Loading…
BruCON 0x10 has ended
arrow_back View All Dates
Friday, September 20
 

10:00 CEST

Keynote: I don't need privacy, I got confidentiality!
Friday September 20, 2024 10:00 - 11:00 CEST
Debunking this and other persistent privacy myths is highly overdue. In this keynote, we'll explore privacy engineering and discover how it can strengthen security. Threat modeling will be the star player here, as it not only drives and improves the secure development process, but also serves as the perfect vehicle to integrate and align privacy into security practices.
Speakers
avatar for Kim Wuyts

Kim Wuyts

Kim Wuyts  (@Wuytski) is a leading privacy engineering expert with over 15 years of experience in security and privacy. Before joining PwC as Manager Cyber & Privacy, Kim was a senior researcher at KU Leuven where she led the development and extension of LINDDUN, a popular privacy... Read More →
Friday September 20, 2024 10:00 - 11:00 CEST
01. Gouden Carolus

11:00 CEST

MitM but for Mail (MaitM)
Friday September 20, 2024 11:00 - 12:00 CEST
Mistyped domains often take some convincing to be effective in phishing attacks. After finding the perfect typo, the real work starts setting up the perfect lure. Instead of this, an often-forgotten attack vector exists where potential victims already make these typo's when sending email and or configuring systems, letting go of plenty useful information while at it.

In this talk we will explore this attack vector, ultimately setting ourselves up for a Mail-in-the-middle (MaiTM) attack to steal confidential information, login using password resets, embed tracking pixels and even deliver malware. Configuring this can still take some work and requires quick timing, so to help with that we have developed a toolkit that we will demonstrate during this talk. Finally, considering the impact of these attacks we will dive into some detection and prevention strategies for this attack while also releasing some new proof of concept tooling to aid organizations in defending against it.
Speakers
avatar for Felipe Molina

Felipe Molina

Felipe Molina is a Spaniard hacker working in the SensePost Team at Orange Cyberdefense with 10 years of experience in the cyber security field. He loves Andalusia, Spain, to hack, to drink beer, to barbecue with family and friends, and deep diving into new software to find cool... Read More →
avatar for Szymon Ziolkowski

Szymon Ziolkowski

Szymon Ziolkowski is a pentester at the SensePost team of Orange Cyberdefense. Szymon has been in the industry for close to 8 years and enjoys application security and physical assessments - always looking for a door to open with a spoon. "He is Polish and a good guy" - Felipe Mo... Read More →
Friday September 20, 2024 11:00 - 12:00 CEST
01. Gouden Carolus

13:30 CEST

Insert coin: Hacking arcades for fun
Friday September 20, 2024 13:30 - 14:30 CEST
Since we were children we wanted to go to the arcade and play for hours and hours for free. How about we do it now? In this talk I’m gonna show you some vulnerabilities that I discovered in the cashless system of one of the biggest companies in the world, with over 2,300 installations across 70 countries, from arcades in Brazil, amusement parks in the United Arab Emirates to a famous roller coaster in Las Vegas. We will talk about API security, access control and NFC among other things.
Speakers
avatar for Ignacio Navarro

Ignacio Navarro

Ignacio Navarro, an Ethical Hacker and Security Researcher from Cordoba, Argentina. With around 6 years in the cybersecurity game, he's currently working as an Application Security. Their interests include code analysis, web application security, and cloud security.Speaker at Hackers2Hackers... Read More →
Friday September 20, 2024 13:30 - 14:30 CEST
01. Gouden Carolus

14:30 CEST

Forensic Flows, but make them better
Friday September 20, 2024 14:30 - 15:30 CEST
Digital forensic procedures often come with significant overhead, from navigating the complexities of different operating systems to lengthy processes for image collection in the cloud. Additionally, the myriad of available tools can require expertise to select and utilize effectively. Why deal with these challenges when you can automate the basics?

In this talk, we'll discuss the design of a framework aimed at automating triage-level forensics, making it accessible for all analysts to integrate into their investigations. We'll explore the open-source tools we've incorporated and the design paradigms ensuring scalability, concluding with valuable lessons learned.
Speakers
avatar for Jessica Wilson

Jessica Wilson

Jessica Wilson is a security engineer who specializes in response and forensics. She’s worked on a detection and response team for over 6 years building logging pipelines, creating forensic programs, and automating triage level forensics.
Friday September 20, 2024 14:30 - 15:30 CEST
01. Gouden Carolus

16:00 CEST

A Year in Review: Lessons Learnt from Red Teaming Gen AI
Friday September 20, 2024 16:00 - 17:00 CEST
Over the last 12 months Microsoft’s AI Red Team (AIRT) has conducted nearly 100 assessments of AI systems including comprehensive reviews of foundation models, multiple reviews of Copilot features, and in-depth reviews of AI systems in sensitive domains such as health care. From this work AIRT has developed deep knowledge of the most impactful security, safety, and privacy risks that the usage of AI systems in the real world can cause, the techniques and tooling needed to elicit them, and approaches to prevent or detect these risks.

In this presentation we will cover what AI Red Teaming is, the processes and tooling AIRT has developed, and most interesting what the key trends have been in terms of techniques and weaknesses identified during our many assessments. We will discuss how AI security issues are tightly connected with traditional cybersecurity, but also how the safety aspect of AI introduces new and exciting challenges to our work. We will also touch on how AIRT’s work has informed the development of new defenses for AI systems and security professionals should approach defending the AI systems that they use.

We will also look ahead to next year and where the risks might go next, and how we might want to prevent them in a world where AI system capabilities are evolving at an extremely rapid pace.
Speakers
avatar for Peter Bryan

Peter Bryan

"Pete leads Microsoft's AI Red Team, working to identify key security and safety risks in the AI systems Microsoft develops and uses. The team research, develop, and deploy novel attacks against AI systems and work with product teams to develop controls and mitigations for the new... Read More →
Friday September 20, 2024 16:00 - 17:00 CEST
01. Gouden Carolus

17:00 CEST

BruCON Closing
Friday September 20, 2024 17:00 - 18:00 CEST
Friday September 20, 2024 17:00 - 18:00 CEST
01. Gouden Carolus
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Timezone


Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -