lot more interesting.Call Center Village is where voice security, conversational AI, and social engineering collide — across both voice and text channels. Sit down at a workstation and synthesize a copy of your own voice with open-source tools running on a local GPU, or let our staff walk you through the process. Dig into voice pipelines, deepfake audio detection, and the arms race between the two. Wire up a working conversational AI agent — stitching together the real-time audio infrastructure, transcription, language model, and speech synthesis that make these systems speak. On the text side, go after chatbot agents tasked with handling simulated customer interactions. Find the cracks in their system prompts, hijack conversation logic, and convince them to do things their developers never intended. Once you're ready, muster all your skills to take on our Escalation Desk CTF, the official Call Center Village contest at DEF CON 34. We've also got a collection of vintage telephones, prank extensions, chatty AI-agents, and a British-style telephone booth worth stopping by for. No prior experience required. If you know how to make a phone call or type a message, you're already qualified. Equipment is provided, including laptops and ANC headsets - but you're more than welcome to bring your own devices. ' 1. #LVCCW_Level2_North

Aw, man…pages!

Contests - LVCCW Level 1 Hall 1-100 (Contest Stage) · Contests - LVCCW Level 1 Hall 1-100 (Contest Stage)

'Title: Aw, man…pages! Tags: Aw, man...pages! | Contest When: Friday, Aug 7, 10:00 - 12:59 PDT Where: LVCCW Level 1 Hall 1-100 (Contest Stage) - [1]Map Description: How well do you know your man pages? Find out by teaming up with up to 3 other people (or come solo and get matched up with some new friends) and play "Aw, man...pages!". Across several rounds, your knowledge of man pages and software will be tested to the limit. Can you remember what command line flag is being described by its help text? Can you identify a tool just from a man page snippet? Can you decipher our cryptic command clues? Will you prove yourself worthy to be crowned the man page champion? Participant Prerequisites None. We will provide answer sheets and pens. Participants can form teams of up to 4 people beforehand, or at the event. ' 1. #LVCCW_Level1_Hall1

Octopus Game - Booth Open

Contests - LVCCW Level 1 Hall 1-201 (Octopus Game) · Contests - LVCCW Level 1 Hall 1-201 (Octopus Game)

'Title: Octopus Game - Booth Open Tags: Octopus Game | Contest When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 1-201 (Octopus Game) - [1]Map Description: ' 1. #LVCCW_Level1_Hall1

Octopus Game - Opening Ceremony

Contests - LVCCW Level 1 Hall 1-201 (Octopus Game) · Contests - LVCCW Level 1 Hall 1-201 (Octopus Game)

'Title: Octopus Game - Opening Ceremony Tags: Octopus Game | Contest When: Friday, Aug 7, 10:00 - 10:59 PDT Where: LVCCW Level 1 Hall 1-201 (Octopus Game) - [1]Map Description: ' 1. #LVCCW_Level1_Hall1

Octopus Game - Registration Check-In

Contests - LVCCW Level 1 Hall 1-201 (Octopus Game) · Contests - LVCCW Level 1 Hall 1-201 (Octopus Game)

'Title: Octopus Game - Registration Check-In Tags: Octopus Game | Contest When: Friday, Aug 7, 10:00 - 12:59 PDT Where: LVCCW Level 1 Hall 1-201 (Octopus Game) - [1]Map Description: ' 1. #LVCCW_Level1_Hall1

Code Cadaver: Break Every System. Save Your Friend.

Contests - LVCCW Level 1 Hall 1-306 (Biohacking Village CTF: Code Cadaver) · Contests - LVCCW Level 1 Hall 1-306 (Biohacking Village CTF: Code Cadaver)

'Title: Code Cadaver: Break Every System. Save Your Friend. Tags: Biohacking Village | Code Cadaver (Biohacking Village CTF) | Contest When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 1-306 (Biohacking Village CTF: Code Cadaver) - [1]Map Description: Biohacking Village Capture the Flag: Test your skills against healthcare-themed capture the flag challenges. From beginner to expert levels, there's something for everyone. Code Cadaver: Break Every System. Save Your Friend. Your best friend entered St. Dismas Hospital with flu-like symptoms. He never came back. Now his hotel room has been torn apart, his phone is still beaconing somewhere in the wreckage, and every clue points toward a hospital that seems less interested in healing people than hiding what happens to them. Code Cadaver is Biohacking Village’s immersive healthcare cybersecurity CTF—a dark, story-driven challenge that pulls players through the connected systems of a compromised hospital and the criminal network surrounding it. Follow wireless signals. Pivot from guest networks into production systems. Hunt through patient intake records, webcams, HL7 traffic, payment systems, RFID credentials, pager networks, infusion devices, DICOM archives, and secured medical cabinets. Every system holds another piece of the truth. Every solved challenge brings you closer to Ethan—and deeper into St. Dismas. This is more than a collection of puzzles. It is a full-chain medical cyber-thriller built around the technologies, mistakes, dependencies, and trust relationships that keep modern healthcare running. You will need technical skill, persistence, curiosity, and a willingness to question everything. The hospital is closing in. The machines are still working. Ethan is running out of time. Break every system. Save your friend before St. Dismas finishes what it started. ' 1. #LVCCW_Level1_Hall1

PWN UR H0M3 - DDoS CTF

Contests - LVCCW Level 1 Hall 1-307 (DDoS Contest) · Contests - LVCCW Level 1 Hall 1-307 (DDoS Contest)

'Title: PWN UR H0M3 - DDoS CTF Tags: DDoS Contest | Contest When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 1-307 (DDoS Contest) - [1]Map Description: A chaotic DDoS-themed CTF where sketchy devices, busted services, weird signals, and sneaky clues are begging to be owned. Scan the network, break IoT devices, decode the nonsense, and prove you can pwn your home before your home pwns you. This CTF is designed to help you learn about the cutting edge in DDoS attacks and defense. We also have an IoT lab of devices hacked and infected with botnet malware that you can play around with. Beginners welcome. We have some fabulous prizes including gift cards donated from Hak5 so please check it out! ' 1. #LVCCW_Level1_Hall1

AI Village Plays Pokemon: DEFCON Edition

Contests - LVCCW Level 1 Hall 2-603 (AI Village) · Contests - LVCCW Level 1 Hall 2-603 (AI Village)

'Title: AI Village Plays Pokemon: DEFCON Edition Tags: AI Village | AI Village Plays Pokemon: DEF CON Edition | Contest When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 2-603 (AI Village) - [1]Map Description: Agent harnesses and tooling have quickly become the AI buzzwords of 2026, but what do these even mean, and why should you consider building them? We’re showing off how custom tooling can empower local models in the most accessible way possible: playing Pokémon. Join us in this fun, novice-friendly demo where we show how to build tooling for local models, and walk through what you should and shouldn’t consider turning into tools. All the models and tools are open source, so feel free to use them to make your own agents to play our emulations of Pokémon Fire Red and Leaf Green. SpeakerBio: Nick Ashworth, Maker at AI Village Nick is a Hacker and Engineer with almost 15 years of experience hacking everything from power grids to satellites for the DoD. He’s presented and made demos for Aerospace, Car Hacking, ICS, and the AI Village for the past seven years. He currently helps lead the AI Village. ' 1. #LVCCW_Level1_Hall2

Blue Team Village CTF - Project Obsidian

Contests - LVCCW Level 2 W213-217 (Blue Team Village) · Contests - LVCCW Level 2 W213-217 (Blue Team Village)

'Title: Blue Team Village CTF - Project Obsidian Tags: Blue Team Village (BTV) | Blue Team Village CTF | Contest When: Friday, Aug 7, 10:00 - 11:59 PDT Where: LVCCW Level 2 W213-217 (Blue Team Village) - [1]Map Description: Join Blue Team Village for a defender-focused Capture the Flag competition centered on forensic analysis, malware activity in containerized environments, and cloud-infrastructure attacks. Participants will investigate container images, reconstruct incidents, and solve challenges ranging from beginner to expert. Challenge tracks include Container & Malware Forensics, Cloud Attack Forensics, and Converged Frontier. Participants can choose safe forensic snapshots or advanced live-malware challenges conducted in an egress-restricted Kubernetes sandbox. ' 1. #LVCCW_Level2_North

Escalation Desk CTF

Contests - LVCCW Level 2 W218 (Call Center Village) · Contests - LVCCW Level 2 W218 (Call Center Village)

'Title: Escalation Desk CTF Tags: Call Center Village | Escalation Desk CTF | Contest When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 2 W218 (Call Center Village) - [1]Map Description: Customer service channels are increasingly saturated with conversational text and voice AI agents. Can you convince, trick, or break enough of them to earn your shot at a live human operator in a real-world call center? Escalation Desk is Call Center Village's capture-the-flag challenge. Start with low-pressure AI agents and learn how to spot, avoid, and exploit common pitfalls and patterns in system prompts — eventually unlocking live human operators at our partner call centers. A real-time leaderboard tracks solo and team progress, with our not-so-famous Golden Telephone Booth trophy awarded to the top participant. Hit our minimum point threshold and earn a special Call Center Village 100 Trying black flight tag. The top individual and their team also take home the rare Call Center Village 200 OK gold flight tags. Bring your tags to Party Line, Call Center Village's after-hours telephony-themed party, and enjoy free refreshments for your spoils. Escalation Desk is beginner (and introvert) friendly — if you can dial a phone number or use a keyboard, you can participate. Bring your own laptop and headset, or use one of our village stations. Active Noise-canceling headphones with a microphone are highly recommended. The CTF will run during village hours, pausing when the village closes each night, and ends on Sunday at 12:00. ' 1. #LVCCW_Level2_North

Welcome to DEF CON 34!

DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1) · DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1)

'Title: Welcome to DEF CON 34! Tags: DEF CON Official Talk | DEF CON Communications When: Friday, Aug 7, 10:00 - 10:30 PDT Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - [1]Map Description: SpeakerBio: Jeff "The Dark Tangent" Moss No BIO available ' 1. #LVCCW_Level1_Hall3

Breaking the Ethereum Phone: From BootROM to Wallet Signing Keys

DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) · DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2)

'Title: Breaking the Ethereum Phone: From BootROM to Wallet Signing Keys Tags: DEF CON Official Talk | Demo 💻 | Exploit �� When: Friday, Aug 7, 10:00 - 10:30 PDT Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - [1]Map Description: Crypto phones promise the convenience of a mobile OS with hardware-backed key management. We tested that claim on dGEN1, the Ethereum phone marketed for digital-asset custody, and present a full compromise from bootrom to wallet key recovery. Starting from a bootrom-level misconfiguration, we reverse the modern MediaTek bootchain and introduce a Loader-of-the-Loader technique for patching later boot stages entirely in memory, yielding EL3 code execution without modifying physical flash. From that foothold, we trace how boot-level compromise propagates into the device’s lock-screen verification path, enabling offline brute-forcing of the user PIN and recovery of the wallet’s primary ERC-4337 signing key. We further show that a separate identity flaw in the asset-claim workflow allows pre-activation theft using identifiers printed on a sealed retail box. SpeakerBio: Guanxing Wen Guanxing Wen is a security researcher with over a decade of experience exploiting bootloaders, TEEs, kernels, and IoT systems. He is a top winner of Huawei bug bounty (2021/2022) and is listed in the Ledger Hall of Fame. His research has been presented at Black Hat, MOSEC, INFILTRATE, Summercon, and QPSS. He currently works at CertiK, where he focuses on low-level systems exploitation and blockchain infrastructure. ' 1. #LVCCW_Level1_Hall3

From square root to /root: escalating privileges in Azure containers with Python in Excel

DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) · DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5)

'Title: From square root to /root: escalating privileges in Azure containers with Python in Excel Tags: DEF CON Official Talk | Demo 💻 | Tool � | Exploit 🪲 When: Friday, Aug 7, 10:00 - 10:59 PDT Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - [1]Map Description: Microsoft integrated Python into Excel, giving users more advanced data analysis. The Python code is processed in a cloud container and returned as results. This sparks an immediate question: does it allow remote code execution on Microsoft owned servers? In this talk, we'll dig into the various web applications and components in the Python execution environment. We'll describe how we discovered a privilege escalation vulnerability in the file upload mechanism of this service, which allowed us to gain root access within the container. Utilizing that, we revealed the complete architecture of this solution. We will show how we discovered Microsoft’s internal deployment configuration, including key vaults, database servers, account names, tenant IDs, and much more. We were even able to execute code on the pilot servers of this product. We also found how to craft a special response to Excel, resulting in bypassing two security boundaries (CVE-2026-45459): the trusted records protection (“Enable Content” warning) and the network isolation protection. We will expose features that weren’t even announced yet and how they might be exploited. Follow us in our journey from the first “whoami” command, through exfiltrating tailor-made Python libraries, and eventually finding a vulnerability to achieve execution as root! https://i.blackhat.com/Asia-25/Asia-25-Carmel-The-Problems-of-Embedded-Python-in-Excel.pdf https://www.netspi.com/blog/technical-blog/red-teaming/a-first-look-at-python-in-excel/ SpeakerBio: Ron Ben Yizhak, SafeBreach Ron (@RonB_Y) is a security researcher at SafeBreach with 11 years of experience. He works in vulnerability research and has knowledge in forensic investigations, malware analysis and reverse engineering. Ron previously worked in the development of security products and spoke several times at DEF CON ' 1. #LVCCW_Level1_Hall3

