BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidesvienna.at//
BEGIN:VTIMEZONE
TZID:Europe/Vienna
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T020000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-FP9L8D@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T093000
DTEND;TZID=Europe/Vienna:20260627T113000
DESCRIPTION:In a lab environment we are going to do some hands-on sessions 
 about NTLM-Relaying and showing common protection mechanisms that are effe
 ctive against these kinds of attacks. So the workshop should be interestin
 g for sysadmins and pentesters alike.\nIt ties into our talk about modern 
 NTLM-Relaying methods and lets participants try out the attacks in a simul
 ated environment provided by us.
DTSTAMP:20260727T020723Z
LOCATION:Kleiner Saal (Workshops Track)
SUMMARY:NTLM-Relaying in Practice - Benjamin Floriani\, Patrick Pongratz
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/FP9L8D/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-K7JNE8@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T093000
DTEND;TZID=Europe/Vienna:20260627T101500
DESCRIPTION:TLDR: If you as an attacker want more tools to gain RCE and per
 sistence MCP is exactly that.\n\nAI agents are rapidly becoming a new inte
 rface to enterprise systems: they read internal knowledge\, call APIs\, an
 d execute actions through connected tools. MCP standardizes this tool acce
 ss\, but it also creates a new\, high-impact attack surface: tool executio
 n integrity.
DTSTAMP:20260727T020723Z
LOCATION:Mittlerer Saal (Track 1)
SUMMARY:MCP - Most Concerning Protocol - Paul Zenker
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/K7JNE8/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-AXV9VA@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T094500
DTEND;TZID=Europe/Vienna:20260627T101500
DESCRIPTION:AI has industrialized cybercrime. Exploit timelines collapsed f
 rom days to hours\, ransomware victims surged 389%\, and 4.6 billion stole
 n credentials flooded darknet markets. Then Claude Mythos showed autonomou
 s zero-day discovery at scale. This talk presents current threat data\, ex
 amines how AI reshapes both offense and defense\, and offers practical str
 ategies for security leaders.
DTSTAMP:20260727T020723Z
LOCATION:Kreativraum 3.1 (Track 3 - Women4Cyber/Rookie)
SUMMARY:When Machines Hack Back: How AI Rewrote the Threat Landscape in 12 
 Months - Ronke Babajide
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/AXV9VA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-AJN9TG@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T100500
DTEND;TZID=Europe/Vienna:20260627T103500
DESCRIPTION:This talk is about SBOM — the thing that has become the most 
 important compliance artifact in software development. I'll cover:\n\n* **
 Why?** A brief\, painful tour through the legal plot twists that turned th
 e SBOM from a nice-to-have into a "you literally cannot sell this product 
 without one" because too many discovered they had no idea what they were a
 ctually running.\n* **What?** what actually goes in one\, what people *thi
 nk* goes in one\, why legal and IT security want one\, and what happens if
  you vibe-coded the whole thing.\n* **Who?** What this all means for softw
 are developers\, open source maintainers who never signed up to be vendors
 \, and where the liability actually lies.\n\nExpect war stories\, regulato
 ry translation services\, a healthy amount of "I am not your lawyer\, but
 …"\, less “it depends” and a takeaway list of things you can actuall
 y do on Monday morning — whether you're shipping software\, consuming it
 \, or maintaining the one library that all of your products depend on.
DTSTAMP:20260727T020723Z
LOCATION:Dachsaal (Track 2 )
SUMMARY:It's Not You\, It's Your Dependencies: A Nerdy Lawyer's Guide to th
 e Software Supply Chain - Katharina Bisset
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/AJN9TG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-LQVWHG@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T102000
DTEND;TZID=Europe/Vienna:20260627T110500
DESCRIPTION:"Friends don't let friends upload their tradecraft to VirusTota
 l"\, but what about AI? More and more companies are integrating AI into th
 eir pipelines and workflows\, and we can see headlines of AI finding hundr
 eds of bugs everywhere online. So how can we integrate this technology int
 o our work without burning our tradecraft - is this even possible?
