{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.3.0.dev0", "url": "https://cfp.bsidescbr.com.au"}, "schedule": {"url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/schedule/", "version": "0.22", "base_url": "https://cfp.bsidescbr.com.au", "conference": {"acronym": "bsides-canberra-2026", "title": "BSides Canberra 2026", "start": "2026-09-24", "end": "2026-09-26", "daysCount": 3, "timeslot_duration": "00:05", "time_zone_name": "Australia/Sydney", "colors": {"primary": "#3ea3c8"}, "rooms": [{"name": "Main Track", "slug": "5567-main-track", "guid": "4a29fef6-5675-517c-a556-262557f4f117", "description": "Hosted in the Royal Theatre", "capacity": 2500}, {"name": "Off-Main Track", "slug": "5568-off-main-track", "guid": "cfcd59fd-43da-55c5-ada7-f42188c64ea8", "description": "Hosted in Bradman Theatre - streamed to the other theatrettes for overflow", "capacity": null}, {"name": "Registration & Merch", "slug": "5569-registration-merch", "guid": "6ca57102-6a3f-5a32-9126-6a195f46a298", "description": "Located in the Foyer", "capacity": null}, {"name": "Exhibition Hall", "slug": "5570-exhibition-hall", "guid": "6d915690-3dd7-5fb3-a1dd-13163a7b6980", "description": "Competition Space", "capacity": 800}, {"name": "ExHall - front", "slug": "5571-exhall-front", "guid": "454be610-b875-50ee-88ff-53c9eb38c777", "description": "Competition Space", "capacity": null}, {"name": "Murray-Fitzroy Room", "slug": "5572-murray-fitzroy-room", "guid": "b4bfe40e-6d38-5e1e-b67c-8aed7600bce3", "description": "Gallery Room upstairs, hosting the Careers Village and Training", "capacity": 156}, {"name": "Derwent Room", "slug": "5573-derwent-room", "guid": "c1cfcbdd-6e73-507e-a97d-6f8e0a611e83", "description": "Level 1 Gallery Room, overlooking the Exhibition Hall", "capacity": null}, {"name": "Locksport Village", "slug": "5574-locksport-village", "guid": "056576df-9aa1-5aa4-97aa-ac8fa95051ba", "description": "Torrens Swan Room - upstairs", "capacity": 150}, {"name": "Locksport Village - Physical Challenge", "slug": "6153-locksport-village-physical-challenge", "guid": "ce1b665b-9cc3-5d5c-9a58-9ee26f4a3c9e", "description": null, "capacity": null}, {"name": "Hardware Village", "slug": "5575-hardware-village", "guid": "28162d6b-401b-5db8-a506-90d17bca025d", "description": "Ballroom - upstairs", "capacity": 500}, {"name": "Hardware Village - CTF", "slug": "5576-hardware-village-ctf", "guid": "8d70bac1-b031-5f61-8bab-832a8e6f46ce", "description": "Ballroom - upstairs", "capacity": null}, {"name": "Off-Site", "slug": "5577-off-site", "guid": "d9b111d7-93b3-531e-853f-4f812ad3ab4c", "description": null, "capacity": null}], "tracks": [{"name": "Off-Main Track", "slug": "6989-off-main-track", "color": "#05a0c7"}, {"name": "Main Track", "slug": "6990-main-track", "color": "#b34e15"}, {"name": "Event Track", "slug": "6991-event-track", "color": "#1632AB"}, {"name": "Careers Village", "slug": "6992-careers-village", "color": "#0DF785"}, {"name": "BSidesCbr 101", "slug": "6993-bsidescbr-101", "color": "#E027DF"}], "days": [{"index": 1, "date": "2026-09-24", "day_start": "2026-09-24T04:00:00+10:00", "day_end": "2026-09-25T03:59:00+10:00", "rooms": {"Main Track": [{"guid": "bf3ee52b-93ca-5dff-8bfe-7b0b7938adf2", "code": "UPZFD7", "id": 102970, "logo": null, "date": "2026-09-24T09:00:00+10:00", "start": "09:00", "end": "2026-09-24T09:10:00+10:00", "duration": "00:10", "room": "Main Track", "slug": "bsides-canberra-2026-102970-opening-ceremony", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UPZFD7/", "title": "Opening Ceremony", "subtitle": "", "track": "Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "Welcome to BSides Canberra 2026!\n\nJoin us as we kick off another year of Australia's largest hacker conference. In this opening session, we'll welcome you to BSides Canberra, introduce this year's event, and share what's in store over the next three days.\n\nWe'll highlight this year's program, cover important announcements, and run through everything you need to know to make the most of the conference. Whether you're here to learn from world-class speakers, compete in the CTFs, explore the villages, discover new research, or connect with the community, we're thrilled to have you with us.\n\nLet's get BSides Canberra 2026 underway.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "VFNSXA", "name": "Kylie McDevitt", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/9YSTES_46GPsAx.webp", "biography": "-", "public_name": "Kylie McDevitt", "guid": "f93e2b97-9295-5e76-bcf8-8413b2f00e95", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/VFNSXA/"}, {"code": "VGEQFE", "name": "Dr Silvio Cesare", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/ZHDDYU_8oC4brY.webp", "biography": "-", "public_name": "Dr Silvio Cesare", "guid": "569b7832-1e43-57c0-a63f-e4d2cfad0a24", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/VGEQFE/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UPZFD7/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UPZFD7/", "attachments": []}, {"guid": "cf96e2db-423a-54e3-9caf-659ecfd123c1", "code": "VZENQH", "id": 102971, "logo": null, "date": "2026-09-24T09:10:00+10:00", "start": "09:10", "end": "2026-09-24T09:50:00+10:00", "duration": "00:40", "room": "Main Track", "slug": "bsides-canberra-2026-102971-thursday-keynote-tba", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VZENQH/", "title": "Thursday Keynote - TBA", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "TBA", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VZENQH/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VZENQH/", "attachments": []}, {"guid": "07903407-5199-5057-abe3-1ae646a05d93", "code": "8FNRMJ", "id": 102546, "logo": null, "date": "2026-09-24T11:00:00+10:00", "start": "11:00", "end": "2026-09-24T11:55:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-102546-viral-vulnerabilities-unpacking-copy-fail-and-related-linux-kernel-bugs", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/8FNRMJ/", "title": "Viral Vulnerabilities: Unpacking Copy.Fail and related Linux Kernel bugs", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Copy.Fail (CVE-2026-31431), a critical Linux kernel bug found by researchers at Theori, quickly rose to prominence after its public disclosure in April 2026. Discussion was fuelled by a 732-byte Python exploit script that anybody can run; a dedicated disclosure website with glaring mistakes; and the lack of security patches in some major distros upon release. In the following weeks, variant bugs named Dirty Frag (CVE-2026-43284/CVE-2026-43500) and Fragnesia (CVE-2026-46300) were discovered, starting further conversations about the future role of AI in vulnerability discovery.\n\nIn this talk, I break down the Copy.Fail bug and exploit, hoping to explain them in a way that is understandable even if you haven\u2019t looked at the Linux Kernel source before. We will take a look at how they work, how the bugs were patched and mitigated, related vulnerabilities, and discuss this bug class in general.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "KL8ART", "name": "Angus", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/XDCYRK_jL5DzIB.webp", "biography": "Angus is a vulnerability researcher at InfoSect. At work, he is well known for giving talks that go way over time and contain unnecessary amounts of detail. Outside of work, Angus enjoys learning new (usually useless) skills, attempting (and forever failing) to win CTFs, cooking (hopefully) tasty food, and is known to be overly competitive when playing (video|board|role-playing|war)games with his friends.", "public_name": "Angus", "guid": "0f6cc162-2ea5-53d8-9e2f-a985951a7fc6", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/KL8ART/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/8FNRMJ/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/8FNRMJ/", "attachments": []}, {"guid": "d6a0c894-2a3b-59b8-8273-636369a7eb7d", "code": "E7QC78", "id": 101583, "logo": "https://cfp.bsidescbr.com.au/media/bsides-canberra-2026/submissions/E7QC78/image_d6dq2Bz.webp", "date": "2026-09-24T12:00:00+10:00", "start": "12:00", "end": "2026-09-24T12:25:00+10:00", "duration": "00:25", "room": "Main Track", "slug": "bsides-canberra-2026-101583-novel-router-emulation-for-malware-reverse-engineering-infrastructure-discovery", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/E7QC78/", "title": "Novel Router Emulation for Malware Reverse Engineering & Infrastructure Discovery", "subtitle": "", "track": "Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "Traditional reverse engineering of edge networking firmware frequently stall at the system emulation layer due too proprietary headers, missing vendor kernel sources, and strict dependencies on physical hardware controllers. This presentation demonstrates applied User-Mode Emulation and Environment Spoofing techniques via PRoot and QEMU-ARM-Static to execute, debug, and dynamically analyse malicious edge-device implants without a native kernel. By systematically bypassing hardware configuration dependencies through virtual memory reservation, RAM capacity spoofing, and writable system-file topology bind-mounting. Researchers should be able too successfully stabilise and interrogate volatile system management daemons reliably for reverse engineering and remediation.", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "UTWD7K", "name": "Kendo", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/LZKXCL_G4b7oV5.webp", "biography": "A Security Engineer with Advanced Practices at Google. He primarily supports frontline intelligence operations and incident response investigations.", "public_name": "Kendo", "guid": "482b0ef9-5abb-55a8-af94-fd80c65686ec", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/UTWD7K/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/E7QC78/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/E7QC78/", "attachments": []}, {"guid": "0181e06d-73eb-5aaa-8ac4-35f1a080ba49", "code": "CWSFLH", "id": 98431, "logo": null, "date": "2026-09-24T13:30:00+10:00", "start": "13:30", "end": "2026-09-24T14:25:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-98431-azul-how-to-build-good-malware-analysis-platforms", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWSFLH/", "title": "Azul: How to build \u201cgood\u201d malware analysis platforms", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "_Alternatively: Azul - The Talk, or Azul - It\u2019s Blue!_\n\nAzul is ASD\u2019s ACSC\u2019s in-house malware analysis and clustering platform, designed to deal with the \nfast-paced and complex threat landscape that malware reverse engineers and incident responders \nface. This talk will describe why we have built Azul, what it does, and a technical deep-dive into how to build systems that meets both the needs of highly technical users and robustness required for large \norganisations. \n\nThe talk will include live demos on the product\u2019s use in real analysis situations, reflections on previous \ninternal iterations of the product and anecdotes on what not to do when building products like this. The talk will answer why organisations might have a need for automated malware processing products like Azul and where to find our open-source release.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "YUL9AZ", "name": "James L", "avatar": null, "biography": "James is an automation engineer at ASD's ACSC, working on automated malware analysis platforms to improve the speed and accuracy of incident response activities.", "public_name": "James L", "guid": "e2102f82-c652-50cb-8ac4-bcc0c7c10457", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/YUL9AZ/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWSFLH/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWSFLH/", "attachments": []}, {"guid": "f6599fa1-9161-574b-9798-40b72910a3c7", "code": "MMAHSM", "id": 99702, "logo": null, "date": "2026-09-24T14:30:00+10:00", "start": "14:30", "end": "2026-09-24T14:55:00+10:00", "duration": "00:25", "room": "Main Track", "slug": "bsides-canberra-2026-99702-let-it-sync-in", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MMAHSM/", "title": "Let It Sync In", "subtitle": "", "track": "Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "In this talk, I'll present my research into the internals of the Microsoft Edge Sync Service, examining how the platform authenticates users, protects synchronized data, and exposes functionality through its backend APIs. We'll begin by exploring Family of Client ID (FOCI) tokens, how they fit into Microsoft's authentication ecosystem, and why they play a critical role in Edge Sync.\n\nFrom there, we'll dive into the Edge Sync APIs themselves, demonstrating how FOCI tokens can be leveraged to interact directly with synchronization endpoints. We'll examine the structure of synchronized data, the cryptographic protections applied to it, and the mechanisms used to store and transmit sensitive information.\n\nBuilding on this foundation, I'll demonstrate how synchronization functionality can be abused to extract sensitive data including saved passwords, history and other sync data from a victim's Edge profile. \n\nFinally, I'll reveal a novel technique that leverages the Edge Sync Service to transform a FOCI token into a fully authenticated user session through the acquisition of ESTSAUTH cookies, currently the ONLY known method of performing this type of token-to-session conversion.\n\nAttendees will leave with a deep understanding of Microsoft Edge Sync's architecture, authentication model, data protection mechanisms, and associated attack surface. Defenders will gain practical guidance for identifying, detecting, and mitigating these techniques within Microsoft 365 environments.