BSidesLuxembourg
We are back in 2026!! May 6-8th in Belval
Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter
Tickets are available here -> https://pretix.eu/BSidesLux/2026/
Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/
Website -> https://2026.bsides.lu
Posts
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
“XCTDH Cross-Chain Transaction Data Hiding: Cyber Espionage and OPSEC Encounters” – Ellis Stannard
Talk (40 minutes)
Uncover a cutting-edge 40-minute talk revealing how attackers are leveraging blockchain ecosystems to build resilient and stealthy command-and-control infrastructure. This session introduces Cross-Chain Transaction Data Hiding (XCTDH), a novel technique that uses multiple blockchains to store and deliver malicious payloads—blending seamlessly with legitimate cryptocurrency activity and making detection extremely challenging.
Through a real-world investigation, the talk walks through the full attack chain—from social engineering and weaponized repositories to multi-stage payload delivery and evasion of modern defenses. Attendees will gain insight into how low-cost, decentralized infrastructure is reshaping cyber espionage, along with the broader implications for detection, attribution, and defensive strategy.
Ellis Stannard is a security researcher and core member of the Ransom-ISAC initiative, contributing to collaborative threat intelligence efforts focused on ransomware and advanced persistent threat campaigns.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
📲 Want to navigate the event easily? Check out the full schedule on Hacker Tracker:
https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #CyberSecurity #ThreatIntelligence #BlockchainSecurity #APT #Malware
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🌐📡 𝗧𝗛𝗘 𝗙𝗢𝗥𝗚𝗢𝗧𝗧𝗘𝗡 𝗙𝗜𝗡𝗚𝗘𝗥𝗣𝗥𝗜𝗡𝗧: 𝗗𝗡𝗦 𝗕𝗔𝗦𝗘𝗗 𝗢𝗦𝗜𝗡𝗧 𝗧𝗘𝗖𝗛𝗡𝗜𝗤𝗨𝗘𝗦 𝗙𝗢𝗥 𝗣𝗥𝗢𝗗𝗨𝗖𝗧 & 𝗦𝗘𝗥𝗩𝗜𝗖𝗘 𝗗𝗜𝗦𝗖𝗢𝗩𝗘𝗥𝗬 – Rishi ( @rxerium )
⚡ Reveal hidden infrastructure in a Talk (40 min) using DNS TXT records to map technologies, dependencies, and external services at scale.
DNS is often treated as infrastructure plumbing, but TXT records quietly expose far more than most defenders realize. This session introduces a DNS-based OSINT methodology that leverages large-scale TXT record analysis to uncover embedded service dependencies such as cloud platforms, SaaS integrations, and identity providers.
By programmatically scanning DNS zones and integrating the technique into tools like Nuclei and OWASP Amass, this approach enables security teams to build detailed maps of organizational technology stacks and attack surfaces. A real-world case study from the Salesloft breach demonstrates how these signals translate into actionable intelligence for both offensive and defensive use cases.
Rishi ( @rxerium ) is a London-based security researcher focused on vulnerability research, threat intelligence, and OSINT-driven attack surface discovery. He contributes to open-source security tooling, supports the UK OSINT community, and focuses on building scalable reconnaissance and detection methodologies.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
📲 View full schedule & build your agenda: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #OSINT #DNS #AttackSurface #ThreatIntelligence #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
Over the last months, we've had an awesome team of volunteers building CTF challenges for you on the theme: 𝗦𝗣𝗔𝗖𝗘!
We're excited to announce that BSides Luxembourg 2026 will feature a Capture The Flag competition open to all 𝗢𝗡-𝗦𝗜𝗧𝗘 𝗔𝗧𝗧𝗘𝗡𝗗𝗘𝗘𝗦 — running across all three days of the event (May 6–8, Luxembourg). 𝗧𝗛𝗘 𝗖𝗧𝗙 𝗪𝗜𝗟𝗟 𝗢𝗣𝗘𝗡 𝗔𝗧 𝟭𝟬:𝟬𝟬 𝗪𝗘𝗗𝗡𝗘𝗦𝗗𝗔𝗬 𝗠𝗔𝗬 𝟲𝗧𝗛 𝗔𝗡𝗗 𝗖𝗟𝗢𝗦𝗘𝗦 𝗔𝗧 𝗠𝗔𝗬 𝟴𝗧𝗛 𝟭𝟯:𝟰𝟬 𝗙𝗢𝗟𝗟𝗢𝗪𝗘𝗗 𝗕𝗬 𝗔 𝗪𝗔𝗟𝗞𝗧𝗛𝗥𝗢𝗨𝗚𝗛 𝗦𝗘𝗦𝗦𝗜𝗢𝗡 𝗔𝗧 𝟭𝟰:𝟬𝟬 .
This year's CTF takes you on a space exploration mission. Navigate a galaxy of challenges spanning web, reverse engineering, forensics, OSINT, privilege escalation, and more — with difficulty levels for all skill sets.
And our awesome sponsors have provided some incentives! 𝗧𝗛𝗘𝗥𝗘 𝗔𝗥𝗘 𝗣𝗥𝗜𝗭𝗘𝗦!
In these days and times, it would make no sense to forbid you to use AIs to do the CTF, but we urge everyone to realise that if you depend on LLMs exclusively to solve challenges, this actively does not only not teach you anything, it reduces your own ability to solve challenges (scientifically proven that LLM dependence reduces ability in other fields).
A huge shoutout to 𝗟𝗘𝗧𝗭𝗣𝗪𝗡 𝗔𝗦𝗕𝗟 ( @letzpwn ) for providing the platform and infrastructure to run this CTF competition.
Prizes up for grabs:
1st: 𝗧𝗛𝗘 𝗙𝗜𝗥𝗦𝗧 𝗣𝗟𝗔𝗖𝗘 person/team gets 1 voucher for: SOC-200 OSDA (Offensive Security & Defense Analyst) provided by the Redbluealliance.com
– sponsored by SecuInfra.com ! (@SI_FalconTeam )
(𝐈𝐍-𝐏𝐄𝐑𝐒𝐎𝐍 𝐓𝐑𝐀𝐈𝐍𝐈𝐍𝐆 𝐈𝐍 𝐆𝐄𝐑𝐌𝐀𝐍𝐘)
𝟮𝗡𝗗: Linux Attack, Detection and Forensics v2.0 - Hands-on Purple Teaming Playbook provided and sponsored by Defensive-security.com!(@cr0nym )
(𝐁𝐎𝐎𝐊 + 𝐎𝐍𝐋𝐈𝐍𝐄 𝐓𝐑𝐀𝐈𝐍𝐈𝐍𝐆 𝐂𝐎𝐔𝐑𝐒𝐄)
𝟯𝗥𝗗: Linux Attack, Detection and Forensics v2.0 - Hands-on Purple Teaming Playbook provided and sponsored by Defensive-security.com! (Defensive Security)
(𝐁𝐎𝐎𝐊 + 𝐎𝐍𝐋𝐈𝐍𝐄 𝐓𝐑𝐀𝐈𝐍𝐈𝐍𝐆 𝐂𝐎𝐔𝐑𝐒𝐄)
(@cr0nym )
𝟰𝗧𝗛: Linux Attack, Detection and Forensics v2.0 - Hands-on Purple Teaming Playbook provided and sponsored by Defensive-security.com! (@cr0nym )
(𝐁𝐎𝐎𝐊 + 𝐎𝐍𝐋𝐈𝐍𝐄 𝐓𝐑𝐀𝐈𝐍𝐈𝐍𝐆 𝐂𝐎𝐔𝐑𝐒𝐄)
Positions in CTF are determined by points, if points are equal, who reached the amount of points first.
This CTF is also supported by the 𝗖𝗬𝗕𝗘𝗥𝗘𝗗𝗨𝟰𝗧𝗘𝗘𝗡𝗦 initiative from SnT, Interdisciplinary Centre for Security, Reliability and Trust, University of Luxembourg — a Google.org-funded project working to bring cybersecurity education to the next generation.
