Attacking the Identity Plane: A Purple Team Framework for SPIFFE/SPIRE
Red Team Track · 10am–11am · Bodhisattva Das
SPIFFE and SPIRE promise to eliminate static credentials from cloud-native infrastructure. Short-lived X.509 SVIDs, automatic rotation, cryptographic workload identity, the security properties are genuinely excellent. The attack surface they introduce is not widely understood.
This talk presents the first open-source framework for attacking and detecting SPIFFE/SPIRE deployments. Running against a real SPIRE deployment, not slides, not a mock server. 13 attack scenarios cover all 10 documented SPIFFE/SPIRE attack vectors.
The framework also introduces spiffe-security-bench, a kube-bench-equivalent auditing tool that scans live SPIRE deployments for 23 security controls across server configuration, agent configuration, trust bundle management, and workload attestor hardening. SPIFFE is a CNCF graduated project.
The security community does not yet have structured offensive tooling for it. This talk changes that.
Ghost Admins: How Attackers Own Environments Without Touching a User Account
Blue Team Track · 10am–11am · Craig Birch
Organizations have spent years protecting human identities with MFA, Conditional Access, and privileged access controls. Attackers have responded by targeting the identities those controls often overlook: app registrations, service principals, managed identities, gMSAs, and service accounts. These nonhuman identities frequently hold standing privilege across Active Directory, Microsoft Entra ID, Microsoft 365, Azure, and Intune.
In this session, we'll examine five real-world attack paths attackers use to abuse nonhuman identities, including app registration hijacking, managed identity abuse, orphaned gMSAs, Service Connection Point manipulation, and Intune policy tampering. Attendees will learn how these attacks work, why they often evade traditional detection, and how to identify, monitor, and secure privileged nonhuman identities before they become an attacker persistence mechanism
Foiled: A Side-Channel Attack on Sealed Sports and Trading Card Packs
Solar Punk/Hardware Hacking Track · 10am–11am · packenheimer
Scalpers, collectors, and corporations have tried countless methods to gain access to data about the contents of sealed sports and trading card packs to create information asymmetry and generate profits. From using metal detectors to lasers to scales to x-ray machines, all existing methods of information extraction have either been incorrect, unreliable, or economically unfeasible. Manufacturers have taken steps to mitigate such attempts through use of foil wrappers, decoy cards, pulp weight adjustments, and more.
This talk reveals a new side-channel attack on all modern sports and trading card packs that bypasses current prevention techniques. Using widely available and inexpensive components, this method of attack can reveal the contents and classification of pack contents without altering or damaging the product. The presentation will reveal the methods used, discuss ethical considerations, and reveal countermeasures that can be implemented in future pack construction.
Leveraging Frida to Bypass Mobile Application Security Controls
Red Team Track · 11am–12pm · Jr0dR87
I gave this talk at DEF CON 34. It introduces Frida: what it is, what it's capable of, and how to put it to work during a penetration test. I walk through a recent engagement where I used Frida to run an application on a jailbroken device and get past the app's jailbreak detection. Along the way I use Frida scripts to enumerate and identify classes and methods, pinpoint the security protections in place, and then pull an existing script from Frida CodeShare to bypass those controls and run the app on a jailbroken iPad.
Most organizations aren’t trying to build unsafe AI. But positive intent doesn’t prevent prompt injection, sensitive data exposure, excessive agency, or the other risks identified in the OWASP Top 10 for LLM and GenAI applications.
Security problems take shape long before Security sees the system.
This session maps the OWASP Top 10 across an enterprise AI lifecycle: from ideation and intake through assessment, design, build/buy, validation, deployment, and monitoring. Earlier decisions can shape AI security risk.
We’ll follow several threats backward and look at the business, governance, data, and architecture decisions that influenced the risk. Who was involved? Who should have been? And at what point could a different decision have changed the outcome?
AI governance teams don’t need to become security engineers. But we do need to understand when security needs a seat at the table and make sure they get there before risk is built into the architecture.
Three Paths of Hacktivism: Russia, Ukraine and Belarus
Solar Punk/Hardware Hacking Track · 11am–12pm · Ian Litschko
Exploring the hacktivist landscapes of Russia, Ukraine and Belarus, this talk will look at how the war in Ukraine has shaped the three diverging paths for each country's hacktivist landscape. It will explore novel approaches adopted by hacktivist personas across the three countries, and the differing circumstances for each country that have influenced these choices. The result is a novel framework through which to explore the broader global hacktivist landscape and how real world changes can significantly influence hacktivist activity.
