Loading…
ChiBrrCon 2027
Type: common clear filter
Friday, October 9
 

10:15am PDT

AI Meets APT: Tearing Apart a Russian Threat Actor’s Malware
LIMITED
Friday October 9, 2026 10:15am - 11:00am PDT
Limited Capacity seats available
This session breaks down a real reverse-engineering case: dissecting malware from a Russian threat actor using a mix of traditional tooling and heavy AI augmentation. It’s a practical walkthrough, not a theory talk, showing exactly how modern AI fits into an RE workflow without replacing the analyst’s judgment.


The story starts with the basics: loading the sample into Visual Studio Code, wiring Copilot into the workspace, and using it to speed up early triage, sketch hypotheses, and clean up noisy decompiled output. From there, we move into Ghidra and Ghidra MCP, using AI-assisted explanations to untangle obfuscated functions, unpack encoding routines, and clarify the malware’s execution flow.


Next, we switch to Unicorn. You’ll see how AI helped generate the scaffolding and “ballast” needed to emulate tricky code paths, build test harnesses, and sanity-check behaviors that were too opaque in static form. This combination of emulation, targeted prompting, and iterative refinement peeled back layers of the loader, payload, and C2 logic far faster than a pure manual approach.


The session covers what worked, what failed, and how to avoid AI-induced dead ends. YThe goal is simple: show a realistic, repeatable way to integrate AI with VS Code, Copilot, Ghidra, Ghidra MCP, and Unicorn to speed analysis while staying firmly in control.


By the end, you’ll walk away with a complete, end-to-end view of how AI can boost malware reverse engineering on real hostile code — not as magic, but as a force multiplier for someone who knows what they’re doing.
Speakers
avatar for Dmitry Moiseev

Dmitry Moiseev

Sr Director of Engineering, Cambium Networks
An engineer with a hacker streak who happened to grow into an executive role. I’ve worked across cloud, firmware, RF, reverse engineering, and yes, that and once even got me sued for. I see it all as part of learning how to build things that actually hold up.
Friday October 9, 2026 10:15am - 11:00am PDT
⏪️ 3. Despair (Ballroom)

10:15am PDT

The Anatomy of an AI
LIMITED
Friday October 9, 2026 10:15am - 11:00am PDT
Limited Capacity seats available
Systems designed around AI and ML technologies are growing as fast in complexity as they are in popularity. These systems, especially in production and at scale, often follow a microservice architecture with LLMs, Rag databases, MCP Servers, clients, and more all communicating over the network. That doesn't even include all the other supporting technologies that are usually needed to orchestrate and deploy complicated systems. With all this complexity comes risk. However, discussions on the risks and vulnerabilities of these AI systems often leave out one of the most important perspectives; Traditional network design & security.  

During this session we will investigate the technologies and risks associated with running production AI systems by walking through several common architectures, from the simplest to among the most complicated. We will discuss vulnerabilities that are unique to these systems, such as prompt injection, as well as more traditional network and application security risks.  Also in focus is the attacker perspective. We will discuss how attackers view these systems, including their infrastructure targets, priorities, and motivations. Sprinkled throughout this conversation are real examples from penetration tests, red teams, and public disclosures.  This presentation might be a good fit for attendees interested in learning more about the network and systems architecture behind AI and ML systems, their security vulnerabilities and risks, or those who want to hear a few war stories on exploiting AI systems.
Speakers
avatar for Alec Gleason

Alec Gleason

Security Architect, Cisco
I am a Security Architect & Consultant that has been working at Cisco for over 10 years. I focus on Application, AI, Cloud, and IOT security. I have performed penetration tests, architecture
assessments, and red team engagements against systems of all sizes and
complexities... Read More →
Friday October 9, 2026 10:15am - 11:00am PDT
⏺️ 6. Harmony (Auditorium) Hermann Hall Conference Center, 3241 S Federal St, Chicago, IL 60616, USA

11:15am PDT

Building an AI-First Center of Excellence: From Legacy Transformation to Enterprise-Wide AI Capability
LIMITED
Friday October 9, 2026 11:15am - 12:00pm PDT
Limited Capacity seats available
Artificial intelligence has reached unprecedented capability levels—foundation models demonstrate sophisticated reasoning, generation, and autonomous action across diverse domains. Yet most organizations struggle to unlock this potential, constrained by fragmented implementations, unclear governance frameworks, and inability to scale beyond isolated experiments. The gap between AI's technical maturity and organizational readiness represents the defining competitive challenge.
Old National Bank's Transformation Office has pioneered an AI-First approach through establishment of a Center of Excellence addressing five strategic pillars: Vision, Governance, Culture, Capabilities, and Enablement. This framework positions AI not as a helper, but as how work fundamentally gets done.
Our presentation will demonstrate practical implementation through real-world examples including custom AI assistants optimized for individual roles, AI-driven intake processes with automated risk rating and routing, and LLM orchestration frameworks employing specialized models for generation, evaluation, and human-in-the-loop oversight. These implementations illustrate building new processes for AI-integrated operations rather than retrofitting legacy workflows.
Critical to sustainable AI capability is governance that enables innovation without creating impediments. We will share our approach to phased implementation with control gates, capability-level risk assessment addressing core AI functions, and productized architectural patterns including RAG for Agents that enable reuse across multiple use cases.
Conference attendees will gain actionable insights into establishing AI Centers of Excellence that balance competitive imperatives with responsible risk management. Our framework addresses the challenge of preventing overly rapid adoption with insufficient controls while maintaining organizational agility and innovation capacity.
This presentation offers enterprises a roadmap for transforming from AI experimentation to enterprise-wide AI capability, positioning organizations to compete effectively in an AI-native marketplace while maintaining operational resilience and structured governance appropriate to deployment scope.
Speakers
avatar for Daniel Flaningan

Daniel Flaningan

Chief Transformation Officer, Old National
I am a Chief Transformation Officer who designs and delivers enterprise systems that resolve complexity, modernize delivery, and generate durable growth. Drawing from executive experience across banking, private equity, and technology, I leverage AI, digital and data analytics and... Read More →
avatar for Meredith Winegar

Meredith Winegar

Transformation Office Director, Old National
Leads the AI Center of Excellence at Old National, passionate about organizational transformation and innovation.
Friday October 9, 2026 11:15am - 12:00pm PDT
⏺️ 6. Harmony (Auditorium) Hermann Hall Conference Center, 3241 S Federal St, Chicago, IL 60616, USA

1:15pm PDT

Gen AI Ain't Your Buddy - Neither Is Your Lawnmower
LIMITED
Friday October 9, 2026 1:15pm - 2:00pm PDT
Limited Capacity seats available
When we think about "AI" we are usually talking about Generative AI these days. And now that we can "talk" to Gen AI in plain language we're treating it like a "buddy. But Gen AI isn't your buddy, and that's ok, because neither is your lawnmower, drill, or car for that matter. They're all tools - necessary, but just tools.

This session will look at some of the pitfalls of Gen AI that we may not be taking into account when we interact with it. We'll also discuss some examples of where Gen AI shines and share some guidance on how to make the best use of Gen AI when you choose to. All this is presented in a non-technical, humorous, relatable way for AI users of all experience and skill levels.
Speakers
avatar for Bill Bernard

Bill Bernard

Owner, Between Two Firewalls
Some call him an industry veteran. Some call him a crusty curmudgeon. Bill has been in Cybersecurity from before we called it that, and his career has covered the spectrum from IT to IS practitioner and architect, through to VAR and vendor technical seller, to presales team builder... Read More →

Friday October 9, 2026 1:15pm - 2:00pm PDT
⏺️ 6. Harmony (Auditorium) Hermann Hall Conference Center, 3241 S Federal St, Chicago, IL 60616, USA

1:15pm PDT

Securing Vibe Coding - What You Need to Know
FULL
Friday October 9, 2026 1:15pm - 2:00pm PDT
Limited Capacity full
This presentation is designed to get attendees vibe coding securely.  It will show them how vibe coding works, demonstrate how vibe coding can create issues, like added surface area and orphaned code and then discuss and demonstrate how to fix them.
Here is a brief outline of the presentation:
  • Introduction – what is vibe coding
  • Discussion of prompts and intent
  • Demonstration of vibe coding and prompting app generation
  • Demonstration of how vibe coding creates security issues
  • Discussion of the security issues created by vibe coding and how to prevent, mitigate and repair them
  • Demonstration of how to fix vibe-coding created security issue
Note that most of the presentation will not require significant coding experience.  A short bit of time will be spent showing where the created issue is within the code, but this will be presented in a way to be informative to those that can code, but also not lose those who cannot code.   Audience suggestions will be requested regarding what to make for the vibe coding example.
Speakers
JS

