Join Us At Hacker Summer Camp

I am CVE, AMA!

Common Ground, Wed, August 5 @ 12pm PDT (Florentine F)
lanyard-rope
lanyard-clip

Presented by:

Tod Beardsley

VP, Security Research

At BSidesLV 2025, a panel of CVE experts discussed the state and future of CVE. Alas, the event ran out of time for audience questions, and caught some shade over that, so this year, BSidesLV 2026 is coming back with an “Oops all questions!” version.

Expect a short intro from the panel, then it'll turn it over to you, the audience, for questions and discussion! No topic is taboo, modulo the code of conduct, of course.


More great things from Tod

Webcasts
runZero Hour, Ep. 31: The New Rules of Risk: EPSS v5 and Agentic Adversaries
In this episode, learn how your security team can use EPSS v5 to inform daily risk decisions in a world increasingly targeted by the apex agentic...
Podcasts
From two weeks to three days: The KEV deadline debate
Former CISA insider Todd Beardsley joins Greg to reveal what it takes to land on the KEV catalog and why ultra-short patching deadlines might...
Podcasts
We need to talk about KEV with Tod Beardsley (Decipher podcast)
Tod Beardsley joins Dennis Fisher to talk about the evolution of the KEV catalog, how much value you should place on the KEV, and his new KEVology...
Reports
KEVology: an analysis of exploits, scores, & timelines on the CISA KEV
We examine the CISA KEV as an operational signal with the goal of helping infosec practitioners make defensible prioritization decisions in the...

More Summer Camp Talks!

Tue, August 4 @ 2:00pm -2:30pm (Florentine A)
Mind the Gap: Bridges, Backplanes, and BloodHound
Network segmentation is a critical final line of defense, but enforcing it at scale is an immense challenge. Join HD Moore as he reveals how attackers routinely bypass firewalls by exploiting overlooked, accidental bridges, from technician laptops and smart thermostats to out-of-band management channels and exposed OT backplanes.

In this session, HD will demonstrate how to leverage identity-correlation techniques to catch dual-homed hosts hiding across multiple networks simultaneously. Discover how to feed this raw data into open-source tools like BloodHound Open Graph to map out the true, unfiltered layout of your network.
Learn More
Wed, August 5 @ 3:35pm - 4:15pm (Oceanside A, Level 2)
Lights Out: BMC's are Still Broken and Now We Have the Receipts

HD Moore uncovers the critical, overlooked threats hiding in your server's BMCs. Drawing from a massive scan of over 140,000 devices, HD reveals that three out of four internet-facing IPMI hosts still leak passwords and system data.

Learn how attackers are using these always-on, highly trusted devices to deploy persistent firmware implants that survive OS reinstalls, and gain access to OOBscan, a brand-new open-source IPMI auditing tool released exclusively during this session.

Learn More
Sat, August 8 @ 2pm - 3pm (LVCC - L1 - Exhibit Hall West 3 - 1006, Main Track 1)
Lights Out: Out-of-Band, Out of Mind, Out of Control
In this talk, runZero's HD Moore exposes severe flaws in BMC's, demonstrating how his team extracted password hashes from 75% of 140,000 scanned targets without credentials and bypassed "random" password laws.

HD reveals how attackers can completely neutralize network segmentation by using the internal PCIe bus to pivot from a compromised host into the management VLAN, ultimately hijacking the entire fleet.

The session concludes with a live demonstration of this devastating attack chain using their new open-source tool, OOBscan.
Learn More

Book some 1:1 time

Meet with us during Summer Camp