<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2026.3.0.dev0. -->
<schedule>
    <generator name="pretalx" system="pretalx.com" version="2026.3.0.dev0" />
    <version>0.5</version>
    <conference>
        <title>BSides Cape Town 2024</title>
        <acronym>bsides-cape-town-2024</acronym>
        <start>2024-12-06</start>
        <end>2024-12-07</end>
        <days>2</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://pretalx.com</base_url>
        <logo>https://pretalx.com/media/bsides-cape-town-2024/img/artwork_logo_v2_XKgtJ6X.png</logo>
        <time_zone_name>Africa/Johannesburg</time_zone_name>
        
        
        <track name="Track 1" slug="4891-track-1"  color="#ee1919" />
        
        <track name="Track 2" slug="4892-track-2"  color="#db8615" />
        
        <track name="Workshops" slug="4893-workshops"  color="#18b423" />
        
    </conference>
    <day index='1' date='2024-12-06' start='2024-12-06T04:00:00+02:00' end='2024-12-07T03:59:00+02:00'>
        
    </day>
    <day index='2' date='2024-12-07' start='2024-12-07T04:00:00+02:00' end='2024-12-08T03:59:00+02:00'>
        <room name='Track 1' guid='7fb9d121-e957-58ec-9011-d40640582488'>
            <event guid='8cf30179-e43a-518e-8829-b988f6ef26bb' id='54683' code='RYA3LS'>
                <room>Track 1</room>
                <title>Zen and the Art of Cognitive Defense: Zero-Trust Mindsets and Cyber-Mindfulness</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T09:30:00+02:00</date>
                <start>09:30</start>
                <duration>00:45</duration>
                <abstract>This talk will delve into the critical findings from the speaker&apos;s Cyber psychology Master&#8217;s research thesis, exploring the human susceptibility factors to social engineering and deception. It will touch on how scientifically evidenced mindfulness practices can effectively &apos;patch&apos; many (23 out of 33) of these human vulnerabilities. Additionally, we will share practical insights from a 1.5-year journey into implementing a cyber mindfulness campaign at Nedbank.</abstract>
                <slug>bsides-cape-town-2024-54683-zen-and-the-art-of-cognitive-defense-zero-trust-mindsets-and-cyber-mindfulness</slug>
                <track></track>
                
                <persons>
                    <person id='56693'>Anna</person><person id='56695'>Christine Gordon-Bennett</person>
                </persons>
                <language>en</language>
                <description>I previously wrote about how I failed a phishing simulation test during an Uber ride and how this led me to research human susceptibility factors to social engineering and cyber-mindfulness. I wanted to dig into the real reason why I clicked on a phishing email as a security person with 22+ years of experience in cybersecurity. (By the way, the Uber incident was not the only phishing test I failed - there were quite a few more examples). My theory back then was that it wasn&apos;t my lack of skills that made me click, but rather a distracted and multi-tasking state of mind. And some initial research confirmed this theory. Motivated by these findings, I decided to make this question the focus of my research thesis for my Cyberpsychology Master&apos;s program. The talk will provide the key highlights from the thesis, such as: 
1. Findings from the literature review to identify factors contributing to susceptibility to phishing and SE. Factors found were classified into cognitive, behavioural, psychological, situational, and demographic categories
2.  these were then mapped against validated benefits of mindfulness&#8212;such as improved attentional control, enhanced meta-awareness, reduced stress, and emotional regulation. 
3. Existing literature covering mindfulness in cybersecurity specifically confirmed that participants who underwent mindfulness training were better in detecting phishing attempts compared to control groups, indicating a clear link between mindfulness practices and reduced susceptibility to SE tactics.

Through interviews with 20 experts in cybersecurity and mindfulness and using inductive qualitative analysis, themes and categories related to the integration of mindfulness in cybersecurity awareness programmes and general organisational settings were identified. While the interviews confirmed many of the theoretical benefits, they also uncovered significant challenges, such as resistance from employees to terminology, ensuring consistent adoption, difficulties in communication and quantifying the effectiveness. Based on the findings, I recommend a companywide culture shift to one that favours deliberation over immediacy and one that integrates mindfulness into the broader organisational and cybersecurity agenda. 
Lastly we will also share some real-world examples of organisations that have embraced this concept, such as Nedbank.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/RYA3LS/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/RYA3LS/feedback/</feedback_url>
            </event>
            <event guid='cd3701eb-4569-59b4-8474-ad8e8ef8866a' id='55696' code='BNAFAV'>
                <room>Track 1</room>
                <title>Ignorantia Juris Non Excusat - Understanding the Impact of the Law on the SA Hacker Community</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T10:30:00+02:00</date>
                <start>10:30</start>
                <duration>00:45</duration>
                <abstract>Many cybersecurity researchers and ethical hackers are becoming the target of criminal prosecutions and litigation, essentially for trying to do the right thing, and acting in an ethical manner. The reality is that cybersecurity researchers, practitioners and ethical hackers do run the risk of running afoul of both criminal and civil law in South Africa. This talk will explore the various laws and legal actions that could impact on them, and how to work within the framework of the law in South Africa, and essentially keep them safe from legal harm.</abstract>
                <slug>bsides-cape-town-2024-55696-ignorantia-juris-non-excusat-understanding-the-impact-of-the-law-on-the-sa-hacker-community</slug>
                <track></track>
                
                <persons>
                    <person id='57607'>Jason Jordaan</person>
                </persons>
                <language>en</language>
                <description>The talk will cover the various activities that cybersecurity researchers, practitioners and ethical hackers undertake, and explore the various legal issues that may impact on these activities. The focus of the talk is to educate the community of how our actions can inadvertently break the law or leave us open to litigation, simply for trying to make the world a safer place.

