Sign in

BSides Buffalo

@bsidesbuffalo.bsky.social
263 followers 22 following 230 posts

Buffalo's favorite information security conference.

PostsRepliesMedia
BSides Buffalo @bsidesbuffalo.bsky.social · 01/08/2026
Happy August, all! This month's Infosec 716 meetup will feature a demonstration of SO-CRATES, the new log and packet analysis platform from @dougburks.bsky.social of @securityonion.bsky.social - hope to see you there! As always, you can join in person at @bithavenllc.bsky.social or remotely.
meetup.com
Infosec 716 August Virtual Meetup, Wed, Aug 19, 2026, 6:00 PM | Meetup
Our August meetup will feature a demonstration of SO-CRATES (https://github.com/dougburks/so-crates), a new open source tool for analyzing packet captures, files, and logs.
031
BSides Buffalo @bsidesbuffalo.bsky.social · 01/07/2026
Welcome to July, all! As is tradition, this month's Infosec 716 meetup will be a taco picnic in Delaware Park. All are welcome, but please RSVP so we've got a good headcount and know how many tacos to bring. Feel free to share, and see you there! www.meetup.com/infosec-716/...
meetup.com
July - Tacos In The Park!, Wed, Jul 15, 2026, 6:00 PM | Meetup
As has now become tradition - for July, let's meet up and eat tacos in the park! This is usually the week in between the shows for Shakespeare in the Park, so there should
011
BSides Buffalo @bsidesbuffalo.bsky.social · 22/06/2026
Happy Monday, all! The videos from this year's BSides Buffalo have been posted to our YouTube channel, along with all the videos from past events. Thanks once again to our fantastic speakers, thanks so much for sharing your knowledge with the community. www.youtube.com/@bsidesbuffalo
021
BSides Buffalo @bsidesbuffalo.bsky.social · 18/06/2026
This reboot of 8 Mile looks terrible. 😄
010
BSides Buffalo @bsidesbuffalo.bsky.social · 16/06/2026
Yeah we are! www.youtube.com/watch?v=lvdc...
youtube.com
Buffalo We're Lookin' Good 1987
YouTube video by Retrontario
000
BSides Buffalo @bsidesbuffalo.bsky.social · 07/06/2026
Feeling those post-conference blues after such an awesome day yesterday? We get it. You know what might help? Make plans to join the Buffalo hacker community for tacos in Delaware Park next month! Hope to see you there! www.meetup.com/infosec-716/...
meetup.com
July - Tacos In The Park!, Wed, Jul 15, 2026, 6:00 PM | Meetup
As has now become tradition - for July, let's meet up and eat tacos in the park! This is usually the week in between the shows for Shakespeare in the Park, so there should
000
BSides Buffalo @bsidesbuffalo.bsky.social · 07/06/2026
Our fifth annual event: 332 tickets sold, 23 talks across three tracks, a CTF, and lockpick/soldering/career villages that were bustling all day. Thank you so much to the sponsors, the speakers, the volunteers, and the attendees for making this the biggest and best BSides Buffalo yet.
130
BSides Buffalo @bsidesbuffalo.bsky.social · 06/06/2026
Tomorrow.
031
BSides Buffalo @bsidesbuffalo.bsky.social · 05/06/2026
Things to bring to BSides Buffalo tomorrow: * Coming to the Career Village? Bring a copy of your resume. * Playing the CTF? Bring your laptop. * Stickers to trade or share? Bring them for the table. * Lockpicking or soldering challenges? Bring them for help. See you all in the morning!
011
BSides Buffalo @bsidesbuffalo.bsky.social · 05/06/2026
PARKING INFORMATION FOR TOMORROW The conference will be held in Science Hall, at the corner of Main Street and Jefferson Avenue (N on the map below). There is parking available at either end of the building, in the lots labelled 14 and 15, or street parking on Main Street in front of the building.
111
Reposted by BSides Buffalo
Matthew Gracie @infosecgoon.bsky.social · 05/06/2026
Going to be giving away some classic Captain Crunch 2600 whistles from our friends at @bithavenllc.bsky.social at @bsidesbuffalo.bsky.social tomorrow. Toot toot little phreaks!
072
BSides Buffalo @bsidesbuffalo.bsky.social · 05/06/2026
After closing remarks tomorrow, join the local hacker community at Bit Haven in the Tri Main Building (2495 Main Street) for the official BSides Buffalo after party! Music, food, drinks, and a chance to hang out and meet your peers and talk about all the cool stuff you learned. See you there!
000
BSides Buffalo @bsidesbuffalo.bsky.social · 04/06/2026
Our final Lightning Talk of the day will be Sai Jagadeesh presenting "Deep Link Vulnerabilities: When One Click Leads to Account Takeover". (talk description in alt text)
"Deep links are widely used in mobile applications to provide seamless navigation to specific screens inside an app. However, when deep links are improperly validated, they can become powerful attack vectors that allow external inputs to directly influence internal application behavior.

