BSides Las Vegas 2026: Following the Trust Relationships Attackers Are Targeting
Blog post from GitGuardian
BSides Las Vegas 2026, the 17th annual event held alongside Black Hat and DEF CON, sold out for the first time since the pandemic and centered many discussions on how attackers exploit persistent trust relationships across modern systems. Presentations examined risks in misconfigured Google Cloud Workload Identity Federation, highly privileged CI/CD platforms, stolen browser sessions that can bypass password and MFA protections, and AI agents whose long-term memory can be manipulated to leak sensitive data. Across these examples, speakers emphasized that trust records such as credentials, sessions, DNS entries, automation identities, and stored agent context can remain valid after the circumstances that justified them have changed. The event also highlighted how AI and automation accelerate development, exploitation, and remediation, increasing the importance of narrow permissions, strong observability, reviewed trust policies, and timely access removal. Participants broadly argued that security must be approached as a systems problem involving interconnected dependencies and human behavior, with defenders needing to trace, verify, and continuously reassess trusted paths before attackers abuse them.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 2 | 5,780 | 1,243 | 245 | -15% |
| Observability | 1 | 3,175 | 737 | 186 | -24% |
| OpenClaw | 1 | 184 | 39 | 19 | -39% |
| Secrets Management | 1 | 2,244 | 480 | 132 | -13% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.