The talk will start with an introduction highlighting some case studies from around the world and then looking at the South African situation and how we expose ourselves to risks.

I will then look at the various statutes, common law offences, and civil causes of action that can be used against us and the consequences of these. I will discuss the aspects of these in way will be understandable to a technical audience using practical examples.

I will then discuss ways in which we can perform our activities in a manner that will insulate us from legal action in both the criminal and civil sphere, as well as what to do if we ever find ourselves on the wrong side of the law for doing something ethical.

One thing that I will also discuss is the upcoming Cybersecurity Bill that the SA Government is pushing forward.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://pretalx.com/media/bsides-cape-town-2024/submissions/BNAFAV/resources/Jason21c_5Jun21_Web_2UYm6Ps.jpg">Profile Pic</attachment>
                
                    <attachment href="https://pretalx.com/media/bsides-cape-town-2024/submissions/BNAFAV/resources/Short_BioJason_Jordaan_suchqkZ.docx">Short Bio</attachment>
                </attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/BNAFAV/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/BNAFAV/feedback/</feedback_url>
            </event>
            <event guid='0864c712-c15b-58f2-b673-83e9c29540e8' id='54802' code='N83V7V'>
                <room>Track 1</room>
                <title>DevOps or DevOops? Securing a Pipeline Without Losing Your Mind</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T11:30:00+02:00</date>
                <start>11:30</start>
                <duration>00:45</duration>
                <abstract>This talk will follow a light-hearted take on the mistakes and solutions I had while setting up a Gitlab to Jenkins to Tomcat CICD pipeline this year. Many of the configurations were insecure by default and when approached a mentality of &quot;Make it work&quot; it just compounds the issue. The talk will go through each stage of the pipeline, the issues I found, the issues I caused and the solutions for both.</abstract>
                <slug>bsides-cape-town-2024-54802-devops-or-devoops-securing-a-pipeline-without-losing-your-mind</slug>
                <track></track>
                <logo>/media/bsides-cape-town-2024/submissions/N83V7V/DevOps_or_DevO_8O7YMFU.png</logo>
                <persons>
                    <person id='56802'>Jonathon Everatt</person>
                </persons>
                <language>en</language>
                <description>Introduction:

The introduction will paint a background of how this talk came about and the components in the pipeline. The idea is that Source Code from Gitlab sends a webhook on merge to Jenkins. Jenkins then pulls the code and builds it, then deploys it to the Tomcat web server. Tomcat itself is hosted on localhost port 8080 which is served to the internet using an NGINX reverse proxy. If that sounds like a whole lot of technical gibberish, don&apos;t worry we&apos;ll understand it by the end of the talk.

Gitlab:

Gitlab is a source code repository on Linux, much like GitHub it can store your code and your code changes. However, by default it has a few problems. For example anyone can register on the application. We&apos;ll look into some of these common problems as well as common mistakes that I made while configuring a repository. Even though Jenkins is only meant to be exposed internally, that doesn&apos;t mean that everyone internally should see your typos in your commit messages.

Some of the misconfigurations I made included the creation of a public repo, being able to create and accept my own merge requests and allowing developers to see information. So by the time I had a working pipeline, anyone with access could compromise each host in the pipeline.


Jenkins:

Jenkins is a automation server which in my pipeline is used to build and deploy code from Gitlab to web servers (in the case of this example). It is basically RCE as a feature with a few added security issues on top. One of my favourites was creating a webhook that had my Jenkins Admin creds in it. We&apos;ll look at what attack paths exist in Jenkins and against Jenkins and build it back to the access an might have have with Gitlab.

Apart from embedding my credentials into a webhook I also had to work out ways to move code from the build agent to the web server. This started with some very bad ideas, like python simple server, and ended up with ssh.

Deployments:

Finally with deployments, I&apos;ll give a brief overview of the pain I experienced with trying to get Tomcat working in the first place, but then we&apos;ll go through some attacks that work and are fairly under the radar if you can deploy malicious code to production. We will also tackle the problem of how you block client-side code from calling out to a specific domain.

Some interesting things here is that any Javascript I&apos;ve written for key logging, information stealing, and the works are never detected by any controls. Especially with attacks like dependency confusion attacks: How do you block a domain client-side if you can&apos;t necessarily remove the malware yourself?


Conclusions:

For the conclusions we&apos;ll take a look at where the network started, and the amount of issues it had (Security and others). Then compare it to where the network ended and how non-intuitive the fixes were. To end off, the attacks will be mapped back to a DevOps pipeline to see what type of risks each stage of the pipeline could introduce.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/N83V7V/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/N83V7V/feedback/</feedback_url>
            </event>
            <event guid='9f61503f-cdc4-5aca-b836-bc7aa56a97f5' id='54758' code='MLQWTA'>
                <room>Track 1</room>
                <title>Attack of the clones: Modern deepfake phishing</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T13:15:00+02:00</date>
                <start>13:15</start>
                <duration>00:45</duration>
                <abstract>Recent trends have shown that the next evolution in phishing is the abuse of AI tooling to create realistic and believable deepfake clones. Organisational resilience against deepfake phishing is drastically behind the curve.