Jeremy Straub

Associate Professor, Center for Cybersecurity, University of West Florida
Dr. Jeremy Straub is an associate professor at the University of West Florida Center for Cybersecurity. He holds two B.S. Degrees (business and IT), two M.S. Degrees (MBA and MS in Computer Systems and Software Design), a Ph.D. in Scientific Computing and Graduate Certificates in... Read More →
Friday October 9, 2026 1:15pm - 2:00pm PDT
↖️ 1. Fear (Alumni Lounge) Hermann Hall Conference Center, 3241 S Federal St, Chicago, IL 60616, USA

2:15pm PDT

AI in the Wild: Real-World Risk, Real-Time Response
LIMITED
Friday October 9, 2026 2:15pm - 3:00pm PDT
Limited Capacity seats available
AI is no longer a future threat—it’s a present reality. From deepfakes and data poisoning to shadow IT and vendor vulnerabilities, AI is reshaping the cybersecurity landscape in ways that demand urgent attention. In this session, Lori Kevin, VP of Security & Compliance at IMO Health, shares real-world breach scenarios, their business and enterprise impact, and governance frameworks designed to stay ahead of these threats. Attendees will walk away with actionable strategies for evaluating AI tools, securing sensitive data, and building resilient security programs that align with SOC 2, HIPAA, and HITRUST. Expect to learn more about field-tested insights for practitioners ready to confront AI risk head-on.


Speakers
avatar for Lori Kevin

Lori Kevin

VP Security & Compliance, IMO Health
Lori Kevin is a seasoned cybersecurity executive with over two decades of experience leading enterprise security, risk management, and compliance programs across highly regulated industries. As Vice President of Security & Compliance, Lori drives strategic initiatives that safeguard... Read More →
Friday October 9, 2026 2:15pm - 3:00pm PDT
⏺️ 6. Harmony (Auditorium) Hermann Hall Conference Center, 3241 S Federal St, Chicago, IL 60616, USA

2:15pm PDT

From Cyber Metrics to Cyber Economics: Proving the Value of Security and leveraging AI as Your Second Brain
FULL
Friday October 9, 2026 2:15pm - 3:00pm PDT
Limited Capacity full
Security leaders have long struggled to balance speed with rigor: CISOs must make rapid calls on investments, incident response, and program direction, then justify those decisions to executives, boards, and regulators. Artificial Intelligence promises not just faster answers but defensible ones. In this presentation, drawing on experience as a penetration tester, auditor, regulator, and program leader, we will explore how AI can serve as a “second brain” for security decision-making tapping in various sources of information. We’ll show how AI-driven analysis can cut through noise, reveal where risk is actually reduced, and help translate technical data into financial and operational terms. Beyond the hype, we’ll address practical realities: What works today? Where are the pitfalls? Attendees will walk away with strategies to use AI not only for efficiency, but as a force multiplier for risk accountability and executive alignment.


Key Takeaways are:
- How AI can accelerate and defend security program decisions 
- Lessons from real-world use cases (metrics, risk quantification, regulatory oversight) 
- Governance practices for responsible AI adoption in security programs


Participants will hear concrete examples of AI applied in action: how AI-driven analytics can cut through noise to highlight latest threat information, how machine learning models are improving speed of evaluating relevance, and how automation is reducing the burden on security teams facing information overload and response time pressure. 
Speakers
avatar for Sebastiaan Gybels

Sebastiaan Gybels

SVP Cybersecurity, Northern Trust
Sebastiaan Gybels is an accomplished technology leader with over 20 years of experience in Cybersecurity and IT. In his current role with Northern Trust, he is leading the automation of cyber governance and identifying key initiatives to align with the risk appetite of the organization. As the Ch... Read More →
avatar for Josh McChristian

Josh McChristian

Senior Lead Cyber GRC, Northern Trust
I’m a cybersecurity and risk management leader with 20+ years of experience helping organizations navigate complexity, build trust, and make confident, value-aligned decisions. My expertise spans cyber risk, governance, regulatory compliance, enterprise architecture, and stakeholder... Read More →
Friday October 9, 2026 2:15pm - 3:00pm PDT
↖️ 1. Fear (Alumni Lounge) Hermann Hall Conference Center, 3241 S Federal St, Chicago, IL 60616, USA

