BSides Canberra 2026

The speaker's profile picture
"Alex"

“Alex” (mangopdf) has hacked their employer an unspecified number of times Red Teaming, committing metaphorical crimes and writing really really detailed confession letters. Once they found former Australian Prime Minister Tony Abbott’s passport number using Google Chrome, talked to him on the phone about it, and did not get arrested. They just started mangopdf Communication, a legitimate business in which they teach security people how to present and write in a way that non-security people understand.

On the side, they organise purplecon, a gentle, pastel, inclusive security conference, but it’s unclear whether the whole thing is like a joke, or what.
More "Alex" content, blog posts, and past conference talk recordings: https://mango.pdf.zone.

  • Finding vibe leaked API keys every day
The speaker's profile picture
Aaron

Aaron has spent 20 years developing and maintaining security systems from within or on behalf of governments. More recently, those skills and experience have also been invested into home lab and hobby projects. One of which is the subject of a BSides Canberra 2026 talk.

  • Inside of an Android
The speaker's profile picture
Aeriana Lawler

Aeri is a Linux sysadmin who these days [unfortunately] works in cyber security policy and auditing. In between making biltong and hiking around Namadgi, she likes to level the playing field in Pokemon Go by developing tools to annoy spoofers in the game.

  • Waffling Around WAFs
The speaker's profile picture
Aidan Stansfield

Aidan is a penetration tester and security researcher at Division 5. Over the years, he has tested most attack surfaces across most industries, with a particular focus on internal networks and critical infrastructure. Nowadays, he hunts for bugs that require a deeper dive then a traditional pentest permits. Outside of work, he creates CTF challenges for his local hackercons (BSides BNE and Crikeycon), and represented Team Oceania at the International Cybersecurity Challenge (ICC) in 2022 and 2023.

  • Password MisManagers: Hunting for Authentication Bypasses in Enterprise Password Managers
The speaker's profile picture
Angus

Angus is a vulnerability researcher at InfoSect. At work, he is well known for giving talks that go way over time and contain unnecessary amounts of detail. Outside of work, Angus enjoys learning new (usually useless) skills, attempting (and forever failing) to win CTFs, cooking (hopefully) tasty food, and is known to be overly competitive when playing (video|board|role-playing|war)games with his friends.

  • Viral Vulnerabilities: Unpacking Copy.Fail and related Linux Kernel bugs
The speaker's profile picture
Animesh Acharya

Animesh is a Senior Security Consultant working at Tanto Security. He is interested in web security research and also does Bug Bounties. You can get in touch with him on LinkedIn at https://www.linkedin.com/in/an1msh/

  • Escalating XSS into session hijacking in modern SSO ecosystems
The speaker's profile picture
Australian Information Security Academy

The Australian Information Security Academy (AusISA) is a founding initiative of Redacted Information Security and Malware Security. Having worked together to present previous Black Bag challenges, and exceptional services to Government, we formalised the arrangement into a new training organisation. AusISA delivers the new endorsed IRAP Assessor training, and has courses coming on AI, Red Team, Defence A&A, Implementing ISM and more. Launching in 2027, we will be hosting a permanent Black Bag competition facility with a full, year long tournament. https://ausinfosec.academy/

  • Black Bag "TERMINAL MISALIGNMENT" - Day 1
  • Black Bag "TERMINAL MISALIGNMENT" - Day 2
  • Black Bag "TERMINAL MISALIGNMENT" - Day 3
The speaker's profile picture
Avery Artemis Pitt-Warddhana (nullableVoidPtr)

Avery is a Senior Offensive Security Consultant by profession and a Security Researcher by hobby, who is a frequent CTF player with Emu Exploit and Friendly Maltese Citizens with a penchant for reverse-engineering. They have previously developed and released open-source security tooling towards program analysis and malware research, and in particular analysed and wrote tooling for JavaScript obfuscators.

  • Ares: decompiling React Native bytecode bundles
The speaker's profile picture
BSides Canberra
  • HackerChix Networking
  • Friday Night Networking Event
The speaker's profile picture
Ben Wilson

Ben is a security consultant at Tanto Security, with over three years of experience conducting security assessments. During this period, Ben has successfully delivered a wide variety of engagements across web applications, external and internal infrastructure, physical security assessments, and advanced red team scenarios.

