<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2026.1.2. -->
<schedule>
    <generator name="pretalx" version="2026.1.2" />
    <version>0.6</version>
    <conference>
        <title>Call For Paper - Presentations</title>
        <acronym>call-for-paper-presentations-2026</acronym>
        <start>2026-09-10</start>
        <end>2026-09-10</end>
        <days>1</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://cfp.bsidesfrankfurt.org</base_url>
        <logo>https://cfp.bsidesfrankfurt.org/media/call-for-paper-presentations-2026/img/bsides-frankfurt-logo-main_qyCfnQF.png</logo>
        <time_zone_name>Europe/Berlin</time_zone_name>
        
        
        <track name="Main Track" slug="1-main-track"  color="#2e3d41" />
        
    </conference>
    <day index='1' date='2026-09-10' start='2026-09-10T04:00:00+02:00' end='2026-09-11T03:59:00+02:00'>
        <room name='Gro&#223;er Saal' guid='0991b703-0b77-5b23-a0ca-abfbae39950f'>
            <event guid='3418d1a3-c38b-5b7a-874b-5b05815aad7c' id='108' code='ZTPWJS'>
                <room>Gro&#223;er Saal</room>
                <title>Intro</title>
                <subtitle></subtitle>
                <type>Short-Talk</type>
                <date>2026-09-10T09:20:00+02:00</date>
                <start>09:20</start>
                <duration>00:10</duration>
                <abstract>Intro</abstract>
                <slug>call-for-paper-presentations-2026-108-intro</slug>
                <track>Main Track</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZTPWJS/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZTPWJS/feedback/</feedback_url>
            </event>
            <event guid='4a64a37e-a20d-5f97-998a-c07727755fdb' id='106' code='7ZNYWP'>
                <room>Gro&#223;er Saal</room>
                <title>Keynote (J&#246;rn Schneeweisz)</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-10T09:30:00+02:00</date>
                <start>09:30</start>
                <duration>00:40</duration>
                <abstract>Keynote</abstract>
                <slug>call-for-paper-presentations-2026-106-keynote-jorn-schneeweisz</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='110'>Joernchen</person>
                </persons>
                <language>en</language>
                <description>J&#246;rn Schneeweisz is a Principal Security Engineer at GitLab who managed to turn a decade of breaking other people&apos;s broken Ruby on Rails code into a legitimate corporate career, because apparently, getting paid to tell companies how bad their security is qualifies as a real job.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/7ZNYWP/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/7ZNYWP/feedback/</feedback_url>
            </event>
            <event guid='638e15d9-dfb7-56b1-82be-7f5437359dbd' id='100' code='KVLR3V'>
                <room>Gro&#223;er Saal</room>
                <title>Welcome to Hybrid Hell - Breaking Entrpise Identity beyond Active Directory</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-10T10:10:00+02:00</date>
                <start>10:10</start>
                <duration>00:55</duration>
                <abstract>Enterprise identity has fundamentally changed.

Large organisations no longer rely on a single identity system. Instead, Active Directory, Microsoft Entra ID, Azure, Microsoft 365, SaaS applications, identity synchronisation, third-party identity providers and cross-tenant trust relationships have evolved into a single interconnected identity architecture.

Unfortunately, attackers don&#8217;t think in terms of &#8220;on-premises&#8221; or &#8220;cloud.&#8221; They follow trust relationships.

While organisations often assess Active Directory and cloud environments separately, the most valuable attack paths increasingly exist between them. Hybrid identity, multi-forests, multiple Entra ID tenants, synchronisation services, service principals, managed identities and delegated administration all contribute to an enterprise identity attack surface that is significantly larger, and far less understood, than many organisations realise.

This session explores enterprise identity architecture from an attacker&#8217;s perspective. Rather than focusing on individual attack techniques, it examines how identity systems interact, where trust boundaries actually exist, and how seemingly isolated weaknesses can be chained together across on-premises and cloud environments.

