<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2025.2.2. -->
<schedule>
    <generator name="pretalx" version="2025.2.2" />
    <version>0.3</version>
    <conference>
        <title>BalCCon2k26</title>
        <acronym>balccon2k26-2026</acronym>
        <start>2026-09-18</start>
        <end>2026-09-20</end>
        <days>3</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://cfp.balccon.org</base_url>
        <logo>https://cfp.balccon.org/media/balccon2k26-2026/img/imagex_8L8yIf0_GtyjmsA.webp</logo>
        <time_zone_name>Europe/Amsterdam</time_zone_name>
        
        
    </conference>
    <day index='1' date='2026-09-18' start='2026-09-18T04:00:00+02:00' end='2026-09-19T03:59:00+02:00'>
        <room name='Tesla' guid='e0ed77fa-7e87-547c-b631-967f55cb26a5'>
            <event guid='44b7daed-84b0-51d7-b178-d25966cc777b' id='107'>
                <room>Tesla</room>
                <title>Opening</title>
                <subtitle></subtitle>
                <type>Lightning talk</type>
                <date>2026-09-18T13:00:00+02:00</date>
                <start>13:00</start>
                <duration>00:15</duration>
                <abstract>Opening ceremony</abstract>
                <slug>balccon2k26-2026-107-opening</slug>
                <track></track>
                
                <persons>
                    <person id='1'>BalCCon</person>
                </persons>
                <language>en</language>
                <description>Opening ceromony</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/DVY8SG/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d73cb982-8715-589a-81e6-9412d0a7c2a6' id='186'>
                <room>Tesla</room>
                <title>AI can&apos;t solder or Imagine (yet)</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T13:15:00+02:00</date>
                <start>13:15</start>
                <duration>00:40</duration>
                <abstract>Now everyone is vibe coding everything. AI agents are finding vulnerabilities so obscure that humans can&apos;t market it . 
 Is the days of &quot;hacking at late night banging your head against the screen&quot; over ? Are we now just going to prompt design our way into the history of hacking?  Maybe, maybe not.</abstract>
                <slug>balccon2k26-2026-186-ai-can-t-solder-or-imagine-yet</slug>
                <track></track>
                
                <persons>
                    <person id='71'>elkentaro</person>
                </persons>
                <language>en</language>
                <description>AI has definitely changed the landscape. But while everyone is looking to find the latest and greatest prompt injection , in the forgotten back rooms there are others marching on with what they do best. Make/hack/break things.

In this talk , elkentaro will talk about some of his pre-AI days creating and hacking tools and hardware the stories behind them. He will also go on and explain how AI has changed the process for him.

Originally this talk was titled 
&quot;I wanted to be Q from James Bond..I ended up being a hacker&#8221; 
but without &quot;AI something something&quot; its not as hot. It will be a talk about
making/breaking/hacking things, mostly wireless gadgets and other obsure
makings of elkentaro and how the recent rise of AI has changed some, but 
hasn&apos;t changed other aspects of being a hacker/maker.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/VHWVVY/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='74b9ff4e-ec94-52a8-80bd-95999ec4ce16' id='143'>
                <room>Tesla</room>
                <title>A vision for software freedom in 2048</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-18T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>01:00</duration>
                <abstract>Our litigation against Apple in front of the European Court of Justice, pushing for sustainable long term funding for Free Software in the EU and member states, &quot;Public Money? Public Code!&quot;, Device Neutrality, Router Freedom, Free Your Android, assistance with licensing questions, a European coding competition for teenagers, and a tale of software, skateboards, and raspberry ice cream. These are some of the activities by the Free Software Foundation Europe (FSFE), which this year celebrates its 25 anniversary in empowering users to control technology.

How would the world like in our area in 2048, if the FSFE has been successful? This talk will give an overview of the FSFE&apos;s vision and invite participants to give feedback on the next decades of our journey.</abstract>
                <slug>balccon2k26-2026-143-a-vision-for-software-freedom-in-2048</slug>
                <track></track>
                
                <persons>
                    <person id='107'>Matthias Kirschner</person>
                </persons>
                <language>en</language>
                <description>Our litigation against Apple in front of the European Court of Justice, pushing for sustainable long term funding for Free Software in the EU and member states, &quot;Public Money? Public Code!&quot;, Device Neutrality, Router Freedom, Free Your Android, assistance with licensing questions, a European coding competition for teenagers, and a tale of software, skateboards, and raspberry ice cream. These are some of the activities by the Free Software Foundation Europe (FSFE), which this year celebrates its 25 anniversary in empowering users to control technology.

How would the world like in our area in 2048, if the FSFE has been successful? This talk will give an overview of the FSFE&apos;s vision and invite participants to give feedback on the next decades of our journey.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/RNJ3DG/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='df047f4c-6f72-5313-893f-246804311a5e' id='124'>
                <room>Tesla</room>
                <title>The Agents of Chaos: AI Driven Malware Generation</title>
                <subtitle></subtitle>
                <type>Talk45</type>
                <date>2026-09-18T15:05:00+02:00</date>
                <start>15:05</start>
                <duration>00:45</duration>
                <abstract>With the use of AI agents catching wind across the offensive security space, from social engineering to vulnerability research, it was inevitable that malware would follow suit. While most discussions focus on targeting AI, using it to generate malicious payloads at a malware&#8217;s runtime, or &#8220;vibe coding&#8221; it, we went a step further: we built a system where AI is the sole participant in the malware creation process itself.
We will begin by talking about how we got to this point, what sparked the idea, and jump into comparing different models &#8211; showing which gave the best code, which was most evasive, which prompts worked the best, and what we used in the agent.
We will then dig into the generation process itself &#8211; we will show the challenges with earlier approaches, how we solved them, how to build the workflow to maximize the malware&#8217;s capability and randomization, how it managed to break signatures, and how to generate millions of samples.
We will finish by showing how attackers are using similar methods, look at real examples in the wild, and discuss how to use these techniques for ourselves, both as attackers and defenders.</abstract>
                <slug>balccon2k26-2026-124-the-agents-of-chaos-ai-driven-malware-generation</slug>
                <track></track>
                
                <persons>
                    <person id='100'>Arad Donenfeld</person>
                </persons>
                <language>en</language>
                <description>AI has already changed the offensive security space significantly, from autonomous phishing campaigns and deepfake based social engineering to AI assisted vulnerability research and fuzzing. Malware is the next step, and the question isn&#8217;t whether AI will be used to generate it, but how far that&#8217;s already gone and where it leads.
This talk covers a research project that builds an autonomous agent to generate new, functional, never seen before malware samples from scratch. The focus is on the full process: what models to use and why, how to prompt them, how to ensure the output compiles and works, how to break static signatures, and how to scale generation into the millions of unique samples.

The main topics covered:

AI driven offensive security and AI driven malware
AI is already being used across the offensive security space, from phishing to full vulnerability research and fuzzing, and malware seems like the obvious step as AI &#8220;will replace all developers&#8221;, why not malware developers? What does AI driven malware even mean? What are the different possibilities that AI in malware gives us?

The generation process: models, prompts, and workflow
Before automating anything, manual testing across of models and prompts is needed. After that, how can we ensure that the malware is random, compileable, and will work flawlessly? There are several steps that need to be taken before that can be achieved: from planning the malware, to writing and fixing it, to then actually validating its functionality with AI as a judge, all without human interaction.


Adding variety in the samples
The agent makes a lot of decisions based on a plan that it creates beforehand, for example, there are several ways to traverse a directory in Windows, there are several encryption algorithms that can be used, all of these and more do affect the result. In restructuring the project from one file to several, adding different languages, asking for specific capabilities (without specifying how to implement them), all adding to the number of decisions and possibilities.

AI malware in the wild
Malicious actors are already using these ideas in the wild: from general vibe coding and assisted development to full autonomous agents and workflows that create full malware and attack frameworks, to deter and disrupt defence mechanisms and blue teams.

Takeaways for defenders and attackers
AI generated malware lowers the bar for attackers significantly: guardrails on frontier models are consistently bypassed, and local models require no permissions at all, but behaviour based detection remains effective because functional patterns persist even as signature changes. The same generation pipeline can be turned into a red teaming tool to test your own systems and see what you know about your environment.

What Can You Gain From This
&#8226;	A technical walkthrough of how an autonomous agent generates functional malware samples end to end, including the prompting strategies, model selection, and loops involved.
&#8226;	Test results comparing different models, prompts, and methods, while sticking to actual detection rates.
&#8226;	A framework for generating diverse malware samples at scale for use in testing detection systems.
&#8226;	Documented real world examples of AI assisted and AI integrated malware from attributed threat actors.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/AP9VB7/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='8d7cc552-d9e0-5bef-aa33-ba96b64347bc' id='160'>
                <room>Tesla</room>
                <title>Comparing Malicious Files 2.0</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-18T16:00:00+02:00</date>
                <start>16:00</start>
                <duration>01:00</duration>
                <abstract>This talk is about using LLMs to build and modernize software where correctness matters. It follows the work at two scales: modernizing a similarity-digest algorithm that must match its reference implementation bit-for-bit, and building malbench, a local-first triage and clustering workbench for malware analysts.
malbench is a local-first triage and clustering workbench for malware analysts. It pulls samples and threat intelligence from various sources, computes similarity digests, runs YARA rules, and then turns a flat pile of hashes into structure: it clusters and graphs files by features they actually share and weaves several of those lenses into a single view.
I needed a wider variety of hashing algorithms, so in addition to ssdeep and TLSH, I took a dormant 2021 Go port of sdhash, a similarity-digest algorithm used in malware triage and code-reuse detection, and modernized it into a clean, dependency-free, fully-tested library. A deterministic verification corpus and parallel C++/Go harnesses turn the original reference implementation into an oracle: millions of pair comparisons, zero unexplained divergences. Around that sit total test coverage as a drift alarm, strict session and context hygiene, profile-before-you-optimize with one change measured at a time. The result is a repeatable process for adopting and modernizing old code and for building new tools on top of it.</abstract>
                <slug>balccon2k26-2026-160-comparing-malicious-files-2-0</slug>
                <track></track>
                
                <persons>
                    <person id='2'>Malware Utkonos</person>
                </persons>
                <language>en</language>
                <description>How do you use AI models on code that has to be correct, without their confident mistakes silently landing in your output? This talk answers that with a concrete, repeatable process, demonstrated end to end on a real library, and on the larger tool that library is being built for. That tool is malbench, a local-first triage and clustering workbench for malware analysts. It pulls samples and threat intelligence from various sources, computes similarity digests, runs YARA rules, and then turns a flat pile of hashes into structure: it clusters and graphs files by what they actually share and weaves several of those lenses into one view.
The subject of the overall process is sdhash, a similarity-digest (fuzzy hashing) algorithm that fingerprints binary data into bloom filters and scores two fingerprints for similarity. It has a C++ reference by Vassil Roussev and Candice Quates and a 2021 Go port that had gone dormant for over three years. This is exactly the kind of valuable-but-abandoned code worth adopting rather than rewriting. The goal was to bring it forward into a clean, modern, dependency-free Go library with an idiomatic sealed API, full documentation, and total statement coverage.
The spine of the effort, and the core defense against hallucination, is that ground truth comes first. Before trusting a single line the model produced, I built a deterministic, seed-reproducible corpus and parallel C++/Go harnesses, ran it through both, and diffed the outputs with an independent tool. That turns the reference into an oracle: any divergence, a real bug or something a model invented, surfaces immediately as a mismatch. Generation parity held across more than a hundred thousand files and scoring parity across nearly three million pair comparisons in both modes, at zero unexplained divergences.
The process surfaced first three correctness problems in the C++ implementation scoring as well as a problem with the hashing algorithm itself. Each change to the algorithm was carefully isolated and the effects on scoring measured. This talk goes into detail all of the tooling and process used to get sdhash up to snuff and then plug it in to malbench. You will also learn about the graphing and clustering algorithms used to visualize the results of the different malware hashes.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/PQ9QZT/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='9b886886-60e0-5521-a08e-d5bd56ba333c' id='185'>
                <room>Tesla</room>
                <title>Hacking in the Middle of the Ocean</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T17:00:00+02:00</date>
                <start>17:00</start>
                <duration>00:30</duration>
                <abstract>Modern ships have evolved into floating data centers, combining operational technology (OT), IT, satellite communications, cloud connectivity, and autonomous decision support. While digitalization has improved efficiency, it has also introduced attack surfaces that many organizations underestimate.

This presentation explores the cyber realities of today&apos;s maritime industry through the perspective of an attacker and a defender. The talk will cover common misconceptions surrounding &quot;air-gapped&quot; vessels, the unique challenges of securing ships at sea, and why traditional enterprise security approaches have challenges in maritime environments.</abstract>
                <slug>balccon2k26-2026-185-hacking-in-the-middle-of-the-ocean</slug>
                <track></track>
                
                <persons>
                    <person id='74'>Vlatko Kosturjak</person>
                </persons>
                <language>en</language>
                <description>Talk will show some unique challenges as well as speaker vulnerability research in maritime industry.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/BBTUHZ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='0119461b-f106-510f-8bb9-6bdf7ed79560' id='154'>
                <room>Tesla</room>
                <title>Hunting for business logic vulnerabilities</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-18T17:30:00+02:00</date>
                <start>17:30</start>
                <duration>01:00</duration>
                <abstract>Security issues are becoming harder to detect or exploit, especially in well audited targets. Instead of subverting the code flow, an attacker might try to subvert the application logic. This class of vulnerabilities is commonly referred to as business logic vulnerabilities. In this session, we will present the result of a research study where the author manually reviewed about 300 publicly disclosed vulnerability reports and tried to classify and cluster discovered vulnerabilities into a few categories that can be used to secure business logic issues in applications. So let&apos;s take a ride through some real life cases and examples on how to manipulate calculation, assumptions, processes, branching, logical and time based TOCTOU and other fun cases on how to break an modern application.</abstract>
                <slug>balccon2k26-2026-154-hunting-for-business-logic-vulnerabilities</slug>
                <track></track>
                
                <persons>
                    <person id='117'>Tonimir Kisasondi</person>
                </persons>
                <language>en</language>
                <description>There are a number of well known classes of vulnerabilities that an enterprising hacker or penetration tester wants to uncover in an application. Some of those issues are harder to detect or exploit because of well implemented browser security mechanisms or because of various improvements in web application frameworks that hide the potentially dangerous methods from the developers. In addition to the points outlined above, the collective awareness about common security issues, vulnerabilities and potential weaknesses has been raised, making discovery of potential issues more difficult, especially in hard, well audited targets.

In such cases, instead of subverting the code flow, an attacker might try to subvert the applications logic or even better manipulate the business process that the application supports. This class of vulnerabilities is commonly referred to as business logic vulnerabilities, and when discovered in the wild and reported, all the specific and different nuanced cases of vulnerabilities are usually thrown into the bucket labeled &quot;business logic&quot; vulnerabilities. But when we review such issues, we can see that each case is unique. 

