<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2026.3.0.dev0. -->
<schedule>
    <generator name="pretalx" system="pretalx.com" version="2026.3.0.dev0" />
    <version>0.5</version>
    <conference>
        <title>BSides Joburg 2026</title>
        <acronym>bsides-joburg-2026</acronym>
        <start>2026-07-25</start>
        <end>2026-07-25</end>
        <days>1</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://pretalx.com</base_url>
        <logo>https://pretalx.com/media/bsides-joburg-2026/img/logo_XsQ2Stp.webp</logo>
        <time_zone_name>Africa/Johannesburg</time_zone_name>
        
        
    </conference>
    <day index='1' date='2026-07-25' start='2026-07-25T04:00:00+02:00' end='2026-07-26T03:59:00+02:00'>
        <room name='Track 1' guid='72ab5b9d-7650-5ed5-aa34-b0ed4c25e7b1'>
            <event guid='c4c0ef97-8e4a-5545-ba58-ed0d318e27cd' id='103220' code='KCZJXM'>
                <room>Track 1</room>
                <title>&quot;Goedkoop koop is duur koop&quot; - the price of cheap thinking</title>
                <subtitle></subtitle>
                <type>Keynote</type>
                <date>2026-07-25T09:30:00+02:00</date>
                <start>09:30</start>
                <duration>00:50</duration>
                <abstract>Thinking is expensive: time and effort, the one budget you can&apos;t refill. So we buy discounts like heuristics, tidy stories, curated feeds, and now agents that decide for us. Every discount is rational. Every discount is also an attack surface, and for twenty years an industry has been optimizing against it: a kill chain running recon, exploit, and payload against human cognition, at machine speed, one operator per user. This talk maps that attack: who runs it, how, and why &#8212; then asks the harder question: what actually defends against it, and where those defenses could break.</abstract>
                <slug>bsides-joburg-2026-103220-goedkoop-koop-is-duur-koop-the-price-of-cheap-thinking</slug>
                <track></track>
                
                <persons>
                    <person id='102253'>Roelof Temmingh</person>
                </persons>
                <language>en</language>
                <description>Cognition is expensive, so we buy cheaper substitutes, and someone else gets to set the price.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/KCZJXM/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/KCZJXM/feedback/</feedback_url>
            </event>
            <event guid='c93cbc22-e58f-5413-b749-79de3564486d' id='98029' code='MJG7ER'>
                <room>Track 1</room>
                <title>The Missing Drive: Proving a Hidden Linux HDD Through Windows Registry Forensics</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T10:25:00+02:00</date>
                <start>10:25</start>
                <duration>00:45</duration>
                <abstract>A suspect was linked to online financial fraud through ISP records. The user agent data suggested that the transactions had been performed from a Linux system. Yet when the computer was examined, only a Windows hard drive was present. The original forensic examination looked for familiar Windows artefacts, found nothing of value, and concluded that the computer could not have been used.

But what if the most important evidence was not on the drive that was examined?

This talk presents a real-world forensic case study of a missing Linux hard drive, a suspected dual-boot system, and the Windows registry artefacts that helped prove what had been removed. It is a technical walk-through of how forensic reconstruction can reveal the historical presence of storage devices, expose weak assumptions, and turn apparently absent evidence into a defensible conclusion.
The presentation will show how careful analysis of Windows registry hives, storage artefacts, boot-related configuration, and physical indicators allowed the investigation to move from &#8220;there is no Linux drive&#8221; to &#8220;there was a Linux drive, it was used in this computer, and it appears to have been removed.&#8221;

This is a talk about finding the evidence that someone hoped would stay hidden.</abstract>
                <slug>bsides-joburg-2026-98029-the-missing-drive-proving-a-hidden-linux-hdd-through-windows-registry-forensics</slug>
                <track></track>
                
                <persons>
                    <person id='97607'>Jason Jordaan</person>
                </persons>
                <language>en</language>
                <description>In digital forensics, some of the most important evidence is not always the evidence that is immediately visible. Sometimes the real question is not what is present, but what is missing, why it is missing, and what traces it left behind.

This talk presents a real-world forensic case study involving a suspect alleged to have conducted online financial fraud using a Linux-based system. The transactions had been traced back to the suspect through ISP records, and user agent string data suggested that the activity had originated from a Linux environment. However, when the suspect&#8217;s computer was examined, the police only considered the Windows hard drive that was present in the machine. They searched for familiar Windows artefacts, including LNK files and Shellbags, and found nothing that linked the fraud activity to that Windows installation. On that basis, they concluded that the computer could not have been used.

That conclusion was wrong.

The problem was not simply that the police had failed to find the right artefacts. The deeper problem was that they had asked the wrong forensic question. The allegation was not that the suspect had conducted the transactions from Windows. The allegation, supported by the user agent evidence, was that the activity had taken place from a Linux system. The relevant question was therefore not whether there were Windows user artefacts proving the transactions. The relevant question was whether the physical computer had also been configured to boot into, or otherwise use, a Linux system that was no longer present.

Through a detailed forensic examination of the Windows registry hives and related system artefacts, it was possible to prove the prior existence of a second physical hard drive. Further analysis established evidence consistent with the computer having been configured as a dual-boot system, with Windows on one drive and Linux on another. The digital findings were then correlated with a physical examination of the computer itself, where tool marks and other physical indicators suggested that the second drive had been removed.

This presentation will walk through the investigative reasoning and technical analysis used to move from an apparent absence of evidence to a defensible forensic conclusion. It will examine how Windows can retain traces of historical storage devices, how registry artefacts can assist in reconstructing prior system configurations, and how boot-related and storage-related evidence can be used to identify signs of a missing operating system drive. It will also consider how physical examination findings can support and corroborate digital forensic conclusions.
The talk is not intended as a general overview of Windows artefacts. It is a practical, technical case study about forensic reconstruction in the face of deliberate concealment. It will show why forensic practitioners must be careful not to confuse the absence of expected artefacts with the absence of relevant evidence. It will also demonstrate the importance of hypothesis-led investigation, especially in cases where a suspect may have attempted to remove or conceal the most incriminating evidence.

For the BSides Johannesburg theme of &#8220;Light the Way&#8221;, this case provides a very direct example of what digital forensics should do. It is about illuminating what was hidden, testing assumptions, challenging weak conclusions, and helping investigators and courts understand what really happened. In this case, the light did not come from a single artefact or a single tool. It came from methodical forensic reasoning, careful registry analysis, and the convergence of digital and physical evidence.

Attendees will leave with a better understanding of how Windows registry artefacts can reveal the historical presence of missing storage devices, how dual-boot configurations may be reconstructed after a drive has been removed, and why forensic conclusions must be based on tested hypotheses rather than a narrow search for familiar artefacts.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/MJG7ER/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/MJG7ER/feedback/</feedback_url>
            </event>
            <event guid='44fc96ca-7d3d-5fa2-8ce8-1752dc5d8e05' id='100285' code='GGUMFJ'>
                <room>Track 1</room>
                <title>Rooting the Wink Hub 2 (finally)</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T11:15:00+02:00</date>
                <start>11:15</start>
                <duration>00:45</duration>
                <abstract>The Wink Hub 2 is a 2016 multi-radio home automation hub, which was locked down using High Assurance Boot techniques. This talk will cover my efforts over a period of 3 years to finally run my own code on it - apparently the first person to do so.</abstract>
                <slug>bsides-joburg-2026-100285-rooting-the-wink-hub-2-finally</slug>
                <track></track>
                
                <persons>
                    <person id='99639'>Rogan Dawes</person>
                </persons>
                <language>en</language>
                <description>The Wink Hub 2 is a 2016 multi-radio home automation hub, originally purchased by myself because of its appearance as a hardware hacking playground - multiple manufacturer radio reference implementations dotted around the board, each with their own programming interface brought out to headers. Due to how easily the prior generation Hub 1 was hacked, the company implemented Freescale/NXP High Assurance Boot v4 techniques to lock the Hub 2 down. These were effective for 10 years to the best of my knowledge - I have seen no reports of anyone else successfully executing their own code on the Hub 2.

