BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidessatx.com//bsidessatx-2026//speaker//AYZDUT
BEGIN:VTIMEZONE
TZID:US/Central
BEGIN:DAYLIGHT
DTSTART:20250613T000000
TZNAME:CDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0500
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251102T020000
RDATE:20261101T020000
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260308T030000
RDATE:20270314T030000
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Workstation Is Still the Breach: Zero Trust Tactics from Bybit to 
 Bitwarden - Evan Borysko
DTSTART;TZID=US/Central:20260613T130500
DTEND;TZID=US/Central:20260613T135000
DTSTAMP:20260924T012655Z
UID:pretalx-bsidessatx-2026-WMAZK3@cfp.bsidessatx.com
DESCRIPTION:February 2025: $1.5B stolen from one developer's laptop. April
  2026: the worm came back\, targeting ~/.claude.json and MCP configs by na
 me. Same surface\, same trust assumptions\, new vector. We'll map the deve
 loper workstation through Kindervag's Zero Trust methodology\, dissect how
  recent attacks (Bybit\, Shai-Hulud\, TeamPCP\, Bitwarden CLI) actually ex
 ecuted\, and walk through eight defender techniques on a four-level maturi
 ty ladder\, starting with what you can do solo on Monday morning.
LOCATION:Track 2 I.T.W. (Moody Rm. 101)
URL:https://cfp.bsidessatx.com/bsidessatx-2026/talk/WMAZK3/
END:VEVENT
END:VCALENDAR
