Meet YesWeHack at DEF CON 34

YesWeHack at DEF CON 34 in Las Vegas, 6–9 August 2026, featuring the Las Vegas skyline and a “Meet us there” message.

Las Vegas is calling once again!

From 6–9 August 2026, hackers, security researchers and cybersecurity professionals from around the world will gather at the Las Vegas Convention Center for DEF CON 34.

YesWeHack will be there throughout the event and, once again, we are proud to sponsor the DEF CON Bug Bounty Village.

Dedicated to all things Bug Bounty, the village gives security researchers, platforms and organisations a place to meet, share experiences and learn from one another through talks, workshops and practical challenges.

Three things not to miss from YesWeHack at the Bug Bounty Village:

  • An exclusive talk by Brumens
  • Our participation in a panel discussion on AI in Bug Bounty
  • Our Payload Plz Reloaded hacking challenge

What if the cache key itself is the vulnerability?

Cache poisoning research has traditionally focused on unkeyed inputs. But what happens when attacker-controlled data is mistakenly included in the cache key itself?

In ‘Cache Key Injection: Smuggling Poison Through the Door’, Brumens will explore how subtle cache misconfigurations can trigger cache key collisions and open the door to cache poisoning, CPDoS, cache deception and stored XSS. Expect practical insights into how these flaws can be identified, exploited and prevented.

Date: Friday, 7 August
Time: 3:00 PM
Location: Bug Bounty Village, Level 2, Rooms W206–W207

Navigating AI-assisted submissions

AI is reshaping offensive security and Bug Bounty, creating new questions around submission volumes, program scope, report quality and platform processes.

In the panel ‘Navigating AI-Assisted Submissions’, Selim Jaafar, YesWeHack’s Chief Customer Officer, will discuss how the industry is adapting alongside Tony Lee from HackerOne; Eddie Rios from Synack; Michael Skelton from Bugcrowd; and Alexander Wren from Intigriti. The session will be moderated by Shlomie Liberow.

Date: Friday, 7 August
Time: 2:00 PM–3:00 PM
Location: Bug Bounty Village, Level 2, Rooms W206–W207

The conversation will explore the challenges platforms are facing, the solutions they are putting in place and what researchers can do to succeed as AI-assisted security testing becomes increasingly common.

Take on ‘Payload Plz Reloaded’

At the Bug Bounty Village, you can put your skills to the test with Payload Plz Reloaded.

The challenge is to create one polyglot payload capable of exploiting as many vulnerabilities as possible. Your score will also take into account the length of your payload and the number of failed attempts.

To join, pick up a YesWeHack challenge coin from the village swag tables, or catch Brumen, Selim, or Pwnii, who might have some in their pockets, scan the QR code and log in with your YesWeHack account.

The challenge is only available onsite. The top three submissions will be contacted by email after the event and will receive exclusive prizes.

Grab Some Exclusive Swag!

Don't leave empty-handed! We are bringing hundreds of YesWeHack t-shirts, stickers, and tote bags that will be distributed directly from the Bug Bounty Village swag tables. These tend to go fast, so make sure you swing by early and don't miss out!

About us

YesWeHack is a leading Offensive Security and Exposure Management platform powered by a global community of 150,000+ ethical hackers. Built by hunters for hunters, we prioritize the researcher experience with a "Hacker-First" model featuring in-house triage, fast payments, and clear communication. Start hacking on programs from global leaders like Vinci, Tencent, L’Oréal, and Louis Vuitton, and continuously level up your skills through our Dojo training platform and an extensive library of practical guides published each year.