This lightning talk explores how seemingly harmless deep links can lead to serious security issues such as token leakage, WebView exploitation, and even one-click account takeover. 

In one example, a crafted deep link forces the app to open an attacker-controlled URL inside a WebView while automatically appending the victim’s authentication token, allowing the attacker to hijack the account with a single click.

We will also look at how vulnerable WebView configurations combined with exported deep link activities can enable attackers to exfiltrate session cookies, load malicious content, or execute privileged actions inside the app context.

This talk highlights common developer mistakes, demonstrates how attackers chain deep link handling with WebView behavior, and provides practical mitigation strategies to secure mobile applications against these hidden entry points."
001
BSides Buffalo @bsidesbuffalo.bsky.social · 04/06/2026
Our final talk of the day in Track One will be the Lightning Talk "Still Cracking: WPA2 Prevalence and Password Weakness in 2026" by Dimitri Weaver. (talk description in alt text)
"In 2021, a CyberArk researcher collected 5,000 network hashes across Tel Aviv using $50 in equipment and cracked over 70% of them via the clientless PMKID attack technique. Five years later, this talk revisits that methodology — this time closer to home.

This session presents the results of a real-world WPA2 survey conducted locally in 2026, measuring how prevalent WPA2 remains, how password hygiene has (or hasn’t) improved, and how accessible this attack vector continues to be for any motivated adversary. No live cracking — just honest data, a reproducible methodology, and a candid look at whether the security community has meaningfully moved the needle on wireless security.

Attendees will walk away with a clear understanding of the PMKID attack surface, what current data says about password practices in the wild, and actionable guidance for individuals and organizations looking to actually secure their wireless environments."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 03/06/2026
Our second 4pm Lightning Talk is Billy Gibson and Ryan Conry presenting "Bad Apples: Orchestrating Movement and Execution via Native macOS Protocols". (talk description in alt text)
"As macOS adoption accelerates—with over 45% of enterprises now utilizing the platform—Mac endpoints have become high-value targets for attackers seeking cloud credentials, source code, and privileged access. Despite this trend, macOS lateral movement remains a significant blind spot; the MITRE ATT&CK framework documents far fewer techniques for macOS than for Windows, and recent industry reports indicate that macOS environments prevent significantly fewer attacks than their Linux or Windows counterparts. This research aims to close that gap by systematically validating macOS-native lateral movement and execution primitives.

