<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2026.3.0.dev0. -->
<schedule>
    <generator name="pretalx" system="cfp.bsidescbr.com.au" version="2026.3.0.dev0" />
    <version>0.22</version>
    <conference>
        <title>BSides Canberra 2026</title>
        <acronym>bsides-canberra-2026</acronym>
        <start>2026-09-24</start>
        <end>2026-09-26</end>
        <days>3</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://cfp.bsidescbr.com.au</base_url>
        
        <time_zone_name>Australia/Sydney</time_zone_name>
        
        
        <track name="Off-Main Track" slug="6989-off-main-track"  color="#05a0c7" />
        
        <track name="Main Track" slug="6990-main-track"  color="#b34e15" />
        
        <track name="Event Track" slug="6991-event-track"  color="#1632ab" />
        
        <track name="Careers Village" slug="6992-careers-village"  color="#0df785" />
        
        <track name="BSidesCbr 101" slug="6993-bsidescbr-101"  color="#e027df" />
        
    </conference>
    <day index='1' date='2026-09-24' start='2026-09-24T04:00:00+10:00' end='2026-09-25T03:59:00+10:00'>
        <room name='Main Track' guid='4a29fef6-5675-517c-a556-262557f4f117'>
            <event guid='bf3ee52b-93ca-5dff-8bfe-7b0b7938adf2' id='102970' code='UPZFD7'>
                <room>Main Track</room>
                <title>Opening Ceremony</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-24T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>00:10</duration>
                <abstract>Welcome to BSides Canberra 2026!

Join us as we kick off another year of Australia&apos;s largest hacker conference. In this opening session, we&apos;ll welcome you to BSides Canberra, introduce this year&apos;s event, and share what&apos;s in store over the next three days.

We&apos;ll highlight this year&apos;s program, cover important announcements, and run through everything you need to know to make the most of the conference. Whether you&apos;re here to learn from world-class speakers, compete in the CTFs, explore the villages, discover new research, or connect with the community, we&apos;re thrilled to have you with us.

Let&apos;s get BSides Canberra 2026 underway.</abstract>
                <slug>bsides-canberra-2026-102970-opening-ceremony</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='101986'>Kylie McDevitt</person><person id='101987'>Dr Silvio Cesare</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UPZFD7/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UPZFD7/feedback/</feedback_url>
            </event>
            <event guid='cf96e2db-423a-54e3-9caf-659ecfd123c1' id='102971' code='VZENQH'>
                <room>Main Track</room>
                <title>Thursday Keynote - TBA</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-24T09:10:00+10:00</date>
                <start>09:10</start>
                <duration>00:40</duration>
                <abstract>TBA</abstract>
                <slug>bsides-canberra-2026-102971-thursday-keynote-tba</slug>
                <track>Main Track</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VZENQH/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VZENQH/feedback/</feedback_url>
            </event>
            <event guid='07903407-5199-5057-abe3-1ae646a05d93' id='102546' code='8FNRMJ'>
                <room>Main Track</room>
                <title>Viral Vulnerabilities: Unpacking Copy.Fail and related Linux Kernel bugs</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-24T11:00:00+10:00</date>
                <start>11:00</start>
                <duration>00:55</duration>
                <abstract>Copy.Fail (CVE-2026-31431), a critical Linux kernel bug found by researchers at Theori, quickly rose to prominence after its public disclosure in April 2026. Discussion was fuelled by a 732-byte Python exploit script that anybody can run; a dedicated disclosure website with glaring mistakes; and the lack of security patches in some major distros upon release. In the following weeks, variant bugs named Dirty Frag (CVE-2026-43284/CVE-2026-43500) and Fragnesia (CVE-2026-46300) were discovered, starting further conversations about the future role of AI in vulnerability discovery.

In this talk, I break down the Copy.Fail bug and exploit, hoping to explain them in a way that is understandable even if you haven&#8217;t looked at the Linux Kernel source before. We will take a look at how they work, how the bugs were patched and mitigated, related vulnerabilities, and discuss this bug class in general.</abstract>
                <slug>bsides-canberra-2026-102546-viral-vulnerabilities-unpacking-copy-fail-and-related-linux-kernel-bugs</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='101644'>Angus</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/8FNRMJ/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/8FNRMJ/feedback/</feedback_url>
            </event>
            <event guid='d6a0c894-2a3b-59b8-8273-636369a7eb7d' id='101583' code='E7QC78'>
                <room>Main Track</room>
                <title>Novel Router Emulation for Malware Reverse Engineering &amp; Infrastructure Discovery</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-24T12:00:00+10:00</date>
                <start>12:00</start>
                <duration>00:25</duration>
                <abstract>Traditional reverse engineering of edge networking firmware frequently stall at the system emulation layer due too proprietary headers, missing vendor kernel sources, and strict dependencies on physical hardware controllers. This presentation demonstrates applied User-Mode Emulation and Environment Spoofing techniques via PRoot and QEMU-ARM-Static to execute, debug, and dynamically analyse malicious edge-device implants without a native kernel. By systematically bypassing hardware configuration dependencies through virtual memory reservation, RAM capacity spoofing, and writable system-file topology bind-mounting. Researchers should be able too successfully stabilise and interrogate volatile system management daemons reliably for reverse engineering and remediation.</abstract>
                <slug>bsides-canberra-2026-101583-novel-router-emulation-for-malware-reverse-engineering-infrastructure-discovery</slug>
                <track>Main Track</track>
                <logo>/media/bsides-canberra-2026/submissions/E7QC78/image_d6dq2Bz.webp</logo>
                <persons>
                    <person id='100762'>Kendo</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/E7QC78/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/E7QC78/feedback/</feedback_url>
            </event>
            <event guid='0181e06d-73eb-5aaa-8ac4-35f1a080ba49' id='98431' code='CWSFLH'>
                <room>Main Track</room>
                <title>Azul: How to build &#8220;good&#8221; malware analysis platforms</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-24T13:30:00+10:00</date>
                <start>13:30</start>
                <duration>00:55</duration>
                <abstract>_Alternatively: Azul - The Talk, or Azul - It&#8217;s Blue!_

Azul is ASD&#8217;s ACSC&#8217;s in-house malware analysis and clustering platform, designed to deal with the 
fast-paced and complex threat landscape that malware reverse engineers and incident responders 
face. This talk will describe why we have built Azul, what it does, and a technical deep-dive into how to build systems that meets both the needs of highly technical users and robustness required for large 
organisations. 

The talk will include live demos on the product&#8217;s use in real analysis situations, reflections on previous 
internal iterations of the product and anecdotes on what not to do when building products like this. The talk will answer why organisations might have a need for automated malware processing products like Azul and where to find our open-source release.</abstract>
                <slug>bsides-canberra-2026-98431-azul-how-to-build-good-malware-analysis-platforms</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='97948'>James L</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWSFLH/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWSFLH/feedback/</feedback_url>
            </event>
            <event guid='f6599fa1-9161-574b-9798-40b72910a3c7' id='99702' code='MMAHSM'>
                <room>Main Track</room>
                <title>Let It Sync In</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-24T14:30:00+10:00</date>
                <start>14:30</start>
                <duration>00:25</duration>
                <abstract>In this talk, I&apos;ll present my research into the internals of the Microsoft Edge Sync Service, examining how the platform authenticates users, protects synchronized data, and exposes functionality through its backend APIs. We&apos;ll begin by exploring Family of Client ID (FOCI) tokens, how they fit into Microsoft&apos;s authentication ecosystem, and why they play a critical role in Edge Sync.

From there, we&apos;ll dive into the Edge Sync APIs themselves, demonstrating how FOCI tokens can be leveraged to interact directly with synchronization endpoints. We&apos;ll examine the structure of synchronized data, the cryptographic protections applied to it, and the mechanisms used to store and transmit sensitive information.

Building on this foundation, I&apos;ll demonstrate how synchronization functionality can be abused to extract sensitive data including saved passwords, history and other sync data from a victim&apos;s Edge profile. 

Finally, I&apos;ll reveal a novel technique that leverages the Edge Sync Service to transform a FOCI token into a fully authenticated user session through the acquisition of ESTSAUTH cookies, currently the ONLY known method of performing this type of token-to-session conversion.