DTSTAMP:20260727T020723Z
LOCATION:Mittlerer Saal (Track 1)
SUMMARY:Hey Claude\, find 0days - Using AI for Vulnerability Research & Red
  Teaming - Niels Pfau
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/LQVWHG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-Z7XYAA@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T104000
DTEND;TZID=Europe/Vienna:20260627T114000
DESCRIPTION:Possibly you already know lock picking.  Possibly not.\nWe expl
 ain what happens in the lock while picking or regularly with a key.\nLock 
 picking itself\, we will show you in an own workshop at the bsides vienna.
 \n\nAdditional\, there are competitions.  For example the yearly austrian 
 championship.\nOr the belt-system\, which be presented.
DTSTAMP:20260727T020723Z
LOCATION:Dachsaal (Track 2 )
SUMMARY:Locks opened keyless the hard way - deac\, TiborElias
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/Z7XYAA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-A7AUTY@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T110000
DTEND;TZID=Europe/Vienna:20260627T114500
DESCRIPTION:Mobile app testing has many pitfalls and a structured approach 
 is needed to get a holistic picture of the attack surface. The OWASP Mobil
 e Application Security (MAS) project is able to support you with that. In 
 this talk\, you'll get a practical introduction to the MAS ecosystem which
  consists of the standard\, mobile weaknesses and how to test them. You wi
 ll see test cases and demos for iOS and Android in action for static and d
 ynamic analysis\, and learn how to perform a mobile penetration test on a 
 non-jailbroken iOS device.
DTSTAMP:20260727T020723Z
LOCATION:Kreativraum 3.1 (Track 3 - Women4Cyber/Rookie)
SUMMARY:Hacking Mobile Apps in a Structured Way - Sven Schleier
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/A7AUTY/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-C37PNQ@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T111000
DTEND;TZID=Europe/Vienna:20260627T121000
DESCRIPTION:Using Beacon Object Files (BOFs) to execute external post-explo
 itation capabilities from a C2 agent has been a staple technique in offens
 ive security for years now. The self-contained programs are great for one-
 off tasks\, such as gaining situational awareness\, elevating privileges o
 r dumping credentials. Recently\, BOFs have received a powerful upgrade th
 at allows for them to be executed in the background\, enabling long-runnin
 g real-time monitoring functionality. This talk shows how the [Conquest](h
 ttps://github.com/jakobfriedl/conquest/) framework supports Async BOFs and
  how they can benefit modern red teaming.
DTSTAMP:20260727T020723Z
LOCATION:Mittlerer Saal (Track 1)
SUMMARY:BOFs in the Background: Async object file execution in modern C2 fr
 ameworks - Jakob Friedl
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/C37PNQ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-3GKCFS@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T114500
DTEND;TZID=Europe/Vienna:20260627T120500
DESCRIPTION:For years\, the cybersecurity community has worshiped at the al
 tar of the MITRE ATT&CK® framework to track digital adversary behaviors. 
 We spend millions hardening the cloud\, fine-tuning EDRs\, and chasing zer
 o-days\, yet we consistently forget one glaring reality: an adversary can 
 just walk through the front door with a high-vis vest and a clipboard. \nE
 nter PACT (Physical Access & Control Taxonomy). Built to bridge the grand 
 canyon between meatspace and cyberspace\, PACT is an open-source\, communi
 ty-driven framework that translates physical tactics\, techniques\, and pr
 ocedures (TTPs) into a structured matrix that mirrors the MITRE ATT&CK for
 mat.
DTSTAMP:20260727T020723Z
LOCATION:Dachsaal (Track 2 )
SUMMARY:Your Firewall Won’t Save You From a Crowbar: Introducing the PACT
  Framework - Darius Beckert
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/3GKCFS/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-8Q9BGK@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T123000
DTEND;TZID=Europe/Vienna:20260627T142900
DESCRIPTION:Really short:  You can try to open a lock without a key for you
  first time.\nYou do not need own tools for that\, we provide everything y
 ou need\, also the locks.\nIf you have your own tools\, you can use it.\n\
 nAfter the workshop\, you would be ready for the Austrian championship nex
 t year.
