BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-joburg-2026//speaker//KYKKQK
BEGIN:VTIMEZONE
TZID:Africa/Johannesburg
BEGIN:STANDARD
DTSTART:20250725T000000
TZNAME:SAST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Illuminating the Underground : How Infostealers are Bypassing MFA 
 - Drystan Govender
DTSTART;TZID=Africa/Johannesburg:20260725T155500
DTEND;TZID=Africa/Johannesburg:20260725T161000
DTSTAMP:20260726T033304Z
UID:pretalx-bsides-joburg-2026-QV988R@pretalx.com
DESCRIPTION:Traditional security perimeters are failing because attackers 
 are no longer hacking in\, they are logging in. Stolen credentials are now
  the top initial access vector\, involved in 88% of basic web application 
 attacks\n\n- As Infostealer Malware-as-a-Service operations industrialize\
 , the dark web and illicit messaging apps are flooded with valid credentia
 ls and active session tokens\n- This presentation "lights the way" by expo
 sing the hidden mechanics of the modern stealer log ecosystem. We would ex
 plore how malware variants like RedLine and Vidar harvest session cookies 
 to seamlessly bypass Multi-Factor Authentication (MFA)\, granting adversar
 ies instant access to centralized environments like Microsoft Entra ID.\n-
  Attendees will leave with a clear understanding of this unseen undergroun
 d economy and practical strategies for Identity Exposure Management (IEM) 
 to illuminate their blind spots\, validate exposures\, and neutralize thre
 ats before exploitation.
LOCATION:Track 2
URL:https://pretalx.com/bsides-joburg-2026/talk/QV988R/
END:VEVENT
END:VCALENDAR
