Editor's Picks
Best Talks at BSides NYC 2025 (0x05)
Hand-picked from in-depth reviewer verdicts — the top 12 talks from this conference. Skip the noise, find the signal.
-
1
Spycraft 2.0: Hunting Dead Drops in Web Applications
Jonathan Fuller
In "Spycraft 2.0: Hunting Dead Drops in Web Applications," Jonathan Fuller, CISO at the United States Military Academy and an assistant professor specializing in forensics and malware analysis, delves into cutting-edge techniques for disrupting botnets by turning adversaries'…
0 Dr. Zero STRONG ACCEPT ★★★★☆ H Heather Calloway SOLID ★★★☆☆ -
2
Using Volatility 3 to Detect Sophisticated Malware
Andrew Case
In this insightful talk from BSides NYC, Andrew Case, Director of Research at Vexity and a core developer of the Volatility memory forensics framework, delved into the critical role of **memory forensics** in detecting highly sophisticated malware. The presentation highlighted…
0 Dr. Zero STRONG ACCEPT ★★★★☆ H Heather Calloway SOLID ★★★☆☆ -
3
Unseen in the Stack: Mapping Hidden Java Dependencies for Real-World Defense
Oron Gutman
This talk, presented by Oron Gutman, Co-founder and CTO of Hopper Security, unveils critical research into the pervasive yet often overlooked problem of **shaded and repackaged libraries** within the Java ecosystem. Based on an extensive analysis of real-world Maven…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆ -
4
Trust at Scale: Lessons Learned from a Decade of Engineering for Identity
Frederic Rivain
In his BSides NYC talk, "Trust at Scale: Lessons Learned from a Decade of Engineering for Identity," Frederic Rivain, CTO of Dashlane, offered a candid and insightful retrospective on the challenges and triumphs of building and scaling a security-focused product over nearly ten…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆ -
5
The Log Rings Don't Lie: Historical Enumeration in Plain Sight
Bleon Proko
In a revealing talk at BSides NYC, security researcher Bleon Proko from Exa Force illuminated a critical, yet often overlooked, attack vector in cloud environments: the weaponization of **logs** for historical enumeration. While logs are universally understood as vital tools…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆ -
6
From pocket to Pwn: How we hacked a multinational corp for $200 with what's in our pockets
Tim Shipp
In this compelling BSides NYC talk, Tim Shipp, CTO and co-founder of Threat Lights, unveils a highly effective, low-cost attack methodology that successfully compromised a multinational corporation. Titled "From pocket to Pwn: How we hacked a multinational corp for $200 with…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆ -
7
Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks
Cory Wolff
In "Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks," Cory Wolff, Director of Offensive Security at Risk 360, provides an unprecedented look into the internal operations of two of the most prolific ransomware groups: Black Basta and LockBit. Drawing…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆ -
8
Sniffing Out Cert Abuse: A Dogged Approach to ESC Remediation
Emily Leidy
In this insightful talk, Emily Leidy, a Managing Consultant at Spectre Ops, delves into the pervasive and critical security risks posed by misconfigurations in **Active Directory Certificate Services (ADCS)**. Specifically, she focuses on **Escalation (ESC)** attack paths…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆ -
9
Inside Cloud Attack Paths: End-to-End Adversary Simulation
Mauricio Velazco
In an increasingly cloud-centric world, traditional cybersecurity defenses are proving insufficient against evolving adversary tactics. Mauricio Velazco's talk, "Inside Cloud Attack Paths: End-to-End Adversary Simulation," at BSides NYC, illuminated a critical shift in the…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆ -
10
From CISA to Starting Up: Shifting Secure by Design at Scale
Jack Cable
Jack Cable, CEO and co-founder of Corridor, delivered a compelling talk at BSides NYC, tracing his journey from leading the "Secure by Design" initiative at the Cybersecurity and Infrastructure Security Agency (CISA) to founding a startup focused on securing AI coding. The…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆ -
11
Beyond Vibe Coding: Building Reliable AI AppSec Tools
Emily Choi-Greene
In "Beyond Vibe Coding: Building Reliable AI AppSec Tools," Emily Choi-Greene delves into the critical intersection of artificial intelligence and application security, advocating for the strategic application of AI to solve pressing security challenges. While acknowledging the…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆ -
12
Cloud's Dirty Little Secret: It Was Misconfigs All Along
Karl Ots
In "Cloud's Dirty Little Secret: It Was Misconfigs All Along," Karl Ots, a Cloud Security Lead and consultant at EPAM, delivers a pragmatic and critical assessment of the persistent threat posed by cloud misconfigurations. Drawing from extensive experience as both a cloud…
0 Dr. Zero SOLID ★★★☆☆ H Heather Calloway SOLID ★★★☆☆