The audience will leave this talk with a deeper understanding of hacktivism within Russia/Ukraine/Belarus, and a framework through which to consider hacktivism in a global context. For attendees, they can then apply this to their individual company threat landscapes and explore how the hacktivist landscape can change to inform leadership as the global environment changes.
Pentesting with Claude Code
Red Team Track · 12pm–1pm · Michael Zinn
I told an AI coding agent to pentest my own home lab and see if it could escape a container to the hypervisor. This is what happened.
Claude Code enumerated eleven web apps on a segmented Proxmox network, fingerprinted a Gitea instance, and found CVE-2026-59774, a CVSS 9.8 unauthenticated file read with no public exploit. It read the advisory, built its own proof of concept, and chained that read into instance secrets and a stolen credential database. Then it went for RCE and escape. My defenses held, and it said so instead of overstating.
What surprised me: I ran the identical engagement on three Claude models. One stalled at looks outdated. One refused the offensive work on policy grounds despite being fully capable. One ran it end to end and turned the engagement into eight reusable skills.
Expect a real CVE, a real exploit chain, live evidence, and an honest read on where AI agents help offensive security, where they stop, and why model choice is methodology, not preference.
The Common Sense Security Framework: Revisited and Revised
Blue Team Track · 12pm–1pm · Jerod Brennen
20 years ago, I learned first-hand how disconnected cybersecurity was from any organization smaller than an enterprise.
10 years ago, I took to a BSides stage to pitch a different approach to building a cybersecurity program: The Common Sense Security Framework.
This year, I vetted the framework against data from the most well-known, well-established global cybersecurity reports, and you know what?
It fits like a glove.
The CSSF is built on two core beliefs: any program too complicated to explain to your C-suite is broken, and fundamentals will win the day.
Ten years may have changed how we conduct business and the threat landscape, but the CSSF holds up better than ever.
What does a decade of data breach data confirm we got right a decade ago? What really changed? What does common sense look like now?
I built version 2.0 to answer that. Same principles, sharper edges, and ten years of proof behind it.
Now it’s time to share the new CSSF with the world.
Securing the Green Digital Thread
Solar Punk/Hardware Hacking Track · 12pm–1pm · Vivek
Manufacturers increasingly rely on PLM platforms, supplier integrations and Digital Product Passports to exchange carbon and product data. These connected systems create security risks: unauthorized changes to bills of materials, supplier emissions, material records or process data can compromise sustainability reports and engineering decisions.
This session explains how to protect the Green Digital Thread using identity-based access controls, data provenance, API security, cryptographic validation, immutable audit trails and anomaly detection. Attendees will learn how to detect suspicious changes in component quantities, material classifications, logistics data and emission factors.
The session also addresses third-party risk, secure supplier exchange and manipulated environmental claims. Attendees will leave with a roadmap for securing sustainability data across engineering, manufacturing, procurement and supply-chain systems.
Kickin Graphs and Takin (AR)Names: Mapping Avenues of Attack in AWS
Red Team Track · 1pm–2pm · vexance
Most documented attack paths in AWS focus on dangerous combinations of IAM permissions, but these permissions are not necessarily a complete picture of possible cloud attack chains. While several tools exist that help identify known privilege escalation paths stemming from IAM permissions, understanding the interconnectedness of AWS resources remains a significant challenge. In this session, we'll discuss attacks through the lens of improving one's position against identity, network, and resource boundaries. After discussing core attack primitives, we'll walk through new principal compromise paths we've discovered in other AWS services, showing identification steps and sample code snippets where necessary to exfiltrate IAM role credentials. The session will contain visualizations depicting attack graph patterns covered by an upcoming tool release.
Governance Is About Clarity, Not Control: Designing Guardrails for Sustainable Security Operations
Blue Team Track · 1pm–2pm · Michael Toguchi
As data risk and compliance pressures mount, organizations often respond by adding restrictive controls and heavy oversight layers. However, rigid governance frequently triggers a dangerous, hidden vulnerability: it slows execution, obscures accountability, and pushes technical teams into insecure shadow IT channels just to keep daily operations moving. True security governance is about structural clarity, not obstructive control. In this session, Michael Toguchi reframes modern data governance from a compliance box into a strategic security discipline. Introducing the "Guardrails Over Gates" framework, he outlines actionable tactics to establish safe operational boundaries, define absolute decision ownership, and maintain clear technical visibility without stalling execution speed. Security leaders will leave with data-driven insights to bridge the gap between risk management and practical execution.
