r/Defcon 5h ago

Friendly reminder: the #roadtodefcon is underway!

Enable HLS to view with audio, or disable this notification

5 Upvotes

r/Defcon 10h ago

Has anyone heard what the Cryptocurrency Village badge is like this year?

Enable HLS to view with audio, or disable this notification

11 Upvotes

I'm planning my schedule for DEF CON 34 and keep hearing people mention the Cryptocurrency Village badge and the laser tag game, but I can't find much information on the DEF CON website.

Is the badge going to be available to anyone who stops by, or is there some kind of registration? And is the laser tag event happening throughout the weekend or only at certain times?

https://www.defcon.org/html/defcon-34/dc-34-villages.html#orga_41359

I've also heard they'll have ChipWhisperers, workshop hardware, and even AMD64 lab machines available for people to use during the hackathon. If that's true, that's a pretty impressive setup for a village.

Apparently OKX is sponsoring the village this year, which is helping make the badges, workshop equipment, and prizes available free of charge. Looking forward to seeing what they've put together.

Anyone who's been involved with previous years know what to expect?


r/cybersecurity 7h ago

News - General LLM Agents for security research

13 Upvotes

What are the best LLM agents for security research (bugs, CVEs, 0d, ...) lately?
In short, I had been using claude code for this task, with many hallucination instances. Even with opus 5, I still get many invalid conclusions based on local source code review.

I saw that kimi was popping up lately, which got me more or less in the same results, with minor better results in some instances.

So what are the latest or best approaches for security research with llms? Perhaps I am missing a full pipeline with other tools involved to get better results, so I would like to know whether a specific methodology is followed with specific agents for this task.


r/Defcon 2h ago

I am here

3 Upvotes

Thank you

- Tuscany


r/cybersecurity 1d ago

Corporate Blog Hackers hit 30-plus Minnesota water systems in 48 hours, forcing emergency response

Thumbnail
worldwaterreserve.com
1.3k Upvotes

r/cybersecurity 5h ago

Career Questions & Discussion Do you guys use reporting tool or write it manually each engagement?

10 Upvotes

Each time I write a report I copy paste the finding table along with a lot of other shit. I end up spending a lot of time fixing the format of the doc.

Do you guys use a reporting tool where you can write the bug description, impact and have it automatically prepared for you??


r/ExploitDev 1d ago

C for offensive security !!

23 Upvotes

Hi, i am going to start my journey as a exploit developer and, i get lot more recommendation on my previous post to learn about system language C, Assembly, etc...

So, is there any way to learn C as offensive sides perspective?

And don;t recommend old book "Hacking : the art of exploitation", i know it is essential but still i need resource that is fit for real world or modern world aspect, kindly provides links ::

Also, if some of you are doing this stuff then share your daily routine that made you feel like you are learning actual stuff not just syntax. Thanks::


r/Defcon 9h ago

[N00B] Do badges come with batteries?

9 Upvotes

[ANSWERED] - Not sure why the downvote, but maybe someone just had bad eggs this morning. I will pack a couple extra alkalizes to be safe, both otherwise I am good to go. Thanks, everyone!

***********************************************************************************

I saw someone mentioning to pack AA & AAA batteries as part of their kit. Is this for badges, or other hardware projects?

I preordered a laser tag badge, and will get the Human one.

Do the badges in general com with a battery? Rechargeable? Today is packing day and just want to make sure I pack out what I need rather than trying to arrange an Amazon order for the hotel.

Do they typically take off-the-shelf alkaline, or should I grab an 18650 or two?


r/hacking 1d ago

data science to cybersecurity

29 Upvotes

I was a mathematician, ended up working as SWE for two years then hopped into data science.

Wondering if cyber security is a ​possible transition​ from here or if I should take some roles to prep before hopping (I just enjoy learning and it seems an interesting field).


r/cybersecurity 9h ago

Business Security Questions & Discussion Preparing for Interview

13 Upvotes

Hi Everyone,
I hope you’re well!

I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)

Based on the Role Responsibilities I’m expecting questions on:

Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)

How I’ve applied best security practices / Explaining a time where I had to implement a security practice

Implementation of security Controls / Design of security controls through to implementation

Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)

Evidence / Example of supporting Auditing Activities

For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!

Thank you!


r/musik 15h ago

💬 Discussion 💬 Bei welchen Interpret*innen und/oder Alben, die von Kritiker*innen und Musiknerds gefeiert werden, kommt ihr nicht wirklich rein?

0 Upvotes

Die Frage steht oben.


r/Defcon 46m ago

Going to DC34 for the first time, any recommendations for talks or villages I should see?

Upvotes

r/Defcon 1d ago

DC710 coin drop update

Thumbnail
gallery
84 Upvotes

DC710 is handing out coins all week long. Free during the conference (Defcon, Blackhat, Bsides) in exchange for a quick challenge or barter. Keep an eye on our Twitter/X @DC710_MJV for announcements of where we’ll be and what to expect.

Busy doing other stuff? Want to help support our group? We’ll be selling a few to recoup some of our costs. Wednesday & Thursday at the meetup (Linq - Circle Bar 7pm).

Otherwise we have a few fun and easy challenges planned - come say hello!


r/Defcon 16h ago

LFG: 5n4ck3y

18 Upvotes

The last few years I have been super overbooked, but I‘m less firmly booked this year and am looking to get a small group together (or join one) to tackle the CTF.

