<?xml version='1.0' encoding='utf-8' ?>
<iCalendar xmlns:pentabarf='http://pentabarf.org' xmlns:xCal='urn:ietf:params:xml:ns:xcal'>
    <vcalendar>
        <version>2.0</version>
        <prodid>-//Pentabarf//Schedule//EN</prodid>
        <x-wr-caldesc></x-wr-caldesc>
        <x-wr-calname></x-wr-calname>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JCHBUP@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JCHBUP</pentabarf:event-slug>
            <pentabarf:title>Browser Exploitation: From N-Days to Real-World Exploit Chains in Google Chrome</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250618T140000</dtstart>
            <dtend>20250618T144500</dtend>
            <duration>004500</duration>
            <summary>Browser Exploitation: From N-Days to Real-World Exploit Chains in Google Chrome</summary>
            <description>What does it take to exploit a modern browser in 2025?

In this session, we&#8217;ll dissect the creation of a real-world exploit chain targeting Google Chrome on Windows, using recently patched (n-day) vulnerabilities. This is a practical, technical session, aimed at showing how modern browser exploitation is still very much alive &#8212; and achievable with the right tools and approach.

Key topics covered include:
- Fundamentals of modern browser security and vulnerability research
- Patch diffing to turn Chrome updates and public issues into vulnerabilities
- Mitigations and sandboxes bypass
- Exploit chain development: from initial bug to payload execution
- New methods and tools for Chrome exploit development
- Live demo of an exploit chain based upon recent vulnerabilities

The session also explores the current state of browser security and its implications for future offensive and defensive research.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Offensive Village talks</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/JCHBUP/</url>
            <location>Main Stage</location>
            
            <attendee>@Petitoto</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MNXYAU@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MNXYAU</pentabarf:event-slug>
            <pentabarf:title>Hacking EV Chargers: Fast Track to Market, Fast Track to Vulnerabilities</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250618T144500</dtstart>
            <dtend>20250618T152500</dtend>
            <duration>004000</duration>
            <summary>Hacking EV Chargers: Fast Track to Market, Fast Track to Vulnerabilities</summary>
            <description>We&#8217;ll dive deeper into the product, how it works under the hood, how it&#8217;s meant to be provisioned, and where things went hilariously wrong, allowing privilege escalation (extended, augmented version).

We&#8217;ll also step back and look at the bigger picture: why fast go-to-market pressures often lead to critical security oversights, and how these patterns show up across the EV charging ecosystem. Beyond the original device, I&#8217;ll share insights from examining other products, where the security posture is sometimes even worse. Expect fun discoveries, and some tales from the fast-moving world of connected devices.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Offensive Village talks</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/MNXYAU/</url>
            <location>Main Stage</location>
            
            <attendee>Simon Petitjean</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NESLTT@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-NESLTT</pentabarf:event-slug>
            <pentabarf:title>Targeting pentesters</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250618T154500</dtstart>
            <dtend>20250618T162500</dtend>
            <duration>004000</duration>
            <summary>Targeting pentesters</summary>
            <description>Pentesters and red teamers often focus on identifying weaknesses in others&#8217; systems &#8212; but what about their own practices? This talk aims to turn the lens inward and critically examine the techniques, tools, and habits commonly used by us, offensive security professionals. We&#8217;ll highlight some weaknesses that can make pentesters high-value, vulnerable targets.

The goal is to initiate a conversation around operational hygiene, threat modeling, and risk awareness within the offensive security community. By identifying bad habits and systemic gaps, we hope to inspire more resilient and secure practices among those who break things for a living.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Offensive Village talks</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/NESLTT/</url>
            <location>Main Stage</location>
            
            <attendee>Charlie Bromberg</attendee>
            
            <attendee>Mathieu Calemard du Gardin (Dramelac)</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>HETCHC@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-HETCHC</pentabarf:event-slug>
            <pentabarf:title>Unpacking Azure Initial Access Attack Techniques</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250618T162500</dtstart>
            <dtend>20250618T170500</dtend>
            <duration>004000</duration>
            <summary>Unpacking Azure Initial Access Attack Techniques</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Offensive Village talks</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/HETCHC/</url>
            <location>Main Stage</location>
            
            <attendee>Patrick Mkhael</attendee>
            
            <attendee>Fran&#231;ois-J&#233;r&#244;me Daniel</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>3MBNZC@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-3MBNZC</pentabarf:event-slug>
            <pentabarf:title>Lockpicking village</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250618T140000</dtstart>
            <dtend>20250619T170000</dtend>
            <duration>030000</duration>
            <summary>Lockpicking village</summary>
            <description>A lifelong passion for physical intrusion and social engineering fuels this hands-on workshop, where you&apos;ll discover both classic techniques like lockpicking, tailgating, and pole-based door opening and unconventional methods inspired by real-world experience. 
The goal: understand how intrusions really happen, and how to spot and prevent them before they do.
(The workshop will primarily be conducted in French, with the possibility to speak a little English to facilitate communication.)</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop 4h</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/3MBNZC/</url>
            <location>Atrium (common area)</location>
            
