BSides NYC 2024
BSides NYC 2024 (0x04) is the community-driven, volunteer-run security conference held at John Jay College of Criminal Justice, featuring Red, Blue, Other, and Entrepreneur tracks.
→ See editor’s top picks at BSides NYC 2024
- Launch — Huxley Barbee
This article details the opening remarks from the BSides NYC 2024 conference, delivered by Huxley Barbee, the Lead Organizer from Peace Science University, followed by an introduction from Professor…
- BSidesNYC 0x04 Keynote: When Do We Get to Play On Easy Mode? — Wendy Nather
Wendy Nather, a distinguished voice in the cybersecurity community and a member of the National Academy of Sciences committee on hard problems in cybersecurity, delivered a thought-provoking keynote…
- Building Burp Extensions with Kotlin — Nick Coblentz
This presentation, delivered by Nick Coblentz, a seasoned application penetration tester and PortSwigger Discord moderator, delves into the advantages and practicalities of developing Burp Suite…
- Breaking free from the chains of fate - Bypassing AWSCompromisedKeyQuarantineV2 Policy — gl4ssesbo1, Opie
This talk, "Breaking free from the chains of fate - Bypassing AWSCompromisedKeyQuarantineV2 Policy," delivered by gl4ssesbo1 and Opie (with initial research collaboration from Andrew Kraut) at…
- How I hacked a cloud production environment with external Terraform manipulation — Uri Aronovici
In his compelling BSides NYC talk, "How I hacked a cloud production environment with external Terraform manipulation," Uri Aronovici, CTO and co-founder of Zest, unveiled critical security risks…
- Discover the Unseen: Azure Vulnerability Exploitation — Scott Miller
In his BSides NYC talk, "Discover the Unseen: Azure Vulnerability Exploitation," Scott Miller, a seasoned pentester at Accenture, provided a deep dive into common misconfigurations and attack paths…
- From HiatusRAT to Cuttlefish: advances in credential theft through the router — Danny Adamitis
In a revealing presentation at BSides NYC, Danny Adamitis, a researcher from Lumen Technologies' Black Lotus Labs, unveiled a detailed case study of persistent and sophisticated Chinese espionage…
- How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts — Moshiko
This talk, presented by Moshiko from Appwin at BSides NYC, unveils critical security research demonstrating how his team successfully impersonated Google Cloud Code, a popular Visual Studio Code…
- RE-Thinking: Modernizing the Malware Analyst — Joseph Edwards
Joseph Edwards' talk, "RE-Thinking: Modernizing the Malware Analyst," delves into the evolving landscape of malware analysis, highlighting critical gaps in current educational approaches and…
- XZ Backdoor: Navigating the Complexities of Supply Chain Attacks Detected by Accident — DevSecYoad
In an era increasingly reliant on open-source software, the talk "XZ Backdoor: Navigating the Complexities of Supply Chain Attacks Detected by Accident" delivered by DevSecYoad, CEO and co-founder…
- 10 Things to Know Before You Work on Your Next M365 BEC — Ida Musheyev-Polishchuk, Natasha Vij
In an insightful talk at BSides NYC, Ida Musheyev-Polishchuk and Natasha Vij, both from Strauss-Friedberg's Digital Forensics and Incident Response (DFIR) team, shed light on the intricacies of…
- Bridging the Gap: Developing Accessible Anti-Phishing Solutions — Lydia Stepanek
In "Bridging the Gap: Developing Accessible Anti-Phishing Solutions," Lydia Stepanek, a seasoned software engineer and consultant, addresses the persistent and evolving threat of phishing, arguing…
- Building canaries with ELK and ElastAlert2 — Andrew Januszak, Keith Erekson
In "Building Canaries with ELK and ElastAlert2," Andrew Januszak and Keith Erekson from Lehigh University present a practical, cost-effective approach to enhancing organizational security through…
- Trusted Types: DOM XSS Protection at Scale — Jen Ozmen, Youssef Attia
This talk, presented by Jen Ozmen and Youssef Attia, Software Engineers at Google, introduces **Trusted Types**, an innovative browser feature designed to mitigate **DOM-based Cross-Site Scripting…
- CloudTail: Making Heads or Tails of Selectively Retaining Multi-Cloud Logs (w/o a SIEM!) — Ela Dogjani