This talk will cover my efforts to break the security of the Wink Hub 2, and the lengths to which I went over a three year period to finally execute my own code on this device.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/GGUMFJ/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/GGUMFJ/feedback/</feedback_url>
            </event>
            <event guid='f313257d-597a-5af8-aba6-efccf391f964' id='97937' code='VY8CVH'>
                <room>Track 1</room>
                <title>Stop Waiting for Unicorns: Bulding SA&apos;s Security Pipeline with 3,300 Interns</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T12:05:00+02:00</date>
                <start>12:05</start>
                <duration>00:45</duration>
                <abstract>South Africa&apos;s cybersecurity skills gap isn&apos;t a future problem, it&apos;s a present one. Demand for security experts has been outpacing supply for years, and the organisations feeling the squeeze tend to respond the same way: raise the hiring salary and wait for job-ready candidates who don&apos;t exist yet.

We decided to test a different approach. MWR launched a free virtual internship programme for any students designed to take motivated individuals and give them structured, practical security training over 16 weeks. There was no barrier to entry, but there was only one condition, if you fail 3 assignments you&apos;re out. More than 3,300 people applied. After five weeks and the simple three-strike rule, over 1,800 had already dropped off. But roughly 800 stuck it out, keeping up with assignments week on week and  demonstrating exactly the kind of persistence the industry claims it can&apos;t find.

This talk draws on data from that programme alongside experience recruiting through MWR&apos;s traditional pipelines, observing self-directed learning trends through TryHackMe, and working inside university cybersecurity programmes at the University of Pretoria and Wits. Together, these lenses reveal where the talent pipeline is breaking, where it&apos;s stronger than we think, and why the organisations waiting for the &quot;finished product&quot; are missing the point.

We&apos;ll end off  with a practical call to action to the entire cyber security community. Highlighting specific, low-barrier ways the security community, not just employers, can help widen and strengthen the pipeline. MWR can&apos;t do this alone. The data says the talent and passion is there. The question is whether our industry is willing to meet it halfway.</abstract>
                <slug>bsides-joburg-2026-97937-stop-waiting-for-unicorns-bulding-sa-s-security-pipeline-with-3-300-interns</slug>
                <track></track>
                
                <persons>
                    <person id='97521'>Tinus Green</person><person id='97534'>Jonathon Everatt</person>
                </persons>
                <language>en</language>
                <description>## Talk Overview

### 1. The Gap Is Real (and Getting Louder)
Framing the South African cybersecurity skills shortage with demand-side data and what it looks like from inside recruitment. Why the current model of &quot;post a job and hope&quot; isn&apos;t working.

### 2. Four Lenses on the Pipeline
What MWR recruitment (600+ applicants), TryHackMe training data, university programmes (University of Pretoria, Wits), and the virtual internship each reveal about the talent funnel. Where candidates come from, where they stall, and what accelerates them.

### 3. 3,300 to 800: The Virtual Internship Experiment
The design and structure of the programme, the three-strike attrition model, the dropout curve over 16 weeks, and what the data tells us about motivation versus readiness. Who stayed, who left, and what separated the two groups.

### 4. Where the Pipeline Breaks
Why traditional recruitment signals (degrees, certifications, prior experience) miss good candidates. Why &quot;job-ready&quot; expectations are unrealistic when training structures don&apos;t exist. Why formal postgraduate programmes are arriving slowly and what that means for the next few years.

### 5. Where the Pipeline Is Stronger Than We Think
The 800 who stayed and what they demonstrated. How self-learning platforms have changed the speed of skill acquisition. What effective junior development actually looks like when organisations invest in it.

### 6. The Call to Action
Concrete, specific, low-barrier ways organisations and individuals can contribute: mentorship commitments, structured shadowing placements, open training content contributions, and hiring model adjustments that recognise non-traditional pathways. What MWR has learned about what works, and where we need the rest of the industry to step in.

---

## Key Takeaways

1. **The bottleneck isn&apos;t motivation, it&apos;s the gap between &quot;interested&quot; and &quot;employable&quot;**.

2. **Structured programmes surface committed candidates quickly**: Data from 3,300 virtual internship applicants shows that a deliberate attrition model identified 800 consistently engaged participants within five weeks.

3. **Traditional recruitment signals frequently fail**: Degrees, certifications, and prior experience don&apos;t reliably predict who will succeed when given structured support and practical training.

4. **Self-learning platforms have changed the game, but they&apos;re not enough**: Without industry investment in mentorship and practical pathways, the pipeline remains fragile and dependent on individual resilience.

5. **Small, concrete actions from the broader community can meaningfully widen the talent stream**: This isn&apos;t a problem that requires massive budgets, just willingness to meet emerging talent halfway.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/VY8CVH/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/VY8CVH/feedback/</feedback_url>
            </event>
            <event guid='f9469184-b697-56f2-820f-d64c8bff8cf8' id='100177' code='3FQBRW'>
                <room>Track 1</room>
                <title>1 LogSource to rule them all: What DNS Is Telling You(That You&apos;re Not Listening)</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T13:30:00+02:00</date>
                <start>13:30</start>
                <duration>00:45</duration>
                <abstract>Every organisation on this continent is generating DNS logs right now. Very few of them are reading those logs for threats. That single oversight is letting attackers use the most trusted protocol on your network as a covert highway for command and control, data exfiltration, and long-term persistence. South Africa now faces nearly 2,000 cyberattacks per organisation per week, yet most SOCs are drowning in endpoint alerts while DNS queries whisper attacker activity in plain text, completely unread. This talk shows what a single, generally available log source reveals: C2 beaconing hidden in query frequency, data leaving your network one subdomain at a time, and malware phoning home through resolvers you trust.</abstract>
                <slug>bsides-joburg-2026-100177-1-logsource-to-rule-them-all-what-dns-is-telling-you-that-you-re-not-listening</slug>
                <track></track>
                
                <persons>
                    <person id='99544'>Mohammed Anas</person>
                </persons>
                <language>en</language>
                <description>**Introduction &#8212; The Log Source You Already Have**
Every organisation running a network has DNS. It is the first thing that fires when a device connects, the last thing that fires before data leaves, and the quiet witness to almost every stage of an attack. Yet in most African SOCs, DNS logs sit unqueried. This talk makes the case what defenders can do with less,  they need to start listening to the one witness that never goes offline. The theme of this conference is &quot;Light the Way.&quot; DNS is the flashlight that was always in your pocket.

**Technical Deep Dive &#8212; Five Things DNS Sees That Your SIEM Misses**
We walk through five concrete attacker behaviours that leave clear, detectable traces in DNS logs alone: C2 beaconing via regular query intervals to attacker-controlled domains; DNS tunneling for covert data exfiltration encoded in subdomains; domain generation algorithms (DGAs) used by malware to find live C2 infrastructure; newly registered domain (NRD) abuse for phishing and initial access; and lateral movement fingerprinted through internal DNS resolution patterns. For each, we show the exact query patterns, the ES|QL detection rule that catches it, and what a clean alert looks like versus noise.

**Real-World Relevance &#8212; What African Attackers Are Actually Doing**
Drawing on publicly documented attack patterns from recent African incidents, including telecom breaches and ransomware campaigns active in the region in 2025, we map the DNS artifacts those attackers left behind. Ransomware groups like Qilin, Akira, and DragonForce, all confirmed active in Africa as of early 2026, rely heavily on DNS for C2 and staging. Their tradecraft is well-documented. Their DNS fingerprints are detectable.