Attendees will leave with a deep understanding of Microsoft Edge Sync&apos;s architecture, authentication model, data protection mechanisms, and associated attack surface. Defenders will gain practical guidance for identifying, detecting, and mitigating these techniques within Microsoft 365 environments.</abstract>
                <slug>bsides-canberra-2026-99702-let-it-sync-in</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='99145'>Dylan Bradley</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MMAHSM/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MMAHSM/feedback/</feedback_url>
            </event>
            <event guid='f889d7ca-ab16-5913-99da-2f8f04e0ddb4' id='101767' code='EQ7PKG'>
                <room>Main Track</room>
                <title>Password MisManagers: Hunting for Authentication Bypasses in Enterprise Password Managers</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-24T15:15:00+10:00</date>
                <start>15:15</start>
                <duration>00:55</duration>
                <abstract>Enterprise password managers hold the keys to the kingdom. Pop one, and you can instantly compromise every piece of infrastructure whose admin credentials were kept inside. So how well do these pieces of software hold up? In this talk, I&apos;ll walk through three different authentication bypass vulnerabilities I&apos;ve found in self-hosted enterprise password managers used by Australian organisations. Each one allowing a user without access to walk on in as an admin and loot all the secrets. Along the way, I&apos;ll discuss overcoming two commercial code obfuscators, a fun bonus vulnerability that wandered straight out of a CTF and into production, and what defenders should actually do about all of this.</abstract>
                <slug>bsides-canberra-2026-101767-password-mismanagers-hunting-for-authentication-bypasses-in-enterprise-password-managers</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='100863'>Aidan Stansfield</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/EQ7PKG/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/EQ7PKG/feedback/</feedback_url>
            </event>
            <event guid='e4e359d0-6207-5cfc-88fc-c328fb6e3c05' id='95351' code='MTNFGS'>
                <room>Main Track</room>
                <title>Unlimited Exploitation of Signed Windows Drivers</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-24T16:15:00+10:00</date>
                <start>16:15</start>
                <duration>00:55</duration>
                <abstract>Bring your own vulnerable driver (BYOVD) is a technique used by many APTs and ransomware groups to gain privileged Kernel access to a Windows target, typically to terminate security software running in protected processes on the host that cannot be modified by regular processes. 

Its enough of a threat that Microsoft keep a list of vulnerable drivers that can be blocked from installation on Windows systems. Does this actually stop attackers though? How common are vulnerable signed Kernel drivers?

This talk explores how I built tooling to automatically pull down hundreds of random signed drivers, perform automated analysis on them and also perform automated exploit generation to easily generate weaponised BYOVD bundles that are not known or present in the Window&apos;s blocklist.</abstract>
                <slug>bsides-canberra-2026-95351-unlimited-exploitation-of-signed-windows-drivers</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='95041'>Christopher Vella (Kharosx0)</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MTNFGS/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/MTNFGS/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Off-Main Track' guid='cfcd59fd-43da-55c5-ada7-f42188c64ea8'>
            <event guid='4f8a58b5-71ca-5498-b3af-3797d6c5b326' id='103507' code='NN99FA'>
                <room>Off-Main Track</room>
                <title>Careers Village</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-24T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>07:00</duration>
                <abstract>The goal of the Career Village is all about supporting people in their cyber security careers and linking them up with hiring managers. When you come to the village, you&apos;ll have the chance to learn about making yourself look good to employers, putting together a killer resume, nailing the interview, and meeting industry professionals and people who want to hire more security staff. We&apos;ve got experts in recruitment and security who can help you no matter what stage of your career you&apos;re at - whether you&apos;re just starting out or you&apos;re looking for the next stage in your cyber security career.</abstract>
                <slug>bsides-canberra-2026-103507-careers-village</slug>
                <track>Careers Village</track>
                
                <persons>
                    <person id='102580'>Ricki Burke</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/NN99FA/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/NN99FA/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Exhibition Hall' guid='6d915690-3dd7-5fb3-a1dd-13163a7b6980'>
            <event guid='2f9c0994-44a7-5753-a379-cb4b299be5d4' id='102788' code='ERKKBA'>
                <room>Exhibition Hall</room>
                <title>Speedrun CTF Qualifiers</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-24T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>04:00</duration>
                <abstract>Welcome to the Speedrun CTF Qualifier! Where precision, speed, and nerves of steel collide.

Individual competitors will face two challenges drawn from a mix of web, pwn, reverse engineering, or crypto. You&#8217;ll have a maximum of 15 minutes to complete both.

The faster you solve, the higher you climb. Only the top 8 fastest solvers will earn a spot in the live finale.

No second chances. No warm-ups. Just you, the challenge, and the clock. Think you&apos;re fast enough?</abstract>
                <slug>bsides-canberra-2026-102788-speedrun-ctf-qualifiers</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='101819'>toasterpwn</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ERKKBA/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ERKKBA/feedback/</feedback_url>
            </event>
            <event guid='178b1ef5-3525-5b84-b8c5-03982f207f93' id='102789' code='7EVT9P'>
                <room>Exhibition Hall</room>
                <title>Speedrun CTF Finale</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-24T14:00:00+10:00</date>
                <start>14:00</start>
                <duration>02:30</duration>
                <abstract>The top 8 have qualified - now it&#8217;s time to crown a champion live on stage.

In the Speedrun CTF Finale, competitors go head-to-head in a single-elimination bracket, racing through a gauntlet of challenges in front of a live audience. The fastest solver in each match advances, with the pressure mounting as the field thins.

Round by round, the competition intensifies - until only one winner remains standing.</abstract>
                <slug>bsides-canberra-2026-102789-speedrun-ctf-finale</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='101819'>toasterpwn</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/7EVT9P/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/7EVT9P/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Murray-Fitzroy Room' guid='b4bfe40e-6d38-5e1e-b67c-8aed7600bce3'>
            <event guid='d213f615-78dc-5147-971e-f94e0cb5cd3c' id='102325' code='QWSKGN'>
                <room>Murray-Fitzroy Room</room>
                <title>From Copilot to Commander: Building Agentic AI for Security Investigations</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-24T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>07:00</duration>
                <abstract>A hands-on 8-hour workshop on building AI systems that run real security investigations - not just isolated copilot tasks. Most teams get useful help from Claude or ChatGPT on single questions. Few can reliably run multi-step investigations across logs, tools, and incidents.
Taught by instructors behind the most popular Black Hat 2025 AI training and the team that built the first AI agent to autonomously solve the Splunk Boss of the SOC CTF.
Investigation agents fail not because of model quality, but because investigations are multi-step, ambiguous, and tool-heavy - small errors compound and there are no unit tests to keep things on track.

Four labs:
Lab 1: Run an OSS LLM locally and watch it hallucinate on SOC questions
Lab 2: Wrap it in an agent harness against Splunk BOTSv3
Lab 3: Author a plan.md timelining skill
Lab 4: Score it, error-analyze traces, fix the skill, watch the score move

Concept blocks cover harness anatomy, MCP and skills, planning patterns, evals, agentic memory and RAG, and securing agents against the lethal trifecta.
You leave with a working agent, a reusable skill, an eval harness, and a methodology.

Audience: SOC, IR, threat hunters, detection engineers, architects, technical leaders.
Prereqs: Laptop, terminal comfort, optional Python. Pre-work to install harness + pull local model.
We bring: LLM API key for attendees, bring your own key if prefered.</abstract>
                <slug>bsides-canberra-2026-102325-from-copilot-to-commander-building-agentic-ai-for-security-investigations</slug>
                <track>Event Track</track>
                <logo>/media/bsides-canberra-2026/submissions/QWSKGN/image_uAOW5UJ.webp</logo>
                <persons>
                    <person id='101417'>Sindre Breda</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QWSKGN/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QWSKGN/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Derwent Room' guid='c1cfcbdd-6e73-507e-a97d-6f8e0a611e83'>
            <event guid='3e9a789c-8c47-59c7-8b4f-89a3d2c7b3fd' id='102988' code='Z8EKP7'>
                <room>Derwent Room</room>
                <title>Black Bag - Day 1</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-24T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>07:00</duration>
                <abstract>The Black Bag is returning to BSides Canberra 2026. More details coming soon.</abstract>
                <slug>bsides-canberra-2026-102988-black-bag-day-1</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='102003'>TBA</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/Z8EKP7/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/Z8EKP7/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Locksport Village' guid='056576df-9aa1-5aa4-97aa-ac8fa95051ba'>
            <event guid='cde3c14b-8a46-5ade-8777-d8a7b2fa79ea' id='103041' code='CFPTRQ'>
                <room>Locksport Village</room>
                <title>Locksport (Day 1)</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-24T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>07:00</duration>
                <abstract>The Locksport village is your gateway into the fascinating world of physical security. Whether you&apos;re a total newcomer or a seasoned picker, there&apos;s something here for everyone.