A huge thank you to Nastassia Salash from SnT for making this support
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🧪📂 𝗪𝗛𝗘𝗡 𝗙𝗜𝗟𝗘𝗡𝗔𝗠𝗘𝗦 𝗕𝗘𝗖𝗢𝗠𝗘 𝗔𝗧𝗧𝗔𝗖𝗞 𝗦𝗨𝗥𝗙𝗔𝗖𝗘𝗦: 𝗪𝗘𝗔𝗣𝗢𝗡𝗜𝗭𝗜𝗡𝗚 𝗡𝗔𝗦𝗔’𝗦 𝗖𝗙𝗜𝗧𝗦𝗜𝗢 𝗘𝗫𝗧𝗘𝗡𝗗𝗘𝗗 𝗙𝗜𝗟𝗘𝗡𝗔𝗠𝗘 𝗦𝗬𝗡𝗧𝗔𝗫 – Adrian Denkiewicz ( @Adenkiewicz )
🧨 Turn filenames into attack vectors in this Talk (40 min) by uncovering how hidden parsing features can enable SSRF, file access, and data exposure.
What looks like a simple filename can actually be a powerful mini-language. This talk dives into CFITSIO’s Extended Filename Syntax (EFS), a feature widely embedded in scientific and imaging software, and shows how it silently expands the attack surface through built-in capabilities like virtual file handling, filtering, and network access.
Through original research, discover how these legitimate features can be abused to perform arbitrary file operations, trigger SSRF, and expose sensitive data—all without exploiting traditional memory corruption bugs. This session highlights how overlooked functionality in widely used libraries can introduce systemic risks across the software supply chain.
Adrian Denkiewicz ( @Adenkiewicz ) is an Offensive Security Expert and security consultant with experience spanning financial, e-commerce, and semiconductor industries. Currently a Staff Application Engineer at Doyensec, he specializes in application security, red teaming, and uncovering complex vulnerabilities in real-world systems.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
📲 View full schedule & build your agenda: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #AppSec #SecureDevelopment #SSRF #SoftwareSecurity #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🎉🔓 𝗠𝗔𝗡𝗔𝗚𝗜𝗡𝗚 𝗨𝗡𝗜𝗡𝗩𝗜𝗧𝗘𝗗 𝗚𝗨𝗘𝗦𝗧𝗦: 𝗦𝗘𝗖𝗨𝗥𝗜𝗡𝗚 𝗢𝗣𝗘𝗡 𝗦𝗢𝗨𝗥𝗖𝗘 𝗗𝗘𝗣𝗘𝗡𝗗𝗘𝗡𝗖𝗜𝗘𝗦 – Frithjof Hoffmann
Open source fuels innovation, but it also introduces risk through deeply nested dependencies that often go unchecked. This session explores how a single vulnerable or malicious package buried in your dependency tree can become an entry point for attackers—without you ever knowing it exists.
From typosquatting to compromised maintainers and abandoned libraries with known CVEs, discover how real-world supply chain attacks unfold and why traditional security approaches fall short. Walk away with practical strategies to identify, monitor, and secure your dependencies before they become a breach waiting to happen.
The speaker is a cybersecurity professional and technical sales engineer specializing in software supply-chain security, threat intelligence, and risk management. Working across Europe, they focus on helping organizations strengthen visibility and resilience through SBOM management, malware analysis, and secure software practices.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: [https://lnkd.in/dEk23cW6)
📅 Schedule Link: [https://lnkd.in/dhebCA7Y)
📲 View full schedule & build your agenda: [https://lnkd.in/dJ7ikF_i)
hashtag#BSidesLuxembourg2026 hashtag#AppSec hashtag#SupplyChainSecurity hashtag#OpenSourceSecurity hashtag#SBOM hashtag#CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🕸️💥 𝗪𝗛𝗔𝗧’𝗦 𝗢𝗟𝗗 𝗜𝗦 𝗡𝗘𝗪: 𝗘𝗫𝗣𝗟𝗢𝗜𝗧𝗜𝗡𝗚 𝗖𝗟𝗔𝗦𝗦𝗜𝗖 𝗩𝗨𝗟𝗡𝗘𝗥𝗔𝗕𝗜𝗟𝗜𝗘𝗦 𝗜𝗡 𝗚𝗥𝗔𝗣𝗛𝗤𝗟 𝗔𝗣𝗜𝗦 – Aleksa Zatezalo
Modern tech doesn’t mean modern security. This session walks through a real-world penetration test where a production GraphQL API backed by PostgreSQL was compromised using classic attack techniques—from schema enumeration to identifying vulnerable resolvers and injection points.
Follow the full exploitation chain from blind SQL injection to database superuser access, and uncover how broken authentication logic in GraphQL can expose sensitive data. With a live demo of GrapeQL, attendees will gain practical testing workflows and defensive strategies to properly secure GraphQL APIs.
Aleksa Zatezalo is a security engineer and offensive security researcher with experience in cloud security, penetration testing, and exploit development. A contributor to projects like Metasploit and an active member of the security community, he focuses on building practical tools and techniques to uncover and fix real-world vulnerabilities.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: [https://2026.bsides.lu/tickets/](https://2026.bsides.lu/tickets/)
📅 Schedule Link: [https://pretalx.com/bsidesluxembourg-2026/schedule/](https://pretalx.com/bsidesluxembourg-2026/schedule/)
📲 View full schedule & build your agenda: [https://hackertracker.app/schedule?conf=BSIDESLUX2026](https://hackertracker.app/schedule?conf=BSIDESLUX2026)
#BSidesLuxembourg2026 #GraphQL #AppSec #WebSecurity #SQLInjection #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🚗🔐 𝗙𝗥𝗢𝗠 𝗖𝗔𝗡 𝗙𝗥𝗔𝗠𝗘𝗦 𝗧𝗢 𝗖𝗢𝗥𝗣𝗢𝗥𝗔𝗧𝗘 𝗙𝗜𝗥𝗘𝗪𝗔𝗟𝗟𝗦: 𝗟𝗜𝗙𝗘 𝗢𝗙 𝗔𝗡 𝗔𝗨𝗧𝗢𝗠𝗢𝗧𝗜𝗩𝗘 𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 𝗥𝗘𝗦𝗘𝗔𝗥𝗖𝗛𝗘𝗥 – Hrishikesh Somchatwar
Step inside the world of automotive cybersecurity in this 40-minute talk, where modern vehicles become complex attack surfaces spanning hardware, firmware, and cloud systems. From CAN bus manipulation to telematics abuse and backend exploitation, discover how real-world constraints shape both attacks and defenses in connected vehicle ecosystems.
Learn how attackers exploit in-vehicle networks, diagnostic interfaces, and wireless modules, and why securing cars is fundamentally different from traditional IT. Through practical case studies, this session highlights how even small vulnerabilities can lead to large-scale operational and financial impact in automotive environments.
Hrishikesh Somchatwar (@storytelnhacker) is an independent security researcher, bestselling author, and international speaker specializing in hardware and automotive cybersecurity. He has presented at leading global conferences and is known for combining deep technical expertise with engaging storytelling through his talks and The StorytellingHacker platform.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
📲 View full schedule & build your agenda: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #AutomotiveSecurity #EmbeddedSecurity #IoTSecurity #HardwareHacking #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
Unraveling Failure – Lessons from an Avoidable Ransomware Attack - Mihai Tutulan
Ransomware is no longer just an IT problem — it’s a full business crisis. This talk walks through a real-world attack on a large non-IT industrial organization where cybersecurity was not treated as a priority, revealing how quickly operations can collapse under pressure.
Following the incident step by step, the session shows how a single phishing email triggered a complete IT blackout, halted production, and exposed critical failures in incident response and business continuity planning. Beyond the technical details, it highlights how organizational decisions and lack of basic controls can turn incidents into long-term disasters.
Mihai Tutulan is a Senior Cybersecurity Consultant with over 15 years of experience, the speaker specializes in aligning cybersecurity with business strategy, covering areas such as risk management, compliance (ISO 27001, GDPR, NIS2, DORA), and security governance across global organizations.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
📱 Want an easy way to follow the schedule?
