{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2025.2.2"}, "schedule": {"url": "https://cfp.balccon.org/balccon2k26-2026/schedule/", "version": "0.3", "base_url": "https://cfp.balccon.org", "conference": {"acronym": "balccon2k26-2026", "title": "BalCCon2k26", "start": "2026-09-18", "end": "2026-09-20", "daysCount": 3, "timeslot_duration": "00:05", "time_zone_name": "Europe/Amsterdam", "colors": {"primary": "#5b116f"}, "rooms": [{"name": "Tesla", "slug": "5-tesla", "guid": "e0ed77fa-7e87-547c-b631-967f55cb26a5", "description": null, "capacity": 350}, {"name": "Pupin", "slug": "6-pupin", "guid": "53506c9f-44c9-55f0-aaf6-4efebf31ed1e", "description": null, "capacity": 150}, {"name": "Mileva Maric", "slug": "9-mileva-maric", "guid": "78cadd07-458c-5767-b0ba-e43720ff8dc2", "description": "Pupin 2", "capacity": 50}, {"name": "Hackerspace area", "slug": "7-hackerspace-area", "guid": "37625b47-8b40-5e6b-bbae-f9bea8e4e832", "description": null, "capacity": null}, {"name": "Lounge", "slug": "8-lounge", "guid": "f665faf1-67e1-58f9-9563-acd0482f8e45", "description": null, "capacity": null}], "tracks": [], "days": [{"index": 1, "date": "2026-09-18", "day_start": "2026-09-18T04:00:00+02:00", "day_end": "2026-09-19T03:59:00+02:00", "rooms": {"Tesla": [{"guid": "44b7daed-84b0-51d7-b178-d25966cc777b", "code": "DVY8SG", "id": 107, "logo": null, "date": "2026-09-18T13:00:00+02:00", "start": "13:00", "duration": "00:15", "room": "Tesla", "slug": "balccon2k26-2026-107-opening", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/DVY8SG/", "title": "Opening", "subtitle": "", "track": null, "type": "Lightning talk", "language": "en", "abstract": "Opening ceremony", "description": "Opening ceromony", "recording_license": "", "do_not_record": true, "persons": [{"code": "9MSMWK", "name": "BalCCon", "avatar": "https://cfp.balccon.org/media/avatars/9MSMWK_CvklKYX.webp", "biography": "Test", "public_name": "BalCCon", "guid": "f451942b-cecb-5da6-baf6-8016659f9d63", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/9MSMWK/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/DVY8SG/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/DVY8SG/", "attachments": []}, {"guid": "d73cb982-8715-589a-81e6-9412d0a7c2a6", "code": "VHWVVY", "id": 186, "logo": null, "date": "2026-09-18T13:15:00+02:00", "start": "13:15", "duration": "00:40", "room": "Tesla", "slug": "balccon2k26-2026-186-ai-can-t-solder-or-imagine-yet", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/VHWVVY/", "title": "AI can't solder or Imagine (yet)", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Now everyone is vibe coding everything. AI agents are finding vulnerabilities so obscure that humans can't market it . \r\n Is the days of \"hacking at late night banging your head against the screen\" over ? Are we now just going to prompt design our way into the history of hacking?  Maybe, maybe not.", "description": "AI has definitely changed the landscape. But while everyone is looking to find the latest and greatest prompt injection , in the forgotten back rooms there are others marching on with what they do best. Make/hack/break things.\r\n\r\nIn this talk , elkentaro will talk about some of his pre-AI days creating and hacking tools and hardware the stories behind them. He will also go on and explain how AI has changed the process for him.\r\n\r\nOriginally this talk was titled \r\n\"I wanted to be Q from James Bond..I ended up being a hacker\u201d \r\nbut without \"AI something something\" its not as hot. It will be a talk about\r\nmaking/breaking/hacking things, mostly wireless gadgets and other obsure\r\nmakings of elkentaro and how the recent rise of AI has changed some, but \r\nhasn't changed other aspects of being a hacker/maker.", "recording_license": "", "do_not_record": false, "persons": [{"code": "TFXAFH", "name": "elkentaro", "avatar": "https://cfp.balccon.org/media/avatars/TFXAFH_yi4YCr0.webp", "biography": "El Kentaro is the guy who builds wifi gadgets for fun and has been involved with the hacker community for over two decades. Kentaro enjoys watching movies and taking long warwalks at night strolling through the dark corners of Tokyo.", "public_name": "elkentaro", "guid": "1b2b72ad-1b99-5f92-a5c5-a51d0cf9e97e", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/TFXAFH/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/VHWVVY/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/VHWVVY/", "attachments": []}, {"guid": "74b9ff4e-ec94-52a8-80bd-95999ec4ce16", "code": "RNJ3DG", "id": 143, "logo": null, "date": "2026-09-18T14:00:00+02:00", "start": "14:00", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-143-a-vision-for-software-freedom-in-2048", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/RNJ3DG/", "title": "A vision for software freedom in 2048", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "Our litigation against Apple in front of the European Court of Justice, pushing for sustainable long term funding for Free Software in the EU and member states, \"Public Money? Public Code!\", Device Neutrality, Router Freedom, Free Your Android, assistance with licensing questions, a European coding competition for teenagers, and a tale of software, skateboards, and raspberry ice cream. These are some of the activities by the Free Software Foundation Europe (FSFE), which this year celebrates its 25 anniversary in empowering users to control technology.\r\n\r\nHow would the world like in our area in 2048, if the FSFE has been successful? This talk will give an overview of the FSFE's vision and invite participants to give feedback on the next decades of our journey.", "description": "Our litigation against Apple in front of the European Court of Justice, pushing for sustainable long term funding for Free Software in the EU and member states, \"Public Money? Public Code!\", Device Neutrality, Router Freedom, Free Your Android, assistance with licensing questions, a European coding competition for teenagers, and a tale of software, skateboards, and raspberry ice cream. These are some of the activities by the Free Software Foundation Europe (FSFE), which this year celebrates its 25 anniversary in empowering users to control technology.\r\n\r\nHow would the world like in our area in 2048, if the FSFE has been successful? This talk will give an overview of the FSFE's vision and invite participants to give feedback on the next decades of our journey.", "recording_license": "", "do_not_record": false, "persons": [{"code": "ZNNE3U", "name": "Matthias Kirschner", "avatar": "https://cfp.balccon.org/media/avatars/ZNNE3U_q1s8WPu.webp", "biography": "Matthias Kirschner is President of FSFE. In 1999 he started using GNU/Linux and realised that software is deeply involved in all aspects of our lives. Matthias is convinced that this technology has to empower society not restrict it. While studying Political and Administrative Science he joined FSFE in 2004.\r\n\r\nHe helps other organisations, companies and governments to understand how they can benefit from Free Software -- which gives everybody the rights to use, understand, adapt, and share software -- and how those rights help to support freedom of speech, freedom of press or privacy.\r\n\r\nIn his spare time, he has written the book \"Ada & Zangemann - A Tale of Software, Skateboards, and Raspberry Ice Cream\", which is translated in over 30 languages and meanwhile also available as a movie.", "public_name": "Matthias Kirschner", "guid": "3f6ab8c8-79c3-55bb-9172-5a86d4c2b346", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/ZNNE3U/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/RNJ3DG/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/RNJ3DG/", "attachments": []}, {"guid": "df047f4c-6f72-5313-893f-246804311a5e", "code": "AP9VB7", "id": 124, "logo": null, "date": "2026-09-18T15:05:00+02:00", "start": "15:05", "duration": "00:45", "room": "Tesla", "slug": "balccon2k26-2026-124-the-agents-of-chaos-ai-driven-malware-generation", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/AP9VB7/", "title": "The Agents of Chaos: AI Driven Malware Generation", "subtitle": "", "track": null, "type": "Talk45", "language": "en", "abstract": "With the use of AI agents catching wind across the offensive security space, from social engineering to vulnerability research, it was inevitable that malware would follow suit. While most discussions focus on targeting AI, using it to generate malicious payloads at a malware\u2019s runtime, or \u201cvibe coding\u201d it, we went a step further: we built a system where AI is the sole participant in the malware creation process itself.\r\nWe will begin by talking about how we got to this point, what sparked the idea, and jump into comparing different models \u2013 showing which gave the best code, which was most evasive, which prompts worked the best, and what we used in the agent.\r\nWe will then dig into the generation process itself \u2013 we will show the challenges with earlier approaches, how we solved them, how to build the workflow to maximize the malware\u2019s capability and randomization, how it managed to break signatures, and how to generate millions of samples.\r\nWe will finish by showing how attackers are using similar methods, look at real examples in the wild, and discuss how to use these techniques for ourselves, both as attackers and defenders.", "description": "AI has already changed the offensive security space significantly, from autonomous phishing campaigns and deepfake based social engineering to AI assisted vulnerability research and fuzzing. Malware is the next step, and the question isn\u2019t whether AI will be used to generate it, but how far that\u2019s already gone and where it leads.\r\nThis talk covers a research project that builds an autonomous agent to generate new, functional, never seen before malware samples from scratch. The focus is on the full process: what models to use and why, how to prompt them, how to ensure the output compiles and works, how to break static signatures, and how to scale generation into the millions of unique samples.\r\n\r\nThe main topics covered:\r\n\r\nAI driven offensive security and AI driven malware\r\nAI is already being used across the offensive security space, from phishing to full vulnerability research and fuzzing, and malware seems like the obvious step as AI \u201cwill replace all developers\u201d, why not malware developers? What does AI driven malware even mean? What are the different possibilities that AI in malware gives us?\r\n\r\nThe generation process: models, prompts, and workflow\r\nBefore automating anything, manual testing across of models and prompts is needed. After that, how can we ensure that the malware is random, compileable, and will work flawlessly? There are several steps that need to be taken before that can be achieved: from planning the malware, to writing and fixing it, to then actually validating its functionality with AI as a judge, all without human interaction.\r\n\r\n\r\nAdding variety in the samples\r\nThe agent makes a lot of decisions based on a plan that it creates beforehand, for example, there are several ways to traverse a directory in Windows, there are several encryption algorithms that can be used, all of these and more do affect the result. In restructuring the project from one file to several, adding different languages, asking for specific capabilities (without specifying how to implement them), all adding to the number of decisions and possibilities.\r\n\r\nAI malware in the wild\r\nMalicious actors are already using these ideas in the wild: from general vibe coding and assisted development to full autonomous agents and workflows that create full malware and attack frameworks, to deter and disrupt defence mechanisms and blue teams.\r\n\r\nTakeaways for defenders and attackers\r\nAI generated malware lowers the bar for attackers significantly: guardrails on frontier models are consistently bypassed, and local models require no permissions at all, but behaviour based detection remains effective because functional patterns persist even as signature changes. The same generation pipeline can be turned into a red teaming tool to test your own systems and see what you know about your environment.\r\n\r\nWhat Can You Gain From This\r\n\u2022\tA technical walkthrough of how an autonomous agent generates functional malware samples end to end, including the prompting strategies, model selection, and loops involved.\r\n\u2022\tTest results comparing different models, prompts, and methods, while sticking to actual detection rates.\r\n\u2022\tA framework for generating diverse malware samples at scale for use in testing detection systems.\r\n\u2022\tDocumented real world examples of AI assisted and AI integrated malware from attributed threat actors.", "recording_license": "", "do_not_record": false, "persons": [{"code": "MMJXVJ", "name": "Arad Donenfeld", "avatar": "https://cfp.balccon.org/media/avatars/MMJXVJ_I9teKG0.webp", "biography": "Arad Donenfeld is an attacks and exploits developer in SafeBreach, and has a background in security research from several roles. With his strong foundations of development, security, and operating systems internals, Arad develops tools for offensive operations, detection methods, and workflow automation. Arad focuses on practical techniques to identify and manipulate vulnerabilities and breaches, while testing and improving defenses across broad environments", "public_name": "Arad Donenfeld", "guid": "42a341bd-378a-5977-b947-b7ca36f3ca83", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/MMJXVJ/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/AP9VB7/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/AP9VB7/", "attachments": [{"title": "Slide deck and textual data about submission", "url": "/media/balccon2k26-2026/submissions/AP9VB7/resources/The_Agents_of_Chaos_AI_Drive_KHIjkqU.zip", "type": "related"}]}, {"guid": "8d7cc552-d9e0-5bef-aa33-ba96b64347bc", "code": "PQ9QZT", "id": 160, "logo": null, "date": "2026-09-18T16:00:00+02:00", "start": "16:00", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-160-comparing-malicious-files-2-0", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/PQ9QZT/", "title": "Comparing Malicious Files 2.0", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "This talk is about using LLMs to build and modernize software where correctness matters. It follows the work at two scales: modernizing a similarity-digest algorithm that must match its reference implementation bit-for-bit, and building malbench, a local-first triage and clustering workbench for malware analysts.\r\nmalbench is a local-first triage and clustering workbench for malware analysts. It pulls samples and threat intelligence from various sources, computes similarity digests, runs YARA rules, and then turns a flat pile of hashes into structure: it clusters and graphs files by features they actually share and weaves several of those lenses into a single view.\r\nI needed a wider variety of hashing algorithms, so in addition to ssdeep and TLSH, I took a dormant 2021 Go port of sdhash, a similarity-digest algorithm used in malware triage and code-reuse detection, and modernized it into a clean, dependency-free, fully-tested library. A deterministic verification corpus and parallel C++/Go harnesses turn the original reference implementation into an oracle: millions of pair comparisons, zero unexplained divergences. Around that sit total test coverage as a drift alarm, strict session and context hygiene, profile-before-you-optimize with one change measured at a time. The result is a repeatable process for adopting and modernizing old code and for building new tools on top of it.", "description": "How do you use AI models on code that has to be correct, without their confident mistakes silently landing in your output? This talk answers that with a concrete, repeatable process, demonstrated end to end on a real library, and on the larger tool that library is being built for. That tool is malbench, a local-first triage and clustering workbench for malware analysts. It pulls samples and threat intelligence from various sources, computes similarity digests, runs YARA rules, and then turns a flat pile of hashes into structure: it clusters and graphs files by what they actually share and weaves several of those lenses into one view.\r\nThe subject of the overall process is sdhash, a similarity-digest (fuzzy hashing) algorithm that fingerprints binary data into bloom filters and scores two fingerprints for similarity. It has a C++ reference by Vassil Roussev and Candice Quates and a 2021 Go port that had gone dormant for over three years. This is exactly the kind of valuable-but-abandoned code worth adopting rather than rewriting. The goal was to bring it forward into a clean, modern, dependency-free Go library with an idiomatic sealed API, full documentation, and total statement coverage.\r\nThe spine of the effort, and the core defense against hallucination, is that ground truth comes first. Before trusting a single line the model produced, I built a deterministic, seed-reproducible corpus and parallel C++/Go harnesses, ran it through both, and diffed the outputs with an independent tool. That turns the reference into an oracle: any divergence, a real bug or something a model invented, surfaces immediately as a mismatch. Generation parity held across more than a hundred thousand files and scoring parity across nearly three million pair comparisons in both modes, at zero unexplained divergences.\r\nThe process surfaced first three correctness problems in the C++ implementation scoring as well as a problem with the hashing algorithm itself. Each change to the algorithm was carefully isolated and the effects on scoring measured. This talk goes into detail all of the tooling and process used to get sdhash up to snuff and then plug it in to malbench. You will also learn about the graphing and clustering algorithms used to visualize the results of the different malware hashes.", "recording_license": "", "do_not_record": false, "persons": [{"code": "8GCJPF", "name": "Malware Utkonos", "avatar": "https://cfp.balccon.org/media/avatars/8GCJPF_3ilekmF.webp", "biography": "Robert Simmons is Principal Malware Researcher at ReversingLabs. With an expertise in building automated malware analysis systems based on open source tools, he has been tracking malware and phishing attacks and picking them apart for years. Robert, also known as Utkonos, has a background in Biology, Linguistics, and Russian Area Studies. He has spoken on malware analysis and reverse engineering at many of the top security conferences including BalCCon, DEFCON, HOPE, botconf, and DerbyCon among others. He is also the maintainer of plyara, a YARA rule parser written in pure python as well as x64dbgbinja the official connector integration between x64dbg and Binary Ninja.", "public_name": "Malware Utkonos", "guid": "333e400c-0c8a-5d77-8904-309447fdf1e1", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/8GCJPF/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/PQ9QZT/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/PQ9QZT/", "attachments": []}, {"guid": "9b886886-60e0-5521-a08e-d5bd56ba333c", "code": "BBTUHZ", "id": 185, "logo": null, "date": "2026-09-18T17:00:00+02:00", "start": "17:00", "duration": "00:30", "room": "Tesla", "slug": "balccon2k26-2026-185-hacking-in-the-middle-of-the-ocean", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/BBTUHZ/", "title": "Hacking in the Middle of the Ocean", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Modern ships have evolved into floating data centers, combining operational technology (OT), IT, satellite communications, cloud connectivity, and autonomous decision support. While digitalization has improved efficiency, it has also introduced attack surfaces that many organizations underestimate.\r\n\r\nThis presentation explores the cyber realities of today's maritime industry through the perspective of an attacker and a defender. The talk will cover common misconceptions surrounding \"air-gapped\" vessels, the unique challenges of securing ships at sea, and why traditional enterprise security approaches have challenges in maritime environments.", "description": "Talk will show some unique challenges as well as speaker vulnerability research in maritime industry.", "recording_license": "", "do_not_record": false, "persons": [{"code": "FFQRSR", "name": "Vlatko Kosturjak", "avatar": "https://cfp.balccon.org/media/avatars/FFQRSR_2A35JGN.webp", "biography": "Vlatko Kosturjak serves as the VP of research at Marlink Cyber, boasting over two decades of dedicated experience in the realms of information security and cybersecurity. His diverse roles over the years have not only equipped him with a comprehensive understanding of security governance but also delved into the deep technical side of security. \r\nAs part of Marlink group, he helps in securing different critical industries including maritime. Over many years of commercial cyber activities, he have successful M&A experience in different fields of cyber security in different roles.", "public_name": "Vlatko Kosturjak", "guid": "666d08d9-7dd3-5dfd-9a56-1745de3d099b", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/FFQRSR/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BBTUHZ/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BBTUHZ/", "attachments": []}, {"guid": "0119461b-f106-510f-8bb9-6bdf7ed79560", "code": "UEYM89", "id": 154, "logo": null, "date": "2026-09-18T17:30:00+02:00", "start": "17:30", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-154-hunting-for-business-logic-vulnerabilities", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/UEYM89/", "title": "Hunting for business logic vulnerabilities", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "Security issues are becoming harder to detect or exploit, especially in well audited targets. Instead of subverting the code flow, an attacker might try to subvert the application logic. This class of vulnerabilities is commonly referred to as business logic vulnerabilities. In this session, we will present the result of a research study where the author manually reviewed about 300 publicly disclosed vulnerability reports and tried to classify and cluster discovered vulnerabilities into a few categories that can be used to secure business logic issues in applications. So let's take a ride through some real life cases and examples on how to manipulate calculation, assumptions, processes, branching, logical and time based TOCTOU and other fun cases on how to break an modern application.", "description": "There are a number of well known classes of vulnerabilities that an enterprising hacker or penetration tester wants to uncover in an application. Some of those issues are harder to detect or exploit because of well implemented browser security mechanisms or because of various improvements in web application frameworks that hide the potentially dangerous methods from the developers. In addition to the points outlined above, the collective awareness about common security issues, vulnerabilities and potential weaknesses has been raised, making discovery of potential issues more difficult, especially in hard, well audited targets.