DEF CON 4 Hack the Planet. Defend the Stack.

DEF CON 4

Hack the Planet. Defend the Stack.

Latest Articles

Show Me the Money: How Bug Bounties Are Eating the Zero-Day Black Market
Security Research

Show Me the Money: How Bug Bounties Are Eating the Zero-Day Black Market

The underground exploit market has operated in the shadows for decades, but legitimate bug bounty platforms are finally putting real financial pressure on the gray and black markets. We dug into the numbers, talked to researchers on both sides of the fence, and found a surprisingly complex economic battlefield.

When the Alarms Go Off: Incident Response Lessons Written in Blood (and Breach Notifications)
Defense & Blue Team

When the Alarms Go Off: Incident Response Lessons Written in Blood (and Breach Notifications)

The gap between companies that survived 2024's worst breaches with manageable damage and those that ended up in congressional hearings comes down to decisions made before the attackers ever showed up. Here's what actually separated the survivors from the cautionary tales.

Poison at the Source: A Technical Deep Dive Into How Supply Chain Attacks Are Evolving
Threat Intelligence

Poison at the Source: A Technical Deep Dive Into How Supply Chain Attacks Are Evolving

Supply chain attacks represent the most elegant class of intrusion available to sophisticated threat actors — compromise the builder, own the users. From SolarWinds to 3CX to the XZ Utils backdoor, we break down the technical tradecraft and explain why your current defenses probably won't catch the next one.

Poison in the Pipeline: How Foreign Adversaries Are Turning Open Source Into a Weapon
Threat Intelligence

Poison in the Pipeline: How Foreign Adversaries Are Turning Open Source Into a Weapon

Nation-state actors have figured out that the fastest way to breach critical US infrastructure isn't through the front door — it's through the code your developers trust without thinking twice. From SolarWinds to Log4Shell, the open source supply chain has become the most dangerous attack surface most organizations aren't defending properly.

Steal Like a Red Teamer: 7 Offensive Techniques Your Defenders Need to Know Cold
Hands-On Security

Steal Like a Red Teamer: 7 Offensive Techniques Your Defenders Need to Know Cold

Red teams have been quietly cataloging your blind spots for years. It's time blue teams flipped the script — understanding the exact techniques adversaries use in the wild and building detection logic that catches them in the act. Here are seven offensive plays worth stealing.

Opinion

Zero Trust, Zero Results: The Uncomfortable Truth About Why Your Security Transformation Is Stalling

Zero trust is the most overhyped and underdelivered concept in enterprise security right now. Security leaders across the country are spending millions on the label while their actual posture barely moves — and the reasons why are more organizational than technical.