BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Beyond Theoretical Risk: How Cache Poisoning Escalat
 ed to\n   Critical Account Takeover in TikTokâ€™s Web Infrastructure\n   T
 ags: Bug Bounty Village | Creator Talk/Panel\n   When: Friday\, Aug 7\, 12
 :30 - 12:59 PDT\n   Where: LVCCW Level 1 Hall 3 1102 (Creator Stage 6) - [
 1]Map\n\n   Description:\n\n   Web cache poisoning is often written off as
  a class of vulnerabilities\n   with limited real-world impact. Most repor
 ted instances only expose\n   non-sensitive user metadata\, cause temporar
 y\, minor disruptions to\n   static content\, or require such narrow\, imp
 ractical conditions to\n   exploit that they rarely move beyond theoretica
 l proof-of-concept. For\n   TikTokâ€™s Vulnerability Management team\, thi
 s framing shaped our\n   initial approach to triaging cache poisoning subm
 issions for\n   yearsâ€”until two radical researcher submissions upended t
 hat\n   assumption entirely\, proving misconfigured web caches can undermi
 ne\n   every pillar of the CIA triad (confidentiality\, integrity\,\n   av
 ailability) to enable catastrophic\, scalable harm. In this talk\,\n   weâ
 €™ll start with a foundational breakdown of web cache poisoning:\n   commo
 n misconfigurations (from flawed cache key logic to mishandled\n   origin 
 headers) that enable exploitation\, and the limited impact\n   profiles th
 at led our team (and many in the bug bounty ecosystem) to\n   historically
  deprioritize these flaws. Weâ€™ll then deep dive into the\n   game-changi
 ng submissions that reshaped our security posture and why\n   security tea
 ms and bug bounty hunters must re-evaluate how they assess\n   cache poiso
 ning riskâ€”moving past surface-level assumptions about\n   limited impact
  to audit for hidden\, critical exploit pathways. Whether\n   you triage w
 eb vulnerabilities\, build global web infrastructure\, or\n   hunt for bug
 s at scale\, this session will equip you to spot and\n   remediate cache p
 oisoning risks before theyâ€™re weaponized against\n   your users.\n\n   S
 peakerBio:  Glendon Chong\, Tiktok\n\n   I am part of the Vulnerability Ma
 nagement team for TikTok. Over the\n   past year\, Iâ€™ve been actively in
 volved in web application\n   vulnerability triage\, collaborating with se
 curity researchers and\n   internal teams to dissect\, validate\, and reme
 diate a wide spectrum of\n   web-based threats. My work centers on bridgin
 g reporter expertise and\n   TikTokâ€™s security postureâ€”including in-de
 pth negotiations over\n   CVSS scoring\, refining triage workflows for eme
 rging attack vectors\,\n   and translating complex vulnerability details i
 nto actionable\n   remediations. I bring hands-on experience identifying g
 aps in modern\n   web architectures\, advocating for fair\, transparent ri
 sk assessment\n   with the bug bounty community\, and aligning vulnerabili
 ty\n   prioritization with our platformâ€™s commitment to user safety.\n\n
    '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T195900Z
DTSTART:20260807T193000Z
LOCATION:Bug Bounty Village - LVCCW Level 1 Hall 3 1102 (Creator Stage 6)
SUMMARY:Beyond Theoretical Risk: How Cache Poisoning Escalated to Critical 
 Account Takeover in TikTokâ€™s Web Infrastructure
END:VEVENT
END:VCALENDAR
