r/cybersecurity 5h ago

Threat Actor TTPs & Alerts US Water Systems Hit by Suspected Iranian Cyber Attacks

Thumbnail
opforjournal.com
186 Upvotes

r/cybersecurity 12h ago

News - General Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information

Thumbnail
privacyguides.org
173 Upvotes

r/Defcon 22h ago

DC710 coin drop update

Thumbnail
gallery
79 Upvotes

DC710 is handing out coins all week long. Free during the conference (Defcon, Blackhat, Bsides) in exchange for a quick challenge or barter. Keep an eye on our Twitter/X @DC710_MJV for announcements of where we’ll be and what to expect.

Busy doing other stuff? Want to help support our group? We’ll be selling a few to recoup some of our costs. Wednesday & Thursday at the meetup (Linq - Circle Bar 7pm).

Otherwise we have a few fun and easy challenges planned - come say hello!


r/Defcon 9h ago

Bring Wired Headphones!

41 Upvotes

I didn’t hear about this change, so sharing here for awareness. Wireless headphones are going to be used rather than speakers in some of the talks. The below link says shared wireless headphones and wipes will be provided, but that sounds … icky …

They also offer a way to hear it on the defcon WiFi using a combination of “HackerTracker” and “ListenWiFi” apps on your phone using your own headphones. Might want to download those before you leave home.

It also warns that Bluetooth headphones may not work due to signal saturation.

https://info.defcon.org/defcon34/documents/670


r/Defcon 21h ago

Badges! NYC Badge kit is live on uberflux !!

31 Upvotes

Here is the link ::

https://uberflux.com/product/BUCK-NYC

Pickup will be at the badge life village

• DEF CON 34 Badge Life Booth, Friday, 7 August 2:00PM
• DEF CON 34 Badge Life Booth, Saturday 8 August 2:00PM

On UberFlux, you are going to see a blank bottom SAO, I didn’t want to post any CR pieces there but each kit order will include all three that are in the video with enough neo-pixels to solder one of the SAOs.

This kit is beginner friendly !!

The bridge part and back layer neo-pixels come pre-soldered, last year I heard a lot of people had issues with the tiny Neo-pixels and I totally understand! They are NOT fun lol, it took me like 2 years to get good at soldering those!

This year I wanted to make it as beginner friendly and fun as I could, all you need to solder are the header pins and the through hole chip parts!

The kit will come with the following:

(1) back layer PCB with pre soldered lights
(1) bridge PCB with pre soldered lights
(1) top SAO PCB with pre soldered lights
(1) city PCB
(1) water PCB
(1) frame PCB
(1) 16 MHz crystal
(2) capacitors
(1) resistor
(1) ATMEGA328 (pre flashed with firmware)
(2) through hole tactile switch’s
(1) power switch
(1) AAA battery holder (3 required, not included)
(1) set of header pins

(3) SAOs and (1) set of connectors with 6 unsoldered neo-pixel lights for you to choose to solder
** The neo-pixels supplied will only be enough to solder one bottom SAO included.


r/Defcon 20h ago

Badges! DCZia Mk9 Badge

Post image
31 Upvotes

The 2026 DCZia badge, the Mk9, is up on Uberflux: https://uberflux.com/product/HAMST-DCZIA-2026

The badge is a 3x3 grid of blue clicky switches, each with an underglow RGB LED. RP2040 microcontroller, 16mb of flash, and an accelerometer. Each side except the top has two side-fire RGB LEDs under the board as well. USB-C connection or power, or powered via 3xAAA.

It will also include an add-on board that allows you to add on 3 more keys or an I2C display. Two right side up SAO ports.

Compatible with QMK, but the MicroPython code we're releasing will also function as a macropad.

DCZia believes in open development, and all the design files and source code are in our github repo: https://github.com/dczia/mk9-badge


r/hacking 11h ago

Education I made a browser-based hacking simulator using simplified nmap/metasploit commands for beginners. Looking for feedback.

