Defcon
146 videos
John Novak: 0-Day in Azure B2C and an Account Takeover Chain
A DEF CON 31 talk on a chain of vulnerabilities in Microsoft Azure B2C that...
J. Hoffman & K. Morgan: Attacks on 1Password Local Security on macOS
A DEF CON 32 talk on the security of the 1Password desktop app for macOS....
Emma Stewart: Choosing the Lesser Evil — Cybersecurity in the Clean Energy Transition
A DEF CON 32 talk where energy policy expert Emma Stewart examines cybersecurity risks in...
Dan Petro & David Vargas: Vulnerabilities in the OSDP Protocol for Access Control Systems
A DEF CON 31 talk on security issues in the OSDP protocol — a newer...
Melvin Langvik: Bypassing Modern Protections with QR Code Phishing
A DEF CON 32 talk where researcher Melvin Langvik explores phishing techniques using QR codes....
José Pico and Fernando Perera: Wireless Keystroke Injection via Bluetooth LE
A DEF CON 30 talk about a vulnerability in Microsoft Windows that allows a remote...
Bill Demirkapi: Secrets and Shadows — Finding Vulnerabilities with Big Data
A DEF CON 32 talk where security researcher Bill Demirkapi presents an alternative approach to...
Mauro Eldritch & Sibel Oliveira: Malicious Tokens — Using NFTs as Command-and-Control Infrastructure
A DEF CON 32 talk where researchers Mauro Eldritch and Sibel Oliveira demonstrate how NFTs...
stacksmashing: A Hacker’s Guide to Lightning and JTAG in iPhone
A DEF CON 30 talk exploring the hidden capabilities of the iPhone’s Lightning port. Beyond...
Patrick Wardle: While You’re on Zoom — Your Mac Might Already Be Compromised
A DEF CON 30 talk about critical vulnerabilities in the Zoom client for macOS that...
Slava Makkaveev: Hacking Xiaomi’s TEE and Attacking Mobile Payments
A DEF CON 30 talk examining the security of mobile payment systems on Xiaomi smartphones...
The History of XR: From Science Fiction to Reality
A DEF CON 31 discussion at XR Village on the evolution of extended reality (XR)...
Tony Sager: A Stranger in a Changed World — 35 Years of Cyber Defense at the NSA
A DEF CON 32 talk where cybersecurity veteran Tony Sager reflects on more than 35...
Samy Kamkar: Optical Spying — Eavesdropping on Keystrokes with Lasers
A DEF CON 32 talk where well-known security researcher Samy Kamkar demonstrates techniques of physical...
Cory Doctorow: How to Stop the Degradation of the Internet
A DEF CON 31 talk on “enshittification” — the gradual decline of online platforms. According...
Ege Feyzioglu & Andrew M.: RFID 101 — Hacking Access Control Systems
A DEF CON 32 talk where researchers Ege Feyzioglu and Andrew M. explain the fundamentals...
Lukas Roekaerts & Billy Graydon: Getting Fit for Physical Red Teaming
A DEF CON 32 talk where security professionals Lukas Roekaerts and Billy Graydon discuss physical...
Martin Doyhenard: When HTTP Breaks Everything — Attacking IPC in SAP
A DEF CON 30 talk on reverse engineering SAP’s proprietary HTTP server and exploiting critical...
Squirer: GhostToken — Undeletable Trojan Apps in Google Cloud
A DEF CON 31 talk on a 0-day vulnerability in Google Cloud Platform that allowed...
James Horsman and Zach Hanley: How to Find an RCE and Win $20K at Pwn2Own
A talk about how basic vulnerabilities still go unnoticed in enterprise software. The speakers share...
Nils Amiet & Marco Maccetti: Polynonce — A New Attack on ECDSA
A DEF CON 31 talk on a new attack against the ECDSA digital signature algorithm....
James Kettle: Browser-Powered Desync — A New Era of HTTP Request Smuggling
A DEF CON 30 talk about a new class of HTTP Request Smuggling attacks where...
Ken Munro: GPS Spoofing — It’s Not Just About Location, But Time
A DEF CON 32 talk where security researcher Ken Munro highlights a lesser-known aspect of...
