All talks from BSidesSF
BSidesSF 2026 - Opening Remarks (Sunday) (Reed Loden)
This talk features Reed Loden delivering the opening remarks for Day Two of BSidesSF 2026. Loden set...
BSidesSF 2026 - Follow the data to learn the secret (Dylan Ayrey)
This talk by Dylan Ayrey explores the hidden vulnerabilities within datasets that are essential for...
BSidesSF 2026 - Not My Vibe: When AI Coding Agents Go Off the Rails (Aonan Guan, Zhengyu Liu)
This talk explores a critical new attack surface in command-line interface (CLI) AI agents, presente...
BSidesSF 2026 - "Ask the EFF" Panel (Panel)
This talk features a panel from the Electronic Frontier Foundation (EFF) at BSidesSF, where experts...
BSidesSF 2026 - The Room Where It Happens (Identity Compromise Edition):... (Julie Agnes Sparks)
This talk, led by Julie Agnes Sparks, explores the unsettling reality of identity compromises in cri...
BSidesSF 2026 - The Epistemology of Trust (Mike Wilkes)
This talk, presented by Mike Wilkes, challenges the conventional goal of breach prevention in securi...
BSidesSF 2026 - Your Threat Model Is Lying to You: Why Modeling the Design Isn’t... (Farshad Abasi)
This talk features Farshad Abasi discussing the shortcomings of traditional threat modeling approach...
BSidesSF 2026 - Opening Remarks (Saturday) (Reed Loden)
In this session, Reed Loden delivers the opening remarks for Day One of BSidesSF 2026. The talk sets...
BSidesSF 2026 - The Phaaaaaaaaantom of the Salt Typhoon is there, inside i-SOON (Daniel Schwalbe)
In this session, Daniel Schwalbe discusses the tactics, techniques, and procedures (TTPs) of the Chi...
BSidesSF 2026 - Detection at Scale: Abstracting Detection Intent (Gaurav Singh, Dario Amiri)
This talk covers the concept of abstracting detection intent to enhance scalability within large org...
BSidesSF 2026 - How to Be a GRC Hero (Without Heroics) (Stas Bojoukha)
This talk, led by Stas Bojoukha, explores the concept of becoming a GRC (Governance, Risk, and Compl...
BSidesSF 2026 - CloudShell Hide-n-Seek: enjoying the sweet persistent... (Jenko Hwong, Chris Ryan)
This talk explores the concept of CloudShell persistence in terms of compute, data, and access, draw...
BSidesSF 2026 - Your Arch-Nemesis is a Data Scientist: What's the... (Aleatha Parker-Wood)
This talk by Aleatha Parker-Wood examines the distinctions between security and privacy in the conte...
BSidesSF 2026 - Google Drive Hunter: Building the Tool Google Should’ve Built (Ayman Elsawah)
This talk features Ayman Elsawah discussing Google Drive Hunter, an open-source tool designed to ide...
BSidesSF 2026 - Prompt, Commit, Repeat: Security at Scale When 1,000 Devs... (Balachandra Shanabhag)
This talk, led by Balachandra Shanabhag, explores the integration of AI coding assistants into enter...
BSidesSF 2026 - Security on a Shoestring: A Low-Budget Security Revival Tour (Jared Casner)
This talk features Jared Casner discussing the challenges of implementing effective security measure...
BSidesSF 2026 - Conducting the Kill-Chain: Detecting APT... (Krupa Brahmkstri, Sneha Rangari)
This talk, presented by Krupa Brahmkstri and Sneha Rangari, explores how sequence-aware modeling can...
BSidesSF 2026 - Breaking Endpoint Anti-Ransomware: Going... (Nishant Sharma, Vivek Ramachandran)
This talk, presented by Nishant Sharma and Vivek Ramachandran, addresses the increasing threat of ra...
BSidesSF 2026 - Detection Allegro: Composing Detection Rules with... (Raphael Ruban, Chen Cao)
This talk focuses on improving the efficiency of threat detection development through the introducti...
BSidesSF 2026 - Composing the Response: Building an Incident Pipeline from Scratch (Geet Pradhan)
This talk features Geet Pradhan discussing the challenges security teams face when improvising respo...
BSidesSF 2026 - When the supply chain hits a sour note (Kennedy Toomey)
This talk, presented by Kennedy Toomey, addresses the critical issue of supply chain attacks and the...
BSidesSF 2026 - The great SAST dissonance: how to please every... (Claudio Merloni, Romain Gaucher)
This talk addresses the challenges faced by Static Application Security Testing (SAST) tools in mode...
BSidesSF 2026 - AI as an Accountable Entity: Governing Risk When Machines Make... (Pavithra Pradip)
This talk, presented by Pavithra Pradip, explores the accountability of AI systems in decision-makin...
