ʇɐʞlᴉʌƎ 🇺🇦🌈 is rnbwkat

611 Followers
139 Following
602 Posts
Drummer, hacker, defender against rogue IoT (especially toasters), Skydiver, photographer, lover of fine tequilas, honeypots & Dancing Flamingos. BsidesChicago Lead ([email protected])
Views are my own, She/Her

Friendly reminder that today is both Tax Day AND the night @rnbwkat is hosting her farewell tequila tasting at Nobody's Darling. (Chicago)

One of these things will cause you pain.
The other will absolutely fix it.

Chef Nancy Duran is feeding you. Jeannie Tanner is providing the soundtrack. Kat is pouring things in an order that will surprise you and make complete sense by the end.

Also there may or may not be a flamingo in attendance. Flamingos do not pay taxes. Just saying.

https://www.nobodysdarlingbar.com/product/Tequila-Darling

Tequila, Darling!

April 15, 2026 6-8pm Join us for Tequila, Darling! —a special tasting experience hosted by Kat Fitzgerald. Enjoy a guided journey through three of Kat’s thoughtfully selected tequilas, complete with fun facts and flavor notes along the way. Food will be served as we sip, learn, and celebrate. Come raise a glass and wish Kat well as she embarks on her next chapter in Portugal! Reserve your spot

Nobody's Darling

⚙️ Technical Spotlight: New Session at BSides Luxembourg 2026

☁️💥 𝗖𝗟𝗢𝗨𝗗 𝗠𝗜𝗦𝗖𝗢𝗡𝗙𝗜𝗚𝗨𝗥𝗔𝗧𝗜𝗢𝗡𝗦: 𝗣𝗢𝗞𝗘 𝗣𝗢𝗞𝗘, 𝗕𝗥𝗘𝗔𝗖𝗛 – Kat Fitzgerald ( @rnbwkat ) 🔐☁️

Cloud breaches aren’t going away—they’re evolving.

Forget the classic “public bucket” mistakes. In 2026, real-world breaches are driven by over-privileged identities, risky SaaS integrations, forgotten environments, and insecure defaults in AI and Kubernetes. These aren’t obvious missteps—they’re systemic risks hiding in plain sight.

This talk breaks down the modern hierarchy of cloud misconfigurations based on recent breach data, then shifts the focus from reacting to preventing. Using Policy as Code (PaC), security becomes proactive—blocking risky deployments before they ever reach production.

You’ll also explore the Toxic Trilogy: assets that are publicly exposed, highly privileged, and critically vulnerable. When these overlap, breaches aren’t just possible—they’re predictable.

Kat Fitzgerald ( @rnbwkat )is a Chicago-based cybersecurity professional with a passion for cloud security, OSS, and creative defensive strategies. Known for blending technical depth with a unique personality (and a certain opinionated flamingo), Kat brings real-world insights into modern cloud risks and how to stop them before they start.

📱 Want to easily navigate all talks, villages, and stages?
Check out the official schedule on Hacker Tracker:
https://hackertracker.app/schedule?conf=BSIDESLUX2026

📅 Conference Dates: 6–8 May 2026 | 09:00–18:00
📍 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
📅 Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg2026 #CloudSecurity #Misconfiguration #Kubernetes #PolicyAsCode #DevSecOps #CyberSecurity

Six days. Six absolutely magnificent days in Porto!

The wine. The light. The tiles. The feeling of walking cobblestones that have been here longer than the country I came from. Six days of thinking - Yes! This. This is the right decision!

And then, day six.

Day six brought me a gift I did not ask for, did not want, and cannot return: an older American expat gentleman who, upon learning what I do for a living, decided that what I really needed was an explanation of cybersecurity.

To me. A Principal Security Architect. 🦩

- Who runs a global honeypot network.
- Who speaks at international conferences about this exact subject.
- Who has forgotten more about this field than this man has ever Googled.

But please. Continue. Tell me more about “the cyber.” I’ll wait. 🤷‍♀️

I want to be clear: I have lived in this city less than a week and I have already met genuinely brilliant and fun Portuguese people who engage in conversation like it’s a exchange - a radical concept where both parties occasionally speak and listen.

Revolutionary stuff.

And then there’s the expat who packed his condescension in his carry-on and brought it right across the Atlantic with him. Customs didn’t catch it. They really should have. 😳

I walked away. It was either that or say things that would make my conference keynotes look tame!

Porto, you are not responsible for him. He is an import. A defective one at that. We should check the return policy. 😡

The rest of you - I’ll see you on the other side of a very necessary glass of wine.

#BSidesCharm 2026 Track 1 Speaker Spotlight: Sat 1500 - Kat Fitzgerald @rnbwkat presenting "Cloud Misconfigurations: Oh look – Poke, Poke,, Breach!"

I can't believe it has come to this. 😟

I have lived a good life. A righteous life. I have given more than I have taken. I have held doors open for strangers. I have let people merge in traffic. I have sat through vendor demos with a smile on my face. And yes, fine - there were a couple of speeding tickets, but those were on the highway and everyone was doing it and that's not the point.

