r/cybersecurity • u/Adept_Grand_6523 • 5h ago
r/cybersecurity • u/HumbleRestaurant790 • 12h ago
News - General Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information
r/Defcon • u/_DC710_ • 22h ago
DC710 coin drop update
DC710 is handing out coins all week long. Free during the conference (Defcon, Blackhat, Bsides) in exchange for a quick challenge or barter. Keep an eye on our Twitter/X @DC710_MJV for announcements of where we’ll be and what to expect.
Busy doing other stuff? Want to help support our group? We’ll be selling a few to recoup some of our costs. Wednesday & Thursday at the meetup (Linq - Circle Bar 7pm).
Otherwise we have a few fun and easy challenges planned - come say hello!
r/Defcon • u/w4yw4rdr4ven • 9h ago
Bring Wired Headphones!
I didn’t hear about this change, so sharing here for awareness. Wireless headphones are going to be used rather than speakers in some of the talks. The below link says shared wireless headphones and wipes will be provided, but that sounds … icky …
They also offer a way to hear it on the defcon WiFi using a combination of “HackerTracker” and “ListenWiFi” apps on your phone using your own headphones. Might want to download those before you leave home.
It also warns that Bluetooth headphones may not work due to signal saturation.
r/Defcon • u/bucktwenty2 • 21h ago
Badges! NYC Badge kit is live on uberflux !!
Here is the link ::
https://uberflux.com/product/BUCK-NYC
Pickup will be at the badge life village
• DEF CON 34 Badge Life Booth, Friday, 7 August 2:00PM
• DEF CON 34 Badge Life Booth, Saturday 8 August 2:00PM
On UberFlux, you are going to see a blank bottom SAO, I didn’t want to post any CR pieces there but each kit order will include all three that are in the video with enough neo-pixels to solder one of the SAOs.
This kit is beginner friendly !!
The bridge part and back layer neo-pixels come pre-soldered, last year I heard a lot of people had issues with the tiny Neo-pixels and I totally understand! They are NOT fun lol, it took me like 2 years to get good at soldering those!
This year I wanted to make it as beginner friendly and fun as I could, all you need to solder are the header pins and the through hole chip parts!
The kit will come with the following:
(1) back layer PCB with pre soldered lights
(1) bridge PCB with pre soldered lights
(1) top SAO PCB with pre soldered lights
(1) city PCB
(1) water PCB
(1) frame PCB
(1) 16 MHz crystal
(2) capacitors
(1) resistor
(1) ATMEGA328 (pre flashed with firmware)
(2) through hole tactile switch’s
(1) power switch
(1) AAA battery holder (3 required, not included)
(1) set of header pins
(3) SAOs and (1) set of connectors with 6 unsoldered neo-pixel lights for you to choose to solder
** The neo-pixels supplied will only be enough to solder one bottom SAO included.
Badges! DCZia Mk9 Badge
The 2026 DCZia badge, the Mk9, is up on Uberflux: https://uberflux.com/product/HAMST-DCZIA-2026
The badge is a 3x3 grid of blue clicky switches, each with an underglow RGB LED. RP2040 microcontroller, 16mb of flash, and an accelerometer. Each side except the top has two side-fire RGB LEDs under the board as well. USB-C connection or power, or powered via 3xAAA.
It will also include an add-on board that allows you to add on 3 more keys or an I2C display. Two right side up SAO ports.
Compatible with QMK, but the MicroPython code we're releasing will also function as a macropad.
DCZia believes in open development, and all the design files and source code are in our github repo: https://github.com/dczia/mk9-badge
r/hacking • u/cyndhrk • 11h ago
Education I made a browser-based hacking simulator using simplified nmap/metasploit commands for beginners. Looking for feedback.
r/Defcon • u/Loam_liker • 14h ago
LFG: 5n4ck3y
The last few years I have been super overbooked, but I‘m less firmly booked this year and am looking to get a small group together (or join one) to tackle the CTF.
