BSides NYC 2025 (0x05)
BSides NYC 0x05 is the fifth edition of the volunteer-run, community-driven security conference held at John Jay College of Criminal Justice, featuring Red, Blue, Other, and Entrepreneur tracks.
→ See editor’s top picks at BSides NYC 2025 (0x05)
- Conference Launch and Keynote — Huxley Barbee, Shweta Jain, John Hammond
John Hammond's keynote at BSides NYC 2024, titled "The Good, Bad, and Ugly: An Origin Story," offers a deeply personal and unusually candid look into the non-linear path to a successful career in…
- Inside the Mind of a Cyber VC: What Founders Get Wrong and How to Pitch Like a Pro — Lucas Nelson
In a candid and insightful presentation at BSides NYC, seasoned **Venture Capitalist (VC)** Lucas Nelson provided an unparalleled look into the intricate world of fundraising from the investor's…
- From Interview Questions to Cluster Damage: Adventures in k8s Cluster Hacking — Amit Serper
In this insightful talk from BSides NYC, Amit Serper, a security researcher at CrowdStrike, delves into the often-overlooked security implications of Kubernetes' inherent complexity and native…
- What It's Like Being the Only Security Startup in Your YC Batch — Alex Chantavy, Kunaal Sikka
This talk provides a candid and insightful look into the challenging yet rewarding journey of founding a security startup, Subimage, and navigating the highly competitive Y Combinator (YC)…
- Essential Marketing for Cyber Founders — Gianna Whitver
In a landscape often dominated by technical prowess and advanced threat intelligence, the role of effective marketing for cybersecurity startups can be paradoxically overlooked or misunderstood…
- Spycraft 2.0: Hunting Dead Drops in Web Applications — Jonathan Fuller
In "Spycraft 2.0: Hunting Dead Drops in Web Applications," Jonathan Fuller, CISO at the United States Military Academy and an assistant professor specializing in forensics and malware analysis…
- The Human-AI Handshake: A Framework to Build Trust and Unlock Innovation in Modern Security Ops — Michael Raggi
In an era where Artificial Intelligence (AI) is frequently heralded as a transformative "Big Bang" for various industries, including cybersecurity, Michael Raggi's talk at BSides NYC offered a…
- They Don't Want to Talk to Sales—So Let the Community Sell for You — Mariana Padilla
In an insightful talk at BSides NYC, Mariana Padilla, Community Evangelist at Harmonic and former CEO of Hackerverse, challenged traditional sales and marketing paradigms in the cybersecurity…
- Unseen in the Stack: Mapping Hidden Java Dependencies for Real-World Defense — Oron Gutman
This talk, presented by Oron Gutman, Co-founder and CTO of Hopper Security, unveils critical research into the pervasive yet often overlooked problem of **shaded and repackaged libraries** within…
- How to Create Deep Partnerships with Technical Teams: Sales Engineering Lessons Learned — Samantha Pearlstein
In this insightful talk, Samantha Pearlstein, Founding Sales Engineer at Escape, addresses a pervasive challenge in the cybersecurity industry: the often-strained relationship between security teams…
- Trust at Scale: Lessons Learned from a Decade of Engineering for Identity — Frederic Rivain
In his BSides NYC talk, "Trust at Scale: Lessons Learned from a Decade of Engineering for Identity," Frederic Rivain, CTO of Dashlane, offered a candid and insightful retrospective on the challenges…
- Using Volatility 3 to Detect Sophisticated Malware — Andrew Case
In this insightful talk from BSides NYC, Andrew Case, Director of Research at Vexity and a core developer of the Volatility memory forensics framework, delved into the critical role of **memory…
- Living off the (land)cloud: Scattered Spider and the cloud control plane — Shivakumar Buruganahalli
In an era of rapidly evolving cyber threats, the Scattered Spider group, also known as UNC3944 or Scatterswine, has emerged as a particularly insidious adversary. This talk by Shivakumar…
- When the Shadow Crosses Over — Ilya Yatsenko
In his BSides NYC talk, "When the Shadow Crosses Over," Ilya Yatsenko, a graduate student at the University of Maryland, delved into the often-overlooked and powerful Remote Desktop Services (RDS)…
- Building a security startup as an outsider — Kabir Mathur
In a candid and insightful talk at BSides NYC, Kabir Mathur, CEO and co-founder of Lean, shared the unconventional journey of building a cybersecurity startup from the ground up, despite having…
- When Build vs Buy Is Rigged: Selling to Enterprises That Prefer Building In-House — Amir Kavousian
In the competitive landscape of cybersecurity startups, a founder's most formidable adversary often isn't another vendor, but rather the deeply ingrained "build in-house" culture prevalent within…
- The Log Rings Don't Lie: Historical Enumeration in Plain Sight — Bleon Proko
In a revealing talk at BSides NYC, security researcher Bleon Proko from Exa Force illuminated a critical, yet often overlooked, attack vector in cloud environments: the weaponization of **logs** for…
- The History of Malware: From Floppies to Droppers — Eliad Kimhy
