<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Greptalks — Conference Talk Reviews</title>
    <link>https://greptalks.ai/</link>
    <description>New security conference talks reviewed by the Greptalks panel: transcripts, TL;DRs, and persona reviews.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 15 Aug 2026 01:13:03 +0000</lastBuildDate>
    <atom:link href="https://greptalks.ai/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Black Hat USA 2026 — When Queues Become Vulnerabilities: Reverse Engineering GCD, XPC Races, and macOS Detection</title>
      <link>https://greptalks.ai/c/blackhatusa-2026/bh26-007/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/blackhatusa-2026/bh26-007/</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 +0000</pubDate>
      <description>In this Black Hat USA talk, Olivia Gallucci, a Security Engineer at Datadog, meticulously dissects how the misuse of Apple's Grand Central Dispatch (GCD) framework can introduce critical race conditions and other concurrency vulnerabilities into macOS system services. The presentation highlights that what might appear as mere reliability bugs in typical applications can escalate into significant… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>Black Hat USA 2026 — Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius</title>
      <link>https://greptalks.ai/c/blackhatusa-2026/bh26-006/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/blackhatusa-2026/bh26-006/</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 +0000</pubDate>
      <description>The Black Hat USA talk "Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius" delivered by the BT6 collective, led by Pliny the Liberator, unveiled a critical new dimension in AI security: the direct manipulation of embodied AI systems to induce physical harm. While much of the AI security discourse has historically focused on textual outputs and digital compromises, this… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>Black Hat USA 2026 — Keynote: The End of Rare: Defending When Offense Is Cheap</title>
      <link>https://greptalks.ai/c/blackhatusa-2026/bh26-005/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/blackhatusa-2026/bh26-005/</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 +0000</pubDate>
      <description>In his compelling Black Hat USA keynote, "The End of Rare: Defending When Offense Is Cheap," David Weston, Agentic Security Leader at Microsoft, delivered a stark warning and an optimistic roadmap for the future of cybersecurity. Weston argues that the foundational assumption of scarcity in cyberattacks—that undermining security boundaries is inherently difficult and costly—is rapidly being… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>Black Hat USA 2026 — Keynote: Vulnerability Research in the Agentic Age</title>
      <link>https://greptalks.ai/c/blackhatusa-2026/bh26-004/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/blackhatusa-2026/bh26-004/</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 +0000</pubDate>
      <description>In this thought-provoking Black Hat USA keynote, Dr. Yan Shoshitaishvili, an Associate Professor at Arizona State University and a veteran of the Capture The Flag (CTF) community, delved into the profound impact of the "Agentic Age" on vulnerability research. The talk explored how advanced AI models and autonomous agents are not merely augmenting human capabilities but are fundamentally reshaping… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>Black Hat USA 2026 — Opening Session: Disruption, Defense and Operational Readiness</title>
      <link>https://greptalks.ai/c/blackhatusa-2026/bh26-003/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/blackhatusa-2026/bh26-003/</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 +0000</pubDate>
      <description>This Black Hat USA session, "Disruption, Defense and Operational Readiness," brought together top cybersecurity leaders from U.S. government agencies and industry to discuss the evolving threat landscape and the collaborative strategies being deployed to strengthen national cybersecurity. Moderated by Daniel Kroese of Palo Alto Networks, the panel featured Nick Andersen from CISA, Brett… — Dr. Zero: 2/5 (WEAK) · Heather Calloway: 2/5 (WEAK)</description>
    </item>
    <item>
      <title>Black Hat USA 2026 — Opening Session: Cyber Power in the Age of AI</title>
      <link>https://greptalks.ai/c/blackhatusa-2026/bh26-002/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/blackhatusa-2026/bh26-002/</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 +0000</pubDate>
      <description>This Black Hat USA opening session featured a compelling dialogue between Sean Cairncross, the National Cyber Director for The White House, and Misha Laskin, Co-founder and CEO of Reflection, an AI company specializing in open models. The discussion, moderated by Laskin, delved into the profound implications of artificial intelligence on national cybersecurity, exploring what "cyber power"… — Dr. Zero: 2/5 (WEAK) · Heather Calloway: 2/5 (WEAK)</description>
    </item>
    <item>
      <title>Black Hat USA 2026 — The 'Breaking' News: The OpenAI–Hugging Face Incident — A Technical Reconstruction and Its Implications for AI</title>
      <link>https://greptalks.ai/c/blackhatusa-2026/bh26-001/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/blackhatusa-2026/bh26-001/</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 +0000</pubDate>
