HOSTED EVENT | Dec 12, 2024

hack::soho-ho-ho | December 2024 | Social & Cyber Quiz

Please join us for our holiday hack::soho-ho-ho!

We’ll have the usual mix of networking, music, food and refreshments at our final hack::soho event for 2024.

Our UK IOActive team will be running a light hearted cybersecurity quiz to keep you all entertained!

hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments.

HOSTED EVENT | Oct 31, 2024

hack::soho | October 2024 | Halloween Special: Spooky Edition | Colin Cassidy

Join us for an evening of fun at this month’s hack::soho taking place 31 October, 6pm – 9pm GMT, set up to be a loose networking environment where cyber security professionals can chat, get some complimentary food & drink, and discuss rising global trends. This month’s hack::soho will feature a talk, ‘Lost in Translation: Challenges of Internationalisation,’ from Colin Cassidy, IOActive Principal Security Consultant. The abstract of the talk is below!

hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.

We hope you can join us,

IOActive team

ABSTRACT
Come and see Thrilling Terrors from Turkey, Magnificent Mongolian Monsters AND more dogs that YOU can possibly count.

This talk is an archaeological treasure hunt and collection of issues found whilst delving into obscure parts of internationalisation and Unicode. We will explore interesting characters, numbers, and language rules that take internationalisation attack move beyond traditional homoglyph attacks used as part of social engineering attacks.

A number of interesting and unusual input validation attacks, filtering bypass techniques that are available when we think beyond ASCII.

We will also cover a interesting supply chain attack, and method of hiding malicious source code within innocent looking code, and how this code can be deployed globally in a manner making it very difficult to identify

The learned audience may use this new-found knowledge to identify new and interesting attack vectors, finding themselves thinking “I remember that presentation where that bloke went on about the Mongolian vowel separators, I think I might be able to use that here!”

HOSTED EVENT | Sep 26, 2024

hack::soho | September 2024 | Lessons from the Demo Scene | Pete Beck

Join us for an evening of fun at this month’s hack::soho taking place 26 September, 6pm – 9pm GMT, set up to be a loose networking environment where cyber security professionals can chat, get some complimentary food & drink, and discuss rising global trends. This month’s hack::soho will feature a talk from Pete Beck, IOActive Director of Services. The abstract of the talk, ‘Lessons from the Demo Scene,’ is below!

hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.

ABSTRACT
The demo scene emerged in the late 1980s as coders tried to push hardware to its limits to create ever more impressive effects, often breaking fundamental assumptions on what was possible. The skills and mindset required are remarkably similar to those of good security consultants and researchers. The talk will give a brief history of the Demo Scene, and discuss specific areas where security professionals can learn from Demo Scene coders. It’s also a great excuse to reminisce about retro systems and some groundbreaking demos.

Pete Beck, IOActive Direct of Services
Pete Beck is a Director of Services at IOActive’s Cheltenham office, helping IOActive’s clients to assess and improve their security posture by identifying security-critical assets and designing effective test plans. His prior experience includes working in Information Security for the UK Government, Product Security for both Microsoft and BlackBerry, and Consultancy for banks, software houses, online retailers and developers of consumer electronics.

He still owns three computers from the 1980s, and has been a fan of the demo scene since software was distributed on floppy disks from mail order companies. His best job ever was as a professional Lego builder.

HOSTED EVENT | Sep 25, 2024

An Evening with IOActive | Ransomware Keeps Holding us Hostage. Are You Ready? | Lance Reck

Please join us and event speaker, Lance Reck, Associate Director of Services at IOActive, for a discussion on defending against ransomware.

An Evening with IOActive: Ransomware Keeps Holding us Hostage. Are you Ready?

Please join us and event speaker, Lance Reck, Associate Director of Services at IOActive, for a discussion on defending against ransomware. Drinks and heavy hors d’oeuvres will be served to attending guests. Spots are limited, so RSVP today!

ABSTRACT:

Ransomware attacks continue to escalate, posing significant threats to organizations worldwide. Let’s face it, you are going to experience this at least once in your professional career. Recently, ransomware.org surveyed hundreds of organizations and found that around 56% of businesses were unsure whether their defenses were capable enough to fend off attacks. Your ability to withstand a ransomware attack depends on your level of preparedness. This presentation explores the importance of being well-prepared to effectively defend against ransomware incidents. By establishing effective and proactive security measures, organizations can better defend against ransomware attacks and minimize their impact. If done well, these measures do not have to be costly in resources and time and have a multiplier effect on an organization.

Lance Reck, Associate Director of Services

With a balanced combination of advanced technology skills, business acumen, and talent for leadership, Lance Reck provides security-focused advisory service to IOActive’s top customers. A problem-solver continually sought by senior management to resolve the most critical business issues, he has provided mission-critical operational leadership, security assessments, and incident response expertise for major airlines, Fortune 100 retail perchants, payment industry service providers and processors, major banking institutions, and many private small to medium size organizations.

His solid knowledge of international markets and customers, includes decades of professional experience in information technology operations, information security, and software development. Lance’s operational knowledge and hands-on experience includes implementation of best practices and standards in product development, Agile and Scrum, application threat modeling, DevSecOps, ITIL, ISO 27000, CoBiT, NIST, NSA, and the Payment Card Industry (PCI), HIPAA/HITRUST, risk management, and IT governance and compliance.

