DEF CON 34: Intelligence Briefing

Article · 6 min read

DEF CON 34: the Agency theme, Microsoft's legal threat, the disclosure fight.

DEF CON 34 runs its Agency theme, self-determination in how we use technology, the same summer Microsoft threatened security researchers with legal action over zero-day disclosure. The disclosure-rights fight is not a side village this year, it is the room.

Context

DEF CON 34 runs August 6 through 9 at the Las Vegas Convention Center, the same week as Black Hat and a very different room. It is the event that sets the tone for independent security research each year, and this year it opens under a theme, Agency, that reads as a direct answer to a vendor that just told researchers to lawyer up.

The headline: Agency, right after Microsoft reached for the lawyers

Start with the theme. DEF CON 34's is 'Agency', self-determination in how we use technology, charting our own course and helping others do the same, straight from the front page of defcon.org and the con's own announcement. On its own that is a philosophy-village slogan. Then look at late May 2026: Microsoft issued legal threats against security researchers who disclosed active-exploitation zero-days in Windows and Defender, and the backlash was loud enough that Rescana published an executive summary on it by June 2. Agency stops being abstract the second a vendor with a trillion-dollar balance sheet decides how, when, and whether you are allowed to publish what you found. The through-line of the con this year is a single question: who owns the right to look. Watch the Policy and Bug Bounty rooms for whether they treat the Microsoft episode as a one-off or the opening move.

Who to watch (the list is not out, so watch roles)

The DEF CON 34 speaker and talk list is not in this bundle. The event-spec ships zero confirmed speakers, and the schedule that surfaced in search is a prior-year artifact. So this is roles and rooms, with one name.

The founder's opening remarks. The Dark Tangent (Jeff Moss) traditionally opens the con, and in a year he themed 'Agency', how he frames the disclosure fight is the tell for the whole weekend. The question to ask anyone near the org: is there a concrete ask behind the theme, a legal defense fund, a coordinated disclosure stance, or is Agency just a mood.

Whoever runs the Policy track. DEF CON's Policy department pulls in government, legal, and civil-society people most attendees never see at a hacker con. After the Microsoft episode, the question is whether Policy ships anything durable this year, model language protecting good-faith research, or hosts another well-attended panel that ends at the door.

The machine-learning security village organizers. Last year's recap (Automox's Jason Kikta) put the shift plainly: AI talk moved from hype to practical defender use, CI/CD and alert triage. The question for 2026: when the flaw is a model's behavior and the vendor is the same class of company now reaching for lawyers, what does responsible disclosure even look like.

The Car Hacking Village crew. Expected back per the Lensmor guide. Right-to-repair is Agency with a torque wrench. Ask them which automaker's disclosure process actually works and which one sends the cease-and-desist.

Rooms with signal density

The Villages are where DEF CON's real conversation lives, the working rooms with hands-on gear, not the main-stage talks that fill a house.

Policy Village. The room that matters most this year. If the community is going to turn the Microsoft backlash into a norm instead of a news cycle, it starts here. Signal to read: does anyone show up from a vendor to defend the legal-threat posture, or is the room a one-sided rally.

Bug Bounty Village. Where the economics get argued. If a vendor can threaten a researcher who discloses, the price of a finding and the trust in the whole coordinated-disclosure model get repriced in real time. Sit in for the platform-versus-researcher tension.

The machine-learning security village. Hands-on, and a year past the hype-to-practical pivot. Watch whether it has moved from defenders using models to attacking the models themselves, and how disclosure works when the target retrains weekly.

Recon and OSINT rooms. Relevant for a crowd that trades Signal handles, not business cards. The tradecraft on display is also the tradecraft used to reconstruct who you met after the fact.

Booths to read (the list is not posted, so read by category)

The DEF CON 34 sponsor list is not in the bundle. Slots opened at around $500 apiece per the Call for Sponsors, and confirmed names are not up. So read these by category, present or not, because they are what the floor will be arguing about.

Bug bounty and disclosure platforms (HackerOne and peers). The pitch: a managed channel between researcher and vendor. The actual sale in 2026: the Microsoft episode is a live advertisement for exactly that intermediation, and the strategic question is whether they position as researcher protection or vendor comfort. They cannot be both, and the room will notice which they pick.

Continuous pen-test platforms (Cobalt, Oneleet, vPenTest). The pitch: pen testing on a subscription. The actual sale: compliance-grade attestation, the SOC 2 letter more than the exploit. G2 ranked this cohort the top of 2026 pen-test tooling, which tells you the buyer is a compliance officer, not a hacker.

Web3 security shops (CertiK and similar). The pitch: contract audits. The actual sale: ecosystem capture. CertiK put $50,000 into Ethereum's security funding round per HackerNoon. That is a play to own the rails everyone else has to build on, and one audit fee is beside the point.

The hallway track

Three arguments will run hot between sessions this year.

One: does the Microsoft episode chill disclosure or organize it. In late May 2026 the company threatened legal action against researchers who published active-exploitation zero-days in Windows and Defender (Rescana, June 2). Half the floor will read that as a warning shot that makes people publish less. The other half will read it as the thing that finally forces a formal researcher-protection push. Which way it breaks is the actual story of the weekend.

Two: is there anything new left to say about AI security. Last year the talk moved from hype to defender plumbing, CI/CD and alert triage, and the recap crowd was already calling it SIEM fatigue (Cybersecurity Pulse, August 2025). Expect a real fight over whether model red-teaming is a new discipline or last year's tooling with a fresh label.

Three: who still does both Black Hat and DEF CON. Same week, same city, very different price and posture. The vendor-heavy Black Hat floor keeps growing while the independent-research crowd watches its oxygen. Expect grumbling about cost, badge prices, and whether the two events are drifting into different professions.

The thing the room will not say out loud: the independence in 'independent security researcher' is mostly gone. Bounty programs, platform retainers, and vendor red teams sign a large share of the checks now. So when the room rallies around researcher agency against Microsoft's lawyers, it is partly rallying against the hand that feeds it. You choose self-determination as a rallying cry precisely when you can feel it slipping. That is what the Agency theme is telling on.

The follow-up problem, and the 72-hour window

DEF CON runs on handshakes and handles, not LinkedIn requests. You will leave with a badge full of stickers, a phone full of Signal usernames, and a stack of people you swore you would remember by the Sunday closing ceremony. By the time you are back at your desk the warm window is closing, and the researcher you traded notes with at the Bug Bounty Village is just 'the one in the DeadTech shirt' in your memory. Met is built for that 72-hour gap: log who you met and why they mattered while the context is still in your head, before Vegas turns into a blur. It is iPhone-only and free to start. Grab it before you fly.

Download for iPhone

Read by researchers heading to DEF CON 34 who want the intel before they fly.

Get Met in your inbox

Field notes on conference networking, follow-up timing, and what we ship next. No spam, no AI hype.

No spam. Unsubscribe anytime. Replies go to support@sailquery.com.