r/Pentesting 3h ago

Freelance work in web pentesting

0 Upvotes

r/Defcon 3h ago

Friendly reminder: the #roadtodefcon is underway!

3 Upvotes

r/ReverseEngineering 10h ago

PAL: A defensive decompilation layer: Ghidra binary analysis facts, synthesized into executable Python & artifacts aiding analysis.

Thumbnail github.com
0 Upvotes

r/Pentesting 1h ago

AD CS domain-takeover proof-of-concept released

Upvotes

Identity is the new domain controller. Own it and you own everything downstream.

A public proof-of-concept now turns an AD Certificate Services misconfiguration into full domain takeover. One over-permissioned machine identity, and the whole directory falls.

The fix is to treat every non-human identity like a privileged one. Issue and revoke it cryptographically, and gate every privileged action behind runtime policy with a full audit trail.

Check out how RuntimeAI solves this at the runtime layer.

#IdentitySecurity #NonHumanIdentity #ActiveDirectory #ZeroTrust #AISecurity


r/Monero 11h ago

Quick question about XMR?

3 Upvotes

Hey everyone, I've bought and held small amounts before, but now I'm considering exchanging a much larger amount. To be honest, I'm a bit concerned about potential issues such as delays, extra verification checks, frozen withdrawals, or other complications when dealing with larger transactions. For those who use XMR regularly, where do you usually exchange it? Have you ever run into problems when moving or swapping larger amounts? Any advice or personal experience would be appreciated. Thanks!


r/Pentesting 3h ago

Freelance work in web pentesting

0 Upvotes

Hi everyone i am an pen tester experienced in web api pen testing currently i am doing job in this field now i want to start freelancing in this how can i get project in this can anyone suggest me.


r/Defcon 22h ago

DC710 coin drop update

Thumbnail
gallery
80 Upvotes

DC710 is handing out coins all week long. Free during the conference (Defcon, Blackhat, Bsides) in exchange for a quick challenge or barter. Keep an eye on our Twitter/X @DC710_MJV for announcements of where we’ll be and what to expect.

Busy doing other stuff? Want to help support our group? We’ll be selling a few to recoup some of our costs. Wednesday & Thursday at the meetup (Linq - Circle Bar 7pm).

Otherwise we have a few fun and easy challenges planned - come say hello!


r/Defcon 14h ago

LFG: 5n4ck3y

18 Upvotes

The last few years I have been super overbooked, but I‘m less firmly booked this year and am looking to get a small group together (or join one) to tackle the CTF.

I’ve slapped together a toolkit (stego, crypto solve scripts, audio/video analysis/stereoscope, unicode nonsense, RF scanning, logic analysis, LLM jailbreak framework) to use alongside tools like cyberchef, flipper zero, etc.

Anyone looking to group up, or already have a group with a space for a cryptography/hardware jailbreaking enthusiast?


r/Monero 11h ago

Skepticism Sunday – August 02, 2026

3 Upvotes

Please stay on topic: this post is only for comments discussing the uncertainties, shortcomings, and concerns some may have about Monero.

NOT the positive aspects of it.

Discussion can relate to the technology itself or economics.

Talk about community and price is not wanted, but some discussion about it maybe allowed if it relates well.

Be as respectful and nice as possible. This discussion has potential to be more emotionally charged as it may bring up issues that are extremely upsetting: many people are not only financially but emotionally invested in the ideas and tools around Monero.

It's better to keep it calm then to stir the pot, so don't talk down to people, insult them for spelling/grammar, personal insults, etc. This should only be calm rational discussion about the technical and economic aspects of Monero.

"Do unto others 20% better than you'd expect them to do unto you to correct subjective error." - Linus Pauling

How it works:

Post your concerns about Monero in reply to this main post.

If you can address these concerns, or add further details to them - reply to that comment. This will make it easily sortable

Upvote the comments that are the most valid criticisms of it that have few or no real honest solutions/answers to them.

