
Members of the Raxis pentest team joined me last week at the Las Vegas Convention Center for DEF CON 34. As always, we came home with more homework than souvenirs.
This year’s theme was “Agency,” a call to take back control of the technology that increasingly makes decisions for us. The idea showed up everywhere, right down to the badge itself, an open and fully inspectable device from Bunnie Huang that doubles as a hardware security token you can actually audit.
A few sessions landed especially close to the work we do every day.
Identity Is Still the Shortest Path In
One session walked through escalating from a low-privilege foothold to full domain compromise by way of Active Directory Certificate Services. Another detailed novel vulnerabilities that force a Kerberos downgrade. Neither is exotic. Both describe the kind of misconfiguration our team finds routinely on internal engagements, and both are worth checking in your environment.
Trust Is Weaponized
A researcher demonstrated turning legitimate Microsoft applications into a phishing platform, which means the sender your users have been trained to trust becomes the delivery mechanism. Another showed a persistent browser-in-the-middle technique that survives the controls most organizations assume will stop credential theft.
The Devices Around Us Aren’t Secure
A dealer-installed anti-theft system exposed more than a million vehicles over Bluetooth. A single wildcard certificate exposed 1.1 million cameras sitting behind an IoT cloud. These are not research curiosities. They are the same class of vendor shortcut we find on client networks.
AI Moved from Novelty to Infrastructure
Last year the AI conversation was mostly about what these tools might eventually do. This year it was about breaking the runtimes and agent sandboxes that organizations have already deployed. If your company adopted an AI platform in the past twelve months, it is now part of your attack surface whether or not anyone has tested it.
Our Takeaways
Before attending DEF CON this year, our team worked the Raxis booth at Black Hat, and this ties directly to what we saw there. There are several pentest companies that want organizations to trust their security to automated processes and AI without humans taking part in the process. While that saves money on testing, it misses the key attacks that are the biggest threats.
What I keep coming back to is DEF CON’s theme. Agency means knowing what your systems are actually doing instead of trusting that someone else (or some system) has handled it. That is the entire premise of a good human-led penetration test, and it is why we make the trip every August.

Brian Tant
About The Exploit
The Exploit is written by Raxis penetration testers. Every post is a technical writeup from someone who runs engagements for a living, with code, command output, and the reasoning behind each step. Topics include exploit research, vulnerability disclosure, tool development, and the offensive techniques showing up in current client work.
Raxis Discovered Vulnerabilities
View the CVEs and bugs that Raxis pentesters have uncovered and submitted.
Work With the Pentesters Who Wrote This Blog
The engineers behind these posts run real engagements every week. Put them on your network, web apps, APIs, or cloud and see what an attacker would find first.
Blog Categories
- AI
- Careers
- Choosing a Penetration Testing Company
- Exploits
- How To
- In The News
- Injection Attacks
- Just For Fun
- Meet Our Team
- Mobile Apps
- Networks
- Password Cracking
- Patching
- Penetration Testing
- Phishing
- PTaaS
- Raxis Discovered Vulnerabilities
- Raxis In The Community
- Red Team
- Security Recommendations
- Social Engineering
- Tips For Everyone
- Web Apps
- What People Are Saying
- Wireless