Loading…
Venue: AMC Theatre 15 clear filter
Saturday, April 26
 

11:15am PDT

Inside the Information Stealer Ecosystem: From Compromise to Countermeasure
Saturday April 26, 2025 11:15am - 12:00pm PDT
Information stealer malware is underestimated by our industry. In this deep-dive, we look into what is captured by them – desktop screenshots, password vaults, browser extensions, MFA bypass material, etc. –, cover the Redline takedown, and offer defensive countermeasures including code and samples.
Speakers
Saturday April 26, 2025 11:15am - 12:00pm PDT
AMC Theatre 15 AMC at Metreon

1:00pm PDT

Light in the Labyrinth: Attack Path Analysis for Anyone
Saturday April 26, 2025 1:00pm - 1:45pm PDT
Learn to build your own treasure map of how attackers might move laterally through your company’s assets. We’ll provide a conceptual engineering framework for attack path analysis, recommend no- or low-cost tools, share examples, and release an open-source attack graph ontology to learn from.
Speakers
Saturday April 26, 2025 1:00pm - 1:45pm PDT
AMC Theatre 15 AMC at Metreon

2:00pm PDT

Hack, Patch, Repeat: Insider Tales from Android’s Bug Bounty
Saturday April 26, 2025 2:00pm - 2:45pm PDT
What does it take to secure 3 billion users on the world’s leading mobile platform? This session dives into Android security from a holistic perspective.
Saturday April 26, 2025 2:00pm - 2:45pm PDT
AMC Theatre 15 AMC at Metreon

3:00pm PDT

0.0.0.0 Day: Exploiting Localhost APIs From The Browser
Saturday April 26, 2025 3:00pm - 3:45pm PDT
While seemingly local, services running on localhost are accessible to the browser using a flaw we found, exposing the ports on the localhost network interface, and leaving the floodgates ajar to remote network attacks. This session will dive into the 0.0.0.0 exploit research conducted by the team.
Speakers
Saturday April 26, 2025 3:00pm - 3:45pm PDT
AMC Theatre 15 AMC at Metreon

4:00pm PDT

Service Mesh Security: Shifting Focus to the Application Layer
Saturday April 26, 2025 4:00pm - 4:45pm PDT
Discover how Yelp's Infrastructure Security team transformed past challenges and failures into success by shifting authentication and authorization from the infrastructure to the application layer. Learn how this pragmatic approach met all security requirements applicable to Yelp's threat model.
Speakers
Saturday April 26, 2025 4:00pm - 4:45pm PDT
AMC Theatre 15 AMC at Metreon

5:00pm PDT

Netsec is dead(?): Modern Network Fingerprinting for Real-World Defense
Saturday April 26, 2025 5:00pm - 5:45pm PDT
From p0f to MuonFP and JA4+, learn how network fingerprinting evolved. See how each step helps security teams spot malicious traffic, detect scanners, and more. Attendees gain real-world use cases and practical tips to deploy fingerprinting for monitoring and threat hunting.
Speakers
Saturday April 26, 2025 5:00pm - 5:45pm PDT
AMC Theatre 15 AMC at Metreon
 
Sunday, April 27
 

11:30am PDT

Don’t Sh*t-Left: How to Actually Shift-Left
Sunday April 27, 2025 11:30am - 12:15pm PDT
Shift-left sounds great—catch issues early, save time, empower devs—but too often it backfires, creating noise and chaos. Learn from real-world fails, laugh at sh*t-left stories, and discover practical strategies to make shift-left work. Let’s fix AppSec, one bug at a time.
Speakers
Sunday April 27, 2025 11:30am - 12:15pm PDT
AMC Theatre 15 AMC at Metreon

1:15pm PDT

Confidential Computing: Protecting Customer Data in the Cloud
Sunday April 27, 2025 1:15pm - 2:00pm PDT
Ever wonder how your data is really handled in the cloud? Confidential Computing gives you an answer by isolating your data and cryptographically proving what code was ran. This talk dives into the hardware and software behind Confidential Computing, and how to ship it in real-world cases.
Speakers
Sunday April 27, 2025 1:15pm - 2:00pm PDT
AMC Theatre 15 AMC at Metreon

2:15pm PDT

don't trust, verify! - how I found a CSRF bug hiding in plain sight
Sunday April 27, 2025 2:15pm - 2:45pm PDT
This talk explores the discovery of a long-standing CSRF (Cross-Site Request Forgery) vulnerability in the popular gorilla/csrf Go library. The goal is to encourage the audience to perform vulnerability research experiments in their own commonly used tools.
Sunday April 27, 2025 2:15pm - 2:45pm PDT
AMC Theatre 15 AMC at Metreon

3:00pm PDT

Care and Feeding of HSMs: Key Management in Hard Mode
Sunday April 27, 2025 3:00pm - 3:30pm PDT
Using cryptography solves certain problems but adds a new challenge: key management. This talk explores how various key types require different management approaches, then walks though an example of securing a long-lived code-signing key in an HSM, with a look at operational burdens and pitfalls.
Speakers
Sunday April 27, 2025 3:00pm - 3:30pm PDT
AMC Theatre 15 AMC at Metreon

3:45pm PDT

Shadow IT Battlefield: The CyberHaven Breach and Defenses that worked
Sunday April 27, 2025 3:45pm - 4:15pm PDT
Discover how the Cyberhaven breach case exposed critical Shadow IT risks—and the proactive allowlist strategy that minimized business disruption. The proactive controls saved our 40M+ users from being impacted. Gain insights, metrics, and a blueprint for continuous monitoring
Speakers
Sunday April 27, 2025 3:45pm - 4:15pm PDT
AMC Theatre 15 AMC at Metreon

4:30pm PDT

Understanding IRSF Fraud: Protecting Against SMS Exploitation
Sunday April 27, 2025 4:30pm - 5:00pm PDT
Attackers making money from MY 2FA? It's more likely than you think! SMS is a common 2FA method but creates risk: International Revenue Share Fraud, inflating SMS traffic to siphon revenue. Attendees will learn how to detect and mitigate IRSF with Cloudflare, OpenAI, and Datadog.
Speakers
Sunday April 27, 2025 4:30pm - 5:00pm PDT
AMC Theatre 15 AMC at Metreon
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.