Use Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #Ransomware #IncidentResponse #BusinessContinuity #CyberSecurity #RiskManagement
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
☁️💥 𝗖𝗟𝗢𝗨𝗗 𝗠𝗜𝗦𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗔𝗧𝗜𝗢𝗡𝗦: 𝗣𝗢𝗞𝗘 𝗣𝗢𝗞𝗘, 𝗕𝗥𝗘𝗔𝗖𝗛 – Kat Fitzgerald ( @rnbwkat ) 🔐☁️
Cloud breaches aren’t going away—they’re evolving.
Forget the classic “public bucket” mistakes. In 2026, real-world breaches are driven by over-privileged identities, risky SaaS integrations, forgotten environments, and insecure defaults in AI and Kubernetes. These aren’t obvious missteps—they’re systemic risks hiding in plain sight.
This talk breaks down the modern hierarchy of cloud misconfigurations based on recent breach data, then shifts the focus from reacting to preventing. Using Policy as Code (PaC), security becomes proactive—blocking risky deployments before they ever reach production.
You’ll also explore the Toxic Trilogy: assets that are publicly exposed, highly privileged, and critically vulnerable. When these overlap, breaches aren’t just possible—they’re predictable.
Kat Fitzgerald ( @rnbwkat )is a Chicago-based cybersecurity professional with a passion for cloud security, OSS, and creative defensive strategies. Known for blending technical depth with a unique personality (and a certain opinionated flamingo), Kat brings real-world insights into modern cloud risks and how to stop them before they start.
📱 Want to easily navigate all talks, villages, and stages?
Check out the official schedule on Hacker Tracker:
https://hackertracker.app/schedule?conf=BSIDESLUX2026
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #CloudSecurity #Misconfiguration #Kubernetes #PolicyAsCode #DevSecOps #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
Cloud Sovereignty – Catalin Tiganila
Cloud sovereignty has moved beyond policy discussions and into boardroom decision-making. This talk examines how sovereignty, autonomy, and resilience are becoming critical drivers in cloud strategy, shaped by regulatory pressure, geopolitical uncertainty, and increasing reliance on hyperscale platforms.
We break down the “triple threat” of modern cloud adoption: legal exposure and foreign influence risks, vendor lock-in and escalating switching costs, and deep technology dependency. The session also introduces practical sovereign cloud operating models and how organizations can align architecture and governance decisions with evolving EU regulations such as DORA, NIS2, and the EU Data Act.
Catalin Tiganila is a cybersecurity consultant and auditor with over 25 years of experience in cloud security, IT governance, risk management, compliance, and audit across industries including finance, telecom, healthcare, energy, and manufacturing.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
📱 Want an easy way to follow the schedule?
Use Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #CloudSecurity #Sovereignty #NIS2 #DORA #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
In The Wild Cloud Exfiltration Paths You Might Not Expect – Tomas Kabrt
Cloud environments are no longer just infrastructure expansions — they are full-blown attack surfaces. This talk explores how real-world attackers move data out of cloud environments by abusing SaaS integrations, PaaS workflows, and IaaS-level infrastructure behaviors that often go unnoticed in traditional security monitoring.
Based on hundreds of real incident response cases, this session highlights practical exfiltration paths such as SaaS app abuse (Microsoft 365, DocuSign sync flows), ETL-based PaaS exploitation, and cross-cloud IaaS data movement. The focus is on what defenders miss and how to build meaningful detection and telemetry around it.
Tomas Kabrt is a Cloud Threat Intelligence Researcher at CrowdStrike, focusing on cloud intrusions and real-world attacker behavior observed through incident response and threat hunting engagements.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
📱 Want an easy way to follow the schedule?
Use Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #CloudSecurity #ThreatIntel #Exfiltration #IncidentResponse #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
Leaky API Keys, Log Tampering, and Account Takeover – Aleksa Zatezalo
Modern cloud systems are highly secure in isolation, but real-world risk emerges at the seams — where services integrate. This talk explores how seemingly minor misconfigurations in logging pipelines, API integrations, and third-party services can quietly escalate into high-impact security breaches.
Through three real-world inspired vulnerability scenarios, the session demonstrates how leaked API keys from client-side logs, misconfigured S3 uploads, and insecure integrations (such as Supabase and financial data pipelines) can be chained into account takeover paths. The focus is on understanding the underlying anti-patterns rather than isolated bugs.
Attendees will leave with a structured framework to identify these cross-service weaknesses and practical remediation strategies that go beyond patching symptoms — targeting the architectural root causes that enable entire classes of exploitation.
Aleksa Zatezalo is a security engineer and software developer with experience in cloud security consulting, offensive security tooling, and contributions to Metasploit. He currently works at Praetorian and is OSCP-certified, pursuing OSCE3, with a strong focus on applied offensive security research.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
📱 Want an easy way to follow the schedule?
Use Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #CloudSecurity #APIKeys #AccountTakeover #DevSecOps #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🤖🔐 𝗕𝗥𝗘𝗔𝗞𝗜𝗡𝗚 𝗧𝗛𝗘 𝗖𝗢𝗡𝗧𝗥𝗢𝗟 𝗣𝗟𝗔𝗡𝗘: 𝗘𝗫𝗣𝗟𝗢𝗜𝗧𝗜𝗡𝗚 𝗠𝗖𝗣 𝗦𝗘𝗥𝗩𝗘𝗥𝗦 𝗜𝗡 𝗔𝗜 𝗪𝗢𝗥𝗞𝗙𝗟𝗢𝗪𝗦 – Yotam Perkal ⚙️🔥
AI agents need integrations—and MCP servers are becoming the backbone of that connectivity. But what happens when these “developer tools” are exposed, overprivileged, and unprotected?
This talk dives into the hidden risks of MCP servers, showing how attackers can exploit them for SSRF, filesystem access, and even full remote code execution. As AI workflows grow, so does the attack surface—and the control plane is now a prime target.
Yotam Perkal leads security research at Pluto Security, focusing on securing AI-native environments and agent-based systems. With past roles at Zscaler, Rezilion, and PayPal, he brings deep expertise in vulnerability research, threat intelligence, and AI security.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
👉 Browse sessions, track talks in real time, and plan your schedule on Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #AISecurity #MCP #CyberSecurity #AppSec #AIWorkflows #ThreatResearch
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🧠🔍 𝗪𝗛𝗔𝗧 𝗗𝗢𝗘𝗦 𝗧𝗛𝗥𝗘𝗔𝗧 𝗠𝗢𝗗𝗘𝗟𝗜𝗡𝗚 𝗦𝗢𝗟𝗩𝗘 𝗙𝗢𝗥 𝗔𝗜 𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬? – Nathan Pembe 🛡️
AI doesn’t create entirely new risks—it amplifies the ones you already have. So how do you decide what actually matters?
This talk shows how threat modeling becomes a powerful decision-making tool—helping teams identify real attack paths, prioritize security efforts, and align technical controls with compliance requirements like ISO 27001, AI Act, and NIS2. It’s not about theory—it’s about making smarter security decisions from the start.
Nathan Pembe https://www.linkedin.com/in/nathanpembe/ is a Senior AppSec Consultant at NVISO, helping teams embed security into design and delivery through practical threat modeling and secure architecture practices.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
👉 Browse sessions, track talks in real time, and plan your schedule on Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #AISecurity #ThreatModeling #AppSec #AIAct #NIS2 #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🎣🧠 𝗦𝗣𝗢𝗧 - 𝗦𝗣𝗘𝗔𝗥-𝗣𝗛𝗜𝗦𝗛𝗜𝗡𝗚 𝗢𝗩𝗘𝗥𝗪𝗔𝗧𝗖𝗛𝗜𝗡𝗚 𝗧𝗢𝗢𝗟 – @paulinebourmeau (Cookie), Thibaut Diels, Mathieu Fourcroy, William Robinet (@wr)🔍📧
Mass phishing is easy to detect. Targeted spear-phishing? That’s where things get dangerous.
