Videos / Defcon

Defcon

146 videos

1 John Novak: 0-Day in Azure B2C and an Account Takeover Chain 40:13

John Novak: 0-Day in Azure B2C and an Account Takeover Chain

A DEF CON 31 talk on a chain of vulnerabilities in Microsoft Azure B2C that...

2 J. Hoffman & K. Morgan: Attacks on 1Password Local Security on macOS 38:50

J. Hoffman & K. Morgan: Attacks on 1Password Local Security on macOS

A DEF CON 32 talk on the security of the 1Password desktop app for macOS....

3 Emma Stewart: Choosing the Lesser Evil — Cybersecurity in the Clean Energy Transition 30:44

Emma Stewart: Choosing the Lesser Evil — Cybersecurity in the Clean Energy Transition

A DEF CON 32 talk where energy policy expert Emma Stewart examines cybersecurity risks in...

4 Dan Petro & David Vargas: Vulnerabilities in the OSDP Protocol for Access Control Systems 42:45

Dan Petro & David Vargas: Vulnerabilities in the OSDP Protocol for Access Control Systems

A DEF CON 31 talk on security issues in the OSDP protocol — a newer...

5 Melvin Langvik: Bypassing Modern Protections with QR Code Phishing 17:47

Melvin Langvik: Bypassing Modern Protections with QR Code Phishing

A DEF CON 32 talk where researcher Melvin Langvik explores phishing techniques using QR codes....

6 José Pico and Fernando Perera: Wireless Keystroke Injection via Bluetooth LE 37:06

José Pico and Fernando Perera: Wireless Keystroke Injection via Bluetooth LE

A DEF CON 30 talk about a vulnerability in Microsoft Windows that allows a remote...

7 Bill Demirkapi: Secrets and Shadows — Finding Vulnerabilities with Big Data 42:24

Bill Demirkapi: Secrets and Shadows — Finding Vulnerabilities with Big Data

A DEF CON 32 talk where security researcher Bill Demirkapi presents an alternative approach to...

8 Mauro Eldritch & Sibel Oliveira: Malicious Tokens — Using NFTs as Command-and-Control Infrastructure 21:40

Mauro Eldritch & Sibel Oliveira: Malicious Tokens — Using NFTs as Command-and-Control Infrastructure

A DEF CON 32 talk where researchers Mauro Eldritch and Sibel Oliveira demonstrate how NFTs...

9 stacksmashing: A Hacker’s Guide to Lightning and JTAG in iPhone 20:12

stacksmashing: A Hacker’s Guide to Lightning and JTAG in iPhone

A DEF CON 30 talk exploring the hidden capabilities of the iPhone’s Lightning port. Beyond...

10 Patrick Wardle: While You’re on Zoom — Your Mac Might Already Be Compromised 40:42

Patrick Wardle: While You’re on Zoom — Your Mac Might Already Be Compromised

A DEF CON 30 talk about critical vulnerabilities in the Zoom client for macOS that...

11 Slava Makkaveev: Hacking Xiaomi’s TEE and Attacking Mobile Payments 23:16

Slava Makkaveev: Hacking Xiaomi’s TEE and Attacking Mobile Payments

A DEF CON 30 talk examining the security of mobile payment systems on Xiaomi smartphones...

12 The History of XR: From Science Fiction to Reality 15:44

The History of XR: From Science Fiction to Reality

A DEF CON 31 discussion at XR Village on the evolution of extended reality (XR)...

13 Tony Sager: A Stranger in a Changed World — 35 Years of Cyber Defense at the NSA 29:20

Tony Sager: A Stranger in a Changed World — 35 Years of Cyber Defense at the NSA

A DEF CON 32 talk where cybersecurity veteran Tony Sager reflects on more than 35...

14 Samy Kamkar: Optical Spying — Eavesdropping on Keystrokes with Lasers 45:34

Samy Kamkar: Optical Spying — Eavesdropping on Keystrokes with Lasers

A DEF CON 32 talk where well-known security researcher Samy Kamkar demonstrates techniques of physical...

15 Cory Doctorow: How to Stop the Degradation of the Internet 45:42

Cory Doctorow: How to Stop the Degradation of the Internet

A DEF CON 31 talk on “enshittification” — the gradual decline of online platforms. According...

16 Ege Feyzioglu & Andrew M.: RFID 101 — Hacking Access Control Systems 20:55

Ege Feyzioglu & Andrew M.: RFID 101 — Hacking Access Control Systems

A DEF CON 32 talk where researchers Ege Feyzioglu and Andrew M. explain the fundamentals...

17 Lukas Roekaerts & Billy Graydon: Getting Fit for Physical Red Teaming 24:53

Lukas Roekaerts & Billy Graydon: Getting Fit for Physical Red Teaming

A DEF CON 32 talk where security professionals Lukas Roekaerts and Billy Graydon discuss physical...

