Call for Proposals

in 3 months

AppSec Village Wargame - Call For Challenges

event starts

7 Aug 2026

event ends

9 Aug 2026

location

Las Vegas Convention Center, West Hall Level 2 Las Vegas, Nevada, United States


SecDim AppSec Village Wargame — Call for Challenges

The SecDim AppSec Village Wargame is a hybrid secure coding competition that combines application security engineering, adversarial thinking, and live head-to-head play.

Unlike a traditional CTF where the goal is to exploit a target, this wargame asks players to fix vulnerable software first — preserving intended functionality — and then defend it against other competitors in a live attack-and-defence round. 

All challenges must be built using the SecDim Play SDK.

Challenge Types

Secure Coding

Players receive a deliberately vulnerable application and must identify and correctly patch the flaw. Submissions are automatically tested for both functionality and security. Points are awarded for fixes that pass both test suites.

Attack & Defence

Each player receives a containerized vulnerable application to patch and deploy. Once deployed, players enter a live battle lobby where they attempt to exploit each other's running applications. Capturing a flag from another player's app earns points; a player whose app is exploited is removed from the lobby and must redeploy to rejoin.

How to Submit

Step 1 — Create your repository

Use this GitHub Classroom link to generate a private repository pre-configured with CI tests via GitHub Actions. This is where you'll build your challenge.

Step 2 — Submit your proposal

Fill out the submission form with:

- Your name, email, and GitHub username

- A link to your repository

- A description of your challenge: the vulnerability or technique it covers, the intended difficulty, and what makes it interesting

Step 3 — Build and submit

Develop your challenge directly in the repository — including the vulnerable app, your patch, and all required tests. When ready, open a pull request to trigger the final review.

Step 4 — Review and feedback

The AppSec Village CTF and SecDim team will review your challenge, patch, and tests, and provide feedback directly in the PR. Once approved, you'll receive a confirmation via email and Sessionize.

We look forward to seeing what you build.

open, 3 months left
Call for Proposals
Call opens at 12:00 AM

11 May 2026

Call closes at 11:59 PM

31 Jul 2026

Call closes in Pacific Daylight Time (UTC-07:00) timezone.
Closing time in your timezone () is .

PLEASE NOTE: As a non-profit, volunteer-run organization, we are guests at DEF CON and are unable to cover conference fee, travel or accommodation expenses.


Login with your preferred account


If you haven't logged in before, you'll be able to register.

Using social networks to login is faster and simpler, but if you prefer username/password account - use Classic Login.