| Time | Event |
|---|---|
| 11:00 - 11:30 | Doors open + registration |
| 11:30 - 12:00 | Welcome to The Long Con |
| 12:00 - 12:30 |
Mea culpa! What I got right about audits in 2013 and wrong in 2025
Mark Jenkins |
| 12:30 - 13:00 |
Bits about Space: How Satellites Network from the Ground to Apogee
Nik Reichert |
| 13:00 - 13:30 |
Where the Hell Is That Laptop?
rafran |
| 13:30 - 14:30 | Catered lunch |
| 14:30 - 15:00 |
Security Incident Response within Identity Federations
Dan |
| 15:00 - 16:00 |
A Photographer's Guide to Red Teaming
Mike |
| 16:00 - 16:30 | Break |
| 16:30 - 17:00 |
A policy control is still a control!
Mike Himbeault |
| 17:00 - 18:00 |
The Perimeter Is a Refresh Token: Red Teaming Entra
Will |
| Time | Event |
|---|---|
| 11:00 - 11:30 | Doors open + registration |
| 11:30 - 12:00 |
GRC Engineering: From Compliance Burden to Security Advantage
AL Sajjadieh |
| 12:00 - 13:00 |
Nobody's Mining Crypto Anymore: What Attackers Actually Want From Your CI
Magno Logan |
| 13:00 - 13:30 |
PAM: Your low-friction way to controlling access.
Travis |
| 13:30 - 14:30 | Catered lunch |
| 14:30 - 15:00 |
Harvest Now, Decrypt Later: The Quantum Threat to Conventional Security
Shab |
| 15:00 - 16:00 |
A gentle introduction to Fully Homomorphic Encryption (FHE)
Rob Keizer |
| 16:00 - 16:30 | Break |
| 16:30 - 17:30 |
Pod-tential for Disaster: Hacking Kubernetes from Pod to Cluster
Scott Miller |
| 17:30 - 18:00 | Closing remarks |
In my 2013 BSides Winnipeg talk I correctly identified the importance of code surface and simplicity for auditing and used the example of bitcoin key generation where there is no room for error and wrote my own streamlined implementation. By 2025 I was in love with hardware security modules (HSMs) as a means to make cryptography of all kinds more convenient and safe for the masses. I gave a talk at Skullspace on how bitcoin hardware wallets also have features for non-cryptocurrency use-cases, sometimes with improvements over other HSMs. One device I talked about with love was the COLDCARD by Conkite. Ooops! I will discuss how the critical seed generation flaw found in July 2026 is a hard lesson in audit complexity.
Bio: "A multi-repeat Long Con speaker, Mark is a long time Skullspace member where he founded an annual Hax festival with some Long Con inspiration."
Devices on the internet need protocols such as TCP, UDP, IP, Ethernet, and more as a common language to communicate, and satellites are no different. From weather imagery, to command & control data, to videos of astronauts performing covers of David Bowie’s “Space Oddity,” how does data get from the earth to a satellite (and back)? In this talk, I will discuss what makes up a satellite communication system. We will compare the protocols that make up the wider internet with those in space systems, like satellites, rovers, and the International Space Station. I will give an overview of the CCSDS standards that make up satellite communications, show how data gets from space agencies to satellites and back, and how those standards are developing to support future habitation of places like the moon.
Bio: "Nik Reichert is an avid enthusiast in Competitive Robotics, Cybersecurity, High-Altitude Ballooning, Radio Communications, STEM Education, and Aerospace! He has a B.Sc in Computer Engineering from the University of Manitoba and works at Magellan Aerospace Limited’s Space Systems Department. At Magellan, he specializes in the development of Communications, Avionics, Operations, and Simulation systems for various satellite missions."
Where the Hell Is That Laptop? — Finding endpoints when the IP is lying What happens when Windows Location Services is blocked, the public IP points to the wrong city, the user is behind a VPN, or the VPN is running on the router instead of the endpoint? This talk follows the evolution of Get-DeviceCoords, a PowerShell-based endpoint geolocation tool that grew from a simple Windows Location Services lookup into an evidence-fusion workflow.