18 Martin Doyhenard: When HTTP Breaks Everything — Attacking IPC in SAP 48:25

Martin Doyhenard: When HTTP Breaks Everything — Attacking IPC in SAP

A DEF CON 30 talk on reverse engineering SAP’s proprietary HTTP server and exploiting critical...

19 Squirer: GhostToken — Undeletable Trojan Apps in Google Cloud 23:44

Squirer: GhostToken — Undeletable Trojan Apps in Google Cloud

A DEF CON 31 talk on a 0-day vulnerability in Google Cloud Platform that allowed...

20 James Horsman and Zach Hanley: How to Find an RCE and Win $20K at Pwn2Own 37:03

James Horsman and Zach Hanley: How to Find an RCE and Win $20K at Pwn2Own

A talk about how basic vulnerabilities still go unnoticed in enterprise software. The speakers share...

21 Nils Amiet & Marco Maccetti: Polynonce — A New Attack on ECDSA 20:09

Nils Amiet & Marco Maccetti: Polynonce — A New Attack on ECDSA

A DEF CON 31 talk on a new attack against the ECDSA digital signature algorithm....

22 James Kettle: Browser-Powered Desync — A New Era of HTTP Request Smuggling 42:13

James Kettle: Browser-Powered Desync — A New Era of HTTP Request Smuggling

A DEF CON 30 talk about a new class of HTTP Request Smuggling attacks where...

23 Ken Munro: GPS Spoofing — It’s Not Just About Location, But Time 22:04

Ken Munro: GPS Spoofing — It’s Not Just About Location, But Time

A DEF CON 32 talk where security researcher Ken Munro highlights a lesser-known aspect of...

24 Taiiwo, Artorias, Puck & TheClockworkBird: Hacking Cicada 3301 41:57

Taiiwo, Artorias, Puck & TheClockworkBird: Hacking Cicada 3301

A DEF CON 31 talk about the community’s efforts to decrypt Liber Primus — a...

25 Ford & Reu: Attacks on Truck Diagnostic Adapters (VDA) 28:36

Ford & Reu: Attacks on Truck Diagnostic Adapters (VDA)

A DEF CON 31 talk on the security of Vehicle Diagnostics Adapters (VDA) — devices...

26 Hunters and Gatherers: A Close Look at the Bug Bounty World 56:36

Hunters and Gatherers: A Close Look at the Bug Bounty World

A DEF CON 32 panel where bug bounty program managers and security researchers discuss the...

27 Makriyiannis & Yomtov: Small Leaks — Big Losses 33:08

Makriyiannis & Yomtov: Small Leaks — Big Losses

A DEF CON 31 talk on the security of crypto wallets using Multi-Party Computation (MPC)...

28 Evie McGrady: Cybersecurity in School Education 23:34

Evie McGrady: Cybersecurity in School Education

A DEF CON 32 talk on the need to teach cybersecurity and digital privacy in...

29 Jayson E. Street: Social Engineering Like Picard 46:49

Jayson E. Street: Social Engineering Like Picard

A DEF CON 32 talk where social engineering expert Jayson E. Street shows how modern...

30 Minh Duong: The Big Rick — How I Rickrolled an Entire School District and Got Away With It 20:48

Minh Duong: The Big Rick — How I Rickrolled an Entire School District and Got Away With It

A DEF CON 30 talk about a massive rickroll prank that spread across six high...

31 punkcoder: Cybersecurity as a Labyrinth — Choose Your Own Adventure 27:18

punkcoder: Cybersecurity as a Labyrinth — Choose Your Own Adventure

A DEF CON 32 talk where the researcher known as punkcoder explores how cybersecurity has...

32 Gregory Carpenter: The Strong Adversary — And Why It’s Not About Sun Tzu 22:44

Gregory Carpenter: The Strong Adversary — And Why It’s Not About Sun Tzu

A DEF CON 32 talk where former NSA official Gregory Carpenter explores the strategic and...

33 Gal Zror: Hacking ISPs via PPPoE 39:18

Gal Zror: Hacking ISPs via PPPoE

A DEF CON 30 talk about a hidden attack surface in internet service provider infrastructure....

34 Cooper Quintin: How We Tracked Down the Dumbest Cyber Mercenaries in the World 20:30

Cooper Quintin: How We Tracked Down the Dumbest Cyber Mercenaries in the World

A talk by Cooper Quintin about investigating the cyber mercenary group known as Dark Caracal....

35 Adrian Dabrowski & Gabriel Gegenhuber: SIM Tunneling and Attacks on Mobile Networks 44:50

Adrian Dabrowski & Gabriel Gegenhuber: SIM Tunneling and Attacks on Mobile Networks

A DEF CON 31 talk on MobileAtlas — an open platform for mobile network research...

36 Winn Schwartau: My First Hack Was in 1958 37:35

Winn Schwartau: My First Hack Was in 1958

A DEF CON 30 talk about the early history of hacking — long before the...

