AI-Powered Application Penetration Testing—Scale Security Without Compromise Learn More

Bishop Fox graphic with HackGDL official logo in retro computer with Conference in bold for the HackGDL 2026 conference.

We’re excited to be back at HackGDL once again! This event has become a great place to connect with builders, breakers, and curious minds who care about how security actually works in the real world. HackGDL’s focus on hands-on learning, community, and open knowledge lines up closely with how we approach offensive security. We’re proud to return as a sponsor and to share what our team has been learning through a series of practical, workshop sessions.

Why stop by?

  1. Learn directly from practitioners who break real systems for a living
  2. Get hands-on exposure to modern attack techniques and common failure patterns
  3. Ask questions and swap stories with our team between sessions
  4. Connect with the local and regional security community
  5. Pick up ideas you can apply immediately in your own work

For more details, visit: HackGDL.net

"Unpacking the Bundle - Weaponizing Webpack & Source Maps for Critical Info Disclosure"

Speaker: Emiliano Perez, Security Consultant, Bishop Fox

Abstract: Modern Single Page Applications (SPAs) rely heavily on bundlers like Webpack, Vite, and Parcel to package dependencies and business logic. However, the transition from development to production can leave sensitive information, leading to an information disclosure. In this workshop, I will dissect the internal structure of JavaScript bundles and the associated Source Map standard. We will look specifically at how the devtool configuration in webpack.config.js impacts the final artifact and why developers frequently leave full source recovery enabled by mistake.

"Cloud Hacking 101: How to Survive in the Clouds"

Speaker: Juan Jasso, Security Consultant II, Bishop Fox

Abstract: In this workshop we will learn the basics of Security Assessments on cloud environments. To show/illustrate this ideas we will use a custom made AWS environment from the Bishop Fox's learning platform "Cloudfoxable" and Bishop Fox's cloud security tool Cloudfox, to show how to look for/discover exploitation techniques. Participants will get hands-on activities to perform with live challenges to sense real life problems and solutions. The challenges will include enumeration and exploitation activities discovering misconfigurations on the environment.

"Reverse Engineering Your Career: A Hacker’s Approach"

Speaker: Patricio Sanchez, Regional Director I, Bishop Fox

Abstract: After more than 20 years building and leading advanced offensive and defensive security teams across Latin America and the United States, I’ve observed a consistent pattern: highly skilled technical professionals often struggle to advance, not because of a lack of capability, but because of how they approach their careers.

In cybersecurity, career paths are rarely linear. Roles evolve quickly, expectations shift, and the skills that make someone a strong practitioner are not always the same skills that drive long-term growth.

This talk reframes career progression through a technical lens. We will examine why technical depth alone is insufficient, what high-performing red and blue teams actually value beyond tooling and exploits, and how to strategically build expertise in areas such as advanced tradecraft, specialization, and cross-functional impact.

Rather than motivational advice, this session offers a practical framework to help security professionals think like attackers—not just against systems, but against the limitations of their own career models.

"From Debug to Root: A Friendly Introduction to Hardware Hacking"

Speaker: Marco Sanchez, Security Consultant II, Bishop Fox & Abdel Bolivar, Managing Senior Consultant I, Bishop Fox

Abstract: Nowadays, embedded and IoT devices play an important role in corporate and industrial environments, and even in our homes. Some of them are responsible for critical tasks. But how secure are they? In this workshop, attendees will explore the world of hardware hacking by evaluating a real device. They will learn how to identify the main components of a device, interact with debugging interfaces, and extract and analyze the device's firmware to identify vulnerabilities and misconfigurations.

"Tales from the Bugfront: The Chain That Broke the Castle"

Speaker: Roberto Chavez, Security Consultant II, Bishop Fox

Abstract: This talk explores how security impact is achieved through the combination of multiple small weaknesses rather than a single vulnerability. It focuses on how repeated developer oversights and common security misconfigurations can gradually expand the attack surface. Throughout the session, concepts such as reconnaissance, application analysis, API testing, and mobile security are introduced to demonstrate how these weaknesses can be discovered, analyzed, and chained together, ultimately leading to serious vulnerabilities across modern applications.

"Craft your Cyber Identity & Ace Your Interviews"

Speaker: Areli Ch. Duran, Senior Technical Recruiter, Bishop Fox

Abstract: In this session, you’ll learn how to create a personal cybersecurity brand that feels authentic, confident, and uniquely you. We’ll break it down into five simple steps that help you define your professional value, communicate it clearly, and stand out in a competitive industry.

You’ll also get practical interviewing tips that recruiters actually care about, plus the chance to practice live so you walk away ready to shine in your next interview. Perfect for students, aspiring professionals, and anyone looking to level up their cyber career.

"iOS Game Hacking: From Zero to God Mode"

Speaker: Steeven Rodriguez, Senior Operator I, Bishop Fox & Luis De la Rosa, Security Consultant III, Bishop Fox

Abstract: A practical introduction to game hacking on iOS, demonstrating from scratch how games developed for this platform can be analyzed and modified in real time. Through live demos, reverse engineering and hooking techniques are shown to enable features such as God Mode, Infinite Coins, and Speed Hacks, dispelling the myth that iOS is an unhackable ecosystem.