            <attendee>Nicolas Aunay (aka Joker2a)</attendee>
            
            <attendee>Nicolas B. (aka Warlok)</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GURPHA@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GURPHA</pentabarf:event-slug>
            <pentabarf:title>Cybersecurity in an Age of Uncertainty</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T090000</dtstart>
            <dtend>20250619T091000</dtend>
            <duration>001000</duration>
            <summary>Cybersecurity in an Age of Uncertainty</summary>
            <description>Opening address by Luxembourg&#8217;s new Ambassador for Cybersecurity and Digitalisation on security, resilience, and protecting human rights in an age of authoritarian repression and democratic backsliding.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Opening Speech</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/GURPHA/</url>
            <location>Main Stage</location>
            
            <attendee>Luc Dockendorf</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>CZHSL3@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-CZHSL3</pentabarf:event-slug>
            <pentabarf:title>Workshop introductions</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T091000</dtstart>
            <dtend>20250619T092000</dtend>
            <duration>001000</duration>
            <summary>Workshop introductions</summary>
            <description>1 minute per workshop organizer to introduce their workshops.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop intros</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/CZHSL3/</url>
            <location>Main Stage</location>
            
            <attendee>Various speakers with Infosec lightning talks</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>LDCKC8@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-LDCKC8</pentabarf:event-slug>
            <pentabarf:title>7 layers for improving your Quality of Life in Cyber Security</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T092000</dtstart>
            <dtend>20250619T100000</dtend>
            <duration>004000</duration>
            <summary>7 layers for improving your Quality of Life in Cyber Security</summary>
            <description>Same talk as in BsidesMunich Keynotes, but of course with some adjustments to adopt to BSides Luxembourg and I can add the references, that Carson Zimmermann and I use in the FIRST talk at the end. (I mapped out all of the science research to all of the topics).</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/LDCKC8/</url>
            <location>Main Stage</location>
            
            <attendee>Desiree Sacher-Boldewin</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7VZQY8@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-7VZQY8</pentabarf:event-slug>
            <pentabarf:title>Error 404: Experience Not Required (When You Have a Homelab)</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T103000</dtstart>
            <dtend>20250619T111500</dtend>
            <duration>004500</duration>
            <summary>Error 404: Experience Not Required (When You Have a Homelab)</summary>
            <description>What&apos;s the perfect home lab? It&apos;s the one that lands you your next job! Forget about turning your spare room into a data center &#8211; this talk is about building a smart, strategic homelab that advances your career and gets you noticed.
We&apos;re flipping the script on traditional homelab discussions. Instead of focusing on fancy hardware specs or power-hungry setups, we&apos;ll explore how to:

- Build a practical lab environment on a shoestring budget
- Transform weekend projects into impressive resume bullets
- Master key technologies employers actually care about (think virtualization, containers, security)
- Make learning technical skills genuinely fun and engaging

Think of this as your career-boosting homelab blueprint. We&apos;ll cover exactly how to document your projects, translate them into resume gold, and discuss them confidently in interviews. Plus, you&apos;ll learn why dancing flamingos might just be the secret sauce your homelab needs!
This isn&apos;t about hoarding hardware &#8211; it&apos;s about strategically building experience that sets you apart from other candidates. Come learn how to make your homelab work smarter, not hotter, for your career growth!

Key Takeaways:
- A framework for choosing projects that maximize your career impact
- Templates for translating technical projects into powerful resume bullets
- Strategies for discussing your homelab experience in interviews
- Budget-friendly approaches to building meaningful technical skills
- The secret to keeping learning fun and sustainable (yes, flamingos involved!)</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/7VZQY8/</url>
            <location>Main Stage</location>
            
            <attendee>Kat Fitzgerald</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JUFKPL@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JUFKPL</pentabarf:event-slug>
            <pentabarf:title>From Unrestricted Uploads to Security Nightmares: Preventing and Mitigating File Upload Vulnerabilities</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T111500</dtstart>
            <dtend>20250619T115500</dtend>
            <duration>004000</duration>
            <summary>From Unrestricted Uploads to Security Nightmares: Preventing and Mitigating File Upload Vulnerabilities</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/JUFKPL/</url>
            <location>Main Stage</location>
            
            <attendee>Sewar Khalifeh</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>8A7FZZ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-8A7FZZ</pentabarf:event-slug>
            <pentabarf:title>Fresh Secrets From The Docks: Lessons Learnt from Analyzing 15,000,000 Public DockerHub Images</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T133000</dtstart>
            <dtend>20250619T141500</dtend>
            <duration>004500</duration>
            <summary>Fresh Secrets From The Docks: Lessons Learnt from Analyzing 15,000,000 Public DockerHub Images</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/8A7FZZ/</url>
            <location>Main Stage</location>
            
            <attendee>Guillaume Valadon</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>JWWFQB@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-JWWFQB</pentabarf:event-slug>
            <pentabarf:title>SOC Must Die - Engineering our way to Detection and Response Operations</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T141500</dtstart>
            <dtend>20250619T145500</dtend>
            <duration>004000</duration>
            <summary>SOC Must Die - Engineering our way to Detection and Response Operations</summary>
            <description>What are we even doing with SOC ? We&apos;re still mostly dealing with false Positives, running outdated analyst tiers leading to burnouts, and SIEMs are still hard to tame monsters. And yet, we still don&apos;t really grasp our detection coverage, or are really efficient at adopting SOARs. But there&apos;s a new trend emerging, the Detection and Response Engineer.

SOCs worldwide are facing a hard transition - from an analyst organization, responding to events, to an engineering organization, proactively building systems with an emphasis on automation from the start. Detection Engineering is being increasingly adopted, and SOAR practices are being generalized to Response Engineering.

We will in this session peer into an engineering future for SOCs, where teams are smaller, more expert, tech-centric, and laser focused on key capabilities with less externalization of human effort.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/JWWFQB/</url>
            <location>Main Stage</location>
            
            <attendee>Amine Besson</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>9HGXTK@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-9HGXTK</pentabarf:event-slug>
            <pentabarf:title>Unpacking Packers - So What? Does it ever get easier? No.</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T151500</dtstart>
            <dtend>20250619T160000</dtend>
            <duration>004500</duration>
            <summary>Unpacking Packers - So What? Does it ever get easier? No.</summary>
            <description>Crypters, also known as loaders or packers, have long been a staple in the malware landscape, continually evolving to keep pace with advancements in cybersecurity defenses. These tools are no longer niche; they have become commodities widely available for purchase or lease on underground markets. As a result, they&#8217;ve commercialized sophisticated malware deployment, enabling a wider range of threat actors to access advanced techniques that once required specialized skill. A single loader can deliver varied malicious payloads across different campaigns, underscoring their adaptability and utility in modern cyberattacks.

Despite substantial focus on analyzing and documenting payloads, crypters themselves remain an often overlooked aspect of malware distribution. This talk explores the ever-evolving arms race between malware developers and security vendors. The cybersecurity community has developed robust solutions such as signature-based detection, AI-driven threat dissection, code-reuse analysis, and behavioral monitoring, yet crypters have continuously evolved to evade these defenses through sophisticated techniques like in-memory execution and anti-analysis features.

We will dissect the latest solutions in this ongoing battle, examine how they&#8217;ve been overcome by recent crypter innovations, and discuss what&#8217;s next in this relentless cycle of offense and defense. This session promises valuable insights for researchers, security professionals, and anyone interested in understanding and mitigating the threat of crypters in modern cyber warfare.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/9HGXTK/</url>
            <location>Main Stage</location>
            
            <attendee>Nicole Fishbein</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>RPGQ7B@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-RPGQ7B</pentabarf:event-slug>
            <pentabarf:title>Still living with ADHD in Infosec</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T160000</dtstart>
            <dtend>20250619T164500</dtend>
            <duration>004500</duration>
            <summary>Still living with ADHD in Infosec</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/RPGQ7B/</url>
            <location>Main Stage</location>
            
            <attendee>Klaus Agnoletti</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>EHAWQX@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-EHAWQX</pentabarf:event-slug>
            <pentabarf:title>When Data Talks, We Let AI Listen</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T170000</dtstart>
            <dtend>20250619T170500</dtend>
            <duration>000500</duration>
            <summary>When Data Talks, We Let AI Listen</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/EHAWQX/</url>
            <location>Main Stage</location>
            
            <attendee>L&#233;a ULUSAN</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>VNUTCG@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-VNUTCG</pentabarf:event-slug>
            <pentabarf:title>Kunai vs io_uring</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T170500</dtstart>
            <dtend>20250619T171000</dtend>
            <duration>000500</duration>
            <summary>Kunai vs io_uring</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/VNUTCG/</url>
            <location>Main Stage</location>
            
            <attendee>Quentin JEROME</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>MU8WHL@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-MU8WHL</pentabarf:event-slug>
            <pentabarf:title>Lightning talks - Infosec only</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T171000</dtstart>
            <dtend>20250619T172500</dtend>
            <duration>001500</duration>
            <summary>Lightning talks - Infosec only</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Infosec lightning talks</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/MU8WHL/</url>
            <location>Main Stage</location>
            
            <attendee>Various speakers with Infosec lightning talks</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>3UD8W3@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-3UD8W3</pentabarf:event-slug>
            <pentabarf:title>From Indicators to Insights: The Evolution and Future of Cyber Threat Intelligence</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T172500</dtstart>
            <dtend>20250619T173000</dtend>
            <duration>000500</duration>
            <summary>From Indicators to Insights: The Evolution and Future of Cyber Threat Intelligence</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/3UD8W3/</url>
            <location>Main Stage</location>
            
            <attendee>Nath, Adewole</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>GN9QK3@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-GN9QK3</pentabarf:event-slug>
            <pentabarf:title>DRINKS RECEPTION</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T173000</dtstart>
            <dtend>20250619T200000</dtend>
            <duration>023000</duration>
            <summary>DRINKS RECEPTION</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop 2h</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/GN9QK3/</url>
            <location>Main Stage</location>
            