Taiiwo, Artorias, Puck & TheClockworkBird: Hacking Cicada 3301
A DEF CON 31 talk about the community’s efforts to decrypt Liber Primus — a...
Ford & Reu: Attacks on Truck Diagnostic Adapters (VDA)
A DEF CON 31 talk on the security of Vehicle Diagnostics Adapters (VDA) — devices...
Hunters and Gatherers: A Close Look at the Bug Bounty World
A DEF CON 32 panel where bug bounty program managers and security researchers discuss the...
Makriyiannis & Yomtov: Small Leaks — Big Losses
A DEF CON 31 talk on the security of crypto wallets using Multi-Party Computation (MPC)...
Evie McGrady: Cybersecurity in School Education
A DEF CON 32 talk on the need to teach cybersecurity and digital privacy in...
Jayson E. Street: Social Engineering Like Picard
A DEF CON 32 talk where social engineering expert Jayson E. Street shows how modern...
Minh Duong: The Big Rick — How I Rickrolled an Entire School District and Got Away With It
A DEF CON 30 talk about a massive rickroll prank that spread across six high...
punkcoder: Cybersecurity as a Labyrinth — Choose Your Own Adventure
A DEF CON 32 talk where the researcher known as punkcoder explores how cybersecurity has...
Gregory Carpenter: The Strong Adversary — And Why It’s Not About Sun Tzu
A DEF CON 32 talk where former NSA official Gregory Carpenter explores the strategic and...
Gal Zror: Hacking ISPs via PPPoE
A DEF CON 30 talk about a hidden attack surface in internet service provider infrastructure....
Cooper Quintin: How We Tracked Down the Dumbest Cyber Mercenaries in the World
A talk by Cooper Quintin about investigating the cyber mercenary group known as Dark Caracal....
Adrian Dabrowski & Gabriel Gegenhuber: SIM Tunneling and Attacks on Mobile Networks
A DEF CON 31 talk on MobileAtlas — an open platform for mobile network research...
Winn Schwartau: My First Hack Was in 1958
A DEF CON 30 talk about the early history of hacking — long before the...
Mikko Hyppönen: What Is It Like to Live Next to Russia
A talk by Mikko Hyppönen on how Finland lived alongside Russia for decades — from...
Silvia Puglisi & Roger Dingledine: Measuring and Protecting the Tor Network
A DEF CON 32 talk where Silvia Puglisi and Roger Dingledine explain how the Tor...
Christopher Panayi: Extracting Passwords from Microsoft Configuration Manager
A DEF CON 30 talk about vulnerabilities in the system deployment process using Microsoft Endpoint...
Joseph Gabay: Hacking “Smart” Shopping Cart Wheels via RF Interception
A DEF CON 31 talk on the security of electronic shopping cart wheels used for...
Larry Pesce: SBOM the Hard Way — Hacking the Bob the Minion Router
A DEF CON 32 talk where security researcher Larry Pesce shows how to build a...
Octavio Gianatempo & Octavio Galland: Hidden Vulnerabilities in IoT Devices
A DEF CON 30 talk about the hidden attack surface in consumer routers and other...
Tom Paul: Private Keys Hidden in Firmware and Software
A DEF CON 31 talk on how private keys, certificates, and cryptographic secrets are often...
Marcello Salvati: Spoofing Emails from Over 2 Million Domains
A DEF CON 31 talk on a critical vulnerability in email infrastructure. The researcher demonstrated...
Andrew Bellini: How to Hack Your First IoT Device — A Beginner’s Guide
A DEF CON 32 talk where security researcher Andrew Bellini explains how to get started...
Bar Attias: How Windows Defender Updates Can Become a Vulnerability
A DEF CON 31 talk on a 0-day vulnerability in the Windows Defender signature update...
Aaditya Purani and Max Garrett: ElectroVolt — Pwning Popular Desktop Applications
A DEF CON 30 talk on novel attack vectors targeting Electron applications that can lead...
Laurie Kirk: Runtime Manipulation in Android to Evade Analysis
A DEF CON 31 talk on a new Android obfuscation technique — runtime manipulation. This...
Tamas Jos: Passwordless Remote Authentication
A DEF CON 31 talk introducing a new post-exploitation technique in Windows networks. It allows...