In this talk, we will investigate the state of the art, present case studies of actual deepfake attacks, examine the practical feasibility and ease of execution of these kinds of attacks as well as possible solutions to these problems.</abstract>
                <slug>bsides-cape-town-2024-54758-attack-of-the-clones-modern-deepfake-phishing</slug>
                <track></track>
                
                <persons>
                    <person id='56758'>Johan VD Merwe</person><person id='56759'>Jacob Simmons</person>
                </persons>
                <language>en</language>
                <description>1. Introduction to the current state of the art
- An overview of what attackers are capable of with current techniques and technology (AI specific)
- Case studies of specific incidents where deepfake phishing has been abused successfully

2. Technical Overview
- Detailed overview of how an attacker could accomplish same results
--Specific attention to whether it is possible without extensive training data

3. Demonstration
- Recorded demonstrations of all of the above
- (Hardware Permitting) Live demonstration of an audience member made to look like one of the authors

4. Remediation
- Possible Social, Corporate and Technical solutions to fight this issue
- Tools and techniques for detection

Takeaways

- Understanding the current state of the art:
    * Attendees will gain a solid understanding of the current capabilities of deepfakes and AI models.
- Identifying and Mitigating Risks:
    * Participants will learn how to identify these kinds of threat actors. 
    * Participants will gain an understanding of what technical and organisational controls can be used to mitigate such threats</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/MLQWTA/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/MLQWTA/feedback/</feedback_url>
            </event>
            <event guid='b7ce1054-b060-58c1-9329-7132c9195992' id='56507' code='SM333W'>
                <room>Track 1</room>
                <title>Cloud Security Theater: Rising above the noise of misguided strategies</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T14:10:00+02:00</date>
                <start>14:10</start>
                <duration>00:45</duration>
                <abstract>To secure cloud environments effectively, a modern operating model needs to be created to solve the real security challenges faced during cloud adoption. However, are security teams focusing on the right problems when it comes to cloud security or we are just doing Cloud Security Theater?</abstract>
                <slug>bsides-cape-town-2024-56507-cloud-security-theater-rising-above-the-noise-of-misguided-strategies</slug>
                <track></track>
                
                <persons>
                    <person id='58386'>Jared Naude</person>
                </persons>
                <language>en</language>
                <description>Cloud adoption is booming, with many organizations migrating to the cloud for cost efficiency, scalability and agility. This shift requires a critical review of traditional IT operating models and the cybersecurity controls that go along with it. However, many organizations are struggling to operationalize cloud effectively which often leads to unmitigated risks and an over reliance on technology when it comes to securing their cloud environments.

In this talk, I will share my learnings around the common missteps and pitfalls that organizations make securing their cloud environment. The first part of my talk will focus on background including:
* A high level overview of why people adopt cloud
* The mind set change that needs to occur when using cloud
* The change of ownership and responsibility in cloud environments

The second part of my talk will focus on highlighting the problems and missteps that we see organizations make. This includes:
* The problems with relying on compliance frameworks
* Tackling the nuances in multi-account environments
* Understanding attack vectors and paths
* Baseline controls including Guard Rails, Network Security &amp; IAM
* Regulatory Compliance Gaps
* Automation Fallacies
* Products and services not fit for cloud

The third and final part of my talk will focus on sharing ideas for strategies and approaches that organizations should consider.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/SM333W/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/SM333W/feedback/</feedback_url>
            </event>
            <event guid='4a6fb1a5-de1d-5a87-a278-bfef3327d31c' id='55110' code='YMABRP'>
                <room>Track 1</room>
                <title>Attacking GraphQL : A guide for penetration testers</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2024-12-07T15:05:00+02:00</date>
                <start>15:05</start>
                <duration>00:30</duration>
                <abstract>Whats GraphQL? How do pwn it? And what do I write in my pentest report if I get this in a test? If these questions get your heart racing, fret not, this stalk is for you!

GraphQL is at minimum, yet another API technology your company can get horribly wrong. The technology has grown considerably has an API interface technology in the last few years. With the growing interest, security engineering has been a keen focus for deployments because the technology is new, promises a lot (i.e. strict data typing, query batching and nesting, rapid adaptability etc.) and may not deliver the same impact in all environments or use cases. Futhermore, in the contemporary landscape there are a number of services, and open source projects that make this accessible each with their own set of complexities and pitfalls.  With all these new fangled environments, a novel query language, and wildly variable backends, pentesters and security engineers need a good overview in order to navigate a security assessment or deployment. The talk here aims to provide guidance to pentesters in navigating these environments, using the open source and free tooling on offer and delivering a good quality penetration test against GraphQL environments.</abstract>
                <slug>bsides-cape-town-2024-55110-attacking-graphql-a-guide-for-penetration-testers</slug>
                <track></track>
                
                <persons>
                    <person id='57635'>Keith Makan</person>
                </persons>
                <language>en</language>
                <description>GraphQL was released and developed at Facebook just under 10 years ago, but has only really seen a surge in public interest over the latest 5 years of its life. Being adopted by the likes of Amazon AWS, Microsoft and IBM as well as many more big names. GraphQL grew rapidly due to its proactive approach to many problematic aspects of API deployment and design, namely: Data typing, Query formatting, Data Source independence and many others.

Although providing a myriad of technological improvements deployments still suffer from common vulnerabilities and misconfigurations. Whats more beyond the vulnerabilities which stem from common misconfigurations, many security problems also source from complex integrations between traditional API tech (like REST, SOAP etc). In an effort to help users be aware of these problems the talk here will walk through many of the scenarios that may introduce vulnerability as well as ways they can avoid incurring more risk.