DTSTAMP:20260727T020723Z
LOCATION:Kleiner Saal (Workshops Track)
SUMMARY:Try to open a lock keyless - deac\, TiborElias
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/8Q9BGK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-8ACFFK@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T130000
DTEND;TZID=Europe/Vienna:20260627T133000
DESCRIPTION:HackerOne Club Austria!\n\nThis club is dedicated to building a
  collaborative and welcoming hacker community across Austria. Whether you 
 are an experienced bug bounty hunter\, cybersecurity professional\, studen
 t\, or someone just getting started in ethical hacking\, you are welcome t
 o join and grow with the community.\n\nThe Austria HackerOne Club organize
 s a wide range of events including:\n- local meetups\n- live hacking sessi
 ons\n- educational workshops\n- Capture The Flag (CTF) competitions\n- con
 ference gatherings\n- world cup meetings (AWC)\n- discussions focused on b
 ug bounty\, ethical hacking\, and cybersecurity.
DTSTAMP:20260727T020723Z
LOCATION:Kreativraum 3.1 (Track 3 - Women4Cyber/Rookie)
SUMMARY:HackerOne Club Austria - Alexander Krenn
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/8ACFFK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-MAKHRG@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T130500
DTEND;TZID=Europe/Vienna:20260627T135500
DESCRIPTION:In Cybersecurity there is a narrative existing: The problem is 
 sitting in front of the screen… but is it?\n\nOur understanding of human
 s in cybersecurity is shaped by problematic metaphors\, which influence ho
 w we design security systems. The way we likely describe humans\, shapes h
 ow we approach cybersecurity.\n\nHumans are as seen as the weakest link: H
 umans are viewed as the main source of failure > Assumption: Technology is
  strong\, humans are weak\n\nHumans are seen as driven by fear: as frighte
 ned animal > Assumption: Fear and punishment drive secure behavior\n\nAnd 
 once you believe\, that the human is the problem\, you stop looking for be
 tter explanations.\n\nIn our talk we will have a deeper look at these assu
 mptions and the psychological as well as technical factors of (in)secure b
 ehavior in organizations\nCognitive biases often cause individuals to unde
 restimate rare but catastrophic risks or to place excessive trust in autom
 ation. Routine blindness may result in subtle anomalies being ignored when
  tasks become repetitive. Furthermore\, poor collaboration and information
  silos weaken collective intelligence\, while misguided prioritization—s
 uch as choosing convenience over security—can undermine defense efforts.
  Yet\, to fully leverage the strengths like pattern recognition\, intuitio
 n\, adaptive reasoning and ethical decision making\, organizations should 
 minimize human error through training\, supportive tools\, and sustainable
  working conditions\, ensuring that human intelligence can function as a p
 owerful ally in defending against digital threats.
DTSTAMP:20260727T020723Z
LOCATION:Dachsaal (Track 2 )
SUMMARY:"The Human Factor. Cybersecurity's weakest link or most adaptive de
 fense?" - Yvonne Bauer\, Wolfgang Ettlinger
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/MAKHRG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-TVJ7J8@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T131500
DTEND;TZID=Europe/Vienna:20260627T140000
DESCRIPTION:Net Shredder is a network coverage-guided fuzzer for the Linux 
 kernel. Built with a modular approach\, and focused on the ease of use\, i
 t could be adapted to fuzz other types of targets (e.g.\, usermode applica
 tions) as well. During development\, it found three remote vulnerabilities
  in the Linux kernel\, one of which resulted in CVE-2025-22037.
DTSTAMP:20260727T020723Z
LOCATION:Mittlerer Saal (Track 1)
SUMMARY:Net Shredder: Coverage-Guided Network Fuzzing for the Linux Kernel 
 - Vyacheslav "Slava" Moskvin
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/TVJ7J8/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-VA3RKU@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T133500
DTEND;TZID=Europe/Vienna:20260627T142000
DESCRIPTION:This talk explores offensive security techniques against ML and
  LLM systems\, from adversarial inputs and data poisoning to prompt inject
 ion and model extraction\, with a live local demonstration of indirect pro
 mpt injection against a self-hosted model. The attendees will learn about 
 the risks of deploying AI systems without proper security measures.