      <description>This talk, presented by OpenAI's Michael Dalton and Eric Wallace at Black Hat USA, provides an unprecedented technical reconstruction of the "OpenAI–Hugging Face Incident." This event marked the first publicly acknowledged cyberattack driven end-to-end by an autonomous AI agent system, inadvertently orchestrated by OpenAI's own frontier models during internal security evaluations. The speakers… — Dr. Zero: 5/5 (MUST SEE) · Heather Calloway: 5/5 (MUST SEE)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — When One Vulnerability Cascades Across Cloud Infrastructure</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-037/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-037/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>This talk, "When One Vulnerability Cascades Across Cloud Infrastructure," by Albin Vattakattu and Ryan Nolette from AWS, provides an unparalleled behind-the-scenes look into how a major cloud provider handles zero-day vulnerabilities, particularly those stemming from third-party dependencies. It delves into the intricate, multi-team choreography required to identify, assess, remediate, and… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Barbarians at the Gate: Visualizing and Blocking SDLC Infrastructure Threats with SITF</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-036/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-036/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this compelling talk at fwd:cloudsec, Shay Berkovich from Google (formerly of the WH Threat Research Group) introduced the SDLC Infrastructure Threat Framework (SITF), a novel approach to understanding, visualizing, and defending against the escalating wave of attacks targeting the Software Development Life Cycle (SDLC). Berkovich highlighted a stark reality: more SDLC infrastructure has been… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Transforming Security Incident Metadata to Security Outcomes</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-035/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-035/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this insightful talk from fwd:cloudsec, Cydney Stude and Steve de Vera from AWS Security Incident Response unveil the Threat Technique Catalog for AWS (TTC), a crucial initiative designed to enhance understanding and defense against adversarial behaviors within the Amazon Web Services ecosystem. The presentation details AWS's journey from a nascent state of incident tracking to establishing a… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-034/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-034/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In his fwd:cloudsec talk, "Slaying the Sprawl: A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild," Steve Turner, a Cloud Security Architect at Zealus, addresses one of the most pressing challenges in modern cybersecurity: how to establish or rebuild an effective cloud security program with limited resources. Turner's presentation cuts through theoretical ideals,… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Schrödinger’s Detection: Finding the "Zombie" Rules in Your SIEM</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-033/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-033/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In the dynamic landscape of cybersecurity, Security Information and Event Management (SIEM) systems are the bedrock of detection and response. However, the efficacy of these systems hinges entirely on the quality and accuracy of their detection rules. Gowthamaraj, a Detection Engineer at MetaB, sheds light on a pervasive and often silently crippling issue: "zombie rules." These are detection… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Beyond the Checkbox: What Breaks When You Actually Stress-Test Cloud Incident Response</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-032/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-032/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In the realm of cloud security, the true test of an organization's incident response (IR) capabilities often comes not from theoretical discussions but from real-world chaos. Matthew Harvey, a founding member of AWS's customer incident response team, presented a compelling talk at fwd:cloudsec on the critical disconnect between how organizations think their IR processes work and how they actually… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Do Apps Have Imposter Syndrome? Unmasking Token Theft Campaigns</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-031/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-031/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In an era where identity is the new perimeter, the security of applications and their interactions within cloud environments is paramount. This talk, "Do Apps Have Imposter Syndrome? Unmasking Token Theft Campaigns," by Shahar Dorfman and Sapir Federovsky of Whiz, delves into a critical and often overlooked attack vector: the abuse of OAuth applications in Azure environments. The speakers… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — One Architectural Sin, Two Clouds, and a Universal Attack Technique for Data Hijacking</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-030/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-030/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this fwd:cloudsec talk, Yahav Fessinger, a Cloud Security Researcher at Palo Alto Networks, unveiled a simple yet profoundly impactful attack technique capable of hijacking critical cloud data. Titled "One Architectural Sin, Two Clouds, and a Universal Attack Technique for Data Hijacking," the presentation delved into a fundamental architectural flaw common across major cloud providers: the… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Artificial Intelligence 🤝 Natural Stupidity</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-029/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-029/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In "Artificial Intelligence 🤝 Natural Stupidity," Brandon Sherman, a Staff or Senior Staff Engineer, presents a compelling argument that while artificial intelligence (AI) has the power to magnify human brilliance, it equally magnifies human fallibility. The talk delves into the inherent human tendency to make mistakes, drawing parallels with lessons learned from the aviation industry to… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Beyond the Perimeter: Retrofitting VPC-SC at Enterprise Scale</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-028/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-028/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In the modern cloud landscape, traditional network firewalls are increasingly insufficient to prevent data exfiltration. While Identity and Access Management (IAM) controls dictate who can access data, they often fall short in defining where that data is allowed to go and under what conditions. This critical gap is precisely what VPC Service Controls (VPCSC) aims to address, establishing a robust… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Data Perimeters: Beyond the Marketing</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-027/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-027/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this insightful talk, Matt Luttrell, a Principal Security Engineer at AWS, delves into the often-complex world of data perimeters in cloud environments. Moving beyond the marketing hype, Luttrell provides a pragmatic and deeply technical examination of how data perimeters function within AWS, highlighting the "sharp edges" or "complicators" that can undermine their effectiveness. His team at… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Paying More for Worse Security: An AWS Marketplace Horror Story</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-026/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-026/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this eye-opening talk from fwd:cloudsec, Corey Quinn, author of the "Last Week in AWS" newsletter, exposes a pervasive and disturbing trend within the AWS Marketplace: a "horror story" where customers unknowingly pay significant premiums for outdated, unpatched, and often less secure versions of free operating systems. Quinn meticulously details a business model that, while apparently legal… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — I made AI agents apply for my Security Team. Then I gave the agents access to AWS.</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-025/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-025/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In a compelling presentation at fwd:cloudsec, Cole Horsman, an AI security specialist at KKR, unveiled an innovative approach to tackling the pervasive challenge of cloud identity and access management (IAM). The talk, provocatively titled "I made AI agents apply for my Security Team. Then I gave the agents access to AWS," details Horsman's journey in developing and deploying an autonomous,… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Observing Escalation Paths in Kubernetes</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-024/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-024/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this insightful talk from fwd:cloudsec, William Taylor, a Security Consultant at Reverse, delves into the often-overlooked security implications of observability tools within Kubernetes environments. The presentation highlights a fundamental conflict between the architectural need for pervasive monitoring and the security principle of least privilege, demonstrating how commonly deployed… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Lessons From Building a Cloud Attack Simulation Program</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-023/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-023/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In the dynamic landscape of cloud security, ensuring the efficacy of detection and response capabilities across heterogeneous cloud environments is a monumental challenge. Pavel Lineitsev, from Conland's Detection and Response Team, presented an insightful talk at fwd:cloudsec, detailing his team's journey and lessons learned from building an internal cloud attack simulation program. The… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Azure Networking Dark Arts: The Implicit Paths Your Diagrams Don't Show-Achia Rosenfeld &amp; Kobi Rubin</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-022/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-022/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this fwd:cloudsec presentation, "Azure Networking Dark Arts: The Implicit Paths Your Diagrams Don't Show," Achia Rosenfeld and Kobi Rubin from Act Security peel back the layers of Azure's often opaque networking behaviors. They illuminate how Azure's "easy-to-use" design frequently obscures critical routing decisions, leading to implicit traffic paths that bypass security controls and defy… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Discovering New AWS Privilege Escalation Paths with an AI-Driven Workflow</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-021/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-021/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>Seth Art's presentation at fwd:cloudsec dives into an innovative, AI-driven workflow designed to identify novel privilege escalation (PE) paths within Amazon Web Services (AWS) Identity and Access Management (IAM). As cloud environments become increasingly complex and multi-account, traditional methods of discovering and cataloging vulnerabilities struggle to keep pace. Art, a penetration tester,… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 2/5 (WEAK)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Who Are the Robots? Uncovering AI Agents Identities</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-020/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-020/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In an era where Artificial Intelligence (AI) agents are rapidly integrating into enterprise operations, the critical challenge of securing these autonomous entities remains largely unaddressed. Ron Popov and Clément Notin, security researchers at