Bio: "Raphael Francoeur is a Threat Detection Engineering Specialist who spends his days building detections, hunting threats, and finding increasingly unreasonable things to automate with PowerShell. His work focuses on many things, and turning messy security data into something an analyst can actually use. When he isn’t writing detections, Raphael has a habit of taking simple questions like “where is this laptop?” far beyond their original scope. The result is usually more PowerShell, more telemetry, and at least one coworker asking whether he works for a three-letter agency."
Identity federations can provide a lot of convenience for users, as they allow access to multiple service providers with a single set of credentials. However, within identity federations, a successful attack against a single identity or service provider can quickly spread to multiple institutions. To mitigate this, a federation needs good communication and coordination between its security contacts, and it is best to practice this coordination ahead of (rather than during) a real-world incident. In this talk, I will share my experience working with the InCommon Federation’s Sirtfi (Security Incident Response Trust Framework for Federated Identity) Exercise Working Group as we prepared and ran a cybersecurity incident response exercise for thirteen participating institutions.
Bio: "Dan has been a Software Engineer at North Dakota State University since 2022, specializing in Identity and Access Management. He is an active member of the InCommon Sirtfi Exercise Working Group and the broader higher education IAM community."
Photography and Red Teaming? At first glance, you might not think these two things could possibly be related. Beyond both requiring dedication and practice to excel at, there are other areas where these disciplines overlap. In this talk, Mike will explore how these two are related using examples from his portfolio and stories from his red teaming experiences.
Bio: "Mike Saunders is Red Siege Information Security’s Principal Consultant. Mike has over 25 years of IT and security expertise, having worked in the ISP, banking, insurance, and agriculture businesses. Mike gained knowledge in a range of roles throughout his career, including system and network administration, development, and security architecture. Mike is a highly regarded and experienced international speaker with notable cybersecurity talks at conferences such as DerbyCon, Circle City Con, SANS Enterprise Summit, and NorthSec, in addition to having more than a decade of experience as a penetration tester. You can find Mike’s in-depth technical blogs and tool releases online and learn from his several offensive and defensive-focused SiegeCasts. He has been a member of the NCCCDC Red Team on several occasions and is the Lead Red Team Operator for Red Siege Information Security."
Policies suck. But they are still a control. They are the most important one. They are the one you fall back on when you forget to add that deny-all rule in the firewall. This talk will develop a policy framework foundation from scratch by walking through the life of the world's most unlucky hypoethical startup.
Bio: "Mike is a mathematician by training, and a photographer, a software dev, and most recently a drone pilot by hobby. Note that security isn't anywhere in there. And yet that's my day job. Draw your own conclusions."
Enterprise compromise used to be easier to reason about. If a red team wanted access to email or internal collaboration systems, they often needed some combination of VPN access, network placement, Kerberos authentication, internal links, or on-prem Exchange reachability. Microsoft 365 changed that model. Mail, files, Teams, SharePoint, and identity data are now reachable from the internet, and access often depends less on where you are on the network and more on which cloud identity tokens you possess. This talk explains that shift from a red team perspective. We will start with the basics of Microsoft cloud identity: access tokens, refresh tokens, Primary Refresh Tokens, device trust, and Microsoft Graph. Then we will show how those concepts turn into practical Microsoft 365 tradecraft, including token reuse, registered-device abuse, long-lived refresh tokens, FOCI token family behavior, Graph-mediated SharePoint and OneDrive access, user-level tenant enumeration, and mailbox-based persistence. The goal is not to demo a single tool or assume deep OAuth expertise. Instead, this talk builds a practical mental model for how Microsoft 365 access works, how red teams abuse it, and where the limits are. We will cover what works today, what conditions make techniques fail, and why controls like device joining, Token Protection, Conditional Access, sign-in frequency, and session revocation matter. Attendees will leave understanding why modern Microsoft 365 compromise is token-first, why “being off the VPN” no longer means being out of reach, and why cloud session revocation is more complicated than simply clicking “sign out everywhere.”