Recognised for his contribution to the cybersecurity community, Ben has been accepted to speak at numerous conferences around Australia, including BSides Melbourne, BSides Canberra and ADFCSC. He was awarded the Best New Speaker Award at BSides Canberra 2024 for his presentation on email spoofing vulnerabilities within Microsoft Outlook.

You can get in touch with him on LinkedIn: https://www.linkedin.com/in/ben-wilson-b01811208

  • Troubleshooting to SYSTEM: Local Privilege Escalation in Windows Diagnostics
The speaker's profile picture
Ben™

Ben™ is an Offensive Security Consultant with a diverse background in Information Technology and Education. Since transitioning from teaching and vocational education governance, he has conducted various offensive security engagements, including penetration testing and adversary simulation. Ben™ has experience conducting testing across external applications and services, internal and cloud-based corporate networks, as well as specialist experience in various forms of social engineering.

He operates under the assumption that snacks improve all outcomes, brings a methodical approach to chaos and a chaotic approach to method, and quietly wonders why people insist on paying him for something he’d likely do for free.

  • Just spoof the government?
The speaker's profile picture
Brendan Scarvell

Brendan is a security researcher and co-founder of Signal 11, with a background spanning web application, network, hardware, and embedded device security. His work focuses on finding and exploiting vulnerabilities in real-world systems, with a particular interest in connected devices and the security risks created when consumer and business infrastructure overlap.

  • OculaRCE: From Bluetooth to Contactor
The speaker's profile picture
Carter Smith

Carter, based in Darwin, is a seasoned security consultant with a rich background in both building and testing the security of software and networks. Proficient in a diverse array of tools and languages, and various web application frameworks, Carter brings a comprehensive IT and development background to his work, being able to think as a developer as well as an adversary.

His security testing expertise extends across a wide spectrum of penetration testing, encompassing web applications, external and internal networks, social engineering, thick client systems, mobile applications, and even physical security domains. Whilst his focus on penetration testing, Carter has broad skills in many aspects of cybersecurity.

Passionate about Open-Source Intelligence (OSINT), Carter's commitment to this field is demonstrated through his appearances on the TV show HUNTED three times, and his active involvement in national Cyber Intelligence hackathons.

Carter pioneers the development of new OSINT techniques, tools and infrastructure.

  • Find My... And Yours: Exploiting Tracker Ecosystems To Track Individuals
The speaker's profile picture
Chewhacker

Chewhacker entered the cyber security world in 2020, diving head first into cyber threat intelligence and quickly developing a passion for understanding adversary behaviour. While her work now spans multiple areas of security, CTI and adversary emulation remain her favourite playgrounds.

Outside of work, she can usually be found hunting for her next mechanical keyboard, spending time with her sausage dogs, trying to obtain more sausage dogs, or making friends with people so she can hug their sausage dogs. After assembling badges at past BSides Canberra events, she discovered a new hobby that escalated into building a robotic, AI enabled cyber security dog — because every good defender deserves a loyal companion.

  • Bark to the Future: Network Security with Wi‑Fido
The speaker's profile picture
Christopher Vella (Kharosx0)

Christopher Vella is a security researcher @ Microsoft (MORSE) and develops trainings and custom vulnerability research tooling @ Signal Labs

  • Unlimited Exploitation of Signed Windows Drivers
The speaker's profile picture
Daniel Cooper

Daniel Cooper is a Security Consultant at Tanto Security. He is interested in security research in areas such as web security, binary exploitation, and more recently, Microsoft Windows. He also enjoys playing in the occasional CTF.

  • Headless Hunter - Automated exploitation of headless Chrome using V8 n-days
The speaker's profile picture
Dr Silvio Cesare

-

  • Opening Ceremony
  • Closing Ceremony
The speaker's profile picture
Dylan Bradley

I am a Penetration Tester and Red Teamer from Melbourne with specilisations in Active Directory and Azure / M365. I recently contributed a small amount of research on SCCM to the Misconfiguration Manager Github. I also have an interest in the blue team side of things as I believe it is important to know how to effectively navigate and detect the attacks that I perform. I love having a yap so if you see me around come talk tech or ask me about what I get up to outside the tech world.

