runZero has six, count ‘em, six, talks at Vegas!

|
Updated

Summer Camp in Las Vegas

Hey y’all! It’s just about that time again. The annual pilgrimage to the sweaty, sparkly hive of cybersecurity of Hacker Summer Camp is upon us. And I’m super stoked to get back out there to see my old friends, make a few new ones (possibly Klingon or Vulcan, since it’s running opposite Star Trek Las Vegas again), and deliver a thrilling and mysterious talk about scoring systems and other omen-readings.

And check it out, I’m not the only runZero nerd hitting the stage. We’ve got six talks happening across BSidesLV, The Diana Initiative, Black Hat, and DEF CON. Holy frijoles.

  • August 4 @ BSidesLV: Turbo Tactical Exploitation, 22 Tips for Tricky Targets – HD Moore speedruns through practical exploitation tips faster than you can say SYN/ACK/SYN-ACK.

  • August 4 @ The Diana Initiative: Forging Strong Cyber Communities in Uncertain Times – HD Moore and Nicole Schwartz share what it really takes to build and sustain infosec communities that don’t suck. No toxic positivity LinkedIn nonsense, but real talk and battle-tested advice

  • August 6 @ Black Hat USA: Akheron Proxy, Interchip Communication Serial Proxy – Matthew Kienow and our pal Deral Heiland demo a tool that proxies microcontroller traffic over serial lines, with all the replay and fuzzing bells and whistles.

  • August 7 @ Black Hat USA: Vulnerability Haruspicy, Picking Out Risk Signals from Scoring System Entrails – That’s me! I’ll be slicing open CVSS, EPSS, and SSVC, spilling their guts all over the Black Hat stage, as well as inspecting the latest like LEV, AIVSS, and more!

  • August 9 @ DEF CON: There and Back Again, Detecting OT Devices Across Protocol Gateways – Rob King leads a tour of ancient protocol lands, revealing how to spot hidden devices lurking on your (or someone else’s) network.

  • August 9 @ DEF CON: Shaking Out Shells with SSHamble – HD Moore returns to the DEF CON stage with an update to SSHamble, with fresh research on SSH bugs, backdoors, and the weird stuff lurking in our favorite remote admin tool.

Vegas is going to be hot, weird, exhausting, and amazing, and I can’t wait.

Of course, we’re up to much more than sharing our latest research on stage. If you’re looking to hang and/or score some very neat branded swag, keep an eye on our Summer Camp plans which will have the latest spacetime coordinates, as well as links to the more exclusive, invite-only events we’ll be hosting through the week.

It’s going to be a busy few days, and I’m kind of already exhausted just thinking about it. But in a good way. Let’s say.

Update (July 30, 2025): We've confirmed two more panel slots. Who needs sleep?

  • August 5 @ Black Hat USA: Self-Funded Security: Bootstrapping Your Way to Success in Cyber – HD Moore joins a panel to share how to grow a cybersecurity company, including using open-source work and community ties, both ethically and without huge capital investments.
  • August 5 @ BSidesLV: What Should CVE Be When It Grows Up? – TodB joins a panel to discuss the challenges facing the CVE program, and what you can do to help.

Written by todb

Tod Beardsley is VP of Security Research at runZero, where he "kicks assets and fakes frames." Prior to 2025, he was the Section Chief for the Vulnerability Response section for CSD/VM/VRC at CISA, the Cybersecurity and Infrastructure Security Agency, part of the US government, and a seasonal Travis County Election Judge in Texas. He's also a founder and CNA point of contact for AHA!. Tod spends much of his time involved in vulnerability research and coordinated vulnerability disclosure (CVD). He has over 30 years of hands-on security experience, stretching from in-band telephony switching to modern ICS/OT implementations. He has held IT ops, security, software engineering, and management positions in large organizations such as the US Government, Rapid7, 3Com, Dell, and Westinghouse, as both an offensive and defensive practitioner. Tod is a CVE Board member, has authored several research papers, and is an internationally-tolerated horror fiction expert.

More about todb
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 4.9: Unmask attack paths and segmentation gaps with advanced topology and deep OT device intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
Webcasts
runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...
Product Videos
runZero 4.9: Advanced topology, attack path mapping, & deep OT intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Podcasts
Risky Biz Interview: Navigating the AI vibe shift with HD Moore
runZero Founder and CEO HD Moore drops by in this week's Risky Biz sponsor interview to talk about the concerning AI vibe shift and what to do...
Podcasts
From two weeks to three days: The KEV deadline debate
Former CISA insider Todd Beardsley joins Greg to reveal what it takes to land on the KEV catalog and why ultra-short patching deadlines might...
Solution Briefs
runZero for NIS2 compliance
You can’t secure what you can’t see. runZero provides the complete asset visibility and continuous reporting you need to satisfy strict NIS2...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.