Explore a wide variety of locks, pick tools, and hands-on challenges &#8211; all under the guidance of experienced instructors ready to share their tips and tricks. Learn how locks work, discover their vulnerabilities, and test your skills on locks ranging from beginner to expert difficulty.

This isn&#8217;t just a display &#8211; it&#8217;s a fully interactive experience. Step into the shoes of a lockpicker, challenge yourself, and maybe even surprise yourself with a hidden knack for tumblers and tension wrenches.

Come for the curiosity, stay for the challenge. You might just unlock a new obsession.</abstract>
                <slug>bsides-canberra-2026-103041-locksport-day-1</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='102058'>Volunteers</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CFPTRQ/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CFPTRQ/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Hardware Village' guid='28162d6b-401b-5db8-a506-90d17bca025d'>
            <event guid='9dc72f29-dd40-5591-a61f-ec04b112faa6' id='103044' code='CKHTDK'>
                <room>Hardware Village</room>
                <title>Hardware Village (Day One)</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-24T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>06:00</duration>
                <abstract>Step away from the keyboard &#8211; it&#8217;s time to get hands-on. Whether you&apos;re a seasoned tinkerer or just curious about what&#8217;s inside your badge, the Hardware Village is your space to learn, hack, solder, and explore.

We&#8217;ll have soldering stations ready for badge mods and hardware experiments, plus friendly experts on hand to help with troubleshooting or inspiration. Bring your gear or just swing by to see what others are building and tinkering with.

There&#8217;s always something to learn, create, or break (safely, of course).</abstract>
                <slug>bsides-canberra-2026-103044-hardware-village-day-one</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='102058'>Volunteers</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CKHTDK/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CKHTDK/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='2' date='2026-09-25' start='2026-09-25T04:00:00+10:00' end='2026-09-26T03:59:00+10:00'>
        <room name='Main Track' guid='4a29fef6-5675-517c-a556-262557f4f117'>
            <event guid='92e80d86-9579-5be4-acb4-09dffa37a086' id='102972' code='FYAJ8P'>
                <room>Main Track</room>
                <title>Friday Keynote - TBA</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-25T09:10:00+10:00</date>
                <start>09:10</start>
                <duration>00:40</duration>
                <abstract>TBA</abstract>
                <slug>bsides-canberra-2026-102972-friday-keynote-tba</slug>
                <track>Main Track</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/FYAJ8P/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/FYAJ8P/feedback/</feedback_url>
            </event>
            <event guid='dd2d5bbf-ddaa-5bf5-bd73-3dbda7c7f6ef' id='95403' code='GZAL9B'>
                <room>Main Track</room>
                <title>Doppelganger - Weaponizing CVE-2026-23066 at ZeroDay.Cloud</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-25T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>00:55</duration>
                <abstract>What happens when the kernel loses track of its own objects?

Doppelganger (CVE-2026-23066) is a race-condition in the Linux kernel&apos;s RxRPC subsystem that allows the same object reference to be queued into a linked list more than once. Could such a simple primitive really be turned into a reliable kernel exploit?

It can, and it was. This talk traces the full journey from discovery of the subtle bug in `rxrpc_recvmsg()` to a working exploit demonstrated live at the ZeroDay.Cloud competition in London.</abstract>
                <slug>bsides-canberra-2026-95403-doppelganger-weaponizing-cve-2026-23066-at-zeroday-cloud</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='95092'>Faraz</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GZAL9B/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GZAL9B/feedback/</feedback_url>
            </event>
            <event guid='74dd5179-a67d-57b9-a8e5-72dd42c018bc' id='96775' code='LESWA7'>
                <room>Main Track</room>
                <title>Fatal Errors: Forensics Pitfalls in the &quot;Mushroom Murders&quot; Case Study</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-25T11:00:00+10:00</date>
                <start>11:00</start>
                <duration>00:55</duration>
                <abstract>Digital forensics is often the &quot;silent witness&quot; that secures a conviction, but procedural missteps can risk the entire case. This presentation uses the infamous 2023 &quot;Mushroom Murders&quot; investigation as a case study to demonstrate critical failures in the collection, processing, and reporting of digital evidence. Drawing on first-hand experience as an examiner in the case, I will analyse high-profile technical hurdles, including remote wipes, SIM swapping, and contested data integrity that became focal points in the Supreme Court. Attendees will explore the technical &quot;what-not-to-do&quot; of forensics through real-world examples of factory resets and search history recovery, providing a roadmap for ensuring admissibility in high-stakes criminal litigation.</abstract>
                <slug>bsides-canberra-2026-96775-fatal-errors-forensics-pitfalls-in-the-mushroom-murders-case-study</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='96463'>Zoran Iliev</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LESWA7/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LESWA7/feedback/</feedback_url>
            </event>
            <event guid='1e73c339-a5d4-5f93-a759-46283cbcb4d7' id='102381' code='KHLBMX'>
                <room>Main Track</room>
                <title>Chasing Shadows: Portable Memory Corruption in Ghostscript</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-25T12:00:00+10:00</date>
                <start>12:00</start>
                <duration>00:25</duration>
                <abstract>Ghostscript is one of the most ubiquitous PostScript interpreters in the world. Even if you never run it directly, your systems probably do: rendering thumbnails, converting documents, previewing uploads, or handling images that quietly become PostScript somewhere along the way.

Ghostscript is also a C codebase with roots in the late 1980s, which means there is still plenty of room for memory corruption when parsing untrusted input.

In this talk, we will walk through two heap corruption bugs we discovered in Ghostscript and show how we turned them into reliable memory read/write primitives callable from PostScript. Rather than relying on fixed offsets, the exploit uses those primitives to scan Ghostscript&#8217;s address space at runtime, locate the internal structures needed for the attack, and construct a data-only sandbox escape from PARANOIDSAFER that works across multiple versions and builds.

We will then zoom out and look at where this kind of bug can actually be exploited. Thumbnailers, ImageMagick, LibreOffice, web applications, and document-processing pipelines all have different file formats and integration points, but the sink is often the same PostScript interpreter.</abstract>
                <slug>bsides-canberra-2026-102381-chasing-shadows-portable-memory-corruption-in-ghostscript</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='101483'>Rick de Jager</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/KHLBMX/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/KHLBMX/feedback/</feedback_url>
            </event>
            <event guid='f7d63311-a083-530f-a293-326b058e77f7' id='103087' code='LFCLZK'>
                <room>Main Track</room>
                <title>[redacted] until 7Aug 2026</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-25T14:00:00+10:00</date>
                <start>14:00</start>
                <duration>00:55</duration>
                <abstract>[redacted] until 7Aug 2026 due to disclosure timelines</abstract>
                <slug>bsides-canberra-2026-103087-redacted-until-7aug-2026</slug>
                <track>Main Track</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LFCLZK/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LFCLZK/feedback/</feedback_url>
            </event>
            <event guid='48ed41ba-a152-5431-8be8-f2f1f2c2057f' id='102359' code='ZREJ37'>
                <room>Main Track</room>
                <title>Time Crisis: Exploiting time-based padding oracle vulnerabilities using Timeless Timing Attacks</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-25T15:15:00+10:00</date>
                <start>15:15</start>
                <duration>00:55</duration>
                <abstract>Cryptographic padding oracle vulnerabilities are far from new. If you can throw crafted ciphertext at a Cipher Block Chaining (CBC) decryption endpoint, and it is kind enough to tell you whether it was a padding error or something else that caused it to blow up, you can use some crafty block algebra to turn it into a byte-by-byte decryption/encryption machine.

It may be tempting to fix a padding oracle vulnerability by normalising the error messages. Instead of saying, &quot;Oops, there was a padding error!&quot; simply say &quot;Oops, there was an error.&quot; Better yet, just return a generic HTTP 500 response.