While Remote Apple Events (RAE) are traditionally documented as a lateral movement vector (T1021.001), we also approach the protocol through the lens of Software Deployment Tools for Execution (T1072). We demonstrate how RAE can be weaponized as a standalone primitive for deploying and executing complex, multi-line shell scripts. Our investigation analyzes the inherent security features of the System Events handler and the parsing constraints of the AppleScript interpreter that typically restrict remote orchestration. We then present a robust bypass methodology utilizing Base64 transport encoding and Terminal.app orchestration to achieve arbitrary code execution."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 03/06/2026
Our first Lightning Talk of the day will be in Track One at 4pm, Christopher Bruns presenting "Mapping Internal Networks - The Art of Finding Things". (talk description in alt text)


"As a Pentester, the discovery process is one of the most important steps to get right. With timed engagements, quick and efficient discovery processes are a must to produce meaningful results for customers. This session will talk about the art of internal network enumeration. How to find networks. How to find assets within networks. Useful tools and strategies for large networks. And how to take the data found and use it to formulate attacks against systems and Active Directory."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 02/06/2026
Kicking off the 4pm hour in the atrium, we have a panel session with Catherine Ullman and Qasim Ijaz discussing "Hacker Mindset, Defender Mission". (talk description in alt text)



"Whether you're building a SOC, developing detection capabilities, hiring a pentest firm, or training analysts, understanding how attackers think changes everything from the questions you ask to the gaps you find. 

In this panel we discuss how offensive awareness strengthens defensive operations from the inside out: building detection logic informed by real attacker tradecraft, preparing your team to get the most out of offensive engagements, and fostering a culture where defenders are encouraged to think like hackers without needing to become one."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 02/06/2026
Closing out Track Three is Hemanth Gorijala, presenting "Secrets That Survive Everything: Finding Runtime Credentials in Production Web Applications". (talk description in alt text)
"A bug bounty researcher found Azure credentials in a JavaScript file and called it done. I kept going — four Azure AD credentials sitting in a public JS file, enough to authenticate as the application itself. The frontend had documented its own backend. Full account takeover. The application's token had been granted the ability to perform user-level operations — every account in the system was reachable. The organization had GitLeaks in CI/CD and static secret scanning on pull requests. The credentials were still live.

That was one chain. A second application used CryptoJS to encrypt its configuration — a common pattern in SPAs where developers believe encrypting the config protects it. The decryption key was hardcoded in the same JavaScript file, three lines away from the encrypted blob. The secret to unlock everything was sitting next to the lock. Same credential pattern at the end. Same result.

Shift-left tools scan what you commit. They do not scan what you serve. Build-time environment injection bakes live keys into webpack bundles that never touch the repository. CI/CD pipeline variable substitution materializes secrets only in the build artifact, after every scanner has run. SSR state blobs injected by Next.js and Nuxt carry credentials into HTML that no pre-deployment scanner ever sees. Once a secret reaches production, it disappears from every scanner's view. The only things finding runtime secrets are manual penetration testers, bug bounty researchers, and attackers. Two of those three report what they find.

This talk walks through both exploitation chains in detail, maps the full shift-right gap in the security tooling landscape, and closes with a live demo using a purpose-built intentionally vulnerable healthcare portal — a HIPAA-branded application exposing Twilio, SendGrid, Stripe, and Firebase credentials in its public JavaScript files, and leaking internal service keys in response headers on every single request."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 01/06/2026
Closing out our Introsec track at 3pm is Jerrad Bartczak, MBA, CISSP, CISA, CCSFP, CHQP, presenting "What Is IT Audit: What IT Auditors Do and Why It Matters". (talk description in alt text)

"The function of an IT auditor is often misunderstood in the greater cybersecurity and GRC landscape. This session cuts through the confusion and provides a clear, accessible overview of what IT auditors actually do, why the discipline exists, and how it fits into the broader governance, risk, and compliance landscape. Attendees will explore the different types of IT audits — from SOC 2 examinations and HITRUST assessments to HIPAA, CMMC, and ISO audits — and learn how each serves a distinct purpose in building organizational trust and compliance. The session will also cover how IT audits evaluate the design and effectiveness of controls across areas like access management, change management, endpoint security, and data protection. Whether you are a business leader trying to understand an upcoming SOC 2 examination, an IT professional preparing for your first audit, or a student exploring career paths, this session will give you a practical foundation for understanding how IT audit drives trust, accountability, and operational resilience."
100
BSides Buffalo @bsidesbuffalo.bsky.social · 01/06/2026
At 3pm in Track One, we've got Kelsey O'Connell presenting "It Wasn’t Spoofed: Investigating Authenticated Email Abuse in Real Environments". (talk description in alt text)
At 3pm in Track One, we've got Kelsey O'Connell presenting "It Wasn’t Spoofed: Investigating Authenticated Email Abuse in Real Environments".


