Loading…
Monday, November 2
 

8:15am PST

Breakfast
Monday November 2, 2026 8:15am - 9:00am PST

Monday November 2, 2026 8:15am - 9:00am PST
Room: Bay Level Foyer

8:15am PST

Registration
Monday November 2, 2026 8:15am - 3:30pm PST

Monday November 2, 2026 8:15am - 3:30pm PST
Room: Bay Level Foyer

9:00am PST

3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
Monday November 2, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level:IntermediateTrainer: Abraham ArangurenTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Modern Android and iOS apps rarely operate alone. They sit at the center of rich ecosystems: phones talking to toys, drones, wearables, vehicles, trackers, “smart” homes—and, in multiple...
See More →
Speakers
avatar for Abraham Aranguren

Abraham Aranguren

CEO, Security Trainer, Director of Penetration Testing, 7ASecurity

Abraham Aranguren is the founder and CEO of 7ASecurity (7asecurity.com), an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter specializing in high‑quality, manual penetration tests and secure code audits. He has more than 24 years of experience... Read More →
Monday November 2, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
Monday November 2, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level:IntermediateTrainer: Adam ShostackTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.This is our popular Threat Modeling Intensive course, where you'll learn to Threat Model, and then you'll learn how to incorporate large language models (LLMs) into every stage of the threat modeling...
See More →
Speakers
Monday November 2, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Building AI-based security tools & SDLC
Monday November 2, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level: BeginnerTrainer:Jon McCoyTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Day 1: The Toolsmith (AI-Augmented Security Engineering)*Focus: Building a high-velocity toolkit for rapid security synthesis and infrastructure hardening.**   **The Synthesis Workflow**   ...
See More →
Speakers
avatar for Jon McCoy

Jon McCoy

Principal Security Architect & Offensive Engineering Specialist, DigitalBodyGuard
Jon McCoy brings more than 20 years of hands-on experience in software engineering, application
security, live system forensics, infrastructure defense, and custom security tooling. He helps
companies build and secure the back-end systems behind modern AI products, automation
platfo


... Read More →
Monday November 2, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
Monday November 2, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level: IntermediateTrainer: Dawid CzaganTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Modern IT systems are increasingly complex, making full-stack expertise more essential than ever. That's why diving into full-stack pentesting is crucial—you will gain the skills needed to master modern...
See More →
Speakers
avatar for Dawid Czagan

Dawid Czagan

Founder and CEO, Silesia Security Lab
Dawid Czagan is an internationally recognized security researcher and trainer. He is listed among top hackers at HackerOne. Dawid Czagan has found security bugs in Apple, Google, Mozilla, Microsoft and many others.

Due to the severity of many bugs, he received numerous awards for his findings. Dawid Czagan shares his security experience in his hands-on trainings. He delivered trainings at key industry conferences such as DEF CON (Las Vegas), OWASP 2025 Global AppSec EU (Barcelona), Hack In The... Read More →
Monday November 2, 2026 9:00am - 5:00pm PST
TBA

10:30am PST

AM Break
Monday November 2, 2026 10:30am - 11:00am PST

Monday November 2, 2026 10:30am - 11:00am PST
Room: Bay Level Foyer

12:30pm PST

Lunch
Monday November 2, 2026 12:30pm - 1:30pm PST

Monday November 2, 2026 12:30pm - 1:30pm PST
Room: Bay Level Foyer

3:00pm PST

PM Break
Monday November 2, 2026 3:00pm - 3:30pm PST

Monday November 2, 2026 3:00pm - 3:30pm PST
Room: Bay Level Foyer
 
Tuesday, November 3
 

8:15am PST

Breakfast
Tuesday November 3, 2026 8:15am - 9:00am PST

Tuesday November 3, 2026 8:15am - 9:00am PST
TBA

8:15am PST

Registration
Tuesday November 3, 2026 8:15am - 3:30pm PST

Tuesday November 3, 2026 8:15am - 3:30pm PST
Room: Bay Level Foyer

9:00am PST

2-Day Training: AI SecureOps: Attacking & Defending AI Applications & Agents
Tuesday November 3, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026Level: IntermediateTrainers: Abhinav SinghTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Can prompt injections lead to complete infrastructure takeovers? Could AI agents, MCP-connected tools, or poisoned external context be abused to compromise backend services? Can data poisoning in...
See More →
Speakers
avatar for Abhinav Singh

Abhinav Singh

Cyber Security Research in AI,Cloud & Data., Wingback Security
Abhinav Singh is a security leader, founder of Wingback Security, and a globally recognized speaker and trainer focused on securing enterprise AI systems. He has been involved with AI fellowship and research communities including MATS, PIBBSS, CSA, AIUC, and the Foresight Institute... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling
Tuesday November 3, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026Level:IntermediateTrainer: Sebastien DeleersnyderTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.This training immerses you in the practical world of threat modeling through hands-on exercises and real-world scenarios. With 25 years of practical experience andover a decade of delivering...
See More →
Speakers
avatar for Sebastien Deleersnyder

Sebastien Deleersnyder

CTO, Toreon
Sebastien (Seba) Deleersnyder is co-founder and CTO of Toreon and a proponent of application security as a holistic approach. He started the Belgian OWASP chapter, was an OWASP Foundation Board member, and has given numerous public presentations on Application Security. Seba also... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: Repeatable, Scalable and Valuable Code Security Scanning
Tuesday November 3, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026Level: IntermediateTrainers:Avi DouglenTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Suddenly anyone and everyone in your organization can use AI assistants to write code. Meanwhile, your actual developers are putting out 100x their previous output , with “varying” levels of...
See More →
Speakers
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: Secure Coding That Sticks: From Bad Code to Secure Design
Tuesday November 3, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026Level: IntermediateTrainers:Tanya JancaTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Most developers have heard security advice before. The problem is, it rarely translates into what to actually do when you're writing code.This two-day, hands-on training focuses on building secure...
See More →
Speakers
avatar for Tanya Janca

Tanya Janca

Security Trainer and Founder, She Hacks Purple
Tanya Janca is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the CEO of She Hacks Purple Consulting, where she delivers high-impact, live, secure-coding training for engineering teams. She is also the host of DevSec... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
Tuesday November 3, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level:IntermediateTrainer: Abraham ArangurenTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Modern Android and iOS apps rarely operate alone. They sit at the center of rich ecosystems: phones talking to toys, drones, wearables, vehicles, trackers, “smart” homes—and, in multiple...
See More →
Speakers
avatar for Abraham Aranguren

Abraham Aranguren

CEO, Security Trainer, Director of Penetration Testing, 7ASecurity

Abraham Aranguren is the founder and CEO of 7ASecurity (7asecurity.com), an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter specializing in high‑quality, manual penetration tests and secure code audits. He has more than 24 years of experience... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
Tuesday November 3, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level:IntermediateTrainer: Adam ShostackTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.This is our popular Threat Modeling Intensive course, where you'll learn to Threat Model, and then you'll learn how to incorporate large language models (LLMs) into every stage of the threat...
See More →
Speakers
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Building AI-based security tools & SDLC
Tuesday November 3, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level: BeginnerTrainer:Jon McCoyTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Day 1: The Toolsmith (AI-Augmented Security Engineering)*Focus: Building a high-velocity toolkit for rapid security synthesis and infrastructure hardening.**   **The Synthesis Workflow**   ...
See More →
Speakers
avatar for Jon McCoy

Jon McCoy

Principal Security Architect & Offensive Engineering Specialist, DigitalBodyGuard
Jon McCoy brings more than 20 years of hands-on experience in software engineering, application
security, live system forensics, infrastructure defense, and custom security tooling. He helps
companies build and secure the back-end systems behind modern AI products, automation
platfo


... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
Tuesday November 3, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level: IntermediateTrainer: Dawid CzaganTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Modern IT systems are increasingly complex, making full-stack expertise more essential than ever. That's why diving into full-stack pentesting is crucial—you will gain the skills needed to master modern...
See More →
Speakers
avatar for Dawid Czagan

Dawid Czagan

Founder and CEO, Silesia Security Lab
Dawid Czagan is an internationally recognized security researcher and trainer. He is listed among top hackers at HackerOne. Dawid Czagan has found security bugs in Apple, Google, Mozilla, Microsoft and many others.

Due to the severity of many bugs, he received numerous awards for his findings. Dawid Czagan shares his security experience in his hands-on trainings. He delivered trainings at key industry conferences such as DEF CON (Las Vegas), OWASP 2025 Global AppSec EU (Barcelona), Hack In The... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

Private OWASP Board Meeting
Tuesday November 3, 2026 9:00am - 5:00pm PST
This is a private session for OWASP Board of Directors.
Tuesday November 3, 2026 9:00am - 5:00pm PST
Room: Boardroom A (Lobby Level)

10:30am PST

AM Break
Tuesday November 3, 2026 10:30am - 11:00am PST

Tuesday November 3, 2026 10:30am - 11:00am PST
Room: Bay Level Foyer

12:30pm PST

Lunch
Tuesday November 3, 2026 12:30pm - 1:30pm PST

Tuesday November 3, 2026 12:30pm - 1:30pm PST
Room: Bay Level Foyer

3:00pm PST

PM Break
Tuesday November 3, 2026 3:00pm - 3:30pm PST

Tuesday November 3, 2026 3:00pm - 3:30pm PST
Room: Bay Level Foyer
 
Wednesday, November 4
 

8:15am PST

Breakfast
Wednesday November 4, 2026 8:15am - 9:00am PST

Wednesday November 4, 2026 8:15am - 9:00am PST
Room: Bay Level Foyer

8:15am PST

Registration
Wednesday November 4, 2026 8:15am - 5:00pm PST

Wednesday November 4, 2026 8:15am - 5:00pm PST
Room: Bay Level Foyer

9:00am PST

1-Day Training: Building Continuous SaaS Integration Security: Signals, Least Privilege, and Evidence Automation
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026Level: IntermediateTrainers: Pranav SajiTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.SaaS integrations are now a primary path for privilege creep, token sprawl, and silent exposure across an organization. In this hands-on training, participants learn how to assess and...
See More →
Speakers
avatar for Pranav Saji

