LC-2 · Software Danger Reports
LrrK Def Cuts
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Def Cuts **LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems. | Field | Value | | --- | --- | | Collection cutoff | 9 August 2026 | | Platform | Quiet Systems | | Series | DC-Y-2026 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF DEF CON 34 put three kinematic items on Creator Stage and village stages: PX4 memory-safety and timing flaws that can deny vehicle control, Remote ID beacons that consumer receivers miss, and C-UAS detect-to-respond chains that fail on authority, coverage, and cheap detectors. Black Hat USA 2026 briefings were NIL. The DEF CON 34 `media.defcon.org` presentations folder was empty at collection. ### Key judgments 1. **[Assessment — High confidence]** Three titled DEF CON 34 items have live schedule and creator-talk primary pages. No after-record was on `media.defcon.org` at collection (folder empty). 2. **[Assessment — High confidence]** Black Hat USA 2026 briefing pages had no in-scope title at collection. Black Hat USA / Europe / Asia briefings 2022–2026 remain NIL. Excluded DC34 titles (consumer GPS-tracker IoT, jetskis, EOD bot, manned CPDLC / AFDX / electronic conspicuity, NMEA 2000 vessel IDS, maritime NTN) are outside the UAS / ROV / UUV / USV / vehicle-GNSS filter. 3. **[Inference — Moderate confidence]** Until slides land, the PX4 failure class is established by the official talk title and listing, not by a talk-cited CVE. Other PX4 NVD entries exist for other MAVLink / FTP / geofence issues and are not cited on these talk pages. ## 01. PX4 MAVLink logging path: memory-safety and timing flaws can deny control *Event / publication dates: Saturday 8 August 2026, 14:00 PT (30 min), DEF CON 34 Aerospace Village / Creator Stage 5.* | Field | Value | | --- | --- | | Venue | village | | Component | software | | Product | PX4 Autopilot (MAVLink logging path) | | CVE / advisory | no CVE | | Patch | none | | Exploit status | public writeup | **Verified record — [Fact — A1]** Nefeli Georgilas presented *Racing PX4: Memory Safety and Timing Vulnerabilities* on the DEF CON 34 schedule and creator-talks pages (`https://defcon.org/html/defcon-34/dc-34-schedule.html`, `https://www.defcon.org/html/defcon-34/dc-34-creator-talks.html`). Failure class on that record: memory-safety and timing / TOCTOU flaws in PX4’s MAVLink logging path can desynchronize command and telemetry state and deny vehicle control. No CVE or advisory is published with the talk. Talk pages do not cite existing PX4 NVD entries for other MAVLink / FTP / geofence issues; those IDs are not attached here. No Exploit-DB ID. No GitHub repo published with the talk. No after-record on `media.defcon.org` as of collection. UNLV and Aerospace Village LinkedIn notices exist as supporting mentions only, not primaries. **Exposure.** Move and Act: desynchronized command and telemetry is loss of a trusted control loop. Physical consequence is denied control — hold, fly-away, or crash — not a new radio chip. **Intelligence assessment.** [Assessment — High confidence] Official DC34 pages name PX4, the MAVLink logging path, and deny-control as the stated outcome. [Uncertainty] Slides and a talk-cited CVE are not on the public record. [Inference — Moderate confidence] Passports that treat “PX4 plus MAVLink 2 available” as a closed Control Fabric will miss a logging-path integrity failure that still breaks the loop. **Opportunity.** After-record slides or a talk-cited CVE/advisory would raise this from listing to patched-build evidence. Passport PX4 version and whether command/telemetry state is still trusted after logging-path faults. Lab the integrity outcome (sync held versus denied), not a reproduction recipe. Kestrel the same logging path across PX4-family airframes. **LRRK relevance.** Control Fabric and KAT from MAVLink logging to the command/telemetry loop. Passport and Lab on PX4 builds. Watch for a talk-cited advisory. Sense-Move-Act: Move and Act are what fail when the loop desynchronizes. **Confidence.** High on the official listing and stated failure class. Moderate as a CVE case: no identifier on the talk pages. ## 02. Remote ID beacons are inconsistently visible to consumer receivers *Event / publication dates: Saturday 8 August 2026, 16:00–17:00 PT, DEF CON 34 Packet Hacking Village, Creator Stage 6.* | Field | Value | | --- | --- | | Venue | village | | Component | firmware | | Product | DJI Remote ID; ASTM Remote ID (Wi-Fi / BLE) | | CVE / advisory | no CVE | | Patch | none | | Exploit status | none public | **Verified record — [Fact — A1]** Will Hatzer and Charles Grow presented *Why Couldn't I See My Own Drone? Remote ID, ESP32s, and the Packet Trail to Friend or Foe* on the DEF CON 34 schedule and the Packet Hacking Village creator-stage list (`https://defcon.org/html/defcon-34/dc-34-schedule.html`, `https://www.phvillage.io/events/packet-hacking-village-creator-stage-talks-at-def-con-34/`). Failure class on that record: DJI and ASTM Remote ID beacons (Wi-Fi / BLE) are inconsistently visible to consumer receivers, producing missed drone detections and weak-evidence alerts. No CVE, advisory, Exploit-DB ID, or GitHub repo published with the talk. No after-record on `media.defcon.org` as of collection. **Exposure.