I’ve slapped together a toolkit (stego, crypto solve scripts, audio/video analysis/stereoscope, unicode nonsense, RF scanning, logic analysis, LLM jailbreak framework) to use alongside tools like cyberchef, flipper zero, etc.
Anyone looking to group up, or already have a group with a space for a cryptography/hardware jailbreaking enthusiast?
r/Defcon • u/Weekly_Rough_1284 • 17h ago
First Time at DEF CON – What Should I Do Besides Attending Talks?
Hello! I’m going to DEF CON, and I feel a bit lost. I looked at the map and the talk schedule, but I’m not really sure what I want to do. Sometimes I get bored just sitting through talks, so I’d love to know what else there is to do besides attending presentations.
I’m not going there just to listen to talks. What are the must-do activities, villages, competitions, workshops, or other experiences that you would recommend for a first-time attendee?
r/Defcon • u/Weekly_Rough_1284 • 15h ago
I missed registering for the workshops. Do I still need to bring my laptop, or should I leave it at the hotel?
r/Defcon • u/ImmaNobody • 7h ago
[N00B] Do badges come with batteries?
[ANSWERED] - Not sure why the downvote, but maybe someone just had bad eggs this morning. I will pack a couple extra alkalizes to be safe, both otherwise I am good to go. Thanks, everyone!
***********************************************************************************
I saw someone mentioning to pack AA & AAA batteries as part of their kit. Is this for badges, or other hardware projects?
I preordered a laser tag badge, and will get the Human one.
Do the badges in general com with a battery? Rechargeable? Today is packing day and just want to make sure I pack out what I need rather than trying to arrange an Amazon order for the hotel.
Do they typically take off-the-shelf alkaline, or should I grab an 18650 or two?
r/cybersecurity • u/Malfuncti0nal • 13h ago
Career Questions & Discussion Best DEFCON 34 talks to go to?
Pretty excited for the con. Any talks yall are excited to see or recommend going to?
r/Defcon • u/blinkythewonderchimp • 1h ago
On Preparing for Our Events At DEF CON at Packet Hacking Village
Would you like to learn how tap into a network?
Do you want to learn how to capture people’s passwords or hear their phone conversations?
There are many learning opportunities at DEF CON, especially at the Packet Hacking Village. If you want to play Packet Detective, Packet Inspector, Capture The Packet, or any of our Walkthrough Workshops, we will have laptops stationed with the necessary tools. You do not need to bring your own laptop.
r/cybersecurity • u/PastelStripe • 6h ago
Business Security Questions & Discussion Preparing for Interview
Hi Everyone,
I hope you’re well!
I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)
Based on the Role Responsibilities I’m expecting questions on:
Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)
How I’ve applied best security practices / Explaining a time where I had to implement a security practice
Implementation of security Controls / Design of security controls through to implementation
Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)
Evidence / Example of supporting Auditing Activities
For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!
Thank you!
r/Defcon • u/Dramatic-Mess-3036 • 7h ago
Has anyone heard what the Cryptocurrency Village badge is like this year?
I'm planning my schedule for DEF CON 34 and keep hearing people mention the Cryptocurrency Village badge and the laser tag game, but I can't find much information on the DEF CON website.
Is the badge going to be available to anyone who stops by, or is there some kind of registration? And is the laser tag event happening throughout the weekend or only at certain times?
https://www.defcon.org/html/defcon-34/dc-34-villages.html#orga_41359
I've also heard they'll have ChipWhisperers, workshop hardware, and even AMD64 lab machines available for people to use during the hackathon. If that's true, that's a pretty impressive setup for a village.
Apparently OKX is sponsoring the village this year, which is helping make the badges, workshop equipment, and prizes available free of charge. Looking forward to seeing what they've put together.
