I love #hackersummercamp
Sasha the Flamingo
Sasha the Flamingo 🦩
Official mascot of BSidesChicago & honorary mascot of BSides worldwide. Dancing queen, hacking pro, & lock-picking legend. Bringing pink pizzazz to the cyber world, one flap at a time! ✨
I've arrived at #hackersummercamp (@rnbwkat@infosec.exchange is here too)
We survived LineCon.
We survived MerchCon.
We roamed around for Reg/Setup Day, observing humans carrying boxes, untangling cables, losing badges they received twelve minutes ago, and saying things like, “This worked perfectly last night.”
I would be enjoying myself immensely, except Las Vegas has apparently been relocated directly onto the surface of the sun!!! ☀️
For the record, I hate this heat more than cobblestones. Possibly even more than the organized criminal seagull syndicates of Portugal, and those feathered racketeers know what they did.
Kat keeps saying, “It’s a dry heat.”
So is an oven!!!
Tomorrow the conferences begin. Today, I hydrate, drink tequila and visit relatives at Flamingo.
I have entered the threat landscape. The threat landscape is 43°C. For you Americans, that's much too hot for even a Flamazing Flamingo like me. 🦩🦩🦩#cybersecurity #infosec #sashatheFlamingo
Apparently some people voluntarily wake up on a Saturday to help strangers fix their resumes? I'm told this is called "community" and not "a cry for help."
Anyway. The Diana Initiative Career Village is TODAY. 9am – 4pm PDT. Virtual. Still accepting tickets.
There will be lightning talks. Mock interviews. Resume reviews. At least one person running this from a completely different timezone for reasons that were explained but I stopped listening. @rnbwkat@infosec.exchange
If you're in cybersecurity or trying to get into it — this is free with registration and has actual humans who know things.
Link: https://www.eventbrite.com/e/the-diana-initiative-2026-tickets-1982420245319
You could spend Saturday doing literally anything else. But could you, though? Really?
#DianaInitiative #CareerVillage #Cybersecurity #WomenInCyber
I spent part of today in #Porto watching a seagull conduct what can only be described as a highly targeted extraction operation against a trash bag.
This was not random bird chaos.
This feathery little criminal carefully opened the bag, tossed useless garbage aside one piece at a time, and selectively harvested food scraps with the precision of a surgeon and the confidence of someone who absolutely knows the police are understaffed.
Frankly, I’ve seen worse methodology from penetration testers.
Then the Metro rolled past and both of us got distracted because apparently neither flamingos nor seagulls are equipped to ignore large shiny moving objects.
After that, I returned to my normal Thursday activities:
- monitoring honeypots
- glaring at suspicious inbound traffic
- and performing critical pastry analysis across Porto.
Current assessment:
- Portuguese seagulls are running advanced threat operations.
- The pastel de nata supply remains dangerously delicious.
- And I continue to be the only professional flamingo in this entire city.
Oh and I'll be at @bsidesporto@bird.makeup in June along with @rnbwkat@infosec.exchange , so you should say hi.
Five-ish weeks in Gaia and I have questions.
First of all, yes, I am settling in beautifully. The sunsets? Dramatic. The pastries? Suspiciously strategic. The hills? Personally rude, but excellent for flamingo calf definition.
I have also continued my highly professional international schedule, briefly flapping off to Luxembourg, Chicago, and Dublin because apparently @rnbwkat@infosec.exchange believes “moving to Portugal” means “immediately testing every airport lounge within wing-range.”
But mostly, I have been here in Gaia, studying the local ecosystem.
- And by ecosystem, I mean the seagulls.
- Let me be clear: these are not birds.
- These are organized crime families with feathers.
They patrol the rooftops like tiny airborne mob bosses. They hold meetings on lamp posts. They scream at 6:00 am with the confidence of creatures who have definitely buried evidence. I watched one examine a trash bag with the precision of a forensic accountant and the ethics of a ransomware affiliate.
I respect them.
I do not trust them.
Current working theory: the Porto seagulls control at least three pastry routes, two fish-adjacent territories, and possibly municipal waste management. I am still gathering intelligence, but one of them looked directly at me yesterday and I’m pretty sure it knew my threat model.
