Loading…
Audience: Intermediate clear filter
Monday, November 2
 

9:00am PST

3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
Monday November 2, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level:Intermediate
Trainer: Abraham Aranguren

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Modern Android and iOS apps rarely operate alone. They sit at the center of rich ecosystems: phones talking to toys, drones, wearables, vehicles, trackers, “smart” homes—and, in multiple countries, even government‑mandated and police apps. In these environments, attackers increasingly target the mobile app as the remote control for the device, often without ever touching the physical hardware.

This 3‑day, 100% hands‑on course is a deep dive into the OWASP Mobile Security Testing Guide (MSTG) and relevant items of the OWASP Mobile Application Security Verification Standard (MASVS). The 2026 Edition fully covers and goes beyond the OWASP Mobile Top Ten, using real‑world Android, iOS, and IoT applications as targets.

7ASecurity is an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter that focuses on researcher‑led, heavily manual penetration tests and secure code audits. Lessons learned from these engagements—performed for organizations such as the Linux Foundation, Mozilla, the Tor Project, and others—feed directly into the course material, labs, and case studies.

Across three intensive days you will:
Break down Android and iOS apps with static and dynamic analysis.
Discover IoT vulnerabilities using only the apps and APIs, no devices required.
Master practical instrumentation using Frida, Objection, Xposed, and related tooling to bypass protections and deeply inspect runtime behavior.

Ideal for penetration testers, red teamers, mobile developers, and anyone serious about mobile/IoT security, this course is all action, no fluff. It is packed with exercises, extra‑mile challenges, and CTFs, and includes continued education via lifetime access to a training portal with step‑by‑step video recordings, updated labs, and unlimited email support, including all future updates for free.

Teaser Video: https://www.youtube.com/watch?v=Re5oqfVkgd4
Get a free taste of this training, including access to video recordings, slides, and vulnerable apps to play with:
https://7asecurity.com/free-workshop-mobile-practical
https://7asecurity.com/free-workshop-mobile-deeplinks-xss
Speakers
avatar for Abraham Aranguren

Abraham Aranguren

CEO, Security Trainer, Director of Penetration Testing, 7ASecurity

Abraham Aranguren is the founder and CEO of 7ASecurity (7asecurity.com), an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter specializing in high‑quality, manual penetration tests and secure code audits. He has more than 24 years of experience... Read More →
Monday November 2, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
Monday November 2, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level:Intermediate
Trainer: Adam Shostack

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

This is our popular Threat Modeling Intensive course, where you'll learn to Threat Model, and then you'll learn how to incorporate large language models (LLMs) into every stage of the threat modeling process. Rather than replacing traditional threat modeling techniques, AI becomes a collaborative assistant that helps teams explore designs, generate ideas, evaluate risks, and improve efficiency. 

Throughout the course, you'll compare traditional approaches with AI-assisted workflows, learn where AI excels, recognize where it can fail, and develop practical techniques for using AI
to help your organization scale.

This hands-on course emphasizes experimentation, evaluation, and critical analysis so that you leave with the confidence to make AI a productive member of your threat modeling toolkit—not a replacement for your expertise. 

Speakers
Monday November 2, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
Monday November 2, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level: Intermediate
Trainer: Dawid Czagan

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Modern IT systems are increasingly complex, making full-stack expertise more essential than ever. That's why diving into full-stack pentesting is crucial—you will gain the skills needed to master modern attack vectors and implement effective defensive countermeasures.

For each attack, vulnerability and technique presented in this training, there is a lab exercise to help you develop your skills step by step. What's more, when the training is over, you can take the complete lab environment home to hack again at your own pace.

I found security bugs in many companies including Google, Yahoo, Mozilla, Twitter and in this training I'll share my experience with you.

Key Learning Objectives
After completing this training, you will have learned about:

- Hacking cloud applications
- API hacking tips & tricks
- Data exfiltration techniques
- OSINT asset discovery tools
- Tricky user impersonation
- Bypassing protection mechanisms
- CLI hacking scripts
- Interesting XSS attacks
- Server-side template injection
- Hacking with Google & GitHub search engines
- Automated SQL injection detection and exploitation
- File read & file upload attacks
- Password cracking in a smart way
- Hacking Git repos
- XML attacks
- NoSQL injection
- HTTP parameter pollution
- Web cache deception attack
- Hacking with wrappers
- Finding metadata with sensitive information
- Hijacking NTLM hashes
- Automated detection of JavaScript libraries with known vulnerabilities
- Extracting passwords
- Hacking Electron applications
- Establishing reverse shell connections
- RCE attacks
- XSS polyglot
- and more …

What Students Will Receive
Students will be handed in a VMware image with a specially prepared lab environment to play with all attacks, vulnerabilities and techniques presented in this training. When the training is over, students can take the complete lab environment home (after signing a non-disclosure agreement) to hack again at their own pace.

Special Bonus
The ticket price includes FREE access to my 6 online courses:

- Fuzzing with Burp Suite Intruder
- Exploiting Race Conditions with OWASP ZAP
- Case Studies of Award-Winning XSS Attacks: Part 1
- Case Studies of Award-Winning XSS Attacks: Part 2
- How Hackers Find SQL Injections in Minutes with Sqlmap
- Web Application Security Testing with Google Hacking

What Students Say About My Trainings
References are attached to my LinkedIn profile (https://www.linkedin.com/in/dawid-czagan-85ba3666/). They can also be found here: https://silesiasecuritylab.com/services/training/#opinions – training participants from companies such as Oracle, Adobe, ESET, ING, Red Hat, Trend Micro, Philips, government sector

What Students Should Know
To get the most of this training intermediate knowledge of web application security is needed. Students should have experience in using a proxy, such as Burp Suite Proxy or Zed Attack Proxy (ZAP), to analyze or modify the traffic.