In this talk, the speaker will talk through:
(i) The recent history of GraphQL, its adoption rate, the innovations and APIs that currently make use of this tech.
(ii) Common GraphQL setups and projects (what to expect in the wild)
(iii) How to threat model a GraphQL deployment, where to expect things to go wrong.
(iv) A detailed enumeration of common issues like Query batching, nesting, incorrect usage of the typing system and other problems - some of which will be supported by real world examples.
(v) Exploitation patterns and tools that will enhance a penetration testers ability to assess and exploit vulnerabilities mentioned in the talk.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/YMABRP/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/YMABRP/feedback/</feedback_url>
            </event>
            <event guid='f48d8118-36ab-5543-a503-c4d1e8266981' id='56556' code='PHMBBP'>
                <room>Track 1</room>
                <title>Find and fix Vulnerabilities within open source projects</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2024-12-07T15:35:00+02:00</date>
                <start>15:35</start>
                <duration>00:15</duration>
                <abstract>It&apos;s actually pretty easy to find and fix vulnerabilities within open-source projects. With the right tools and techniques, identifying security flaws and patching them can be a straightforward process. 

In this talk, we&#8217;ll explore practical methods to detect vulnerabilities, from automated scanning to manual code review, and guide you through the steps to address them effectively. 

Whether you&#8217;re a seasoned developer or new to open source, you&#8217;ll learn how to contribute to making projects more secure. 

Let&apos;s commit to securing open-source code&#8212;starting today, with your next pull request!</abstract>
                <slug>bsides-cape-town-2024-56556-find-and-fix-vulnerabilities-within-open-source-projects</slug>
                <track></track>
                
                <persons>
                    <person id='58422'>Callian Berends</person>
                </persons>
                <language>en</language>
                <description>In this talk, I will provide a brief but comprehensive introduction on how to find and fix vulnerabilities in open-source projects.

We&apos;ll explore not only the techniques for identifying and addressing security flaws but also how anyone&#8212;regardless of experience&#8212;can contribute to improving open-source software. 

Whether you&apos;re scanning for vulnerabilities, submitting patches, or helping with code reviews, you&apos;ll discover practical ways to get involved and make a meaningful impact in the open-source community.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/PHMBBP/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/PHMBBP/feedback/</feedback_url>
            </event>
            <event guid='5488867e-238c-5ba7-a90e-8ead45f9b35a' id='56343' code='SZU8GJ'>
                <room>Track 1</room>
                <title>Going Beyond your own Barriers</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2024-12-07T16:00:00+02:00</date>
                <start>16:00</start>
                <duration>00:15</duration>
                <abstract>How do you recognise your own barriers and things that are holding you back? And more importantly, once you know those barriers, how are you able to overcome them?</abstract>
                <slug>bsides-cape-town-2024-56343-going-beyond-your-own-barriers</slug>
                <track></track>
                
                <persons>
                    <person id='58188'>Roberto Arico</person>
                </persons>
                <language>en</language>
                <description>For my talk, I&apos;d like to identify the most common things people face when trying to progress. I have helped and coached many people, and want to share what I have seen and learnt to a wider audience. My talk will include:
- Barriers to getting into Cyber - where to start?
- Barriers related to Job Posts/Spec - Unreasonable expectations
- Are certifications a Barrier/Are certifications needed upfront?
- Human barriers, such as neuro diversity and imposter syndrome
- Emotional Barriers - Are your emotions keeping you back
- Skills barrier (related to certifications above)

And while discussing this, will be providing some experiences I have had and tips and tricks from talking to people and coaching others in this industry.

 These are all subjects I am passionate about and things that I would like to pass on to the next generation of hackers. This talk isn&apos;t aimed at those who are established, but for the students and newcomers to BSides who may be wondering how to make the next career move.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/SZU8GJ/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/SZU8GJ/feedback/</feedback_url>
            </event>
            <event guid='86b56388-3a0e-5140-ab34-8c45a5ad6029' id='55863' code='GHTA9V'>
                <room>Track 1</room>
                <title>Rite of Passage: My Journey from BSides Volunteer to Black Hat Asia Attendee</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2024-12-07T16:15:00+02:00</date>
                <start>16:15</start>
                <duration>00:15</duration>
                <abstract>From volunteering at BSides Cape Town to being sponsored to attend Black Hat Asia, I&#8217;ll share my unexpected journey and the power of community involvement in shaping my career in cybersecurity. Through this talk, I aim to inspire students to take that first step into getting involved with the cybersecurity community.</abstract>
                <slug>bsides-cape-town-2024-55863-rite-of-passage-my-journey-from-bsides-volunteer-to-black-hat-asia-attendee</slug>
                <track></track>
                
                <persons>
                    <person id='57744'>Blessing Mufaro Kashava</person>
                </persons>
                <language>en</language>
                <description>In 2023, I volunteered at BSides Cape Town as a way to immerse myself in the cybersecurity community. What I didn&#8217;t anticipate was that my involvement would lead to an incredible opportunity: being selected for the Rite of Passage Initiative and getting sponsored to attend Black Hat Asia 2024. This talk will take attendees on a journey from my beginnings as a volunteer to attending one of the most prestigious cybersecurity conferences in the world. I&#8217;ll reflect on my personal experiences, the invaluable lessons I learned, and the connections I made, all of which have had a profound impact on my career and personal growth.