Attendees will leave with a practical approach to identifying enterprise identity attack paths, defining realistic assessment scopes, and understanding why the biggest identity risks often exist in the connections between systems,not the systems themselves.</abstract>
                <slug>call-for-paper-presentations-2026-100-welcome-to-hybrid-hell-breaking-entrpise-identity-beyond-active-directory</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='99'>georg</person>
                </persons>
                <language>en</language>
                <description>Enterprise identity is no longer defined by a single directory service. Modern organisations operate complex identity architectures spanning Active Directory, Microsoft Entra ID, Azure, Microsoft 365, SaaS platforms, synchronisation services, multiple identity providers and increasingly multiple business units, subsidiaries and cloud tenants. Every integration introduces new trust relationships. Every trust relationship introduces new attack paths.

This session approaches enterprise identity from the perspective that matters most during an assessment: the attacker&#8217;s.

Rather than presenting a catalogue of Active Directory or Entra ID attack techniques, the talk focuses on how modern enterprise identity is constructed, why traditional assessment methodologies frequently fail to capture the complete attack surface, and how attackers move across identity boundaries by abusing trust instead of exploiting individual technologies.

Using realistic enterprise architectures, practical demonstrations and real-world attack scenarios, the session examines common challenges encountered during offensive security engagements, including hybrid identity deployments, synchronisation, multi-forest environments, multiple Entra ID tenants, delegated administration, identity trust relationships and assessment scoping. The audience will see how architectural decisions influence attack paths, why trust relationships become the true security boundary, and how weaknesses in one part of the identity architecture can create unexpected consequences elsewhere.

The presentation concludes with a practical framework for mapping enterprise identity architecture from an attacker&#8217;s perspective, enabling security teams to define more realistic assessment scopes, prioritise the trust relationships that matter most, and better understand how identity has become one of the largest and least visible enterprise attack surfaces.

Key takeaways

* Understand how enterprise identity has evolved beyond a single directory service.
* Learn why attackers focus on trust relationships rather than technology boundaries.
* Identify common architectural patterns that expand the enterprise identity attack surface.
* Recognise the challenges of scoping and assessing complex hybrid identity environments.
* Apply an attacker-focused methodology for analysing enterprise identity architecture and prioritising risk.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/KVLR3V/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/KVLR3V/feedback/</feedback_url>
            </event>
            <event guid='af22faf4-606b-50bc-bfcf-27921ee84f73' id='25' code='QDB7NB'>
                <room>Gro&#223;er Saal</room>
                <title>What Windows 11 Remembers (And Most Investigators Miss)</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-10T11:05:00+02:00</date>
                <start>11:05</start>
                <duration>00:55</duration>
                <abstract>Every Windows release quietly introduces new places where the operating system writes things down, and Windows 11 is no exception. While most DFIR playbooks still lean on the same artifacts we&apos;ve relied on for a decade, the modern Windows stack has been busy generating evidence in places few investigators routinely check. Timelines end up with gaps that didn&apos;t need to be there, and execution evidence sits untouched on disk.

Drawing on recurring patterns across hundreds of Windows 11 investigations, this talk maps the evidence surface that standard triage misses. We&apos;ll spend time with Recall and the near-continuous record it keeps of user activity on Copilot+ devices, follow the SMS and call history that Phone Link pulls from paired Android phones onto the Windows host, and read through Copilot conversations where user intent is often spelled out in plain English. From there we&apos;ll move into the secondary telemetry channels that keep writing long after Event Logs are cleared.

For each artifact, we&apos;ll cover where it lives, what it records, how long it persists, and the common misreadings that lead investigators astray. Attendees will leave with a mental model for where Windows 11 records user activity outside the classic artifact set, a working understanding of how to parse each source, and a feel for the interpretation pitfalls that matter most at triage time.</abstract>
                <slug>call-for-paper-presentations-2026-25-what-windows-11-remembers-and-most-investigators-miss</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='22'>Maurice Fielenbach</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>true</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/QDB7NB/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/QDB7NB/feedback/</feedback_url>
            </event>
            <event guid='d3e6975b-d68b-5956-a157-91fe048a66af' id='27' code='AXSXQW'>
                <room>Gro&#223;er Saal</room>
                <title>Hacking Consumer Drones: From Flash Dumping to Root Exploits</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-10T13:00:00+02:00</date>
                <start>13:00</start>
                <duration>00:55</duration>
                <abstract>Hacking the Potensic Atom 2 consumer drone, including a full walkthrough of the process of disassembling the drone, dumping the firmware, reverse-engineering its long-range RF control protocol, finding vulnerabilities, and exploiting them to take over the drone remotely.</abstract>
                <slug>call-for-paper-presentations-2026-27-hacking-consumer-drones-from-flash-dumping-to-root-exploits</slug>
                <track>Main Track</track>
                <logo>/media/call-for-paper-presentations-2026/submissions/AXSXQW/image_zIXnT09.webp</logo>
                <persons>
                    <person id='25'>Tim Schmidt</person>
                </persons>
                <language>en</language>
                <description>This talk tracks an IT security researcher&#8217;s journey through the process of disassembling, dumping and exploiting the Potensic Atom 2 consumer drone. We&#8217;ll follow the full lifecycle of a hardware exploit: Starting with low-level chip identification and flash desoldering, we make a detour into recovering heavily corrupted flash firmware by reverse engineering error correction codes.