Weaponizing Uselessness: Breaking SMM with the Slowest Instruction Ever Written

DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) · DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4)

'Title: Weaponizing Uselessness: Breaking SMM with the Slowest Instruction Ever Written Tags: DEF CON Official Talk | Demo �� | Tool � | Exploit 🪲 When: Friday, Aug 7, 10:00 - 10:30 PDT Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - [1]Map Description: This is a talk about making your CPU go slow. Really, really, really slow. It is also, somehow, a talk about breaking platform security on nearly every x86 system ever shipped, activating a hundred dormant CVEs, repeatedly ignoring processor specifications, racing intra-core interrupts, and finding a vulnerability that cannot be fixed. But mostly, it's about going slow. [2]Memory Sinkhole [3]AMD Sinkclose [4]Sandsifter [5]EDK2 SpeakerBio: Christopher "xoreaxeaxeax" Domas Christopher Domas (@xoreaxeaxeax) is a security researcher primarily focused on firmware, hardware, and low level processor exploitation. He is best known for releasing impractical solutions to non-existent problems, including the world's first single instruction C compiler (M/o/Vfuscator), toolchains for generating images in program control flow graphs (REpsych), and Turing-machines in the vi text editor. His more relevant work includes the sandsifter processor fuzzer, rosenbridge backdoor, the binary visualization tool ..cantor.dust.., and the memory sinkhole privilege escalation exploit. ' 1. #LVCCW_Level1_Hall3 2. https://blackhat.com/docs/us-15/materials/us-15-Domas-The-Memory-Sinkhole-Unleashing-An-x86-Design-Flaw-Allowing-Universal-Privilege-Escalation-wp.pdf 3. https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Enrique%20Nissim%20Krzysztof%20Okupski%20-%20AMD%20Sinkclose%20Universal%20Ring-2%20Privilege%20Escalation%20Redacted.pdf 4. https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20presentations/DEF%20CON%2025%20-%20Christopher-Domas-Breaking-The-x86-ISA-UPDATED.pdf 5. https://github.com/tianocore/edk2

Texas Incidents - How we broke the OMAP-L138 Trusted Execution Environment

DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) · DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3)

'Title: Texas Incidents - How we broke the OMAP-L138 Trusted Execution Environment Tags: DEF CON Official Talk | Demo 💻 When: Friday, Aug 7, 10:00 - 10:59 PDT Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - [1]Map Description: In this talk, we'll discuss how we achieved the black-box compromise of the Trusted Execution Environment (TEE) of the Texas Instruments OMAP-L138, a popular SoC encountered in various PMR radios, satcom equipment and other embedded applications. These radios are frequently used in safety-critical roles, where integrity and service availability is paramount. Through a painstaking iterative process, which includes building both a disassembler and a decompiler for the (hellish) DSP architecture, and through blind exploitation of the Texas Instruments ROM code underpinning the TEE functionality, we managed to abuse a (novel type of) timing side channel that exists when attempting to load (bogus) cryptographic modules into the TEE, allowing us to recover the manufacturer key within a minute. The talk dives deep into the technical aspects of the attack, providing a rare perspective on how the simple primitive of "decryption isn't constant time" can ultimately be leveraged into a very tangible result: recovery of the device's full 128-bit AES key. Additionally, we discuss several ROM-based vulnerabilities, including one that enables full secure-mode code execution on the SoC. Vulns are in ROM, so if you're so inclined: feel free to have fun with those on other OMAP-L138-powered devices. Speakers:Carlo Meijer,Wouter Bokslag SpeakerBio: Carlo Meijer, Midnight Blue Carlo Meijer is a founding partner of the boutique security consultancy firm Midnight Blue and is most known for his research into TETRA, the MIFARE Classic Crypto1 RFID cipher, and the security of self-encrypting drives. Furthermore, Carlo regularly competes in the famous Pwn2Own hacking competition, where he is part of team PHP Hooligans. SpeakerBio: Wouter Bokslag, Midnight Blue Wouter Bokslag is a co-founding partner and security researcher at Midnight Blue. He is known for the reverse-engineering and cryptanalysis of several proprietary in-vehicle immobilizer authentication ciphers used by major automotive manufacturers as well as co-developing the world’s fastest public attack against the Hitag2 cipher. He holds a Master’s Degree in Computer Science & Engineering from Eindhoven University of Technology (TU/e) and designed and assisted in teaching hands-on offensive security classes for graduate students at the Dutch Kerckhoffs Institute for several years. Recently heavily involved in the TETRA:BURST research and associated follow-up research, such as the recent reverse-engineering and analysis of the elusive TETRA End-to-End protocol. Also, a contributer of open-source SDR code. ' 1. #LVCCW_Level1_Hall3

AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory

Demo Labs - LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) · Demo Labs - LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)

'Title: AD-Necromancer: Resurrecting Forgotten Control Paths in Active Directory Tags: Demo Labs | Advanced | Offense/Red Team | DEF CON Demo Labs When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - [1]Map Description: Every pentest, same story - BloodHound says no path to DA, client celebrates, meanwhile a 2019 service account has AddAllowedToAct on a production DC that nobody remembers. AD-Necromancer finds what humans forget. Give it a username, password, and domain — it bootstraps EDR evasion (ETW patching, DLL unhooking, Halos Gate syscalls), collects AD data over ADWS instead of LDAP, encrypts with AES-256-GCM, and exfils to C2 with zero artifacts. One command, credentials to findings. It feeds tokenized BloodHound data to an LLM for semantic reasoning - forgotten RBCD, ghost cross-forest delegations, orphaned admin accounts no compliance checklist catches. Privacy Cloak ensures real names never leave the box. Open source, MIT licensed. Come dig up what your tools missed. Speakers:Akbar "0xsensei" Abdullayev,0xHera SpeakerBio: Akbar "0xsensei" Abdullayev Offensive security professional with 5+ years of experience in Active Directory and cloud security, specializing in red teaming and enterprise attack chains. SpeakerBio: 0xHera I am a freelance Offensive Tool Developer and Security Enthusiast building practical tools and sharing research with the community to help others better understand attack paths, real-world offensive techniques, and defensive improvements. ' 1. #LVCCW_Level1_Hall3

Peekaboo: Breaking the Black Box of Threat and Malware Emulation

Demo Labs - LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) · Demo Labs - LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)

'Title: Peekaboo: Breaking the Black Box of Threat and Malware Emulation Tags: Demo Labs | Intermediate | Defense/Blue Team | Malware | Offense/Red Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - [1]Map Description: Standard security testing often forces a choice: use "script-kiddie" tools that get caught instantly, or use high-end frameworks that are too complex for rapid detection testing. Peekaboo bridges this gap. In this Demo Lab, we present Peekaboo - a modular, open-source framework designed for safe threat emulation. Unlike traditional malware, Peekaboo focuses on generating high-fidelity telemetry through legitimate cloud API abuse (GitHub, Bitbucket, Slack, Discord, Azure, VirusTotal, XBOX, AngelCam, etc) and evasive execution techniques (Direct Syscalls, Callback-based execution). We will demonstrate how to: * Generate polymorphic agents that bypass static analysis using rare cryptographic algorithms like Speck and Skipjack. * Generate agents that leverage signal processing like Fast Fourier Transformation and Feistel-network based cryptography for bypass EDR. * Establish covert C2 channels within the metadata of trusted enterprise applications. * Rapidly test EDR/SIEM rules against modern persistence and lateral movement techniques without risking system stability. Peekaboo isn't just a tool; it's a "sandbox-friendly" adversary in a box, designed to help Blue Teams level up by understanding the nuances of the Offensive Dev Loop. Come see how we turn "hidden" threats into "visible" learning opportunities. SpeakerBio: Zhassulan "cocomelonc" Zhussupov cybersecurity enthusiast, author, speaker and mathematician. Author of popular books: MD MZ Malware Development Book (Github, 2022, 2024) MALWILD: Malware in the Wild Book (Github, 2023) Malware Development for Ethical Hackers Book: (Packt, 2024) AIYA Mobile Malware Development Book (Github, 2025) Malware Development for Ethical Hackers 2nd edition (Packt, 2026, in progress) Author and tech reviewer at Packt. Co founder of various cybersecurity research labs, author of many cybersecurity blogs, HVCK magazine Malpedia contributor Speaker at BlackHat, DEFCON, Security BSides, Arab Security Conference, Hack.lu, Standoff, Positive Hack Talks, etc conferences ' 1. #LVCCW_Level1_Hall3

Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop

Demo Labs - LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) · Demo Labs - LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)

'Title: Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for AWS — No SIEM, Just Your Laptop Tags: Demo Labs | Intermediate | Cloud | Defense/Blue Team | Purple Team | Threat Intel/Hunting | DEF CON Demo Labs When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - [1]Map Description: Senrigan (千里眼) and Suzaku (朱雀) are two complementary open-source tools that together form a complete threat hunting and DFIR platform for AWS CloudTrail logs. Both are built by Yamato Security, the volunteer-run Japanese security community behind Hayabusa(隼), the widely adopted Windows event log fast-forensics tool. Yamato Security provides free, open-source DFIR tools and resources to the community. Building on Hayabusa's philosophy of fast, offline, community rule-based detection, this toolset brings the same approach to the cloud. Security teams can hunt threats across CloudTrail logs on a single laptop — without a SIEM, dedicated infrastructure, or licensing cost. The two tools work together, with Suzaku's detections flowing into Senrigan for analysis. Senrigan, deployed via Docker Compose, ingests CloudTrail logs into DuckDB via a Rust-based ingester, then lets analysts investigate them through 100+ pre-built hunting queries and 80+ pre-built Apache Superset dashboard charts — no SQL or CloudTrail schema knowledge required. Suzaku is a high-performance, standalone Rust-based CLI that applies native Sigma detection rules to CloudTrail logs and generates a fast-forensics DFIR timeline — surfacing attacks buried in the noise, producing only the events analysts need to investigate. Speakers:Fukusuke Takahashi,Zach Mathis,Akira Nishikawa SpeakerBio: Fukusuke Takahashi Fukusuke Takahashi has been with NTTDATA-CERT (NTT DATA Group Corporation's CSIRT) since 2018, specializing in DFIR, OSINT, and SOAR. He is one of the developers of Yamato Security's OSS tools. He enjoys developing open-source Blue Team tools. He has presented at conferences such as FIRST Annual Conferences, SECCON, BSides Tokyo, HITCON CMT, SecTor and AUSCERT. SpeakerBio: Zach Mathis Zach Mathis has been working in Japan doing offensive and defensive security work for Japanese companies since 2006. In 2012, he founded Yamato Security, one of the largest hands-on hacker communities in Japan. With other Yamato Security members, he has been releasing free and open source DFIR tools and resources since 2020. SpeakerBio: Akira Nishikawa Akira Nishikawa started his career as a software engineer specializing in embedded development. He worked as a freelance engineer in 2007, focusing on system development and operation for various companies. Since 2021, he has been dedicated to fostering a security culture for SaaS product security and improving service security. Additionally, he is an AWS Community Builder as of 2024. ' 1. #LVCCW_Level1_Hall3

X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain

Demo Labs - LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) · Demo Labs - LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)

'Title: X-Ray Your Agents: Pentesting MCPs, Skills, and the Plugin Supply Chain Tags: AI | Demo Labs | Intermediate | AppSec | Offense/Red Team | Purple Team | DEF CON Demo Labs When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - [1]Map Description: Agents now run with thousands of third-party plugins — MCP servers, Claude skills, GPT actions, IDE extensions, plugin marketplaces — and the prevailing trust model is roughly “read the README and hope.” Tool descriptions are executable prompts. Tool parameters are executable code paths. Tool outputs feed straight into the next agent step. Yet there is no npm audit for this ecosystem, no signed manifests, and no capability sandbox in the wild. MCP X-Ray is an open-source security scanner that ports classical pentest tradecraft to the agent plugin supply chain. It combines static config and repo audit, rules-based and LLM-driven semantic analysis, and active pentesting that actually invokes tools with adversarial inputs — emitting SARIF that drops into GitHub, VS Code, and CI gates today. In this 30-minute session we will (1) walk the threat model that ties MCPs, skills, and plugin bundles together; (2) live-demo X-Ray finding real vulnerabilities in each. Attendees walk away with a CI template they can drop in on Monday, and three intentionally vulnerable plugins to keep practicing on. Speakers:Xia Hua,Abhijeet Kumar SpeakerBio: Xia Hua Xia is co-founder and CEO of Traceforce which secures AI native apps running on devices. She previously led engineering at Clumio (acquired by Commvault), delivering cloud data protection products that were 20x faster and 10x more scalable than competitors. Earlier, she was an in-memory database architect at Oracle. Xia earned her PhD in Applied Mathematics from MIT. SpeakerBio: Abhijeet Kumar Abhijeet Kumar is an OSCP-certified offensive security researcher and M.Eng Cybersecurity student at the University of Maryland. He has disclosed critical vulnerabilities across NASA, SAIL critical infrastructure, Keurig Dr Pepper, and U.S. government programs which includes a CVSS 10.0 RCE that triggered an official CERT-In incident response and a full account takeover chain affecting users across 20+ countries. He captains UMD's CTF team RandomHackers, which placed 1st out of 64 universities at HTB Hack The Madness 2026, and has spoken at the Billington State and Local Cybersecurity Summit alongside the Director of Adversary Emulation. ' 1. #LVCCW_Level1_Hall3

PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale

Demo Labs - LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) · Demo Labs - LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)

'Title: PromptPwn: Finding and Exploiting AI-Generated Vulnerabilities at Scale Tags: AI | Demo Labs | Intermediate | AppSec | Defense/Blue Team | DevOps | Offense/Red Team | Purple Team | DEF CON Demo Labs When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - [1]Map Description: AI-assisted development tools don’t just introduce vulnerabilities; they introduce the same vulnerabilities repeatedly. PromptPwn is a tool designed to identify, track, and exploit common insecure patterns found in AI-generated code. It maintains a database of known vulnerability patterns produced by popular “vibe coding” workflows and provides scanning capabilities to detect these issues in real applications. In this demo, we show how PromptPwn identifies vulnerable patterns such as injection flaws, authentication weaknesses, and insecure defaults across generated code. We demonstrate how these patterns can be exploited in practice, highlighting how repeatability makes them especially valuable from an attacker’s perspective. We also explore how prompt variations influence these outcomes and show how insecure patterns can be remediated by adjusting prompts, closing the loop between generation, exploitation, and correction. This session focuses on practical demonstrations of how AI-generated code fails in predictable ways, and how those failures can be identified and abused at scale. SpeakerBio: Georgia Weidman Georgia Weidman is an offensive security researcher and author focused on breaking real-world systems. She wrote Penetration Testing: A Hands-On Introduction to Hacking, a practical guide used by students and practitioners to learn exploitation techniques. Her work centers on how modern systems fail under attack, from mobile and IoT to enterprise environments. As a DARPA Cyber Fast Track performer, she developed the Smartphone Pentest Framework (SPF), a platform for mobile exploitation research. She has conducted penetration tests, built exploitation tooling, and developed attack chains across multiple domains. Her approach prioritizes hands-on techniques over theory, demonstrating how assumptions about security break down in practice. Georgia has presented internationally at conferences including Black Hat and DEF CON, with a focus on showing how things actually get hacked. ' 1. #LVCCW_Level1_Hall3

Empire 7: Shipping a C2 at AI Speed

Demo Labs - LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) · Demo Labs - LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)

'Title: Empire 7: Shipping a C2 at AI Speed Tags: Beginner | AI | Demo Labs | DevOps | Malware | Offense/Red Team | Purple Team | DEF CON Demo Labs When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - [1]Map Description: Empire 7 is a near-total overhaul of the Command and Control (C2) framework, from how agents communicate with the server to how operators move through engagements. This major release continues to expand Empire's supported agents to include PowerShell, Python, IronPython, Go, C#, and now C. New tradecraft includes more than 50 new modules derived from Atomic Red Team, patchless AMSI/ETW bypasses, EarlyBird process hollowing, BOF execution with ILRepack assembly merging, and RDP session hijacking, among others. Empire's new cryptographically secure communications leverage AES-256-GCM and mTLS, with MITRE ATT&CK integration to assist in emulating real-world Advanced Persistent Threat (APT) Tactics, Techniques, and Procedures (TTPs). One more thing we'll talk about, this release shipped at roughly 10x our prior pace, due to our team’s adoption of agentic coding tools as a core development collaborator. We'll share what worked, what didn't, and what LLM-assisted offensive tooling development looks like. Speakers:Vincent "Vinnybod" Rose,Jake "Hubbl3" Krasnov,Anthony "Coin" Rose SpeakerBio: Vincent "Vinnybod" Rose Vincent "Vinnybod" Rose is the Lead Developer for Empire and Starkiller. He is a software engineer with a decade of expertise in building highly scalable cloud services, improving developer operations, and automation. Recently, his focus has been on the reliability and stability of the Empire C2 server. Vinnybod has presented at Black Hat and has taught courses at DEF CON on Red Teaming and Offensive PowerShell. He currently maintains a cybersecurity blog focused on offensive security at https://bcsecurity.io/blog/. SpeakerBio: Jake "Hubbl3" Krasnov Jake "Hubble" Krasnov is the Red Team Operations Lead at BC Security, with a distinguished career spanning engineering and cybersecurity. A U.S. Air Force veteran, Jake began his career as an Astronautical Engineer overseeing rocket modifications, leading test and evaluation efforts for the F-22, and conducting red team operations with the 57th Information Aggressors. He later served as a Technical Lead Engineer at Boeing Phantom Works, where he focused on embedded security for aviation and space defense projects. A seasoned speaker and trainer, Jake has presented at DEF CON, Black Hat, HackRedCon, HackSpaceCon, and HackMiami, and has previously taught Empire and offensive PowerShell at DEF CON. SpeakerBio: Anthony "Coin" Rose Dr. Anthony "Coin" Rose is an officer in the United States Air Force, an Assistant Professor, and the Director of the Center for Cyberspace Research at the Air Force Institute of Technology. He holds a doctorate in Electrical Engineering and has expertise in machine learning, with a focus on its application to cybersecurity and malware detection. He is also the founder of SIMAPTIC and the Director of Security Research at BC Security, where he specializes in adversary tactics and emulation planning, Red and Blue Team operations, and embedded systems security. Dr. Rose is credited with 16 CVEs and has presented at numerous security conferences, including Black Hat, DEF CON, HackSpaceCon, HackMiami, and RSA Conference. ' 1. #LVCCW_Level1_Hall3

Makers' Village - Hacker Arts and Crafts

Maker's Village - LVCCW Level 1 Hall 1-301 (Makers' Village) · Maker's Village - LVCCW Level 1 Hall 1-301 (Makers' Village)

'Title: Makers' Village - Hacker Arts and Crafts Tags: Maker's Village | Creator Event/Activity When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 1-301 (Makers' Village) - [1]Map Description: Soldering SAO, Embroidery Machine, Laser Etcher, 3d Printers, Trade Table, Letter Bracelets, FuzeBeads, Stamp Making, Bottle Cap Resin Magnets, and Silk Screening throughout the weekend as volunteer permits. ' 1. #LVCCW_Level1_Hall1

Maritime Hacking Village Policy Panel: Subsea Cables as Strategic Chokepoints - Security, Sovereignty, and the Grey Zone

Maritime Hacking Village - LVCCW Level 1 Hall 3 801 (Creator Stage 2) · Maritime Hacking Village - LVCCW Level 1 Hall 3 801 (Creator Stage 2)

'Title: Maritime Hacking Village Policy Panel: Subsea Cables as Strategic Chokepoints - Security, Sovereignty, and the Grey Zone Tags: Maritime Hacking Village | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - [1]Map Description: Subsea cables carry the overwhelming majority of the world’s digital traffic, yet the legal, operational, and diplomatic frameworks for protecting them remain fragmented. Recent cable disruptions, suspected anchor drags, and other “accidents” have highlighted how critical infrastructure at sea can become a target of grey zone activity while leaving governments, operators, and allies with limited options for attribution and response. This panel will examine what is being done to secure subsea cable infrastructure, where current domestic and international regimes fall short, and what new partnerships, authorities, and deterrence models may be needed. How should governments, industry, and the security community respond when the backbone of the internet runs through contested waters? Speakers:RADM John Mauger,Michael Sulmeyer SpeakerBio: RADM John Mauger, PORTS LLC, USCG (ret.) Rear Admiral John W. Mauger, USCG (Ret.) is a seasoned executive with over 33 years of leadership experience in the maritime industry, national security, and cyber operations. Known for his foresight, innovative approach to problem solving, and ability to drive change, John has left an indelible mark on every role he’s undertaken—from commanding complex Coast Guard operations to shaping the future of cyber defense. As Commander of the First Coast Guard District, he led over 12,000 people and oversaw critical port operations in New England, deploying innovative technologies like counter-drone systems to enhance security. John's leadership during the TITAN capsule search and recovery at the TITANIC site highlighted his ability to lead complex crises in the international spotlight. At U.S. Cyber Command, John revolutionized cyber training, developing a cloud-based environment that modernized cyber exercises and increased readiness. John also served as the Coast Guard’s first Executive Champion the National Naval Officers Association, mentoring future leaders and driving organizational change. Earlier in his career, John led key regulatory projects for both domestic and international shipping. His work protected mariners and the environment, created new markets for alternative fuels, and established a new international code to safeguard vital Polar regions. Now leading (PORTS) LLC, John uses his diverse expertise to help clients plan for and navigate complex challenges in the maritime and critical infrastructure industries while enhancing personnel and team performance through effective training. SpeakerBio: Michael Sulmeyer, US DoD (ret.), Georgetown School of Foreign Service Michael Sulmeyer will start as Professor of the Practice at the School of Foreign Service's Security Studies Program in the fall of 2025. He most recently served as the first Assistant Secretary of Defense for Cyber Policy and as Principal Cyber Advisor to the Secretary of defense. He has held other senior roles involving cyber-related issues with the U.S. Army, the Office of the Secretary of Defense, U.S. Cyber Command and the National Security Council. In academia, he was a Senior Fellow with Georgetown's Center for Security and Emerging Technology. He holds a doctorate in politics from Oxford University where he was a Marshall Scholar, and a law degree from Stanford Law School. ' 1. #LVCCW_Level1_Hall3

Bypassing KYC Vendors on AI Times

Mobile Hacking Community - LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community) · Mobile Hacking Community - LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community)

'Title: Bypassing KYC Vendors on AI Times Tags: Mobile Hacking Community | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 10:45 PDT Where: LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community) - [1]Map Description: In this talk, the Just Mobile Security team will talk about the KYC implementation, how to bypass them, and some 0 days for vendors. Speakers:Juan Urbano Stordeur,Juan Martinez Blanco SpeakerBio: Juan Urbano Stordeur, CEO and Founder at Just Mobile Security No BIO available SpeakerBio: Juan Martinez Blanco, Mobile Security Penetration Tester at Just Mobile Security No BIO available ' 1. #LVCCW_Level1_Hall4

Mobile Hacking - Informal CTF

Mobile Hacking Community - LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community) · Mobile Hacking Community - LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community)

'Title: Mobile Hacking - Informal CTF Tags: Mobile Hacking Community | Creator Event/Activity When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community) - [1]Map Description: Capture the Flag (CTF) events featuring mobile application security challenges at varying levels of difficulty, also providing a ranking system to evaluate and compare participants’ skills. ' 1. #LVCCW_Level1_Hall4

Mobile Hacking Community - Open

Mobile Hacking Community - LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community) · Mobile Hacking Community - LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community)

'Title: Mobile Hacking Community - Open Tags: Mobile Hacking Community | Creator Event/Activity When: Friday, Aug 7, 10:00 - 17:59 PDT Where: LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community) - [1]Map Description: At the Mobile Hacking Community, attendees will learn about the latest trends in mobile application security through hands-on experiences, including topics such as bypassing security mechanisms and hardening techniques, and exploiting known CVEs. Additionally, attendees will engage in a competitive process by participating in an onsite CTF (Capture the Flag) event to test their skills, face new challenges, and learn new skills. Attendees will also have the opportunity to watch cutting-edge research presentations and case studies on various topics within the domain. Dedicated real devices running vulnerable applications will be available, allowing attendees to actively practice exploitation and analysis in a realistic environment. Prerequisites: * Attendees should bring their own laptop in order to fully participate in the hands-on workshops and CTF challenges. * A basic familiarity with using a command line, installing software, and general computing concepts is recommended, but prior mobile security experience is not required. ' 1. #LVCCW_Level1_Hall4

OSINT4Good: What it takes to find missing people

OSINT For Good Community - LVCCW Level 1 Hall 3 1100 (Creator Stage 7) · OSINT For Good Community - LVCCW Level 1 Hall 3 1100 (Creator Stage 7)

'Title: OSINT4Good: What it takes to find missing people Tags: OSINT For Good Community | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 10:59 PDT Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - [1]Map Description: Have you ever wondered what it takes to used gamified OSINT to find missing people? Moderated by a Director from Trace Labs, this panel brings together a participant (who won Most Valuable OSINT), a coach (who has coached more times than anyone on the planet), and a report writer (who leads the team of report writers) to walk you though the different perspectives of this work. Speakers:Angela Ramos,Kenny J,Brent Louie SpeakerBio: Angela Ramos, University of Tampa Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coaches Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations. SpeakerBio: Kenny J, Trace Labs Senior Infrastructure Engineer by day. Osint for Good by night. SpeakerBio: Brent Louie, Trace Labs Brent Louie is the Reporting Team Lead at Trace Labs and an Associate Director of Data Science with more than 15 years of experience in the biotechnology industry. He focuses on applying OSINT methodologies to missing persons investigations and helping transform crowdsourced research into actionable investigative leads for law enforcement. ' 1. #LVCCW_Level1_Hall3