37 Mikko Hyppönen: What Is It Like to Live Next to Russia 47:45

Mikko Hyppönen: What Is It Like to Live Next to Russia

A talk by Mikko Hyppönen on how Finland lived alongside Russia for decades — from...

38 Silvia Puglisi & Roger Dingledine: Measuring and Protecting the Tor Network 41:34

Silvia Puglisi & Roger Dingledine: Measuring and Protecting the Tor Network

A DEF CON 32 talk where Silvia Puglisi and Roger Dingledine explain how the Tor...

39 Christopher Panayi: Extracting Passwords from Microsoft Configuration Manager 54:28

Christopher Panayi: Extracting Passwords from Microsoft Configuration Manager

A DEF CON 30 talk about vulnerabilities in the system deployment process using Microsoft Endpoint...

40 Joseph Gabay: Hacking “Smart” Shopping Cart Wheels via RF Interception 38:23

Joseph Gabay: Hacking “Smart” Shopping Cart Wheels via RF Interception

A DEF CON 31 talk on the security of electronic shopping cart wheels used for...

41 Larry Pesce: SBOM the Hard Way — Hacking the Bob the Minion Router 20:53

Larry Pesce: SBOM the Hard Way — Hacking the Bob the Minion Router

A DEF CON 32 talk where security researcher Larry Pesce shows how to build a...

42 Octavio Gianatempo & Octavio Galland: Hidden Vulnerabilities in IoT Devices 39:15

Octavio Gianatempo & Octavio Galland: Hidden Vulnerabilities in IoT Devices

A DEF CON 30 talk about the hidden attack surface in consumer routers and other...

43 Tom Paul: Private Keys Hidden in Firmware and Software 40:05

Tom Paul: Private Keys Hidden in Firmware and Software

A DEF CON 31 talk on how private keys, certificates, and cryptographic secrets are often...

44 Marcello Salvati: Spoofing Emails from Over 2 Million Domains 37:22

Marcello Salvati: Spoofing Emails from Over 2 Million Domains

A DEF CON 31 talk on a critical vulnerability in email infrastructure. The researcher demonstrated...

45 Andrew Bellini: How to Hack Your First IoT Device — A Beginner’s Guide 54:11

Andrew Bellini: How to Hack Your First IoT Device — A Beginner’s Guide

A DEF CON 32 talk where security researcher Andrew Bellini explains how to get started...

46 Bar Attias: How Windows Defender Updates Can Become a Vulnerability 39:03

Bar Attias: How Windows Defender Updates Can Become a Vulnerability

A DEF CON 31 talk on a 0-day vulnerability in the Windows Defender signature update...

47 Aaditya Purani and Max Garrett: ElectroVolt — Pwning Popular Desktop Applications 44:47

Aaditya Purani and Max Garrett: ElectroVolt — Pwning Popular Desktop Applications

A DEF CON 30 talk on novel attack vectors targeting Electron applications that can lead...

48 Laurie Kirk: Runtime Manipulation in Android to Evade Analysis 41:58

Laurie Kirk: Runtime Manipulation in Android to Evade Analysis

A DEF CON 31 talk on a new Android obfuscation technique — runtime manipulation. This...

49 Tamas Jos: Passwordless Remote Authentication 45:01

Tamas Jos: Passwordless Remote Authentication

A DEF CON 31 talk introducing a new post-exploitation technique in Windows networks. It allows...

50 Joseph Ravichandran: PACMAN Attack — Breaking Apple M1 Protections 32:27

Joseph Ravichandran: PACMAN Attack — Breaking Apple M1 Protections

A DEF CON 30 talk about a novel hardware-software attack on Apple M1 processors. The...

51 Dennis Giese: Robot Vacuum Security — How to Protect Your Data 44:24

Dennis Giese: Robot Vacuum Security — How to Protect Your Data

The speaker demonstrates vulnerabilities in popular robot vacuum models and explains why device certifications do...

52 Jason Haddix: The Dark Side of Bug Bounty 32:29

Jason Haddix: The Dark Side of Bug Bounty

A talk by Jason Haddix about the behind-the-scenes realities of the bug bounty industry —...

53 Daniel Mess: “Shadow Librarian” — Resisting the Rise of Digital Capitalism 43:02

Daniel Mess: “Shadow Librarian” — Resisting the Rise of Digital Capitalism

A DEF CON 32 talk where librarian Daniel Mess discusses the challenges facing public libraries...

54 Tom Cross and Greg Conti: How to Defend Yourself in a World of Digital Deception 42:54

Tom Cross and Greg Conti: How to Defend Yourself in a World of Digital Deception

A DEF CON 32 talk on how the internet has evolved into a global engine...

55 Karl Koscher and Andrew Green: Hack the Hemisphere — Hacker Satellite Broadcasting 45:54

Karl Koscher and Andrew Green: Hack the Hemisphere — Hacker Satellite Broadcasting

A DEF CON 30 talk about an unusual experiment with satellite communications. After obtaining legal...