Eliad Kimhy's talk, "The History of Malware: From Floppies to Droppers," takes the audience on an engaging journey through the evolution of malicious software, tracing its origins from the early…
- From pocket to Pwn: How we hacked a multinational corp for $200 with what's in our pockets — Tim Shipp
In this compelling BSides NYC talk, Tim Shipp, CTO and co-founder of Threat Lights, unveils a highly effective, low-cost attack methodology that successfully compromised a multinational corporation…
- Rebooting the cyber arsenal of democracy — Eric Foster
In a compelling presentation at BSides NYC, Eric Foster, CEO of **10X AI** and a veteran of the cybersecurity industry, laid out a powerful argument for why now is the "golden era" for aspiring…
- P0LR Espresso - Pulling Shots of Cloud Live Response & Advanced Analysis — Art Ukshini
In the rapidly evolving landscape of cloud security, defenders face a formidable challenge: the sheer diversity and fragmentation of logs across multiple cloud providers. Art Ukshini's talk, "P0LR…
- The Allure of Go's Cross-Platform Capability: A Gateway for Threat Actors to Mac and Linux — Anmol Maurya
In an insightful presentation at BSides NYC, Anmol Maurya, a malware and threat researcher at Paletto Networks (formerly with CrowdStrike), unveiled the growing trend of threat actors leveraging…
- Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks — Cory Wolff
In "Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks," Cory Wolff, Director of Offensive Security at Risk 360, provides an unprecedented look into the internal operations…
- Sniffing Out Cert Abuse: A Dogged Approach to ESC Remediation — Emily Leidy
In this insightful talk, Emily Leidy, a Managing Consultant at Spectre Ops, delves into the pervasive and critical security risks posed by misconfigurations in **Active Directory Certificate…
- Inside Cloud Attack Paths: End-to-End Adversary Simulation — Mauricio Velazco
In an increasingly cloud-centric world, traditional cybersecurity defenses are proving insufficient against evolving adversary tactics. Mauricio Velazco's talk, "Inside Cloud Attack Paths…
- Why Being A Great Technologist May Not Make You A Great CEO (And How To Bridge The Gap) — Jason Kaplan
Jason Kaplan's talk at BSides NYC, "Why Being A Great Technologist May Not Make You A Great CEO (And How To Bridge The Gap)," delves into the profound differences between excelling as a technologist…
- Contribute to Learn: Building DFIR Expertise Through Open Source — Christopher Eng
Christopher Eng's talk, "Contribute to Learn: Building DFIR Expertise Through Open Source," delivered at BSides NYC, presents a compelling argument for leveraging open-source contributions as a…
- From CISA to Starting Up: Shifting Secure by Design at Scale — Jack Cable
Jack Cable, CEO and co-founder of Corridor, delivered a compelling talk at BSides NYC, tracing his journey from leading the "Secure by Design" initiative at the Cybersecurity and Infrastructure…
- Slaying Hidden Threats in Residential (and Mobile!) IP Proxies — Christo Roberts
In a revealing talk at BSides NYC, Christo Roberts from Cloudflare delved into the clandestine world of residential and mobile IP proxies, exposing how these sophisticated tools are leveraged by a…
- Beyond Vibe Coding: Building Reliable AI AppSec Tools — Emily Choi-Greene
In "Beyond Vibe Coding: Building Reliable AI AppSec Tools," Emily Choi-Greene delves into the critical intersection of artificial intelligence and application security, advocating for the strategic…
- The Good Business: How to Bootstrap a Business to $10M and Beyond — Christian Hyatt
In an engaging and reflective presentation at BSides NYC, Christian Hyatt, CEO and co-founder of Risk 360, shared his nine-year journey of bootstrapping a cybersecurity services and SaaS company…
- Cloud's Dirty Little Secret: It Was Misconfigs All Along — Karl Ots
In "Cloud's Dirty Little Secret: It Was Misconfigs All Along," Karl Ots, a Cloud Security Lead and consultant at EPAM, delivers a pragmatic and critical assessment of the persistent threat posed by…
- Navigating the Virtualization Battlefield: A Deep Dive into Hypervisor Attack Vectors — Austin Gadient
This talk, presented by Austin Gadient, CTO and co-founder of Valley Cyber, provides a critical examination of the escalating threat landscape surrounding hypervisors, with a particular focus on…
- Exploit Intelligence with Agentic AI: Patch What Matters — Dmitrijs Trizna
In an era where cyber threats are escalating in sophistication and scale, this talk by Dmitrijs Trizna from Microsoft addresses the critical asymmetry currently favoring offensive actors in the…
- Breaking the Mobile Log Analysis Barrier with AI — Numa Dhamani
In the realm of cybersecurity, mobile device logs represent an invaluable, yet often inaccessible, trove of forensic data. Numa Dhamani, Head of Machine Learning at iVerify, delivered a compelling…
- Closing Ceremonies — Huxley Barbee
The "Closing Ceremonies" of BSides NYC, led primarily by conference organizer Huxley Barbee, marked the culmination of a successful and community-driven cybersecurity event. Far from a traditional…