BSides Boulder 2024: Boosting Security in the High Desert

June 19, 2024
1 min read

TLDR:

Key Points:

  • BSides Boulder 2024 was the largest gathering to date, with over 150 attendees.
  • Topics covered at the event included AI prompt engineering, Git repository mysteries, and remote code execution via DNS.

In the fifth installment of BSides Boulder 2024, held in the high desert town of Boulder, Colorado, over 150 attendees gathered at the University of Colorado Boulder to discuss various topics related to cybersecurity.

Jason Haddix, CEO of Arcanum Security, presented on AI prompt engineering, emphasizing the importance of providing context to AI models for better results. Natalie Somersall from Chainguard discussed Git repository mysteries and the complexity of tracking ‘who’ and ‘when’ in Git logs. Heidi Metzler demonstrated remote code execution via DNS as a means of exploiting RCE vulnerabilities in systems like CMS Drupal.

Overall, a theme of secrets security emerged throughout the event, with a focus on preventing data breaches and securing applications against vulnerabilities. Attendees engaged in lively discussions and shared experiences, highlighting the importance of community collaboration in addressing cybersecurity challenges.

The event concluded with an after-party at a local brewery, underscoring the thirst for knowledge and camaraderie within the cybersecurity community.

Latest from Blog

Top 20 Linux Admin Tools for 2024

TLDR: Top Linux Admin Tools in 2024 Key points: Linux admin tools streamline system configurations, performance monitoring, and security management. Popular Linux admin tools include Webmin, Puppet, Zabbix, Nagios, and Ansible. Summary

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives