Welcome to AppSec Village

where red, blue and purple teamers, come together learn from the best of the best on how to exploit software vulnerabilities and how to secure software. Software is everywhere, and Application Security vulnerabilities are lurking around every corner making the software attack surface attractive for abuse. If you are just an AppSec n00b or launch deserialization attacks for fun and profit, you will find something to tickle your interest at the AppSec Village.

Read More

DEF CON Talks

Sponsored Content

  • State of Security Vibe-Coded Apps

    State of Security Vibe-Coded Apps

    Vibe coding democratizes app development — but it also democratizes insecure deployments. When non-technical users build production apps with AI and ship them without review, the failure modes are predictable:...

    State of Security Vibe-Coded Apps

    Vibe coding democratizes app development — but it also democratizes insecure deployments. When non-technical users build production apps with AI and ship them without review, the failure modes are predictable:...

  • State of Cyber

    State of Cyber

    Most cybersecurity reports are hard to get through. Long, dense, and not that useful when you actually need answers. Symbiotic Security built something different: State of Cyber. A simple place...

    State of Cyber

    Most cybersecurity reports are hard to get through. Long, dense, and not that useful when you actually need answers. Symbiotic Security built something different: State of Cyber. A simple place...

  • AI in Production: The 2026 Runtime Execution Report

    AI in Production: The 2026 Runtime Execution Re...

    Code review can tell you what AI was supposed to do. It can't tell you what it's actually doing in production. The 2026 Runtime Execution Report from OLIGO Security digs...

    AI in Production: The 2026 Runtime Execution Re...

    Code review can tell you what AI was supposed to do. It can't tell you what it's actually doing in production. The 2026 Runtime Execution Report from OLIGO Security digs...

  • LLM Application Security: Governing AI-Driven Risk Across the Software Lifecycle

    LLM Application Security: Governing AI-Driven R...

    What does application security look like when AI is generating the code? In LLM Application Security: Governing AI-Driven Risk Across the Software Lifecycle, Checkmarx Zero explores how AI is reshaping...

    LLM Application Security: Governing AI-Driven R...

    What does application security look like when AI is generating the code? In LLM Application Security: Governing AI-Driven Risk Across the Software Lifecycle, Checkmarx Zero explores how AI is reshaping...

  • How to Prioritize Firmware Vulnerabilities for CRA Compliance

    How to Prioritize Firmware Vulnerabilities for ...

    Firmware scanners can return tens of thousands of CVEs, but the EU Cyber Resilience Act (CRA) expects remediation decisions to be risk-based, proportionate, and documented. How do you find the...

    How to Prioritize Firmware Vulnerabilities for ...

    Firmware scanners can return tens of thousands of CVEs, but the EU Cyber Resilience Act (CRA) expects remediation decisions to be risk-based, proportionate, and documented. How do you find the...

  • Claude x Security Engineering: From POC to Production

    Claude x Security Engineering: From POC to Prod...

    You can't just drop Claude into your security workflow. So how do you harness it to truly scale security and go beyond the hype? Tristan Kalos (Co-Founder and CEO, Escape)...

    Claude x Security Engineering: From POC to Prod...

    You can't just drop Claude into your security workflow. So how do you harness it to truly scale security and go beyond the hype? Tristan Kalos (Co-Founder and CEO, Escape)...

  • Cloud Application Detection and Response (CADR) For Dummies

    Cloud Application Detection and Response (CADR)...

    Firewalls. EDR. CWPP. CNAPP. Each solved a piece of the puzzle, but attackers keep finding the gaps. The new "CADR For Dummies" guide breaks down why runtime visibility is the...

    Cloud Application Detection and Response (CADR)...

    Firewalls. EDR. CWPP. CNAPP. Each solved a piece of the puzzle, but attackers keep finding the gaps. The new "CADR For Dummies" guide breaks down why runtime visibility is the...

  • State of AI in Pentesting 2026

    State of AI in Pentesting 2026

    The average pentest validates a system that stopped existing weeks ago, because the code kept shipping after the testers went home. Our sponsor, @Aikido Security, asked 400 security and engineering...

    State of AI in Pentesting 2026

    The average pentest validates a system that stopped existing weeks ago, because the code kept shipping after the testers went home. Our sponsor, @Aikido Security, asked 400 security and engineering...

  • 10 AI Supply Chain Risks Hiding in Your Codebase, and How to Get Ahead of Them

    10 AI Supply Chain Risks Hiding in Your Codebas...

    As organizations rapidly adopt AI, new components, including models, agents, MCP servers, prompts, datasets, and hosted AI services, are becoming part of the software supply chain. Many of them exist...

    10 AI Supply Chain Risks Hiding in Your Codebas...

    As organizations rapidly adopt AI, new components, including models, agents, MCP servers, prompts, datasets, and hosted AI services, are becoming part of the software supply chain. Many of them exist...

  • The malware dating guide: Understanding the types of malware on NPM

    The malware dating guide: Understanding the typ...

    You’ve heard of red flags in dating… but what about in your npm install? Our friends at Aikido Security just dropped the Malware Dating Guide. A brilliant (and hilarious) breakdown...

    The malware dating guide: Understanding the typ...

    You’ve heard of red flags in dating… but what about in your npm install? Our friends at Aikido Security just dropped the Malware Dating Guide. A brilliant (and hilarious) breakdown...

Our Sponsors