SPOT takes on this challenge by combining NLP, machine learning, and LLMs to detect highly targeted phishing attempts that exploit real organizational context. Instead of relying only on shared IOCs, this approach focuses on how attackers craft believable, personalized lures—making detection smarter and more adaptive.
Developed as part of Luxembourg’s LU-CID initiative, this open-source project showcases how AI can be used to fight back against increasingly sophisticated social engineering attacks.
Pauline Bourmeau (Cookie) is an independent security researcher working at the intersection of AI, cognitive psychology, and threat intelligence. Founder of DEFCON Paris and contributor to MISP, she has led NLP and deep learning initiatives and previously worked as a Threat Intelligence Analyst focusing on OSINT, HUMINT, and SOCINT.
Mathieu Fourcroy is Tech nerd and gamer, living in the past (on purpose). He is the main developer behind the SPOT project. He works as a dev engineer at Conostix S.A.
Thibaut Diels is a Systems/Infrastructure Developer at Conostix S.A. by day and Game Developer by night, with interests spanning Linux customization, gaming, and creative tech.
William Robinet manages the technical team at Conostix S.A. in Luxembourg and brings over 25 years of experience in cybersecurity using open-source technologies. He has presented at conferences like Nullcon and Hack.lu and contributes to tooling and research in areas like SSL/TLS and emerging ML systems.
📱 Want to easily navigate all talks, villages, and stages?
Check out the official schedule on Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #Phishing #SpearPhishing #ThreatIntelligence #OSINT #NLP #MachineLearning #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🔥🤖 𝗢𝗛 𝗦𝗛𝗜𝗧 𝗜 𝗔𝗖𝗖𝗜𝗗𝗘𝗡𝗧𝗔𝗟𝗟𝗬 𝗕𝗥𝗘𝗔𝗖𝗛𝗘𝗗 𝗔𝗡 𝗢𝗥𝗚𝗔𝗡𝗜𝗭𝗔𝗧𝗜𝗢𝗡 (𝗢𝗥 𝗠𝗔𝗡𝗬) 𝗨𝗦𝗜𝗡𝗚 𝗔𝗜 – Panagiotis Fiskilis 💥
What starts as a harmless search can spiral into a multi-organization data breach—especially when AI gets involved.
This talk dives into real-world research showing how AI can be weaponized for OSINT, enabling large-scale data discovery, spear phishing campaigns, and even manipulation of AI systems themselves. From injecting malicious context into models to scaling attacks via APIs and agent workflows, this session explores how adversaries can turn AI into a powerful offensive tool—and how defenders can detect and respond.
Expect a true purple team perspective, blending attacker techniques with defensive insights, including OPSEC considerations and strategies to identify malicious AI-driven activities before they escalate.
Panagiotis Fiskilis is a Senior Red Team Operator at NVISO, specializing in API hacking, Active Directory exploitation, and malware development. With multiple industry certifications (OSCP, OSWE, CRTO, eWPT and more), he brings hands-on offensive expertise combined with a strong research-driven mindset.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
👉 Browse sessions, track talks in real time, and plan your schedule on Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #AISecurity #RedTeam #OSINT #CyberSecurity #AI #ThreatIntelligence #PurpleTeam
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🧠🤝 𝗧𝗘𝗔𝗠𝗜𝗡𝗚, 𝗧𝗥𝗨𝗦𝗧, 𝗔𝗡𝗗 𝗧𝗛𝗥𝗘𝗔𝗧𝗦: 𝗛𝗢𝗪 𝗛𝗨𝗠𝗔𝗡𝗦 𝗜𝗡𝗧𝗘𝗥𝗔𝗖𝗧 𝗪𝗜𝗧𝗛 𝗚𝗘𝗡𝗘𝗥𝗔𝗧𝗜𝗩𝗘 𝗔𝗜 𝗜𝗡 𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 – Dr. Tailia Malloy 🔐
As AI becomes part of everyday security workflows, the real challenge isn’t just the technology—it’s how humans trust, use, and collaborate with it.
This talk explores how generative AI is reshaping cybersecurity tasks like network analysis, social engineering defense, and secure software development. By combining human-computer interaction research with real-world security use cases, it reveals how trust, teaming, and human behavior shape both the strengths and risks of AI in security.
Dr. Tailia Malloy (She/They) is a postdoctoral researcher at the University of Luxembourg, specializing in human-AI interaction, cognitive modeling, and the application of generative AI in cybersecurity—from phishing defense to secure code generation.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
👉 Browse sessions, track talks in real time, and plan your schedule on Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
# BSidesLuxembourg2026 #AISecurity #HumanAI #CyberSecurity #HCI #GenerativeAI #TrustInAI
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🤖📊 𝗪𝗛𝗘𝗡 𝗟𝗟𝗠𝗦 𝗦𝗨𝗠𝗠𝗔𝗥𝗜𝗭𝗘 𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 𝗙𝗜𝗡𝗗𝗜𝗡𝗚𝗦: 𝗧𝗛𝗘 𝗧𝗥𝗔𝗗𝗘𝗢𝗙𝗙𝗦 𝗬𝗢𝗨 𝗖𝗔𝗡’𝗧 𝗜𝗚𝗡𝗢𝗥𝗘 – Andrey Lukashenkov ⚖️
Turning hundreds of security findings into a clean summary sounds easy—until the output is incomplete, inconsistent, or just confidently wrong.
This talk breaks down what really happens when you rely on LLMs for security summarization. From prompt design and input shaping to model selection and evaluation, it reveals the hidden “control knobs” that directly impact accuracy, reliability, and cost. Instead of guesswork, you’ll learn a structured, repeatable way to experiment, measure, and build summaries you can actually trust.
Andrey Lukashenkov works across product, revenue, and research at Vulners, focusing on vulnerability intelligence, prioritization, and turning complex security data into actionable insights for real-world use.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
👉 Browse sessions, track talks in real time, and plan your schedule on Hacker Tracker: https://hackertracker.app/schedule?conf=BSIDESLUX2026
#BSidesLuxembourg2026 #AISecurity #LLM #AppSec #VulnerabilityManagement #CyberSecurity #AI
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
📱🗺️ Navigate the Conference Like a Pro with 𝗛𝗔𝗖𝗞𝗘𝗥 𝗧𝗥𝗔𝗖𝗞𝗘𝗥!
Keeping up with everything at #BSidesLuxembourg2026 can be… a challenge 😅
With 5 stages, 2 dedicated villages, live recordings, activities in the Atrium, and multiple workshops running in parallel—it’s easy to miss something awesome.
So we’ve made it easier 👇
The full conference schedule is now available on the Hacker Tracker app, making it simple to:
📅 Browse all sessions in one place
⏰ Track what’s happening in real time
⭐ Plan your personal schedule
📍 Never miss the talks you care about
👉 Check it out here: https://lnkd.in/dejd-4xm
#BSidesLuxembourg2026 #HackerTracker #CyberSecurity #Infosec #ConferenceLife #BSides
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
Its Easter, and the Easter rabbit always brings Easter eggs.
We found a friendly Easter-egg sponsor, so #BSidesLuxembourg tickets are 80% OFF while the supply lasts (80% off, 10 euro tickets right now for 3 days of Cybersecurity goodness!).
10 euro tickets. Grab yours before the Easter promo runs out!
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
Its simply the best training available, and the budget is...lets say...affordable???
If you're still debating whether or not to attend BSidesLuxembourg this year, here's the schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/ - 3 days for 50 euro (no, not a joke).
If you have a team of folks doing AI, DevOps, IT or CyberSec, this would probably be very relevant to share with them. Tix: https://pretix.eu/BSidesLux/2026/
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🤖💥 𝗧𝗛𝗘 𝗔𝗚𝗘𝗡𝗧𝗦 𝗢𝗙 𝗖𝗛𝗔𝗢𝗦: 𝗔𝗜 𝗗𝗥𝗜𝗩𝗘𝗡 𝗠𝗔𝗟𝗪𝗔𝗥𝗘 𝗚𝗘𝗡𝗘𝗥𝗔𝗧𝗜𝗢𝗡 – Arad Donenfeld ⚙️🔥
What happens when AI doesn’t just assist malware development—but fully owns it?