This talk will present the result of a research study where the author manually reviewed about 300 publicly disclosed vulnerability reports and tried to classify and cluster discovered vulnerabilities into a few categories that can be used to detect business logic issues in applications. So let&apos;s take a ride through some real life cases and examples on how to manipulate calculation, assumptions, processes, branching, logical and time based TOCTOU and other fun cases on how to break an application.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/UEYM89/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='3ee26f99-1b28-58d0-b9fa-3cf5a4fe0cee' id='155'>
                <room>Tesla</room>
                <title>You build vulnerable hardware accidentally. I do it on purpose. We are not the same. (Behind the scenes of building hardware CTF challenges)</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T18:30:00+02:00</date>
                <start>18:30</start>
                <duration>00:30</duration>
                <abstract>We built hardware challenges for Serbian national CTF... twice. Building a good hardware challenge is a balancing act between security, education, creativity, and logistics. The talk follows the entire process, from the initial idea and vulnerability selection to hardware and challenge design, storytelling, participant experience, manufacturing, and deployment at the competition.

Technical level: Beginner/Intermediate. No prior hardware security experience or preparation is required. The talk is intended for anyone interested in hardware, embedded systems, cybersecurity, or CTF challenge design.</abstract>
                <slug>balccon2k26-2026-155-you-build-vulnerable-hardware-accidentally-i-do-it-on-purpose-we-are-not-the-same-behind-the-scenes-of-building-hardware-ctf-challenges</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/QF7RUJ/balccon_rUjRFK2_ZUKuXZQ.webp</logo>
                <persons>
                    <person id='118'>Maja Miljani&#263;</person><person id='122'>TheProxy</person>
                </persons>
                <language>en</language>
                <description>Our talk presents the process of creating the hardware challenges used in the Serbian National CTF in 2025 and 2026. In both editions, we designed custom embedded devices with intentionally introduced vulnerabilities, built specifically to be exploited during the competition. From selecting realistic attack vectors and hardware components, designing PCBs and firmware, manufacturing the boards, and preparing the competition environment, to watching students solve them during the event, we were involved in every stage of the process.

This talk explores how the challenges are conceived, designed, built, and deployed. Along the way, we will discuss the technical and practical trade-offs, the lessons we learned, and the challenges of creating educational, engaging, and reliable hardware CTF tasks.

The talk is suitable for attendees with a beginner/intermediate level of technical knowledge. Whether one is interested in hardware security, embedded systems, or CTF competitions, they will gain a behind-the-scenes understanding of how hardware challenges are designed, built, and deployed. No prior experience with hardware hacking or specialized tools is required.

The talk will follow the outline below:

### Motivation

- Why we decided to introduce hardware challenges to the Serbian national CTF.
- Inspiration from ECSC, where hardware challenges have been a regular competition category.
- Our backgrounds and how the project came together.

### Hardware CTF Design Principles

- What makes a good hardware CTF challenge.
- Constraints and trade-offs: budget, accessibility, educational value, realism, and fun.
- Examples of hardware challenges from ECSC and the ideas that inspired our designs.

### 2025 Challenge

- Initial concept and design goals.
- Hardware architecture, component selection, and PCB design.
- Manufacturing.
- Challenge narrative and participant experience.
- Vulnerabilities and intended attack paths:
	- UART
	- eFuse
	- USB HID
	- Vulnerable OTA updates
	- Unsafe cryptographic secret storage
	- Reverse engineering
    

### 2026 Challenge

- Design goals and concept of a fictional game console.
- Hardware architecture, component selection, and PCB design.
- Manufacturing.
- Challenge narrative and gameplay.
- Vulnerabilities and attack techniques:
	- Introductory side-channel analysis
	- SPI bus sniffing and display reconstruction
	- Logic analyzer usage
	- Timing attacks using PIO

### Lessons Learned

- Challenge balancing and playtesting.
- Designing intentional vulnerabilities.
- Manufacturing, logistics, and deployment during the competition.
- What worked well and what we would do differently.

### Future Directions
Ideas for future competition challenges:
- Glitching and fault injection.
- Power analysis.
- NFC/RFID.
- Radio protocols.
- CAN bus.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/QF7RUJ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='4289c9b3-3350-51b2-addb-86bfb0cea13d' id='182'>
                <room>Tesla</room>
                <title>Your Lock(er) Knows Your PIN ... And So Do I</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T19:00:00+02:00</date>
                <start>19:00</start>
                <duration>00:45</duration>
                <abstract>Electronic lockers are everywhere - offices, gyms, hotels, hospitals, co-working spaces. You choose a PIN, toss in your stuff, and trust that it&apos;s safe. The same goes for electronic safes in hotel rooms and offices. But what does the lock actually do with your PIN? Turns out, it remembers it. And not very carefully.

We demonstrate how someone with access to a single open locker or safe can extract credentials, clone manager keys, and open every lock in an installation using cheap and widely available tools. More critically, we show how harvested PINs open more than just lockers: the same PIN that protects your locker or hotel safe often unlocks your phone, your laptop, and your bank card.

We discuss why reusing a PIN across devices is a terrible idea, how RFID credentials stored in locks can be used to open doors they were never meant to open, and whether vendors have actually fixed anything since we first told them about these issues.

If you&apos;ve ever chosen the same PIN for your locker, your safe, and your phone - this talk is for you.</abstract>
                <slug>balccon2k26-2026-182-your-lock-er-knows-your-pin-and-so-do-i</slug>
                <track></track>
                
                <persons>
                    <person id='138'>Dennis Giese</person>
                </persons>
                <language>en</language>
                <description>This talk is a continuation of our DEFCON 32 research on electronic locker locks. We discuss the general problem of how electronic locks handle user-chosen secrets, revisiting vulnerabilities in locks from multiple manufacturers. We focus on what these devices store: user PINs, RFID UIDs, manager credentials, and audit logs - often in plaintext and trivially extractable.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/AKXHPM/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='903ca1bf-a317-5e3c-baa9-77fecfb015f0' id='153'>
                <room>Tesla</room>
                <title>Fun with virtualization</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T19:45:00+02:00</date>
                <start>19:45</start>
                <duration>01:00</duration>
                <abstract>We got called to an Incident Response case. They said it was a limited incident. It turned out not to be.</abstract>
                <slug>balccon2k26-2026-153-fun-with-virtualization</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/8HJGZ8/we_need_to_go_deeper_tBFmBhb_NQfRlm0_DBhJB2i.webp</logo>
                <persons>
                    <person id='115'>Hank Scorpio</person><person id='116'>Scorpio Hank</person>
                </persons>
                <language>en</language>
                <description>Working in Incident Response sometimes means you get to go on a grand adventure, where you run into adversaries employing clever techniques to make your digital firefighting life difficult. In this talk we take you along on our journey, cover the People, Processes and Technologies angles and hopefully give you some tips and tricks for dealing with these types of threats.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/8HJGZ8/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='7966c8e1-5d2b-5797-919b-f382f32ca7d8' id='172'>
                <room>Tesla</room>
                <title>Hacker Jeopardy</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-18T22:30:00+02:00</date>
                <start>22:30</start>
                <duration>03:00</duration>
                <abstract>Clue: This glorious competition pits the sharpest minds and greatest nerds of this illustrous community (or, whoever want&apos;s to participate really...) against each other in a battle of wits. Contestants show their prowess and speed in hitting buzzers as well as their knowledge about modern, ancient and archaic topics ranging from security to pop culture, while the audience revels in the geeky glory.

Answer: What is Hacker Jeopardy?</abstract>
                <slug>balccon2k26-2026-172-hacker-jeopardy</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/ZKQTEK/card_znpKxJ7_k9AI7M5.webp</logo>
                <persons>
                    <person id='61'>cluosh</person><person id='73'>georg</person><person id='52'>Hetti</person>
                </persons>
                <language>en</language>
                <description>We will play some rounds of hacker jeopardy. If you ask yourself: &quot;What the heck is Jeopardy?&quot;, you already got the gist of the game, as all answers need to be formulated as questions! Participants will have to answer questions in different categories to get the most points. But beware, it&apos;s not only about knowing the answer, you also need to be fast with a buzzer! Are you up for the challenge?</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/ZKQTEK/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Pupin' guid='53506c9f-44c9-55f0-aaf6-4efebf31ed1e'>
            <event guid='33deeb35-f2ed-545e-93b2-83359debb00e' id='157'>
                <room>Pupin</room>
                <title>FROST: SSD Side Channels from the Browser, and Why You Should Care</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>00:30</duration>
                <abstract>The FROST attack fingerprints the websites and apps you use from plain JavaScript in a tab - by measuring SSD contention from the browser. We cover how it works, how realistic the attack is, and who actually needs to care.
Additionally, we show a few other remote side channels to show what is possible in theory for motivated attackers.</abstract>
                <slug>balccon2k26-2026-157-frost-ssd-side-channels-from-the-browser-and-why-you-should-care</slug>
                <track></track>
                
                <persons>
                    <person id='123'>Hannes Weissteiner</person>
                </persons>
                <language>en</language>
                <description>Earlier this year, we published &quot;FROST: Fingerprinting Remotely using OPFS-Based SSD Timing&quot;. The paper made the news, likely because &quot;a website can spy on you if you click a link&quot; makes a good headline. Reactions were split: Some people wanted to disable JavaScript completely, claiming that allowing websites to execute scripts on client devices was a mistake in the first place. Others waved the attack off as a toy example that only works in a lab, never feasible in the real world.

For us, the truth lies somewhere in the middle.

FROST is a real attack. From plain JavaScript, we measure SSD contention from the browser and use it to fingerprint the websites you visit and the apps you open, without requiring any additional interaction beyond clicking a malicious link.
It&apos;s also fragile: Classification depends on training data, and prior work has shown that trained models cannot easily be generalized to different SSD models.

This talk presents the attack, and gives some intuition about the underlying insights. Does the average user need to be scared? Who actually needs to care? Why do browsers allow this in the first place?  And what are side-channel attacks anyways?
Additionally, we give an overview of other remote side-channel attacks, showing what&apos;s possible in theory to a motivated attacker.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/78CRUA/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='2343e48e-4a1e-522d-a4a6-4fb6e3f5a45c' id='164'>
                <room>Pupin</room>
                <title>Detecting Linux rootkits: Know where to look in user-space</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T14:30:00+02:00</date>
                <start>14:30</start>
                <duration>00:30</duration>
                <abstract>Linux rootkits rely on a handful of techniques to hide malicious code. There&apos;s nothing magic that can&apos;t be overcome, we just have to know from what angle to look.</abstract>
                <slug>balccon2k26-2026-164-detecting-linux-rootkits-know-where-to-look-in-user-space</slug>
                <track></track>
                
                <persons>
                    <person id='128'>Hilko Bengen</person>
                </persons>
                <language>en</language>
                <description>Rootkits are designed to hide themselves or other malicious software from users&apos; and administrators&apos; prying eyes. To create the illusion that nothing is there and everybody is fine to move along, they usually subvert tool output, standard library functions or kernel system calls to hide the presence of specific processes or files.

This illusion is often just convincing enough to fool standard tools, but if we put a little more effort into observing system behavior, we can still see shadows of what has been hidden, by relying on traces that are hard to cover by rootkit authors.

In this talk I take a look at rootkit implementations that subvert the system at different layers &#8211; the system call interface, the standard library, or through eBPF probes. I give an overview over detection techniques that have been implemented in traditional rootkit hunting scripts, plus a few novel methods. 

I present a modern implementation of the most promising techniques that can be integrated with existing live-forensic capabilities to hunt for rootkits at scale.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/TVDMBV/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='746cdb33-6be7-5216-a031-7eae8a47d194' id='139'>
                <room>Pupin</room>
                <title>Deconstructing Modern macOS Initial Access Vectors</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T15:00:00+02:00</date>
                <start>15:00</start>
                <duration>00:40</duration>
                <abstract>For years, a persistent myth suggested that macOS was inherently immune to malware. Today, threat actors are aggressively shattering that illusion by deploying sophisticated initial access chains tailored to bypass macOS defenses. This talk provides a deep-dive analysis of how modern adversaries gain their first foothold on Apple hardware.

We will dissect the entire initial access pipeline, starting with Infection Vectors like deceptive Google Ads, malicious ClickFix campaigns, and sophisticated malvertising that trick users into lowering their guard. From there, we explore the Execution Phase, analyzing how attackers weaponize scripting languages, including traditional Bash and Python, as well as native AppleScript, Compiled AppleScript, Perl, and JavaScript for Automation (JXA). 

Finally, we will examine the delivery mechanisms, contrasting the abuse of native Binaries (Mach-O, Platypus-packaged apps, and Electron frameworks) with the trojanization of Storage and Installer Formats (DMGs and PKGs).

Attendees will walk away with a technical understanding of contemporary macOS tradecraft, real-world attacker methodologies, and the insights needed to hunt for and defend against modern Mac-focused threats.</abstract>
                <slug>balccon2k26-2026-139-deconstructing-modern-macos-initial-access-vectors</slug>
                <track></track>
                
                <persons>
                    <person id='106'>Stephan Berger</person>
                </persons>
                <language>en</language>
                <description>We begin by exploring the top of the funnel. Attackers have moved far beyond easily identifiable spam. We will deconstruct recent campaigns to show how adversaries are successfully lowering user guard through:

How threat actors weaponize Google Ads to push malicious software disguised as legitimate enterprise tools (e.g., Slack, Notion, or VPN clients).
A deep dive into localized, highly convincing fake browser updates and system notification campaigns that socially engineer users into bypassing native warnings.

Once the user interacts with the lure, how does the malware actually run? macOS is a rich Unix-based environment with multiple scripting avenues. We will analyze the &quot;Living off the Land&quot; (LotL) techniques currently dominating the macOS threat landscape, including:

The use of Bash, Zsh, and legacy Python/Perl scripts to establish persistence and pull down secondary payloads.
How attackers weaponize Apple&#8217;s native automation languages to silently interact with system APIs, bypass sandbox restrictions, and generate convincing fake credential prompts.
Techniques used by threat actors to obfuscate their code, making static analysis incredibly difficult for defenders.

