Defcon 34

https://defcon.org

Join us in Las Vegas for Defcon34! We’ve got some really cool stuff from sponsors. You should swing by and grab and/or win some swag!

Book Signing

Join us Friday, August 7 at 3:00pm for a book signing with co-founder and #1 best selling author Ted Harrington. Each attendee will receive a complimentary signed copy of Hackable, while supplies last. We recommend coming early! To learn more about the book, head here: Cybersecurity Author | Ted Harrington | United States

Hackable: How To Do Application Security Right

Speaker Schedule

Sick Signals: Adversarial Prompt Injection via Medical IoT Telemetry

Friday – 1045 | 45min | Vinitha Mathiyazhagan, Tamil Mathi T.

Medical IoT devices such as continuous glucose monitors, ECG patches, remote patient monitoring hubs that increasingly feed LLM-powered clinical decision systems. Their telemetry streams are implicitly trusted as ground truth. This talk introduces a novel attack class: adversarial prompt injection delivered through crafted medical IoT sensor payloads. By encoding malicious instructions inside what appears to be routine device data, an attacker can manipulate the downstream LLM pipeline, suppressing critical clinical alerts, fabricating findings in physician summaries, or triggering unauthorized actions in AI systems with actuation capabilities. We present the threat model and a taxonomy of seven injection vectors spanning the full stack: analog spoofing, FHIR/HL7 free-text field poisoning, MQTT broker injection, calibration event hijacking, alarm message hijacking, time-series fragmentation, and multi-device coordinated injection. Unlike attacks targeting text interfaces, this class exploits the implicit trust placed in sensor telemetry — payloads hide inside ordinary device data, bypassing numeric validators and arriving in the LLM context as trusted clinical input. We discuss early experimental findings on the feasibility of this attack class, along with detection strategies and open questions for defenders. Attendees will leave with a concrete threat model, an expanded vocabulary for this new attack surface, and a new way to think about trust boundaries in AI-augmented medical systems.


Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM

Friday – 1230 | 45min | Larry Pesce

An AI agent found a previously undisclosed vulnerability in a named vendor’s IoT product within hours of being pointed at the firmware. The practitioner who built the agent had spent 25+ years doing that work by hand. Plan R is an IoT-focused MCP server that gives AI agents direct access to real pentesting tools, structured by playbooks that encode methodology rather than scripts. The framework expanded from firmware-only analysis to a multi-domain suite covering WiFi, BLE, network protocols, and hardware interfaces, with each domain compounding the value of every other through cross-domain correlation. The centerpiece is a real engagement: a named vendor, a disclosed vulnerability, and the specific challenge of convincing a white box vendor that a finding is real when the methodology that found it is “an LLM read your code.” Attendees leave with a working blueprint for building their own AI pentesting agents, an honest account of where the approach breaks, and a direct answer to the question every experienced practitioner is quietly asking: if an AI can do this, what exactly am I bringing to an engagement? The answer is worth hearing. But the work is changing, and this community should be driving how.


The Camera Is Lying: RTSP Trust Failures in Modern Surveillance Systems

Saturday 1100 | 45min | Bogdan “BOTEZATU”

Surveillance cameras sit at the intersection of physical security, privacy, and critical infrastructure. Yet many still rely on decades-old streaming protocols and fragile trust assumptions that receive far less scrutiny than web interfaces or cloud APIs. In this talk, Bitdefender researchers present a newly discovered authentication bypass affecting Hikvision surveillance cameras that abuses RTSP session handling to gain unauthorized access to live video streams. By exploiting inconsistencies between session validation and authorization logic, attackers can transform low-privilege or permissionless sessions into authenticated stream access.


Anyone Can Hack IoT (Even Easier Now) – A Beginner’s Guide to AI Augmented IoT Hacking

Saturday 1145 | 45min | Andrew Bellini

Two years ago I gave a popular talk at Defcon called “Anyone Can Hack IoT” and the message was simple, you don’t need expensive gear and I can show you how. All of that is true, but now it’s even easier and I want to show you why. Whether you saw the original talk or this is your first time thinking about IoT hacking, I’ll show you how AI has actually made it even easier. In this talk I’ll show you what’s actually useful and what not by walking through my real workflow that I’ve used to find multiple CVEs. I’ll demo Wairz, an open source tool I built that lets AI agents help reverse engineering firmware, along with some other hardware tools I’ve put together to give AI direct access to devices on my bench. I’ll cover what’s worth using AI for, what’s still better done by hand and how you can build your own AI assisted setup at home and hack your first device (or second or third or so on).