            <attendee>Various speakers with Infosec lightning talks</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>FGFMAR@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-FGFMAR</pentabarf:event-slug>
            <pentabarf:title>Lightning talks - NO SECURITY TOPICS!</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T200000</dtstart>
            <dtend>20250619T203000</dtend>
            <duration>003000</duration>
            <summary>Lightning talks - NO SECURITY TOPICS!</summary>
            <description>Nothing about security.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Lightning talks NO SECURITY TOPICS</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/FGFMAR/</url>
            <location>Main Stage</location>
            
            <attendee>Various speakers with Infosec lightning talks</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7FDANC@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-7FDANC</pentabarf:event-slug>
            <pentabarf:title>Securing AI Assistants: Strategies and Practices for Protecting Data</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T103000</dtstart>
            <dtend>20250619T111500</dtend>
            <duration>004500</duration>
            <summary>Securing AI Assistants: Strategies and Practices for Protecting Data</summary>
            <description>In this technical session, we delve into the unique security challenges faced by AI copilots/chatbots/agents&#8212;AI systems designed to assist with various tasks&#8212;focusing specifically on data as their most critical asset. The talk will cover AI-specific threats such as data poisoning, prompt injection attacks/hallucinations, and data extraction risks, exploring how these vulnerabilities differ from traditional security concerns. We will discuss various AI deployment architectures and their impact on data security. Practical strategies will be provided to secure AI data, including hands-on techniques like automating data cleaning pipelines and configuring secure inference pipelines. The session will also introduce AI-specific threat modelling and explore real-world examples, demonstrating how to integrate security measures into AI development workflows. By the end, attendees will be equipped with actionable insights and tools to align their AI strategy with robust security practices, ensuring the safe and effective deployment of AI chatbots.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/7FDANC/</url>
            <location>Secondary stage</location>
            
            <attendee>Andra Lezza</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>3FK3MV@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-3FK3MV</pentabarf:event-slug>
            <pentabarf:title>Unifying Security Tools with OCSF and 60 lines of code</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T111500</dtstart>
            <dtend>20250619T115500</dtend>
            <duration>004000</duration>
            <summary>Unifying Security Tools with OCSF and 60 lines of code</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/3FK3MV/</url>
            <location>Secondary stage</location>
            
            <attendee>spyros gasteratos</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>DW3QWB@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-DW3QWB</pentabarf:event-slug>
            <pentabarf:title>The Firewall Project: Open Source, Shift-Left, Security Platform</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T133000</dtstart>
            <dtend>20250619T141500</dtend>
            <duration>004500</duration>
            <summary>The Firewall Project: Open Source, Shift-Left, Security Platform</summary>
            <description>The Current State of Cybersecurity
&gt; Increasing frequency and severity of security breaches.
&gt; Businesses struggle to keep up with evolving threats.
&gt; Many organizations can&apos;t afford advanced security solutions.
&gt; Security becoming a luxury rather than a necessity.

Security in the Age of AI: When Code Moves Faster Than Controls
&gt; While developers can now write code 10x faster using AI coding assistants like GitHub Copilot, security teams are struggling to keep pace.
&gt; Security teams are losing visibility into what&apos;s actually going into production, with each development decision potentially introducing unknown vulnerabilities or compliance risks.

Challenges in Remediation
&gt; Who is the owner of this asset in my organization&#8217;s SDLC?
&gt; Which teams should be involved? What are the best ways to collaborate with them?
&gt; Can I detect and remediate new issues across SDLC?
&gt; How do I manage the backlog of issues in my organization&#8217;s SDLC?

Introducing &#8220;The Firewall Project&#8217;s Appsec Platform&#8221;
&gt; Unconditional Visibility - Gain full visibility without bothering anyone
&gt; Risk Based Prioritisation - Use context to help devs understand the impact
&gt; Democratization for Developers/PMs - Empower devs to be proactive and take the ownership of their applications
&gt; Simplifying Remediation Process

Demo
&gt; Deployment - Docker Compose, CFT, Cloud Marketplaces
&gt; Configuration - VCs(Github/Bitbucket/Gitlab), Cloud(AWS/Azure/GCP) &amp; Alerts(Slack/Jira), RBAC
&gt; Asset Inventory - Repos, Web Application, Secrets, Vulnerabilities
&gt; Runtime Scans - PR and post-commit scans via webhooks

Incident Management

Live Dashboards

Automated Remediation Workflows
&gt; One-click allowlisting for false positive management.
&gt; Grouping of assets to establish ownership.
&gt; SLA and business context powered dynamic scoring for risk based prioritisation.