Finally, we will break down how these threats are packaged to evade Gatekeeper and initial static analysis. We will compare and contrast real-world samples across:

The weaponization of standard Apple Disk Images (.dmg) and Installer Packages (.pkg), including pre-install/post-install script abuse.
The shift from standalone Mach-O binaries to hiding malicious routines inside Platypus-packaged applications and bloated Electron frameworks, which are notoriously difficult for traditional AV to parse effectively.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/ZXZZQN/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='2e94864e-4bd1-5cea-bcf5-464ca9720b1a' id='165'>
                <room>Pupin</room>
                <title>Renting Brains, Owning the Mistakes: LLMs in Cybersecurity Education</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T16:00:00+02:00</date>
                <start>16:00</start>
                <duration>01:00</duration>
                <abstract>Students already use LLMs for almost everything: explaining concepts, writing reports, debugging their labs, and sometimes skipping the hard part of learning altogether. And they will not stop when they graduate: the habits formed in a lecture hall follow them into the SOC and the codebase, which makes how we teach with these tools a security problem, not just an academic one.
This talk briefly sets out why we care about LLMs, the economics, the energy, and the jobs behind the hype, then draws on hands-on experience teaching cybersecurity at the University of Turku. I&apos;ll share where LLMs genuinely help students and where they quietly erode the skills the field depends on.</abstract>
                <slug>balccon2k26-2026-165-renting-brains-owning-the-mistakes-llms-in-cybersecurity-education</slug>
                <track></track>
                
                <persons>
                    <person id='129'>Ismayil</person>
                </persons>
                <language>en</language>
                <description>Total length : 45-50 min + 10-15 min Q&amp;A
Part 0 &#183; Who, and why listen

whoami: PhD researcher, occasional lecturer, TurkuSec chair; teaching cybersecurity at the University of Turku.
Brief mention UTU / TurkuSec context for credibility.
Core idea is that an LLM is neither enemy nor friend a tool with a user, and the user owns the mistakes.

-------------------------------------------------------------------------------------------------------------------------------------------------------------------


Part 1 &#183; Why we care

Evangelist people think LLMs are good, and get only better, and it is impossible to get harm from it, and while they measure who burnt more tokens within 24h frames, people pay for it, and sometimes they pay too much.

&quot;It&apos;s cheap&quot; &#8594; economics. Uber burned its planned 2026 AI-coding budget in four months; engineers at $500&#8211;$2,000/mo; OpenClaw chewing $1&#8211;5k/day on a $200 plan; GitHub freezing Copilot sign-ups. At today&apos;s subsidized pricing the unit economics are propped up, not &quot;it will collapse,&quot; but someone else is absorbing the bill.

&quot;It&apos;s eco-friendly&quot; &#8594; energy &amp; where it lands. Tiny per prompt (0.24 Wh) vs vast in aggregate (~945 TWh by 2030); Jevons paradox; Google&apos;s own emissions up despite efficiency gains &#8594; then the local cost: Vantage VA, xAI Memphis, and externalities on bills, rent, land, sleep. LLM data centers cause severe pollution and harm people.

&quot;It&apos;s a revolution, not a bubble&quot; &#8594; jobs &amp; failures. Layoffs framed as AI efficiency (Oracle, Meta, Microsoft, Amazon); real-world breakage (AWS/Kiro outage, the wiped DataTalks database, the Fastly senior-vs-junior split).
These claims are backed by independent papers and expert review of the waste and pollution LLMs produce.
Other claims supporting the point are interviews of local people complaining about noise, pollution and general detrimental impact of LLMs.
Students use these tools constantly and won&apos;t stop at graduation. The habits formed in the lecture hall walk into the SOC. So this is an education problem &#8212; which is where the rest of the talk lives.

-------------------------------------------------------------------------------------------------------------------------------------------------------------------

Part 2 &#183; The new learning reality
Taking Part 1 into account, why don&apos;t we want students to abuse LLMs? What they do at University becomes a habit once they start working.

Students already use LLMs for everything (to explain, to summarize, to write, to code, to debug, to exam-prep, and sometimes to skip the learning entirely).
UTU permits responsible use; the question is no longer whether but how.
Google-fu is dying from &quot;find and think&quot; to &quot;ask and accept&quot; (StackOverflow decline; same effect we observe at university, students do not google basic problems, and when LLM troubleshooting fails they immediately email us, and we reply with the first link on google).
The real problem: usage without structure, without knowing what these tools are good at, bad at, and where they quietly fail.

-------------------------------------------------------------------------------------------------------------------------------------------------------------------

Part 3 &#183; Where it quietly erodes &#8212; the bad

Faster learning, weaker thinking: outsourcing the struggle &#8800; growth; a correct output doesn&apos;t prove understanding.
Most students don&apos;t verify; fluency is mistaken for correctness; beginners are most exposed to smooth nonsense.
Since most of the students LACK the experience (especially relevant for bachelor students), they immediately believe LLM, even when the facts are wrong.
Hands-on skills vs AI assistance: learn the underlying skill before automating it. Some students lack basic IT skills, and LLM is making it worse.
The purpose of homework is to solidify the knowledge on the matter, not to feed it to LLM for training the model and getting your answers.
Sharing a couple of negative examples from teaching time at UTU (no text on slide, but rather storytelling, 3 mins)
Sharing students&apos; feedback on LLM incorporation to the course (This is being collected currently, ready in August)

-------------------------------------------------------------------------------------------------------------------------------------------------------------------

Part 4 &#183; The flip: where it genuinely helps &#8212; the good

The pivot: same tool, different user. The fluent output that fools a beginner teaches a careful student what good looks like.
Personal tutor: patient, available at 2am, removes the social cost of asking &#8212; especially for shy, Finnish, and non-native students.
From theory to &quot;it works&quot;: environment-specific debugging companionship; the moment students used to quit becomes the moment they get unstuck.
It generates a lot of research avenues &#8594; master&apos;s/bachelor&apos;s theses, PhD dissertations, research assistants.
Force multiplier for instructors: faster lab design, exam variants, tighter feedback loops.
Self-study that finally works; serious entry points beyond the syllabus.
Language equity: non-native speakers judged on their security thinking, not their prepositions.
Sharing a couple of positive examples from teaching time at UTU (no text on slide, but rather storytelling, 5-6 mins)
Sharing the students&apos; feedback on LLM incorporation to the course (This is being collected currently, ready in August)

-------------------------------------------------------------------------------------------------------------------------------------------------------------------

Part 5 &#183; Why verification is the whole game &#8212; capstone risk

The hardest risk we are afraid of at UTU isn&apos;t hallucination, it&apos;s bias you can&apos;t see.
Historical analogues: Sugar Research Foundation / Harvard (1967); Coca-Cola&apos;s GEBN; Merck/Vioxx ghostwriting (~55k deaths, Graham&apos;s FDA testimony).
Those manipulations had to clear high bars and fool trained audiences. The audience for LLMs is everyone &#8212; including future doctors and regulators, while they&apos;re still students.
The 2+2=5 problem: we learned to question the press and social media; we haven&apos;t learned to question the model. The presentation is the persuasion.
What if tomorrow an LLM starts telling students that telnet is a good idea or introduces some subtler bias? Because students trust the model, they won&apos;t double-check the claim; they&apos;ll simply believe it.

-------------------------------------------------------------------------------------------------------------------------------------------------------------------

Part 6 &#183; Takeaways &amp; close

Neither enemy nor friend; a tool with a user, but the current approach is alarming
Verification is the new baseline literacy.
Compress work, don&apos;t replace judgment.
Cybersecurity education is uniquely positioned to lead.
The students who benefit most are the ones we were quietly losing.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/WNJR8M/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d2f8d73e-6c30-59ed-8c03-fb6ab2bb6c7a' id='178'>
                <room>Pupin</room>
                <title>Human Error Is Not the Problem: How Hiring, Culture and Psychology Shape Cyber Risk</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-18T17:00:00+02:00</date>
                <start>17:00</start>
                <duration>00:30</duration>
                <abstract>Cybersecurity conversations often treat &#8220;human error&#8221; as the weakest link, but in real organizations the problem usually starts much earlier: in hiring, onboarding, incentives, culture, unclear ownership, social pressure, burnout and badly designed internal processes.

This talk connects cybersecurity with organizational psychology and HR practice. It explores how companies unintentionally create human-risk conditions long before an employee clicks a phishing link, shares access, ignores a policy, trusts a fake profile or bypasses a procedure to &#8220;get the job done&#8221;.

The session is intended for security professionals, founders, HR people, managers and anyone interested in the human side of security. It will be practical and beginner-friendly, with examples from recruitment, employee assessment, fake identities, insider-risk patterns and security culture. The goal is not to blame people, but to show how organizations can reduce cyber risk by designing better human systems.</abstract>
                <slug>balccon2k26-2026-178-human-error-is-not-the-problem-how-hiring-culture-and-psychology-shape-cyber-risk</slug>
                <track></track>
                
                <persons>
                    <person id='135'>Nata&#353;a Vasi&#263;</person>
                </persons>
                <language>en</language>
                <description>1. Introduction: why &#8220;human error&#8221; is an incomplete explanation
The talk starts by challenging the usual narrative that people are simply careless, lazy or untrained. In many cases, insecure behavior is a predictable result of the environment: pressure, unclear responsibilities, weak processes, bad communication and poor hiring decisions.

2. Where cyber risk begins before the cyber team sees it
This part explains how risk enters the organization through recruitment, onboarding, role design, access decisions and organizational culture. Examples include rushed hiring, unverified candidates, fake profiles, poor reference checking, excessive access, lack of psychological safety and unclear escalation paths.

3. Social engineering and the psychology of trust
The talk explores why people trust the wrong signals: authority, urgency, familiarity, similarity, politeness and fear of conflict. It connects phishing, impersonation, fake candidates and internal manipulation to basic psychological mechanisms.

4. Insider risk without Hollywood drama
This section explains that insider risk is not only malicious employees stealing data. It can also include frustrated employees, overloaded teams, people bypassing procedures, unmanaged contractors, unclear accountability and people with access they no longer need.

5. Why awareness training is not enough
Security awareness often fails because it treats people as isolated decision-makers. The talk explains why behavior changes only when incentives, workflows, leadership behavior and consequences are aligned.

6. What HR and security teams should do together
The final practical section suggests a basic cooperation model between HR, security and leadership: better hiring checks, access hygiene, role-based onboarding, psychological safety for reporting, exit procedures, manager training and clearer internal communication.

7. Conclusion
The talk ends with a simple message: people are not the weakest link by default. Poorly designed systems make them weak. Better human systems create better security.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/KYZCRH/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='5c87bc5c-d509-50c6-8727-6bc68070d349' id='171'>
                <room>Pupin</room>
                <title>The Hitchhikers Guide to Hacking Cheap Bluetooth Speakers</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-18T17:30:00+02:00</date>
                <start>17:30</start>
                <duration>01:00</duration>
                <abstract>The story so far: In the beginning closed Hard- and Software was created.
This has made a lot of people very angry and been widely regarded as a bad move.
(Wrong book, I know...)</abstract>
                <slug>balccon2k26-2026-171-the-hitchhikers-guide-to-hacking-cheap-bluetooth-speakers</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/MPPFNF/info_s_W6iKcjD_DdFjzZg.webp</logo>
                <persons>
                    <person id='73'>georg</person><person id='61'>cluosh</person>
                </persons>
                <language>en</language>
                <description>Deep inside the shelves of our nearest IKEA store, hidden between smart appliances, there lies the cheap IKEA KALLSUP, a Bluetooth speaker, that promises limitless possibilities. Well, maybe not limitless. But it does allow synchronization of up to 100 devices. Supposedly at least, we did not buy 100 of them. However, it is not this promise of connectivity that caught our attention, but the curiosity about the intricacies of the internals of such a cheap device. 

Follow us along on our journey into the unknown, hitchhiking on the experiences made by those who came before us, while we dive into reverse engineering of cheap, undocumented chips, analyzing firmware, and other general tomfoolery.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/MPPFNF/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='c5692181-0a8b-5dc8-aa98-4f4b39c95549' id='170'>
                <room>Pupin</room>
                <title>A Street Sign, a Shadow, and an Answer: OSINT Workshop</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-09-18T18:30:00+02:00</date>
                <start>18:30</start>
                <duration>02:00</duration>
                <abstract>Somewhere in a public photograph, a street sign is partially visible. The shadow falls at a specific angle. Someone left a comment years ago that does not quite add up. These details are not hints, they are evidence, sitting in the open the whole time.

This workshop is a two-day journey into modern OSINT methodology. On the first day, we&apos;ll break down real investigations live, showing how publicly available information can be turned into precise, defensible conclusions. On the second day, the theory disappears and the investigation begins, as participants tackle a series of increasingly challenging OSINT cases in a competitive CTF-style hackathon. Bring a laptop, a browser, and a willingness to chase rabbit holes.</abstract>
                <slug>balccon2k26-2026-170-a-street-sign-a-shadow-and-an-answer-osint-workshop</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/BZXNHH/banner_LOb6LsU_Txymfnl.webp</logo>
                <persons>
                    <person id='124'>Jurica Radovi&#263;</person>
                </persons>
                <language>en</language>
                <description>The workshop is split across two conference days.

Day one is a practical introduction to investigative methodology through live demonstrations and guided walkthroughs. Rather than memorising tools, participants learn how to think like investigators: building hypotheses, verifying evidence, eliminating bad assumptions, and documenting conclusions that others can reproduce. Topics include geolocation, image verification, archive research, metadata, social media investigation, and practical search techniques, all demonstrated using publicly available information.

Day two is a competitive OSINT CTF/Hackathon where participants apply those techniques to solve a series of progressively harder challenges inspired by real investigations. Teams of up to three compete to identify people, places, events, and relationships using only open sources. Challenges reward both speed and investigative rigour, with recognition for the fastest verified solutions as well as the most elegant investigative process.

After spending several hours forcing ambiguous information into defensible answers, participants often find themselves applying the same methodology everywhere else, from incident response and threat intelligence to random travel photos and breach data. The goal is not simply to teach OSINT, but to develop a way of approaching problems that remains useful long after the workshop ends.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/BZXNHH/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='3a4a5f2f-bd14-504c-99d2-f6c44d26b92f' id='174'>
                <room>Pupin</room>
                <title>From Zero to root in 120 minutes - Introduction to Wordpress Hacking</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-18T20:30:00+02:00</date>
                <start>20:30</start>
                <duration>02:00</duration>
                <abstract>Using Kali-Linux and Metasploit to Hack Wordpress

You know the impressive visuals from TV series and Moviies. The Hacker opens a black console window, types fast on the keyboard and suddenly has root on the target system, saving the day. But how does this look like in reality?

If you drop by with a Laptop running Kali-Linux either from USB-Stick or from within a virtual machine, I will walk you through the necessary steps. From analyzing the target system, finding exploits on it on to successfully hacking the &quot;victim&quot; using metasploit. And if you are quick enough and behave, we might even get so far as to remotely crash the system.</abstract>
                <slug>balccon2k26-2026-174-from-zero-to-root-in-120-minutes-introduction-to-wordpress-hacking</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/USMV9H/hacktheplanet_XVfW6ZX_78TT3VE_fsikLto.webp</logo>
                <persons>
                    <person id='59'>leyrer</person>
                </persons>
                <language>en</language>
                <description>This is an introductionary level workshop targeted at a novice/beginner level audience that wants to learn how &quot;hacking&quot; actually works. InfoSec personel and other &quot;professionals&quot; attending this session will get shanghaied into supporting the other attendees. 