**Key Takeaways &#8212; Getting the Most Out of What You Already Have**
DNS logs are basic. What you do with them is not. Attendees will leave knowing how to enrich raw DNS telemetry, adding context like domain lengths, TXT payload size, DNS history, threat intel enrichment, domain age, and reputation scoring to transform a plain query log into a high-signal detection source. We cover the specific attack behaviours that DNS exposes at each stage of the kill chain, the signatures that distinguish malicious DNS patterns from legitimate traffic (query length anomalies, entropy scoring for DGA detection, beaconing intervals, TXT record abuse), and the detection rules that operationalise those signatures immediately.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/3FQBRW/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/3FQBRW/feedback/</feedback_url>
            </event>
            <event guid='0333380d-0c1f-5520-927e-b9340c4d12ec' id='100564' code='WAKEAZ'>
                <room>Track 1</room>
                <title>The Black Box Problem: Detection Engineering in the Age of AI Agents</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-07-25T14:20:00+02:00</date>
                <start>14:20</start>
                <duration>00:20</duration>
                <abstract>Detection engineering is about more than alerts and SIEM rules; it is the practice of understanding attacker behaviour and building the visibility needed to detect it. As AI becomes embedded into enterprise environments through agents, copilots, and connected ecosystems, organisations face new identity, data, and supply chain risks that are difficult to monitor using traditional approaches. This talk explores how detection engineering can help illuminate these emerging threats and asks a bigger question: if every breach contains valuable lessons, why does cybersecurity still lack an effective way to share them with the wider industry?</abstract>
                <slug>bsides-joburg-2026-100564-the-black-box-problem-detection-engineering-in-the-age-of-ai-agents</slug>
                <track></track>
                
                <persons>
                    <person id='99891'>Jared Naude</person>
                </persons>
                <language>en</language>
                <description>Many organisations invest heavily in SIEM platforms and security tooling, yet struggle to answer a simple question: what attacks can we actually detect? Detection engineering seeks to bridge that gap by focusing on visibility, telemetry, attacker behaviour, and continuous improvement rather than simply collecting logs and generating alerts.

At the same time, organisations are rapidly embedding AI into everyday business operations. AI assistants, autonomous agents, MCP servers, and AI-powered workflows are becoming trusted participants in enterprise environments. These systems are creating entirely new security challenges. AI agents increasingly operate with delegated permissions, access sensitive corporate data, and interact with critical business systems, introducing new identity risks that traditional security models were never designed to handle. The growing ecosystem of models, plugins, connectors, MCP servers, and open-source components also introduces significant supply chain risk, often with limited visibility into how these systems operate or what dependencies they rely upon.

As adoption accelerates, these challenges will inevitably contribute to new classes of security incidents, compromises, and failures. Yet cybersecurity has a problem of its own. Unlike industries such as aviation, which have mature processes for investigating accidents and sharing lessons learned, cybersecurity lacks an effective mechanism for collective learning. Breaches are often hidden behind legal agreements, reputational concerns, or private incident reports, leaving the broader community unable to benefit from the lessons they contain.

This talk explores what detection engineering is, how it extends beyond traditional SIEM deployments, and why it is becoming increasingly important as AI reshapes enterprise environments. It also examines the growing AI attack surface, the identity and supply chain risks that accompany it, and why the industry may need its own equivalent of an aviation accident investigation board if we want to stop repeating the same mistakes and start learning from each other&apos;s failures.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/WAKEAZ/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/WAKEAZ/feedback/</feedback_url>
            </event>
            <event guid='1a7aaffd-72f8-528d-9b6b-14b81bf40209' id='99982' code='SCMAG7'>
                <room>Track 1</room>
                <title>Cells and Claws: A Mental Model for Autonomous AI Agents</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-07-25T14:40:00+02:00</date>
                <start>14:40</start>
                <duration>00:15</duration>
                <abstract>&quot;AI agent&quot; has become a catch-all term that hides more than it reveals, and builders, defenders, and testers are making decisions on top of incomplete mental models. This talk builds one from first principles: starting with the base LLM and climbing seven generations to the Claw, an autonomous digital agent operating with persistent identity, tools, and goals. We then contrast the Claw with the most successful autonomous agent we know, the biological cell, and find a shared code/data problem, a shared hijack pattern (adenovirus vs. prompt injection), and one critical gap: the Claw has no immune system. Attendees leave with a working mental model of AI agents, a reasoning tool, not a checklist that drives better decisions on design, control selection, surveillance, and response.</abstract>
                <slug>bsides-joburg-2026-99982-cells-and-claws-a-mental-model-for-autonomous-ai-agents</slug>
                <track></track>
                
                <persons>
                    <person id='99368'>Marinus van Aswegen</person>
                </persons>
                <language>en</language>
                <description>Introduction

Ask ten security professionals what an &quot;AI agent&quot; is and you will get ten different answers, most of them gesturing at something between an over-eager intern, a souped-up search engine, and an embryonic AGI. None of those models are wrong, but none of them are useful when you have to decide what to sandbox, what to log, or what to kill. As Claws, autonomous, tool-using, goal-pursuing systems with persistent identity move from labs into production, the cost of operating without a working mental model is measured in incidents. This talk is about lighting that path: building a model that is technically incomplete (all models are) but sharp enough to reason with.

Technical Deep Dive

We start at Generation 0: the base LLM as a probability distribution over tokens, demonstrated with a Galton board and grounded in a simplistic example of Karpathy&apos;s &quot;200 lines of Python&quot; microGPT. From there we climb seven generations Chat, Tool-Using, Workspace, Coding, Autonomous, Multi-Agent, and finally the Claw: a digital agent with persistent identity, file access, code execution, long-running tasks, and the ability to delegate. Along the way we look at what the industry currently uses to control these systems: sandboxing, prompt-injection guards, code / data separation attempts, and where each control breaks down at Claw scale. 

Real-World Relevance

Cells are autonomous, tool-using, self-replicating agents, and they are the best-studied agents we have. They solve the same problems Claws do, code / data confusion, identity, surveillance, shutdown &#8212; and we can take some lessons from their solutions. We build a parallel mental model of the cell, DNA as code-and-data, mRNA as instruction stream, MHC (Major Histocompatibility Complex) presentation as mandatory observability, apoptosis as self-attested shutdown, and then introduce the adenovirus as a textbook hijack: code-flow takeover by injecting foreign DNA into a system that cannot distinguish self from non-self at the molecular level. The talk will discuss comparisons of Cell vs. Claw across code / data confusion, hijack vector, surveillance, shutdown, and identity. The findings are uncomfortable: the Claw shares most of the cell&apos;s failure modes, and has none of the cell&apos;s defenses.

Key Takeaways

The headline takeaway is the model itself. A useful mental model is not a list of answers, it is a reasoning tool. Once you have one for AI agents as a class, anchored by the seven-generation ladder and the cell mirror, you can think more clearly and make better decisions.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/SCMAG7/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/SCMAG7/feedback/</feedback_url>
            </event>
            <event guid='940d0211-ebd2-5484-b6db-3a0e56a95b52' id='99006' code='YHKD9B'>
                <room>Track 1</room>
                <title>Pipe Dreams: Escalating to SYSTEM via Cooler Master MasterPlus</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T15:05:00+02:00</date>
                <start>15:05</start>
                <duration>00:45</duration>
                <abstract>Every gaming peripheral that ships to your desk comes bundled with software running silently as NT AUTHORITY\SYSTEM. These OEM utilities are trusted, rarely audited, and almost never patched.

In this talk I walk through the discovery and exploitation of a local privilege escalation vulnerability in Cooler Master MasterPlus. A  peripheral management suite installed on millions of Windows machines. The root cause is an unauthenticated named pipe exposed by MPService.exe (SYSTEM). Any standard local user can connect, send a single JSON payload, and execute arbitrary commands as SYSTEM with no admin rights, no user interaction, and no race condition required.

I&apos;ll cover the full methodology: service enumeration, pipe discovery, Ghidra static analysis, dynamic confirmation, and a working proof-of-concept.</abstract>
                <slug>bsides-joburg-2026-99006-pipe-dreams-escalating-to-system-via-cooler-master-masterplus</slug>
                <track></track>
                
                <persons>
                    <person id='98487'>Tyron Kemp</person>
                </persons>
                <language>en</language>
                <description>OEM peripheral software ships trusted on millions of Windows machines, runs as SYSTEM, and almost never receives a security review. Inspired by Leon Jacobs&apos; DEF CON 33 research, this talk applies the same methodology to a major peripheral manufacturer&apos;s management suite.

Methodology:
Systematic enumeration of SYSTEM services, IPC surface discovery, access control analysis, and binary reverse engineering. I&apos;ll cover the tooling and decision points that led from initial enumeration to a confirmed vulnerability.

Root Cause Analysis:
Static analysis identifies a privileged IPC handler that accepts unauthenticated connections from any local user and processes attacker-controlled input without validation. I&apos;ll walk through the decompiled code showing exactly where the trust boundary fails and why the impact is full SYSTEM code execution.

Demo:
Proof-of-concept demonstrated live: standard user to NT AUTHORITY\SYSTEM in a single step. No admin rights, no user interaction, no race condition.

Remediation &amp; Disclosure:
Vendor disclosure process including what to expect when a vendor has no dedicated PSIRT.

Takeaways &amp; Q&amp;A:

Key Takeaways
1. A replicable methodology for auditing OEM/bloatware SYSTEM services
2. How Windows IPC access controls are commonly misconfigured
3. Navigating coordinated disclosure with vendors that lack a PSIRT</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/YHKD9B/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/YHKD9B/feedback/</feedback_url>
            </event>
            <event guid='645df8ec-bf33-5d71-af1a-0326d131b039' id='99829' code='EQCAL7'>
                <room>Track 1</room>
                <title>Shedding Light on Mobile Trust: Rethinking SSL Pinning</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-07-25T15:55:00+02:00</date>
                <start>15:55</start>
                <duration>00:15</duration>
                <abstract>**SSL pinning is not dead &#8212; it just needs a redesign.**

Mobile applications have traditionally relied on static SSL pinning to defend against man-in-the-middle attacks. However, static pins introduce operational challenges, including certificate rotations, application updates, and recovery from compromised trust anchors.

This talk explores an alternative approach: a protocol-driven model that enables the secure exchange and validation of SSL pins between a mobile application and backend services. By moving beyond hardcoded trust relationships, organisations can improve resilience, reduce deployment friction, and maintain strong transport security without sacrificing agility.

We will examine the threat landscape, design considerations, trust-establishment mechanisms, and practical implementation patterns for securely distributing and validating pins at runtime. Attendees will leave with a fresh perspective on mobile trust models and a roadmap for building more adaptable, future-ready SSL pinning solutions.</abstract>
                <slug>bsides-joburg-2026-99829-shedding-light-on-mobile-trust-rethinking-ssl-pinning</slug>
                <track></track>
                <logo>/media/bsides-joburg-2026/submissions/EQCAL7/image_LpiEAax.webp</logo>
                <persons>
                    <person id='99253'>Christoff Jacobs</person>
                </persons>
                <language>en</language>
                <description>**Bootstrapping Trust: Secure Distribution of SSL Pins in Mobile Applications**

SSL pinning has long been considered a cornerstone of mobile application security. Yet most implementations still rely on hardcoded pins embedded within applications, creating an uncomfortable trade-off between security and operational agility. Certificate rotations, emergency key replacements, backend migrations, and application release cycles often turn a security control into an operational burden.

This talk explores a different approach to establishing trust between mobile applications and backend services. Instead of shipping static trust anchors inside the application, we examine a protocol that securely bootstraps trust and dynamically distributes SSL pinning configuration to mobile clients.

The architecture leverages modern cryptographic primitives, including Ed25519 for digital signatures, asymmetric key exchange for trust establishment, and AES encryption for secure transport of sensitive configuration data. During an initial registration phase, the mobile application generates a unique device trust identity and establishes a secure cryptographic relationship with the server. Once trust has been established, the server can securely distribute and rotate SSL pinning information without requiring application updates or exposing trust material to interception.

The session walks through the protocol design, trust establishment process, cryptographic decision-making, and implementation challenges encountered while building the solution. We will discuss key rotation strategies, secure storage considerations, and how the design resists common attacks such as man-in-the-middle interception, and other pin distribution strategies.

Attendees will gain practical insights into the future of mobile trust models, understand the limitations of traditional SSL pinning approaches, and leave with architectural patterns to build more resilient mobile security controls in environments where change is constant and trust cannot be hardcoded forever.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/EQCAL7/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/EQCAL7/feedback/</feedback_url>
            </event>
            <event guid='8287c125-bdfd-5ef5-8ea4-69166831e212' id='98263' code='WKRNMH'>
                <room>Track 1</room>
                <title>From Unknown to Understood: Malware Triage in Minutes</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-07-25T16:10:00+02:00</date>
                <start>16:10</start>
                <duration>00:15</duration>
                <abstract>Malware analysis can often feel out of reach for newer analysts, particularly when discussions move into reverse engineering and assembly. In practice, however, the earliest stages of analysis frequently provide enough information to form an initial understanding of a sample.

This talk introduces a structured &#8220;first 10 minutes&#8221; malware triage workflow, covering hashes, reputation analysis, strings extraction, and sandbox detonation. The focus is on efficiently identifying behavioural indicators and building a coherent analytical narrative from early observations, rather than immediately relying on deep reverse engineering.

Attendees will leave with a repeatable and practical approach to early-stage malware analysis that supports incident response workflows, strengthens analytical confidence, and improves the ability to quickly translate unknown samples into meaningful, actionable insight.</abstract>
                <slug>bsides-joburg-2026-98263-from-unknown-to-understood-malware-triage-in-minutes</slug>
                <track></track>
                
                <persons>
                    <person id='93834'>Latasha Friend</person>
                </persons>
                <language>en</language>
                <description>This session is aimed at analysts who want a practical starting point for malware analysis without immediately diving into reverse engineering. Using a lightweight workflow, I will show how simple triage steps can quickly uncover useful context, suspicious behaviour, infrastructure, and attacker intent.

Static and dynamic analysis techniques are combined to show how hashes, strings, reputation data, and sandbox observations can be used together to build a clearer understanding of a sample. Along the way, we discuss the importance of treating indicators as clues rather than conclusions, and how defenders can turn scattered observations into practical, actionable insight.

Rather than focusing on advanced reverse engineering, this session demonstrates that meaningful analysis begins much earlier, and that newer analysts can contribute valuable findings with the right approach.

Key Takeaways:
- A simple malware triage workflow for the first 10 minutes
- How to combine simple static and dynamic analysis effectively
- Ways to identify useful indicators and suspicious behaviour quickly
- How to turn technical findings into a coherent analysis story</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/WKRNMH/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/WKRNMH/feedback/</feedback_url>
            </event>
            <event guid='84e3188d-5599-5a06-abb0-2e4fbd2b6f9f' id='100032' code='AXTUMN'>
                <room>Track 1</room>
                <title>Using CSC to build future cyber workforce</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-07-25T16:25:00+02:00</date>
                <start>16:25</start>
                <duration>00:15</duration>
                <abstract>The cyber security skills gap is a global problem, but it is acutely felt in South Africa, where access to structured, affordable, and locally relevant training remains limited. This talk draws on first-hand experience designing and building Capture the Flag (CTF) challenges for the SANReN Cyber Security Challenge (CSC) to explore how individuals and small groups can become the spark that ignites a local security community.

From identifying the gap to building beginner-friendly challenges, running competitions, and watching participants grow into contributors. The SANReN CSC was created with the sole purpose of building up local cyber security skills but we would like to extend that goal by supporting local communities to start up their own initiatives and hacking communities.</abstract>
                <slug>bsides-joburg-2026-100032-using-csc-to-build-future-cyber-workforce</slug>
                <track></track>
                
                <persons>
                    <person id='99415'>Ivan Burke</person>
                </persons>
                <language>en</language>
                <description>Most cyber security training is expensive, foreign, or assumes a level of access that many South African students and practitioners simply do not have. Many South African tertiary institutions do not even offer cyber security at undergrad level, only at Honours or Masters level. Yet many of these students have immense talent. It just needs _a guiding light_.

This talk will cover the story behind building CTF challenges for the SANREN CSC, what worked, what did not, and what any motivated person or group can replicate without a large budget.

Previously a similar talk was presented at BSides Cape Town 2025, this talk has been updated and expanded for BSides Joburg with new lessons learned and a broader focus on community building beyond the CTF context.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/AXTUMN/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/AXTUMN/feedback/</feedback_url>
            </event>
            <event guid='0710ee4c-e258-5a32-9eea-2704a7014e34' id='99879' code='3QBKMN'>
                <room>Track 1</room>
                <title>SocVel Live : The CISO&apos;s Gambit</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T16:45:00+02:00</date>
                <start>16:45</start>
                <duration>00:45</duration>
                <abstract>I don&apos;t sign off on risk waivers and I don&apos;t set the budgets. But, more often than not, I am the one who tells the CISO why their weekend plans are about to get ruined.

