HackMex 2026
- Date:
- October 15-16, 2026
- Location:
- ESIME Culhuacán, IPN, Mexico City, Mexico
Bishop Fox is glad to once again play a part in HackMex 2026, bringing together Mexico's security community for a day of offensive security talks and hands-on workshops. Juan Jasso will break down API security testing fundamentals, from authorization flaws to injection attacks, built for anyone getting started in pentesting. Samanta Aranda will lead a hands-on cloud security workshop on weaponizing AWS CloudFormation for privilege escalation, from IAM misconfigurations to covering your tracks in CloudTrail. And Eduardo Maceda will show, live, exactly where AI-generated code breaks, from SSRF and broken auth to hardcoded credentials and slopsquatted dependencies.
Bishop Fox Foxes have taken the top spot in the CTF's Private Sector category for two years running. This year, Miguel Rosas, Gustavo Reyes, Roberto Chavez, and Juan Jasso are back to defend the title. Come cheer them on!
For more details, visit: HackMex 2026
"APIs Desde Cero" (APIs from Scratch)
Speakers: Juan Jasso, Security Consultant, Bishop Fox
Abstract: Juan will present an introductory talk on API security testing methodologies, covering topics such as authorization testing, injections, parameter discovery, and real-world vulnerability examples. The session is aimed at people getting started with pentesting and will focus on how to approach API assessments effectively and within the correct scope.
"Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS"
Speakers: Samanta Aranda, Managing Senior Consultant, Bishop Fox
Abstract: Samanta will deliver a hands-on offensive cloud security workshop focused on abusing misconfigured AWS CloudFormation execution roles for privilege escalation and persistence. Attendees will work through realistic attack paths involving IAM permissions, iam:PassRole, service roles, Lambda-backed Custom Resources, and CloudFormation templates. The workshop will also cover rollback abuse and how these activities appear in CloudTrail and IAM logs.
"Vulnerabilidades Reales Detrás del Vibe Coding" (Real-World Vulnerabilities Behind Vibe Coding)
Speakers: Eduardo Maceda, Security Consultant, Bishop Fox
Abstract: This talk explores, from an offensive security perspective, the security risks that consistently emerge in AI-generated code and "vibe coding" workflows. It covers real-world vulnerability patterns such as SSRF, IDOR and broken authorization, hardcoded credentials, and dependencies on nonexistent packages (slopsquatting). The session will include an end-to-end live demonstration where a typical application feature is generated using an AI coding assistant and then tested and exploited in front of the audience. The goal is not to discourage the use of AI for development, but to demonstrate where blind trust in AI-generated code can fail and which security controls can help identify these issues before they reach production.