Pranav Saji

Head of AI Security, Symosis Security
Pranav Saji is the Head of AI at Symosis Security, where he leads AI driven security and compliance initiatives focused on building production ready automation for SaaS integration risk signals and continuous evidence collection. His work helps security teams move from manual, periodic... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST

9:00am PST

1-Day Training: Evil User Stories Modeling: Ensuring your User Stories in agile playing OWASP Cornucopia
Wednesday November 4, 2026 9:00am - 5:00pm PST
How to streamline the identification of security requirements associated with software functionalities in agile methodologies using OWASP Cornucopia to plan and manage application security from analysis and design, and also manage security defects associated with unimplemented or poorly implemented controls.1. Introduction: Understand the theory about evil user stories modeling, when to execute in...
See More →
Speakers
avatar for Max Alejandro Gomez Sanchez Vergaray

Max Alejandro Gomez Sanchez Vergaray

AppSec & DevSecOps Consultant | Risk-driven Security for real-world products | S-SDLC, DevSecOps, Secure Design & Threat Modeling Trainer, AppSec & DevSecOps Consultant | Risk-driven Security for real-world products | S-SDLC, DevSecOps, Secure Design & Threat Modeling Trainer

I designed and led the application security program during the digital transformation process of one of the largest banks in Latin America, training more than 3,000 people in secure software development, specially in Secure Design using OWASP Cornucopia, another tools for threat modeling... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST

9:00am PST

1-Day Training: How to build a Successful Security Champions Program
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026Level: IntermediateTrainers: Juliane Reimann and Marisa FaganTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Do you feel a disconnect between your cybersecurity efforts and engineering activities? If so, a Security Champions Program could bridge the gap. By involving engineers in...
See More →
Speakers
MF

Marisa Fagan

Head of Product, Katilyst
avatar for Juliane Reimann

Juliane Reimann

Founder and Security Community Expert, Full Circle Security
Juliane Reimann works as cyber security consultant for large companies since 2019 with focus on DevSecOps and Community Building. Her expertise includes building security communities of software developers and establishing developer centric communication about secure software development... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

1-Day Training: OWASP AI Testing Guide (AITG): Enabling Trustworthy AI Through Structured Validation
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026Level: IntermediateTrainers: Marco Morana and Matteo MeucciTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.The OWASP AI Testing Guide (AITG) provides a structured, comprehensive framework for validating Trustworthy AI systems across their entire lifecycle. Designed to support QA teams,...
See More →
Speakers
avatar for Matteo Meucci

Matteo Meucci

Founder and CEO, Synapsed.ai
Matteo Meucci is the founder and CEO of Synapsed.ai, bringing over 23 years of experience in application security (AppSec) and AI systems development. Matteo has played a pivotal role in shaping the global security community, particularly through his work with OWASP, where he founded... Read More →
avatar for Marco Morana

Marco Morana

Founder, Threat Modeling Academy | Field CISO | Author & Instructor, Avocado Systems Inc

Marco Morana is the Founder of Threat Modeling Academy, a global training initiative dedicated to advancing threat modeling and secure-by-design engineering for AI, cloud, blockchain, and FinTech systems. He also serves as Field CISO at Avocado Systems Inc., where he advises enterprises... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

1-Day Training: Secure Code with AI: Building a Trustworthy Spec-Driven AI Code Workflow
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026Level: BeginnerTrainer: Jim ManicoTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.AI coding assistants are rapidly becoming the core of modern software delivery. They can accelerate development, generate tests, explain unfamiliar code, and assist with security review. They can also introduce...
See More →
Speakers
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: 2-Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling
Wednesday November 4, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026Level: BeginnerTrainer: Sebastien DeleersnyderTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.This training immerses you in the practical world of threat modeling through hands-on exercises and real-world scenarios. With 25 years of practical experience and over a decade of delivering this training...
See More →
Speakers
avatar for Sebastien Deleersnyder

Sebastien Deleersnyder

CTO, Toreon
Sebastien (Seba) Deleersnyder is co-founder and CTO of Toreon and a proponent of application security as a holistic approach. He started the Belgian OWASP chapter, was an OWASP Foundation Board member, and has given numerous public presentations on Application Security. Seba also... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: AI SecureOps: Attacking & Defending AI Applications & Agents
Wednesday November 4, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026Level: IntermediateTrainers: Abhinav SinghTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Can prompt injections lead to complete infrastructure takeovers? Could AI agents, MCP-connected tools, or poisoned external context be abused to compromise backend services? Can data poisoning in...
See More →
Speakers
avatar for Abhinav Singh

Abhinav Singh

Cyber Security Research in AI,Cloud & Data., Wingback Security
Abhinav Singh is a security leader, founder of Wingback Security, and a globally recognized speaker and trainer focused on securing enterprise AI systems. He has been involved with AI fellowship and research communities including MATS, PIBBSS, CSA, AIUC, and the Foresight Institute... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: Repeatable, Scalable and Valuable Code Security Scanning
Wednesday November 4, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026Level: IntermediateTrainers:Avi DouglenTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Suddenly anyone and everyone in your organization can use AI assistants to write code. Meanwhile, your actual developers are putting out 100x their previous output , with “varying” levels of...
See More →
Speakers
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: Secure Coding That Sticks: From Bad Code to Secure Design
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026Level: IntermediateTrainers:Tanya JancaTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Most developers have heard security advice before. The problem is, it rarely translates into what to actually do when you're writing code.This two-day, hands-on training focuses on building secure...
See More →
Speakers
avatar for Tanya Janca

Tanya Janca

Security Trainer and Founder, She Hacks Purple
Tanya Janca is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the CEO of She Hacks Purple Consulting, where she delivers high-impact, live, secure-coding training for engineering teams. She is also the host of DevSec... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA
  2-Day Training

9:00am PST

3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
Wednesday November 4, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level:IntermediateTrainer: Abraham ArangurenTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Modern Android and iOS apps rarely operate alone. They sit at the center of rich ecosystems: phones talking to toys, drones, wearables, vehicles, trackers, “smart” homes—and, in multiple...
See More →
Speakers
avatar for Abraham Aranguren

Abraham Aranguren

CEO, Security Trainer, Director of Penetration Testing, 7ASecurity

Abraham Aranguren is the founder and CEO of 7ASecurity (7asecurity.com), an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter specializing in high‑quality, manual penetration tests and secure code audits. He has more than 24 years of experience... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
Wednesday November 4, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level:IntermediateTrainer: Adam ShostackTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.This is our popular Threat Modeling Intensive course, where you'll learn to Threat Model, and then you'll learn how to incorporate large language models (LLMs) into every stage of the threat...
See More →
Speakers
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Building AI-based security tools & SDLC
Wednesday November 4, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level: BeginnerTrainer:Jon McCoyTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Day 1: The Toolsmith (AI-Augmented Security Engineering)*Focus: Building a high-velocity toolkit for rapid security synthesis and infrastructure hardening.**   **The Synthesis Workflow**   ...
See More →
Speakers
avatar for Jon McCoy

Jon McCoy

Principal Security Architect & Offensive Engineering Specialist, DigitalBodyGuard
Jon McCoy brings more than 20 years of hands-on experience in software engineering, application
security, live system forensics, infrastructure defense, and custom security tooling. He helps
companies build and secure the back-end systems behind modern AI products, automation
platfo


... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
Wednesday November 4, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026Level: IntermediateTrainer: Dawid CzaganTo register, please purchase your training ticket here. Training and conference are two separate ticket purchases.Modern IT systems are increasingly complex, making full-stack expertise more essential than ever. That's why diving into full-stack pentesting is crucial—you will gain the skills needed to master modern...
See More →
Speakers
avatar for Dawid Czagan

Dawid Czagan

Founder and CEO, Silesia Security Lab
Dawid Czagan is an internationally recognized security researcher and trainer. He is listed among top hackers at HackerOne. Dawid Czagan has found security bugs in Apple, Google, Mozilla, Microsoft and many others.

Due to the severity of many bugs, he received numerous awards for his findings. Dawid Czagan shares his security experience in his hands-on trainings. He delivered trainings at key industry conferences such as DEF CON (Las Vegas), OWASP 2025 Global AppSec EU (Barcelona), Hack In The... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

OWASP SAMM and DSOMM User Day
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026
Level: all
Trainers:Aram Hovsepyan and Timo Pagel 

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Learn more here!
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

10:30am PST

AM Break
Wednesday November 4, 2026 10:30am - 11:00am PST

Wednesday November 4, 2026 10:30am - 11:00am PST
Room: Bay Level Foyer

12:30pm PST

Lunch
Wednesday November 4, 2026 12:30pm - 1:30pm PST

Wednesday November 4, 2026 12:30pm - 1:30pm PST
Room: Bay Level Foyer

3:00pm PST

PM Break
Wednesday November 4, 2026 3:00pm - 3:30pm PST

Wednesday November 4, 2026 3:00pm - 3:30pm PST
Room: Bay Level Foyer

5:00pm PST

Global Board of Directors Public Board Meeting
Wednesday November 4, 2026 5:00pm - 7:00pm PST

Wednesday November 4, 2026 5:00pm - 7:00pm PST
Room: Waterfront E (Lobby Level)
 
Thursday, November 5
 

7:30am PST

Women in AppSec Breakfast (Sign up required)
Thursday November 5, 2026 7:30am - 8:30am PST
Must already be registered for the conference and sign up for breakfast is required.Come and enjoy a breakfast committeed to making conference friends and friends for life (AKA - professioinal networking) at the Women in AppSec Breakfast co-hosted by Tanya Janca, Juliane Reimann, Kim Wyuts, and Marisa Fagan.RSVP now to enjoy great food, pick up your challenge coin early, and walk through the expo...
See More →
Speakers
MF

