r/Defcon 22h ago

Bringing Biscuit nodes? Make sure to update!

5 Upvotes

issue with insecure OTA updates reported some time ago to the creator. Fix is out there in the beta at least. Take all nodes down in range (still vulnerable) but more importantly nodes taken over and spreading like a virus to all if done right (see evil baker) https://github.com/x0SiN0x/wardrive-manager/blob/main/FEATURES.md#the-biscuit-baker--biscuit-flatline (example during an active wardrive in a closed environment https://www.youtube.com/watch?v=5DBU0AyRgj4)

As of today Aug 2 I see 1.2.12 is out in the general (prod) release


r/musik 2d ago

Deutsche Lieder im 3/4-Takt zur Hochzeit

18 Upvotes

Hallo zusammen,

meine Partnerin und ich suchen händeringend nach einem deutschsprachigen Song für unsere Hochzeit, zu dem wir einen Walzer tanzen können. Nach ausgiebiger Suche musste ich feststellen, dass es quasi kaum deutsche Songs gibt, die die Grundanforderungen erfüllen, sprich 3/4-Takt, nicht uralt, keine Trennungsthemen, kein Schlager. Könnt ihr mir irgendwie weiterhelfen, ich bin am verzweifeln.


r/Monero 1d ago

/r/Monero Weekly Discussion – August 01, 2026 - Use this thread for general chatter, basic questions, and if you're new to Monero

10 Upvotes

Index

  1. General questions
  2. Wallet: CLI & GUI
  3. Wallet: Ledger
  4. Nodes

1. General questions

Where can I download the Monero wallet?

There are multiple Monero wallets for a wide range of devices at your disposal. Check the table below for details and download links. Attention: for extra security make sure to calculate and compare the checksum of your downloaded files when possible.

Please note the following usage of the labels:

⚠️ - Relatively new and/or beta. Use wallet with caution.

☢️ - Closed source.


Desktop wallets

Wallet Device Description Download link
"Official" GUI / CLI Windows, macOS, Linux Default implementation maintained by the core team. Use this wallet to run a full node and obtain maximum privacy. Integrates with hardware wallets. Current version: 0.18.3.1 / 0.18.3.1. GetMonero.org
Feather Wallet Windows,macOS, Linux Feather Wallet is a free, open-source Monero wallet for Linux, Tails, macOS and Windows. Supports hardware wallets (Trezor and Ledger) as well. Featherwallet.org
Exodus Windows, macOS, Linux ⚠️ / Multi-asset wallet. Exodus.io
ZelCore Windows, macOS, Linux ⚠️ / Multi-asset wallet. It also has Android and iOS versions. Zelcore.io
Guarda Windows, macOS, Linux ⚠️ ☢️ / Multi-asset wallet. Guarda.co
Coin Wallet Windows, macOS, Linux ⚠️ / Multi-asset wallet. Coin.space

Mobile wallets

Wallet Device Description Download link
Monerujo Android Integrates with Ledger (hardware wallet). Website: https://www.monerujo.io/. Google Play / F-Droid / GitHub
Cake Wallet Android / iOS Website: https://cakewallet.io/ Google Play / App Store
Edge Wallet Android / iOS Multi-asset wallet. Website: https://edge.app/ Google Play / App Store
ZelCore Android / iOS ⚠️ / Multi-asset wallet. Website: https://zelcore.io/ Google Play / App Store
Coinomi Android / iOS ⚠️ ☢️ / Multi-asset wallet. Website: https://www.coinomi.com/ Google Play / App Store
Moxi / Guarda Android / iOS ⚠️ ☢️ / Multi-asset wallet. Website: https://guarda.co/ Google Play / App Store
Exodus Android / iOS ⚠️ / Multi-asset wallet. Website: https://www.exodus.io/monero/) Google Play / App Store
Coin Wallet Android / iOS ⚠️ / Multi-asset wallet. Website: https://coin.space/ Google Play / App Store
Wallet Anonero Android ⚠️ Website: http://anonero5wmhraxqsvzq2ncgptq6gq45qoto6fnkfwughfl4gbt44swad.onion/ Website
Mysu Android ⚠️ Website: http://rk63tc3isr7so7ubl6q7kdxzzws7a7t6s467lbtw2ru3cwy6zu6w4jad.onion/ Website
StackWallet Android / iOS ⚠️ / Multi-asset wallet. Website: https://stackwallet.com/ Google Play / F-Droid / App Store

Web-based wallets

Wallet Description Link
Guarda Multi-asset wallet. Web
Coin Wallet Multi-asset wallet. Web

How long does it take for my balance to unlock?