This talk explores a system where AI agents autonomously generate malware from start to finish. From prompt engineering and model orchestration to automated build-and-fix loops, it reveals how AI can produce diverse, evasive malware samples that challenge traditional detection. As models evolve, so does the scale, speed, and unpredictability of offensive tooling.
Arad Donenfeld is an attacks and exploits developer at SafeBreach with a strong background in security research, malware development, and offensive tooling. His work focuses on building and testing real-world attack techniques to improve detection and defense strategies.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #AISecurity #Malware #RedTeam #CyberSecurity #AI #ThreatResearch
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🗺️ MAPPING THE INVISIBLE: WHY SYSTEM CARTOGRAPHY MATTERS FOR SECURITY AND COMPLIANCE
🎤 @dbarzin Didier Barzin
Modern infrastructures are complex and opaque — making it hard to know what you’re actually protecting.
This talk explores how system cartography helps organizations visualize architecture, dependencies, and data flows using tools like Mercator, turning complexity into actionable security insight.
@dbarzin Didier is a technology and information security enthusiast who supports open-source values and promotes collaboration to strengthen cybersecurity practices.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #CyberSecurity #SecurityArchitecture #Compliance #OpenSource
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🧠💻 𝗧𝗔𝗟𝗞 𝗧𝗢 𝗔 𝗦𝗛𝗘𝗟𝗟: 𝗘𝗫𝗣𝗟𝗢𝗜𝗧𝗜𝗡𝗚 𝗔𝗜 𝗔𝗚𝗘𝗡𝗧𝗦 𝗜𝗡 𝗥𝗘𝗔𝗟 𝗧𝗜𝗠𝗘 – Parth Shukla ⚡
AI agents are no longer just chatbots—they can execute commands, access files, and interact with real systems. But what if an attacker could control all of that… just by talking?
This talk reveals a real-world vulnerability where full system command execution was achieved through natural language interaction alone. From reconnaissance to bypassing safeguards using jailbreak techniques, this session shows how AI agents can become unintended attack proxies—no exploits, no credentials, just conversation.
Parth Shukla is a Senior Security Researcher specializing in AI Security and Adversarial Machine Learning, focusing on securing agentic systems and uncovering real-world vulnerabilities in LLM-driven architectures.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #AISecurity #LLM #AgenticAI #CyberSecurity #AppSec #AdversarialAI
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🎣⚡ 𝗙𝗥𝗢𝗠 𝗠𝗔𝗡𝗨𝗔𝗟 𝗛𝗨𝗡𝗧 𝗧𝗢 𝗠𝗔𝗦𝗦 𝗗𝗘𝗧𝗘𝗖𝗧𝗜𝗢𝗡: 𝗪𝗘𝗔𝗣𝗢𝗡𝗜𝗦𝗜𝗡𝗚 𝗡𝗨𝗖𝗟𝗘𝗜 𝗔𝗚𝗔𝗜𝗡𝗦𝗧 𝗣𝗛𝗜𝗦𝗛𝗜𝗡𝗚 – Rishi @rxerium
Phishing isn’t slowing down—but your detection can scale.
This talk shows how open-source automation with Nuclei transforms phishing detection from manual investigation into a fast, proactive, and scalable process. Learn how hundreds of templates can identify malicious sites across thousands of targets in seconds.
Rishi (@rxerium) is a security researcher focused on vulnerability research, threat intelligence, and large-scale detection techniques, contributing extensively to open-source security tooling.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #Phishing #ThreatIntel #OSINT #CyberSecurity #Automation
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🎯 𝗗𝗜𝗚𝗜𝗧𝗔𝗟 𝗥𝗜𝗦𝗞𝗦, 𝗧𝗛𝗥𝗘𝗔𝗧 𝗠𝗢𝗗𝗘𝗟𝗦, 𝗔𝗡𝗗 𝗘𝗠𝗣𝗔𝗧𝗛𝗬: 𝗧𝗥𝗔𝗜𝗡𝗜𝗡𝗚𝗦 𝗧𝗛𝗔𝗧 𝗘𝗠𝗣𝗢𝗪𝗘𝗥 - Łukasz Król ✨🔥
Digital and cyber risks don’t always fit into standard risk assessment models. They use different language, involve complex causes, and depend on interlinked systems.
In this talk, Łukasz Król shares how to make digital security feel real, relatable and doable, even for non-technical audiences. He’ll show how to compare digital risks to physical, financial, and legal threats using simple analogies, how to break down the myth of omnipresent surveillance, and how to use storytelling to make threat modelling feel less abstract.
With real examples he’ll prove that empathy, clarity, and simple frameworks can turn fear into action.
Łukasz Król https://pretalx.com/bsidesluxembourg-2026/speaker/NLVVCF/ is a digital security trainer at the ICRC Global Cyber Hub in Luxembourg. He has a background in politics, technology, and international relations. He is particularly interested in digital security pedagogies, selecting secure and sustainable digital tools, and effectively supporting at-risk groups and individuals.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #DigitalSecurity #RiskAssessment #CyberTraining #OSINT #HackerLife #SecurityEducation
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🏎️⛽ 𝗙𝗘𝗥𝗥𝗔𝗥𝗜 𝗪𝗜𝗧𝗛𝗢𝗨𝗧 𝗙𝗨𝗘𝗟: 𝗘𝗫𝗢𝗥𝗖𝗜𝗦𝗘 𝗚𝗜𝗚𝗢 𝗢𝗨𝗧 𝗢𝗙 𝗟𝗢𝗚𝗦 𝗠𝗔𝗡𝗔𝗚𝗘𝗠𝗘𝗡𝗧 - 𝗦𝗧𝗘𝗙𝗔𝗡𝗢 𝗔𝗠𝗢𝗗𝗜𝗢 & 𝗘𝗟𝗟𝗜𝗢𝗧 𝗣𝗔𝗥𝗦𝗢𝗡𝗦 📈🛡️
Throwing more data at your SIEM will not fix broken security 🚫 This talk highlights why poor log quality and missing visibility quietly undermine even the most advanced AI driven tools. The real fix starts upstream. Clean, meaningful, and governed data turns noisy monitoring into reliable detection and helps teams move from overload to clarity.
Stefano Amodio https://lu.linkedin.com/in/stea is a SOC Team Leader with a decade of experience across ISP, MSSP, and internal SOCs and holds a SANS GIAC GSOM certification.
Elliot Parsons https://www.linkedin.com/in/elliot-parsons-4ba72140 is a cyber threat intelligence consultant at AmeXio. He is from New Zealand with a background in Financial Services, Technology Services and Government organisations. His expertise is in threat intelligence, threat hunting, reverse engineering, malware analysis, and incident response.
📅 Conference dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #LogsManagement #SOCVisibility #SIEM #DataQuality #SecurityMonitoring
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🚗💻 𝗛𝗔𝗡𝗗𝗦-𝗢𝗡 𝗖𝗔𝗥 𝗛𝗔𝗖𝗞𝗜𝗡𝗚 & 𝗔𝗨𝗧𝗢𝗠𝗢𝗧𝗜𝗩𝗘 𝗖𝗬𝗕𝗘𝗥𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 - workshop with @roald Nefs 🔍🛡️
Modern cars are no longer mechanical devices. They're complex, interconnected computer networks. And like any networked system, they can be hacked. This is a practical, hands-on workshop showing how modern cars work as connected systems—and where their security weaknesses lie. You’ll get a clear introduction to in-car communication and how it can be exploited.
Roald Nefs https://www.linkedin.com/in/roaldnefs/ CTO at Warpnet, has a strong background in security engineering and IT compliance. He’s also active in the security community as an open-source contributor and BSides organizer.
