BSides Toronto 2026

AbdulMoiz Lakdawala

I'm a principal consultant in the SOC advisory space, and I've spent the last 6-7 years building and running security operations

from second-line analyst work to architecting SOAR automation to leading SOC and detection engineering programs. I've stood up SOCs from scratch (triage workflows, escalation, the boring-but-critical plumbing), built and tuned detections against MITRE ATT&CK, and spent years automating the busywork analysts hate using Python, SOAR playbooks, and custom connectors.

That automation work is what pulled me into agentic AI — because once you've wired enough response pipelines by hand, you start asking which parts an LLM could actually own.

  • Agentic SOC, Demystified: From Buzzword to Working Pipeline
Ahmed Khan

Ahmed Khan is a cybersecurity researcher and developer focused on threat detection, command-line behavior analysis, and applied machine learning for security. He is the creator of Genos, an open-source command intelligence engine that classifies shell commands in real time and maps suspicious behavior to MITRE ATT&CK techniques.

Ahmed’s work combines security engineering, machine learning, and practical detection research. He has built systems for endpoint telemetry, Windows Event Log analysis, command-line classification, de-obfuscation, and ATT&CK technique mapping. He is also the first author of two accepted IEEE AIIoT 2026 papers covering command-line classification and an open-source endpoint detection and response prototype.

His current research interests include Linux threat research, behavioral detection, adversarial command analysis, endpoint security, and building practical tools that help defenders understand attacker behavior more clearly.

  • From Shell Commands to ATT&CK: Building Genos, an Open-Source Command Intelligence Engine
Aleksa Zatezalo

Aleksa is a passionate security engineer, software developer, and aspiring open sorcerer. He enjoys writing and publishing software that provides elegant solutions to offensive security problems. He has contributed to multiple projects, including Metasploit. In April of 2022, Aleksa graduated from the University of Toronto with a bachelor’s degree in computer science and a Certificate of Ethical Hacking (CEHv10). He began working as a Cloud Security consultant and hacker. He also began attending Defcon as an attendee and a volunteer for the Blue Team Village (BTV). One of Aleksa’s fondest cybersecurity memories is playing the Pros Versus Joes CTF during BSides Las Vegas. By April 2024, Aleksa had obtained his OSCP and begun working as a security engineer at Praetorian. He is currently pursuing his OSCE3. He enjoys Brazilian Jiu-Jitsu, running long distances, and reading in his free time. He currently holds a blue belt in Brazilian Jiu-Jitsu. The book Mastery by Robert Greene is a big inspiration for Aleksa.

  • From Schema to Shell: The Agentic Exploitation of GraphQL APIs
Amir H

Amir is an offensive security consultant based in Toronto. He spends most weeks either breaking a client's stack or finding new ways to break IoT hardware on his own time. This talk is the second kind.

Outside the day job he co-organizes DefCon Toronto (DC416) and sits on the organizing committee for TASK. Both keep him plugged into the local Toronto security community year round.

He speaks at conferences when he has something worth saying. This is one of those times.

  • I've Been Rolling Around Your House: Domestic Surveillance, $500
Andre Piazza

Andre Piazza is a cybersecurity strategist at BforeAI who works left of boom, catching adversary infrastructure during its staging window, before ransomware, account fraud, or brand and supplier impersonation reaches a target. He treats attacks as infrastructure and behavior rather than content, working from public signals like WHOIS, DNS, certificate transparency, and ASN data, and linking domains by registration velocity, shared certificate fingerprints, and hosting overlap to surface lookalike and impersonation infrastructure before it goes live. His work spans verification fraud, impersonation built with AI, scams that spin up around breaking news, and operational technology, and it gives as much weight to the human trust attackers exploit as to the technology. He turns published threat research into methods practitioners can use the next day, and he is a regular speaker at the SANS AI Cybersecurity Summit, BSides conferences including Seattle, Hou.Sec.Con, and Cybr.Hak.Con. He cares about building a more resilient community through collective defense.

  • Faster Than a Takedown: How Collective Internet Defense Disrupts Attacks at Scale
Anthony Navarro

Anthony Navarro is a Linux Systems Administrator with over 15 years of experience designing, securing, and operating Linux infrastructure. His work spans enterprise Linux administration, Kubernetes, automation, PKI, observability, and open source technologies, with a focus on building secure, resilient systems.

Outside of his day job, Anthony maintains an enterprise-style home lab where he explores Linux security, Kubernetes, AI, and modern infrastructure. He enjoys sharing practical, real-world techniques that attendees can immediately apply to their own environments, from home labs to production servers.

Anthony is an active member of the Linux community, regularly contributes to open source projects, and speaks at technology conferences on Linux, infrastructure, and emerging technologies. He believes security is most effective when it is practical, understandable, and built into everyday system administration.

  • Defending Linux Against Real Attackers
Drew Wade

Andrew Wade is a Principal Security Consultant with NCC Group, where he leads and delivers penetration testing and cloud security engagements across application, container, Kubernetes, and cloud environments. He also leads NCC Group’s Cloud Security Community of Practice and guides the global Cloud Security Practice, including service design, delivery standards, scoping improvements, and consultant enablement.

Andrew’s work sits at the intersection of hands-on technical testing, practice leadership, and client advisory. He focuses on helping organizations turn security testing into clearer risk understanding, better remediation decisions, and more mature security programs. Prior to cybersecurity consulting, Andrew worked in academic research and university teaching, bringing a background in anthropology, communication, and human behaviour that directly informs his perspective on why penetration testing succeeds or fails in practice.

  • What to Expect When You’re Expecting Pentesters
Emily Liu

Emily Liu is a Senior Security Consultant at NCC Group with five years working in offensive security, and 8 years working in tech overall. She leads and conducts penetration testing engagements against different types of enterprises with hands-on work experience spanning from application testing to cloud to network and to physical/social engineering engagements. Emily holds the OSCP and CRTO certifications and has previously published research such as Exploring the Security & Privacy of Canada’s Digital Proof of Vaccination Programs and Vulnerability Analysis of CVE-2026-21236.
In her spare time, she likes to volunteer and play video games.

  • From CVE to PoC: Dissecting a Windows AFD.sys Heap Overflow
Frankline Ombachi Ondieki

Frankline Ondieki Ombachi is an AI and Machine Learning Engineer from Nairobi, Kenya, and an incoming student in the Cyber Security Analytics programme at Mohawk College, Hamilton, Ontario. He has three years of production experience deploying machine learning systems at Absa Bank Kenya, Equity Bank Kenya, and the Commercial Bank of Ethiopia.
His research — "Poisoning the Compliance Mind: Adversarial Memory Injection Attacks on RAG-Based AML Agents" (SSRN 6734225) — formalises the first formal threat model for adversarial attacks on RAG-based AI agents in financial compliance and introduces the Memory Hygiene Layer as a practical defense framework. The paper is being submitted to ACM ICAIF 2026 in Milan.
Frankline was recognised as one of Africa's Top 100 Rising AI Developers (2025) by UNDP, the African Development Bank, Microsoft, and Meta.

  • Poisoning the Compliance Mind: How I Silently Collapsed an AI Anti-Money Laundering System with 50 Documents
George Bragg

George has worked in cybersecurity and related areas for 25 years. In addition to industry certifications such as CISSP, CISA, CEH, and SABSA SCF, he has a masters degree in cybersecurity from Western Governors University and is a doctoral candidate in cybersecurity at City University of Seattle, where he also works as adjunct faculty.

  • Throwing gasoline on the fire: The causes and impact of stress and burnout in cybersecurity
Jason Murray

With 27 years in information security, I've recognized the need for a transformative approach that goes beyond traditional compliance-focused methods. My philosophy centers on capability-driven strategies, quantitative risk management, and the integration of diverse management principles.

As a trusted security advisor to organizations across banking & finance, insurance, municipal government, healthcare, higher education, retail, service providers, and commercial sectors, I bring extensive technical knowledge of computing and networking systems in a wide range of scales from single desktops to cloud computing to corporate environments.