2:15pm PDT

InfoSecs and the City
LIMITED
Friday October 9, 2026 2:15pm - 3:00pm PDT
Limited Capacity seats available
BurbSec Meetup: Exploring the Midwest’s Social InfoSec Scene
A current showrunner of BurbSec meetups will delve into the vibrant social InfoSec community developing across the Midwest. Drawing from real-world experiences and notable success stories, they’ll offer insights into the most productive “CitySec” frameworks in the region. You’ll gain an insider’s look at how these grassroots gatherings have fostered networking, professional development, and knowledge sharing among security enthusiasts at all levels.
By the end of this session, you’ll walk away equipped with the essential knowledge and practical tools needed to launch your own meetup or to breathe new life into an existing one. Whether you’re a seasoned InfoSec professional or just starting out, you’ll discover clear, achievable steps for building a thriving local security community. Join us to learn how to forge meaningful connections and set your “CitySec” initiative on a solid path to success!
Speakers
avatar for Johnny Xmas

Johnny Xmas

Head of Offensive Security, Sneed's Feed and Seed (Formerly Chuck's)
Johnny Xmas, a prominent figure in the Information Security community since 2002, is a board member of both Chicago's famous BurbSec communit, as well as its BSides312 conference. He's most notably recognized for his pivotal role in exposing the American TSA Master Key leaks (2014-2018... Read More →
Friday October 9, 2026 2:15pm - 3:00pm PDT
➡️ 8. Empathy (Expo)

2:15pm PDT

Probably Secure: What We Misunderstand About AI And Determinism Is Making Us Less Secure
LIMITED
Friday October 9, 2026 2:15pm - 3:00pm PDT
Limited Capacity seats available
When I say "probabilistic" outcomes, your mind likely jumps to coins or dice. However, probability also lies at the heart of the most significant development in computer science in recent memory: Artificial Intelligence. From classifying pictures of dogs to the probabilistic transformers of Generative AI, it is all based on the concept of "maybe."


GenAI is just another tech....right? Can we safely assume the same tools and mental models we have used for deterministic systems up til now are the best choice for this new world of probabilistic outcomes? 
What are the security ramifications of a probabilistic system at scale?
The good news is that many of the rule-based security tools we have been relying on for years are still there to provide us with some safety netting, if we know when to employ them and where AI can best assist us in our mission.  


Let's step way back and talk about systems that run on "most likely correct." 
Join this talk if your teams are increasingly using AI-assistants and you're trying to figure out how to keep everyone safe. Let's have an interactive conversation about why it's important that you don't treat 'probably' and 'definitely' the same way.
Speakers
avatar for Dwayne McDaniel

Dwayne McDaniel

Principal Developer Advocate, GItGuardian
Dwayne McDaniel is a Principal Developer Advocate who has been on a mission to "help people figure stuff out" for over a decade. At GitGuardian, he specializes in secrets security and non-human identity governance across cloud and DevOps environments. A frequent speaker at events... Read More →
Friday October 9, 2026 2:15pm - 3:00pm PDT
⏪️ 3. Despair (Ballroom)

2:15pm PDT

Rebooting SecOps: The Intentional SOC & Combined Arms Strategy
FULL
Friday October 9, 2026 2:15pm - 3:00pm PDT
Limited Capacity full
The modern SOC is at a breaking point, trapped in a cycle of reactive firefighting and analyst burnout. Join Matt Michalek—a 27-year U.S. Army combat veteran and cybersecurity leader—for a session on transforming security operations using the military "Combined Arms" doctrine.
Discover how to move beyond a fragmented "stack of tools" to a state of seamless integration where humans and AI act as a single, cohesive fighting force. Learn to apply the rigor of formalized "Battle Drills" to shift your team from a pinned-down defense to a proactive posture. Whether you're an executive managing the "Deep Battle" or an analyst "grunt" on the front lines, you will leave with a battle-tested roadmap for building a resilient, effective, and human-centric defensive operation.