** Sense: a drone that is physically present can be absent from the receiver that an operator or C-UAS cell treats as truth. The physical consequence is a missed track or a weak-evidence alert — not a takedown method. **Intelligence assessment.** [Assessment — High confidence] Official pages name DJI and ASTM Remote ID and the visibility failure. [Uncertainty] Slides are not posted; receiver models beyond “consumer” are not on the talk page. [Inference — Moderate confidence] Detection stacks that treat RID broadcast as a complete air picture will inherit missed tracks. **Opportunity.** Passport which RID dialect a fleet actually emits and which receivers the operation trusts. Watch after-record packet notes that name a receiver class. Lab visibility as a Sense outcome (seen / not seen), not a beacon-crafting exercise. **LRRK relevance.** Sense and Watch. Passport on RID dialect and receiver coverage. Kestrel DJI versus ASTM beacon families. Campaign picture quality depends on whether RID is a sensor or a closed identity. Sense-Move-Act: Sense is the failed function. **Confidence.** High on the village and schedule listings. Moderate as a product case until slides name receivers and firmware. ## 03. C-UAS detect-to-respond chains fail on authority, coverage, and cheap detectors *Event / publication dates: Friday 7 August 2026, 15:00 PT (30 min), DEF CON 34 Creator Stage 5 (Aerospace Village programming).* | Field | Value | | --- | --- | | Venue | village | | Component | software | | Product | C-UAS detectors / detect-to-respond chains (no named product) | | CVE / advisory | no CVE | | Patch | none | | Exploit status | none public | **Verified record — [Fact — A1]** Greg Albrecht presented *Drones, Detectors, and the Kill Chain* on the DEF CON 34 schedule and creator-talks pages (`https://defcon.org/html/defcon-34/dc-34-schedule.html`, `https://www.defcon.org/html/defcon-34/dc-34-creator-talks.html`). Failure class on that record: C-UAS detect-to-respond chains fail on legal authority, sensor coverage, and overconfident low-cost detectors. No CVE, advisory, or Exploit-DB ID. No GitHub repo published *with the talk* (the speaker independently maintains C-UAS TAK gateways; that work is not linked on the talk page and is not treated as a talk artifact). No after-record on `media.defcon.org` as of collection. **Exposure.** Sense and Act on the defender side: a gap in coverage or authority, or an over-trusted low-cost detector, produces a missed intercept or an unjustified response. Physical consequence is an unengaged airframe or a bad engagement decision — not a C-UAS exploit path. **Intelligence assessment.** [Assessment — High confidence] Official DC34 pages name the detect-to-respond chain and the three failure modes. [Uncertainty] No product, CVE, or after-record. [Inference — Moderate confidence] Campaigns that buy a detector as if it were a closed kill chain will inherit those gaps. **Opportunity.** Passport detector class, coverage claim, and whether legal authority is part of the engagement decision. Watch for slides that name a detector product. Do not treat the speaker’s separate TAK-gateway repos as talk evidence. **LRRK relevance.** Watch and Campaign on C-UAS kill-chain completeness. Sense-Move-Act: Sense (coverage / detector confidence) and Act (authority to respond). Not a Control Fabric finding on an airframe. **Confidence.** High on the listing and stated failure class. Low as a software-danger case: no product CVE. ## Forward indicators 1. DEF CON 34 slides or video for Georgilas, Hatzer / Grow, and Albrecht — `media.defcon.org` presentations folder was empty at collection. 2. A talk-cited PX4 CVE or vendor/CISA advisory that maps the MAVLink logging-path class to a build. 3. A Black Hat USA 2026 briefing page that later posts an in-scope UAS title (briefing lists were NIL at collection). If a BH 2026 briefing later posts materials, it was not on a live primary briefing page as of this cutoff. 4. After-record receiver names for the Remote ID talk, sufficient to Passport a detection stack. 5. Any Black Hat Europe 2026 briefing that becomes the later in-scope conference day; this filing cuts at DEF CON 34 Sunday, 9 August 2026. > **Collection integrity.** Public sources only. No invented talks. No exploit steps, PoCs, or payloads. DEF CON 34 ran 6–9 August 2026 PT; Black Hat USA 2026 ran 1–6 August 2026 PT. Collection cutoff for this filing is 9 August 2026 (DEF CON 34 Sunday). Inventory after-record check through 19 August 2026 PT: DC34 `media.defcon.org` presentations folder empty. Also searched in 2026 and excluded: DC34 main-track *Tracking the Trackers* (consumer GPS-tracker IoT), *Hacking Jetskis*, *Hacking the EOD Bot*, CPDLC / AFDX / electronic-conspicuity (manned aviation), NMEA 2000 vessel IDS, maritime NTN; Aerospace Village STARPWN CTF and UAV Research Series (not talks); Hardware / IoT / RF villages — no additional in-scope title on a live primary page. Black Hat USA / Europe / Asia briefings 2022–2026: NIL (USA 2022–2026 and Europe / Asia microsite briefing landings; InfoconDB drone/UAV/MAVLink hits in-range are Asia 2016 only). Excluded as not talks or not in filter: paid trainings (including Dark Wolf UAS workshops at Black Hat USA 2025 and DEF CON Training 2026); Black Hat / Aerospace Village Drone Zone or cage/CTF without a named talk; manned-aviation datalinks. Supporting UNLV and LinkedIn notices were not used as primaries. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>