BSides Las Vegas 2025
Community-driven security conference in Las Vegas featuring practitioner talks across offensive, defensive, and governance topics.
→ See editor’s top picks at BSides Las Vegas 2025
- Broke but Breached: Secret Scanning at Scale on a Student Budget — Ming Chow, Raviteja
This session presents a large-scale secret scanning research effort focused on Visual Studio Code extensions in the public marketplace. The speaker, who introduces herself as Ravita and describes…
- Avoiding Credential Chaos: Authenticating With No Secrets — Chitra Dharmarajan, Steve Jarvis
Chitra Dhar Rajan and Steve Jarvis deliver a paired talk that reframes enterprise authentication and automation around a deliberately provocative golden rule: “Thou shalt not have the burden of any…
- No IP, No Problem: Exfiltrating Data Behind IAP — Ariel Kalman
Ariel Kalman presents an attack path against Google Cloud Platform’s Identity-Aware Proxy (IAP), framed as an identity firewall that intercepts requests to protected applications, enforces…
- Human Attack Surfaces in Agentic Web: How I Learned to Stop Worrying and Love the AI Apocalypse — Matthew Canham
Matthew Canaham argues that AI agents are not a passing fad by drawing a parallel to the internet’s productivity gains—time saved on mundane tasks compounds into macroeconomic and behavioral shifts…
- The Protocol Behind the Curtain: What MCP Really Exposes — Srajan Gupta, Vinay Kumar
Srajan Gupta and Vinkumar use Model Context Protocol (MCP) as a lens on why AI agents struggle to integrate safely with deterministic APIs. They argue LLM probabilism clashes with rigid…
- Rewriting the Playbook: Smarter Vulnerability Management with EPSSv3, CVSSv4, SSVC & VEX Frameworks — Avinash Nutalapati
Avin delivers an introductory-to-intermediate talk aimed at vulnerability management leaders who feel buried in CVE noise. The speaker, who identifies as a vulnerability analyst at Discover working…
- The Two Types of Fool – Generations in Cybersecurity — Casey John Ellis
Casey Ellis delivers a reflective keynote on generational knowledge transfer in cybersecurity, anchored by a thesis borrowed from John Brunner’s novel The Shockwave Rider: there are two kinds of…
- Hardening Containers with Seccomp: Hands-On Profiles, Pitfalls, and Real Exploits — Ben Hirschberg
This session frames seccomp as an underused Linux kernel capability that can materially constrain attackers inside containerized environments—even when initial compromise succeeds. The speaker…
- The Not So Boring Threat Model of CSP-Managed NHI’s — Kat Traxler
Cat Traxler, introducing herself as principal security researcher at Vector AI, delivers a comparative threat model of cloud service provider (CSP) managed non-human identities (NHIs) across AWS…
- PEBKAC Rebooted: A Hacker’s Guide to People‑Patching in 90 Days — David Shipley
David Shipley opens by reframing “PEBKAC” from an insult about user stupidity to a more constructive idea: people as partners between keyboard and chair—capable, human, and shaped by biology and…
- The Scene is Dead — Allison Nixon
Allison opens her BSides Las Vegas keynote with a deliberate contradiction: she declares the scene is dead, then insists it is more alive than it has ever been—just no longer underground, still full…
- Opening Remarks, Tuesday: Breaking Ground — Daemon Tamer
This recording captures Tuesday opening remarks for BSides Las Vegas 2025, framed by the host as the unusual “day two” experience of a Tuesday—reflecting the conference’s expanded schedule. Rather…
- Advancing Network Threat Detection Thru Standardized Feature Extraction & Dynamic Ensemble Learning — Jason Ford
Jason Ford, introducing himself as a research engineer at Proofpoint giving his first BSides talk, presents roughly two years of research on improving network intrusion detection by fixing what he…
- Hackers Kinda Like to Eat — Curtis Hanson, Whitney Bowman-Zatzkin, Andrew Rose
This I Am The Cavalry track session pairs Curtis Hansen (in person), representing Invictus Incident Response and describing himself as a new BioISAC member, with Andrew Rose (remote on AV)…
- The Age of Zygote Injection — Tricta
This presentation makes a focused case for zygote injection as a powerful, comparatively stealthy way to instrument or subvert Android applications at scale. The speaker—who asks the audience to…
- The World Famous Hire Ground Panel, Tuesday Edition — Kirsten Renner, Kris Rides, Heather Morris, Noelle Hori
BSides Las Vegas’s Higher Ground hiring village anchors a long-running community effort to make career navigation in security more humane and more legible. This Tuesday panel, moderated by Kirsten…
- The Unbearable Weight of Commercial Licensing. Combining Closed Systems with Open Source Defense — Keya Arestad
Kia Ard’s talk uses commercial licensing complexity and closed security products as a launch point for a defender-centered argument: when procurement, entitlements, and opaque alert taxonomies slow…
- Defending Our Water – Defending Our Lives — Dean Ford, Virginia “Ginger” Wright, Andrew Ohrt
This water and wastewater panel connects public health, civil engineering scale, and cyber risk through the lens of cyber-informed engineering (CIE)—a discipline, championed in the session by Ginger…
- Agentic AI Malware: Why the Cybersecurity Battle Isn’t Over — Candid Wuest
Candid West opens with a deliberately skeptical frame: headlines suggest agentic AI malware has ended the defensive game—self-adapting implants that bypass everything—yet telemetry and sample volume…
- Malicious Packages – they’re gonna get ya! — Allan Friedman, Megg Sage
Meg Sage delivers a BSides Proving Grounds talk aimed at developers and security engineers who treat dependency installation as a routine npm install or pip install—and therefore miss that…
- RAG Against the Machine: Using Retrieval-Augmented Generation & MCP to Fortify Cybersecurity Defense — Brennan Lodge
Brennan Lodge uses BSides Las Vegas as a venue to argue that retrieval-augmented generation (RAG) and the Model Context Protocol (MCP) are practical, mostly open-source building blocks for defensive…
- Time is Running Out – Tying it All Together – What Will You Do in the Near Term? — Josh Corman
This closing session for the I Am the Cavalry track at BSides Las Vegas is a synthesis talk and forward-looking briefing from Josh Corman, who describes himself as the founder of I Am the Cavalry…
- Rusty pearls: Postgres RCE on cloud databases — Coby Abrams, Tal Peleg
Tal (as introduced) and Kobe Abrams of Veronus (as transcribed) present a privilege-escalation style attack chain against PostgreSQL that starts from a surprising property of trusted PL/Perl: the…
- Phish-Back: How to turn the problem into a solution. — Gautier Bugeon
Gutier Bjon, CEO of Moken, presents “Phish-Back” (spelled “Fishbach” by the host in the transcript): a strategy to recover visibility into stolen credentials by placing high-fidelity fake login…
- XSS is dead – Browser Security Features that Eliminate Bug Classes — Javan Rasokat
Yavan delivers a fast-paced survey arguing that cross-site scripting (XSS) remains a top bug class not because browsers lack defenses, but because organizations remain reactive, under-automate…
- Let’s Go Shopping: Third-Party Vendors and CyberRisk — Meghan Jacquot, Rafael Ayala
Rafael Lyala uses a grocery shopping metaphor to explain third-party risk management (TPRM) for mixed audiences: security professionals, coworkers, family, and friends. The talk explicitly warns…
- Hacking Secure Coding Into Education — Or Sahar, Yariv Tal
Osar and Yariv Ta argue that software remains insecure in 2025 because education still teaches dangerous patterns—using a real high school “internet programming” assignment as a case study with…