What Students Should Bring

Students will need a laptop with 64-bit operating system, at least 8 GB RAM, 35 GB free hard drive space, administrative access, ability to turn off AV/firewall and VMware Player/Fusion installed (64-bit version). Prior to the training, make sure there are no problems with running x86_64 VMs.

Additional notes

This new 3-day training was sold out at top security conferences e.g. DEF CON (Las Vegas), Hack In Paris (Paris).

This is a 100% hands-on training: for each attack, vulnerability and technique presented in this training, there is a lab exercise to help students develop their skills step by step.
Speakers
avatar for Dawid Czagan

Dawid Czagan

Founder and CEO, Silesia Security Lab
Dawid Czagan is an internationally recognized security researcher and trainer. He is listed among top hackers at HackerOne. Dawid Czagan has found security bugs in Apple, Google, Mozilla, Microsoft and many others.

Due to the severity of many bugs, he received numerous awards for his findings. Dawid Czagan shares his security experience in his hands-on trainings. He delivered trainings at key industry conferences such as DEF CON (Las Vegas), OWASP 2025 Global AppSec EU (Barcelona), Hack In The... Read More →
Monday November 2, 2026 9:00am - 5:00pm PST
TBA
 
Tuesday, November 3
 

9:00am PST

2-Day Training: AI SecureOps: Attacking & Defending AI Applications & Agents
Tuesday November 3, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026
Level: Intermediate
Trainers: Abhinav Singh

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Can prompt injections lead to complete infrastructure takeovers? Could AI agents, MCP-connected tools, or poisoned external context be abused to compromise backend services? Can data poisoning in AI copilots impact a company’s stock? Can jailbreaks create false crisis alerts in security systems? This immersive, CTF-styled training in GenAI, LLM, agent, and MCP security dives into these pressing questions. Engage in realistic attack-and-defense scenarios focused on real-world threats, from prompt injection and remote code execution to backend compromise, tool abuse, unsafe agent orchestration, trust and authorization failures. Tackle hands-on challenges with live AI applications to understand vulnerabilities and build robust defenses. Learn how to build a comprehensive security pipeline, master AI red and blue team strategies, secure tool-connected and agentic systems, implement resilient guardrails for LLMs, and handle incident response for AI-based threats. You will also explore governance, Responsible AI, and enterprise security patterns for modern AI ecosystems.

By the end of this training, you will be able to:

- Exploit vulnerabilities in AI applications to achieve code and command execution, uncovering scenarios such as instruction injection, agent control bypass, remote code execution for infrastructure takeover, as well as chaining multiple agents for goal hijacking.
- Conduct AI red-teaming using adversary simulation, OWASP LLM Top 10, and MITRE ATLAS frameworks, while applying AI security and ethical principles in real-world scenarios.
- Execute and defend against adversarial attacks, including prompt injection, data poisoning, jailbreaks, agentic attacks, and insecure tool-connected workflows.
- Perform advanced AI red and blue teaming through multi-agent auto-prompting attacks, implementing a 3-way autonomous system consisting of attack, defend, and judge models.
- Build and deploy enterprise-grade LLM defenses, including custom guardrails for input/output protection, security benchmarking, penetration testing of LLM agents, and defensive controls for MCP-enabled integrations.
- Understand MCP fundamentals and assess how they expand the attack surface of modern AI systems.
- Establish a comprehensive LLM SecOps process to secure the supply chain from adversarial attacks and create a robust threat model for enterprise applications, including AI systems connected to external tools and data sources through MCP-like architectures.
- Implement an incident response and risk management plan for enterprises developing or using AI services.
Speakers
avatar for Abhinav Singh

Abhinav Singh

Cyber Security Research in AI,Cloud & Data., Wingback Security
Abhinav Singh is a security leader, founder of Wingback Security, and a globally recognized speaker and trainer focused on securing enterprise AI systems. He has been involved with AI fellowship and research communities including MATS, PIBBSS, CSA, AIUC, and the Foresight Institute... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: Repeatable, Scalable and Valuable Code Security Scanning
Tuesday November 3, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026
Level: Intermediate
Trainers:Avi Douglen

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Suddenly anyone and everyone in your organization can use AI assistants to write code. Meanwhile, your actual developers are putting out 100x their previous output , with “varying” levels of quality. So how are you going to secure code at this scale?

This course is designed to be a deep dive into state-of-the-art techniques for validating code security within an organization’s codebase. The course has a strong emphasis on how AI-driven analysis can drive this forward whilst also clearly highlighting where standard, deterministic techniques (albeit incorporating AI acceleration) will be more effective.

During the course, you will learn how to combine these techniques, in a scalable and repeatable way, based on our experience doing just this with real organizations and real teams and with a focus on the current state of the art in this fast-moving area.

This course goes beyond the scope of standard application security knowledge and is designed to make you a specialist in this area. Having spent several years perfecting this process, we are excited to impart the lessons we have learnt!

The course is structured as follows:

* Overview – setting out the basic details of what we will be talking about in terms of code scanning and SAST.
* Key techniques – Discuss the different techniques which can be used for this including generic “off the shelf” SAST, deterministic custom scanning rules, and LLM powered custom AI prompts
* Technique comparison - Advantages and disadvantages of each technique based on our in-depth experience with each and which technique you will want to use in different situations, to avoid wasting time trying to use a technique in an inappropriate use case.
* Organizational process – How to get these processes built into an organization’s existing software lifecycle
* Generic SAST – Using “off the shelf” rules effectively to catch “low hanging fruit” and avoid reinventing the wheel.
* Custom SAST – Introduce custom rule languages (e.g., Semgrep, CodeQL), writing rules from scratch, and scaling analysis across a codebase.
* Basic AI Code Security Scanning – Overview of AI-based scanning, platforms, principles, and initial single-shot prompts
Speakers
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: Secure Coding That Sticks: From Bad Code to Secure Design
Tuesday November 3, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026
Level: Intermediate
Trainers:Tanya Janca

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Most developers have heard security advice before. The problem is, it rarely translates into what to actually do when you're writing code.