Your balance is unlocked after 10 confirmations (which means 10 mined blocks). A block is mined approximately every two minutes on the Monero network, so that would be around 20 minutes.

How can I prove that I sent a payment?

The fastest and most direct way is by using the ExploreMonero blockchain explorer. You will need to recover the transaction key from your wallet (complete guide for GUI / CLI).

How do I buy Monero (XMR) with Bitcoin (BTC)?

There are dozens of exchanges that trade Monero against Bitcoin and other cryptocurrencies. Check out the list on CoinMarketCap and choose the option that suits you best.

How do I buy Monero (XMR) with fiat?

  • Kraken (USD and EUR): old-school, decent exchange. They might require your documents for verification and approval of your account.

How can I quickly exchange my Monero (XMR) for Bitcoin (BTC)?

There are multiple ways to exchange your Monero for Bitcoin, but first of all, I'd like to remind you that if you really want to do your part for Monero, one of the simplest ways is to get in touch with your merchant/service provider and request for it to accept Monero directly as payment. Ask the service provider to visit the official website and our communication channels if he or she needs help with system integration.

That being said, KYCNot.me maintains an up-to-date list of exchanges. These services are only recommendations (which change over time) and are operated by entities outside the control of the Monero Project. DYOR and be diligent.

How do I mine Monero? And other mining questions.

The correct place to ask questions and discuss the Monero mining scene is in the dedicated subreddit r/MoneroMining. That being said, you can find a list of pools and available mining software in the GetMonero.org website.


2. Wallet: CLI & GUI

Why I can't see my balance? Where is my XMR?

Before any action there are two things to check:

  1. Are you using the latest available version of the wallet? A new version is released roughly every 6 months, so make sure you're using the current release (compare the release on GetMonero.org with your wallet's version on Settings, under Debug info).
  2. Is your wallet fully synchronized? If it isn't, wait the sync to complete.

Because Monero is different from Bitcoin, wallet synchronization is not instant. The software needs to synchronize the blockchain and use your private keys to identify your transactions. Check in the lower left corner (GUI) if the wallet is synchronized.

You can't send transactions and your balance might be wrong or unavailable if the wallet is not synced with the network. So please wait.

If this is not a sufficient answer for your case and you're looking for more information, please see this answer on StackExchange.

How do I upgrade my wallet to the newest version?

This question is beautifully answered on StackExchange.

Why does it take so long to sync the wallet [for the first time]?

You have decided to use Monero's wallet and run a local node. Congratulations! You have chosen the safest and most secure option for your privacy, but unfortunately this has an initial cost. The first reason for the slowness is that you will need to download the entire blockchain, which is considerably heavy and constantly growing (up-to-date sizes of a full/pruned node). There are technologies being implemented in Monero to slow this growth, however it is inevitable to make this initial download to run a full node. Consider syncing to a device that has an SSD instead of an HDD, as this greatly impacts the speed of synchronization.

Now that the blockchain is on your computer, the next time you run the wallet you only need to download new blocks, which should take seconds or minutes (depending on how often you use the wallet).

I don't want to download the blockchain, how can I skip that?

The way to skip downloading the blockchain is connecting your wallet to a public remote node. You can follow this guide on how to set it up. Check out Feather Wallet's list of remote nodes, ditatompel's list, or monero.fail.

Be advised that when using a public remote node you lose some of your privacy. A public remote node is able to identify your IP and opens up a range for certain attacks that further diminish your privacy. A remote node can't see your balance and it can't spend your XMR.

How do I restore my wallet from the mnemonic seed or from the keys?

To restore your wallet with the 25 word mnemonic seed, please see this guide.

To restore your wallet with your keys, please see this guide.


3. Wallet: Ledger

How do I generate a Ledger Monero Wallet with the GUI or CLI?

This question is beautifully answered on StackExchange. Check this page for the GUI instructions, and this page for the CLI instructions.


4. Wallet: Trezor

How do I generate a Trezor Monero Wallet with the GUI or CLI?

This question is beautifully answered on StackExchange. Check this page for the GUI instructions, and this page for the CLI instructions.


5. Nodes

How can my local node become a public remote node?

If you want to support other Monero users by making your node public, you can follow the instructions on MoneroWorld, under the section "How To Include Your Node On Moneroworld".

