Подтвердите e-mail

Для публикаций, комментариев, реакций и сообщений подтвердите адрес.

Профиль

BSides Las Vegas

Профиль Vively

BSides Las Vegas will take place August 3-5, 2026 Las Vegas · bsideslv.org

89 seconds. That's the window between malicious package publication and downstream impact. This is a practitioner account of two massive npm breaches: Nx/s1ngularity and the Axios attack. See Mohit Bansal @ Proving Ground during #BSidesLV on Wed Aug 5 @ 10:30.

000

Online presence and networking aren't soft skills. For a music school dropout who ended up at Google, they were the actual path in. This talk names what worked and what didn't. See Kim Cote @ Hire Ground during #BSidesLV on Wed Aug 5 @ 12:30.

000

An AI governance program becomes useful when it can assess vendors, test integrations, and give teams a path to yes without ignoring risk. See Bo Barger, Alex Sayre @ Proving Ground during #BSidesLV on Tue Aug 4 @ 11:30.

010

The Four Thieves Vinegar Collective always planned to disband. After ten years of HIV, HCV, and overdose reversal work, they're following through. See the keynote by Mixæl Laufer, Zac Ilex, String Fellow, Mike Kiss & Hugo Bosler @ #BSidesLV on Wed Aug 5 @ 13:00.

000

The skills, MCP servers, and plugins your coding agent loads come from a supply chain you mostly didn't build, distributed through marketplaces with varying vetting. See Rajaram Srinivasan @ Common Ground during #BSidesLV on Wed Aug 5 @ 11:00.

000

Social engineering isn't random. Analysis of 1,200+ vishing transcripts shows key elements appearing in predictable positions and co-occurring as structured patterns, not independent signals. See Jordan Schoenherr @ Ground Truth during #BSidesLV on Tue Aug 4 @ 17:00.

000

We can't believe it's almost here! We wanted to thank @flaresystems again for being an All In sponsor 🎰 Don't forget to stop by their table August 3rd–5th! Interested in learning more about their company? Visit flare.io/company/car...

000

Bonsai 1.7B is a 1-bit quantized LLM with a 250MB footprint. It runs entirely on the device, no cloud dependency, and turns raw IoT logs into natural-language anomaly explanations. See Tetsuro Ishida @ Proving Ground during #BSidesLV on Wed Aug 5 @ 10:00.

010

Breaking into cybersecurity without prior professional experience is possible. The tools to do it are free and accessible. What's missing for most career changers is knowing which ones matter. See Thomas Boeckman @ Hire Ground during #BSidesLV on Wed Aug 5 @ 12:00.

042

Thirty blue teams. Millions of tokens intercepted. Some AI use worked. Some didn't. Handing even partial control to AI agents in active defensive scenarios has real consequences worth measuring. See wasabi wasabi @ Ground Truth during #BSidesLV on Wed Aug 5 @ 11:00.

000

GitHub Security Advisories show where cryptographic failures cluster. Real libraries reveal how small validation mistakes become exploitable flaws. See Diptendu Kar @ Proving Ground during #BSidesLV on Tue Aug 4 @ 10:00.

000

Don't forget! On Monday, [un]prompted will be at BSides Las Vegas with a track dedicated to AI practitioner talks covering development and security. This is a single day event. Their schedule is online at: bsideslv.org/schedule

000

An MCP server becomes dangerous when its capability list grows faster than its controls. A smaller surface often beats another guardrail. See Saquib Saifee @ Proving Ground during #BSidesLV on Tue Aug 4 @ 17:30.

120

We can't wait to see everyone in person! We wanted to thank @TrustVanta again for being an All In sponsor 🎰 Don't forget to stop by their table August 3rd–5th! Interested in learning more about their company? Visit www.vanta.com/compan...

000

Your internal hostnames are in the CT logs if you issued public certs for private services. Every major company does it. The data is searchable, public, and has been there for years. See Kenton McDonough @ PasswordsCon during #BSidesLV on Wed Aug 5 @ 12:00.

010

Grinding alerts and feeling stuck is a real career phase in SOC work. This talk is for analysts who are hungry to grow but haven't been handed a map, because most shops don't have one. See Efrain Orsini Jr & Austin Phillips @ Hire Ground during #BSidesLV on Wed Aug 5 @ 11:00.

000

Agentic AI can reduce the labor behind vulnerable lab design without removing the need for sound attack-path planning. See Akshay Rohatgi @ Proving Ground during #BSidesLV on Tue Aug 4 @ 11:00.

000

In 2014, a small group of hackers walked into DOJ's offices to convince federal prosecutors to stop chilling legitimate security research. Eight years later, it worked. See Leonard Bailey's Keynote @ Breaking Ground during #BSidesLV on Mon Aug 4 @ 11:30.

011

GCP's built-in service agent identities are inherently flawed. Two 0-days demonstrate why, and the methodology to find more of them is repeatable by anyone willing to look. See Moshe Bernstein @ Common Ground during #BSidesLV on Wed Aug 5 @ 10:30.

000

Prompt injection isn't an AI safety problem. It's an auth problem. OAuth, JWTs, mTLS encode who is acting. None encode why. Finer scopes can't close that gap. See Noelle Murata @ [un]prompted during #BSidesLV on Mon Aug 3 @ 14:00.

000
Показать ещё