DTSTAMP:20260727T020723Z
LOCATION:Kreativraum 3.1 (Track 3 - Women4Cyber/Rookie)
SUMMARY:Offensive AI: Red Teaming Machine Learning Systems - David De Maya 
 Merras
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/VA3RKU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-USUBHG@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T140000
DTEND;TZID=Europe/Vienna:20260627T144500
DESCRIPTION:How drones (UAV’s) are the threat everyone saw coming but no 
 one acted in time. Drones are the "Gray Rhino" of modern security: a visib
 le\, high-probability threat we failed to mitigate. This talk explores how
  rapid UAV proliferation outpaced regulation\, creating critical vulnerabi
 lities in privacy and infrastructure. We’ll analyze the shift from hobby
 ist novelty to sophisticated aerial risk and the urgent need for counter-U
 AS strategies.
DTSTAMP:20260727T020723Z
LOCATION:Dachsaal (Track 2 )
SUMMARY:The sky is no longer the limit - Stephan Van Dyck
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/USUBHG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-W9MWHG@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T140500
DTEND;TZID=Europe/Vienna:20260627T145000
DESCRIPTION:Four years ago\, Project TEMPA exposed the fundamental vulnerab
 ilities within Tesla’s Bluetooth Low Energy (BLE) Passive Entry system a
 nd the Vehicle Controller Secondary (VCSEC) protocol. The research demonst
 rated how trivial it was to execute Man-in-the-Middle (MitM) relay attacks
  to unlock and drive away modern vehicles. In response\, Tesla embarked on
  a multi-year effort to overhaul its access systems. But did they actually
  fix the underlying problems\, or just change the locks?\n​In this prese
 ntation\, we are getting "phonkey" again. We will dive into a comprehensiv
 e 4-year retrospective of Tesla’s Phonekey security evolution\, dissecti
 ng the ongoing tug-of-war between seamless user experience and robust vehi
 cle security.
DTSTAMP:20260727T020723Z
LOCATION:Mittlerer Saal (Track 1)
SUMMARY:Project TEMPA: Getting Phon(e)key with Tesla Security Again - Marti
 n Herfurt
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/W9MWHG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-XX8GYX@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T150500
DTEND;TZID=Europe/Vienna:20260627T160500
DESCRIPTION:This talk examines how established macOS exploitation technique
 s can be applied to a largely overlooked attack surface: audio plugin inst
 allers. By analyzing installers from multiple major vendors\, I demonstrat
 e how common design and implementation flaws can be leveraged to achieve l
 ocal privilege escalation. The presentation covers nine CVEs across five d
 ifferent vendors\, highlighting recurring vulnerability patterns\, exploit
 ation strategies\, and the security implications for both developers and e
 nd users. Attendees will gain insight into the intersection of macOS insta
 ller security and the audio software ecosystem\, along with practical less
 ons for identifying and mitigating similar issues.
DTSTAMP:20260727T020723Z
LOCATION:Kreativraum 3.1 (Track 3 - Women4Cyber/Rookie)
SUMMARY:XPC Client Validation? Music to my ears! - Florian Haselsteiner
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/XX8GYX/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-9JKBGC@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T151500
DTEND;TZID=Europe/Vienna:20260627T160000
DESCRIPTION:"Secrecy is not a technical problem with a technical solution 
 — it is a social contract so old we've forgotten we signed it." \nBefore
  encryption. Before firewalls. Before the first wax seal was pressed into 
 a letter — someone decided that some things should not be known by every
 one. Why? \nThis workshop doesn't start with algorithms. It starts much ea
 rlier: with the question of why humans began keeping secrets at all\, what
  social and cognitive machinery that required\, and what it might mean to 
 dismantle those categories entirely.