During the talk, I will cover:

1. Volunteering at BSides Cape Town 2023: How volunteering introduced me to the wider cybersecurity community, and why this experience was so transformative.
2. The Rite of Passage Initiative: What this initiative is and how it provides opportunities for students passionate about cybersecurity. I&#8217;ll share my own experience of being selected and how that set the stage for my trip to Black Hat Asia.
3. Black Hat Asia 2024: I&#8217;ll highlight key moments from my experience at the conference&#8212;everything from the talks I attended to the incredible people I met from across the globe. 
4. The Value of Community: I&#8217;ll dive into how community involvement&#8212;through volunteering and attending conferences&#8212;has been instrumental in my career growth. Whether it&apos;s learning new skills, networking with professionals, or simply gaining exposure to the global cybersecurity scene, I&#8217;ll emphasize the power of being part of a supportive community.
5. Encouraging Students: The heart of this talk is to inspire students and young professionals to get involved in their local cybersecurity communities. I&#8217;ll share actionable advice on how they can volunteer, apply for scholarships, and make connections that could change the trajectory of their careers.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/GHTA9V/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/GHTA9V/feedback/</feedback_url>
            </event>
            <event guid='1e105a0a-03d5-5f3d-bcbd-5032addbba21' id='56236' code='QC8SGL'>
                <room>Track 1</room>
                <title>AI in OSINT - Zero snake oil</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2024-12-07T16:40:00+02:00</date>
                <start>16:40</start>
                <duration>00:45</duration>
                <abstract>In this blink-and-you&apos;ll-miss-it talk we cut all the introductions and waffle and, just like this abstract, get straight to the point :) Can we use AI in OSINT? Spoiler - yes and its pretty magical. We&apos;ll show, on screen, how AI helped solved real(ish) world cases. That&apos;s it.</abstract>
                <slug>bsides-cape-town-2024-56236-ai-in-osint-zero-snake-oil</slug>
                <track></track>
                
                <persons>
                    <person id='58074'>Roelof Temmingh</person>
                </persons>
                <language>en</language>
                <description>In the talk, I&apos;ll demo how we&apos;ve build software that uses RAG AI to create an assistant that you can query about (deep, eg post authentication) web pages. I will show how the software works and then I will show results that were interesting. 

I&apos;ll end the talk with my predictions on how AI will impact OSINT in the near future.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/QC8SGL/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/QC8SGL/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Track 2' guid='3d034bb8-4a18-5bfd-956f-c3250d9cadae'>
            <event guid='857e89b1-6d98-5a23-9f93-1156bb09e47e' id='56394' code='H9YVRY'>
                <room>Track 2</room>
                <title>Breaking the Barrier: Exploring modern WAFs.</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T10:30:00+02:00</date>
                <start>10:30</start>
                <duration>00:45</duration>
                <abstract>In an era where web threats evolve as quickly as the technologies we deploy, the temptation to rely on Web Application Firewalls (WAFs) to mitigate holes in a web application&apos;s security is high. But how effective are these digital shields? Could they be more prone to error than we think? This talk will uncover the gaps within our WAF defenses, examining a variety of WAF bypass techniques, both complex and simple. By showcasing these potential weaknesses, we can get a better understanding of the state of modern WAFs so that teams know what to expect when choosing to fall back on WAFs for &quot;protection&quot;.</abstract>
                <slug>bsides-cape-town-2024-56394-breaking-the-barrier-exploring-modern-wafs</slug>
                <track></track>
                
                <persons>
                    <person id='58220'>Ethan Havinga</person>
                </persons>
                <language>en</language>
                <description>**Introduction**:
The introduction will start with a brief overview of my background and experience in cybersecurity, setting the stage for the discussion to come by giving a high-level overview of Web Application Firewalls. During the WAF overview, the talk will focus on why WAFs don&apos;t remediate security vulnerabilities and instead mitigate them. I will give some well known examples and set out the expectation that WAFs are generally expected to cover the OWASP Top 10.

**Understanding WAFs**:
In this section, I will introduce the audience to the fundamental aspects of Web Application Firewalls (WAFs), by exploring their architecture and the roles they play in protecting web applications and simply what makes a WAF a WAF. We will discuss how the WAFs are designed to filter and monitor HTTP traffic between a web application and the internet. By understanding the general purpose of WAFs and where we usually find them, we can see how they fit into a broader security environment. I will also go into some security overlaps that exist when choosing a WAF not developed with an organisation&apos;s custom implementations (eg: Custom Cryptography, Custom Querying Syntax) in mind, and how this can defeat the purpose of having a WAF.

**WAFs In Modern Times**:
It is essential to understand what makes a modern WAF and the key features and improvements that set apart older WAFs from modern ones. I will run through what modern WAFs are expected to cover in contrast to what older and deprecated WAFs cover. We will look at the historical development of WAFs and what evolution WAFs have gone through to get to where they are today. I will also briefly highlight the great value of having a WAF be open-source and the developmental benefits that unlocks through community-driven development.

**The Good**:
To start off we will focus on what WAF&apos;s generally do well and what expectations we can have for them. We see how WAFs react when given payloads from some common vulnerabilities listed in the OWASP Top 10 and give a high-level overview of how specific payloads are detected. The discussion will include points about what parts of the payload are detected and because of this the audience will better understand why we obfuscate the parts of payloads that we do, in order to get a working bypass.

**The Oopsies**:
In contrast to the above section we will focus on modifying the payloads attempted in the previous section, based on the aspects of a payload that were detected. Furthermore we will look at exactly what changes were made to payloads and why those payloads might have worked. This leads to a better understanding as to how bypasses are developed and gives a rough methodology that we can follow when approaching the creation of WAF bypasses.

**Learning from Bypasses**:
This section will focus on how we can learn from the bypasses discussed in the previous section and expand on the rough methodology in order to transform it into a more concrete methodology that we can practically use. The methodology will focus on 3 aspects:
- Identify -- the specific keywords blocked by a WAF
- Obfuscate -- the keywords in various manners
- Test -- the obfuscated payloads

**In Denial**:
It is also necessary for us to talk about how WAFs are used to mitigate vulnerabilities and why this has the potential to create an illusion of security. This will also highlight the importance of root cause remediations in place of WAFs while still acknowledging the improvement to the overall security posture of a web application that a WAF can provide.

