Blog

[ 24 / notes from the community ]

Write-ups, announcements, and security notes from the BSides Mumbai community.

Showing posts tagged #bsides-2024 · clear filter

How Secure Are the Companies We Trust? A BSides Mumbai Panel on Big Tech, Open Source & Privacy
18 Jul 2026· BSides Mumbai 2024 Panel

How Secure Are the Companies We Trust? A BSides Mumbai Panel on Big Tech, Open Source & Privacy

Google, Microsoft, and Apple ship the most CVEs of anyone - so is your data safer with them or with open source? The BSides Mumbai 2024 closing panel on the security-vs-privacy-vs-usability trade-off, supply-chain risk, and who's really responsible for your security.

#panel#privacy#supply-chain#open-source#bsides-2024
Read →
macOS Dylib Injection: How DYLD_INSERT_LIBRARIES Works (and Why Apple Silicon Broke It)
17 Jul 2026· Palak Bansal & Farhad Sajid (Honeywell)

macOS Dylib Injection: How DYLD_INSERT_LIBRARIES Works (and Why Apple Silicon Broke It)

The macOS answer to Windows DLL injection - how dyld loads dynamic libraries, how attackers hijack that process with DYLD_INSERT_LIBRARIES, and how SIP, AMFI, code signing, and restricted segments make it far harder on M-series Macs.

#macos#dylib-injection#red-team#reverse-engineering#bsides-2024
Read →
V2X Exploitation: How Connected & Autonomous Cars Get Hacked
16 Jul 2026· Ravi Rajput (AutoHackOS)

V2X Exploitation: How Connected & Autonomous Cars Get Hacked

From a browser bug that stopped a moving car to jamming, GPS spoofing, and IMSI-catcher attacks - a tour of connected-vehicle (V2X) security from BSides Mumbai 2024, and why car hacking is really telecom hacking.

#automotive-security#v2x#telecom#iot#bsides-2024
Read →
OSINT Tracking: How Investigators Trace Vehicles, Ships, Aircraft & Radio Signals
15 Jul 2026· Sagar Tiwari & Shubham Kumar

OSINT Tracking: How Investigators Trace Vehicles, Ships, Aircraft & Radio Signals

A field guide to open-source intelligence from BSides Mumbai 2024 - sock puppets, image reversing, license-plate and VIN decoding, maritime AIS tracking, aircraft ADS-B, and listening to live radio with web SDR.

#osint#reconnaissance#privacy#bsides-2024
Read →
Introduction to AWS Serverless Exploitation: Attacking Lambda, API Gateway & Cognito
14 Jul 2026· Sankalp Paranjpe (Intangles Labs)

Introduction to AWS Serverless Exploitation: Attacking Lambda, API Gateway & Cognito

A beginner-friendly guide to AWS serverless security - the shared responsibility model, the OWASP top 10 serverless risks, and a live demo that turns a command injection in a Lambda function into stolen AWS credentials.

#cloud-security#aws#serverless#red-team#bsides-2024
Read →
25 Years in Cybersecurity: Building Security Teams That Last
13 Jul 2026· Ravi Burlagadda (Jio Platforms)

25 Years in Cybersecurity: Building Security Teams That Last

BSides Mumbai 2024's opening keynote - Jio's Ravi Burlagadda on security as an invisible business enabler, building teams that stay, and the trends shaping the next few years.

#keynote#leadership#career#bsides-2024
Read →
Pwning IPv6 Networks: The Infamous IPv6 DNS Takeover Attack
12 Jul 2026· Shashi Prasad (RedFox Security)

Pwning IPv6 Networks: The Infamous IPv6 DNS Takeover Attack

See how the infamous IPv6 DNS takeover attack lets an attacker pwn IPv6 networks and seize a whole Windows domain in minutes, plus how to shut it down.

#active-directory#red-team#windows#bsides-2024
Read →
ChatGPT-Assisted Hacking: Pentesting Roku Apps for Fun and Profit
11 Jul 2026· Aakash Kharade (Accorian)

ChatGPT-Assisted Hacking: Pentesting Roku Apps for Fun and Profit

ChatGPT-assisted hacking meets Roku app pentesting for fun and profit. See how a tester found broken access controls, leaks, and weak watermarks.

#pentesting#iot#ai#bsides-2024
Read →
Threat Intelligence Strategies Against Malware: How to Stay a Step Ahead
10 Jul 2026· Pavan Karthick M & Abhishek Mathew (CloudSEK)

Threat Intelligence Strategies Against Malware: How to Stay a Step Ahead

Learn practical threat intelligence strategies against malware, from spotting SEO poisoning to tracing infostealers before they reach your team.

#threat-intelligence#malware#bsides-2024
Read →