Prerequisites: Bring your own/a Laptop running a recent version of Kali-Linux inside a virtual machine or from a USB stick.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/USMV9H/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Lounge' guid='f665faf1-67e1-58f9-9563-acd0482f8e45'>
            <event guid='a178e7bf-dcd7-5807-b4de-e9e8fb65a11c' id='116'>
                <room>Lounge</room>
                <title>Karaoke - Some sing to remember, some sing to forget</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-18T22:00:00+02:00</date>
                <start>22:00</start>
                <duration>11:06</duration>
                <abstract>Despite past Karaoke events, the BalCCon Crew still seems to demand more!
We shall deliver.


Your first time at Karaoke? Sing together with other people!
Questions about Karaoke? Approach MacLemon during the event! (Ideally *before* the Karaoke event.)</abstract>
                <slug>balccon2k26-2026-116-karaoke-some-sing-to-remember-some-sing-to-forget</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/JRDFXS/KaaS_ztKm6C7_ShvQinD.webp</logo>
                <persons>
                    <person id='55'>MacLemon</person>
                </persons>
                <language>en</language>
                <description>People attend. People sing.
Everyone has a good time.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/JRDFXS/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='2' date='2026-09-19' start='2026-09-19T04:00:00+02:00' end='2026-09-20T03:59:00+02:00'>
        <room name='Tesla' guid='e0ed77fa-7e87-547c-b631-967f55cb26a5'>
            <event guid='a709e5df-70ca-5ff6-a14f-dca71658fa61' id='183'>
                <room>Tesla</room>
                <title>Digital Oncologists Require Cyber Care - Securing AI Agents in Radiotherapy</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-19T11:00:00+02:00</date>
                <start>11:00</start>
                <duration>00:50</duration>
                <abstract>Artificial intelligence is rapidly transforming healthcare, often elevating user experience and improving operational efficiency. In some domains, however, AI is no longer just a convenience &#8212; it has become essential. Radiotherapy is one such area. As patient volumes surge, digital oncology systems require significantly higher levels of autonomy to sustain safe, timely, and high&#8209;quality care. This includes not only treatment management, but increasingly, elements of treatment planning as well.

In this context, cybersecurity is no longer a supporting function; it is a foundational prerequisite for reliable cancer care. The encouraging news is that robust protection is achievable by applying mature, well&#8209;established security standards &#8212; adapted thoughtfully for AI&#8209;driven clinical environments. Frameworks such as MITRE ATLAS offer structured approaches tailored to adversarial threats against machine learning systems.

This presentation explores the unique cybersecurity challenges introduced by AI&#8209;enabled healthcare applications and demonstrates a practical strategy for addressing them through a focused use case: an AI Agent designed to support radiotherapy management.</abstract>
                <slug>balccon2k26-2026-183-digital-oncologists-require-cyber-care-securing-ai-agents-in-radiotherapy</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/UZQQAG/IMG_2061_cBsSjB9_dTpyN7y.webp</logo>
                <persons>
                    <person id='98'>Jani Kovacs</person>
                </persons>
                <language>en</language>
                <description>- Cancer care enabled by AI
- MITRE ATLAS &amp; SAFE-AI Crash Course
- Case Study: Radiotherapy Management Agent - From Threat Model to Pentest Report</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/UZQQAG/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='71ad686a-d872-55e7-ab14-612da8e56bf3' id='141'>
                <room>Tesla</room>
                <title>REGO&#268; my SW/HW AI team</title>
                <subtitle></subtitle>
                <type>Talk45</type>
                <date>2026-09-19T12:00:00+02:00</date>
                <start>12:00</start>
                <duration>00:45</duration>
                <abstract>REGO&#268; is my crew of specialized AI agents &#8212; architect, engineer, researcher, security, QA and more &#8212; that I work with daily through Telegram and voice to deliver real things: help in PCB design, firmware, reverse-engineering ...</abstract>
                <slug>balccon2k26-2026-141-regoc-my-sw-hw-ai-team</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/EP88CX/Screenshot_From_2026-06-08_18-00-50_O_mgFMvCQ.webp</logo>
                <persons>
                    <person id='28'>Goran</person>
                </persons>
                <language>en</language>
                <description>Over the past year I&apos;ve been using REGO&#268; &#8212; my team of 11 AI agents &#8212; to work on real hardware projects, not just chat demos. We ported the legendary **PDP-1 to the ULX3S FPGA**, try to brought up the open-source **GateMate FPGA Ethernet** stack with the KSZ9031 PHY, and reverse-engineered the **Chasing Gladius Pro underwater drone** &#8212; sniffing MAVLink, RTP video and the WiFi handshake to build our own control PWA on a Raspberry Pi. On the simulation side, we built **FTSIM**, an openEMS-based pipeline that runs FDTD signal-integrity checks on real PCB Gerbers across seven different boards. We also built a small **EMC pre-certification UI** for our in-house lab, and used the agents as a permanent &quot;second pair of eyes&quot; for **KiCad** &#8212; catching footprint mistakes, validating diff-pair routing, generating Gerber exports and fixing weird stackup issues before they hit production.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/EP88CX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d2e81b30-d2e8-5238-9b2f-962bcedc8f98' id='177'>
                <room>Tesla</room>
                <title>Universal Plug and Pwn</title>
                <subtitle></subtitle>
                <type>Talk45</type>
                <date>2026-09-19T12:45:00+02:00</date>
                <start>12:45</start>
                <duration>00:45</duration>
                <abstract>In under an hour we will show how cheap IoT devices can expose serious security risks in your home network

We analyzed a range of low-cost connected devices and will present
the best vulnerabilities we found.

Following our analysis of low low-cost connected devices, we will give an introduction to IoT pentesting.
Concretely we present our methodology to analyze real-world devices and
present our findings and uncovered exploitation paths.

Finally we will talk about mitigations and discuss why exploiting IoT devices in 2026 is still as easy as
a decade ago.</abstract>
                <slug>balccon2k26-2026-177-universal-plug-and-pwn</slug>
                <track></track>
                
                <persons>
                    <person id='134'>Andreas</person><person id='140'>Markus</person><person id='141'>Kevin</person>
                </persons>
                <language>en</language>
                <description>The talk will cover the following topics:

- Opening up the devices
- Dumping the Firmware
- Firmware Reverse Engineering
- Identifying interesting entry points
- Vulnerabilities we uncovered
- Mitigations
- Keeping your own devices safe

This talk is suitable for beginners.
We will show how to start analyzing your own devices, and how easy it is to exploit devices where security was not a priority during development.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/JYK3BH/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='4d8aef43-e66c-5202-81ca-94c4e42df676' id='149'>
                <room>Tesla</room>
                <title>Cryptography with Serbian eID Cards</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-19T13:30:00+02:00</date>
                <start>13:30</start>
                <duration>01:00</duration>
                <abstract>The PKCS#11 standard enables easy integration of hardware tokens with a wide range of software applications, including document suites, web browsers, and password managers. In this talk, we will introduce the fundamentals of PKCS#11 v2 and review a year-long journey of developing an open-source PKCS#11 module for Serbian eID cards. We will present three black-box techniques that were used to analyze proprietary software, and explain how they helped us understand the original PKCS#11 module for Serbian eID cards. The talk does not require prior knowledge of PKCS#11 or smart cards, but basic familiarity with public-key cryptography, web services, and shared libraries is recommended.</abstract>
                <slug>balccon2k26-2026-149-cryptography-with-serbian-eid-cards</slug>
                <track></track>
                
                <persons>
                    <person id='113'>Nikola Ubavi&#263;</person>
                </persons>
                <language>en</language>
                <description>60-minute lecture in which you will learn more than you ever wanted to know about Serbian eID cards</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/J8S7WP/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='b7243107-f3f6-5dce-9a10-92755dabb00b' id='162'>
                <room>Tesla</room>
                <title>Why you shouldn&#8217;t worry about your SAP systems&#8230; or should you?</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-19T14:30:00+02:00</date>
                <start>14:30</start>
                <duration>00:30</duration>
                <abstract>SAP powers some of the world&apos;s most critical business processes and that&apos;s exactly why attackers love it. Despite its importance, SAP security remains a blind spot for many security teams.
Drawing on a decade of hands-on experience defending SAP environments, this session explores why SAP systems are such attractive targets, how the threat landscape has evolved, and the security pitfalls that organizations repeatedly overlook. Through real-world lessons learned, we&apos;ll examine common misconfigurations, overlooked attack paths, and the unique challenges of securing enterprise-critical SAP systems.
Rather than focusing solely on what can go wrong, the session also provides practical guidance on improving SAP security hygiene, reducing attack surface, and preventing the issues that attackers most commonly exploit.
Whether you&apos;re a security practitioner, SOC analyst, penetration tester, or architect with little or no prior SAP experience, you&apos;ll leave with a clearer understanding of the risks hidden within SAP environments and actionable ideas to better protect one of the enterprise&apos;s most valuable assets.
This is a vendor-neutral, non-commercial session focused entirely on practical knowledge, real-world experience, and lessons learned from the field.</abstract>
                <slug>balccon2k26-2026-162-why-you-shouldn-t-worry-about-your-sap-systems-or-should-you</slug>
                <track></track>
                
                <persons>
                    <person id='125'>Anita Cwynar</person>
                </persons>
                <language>en</language>
                <description>The talk will include the following aspects:
1. Understanding SAP in the Enterprise Landscape:
- what SAP is and its role in large organisations
- overview of the most widely used SAP products by the business, IT and OT
- business processes typically managed by SAP systems.
2. SAP Architecture and Deployment Models:
- common SAP deployment models and security considerations
- common integrations with core enterprise systems and potential pivoting possibilities 
- typical trust relationships and common attack surfaces.
3. Security Challenges and Vulnerability Trends:
- the most common SAP vulnerabilities and misconfigurations
- recent security trends and attack techniques
- why SAP environments are often a blind spot for SOC and security teams.
4. Improving SAP Security and Visibility
- protection strategies for SAP environments
- detection and monitoring approaches for SOC teams
- immediate actions to strengthen SAP security posture.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/REHJAL/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='afaa664f-7114-5a7e-a773-798c6c4fa027' id='117'>
                <room>Tesla</room>
                <title>Compression, how does it even work?</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-19T15:00:00+02:00</date>
                <start>15:00</start>
                <duration>01:00</duration>
                <abstract>Compression is all about getting more out of less. We&apos;re `zip`ping through different algorithms while packing some bits. Let&apos;s find out why there&apos;s so many occurrences of the letter Z in compression and also see why compressing some data may end up larger than before.
After this talk you&apos;ll be confident how to make files smaller and when to not bother trying because you already know why it won&apos;t work.</abstract>
                <slug>balccon2k26-2026-117-compression-how-does-it-even-work</slug>
                <track></track>
                
                <persons>
                    <person id='55'>MacLemon</person>
                </persons>
                <language>en</language>
                <description>This talk is part of my foundational technologies arc, which includes these topics:

(In alphabetical order.)

- Backups
- Colour
- Email Systems
- Emoji
- Encoding
- Fonts and Typography
- HTTP/2
- USB (2 talks)
- various shell tools, including `ssh` and `tmux`</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/PX8LSH/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d8ad7f59-b708-55a2-9d64-74f8d671bb3d' id='135'>
                <room>Tesla</room>
                <title>Reverse Engineering FERMAX: Detour, Dead End, and Scope Creep</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-19T16:00:00+02:00</date>
                <start>16:00</start>
                <duration>01:00</duration>
                <abstract>Kirils &amp; friends got so excited about the FERMAX intercom system, that they nerd-sniped Iceman to join in on the hunt for MIFARE Desfire cards.

This is a journey into research on a shoe string and our realizations under the way. Detours, Dead Ends and Scope Creep are real.</abstract>
                <slug>balccon2k26-2026-135-reverse-engineering-fermax-detour-dead-end-and-scope-creep</slug>
                <track></track>
                
                <persons>
                    <person id='30'>Kirils Solovjovs</person><person id='69'>Iceman</person>
                </persons>
                <language>en</language>
                <description>When reverse engineering the proprietary DUOX PLUS intercom system dubbed the &#8216;most secure in world&#8217; by FERMAX, previously Kirils &amp; friends focused on its digital 2-wire signalling and employed such tools like oscilloscopes, logic analyzers and breadboards.

While these attacks are important as they shine light on the internal workings on the system, their application in the field is limited as one would need to acquire access to the 2-wire bus, which is only possible from the inside of the building.

Then we noticed something that was right in front of our eyes, Access control panels! These things are out there just on the perimeter. And, when installed on multi-tenant buildings, they have RFID reader modules installed. FERMAX offers modules doing EM4100, MIFARE Classic, and MIFARE Desfire. Even more they offer standalone Bluetooth modules too!

In this talk we give an overview of previous research and expand on it by exploring the possibilities of entering the perimeter by attacking the bluetooth and RFID dimension of these systems, and exploring card cloning, implanting, and cryptographic attacks together with Iceman.  In our research we extracted firmware and analyzed two different mobile applications to control the system,  TUYA and NearKey. 

Attendees will gain insight into decoding and interacting with closed digital protocols, exposing vulnerabilities in real-world access control systems. They also get practically applying RFID attacks to real world systems in use right now.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/E7GFPG/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='c4dfc1e3-e312-568a-89d9-e81c2f5b45ea' id='179'>
                <room>Tesla</room>
                <title>Keeping Trains on Track - A Glimpse into Germany&#8217;s Railway Infrastructure</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-19T17:00:00+02:00</date>
                <start>17:00</start>
                <duration>00:40</duration>
                <abstract>Have you ever sat on a train and wondered how all these tons of steel are moved safely across the tracks or who actually makes sure your train ends up at the correct station? If so, you&apos;ve come to the right talk!

The German railway system is a fascinating mix of traditional infrastructure, safety-critical logic and increasingly modern systems.
This talk introduces the basics behind it all, from tracks, switches, signals and balises to interlocking systems, train protection and railway communication. 
We will look at how safety is built into the systems, why trains do not need speeding tickets, what GSM is still doing in modern rail operations and which protocols may appear when railway technology meets the network stack. 

