<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>DEF CON 4</title>
  <link>https://defcon4.org/</link>
  <description>Hack the Planet. Defend the Stack.</description>
  <language>en</language>
  <lastBuildDate>Fri, 07 Aug 2026 08:14:05 GMT</lastBuildDate>
  <atom:link href="https://defcon4.org/feed.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>Show Me the Money: How Bug Bounties Are Eating the Zero-Day Black Market</title>
    <link>https://defcon4.org/bug-bounties-vs-zero-day-black-market-economics/</link>
    <guid isPermaLink="true">https://defcon4.org/bug-bounties-vs-zero-day-black-market-economics/</guid>
    <description>The underground exploit market has operated in the shadows for decades, but legitimate bug bounty platforms are finally putting real financial pressure on the gray and black markets. We dug into the numbers, talked to researchers on both sides of the fence, and found a surprisingly complex economic battlefield.</description>
    <author>DEF CON 4</author>
    <category>Security Research</category>
    <pubDate>Fri, 07 Aug 2026 08:14:01 GMT</pubDate>
  </item>
  <item>
    <title>When the Alarms Go Off: Incident Response Lessons Written in Blood (and Breach Notifications)</title>
    <link>https://defcon4.org/incident-response-lessons-from-2024-breaches/</link>
    <guid isPermaLink="true">https://defcon4.org/incident-response-lessons-from-2024-breaches/</guid>
    <description>The gap between companies that survived 2024&#039;s worst breaches with manageable damage and those that ended up in congressional hearings comes down to decisions made before the attackers ever showed up. Here&#039;s what actually separated the survivors from the cautionary tales.</description>
    <author>DEF CON 4</author>
    <category>Defense &amp; Blue Team</category>
    <pubDate>Fri, 07 Aug 2026 08:14:01 GMT</pubDate>
  </item>
  <item>
    <title>Poison at the Source: A Technical Deep Dive Into How Supply Chain Attacks Are Evolving</title>
    <link>https://defcon4.org/supply-chain-attacks-technical-breakdown-solarwinds-3cx/</link>
    <guid isPermaLink="true">https://defcon4.org/supply-chain-attacks-technical-breakdown-solarwinds-3cx/</guid>
    <description>Supply chain attacks represent the most elegant class of intrusion available to sophisticated threat actors — compromise the builder, own the users. From SolarWinds to 3CX to the XZ Utils backdoor, we break down the technical tradecraft and explain why your current defenses probably won&#039;t catch the next one.</description>
    <author>DEF CON 4</author>
    <category>Threat Intelligence</category>
    <pubDate>Fri, 07 Aug 2026 08:14:01 GMT</pubDate>
  </item>
  <item>
    <title>Poison in the Pipeline: How Foreign Adversaries Are Turning Open Source Into a Weapon</title>
    <link>https://defcon4.org/poison-in-the-pipeline-nation-state-open-source-supply-chain-attacks/</link>
    <guid isPermaLink="true">https://defcon4.org/poison-in-the-pipeline-nation-state-open-source-supply-chain-attacks/</guid>
    <description>Nation-state actors have figured out that the fastest way to breach critical US infrastructure isn&#039;t through the front door — it&#039;s through the code your developers trust without thinking twice. From SolarWinds to Log4Shell, the open source supply chain has become the most dangerous attack surface most organizations aren&#039;t defending properly.</description>
    <author>DEF CON 4</author>
    <category>Threat Intelligence</category>
    <pubDate>Fri, 07 Aug 2026 08:13:48 GMT</pubDate>
  </item>
  <item>
    <title>Steal Like a Red Teamer: 7 Offensive Techniques Your Defenders Need to Know Cold</title>
    <link>https://defcon4.org/steal-like-a-red-teamer-7-offensive-techniques-defenders-need-to-know/</link>
    <guid isPermaLink="true">https://defcon4.org/steal-like-a-red-teamer-7-offensive-techniques-defenders-need-to-know/</guid>
    <description>Red teams have been quietly cataloging your blind spots for years. It&#039;s time blue teams flipped the script — understanding the exact techniques adversaries use in the wild and building detection logic that catches them in the act. Here are seven offensive plays worth stealing.</description>
    <author>DEF CON 4</author>
    <category>Hands-On Security</category>
    <pubDate>Fri, 07 Aug 2026 08:13:48 GMT</pubDate>
  </item>
  <item>
    <title>Zero Trust, Zero Results: The Uncomfortable Truth About Why Your Security Transformation Is Stalling</title>
    <link>https://defcon4.org/zero-trust-zero-results-why-your-security-transformation-is-stalling/</link>
    <guid isPermaLink="true">https://defcon4.org/zero-trust-zero-results-why-your-security-transformation-is-stalling/</guid>
    <description>Zero trust is the most overhyped and underdelivered concept in enterprise security right now. Security leaders across the country are spending millions on the label while their actual posture barely moves — and the reasons why are more organizational than technical.</description>
    <author>DEF CON 4</author>
    <category>Opinion</category>
    <pubDate>Fri, 07 Aug 2026 08:13:48 GMT</pubDate>
  </item>
</channel>
</rss>