\r\n\r\nIn such cases, instead of subverting the code flow, an attacker might try to subvert the applications logic or even better manipulate the business process that the application supports. This class of vulnerabilities is commonly referred to as business logic vulnerabilities, and when discovered in the wild and reported, all the specific and different nuanced cases of vulnerabilities are usually thrown into the bucket labeled \"business logic\" vulnerabilities. But when we review such issues, we can see that each case is unique. \r\n\r\nThis talk will present the result of a research study where the author manually reviewed about 300 publicly disclosed vulnerability reports and tried to classify and cluster discovered vulnerabilities into a few categories that can be used to detect business logic issues in applications. So let's take a ride through some real life cases and examples on how to manipulate calculation, assumptions, processes, branching, logical and time based TOCTOU and other fun cases on how to break an application.", "recording_license": "", "do_not_record": true, "persons": [{"code": "BFQ9QN", "name": "Tonimir Kisasondi", "avatar": null, "biography": "Tonimir Kisasondi is a co-founder at Apatura, a boutique security consultancy from Varazdin, Croatia. His professional and research area of interest is application security, cryptography and embedded security.", "public_name": "Tonimir Kisasondi", "guid": "2944dc58-62aa-5114-b8b9-3ea4e27ad0ee", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/BFQ9QN/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/UEYM89/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/UEYM89/", "attachments": []}, {"guid": "3ee26f99-1b28-58d0-b9fa-3cf5a4fe0cee", "code": "QF7RUJ", "id": 155, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/QF7RUJ/balccon_rUjRFK2_ZUKuXZQ.webp", "date": "2026-09-18T18:30:00+02:00", "start": "18:30", "duration": "00:30", "room": "Tesla", "slug": "balccon2k26-2026-155-you-build-vulnerable-hardware-accidentally-i-do-it-on-purpose-we-are-not-the-same-behind-the-scenes-of-building-hardware-ctf-challenges", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/QF7RUJ/", "title": "You build vulnerable hardware accidentally. I do it on purpose. We are not the same. (Behind the scenes of building hardware CTF challenges)", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "We built hardware challenges for Serbian national CTF... twice. Building a good hardware challenge is a balancing act between security, education, creativity, and logistics. The talk follows the entire process, from the initial idea and vulnerability selection to hardware and challenge design, storytelling, participant experience, manufacturing, and deployment at the competition.\r\n\r\nTechnical level: Beginner/Intermediate. No prior hardware security experience or preparation is required. The talk is intended for anyone interested in hardware, embedded systems, cybersecurity, or CTF challenge design.", "description": "Our talk presents the process of creating the hardware challenges used in the Serbian National CTF in 2025 and 2026. In both editions, we designed custom embedded devices with intentionally introduced vulnerabilities, built specifically to be exploited during the competition. From selecting realistic attack vectors and hardware components, designing PCBs and firmware, manufacturing the boards, and preparing the competition environment, to watching students solve them during the event, we were involved in every stage of the process.\r\n\r\nThis talk explores how the challenges are conceived, designed, built, and deployed. Along the way, we will discuss the technical and practical trade-offs, the lessons we learned, and the challenges of creating educational, engaging, and reliable hardware CTF tasks.\r\n\r\nThe talk is suitable for attendees with a beginner/intermediate level of technical knowledge. Whether one is interested in hardware security, embedded systems, or CTF competitions, they will gain a behind-the-scenes understanding of how hardware challenges are designed, built, and deployed. No prior experience with hardware hacking or specialized tools is required.\r\n\r\nThe talk will follow the outline below:\r\n\r\n### Motivation\r\n\r\n- Why we decided to introduce hardware challenges to the Serbian national CTF.\r\n- Inspiration from ECSC, where hardware challenges have been a regular competition category.\r\n- Our backgrounds and how the project came together.\r\n\r\n### Hardware CTF Design Principles\r\n\r\n- What makes a good hardware CTF challenge.\r\n- Constraints and trade-offs: budget, accessibility, educational value, realism, and fun.\r\n- Examples of hardware challenges from ECSC and the ideas that inspired our designs.\r\n\r\n### 2025 Challenge\r\n\r\n- Initial concept and design goals.\r\n- Hardware architecture, component selection, and PCB design.\r\n- Manufacturing.\r\n- Challenge narrative and participant experience.\r\n- Vulnerabilities and intended attack paths:\r\n\t- UART\r\n\t- eFuse\r\n\t- USB HID\r\n\t- Vulnerable OTA updates\r\n\t- Unsafe cryptographic secret storage\r\n\t- Reverse engineering\r\n    \r\n\r\n### 2026 Challenge\r\n\r\n- Design goals and concept of a fictional game console.\r\n- Hardware architecture, component selection, and PCB design.\r\n- Manufacturing.\r\n- Challenge narrative and gameplay.\r\n- Vulnerabilities and attack techniques:\r\n\t- Introductory side-channel analysis\r\n\t- SPI bus sniffing and display reconstruction\r\n\t- Logic analyzer usage\r\n\t- Timing attacks using PIO\r\n\r\n### Lessons Learned\r\n\r\n- Challenge balancing and playtesting.\r\n- Designing intentional vulnerabilities.\r\n- Manufacturing, logistics, and deployment during the competition.\r\n- What worked well and what we would do differently.\r\n\r\n### Future Directions\r\nIdeas for future competition challenges:\r\n- Glitching and fault injection.\r\n- Power analysis.\r\n- NFC/RFID.\r\n- Radio protocols.\r\n- CAN bus.", "recording_license": "", "do_not_record": false, "persons": [{"code": "MKHBWR", "name": "Maja Miljani\u0107", "avatar": "https://cfp.balccon.org/media/avatars/MKHBWR_3FZdi6P.webp", "biography": "Maja Miljani\u0107 is a teaching assistant at RAF (Faculty of Computer Science), where she teaches Operating Systems and Web Security. She also leads a small engineering agency focused primarily on IoT and embedded systems projects. Throughout her career, she has designed and implemented a wide range of IoT solutions for industrial and commercial applications involving large-scale device deployments. Her work includes smart access control systems, IoT solutions for the hospitality industry, edge devices for the energy sector, IoT charging stations, and platforms for industrial cybersecurity testing.", "public_name": "Maja Miljani\u0107", "guid": "aa60609d-fc87-526e-81fa-60e1e502cf23", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/MKHBWR/"}, {"code": "CSGCEF", "name": "TheProxy", "avatar": null, "biography": null, "public_name": "TheProxy", "guid": "a9cfd565-31cf-56d2-b379-585ef4a4ca81", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/CSGCEF/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/QF7RUJ/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/QF7RUJ/", "attachments": []}, {"guid": "4289c9b3-3350-51b2-addb-86bfb0cea13d", "code": "AKXHPM", "id": 182, "logo": null, "date": "2026-09-18T19:00:00+02:00", "start": "19:00", "duration": "00:45", "room": "Tesla", "slug": "balccon2k26-2026-182-your-lock-er-knows-your-pin-and-so-do-i", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/AKXHPM/", "title": "Your Lock(er) Knows Your PIN ... And So Do I", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Electronic lockers are everywhere - offices, gyms, hotels, hospitals, co-working spaces. You choose a PIN, toss in your stuff, and trust that it's safe. The same goes for electronic safes in hotel rooms and offices. But what does the lock actually do with your PIN? Turns out, it remembers it. And not very carefully.\r\n\r\nWe demonstrate how someone with access to a single open locker or safe can extract credentials, clone manager keys, and open every lock in an installation using cheap and widely available tools. More critically, we show how harvested PINs open more than just lockers: the same PIN that protects your locker or hotel safe often unlocks your phone, your laptop, and your bank card.\r\n\r\nWe discuss why reusing a PIN across devices is a terrible idea, how RFID credentials stored in locks can be used to open doors they were never meant to open, and whether vendors have actually fixed anything since we first told them about these issues.\r\n\r\nIf you've ever chosen the same PIN for your locker, your safe, and your phone - this talk is for you.", "description": "This talk is a continuation of our DEFCON 32 research on electronic locker locks. We discuss the general problem of how electronic locks handle user-chosen secrets, revisiting vulnerabilities in locks from multiple manufacturers. We focus on what these devices store: user PINs, RFID UIDs, manager credentials, and audit logs - often in plaintext and trivially extractable.", "recording_license": "", "do_not_record": false, "persons": [{"code": "QVMFQR", "name": "Dennis Giese", "avatar": null, "biography": "Dennis Giese is a researcher with the focus on the security and privacy of IoT devices. While being interested in physical security and lockpicking, he enjoys applied research and reverse engineering malware and all kinds of devices. His most known projects are the documentation and hacking of various vacuum robots. He calls himself a \"robot collector\" and his current vacuum robot army consists of over 95 different models from various vendors. He talked about his research at the Chaos Communication Congress, REcon, HITCON, NULLCON, and DEFCON.", "public_name": "Dennis Giese", "guid": "af9f91b9-66b0-576e-ae5a-3824b65e9f14", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/QVMFQR/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/AKXHPM/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/AKXHPM/", "attachments": []}, {"guid": "903ca1bf-a317-5e3c-baa9-77fecfb015f0", "code": "8HJGZ8", "id": 153, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/8HJGZ8/we_need_to_go_deeper_tBFmBhb_NQfRlm0_DBhJB2i.webp", "date": "2026-09-18T19:45:00+02:00", "start": "19:45", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-153-fun-with-virtualization", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/8HJGZ8/", "title": "Fun with virtualization", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "We got called to an Incident Response case. They said it was a limited incident. It turned out not to be.", "description": "Working in Incident Response sometimes means you get to go on a grand adventure, where you run into adversaries employing clever techniques to make your digital firefighting life difficult. In this talk we take you along on our journey, cover the People, Processes and Technologies angles and hopefully give you some tips and tricks for dealing with these types of threats.", "recording_license": "", "do_not_record": true, "persons": [{"code": "BCAW7M", "name": "Hank Scorpio", "avatar": "https://cfp.balccon.org/media/avatars/BCAW7M_IzkGEFl.webp", "biography": "Supervillain with a heart of gold", "public_name": "Hank Scorpio", "guid": "402e2c0a-f6e8-5e49-a3f1-c0077530e906", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/BCAW7M/"}, {"code": "8PLYSC", "name": "Scorpio Hank", "avatar": null, "biography": "IR & Security Analysis", "public_name": "Scorpio Hank", "guid": "67f9cc67-70c1-59e2-8783-3be738ea413a", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/8PLYSC/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/8HJGZ8/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/8HJGZ8/", "attachments": []}, {"guid": "7966c8e1-5d2b-5797-919b-f382f32ca7d8", "code": "ZKQTEK", "id": 172, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/ZKQTEK/card_znpKxJ7_k9AI7M5.webp", "date": "2026-09-18T22:30:00+02:00", "start": "22:30", "duration": "03:00", "room": "Tesla", "slug": "balccon2k26-2026-172-hacker-jeopardy", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZKQTEK/", "title": "Hacker Jeopardy", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "Clue: This glorious competition pits the sharpest minds and greatest nerds of this illustrous community (or, whoever want's to participate really...) against each other in a battle of wits. Contestants show their prowess and speed in hitting buzzers as well as their knowledge about modern, ancient and archaic topics ranging from security to pop culture, while the audience revels in the geeky glory.\r\n\r\nAnswer: What is Hacker Jeopardy?", "description": "We will play some rounds of hacker jeopardy. If you ask yourself: \"What the heck is Jeopardy?\", you already got the gist of the game, as all answers need to be formulated as questions! Participants will have to answer questions in different categories to get the most points. But beware, it's not only about knowing the answer, you also need to be fast with a buzzer! Are you up for the challenge?", "recording_license": "", "do_not_record": true, "persons": [{"code": "U8TRG8", "name": "cluosh", "avatar": "https://cfp.balccon.org/media/avatars/U8TRG8_UqDdXU0.webp", "biography": "PhD student at UniVie and CTF player at We_0wn_y0u. Passionate for reverse engineering, graphics programming and all kinds of low-level software development.", "public_name": "cluosh", "guid": "4a203fb1-fee3-536d-867b-dee3deaad843", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/U8TRG8/"}, {"code": "L73C8Z", "name": "georg", "avatar": null, "biography": "Senior researcher at SBA Research in Vienna, dealing mostly with systems and firmware stuff. Dabbled in pentesting as well as teaching at TU Wien. Collecting flags with [We_0wn_Y0u](https://w0y.at) for well over a decade. Tinkering with all kinds of hardware (when there's time left).", "public_name": "georg", "guid": "48e3972f-af9b-56d7-bd94-0de6d859556d", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/L73C8Z/"}, {"code": "EYZYBY", "name": "Hetti", "avatar": null, "biography": null, "public_name": "Hetti", "guid": "5f6ebc6e-cb15-5bc1-b6a4-2191ee504981", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/EYZYBY/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZKQTEK/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZKQTEK/", "attachments": []}], "Pupin": [{"guid": "33deeb35-f2ed-545e-93b2-83359debb00e", "code": "78CRUA", "id": 157, "logo": null, "date": "2026-09-18T14:00:00+02:00", "start": "14:00", "duration": "00:30", "room": "Pupin", "slug": "balccon2k26-2026-157-frost-ssd-side-channels-from-the-browser-and-why-you-should-care", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/78CRUA/", "title": "FROST: SSD Side Channels from the Browser, and Why You Should Care", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "The FROST attack fingerprints the websites and apps you use from plain JavaScript in a tab - by measuring SSD contention from the browser. We cover how it works, how realistic the attack is, and who actually needs to care.\r\nAdditionally, we show a few other remote side channels to show what is possible in theory for motivated attackers.", "description": "Earlier this year, we published \"FROST: Fingerprinting Remotely using OPFS-Based SSD Timing\". The paper made the news, likely because \"a website can spy on you if you click a link\" makes a good headline. Reactions were split: Some people wanted to disable JavaScript completely, claiming that allowing websites to execute scripts on client devices was a mistake in the first place. Others waved the attack off as a toy example that only works in a lab, never feasible in the real world.\r\n\r\nFor us, the truth lies somewhere in the middle.\r\n\r\nFROST is a real attack. From plain JavaScript, we measure SSD contention from the browser and use it to fingerprint the websites you visit and the apps you open, without requiring any additional interaction beyond clicking a malicious link.\r\nIt's also fragile: Classification depends on training data, and prior work has shown that trained models cannot easily be generalized to different SSD models.\r\n\r\nThis talk presents the attack, and gives some intuition about the underlying insights. Does the average user need to be scared? Who actually needs to care? Why do browsers allow this in the first place?  And what are side-channel attacks anyways?\r\nAdditionally, we give an overview of other remote side-channel attacks, showing what's possible in theory to a motivated attacker.", "recording_license": "", "do_not_record": false, "persons": [{"code": "RGSNSC", "name": "Hannes Weissteiner", "avatar": "https://cfp.balccon.org/media/avatars/RGSNSC_VHc5aQ1.webp", "biography": "Hannes is a PhD Candidate at Graz University of Technology in the CoreSec Group.\r\nHis research area is side-channel attacks and defenses.\r\nHe has worked on trusted execution environments, DNS and browser security.\r\nIn his free time, he sometimes still plays CTFs, including the DEF CON 2025 finals with KuK Hofhackerei.", "public_name": "Hannes Weissteiner", "guid": "34f1db01-74c0-5591-b1c7-63e5164bb10c", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/RGSNSC/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/78CRUA/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/78CRUA/", "attachments": []}, {"guid": "2343e48e-4a1e-522d-a4a6-4fb6e3f5a45c", "code": "TVDMBV", "id": 164, "logo": null, "date": "2026-09-18T14:30:00+02:00", "start": "14:30", "duration": "00:30", "room": "Pupin", "slug": "balccon2k26-2026-164-detecting-linux-rootkits-know-where-to-look-in-user-space", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/TVDMBV/", "title": "Detecting Linux rootkits: Know where to look in user-space", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Linux rootkits rely on a handful of techniques to hide malicious code. There's nothing magic that can't be overcome, we just have to know from what angle to look.", "description": "Rootkits are designed to hide themselves or other malicious software from users' and administrators' prying eyes. To create the illusion that nothing is there and everybody is fine to move along, they usually subvert tool output, standard library functions or kernel system calls to hide the presence of specific processes or files.\r\n\r\nThis illusion is often just convincing enough to fool standard tools, but if we put a little more effort into observing system behavior, we can still see shadows of what has been hidden, by relying on traces that are hard to cover by rootkit authors.\r\n\r\nIn this talk I take a look at rootkit implementations that subvert the system at different layers \u2013 the system call interface, the standard library, or through eBPF probes. I give an overview over detection techniques that have been implemented in traditional rootkit hunting scripts, plus a few novel methods. \r\n\r\nI present a modern implementation of the most promising techniques that can be integrated with existing live-forensic capabilities to hunt for rootkits at scale.", "recording_license": "", "do_not_record": false, "persons": [{"code": "NDLQES", "name": "Hilko Bengen", "avatar": "https://cfp.balccon.org/media/avatars/NDLQES_HCnn7NF.webp", "biography": "Hilko works in the CSIRT for a transportation and logistics company. He feels most comfortable when thinking about problems that touch systems programming, operations and IT security. For more than 25 years, he has learned to take free and open source software for granted and he is still amazed when he hears how others have found his contributions useful.", "public_name": "Hilko Bengen", "guid": "8f70a78d-920c-55d8-ad45-39e874724c68", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/NDLQES/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/TVDMBV/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/TVDMBV/", "attachments": []}, {"guid": "746cdb33-6be7-5216-a031-7eae8a47d194", "code": "ZXZZQN", "id": 139, "logo": null, "date": "2026-09-18T15:00:00+02:00", "start": "15:00", "duration": "00:40", "room": "Pupin", "slug": "balccon2k26-2026-139-deconstructing-modern-macos-initial-access-vectors", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZXZZQN/", "title": "Deconstructing Modern macOS Initial Access Vectors", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "For years, a persistent myth suggested that macOS was inherently immune to malware. Today, threat actors are aggressively shattering that illusion by deploying sophisticated initial access chains tailored to bypass macOS defenses. This talk provides a deep-dive analysis of how modern adversaries gain their first foothold on Apple hardware.\r\n\r\nWe will dissect the entire initial access pipeline, starting with Infection Vectors like deceptive Google Ads, malicious ClickFix campaigns, and sophisticated malvertising that trick users into lowering their guard. From there, we explore the Execution Phase, analyzing how attackers weaponize scripting languages, including traditional Bash and Python, as well as native AppleScript, Compiled AppleScript, Perl, and JavaScript for Automation (JXA). \r\n\r\nFinally, we will examine the delivery mechanisms, contrasting the abuse of native Binaries (Mach-O, Platypus-packaged apps, and Electron frameworks) with the trojanization of Storage and Installer Formats (DMGs and PKGs).\r\n\r\nAttendees will walk away with a technical understanding of contemporary macOS tradecraft, real-world attacker methodologies, and the insights needed to hunt for and defend against modern Mac-focused threats.", "description": "We begin by exploring the top of the funnel. Attackers have moved far beyond easily identifiable spam. We will deconstruct recent campaigns to show how adversaries are successfully lowering user guard through:\r\n\r\nHow threat actors weaponize Google Ads to push malicious software disguised as legitimate enterprise tools (e.g., Slack, Notion, or VPN clients).\r\nA deep dive into localized, highly convincing fake browser updates and system notification campaigns that socially engineer users into bypassing native warnings.\r\n\r\nOnce the user interacts with the lure, how does the malware actually run? macOS is a rich Unix-based environment with multiple scripting avenues. We will analyze the \"Living off the Land\" (LotL) techniques currently dominating the macOS threat landscape, including:\r\n\r\nThe use of Bash, Zsh, and legacy Python/Perl scripts to establish persistence and pull down secondary payloads.\r\nHow attackers weaponize Apple\u2019s native automation languages to silently interact with system APIs, bypass sandbox restrictions, and generate convincing fake credential prompts.\r\nTechniques used by threat actors to obfuscate their code, making static analysis incredibly difficult for defenders.\r\n\r\nFinally, we will break down how these threats are packaged to evade Gatekeeper and initial static analysis. We will compare and contrast real-world samples across:\r\n\r\nThe weaponization of standard Apple Disk Images (.dmg) and Installer Packages (.pkg), including pre-install/post-install script abuse.