The CISO&apos;s Gambit is a live strategy simulation where Threat Intelligence sets the scene and the audience drives the response. Drawing on the cyber roller coaster of the past 12 months, you get put in the hot seat of the one whose weekend is now also ruined. When a critical vendor is compromised, do you halt production or do &quot;heightened monitoring&quot; and pray. When the geopolitical mess spills over into cyber, do you change vendors or duck and cover. 

Through live audience voting, we track the real-world impact of your choices across key metrics. No slides. No safe paths. Just trade-offs, facepalms and high-fives through a collective decision-making experiment.</abstract>
                <slug>bsides-joburg-2026-99879-socvel-live-the-ciso-s-gambit</slug>
                <track></track>
                
                <persons>
                    <person id='99296'>Jaco Swanepoel</person>
                </persons>
                <language>en</language>
                <description>This isn&apos;t a talk about security leadership. But a look at how those decisions are made collectively. Decisions that need to get taken because someone, probably someone in this room, found something. Flagged something. Wrote the email that landed in the wrong inbox at the wrong time and suddenly it&apos;s everyone&apos;s problem. 

The CISO&apos;s Gambit is the next evolution of SocVel Live, the interactive tabletop format that took home Best Speaker at BSides JHB 2025. This time, we&apos;re not hunting the threat. We&apos;re managing what comes after.

Working through scenarios grounded in real threat intelligence from the past year: each one a moment where a technical finding collides with a business reality &#8212; and someone has to make a call with incomplete information, an impatient board, and a vendor on hold. Sound familiar? 

The scenarios cover the kind of things that have been quietly ruining people&apos;s Fridays since 2025. ClickFix campaigns, the AI apocalypse, geopolitical shenanigans, supply chain compromises and malicious dev tooling that handed your build pipeline over to someone called Vlad.

The audience votes on what to do at each decision point. Consequences unfold in real time. And we track the impact across three metrics: Board Confidence, Reputation, and Threat Exposure.

This session is built for techies. Because the best leadership decisions in security are only as good as the technical insight behind them. The techies are the ones who assess the new tool that is supposed to be the silver bullet, give feedback on what the blast radius of a change will be, or flag the dodgy process the entire business is running on. This simulation puts that work in context &#8212; and shows what happens when it hits the decision layer.

No single right answer. No fixed path. Just trade-offs, pressure, and the collective weight of a room that knows exactly what&apos;s at stake.

Hope you like awkward board meetings.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/3QBKMN/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/3QBKMN/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Track 2' guid='2fd34c2d-802d-5c37-9ebc-0f13a4d1df25'>
            <event guid='b6209c45-fcca-5e7c-9411-43b252800218' id='96042' code='EFWTWY'>
                <room>Track 2</room>
                <title>Gimme! Gimme! Your Creds After Midnight: Weaponising Veeam Credential Extraction</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T10:25:00+02:00</date>
                <start>10:25</start>
                <duration>00:45</duration>
                <abstract>## Abstract

Backup solutions deal with incredibly sensitive data, and for ransomware to be truly effective, backups are a primary target. One of the common backup technologies we encounter during red team engagements is Veeam and it often stores highly privileged credentials needed to perform backup jobs across the environment. Domain Admin, vSphere administrator, ESXi root: all sitting in a database, encrypted with DPAPI, waiting for someone to ask nicely.

In this talk, we walk through how we went from manually extracting credentials from Veeam Backup &amp; Replication and Veeam ONE databases to building and releasing VeeamDumper, a .NET tool and Beacon Object File (BOF) that automates the entire process. We&apos;ll cover the credential storage mechanisms and encryption differences between VBR and Veeam ONE (including the undocumented Veeam ONE entropy value we had to figure out ourselves), the DPAPI decryption chain, and how extracted credentials map to infrastructure targets for lateral movement.

Beyond the tool itself, we&apos;ll break down the process of porting a .NET post-exploitation tool into a BOF including the design decisions, the pain points, and why having both gives operators flexibility across different C2 frameworks. We&apos;ll demonstrate VeeamDumper live, from enumeration through to cleartext credential extraction and target mapping.

We&apos;ll close with the defender&apos;s perspective: what makes Veeam infrastructure vulnerable, why domain-joining backup servers to your primary AD domain is asking for trouble, and practical hardening steps to stop us from doing exactly what we just showed you.

VeeamDumper will be released as open-source prior to this talk.</abstract>
                <slug>bsides-joburg-2026-96042-gimme-gimme-your-creds-after-midnight-weaponising-veeam-credential-extraction</slug>
                <track></track>
                
                <persons>
                    <person id='95776'>Stephen</person><person id='95775'>Logan Kroeger</person>
                </persons>
                <language>en</language>
                <description>## Talk Overview

### 1. Why Attackers Love Your Backups
The role of backup infrastructure in targeted attacks and ransomware operations. Why Veeam servers are high-value targets and what we keep finding during real-world engagements: domain-joined backup servers, over-privileged service accounts, and credentials that unlock far more than just backup jobs.

### 2. How Veeam Stores Credentials (And How We Extract Them)
The technical internals: how VBR and Veeam ONE store credentials in MSSQL and PostgreSQL databases, how DPAPI encryption is applied differently between the two products, and the undocumented Veeam ONE entropy value that isn&apos;t covered in Veeam&apos;s own KB articles. We&apos;ll walk through the decryption chain step by step, from encrypted database blob to cleartext password.

### 3. Building VeeamDumper: From Manual Process to Automated Tooling
How repeated encounters with Veeam during engagements drove us to automate the extraction process. The design of VeeamDumper&apos;s modules (ENUM, AUTO, MSSQL/PSQL, MAP), why we built it as a .NET assembly for execute-assembly compatibility, and how the MAP module connects extracted credentials to specific infrastructure targets.

### 4. From .NET to BOF: Porting Post-Exploitation Tooling to C
The process of taking a working .NET tool and porting it into a Beacon Object File. Why BOFs exist, what changes when you move from managed .NET to raw C and practical lessons for anyone building red team tooling

### 5. Live Demo: VeeamDumper in Action
Live demonstration of VeeamDumper against a lab environment: enumeration, automatic credential extraction, DPAPI decryption, and credential-to-target mapping. We&apos;ll show both the .NET execute-assembly path and the BOF execution.

### 6. Securing Your Backup Infrastructure
Practical hardening guidance: why backup servers should not be domain-joined to your primary AD domain, how to restrict access to credential stores, detection opportunities for credential extraction activity, and the questions every organisation should be asking about their backup security posture.

## Key Takeaways

1. **Veeam backup servers frequently store Domain Admin-level credentials** in a reversible format and once an attacker has local admin on the server, extracting them is straightforward.

2. **Veeam ONE handles credential encryption differently to VBR** using an undocumented entropy value, a detail not covered in Veeam&apos;s public documentation that we had to reverse ourselves.

3. **VeeamDumper automates the full extraction chain** enumeration, database identification, DPAPI decryption, and credential-to-target mapping as both a .NET assembly and a BOF, released as an open-source tool on MWR&apos;s GitHub.

4. **Porting .NET post-exploitation tooling to a BOF** involves meaningful design tradeoffs of which we&apos;ll share the practical lessons for anyone building red team tools that need to operate across C2 frameworks.

5. **Domain-joining backup servers to your primary AD domain** creates a compounding risk that turns a single compromise into full infrastructure takeover, including the destruction of your recovery capability.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/EFWTWY/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/EFWTWY/feedback/</feedback_url>
            </event>
            <event guid='56118aab-a8c8-5852-bfc8-0a6ea4a7859b' id='98231' code='FJCUKR'>
                <room>Track 2</room>
                <title>The Device Doesn&apos;t Take No for an Answer</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T11:15:00+02:00</date>
                <start>11:15</start>
                <duration>00:45</duration>
                <abstract>The vendor app says &quot;online&quot; while the firewall drops every byte of outbound traffic. The voice prompt says &quot;router connection unsuccessful&quot; while the device hammers an IP it never resolved. Embedded devices lie to their owners, and most owners can&apos;t see it.