From there, we pivot to the software, reverse-engineering the binary firmware to uncover hidden backdoors in the drone&apos;s control protocol. Ending with a presentation of a custom exploit designed to hijack the drone and gain full root access. Whether you&apos;re interested in hardware RE or binary exploitation, this is a fast-paced look at every stage of the IoT research process.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/AXSXQW/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/AXSXQW/feedback/</feedback_url>
            </event>
            <event guid='71749803-b166-5515-b5eb-44d927cc1085' id='74' code='ZETL7P'>
                <room>Gro&#223;er Saal</room>
                <title>Deconstructing Modern macOS Initial Access Vectors</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-10T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>00:55</duration>
                <abstract>For years, a persistent myth suggested that macOS was inherently immune to malware. Today, threat actors are aggressively shattering that illusion by deploying sophisticated initial access chains tailored to bypass macOS defenses. This talk provides a deep-dive analysis of how modern adversaries gain their first foothold on Apple hardware.

We will dissect the entire initial access pipeline, starting with Infection Vectors like deceptive Google Ads, malicious ClickFix campaigns, and sophisticated malvertising that trick users into lowering their guard. From there, we explore the Execution Phase, analyzing how attackers weaponize scripting languages, including traditional Bash and Python, as well as native AppleScript, Compiled AppleScript, Perl, and JavaScript for Automation (JXA). Finally, we will examine the delivery mechanisms, contrasting the abuse of native Binaries (Mach-O, Platypus-packaged apps, and Electron frameworks) with the trojanization of Storage and Installer Formats (DMGs and PKGs).

Attendees will walk away with a technical understanding of contemporary macOS tradecraft, real-world attacker methodologies, and the insights needed to hunt for and defend against modern Mac-focused threats.</abstract>
                <slug>call-for-paper-presentations-2026-74-deconstructing-modern-macos-initial-access-vectors</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='73'>Stephan Berger</person>
                </persons>
                <language>en</language>
                <description>We begin by exploring the top of the funnel. Attackers have moved far beyond easily identifiable spam. We will deconstruct recent campaigns to show how adversaries are successfully lowering user guard through:

How threat actors weaponize Google Ads to push malicious software disguised as legitimate enterprise tools (e.g., Slack, Notion, or VPN clients).
A deep dive into localized, highly convincing fake browser updates and system notification campaigns that socially engineer users into bypassing native warnings.

Once the user interacts with the lure, how does the malware actually run? macOS is a rich Unix-based environment with multiple scripting avenues. We will analyze the &quot;Living off the Land&quot; (LotL) techniques currently dominating the macOS threat landscape, including:

The use of Bash, Zsh, and legacy Python/Perl scripts to establish persistence and pull down secondary payloads.
How attackers weaponize Apple&#8217;s native automation languages to silently interact with system APIs, bypass sandbox restrictions, and generate convincing fake credential prompts.
Techniques used by threat actors to obfuscate their code, making static analysis incredibly difficult for defenders.