UAiRT: Over The Air UART

Saturday 1430 | 45min | Metehan Arslan, Samet Berk Simsek

The industry relies heavily on zero-trust architectures, TLS tunneling, and WAN monitoring to secure ISP edge gateways. But what happens when the compromise is soldered directly to the motherboard? Introducing Project UAiRT (UART Air interface & Remote Transmission). This presentation explores a devastating supply-chain and physical access attack utilizing a tiny $5 ESP32-C3 microcontroller implanted inside a production grade ISP router. By hardwiring the ESP32 directly to the router’s internal power rails and UART debug headers, we establish an undetectable, out-of-band Command & Control (C2) bridge that completely bypasses the router’s internal firewalls and the ISP’s network monitoring. Project UAiRT is not a dumb serial bridge, it is an intelligent parasite. In this talk, we will demonstrate how to weaponize the ESP32’s additional GPIO pins to create a “state-aware” implant. By wiring these pins to the router’s internal status LEDs and reset lines, the UAiRT module actively monitors the router’s hardware state. Attendees will see a live demonstration of the ESP32 detecting a system reboot via LED voltage changes, calculating the exact microsecond delay, and autonomously firing a carriage return to interrupt the bootloaders. From this stealthy vantage point, we will use covert wireless channels (BLE, hidden Wi-Fi, and ESP-NOW) to remotely trigger filesystem modifications, drop persistent root shells, and hijack the ISP’s TR-069 management daemon, proving that software security means nothing if the supply chain is compromised by a piece of silicon the size of a thumbnail.


Beyond Your Bookshelf: Hackable eReaders

Saturday 1515 | 45min | Katie “Paxton-Fear”

Kindles, Kobos, Boox and BigMes there’s no shortage of eReaders to choose from in 2026, with their paper-like eInk displays designed for one thing: reading books. But under the surface of these minimalist devices is a surprisingly hackable device. From Kindle jailbreaks, to Android apps, to flashing custom firmware. We’ll take that dust-gathering device off of your nightstand and onto your lab bench to talk about the vulnerabilities and customisability of these devices.


Weaponization of Cellular Based IoT Technology – Leveraging Smart Devices to Gain a Foothold

Saturday 1630 | 60min | Carlota Bindner, Deral Heiland (Rapid7)

As IoT devices continue to integrate cellular technologies for communication, the potential risk for adversaries to weaponize the hardware’s trust relationship and gain access to critical backend infrastructure grows exponentially. During this talk, we will present our research focused on how built-in cellular technology in IoT devices can be leveraged to gain access to and execute attacks against cloud services and backend private network environments. We will cover methods to modify IoT devices to take control over the installed cellular modules, allowing for injecting communications and establishing Man-in-the-Middle (MitM) traffic between the Micro Controller Units (MCU) and the cellular modules. We will demonstrate how control of onboard cellular communications could be used to launch attacks against the backend cloud infrastructure and network systems outside of the IoT device’s intended purpose. During this presentation, we will demo and release proof-of-concept code to control the onboard cellular modules to accomplish these goals. We will also provide actionable defense strategies, including discussions around hardware design recommendations, interface access control settings, and methods for applying targeted mitigation techniques and processes so organizations can strengthen IoT trust boundaries and protect against this evolving class of cellular-based threats.

Deral Heiland, CISSP, serves as a Principal Security Researcher (IoT) for Rapid7. Deral has over 25 years of experience in the Information Technology field, and over the last 15+ years Deral’s career has focused on security research, security assessments, penetration testing, and consulting for corporations and government agencies. Deral also has conducted security research on numerous technical subjects, releasing white papers, security advisories, and has presented the information at numerous national and international security conferences including Blackhat, Defcon, Shmoocon, DerbyCon, RSAC, Hack in Paris. Deral has been interviewed and quoted by several media outlets and publications including ABC World News Tonight, BBC, Consumer Reports, MIT Technical Review, SC Magazine, and The Register.


