Members of the Raxis pentest team joined me last week at the Las Vegas Convention Center for DEF CON 34. As always, we came home with more homework than souvenirs.
This year’s theme was “Agency,” a call to take back control of the technology that increasingly makes decisions for us. The idea showed up everywhere, right down to the badge itself, an open and fully inspectable device from Bunnie Huang that doubles as a hardware security token you can actually audit.
A few sessions landed especially close to the work we do every day.
Identity Is Still the Shortest Path In
One session walked through escalating from a low-privilege foothold to full domain compromise by way of Active Directory Certificate Services. Another detailed novel vulnerabilities that force a Kerberos downgrade. Neither is exotic. Both describe the kind of misconfiguration our team finds routinely on internal engagements, and both are worth checking in your environment.
Trust Is Weaponized
A researcher demonstrated turning legitimate Microsoft applications into a phishing platform, which means the sender your users have been trained to trust becomes the delivery mechanism. Another showed a persistent browser-in-the-middle technique that survives the controls most organizations assume will stop credential theft.
The Devices Around Us Aren’t Secure
A dealer-installed anti-theft system exposed more than a million vehicles over Bluetooth. A single wildcard certificate exposed 1.1 million cameras sitting behind an IoT cloud. These are not research curiosities. They are the same class of vendor shortcut we find on client networks.
AI Moved from Novelty to Infrastructure
Last year the AI conversation was mostly about what these tools might eventually do. This year it was about breaking the runtimes and agent sandboxes that organizations have already deployed. If your company adopted an AI platform in the past twelve months, it is now part of your attack surface whether or not anyone has tested it.
Our Takeaways
Before attending DEF CON this year, our team worked the Raxis booth at Black Hat, and this ties directly to what we saw there. There are several pentest companies that want organizations to trust their security to automated processes and AI without humans taking part in the process. While that saves money on testing, it misses the key attacks that are the biggest threats.
What I keep coming back to is DEF CON’s theme. Agency means knowing what your systems are actually doing instead of trusting that someone else (or some system) has handled it. That is the entire premise of a good human-led penetration test, and it is why we make the trip every August.