Joseph Ravichandran: PACMAN Attack — Breaking Apple M1 Protections
A DEF CON 30 talk about a novel hardware-software attack on Apple M1 processors. The...
Dennis Giese: Robot Vacuum Security — How to Protect Your Data
The speaker demonstrates vulnerabilities in popular robot vacuum models and explains why device certifications do...
Jason Haddix: The Dark Side of Bug Bounty
A talk by Jason Haddix about the behind-the-scenes realities of the bug bounty industry —...
Daniel Mess: “Shadow Librarian” — Resisting the Rise of Digital Capitalism
A DEF CON 32 talk where librarian Daniel Mess discusses the challenges facing public libraries...
Tom Cross and Greg Conti: How to Defend Yourself in a World of Digital Deception
A DEF CON 32 talk on how the internet has evolved into a global engine...
Karl Koscher and Andrew Green: Hack the Hemisphere — Hacker Satellite Broadcasting
A DEF CON 30 talk about an unusual experiment with satellite communications. After obtaining legal...
Sam Bent: Tor and OpSec in the Darknet — An Insider’s Perspective
A talk by a former darknet vendor about applying hacker thinking to operational security within...
Ben Sadeghipour & Corben Leo: A Series of Unfortunate Events
A DEF CON 31 talk featuring real-world hacking stories. The speakers share cases where they...
Mark Colaluca & Nick Saunders: Securing the KA-SAT Network After a Cyberattack
A DEF CON 31 talk on the cyberattack against Viasat’s KA-SAT satellite network in February...
Vangelis Stykas: Hacking Malware Command-and-Control Servers
A DEF CON 31 talk on compromising command-and-control (C2) servers used by malware. After malware...
Ryan Johnson, Mohamed Elsabagh & Angelos Stavrou: Android Phones Vulnerable Right Out of the Box
A DEF CON 31 talk on the security of low-cost prepaid Android smartphones. Researchers analyzed...
Sam Curry: How I Hacked Millions of Modems — and Tried to Figure Out Who Hacked Mine
A DEF CON 32 talk where security researcher Sam Curry describes how he discovered his...
James Pavur: Space Jam — Attacking Satellites via Radio Signals
A DEF CON 30 talk about the security of satellite communications — a critical component...
Miana Ella Windall: RFID Implants — When Your Middle Finger Opens Doors
A DEF CON 31 talk about building implantable RFID chips. The speaker explains how she...
Richard Thieme: UFOs, Alien Life, and the Most Honest Version of the Truth
A DEF CON 30 talk about decades of research into the UFO phenomenon. The speaker...
Jeff Mann: The Evolution of Cryptography
A DEF CON 32 talk where security expert Jeff Mann explores how the meaning of...
Tiffany Rad & Austin Shamlin: Civilian Cyber Defense
A DEF CON 31 talk on how volunteers and students help protect human rights organizations,...
Michelle Eggers: The Immortal Retrofuturism of Mainframes — and How to Secure Them
A DEF CON 32 talk where security expert Michelle Eggers explores the role of mainframes...
Aapo Oksman: certmitm — Automated Exploitation of TLS Certificate Validation Flaws
A DEF CON 31 talk on weaknesses in TLS certificate validation within client applications. Despite...
Chris Inglis & Kim Zetter: Cybersecurity and Public Policy
A DEF CON 30 panel featuring U.S. National Cyber Director Chris Inglis, moderated by journalist...
Wietze Beukema: Environment Variables as a Way to Hijack Legitimate Applications
A DEF CON 30 talk on a stealthier alternative to classic DLL hijacking — abusing...
Ben Barnea and Ophir Harpaz: Ancient Protocols, Modern Bugs — Exploring MS-RPC
A DEF CON 30 talk about the security of MS-RPC, the Remote Procedure Call implementation...
Andrew Logan: Tracking “Ghost” Military Helicopters over Washington, D.C.
A DEF CON 30 talk about efforts to make visible the flights of military and...
Daniel Bohannon & Sabajete Elezaj: MaLDAPtive — LDAP Obfuscation and De-Obfuscation
A DEF CON 32 talk on how attackers can hide malicious LDAP queries targeting Active...