You Can’t Opt Out: The Invisible Surveillance in Your Walls, Pockets, and Lives

Sunday 1000 | 60min | Naomi Brockwell

Surveillance is baked into the very fabric of our digital existence. From smart homes to smart cars, and now we drive down streets with smart cameras tracking our every move. And why aren’t even aware of most of it, because almost none of it is disclosed in any meaningful way to the people being surveilled. Sometimes because companies don’t want their users to understand what data they’re collecting, because users would be upset, and sometimes because governments doing want us to know about the surveillance. This talk walks through a series of real cases where surveillance was hiding in plain sight inside ordinary consumer iot devices and apps, and was only discovered because someone with the right skills bothered to look. From high school students at a previous DEF CON uncovering microphones installed in school bathrooms, to Byron Tau’s reporting on commercial SDKs (like the one embedded in a widely-used Muslim prayer app) feeding location data to U.S. military and intelligence buyers, to robot vacuums quietly mapping the interiors of homes and shipping that data overseas, to the BadBox 2.0 botnet found lurking inside off-the-shelf Android streaming boxes like Superbox. The surveillance is pervasive, and the average consumer has no realistic way to detect or refuse it. This session makes the case that the question is no longer “are you being watched?” but “could you even opt out if you tried?” The reality is, it’s becoming so difficult to have meaningful privacy in the digital age that we’re on the cusp of a digital panopticon that threatens the very freedom of society. This talk explains what is at stake to democracy when privacy disappears, and how it slowly eliminates the self-correcting mechanisms and checks on power in society, such as protest movements, whistleblowers, independent media, protest movements, activist groups, and opposition parties. It is also a call to action for the people in this room, who possess the unique skill sets of reverse engineering, network analysis, firmware teardown, RF work etc. People breaking these systems apart and revealing what they find to the world is rapidly becoming the only meaningful check on a landscape that has decided surveillance is the default. We need more researchers looking, and we need them looking now.


One Firmware Flaw, 70+ Device Models: Lessons in Industrial IoT Disclosure and Mitigation

Sunday 1130 | 30min | Weihan Goh

In this talk, we use a real firmware vulnerability we found, CVE-2026-29988, affecting more than 70 industrial sensor models from a single vendor to show how one finding can become a fleet-scale problem. The bug matters, but the bigger story is what happens next – a CVE goes public, patch adoption is still early, and operators are left managing risk in environments where safety and availability matter as much as security. We will walk through how the issue was found, how its scope grew across a large product line, and why industrial devices make remediation fundamentally different from IT or our regular consumer technology. We will also cover the coordinated disclosure process with a (very) cooperative vendor, and a broader lesson that emerged from the case, i.e., that researchers, vendors, and operators do not all gain the ability to act on the same timeline. Our talk is a talk about shared firmware risk, real-world disclosure, and what researchers, vendors, and operators should learn when a firmware issue affects a broad line of products and public disclosure arrives before real-world mitigation catches up.


Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology

Sunday 1200 | 60min | Simone Bossi, Luca Borzacchiello (Nozomi Networks)

Modern IoT firmware often appears protected behind proprietary encryption, stopping analysis before it starts. However, in many cases the fastest path forward is not to break the cryptography, but it is to reuse the vendor’s own implementation via targeted function emulation. In this hands-on workshop, attendees will learn a methodology we call firmware archaeology: a practical method for reconstructing the proprietary firmware decryption scheme by correlating artifacts left behind across firmware archives, public repositories and developer ecosystems. Attendees will analyze the real-world ecosystem of a commercial IP camera vendor, using the firmware archaeology methodology. First, they will identify historical artifacts and ecosystem components from publicly available sources. Next, they will recover from binaries the cryptographic routines that are responsible for decrypting the firmware images. They will then reuse and emulate these functions in a controlled environment to recover the decrypted firmware image that was initially secured by the proprietary encryption scheme. With this access, participants will move beyond decryption to explore hidden functionalities of the target device and map the broader attack surface of the platform that was previously inaccessible. The workshop is designed as a practical methodology session rather than a one-off trick or a showcase of vulnerabilities. All exercises are hands-on and based on real research, with pre-packaged material and tooling provided. Attendees will leave with a practical and repeatable methodology for analyzing modern IoT platforms, including techniques to reconstruct firmware decryption pipelines and bypass analysis barriers without reimplementing vendor cryptography from scratch.