The point is: I am good.

I left everything behind. I crossed an ocean. I started fresh in this beautiful country, with its cobblestones and pastéis de nata and the kind of light that makes you believe the universe is basically on your side.

And then. THEN! 😲

I was changing the sheets on my new bed - my beautiful new bed in my beautiful new life - when my nail caught on something and before my brain could even register what was happening, before I could stop it, before God herself could intervene - I removed the tag from the mattress. 😱

The tag. The one that says DO NOT REMOVE. The one backed by the full weight of law and moral authority and whatever shadowy international body governs these things!!!

I just... I stood there holding it. A small rectangle of fabric. A federal crime. 😢

They will come for me. They always come. The Mattress Police don't sleep - ironic, given their jurisdiction - and they are everywhere!! I don't know if it's Interpol. I don't know if it's a dedicated task force. I don't know if my NovoBanco account is already flagged? 😮

I only know one thing.

I should have been more careful with the sheets.

Google, it's been real.

5.5 years. Started as a Security Engineering Manager in 2020, built Team Flamingo from scratch during COVID (because "EIP-Cloud-PMA" is not a team name, it's an acronym crying for help), and turned it into something special. When I stepped down in 2022 to go back to being a Staff Security Engineer, multiple people told me I was the best manager they'd ever had. I'll take that over any performance review!!

Became Tech Lead for revamping the third-party assessment program - got to work with exceptional FTEs and a ridiculously talented XWF team called Prime. Built things that actually worked. Left with my dignity intact and my head held high.

Now Sasha and I are headed to Porto at the end of the month, and honestly? I'm ready. New country, new challenges, and the freedom to do consulting work without someone questioning why my vendor questionnaire has 30 questions instead of 300.

If you need someone who can transform broken TPRM programs, speak at your conference, or tell you the truth about your security theater - you know where to find me!!

Cheers to what's next. 🦩
Kat & @sashatheflamingo

Starting tomorrow morning, we will spotlight each of the presentations scheduled for #BSidesCharm 2026 - posts will go in schedule order starting with Sat 04/25 - watch for them weekdays at 1000 and 1300!

Yesterday was fun.

I'm ok. It was my treadmill that tried to kill me.

Both hands got stuck between the track and the base which is hydraulic. Hard to explain. Was trapped for almost 30 mins. Was moving it to sell it.

Biggest issue was I was scared. I was in my basement and trapped stuck with a 150 lbs treadmill and could not move. I finally got one hand free after 10 mins. Then dragged it over to where I could reach a drumstick which I finally used to pry it apart before the drumstick snapped from the hydraulic pressure.

I have soft tissue and nerve damage on 3 fingers and I broke the tip of another finger - it crushed the bone and fractured it. I never knew that was a thing? 🤷‍♀️

Made new friends at the ER that were almost as frightened as me when I told them how I was trapped. Oh and yes, I sold it later that afternoon.

New story drop! “Terms and Conditions” is live!!
Come for Harvestide, stay for the part where everyone realizes they probably should’ve read page 37...

https://docs.google.com/document/d/1voXtGy74ZBHt50_X7YdaPdB2vHx3fmp3YJQ47v8mIRg/edit?usp=sharing

#Noir #CyberSecurity #EULA #PopTarts @sashatheflamingo

terms_and_conditions

Terms and Conditions Written by: Kathleen Fitzgerald (The Unfrosted Files: Book 13) (Book 12 - here) March, 2026 Arrivals Popolis International Airport — POP, as every sign helpfully reminded you - was busy in the particular way it always was at the start of Harvestide. Not frantic. Not rushed. ...

Google Docs

Sasha insisted we co-author this, and honestly, after the weekend she had, I didn’t have the authority to say no. 🦩

- We arrived at @bsidesroc as first-timers
- We left with a suspicious number of new friends, at least three inside jokes, and what I can only assume is the beginning of Sasha’s unofficial “Flamingo Ambassador Program.”

Sasha, for her part, would like it formally noted that:
- She achieved a 100% success rate in attracting delightful humans
- She was questioned about her honeypots approximately 47 times (conservative estimate)
- She may now have more friends in Rochester than I do

Post-conference, we migrated to Bitter Honey, which Sasha has classified as “Tequila Research HQ.”

Extensive… research… was conducted. 👍

Findings include:
- The tequila selection is both impressive and slightly dangerous
- The food is absolutely worth writing home about
- “Quick dinner” is a fictional concept when you’re surrounded by great people

Somewhere between the laughter, the stories, and the “just one more” moments, the night quietly turned into one of those you wish you could bottle. 💃

The flight home added a touch of airborne chaos, with turbulence strong enough to keep everyone seated, including the FAs. Sasha remained calm, mostly because she does not believe in gravity. 🛩️

And now it’s Monday. 🤷‍♀️

Sasha is back to monitoring global flamingo #honeypot operations.
I’m back to working on my Portugal move.

But we’re both still carrying that post-conference glow, the kind powered by community, connection, and just the right amount of tequila-fueled storytelling!!

Rochester, we’ll be back!!!