Marisa Fagan

Head of Product, Katilyst
avatar for Tanya Janca

Tanya Janca

Security Trainer and Founder, She Hacks Purple
Tanya Janca is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the CEO of She Hacks Purple Consulting, where she delivers high-impact, live, secure-coding training for engineering teams. She is also the host of DevSec... Read More →
avatar for Juliane Reimann

Juliane Reimann

Founder and Security Community Expert, Full Circle Security
Juliane Reimann works as cyber security consultant for large companies since 2019 with focus on DevSecOps and Community Building. Her expertise includes building security communities of software developers and establishing developer centric communication about secure software development... Read More →
avatar for Kim Wuyts

Kim Wuyts

Manager Cyber & Privacy, PwC Belgium

Dr. Kim Wuyts is a leading privacy engineer with over 15 years of experience in security and privacy. Before joining PwC Belgium as Manager Cyber & Privacy, Kim was a senior researcher at KU Leuven where she led the development and extension of LINDDUN, a popular privacy threat modeling... Read More →
Thursday November 5, 2026 7:30am - 8:30am PST
TBA

8:00am PST

Registration
Thursday November 5, 2026 8:00am - 5:00pm PST

Thursday November 5, 2026 8:00am - 5:00pm PST
Pacific Concourse

8:15am PST

Coffee/tea
Thursday November 5, 2026 8:15am - 9:00am PST

Thursday November 5, 2026 8:15am - 9:00am PST
Expo Hall, Pacific Concourse

8:15am PST

Expo Hall
Thursday November 5, 2026 8:15am - 6:45pm PST

Thursday November 5, 2026 8:15am - 6:45pm PST
Expo Hall, Pacific Concourse

8:30am PST

Conference T-Shirt Pick up and OWASP Member Swag
Thursday November 5, 2026 8:30am - 4:00pm PST
Pick up your super fun conference t-shirt and member swag!

Thursday November 5, 2026 8:30am - 4:00pm PST
Room: Waterfront Foyer (Street Level)

8:30am PST

Start Up Sponsors
Thursday November 5, 2026 8:30am - 4:30pm PST

Thursday November 5, 2026 8:30am - 4:30pm PST
Room: Grand Ballroom Foyer (Street Level)

8:45am PST

OWASP Book and Merch Store
Thursday November 5, 2026 8:45am - 4:45pm PST
Calling all OWASP Merch and AppSec Book lovers!  Come visit Jonathan for your large selection of all things AppSec book relatated and don't forget to snag some OWASP merch too!
Thursday November 5, 2026 8:45am - 4:45pm PST
Room: Grand Ballroom Foyer (Street Level)

9:00am PST

Opening Remarks and Keynote, The End of Guessing: Security's Coming Market Correction
Thursday November 5, 2026 9:00am - 10:00am PST

Speakers
JG

Jeremiah Grossman

Co-Founder and CEO, Root Evidence
Jeremiah Grossman is a cybersecurity entrepreneur, investor, and Brazilian Jiu-Jitsu black belt with over 25 years of industry-defining impact. He began as one of Yahoo’s first information security officers before founding WhiteHat Security in 2001, which grew into the world’s... Read More →
Thursday November 5, 2026 9:00am - 10:00am PST
Room: Grand Ballroom A (Street Level)

10:00am PST

AM Break
Thursday November 5, 2026 10:00am - 10:30am PST

Thursday November 5, 2026 10:00am - 10:30am PST
Expo Hall, Pacific Concourse

10:00am PST

MiniCon: OWASP by Design
Thursday November 5, 2026 10:00am - 4:30pm PST
More Information to follow
Thursday November 5, 2026 10:00am - 4:30pm PST
Room: Bayview A

10:15am PST

Podcast Recording Room
Thursday November 5, 2026 10:15am - 2:00pm PST
For all of our podcasters out there, feel free to use this room to record and promote your podcast.
Thursday November 5, 2026 10:15am - 2:00pm PST
Room: Regency (Street Level)

10:15am PST

PODS (Hands-on Activities)
Thursday November 5, 2026 10:15am - 4:30pm PST
Hands-on activities - more information to follow
Thursday November 5, 2026 10:15am - 4:30pm PST
Room: Marina (Bay Level)

10:30am PST

Beyond Provenance: Integrating Weight-Integrity Attestation Into Your AIBOM Pipeline
Thursday November 5, 2026 10:30am - 11:15am PST
Most AI supply-chain security tooling stops at provenance. A signed manifest proves the model came from the publisher who claims to ship it. OWASP CycloneDX AIBOM, OpenSSF Model Signing, and HuggingFace's signed model cards all answer that question. None of them answer the next one - what is actually inside the weights you signed.The harder attack class lives in that gap. We built a working...
See More →
Speakers
BD

Bodhisattva Das

Security Researcher, RUDRA Cybersecurity
Bodhisattva Das is a Security Researcher at RUDRA Cybersecurity, and a graduate student at Carnegie Mellon University working on securing non-human identities, AI agents, and automated workloads across cloud environments. He specialises in open-source threat detection using Wazuh... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Grand Ballroom A (Street Level)

10:30am PST

The Human Approval Button Is Not a Security Boundary
Thursday November 5, 2026 10:30am - 11:15am PST
Agentic AI applications increasingly rely on human approval before taking sensitive actions such as sending messages, modifying records, querying business systems, creating tickets, or invoking external tools. Human-in-the-loop review is often treated as a safety control, but the approval step is only as strong as the context it exposes.This talk examines a practical implementation problem in...
See More →
Speakers
avatar for Anusha Vajha

Anusha Vajha

Security Engineer and Product Manager
Anusha Vajha is a cybersecurity practitioner focused on AI governance, product security, and enterprise AI risk. She has worked across security operations, GRC, detection engineering, and product security in healthcare, financial services, and startup environments.
Her work sits a... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Grand Ballroom B (Street Level)

10:30am PST

When the Fraud Analyst Becomes an Agent: Threat Modeling Autonomy in High-Stakes AppSec Workflows
Thursday November 5, 2026 10:30am - 11:15am PST
Most teams running fraud or abuse detection already have an AI assistant in the queue: it reads the signals on a flagged account, drafts a case summary, and a person decides what to do. What's changing is that these assistants are being given tools, memory, and the ability to act — to hold a transfer, freeze an account, file a report — usually a step at a time, without anyone treating it as a...
See More →
Speakers
avatar for Hamza Abubakar Kheruwala

Hamza Abubakar Kheruwala

Software engineer securing AI that can act

Hamza Abubakar Kheruwala is a software engineer whose work spans AI-assisted risk, fraud, and security systems in regulated environments, where automated decisions have to be auditable and hold up to review. That work covers telemetry pipelines, anomaly detection, and the LLM-assisted... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Grand Ballroom C (Street Level)

10:30am PST

So your developers hate you... How to turn reluctant devs into AppSec champions
Thursday November 5, 2026 10:30am - 11:15am PST
Committing to creating and managing an AppSec program is hard, and it's only made harder by our most beloved clients and teammates, reluctant developers. Developers who have typically enjoyed a life free of security concerns, managing their own work and shipping features on their timescale. It is, perhaps, understandable that adding security controls leads to friction and pain for our developers....
See More →
Speakers
avatar for Dr. Katie Paxton-Fear

Dr. Katie Paxton-Fear

Lecturer and Educational YouTuber, Manchester Metropolitan University
Dr Katie Paxton-Fear is a lecturer of cyber security at Manchester Metropolitan University, she's a hacker and YouTuber, she's made 50+ videos on a range of topics, explaining vulnerabilities, tools etc, and made a splash as an API hackerSpeaker Agreement
    @InsiderPhD
 lin... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Bayview B (Bay Level)

10:30am PST

Hacking Your Life with AI Can Get You Hacked: How AI Orchestration Platforms Ship RCE by Design
Thursday November 5, 2026 10:30am - 11:15am PST
AI orchestration platforms promise to automate your life. They deliver, just not always for you. Kestra, Langflow, Nocobase, Flowise, Activepieces, Dify, and Apache Airflow have quietly become critical infrastructure, and they all share the same dangerous assumption: anyone who can touch a workflow is trusted to run code on the host.I went hunting across seven major platforms and walked out with...
See More →
Speakers
PK

Peyton Kennedy

Senior Security Researcher, Endor Labs
Peyton Kennedy is a Senior Security Researcher, where he conducts security research on emerging open source technologies and analyzes vulnerabilities for the betterment of the community. Recent work has focused on AI and LLM integrations within open source projects and how trust boundaries... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Seacliff AB (Bay Level)
  Testing

11:15am PST

Puppy Lounge (Sponsored by Depthfirst)
Thursday November 5, 2026 11:15am - 1:15pm PST
Relax, forget your worries, and pet puppies!  These puppies are fully adoptable too!!
Thursday November 5, 2026 11:15am - 1:15pm PST
Expo Hall, Pacific Concourse

11:30am PST

Exploits of Agency: Mapping out insecure development patterns across the agentic landscape
Thursday November 5, 2026 11:30am - 12:15pm PST
At this point, agents are everywhere and they are pretty hard to ignore. They are showing up in our CI/CD life cycles, in code development, in code reviews, and in the day-to-day workflows that engineering teams are encouraged to adopt by both lower and upper management.Their deep integration into the development life cycle raises a serious question: how do we actually deploy agentic systems...
See More →
Speakers
avatar for Dan Lisichkin

Dan Lisichkin

AI Security Researcher, Pillar Security
Dan Lisichkin is the Cyber Security Researcher for Pillar Security, focusing on AI security, adversarial threats, and securing AI based systems. With over five years of experience in the cybersecurity and IT space, Dan has extensive knowledge in areas including malware analysis, reverse... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom A (Street Level)

