AI-Powered Application Penetration Testing—Scale Security Without Compromise Learn More

Bishop Fox at HackGDL 2026

Date:
March 12-14, 2026
Location:
Guadalajara, México
Bishop Fox graphic with HackGDL official logo in retro computer with Conference in bold for the HackGDL 2026 conference.

We’re excited to be back at HackGDL once again! This event has become a great place to connect with builders, breakers, and curious minds who care about how security actually works in the real world. HackGDL’s focus on hands-on learning, community, and open knowledge lines up closely with how we approach offensive security. We’re proud to return as a sponsor and to share what our team has been learning through a series of practical, workshop sessions.

Why stop by?

  1. Learn directly from practitioners who break real systems for a living
  2. Get hands-on exposure to modern attack techniques and common failure patterns
  3. Ask questions and swap stories with our team between sessions
  4. Connect with the local and regional security community
  5. Pick up ideas you can apply immediately in your own work

For more details, visit: HackGDL.net

"Unpacking the Bundle - Weaponizing Webpack & Source Maps for Critical Info Disclosure"

Speaker: Emiliano Perez, Security Consultant, Bishop Fox

Abstract: Modern Single Page Applications (SPAs) rely heavily on bundlers like Webpack, Vite, and Parcel to package dependencies and business logic. However, the transition from development to production can leave sensitive information, leading to an information disclosure. In this workshop, I will dissect the internal structure of JavaScript bundles and the associated Source Map standard. We will look specifically at how the devtool configuration in webpack.config.js impacts the final artifact and why developers frequently leave full source recovery enabled by mistake.

"Cloud Hacking 101: How to Survive in the Clouds"

Speaker: Juan Jasso, Security Consultant II, Bishop Fox

Abstract: In this workshop we will learn the basics of Security Assessments on cloud environments. To show/illustrate this ideas we will use a custom made AWS environment from the Bishop Fox's learning platform "Cloudfoxable" and Bishop Fox's cloud security tool Cloudfox, to show how to look for/discover exploitation techniques. Participants will get hands-on activities to perform with live challenges to sense real life problems and solutions. The challenges will include enumeration and exploitation activities discovering misconfigurations on the environment.

"Tales from the Bugfront: The Chain That Broke the Castle"

Speaker: Roberto Chavez, Security Consultant II, Bishop Fox

Abstract: This talk explores how security impact is achieved through the combination of multiple small weaknesses rather than a single vulnerability. It focuses on how repeated developer oversights and common security misconfigurations can gradually expand the attack surface. Throughout the session, concepts such as reconnaissance, application analysis, API testing, and mobile security are introduced to demonstrate how these weaknesses can be discovered, analyzed, and chained together, ultimately leading to serious vulnerabilities across modern applications.

"Craft your Cyber Identity & Ace Your Interviews"

Speaker: Areli Ch. Duran, Senior Technical Recruiter, Bishop Fox

Abstract: In this session, you’ll learn how to create a personal cybersecurity brand that feels authentic, confident, and uniquely you. We’ll break it down into five simple steps that help you define your professional value, communicate it clearly, and stand out in a competitive industry.

You’ll also get practical interviewing tips that recruiters actually care about, plus the chance to practice live so you walk away ready to shine in your next interview. Perfect for students, aspiring professionals, and anyone looking to level up their cyber career.


Bfx25 Jose Emiliano Perez Headshot

About the speaker, José Emiliano Perez

Security Consultant

José Emiliano Perez is a Security Consultant specializing in Web Application Security. With a focus on client-side vulnerabilities and secure code development, Emiliano has spent years analyzing how modern development stacks introduce new attack surfaces. Passionate about bridging the gap between DevOps and OffSec, he regularly contributes to the community through talks and sharing knowledge on how to detect and remediate issues.

Spoke previously at Pwnterrey 2025, Ekoparty 2023

More by José

Bfx25 Juan Jasso

About the speaker, Juan Jasso

Security Consultant II

Juan Jasso is a Security Consultant II at Bishop Fox, specializing in offensive security and cloud penetration testing. Active in cybersecurity since 2017, he’s honed his skills on platforms like TryHackMe, Hack The Box, and Offensive Security.

He has delivered pen testing services to both Mexican and global clients and has competed in the Hackmex tournament, representing National Autonomous University of Mexico (UNAM) with Team PumaHat and Bishop Fox with the Vicious Interns. Juan is currently completing a Computer Science degree at UNAM.

More by Juan

Areli Ch Duran

About the speaker, Areli Ch Duran

Senior Technical Recruiter

Areli Ch Duran is a Senior Technical Recruiter at Bishop Fox. Her experience includes human resources management, talent acquisition, capacity planning, recruitment, staffing, and candidate experience. She specializes in recruiting qualified candidates in software development, cybersecurity, information technology, and education. Areli is looking for all the talented white-hat hackers and offensive security experts in Mexico for our team expansion.

More by Areli

Ready to get started? We can help.

Contact Us

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.