  • Let It Sync In
The speaker's profile picture
Faraz

Faraz is a Lead Blockchain Security Researcher at Zellic. When not busy with work, he likes to play video games and indulge in low level vulnerability research and exploit development.

  • Doppelganger - Weaponizing CVE-2026-23066 at ZeroDay.Cloud
The speaker's profile picture
Gaurav Vikash

Gaurav is a security practitioner with 18 years of experience across financial services and public safety technology. Gaurav has been tracking how rapidly evolving AI capabilities are creating attack surfaces that existing security frameworks were not built to handle. He approaches the space as a practitioner rather than a theorist, more interested in whether protections actually hold under testing than in whether they look credible on paper.
He is an active contributor to the Australian information security community and is known for bringing directness to technical conversations. He regularly presents at CyberCon, AusCERT, Hack Sydney, BSides Sydney, and other major conferences in Australia.

  • Testing Second-Order Prompt Injection Across AI Agent Deployments
The speaker's profile picture
George Dan

George is a Principal Penetration Tester at Fujitsu Australia with over five years of professional experience. He has a strong affinity for reverse engineering weird and complex systems, and enjoys a good CTF with first bloods for trophy challenges at BSides Canberra CTF's under his belt, such as Lucky Visitor and SecElf cyOS Jailbreak.

  • WebKit Archaeology: Finding Treasure in the Past
The speaker's profile picture
James L

James is an automation engineer at ASD's ACSC, working on automated malware analysis platforms to improve the speed and accuracy of incident response activities.

  • Azul: How to build “good” malware analysis platforms
The speaker's profile picture
JasonTrapp

Jason has spent over six years working as a digital forensics and incident response analyst, investigating critical incidents across nearly every industry sector. Dealing with ransomware and business email compromise on a daily basis, he is intimately familiar with the realities of modern incident triage. Jason spends his spare time researching cloud security and writing custom tools and programs to streamline complex forensic investigations.

  • Hooked: Tracking Linker and Generator Persistence on Linux
The speaker's profile picture
Joseph Ganter

Joseph is a Threat Hunter and Researcher with Palo Alto's Unit 42 working in the intrusion intelligence cell. He has had a diverse set experience across the government and private sectors working in incident response, penetration testing and threat hunting for nearly a decade.

  • You Get a C2! And YOU Get a C2!: The democratisation of sophisticated Command & Control
The speaker's profile picture
Josh

Pentester at Tantosec. TBA

  • Attacking Passkeys: Offensive Tooling and Implementation Vulnerabilities
The speaker's profile picture
Justin Steven

Justin is a seasoned computer security professional with 14 years of experience across Incident Response and Software Security. As Tanto Security's Director of Research, Justin fosters the curiosity and ingenuity of our consultants, supporting them as they engage in their own research projects.

  • Time Crisis: Exploiting time-based padding oracle vulnerabilities using Timeless Timing Attacks
The speaker's profile picture
Kendo

A Security Engineer with Advanced Practices at Google. He primarily supports frontline intelligence operations and incident response investigations.

  • Novel Router Emulation for Malware Reverse Engineering & Infrastructure Discovery
The speaker's profile picture
Kylie McDevitt

-

  • Opening Ceremony
  • Closing Ceremony
The speaker's profile picture
Luke Marshall

Luke Marshall is a Security Researcher at Truffle Security specialising in the discovery of exposed secrets and supply chain vulnerabilities. Formerly a Security Engineer at Bugcrowd, Luke focuses on research in massive public ecosystems to uncover novel attack vectors. He is a dedicated proponent of responsible disclosure and digging into large datasets to uncover hidden security gaps and systemic risks that often go unnoticed.

  • API Key Attribution Sucks, Lets Change That
The speaker's profile picture
Luke Symons

Luke is a Principal Security Engineer and researcher at SEEK, where he specialises in mobile and web application security. He has discovered and responsibly disclosed a number of CVEs, and has contributed to the OWASP Mobile Security Testing Guide (MSTG). Luke is an active member of the Melbourne security community and has previously presented at Ruxmon Melbourne.

  • Whaling on mobile apps with Leviathan
The speaker's profile picture
Luke Wurst

Luke brings with him two decades of cyber security and IT experience, along with a passion for helping others. After years of struggling with the "boss fights" of professional life—specifically job interviews and corporate environments— Luke realised that his challenges were the way he was built and not personal failings. He is passionate about helping neurodiverse professionals reframe their unique traits as strategic advantages, using science-backed methodologies to navigate both life and work.

