BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Gotta Phish 'Em All! Novel Attack Techniques via Per
 sistent\n   Browser-in-the-Middle\n   Tags: DEF CON Official Talk | Demo ð
 Ÿ’» | Tool ðŸ› \n   When: Sunday\, Aug 9\, 10:30 - 11:30 PDT\n   Where: LV
 CCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - [1]Map\n\n   Descriptio
 n:\n\n   Browser-in-the-Middle (BitM) phishing is no longer just a researc
 h\n   curiosity. Since its 2021 formalization\, BitM has been cataloged by
 \n   MITRE as an official attack pattern\, recognized as a severe threat t
 o\n   MFA-protected web applications. Because the victim authenticates\n  
  directly through the attacker's browser rather than their own\, the\n   t
 echnique effectively bypasses most traditional forms of MFA.\n\n   This ta
 lk presents two years of research on weaponizing BitM for\n   advanced off
 ensive operations. We investigated what novel attack\n   techniques become
  possible when an attacker fully controls the browser\n   the victim inter
 acts with. This includes real-time keystroke logging\,\n   in-transit file
  interception and silent modification\, session\n   persistence that keeps
  operator access alive long after the victim\n   logs out\, and microphone
 /webcam capture achieved through\n   social-engineered browser flows.\n\n 
   The practical validation of this research is P-BitM\, the first\n   open
 -source framework for Persistent Browser-in-the-Middle\n   spear-phishing\
 , which will be released at DEF CON 34. The "Persistent"\n   in P-BitM car
 ries its full offensive meaning: a single phishing click\n   becomes a per
 sistent beachhead. We will break down our core research\,\n   demonstrate 
 these new attack vectors via demo videos\, and showcase the\n   capabiliti
 es of the tool.\n\n   https://link.springer.com/article/10.1007/s10207-021
 -00548-5\n   https://github.com/JoelGMSec/EvilnoVNC https://github.com/b3r
 ito/peeko\n\n   SpeakerBio:  Giacomo "GiacoLenzo2109" Lenzini\, EY\n\n   G
 iacomo Lenzini is an Offensive Security Specialist and Red Teamer at\n   E
 Y Italy\, and an independent security researcher. His work focuses on\n   
 adversary simulation\, red team operations\, and penetration testing. He\n
    has received recognition from organizations such as NASA and has\n   id
 entified several vulnerabilities with associated CVEs.\n\n   '\n\n   1. #L
 VCCW_Level1_Hall3\n\n\n
DTEND:20260809T183000Z
DTSTART:20260809T173000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Gotta Phish 'Em All! Novel Attack Techniques via Persistent Browser
 -in-the-Middle
END:VEVENT
END:VCALENDAR