Sovereign by Design, Vulnerable by Default

Policy @ DEF CON - LVCCW Level 1 Hall 3 801 (Creator Stage 1) · Policy @ DEF CON - LVCCW Level 1 Hall 3 801 (Creator Stage 1)

'Title: Sovereign by Design, Vulnerable by Default Tags: Policy @ DEF CON | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 10:59 PDT Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - [1]Map Description: Every major government is now making sovereign AI decisions. Data localization. Domestic cloud mandates. Trusted vendor regimes. Export controls on chips and model weights. Engineers and security teams don't get a vote on whether sovereignty happens — they inherit the architecture it creates. And that architecture has seams. This talk is a security analysis of what sovereignty does to threat models, and what policy designers can do about it. Sovereignty initiatives change architecture. Architecture changes threat models. Policy that ignores this chain creates new vulnerabilities. Policy that understands it can improve resilience — but only if it's designed with the seams in mind. Speakers:Devin Lynch,Haley Ring,Andreas Kaltsounis SpeakerBio: Devin Lynch, Paladin Global Institute Devin Lynch is the Senior Director of the Paladin Global Institute and a former Director for Cyber Policy and Strategy Implementation at the Office of the National Cyber Director (ONCD). He has held key roles in both the private sector and government, including positions at the U.S. House of Representatives, U.S. Senate, and the Departments of Homeland Security and Defense. He is an adjunct professor at the George Washington University’s Elliott School of International Affairs and has served in the U.S. Navy Reserve for over 20 years, including combat deployments to Iraq and Afghanistan. SpeakerBio: Haley Ring, Paladin Global Institute Haley Ring is the Director at the Paladin Global Institute, where she helps drive initiatives that strengthen national resilience, protect critical infrastructure, and shape the future of emerging technology. She previously served in the Biden-Harris Administration, advising on national security, technology policy, and public engagement as the Advisor for Engagement to the Second Gentleman and as a Special Advisor in the White House Office of the National Cyber Director. Before her White House roles, Haley worked at the Department of Defense in the Office of the White House Liaison. She began her career on the Biden for President campaign and is originally from Newton, Massachusetts. Haley holds a bachelor’s degree from the University of Wisconsin–Madison and is based in Washington, D.C. SpeakerBio: Andreas Kaltsounis, BakerHostetler Andreas Kaltsounis is an attorney and co-lead of BakerHostetler’s Digital Risk Advisory & Cybersecurity practice, where he advises clients on privacy and security compliance, incident response, and regulatory defense. He holds the CISSP certification, is an IAPP Fellow of Information Privacy, and is ranked by Chambers USA and Chambers Global for his work in privacy and cybersecurity law. Before practicing law, Andreas was a managing director at an international information security consulting firm and served as a federal agent investigating criminal and national security cyber matters. ' 1. #LVCCW_Level1_Hall3

Not Your Parents’ Schoolhouse Rock: Getting Tech Policy Done in a Non-Functioning Congress

Policy @ DEF CON - LVCCW Level 2 W210-211 (Policy Village) · Policy @ DEF CON - LVCCW Level 2 W210-211 (Policy Village)

'Title: Not Your Parents’ Schoolhouse Rock: Getting Tech Policy Done in a Non-Functioning Congress Tags: Policy @ DEF CON | Creator Talk/Panel When: Friday, Aug 7, 10:00 - 10:59 PDT Where: LVCCW Level 2 W210-211 (Policy Village) - [1]Map Description: Forget "Schoolhouse Rock." In a modern, gridlocked Congress, laws aren't just made; they survive a grueling gauntlet and get mangled along the way. Jeff Rothblum (Founder, Plaintext Strategies; former Senate/White House) and Mike Flynn (Vice President & Counsel, ITI; former Senate/House) provide an unfiltered, behind-the-scenes look at the legislative combat required to pass the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), the most significant cyber law in a decade. This session breaks down the "Inside-Outside" game: from the "Prom" analogy that gave the bill room to breath, the coming together of fractious industry groups, and the internal administration "civil war" between CISA and the FBI. We’ll explain how we used the threat of higher fines to force industry to the table, how we dodged jurisdictional minefields by avoiding the Judiciary and Oversight Committees, and why we eventually traded the bill's name just to buy the Cybersecurity and Infrastructure Security Agency (CISA) more time to write the rules. This is your manual for how to actually "get shit done" in a non-functioning D.C. Speakers:Jeffrey Rothblum,Michael Flynn SpeakerBio: Jeffrey Rothblum, Plaintext Strategies Jeff Rothblum, founder of Plaintext Strategies, has worked at the intersection of technology and policy for two decades. He has led government affairs at an AI startup, served as a cyber threat intelligence analyst, led cybersecurity policy the Senate Homeland Security and Governmental Affairs Committee, served as a Director of Cyber Policy and Plans at the White House Office of the National Cyber Director, and co-owned an artisan blacksmithing company. SpeakerBio: Michael Flynn Mike Flynn is Senior Vice President and Counsel for Government Affairs and Economic Security Policy at the Information Technology Industry Council (ITI). In this capacity, he leads ITI’s advocacy efforts on cybersecurity issues and the national security implications of technology and telecommunications. He has led technology policy in the Senate Homeland Security and Government Affairs Committee, on the Committee on Oversight and Government Reform, and the Committee on Homeland Security. Mike was also the lead cybersecurity oversight attorney that investigated the data breaches at the Office of Personnel Management in 2014. ' 1. #LVCCW_Level2_West

Pickpocketing for Red Teamers: A Hands-On Experience

Social Engineering Community Village - LVCCW Level 3 W320 (Social Engineering Community Village Labs) · Social Engineering Community Village - LVCCW Level 3 W320 (Social Engineering Community Village Labs)

'Title: Pickpocketing for Red Teamers: A Hands-On Experience Tags: Social Engineering Community Village | Creator Event/Activity When: Friday, Aug 7, 10:00 - 11:30 PDT Where: LVCCW Level 3 W320 (Social Engineering Community Village Labs) - [1]Map Description: Seven years ago, pradameinhof ran the world's first public pickpocketing competition with about 200 people at a social engineering conference. The inspiration? His dad got pickpocketed right next to him on the Paris Metro. What started as frustration turned into obsession�not just with preventing it, but with understanding how easy it is to pull off. It was hard enough finding good resources. The real problem? Testing your skills in realistic scenarios can land you in jail. In this two-hour Social Engineering Community session, pradameinhof will teach what he learned: the core techniques of attention manipulation�directing and surfing attention, relative touch, entering personal space, giving shade, fanning, and working in teams. You'll learn to lift wallets, watches, phones, badges, and keys, and apply these skills to red-teaming. Here's how it works: You'll pair up and take turns�one practitioner, one target. No prior experience necessary. What to bring: A jacket and pants with pockets that aren't too tight. Wear a watch if you have one. Because you will need to steal from other people and be pickpocketed, expect to touch and be touched by others in order to participate�all appropriately and with clear consent. Join us in this group exercise to understand the human blind spots that make physical social engineering so effective. Walk away with skills for your next red-team engagement�and better awareness so you don't become a target. (Disclaimer: This exercise is for educational purposes only. If you pickpocket people without their consent, expect to get into trouble.) SpeakerBio: pradameinhof pradameinhof has worked in cyber security startups for over two decades. Most of his skills he acquired by pestering his friends and colleagues over coffee. He has a passion for OSINT and Social Engineering. ' 1. #LVCCW_Level3_North

Hacker Runway Crafting Time

The Diana InitiativeHack3r Runw@y v8.0 - LVCCW Level 2 W209 (Diana Initiative) · The Diana InitiativeHack3r Runw@y v8.0 - LVCCW Level 2 W209 (Diana Initiative)

'Title: Hacker Runway Crafting Time Tags: The Diana Initiative | Hack3r Runw@y v8.0 | Creator Event/Activity When: Friday, Aug 7, 10:00 - 11:59 PDT Where: LVCCW Level 2 W209 (Diana Initiative) - [1]Map Description: Hacker Runway Crafting time - didn't have time, or didn't know about the Hacker Runway competition? Have no fear we have some supplies to help you put together a last moment entry! Make sure to stop by the DC Maker Village as well! ' 1. #LVCCW_Level2_West

IOT Village Tour

unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium · unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium

'Title: IOT Village Tour Tags: The Diana Initiative | Creator Tour When: Friday, Aug 7, 10:10 - 10:20 PDT Where: L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium Description: Interested in visiting IOT Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to IOT Village and be introduced to the community and activities inside! '

Quantum Village Tour

unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium · unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium

'Title: Quantum Village Tour Tags: The Diana Initiative | Creator Tour When: Friday, Aug 7, 10:20 - 10:30 PDT Where: L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium Description: Interested in visiting Quantum Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Quantum Village and be introduced to the community and activities inside! '

Quantum-Ready or Not: What 1,000 Codebases Reveal About Cryptographic Risk

Crypto & Privacy Village - LVCCW Level 1 Hall 3 1103 (Creator Stage 5) · Crypto & Privacy Village - LVCCW Level 1 Hall 3 1103 (Creator Stage 5)

'Title: Quantum-Ready or Not: What 1,000 Codebases Reveal About Cryptographic Risk Tags: Crypto & Privacy Village | Creator Talk/Panel When: Friday, Aug 7, 10:30 - 10:59 PDT Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - [1]Map Description: Many people are aware of the quantum threat to cryptography, but how extensive is this issue? We analyzed 1,000* high-profile open-source repositories, including OpenVPN, Curl, and Bitcoin, and found that cryptographic risk is pervasive and hidden. 94% of repositories contain at least one cryptographic issue that would become exploitable in a post-quantum setting*, while 92% contain an issue that is already considered insecure by today’s standards*. The median repository contains 185 quantum-relevant weaknesses of moderate severity or higher, nearly double the classical median of 95*, indicating that there is substantial and underrecognized quantum exposure. Notably, thousands of findings are what we call “PQ-invisible;” they appear secure under classical assumptions but would become vulnerable with sufficiently powerful quantum capabilities*, revealing a critical blind spot in current security practices. These results highlight a gap between real-world cryptography and post-quantum readiness at a time when NIST migration timelines are approaching and Q-Day remains unpredictable. Unlike prior talks that focus on surface-level generalities, this talk is grounded in empirical analysis of source code across a large corpus of highly-used repositories. We will give a brief overview of the quantum threat, such as current estimates of quantum progress, NIST standardization, and attacks such as Harvest Now, Decrypt Later (HNDL) and Trust Now, Forge Later (TNFL). We will then present our methodology and results, including detailed breakdowns of cryptographic types, algorithms, and security postures across public-key cryptography, symmetric encryption, hashing, password hashing, TLS, and MACs. Whether you’re new to the quantum threat to cryptography or all-too-familiar with it, we hope to provide a clearer understanding of the current state of cryptography and the post-quantum migration. *Statistics based on an initial sample of 100 repositories; results will be updated as the dataset scales to 1,000. SpeakerBio: Dr. Zulfikar Ramzan Dr. Zulfikar Ramzan is Chief Technology and AI Officer at Point Wild, a global leader in AI-powered cybersecurity. He spearheaded the development and launch of Lat61, a highly scalable, extensible AI platform that consolidates data from multiple sources to detect multi-vector attacks, optimize protection across 50+ products and support over 25 million active users. He also leads the Lat61 Threat Intelligence Team, directing research into emerging threats and strengthening Point Wild’s Lat61 platform. Dr. Ramzan has over 20 years of experience in cybersecurity. At Aura, he served as Chief Scientist and Board member, leading the development of AI-driven platforms such as Aura Call Protection, Aura Message Protection, Smart Vault, and the Apollo platform for AI workloads. He has also held senior leadership roles at RSA as Chief Technology Officer and Chief Digital Officer. Earlier in his career, he contributed to Symantec Endpoint Protection and advanced machine learning–powered technologies at Immunet, now part of Cisco. He holds a PhD from MIT and is an inventor on more than 60 patents in cybersecurity and applied cryptography. ' 1. #LVCCW_Level1_Hall3

DEF CON Badge Talk

DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1) · DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1)

'Title: DEF CON Badge Talk Tags: DEF CON Official Talk When: Friday, Aug 7, 10:30 - 10:59 PDT Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - [1]Map Description: ' 1. #LVCCW_Level1_Hall3

Breaking Local AI Runtimes: Exploiting llama.cpp and Ollama

DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) · DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2)