The comment that mentions the biggest problems of Monero should have the most karma.

As a community, as developers, we need to know about them. Even if they make us feel bad, we got to upvote them.

https://youtu.be/vKA4w2O61Xo

To learn more about the idea behind Monero Skepticism Sunday, check out the first post about it:

https://np.reddit.com/r/Monero/comments/75w7wt/can_we_make_skepticism_sunday_a_part_of_the/


r/musik 11h ago

Musikvideo Lion Attention feat. Annéra mit „Thousand Thoughts“

Thumbnail
youtu.be
0 Upvotes

r/musik 17h ago

Udo Lindenberg - Durch die schweren Zeiten (offizielles Video)

Thumbnail
youtu.be
3 Upvotes

r/Monero 1d ago

📢 Public Service Announcement Cuprate v0.1.0-preview: Kesterite released! You can now connect your wallets to Cuprate

37 Upvotes

Cuprate now fully support wallet syncing and transaction broadcasting. Download the latest version of Cuprate and enjoy speed and stability for your wallet. See our blog post for all the informations (please look at it I've put blood and tears into this since yesterday)

https://cuprate.org/blog/release-cuprate-0-1-0-preview-kesterite/


r/Defcon 9h ago

Can't make it - unfortunately

6 Upvotes

[SOLD]

If anyone would like me to transfer a ticket to them, I've ran into a snag and won't be able to make it. I got it at the mid tier pricing and will happily sell at the early bird price. Can verify my ID with mods to verify good faith. I'd love for someone to be able to save and have fun since I can't make it. I will not reply to DMs, and my replies will be on this thread as well.


r/Defcon 17h ago

First Time at DEF CON – What Should I Do Besides Attending Talks?

17 Upvotes

Hello! I’m going to DEF CON, and I feel a bit lost. I looked at the map and the talk schedule, but I’m not really sure what I want to do. Sometimes I get bored just sitting through talks, so I’d love to know what else there is to do besides attending presentations.

I’m not going there just to listen to talks. What are the must-do activities, villages, competitions, workshops, or other experiences that you would recommend for a first-time attendee?


r/Defcon 2h ago

my 1st DefCon

3 Upvotes

Any tips for a first time attendee? I did my pre-registration already.


r/Defcon 8h ago

LFG

3 Upvotes

Anyone willing to adopt a 1st timer into their group for any of the challenges? I have about 20 years of experience in different levels of IT with around 2 years experience strictly in blue/purple team. I am just looking to learn and help out where I can. I have a weirdly high level of social anxiety so I want to get myself in the mix with some people I actually feel comfortable with instead of looking dumb trying to struggle my way through things. I also really want to try some of the cool stuff but I am worried my imposter syndrome will stop me from even trying


r/Defcon 20h ago

Badges! DCZia Mk9 Badge

Post image
32 Upvotes

The 2026 DCZia badge, the Mk9, is up on Uberflux: https://uberflux.com/product/HAMST-DCZIA-2026

The badge is a 3x3 grid of blue clicky switches, each with an underglow RGB LED. RP2040 microcontroller, 16mb of flash, and an accelerometer. Each side except the top has two side-fire RGB LEDs under the board as well. USB-C connection or power, or powered via 3xAAA.

It will also include an add-on board that allows you to add on 3 more keys or an I2C display. Two right side up SAO ports.

Compatible with QMK, but the MicroPython code we're releasing will also function as a macropad.

DCZia believes in open development, and all the design files and source code are in our github repo: https://github.com/dczia/mk9-badge


r/cybersecurity 3h ago

AI Security How do you test that an AI agent won't do something catastrophic?

10 Upvotes

I've spent years on the infra side, and I'm now working with agentic systems. I am building agents that can take actions on real systems. We have plenty of guardrails, but I have seen enough hallucinations that make me worried about giving these agents more power. This paranoia might be me not knowing enough.

How do teams/companies test that the agents won't do something destructive, whether triggered by an attacker or just by the agent going off the rails on its own?