Real-World Use Cases
&gt; Git PAT Token Exposure: Imagine a scenario where a GitHub Personal Access Token (PAT) is accidentally stored in a private repository for a React.js project. Due to a misconfiguration, this token becomes accessible to the public via the client-side browser. With The Firewall Secrets, this kind of exposure can be detected early in the Software Development Life Cycle (SDLC), preventing potentially catastrophic breaches.
&gt; Vendor Compromise: Consider a case where a vendor, who has access to one of your private repositories, gets compromised. This breach could lead to the leaking of secrets and sensitive data. In such situations, a fast and efficient patch management system is crucial to identifying other services impacted by the breach. The Firewall Platform&apos;s incident tracker ensures that you&apos;re able to respond quickly and effectively to such incidents.
&gt; Insider Threats: In a recent incident at a prominent organization, the IT team discovered through logs that an employee, before leaving the company, downloaded a repository containing sensitive secrets. The immediate priority was to identify the compromised services and initiate a rapid incident response. With The Firewall Secrets and The Firewall Platform, you can identify exposure across your organization and take swift action to mitigate the risks.

Roadmap
&gt; Addition of AI powered DAST Capabilities
&gt; AI assistant
&gt; Container Images Scanning Capabilities

Contributors

Conclusion
&gt; Shifting left to prevent security issues early in development.
&gt; Operationalising security using risk based prioritization and comprehensive owner-to-asset mapping can significantly improve the efficiency of security teams 
&gt; We envision a world where every business, regardless of size or budget, has access to state-of-the-art cybersecurity. Where security isn&apos;t a luxury, but a fundamental right. Where we stand united against cyber threats, leaving no one behind.

Presentation for the talk:
&gt; https://docs.google.com/presentation/d/11nTQ9g1Xgm700dxAYqJEa6A8DsanA-qYScwc-aGDd_0/edit?usp=sharing 

Important Links:
&gt; Website: https://thefirewall.org
&gt; Blogs: https://blogs.thefirewall.org
&gt; Github: https://github.com/TheFirewall-code/TheFirewall-Secrets-SCA
&gt; Documentation: https://docs.thefirewall.org 
&gt; Youtube: https://www.youtube.com/@TheFirewallAppsecPlatform</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/DW3QWB/</url>
            <location>Secondary stage</location>
            
            <attendee>Sparsh K</attendee>
            
            <attendee>Lavlesh Joshi</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>3TUS97@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-3TUS97</pentabarf:event-slug>
            <pentabarf:title>DDoS Protection of the Europa websites</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T141500</dtstart>
            <dtend>20250619T145500</dtend>
            <duration>004000</duration>
            <summary>DDoS Protection of the Europa websites</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/3TUS97/</url>
            <location>Secondary stage</location>
            
            <attendee>Andrei Petrovici</attendee>
            
            <attendee>Florin Bota</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>BEZMZH@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-BEZMZH</pentabarf:event-slug>
            <pentabarf:title>Navigating the EU Cyber Resilience Act: Scope, Obligations, and Strategic Compliance for Digital Product Providers</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T151500</dtstart>
            <dtend>20250619T160000</dtend>
            <duration>004500</duration>
            <summary>Navigating the EU Cyber Resilience Act: Scope, Obligations, and Strategic Compliance for Digital Product Providers</summary>
            <description>This presentation will provide a comprehensive overview of the CRA&#8217;s scope, key obligations, and implications for companies across the digital product supply chain. 

Participants will gain practical insights into how to prepare for CRA compliance, including a five-step roadmap: from applicability assessment and product classification to gap analysis, action planning, and implementation. With significant penalties and market access restrictions for non-compliance, early preparation is essential. This session aims to equip stakeholders with the knowledge and strategies needed to ensure readiness and resilience in the face of evolving EU cybersecurity regulations.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/BEZMZH/</url>
            <location>Secondary stage</location>
            
            <attendee>BERDAI Sadia</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>N8GXFJ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-N8GXFJ</pentabarf:event-slug>
            <pentabarf:title>Coping with Reality: Chaos Engineering through Gamedays</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T160000</dtstart>
            <dtend>20250619T164500</dtend>
            <duration>004500</duration>
            <summary>Coping with Reality: Chaos Engineering through Gamedays</summary>
            <description>What if the best way to build resilient systems is to break them, intentionally? This 40-minute talk will challenge our conventional thinking about resilience by diving into the hands-on execution of Chaos Engineering through Gamedays, which are structured, high-impact events where teams deliberately inject failure to uncover weaknesses before they manifest in production and impact customers. Despite its playful name, a Gameday is anything but a game; it&#8217;s a methodical, collaborative, and sometimes nerve-wrecking exercise designed to stretch the limits of our systems and validate our assumptions.

We&#8217;ll explore what it takes to run an effective Gameday: from selecting the right applications and environments to defining steady states and executing controlled, high-value chaos experiments. Attendees will gain insight into how Datadog orchestrates Gamedays, curating participants based on system architecture, aligning on steady-state definitions, and incrementally scaling failure scenarios from isolated latency injections to full-scale zonal disruptions.

