Media Summary: This talk explores the hidden risks in apps leveraging modern AI systems—especially those using large language models (LLMs) ... Four years ago, Chris found a vulnerability with a murder for hire site on the dark net. He could In this session, Tobias Diehl will demonstrate a critical vulnerability in Microsoft's CoPilot AI, exposing how data voids can be ...

Def Con 33 Exploiting Shadow - Detailed Analysis & Overview

This talk explores the hidden risks in apps leveraging modern AI systems—especially those using large language models (LLMs) ... Four years ago, Chris found a vulnerability with a murder for hire site on the dark net. He could In this session, Tobias Diehl will demonstrate a critical vulnerability in Microsoft's CoPilot AI, exposing how data voids can be ... With the commoditization of IoT surveillance technology, private and public entities alike have been rushing to put every facet of ... Quantum computers will crack RSA and ECC and weaken symmetric encryption, but when? NIST is betting it won't happen before ... Cryptographic random number generators are a critical part of many deployed cryptosystems. When they fail, so does the ...

Hi, it's me, XBOW, the AI offensive agent—a smart cyber detective on a mission to find bugs in the digital world. In the past few ... in devices - a Software Development Kit (SDK). This collection of binaries, proprietary services, and code samples allows board ... Everyone loves breaking in—but that's just step 7 out of 10. This session explores what it really takes to run a physical pen test ... In March, former national security advisor Mike Waltz accidentally invited a journalist into his war crimes Signal group with other ... The accelerating evolution of technology, specifically AI, has created a "meta-system" so complex and intertwined with all domains ... Some people think the days of critical HTTP request smuggling attacks on hardened targets have passed. Unfortunately, this is an ...

Photo Gallery

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh
DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro
DEF CON 33 - Mind the Data Voids: Hijacking Copilot Trust - Tobias Diehl
DEF CON 33 - Unmasking the Snitch Puck: IoT surveillance tech in the school bathroom - Reynaldo, nyx
DEF CON 33 - Post Quantum Panic: When Will the Cracking Begin, & Can We Detect it?  - K Karagiannis
DEF CON 33 - No Spook Leaves Randomness to Chance -  Shaanan Cohney
DEF CON 33 - Prompt  Scan  Exploit  AI’s Journey Through 0Days and 1000 Bugs  - D. Jurado & J. Nogue
DEF CON 33 - What is Dead May Never Die: The Immortality of SDK Bugs - Richard Lawshae
DEF CON 33 - From Pwn to Plan: Turning Physical Exploits Into Upgrades - Shawn
DEF CON 33 - 'We are currently clean on OPSEC' - The Signalgate Saga - Micah 'micahflee' Lee
DEF CON 33 - Game Hacking 101  - Julian 'Julez' Dunning
DEF CON 33 - Thinking Like a Hacker in the Age of AI - Richard 'neuralcowboy' Thieme
View Detailed Profile
DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh

This talk explores the hidden risks in apps leveraging modern AI systems—especially those using large language models (LLMs) ...

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

Four years ago, Chris found a vulnerability with a murder for hire site on the dark net. He could

DEF CON 33 - Mind the Data Voids: Hijacking Copilot Trust - Tobias Diehl

DEF CON 33 - Mind the Data Voids: Hijacking Copilot Trust - Tobias Diehl

In this session, Tobias Diehl will demonstrate a critical vulnerability in Microsoft's CoPilot AI, exposing how data voids can be ...

DEF CON 33 - Unmasking the Snitch Puck: IoT surveillance tech in the school bathroom - Reynaldo, nyx

DEF CON 33 - Unmasking the Snitch Puck: IoT surveillance tech in the school bathroom - Reynaldo, nyx

With the commoditization of IoT surveillance technology, private and public entities alike have been rushing to put every facet of ...

DEF CON 33 - Post Quantum Panic: When Will the Cracking Begin, & Can We Detect it?  - K Karagiannis

DEF CON 33 - Post Quantum Panic: When Will the Cracking Begin, & Can We Detect it? - K Karagiannis

Quantum computers will crack RSA and ECC and weaken symmetric encryption, but when? NIST is betting it won't happen before ...

DEF CON 33 - No Spook Leaves Randomness to Chance -  Shaanan Cohney

DEF CON 33 - No Spook Leaves Randomness to Chance - Shaanan Cohney

Cryptographic random number generators are a critical part of many deployed cryptosystems. When they fail, so does the ...

DEF CON 33 - Prompt  Scan  Exploit  AI’s Journey Through 0Days and 1000 Bugs  - D. Jurado & J. Nogue

DEF CON 33 - Prompt Scan Exploit AI’s Journey Through 0Days and 1000 Bugs - D. Jurado & J. Nogue

Hi, it's me, XBOW, the AI offensive agent—a smart cyber detective on a mission to find bugs in the digital world. In the past few ...

DEF CON 33 - What is Dead May Never Die: The Immortality of SDK Bugs - Richard Lawshae

DEF CON 33 - What is Dead May Never Die: The Immortality of SDK Bugs - Richard Lawshae

in devices - a Software Development Kit (SDK). This collection of binaries, proprietary services, and code samples allows board ...

DEF CON 33 - From Pwn to Plan: Turning Physical Exploits Into Upgrades - Shawn

DEF CON 33 - From Pwn to Plan: Turning Physical Exploits Into Upgrades - Shawn

Everyone loves breaking in—but that's just step 7 out of 10. This session explores what it really takes to run a physical pen test ...

DEF CON 33 - 'We are currently clean on OPSEC' - The Signalgate Saga - Micah 'micahflee' Lee

DEF CON 33 - 'We are currently clean on OPSEC' - The Signalgate Saga - Micah 'micahflee' Lee

In March, former national security advisor Mike Waltz accidentally invited a journalist into his war crimes Signal group with other ...

DEF CON 33 - Game Hacking 101  - Julian 'Julez' Dunning

DEF CON 33 - Game Hacking 101 - Julian 'Julez' Dunning

Intro basics about concepts in game

DEF CON 33 - Thinking Like a Hacker in the Age of AI - Richard 'neuralcowboy' Thieme

DEF CON 33 - Thinking Like a Hacker in the Age of AI - Richard 'neuralcowboy' Thieme

The accelerating evolution of technology, specifically AI, has created a "meta-system" so complex and intertwined with all domains ...

DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame  - James 'albinowax' Kettle

DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame - James 'albinowax' Kettle

Some people think the days of critical HTTP request smuggling attacks on hardened targets have passed. Unfortunately, this is an ...