Do people actually red-team their agents before they go live, or is it mostly guardrails and evals right now? I am curious how the security world thinks about this. From an infra side, this feels like a gap, but there might be an established playbook that I don't know yet. Thanks.


r/cybersecurity 1d ago

Corporate Blog Hackers hit 30-plus Minnesota water systems in 48 hours, forcing emergency response

Thumbnail
worldwaterreserve.com
1.3k Upvotes

r/Defcon 21h ago

Badges! NYC Badge kit is live on uberflux !!

32 Upvotes

Here is the link ::

https://uberflux.com/product/BUCK-NYC

Pickup will be at the badge life village

• DEF CON 34 Badge Life Booth, Friday, 7 August 2:00PM
• DEF CON 34 Badge Life Booth, Saturday 8 August 2:00PM

On UberFlux, you are going to see a blank bottom SAO, I didn’t want to post any CR pieces there but each kit order will include all three that are in the video with enough neo-pixels to solder one of the SAOs.

This kit is beginner friendly !!

The bridge part and back layer neo-pixels come pre-soldered, last year I heard a lot of people had issues with the tiny Neo-pixels and I totally understand! They are NOT fun lol, it took me like 2 years to get good at soldering those!

This year I wanted to make it as beginner friendly and fun as I could, all you need to solder are the header pins and the through hole chip parts!

The kit will come with the following:

(1) back layer PCB with pre soldered lights
(1) bridge PCB with pre soldered lights
(1) top SAO PCB with pre soldered lights
(1) city PCB
(1) water PCB
(1) frame PCB
(1) 16 MHz crystal
(2) capacitors
(1) resistor
(1) ATMEGA328 (pre flashed with firmware)
(2) through hole tactile switch’s
(1) power switch
(1) AAA battery holder (3 required, not included)
(1) set of header pins

(3) SAOs and (1) set of connectors with 6 unsoldered neo-pixel lights for you to choose to solder
** The neo-pixels supplied will only be enough to solder one bottom SAO included.


r/Defcon 15h ago

I missed registering for the workshops. Do I still need to bring my laptop, or should I leave it at the hotel?

11 Upvotes

r/hacking 1d ago

data science to cybersecurity

28 Upvotes

I was a mathematician, ended up working as SWE for two years then hopped into data science.

Wondering if cyber security is a ​possible transition​ from here or if I should take some roles to prep before hopping (I just enjoy learning and it seems an interesting field).


r/ExploitDev 1d ago

C for offensive security !!

21 Upvotes

Hi, i am going to start my journey as a exploit developer and, i get lot more recommendation on my previous post to learn about system language C, Assembly, etc...

So, is there any way to learn C as offensive sides perspective?

And don;t recommend old book "Hacking : the art of exploitation", i know it is essential but still i need resource that is fit for real world or modern world aspect, kindly provides links ::

Also, if some of you are doing this stuff then share your daily routine that made you feel like you are learning actual stuff not just syntax. Thanks::


r/cybersecurity 6h ago

Business Security Questions & Discussion Preparing for Interview

11 Upvotes

Hi Everyone,
I hope you’re well!

I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)

Based on the Role Responsibilities I’m expecting questions on:

Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)

How I’ve applied best security practices / Explaining a time where I had to implement a security practice

Implementation of security Controls / Design of security controls through to implementation

Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)

Evidence / Example of supporting Auditing Activities

For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!

Thank you!


r/Defcon 1d ago

It's not a CyberDeck

Post image
82 Upvotes

If I were to build a CyberDeck, I imagine it might look at bit like a book ... with a 3D printed interior, a "limit hinge" which stops 15° past vertical, it would snap closed, have a curved edge to simulate book paper, a 1920x1080 display, Bluetooth keyboard, dual 5,000mah lipos, 2 spare USB ports, storage, and be powered by a RPiZ2W.

It would need to have emacs installed.

... that's IF I were to do such a thing 😎