Workstation Is Still the Breach: Zero Trust Tactics from Bybit to Bitwarden

No ratings

Presented at BSidesSATX 2026 by

February 2025: $1.5B stolen from one developer's laptop. April 2026: the worm came back, targeting ~/.claude.json and MCP configs by name. Same surface, same trust assumptions, new vector. We'll map the developer workstation through Kindervag's Zero Trust methodology, dissect how recent attacks (Bybit, Shai-Hulud, TeamPCP, Bitwarden CLI) actually executed, and walk through eight defender techniques on a four-level maturity ladder, starting with what you can do solo on Monday morning.