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "LAHWQA", "name": "Dylan Bradley", "avatar": null, "biography": "I am a Penetration Tester and Red Teamer from Melbourne with specilisations in Active Directory and Azure / M365. I recently contributed a small amount of research on SCCM to the Misconfiguration Manager Github. I also have an interest in the blue team side of things as I believe it is important to know how to effectively navigate and detect the attacks that I perform. I love having a yap so if you see me around come talk tech or ask me about what I get up to outside the tech world.", "public_name": "Dylan Bradley", "guid": "51e803dc-c8df-5cb9-8b5b-35a90ca4141a", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/LAHWQA/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MMAHSM/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MMAHSM/", "attachments": []}, {"guid": "f889d7ca-ab16-5913-99da-2f8f04e0ddb4", "code": "EQ7PKG", "id": 101767, "logo": null, "date": "2026-09-24T15:15:00+10:00", "start": "15:15", "end": "2026-09-24T16:10:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-101767-password-mismanagers-hunting-for-authentication-bypasses-in-enterprise-password-managers", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/EQ7PKG/", "title": "Password MisManagers: Hunting for Authentication Bypasses in Enterprise Password Managers", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Enterprise password managers hold the keys to the kingdom. Pop one, and you can instantly compromise every piece of infrastructure whose admin credentials were kept inside. So how well do these pieces of software hold up? In this talk, I'll walk through three different authentication bypass vulnerabilities I've found in self-hosted enterprise password managers used by Australian organisations. Each one allowing a user without access to walk on in as an admin and loot all the secrets. Along the way, I'll discuss overcoming two commercial code obfuscators, a fun bonus vulnerability that wandered straight out of a CTF and into production, and what defenders should actually do about all of this.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "HW9MQQ", "name": "Aidan Stansfield", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/8VZY3A_023F8IA.webp", "biography": "Aidan is a penetration tester and security researcher at Division 5. Over the years, he has tested most attack surfaces across most industries, with a particular focus on internal networks and critical infrastructure. Nowadays, he hunts for bugs that require a deeper dive then a traditional pentest permits. Outside of work, he creates CTF challenges for his local hackercons (BSides BNE and Crikeycon), and represented Team Oceania at the International Cybersecurity Challenge (ICC) in 2022 and 2023.", "public_name": "Aidan Stansfield", "guid": "42cbbc29-284b-56d9-9bb1-bf1813fa99b2", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/HW9MQQ/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/EQ7PKG/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/EQ7PKG/", "attachments": []}, {"guid": "e4e359d0-6207-5cfc-88fc-c328fb6e3c05", "code": "MTNFGS", "id": 95351, "logo": null, "date": "2026-09-24T16:15:00+10:00", "start": "16:15", "end": "2026-09-24T17:10:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-95351-unlimited-exploitation-of-signed-windows-drivers", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MTNFGS/", "title": "Unlimited Exploitation of Signed Windows Drivers", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Bring your own vulnerable driver (BYOVD) is a technique used by many APTs and ransomware groups to gain privileged Kernel access to a Windows target, typically to terminate security software running in protected processes on the host that cannot be modified by regular processes. \n\nIts enough of a threat that Microsoft keep a list of vulnerable drivers that can be blocked from installation on Windows systems. Does this actually stop attackers though? How common are vulnerable signed Kernel drivers?\n\nThis talk explores how I built tooling to automatically pull down hundreds of random signed drivers, perform automated analysis on them and also perform automated exploit generation to easily generate weaponised BYOVD bundles that are not known or present in the Window's blocklist.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "MR38YM", "name": "Christopher Vella (Kharosx0)", "avatar": null, "biography": "Christopher Vella is a security researcher @ Microsoft (MORSE) and develops trainings and custom vulnerability research tooling @ Signal Labs", "public_name": "Christopher Vella (Kharosx0)", "guid": "af85f24b-6cda-55bc-98e5-a0497f09c4d8", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/MR38YM/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MTNFGS/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MTNFGS/", "attachments": []}], "Off-Main Track": [{"guid": "4f8a58b5-71ca-5498-b3af-3797d6c5b326", "code": "NN99FA", "id": 103507, "logo": null, "date": "2026-09-24T10:00:00+10:00", "start": "10:00", "end": "2026-09-24T17:00:00+10:00", "duration": "07:00", "room": "Off-Main Track", "slug": "bsides-canberra-2026-103507-careers-village", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/NN99FA/", "title": "Careers Village", "subtitle": "", "track": "Careers Village", "type": "Event", "language": "en", "abstract": "The goal of the Career Village is all about supporting people in their cyber security careers and linking them up with hiring managers. When you come to the village, you'll have the chance to learn about making yourself look good to employers, putting together a killer resume, nailing the interview, and meeting industry professionals and people who want to hire more security staff. We've got experts in recruitment and security who can help you no matter what stage of your career you're at - whether you're just starting out or you're looking for the next stage in your cyber security career.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "EVPECT", "name": "Ricki Burke", "avatar": null, "biography": null, "public_name": "Ricki Burke", "guid": "21b060c6-9f55-554a-be6a-c737a04c1d11", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/EVPECT/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/NN99FA/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/NN99FA/", "attachments": []}], "Exhibition Hall": [{"guid": "2f9c0994-44a7-5753-a379-cb4b299be5d4", "code": "ERKKBA", "id": 102788, "logo": null, "date": "2026-09-24T10:00:00+10:00", "start": "10:00", "end": "2026-09-24T14:00:00+10:00", "duration": "04:00", "room": "Exhibition Hall", "slug": "bsides-canberra-2026-102788-speedrun-ctf-qualifiers", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ERKKBA/", "title": "Speedrun CTF Qualifiers", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "Welcome to the Speedrun CTF Qualifier! Where precision, speed, and nerves of steel collide.\n\nIndividual competitors will face two challenges drawn from a mix of web, pwn, reverse engineering, or crypto. You\u2019ll have a maximum of 15 minutes to complete both.\n\nThe faster you solve, the higher you climb. Only the top 8 fastest solvers will earn a spot in the live finale.\n\nNo second chances. No warm-ups. Just you, the challenge, and the clock. Think you're fast enough?", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "S9DW9G", "name": "toasterpwn", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/LWEWGJ_i9aQz7m.webp", "biography": "Your Speedrun CTF host returns for 2026: toasterpwn [https://x.com/toasterpwn](https://x.com/toasterpwn)\n\nAfter a hugely successful debut at BSides Canberra last year, toasterpwn is back to put competitors through another fast-paced gauntlet of hacking challenges. Winner of the Hexacon Speedrun CTF 2024, captain of the Australian team Emu Exploit, and a professional vulnerability researcher at InfoSect, toasterpwn combines elite technical skills with a passion for creating fun, competitive challenges.\n\nKnown for lightning-fast exploitation and a love of all things pwn, toasterpwn has earned a reputation as one of Australia's rising offensive security talents. Whether you're chasing the top spot or simply looking to test your skills against the clock, the Speedrun CTF is back for another year of rapid-fire hacking action.", "public_name": "toasterpwn", "guid": "8c85474a-0bc8-52a2-99e3-1736c5c0ed63", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/S9DW9G/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ERKKBA/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ERKKBA/", "attachments": []}, {"guid": "178b1ef5-3525-5b84-b8c5-03982f207f93", "code": "7EVT9P", "id": 102789, "logo": null, "date": "2026-09-24T14:00:00+10:00", "start": "14:00", "end": "2026-09-24T16:30:00+10:00", "duration": "02:30", "room": "Exhibition Hall", "slug": "bsides-canberra-2026-102789-speedrun-ctf-finale", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/7EVT9P/", "title": "Speedrun CTF Finale", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "The top 8 have qualified - now it\u2019s time to crown a champion live on stage.\n\nIn the Speedrun CTF Finale, competitors go head-to-head in a single-elimination bracket, racing through a gauntlet of challenges in front of a live audience. The fastest solver in each match advances, with the pressure mounting as the field thins.\n\nRound by round, the competition intensifies - until only one winner remains standing.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "S9DW9G", "name": "toasterpwn", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/LWEWGJ_i9aQz7m.webp", "biography": "Your Speedrun CTF host returns for 2026: toasterpwn [https://x.com/toasterpwn](https://x.com/toasterpwn)\n\nAfter a hugely successful debut at BSides Canberra last year, toasterpwn is back to put competitors through another fast-paced gauntlet of hacking challenges. Winner of the Hexacon Speedrun CTF 2024, captain of the Australian team Emu Exploit, and a professional vulnerability researcher at InfoSect, toasterpwn combines elite technical skills with a passion for creating fun, competitive challenges.\n\nKnown for lightning-fast exploitation and a love of all things pwn, toasterpwn has earned a reputation as one of Australia's rising offensive security talents. Whether you're chasing the top spot or simply looking to test your skills against the clock, the Speedrun CTF is back for another year of rapid-fire hacking action.", "public_name": "toasterpwn", "guid": "8c85474a-0bc8-52a2-99e3-1736c5c0ed63", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/S9DW9G/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/7EVT9P/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/7EVT9P/", "attachments": []}], "Murray-Fitzroy Room": [{"guid": "d213f615-78dc-5147-971e-f94e0cb5cd3c", "code": "QWSKGN", "id": 102325, "logo": "https://cfp.bsidescbr.com.au/media/bsides-canberra-2026/submissions/QWSKGN/image_uAOW5UJ.webp", "date": "2026-09-24T10:00:00+10:00", "start": "10:00", "end": "2026-09-24T17:00:00+10:00", "duration": "07:00", "room": "Murray-Fitzroy Room", "slug": "bsides-canberra-2026-102325-from-copilot-to-commander-building-agentic-ai-for-security-investigations", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QWSKGN/", "title": "From Copilot to Commander: Building Agentic AI for Security Investigations", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "A hands-on 8-hour workshop on building AI systems that run real security investigations - not just isolated copilot tasks. Most teams get useful help from Claude or ChatGPT on single questions. Few can reliably run multi-step investigations across logs, tools, and incidents.\nTaught by instructors behind the most popular Black Hat 2025 AI training and the team that built the first AI agent to autonomously solve the Splunk Boss of the SOC CTF.\nInvestigation agents fail not because of model quality, but because investigations are multi-step, ambiguous, and tool-heavy - small errors compound and there are no unit tests to keep things on track.\n\nFour labs:\nLab 1: Run an OSS LLM locally and watch it hallucinate on SOC questions\nLab 2: Wrap it in an agent harness against Splunk BOTSv3\nLab 3: Author a plan.md timelining skill\nLab 4: Score it, error-analyze traces, fix the skill, watch the score move\n\nConcept blocks cover harness anatomy, MCP and skills, planning patterns, evals, agentic memory and RAG, and securing agents against the lethal trifecta.\nYou leave with a working agent, a reusable skill, an eval harness, and a methodology.\n\nAudience: SOC, IR, threat hunters, detection engineers, architects, technical leaders.\nPrereqs: Laptop, terminal comfort, optional Python. Pre-work to install harness + pull local model.\nWe bring: LLM API key for attendees, bring your own key if prefered.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "G8NVCQ", "name": "Sindre Breda", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/3SQQQ3_kgTgV97.webp", "biography": "Police officer turned computer forensic investigator, turned analyst/developer. Sindre started his career as a street cop that quickly switched to computer forensics/mobile forensics with key focus on online child abuse.\nFrom 2018 he worked at the Norwegian \"National Criminal Investigation Service\", more commonly known as Kripos.\nAt Kripos he worked with analyzing data that the commercial forensic toolkits did not parse/present, most actively in the investigations of the ransomware attack against Norsk Hydro in 2019. Currently working as a Solutions architect at Graphistry.", "public_name": "Sindre Breda", "guid": "45ce9e2d-24f4-5e1f-951f-5f23902acd68", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/G8NVCQ/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QWSKGN/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QWSKGN/", "attachments": []}], "Derwent Room": [{"guid": "3e9a789c-8c47-59c7-8b4f-89a3d2c7b3fd", "code": "Z8EKP7", "id": 102988, "logo": null, "date": "2026-09-24T10:00:00+10:00", "start": "10:00", "end": "2026-09-24T17:00:00+10:00", "duration": "07:00", "room": "Derwent Room", "slug": "bsides-canberra-2026-102988-black-bag-day-1", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/Z8EKP7/", "title": "Black Bag - Day 1", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "The Black Bag is returning to BSides Canberra 2026. More details coming soon.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "GRHHVD", "name": "TBA", "avatar": null, "biography": null, "public_name": "TBA", "guid": "711291c1-2dec-5716-92cf-5c928d0b46a8", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/GRHHVD/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/Z8EKP7/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/Z8EKP7/", "attachments": []}], "Locksport Village": [{"guid": "cde3c14b-8a46-5ade-8777-d8a7b2fa79ea", "code": "CFPTRQ", "id": 103041, "logo": null, "date": "2026-09-24T10:00:00+10:00", "start": "10:00", "end": "2026-09-24T17:00:00+10:00", "duration": "07:00", "room": "Locksport Village", "slug": "bsides-canberra-2026-103041-locksport-day-1", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CFPTRQ/", "title": "Locksport (Day 1)", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "The Locksport village is your gateway into the fascinating world of physical security. Whether you're a total newcomer or a seasoned picker, there's something here for everyone.\n\nExplore a wide variety of locks, pick tools, and hands-on challenges \u2013 all under the guidance of experienced instructors ready to share their tips and tricks. Learn how locks work, discover their vulnerabilities, and test your skills on locks ranging from beginner to expert difficulty.\n\nThis isn\u2019t just a display \u2013 it\u2019s a fully interactive experience. Step into the shoes of a lockpicker, challenge yourself, and maybe even surprise yourself with a hidden knack for tumblers and tension wrenches.\n\nCome for the curiosity, stay for the challenge. You might just unlock a new obsession.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "L9BFYP", "name": "Volunteers", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/FYKFVH_Fz6KAh3.webp", "biography": "BSides Canberra is entirely volunteer-run, with around 40 dedicated volunteers who contribute both before and during the event. Volunteers can be easily identified by their maroon t-shirts.", "public_name": "Volunteers", "guid": "36a8643c-eada-5b68-8d2f-610966fefbd9", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/L9BFYP/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CFPTRQ/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CFPTRQ/", "attachments": []}], "Hardware Village": [{"guid": "9dc72f29-dd40-5591-a61f-ec04b112faa6", "code": "CKHTDK", "id": 103044, "logo": null, "date": "2026-09-24T10:00:00+10:00", "start": "10:00", "end": "2026-09-24T16:00:00+10:00", "duration": "06:00", "room": "Hardware Village", "slug": "bsides-canberra-2026-103044-hardware-village-day-one", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CKHTDK/", "title": "Hardware Village (Day One)", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "Step away from the keyboard \u2013 it\u2019s time to get hands-on. Whether you're a seasoned tinkerer or just curious about what\u2019s inside your badge, the Hardware Village is your space to learn, hack, solder, and explore.\n\nWe\u2019ll have soldering stations ready for badge mods and hardware experiments, plus friendly experts on hand to help with troubleshooting or inspiration. Bring your gear or just swing by to see what others are building and tinkering with.\n\nThere\u2019s always something to learn, create, or break (safely, of course).", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "L9BFYP", "name": "Volunteers", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/FYKFVH_Fz6KAh3.webp", "biography": "BSides Canberra is entirely volunteer-run, with around 40 dedicated volunteers who contribute both before and during the event. Volunteers can be easily identified by their maroon t-shirts.", "public_name": "Volunteers", "guid": "36a8643c-eada-5b68-8d2f-610966fefbd9", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/L9BFYP/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CKHTDK/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CKHTDK/", "attachments": []}]}}, {"index": 2, "date": "2026-09-25", "day_start": "2026-09-25T04:00:00+10:00", "day_end": "2026-09-26T03:59:00+10:00", "rooms": {"Main Track": [{"guid": "92e80d86-9579-5be4-acb4-09dffa37a086", "code": "FYAJ8P", "id": 102972, "logo": null, "date": "2026-09-25T09:10:00+10:00", "start": "09:10", "end": "2026-09-25T09:50:00+10:00", "duration": "00:40", "room": "Main Track", "slug": "bsides-canberra-2026-102972-friday-keynote-tba", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/FYAJ8P/", "title": "Friday Keynote - TBA", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "TBA", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/FYAJ8P/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/FYAJ8P/", "attachments": []}, {"guid": "dd2d5bbf-ddaa-5bf5-bd73-3dbda7c7f6ef", "code": "GZAL9B", "id": 95403, "logo": null, "date": "2026-09-25T10:00:00+10:00", "start": "10:00", "end": "2026-09-25T10:55:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-95403-doppelganger-weaponizing-cve-2026-23066-at-zeroday-cloud", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GZAL9B/", "title": "Doppelganger - Weaponizing CVE-2026-23066 at ZeroDay.Cloud", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "What happens when the kernel loses track of its own objects?\n\nDoppelganger (CVE-2026-23066) is a race-condition in the Linux kernel's RxRPC subsystem that allows the same object reference to be queued into a linked list more than once. Could such a simple primitive really be turned into a reliable kernel exploit?\n\nIt can, and it was. This talk traces the full journey from discovery of the subtle bug in `rxrpc_recvmsg()` to a working exploit demonstrated live at the ZeroDay.Cloud competition in London.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "UFHJFD", "name": "Faraz", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/8XSSQU_UcEcXUg.webp", "biography": "Faraz is a Lead Blockchain Security Researcher at Zellic. When not busy with work, he likes to play video games and indulge in low level vulnerability research and exploit development.", "public_name": "Faraz", "guid": "2aa1400b-40d2-54b1-bb34-3e4ddea411e8", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/UFHJFD/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GZAL9B/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GZAL9B/", "attachments": []}, {"guid": "74dd5179-a67d-57b9-a8e5-72dd42c018bc", "code": "LESWA7", "id": 96775, "logo": null, "date": "2026-09-25T11:00:00+10:00", "start": "11:00", "end": "2026-09-25T11:55:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-96775-fatal-errors-forensics-pitfalls-in-the-mushroom-murders-case-study", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LESWA7/", "title": "Fatal Errors: Forensics Pitfalls in the \"Mushroom Murders\" Case Study", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Digital forensics is often the \"silent witness\" that secures a conviction, but procedural missteps can risk the entire case. This presentation uses the infamous 2023 \"Mushroom Murders\" investigation as a case study to demonstrate critical failures in the collection, processing, and reporting of digital evidence. Drawing on first-hand experience as an examiner in the case, I will analyse high-profile technical hurdles, including remote wipes, SIM swapping, and contested data integrity that became focal points in the Supreme Court. Attendees will explore the technical \"what-not-to-do\" of forensics through real-world examples of factory resets and search history recovery, providing a roadmap for ensuring admissibility in high-stakes criminal litigation.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "ZE9SA7", "name": "Zoran Iliev", "avatar": null, "biography": "With over 25 years of pioneering digital forensics for government agencies, law enforcement, and global corporations, Zoran has shaped the future of forensic science. His innovative methodologies and insights have solved high-stakes investigations, from cyber fraud to international policy breaches. As a Lead Forensic Examiner at the Department of Home Affairs and a recognised educator, Zoran empowers organisations worldwide, transforming challenges into resolutions. Zoran holds a Master of eForensics and Enterprise Security from the University of Melbourne. He is a NATA technical assessor and the only ANAB technical assessor and auditor in Australia.", "public_name": "Zoran Iliev", "guid": "01693d32-5d60-5220-874f-a0825bec6021", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/ZE9SA7/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LESWA7/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LESWA7/", "attachments": []}, {"guid": "1e73c339-a5d4-5f93-a759-46283cbcb4d7", "code": "KHLBMX", "id": 102381, "logo": null, "date": "2026-09-25T12:00:00+10:00", "start": "12:00", "end": "2026-09-25T12:25:00+10:00", "duration": "00:25", "room": "Main Track", "slug": "bsides-canberra-2026-102381-chasing-shadows-portable-memory-corruption-in-ghostscript", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/KHLBMX/", "title": "Chasing Shadows: Portable Memory Corruption in Ghostscript", "subtitle": "", "track": "Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "Ghostscript is one of the most ubiquitous PostScript interpreters in the world. Even if you never run it directly, your systems probably do: rendering thumbnails, converting documents, previewing uploads, or handling images that quietly become PostScript somewhere along the way.\n\nGhostscript is also a C codebase with roots in the late 1980s, which means there is still plenty of room for memory corruption when parsing untrusted input.\n\nIn this talk, we will walk through two heap corruption bugs we discovered in Ghostscript and show how we turned them into reliable memory read/write primitives callable from PostScript. Rather than relying on fixed offsets, the exploit uses those primitives to scan Ghostscript\u2019s address space at runtime, locate the internal structures needed for the attack, and construct a data-only sandbox escape from PARANOIDSAFER that works across multiple versions and builds.\n\nWe will then zoom out and look at where this kind of bug can actually be exploited. Thumbnailers, ImageMagick, LibreOffice, web applications, and document-processing pipelines all have different file formats and integration points, but the sink is often the same PostScript interpreter.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "CGGLLV", "name": "Rick de Jager", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/LYVAV7_ci8vijp.webp", "biography": "Rick is a full-time security researcher at v12.sh and a member of the Pwn2Own team \u201cPHP Hooligans.\u201d He has competed in five editions of Pwn2Own, exploiting a wide range of targets including routers, printers, and automotive systems. Outside of Pwn2Own, Rick is an avid CTF player, having competed as part of 0rganizers and ICC\u2019s Team Europe.", "public_name": "Rick de Jager", "guid": "42fbcdf1-363b-5a5b-a5e2-eb18590ca836", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/CGGLLV/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/KHLBMX/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/KHLBMX/", "attachments": []}, {"guid": "f7d63311-a083-530f-a293-326b058e77f7", "code": "LFCLZK", "id": 103087, "logo": null, "date": "2026-09-25T14:00:00+10:00", "start": "14:00", "end": "2026-09-25T14:55:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-103087-redacted-until-7aug-2026", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LFCLZK/", "title": "[redacted] until 7Aug 2026", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "[redacted] until 7Aug 2026 due to disclosure timelines", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LFCLZK/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LFCLZK/", "attachments": []}, {"guid": "48ed41ba-a152-5431-8be8-f2f1f2c2057f", "code": "ZREJ37", "id": 102359, "logo": null, "date": "2026-09-25T15:15:00+10:00", "start": "15:15", "end": "2026-09-25T16:10:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-102359-time-crisis-exploiting-time-based-padding-oracle-vulnerabilities-using-timeless-timing-attacks", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZREJ37/", "title": "Time Crisis: Exploiting time-based padding oracle vulnerabilities using Timeless Timing Attacks", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Cryptographic padding oracle vulnerabilities are far from new. If you can throw crafted ciphertext at a Cipher Block Chaining (CBC) decryption endpoint, and it is kind enough to tell you whether it was a padding error or something else that caused it to blow up, you can use some crafty block algebra to turn it into a byte-by-byte decryption/encryption machine.\n\nIt may be tempting to fix a padding oracle vulnerability by normalising the error messages. Instead of saying, \"Oops, there was a padding error!\" simply say \"Oops, there was an error.\" Better yet, just return a generic HTTP 500 response.\n\nThe problem is that error messages are only a symptom of padding oracles, they are not the root cause. Any kind of divergent code path behaviour can give rise to a subtle sub-millisecond timing difference, which can be just enough to reveal the secrets of a padding oracle.\n\nJustin will walk you through the methodology behind CBC padding oracle exploitation, the curse of WAN jitter that can destroy a fragile timing signal, and the blessing of Timeless Timing Attacks (Van Goethem et al., 2020) which uses HTTP/2 co-scheduling to sniff out even the faintest of timing differentials.