Mesh Networking in Collapse: Meshtastic, MeshCore, Reticulum
Solar Punk/Hardware Hacking Track · 1pm–2pm · nopswamp
Right now the "big 3" in alternative data network infrastructure are Meshtastic, MeshCore, and Reticulum, with Meshtastic breaking into techie "mainstream". It's no surprise, building our own encrypted communications networks that don't depend on the internet is very cool and solarpunk. All 3 have promise, but have different security properties, use-cases and potential.
This talk will cover all three, though mostly Meshtastic. I'll review existing research and my own Meshtastic network simulations to give recommendations for Meshtastic buildouts, and advice on best practices for secure Meshtastic usage. I'll also cover MeshCore and Reticulum as complementary options, covering the different use-cases they excel at and their own security properties, though in less detail. I'll close with some thoughts on building alternative networks going forward, and leave attendees with enough to get started exploring any of the three options and building networks in their own communities.
This lightning talk gives attendees a fast, practical, interactive introduction to OWASP Finbot — an intentionally vulnerable agentic‑AI system designed to teach the OWASP LLM Top 10 and OWASP Agentic Top 10 through real, breakable examples.
Hardening Supply Chain Security by Pruning JavaScript Dependencies
Blue Team Track · 2pm–3pm · Jim Ender
The JavaScript ecosystem is currently built on a house of cards. With the rise of automated supply chain exploits, your biggest security hole isn't your code—it's the code you didn't write. We will analyze the hidden costs of massive node_modules folders, from CI/CD bottlenecks to critical security vulnerabilities. We will be looking at either modernizing code with updated packages, reducing supply chain dependencies and removing dead code. By the end of this talk, you’ll be equipped with the mindset and the tools to audit your tree, replace bloat with native APIs, and level up by demanding less.
The Human Grid: Powering Cybersecurity Through Knowledge, Skills, and Abilities
Solar Punk/Hardware Hacking Track · 2pm–3pm · Damon Drake
Beneath every secure network, cloud service, AI system, and incident response operation is a hidden infrastructure: the Human Grid.
This Solarpunk-inspired presentation explores how cybersecurity knowledge generates potential, skills transmit that potential into action, and abilities deliver results under real-world conditions. Participants will examine where capability is lost between education, training, credentials, roles, and workplace performance, and how employers, educators, standards developers, credentialing organizations, and practitioners can build a more connected and renewable cybersecurity workforce.
Participants will leave with a practical model for identifying where capability is generated, where it is lost, and how it can be strengthened. The session’s central message is optimistic but urgent: cybersecurity’s most renewable resource is human capability, but that resource must be intentionally cultivated, connected, and renewed.
Sockpuppets - because the world needs another c2 platform that doesn't suck
Red Team Track · 3pm–4pm · ajm4n
Off-the-shelf C2 frameworks are well-signatured. Red teams increasingly need custom tooling that EDR vendors haven't trained on, but building one from zero is a journey through every layer of the detection stack. This talk walks through the design and development of SockPuppets, an open-source polymorphic C2 framework built in Python that supports WebSocket, HTTP, and HTTPS transports with multi-language agent generation. We'll cover the engineering decisions, the evasion techniques that actually work, and the ones that don't. Topics include: - Transport design trade-offs - why WebSocket streaming, HTTP long-poll, and beacon modes each have a place, and how transport selection affects detectability - Anti-analysis layers - anti-debugging checks, sandbox/VM timing detection, and behavioral evasion techniques that matter more than obfuscation in 2026 - What actually gets caught - analysis of where modern EDR still wins, and the evasion approaches we developed in response
Inductive Compliance: Lightweight & Noninvasive Transition-Gating for Declarative Infrastruce
Blue Team Track · 3pm–4pm · Kavin Muthuselvan
Inductive Compliance is a lightweight, noninvasive model for transition gating updates in declarative systems. The model authorizes specific predecessor to successor state transitions rather than relying on invasive full-state disclosure. This talk uses a NixOS proof-of-concept to model Inductive Compliance and demonstrate projected-state compliance, local builder enforcement, and why transition-aware security can reduce drift, overhead, and unnecessary host state disclosure.
