LC-2 · Software Danger Reports
LrrK Def Cuts
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Def Cuts **LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems. | Field | Value | | --- | --- | | Collection cutoff | 7 December 2023 | | Platform | Quiet Systems | | Series | DC-Y-2023 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF DEF CON 31 put one kinematic talk on the main stage: frequency-hopping disposable drones that degrade C-UAS jamming, while unprotected DIY command links stay open to RF denial. Black Hat 2023 briefings were NIL. ### Key judgments 1. **[Assessment — High confidence]** The only verified 2023 primary is Melendez and García, DEF CON 31 Track 4, 12 August 2023, with a live speakers page and slides plus demos on `media.defcon.org`. 2. **[Assessment — High confidence]** Aerospace Village DEF CON 31, IoT / Hardware / RF village pages, and Black Hat USA / Europe / Asia 2023 briefing landings added no in-scope title. InfoconDB lists a “Strix Interceptor” C-UAS demo that is not on the live DEF CON 31 speakers page and has no village primary, so it is not a signal. 3. **[Inference — Moderate confidence]** The year’s public conference signal is C-UAS effectiveness against hopping disposable airframes, not a named-product CVE on a flight stack or GCS. ## 01. Frequency-hopping disposable drones degrade C-UAS jamming *Event / publication dates: Saturday 12 August 2023, 11:00 PT (45 min), DEF CON 31 Track 4.* | Field | Value | | --- | --- | | Venue | DEF CON | | Component | firmware | | Product | Disposable / DIY drones (unnamed); C-UAS jammers (unnamed) | | CVE / advisory | no CVE | | Patch | none | | Exploit status | public writeup | **Verified record — [Fact — A1]** David Melendez and Gabriela “Gabs” García presented *Spread spectrum techniques in disposable drones for anti drone evasion* on DEF CON 31 Track 4. Official speakers page: `https://www.defcon.org/html/defcon-31/dc-31-speakers.html#Melendez`. Slides and demos sit on the DEF CON 31 `media.defcon.org` presentations directory; video is on the DEF CON channel (`https://www.youtube.com/watch?v=8Ng91UY3D2M`). No CVE, advisory, Exploit-DB ID, or GitHub repo was published with the talk. Failure class on the record: unprotected DIY drone command links stay exposed to RF denial, so frequency-hopping airframes degrade C-UAS jamming. **Exposure.** Act on C-UAS: hop-capable disposable airframes reduce the effect of RF denial that assumes a fixed command link. Move on the DIY airframe: an unprotected command link can still be denied, which is loss of control and a crash or fly-away, not a new airframe CVE. **Intelligence assessment.** [Assessment — High confidence] This is the only 2023 conference primary that names both a UAS command-link class and a C-UAS physical consequence. [Uncertainty] The talk does not name a vendor product, CVE, or patched build. [Inference — Moderate confidence] C-UAS claims that treat disposable DIY links as fixed-frequency will overstate jam effectiveness against hopped airframes. **Opportunity.** Passport whether a given disposable or DIY command link is authenticated, or only hopped. Watch C-UAS product claims that assume a static DIY bearer. Lab hop-versus-jam as a class of outcome (denied versus still-commanded), not as a recipe. **LRRK relevance.** Control Fabric on the DIY command link. Watch on C-UAS effectiveness claims. Lab and KAT from RF denial to loss of Move. Sense-Move-Act: Act is the C-UAS side; Move is the airframe that stays or falls off the link. **Confidence.** High on the talk page, slides, and after-record. Moderate as a fleet case: no named product or CVE. ## Forward indicators 1. A vendor or C-UAS advisory that names hop-capable disposable airframes as a jam-effectiveness limit. 2. A CVE or maintainer note on DIY / open command-link authentication that cites this talk or the same failure class. 3. A later DEF CON or Black Hat briefing that names a product C-UAS against hopped disposable drones. 4. Any live primary for the InfoconDB “Strix Interceptor” item, which stays unrecorded until a speakers or village page exists. > **Collection integrity.** Public sources only. No invented talks. No exploit steps, PoCs, or payloads. Also searched in 2023 with no additional in-scope talk: Aerospace Village DEF CON 31 talk list (`aerospacevillage.org/defcon-31-talks`) — space, ISS, 737, weather-radiosonde, satellite-comms; GPS appears as a satellite service, not a vehicle/UAS briefing. IoT / Hardware / RF village 2023 pages: no in-scope title. InfoconDB “Strix Interceptor” excluded (no live DEF CON 31 or village primary). Black Hat USA / Europe / Asia briefings 2022–2026: NIL. Excluded as not talks or not in filter: paid trainings; Drone Zone or cage/CTF activities without a named talk; manned-aviation datalinks; satellite / space-mission talks without a vehicle GNSS or UAS datalink focus. Last in-scope conference day 2023 is Black Hat Europe, 7 December 2023. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>