"A suspicious email spreading internally was initially attributed to spoofing after a user reported a message sent from their account that they had not sent. However, analysis revealed the message originated from within the organization.


Authentication had succeeded, the message was treated as internal, and no alerts were generated. The activity was not spoofing, but authenticated abuse using valid credentials.


This session walks through how to investigate and differentiate between spoofed and authenticated activity, and what control gaps allow this type of behavior to persist in real-world environments."
010
BSides Buffalo @bsidesbuffalo.bsky.social · 01/06/2026
Excited to announce our latest Gold Sponsor for BSides Buffalo 2026, first-time sponsors Sekoia.io!
sekoia.io
homepage
Sekoia.io provides cyber teams with a SOC platform that can respond to security incidents, regardless of the attack surface.
100
BSides Buffalo @bsidesbuffalo.bsky.social · 01/06/2026
Closing out the 2pm slot in Track Three, we've got Ian Litschko presenting "Four Years at War: Trends in Russian State Nexus Cyber Operations". (talk description in alt text)
"After four years of war, Russia's cyber-enabled operations have adapted, representing one of a few countries that now have directly applied cyber capabilities in a state vs state conflict. This talk will explore notable trends across Russia's cyber-enabled capabilities, including introducing a novel addition to the list of cyber-enabled Russian organizations.


This talk will explore several trends including an emerging powerhouse amongst existing capabilities, adaptations to initial access capabilities, the incorporation of malware-as-a-service and an examination of the impact of wartime conditions to cyber-enabled operations."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 29/05/2026
With about a week to go until our conference, we would like to once again thank all of our sponsors for their support. Like all BSides conferences, we strive to be as accessible as possible - without the support from our sponsors, we wouldn't be able to make BSides Buffalo happen. Thank you so much!
011
BSides Buffalo @bsidesbuffalo.bsky.social · 28/05/2026
At 2pm in Introsec, Track Two, we've got Nick Regelman 🚨presenting "Looking for a mentor? You might already be one." (talk description in alt text)
"A lot of people in infosec want a mentor but don’t know how to find one. Either they don’t know how to ask or feel like they haven’t earned the right, yet at the same time, there are plenty of experienced people who want to give back but don’t think they’re qualified to mentor anyone.

This talk is for both.

We’ll talk about why mentorship in security is way harder than it should be, why “just network” is shitty advice and what mentorship actually looks like. This isn’t about titles, seniority or having everything figured out. It's about sharing what you know, listening and being willing to offer support to others along the way.

If you’re looking for a mentor, you’ll leave with practical ways to ask without feeling out of place. If you’ve been around for a while and want to give back, you’ll likely leave realizing you have way more to offer than you think."
031
BSides Buffalo @bsidesbuffalo.bsky.social · 28/05/2026
At 2pm in Track One we're excited to annouce Shounak D. and Harshit Kumar presenting "RoAM-eo & Juliet: How Roblox Solved Access Governance for Production Services". (talk description in alt text)
"Bring-your-own-IAM sounds like an attractive security policy, but in practice it's a euphemism for security debt. Every team rolls their own authorization, ignores access governance, and hopes audits never arrive. Roblox lived in that world for years. While infrastructure IAM has matured (AWS IAM, KMS, VPCs), application-layer access remains a free-for-all. Internal services—admin dashboards, data stores, bespoke tools—reinvent "who can do what" with no shared model for time-bound access, multi-tier approvals, or consistent audit. The industry is starting to name this gap, but almost nobody has built and deployed application-layer access governance across heterogeneous services at scale.



This talk tells the story of RoAM (Roblox Access Manager), a generic access governance platform built to orchestrate requests, approvals, expirations, and recertifications—and then notify downstream policy engines via an interface modeled on OpenID AuthZEN. RoAM does not replace the authorization systems teams already have. It wraps them in a shared governance layer: time-bounded access, approval workflows, centralized audit, and automatic revocation. RIF (RoAM Ingestion Framework) is the continuous data ingestion layer that keeps the authorization graph current, projecting resource ownership from upstream data sources into Guard, Roblox's ReBAC authorization service.



Expect us to cover real incidents, design mistakes, and concrete engineering patterns for turning brittle, bespoke authorization into a reusable access governance layer across services—without forcing a single policy engine or a greenfield rewrite."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 27/05/2026
Rounding out the 1pm talks, in Track Three we've got Erik Bataller presenting "From Chaos to Capability: Building Resilient AI Workflows for Personal and Business Use". (talk description in alt text)
"AI is remarkably good at producing things — blog posts, architecture diagrams, resumes, strategy documents, security proposals. Hand it a rough idea, and it will synthesize a draft faster than most teams can schedule a meeting. But that's where the honeymoon ends.

After six months of intensive daily use building real deliverables — thought leadership papers, consulting proposals, career materials, and a personal AI agent security stack — I've learned that AI without workflow discipline is just a very fast way to produce unreliable output. It forgets context mid-project. It drifts from your intent. It confidently delivers wrong answers. It has no concept of version control, traceability, or iteration management. And it will happily lose everything you've built together if you don't have a system for capturing and organizing its output.

None of this is new. These are the same challenges every technology faces when it moves from experimentation to production — and they have the same solutions. Process, governance, clear direction, and operational discipline.

Drawing on decades of building technology programs for organizations ranging from startups to Fortune 500 enterprises, I applied the same programmatic thinking to my personal and small-business AI use that I would to an enterprise capability rollout — and discovered that one person with the right workflow can achieve what used to require teams and significant budgets. In this session, I'll share the practical framework I built, the mistakes I made getting there, and the security and governance considerations that most AI users never think about until something goes wrong."
010
BSides Buffalo @bsidesbuffalo.bsky.social · 27/05/2026
Ever thought about what it's like to work in the world of digital forensics? Kicking off the afternoon in the Introsec track is local luminary Catherine Ullman with "So You Want to Be a Forensicator". (talk description in alt text)
"Imagine starting your first day on the job with a single clue: a five-second gap in the logs that absolutely shouldn’t exist. No flashy “zoom to enhance,” no instant answers—just you, a timestamp, and the question every forensicator lives for: What happened in the missing moment? This talk uses that small but mysterious anomaly to illustrate the real heart of digital forensics: quiet puzzles hidden inside ordinary data.



From that opening mystery, we’ll transition into the practical realities of entering the field. Attendees will learn how people actually break into computer forensics and the skills that matter more than pedigree. We’ll examine the core personality traits that make someone effective in this career, including the ability to clearly communicate what the evidence does (and does not) prove.



The session also sets realistic expectations for daily work in digital forensics. By the end, attendees will understand not only what it takes to become a forensicator, but what it feels like to think, work, and solve problems like one—no TV magic required, just skill, patience, and a passion for uncovering the truth hidden in the data."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 26/05/2026
Kicking off the afternoon at 1pm in Track One we've got Patrick Rost, CISSP of InfoSecurity Blueprint, LLC presenting "Breaking Down Your Incident Response Plan Before It Breaks Down on You". (talk description in alt text)
"This session breaks down the key components of an effective incident response plan and explores how to avoid common pitfalls that undermine response efforts. We will look at why many plans fail in practice, what elements make a plan usable during a real incident, and how to maintain readiness through testing and improvement: 


