HackMex 2026
- Date:
- October 15-16, 2026
- Location:
- ESIME Culhuacán, IPN, Mexico City, Mexico
Bishop Fox is glad to once again play a part in HackMex 2026, bringing together Mexico's security community for a day of offensive security talks and hands-on workshops. Juan Jasso will break down API security testing fundamentals, from authorization flaws to injection attacks, built for anyone getting started in pentesting. Samanta Aranda will lead a hands-on cloud security workshop on weaponizing AWS CloudFormation for privilege escalation, from IAM misconfigurations to covering your tracks in CloudTrail.
Bishop Fox Foxes have taken the top spot in the CTF's Private Sector category for two years running. This year, Miguel Rosas, Gustavo Reyes, Roberto Chavez, and Juan Jasso are back to defend the title. Come cheer them on!
For more details, visit: HackMex 2026
"APIs Desde Cero" (APIs from Scratch)
Speakers: Juan Jasso, Security Consultant, Bishop Fox
Abstract: Juan will present an introductory talk on API security testing methodologies, covering topics such as authorization testing, injections, parameter discovery, and real-world vulnerability examples. The session is aimed at people getting started with pentesting and will focus on how to approach API assessments effectively and within the correct scope.
"Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS"
Speakers: Samanta Aranda, Managing Senior Consultant, Bishop Fox
Abstract: Samanta will deliver a hands-on offensive cloud security workshop focused on abusing misconfigured AWS CloudFormation execution roles for privilege escalation and persistence. Attendees will work through realistic attack paths involving IAM permissions, iam:PassRole, service roles, Lambda-backed Custom Resources, and CloudFormation templates. The workshop will also cover rollback abuse and how these activities appear in CloudTrail and IAM logs.