This two-day, hands-on training focuses on building secure coding skills that work in real life. Attendees learn how to recognize insecure patterns, fix them, and replace them with practical, repeatable approaches they can apply immediately. As AI-generated code becomes the norm, the ability to read code critically, spot security issues, and fix them confidently has never mattered more. This training builds this exact skill.

Day One covers secure coding fundamentals across the areas where vulnerabilities happen most often: input and output handling, data and secrets protection, authentication and authorization, infrastructure and application safety, resilience, supply chain risks, logging, and operational practices. Each topic is taught using a Bad / Better / Best approach, with real code examples and hands-on exercises so participants can clearly see what insecure code looks like, how it fails, and how to fix it properly.

Day Two applies those skills to APIs using the OWASP API Security Top 10. Participants work through each category of vulnerability using practical examples, learning how issues like broken object-level authorization, SSRF, and unsafe API consumption actually show up in code and how to remediate them effectively.

In the final section, the training moves into secure design. Attendees are introduced to core design principles and guided through a live threat modeling exercise, where they identify assets, trust boundaries, and risks in a realistic system, then prioritize and propose mitigations.

Attendees leave with 42 actionable secure coding rules, hands-on experience with the OWASP API Security Top 10, and a practical threat modeling approach they can use immediately. The goal is not a list of things to memorize. It's a new way of thinking about code and your everyday work.
Speakers
avatar for Tanya Janca

Tanya Janca

Security Trainer and Founder, She Hacks Purple
Tanya Janca is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the CEO of She Hacks Purple Consulting, where she delivers high-impact, live, secure-coding training for engineering teams. She is also the host of DevSec... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
Tuesday November 3, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level:Intermediate
Trainer: Abraham Aranguren

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Modern Android and iOS apps rarely operate alone. They sit at the center of rich ecosystems: phones talking to toys, drones, wearables, vehicles, trackers, “smart” homes—and, in multiple countries, even government‑mandated and police apps. In these environments, attackers increasingly target the mobile app as the remote control for the device, often without ever touching the physical hardware.

This 3‑day, 100% hands‑on course is a deep dive into the OWASP Mobile Security Testing Guide (MSTG) and relevant items of the OWASP Mobile Application Security Verification Standard (MASVS). The 2026 Edition fully covers and goes beyond the OWASP Mobile Top Ten, using real‑world Android, iOS, and IoT applications as targets.

7ASecurity is an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter that focuses on researcher‑led, heavily manual penetration tests and secure code audits. Lessons learned from these engagements—performed for organizations such as the Linux Foundation, Mozilla, the Tor Project, and others—feed directly into the course material, labs, and case studies.

Across three intensive days you will:
Break down Android and iOS apps with static and dynamic analysis.
Discover IoT vulnerabilities using only the apps and APIs, no devices required.
Master practical instrumentation using Frida, Objection, Xposed, and related tooling to bypass protections and deeply inspect runtime behavior.

Ideal for penetration testers, red teamers, mobile developers, and anyone serious about mobile/IoT security, this course is all action, no fluff. It is packed with exercises, extra‑mile challenges, and CTFs, and includes continued education via lifetime access to a training portal with step‑by‑step video recordings, updated labs, and unlimited email support, including all future updates for free.

Teaser Video: https://www.youtube.com/watch?v=Re5oqfVkgd4
Get a free taste of this training, including access to video recordings, slides, and vulnerable apps to play with:
https://7asecurity.com/free-workshop-mobile-practical
https://7asecurity.com/free-workshop-mobile-deeplinks-xss
Speakers
avatar for Abraham Aranguren

Abraham Aranguren

CEO, Security Trainer, Director of Penetration Testing, 7ASecurity

Abraham Aranguren is the founder and CEO of 7ASecurity (7asecurity.com), an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter specializing in high‑quality, manual penetration tests and secure code audits. He has more than 24 years of experience... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
Tuesday November 3, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level:Intermediate
Trainer: Adam Shostack

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

This is our popular Threat Modeling Intensive course, where you'll learn to Threat Model, and then you'll learn how to incorporate large language models (LLMs) into every stage of the threat modeling process. Rather than replacing traditional threat modeling techniques, AI becomes a collaborative assistant that helps teams explore designs, generate ideas, evaluate risks, and improve efficiency. 

Throughout the course, you'll compare traditional approaches with AI-assisted workflows, learn where AI excels, recognize where it can fail, and develop practical techniques for using AI
to help your organization scale.

This hands-on course emphasizes experimentation, evaluation, and critical analysis so that you leave with the confidence to make AI a productive member of your threat modeling toolkit—not a replacement for your expertise. 

Speakers
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
Tuesday November 3, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level: Intermediate
Trainer: Dawid Czagan

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Modern IT systems are increasingly complex, making full-stack expertise more essential than ever. That's why diving into full-stack pentesting is crucial—you will gain the skills needed to master modern attack vectors and implement effective defensive countermeasures.

For each attack, vulnerability and technique presented in this training, there is a lab exercise to help you develop your skills step by step. What's more, when the training is over, you can take the complete lab environment home to hack again at your own pace.

I found security bugs in many companies including Google, Yahoo, Mozilla, Twitter and in this training I'll share my experience with you.