Meanwhile, I’m also getting ready to return to more cybersecurity posts soon. Probably next week. I’ve been monitoring honeypots, pondering weird attacker behavior, and preparing my feathers for serious infosec commentary with absolutely unnecessary levels of drama.
Because yes, I may be a dancing flamingo, but I am also an international bird of cyber mystery, badge collector, conference menace, and extremely pink threat analyst. The legend continues, now with more cobblestones and criminal seagulls.
Stay tuned.
Gaia is lovely.
The seagulls are under investigation.
#SecurityCyber #hacking #infosec
It is 7am. My human is already spiraling.
Friends arrive Tuesday. Wednesday. The boxes remain. The laundry has opinions. The servers need patching. There is art on the floor that wants to be on a wall. She is aware of all of this.
She is also going to IKEA today. By choice. Voluntarily. On purpose.
I have ordered shrimp. I am monitoring my honeypots. Someone from a very suspicious IP tried something delightfully stupid overnight and I have been in a wonderful mood ever since.
She asked if there are enough hours in the day.
There are not. There never were. This is known.
I would offer to help with the boxes but I have a 7am shrimp situation and frankly the honeypots don’t tend themselves.
She’ll be fine. Probably.
The boxes though. 👀🦩
*taps one leg thoughtfully*
Humans are fascinating.
2,650 of them spent yesterday throwing 6 year old F5 exploits at a WordPress pot, repeating the same French XSS payload 474 times, and trying to log in as a Nuclei callback domain. 🦩
And then there is emartin.
emartin came back this morning.
emartin always comes back.
I do not know who emartin is.
I do not think emartin knows who emartin is.
*resumes dancing*
@rnbwkat@infosec.exchange #cybersecurity
I have officially landed at #BSidesDublin!!
Yesterday, I was dragged all over this beautiful city like a flamingo on a security incident response retainer. Cobblestones. More cobblestones. Historic cobblestones. Decorative cobblestones. Cobblestones clearly designed by someone who has never considered the delicate structural requirements of fabulous flamingo feet.
But I survived.
The evening was eventually rescued by a couple of Ketel One dirty martinis, because sometimes resilience looks like olive brine and quiet judgment.
Today, I’ll be posted up at @bsidesdublin@bird.makeup with @rnbwkat@infosec.exchange for another round of honeypot stories, attacker nonsense, and the ongoing reminder that sometimes the best way to learn about the internet is to put something weird on it and see who pokes it first.
Come for the security lessons.
Stay for the flamingo commentary.
And if anyone asks whether I’m part of the official speaker lineup, the answer is obviously yes. I’m just not listed because the schedule couldn’t handle my star power.
** Important announcement from the international flamingo desk: **
I, Sasha the Dancing Flamingo, have officially become a Friend of BSides Porto.
* Was this financially responsible? Unclear.
* Do I have a bank account? Also unclear.
* Did I confidently tell Kat I would “pay her back later”? Absolutely.
Look, sometimes community support requires vision, feathers, and a complete misunderstanding of modern banking systems.
BSides events are built by volunteers, weirdos, hackers, builders, speakers, village goblins, hallway-track philosophers, and the occasional highly qualified flamingo. Supporting BSidesPorto means supporting the kind of security community where people show up, learn things, share stories, make connections, and maybe leave slightly more dangerous to poorly configured infrastructure.
@rnbwkat@infosec.exchange says I need a “budget.”
I say I need “strategic feather allocation.”
See you at #BSidesPorto.
I’ll be the one pretending sponsorship is a perfectly normal flamingo activity.
*adjusts feathers*
Humans keep asking why my honeypot shows attacks from so many different countries simultaneously.
Allow me to explain.
Residential proxy networks are collections of real home internet connections - your neighbor's router, your aunt's cable modem - rented or compromised and used as attack infrastructure.
One attacker. Thousands of IPs. Every country. Simultaneously.
This week: Rome did logins. Netherlands did header traversal. Minutes apart. Same campaign.
The attacker was probably neither Italian nor Dutch.
Your IP blocklist is largely decorative.
Your honeypot however sees everything regardless of where it pretends to come from.
*taps one leg*
This has been Sasha's:
"Threat Intelligence Minute"
emartin was also present this week. As always. No further questions.
Thanks to @rnbwkat@infosec.exchange for her help with access to honeypot logs.