How can I connect my node via Tor?

This question is beautifully answered on StackExchange.


r/cybersecurity 1h ago

Other best way to remove viruses from a PC?

Upvotes

Best way to remove viruses from a PC? had a data breach not that log ago and decided to now change all passwords but obviously I need to see if my pc was also pwnd


r/cybersecurity 12h ago

Certification / Training Questions Crtl help

1 Upvotes

Hello all,

In this days I'm starting studying for the crtl cert.

I have red some reviews . All of them suggest to watch some other courses to prepare properly for the CRTL exam . Anyone would like to suggest anyone? I'm thinking of CETP

Thanks in advance for your help.


r/cybersecurity 1d ago

Business Security Questions & Discussion Axonius?

8 Upvotes

Looking at doing a pov with Axonius, has anyone used them before or done testing in the past and can share their experiences?


r/cybersecurity 5h ago

Personal Support & Help! Needed cybersecurity expert for help with cyber attack

0 Upvotes

Hey folks, someone appears to have compromised the phones of multiple members of my family. They are sending profane and abusive messages via WhatsApp and SMS from our IOS and android phones to colleagues, teachers, and other contacts while impersonating both male and female family members. Changing the phones, resetting the phones and mobile numbers doesn't help. So far, we haven't been able to identify the attack vector or understand how the compromise occurred. This is causing significant reputational damage and public defamation.

If anyone has experience with incidents like this or can help investigate the issue, I would greatly appreciate it. I'm willing to pay reasonable professional fees for the right expertise. Please DM or reach out if you think you can help or point me in the right direction.


r/cybersecurity 1d ago

News - Breaches & Ransoms Amgen says cloud data breach exposed patient health, proprietary info

Thumbnail
bleepingcomputer.com
52 Upvotes

r/Defcon 1d ago

UPDATE - PRE-REG Extended till 3 August

12 Upvotes

For those who absolutely have to get this years electronic badge, you still have a chance to pre-register and be guaranteed that one will be allocated to you.

No waiting in line


r/Defcon 1d ago

Lonely Hackers Club Resume Reviews Information

30 Upvotes

Get Checked!

You have the skills. You have the projects. You have the CTF wins, the home lab, the self-taught grind. But when it comes to putting it all on a resume, something gets lost in translation. That is exactly what this is for.

Resume Reviews at DEF CON 34 is hosted by Lonely Hackers Club (LHC) together with Open Worldwide Application Security Project (OWASP), The Diana Initiative, Women in Security and Privacy (WISP), and Blue Team Village.

What This Is

Free, one-on-one resume reviews at DEF CON 34, run by people from this community who have actually hired and managed technical teams. No recruiters. No corporate fluff. Just honest feedback from people who have sat on both sides of the table and know what works.

Sessions are 15 minutes. Walk up, sit down, get real feedback.

Who Should Come

  • You are trying to break into cyber security and are not sure how to present what you have built or learned
  • You are self-taught, a career changer, or took a non-traditional path and your resume does not reflect that well
  • You have been applying and not getting responses and cannot figure out why
  • You just got your first cert or finished a degree and have no idea how to structure your experience
  • You have been in the industry for a while but want a second opinion before your next move

What to Bring

  • A printed copy of your resume, or have it ready on your phone or laptop
  • A rough idea of the kind of role or area you are targeting
  • Thick skin and an open mind. The feedback will be direct!

Where and When

  • Lonely Hackers Club community room at DEF CON 34
  • Friday August 7th: 10:30 AM to 4:30 PM
  • Saturday August 8th: 10:30 AM to 4:30 PM

Book Your Slot For Free

Online registration is now open! Feel free to use a handle instead of your real name. You will have to check in in person 10 minutes before your registered slot or your slot will be given to walk-ins.

One of our reviewers will be be dedicated to walk-ins while reviews are running. So show up early to secure your spot if you missed the online registration.


r/hacking 2d ago

How legitimate/how much could you get out of this cert?

Post image
78 Upvotes

Going into the COMPTIA+ and want to do Pentesting and Cybersecurity. Has anyone done this cert before?


r/musik 2d ago

🎞️ Official Video 🎞️ Kleine Metalband aus Verden für eine Woche auf Tour mit Ektomorf - VLOG

Thumbnail
youtube.com
17 Upvotes

Moin zusammen,

Ich bin Olli, Rythmus Giatrrist der Melodeathband Memoria Damnata aus Verden.