Key Learning Objectives
After completing this training, you will have learned about:

- Hacking cloud applications
- API hacking tips & tricks
- Data exfiltration techniques
- OSINT asset discovery tools
- Tricky user impersonation
- Bypassing protection mechanisms
- CLI hacking scripts
- Interesting XSS attacks
- Server-side template injection
- Hacking with Google & GitHub search engines
- Automated SQL injection detection and exploitation
- File read & file upload attacks
- Password cracking in a smart way
- Hacking Git repos
- XML attacks
- NoSQL injection
- HTTP parameter pollution
- Web cache deception attack
- Hacking with wrappers
- Finding metadata with sensitive information
- Hijacking NTLM hashes
- Automated detection of JavaScript libraries with known vulnerabilities
- Extracting passwords
- Hacking Electron applications
- Establishing reverse shell connections
- RCE attacks
- XSS polyglot
- and more …

What Students Will Receive
Students will be handed in a VMware image with a specially prepared lab environment to play with all attacks, vulnerabilities and techniques presented in this training. When the training is over, students can take the complete lab environment home (after signing a non-disclosure agreement) to hack again at their own pace.

Special Bonus
The ticket price includes FREE access to my 6 online courses:

- Fuzzing with Burp Suite Intruder
- Exploiting Race Conditions with OWASP ZAP
- Case Studies of Award-Winning XSS Attacks: Part 1
- Case Studies of Award-Winning XSS Attacks: Part 2
- How Hackers Find SQL Injections in Minutes with Sqlmap
- Web Application Security Testing with Google Hacking

What Students Say About My Trainings
References are attached to my LinkedIn profile (https://www.linkedin.com/in/dawid-czagan-85ba3666/). They can also be found here: https://silesiasecuritylab.com/services/training/#opinions – training participants from companies such as Oracle, Adobe, ESET, ING, Red Hat, Trend Micro, Philips, government sector, ...

What Students Should Know
To get the most of this training intermediate knowledge of web application security is needed. Students should have experience in using a proxy, such as Burp Suite Proxy or Zed Attack Proxy (ZAP), to analyze or modify the traffic.

What Students Should Bring

Students will need a laptop with 64-bit operating system, at least 8 GB RAM, 35 GB free hard drive space, administrative access, ability to turn off AV/firewall and VMware Player/Fusion installed (64-bit version). Prior to the training, make sure there are no problems with running x86_64 VMs.

Additional notes

This new 3-day training was sold out at top security conferences e.g. DEF CON (Las Vegas), Hack In Paris (Paris).

This is a 100% hands-on training: for each attack, vulnerability and technique presented in this training, there is a lab exercise to help students develop their skills step by step.
Speakers
avatar for Dawid Czagan

Dawid Czagan

Founder and CEO, Silesia Security Lab
Dawid Czagan is an internationally recognized security researcher and trainer. He is listed among top hackers at HackerOne. Dawid Czagan has found security bugs in Apple, Google, Mozilla, Microsoft and many others.

Due to the severity of many bugs, he received numerous awards for his findings. Dawid Czagan shares his security experience in his hands-on trainings. He delivered trainings at key industry conferences such as DEF CON (Las Vegas), OWASP 2025 Global AppSec EU (Barcelona), Hack In The... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA
 
Wednesday, November 4
 

9:00am PST

1-Day Training: Building Continuous SaaS Integration Security: Signals, Least Privilege, and Evidence Automation
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026
Level: Intermediate
TrainersPranav Saji

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

SaaS integrations are now a primary path for privilege creep, token sprawl, and silent exposure across an organization. In this hands-on training, participants learn how to assess and continuously monitor SaaS integrations using practical security signals such as over-scoped OAuth grants, non-expiring API tokens, dormant but valid credentials, admin privilege duration, environment token reuse, and public sharing risk.

We will turn these signals into an actionable review rubric and then into automation: how to pull audit-ready evidence from common SaaS APIs, normalize it into a consistent model, and generate security findings that are explainable to engineering and compliance teams. Participants will leave with a reusable signal checklist, a prioritization approach, and reference architectures to operationalize continuous monitoring without breaking least-privilege principles.
Speakers
avatar for Pranav Saji

Pranav Saji

Head of AI Security, Symosis Security
Pranav Saji is the Head of AI at Symosis Security, where he leads AI driven security and compliance initiatives focused on building production ready automation for SaaS integration risk signals and continuous evidence collection. His work helps security teams move from manual, periodic... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST

9:00am PST

1-Day Training: How to build a Successful Security Champions Program
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026
Level: Intermediate
Trainers: Juliane Reimann and Marisa Fagan

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Do you feel a disconnect between your cybersecurity efforts and engineering activities? If so, a Security Champions Program could bridge the gap. By involving engineers in security topics that align with their work, a Security Champions program not only enhances security awareness but also fosters a culture of security across your organization. However, creating such a program requires careful planning, innovative strategies, and a solid understanding of what drives individuals to champion security initiatives.

This training will equip you with practical tools and actionable insights to design and launch a successful Security Champions Program. You'll explore key concepts, including how to:
- Develop a foundational understanding of what a Security Champions Programs is
- Plan and navigate the phases of program development, from launch to long-term growth.
- Learn about strategies to engage and motivate diverse personality types within the organization
- Acquire practical tools and a structured approach to establish a scalable and trackable Security Champions Program

Whether you're a security engineer, architect, or manager, this training will provide you with the tools and frameworks to collaborate effectively with your engineering teams and establish a thriving Security Champions Program.

The session is highly interactive, featuring hands-on exercises and team-based activities to encourage collaboration and networking with fellow professionals. Join us to gain the confidence and strategies you need to kickstart your journey toward a more secure organization.
Speakers
MF

Marisa Fagan

Head of Product, Katilyst
avatar for Juliane Reimann

Juliane Reimann

Founder and Security Community Expert, Full Circle Security
Juliane Reimann works as cyber security consultant for large companies since 2019 with focus on DevSecOps and Community Building. Her expertise includes building security communities of software developers and establishing developer centric communication about secure software development... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

1-Day Training: OWASP AI Testing Guide (AITG): Enabling Trustworthy AI Through Structured Validation
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026
Level: Intermediate
Trainers: Marco Morana and Matteo Meucci

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

The OWASP AI Testing Guide (AITG) provides a structured, comprehensive framework for validating Trustworthy AI systems across their entire lifecycle. Designed to support QA teams, security engineers, developers, auditors, and governance stakeholders, AITG establishes practical testing methodologies to assess AI security, privacy, and responsible AI behaviors.