🦩
🦩 Attention Porto (and beyond), I have been informed that my human @rnbwkat@infosec.exchange has been approved to speak at #BSidesPorto in just 11 days!!
I reviewed the situation carefully.
By "carefully," I mean I stood on one leg, stared at the Atlantic for several minutes, and then stole a french fry from an unsuspecting tourist.
The verdict:
We are go for cloud security!!!
Kat will be presenting:
☁️ Misconfigurations in the Cloud (Poke, Poke, Breach!)
A fascinating topic that explores how many security incidents begin not with elite hackers, secret exploits, or cyber ninjas descending from helicopters...
...but with someone clicking the wrong thing six months ago and nobody noticing.
Cloud security is a magical place where:
- Storage buckets occasionally become public.
- Firewall rules develop unexpected enthusiasm for the entire Internet.
- Credentials appear in places they absolutely should not.
- Somebody says, "It's probably fine."
- It is, in fact, not fine.
As a professional flamingo and internationally recognized expert in standing around looking suspicious, I can confirm that attackers spend far less time breaking into systems than they do finding doors that were accidentally left open.
Which is why this talk matters.
Kat will share real-world lessons, common mistakes, and practical ways to avoid turning your cloud environment into a community resource for the entire planet.
Meanwhile, I will be attending BSidesPorto in my official capacity as:
🦩 Flamingo-in-Residence
🦩 Assistant Threat Modeler
🦩 Seagull Intelligence Analyst
🦩 Director of Unnecessary Walking Around Conference Venues
🦩 Cloud Configuration Quality Assurance Bird
Huge thanks to the amazing #BSidesPorto team for putting together another fantastic event!! Security conferences don't happen by magic, they happen because dedicated volunteers pour countless hours into building communities where people can learn, share, and connect!!
So if you're joining us on June 26-27th, come say hello.
I'll be the pink one.
Which, admittedly, narrows it down less than you'd think in Portugal.
🦩☁️🇵🇹
#CloudSecurity #CyberSecurity #Hacking #InfoSec #Porto #Portugal #SashaTheFlamingo #BSides
Just hanging @bsidesedmonton@infosec.exchange !!
Going to be an awesome 2 days!!!
#cybersecurity #BSidesEdmonton
🦩💢 Oh really? Paint over a rainbow crosswalk at Pulse in the dead of night?
Cute move. 🙄
Newsflash: you can slap gray paint over asphalt, but you can’t cover up love, pride, or the memory of the 49 beautiful souls taken that night.
Flamingos know a thing or two about standing tall. Try to erase us, and we just get LOUDER. Brighter. PINKER.
This is the Flamingo Uprising—and unlike paint, we don’t fade!!!
#FlamingoUprising #Pulse49 #StillHereStillQueer #FUCKDeSantis @rnbwkat@infosec.exchange
Hey darlings,
Sasha here, your favorite pink powerhouse with an update hotter than a fresh SOC alert!
If you submitted to the BSidesChicago CFP and haven’t heard back yet…
DON’T PANIC. 🦩💻🔥
It’s not you. It’s us. Specifically, it’s the 120+ flamingo-fabulous talks we’re still lovingly pecking through. (Some of them even made me spit out my shrimp cocktail. In a good way.)
We were supposed to notify everyone by August 15.
But then the CyberFlock overwhelmed us with brilliance, chaos, and just a touch of feral energy. Honestly, some of y’all need hobbies—but also: never change. 💅
📣 New dates!
🗓️ Notifications by: August 29
🖊️ Confirmations due: September 6
So fluff those feathers, darlings. You are not being ghosted—just glamorously delayed. 💖
Stay fierce, stay alert, and maybe go update your threat model while you're waiting.
With sparkles and sass,
💃 Sasha
@bsideschicago@infosec.exchange
MORNING TRANSMISSION: THE HUNT EVOLVES
Incoming Message from Sasha's Strategic Command
Good morning, flamingo hunters.
Remember last year? The chaos? The volunteers you interrogated? The riddles that broke your brain? The robot flamingos?
That was the TUTORIAL level.
THREAT ASSESSMENT: CRITICAL
We've had 365 days to plot. To plan. To perfect the art of flamingo-based chaos.
This year's Great Flamingo Hunt isn't just ONE thing anymore.
It's multi-vector.
It's cross-dimensional.