**Takeaways**:
In this final section we will go over and summarise the high-level key points discussed during the talk and how each key point can be applied in the real world:
- What makes a WAF; a WAF
- How WAFs should be approached by red/blue teams
- The importance of remedial actions</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/H9YVRY/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/H9YVRY/feedback/</feedback_url>
            </event>
            <event guid='1c5ed8d0-97d3-5a52-a51c-153997dbcefb' id='54915' code='QUQJME'>
                <room>Track 2</room>
                <title>Unmasking the Digital Shadows: OSINT Techniques for Cybersecurity Professionals</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T11:30:00+02:00</date>
                <start>11:30</start>
                <duration>00:45</duration>
                <abstract>The cyber threat landscape is becoming increasingly complex and sophisticated. Cybersecurity professionals are constantly challenged to stay ahead of attackers who exploit the anonymity of the internet to carry out malicious activities. Open Source Intelligence (OSINT) has emerged as a powerful tool in the cybersecurity arsenal, enabling professionals to uncover hidden threats, track malicious actors, and safeguard sensitive information.</abstract>
                <slug>bsides-cape-town-2024-54915-unmasking-the-digital-shadows-osint-techniques-for-cybersecurity-professionals</slug>
                <track></track>
                
                <persons>
                    <person id='56910'>Sharon Knowles</person>
                </persons>
                <language>en</language>
                <description>Objective: The primary objective of this keynote is to equip cybersecurity professionals with the basic OSINT techniques that can be used to enhance their threat detection, investigation, and mitigation capabilities. Attendees will gain insights into how OSINT can be leveraged to unmask digital shadows&#8212;those elusive and often hidden elements of the cyber world that pose significant risks to organisations and individuals alike.

Key Takeaways:
1.	Understanding the Power of OSINT:
o	Explore the evolution of OSINT and its growing significance in cybersecurity.
o	Learn about the different types of OSINT sources and tools available to cybersecurity professionals.
o	Understand how OSINT can complement traditional cybersecurity measures.
2.	Advanced OSINT Techniques for Cyber Threat Intelligence:
o	Discover innovative methods to gather and analyse OSINT data for threat intelligence.
o	Learn how to trace the digital footprints of cybercriminals and identify patterns in their activities.
o	Explore case studies that demonstrate the successful application of OSINT in uncovering and mitigating cyber threats.


3.	Unmasking Anonymity: Techniques to Identify Hidden Actors:
o	Delve into techniques for de-anonymising online identities and uncovering the real personas behind cyber activities.
o	Understand the role of OSINT in tracking down and profiling threat actors, from lone hackers to organised cybercrime groups.
o	Learn how to use OSINT to uncover connections between seemingly unrelated cyber incidents.
4.	Legal and Ethical Considerations in OSINT:
o	Explore the legal frameworks governing the use of OSINT in cybersecurity.
o	Discuss ethical dilemmas and best practices for conducting OSINT investigations responsibly.
o	Understand the importance of balancing privacy concerns with the need for robust cybersecurity measures.
5.	Future Trends in OSINT and Cybersecurity:
o	Gain insights into emerging trends and technologies that will shape the future of OSINT in cybersecurity.
o	Explore how AI and machine learning are revolutionizing OSINT techniques.
o	Discuss the potential challenges and opportunities that lie ahead for cybersecurity professionals in the OSINT domain.

Conclusion: This keynote will empower cybersecurity professionals with the knowledge and skills to effectively utilise OSINT in their daily work. By unmasking the digital shadows, they will be better equipped to protect their organisations, clients, and the wider digital ecosystem from the ever-evolving threats posed by cyber adversaries.

Target Audience: This keynote is designed for cybersecurity professionals, including threat analysts, investigators, incident responders, and security operations centre (SOC) teams, who are looking to enhance their skill sets with advanced OSINT techniques</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/QUQJME/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/QUQJME/feedback/</feedback_url>
            </event>
            <event guid='f94e6156-eb85-5cc2-a446-ec031886952a' id='54651' code='LBDUWJ'>
                <room>Track 2</room>
                <title>Dependable Red Teaming by using Confusion</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T13:15:00+02:00</date>
                <start>13:15</start>
                <duration>00:45</duration>
                <abstract>Dependency Confusion, a DevOps supply chain attack path discovered in 2021, hasn&apos;t really gotten the attention that it deserves. This is mainly due to a misunderstanding of how large the attack surface can be. In this talk, we will show how dependency confusion can be exploited to not just attack the pipeline, but covertly gain full access to PROD!</abstract>
                <slug>bsides-cape-town-2024-54651-dependable-red-teaming-by-using-confusion</slug>
                <track></track>
                
                <persons>
                    <person id='56657'>Tinus Green</person>
                </persons>
                <language>en</language>
                <description>Dependency Confusion attacks leverage confusion that can be created in a package manager&apos;s approach to determining where libraries need to be installed from. Simply knowing the name of an internally-hosted package is sufficient for a threat actor to stage such an attack, which can trick a package manager to install a malicious version of the library from an external repository instead.

When this vulnerability was first discovered and published, the author was able to show how they infected companies such as the likes of Apple and Microsoft. However, since then, there hasn&apos;t been any real traction from the security community to include testing for this in their methodology. This is largely due to the difficulties in explaining the impact that such a vulnerability can have. A key argument made against the vulnerability&apos;s impact is that the risk is mitigated since proper CI/CD pipelines make use of ephemeral build agents meaning the threat actor&apos;s package would not have the relevant code to pass unit tests. Thus a compromise here would not really amount to anything serious.

This got us thinking. What if we could weaponise dependency confusion not to compromise a developer installing package or the build agent, but to actually compromise production? Turns out, this is possible and actually not that hard to achieve! This brings a whole new dynamic for red teams looking to deploy a near-silent but incredibly potent backdoor.