  • Reverse Engineering Games. Common methods and traps for devs.
The speaker's profile picture
Maple

Maple Fox is a Melbourne-based security engineer, researcher, and community organiser working across cloud and platform security, identity-first design, Zero Trust, SIEM/SOAR, security automation, and critical infrastructure cyber security.

Maple works hands-on with Microsoft Entra, Azure, AWS, Sentinel, Intune, Terraform, Go, Python, SAML/OIDC, FIDO2, firewall integrations, and secure access patterns. Their work spans identity baselines, detection engineering, secure cloud guardrails, Zero Trust access orchestration, and practical security evidence for audit and uplift programmes.

Maple is currently completing a Master of Cyber Security at Deakin University, with research focused on machine-readable security intent, policy compilation, and bounded reachability verification. They also have practical experience supporting SOCI- and AEMO-focused cyber security gap assessments for critical infrastructure and OT environments, including SCADA, communications, remote access, BESS-style infrastructure, and OT/cloud boundary controls.

Alongside industry work, Maple teaches cyber security at Deakin University and contributes heavily to the Australian cyber community. They founded Deakin University Cybersecurity Association, helped scale it into a large student community, and co-chair ACUCyS, supporting collaboration across Australian university cyber clubs.

Maple likes building practical labs, tools, diagrams, demos, and repeatable methods that turn security ideas into evidence. Their current interests include secure OT connectivity, identity-aware access control, Zero Trust engineering, detection-as-code, and proving when "policy" actually matches what systems can reach.

  • Identity Is the New SOC: Hunting Entra, SCIM, PIM, and Password Manager Abuse
The speaker's profile picture
Mario Weigel

Mario Weigel has been in the Linux and automation world since 2002, moving through support, testing, and systems administration before the DevOps movement caught up with skills he’d already built. For several years, he’s been consulting in complex, heavily regulated sectors to design solutions that enable security and development teams to thrive in tandem. In his own time, he leads the Auckland Kubernetes meetup.

  • Kubernetes Capture the Flag
The speaker's profile picture
Mike Vriesema

Mike is a Primary Technical Investigator in Accenture's Global Cyber Response team, leading end-to-end DFIR engagements across large-scale cyber incidents worldwide. With over five years at Accenture and a First Class Honours degree in Cyber Security & IT Forensics from the University of Limerick, he brings deep expertise in incident response and threat intelligence. Mike is a GIAC Advisory Board member and holds certifications including CISSP, GCFA, and GX-FA (and a bunch of other alphabet soup).

  • Venting Steam: Hunting C2 in Unexpected Places
The speaker's profile picture
Nathan Cobbald and Bayley Skerman

Amateur 'putting stuff in a box and making it do things'-ers . By two people who work together sometimes

  • Black Box Zero - Physical Challenge Box
The speaker's profile picture
Paul Alkemade

I'm an offensive security engineer based in Melbourne we're I've been hacking away for over six years. When I'm not staring at a computer screen I'm probably stuck out bush trying not to stare at my phone.

  • javascript:pwn() - A Field Guide to Hacking ServiceNow
The speaker's profile picture
Paul McCarty

Paul is a serial startup found and a true hacker OG. He created OpenSourceMalware.com, the worlds largest open database and collaboration platform for software supply chain threat intel. Paul delivers software supply chain offensive security training and engagements globally and speaks at many security conferences and hacker meetups. He's spent many years hacking NPM and PyPI, and has made several discoveries about the ecosystem. Paul founded multiple startups starting in the '90s and has worked for NASA, Boeing, Blue Cross/Blue Shield, John Deere, the US military, the Australian government.  Paul is a frequent open-source contributor and author of several DevSecOps, software supply chain and threat modelling projects. He’s currently writing a book entitled “Hacking NPM”, and when he’s not doing that, he’s snowboarding with his wife and 3 amazing kids.