Finally, we will break down how these threats are packaged to evade Gatekeeper and initial static analysis. We will compare and contrast real-world samples across:

The weaponization of standard Apple Disk Images (.dmg) and Installer Packages (.pkg), including pre-install/post-install script abuse.
The shift from standalone Mach-O binaries to hiding malicious routines inside Platypus-packaged applications and bloated Electron frameworks, which are notoriously difficult for traditional AV to parse effectively.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZETL7P/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZETL7P/feedback/</feedback_url>
            </event>
            <event guid='05e18fc1-b4c1-5cbd-9f5d-0a2868f65926' id='15' code='XPLEJW'>
                <room>Gro&#223;er Saal</room>
                <title>Lessons learned while building an Agentic SOC: The good, the bad, and the scary.</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-10T15:25:00+02:00</date>
                <start>15:25</start>
                <duration>00:55</duration>
                <abstract>The AI powered SOC is coming whether you are ready or not, as attackers use AI to accelerate their operations we have to also go faster. Moving from a traditional SOC to an &quot;Agentic&quot; SOC is often pitched as a magic bullet for SOC automation, but because you can&apos;t stop your SOC sometimes the process feels like upgrading your engine while going 200 km/h on the Autobahn, and the upgrades you make are sometimes superseded the moment you add it. 

This talk bypasses the AI hype to share the real internal journey at Elastic as we integrated AI agents and processes into our daily SecOps. I&apos;ll talk about the Agentic Boundary: the point where the agent stops and the human starts, the lessons learned when building the agents, and how to connect your data to the agents. I&apos;ll cover the &apos;good&apos; where AI Agents are doing amazing things like L1 triage and timeline creation, the &apos;bad&apos; where agents used a bunch of time and tokens to provide mediocre or wrong results, and some of the &apos;scary&apos; such as how AI agents can turn on you to be the cause of a security incident instead of a helper. This talk will also address the scariest AI topic of them all: &apos;will this replace me?&apos;</abstract>
                <slug>call-for-paper-presentations-2026-15-lessons-learned-while-building-an-agentic-soc-the-good-the-bad-and-the-scary</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='11'>Aaron Jewitt</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/XPLEJW/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/XPLEJW/feedback/</feedback_url>
            </event>
            <event guid='2f5ba4ab-2c20-550e-b09a-f5bdd9cb1a6d' id='72' code='3WDFBK'>
                <room>Gro&#223;er Saal</room>
                <title>Keyless Entry: Hacking SwitchBot Smartlocks</title>
                <subtitle></subtitle>
                <type>Short-Talk</type>
                <date>2026-09-10T16:20:00+02:00</date>
                <start>16:20</start>
                <duration>00:25</duration>
                <abstract>Smart locks are rapidly replacing physical keys, but trusting your front door to an IoT device still comes with significant risks. In this talk, we will dissect the highly rated SwitchBot Lock Pro and demonstrate how a classic cryptographic implementation flaw allowed anyone to silently unlock the door without an physical tampering. By reverse-engineering the firmware and analyzing the custom Bluetooth Low Energy (BLE) protocol between the outdoor keypad and the indoor actuator, we discovered the system relies on AES in Counter (CTR) mode with zero integrity checks. We will demonstrate how we exploited this to create a universal, software-only UNLOCK payload. Join us as we showcase the live exploit, break down the vendor&apos;s flawed patch, explain how backward compatibility significantly delayed the patch, and celebrate our massive 100&#8364; bug bounty.</abstract>
                <slug>call-for-paper-presentations-2026-72-keyless-entry-hacking-switchbot-smartlocks</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='71'>Kolja Grassmann</person>
                </persons>
                <language>en</language>
                <description>While selecting targets for a team IoT hacking event, the SwitchBot Lock Pro Combo stood out: it is one of the most sold smart locks on the market, offering PIN, fingerprint, NFC, and app-based entry. The hardware consists of an indoor actuator that turns the physical key and an outdoor keypad. However, our initial recon of the Android app revealed, that the outdoor keypad holds the decision-making logic and sends execution commands to the indoor actuator over unprotected BLE, relying entirely on a custom application-layer encrypted protocol.

Diving deeper into this custom protocol, we discovered a fatal cryptographic failure. The devices negotiate a secret key and a nonce, but they encrypt their commands using AES in Counter (CTR) mode. Because CTR mode turns a block cipher into a stream cipher and lacks any integrity protection (like a MAC), bit-flips in the ciphertext propagate directly to the plaintext upon decryption without an opportunity to detect the manipulation.