David Leadbeater: 60 Years of Terminal Vulnerabilities
A DEF CON 31 talk on the security of terminal emulators and escape sequences dating...
Vivek Ramachandran & Shourya Pratap Singh: Hidden Extensions — Bypassing Chrome MV3 Protections
A DEF CON 32 talk where security researchers Vivek Ramachandran and Shourya Pratap Singh analyze...
Kemba Walden: U.S. Cyber Strategy and the Role of Hackers in Shaping It
A DEF CON 31 talk on the U.S. national cyber strategy and efforts to build...
Mickey Shkatov and Jesse Michael: One Bootloader to Rule Them All — Bypassing Secure Boot
A DEF CON 30 talk examining weaknesses in Secure Boot — the foundational trusted boot...
Gunnar Andrews: Effective Automation in Bug Bounty
A DEF CON 32 talk on how automation helps bug bounty hunters find vulnerabilities faster...
Matt Domko: On-Demand AI Devices — Building AI with Privacy in Mind
A DEF CON 32 talk where Matt Domko discusses the challenges of building consumer AI...
Cult of the Dead Cow & Friends: Highlights from Hacker History — 40 Years of 31337
A DEF CON 32 panel dedicated to the history of hacker culture from the 1980s...
Craig Martell: Shall We Play a Game?
A DEF CON 31 talk about the risks of over-relying on large language models. The...
Elad Pticha and Oreen Livni: Why Your CI/CD Pipeline Is Vulnerable — and It’s Not Your Fault
A DEF CON 32 talk exploring how a single command injection vulnerability in a CI/CD...
Cory Doctorow, Christian Dameff, and Jeff Tully: Why Patients Should Hack Medical Technology
A DEF CON 30 talk about the right of users to study, modify, and repair...
Daniel Beard: Hacking Air-Gapped Systems for $10 with Arduino
A DEF CON 32 talk where security engineer Daniel Beard demonstrates how to gain remote...
Michael Bargury: How to Take Over an Enterprise Through No-Code
A DEF CON 30 talk on how low-code and no-code platforms are becoming the perfect...
Eugene Lim: You Have 1 New Invitation — Hacking Proprietary iCalendar Properties
A DEF CON 30 talk about hidden vulnerabilities in the iCalendar standard, which has been...
Roger Dingledine: How Russia Is Trying to Block Tor
A DEF CON 30 talk about attempts to censor the Tor network in Russia. After...
Michael Bargury: No-Code Malware — Abusing Power Automate in Windows 11
A DEF CON 30 talk about how the built-in Windows 11 automation tool Power Automate...
Chloé Messdaghi & Kazimir Schulz: Challenges of Responsible Disclosure in AI Systems
A DEF CON 32 talk where researchers Chloé Messdaghi and Kazimir Schulz discuss the difficulties...
Angelina Tsuboi: A Raspberry Pi Device for Detecting Aircraft Signal Spoofing
A DEF CON 32 talk on building a low-cost device called Fly Catcher to detect...
Andrew Brandt: You’re Not George Clooney, and This Isn’t Ocean’s Eleven
A DEF CON 31 talk about modern social engineering attacks. The speaker shares investigations of...
Nikhil Srivastava & Charlie Waterhouse: 10 Years in Bug Bounty
A DEF CON 32 talk where security researcher Nikhil Srivastava shares his decade-long journey in...
Paul Roberts: “Brazil” Today — The Right to Repair vs. Tech Dystopia
A DEF CON 30 talk about the Right to Repair movement and the fight for...
James Kettle: Race Condition Attacks in Web Applications
A DEF CON 31 talk on new types of race condition vulnerabilities in web applications....
ColdwaterQ: Backdooring Python Pickle — Why Things Got Worse Over the Last Decade
A DEF CON 30 talk about the security risks of using the Python Pickle serialization...
Zachary Minneker: MUMPS After 30 Years — Legacy Language Vulnerabilities in Government Systems
A DEF CON 30 talk about the MUMPS programming language, originally developed in the 1960s...
Elonka Dunin & Klaus Schmeh: Encrypted Newspaper Ads of the 19th Century
A DEF CON 32 talk where researchers Elonka Dunin and Klaus Schmeh explore a unique...