In the increasingly complex landscape of cloud computing, effective log management stands as a cornerstone of robust security and operational resilience. However, the proliferation of services and…
- Panel: Ctrl-Alt-Detected: Unraveling Threats with Detection Practitioners
This panel discussion, "Ctrl-Alt-Detected: Unraveling Threats with Detection Practitioners," brought together leading voices in detection engineering from Snowflake, Salesforce, Twitch/NASA/Stripe…
- Open & Secure: Novel Sandboxing Technique for Any Open Source Library — Gal Elbaz
In this compelling talk at BSides NYC, Gal Elbaz, CTO and co-founder of Oligo Security, unveiled a groundbreaking approach to securing the ubiquitous world of open-source software. The presentation…
- Protecting Snowflake and Critical Data Systems from Unauthorized Access — Shelley, Stephen Spano
In an era where data is often a company's most valuable asset, securing critical data systems like Snowflake against unauthorized access has become paramount. This talk, delivered by Shelley, a…
- Detection and Triage of Domain Persistence — Joshua Prager, Nico
This talk, presented by Nico and Joshua Prager from SpectreOps, delves into the critical and often overlooked area of **domain persistence techniques** utilized by advanced adversaries. Drawing from…
- When Apps Attack: Hunting Traitorware and Rogue Microsoft 365 Apps at Scale — Matt Kiely, Christina Parry
In this compelling talk, "When Apps Attack: Hunting Traitorware and Rogue Microsoft 365 Apps at Scale," Matt Kiely and Christina Parry from Huntress shed light on what they describe as one of the…
- Fortifying Active Directory: Combatting Misconfigurations — Jeff
In his BSides NYC presentation, "Fortifying Active Directory: Combatting Misconfigurations," Jeff Tomkiewicz delves into the pervasive and often overlooked security vulnerabilities stemming from…
- Cloud Warfare: Grappling and Strangling Scattered Spider — Andi Ahmeti, Abian Morina
In the dynamic landscape of cloud security, threat actors continually evolve their tactics, techniques, and procedures (TTPs) to bypass traditional defenses. The talk "Cloud Warfare: Grappling and…
- The Life of an SBOM: Where does it go and what do organizations do to it and with it? — Anita D'Amico, Ken Zalevsky
In an era of increasing software supply chain attacks and regulatory scrutiny, the Software Bill of Materials (SBOM) has emerged as a critical tool for transparency and risk management. This talk…
- Challenges of GraphQL security in 2024 — Tristan Kalos, iCarossio
In "Challenges of GraphQL security in 2024," Tristan Kalos and Antoine Carossio, co-founders of the API security company ESCAPE, presented exclusive research from their "State of GraphQL Security…
- Securing a Generative AI Implementation — eyrsec
In this insightful talk, Nandita Joshi, a Senior Product Security Engineer at Zendesk, delves into the critical and rapidly evolving domain of **Generative AI (Gen-AI) security**. Titled "Securing a…
- How to Talk So That They Will Listen: Selling Cybersecurity — May Brooks
In "How to Talk So That They Will Listen: Selling Cybersecurity," May Brooks, a seasoned CISO turned entrepreneur and advisor, delivers a compelling exploration into the art and science of…
- Panel: So You Want to Be a Founder?
The "So You Want to Be a Founder?" panel at BSides NYC offered a candid, no-holds-barred look into the exhilarating yet often brutal world of startup entrepreneurship, particularly within the…
- Building Cyber Products Customers Love — Ross Haleliuk
Ross Haleliuk's talk at BSides NYC, "Building Cyber Products Customers Love," delves into the unique and often challenging landscape of cybersecurity product management. Haleliuk, an author and…
- Startup Survival Tips and Uncommon Sense for First-Time Tech Founders — Eldon Sprickerhoff
Eldon Sprickerhoff's talk, "Startup Survival Tips and Uncommon Sense for First-Time Tech Founders," delivered at BSides NYC, serves as a candid and sobering guide for aspiring and early-stage…
- Closing Ceremonies — Huxley Barbee
The "Closing Ceremonies" at BSides NYC 2024, led primarily by Huxley Barbee, served as more than just a formal conclusion to the event; it was a vibrant affirmation of the conference's successful…