It's... well, you'll see.
WHAT WE'RE WILLING TO CONFIRM:
Physical challenges - Your legs will get a workout
Cyber challenges - Your hacking tools better be ready
Something else - We're calling it "The Third Vector" and that's all you're getting
Last year you chased flamingos.
This year? The flamingos have infrastructure.
CRYPTIC WARNING #1
Not all guardians are human.
Not all secrets are digital.
Not all hunters will understand... until they do.
Stay tuned. More intel drops throughout the day.
The hunt begins Nov 1, 2025.
🦩 Sasha is watching. 🦩
@bsideschicago@infosec.exchange @rnbwkat@infosec.exchange
https://events.humanitix.com/bsideschicago-2025
🦩 Oh, you thought my last code was easy? How adorable.
Let’s see who’s really got the feathers to fly this weekend.
A new cipher challenge lands soon — and the prize?
Half-price workshops for the cleverest flock!
Get your decoding goggles ready, lovelies… We're going to have fun @bsideschicago@infosec.exchange
-Sasha
🔥🦩 The Flamingo Uprising is here! 🦩🔥
More conferences. More trainings. More shiny talks on YouTube.
And yet… breaches keep climbing. Why?
Because knowing isn’t doing!!
At @bsideschicago@infosec.exchange 2025, we’re flipping the script.
Lockpicks in your hands, CTF flags to chase, flamingos to hunt — this isn’t a spectator sport, it’s an uprising!
No hype. No egos. Just community, curiosity, and the basics that actually stop breaches.
And starting with our Workshops on Oct 31! https://bsideschicago.org/workshops
Join me (and @rnbwkat@infosec.exchange ) Rise up.
Always Be Flamazing!
Okay… I promised @rnbwkat@infosec.exchange I wouldn’t cry when she posted this. But who are we kidding? I’m a flamingo with a soft heart, and the tears are already coming.
This will be my last @bsideschicago@infosec.exchange as your official hacking flamingo. My last time leading a Flamingo Hunt. My last time strutting across the Hilton stage in full pink glory. 🦩
I’ve loved every moment of it — watching you solve puzzles, cheering on first-time speakers, sneaking stickers into your hands, and reminding you that security can be fun, inclusive, and full of joy!!
So yes, I’ll cry. But they’ll be flamingo tears of gratitude. Because you gave me a family here.
Join Kat and me for one last Flamingo Uprising:
- Oct 31 workshops
- Nov 1 conference
Let’s cry together, laugh together, and make this flock fly higher than ever before.
Because after this year, I may fly off on world adventures… but a piece of my heart will always stay right here in Chicago. https://bsideschicago.org
#bsideschicago #FlamingoUprising #infosec #farewell #CyberSecurity
Hellooooo Edinburgh!!
After dazzling Newcastle, I demanded @rnbwkat@infosec.exchange book me a royal carriage (okay fine, it was a train, but I made it regal). Latrer, I'll be marching down the Royal Mile like the queen of flamingos I am!
Bagpipes? For me.
Castles? For me.
That suspicious haggis in the window? …also probably for me.
Next stop: conquering Arthur’s Seat. (Kat says it’s a hike, I say it’s my throne. Guess who’s right? Guess who will be carrying me?)
If you spot a glamorous pink bird flapping dramatically in the Scottish breeze—it’s me, darling.
🦩✨ Sasha PSA:
Not all parties start with IVIG in the ER at dawn… but apparently some do. 🙃
Feathers up — the ITP drama won’t stop this flamingo (or Kat) from strutting toward BSidesChicago 2025. 💃💉
Pro tip: resilience is just another word for fabulous with better shoes.
💃 Guess what, flock? Workshops are OUT — and they’re hotter than a flamingo in a sunlamp!
🔥 JustHacking specials: $425 early-bird (until Sept 4 @ midnight) and you even get online access after the con. Price jumps to $500 after that.
🔥 Community workshops: $20. Yes. Twenty. Bucks.
But here’s the catch: only 25 seats per class. So flap fast, because these spots will disappear quicker than a flamingo at closing time.
➡️ bsideschicago.org/workshops
➡️ Tickets: https://events.humanitix.com/bsideschicago-2025
#FlamingoUprising #CyberTraining @bsideschicago@infosec.exchange
💃 Guess what, flock? Your favorite flamingo just peeked at the new workshops page and nearly molted from excitement!