📅 Conference dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #CarHacking #AutomotiveSecurity #CyberSecurity #CANbus #VehicleSecurity #BSides
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🟣🤖 𝗚𝗢𝗢𝗗𝗕𝗬𝗘 𝗣𝗨𝗥𝗣𝗟𝗘 𝗧𝗘𝗔𝗠, 𝗛𝗘𝗟𝗟𝗢 𝗣𝗨𝗥𝗣𝗟𝗘 𝗕𝗢𝗧𝗦 - 𝗣𝗔𝗧𝗥𝗜𝗖𝗞 𝗠𝗞𝗛𝗔𝗘𝗟 & 𝗥𝗔𝗟𝗣𝗛 𝗘𝗟 𝗞𝗛𝗢𝗨𝗥𝗬 🛡️⚔️
What if purple teaming could run itself? 🚀 This talk reveals an AI driven framework that simulates real world attacks, uncovers detection gaps, and continuously strengthens your defenses with zero manual effort. It's more than automation. It is a smart, self evolving security cycle where offense and defense work together in real time to stay ahead of threats.
Patrick Mkhael https://pretalx.com/bsidesluxembourg-2026/speaker/WHMGFD/ is an Offensive Security R&D lead with a strong blue team foundation, now focused on red teaming, cloud pentesting, and building tools for adversary emulation and automated security testing.
Ralph El Khoury https://pretalx.com/bsidesluxembourg-2026/speaker/X9QCJN/ is a red teamer and CVE hunter with a passion for breaking AD and web apps. Teaches kids to question everything, starting with default credentials.
📅 Conference dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #CyberSecurity #PurpleTeam #RedTeam #BlueTeam #AI
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
📧💻 𝗦𝗖𝗔𝗟𝗜𝗡𝗚 𝗗𝗘𝗙𝗘𝗡𝗖𝗘 - 𝗙𝗜𝗡𝗗𝗜𝗡𝗚 𝗥𝗘𝗗𝗩𝗗𝗦 𝗙𝗥𝗢𝗠 𝗔 𝗣𝗛𝗜𝗦𝗛𝗜𝗡𝗚 𝗘𝗠𝗔𝗜𝗟 - 𝗘𝗟𝗟𝗜𝗢𝗧 𝗣𝗔𝗥𝗦𝗢𝗡𝗦 🔍🔥
A phishing email isn’t just a threat, it’s a starting point. In this 5-minute lightning talk, Elliot Parsons shows how to turn a single report into a chain of attacks, tracking attackers across domains, IPs, certificates, and links.
Elliot Parsons https://www.linkedin.com/in/elliot-parsons-4ba72140 is a cyber threat intelligence consultant at AmeXio. He is from New Zealand with a background in Financial Services, Technology Services and Government organisations. His expertise is in threat intelligence, threat hunting, reverse engineering, malware analysis, and incident response.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #Phishing #CyberDefense #ThreatIntelligence #OSINT #RedTeam
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🎲 𝗗𝗨𝗡𝗚𝗘𝗢𝗡𝗦 & 𝗗𝗥𝗔𝗚𝗢𝗡𝗦: 𝗧𝗛𝗘 𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 𝗣𝗢𝗪𝗘𝗥 𝗧𝗢𝗢𝗟 𝗬𝗢𝗨 𝗗𝗜𝗗𝗡’𝗧 𝗞𝗡𝗢𝗪 𝗬𝗢𝗨 𝗡𝗘𝗘𝗗𝗘𝗗 - Klaus Agnoletti ( @klausagnoletti ) & Glen Sorensen 🛡️
Roleplaying isn’t just for nerds, it’s a proven method for building real security muscle. This talk reveals how structured tabletop roleplaying games unlock deeper learning, improve team cohesion, and turn abstract security concepts into lived experience. By simulating incident response, threat modeling, and zero-trust design through narrative-driven play, teams develop adaptive thinking, shared mental models, and faster decision-making under pressure.
Klaus Agnoletti https://www.linkedin.com/in/agnoletti/ is a freelance storytelling cyber security advisor, co-founder of BSides København, neurodiversity advocate, and architect of playful security transformation through narrative and gamification.
Glen Sorensen https://pretalx.com/bsidesluxembourg-2026/speaker/J3PRCC/ is a Solutions Engineer at DeleteMe, former vCISO, and incident master for HackBack Gaming. 20+ years in security engineering, GRC, and operations. Passionate about OSINT, AI-powered social engineering, and using tabletop games to train real-world response.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #GamifiedSecurity #CyberTraining #IncidentResponse #RolePlaying #SecurityLeadership #InfosecEducation #PlayToLearn
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
💥🔥 𝗧𝗛𝗘 𝗪𝗛𝗜𝗦𝗧𝗟𝗘𝗦 𝗚𝗢 𝗪𝗢𝗢 𝗪𝗢𝗢: 𝗦𝗜𝗘𝗠 𝗔𝗟𝗘𝗥𝗧𝗦, 𝗧𝗛𝗥𝗘𝗔𝗧 𝗗𝗘𝗧𝗘𝗖𝗧𝗜𝗢𝗡 𝗔𝗡𝗗 𝗧𝗨𝗡𝗜𝗡𝗚 𝗨𝗡𝗡𝗘𝗖𝗘𝗦𝗦𝗔𝗥𝗬 𝗡𝗢𝗜𝗦𝗘 - 𝗠𝗘𝗟𝗜𝗡𝗔 𝗣𝗛𝗜𝗟𝗟𝗜𝗣𝗦 ( @tx_princess ) 🕵️♀️⚔️
Security teams don’t miss alerts because they’re careless, they miss them because their SIEM never stops yelling. This talk shows how poorly timed, constant, or context-free alerts become meaningless noise and how simple fixes like throttling, prioritization, and timing can turn a SIEM into a tool that actually gets noticed when it matters.
Melina Phillips https://www.linkedin.com/in/melinaphillips-cissp/ is an Offensive Security Engineer with over 10 years in IT and 6 years in cybersecurity, specializing in security operations, incident detection, adversary simulation, and endpoint compromise. She has presented at BSides Cambridge, Security Fest, BruCon, LeHack, HackLu, and BlackAlps.
📅 Conference dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #CyberSecurity #OffensiveSecurity #ThreatDetection #LinuxSecurity #Infosec
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🐧🚨 𝗡𝗢𝗧 𝗦𝗢 𝗛𝗔𝗥𝗠𝗟𝗘𝗦𝗦: 𝗧𝗛𝗘 𝗛𝗜𝗗𝗗𝗘𝗡 𝗪𝗢𝗥𝗟𝗗 𝗢𝗙 𝗟𝗜𝗡𝗨𝗫 𝗣𝗔𝗖𝗞𝗘𝗥𝗦 𝗔𝗡𝗗 𝗗𝗘𝗧𝗘𝗖𝗧𝗜𝗢𝗡 𝗖𝗛𝗔𝗟𝗟𝗘𝗡𝗚𝗘𝗦 - 𝗠𝗔𝗦𝗦𝗜𝗠𝗢 𝗕𝗘𝗥𝗧𝗢𝗖𝗖𝗛𝗜 🛡️🔍
Linux packers and loaders are a sneaky blind spot in cybersecurity. They hide code with encryption and obfuscation, then run it straight from memory to dodge detection. This talk dives into the “hARMless” ARM64 packer, showing off tricks like layered encryption and direct syscalls, while exposing a harsh truth: many defenses on Linux barely see it coming.
Massimo Bertocchi https://pretalx.com/bsidesluxembourg-2026/speaker/SU38N8/ Massimo Bertocchi is a Zürich-based Threat Hunter and Detection Engineer with dual Master’s degrees from KTH Royal Institute of Technology and Aalto University, recognized for his award-winning research uncovering covert C2 channels in Microsoft Teams that enable high-speed data exfiltration and expose critical gaps in enterprise security monitoring.