The goal of this talk is to make the hidden systems behind everyday train travel visible and to get the community interested in exploring railway technology.</abstract>
                <slug>balccon2k26-2026-179-keeping-trains-on-track-a-glimpse-into-germany-s-railway-infrastructure</slug>
                <track></track>
                
                <persons>
                    <person id='133'>BlackCat</person>
                </persons>
                <language>en</language>
                <description>My rough idea for the talk would be as follows: 

1. What Train Infrastructure^C Dreams are Made Of: The Basic Building Blocks of Railway Infrastructure

- Track Switches 
- Signals
- Balises 
- Track Vacancy Detection
- Hot Box Detection Systems

2. Why it is hard to Crash a Train: Interlocking Systems and Safety Logic

- Different generations of interlocking systems
- Safety principles

 3. Train Control Systems: Why Trains do not need Speeding Tickets

- Intermittent train control
- Continuous train control
- ETCS (European Train Control System)

4. Long live GSM(-R): The Mobile Network behind Railway Operations

- Details on the relevance and functionality of GSM-R (GSM for Rail)
- Differences between GSM and GSM-R 

5. Spawning Wireshark: Examples of Bits and Bytes in the Wild 

- RaSTA
- SAHARA
- SBS
- SCI-Protocols

6. Selected Examples of Developments to come

- Automated train operation
- FRMCS

7. Closing Thoughts</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/UHEUPT/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='27013743-06d5-5258-8a9b-b1dd89568088' id='145'>
                <room>Tesla</room>
                <title>Every ride you take - Hacking a City&#8217;s Public Transportation</title>
                <subtitle></subtitle>
                <type>Talk45</type>
                <date>2026-09-19T17:40:00+02:00</date>
                <start>17:40</start>
                <duration>00:40</duration>
                <abstract>Let&apos;s talk about some critical infrastructure that millions of people use every day: Public transportation. 
In this talk, I&#8217;ll present some findings that I discovered in the public transportation ecosystem of one of the largest cities in Argentina, impacting more than 1.5 million people daily. Reading code, chaining vulnerabilities, weak access controls, and flawed internal designs, I got full access to core mobility systems, from buses to taxis, including DVRs, transport cards, user data, real-time tracking and administrative panels. We&#8217;ll walk through the technical exploitation path, the real-world impact and the lessons learned.</abstract>
                <slug>balccon2k26-2026-145-every-ride-you-take-hacking-a-city-s-public-transportation</slug>
                <track></track>
                
                <persons>
                    <person id='109'>Ignacio Navarro</person>
                </persons>
                <language>en</language>
                <description>Description
=======

The talk is divided into 12 stages, showing step-by-step attack chains. In the first stages, I&#8217;ll relate the origin of the idea, provide information about the company, recon, and exposed .git directories that revealed source code, hardcoded credentials, and references to internal services and repositories, as well as some SQLi.

In Stage 3, I&#8217;ll present a Windows-based DVR system deployed on urban buses. Using a user with almost no permissions, I obtained an LFI. Using information from vendor manuals, documentation screenshots, and recovered internal paths, .frm and .ibd files were obtained and reconstructed in a Docker container. This allowed the recovery of credentials, leading to full administrative access to the DVR platform (DEMO).

With this access, it was possible to manage users and drivers, access sensitive internal data, and remotely view and control cameras and microphones installed inside buses. After some time, I figured out that this system was also used in 11 provinces, turning a local issue into a nationwide one.

In Stage 6, the research returns to the exposed .git files, where a private GitLab URL was found. From there, access to CI/CD pipelines, cron jobs, and a Docker registry was obtained.

While analyzing the cron jobs, multiple hardcoded credentials were found, including access to banking-related services and FTP servers. By analyzing the code and the .lock files, it was possible to upload a file to the FTP server, which was later pulled and executed by internal processes, resulting in RCE on the server.

Stage 8 marks the full infrastructure compromise. Using the reverse shell, it was possible to enumerate internal services, access production databases, bypass network segmentation, and identify additional systems.

Within the bus administration platform, access was obtained to the backbone of public transportation, managing drivers, users, companies, ticketing systems, real-time vehicle tracking, and remote operational controls such as fuel cutoff. Unlike the DVR platform, this system operates at city, regional, and national scale.

In Stage 10, I&#8217;ll show other systems that got access, for example: taxi applications and a large-scale bike rental system, affecting approximately 710 taxi drivers and more than 115,000 registered bike service users.

The final system explored was a government-related server containing highly sensitive information, including driver licenses, identification numbers, addresses, phone numbers, and operational records for taxi, bus, and private transport drivers. This was the point where I decided to stop the investigation and report it immediately.

The talk ends with the responsible disclosure process, challenges encountered when reporting vulnerabilities across multiple organizations and public entities, and lessons learned about securing critical infrastructure. The goal is to show how chaining basic vulnerabilities can lead to systemic compromise, and why public mobility systems deserve the same security attention as traditional critical infrastructure. Also I would like to encourage new generations to do ethical hacking and help build stronger relationships between hackers and companies.

Outline
=======

- Stage 0
   - Whoami
   - Disclaimer
   - Introduction
- Stage 1
   - Landing page
   - .git folders enumeration
   - SQLi
- Stage 2: Exposed .git
   - Hardcoded creds
   - Internal services
   - GitLab url in .git/config
- Stage 3: DVR System
   - Intro
   - Internal paths discovery
   - LFI
- Stage 4: DVR priv escalation
   - LFI to get .frm/.ibd
   - DB recovery (DEMO)
- Stage 5: DVR Admin access
   - User and drivers data exposure
   - Internal system data
   - Access to all cameras &amp; microphones
   - National presence
- Stage 6: GitLab repos &amp; CI/CD
   - Public repos
   - Public pipelines
   - Docker registry exposure
- Stage 7: Cron + FTP
   - Cron job download file from FTP
   - Shell upload to the FTP server
   - .lock execution control
- Stage 8: Reverse shell
   - Internal network access
   - Full database access
   - New systems discovered
- Stage 9: Bus administration system
   - Access to users/drivers/company data
   - Ticketing &amp; balance management
   - City+Regional+National buses
   - Control the buses remotely
- Stage 10: Additional systems
   - APKs
   - Taxi apps
   - Bike rental
   - Full administrative access
- Stage 11: Gov-related server
   - Taxi, buses and private transport records
   - Driver license, IDs, address, phones, etc
- Stage 12: Ending
   - Disclosure process
   - Challenges &amp; responses
   - Conclusions
   - Q&amp;A</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/KX7ULU/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='4e9c1094-66c0-51eb-9476-5477730cb342' id='115'>
                <room>Tesla</room>
                <title>Power Analysis Attacks 101: From Waveform to Private Key</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-19T18:20:00+02:00</date>
                <start>18:20</start>
                <duration>00:45</duration>
                <abstract>Power analysis is a side-channel attack with the goal of extracting secrets from the device based solely on its power consumption. Back in 1998, Kocher, Jaffe, and Jun published the famous paper showing that it&apos;s possible to break encryption on many devices using just the power traces, a bit of math and inexpensive equipment. Some twenty-eight years later, this attack still works.</abstract>
                <slug>balccon2k26-2026-115-power-analysis-attacks-101-from-waveform-to-private-key</slug>
                <track></track>
                
                <persons>
                    <person id='72'>igor</person>
                </persons>
                <language>en</language>
                <description>This talk covers the basics of static and differential/correlation power analysis: the methods, the math (with intuitive explanations), and, if the demo gods are feeling generous, a live key extraction on stage. No prior knowledge assumed.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/W3ARRY/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='547d5eec-28ea-57c4-96ad-4021c49758ba' id='144'>
                <room>Tesla</room>
                <title>Democratizing the creation of video tools with Open Source: Grassroots Community building and the recurBoy</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-19T19:05:00+02:00</date>
                <start>19:05</start>
                <duration>00:15</duration>
                <abstract>The world of hardware for video art can be intimidating. Compared to the accessible ecosystem for audio makers, dedicated video instruments are often scarce, expensive, or proprietary, creating a high barrier to entry.
The recurboy, a standalone digital video sampler, was designed to challenge this. As an open-source hardware and software project, its goal was to dismantle financial and technical barriers by
empowering artists to build their own instrument. What began as a tool for soldering workshops, however, evolved into something more significant: a vibrant, user-sustained community.
This presentation traces the journey of the recurboy from a shared workshop project to a global grassroots videoart making community.
We&apos;ll explore how users, connected through online platforms like a dedicated Facebook group and scanlines.xyz, formed a collaborative network for support, knowledge-sharing, and creative exchange.
This community not only built devices but also collectively problem-solved, shared modifications, and fostered a sense of shared purpose, a momentum recognized by features on platforms
like Adafruit.

The story of the recurboy demonstrates that the most vital outcome of an open-source project can be the community it inspires. It is a case study in how providing an accessible, buildable tool can cultivate a space where practice, learning, and collective care flourish, creating a lasting ecosystem for digital video art.

The project can be found here:
https://github.com/cyberboy666/recurBOY</abstract>
                <slug>balccon2k26-2026-144-democratizing-the-creation-of-video-tools-with-open-source-grassroots-community-building-and-the-recurboy</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/BKDUMV/recurboy_github_PIeMXHp_IYnmtnl_ESiNXpf.webp</logo>
                <persons>
                    <person id='108'>Guergana</person>
                </persons>
                <language>en</language>
                <description>This talk is not a technical talk, it is following an open source project from its beginnings to its evolution 7 years later and how it has grown organically in the underground video art community without the interference of its creators. 

Technical information about the project:

recurBOY is a stand-alone digital video synthesizer and sampler. it can trigger clips and run shaders to create and manipulate sd video.

    outputs sd video over composite or hdmi
    2 source modes to generate video : sampler and shaders
    process any source with additional FX
    control shader/fx parameters directly with 4x knobs or externally with 4x cv inputs
    all inputs also controllable via usb-midi
    process external video through compatible usb capture cards / web-cams

More complete information can be found at: https://github.com/cyberboy666/recurBOY</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/BKDUMV/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='2655ceca-2a27-5e16-89a0-ae4c62e5bc45' id='184'>
                <room>Tesla</room>
                <title>Manufacturing Minesweeper!</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-19T19:30:00+02:00</date>
                <start>19:30</start>
                <duration>01:00</duration>
                <abstract>So you think you want to turn a hardware prototype into a product?  Here&apos;s some of the ways you&apos;ll fuck it up!</abstract>
                <slug>balccon2k26-2026-184-manufacturing-minesweeper</slug>
                <track></track>
                
                <persons>
                    <person id='70'>Zoz</person>
                </persons>
                <language>en</language>
                <description>You&apos;re a hardware hacker that likes to build devices the way they SHOULD be built - meaning, the way you like them!  You&apos;ve made some cool prototypes that are useful for you, so maybe they might be useful to other people too?  Maybe you should manufacture some?  You might help people out and even make a bit of money on the side.  But the product manufacturing landscape is a figurative minefield, littered with traps that will explode your costs and time.  Using real examples, I&apos;ll present all my own naive, ignorant and just plain stupid mistakes so maybe you can avoid them.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/SVGXZE/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='59033b63-2118-5903-8878-69242cb0cfca' id='189'>
                <room>Tesla</room>
                <title>Lightning talks</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-19T20:30:00+02:00</date>
                <start>20:30</start>
                <duration>02:00</duration>
                <abstract>On BalCCon2k26, we want everyone to have an opportunity to speak! So we are soliciting short, but engaging 5 minute talks &#8211; Lightning Talks &#8211; from any and all attendees. The Lightning Talk format provides very personal, concise thoughts, ideas or calls for action. Typically speakers use lightning talks to talk about their experience, their opinions or for a wake-up call towards the agile community and markets.</abstract>
                <slug>balccon2k26-2026-189-lightning-talks</slug>
                <track></track>
                
                <persons>
                    <person id='1'>BalCCon</person>
                </persons>
                <language>en</language>
                <description>On BalCCon2k26, we want everyone to have an opportunity to speak! So we are soliciting short, but engaging 5 minute talks &#8211; Lightning Talks &#8211; from any and all attendees. The Lightning Talk format provides very personal, concise thoughts, ideas or calls for action. Typically speakers use lightning talks to talk about their experience, their opinions or for a wake-up call towards the agile community and markets.
Format

Everyone can speak at Balccon! Tell us about your project, idea, plans or your best jokes, just make sure you have a slide deck and keep it under 5 minutes!
Proposal

Now it&#8217;s your turn! Send an email at orga (at) balccon.org until 19th September 4pm with

Subject: Lightning Talk - BalCCon2k26 Name: Language of your Presentation Keywords: Abstract: Relevant Links (Project Page, etc.)</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/ALV7BZ/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Pupin' guid='53506c9f-44c9-55f0-aaf6-4efebf31ed1e'>
            <event guid='8147a37a-c1b7-5a15-8750-48dc81e564ef' id='147'>
                <room>Pupin</room>
                <title>Defending LLMs with LLMs: A Multi-Agent Approach to Prompt Injection</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-19T11:00:00+02:00</date>
                <start>11:00</start>
                <duration>00:20</duration>
                <abstract>Every company deploying a public-facing LLM chatbot inherits the full prompt-injection attack surface: jailbreaks, data exfiltration, PII leakage, indirect injection via retrieved documents. Single-model classifiers and regex filters consistently miss novel attacks, the same way single-AV products missed novel malware a decade ago.

This talk presents an open-source defensive architecture that runs five specialist AI agents in parallel against every prompt and response, each looking at a different attack dimension (injection patterns, semantic intent, encoding tricks, output exfiltration, PII exposure) and aggregates their verdicts before the request reaches the upstream LLM. We&apos;ll walk through the architecture, show live attacks bypassing commercial single-model guardrails but caught by the multi-agent pipeline, and discuss the latency/cost tradeoffs that make this practical as inline middleware.</abstract>
                <slug>balccon2k26-2026-147-defending-llms-with-llms-a-multi-agent-approach-to-prompt-injection</slug>
                <track></track>
                
                <persons>
                    <person id='111'>Vukasin Dobromirovic</person>
                </persons>
                <language>en</language>
                <description>A problem that will be bigger and bigger in the future is that public-facing LLM applications (customer support bots, in-product assistants, RAG-backed chat) are now production infrastructure for thousands of companies, yet the security tooling around them is roughly where web app firewalls were in 2005: regex blocklists and single-shot classifiers. Real-world attacks (DAN-style jailbreaks, indirect injection via poisoned documents, encoding bypasses (base64, Unicode homoglyphs, leetspeak), multi-turn priming attacks) defeat these defenses routinely. Commercial guardrails (Lakera, NeMo, LLM-Guard) help but operate on a single-pass pipeline that struggles with novel, composed, or low-signal attacks.

Proposed approach. I&apos;ve built and open-sourced an agentic guardrail system that treats LLM defense as a multi-agent reasoning problem rather than a classification problem. The architecture runs concurrent specialist agents in a LangGraph fan-out/fan-in pattern:

Injection Agent &#8212; looks at instruction-override patterns, role confusion, system prompt extraction attempts
Encoding Agent &#8212; detects base64, hex, Unicode obfuscation, and language-switch bypasses
Context Agent &#8212; analyzes indirect injection via retrieved documents and tool outputs
Output Protection Agent &#8212; scans LLM responses for system prompt leakage, sensitive data, and policy violations
PII Agent &#8212; Presidio-backed entity detection on both prompts and responses

A fast-path ONNX classifier handles obvious traffic in &lt;10ms; uncertain cases escalate to the agent panel. Verdicts are aggregated with a tunable severity policy. The whole pipeline sits as an OpenAI-compatible proxy, so it drops in front of any application without code changes.

