BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: From Buffer Overflow to Blackout: Chaining Attacks A
 gainst\n   Industrial Systems\n   Tags: Red Team Village | Misc\n   When: 
 Sunday\, Aug 9\, 12:00 - 13:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Re
 d Team Village) Tactic Table 2 -\n   [1]Map\n\n   Description:\n\n   This 
 presentation takes a practical\, demo-driven approach to\n   exploitation\
 , demonstrating how a buffer overflow vulnerability can\n   still serve as
  an entry point to compromise modern industrial\n   infrastructures. The s
 ession is approximately 90% hands-on and 10%\n   theoretical. The talk wal
 ks through the full attack chain\, starting\n   from initial exploitation 
 and progressing to the development and\n   execution of multistage shellco
 de. This shellcode establishes\n   communication with a remote Command and
  Control (C2) server\, retrieves\n   an additional payload\, and executes 
 it directly in memory\, bypassing\n   traditional detection mechanisms. On
 ce the environment is compromised\,\n   the session demonstrates how an at
 tacker can gain full remote control\,\n   enabling command execution\, lat
 eral movement\, and exfiltration of\n   sensitive data\, including critica
 l assets such as licenses and\n   proprietary industrial information. The 
 talk also includes interaction\n   with real-world devices such as RTUs (R
 emote Terminal Units)\, showing\n   how malicious actions can directly imp
 act industrial operations. In\n   critical scenarios\, this can lead to di
 sruptions in essential\n   services\, including failures in energy systems
  and potential\n   blackouts. The content is based on real-world pentestin
 g experience\n   conducted in an energy sector company in Brazil\, providi
 ng a practical\n   and applied perspective on risks in ICS/SCADA environme
 nts. The goal\n   is to demonstrate how modern attacks combine vulnerabili
 ties with\n   advanced techniques\, reinforcing the need for robust securi
 ty\n   strategies to protect critical infrastructure.\n\n   Speakers:Ferna
 ndo Mengali\,Thiago Cunha da Silva\n\n   SpeakerBio:  Fernando Mengali\, I
 nformation Security Specialist\n\n   Cybersecurity researcher focused on P
 entesting and AppSec\, also\n   serving as a Practical / Hands-on Speaker.
  He also dedicates part of\n   his research to critical infrastructure sec
 urity (ICS/SCADA)\,\n   exploring the intersection between classic vulnera
 bilities and\n   industrial environments. He has over 18 years of experien
 ce in\n   offensive security and practical application exploitation.\n\n  
  He has participated in research and development projects focused on\n   v
 ulnerability exploitation and offensive security.\n\n   Specialized in 0da
 y discovery and exploit development\, he has over 135\n   published CVEs a
 nd is ranked in the Top 10 contributors on VulDB\n   https://vuldb.com/use
 rs.top.\n\n   Additionally\, he has published multiple exploits and techni
 cal papers\n   publicly available https://www.exploit-db.com/?author=12136
  and\n   https://packetstorm.news/files/author/8470/1.\n\n   His work focu
 ses on real-world vulnerability exploitation\, including\n   advanced scen
 arios such as memory corruption\, buffer overflows\, and\n   complex envir
 onments.\n\n   He is the creator of https://yrprey.com\, an educational fr
 amework that\n   brings together more than 20 vulnerable applications base
 d on the\n   OWASP Top 10\, used for practical training in Application Sec
 urity and\n   Offensive Security\n   https://owasp.org/www-project-vulnera
 ble-web-application-directory.\n\n   He is also the driving force behind h
 ttps://speakfy.io\, a project\n   focused on promoting Information Securit
 y events globally.\n\n   Furthermore\, he develops application security-or
 iented tools\, such as\n   https://leapfix.co (static code analysis) and h
 ttps://fitoxs.com\, a\n   dynamic application analysis platform powered by
  artificial\n   intelligence.\n\n   SpeakerBio:  Thiago Cunha da Silva\n\n
    Thiago Cunha is an offensive security specialist\, or as he likes to\n 
   put it: “professionally paid to break into systems before someone\n   
 less friendly does.”\n\n   He currently works as a Red Team and Threat I
 ntelligence Consultant at\n   Banco Carrefour and as an instructor at the 
 Kryfal\, teaching future\n   ethical hackers not to click on suspicious li
 nks.\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20260809T205900Z
DTSTART:20260809T190000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Tac
 tic Table 2
SUMMARY:From Buffer Overflow to Blackout: Chaining Attacks Against Industri
 al Systems
END:VEVENT
END:VCALENDAR