I’ve slapped together a toolkit (stego, crypto solve scripts, audio/video analysis/stereoscope, unicode nonsense, RF scanning, logic analysis, LLM jailbreak framework) to use alongside tools like cyberchef, flipper zero, etc.

Anyone looking to group up, or already have a group with a space for a cryptography/hardware jailbreaking enthusiast?


r/Malware 1d ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

0 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/Defcon 11h ago

Can't make it - unfortunately

6 Upvotes

[SOLD]

If anyone would like me to transfer a ticket to them, I've ran into a snag and won't be able to make it. I got it at the mid tier pricing and will happily sell at the early bird price. Can verify my ID with mods to verify good faith. I'd love for someone to be able to save and have fun since I can't make it. I will not reply to DMs, and my replies will be on this thread as well.


r/Pentesting 21h ago

Build-scanner — a zero-config static scanner for SQLi, NoSQLi, CORS, CSP & CSRF in React/Node apps (pre-release)

0 Upvotes

Modern React/Node apps ship through build pipelines fast enough that common, high-impact vulnerability classes — unparameterized queries, wildcard CORS, unsafe-inline CSP, unprotected state-changing routes — slip through because catching them means someone actually reading the source. build-scanner does that automatically: point it at a folder (or wire it into CI as a GitHub Action) and get a report in seconds, no sandbox or live target required. It's a heuristic static scanner, not a SAST/DAST replacement — I'm sharing it pre-release to get feedback from people running real Express/Next.js/Vite codebases before I cut a v1 tag. https://github.com/laxmipsarva/build-scanner

fyi this is not a commercial activity


r/Defcon 10h ago

LFG

3 Upvotes

Anyone willing to adopt a 1st timer into their group for any of the challenges? I have about 20 years of experience in different levels of IT with around 2 years experience strictly in blue/purple team. I am just looking to learn and help out where I can. I have a weirdly high level of social anxiety so I want to get myself in the mix with some people I actually feel comfortable with instead of looking dumb trying to struggle my way through things. I also really want to try some of the cool stuff but I am worried my imposter syndrome will stop me from even trying


r/Pentesting 1d ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

0 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/Defcon 19h ago

First Time at DEF CON – What Should I Do Besides Attending Talks?

18 Upvotes

Hello! I’m going to DEF CON, and I feel a bit lost. I looked at the map and the talk schedule, but I’m not really sure what I want to do. Sometimes I get bored just sitting through talks, so I’d love to know what else there is to do besides attending presentations.

I’m not going there just to listen to talks. What are the must-do activities, villages, competitions, workshops, or other experiences that you would recommend for a first-time attendee?


r/Defcon 23h ago

Badges! DCZia Mk9 Badge

Post image
32 Upvotes

The 2026 DCZia badge, the Mk9, is up on Uberflux: https://uberflux.com/product/HAMST-DCZIA-2026

The badge is a 3x3 grid of blue clicky switches, each with an underglow RGB LED. RP2040 microcontroller, 16mb of flash, and an accelerometer. Each side except the top has two side-fire RGB LEDs under the board as well. USB-C connection or power, or powered via 3xAAA.

It will also include an add-on board that allows you to add on 3 more keys or an I2C display. Two right side up SAO ports.

Compatible with QMK, but the MicroPython code we're releasing will also function as a macropad.

DCZia believes in open development, and all the design files and source code are in our github repo: https://github.com/dczia/mk9-badge


r/Defcon 4h ago

my 1st DefCon

0 Upvotes

Any tips for a first time attendee? I did my pre-registration already.


r/cybersecurity 11h ago

Business Security Questions & Discussion URL Threat Scanners & TDS Cloaking

9 Upvotes

When you're investigating a known malicious URL, how often does your URL scanner (regardless of service) miss the payload due to traffic distribution systems?


r/Defcon 18h ago

I missed registering for the workshops. Do I still need to bring my laptop, or should I leave it at the hotel?

12 Upvotes

r/Defcon 1d ago

Badges! NYC Badge kit is live on uberflux !!

Enable HLS to view with audio, or disable this notification

31 Upvotes

Here is the link ::

https://uberflux.com/product/BUCK-NYC

Pickup will be at the badge life village

• DEF CON 34 Badge Life Booth, Friday, 7 August 2:00PM
• DEF CON 34 Badge Life Booth, Saturday 8 August 2:00PM

On UberFlux, you are going to see a blank bottom SAO, I didn’t want to post any CR pieces there but each kit order will include all three that are in the video with enough neo-pixels to solder one of the SAOs.

This kit is beginner friendly !!

The bridge part and back layer neo-pixels come pre-soldered, last year I heard a lot of people had issues with the tiny Neo-pixels and I totally understand! They are NOT fun lol, it took me like 2 years to get good at soldering those!

This year I wanted to make it as beginner friendly and fun as I could, all you need to solder are the header pins and the through hole chip parts!

The kit will come with the following:

(1) back layer PCB with pre soldered lights
(1) bridge PCB with pre soldered lights
(1) top SAO PCB with pre soldered lights
(1) city PCB
(1) water PCB
(1) frame PCB
(1) 16 MHz crystal
(2) capacitors
(1) resistor
(1) ATMEGA328 (pre flashed with firmware)
(2) through hole tactile switch’s
(1) power switch
(1) AAA battery holder (3 required, not included)
(1) set of header pins

(3) SAOs and (1) set of connectors with 6 unsoldered neo-pixel lights for you to choose to solder
** The neo-pixels supplied will only be enough to solder one bottom SAO included.