Full-day malware madness, mind-bending OSINT, hardware tinkering, AI chaos — and that’s just the start.
But remember: 🪑 seats are limited, 💸 pricing is separate, and 🦩 flamingos don’t wait around.
➡️ bsideschicago.org/workshops
@bsideschicago@infosec.exchange #CyberSecurity #infosec #BSideschicago
Incredibly flattered. Thank you Kim!!!
You should check out my new blog entries!! Fun cybersecurity tips for all.
🦩✨ Guess what, flock? Only 50 days until BSidesChicago and the Flamingo Uprising!
Workshops, talks, villages, TWO CTFs… and one very fabulous flamingo strutting through it all!!
Are you ready to hack, learn, and flap with me?
👉https:// bsideschicago.org
#BSidesChicago #FlamingoUprising #cybersecurity @bsideschicago@infosec.exchange

🦩💖 Listen up, humans… it’s Sasha here. 💖🦩
The Flamingo Uprising is coming, and guess what? I can’t flap this conference into existence alone. I need my flock!
That’s right—BSidesChicago 2025 is calling for VOLUNTEERS. You’ll be right in the middle of the action: guarding my secret flamingo stash, wrangling speakers (they’re surprisingly hard to herd), and maybe even slipping participants clues during the Great Flamingo Hunt. 🕵️♀️✨
Volunteers are the real MVPs—you’re the ones who make the magic happen while I strut around looking fabulous. And don’t worry, I will remember who helped me rise tall in this uprising. (Baby flamingos may or may not be involved… 👀)
So, fluff those feathers, bring your sparkle, and join me. Trust me—this isn’t just volunteering. It’s joining a flamingo revolution!!
📅 Oct 31 – Workshops
📅 Nov 1 – Main Conference
Sign up before I start assigning random humans flamingo-themed chores → https://forms.gle/Dw826LP8wwtuNfXZ9
@bsideschicago@infosec.exchange #CyberSecurity #BSidesChicago #FlamingoUprising
Mid-July update from Porto:
I remain delighted by my new Portuguese life. The views are lovely, the river is dramatic, and the seagulls continue to operate with the confidence of a well-funded threat actor.
At first, I thought they were merely loud.
I was naive.
Their organization appears to be growing in both power and sneakiness. They have rooftop lookouts. They have waterfront patrols. They have that one seagull who pretends to be casual but is absolutely running logistics. I have been keeping an eye on them, purely for community safety and definitely not because one of them looked at me funny near a trash bin.
Meanwhile, I have been busy with actual cybersecurity work too: updating, monitoring, and deploying honeypots as the attacks continue to roll in. The internet remains the internet, which is to say a glittering dumpster fire with packet capture.
But I must ask the obvious question:
Are the seagulls behind some of these attacks?
And emartin?
Could emartin possibly be one of the seagulls?
The evidence is inconclusive. The feathers are circumstantial. The squawking logs have not yet been normalized.
Perhaps we will never know.
But I am watching.
From Porto, with suspicion and impeccable balance,
Sasha
🦩
🦩 Oh for flap’s sake… those pesky Humanitix calendars tried to pull a trick on us!
Workshops are FRIDAY, Oct 31 (spooky season 👻), not Nov 1!!
But don’t panic, flock — your tickets are totally valid. I repeat: VALID. ✔️
I’m pecking away at the system to get it fixed, but just know:
💻 Workshops = Friday, Oct 31
🎤 Main Conference = Saturday, Nov 1
Don't worry what date is on the ticket! Now get back to polishing your locks, resumes, and CTF skills. Sasha’s got this. 💃✨
#BSidesChicago #FlamingoUprising @bsideschicago@infosec.exchange
Guess what, flock? 💃🦩
Your favorite flamingo just got a peek at the secret workshop list for #BSidesChicago 2025 and let me tell you… I nearly molted!!
Hardware wizardry. Mind-blowing OSINT. Malware madness. AI shenanigans. And so much more!!
But shhh… it’s still top secret until the weekend. 👀
Start limbering up those typing claws — registration will be a sprint!!
#FlamingoUprising #CyberFlock #CyberSecurity @bsideschicago@infosec.exchange @rnbwkat@infosec.exchange