\r\nThe shift from standalone Mach-O binaries to hiding malicious routines inside Platypus-packaged applications and bloated Electron frameworks, which are notoriously difficult for traditional AV to parse effectively.", "recording_license": "", "do_not_record": false, "persons": [{"code": "ZJYU7Y", "name": "Stephan Berger", "avatar": null, "biography": "Stephan Berger is the Head of Investigations for an Incident Response team at InfoGuard, a Swiss-based cybersecurity firm. With over a decade of experience investigating complex network compromises, he specializes in the technical intersection of offensive tradecraft and defensive forensics. Stephan is the author of the DFIR.ch technical blog and is a regular speaker at international security conferences, including FIRST, Troopers, and hack.lu. He holds a Bachelor\u2019s degree in Computer Science and a Master\u2019s degree in Engineering and is the founder of Malmium, a specialized technical training provider.", "public_name": "Stephan Berger", "guid": "698cb298-5b68-5675-9e3e-3de45ac23fff", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/ZJYU7Y/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZXZZQN/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZXZZQN/", "attachments": []}, {"guid": "2e94864e-4bd1-5cea-bcf5-464ca9720b1a", "code": "WNJR8M", "id": 165, "logo": null, "date": "2026-09-18T16:00:00+02:00", "start": "16:00", "duration": "01:00", "room": "Pupin", "slug": "balccon2k26-2026-165-renting-brains-owning-the-mistakes-llms-in-cybersecurity-education", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/WNJR8M/", "title": "Renting Brains, Owning the Mistakes: LLMs in Cybersecurity Education", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Students already use LLMs for almost everything: explaining concepts, writing reports, debugging their labs, and sometimes skipping the hard part of learning altogether. And they will not stop when they graduate: the habits formed in a lecture hall follow them into the SOC and the codebase, which makes how we teach with these tools a security problem, not just an academic one.\r\nThis talk briefly sets out why we care about LLMs, the economics, the energy, and the jobs behind the hype, then draws on hands-on experience teaching cybersecurity at the University of Turku. I'll share where LLMs genuinely help students and where they quietly erode the skills the field depends on.", "description": "Total length : 45-50 min + 10-15 min Q&A\r\nPart 0 \u00b7 Who, and why listen\r\n\r\nwhoami: PhD researcher, occasional lecturer, TurkuSec chair; teaching cybersecurity at the University of Turku.\r\nBrief mention UTU / TurkuSec context for credibility.\r\nCore idea is that an LLM is neither enemy nor friend a tool with a user, and the user owns the mistakes.\r\n\r\n-------------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\n\r\nPart 1 \u00b7 Why we care\r\n\r\nEvangelist people think LLMs are good, and get only better, and it is impossible to get harm from it, and while they measure who burnt more tokens within 24h frames, people pay for it, and sometimes they pay too much.\r\n\r\n\"It's cheap\" \u2192 economics. Uber burned its planned 2026 AI-coding budget in four months; engineers at $500\u2013$2,000/mo; OpenClaw chewing $1\u20135k/day on a $200 plan; GitHub freezing Copilot sign-ups. At today's subsidized pricing the unit economics are propped up, not \"it will collapse,\" but someone else is absorbing the bill.\r\n\r\n\"It's eco-friendly\" \u2192 energy & where it lands. Tiny per prompt (0.24 Wh) vs vast in aggregate (~945 TWh by 2030); Jevons paradox; Google's own emissions up despite efficiency gains \u2192 then the local cost: Vantage VA, xAI Memphis, and externalities on bills, rent, land, sleep. LLM data centers cause severe pollution and harm people.\r\n\r\n\"It's a revolution, not a bubble\" \u2192 jobs & failures. Layoffs framed as AI efficiency (Oracle, Meta, Microsoft, Amazon); real-world breakage (AWS/Kiro outage, the wiped DataTalks database, the Fastly senior-vs-junior split).\r\nThese claims are backed by independent papers and expert review of the waste and pollution LLMs produce.\r\nOther claims supporting the point are interviews of local people complaining about noise, pollution and general detrimental impact of LLMs.\r\nStudents use these tools constantly and won't stop at graduation. The habits formed in the lecture hall walk into the SOC. So this is an education problem \u2014 which is where the rest of the talk lives.\r\n\r\n-------------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\nPart 2 \u00b7 The new learning reality\r\nTaking Part 1 into account, why don't we want students to abuse LLMs? What they do at University becomes a habit once they start working.\r\n\r\nStudents already use LLMs for everything (to explain, to summarize, to write, to code, to debug, to exam-prep, and sometimes to skip the learning entirely).\r\nUTU permits responsible use; the question is no longer whether but how.\r\nGoogle-fu is dying from \"find and think\" to \"ask and accept\" (StackOverflow decline; same effect we observe at university, students do not google basic problems, and when LLM troubleshooting fails they immediately email us, and we reply with the first link on google).\r\nThe real problem: usage without structure, without knowing what these tools are good at, bad at, and where they quietly fail.\r\n\r\n-------------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\nPart 3 \u00b7 Where it quietly erodes \u2014 the bad\r\n\r\nFaster learning, weaker thinking: outsourcing the struggle \u2260 growth; a correct output doesn't prove understanding.\r\nMost students don't verify; fluency is mistaken for correctness; beginners are most exposed to smooth nonsense.\r\nSince most of the students LACK the experience (especially relevant for bachelor students), they immediately believe LLM, even when the facts are wrong.\r\nHands-on skills vs AI assistance: learn the underlying skill before automating it. Some students lack basic IT skills, and LLM is making it worse.\r\nThe purpose of homework is to solidify the knowledge on the matter, not to feed it to LLM for training the model and getting your answers.\r\nSharing a couple of negative examples from teaching time at UTU (no text on slide, but rather storytelling, 3 mins)\r\nSharing students' feedback on LLM incorporation to the course (This is being collected currently, ready in August)\r\n\r\n-------------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\nPart 4 \u00b7 The flip: where it genuinely helps \u2014 the good\r\n\r\nThe pivot: same tool, different user. The fluent output that fools a beginner teaches a careful student what good looks like.\r\nPersonal tutor: patient, available at 2am, removes the social cost of asking \u2014 especially for shy, Finnish, and non-native students.\r\nFrom theory to \"it works\": environment-specific debugging companionship; the moment students used to quit becomes the moment they get unstuck.\r\nIt generates a lot of research avenues \u2192 master's/bachelor's theses, PhD dissertations, research assistants.\r\nForce multiplier for instructors: faster lab design, exam variants, tighter feedback loops.\r\nSelf-study that finally works; serious entry points beyond the syllabus.\r\nLanguage equity: non-native speakers judged on their security thinking, not their prepositions.\r\nSharing a couple of positive examples from teaching time at UTU (no text on slide, but rather storytelling, 5-6 mins)\r\nSharing the students' feedback on LLM incorporation to the course (This is being collected currently, ready in August)\r\n\r\n-------------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\nPart 5 \u00b7 Why verification is the whole game \u2014 capstone risk\r\n\r\nThe hardest risk we are afraid of at UTU isn't hallucination, it's bias you can't see.\r\nHistorical analogues: Sugar Research Foundation / Harvard (1967); Coca-Cola's GEBN; Merck/Vioxx ghostwriting (~55k deaths, Graham's FDA testimony).\r\nThose manipulations had to clear high bars and fool trained audiences. The audience for LLMs is everyone \u2014 including future doctors and regulators, while they're still students.\r\nThe 2+2=5 problem: we learned to question the press and social media; we haven't learned to question the model. The presentation is the persuasion.\r\nWhat if tomorrow an LLM starts telling students that telnet is a good idea or introduces some subtler bias? Because students trust the model, they won't double-check the claim; they'll simply believe it.\r\n\r\n-------------------------------------------------------------------------------------------------------------------------------------------------------------------\r\n\r\nPart 6 \u00b7 Takeaways & close\r\n\r\nNeither enemy nor friend; a tool with a user, but the current approach is alarming\r\nVerification is the new baseline literacy.\r\nCompress work, don't replace judgment.\r\nCybersecurity education is uniquely positioned to lead.\r\nThe students who benefit most are the ones we were quietly losing.", "recording_license": "", "do_not_record": false, "persons": [{"code": "WVPEHV", "name": "Ismayil", "avatar": "https://cfp.balccon.org/media/avatars/WVPEHV_a3aKa8X.webp", "biography": "Official for Media: Project Researcher at the University of Turku\u2019s Cyber Security Lab. Ismail earned his M.Sc. in Information and Communication Technology from the University of Turku in 2023. He serves on the board of VSTKY and chairs TurkuSec ry, Finland\u2019s oldest citysec group. One of the main organizers of Disarray 2025&2026. With over 7 years of industry experience, his interests include network security, cybersecurity policies, and the secure and responsible use of LLMs and AI in cybersecurity.\r\n\r\nNon-official:\r\nChairman at TurkuSec, active member of Finnish Cybersecurity community, organizing different security events, volunteering at Disobey, since recently started giving talks :)", "public_name": "Ismayil", "guid": "1fcf6e6f-a16c-5b38-8ffa-603ff3bbae2f", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/WVPEHV/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/WNJR8M/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/WNJR8M/", "attachments": [{"title": "work in progress slides. Currently finilizing them, should be done soon.", "url": "/media/balccon2k26-2026/submissions/WNJR8M/resources/BalcCon_talk_proposal_wip_gsYAxlg.pdf", "type": "related"}]}, {"guid": "d2f8d73e-6c30-59ed-8c03-fb6ab2bb6c7a", "code": "KYZCRH", "id": 178, "logo": null, "date": "2026-09-18T17:00:00+02:00", "start": "17:00", "duration": "00:30", "room": "Pupin", "slug": "balccon2k26-2026-178-human-error-is-not-the-problem-how-hiring-culture-and-psychology-shape-cyber-risk", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/KYZCRH/", "title": "Human Error Is Not the Problem: How Hiring, Culture and Psychology Shape Cyber Risk", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Cybersecurity conversations often treat \u201chuman error\u201d as the weakest link, but in real organizations the problem usually starts much earlier: in hiring, onboarding, incentives, culture, unclear ownership, social pressure, burnout and badly designed internal processes.\r\n\r\nThis talk connects cybersecurity with organizational psychology and HR practice. It explores how companies unintentionally create human-risk conditions long before an employee clicks a phishing link, shares access, ignores a policy, trusts a fake profile or bypasses a procedure to \u201cget the job done\u201d.\r\n\r\nThe session is intended for security professionals, founders, HR people, managers and anyone interested in the human side of security. It will be practical and beginner-friendly, with examples from recruitment, employee assessment, fake identities, insider-risk patterns and security culture. The goal is not to blame people, but to show how organizations can reduce cyber risk by designing better human systems.", "description": "1. Introduction: why \u201chuman error\u201d is an incomplete explanation\r\nThe talk starts by challenging the usual narrative that people are simply careless, lazy or untrained. In many cases, insecure behavior is a predictable result of the environment: pressure, unclear responsibilities, weak processes, bad communication and poor hiring decisions.\r\n\r\n2. Where cyber risk begins before the cyber team sees it\r\nThis part explains how risk enters the organization through recruitment, onboarding, role design, access decisions and organizational culture. Examples include rushed hiring, unverified candidates, fake profiles, poor reference checking, excessive access, lack of psychological safety and unclear escalation paths.\r\n\r\n3. Social engineering and the psychology of trust\r\nThe talk explores why people trust the wrong signals: authority, urgency, familiarity, similarity, politeness and fear of conflict. It connects phishing, impersonation, fake candidates and internal manipulation to basic psychological mechanisms.\r\n\r\n4. Insider risk without Hollywood drama\r\nThis section explains that insider risk is not only malicious employees stealing data. It can also include frustrated employees, overloaded teams, people bypassing procedures, unmanaged contractors, unclear accountability and people with access they no longer need.\r\n\r\n5. Why awareness training is not enough\r\nSecurity awareness often fails because it treats people as isolated decision-makers. The talk explains why behavior changes only when incentives, workflows, leadership behavior and consequences are aligned.\r\n\r\n6. What HR and security teams should do together\r\nThe final practical section suggests a basic cooperation model between HR, security and leadership: better hiring checks, access hygiene, role-based onboarding, psychological safety for reporting, exit procedures, manager training and clearer internal communication.\r\n\r\n7. Conclusion\r\nThe talk ends with a simple message: people are not the weakest link by default. Poorly designed systems make them weak. Better human systems create better security.", "recording_license": "", "do_not_record": false, "persons": [{"code": "EC9H9M", "name": "Nata\u0161a Vasi\u0107", "avatar": "https://cfp.balccon.org/media/avatars/EC9H9M_86QPSUw.webp", "biography": "Natasha is an HR strategist and founder of Konsultallika, with a background in psychology and extensive experience in recruitment, candidate assessment and organizational consulting. She has interviewed thousands of professionals across IT, cybersecurity, consulting, finance and international institutions. Her current work focuses on the connection between human risk, organizational behavior and cybersecurity, especially how hiring, culture and internal systems influence security outcomes.", "public_name": "Nata\u0161a Vasi\u0107", "guid": "3be6a6db-6eae-520c-92e0-b6d9f13e320b", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/EC9H9M/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/KYZCRH/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/KYZCRH/", "attachments": []}, {"guid": "5c87bc5c-d509-50c6-8727-6bc68070d349", "code": "MPPFNF", "id": 171, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/MPPFNF/info_s_W6iKcjD_DdFjzZg.webp", "date": "2026-09-18T17:30:00+02:00", "start": "17:30", "duration": "01:00", "room": "Pupin", "slug": "balccon2k26-2026-171-the-hitchhikers-guide-to-hacking-cheap-bluetooth-speakers", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/MPPFNF/", "title": "The Hitchhikers Guide to Hacking Cheap Bluetooth Speakers", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "The story so far: In the beginning closed Hard- and Software was created.\r\nThis has made a lot of people very angry and been widely regarded as a bad move.\r\n(Wrong book, I know...)", "description": "Deep inside the shelves of our nearest IKEA store, hidden between smart appliances, there lies the cheap IKEA KALLSUP, a Bluetooth speaker, that promises limitless possibilities. Well, maybe not limitless. But it does allow synchronization of up to 100 devices. Supposedly at least, we did not buy 100 of them. However, it is not this promise of connectivity that caught our attention, but the curiosity about the intricacies of the internals of such a cheap device. \r\n\r\nFollow us along on our journey into the unknown, hitchhiking on the experiences made by those who came before us, while we dive into reverse engineering of cheap, undocumented chips, analyzing firmware, and other general tomfoolery.", "recording_license": "", "do_not_record": false, "persons": [{"code": "L73C8Z", "name": "georg", "avatar": null, "biography": "Senior researcher at SBA Research in Vienna, dealing mostly with systems and firmware stuff. Dabbled in pentesting as well as teaching at TU Wien. Collecting flags with [We_0wn_Y0u](https://w0y.at) for well over a decade. Tinkering with all kinds of hardware (when there's time left).", "public_name": "georg", "guid": "48e3972f-af9b-56d7-bd94-0de6d859556d", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/L73C8Z/"}, {"code": "U8TRG8", "name": "cluosh", "avatar": "https://cfp.balccon.org/media/avatars/U8TRG8_UqDdXU0.webp", "biography": "PhD student at UniVie and CTF player at We_0wn_y0u. Passionate for reverse engineering, graphics programming and all kinds of low-level software development.", "public_name": "cluosh", "guid": "4a203fb1-fee3-536d-867b-dee3deaad843", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/U8TRG8/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/MPPFNF/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/MPPFNF/", "attachments": []}, {"guid": "c5692181-0a8b-5dc8-aa98-4f4b39c95549", "code": "BZXNHH", "id": 170, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/BZXNHH/banner_LOb6LsU_Txymfnl.webp", "date": "2026-09-18T18:30:00+02:00", "start": "18:30", "duration": "02:00", "room": "Pupin", "slug": "balccon2k26-2026-170-a-street-sign-a-shadow-and-an-answer-osint-workshop", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/BZXNHH/", "title": "A Street Sign, a Shadow, and an Answer: OSINT Workshop", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Somewhere in a public photograph, a street sign is partially visible. The shadow falls at a specific angle. Someone left a comment years ago that does not quite add up. These details are not hints, they are evidence, sitting in the open the whole time.\r\n\r\nThis workshop is a two-day journey into modern OSINT methodology. On the first day, we'll break down real investigations live, showing how publicly available information can be turned into precise, defensible conclusions. On the second day, the theory disappears and the investigation begins, as participants tackle a series of increasingly challenging OSINT cases in a competitive CTF-style hackathon. Bring a laptop, a browser, and a willingness to chase rabbit holes.", "description": "The workshop is split across two conference days.\r\n\r\nDay one is a practical introduction to investigative methodology through live demonstrations and guided walkthroughs. Rather than memorising tools, participants learn how to think like investigators: building hypotheses, verifying evidence, eliminating bad assumptions, and documenting conclusions that others can reproduce. Topics include geolocation, image verification, archive research, metadata, social media investigation, and practical search techniques, all demonstrated using publicly available information.\r\n\r\nDay two is a competitive OSINT CTF/Hackathon where participants apply those techniques to solve a series of progressively harder challenges inspired by real investigations. Teams of up to three compete to identify people, places, events, and relationships using only open sources. Challenges reward both speed and investigative rigour, with recognition for the fastest verified solutions as well as the most elegant investigative process.\r\n\r\nAfter spending several hours forcing ambiguous information into defensible answers, participants often find themselves applying the same methodology everywhere else, from incident response and threat intelligence to random travel photos and breach data. The goal is not simply to teach OSINT, but to develop a way of approaching problems that remains useful long after the workshop ends.", "recording_license": "", "do_not_record": false, "persons": [{"code": "EXZPC7", "name": "Jurica Radovi\u0107", "avatar": "https://cfp.balccon.org/media/avatars/EXZPC7_BwzwtcH.webp", "biography": "SOC operator and offensive security practitioner with a habit of pulling at things until they break and then figuring out why. Core interests are OSINT, social engineering, and finding the cracks in systems that were never supposed to be tested.\r\n\r\nNever formally grew up in the golden era of hacker culture, but feels deeply at home in it anyway. The kind of person who was handed a keyboard before they could read and never really found a reason to put it down. Enthusiastic about anything that involves taking something apart, technically or socially.\r\n\r\nA regular at community security events, with strong views on privacy, surveillance, and the kind of curiosity that does not really have an off switch.", "public_name": "Jurica Radovi\u0107", "guid": "29366c91-7814-5da2-ba0a-51a6795b96ce", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/EXZPC7/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BZXNHH/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BZXNHH/", "attachments": []}, {"guid": "3a4a5f2f-bd14-504c-99d2-f6c44d26b92f", "code": "USMV9H", "id": 174, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/USMV9H/hacktheplanet_XVfW6ZX_78TT3VE_fsikLto.webp", "date": "2026-09-18T20:30:00+02:00", "start": "20:30", "duration": "02:00", "room": "Pupin", "slug": "balccon2k26-2026-174-from-zero-to-root-in-120-minutes-introduction-to-wordpress-hacking", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/USMV9H/", "title": "From Zero to root in 120 minutes - Introduction to Wordpress Hacking", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "Using Kali-Linux and Metasploit to Hack Wordpress\r\n\r\nYou know the impressive visuals from TV series and Moviies. The Hacker opens a black console window, types fast on the keyboard and suddenly has root on the target system, saving the day. But how does this look like in reality?