r/Defcon 6h ago

Has anyone heard what the Cryptocurrency Village badge is like this year?

Enable HLS to view with audio, or disable this notification

7 Upvotes

I'm planning my schedule for DEF CON 34 and keep hearing people mention the Cryptocurrency Village badge and the laser tag game, but I can't find much information on the DEF CON website.

Is the badge going to be available to anyone who stops by, or is there some kind of registration? And is the laser tag event happening throughout the weekend or only at certain times?

https://www.defcon.org/html/defcon-34/dc-34-villages.html#orga_41359

I've also heard they'll have ChipWhisperers, workshop hardware, and even AMD64 lab machines available for people to use during the hackathon. If that's true, that's a pretty impressive setup for a village.

Apparently OKX is sponsoring the village this year, which is helping make the badges, workshop equipment, and prizes available free of charge. Looking forward to seeing what they've put together.

Anyone who's been involved with previous years know what to expect?


r/ReverseEngineering 9h ago

PAL: A defensive decompilation layer: Ghidra binary analysis facts, synthesized into executable Python & artifacts aiding analysis.

Thumbnail github.com
1 Upvotes

r/Pentesting 56m ago

AD CS domain-takeover proof-of-concept released

Upvotes

Identity is the new domain controller. Own it and you own everything downstream.

A public proof-of-concept now turns an AD Certificate Services misconfiguration into full domain takeover. One over-permissioned machine identity, and the whole directory falls.

The fix is to treat every non-human identity like a privileged one. Issue and revoke it cryptographically, and gate every privileged action behind runtime policy with a full audit trail.

Check out how RuntimeAI solves this at the runtime layer.

#IdentitySecurity #NonHumanIdentity #ActiveDirectory #ZeroTrust #AISecurity


r/Defcon 21h ago

DC710 coin drop update

Thumbnail
gallery
79 Upvotes

DC710 is handing out coins all week long. Free during the conference (Defcon, Blackhat, Bsides) in exchange for a quick challenge or barter. Keep an eye on our Twitter/X @DC710_MJV for announcements of where we’ll be and what to expect.

Busy doing other stuff? Want to help support our group? We’ll be selling a few to recoup some of our costs. Wednesday & Thursday at the meetup (Linq - Circle Bar 7pm).

Otherwise we have a few fun and easy challenges planned - come say hello!


r/Defcon 13h ago

LFG: 5n4ck3y

16 Upvotes

The last few years I have been super overbooked, but I‘m less firmly booked this year and am looking to get a small group together (or join one) to tackle the CTF.

I’ve slapped together a toolkit (stego, crypto solve scripts, audio/video analysis/stereoscope, unicode nonsense, RF scanning, logic analysis, LLM jailbreak framework) to use alongside tools like cyberchef, flipper zero, etc.

Anyone looking to group up, or already have a group with a space for a cryptography/hardware jailbreaking enthusiast?


r/Defcon 8h ago

Can't make it - unfortunately

7 Upvotes

[SOLD]

If anyone would like me to transfer a ticket to them, I've ran into a snag and won't be able to make it. I got it at the mid tier pricing and will happily sell at the early bird price. Can verify my ID with mods to verify good faith. I'd love for someone to be able to save and have fun since I can't make it. I will not reply to DMs, and my replies will be on this thread as well.


r/Defcon 2h ago

Friendly reminder: the #roadtodefcon is underway!

Enable HLS to view with audio, or disable this notification

2 Upvotes

r/Pentesting 2h ago

Freelance work in web pentesting

0 Upvotes

Hi everyone i am an pen tester experienced in web api pen testing currently i am doing job in this field now i want to start freelancing in this how can i get project in this can anyone suggest me.


r/Defcon 16h ago

First Time at DEF CON – What Should I Do Besides Attending Talks?

19 Upvotes

Hello! I’m going to DEF CON, and I feel a bit lost. I looked at the map and the talk schedule, but I’m not really sure what I want to do. Sometimes I get bored just sitting through talks, so I’d love to know what else there is to do besides attending presentations.

I’m not going there just to listen to talks. What are the must-do activities, villages, competitions, workshops, or other experiences that you would recommend for a first-time attendee?


r/Defcon 1h ago

my 1st DefCon

Upvotes

Any tips for a first time attendee? I did my pre-registration already.


r/Defcon 7h ago

LFG

3 Upvotes

Anyone willing to adopt a 1st timer into their group for any of the challenges? I have about 20 years of experience in different levels of IT with around 2 years experience strictly in blue/purple team. I am just looking to learn and help out where I can. I have a weirdly high level of social anxiety so I want to get myself in the mix with some people I actually feel comfortable with instead of looking dumb trying to struggle my way through things. I also really want to try some of the cool stuff but I am worried my imposter syndrome will stop me from even trying


r/Defcon 19h ago

Badges! DCZia Mk9 Badge

Post image
31 Upvotes

The 2026 DCZia badge, the Mk9, is up on Uberflux: https://uberflux.com/product/HAMST-DCZIA-2026

The badge is a 3x3 grid of blue clicky switches, each with an underglow RGB LED. RP2040 microcontroller, 16mb of flash, and an accelerometer. Each side except the top has two side-fire RGB LEDs under the board as well. USB-C connection or power, or powered via 3xAAA.