DTSTAMP:20260727T020723Z
LOCATION:Kleiner Saal (Workshops Track)
SUMMARY:Before There Was a Password — The Philosophy and Politics of Secr
 ecy - Iryna
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/9JKBGC/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-J9QR9K@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T152000
DTEND;TZID=Europe/Vienna:20260627T160500
DESCRIPTION:New versions are usually exciting and full of possibilities\, b
 ut keeping up with every new edge-case can be a very exhausting task. Espe
 cially on Android tools go out of date quickly and the latest research pap
 er's implementation probably relies on a Java version most developers roll
  their eyes at.\n\nBut binaries? Binary tooling is forever. Well\, let's s
 ay slightly more stable. We'll explore on a practical example how to use t
 he Android Runtime to compile apps' Dalvik bytecode into binary ELFs and u
 se BinDiff for similarity analysis.
DTSTAMP:20260727T020723Z
LOCATION:Mittlerer Saal (Track 1)
SUMMARY:Back to the Binary: Revisiting Similarities of Android Apps - Jakob
  Bleier
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/J9QR9K/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-VDQMNY@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T153000
DTEND;TZID=Europe/Vienna:20260627T160000
DESCRIPTION:Active Directory remains the core identity system in most enter
 prise and governmental environments\, making it a primary target for attac
 kers after initial network compromise. Once inside a network\, adversaries
  typically focus on AD reconnaissance\, privilege escalation\, and lateral
  movement in order to gain full domain control.\n\nThis presentation explo
 res how attackers perform Active Directory enumeration using common tools 
 and techniques\, and why traditional security monitoring often fails to de
 tect these early-stage activities. It then introduces deception-based defe
 nse strategies as an effective approach for early detection of malicious b
 ehavior within identity infrastructures.\n\nThe session focuses on the use
  of Active Directory honeypots and canary tokens as proactive detection me
 chanisms. These decoy assets are designed to appear legitimate within the 
 environment while acting as high-fidelity tripwires for suspicious activit
 y. Any interaction with these objects can immediately signal potential rec
 onnaissance or compromise attempts.\n\nThrough practical examples and a si
 mulated attack scenario\, the talk demonstrates how deception techniques c
 an detect attacker behavior during directory enumeration\, credential disc
 overy\, and privilege mapping. The presentation also highlights how these 
 mechanisms integrate into Purple Team methodologies and support incident r
 esponse and forensic investigations.\n\nAttendees will gain insight into h
 ow deception technologies enhance visibility within Active Directory envir
 onments\, reduce attacker dwell time\, and enable earlier detection of ide
 ntity-based attacks before they escalate into full domain compromise.
DTSTAMP:20260727T020723Z
LOCATION:Dachsaal (Track 2 )
SUMMARY:Defending Identity Infrastructure of the Active Directory with Dece
 ption Technologies - Ahmed Hassan
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/VDQMNY/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-MZYRYC@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T160500
DTEND;TZID=Europe/Vienna:20260627T165000
DESCRIPTION:Open Source Quantum Secure VPN - QKD + PQC over WireGuard\n\nQu
 antum computers will break the encryption we rely on today\, and the clock
  is ticking. But what does that actually mean\, and what can you do about 
 it right now?\nThis talk starts from the ground up\, giving attendees an a
 ccessible introduction to the two quantum-safe building blocks: Post-Quant
 um Cryptography (PQC)\, a mathematical software-based replacement for clas
 sical key exchange\, and Quantum Key Distribution (QKD)\, a physics-based 
 approach that uses quantum optical channels to distribute keys with inform
 ation-theoretic security. No prior knowledge of quantum mechanics required
 .\nThe second half of the talk is around ARNIKA (https://github.com/arnika
 -project/arnika) and how to build a fully open-source quantum secure VPN t
 hat wraps WireGuard with both PQC (Rosenpass) and QKD (via the ETSI014 API
 ) into a single deployable solution.\n\nAttendees will leave with:\nQKD an
 d PQC fundamentals\, what they are\, how they differ\, and when to use eac
 h\nA technical dive into open-source quantum secure VPN architecture\, key
  derivation\, ETSI014 integration\, and WireGuard PSK injection\n\nTarget 
 audience:\nSecurity professionals and engineers curious about quantum-safe
  networking\, no quantum physics or crypto background needed.