This talk will be beginner friendly by covering what dependency confusion is but then take it further to show in a live network how dependency confusion can be weaponised to blast its way past both the build and deploy stages and into production, providing a fun new breach to goal execution shortcut for red teams!

The talk overview is as follows:

1. Introduction to dependency confusion
2. Why the security community overlooks dependency confusion
3. Reevaluating the threat of dependency confusion
4. Weaponising dependency confusion
5. Mitigation strategies and best practice to prevent and detect dependency confusion

Takeaways:

Those attending this talk will better understand the true impact that dependency confusion can have and how its discovery can be weaponised to showcase this true impact. Equipped with this knowledge, attendees will be able to supplement their testing methodologies and understand how to better protect their organisations from this attack vector.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/LBDUWJ/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/LBDUWJ/feedback/</feedback_url>
            </event>
            <event guid='bf7cb2c2-9373-59f9-811c-6b0ae5ad4016' id='56561' code='K8FETB'>
                <room>Track 2</room>
                <title>LOLGrid: Don&#8217;t bring your own network, one already exists.</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T14:10:00+02:00</date>
                <start>14:10</start>
                <duration>00:45</duration>
                <abstract>A fun look at network over powerline systems. The use and abuse of these solutions, what kind of attacks are possible, what are the limits, and how can you defend yourself?</abstract>
                <slug>bsides-cape-town-2024-56561-lolgrid-don-t-bring-your-own-network-one-already-exists</slug>
                <track></track>
                
                <persons>
                    <person id='58425'>Brent Shaw</person>
                </persons>
                <language>en</language>
                <description>Sometimes things just need to be looked at differently. 

Ethernet over power lines (IEEE 1901, Powerline, PowerPlug, you might or might not know it under different names) has been around for quite some time. That being said, while maybe might have heard of it, it seems to be a technology that never took off.

The technology allows for Ethernet traffic to be routed over alternating current (AC) power lines. This can help avoid clumsy cabling in small flats, or remove the need for long cable runs, providing a neat alternative to running new Ethernet cables. It can also be viewed as an interesting attack vector.

While work has been done to stop different power line devices intercepting other devices traffic, allowing multiple networks to be hosted together, this leads to new problems when it comes to securing your own infrastructure.

The talk will do into some background on the tech (very briefly) to explain its intended purpose and use cases. We will then look at how it can be used as part of attacks/engagements. We will then look at how one can defend against this.

We will looks at some interesting things I discovered along the way.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/K8FETB/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/K8FETB/feedback/</feedback_url>
            </event>
            <event guid='e2f94dd4-b776-5304-9b2d-4657d3a6e2fa' id='56513' code='DM7THC'>
                <room>Track 2</room>
                <title>Attacking Pipelines: Large Scale Exploitation of Workflow Files</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T15:05:00+02:00</date>
                <start>15:05</start>
                <duration>00:45</duration>
                <abstract>In this talk, we present a tool designed to perform large-scale scanning of GitHub repositories to identify potential expression injection vulnerabilities within their workflow files. Our system efficiently scrapes repositories, concurrently pulling and analysing workflow configurations for insecure patterns. Through this mining process, we have discovered that expression injection vulnerabilities are surprisingly prevalent, even among popular projects, and often go unnoticed. We have reached out to affected vendors for remediation and hypothesis this prevalence attributed to a lack of in detection mechanisms and key documentation on GitHub&#8217;s end. Additionally, we found that even when vulnerabilities are patched, they can be easily reintroduced by interpolating sanitised values. Our findings underscore the need for better tooling and awareness around securing GitHub workflows. Finally, we make our tool available to open-source for both blue and red team security researchers to benefit from.</abstract>
                <slug>bsides-cape-town-2024-56513-attacking-pipelines-large-scale-exploitation-of-workflow-files</slug>
                <track></track>
                
                <persons>
                    <person id='58398'>David Baker Effendi</person><person id='58413'>Rohan Dayaram</person>
                </persons>
                <language>en</language>
                <description>In this talk, we introduce a powerful tool that we developed for performing large-scale scanning of GitHub repositories, aimed at identifying expression injection vulnerabilities within workflow files. The motivation for this project arose from an incident where a client was exploited by a white-hat hacker who leveraged such a vulnerability to patch it through exploitation. This incident highlighted the prevalence and potential severity of expression injection in GitHub workflows, where attackers can inject malicious code through interpolated GitHub variables. This type of vulnerability can lead to the unauthorised exposure of sensitive information, such as the highly privileged `GITHUB_TOKEN`.

Our tool is designed to efficiently scrape repositories, interacting with the GitHub API to concurrently pull and analyse workflow configuration files. By parsing these YAML files and detecting insecure patterns, we were able to uncover a surprising prevalence of expression injection vulnerabilities across a wide range of repositories, including some of the most popular open-source projects. Through the process of continuous mining, our system adheres to GitHub&apos;s rate limits, allowing it to run in the background without overwhelming the platform.

A key aspect of our findings is that even when these vulnerabilities are patched, they are often reintroduced through seemingly benign changes, such as interpolating sanitized values back into workflows. This creates a cyclical security risk that many teams may not even realise. We observed that existing mitigations, such as restricting permissions for each step and cautiously using the `env` directive to safely insert GitHub variables, are not prioritised in the documentation and inadequately enforced in real-world projects.

Written entirely in Scala, our application serves as a robust scanner that not only parses and identifies risky patterns but, allows for an interactive review process of the findings. Through this ongoing effort, we hope to drive awareness around this often-overlooked class of security issues in CI/CD pipelines. Additionally, we have made this tool open-source, allowing both blue team (defensive) and red team (offensive) security researchers to benefit from it.

