Conference Hack Mex 2026 with Hack Mex official logo in retro computer.

Bishop Fox is glad to once again play a part in HackMex 2026, bringing together Mexico's security community for a day of offensive security talks and hands-on workshops. Juan Jasso will break down API security testing fundamentals, from authorization flaws to injection attacks, built for anyone getting started in pentesting. Samanta Aranda will lead a hands-on cloud security workshop on weaponizing AWS CloudFormation for privilege escalation, from IAM misconfigurations to covering your tracks in CloudTrail. And Eduardo Maceda will show, live, exactly where AI-generated code breaks, from SSRF and broken auth to hardcoded credentials and slopsquatted dependencies.

Bishop Fox Foxes have taken the top spot in the CTF's Private Sector category for two years running. This year, Miguel Rosas, Gustavo Reyes, Roberto Chavez, and Juan Jasso are back to defend the title. Come cheer them on!

For more details, visit: HackMex 2026

"APIs Desde Cero" (APIs from Scratch)

Speakers: Juan Jasso, Security Consultant, Bishop Fox

Abstract: Juan will present an introductory talk on API security testing methodologies, covering topics such as authorization testing, injections, parameter discovery, and real-world vulnerability examples. The session is aimed at people getting started with pentesting and will focus on how to approach API assessments effectively and within the correct scope.

"Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS"

Speakers: Samanta Aranda, Managing Senior Consultant, Bishop Fox

Abstract: Samanta will deliver a hands-on offensive cloud security workshop focused on abusing misconfigured AWS CloudFormation execution roles for privilege escalation and persistence. Attendees will work through realistic attack paths involving IAM permissions, iam:PassRole, service roles, Lambda-backed Custom Resources, and CloudFormation templates. The workshop will also cover rollback abuse and how these activities appear in CloudTrail and IAM logs.

"Vulnerabilidades Reales Detrás del Vibe Coding" (Real-World Vulnerabilities Behind Vibe Coding)

Speakers: Eduardo Maceda, Security Consultant, Bishop Fox

Abstract: This talk explores, from an offensive security perspective, the security risks that consistently emerge in AI-generated code and "vibe coding" workflows. It covers real-world vulnerability patterns such as SSRF, IDOR and broken authorization, hardcoded credentials, and dependencies on nonexistent packages (slopsquatting). The session will include an end-to-end live demonstration where a typical application feature is generated using an AI coding assistant and then tested and exploited in front of the audience. The goal is not to discourage the use of AI for development, but to demonstrate where blind trust in AI-generated code can fail and which security controls can help identify these issues before they reach production.


Bfx25 Juan Jasso

About the speaker, Juan Jasso

Security Consultant

Juan Jasso is a Security Consultant at Bishop Fox, specializing in offensive security and cloud penetration testing. Active in cybersecurity since 2017, he’s honed his skills on platforms like TryHackMe, Hack The Box, and Offensive Security.

He has delivered pen testing services to both Mexican and global clients and has competed in the Hackmex tournament, representing National Autonomous University of Mexico (UNAM) with Team PumaHat and Bishop Fox with the Vicious Interns. Juan is currently completing a Computer Science degree at UNAM.


Bfx25 Samanta Bio

About the speaker, Samanta Aranda

Managing Senior Consultant

Passionate about cybersecurity, Samanta is a Managing Senior Consultant at Bishop Fox. With a background in Electronics and Communications Engineering and a Master’s in Computer Science and Technology Management, she brings over a decade of experience helping global organizations strengthen their security posture. She holds 16 professional certifications and was honored by EC-Council as part of its Circle of Excellence in 2021.


Eduardo Maceda Islas

About the speaker, Eduardo Maceda Islas

Security Consultant

Eduardo Maceda Islas is a Security Consultant III at Bishop Fox, where he is part of the offensive security consulting teams. With more than 5 years of experience in cybersecurity, he specializes in Red Team operations, ethical hacking, and penetration testing across web applications, APIs, and mobile applications.

Throughout his career, Eduardo has led full-scope Red Team campaigns emulating the TTPs of real-world threat actors. His work stands out for translating complex technical findings into quantified business impact, communicating risk at the executive level.


Miguel Rosas

About the speaker, Miguel Rosas

Security Consultant

Miguel Rosas is a Security Consultant at Bishop Fox, specializing in application, API, and external penetration testing. In this role, he has had the opportunity to put his skills to the test across engagements with international companies, identifying significant vulnerabilities and helping organizations strengthen their security posture.

Miguel studied Computer Engineering at UPIICSA, Instituto Politécnico Nacional (IPN) in Mexico, where he was a member and later a mentor of the Hacking Club, introducing students to hacking and preparing them to participate in CTF competitions.


Gustavo Reyes

About the speaker, Gustavo Reyes

Security Consultant

Gustavo Reyes is a Security Consultant at Bishop Fox specializing in external and application penetration testing. His work focuses on identifying and validating security weaknesses across web applications, APIs, network services, and other externally exposed attack surfaces.


Bfx25 Roberto Chavez Profile Bio Headshot

About the speaker, Roberto Chavez

Security Consultant

Roberto Chavez is a security consultant specializing in external penetration testing and application penetration testing, with additional experience in source code review and cloud security. Roberto holds several security certifications, including eWPTX, CAPEN, and CAPENX, and is actively involved in security research, with a current focus on IoTand mobile security and their various attack surfaces. He has presented at BUGCON, where he spoke about different vulnerable scenarios, sharing practical insights based on real-world offensive security experience.

Ready to get started? We can help.

Contact Us