The problem is that error messages are only a symptom of padding oracles, they are not the root cause. Any kind of divergent code path behaviour can give rise to a subtle sub-millisecond timing difference, which can be just enough to reveal the secrets of a padding oracle.

Justin will walk you through the methodology behind CBC padding oracle exploitation, the curse of WAN jitter that can destroy a fragile timing signal, and the blessing of Timeless Timing Attacks (Van Goethem et al., 2020) which uses HTTP/2 co-scheduling to sniff out even the faintest of timing differentials.

Join us to hear about the full suite of Timeless Timing Attacks tooling we&apos;re releasing at BSides Canberra 2026 including Go libraries, statistical engines, and command-line tools. Learn how to exploit time-based padding oracle vulnerabilities, get bamboozled by statistical methodologies you thought you&apos;d never have to hear about again, and wonder whether there are other &quot;obvious&quot; vulnerability fixes that could come undone given careful consideration of time. We can&apos;t wait to hear what you come up with!</abstract>
                <slug>bsides-canberra-2026-102359-time-crisis-exploiting-time-based-padding-oracle-vulnerabilities-using-timeless-timing-attacks</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='101451'>Justin Steven</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZREJ37/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZREJ37/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Off-Main Track' guid='cfcd59fd-43da-55c5-ada7-f42188c64ea8'>
            <event guid='d3131184-dcef-5eaf-bae8-1e1b679eb712' id='102348' code='PZEVCX'>
                <room>Off-Main Track</room>
                <title>Exploiting the Microsoft 365 Substrate: How their OAuth Clients Became an MFA Bypass Across Enterprise Tenants</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-25T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>00:55</duration>
                <abstract>Every time you sign in to Microsoft 365, a quiet exchange happens behind the scenes. Entra ID issues a token, and a sprawling backend known as the Microsoft 365 Substrate decides what that token is allowed to do. Most of that machinery is invisible, well trusted, and rarely questioned, which makes it exactly the kind of place worth questioning.

Tucked inside those tokens are claims that downstream services lean on to decide whether you really are who you say you are, and whether you have done the things, like MFA, that policy demands. But what happens when two parts of Microsoft&apos;s own platform disagree about what a token has actually proven?

In this talk I&apos;ll show how an asymmetry of authorisation between Microsoft Entra ID single sign-on and the Microsoft 365 Substrate led to enterprise account compromise on accounts where MFA should have been enforced.

You&apos;ll see how the now-patched, Important-rated vulnerability I found works end to end, starting from where it began and following how a small finding grew into something much larger.
I&apos;ll trace how misplaced trust in the claims of an access token turned into enterprise-scale data exfiltration, show some of the stranger quirks of the Substrate I ran into along the way, and explain why the asymmetry existed in the first place, with Windows Search, Microsoft Edge and Microsoft Teams all turning out to be the stars of the show.

Finally, we&apos;ll change lens and see why this isn&apos;t just a Microsoft bug, and why it might be a cautionary tale for the applications you&apos;re building. We&apos;ll walk through the common OAuth and OIDC gotchas: where developers over-trust the IdP, which claims actually carry the guarantees you think they do, and why a growing number of application providers are taking MFA enforcement into their own hands rather than waiting on the IdP to do it for them.</abstract>
                <slug>bsides-canberra-2026-102348-exploiting-the-microsoft-365-substrate-how-their-oauth-clients-became-an-mfa-bypass-across-enterprise-tenants</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='101439'>Rawson Wade</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/PZEVCX/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/PZEVCX/feedback/</feedback_url>
            </event>
            <event guid='7b24e890-cb1a-5d98-852b-9017fab42da2' id='100744' code='3VQLVR'>
                <room>Off-Main Track</room>
                <title>Find My... And Yours: Exploiting Tracker Ecosystems To Track Individuals</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-25T11:00:00+10:00</date>
                <start>11:00</start>
                <duration>00:55</duration>
                <abstract>Modern Bluetooth Low Energy tracking ecosystems: Apple Find My, Samsung SmartThings, Tile, and Google Fast Pair, have each implemented privacy controls designed to prevent persistent observation and protect user privacy. This talk demonstrates how those controls fail in practice. Through passive BLE advertisement collection, protocol-level attacks, linkage analysis, we shows how rotating identifiers can be correlated across time and space to re-identify devices, attribute them to individuals, and reconstruct movement histories.

Specifically, it will explore how:
- Rotating identifier schemes, designed to prevent tracking, can be defeated through cryptographic, temporal, and behavioural linkage analysis
- Passive advertisement collection alone, requiring no active probing, no accounts, and no interaction with target devices or ecosystems and is sufficient to re-identify devices and reconstruct movement
- Cross-vendor artefacts and advertisement structure leak identity signals that individual vendors have not accounted for in their threat models
- The privacy guarantees communicated to hundreds of millions of users do not reflect the practical reality of what passive observers can determine

The session will present a mix of linkage algorithms targeting different artifact classes across the four ecosystems and connect the findings to the broader question of what &quot;privacy by design&quot; actually requires when adversarial passive observation is the threat model.</abstract>
                <slug>bsides-canberra-2026-100744-find-my-and-yours-exploiting-tracker-ecosystems-to-track-individuals</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='100032'>Carter Smith</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3VQLVR/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3VQLVR/feedback/</feedback_url>
            </event>
            <event guid='d1ac2c21-585b-555f-829d-a682a544619b' id='102364' code='ZYRVZG'>
                <room>Off-Main Track</room>
                <title>Hooked: Tracking Linker and Generator Persistence on Linux</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-25T12:00:00+10:00</date>
                <start>12:00</start>
                <duration>00:25</duration>
                <abstract>Standard Linux persistence tracking typically focuses heavily on the more obvious artefacts like cron jobs, rc.local scripts, and standard systemd services. Because security teams look there first, modern attackers are shifting to more elegant, hook-based execution vectors that bypass traditional file-integrity monitoring.
This talk dives into dissecting two low-overhead Linux persistence mechanisms: dynamic linker hijacking and Systemd Generators. We will look at the underlying OS mechanics of both vectors, look at a live example of how easily it can blend into legitimate infrastructure and how you can audit them across your entire fleet tomorrow.</abstract>
                <slug>bsides-canberra-2026-102364-hooked-tracking-linker-and-generator-persistence-on-linux</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='101455'>JasonTrapp</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZYRVZG/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ZYRVZG/feedback/</feedback_url>
            </event>
            <event guid='7d78e580-29cf-54d3-a98f-92ae8df3c6dc' id='98116' code='QB3CLU'>
                <room>Off-Main Track</room>
                <title>Inside of an Android</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-25T15:15:00+10:00</date>
                <start>15:15</start>
                <duration>00:55</duration>
                <abstract>Have you ever been curious what *really* happens inside a mobile device? How often are different  syscalls used? Are syscall errors common? What binaries are executed, and when?  Whose actually making all these network requests? Do these behaviours change when not connected to USB? If &quot;yes&quot;, then you&apos;re not alone. This talk is a tour of modifications I made to Android to enable answering these questions, and more. Starting from source code, I&apos;ll discuss different Android technologies and the changes made to include a range of system and endpoint monitoring tools, as well as the services used to collect, analyse and alert on behaviour from both emulated and physical devices.</abstract>
                <slug>bsides-canberra-2026-98116-inside-of-an-android</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='97685'>Aaron</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QB3CLU/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QB3CLU/feedback/</feedback_url>
            </event>
            <event guid='bf3c7675-01e1-51de-ac3f-6920bbc04111' id='95338' code='YDT9EC'>
                <room>Off-Main Track</room>
                <title>Bark to the Future: Network Security with Wi&#8209;Fido</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-25T16:15:00+10:00</date>
                <start>16:15</start>
                <duration>00:25</duration>
                <abstract>Turning the whimsical charm of a Pwnagotchi into a fully mobile, AI&#8209;enabled robotic dog is more complex than strapping a Raspberry Pi to a chassis and calling it a day. This talk explores the challenges behind creating Wi&#8209;Fido&#8212;a roaming, autonomous, cybersecurity companion that can literally sniff out trouble.

We&#8217;ll examine the hurdles encountered during this evolution: adapting a traditionally stationary, packet&#8209;sniffing program into a faithful friend capable of continuous, context&#8209;aware wireless monitoring; integrating AI&#8209;driven decision&#8209;making to distinguish between benign and suspicious signals. 

