Sched.com Conference Mobile Apps
OWASP Global AppSec USA 2026
OWASP Global AppSec USA 2026
Sign up
or
log in
to add sessions to your schedule and sync them to your phone or calendar.
About
Schedule
Know before you go!
Venue Map
Search
Menu
About
Schedule
Know before you go!
Venue Map
Search
Share your event
Share via
or Copy link
Copy
Event Schedule
My Schedule
0
View
Simple
Expanded
Grid
By Venue
View
Simple
Expanded
Grid
By Venue
Audience:
Intermediate
clear filter
Monday
, November 2
9:00am
PST
3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
TBA
Abraham Aranguren
3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
TBA
Adam Shostack
3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
TBA
Dawid Czagan
Tuesday
, November 3
9:00am
PST
2-Day Training: AI SecureOps: Attacking & Defending AI Applications & Agents
TBA
Abhinav Singh
2-Day Training: Repeatable, Scalable and Valuable Code Security Scanning
TBA
Avi Douglen
2-Day Training: Secure Coding That Sticks: From Bad Code to Secure Design
TBA
Tanya Janca
3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
TBA
Abraham Aranguren
3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
TBA
Adam Shostack
3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
TBA
Dawid Czagan
Wednesday
, November 4
9:00am
PST
1-Day Training: Building Continuous SaaS Integration Security: Signals, Least Privilege, and Evidence Automation
Pranav Saji
1-Day Training: How to build a Successful Security Champions Program
TBA
Marisa Fagan • Juliane Reimann
1-Day Training: OWASP AI Testing Guide (AITG): Enabling Trustworthy AI Through Structured Validation
TBA
Matteo Meucci • Marco Morana
2-Day Training: AI SecureOps: Attacking & Defending AI Applications & Agents
TBA
Abhinav Singh
2-Day Training: Repeatable, Scalable and Valuable Code Security Scanning
TBA
Avi Douglen
2-Day Training: Secure Coding That Sticks: From Bad Code to Secure Design
TBA
Tanya Janca
3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
TBA
Abraham Aranguren
3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
TBA
Adam Shostack
3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
TBA
Dawid Czagan
Thursday
, November 5
10:30am
PST
Beyond Provenance: Integrating Weight-Integrity Attestation Into Your AIBOM Pipeline
Room: Grand Ballroom A (Street Level)
Bodhisattva Das
The Human Approval Button Is Not a Security Boundary
Room: Grand Ballroom B (Street Level)
Anusha Vajha
So your developers hate you... How to turn reluctant devs into AppSec champions
Room: Bayview B (Bay Level)
Dr. Katie Paxton-Fear
11:30am
PST
Exploits of Agency: Mapping out insecure development patterns across the agentic landscape
Room: Grand Ballroom A (Street Level)
Dan Lisichkin
Crypto Is Fine. The Code Is Not: OWASP A04 Cryptographic Failures Through Real-World CVEs
Room: Grand Ballroom B (Street Level)
Diptendu Kar
How Security Champions can keep AI-driven software safe
Room: Bayview B (Bay Level)
Stanley Harris
Beyond Detection: What We Learned Testing Every AI Approach to Vulnerability Classification
Room: Seacliff AB (Bay Level)
Arshan Dabirsiaghi • Ryan Dens
1:15pm
PST
Intent Contracts: Giving AI Agents the Missing Context for Safe Infrastructure Changes
Room: Grand Ballroom A (Street Level)
Chris Wysopal
Enterprise AppSec That Scales Itself
Room: Bayview B (Bay Level)
Dheven Kara • Kailey Stauble
Reproducing the exploit, not the report
Room: Seacliff AB (Bay Level)
Hugo Guillaume • Hedi Sfaxi
2:15pm
PST
When the Robot Writes the Bug: A Merge Gate for AI-Generated Code
Room: Grand Ballroom B (Street Level)
Maulik Bhatt
Prompt Injection Through the Image Channel of Multimodal LLMs: An Ignored Attack Surface
Room: Grand Ballroom C (Street Level)
Pavan Reddy
The attacker does not sort by CVSS
Room: Bayview B (Bay Level)
Hugo Guillaume
Download, Merge, Compromised: A Live Backdoored Coding Model From a Public Hub
Room: Seacliff AB (Bay Level)
Vishal Khobare • Sandeep Kamble
3:30pm
PST
No value until it’s fixed: turning security reviews into a remediation loop
Room: Bayview B (Bay Level)
Emil Kvarnhammar
Same Bug, Bigger Blast Radius: Breaking AI Control Planes with Classic AppSec
Room: Seacliff AB (Bay Level)
Aditi Bhatnagar
Friday
, November 6
10:30am
PST
Losing Context: Breaking & Binding MCP Sessions
Room: Grand Ballroom B (Street Level)
Srikanth Ramu
When Finding Bugs Is the Easy Part: Lessons from an Agentic Vulnerability Harness
Room: Seacliff AB (Bay Level)
Venkata Suresh Sanga • Milind Daftari • Yuliana Martirosyan • Daniel Fernandez Coviella
11:30am
PST
Finding Pwn Requests in OSS: Auditing CI/CD Pipelines for Supply-Chain Vulnerabilities at Scale
Room: Grand Ballroom A (Street Level)
Arpit Jain
Modelling for Agentic Failure; when attack trees meet safety engineering
Room: Grand Ballroom C (Street Level)
Petra Vukmirovic
Shadow AI is the new Shadow IT
Room: Bayview B (Bay Level)
Sebastian Avarvarei
Context Confusion Is the New Broken Access Control
Room: Seacliff AB (Bay Level)
Anusha Vajha
1:15pm
PST
LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
Room: Grand Ballroom A (Street Level)
Aviv Donenfeld
So you think AI writes secure code?