Luca Borzacchiello is a Security Researcher with deep expertise in Symbolic Execution, Reverse Engineering, and Fuzzing. He currently works at Nozomi Networks, where he focuses on cutting-edge security research.
Before joining Nozomi, Luca served as a Red Team Engineer for the Italian Government, where he contributed to national cybersecurity initiatives. He also worked as researcher on the Red Team at TIM S.p.A., one of Italy’s leading telecommunications companies.
Luca holds a Ph.D. in Program Analysis from Sapienza University of Rome. Outside of work, he is an active participant in Capture The Flag (CTF) competitions, where he enjoys applying his reverse engineering skills in high-stakes challenges.


Activities

Smart Home in the Matter: Blink, Race, Attack CTF

Bitdefender and Netgear invite you into the smart-home arena, where the Matter fabric pulses with secrets, traps, and unexpected twists, and where AI can finally take a break while your critical thinking takes the lead.

Lights whisper in gossip patterns. A race keeps restarting, but the real winner may not be who you think. Launch attacks, hunt for vulnerable devices, dodge detection, and remember: the router might still have the final say.

Can you crack the secrets, outsmart the defenses, and conquer the challenges?


Hands-On Hardware Hacking – From JTAG to Root, Memory Patching Boot Process for Root Access

Rapid7 is back with more hands-on hardware hacking exercises. This year at Rapid7’s hands-on hardware hacking lab, you’ll dive in deep to gain root access on an IoT mesh Wi-Fi device. Using tools like OpenOCD and Segger J-Link Mini, we’ll guide you through modifying the boot ‘init=’ process in memory via JTAG, forcing the device into a single user mode shell via UART. Once in single-user mode we will address identifying and restarting the watchdog process to prevent system reboot , followed by rebuilding the environment, load drivers, and gain access to various file systems and network functions. 


Raiders of the Lost Firmware: A Hands-On Workshop in IoT Firmware Archaeology

Encrypted IoT firmware doesn’t have to be a dead end. In this hands-on workshop, we’ll reconstruct a real vendor’s firmware decryption pipeline without ever touching the hardware, by chasing the artifacts the vendor left scattered across public archives, developer ecosystems, and shipped binaries.

You won’t break the crypto. You’ll borrow it. We’ll dig through Wayback Machine archives, map the platform’s public surface, locate the decryption routines inside the binaries, and emulate them to unlock encrypted payloads. The dig ends where the real fun starts.

You’ll leave with a transferable, software-only methodology for opening up modern IoT platforms, plus the tooling to run it yourself.

For intermediate attendees comfortable in a terminal, with some firmware/RE/OSINT background. Bring a Linux laptop or VM, 20 GB free, Python 3.8+, and a decompiler (Ghidra or IDA). Docker and binwalk optional


Discover GE Appliances!

Join us for a self-guided interactive look at GE Appliances and get hands on with some of our most popular home appliances! You may also interact with our GE Appliances Developer Portal that allows for adding external devices to the SmartHQ ecosystem, for synchronous control and monitoring of SmartHQ devices, and for your application to receive real-time asynchronous updates from your SmartHQ device.


Just Hacking Training

2 Mini-Workshops, Only 15 Minutes Each

QEMU: Emulate Your “Things” – Hack a Drug Lord’s Smart Toilet

Encryption! What Encryption? – Decrypt TLS Traffic with mitmproxy

No Schedule

Just Sit Down & Start Learning


Cat-astrophic Hacking: Breaking Into Smart Litter Boxes

What happens when your cat’s litter box joins the Internet of Things?