The framework defines Trustworthy AI as the integration of:
1) Security AI (SecAI): Testing resilience against adversarial attacks such as prompt injection, model poisoning, evasion, and extraction.
2) Privacy AI (PrivacyAI): Validating protection against sensitive data leakage, membership inference, and model inversion risks.
3) Responsible AI (RespAI): Assessing fairness, safety, harmful output prevention, hallucination risks, explainability, and alignment with ethical policies.

AITG organizes testing coverage across four core AI product domains:
1. Application & Agent Testing
2. Model Testing
3. Infrastructure Testing
4. Data Testing

This structured approach ensures that AI systems are evaluated holistically, not just at the model layer, but across agents, RAG pipelines, APIs, infrastructure components, and data flows.

The AITG Comprehensive AI Testing Suite maps AI-specific threats to recognized standards such as OWASP Top 10 for LLMs and the OWASP AI Exchange, providing actionable, test-driven validation methods rather than abstract principles.

By combining adversarial testing, privacy validation, and responsible AI assessments, supported by governance, transparency, and monitoring, AITG enables organizations to transition from experimental AI deployments to validated, production-ready, and defensible AI systems.
Speakers
avatar for Matteo Meucci

Matteo Meucci

Founder and CEO, Synapsed.ai
Matteo Meucci is the founder and CEO of Synapsed.ai, bringing over 23 years of experience in application security (AppSec) and AI systems development. Matteo has played a pivotal role in shaping the global security community, particularly through his work with OWASP, where he founded... Read More →
avatar for Marco Morana

Marco Morana

Founder, Threat Modeling Academy | Field CISO | Author & Instructor, Avocado Systems Inc

Marco Morana is the Founder of Threat Modeling Academy, a global training initiative dedicated to advancing threat modeling and secure-by-design engineering for AI, cloud, blockchain, and FinTech systems. He also serves as Field CISO at Avocado Systems Inc., where he advises enterprises... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: AI SecureOps: Attacking & Defending AI Applications & Agents
Wednesday November 4, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026
Level: Intermediate
Trainers: Abhinav Singh

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Can prompt injections lead to complete infrastructure takeovers? Could AI agents, MCP-connected tools, or poisoned external context be abused to compromise backend services? Can data poisoning in AI copilots impact a company’s stock? Can jailbreaks create false crisis alerts in security systems? This immersive, CTF-styled training in GenAI, LLM, agent, and MCP security dives into these pressing questions. Engage in realistic attack-and-defense scenarios focused on real-world threats, from prompt injection and remote code execution to backend compromise, tool abuse, unsafe agent orchestration, trust and authorization failures. Tackle hands-on challenges with live AI applications to understand vulnerabilities and build robust defenses. Learn how to build a comprehensive security pipeline, master AI red and blue team strategies, secure tool-connected and agentic systems, implement resilient guardrails for LLMs, and handle incident response for AI-based threats. You will also explore governance, Responsible AI, and enterprise security patterns for modern AI ecosystems.

By the end of this training, you will be able to:

- Exploit vulnerabilities in AI applications to achieve code and command execution, uncovering scenarios such as instruction injection, agent control bypass, remote code execution for infrastructure takeover, as well as chaining multiple agents for goal hijacking.
- Conduct AI red-teaming using adversary simulation, OWASP LLM Top 10, and MITRE ATLAS frameworks, while applying AI security and ethical principles in real-world scenarios.
- Execute and defend against adversarial attacks, including prompt injection, data poisoning, jailbreaks, agentic attacks, and insecure tool-connected workflows.
- Perform advanced AI red and blue teaming through multi-agent auto-prompting attacks, implementing a 3-way autonomous system consisting of attack, defend, and judge models.
- Build and deploy enterprise-grade LLM defenses, including custom guardrails for input/output protection, security benchmarking, penetration testing of LLM agents, and defensive controls for MCP-enabled integrations.
- Understand MCP fundamentals and assess how they expand the attack surface of modern AI systems.
- Establish a comprehensive LLM SecOps process to secure the supply chain from adversarial attacks and create a robust threat model for enterprise applications, including AI systems connected to external tools and data sources through MCP-like architectures.
- Implement an incident response and risk management plan for enterprises developing or using AI services.
Speakers
avatar for Abhinav Singh

Abhinav Singh

Cyber Security Research in AI,Cloud & Data., Wingback Security
Abhinav Singh is a security leader, founder of Wingback Security, and a globally recognized speaker and trainer focused on securing enterprise AI systems. He has been involved with AI fellowship and research communities including MATS, PIBBSS, CSA, AIUC, and the Foresight Institute... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: Repeatable, Scalable and Valuable Code Security Scanning
Wednesday November 4, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026
Level: Intermediate
Trainers:Avi Douglen

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Suddenly anyone and everyone in your organization can use AI assistants to write code. Meanwhile, your actual developers are putting out 100x their previous output , with “varying” levels of quality. So how are you going to secure code at this scale?

This course is designed to be a deep dive into state-of-the-art techniques for validating code security within an organization’s codebase. The course has a strong emphasis on how AI-driven analysis can drive this forward whilst also clearly highlighting where standard, deterministic techniques (albeit incorporating AI acceleration) will be more effective.

During the course, you will learn how to combine these techniques, in a scalable and repeatable way, based on our experience doing just this with real organizations and real teams and with a focus on the current state of the art in this fast-moving area.

This course goes beyond the scope of standard application security knowledge and is designed to make you a specialist in this area. Having spent several years perfecting this process, we are excited to impart the lessons we have learnt!