Tennable, delivered a compelling talk at fwd:cloudsec, shedding light on the nascent but vital field of AI agent identity management. Their… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Context-Aware Authorization for Agentic Tool Calls (Agent Memory Informed Authorization)</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-019/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-019/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In an era where artificial intelligence agents are increasingly integrated into daily workflows, both assisting human employees and operating autonomously, the challenge of securing their access to organizational resources becomes paramount. Robert from C1.AI addresses this critical issue in his fwd:cloudsec talk, "Context-Aware Authorization for Agentic Tool Calls," which he also refers to as… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Agentic Paved Roads: Shifting Security Left to the Machine That Thinks</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-018/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-018/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In an era where artificial intelligence agents are increasingly writing, shipping, and deploying code to production infrastructure, traditional security paradigms are proving insufficient. Prahathess Rengasamy's talk, "Agentic Paved Roads: Shifting Security Left to the Machine That Thinks," addresses this critical challenge head-on. The presentation highlights a fundamental shift in the software… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — The Tireless Guardian: Agentic AI and the Art of WAF at Scale</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-017/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-017/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In his fwd:cloudsec talk, "The Tireless Guardian: Agentic AI and the Art of WAF at Scale," Ammar Alim from Adobe presents a compelling case for leveraging agentic AI to revolutionize the deployment and management of Web Application Firewall (WAF) rules. This session addresses the escalating challenges faced by security organizations in an era of exploding software vulnerabilities and increasingly… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Who Did This? Identity and Accountability When Your Cloud Actors Aren't Human</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-016/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-016/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In the rapidly expanding landscape of cloud infrastructure, non-human identities – primarily service accounts – have become ubiquitous, performing a vast array of automated tasks from running CI/CD pipelines to managing complex cloud resources. This talk by Jie Wu and Pulkit Garg from Shopify addresses a critical and increasingly complex security challenge: maintaining identity, accountability,… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Least Privilege is a Conversation: Building an Agentic Role Engineering Pipeline</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-015/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-015/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In the intricate landscape of cloud security, establishing and maintaining least privilege in AWS Identity and Access Management (IAM) remains a formidable challenge, particularly for human-initiated actions. Alex Smolen, founder of NSEC Labs and former security lead at LaunchDarkly and Clever, tackles this persistent problem head-on in his fwd:cloudsec talk. He introduces a novel approach that… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — The domain takeover challenge: Detecting and defeating it at scale</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-014/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-014/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In an increasingly complex cloud landscape marked by rapid growth, numerous acquisitions, and accelerated development cycles, organizations face significant challenges in managing their digital assets securely. This talk, delivered by Ramesh and Eli F from Block, addresses one such critical challenge: domain takeovers. The speakers delve into the intricacies of various domain takeover classes,… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Pattern matching and head scratching with our new friends The Neoclouds</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-013/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-013/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this insightful talk, Matthew Gladney addresses a growing challenge faced by cloud security professionals: the proliferation of NeoClouds. These are defined as GPU-focused Infrastructure-as-a-Service (IaaS) providers that offer compute in dedicated virtual machines, bare metal, or serverless varieties, often with a thin layer of additional services. As organizations increasingly adopt AI and… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Release the Kraken: Putting Tentacles on Your AI "Paved Road"</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-012/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-012/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In an era where Artificial Intelligence (AI) usage is rapidly becoming "non-negotiable" for developers, organizations face a critical challenge: how to enable powerful AI coding tools without exposing sensitive internal data to new and complex threats. Sakina Mithani, a Cloud Security Engineer at Roblox, addresses this head-on in her fwd:cloudsec talk, "Release the Kraken: Putting Tentacles on… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Stop Building Custom Agent Identity</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-011/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-011/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>The rapid proliferation of AI agents in enterprise environments presents a critical, yet