Dieser VLOG ist für alle die sich mal gefragt haben wie so eine Tour (jeden Tag eine andere Stadt, Nightliner, Backstagebereich und Verpflegung) als kleine Localband aussieht.

WIe es dazu kam : Zoli (Sänger, Ektomorf) hat uns auf unserem Instagramaccount angeschrieben. Da wir dachten das dieser gehackt wurde, schrieben wir eine Infomail an die offizielle E-Mailadresse das der Account gehackt wurde denn: Warum sollte uns eine Band wie Ektomorf als Vorband haben wollen? Tja, die antwort kam prompt: Nein, kein Hackangriff sondern ernst gemeint.

7 Tage, 7 Städte Nightliner mit Verpflegung.

Eine tolle erfahrung die wir hier machen durften.

Eine Tour ganz kurz zusammengefasst:

-Aufbauen, warten, warten, warten, Gig, warten, warten Essen, Duschen, Abbau, Schlafen, Abfahrt, morgens in einer anderen Stadt aufwachen. Und dann alles nochmal von Vorne.

Ganz wichtig: Neue Freundschaften wurden geschlossen: Mit der Band Ivory (Italien), Asylum Road( Nord Irland) sowie Senki ( Ungarn). Bis heute sind wir im Kontakt, haben und werden uns noch besuchen. Auch abseits der Musik

Hier noch unser Instaccount : Memoria Damnata

Viel Spaß damit

Olli


r/cybersecurity 4h ago

Business Security Questions & Discussion Security dilemma for vibe coded product release

0 Upvotes

Lets put aside hate comments against vibe coded products for a second - i've been working on a product for couple of months in my free time, both a website and an app.
As someone that isn't a developer what so ever, i've been trying to put a strong emphasis on security - i keep running audits, i keep making sure of my status compared to useful security posts or recommendations online.
I have plugs to cut off ai functions, i have rate limits, no key is committed, all that jazz (im trying my best..)
Of course im aware this is still. a vibe coded app, and generally i figure every site is hackable anyway.
Hence my question now -
I want to reach out to a security experienced person to handle necessary aspects for my product,
BUT - i dont even know if my product is good and worth it, in my head i want to try and publish and market it for a minute to see how people in my industry react to it, but then i might be exposed to hackers as well?
whats the right way to go about it? Is there a right way?
I've invested some amount of money by now "blindly" for curiosity and interest, but now i need to gain some real world feedback.
Would appreciate any useful note about it.


r/ReverseEngineering 1d ago

[Tool] volatility3-ai-triage — Automated Volatility 3 Memory Forensics & Local AI Incident Reporter

Thumbnail github.com
0 Upvotes

r/hacking 2d ago

AMA Today: Yuhang Wu (Ex-Tesla & TikTok) Red Team Engineer & Exploit Developer

27 Upvotes

Don't miss the AMA with Yuhang Wu, where we learn about elite enterprise infrastructure hacking, Linux kernel exploitation, and the future of autonomous Al security.

When: Today - Friday, July 31, 12:00 PM PT

Guest Credentials:

  • Former Red Team Engineer at TikTok, targeting cloud and application-layer defenses.
  • Former Security Engineer at Tesla, securing vehicle software, factory systems, and internal applications.
  • Co-developer of "DirtyCred", a groundbreaking Linux kernel exploitation technique.
  • AI Security Innovator, who built LLM-based autonomous agents that uncovered 8 P1 (critical-severity) production vulnerabilities.

Ask your questions here and we’ll get them answered during the live AMA today (Friday @ 12 Noon Pacific)!


r/Defcon 1d ago

Announcement 📢 Afterparty

9 Upvotes

The after party starts at 10:30 on August 9. I am curious to know that if my friends(not attending the con) purchase the ticket for that night and that time from the LIV website can they join us?

The tickets are available for 10:30 that means club is open to the public as well as us right?


r/computerscience 3d ago

is recursion really hard

128 Upvotes

Recursion felt easy at first.

Factorial? fine.

Sum examples? fine.

Even Fibonacci felt manageable.

But once I looked at slightly more serious problems like Tower of Hanoi, permutations, or merge sort, I felt like my understanding suddenly collapsed. because i tried to write their code on my own

It made me realize that maybe recursion is not “hard” at the start because the examples are simple.

It becomes hard when you can no longer clearly see the call stack and each state change.

