Thank you to everyone who joined us for day 1 of BlueHat 2026!
We kicked things off with opening remarks from Tom Gallagher (
@secbughunter), VP of Engineering, MSRC, setting the tone for a day focused on shared responsibility, real-world impact, and the strength of the security research community. That energy carried throughout the day, with packed sessions and great conversations across the Villages.
We’re grateful to our speakers and to everyone who contributed to the conversations and learning throughout the day.
Taesoo Kim, VP of Security Research at Microsoft, explored how modern attack surfaces evolve alongside systems, highlighting the need to rethink assumptions, anticipate abuse paths, and build more resilient defenses.
Dylan Ryan-Zilavy and Cameron Vincent (
@SecretlyHidden1) demonstrated a novel privilege escalation path in Microsoft APIs, showing how access token audiences can expose overlooked attack surfaces in Entra ID.
Mario Samolis (
@MarioSamolis) and Allie L. analyzed DPRK-linked malware campaigns across npm, revealing highly structured operations and a scalable methodology for identifying malicious packages.
Aaron Crawfis covered the shift to shorter certificate lifetimes, post-quantum considerations, and how attackers can leverage certificate transparency, along with practical guidance to reduce risk.
Matt Swann showed how applying Trusted Computing Base principles helps reduce risk across complex cloud dependencies.
Henrique Pereira (
@ikkebr) and Varsha Chahal shared how they uncovered vulnerabilities in Azure Functions at scale, leading to dozens of real-world cases.
James Nix, CISSP and Jason C. discussed practical patterns for safely integrating LLMs into security workflows, including guardrails and common pitfalls.
Gautam Peri (
@HawkeyeDev) discussed recurring insecure deserialization issues and shared approaches to detect and prevent them at scale.
🙌 Thank you again to our speakers and attendees for a strong start.
Between the sessions and the conversations across the Villages, Day 1 showed the strength of this community.
Looking forward to Day 2.
#BlueHat