BSidesSF 2026 - Practice Cyber Skills Like a Musician (Bianca Ionescu)
This talk features Bianca Ionescu, who illustrates how the discipline of music can enhance essential...
BSidesSF 2026 - What a False Alarm Taught Us About Security as a... (Alex Chantavy, Kunaal Sikka)
In this talk, Alex Chantavy and Kunaal Sikka share their experience as a two-person startup facing a...
BSidesSF 2026 - How the Vietnam War created single sign-on — and how it's evolved... (Connor Peshek)
This talk by Connor Peshek explores the origins of single sign-on (SSO), tracing its development fro...
BSidesSF 2026 - Building an open source security... (Fletcher Heisler, Marcelo Elizeche Landó)
This talk focuses on the challenges and successes of building an open source security project that h...
BSidesSF 2026 - Saving Bug Bounties from AI Slop (Anto Joseph)
This talk, presented by Anto Joseph, addresses the challenges that bug bounties face due to the over...
BSidesSF 2026 - Threat Chords: Tuning into Persistent Patterns in... (Karthika, Samhita Vempatti)
This talk by Karthika, Samhita Vempatti explores the concept of identifying persistent patterns in a...
BSidesSF 2026 - Gettings PCAPs from Stingrays for $20 with... (Cooper Quintin, Will Greenberg)
This talk focuses on Rayhunter, a cell site simulator detector developed by Cooper Quintin and Will...
BSidesSF 2026 - So you think you can airgap? (No.) (Ziyad Edher)
This talk, presented by Ziyad Edher, explores the challenges of air-gapping and introduces an altern...
BSidesSF 2026 - Securing Space: The Next Frontier for Security Engineers (Anshu Gupta)
This talk, presented by Anshu Gupta, explores the critical intersection of cybersecurity and space t...
BSidesSF 2026 - How to sell your soul, err, your security program (Jenn Gile)
In this talk, Jenn Gile explores strategies for improving the perception of security programs by lev...
BSidesSF 2026 - Power Dynamics in Security Leadership: a legato leitmotif... (Sarai Rosenberg)
In this talk, Sarai Rosenberg explores the intricacies of power dynamics within security leadership,...
BSidesSF 2026 - Against the Tyranny of Optimization: On the Stability of... (Katie Moussouris)
This talk, presented by Katie Moussouris, focuses on the rapid transformation of cybersecurity drive...
BSidesSF 2026 - Orchestrating Resilience: Composing a New Score... (Sandhya Narayan, Prachi Jain)
This talk features Sandhya Narayan and Prachi Jain as they explore Netflix's innovative strategies f...
BSidesSF 2026 - What happened to the lock icon? (Serena Chen)
In this talk, Serena Chen discusses the disappearance of the lock icon from Chrome, exploring the im...
BSidesSF 2026 - Let's Do the Timewarp Again! A Look Back to Move Forward (Anna Westelius)
This talk features Anna Westelius, who shares valuable lessons and in-depth examples of foundational...
BSidesSF 2026 - Demystifying File Similarity for Malware Detection (Udbhav Prasad)
This talk, presented by Udbhav Prasad, explores file similarity techniques that play a critical role...
BSidesSF 2026 - From Auditions to Opening Night: Selecting Security Tools that... (Saurabh Sharma)
This talk, presented by Saurabh Sharma, explores the intricacies of selecting security tools in a wa...
BSidesSF 2026 - Red Teaming from outside: Identifying and exploiting SaaS systems... (Rojan Rijal)
This talk, presented by Rojan Rijal, delves into the vulnerabilities of SaaS applications as a moder...
BSidesSF 2026 - Closing Remarks (Reed Loden)
This talk offers a recap of BSidesSF 2026, presented by Reed Loden. The speaker shares insightful be...
BSidesSF 2026 - Reverse Engineering Go Malware: From Manual to AI-Powered Analysis (Asher Davila)
This talk by Asher Davila focuses on the reverse engineering of Go-based malware, particularly targe...
BSidesSF 2026 - CISO Series Live Podcast Recording (Panel)
This talk presents a live recording of the CISO Series Podcast, featuring engaging discussions betwe...
BSidesSF 2026 - Pwning and Defending AI Agent Code Interpreters (Kinnaird McQuade)
This talk, presented by Kinnaird McQuade, explores the vulnerabilities associated with AI agents and...
BSidesSF 2026 - Architecting the Modern SOC: The Evolving AI Reality for Blue Teams (Panel)
This talk explores the architectural decisions essential for modernizing Security Operations Centers...