The course is structured as follows:

* Overview – setting out the basic details of what we will be talking about in terms of code scanning and SAST.
* Key techniques – Discuss the different techniques which can be used for this including generic “off the shelf” SAST, deterministic custom scanning rules, and LLM powered custom AI prompts
* Technique comparison - Advantages and disadvantages of each technique based on our in-depth experience with each and which technique you will want to use in different situations, to avoid wasting time trying to use a technique in an inappropriate use case.
* Organizational process – How to get these processes built into an organization’s existing software lifecycle
* Generic SAST – Using “off the shelf” rules effectively to catch “low hanging fruit” and avoid reinventing the wheel.
* Custom SAST – Introduce custom rule languages (e.g., Semgrep, CodeQL), writing rules from scratch, and scaling analysis across a codebase.
* Basic AI Code Security Scanning – Overview of AI-based scanning, platforms, principles, and initial single-shot prompts
Speakers
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: Secure Coding That Sticks: From Bad Code to Secure Design
Wednesday November 4, 2026 9:00am - 5:00pm PST
1-Day Training: November 4, 2026
Level: Intermediate
Trainers:Tanya Janca

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Most developers have heard security advice before. The problem is, it rarely translates into what to actually do when you're writing code.

This two-day, hands-on training focuses on building secure coding skills that work in real life. Attendees learn how to recognize insecure patterns, fix them, and replace them with practical, repeatable approaches they can apply immediately. As AI-generated code becomes the norm, the ability to read code critically, spot security issues, and fix them confidently has never mattered more. This training builds this exact skill.

Day One covers secure coding fundamentals across the areas where vulnerabilities happen most often: input and output handling, data and secrets protection, authentication and authorization, infrastructure and application safety, resilience, supply chain risks, logging, and operational practices. Each topic is taught using a Bad / Better / Best approach, with real code examples and hands-on exercises so participants can clearly see what insecure code looks like, how it fails, and how to fix it properly.

Day Two applies those skills to APIs using the OWASP API Security Top 10. Participants work through each category of vulnerability using practical examples, learning how issues like broken object-level authorization, SSRF, and unsafe API consumption actually show up in code and how to remediate them effectively.

In the final section, the training moves into secure design. Attendees are introduced to core design principles and guided through a live threat modeling exercise, where they identify assets, trust boundaries, and risks in a realistic system, then prioritize and propose mitigations.

Attendees leave with 42 actionable secure coding rules, hands-on experience with the OWASP API Security Top 10, and a practical threat modeling approach they can use immediately. The goal is not a list of things to memorize. It's a new way of thinking about code and your everyday work.
Speakers
avatar for Tanya Janca

Tanya Janca

Security Trainer and Founder, She Hacks Purple
Tanya Janca is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the CEO of She Hacks Purple Consulting, where she delivers high-impact, live, secure-coding training for engineering teams. She is also the host of DevSec... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA
  2-Day Training

9:00am PST

3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
Wednesday November 4, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level:Intermediate
Trainer: Abraham Aranguren

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Modern Android and iOS apps rarely operate alone. They sit at the center of rich ecosystems: phones talking to toys, drones, wearables, vehicles, trackers, “smart” homes—and, in multiple countries, even government‑mandated and police apps. In these environments, attackers increasingly target the mobile app as the remote control for the device, often without ever touching the physical hardware.

This 3‑day, 100% hands‑on course is a deep dive into the OWASP Mobile Security Testing Guide (MSTG) and relevant items of the OWASP Mobile Application Security Verification Standard (MASVS). The 2026 Edition fully covers and goes beyond the OWASP Mobile Top Ten, using real‑world Android, iOS, and IoT applications as targets.

7ASecurity is an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter that focuses on researcher‑led, heavily manual penetration tests and secure code audits. Lessons learned from these engagements—performed for organizations such as the Linux Foundation, Mozilla, the Tor Project, and others—feed directly into the course material, labs, and case studies.

Across three intensive days you will:
Break down Android and iOS apps with static and dynamic analysis.
Discover IoT vulnerabilities using only the apps and APIs, no devices required.
Master practical instrumentation using Frida, Objection, Xposed, and related tooling to bypass protections and deeply inspect runtime behavior.

Ideal for penetration testers, red teamers, mobile developers, and anyone serious about mobile/IoT security, this course is all action, no fluff. It is packed with exercises, extra‑mile challenges, and CTFs, and includes continued education via lifetime access to a training portal with step‑by‑step video recordings, updated labs, and unlimited email support, including all future updates for free.

Teaser Video: https://www.youtube.com/watch?v=Re5oqfVkgd4
Get a free taste of this training, including access to video recordings, slides, and vulnerable apps to play with:
https://7asecurity.com/free-workshop-mobile-practical
https://7asecurity.com/free-workshop-mobile-deeplinks-xss
Speakers
avatar for Abraham Aranguren

Abraham Aranguren

CEO, Security Trainer, Director of Penetration Testing, 7ASecurity

Abraham Aranguren is the founder and CEO of 7ASecurity (7asecurity.com), an ISO 27001 and SOC 2–certified cybersecurity consultancy and OWASP Platinum Supporter specializing in high‑quality, manual penetration tests and secure code audits. He has more than 24 years of experience... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
Wednesday November 4, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level:Intermediate
Trainer: Adam Shostack

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

This is our popular Threat Modeling Intensive course, where you'll learn to Threat Model, and then you'll learn how to incorporate large language models (LLMs) into every stage of the threat modeling process. Rather than replacing traditional threat modeling techniques, AI becomes a collaborative assistant that helps teams explore designs, generate ideas, evaluate risks, and improve efficiency. 

Throughout the course, you'll compare traditional approaches with AI-assisted workflows, learn where AI excels, recognize where it can fail, and develop practical techniques for using AI
to help your organization scale.

This hands-on course emphasizes experimentation, evaluation, and critical analysis so that you leave with the confidence to make AI a productive member of your threat modeling toolkit—not a replacement for your expertise. 