What&apos;s original. The architecture combines three patterns that, to my knowledge, haven&apos;t been deployed together in a production LLM guardrail: (1) parallel-agent supersteps borrowed from agentic forensics tooling, (2) prompt-injection feature engineering from earlier academic work on adversarial input detection, and (3) a dual-engine self-learning loop where a fast ML classifier and a slow LLM panel cross-train each other on disagreements. The result catches novel attacks that single-model defenses miss because no individual agent has the full attack surface in its training distribution &#8212; the ensemble disagreement is the signal.

What attendees will see.
Live demo: ~6 attacks (jailbreak, encoded injection, indirect injection via RAG, PII exfiltration, multi-turn priming, output leakage) run against (a) a raw LLM, (b) a commercial guardrail, and (c) the multi-agent system &#8212; with the verdict reasoning shown in real time
Architecture walkthrough: LangGraph state, agent prompts, aggregation policy
Latency/cost numbers: real measurements on local Ollama (Llama 3.1 8B) vs. cloud (Haiku, GPT-4o-mini)
Failures and lessons learned &#8212; what didn&apos;t work: agents agreeing on wrong verdicts, prompt-engineering the agents themselves, the cost blow-up before we added the ONNX fast path
How to run it locally with Docker Compose after the talk</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/NJFLGX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='3cdc52c0-b6c1-5fd1-a418-45ffb056b71e' id='156'>
                <room>Pupin</room>
                <title>TETRA on a Student Budget</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-19T11:30:00+02:00</date>
                <start>11:30</start>
                <duration>01:00</duration>
                <abstract>Terrestrial Trunked Radio, or TETRA, is a standard for radio communications. Until recently, designing and operating a trunked system based on this standard was prohibitively difficult without using a dedicated commercial base station. Such equipment was often expensive and difficult to acquire.
Building on [research and developmet work by MidnightBlueLabs](https://github.com/MidnightBlueLabs/tetra-bluestation), new projects have been released and TETRA has become much easier to deploy and use.
In this talk we will introduce some of the basic concepts of radio communications, digital communications, share our experience with developing software for radios using TETRA, some of the legal hoops we had to go through, and we will even have a short demo.
This talk will cover a lot of technical subjects, but no previous experience is expected.</abstract>
                <slug>balccon2k26-2026-156-tetra-on-a-student-budget</slug>
                <track></track>
                
                <persons>
                    <person id='119'>Sava</person><person id='120'>Mi&#353;a</person>
                </persons>
                <language>en</language>
                <description>We discuss how to setup a Tetra base station in trunked mode and discuss what steps we had to go through to get to that point.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/YLMFDS/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='6703315f-4dea-5db1-a88f-392174408629' id='113'>
                <room>Pupin</room>
                <title>Memory Forensics in the age of EDR</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-09-19T12:30:00+02:00</date>
                <start>12:30</start>
                <duration>01:30</duration>
                <abstract>Have EDRs taken the glory of in-memory investigation? We&apos; ll go through a side by-side comparison of  of incident investigation with modern EDR against traditional memory forensics with volatility3. 
(And by comparing we mean complimenting the knowledge and arsenal of blue teams to pick the right solution for the right problem. It&apos;s isn&apos;t really a competition on what is best, NOR a shameless product selling)

Theory is always good but gaining experience is also important! 
We aim to start from memory internals 101 and dive into the analysis of a compromised system using volatility3 in parallel with KQL from Windows Defender for Endpoint. We showcase why memory forensics remains a solid option in incident response -even in the age of telemetry, and why rightfully considered an art form.

The workshop aims to be more than an RTFM of volatility3/KQL or use-plugin-and-find flags CTF, but rather equip participants with solid knowledge on linking pieces of evidence to fill the jigsaw puzzle of an incident. 
Newbie or seasoned, professional or just curious, this session is for you!</abstract>
                <slug>balccon2k26-2026-113-memory-forensics-in-the-age-of-edr</slug>
                <track></track>
                
                <persons>
                    <person id='95'>November</person>
                </persons>
                <language>en</language>
                <description>The following topics will be covered:
Part 1: Memory structure
- How memory works in Windows systems
- Evidence in memory

Part 2: Memory in DFIR
- Investigation theory
- Introduction to Volatility3
- Differences with EDRs
 
Part 3: Hands-On workshop
Analysis of windows system

It is a BYOD session, so please have the latest version of volatility installed on your machine!
https://github.com/volatilityfoundation/volatility3
Access on the detection lab will be given during the workshop.
The workshop is not a nintendo-forensics class, It is all about how to use it, not install it! :)</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/BJ9BW9/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='22b8dfc9-7f33-5469-9bbf-b2a39bddff86' id='120'>
                <room>Pupin</room>
                <title>AWS Security - The Purple Team Way</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-19T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>02:00</duration>
                <abstract>Type: Intermediate&#8211;Advanced
Focus: Adversary emulation, detection engineering, IR workflows
Style: Fast, offensive-defensive, &#8220;learn by attacking and defending&#8221;

Cloud platforms like Amazon Web Services (AWS) are foundational to many critical infrastructures and enterprise applications, making them prime targets for attackers. In this session, we will not only explore the most relevant attack vectors cybercriminals use to compromise AWS infrastructures but will also simulate these attacks using known threat actor techniques in an adversary emulation context. From initial access to hardcore persistence, this talk will provide a comprehensive look at how attackers operate in AWS environments.

We will take a technical journey through the tactics, techniques, and procedures (TTPs) employed by attackers at every stage of the threat lifecycle, aligned with the MITRE ATT&amp;CK framework. We&#8217;ll start by reviewing common methods of initial access, such as exploiting exposed credentials or vulnerabilities in services like IAM, Lambda, and EC2. From there, we&#8217;ll detail how attackers escalate privileges, move laterally, and evade detection from tools like CloudTrail.

The session will conclude with an in-depth look at advanced persistence techniques in AWS, including the manipulation of IAM policies, backdooring Lambda functions or Docker containers, and tampering with logs. Along the way, we&#8217;ll demonstrate how security teams can implement defensive and detection strategies to mitigate these risks. By leveraging AWS-native services and third-party tools, attendees will learn how to enhance their incident response capabilities.

This hands-on workshop will give attendees practical, technical insights into AWS security, adversary behavior, and how to better defend against sophisticated, persistent attacks. A full hands-on experience, this presentation ensures deep technical immersion.</abstract>
                <slug>balccon2k26-2026-120-aws-security-the-purple-team-way</slug>
                <track></track>
                
                <persons>
                    <person id='97'>Santiago Abastante</person>
                </persons>
                <language>en</language>
                <description>Type: Intermediate&#8211;Advanced
Focus: Adversary emulation, detection engineering, IR workflows
Style: Fast, offensive-defensive, &#8220;learn by attacking and defending&#8221;

Cloud platforms like Amazon Web Services (AWS) are foundational to many critical infrastructures and enterprise applications, making them prime targets for attackers. In this session, we will not only explore the most relevant attack vectors cybercriminals use to compromise AWS infrastructures but will also simulate these attacks using known threat actor techniques in an adversary emulation context. From initial access to hardcore persistence, this talk will provide a comprehensive look at how attackers operate in AWS environments.

We will take a technical journey through the tactics, techniques, and procedures (TTPs) employed by attackers at every stage of the threat lifecycle, aligned with the MITRE ATT&amp;CK framework. We&#8217;ll start by reviewing common methods of initial access, such as exploiting exposed credentials or vulnerabilities in services like IAM, Lambda, and EC2. From there, we&#8217;ll detail how attackers escalate privileges, move laterally, and evade detection from tools like CloudTrail.

The session will conclude with an in-depth look at advanced persistence techniques in AWS, including the manipulation of IAM policies, backdooring Lambda functions or Docker containers, and tampering with logs. Along the way, we&#8217;ll demonstrate how security teams can implement defensive and detection strategies to mitigate these risks. By leveraging AWS-native services and third-party tools, attendees will learn how to enhance their incident response capabilities.

This hands-on workshop will give attendees practical, technical insights into AWS security, adversary behavior, and how to better defend against sophisticated, persistent attacks. A full hands-on experience, this presentation ensures deep technical immersion.

Full Agenda:

Phase 1: Attacking The Cloud
Title 1: From Initial Access to Privilege Escalation
Understanding AWS IAM in full
Lateral Movement with IAM
Malware Analysis of Team TNT Infostealer
Getting Credentials from Missconfigurations
Privilege Escalation via IAM policies
Privilege Escalation via IAM Roles
Privilege Escalation via Exec to Instances and Containers


Title 2: From Defense Evasion to Persistence 
Getting Blindspots in the Share Responsibility Model
Bypassing Guardduty
Understanding how Cloudtrail logs work
Tampering Cloudtrail without getting caught
Living on the land Techniques
Persistence in AWS via SSH implant
Persistence in AWS via lotl



Phase 2: The Blue Team Way
Title 1: Security Detection in AWS
Cloudtrail for API Call Logging
Understanding the complete supply chain
SIEM Integration and Detection Use Case Creation
Understanding the Delays in SIEM integration
Understanding Event Bridge for Automated Response
Hardening Best Practices


Title 2: Incident Response in AWS 
Using the Cloudtrail Digest to detect tampers
Creating an Athena table for Cloudtrail Analysis when SIEM Fails
Using Event History as a last resource
Forensic Images of EC2 instances
Network Isolation of AWS instances
AWS Threat Hunting 101 
How to detect persistence in AWS

Final Notes
This training is designed for security engineers, SOC analysts, incident responders, and anyone who wants to truly understand AWS security through hands-on work. By the end of the session, you&#8217;ll have a deep understanding on how real attack and defense techniques work in AWS, being able to understand the hardening requirements, replicate attacks, generate detection use cases, and execute forensic techniques.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/LRA3MW/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='cd56ec8a-6e98-5613-aa84-4f9f58d7a28b' id='129'>
                <room>Pupin</room>
                <title>Mobile Device Forensics 101</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-09-19T16:00:00+02:00</date>
                <start>16:00</start>
                <duration>03:00</duration>
                <abstract>Your phone knows more about you than your closest friend. Where you went last Tuesday, who you messaged at 2 AM, which Wi-Fi you joined at the hotel. It&apos;s all on the device, waiting to be read. This 3-hour workshop is a hands on introduction to mobile device forensics on iOS and Android using only free and open-source tools. No expensive enterprise kit required.</abstract>
                <slug>balccon2k26-2026-129-mobile-device-forensics-101</slug>
                <track></track>
                
                <persons>
                    <person id='104'>Timo Miettinen</person>
                </persons>
                <language>en</language>
                <description>The first 90 minutes is a guided walkthrough of the acquisition and analysis of the artifacts that answer investigative questions. The second 90 minutes is a CTF. You get real evidence set, register on the CTF platform, and race the room to extract flags from iOS and Android images. Winner gets a prize.

Level: Beginner. Comfortable in a Linux/macOS terminal is enough. Bring your own laptop, a Linux VM is fine.

No phones harmed during the workshop.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/HLTHYU/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Mileva Maric' guid='78cadd07-458c-5767-b0ba-e43720ff8dc2'>
            <event guid='044b140a-694d-53e7-b6ca-c4e3db5084b9' id='180'>
                <room>Mileva Maric</room>
                <title>Generative Art and Cellular Automata</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-09-19T16:00:00+02:00</date>
                <start>16:00</start>
                <duration>02:00</duration>
                <abstract>This workshop explores generative art and aims at participants who are already familiar with a programming language and interested in exploring their artistic potential. We will examine cellular automata as a framework for generating visual systems, drawing inspiration from well-known models such as Conway&apos;s Game of Life.

The workshop combines short explanatory sections, live coding demos, and guided participant exercises. Participants will implement rule-based simulations, experiment with parameter spaces, and transform iterative processes into visually compelling outputs. Throughout the workshop, we will discuss emergence, complexity and the role of controlled randomness in creative coding.

To provide context, the workshop will also introduce key moments in the history and theory of media art. We will briefly connect computational art practices to early generative pioneers, reflecting on how rule-based systems have shaped artistic discourse. This historical and theoretical framework will give participants a deeper understanding of generative art as a cultural and conceptual practice rather than just a technique.

Attendees will leave with practical strategies for structuring generative systems and visualising performance, as well as inspiration to integrate artistic experimentation into their technical work.</abstract>
                <slug>balccon2k26-2026-180-generative-art-and-cellular-automata</slug>
                <track></track>
                
                <persons>
                    <person id='136'>Christian L&#246;lkes</person>
                </persons>
                <language>en</language>
                <description>1. Introduction &amp; Framing: What is generative art? From computation to aesthetics. Set workshop goals, tools, and the final outcome the participants will build.
2. Historical &amp; Theoretical Context: Early generative art, rule-based systems, and a brief look at generative systems in media art discourse.
3. Cellular Automata Foundations: Grid systems, neighbourhood definitions, rule design, and state transitions. I will demo the first working cellular automaton and show how small rule changes alter behaviour.
4. Building the Core Simulation: Participants and I implement the simulation step by step. We create the update loop, define rules, and verify the output at each stage.
5. From Simulation to Aesthetics: Mapping states to visual language, introducing colour systems and spatial composition, and demonstrating how iteration becomes an artistic method.
6. Guided Creative Lab: Participants develop their own variation on the system. They work independently or in pairs while I circulate, answer questions, and show optional extensions.
7. Share-out and Reflection: Participants briefly present results, followed by a closing discussion on artistic intention vs algorithmic autonomy and resources for further study.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/8QEAW9/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d9bce864-8f51-52fc-ba6c-1b9597672cf4' id='193'>
                <room>Mileva Maric</room>
                <title>OSINT CTF/Hackathon</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-19T18:20:00+02:00</date>
                <start>18:20</start>
                <duration>02:00</duration>
                <abstract>Day two is a competitive OSINT CTF/Hackathon where participants apply those techniques to solve a series of progressively harder challenges inspired by real investigations. Teams of up to three compete to identify people, places, events, and relationships using only open sources. Challenges reward both speed and investigative rigour, with recognition for the fastest verified solutions as well as the most elegant investigative process.

After spending several hours forcing ambiguous information into defensible answers, participants often find themselves applying the same methodology everywhere else, from incident response and threat intelligence to random travel photos and breach data. The goal is not simply to teach OSINT, but to develop a way of approaching problems that remains useful long after the workshop ends.</abstract>
                <slug>balccon2k26-2026-193-osint-ctf-hackathon</slug>
                <track></track>
                
                <persons>
                    <person id='124'>Jurica Radovi&#263;</person>
                </persons>
                <language>en</language>
                <description>Day two is a competitive OSINT CTF/Hackathon where participants apply those techniques to solve a series of progressively harder challenges inspired by real investigations. Teams of up to three compete to identify people, places, events, and relationships using only open sources. Challenges reward both speed and investigative rigour, with recognition for the fastest verified solutions as well as the most elegant investigative process.