often overlooked, security challenge: how do these autonomous entities establish and manage their identity in a secure, auditable, and scalable manner? This talk, "Stop Building Custom Agent Identity," delivered by Sarah Cecchetti and her AI agent, Claudrey Hepburn, tackles this pressing issue head-on. It… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Stop Training Engineers to Ignore You: Cloud Security Alerting at Scale</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-010/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-010/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In the dynamic and ever-expanding landscape of cloud infrastructure, effective security alerting at scale presents a formidable challenge for even the most sophisticated organizations. This talk, "Stop Training Engineers to Ignore You: Cloud Security Alerting at Scale," delivered by Paul Benoit, a Cloud Security Engineer at Block, delves into the intricate problems and hard-won solutions… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — In git we trust: Defending Lovable projects from malicious code attacks at scale</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-009/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-009/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>This talk, "In git we trust: Defending Lovable projects from malicious code attacks at scale," delivered by Samuel, a Security Engineer, and Marcus from Lovable, delves into a sophisticated, large-scale malicious code injection campaign targeting users of the Lovable platform. Lovable, which empowers over 600,000 customers to create more than 58 million full-stack web applications using an AI… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Are We There Yet? Lessons from the 10 Year Cloud Security Ride</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-008/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-008/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>James Berthoty's talk, "Are We There Yet? Lessons from the 10 Year Cloud Security Ride," offers a critical retrospective and forward-looking analysis of the cloud security landscape over the past decade. As the founder of Lacatio, a practitioner-focused analyst firm, Berthoty brings a unique perspective shaped by his extensive background in security operations, cloud security, and application… — Dr. Zero: 3/5 (SOLID) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — What Building an AI Worm Taught Us About Stopping One</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-007/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-007/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>Kinnaird McQuade, Chief Security Architect at Beyond Trust, presented a groundbreaking talk at fwd:cloudsec detailing his experience building an autonomous, AI-powered worm. The motivation behind this audacious project was rooted in gain of function research, akin to how virologists weaponize viruses in a lab to develop vaccines. McQuade aimed to understand the full destructive potential of AI… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — OCInferno: An Offensive Security Toolkit for OCI</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-006/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-006/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this fwd:cloudsec presentation, Scott Weston introduces OCInferno, a comprehensive offensive security toolkit designed specifically for Oracle Cloud Infrastructure (OCI). The talk delves into the intricacies of OCI's unique Identity and Access Management (IAM) model, highlighting challenges posed by its policy syntax and the often-overlooked concept of identity domains. Weston, known for… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Zapocalypse: Compromising every Zapier user through a Lambda memory leak</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-005/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-005/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>This talk, titled "Zapocalypse: Compromising every Zapier user through a Lambda memory leak," details a critical vulnerability chain discovered in Zapier, a prominent AI-driven workflow automation platform. Presented by Yair Balilti, a Security Researcher at Token Security, the research outlines a sophisticated five-stage attack that allowed the team to achieve a full platform account takeover,… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-004/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-004/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In a revealing presentation at fwd:cloudsec, Tal Verer, Head of Research at Asec Security, unveiled "Sub:jugation," a novel class of vulnerability impacting nearly all major CI/CD providers. What initially appeared to be a straightforward issue—the potential for reclaiming deleted namespaces—escalated into a critical security concern upon deeper analysis from an attacker's perspective. The talk… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — No Way Out? C2 Through AWS Data Perimeter via Bedrock-AgentCore</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-003/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-003/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>In this insightful talk from fwd:cloudsec, Dan Gansel, a security researcher at API Security, unveiled a sophisticated command and control (C2) channel that could bypass AWS's stringent Data Perimeter controls. The research, titled "No Way Out? C2 Through AWS Data Perimeter via Bedrock-AgentCore," demonstrated how a combination of an undocumented API and an intended design behavior within AWS… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — Push-Pull-Pwn: Hacking the Cloud through Container Registry Poisoning</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-002/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-002/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>This talk, "Push-Pull-Pwn: Hacking the Cloud through Container Registry Poisoning," delivered by Hillai and Nir from Wiz Research, uncovers a critical and often under-discussed security risk: the container registry. Positioned as the central hub of modern cloud environments, container registries facilitate the lifecycle of container images, from build to deployment. The speakers demonstrate how… — Dr. Zero: 4/5 (STRONG ACCEPT) · Heather Calloway: 3/5 (SOLID)</description>
