2026 Talks

We are excited to announce our talks for BSidesTC 2026!

We Keep Us Safe – Ian Coldwater
Who keeps us safe? We keep us safe.

It’s a rallying cry for community defenders, and for us working in security, it’s the job description. All of us are fighting uphill battles with short resources and long odds, and we have a lot to learn from each other.

From protecting our neighbors to fighting for the users, how can we do our work most effectively when we can’t count on institutions to have our backs?

This talk takes lessons from local organizing and applies them to computing, envisioning security that is rooted in a different kind of trust with a shared responsibility model built on relationships and care. Attendees will leave with practical advice for what we can do in our communities and organizations to help get us there together.

Strength in Diversity: Building an inclusive Cybersecurity Workforce – Rick Hudson
“Strength in Diversity: Building an Inclusive Cybersecurity Workforce” highlights how diversity across race, gender, sexual orientation, and neurodiversity enhances resilience, creativity, and effectiveness in cybersecurity. The presentation argues that cybersecurity is not only a technological challenge but also a human one—requiring varied perspectives to counter increasingly complex global threats.
It begins with a personal story of a gay man’s resilience, illustrating how lived experiences foster adaptability and leadership in a demanding field. Current data reveal persistent underrepresentation: only about 26% of U.S. cybersecurity professionals are women, and racial minorities and LGBTQ+ individuals remain significantly underrepresented. Nonetheless, programs promoting inclusion are growing, led by initiatives from organizations such as the Department of Homeland Security and major corporations like Microsoft.

Crowd-Sourced Truth – John Hogue
When official narratives don’t match what communities are seeing on the ground, grassroots organizations turn to crowd-sourced data to fill the gaps. But good intentions alone don’t produce reliable data. This talk walks through the key questions any community group should ask before, during, and after launching a collection effort.

Rip and Reuse: Starve the Corpos, Scavenge the Chrome – Matt Evans
As AI compute demand and (alleged) anti-trust cartel behavior drive the cost of components (and their composite creations) up, learn how to shop loss-leaders, ad-subsidized equipment, and second-hand treasures to avoid getting priced out of your hobbies (or your ability to exist in a modern world). This talk includes case studies such as: a $25 Android TV box as my “Raspberry Pi Benchmark” replacement, carrier-subsidized prepaid phones as gaming handhelds, recovering “enterprise locked” Chromebooks to get a netbook-equivalent laptop for $20-$30, how to shop surprisingly-powerful laptops for gaming with friends in the $100-$200 range, and more (as time allows). Additionally, learn how you and I can contribute to the cause via contributions to Coreboot and PostmarketOS.

Policy Doesn’t Wear Steel-Toe Boots: Human Risk on the Manufacturing Floor – Katy W
Cybersecurity programs are often designed, documented, audited, and measured from behind a desk. But in manufacturing, risk lives somewhere else: on the production floor, across shifts, inside maintenance teams, with contractors, operators, engineers, shared workstations, badge access, USB devices, vendors, and people trying to keep production running. Building resilience means taking human risk management out of the annual training module and putting boots on the ground.

The disconnect
What corporate cybersecurity thinks the environment looks like versus what actually happens in manufacturing.

Boots on the ground
Walk the floor. Talk to operators. Understand why someone bypasses a process before deciding the answer is “more training.” Explain the operational pressures: uptime, production, shift work, contractors, shared systems, physical access, OT/IT boundaries.

Human risk is bigger than phishing
Compliance vs. resilience of the people on the manufacturing floor

What works in cybersecurity – John Benninghoff
Resilient cybersecurity requires a focus on improving performance, rather than preventing negative outcomes, to be prepared when exposed to threats. But how can we best maximize our performance?

Reviewing emerging research of what works in cybersecurity, we’ll review what an evidence-based cybersecurity practice looks like, prioritizing the most effective security measures and avoiding myths and hacklore along the way, covering what works (multi-factor authentication, patch management, and cloud), what doesn’t (perimeter security appliances), and advice that should be retired (don’t use public wi-fi or USB chargers), along with the supporting research and evidence.

AI TPRM – You need a Red Team – Mea Clift

Generative AI, MCPs, Large Language Models. They’re all becoming part of our everyday lexicon in cybersecurity, with business units scrambling to implement them, vibe code them, or connect them to sensitive systems. In this presentation, we’ll discuss the concerns therein, and why instead of just doing the standard third party risk security questionnaires and exercises, you should be red teaming every LLM, MCP and agent being brought in, to ensure security is maintained when 3 racoons in a trench coat are introduced to your environment.

The Blueprint of a North Korean Attack on Open-Source – Rene

In the span of a week, LiteLLM and axios were both hit by supply chain attacks. Around the same time, the maintainer of a popular JS auth library caught repeated attempts to sneak malicious code into his project through legitimate-looking pull requests. This talk dissects that attempted attack, which closely mirrors DPRK’s “EtherHiding” technique.
We’ll walk through the full anatomy: how the malicious code is smuggled in via functional PRs and hidden in build config files where GitHub’s UI won’t show it, how the multi-stage payload deobfuscates itself using the Function constructor, and how it pulls encrypted code from blockchain “dead drops” (TronGrid, Aptos, Binance Smart Chain) that can’t be taken down like traditional C2 infrastructure.

You’ll leave knowing what these attacks look like, why blockchain hosting breaks the usual takedown playbook, and how to spot the signatures in your own repos.

Hotdish during Occupation – Jenny Wallace

During December of 2025, and January, February of 2026, federal agents conducted a series of actions in MSP area of Minnesota under “Operation Metro Surge”. This will be some examples of how some basic security hygiene, and intel activities helped provide some support from my point of view helping out of a shop in the Lavender District of Minneapolis during the occupation.

Improving supply chain security in the NPM ecosystem with trusted publishing – Dan

It’s happened too often recently: an overworked and underappreciated maintainer of a popular NPM package gets phished and exploited, and new, malware-laden versions of the package are published to NPM with their stolen credentials. If we are lucky, these packages are discovered in a matter of hours, the packages are yanked, and security advisories are published.

Responding to a huge uptick in these attacks in the past few years, NPM introduced trusted publishing as a way for projects to eliminate long-lived maintainer credentials in publishing workflows.

In this talk, I’ll overview NPM trusted publishing and how it improves the supply chain security of a package. Next, I’ll do a deep dive into how it works in an example GitHub project, analyzing why its security is better than the status quo. Lastly, I’ll share some weaknesses in the current trusted publishing implementation and next steps.

Resilient Communications and Situational Awareness without the Internet – Save It For Parts

In today’s always-online world, can people still organize, plan, and react to changes when networks go down? Can we trust the information coming from corporate networks filled with AI and murky political alliances? How can communities anticipate and react to threats both natural and otherwise? Fortunately there are many options for off-grid or home-brew services, from contacting your neighbors to forecasting the weather. This talk discusses some communication tools and techniques that communities can build and maintain themselves.