56 Sam Bent: Tor and OpSec in the Darknet — An Insider’s Perspective 48:28

Sam Bent: Tor and OpSec in the Darknet — An Insider’s Perspective

A talk by a former darknet vendor about applying hacker thinking to operational security within...

57 Ben Sadeghipour & Corben Leo: A Series of Unfortunate Events 34:08

Ben Sadeghipour & Corben Leo: A Series of Unfortunate Events

A DEF CON 31 talk featuring real-world hacking stories. The speakers share cases where they...

58 Mark Colaluca & Nick Saunders: Securing the KA-SAT Network After a Cyberattack 45:42

Mark Colaluca & Nick Saunders: Securing the KA-SAT Network After a Cyberattack

A DEF CON 31 talk on the cyberattack against Viasat’s KA-SAT satellite network in February...

59 Vangelis Stykas: Hacking Malware Command-and-Control Servers 35:05

Vangelis Stykas: Hacking Malware Command-and-Control Servers

A DEF CON 31 talk on compromising command-and-control (C2) servers used by malware. After malware...

60 Ryan Johnson, Mohamed Elsabagh & Angelos Stavrou: Android Phones Vulnerable Right Out of the Box 43:04

Ryan Johnson, Mohamed Elsabagh & Angelos Stavrou: Android Phones Vulnerable Right Out of the Box

A DEF CON 31 talk on the security of low-cost prepaid Android smartphones. Researchers analyzed...

61 Sam Curry: How I Hacked Millions of Modems — and Tried to Figure Out Who Hacked Mine 24:57

Sam Curry: How I Hacked Millions of Modems — and Tried to Figure Out Who Hacked Mine

A DEF CON 32 talk where security researcher Sam Curry describes how he discovered his...

62 James Pavur: Space Jam — Attacking Satellites via Radio Signals 36:05

James Pavur: Space Jam — Attacking Satellites via Radio Signals

A DEF CON 30 talk about the security of satellite communications — a critical component...

63 Miana Ella Windall: RFID Implants — When Your Middle Finger Opens Doors 44:34

Miana Ella Windall: RFID Implants — When Your Middle Finger Opens Doors

A DEF CON 31 talk about building implantable RFID chips. The speaker explains how she...

64 Richard Thieme: UFOs, Alien Life, and the Most Honest Version of the Truth 48:27

Richard Thieme: UFOs, Alien Life, and the Most Honest Version of the Truth

A DEF CON 30 talk about decades of research into the UFO phenomenon. The speaker...

65 Jeff Mann: The Evolution of Cryptography 23:41

Jeff Mann: The Evolution of Cryptography

A DEF CON 32 talk where security expert Jeff Mann explores how the meaning of...

66 Tiffany Rad & Austin Shamlin: Civilian Cyber Defense 29:49

Tiffany Rad & Austin Shamlin: Civilian Cyber Defense

A DEF CON 31 talk on how volunteers and students help protect human rights organizations,...

67 Michelle Eggers: The Immortal Retrofuturism of Mainframes — and How to Secure Them 25:46

Michelle Eggers: The Immortal Retrofuturism of Mainframes — and How to Secure Them

A DEF CON 32 talk where security expert Michelle Eggers explores the role of mainframes...

68 Aapo Oksman: certmitm — Automated Exploitation of TLS Certificate Validation Flaws 50:08

Aapo Oksman: certmitm — Automated Exploitation of TLS Certificate Validation Flaws

A DEF CON 31 talk on weaknesses in TLS certificate validation within client applications. Despite...

69 Chris Inglis & Kim Zetter: Cybersecurity and Public Policy 44:17

Chris Inglis & Kim Zetter: Cybersecurity and Public Policy

A DEF CON 30 panel featuring U.S. National Cyber Director Chris Inglis, moderated by journalist...

70 Wietze Beukema: Environment Variables as a Way to Hijack Legitimate Applications 41:51

Wietze Beukema: Environment Variables as a Way to Hijack Legitimate Applications

A DEF CON 30 talk on a stealthier alternative to classic DLL hijacking — abusing...

71 Ben Barnea and Ophir Harpaz: Ancient Protocols, Modern Bugs — Exploring MS-RPC 45:22

Ben Barnea and Ophir Harpaz: Ancient Protocols, Modern Bugs — Exploring MS-RPC

A DEF CON 30 talk about the security of MS-RPC, the Remote Procedure Call implementation...

72 Andrew Logan: Tracking “Ghost” Military Helicopters over Washington, D.C. 18:51

Andrew Logan: Tracking “Ghost” Military Helicopters over Washington, D.C.

A DEF CON 30 talk about efforts to make visible the flights of military and...

73 Daniel Bohannon & Sabajete Elezaj: MaLDAPtive — LDAP Obfuscation and De-Obfuscation 46:42

Daniel Bohannon & Sabajete Elezaj: MaLDAPtive — LDAP Obfuscation and De-Obfuscation

A DEF CON 32 talk on how attackers can hide malicious LDAP queries targeting Active...