Jonathan Leitschuh: Scaling Security Research to Fix Open-Source Vulnerabilities at Scale
A DEF CON 30 talk about automating the discovery and remediation of common vulnerabilities in...
Denis Smaylovich: An Introduction to IPv6
A DEF CON 32 talk where security specialist Denis Smaylovich explains why the modern internet...
Jeffrey Hofmann: Pre-Auth RCE Chains in MDM — Full Compromise of KACE SMA
A DEF CON 30 talk covering three pre-authentication RCE chains in KACE Systems Management Appliance...
Pete Hea: Why Cybersecurity Analysts Need “Arts and Crafts”
A DEF CON 31 talk on how visualization helps analyze cyber attacks. The speaker shows...
Jacob Baines: Do Not Trust the ASA — Vulnerabilities in Cisco Firewalls
A DEF CON 30 talk about newly discovered vulnerabilities in Cisco ASA and ASA-X firewalls,...
Lennert Wouters: Hacking the Starlink Terminal
A DEF CON 30 talk presenting the first hardware analysis of a Starlink user terminal....
Wojciech Reguła: Bypassing macOS Privacy via Electron Apps
A DEF CON 31 talk on bypassing macOS privacy protections through the TCC (Transparency, Consent,...
Daniel Jensen: Hunting Vulnerabilities in Aruba Networking Devices
A DEF CON 30 talk about vulnerability research in enterprise networking products from Aruba Networks....
Diego Jurado & Joel Niemand Sec Noguera: Using AI to Improve Vulnerability Discovery
A DEF CON 32 talk where researchers Diego Jurado and Joel Niemand Sec Noguera show...
Michael Gorelik & Arnold Osipov: Outlook RCE Chaos — CVE-2024-30103
A DEF CON 32 talk where researchers Michael Gorelik and Arnold Osipov present a series...
Joseph Cox: Inside the FBI’s Secret Encrypted Phone Network Anom
A DEF CON 32 talk where journalist and cybercrime researcher Joseph Cox рассказывает историю мессенджера...
Bill Woodcock: The Internet and Sanctions — Russia, Ukraine, and the Future of the Network
A DEF CON 30 talk about the role of the internet in international sanctions following...
Justin Reineiter Gardner: Best Stories from a Bug Bounty Hunter
A DEF CON 32 talk where security researcher Justin Reineiter Gardner shares real-world stories from...
Patrick Wardle: How macOS Background Task Management Works — and How It’s Bypassed
A DEF CON 31 talk about a new macOS Ventura security feature that monitors persistence...
Bill Graydon: Bypassing Moving Elements in High-Security Keys
A DEF CON 30 talk on a new trend in the lock industry — adding...
Nikita Kurtin: Bypassing All Android Permission Levels
A DEF CON 30 talk exploring systemic ways to bypass Android’s permission model — from...
Moritz Abrell: Phreaking 2.0 — Abusing Microsoft Teams Direct Routing
A DEF CON 30 talk about vulnerabilities in Microsoft Teams’ Direct Routing feature, which allows...
Anthony Kawa: Solving the “Lover, Stalker, Killer” Murder
A DEF CON 32 talk where digital forensics expert Anthony Kawa explains how investigators solved...
Dagan Henderson and Will Kline: The Threat Inside the Cluster — Common Kubernetes Vulnerabilities
A DEF CON 30 talk about common security flaws in the Kubernetes ecosystem. No 0-days...
Yolan Romailler: A “Dead Man’s” Responsible Disclosure System
A DEF CON 30 talk introducing a new model of responsible disclosure based on timelock...
Yisroel Mirsky: Your AI Assistant Has a Big Mouth
A DEF CON 32 talk on a new side-channel vulnerability affecting popular AI assistants. The...
Harriet Farlow: Hackers vs AI — A Former Intelligence Officer’s Perspective
A DEF CON 32 talk where former intelligence officer Harriet Farlow explores the intersection of...
Bertocchi, Campbell, Gibson & Harris: Infinite Money Glitch — Hacking Transit Cards
A DEF CON 31 talk about reverse engineering Boston’s subway payment system. Four students analyzed...