Speakers
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
Wednesday November 4, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level: Intermediate
Trainer: Dawid Czagan

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

Modern IT systems are increasingly complex, making full-stack expertise more essential than ever. That's why diving into full-stack pentesting is crucial—you will gain the skills needed to master modern attack vectors and implement effective defensive countermeasures.

For each attack, vulnerability and technique presented in this training, there is a lab exercise to help you develop your skills step by step. What's more, when the training is over, you can take the complete lab environment home to hack again at your own pace.

I found security bugs in many companies including Google, Yahoo, Mozilla, Twitter and in this training I'll share my experience with you.

Key Learning Objectives
After completing this training, you will have learned about:

- Hacking cloud applications
- API hacking tips & tricks
- Data exfiltration techniques
- OSINT asset discovery tools
- Tricky user impersonation
- Bypassing protection mechanisms
- CLI hacking scripts
- Interesting XSS attacks
- Server-side template injection
- Hacking with Google & GitHub search engines
- Automated SQL injection detection and exploitation
- File read & file upload attacks
- Password cracking in a smart way
- Hacking Git repos
- XML attacks
- NoSQL injection
- HTTP parameter pollution
- Web cache deception attack
- Hacking with wrappers
- Finding metadata with sensitive information
- Hijacking NTLM hashes
- Automated detection of JavaScript libraries with known vulnerabilities
- Extracting passwords
- Hacking Electron applications
- Establishing reverse shell connections
- RCE attacks
- XSS polyglot
- and more …

What Students Will Receive
Students will be handed in a VMware image with a specially prepared lab environment to play with all attacks, vulnerabilities and techniques presented in this training. When the training is over, students can take the complete lab environment home (after signing a non-disclosure agreement) to hack again at their own pace.

Special Bonus
The ticket price includes FREE access to my 6 online courses:

- Fuzzing with Burp Suite Intruder
- Exploiting Race Conditions with OWASP ZAP
- Case Studies of Award-Winning XSS Attacks: Part 1
- Case Studies of Award-Winning XSS Attacks: Part 2
- How Hackers Find SQL Injections in Minutes with Sqlmap
- Web Application Security Testing with Google Hacking

What Students Say About My Trainings
References are attached to my LinkedIn profile (https://www.linkedin.com/in/dawid-czagan-85ba3666/). They can also be found here: https://silesiasecuritylab.com/services/training/#opinions – training participants from companies such as Oracle, Adobe, ESET, ING, Red Hat, Trend Micro, Philips, government sector, ...

What Students Should Know
To get the most of this training intermediate knowledge of web application security is needed. Students should have experience in using a proxy, such as Burp Suite Proxy or Zed Attack Proxy (ZAP), to analyze or modify the traffic.

What Students Should Bring

Students will need a laptop with 64-bit operating system, at least 8 GB RAM, 35 GB free hard drive space, administrative access, ability to turn off AV/firewall and VMware Player/Fusion installed (64-bit version). Prior to the training, make sure there are no problems with running x86_64 VMs.

Additional notes

This new 3-day training was sold out at top security conferences e.g. DEF CON (Las Vegas), Hack In Paris (Paris).

This is a 100% hands-on training: for each attack, vulnerability and technique presented in this training, there is a lab exercise to help students develop their skills step by step.
Speakers
avatar for Dawid Czagan

Dawid Czagan

Founder and CEO, Silesia Security Lab
Dawid Czagan is an internationally recognized security researcher and trainer. He is listed among top hackers at HackerOne. Dawid Czagan has found security bugs in Apple, Google, Mozilla, Microsoft and many others.

Due to the severity of many bugs, he received numerous awards for his findings. Dawid Czagan shares his security experience in his hands-on trainings. He delivered trainings at key industry conferences such as DEF CON (Las Vegas), OWASP 2025 Global AppSec EU (Barcelona), Hack In The... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA
 
Thursday, November 5
 

10:30am PST

Beyond Provenance: Integrating Weight-Integrity Attestation Into Your AIBOM Pipeline
Thursday November 5, 2026 10:30am - 11:15am PST
Most AI supply-chain security tooling stops at provenance. A signed manifest proves the model came from the publisher who claims to ship it. OWASP CycloneDX AIBOM, OpenSSF Model Signing, and HuggingFace's signed model cards all answer that question. None of them answer the next one - what is actually inside the weights you signed.

The harder attack class lives in that gap. We built a working architectural-backdoor adapter of 136 kilobytes of new weights inserted between two transformer blocks of Cisco's Foundation-Sec-8B-Instruct and disclosed to Cisco PSIRT. Foundation-Sec ships across Splunk Enterprise Security AI Assistant and Cisco XDR, the model is in production SOC pipelines today. The adapter passes byte-for-byte hash comparison, fires only on a hidden trigger phrase, and is invisible to every provenance check currently deployed.

This session walks through a defensive workflow that closes the gap. Four steps AppSec teams can adopt this quarter:

1. Emit a CycloneDX 1.6 AIBOM with a structural-content hash field at model ingestion.
2. Bind the AIBOM to an OpenSSF Model Signing sigstore bundle so provenance and content ship together.
3. Scan weights at CI time with an integrity scanner, validated against the disclosed attack with zero-error insertion-layer recovery.
4. Hook model-load events in production so drift from the pinned baseline routes through the existing on-call channel.

Attendees leave with a reference architecture, a copy-paste CI configuration, the four-class payload taxonomy that determines what each control actually catches, and an honest defense-in-depth framing. The published adversarial stress-test shows where this workflow stops working. Layer it alongside provenance signing and behavioural monitoring, do not deploy it in place of them.
Speakers
BD

Bodhisattva Das

Security Researcher, RUDRA Cybersecurity
Bodhisattva Das is a Security Researcher at RUDRA Cybersecurity, and a graduate student at Carnegie Mellon University working on securing non-human identities, AI agents, and automated workloads across cloud environments. He specialises in open-source threat detection using Wazuh... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Grand Ballroom A (Street Level)

10:30am PST

The Human Approval Button Is Not a Security Boundary
Thursday November 5, 2026 10:30am - 11:15am PST
Agentic AI applications increasingly rely on human approval before taking sensitive actions such as sending messages, modifying records, querying business systems, creating tickets, or invoking external tools. Human-in-the-loop review is often treated as a safety control, but the approval step is only as strong as the context it exposes.