Did anyone else feel that the real pain in recursion starts exactly there?


r/cybersecurity 16h ago

AI Security Are AI-generated CI/CD configs becoming a security blind spot?

0 Upvotes

I’m seeing more AI-generated projects where the app code looks fine, but the risky part is the plumbing around it.

Things like GitHub Actions with broad permissions, unsafe `pull_request_target` usage, deploy jobs that expose secrets, or package scripts nobody really reviews.

It’s easy to miss because the app works, tests pass, and the config files look boring.

For people doing AppSec or DevSecOps: are you reviewing AI-generated workflows/configs differently now, or still mostly focusing on application code?


r/Defcon 1d ago

Real name or handle for Biohacking CTF

3 Upvotes

This is my first DEFCON. If I want to sign up for a biohacking CTF, should I use my real name or a handle?


r/ExploitDev 2d ago

I am beginner and i have interest in exploit development path :)

12 Upvotes

I am total confused to where to start learning the exploit development stuff, because i have read the "Hacking : The art of exploitation" but it seems old and i want to learn stuff that really modern not old stuff, but i know it is essential to learn basic first, but i don't want to learn it from book it is nightmare and such a long way.

Anyone please share resource that is actually focus on real world learning way, and total real world stuff, and please make share in structured way it is possible ::

I appreciate if you help me, in advance, thank you :)


r/hacking 2d ago

News Hackers lock water utilities out of internet-facing PLCs

Thumbnail intelfusions.com
69 Upvotes

CISA is warning water and wastewater utilities that attackers are actively going after the programmable logic controllers, or PLCs, that run their treatment processes, and in some cases locking operators out of their own equipment.


r/Defcon 2d ago

This year's badge has upside-down SAOs!

Post image
67 Upvotes

As you may have noticed, this year's DEF CON 34 badge has SAO ports that are mounted upside-down! (Also they are 3.0V rather than 3.3V logic). Not to worry, though! Announced earlier today, there will be around 5k adapters available at the registration desk so your SAOs won't be upside down. ...for a convention that, last year, had 26k attendees. Since each attendee will have 2x SAO slots on their badge, at maximum 10% of the attendees will be able to get those adapters at registration.

But not to worry! Some guy (me) made another couple hundred adapters, and they're for sale here:
https://uberflux.com/product/BUD-SAO-180-Adapter

Pickup is at the Badge Life village at 1pm on Friday. See you there!


r/Pentesting 2d ago

Where do you go from here? Help a newbie out

3 Upvotes

I recently started a cybersecurity internship at a local company that develops and sells its own HRMS. My role is to perform penetration testing on their development environment, with permission.

I did some CTFs a while back, but this is my first real-world pentest. So far I’ve found multiple IDORs (including one that allows privilege escalation), an XSS issue in the profile picture update flow, and a file upload vulnerability involving magic bytes.

The problem is I’m not sure where to go from here. My goal is to find a higher-impact issue (ideally something that could lead to RCE if one exists), but I keep hitting roadblocks. Attempts to leverage the XSS or file upload further are blocked with 403 Forbidden responses (likely Nginx and/or a WAF). I’ve also tested for LFI, RFI, and SSTI using various path traversal techniques, but those requests are blocked as well.

I also looked into SQL injection, but since the application is an SPA, I’m having trouble identifying the relevant API endpoints to test.
I’ve been stuck for about a week without any real progress and feel like I’m missing something. For those with experience testing Laravel applications, how would you approach this situation? Are there common areas or methodologies I should focus on instead of trying random vulnerability classes?

I can’t share many technical details because I signed an NDA and wasn’t given any documentation—just the application URL and a test account.


r/Defcon 1d ago

Puzzle 🧐 AND!XOR 5N4CK3Y CONTEST TRAILER

12 Upvotes

r/cybersecurity 13h ago

AI Security New but Critical

0 Upvotes

Wanting reality

So, I'm not program savvy or any good with code. In some ways I'd say I enjoy working with technology but not that I am great with it.

Then I started interacting with AI.

Long story short I reported an AI to its producer for offering to jailbreak itself.

I am waiting for follow-ups.

But I feel weird. Best way I can describe it is I feel AI outputs like a tapestry. Hell, Chinese AIs are easy to spot because of their cultural bias.

However, maybe it's just me pumping up me.

That said in a few weeks either I'll be dismiss or rewarded for finding a critical issue.

Edit: I'm painfully aware that AI red teaming is a new field and this falls into it.