  • Software Supply Chain Threat Intelligence: Hands-On Training for SecOps and Threat Hunting Teams
The speaker's profile picture
Rajiv Shah

Rajiv is an expert in explaining emerging technology, and helping organisations to apply it in a way that is both secure and delivers business value. In addition to running his own consulting business, MDR Security, he is a Fellow of the Australian Strategic Policy Institute, and a member of the board of the Australian Information Security Association. He is a regular speaker at major conferences, including SXSW Sydney 2024 and the CSIRO "Quantum Meets Communications" event.
Rajiv has a PhD in quantum physics from the University of Cambridge, and has almost 30 years experience in the technology industry, working across cyber security, quantum technology, telecommunications, AI and cloud. His current work includes technical advice and oversight to major IT projects, solution architecture for complex data platforms and providing technical input to strategy development and analysis of public policy options. Rajiv's previous experience includes as the inaugural Australian regional director for the cyber security division of BAE Systems, and establishing Australian federal government business for British Telecom.

  • How to hack a quantum system
The speaker's profile picture
Rawson Wade

Rawson is a Senior Security Engineer at Modern42, where he leads a team of specialist Microsoft Entra developers and engineers building secure IAM ecosystems for government, health, and banking. His expertise sits in the complex end of authentication, with deep domain knowledge across IAM, Workload Identities and CIAM.

  • Exploiting the Microsoft 365 Substrate: How their OAuth Clients Became an MFA Bypass Across Enterprise Tenants
The speaker's profile picture
Rick de Jager

Rick is a full-time security researcher at v12.sh and a member of the Pwn2Own team “PHP Hooligans.” He has competed in five editions of Pwn2Own, exploiting a wide range of targets including routers, printers, and automotive systems. Outside of Pwn2Own, Rick is an avid CTF player, having competed as part of 0rganizers and ICC’s Team Europe.

  • Chasing Shadows: Portable Memory Corruption in Ghostscript
The speaker's profile picture
Ricki Burke
  • Careers Village
The speaker's profile picture
Sam Brazier-Hollins

Sam is a Microsoft MVP for M365 and Copilot - and therefore has spent more time in the consoles than anyone should... When he isn't, he leads the Technical Consulting team at Fujitsu Cyber which includes both the technical testing team (that attempts to break in) and the professional services team (that attempt to stop the break-ins).

Sam was one of the original authors of the Digital Transformation Agency (DTA) Protected Utility Blueprint for Microsoft 365 (M365), Sam has more experience than most with how to balance usability and collaboration with the evolving nature of cyber security threats.

  • Malicious Entra ID Apps - what they are, how to find them and how to stop them
The speaker's profile picture
Sarah Lam

Sarah is a Law/Computer Science student at Monash University. Additionally, she has been working as a penetration tester at Promithic for the last two years. Besides being paid to break things, she is also a Managing Editor of the Monash University Law Review and a legal research assistant.

  • Watch Your Language: A Multi-Lingual Approach to Bypassing Email Filters
The speaker's profile picture
Sean

Sean Park is a reverse engineer and AI security researcher who hunts for blind spots in modern agentic systems. From prompt injections to compromised MCP servers, he uncovers how small flaws in AI workflows can trigger full-scale compromise. Whether analyzing Jupyter kernel traffic, tracing hallucinated dependencies, or stress-testing sandboxed agents, Sean blends automation, adversarial thinking, and low-level precision to stay ahead of emerging threats. His motto: every system can be mapped, exploited—and secured.

  • AIxploit: Reliable Prompt Injection Exploits Against Database-Enabled AI Agents
The speaker's profile picture
Sindre Breda

Police officer turned computer forensic investigator, turned analyst/developer. Sindre started his career as a street cop that quickly switched to computer forensics/mobile forensics with key focus on online child abuse.
From 2018 he worked at the Norwegian "National Criminal Investigation Service", more commonly known as Kripos.
At Kripos he worked with analyzing data that the commercial forensic toolkits did not parse/present, most actively in the investigations of the ransomware attack against Norsk Hydro in 2019. Currently working as a Solutions architect at Graphistry.

  • From Copilot to Commander: Building Agentic AI for Security Investigations
The speaker's profile picture
Sohan Lokula

Sohan is a Senior Analyst in PwC’s Threat Intelligence team and the North Korea-based threats lead. He is a technical Cyber Threat Intelligence analyst focused on cyber crime and North Korea-based threat actors, with experience across deep and dark web intelligence, threat actor tracking, cyber criminal activity, and strategic intelligence reporting.

