BSidesLuxembourg

222 Followers
475 Following
455 Posts

⚑ Secure Development Spotlight at BSides Luxembourg 2026!

𝗧π—₯𝗨𝗦𝗧 𝗔𝗑𝗗 𝗧π—₯π—”π—–π—˜π—”π—•π—œπ—Ÿπ—œπ—§π—¬: π——π—˜π—©π—˜π—Ÿπ—’π—£π—˜π—₯ π—’π—•π—¦π—˜π—₯π—©π—”π—•π—œπ—Ÿπ—œπ—§π—¬ π—œπ—‘ π—§π—›π—˜ π—”π—œ 𝗣𝗒π—ͺπ—˜π—₯π—˜π—— π—¦π——π—Ÿπ—– – Omar Rachid

As AI coding tools become deeply embedded in modern development workflows, organizations are facing a new challenge: developers are using them everywhereβ€”often without visibility, governance, or consistent security oversight. This 40-minute talk explores how the rapid adoption of AI in the SDLC is exposing critical gaps in developer security skills and enterprise risk management.

The session focuses on how security leaders can build observability into the development lifecycle to better understand both developer behavior and the security posture of AI-generated code. It covers strategies for establishing developer risk baselines, improving secure coding practices, addressing AI-induced vulnerabilities, and building governance models that scale with modern AI-assisted engineering workflows.

Omar Rachid is an Application Security Engineer with over 10 years of experience helping organizations embed security into the software development lifecycle. His work sits at the intersection of AppSec, DevOps, and AI security, with a strong focus on practical risk reduction and secure adoption of emerging technologies.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AppSec #AISecurity #SDLC #DevSecOps #SecureDevelopment

⚑ Secure Development Highlight at BSides Luxembourg 2026!

π—•π—¨π—œπ—Ÿπ——π—œπ—‘π—š π—¦π—˜π—–π—¨π—₯π—˜ π—”π—œ: π— π—”π—žπ—œπ—‘π—š 𝗧𝗛π—₯π—˜π—”π—§ π— π—’π——π—˜π—Ÿπ—œπ—‘π—š 𝗔 𝗖𝗒π—₯π—˜ 𝗣𝗔π—₯𝗧 𝗒𝗙 π——π—˜π—©π—˜π—Ÿπ—’π—£π— π—˜π—‘π—§ – Diana Waithanji

As AI systems become deeply embedded in modern applications, security can no longer be an afterthought. This 40-minute talk explores how threat modeling can be integrated directly into the AI development lifecycle, ensuring vulnerabilities are identified and addressed early using a β€œshift-left” approach.

The session introduces practical methods for conducting effective AI threat modeling sessions, including frameworks like STRIDE, relevant OWASP research, and tools that help teams systematically identify and mitigate risks unique to AI systems. Beyond methodology, it also focuses on making threat modeling collaborative and engaging, ensuring active participation from both technical and non-technical stakeholders.

Diana Waithanji is a cybersecurity professional at SAP specializing in cloud infrastructure security. She is a TechWomen USA fellow at Google and an AFRIKA KOMMT alumna, with active roles in cybersecurity standards and community initiatives promoting diversity and secure digital development.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AISecurity #ThreatModeling #SecureDevelopment #OWASP #AppSec

⚑ Story-Driven Security Talk at BSides Luxembourg 2026!

𝗙π—₯𝗒𝗠 π—£π—›π—œπ—¦π—›π—œπ—‘π—š 𝗧𝗒 π— π—œπ—§π—œπ—šπ—”π—§π—œπ—’π—‘: 𝗔𝗑 π—˜π—”π—₯π—Ÿπ—¬-𝗖𝗔π—₯π—˜π—˜π—₯ π—œπ—‘π—–π—œπ——π—˜π—‘π—§ π—₯π—˜π—¦π—£π—’π—‘π—¦π—˜ – Chris Beckman

Follow a real-world journey from chaos to control in this engaging 40-minute talk. What began as an overwhelming phishing campaign at a fast-growing AI startup quickly escalated into a serious operational threatβ€”flooding inboxes, disrupting workflows, and even triggering convincing social engineering scenarios inside the company.

Through careful analysis of email data and infrastructure tracing, this session reveals how seemingly scattered attacks were linked back to a small set of IP rangesβ€”and how an unexpected approach, combining technical investigation with responsible disclosure and human communication, led to resolution. This talk highlights a powerful lesson: not every security problem is solved with tools aloneβ€”sometimes collaboration and perspective make all the difference.

Chris Beckman is a Principal Security Engineer at TaxBit, specializing in AI security and architecture across startups and large organizations. His work emphasizes practical, real-world security decision-making shaped by hands-on experience in complex environments.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #CyberSecurity #IncidentResponse #Phishing #ThreatIntelligence #BlueTeam

⚑ Fresh Talk Alert for BSides Luxembourg 2026!