\n\nJoin us to hear about the full suite of Timeless Timing Attacks tooling we're releasing at BSides Canberra 2026 including Go libraries, statistical engines, and command-line tools. Learn how to exploit time-based padding oracle vulnerabilities, get bamboozled by statistical methodologies you thought you'd never have to hear about again, and wonder whether there are other \"obvious\" vulnerability fixes that could come undone given careful consideration of time. We can't wait to hear what you come up with!", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "Z7QJTJ", "name": "Justin Steven", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/FWBHEM_1ris77o.webp", "biography": "Justin is a seasoned computer security professional with 14 years of experience across Incident Response and Software Security. As Tanto Security's Director of Research, Justin fosters the curiosity and ingenuity of our consultants, supporting them as they engage in their own research projects.", "public_name": "Justin Steven", "guid": "536f79f1-607e-50f6-a56c-39883861836f", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/Z7QJTJ/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZREJ37/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZREJ37/", "attachments": []}], "Off-Main Track": [{"guid": "d3131184-dcef-5eaf-bae8-1e1b679eb712", "code": "PZEVCX", "id": 102348, "logo": null, "date": "2026-09-25T10:00:00+10:00", "start": "10:00", "end": "2026-09-25T10:55:00+10:00", "duration": "00:55", "room": "Off-Main Track", "slug": "bsides-canberra-2026-102348-exploiting-the-microsoft-365-substrate-how-their-oauth-clients-became-an-mfa-bypass-across-enterprise-tenants", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/PZEVCX/", "title": "Exploiting the Microsoft 365 Substrate: How their OAuth Clients Became an MFA Bypass Across Enterprise Tenants", "subtitle": "", "track": "Off-Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Every time you sign in to Microsoft 365, a quiet exchange happens behind the scenes. Entra ID issues a token, and a sprawling backend known as the Microsoft 365 Substrate decides what that token is allowed to do. Most of that machinery is invisible, well trusted, and rarely questioned, which makes it exactly the kind of place worth questioning.\n\nTucked inside those tokens are claims that downstream services lean on to decide whether you really are who you say you are, and whether you have done the things, like MFA, that policy demands. But what happens when two parts of Microsoft's own platform disagree about what a token has actually proven?\n\nIn this talk I'll show how an asymmetry of authorisation between Microsoft Entra ID single sign-on and the Microsoft 365 Substrate led to enterprise account compromise on accounts where MFA should have been enforced.\n\nYou'll see how the now-patched, Important-rated vulnerability I found works end to end, starting from where it began and following how a small finding grew into something much larger.\nI'll trace how misplaced trust in the claims of an access token turned into enterprise-scale data exfiltration, show some of the stranger quirks of the Substrate I ran into along the way, and explain why the asymmetry existed in the first place, with Windows Search, Microsoft Edge and Microsoft Teams all turning out to be the stars of the show.\n\nFinally, we'll change lens and see why this isn't just a Microsoft bug, and why it might be a cautionary tale for the applications you're building. We'll walk through the common OAuth and OIDC gotchas: where developers over-trust the IdP, which claims actually carry the guarantees you think they do, and why a growing number of application providers are taking MFA enforcement into their own hands rather than waiting on the IdP to do it for them.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "B3333H", "name": "Rawson Wade", "avatar": null, "biography": "Rawson is a Senior Security Engineer at Modern42, where he leads a team of specialist Microsoft Entra developers and engineers building secure IAM ecosystems for government, health, and banking. His expertise sits in the complex end of authentication, with deep domain knowledge across IAM, Workload Identities and CIAM.", "public_name": "Rawson Wade", "guid": "47421ce3-100c-5162-b686-d43b324aaafa", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/B3333H/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/PZEVCX/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/PZEVCX/", "attachments": []}, {"guid": "7b24e890-cb1a-5d98-852b-9017fab42da2", "code": "3VQLVR", "id": 100744, "logo": null, "date": "2026-09-25T11:00:00+10:00", "start": "11:00", "end": "2026-09-25T11:55:00+10:00", "duration": "00:55", "room": "Off-Main Track", "slug": "bsides-canberra-2026-100744-find-my-and-yours-exploiting-tracker-ecosystems-to-track-individuals", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3VQLVR/", "title": "Find My... And Yours: Exploiting Tracker Ecosystems To Track Individuals", "subtitle": "", "track": "Off-Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Modern Bluetooth Low Energy tracking ecosystems: Apple Find My, Samsung SmartThings, Tile, and Google Fast Pair, have each implemented privacy controls designed to prevent persistent observation and protect user privacy. This talk demonstrates how those controls fail in practice. Through passive BLE advertisement collection, protocol-level attacks, linkage analysis, we shows how rotating identifiers can be correlated across time and space to re-identify devices, attribute them to individuals, and reconstruct movement histories.\n\nSpecifically, it will explore how:\n- Rotating identifier schemes, designed to prevent tracking, can be defeated through cryptographic, temporal, and behavioural linkage analysis\n- Passive advertisement collection alone, requiring no active probing, no accounts, and no interaction with target devices or ecosystems and is sufficient to re-identify devices and reconstruct movement\n- Cross-vendor artefacts and advertisement structure leak identity signals that individual vendors have not accounted for in their threat models\n- The privacy guarantees communicated to hundreds of millions of users do not reflect the practical reality of what passive observers can determine\n\nThe session will present a mix of linkage algorithms targeting different artifact classes across the four ecosystems and connect the findings to the broader question of what \"privacy by design\" actually requires when adversarial passive observation is the threat model.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "UNNPLD", "name": "Carter Smith", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/TMJHAB_SHY82F4.webp", "biography": "Carter, based in Darwin, is a seasoned security consultant with a rich background in both building and testing the security of software and networks. Proficient in a diverse array of tools and languages, and various web application frameworks, Carter brings a comprehensive IT and development background to his work, being able to think as a developer as well as an adversary.\n\nHis security testing expertise extends across a wide spectrum of penetration testing, encompassing web applications, external and internal networks, social engineering, thick client systems, mobile applications, and even physical security domains. Whilst his focus on penetration testing, Carter has broad skills in many aspects of cybersecurity.\n\nPassionate about Open-Source Intelligence (OSINT), Carter's commitment to this field is demonstrated through his appearances on the TV show HUNTED three times, and his active involvement in national Cyber Intelligence hackathons.\n\nCarter pioneers the development of new OSINT techniques, tools and infrastructure.", "public_name": "Carter Smith", "guid": "e2c0251e-fcda-57b4-92fe-7996b767a75d", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/UNNPLD/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3VQLVR/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3VQLVR/", "attachments": []}, {"guid": "d1ac2c21-585b-555f-829d-a682a544619b", "code": "ZYRVZG", "id": 102364, "logo": null, "date": "2026-09-25T12:00:00+10:00", "start": "12:00", "end": "2026-09-25T12:25:00+10:00", "duration": "00:25", "room": "Off-Main Track", "slug": "bsides-canberra-2026-102364-hooked-tracking-linker-and-generator-persistence-on-linux", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZYRVZG/", "title": "Hooked: Tracking Linker and Generator Persistence on Linux", "subtitle": "", "track": "Off-Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "Standard Linux persistence tracking typically focuses heavily on the more obvious artefacts like cron jobs, rc.local scripts, and standard systemd services. Because security teams look there first, modern attackers are shifting to more elegant, hook-based execution vectors that bypass traditional file-integrity monitoring.\nThis talk dives into dissecting two low-overhead Linux persistence mechanisms: dynamic linker hijacking and Systemd Generators. We will look at the underlying OS mechanics of both vectors, look at a live example of how easily it can blend into legitimate infrastructure and how you can audit them across your entire fleet tomorrow.", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "PVBLFC", "name": "JasonTrapp", "avatar": null, "biography": "Jason has spent over six years working as a digital forensics and incident response analyst, investigating critical incidents across nearly every industry sector. Dealing with ransomware and business email compromise on a daily basis, he is intimately familiar with the realities of modern incident triage. Jason spends his spare time researching cloud security and writing custom tools and programs to streamline complex forensic investigations.", "public_name": "JasonTrapp", "guid": "0738b376-bb26-5d33-b47d-8746668e9a85", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/PVBLFC/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZYRVZG/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZYRVZG/", "attachments": []}, {"guid": "7d78e580-29cf-54d3-a98f-92ae8df3c6dc", "code": "QB3CLU", "id": 98116, "logo": null, "date": "2026-09-25T15:15:00+10:00", "start": "15:15", "end": "2026-09-25T16:10:00+10:00", "duration": "00:55", "room": "Off-Main Track", "slug": "bsides-canberra-2026-98116-inside-of-an-android", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QB3CLU/", "title": "Inside of an Android", "subtitle": "", "track": "Off-Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Have you ever been curious what *really* happens inside a mobile device? How often are different  syscalls used? Are syscall errors common? What binaries are executed, and when?  Whose actually making all these network requests? Do these behaviours change when not connected to USB? If \"yes\", then you're not alone. This talk is a tour of modifications I made to Android to enable answering these questions, and more. Starting from source code, I'll discuss different Android technologies and the changes made to include a range of system and endpoint monitoring tools, as well as the services used to collect, analyse and alert on behaviour from both emulated and physical devices.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "GSSSBW", "name": "Aaron", "avatar": null, "biography": "Aaron has spent 20 years developing and maintaining security systems from within or on behalf of governments. More recently, those skills and experience have also been invested into home lab and hobby projects. One of which is the subject of a BSides Canberra 2026 talk.", "public_name": "Aaron", "guid": "889cdf25-68b0-5425-a38b-4afdb11c9552", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/GSSSBW/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QB3CLU/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QB3CLU/", "attachments": []}, {"guid": "bf3c7675-01e1-51de-ac3f-6920bbc04111", "code": "YDT9EC", "id": 95338, "logo": "https://cfp.bsidescbr.com.au/media/bsides-canberra-2026/submissions/YDT9EC/image_5AqQ4hy.webp", "date": "2026-09-25T16:15:00+10:00", "start": "16:15", "end": "2026-09-25T16:40:00+10:00", "duration": "00:25", "room": "Off-Main Track", "slug": "bsides-canberra-2026-95338-bark-to-the-future-network-security-with-wi-fido", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YDT9EC/", "title": "Bark to the Future: Network Security with Wi\u2011Fido", "subtitle": "", "track": "Off-Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "Turning the whimsical charm of a Pwnagotchi into a fully mobile, AI\u2011enabled robotic dog is more complex than strapping a Raspberry Pi to a chassis and calling it a day. This talk explores the challenges behind creating Wi\u2011Fido\u2014a roaming, autonomous, cybersecurity companion that can literally sniff out trouble.\n\nWe\u2019ll examine the hurdles encountered during this evolution: adapting a traditionally stationary, packet\u2011sniffing program into a faithful friend capable of continuous, context\u2011aware wireless monitoring; integrating AI\u2011driven decision\u2011making to distinguish between benign and suspicious signals. \n\nAdditional challenges include sharing localised data with an LLM, integrating robot interactions, and ensuring Wi-Fido's behavior remains transparent and interpretable\u2014because no one wants a black\u2011box robot dog silently judging their Wi\u2011Fi hygiene. \n\nAttendees will leave with insights into the coding, AI models, and design philosophies that shaped Wi\u2011Fido\u2014and practical lessons learned in turning a traditional Wi\u2011Fi capture workflow into a four\u2011legged, tail\u2011wagging cybersecurity assistant that makes network defense more effective and a lot more fun.", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "Z9N7RC", "name": "Chewhacker", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/PAZATR_EUuLn6e.webp", "biography": "Chewhacker entered the cyber security world in 2020, diving head first into cyber threat intelligence and quickly developing a passion for understanding adversary behaviour. While her work now spans multiple areas of security, CTI and adversary emulation remain her favourite playgrounds.