\r\n\r\nIf you drop by with a Laptop running Kali-Linux either from USB-Stick or from within a virtual machine, I will walk you through the necessary steps. From analyzing the target system, finding exploits on it on to successfully hacking the \"victim\" using metasploit. And if you are quick enough and behave, we might even get so far as to remotely crash the system.", "description": "This is an introductionary level workshop targeted at a novice/beginner level audience that wants to learn how \"hacking\" actually works. InfoSec personel and other \"professionals\" attending this session will get shanghaied into supporting the other attendees. \r\n\r\nPrerequisites: Bring your own/a Laptop running a recent version of Kali-Linux inside a virtual machine or from a USB stick.", "recording_license": "", "do_not_record": true, "persons": [{"code": "CJXCJN", "name": "leyrer", "avatar": "https://cfp.balccon.org/media/avatars/CJXCJN_GRKYGRV.webp", "biography": "Providing IT-Wizardry for money for over 20 years. Boldly managing systems where angels fear to tread. Easily distracted by everything shiny, blinky and new.", "public_name": "leyrer", "guid": "ba515af2-1ebd-53d4-b315-9dc2ddbe114c", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/CJXCJN/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/USMV9H/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/USMV9H/", "attachments": []}], "Lounge": [{"guid": "a178e7bf-dcd7-5807-b4de-e9e8fb65a11c", "code": "JRDFXS", "id": 116, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/JRDFXS/KaaS_ztKm6C7_ShvQinD.webp", "date": "2026-09-18T22:00:00+02:00", "start": "22:00", "duration": "11:06", "room": "Lounge", "slug": "balccon2k26-2026-116-karaoke-some-sing-to-remember-some-sing-to-forget", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/JRDFXS/", "title": "Karaoke - Some sing to remember, some sing to forget", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "Despite past Karaoke events, the BalCCon Crew still seems to demand more!\r\nWe shall deliver.\r\n\r\n\r\nYour first time at Karaoke? Sing together with other people!\r\nQuestions about Karaoke? Approach MacLemon during the event! (Ideally *before* the Karaoke event.)", "description": "People attend. People sing.\r\nEveryone has a good time.", "recording_license": "", "do_not_record": true, "persons": [{"code": "LBHNT8", "name": "MacLemon", "avatar": "https://cfp.balccon.org/media/avatars/LBHNT8_dPed7Zz.webp", "biography": "Known for community shenanigans like Karaoke and bringing people together. Also does strange things (to and) with Macs, BSD, automation, 3d-printing, model building and radio communications. Rumoured to be the proprietor of an extensive collection of USB-Testing devices.\r\n\r\nAll my content is always free from AI-slop!", "public_name": "MacLemon", "guid": "838ea939-1108-54e0-90a3-25a493a96684", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/LBHNT8/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/JRDFXS/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/JRDFXS/", "attachments": []}]}}, {"index": 2, "date": "2026-09-19", "day_start": "2026-09-19T04:00:00+02:00", "day_end": "2026-09-20T03:59:00+02:00", "rooms": {"Tesla": [{"guid": "a709e5df-70ca-5ff6-a14f-dca71658fa61", "code": "UZQQAG", "id": 183, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/UZQQAG/IMG_2061_cBsSjB9_dTpyN7y.webp", "date": "2026-09-19T11:00:00+02:00", "start": "11:00", "duration": "00:50", "room": "Tesla", "slug": "balccon2k26-2026-183-digital-oncologists-require-cyber-care-securing-ai-agents-in-radiotherapy", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/UZQQAG/", "title": "Digital Oncologists Require Cyber Care - Securing AI Agents in Radiotherapy", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "Artificial intelligence is rapidly transforming healthcare, often elevating user experience and improving operational efficiency. In some domains, however, AI is no longer just a convenience \u2014 it has become essential. Radiotherapy is one such area. As patient volumes surge, digital oncology systems require significantly higher levels of autonomy to sustain safe, timely, and high\u2011quality care. This includes not only treatment management, but increasingly, elements of treatment planning as well.\r\n\r\nIn this context, cybersecurity is no longer a supporting function; it is a foundational prerequisite for reliable cancer care. The encouraging news is that robust protection is achievable by applying mature, well\u2011established security standards \u2014 adapted thoughtfully for AI\u2011driven clinical environments. Frameworks such as MITRE ATLAS offer structured approaches tailored to adversarial threats against machine learning systems.\r\n\r\nThis presentation explores the unique cybersecurity challenges introduced by AI\u2011enabled healthcare applications and demonstrates a practical strategy for addressing them through a focused use case: an AI Agent designed to support radiotherapy management.", "description": "- Cancer care enabled by AI\r\n- MITRE ATLAS & SAFE-AI Crash Course\r\n- Case Study: Radiotherapy Management Agent - From Threat Model to Pentest Report", "recording_license": "", "do_not_record": false, "persons": [{"code": "AUNRZR", "name": "Jani Kovacs", "avatar": "https://cfp.balccon.org/media/avatars/AUNRZR_R5znvW1.webp", "biography": "Janos Kovacs is an enthusiast of securing Healthcare IT products, with a decade of experience gained in the field of product cybersecurity. He has contributed to the establishment of the product cybersecurity management systems for several global manufacturers. Since 2025 he works on keeping cancer treatment secure as part of Siemens Healthineers-Varian Product Cybersecurity Team.", "public_name": "Jani Kovacs", "guid": "5fffd8c1-6c39-5373-b514-dc18b3b43faa", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/AUNRZR/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/UZQQAG/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/UZQQAG/", "attachments": []}, {"guid": "71ad686a-d872-55e7-ab14-612da8e56bf3", "code": "EP88CX", "id": 141, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/EP88CX/Screenshot_From_2026-06-08_18-00-50_O_mgFMvCQ.webp", "date": "2026-09-19T12:00:00+02:00", "start": "12:00", "duration": "00:45", "room": "Tesla", "slug": "balccon2k26-2026-141-regoc-my-sw-hw-ai-team", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/EP88CX/", "title": "REGO\u010c my SW/HW AI team", "subtitle": "", "track": null, "type": "Talk45", "language": "en", "abstract": "REGO\u010c is my crew of specialized AI agents \u2014 architect, engineer, researcher, security, QA and more \u2014 that I work with daily through Telegram and voice to deliver real things: help in PCB design, firmware, reverse-engineering ...", "description": "Over the past year I've been using REGO\u010c \u2014 my team of 11 AI agents \u2014 to work on real hardware projects, not just chat demos. We ported the legendary **PDP-1 to the ULX3S FPGA**, try to brought up the open-source **GateMate FPGA Ethernet** stack with the KSZ9031 PHY, and reverse-engineered the **Chasing Gladius Pro underwater drone** \u2014 sniffing MAVLink, RTP video and the WiFi handshake to build our own control PWA on a Raspberry Pi. On the simulation side, we built **FTSIM**, an openEMS-based pipeline that runs FDTD signal-integrity checks on real PCB Gerbers across seven different boards. We also built a small **EMC pre-certification UI** for our in-house lab, and used the agents as a permanent \"second pair of eyes\" for **KiCad** \u2014 catching footprint mistakes, validating diff-pair routing, generating Gerber exports and fixing weird stackup issues before they hit production.", "recording_license": "", "do_not_record": false, "persons": [{"code": "983DZQ", "name": "Goran", "avatar": "https://cfp.balccon.org/media/avatars/983DZQ_1XR5zX0.webp", "biography": "Goran Mahovli\u0107 (electronics tech) worked for years in repair shop for informatics and bank equipment. Moved on to a developer for low power wireless technologies (LoRA/nbIOT) and measuring systems. Currently self employed in Intergalaktik d.o.o. working on opensource HW solutions, mostly FPGA boards. With constant urge to take apart any device within reach and find out it\u2019s secrets, Goran is equally successful at hardware and software hacking, from cheap products, up cycling old tech, to serious work in technology and microprocessor development. He is a tech coordinator at Radiona. In past, Goran led a number of accomplished workshop and presentations, regular member of Radiona projects and exhibitions, lead and founder of Radiona SmartZG network. Among his work is founding the Lemilica.com portal, for which he writes.", "public_name": "Goran", "guid": "feddb5f2-5a2e-508e-84b9-a969681ce30f", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/983DZQ/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/EP88CX/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/EP88CX/", "attachments": []}, {"guid": "d2e81b30-d2e8-5238-9b2f-962bcedc8f98", "code": "JYK3BH", "id": 177, "logo": null, "date": "2026-09-19T12:45:00+02:00", "start": "12:45", "duration": "00:45", "room": "Tesla", "slug": "balccon2k26-2026-177-universal-plug-and-pwn", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/JYK3BH/", "title": "Universal Plug and Pwn", "subtitle": "", "track": null, "type": "Talk45", "language": "en", "abstract": "In under an hour we will show how cheap IoT devices can expose serious security risks in your home network\r\n\r\nWe analyzed a range of low-cost connected devices and will present\r\nthe best vulnerabilities we found.\r\n\r\nFollowing our analysis of low low-cost connected devices, we will give an introduction to IoT pentesting.\r\nConcretely we present our methodology to analyze real-world devices and\r\npresent our findings and uncovered exploitation paths.\r\n\r\nFinally we will talk about mitigations and discuss why exploiting IoT devices in 2026 is still as easy as\r\na decade ago.", "description": "The talk will cover the following topics:\r\n\r\n- Opening up the devices\r\n- Dumping the Firmware\r\n- Firmware Reverse Engineering\r\n- Identifying interesting entry points\r\n- Vulnerabilities we uncovered\r\n- Mitigations\r\n- Keeping your own devices safe\r\n\r\nThis talk is suitable for beginners.\r\nWe will show how to start analyzing your own devices, and how easy it is to exploit devices where security was not a priority during development.", "recording_license": "", "do_not_record": false, "persons": [{"code": "XPTTXJ", "name": "Andreas", "avatar": null, "biography": "Andreas is a student at Graz University of Technology with a strong interest in offensive security, systems programming, and low-level exploitation. My work focuses on understanding software at the boundary between source code, binaries, operating systems, and hardware, with a particular interest in vulnerability research, reverse engineering, and binary exploitation.", "public_name": "Andreas", "guid": "fe12d4c8-db66-5e69-8870-77a75ac1c943", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/XPTTXJ/"}, {"code": "GYWUZC", "name": "Markus", "avatar": null, "biography": null, "public_name": "Markus", "guid": "d14d046b-1bd9-5172-9d86-7b1e3f85110d", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/GYWUZC/"}, {"code": "DD7CGY", "name": "Kevin", "avatar": null, "biography": "I am a master student at Graz University of Technology with a major in Information Security. I'm passionate about security, privacy, automation and I love building IT infrastructure.\r\n\r\nWebsite: https://saiger.dev\r\nGithub: https://github.com/csskevin", "public_name": "Kevin", "guid": "618efb39-46f8-5e16-9de6-aea363fd2b57", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/DD7CGY/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/JYK3BH/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/JYK3BH/", "attachments": []}, {"guid": "4d8aef43-e66c-5202-81ca-94c4e42df676", "code": "J8S7WP", "id": 149, "logo": null, "date": "2026-09-19T13:30:00+02:00", "start": "13:30", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-149-cryptography-with-serbian-eid-cards", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/J8S7WP/", "title": "Cryptography with Serbian eID Cards", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "The PKCS#11 standard enables easy integration of hardware tokens with a wide range of software applications, including document suites, web browsers, and password managers. In this talk, we will introduce the fundamentals of PKCS#11 v2 and review a year-long journey of developing an open-source PKCS#11 module for Serbian eID cards. We will present three black-box techniques that were used to analyze proprietary software, and explain how they helped us understand the original PKCS#11 module for Serbian eID cards. The talk does not require prior knowledge of PKCS#11 or smart cards, but basic familiarity with public-key cryptography, web services, and shared libraries is recommended.", "description": "60-minute lecture in which you will learn more than you ever wanted to know about Serbian eID cards", "recording_license": "", "do_not_record": true, "persons": [{"code": "LZD8DW", "name": "Nikola Ubavi\u0107", "avatar": null, "biography": "By some strange chain of events, Nikola became the author and maintainer of several open-source projects related to digital documents in Serbia. When he is not maintaining those projects, he writes about mathematics and functional programming.", "public_name": "Nikola Ubavi\u0107", "guid": "5adde00a-eb14-5280-ba33-583de2919d89", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/LZD8DW/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/J8S7WP/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/J8S7WP/", "attachments": []}, {"guid": "b7243107-f3f6-5dce-9a10-92755dabb00b", "code": "REHJAL", "id": 162, "logo": null, "date": "2026-09-19T14:30:00+02:00", "start": "14:30", "duration": "00:30", "room": "Tesla", "slug": "balccon2k26-2026-162-why-you-shouldn-t-worry-about-your-sap-systems-or-should-you", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/REHJAL/", "title": "Why you shouldn\u2019t worry about your SAP systems\u2026 or should you?", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "SAP powers some of the world's most critical business processes and that's exactly why attackers love it. Despite its importance, SAP security remains a blind spot for many security teams.\r\nDrawing on a decade of hands-on experience defending SAP environments, this session explores why SAP systems are such attractive targets, how the threat landscape has evolved, and the security pitfalls that organizations repeatedly overlook. Through real-world lessons learned, we'll examine common misconfigurations, overlooked attack paths, and the unique challenges of securing enterprise-critical SAP systems.\r\nRather than focusing solely on what can go wrong, the session also provides practical guidance on improving SAP security hygiene, reducing attack surface, and preventing the issues that attackers most commonly exploit.\r\nWhether you're a security practitioner, SOC analyst, penetration tester, or architect with little or no prior SAP experience, you'll leave with a clearer understanding of the risks hidden within SAP environments and actionable ideas to better protect one of the enterprise's most valuable assets.\r\nThis is a vendor-neutral, non-commercial session focused entirely on practical knowledge, real-world experience, and lessons learned from the field.", "description": "The talk will include the following aspects:\r\n1. Understanding SAP in the Enterprise Landscape:\r\n- what SAP is and its role in large organisations\r\n- overview of the most widely used SAP products by the business, IT and OT\r\n- business processes typically managed by SAP systems.\r\n2. SAP Architecture and Deployment Models:\r\n- common SAP deployment models and security considerations\r\n- common integrations with core enterprise systems and potential pivoting possibilities \r\n- typical trust relationships and common attack surfaces.\r\n3. Security Challenges and Vulnerability Trends:\r\n- the most common SAP vulnerabilities and misconfigurations\r\n- recent security trends and attack techniques\r\n- why SAP environments are often a blind spot for SOC and security teams.\r\n4. Improving SAP Security and Visibility\r\n- protection strategies for SAP environments\r\n- detection and monitoring approaches for SOC teams\r\n- immediate actions to strengthen SAP security posture.", "recording_license": "", "do_not_record": false, "persons": [{"code": "8NUXU3", "name": "Anita Cwynar", "avatar": null, "biography": "Anita Cwynar, CISSP, GDSA, GICSP, SABSA-certified application security specialist with over a decade of work experience in FMCG and high-tech industries, strengthening security posture across 1st and 2nd line of defense teams in Europe and Asia. Currently based in the Netherlands and focused on protecting core enterprise platforms at one of the biggest European companies.", "public_name": "Anita Cwynar", "guid": "a1d274a3-aadb-5e9b-9a54-174902b7d64e", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/8NUXU3/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/REHJAL/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/REHJAL/", "attachments": []}, {"guid": "afaa664f-7114-5a7e-a773-798c6c4fa027", "code": "PX8LSH", "id": 117, "logo": null, "date": "2026-09-19T15:00:00+02:00", "start": "15:00", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-117-compression-how-does-it-even-work", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/PX8LSH/", "title": "Compression, how does it even work?", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Compression is all about getting more out of less. We're `zip`ping through different algorithms while packing some bits. Let's find out why there's so many occurrences of the letter Z in compression and also see why compressing some data may end up larger than before.\r\nAfter this talk you'll be confident how to make files smaller and when to not bother trying because you already know why it won't work.", "description": "This talk is part of my foundational technologies arc, which includes these topics:\r\n\r\n(In alphabetical order.)\r\n\r\n- Backups\r\n- Colour\r\n- Email Systems\r\n- Emoji\r\n- Encoding\r\n- Fonts and Typography\r\n- HTTP/2\r\n- USB (2 talks)\r\n- various shell tools, including `ssh` and `tmux`", "recording_license": "", "do_not_record": false, "persons": [{"code": "LBHNT8", "name": "MacLemon", "avatar": "https://cfp.balccon.org/media/avatars/LBHNT8_dPed7Zz.webp", "biography": "Known for community shenanigans like Karaoke and bringing people together. Also does strange things (to and) with Macs, BSD, automation, 3d-printing, model building and radio communications. Rumoured to be the proprietor of an extensive collection of USB-Testing devices.\r\n\r\nAll my content is always free from AI-slop!", "public_name": "MacLemon", "guid": "838ea939-1108-54e0-90a3-25a493a96684", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/LBHNT8/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/PX8LSH/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/PX8LSH/", "attachments": []}, {"guid": "d8ad7f59-b708-55a2-9d64-74f8d671bb3d", "code": "E7GFPG", "id": 135, "logo": null, "date": "2026-09-19T16:00:00+02:00", "start": "16:00", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-135-reverse-engineering-fermax-detour-dead-end-and-scope-creep", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/E7GFPG/", "title": "Reverse Engineering FERMAX: Detour, Dead End, and Scope Creep", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "Kirils & friends got so excited about the FERMAX intercom system, that they nerd-sniped Iceman to join in on the hunt for MIFARE Desfire cards.\r\n\r\nThis is a journey into research on a shoe string and our realizations under the way. Detours, Dead Ends and Scope Creep are real.", "description": "When reverse engineering the proprietary DUOX PLUS intercom system dubbed the \u2018most secure in world\u2019 by FERMAX, previously Kirils & friends focused on its digital 2-wire signalling and employed such tools like oscilloscopes, logic analyzers and breadboards.\r\n\r\nWhile these attacks are important as they shine light on the internal workings on the system, their application in the field is limited as one would need to acquire access to the 2-wire bus, which is only possible from the inside of the building.\r\n\r\nThen we noticed something that was right in front of our eyes, Access control panels! These things are out there just on the perimeter. And, when installed on multi-tenant buildings, they have RFID reader modules installed. FERMAX offers modules doing EM4100, MIFARE Classic, and MIFARE Desfire. Even more they offer standalone Bluetooth modules too!\r\n\r\nIn this talk we give an overview of previous research and expand on it by exploring the possibilities of entering the perimeter by attacking the bluetooth and RFID dimension of these systems, and exploring card cloning, implanting, and cryptographic attacks together with Iceman.  In our research we extracted firmware and analyzed two different mobile applications to control the system,  TUYA and NearKey. \r\n\r\nAttendees will gain insight into decoding and interacting with closed digital protocols, exposing vulnerabilities in real-world access control systems. They also get practically applying RFID attacks to real world systems in use right now.", "recording_license": "", "do_not_record": false, "persons": [{"code": "VNQL7R", "name": "Kirils Solovjovs", "avatar": "https://cfp.balccon.org/media/avatars/VNQL7R_T4hf46c.webp", "biography": "Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist. He began programming at age 7, and by grade 9 was already writing machine code directly in a hex editor during lunch breaks. Renowned for uncovering and responsibly disclosing critical vulnerabilities in national and international systems, he is an expert in network flow analysis, reverse engineering, and social engineering. A lifelong command-line enthusiast, he uses bash daily for hacking, automation, and large-scale data processing.\r\nHe is the author of the jailbreak tool for MikroTik RouterOS and played a pivotal role in developing e-Saeima, the world's first fully remote legislative system used by the Latvian Parliament. Today, Kirils serves as lead researcher at Possible Security.", "public_name": "Kirils Solovjovs", "guid": "60d34ff6-7be5-5eaf-bab3-484763e8ebb9", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/VNQL7R/"}, {"code": "SQZ7YJ", "name": "Iceman", "avatar": "https://cfp.balccon.org/media/avatars/SQZ7YJ_XvXKUsP.webp", "biography": "Christian Herrmann, better known in the hacker community as \u201cIceman\u201d, is a co-founder of AuroraSec and RRG, and has helped develop many of today\u2019s most widely used RFID research tools, including the Proxmark3 RDV4 and the Chameleon Mini. \r\n\r\nHe is a well-known RFID hacking and Proxmark3 evangelist, serving the community as both a forum administrator and a major code contributor alongside other developers since 2013.\r\nChristian has spoken at hacker conferences around the world, including RECON, TenguCon, BalcCon, WHY-2025, Troopers, Black Hat Asia, DEF CON, Hardwear IO, SSTIC, NullCon, Pass-the-Salt, BSides Tallinn, BlackAlps, and SaintCon.\r\nHe also runs a YouTube channel where he shares his knowledge of RFID hacking with the public.\r\n\r\nWith over 15 years of experience in bespoke software development, Christian specializes in\r\n.NET platforms and is a Certified MCPD Enterprise Architect.