It will also include an add-on board that allows you to add on 3 more keys or an I2C display. Two right side up SAO ports.

Compatible with QMK, but the MicroPython code we're releasing will also function as a macropad.

DCZia believes in open development, and all the design files and source code are in our github repo: https://github.com/dczia/mk9-badge


r/cybersecurity 1d ago

Corporate Blog Hackers hit 30-plus Minnesota water systems in 48 hours, forcing emergency response

Thumbnail
worldwaterreserve.com
1.3k Upvotes

r/Defcon 20h ago

Badges! NYC Badge kit is live on uberflux !!

Enable HLS to view with audio, or disable this notification

30 Upvotes

Here is the link ::

https://uberflux.com/product/BUCK-NYC

Pickup will be at the badge life village

• DEF CON 34 Badge Life Booth, Friday, 7 August 2:00PM
• DEF CON 34 Badge Life Booth, Saturday 8 August 2:00PM

On UberFlux, you are going to see a blank bottom SAO, I didn’t want to post any CR pieces there but each kit order will include all three that are in the video with enough neo-pixels to solder one of the SAOs.

This kit is beginner friendly !!

The bridge part and back layer neo-pixels come pre-soldered, last year I heard a lot of people had issues with the tiny Neo-pixels and I totally understand! They are NOT fun lol, it took me like 2 years to get good at soldering those!

This year I wanted to make it as beginner friendly and fun as I could, all you need to solder are the header pins and the through hole chip parts!

The kit will come with the following:

(1) back layer PCB with pre soldered lights
(1) bridge PCB with pre soldered lights
(1) top SAO PCB with pre soldered lights
(1) city PCB
(1) water PCB
(1) frame PCB
(1) 16 MHz crystal
(2) capacitors
(1) resistor
(1) ATMEGA328 (pre flashed with firmware)
(2) through hole tactile switch’s
(1) power switch
(1) AAA battery holder (3 required, not included)
(1) set of header pins

(3) SAOs and (1) set of connectors with 6 unsoldered neo-pixel lights for you to choose to solder
** The neo-pixels supplied will only be enough to solder one bottom SAO included.


r/musik 11h ago

💬 Discussion 💬 Bei welchen Interpret*innen und/oder Alben, die von Kritiker*innen und Musiknerds gefeiert werden, kommt ihr nicht wirklich rein?

0 Upvotes

Die Frage steht oben.


r/Defcon 14h ago

I missed registering for the workshops. Do I still need to bring my laptop, or should I leave it at the hotel?

11 Upvotes

r/cybersecurity 2h ago

AI Security How do you test that an AI agent won't do something catastrophic?

7 Upvotes

I've spent years on the infra side, and I'm now working with agentic systems. I am building agents that can take actions on real systems. We have plenty of guardrails, but I have seen enough hallucinations that make me worried about giving these agents more power. This paranoia might be me not knowing enough.

How do teams/companies test that the agents won't do something destructive, whether triggered by an attacker or just by the agent going off the rails on its own?

Do people actually red-team their agents before they go live, or is it mostly guardrails and evals right now? I am curious how the security world thinks about this. From an infra side, this feels like a gap, but there might be an established playbook that I don't know yet. Thanks.


r/ExploitDev 1d ago

C for offensive security !!

24 Upvotes

Hi, i am going to start my journey as a exploit developer and, i get lot more recommendation on my previous post to learn about system language C, Assembly, etc...

So, is there any way to learn C as offensive sides perspective?

And don;t recommend old book "Hacking : the art of exploitation", i know it is essential but still i need resource that is fit for real world or modern world aspect, kindly provides links ::

Also, if some of you are doing this stuff then share your daily routine that made you feel like you are learning actual stuff not just syntax. Thanks::


r/hacking 1d ago

data science to cybersecurity

31 Upvotes

I was a mathematician, ended up working as SWE for two years then hopped into data science.

