All talks from BSidesSF
BSidesSF 2026 - Opening Remarks (Sunday) (Reed Loden)
This talk provides an overview of the Bides SF 2026 conference, highlighting its record attendance o...
BSidesSF 2026 - Follow the data to learn the secret (Dylan Ayrey)
In this talk, Dylan, CEO of Truffle Security, explores the intricate history and evolution of Huggin...
BSidesSF 2026 - Not My Vibe: When AI Coding Agents Go Off the Rails (Aonan Guan, Zhengyu Liu)
This talk discusses the vulnerabilities and security concerns associated with AI coding agents, part...
BSidesSF 2026 - "Ask the EFF" Panel (Panel)
In this session, representatives from the Electronic Frontier Foundation (EFF) engage in a dynamic Q...
BSidesSF 2026 - The Room Where It Happens (Identity Compromise Edition):... (Julie Agnes Sparks)
In this talk, Julie delves into the intricacies of Octa's logging capabilities and the emerging thre...
BSidesSF 2026 - The Epistemology of Trust (Mike Wilkes)
In this conference talk, Mike Wilks explores the complex relationship between technology, trust, and...
BSidesSF 2026 - Your Threat Model Is Lying to You: Why Modeling the Design Isn’t... (Farshad Abasi)
In this talk, Farshad Abbasi addresses the shortcomings of traditional threat modeling, emphasizing...
BSidesSF 2026 - Opening Remarks (Saturday) (Reed Loden)
This talk introduces the BSidesSF 2026 event, highlighting its themes and the importance of communit...
BSidesSF 2026 - The Phaaaaaaaaantom of the Salt Typhoon is there, inside i-SOON (Daniel Schwalbe)
In this talk, Daniel Schwabby, the CISO and head of investigations at Domain Tools, presents an in-d...
BSidesSF 2026 - Detection at Scale: Abstracting Detection Intent (Gaurav Singh, Dario Amiri)
This talk discusses detection at scale, presented by Dario Amiri and Garov Singh from Google, focusi...
BSidesSF 2026 - How to Be a GRC Hero (Without Heroics) (Stas Bojoukha)
This talk focuses on the evolution of Governance, Risk, and Compliance (GRC) in the context of incre...
BSidesSF 2026 - CloudShell Hide-n-Seek: enjoying the sweet persistent... (Jenko Hwong, Chris Ryan)
This talk explores the vulnerabilities and the manipulation of cloud environments, specifically focu...
BSidesSF 2026 - Your Arch-Nemesis is a Data Scientist: What's the... (Aleatha Parker-Wood)
In this talk, Altha Parker Wood discusses the critical distinctions between security work and privac...
BSidesSF 2026 - Google Drive Hunter: Building the Tool Google Should’ve Built (Ayman Elsawah)
In this talk, Aiman Elswis introduces Sleuthther, a tool designed to mitigate risks associated with...
BSidesSF 2026 - Prompt, Commit, Repeat: Security at Scale When 1,000 Devs... (Balachandra Shanabhag)
This talk addresses the security challenges associated with the adoption of AI coding tools within e...
BSidesSF 2026 - Security on a Shoestring: A Low-Budget Security Revival Tour (Jared Casner)
In this talk, Jared Kner, co-founder of Blacksmith Infosac, discusses how to establish a security pr...
BSidesSF 2026 - Conducting the Kill-Chain: Detecting APT... (Krupa Brahmkstri, Sneha Rangari)
This talk, presented by Krupa Brahmkstri and Sneha Rangari, explores how sequence-aware modeling can...
BSidesSF 2026 - Breaking Endpoint Anti-Ransomware: Going... (Nishant Sharma, Vivek Ramachandran)
This talk covers the emerging threats of browser-native ransomware and how traditional endpoint secu...
BSidesSF 2026 - Detection Allegro: Composing Detection Rules with... (Raphael Ruban, Chen Cao)
This talk focuses on Detection Allegro, a system developed by the detection response team at Vacasa...
BSidesSF 2026 - Composing the Response: Building an Incident Pipeline from Scratch (Geet Pradhan)
In this talk, Git Pradan discusses building an incident response pipeline from scratch, specifically...
BSidesSF 2026 - When the supply chain hits a sour note (Kennedy Toomey)
In this session, Kennedy Tumi discusses the increasing risks associated with supply chain attacks in...
BSidesSF 2026 - The great SAST dissonance: how to please every... (Claudio Merloni, Romain Gaucher)
This talk, delivered by Claudio Melani, focuses on the challenges and innovations in scaling Static...