74 David Leadbeater: 60 Years of Terminal Vulnerabilities 47:33

David Leadbeater: 60 Years of Terminal Vulnerabilities

A DEF CON 31 talk on the security of terminal emulators and escape sequences dating...

75 Vivek Ramachandran & Shourya Pratap Singh: Hidden Extensions — Bypassing Chrome MV3 Protections 20:30

Vivek Ramachandran & Shourya Pratap Singh: Hidden Extensions — Bypassing Chrome MV3 Protections

A DEF CON 32 talk where security researchers Vivek Ramachandran and Shourya Pratap Singh analyze...

76 Kemba Walden: U.S. Cyber Strategy and the Role of Hackers in Shaping It 50:17

Kemba Walden: U.S. Cyber Strategy and the Role of Hackers in Shaping It

A DEF CON 31 talk on the U.S. national cyber strategy and efforts to build...

77 Mickey Shkatov and Jesse Michael: One Bootloader to Rule Them All — Bypassing Secure Boot 52:21

Mickey Shkatov and Jesse Michael: One Bootloader to Rule Them All — Bypassing Secure Boot

A DEF CON 30 talk examining weaknesses in Secure Boot — the foundational trusted boot...

78 Gunnar Andrews: Effective Automation in Bug Bounty 22:06

Gunnar Andrews: Effective Automation in Bug Bounty

A DEF CON 32 talk on how automation helps bug bounty hunters find vulnerabilities faster...

79 Matt Domko: On-Demand AI Devices — Building AI with Privacy in Mind 40:47

Matt Domko: On-Demand AI Devices — Building AI with Privacy in Mind

A DEF CON 32 talk where Matt Domko discusses the challenges of building consumer AI...

80 Cult of the Dead Cow & Friends: Highlights from Hacker History — 40 Years of 31337 01:54:59

Cult of the Dead Cow & Friends: Highlights from Hacker History — 40 Years of 31337

A DEF CON 32 panel dedicated to the history of hacker culture from the 1980s...

81 Craig Martell: Shall We Play a Game? 47:08

Craig Martell: Shall We Play a Game?

A DEF CON 31 talk about the risks of over-relying on large language models. The...

82 Elad Pticha and Oreen Livni: Why Your CI/CD Pipeline Is Vulnerable — and It’s Not Your Fault 25:44

Elad Pticha and Oreen Livni: Why Your CI/CD Pipeline Is Vulnerable — and It’s Not Your Fault

A DEF CON 32 talk exploring how a single command injection vulnerability in a CI/CD...

83 Cory Doctorow, Christian Dameff, and Jeff Tully: Why Patients Should Hack Medical Technology 43:33

Cory Doctorow, Christian Dameff, and Jeff Tully: Why Patients Should Hack Medical Technology

A DEF CON 30 talk about the right of users to study, modify, and repair...

84 Daniel Beard: Hacking Air-Gapped Systems for $10 with Arduino 24:18

Daniel Beard: Hacking Air-Gapped Systems for $10 with Arduino

A DEF CON 32 talk where security engineer Daniel Beard demonstrates how to gain remote...

85 Michael Bargury: How to Take Over an Enterprise Through No-Code 40:07

Michael Bargury: How to Take Over an Enterprise Through No-Code

A DEF CON 30 talk on how low-code and no-code platforms are becoming the perfect...

86 Eugene Lim: You Have 1 New Invitation — Hacking Proprietary iCalendar Properties 33:39

Eugene Lim: You Have 1 New Invitation — Hacking Proprietary iCalendar Properties

A DEF CON 30 talk about hidden vulnerabilities in the iCalendar standard, which has been...

87 Roger Dingledine: How Russia Is Trying to Block Tor 47:26

Roger Dingledine: How Russia Is Trying to Block Tor

A DEF CON 30 talk about attempts to censor the Tor network in Russia. After...

88 Michael Bargury: No-Code Malware — Abusing Power Automate in Windows 11 32:12

Michael Bargury: No-Code Malware — Abusing Power Automate in Windows 11

A DEF CON 30 talk about how the built-in Windows 11 automation tool Power Automate...

89 Chloé Messdaghi & Kazimir Schulz: Challenges of Responsible Disclosure in AI Systems 40:06

Chloé Messdaghi & Kazimir Schulz: Challenges of Responsible Disclosure in AI Systems

A DEF CON 32 talk where researchers Chloé Messdaghi and Kazimir Schulz discuss the difficulties...

90 Angelina Tsuboi: A Raspberry Pi Device for Detecting Aircraft Signal Spoofing 20:01

Angelina Tsuboi: A Raspberry Pi Device for Detecting Aircraft Signal Spoofing

A DEF CON 32 talk on building a low-cost device called Fly Catcher to detect...

91 Andrew Brandt: You’re Not George Clooney, and This Isn’t Ocean’s Eleven 44:17

Andrew Brandt: You’re Not George Clooney, and This Isn’t Ocean’s Eleven

A DEF CON 31 talk about modern social engineering attacks. The speaker shares investigations of...