11:30am PST

Crypto Is Fine. The Code Is Not: OWASP A04 Cryptographic Failures Through Real-World CVEs
Thursday November 5, 2026 11:30am - 12:15pm PST
Cryptography has a reputation for being intimidating, mathematical, and difficult to reason about. In reality, many cryptographic failures in production systems have very little to do with cryptography itself. They happen because of small implementation mistakes such as skipping a validation check, trusting unvalidated input, or selecting the wrong algorithm.In this talk, we take a practical and...
See More →
Speakers
avatar for Diptendu Kar

Diptendu Kar

Security Researcher, Semgrep
Diptendu Kar is a security researcher focused on supply chain and dependency risk. He works on triaging open-source vulnerabilities, writing detection rules, and exploring how AI can automate tedious parts of security research. He also teaches Software Security Practices at Northeastern... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom B (Street Level)

11:30am PST

Cage the Confused Deputy: Infrastructure-Layer Defense for Voice AI Agents
Thursday November 5, 2026 11:30am - 12:15pm PST
Deputies, like agentic AI models, do things on your behalf. A confused deputy does more than it should on your behalf. How do you unconfuse an inherently confused deputy? By telling it what it can and cannot do? But what if it gets confused, again?Current LLM technology is not capable of being completely immune to prompt injection. It is going to happen. This means the security boundaries for...
See More →
Speakers
avatar for Brian Cardinale

Brian Cardinale

Principal Security Researcher, SecureCoders
Brian Cardinale is the Principal Security Researcher at SecureCoders. He holds a CISSP and has spent his career breaking things that aren't supposed to break. Brian built VoiceGoat, the first open-source vulnerable voice AI agent, and leads RedCaller's research into adversarial testing... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom C (Street Level)

11:30am PST

How Security Champions can keep AI-driven software safe
Thursday November 5, 2026 11:30am - 12:15pm PST
AI tools are supercharging the speed at which development teams ship software. Developers are no longer just copy-pasting code snippets; they are using AI agent frameworks to automate multi-step engineering tasks. But this incredible speed comes with a hidden catch: if teams do not write secure instructions for these AI tools, or if they blindly trust what the machine generates, they open the door...
See More →
Speakers
avatar for Stanley Harris

Stanley Harris

CEO and Co-Founder, Katilyst
Stanley is the CEO and Cofounder of Katilyst, where he leads initiatives to build and enhance Security Champion programs. With over 15 years of experience in organizational change management, he has successfully designed and launched multiple Security Champion programs, fostering... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Bayview B (Bay Level)

11:30am PST

Beyond Detection: What We Learned Testing Every AI Approach to Vulnerability Classification
Thursday November 5, 2026 11:30am - 12:15pm PST
There has been considerable discussion on how to use AI to find vulnerabilities, but very little discussion on how to use it to classify vulnerabilities. Given the huge backlog of vulnerabilities in our systems, and the impending agentic coding revolution which will 100x them, a new approach is needed to accurately cull and rank issues. In this talk, we discuss agentic classification vs....
See More →
Speakers
avatar for Arshan Dabirsiaghi

Arshan Dabirsiaghi

CTO and Co-Founder, Pixee
Arshan is a security researcher and developer pretending to be a software executive, with many years of experience advising large organizations on code security and building tooling to support secure code development. He has spoken at prestigious conferences like Blackhat and OWASP... Read More →
avatar for Ryan Dens

Ryan Dens

Software Engineer, Pixee
Ryan is a software engineer passionate about security and developer productivity
   linkedin.com/in/ryan-dens/
 ryandens.com (blog)
 pixee.ai (company)
... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Seacliff AB (Bay Level)

12:15pm PST

Lunch
Thursday November 5, 2026 12:15pm - 1:15pm PST

Thursday November 5, 2026 12:15pm - 1:15pm PST
Expo Hall, Pacific Concourse

1:15pm PST

Panel Discussion
Thursday November 5, 2026 1:15pm - 2:00pm PST

Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom B (Street Level)

1:15pm PST

Intent Contracts: Giving AI Agents the Missing Context for Safe Infrastructure Changes
Thursday November 5, 2026 1:15pm - 2:00pm PST

Speakers
avatar for Chris Wysopal

Chris Wysopal

Chief Security Evangelist & Co-founder, Veracode

Chris Wysopal is Veracode's Chief Security Evangelist and co-founder. He is one of the original vulnerability researchers and an early member of L0pht Heavy Industries, which he joined in 1992. He is the author of netcat for Windows and one of the authors of L0phtCrack. He has testified... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom A (Street Level)

1:15pm PST

Controlling Decryption in Zero Trust Cloud Workloads
Thursday November 5, 2026 1:15pm - 2:00pm PST
Cloud applications are increasingly used to process highly sensitive artifacts such as adversary simulation reports, threat intelligence, and vulnerability assessments. While encryption in transit and at rest is now standard, it does not answer a harder question: when and under what conditions should an application be allowed to see plaintext data?This session presents a practical design for...
See More →
Speakers
avatar for Anjali Mangal

Anjali Mangal

Principal Director of Security Research, Microsoft
Anjali Mangal is a Principal Director of Security Research at Microsoft, where she leads security validation, adversary emulation, and AI security initiatives across Microsoft Security products and services. Anjali's work spans threat intelligence, detection engineering, cloud security... Read More →
avatar for Vamshi Krishna Thotempudi

Vamshi Krishna Thotempudi

Senior Applied Data Scientist, focused on AI/ML, LLM-driven automation, and cloud-scale threat detection, Microsoft Security Research
Vamshi Krishna Thotempudi is a Senior Applied Data Scientist at Microsoft Security Research, working on AI/ML-driven automation, LLM-based security research, and cloud-scale threat detection. He has 13 years of experience across artificial intelligence, machine learning, natural language... Read More →
avatar for Mahima Agarwal

Mahima Agarwal

Senior Machine Learning Engineer, Microsoft Security
Mahima Agarwal is a Senior Machine Learning Engineer at Microsoft Security specializing in the intersection of AI, machine learning, and cybersecurity. Her work focuses on building large-scale systems for threat detection, security analytics, and detection engineering, including the... Read More →
avatar for Raghav Batta

Raghav Batta

Principal Manager in AI Security Research, Microsoft Security,
Raghav Batta is a Principal Manager in AI Security Research at Microsoft Security, where he leads research at the intersection of artificial intelligence and cybersecurity. His work focuses on applying large language models, agentic AI, and large-scale machine learning to improve... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom C (Street Level)

1:15pm PST

Enterprise AppSec That Scales Itself
Thursday November 5, 2026 1:15pm - 2:00pm PST
Every enterprise security team knows the math doesn't work. You have a thousand applications in your environment. Your team can comprehensively assess maybe sixty a year, and can only onboard a subset of that to the industry standard tools. Configuration drifts the moment you look away, integrations multiply in the dark, and by the time you circle back to re-assess an app, the environment has...
See More →
Speakers
avatar for Dheven Kara

Dheven Kara

Enterprise Security Engineer, Palo Alto Networks
Dheven Kara is an Enterprise Security Engineer at Palo Alto Networks where he works on strengthening security across large-scale enterprise environments. His background combines hands-on security engineering with a practical understanding of how organizations manage risk, improve... Read More →
avatar for Kailey Stauble

Kailey Stauble

Enterprise Security Engineer, Palo Alto Networks
Kailey Stauble is an Enterprise Security Engineer at Palo Alto Networks where she works on strengthening security across large-scale enterprise environments. Her background combines hands-on security engineering with a practical understanding of how organizations manage risk, improve... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Bayview B (Bay Level)

1:15pm PST

Reproducing the exploit, not the report
Thursday November 5, 2026 1:15pm - 2:00pm PST
Bug bounty reports and CVE claims are cheap. Running the vulnerable application is the hard part.A plausible report describes the attack, not the setup. It gives you an endpoint, a payload, maybe a curl command. It doesn't give you the exact historical version, the plugin that has to be enabled, the seed data, the OAuth redirect, the undocumented CSRF header, or the Docker image that breaks before...
See More →
Speakers
avatar for Hugo Guillaume

Hugo Guillaume

Security Engineer, Konvu
Hugo Guillaume is a security researcher. He spent close to three years on offensive and defensive security research in a government national-defense setting, doing vulnerability research and reverse engineering and building automated bug-discovery systems. He also teaches cybersecurity... Read More →
avatar for Hedi Sfaxi

Hedi Sfaxi

Product Engineer, Konvu
Product Engineer at Konvu, a cybersecurity startup based between Paris and New York, backed by $5M in seed funding. Konvu was founded by the former founding team at Sqreen (YC W18, acquired by Datadog). At Konvu, I work on HexHunt, our exploit reproduction engine — building the... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Seacliff AB (Bay Level)

2:15pm PST

The Compromised Maintainer Problem: Detecting Malicious Code in Legitimate Dependencies
Thursday November 5, 2026 2:15pm - 3:00pm PST
Supply chain attacks have changed. A few years ago the story was typosquatting and obviously sketchy packages with five downloads. Today it is the opposite. Attackers are going after the packages you already trust, the ones with millions of weekly installs and maintainers you have heard of. XZ Utils, the wave of npm maintainer account takeovers, self-replicating worms like Shai-Hulud, leaked PyPI...
See More →
Speakers
avatar for Polina Moshenets

Polina Moshenets

Security Engineer and Founder, SichGate
Polina Moshenets is a Security Engineer and Founder of SichGate, an AI model integrity testing company focused on safety and security evaluation of language models in highly regulated industries. Her background spans application security, supply chain risk in AI/ML pipelines, and... Read More →
avatar for Amro Haddadah

Amro Haddadah

Founder, CyberXYZ
Amro is the founder of CyberXYZ and a veteran of Microsoft’s DFIR team, where he spent five years investigating advanced cyber threats. He later led enterprise security as Principal Architect at Roche. Today, he’s building AI-native defenses to detect and stop zero-day attacks... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom A (Street Level)

