The best part of BSidesLV/BlackHat/DEFCON is getting to meet the people you admire. I got a chance to nerd out with Thai Duong of calif.io today (photo proof!). Thai and team just posted their latest work - 3 remote exploits in FreeBSD - all critical issues if you use HA with your FreeBSD-based firewalls. Noteworthy is that these bugs were found months ago with relatively old model. Vulnerability discovery continues to accelerate!

Hello Las Vegas (and hackers following along at home)! I'm excited to share the first batch of our Out-of-Band / Baseboard Management Controller research at Black Hat USA today and DEFCON 34 this weekend. Read an exclusive by Ars Technica at:
Interested in checking your network? The pre-release of OOBscan is live on GitHub: https://github.com/runZeroInc/oobscan
Thank you to our friends at Dragos.com, NetRise.io, and all of the researchers abroad who helped with review & feedback!

Skipping Black Hat and DEFCON this year? Consider presenting at BSides Hanoi instead. Now in its second year, the conference takes place on August 5th, 2026, and a few more talk slots are still open - but the submission deadline is today. Apply here: https://www.bsideshanoi.net/en/call-for-paper
Thank you to everyone who has already submitted!

My favorite bugs are where the vendor doesn't consider it a vulnerability: How a USB-connected speaker can infect a PC without ever being touched: https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/

ATX Go is TONIGHT (a week early this month):
Hey gophers! Join us Wednesday (May 6th, today), 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, and a few short talks on Go. Bring a talk, a friend, or an idea!

ATX Go is a week early this month, tomorrow night!
Hey gophers! Join us Wednesday, 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, a few short talks on Go, and general discussion. Whether you write Go all day or just dabble on the weekends, come hang out and meet other folks in the Austin Go community.

RE: https://infosec.exchange/@runZeroInc/116493908814143481
Excited to share what we've been cooking for the last few months:
Interactive attack graphs, with hop-by-hop planning, support for over 220 protocols, and no-auth backplane enumeration to identify non-IP systems unauth over the network!
Our free trial includes a fun Demo Organization you can explore and converts into our free Community Edition at the end (with all of the same capabilities, just a lower asset limit)!

Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future:
https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/
Joseph Menn, renowned journalist & author of "The Cult of the Dead Cow," joins us for a special book signing event at RSAC! runZero and Mallory are thrilled to co-host a private book signing with renowned investigative journalist Joseph Menn during RSA Conference 2026! This is your chance to meet the man who writes the stories the industry talks about.
Join us to grab a signed copy:
Copyright 1998-2026 HD Moore