BSides NYC 2023 (0x04)
BSides NYC 2023 is the community-driven, volunteer-run security conference held at John Jay College of Criminal Justice, featuring Red, Blue, and Other talk tracks.
→ See editor’s top picks at BSides NYC 2023 (0x04)
- Opening Remarks — Huxley Barbee, Shweta Jain
This article details the opening remarks for BSides NYC 2023, a significant event marking the conference's return after a five-year hiatus. Delivered by Huxley Barbee, the primary organizer, and…
- Keynote — Lance James
In his compelling keynote at BSides NYC, Lance James, CEO of Unit 221B, delivered a provocative and insightful critique of the conventional cybersecurity landscape, urging the community to "reboot"…
- The Rise and Fall of the Trickbot and Conti Empires — Alex Holden
In a captivating presentation at BSides NYC, Alex Holden, CEO of Hold Security, unveiled the intricate, often turbulent, history of two of the most notorious cybercriminal organizations of the past…
- Low Code High Risk: Enterprise Domination via Low Code Abuse — Michael Bargury
In an era where digital transformation is paramount, low-code and no-code platforms have emerged as powerful tools, empowering business users—often termed **citizen developers**—to rapidly build…
- Hunting Threat Actors using OSINT Forensics — Abi Waddell
In this compelling presentation from BSides NYC, Abi Waddell, Vice President of Security Testing at Inquirics, delved into the often-overlooked yet critical domain of **Open Source Intelligence…
- The FBI Citizen's Academy: Outreach Experience — Beck (blither)
In "The FBI Citizen's Academy: Outreach Experience," Beck (blither), a seasoned CISO, offers a unique and deeply personal account of her participation in the FBI Citizen's Academy. This talk…
- xIoT Hacking Demonstrations & Strategies to Disappoint Bad Actors — Brian Contos
In a compelling presentation at BSides NYC, Brian Contos, Chief Strategy Officer at Sevco Security, illuminated the pervasive and often-overlooked security risks associated with **Extended Internet…
- Analyzing volatile memory on a Google Kubernetes Engine node — Marcus Hallberg
In this insightful talk at BSides NYC, Marcus Hallberg, a Detection Engineer at Spotify, unveiled a novel approach to conducting volatile memory analysis on Google Kubernetes Engine (GKE) nodes. The…
- Modern Day Automobile Safety: Rescue Ops using CanBus — Checco, Kat Delorean
In an era where vehicles are increasingly sophisticated computers on wheels, the security implications extend far beyond protecting personal data or preventing theft. This talk, "Modern Day…
- Pen Testing for NOT Dummies — Alex Holden
In his talk, "Pen Testing for NOT Dummies," Alex Holden delivers a compelling and experience-driven critique of conventional penetration testing methodologies, advocating for a more complex…
- Closing the Gap vs Adversaries With Community Resources — Ian Davila
In this insightful talk from BSides NYC, Ian Davila, Lead Adversary Emulation at Scythe Cyber, delves into the critical importance of **threat-informed defense** and how organizations can leverage…
- Hacking Serverless Applications: A Treasure Map for Uncharted Waters — Matteo Rosi
Matteo Rosi's talk, "Hacking Serverless Applications: A Treasure Map for Uncharted Waters," delivered at BSides NYC, explores the evolving landscape of application security in the era of serverless…
- Elements of an Effective Software Supply Chain Strategy — Anita D'Amico
In this insightful talk at BSides NYC, Anita D'Amico, Vice President of Cross-Portfolio Solutions and Strategy at Synopsys, delves into the multifaceted landscape of software supply chain risk…
- The Dark Side of ChatGPT: Balancing Innovation and Security in the Age of Generative AI — Aditya Patel
Aditya Patel's talk, "The Dark Side of ChatGPT," delves into the burgeoning security, privacy, and ethical challenges posed by large language models (LLMs) like ChatGPT, Google Bard, and Bing…
- Infrastructure as Remote Code Execution: How to abuse Terraform to elevate access — Mike McCabe
This talk, presented by Mike McCabe, President of Cloud Security Partners, delves into the often-overlooked security implications of Infrastructure as Code (IaC) tools, specifically focusing on…
- The Metrics Mess: Why the Lack of Clear and Common KPIs is Undermining SecOps (and How We Can Fix It) — Eric Olson
Eric Olson, a self-described "NBA bean counter weenie" who accidentally found his way into cybersecurity in 1999, delivered a compelling talk at BSides NYC addressing a fundamental flaw in the…
- Beyond the Buzz: SBOMs, AI, and DataOps for Organizational Resilience in a Post-Log4j World — Jessie Jamieson
In an era defined by escalating supply chain attacks and the rapid proliferation of artificial intelligence, Jessie Jamieson's talk at BSides NYC, "Beyond the Buzz: SBOMs, AI, and DataOps for…
- Save the Environment (Variable): Hijacking Legitimate Applications with a Minimal Footprint — Wietze Beukema
In this insightful talk from BSides NYC, Wietze Beukema of CrowdStrike unveils a novel and stealthy technique for **DLL hijacking** that leverages **environment variables**. The presentation delves…
- Broken links - Behind the scenes of Supply Chain breaches — François Proulx
In this comprehensive talk, François Proulx, Senior Product Security Engineer at Boost Security, dissects the rapidly escalating threat landscape of **software supply chain security**. The…
- A few tricks to Anonymizing your Red Team — Patrick Matthews
In the dynamic and often adversarial landscape of cybersecurity, red teams and penetration testers are constantly striving to enhance their effectiveness while maintaining operational security…
- BSidesNYC 0x04 CFP Information — Huxley Barbee
This presentation by Huxley Barbee of BSidesNYC serves as the official Call for Papers (CFP) for the fourth annual BSides NYC conference, scheduled for October 19th, 2024, at John Jay College. Far…
- Closing Remarks — Huxley Barbee