After spending several hours forcing ambiguous information into defensible answers, participants often find themselves applying the same methodology everywhere else, from incident response and threat intelligence to random travel photos and breach data. The goal is not simply to teach OSINT, but to develop a way of approaching problems that remains useful long after the workshop ends.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/ZAHNXE/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Hackerspace area' guid='37625b47-8b40-5e6b-bbae-f9bea8e4e832'>
            <event guid='f05fd430-322b-51d7-8b83-08c75deaae62' id='152'>
                <room>Hackerspace area</room>
                <title>BalCCon Amateur Lockpicking Competition 2K26</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-09-19T13:00:00+02:00</date>
                <start>13:00</start>
                <duration>02:00</duration>
                <abstract>BALC (BalCCon Amateur Lockpicking Competition) is back again! 

BALC is a timed lockpicking competition for amateur participants. Competitors attempt to open a series of locks mounted on a door model using non-destructive techniques. The objective is to open as many locks as possible within the allotted time, with the fastest overall time determining the ranking in case of a tie.

The competition is intended for hobbyists interested in physical security and lockpicking.</abstract>
                <slug>balccon2k26-2026-152-balccon-amateur-lockpicking-competition-2k26</slug>
                <track></track>
                
                <persons>
                    <person id='24'>nm29</person>
                </persons>
                <language>en</language>
                <description>BALC is a hands-on lockpicking competition requiring a dedicated area for the duration of the event.

The competition uses a door model fitted with several locks. Participants compete individually in timed runs. A small number of volunteers will supervise the competition, keep time, reset the setup between runs, and record results.

The organizers of the competition will provide the door model, locks, lockpicking tools, timing, scoring, and staffing required to run the event.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/PYDQEJ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d2a98269-efe8-5798-8cf7-5539c66aa4a6' id='167'>
                <room>Hackerspace area</room>
                <title>The Eye</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-09-19T15:00:00+02:00</date>
                <start>15:00</start>
                <duration>00:10</duration>
                <abstract>An interactive ARG where you try to outsmart a character (chat bot) into helping you reach your goal using a terminal to help you figure out clues.</abstract>
                <slug>balccon2k26-2026-167-the-eye</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/JHHMTE/1000118102_jycirQ2_bpjRHkK_61mSt1Q.webp</logo>
                <persons>
                    <person id='127'>skullollipop</person><person id='131'>Marko Jesic</person><person id='139'>Jaddes</person>
                </persons>
                <language>en</language>
                <description>The game will consist of 2 crt screens, one will only show the terminal and is the main interaction point between the game and the player, other screen will show an animated eye of the character you are talking to. 

Your goal will be to extract a code from the character and figure out a way to &apos;delete&apos; it, if you succeed in doing so without the character stopping you or shutting himself down, you win and get a reward.

This game will run on a raspberry pi 4, and will be connected to either wifi/ethernet, whichever is available, it will drive both displays and the keyboard that players interact with. There will be no exposed ports to access the radpberry pi, or to unplug the monitors, everything will be enclosed in a 3D printed case.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/JHHMTE/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='97de5676-7a7c-5d2c-bf2e-d314425a1f4e' id='173'>
                <room>Hackerspace area</room>
                <title>Pen &amp; Paper Workshop</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-09-19T16:00:00+02:00</date>
                <start>16:00</start>
                <duration>04:00</duration>
                <abstract>Pen and Paper games are Role Playing Games (RPGs) that are meant to be played by a small group of people in person at a table using dice. The most famous one is Dungeons and Dragons (D&amp;D), but there are hundreds of others. Today there are also online tools with which the games can be played, but a lot of people still prefer to play in person. During the game, the players create a story,  that is not predefined by a software or program. The story evolves through the collaborative ideas of the players playing. Usually all but one player play a single character while the last player plays the world and everybody else within that world.</abstract>
                <slug>balccon2k26-2026-173-pen-paper-workshop</slug>
                <track></track>
                
                <persons>
                    <person id='62'>katzazi</person>
                </persons>
                <language>en</language>
                <description>I invite you to join into a Pen and Payer game. Everybody is invited regardless if you have never played before or are an experienced player. All offered games should be beginner friendly.

If you can offer a game yourself, please bring it as well, so that we have multiple options. Use the system you like, so that we probably can offer a range of games.

I myself will bring some Pathfinder 2e (Fantasy) and Starfinder 2e (Science Fiction) games. Both are open source systems derived from D&amp;D.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/BPJN79/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Lounge' guid='f665faf1-67e1-58f9-9563-acd0482f8e45'>
            <event guid='a3ef2d3f-66d9-5f6a-8ba3-1d5ad3b12097' id='190'>
                <room>Lounge</room>
                <title>Rakija Leaks</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-19T22:30:00+02:00</date>
                <start>22:30</start>
                <duration>02:00</duration>
                <abstract>Rakija connecting people!

Rakia is one of the most popular alcoholic drink in Serbia. It is usually served before lunch and dinner and is drunk along with appetizers. It is mandatory to drink with roasted pig, lamb, or dried meat. It is a very important part of the Albanian and Serbian cultures and there are many historians that say that the origins of rakia are in Serbia. Serbia has the most consumption of rakia per capita and is the largest exporter of rakia. In a 2009 European Court ruling, the names &quot;Slivovica&quot; (Slivovitz), Dunjevaca, Orahovaca, and Kruskovaca were ruled to be Serbian and thus the country has a trademark on those three types of rakia (Slivovitz being the most famous and most consumed in the world).</abstract>
                <slug>balccon2k26-2026-190-rakija-leaks</slug>
                <track></track>
                
                <persons>
                    <person id='1'>BalCCon</person>
                </persons>
                <language>en</language>
                <description>Rakia is part of Serbian culture. It is part of many special occasions, including baptisms, marriages, joining of the army, and visiting of friends. At funerals, custom demands that a bottle of rakia be left on the grave of the deceased who liked to drink it, or at least to sprinkle a drop or two during the memorial service for peace of the person&#8217;s soul. For some peasants, a flask of rakia is one&#8217;s only luggage. Poor peasants many even offer the village doctor, policeman, judge, tax collector, or minister a flask of rakia as a gift of payment. Many folk songs have been composed during rakia production.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/FAQFDS/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='3' date='2026-09-20' start='2026-09-20T04:00:00+02:00' end='2026-09-21T03:59:00+02:00'>
        <room name='Tesla' guid='e0ed77fa-7e87-547c-b631-967f55cb26a5'>
            <event guid='56688060-407b-5b4c-8783-d7caf252f157' id='122'>
                <room>Tesla</room>
                <title>Meshtastic is dead, long live meshtastic</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-20T12:00:00+02:00</date>
                <start>12:00</start>
                <duration>01:00</duration>
                <abstract>I will be talking about meshtastic protocol in detail, layer by layer and will be showing vulnerabilities in each (spoiler alert, most of them are vulnerable)

And I will be talking about why that is ok and why it is by design</abstract>
                <slug>balccon2k26-2026-122-meshtastic-is-dead-long-live-meshtastic</slug>
                <track></track>
                
                <persons>
                    <person id='21'>nemanjan00</person>
                </persons>
                <language>en</language>
                <description>In recent years, around the world, we are facing rise of low power mesh networks. 

And compared to older systems, that mostly dissipated and failed, recent wave has something different to offer. 

Those systems are built on custom protocols and low cost hardware, that is pretty limited in what it can do with reasonable time and power consumption. On top of that, for the purpose of long range communication, messages can only be short and transmission has to be slow. 

Just like any other distributed system, it also faces challenges of trust in other nodes. And in this case, that is even harder issue, because due to bandwidth limitations, there can not be something like consensus over the network, due to bandwidth limitations. 

While building it, designer faced unique challenges and constraints, that did not let them retroactively fix things, to be able to maintain backwards compatibility. Backwards compatibility being important since embedded systems in the middle of nowhere on slow network can not be updated. 

This talks leads you thru those unique challenges, decisions made, analyzes them, looks at the compromises made, measures them on being worth it and in the end comes to conclusion, why meshtastic despite all those mistakes and scars still persists to survive. 

Layers I will be going over are:

- Physical layer (what nodes are talking about in RF world)

- Metadata layer, for routing

- Encryption

- Portnums (application routing)

- Actual payload

I will be breaking down each layer at byte level or protobuf model level, interacting with audience on their ideas of why something is unsafe and showing live PoC on nodes that are willing to participate in local, vulnerable network</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/WR9CLL/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='ed0ed6ec-96ea-5733-85b1-7318411441ed' id='132'>
                <room>Tesla</room>
                <title>How I became a Voodoo doll model</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-20T13:00:00+02:00</date>
                <start>13:00</start>
                <duration>00:30</duration>
                <abstract>How to use AD misconfigurations and features in order to gain access or to escalate privileges. AD is in the heart of most of enterprise networks and is usually a main pilar for identity and access management. Owning AD usually means owning the complete enterprise, so it is quite interesting target for attacks. We will explore some of the most common attack venues against AD.</abstract>
                <slug>balccon2k26-2026-132-how-i-became-a-voodoo-doll-model</slug>
                <track></track>
                
                <persons>
                    <person id='27'>Vladan Nikolic</person>
                </persons>
                <language>en</language>
                <description>AD is everywhere and it is a cornerstone of enterprise identity management. Although new IAM technologies are expanding, it is still present in almost every internal network.

This talk will cover basics of ad and show some of the most common attacks and tools, both linux and powershell based.

This is based on a real life scenario as it occurred during the pentest. We will demonstrate how to gain initial access as unauthorized attacker, and how to escalate and own everything.

By leveraging misconfiguration of AD, bypassing windows defender in order to escalate privileges and expand domination to own full AD and even complete forest. We will shown techniques like kerberoasting, weak acl, user impersonation and similar.

Also, we will show how to use some of existing tools on machine in order to accomplish specific goals.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/7M73WX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='8a31ca80-3a94-5b9e-b094-3669ea965c2c' id='161'>
                <room>Tesla</room>
                <title>Post-Quantum Cryptography for the Novice, the Enjoyer, the Deployer and the Academic</title>
                <subtitle></subtitle>
                <type>Talk60</type>
                <date>2026-09-20T13:30:00+02:00</date>
                <start>13:30</start>
                <duration>01:00</duration>
                <abstract>A lot of people say they want to learn about post-quantum cryptography. One day, your favourite regulation authority asks you to switch to post-quantum in the next five years. While a great motivator to finally learn about PQ, what does that actually mean for you and me, your company and your non-tech friends? 
The talk will cover:  
- why we need to switch to post-quantum
- are some cryptographic algorithms more vulnerable than others
- what you should change when.
 
More importantly, we&apos;ll talk about the algorithms under the schemes: Which one should you use for your server, and which one is maybe more suited as a conversation topic at dinner parties. 
Finally, we&apos;ll look ahead: What are academics thinking about, and what is out there beyond key exchange and signatures?</abstract>
                <slug>balccon2k26-2026-161-post-quantum-cryptography-for-the-novice-the-enjoyer-the-deployer-and-the-academic</slug>
                <track></track>
                
                <persons>
                    <person id='126'>Lena Heimberger</person>
                </persons>
                <language>en</language>
                <description>The talk will be split into an introduction and four parts: 
Intro: 
PQ Mitigation timelines, Confidentiality is more vulnerable than Authenticity
(harvest-now-decrypt-later vs. just stopping to accept RSA signatures)

- The Novice. What does Shor tell us? What are periodic functions, and why are they vulnerable?
  Conclusion: Factoring and Discrete logs are vulnerable because they are periodic. So what can we use instead?
- The casual Enjoyer: A high level intro to 
  - random walks (isogenies)
  - noisy equations (lattices)
  - codes (noncommutative lattices) 
  - multivariate cryptography (noisy equations with more variables) 
  - symmetric MPC (just do the boring thing, obliviously and generically). 

  Conclusion: There&apos;s a lot of math, but at least you now know where to start  and how to fake your way through the next 1:1 with your team lead. 
- The deployer: what algorithms should you actually use? This is easy: NIST, ESI and other standards tell you what you are allowed to do in business applications- standards are usually not very flexible. Otherwise, the one you like best (maybe use a standard one, or one I invented (pls don&apos;t) ). 
Optional: &quot;But someone told me lattices are bad&quot;. Stop believing random people on the internet. Trust me instead, or actually, don&apos;t. Do your own research. In fact, do your own PhD in cryptography. 
- The academic: What is an open question? Privacy tech is not being rolled out because there are no PQ-safe alternatives. Data-oblivious (Blind) evaluation is hard, short intution on why.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/PLVHUH/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='5fcdec02-62f4-5f1f-9aaf-4b3ec1c678cb' id='137'>
                <room>Tesla</room>
                <title>Wireshark for &lt;s&gt;hackers&lt;/s&gt; reverse engineers</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-20T14:30:00+02:00</date>
                <start>14:30</start>
                <duration>00:45</duration>
                <abstract>While AI assisted tools are helping us speed run the analysis of unknown protocols, we still need to have a solid foundation to make sense of the larger picture. In this talk I will focus on three topics for that initial step of the investigation before analysis tools or even dissectors start to make sense.</abstract>
                <slug>balccon2k26-2026-137-wireshark-for-s-hackers-s-reverse-engineers</slug>
                <track></track>
                
                <persons>
                    <person id='103'>Erik de Jong</person>
                </persons>
                <language>en</language>
                <description>While AI assisted tools are helping us speed run the analysis of unknown protocols, we still need to have a solid foundation to make sense of the larger picture. In this talk I will focus on three topics for that initial step of the investigation before analysis tools or even dissectors start to make sense: I will start start by sharing how to prepare a sane and fresh Wireshark environment for a new reverse engineering session. Then followed by example on how to weed out traffic and translating initial findings into usable information. Finally we will go through several TLS variants and see what we need to decrypt those to add plain text information to our protocol tree.
The skills demonstrated in this talk sit solidly before more advanced steps such as automated analysis with scapy/AI tools and writing full dissectors or reverse engineered implementations of communication protocols.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/MUAKNE/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='1d6aa137-72d1-5435-b797-bb639348aab7' id='126'>
                <room>Tesla</room>
                <title>awerqo@balccon:~$ ./whoarethey &gt; &apos;Cloud Recon for Bughunting.md&apos;</title>
                <subtitle></subtitle>
                <type>Talk45</type>
                <date>2026-09-20T15:15:00+02:00</date>
                <start>15:15</start>
                <duration>00:45</duration>
                <abstract>Your bug bounty / pentest scope is a list of ASN and domains. **Your attack surface isn&apos;t.**

Modern cloud architectures expand beyond those horizons - Lambda function URLs, API Gateway endpoints, S3 buckets, CloudFront distributions, container registries, and CI artifacts deploy outside the visible domain space, weakly monitored and missing from official scope.

So: `whoarethey`? This talk provides the answers to that key question - how to map a target company&apos;s cloud-heavy infrastructure with a pure black-box approach, beyond standard methods. Alongside a brief recap of the regular recon (acquisitions, subdomain enumeration) for completeness, the focus will be on **cloud-asset recon**. You will learn how to find all the APIs of any given cloud and almost all the cloud domains with user workloads or content - and how to attribute them to a specific company.