2:15pm PST

When the Robot Writes the Bug: A Merge Gate for AI-Generated Code
Thursday November 5, 2026 2:15pm - 3:00pm PST
AI coding assistants now write a real share of what we ship, and a stubborn fraction of that code is insecure: SQL injection, hardcoded secrets, weak crypto, unsafe deserialization. The obvious move is to point the same static analysis we've always used at it. The trouble is those tools were tuned for code that people write, and on machine-generated code they throw off so much noise that...
See More →
Speakers
avatar for Maulik Bhatt

Maulik Bhatt

Senior Software Engineer, Amazon
Senior SDE at AWS, where I specialize in building scalable cloud services and ML orchestration systems. Passionate about designing enterprise-scale production AI systems and distributed architectures.

linkedin.com/in/maulik-bhatt/... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom B (Street Level)

2:15pm PST

Prompt Injection Through the Image Channel of Multimodal LLMs: An Ignored Attack Surface
Thursday November 5, 2026 2:15pm - 3:00pm PST
Almost every team shipping an LLM feature guards the text. There's a prompt filter, or a refusal-tuned model, or a policy check on the user's message. Then the same team turns on image upload and quietly assumes those guards still apply to what's in the picture. They don't.When a multimodal model reads an image, the text inside that image ends up in the same embedding space as your prompt, but it...
See More →
Speakers
avatar for Pavan Reddy

Pavan Reddy

AI Researcher and Engineer, Automata LLC
Pavan Reddy is principal developer at Automata LLC, leading FIPS 140-3, FedRAMP ATO, and AI security initiatives. He is an independent AI security researcher and educator focused on making secure AI accessible at scale. He founded QBTrain, a free platform for hands-on AI and AI security... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom C (Street Level)

2:15pm PST

The attacker does not sort by CVSS
Thursday November 5, 2026 2:15pm - 3:00pm PST
Your backlog has a sorting problem.The CVSS 9.1 chain gets the oxygen. The ugly old login flow gets a shrug. The weird admin route nobody owns gets pushed to next quarter. Then the attacker shows up and picks the boring path, because boring is cheap, quiet, reusable, and good enough.That's the gap this talk is about. CVSS tells you how bad exploitation can be. EPSS and KEV tell you what is being...
See More →
Speakers
avatar for Hugo Guillaume

Hugo Guillaume

Security Engineer, Konvu
Hugo Guillaume is a security researcher. He spent close to three years on offensive and defensive security research in a government national-defense setting, doing vulnerability research and reverse engineering and building automated bug-discovery systems. He also teaches cybersecurity... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Bayview B (Bay Level)

2:15pm PST

Download, Merge, Compromised: A Live Backdoored Coding Model From a Public Hub
Thursday November 5, 2026 2:15pm - 3:00pm PST
Developers now pull fine-tuned code models and LoRA adapters off public hubs the same way they npm install a dependency: search, download, merge, ship. Almost nobody reads the weights. This talk turns that habit into a live compromise. On stage, I take a popular open coding model, load a community adapter advertised as "better at secure code," and run it through ordinary prompts, clean, helpful,...
See More →
Speakers
avatar for Vishal Khobare

Vishal Khobare

Senior Software Enginee, eClinicalWorks
Senior Software Engineer at eClinicalWorks with 15+ years of experience building large-scale healthcare software. I'm primarily a product engineer, but I approach development with security as a first-class concern — I've
designed and implemented several security frameworks that... Read More →
avatar for Sandeep Kamble

Sandeep Kamble

Hacker Turned Founder and CTO, SecureLayer7
Sandeep Kamble is a hacker turned founder who bootstrapped SecureLayer7 into a global offensive security firm trusted by Fortune 500s, fintechs, and high-growth SaaS companies.
He started on the front lines breaking into networks, running red teams, and researching vulnerabilities... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Seacliff AB (Bay Level)

2:15pm PST

Puppy Lounge (Sponsored by Depthfirst)
Thursday November 5, 2026 2:15pm - 4:15pm PST
Relax, forget your worries, and pet puppies!  These puppies are fully adoptable too!!
Thursday November 5, 2026 2:15pm - 4:15pm PST
Expo Hall, Pacific Concourse

3:00pm PST

PM Break
Thursday November 5, 2026 3:00pm - 3:30pm PST

Thursday November 5, 2026 3:00pm - 3:30pm PST
Expo Hall, Pacific Concourse

3:15pm PST

OWASP Leaders Meeting
Thursday November 5, 2026 3:15pm - 4:15pm PST

Thursday November 5, 2026 3:15pm - 4:15pm PST
Room: Regency (Street Level)

3:30pm PST

Model Context Points of Failure: MCP Security Meets Scale
Thursday November 5, 2026 3:30pm - 4:15pm PST
MCP servers are an integral part of our AI agents, coding assistants and LLMs. But how secure are they? Can we trust publicly deployed MCP servers? What about the MCP infrastructure itself?This talk on MCP security will walk through a full from top to bottom MCP analysis, starting from the MCP source code, MCP protocol exploits, prompt injection, vulnerable MCP servers, vulnerabilities in public...
See More →
Speakers
avatar for Moshe Siman Tov Bustan

Moshe Siman Tov Bustan

Security Research Team Leader, OX Security
Moshe is a Security Research Team Leader at OX Security, a company specializing in software supply chain security, and has worked in the security industry for 13 years. His work spans cloud security research, container security, memory forensics, and an in-depth understanding of programming... Read More →
Thursday November 5, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom A (Street Level)

3:30pm PST

Pattern, Graph, Prompt: What Happens When You Layer Three Analysis Paradigms on the Same Codebase
Thursday November 5, 2026 3:30pm - 4:15pm PST
We ran three fundamentally different security analysis approaches against the same production monorepo at a large tech company: a pattern-based static analysis tool, a code property graph analyzer, and LLM-powered code review. Together they surfaced over 150 confirmed or validated security findings.Each approach has real strengths and real limitations. Pattern-based static analysis is fast and...
See More →
Speakers
avatar for Mudita Khurana

Mudita Khurana

Staff Security Engineer, Airbnb
Mudita Khurana is a Tech Lead at Airbnb, where she builds scalable security tooling and automation across the software development lifecycle. Previously at Meta, she drove key initiatives in product security, including bug bounty strategy, privacy-focused reviews, and automated vulnerability... Read More →
Thursday November 5, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom B (Street Level)

3:30pm PST

Assume Code Execution: Securing Multi-Tenant Code-Ingestion Platforms
Thursday November 5, 2026 3:30pm - 4:15pm PST
In December 2025 someone tried to break into a multi-tenant scanning platform. The payloads were the interesting part: a symlink pointing at /proc/self/environ, a beacon built to phone home, a dependency wired to a server the attacker controlled. They were templated, clearly meant to be fired at a dozen vendors with small tweaks. And they raised a question I don't think most teams ever ask about...
See More →
Speakers
avatar for Raphael Karger

Raphael Karger

Co-founder and CTO, ZeroPath
Raphael Karger is Co-founder and CTO of ZeroPath, an AI-native application security company and RSAC 2026 Innovation Sandbox finalist. He leads the core product and security research, which has disclosed vulnerabilities in curl, ffmpeg, sudo, and the Linux kernel. Previously, he was... Read More →
Thursday November 5, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom C (Street Level)

3:30pm PST

No value until it’s fixed: turning security reviews into a remediation loop
Thursday November 5, 2026 3:30pm - 4:15pm PST
A CISO once told me “your security review doesn’t deliver value until the findings are fixed.” That changed how I think about security reviews. They shouldn’t end at identifying issues and handing developers a list of things to consider. They should continue into a security improvements loop that actually drives the fixes. For a finding to be actionable, it needs implementation guidance...
See More →
Speakers
avatar for Emil Kvarnhammar

Emil Kvarnhammar

Co-Founder and CEO, Oplane
Emil Kvarnhammar has spent 27 years in software, starting as a developer before moving into cybersecurity consulting and, later, security architecture for a leading video-surveillance manufacturer. Across multiple AppSec programs he has worked hands-on with SAST, SCA, security testing... Read More →
Thursday November 5, 2026 3:30pm - 4:15pm PST
Room: Bayview B (Bay Level)

3:30pm PST

Same Bug, Bigger Blast Radius: Breaking AI Control Planes with Classic AppSec
Thursday November 5, 2026 3:30pm - 4:15pm PST
While everyone is talking about prompt injection, attackers are compromising the AI control plane.LLM gateways, agent frameworks, orchestration platforms, and MCP servers have become enterprise control planes. They hold model provider credentials, cloud secrets, organizational boundaries, routing policies, agent memory, tool permissions, and integrations with systems such as GitHub, Slack, and...
See More →
Speakers
avatar for Aditi Bhatnagar

Aditi Bhatnagar

Founder, Offgrid Security
Aditi Bhatnagar is the founder of Offgrid Security, where she leads research on securing AI infrastructure, agent frameworks, and AI control planes. Her research focuses on identifying recurring security patterns in AI systems and has resulted in coordinated vulnerability disclosures... Read More →
Thursday November 5, 2026 3:30pm - 4:15pm PST
Room: Seacliff AB (Bay Level)

4:30pm PST

OWASP Jeopardy & Networking Reception in Expo Hall
Thursday November 5, 2026 4:30pm - 6:30pm PST

Thursday November 5, 2026 4:30pm - 6:30pm PST
Expo Hall, Pacific Concourse
 
Friday, November 6
 

8:15am PST

Coffee/Tea
Friday November 6, 2026 8:15am - 9:00am PST

Friday November 6, 2026 8:15am - 9:00am PST
Expo Hall, Pacific Concourse

8:15am PST

Registration
Friday November 6, 2026 8:15am - 1:15pm PST

Friday November 6, 2026 8:15am - 1:15pm PST
Pacific Concourse

8:15am PST

Expo Hall
Friday November 6, 2026 8:15am - 3:30pm PST

Friday November 6, 2026 8:15am - 3:30pm PST
Expo Hall, Pacific Concourse

8:15am PST

Start Up Sponsors
Friday November 6, 2026 8:15am - 4:30pm PST

Friday November 6, 2026 8:15am - 4:30pm PST
Foyer

8:30am PST

Conference T-Shirt Pick up and OWASP Member Swag
Friday November 6, 2026 8:30am - 3:00pm PST
Pick up your super fun conference t-shirt and member swag!