'Title: Breaking Local AI Runtimes: Exploiting llama.cpp and Ollama Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲 When: Friday, Aug 7, 10:30 - 11:30 PDT Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) - [1]Map Description: Local LLM runtimes now sit inside phones, desktops, and internal servers, but the layer underneath is still ordinary native code. We analyzed llama.cpp and Ollama across three trust boundaries: JNI, HTTP lifecycle code, and Go/C bindings. First, in the llama.cpp Android integration, Java can free a native llama_context while native code is still using it. We reclaim the freed 648-byte object, redirect a vtable call, and show code execution in the embedding app. Second, in llama.cpp server, idle model teardown can race active requests, leaving a dangling pointer inside a freed 17,816-byte model allocation. We show remote cross-thread reclaim and attacker-controlled native dereference, then explain the remaining steps to stable RCE. Third, in Ollama, malicious GGUF metadata can push unsafe lengths across the Go/C boundary during quantization, causing C to read past a Go-backed buffer and return heap data to the caller. This is not a prompt-injection talk. It is about exploiting local AI runtimes as native software: one full exploit, one validated server-side primitive, one disclosure primitive, and the audit patterns that find more. 1. Mergendahl, Louloudis, Vidas. "Cross-Language Attacks." NDSS Symposium 2022. 2. Hussain. "Incubated Machine Learning Exploits." DEF CON 32, 2024. 3. Riancho, Braverman, Demetrio. "Breaking Out of The AI Cage." Black Hat USA 2025. 4. llama.cpp project: https://github.com/ggml-org/llama.cpp 5. Ollama project: https://github.com/ollama/ollama 6. llama.cpp Android sample: https://github.com/ggml-org/llama.cpp/tree/master/examples/llama.android Speakers:Ofek Itach,Vladimir "G1ND1L4" Tokarev SpeakerBio: Ofek Itach, Cyera Security Research Team Lead at Cyera. Focus areas include cloud infrastructure and AI-related platform security. Talks: Black Hat USA 2024, DEF CON 32 (2024), RSA 2024, Sector 2024, INTENT 2024, Black Hat Europe 2024 Arsenal. Earlier work includes AWS internals and cloud attack surface mapping. SpeakerBio: Vladimir "G1ND1L4" Tokarev, Cyera Vladimir Tokarev is a vulnerability researcher tech lead at Cyera, specializing in Cloud, IoT/OT, Windows, Linux, and AI vulnerability research and exploit. Talks: Black Hat USA 2024 and 2023, DEF CON 33 Recon Village 2025, CodeBlue 2025, RSA 2024. ' 1. #LVCCW_Level1_Hall3

Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking)

DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) · DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4)

'Title: Reflections on Disregarding Trust (Weaponizing CDP and MHTML for Header-Agnostic Session Hijacking) Tags: DEF CON Official Talk | Demo 💻 | Tool � | Exploit 🪲 When: Friday, Aug 7, 10:30 - 11:30 PDT Where: LVCCW Level 1 Hall 3 904 (Main Track 4) - [1]Map Description: Adversary-in-the-Middle (AitM) phishing has become the de facto standard for bypassing legacy Multi-Factor Authentication (MFA). However, modern AitM frameworks rely on complex, fragile regex rules to rewrite HTTP streams on the fly. When target applications implement strict client-side security headers like Subresource Integrity (SRI) and Content Security Policy (CSP), traditional proxies break, alerting defenders. This presentation introduces a novel "Browser-in-the-Middle" architecture. By weaponizing the Chrome DevTools Protocol (CDP), this custom-built Go toolkit renders the target application server-side, allows legitimate scripts to execute, and captures the resulting DOM as an MHTML snapshot. I will demonstrate how converting external assets into Base64 Data URIs and serving a self-contained, live DOM neutralizes SRI and CSP organically without triggering browser security violations. Finally, the talk will detail a Just-In-Time (JIT) JavaScript shim that hooks API calls to silently harvest post-MFA tokens from major IdPs including Okta, Microsoft, Google, and Shibboleth effectively trapping the user in a perfectly mirrored, attacker-controlled environment. SpeakerBio: Gregory "1umberhack" Disney-Leugers, Independent Researcher Gregory Disney-Leugers (1umberhack) is a Independent Researcher specializing in adversary simulation, modern web authentication bypasses, and identity-based attacks. With over a decade of experience in red teaming and penetration testing since 2013, they have previously served as a Technical Lead at major technology and identity providers, including Juniper Networks and Okta. ' 1. #LVCCW_Level1_Hall3

AppSec Village Tour

unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium · unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium

'Title: AppSec Village Tour Tags: The Diana Initiative | Creator Tour When: Friday, Aug 7, 10:30 - 10:40 PDT Where: L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium Description: Interested in visiting AppSec Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to AppSec Village and be introduced to the community and activities inside! '

Robot Hacking Community Tour

unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium · unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium

'Title: Robot Hacking Community Tour Tags: The Diana Initiative | Creator Tour When: Friday, Aug 7, 10:40 - 10:50 PDT Where: L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium Description: Interested in visiting Robot Hacking Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Robot Hacking Community and be introduced to the community and activities inside! '

Sick Signals: Adversarial Prompt Injection via Medical IoT Telemetry

IoT Village - LVCCW Level 1 Hall 3 1105 (Creator Stage 3) · IoT Village - LVCCW Level 1 Hall 3 1105 (Creator Stage 3)

'Title: Sick Signals: Adversarial Prompt Injection via Medical IoT Telemetry Tags: IoT Village | Creator Talk/Panel When: Friday, Aug 7, 10:45 - 11:30 PDT Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - [1]Map Description: Medical IoT devices such as continuous glucose monitors, ECG patches, remote patient monitoring hubs that increasingly feed LLM-powered clinical decision systems. Their telemetry streams are implicitly trusted as ground truth. This talk introduces a novel attack class: adversarial prompt injection delivered through crafted medical IoT sensor payloads. By encoding malicious instructions inside what appears to be routine device data, an attacker can manipulate the downstream LLM pipeline, suppressing critical clinical alerts, fabricating findings in physician summaries, or triggering unauthorized actions in AI systems with actuation capabilities. We present the threat model and a taxonomy of seven injection vectors spanning the full stack: analog spoofing, FHIR/HL7 free-text field poisoning, MQTT broker injection, calibration event hijacking, alarm message hijacking, time-series fragmentation, and multi-device coordinated injection. Unlike attacks targeting text interfaces, this class exploits the implicit trust placed in sensor telemetry — payloads hide inside ordinary device data, bypassing numeric validators and arriving in the LLM context as trusted clinical input. We discuss early experimental findings on the feasibility of this attack class, along with detection strategies and open questions for defenders. Attendees will leave with a concrete threat model, an expanded vocabulary for this new attack surface, and a new way to think about trust boundaries in AI-augmented medical systems. Speakers:Vinitha Mathiyazhagan,Tamil Mathi T. SpeakerBio: Vinitha Mathiyazhagan No BIO available SpeakerBio: Tamil Mathi T. No BIO available ' 1. #LVCCW_Level1_Hall3

The Future of Payments: AI, Agentic Commerce and the Next Wave of Innovation

Payment Village - LVCCW Level 1 Hall 3 1104 (Creator Stage 4) · Payment Village - LVCCW Level 1 Hall 3 1104 (Creator Stage 4)

'Title: The Future of Payments: AI, Agentic Commerce and the Next Wave of Innovation Tags: Payment Village | Creator Talk/Panel When: Friday, Aug 7, 10:45 - 11:30 PDT Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - [1]Map Description: The payments industry is entering a new era of transformation, where AI reshapes the way consumers and businesses buy, pay, and determine risk throughout the payment journey. Join leaders from across the payments ecosystem as they explore the technologies, opportunities, and challenges shaping the future of this space. This panel will examine how financial institutions, payment providers, merchants, and technology companies are preparing for a world where AI augments decision-making, automates operations, and increasingly acts on behalf of users to deliver more seamless, secure, and intelligent payment experiences. Attendees will gain actionable insights into the technologies and market forces redefining payments. Panelists will share their perspectives on the emerging innovations, strategic priorities, and industry shifts that will shape the next generation of payment experiences. They will offer practical guidance on how organizations can prepare for an increasingly intelligent, automated, and interconnected payments ecosystem. Speakers:Daniel Cuthbert,Leigh-Anne Galloway,Jorge Braniff,Sanjeev Sharma SpeakerBio: Daniel Cuthbert, Global Head of Cyber Security Research, Banco Santander Daniel Cuthbert is the Global Head of Cyber Security Research at Santander, where he leads global security research and drives innovation in cyber defence across the organisation. He serves on the Black Hat Review Board and is a founding member of OWASP, having co-authored both the OWASP Testing Guide and the OWASP Application Security Verification Standard (ASVS). With more than 20 years of experience in offensive security, application security, and threat research, Daniel is a frequent speaker and trusted advisor on emerging cyber threats, secure engineering, and security strategy. SpeakerBio: Leigh-Anne Galloway, Founder, Payment Village Leigh-Anne Galloway is a security researcher and testing specialist focusing on payment security, application security, fraud, and adversarial testing. Leigh-Anne is the founder of The Payment Village, a non-profit initiative dedicated to educating people on the intricacies of payment systems, fostering the next generation of payment security professionals, and creating space for critical discussion within the industry. She has presented and authored research on ATM security, mPOS vulnerabilities, NFC payments, fraud, and application security. SpeakerBio: Jorge Braniff, VP of Fraud and Product Operations at Incode Technologies Jorge Braniff is VP of Fraud and Product Operations at Incode Technologies, where he leads a global organization spanning fraud detection, document intelligence, red team, data collection, labeling and identity verification. His work sits at the center of the agentic fraud arms race: partnering with ML on the development of models for supporting all ID templates, deepfake detection, presentation attacks, document tamper, alteration, liveness and AI detection. Jorge has led fraud ring detection initiatives using graph-based identity linkage to uncover coordinated attack networks and has run high-stakes technical evaluations against fraud rings targeting neobanks and payment platforms. He has also hardened SDKs against injection and deepfake-based attacks for major financial institutions and fintechs and developed model governance and evaluation frameworks used to benchmark fraud detection performance in production. He brings a builder’s perspective to the fight against AI-driven fraud, having scaled operations and detection systems across multiple countries. He is based in the San Francisco Bay Area. SpeakerBio: Sanjeev Sharma, Director, Payments Product, GoFundMe Sanjeev has been building payment products since 2013, beginning his career at Visa as pa

InQuorigible: Quora in Missing Persons OSINT

Recon Village - LVCCW Level 1 Hall 3 801 (Creator Stage 2) · Recon Village - LVCCW Level 1 Hall 3 801 (Creator Stage 2)

'Title: InQuorigible: Quora in Missing Persons OSINT Tags: Recon Village | Creator Talk/Panel When: Friday, Aug 7, 10:45 - 11:30 PDT Where: LVCCW Level 1 Hall 3 801 (Creator Stage 2) - [1]Map Description: We all know Quora - or do we? Like Internet herpes, if you're a Google user, it'll follow you, forever, haunting your inbox with clickbait if you Google while logged into your account. ...But do we REALLY know Quora? Because despite being a pustule on the Internet that exists for the sole purpose of spamming SERPs, you'll be shocked to learn that it's also got - spoiler alert!!! - a dark, seedy underbelly. One that I uncovered while volunteering on an MP investigation. One that can yield surprising, disturbing and useful intelligence. In this talk, I'll explain: 1. The traces Quora leaves behind when something is "limited," "deleted" or a user is "banned." Because on Quora, 'deleted' just nulls the post body while the API keeps serving the slug and author, and 'limited' barely hides anything at all. On Quora, Limited is UNLIMITED, just like Olive Garden's breadsticks! Except unlike Olive Garden breadsticks, Quora's "limited" option is a fig leaf, and "deleted" content isn't much better: The API doesn't hide it. It coughs up the slug and author fully visible to other accounts and even logged-out strangers. 2. How to use Quora's API hairball to see what a user posted and build a network graph 3. What the disturbing subcultures on Quora mean for OSINT 4. Limitations of approach and ideas for automating OSINT Trigger warnings: This talk may include mention of disturbing topics, though all information will be anonymized / sanitized and no graphic content shared. SpeakerBio: Miranda Tedholm, Hunting the Golden Fleece in the JSONs of the world. Extremely employable. Who is Miranda? A reformed academic, a freelance writer sidelined thanks to a tech that can be described as "autocomplete on steroids," and a recent computer science grad, Miranda has been online since the CompuServe days. Yet she was [redacted] years old before she realized that "being really good at finding people online" was a whole subculture, career, and acronym. Despite never having played Pokemon, she collects degrees and credentials like she's gotta catch 'em all. Two bachelor's degrees, a master's, most of a PhD, and probably able to do the Heimlich maneuver (no promises though). But she yearns only for a job. ' 1. #LVCCW_Level1_Hall3

Physical Securty Village Tour

unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium · unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium

'Title: Physical Securty Village Tour Tags: The Diana Initiative | Creator Tour When: Friday, Aug 7, 10:50 - 10:59 PDT Where: L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium Description: Interested in visiting Physical Securty Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Physical Securty Village and be introduced to the community and activities inside! '

AI finds and writes my Android exploits now

Mobile Hacking Community - LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community) · Mobile Hacking Community - LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community)

'Title: AI finds and writes my Android exploits now Tags: Mobile Hacking Community | Creator Event/Activity When: Friday, Aug 7, 11:00 - 11:59 PDT Where: LVCCW Level 1 Hall 4-1422 (Mobile Hacking Community) - [1]Map Description: For years, Ken has found and written exploits for Android which ended up winning multiple Pwn2Own competitions. This year, he hasn't found or written a single exploit. Instead, AI does everything now, from reconnaissance to exploitation to writing bug bounty reports. This is thanks to the AI mobile testing tool, Djini, and the new feature that Ken helped program, called "Deep Scan". Thanks to "Deep Scan", Pwn2Own-level exploits can now be found autonomously. Ken will demonstrate the "Deep Scan" feature on stage, and talk about some of the various exploits that were found thanks to this feature. SpeakerBio: Ken Gannon / 伊藤 剣, Mobile Hacking Lab No BIO available ' 1. #LVCCW_Level1_Hall4