Gamedays are a shift in mindset, from preventing failure to preparing for it. We&#8217;ll also discuss a crucial evolution: transitioning from manual, ad-hoc failure injection to a scalable, automated platform that enables safe, rapid, and transparent execution. The ultimate goal? To shift the mindset from fearing failure to leveraging it as a catalyst for resilience. By embracing Chaos Engineering through Gamedays, teams don&#8217;t just prevent outages - they gain deep, actionable insights, foster cross-team collaboration, and build a culture where failure isn&#8217;t a setback, but a stepping stone to resilience.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/N8GXFJ/</url>
            <location>Secondary stage</location>
            
            <attendee>Tai Huynh</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>VHZNXC@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-VHZNXC</pentabarf:event-slug>
            <pentabarf:title>Let&apos;s play HackBack, a fun and engaging IR role playing game designed for learning</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T100000</dtstart>
            <dtend>20250619T120000</dtend>
            <duration>020000</duration>
            <summary>Let&apos;s play HackBack, a fun and engaging IR role playing game designed for learning</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop 2h</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/VHZNXC/</url>
            <location>Classroom 1 workshops</location>
            
            <attendee>Klaus Agnoletti</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>VS8LNA@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-VS8LNA</pentabarf:event-slug>
            <pentabarf:title>Automate Your Hacking: Writing New Tools &amp; Extending Existing Ones</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T130000</dtstart>
            <dtend>20250619T170000</dtend>
            <duration>040000</duration>
            <summary>Automate Your Hacking: Writing New Tools &amp; Extending Existing Ones</summary>
            <description>## Training Outline

### Tool &amp; Techniques for Security Automation
* Network Security
* Web Security Automation
* Malware Analysis Automation
* Automating Cloud Security Tasks
* Automating Security Tasks using Cloud
* Analyzing Custom Protocols &amp; Services
* Leveraging LLM and GenAI for Exploring the Unknown

### Writing Your Own Tools
* Developing the Automation Mindset
* Basics of Security Automation
* Mind Map for Writing Your Own Tools
* Writing Tools for Threat Intelligence

### Extending Existing Tools
* Writing Nmap NSE Scripts
* Writing Nuclei Templates
* Extending Burp/mitmproxy</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop 4h</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/VS8LNA/</url>
            <location>Classroom 1 workshops</location>
            
            <attendee>Rahul Binjve</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>EHSQ88@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-EHSQ88</pentabarf:event-slug>
            <pentabarf:title>Mapping Your Information System with Mercator: A Hands-On Workshop</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T100000</dtstart>
            <dtend>20250619T120000</dtend>
            <duration>020000</duration>
            <summary>Mapping Your Information System with Mercator: A Hands-On Workshop</summary>
            <description>Discover how [Mercator](https://github.com/dbarzin/mercator), the award-winning open source tool for information system mapping, can transform your approach to managing infrastructures and data. In this 2-hour workshop, you will learn to use Mercator to model, visualize, and analyze your IT ecosystem efficiently. Whether you are a CISO, system administrator, or security consultant, this hands-on session will guide you through Mercator&#8217;s key features&#8212;from creating your first map to integrating advanced data.

Join us for an interactive session combining theory and practice. You&#8217;ll have the opportunity to explore real-world use cases, work directly with the tool, and leave with skills you can apply immediately to your professional projects. No prior knowledge of Mercator is required, but please bring your laptop to make the most of this experience!</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop 2h</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/EHSQ88/</url>
            <location>Classroom 2 workshops</location>
            
            <attendee>Didier Barzin</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>TAXNZH@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-TAXNZH</pentabarf:event-slug>
            <pentabarf:title>API Underworld: Red Team Hacking Secrets</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T130000</dtstart>
            <dtend>20250619T170000</dtend>
            <duration>040000</duration>
            <summary>API Underworld: Red Team Hacking Secrets</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop 4h</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/TAXNZH/</url>
            <location>Classroom 2 workshops</location>
            
            <attendee>Parth Shukla</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>HVC8NP@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-HVC8NP</pentabarf:event-slug>
            <pentabarf:title>Fortifying Cyber Defenses: A hands-on workshop with IDPS-ESCAPE and SATRAP</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T100000</dtstart>
            <dtend>20250619T120000</dtend>
            <duration>020000</duration>
            <summary>Fortifying Cyber Defenses: A hands-on workshop with IDPS-ESCAPE and SATRAP</summary>
            <description>**Duration**: 2 hours  
**Level**: Intermediate (familiarity with concepts in basic machine learning, SIEM/IDPS and CTI recommended)

## Workshop outline

### I. Introduction to IDPS-ESCAPE

- Presentation of the IDPS-ESCAPE architecture and its building blocks: open-source SOAR, ADBox, Wazuh-Suricata integration, and anomaly detection training and prediction pipelines 
- Use cases: user and entity behavior analytics (UEBA), automated response/prevention based on detected anomalies
- **Demonstration: Deploying ADBox for Multivariate Anomaly Detection**

  1. Configure ADBox to ingest Wazuh alerts and resource metrics
  2. Train a custom MTAD-GAT model and monitor to detect suspicious behavior (UEBA)
  3. Visualize anomalies in Wazuh Dashboards
  4. Overview of IDPS-ESCAPE integrations: Wazuh, Suricata, MISP, OpenCTI, OpenBAS
  5. Overview of implemented UEBA and AD scenarios, along with implemented active responses

