Loading…
Venue: AMC Theatre 06 clear filter
Saturday, April 26
 

11:15am PDT

How to Train Your Detection Dragon
Saturday April 26, 2025 11:15am - 12:00pm PDT
Ever wanted to start fresh and train the "detection and response" dragon? Hear my account of how I did this (and hope to continue building!) from scratch with learnings from my professional experience so far!
Speakers
avatar for Geet Pradhan

Geet Pradhan

Sr Security Engineer, Lime
Big fan of Aesop’s hand cream.
Saturday April 26, 2025 11:15am - 12:00pm PDT
AMC Theatre 06 AMC at Metreon

1:00pm PDT

Into The Dragon’s Den
Saturday April 26, 2025 1:00pm - 1:45pm PDT
In this talk, we will take you through our journey of bringing a high-stakes SaaS product to the Chinese market while exploring the challenges faced and sharing what we learned. We will offer insights and practical advice for navigating the unique threats of the Chinese market for a global company.
Speakers
avatar for Jacob Salassi

Jacob Salassi

Former director of Product Security at Snowflake. Led Snowflake's pre- & post IPO transformation from a bottlenecked, security engineer centric process that slowed teams down to a developer owned security process that ships features faster and more securely. My teams & I handled security... Read More →
Saturday April 26, 2025 1:00pm - 1:45pm PDT
AMC Theatre 06 AMC at Metreon

2:00pm PDT

Trace to Triage: How to Connect Product Vulnerabilities to Security Paths
Saturday April 26, 2025 2:00pm - 2:45pm PDT
AppSec must balance usability and security, but traditional approaches often lead to disjointed efforts—developers patching blindly, detection teams creating incomplete rules, and threat hunters chasing past compromises. This talk uses eBPF to show how tracing brings context for actionable insights.
Speakers
Saturday April 26, 2025 2:00pm - 2:45pm PDT
AMC Theatre 06 AMC at Metreon

3:00pm PDT

Data Splicing Attacks: Breaking Enterprise DLP from the Inside Out
Saturday April 26, 2025 3:00pm - 3:45pm PDT
We uncovered a data exfiltration technique, capable of bypassing all major DLP vendors listed by Gartner. We will dissect the architectural flaws in endpoint and proxy-based DLP, showcase live bypass demos, and launch Angry Magpie, an open-source toolkit for red teams to replicate these attacks.
Speakers
VR

Vivek Ramachandran

Founder, SquareX
Vivek Ramachandran is a security researcher, book author, speaker-trainer, and serial entrepreneur with over two decades of experience in offensive cybersecurity. He is currently the founder of SquareX, building a browser-native security product focused on detecting, mitigating, and threat-hunting web attacks against enterprise users and consumers. Prior to that, he was the founder of Pentester Academy (acquired in 2021), which has trained thousands of customers from governmen... Read More →
avatar for Audrey Adeline

Audrey Adeline

Researcher, SquareX
Audrey is currently a security researcher at SquareX and published author of The Browser Security Field Manual. She leads the Year of Browser Bugs (YOBB) project which has disclosed multiple major architectural browser vulnerabilities to date. Key discoveries from YOBB include Polymorphic... Read More →
Saturday April 26, 2025 3:00pm - 3:45pm PDT
AMC Theatre 06 AMC at Metreon

4:00pm PDT

Decentralized Communications: Deep-Dive into APRS and Meshtastic
Saturday April 26, 2025 4:00pm - 4:45pm PDT
This talk compares APRS and Meshtastic protocols for decentralized communications, examining their security models, vulnerabilities, and real-world applications. We will explore how these systems handle encryption, authentication, and their attack surface.
Saturday April 26, 2025 4:00pm - 4:45pm PDT
AMC Theatre 06 AMC at Metreon
 
Sunday, April 27
 

11:30am PDT

Effective Handling of Third-Party Supplier Incidents
Sunday April 27, 2025 11:30am - 12:15pm PDT
Discover efficient incident handling strategies for third-party supplier incidents. Learn the importance of a predefined process and collaboration between risk management and incident response teams. Gain insights into key decision-making considerations and elevate your IR capabilities.
Speakers
avatar for Kasturi Puramwar

Kasturi Puramwar

Information Security Manager, Equinix
Sunday April 27, 2025 11:30am - 12:15pm PDT
AMC Theatre 06 AMC at Metreon

1:15pm PDT

CyberCAN: A Roadmap for Municipal Support of Nonprofit Cybersecurity in SF
Sunday April 27, 2025 1:15pm - 2:00pm PDT
UC Berkeley studied 68 San Francisco nonprofits to assess their cybersecurity needs, resources, and adoption of protective controls. Our findings include actionable recommendations for the City of San Francisco to improve support for nonprofits and boost resilience against growing cyber threats.
Speakers
SP

Sarah Powazek

UC Berkeley CLTC
Sarah Powazek is the Program Director of Public Interest Cybersecurity at the UC Berkeley Center for Long-Term Cybersecurity (CLTC), where she leads flagship policy and research work to help under-resourced public interest organizations improve their defenses. Sarah co-leads the Consortium... Read More →
avatar for Shannon Pierson

Shannon Pierson

Senior Fellow of Public Interest Cybersecurity, UC Berkeley Center for Long-Term Cybersecurity
Shannon Pierson is a senior fellow of Public Interest Cybersecurity at the UC Berkeley Center for Long-Term Cybersecurity (CLTC), where she leads research initiatives focused on strengthening the cybersecurity of organizations that often fall through the cracks of cyber defense—namely... Read More →
Sunday April 27, 2025 1:15pm - 2:00pm PDT
AMC Theatre 06 AMC at Metreon

2:15pm PDT

Compliance Without the Chaos: Building It Right Into Your DevOps Pipeline
Sunday April 27, 2025 2:15pm - 3:00pm PDT
Compliance often feels like the party crasher in the DevOps world- unwanted, and slowing everyone down. But what if compliance could be an insider, seamlessly fitting into your CI/CD pipeline without breaking a sweat? In this talk, we’ll tackle the age-old battle between engineers and compliance.
Speakers
avatar for Varun Gurnaney

Varun Gurnaney

Staff Security Engineer, GRC Engineering
Security Engineer in of San Francisco. Previously held security roles at Robinhood, Zendesk and EY.  I didn’t watch the eclipse
Sunday April 27, 2025 2:15pm - 3:00pm PDT
AMC Theatre 06 AMC at Metreon

3:15pm PDT

Slaying the Dragons: A Security Professional’s Guide to Malicious Packages
Sunday April 27, 2025 3:15pm - 4:00pm PDT
This session reveals how attackers exploit typosquatting, author impersonation, and innovative malware campaigns to infiltrate software supply chains. Learn practical threat hunting methodologies and gain step-by-step guides to detect, analyze, and defend against these software supply chain dragons.
Speakers
Sunday April 27, 2025 3:15pm - 4:00pm PDT
AMC Theatre 06 AMC at Metreon

4:15pm PDT

The Silent Breach: Security Threats in Google Workspace
Sunday April 27, 2025 4:15pm - 4:45pm PDT
Google Workspace enables enterprise productivity, but attackers exploit logging gaps to escalate privileges, exfiltrate data, and evade detection. This talk reveals real-world attacks that bypass monitoring and shares techniques to investigate these threats, even without sufficient logs.
Sunday April 27, 2025 4:15pm - 4:45pm PDT
AMC Theatre 06 AMC at Metreon
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.