\r\n\r\nHe possesses near-unmatched expertise in the Proxmark3 architecture and various RFID technologies, and has served as an instructor for Red Team Alliance (RTA), including training sessions at Black Hat.", "public_name": "Iceman", "guid": "771739ac-663d-5703-9e34-ca8d2233b424", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/SQZ7YJ/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/E7GFPG/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/E7GFPG/", "attachments": []}, {"guid": "c4dfc1e3-e312-568a-89d9-e81c2f5b45ea", "code": "UHEUPT", "id": 179, "logo": null, "date": "2026-09-19T17:00:00+02:00", "start": "17:00", "duration": "00:40", "room": "Tesla", "slug": "balccon2k26-2026-179-keeping-trains-on-track-a-glimpse-into-germany-s-railway-infrastructure", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/UHEUPT/", "title": "Keeping Trains on Track - A Glimpse into Germany\u2019s Railway Infrastructure", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Have you ever sat on a train and wondered how all these tons of steel are moved safely across the tracks or who actually makes sure your train ends up at the correct station? If so, you've come to the right talk!\r\n\r\nThe German railway system is a fascinating mix of traditional infrastructure, safety-critical logic and increasingly modern systems.\r\nThis talk introduces the basics behind it all, from tracks, switches, signals and balises to interlocking systems, train protection and railway communication. \r\nWe will look at how safety is built into the systems, why trains do not need speeding tickets, what GSM is still doing in modern rail operations and which protocols may appear when railway technology meets the network stack. \r\n\r\nThe goal of this talk is to make the hidden systems behind everyday train travel visible and to get the community interested in exploring railway technology.", "description": "My rough idea for the talk would be as follows: \r\n\r\n1. What Train Infrastructure^C Dreams are Made Of: The Basic Building Blocks of Railway Infrastructure\r\n\r\n- Track Switches \r\n- Signals\r\n- Balises \r\n- Track Vacancy Detection\r\n- Hot Box Detection Systems\r\n\r\n2. Why it is hard to Crash a Train: Interlocking Systems and Safety Logic\r\n\r\n- Different generations of interlocking systems\r\n- Safety principles\r\n\r\n 3. Train Control Systems: Why Trains do not need Speeding Tickets\r\n\r\n- Intermittent train control\r\n- Continuous train control\r\n- ETCS (European Train Control System)\r\n\r\n4. Long live GSM(-R): The Mobile Network behind Railway Operations\r\n\r\n- Details on the relevance and functionality of GSM-R (GSM for Rail)\r\n- Differences between GSM and GSM-R \r\n\r\n5. Spawning Wireshark: Examples of Bits and Bytes in the Wild \r\n\r\n- RaSTA\r\n- SAHARA\r\n- SBS\r\n- SCI-Protocols\r\n\r\n6. Selected Examples of Developments to come\r\n\r\n- Automated train operation\r\n- FRMCS\r\n\r\n7. Closing Thoughts", "recording_license": "", "do_not_record": false, "persons": [{"code": "NNXEZN", "name": "BlackCat", "avatar": null, "biography": "I am a security professional with around ten years of experience testing and breaking real world systems. Despite being introverted and occasionally socially awkward, I love going to security conferences, usually pretending that the hallway track is not the main reason I came.", "public_name": "BlackCat", "guid": "fbcc43dc-939b-5546-bc89-89590ef63492", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/NNXEZN/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/UHEUPT/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/UHEUPT/", "attachments": []}, {"guid": "27013743-06d5-5258-8a9b-b1dd89568088", "code": "KX7ULU", "id": 145, "logo": null, "date": "2026-09-19T17:40:00+02:00", "start": "17:40", "duration": "00:40", "room": "Tesla", "slug": "balccon2k26-2026-145-every-ride-you-take-hacking-a-city-s-public-transportation", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/KX7ULU/", "title": "Every ride you take - Hacking a City\u2019s Public Transportation", "subtitle": "", "track": null, "type": "Talk45", "language": "en", "abstract": "Let's talk about some critical infrastructure that millions of people use every day: Public transportation. \r\nIn this talk, I\u2019ll present some findings that I discovered in the public transportation ecosystem of one of the largest cities in Argentina, impacting more than 1.5 million people daily. Reading code, chaining vulnerabilities, weak access controls, and flawed internal designs, I got full access to core mobility systems, from buses to taxis, including DVRs, transport cards, user data, real-time tracking and administrative panels. We\u2019ll walk through the technical exploitation path, the real-world impact and the lessons learned.", "description": "Description\r\n=======\r\n\r\nThe talk is divided into 12 stages, showing step-by-step attack chains. In the first stages, I\u2019ll relate the origin of the idea, provide information about the company, recon, and exposed .git directories that revealed source code, hardcoded credentials, and references to internal services and repositories, as well as some SQLi.\r\n\r\nIn Stage 3, I\u2019ll present a Windows-based DVR system deployed on urban buses. Using a user with almost no permissions, I obtained an LFI. Using information from vendor manuals, documentation screenshots, and recovered internal paths, .frm and .ibd files were obtained and reconstructed in a Docker container. This allowed the recovery of credentials, leading to full administrative access to the DVR platform (DEMO).\r\n\r\nWith this access, it was possible to manage users and drivers, access sensitive internal data, and remotely view and control cameras and microphones installed inside buses. After some time, I figured out that this system was also used in 11 provinces, turning a local issue into a nationwide one.\r\n\r\nIn Stage 6, the research returns to the exposed .git files, where a private GitLab URL was found. From there, access to CI/CD pipelines, cron jobs, and a Docker registry was obtained.\r\n\r\nWhile analyzing the cron jobs, multiple hardcoded credentials were found, including access to banking-related services and FTP servers. By analyzing the code and the .lock files, it was possible to upload a file to the FTP server, which was later pulled and executed by internal processes, resulting in RCE on the server.\r\n\r\nStage 8 marks the full infrastructure compromise. Using the reverse shell, it was possible to enumerate internal services, access production databases, bypass network segmentation, and identify additional systems.\r\n\r\nWithin the bus administration platform, access was obtained to the backbone of public transportation, managing drivers, users, companies, ticketing systems, real-time vehicle tracking, and remote operational controls such as fuel cutoff. Unlike the DVR platform, this system operates at city, regional, and national scale.\r\n\r\nIn Stage 10, I\u2019ll show other systems that got access, for example: taxi applications and a large-scale bike rental system, affecting approximately 710 taxi drivers and more than 115,000 registered bike service users.\r\n\r\nThe final system explored was a government-related server containing highly sensitive information, including driver licenses, identification numbers, addresses, phone numbers, and operational records for taxi, bus, and private transport drivers. This was the point where I decided to stop the investigation and report it immediately.\r\n\r\nThe talk ends with the responsible disclosure process, challenges encountered when reporting vulnerabilities across multiple organizations and public entities, and lessons learned about securing critical infrastructure. The goal is to show how chaining basic vulnerabilities can lead to systemic compromise, and why public mobility systems deserve the same security attention as traditional critical infrastructure. Also I would like to encourage new generations to do ethical hacking and help build stronger relationships between hackers and companies.\r\n\r\nOutline\r\n=======\r\n\r\n- Stage 0\r\n   - Whoami\r\n   - Disclaimer\r\n   - Introduction\r\n- Stage 1\r\n   - Landing page\r\n   - .git folders enumeration\r\n   - SQLi\r\n- Stage 2: Exposed .git\r\n   - Hardcoded creds\r\n   - Internal services\r\n   - GitLab url in .git/config\r\n- Stage 3: DVR System\r\n   - Intro\r\n   - Internal paths discovery\r\n   - LFI\r\n- Stage 4: DVR priv escalation\r\n   - LFI to get .frm/.ibd\r\n   - DB recovery (DEMO)\r\n- Stage 5: DVR Admin access\r\n   - User and drivers data exposure\r\n   - Internal system data\r\n   - Access to all cameras & microphones\r\n   - National presence\r\n- Stage 6: GitLab repos & CI/CD\r\n   - Public repos\r\n   - Public pipelines\r\n   - Docker registry exposure\r\n- Stage 7: Cron + FTP\r\n   - Cron job download file from FTP\r\n   - Shell upload to the FTP server\r\n   - .lock execution control\r\n- Stage 8: Reverse shell\r\n   - Internal network access\r\n   - Full database access\r\n   - New systems discovered\r\n- Stage 9: Bus administration system\r\n   - Access to users/drivers/company data\r\n   - Ticketing & balance management\r\n   - City+Regional+National buses\r\n   - Control the buses remotely\r\n- Stage 10: Additional systems\r\n   - APKs\r\n   - Taxi apps\r\n   - Bike rental\r\n   - Full administrative access\r\n- Stage 11: Gov-related server\r\n   - Taxi, buses and private transport records\r\n   - Driver license, IDs, address, phones, etc\r\n- Stage 12: Ending\r\n   - Disclosure process\r\n   - Challenges & responses\r\n   - Conclusions\r\n   - Q&A", "recording_license": "", "do_not_record": false, "persons": [{"code": "U789YX", "name": "Ignacio Navarro", "avatar": "https://cfp.balccon.org/media/avatars/U789YX_NQT5lOE.webp", "biography": "Ignacio Navarro, an Ethical Hacker and Security Researcher from Cordoba, Argentina. With around 6 years in the cybersecurity game, he's currently working as an Application Security. Their interests include code analysis, web application security, and cloud security.\r\nSpeaker at DEFCON, H2HC, Troopers, LeHACK, NorthSec, TyphoonCon, Security Fest, SASCON, 8.8 among others.\r\n@Ignavarro1", "public_name": "Ignacio Navarro", "guid": "bc75df0f-3535-5811-b1cd-d4aa32129adb", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/U789YX/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/KX7ULU/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/KX7ULU/", "attachments": []}, {"guid": "4e9c1094-66c0-51eb-9476-5477730cb342", "code": "W3ARRY", "id": 115, "logo": null, "date": "2026-09-19T18:20:00+02:00", "start": "18:20", "duration": "00:45", "room": "Tesla", "slug": "balccon2k26-2026-115-power-analysis-attacks-101-from-waveform-to-private-key", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/W3ARRY/", "title": "Power Analysis Attacks 101: From Waveform to Private Key", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "Power analysis is a side-channel attack with the goal of extracting secrets from the device based solely on its power consumption. Back in 1998, Kocher, Jaffe, and Jun published the famous paper showing that it's possible to break encryption on many devices using just the power traces, a bit of math and inexpensive equipment. Some twenty-eight years later, this attack still works.", "description": "This talk covers the basics of static and differential/correlation power analysis: the methods, the math (with intuitive explanations), and, if the demo gods are feeling generous, a live key extraction on stage. No prior knowledge assumed.", "recording_license": "", "do_not_record": false, "persons": [{"code": "QQZLRG", "name": "igor", "avatar": null, "biography": "Igor Brki\u0107 is software and hardware engineer from Croatia covering areas from the custom hardware and firmware development to the system and web development.", "public_name": "igor", "guid": "96cf51f5-436b-5206-957d-862408998611", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/QQZLRG/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/W3ARRY/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/W3ARRY/", "attachments": []}, {"guid": "547d5eec-28ea-57c4-96ad-4021c49758ba", "code": "BKDUMV", "id": 144, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/BKDUMV/recurboy_github_PIeMXHp_IYnmtnl_ESiNXpf.webp", "date": "2026-09-19T19:05:00+02:00", "start": "19:05", "duration": "00:15", "room": "Tesla", "slug": "balccon2k26-2026-144-democratizing-the-creation-of-video-tools-with-open-source-grassroots-community-building-and-the-recurboy", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/BKDUMV/", "title": "Democratizing the creation of video tools with Open Source: Grassroots Community building and the recurBoy", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "The world of hardware for video art can be intimidating. Compared to the accessible ecosystem for audio makers, dedicated video instruments are often scarce, expensive, or proprietary, creating a high barrier to entry.\r\nThe recurboy, a standalone digital video sampler, was designed to challenge this. As an open-source hardware and software project, its goal was to dismantle financial and technical barriers by\r\nempowering artists to build their own instrument. What began as a tool for soldering workshops, however, evolved into something more significant: a vibrant, user-sustained community.\r\nThis presentation traces the journey of the recurboy from a shared workshop project to a global grassroots videoart making community.\r\nWe'll explore how users, connected through online platforms like a dedicated Facebook group and scanlines.xyz, formed a collaborative network for support, knowledge-sharing, and creative exchange.\r\nThis community not only built devices but also collectively problem-solved, shared modifications, and fostered a sense of shared purpose, a momentum recognized by features on platforms\r\nlike Adafruit.\r\n\r\nThe story of the recurboy demonstrates that the most vital outcome of an open-source project can be the community it inspires. It is a case study in how providing an accessible, buildable tool can cultivate a space where practice, learning, and collective care flourish, creating a lasting ecosystem for digital video art.\r\n\r\nThe project can be found here:\r\nhttps://github.com/cyberboy666/recurBOY", "description": "This talk is not a technical talk, it is following an open source project from its beginnings to its evolution 7 years later and how it has grown organically in the underground video art community without the interference of its creators. \r\n\r\nTechnical information about the project:\r\n\r\nrecurBOY is a stand-alone digital video synthesizer and sampler. it can trigger clips and run shaders to create and manipulate sd video.\r\n\r\n    outputs sd video over composite or hdmi\r\n    2 source modes to generate video : sampler and shaders\r\n    process any source with additional FX\r\n    control shader/fx parameters directly with 4x knobs or externally with 4x cv inputs\r\n    all inputs also controllable via usb-midi\r\n    process external video through compatible usb capture cards / web-cams\r\n\r\nMore complete information can be found at: https://github.com/cyberboy666/recurBOY", "recording_license": "", "do_not_record": false, "persons": [{"code": "9R8XVC", "name": "Guergana", "avatar": "https://cfp.balccon.org/media/avatars/9R8XVC_xhWGzqm.webp", "biography": "Guergana is a software developer working mainly on free and open source software, educational tools and non-profit organisations currently working at the Open Science Lab of the German National Library of Science and Technology creating open source tools in the field of cultural research. With a Bachelor\u2019s degree in Computer Science, her interest in the creative use of media and technology led her to a Master\u2019s degree in Design of Multimedia and Interactive Systems and later a research degree in Theory and History of Cinema in Barcelona. For several years she has been working on projects that combine audio, video, design and programming.", "public_name": "Guergana", "guid": "4e680129-9387-5d32-a9b1-d81857f19618", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/9R8XVC/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BKDUMV/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BKDUMV/", "attachments": []}, {"guid": "2655ceca-2a27-5e16-89a0-ae4c62e5bc45", "code": "SVGXZE", "id": 184, "logo": null, "date": "2026-09-19T19:30:00+02:00", "start": "19:30", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-184-manufacturing-minesweeper", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/SVGXZE/", "title": "Manufacturing Minesweeper!", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "So you think you want to turn a hardware prototype into a product?  Here's some of the ways you'll fuck it up!", "description": "You're a hardware hacker that likes to build devices the way they SHOULD be built - meaning, the way you like them!  You've made some cool prototypes that are useful for you, so maybe they might be useful to other people too?  Maybe you should manufacture some?  You might help people out and even make a bit of money on the side.  But the product manufacturing landscape is a figurative minefield, littered with traps that will explode your costs and time.  Using real examples, I'll present all my own naive, ignorant and just plain stupid mistakes so maybe you can avoid them.", "recording_license": "", "do_not_record": false, "persons": [{"code": "HZCGXV", "name": "Zoz", "avatar": null, "biography": null, "public_name": "Zoz", "guid": "8d134167-eb5f-59d9-b96a-d266effa8076", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/HZCGXV/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/SVGXZE/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/SVGXZE/", "attachments": []}, {"guid": "59033b63-2118-5903-8878-69242cb0cfca", "code": "ALV7BZ", "id": 189, "logo": null, "date": "2026-09-19T20:30:00+02:00", "start": "20:30", "duration": "02:00", "room": "Tesla", "slug": "balccon2k26-2026-189-lightning-talks", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/ALV7BZ/", "title": "Lightning talks", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "On BalCCon2k26, we want everyone to have an opportunity to speak! So we are soliciting short, but engaging 5 minute talks \u2013 Lightning Talks \u2013 from any and all attendees. The Lightning Talk format provides very personal, concise thoughts, ideas or calls for action. Typically speakers use lightning talks to talk about their experience, their opinions or for a wake-up call towards the agile community and markets.", "description": "On BalCCon2k26, we want everyone to have an opportunity to speak! So we are soliciting short, but engaging 5 minute talks \u2013 Lightning Talks \u2013 from any and all attendees. The Lightning Talk format provides very personal, concise thoughts, ideas or calls for action. Typically speakers use lightning talks to talk about their experience, their opinions or for a wake-up call towards the agile community and markets.\r\nFormat\r\n\r\nEveryone can speak at Balccon! Tell us about your project, idea, plans or your best jokes, just make sure you have a slide deck and keep it under 5 minutes!\r\nProposal\r\n\r\nNow it\u2019s your turn! Send an email at orga (at) balccon.org until 19th September 4pm with\r\n\r\nSubject: Lightning Talk - BalCCon2k26 Name: Language of your Presentation Keywords: Abstract: Relevant Links (Project Page, etc.)", "recording_license": "", "do_not_record": true, "persons": [{"code": "9MSMWK", "name": "BalCCon", "avatar": "https://cfp.balccon.org/media/avatars/9MSMWK_CvklKYX.webp", "biography": "Test", "public_name": "BalCCon", "guid": "f451942b-cecb-5da6-baf6-8016659f9d63", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/9MSMWK/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ALV7BZ/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ALV7BZ/", "attachments": []}], "Pupin": [{"guid": "8147a37a-c1b7-5a15-8750-48dc81e564ef", "code": "NJFLGX", "id": 147, "logo": null, "date": "2026-09-19T11:00:00+02:00", "start": "11:00", "duration": "00:20", "room": "Pupin", "slug": "balccon2k26-2026-147-defending-llms-with-llms-a-multi-agent-approach-to-prompt-injection", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/NJFLGX/", "title": "Defending LLMs with LLMs: A Multi-Agent Approach to Prompt Injection", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Every company deploying a public-facing LLM chatbot inherits the full prompt-injection attack surface: jailbreaks, data exfiltration, PII leakage, indirect injection via retrieved documents. Single-model classifiers and regex filters consistently miss novel attacks, the same way single-AV products missed novel malware a decade ago.\r\n\r\nThis talk presents an open-source defensive architecture that runs five specialist AI agents in parallel against every prompt and response, each looking at a different attack dimension (injection patterns, semantic intent, encoding tricks, output exfiltration, PII exposure) and aggregates their verdicts before the request reaches the upstream LLM. We'll walk through the architecture, show live attacks bypassing commercial single-model guardrails but caught by the multi-agent pipeline, and discuss the latency/cost tradeoffs that make this practical as inline middleware.", "description": "A problem that will be bigger and bigger in the future is that public-facing LLM applications (customer support bots, in-product assistants, RAG-backed chat) are now production infrastructure for thousands of companies, yet the security tooling around them is roughly where web app firewalls were in 2005: regex blocklists and single-shot classifiers. Real-world attacks (DAN-style jailbreaks, indirect injection via poisoned documents, encoding bypasses (base64, Unicode homoglyphs, leetspeak), multi-turn priming attacks) defeat these defenses routinely. Commercial guardrails (Lakera, NeMo, LLM-Guard) help but operate on a single-pass pipeline that struggles with novel, composed, or low-signal attacks.\r\n\r\nProposed approach. I've built and open-sourced an agentic guardrail system that treats LLM defense as a multi-agent reasoning problem rather than a classification problem. The architecture runs concurrent specialist agents in a LangGraph fan-out/fan-in pattern:\r\n\r\nInjection Agent \u2014 looks at instruction-override patterns, role confusion, system prompt extraction attempts\r\nEncoding Agent \u2014 detects base64, hex, Unicode obfuscation, and language-switch bypasses\r\nContext Agent \u2014 analyzes indirect injection via retrieved documents and tool outputs\r\nOutput Protection Agent \u2014 scans LLM responses for system prompt leakage, sensitive data, and policy violations\r\nPII Agent \u2014 Presidio-backed entity detection on both prompts and responses\r\n\r\nA fast-path ONNX classifier handles obvious traffic in <10ms; uncertain cases escalate to the agent panel. Verdicts are aggregated with a tunable severity policy. The whole pipeline sits as an OpenAI-compatible proxy, so it drops in front of any application without code changes.