Additional challenges include sharing localised data with an LLM, integrating robot interactions, and ensuring Wi-Fido&apos;s behavior remains transparent and interpretable&#8212;because no one wants a black&#8209;box robot dog silently judging their Wi&#8209;Fi hygiene. 

Attendees will leave with insights into the coding, AI models, and design philosophies that shaped Wi&#8209;Fido&#8212;and practical lessons learned in turning a traditional Wi&#8209;Fi capture workflow into a four&#8209;legged, tail&#8209;wagging cybersecurity assistant that makes network defense more effective and a lot more fun.</abstract>
                <slug>bsides-canberra-2026-95338-bark-to-the-future-network-security-with-wi-fido</slug>
                <track>Off-Main Track</track>
                <logo>/media/bsides-canberra-2026/submissions/YDT9EC/image_5AqQ4hy.webp</logo>
                <persons>
                    <person id='95026'>Chewhacker</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YDT9EC/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YDT9EC/feedback/</feedback_url>
            </event>
            <event guid='6ffd801c-e544-55fc-9d34-ab83f9f864ed' id='102336' code='3BGZWM'>
                <room>Off-Main Track</room>
                <title>From Dream Jobs to Developer Tokens: How North Korea-based threat actors abuse trust</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-25T16:45:00+10:00</date>
                <start>16:45</start>
                <duration>00:15</duration>
                <abstract>For years, defending against North Korea-based threat actors meant defenders using the same standard checklist. Block the phishing email, sandbox the lure document, or kill the macro. Since 2021 that checklist has been quietly going out of date. This talk looks at how North Korea-based threat actors changed their game. They did not just write better malware, but they moved closer to targeting the workflows and assets that organisations often implicitly trust.  They target developers, maintainers, recruiters, SaaS logins, CI/CD pipelines, browser sessions, crypto wallets, and in a growing number of cases, they stopped breaking in entirely and simply got hired. 

Drawing on PwC Threat Intelligence research into North Korea-based threat actor activity through 2026, I will walk through how the access model works today, using real world examples. A recruiter message that turns into a terminal command. A job interview that becomes the malware delivery mechanism. A developer laptop that quietly hands over source code, cloud keys and wallets, and a new remote hire who was never a real person. The point is simple and a little uncomfortable. The North Korea-based threat actor&#8217;s intrusion path no longer starts where most defenders are looking. It starts in your hiring pipeline, your dependency tree, your build system and your payroll. 

Whether you work in defence, threat intel, offensive security, or you are just breaking into the industry, you will leave this talk able to spot what these intrusions look like, not just &quot;what payload ran&quot; but &quot;which trust relationship did they abuse, and what did it expose?&quot;.</abstract>
                <slug>bsides-canberra-2026-102336-from-dream-jobs-to-developer-tokens-how-north-korea-based-threat-actors-abuse-trust</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='101428'>Sohan Lokula</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3BGZWM/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/3BGZWM/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Exhibition Hall' guid='6d915690-3dd7-5fb3-a1dd-13163a7b6980'>
            <event guid='845f2f29-7a5f-57b5-b6f0-888607bc76ee' id='102974' code='HBTFRM'>
                <room>Exhibition Hall</room>
                <title>Capture-the-Flag (Day One)</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-25T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>07:00</duration>
                <abstract>CALLING ALL HACKERS, GAMERS, PUZZLE SOLVERS, CRYPTO NERDS, PWN ENJOYERS, REVERSERS, AND CURIOUS NEWCOMERS.

skateboarding dog is back for another year of Capture the Flag featuring brand new challenges, puzzles, and games to put your skills to test.

We&apos;ve listened to your feedback! This year, dedicated teams will able to gun for the coveted leaderboard positions as usual, while a *new* mini CTF will be available for the part-time players, merch-oriented gatherers, fun-maximisers, and beginners looking for a more gentle introduction to the world of CTF.

Changing times calls for a shift in our competition rules. We&apos;ll be placing restrictions on AI usage and limiting team sizes to keep things fair and fun for everyone.

Prizes to be announced.</abstract>
                <slug>bsides-canberra-2026-102974-capture-the-flag-day-one</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='101989'>skateboarding dog</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/HBTFRM/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/HBTFRM/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Murray-Fitzroy Room' guid='b4bfe40e-6d38-5e1e-b67c-8aed7600bce3'>
            <event guid='b94fd002-da5a-557f-813e-0cf5787ccf19' id='98114' code='GY3NLF'>
                <room>Murray-Fitzroy Room</room>
                <title>Kubernetes Capture the Flag</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-25T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>04:00</duration>
                <abstract>Delve deeper into the dark and mysterious world of Kubernetes security. Start your journey deep inside the target infrastructure, collecting flags as you exploit your position in the environment and hunt for vulnerabilities.

Attendees can play three increasingly beguiling and demanding scenarios to bushwhack their way through the dense jungle of Kubernetes security. Everybody is welcome, from beginner to hardened veteran but attendees will be expected to be hands-on to understand more about core Kubernetes components and how they can be misconfigured and compromised.

Each attendee will be given access to their own Kubernetes cluster built within our bespoke sandboxed training environment. A laptop with an SSH client is required to participate.</abstract>
                <slug>bsides-canberra-2026-98114-kubernetes-capture-the-flag</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='97681'>Mario Weigel</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GY3NLF/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/GY3NLF/feedback/</feedback_url>
            </event>
            <event guid='4536f9cc-8068-5da4-a505-28d73ae0ad3a' id='102385' code='G9B7GT'>
                <room>Murray-Fitzroy Room</room>
                <title>Escalating XSS into session hijacking in modern SSO ecosystems</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-25T13:30:00+10:00</date>
                <start>13:30</start>
                <duration>03:00</duration>
                <abstract>Finding an XSS and getting alert(1) to fire is one thing. Turning it into something a program or a client treats as high impact is another, and often the trickier part. A reflected or stored XSS on a subdomain that holds no session, or an XSS you can only trigger on yourself, is easy to set aside as low severity.

Modern applications, though, are rarely a single site. They are ecosystems tied together by shared single sign-on, OAuth, parent-domain cookies, CDN caches, and postMessage. Once you understand how those pieces fit together, an XSS almost anywhere on an origin can often be escalated into a one-click account takeover of the main application.

Over the last couple of years I have reported a number of these escalations to bug bounty programs, taking reflected, stored, DOM, and self XSS and chaining them into session hijacking. This workshop walks through how that is done, using a lab built from those findings. It is aimed at testers and bug bounty hunters who can already find XSS and want to learn how to take it further. This workshop will leave you with a set of techniques, a sense of which one fits a given situation, and the confidence to build your own session hijacking chains.</abstract>
                <slug>bsides-canberra-2026-102385-escalating-xss-into-session-hijacking-in-modern-sso-ecosystems</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='101487'>Animesh Acharya</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/G9B7GT/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/G9B7GT/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Derwent Room' guid='c1cfcbdd-6e73-507e-a97d-6f8e0a611e83'>
            <event guid='85a82138-42c3-50f1-94a0-1469b292e45c' id='102989' code='XSJNE9'>
                <room>Derwent Room</room>
                <title>Black Bag - Day 2</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-25T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>08:00</duration>
                <abstract>The Black Bag is returning to BSides Canberra 2026. More details coming soon.</abstract>
                <slug>bsides-canberra-2026-102989-black-bag-day-2</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='102003'>TBA</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/XSJNE9/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/XSJNE9/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Locksport Village' guid='056576df-9aa1-5aa4-97aa-ac8fa95051ba'>
            <event guid='4d9b5ad4-4edd-50a7-bb7e-8e6890a29ddd' id='103042' code='ESQF9W'>
                <room>Locksport Village</room>
                <title>Locksport (Day 2)</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-25T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>07:00</duration>
                <abstract>The Locksport village is your gateway into the fascinating world of physical security. Whether you&apos;re a total newcomer or a seasoned picker, there&apos;s something here for everyone.

Explore a wide variety of locks, pick tools, and hands-on challenges &#8211; all under the guidance of experienced instructors ready to share their tips and tricks. Learn how locks work, discover their vulnerabilities, and test your skills on locks ranging from beginner to expert difficulty.