This talk is the result of putting six embedded devices through the same enforcement lab, a mix of bottom-of-market kit and units from more recognisable vendors, and measuring the gap between what they say and what they do. You walk out with a nine-phase test you can run on your own kit, a four-axis scorecard that survives a procurement meeting, and a way to tell the difference between failing safe and failing by lying.</abstract>
                <slug>bsides-joburg-2026-98231-the-device-doesn-t-take-no-for-an-answer</slug>
                <track></track>
                
                <persons>
                    <person id='97798'>Travis More</person>
                </persons>
                <language>en</language>
                <description>We tell each other to &quot;segment the IoT device.&quot; Then we put it on a separate VLAN, the device gets quiet for ninety seconds, and goes back to phoning home from an IP that no DNS record ever pointed at. While the vendor app cheerfully reports &quot;online.&quot;

That gap, between what the device tells the user and what it&apos;s actually doing, is what this talk measures.

This isn&apos;t a talk about zero-days. It&apos;s about the other dodgy things these devices do on the networks they sit on: talking to hosts they shouldn&apos;t, ignoring the policy you set, lying about their own state when you ask. Still a security problem. Still mostly invisible from where most owners and network admins are standing.

I built a small enforcement lab around an open-source firewall and a Pi access point, and put six embedded devices through the same nine-phase routine: an IP camera, an attendance terminal, a SOHO router, a smart plug, a video doorbell, and a Zigbee smart-home hub. The sample mixes bottom-of-market kit with units from more recognisable vendors. Part of the point is that what the scorecard catches doesn&apos;t have much to do with what you paid. Cold boot. Idle baseline. Then a sequence of restrictions: full outbound block, vendor-domain sinkhole, wildcard DNS blackhole on the vendor zone, half a second of injected latency, two seconds of latency, a UDP block. At every step I pull the packet capture, the firewall counters, and the live filter log, and score the device against a four-axis scorecard: can you segment it, does it tell you the truth when you do, who does it actually trust, and how does it fail when something breaks?

The findings are the kind of thing a typical owner can&apos;t see from the vendor app:

- Devices that ignore the network&apos;s DHCP-assigned resolver and do their own DNS to a public address. Any DNS policy not fronted by a redirect rule does nothing in that case.
- Devices that reach a long list of hardcoded public IPs that no DNS query ever resolved, across multiple cloud providers and continents, well before any user interaction.
- Devices that ship credentials in cleartext alongside user-generated content over HTTP/80, in 2026.
- Devices that enter sticky failure modes on a few seconds of injected latency. Only a hard power cycle gets them back.
- Devices that announce a network failure to the user, then keep uploading at a steady rate to a hardcoded fallback for the next twenty minutes. The vendor app cheerfully reports &quot;online&quot; for minutes after the network has actually been cut.

Pushing a device a little past its design envelope is itself a way to surface weaknesses you wouldn&apos;t see at rest. The wedged state machines above are the clearest example. The device was never built to handle the network it found itself on, and what was meant to be measurement turned into something that looks a lot like a bug report.

The point isn&apos;t that any one of these devices is uniquely bad. The point is that for a real slice of the embedded device market, &quot;secure deployment&quot; stops being a configuration choice and becomes an architectural fact about what you bought. That conversation needs better ammunition than a feeling. This talk is an attempt to give it some.

What you&apos;ll leave with:

- A repeatable nine-phase test you can run on a device sitting on your desk, with open-source firewall and packet-analysis tools you probably already have.
- A four-axis scorecard (segmentation viability, transparency, trust hygiene, fail posture) with worked examples you can defend with a line of packet capture per score.
- The procurement questions that surface a hardcoded dependency on the spec sheet, not after install.
- A concrete way to tell the difference between a device that fails safely under enforcement and a device that fails by lying to you.

What you won&apos;t get: zero days, exploit chains, or vendor names on the slides. The talk is written for defenders and procurement people, not red teamers, though the failure modes will look familiar to both.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/FJCUKR/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/FJCUKR/feedback/</feedback_url>
            </event>
            <event guid='f76a1b53-8302-54c2-bd03-4278e1f483d8' id='98923' code='3JE8KJ'>
                <room>Track 2</room>
                <title>Lighting the Way in the Dark: Binary-Only Race Detection in Go with Zorya-Volos</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T12:05:00+02:00</date>
                <start>12:05</start>
                <duration>00:45</duration>
                <abstract>&quot;How do I find race conditions in a Go binary without being a wizard? Do any tools actually cater to real-world, off-the-shelf binaries?&quot; When source code is unavailable, Go&#8217;s runtime acts as a dark, impenetrable black box where traditional scanners fail. Given the prevalence of Go in critical cloud infrastructure and high-stakes cryptocurrency environments, these &quot;invisible&quot; vulnerabilities represent a significant and under-addressed security risk.

To address this, we present Zorya-Volos, a specialized framework that lights the way into the obscured depths of Go runtime internals and concurrent behavior, bridging the gap between theoretical research and practical, in-depth security assessment. Zorya-Volos is built by leveraging Ghidra&#8217;s P-Code intermediate representation, processed through an internally developed translation layer that interfaces directly with the Z3 SMT solver to model binary execution paths with mathematical rigor. Zorya-Volos differentiates itself from other approaches by (i) being rigorously tested on COTS binaries, (ii) fielding a hybrid race detection algorithm developed through deep binary analysis to identify both lock inconsistencies and race-able memory access, and (iii) utilizing symbolic execution for the comprehensive modelling of execution paths.

Expanding on our Black Hat Asia presentation, we demonstrate how this engine maps runtime scheduler behavior to state-changing operations within the binary. We will explore the technical challenges of symbolic execution at scale, showcasing how our approach successfully identifies critical concurrency flaws and null pointer dereferences that current industry tooling and automated scanners consistently overlook in production environments.</abstract>
                <slug>bsides-joburg-2026-98923-lighting-the-way-in-the-dark-binary-only-race-detection-in-go-with-zorya-volos</slug>
                <track></track>
                
                <persons>
                    <person id='98402'>Keith Makan</person>
                </persons>
                <language>en</language>
                <description>Go&#8217;s concurrency model&#8212;built on the pillars of Goroutines and a sophisticated M:N scheduler&#8212;offers powerful performance but introduces complex, often non-deterministic, vulnerability surfaces. Because Go is the language of the cloud, powering critical infrastructure like Kubernetes and Docker, as well as high-stakes distributed systems and cryptocurrency utilities, these vulnerabilities are widespread. When source code is unavailable, identifying race conditions in Go binaries becomes a daunting challenge for security researchers navigating in the dark.

This talk introduces Zorya-Volos, a concolic execution framework built on Rust and Ghidra&#8217;s P-Code IR, designed specifically to tackle the challenges of binary-only analysis of concurrent Go programs. We will light the way into the black box of the Go runtime, examining how the scheduler orchestrates Goroutine execution and manages thread mapping under the hood.

Attendees will learn how Volos leverages advanced concolic execution to lift Go binaries, track execution paths without source code, and identify race conditions by modeling memory access patterns and lock states across threads. We will conclude with a comparative look at the current tooling landscape and demonstrate why our approach to in-depth manual vulnerability assessment remains essential for uncovering the race conditions that traditional scanners miss.

What attendees will learn:

- Go Runtime Internals: A deep dive into how Go binaries launch, how the scheduler distributes tasks across P, M, and G (Processor, Machine, and Goroutine) structures, and how to track the execution state of specific Goroutines.
- Source-less Analysis: How Zorya-Volos disassembles and lifts binary code to track execution paths and identify concurrency-impacting operations without needing access to the original Go source.
- Race Condition Detection: A technical breakdown of the Volos engine&#8217;s unique ability to correlate memory read/write operations with concurrency primitives to detect race conditions in compiled Go.
- Tooling Landscape: A comparison of current binary analysis tools for Go, highlighting the limitations of current solutions and the unique advantages of the Zorya-Volos methodology in securing production-grade cloud and crypto infrastructure.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/3JE8KJ/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/3JE8KJ/feedback/</feedback_url>
            </event>
            <event guid='accf90e3-f98d-581c-9b53-2d8026f757ac' id='99348' code='BRXAF8'>
                <room>Track 2</room>
                <title>Should&apos;ve, Could&apos;ve, Would&apos;ve: How Organisations Drift Into Breach</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T13:30:00+02:00</date>
                <start>13:30</start>
                <duration>00:45</duration>
                <abstract>Cyber breaches are often portrayed as the result of sophisticated attackers, yet many incidents are enabled long before compromise occurs. Organisational behaviours such as delayed patches, recurring exceptions, ignored audit findings, security fatigue, and risk acceptance quietly create the conditions that attackers exploit. This talk examines the cultural and operational patterns that tend to precede breaches, drawing on case studies across various industries to highlight how risk normalisation and organisational drift increase exposure.</abstract>
                <slug>bsides-joburg-2026-99348-should-ve-could-ve-would-ve-how-organisations-drift-into-breach</slug>
                <track></track>
                
                <persons>
                    <person id='98808'>Kitso Moema</person>
                </persons>
                <language>en</language>
                <description>Most cyber breaches are framed as sophisticated technical attacks carried out by highly skilled threat actors. Although this might hold for certain situations, many breaches are ultimately enabled by decisions, trade-offs, and accepted risks that existed long before an attacker ever gained access.

