Wiring the Harness: Orchestrating Frontier Models for Vulnerability Hunting at Scale

Tony Martin, Sr. Principal Engineer & Offensive Security Research lead, INT31 Security Research, Intel

Arie Haenel, Principal Engineer & Offensive Security Research lead, INT31 Security Research, Intel

Friday, 14:30 – 15:30, Creator Stage 4

While frontier models are powerful, simply asking one to “find vulnerabilities” is far less effective than pairing with a well-designed harness, a gap that widens further down the stack and peaks at embedded firmware. During Project Glasswing, Intel scanned hundreds of repositories, from firmware to containers. This talk covers common pitfalls in LLM vulnerability hunting and presents a multi-stage harness: reconnaissance and context compression, multi-model hunting, deduplication, false positive detection, and verification. We will explore selecting the right models per stage, cutting token costs, and, the real battle, reducing false positives, especially for lower-level code where accuracy is hardest.

Tony Martin is a Sr. Principal Engineer in Intel’s INT31 Security Research team, where he focuses on emerging threats, software architecture and AI security. He has discovered thirty CVEs and one CWE and is senior staff at DEF CON’s Packet Hacking Village.

Arie Haenel is a Principal Engineer at Intel, where he leads ASSERT, an Offensive Security Research team. He has over 25 years of professional experience, in security research and security product development on a vast number of embedded platforms, at Intel, Cisco and NDS. In his spare time, Arie teaches security engineering as an Adjunct Lecturer at the Lev Academic Center.

PhantomShell: As If Firewalls Didn’t Exist

Khael Kugler, Lead Offensive Security Engineer, Praetorian Security, Inc.

Saturday, 13:00 – 14:00, Creator Stage 6

PhantomShell is a Linux command & control implant that sniffs traffic of active TCP services to create a bidirectional C2 channel through any open port, using only stateful inbound traffic. It captures packets at the link layer, allowing it to read packets destined for legitimate services. Responses are constructed as raw TCP frames with sequence numbers derived from the original connection, making them difficult to distinguish from the service’s own replies. This effectively turns every open service port into a bind shell, making the implant effectively impossible to firewall so long as any service remains externally accessible.

Khael Kugler is a Lead Security Engineer at Praetorian, where he primarily executes on red team and IoT engagements. Khael also volunteers as a red teamer for multiple CCDC regions, primarily focusing on linux persistence for SECCDC and WRCCDC (if you’re interested in helping, reach out!).

There’s A Bug in My Boot! Finding Vulnerabilities in U-Boot

Jared Stroud, Lead Reverse Engineer, The Johns Hopkins University Applied Physics Lab

Saturday, 15:00 – 16:00, Creator Stage 6

Bootloaders underpin the security of modern embedded systems. Their privileged position in the tech stack often means a vulnerability early in the boot process can result in total system compromise. Despite this, they frequently lack modern software security protections (ASLR, CFI, Stack Canaries), making them an easier target to exploit. This talk will explore hardware-in-the-loop, emulation, and native binary fuzzing approaches with U-Boot, a popular embedded system bootloader for networking devices, and the challenges each approach presents.

Jared Stroud is a Lead Reverse Engineer at The Johns Hopkins University Applied Physics Lab. Currently he’s pursuing a Doctorate of Engineering focused on scaling vulnerability identification and remediation in embedded systems. For the past 7 years Jared has documented independent security research at Arch Cloud Labs (https://www.archcloudlabs.com/projects), and has presented workshops on reverse engineering topics at DEF CON, Shmoocon, and BSides Rochester.

Why Couldn’t I See My Own Drone? Remote ID, ESP32s, and the Packet Trail to Friend or Foe

Will Hatzer, Founder, GameChangersAI / Team Charity Case

Charles Grow, Hardware Designer / RF Researcher, Team Charity Case / GameChangersAI

Saturday, 16:00 – 17:00, Creator Stage 6

Friend or Foe started when adding Remote ID support to an Android airspace app still failed to detect our own DJI drone. This led us into DJI Wi-Fi Beacon behavior, vendor information elements, ESP32 promiscuous capture, and conservative evidence handling using Bayesian fusion. This talk covers practical packet analysis techniques for Remote ID (BLE and Wi-Fi), hardware tradeoffs for reliable scanning, and how to avoid turning weak signals into overconfident alerts. Attendees will learn how to build honest, low-cost RF sensors and interpret packet evidence responsibly.

Will “OGThorne” Hatzer is a security engineer, adversarial researcher, and founder of GameChangersAI. He works in security engineering at OpenAI and builds open-source tools across RF, Android, embedded systems, and defensive security. A former DEF CON Car Hacking Village speaker, his work includes a bot-detection patent and Hyundai BlueLink research later referenced by CISA.

Charles “OhYou_” Grow is a hardware designer, RF researcher, and ham radio operator. He designed the Friend or Foe badge hardware, solving component layout, USB-C access, GPIO conflicts, and RF ground-plane challenges. His background in fox hunting, electronics, and field debugging helped turn early prototypes into a practical, wearable device.

Ghost Followers: Using AI to Unmask Fake LinkedIn Profiles at Scale

Aiswarya Venkitesh, Principal Cloud Solution Architect, Microsoft

Saturday, 17:00 – 18:00, Creator Stage 6

LinkedIn hosts over 1 billion profiles and a growing number are fake. From AI-generated profile photos to synthetic work histories, adversaries use fake identities for spear-phishing, social engineering, and influence operations. This talk breaks down the anatomy of a fake LinkedIn profile and demonstrates an AI-powered detection framework using behavioral signals, image forensics, and network graph analysis. Attendees will leave with a hands-on methodology and open-source toolset to identify synthetic identities before they become insider threats. Prior knowledge of networking fundamentals is helpful; no machine learning background is required.

Aiswarya Venkitesh is a Principal Cloud Solution Architect at Microsoft Canada with 13+ years in Data & AI, specializing in agentic AI architecture, multi-agent orchestration, and enterprise Azure deployments. Ranked #4 globally in IT & Tech by Favikon with 55,000+ LinkedIn followers, she studies identity authenticity and influence operations on professional networks as both a practitioner and creator. She is a confirmed keynote speaker at Futura AI Conference 2026 and author of the forthcoming book The Agentic AI Playbook.