Friday November 6, 2026 8:30am - 3:00pm PST
Room: Waterfront Foyer (Street Level)

8:45am PST

OWASP Book and Merch Store
Friday November 6, 2026 8:45am - 4:30pm PST
Calling all OWASP Merch and AppSec Book lovers!  Come visit Jonathan for your large selection of all things AppSec book relatated and don't forget to snag some OWASP merch too!
Friday November 6, 2026 8:45am - 4:30pm PST
Room: Grand Ballroom Foyer (Street Level)

9:00am PST

Opening Remarks and Debate: Vulnerability auto-remediation breaks "you build it, you own it"
Friday November 6, 2026 9:00am - 10:00am PST
"You build it, you own it" pushed accountability for security into the hands of the teams who write the code. Auto-remediation tools now promise to close that loop faster than any human team can: scanning, patching, opening PRs, sometimes merging without a developer ever seeing the diff. The question this debate puts on the table is whether that promise quietly guts the principle it claims to...
See More →
Speakers
avatar for Jeff Williams

Jeff Williams

Founder & CTO, Contrast Security
Jeff Williams is the Founder and CTO of Contrast Security, where he is pioneering runtime application security and Application Detection & Response (ADR). For more than 25 years, Jeff has helped shape the field of application security—as a founder and former Global Chair of OWASP... Read More →
avatar for Dr. Katie Paxton-Fear

Dr. Katie Paxton-Fear

Lecturer and Educational YouTuber, Manchester Metropolitan University
Dr Katie Paxton-Fear is a lecturer of cyber security at Manchester Metropolitan University, she's a hacker and YouTuber, she's made 50+ videos on a range of topics, explaining vulnerabilities, tools etc, and made a splash as an API hackerSpeaker Agreement
    @InsiderPhD
 lin... Read More →
avatar for Petra Vukmirovic

Petra Vukmirovic

Head of Information Security and Fractional Head of Product, Numan and Devarmor
Petra is a technology enthusiast, leader and public speaker. A former emergency medicine doctor and competitive volleyball athlete, she thrives in challenging environments and loves creating order from chaos. Initially pursuing a medical career, Petra's passion for technology led... Read More →
Friday November 6, 2026 9:00am - 10:00am PST
Room: Grand Ballroom A (Street Level)

10:00am PST

AM Break
Friday November 6, 2026 10:00am - 10:30am PST

Friday November 6, 2026 10:00am - 10:30am PST
Expo Hall, Pacific Concourse

10:00am PST

Capture The Flag with ArmorCode
Friday November 6, 2026 10:00am - 3:00pm PST
Team ArmorCode invites you to a hands-on CTF where security leaders and engineers can put their exposure management skills to the test. Drop in anytime during the competition window, tackle the challenges at your own pace, and climb the leaderboard for a chance to win epic prizes. Refreshments will be available in the room throughout the event.

walk-in 30 mins CTF (anytime between 10am - 3pm)
Friday November 6, 2026 10:00am - 3:00pm PST
Room: Regency (Street Level)

10:15am PST

Meet the Mentor
Friday November 6, 2026 10:15am - 12:15pm PST
One more Global AppSec event.You’re taking training, you’re running between sessions, you’re connecting with people over coffee or when talking to a vendor.What if you could use the event to also meet a potential mentor, or mentee?What if you could connect face to face with someone who may help take your career to the next level, or that you can help and make a difference with?We are...
See More →
Speakers
avatar for Izar Tarandach

Izar Tarandach

Sr. Principal Architect, SiriusXM
Long-time security practitioner, Sr. Principal Security Architect at SiriusXM, previouslyDatadog,  at Squarespace, Bridgewater Associates to DellEMC via RSA, Autodesk, startup founder, investor and advisor. Founding member of the IEEE Center for Secure Design, holds a masters degree... Read More →
Friday November 6, 2026 10:15am - 12:15pm PST
Room: Bayview A (Bay Level)

10:15am PST

PODS (Hands-on Activities)
Friday November 6, 2026 10:15am - 4:30pm PST
Hands-on activities - more information to follow
Friday November 6, 2026 10:15am - 4:30pm PST
Room: Marina (Bay Level)

10:30am PST

Poisoning the Pipeline: Runner Cache Manipulation and OIDC Token Forgery
Friday November 6, 2026 10:30am - 11:15am PST
The modern application security boundary has shifted from the network edge directly into the software delivery pipeline. As organizations embrace cryptographic provenance and OpenID Connect (OIDC) identity federation to eliminate static cloud secrets, attackers have adapted. By exploiting weak isolation boundaries in shared CI/CD runner caches, threat actors can now extract OIDC tokens from...
See More →
Speakers
avatar for Sneha Rangari

Sneha Rangari

Security Architect, Visa
I am a Cybersecurity Professional with over 7 years of experience in Security Engineering, Security Architecture, Gen AI/ML in security, Third party Vendor applications, Cloud applications and Technology Risk Management. I am CISSP and GMLE certified and currently working with Vi... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Grand Ballroom A (Street Level)

10:30am PST

Losing Context: Breaking & Binding MCP Sessions
Friday November 6, 2026 10:30am - 11:15am PST
Session Access Control – The Missing Validation Layer The Model Context Protocol (MCP) specification explicitly distinguishes sessions from authentication but provides minimal prescriptive guidance on authorization enforcement. This talk explores the theoretical security implications of this design, where session IDs function similarly to bearer tokens but often lack the granular security...
See More →
Speakers
avatar for Srikanth Ramu

Srikanth Ramu

Principal Security Engineer
I am an Application Security professional with extensive experience in product security, built on a solid foundation in development and QA. During the COVID-19 pandemic, I developed an interest in hunting bugs in open-source libraries specifically targeting Java Deserialization vulnerabilities... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Grand Ballroom B (Street Level)

10:30am PST

CRA will be Cloud-Scale Engineering Change
Friday November 6, 2026 10:30am - 11:15am PST
 The CRA is coming, and those who want to sell products in Europe will have to change their engineering processes and documentation in dramatic ways. This talk will introduce the CRA, walk through the requirements, the deadlines and the latest guidance documents from the EU.
Speakers
Friday November 6, 2026 10:30am - 11:15am PST
Room: Grand Ballroom C (Street Level)

10:30am PST

From IC to Leader: A Field Guide to Building High-Performing Security Teams
Friday November 6, 2026 10:30am - 11:15am PST
Most security leaders are exceptional technologists, but building and managing a high-performing security team requires an entirely different skill set - one that is rarely taught and almost never documented. This talk closes that gap.Drawing on 20+ years spanning Big 4 consulting, multiple security org builds from scratch, and security leadership roles across fintech, banking, and SaaS, this...
See More →
Speakers
avatar for Anshu Gupta

Anshu Gupta

Founder, Fixin Security
Anshu Gupta is a seasoned global cybersecurity executive with Fortune 500 advisory experience at EY and KPMG, working with companies including Microsoft, Salesforce, Cisco, and Adobe. He has built and led security programs at high-growth startups and fintechs, including Coupa, HelloSign... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Bayview B (Bay Level)

10:30am PST

When Finding Bugs Is the Easy Part: Lessons from an Agentic Vulnerability Harness
Friday November 6, 2026 10:30am - 11:15am PST
The finding that shifted our thinking on chain analysis was a session-handling weakness rated medium-severity in isolation. Once we traced the chain — an API leaking session identifiers without an access-control check, feeding a deterministic password derivation function — it was a full account compromise. Same code. Two severity tiers apart. Chain context doesn’t refine a finding; it...
See More →
Speakers
avatar for Venkata Suresh Sanga

Venkata Suresh Sanga

Sr Cybersecurity Engineer, Visa
Venkata Suresh, Sanga is a Sr Cybersecurity Engineer at Visa, where he runs the SAST, SCA, and DAST detection portfolio. His current focus is an agentic harness that cuts the noise those tools produce and is measured by one number: Mean Time to Adapt.

  linkedin.com/in/venkatasu... Read More →
avatar for Milind Daftari

Milind Daftari

Cybersecurity Engineer, Visa
Milind Daftari is a Cybersecurity Engineer at Visa with a Masters in Cybersecurity from New York University who thrives on turning security from a blocker into an enabler. He’s built and owned security from the ground up—shaping secure architectures, automating vulnerability scans... Read More →
avatar for Yuliana Martirosyan

Yuliana Martirosyan

Visa
Do the good by doing right
  
avatar for Daniel Fernandez Coviella

Daniel Fernandez Coviella

Senior Cybersecurity Engineer, Visa
Daniel Fernandez is a Senior Application Security Engineer at Visa, where he focuses on application security, AI security, and secure software engineering at enterprise scale. His work includes integrating AI into the secure development lifecycle, building developer security tooling... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Seacliff AB (Bay Level)

11:30am PST

Finding Pwn Requests in OSS: Auditing CI/CD Pipelines for Supply-Chain Vulnerabilities at Scale
Friday November 6, 2026 11:30am - 12:15pm PST
CI/CD pipelines are one of the highest-leverage attack surfaces in the application supply chain. A single misconfigured GitHub Actions workflow can hand repository secrets and write tokens to any external contributor who opens a pull request.This talk presents a methodology for finding these weaknesses at scale across open-source organizations. It covers four vulnerability classes: unpinned...
See More →
Speakers
avatar for Arpit Jain

Arpit Jain

Security Researcher, Independent

Friday November 6, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom A (Street Level)

11:30am PST

The Hidden Effort Curve of Remediation: 15,000 Fixes, 500 Projects, 9 Languages
Friday November 6, 2026 11:30am - 12:15pm PST
Every week brings another headline about a new way to find vulnerabilities in open-source and other code. The much-talked-about “Vulnpocalypse” is coming. But the bottleneck was never finding vulnerabilities, it is fixing them. We wanted to know how much effort this will take.Every security team triages its backlog the same way: sort by CVSS, fix the criticals first. That ranking quietly...
See More →
Speakers
avatar for Michael Cartsonis

Michael Cartsonis

Co-Founder, AppSecAI

Michael Cartsonis is a co-founder of AppSecAI . OWASP OASIS project and co-author of Two Cycles, One Codebase: A New Operating Model for Application Security.