This isn&#8217;t just a display &#8211; it&#8217;s a fully interactive experience. Step into the shoes of a lockpicker, challenge yourself, and maybe even surprise yourself with a hidden knack for tumblers and tension wrenches.

Come for the curiosity, stay for the challenge. You might just unlock a new obsession.</abstract>
                <slug>bsides-canberra-2026-103042-locksport-day-2</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='102058'>Volunteers</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ESQF9W/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ESQF9W/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Locksport Village - Physical Challenge' guid='ce1b665b-9cc3-5d5c-9a58-9ee26f4a3c9e'>
            <event guid='c241237e-f91d-5e40-867e-f6513d853c0f' id='95309' code='UWEBSR'>
                <room>Locksport Village - Physical Challenge</room>
                <title>Black Box Zero - Physical Challenge Box</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-25T09:30:00+10:00</date>
                <start>09:30</start>
                <duration>07:00</duration>
                <abstract>Hello! Black Box Zero is a three stage physical challenge box that gets participants to solve ciphers, hack webapps, and learn to read/write NFC tags to unlock the final box. The brains are driven by a Raspberry Pi 4 that controls the webapp, hotspot, NFC reader, lights, and sounds. Suitable for someone with beginner/intermediate hacking/cybersecurity know how, but all skill levels are encouraged.</abstract>
                <slug>bsides-canberra-2026-95309-black-box-zero-physical-challenge-box</slug>
                <track>Event Track</track>
                <logo>/media/bsides-canberra-2026/submissions/UWEBSR/image_5Hl5Zcd.jpg</logo>
                <persons>
                    <person id='94990'>Nathan Cobbald and Bayley Skerman</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UWEBSR/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UWEBSR/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Hardware Village' guid='28162d6b-401b-5db8-a506-90d17bca025d'>
            <event guid='1be9a067-80e5-5fca-ae51-7a2c70295069' id='103045' code='CGFLPS'>
                <room>Hardware Village</room>
                <title>Hardware Village (Day Two)</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-25T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>07:00</duration>
                <abstract>Step away from the keyboard &#8211; it&#8217;s time to get hands-on. Whether you&apos;re a seasoned tinkerer or just curious about what&#8217;s inside your badge, the Hardware Village is your space to learn, hack, solder, and explore.

We&#8217;ll have soldering stations ready for badge mods and hardware experiments, plus friendly experts on hand to help with troubleshooting or inspiration. Bring your gear or just swing by to see what others are building and tinkering with.

There&#8217;s always something to learn, create, or break (safely, of course).</abstract>
                <slug>bsides-canberra-2026-103045-hardware-village-day-two</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='102058'>Volunteers</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CGFLPS/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CGFLPS/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='3' date='2026-09-26' start='2026-09-26T04:00:00+10:00' end='2026-09-27T03:59:00+10:00'>
        <room name='Main Track' guid='4a29fef6-5675-517c-a556-262557f4f117'>
            <event guid='4f2cbd16-8845-554d-b1a4-cfe07efd0f86' id='102973' code='C7HSRZ'>
                <room>Main Track</room>
                <title>Saturday Keynote - TBA</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-26T09:10:00+10:00</date>
                <start>09:10</start>
                <duration>00:40</duration>
                <abstract>TBA</abstract>
                <slug>bsides-canberra-2026-102973-saturday-keynote-tba</slug>
                <track>Main Track</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/C7HSRZ/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/C7HSRZ/feedback/</feedback_url>
            </event>
            <event guid='ddaa4974-688b-5db3-a852-06d20e80b126' id='102269' code='88SUTA'>
                <room>Main Track</room>
                <title>javascript:pwn() - A Field Guide to Hacking ServiceNow</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-26T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>00:55</duration>
                <abstract>ServiceNow is at the center of workflows and platform integrations for roughly 85% of enterprises - yet it rarely charts high as a priority in the pentesting backlog. Instances are generally put togther by &quot;no-code / low-code&quot; citizen developers who rarely have a software-engineering background. Combine all of this with the fact they are tinkering with a 20 year old monolith to plumb together some of your organisations most sensitive data - and you have an incredibly bespoke attack surface, unique to every org.

This talk is a field guide to attacking that surface, how to navigate and dissect a ServiceNow instance to review the custom code and components for critical vulnerabilities. Covering insecure patterns that lead to unauthorized data access, privilege escalation, and even arbitrary code execution. 

While this talk isn&apos;t aimed at identifying platform level bugs, it reviews CVE-2026-0542, a critical unauthenticated arbitrary code execution vulberabiltiy discovered using the same techniques. This vulnerability was present in default components written by ServiceNow that affected every instance - and the deep dive reveals why customer instances could still harbor their own versions of this.

Defenders leave knowing their actual attack surface and how to reduce it, what to audit in custom code, enabling better logging and monitoring, and awareness of a reporting gap between ServiceNow&apos;s own CVEs versus the advisories that go straight to customers &#8212; including a public CVE record that still reads &quot;fixed&quot; for a bug class only truly closed by patches much later. 

Since most customers get exactly one self-run pentest per calendar year, the goal of this talk is to leave you able to make that one shot really count.</abstract>
                <slug>bsides-canberra-2026-102269-javascript-pwn-a-field-guide-to-hacking-servicenow</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='101349'>Paul Alkemade</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/88SUTA/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/88SUTA/feedback/</feedback_url>
            </event>
            <event guid='6cea04cc-2723-5a7d-b0da-aaba9c55cda3' id='102061' code='V3BXU8'>
                <room>Main Track</room>
                <title>OculaRCE: From Bluetooth to Contactor</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-26T11:00:00+10:00</date>
                <start>11:00</start>
                <duration>00:55</duration>
                <abstract>A full-stack teardown of a commercial EV charger, from default credentials in the installation guide through to unauthenticated control of the AC power contactors.

This research covers multiple pre-auth RCE vulnerabilities including a Bluetooth attack requiring no network access, an unauthenticated manufacturing test mode that bypasses every safety interlock on the charger, and a design flaw that puts all safety mechanisms in a single Linux process with no independent hardware verification.

The affected firmware platform is used by multiple resellers globally. A single broadcast UDP packet can disable ground fault protection across an entire fleet.</abstract>
                <slug>bsides-canberra-2026-102061-ocularce-from-bluetooth-to-contactor</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='99951'>Brendan Scarvell</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/V3BXU8/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/V3BXU8/feedback/</feedback_url>
            </event>
            <event guid='4252d3cc-528a-5fbb-ba6a-6c1559a61e41' id='101158' code='LUJCEL'>
                <room>Main Track</room>
                <title>Waffling Around WAFs</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-26T12:00:00+10:00</date>
                <start>12:00</start>
                <duration>00:25</duration>
                <abstract>Collecting data from the game of Pokemon Go involves bulk creation of game accounts. In order to combat bots and other abusers of the game, cloud WAFs are used to prevent mass account sign-ups. This talk outlines some cheap techniques that can be used to bypass anti-bot measures employed by Imperva and other similar security platforms.</abstract>
                <slug>bsides-canberra-2026-101158-waffling-around-wafs</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='100390'>Aeriana Lawler</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LUJCEL/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/LUJCEL/feedback/</feedback_url>
            </event>
            <event guid='2813f4d4-0d7f-5fc8-a913-a2dae7503eb5' id='102227' code='CWMDP3'>
                <room>Main Track</room>
                <title>Finding vibe leaked API keys every day</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-26T13:30:00+10:00</date>
                <start>13:30</start>
                <duration>00:25</duration>
                <abstract>&#8220;Wait hang on if everyone&#8217;s vibe coding I bet they&#8217;re accidentally leaking soooooo many API keys like, publicly. And they don&#8217;t even know&#8221;, is what I thought one day.

&#8220;But *how* bad is it?&#8221; I had to know, so I tried scanning newly registered domain names every day.

This talk is the story of how I found myself drowning in poor vibe coders&#8217; diverse selection of API keys, and, um, how anyone could &#128563;. I tried to measure how easy it was to find actual, valid API keys on new, presumably vibe coded websites.