We will explore how to:
  • Apply Military Rigor to Cyber Defense: Utilize formalized "Battle Drills" to move beyond theoretical playbooks and build instinctive, standardized muscle memory for critical incident response.
  • Leverage AI as a Force Multiplier: Move past the hype to implement AI as a "Unit of Action" that automates 80% of mundane triage, slashing engagement times.
  • Operationalize Empathy: Understand why empathy and psychological safety are not just "soft skills" but essential components of cyber readiness and sustainable cyber power.
  • Reclaim Maneuver Space: Reclaim analyst time to focus on uniquely human tasks such as proactive hunting, deep investigation, and long-term defensive strategy.



Speakers
avatar for Matt Michalek

Matt Michalek

Previously - Director, Cybersecurity Operations, Currently in between gigs.
Matt Michalek is a Cybersecurity Senior Leader and Evangelist with over 10 years of senior leadership experience and 25+ years in technology, holding CISM, CISSP, and multiple GIAC certifications. He is a visionary and technically hands-on cyber leader with a proven track record... Read More →
Friday October 9, 2026 2:15pm - 3:00pm PDT
↙️ 4. Paranoia (Hermann Lounge) Hermann Hall Conference Center, 3241 S Federal St, Chicago, IL 60616, USA

3:15pm PDT

Decoding Dyslexia: Thriving In Cybersecurity With A Different Brain
FULL
Friday October 9, 2026 3:15pm - 4:00pm PDT
Limited Capacity full
Cybersecurity is a field that thrives on diverse thinking, pattern recognition, and creative problem-solving — all strengths that often come naturally to those with dyslexia. But for many, dyslexia is still seen as a barrier instead of an asset. In this talk, we’ll challenge that perception.I’ll share a personal journey of working in cybersecurity while navigating dyslexia, offering practical strategies for success. From how to advocate for yourself in the workplace and build a support system, to using free tools like dyslexia-friendly fonts, high-contrast settings, and even ChatGPT to simplify complex logs — this session is packed with real-world advice.We’ll also reframe the narrative around dyslexia, focusing on the unique strengths it brings to our field. Whether you’re dyslexic, work with someone who is, or just want to make your team more inclusive, you’ll leave this talk with a better understanding of how neurodiversity can elevate cybersecurity.
Speakers
avatar for Caleb Grossnickle

Caleb Grossnickle

Cybersecurity Analyst 2, StoneX
I’m a Cybersecurity Analyst at StoneX, where I help protect the organization’s systems and data by investigating threats, responding to incidents, and improving overall security operations. I’ve been working in cybersecurity for several years, starting my journey with the State... Read More →
Friday October 9, 2026 3:15pm - 4:00pm PDT
↙️ 4. Paranoia (Hermann Lounge) Hermann Hall Conference Center, 3241 S Federal St, Chicago, IL 60616, USA

3:15pm PDT

Fighting Fires Without Burning Out: How AI Can Take the Heat
LIMITED
Friday October 9, 2026 3:15pm - 4:00pm PDT
Limited Capacity seats available
Burnout is reaching critical levels across cybersecurity. Alert fatigue, nonstop interruptions, mounting documentation debt, and constant urgency are pushing practitioners to the edge. AI promises relief, but only when applied to the specific cognitive and operational burdens that cause burnout in the first place.


In this session, we’ll break down what burnout actually is (psychologically and operationally) and map those drivers to security workflows such as alert triage, investigation, detection engineering, vulnerability management, and stakeholder communication. You’ll see where the real friction points are, why they drain humans so consistently, and how AI can meaningfully reduce the load when used with intention instead of buzzwords.


We’ll explore practical, real-world AI patterns that teams can adopt immediately: enrichment assistants, triage accelerators, investigation summarizers, detection documentation generators, vuln-management classifiers, and communication translators. We’ll also cover pitfalls and limitations, emphasizing where human judgment remains essential.


Through stories, examples, and optional short demos, this talk provides a grounded, practitioner-first blueprint for reducing burnout while improving the quality and sustainability of security work. Attendees will leave with realistic workflows they can implement the next day and a clearer path toward a healthier, more humane cybersecurity practice.
Speakers
avatar for Brayden Santo

Brayden Santo

Senior Security Engineer, Sprout Social
Brayden Santo is a Senior Security Engineer specializing in threat analysis, detection engineering, and security operations. He focuses on building scalable, risk-informed security programs that bridge strategic vision with practical execution. Brayden is known for translating complex... Read More →
Friday October 9, 2026 3:15pm - 4:00pm PDT
➡️ 8. Empathy (Expo)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.