Back to Talks 2026
Talk

The Breach Is Over. The Exposure Is Not

Recon Village @ DEF CON 34August 7-9, 2026

3:00 PM – 3:30 PMSaturday, August 8DEF CON Creator Stage 2

Abstract

Breaches are usually treated as discrete incidents. A leak is discovered, the most recognisable credentials are rotated, incident-response activity slows down, and attention moves to the next compromise. The exposure rarely ends with the incident. Credentials can remain valid for months, sometimes long enough to be reused in later attacks. While common credential types receive immediate attention, large breach datasets often contain hundreds of less familiar secret classes that are harder to recognise, validate, or prioritise. This talk examines the long tail of a major software supply chain breach and measures how exposed credentials age, which categories survive longest, and whether public disclosure actually results in remediation.

The leaked values are only part of the exposure. Secret names, environment variables, repository paths, service identifiers, deployment stages, and naming conventions can reveal how an organisation builds and operates its systems. Even when a credential has expired, this contextual residue can support attack-surface discovery, technology identification, infrastructure correlation, and future targeting. By looking beyond the obvious credential classes and focusing on the outliers, this talk demonstrates how breach data can be transformed into durable reconnaissance intelligence, and why recovery should be measured by the disappearance of usable exposure rather than the closure of the original incident.

Speaker

Anant Shrivastava
Anant Shrivastava

Founder @ Cyfinoid

Anant Shrivastava is a highly experienced information security professional with over 15 years of corporate experience. He is a frequent speaker and trainer at international conferences, and is the founder of Cyfinoid Research, a cyber security research firm. He leads open source projects such as Tamer Platform and CodeVigilant, and is actively involved in information security communities such as null, OWASP and various bsides and defcon groups.

View full speaker profile →