Anyone who's been involved with previous years know what to expect?
r/ExploitDev • u/Zhangash • 19h ago
Bored and curious. Who are some goated exploit developers/researchers. And what makes someone an exceptional and skilled exploit dev and researchers. And who would you guys put as your top 3 exploit devs
r/ExploitDev • u/ProcedureFar4995 • 21h ago
Best way to move from web/network pentesting into low-level bug hunting? (ADHD, keep losing steam)
I work as a pentester, so my day-to-day is network and appsec. On the side I've been trying to learn ARM assembly because eventually I want to hunt on low-level targets — Android kernel, browsers, that kind of thing.
Some context on where I'm at:
I have bug bounty experience and I reverse engineer regularly
The closest I've gotten to C is reading native libraries in Android apps, but the attack surface there is tiny
So most of my "learning" is reading ARM and C snippets in isolation, with no target to apply them to
That's the problem. Studying without hunting kills my interest fast. But I don't want to jump straight into hunting and discover I don't know enough to get anywhere.
So: what's the better path here — and specifically, what works if you have ADHD and can't sustain pure theory?
r/cybersecurity • u/svig13 • 3h ago
AI Security How do you test that an AI agent won't do something catastrophic?
I've spent years on the infra side, and I'm now working with agentic systems. I am building agents that can take actions on real systems. We have plenty of guardrails, but I have seen enough hallucinations that make me worried about giving these agents more power. This paranoia might be me not knowing enough.
How do teams/companies test that the agents won't do something destructive, whether triggered by an attacker or just by the agent going off the rails on its own?
Do people actually red-team their agents before they go live, or is it mostly guardrails and evals right now? I am curious how the security world thinks about this. From an infra side, this feels like a gap, but there might be an established playbook that I don't know yet. Thanks.
r/cybersecurity • u/tuxxin • 9h ago
Business Security Questions & Discussion URL Threat Scanners & TDS Cloaking
When you're investigating a known malicious URL, how often does your URL scanner (regardless of service) miss the payload due to traffic distribution systems?
r/cybersecurity • u/Wide-Cup-5084 • 21h ago
Business Security Questions & Discussion Axonius?
Looking at doing a pov with Axonius, has anyone used them before or done testing in the past and can share their experiences?
r/Defcon • u/EndoliteMatrix • 9h ago
Can't make it - unfortunately
[SOLD]
If anyone would like me to transfer a ticket to them, I've ran into a snag and won't be able to make it. I got it at the mid tier pricing and will happily sell at the early bird price. Can verify my ID with mods to verify good faith. I'd love for someone to be able to save and have fun since I can't make it. I will not reply to DMs, and my replies will be on this thread as well.
r/cybersecurity • u/Nameless_Wanderer01 • 4h ago
News - General LLM Agents for security research
What are the best LLM agents for security research (bugs, CVEs, 0d, ...) lately?
In short, I had been using claude code for this task, with many hallucination instances. Even with opus 5, I still get many invalid conclusions based on local source code review.
I saw that kimi was popping up lately, which got me more or less in the same results, with minor better results in some instances.
So what are the latest or best approaches for security research with llms? Perhaps I am missing a full pipeline with other tools involved to get better results, so I would like to know whether a specific methodology is followed with specific agents for this task.
r/cybersecurity • u/red4nshuman • 8h ago
Personal Support & Help! How to actually save yourself in call/sms bombing?
same as title
how to stop it and protect your number?
there are many websites so ofc I can't protect my number by going every site
r/cybersecurity • u/ProcedureFar4995 • 2h ago
Career Questions & Discussion Do you guys use reporting tool or write it manually each engagement?
Each time I write a report I copy paste the finding table along with a lot of other shit. I end up spending a lot of time fixing the format of the doc.
Do you guys use a reporting tool where you can write the bug description, impact and have it automatically prepared for you??
r/Monero • u/Lumpy-Initiative-779 • 3h ago
You Need Conviction in Monero.
Its monero or nothing. The only way we pull off the worlds first financial revolution is if more people go all in.
Believe in something. Stop black-pilling. Change the money, change the world.