\n\nOutside of work, she can usually be found hunting for her next mechanical keyboard, spending time with her sausage dogs, trying to obtain more sausage dogs, or making friends with people so she can hug their sausage dogs. After assembling badges at past BSides Canberra events, she discovered a new hobby that escalated into building a robotic, AI enabled cyber security dog \u2014 because every good defender deserves a loyal companion.", "public_name": "Chewhacker", "guid": "822bc665-8b42-567f-943d-fc7d8a251254", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/Z9N7RC/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YDT9EC/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YDT9EC/", "attachments": []}, {"guid": "6ffd801c-e544-55fc-9d34-ab83f9f864ed", "code": "3BGZWM", "id": 102336, "logo": null, "date": "2026-09-25T16:45:00+10:00", "start": "16:45", "end": "2026-09-25T17:00:00+10:00", "duration": "00:15", "room": "Off-Main Track", "slug": "bsides-canberra-2026-102336-from-dream-jobs-to-developer-tokens-how-north-korea-based-threat-actors-abuse-trust", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3BGZWM/", "title": "From Dream Jobs to Developer Tokens: How North Korea-based threat actors abuse trust", "subtitle": "", "track": "Off-Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "For years, defending against North Korea-based threat actors meant defenders using the same standard checklist. Block the phishing email, sandbox the lure document, or kill the macro. Since 2021 that checklist has been quietly going out of date. This talk looks at how North Korea-based threat actors changed their game. They did not just write better malware, but they moved closer to targeting the workflows and assets that organisations often implicitly trust.  They target developers, maintainers, recruiters, SaaS logins, CI/CD pipelines, browser sessions, crypto wallets, and in a growing number of cases, they stopped breaking in entirely and simply got hired. \n\nDrawing on PwC Threat Intelligence research into North Korea-based threat actor activity through 2026, I will walk through how the access model works today, using real world examples. A recruiter message that turns into a terminal command. A job interview that becomes the malware delivery mechanism. A developer laptop that quietly hands over source code, cloud keys and wallets, and a new remote hire who was never a real person. The point is simple and a little uncomfortable. The North Korea-based threat actor\u2019s intrusion path no longer starts where most defenders are looking. It starts in your hiring pipeline, your dependency tree, your build system and your payroll. \n\nWhether you work in defence, threat intel, offensive security, or you are just breaking into the industry, you will leave this talk able to spot what these intrusions look like, not just \"what payload ran\" but \"which trust relationship did they abuse, and what did it expose?\".", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "TP33QG", "name": "Sohan Lokula", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/YGFQLU_bfx2uH1.webp", "biography": "Sohan is a Senior Analyst in PwC\u2019s Threat Intelligence team and the North Korea-based threats lead. He is a technical Cyber Threat Intelligence analyst focused on cyber crime and North Korea-based threat actors, with experience across deep and dark web intelligence, threat actor tracking, cyber criminal activity, and strategic intelligence reporting.", "public_name": "Sohan Lokula", "guid": "aa7a3182-1816-508a-b276-0b86152e8cb7", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/TP33QG/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3BGZWM/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3BGZWM/", "attachments": []}], "Exhibition Hall": [{"guid": "845f2f29-7a5f-57b5-b6f0-888607bc76ee", "code": "HBTFRM", "id": 102974, "logo": null, "date": "2026-09-25T10:00:00+10:00", "start": "10:00", "end": "2026-09-25T17:00:00+10:00", "duration": "07:00", "room": "Exhibition Hall", "slug": "bsides-canberra-2026-102974-capture-the-flag-day-one", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/HBTFRM/", "title": "Capture-the-Flag (Day One)", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "CALLING ALL HACKERS, GAMERS, PUZZLE SOLVERS, CRYPTO NERDS, PWN ENJOYERS, REVERSERS, AND CURIOUS NEWCOMERS.\n\nskateboarding dog is back for another year of Capture the Flag featuring brand new challenges, puzzles, and games to put your skills to test.\n\nWe've listened to your feedback! This year, dedicated teams will able to gun for the coveted leaderboard positions as usual, while a *new* mini CTF will be available for the part-time players, merch-oriented gatherers, fun-maximisers, and beginners looking for a more gentle introduction to the world of CTF.\n\nChanging times calls for a shift in our competition rules. We'll be placing restrictions on AI usage and limiting team sizes to keep things fair and fun for everyone.\n\nPrizes to be announced.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "9GCRLS", "name": "skateboarding dog", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/UWXEJY_viSHwMX.webp", "biography": "After an outstanding debut as CTF hosts in 2025, skateboarding dog are back to design and run the BSides Canberra CTF for a second year.\n\nThey're not just any CTF team, they're one of Australia's most accomplished. A powerhouse of talented hackers, this team has dominated the local CTF scene for years, consistently finishing at the top of competitions around the country. Before taking over as hosts, they claimed first place in the BSides Canberra CTF for three consecutive years.\n\nKnown for deep technical expertise, creative exploitation techniques, and exceptionally well-crafted challenges, skateboarding dog has earned a reputation for building CTFs that are approachable for newcomers while still pushing seasoned players to their limits. If last year's competition was anything to go by, you're in for another fantastic weekend of hacking.\n\nWhether you're chasing the podium or tackling your very first challenge, the BSides Canberra 2026 CTF promises another memorable experience with skateboarding dog at the helm.\n\nFollow them on X: [https://x.com/sk8boardingdog](https://x.com/sk8boardingdog)", "public_name": "skateboarding dog", "guid": "2e6415f9-18c2-548b-858d-3e2a379706b2", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/9GCRLS/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/HBTFRM/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/HBTFRM/", "attachments": []}], "Murray-Fitzroy Room": [{"guid": "b94fd002-da5a-557f-813e-0cf5787ccf19", "code": "GY3NLF", "id": 98114, "logo": null, "date": "2026-09-25T09:00:00+10:00", "start": "09:00", "end": "2026-09-25T13:00:00+10:00", "duration": "04:00", "room": "Murray-Fitzroy Room", "slug": "bsides-canberra-2026-98114-kubernetes-capture-the-flag", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GY3NLF/", "title": "Kubernetes Capture the Flag", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "Delve deeper into the dark and mysterious world of Kubernetes security. Start your journey deep inside the target infrastructure, collecting flags as you exploit your position in the environment and hunt for vulnerabilities.\n\nAttendees can play three increasingly beguiling and demanding scenarios to bushwhack their way through the dense jungle of Kubernetes security. Everybody is welcome, from beginner to hardened veteran but attendees will be expected to be hands-on to understand more about core Kubernetes components and how they can be misconfigured and compromised.\n\nEach attendee will be given access to their own Kubernetes cluster built within our bespoke sandboxed training environment. A laptop with an SSH client is required to participate.", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "BXEWZT", "name": "Mario Weigel", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/9USFZK_XpyesXo.webp", "biography": "Mario Weigel has been in the Linux and automation world since 2002, moving through support, testing, and systems administration before the DevOps movement caught up with skills he\u2019d already built. For several years, he\u2019s been consulting in complex, heavily regulated sectors to design solutions that enable security and development teams to thrive in tandem. In his own time, he leads the Auckland Kubernetes meetup.", "public_name": "Mario Weigel", "guid": "ff536eb0-ecf0-5749-99f6-824c60d15c84", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/BXEWZT/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GY3NLF/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GY3NLF/", "attachments": []}, {"guid": "4536f9cc-8068-5da4-a505-28d73ae0ad3a", "code": "G9B7GT", "id": 102385, "logo": null, "date": "2026-09-25T13:30:00+10:00", "start": "13:30", "end": "2026-09-25T16:30:00+10:00", "duration": "03:00", "room": "Murray-Fitzroy Room", "slug": "bsides-canberra-2026-102385-escalating-xss-into-session-hijacking-in-modern-sso-ecosystems", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/G9B7GT/", "title": "Escalating XSS into session hijacking in modern SSO ecosystems", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "Finding an XSS and getting alert(1) to fire is one thing. Turning it into something a program or a client treats as high impact is another, and often the trickier part. A reflected or stored XSS on a subdomain that holds no session, or an XSS you can only trigger on yourself, is easy to set aside as low severity.\n\nModern applications, though, are rarely a single site. They are ecosystems tied together by shared single sign-on, OAuth, parent-domain cookies, CDN caches, and postMessage. Once you understand how those pieces fit together, an XSS almost anywhere on an origin can often be escalated into a one-click account takeover of the main application.\n\nOver the last couple of years I have reported a number of these escalations to bug bounty programs, taking reflected, stored, DOM, and self XSS and chaining them into session hijacking. This workshop walks through how that is done, using a lab built from those findings. It is aimed at testers and bug bounty hunters who can already find XSS and want to learn how to take it further. This workshop will leave you with a set of techniques, a sense of which one fits a given situation, and the confidence to build your own session hijacking chains.", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "SXXTBM", "name": "Animesh Acharya", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/H877ZM_YCTmpXI.webp", "biography": "Animesh is a Senior Security Consultant working at Tanto Security. He is interested in web security research and also does Bug Bounties. You can get in touch with him on LinkedIn at https://www.linkedin.com/in/an1msh/", "public_name": "Animesh Acharya", "guid": "1b2050e0-8589-5e61-80e7-5624dd97f229", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/SXXTBM/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/G9B7GT/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/G9B7GT/", "attachments": []}], "Derwent Room": [{"guid": "85a82138-42c3-50f1-94a0-1469b292e45c", "code": "XSJNE9", "id": 102989, "logo": null, "date": "2026-09-25T09:00:00+10:00", "start": "09:00", "end": "2026-09-25T17:00:00+10:00", "duration": "08:00", "room": "Derwent Room", "slug": "bsides-canberra-2026-102989-black-bag-day-2", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/XSJNE9/", "title": "Black Bag - Day 2", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "The Black Bag is returning to BSides Canberra 2026. More details coming soon.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "GRHHVD", "name": "TBA", "avatar": null, "biography": null, "public_name": "TBA", "guid": "711291c1-2dec-5716-92cf-5c928d0b46a8", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/GRHHVD/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/XSJNE9/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/XSJNE9/", "attachments": []}], "Locksport Village": [{"guid": "4d9b5ad4-4edd-50a7-bb7e-8e6890a29ddd", "code": "ESQF9W", "id": 103042, "logo": null, "date": "2026-09-25T09:00:00+10:00", "start": "09:00", "end": "2026-09-25T16:00:00+10:00", "duration": "07:00", "room": "Locksport Village", "slug": "bsides-canberra-2026-103042-locksport-day-2", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ESQF9W/", "title": "Locksport (Day 2)", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "The Locksport village is your gateway into the fascinating world of physical security. Whether you're a total newcomer or a seasoned picker, there's something here for everyone.\n\nExplore a wide variety of locks, pick tools, and hands-on challenges \u2013 all under the guidance of experienced instructors ready to share their tips and tricks. Learn how locks work, discover their vulnerabilities, and test your skills on locks ranging from beginner to expert difficulty.\n\nThis isn\u2019t just a display \u2013 it\u2019s a fully interactive experience. Step into the shoes of a lockpicker, challenge yourself, and maybe even surprise yourself with a hidden knack for tumblers and tension wrenches.\n\nCome for the curiosity, stay for the challenge. You might just unlock a new obsession.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "L9BFYP", "name": "Volunteers", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/FYKFVH_Fz6KAh3.webp", "biography": "BSides Canberra is entirely volunteer-run, with around 40 dedicated volunteers who contribute both before and during the event. Volunteers can be easily identified by their maroon t-shirts.", "public_name": "Volunteers", "guid": "36a8643c-eada-5b68-8d2f-610966fefbd9", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/L9BFYP/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ESQF9W/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ESQF9W/", "attachments": []}], "Locksport Village - Physical Challenge": [{"guid": "c241237e-f91d-5e40-867e-f6513d853c0f", "code": "UWEBSR", "id": 95309, "logo": "https://cfp.bsidescbr.com.au/media/bsides-canberra-2026/submissions/UWEBSR/image_5Hl5Zcd.jpg", "date": "2026-09-25T09:30:00+10:00", "start": "09:30", "end": "2026-09-25T16:30:00+10:00", "duration": "07:00", "room": "Locksport Village - Physical Challenge", "slug": "bsides-canberra-2026-95309-black-box-zero-physical-challenge-box", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UWEBSR/", "title": "Black Box Zero - Physical Challenge Box", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "Hello! Black Box Zero is a three stage physical challenge box that gets participants to solve ciphers, hack webapps, and learn to read/write NFC tags to unlock the final box. The brains are driven by a Raspberry Pi 4 that controls the webapp, hotspot, NFC reader, lights, and sounds. Suitable for someone with beginner/intermediate hacking/cybersecurity know how, but all skill levels are encouraged.