BSidesSF 2026 - AI as an Accountable Entity: Governing Risk When Machines Make... (Pavithra Pradip)
This talk discusses the importance of accountability in AI systems, particularly as they evolve from...
BSidesSF 2026 - Practice Cyber Skills Like a Musician (Bianca Ionescu)
In this session, Bianca Amescu draws parallels between musical training and the skills required in c...
BSidesSF 2026 - What a False Alarm Taught Us About Security as a... (Alex Chantavy, Kunaal Sikka)
In this talk, Alex and Kunal, co-founders of the security startup Subage, share their challenging jo...
BSidesSF 2026 - How the Vietnam War created single sign-on — and how it's evolved... (Connor Peshek)
In this talk, Conner explores the unexpected historical connections between the Vietnam War and the...
BSidesSF 2026 - Building an open source security... (Fletcher Heisler, Marcelo Elizeche Landó)
In this talk, Fletcher Heisler and Marcelo Elizondo discuss their journey of building the open-sourc...
BSidesSF 2026 - Saving Bug Bounties from AI Slop (Anto Joseph)
In this talk, Anto Joseph discusses the complexities and challenges of bug bounties, particularly as...
BSidesSF 2026 - Threat Chords: Tuning into Persistent Patterns in... (Karthika, Samhita Vempatti)
This talk features Karthika and Samita, cyber security researchers at Adobe, discussing threat chord...
BSidesSF 2026 - Gettings PCAPs from Stingrays for $20 with... (Cooper Quintin, Will Greenberg)
This talk focuses on the use of cell site simulators, commonly known as Stingrays or MC catchers, by...
BSidesSF 2026 - So you think you can airgap? (No.) (Ziyad Edher)
In this talk, Ziad discusses the challenges of securing AI research clusters, particularly regarding...
BSidesSF 2026 - Securing Space: The Next Frontier for Security Engineers (Anshu Gupta)
This talk, presented by Anu Gupta, delves into the emerging field of space security, emphasizing the...
BSidesSF 2026 - How to sell your soul, err, your security program (Jenn Gile)
In this talk, Jen Guile discusses how professionals in security roles can effectively communicate th...
BSidesSF 2026 - Power Dynamics in Security Leadership: a legato leitmotif... (Sarai Rosenberg)
This talk covers the dynamics of power within security leadership, emphasizing the importance of tru...
BSidesSF 2026 - Against the Tyranny of Optimization: On the Stability of... (Katie Moussouris)
This talk, presented by Katie Moussouris, focuses on the rapid transformation of cybersecurity drive...
BSidesSF 2026 - Orchestrating Resilience: Composing a New Score... (Sandhya Narayan, Prachi Jain)
This talk explores the challenges of maintaining service reliability at Netflix during critical even...
BSidesSF 2026 - What happened to the lock icon? (Serena Chen)
This talk discusses the removal of the lock icon in Chrome's 2023 redesign, originally a symbol of s...
BSidesSF 2026 - Let's Do the Timewarp Again! A Look Back to Move Forward (Anna Westelius)
In this keynote address, Anna Vastelius discusses the evolving landscape of cybersecurity and the op...
BSidesSF 2026 - Demystifying File Similarity for Malware Detection (Udbhav Prasad)
This talk focuses on the intricacies of file similarity algorithms for malware detection. The speake...
BSidesSF 2026 - From Auditions to Opening Night: Selecting Security Tools that... (Saurabh Sharma)
In this talk, Saurabh Sharma addresses the challenges of selecting and deploying security tools effe...
BSidesSF 2026 - Red Teaming from outside: Identifying and exploiting SaaS systems... (Rojan Rijal)
This talk focuses on red teaming techniques used to identify and exploit vulnerabilities within SaaS...
BSidesSF 2026 - Closing Remarks (Reed Loden)
This talk reviews the highlights and accomplishments of BSides San Francisco 2026, emphasizing the r...
BSidesSF 2026 - Reverse Engineering Go Malware: From Manual to AI-Powered Analysis (Asher Davila)
In this talk, Asher Dila, a security researcher at Palo Alto Networks, discusses the complexities of...
BSidesSF 2026 - CISO Series Live Podcast Recording (Panel)
This talk features a live recording of the CISO Series podcast at a cybersecurity event in San Franc...
BSidesSF 2026 - Pwning and Defending AI Agent Code Interpreters (Kinnaird McQuade)
This talk features Canard McUade, the chief security architect at Beyond Trust, who presents his ext...
BSidesSF 2026 - Architecting the Modern SOC: The Evolving AI Reality for Blue Teams (Panel)
This panel discussion focuses on the evolving role of Security Operations Centers (SOCs) in the cont...