This talk will be targeted at a universal audience. I aim to leave the audience with practical knowledge of: 1. Configuring declarative systems with NixOS 2. The relationship between state and security (Configuration drift) 3. Noninvasive enforcement of security policies 4. How all three of these topics tie together with inductive compliance
Solar Punk/Hardware Hacking Track · 3pm–4pm · Nikhil Jindal
Solar panels, batteries, and community microgrids are solarpunk made real and Cleveland is building it now. Cuyahoga Green Energy's microgrid utility is set to go live soon, right as reliability failures make the case for energy independence. But the protocols connecting inverters to the grid were adapted from outdated industrial protocols never built with authentication or encryption. At scale, this becomes an aggregated grid-reliability risk: thousands of low-value devices that, compromised together, could destabilize a feeder. This talk covers the DER threat model, includes a live Modbus demo with zero authentication, and looks at real-world aggregation risk.
Security Vulnerabilities In ALPRs
Red Team Track · 4pm–5pm · Nettle
My talk will be about the security vulnerabilities in Flock (and other ALPR cameras) and how that puts people at more risk than just not having ALPRs. I hope to go over some of the safety issues these devices have (being on unsecured wifi, having exposed USB ports, etc), and beyond the technical security of the devices, I'd like to analyze some of the social consequences to surveillance, and encourage people to question if surveillance invites safety or control.
Zero-Trust CI/CD: Securing Kubernetes and GitOps Pipelines for Regulated Enterprises
Blue Team Track · 4pm–5pm · Shashi Kumar
Regulated enterprises must deliver software quickly while meeting strict security, compliance, and audit requirements such as SOX, SOC2, PCI-DSS, HIPAA, and FFIEC. Traditional CI/CD pipelines often create risk through manual approvals, inconsistent environments, excessive cluster access, and weak traceability.
This session explores how Kubernetes, GitOps, and policy-driven automation can help build secure, compliant, and observable CI/CD pipelines. It covers zero-trust architecture using pull-based GitOps tools like ArgoCD and FluxCD to reduce direct production access while supporting separation of duties and immutable change management.
Attendees will learn practical DevSecOps patterns, including policy-as-code with OPA Gatekeeper and Kyverno, supply chain security, image signing, SBOM generation, MFA-based approvals, audit-ready logging, and secure deployments across hybrid cloud and regulated environments.
Generalizing Operational Design Domains for Secure and Scalable Physical AI
Solar Punk/Hardware Hacking Track · 4pm–5pm · Vraj Mukeshbhai Patel
As Physical AI systems such as humanoid robots and mobile manipulators move from research to real-world deployment, defining secure and reliable operational boundaries has become a critical challenge. While autonomous vehicles rely on standardized Operational Design Domain (ODD) frameworks such as SAE J3016 and PAS 1883, no equivalent taxonomy exists for Physical AI platforms. This session explores how the proven four-step ODD methodology can be generalized to Physical AI using established standards including ANSI/RIA R15.08-1:2020, ISO 3691-4, ISO 13482, and the EU Machinery Regulation. Attendees will learn how operational boundaries, human interaction, deployment environments, and risk-aware constraints contribute to scalable, auditable, and security-conscious Physical AI systems, while supporting safety engineering, regulatory compliance, and resilient autonomous operations.
Groking the Kill Chain
Red Team Track · 5pm–6pm · DotNetRussell
Most LLM-powered recon tools look impressive in a 90-second demo and fall apart on real targets. They hallucinate, loop, go out of scope, double-fire the same endpoint, or die the moment a WAF or rate limit appears. This talk is about what it actually takes to run fifty-plus specialist agents in parallel for hours or days without the chaos.
We built a system where every agent is locked to the rails: a concrete tool, a strict pipeline phase, explicit prerequisites, timeouts, and sandboxes. The model does not drive. It rides. The binaries (and only the binaries) touch the target. This "Agents on Rails" approach eliminates freestyle LLM behavior while still letting the model do what it is good at—reasoning over evidence.
The SOC Intern That Never Sleeps: Lessons Learned Using AI for Security Operations
Blue Team Track · 5pm–6pm · Michael Blanchard
AI promises to transform security operations, but most organizations are still trying to answer a simpler question: "Can it actually help my analysts?" In this session, we'll examine where AI assistants provide real value in security operations and where human expertise remains essential. Through realistic investigation scenarios, attendees will see how analysts can use AI to accelerate triage, understand unfamiliar attack techniques, summarize incidents, generate hunting queries, and reduce the time spent on repetitive tasks. We'll also discuss common failure modes, hallucinations, data quality challenges, and governance concerns that security teams must address before integrating AI into their operational workflows.
