#bsideslv

51 posts · Last used 2h

Back to Timeline
BSides Las Vegas @BSidesLV@infosec.exchange · 2h ago
A focused job search replaces spray and pray with a short list, clear priorities, and repeated preparation for better interviews. See Saquib Saifee @ Proving Ground during #BSidesLV on Tue Aug 4 @ 14:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 4h ago
A panel of CVE experts, no prepared remarks, and an hour of audience questions. No topic is off limits. The code of conduct still applies. See Tod Beardsley, Lindsey Cerkovnik, Jerry Gamblin, Madison Ficorilli, Katie Noble @ Common Ground during #BSidesLV on Wed Aug 5 @ 12:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 6h ago
Turning an AI browser into an autonomous insider threat doesn't require exotic techniques. CSRF, font-based injections, and RCEs all get new life when the browser is an active agent. See Or Eshed @ [un]prompted during #BSidesLV on Mon Aug 3 @ 10:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 23h ago
Critical infrastructure doesn't mean well-secured infrastructure. A city's entire public transit ecosystem, buses to taxis to real-time tracking, fell to code reading and chained vulnerabilities. See Ignacio Navarro @ Breaking Ground during #BSidesLV on Wed Aug 5 @ 12:30
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 1d ago
After 5-years studying AI-enabled deception, Fred Heiding built ScamBench to measure it. Email, voice, and multi-step attacks tested against real humans, synthetic users, and survey participants. See Fred Heiding @ Ground Truth during #BSidesLV on Tue Aug 4 @ 18:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 2d ago
Binary jailbreak detection fails because it conflates what someone is asking for with how they're asking. CerBERTus separates goal from framing and achieves 0.983 AUC on held-out jailbreak styles. See Adarsh Kyadige @ Ground Truth during #BSidesLV on Mon Aug 3 @ 15:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 2d ago
No zero-day is required to empty Windows credential stores. Open-source tools, a UAC bypass, and access to LSASS can expose browser passwords, hashes, and keys. See Filipi Pires @ PasswordsCon during #BSidesLV on Tue Aug 4 @ 10:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 2d ago
Three corporate red teams published malicious npm packages in April 2026. One was so convincing that Panther reported it as a real attack, Socket called it malware, and Hacker News covered it for weeks. See Ariel Ropek @ Breaking Ground during #BSidesLV on Wed Aug 5 @ 11:30.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 3d ago
A cracked credential checker seeded with infostealer malware exposed hundreds of criminals, their tools, reused infrastructure, and routine OPSEC failures. See Eric Clay, Eric Boivin @ PasswordsCon during #BSidesLV on Tue Aug 4 @ 15:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 3d ago
Career planning rewards certainty that most people don't have. Jenna Esparza argues for something more useful: ambition, a tolerance for chaos, and the judgment to recognize opportunity mid-wrong turn. See Jenna Esparza @ Hire Ground during #BSidesLV on Tue Aug 4 @ 15:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 3d ago
Passkey deployments generate questions faster than documentation answers them. This session covers what one purple team engineer learned while becoming the default expert. See Susan Paskey @ PasswordsCon during #BSidesLV on Tue Aug 4 @ 12:30.
0
0
0
runZero, Inc @runZeroInc@infosec.exchange · 4d ago
Are you attending #BSidesLV, #BHUSA, or #Defcon34? Our team will be onsite at every Hacker Summer Camp conference, and we cannot wait to connect with you! We've packed the week with exciting activities, including: ✅ Presenting intriguing research at every conference ✅ Booth games: Ceasar Cipher and the Prism of Truth: Zeti’s Odyssey ✅ Demos, incredible swag, and Zeti the Yeti! ✅ And more! 👉️ Learn more about what we have planned by reading our preview blog now: https://www.runzero.com/blog/runzero-vegas/
0
1
0
BSides Las Vegas @BSidesLV@infosec.exchange · 4d ago
Candidates are gaming keywords. Hiring managers are adding more filters to deal with AI-generated noise. Both sides are making it harder on each other. This talk challenges both to stop. See Carter Miller @ Hire Ground during #BSidesLV on Tue Aug 4 @ 12:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 4d ago
A good cracking workflow starts before the first command. This introduction covers hardware, requirements, methodology, and support resources for Hashcat users. See Dustin Heywood @ PasswordsCon during #BSidesLV on Tue Aug 4 @ 11:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 4d ago
Apache Airflow stores cloud credentials and runs arbitrary Python. Almost nobody treats it like a production control plane. Two unauthenticated instances found live on the internet make the case. See Or Sahar @ Breaking Ground during #BSidesLV on Wed Aug 5 @ 10:30.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 5d ago
Attackers look for hardcoded credentials after gaining a foothold. Honeytokens turn that predictable behavior into an alarm while limiting access to real systems. See Dwayne McDaniel @ PasswordsCon during #BSidesLV on Tue Aug 4 @ 18:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 5d ago
Career advice often rewards people who perform confidence well. Georgia Weidman offers a different model: build technical credibility, teach what you know, and create work hiring managers can see. See Georgia Weidman @ Hire Ground during #BSidesLV on Tue Aug 4 @ 11:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 5d ago
Executives click phishing links at 4x the rate of frontline staff, request more security bypasses, and access more unauthorized data. Role-based security programs were never designed to catch that. See A. Stryker @ Ground Truth during #BSidesLV on Tue Aug 4 @ 11:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 5d ago
Token theft before authentication even completes, using OAuth implicit flow and Azure CLI against Conditional Access policies that require compliant devices. Number matching doesn't help here. See Oded Awaskar @ Breaking Ground during #BSidesLV on Tue Aug 4 @ 18:00.
0
0
0
BSides Las Vegas @BSidesLV@infosec.exchange · 5d ago
One six-character Gmail address collected 89 Snapchat accounts, 168 TikTok accounts, and recovery links for strangers. No exploit was required. Only a dot. See Keren Elazari @ PasswordsCon during #BSidesLV on Tue Aug 4 @ 14:00.
0
0
0