BSidesSF 2026 - Hunting Malicious IDE Extensions: Building Detection at Scale... (Vinod Tiwari)
In this talk, Vinod Tiwari addresses the significant issue of malicious integrated development (ID)...
BSidesSF 2026 - Level Up Your Threat Modeling: Turning Security Into a Team... (Stanley Harris)
In this talk, Stanley Harris shares innovative methods to enhance threat modeling by gamifying the p...
BSidesSF 2026 - Security for AI Agents Using an Ensemble of Fine-tuned... (Lidan Hazout, Bar Kaduri)
This talk focuses on the security of AI agents, specifically through the lens of fine-tuned small la...
BSidesSF 2026 - The Trusted Platform Module (Eric Chiang)
In this session, Eric Chang discusses the Trusted Platform Module (TPM), outlining its significance...
BSidesSF 2026 - From Assistant to Assassin: Weaponizing An OpenClaw Vulnerability to... (Mav Levin)
This talk explores the exploitation of an OpenClaw vulnerability to achieve one-click remote code ex...
BSidesSF 2026 - One Thousand and One AI-Prevented CVEs: Vibe Coding a Whole New... (Brandon Wu)
In this talk, Brandon Wu discusses the challenges and strategies associated with supply chain securi...
BSidesSF 2026 - The Great Credential Caper: How to Perform and... (Christo Roberts, Dan Hollinger)
This talk delves into the critical issue of credential stuffing and account takeover attacks. The sp...
BSidesSF 2026 - How We Red-Teamed Our Own AI Agent: Lessons from... (Josiah Peedikayil, HS)
In this talk, Josiah Pedale discusses Operation Pailfire, a red team operation conducted by Block's...
BSidesSF 2026 - Your Load Balancer is Your New Perimeter: Attacks & Defenses at Scale (Arjun Sharma)
This talk covers the importance of load balancers in securing enterprise infrastructure against comm...
BSidesSF 2026 - Detecting Race Conditions on macOS (Olivia Gallucci)
In this talk, Olivia Galuchcci from Data Dog discusses how to detect race conditions on Mac OS, emph...
BSidesSF 2026 - MCPwned: Hacking MCP Servers with One Skeleton Key... (Jonathan Leitschuh)
In this presentation, Jonathan Lishu discusses the security vulnerabilities associated with Model Co...
BSidesSF 2026 - More Role Models in AppSec: How to Get It Right (Alexandra Charikova)
This talk by Alexandra Cherkashina focuses on the importance of moral models in application security...
BSidesSF 2026 - Web standard consortiums are a game with Chrome as the monopoly... (Simon Wijckmans)
In this talk, Simon Witzmans discusses the complexities of web standards and the role of the World W...
BSidesSF 2026 - State of (Absolute) AppSec (Panel)
This panel discussion focuses on the evolving landscape of application security in the context of AI...
BSidesSF 2026 - Rehearsal is Over: Moving GRC Engineering from Theory into... (Branden Rosenlieb)
In this talk, Brandon Rosen Lee discusses moving Governance, Risk, and Compliance (GRC) from theory...
BSidesSF 2026 - AI-Powered AppSec: 10x Your Security Team Without Scaling... (Anshuman Bhartiya)
This talk focuses on the application of AI in app security (AppSec), specifically how it can enable...
BSidesSF 2026 - Practical (and impractical) git commit signing (Matthew Garrett)
In this talk, Matthew Garrett discusses the importance of practical and impractical Git commit signi...
BSidesSF 2026 - Lessons Learned from Building Custom Hacker Hardware (c4m0ufl4g3)
This talk covers Jonathan Fischer's journey in developing custom hacker hardware, specifically an im...
BSidesSF 2026 - Anatomy and Defense of LOTL Fileless Intrusions (Amol Sarwate)
This talk features Amal Savvate, head of the Cohesidi Red Lab, who discusses the anatomy of fileless...
BSidesSF 2026 - RBAC Atlas: Mapping Real-World Kubernetes Permissions and... (Lenin Alevski)
In this talk, Lenin Alesky discusses Kubernetes and the importance of Role-Based Access Control (RBA...
BSidesSF 2026 - The Risky Business of Risk Illiteracy (Sean Juroviesky)
This talk explores the challenges of measuring risk in cybersecurity and the conceptual misunderstan...
BSidesSF 2026 - You’re Gonna Be Popular: Why They’re Getting a... (Ruby Murphy, Clea Ostendorf)
In this talk, Ruby Murphy and Clea Assendorf discuss the current challenges in the job market, parti...
BSidesSF 2026 - Increasing the Analysis Surface of Large Language Models (Stephen Brennan, Ulrich)
This talk discusses the increasing analysis surface of large language models (LLMs) with a focus on...