Samuel Erb and Justin Gardner: Crossing the KASM — A Pentest Story
A DEF CON 30 talk about how a seemingly hardened bug bounty target — KASM...
Marc Faudi: How Voice Cloning Bypasses Voice Authentication Systems
A DEF CON 32 talk where researcher Marc Faudi demonstrates how neural network–based voice cloning...
Sam Quinn and Steve Povolny: Hacking an Access Control System
A DEF CON 30 talk about compromising the HID Mercury networked physical access control system,...
Pete Stegemeyer: What the Biggest Heist in History Teaches Us
A DEF CON 32 talk where security expert Pete Stegemeyer analyzes the 2003 Antwerp diamond...
Ionut Cernica: De-anonymizing HTTP Services on Tor
A DEF CON 30 talk about techniques for de-anonymizing hidden web services on the Tor...
Global Challenges and Different Approaches to Cyber Policy
A DEF CON 30 panel discussion on how different countries shape their cybersecurity policies. Despite...
Christopher Wade: Physical Attacks on Modern Android Smartphones
A DEF CON 31 talk on vulnerabilities that still exist in modern Android devices despite...
RenderMan & Tom Dang: The Risks of Telling the Truth About Vulnerabilities
A DEF CON 31 talk about the challenges of disclosing vulnerabilities in government systems. Despite...
nyxgeek: Tracking Users in the Azure Ecosystem
A DEF CON 31 talk exploring how Microsoft Azure services can expose user information. The...
Kyle Avery: Evading Memory Scanners — Bypassing YARA and PE-sieve
A DEF CON 30 talk about techniques for evading memory analysis tools used by antivirus...
Hadrien Barral: Emoji Shellcoding
A DEF CON 30 talk about an unusual approach to writing shellcode — using only...
Gal Zror: Look Mom — I’m the CEO
A DEF CON 31 talk on real-time deepfake capabilities. The researcher demonstrates how, using open-source...
Tracy Mosley: The Evolution of Mobile Networks — from 2G to 5G
A talk by Tracy Mosley on how mobile networks have evolved — from 2G to...
Javan Rasokat and Andra Lezza: Lessons from Building and Defending LLM Applications
A DEF CON 32 talk on real-world experience developing and securing applications powered by large...
Nick Powers and Steven Flores: ClickOnce as a Trusted Code Execution Vector
A DEF CON 30 talk exploring ClickOnce as an underused yet powerful initial access technique....
Jen Easterly: What Run-DMC and Aerosmith Can Teach Cybersecurity
A DEF CON 30 talk about how unexpected partnerships can reshape entire industries. The speaker...
Paul Gerste: SQL Injection Isn’t Dead — Protocol-Level Injection Attacks
A DEF CON 32 talk where security researcher Paul Gerste presents a new approach to...
Policy Dept DEF CON: Hackers and Policy — Why It Matters
A DEF CON 30 talk about the role of the hacker community in shaping public...
Suha Hussein: Injecting Backdoors into ML Pipelines via Input Handling Flaws
A DEF CON 32 talk where security researcher Suha Hussein presents a new class of...
Elonka Dunin & Klaus Schmeh: Famous and Lesser-Known Unsolved Codes
A DEF CON 32 talk where cryptography researchers Elonka Dunin and Klaus Schmeh explore famous...
Allison Young & Diane Ackerman: Your Data Is Private… Until Law Enforcement Wants It
A DEF CON 31 talk on how personal data from smartphones can be used by...
Joe Sullivan: Another Version of the Uber Incident
A DEF CON 31 talk about the 2016 Uber breach and the subsequent criminal case...
Sharon Brizinov: Evil PLC — Turning Industrial Controllers into Weapons
A DEF CON 30 talk introducing a new attack technique against industrial systems — Evil...
Lukas McCullough: OSINT — Reconnaissance Before Stepping on Site
A DEF CON 32 talk on how to gather intelligence about people and locations using...
Hackers, Lawyers, and the Security Research Legal Defense Fund
A DEF CON 31 panel discussing the legal risks faced by security researchers. Speakers share...
Alexey: Meduza vs Censorship — How Independent Media Bypasses Kremlin Blocks
A DEF CON 31 talk on how the independent outlet Meduza continues to operate and...