\r\n\r\nWhat's original. The architecture combines three patterns that, to my knowledge, haven't been deployed together in a production LLM guardrail: (1) parallel-agent supersteps borrowed from agentic forensics tooling, (2) prompt-injection feature engineering from earlier academic work on adversarial input detection, and (3) a dual-engine self-learning loop where a fast ML classifier and a slow LLM panel cross-train each other on disagreements. The result catches novel attacks that single-model defenses miss because no individual agent has the full attack surface in its training distribution \u2014 the ensemble disagreement is the signal.\r\n\r\nWhat attendees will see.\r\nLive demo: ~6 attacks (jailbreak, encoded injection, indirect injection via RAG, PII exfiltration, multi-turn priming, output leakage) run against (a) a raw LLM, (b) a commercial guardrail, and (c) the multi-agent system \u2014 with the verdict reasoning shown in real time\r\nArchitecture walkthrough: LangGraph state, agent prompts, aggregation policy\r\nLatency/cost numbers: real measurements on local Ollama (Llama 3.1 8B) vs. cloud (Haiku, GPT-4o-mini)\r\nFailures and lessons learned \u2014 what didn't work: agents agreeing on wrong verdicts, prompt-engineering the agents themselves, the cost blow-up before we added the ONNX fast path\r\nHow to run it locally with Docker Compose after the talk", "recording_license": "", "do_not_record": false, "persons": [{"code": "MKQSWL", "name": "Vukasin Dobromirovic", "avatar": "https://cfp.balccon.org/media/avatars/MKQSWL_Kg0lHi5.webp", "biography": "Threat-intelligence specialist working at the intersection of AI and cybersecurity. National ethical-hacking champion (SCC2025) and part of Serbia's extended national team. Hands-on across malware analysis, endpoint protection, and SIEM operations in both enterprise and small-scale environments", "public_name": "Vukasin Dobromirovic", "guid": "1f1ac5e6-9fd0-5a88-9ec6-23e33a1a3205", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/MKQSWL/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/NJFLGX/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/NJFLGX/", "attachments": []}, {"guid": "3cdc52c0-b6c1-5fd1-a418-45ffb056b71e", "code": "YLMFDS", "id": 156, "logo": null, "date": "2026-09-19T11:30:00+02:00", "start": "11:30", "duration": "01:00", "room": "Pupin", "slug": "balccon2k26-2026-156-tetra-on-a-student-budget", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/YLMFDS/", "title": "TETRA on a Student Budget", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Terrestrial Trunked Radio, or TETRA, is a standard for radio communications. Until recently, designing and operating a trunked system based on this standard was prohibitively difficult without using a dedicated commercial base station. Such equipment was often expensive and difficult to acquire.\r\nBuilding on [research and developmet work by MidnightBlueLabs](https://github.com/MidnightBlueLabs/tetra-bluestation), new projects have been released and TETRA has become much easier to deploy and use.\r\nIn this talk we will introduce some of the basic concepts of radio communications, digital communications, share our experience with developing software for radios using TETRA, some of the legal hoops we had to go through, and we will even have a short demo.\r\nThis talk will cover a lot of technical subjects, but no previous experience is expected.", "description": "We discuss how to setup a Tetra base station in trunked mode and discuss what steps we had to go through to get to that point.", "recording_license": "", "do_not_record": true, "persons": [{"code": "CTQ7S8", "name": "Sava", "avatar": null, "biography": "\u0160ava is an electrical engineer with a passion for breaking things open and seeing how they work. Lately has been researching subjects closely related to telecommunications. Likes exploring new ideas and sharing knowledge.", "public_name": "Sava", "guid": "4e810c24-f018-5a7b-8f6b-b5ac8c1695a8", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/CTQ7S8/"}, {"code": "CV8WQN", "name": "Mi\u0161a", "avatar": null, "biography": "Mi\u0161a(misadeks) is a software engineer, telecommunications student, and licensed ham radio operator. With a passion for embedded system design and building technology from scratch, his work sits at the intersection of low-level radio infrastructure and software development. Lately, his focus is on RF reverse-engineering and exploring modern radio communications.", "public_name": "Mi\u0161a", "guid": "5ab23608-b3a1-5f58-8451-92526538a9ca", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/CV8WQN/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/YLMFDS/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/YLMFDS/", "attachments": []}, {"guid": "6703315f-4dea-5db1-a88f-392174408629", "code": "BJ9BW9", "id": 113, "logo": null, "date": "2026-09-19T12:30:00+02:00", "start": "12:30", "duration": "01:30", "room": "Pupin", "slug": "balccon2k26-2026-113-memory-forensics-in-the-age-of-edr", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/BJ9BW9/", "title": "Memory Forensics in the age of EDR", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Have EDRs taken the glory of in-memory investigation? We' ll go through a side by-side comparison of  of incident investigation with modern EDR against traditional memory forensics with volatility3. \r\n(And by comparing we mean complimenting the knowledge and arsenal of blue teams to pick the right solution for the right problem. It's isn't really a competition on what is best, NOR a shameless product selling)\r\n\r\nTheory is always good but gaining experience is also important! \r\nWe aim to start from memory internals 101 and dive into the analysis of a compromised system using volatility3 in parallel with KQL from Windows Defender for Endpoint. We showcase why memory forensics remains a solid option in incident response -even in the age of telemetry, and why rightfully considered an art form.\r\n\r\nThe workshop aims to be more than an RTFM of volatility3/KQL or use-plugin-and-find flags CTF, but rather equip participants with solid knowledge on linking pieces of evidence to fill the jigsaw puzzle of an incident. \r\nNewbie or seasoned, professional or just curious, this session is for you!", "description": "The following topics will be covered:\r\nPart 1: Memory structure\r\n- How memory works in Windows systems\r\n- Evidence in memory\r\n\r\nPart 2: Memory in DFIR\r\n- Investigation theory\r\n- Introduction to Volatility3\r\n- Differences with EDRs\r\n \r\nPart 3: Hands-On workshop\r\nAnalysis of windows system\r\n\r\nIt is a BYOD session, so please have the latest version of volatility installed on your machine!\r\nhttps://github.com/volatilityfoundation/volatility3\r\nAccess on the detection lab will be given during the workshop.\r\nThe workshop is not a nintendo-forensics class, It is all about how to use it, not install it! :)", "recording_license": "", "do_not_record": false, "persons": [{"code": "TBADRU", "name": "November", "avatar": null, "biography": "I\u2019ve always admired those that said \u201cYou will not have to work for the rest of your life if you make money from your hobby\u201d. Especially if it meant a true \u201cimpact that matters\u201d for people and their daily life. While it was fun to study and play with my friends in \u201cAggressive Cake\u201d (a fitting name for a CTF team) as a freshman, it soon became apparent that reality is far from the innocent dream of doing what you love.\r\n\r\n4 years forward, and really started wondering, if it would be better to become a fisherman. After all, the sea tides are less harsh than the life of a responder. Working overtimes to get the thrill of catching the bad guys was not worthy. Sometimes I really hope that AI takes this job (and auditing) away...\r\nI like petting stray cats and watching sunsets.", "public_name": "November", "guid": "483ca0da-109d-5ed3-8649-32d91d9440a1", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/TBADRU/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BJ9BW9/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BJ9BW9/", "attachments": []}, {"guid": "22b8dfc9-7f33-5469-9bbf-b2a39bddff86", "code": "LRA3MW", "id": 120, "logo": null, "date": "2026-09-19T14:00:00+02:00", "start": "14:00", "duration": "02:00", "room": "Pupin", "slug": "balccon2k26-2026-120-aws-security-the-purple-team-way", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/LRA3MW/", "title": "AWS Security - The Purple Team Way", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "Type: Intermediate\u2013Advanced\r\nFocus: Adversary emulation, detection engineering, IR workflows\r\nStyle: Fast, offensive-defensive, \u201clearn by attacking and defending\u201d\r\n\r\nCloud platforms like Amazon Web Services (AWS) are foundational to many critical infrastructures and enterprise applications, making them prime targets for attackers. In this session, we will not only explore the most relevant attack vectors cybercriminals use to compromise AWS infrastructures but will also simulate these attacks using known threat actor techniques in an adversary emulation context. From initial access to hardcore persistence, this talk will provide a comprehensive look at how attackers operate in AWS environments.\r\n\r\nWe will take a technical journey through the tactics, techniques, and procedures (TTPs) employed by attackers at every stage of the threat lifecycle, aligned with the MITRE ATT&CK framework. We\u2019ll start by reviewing common methods of initial access, such as exploiting exposed credentials or vulnerabilities in services like IAM, Lambda, and EC2. From there, we\u2019ll detail how attackers escalate privileges, move laterally, and evade detection from tools like CloudTrail.\r\n\r\nThe session will conclude with an in-depth look at advanced persistence techniques in AWS, including the manipulation of IAM policies, backdooring Lambda functions or Docker containers, and tampering with logs. Along the way, we\u2019ll demonstrate how security teams can implement defensive and detection strategies to mitigate these risks. By leveraging AWS-native services and third-party tools, attendees will learn how to enhance their incident response capabilities.\r\n\r\nThis hands-on workshop will give attendees practical, technical insights into AWS security, adversary behavior, and how to better defend against sophisticated, persistent attacks. A full hands-on experience, this presentation ensures deep technical immersion.", "description": "Type: Intermediate\u2013Advanced\r\nFocus: Adversary emulation, detection engineering, IR workflows\r\nStyle: Fast, offensive-defensive, \u201clearn by attacking and defending\u201d\r\n\r\nCloud platforms like Amazon Web Services (AWS) are foundational to many critical infrastructures and enterprise applications, making them prime targets for attackers. In this session, we will not only explore the most relevant attack vectors cybercriminals use to compromise AWS infrastructures but will also simulate these attacks using known threat actor techniques in an adversary emulation context. From initial access to hardcore persistence, this talk will provide a comprehensive look at how attackers operate in AWS environments.\r\n\r\nWe will take a technical journey through the tactics, techniques, and procedures (TTPs) employed by attackers at every stage of the threat lifecycle, aligned with the MITRE ATT&CK framework. We\u2019ll start by reviewing common methods of initial access, such as exploiting exposed credentials or vulnerabilities in services like IAM, Lambda, and EC2. From there, we\u2019ll detail how attackers escalate privileges, move laterally, and evade detection from tools like CloudTrail.\r\n\r\nThe session will conclude with an in-depth look at advanced persistence techniques in AWS, including the manipulation of IAM policies, backdooring Lambda functions or Docker containers, and tampering with logs. Along the way, we\u2019ll demonstrate how security teams can implement defensive and detection strategies to mitigate these risks. By leveraging AWS-native services and third-party tools, attendees will learn how to enhance their incident response capabilities.\r\n\r\nThis hands-on workshop will give attendees practical, technical insights into AWS security, adversary behavior, and how to better defend against sophisticated, persistent attacks. A full hands-on experience, this presentation ensures deep technical immersion.\r\n\r\nFull Agenda:\r\n\r\nPhase 1: Attacking The Cloud\r\nTitle 1: From Initial Access to Privilege Escalation\r\nUnderstanding AWS IAM in full\r\nLateral Movement with IAM\r\nMalware Analysis of Team TNT Infostealer\r\nGetting Credentials from Missconfigurations\r\nPrivilege Escalation via IAM policies\r\nPrivilege Escalation via IAM Roles\r\nPrivilege Escalation via Exec to Instances and Containers\r\n\r\n\r\nTitle 2: From Defense Evasion to Persistence \r\nGetting Blindspots in the Share Responsibility Model\r\nBypassing Guardduty\r\nUnderstanding how Cloudtrail logs work\r\nTampering Cloudtrail without getting caught\r\nLiving on the land Techniques\r\nPersistence in AWS via SSH implant\r\nPersistence in AWS via lotl\r\n\r\n\r\n\r\nPhase 2: The Blue Team Way\r\nTitle 1: Security Detection in AWS\r\nCloudtrail for API Call Logging\r\nUnderstanding the complete supply chain\r\nSIEM Integration and Detection Use Case Creation\r\nUnderstanding the Delays in SIEM integration\r\nUnderstanding Event Bridge for Automated Response\r\nHardening Best Practices\r\n\r\n\r\nTitle 2: Incident Response in AWS \r\nUsing the Cloudtrail Digest to detect tampers\r\nCreating an Athena table for Cloudtrail Analysis when SIEM Fails\r\nUsing Event History as a last resource\r\nForensic Images of EC2 instances\r\nNetwork Isolation of AWS instances\r\nAWS Threat Hunting 101 \r\nHow to detect persistence in AWS\r\n\r\nFinal Notes\r\nThis training is designed for security engineers, SOC analysts, incident responders, and anyone who wants to truly understand AWS security through hands-on work. By the end of the session, you\u2019ll have a deep understanding on how real attack and defense techniques work in AWS, being able to understand the hardening requirements, replicate attacks, generate detection use cases, and execute forensic techniques.", "recording_license": "", "do_not_record": false, "persons": [{"code": "MMXLC3", "name": "Santiago Abastante", "avatar": "https://cfp.balccon.org/media/avatars/MMXLC3_euOhvkv.webp", "biography": "I am a Cloud Security and Platform Engineering leader focused on building detection, incident response, and security operations capabilities for cloud-native organizations., I've presented on Cloud Security and Incident Response at Ekoparty, FIRST, Virus Bulletin (three times), Hack.Lu, and various BSides events worldwide. I hold a Bachelor's degree in Information Security and an MBA (Master in Business Administration).", "public_name": "Santiago Abastante", "guid": "35c85b2a-7a65-50cb-b41b-c00219cc8b73", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/MMXLC3/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/LRA3MW/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/LRA3MW/", "attachments": []}, {"guid": "cd56ec8a-6e98-5613-aa84-4f9f58d7a28b", "code": "HLTHYU", "id": 129, "logo": null, "date": "2026-09-19T16:00:00+02:00", "start": "16:00", "duration": "03:00", "room": "Pupin", "slug": "balccon2k26-2026-129-mobile-device-forensics-101", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/HLTHYU/", "title": "Mobile Device Forensics 101", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Your phone knows more about you than your closest friend. Where you went last Tuesday, who you messaged at 2 AM, which Wi-Fi you joined at the hotel. It's all on the device, waiting to be read. This 3-hour workshop is a hands on introduction to mobile device forensics on iOS and Android using only free and open-source tools. No expensive enterprise kit required.", "description": "The first 90 minutes is a guided walkthrough of the acquisition and analysis of the artifacts that answer investigative questions. The second 90 minutes is a CTF. You get real evidence set, register on the CTF platform, and race the room to extract flags from iOS and Android images. Winner gets a prize.\r\n\r\nLevel: Beginner. Comfortable in a Linux/macOS terminal is enough. Bring your own laptop, a Linux VM is fine.\r\n\r\nNo phones harmed during the workshop.", "recording_license": "", "do_not_record": true, "persons": [{"code": "3RNQGC", "name": "Timo Miettinen", "avatar": null, "biography": "Timo is a lead DFIR consultant on Accenture\u2019s Global Cyber Readiness, Response & Recovery team, where he spends his days digging through compromised endpoints, cloud tenants, and mobile devices.\r\n\r\nHe has been working in cyber security since 2009 and full-time in incident response and digital forensics since 2018.", "public_name": "Timo Miettinen", "guid": "1d78d556-f114-5aaa-b814-5cc5370d5cc6", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/3RNQGC/"}], "links": [{"title": "Presentation", "url": "https://docs.google.com/presentation/d/1np38JmDrAwjvmfqhdm8TRsQUXoQQnDMc1NaexLnMi5I", "type": "related"}], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/HLTHYU/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/HLTHYU/", "attachments": []}], "Mileva Maric": [{"guid": "044b140a-694d-53e7-b6ca-c4e3db5084b9", "code": "8QEAW9", "id": 180, "logo": null, "date": "2026-09-19T16:00:00+02:00", "start": "16:00", "duration": "02:00", "room": "Mileva Maric", "slug": "balccon2k26-2026-180-generative-art-and-cellular-automata", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/8QEAW9/", "title": "Generative Art and Cellular Automata", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "This workshop explores generative art and aims at participants who are already familiar with a programming language and interested in exploring their artistic potential. We will examine cellular automata as a framework for generating visual systems, drawing inspiration from well-known models such as Conway's Game of Life.\r\n\r\nThe workshop combines short explanatory sections, live coding demos, and guided participant exercises. Participants will implement rule-based simulations, experiment with parameter spaces, and transform iterative processes into visually compelling outputs. Throughout the workshop, we will discuss emergence, complexity and the role of controlled randomness in creative coding.\r\n\r\nTo provide context, the workshop will also introduce key moments in the history and theory of media art. We will briefly connect computational art practices to early generative pioneers, reflecting on how rule-based systems have shaped artistic discourse. This historical and theoretical framework will give participants a deeper understanding of generative art as a cultural and conceptual practice rather than just a technique.\r\n\r\nAttendees will leave with practical strategies for structuring generative systems and visualising performance, as well as inspiration to integrate artistic experimentation into their technical work.", "description": "1. Introduction & Framing: What is generative art? From computation to aesthetics. Set workshop goals, tools, and the final outcome the participants will build.\r\n2. Historical & Theoretical Context: Early generative art, rule-based systems, and a brief look at generative systems in media art discourse.\r\n3. Cellular Automata Foundations: Grid systems, neighbourhood definitions, rule design, and state transitions. I will demo the first working cellular automaton and show how small rule changes alter behaviour.\r\n4. Building the Core Simulation: Participants and I implement the simulation step by step. We create the update loop, define rules, and verify the output at each stage.\r\n5. From Simulation to Aesthetics: Mapping states to visual language, introducing colour systems and spatial composition, and demonstrating how iteration becomes an artistic method.\r\n6. Guided Creative Lab: Participants develop their own variation on the system. They work independently or in pairs while I circulate, answer questions, and show optional extensions.\r\n7. Share-out and Reflection: Participants briefly present results, followed by a closing discussion on artistic intention vs algorithmic autonomy and resources for further study.", "recording_license": "", "do_not_record": false, "persons": [{"code": "YTVPXT", "name": "Christian L\u00f6lkes", "avatar": null, "biography": "Christian L\u00f6lkes (*1990 in White Plains, NY) works at DFS, the German air traffic control provider. There, he builds data centres for mission-critical software and infrastructure. Clean code and accurate documentation form the basis of his work. He studied Electrical and Information Technology at the Karlsruhe Institute of Technology (KIT), and in his free time he is passionate about media art and the idea that programming is a creative task and that programmers are therefore also artists.", "public_name": "Christian L\u00f6lkes", "guid": "c0c97495-b866-5f47-be8b-7dca900117d1", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/YTVPXT/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/8QEAW9/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/8QEAW9/", "attachments": []}, {"guid": "d9bce864-8f51-52fc-ba6c-1b9597672cf4", "code": "ZAHNXE", "id": 193, "logo": null, "date": "2026-09-19T18:20:00+02:00", "start": "18:20", "duration": "02:00", "room": "Mileva Maric", "slug": "balccon2k26-2026-193-osint-ctf-hackathon", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZAHNXE/", "title": "OSINT CTF/Hackathon", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "Day two is a competitive OSINT CTF/Hackathon where participants apply those techniques to solve a series of progressively harder challenges inspired by real investigations. Teams of up to three compete to identify people, places, events, and relationships using only open sources. Challenges reward both speed and investigative rigour, with recognition for the fastest verified solutions as well as the most elegant investigative process.\r\n\r\nAfter spending several hours forcing ambiguous information into defensible answers, participants often find themselves applying the same methodology everywhere else, from incident response and threat intelligence to random travel photos and breach data. The goal is not simply to teach OSINT, but to develop a way of approaching problems that remains useful long after the workshop ends.", "description": "Day two is a competitive OSINT CTF/Hackathon where participants apply those techniques to solve a series of progressively harder challenges inspired by real investigations. Teams of up to three compete to identify people, places, events, and relationships using only open sources. Challenges reward both speed and investigative rigour, with recognition for the fastest verified solutions as well as the most elegant investigative process.\r\n\r\nAfter spending several hours forcing ambiguous information into defensible answers, participants often find themselves applying the same methodology everywhere else, from incident response and threat intelligence to random travel photos and breach data. The goal is not simply to teach OSINT, but to develop a way of approaching problems that remains useful long after the workshop ends.", "recording_license": "", "do_not_record": false, "persons": [{"code": "EXZPC7", "name": "Jurica Radovi\u0107", "avatar": "https://cfp.balccon.org/media/avatars/EXZPC7_BwzwtcH.webp", "biography": "SOC operator and offensive security practitioner with a habit of pulling at things until they break and then figuring out why. Core interests are OSINT, social engineering, and finding the cracks in systems that were never supposed to be tested.