A delayed patch. A temporary exception. An ignored audit finding. A burned-out SOC team. A business decision to &#8220;accept the risk.&#8221;

This talk examines the organisational behaviours, decisions, and trade-offs that quietly create ideal conditions for attackers. Drawing on publicly documented breach case studies across multiple industries, it explores how risk normalisation, recurring exceptions, technical debt, security fatigue, and competing business priorities can gradually increase an organisation&apos;s exposure to cyber threats.

This discussion focuses on the often-overlooked pre-breach phase: the warning signs, decisions, and cultural patterns that frequently precede compromise. By understanding these signals, security professionals can better identify environments where cyber risk is accumulating before it manifests as a major incident.

Organisations rarely approve breaches outright, but by normalising risky conditions they unintentionally pave the way for them.

Takeaways from this talk will include:
1. Recognising organisational drift.
2. Spotting cultural warning signs and patterns that signal rising exposure.
3. Examining publicly documented case studies to see how organisational behaviours, not just attacker sophistication, paved the way for incidents.
4. Gaining practical methods to detect and counteract organisational drift.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/BRXAF8/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/BRXAF8/feedback/</feedback_url>
            </event>
            <event guid='067d4047-af73-5e16-84f0-c20b38115192' id='100322' code='KVU7J3'>
                <room>Track 2</room>
                <title>A journey through Cybersecurity Regulation in practice</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-07-25T14:20:00+02:00</date>
                <start>14:20</start>
                <duration>00:35</duration>
                <abstract>Join us on a journey through the OT cybersecurity of a fictitious chemical plant in Germany where everything seems under control - until the regulators arrive. The IT team has done its best, the engineers trust their safety systems, and everyone is fairly confident that &#8220;nothing serious can happen here.&#8221; But as new regulatory demands start landing on the desk, the plant is forced to confront an uncomfortable question: is the plant actually secure, or merely hoping for the best?

In this session, we follow a chemical plant as it navigates real European and German cybersecurity regulations, including KAS-51, TRBS 1115-1, and the EU Cyber Resilience Act. Along the way we explore OT risk assessments, safety instrumented systems, hazardous incident reporting and a lot more!

Finally, we bring the lessons home to South Africa. As our own regulatory environment continues to develop, what should we copy, what should we avoid, and what should we design differently from the start? Attendees will leave with a practical, story-driven view of how cybersecurity regulation moves from policy documents into control rooms, engineering workshops, audit reports, and national resilience.</abstract>
                <slug>bsides-joburg-2026-100322-a-journey-through-cybersecurity-regulation-in-practice</slug>
                <track></track>
                
                <persons>
                    <person id='99669'>Dietmar Marggraff</person>
                </persons>
                <language>en</language>
                <description>**Introduction to the topic**
South Africa&#8217;s cybersecurity landscape largely relies on best-effort security practices, often without strong regulatory enforcement to drive consistency and accountability. While this approach allows flexibility, it can make it difficult to achieve baseline security maturity across industries. In contrast, many international environments operate under detailed, enforceable cybersecurity regulations that actively shape how organisations build, operate, and maintain their security programs. Understanding how these regulations work in practice is key to evaluating how similar approaches could strengthen local cybersecurity outcomes.

**Technical Deep Dive**
This talk will explore a selection of modern cybersecurity regulations, including the Cyber Resilience Act (CRA), Germany&#8217;s KAS-51 and TRBS 1115-1. For each, we will examine:

- Who is in scope and why
- How the regulation is structured and applied
- The role of regulators and oversight bodies
- What organisations are concretely required to implement

The focus will not be on legal text, but on translating regulatory requirements into actionable security practices - covering areas such as risk management, incident reporting, security controls, and audit readiness.

**Real-World Relevance**
To ground the discussion, the talk will include practical case studies drawn from implementing the CRA, KAS-51, and TRBS 1115-1 in real environments. These will cover:
- How requirements were interpreted and operationalised
- How audits and assessments were conducted in practice
- Where the regulations drove meaningful improvements in security posture
- Where challenges emerged, particularly around administrative burden and compliance-driven approaches

These examples will provide a realistic view of both the strengths and limitations of regulatory-driven security.

**Key Takeaways**
Attendees will leave with:
- A clear understanding of how modern cybersecurity regulations function in practice
- Insight into the implementation realities behind major frameworks like the CRA
- An appreciation of both the benefits and pitfalls of regulatory-driven security
- Practical ideas for how similar approaches could be adapted to the South African context to support stronger, more effective cybersecurity outcomes</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/KVU7J3/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/KVU7J3/feedback/</feedback_url>
            </event>
            <event guid='a5a2cbb2-067d-52d5-ac65-5b66375f42d6' id='98701' code='HWSVHB'>
                <room>Track 2</room>
                <title>Turning Roadkill into braAI-VibeSDLC</title>
                <subtitle></subtitle>
                <type>Standard Talk</type>
                <date>2026-07-25T15:05:00+02:00</date>
                <start>15:05</start>
                <duration>00:45</duration>
                <abstract>Anyone got a light? When the CEO or product people send you a zip or github project do we burn or braai? Corporate and enterprise level AI enabled development is another beast in of itself. This talk reflects 3-6 months of rolling out claude code enterprise to 200+ engineers securely, turning agentic roadkill into a product with AI-SDLC and how you can shine the light in the generative darkness. 

Often the discussions start with a solution seeking a problem. Ample opportunity to search for problems that kill the project. Who is this for? Why? How much will it cost? Saving $3000 a year on SAAS licence can often translate into $30000 engineering time and fines way above that when you vibe-exfiltrate your company&apos;s data.</abstract>
                <slug>bsides-joburg-2026-98701-turning-roadkill-into-braai-vibesdlc</slug>
                <track></track>
                
                <persons>
                    <person id='98185'>Christo Goosen</person>
                </persons>
                <language>en</language>
                <description>Remember that scene where Grommit lays out the track while the train is going down an unbuilt section in Wallace &amp; Grommit. Well thats what enterprise, AI coding agents and AI productivity tools rollouts are like in 2026. CTO says we need AI agents yesterday, MDM reports everyone has had it for a year anyway and your CISO says what are our controls.

This is the war stories of a SOC and DevSecOps team rolling out agentic controls as we figure things out. This is a pro-active vs reactive story of all the disucssions, policy work, controls and incident response over the period. 

