DEF CON 34 preview: The theme is “Agency”, the villages get bigger, and the industry’s biggest hacker weekend arrives with a very specific problem list

Las Vegas, 6–9 August. DEF CON returns to the Las Vegas Convention Center West Hall this month for its 34th edition under a single-word theme — “Agency” — that the organisers have chosen with the deliberateness they usually reserve for programme design. Self-determination in technology use, the ability to chart one’s own course as an operator or defender or citizen, and the practical work of helping others do the same: that is the theme’s stated framing. The subtext, for anyone who has read the community’s mood through the year of election-adjacent AI-enabled information operations and the run of large-scale incidents that reshaped the industry’s risk perception, is the specific one — the person, the researcher, the small organisation, up against the increasing scale of everything else.

The 30,000-plus attendees who will file through West Hall over four days do not need the theme spelled out. The Villages — the specialist rooms that have been DEF CON’s most durable innovation for two decades — are, in aggregate, the actual industrial-scale defensive community’s annual working session. This year’s programme includes an expanded AI Village, an Adversary Village, an Aerospace Village, an AppSec Village, the always-consequential IoT Village and Crypto & Privacy Village, plus the ecosystem of newer and specialist rooms that keeps the programme growing.

The AI Village is where the field’s most consequential work will be shown

The AI Village has grown, over recent editions, from a curiosity into what is now — on any honest read — one of DEF CON’s most operationally consequential rooms. The 2026 programme will include red-teaming methodologies for large language models, jailbreak taxonomies and their limits, prompt-injection attack patterns against tool-using agents, model-extraction and membership-inference research, watermarking-and-provenance defensive tooling, and — the newer chapter — the specific security architectures around agentic AI deployments.

The audience for the AI Village is now materially broader than in earlier editions. Enterprise security teams from Fortune 500 organisations, government red teams, model-lab security researchers, academic security PhDs, and the compliance-and-audit cohort — all show up because their organisations now have production AI systems whose security posture they cannot honestly assess without the community-level knowledge the Village produces.

Adversary Village and the maturation of threat-emulation

The Adversary Village — dedicated to purple-team methodology, threat-actor emulation, and the shared language between offensive and defensive work — has become one of DEF CON’s most professionalised rooms. The programme covers specific threat-actor tradecraft (with all appropriate ethical framing), detection engineering, purple-team programme design for enterprise deployments, and the ongoing work to build shared vocabularies (MITRE ATT&CK, D3FEND, and their community extensions) that let defenders and adversary-simulators talk about the same thing.

The professionalisation is the story. Ten years ago, threat emulation was an ad-hoc consultancy practice. Today, the Adversary Village is where enterprise security programmes come to learn how to run credible purple-team engagements as a durable capability rather than a project. That is the shape of a maturing category.

Aerospace Village: dual-use, national security, and the specific problem set

The Aerospace Village continues its unique niche at DEF CON — the collaboration between the security research community, aerospace primes, government agencies, and the specific research programmes that address dual-use systems, satellite security, and the operational-technology tail of aerospace and defence. The Village runs hands-on challenges (satellite CTFs, avionics-security workshops), technical talks, and, importantly, the working relationships that produce the coordinated-disclosure ecosystem for aerospace vulnerabilities.

IoT Village and the operational-technology tail

The IoT Village and its adjacent operational-technology-focused rooms will, as always, be where the industry’s messiest security problems get worked. Consumer IoT devices, medical devices, industrial control systems, building automation, and the very long tail of connected hardware that ends up in critical infrastructure — the room is where the vulnerabilities get demonstrated and, increasingly, where the vendors that have shown up to work on them collaborate with the researchers who find them. The dynamic is healthier than it was five years ago; the underlying problem set is still enormous.

Crypto & Privacy Village and the post-quantum year

The Crypto & Privacy Village returns to a room where post-quantum cryptography migration — which moved from research topic to operational project plan at RSA earlier in the year — will occupy a serious share of the programme. Cryptographic inventory tooling, hybrid TLS deployments, hardware-security-module lifecycle planning, and the specific migration challenges for regulated buyers are all on the community’s mind. The Village is where the community-level knowledge that will accelerate migration for the industry as a whole gets exchanged.

Election infrastructure and civic-cybersecurity readiness

Election infrastructure, civic-cybersecurity readiness, and disinformation-operations research have their own track and their own programming, and the mood is more sombre than at any recent DEF CON. The specific research programmes and community-of-practice conversations continue: identity-based attacks on election workers, disinformation infrastructure, and the resilience of state-level systems. The community’s contribution is the sustained empirical work that professional research programmes and civic-infrastructure operators can build on.

The corporate-security cohort shows up in force

The presence of CISOs, security-architecture teams, and enterprise-security programme managers at DEF CON has grown steadily over the recent editions. The community is no longer a purely researcher-and-hacker room. That change is a mixed blessing — the enterprise buyer is more numerous, the vendor presence is larger, and some of the community’s original character has evolved. What the shift also produces is a research-community-to-enterprise-buyer feedback loop that is materially healthier for the industry than it was ten years ago. Research that solves a real defensive problem gets adopted; research that does not gets refined.

The Contests, the CTFs, and the community’s centre of gravity

The competitions — the flagship Capture-the-Flag tournament, the hardware-hacking villages, and the ecosystem of smaller contests across the Villages — remain DEF CON’s community centre of gravity. The CTF is one of the most technically demanding competitions in the security industry, and its winners get watched by every serious enterprise-security recruiter for the next twelve months. The hardware-hacking rooms remain where the industry’s most creative practical research surfaces first.

What to watch, on the ground

  • The AI Village red-teaming and agentic-AI security tracks. The field’s most consequential work.
  • The Adversary Village purple-team programming. Enterprise-grade methodology.
  • The Aerospace Village dual-use research. Coordinated disclosure with the primes and agencies.
  • The Crypto & Privacy Village post-quantum sessions. Where the community-level migration knowledge lives.
  • The Election Village and civic-infrastructure programming. Sober, sustained research.

Open questions

Does the AI Village’s red-teaming and agentic-AI security work converge on shared community standards through the second half of 2026? Do enterprise buyers’ willingness to fund adversary-emulation and purple-team programmes hold as a durable line item, or slip when other security priorities compete for the budget? And does the post-quantum crypto migration retain the tempo the regulated-industry playbook requires, or slip into a longer horizon as the fiscal cycle tightens?

Bottom line: DEF CON 34’s Agency theme is an accurate frame for a community that has spent a decade professionalising itself into the industrial infrastructure of the modern cybersecurity industry without losing the original hacker-community character that made the research and the culture worth building on. The Villages will be where the year’s most consequential defensive work gets shown. Agora Media will be reporting from West Hall.