92 Nikhil Srivastava & Charlie Waterhouse: 10 Years in Bug Bounty 59:12

Nikhil Srivastava & Charlie Waterhouse: 10 Years in Bug Bounty

A DEF CON 32 talk where security researcher Nikhil Srivastava shares his decade-long journey in...

93 Paul Roberts: “Brazil” Today — The Right to Repair vs. Tech Dystopia 01:16:34

Paul Roberts: “Brazil” Today — The Right to Repair vs. Tech Dystopia

A DEF CON 30 talk about the Right to Repair movement and the fight for...

94 James Kettle: Race Condition Attacks in Web Applications 42:18

James Kettle: Race Condition Attacks in Web Applications

A DEF CON 31 talk on new types of race condition vulnerabilities in web applications....

95 ColdwaterQ: Backdooring Python Pickle — Why Things Got Worse Over the Last Decade 19:30

ColdwaterQ: Backdooring Python Pickle — Why Things Got Worse Over the Last Decade

A DEF CON 30 talk about the security risks of using the Python Pickle serialization...

96 Zachary Minneker: MUMPS After 30 Years — Legacy Language Vulnerabilities in Government Systems 42:54

Zachary Minneker: MUMPS After 30 Years — Legacy Language Vulnerabilities in Government Systems

A DEF CON 30 talk about the MUMPS programming language, originally developed in the 1960s...

97 Elonka Dunin & Klaus Schmeh: Encrypted Newspaper Ads of the 19th Century 44:14

Elonka Dunin & Klaus Schmeh: Encrypted Newspaper Ads of the 19th Century

A DEF CON 32 talk where researchers Elonka Dunin and Klaus Schmeh explore a unique...

98 Jonathan Leitschuh: Scaling Security Research to Fix Open-Source Vulnerabilities at Scale 44:20

Jonathan Leitschuh: Scaling Security Research to Fix Open-Source Vulnerabilities at Scale

A DEF CON 30 talk about automating the discovery and remediation of common vulnerabilities in...

99 Denis Smaylovich: An Introduction to IPv6 25:17

Denis Smaylovich: An Introduction to IPv6

A DEF CON 32 talk where security specialist Denis Smaylovich explains why the modern internet...

100 Jeffrey Hofmann: Pre-Auth RCE Chains in MDM — Full Compromise of KACE SMA 35:58

Jeffrey Hofmann: Pre-Auth RCE Chains in MDM — Full Compromise of KACE SMA

A DEF CON 30 talk covering three pre-authentication RCE chains in KACE Systems Management Appliance...

101 Pete Hea: Why Cybersecurity Analysts Need “Arts and Crafts” 43:39

Pete Hea: Why Cybersecurity Analysts Need “Arts and Crafts”

A DEF CON 31 talk on how visualization helps analyze cyber attacks. The speaker shows...

102 Jacob Baines: Do Not Trust the ASA — Vulnerabilities in Cisco Firewalls 36:04

Jacob Baines: Do Not Trust the ASA — Vulnerabilities in Cisco Firewalls

A DEF CON 30 talk about newly discovered vulnerabilities in Cisco ASA and ASA-X firewalls,...

103 Lennert Wouters: Hacking the Starlink Terminal 35:48

Lennert Wouters: Hacking the Starlink Terminal

A DEF CON 30 talk presenting the first hardware analysis of a Starlink user terminal....

104 Wojciech Reguła: Bypassing macOS Privacy via Electron Apps 19:54

Wojciech Reguła: Bypassing macOS Privacy via Electron Apps

A DEF CON 31 talk on bypassing macOS privacy protections through the TCC (Transparency, Consent,...

105 Daniel Jensen: Hunting Vulnerabilities in Aruba Networking Devices 43:22

Daniel Jensen: Hunting Vulnerabilities in Aruba Networking Devices

A DEF CON 30 talk about vulnerability research in enterprise networking products from Aruba Networks....

106 Diego Jurado & Joel Niemand Sec Noguera: Using AI to Improve Vulnerability Discovery 40:52

Diego Jurado & Joel Niemand Sec Noguera: Using AI to Improve Vulnerability Discovery

A DEF CON 32 talk where researchers Diego Jurado and Joel Niemand Sec Noguera show...

107 Michael Gorelik & Arnold Osipov: Outlook RCE Chaos — CVE-2024-30103 41:09

Michael Gorelik & Arnold Osipov: Outlook RCE Chaos — CVE-2024-30103

A DEF CON 32 talk where researchers Michael Gorelik and Arnold Osipov present a series...

108 Joseph Cox: Inside the FBI’s Secret Encrypted Phone Network Anom 39:23

Joseph Cox: Inside the FBI’s Secret Encrypted Phone Network Anom

A DEF CON 32 talk where journalist and cybercrime researcher Joseph Cox рассказывает историю мессенджера...

