DEFCON 2026
Join Finite State at DEF CON 2026 to explore how security teams can move beyond theoretical findings and understand how vulnerabilities actually manifest across connected systems, firmware, and shipped software.
As connected systems become increasingly software-defined, security teams face growing challenges understanding what is actually deployed, identifying which vulnerabilities are operationally relevant, and responding quickly across complex software supply chains.
At DEF CON, those conversations move beyond theory. Offensive researchers, red and blue teams, embedded security practitioners, and product security engineers are focused on how systems fail in practice, where visibility breaks down, and how exploitability differs from vulnerability volume.
Finite State helps teams cut through fragmented tooling and incomplete visibility by transforming firmware, binaries, source code, supplier SBOMs, and third-party outputs into a continuous, artifact-backed security workflow grounded in what actually ships.
By unifying firmware and source intelligence in minutes, Finite State enables teams to prioritize reachable and relevant vulnerabilities, accelerate impact analysis, maintain traceable VEX decisions, and continuously generate audit-ready security outputs across evolving products and releases.
🎯 Join Finite State at AppSec Village at DEF CON
This year at AppSec Village, Finite State is bringing a hands-on incident response challenge designed around realistic operational technology (OT), connected device, and software supply chain security scenarios.
Factory Floor MVP Incident Response Challenge
Game Session 1: Friday, August 7, 1:00–3:00 PM
Game Session 2: Saturday, August 8, 1:00–3:00 PM
Step into the role of a defender responsible for protecting a modern manufacturing environment as you investigate active cyberattacks across industrial control systems, engineering workstations, sensors, historians, and connected infrastructure.
Working as a team, participants will analyze indicators of compromise, investigate suspicious activity, uncover attacker actions, and make incident response decisions before operational disruption or safety impacts occur.
Designed for the DEF CON community, the challenge blends offensive security concepts, incident response, supply chain security, firmware analysis, and practical investigative techniques into a collaborative experience grounded in real-world scenarios. Participants will explore how vulnerabilities actually manifest in deployed systems while evaluating exploitability, attack paths, reachability, and operational risk.
What You'll Experience
- Investigating attacks across OT and connected device environments
- Discovering adversary activity spanning initial access, persistence, lateral movement, and actions on objectives
- Analyzing firmware, SBOMs, threat intelligence, and forensic evidence
- Balancing security decisions against operational and safety requirements
- Applying practical incident response workflows used in modern manufacturing environments
Built for offensive security researchers, product security engineers, red and blue teams, incident responders, embedded security practitioners, and anyone interested in how systems fail in the real world, this challenge emphasizes hands-on learning, collaborative problem solving, and realistic security tradeoffs.
Following each session, teams will participate in a facilitated debrief examining attack paths, visibility gaps, operational impacts, and opportunities to improve resilience across connected systems and software supply chains.
Stop by AppSec Village at DEF CON and put your investigation skills to the test.
🎤 Hear from the Finite State Team at DEF CON
Dr. Strangepwn: How I Learned to Stop Worrying and Love the LLM
Speaker: Larry Pesce, VP of Services
Date: Friday, August 7
Time: 12:30 PM – 1:15 PM
Location: Stage 3, IoT Village
As AI transforms offensive security, what role will human expertise play? Join Larry Pesce as he shares how an AI-driven penetration testing agent uncovered a previously undisclosed IoT vulnerability in hours, explores where AI excels and where it falls short, and provides a practical blueprint for building AI-assisted security testing workflows.
AI Safety Theater: What the RAISE Act Regulates, and What It Does Not
Speaker: Joshua Marpet, Senior Product Security Consultant
Date: Saturday, August 8
Time: 5:00 PM – 5:30 PM
Location: Creators Stage 1
New AI safety regulations are arriving quickly, but do they meaningfully reduce risk? Joshua Marpet examines New York's RAISE Act through a security researcher's lens, highlighting where the legislation strengthens transparency, where critical gaps remain, and what security professionals should understand as similar laws emerge across the United States.
🛡️ Why Meet with Finite State?
Talk with Finite State about practical approaches to connected device security, firmware analysis, vulnerability prioritization, and operational product security workflows.
Meet with our team to:
- Transform firmware and software artifacts into a continuous, audit-ready assurance workflow
- Unify firmware, binary, and source intelligence across products and environments
- Reduce vulnerability noise with reachability-based prioritization
- Accelerate response from new CVE to stakeholder-ready outputs
- Improve collaboration between offensive security, product security, PSIRT, and engineering teams
- Maintain defensible security evidence and continuous compliance outputs across releases
🎯 Key Takeaways
Connect with our team at DEF CON for practical guidance on firmware-grounded product security, exploitability-driven vulnerability prioritization, and understanding how modern connected systems actually fail in operational environments.
Secure every release. Prove compliance continuously.
We will be at DEF CON. Will you?
Speakers

Larry Pesce
VP of Services
Finite State

Joshua Marpet
Sr. Product Security Consultant
Finite State