The Fence Was Fine: A Tale of Infiltrating Two Datacenters
Solar Punk/Hardware Hacking Track · 5pm–6pm · Michael Stringer
A colocation provider sells physical security as a product. Fence, cameras, mantrap, badge readers, a guard desk behind bullet-proof glass staffed around the clock. The customers racking equipment inside those cages are buying that pitch, and most of them will never walk the site to check it.
Earlier this year we spent five weeks checking one. Four facilities across two campuses, and by the end a tester was standing in a room he had no badge for.
This talk walks through the engagement start to finish. We drop details on every tool, every technique, every failure, and every success on the road to pwn.
Of all the things we'll explain in this talk, the most important will be the things that would have and should have stopped us, and ultimately the thing that let us in, which is the thing that always lets us into places we are not supposed to be — people.
The audience this is for: everyone, but especially up-and-coming red teamers and blue-team looking to see how intrusion happens.
Still Phishing in 2026: Bypassing Modern Email and Identity Defenses
Red Team Track · 6pm–7pm · Sanchit Sokhey, Ashish Kumar
What happens after a user clicks a phishing link and authenticates? There's a limited window to register your own MFA method on the target account before the session hardens. We show how automated tooling wins that race and establishes persistent access, even with MFA enforced.
Getting there requires a hardened adversary-in-the-middle proxy. Default setups get caught immediately by browser-level detection of identity provider URL patterns. We cover the modifications that keep it working in 2026 against providers like Google Workspace and Microsoft 365.
We also walk through email delivery: getting past spam engines, safe browsing, and domain reputation. These layers keep improving, and so do the techniques to get around them.
We close with defenses that work: FIDO2/passkeys, device compliance, and MFA registration monitoring. Useful whether you're on offense or defense.
Stop Agents From Leaking Your Secrets - AI Hooks To The Rescue
Blue Team Track · 6pm–7pm · mcdwayne
Git gives us a way to automate just about anything. With Git hooks and off-the-shelf security tools, developers have been able to weave all sorts of checks into their Git rituals, 'shifting left' in order to eliminate security rework later. But Git was made for humans, and only the commit was meant to be shared. Today, coding assistants like Cursor, Claude Code, and Copilot can read files, propose changes, run commands, and interact with project context, often across a messy workspace. In an agentic workflow, secrets leak through context, output, and history. Fortunately, these tools have started supporting AI hooks, which allow you to move your testing closer to when the code and development artifacts are produced. Come to this session if you want to learn how hooks provide a practical pattern for catching mistakes before they leave a developer’s machine, and why AI coding tools like Cursor, Claude, and Copilot need guardrails beyond prompts and trust.
ajm4n
Sr. Red Teamer @ Praetorian, AD & Initial access researcher
As a Senior Offensive Security Engineer on the Red Team at Praetorian, my role encompasses conducting security assessments, with a specialization in Red Team Operations, and presenting risk remediation strategies to enhance client defenses across various industries. I also spearhead research initiatives involving internal windows network attacks, social engineering methodology, internal penetration testing methodology, and creating novel initial access tactics, techniques, and procedures.
Talk: Sockpuppets - because the world needs another c2 platform that doesn't suck
DotNetRussell
Cyber Security Software Engineer
Anthony Russell, is a senior cyber security engineer with over 13 years of professional experience building software. He has a focus in information security and has been featured in 2600 magazine, on Hak5 and has spoken at both Defcon and DerbyCon multiple times. Favorite things to discuss are blockchain technology, baking custom IoT devices, and everything infosec. You can see more of Anthony's work at SquidHacker.com or Twitter.com/DotNetRussell
Talk: Still Phishing in 2026: Bypassing Modern Email and Identity Defenses
Bodhisattva Das
Security Engineer - RUDRA Cybersecurity
Bodhisattva Das is a Security Engineer at Rudra Cybersecurity, focused on securing non-human identities, AI agents, and automated workloads across cloud environments. He specialises in open-source threat detection using Wazuh, and builds practical solutions for identity governance and AI-driven security operations. Driven by a passion for digital rights and responsible AI governance, he strives to build secure systems that protect people as technology evolves.