### II. Introduction to SATRAP

- Overview of SATRAP and its application in cyber threat intelligence, plus an explanation of logic-based automated reasoning and its benefits
- **Hands-On Lab: CTI analysis with SATRAP**

  1. Setting up SATRAP in a controlled environment
  2. Creating and populating a CTI knowledge base
  3. Developing a playbook in the form of a Jupyter Notebook to demonstrate how we can benefit from the automated reasoning functions of the SATRAP Python CTI Analysis Toolbox in a step-by-step CTI investigation

### III. Integration and best practices

- Strategies for integrating IDPS-ESCAPE and SATRAP with existing security systems
- Best practices for maintaining and updating these tools
- Q&amp;A session to address participant queries and challenges

### **Target Audience**

- SOC analysts and CTI teams seeking to enhance detection, investigation and mitigation capabilities
- Security engineers interested in SOAR systems and open-source tools
- Researchers exploring practical applications of anomaly detection and automated reasoning
- Curious learners

### **Requirements**

- A basic understanding of cybersecurity concepts and familiarity with security tools
- Laptop with Docker and preferably VS Code installed
- Basic Python and GNU/Linux experience (no advanced ML expertise required)</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop 2h</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/HVC8NP/</url>
            <location>Classroom 3 workshops</location>
            
            <attendee>Arash Atashpendar</attendee>
            
            <attendee>Itzel Vazquez Sandoval</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>ZS73U7@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-ZS73U7</pentabarf:event-slug>
            <pentabarf:title>Becoming the Godfather of Threat Modeling</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T130000</dtstart>
            <dtend>20250619T150000</dtend>
            <duration>020000</duration>
            <summary>Becoming the Godfather of Threat Modeling</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop 2h</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/ZS73U7/</url>
            <location>Classroom 3 workshops</location>
            
            <attendee>Mike van der Bijl</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>RK8JDA@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-RK8JDA</pentabarf:event-slug>
            <pentabarf:title>Practical intro to deep learning: chihuahuas vs muffins</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T151000</dtstart>
            <dtend>20250619T170000</dtend>
            <duration>015000</duration>
            <summary>Practical intro to deep learning: chihuahuas vs muffins</summary>
            <description>Agenda:

&#8226; Short introduction to deep learning

&#8226; Setting up the environment

&#8226; Hands-on session: we&#8217;ll experiment with image classification

&#8226; Hands-on session: we build a web app with Gradio

We&#8217;ll also be discussing applications to cybersecurity you can prototype, deep learning and training methods, cool the hype and discuss realistic LLM capacities.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop 2h</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/RK8JDA/</url>
            <location>Classroom 3 workshops</location>
            
            <attendee>Pauline Bourmeau (Cookie)</attendee>
            
            <attendee>William Robinet</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>KHJVRN@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-KHJVRN</pentabarf:event-slug>
            <pentabarf:title>Opening of CLUSIL track</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T103000</dtstart>
            <dtend>20250619T104500</dtend>
            <duration>001500</duration>
            <summary>Opening of CLUSIL track</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Opening Speech</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/KHJVRN/</url>
            <location>Classroom 4 - CLUSIL track</location>
            
            <attendee>Luc Dockendorf</attendee>
            
            <attendee>Cedric MAUNY</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>FVYWMW@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-FVYWMW</pentabarf:event-slug>
            <pentabarf:title>The Psychology of Deception: How Today&apos;s World Leaves Us Exposed to Social Engineering</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T104500</dtstart>
            <dtend>20250619T112000</dtend>
            <duration>003500</duration>
            <summary>The Psychology of Deception: How Today&apos;s World Leaves Us Exposed to Social Engineering</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/FVYWMW/</url>
            <location>Classroom 4 - CLUSIL track</location>
            
            <attendee>Elo&#239;se ZEHNDER</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>Y3L9MQ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-Y3L9MQ</pentabarf:event-slug>
            <pentabarf:title>Maximizing AI Innovation While Staying Compliant: A Pragmatic Approach</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T112000</dtstart>
            <dtend>20250619T120000</dtend>
            <duration>004000</duration>
            <summary>Maximizing AI Innovation While Staying Compliant: A Pragmatic Approach</summary>
            <description>In this talk, we will explore key elements for successfully and securely integrating AI in businesses:

Understanding the AI Act and its implications for organizations
The intersection of AI and data protection (GDPR, DPIA, etc.)
Implementing an effective AI governance strategy
Case studies and common pitfalls to avoid
Real-world strategies that actually work
This session is designed for decision-makers, DPOs, CISOs, and digital transformation leaders looking to leverage AI without exposing their organizations to legal risks or compliance failures.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/Y3L9MQ/</url>
            <location>Classroom 4 - CLUSIL track</location>
            
            <attendee>Julien Winkin</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>VYZDUA@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-VYZDUA</pentabarf:event-slug>
            <pentabarf:title>Beyond the Buzzwords: Threat Exposure and Attack Surface Management in 2025</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T133000</dtstart>
            <dtend>20250619T141500</dtend>
            <duration>004500</duration>
            <summary>Beyond the Buzzwords: Threat Exposure and Attack Surface Management in 2025</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/VYZDUA/</url>
            <location>Classroom 4 - CLUSIL track</location>
            