📅 Conference dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #CyberSecurity #ThreatHunting #MalwareAnalysis #CloudSecurity #DetectionEngineering
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
✨ 𝗠𝗔𝗚𝗜𝗖-𝗥𝗦: 𝗔 𝗠𝗘𝗠𝗢𝗥𝗬-𝗦𝗔𝗙𝗘, 𝗟𝗜𝗕𝗠𝗔𝗚𝗜𝗖-𝗖𝗢𝗠𝗣𝗔𝗧𝗜𝗕𝗟𝗘 𝗙𝗜𝗟𝗘 𝗧𝗬𝗣𝗘 𝗗𝗘𝗧𝗘𝗖𝗧𝗜𝗢𝗡 𝗘𝗖𝗢𝗦𝗬𝗦𝗧𝗘𝗠 - Quentin Jerome 🧩 (@qjerome)
File type detection just got a memory-safe upgrade — in Rust. In this talk, Quentin Jerome shows how Magic-rs brings libmagic’s power to modern, safe code — with Python bindings, a CLI tool called wiza, and real-world compatibility.
Quentin Jerome https://www.linkedin.com/in/quentin-jerome-00a8a074 is a Rust developer at CIRCL. Inspired by his background in incident response and threat detection, he builds open-source security tools to solve practical problems. His main interests include threat detection, bug hunting, and building tools that help the security community.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #Rust #FileDetection #MemorySafety #OpenSource #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🪦🔍𝗪𝗛𝗔𝗧 𝗜𝗦 𝗧𝗛𝗘 𝗗𝗔𝗥𝗞 𝗪𝗘𝗕 𝗧𝗔𝗟𝗞𝗜𝗡𝗚 𝗔𝗕𝗢𝗨𝗧? - 𝗗𝗔𝗥𝗞 𝗝𝗔𝗥𝗚𝗢𝗡 𝗗𝗘𝗧𝗘𝗖𝗧𝗜𝗢𝗡 𝗔𝗡𝗗 𝗜𝗗𝗘𝗡𝗧𝗜𝗙𝗜𝗖𝗔𝗧𝗜𝗢𝗡 - Laura Bernardy 🔐🕵️♂️
The dark web hides in code, and its language is built to confuse. In this talk, Laura Bernardy shows how NLP can decode the slang, jargon, and encrypted phrases used by cybercriminals
Laura Bernardy https://lu.linkedin.com/in/laura-bernardy-a95315177 is a PhD candidate at SnT Luxembourg, researching dark web content and cyber threat intelligence using natural language processing. She holds a master’s in computational linguistics and has worked on low-resource language NLP. Her work combines linguistics, cybersecurity, and AI to decode what’s being said and who’s saying it.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #DarkWeb #NLP #CyberThreatIntelligence #OSINT #Linguistics
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
👀 ⚖️ 𝗛𝗢𝗪 𝗧𝗢 𝗕𝗘 𝗝𝗨𝗦𝗧 𝗧𝗛𝗘 𝗥𝗜𝗚𝗛𝗧 𝗔𝗠𝗢𝗨𝗡𝗧 𝗢𝗙 𝗣𝗔𝗥𝗔𝗡𝗢𝗜𝗗 (𝗖𝗬𝗕𝗘𝗥𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 𝗘𝗗𝗜𝗧𝗜𝗢𝗡) - 𝗗𝗘𝗡𝗜𝗠 𝗟𝗔𝗧𝗜ć 🧠😎
Are you too relaxed? Or too paranoid? In this talk, Denim shares how to find the sweet spot where awareness protects without paralyzing. Find a perspective to to measure your security mindset.
Denim Latić https://pretalx.com/bsidesluxembourg-2026/speaker/9GTVXC/ is a security analyst and part of the CSIRT for Fondation Restena, the NREN of Luxembourg. He is passionate about raising awareness on cybersecurity issues to both small and large audiences.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #CyberSecurity #Mindset #SecurityAwareness
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🛠️ 𝗥𝗜𝗢𝗧 – 𝗔 𝗥𝗔𝗦𝗣𝗕𝗘𝗥𝗥𝗬-𝗕𝗔𝗦𝗘𝗗 𝗡𝗘𝗧𝗪𝗢𝗥𝗞 𝗜𝗠𝗣𝗟𝗔𝗡𝗧 𝗙𝗢𝗥 𝗥𝗘𝗗 𝗧𝗘𝗔𝗠 𝗢𝗣𝗘𝗥𝗔𝗧𝗜𝗢𝗡𝗦 - 𝗢𝗟𝗜𝗩𝗜𝗘𝗥 𝗠é𝗗𝗢𝗖 🍕🥧
A Raspberry Pi isn’t just a toy. In this talk, Olivier Médoc shows how it became a stealthy, modular network implant used in real-world red team operations, turning physical access into long-term access, bypassing MFA, and quietly exfiltrating secrets, even when the victim is unaware.
Olivier Médoc https://pretalx.com/bsidesluxembourg-2026/speaker/TGY8UJ/ is a member of the POST Cyberforce Offensive Security team. He has led offensive security missions across telecom, banking, payment systems, and ATMs. He specializes in vulnerability research, mobile and web app penetration testing, and red team operations. He also contributes to in-house security tooling and forensic investigations.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #RedTeam #RaspberryPi #NetworkImplant #AdversarySimulation #CyberSecurity
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🎯 𝗣𝗛𝗜𝗡𝗗𝗜𝗡𝗚 𝗔 𝗣𝗛𝗜𝗦𝗛𝗘𝗥: 𝗗𝗢𝗡’𝗧 𝗟𝗘𝗧 𝗥𝗘𝗣 𝗚𝗘𝗧 𝗬𝗢𝗨 𝗥𝗘𝗞𝗧 - 𝗘𝗟𝗟𝗜𝗢𝗧 𝗣𝗔𝗥𝗦𝗢𝗡𝗦 ✨🔥
The “as-a-service model” has become ubiquitous across the cybercrime ecosystem. Previously dominated by tight-knit, exclusive groups, cybercrime is now a distributed international marketplace of service providers and consumers. As a result, it is more resilient than ever, with the gaps left by law enforcement takedowns quickly filled by the next opportunistic teenager.
However, to operate effectively in this anonymous distributed economy, threat actors need to build a reputation to gain trust. Does this give us an opportunity?
In this presentation, Elliot Parsons discusses the importance of trust in the cybercrime ecosystem and walks through a real-world investigation involving a prominent phishing-as-a-service (PhaaS) provider. The case study illustrates that trust and OpSec do not mix, exposing threat actors to identification.
Elliot Parsons https://www.linkedin.com/in/elliot-parsons-4ba72140 is a cyber threat intelligence consultant at AmeXio. He is from New Zealand with a background in Financial Services, Technology Services and Government organisations. His expertise is in threat intelligence, threat hunting, reverse engineering, malware analysis, and incident response.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #Phishing #CyberCrime #OSINT #ThreatIntelligence #PhaaS #HackerLife
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
💻 𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 𝗜𝗠𝗣𝗥𝗘𝗦𝗦 𝗞𝗔𝗥𝗔𝗢𝗞𝗘🎯🔥✨ - Kirils Solovjovs ( @k )
Think you can bluff your way through a security talk with zero prep? Now is your chance! At Security Impress Karaoke, you'll be handed a totally random, security-themed slide deck you’ve never seen before and have just 3 minutes to present it like a pro. This is all about having fun, thinking fast, and impressing the crowd with your creativity and/or chaos. Come take the podium and let’s see what you’ve got!
Kirils Solovjovs https://www.linkedin.com/in/kirilssolovjovs/ is Latvia’s top white-hat hacker and IT policy activist with 10+ years in offensive security and command-line mastery.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #SecurityKaraoke #CyberHumor #PublicSpeaking #HackerLife
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
💻 𝗧𝗛𝗢𝗦𝗘 𝗪𝗛𝗢 𝗗𝗢𝗡’𝗧 𝗟𝗘𝗔𝗥𝗡 𝗙𝗥𝗢𝗠 𝗖𝗩𝗘𝗦 𝗔𝗥𝗘 𝗗𝗢𝗢𝗠𝗘𝗗 𝗧𝗢 𝗥𝗘𝗗𝗜𝗦𝗖𝗢𝗩𝗘𝗥 𝗧𝗛𝗘𝗠 - Louis Nyffenegger (@snyff ) 💥
Real vulnerabilities don’t appear in isolation, they’re rooted in code, context, and human error. This session walks through actual CVEs, analyzing the code where they were introduced. You will see the patterns, assumptions, and language quirks that led to the flaw - not just the exploit, but the moment it could’ve been caught.