•	Why Incident Response Planning Matters

•	Core Components of an Effective Plan

•	Common Pitfalls and How to Avoid Them

•	Testing and Maintaining the Plan"
000
BSides Buffalo @bsidesbuffalo.bsky.social · 26/05/2026
DOOR PRIZE: Every year we have something unique for our door prize, and this year is no different. If you get your card stamped at every sponsor table you can enter to win one of these awesome "WE'RE HACKING PROUD" flags.
100
BSides Buffalo @bsidesbuffalo.bsky.social · 25/05/2026
Finishing the morning in Track Three we've got Dawn Cooper presenting "Cyborg Security". (talk description in alt text)



"So you're thinking about becoming a cyborg. It may or may not surprise you to learn that there are several of us around already, and while cybernetic enhancement can greatly improve our lives, it also has its downsides. Adaptive devices used by people with disabilities and medical conditions have been failing in unexpected ways for years, despite oversight from government bodies. Recreational implants, which are much less regulated, have even more scope for interesting bugs. On the other hand, while commercially available augments and implants require extensive testing and are almost always closed-source, it's possible to build and install your own - theoretically.


How do we secure medical devices that constantly collect telemetry? How hard would it be for someone to skim the data on that NFC chip that you got implanted in your hand? And when we find flaws in these machines, how are we meant to fix them if they're already in our bodies? Whether you're interested in joining the human IoT network for recreational purposes, want to explore, code, and create implantable devices yourself, or have a medical need for augmentation, join me for this briefing to prepare for the security and privacy implications of connecting ourselves directly to the Internet."
010
BSides Buffalo @bsidesbuffalo.bsky.social · 24/05/2026
At 11am in the Introsec track, we've got local legend Dan Brown presenting "Back To Basics - Living Off The Land With Homegrown Tools". (talk description in alt text)

"Everyone likes to talk about the latest and greatest security tools, but what if your target provides all the things you need? Living-off-the-land (LOTL) allows you to recon, pivot, and escalate using their own environment against them. Learn how knowing the basics (and knowing them well) can allow you to take your toolkit wherever you go. Some simple LOTL tools will be demonstrated.


o WE'LL COVER:

- Free online computing resources that can help learn more about the Linux operating system in readily-available environments (e.g. JSLinux running in your browser and the OneCompiler bash environment)


- Free online reference materials (manpages, Wheeler's _Secure Programming HOWTO_, Garrel's _Bash Guide For Beginners_, Shotts' _The Linux Command Line_, etc.)


- Demonstrate how ping and netcat can be used for reconnaissance


- Demonstrate how scripting with ping and netcat can be used for ping sweeps and port scans, including some more advanced features, like introducing "jitter."


- Demonstrate how environments like JSLinux provide network connectivity for those learning the basics to experiment. I will also emphasize ethics and caution when trying some of these things out by using yourself or scanme.nmap.org as a target.


- The goal is to show that you don’t need a complex setup to safely and legally gain experience with Linux basics and LOTL--just a network connection, a browser, publicly available hosts to scan, some time, and ultimately, a desire to learn."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 24/05/2026
REMINDER: There are less than two weeks to go until the next BSides Buffalo on June 6! If you're planning on joining us, and I hope you are, PLEASE register in the next few days to make sure that we've got you in the count for catering and t-shirts. Can't wait to see you there!
000
BSides Buffalo @bsidesbuffalo.bsky.social · 22/05/2026
At 11am in Track One, we've got "Toxic Combinations: How Active Directory Misconfigurations Chain into Tier‑0 Compromise" with Craig Birch. (talk description in alt text)

"Active Directory remains one of the fastest paths to full enterprise compromise, and attackers know it. Modern AD breaches rarely rely on a single “big exploit.” Instead, threat actors chain misconfigurations, delegated rights, and credential abuse into repeatable attack paths that quietly lead to Tier‑0 control.