            <attendee>Peder Grundvold</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NFHVDZ@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-NFHVDZ</pentabarf:event-slug>
            <pentabarf:title>From Legalese to Human-Ease: Transforming Security Policies with AI</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T141500</dtstart>
            <dtend>20250619T145500</dtend>
            <duration>004000</duration>
            <summary>From Legalese to Human-Ease: Transforming Security Policies with AI</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/NFHVDZ/</url>
            <location>Classroom 4 - CLUSIL track</location>
            
            <attendee>Klaus Agnoletti</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>VGMSMG@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-VGMSMG</pentabarf:event-slug>
            <pentabarf:title>From Buzzword to Battlefield: The Cybersecurity Challenges of Smart Cities</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T151500</dtstart>
            <dtend>20250619T160000</dtend>
            <duration>004500</duration>
            <summary>From Buzzword to Battlefield: The Cybersecurity Challenges of Smart Cities</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/VGMSMG/</url>
            <location>Classroom 4 - CLUSIL track</location>
            
            <attendee>Marina Bochenkova</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>UNYABC@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-UNYABC</pentabarf:event-slug>
            <pentabarf:title>Remove Barriers To Data Sharing To Boost Collaboration Against Cybercrime</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T160000</dtstart>
            <dtend>20250619T162500</dtend>
            <duration>002500</duration>
            <summary>Remove Barriers To Data Sharing To Boost Collaboration Against Cybercrime</summary>
            <description>Data sharing is notably the most efficient manner to fight cybercrime as it enhances the capabilities of collaborating by sharing Tactics, Techniques, and Procedure used by attackers. However, good practices are often challenging to implement due to hurdles like 1) compliance and regulatory constraints, 2) time constraints for sharing and processing shared information, and 3) perceived lack of value in the information. These barriers hinder the dissemination of crucial information that could improve attack detection and response.

This session will address each of these obstacles by identifying strategies for mutualizing data without revealing the data itself. To do this, I will explain how to remove barriers limiting information sharing by leveraging the data mesh&#8212;where the interpretation, rather than the raw data, is shared&#8212;and by using advanced technical solutions such as Federated Learning&#8212; where only the AI model&apos;s parameters are shared instead of the training data&#8212;and Fully Homomorphic Encryption&#8212;which allows operations on encrypted data without revealing the data itself&#8212;. These technologies used within a specific ecosystem will both help bypass regulatory hurdles while strongly elevating the value of data and the competitive advantage against cybercrime by dismantling existing barriers that prevent sharing. 

Attendees will be informed how this approach contributes to the compliance with regulatory frameworks like NIS2 and DORA applicable to any corporation doing business with European customers also to gain insights from the success of Luxembourg&apos;s first ISAC for the manufacturing industries. The session will also review Luxembourg&apos;s National Cybersecurity Strategy, which aims to enhance cybersecurity capabilities by implementing a national network of probes and by introducing sectoral Security Operations Centers. The latter to fortify national defenses against organized attacks targeting economic sectors, critical infrastructures and the society at large.

Attendees will leave this session with a comprehensive understanding of how some advanced technologies can remove barriers to increase the volume and type of shared information while ensuring compliance with regulatory standards that leads to a more secure global community. My goal is to sensitize the audience on how to reduce the usual reluctance when it comes to information sharing by demonstrating how to use processes and technologies at community scale to protect the society at large.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/UNYABC/</url>
            <location>Classroom 4 - CLUSIL track</location>
            
            <attendee>Cedric MAUNY</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>J7Q87U@@pretalx.com</uid>
            <pentabarf:event-id></pentabarf:event-id>
            <pentabarf:event-slug>-J7Q87U</pentabarf:event-slug>
            <pentabarf:title>AI in cybercrime: A threat or an opportunity?</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20250619T162500</dtstart>
            <dtend>20250619T165500</dtend>
            <duration>003000</duration>
            <summary>AI in cybercrime: A threat or an opportunity?</summary>
            <description>The rise of generative AI, based primarily on neural networks, has completely boosted the hype surrounding AI, which has become indispensable in today&apos;s digital landscape.
In the field of cybersecurity, it is possible to ask how AI can be used by hackers but also serve as a defence mechanism.

This is a game that hackers currently tend to win because they have a head start, but in the future, will we see AI challenged by other AI in terms of attacks and countermeasures?

This raises many questions, both in terms of ethics or the lack thereof within AI, as well as the limits of circumventing the ethical filter applied to AI, but also the ability of hackers to use specialised and proprietary AI.

There will also remain the question of the energy required to power these AI systems. Will it be accessible to all, including hackers?</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://pretalx.com/bsidesluxembourg-2025/talk/J7Q87U/</url>
            <location>Classroom 4 - CLUSIL track</location>
            
            <attendee>David Hagen</attendee>
            
        </vevent>
        
    </vcalendar>
</iCalendar>