BSidesSF 2026 - Hunting Malicious IDE Extensions: Building Detection at Scale... (Vinod Tiwari)
This talk, presented by Vinod Tiwari, focuses on the security risks posed by malicious IDE extension...
BSidesSF 2026 - Level Up Your Threat Modeling: Turning Security Into a Team... (Stanley Harris)
This talk by Stanley Harris focuses on transforming threat modeling into an engaging team experience...
BSidesSF 2026 - Security for AI Agents Using an Ensemble of Fine-tuned... (Lidan Hazout, Bar Kaduri)
This talk addresses the growing security risks associated with AI agents as they gain access to sens...
BSidesSF 2026 - The Trusted Platform Module (Eric Chiang)
In this talk, Eric Chiang explores the role of the Trusted Platform Module (TPM) in modern operating...
BSidesSF 2026 - From Assistant to Assassin: Weaponizing An OpenClaw Vulnerability to... (Mav Levin)
This talk dissects a 1-click Remote Code Execution (RCE) chain in OpenClaw, where the speaker, Mav L...
BSidesSF 2026 - One Thousand and One AI-Prevented CVEs: Vibe Coding a Whole New... (Brandon Wu)
This talk explores the emerging threat of supply chain attacks, referencing over 20,000 CVEs filed i...
BSidesSF 2026 - The Great Credential Caper: How to Perform and... (Christo Roberts, Dan Hollinger)
This talk explores the complexities of account takeover (ATO) attacks, highlighting recent breaches...
BSidesSF 2026 - How We Red-Teamed Our Own AI Agent: Lessons from... (Josiah Peedikayil, HS)
This talk covers Operation Pale Fire, where Josiah Peedikayil examines how attackers can exploit Blo...
BSidesSF 2026 - Your Load Balancer is Your New Perimeter: Attacks & Defenses at Scale (Arjun Sharma)
This talk features Arjun Sharma discussing the evolving role of load balancers in security architect...
BSidesSF 2026 - Detecting Race Conditions on macOS (Olivia Gallucci)
In this talk, Olivia Gallucci explores the intricacies of detecting race conditions on macOS, focusi...
BSidesSF 2026 - MCPwned: Hacking MCP Servers with One Skeleton Key... (Jonathan Leitschuh)
This talk, titled MCPwned, explores a significant yet often ignored weakness in MCP specifications,...
BSidesSF 2026 - More Role Models in AppSec: How to Get It Right (Alexandra Charikova)
This talk by Alexandra Charikova focuses on promoting diverse leadership in Application Security (Ap...
BSidesSF 2026 - Web standard consortiums are a game with Chrome as the monopoly... (Simon Wijckmans)
This talk explores the challenges of advancing web standards in the current landscape dominated by G...
BSidesSF 2026 - State of (Absolute) AppSec (Panel)
This talk, "State of (Absolute) AppSec," features a panel discussion with Seth Law, Ken Johnson, Kev...
BSidesSF 2026 - Rehearsal is Over: Moving GRC Engineering from Theory into... (Branden Rosenlieb)
In this session, Branden Rosenlieb discusses the challenges faced by tech workers in Governance, Ris...
BSidesSF 2026 - AI-Powered AppSec: 10x Your Security Team Without Scaling... (Anshuman Bhartiya)
This talk features Anshuman Bhartiya discussing the challenges faced by security teams overwhelmed w...
BSidesSF 2026 - Practical (and impractical) git commit signing (Matthew Garrett)
This talk features Matthew Garrett discussing the importance of cryptographic signing of git commits...
BSidesSF 2026 - Lessons Learned from Building Custom Hacker Hardware (c4m0ufl4g3)
This talk covers the speaker's journey in building custom hacker hardware, providing insights into d...
BSidesSF 2026 - Anatomy and Defense of LOTL Fileless Intrusions (Amol Sarwate)
This talk by Amol Sarwate explores the anatomy and defense of living-off-the-land (LOTL) fileless in...
BSidesSF 2026 - RBAC Atlas: Mapping Real-World Kubernetes Permissions and... (Lenin Alevski)
In this talk, Lenin Alevski discusses the importance of Role-Based Access Control (RBAC) as a protec...
BSidesSF 2026 - The Risky Business of Risk Illiteracy (Sean Juroviesky)
This talk by Sean Juroviesky explores the concept of risk illiteracy, focusing on when risks may not...
BSidesSF 2026 - You’re Gonna Be Popular: Why They’re Getting a... (Ruby Murphy, Clea Ostendorf)
This talk, featuring Ruby Murphy and Clea Ostendorf, explores the dynamics of security hiring and th...
BSidesSF 2026 - Increasing the Analysis Surface of Large Language Models (Stephen Brennan, Ulrich)
This talk focuses on enhancing the analysis surface of large language models (LLMs) by introducing a...