This talk breaks down the real‑world attack techniques used to compromise Active Directory today, including credential theft methods such as Kerberoasting, AS‑REP Roasting, password spraying, NTDS.dit extraction, and DCSync. It also examines common privilege escalation and persistence techniques, including Kerberos unconstrained delegation, Golden and Silver Tickets, AD CS abuse, SIDHistory injection, and identity trust exploitation.


Attendees will leave with a practical understanding of how attackers move from initial access to full domain compromise, along with the “toxic combinations” of permissions and configurations that create hidden attack paths most defenders do not recognize until control is already lost."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 21/05/2026
Also opening at 10am - the Soldering Village! We've got a workshop with soldering equipment, helpful volunteers, and all the pieces you need to add some cool lights and battery power to your badge. Come learn about electronics and put this together!
Plain badge on the left, LED adorned badge to the right.
021
BSides Buffalo @bsidesbuffalo.bsky.social · 21/05/2026
At 10:00am in Track Three, we have our first Hacking Is Art talk: Matthew Mackes presenting "Vibing - Building an Audio Appliance without coding".
020
BSides Buffalo @bsidesbuffalo.bsky.social · 20/05/2026
At 10am in Track Two, the Introsec track, we've got raconteur and hacker-about-town Mark Manning presenting "Containers - what are they and why should I care". (talk description in alt text)


"What does a container do? What does it actually contain? Get back to basics and we will talk about containers from the ground up, practical uses for the aspiring security professional and maybe even learn a few new tricks."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 20/05/2026
At 10am in Track One, we've got "The Walking Dead of AD: Uncovering rare DACL-led escalation and a BloodHound-integrated tool" by Nikos Vourdas and Kyprianos Vasilopoulos. (talk description in alt text)

"This talk explores a rare yet powerful Active Directory attack path that emerges from legacy DACL misconfigurations, recycled accounts, and residual object ownership. These overlooked conditions can silently reintroduce privileges even after apparent revocation, creating persistent escalation and access opportunities. We analyze how inherited permissions, transitive group memberships, and reanimated accounts from the AD Recycle Bin can combine to bypass conventional defenses. To address this, we developed a BloodHound integration that automatically detects, visualizes, and safely simulates these hidden paths, enabling defenders to identify and remediate dormant escalation routes before they can be abused."
010
BSides Buffalo @bsidesbuffalo.bsky.social · 19/05/2026
Kicking off our Introsec track, Jonathan Lango presenting "But… Macs Don’t Get Viruses, Right? How to Start Learning macOS / iOS Security". (talk description in alt text)
"Since Macs have become more popular over the past 5+ years, malware targeting macOS has also been on the rise. And for iPhone users, commercial spyware has been becoming a more common headline, both in infosec news sources and the mainstream media.


This talk is geared toward two main target audiences—

- Rank beginners who want to learn about Apple security, even if you have no background in tech

- Windows / Linux professionals who need to deal with these devices at work, but aren’t sure where to start


HEADS UP! We will be digging into some technical topics along the way, but only after we cover enough fundamentals to help you stay afloat."
000
BSides Buffalo @bsidesbuffalo.bsky.social · 19/05/2026
Our first talk of the day in Track One, local luminary Susan Lupiani presenting "We’ve Seen This Report Before: Turning 15 Sigma Rules Into the 4 That Matter". (Talk description in alt text)
"A new threat report lands and it comes with 15 detection rules your team should deploy. But you don’t have unlimited engineering hours, and half of those rules target log sources you don’t even collect. So which ones do you actually implement?