Room: Grand Ballroom B (Street Level)
Shruti Datta Gupta • Joseph Seasly
Why Developers Can and We Can't: Making Security Findings That Agents (and Humans) Can Act On
Room: Bayview B (Bay Level)
Hai Maler
2:15pm
PST
When Nobody Wrote the Code: Engineering Lessons from Building AI-Native Application Security
Room: Grand Ballroom B (Street Level)
Manoj Kumar Yuvanesh • Uday Bhaskar Seelamantula
Post Quantum Crypto (PQC) - Field-Tested Strategies to Defeat Harvest Now, Decrypt Later
Room: Grand Ballroom C (Street Level)
Anshu Gupta
The Hidden Risks of Service-to-Service Trust in Microservice Architectures
Room: Seacliff AB (Bay Level)
Bhaumik Shah
3:30pm
PST
Pre-Flight Security Review for MCP Servers Using the OWASP MCP Top 10
Room: Grand Ballroom B (Street Level)
Vinothini Raju
From Design Docs to Mitigations: Scaling Pre-Launch Security Review with Historical Decisions
Room: Grand Ballroom C (Street Level)
Liat Ben Porat • Guy Shtar
Breaking the Headcount Scaling Model: How GitLab's Product Security Teams Achieved Non-Linear Securi
Room: Bayview B (Bay Level)
Vitor Meireles
Finding the Infrastructure Trust Layer: AI-Assisted Discovery of Cross-Product SSRF Classes
Room: Seacliff AB (Bay Level)
Ofri Ouzan • Stav David
Filter By Date
Nov 2
-
6, 2026
Monday
, November 2
Tuesday
, November 3
Wednesday
, November 4
Thursday
, November 5
Friday
, November 6
Filter By Venue
Hyatt Regency San Francisco, CA
All
Expo Hall, Pacific Concourse
Foyer
Hyatt Regency, Lower Atrium
Pacific Concourse
Room: Bay Level Foyer
Room: Bayview A
Room: Bayview A (Bay Level)
Room: Bayview B (Bay Level)
Room: Boardroom A (Lobby Level)
Room: Grand Ballroom A (Street Level)
Room: Grand Ballroom B (Street Level)
Room: Grand Ballroom C (Street Level)
Room: Grand Ballroom Foyer (Street Level)
Room: Marina (Bay Level)
Room: Regency (Street Level)
Room: Seacliff AB (Bay Level)
Room: Waterfront E (Lobby Level)
Room: Waterfront Foyer (Street Level)
TBA
Filter By Type
1-Day Training
2-Day Training
3-Day Training
Bonus Track
Capture the Flag
Deployment and Maintenance
Expo Hall
Implementation
Keynote
Meals Provided by OWASP
Meeting
MiniCon: OWASP by Design
Planning and Design
PODS (Hands-on Activities)
Process and Culture
Project User Day
Testing
Audience
Advanced
All
Beginner
Closed Session
Intermediate
Introductory and Overview
Popular
Share Modal
Share this link via
Or copy link
Copy
Filter sessions
Apply filters to sessions.
Filtered by
Audience
(Intermediate) -
Clear filter
close
Dates
Monday
, November 2
Tuesday
, November 3
Wednesday
, November 4
Thursday
, November 5
Friday
, November 6
Venue
Expo Hall, Pacific Concourse
Foyer
Hyatt Regency, Lower Atrium
Pacific Concourse
Room: Bay Level Foyer
Room: Bayview A
Room: Bayview A (Bay Level)
Room: Bayview B (Bay Level)
Room: Boardroom A (Lobby Level)
Room: Grand Ballroom A (Street Level)
Room: Grand Ballroom B (Street Level)
Room: Grand Ballroom C (Street Level)
Room: Grand Ballroom Foyer (Street Level)
Room: Marina (Bay Level)
Room: Regency (Street Level)
Room: Seacliff AB (Bay Level)
Room: Waterfront E (Lobby Level)
Room: Waterfront Foyer (Street Level)
TBA
Session Type
1-Day Training
2-Day Training
3-Day Training
Bonus Track
Capture the Flag
Deployment and Maintenance
Expo Hall
Implementation
Keynote
Meals Provided by OWASP
Meeting
MiniCon: OWASP by Design
Planning and Design
PODS (Hands-on Activities)
Process and Culture
Project User Day
Testing
Other Filters
Audience
Advanced
All
Beginner
Closed Session
Intermediate
Introductory and Overview
Popular