
We’re packing up for Las Vegas to take over at BSides LV, Black Hat USA, and DEF CON! Don’t miss out on our DEF CON kickoff with an exclusive dual-session evening: join offensive security expert Jason Haddix and Anthropic’s Rob Bair for a candid breakdown of AI guardrails, and then test your dark web monitoring skills with high-risk digital threats in the CTF: Darkroom by Flare Academy.
Whether you want to learn from our researchers about infostealers, shadow IT, AI guardrails, and more, grab swag, book a meeting, or test your skills in a CTF, here’s everything you need to know to find us.
Join the Flare Academy Discord channels #announcements and #events-meetups for exclusive swag drops (including the bucket hat!).

Where Will Flare Be During Hacker Summer Camp?
Read below for where we can meet you.
BSides Las Vegas (August 3–5) | Tuscany Suites
Stop by to say hi and pick up a swag bag at our booth.
We’ve also got two speaking sessions you won’t want to miss:
S.L. Confidential: The Dirty Secrets of InfoStealers – TOKEN: 3
Olivier Bilodeau, Principal Cybersecurity Researcher; Eric Boivin, Senior Technical Platform Specialist
Monday, 2:00–2:45 PM | Skytalks | Sienna
Hear from cybersecurity practitioners who read stealer logs for a living. After thousands, you stop seeing credentials and start seeing people: the CEO’s kids’ school names autofilled in the browser, the error message they Google translated at 2am, the bank accounts, the affair, the password they reuse for everything. Stealer logs are the most intimate piece of intelligence in our industry, and they’re sold for the price of a sandwich. Take a look inside several at this talk. Real logs, real victims, including some of the operators themselves, and the full sweep of what 50 million of them floating around the underground looks like at ground level.
Criminal Hijacking: Profiling Threat Actors Engaged in Session Takeover with Infostealer Logs
Eric Clay, Head of Flare Research; Eric Boivin, Senior Technical Platform Specialist
Tuesday, 3:00–4:00 PM | PasswordsCon | Tuscany
Learn about findings from a novel campaign that turned infostealer malware against cybercriminals. By seeding a cracked version of BLTools, a credential checker used almost exclusively in underground forums, a threat actor effectively doxxed hundreds of fellow criminals and created a unique intelligence windfall in the process. This dataset offers an unfiltered view into real-world operations behind account takeover, financial fraud, romance scams, and credential monetization. Rather than observing attackers from the outside, we analyze their behavior from within, including their tools, environments, workflows, and operational mistakes.

Black Hat USA (August 4–6) | Mandalay Bay
Our leaders and researchers are onsite and happy to connect, just a short trip from the show floor. Here’s our availability:
- Tuesday, August 4 | 2:00–6:30 PM PT
- Wednesday, August 5 | 8:30 AM–6:30 PM PT
We’ve also got an exciting speaking session:
ShadowHunt 2.0: Uncovering Shadow IT and Hidden Secrets
Yakir Kadkoda, Co-Founder & CTO at Lava; Assaf Morag, Cybersecurity Researcher
Tuesday, August 4 | 5:15–6:45 PM | Arsenal Station 3, Business Hall
ShadowHunt is a tool designed to expose one of the most dangerous blind spots in modern enterprise security: shadow IT on public repositories.
In today’s decentralized, developer-driven world, employees often use personal accounts (GitHub, Docker Hub, Helm Charts) to push company code, test infrastructure, or fork internal projects, without anyone knowing. ShadowHunt identifies and maps these personal repositories back to organizational employees by analyzing public repository activity (GitHub, Docker Hub, Quay, GIST, GCHR), commit metadata, manifests, templates and contributor patterns. Once linked, it scans those personal repos for leaked secrets such as tokens, keys, and config files that quietly jeopardize your organization’s security.

DEF CON 34 (August 6–9) | Las Vegas Convention Center
Find us at booth #1405 and we’ll also be at Red Team Village. Join us at the Red Team Party on Friday, August 7, 7:00 PM, at the Asylum Bar + Arcade inside AREA15.
Flare Academy & Darkroom CTF (August 6) | Renaissance Las Vegas Hotel
We’ve got a lot to offer in one place: food and drink, panel discussion, limited edition Flare Academy swag, and a hands-on CTF with prizes for the top competitors.
Here’s our agenda for the evening:
- 5:00–5:30 PM: Meet fellow cyber practitioners over food and drinks
- 5:30–6:30 PM: Flare Academy Discussion: AI, Offense, and the Limits of Guardrails, which will go in deep on what AI safety actually looks like from the inside, where it breaks down under real adversarial pressure, and what practitioners need to understand about the threat models that AI companies are, and aren’t, defending against. Our panelists are:
- Rob Bair, head of Cyber & National Security Policy at Anthropic
- Jason Haddix, CEO, Hacker, and Trainer at Arcanum Information Security
- Norman Menz, CEO at Flare
- 6:30–7:00 PM: Debrief the discussion with fellow attendees over more food and drinks, and refuel before the CTF
- 7:00–9:00 PM: Darkroom CTF, hosted by Olivier Bilodeau, Principal Cybersecurity Researcher, and Eric Boivin, Senior Technical Platform Specialist
Space is limited, so register to reserve your spot.
We have one more exciting talk for you by one of our researchers:
Hacking the Hackers who Hack Hackers: Supply-Chain Backdoors in Underground VPN Infrastructure
Assaf Morag, Cybersecurity Researcher
Friday, August 7 | 3:00-4:00 PM | Exhibit Hall West 3 – 903 (Main Track 5)
Underground VPN and tunneling ecosystems are widely used to monetize compromised servers and sell “free internet” access through SSH, SOCKS, and multi-protocol tunnels. These operations rely heavily on open-source infrastructure management tools deployed on rented or hacked Linux servers. But what happens when the tools themselves are weaponized?
In this talk we dissect FirewallFalcon Manager, a VPN/SSH server management toolkit widely promoted in Telegram communities. While it presents itself as a legitimate open-source platform, our analysis reveals a multi-layered supply-chain attack targeting the very operators who deploy it.
See You in Vegas
From infostealers and session takeover to shadow IT and AI guardrails, our researchers are bringing a full slate of talks and hands-on fun to Hacker Week. Keep an eye on the Flare Academy Discord channels #announcements and #events-meetups for real-time updates all week long.
Hope to see you there!
Flare Academy & Darkroom · Live from DEF CON
The Security Front Lines: Expert AI Panel + Live CTF Competition
Kick off DEF CON with an exclusive dual-session evening. Join offensive security expert Jason Haddix and Anthropic’s Rob Bair for a candid breakdown of AI guardrails, then put your skills to the test in a live-fire threat hunting competition with great food and drinks.