Key Aspects of My Approach:
• Advocating for capability-focused methodologies like C2M2 and CMMC
• Prioritizing quantitative risk management in security processes
• Integrating quality management, and agile approaches into information security

I believe effective information security extends beyond technology, encompassing:
• Capability-driven security policies
• Efficient processes aligned with organizational goals
• Flexible security controls adaptable to changing threats

I see the future of information security as:

  1. Shifting from compliance-centric to capability-driven security models
  2. Embracing quantitative risk management for informed decision-making
  3. Seamlessly integrating security capabilities into business processes
  4. Fostering a culture of continuous improvement in security practices
  • Strictly Business: Why Security Is Always a Risk Management Function
Justin Borland

A proven technical leader in the security industry, Justin started his career with a Canadian Secret clearance while still in College. After graduating, he spent the next decade building custom packet capture systems, intrusion detection systems, logging systems, and DFIR tooling for large organizations.
Justin established and ran the Countermeasures team at Equifax.  The team was responsible for building and maintaining the fleet of Moloch PCAP/IDS, IPS, and hundreds of other systems using petabytes of data.  His team was also responsible for discovering the 2017 data breach.  Justin was called into the Senate, while on paternity leave, in 2018.
At Barclays, Justin was part of the Global Hunt team and helped develop and mature many Threat Hunting capabilities and processes, especially related to malware analysis and DFIR.
Justin lead both the Threat Detection & Response and IT Ops functions at Unqork, a no-code/codeless-as-a-service company.
Currently, Justin is the Director of Threat Engineering at Abstract, and works with the Abstract Security Threat Research Organization (ASTRO) team to develop and implement threat detection content.
Despite always being a "Blue Teamer", Justin has documented CVEs in MISP and Qualys Cloud Agent, and actively contributes to open source technology, in addition to having open sourced a malware analysis platform (Phoenix).

  • The Malware is coming from inside the repo.
Moshe Siman Tov Bustan

Moshe is a Security Research Team Lead at OX Security, a company specializing in software supply chain security. His work spans cloud security research, container security, memory forensics, and an in-depth understanding of programming languages. He also has extensive experience in mobile security, including iOS and Android research, deep analysis of Android malware, sandboxing, and memory forensics.

Beyond security research, Moshe has published multiple "Can It Run Doom?" projects online, and is also a professional guitarist in a progressive metal band.


Nir is a rocket scientist who got a bit bored so he moved to cyber. Since then as a whitehat he has managed to break dozens of mobile, web, and desktop applications. These days Nir is focused on software supply chain research and innovative attack vector research via widely-used software projects. Nir holds a B.Sc degree in physics from Tel Aviv University. He enjoys sports and learning Spanish.

  • One IDE to Rule Them All - Securing Your Supply Chain’s Weakest Link
Najam Ul Saqib

With five years of experience in application and cloud security, I have honed my expertise at industry leaders like Systems Ltd, Tkxel, and Constellation Software. My professional journey is rooted in a deep technical understanding of securing complex ecosystems, further sharpened by a successful track record in independent bug bounty programs.

Currently, I am the founder of Exfiltra, a specialized consultancy firm dedicated to delivering high-quality application and cloud security services. While I provide comprehensive security solutions, my primary cloud focus is Azure, helping organizations navigate and fortify their Microsoft cloud environments.

Driven by a passion for the security community, I am a dedicated advocate for open-source intelligence and education. I actively contribute back by developing FOSS tools, authoring insightful blog posts, and producing educational videos. My mission is to bridge the gap between sophisticated threats and robust defense through both professional consultancy and community-driven knowledge sharing.

  • Breaking Modern Electron Apps: Exploitation Patterns & Defensive Lessons
Nirza
  • One IDE to Rule Them All - Securing Your Supply Chain’s Weakest Link
Swar Shah

Swar Shah is a Security Consultant and Penetration Tester with over five years of specialized experience in offensive security operations. Swar holds OSCP, OSWA and CRTP certifications and has developed expertise across multiple domains including web application security, mobile platforms (Android/iOS), cloud infrastructure (AWS/Azure/GCP), Active Directory environments, and emerging technologies such as AI/LLM systems.

Proficient in custom exploit development and multiple programming languages including Python, C, Java, JavaScript, and SQL, Swar specializes in vulnerability assessments, source code reviews, and red team operations. His work spans SAST/DAST methodologies, API security testing (REST/SOAP/GraphQL), and reverse engineering of thick client applications.

With deep knowledge of industry frameworks including OWASP Top 10, MITRE ATT&CK, NIST, and ISO 27001 standards, Swar has proven experience in bug bounty triage and communicating complex security findings to both C-level executives and technical development teams. In his free time, Swar enjoys participating in CTF competitions, contributing to open-source security tools, and researching novel exploitation techniques.

  • Breaking the AI Assembly Line: How Attackers Exploit LLM Supply Chains