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "P9FYS3", "name": "Nathan Cobbald and Bayley Skerman", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/YNYWUX_7iTwXWu.webp", "biography": "Amateur 'putting stuff in a box and making it do things'-ers . By two people who work together sometimes", "public_name": "Nathan Cobbald and Bayley Skerman", "guid": "7facde10-48fb-59da-9d9e-0399649cd84c", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/P9FYS3/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UWEBSR/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UWEBSR/", "attachments": []}], "Hardware Village": [{"guid": "1be9a067-80e5-5fca-ae51-7a2c70295069", "code": "CGFLPS", "id": 103045, "logo": null, "date": "2026-09-25T09:00:00+10:00", "start": "09:00", "end": "2026-09-25T16:00:00+10:00", "duration": "07:00", "room": "Hardware Village", "slug": "bsides-canberra-2026-103045-hardware-village-day-two", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CGFLPS/", "title": "Hardware Village (Day Two)", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "Step away from the keyboard \u2013 it\u2019s time to get hands-on. Whether you're a seasoned tinkerer or just curious about what\u2019s inside your badge, the Hardware Village is your space to learn, hack, solder, and explore.\n\nWe\u2019ll have soldering stations ready for badge mods and hardware experiments, plus friendly experts on hand to help with troubleshooting or inspiration. Bring your gear or just swing by to see what others are building and tinkering with.\n\nThere\u2019s always something to learn, create, or break (safely, of course).", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "L9BFYP", "name": "Volunteers", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/FYKFVH_Fz6KAh3.webp", "biography": "BSides Canberra is entirely volunteer-run, with around 40 dedicated volunteers who contribute both before and during the event. Volunteers can be easily identified by their maroon t-shirts.", "public_name": "Volunteers", "guid": "36a8643c-eada-5b68-8d2f-610966fefbd9", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/L9BFYP/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CGFLPS/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CGFLPS/", "attachments": []}]}}, {"index": 3, "date": "2026-09-26", "day_start": "2026-09-26T04:00:00+10:00", "day_end": "2026-09-27T03:59:00+10:00", "rooms": {"Main Track": [{"guid": "4f2cbd16-8845-554d-b1a4-cfe07efd0f86", "code": "C7HSRZ", "id": 102973, "logo": null, "date": "2026-09-26T09:10:00+10:00", "start": "09:10", "end": "2026-09-26T09:50:00+10:00", "duration": "00:40", "room": "Main Track", "slug": "bsides-canberra-2026-102973-saturday-keynote-tba", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/C7HSRZ/", "title": "Saturday Keynote - TBA", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "TBA", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/C7HSRZ/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/C7HSRZ/", "attachments": []}, {"guid": "ddaa4974-688b-5db3-a852-06d20e80b126", "code": "88SUTA", "id": 102269, "logo": null, "date": "2026-09-26T10:00:00+10:00", "start": "10:00", "end": "2026-09-26T10:55:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-102269-javascript-pwn-a-field-guide-to-hacking-servicenow", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/88SUTA/", "title": "javascript:pwn() - A Field Guide to Hacking ServiceNow", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "ServiceNow is at the center of workflows and platform integrations for roughly 85% of enterprises - yet it rarely charts high as a priority in the pentesting backlog. Instances are generally put togther by \"no-code / low-code\" citizen developers who rarely have a software-engineering background. Combine all of this with the fact they are tinkering with a 20 year old monolith to plumb together some of your organisations most sensitive data - and you have an incredibly bespoke attack surface, unique to every org.\n\nThis talk is a field guide to attacking that surface, how to navigate and dissect a ServiceNow instance to review the custom code and components for critical vulnerabilities. Covering insecure patterns that lead to unauthorized data access, privilege escalation, and even arbitrary code execution. \n\nWhile this talk isn't aimed at identifying platform level bugs, it reviews CVE-2026-0542, a critical unauthenticated arbitrary code execution vulberabiltiy discovered using the same techniques. This vulnerability was present in default components written by ServiceNow that affected every instance - and the deep dive reveals why customer instances could still harbor their own versions of this.\n\nDefenders leave knowing their actual attack surface and how to reduce it, what to audit in custom code, enabling better logging and monitoring, and awareness of a reporting gap between ServiceNow's own CVEs versus the advisories that go straight to customers \u2014 including a public CVE record that still reads \"fixed\" for a bug class only truly closed by patches much later. \n\nSince most customers get exactly one self-run pentest per calendar year, the goal of this talk is to leave you able to make that one shot really count.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "DWNGSG", "name": "Paul Alkemade", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/EZXTB9_GOQNiWE.webp", "biography": "I'm an offensive security engineer based in Melbourne we're I've been hacking away for over six years. When I'm not staring at a computer screen I'm probably stuck out bush trying not to stare at my phone.", "public_name": "Paul Alkemade", "guid": "e67777cd-a860-574f-968b-9429fc43c56f", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/DWNGSG/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/88SUTA/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/88SUTA/", "attachments": []}, {"guid": "6cea04cc-2723-5a7d-b0da-aaba9c55cda3", "code": "V3BXU8", "id": 102061, "logo": null, "date": "2026-09-26T11:00:00+10:00", "start": "11:00", "end": "2026-09-26T11:55:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-102061-ocularce-from-bluetooth-to-contactor", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/V3BXU8/", "title": "OculaRCE: From Bluetooth to Contactor", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "A full-stack teardown of a commercial EV charger, from default credentials in the installation guide through to unauthenticated control of the AC power contactors.\n\nThis research covers multiple pre-auth RCE vulnerabilities including a Bluetooth attack requiring no network access, an unauthenticated manufacturing test mode that bypasses every safety interlock on the charger, and a design flaw that puts all safety mechanisms in a single Linux process with no independent hardware verification.\n\nThe affected firmware platform is used by multiple resellers globally. A single broadcast UDP packet can disable ground fault protection across an entire fleet.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "89LC9R", "name": "Brendan Scarvell", "avatar": null, "biography": "Brendan is a security researcher and co-founder of Signal 11, with a background spanning web application, network, hardware, and embedded device security. His work focuses on finding and exploiting vulnerabilities in real-world systems, with a particular interest in connected devices and the security risks created when consumer and business infrastructure overlap.", "public_name": "Brendan Scarvell", "guid": "aaa053f8-c4d6-53bc-a96e-b1ca83226506", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/89LC9R/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/V3BXU8/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/V3BXU8/", "attachments": []}, {"guid": "4252d3cc-528a-5fbb-ba6a-6c1559a61e41", "code": "LUJCEL", "id": 101158, "logo": null, "date": "2026-09-26T12:00:00+10:00", "start": "12:00", "end": "2026-09-26T12:25:00+10:00", "duration": "00:25", "room": "Main Track", "slug": "bsides-canberra-2026-101158-waffling-around-wafs", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LUJCEL/", "title": "Waffling Around WAFs", "subtitle": "", "track": "Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "Collecting data from the game of Pokemon Go involves bulk creation of game accounts. In order to combat bots and other abusers of the game, cloud WAFs are used to prevent mass account sign-ups. This talk outlines some cheap techniques that can be used to bypass anti-bot measures employed by Imperva and other similar security platforms.", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "GLCFYS", "name": "Aeriana Lawler", "avatar": null, "biography": "Aeri is a Linux sysadmin who these days [unfortunately] works in cyber security policy and auditing. In between making biltong and hiking around Namadgi, she likes to level the playing field in Pokemon Go by developing tools to annoy spoofers in the game.", "public_name": "Aeriana Lawler", "guid": "eb479d21-f41d-53e2-aad8-8d1fe1e137dd", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/GLCFYS/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LUJCEL/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LUJCEL/", "attachments": []}, {"guid": "2813f4d4-0d7f-5fc8-a913-a2dae7503eb5", "code": "CWMDP3", "id": 102227, "logo": "https://cfp.bsidescbr.com.au/media/bsides-canberra-2026/submissions/CWMDP3/image_RZskqNQ.webp", "date": "2026-09-26T13:30:00+10:00", "start": "13:30", "end": "2026-09-26T13:55:00+10:00", "duration": "00:25", "room": "Main Track", "slug": "bsides-canberra-2026-102227-finding-vibe-leaked-api-keys-every-day", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWMDP3/", "title": "Finding vibe leaked API keys every day", "subtitle": "", "track": "Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "\u201cWait hang on if everyone\u2019s vibe coding I bet they\u2019re accidentally leaking soooooo many API keys like, publicly. And they don\u2019t even know\u201d, is what I thought one day.\n\n\u201cBut *how* bad is it?\u201d I had to know, so I tried scanning newly registered domain names every day.\n\nThis talk is the story of how I found myself drowning in poor vibe coders\u2019 diverse selection of API keys, and, um, how anyone could \ud83d\ude33. I tried to measure how easy it was to find actual, valid API keys on new, presumably vibe coded websites.\n\nI have, in my travels, calculated various numbers, such as the average time it takes for a valid API key to be leaked after a domain is registered. There will be a thrilling analysis of today\u2019s results, so please nobody vibe code too hard the day before.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "PGEZFM", "name": "\"Alex\"", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/Y3XRXL_a5iCWu4.webp", "biography": "\u201cAlex\u201d (mangopdf) has hacked their employer an unspecified number of times Red Teaming, committing metaphorical crimes and writing really really detailed confession letters. Once they found former Australian Prime Minister Tony Abbott\u2019s passport number using Google Chrome, talked to him on the phone about it, and did not get arrested. They just started mangopdf Communication, a legitimate business in which they teach security people how to present and write in a way that non-security people understand.\n\nOn the side, they organise purplecon, a gentle, pastel, inclusive security conference, but it\u2019s unclear whether the whole thing is like a joke, or what.\nMore \"Alex\" content, blog posts, and past conference talk recordings: https://mango.pdf.zone.", "public_name": "\"Alex\"", "guid": "a74513f0-135d-5091-8ffc-f51e4358cc21", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/PGEZFM/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWMDP3/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWMDP3/", "attachments": []}, {"guid": "60134fdc-8797-5802-946b-0826c58142e6", "code": "UGYDQS", "id": 100985, "logo": null, "date": "2026-09-26T15:15:00+10:00", "start": "15:15", "end": "2026-09-26T16:10:00+10:00", "duration": "00:55", "room": "Main Track", "slug": "bsides-canberra-2026-100985-headless-hunter-automated-exploitation-of-headless-chrome-using-v8-n-days", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UGYDQS/", "title": "Headless Hunter - Automated exploitation of headless Chrome using V8 n-days", "subtitle": "", "track": "Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Consider a website. One that allows you to export PDF documents. Have you ever stopped to wonder how this works under the hood?\n\nCommercial libraries exist to do the PDF generation heavy lifting, but as they can be quite costly, I wasn\u2019t surprised to see developers reaching for Chrome\u2019s \u201cPrint to PDF\u201d functionality. What did surprise me was web applications not having up to date Chrome builds in their NPM dependencies, developers reaching for --no-sandbox rather than fiddling with Docker and Kubernetes security knobs, and web apps that allowed me to provide custom (and malicious) HTML and JavaScript for conversion to PDF.