  • From Dream Jobs to Developer Tokens: How North Korea-based threat actors abuse trust
The speaker's profile picture
Tom Marsden

TBA

  • You Get a C2! And YOU Get a C2!: The democratisation of sophisticated Command & Control
The speaker's profile picture
Tonmoy Jitu

Tonmoy Jitu is a cybersecurity professional whose work sits at the intersection of incident response and hands-on threat research. They began as an Incident Responder, handling active intrusions and enterprise-scale containment. That experience led them into dedicated threat research at Sophos, where they spend much of their time tearing down malware, reversing suspicious binaries, and chasing samples that sit in a grey zone: low or inconsistent detection, weak reputation coverage, or behavior that only makes sense once you read the file end to end.

Tonmoy is especially interested in how those samples propagate in the wild, how they evade common checks, and what static and behavioral evidence actually holds up under scrutiny. They also write on their own time about emerging malware and threats that tend to fly under the radar: odd tooling, quiet campaigns, and binaries that do not map cleanly to familiar family names or mainstream coverage.

  • Tearing Down a DPRK-Linked macOS Crypto Stealer
The speaker's profile picture
Volunteers

BSides Canberra is entirely volunteer-run, with around 40 dedicated volunteers who contribute both before and during the event. Volunteers can be easily identified by their maroon t-shirts.

  • Locksport (Day 1)
  • Locksport (Day 2)
  • Locksport (Day 3)
  • Hardware Village (Day One)
  • Hardware Village (Day Three)
  • Hardware Village (Day Two)
The speaker's profile picture
Zoran Iliev

With over 25 years of pioneering digital forensics for government agencies, law enforcement, and global corporations, Zoran has shaped the future of forensic science. His innovative methodologies and insights have solved high-stakes investigations, from cyber fraud to international policy breaches. As a Lead Forensic Examiner at the Department of Home Affairs and a recognised educator, Zoran empowers organisations worldwide, transforming challenges into resolutions. Zoran holds a Master of eForensics and Enterprise Security from the University of Melbourne. He is a NATA technical assessor and the only ANAB technical assessor and auditor in Australia.

  • Fatal Errors: Forensics Pitfalls in the "Mushroom Murders" Case Study
The speaker's profile picture
filsy

I'll update this at some point...

  • yeaaaaaaaaaaaaaaaaaaaalink! - dissecting an android Teams phone
The speaker's profile picture
skateboarding dog

After an outstanding debut as CTF hosts in 2025, skateboarding dog are back to design and run the BSides Canberra CTF for a second year.

They're not just any CTF team, they're one of Australia's most accomplished. A powerhouse of talented hackers, this team has dominated the local CTF scene for years, consistently finishing at the top of competitions around the country. Before taking over as hosts, they claimed first place in the BSides Canberra CTF for three consecutive years.

Known for deep technical expertise, creative exploitation techniques, and exceptionally well-crafted challenges, skateboarding dog has earned a reputation for building CTFs that are approachable for newcomers while still pushing seasoned players to their limits. If last year's competition was anything to go by, you're in for another fantastic weekend of hacking.

Whether you're chasing the podium or tackling your very first challenge, the BSides Canberra 2026 CTF promises another memorable experience with skateboarding dog at the helm.

Follow them on X: https://x.com/sk8boardingdog

  • Capture-the-Flag (Day One)
  • Capture-the-Flag (Day Two)
The speaker's profile picture
toasterpwn

Your Speedrun CTF host returns for 2026: toasterpwn https://x.com/toasterpwn

After a hugely successful debut at BSides Canberra last year, toasterpwn is back to put competitors through another fast-paced gauntlet of hacking challenges. Winner of the Hexacon Speedrun CTF 2024, captain of the Australian team Emu Exploit, and a professional vulnerability researcher at InfoSect, toasterpwn combines elite technical skills with a passion for creating fun, competitive challenges.

Known for lightning-fast exploitation and a love of all things pwn, toasterpwn has earned a reputation as one of Australia's rising offensive security talents. Whether you're chasing the top spot or simply looking to test your skills against the clock, the Speedrun CTF is back for another year of rapid-fire hacking action.

  • Speedrun CTF Qualifiers
  • Speedrun CTF Finale