Loading…
Friday November 6, 2026 2:15pm - 3:00pm PST
Modern applications increasingly rely on microservice architectures where APIs, backend services, and cloud workloads continuously communicate with one another. While organizations focus heavily on authenticating end users, service-to-service trust relationships are often implemented with excessive implicit trust, weak authorization boundaries, and inconsistent validation controls.

This talk explores how attackers abuse trust relationships between internal services to move laterally, escalate privileges, and access unintended resources inside distributed application environments. We will examine practical attack scenarios involving internal API trust, token forwarding, over-permissioned service identities, and insecure authorization assumptions between microservices.

Through architectural walkthroughs and demonstrations, attendees will learn how trust propagation inside distributed systems creates hidden attack paths that are difficult to detect using traditional security testing approaches.

The session also provides actionable guidance for securing service-to-service communication, including zero-trust design principles, token validation between services, least privilege for service identities, and authorization enforcement at every layer of the application.

Attendees will leave with practical strategies for reducing lateral movement and strengthening trust boundaries in cloud-native applications.
Speakers
avatar for Bhaumik Shah

Bhaumik Shah

CEO, SecurifyAI
Bhaumik Shah is a cybersecurity leader and founder of Securify, where he helps organizations secure their cloud, applications, and infrastructure through penetration testing, red team operations, and compliance programs like SOC 2 and ISO 27001. With over a decade of experience uncovering... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Seacliff AB (Bay Level)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link