\n\nAll of this inspired me to look into Chrome\u2019s JavaScript engine, V8, to exploit these PDF generators. Chrome\u2019s issue tracker documents many patched vulnerabilities that work on old Chrome versions, which is perfect for my use case. The main challenge was that the exploits and techniques vary depending on the target Chrome version, so I wondered, why not make a tool with enough exploits to cover all of them?\n\nIn this talk I outline my journey for developing the tool, the design decisions I made, the problems that I overcame, and the lessons I learned along the way. The result is a single web page that can exploit 24 common Chrome versions (and counting) for remote code execution using V8 memory corruption.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "TUEZLR", "name": "Daniel Cooper", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/K8ZTSB_fkCDlxw.webp", "biography": "Daniel Cooper is a Security Consultant at Tanto Security. He is interested in security research in areas such as web security, binary exploitation, and more recently, Microsoft Windows. He also enjoys playing in the occasional CTF.", "public_name": "Daniel Cooper", "guid": "a835f8e8-515f-5cf7-91b5-2b65db7bd17b", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/TUEZLR/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UGYDQS/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UGYDQS/", "attachments": []}], "Off-Main Track": [{"guid": "722be904-4448-565e-80c8-ac459427697e", "code": "YXN8DD", "id": 102372, "logo": null, "date": "2026-09-26T10:00:00+10:00", "start": "10:00", "end": "2026-09-26T10:55:00+10:00", "duration": "00:55", "room": "Off-Main Track", "slug": "bsides-canberra-2026-102372-you-get-a-c2-and-you-get-a-c2-the-democratisation-of-sophisticated-command-control", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YXN8DD/", "title": "You Get a C2! And YOU Get a C2!: The democratisation of sophisticated Command & Control", "subtitle": "", "track": "Off-Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "Sophisticated espionage focused Command and Control (C2) frameworks and offensive cyber tooling has been historically restricted to use by large powers and developed economies due to the high cost or lack of turn key solutions offered by open source. At the end of the day these platforms are just software suites built to strict and specialised requirements. \n\nLLMs through shifts in software development methodologies have become commonplace in enterprise software development life cycles and have lowered the barriers of the cost, maintainability and flexibility issues plaguing legacy offensive tooling. \n\nIn this talk we will explore several frameworks that have been captured from the front lines to see first hand how actual APTs are building and breaking sophisticated C2 frameworks to prompt their way to success. \n\nWe will explore the spec driven approaches that produce robust and battle ready tooling without guess work, review examples of development artifacts, documentation and prompts from a mistakenly exposed VoidLinkC2 development server and pass these lessons on to any budding red teamers wanting to replicate this success. \n\nDefenders and researchers need not worry - we will also discuss our lessons learned through researching AI built frameworks and what this means for the way we track and react to these threats in the future.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "APJRYM", "name": "Joseph Ganter", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/M8NGQZ_Wdd8qBE.webp", "biography": "Joseph is a Threat Hunter and Researcher with Palo Alto's Unit 42 working in the intrusion intelligence cell. He has had a diverse set experience across the government and private sectors working in incident response, penetration testing and threat hunting for nearly a decade.", "public_name": "Joseph Ganter", "guid": "5dd9c818-71c0-5693-8961-b0e60d7da425", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/APJRYM/"}, {"code": "A7ULTB", "name": "Tom Marsden", "avatar": null, "biography": "TBA", "public_name": "Tom Marsden", "guid": "f6061c16-3b44-5809-9bbc-f7a7ae5d80f4", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/A7ULTB/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YXN8DD/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YXN8DD/", "attachments": []}, {"guid": "b26ae62e-da73-5378-a6a7-af8235cc4c33", "code": "CNKXQT", "id": 99192, "logo": "https://cfp.bsidescbr.com.au/media/bsides-canberra-2026/submissions/CNKXQT/image_Mjuiymm.webp", "date": "2026-09-26T11:00:00+10:00", "start": "11:00", "end": "2026-09-26T11:25:00+10:00", "duration": "00:25", "room": "Off-Main Track", "slug": "bsides-canberra-2026-99192-malicious-entra-id-apps-what-they-are-how-to-find-them-and-how-to-stop-them", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CNKXQT/", "title": "Malicious Entra ID Apps - what they are, how to find them and how to stop them", "subtitle": "", "track": "Off-Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "We've all heard of password guessing and MFA bypass techniques that are used to attack M365 - but those are old news now! The newer and more interesting vector - to both attackers and defender alike - are malicious Entra ID (formerly Azure AD) apps. In this presentation I'll explain what Entra ID apps are (and what makes some malicious), how attackers trick users/victims into registering them, how you can find any that may already be in your environment, and what you can do to stop more in the future.\n\nThis presentation is designed for technical audiences (or those wanting to become technical) to understand an emerging vector and what can be done to defend against them. The content is based on both our firsthand experience (as both attackers and defenders) as well as that from our partners.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "AB7ENY", "name": "Sam Brazier-Hollins", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/CDYBVP_CwUdsF3.webp", "biography": "Sam is a Microsoft MVP for M365 and Copilot - and therefore has spent more time in the consoles than anyone should... When he isn't, he leads the Technical Consulting team at Fujitsu Cyber which includes  both the technical testing team (that attempts to break in) and the professional services team (that attempt to stop the break-ins). \n\nSam was one of the original authors of the Digital Transformation Agency (DTA) Protected Utility Blueprint for Microsoft 365 (M365), Sam has more experience than most with how to balance usability and collaboration with the evolving nature of cyber security threats.", "public_name": "Sam Brazier-Hollins", "guid": "36ef18a0-a7e5-5260-9f66-a7f45317b156", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/AB7ENY/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CNKXQT/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CNKXQT/", "attachments": []}, {"guid": "09d96765-7b9d-5af8-b949-a33e30b56107", "code": "YUZAQX", "id": 101849, "logo": null, "date": "2026-09-26T11:30:00+10:00", "start": "11:30", "end": "2026-09-26T11:55:00+10:00", "duration": "00:25", "room": "Off-Main Track", "slug": "bsides-canberra-2026-101849-venting-steam-hunting-c2-in-unexpected-places", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YUZAQX/", "title": "Venting Steam: Hunting C2 in Unexpected Places", "subtitle": "", "track": "Off-Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "If the Lumma and Vidar stealers taught us one thing, it's that literally anything can be used as a Command and Control channel. DNS TXT records, Pastebin drops, Steam profiles, telegram, discord - if it can carry a string, it can carry instructions.\nThis talk takes a blue team lens to the unconventional C2 landscape. We'll explore how platforms such as Steam and a handful of other legitimate services, are being quietly abused for command delivery and exfiltration. Hiding in plain sight behind trusted domains and allowlisted traffic. No blocked ports, no suspicious destinations, no alerts.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "NSX7ER", "name": "Mike Vriesema", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/HKSPJE_xtds8Tb.webp", "biography": "Mike is a Primary Technical Investigator in Accenture's Global Cyber Response team, leading end-to-end DFIR engagements across large-scale cyber incidents worldwide. With over five years at Accenture and a First Class Honours degree in Cyber Security & IT Forensics from the University of Limerick, he brings deep expertise in incident response and threat intelligence. Mike is a GIAC Advisory Board member and holds certifications including CISSP, GCFA, and GX-FA (and a bunch of other alphabet soup).", "public_name": "Mike Vriesema", "guid": "f79f01b8-95df-5eb0-8420-aa2ff2090f81", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/NSX7ER/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YUZAQX/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YUZAQX/", "attachments": []}, {"guid": "fb58b196-2191-57f0-9cab-344d5be83ce2", "code": "ASV3UJ", "id": 102368, "logo": null, "date": "2026-09-26T12:00:00+10:00", "start": "12:00", "end": "2026-09-26T12:25:00+10:00", "duration": "00:25", "room": "Off-Main Track", "slug": "bsides-canberra-2026-102368-identity-is-the-new-soc-hunting-entra-scim-pim-and-password-manager-abuse", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ASV3UJ/", "title": "Identity Is the New SOC: Hunting Entra, SCIM, PIM, and Password Manager Abuse", "subtitle": "", "track": "Off-Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "Identity used to be the front door. Now it is the keys, the key cabinet, the floor plan, the alarm panel, and sometimes the weird emergency exit nobody has checked since 2021. \n\nMost organisations have put serious effort into endpoint alerts, phishing workflows, firewall rules, and dashboards. But the thing that quietly decides who can access almost everything is often treated as setup work: turn on MFA, plug in SSO, add Conditional Access, connect SCIM, move on. \n\nThat is fine until someone uses a break-glass account, a privileged role lights up, a password manager owner gets added, a Conditional Access exclusion becomes the easiest path in, or SCIM decides to \"help\" by removing the wrong person from the wrong place. \n\nThis talk is about hunting the identity control plane before it becomes an incident. We will walk through realistic Entra, SCIM, PIM, and password-manager failure modes, then turn those messy admin events into useful detections, triage paths, and response actions. \n\nExpect practical examples, awkward edge cases, noisy logs, bad assumptions, and the occasional reminder that \"we logged it somewhere\" is not the same thing as \"someone can respond to it at 2am.\"", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "3GBKZN", "name": "Maple", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/DYGNEG_Pg2a9xO.webp", "biography": "Maple Fox is a Melbourne-based security engineer, researcher, and community organiser working across cloud and platform security, identity-first design, Zero Trust, SIEM/SOAR, security automation, and critical infrastructure cyber security.\n\nMaple works hands-on with Microsoft Entra, Azure, AWS, Sentinel, Intune, Terraform, Go, Python, SAML/OIDC, FIDO2, firewall integrations, and secure access patterns. Their work spans identity baselines, detection engineering, secure cloud guardrails, Zero Trust access orchestration, and practical security evidence for audit and uplift programmes.\n\nMaple is currently completing a Master of Cyber Security at Deakin University, with research focused on machine-readable security intent, policy compilation, and bounded reachability verification. They also have practical experience supporting SOCI- and AEMO-focused cyber security gap assessments for critical infrastructure and OT environments, including SCADA, communications, remote access, BESS-style infrastructure, and OT/cloud boundary controls.\n\nAlongside industry work, Maple teaches cyber security at Deakin University and contributes heavily to the Australian cyber community. They founded Deakin University Cybersecurity Association, helped scale it into a large student community, and co-chair ACUCyS, supporting collaboration across Australian university cyber clubs.\n\nMaple likes building practical labs, tools, diagrams, demos, and repeatable methods that turn security ideas into evidence. Their current interests include secure OT connectivity, identity-aware access control, Zero Trust engineering, detection-as-code, and proving when \"policy\" actually matches what systems can reach.", "public_name": "Maple", "guid": "2f2eaf85-1bad-5127-8e20-55419800b744", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/3GBKZN/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ASV3UJ/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ASV3UJ/", "attachments": []}, {"guid": "bbad5c11-292b-51d8-8176-b258db401069", "code": "UHLRLX", "id": 102046, "logo": null, "date": "2026-09-26T13:30:00+10:00", "start": "13:30", "end": "2026-09-26T13:55:00+10:00", "duration": "00:25", "room": "Off-Main Track", "slug": "bsides-canberra-2026-102046-api-key-attribution-sucks-lets-change-that", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UHLRLX/", "title": "API Key Attribution Sucks, Lets Change That", "subtitle": "", "track": "Off-Main Track", "type": "25 Mins (including questions)", "language": "en", "abstract": "When a secret is leaked most people look at who leaked the secret; the GitHub committers email, package author, but this sucks. Millions of commits are created by noreply emails, clankers and personal emails with no attribution back to your org at all.\n\nWe analysed hundreds of thousands of live, verified credentials with a new method of attribution, API calls to dynamically fetch ownership information. What we found will change the way you think about secret detection and remediation. \n\nUsing this methodology we were able to achieve attribution at scale, uncovering contextless keys that had access to medical devices, defense equipment and some of the most popular software packages ever (GnuTLS, OpenConnect), KYC databases and much more.