Bio: "I do redteam stuff (maybe you can find my old bio?)"
"GRC Engineering" is transforming how organizations approach governance, risk, and compliance by shifting from manual, document-driven processes to automated, integrated, and engineering-focused practices. In this session, we'll explore what GRC Engineering is, why traditional GRC approaches struggle to keep pace with today's threat landscape, and how automation, AI, and security engineering can enable continuous compliance and better risk visibility. Attendees will leave with practical ideas for integrating GRC into modern security operations, reducing compliance overhead, and turning governance into a strategic advantage rather than a business burden.
Bio: "AL Sajjadieh is the Founder and CEO of "iSecureData Systems Inc." with over 20 years of experience in cybersecurity and Governance, Risk, and Compliance (GRC). He helps organizations build effective security and compliance programs using frameworks such as ISO/IEC 27001, NIST CSF, SOC 2, and HIPAA, with a focus on GRC Engineering, automation, and AI. Al also serves as a "Board Director of ISACA Winnipeg", where he supports the cybersecurity community through professional development and industry collaboration. He is passionate about making GRC more practical, scalable, and aligned with modern engineering practices."
Between 2021 and 2024, I extensively analyzed GitHub Actions runners, initially focusing on cryptocurrency mining abuses. However, that research is now the least interesting thing about Actions security Attackers have shifted from using CI for free computing resources to targeting CI systems directly. A notable example involved a security scanner. In late February, an attacker exploited a pull_request_target misconfiguration in Trivy’s workflows to obtain a privileged token. Although credentials were rotated, the process was not atomic, leaving residual access that allowed the attacker to reach Trivy’s release infrastructure. LiteLLM, which used Trivy for CI security scanning, was subsequently compromised. Weeks later, two malicious LiteLLM releases were published to PyPI, collecting cloud, SSH, and Kubernetes credentials from users who installed them. Both releases passed pip’s hash verification because they were published with legitimate maintainer credentials. This misconfiguration also affected tj-actions/changed-files and reflects the same lesson as the May npm compromise, which was released with valid SLSA provenance: the attestation was correct, and correct wasn't the same as safe. This presentation will explain how runners function, why workflow trust boundaries are less distinct than they appear, and how these attacks occurred. It will also review GitHub’s recent security measures, including dependency locking, an external egress firewall, and execution telemetry, outlining their strengths and limitations. It will also address the emerging risk of workflows providing tokens to AI agents that may process attacker-supplied input. You will gain practical guidance on improving your workflows and learn which existing controls may not withstand an attacker who has already compromised the runner.
Bio: "Magno Logan is the Head of Product Security at Fellow.ai. He spends most of his week on AppSec reviews, security architecture, and encouraging engineers to care about security in a positive way. He has contributed to the MITRE ATT&CK for Containers matrix, published research on Kubernetes, container, and CI/CD supply-chain attacks, and maintains awesome-k8s-security on GitHub. Recently, he has focused on AI security, especially prompt injection in LLM-powered applications. He is also a Cyber Training Specialist at the Bank of Canada and an Instructor and Advisor at GoHacking, a cybersecurity consulting and training company, where he has taught AppSec, secure coding and DevSecOps to over 30,000 students. He founded the OWASP Paraíba chapter in 2011. Magno has spoken at DEF CON, SecTor, NorthSec, KubeCon, NDC Security, several SANS summits, and many BSides events. This will be his third time at The Long Con."
Controlling access to sensitive systems and data is fundamental to securing organizations of any size. In this world of disparate SaaS and bespoke tools, correctly tracking, deprovisioning, and right-sizing access levels can seem insurmountable. Principle-of-least-privilege is sound in theory, but how do we enable that in the real world? This talk will take you through our real-world experiences using best-practices and state-of-the-art(ish) tools to build out and manage secure access controls one of the ripest targets there is: a startup financial institution.