Talk: Attacking the Identity Plane: A Purple Team Framework for SPIFFE/SPIRE
Nettle
Deflock
Nettle is an educator with a knack for explaining how surveillance shapes our world - often in ways we don't notice. With a background in Computer Science and a commitment to digital awareness, Nettle works to help people understand the trade offs of living in a watched society. They believe that surveillance doesn't just watch over us - it changes how we see each other, and who holds the power.
Talk: Security Vulnerabilities In ALPRs
Craig Birch
Principal Technologist at Cayosoft | Identity Security Enthusiast
Craig Birch is a Principal Technologist at Cayosoft and an identity security practitioner specializing in Active Directory and hybrid identity environments. His work focuses on how attackers chain misconfigurations, delegated rights, and credential abuse into repeatable paths to Tier‑0 compromise. Craig regularly speaks on identity attack paths, privilege escalation, persistence, and recovery challenges, helping security teams better understand how modern AD breaches actually unfold.
Talk: Ghost Admins: How Attackers Own Environments Without Touching a User Account
Damon Drake
ybersecurity standards strategist connecting professional knowledge to workforce capability.
Damon Drake, CISSP, is a Standards Development Manager whose work focuses on cybersecurity standards, workforce capability, professional practice, and emerging AI governance. He specializes in connecting knowledge, skills, abilities, tasks, and roles to create clearer and more sustainable pathways into the cybersecurity workforce.
Talk: The Human Grid: Powering Cybersecurity Through Knowledge, Skills, and Abilities
vexance
Offensive Security Engineer
David (@vexance) is a senior security consultant at Bishop Fox. David specializes in application and cloud penetration testing with a particular interest in AWS pathfinding and privilege escalation. David enjoys tool development and has previously spoken at regional and national conferences including Hack Space Con, BSides, CornCon, and the Information Security Summit (ISS).
Talk: Kickin Graphs and Takin (AR)Names: Mapping Avenues of Attack in AWS
mcdwayne
Developer Advocate at GitGuardian and huge fan of open source
Dwayne has been working as a Developer Relations professional since 2015 and has been involved in tech communities since 2005. He loves sharing his knowledge, and he has done so by giving talks at over a hundred events worldwide. Dwayne currently lives in Chicago. Outside of tech, he loves karaoke, live music, and performing improv.
Elizabeth Wadsworth is VP of Decision Intelligence & Transformation at Velera, one of the nation’s largest payment fintechs by volume. She leads enterprise AI strategy, governance, and transformation. Her work focuses on how enterprises turn AI ambition into operating reality by connecting business decisions with governance, data, architecture, risk, and security. She holds the IAPP AIGP certification and serves on the board of Cleveland AI & Data.
Ian is a Russia-focused cyber intelligence analyst at RBC. With over a decade of experience tracking Russia-based state actors and years of in-country experience, he leverages his skillset to conduct deep dives into the organizational structure of the cyber-enabled elements of the intelligence services and delving into the Russian language deep and dark web. His work on Russian cyber activity has been cited by both Canadian and Ukrainian governments.
Talk: Three Paths of Hacktivism: Russia, Ukraine and Belarus
Jr0dR87
FRSecure. Offensive Services Team Lead of Web and Mobile Applications
My name is Jarrod Rizor. I'm the Offensive Services Team Lead of Web and Mobile Applications for FRSecure. I have been a pentester for a little over four years. I started off my career as a web developer, migrated to Devops, then landed a cybersecurity gig as a pentester in 2021. I volunteer at a local wildlife park and help birds of prey over the weekends.
Talk: Leveraging Frida to Bypass Mobile Application Security Controls
Jerod Brennen
CEO & Co-Founder, Aetos One
Jerod Brennen is CEO and Co-Founder of Aetos One and a music teacher turned hacker turned security graybeard. After 25 years in cybersecurity, he has earned every gray hair in that beard. As a fractional CISO, Jerod has enabled organizations that collectively manage nearly $5 billion in revenue. He speaks on the shift from cybersecurity as a technical function to cybersecurity as a business discipline.
Talk: The Common Sense Security Framework: Revisited and Revised
Jim Ender
Computer Engineer
Jim is part developer, part sysadmin, part security, and part miracle worker. He regularly runs and competes in CTF events and also teaches cyber security to high schoolers. He also helps to run LockPicking villages and gives talks at Cyber events throughout the midwest.
