BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidessatx.com//bsidessatx-2026//speaker//7BQLS8
BEGIN:VTIMEZONE
TZID:US/Central
BEGIN:DAYLIGHT
DTSTART:20250613T000000
TZNAME:CDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0500
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251102T020000
RDATE:20261101T020000
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260308T030000
RDATE:20270314T030000
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Secrets That Survive Everything: Finding Runtime Credentials in Pr
 oduction Web Applications - Hemanth Gorijala
DTSTART;TZID=US/Central:20260613T135500
DTEND;TZID=US/Central:20260613T144000
DTSTAMP:20260924T012626Z
UID:pretalx-bsidessatx-2026-LRTNAL@cfp.bsidessatx.com
DESCRIPTION:A bug bounty researcher found Azure credentials in a JavaScrip
 t file and called it done. I kept going — four Azure AD credentials\, en
 ough to authenticate as the application itself. Full account takeover. The
  organization had GitLeaks in CI/CD and static secret scanning. The creden
 tials were still live. Shift-left tools scan what you commit. They do not 
 scan what you serve. Once a secret reaches production\, it disappears from
  every scanner's view.
LOCATION:Track 2 I.T.W. (Moody Rm. 101)
URL:https://cfp.bsidessatx.com/bsidessatx-2026/talk/LRTNAL/
END:VEVENT
END:VCALENDAR
