DEF CON 32 - Reflections on a Decade in Bug Bounties - Nikhil Shrivastava & Charlie Waterhouse

In this talk, I will share my journey from a novice to a seasoned hunter. I will explore how I used to report low-impact, informative bugs when I first started, and how I progressively improved by learning from the community, embracing failures/duplicates, and incorporating feedback from triage teams and clients. This journey of continuous learning and adaptation led me from reporting low vulnerabilities to effectively chaining and converting them into critical impacts. This session is designed for both aspiring and experienced bug bounty hunters. By reflecting on a decade of lessons learned, I will aim to provide valuable takeaways that can help others navigate their own paths in bug bounty hunting and enhance their skills. Additionally, one Synack triage team member will join me on this talk to help differentiate triage thinking from bug bounty hunters' thinking, providing valuable insights into the collaborative process of vulnerability reporting to acceptance.

DEF CON 32 - From Easy Wins to Epic Challenges: Bounty Hunter Edition - Daniel Blaklis Le Gall
▶︎

DEF CON 32 - From Easy Wins to Epic Challenges: Bounty Hunter Edition - Daniel Blaklis Le Gall

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini
▶︎

DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini

DEF CON 32 - Leveraging AI for Smarter Bug Bounties - Diego Jurado & Joel Niemand Sec Noguera
▶︎

DEF CON 32 - Leveraging AI for Smarter Bug Bounties - Diego Jurado & Joel Niemand Sec Noguera

From zero to 6-digit bug bounty earnings in 1 year - Johan Carlsson - BBRD podcast #3
▶︎

From zero to 6-digit bug bounty earnings in 1 year - Johan Carlsson - BBRD podcast #3

The Bug Hunter's Methodology - Application Analysis | Jason Haddix
▶︎

The Bug Hunter's Methodology - Application Analysis | Jason Haddix

DEF CON 31 - Badge of Shame  Breaking into Secure Facilities with OSDP -Dan Petro, David Vargas
▶︎

DEF CON 31 - Badge of Shame Breaking into Secure Facilities with OSDP -Dan Petro, David Vargas

Hacking on Bug Bounties for 10 years: Shubs' (@infosec_au) Keynote at BSides Ahmedabad 2023
▶︎

Hacking on Bug Bounties for 10 years: Shubs' (@infosec_au) Keynote at BSides Ahmedabad 2023

DEF CON 32 - Defeating EDR Evading Malware with Memory Forensics - Case, Sellers, Richard, et al.
▶︎

DEF CON 32 - Defeating EDR Evading Malware with Memory Forensics - Case, Sellers, Richard, et al.

Practical Bug Bounty
▶︎

Practical Bug Bounty

DEF CON 32 - Practical Exploitation of DoS in Bug Bounty - Roni Lupin Carta
▶︎

DEF CON 32 - Practical Exploitation of DoS in Bug Bounty - Roni Lupin Carta

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh
▶︎

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh

DEF CON 31 -  Smashing the State Machine the True Potential of Web Race Conditions - James Kettle
▶︎

DEF CON 31 - Smashing the State Machine the True Potential of Web Race Conditions - James Kettle

Modern Adversarial Reconnaissance – Long Live the External
▶︎

Modern Adversarial Reconnaissance – Long Live the External

DEF CON 32 - Winning the Game of Active Directory - Brandon Colley
▶︎

DEF CON 32 - Winning the Game of Active Directory - Brandon Colley

"Easiest" Beginner Bugs? Access Control and IDORs
▶︎

"Easiest" Beginner Bugs? Access Control and IDORs

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
▶︎

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

DEF CON 33 - China's 5+ year campaign to penetrate perimeter network defenses - Andrew  Brandt
▶︎

DEF CON 33 - China's 5+ year campaign to penetrate perimeter network defenses - Andrew Brandt

FASTEST Way to Learn Bug Bounty and ACTUALLY Get a Job (2026)
▶︎

FASTEST Way to Learn Bug Bounty and ACTUALLY Get a Job (2026)

#NahamCon2024: Modern WAF Bypass Techniques on Large Attack Surfaces
▶︎

#NahamCon2024: Modern WAF Bypass Techniques on Large Attack Surfaces