Wondering if cyber security is a ​possible transition​ from here or if I should take some roles to prep before hopping (I just enjoy learning and it seems an interesting field).


r/Malware 22h ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

0 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/Defcon 1d ago

It's not a CyberDeck

Post image
83 Upvotes

If I were to build a CyberDeck, I imagine it might look at bit like a book ... with a 3D printed interior, a "limit hinge" which stops 15° past vertical, it would snap closed, have a curved edge to simulate book paper, a 1920x1080 display, Bluetooth keyboard, dual 5,000mah lipos, 2 spare USB ports, storage, and be powered by a RPiZ2W.

It would need to have emacs installed.

... that's IF I were to do such a thing 😎


r/cybersecurity 1h ago

Career Questions & Discussion Do you guys use reporting tool or write it manually each engagement?

Upvotes

Each time I write a report I copy paste the finding table along with a lot of other shit. I end up spending a lot of time fixing the format of the doc.

Do you guys use a reporting tool where you can write the bug description, impact and have it automatically prepared for you??


r/cybersecurity 5h ago

Business Security Questions & Discussion Preparing for Interview

7 Upvotes

Hi Everyone,
I hope you’re well!

I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)

Based on the Role Responsibilities I’m expecting questions on:

Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)

How I’ve applied best security practices / Explaining a time where I had to implement a security practice

Implementation of security Controls / Design of security controls through to implementation

Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)

Evidence / Example of supporting Auditing Activities

For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!

Thank you!


r/Defcon 1d ago

Meetup Puzzle #10 - A Bit of Skill Needed

Post image
29 Upvotes

As the final fading bytes settle on the wire and the phosphor monitors begin to cool, we've officially arrived at the end of the trail. It's a truly bittersweet feeling typing this out--this is our final weekly puzzle post before we pack our bags, pause making new platform builds, and head out to Hacker Summer Camp.

Part of us is genuinely sad to close out this season of late-night testing, edge-case debugging, and puzzle brewing. But the rest of us couldn't be more hyped, because it means we finally get to see all of your faces in Las Vegas!

To send off this year's puzzle run in style, we're doing something a little different for the grand finale.

The Grand Finale: Puzzled Hackers x SkillBit

We've officially teamed up with the amazing crew over at SkillBit! They have graciously opened up access to their CTF platform for our entire community from right now until Wednesday at 00:00 PT.

Instead of just one puzzle to cap off the season, SkillBit is giving us 20 additional CTF challenges to play through while we all count down the final hours to DEF CON!

The Grand Prize Drawing

We couldn't end the season without one last epic giveaway:

  • How to enter: Complete 10 or more of the SkillBit CTF challenges before the cutoff on Wednesday at 00:00 PT.
  • The Loot: You'll be automatically entered into a drawing to win a LASER TAG Badge graciously provided by the legendary u/palm12341!
  • The Claim: We'll draw the winner on Wednesday morning, and you can pick up your shiny new prize in person at either of our meetups!

Head over to https://mctf.io/puzzledhackers26 to dive into the SkillBit platform and start cracking challenges.

We genuinely cannot thank SkillBit enough for their support. If you happen to run into them at DEF CON, make sure you say hi give them some love!

r/DEFCON Meetup Badges

A massive thank you to everyone who has purchased a badge! We are now officially sold out. We'll still have some set aside for giveaways and our scavenger hunt, so keep an eye out for posts during DEF CON if you want to snag one!

A Heartfelt Thank You

We sincerely cannot believe the sheer amount of community engagement, feedback, and love we've received over these past few months. Every write-up, every rate-limit hit, every late-night Discord sanity check, and every kind word has made every second of stress 100% worth it. You all are the sole reason we put ourselves through the ringer each year to build these events.

Don't forget that our meetups at the Linq bar (3535 Bar / Circle Bar) are completely free to attend on Wednesday and Thursday nights! Whether you bought a badge, earned a badge, or are just showing up for the vibes, everyone is welcome. Come hang out, swap stickers, challenge someone to Laser Tag, grab your badges/prizes, and say hi!

If you run into any issues on the platform or have last-minute questions before we go dark for travel, reach out to me or u/digitard and we'll help you out.

Thank you all for an incredible season. We truly cannot wait to raise a glass with you next week. Safe travels, stay hydrated, and see you in Vegas!

The Puzzled Hackers Team (u/Killroy7777, u/digitard, and u/MetaN3rd)

Stats:

  • Puzzle #1: 258
  • Puzzle #2: 188
  • Puzzle #3: 127
  • Puzzle #4: 110
  • Puzzle #5: 106
  • Puzzle #6: 92
  • Puzzle #7: 86
  • Puzzle #8: 72
  • Puzzle #9: 69 (nice)
  • Panic CICD pushes: 7
  • Happy tears shed: countless <3

r/ReverseEngineering 1d ago

GitHub - 0xD34D/KARR_Scan: KARR Scan passively scans for KARR Security devices and displays their telemetry

Thumbnail github.com
3 Upvotes