109 Bill Woodcock: The Internet and Sanctions — Russia, Ukraine, and the Future of the Network 46:07

Bill Woodcock: The Internet and Sanctions — Russia, Ukraine, and the Future of the Network

A DEF CON 30 talk about the role of the internet in international sanctions following...

110 Justin Reineiter Gardner: Best Stories from a Bug Bounty Hunter 50:37

Justin Reineiter Gardner: Best Stories from a Bug Bounty Hunter

A DEF CON 32 talk where security researcher Justin Reineiter Gardner shares real-world stories from...

111 Patrick Wardle: How macOS Background Task Management Works — and How It’s Bypassed 49:07

Patrick Wardle: How macOS Background Task Management Works — and How It’s Bypassed

A DEF CON 31 talk about a new macOS Ventura security feature that monitors persistence...

112 Bill Graydon: Bypassing Moving Elements in High-Security Keys 45:44

Bill Graydon: Bypassing Moving Elements in High-Security Keys

A DEF CON 30 talk on a new trend in the lock industry — adding...

113 Nikita Kurtin: Bypassing All Android Permission Levels 32:20

Nikita Kurtin: Bypassing All Android Permission Levels

A DEF CON 30 talk exploring systemic ways to bypass Android’s permission model — from...

114 Moritz Abrell: Phreaking 2.0 — Abusing Microsoft Teams Direct Routing 20:48

Moritz Abrell: Phreaking 2.0 — Abusing Microsoft Teams Direct Routing

A DEF CON 30 talk about vulnerabilities in Microsoft Teams’ Direct Routing feature, which allows...

115 Anthony Kawa: Solving the “Lover, Stalker, Killer” Murder 21:56

Anthony Kawa: Solving the “Lover, Stalker, Killer” Murder

A DEF CON 32 talk where digital forensics expert Anthony Kawa explains how investigators solved...

116 Dagan Henderson and Will Kline: The Threat Inside the Cluster — Common Kubernetes Vulnerabilities 37:33

Dagan Henderson and Will Kline: The Threat Inside the Cluster — Common Kubernetes Vulnerabilities

A DEF CON 30 talk about common security flaws in the Kubernetes ecosystem. No 0-days...

117 Yolan Romailler: A “Dead Man’s” Responsible Disclosure System 43:43

Yolan Romailler: A “Dead Man’s” Responsible Disclosure System

A DEF CON 30 talk introducing a new model of responsible disclosure based on timelock...

118 Yisroel Mirsky: Your AI Assistant Has a Big Mouth 39:58

Yisroel Mirsky: Your AI Assistant Has a Big Mouth

A DEF CON 32 talk on a new side-channel vulnerability affecting popular AI assistants. The...

119 Harriet Farlow: Hackers vs AI — A Former Intelligence Officer’s Perspective 40:38

Harriet Farlow: Hackers vs AI — A Former Intelligence Officer’s Perspective

A DEF CON 32 talk where former intelligence officer Harriet Farlow explores the intersection of...

120 Bertocchi, Campbell, Gibson & Harris: Infinite Money Glitch — Hacking Transit Cards 45:04

Bertocchi, Campbell, Gibson & Harris: Infinite Money Glitch — Hacking Transit Cards

A DEF CON 31 talk about reverse engineering Boston’s subway payment system. Four students analyzed...

121 Samuel Erb and Justin Gardner: Crossing the KASM — A Pentest Story 32:06

Samuel Erb and Justin Gardner: Crossing the KASM — A Pentest Story

A DEF CON 30 talk about how a seemingly hardened bug bounty target — KASM...

122 Marc Faudi: How Voice Cloning Bypasses Voice Authentication Systems 25:35

Marc Faudi: How Voice Cloning Bypasses Voice Authentication Systems

A DEF CON 32 talk where researcher Marc Faudi demonstrates how neural network–based voice cloning...

123 Sam Quinn and Steve Povolny: Hacking an Access Control System 43:09

Sam Quinn and Steve Povolny: Hacking an Access Control System

A DEF CON 30 talk about compromising the HID Mercury networked physical access control system,...

124 Pete Stegemeyer: What the Biggest Heist in History Teaches Us 29:47

Pete Stegemeyer: What the Biggest Heist in History Teaches Us

A DEF CON 32 talk where security expert Pete Stegemeyer analyzes the 2003 Antwerp diamond...

125 Ionut Cernica: De-anonymizing HTTP Services on Tor 18:12

Ionut Cernica: De-anonymizing HTTP Services on Tor

A DEF CON 30 talk about techniques for de-anonymizing hidden web services on the Tor...

126 Global Challenges and Different Approaches to Cyber Policy 46:10

Global Challenges and Different Approaches to Cyber Policy

A DEF CON 30 panel discussion on how different countries shape their cybersecurity policies. Despite...

127 Christopher Wade: Physical Attacks on Modern Android Smartphones 37:00

Christopher Wade: Physical Attacks on Modern Android Smartphones

A DEF CON 31 talk on vulnerabilities that still exist in modern Android devices despite...