\n\nThis session discusses:\nWhy attribution in its current form is broken\nThe challenges of attribution at scale\nWhat our methodology looks like\nCase studies of our findings", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "8N7U8F", "name": "Luke Marshall", "avatar": null, "biography": "Luke Marshall is a Security Researcher at Truffle Security specialising in the discovery of exposed secrets and supply chain vulnerabilities. Formerly a Security Engineer at Bugcrowd, Luke focuses on research in massive public ecosystems to uncover novel attack vectors. He is a dedicated proponent of responsible disclosure and digging into large datasets to uncover hidden security gaps and systemic risks that often go unnoticed.", "public_name": "Luke Marshall", "guid": "d7d50aca-e95e-5620-94ef-68a71d4e1305", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/8N7U8F/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UHLRLX/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UHLRLX/", "attachments": []}, {"guid": "159d568c-99c7-565a-a6e0-058821772fe4", "code": "TN98SC", "id": 95829, "logo": null, "date": "2026-09-26T14:00:00+10:00", "start": "14:00", "end": "2026-09-26T14:55:00+10:00", "duration": "00:55", "room": "Off-Main Track", "slug": "bsides-canberra-2026-95829-just-spoof-the-government", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/TN98SC/", "title": "Just spoof the government?", "subtitle": "", "track": "Off-Main Track", "type": "55 minutes (including questions)", "language": "en", "abstract": "During an authorised social engineering engagement for a state government department, email security flaws were identified which led to successful target interaction with \u201cmalicious\u201d infrastructure.\n\nWith the engagement a success, the question was raised; where else can these email security flaws be found across the gov.au domain, and can we 'just spoof the government?'", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "YVVPA7", "name": "Ben\u2122", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/UH3L3J_YN60Yvh.webp", "biography": "Ben\u2122 is an Offensive Security Consultant with a diverse background in Information Technology and Education. Since transitioning from teaching and vocational education governance, he has conducted various offensive security engagements, including penetration testing and adversary simulation. Ben\u2122 has experience conducting testing across external applications and services, internal and cloud-based corporate networks, as well as specialist experience in various forms of social engineering.\n\nHe operates under the assumption that snacks improve all outcomes, brings a methodical approach to chaos and a chaotic approach to method, and quietly wonders why people insist on paying him for something he\u2019d likely do for free.", "public_name": "Ben\u2122", "guid": "9a33e2d6-04e4-5aca-a1d7-564a8562a6b7", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/YVVPA7/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/TN98SC/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/TN98SC/", "attachments": []}], "Exhibition Hall": [{"guid": "2c0e9ea7-06a7-5785-adee-19af8e481586", "code": "RMC8LB", "id": 102975, "logo": null, "date": "2026-09-26T09:00:00+10:00", "start": "09:00", "end": "2026-09-26T15:00:00+10:00", "duration": "06:00", "room": "Exhibition Hall", "slug": "bsides-canberra-2026-102975-capture-the-flag-day-two", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/RMC8LB/", "title": "Capture-the-Flag (Day Two)", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "CALLING ALL HACKERS, GAMERS, PUZZLE SOLVERS, CRYPTO NERDS, PWN ENJOYERS, REVERSERS, AND CURIOUS NEWCOMERS.\n\nAfter an incredible debut at BSides Canberra 2025, Skateboarding Dog returns with an all-new Capture the Flag competition featuring fresh challenges, new ideas, and plenty of opportunities to test your skills.\n\nExpect all the classic categories: Crypto, Pwn, Reverse Engineering, Web, and more. Alongside the weird, creative, and unexpected challenges you've come to expect from Skateboarding Dog.\n\nWhether you're tackling your very first CTF or you're a seasoned competitor chasing the top of the leaderboard, there's something here for everyone.\n\nBring your laptop, bring your team, and see if you have what it takes to claim the trophy.\n\nPrizes to be announced.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "9GCRLS", "name": "skateboarding dog", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/UWXEJY_viSHwMX.webp", "biography": "After an outstanding debut as CTF hosts in 2025, skateboarding dog are back to design and run the BSides Canberra CTF for a second year.\n\nThey're not just any CTF team, they're one of Australia's most accomplished. A powerhouse of talented hackers, this team has dominated the local CTF scene for years, consistently finishing at the top of competitions around the country. Before taking over as hosts, they claimed first place in the BSides Canberra CTF for three consecutive years.\n\nKnown for deep technical expertise, creative exploitation techniques, and exceptionally well-crafted challenges, skateboarding dog has earned a reputation for building CTFs that are approachable for newcomers while still pushing seasoned players to their limits. If last year's competition was anything to go by, you're in for another fantastic weekend of hacking.\n\nWhether you're chasing the podium or tackling your very first challenge, the BSides Canberra 2026 CTF promises another memorable experience with skateboarding dog at the helm.\n\nFollow them on X: [https://x.com/sk8boardingdog](https://x.com/sk8boardingdog)", "public_name": "skateboarding dog", "guid": "2e6415f9-18c2-548b-858d-3e2a379706b2", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/9GCRLS/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/RMC8LB/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/RMC8LB/", "attachments": []}], "Murray-Fitzroy Room": [{"guid": "a2459efb-180d-5f46-b030-5aefb14d8c3b", "code": "VVRUFE", "id": 96294, "logo": "https://cfp.bsidescbr.com.au/media/bsides-canberra-2026/submissions/VVRUFE/image_et3hexz.webp", "date": "2026-09-26T09:00:00+10:00", "start": "09:00", "end": "2026-09-26T15:30:00+10:00", "duration": "06:30", "room": "Murray-Fitzroy Room", "slug": "bsides-canberra-2026-96294-software-supply-chain-threat-intelligence-hands-on-training-for-secops-and-threat-hunting-teams", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VVRUFE/", "title": "Software Supply Chain Threat Intelligence: Hands-On Training for SecOps and Threat Hunting Teams", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "Software supply chain attacks have become one of the most significant threats to organizations, with nation-state actors like DPRK's Lazarus Group actively compromising NPM packages, PyPI libraries, GitHub repositories, and VS Code extensions to target developers and steal credentials, cryptocurrency, and source code. This all-day hands-on training equips SecOps and threat hunting teams with practical skills to detect, analyze, and extract actionable threat intelligence from real-world supply chain malware\u2014turning raw malware samples into finished intelligence products.\n\nParticipants will work directly with sanitized samples from active campaigns including Contagious Interview, PolinRider (DPRK), and Glassworm (Russia), analyzing malicious artifacts across four major attack surfaces: NPM, PyPI, GitHub, and VS Code extensions. Beyond technical analysis, attendees will learn about Paul's custom software supply chain CTI workflow: extracting IOCs, pivoting across infrastructure to identify campaign scope, attributing activity to threat actors, producing actionable reports, and alerting the community to the threats you expose. The training culminates with a 90-minute live hunting CTF-style session where participants apply their new skills to hunt for real threats and document findings using professional intelligence standards", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "EJD3TM", "name": "Paul McCarty", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/G39HJA_ENb3gyr.webp", "biography": "Paul is a serial startup found and a true hacker OG.  He created [OpenSourceMalware.com](http://OpenSourceMalware.com), the worlds largest open database and collaboration platform for software supply chain threat intel.  Paul delivers software supply chain offensive security training and engagements globally and speaks at many security conferences and hacker meetups.  He's spent many years hacking NPM and PyPI, and has made several discoveries about the ecosystem.  Paul founded multiple startups starting in the '90s and has worked for NASA, Boeing, Blue Cross/Blue Shield, John Deere, the US military, the Australian government. \u00a0Paul is a frequent open-source contributor and author of several DevSecOps, software supply chain and threat modelling projects. He\u2019s currently writing a book entitled \u201cHacking NPM\u201d, and when he\u2019s not doing that, he\u2019s snowboarding with his wife and 3 amazing kids.", "public_name": "Paul McCarty", "guid": "91a9befb-325c-528a-809d-cce6b8cb76e8", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/EJD3TM/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VVRUFE/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VVRUFE/", "attachments": []}], "Derwent Room": [{"guid": "05f4bf33-6644-5be6-96bf-912ad16252b8", "code": "JBCGY7", "id": 102990, "logo": null, "date": "2026-09-26T09:00:00+10:00", "start": "09:00", "end": "2026-09-26T15:00:00+10:00", "duration": "06:00", "room": "Derwent Room", "slug": "bsides-canberra-2026-102990-black-bag-day-3", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/JBCGY7/", "title": "Black Bag - Day 3", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "The Black Bag is returning to BSides Canberra 2026. More details coming soon.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "GRHHVD", "name": "TBA", "avatar": null, "biography": null, "public_name": "TBA", "guid": "711291c1-2dec-5716-92cf-5c928d0b46a8", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/GRHHVD/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/JBCGY7/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/JBCGY7/", "attachments": []}], "Locksport Village": [{"guid": "a15be23a-2024-5042-acfe-aba5fbe324ee", "code": "VDNHNZ", "id": 103043, "logo": null, "date": "2026-09-26T09:00:00+10:00", "start": "09:00", "end": "2026-09-26T15:30:00+10:00", "duration": "06:30", "room": "Locksport Village", "slug": "bsides-canberra-2026-103043-locksport-day-3", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VDNHNZ/", "title": "Locksport (Day 3)", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "The Locksport village is your gateway into the fascinating world of physical security. Whether you're a total newcomer or a seasoned picker, there's something here for everyone.\n\nExplore a wide variety of locks, pick tools, and hands-on challenges \u2013 all under the guidance of experienced instructors ready to share their tips and tricks. Learn how locks work, discover their vulnerabilities, and test your skills on locks ranging from beginner to expert difficulty.\n\nThis isn\u2019t just a display \u2013 it\u2019s a fully interactive experience. Step into the shoes of a lockpicker, challenge yourself, and maybe even surprise yourself with a hidden knack for tumblers and tension wrenches.\n\nCome for the curiosity, stay for the challenge. You might just unlock a new obsession.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "L9BFYP", "name": "Volunteers", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/FYKFVH_Fz6KAh3.webp", "biography": "BSides Canberra is entirely volunteer-run, with around 40 dedicated volunteers who contribute both before and during the event. Volunteers can be easily identified by their maroon t-shirts.", "public_name": "Volunteers", "guid": "36a8643c-eada-5b68-8d2f-610966fefbd9", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/L9BFYP/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VDNHNZ/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VDNHNZ/", "attachments": []}], "Hardware Village": [{"guid": "315e15d6-098d-594a-bedd-54ea18a9abfa", "code": "ES8WKY", "id": 103046, "logo": null, "date": "2026-09-26T09:00:00+10:00", "start": "09:00", "end": "2026-09-26T15:30:00+10:00", "duration": "06:30", "room": "Hardware Village", "slug": "bsides-canberra-2026-103046-hardware-village-day-three", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ES8WKY/", "title": "Hardware Village (Day Three)", "subtitle": "", "track": "Event Track", "type": "Event", "language": "en", "abstract": "Step away from the keyboard \u2013 it\u2019s time to get hands-on. Whether you're a seasoned tinkerer or just curious about what\u2019s inside your badge, the Hardware Village is your space to learn, hack, solder, and explore.\n\nWe\u2019ll have soldering stations ready for badge mods and hardware experiments, plus friendly experts on hand to help with troubleshooting or inspiration. Bring your gear or just swing by to see what others are building and tinkering with.\n\nThere\u2019s always something to learn, create, or break (safely, of course).", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "L9BFYP", "name": "Volunteers", "avatar": "https://cfp.bsidescbr.com.au/media/avatars/FYKFVH_Fz6KAh3.webp", "biography": "BSides Canberra is entirely volunteer-run, with around 40 dedicated volunteers who contribute both before and during the event. Volunteers can be easily identified by their maroon t-shirts.", "public_name": "Volunteers", "guid": "36a8643c-eada-5b68-8d2f-610966fefbd9", "url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/speaker/L9BFYP/"}], "links": [], "feedback_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ES8WKY/feedback/", "origin_url": "https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ES8WKY/", "attachments": []}]}}]}}}