I have, in my travels, calculated various numbers, such as the average time it takes for a valid API key to be leaked after a domain is registered. There will be a thrilling analysis of today&#8217;s results, so please nobody vibe code too hard the day before.</abstract>
                <slug>bsides-canberra-2026-102227-finding-vibe-leaked-api-keys-every-day</slug>
                <track>Main Track</track>
                <logo>/media/bsides-canberra-2026/submissions/CWMDP3/image_RZskqNQ.webp</logo>
                <persons>
                    <person id='101309'>&quot;Alex&quot;</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWMDP3/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CWMDP3/feedback/</feedback_url>
            </event>
            <event guid='60134fdc-8797-5802-946b-0826c58142e6' id='100985' code='UGYDQS'>
                <room>Main Track</room>
                <title>Headless Hunter - Automated exploitation of headless Chrome using V8 n-days</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-26T15:15:00+10:00</date>
                <start>15:15</start>
                <duration>00:55</duration>
                <abstract>Consider a website. One that allows you to export PDF documents. Have you ever stopped to wonder how this works under the hood?

Commercial libraries exist to do the PDF generation heavy lifting, but as they can be quite costly, I wasn&#8217;t surprised to see developers reaching for Chrome&#8217;s &#8220;Print to PDF&#8221; functionality. What did surprise me was web applications not having up to date Chrome builds in their NPM dependencies, developers reaching for --no-sandbox rather than fiddling with Docker and Kubernetes security knobs, and web apps that allowed me to provide custom (and malicious) HTML and JavaScript for conversion to PDF.

All of this inspired me to look into Chrome&#8217;s JavaScript engine, V8, to exploit these PDF generators. Chrome&#8217;s issue tracker documents many patched vulnerabilities that work on old Chrome versions, which is perfect for my use case. The main challenge was that the exploits and techniques vary depending on the target Chrome version, so I wondered, why not make a tool with enough exploits to cover all of them?

In this talk I outline my journey for developing the tool, the design decisions I made, the problems that I overcame, and the lessons I learned along the way. The result is a single web page that can exploit 24 common Chrome versions (and counting) for remote code execution using V8 memory corruption.</abstract>
                <slug>bsides-canberra-2026-100985-headless-hunter-automated-exploitation-of-headless-chrome-using-v8-n-days</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='100240'>Daniel Cooper</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UGYDQS/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UGYDQS/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Off-Main Track' guid='cfcd59fd-43da-55c5-ada7-f42188c64ea8'>
            <event guid='722be904-4448-565e-80c8-ac459427697e' id='102372' code='YXN8DD'>
                <room>Off-Main Track</room>
                <title>You Get a C2! And YOU Get a C2!: The democratisation of sophisticated Command &amp; Control</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-26T10:00:00+10:00</date>
                <start>10:00</start>
                <duration>00:55</duration>
                <abstract>Sophisticated espionage focused Command and Control (C2) frameworks and offensive cyber tooling has been historically restricted to use by large powers and developed economies due to the high cost or lack of turn key solutions offered by open source. At the end of the day these platforms are just software suites built to strict and specialised requirements. 

LLMs through shifts in software development methodologies have become commonplace in enterprise software development life cycles and have lowered the barriers of the cost, maintainability and flexibility issues plaguing legacy offensive tooling. 

In this talk we will explore several frameworks that have been captured from the front lines to see first hand how actual APTs are building and breaking sophisticated C2 frameworks to prompt their way to success. 

We will explore the spec driven approaches that produce robust and battle ready tooling without guess work, review examples of development artifacts, documentation and prompts from a mistakenly exposed VoidLinkC2 development server and pass these lessons on to any budding red teamers wanting to replicate this success. 

Defenders and researchers need not worry - we will also discuss our lessons learned through researching AI built frameworks and what this means for the way we track and react to these threats in the future.</abstract>
                <slug>bsides-canberra-2026-102372-you-get-a-c2-and-you-get-a-c2-the-democratisation-of-sophisticated-command-control</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='101471'>Joseph Ganter</person><person id='101475'>Tom Marsden</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YXN8DD/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YXN8DD/feedback/</feedback_url>
            </event>
            <event guid='b26ae62e-da73-5378-a6a7-af8235cc4c33' id='99192' code='CNKXQT'>
                <room>Off-Main Track</room>
                <title>Malicious Entra ID Apps - what they are, how to find them and how to stop them</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-26T11:00:00+10:00</date>
                <start>11:00</start>
                <duration>00:25</duration>
                <abstract>We&apos;ve all heard of password guessing and MFA bypass techniques that are used to attack M365 - but those are old news now! The newer and more interesting vector - to both attackers and defender alike - are malicious Entra ID (formerly Azure AD) apps. In this presentation I&apos;ll explain what Entra ID apps are (and what makes some malicious), how attackers trick users/victims into registering them, how you can find any that may already be in your environment, and what you can do to stop more in the future.

This presentation is designed for technical audiences (or those wanting to become technical) to understand an emerging vector and what can be done to defend against them. The content is based on both our firsthand experience (as both attackers and defenders) as well as that from our partners.</abstract>
                <slug>bsides-canberra-2026-99192-malicious-entra-id-apps-what-they-are-how-to-find-them-and-how-to-stop-them</slug>
                <track>Off-Main Track</track>
                <logo>/media/bsides-canberra-2026/submissions/CNKXQT/image_Mjuiymm.webp</logo>
                <persons>
                    <person id='98635'>Sam Brazier-Hollins</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CNKXQT/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/CNKXQT/feedback/</feedback_url>
            </event>
            <event guid='09d96765-7b9d-5af8-b949-a33e30b56107' id='101849' code='YUZAQX'>
                <room>Off-Main Track</room>
                <title>Venting Steam: Hunting C2 in Unexpected Places</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-26T11:30:00+10:00</date>
                <start>11:30</start>
                <duration>00:25</duration>
                <abstract>If the Lumma and Vidar stealers taught us one thing, it&apos;s that literally anything can be used as a Command and Control channel. DNS TXT records, Pastebin drops, Steam profiles, telegram, discord - if it can carry a string, it can carry instructions.
This talk takes a blue team lens to the unconventional C2 landscape. We&apos;ll explore how platforms such as Steam and a handful of other legitimate services, are being quietly abused for command delivery and exfiltration. Hiding in plain sight behind trusted domains and allowlisted traffic. No blocked ports, no suspicious destinations, no alerts.</abstract>
                <slug>bsides-canberra-2026-101849-venting-steam-hunting-c2-in-unexpected-places</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='101000'>Mike Vriesema</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YUZAQX/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/YUZAQX/feedback/</feedback_url>
            </event>
            <event guid='fb58b196-2191-57f0-9cab-344d5be83ce2' id='102368' code='ASV3UJ'>
                <room>Off-Main Track</room>
                <title>Identity Is the New SOC: Hunting Entra, SCIM, PIM, and Password Manager Abuse</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-26T12:00:00+10:00</date>
                <start>12:00</start>
                <duration>00:25</duration>
                <abstract>Identity used to be the front door. Now it is the keys, the key cabinet, the floor plan, the alarm panel, and sometimes the weird emergency exit nobody has checked since 2021. 

Most organisations have put serious effort into endpoint alerts, phishing workflows, firewall rules, and dashboards. But the thing that quietly decides who can access almost everything is often treated as setup work: turn on MFA, plug in SSO, add Conditional Access, connect SCIM, move on. 

That is fine until someone uses a break-glass account, a privileged role lights up, a password manager owner gets added, a Conditional Access exclusion becomes the easiest path in, or SCIM decides to &quot;help&quot; by removing the wrong person from the wrong place. 

This talk is about hunting the identity control plane before it becomes an incident. We will walk through realistic Entra, SCIM, PIM, and password-manager failure modes, then turn those messy admin events into useful detections, triage paths, and response actions. 

Expect practical examples, awkward edge cases, noisy logs, bad assumptions, and the occasional reminder that &quot;we logged it somewhere&quot; is not the same thing as &quot;someone can respond to it at 2am.&quot;</abstract>
                <slug>bsides-canberra-2026-102368-identity-is-the-new-soc-hunting-entra-scim-pim-and-password-manager-abuse</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='101458'>Maple</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ASV3UJ/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ASV3UJ/feedback/</feedback_url>
            </event>
            <event guid='bbad5c11-292b-51d8-8176-b258db401069' id='102046' code='UHLRLX'>
                <room>Off-Main Track</room>
                <title>API Key Attribution Sucks, Lets Change That</title>
                <subtitle></subtitle>
                <type>25 Mins (including questions)</type>
                <date>2026-09-26T13:30:00+10:00</date>
                <start>13:30</start>
                <duration>00:25</duration>
                <abstract>When a secret is leaked most people look at who leaked the secret; the GitHub committers email, package author, but this sucks. Millions of commits are created by noreply emails, clankers and personal emails with no attribution back to your org at all.