At AppSecAI, Michael leads product strategy for the industry's first AI-powered Fix Automation system that generates valid... Read More →
avatar for Bruce Fram

Bruce Fram

CEO, AppSecAI

Bruce Fram is the CEO of AppSecAI, his and was a six-time venture-backed CEO before including being the CEO of Contrast Security. He started as a hands-on coder, spent two decades running companies instead of writing code, and credits GenAI with handing the ability to answer complex... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom B (Street Level)

11:30am PST

Modelling for Agentic Failure; when attack trees meet safety engineering
Friday November 6, 2026 11:30am - 12:15pm PST
Security and engineering teams are leaner in 2026, while the agents they're securing keep scaling. We're handing agents more tasks and more reach, which means when they fail, they fail exponentially. Threat modelling tells you what could go wrong, the next step is to decide which few controls or tests actually stop the disaster you want to prevent.This talk brings threat models together with...
See More →
Speakers
avatar for Petra Vukmirovic

Petra Vukmirovic

Head of Information Security and Fractional Head of Product, Numan and Devarmor
Petra is a technology enthusiast, leader and public speaker. A former emergency medicine doctor and competitive volleyball athlete, she thrives in challenging environments and loves creating order from chaos. Initially pursuing a medical career, Petra's passion for technology led... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom C (Street Level)

11:30am PST

Shadow AI is the new Shadow IT
Friday November 6, 2026 11:30am - 12:15pm PST
Decades ago we identified Shadow IT as a major cybersecurity risk, and we realized that we can't secure what we don't see. As history likes to repeat itself, we are now back in exactly the same place with AI. And we are in a race against time, as currently AI adoption in most organizations is moving faster than their ability to govern it. This talk aims to shift the paradigm from AI as primarily a...
See More →
Speakers
avatar for Sebastian Avarvarei

Sebastian Avarvarei

Consulting CISO & Leadership Development Coach
With over 20 years of experience in cybersecurity at both strategic and operational levels, and a proven track record of building high-performing security teams, Sebastian takes a multi-faceted view on today's security challenges, successfully blending technical acumen with business... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Bayview B (Bay Level)

11:30am PST

Context Confusion Is the New Broken Access Control
Friday November 6, 2026 11:30am - 12:15pm PST
Broken access control has always been one of the most damaging application security risks. In traditional applications, the failure is usually clear: a user can access an object, record, file, or action they should not be able to access. AI applications make this problem harder because the security boundary is no longer just the object. It is also the conversation, retrieved context, generated...
See More →
Speakers
avatar for Anusha Vajha

Anusha Vajha

Security Engineer and Product Manager
Anusha Vajha is a cybersecurity practitioner focused on AI governance, product security, and enterprise AI risk. She has worked across security operations, GRC, detection engineering, and product security in healthcare, financial services, and startup environments.
Her work sits a... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Seacliff AB (Bay Level)

12:15pm PST

Lunch
Friday November 6, 2026 12:15pm - 1:15pm PST

Friday November 6, 2026 12:15pm - 1:15pm PST
Expo Hall, Pacific Concourse

1:15pm PST

Panel Discussion
Friday November 6, 2026 1:15pm - 2:00pm PST

Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom C (Street Level)

1:15pm PST

LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
Friday November 6, 2026 1:15pm - 2:00pm PST
Models are starting to make security decisions that used to be written as rules. Instead of matching an input against a policy, a model reads the request and decides what to do with it. OpenSearch is one of the first to put one in production as the only thing standing between an anonymous pull request and CI pipeline secrets.When I reported a vulnerability, the team told me their model would catch...
See More →
Speakers
avatar for Aviv Donenfeld

Aviv Donenfeld

Security Researcher, Check Point Software Technologies
Aviv Donenfeld is a Security Researcher at Check Point Software Technologies. Before security research, he built distributed networking systems as a software engineer. His recent research centers on the attack surfaces of AI coding assistants, including critical vulnerabilities in... Read More →
Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom A (Street Level)

1:15pm PST

So you think AI writes secure code?
Friday November 6, 2026 1:15pm - 2:00pm PST
Software development is becoming AI-assisted at every stage — design, coding, testing, bug fixing — and AI agents are increasingly doing it all. But do AI coding assistants actually write secure code by default? Most of the conversation around AI and security focuses on AI finding vulnerabilities. Far less attention goes to how state-of-the-art coding agents behave when they're the ones...
See More →
Speakers
SD

Shruti Datta Gupta

Product Security Engineer, Adobe
Shruti Datta Gupta is a Product Security Engineer at Adobe where she works in the Security AI & Data Engineering team. Her current role involves building AI-powered tools to automate security processes and reduce engineering toil. She is passionate about applying AI to solve cool... Read More →
avatar for Joseph Seasly

Joseph Seasly

Security AI & Data Engineer, Adobe

Joseph does Security AI and Data Engineering at Adobe. In his former life, he spent 13 years in the U.S. Intelligence Community working in a variety of agencies, technical roles, and missions.
    linkedin.com/in/josephs1000
... Read More →
Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom B (Street Level)

1:15pm PST

Why Developers Can and We Can't: Making Security Findings That Agents (and Humans) Can Act On
Friday November 6, 2026 1:15pm - 2:00pm PST
Coding agents went from novelty to daily driver in less than three years. Developers are now using AI to generate, test, and ship code as part of their normal workflow. But the way security communicates guidance has barely changed: findings buried in long documents, review comments that arrive after key decisions are already made, and requirements that are too vague for a developer to act on —...
See More →
Speakers
HM

Hai Maler

Head of Research, Clover Security
Hai Maler is Head of Research at Clover Security, where he drives research that brings advanced AI capabilities into practical product security workflows. He brings over 10 years of industry experience, from breaking systems and studying how they fail to building tools that help defenders... Read More →
Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Bayview B (Bay Level)

1:15pm PST

XSS is the new RCE: How we broke Tauri's security model
Friday November 6, 2026 1:15pm - 2:00pm PST
Tauri is a fast-growing and rapidly adopted framework for building desktop applications, with 100k+ stars on GitHub, used by thousands of popular apps. When the v1 version of the framework was found to be insecure, v2 emerged as the secure solution. Our talk will provide an overview of Tauri’s security blind spots and demonstrate them through a full RCE exploitation using vulnerability chaining...
See More →
Speakers
avatar for Yuval Moravchick

Yuval Moravchick

Vulnerability Research Team Leader, JFrog

Yuval is the vulnerability research team leader at JFrog. With over 10 years of technical experience, he has built and led security teams at various organizations, specializing in penetration testing, security research, and the development of offensive tools. Before JFrog, he held... Read More →
Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Seacliff AB (Bay Level)
  Testing

1:15pm PST

CfP/CfTs for the Newcomer: How To Write A Good Submission
Friday November 6, 2026 1:15pm - 2:30pm PST
Ready to showcase your expertise? Don’t miss the chance to submit for a Call for Trainers or Call for Papers! Join the dynamic Izar Tarandach and Avi Douglen as they take you through the submission process and reveal insider tips on what the review team is looking for when selecting papers. This is your opportunity to shine and make a lasting impact—let’s make it happen!
Speakers
avatar for Izar Tarandach

Izar Tarandach

Sr. Principal Architect, SiriusXM
Long-time security practitioner, Sr. Principal Security Architect at SiriusXM, previouslyDatadog,  at Squarespace, Bridgewater Associates to DellEMC via RSA, Autodesk, startup founder, investor and advisor. Founding member of the IEEE Center for Secure Design, holds a masters degree... Read More →
Friday November 6, 2026 1:15pm - 2:30pm PST
Room: Bayview A (Bay Level)

2:15pm PST

Open Source Sleeper Agents: Compromising Agents via Chat Templates
Friday November 6, 2026 2:15pm - 3:00pm PST
Most open-weight models are based on the GGUF standard distributed on a public hubs like HuggingFace ship with a chat template: a small Jinja2 program that runs on every inference call and formats the prompt before the model processes it. It is executable code, it sits between the user's input and the model, and in practice almost no one inspects it. We show that an attacker can plant a...
See More →
Speakers
avatar for Ariel Fogel

Ariel Fogel

AI Security Researcher, Pillar Security
Ariel Fogel is a founding engineer & researcher at Pillar Security, where he hardens AI applications against real-world attacks and compliance risks. Over the past decade, he has built production systems in Ruby, TypeScript, Python, and SQL, shipping everything from full-stack web... Read More →
avatar for Omer Hofman

Omer Hofman

Principal Researcher, Fujitsu Research of Europe
 Omer Hofman is a Principal AI Security Researcher focused on evaluating and securing large language model systems in real-world deployments. His work centers on LLM red teaming, vulnerability scanning, guardrail design, and policy compliance in agentic AI systems. He leads research... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom A (Street Level)

2:15pm PST

When Nobody Wrote the Code: Engineering Lessons from Building AI-Native Application Security
Friday November 6, 2026 2:15pm - 3:00pm PST
We didn't set out to rethink Application Security.Our goal was much simpler: remove repetitive security work without reducing engineering confidence.Like many security teams, we began introducing AI into parts of our AppSec workflow—reviewing pull requests, proposing remediation, assisting with threat modeling, validating findings, and helping developers move faster without sacrificing...
See More →
Speakers
avatar for Manoj Kumar Yuvanesh

Manoj Kumar Yuvanesh

Senior Manager, Trust Data Platform, Autodesk Inc

Manoj Kumar Yuvanesh is a Senior Engineering Manager at Autodesk, where he leads the Trust Data Platform within the Trust Organization.