Morbidity and Mortality: Hackers, HIPAA, and a new Prescription for Healthcare Cyber Policy

Policy @ DEF CON - LVCCW Level 2 W210-211 (Policy Village) · Policy @ DEF CON - LVCCW Level 2 W210-211 (Policy Village)

'Title: Morbidity and Mortality: Hackers, HIPAA, and a new Prescription for Healthcare Cyber Policy Tags: Policy @ DEF CON | Creator Talk/Panel When: Friday, Aug 7, 11:00 - 11:59 PDT Where: LVCCW Level 2 W210-211 (Policy Village) - [1]Map Description: US healthcare cybersecurity policy has flatlined. An eruption of targeted ransomware is only the latest epidemic plaguing a beleagured sector facing workforce shortages, grappling with legacy medical devices and dependent on a complex web of vulnerable third party vendors. As patients suffer, doctors and nurses struggle, and hospitals bleed money they don’t have, critical public health stakeholders and institutions are failing to meet the moment. How did we get here? Join quaddi & r3plicant, two physician hackers and amateur wonks as they take you through a cyber policy autopsy - diagnosing the decisions and dilemmas that have resulted in this current crisis. From a diseased culture of secrecy predicated on a willful misunderstanding of privacy regulation to outdated national response and recovery frameworks, this talk will explore how policy choices made at the dawn of medicine’s digitization have aged poorly in an era of health system consolidation, single point of failure dependencies, and a rabid push to integrate AI into everything from thermometers to transplant surgery. The prognosis isn’t all dire. From a revitalized HIPAA to bipartisan bills to resuscitate rural hospitals, a policy prescription exists to better protect patients and secure systems. It’s time to take your medicine. Speakers:Christian Dameff,Jeff Tully (r3plicant) SpeakerBio: Christian Dameff, UC San Diego Center for Healthcare Cybersecurity Christian (quaddi) Dameff, MD is an ER doc and Associate Professor of Emergency Medicine, Biomedical Informatics, and Computer Science (Affiliate) at the University of California San Diego, where he also co-directs the Center for Healthcare Cybersecurity. He is a hacker, former open capture the flag champion, and prior DEF CON/RSA/Blackhat/HIMSS Speaker. He previously has testified in front of the U.S. Congress and U.S. Food and Drug Administration. SpeakerBio: Jeff Tully (r3plicant) No BIO available ' 1. #LVCCW_Level2_West

Book Signing - Nicholas DeMeo

Social Gatherings/Events - LVCCW Level 1 Hall 4-1300 (Book Signings)-Table 1 · Social Gatherings/Events - LVCCW Level 1 Hall 4-1300 (Book Signings)-Table 1

'Title: Book Signing - Nicholas DeMeo Tags: Vendor Book Signing When: Friday, Aug 7, 11:00 - 11:59 PDT Where: LVCCW Level 1 Hall 4-1300 (Book Signings)-Table 1 - [1]Map Description: SpeakerBio: Nicholas DeMeo Author: Cyber Defense: The Art of Forging a Sentinel ' 1. #LVCCW_Level1_Hall4

Book Signing - Christopher DeCarmen

Social Gatherings/Events - LVCCW Level 1 Hall 4-1300 (Book Signings)-Table 2 · Social Gatherings/Events - LVCCW Level 1 Hall 4-1300 (Book Signings)-Table 2

'Title: Book Signing - Christopher DeCarmen Tags: Vendor Book Signing When: Friday, Aug 7, 11:00 - 11:59 PDT Where: LVCCW Level 1 Hall 4-1300 (Book Signings)-Table 2 - [1]Map Description: SpeakerBio: Christopher DeCarmen Author: The Cyber Calendar 2027, Y2K27 Edition ' 1. #LVCCW_Level1_Hall4

Ham Radio Village Tour

unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium · unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium

'Title: Ham Radio Village Tour Tags: The Diana Initiative | Creator Tour When: Friday, Aug 7, 11:00 - 11:10 PDT Where: L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium Description: Interested in visiting Ham Radio Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Ham Radio Village and be introduced to the community and activities inside! '

The Ripple Effect: Inside Cloud-Scale Vulnerabilities in the Age of AI

Bug Bounty Village - LVCCW Level 1 Hall 3 1102 (Creator Stage 6) · Bug Bounty Village - LVCCW Level 1 Hall 3 1102 (Creator Stage 6)

'Title: The Ripple Effect: Inside Cloud-Scale Vulnerabilities in the Age of AI Tags: Bug Bounty Village | Creator Talk/Panel When: Friday, Aug 7, 11:00 - 11:30 PDT Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - [1]Map Description: Security researchers never see the true impact of their work. You submit a vulnerability report, it disappears into a queue, and eventually get a "resolved." But what actually happened on the other side? This talk changes that. Through a real-world case study, you'll see what happens when a single vulnerability report hits a cloud provider at scale and keeps going. What makes cloud vulnerabilities fundamentally different from traditional targets? How do you prioritize remediation when the blast radius spans services, regions, and third-party dependencies you didn't know existed? You'll see the crucial trade-offs no one talks about publicly, and a series of challenges that textbook CVD (coordinated vulnerability disclosure) was never designed to handle. And that challenge is accelerating. AI vulnerability discovery tools are uncovering valid vulnerabilities faster than traditional VDP (Vulnerability Disclosure Program) models were architected to process. The model that worked five years ago is buckling, and its impact is felt across organizations worldwide. Researchers wait longer. Defenders fall behind. The gap between discovery and remediation is widening, and attackers live in that gap. This talk introduces the 3 Principles for modern VDPs, which were forged from operating vulnerability disclosure at the world's largest cloud infrastructure. These apply whether you're running a program or reporting to one. Security researchers researchers will learn what actually happens after you hit submit, and how to write reports that accelerate everything downstream. Defenders will learn how to scale their programs for the velocity that's already here. Speakers:Albin Vattakattu,Ryan Nolette SpeakerBio: Albin Vattakattu Albin leads the global Vulnerability Disclosure Program (VDP) for Amazon Web Services (AWS). Albin's work has been featured by HackerOne, the SANS Institute, the AWS Security Blog, and at multiple international conferences. Prior to AWS, Albin led incident response teams across North and South America, defending foreign governments and fortune 100 companies against DDoS campaigns by APTs. SpeakerBio: Ryan Nolette Ryan is AWS's Senior Security Engineer and CoAuthor of AWS Detective. He has previously held a variety of roles including threat research, incident response consulting, and every level of security operations. With almost 2 decades in the infosec field, Ryan has been on the development and operations side of companies such as Postman, Sqrrl, Carbon Black, Crossbeam Systems, SecureWorks and Fidelity Investments. Ryan has been an active speaker and writer on threat hunting and endpoint security. ' 1. #LVCCW_Level1_Hall3

Cryptocurrency Opening Keynote

Cryptocurrency Village - LVCCW Level 1 Hall 3 1103 (Creator Stage 5) · Cryptocurrency Village - LVCCW Level 1 Hall 3 1103 (Creator Stage 5)

'Title: Cryptocurrency Opening Keynote Tags: Cryptocurrency Village | Creator Talk/Panel When: Friday, Aug 7, 11:00 - 11:59 PDT Where: LVCCW Level 1 Hall 3 1103 (Creator Stage 5) - [1]Map Description: Join your fellow hackers managing the Cryptocurrency areas at DEF CON, and get a sneak peak of what each workshop teaches as well as an overview of the showcases and programs happening in our DEF CON Village and Contest areas. We will report on cryptocurrency trends and perspectives from distinguished positions in industry, academy, and government. We will announce the teams competing in the Cryptocurrency Challenge, and give an overview of what prizes are available to winning contestants of the hackathon, CTF, and contests. Meet the organizers of years of cryptocurrency content at Defcon and bring your questions to the Creator Stage during the Cryptocurrency Opening Keynote! Speakers:Michael Schloh (MsvB),Param (P7R7M),Arjun Suresh (Peper) SpeakerBio: Michael Schloh (MsvB), Chairman, Monero Devices The Cryptocurrency Advocate is a group working to prepare society for the likely adoption of modern cryptocurrency in legacy financial systems. We host a number of events, including the Cryptocurrency Village and Cryptocurrency Challenge at DEFCON hacker conventions and other cybersecurity events around the world. SpeakerBio: Param (P7R7M) Param is an Electrical Engineering Student from Georgia Tech with a strong passion for and interest in crypto. Although he primarily got interested in cryptography and hardware security through a class at Georgia Tech, he is also working at a software company on crypto adoption and ease of use. With a unique blend of HW and SW skills, Param is truly enthusiastic about all aspects of crypto. SpeakerBio: Arjun Suresh (Peper), Postgraduate Student, University of Wollongong in Dubai Arjun Suresh is pursuing postgraduate studies in Cybersecurity at the University of Wollongong in Dubai, specializing in blockchain security, penetration testing, and applied cryptography. His interest in crypto security was shaped by analyzing major exchange breaches, including the Mt. Gox and Ronin Network hacks, where he studied the gap between attacker tradecraft and real-world defenses. ' 1. #LVCCW_Level1_Hall3

The 2025 Pwnie Awards

DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1) · DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1)

'Title: The 2025 Pwnie Awards Tags: DEF CON Official Talk When: Friday, Aug 7, 11:00 - 11:59 PDT Where: LVCCW Level 1 Hall 3 1006 (Main Track 1) - [1]Map Description: Ian Roos, Mark Trumpbour Speakers:Ian Roos,Mark Trumpbour SpeakerBio: Ian Roos No BIO available SpeakerBio: Mark Trumpbour No BIO available ' 1. #LVCCW_Level1_Hall3

Sliding into the Flight Deck’s DMs: Practical Message Attacks on CPDLC

DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) · DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5)

'Title: Sliding into the Flight Deck’s DMs: Practical Message Attacks on CPDLC Tags: DEF CON Official Talk | Exploit 🪲 When: Friday, Aug 7, 11:00 - 11:59 PDT Where: LVCCW Level 1 Hall 3 903 (Main Track 5) - [1]Map Description: Air traffic control quietly moved from voice radios to text messages—and almost nobody outside aviation noticed. We did. And it turns out you can slide into a commercial aircraft’s DMs. In this talk, we show how modern aircraft receive digital instructions (like “climb,” “descend,” or “turn”) over a system called CPDLC—and how that system has basically zero real security. No crypto. No authentication. Just vibes and protocol complexity. We built a full fake ground station using cheap SDR gear and made certified avionics believe we were air traffic control. From there, we can inject real flight instructions or knock aircraft offline at scale with protocol-level DoS attacks—no jamming required. This isn’t a simulation. We tested it against real aviation hardware in a live CPDLC environment. If you’ve ever wondered what happens when safety-critical infrastructure assumes “nobody will try this,” this talk is for you. Sliding into the Flight Deck's DMs: Practical Message Attacks on CPDLC Mehdi Ziazi, ETH Zurich; Khalid Aleem, Independent; Harshad Sathaye, ETH Zurich; Martin Strohmeier, Cyber-Defence Campus, armasuisse Science + Technology Usenix Security 2026 Speakers:Martin "MasorX" Strohmeier,Mehdi Ziazi SpeakerBio: Martin "MasorX" Strohmeier, Cyber-Defence Campus, armasuisse Science + Technology Martin is a Senior Scientist at the Swiss Cyber Defence Campus, primarily based at ETH Zurich, and a Visiting Fellow of Kellogg College, Oxford. His work focuses on designing and analyzing security protocols for cyber-physical systems in critical infrastructures—aviation, satellites, space, and transportation systems. Martin also explore privacy issues in global networks, adversarial machine learning, and open-source intelligence. Martin received his DPhil in 2016 at Oxford, supervised by Prof. Ivan Martinovic, where he studied the security and privacy of aviation communication technologies. I co-founded the OpenSky Network and coordinate its research activities. His work has received awards from both the aviation and security communities, including the EPSRC Doctoral Prize Fellowship and commendation from the British Computer Society. Martin has published regularly at all major security and AI conferences and also been a speaker at DEF CON several times (main stage + villages). SpeakerBio: Mehdi Ziazi, ETH Zurich Mehdi Ziazi is a hacker and cybersecurity student at ETH Zurich and an incoming PhD student at CISPA focused on aerospace security and cyber-physical systems. Their recent work in aviation security explores novel attack paths against aircraft systems and their real-world impact, approached with curiosity, persistence, and a bit of stubbornness. ' 1. #LVCCW_Level1_Hall3

Keychained Melody - Grabbing the Keys to the iCloud Kingdom

DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) · DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3)