Bfx25 Jose Emiliano Perez Headshot

About the speaker, José Emiliano Perez

Security Consultant

José Emiliano Perez is a Security Consultant specializing in Web Application Security. With a focus on client-side vulnerabilities and secure code development, Emiliano has spent years analyzing how modern development stacks introduce new attack surfaces. Passionate about bridging the gap between DevOps and OffSec, he regularly contributes to the community through talks and sharing knowledge on how to detect and remediate issues.

Spoke previously at Pwnterrey 2025, Ekoparty 2023

More by José

Bfx25 Juan Jasso

About the speaker, Juan Jasso

Security Consultant II

Juan Jasso is a Security Consultant II at Bishop Fox, specializing in offensive security and cloud penetration testing. Active in cybersecurity since 2017, he’s honed his skills on platforms like TryHackMe, Hack The Box, and Offensive Security.

He has delivered pen testing services to both Mexican and global clients and has competed in the Hackmex tournament, representing National Autonomous University of Mexico (UNAM) with Team PumaHat and Bishop Fox with the Vicious Interns. Juan is currently completing a Computer Science degree at UNAM.

More by Juan

Bfx25 Patricio Sanchez Profile Bio Headshot

About the speaker, Patricio Sanchez

Regional Director I

Eduardo P. Sánchez Díaz is a cybersecurity leader with more than 20 years of experience building and scaling high-impact security programs across Latin America and global organizations. He currently serves as Regional Director at Bishop Fox, where he leads consulting services and oversees operations in Mexico.

Eduardo has held senior leadership roles in incident response, threat hunting, cyber intelligence, and offensive security. He founded the first cyber intelligence and threat intelligence center in Latin America and has led multidisciplinary teams across the United States and Mexico. His expertise spans security operations transformation, active defense strategies, red teaming, digital forensics, and large-scale cybersecurity service development.

More by Patricio

Bfx25 Marco Sanchez Profile Bio Headshot

About the speaker, Marco Sanchez

Security Consultant II

Marco is a Security Consultant at Bishop Fox. He specializes in applicationand external penetration testing. He has experience in conducting application, mobile, external, and cloud penetration testing for both Mexican and multinational companies and institutions. He has presented at cybersecurity conferences such as Ekoparty, HackGDL, BugCON, Bsides CDMX, and DragonJAR on topics related to RFID, Access Control Systems, Lock Picking, and Active Directory. He has a strong interest in hardware hacking, radio frequencies, and HAM radio.

More by Marco

Bfx25 Abdel Bolivar Bio Image

About the speaker, Abdel Bolivar

Managing Senior Consultant I

Abdel Bolivar is an offensive security leader at Bishop Fox and one of the leads of the Bishop Fox Mexico team, where he manages consultants and delivers security assessments across web, mobile, infrastructure, cloud, and hardware environments. With over 20 years of experience in cybersecurity, Abdel has led offensive security programs, investigated high-impact incidents, and worked on everything from enterprise breaches to ATM fraud and ransomware outbreaks.

His current work focuses on offensive security, hardware and embedded device security, and helping organizations understand how real attackers abuse systems in the physical and digital world. Abdel is passionate about making complex security topics approachable and practical, and he regularly shares hands-on techniques for breaking—and fixing—real-world systems.

More by Abdel

Bfx25 Roberto Chavez Profile Bio Headshot

About the speaker, Roberto Chavez

Security Consultant II

Roberto Chavez is a security consultant specializing in external penetration testing and application penetration testing, with additional experience in source code review and cloud security. Roberto holds several security certifications, including eWPTX, CAPEN, and CAPENX, and is actively involved in security research, with a current focus on IoTand mobile security and their various attack surfaces. He has presented at BUGCON, where he spoke about different vulnerable scenarios, sharing practical insights based on real-world offensive security experience.

More by Roberto

Areli Ch Duran

About the speaker, Areli Ch Duran

Senior Technical Recruiter

Areli Ch Duran is a Senior Technical Recruiter at Bishop Fox. Her experience includes human resources management, talent acquisition, capacity planning, recruitment, staffing, and candidate experience. She specializes in recruiting qualified candidates in software development, cybersecurity, information technology, and education. Areli is looking for all the talented white-hat hackers and offensive security experts in Mexico for our team expansion.

More by Areli

Bfx25 Steeven Rodriguez

About the speaker, Steeven Rodriguez

Senior Adversarial Operator

Steeven Rodriguez is a Senior Adversarial Operator on the Cosmos team at Bishop Fox, where he specializes in advanced offensive security engagements and continuous threat emulation. His work spans penetration testing across network, web, and mobile applications for clients in various industries, including finance, healthcare, and technology.

Steeven is an active contributor to the InfoSec community, regularly attending cybersecurity conferences and competing in CTF competitions. He has hosted hands-on workshops on mobile application penetration testing at events such as Security BSides CDMX and HackGDL, where he shares insights on exploiting mobile vulnerabilities and secure mobile development practices.

More by Steeven

Luis De la Rosa Hernandez BF Headshot 1

About the speaker, Luis De la Rosa Hernandez

Security Consultant II

Luis is a Security Consultant II at Bishop Fox focused on mobile penetration testing and application security. Luis holds several security certifications including Offensive Security Certified Professional (OSCP), eLearn Mobile Application Penetration Tester (eMAPT), and CRT (Crest Registered Penetration Tester). When Luis he isn’t busy hacking, he enjoys playing videogames in his free time.

More by Luis

Ready to get started? We can help.

Contact Us

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.