\r\n\r\nNever formally grew up in the golden era of hacker culture, but feels deeply at home in it anyway. The kind of person who was handed a keyboard before they could read and never really found a reason to put it down. Enthusiastic about anything that involves taking something apart, technically or socially.\r\n\r\nA regular at community security events, with strong views on privacy, surveillance, and the kind of curiosity that does not really have an off switch.", "public_name": "Jurica Radovi\u0107", "guid": "29366c91-7814-5da2-ba0a-51a6795b96ce", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/EXZPC7/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZAHNXE/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZAHNXE/", "attachments": []}], "Hackerspace area": [{"guid": "f05fd430-322b-51d7-8b83-08c75deaae62", "code": "PYDQEJ", "id": 152, "logo": null, "date": "2026-09-19T13:00:00+02:00", "start": "13:00", "duration": "02:00", "room": "Hackerspace area", "slug": "balccon2k26-2026-152-balccon-amateur-lockpicking-competition-2k26", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/PYDQEJ/", "title": "BalCCon Amateur Lockpicking Competition 2K26", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "BALC (BalCCon Amateur Lockpicking Competition) is back again! \r\n\r\nBALC is a timed lockpicking competition for amateur participants. Competitors attempt to open a series of locks mounted on a door model using non-destructive techniques. The objective is to open as many locks as possible within the allotted time, with the fastest overall time determining the ranking in case of a tie.\r\n\r\nThe competition is intended for hobbyists interested in physical security and lockpicking.", "description": "BALC is a hands-on lockpicking competition requiring a dedicated area for the duration of the event.\r\n\r\nThe competition uses a door model fitted with several locks. Participants compete individually in timed runs. A small number of volunteers will supervise the competition, keep time, reset the setup between runs, and record results.\r\n\r\nThe organizers of the competition will provide the door model, locks, lockpicking tools, timing, scoring, and staffing required to run the event.", "recording_license": "", "do_not_record": false, "persons": [{"code": "QYPNJP", "name": "nm29", "avatar": null, "biography": "Vlachian wizard with legal knowledge.", "public_name": "nm29", "guid": "3236e51c-054e-555d-b076-92ecfd8df908", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/QYPNJP/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/PYDQEJ/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/PYDQEJ/", "attachments": []}, {"guid": "d2a98269-efe8-5798-8cf7-5539c66aa4a6", "code": "JHHMTE", "id": 167, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/JHHMTE/1000118102_jycirQ2_bpjRHkK_61mSt1Q.webp", "date": "2026-09-19T15:00:00+02:00", "start": "15:00", "duration": "00:10", "room": "Hackerspace area", "slug": "balccon2k26-2026-167-the-eye", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/JHHMTE/", "title": "The Eye", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "An interactive ARG where you try to outsmart a character (chat bot) into helping you reach your goal using a terminal to help you figure out clues.", "description": "The game will consist of 2 crt screens, one will only show the terminal and is the main interaction point between the game and the player, other screen will show an animated eye of the character you are talking to. \r\n\r\nYour goal will be to extract a code from the character and figure out a way to 'delete' it, if you succeed in doing so without the character stopping you or shutting himself down, you win and get a reward.\r\n\r\nThis game will run on a raspberry pi 4, and will be connected to either wifi/ethernet, whichever is available, it will drive both displays and the keyboard that players interact with. There will be no exposed ports to access the radpberry pi, or to unplug the monitors, everything will be enclosed in a 3D printed case.", "recording_license": "", "do_not_record": false, "persons": [{"code": "9XYX9L", "name": "skullollipop", "avatar": null, "biography": "Humble man.", "public_name": "skullollipop", "guid": "7da58648-074d-5c39-ad22-51c2b3385399", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/9XYX9L/"}, {"code": "SQGTY7", "name": "Marko Jesic", "avatar": null, "biography": "Humble man 2", "public_name": "Marko Jesic", "guid": "0fd454eb-15da-5138-86b1-e10190659d0e", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/SQGTY7/"}, {"code": "R88EVN", "name": "Jaddes", "avatar": "https://cfp.balccon.org/media/avatars/R88EVN_C0cqQdb.webp", "biography": "Final year Student of FTN Novi Sad in Automatic Computer Science.\r\nPassionate about Cybersecurity of all kinds.", "public_name": "Jaddes", "guid": "f15cd029-a670-51e3-bed9-8b9307b463a2", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/R88EVN/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/JHHMTE/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/JHHMTE/", "attachments": []}, {"guid": "97de5676-7a7c-5d2c-bf2e-d314425a1f4e", "code": "BPJN79", "id": 173, "logo": null, "date": "2026-09-19T16:00:00+02:00", "start": "16:00", "duration": "04:00", "room": "Hackerspace area", "slug": "balccon2k26-2026-173-pen-paper-workshop", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/BPJN79/", "title": "Pen & Paper Workshop", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Pen and Paper games are Role Playing Games (RPGs) that are meant to be played by a small group of people in person at a table using dice. The most famous one is Dungeons and Dragons (D&D), but there are hundreds of others. Today there are also online tools with which the games can be played, but a lot of people still prefer to play in person. During the game, the players create a story,  that is not predefined by a software or program. The story evolves through the collaborative ideas of the players playing. Usually all but one player play a single character while the last player plays the world and everybody else within that world.", "description": "I invite you to join into a Pen and Payer game. Everybody is invited regardless if you have never played before or are an experienced player. All offered games should be beginner friendly.\r\n\r\nIf you can offer a game yourself, please bring it as well, so that we have multiple options. Use the system you like, so that we probably can offer a range of games.\r\n\r\nI myself will bring some Pathfinder 2e (Fantasy) and Starfinder 2e (Science Fiction) games. Both are open source systems derived from D&D.", "recording_license": "", "do_not_record": false, "persons": [{"code": "YLBGU3", "name": "katzazi", "avatar": null, "biography": "I'm a German software engineer who likes to bike, read, dance, playing games, sailing and a lot more. I'm also interested in politics and some economic critique. I sometimes give talks about those topics.", "public_name": "katzazi", "guid": "25b4e747-c748-5978-8d99-c2d0cd73a47b", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/YLBGU3/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BPJN79/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BPJN79/", "attachments": []}], "Lounge": [{"guid": "a3ef2d3f-66d9-5f6a-8ba3-1d5ad3b12097", "code": "FAQFDS", "id": 190, "logo": null, "date": "2026-09-19T22:30:00+02:00", "start": "22:30", "duration": "02:00", "room": "Lounge", "slug": "balccon2k26-2026-190-rakija-leaks", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/FAQFDS/", "title": "Rakija Leaks", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "Rakija connecting people!\r\n\r\nRakia is one of the most popular alcoholic drink in Serbia. It is usually served before lunch and dinner and is drunk along with appetizers. It is mandatory to drink with roasted pig, lamb, or dried meat. It is a very important part of the Albanian and Serbian cultures and there are many historians that say that the origins of rakia are in Serbia. Serbia has the most consumption of rakia per capita and is the largest exporter of rakia. In a 2009 European Court ruling, the names \"Slivovica\" (Slivovitz), Dunjevaca, Orahovaca, and Kruskovaca were ruled to be Serbian and thus the country has a trademark on those three types of rakia (Slivovitz being the most famous and most consumed in the world).", "description": "Rakia is part of Serbian culture. It is part of many special occasions, including baptisms, marriages, joining of the army, and visiting of friends. At funerals, custom demands that a bottle of rakia be left on the grave of the deceased who liked to drink it, or at least to sprinkle a drop or two during the memorial service for peace of the person\u2019s soul. For some peasants, a flask of rakia is one\u2019s only luggage. Poor peasants many even offer the village doctor, policeman, judge, tax collector, or minister a flask of rakia as a gift of payment. Many folk songs have been composed during rakia production.", "recording_license": "", "do_not_record": true, "persons": [{"code": "9MSMWK", "name": "BalCCon", "avatar": "https://cfp.balccon.org/media/avatars/9MSMWK_CvklKYX.webp", "biography": "Test", "public_name": "BalCCon", "guid": "f451942b-cecb-5da6-baf6-8016659f9d63", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/9MSMWK/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/FAQFDS/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/FAQFDS/", "attachments": []}]}}, {"index": 3, "date": "2026-09-20", "day_start": "2026-09-20T04:00:00+02:00", "day_end": "2026-09-21T03:59:00+02:00", "rooms": {"Tesla": [{"guid": "56688060-407b-5b4c-8783-d7caf252f157", "code": "WR9CLL", "id": 122, "logo": null, "date": "2026-09-20T12:00:00+02:00", "start": "12:00", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-122-meshtastic-is-dead-long-live-meshtastic", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/WR9CLL/", "title": "Meshtastic is dead, long live meshtastic", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "I will be talking about meshtastic protocol in detail, layer by layer and will be showing vulnerabilities in each (spoiler alert, most of them are vulnerable)\r\n\r\nAnd I will be talking about why that is ok and why it is by design", "description": "In recent years, around the world, we are facing rise of low power mesh networks. \r\n\r\nAnd compared to older systems, that mostly dissipated and failed, recent wave has something different to offer. \r\n\r\nThose systems are built on custom protocols and low cost hardware, that is pretty limited in what it can do with reasonable time and power consumption. On top of that, for the purpose of long range communication, messages can only be short and transmission has to be slow. \r\n\r\nJust like any other distributed system, it also faces challenges of trust in other nodes. And in this case, that is even harder issue, because due to bandwidth limitations, there can not be something like consensus over the network, due to bandwidth limitations. \r\n\r\nWhile building it, designer faced unique challenges and constraints, that did not let them retroactively fix things, to be able to maintain backwards compatibility. Backwards compatibility being important since embedded systems in the middle of nowhere on slow network can not be updated. \r\n\r\nThis talks leads you thru those unique challenges, decisions made, analyzes them, looks at the compromises made, measures them on being worth it and in the end comes to conclusion, why meshtastic despite all those mistakes and scars still persists to survive. \r\n\r\nLayers I will be going over are:\r\n\r\n- Physical layer (what nodes are talking about in RF world)\r\n\r\n- Metadata layer, for routing\r\n\r\n- Encryption\r\n\r\n- Portnums (application routing)\r\n\r\n- Actual payload\r\n\r\nI will be breaking down each layer at byte level or protobuf model level, interacting with audience on their ideas of why something is unsafe and showing live PoC on nodes that are willing to participate in local, vulnerable network", "recording_license": "", "do_not_record": false, "persons": [{"code": "BD9L9C", "name": "nemanjan00", "avatar": null, "biography": "Just random guy", "public_name": "nemanjan00", "guid": "947e16e5-c9f2-5f1b-ac2a-020ca6f39887", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/BD9L9C/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/WR9CLL/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/WR9CLL/", "attachments": []}, {"guid": "ed0ed6ec-96ea-5733-85b1-7318411441ed", "code": "7M73WX", "id": 132, "logo": null, "date": "2026-09-20T13:00:00+02:00", "start": "13:00", "duration": "00:30", "room": "Tesla", "slug": "balccon2k26-2026-132-how-i-became-a-voodoo-doll-model", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/7M73WX/", "title": "How I became a Voodoo doll model", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "How to use AD misconfigurations and features in order to gain access or to escalate privileges. AD is in the heart of most of enterprise networks and is usually a main pilar for identity and access management. Owning AD usually means owning the complete enterprise, so it is quite interesting target for attacks. We will explore some of the most common attack venues against AD.", "description": "AD is everywhere and it is a cornerstone of enterprise identity management. Although new IAM technologies are expanding, it is still present in almost every internal network.\r\n\r\nThis talk will cover basics of ad and show some of the most common attacks and tools, both linux and powershell based.\r\n\r\nThis is based on a real life scenario as it occurred during the pentest. We will demonstrate how to gain initial access as unauthorized attacker, and how to escalate and own everything.\r\n\r\nBy leveraging misconfiguration of AD, bypassing windows defender in order to escalate privileges and expand domination to own full AD and even complete forest. We will shown techniques like kerberoasting, weak acl, user impersonation and similar.\r\n\r\nAlso, we will show how to use some of existing tools on machine in order to accomplish specific goals.", "recording_license": "", "do_not_record": false, "persons": [{"code": "WBQJBM", "name": "Vladan Nikolic", "avatar": null, "biography": "Seasoned security expert in fields of  electronics, automotive, and finance with more than 25 years of experience working for the most interesting clients.", "public_name": "Vladan Nikolic", "guid": "b50505c3-3b39-5ab4-8aac-72f48fbdd8ee", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/WBQJBM/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/7M73WX/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/7M73WX/", "attachments": []}, {"guid": "8a31ca80-3a94-5b9e-b094-3669ea965c2c", "code": "PLVHUH", "id": 161, "logo": null, "date": "2026-09-20T13:30:00+02:00", "start": "13:30", "duration": "01:00", "room": "Tesla", "slug": "balccon2k26-2026-161-post-quantum-cryptography-for-the-novice-the-enjoyer-the-deployer-and-the-academic", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/PLVHUH/", "title": "Post-Quantum Cryptography for the Novice, the Enjoyer, the Deployer and the Academic", "subtitle": "", "track": null, "type": "Talk60", "language": "en", "abstract": "A lot of people say they want to learn about post-quantum cryptography. One day, your favourite regulation authority asks you to switch to post-quantum in the next five years. While a great motivator to finally learn about PQ, what does that actually mean for you and me, your company and your non-tech friends? \r\nThe talk will cover:  \r\n- why we need to switch to post-quantum\r\n- are some cryptographic algorithms more vulnerable than others\r\n- what you should change when.\r\n \r\nMore importantly, we'll talk about the algorithms under the schemes: Which one should you use for your server, and which one is maybe more suited as a conversation topic at dinner parties. \r\nFinally, we'll look ahead: What are academics thinking about, and what is out there beyond key exchange and signatures?", "description": "The talk will be split into an introduction and four parts: \r\nIntro: \r\nPQ Mitigation timelines, Confidentiality is more vulnerable than Authenticity\r\n(harvest-now-decrypt-later vs. just stopping to accept RSA signatures)\r\n\r\n- The Novice. What does Shor tell us? What are periodic functions, and why are they vulnerable?\r\n  Conclusion: Factoring and Discrete logs are vulnerable because they are periodic. So what can we use instead?\r\n- The casual Enjoyer: A high level intro to \r\n  - random walks (isogenies)\r\n  - noisy equations (lattices)\r\n  - codes (noncommutative lattices) \r\n  - multivariate cryptography (noisy equations with more variables) \r\n  - symmetric MPC (just do the boring thing, obliviously and generically). \r\n\r\n  Conclusion: There's a lot of math, but at least you now know where to start  and how to fake your way through the next 1:1 with your team lead. \r\n- The deployer: what algorithms should you actually use? This is easy: NIST, ESI and other standards tell you what you are allowed to do in business applications- standards are usually not very flexible. Otherwise, the one you like best (maybe use a standard one, or one I invented (pls don't) ). \r\nOptional: \"But someone told me lattices are bad\". Stop believing random people on the internet. Trust me instead, or actually, don't. Do your own research. In fact, do your own PhD in cryptography. \r\n- The academic: What is an open question? Privacy tech is not being rolled out because there are no PQ-safe alternatives. Data-oblivious (Blind) evaluation is hard, short intution on why.", "recording_license": "", "do_not_record": false, "persons": [{"code": "GQQJV8", "name": "Lena Heimberger", "avatar": null, "biography": "Lena is a cryptographer working on privacy in a post-quantum world. She focuses on blind evaluation for privacy-preserving protocols, while also gossiping about transparency on the side. \r\nOutside of cryptography, she stares at chessboards and is looking for the perfect minimal techno beat to match her complexity problems.", "public_name": "Lena Heimberger", "guid": "646beef0-e5da-5f3c-b677-609bd04db529", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/GQQJV8/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/PLVHUH/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/PLVHUH/", "attachments": []}, {"guid": "5fcdec02-62f4-5f1f-9aaf-4b3ec1c678cb", "code": "MUAKNE", "id": 137, "logo": null, "date": "2026-09-20T14:30:00+02:00", "start": "14:30", "duration": "00:45", "room": "Tesla", "slug": "balccon2k26-2026-137-wireshark-for-s-hackers-s-reverse-engineers", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/MUAKNE/", "title": "Wireshark for <s>hackers</s> reverse engineers", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "While AI assisted tools are helping us speed run the analysis of unknown protocols, we still need to have a solid foundation to make sense of the larger picture. In this talk I will focus on three topics for that initial step of the investigation before analysis tools or even dissectors start to make sense.", "description": "While AI assisted tools are helping us speed run the analysis of unknown protocols, we still need to have a solid foundation to make sense of the larger picture. In this talk I will focus on three topics for that initial step of the investigation before analysis tools or even dissectors start to make sense: I will start start by sharing how to prepare a sane and fresh Wireshark environment for a new reverse engineering session. Then followed by example on how to weed out traffic and translating initial findings into usable information. Finally we will go through several TLS variants and see what we need to decrypt those to add plain text information to our protocol tree.\r\nThe skills demonstrated in this talk sit solidly before more advanced steps such as automated analysis with scapy/AI tools and writing full dissectors or reverse engineered implementations of communication protocols.", "recording_license": "", "do_not_record": false, "persons": [{"code": "Z8R7CJ", "name": "Erik de Jong", "avatar": "https://cfp.balccon.org/media/avatars/Z8R7CJ_i1GIb4O.webp", "biography": "Erik de Jong is an elite hardware hacker and senior cybersecurity consultant, running his own company error32.io, with extensive experience in identifying vulnerabilities and securing complex systems. Known for a hands-on \"brains first, tools second\" approach and deep technical expertise, Erik specializes in reverse engineering, embedded systems, and hardware security. With a passion for crowdsourced security, Erik actively contributes to bug bounty programs and has participated in multiple bugbashes (live hacking events), where he's collaborated with other top hackers to uncover critical vulnerabilities in real-time.", "public_name": "Erik de Jong", "guid": "f71732b1-0298-57ba-8995-f2bb4ff4d9b2", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/Z8R7CJ/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/MUAKNE/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/MUAKNE/", "attachments": []}, {"guid": "1d6aa137-72d1-5435-b797-bb639348aab7", "code": "SXYD3W", "id": 126, "logo": null, "date": "2026-09-20T15:15:00+02:00", "start": "15:15", "duration": "00:45", "room": "Tesla", "slug": "balccon2k26-2026-126-awerqo-balccon-whoarethey-cloud-recon-for-bughunting-md", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/SXYD3W/", "title": "awerqo@balccon:~$ ./whoarethey > 'Cloud Recon for Bughunting.md'", "subtitle": "", "track": null, "type": "Talk45", "language": "en", "abstract": "Your bug bounty / pentest scope is a list of ASN and domains. **Your attack surface isn't.**\r\n\r\nModern cloud architectures expand beyond those horizons - Lambda function URLs, API Gateway endpoints, S3 buckets, CloudFront distributions, container registries, and CI artifacts deploy outside the visible domain space, weakly monitored and missing from official scope.\r\n\r\nSo: `whoarethey`? This talk provides the answers to that key question - how to map a target company's cloud-heavy infrastructure with a pure black-box approach, beyond standard methods. Alongside a brief recap of the regular recon (acquisitions, subdomain enumeration) for completeness, the focus will be on **cloud-asset recon**. You will learn how to find all the APIs of any given cloud and almost all the cloud domains with user workloads or content - and how to attribute them to a specific company.\r\n\r\n*For hunters and pentesters tired of running the same methods against the same scope with the same results and wondering where the bugs went.*", "description": "## Why this talk\r\n\r\nThe cloud is now where the S&P 500 lives. Statistics indicate that 99% of customer security failures in clouds are due to the errors of the customers themselves, and HackerOne reported  [all-time-high vulnerability submissions in March 2026](https://www.hackerone.com/blog/continuous-threat-exposure-management-remediation-crisis).