Talk: Hardening Supply Chain Security by Pruning JavaScript Dependencies
Joshua Lochner
SecEng (presenting unaffiliated)
Joshua Lochner is a cybersecurity professional with a foundation in system and network administration and operations and a passion for proactive threat mitigation. Joshua brings a wealth of experience in building resilient security infrastructures across complex retail environments.
Independent security researcher and president of the CWRU Cybersecurity Club (cyberCWRU)
Independent security researcher and current student pursuing a B.S. in Computer Science at CWRU, focusing on network security, privacy and compliance. President of CWRU's Cybersecurity Club (cyberCWRU) and member of cyberCWRU's CTF Team.
Talk: Inductive Compliance: Lightweight & Noninvasive Transition-Gating for Declarative Infrastruce
packenheimer
Matthew Crowley, PhD, Associate Professor of Computer Science, Tri-C
Dr. Matthew Crowley is an Associate Professor of Computer Science at Cuyahoga Community College and focuses on cybersecurity. He is the former CIO for Philadelphia International and Cleveland Hopkins International Airports and was an engineer on Microsoft's Internet Explorer team. He is the author of Pro Internet Explorer 8 & 9 Development from Apress and leads research funded by the National Science Foundation, the National Information Technology Innovation Center, and other organizations.
Talk: Foiled: A Side-Channel Attack on Sealed Sports and Trading Card Packs
Michael Blanchard
Cloud Solution Architect - Microsoft
Michael Blanchard is a Senior Cloud Solution Architect on Microsoft's Customer Success (Security) team, helping organizations defend identities, endpoints, and cloud workloads. A lifelong tinkerer, he runs a sprawling home lab spanning virtualization, networking, and self-hosted services — breaking, rebuilding, and truly understanding the systems he relies on. Cleveland-based, he's driven by hands-on learning, homelab culture, and sharing hard-won lessons with the security community.
Talk: The SOC Intern That Never Sleeps: Lessons Learned Using AI for Security Operations
Michael Stringer
Founder & Lead Consultant @ Nomad Security — Securing your Digital Journey
Michael Stringer (OSCP/CISSP) is Lead Consultant at Nomad Security LLC, a Cleveland-area firm specializing in Offensive Security. He specializes in physical intrusion, penetration testing, vulnerability and exploit research, and full-scope adversary simulation, with a focus on facilities where a physical compromise becomes somebody else's data breach. Michael is a teen-hacker turned consultant, with a career spanning over 15 years engaging with financial, retail, healthcare, and tech companies.
Talk: The Fence Was Fine: A Tale of Infiltrating Two Datacenters
Michael Toguchi
CSO @ Tectonic | Strategy & Digital Transformation for Higher Ed & Nonprofits
Michael Toguchi is the Chief Strategy Officer at Tectonic, where he specializes in modernizing operational workflows and data risk governance for complex, mission-driven organizations. With over 25 years of institutional experience, he has led digital transformation projects for prominent universities, foundations, and non-profits—including Stanford, UC Davis, and Rutgers. Michael specializes in helping leadership teams turn organizational complexity into sustainable operational capacity.
Talk: Governance Is About Clarity, Not Control: Designing Guardrails for Sustainable Security Operations
nopswamp
Independent Researcher
I call southeast Michigan home, and have done software engineering and security research professionally in a number of not-so-easy-to-define roles for over a decade touching on CDMA modems, Android ROMs, Linux appliances, eBPF research, and more. I've been tinkering with mesh networking lately, and am always looking for new and interesting opportunities in security research and offensive security.
Talk: Mesh Networking in Collapse: Meshtastic, MeshCore, Reticulum
Michael Zinn
Cyber threat intelligence professional who pointed an AI coding agent at his own network to see how far it would actually get.
Michael Zinn is a Cleveland-based cybersecurity professional holding CCE, CEH, and CHFI certifications, working in cyber threat intelligence and digital forensics. He publishes Behind the Firewall, a newsletter tracking active exploitation, CVEs, and critical infrastructure threats. Off the clock, he runs a segmented Proxmox home lab and recently handed an AI coding agent the keys to pentest it, with mixed and surprising results.
Nikhil attended CWRU for his undergraduate degree and spent most of his non-academic time working for CWRU's University Technology and other Cleveland-based companies in cybersecurity, risk, and IT-related roles. After completing his undergraduate degree, he is now attending Carnegie Mellon University's Heinz College for a Masters in Information Security Policy & Management.
