Skip to content

Commit 4dd8f0a

Browse files
Added new December 2025 meetup (#184)
Co-authored-by: Dawid Ryczko <dawidry@backbase.com>
1 parent b85d24a commit 4dd8f0a

File tree

3 files changed

+76
-7
lines changed

3 files changed

+76
-7
lines changed
83.4 KB
Loading
Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
# Broken isolation. Real-world threats with ADR
2+
3+
Event date: December 9, 2025 | Backbase office | Security | macOS
4+
5+
![](assets/placeholder.webp)
6+
7+
Authors: Backbase Meetups
8+
Date: 2025-11-07T14:02:48.085Z
9+
Category: meetups
10+
11+
tags: krakow, meetup, security, securinga, ADR
12+
13+
Location: Krakow
14+
15+
---
16+
## ✅ Book your spot
17+
18+
Join us for the next Backbase meetup where we speak not only about Tech
19+
20+
[Get your ticket](https://www.meetup.com/backbase-meetups/)
21+
22+
## Speakers & Topics
23+
24+
### [Wojciech Reguła](https://wojciechregula.blog/post/)
25+
"Broken isolation - draining your credentials from popular macOS password managers"
26+
27+
In theory, theory and practice are the same. In theory, all modern macOS applications must be isolated what is enforced by notarization and sandboxing. In practice these enforcements are usually ineffective. This talk starts by explaining basic isolation assumptions and quickly shifts to exploitation. I have selected a few the most popular macOS password managers written in different technologies to prove how a low-privileged malware can abuse various tricks and 0,n-day vulnerabilities to drain your credentials.
28+
During this talk you will:
29+
- learn how macOS hardened runtime, sandboxing, and TCC app management privilege work
30+
- see 0,n-day vulnerabilities and architectonical problems I have found in popular macOS password managers
31+
- understand why software distributed via websites is sometimes more secure than from the Apple Mac App Store
32+
- see my exploits and a lot of *demos*
33+
34+
After the talk, the audience should be able to explain macOS isolation mechanisms (in)security, check their password managers for presented vulnerabilities, and effectively support their macOS blue/red teams.
35+
36+
#### BIO
37+
Wojciech is a Principal Security Specialist working at SecuRing. He specializes in application security on Apple devices and created the iOS Security Suite – an open-source anti-tampering framework. Wojciech has earned recognition as a Bugcrowd MVP and has discovered vulnerabilities in Apple (70+ CVEs), Facebook, Malwarebytes, Slack, Atlassian, and others. In his free time, he runs an infosec blog at https://wojciechregula.blog. Wojciech has shared his research at prominent conferences, including Black Hat (US, EU, Asia), DEF CON (USA), Objective by the Sea (USA), AppSec Global (Israel), TyphoonCon (South Korea), NULLCON (India), and CONFidence (Poland).
38+
39+
### [Brian Vlootman](https://www.linkedin.com/in/brianvlootman/)
40+
"Walking the path: addressing real-world threats with ADR"
41+
42+
An effective application security program focuses on applying the right tools and processes at the right moment. But you will need to rethink your security strategy beyond shift-left practices; while identifying and fixing vulnerabilities early in development before deploying to production is essential, it is simply not enough.
43+
The reality is that vulnerabilities inevitably make it into production. Many security programs overlook how to deal with attacks against the vulnerabilities that were missed. Application Detection and Response (ADR) fills this critical gap by providing real-time visibility into running applications and the ability to block attacks on application vulnerabilities in your production applications.
44+
45+
#### BIO
46+
Brian Vlootman is an experienced security leader with over 25 years in IT and cybersecurity, currently serving as CISO at Backbase. At Backbase, he focuses on implementing a defensible security architecture and driving cyber resilience for the digital banking platform.
47+
His career includes offensive and defensive roles across different tech and security domains, spanning industries like banking and healthcare. He is passionate about bridging the gap between business and technical teams to foster a collaborative approach continuously improving security. He takes a pragmatic approach to cybersecurity, emphasising measurable outcomes and the real-world effectiveness of tools and processes rather than theoretical perfection.
48+
49+
## Place and time
50+
51+
🗓️ Event Date: December 9, 2025
52+
53+
🕑 Time: 18:00
54+
55+
📍 Location: Backbase Office, High 5ive Four, Pawia 21, 31-154 Kraków
56+
57+
[See the map](https://maps.app.goo.gl/UWpwQ9zNaJBxPLEV9)
58+
59+
## Agenda
60+
61+
18:00 - 18:15 - Registration, grab a drink
62+
63+
18:20 - 19:00 - Wojciech Reguła | "Broken isolation - draining your credentials from popular macOS password managers"
64+
65+
19:05 - 19:40 - Brian Vlootman | "Walking the path: addressing real-world threats with ADR"
66+
67+
19:50 - 21:00 - Networking, food & drinks
68+
69+
[Get your ticket](https://www.meetup.com/backbase-meetups/)

content/posts/meetups/meet-js-community/post.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -57,22 +57,22 @@ Mikołaj is a software engineer at Lunar Logic specializing in back-end developm
5757

5858
🗓️ Event Date: November 20, 2025
5959

60-
🕑 Time: 17:30 PM
60+
🕑 Time: 17:30
6161

6262
📍 Location: Backbase Office, High 5ive Four, Pawia 21, 31-154 Kraków
6363

6464
[See the map](https://maps.app.goo.gl/UWpwQ9zNaJBxPLEV9)
6565

6666
## Agenda
6767

68-
17:30 - 17:45 PM - Registration, grab a drink
68+
17:30 - 17:45 - Registration, grab a drink
6969

70-
17:45 - 17:55 PM - Welcome from Backbase and meet.js
70+
17:45 - 17:55 - Welcome from Backbase and meet.js
7171

72-
18:00 - 18:20 PM - Piotr Maliga | "Angular is not that bad"
72+
18:00 - 18:20 - Piotr Maliga | "Angular is not that bad"
7373

74-
18:25 - 18:50 PM - Timofei Iatsenko | "Internalization with LinguiJS"
74+
18:25 - 18:50 - Timofei Iatsenko | "Internalization with LinguiJS"
7575

76-
18:50 - 19:25 PM - Mikołaj Bogucki | "Beyond Video Calls: A Practical Introduction to WebRTC"
76+
18:50 - 19:25 - Mikołaj Bogucki | "Beyond Video Calls: A Practical Introduction to WebRTC"
7777

78-
19:30 - 20:30 PM - Networking, food & drinks
78+
19:30 - 20:30 - Networking, food & drinks

0 commit comments

Comments
 (0)