The talk will cover the following topics:

- Rolling out claude code enterprise
- AI agent controls
- Sandboxing
- MDM and EDR
- OTEL for Agents
- Costs: economic, incident, cognitive load
- SDLC in the agentic era.
- When automation goes wrong.
- Security team leading the way with the torch of controls, education and setting the standard.
- Opportunities for security team to use the tools for creating tools, vuln discovery.
- Security validation testing on these controls

Takeaways:

- Agents, LLMs, etc pros and cons.
- Infosec, Dev, Devops, Infra, etc have always been early adopters. Better they debug tech than the general public debugs medical answers.
- SDLC is still relevant, might need tweaks
- Ownership is key, claude doesn&#8217;t own your code, your responsibility remains
- Trust but verify
- Sandboxing is back
- Enterprise is king ($$$$)
- Manage risk, enable efficiency
- Lead by example, get devs interested and involved.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/HWSVHB/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/HWSVHB/feedback/</feedback_url>
            </event>
            <event guid='14eb8546-d512-5b67-9bfc-d01334d97878' id='95657' code='QV988R'>
                <room>Track 2</room>
                <title>Illuminating the Underground : How Infostealers are Bypassing MFA</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-07-25T15:55:00+02:00</date>
                <start>15:55</start>
                <duration>00:15</duration>
                <abstract>Traditional security perimeters are failing because attackers are no longer hacking in, they are logging in. Stolen credentials are now the top initial access vector, involved in 88% of basic web application attacks

- As Infostealer Malware-as-a-Service operations industrialize, the dark web and illicit messaging apps are flooded with valid credentials and active session tokens
- This presentation &quot;lights the way&quot; by exposing the hidden mechanics of the modern stealer log ecosystem. We would explore how malware variants like RedLine and Vidar harvest session cookies to seamlessly bypass Multi-Factor Authentication (MFA), granting adversaries instant access to centralized environments like Microsoft Entra ID.
- Attendees will leave with a clear understanding of this unseen underground economy and practical strategies for Identity Exposure Management (IEM) to illuminate their blind spots, validate exposures, and neutralize threats before exploitation.</abstract>
                <slug>bsides-joburg-2026-95657-illuminating-the-underground-how-infostealers-are-bypassing-mfa</slug>
                <track></track>
                
                <persons>
                    <person id='95343'>Drystan Govender</person>
                </persons>
                <language>en</language>
                <description>This talk perfectly embodies the &quot;Light The Way&quot; theme by shining a spotlight on the hidden risks and emerging threats lurking in the darkest corners of the internet, specifically, dark web markets and the tens of thousands of illicit Telegram channels where cybercrime thrives

By exposing the mechanics of how attackers monetize infostealer infections to bypass modern defenses like MFA, this session shares critical knowledge that empowers the community. It guides defenders out of the dark, equipping them with the insights needed to illuminate their external attack surface and proactively protect their organizations against the unseen dangers of identity compromise.

**Topic Outline:**
- The Shift in the Threat Landscape: A data-driven look at how the barrier to entry for cybercrime has plummeted. We will review how malware-as-a-service operations distribute tools for as little as $200/month (R3500/Month), resulting in over 50 million breached identities traded weekly

- Anatomy of a Stealer Log: Illuminating what attackers actually see when a device is infected. We&apos;ll break down the contents of a stealer log, which includes saved passwords, browser autofill data, system fingerprints, and most critically, active session cookies

- The Death of Traditional MFA: A technical walkthrough of how active session cookies allow attackers to hijack authenticated sessions without needing a password or triggering an MFA prompt

- The Enterprise Impact: Analysis of recent 2025/2026 data revealing that over 1 in 10 infostealer infections now contain enterprise Single Sign-On (SSO) or Identity Provider (IdP) credentials, with Microsoft Entra ID appearing in 79% of enterprise identity logs

- We will discuss the trajectory that suggests 1 in 5 infections could yield enterprise credentials by Q3 2026

- Proactive Defense and Remediation: How to transition from reactive alert fatigue to proactive defense. We will discuss the principles of Identity Exposure Management (IEM), focusing on how to rapidly ingest intelligence, map the &quot;blast radius&quot; of an exposed user, and close the loop through automated validation and instant session revocation (Short 5 Min Max on how Flare Fits into this)

**Key Takeaways (What Attendees Will Learn):**

- The Cybercrime Supply Chain: How initial access brokers and automated Telegram bots distribute stolen credentials and stealer logs within hours of an infection

- The Mechanics of Session Hijacking: Why traditional perimeter defenses and MFA are insufficient against session cookie theft, and how attackers leverage this data for rapid account takeover

- Threat Forecasting: Real-world insights and statistical trends showing the rapid acceleration of enterprise identity compromise and the increasing targeting of centralized IdPs

- Practical Defense Strategies: Actionable frameworks for implementing continuous monitoring and automated remediation (such as forcing password resets or terminating active sessions) to shrink an attacker&apos;s window of opportunity from days to seconds</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/QV988R/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/QV988R/feedback/</feedback_url>
            </event>
            <event guid='ffe134a6-38e7-5345-bd17-ba83e5a305f6' id='98795' code='VJYQQB'>
                <room>Track 2</room>
                <title>Lighting the Way to the Server Room</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-07-25T16:10:00+02:00</date>
                <start>16:10</start>
                <duration>00:30</duration>
                <abstract>Physical penetration testing is often reduced to lockpicks, cloned badges, and dramatic stories of breaking into buildings. The reality is far less glamorous and far more interesting.

A successful physical penetration test begins long before anyone approaches a target facility. It starts with reconnaissance, understanding human behaviour, identifying operational weaknesses, navigating legal boundaries, and developing believable pretexts that exploit human trust rather than technology.</abstract>
                <slug>bsides-joburg-2026-98795-lighting-the-way-to-the-server-room</slug>
                <track></track>
                
                <persons>
                    <person id='98277'>Aaron Van Den Berg</person>
                </persons>
                <language>en</language>
                <description>Physical penetration testing is often portrayed as lockpicks, badge cloning, and dramatic break-ins. In reality, those activities represent only a small part of a successful engagement. The true challenge lies in understanding how physical security, human behaviour, operational processes, and technical controls intersect to either stop or enable an attacker.

This talk provides a practical walkthrough of a real-world physical penetration test from start to finish. Attendees will follow the complete engagement lifecycle: defining scope and legal boundaries, conducting reconnaissance, developing social engineering pretexts, gaining access to facilities, operating within a target environment, and ultimately reporting findings back to the client.

Drawing from real assessments and industry experience, the session focuses on the decision-making process behind physical testing rather than sensationalized lockpicking demonstrations. We will explore how attackers identify opportunities through open-source intelligence, exploit predictable human behaviours, leverage environmental weaknesses, and navigate physical spaces while balancing operational risk.

**Presentation Outline**:

**Introduction**

* What physical penetration testing actually is and why it remains one of the most effective methods of assessing organisational security.
* Common misconceptions surrounding physical security assessments.
* Understanding how physical, human, and digital security controls overlap.

**Scoping and Legalities**

* Defining rules of engagement, success criteria, and operational constraints.
* Authorisation requirements, legal considerations, and jurisdiction-specific concerns.
* Planning for contingencies, escalation paths, and engagement safety.

**Reconnaissance**

* How attackers and physical testers build target intelligence before arriving on site.
* Using publicly available information to identify entrances, staff routines, security technologies, and potential attack paths.
* Translating reconnaissance findings into actionable engagement plans.

**Breaching the Boundary**

* Common access vectors including tailgating, piggybacking, pretexting, and badge-related weaknesses.
* Understanding why social engineering remains one of the most effective physical attack techniques.
* How human psychology influences security outcomes.
* Building your own toolkit, (custom WIFI Pineapple, custom badge cloner, cheap gadgets to build a bigger toolkit) 

**Operating Once Inside**

* Prioritising objectives after gaining access.
* Identifying high-value targets such as boardrooms, network infrastructure, server rooms, and unattended workstations.
* Leveraging C2 frameworks and Internal Attacks (MITM, ADCS, LLMNR, PTK)
* Understanding the relationship between physical access and broader cyber compromise opportunities.

**Contingency and &#8220;What If You&apos;re Caught?&#8221;**

* Managing encounters with security personnel, facilities staff, or law enforcement.
* Documentation, communication procedures, and safe disengagement strategies.
* Lessons learned from real-world physical testing incidents.

**Reporting and Debrief**

* Converting observations into meaningful security findings.
* Demonstrating impact without creating unnecessary risk.
* Delivering remediation guidance that improves both physical and organisational security.

This talk combines practical field experience, social engineering concepts, and physical security assessment methodologies to provide attendees with a realistic understanding of how physical penetration tests are planned, executed, and reported.

**Key Takeaways**:

**Understanding Physical Attack Methodology**
Attendees will gain a clear understanding of how professional physical penetration tests are conducted from initial planning through final reporting.

**Recognising Security Weaknesses Beyond Technology**
The session demonstrates how human behaviour, organisational processes, and environmental design often create opportunities that technical controls alone cannot prevent.

**Improving Defensive Readiness**
Security practitioners, facilities teams, and business leaders will learn practical ways to identify and address weaknesses before they are discovered by real adversaries.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-joburg-2026/talk/VJYQQB/</url>
                <feedback_url>https://pretalx.com/bsides-joburg-2026/talk/VJYQQB/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