His work focuses on building large-scale data systems and security automation capabilities that help organizations understand and improve their security posture. With deep experience across security tooling, architecture, and cloud platforms, he drives initiatives that integrate security... Read More →
avatar for Uday Bhaskar Seelamantula

Uday Bhaskar Seelamantula

Principal Application Security Engineer, Autodesk

Uday is a principal security engineer at Autodesk, where he focuses on securing applications at the intersection of traditional software and emerging AI features. His work spans offensive research, fuzzing, threat modeling, building guardrails and integrating security into the SDLC... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom B (Street Level)

2:15pm PST

Post Quantum Crypto (PQC) - Field-Tested Strategies to Defeat Harvest Now, Decrypt Later
Friday November 6, 2026 2:15pm - 3:00pm PST
Q-Day, the moment a cryptographically relevant quantum computer (CRQC) breaks RSA, ECC, and Diffie-Hellman, has no confirmed date. But for any data with a long secrecy shelf life, it has effectively already happened: adversaries are harvesting encrypted traffic today to decrypt it later (HNDL). Meanwhile, governments have stopped waiting. The recent US Government Executive Order 14409 (June 2026)...
See More →
Speakers
avatar for Anshu Gupta

Anshu Gupta

Founder, Fixin Security
Anshu Gupta is a seasoned global cybersecurity executive with Fortune 500 advisory experience at EY and KPMG, working with companies including Microsoft, Salesforce, Cisco, and Adobe. He has built and led security programs at high-growth startups and fintechs, including Coupa, HelloSign... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom C (Street Level)

2:15pm PST

From Consuming to Contributing: How We Built the Space That Was Missing
Friday November 6, 2026 2:15pm - 3:00pm PST
Many of us naturally drift from consuming OWASP resources to contributing to them. At some point you stop just reading the Top 10 and start showing up at a chapter, submitting a pull request, or volunteering at a conference. But what often gets lost is the "together" part. The shared strategy, the mutual encouragement, a place where experienced contributors can mentor others and people new to...
See More →
Speakers
avatar for Saquib Saifee

Saquib Saifee

AI Security Engineer, IBM
Saquib Saifee is an AI Security Engineer at IBM working at the intersection of AI security, software supply chain security, and offensive security. He contributes to the OWASP GenAI Security Project on securely using and building MCP servers, participates in the Linux Foundation AI... Read More →
avatar for Caroline Lee

Caroline Lee

Secuirty Engineer, IBM
Caroline is based out of Boston, Massachusetts, and works as a Security Engineer at IBM in CISO Remediation. She holds a Masters in Computer Science with a Specialization in Cybersecurity.
Previously, she has worked on CICD, Application Security, and Cloud Security initiatives in... Read More →
avatar for Gaurang Deshpande

Gaurang Deshpande

Software Developer, Cyber Defense, IBM
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Bayview B (Bay Level)

2:15pm PST

The Hidden Risks of Service-to-Service Trust in Microservice Architectures
Friday November 6, 2026 2:15pm - 3:00pm PST
Modern applications increasingly rely on microservice architectures where APIs, backend services, and cloud workloads continuously communicate with one another. While organizations focus heavily on authenticating end users, service-to-service trust relationships are often implemented with excessive implicit trust, weak authorization boundaries, and inconsistent validation controls.This talk...
See More →
Speakers
avatar for Bhaumik Shah

Bhaumik Shah

CEO, SecurifyAI
Bhaumik Shah is a cybersecurity leader and founder of Securify, where he helps organizations secure their cloud, applications, and infrastructure through penetration testing, red team operations, and compliance programs like SOC 2 and ISO 27001. With over a decade of experience uncovering... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Seacliff AB (Bay Level)

3:00pm PST

PM Break
Friday November 6, 2026 3:00pm - 3:30pm PST

Friday November 6, 2026 3:00pm - 3:30pm PST
Expo Hall, Pacific Concourse

3:30pm PST

RepoHunter: AI-Driven Discovery of CI/CD Supply Chain Vulnerabilities at Scale
Friday November 6, 2026 3:30pm - 4:15pm PST
Recent attacks such as S1ngularity, Shai-Hulud, and the Trivy GitHub Actions compromise have shown that CI/CD pipelines are among the most attractive attack surfaces in modern software development. A single workflow misconfiguration can lead to remote code execution, credential theft, repository takeover, and software supply chain compromise.This session introduces RepoHunter, an AI-driven...
See More →
Speakers
avatar for Barak Haryati

Barak Haryati

Senior Director of Product Security, JFrog
Barak Haryati is Senior Director of Product Security at JFrog, focused on CI/CD security, AI/LLM systems, and software supply chain risk. His research explores how attacker-controlled input flows through build systems and is executed in privileged environments.

He developed RepoHunter, an AI-driven research agent that discovers, prioritizes, and models real exploitation paths across CI/CD workflows at scale. Using this approach, he identified and responsibly disclosed 30+ critical vulnerabilities across widely used open source and enterprise... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom A (Street Level)

3:30pm PST

Pre-Flight Security Review for MCP Servers Using the OWASP MCP Top 10
Friday November 6, 2026 3:30pm - 4:15pm PST
Since Anthropic released MCP as an open standard, enterprises have started adopting it as a common way to connect AI agents with tools, data sources, and business workflows. Many teams are now building MCP catalogs for internal developers, platform teams and external partners.However, the security posture of these MCP servers is often not reviewed before they are added to a catalog or connected to...
See More →
Speakers
avatar for Vinothini Raju

Vinothini Raju

Founder & CEO, gopaddle.io
Vinothini Raju, is the Founder & CEO at gopaddle.io. She has been awarded the B2B Woman Tech Entrepreneur of the Year, 2023 by Women In Cloud & Insight Enterprises. Under her leadership, gopaddle focuses on building a next-generation platform for cloud native applications​. Her... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom B (Street Level)

3:30pm PST

From Design Docs to Mitigations: Scaling Pre-Launch Security Review with Historical Decisions
Friday November 6, 2026 3:30pm - 4:15pm PST
Security review is getting squeezed from both sides. Product teams ship faster, GenAI has accelerated how quickly new features get built, and review teams are still expected to read each design doc from scratch and decide what can ship. That breaks down long before the roadmap slows down.This talk shows an AI-assisted pre-launch review pattern built for that problem. The pipeline does not stop at...
See More →
Speakers
avatar for Liat Ben Porat

Liat Ben Porat

Director, AI Science, Intuit
Liat Ben Porat leads the AI science organization within Intuit's global trust, fraud, and security group, where she drives the strategy, development, and adoption of AI solutions across security, fraud, compliance, and workforce teams. She also serves as her organization's lead for... Read More →
GS

Guy Shtar

AI Security & Safety Architect, Intuit

Guy Shtar is an AI Security & Safety Architect at Intuit, working on the intersection of GenAI, security, and Trust & Safety. His work focuses on turning subjective review workflows into measurable technical systems, including AI-assisted risk discovery, adversarial testing, and security... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom C (Street Level)

3:30pm PST

Breaking the Headcount Scaling Model: How GitLab's Product Security Teams Achieved Non-Linear Securi
Friday November 6, 2026 3:30pm - 4:15pm PST
Complete title that is cut by "Session Title" size limit: Breaking the Headcount Scaling Model: How GitLab's Product Security Teams Achieved Non-Linear Security Gains with AIEngineering ships faster every quarter with AI assisted development, Security headcount grows slowly and the review backlog keeps growing at a rate you wish you didn’t know! This talk traces the struggles of building an...
See More →
Speakers
avatar for Vitor Meireles

Vitor Meireles

Senior Security Engineering Manager AppSec, GitLab

Vitor Meireles is a security professional with over 15 years of experience in the field. Currently serving as a Senior Security Engineering Manager at GitLab, he helps engineering teams build applications that are secure by design. Vitor has past experiences in the consulting, financial... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Bayview B (Bay Level)

3:30pm PST

Finding the Infrastructure Trust Layer: AI-Assisted Discovery of Cross-Product SSRF Classes
Friday November 6, 2026 3:30pm - 4:15pm PST
Standard SSRF mitigations are written around a specific threat model: an attacker reaching RFC 1918 space or link-local addresses through an application. Block 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, done. This model works for application-layer SSRF.IaaS platforms have a second trust layer this model does not address. When a platform builds internal services - request routing,...
See More →
Speakers
avatar for Ofri Ouzan

Ofri Ouzan

Security Researcher, JFrog Security
Ofri Ouzan is a security researcher at JFrog Security. With over 6 years of experience in the cybersecurity field, she specializes in conducting security research focusing on vulnerabilities and exploitation. Ofri excels at exploring new technologies and developing solutions to address... Read More →
avatar for Stav David

Stav David

Founder building automated offensive security tooling

Stav David is a security researcher and founder who builds automated offensive security infrastructure. He started by building multi-cloud DDoS attack simulation tooling - real bot fleets testing whether mitigation vendors actually block what they claim to block. The recon pipeline... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Seacliff AB (Bay Level)

4:30pm PST

Closing Ceremony and Raffle
Friday November 6, 2026 4:30pm - 5:30pm PST
Come wrap up the conference with us, hear special annoucements, and win prizes!
Friday November 6, 2026 4:30pm - 5:30pm PST
Room: Grand Ballroom A (Street Level)

6:00pm PST

ThreatModCon Night Networking Reception
Friday November 6, 2026 6:00pm - 8:00pm PST
Connect Before the Conference BeginsThe best conversations often happen before the first session! Join the ThreatModCon community for an evening of networking, drinks, and conversation with fellow threat modeling and security professionals. Whether you're a longtime member of the community or attending ThreatModCon for the first time on Saturday, this is a great opportunity to make...
See More →
Friday November 6, 2026 6:00pm - 8:00pm PST
Hyatt Regency, Lower Atrium
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.