Talk: Sunny with a Chance of Blackout
Sanchit Sokhey
Senior Offensive Security Engineer
Senior Offensive Security Engineer
Talk: Still Phishing in 2026: Bypassing Modern Email and Identity Defenses
Shashi Kumar
JNTU Hyderabad, India.
Shashi Kumar Munugoti is a Principal Application Engineer and Solution Architect based in Pittsburgh, PA, with over 20 years of IT experience in Java, cloud architecture, microservices, and enterprise systems. At Discover Financial Services, he leads cloud-native microservices for the Discover Card Disputes System and has driven monolith-to-microservices migration on OpenShift. He is certified in AWS, Google Cloud, and Apollo GraphQL.
Talk: Zero-Trust CI/CD: Securing Kubernetes and GitOps Pipelines for Regulated Enterprises
Vivek
Deloitte Consulting LLP
Vivek Agrawal is a PLM and AI-driven digital engineering leader with 15+ years of experience across high-tech, CPG, medical devices, automotive, aerospace, and defense. At Deloitte, he leads global PLM strategy and transformation for Fortune 100 clients, integrating AI, Digital Thread, Digital Twin, ERP, MES, and QMS. He has delivered multi-million-dollar programs, including a PLM transformation generating over $20 million in annual savings.
Vraj Mukeshbhai Patel is a Staff Systems Engineer with 9+ years of experience designing autonomous systems and Physical AI for safety-critical applications. He specializes in autonomous vehicles, humanoid robotics, perception, SLAM, systems architecture, and functional safety. At Apptronik, he leads autonomy architecture for next-generation humanoid robots using scalable, safety-first engineering.
Talk: Generalizing Operational Design Domains for Secure and Scalable Physical AI
About the Venue
Tinkham Veale University Center at Case Western Reserve
University is a modern event and conference facility in University Circle. The venue offers multiple presentation rooms, open gathering spaces,
and convenient parking access to an underground garage.
BSides Cleveland 2026 is proud to be part of
Cleveland Tech Week’s
second annual collection of events this year. Tech Week is a decentralized, community-driven
celebration of Cleveland’s technology ecosystem, running
September 26 – October 3, 2026 — kicking off the
same day as our conference. The week brings together 60+ independently hosted events from
70+ organizations and companies across the region, with 3,000+ attendees expected to take part.
Follow along with #CLETechWeek26 and
#BuildTheTide, and join us in celebrating this year’s
theme: “A Rising Tide Lifts All Boats.” Learn more about the full lineup at
cletechweek.com.
Food and Beverages
12pm–6pm
Coffee and water will be provided. Bar service and a possible included lunch may become
available if sufficient sponsorship is secured.
Two food trucks — Oh Taste and See and
Yum Village — will be on site for a
portion of the day as a lunch option. Additional options include a selection of walkable
restaurants nearby, and on the venue's 1st floor at least Dunkin’
and Med23 should be open.
Outside food cannot be carried back into presentations and must be consumed outside the ballroom.
Parking
7am–Midnight
Street parking is free on Saturdays, a parking garage is in the same building for
$11, and public transportation lines have
stops very close to the venue.
After Party
7pm–10pm
Attendees who want to hang out longer can meet back up at
The Jolly Scholar, next door to the venue and
familiar as last year's beer sponsor. Food and drinks are out of pocket unless/until sponsorship
is secured to cover appetizers.
CTF
10am–1pm (CyberProAI)10am–6pm (Quantum Village)
Day-of CTFs will be provided by CyberProAI and
the Quantum Village.
You can register now for the CyberProAI CTF, which will be open
from 10am to 1pm of conference day. You can participate virtually without conference registration as well!
Villages
10am–6pm
The following villages will be in attendance, offering hands-on activities and demos throughout the day.
As seen at DEF CON, Quantum Village brings together researchers and enthusiasts exploring
quantum computing and its implications for cryptography and security, with hands-on demos
of quantum hardware and concepts.
Locksport
A hands-on physical security village where attendees can learn and practice lock picking,
from beginner-friendly locks to more advanced challenges, under the guidance of experienced
locksport enthusiasts.
A nonprofit collective of aviation, space, and cybersecurity experts focused on the security
of aerospace systems. Known for hands-on demos with real aircraft avionics and satellite
hardware at events like DEF CON, the village helps attendees explore the unique security
challenges of planes and spacecraft.