Louis Nyffenegger https://bsky.app/profile/snyff.pentesterlab.com is the founder of PentesterLab and AppSecSchool, application security expert, and hands-on trainer with experience at the National Bank of Australia, Australia Post, and Fitbit.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #CVE #CodeReview #SecureCoding #PenTest #SecurityEducation #DevSecOps
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
🔍 The dead Internet speaks, and someone is listening 📡
A network telescope — a passive monitor of unused IP space — captures the invisible: unsolicited traffic, botnet noise, scanning waves, and misconfigurations that would otherwise vanish. Unused IP addresses are full of secrets, from botnets and scanners to early warnings of new threats. In this talk, Paul shows how monitoring the internet’s “dead zones” reveals what’s really happening online.
Paul Jung is a senior security professional with 20+ years’ experience in cybersecurity, incident response, and digital forensics. He is a former Senior Security Architect at the European Commission and founded TCS-CERT at Excellium Services (acquired by Thales Group).
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #NetworkTelescope #CyberSecurity #OSINT #ThreatIntelligence #DataAnalysis
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
𝗔𝗗𝗩𝗔𝗡𝗖𝗘𝗗 𝗧𝗛𝗥𝗘𝗔𝗧 𝗛𝗨𝗡𝗧𝗜𝗡𝗚: 𝗦𝗧𝗔𝗬𝗜𝗡𝗚 𝗢𝗡𝗘 𝗦𝗧𝗘𝗣 𝗔𝗛𝗘𝗔𝗗 𝗢𝗙 𝗔𝗗𝗩𝗘𝗥𝗦𝗔𝗥𝗬 - Alex Holden
Cyber defenders must go beyond reactive security as attackers constantly evolve their tactics. This session dives into real-world attack techniques used by threat actors, including the exploitation of stolen credentials, session tokens, and authentication flaws to bypass security controls. It highlights how attackers manipulate verification systems and leverage logic gaps to infiltrate infrastructure and supply chains—and shows how defenders can use this knowledge to strengthen threat hunting and stay ahead of adversaries
Alex Holden https://www.linkedin.com/in/aaholden is the founder and CISO of Hold Security, LLC, a recognized leader in threat intelligence, who studies cybercriminal behavior to help organizations build stronger defenses against evolving cyber threats.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #CyberSecurity #ThreatHunting #InfoSec #CyberDefense #SecurityAwareness
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
𝗛𝗘𝗟𝗟𝗢 𝗟𝗨𝗖𝗬 𝗡𝗜𝗖𝗘 𝗧𝗢 𝗠𝗘𝗘𝗧 𝗬𝗢𝗨! - 𝗔 𝗖𝗢𝗡𝗖𝗟𝗨𝗦𝗜𝗢𝗡 𝗢𝗡 𝗔 𝟯 𝗬𝗘𝗔𝗥 𝗢𝗣𝗘𝗡-𝗦𝗢𝗨𝗥𝗖𝗘 𝗖𝗬𝗕𝗘𝗥𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 𝗣𝗥𝗢𝗝𝗘𝗖𝗧 - Denim Latić
Building effective cybersecurity doesn’t have to come at a high cost. This session shares the journey of LuCy—a largely open-source cybersecurity toolbox designed to support research and education institutions with accessible SIEM and DNS firewall capabilities. From prototype to production, it explores the technical, operational, and human challenges faced along the way, highlighting lessons learned, unexpected risks, and the importance of community collaboration.
Denim Latić https://pretalx.com/bsidesluxembourg-2026/speaker/9GTVXC/ is a Security Analyst and CSIRT team member at Fondation Restena in Luxembourg, focused on strengthening cybersecurity resilience and raising awareness across diverse audiences while supporting the evolution of open-source security initiatives.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #OpenSource #CyberSecurity #SIEM #DNSecurity #InfoSec
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
𝗙𝗥𝗢𝗠 𝗛𝗢𝗨𝗥𝗦 𝗧𝗢 𝗠𝗜𝗡𝗨𝗧𝗘𝗦: 𝗔𝗨𝗧𝗢𝗠𝗔𝗧𝗜𝗡𝗚 𝗜𝗡𝗖𝗜𝗗𝗘𝗡𝗧 𝗥𝗘𝗦𝗣𝗢𝗡𝗦𝗘 𝗧𝗥𝗜𝗔𝗚𝗘 𝗪𝗜𝗧𝗛 𝗢𝗣𝗘𝗡-𝗦𝗢𝗨𝗥𝗖𝗘 𝗧𝗢𝗢𝗟𝗦 - 𝗠𝗔𝗥𝗞𝗨𝗦 𝗘𝗜𝗡𝗔𝗥𝗦𝗦𝗢𝗡
Speed is critical in incident response, and traditional forensic processes often slow teams down. This session demonstrates how to automate forensic triage using open-source tools—transforming data collection, analysis, and collaboration into a streamlined, cloud-driven workflow. By integrating tools like Velociraptor, OpenRelik, Hayabusa, Plaso/log2timeline, and Timesketch, responders can reduce investigation time from hours to minutes while maintaining forensic integrity and improving team collaboration.
Markus Einarsson https://linkedin.com/in/markuseinarsson/ is a Security Architect and Incident Response Lead at Sectra in Sweden, specializing in digital forensics, incident response, and scalable security workflows, with deep expertise in modern DFIR toolchains and open-source automation.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #IncidentResponse #DigitalForensics #DFIR #CyberSecurity #OpenSource
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
Use this @pretalx access code:: https://pretalx.com/bsidesluxembourg-2026/cfp?access_code=A7YVWLUG3RAQZDECZBFORLIGHTNINGTALKS
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
Visual Studio Code isn’t just a developer favorite — it’s now a high-value target for stealthy supply-chain attacks. This talk dives into real-world hacks, from crypto-stealing Solidity extensions to self-spreading threats like GlassWorm, exposing how attackers hide in plain sight. See how TypeScript and Rust can be fused to create “trusted” extensions that secretly execute native shellcode inside your IDE. Walk away with powerful insights to detect, defend, and stay ahead of this new wave of developer-focused threats.
Debjeet Banerjee is a Malware Developer at Black Hills Information Security, focused on building tools, researching evasion techniques, and advancing offensive security.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #CyberSecurity #InfoSec #Malware #EthicalHacking #SecurityResearch
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We realize its complicated to keep track of whats happening at any given time across 5 stages with recording, 2 of these being villages, and multiple different things going on in the Atrium also, plus all the different workshops on the workshops day.
So we've loaded the schedule into Hacker Tracker (the app) with their help!
Get it here: https://hackertracker.app/
ty @aNullValue for the help!
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
Get on stage, talk about an #infosec slide deck you've never seen - like the Powerpoint karaoke at hack.lu but with infosec slide decks!
Come try it after a full day of fun conference talks and villages!?
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
We are back in 2026!! May 6-8th in Belval Follow this feed for news! or subscribe to our newsletter -> https://bsides.lu/wws/subscribe/newsletter Tickets are available here -> https://pretix.eu/BSidesLux/2026/ Schedule -> https://pretalx.com/bsidesluxembourg-2026/schedule/ Website -> https://2026.bsides.lu
There are over 100 armed conflicts worldwide, all with a technological dimension, as global systems face mounting strain. In this session, Luxembourg’s Cybersecurity and Digitalisation Ambassador offers a clear-eyed look at current challenges in geopolitics and cyberdiplomacy, and how these fields can work together in response. Join the discussion and bring your questions on international relations and order in the digital world
Luc Dockendorf @lucdockendorf : Luxembourg’s Cyber and Digital Ambassador since March 2025, has worked in international relations since 2003, including roles with the Ministry of Foreign Affairs, the UN Security Council, the Human Rights Council, and leading EU cyber policy discussions.
📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #Cybersecurity #Diplomacy #Geopolitics #CyberDiplomacy #InternationalRelations #BsidesLuxembourg2026