Key Takeaways:

* Expression injection vulnerabilities in GitHub workflows are more common than previously thought, even in widely used repositories.
* Attackers can exploit this vulnerability to extract privileged data like the `GITHUB_TOKEN`, leading to further compromise.
* Patching vulnerabilities is not always enough&#8212;reintroductions of sanitised values can recreate the problem.
* Proper mitigations, such as limiting permissions and safely handling GitHub variables, require more comprehensive documentation and awareness.
* Our tool, written in Scala, interfaces with the GitHub API and is capable of continuous background mining while adhering to API rate limits.
* We are open-sourcing this tool to promote better security practices and aid both security researchers and developers in safeguarding their workflows.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/DM7THC/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/DM7THC/feedback/</feedback_url>
            </event>
            <event guid='5794242c-e325-5be1-a95b-40644ee24cb7' id='54661' code='RGS8JW'>
                <room>Track 2</room>
                <title>Hacking the Airwaves: Beyond Relay Attacks!</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2024-12-07T16:00:00+02:00</date>
                <start>16:00</start>
                <duration>00:30</duration>
                <abstract>This talk will dive into the fundamental concepts of the radio frequency (RF) Relay attack and how it could be used to attack different type of systems that make use of radio communication. The Relay Attack allows an attacker to extend the intended range of communication between two devices, deceiving them into believing that they are in close proximity to one another to perform some type sensitive action, such as unlocking or starting cars, or making payments with PoS devices!</abstract>
                <slug>bsides-cape-town-2024-54661-hacking-the-airwaves-beyond-relay-attacks</slug>
                <track></track>
                
                <persons>
                    <person id='56674'>Robin Roodt</person>
                </persons>
                <language>en</language>
                <description>**Introduction:**

An introduction of the talk and the topics that are going to be covered. A quick glance into my background and how I got interested in radio frequency hacking. Explaining that the talk is mostly going to be focused diving into the fundamental concepts of the Relay attack and then two demonstrations as to how it could be used to target two completely different systems, namely cars and PoS devices.

**Concept of Relay Attack:**

This section is going to go through a conceptual explanation of what the relay attack is and how it is used to extend the intended range of communication between two devices, deceiving them into believing that they are in close proximity to one another to perform some sensitive action.

**Using the Relay attack to unlock and start cars:**

This section will explain how the Relay attack could be used to target automotive keyless entry and keyless start systems on cars. This will include a brief explanation of how keyless entry and keyless start systems work, with security footage showing how criminals execute the attack to steal a victim&apos;s car while the key remains locked inside the house (Demo 1). 

**How far could you relay signals?**

Now that we understand the fundamentals of the Relay attack, we are going to perform the same attack, but in a different way to illustrate that this attack can be performed over great distances. We are going to attempt to relay signals from Cape Town all the way to Pretoria to unlock a car. An explanation will be given of how the signals are relayed from Cape Town to Pretoria, which will follow a demonstration of the actual proof-of-concept. In-case the proof of concept doesn&apos;t work due to the demo gods, we are going to show a video of the PoC working between Johannesburg and Pretoria. (Demo 2)

**How does this work on other systems such as a PoS device?**

After going through the automotive security explanation, what would this look like on a different device such as a PoS device? This section will give an explanation of how the attack would work when targeting a PoS device&apos;s tap-to-pay to make payments over larger distances. The explanation, followed by a demonstration (Demo 3), is going to show that the PoS device doesn&apos;t actually have to be near the victim&apos;s credit card to make a payment. As long as the signals are correctly relayed, it could be done over any distance. 

**Closing remarks**

This section will be a quick recap of the topics covered during the talk, with a final reminder that this attack could be executed on anything that makes use of radio signals, such as access control system as well. A final note that I hope this talk has brought some insights to radio frequency hacking and raised some security awareness around the topic.

**Takeaways**

Security awareness about the Relay attack and how it could be used on any device that makes use of radio communication.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/RGS8JW/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/RGS8JW/feedback/</feedback_url>
            </event>
            <event guid='7f96bada-00b6-5935-b953-62558ce51858' id='54811' code='HLNZBU'>
                <room>Track 2</room>
                <title>SpeedRunners: The Hackers of the Gaming World</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2024-12-07T16:40:00+02:00</date>
                <start>16:40</start>
                <duration>00:45</duration>
                <abstract>Speedrunning, the art of completing games with incredible speed, has evolved into more than a gaming feat&#8212;it&apos;s a showcase of ingenuity, creativity, and technical prowess. This talk delves into the fascinating world of speedrunners, drawing parallels between their methodologies and those of cybersecurity professionals, while highlighting the significant impact on game development and software security.</abstract>
                <slug>bsides-cape-town-2024-54811-speedrunners-the-hackers-of-the-gaming-world</slug>
                <track></track>
                
                <persons>
                    <person id='56808'>Nunudzai Mrewa</person>
                </persons>
                <language>en</language>
                <description>In this talk, we&apos;ll dive into the fascinating world of speedrunners and uncover the parallels between their methodologies and the techniques used by cybersecurity professionals. We&apos;ll explore how speedrunners discover and exploit glitches in games through a combination of accident, experimentation, and deep code analysis - skills that mirror the vulnerability hunting process in software security.

By understanding the speedrunner&apos;s approach, we&apos;ll gain insights into the creative, persistent, and collaborative nature of finding and leveraging system vulnerabilities. This talk will not only fascinate gaming enthusiasts, but also illuminate the mindset of those who push the boundaries of what&apos;s possible in both the virtual and digital realms.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-cape-town-2024/talk/HLNZBU/</url>
                <feedback_url>https://pretalx.com/bsides-cape-town-2024/talk/HLNZBU/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