In this 30-minute presentation, we will walk the audience through how we weaponized this exact flaw. Because a keypad&apos;s LOCK button always broadcasts an encrypted command, an attacker only needs to sniff it. We will explain the math behind our &quot;master key&quot;, which only required a pre-computed XOR between encrypted LOCK and UNLOCK commands that is identical across all sessions and locks. By simply applying this to any sniffed LOCK ciphertext, we can instantly forge a valid UNLOCK command and open the door. We will give a live demonstration of this software-only attack in action.

Finally, we will detail our responsible disclosure journey, which serves as a perfect case study in the difficulties of patching IoT ecosystems. The vendor&apos;s initial beta patch attempted to add a 2-byte truncated MD5 &quot;YOLO hash&quot; for integrity verification. However, because updating the entire ecosystem takes time, the lock still had to accept legacy commands from the smartphone app. We will show how we trivially bypassed the new patch by simply spoofing the smartphone app, ignoring the checksum entirely.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/3WDFBK/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/3WDFBK/feedback/</feedback_url>
            </event>
            <event guid='a2b5cbde-90ee-5ce2-b4ae-afa89d1843ca' id='43' code='ZCPUYM'>
                <room>Gro&#223;er Saal</room>
                <title>Pentesting in the age of AI - where are we?</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-09-10T16:45:00+02:00</date>
                <start>16:45</start>
                <duration>00:55</duration>
                <abstract>This talk focuses on the opportunities, limitations, and practical results of using AI in penetration testing.

We will compare different approaches to application security testing, including static and dynamic analysis, and examine where AI can provide value in each of them. In particular, we will look at several modes of AI-assisted security testing:

* AI-driven source code analysis
* AI-assisted verification of static analysis tool findings
* AI-driven runtime analysis using custom scripts
* AI-assisted verification of results from established security tools

The effectiveness of these approaches varies significantly depending on the selected method, model, tooling, and target environment.

Instead of relying on idealized lab scenarios, this talk presents real-world results from practical security testing. Beyond classical web application penetration testing, an area where AI already performs comparatively well, we will also explore the use of AI in Active Directory and Windows environment exploitation.

The audience will leave with a realistic understanding of where AI can currently support penetration testers, where it still falls short, and which workflows are most promising in practice.</abstract>
                <slug>call-for-paper-presentations-2026-43-pentesting-in-the-age-of-ai-where-are-we</slug>
                <track>Main Track</track>
                
                <persons>
                    <person id='44'>Christian Biehler</person>
                </persons>
                <language>en</language>
                <description>An AI agent for a few hundred euros doing the job of a highly skilled senior penetration tester? That sounds great. But are we actually there yet?

This talk explores different ways of using AI for static and dynamic security analysis. We will look at AI as the pentester, AI as an assistant for validating tool output, and AI as the convenient interface for people who are too lazy to read the manual.

Evaluating the results of today&#8217;s AI-based pentesting projects can feel familiar to anyone who has reviewed a junior tester&#8217;s first report: some valid findings, some interesting ideas, some missing context, and a few confidently incorrect conclusions.

So what is the real issue? Is AI still not good enough, or is the person in front of the prompt part of the problem?

Focusing on Static Application Security Testing and Dynamic Application Security Testing, this talk presents practical examples, real-world observations, and a sober assessment of where AI can support penetration testing today. We will discuss what works, what fails, and why blindly trusting AI-generated security results is still a bad idea.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZCPUYM/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ZCPUYM/feedback/</feedback_url>
            </event>
            <event guid='0324faf3-a98b-5f86-935e-8b2658dc855b' id='107' code='ELHBVZ'>
                <room>Gro&#223;er Saal</room>
                <title>Outro</title>
                <subtitle></subtitle>
                <type>Short-Talk</type>
                <date>2026-09-10T17:40:00+02:00</date>
                <start>17:40</start>
                <duration>00:15</duration>
                <abstract>Closing</abstract>
                <slug>call-for-paper-presentations-2026-107-outro</slug>
                <track>Main Track</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ELHBVZ/</url>
                <feedback_url>https://cfp.bsidesfrankfurt.org/call-for-paper-presentations-2026/talk/ELHBVZ/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
