A recap of BSides San Antonio 2026 covering three key security sessions. The first explored how production apps can leak secrets even when CI/CD and static scans pass clean, recommending layered defense including BFF patterns and artifact scanning. The second demonstrated how over-permissioned Azure managed identities in serverless resources (Logic Apps, Function Apps, Automation Accounts) can be exploited for lateral movement and privilege escalation. The third addressed why GRC programs fail in practice — controls exist on paper but lack operational evidence — using the cobra effect as an analogy. The unifying theme: attackers exploit trust that has already been granted, and security must follow trust paths through the entire system, not just check boxes.