BSidesSF 2026 - Making WAF Mainstream: From Static Defenses to... (Roy Weisfeld, Surya Pentakota)
This talk discusses the challenges and advancements in implementing Web Application Firewalls (WAF)...
BSidesSF 2026 - A blueprint for building a generic... (Ashwin Sidhalinganahalli, Fletcher Ramee)
In this session, Ashwin and Fletcher from the platform security team at Rob present a blueprint for...
BSidesSF 2026 - From pocket to Pwn: How we hacked a multinational Corp for $200 with... (Tim Shipp)
In this talk, Tim Ship, the CTO and co-founder of Threat, shares insights from a unique red teaming...
BSidesSF 2026 - Running an efficient bug bounty program and PSIRT... (Garrett McNamara, Jeff Guerra)
This talk focuses on running an effective bug bounty program and incident response processes. The sp...
BSidesSF 2026 - Is Q-Day Worse than Y2K? Strategies for Surviving the Quantum... (Sandip Dholakia)
This talk discusses the imminent threat of quantum computing to current encryption methods, comparin...
BSidesSF 2026 - Elevating First-Time Female Voices on Stage (Poorna Rajaraman, Deepika Gupta)
This talk focuses on the challenges of encouraging first-time female speakers in the tech industry,...
BSidesSF 2026 - We Pwn the Night: Growing & Leading an 31337 security research team (Keith Hoodlet)
In this talk, Keith Hoodlett shares his experiences and strategies for building and leading a succes...
BSidesSF 2026 - AI for security - friend or foe? (Panel)
This panel discussion addresses the dual role of artificial intelligence (AI) in cybersecurity, expl...
BSidesSF 2026 - Cringe, Corrected: Hot Takes Fixed by the... (Lawrence Cruciana, Amelia Cruciana)
This talk discusses the CIS controls, a cybersecurity framework focused on practical applications to...
BSidesSF 2026 - From Noise to Notes: Orchestrating SAST with Developers... (Adrián Puente Z.)
In this talk, Adrian Puente discusses the challenges of implementing Static Application Security Tes...
BSidesSF 2026 - A Worm in the Apple: Wormable Zero-Click RCE in AirPlay... (Avi Lumelsky, Uri Katz)
In this presentation, the speakers discuss their research into AirPlay vulnerabilities affecting App...
BSidesSF 2026 - Incident Readiness You and Your Leaders Will... (Shachar Hirshberg, Hadar Waldman)
This talk discusses the challenges of gaining visibility into production environments within cyberse...
BSidesSF 2026 - Breaking Tokens: Modern Attacks on OAuth, OIDC, and JWT Auth Flows (Bhaumik Shah)
This talk discusses modern attacks on OAuth, OIDC, and JWT flows, focusing on the exploitation of to...
BSidesSF 2026 - The Phantoms of the Fraudpera: An Overview of Anti-Detection Tooling (Bobbie Chen)
In this session, Bobby Chen, a product manager at Stitch by Twilio, presents an overview of anti-det...
BSidesSF 2026 - Who Watches the NPM Watchers? (Paul McCarty)
In this talk, Paul McCarthy discusses the state of security within the Node Package Manager (NPM), h...
BSidesSF 2026 - From $10 to $30M: Operating in the Data-Extortion Aftermath (Diego Matos)
This talk covers the evolution of ransomware attacks and their impact on organizations, as discussed...
BSidesSF 2026 - Sandboxes, Seccomp, and Syscalls: Chasing Isolation in Kubernetes (Mark Manning)
In this talk, Mark Manning discusses the complexities and challenges of implementing sandboxes and s...
BSidesSF 2026 - You Just Might Find, You Get What You Need: How MS Became My... (Emily Harden)
In this talk, Emily Harden shares her personal journey with multiple sclerosis, emphasizing the chal...
BSidesSF 2026 - Kidnapping a Library: How Ransomware Taught the British Library to... (Brian Myers)
In this talk, Brian Meyers discusses a significant ransomware attack that took place at the British...
BSidesSF 2026 - The Heist: Chasing an Advanced Crypto Attacker Across the Multi-cloud (Yotam Meitar)
In this talk, Yo Tom, the director of incident response at Whiz, shares the details of a significant...
BSidesSF 2026 - The AppSec Poverty Line: Minimal Viable Security (Tanya Janca)
This talk focuses on the concept of minimal viable security (MVS) in the context of applications and...
BSidesSF 2026 - Your AI Agent Has Production Access: Now What? (Jack)
In this talk, Jack from Anthropic discusses the implications of deploying AI agents with production...