Bio: "N/A (will follow up with a bio later)"
Quantum computing is emerging as a transformative technology with the potential to solve classes of problems beyond the reach of conventional computing. At the same time, a sufficiently powerful cryptographically relevant quantum computer could undermine the public-key cryptography that protects today’s digital ecosystems, including TLS, VPNs, code signing, digital certificates, authentication systems, secure email, and long-term data archives. This presentation examines the new cybersecurity risks quantum computing introduces for conventional systems, with particular focus on “harvest now, decrypt later” attacks, the exposure of RSA and elliptic-curve cryptography, supply-chain dependencies, legacy systems, and the operational challenges of cryptographic discovery and migration. The presentation will also outline a practical readiness approach for organizations: inventorying cryptographic assets, prioritizing high-value and long-lived data, engaging vendors on post-quantum roadmaps, building cryptographic agility into architectures, and planning a phased transition to post-quantum cryptography. By connecting technical risk with governance, procurement, and incident-response realities, the session will help cybersecurity leaders understand why quantum risk is not only a future cryptographic problem, but a present-day risk-management issue requiring coordinated action now.
Bio: "Shab is a Senior IT Security Analyst/Investigator at Red River College Polytechnic and an experienced cybersecurity, IT audit, and digital risk professional with more than 30 years of information technology experience across defence, government, education, financial, and international environments. His work brings together practical threat investigation, governance, compliance, application development, data analysis, and risk management, with a focus on translating complex technical issues into clear, actionable guidance for leadership, audit, and security teams. He holds a Bachelor of Science in Mathematics from the University of Manitoba and has maintained professional certifications including CISA and CISSP for more than fifteen years. Shab is also active in the responsible adoption and governance of artificial intelligence, regularly presenting on topics such as AI-enabled security controls, audit readiness, ethical deployment, and the organizational risks that arise when AI is integrated into business and security processes. He serves as Associate Director for the ISACA Winnipeg Chapter, a volunteer-led professional community that supports education, networking, and advancement in cybersecurity, IT governance, assurance, risk, and audit across the region. Through ISACA Winnipeg Chapter, he contributes to the development of emerging professionals and helps strengthen digital trust in Manitoba’s technology and security community. "
Fully Homomorphic Encryption is a mouthful. FHE allows you to encrypt data, give it to a third party, have them compute on it, all encrypted, the third party doesn't know the content, or what the result was. This talk is a gentle introduction to the topic.
Bio: "Rob lives on a forested property outside of Winnipeg MB Canada with his wife, his dog, and many musical instruments. He has a background in computer science and has been presenting technical topics for decades."
Kubernetes has become the go-to container orchestration platform in modern environments, yet real-world implementations often contain critical misconfigurations. In this talk, we’ll dive into how attackers exploit these weaknesses, from pivoting off a single compromised container to achieving cluster-wide control. After a concise review of core Kubernetes concepts, we’ll showcase live demos of common pitfalls like overly permissive RBAC, insecure API endpoints, and exposed kubelets, breaking down each step of the attack. Throughout the session, you’ll see exactly how bad actors chain these configuration flaws to move laterally, escalate privileges, and ultimately breach critical components. We’ll wrap up by discussing straightforward fixes and best practices that can thwart such attacks in your own deployments. Whether you’re a security pro or just getting started with container orchestration, you’ll come away with a clear understanding of how Kubernetes implementations get hacked and how to keep them secure. If you want to grasp container security by breaking it first, this talk is for you.
Bio: "Scott Miller is a Penetration Tester at Accenture and performs vulnerability assessments and penetration tests for Accenture's clients, with his favorite domains being infrastructure and web. He enjoys traveling and attending conferences and recruiting events related to security and/or diversity and inclusion. Scott is a musician and singer and also enjoys fitness and doing activities like whitewater kayaking, hiking, and boxing."