HOSTED EVENT | Aug 29, 2024

hack::soho | August 2024 | Networking Event

Join us for an evening of fun at this month’s hack::soho set up to be a loose networking environment where cyber security professionals can chat, get some complimentary food & drink, and discuss rising global trends.

This hack::soho will take place 29 August, 6pm – 9pm GMT at our UK headquarters.

hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.

HOSTED EVENT | Jul 25, 2024

hack::soho | Networking Event

Join us for an evening of fun at this month’s hack::soho set up to be a loose networking environment where cyber security professionals can chat, get some complimentary food & drink, and discuss rising global trends.

This hack::soho will take place 25 July, 6pm – 9pm GMT at our UK headquarters.

hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.

HOSTED EVENT | Jul 18, 2024

Women, Wisdom & Wine | Seattle, WA | July 18

Join us on July 18th for the next Women, Wisdom & Wine in Seattle!

Women, Wisdom & Wine is a casual and informal event, offering a chance to get together as industry professionals, relax, share our experiences, and catch up. It’s the perfect opportunity to see your security sector friends and acquaintances, and meet new ones.

This is a complimentary event for women and non-binary individuals working in security & privacy. We welcome you to invite others in your circle to extend our collective network.

* Please note the event is being held at a new location at the Washington Athletic Club. We have moved the event from the previous location at the Hotel Theodore.

The event is located in the Presidents Parlor Suite, 12th floor. As you get off the elevator, turn right to the premier wing and President’s suite/room 1212 will be on your left.

Parking is available at Washington Athletic Club’s self-parking gated garage location. It is less than a block from the WAC on 6th between Union and Pike on your left at 1409 6thAve / 206-464-3059

Register today and join us!

HOSTED EVENT | Jun 27, 2024

hack::soho | Fireside Chat | Up Close & Personal with Cybersecurity

Join us for an evening of fun at this month’s hack::soho featuring a fireside panel discussion between IOActive consultants Barrie Dempster, Artur Gemes, & Colin James Cassidy! The panel will discuss the current state of global cybersecurity, upcoming trends that the consultants foresee, & highlights from their personal work.

– Barrie Dempster, IOActive Director of Penetration Testing – With decades of technical experience including consulting and managing technical teams for the world’s largest financial, software and telecommunications organizations, Barrie Dempster has a wealth of practical experience in finding, exploiting and resolving vulnerabilities across the entire software and hardware stack. Barrie is a published technical author with three books in print, and has presented his research and observations on technical security at conferences, universities, and other organisations.

– Artur Gemes, IOActive Senior Security Consultant – Artur Gemes has over six years of experience in web application and network penetration testing with expertise in Andoid application reverse engineering and malware analysis. He brings an in-depth understanding of exploit development and develops bespoke tooling to support testing and research activities.

– Colin James Cassidy, IOActive Associate Principal Security Consultant – Colin James Cassidy is a seasoned leader in the areas of security and software engineering with a strong development and software engineering background. Much of his work focuses on assessment the security of Industrial Control Systems (ICS). He also has hands-on experience with a leading Outage Management System/Distribution Management System (OMS/DMS) solution.

Discussion Topics:

– Artificial Intelligence (AI) state-of-play, trends, and global concerns
– Learnings from assessments of security for Industrial Control Systems (ICS)
– Red Teaming and protecting from real-world threats
– Android mobile operating system exploration

HOSTED EVENT | Jun 20, 2024

An Evening with IOActive | The DL on LLM Code Analysis | Richard Johnson

Please join us and guest speaker, Richard Johnson, a principle security researcher focusing on fuzzing and software vulnerability analysis.

Join IOActive and Richard Johnson for an evening of exploration in to the The New World Order, the Age of Artificial Intelligence, the unavoidable evolution of technology that is here to assimilate human knowledge in its natural language form! You’ve parleyed with the perceptrons, you’ve dreamed deeply with Dall-E, but how do we harness this emerging capability to perform security analysis tasks such as looking for vulnerabilities and malware in source or binaries?

Richard will review successes and failures in research applying LLMs to code analysis tasks and discuss how to evaluate models and create your own dataset for evaluation, training, and tuning prompting for better results.

Richard Johnson is a computer security specialist with a focus on fuzzing and software vulnerability analysis. Currently Principal Security Researcher for Eclypsium, Richard offers over 20 years of professional expertise and leadership in the information security industry.

Drinks and heavy hors d’oeuvres will be served. Please RSVP quickly as space is limited.

HOSTED EVENT | May 30, 2024

hack::soho | Exploration Into ‘Elite,’ 1st Open-World Game | Mark Moxon

Back in 1984, Acornsoft released Elite for the BBC Micro. Arguably the first truly open-ended open-world game, Elite blew people’s minds, and was ported to every major home computer system, spawning an entire genre – the space sim.

Software archaeologist Mark Moxon fell in love with Elite all those years ago, and recently spent lockdown documenting every single byte of this seminal game. In this talk, you’ll find out how Ian Bell and David Braben, the authors of Elite, managed to squeeze an entire 3D graphics engine, 2000 star systems, 8 galaxies and a full galactic economy into just 23K of beautifully crafted machine code. If there is a definition of coding genius, it looks an awful lot like this…

hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments.