Las Vegas Convention Center, Level 1, West Hall 2, Zone 604

Village Hours

Day 1 Friday, August 8, 10am - 6pm
Day 2 Saturday, August 9, 10am - 6pm
Day 3 Sunday, August 10, 10am - 1pm

All times are in Pacific Time(GMT -7)

Day 1 - August 08, 2025

10:00

10:15

10:20

10:20 - 10:50

Scaling Bug Hunting in Open Source Software

Talk All Audiences

Kyle Kelly

10:30

10:30 - 11:30

AI Supply Chain: Generating AI SBOMs for Hugging Face Models

Arsenal All Audiences

Helen Oakley

11:00

11:00 - 13:00

Finite State IoT Pentest Blitz

POD

Larry Pesce

11:00 - 13:00

Artificially Insecure

POD

Ken Johnson

11:40

11:40 - 12:10

From Tests to Targets: Expanding DAST with Selenium & ZAProxy

Talk Intermediate

Sara Martinez Giner

12:00

12:00 - 13:00

Static Analysis Hero - Security Code Reviews for Professionals

Arsenal All Audiences

Matthias Göhring

Dustin Born

12:20

12:20 - 12:50

Abusing the Rules: Detect and Defend Against Business Logic Attacks in APIs

Talk Intro

Tristan Kalos

Antoine Carossio

12:20 - 15:20

A Taste of Chrome V8 Exploitation

Workshop Intermediate

Hoseok Lee

Youngseo Park

JaeSeok Jung

Hyaesun Ji

Taeeun Lee

13:00

13:00 - 15:00

Finite State IoT Pentest Blitz

POD

Larry Pesce

13:00 - 15:00

Color with Friends & Smallstep

POD

Carl Tashian

Hunter Hawke

13:00 - 15:00

Vulnerability Hunt - The Snippets Edition

POD

Raphael Silva

Darren Meyer

13:30

13:30 - 14:30

Introduction To SeVa [Secret Validator] - Secrets Prioritization Framework

Arsenal All Audiences

Pramod Rana

Leon Denard

13:40

13:40 - 14:10

The AppSec Poverty Line: Minimal Viable Security

Talk Intermediate

SheHacksPurple

14:20

15:00

15:30

15:40

15:40 - 16:10

Pwn My Ride: Jailbreaking Cars with CarPlay

Talk Intermediate

Gal Elbaz

Avi Lumelsky

16:20

17:00

Day 2 - August 09, 2025

10:00

10:00 - 10:30

Beyond Vibe Coding: Building Reliable AI AppSec Tools

Talk Intermediate

Emily Choi-Greene

10:30

10:30 - 11:30

Catch the Flow: Securing CI/CD with Flowlyt

Arsenal All Audiences

HK

kvprashant

Nandan Gupta

Arif

10:40

11:00

11:00 - 13:00

Color with Friends & Smallstep

POD

Carl Tashian

Hunter Hawke

11:20

11:20 - 11:50

r/DIY: How Do We Build Our Own Code Scanning Platform?

Talk Intermediate

Charan Akiri

Christopher Guerra

12:00

12:40

12:40 - 13:10

Breaking the CI/CD Chain: Security Risks in GitHub Actions

Talk Intermediate

Sharon Ohayon Pshoul

Iggy

Michael Goberman

13:00

13:00 - 15:00

Vulnerability Hunt - The Snippets Edition

POD

Raphael Silva

Darren Meyer

13:00 - 15:00

Finite State IoT Pentest Blitz

POD

Larry Pesce

13:15

13:15 - 15:15

Container Escapes 101

Workshop Intermediate

some-natalie

13:20

13:20 - 13:50

The AppSec Program I Regret Building

Talk Intermediate

Thomas Jost

13:30

14:00

14:00 - 14:30

Memory Attacks in a Stateless World

Talk Intermediate

Rashmi

Om Narayan

14:40

14:40 - 15:10

Hijacking AI Agents with ChatML Role Injection

Talk Intermediate

zizkill

Armend Gashi

Anit Hajdari

15:00

15:00 - 17:00

Finite State IoT Pentest Blitz

POD

Larry Pesce

15:00 - 17:00

Artificially Insecure

POD

Ken Johnson

15:00 - 17:00

Color with Friends & Smallstep

POD

Carl Tashian

Hunter Hawke

15:00 - 16:00

PyIntruder: Customizable, CLI-Native Web Fuzzer

Arsenal All Audiences

Sagnik Haldar

Nandan Gupta

Swarup Natukula

Arif

15:20

15:20 - 15:50

Plugins Gone Rogue: Attacking Developer Environments

Talk All Audiences

Raphael Silva

15:30

16:00

16:40

16:40 - 17:35

State of (Absolute) AppSec

Panel Intro

@sethlaw

SheHacksPurple

@cktricky

@jhaddix

Day 3 - August 10, 2025

10:00

10:00 - 11:00

Spotter – Universal Kubernetes Security Engine

Arsenal Intermediate

madhuakula

10:00 - 13:00

AppSec in the Shadows: Adversarial Tradecraft in App and API Defenses

Workshop All Audiences

Roshan Piyush

Soujanya Namburi

10:20

10:20 - 10:50

Exploitable In The Wild CVE Appears! But Should We Fix Them All?

Talk Advanced

Moshe Siman Tov Bustan

Liad Cohen

11:00

11:00 - 13:00

Vulnerability Hunt - The Snippets Edition

POD

Raphael Silva

Darren Meyer

11:00 - 11:30

Chained Exploits: The Silent Takeover

Talk Intermediate

Monish Alur Gowdru

cybermeow

11:30

11:30 - 12:30

Static Analysis Hero - Security Code Reviews for Professionals

Arsenal All Audiences

Matthias Göhring

Dustin Born

11:40

11:50

11:50 - 12:00

CTF Award Ceremony

12:00

12:00 - 13:00

SBOM Meetup

Panel

Allan Friedman

Thanks to our 2025 Sponsors

Gold Sponsors


Silver Sponsors


Bronze Sponsors


Hacker Fuel @ DEF CON 33

Is your organization passionate about application security and want to sponsor?

Read on how to become a sponsor and checkout our available sponsorship opportunities.