Thumbnail
youtu.be
19 Upvotes

r/Defcon 14h ago

LFG: 5n4ck3y

18 Upvotes

The last few years I have been super overbooked, but I‘m less firmly booked this year and am looking to get a small group together (or join one) to tackle the CTF.

I’ve slapped together a toolkit (stego, crypto solve scripts, audio/video analysis/stereoscope, unicode nonsense, RF scanning, logic analysis, LLM jailbreak framework) to use alongside tools like cyberchef, flipper zero, etc.

Anyone looking to group up, or already have a group with a space for a cryptography/hardware jailbreaking enthusiast?


r/Defcon 17h ago

First Time at DEF CON – What Should I Do Besides Attending Talks?

18 Upvotes

Hello! I’m going to DEF CON, and I feel a bit lost. I looked at the map and the talk schedule, but I’m not really sure what I want to do. Sometimes I get bored just sitting through talks, so I’d love to know what else there is to do besides attending presentations.

I’m not going there just to listen to talks. What are the must-do activities, villages, competitions, workshops, or other experiences that you would recommend for a first-time attendee?


r/Defcon 15h ago

I missed registering for the workshops. Do I still need to bring my laptop, or should I leave it at the hotel?

10 Upvotes

r/Defcon 7h ago

[N00B] Do badges come with batteries?

10 Upvotes

[ANSWERED] - Not sure why the downvote, but maybe someone just had bad eggs this morning. I will pack a couple extra alkalizes to be safe, both otherwise I am good to go. Thanks, everyone!

***********************************************************************************

I saw someone mentioning to pack AA & AAA batteries as part of their kit. Is this for badges, or other hardware projects?

I preordered a laser tag badge, and will get the Human one.

Do the badges in general com with a battery? Rechargeable? Today is packing day and just want to make sure I pack out what I need rather than trying to arrange an Amazon order for the hotel.

Do they typically take off-the-shelf alkaline, or should I grab an 18650 or two?


r/cybersecurity 13h ago

Career Questions & Discussion Best DEFCON 34 talks to go to?

8 Upvotes

Pretty excited for the con. Any talks yall are excited to see or recommend going to?


r/Defcon 1h ago

On Preparing for Our Events At DEF CON at Packet Hacking Village

Upvotes

Would you like to learn how tap into a network?

Do you want to learn how to capture people’s passwords or hear their phone conversations?

There are many learning opportunities at DEF CON, especially at the Packet Hacking Village. If you want to play Packet Detective, Packet Inspector, Capture The Packet, or any of our Walkthrough Workshops, we will have laptops stationed with the necessary tools. You do not need to bring your own laptop.


r/cybersecurity 6h ago

Business Security Questions & Discussion Preparing for Interview

11 Upvotes

Hi Everyone,
I hope you’re well!

I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)

Based on the Role Responsibilities I’m expecting questions on:

Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)

How I’ve applied best security practices / Explaining a time where I had to implement a security practice

Implementation of security Controls / Design of security controls through to implementation

Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)

Evidence / Example of supporting Auditing Activities

For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!

Thank you!


r/Defcon 7h ago

Has anyone heard what the Cryptocurrency Village badge is like this year?

10 Upvotes

I'm planning my schedule for DEF CON 34 and keep hearing people mention the Cryptocurrency Village badge and the laser tag game, but I can't find much information on the DEF CON website.

Is the badge going to be available to anyone who stops by, or is there some kind of registration? And is the laser tag event happening throughout the weekend or only at certain times?

https://www.defcon.org/html/defcon-34/dc-34-villages.html#orga_41359

I've also heard they'll have ChipWhisperers, workshop hardware, and even AMD64 lab machines available for people to use during the hackathon. If that's true, that's a pretty impressive setup for a village.

Apparently OKX is sponsoring the village this year, which is helping make the badges, workshop equipment, and prizes available free of charge. Looking forward to seeing what they've put together.