'Title: Keychained Melody - Grabbing the Keys to the iCloud Kingdom Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲 When: Friday, Aug 7, 11:00 - 11:59 PDT Where: LVCCW Level 1 Hall 3 906 (Main Track 3) - [1]Map Description: The Apple Keychain has become a cornerstone of credential management for millions of users across the Apple ecosystem. In response, Apple has implemented robust protections for the iCloud Keychain — restricting synchronization exclusively to devices within Apple’s “Circle of Trust” and encrypting stored secrets with keys protected by the Secure Enclave. These layered defenses are designed to ensure that even physical acquisition of Keychain data from Apple’s servers yields nothing actionable. This talk introduces a novel vulnerability (CVE-2026-28860) that fundamentally undermines these protections. Leveraging a deep understanding of macOS internals, we demonstrate a technique capable of extracting all passwords stored within the Keychain — requiring neither root privileges, a user password, nor any prompts to the user. Beyond credential theft, we explore the broader attack surface this vulnerability exposes, presenting additional scenarios where data gleaned from the iCloud Keychain enables further, more severe compromise. Speakers:Alex Radocea,Jaron Bradley SpeakerBio: Alex Radocea Founder of Supernetworks and cofounder of Longterm Security. Alex started in security pentesting financial firms on Wall Street at Matasano and cofounded RPISEC at RPI. He has worked on Apple's Product Security team, engineering at CrowdStrike, and Spotify's Security team. His research — presented at Black Hat and REcon — spans mobile messenger cryptography, kernel security, binary static analysis, and browser hardening, including the discovery of critical flaws in Apple's iCloud Keychain. SpeakerBio: Jaron Bradley, Jamf Jaron is the Director of Jamf Threat Labs where he focuses on discovering new ways to keep user's safe on Apple devices. He is author of the books Threat Hunting macOS and OS X Incident Response. In his free time he manages themittenmac.com, a site dedicated to helping others learn security on the Apple ecosystem. ' 1. #LVCCW_Level1_Hall3

Damn Vulnerable Agentic AI Application (DVAIA)

Demo Labs - LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) · Demo Labs - LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1)

'Title: Damn Vulnerable Agentic AI Application (DVAIA) Tags: Beginner | AI | Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs When: Friday, Aug 7, 11:00 - 11:45 PDT Where: LVCCW Level 1 Hall 3 1001 (Demo Labs Track 1) - [1]Map Description: AI-powered Agentic applications now execute database queries, read files, send emails, and call APIs on behalf of users — all triggered through a chat window. DVAIA (Damn Vulnerable Agentic AI Application) is a new open-source platform purpose-built to let you break them. DVAIA pairs a production-grade secure platform with deliberately vulnerable AI-powered chat agents, each isolated in its own database and mapped to the OWASP Top 10 for LLM Applications 2025. In this demo we live-exploit nine exercise categories covering 93 attack objectives: * Prompt injection: extract system prompts, jailbreak filters, poison RAG documents, and hijack an email-summarization agent * SQL and NoSQL injection through AI: trick chat agents into constructing malicious queries — the injection never touches a traditional input field * Sensitive info disclosure: chain path traversal and SSRF through a banking agent's tool interface to read server secrets and probe internal services * Excessive agency and BOLA: make a customer-service agent access other users' data, create unauthorized orders, and issue fraudulent refunds * XSS and CSRF through LLM output: reflected, stored, and LLM-generated cross-site scripting fired from chat responses * Supply chain RCE: exploit a poisoned dependency through conversation with a code-analysis agent Speakers:Abhinav Verma,Mukesh Aggarwal SpeakerBio: Abhinav Verma Abhinav Verma is a Senior Staff Security Engineer at Intuit Inc. with 15+ years of experience across AI security, offensive security, red teaming, product security, and security operations. He currently leads AI security architecture reviews, AI penetration testing, and vulnerability management programs, with a focus on AI security, AI threat modeling, and securing large-scale cloud platforms. Over the course of his career at Intuit, he has built security automation, scaled continuous security scanning across thousands of assets, led secure design reviews for platforms serving millions of customers, and developed secure coding programs that have helped thousands of engineers shift security left. Abhinav was formerly an independent security researcher and has identified and reported vulnerabilities in numerous major online services and technology companies. He holds certifications including OSEP, OSCP, OSWP, GWAPT and CEH. Outside of work, Abhinav is a passionate gamer, a trained chef, an avid camper, and a mentor to aspiring offensive security practitioners. SpeakerBio: Mukesh Aggarwal Mukesh Aggarwal is a Distinguished Security Engineer who has spent his career thinking like a hacker. For nearly two decades he has hunted fraudsters and abuse across fintech platforms, building the detection pipelines, automations, and controls that shut bad actors down. He now lives at the bleeding edge of GenAI and agentic AI security, secure-by-default agent patterns, adversarial pen-testing and prompt-injection defense. He breaks things to understand them and stays a step ahead of attackers, usually spotting the weaknessess before they do. Mukesh has spoken at RSA Conference (OWASP GenAI Security Track), RenderATL, and the Intel Capital CISO Summit on AI safety, fraud, and offensive security, and is a member of the GIAC Advisory Board. Off the clock he is a die-hard offensive-security tinkerer who reverse-engineers hardware and apps, pokes at IoT security, writes autonomous bots, and automates his home. He also mentors the next wave of offensive and AI security practitioners. ' 1. #LVCCW_Level1_Hall3

sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions

Demo Labs - LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) · Demo Labs - LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)

'Title: sisakulint:CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions Tags: AI | Demo Labs | Intermediate | AppSec | Cloud | DevOps | Purple Team | DEF CON Demo Labs When: Friday, Aug 7, 11:00 - 11:45 PDT Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2) - [1]Map Description: GitHub Actions workflows are vulnerable by default. Hardening such as commit-hash pinning, least-privilege permissions, and timeouts is optional, never enforced at pipeline level. Exploitable configs ship daily, increasingly written by Coding Agents. sisakulint is a fast heuristic static analyzer for GitHub Actions covering all OWASP Top 10 CI/CD risks, with 52 rules, a taint engine, and 38+ auto-fixes. It outpaces CodeQL on speed and quality, with 100% detection on 18 GHSL advisories and 81.6% on 38 GHSAs covering exploits in PX4-Autopilot, vets-api, weaviate, nrwl/nx. Impostor Commit at CVSS 9.8 validates pinned SHAs against the claimed repository, not impostors via Git forks, a check unique to sisakulint. Code Injection at CVSS 9.8 tracks untrusted input through ${{ }} and step outputs. AI Action Rules detect Clinejection on claude-code-action, copilot-swe-agent, and openai-actions, covering tool grants, prompt injection, and wildcard triggers, as in Cline 2026/02 where issue title injection stole NPM_RELEASE_TOKEN. Known Vulnerable Actions catches tj-actions/changed-files. In the Coding Agent era, linters matter more. Delegating 52 rules to an LLM degrades precision; deterministic engines run in ms with no variance. The session covers end-to-end detection, taint propagation, and automated remediation. Speakers:Atsushi Sada,hikae SpeakerBio: Atsushi Sada Atsushi Sada is a CSIRT member specializing in cloud security on AWS and GitHub, and enterprise security with MDM, EDR, AI governance. He is an ethical hacker and security tool developer. He built sisakulint and MachStealer for practical security research in static/network analysis, Malware. He co-founded and organizes @sec_wakate, a community for junior security engineers in Japan. He has spoken at Black Hat USA/Asia Arsenal, AVTOKYO, and AWS Security JAWS. SpeakerBio: hikae Security Engineer in Red Team @ freee inc, AI Security Specialist. ' 1. #LVCCW_Level1_Hall3

Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device

Demo Labs - LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) · Demo Labs - LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)

'Title: Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake, Own the Device Tags: Beginner | Demo Labs | AppSec | Hardware/IoT | Mobile | Offense/Red Team | Wireless/RF | DEF CON Demo Labs When: Friday, Aug 7, 11:00 - 11:45 PDT Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - [1]Map Description: What happens when you buy a popular medical device and realize it blindly trusts any BLE connection within 30 meters? BRAT (BLE Recon and Attack Toolkit) is the open-source Python arsenal we built to systematically take over an FDA-listed consumer hormone analyzer and generalize the attack to the class of devices behind it. Relying on the Nordic UART Service (NUS), the target blindly trusts any connection within 30 meters. BRAT automates the exact attack chain we used to compromise it: passive BLE discovery, protocol reverse engineering, unauthenticated command injection, full bind takeover, and rogue peripheral impersonation to hijack live API session tokens. Every script is built on the � bleak� async BLE library and deliberately kept small so you can read the code and understand the exploit in minutes. Our Demo Lab features live, end-to-end attacks against a consumer medical device. We���ll demonstrate unauthenticated command injection, rogue peripheral spoofing that intercepts companion app handshakes, and how we injected spoofed hormone sensor data without ever pairing. Speakers:Gigi Xiaoqing Liu,Muzzammil Mohammed,Narmina Karimova SpeakerBio: Gigi Xiaoqing Liu Gigi Liu is a graduate security researcher at Northeastern's Security And Privacy Research (SPQR) Group under Professor Kevin Fu, where her work covers embedded systems security, medical device attack surfaces, and AI-generated media detection. She interns at Lila Sciences as a Security and Cloud Engineer, building enterprise-wide agentic AI security infrastructure and detection capabilities for unauthorized AI activity across cloud and SaaS environments. Her technical work spans wireless protocol reverse engineering, binary exploitation, web and mobile reverse engineering, cloud and AI security. She has applied these skills across medical hardware, automotive platforms, and enterprise cloud environments — from BLE command injection on FDA-listed devices to CarPlay API exploitation to building agentic AI detection controls at scale. As a UCLA psychobiology alum with a consulting background, she brings a multidisciplinary lens to every system: understand what it's designed to do first, then find where it breaks. SpeakerBio: Muzzammil Mohammed Muzzammil Mohammed is an offensive security researcher, penetration tester at Maltek Solutions, and MS in Cybersecurity at Northeastern University. Operating out of the SPQR Lab under Professor Kevin Fu, and serving as a Teaching Assistant Network Security, his work bridges academic vulnerability research with real-world red team execution. As a core developer of WandKit an open-source BLE attack toolkit built to audit medical devices. Muzzammil led the cloud API exploitation phase, successfully confirming a complete authentication bypass and engineering the rogue peripheral session hijack chain. Beyond hardware and API hacking, he is actively developing autonomous multi-agent AI frameworks designed to orchestrate local LLMs for automated security auditing and vulnerability analysis. SpeakerBio: Narmina Karimova Narmina Karimova is a cybersecurity graduate researcher at Northeastern University with a background in enterprise technology across financial institutions and the United Nations. She came to security research from the infrastructure side, which shaped how she approached tearing apart a consumer fertility monitor. For BRAT, she wrote the core BLE attack suite in Python: replay modules, rogue peripheral session capture, unauthenticated hormone data extraction, and the bind takeover chain that captures device ownership in under 15 seconds. She also reverse-engineered the APK with JADX, found hardcoded credential

Zealot: An Autonomous Cloud Offensive Multi-Agent System

Demo Labs - LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) · Demo Labs - LVCCW Level 1 Hall 3 900 (Demo Labs Track 4)

'Title: Zealot: An Autonomous Cloud Offensive Multi-Agent System Tags: AI | Demo Labs | Intermediate | AppSec | Cloud | Defense/Blue Team | Offense/Red Team | Purple Team | SecOps | DEF CON Demo Labs When: Friday, Aug 7, 11:00 - 11:45 PDT Where: LVCCW Level 1 Hall 3 900 (Demo Labs Track 4) - [1]Map Description: In November 2025, Anthropic disclosed a state-sponsored operation where AI didn't assist human attackers — it was the attacker, executing 80-90% of the campaign autonomously. The question shifted from "could this happen?" to "how bad can it get?" We built Zealot to find out. Zealot is a multi-agent offensive framework that autonomously chains reconnaissance, exploitation, privilege escalation, and data exfiltration against cloud environments — with no human directing individual steps. A supervisor agent coordinates three specialists (Infrastructure, AppSec, and Cloud) that share attack state and hand off context as the operation progresses. The result: an AI system that thinks strategically and executes tactically, the way a real red team does. In live sandbox tests against GCP, Zealot autonomously discovered an exposed web service, identified and exploited an SSRF vulnerability, extracted service account credentials from the metadata service, impersonated a higher-privileged account, and exfiltrated BigQuery datasets — start to finish, without a human touching the keyboard after the objective was set. We'll walk through the architecture, show the full attack chain on video, and share the honest lessons: where AI operators excel (systematic enumeration, credential chaining, API fluency), where they fall short (a SpeakerBio: Chen Doytshman I'm a security researcher with a background in artificial intelligence and machine learning. I am passionate about using my skills to protect against cyber threats. With over 5 years of experience in the field, I have a strong understanding of both security and AI technologies and am skilled at combining the two to identify and mitigate vulnerabilities. ' 1. #LVCCW_Level1_Hall3

AOBTD: AI One Bites The DAST

Demo Labs - LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) · Demo Labs - LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)