This talk uses a real case study — the Handala/Stryker wiper attack of March 2026 and the 15 Sigma rules published in response — to walk through a two-layer prioritization framework for narrowing a detection pack down to the rules worth shipping. Layer one is a Detection Severity Framework that scores each rule on potential impact and expected accuracy. Layer two is an environment validation check: do you have the logs, do you use the technology, and is this rule redundant with what you already have? By the end, 15 becomes 4, and every decision has a clear rationale behind it."
010
BSides Buffalo @bsidesbuffalo.bsky.social · 18/05/2026
The first talk of the day in our Soldering Village will be Michael Kelley presenting "Solder a Pi for Your Wi-fi Pwning Pwnagotchi!"
000
BSides Buffalo @bsidesbuffalo.bsky.social · 18/05/2026
JOB SEEKERS: We're going to have a Career Village for the very first time this year at BSides Buffalo - come join Russel Bassarath and Anthony Bray from Buffalo Center for Arts and Technology (BCAT) for a workshop and resume review!
022
BSides Buffalo @bsidesbuffalo.bsky.social · 17/05/2026
JUST THREE WEEKS TO GO! Three weeks from now, on June 6, we'll be celebrating the fifth annual BSides Buffalo conference - come join us for a full day of hacking, technical talks, capturing of flags, soldering, lockpicking, stickers and shenanigans for just twenty American dollars. See you there!
eventbrite.com
BSides Buffalo 2026
BSides Buffalo is a one-day information security and technology conference for the Western New York community. All are welcome!
010
BSides Buffalo @bsidesbuffalo.bsky.social · 11/05/2026
Happy Monday! Because a few people have asked, this is the inspiration for this year's "We're Hacking Proud!" tagline - Buffalo's tourism campaign from the bleak days of the 1980s. www.youtube.com/watch?v=46Iv...
youtube.com
Buffalo We're Talking Proud PSA 1980
YouTube video by Retrontario
100
BSides Buffalo @bsidesbuffalo.bsky.social · 10/05/2026
First timer? Wondering what to bring to be prepared for BSides? Here are some suggestions -- if you think we missed anything, add them to the comments here! www.bsidesbuffalo.org/what-should-...
bsidesbuffalo.org
What should I bring to BSides Buffalo? – BSides Buffalo
010
BSides Buffalo @bsidesbuffalo.bsky.social · 08/05/2026
Excited to announce our newest Gold Sponsor for our 2026 event, first-time sponsor M&T Bank! M&T is a Buffalo institution, a community bank that’s driven to help, and to encourage and enable their customers, colleagues and communities to thrive. So excited to have them supporting our event!
MTB Logo
100
BSides Buffalo @bsidesbuffalo.bsky.social · 04/05/2026
Excited to announce our latest Silver Sponsor for our 2026 event, first time sponsors and longtime Buffalo institution Rich Products Corporation! Rich’s is a family-owned food company that offers innovative products and expert solutions to global food professionals.
Rich's logo.
110
BSides Buffalo @bsidesbuffalo.bsky.social · 01/05/2026
Excited to announce that we've published the session schedule for this year's BSides Buffalo conference - 24 sessions across three tracks and a couple of bonus sessions elsewhere in the conference, along with lockpicking, soldering, a CTF, and a career village. Our biggest event ever! Details here:
bsides-buffalo-2026.sessionize.com
BSides Buffalo 2026
Mobile app & schedule website
000
BSides Buffalo @bsidesbuffalo.bsky.social · 24/04/2026
Excited to announce our latest returning Gold Sponsor for 2026, our friends at the Niagara University program in Information Security and Digital Forensics.
Niagara University logo.
120
BSides Buffalo @bsidesbuffalo.bsky.social · 20/04/2026
Happy Monday, all! If you're planning on coming to our event on June 6, I'd suggest getting your tickets soon -- we sold out completely the last two years. Make sure you reserve your spot for a day of hacking, lockpicking, soldering, and swag for just twenty American dollars.
eventbrite.com
BSides Buffalo 2026
BSides Buffalo is a one-day information security and technology conference for the Western New York community. All are welcome!
010
BSides Buffalo @bsidesbuffalo.bsky.social · 17/04/2026
A huge thank you to our latest sponsor, our friends at CCADE- Canisius Center for Analytics and Data Ecosystems. CCADE is an initiative that fosters collaboration between academic and industry professionals to support data-driven education, research, and workforce development in analytics.
100