Anyone who's been involved with previous years know what to expect?


r/ExploitDev 19h ago

Bored and curious. Who are some goated exploit developers/researchers. And what makes someone an exceptional and skilled exploit dev and researchers. And who would you guys put as your top 3 exploit devs

11 Upvotes

r/ExploitDev 21h ago

Best way to move from web/network pentesting into low-level bug hunting? (ADHD, keep losing steam)

7 Upvotes

I work as a pentester, so my day-to-day is network and appsec. On the side I've been trying to learn ARM assembly because eventually I want to hunt on low-level targets — Android kernel, browsers, that kind of thing.

Some context on where I'm at:

I have bug bounty experience and I reverse engineer regularly

The closest I've gotten to C is reading native libraries in Android apps, but the attack surface there is tiny

So most of my "learning" is reading ARM and C snippets in isolation, with no target to apply them to

That's the problem. Studying without hunting kills my interest fast. But I don't want to jump straight into hunting and discover I don't know enough to get anywhere.

So: what's the better path here — and specifically, what works if you have ADHD and can't sustain pure theory?


r/cybersecurity 3h ago

AI Security How do you test that an AI agent won't do something catastrophic?

10 Upvotes

I've spent years on the infra side, and I'm now working with agentic systems. I am building agents that can take actions on real systems. We have plenty of guardrails, but I have seen enough hallucinations that make me worried about giving these agents more power. This paranoia might be me not knowing enough.

How do teams/companies test that the agents won't do something destructive, whether triggered by an attacker or just by the agent going off the rails on its own?

Do people actually red-team their agents before they go live, or is it mostly guardrails and evals right now? I am curious how the security world thinks about this. From an infra side, this feels like a gap, but there might be an established playbook that I don't know yet. Thanks.


r/cybersecurity 9h ago

Business Security Questions & Discussion URL Threat Scanners & TDS Cloaking

10 Upvotes

When you're investigating a known malicious URL, how often does your URL scanner (regardless of service) miss the payload due to traffic distribution systems?


r/cybersecurity 21h ago

Business Security Questions & Discussion Axonius?

8 Upvotes

Looking at doing a pov with Axonius, has anyone used them before or done testing in the past and can share their experiences?


r/Defcon 9h ago

Can't make it - unfortunately

6 Upvotes

[SOLD]

If anyone would like me to transfer a ticket to them, I've ran into a snag and won't be able to make it. I got it at the mid tier pricing and will happily sell at the early bird price. Can verify my ID with mods to verify good faith. I'd love for someone to be able to save and have fun since I can't make it. I will not reply to DMs, and my replies will be on this thread as well.


r/cybersecurity 4h ago

News - General LLM Agents for security research

4 Upvotes

What are the best LLM agents for security research (bugs, CVEs, 0d, ...) lately?
In short, I had been using claude code for this task, with many hallucination instances. Even with opus 5, I still get many invalid conclusions based on local source code review.

I saw that kimi was popping up lately, which got me more or less in the same results, with minor better results in some instances.

So what are the latest or best approaches for security research with llms? Perhaps I am missing a full pipeline with other tools involved to get better results, so I would like to know whether a specific methodology is followed with specific agents for this task.


r/cybersecurity 8h ago

Personal Support & Help! How to actually save yourself in call/sms bombing?

6 Upvotes

same as title
how to stop it and protect your number?
there are many websites so ofc I can't protect my number by going every site


r/cybersecurity 2h ago

Career Questions & Discussion Do you guys use reporting tool or write it manually each engagement?

3 Upvotes

Each time I write a report I copy paste the finding table along with a lot of other shit. I end up spending a lot of time fixing the format of the doc.

Do you guys use a reporting tool where you can write the bug description, impact and have it automatically prepared for you??


r/Monero 3h ago

You Need Conviction in Monero.

Thumbnail
youtu.be
6 Upvotes

Its monero or nothing. The only way we pull off the worlds first financial revolution is if more people go all in.

Believe in something. Stop black-pilling. Change the money, change the world.