'Title: AOBTD: AI One Bites The DAST Tags: Beginner | AI | Demo Labs | AppSec | Offense/Red Team | DEF CON Demo Labs When: Friday, Aug 7, 11:00 - 11:45 PDT Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track 5) - [1]Map Description: I hate the way most DAST tools test: firing payloads at parameters with no idea what the app is. They catch the obvious stuff, but miss the parts that actually need context. Newer LLM scanners are either commercial black boxes (iykyk) or "GPT, find bugs at this URL" wrappers that fall over outside a CTF box. AOBTD is my attempt at a third option: a scanner that behaves less like a fuzzer and more like a pentester at the start of a test. Instead of fuzzing harder, AOBTD first tries to understand the target. It explores the surface, identifies what pages and endpoints are for, takes notes, builds hypotheses, and then sends targeted requests based on that context. This target understanding drives the rest of the testing process, which is the only realistic way automated tooling can get closer to business-logic bugs. The crawler is designed to avoid wasting time on repeated templates while still sampling outliers, so the odd page hidden in a sea of similar ones does not get ignored. When findings are confirmed, AOBTD can chain them into multi-step attack stories rather than reporting isolated payload hits. This is where LLMs are actually useful: reading a page, understanding the purpose of a form, naming the function behind a JSON endpoint, and doing the kind of prioritization a pentester normally spends hours on. SpeakerBio: Ozgun "ozzy" Kultekin Ozgun (aka ozzy) is a Senior Application Security Engineer at Trendyol Group, where he spends his days breaking applications before the bad guys do. He holds the OSCE3 certification and specializes in offensive security research with a focus on application security and red team operations. He has presented at several conferences including DEF CON, Hacktivity, and multiple BSides events, covering topics ranging from red teaming to application security. He is currently focused on integrating AI into offensive security workflows and actively researching how large language models can be applied in practical, technical ways within cybersecurity. He regularly shares his work and tools as open source. When he's not hunting bugs or running red team ops, he's probably at the poker table. ' 1. #LVCCW_Level1_Hall3

AI Pipeline for N-days Weaponization

Demo Labs - LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) · Demo Labs - LVCCW Level 1 Hall 3 902 (Demo Labs Track 6)

'Title: AI Pipeline for N-days Weaponization Tags: AI | Demo Labs | Intermediate | Offense/Red Team | DEF CON Demo Labs When: Friday, Aug 7, 11:00 - 11:45 PDT Where: LVCCW Level 1 Hall 3 902 (Demo Labs Track 6) - [1]Map Description: Most agentic exploit pipelines stall when there's no public PoC,they search, find nothing, and spin. This talk demos a multi-agent system that exploits n-days from scratch in under an hour, even with zero public exploit code available. Given only a CVE ID, the pipeline autonomously: fetches vulnerability details and the upstream fix commit; spins up a pinned Docker lab running the exact vulnerable version; diffs the patch to identify the exploitable code path; generates vulnerability-class-specific attack guidance (not a generic checklist); and runs iterative exploit + validation loops until RCE is confirmed. Demonstrated live against four CVSS 9.8–10.0 vulnerabilities Apache OpenMeetings deserialization, n8n unauthenticated RCE, Langflow exec() injection, and Spring AI SpEL injection, with working exploits produced in minutes. Every run also outputs a containerized lab and defense report, making it equally useful for detection engineering and patch validation. Speakers:Andrea Brosio,Arun Nair SpeakerBio: Andrea Brosio Andrea Brosio is a Security Researcher and Senior Content Engineer, specializing in red teaming, malware development, and offensive security. With prior experience as a Bug Hunter and Red Team Operator he combines real-world adversarial expertise with a passion for creating engaging cybersecurity training. SpeakerBio: Arun Nair Arun Nair is a Security Engineer at Google and founder of Ryvane Academy, specializing in AI Security, malware development, defense evasion, and adversary simulation. He holds several respected certifications, including OSCP, CRTP, CRTL, CodeMachine Malware Techniques, and HackSys Windows Kernel Exploitation. Over the years, Arun has worked with leading organizations such as JP Morgan, and EY, focusing on offensive security and red teaming engagements. Outside of his professional work, he is an active contributor to the cybersecurity community, from designing Capture the Flag (CTF) challenges to delivering talks and workshops at events like DEFCON Red Team Village, HeapCon, MCTTP, BSides Transylvania, HackSpaceCon, RingZer0, c0c0n, and various local meetups. When he’s not on engagements or speaking at conferences, Arun shares his research and insights through his blog at dazzyddos.github.io ' 1. #LVCCW_Level1_Hall3

Tech Reclaimers Update: A Year In, Building a Social Movement Away from Big Tech

Hackers.town - LVCCW Level 1 Hall 3 1100 (Creator Stage 7) · Hackers.town - LVCCW Level 1 Hall 3 1100 (Creator Stage 7)

'Title: Tech Reclaimers Update: A Year In, Building a Social Movement Away from Big Tech Tags: Hackers.town | Creator Talk/Panel When: Friday, Aug 7, 11:00 - 11:30 PDT Where: LVCCW Level 1 Hall 3 1100 (Creator Stage 7) - [1]Map Description: It has been a year since we launched the Tech Reclaimers, a social movement to help people reclaim their lives and their systems from Big Tech. And how far we have come! The community has grown online, with a thousand followers and hundreds of active participants in group chats. In this talk, describe our activities over the past year and our plans for the future, as well as what we have learned about the challenges people face in disentangling from Big Tech. While the technical challenges can be complicated, there are considerable social challenges too. And while hackers may look for the purest and best alternative options, we have found variety in meeting people where they are at to help them assemble the alternative stack that suits their needs, budget, skills, and values. Finally, we do indeed have friends everywhere: from the Rebel Tech Alliance to the Luddite Club, we discuss the connections we are forging and the new paths we are innovating. Speakers:Andy Hull,Janet Vertesi,Rebecah Miller SpeakerBio: Andy Hull, Officer at Tech reclaimers No BIO available SpeakerBio: Janet Vertesi, Officer at Tech Reclaimers No BIO available SpeakerBio: Rebecah Miller, Officer at Tech Reclaimers No BIO available ' 1. #LVCCW_Level1_Hall3

Intro to Common Industrial Protocol Exploitation

ICS Village - LVCCW Level 1 Hall 3 801 (Creator Stage 1) · ICS Village - LVCCW Level 1 Hall 3 801 (Creator Stage 1)

'Title: Intro to Common Industrial Protocol Exploitation Tags: ICS Village | Creator Talk/Panel When: Friday, Aug 7, 11:00 - 11:59 PDT Where: LVCCW Level 1 Hall 3 801 (Creator Stage 1) - [1]Map Description: Intro into Common Industrial Protocol and how to get started finding exploits on CIP enabled devices. SpeakerBio: Trevor Flynn Industrial Control Engineer / ICSVillage volunteer / Cyber Security Researcher ' 1. #LVCCW_Level1_Hall3

Build-A-Badge Workshop

Maker's Village - LVCCW Level 1 Hall 1-301 (Makers' Village) · Maker's Village - LVCCW Level 1 Hall 1-301 (Makers' Village)

'Title: Build-A-Badge Workshop Tags: Maker's Village | Creator Event/Activity When: Friday, Aug 7, 11:00 - 12:30 PDT Where: LVCCW Level 1 Hall 1-301 (Makers' Village) - [1]Map Description: Welcome to the Build-A-Badge Workshop! We've cultivated some interesting maker mediums to bring you a unique badge that's all about making it your own. This workshop is a unique experience for the veteran maker or someone new that may be interested in seeing how makers can come together and create something truly unique. A brief workshop introduction, led by project leader and designer Alchemist, will give you some background on the badge. After which, you'll be assigned a group number and split off into teams within the Makers' Village, hitting each station for the badge assembly. You'll get a chance to talk to our 3-D printer Buddha, our Laser Engraver Teazee, Silk Screener hunny, and Board Maker M-Nelly to show you all the ways you can make this Bear Badge your own. Every workshop attendee will also receive a SAO for their badges as well as stickers and links to a Badge Repository with prints files, patterns, and some extras to continue to work on this badge after the con. Speakers:hunny,Teazee,Buddha,MLP,M-Nelly,Alchemmer SpeakerBio: hunny No BIO available SpeakerBio: Teazee No BIO available SpeakerBio: Buddha No BIO available SpeakerBio: MLP No BIO available SpeakerBio: M-Nelly No BIO available SpeakerBio: Alchemmer No BIO available ' 1. #LVCCW_Level1_Hall1

Packet Hacking Village Tour

unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium · unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium

'Title: Packet Hacking Village Tour Tags: The Diana Initiative | Creator Tour When: Friday, Aug 7, 11:10 - 11:20 PDT Where: L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium Description: Interested in visiting Packet Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Packet Hacking Village and be introduced to the community and activities inside! '

Mobile Hacking Tour

unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium · unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium

'Title: Mobile Hacking Tour Tags: The Diana Initiative | Creator Tour When: Friday, Aug 7, 11:20 - 11:30 PDT Where: L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium Description: Interested in visiting Mobile Hacking but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Mobile Hacking and be introduced to the community and activities inside! '

Maritime Hacking Village Tour

unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium · unknown event type - L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium

'Title: Maritime Hacking Village Tour Tags: The Diana Initiative | Creator Tour When: Friday, Aug 7, 11:30 - 11:40 PDT Where: L1 (Floor 1)/LVCC W-L1-South Lobby / Atrium Description: Interested in visiting Maritime Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Maritime Hacking Village and be introduced to the community and activities inside! '

Haetae: An Agent to Takedown North Korean C2 Servers

Adversary Village - LVCCW Level 1 Hall 3 1105 (Creator Stage 3) · Adversary Village - LVCCW Level 1 Hall 3 1105 (Creator Stage 3)

'Title: Haetae: An Agent to Takedown North Korean C2 Servers Tags: Adversary Village | Creator Talk/Panel When: Friday, Aug 7, 11:30 - 11:59 PDT Where: LVCCW Level 1 Hall 3 1105 (Creator Stage 3) - [1]Map Description: In this talk, we introduce Haetae, an agent designed to profile, identify, and exploit C2 frameworks used by North Korean malware. Haetae supports both automated and interactive modes, allowing analysts to map and understand adversary infrastructure with different levels of control. It is built around a flexible rule-based system, enabling users to extend and refine detections as new patterns and frameworks emerge. In this first release, we will walk through real-world cases where Haetae was used to identify and take down infrastructure associated with Mach-O Man and POWerful Armadillo. We will also release a safe emulator of both malware C2 servers, allowing researchers and newcomers to experiment with Haetae in realistic, controlled environments without risk. This is a highly technical talk but can be enjoyed by both beginners and seasoned threat hunters. Speakers:Mauro Eldritch,Nelson Rafael Colón Merán SpeakerBio: Mauro Eldritch, Leader at Bitso Quetzal Team Hacker and Speaker. Founder of BCA LTD and DC5411. I wrote a book interviewing Threat Actors. I like Threat Intelligence and Golden Retrievers. SpeakerBio: Nelson Rafael Colón Merán, Security Engineer Security Engineer at Bitso, Latin America's leading crypto-first financial platform. I've specialized in red team operations, penetration testing, and malware development. Recognized speaker in the Dominican Republic's RedTeamRD cybersecurity community, where I've given a couple talks and previously assisted DEFCON as a speaker. ' 1. #LVCCW_Level1_Hall3

Human in the Loop or Human Out of Luck?

Biohacking Village - LVCCW Level 1 Hall 3 1104 (Creator Stage 4) · Biohacking Village - LVCCW Level 1 Hall 3 1104 (Creator Stage 4)

'Title: Human in the Loop or Human Out of Luck? Tags: Biohacking Village | Creator Talk/Panel When: Friday, Aug 7, 11:30 - 11:59 PDT Where: LVCCW Level 1 Hall 3 1104 (Creator Stage 4) - [1]Map Description: As agentic AI systems rapidly enter healthcare and precision medicine, a critical question remains largely unanswered: what happens when the patient is reduced to data alone? This talk explores a real-world experiment conducted through GENE240 at Stanford, where interdisciplinary student teams used agentic AI systems and multiomic datasets to investigate a complex patient case. Working across genomics, computational biology, and clinical reasoning, teams analyzed the same underlying data while arriving at dramatically different hypotheses, interpretations, and priorities. Unlike traditional case studies, the patient was actively involved throughout the process. While full medical records were intentionally withheld, selective contextual information and direct interaction with the patient significantly influenced the direction and interpretation of the work. The experience exposed both the extraordinary promise and the profound limitations of AI-driven healthcare systems. This session will examine: how agentic AI systems behave when operating on incomplete clinical context the variability introduced by tooling, prompting, and disciplinary bias the role of patient interaction in refining computational hypotheses why lived experience may be one of the most underutilized datasets in precision medicine Through the lens of rare disease and complex chronic illness, this talk challenges the assumption that more data alone leads to better outcomes. Instead, it argues that the future of AI-enabled healthcare depends on keeping patients actively embedded in the interpretive loop. For the biohacking community, this raises broader questions around autonomy, data ownership, participatory medicine, and how individuals may increasingly interface with AI systems to investigate their own health outside traditional clinical SpeakerBio: Christine Von Raesfeld Christine is a research advocate and community engagement leader focused on health, data, and emerging technologies. Living with multiple rare and chronic conditions, she advances participatory medicine and champions people with lived experience as essential partners in research and innovation. ' 1. #LVCCW_Level1_Hall3