BSidesSF 2026 - Making WAF Mainstream: From Static Defenses to... (Roy Weisfeld, Surya Pentakota)
This talk explores the transformation of Web Application Firewall (WAF) operations from static defen...
BSidesSF 2026 - A blueprint for building a generic... (Ashwin Sidhalinganahalli, Fletcher Ramee)
This talk presents a blueprint for building a generic authorization service tailored for organizatio...
BSidesSF 2026 - From pocket to Pwn: How we hacked a multinational Corp for $200 with... (Tim Shipp)
This talk by Tim Shipp explores how effective Red Team engagements can be conducted with minimal res...
BSidesSF 2026 - Running an efficient bug bounty program and PSIRT... (Garrett McNamara, Jeff Guerra)
This talk covers tactics for optimizing bug bounty programs and Product Security Incident Response T...
BSidesSF 2026 - Is Q-Day Worse than Y2K? Strategies for Surviving the Quantum... (Sandip Dholakia)
This talk covers the imminent risks posed by Q-Day compared to the Y2K phenomenon, highlighting the...
BSidesSF 2026 - Elevating First-Time Female Voices on Stage (Poorna Rajaraman, Deepika Gupta)
This talk addresses the challenge of speaker intimidation faced by first-time female presenters. Poo...
BSidesSF 2026 - We Pwn the Night: Growing & Leading an 31337 security research team (Keith Hoodlet)
This talk covers the systematic approach taken by Trail of Bits in hiring and leading a team of elit...
BSidesSF 2026 - AI for security - friend or foe? (Panel)
This talk explores the dual role of AI in security, examining its potential as both a defender's for...
BSidesSF 2026 - Cringe, Corrected: Hot Takes Fixed by the... (Lawrence Cruciana, Amelia Cruciana)
This talk features Lawrence and Amelia Cruciana as they address common misconceptions in security ad...
BSidesSF 2026 - From Noise to Notes: Orchestrating SAST with Developers... (Adrián Puente Z.)
This talk, led by Adrián Puente Z., focuses on the implementation of Static Application Security Tes...
BSidesSF 2026 - A Worm in the Apple: Wormable Zero-Click RCE in AirPlay... (Avi Lumelsky, Uri Katz)
This talk presents new insights into AirBorne, a series of vulnerabilities within Apple's AirPlay pr...
BSidesSF 2026 - Incident Readiness You and Your Leaders Will... (Shachar Hirshberg, Hadar Waldman)
This talk features Shachar Hirshberg and Hadar Waldman discussing how to enhance incident readiness...
BSidesSF 2026 - Breaking Tokens: Modern Attacks on OAuth, OIDC, and JWT Auth Flows (Bhaumik Shah)
This talk by Bhaumik Shah explores the vulnerabilities in modern authentication systems, specificall...
BSidesSF 2026 - The Phantoms of the Fraudpera: An Overview of Anti-Detection Tooling (Bobbie Chen)
In this session, Bobbie Chen provides an insightful overview of anti-detection tooling used by bad a...
BSidesSF 2026 - Who Watches the NPM Watchers? (Paul McCarty)
This talk explores the oversight of the NPM ecosystem regarding malicious packages and security thre...
BSidesSF 2026 - From $10 to $30M: Operating in the Data-Extortion Aftermath (Diego Matos)
This talk by Diego Matos delves into the complex landscape of multi-level extortion, focusing on how...
BSidesSF 2026 - Sandboxes, Seccomp, and Syscalls: Chasing Isolation in Kubernetes (Mark Manning)
This talk by Mark Manning explores the intricacies of security within Kubernetes, focusing on the li...
BSidesSF 2026 - You Just Might Find, You Get What You Need: How MS Became My... (Emily Harden)
In this talk, Emily Harden shares her compelling journey of how a Multiple Sclerosis diagnosis trans...
BSidesSF 2026 - Kidnapping a Library: How Ransomware Taught the British Library to... (Brian Myers)
In this talk, Brian Myers discusses a ransomware incident that targeted Britain’s national library,...
BSidesSF 2026 - The Heist: Chasing an Advanced Crypto Attacker Across the Multi-cloud (Yotam Meitar)
This talk features Yotam Meitar recounting a captivating investigation into a sophisticated cyber at...
BSidesSF 2026 - The AppSec Poverty Line: Minimal Viable Security (Tanya Janca)
This talk explores the concept of the "AppSec Poverty Line," focusing on how teams with limited reso...
BSidesSF 2026 - Your AI Agent Has Production Access: Now What? (Jack)
This talk explores the security implications of AI agents with production access, focusing on the ne...