We analysed hundreds of thousands of live, verified credentials with a new method of attribution, API calls to dynamically fetch ownership information. What we found will change the way you think about secret detection and remediation. 

Using this methodology we were able to achieve attribution at scale, uncovering contextless keys that had access to medical devices, defense equipment and some of the most popular software packages ever (GnuTLS, OpenConnect), KYC databases and much more.

This session discusses:
Why attribution in its current form is broken
The challenges of attribution at scale
What our methodology looks like
Case studies of our findings</abstract>
                <slug>bsides-canberra-2026-102046-api-key-attribution-sucks-lets-change-that</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='101155'>Luke Marshall</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UHLRLX/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UHLRLX/feedback/</feedback_url>
            </event>
            <event guid='159d568c-99c7-565a-a6e0-058821772fe4' id='95829' code='TN98SC'>
                <room>Off-Main Track</room>
                <title>Just spoof the government?</title>
                <subtitle></subtitle>
                <type>55 minutes (including questions)</type>
                <date>2026-09-26T14:00:00+10:00</date>
                <start>14:00</start>
                <duration>00:55</duration>
                <abstract>During an authorised social engineering engagement for a state government department, email security flaws were identified which led to successful target interaction with &#8220;malicious&#8221; infrastructure.

With the engagement a success, the question was raised; where else can these email security flaws be found across the gov.au domain, and can we &apos;just spoof the government?&apos;</abstract>
                <slug>bsides-canberra-2026-95829-just-spoof-the-government</slug>
                <track>Off-Main Track</track>
                
                <persons>
                    <person id='95523'>Ben&#8482;</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/TN98SC/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/TN98SC/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Exhibition Hall' guid='6d915690-3dd7-5fb3-a1dd-13163a7b6980'>
            <event guid='2c0e9ea7-06a7-5785-adee-19af8e481586' id='102975' code='RMC8LB'>
                <room>Exhibition Hall</room>
                <title>Capture-the-Flag (Day Two)</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-26T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>06:00</duration>
                <abstract>CALLING ALL HACKERS, GAMERS, PUZZLE SOLVERS, CRYPTO NERDS, PWN ENJOYERS, REVERSERS, AND CURIOUS NEWCOMERS.

After an incredible debut at BSides Canberra 2025, Skateboarding Dog returns with an all-new Capture the Flag competition featuring fresh challenges, new ideas, and plenty of opportunities to test your skills.

Expect all the classic categories: Crypto, Pwn, Reverse Engineering, Web, and more. Alongside the weird, creative, and unexpected challenges you&apos;ve come to expect from Skateboarding Dog.

Whether you&apos;re tackling your very first CTF or you&apos;re a seasoned competitor chasing the top of the leaderboard, there&apos;s something here for everyone.

Bring your laptop, bring your team, and see if you have what it takes to claim the trophy.

Prizes to be announced.</abstract>
                <slug>bsides-canberra-2026-102975-capture-the-flag-day-two</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='101989'>skateboarding dog</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/RMC8LB/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/RMC8LB/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Murray-Fitzroy Room' guid='b4bfe40e-6d38-5e1e-b67c-8aed7600bce3'>
            <event guid='a2459efb-180d-5f46-b030-5aefb14d8c3b' id='96294' code='VVRUFE'>
                <room>Murray-Fitzroy Room</room>
                <title>Software Supply Chain Threat Intelligence: Hands-On Training for SecOps and Threat Hunting Teams</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-26T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>06:30</duration>
                <abstract>Software supply chain attacks have become one of the most significant threats to organizations, with nation-state actors like DPRK&apos;s Lazarus Group actively compromising NPM packages, PyPI libraries, GitHub repositories, and VS Code extensions to target developers and steal credentials, cryptocurrency, and source code. This all-day hands-on training equips SecOps and threat hunting teams with practical skills to detect, analyze, and extract actionable threat intelligence from real-world supply chain malware&#8212;turning raw malware samples into finished intelligence products.

Participants will work directly with sanitized samples from active campaigns including Contagious Interview, PolinRider (DPRK), and Glassworm (Russia), analyzing malicious artifacts across four major attack surfaces: NPM, PyPI, GitHub, and VS Code extensions. Beyond technical analysis, attendees will learn about Paul&apos;s custom software supply chain CTI workflow: extracting IOCs, pivoting across infrastructure to identify campaign scope, attributing activity to threat actors, producing actionable reports, and alerting the community to the threats you expose. The training culminates with a 90-minute live hunting CTF-style session where participants apply their new skills to hunt for real threats and document findings using professional intelligence standards</abstract>
                <slug>bsides-canberra-2026-96294-software-supply-chain-threat-intelligence-hands-on-training-for-secops-and-threat-hunting-teams</slug>
                <track>Event Track</track>
                <logo>/media/bsides-canberra-2026/submissions/VVRUFE/image_et3hexz.webp</logo>
                <persons>
                    <person id='95875'>Paul McCarty</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VVRUFE/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VVRUFE/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Derwent Room' guid='c1cfcbdd-6e73-507e-a97d-6f8e0a611e83'>
            <event guid='05f4bf33-6644-5be6-96bf-912ad16252b8' id='102990' code='JBCGY7'>
                <room>Derwent Room</room>
                <title>Black Bag - Day 3</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-26T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>06:00</duration>
                <abstract>The Black Bag is returning to BSides Canberra 2026. More details coming soon.</abstract>
                <slug>bsides-canberra-2026-102990-black-bag-day-3</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='102003'>TBA</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/JBCGY7/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/JBCGY7/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Locksport Village' guid='056576df-9aa1-5aa4-97aa-ac8fa95051ba'>
            <event guid='a15be23a-2024-5042-acfe-aba5fbe324ee' id='103043' code='VDNHNZ'>
                <room>Locksport Village</room>
                <title>Locksport (Day 3)</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-26T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>06:30</duration>
                <abstract>The Locksport village is your gateway into the fascinating world of physical security. Whether you&apos;re a total newcomer or a seasoned picker, there&apos;s something here for everyone.

Explore a wide variety of locks, pick tools, and hands-on challenges &#8211; all under the guidance of experienced instructors ready to share their tips and tricks. Learn how locks work, discover their vulnerabilities, and test your skills on locks ranging from beginner to expert difficulty.

This isn&#8217;t just a display &#8211; it&#8217;s a fully interactive experience. Step into the shoes of a lockpicker, challenge yourself, and maybe even surprise yourself with a hidden knack for tumblers and tension wrenches.

Come for the curiosity, stay for the challenge. You might just unlock a new obsession.</abstract>
                <slug>bsides-canberra-2026-103043-locksport-day-3</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='102058'>Volunteers</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VDNHNZ/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/VDNHNZ/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Hardware Village' guid='28162d6b-401b-5db8-a506-90d17bca025d'>
            <event guid='315e15d6-098d-594a-bedd-54ea18a9abfa' id='103046' code='ES8WKY'>
                <room>Hardware Village</room>
                <title>Hardware Village (Day Three)</title>
                <subtitle></subtitle>
                <type>Event</type>
                <date>2026-09-26T09:00:00+10:00</date>
                <start>09:00</start>
                <duration>06:30</duration>
                <abstract>Step away from the keyboard &#8211; it&#8217;s time to get hands-on. Whether you&apos;re a seasoned tinkerer or just curious about what&#8217;s inside your badge, the Hardware Village is your space to learn, hack, solder, and explore.

We&#8217;ll have soldering stations ready for badge mods and hardware experiments, plus friendly experts on hand to help with troubleshooting or inspiration. Bring your gear or just swing by to see what others are building and tinkering with.

There&#8217;s always something to learn, create, or break (safely, of course).</abstract>
                <slug>bsides-canberra-2026-103046-hardware-village-day-three</slug>
                <track>Event Track</track>
                
                <persons>
                    <person id='102058'>Volunteers</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ES8WKY/</url>
                <feedback_url>https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/ES8WKY/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