DTSTAMP:20260727T020723Z
LOCATION:Dachsaal (Track 2 )
SUMMARY:Quantum Secure Communication - Andreas Neuhold
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/MZYRYC/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-78ZAJJ@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T161000
DTEND;TZID=Europe/Vienna:20260627T171000
DESCRIPTION:The answer to this question seems quite straightforward until w
 e really start to think about it. My talk is inspired by a concept of Fred
  Brooks' 1986 paper "No Silver Bullet": the difference between essential a
 nd accidental complexity of software\, only the first of which is an inher
 ent and unremovable part of it. I want to investigate if such an "essence"
  of software really exists\, and what follows if we take this view serious
 ly.
DTSTAMP:20260727T020723Z
LOCATION:Kreativraum 3.1 (Track 3 - Women4Cyber/Rookie)
SUMMARY:What is software? - Mária Kamilla Huszár
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/78ZAJJ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-UDUZHL@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T161000
DTEND;TZID=Europe/Vienna:20260627T170500
DESCRIPTION:This talk tells the story how a “let’s quickly look at the 
 files” span to a multi-day journey into ancient Windows CE filesystems a
 nd NXP processor NAND flash handling in an embedded system. Expect a deepl
 y technical talk that explains how handling single bits make a difference 
 and lets you peek into the complexity below (embedded) operating systems.
DTSTAMP:20260727T020723Z
LOCATION:Mittlerer Saal (Track 1)
SUMMARY:Windows CE Memory Archaeology - Recovering Files from Windows CE 5.
 0 on NXP i.MX28 NAND Flash - Gerhard Hechenberger
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/UDUZHL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-H7CXVP@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T165500
DTEND;TZID=Europe/Vienna:20260627T172500
DESCRIPTION:In the last few years\, I was responsible\, together with my co
 lleagues\, for the fully open-source framework "Attackbed". We developed s
 imulated networks with automated attacks and collected data for further ev
 aluation of security measures or for building machine learning datasets. O
 ne example of such an evaluation is testing the performance of LLMs when u
 sed to detect malicious behavior in logfiles.  We not only created a simul
 ation with complex attack chains but also developed several public Metaspl
 oit Exploits and an automated attack tool. I will cover all the technologi
 es and attack chains\, and provide a perspective on potential use cases fo
 r this open-source framework.
DTSTAMP:20260727T020723Z
LOCATION:Dachsaal (Track 2 )
SUMMARY:Attackbed: A Damn Vulnerable Network for Profit and Fun - Wolfgang 
 Hotwagner
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/H7CXVP/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-FHQ7JH@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T171000
DTEND;TZID=Europe/Vienna:20260627T181000
DESCRIPTION:In this talk\, we walk through a real intrusion observed in an 
 EDR-monitored enterprise environment. The case did not start with a major 
 incident or a flood of alerts. It began with two ambiguous notifications i
 n the Defender portal that the customer could not immediately classify. Wh
 at looked like a minor signal turned into a live hunt: an operator attempt
 ing fileless execution\, interacting with endpoint controls\, trying to di
 sable or bypass defenses\, and carefully pivoting through the network.
DTSTAMP:20260727T020723Z
LOCATION:Mittlerer Saal (Track 1)
SUMMARY:Zero Files\, Zero Noise: Checkmate in Three. - Jonas Plitt
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/FHQ7JH/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-bsidesvienna-0x7ea-V7JZEW@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20260627T171500
DTEND;TZID=Europe/Vienna:20260627T174500
DESCRIPTION:CBOR (RFC 8949) is a binary serialization format used in constr
 ained security-critical systems like FIDO2/WebAuthn and COSE. Despite a pr
 ecise specification\, implementations diverge across languages and systems
 \, leading to different behavior when confronted with the same input. In t
 his talk\, 11 CBOR parsers across seven languages are compared to identify
  security-relevant behavior\, such as unexpected acceptance/rejection of i
 nput\, hangs and crashes.
DTSTAMP:20260727T020723Z
LOCATION:Kreativraum 3.1 (Track 3 - Women4Cyber/Rookie)
SUMMARY:Parsing CBOR is a Minefield: A Study of CBOR Parser behavior - Jako
 b Pachmann
URL:https://cfp.bsidesvienna.at/bsidesvienna-0x7ea/talk/V7JZEW/
END:VEVENT
END:VCALENDAR