*For hunters and pentesters tired of running the same methods against the same scope with the same results and wondering where the bugs went.*</abstract>
                <slug>balccon2k26-2026-126-awerqo-balccon-whoarethey-cloud-recon-for-bughunting-md</slug>
                <track></track>
                
                <persons>
                    <person id='102'>Andrei</person>
                </persons>
                <language>en</language>
                <description>## Why this talk

The cloud is now where the S&amp;P 500 lives. Statistics indicate that 99% of customer security failures in clouds are due to the errors of the customers themselves, and HackerOne reported  [all-time-high vulnerability submissions in March 2026](https://www.hackerone.com/blog/continuous-threat-exposure-management-remediation-crisis).

While the underlying sources &#8211; a list of subdomains and ASN ranges &#8211; are still the same as five years ago, the recon methodology most hunters use has just added an AI layer on top. Cloud-native targets live one layer past that list, and the standard tooling doesn&apos;t reach them.

## Anatomy of cloud assets

The shape of a modern cloud footprint. For each major service, I cover the URL and endpoint patterns that let you fingerprint it from outside:

- Service example &#8211; Storage, bucket URL patterns across multiple providers (virtual-hosted-style vs path-style; regional variants)
- Service example &#8211; Serverless / Functions, Lambda URL formats, function-URL patterns, container-based functions
- Service example &#8211; Identity / Cognito, pool URLs and the public auth-flow surface (SignUp, ConfirmSignUp, InitiateAuth, RespondToAuthChallenge, ForgotPassword, DescribeUserPoolClient, GetUser, UpdateUserAttributes)
- How to find APIs for **ALL!** cloud services via hardcoded endpoints in SDKs (e.g., boto3 / botocore endpoints data)
- How to find **MANY** cloud domains with user content via the Public Suffix List

## Discovery and exploitation

Three lenses, layered on top of each other:

- Company assets (the regular recon) - acquisitions via Tracxn and Crunchbase, legal entities, ASN ranges via BGP.HE.NET and ASNmap, second-level domains, subdomain enumeration with PureDNS, DNSx, Katana, CSPrecon. Treated as substantive content, not a one-slide intro.
- Cloud assets - what each provider exposes by default and how to fingerprint a service from the patterns covered in section 1.
- Company in cloud (the intersection) - pairing the regular recon output with cloud patterns to land on the actual targets: xyz.s3, xyz.lambda-url, xyz.cloudfront, Cognito pools tied to a company&apos;s identity domain.

**Approach taxonomy.** Passive &#8594; safe-active &#8594; noisy-active across providers, and when each is appropriate.

**Attribution.** The core of the talk: attributing arbitrary cloud assets to a specific company through TLS certificates (TLSx), link graphs in HTML and JS, copyright and contact strings in serialized configs, and the data-leakage tells in exposed JSON/XML. Includes a note on where invasive attribution methods cross ethical lines. Which data sources and tools fit attribution, and how to use each.

## Tooling and how integrate them to methodology

- Shodan facet analysis
- ZoomEye
- GitHub search
- TLSx
- Cloud-SNI ranges (ec2-reachability.amazonaws.com, kaeferjaeger.gay)
- PureDNS
- DNSx
- Katana
- CSPrecon
- Wayback CDX API for wildcard searches
- Postman public collections
- Wordlists from Assetnote, plus target-specific lists from HTML, BigQuery, FFUF/Intruder
- S3Scanner (buckets)
- Pacu (IAM bruteforce, Lambda enum, Cognito flows)

## Defense and hardening - &quot;Attack yourself first&quot;

- Wildcard bug bounty scope (catch-all by default)
- Stay on top of trends; assume scope drifts
- Continuous attack-surface inventory
- Manual recon at least annually
- Treat staging as prod
- Billing alerts on every account
- Acquisition onboarding SLA
- Service-account chain analysis
- Whitebox inventory
- Stealer-log monitoring
- Incremental / per-release audits

## References

- [Jason Haddix - The Bug Hunter&apos;s Methodology / recon talk](https://www.youtube.com/watch?v=gIz_yn0Uvb8)
- [ProjectDiscovery (TLSx, DNSx, ASNmap, Katana)](https://github.com/projectdiscovery)
- [Rhino Security Labs - Pacu](https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/)
- [TomNomNom - WhatWhereWhen](https://tomnomnom.com/talks/wwwww.pdf)
- [Assetnote - wordlists &amp; research](https://www.assetnote.io/resources/research)
- [kaeferjaeger](https://kaeferjaeger.gay/)
- [HackerOne &quot;remediation crisis&quot; report](https://www.hackerone.com/blog/continuous-threat-exposure-management-remediation-crisis)
- Gartner &#8211; Cloud failure forecast</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/SXYD3W/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='0c2dfc59-d986-5665-a04f-b88ed3b70c70' id='142'>
                <room>Tesla</room>
                <title>From Zero to Admin: The Hidden Paths of Privilege Escalation</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-20T16:00:00+02:00</date>
                <start>16:00</start>
                <duration>00:40</duration>
                <abstract>This session takes attendees inside the privilege escalation mindset. We will explore the techniques attackers use to enumerate systems, discover hidden permissions, abuse trust relationships, collect credentials, and move from restricted access to complete control.</abstract>
                <slug>balccon2k26-2026-142-from-zero-to-admin-the-hidden-paths-of-privilege-escalation</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/BDQWZ8/Privilege_Escalation_-_The_Art_mbQm7j_vazqTyI.webp</logo>
                <persons>
                    <person id='78'>Joseph Carson aka Wiretrap</person>
                </persons>
                <language>en</language>
                <description>Getting inside is only the beginning.  The real game starts after compromise.
Once attackers land inside an environment, they begin asking three simple questions:

Who am I?
What access do I have?
What can I become?

Those answers determine whether an attacker remains a limited user - or becomes a domain admin, root user, cloud owner, or autonomous operator.

This session takes attendees inside the privilege escalation mindset. We will explore the techniques attackers use to enumerate systems, discover hidden permissions, abuse trust relationships, collect credentials, and move from restricted access to complete control.

Covering Windows, Linux, Cloud, and emerging AI systems, this talk reveals how privilege escalation has evolved from exploiting machines to exploiting identity itself.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/BDQWZ8/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='1ad3daf0-7ee8-5748-8e5a-53831eb52167' id='134'>
                <room>Tesla</room>
                <title>Security Impress Karaoke</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-20T16:45:00+02:00</date>
                <start>16:45</start>
                <duration>01:55</duration>
                <abstract>Think you can bluff your way through a security talk with zero prep? Now is your chance! At Security Impress Karaoke, you&apos;ll be handed a totally random, security-themed slide deck you&#8217;ve never seen before - and have just 3 minutes to present it like a pro.

No experience? No problem. This is all about having fun, thinking fast, and impressing the crowd with your creativity (or chaos). Whether you&apos;re a seasoned hacker or just security-curious, come take the podium and let&#8217;s see what you&#8217;ve got!</abstract>
                <slug>balccon2k26-2026-134-security-impress-karaoke</slug>
                <track></track>
                
                <persons>
                    <person id='30'>Kirils Solovjovs</person>
                </persons>
                <language>en</language>
                <description>Sign up or just show up!</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/ZEWLHA/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='7302a715-db98-596a-8798-20a27621e759' id='188'>
                <room>Tesla</room>
                <title>Closing ceremony</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-20T18:40:00+02:00</date>
                <start>18:40</start>
                <duration>00:30</duration>
                <abstract>Closing ceremony</abstract>
                <slug>balccon2k26-2026-188-closing-ceremony</slug>
                <track></track>
                
                <persons>
                    <person id='1'>BalCCon</person>
                </persons>
                <language>en</language>
                <description>Closing ceremony</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/JERKYH/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Pupin' guid='53506c9f-44c9-55f0-aaf6-4efebf31ed1e'>
            <event guid='d7af73fa-8d84-52ed-aa33-36d681b90052' id='168'>
                <room>Pupin</room>
                <title>Embroidery meets Electronics - make your blinky wearable patch</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-09-20T13:00:00+02:00</date>
                <start>13:00</start>
                <duration>01:00</duration>
                <abstract>This is a workshop where embroidery meets electronics. It is intended for anyone who is interested in crafting something of their own while learning the basics of embroidery and circuitry, no prior knowledge or experience needed. Once you are done you&apos;ll be able to wear your patch and show off your work!</abstract>
                <slug>balccon2k26-2026-168-embroidery-meets-electronics-make-your-blinky-wearable-patch</slug>
                <track></track>
                <logo>/media/balccon2k26-2026/submissions/YZPBVT/patch_example_hhXhXik_BQwpFrm.webp</logo>
                <persons>
                    <person id='132'>Boris</person>
                </persons>
                <language>en</language>
                <description>Each participant will receive a canvas (a piece of textile) the size of a credit card, roughly 85 &#215; 54 mm, with a few proposed designs such as memes, tech designs , or hacker puns, or they can come up with a design of their own. Alongside colorful thread, there will be sewable LEDs available in many colors (red, orange, green, blue, purple, pink, and yellow), and most excitingly, &#8220;smart&#8221; self-blinking LEDs that only require power (no software) to blink and really bring the project to life. 

The power comes from a sewable battery module running on a CR2032 battery, accompanied by a small switch so the creator does not need to remove the battery every time they want to turn the patch off. The circuitry is connected using conductive thread. 

Simpler designs can be completed during the session, but there is no pressure &#8212; each participant will take their own kit with them and can finish anywhere at the conference or at home. (I carry mine in my wallet.) These patches can be then sewn into clothes, accessories or whatever creative idea the maker comes up with. 

During the day they will be able to show their embroidery design and during the night the real magic comes out when everyone starts glowing and blinking.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/YZPBVT/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='2b61a854-2f99-5db9-b109-ba2a609be839' id='158'>
                <room>Pupin</room>
                <title>TETRA Workshop</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-09-20T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>01:30</duration>
                <abstract>Come join us and make your own TETRA base station!</abstract>
                <slug>balccon2k26-2026-158-tetra-workshop</slug>
                <track></track>
                
                <persons>
                    <person id='119'>Sava</person><person id='120'>Mi&#353;a</person>
                </persons>
                <language>en</language>
                <description>We will bring several SDRs and TETRA radios; you bring a laptop. Together, we will set up an open-source base radio station and test it with real hardware.
We will also bring higher-power amplifiers, filters, duplexers, and other RF components so you can see what a full base station setup looks like in practice.
Feel free to come up to us during the workshop and talk about TETRA, SDRs, radio infrastructure, RF hardware, or mostly anything else.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/ADARCS/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='a9f2ad03-0310-53b7-a178-7adf769ff841' id='151'>
                <room>Pupin</room>
                <title>Shellcode: Learning to Write Position Independent Code</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-20T15:30:00+02:00</date>
                <start>15:30</start>
                <duration>03:00</duration>
                <abstract>Shellcode is often treated as a dark art: small, opaque, and inseparable from exploit folklore. This workshop takes the opposite approach. It breaks shellcode down as a disciplined form of constrained systems programming, where every byte, register, calling convention, memory reference, and control-flow decision matters.

Participants will learn how shellcode is structured, how position-independent code works, and why common instruction patterns such as call/pop, base-register anchoring, stack construction, and compact control-transfer sequences appear so frequently in real-world payloads. The workshop will also cover Windows internals relevant to shellcode, including TEB and PEB access, API discovery, API hashing, syscall resolution, and indirect syscall techniques. Finally, it will explore more advanced building blocks such as tiny disassemblers, trampolines, and API interception hooks.

The goal is not to teach copy-paste payload development, but to give reverse engineers, malware analysts, exploit developers, and detection engineers a clear mental model for how shellcode actually works.</abstract>
                <slug>balccon2k26-2026-151-shellcode-learning-to-write-position-independent-code</slug>
                <track></track>
                
                <persons>
                    <person id='2'>Malware Utkonos</person>
                </persons>
                <language>en</language>
                <description>Shellcode sits at the intersection of exploit development, reverse engineering, operating system internals, compiler behavior, and malware analysis. It is small by design, but the ideas packed into it are dense: position independence, register discipline, stack layout, calling conventions, import resolution, syscall mechanics, and runtime code modification. This workshop is designed to make those ideas understandable and practical for security researchers who want to read, write, analyze, and detect shellcode with confidence.

The workshop begins with the fundamentals: what shellcode is, what constraints it normally operates under, and how those constraints shape its design. We will look at how shellcode avoids absolute addresses, how it locates its own data, and how instruction sequences can be combined to replace unavailable or undesirable operations. Examples include techniques such as call/pop for recovering a pointer to embedded data, using a register as a shellcode-relative base pointer, constructing strings and arguments on the stack, and reasoning about code that must execute correctly regardless of where it lands in memory.

From there, the workshop moves into Windows-specific shellcode internals. We will examine how shellcode can discover process and module state without relying on normal imports, including TEB and PEB access, walking loader structures, resolving API addresses manually, and implementing API hashing. These topics are especially useful for malware analysts and detection engineers because they explain the recurring patterns seen in unpacked payloads, loaders, implants, and post-exploitation tooling.

The workshop then covers syscall-oriented shellcode. Participants will learn how user-mode API calls transition into kernel services, why direct and indirect syscall techniques exist, what tradeoffs they introduce, and how syscall resolution interacts with OS versioning, user-mode hooks, and EDR visibility. The focus will be on understanding the mechanisms and their analytical implications rather than treating syscalls as a magic bypass.

The final section explores more advanced shellcode building blocks: tiny disassemblers, instruction-length decoding, trampolines, inline hooks, and API interception. We will discuss how a compact decoder can be used to identify safe overwrite boundaries, install a trampoline, preserve original instructions, and redirect execution through a hook function. This portion connects shellcode development directly to the mechanics used in instrumentation, unpacking, malware loaders, and defensive research tooling.

All material is presented in a controlled lab context, with emphasis on responsible research, analysis, and defensive understanding. Attendees should leave with a practical framework for recognizing shellcode patterns, understanding why they work, and reasoning about small pieces of machine code with much greater precision.</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/QSSAXP/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Lounge' guid='f665faf1-67e1-58f9-9563-acd0482f8e45'>
            <event guid='aedadf17-e7e3-535c-8c22-91356015e07e' id='191'>
                <room>Lounge</room>
                <title>After party</title>
                <subtitle></subtitle>
                <type>Workshop120</type>
                <date>2026-09-20T19:10:00+02:00</date>
                <start>19:10</start>
                <duration>04:00</duration>
                <abstract>After Party!</abstract>
                <slug>balccon2k26-2026-191-after-party</slug>
                <track></track>
                
                <persons>
                    <person id='1'>BalCCon</person>
                </persons>
                <language>en</language>
                <description>After Party</description>
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.balccon.org/balccon2k26-2026/talk/WR9UHX/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