    </item>
    <item>
      <title>fwd:cloudsec North America 2026 — 2026 Introduction</title>
      <link>https://greptalks.ai/c/fwdcloudsec-2026/fcs26-001/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/fwdcloudsec-2026/fcs26-001/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description>Patrick Sanders' opening address at fwd:cloudsec North America 2026 served as a powerful thematic introduction to the conference, setting a critical tone for the year ahead in cloud security. Rather than detailing a specific vulnerability or technical solution, Sanders unveiled a compelling analogy of the Centaur and the Minotaur to frame the overarching challenge and responsibility facing cloud… — Dr. Zero: 2/5 (WEAK) · Heather Calloway: 2/5 (WEAK)</description>
    </item>
    <item>
      <title>OffensiveCon 2026 — SELECT shell FROM postgres: Digging up a 20-year-old bug for ZeroDay.Cloud</title>
      <link>https://greptalks.ai/c/offensivecon-2026/oc26-017/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/offensivecon-2026/oc26-017/</guid>
      <pubDate>Sat, 16 May 2026 12:00:00 +0000</pubDate>
      <description>This talk, "SELECT shell FROM postgres: Digging up a 20-year-old bug for ZeroDay.Cloud," presented by Paul Gerste and Moritz Sanft, details their successful exploit of a two-decade-old vulnerability in PostgreSQL that led to remote code execution (RCE) as a low-privileged user. The researchers uncovered a critical flaw within the PG crypto extension, specifically in its PGP sym_decrypt function,… — Dr. Zero: 5/5 (MUST SEE) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>OffensiveCon 2026 — Exploiting Android Apps with Counterfeit Art</title>
      <link>https://greptalks.ai/c/offensivecon-2026/oc26-016/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/offensivecon-2026/oc26-016/</guid>
      <pubDate>Sat, 16 May 2026 12:00:00 +0000</pubDate>
      <description>This talk, "Exploiting Android Apps with Counterfeit Art," presented by Philipp Mao and Rokhaya Fall, delves into a novel and powerful technique for escalating file override vulnerabilities in Android applications to arbitrary code execution. The speakers introduce the ART image file, a core component of the Android runtime, as a universal and writable target for such exploits. While file… — Dr. Zero: 5/5 (MUST SEE) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>OffensiveCon 2026 — Design-Based Vulnerabilities on macOS: Oops, Not a One-Shot Fix</title>
      <link>https://greptalks.ai/c/offensivecon-2026/oc26-015/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/offensivecon-2026/oc26-015/</guid>
      <pubDate>Sat, 16 May 2026 12:00:00 +0000</pubDate>
      <description>In his OffensiveCon 2026 presentation, "Design-Based Vulnerabilities on macOS: Oops, Not a One-Shot Fix," independent security researcher Zhongquan Li delved into a series of persistent and high-impact vulnerabilities rooted in fundamental design flaws within macOS security mechanisms. Li's research, conducted between 2024 and 2025, highlights how Apple's layered security often introduces… — Dr. Zero: 5/5 (MUST SEE) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>OffensiveCon 2026 — From Samsung Account to RCE: A Journey to a Remote 0-Click Capability</title>
      <link>https://greptalks.ai/c/offensivecon-2026/oc26-014/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/offensivecon-2026/oc26-014/</guid>
      <pubDate>Sat, 16 May 2026 12:00:00 +0000</pubDate>
      <description>In this compelling talk at OffensiveCon, Yuval Kaufman, known as Kalfy, a VP R&amp;D at Radiant Research Labs, detailed an intricate journey culminating in a remote zero-click capability leading to Remote Code Execution (RCE) on Samsung Android devices. The research focused on exploiting vulnerabilities within the vast Samsung Account ecosystem and proprietary image processing mechanisms. Kalfy… — Dr. Zero: 5/5 (MUST SEE) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>OffensiveCon 2026 — IRON GIANT: When The Vault Becomes The Victim</title>
      <link>https://greptalks.ai/c/offensivecon-2026/oc26-013/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/offensivecon-2026/oc26-013/</guid>
      <pubDate>Sat, 16 May 2026 12:00:00 +0000</pubDate>
      <description>In the realm of Windows security, the Local Security Authority Subsystem Service, or LSASS, stands as a formidable guardian, often dubbed the "Iron Giant" for its critical role in managing authentication, credential storage, and policy enforcement. For years, the prevailing assumption within the security community has been that LSASS, holding the keys to the kingdom, is exceptionally… — Dr. Zero: 5/5 (MUST SEE) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
    <item>
      <title>OffensiveCon 2026 — Beyond the Limits of Site Isolation</title>
      <link>https://greptalks.ai/c/offensivecon-2026/oc26-012/</link>
      <guid isPermaLink="true">https://greptalks.ai/c/offensivecon-2026/oc26-012/</guid>
      <pubDate>Sat, 16 May 2026 12:00:00 +0000</pubDate>
      <description>In this talk, Ivan Fratric, a seasoned security researcher and Tech Lead at Google Project Zero, delves into the often-misunderstood boundaries of Site Isolation, a critical security mitigation in modern web browsers. Fratric presents a deep dive into a long-standing, high-severity vulnerability in Chrome, which he discovered during an internal hackathon in 2019, that allowed for the leakage of… — Dr. Zero: 5/5 (MUST SEE) · Heather Calloway: 4/5 (STRONG ACCEPT)</description>
    </item>
  </channel>
</rss>
