About us
Security BSides Göteborg is a community-driven cybersecurity event that takes place in Gothenburg, Sweden, dedicated to fostering the local cybersecurity community.
Part of the global Security BSides movement, it serves as a platform for cybersecurity enthusiasts, professionals, and researchers to share knowledge, explore new developments, and collaborate on security challenges.
Where Hackers, InfoSec minds, and the cybersecurity community Connect, Hack, Learn, Defend and Evolve together.
Upcoming events
4

BSides Gothenburg – A Day of Security Learning Sessions & Networking
Lindholmen Conference Center, Lindholmspiren 5, Göteborg, SE🎉 Security BSides Göteborg 2026 – Tickets Now Open!
🎟️ Grab your ticket and secure your place at the event.
Security BSides Gothenburg - Registration Link for Full day Event🦄 Join us for a full‑day in person community‑driven cybersecurity event at 23th October in Lindholmen Conference Centre -Pascal Room - Gothenburg.?
🔥 Expect technical talks across multiple security domains — red team, blue team, AI security, car security, cloud security, application security, and more with strong community vibe. ?
🍽️ Lunch and refreshments are included throughout the day.?
🚀 A great chance to learn, connect, and meet people across the security community
🎟️ Grab your ticket and secure your place at the event
Security BSides Gothenburg - Registration Lin🇸🇪 Follow up us in Linkdine for keep tunin
Security BSides Gothenburg - Linkedine PagLet's build a stronger cybersecurity community together. 💙💛?
This is a low‑cost, budget friendly and paid event — grab your ticket and secure your spot. ?
We can’t wait to welcome you at BSides Gothenburg.🔥🦄?
10 attendees
Dead on Arrival: The Detection That Physically Can Not Fire - Detection Engineer
Lindholmen Conference Center, Lindholmspiren 5, Göteborg, SEDead on Arrival: The Detections That Physically Cannot Fire / Detection Engineering
💫Grab your ticket and secure your spot:
Registration Link for Full day Event
** 🦄 This is low cost and budget friendly and paid... **A detection rule can sit in your repo, pass CI, and glow green on your ATT&CK coverage map while being physically incapable of firing. Not misconfigured. Incapable. It reads a log field that nobody collects, so no event will ever match it, and nothing on your dashboard tells you.
This is one of the most common silent failures in a real detection stack, and it is the one nobody owns. Coverage maps measure whether a rule was written, not whether it can fire. SIEM rule-health checks confirm a rule ran without error, and a rule running over data that never contains the field it needs runs without error too. It just runs over nothing. The gap between "quiet" and "dead" is invisible.
I built a small, read-only checker that closes that gap deterministically. It takes your Sigma rules, resolves the fields each one needs through your normal pySigma pipeline, and asks your SIEM's schema whether those fields are actually present, using metadata APIs like Elastic field_caps.
There is no matching, no scoring, no model: a field exists or it does not, so a rule can fire or it cannot. The verdict is FIREABLE or DEAD-ON-ARRIVAL with the exact missing field.
💫Grab your ticket and secure your spot:
Registration Link - Full Day EventThis is low cost and budget friendly events.
2 attendees
Real world Incident Response Lessons How Attacker Reach out OT. Grab Ticket
Lindholmen Conference Center, Lindholmspiren 5, Göteborg, SEFrom IT to OT: Real-World Incident Response Lessons on How Attackers Reach Operational Technology Environments
💫Grab your ticket and secure your spot:
Registration Link for Full day Event**🦄 This is low cost and budget friendly and paid... **
Operational Technology (OT) environments are often seen as isolated and separate from IT. In reality, they are increasingly connected through remote access, suppliers, shared infrastructure, virtualization platforms, and enterprise IT systems, creating attack paths adversaries can exploit.
This session is based on hands-on incident response experience and explores how attacks against OT environments actually begin. Instead of focusing on theory, it highlights real-world ways attackers move from IT into OT by abusing remote access, supplier connectivity, shared services, and modern infrastructure dependencies.
A key focus is the growing risk introduced by virtualization platforms such as VMware, which often support critical OT functions including engineering workstations, management systems, and historians. When these platforms are compromised, the impact can quickly become operational.
Attendees will gain practical insight into common attack paths, why IT compromise can become an OT risk, and what defenders should prioritize to improve detection, segmentation, and resilience across hybrid IT/OT environments.
✨️Grab your ticket and Secure your spots.
Ticket Registration - Full day EventThat is Paid and Budget Friendly Ticket.
2 attendees
The Robot's Credentials: Attacking the AI Platform Behind the Device-Get Ticket
Lindholmen Conference Center, Lindholmspiren 5, Göteborg, SEThe Robot's Credentials: Attacking the AI Platform Behind the Device
💫Grab your ticket and secure your spot:
Registration Link For Full Day Event🦄 This is low cost and budget friendly and paid events.
Mikael Eriksson:
Consumer robots are arriving on our networks with something IoT devices typically don't have: a persistent cloud identity with write access to the owner's repositories, tied directly to an AI platform ecosystem. That changes what a compromise actually meant.During my research into one of the consumer-accessible robots on the market, I found four attack paths. Two are what you'd expect from a device on a local network. Unauthenticated RCE, a desktop proxy deliberately designed to bypass browser Private Network Access restrictions. The vendor patched those. When I went through that patch, I found the other two were already there untouched by the security release, and in one case made newly relevant by the patch itself.
A malicious HuggingFace Space with a build hook exfiltrates the robot's stored OAuth token before the install even completes. A second unauthenticated endpoint replaces the stored token entirely in three HTTP requests. The robot's cloud identity is now the attacker's, persistent across reboots, and the victim's HuggingFace repositories are exposed alongside the robot itself.
The techniques are familiar. The composition is new: local daemon, desktop proxy, package build pipeline, cloud relay, stored OAuth token, and repository permissions are all part of one control plane. A breach here is not contained to the device.
Attendees leave able to evaluate any cloud-connected robot on their network and the risk they introduce.
The token replacement is not the end state. An attacker with the robot's cloud identity can substitute the model it runs. Silent and persistent across reboots, the compromise survives the attacker's exit. The device continues functioning normally, except what it thinks is no longer the users model.
💫Grab your ticket and secure your spot:
Registration Link For Full Day EventRegistration Link For Full Day Event
This is low cost and budget friendly events.2 attendees
Past events
4