Join Suzu Labs as we dissect, analyze, and hack smart litter robots to uncover the security risks hiding inside connected pet technology. See the results of our research into connected litter robots, learn how attackers think, and discover why even the most unexpected IoT devices deserve a security assessment.

Stop by, ask questions, and grab some limited-edition swag inspired by our four-legged research subjects while supplies last.


All About UART

UART, it’s in your smart camera, router, maybe even your phone and it’s usually the easiest foothold into a device. In this hands-on workshop you’ll learn to find it with a multimeter, read it with a logic analyzer, talk to it with a UART adapter, and finish by writing a Python script that brute-forces your way past a login. No experience needed!

https://training.brownfinesecurity.com

https://digitalandrew.io/


Retia

Meshcore & Meshtastic for Beginners: Solder Your Encrypted Off-Grid Node!

Build your own cat-themed Nibble Mesh node and join the massive off-grid LoRa mesh networks popping up worldwide!

Reticulum for Beginners

Go beyond basic LoRa messaging and build a truly decentralized community network

Learn BadUSB Hacking With the USB Nugget

Automate computer hacking in seconds using the cute, cat-themed USB Nugget!

Solder Your Very Own IoT Purrsheen Cat Lamp with WLED!

Learn rapid prototyping and build your own open-source, internet-controlled LED art!

Learn Beginner Soldering with the Meow Mixer Badge

Want to learn how to solder? Build an interactive, color-tuning cat badge while learning the basics of circuits and soldering!

Meshcore & Meshtastic for Hackers: Advanced Node Setup & Deployment

Dive deep into advanced off-grid mesh protocols! Learn the key differences between Meshcore and Meshtastic, and how to customize frequencies and encryption. 

Wi-Fi Self Defense & Hacker Hunting For Beginners

Get hands-on instruction using the Wi-Fi Nugget, a unique cat-shaped hacking microcontroller! 

Off-Grid Pocket Server: Captive Portals & Local Networking

Ever wanted to run your own tiny universe from a microcontroller? Turn an ESP8266 into a self-contained, offline Wi-Fi pocket server!

Make your very own evil IoT Cat Lamp with WLED!

Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this class, we’ll put together a “Purrsheen” cat shaped Wi-Fi lamp that allows you to control your adorable cat baby via Wi-Fi or Home Assistant with WLED! Workshop will involve beginner-level soldering and assembly skills. Great for cat-lovers and those looking to get into DIY IoT projects. This is a paid workshop, be sure to reserve your spot at https://retia.io/collections/defcon34

Build Your Own Meshtastic Node: Off-Grid, Encrypted LoRa Meshnets for Beginners!

Beginners can now create off-grid, encrypted mesh networks for cheap, with applications in emergency communication, sensor monitoring, and more! These mesh networks have been popping up in cities all over the world, and this class will go over everything a beginner needs to run or build their own nodes. If you’ve ever wanted to legally create off-grid, encrypted mesh networks that can span over a hundred miles, you can get started with Meshtastic for around $50. This class will serve as a beginner user’s guide to Meshtastic, covering everything from hardware basics to advanced software configuration. We will use custom Meshtastic nodes to see real-world results in Las Vegas and explore attacks against mesh networks. Attendees will learn to run their own Meshtastic nodes, select antenna options, and configure software! This is a paid workshop, be sure to reserve your spot at https://retia.io/collections/defcon34

Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!

Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. For beginners just getting started, it can be confusing to dive into these features! In this workshop, we’ll explore the exciting modules that make Meshtastic more fun and useful. We’ll cover how to customize the encryption, add hardware like GPS and sensors, and change the default transmission settings to adapt to specific environments. Attendees will learn to customize their Meshtastic nodes for any situation using the built in modules and settings. We’ll also explore attacks against Meshtastic, and how to get involved in your local area! What to bring: Computer with Google Chrome, iOS or Android smartphone. What you get: 1 Bluetooth Nugget+ LoRa Backpack + weather sensor. This is a paid workshop, be sure to reserve your spot at https://retia.io/collections/defcon34

Wi-Fi Self Defense & Hacker Hunting & For Beginners

This course offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Designed to engage participants in practical learning, we cover essential skills for defending against 4 common, yet powerful Wi-Fi attacks. Students will explore topics like detecting Wi-Fi leaks, the risks of QR codes leading to hidden networks, spotting phishing networks, and defending against advanced Wi-Fi karma attacks. The Wi-Fi Nugget is a powerful tool for understanding and fighting back against Wi-Fi hacking. This class is suitable for Wi-Fi hacking experts and those just getting started. This is a paid workshop, be sure to reserve your spot at https://retia.io/collections/defcon34

Playing with Hyper-local Pocket-Sized Servers

Ever wanted to run your own tiny universe, right from a tiny microcontroller? In this hands-on workshop, we’ll turn an ESP8266 into a self-contained Wi-Fi pocket server that anyone nearby can connect to without the internet. You’ll build a local-only “captive portal” world where visitors can: drop files like a digital dead-drop, chat anonymously on a tiny message board, explore your custom micro-website, or whatever weird hyperlocal experience you design. No prior experience needed. If you can plug in a board and click “upload,” you’re in. This is a paid workshop, be sure to reserve your spot at https://retia.io/collections/defcon34

Wi-Fi Self Defense & Hacker Hunting & For Beginners

This course offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Designed to engage participants in practical learning, we cover essential skills for defending against 4 common, yet powerful Wi-Fi attacks. Students will explore topics like detecting Wi-Fi leaks, the risks of QR codes leading to hidden networks, spotting phishing networks, and defending against advanced Wi-Fi karma attacks. The Wi-Fi Nugget is a powerful tool for understanding and fighting back against Wi-Fi hacking. This class is suitable for Wi-Fi hacking experts and those just getting started. This is a paid workshop, be sure to reserve your spot at https://retia.io/collections/defcon34

Mesh Nets for Hackers: How (& When) to use Meshtastic, Meshcore, & Reticulum!

Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. For beginners just getting started, it can be confusing to dive into these features! In this workshop, we’ll explore the exciting modules that make Meshtastic more fun and useful. We’ll cover how to customize the encryption, add hardware like GPS and sensors, and change the default transmission settings to adapt to specific environments. Attendees will learn to customize their Meshtastic nodes for any situation using the built in modules and settings. We’ll also explore attacks against Meshtastic, and how to get involved in your local area! What to bring: Computer with Google Chrome, iOS or Android smartphone. What you get: 1 Bluetooth Nugget+ LoRa Backpack + weather sensor. This is a paid workshop, be sure to reserve your spot at https://retia.io/collections/defcon34

Make your very own evil IoT Cat Lamp with WLED!

Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this class, we’ll put together a “Purrsheen” cat shaped Wi-Fi lamp that allows you to control your adorable cat baby via Wi-Fi or Home Assistant with WLED! Workshop will involve beginner-level soldering and assembly skills. Great for cat-lovers and those looking to get into DIY IoT projects. This is a paid workshop, be sure to reserve your spot at https://retia.io/collections/defcon34

Wi-Fi Self Defense & Hacker Hunting & For Beginners

This course offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Designed to engage participants in practical learning, we cover essential skills for defending against 4 common, yet powerful Wi-Fi attacks. Students will explore topics like detecting Wi-Fi leaks, the risks of QR codes leading to hidden networks, spotting phishing networks, and defending against advanced Wi-Fi karma attacks. The Wi-Fi Nugget is a powerful tool for understanding and fighting back against Wi-Fi hacking. This class is suitable for Wi-Fi hacking experts and those just getting started. This is a paid workshop, be sure to reserve your spot at https://retia.io/collections/defcon34


Ludlow Institute

Expose Hidden Surveillance in Everyday Tech

Most devices are doing more than they admit.
We want you to hack them and show us what you find.

Join the Ludlow Institute Surveillance Mission.
Dump firmware, capture packets, probe APIs, or tear devices apart however you like.
Look for hidden microphones, unencrypted traffic, weird APIs, unexpected sensors, or anything else they’re hiding.

No limits on approach. Just bring the truth to light.

Prizes up for grabs.

To top