128 RenderMan & Tom Dang: The Risks of Telling the Truth About Vulnerabilities 46:02

RenderMan & Tom Dang: The Risks of Telling the Truth About Vulnerabilities

A DEF CON 31 talk about the challenges of disclosing vulnerabilities in government systems. Despite...

129 nyxgeek: Tracking Users in the Azure Ecosystem 31:55

nyxgeek: Tracking Users in the Azure Ecosystem

A DEF CON 31 talk exploring how Microsoft Azure services can expose user information. The...

130 Kyle Avery: Evading Memory Scanners — Bypassing YARA and PE-sieve 43:33

Kyle Avery: Evading Memory Scanners — Bypassing YARA and PE-sieve

A DEF CON 30 talk about techniques for evading memory analysis tools used by antivirus...

131 Hadrien Barral: Emoji Shellcoding 43:28

Hadrien Barral: Emoji Shellcoding

A DEF CON 30 talk about an unusual approach to writing shellcode — using only...

132 Gal Zror: Look Mom — I’m the CEO 20:52

Gal Zror: Look Mom — I’m the CEO

A DEF CON 31 talk on real-time deepfake capabilities. The researcher demonstrates how, using open-source...

133 Tracy Mosley: The Evolution of Mobile Networks — from 2G to 5G 43:27

Tracy Mosley: The Evolution of Mobile Networks — from 2G to 5G

A talk by Tracy Mosley on how mobile networks have evolved — from 2G to...

134 Javan Rasokat and Andra Lezza: Lessons from Building and Defending LLM Applications 27:04

Javan Rasokat and Andra Lezza: Lessons from Building and Defending LLM Applications

A DEF CON 32 talk on real-world experience developing and securing applications powered by large...

135 Nick Powers and Steven Flores: ClickOnce as a Trusted Code Execution Vector 44:24

Nick Powers and Steven Flores: ClickOnce as a Trusted Code Execution Vector

A DEF CON 30 talk exploring ClickOnce as an underused yet powerful initial access technique....

136 Jen Easterly: What Run-DMC and Aerosmith Can Teach Cybersecurity 55:00

Jen Easterly: What Run-DMC and Aerosmith Can Teach Cybersecurity

A DEF CON 30 talk about how unexpected partnerships can reshape entire industries. The speaker...

137 Paul Gerste: SQL Injection Isn’t Dead — Protocol-Level Injection Attacks 38:13

Paul Gerste: SQL Injection Isn’t Dead — Protocol-Level Injection Attacks

A DEF CON 32 talk where security researcher Paul Gerste presents a new approach to...

138 Policy Dept DEF CON: Hackers and Policy — Why It Matters 59:45

Policy Dept DEF CON: Hackers and Policy — Why It Matters

A DEF CON 30 talk about the role of the hacker community in shaping public...

139 Suha Hussein: Injecting Backdoors into ML Pipelines via Input Handling Flaws 29:41

Suha Hussein: Injecting Backdoors into ML Pipelines via Input Handling Flaws

A DEF CON 32 talk where security researcher Suha Hussein presents a new class of...

140 Elonka Dunin & Klaus Schmeh: Famous and Lesser-Known Unsolved Codes 49:30

Elonka Dunin & Klaus Schmeh: Famous and Lesser-Known Unsolved Codes

A DEF CON 32 talk where cryptography researchers Elonka Dunin and Klaus Schmeh explore famous...

141 Allison Young & Diane Ackerman: Your Data Is Private… Until Law Enforcement Wants It 44:49

Allison Young & Diane Ackerman: Your Data Is Private… Until Law Enforcement Wants It

A DEF CON 31 talk on how personal data from smartphones can be used by...

142 Joe Sullivan: Another Version of the Uber Incident 49:19

Joe Sullivan: Another Version of the Uber Incident

A DEF CON 31 talk about the 2016 Uber breach and the subsequent criminal case...

143 Sharon Brizinov: Evil PLC — Turning Industrial Controllers into Weapons 22:21

Sharon Brizinov: Evil PLC — Turning Industrial Controllers into Weapons

A DEF CON 30 talk introducing a new attack technique against industrial systems — Evil...

144 Lukas McCullough: OSINT — Reconnaissance Before Stepping on Site 15:42

Lukas McCullough: OSINT — Reconnaissance Before Stepping on Site

A DEF CON 32 talk on how to gather intelligence about people and locations using...

145 Hackers, Lawyers, and the Security Research Legal Defense Fund 43:35

Hackers, Lawyers, and the Security Research Legal Defense Fund

A DEF CON 31 panel discussing the legal risks faced by security researchers. Speakers share...

146 Alexey: Meduza vs Censorship — How Independent Media Bypasses Kremlin Blocks 33:34

Alexey: Meduza vs Censorship — How Independent Media Bypasses Kremlin Blocks

A DEF CON 31 talk on how the independent outlet Meduza continues to operate and...