𝗦𝗣π—₯π—˜π—”π——π—œπ—‘π—š π— π—”π—Ÿπ—ͺ𝗔π—₯π—˜ π—ͺπ—œπ—§π—› 𝗨𝗦𝗕 π—žπ—˜π—¬π—¦ - π——π—’π—˜π—¦ π—œπ—§ π—¦π—§π—œπ—Ÿπ—Ÿ π—ͺ𝗒π—₯π—ž ? – Didier Barzin, Mathieu Vajou

Uncover the reality behind one of the oldest yet most effective attack vector in this eye-opening 40-minute talk. Through a real-world experiment conducted in Luxembourg, where 250 USB drives were intentionally β€œlost,” this session reveals how oftenβ€”and how quicklyβ€”people plug in unknown devices, often within minutes.

The findings highlight a critical truth: human curiosity and good intentions can still open the door to compromise. Learn why USB-based attacks continue to succeed, what motivates user behavior, and how organizations can strengthen awareness and defenses against this deceptively simple threat.

Didier Barzin is an information security enthusiast who combines defensive expertise with a hacker mindset. A strong advocate for open source and collaboration, he brings practical insights into real-world security challenges and user behavior.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #CyberSecurity #HumanFactor #USBThreats #SecurityAwareness

πŸ€– AI Security Takes the Stage at BSides Luxembourg 2026

π—§π—›π—˜ π—›π—œπ—šπ—›-π—£π—˜π—₯𝗙𝗒π—₯π— π—”π—‘π—–π—˜ π—™π—¨π—˜π—Ÿ 𝗙𝗒π—₯ π—¦π—’π—–π—œπ—”π—Ÿ π—˜π—‘π—šπ—œπ—‘π—˜π—˜π—₯π—œπ—‘π—š (𝗑𝗒π—ͺ π—œπ—‘ π—”π—œ π—™π—Ÿπ—”π—©π—’π—₯𝗦!) – Glen Sorensen

Unpack the hidden engine behind modern social engineering in this eye-opening 40-minute talk from the AI Security Village. As personal data becomes increasingly accessible, attackers are leveraging AI to scale highly targeted phishing, deepfake scams, and automated fraudβ€”turning everyday digital footprints into powerful attack vectors.

This session bridges privacy, OSINT, and cyber threat intelligence, showing how exposed data is collected, weaponized, and used against individuals and organizations. Walk away with practical strategies to reduce your exposure, detect AI-driven targeting, and strengthen defenses against the next generation of social engineering attacks.

Glen Sorensen is a Solutions Engineer at DeleteMe and a former CISO/vCISO with over 20 years of experience across security engineering, operations, and GRC. He specializes in how AI and OSINT are used in modern social engineering and helps organizations translate risk into practical defense strategies.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AISecurity #SocialEngineering #OSINT #CyberSecurity #ThreatIntelligence

Remember to use your #BSidesLuxembourg2026 Pretix ticket to book which workshops you want to attend, if you’re attending any. Signing up gives precedence.

Folks, we're proud to announce that Lunchtime (https://www.lunchtime.lu/glitter/index.asp) have chosen to help #BSidesLuxembourg2026 with catering!

BTW, check out there services!

Folks, we're proud to announce that SnT (https://www.uni.lu/snt-en/) have chosen to sponsor #BSidesLuxembourg2026 and they're our Platinum sponsors!

Merci Nastassia Sarash, du bass dΓ©i Bescht!

🧠 Another Deep Dive into AI Security at BSides Luxembourg

π—§π—›π—˜ π—–π—›π—”π—Ÿπ—Ÿπ—˜π—‘π—šπ—˜π—¦ 𝗒𝗙 π—”π—œ-𝗔𝗦-𝗔-π—¦π—˜π—₯π—©π—œπ—–π—˜ π—Ÿπ—’π—šπ—šπ—œπ—‘π—š – Jeremy Snyder

Dive into a critical 40-minute session uncovering one of the biggest blind spots in modern AI adoption. As organizations rapidly embrace AI-as-a-Service, most usage remains unmanagedβ€”creating β€œShadow AI” environments where traditional logging and security controls fall short.

This talk breaks down why existing logging approaches fail for LLM-driven systems, highlighting the disconnect between client-side and server-side visibility. Learn how to rethink logging strategies for AI, close detection gaps, and build centralized visibility that actually supports effective security monitoring and response in AI-driven environments.

Jeremy Snyder is the founder and CEO of FireTail, an AI security platform, with a background spanning cloud security, M&A at Rapid7, and over a decade in cyber and IT operations. His work focuses on securing modern API and AI ecosystems at scale.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AISecurity #CloudSecurity #LLMSecurity #CyberSecurity #ThreatDetection