#OOTB2025BKK - Cloud Edge Phishing: Breaking The Future Of Auth - Carlos Gómez Quintana

Adversaries have shifted from basic credential harvesting to sophisticated Adversary-in-the-Middle "AiTM" campaigns that intercept real session cookies and OAuth tokens, bypassing multi-factor defenses. This talk analyzes modern phishing techniques—including OAuth consent hijacking, browser-based MITM proxies, and token-binding attacks—and demonstrates two revolutionary serverless approaches that serve as the ultimate stealthy platforms for phishing operations. We'll explore dual cutting-edge techniques - First, Cloudflare Workers with their global CDN, free TLS, and scriptable edge logic. Second, a groundbreaking single-file approach using Express (node.js) packaged into a portable JavaScript file that can be deployed with one-click across any legitimate PaaS platform Azure, AWS, DigitalOcean, Heroku, Vercel, Railway, etc.). Together, these techniques create invisible proxies that leverage both edge computing and legitimate cloud infrastructure with zero indicators of compromise. This dual-pronged approach enables red teams to establish distributed, resilient phishing infrastructure that appears entirely legitimate to security tools and investigators, operating seamlessly across both specialized edge platforms and mainstream cloud services. The session will detail Microsoft EntraID defenses (token binding, risk-based sign- in, consent screens, and FIDO2/passkeys), followed by an in-depth examination of bypass methods using both Cloudflare Workers and multi-PaaS deployment strategies. We'll explore the end-to-end WebAuthn/passkey flow and reveal advanced MITM strategies that can subvert FIDO protections. We'll also cover methods for minimizing browser telemetry and share defensive best practices. Attendees will gain exclusive insight into newly developed methods techniques spanning both edge computing and legitimate cloud platform deployment. === Carlos Gómez Quintana is a Security Consultant at IOActive, specializing in Red Team operations and offensive security. As one of the youngest professionals to join the firm, he conducts advanced penetration testing, adversarial simulation, and security research across diverse enterprise environments. At IOActive, Carlos focuses on cutting-edge security research, including automotive security where he has developed novel attack techniques such as rollback agnostic replay attacks against vehicular systems. He regularly conducts Red Team engagements that simulate real-world adversarial scenarios for enterprise clients. Carlos is an active security researcher and contributor to Maldev Academy, where he has contributed to the phishing section and active research on malware development.

#OOTB2025BKK #COMMSECLAB - Unpacking Real Malware With Their Runtime Protection - Huy Ngo
▶︎

#OOTB2025BKK #COMMSECLAB - Unpacking Real Malware With Their Runtime Protection - Huy Ngo

#HITB2024BKK #COMMSEC D1: CoralRaider Targets Victims Data and Social Media Accounts
▶︎

#HITB2024BKK #COMMSEC D1: CoralRaider Targets Victims Data and Social Media Accounts

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

Something is jamming GPS over Europe. Here's what we found
▶︎

Something is jamming GPS over Europe. Here's what we found

From Click-Ops to Git-Ops: Rebuilding Citrix & NetScaler Worlds Every 30 Days by Richard Faulkner
▶︎

From Click-Ops to Git-Ops: Rebuilding Citrix & NetScaler Worlds Every 30 Days by Richard Faulkner

#OOTB2025BKK - The Power Of Powerlogs - Sarah Edwards
▶︎

#OOTB2025BKK - The Power Of Powerlogs - Sarah Edwards

#OOTB2025BKK Updates On Public Key Infrastructure - Alexis Hancock
▶︎

#OOTB2025BKK Updates On Public Key Infrastructure - Alexis Hancock

#OOTB2025BKK AI Agents As Your Organization's Personal Security Newsroom - Brett A.
▶︎

#OOTB2025BKK AI Agents As Your Organization's Personal Security Newsroom - Brett A.

Cybersecurity Architecture: Who Are You? Identity and Access Management
▶︎

Cybersecurity Architecture: Who Are You? Identity and Access Management

Complete GitHub Actions Course - From BEGINNER to PRO
▶︎

Complete GitHub Actions Course - From BEGINNER to PRO

#HITB2024BKK #COMMSEC D2: TPMs and the Linux Kernel: A Better Path to Hardware Security
▶︎

#HITB2024BKK #COMMSEC D2: TPMs and the Linux Kernel: A Better Path to Hardware Security

Backend web development - a complete overview
▶︎

Backend web development - a complete overview

#OOTB2025BKK - Build Your Own SOC - Kristen Huang
▶︎

#OOTB2025BKK - Build Your Own SOC - Kristen Huang

AWS Explained: The Most Important AWS Services To Know
▶︎

AWS Explained: The Most Important AWS Services To Know

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
▶︎

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

Passkeys Explained: Are They Actually Better Than Passwords?
▶︎

Passkeys Explained: Are They Actually Better Than Passwords?

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!
▶︎

Let’s Handle 1 Million Requests per Second, It’s Scarier Than You Think!

#OOTB2025BKK Agentic ProbLLMs: Exploiting Al Computer-Use And Coding Agents - Johann Rehberger
▶︎

#OOTB2025BKK Agentic ProbLLMs: Exploiting Al Computer-Use And Coding Agents - Johann Rehberger

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed
▶︎

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

I Hacked This Temu Router. What I Found Should Be Illegal.
▶︎

I Hacked This Temu Router. What I Found Should Be Illegal.