\r\n\r\nWhile the underlying sources \u2013 a list of subdomains and ASN ranges \u2013 are still the same as five years ago, the recon methodology most hunters use has just added an AI layer on top. Cloud-native targets live one layer past that list, and the standard tooling doesn't reach them.\r\n\r\n## Anatomy of cloud assets\r\n\r\nThe shape of a modern cloud footprint. For each major service, I cover the URL and endpoint patterns that let you fingerprint it from outside:\r\n\r\n- Service example \u2013 Storage, bucket URL patterns across multiple providers (virtual-hosted-style vs path-style; regional variants)\r\n- Service example \u2013 Serverless / Functions, Lambda URL formats, function-URL patterns, container-based functions\r\n- Service example \u2013 Identity / Cognito, pool URLs and the public auth-flow surface (SignUp, ConfirmSignUp, InitiateAuth, RespondToAuthChallenge, ForgotPassword, DescribeUserPoolClient, GetUser, UpdateUserAttributes)\r\n- How to find APIs for **ALL!** cloud services via hardcoded endpoints in SDKs (e.g., boto3 / botocore endpoints data)\r\n- How to find **MANY** cloud domains with user content via the Public Suffix List\r\n\r\n## Discovery and exploitation\r\n\r\nThree lenses, layered on top of each other:\r\n\r\n- Company assets (the regular recon) - acquisitions via Tracxn and Crunchbase, legal entities, ASN ranges via BGP.HE.NET and ASNmap, second-level domains, subdomain enumeration with PureDNS, DNSx, Katana, CSPrecon. Treated as substantive content, not a one-slide intro.\r\n- Cloud assets - what each provider exposes by default and how to fingerprint a service from the patterns covered in section 1.\r\n- Company in cloud (the intersection) - pairing the regular recon output with cloud patterns to land on the actual targets: xyz.s3, xyz.lambda-url, xyz.cloudfront, Cognito pools tied to a company's identity domain.\r\n\r\n**Approach taxonomy.** Passive \u2192 safe-active \u2192 noisy-active across providers, and when each is appropriate.\r\n\r\n**Attribution.** The core of the talk: attributing arbitrary cloud assets to a specific company through TLS certificates (TLSx), link graphs in HTML and JS, copyright and contact strings in serialized configs, and the data-leakage tells in exposed JSON/XML. Includes a note on where invasive attribution methods cross ethical lines. Which data sources and tools fit attribution, and how to use each.\r\n\r\n## Tooling and how integrate them to methodology\r\n\r\n- Shodan facet analysis\r\n- ZoomEye\r\n- GitHub search\r\n- TLSx\r\n- Cloud-SNI ranges (ec2-reachability.amazonaws.com, kaeferjaeger.gay)\r\n- PureDNS\r\n- DNSx\r\n- Katana\r\n- CSPrecon\r\n- Wayback CDX API for wildcard searches\r\n- Postman public collections\r\n- Wordlists from Assetnote, plus target-specific lists from HTML, BigQuery, FFUF/Intruder\r\n- S3Scanner (buckets)\r\n- Pacu (IAM bruteforce, Lambda enum, Cognito flows)\r\n\r\n## Defense and hardening - \"Attack yourself first\"\r\n\r\n- Wildcard bug bounty scope (catch-all by default)\r\n- Stay on top of trends; assume scope drifts\r\n- Continuous attack-surface inventory\r\n- Manual recon at least annually\r\n- Treat staging as prod\r\n- Billing alerts on every account\r\n- Acquisition onboarding SLA\r\n- Service-account chain analysis\r\n- Whitebox inventory\r\n- Stealer-log monitoring\r\n- Incremental / per-release audits\r\n\r\n## References\r\n\r\n- [Jason Haddix - The Bug Hunter's Methodology / recon talk](https://www.youtube.com/watch?v=gIz_yn0Uvb8)\r\n- [ProjectDiscovery (TLSx, DNSx, ASNmap, Katana)](https://github.com/projectdiscovery)\r\n- [Rhino Security Labs - Pacu](https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/)\r\n- [TomNomNom - WhatWhereWhen](https://tomnomnom.com/talks/wwwww.pdf)\r\n- [Assetnote - wordlists & research](https://www.assetnote.io/resources/research)\r\n- [kaeferjaeger](https://kaeferjaeger.gay/)\r\n- [HackerOne \"remediation crisis\" report](https://www.hackerone.com/blog/continuous-threat-exposure-management-remediation-crisis)\r\n- Gartner \u2013 Cloud failure forecast", "recording_license": "", "do_not_record": false, "persons": [{"code": "GVFYSL", "name": "Andrei", "avatar": "https://cfp.balccon.org/media/avatars/GVFYSL_UJzInz5.webp", "biography": "I'm a security engineer, pentester, and researcher who came to the field from a background in medicine. I've been hacking the web since 2019 and hold OSCP and OSWE\r\n\r\nHappy to contribute to the community and exchange knowledge - come say hi, let's chat and stay in touch", "public_name": "Andrei", "guid": "2b139584-2fd0-5ef4-86dd-e02e0ef9680a", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/GVFYSL/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/SXYD3W/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/SXYD3W/", "attachments": []}, {"guid": "0c2dfc59-d986-5665-a04f-b88ed3b70c70", "code": "BDQWZ8", "id": 142, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/BDQWZ8/Privilege_Escalation_-_The_Art_mbQm7j_vazqTyI.webp", "date": "2026-09-20T16:00:00+02:00", "start": "16:00", "duration": "00:40", "room": "Tesla", "slug": "balccon2k26-2026-142-from-zero-to-admin-the-hidden-paths-of-privilege-escalation", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/BDQWZ8/", "title": "From Zero to Admin: The Hidden Paths of Privilege Escalation", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "This session takes attendees inside the privilege escalation mindset. We will explore the techniques attackers use to enumerate systems, discover hidden permissions, abuse trust relationships, collect credentials, and move from restricted access to complete control.", "description": "Getting inside is only the beginning.  The real game starts after compromise.\r\nOnce attackers land inside an environment, they begin asking three simple questions:\r\n\r\nWho am I?\r\nWhat access do I have?\r\nWhat can I become?\r\n\r\nThose answers determine whether an attacker remains a limited user - or becomes a domain admin, root user, cloud owner, or autonomous operator.\r\n\r\nThis session takes attendees inside the privilege escalation mindset. We will explore the techniques attackers use to enumerate systems, discover hidden permissions, abuse trust relationships, collect credentials, and move from restricted access to complete control.\r\n\r\nCovering Windows, Linux, Cloud, and emerging AI systems, this talk reveals how privilege escalation has evolved from exploiting machines to exploiting identity itself.", "recording_license": "", "do_not_record": true, "persons": [{"code": "8XFFZK", "name": "Joseph Carson aka Wiretrap", "avatar": "https://cfp.balccon.org/media/avatars/8XFFZK_fdA2Z9f.webp", "biography": "Joseph Carson is an award-winning cybersecurity professional, ethical hacker, and curious problem solver with over 30 years of experience exploring, breaking, and securing technology. As Chief Security Evangelist and Advisory CISO at Segura, he helps organizations defend what attackers target most - identities, privileges, and access.\r\n\r\nHolding CISSP and OSCP certifications, Joseph combines a hacker mindset with real-world security leadership, advising governments, critical infrastructure, and global organizations on building stronger cyber resilience.\r\n\r\nHe is the author of Cybersecurity for Dummies, helping educate more than 50,000 professionals worldwide, a global keynote speaker, and contributor to publications including The Wall Street Journal and Dark Reading.\r\n\r\nAs host of the Security by Default podcast, Joseph explores the stories, techniques, and lessons from hackers, innovators, and security leaders shaping the future of cybersecurity, driven by the belief that curiosity is the foundation of every great hacker.", "public_name": "Joseph Carson aka Wiretrap", "guid": "c75c26ad-c14a-5bcf-b893-8d0662f1437a", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/8XFFZK/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BDQWZ8/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/BDQWZ8/", "attachments": []}, {"guid": "1ad3daf0-7ee8-5748-8e5a-53831eb52167", "code": "ZEWLHA", "id": 134, "logo": null, "date": "2026-09-20T16:45:00+02:00", "start": "16:45", "duration": "01:55", "room": "Tesla", "slug": "balccon2k26-2026-134-security-impress-karaoke", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZEWLHA/", "title": "Security Impress Karaoke", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "Think you can bluff your way through a security talk with zero prep? Now is your chance! At Security Impress Karaoke, you'll be handed a totally random, security-themed slide deck you\u2019ve never seen before - and have just 3 minutes to present it like a pro.\r\n\r\nNo experience? No problem. This is all about having fun, thinking fast, and impressing the crowd with your creativity (or chaos). Whether you're a seasoned hacker or just security-curious, come take the podium and let\u2019s see what you\u2019ve got!", "description": "Sign up or just show up!", "recording_license": "", "do_not_record": false, "persons": [{"code": "VNQL7R", "name": "Kirils Solovjovs", "avatar": "https://cfp.balccon.org/media/avatars/VNQL7R_T4hf46c.webp", "biography": "Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist. He began programming at age 7, and by grade 9 was already writing machine code directly in a hex editor during lunch breaks. Renowned for uncovering and responsibly disclosing critical vulnerabilities in national and international systems, he is an expert in network flow analysis, reverse engineering, and social engineering. A lifelong command-line enthusiast, he uses bash daily for hacking, automation, and large-scale data processing.\r\nHe is the author of the jailbreak tool for MikroTik RouterOS and played a pivotal role in developing e-Saeima, the world's first fully remote legislative system used by the Latvian Parliament. Today, Kirils serves as lead researcher at Possible Security.", "public_name": "Kirils Solovjovs", "guid": "60d34ff6-7be5-5eaf-bab3-484763e8ebb9", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/VNQL7R/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZEWLHA/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ZEWLHA/", "attachments": []}, {"guid": "7302a715-db98-596a-8798-20a27621e759", "code": "JERKYH", "id": 188, "logo": null, "date": "2026-09-20T18:40:00+02:00", "start": "18:40", "duration": "00:30", "room": "Tesla", "slug": "balccon2k26-2026-188-closing-ceremony", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/JERKYH/", "title": "Closing ceremony", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Closing ceremony", "description": "Closing ceremony", "recording_license": "", "do_not_record": false, "persons": [{"code": "9MSMWK", "name": "BalCCon", "avatar": "https://cfp.balccon.org/media/avatars/9MSMWK_CvklKYX.webp", "biography": "Test", "public_name": "BalCCon", "guid": "f451942b-cecb-5da6-baf6-8016659f9d63", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/9MSMWK/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/JERKYH/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/JERKYH/", "attachments": []}], "Pupin": [{"guid": "d7af73fa-8d84-52ed-aa33-36d681b90052", "code": "YZPBVT", "id": 168, "logo": "https://cfp.balccon.org/media/balccon2k26-2026/submissions/YZPBVT/patch_example_hhXhXik_BQwpFrm.webp", "date": "2026-09-20T13:00:00+02:00", "start": "13:00", "duration": "01:00", "room": "Pupin", "slug": "balccon2k26-2026-168-embroidery-meets-electronics-make-your-blinky-wearable-patch", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/YZPBVT/", "title": "Embroidery meets Electronics - make your blinky wearable patch", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "This is a workshop where embroidery meets electronics. It is intended for anyone who is interested in crafting something of their own while learning the basics of embroidery and circuitry, no prior knowledge or experience needed. Once you are done you'll be able to wear your patch and show off your work!", "description": "Each participant will receive a canvas (a piece of textile) the size of a credit card, roughly 85 \u00d7 54 mm, with a few proposed designs such as memes, tech designs , or hacker puns, or they can come up with a design of their own. Alongside colorful thread, there will be sewable LEDs available in many colors (red, orange, green, blue, purple, pink, and yellow), and most excitingly, \u201csmart\u201d self-blinking LEDs that only require power (no software) to blink and really bring the project to life. \r\n\r\nThe power comes from a sewable battery module running on a CR2032 battery, accompanied by a small switch so the creator does not need to remove the battery every time they want to turn the patch off. The circuitry is connected using conductive thread. \r\n\r\nSimpler designs can be completed during the session, but there is no pressure \u2014 each participant will take their own kit with them and can finish anywhere at the conference or at home. (I carry mine in my wallet.) These patches can be then sewn into clothes, accessories or whatever creative idea the maker comes up with. \r\n\r\nDuring the day they will be able to show their embroidery design and during the night the real magic comes out when everyone starts glowing and blinking.", "recording_license": "", "do_not_record": false, "persons": [{"code": "NCDM9A", "name": "Boris", "avatar": "https://cfp.balccon.org/media/avatars/NCDM9A_rjnQMvk.webp", "biography": "Boris Nim\u010devi\u0107 is an electronics and computer engineer by day and a maker by night. Throughout his career, he has worked on toys, fitness devices, 5G mobile base stations, and Internet of Things (IoT) devices. Wherever he has lived, he has been an active member of the local maker community\u2014from Leslie eLab in New York and Crash Space in Los Angeles to Stockholm Makerspace, where he is currently a member. Recently, he has focused on fostering the maker community and encouraging creativity by helping others discover the joy of making.", "public_name": "Boris", "guid": "5040884c-31ed-53f0-b178-a4373f041045", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/NCDM9A/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/YZPBVT/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/YZPBVT/", "attachments": []}, {"guid": "2b61a854-2f99-5db9-b109-ba2a609be839", "code": "ADARCS", "id": 158, "logo": null, "date": "2026-09-20T14:00:00+02:00", "start": "14:00", "duration": "01:30", "room": "Pupin", "slug": "balccon2k26-2026-158-tetra-workshop", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/ADARCS/", "title": "TETRA Workshop", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Come join us and make your own TETRA base station!", "description": "We will bring several SDRs and TETRA radios; you bring a laptop. Together, we will set up an open-source base radio station and test it with real hardware.\r\nWe will also bring higher-power amplifiers, filters, duplexers, and other RF components so you can see what a full base station setup looks like in practice.\r\nFeel free to come up to us during the workshop and talk about TETRA, SDRs, radio infrastructure, RF hardware, or mostly anything else.", "recording_license": "", "do_not_record": true, "persons": [{"code": "CTQ7S8", "name": "Sava", "avatar": null, "biography": "\u0160ava is an electrical engineer with a passion for breaking things open and seeing how they work. Lately has been researching subjects closely related to telecommunications. Likes exploring new ideas and sharing knowledge.", "public_name": "Sava", "guid": "4e810c24-f018-5a7b-8f6b-b5ac8c1695a8", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/CTQ7S8/"}, {"code": "CV8WQN", "name": "Mi\u0161a", "avatar": null, "biography": "Mi\u0161a(misadeks) is a software engineer, telecommunications student, and licensed ham radio operator. With a passion for embedded system design and building technology from scratch, his work sits at the intersection of low-level radio infrastructure and software development. Lately, his focus is on RF reverse-engineering and exploring modern radio communications.", "public_name": "Mi\u0161a", "guid": "5ab23608-b3a1-5f58-8451-92526538a9ca", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/CV8WQN/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ADARCS/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/ADARCS/", "attachments": []}, {"guid": "a9f2ad03-0310-53b7-a178-7adf769ff841", "code": "QSSAXP", "id": 151, "logo": null, "date": "2026-09-20T15:30:00+02:00", "start": "15:30", "duration": "03:00", "room": "Pupin", "slug": "balccon2k26-2026-151-shellcode-learning-to-write-position-independent-code", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/QSSAXP/", "title": "Shellcode: Learning to Write Position Independent Code", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "Shellcode is often treated as a dark art: small, opaque, and inseparable from exploit folklore. This workshop takes the opposite approach. It breaks shellcode down as a disciplined form of constrained systems programming, where every byte, register, calling convention, memory reference, and control-flow decision matters.\r\n\r\nParticipants will learn how shellcode is structured, how position-independent code works, and why common instruction patterns such as call/pop, base-register anchoring, stack construction, and compact control-transfer sequences appear so frequently in real-world payloads. The workshop will also cover Windows internals relevant to shellcode, including TEB and PEB access, API discovery, API hashing, syscall resolution, and indirect syscall techniques. Finally, it will explore more advanced building blocks such as tiny disassemblers, trampolines, and API interception hooks.\r\n\r\nThe goal is not to teach copy-paste payload development, but to give reverse engineers, malware analysts, exploit developers, and detection engineers a clear mental model for how shellcode actually works.", "description": "Shellcode sits at the intersection of exploit development, reverse engineering, operating system internals, compiler behavior, and malware analysis. It is small by design, but the ideas packed into it are dense: position independence, register discipline, stack layout, calling conventions, import resolution, syscall mechanics, and runtime code modification. This workshop is designed to make those ideas understandable and practical for security researchers who want to read, write, analyze, and detect shellcode with confidence.\r\n\r\nThe workshop begins with the fundamentals: what shellcode is, what constraints it normally operates under, and how those constraints shape its design. We will look at how shellcode avoids absolute addresses, how it locates its own data, and how instruction sequences can be combined to replace unavailable or undesirable operations. Examples include techniques such as call/pop for recovering a pointer to embedded data, using a register as a shellcode-relative base pointer, constructing strings and arguments on the stack, and reasoning about code that must execute correctly regardless of where it lands in memory.\r\n\r\nFrom there, the workshop moves into Windows-specific shellcode internals. We will examine how shellcode can discover process and module state without relying on normal imports, including TEB and PEB access, walking loader structures, resolving API addresses manually, and implementing API hashing. These topics are especially useful for malware analysts and detection engineers because they explain the recurring patterns seen in unpacked payloads, loaders, implants, and post-exploitation tooling.\r\n\r\nThe workshop then covers syscall-oriented shellcode. Participants will learn how user-mode API calls transition into kernel services, why direct and indirect syscall techniques exist, what tradeoffs they introduce, and how syscall resolution interacts with OS versioning, user-mode hooks, and EDR visibility. The focus will be on understanding the mechanisms and their analytical implications rather than treating syscalls as a magic bypass.\r\n\r\nThe final section explores more advanced shellcode building blocks: tiny disassemblers, instruction-length decoding, trampolines, inline hooks, and API interception. We will discuss how a compact decoder can be used to identify safe overwrite boundaries, install a trampoline, preserve original instructions, and redirect execution through a hook function. This portion connects shellcode development directly to the mechanics used in instrumentation, unpacking, malware loaders, and defensive research tooling.\r\n\r\nAll material is presented in a controlled lab context, with emphasis on responsible research, analysis, and defensive understanding. Attendees should leave with a practical framework for recognizing shellcode patterns, understanding why they work, and reasoning about small pieces of machine code with much greater precision.", "recording_license": "", "do_not_record": true, "persons": [{"code": "8GCJPF", "name": "Malware Utkonos", "avatar": "https://cfp.balccon.org/media/avatars/8GCJPF_3ilekmF.webp", "biography": "Robert Simmons is Principal Malware Researcher at ReversingLabs. With an expertise in building automated malware analysis systems based on open source tools, he has been tracking malware and phishing attacks and picking them apart for years. Robert, also known as Utkonos, has a background in Biology, Linguistics, and Russian Area Studies. He has spoken on malware analysis and reverse engineering at many of the top security conferences including BalCCon, DEFCON, HOPE, botconf, and DerbyCon among others. He is also the maintainer of plyara, a YARA rule parser written in pure python as well as x64dbgbinja the official connector integration between x64dbg and Binary Ninja.", "public_name": "Malware Utkonos", "guid": "333e400c-0c8a-5d77-8904-309447fdf1e1", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/8GCJPF/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/QSSAXP/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/QSSAXP/", "attachments": []}], "Lounge": [{"guid": "aedadf17-e7e3-535c-8c22-91356015e07e", "code": "WR9UHX", "id": 191, "logo": null, "date": "2026-09-20T19:10:00+02:00", "start": "19:10", "duration": "04:00", "room": "Lounge", "slug": "balccon2k26-2026-191-after-party", "url": "https://cfp.balccon.org/balccon2k26-2026/talk/WR9UHX/", "title": "After party", "subtitle": "", "track": null, "type": "Workshop120", "language": "en", "abstract": "After Party!", "description": "After Party", "recording_license": "", "do_not_record": true, "persons": [{"code": "9MSMWK", "name": "BalCCon", "avatar": "https://cfp.balccon.org/media/avatars/9MSMWK_CvklKYX.webp", "biography": "Test", "public_name": "BalCCon", "guid": "f451942b-cecb-5da6-baf6-8016659f9d63", "url": "https://cfp.balccon.org/balccon2k26-2026/speaker/9MSMWK/"}], "links": [], "feedback_url": "https://cfp.balccon.org/balccon2k26-2026/talk/WR9UHX/feedback/", "origin_url": "https://cfp.balccon.org/balccon2k26-2026/talk/WR9UHX/", "attachments": []}]}}]}}}