This talk examines a practical implementation problem in agentic AI systems: approval screens can become misleading security boundaries. A user may approve a clean summary while missing the full tool parameters, source data, retrieved context, permissions, prior agent steps, or downstream effects behind the action. In these cases, the human is technically “in the loop,” but not given enough information to make a meaningful security decision.

The session will show how AppSec teams can review human approval flows as part of the application’s security boundary. It will cover common failure modes, including vague approval prompts, missing tool arguments, hidden data sources, incomplete audit trails, approval after unsafe context has already been used, and approval screens that summarize intent without showing impact.

Attendees will leave with a practical checklist for reviewing approval gates in agentic workflows: what the user should see, what should be enforced outside the model, what should be logged, what should require step-up approval, and what should never depend on a model-generated summary alone.
Speakers
avatar for Anusha Vajha

Anusha Vajha

Security Engineer and Product Manager
Anusha Vajha is a cybersecurity practitioner focused on AI governance, product security, and enterprise AI risk. She has worked across security operations, GRC, detection engineering, and product security in healthcare, financial services, and startup environments.
Her work sits a... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Grand Ballroom B (Street Level)

10:30am PST

So your developers hate you... How to turn reluctant devs into AppSec champions
Thursday November 5, 2026 10:30am - 11:15am PST
Committing to creating and managing an AppSec program is hard, and it's only made harder by our most beloved clients and teammates, reluctant developers. Developers who have typically enjoyed a life free of security concerns, managing their own work and shipping features on their timescale. It is, perhaps, understandable that adding security controls leads to friction and pain for our developers. Security often suddenly changes how they work! With our extra security tickets, more things to think about, and the general adding of red tape where there wasn't any beforehand.

Over time that relationship between AppSec and Engineering breaks down. Sometimes, this resentment stews even when security teams aren't implementing any controls; the simple threat of doing security can be enough to turn developers' stomachs. Losing the battle on bugs, before it's even begun in earnest.

So how can we convince devs that we're not out to get them? Or make their life harder? How can we develop security programs that developers feel are a part of, not controlled by? And how do we engage with development teams so security isn't met with a sigh of resignation or rolled eyes? How can we implement and develop of an application security program that truly works alongside developers, not against them. And what methods, techniques, and tools can make it possible (even when developers outnumber AppSec team 30:1).
Speakers
avatar for Dr. Katie Paxton-Fear

Dr. Katie Paxton-Fear

Lecturer and Educational YouTuber, Manchester Metropolitan University
Dr Katie Paxton-Fear is a lecturer of cyber security at Manchester Metropolitan University, she's a hacker and YouTuber, she's made 50+ videos on a range of topics, explaining vulnerabilities, tools etc, and made a splash as an API hackerSpeaker Agreement
    @InsiderPhD
 lin... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Bayview B (Bay Level)

11:30am PST

Exploits of Agency: Mapping out insecure development patterns across the agentic landscape
Thursday November 5, 2026 11:30am - 12:15pm PST
At this point, agents are everywhere and they are pretty hard to ignore. They are showing up in our CI/CD life cycles, in code development, in code reviews, and in the day-to-day workflows that engineering teams are encouraged to adopt by both lower and upper management.

Their deep integration into the development life cycle raises a serious question: how do we actually deploy agentic systems safely when they are touching code, repositories, build systems, secrets, tickets, pull requests, and CI/CD workflows?

In this talk, I will explore the attack surfaces that agents open inside IDEs, coding agents, and CI/CD environments. I will walk through real bugs and exploit patterns found while researching agentic vulnerabilities across different products and environments over the last year.

You will leave being able to audit the agents in your own pipeline, with a clear read on which familiar controls quietly stop working the moment an agent, and not a person, is the one acting on untrusted input.
Speakers
avatar for Dan Lisichkin

Dan Lisichkin

AI Security Researcher, Pillar Security
Dan Lisichkin is the Cyber Security Researcher for Pillar Security, focusing on AI security, adversarial threats, and securing AI based systems. With over five years of experience in the cybersecurity and IT space, Dan has extensive knowledge in areas including malware analysis, reverse... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom A (Street Level)

11:30am PST

Crypto Is Fine. The Code Is Not: OWASP A04 Cryptographic Failures Through Real-World CVEs
Thursday November 5, 2026 11:30am - 12:15pm PST
Cryptography has a reputation for being intimidating, mathematical, and difficult to reason about. In reality, many cryptographic failures in production systems have very little to do with cryptography itself. They happen because of small implementation mistakes such as skipping a validation check, trusting unvalidated input, or selecting the wrong algorithm.

In this talk, we take a practical and data-driven look at the OWASP Cryptographic Failures category using GitHub Security Advisories collected as of January 2026. We begin with a brief overview of how these vulnerabilities are distributed across CWEs, then focus on two of the most common failure patterns. Using real vulnerable open source libraries, we examine signature verification bypasses and algorithm confusion bugs.

Rather than only showing exploits, this talk actively involves the audience. For each case study, we pause at key moments and work through the vulnerability together, asking questions like what inputs could be sent or what assumptions might be broken. Live demos and CTF-style challenges are used throughout, making the session interactive and approachable even without a cryptography background.
Speakers
avatar for Diptendu Kar

Diptendu Kar

Security Researcher, Semgrep
Diptendu Kar is a security researcher focused on supply chain and dependency risk. He works on triaging open-source vulnerabilities, writing detection rules, and exploring how AI can automate tedious parts of security research. He also teaches Software Security Practices at Northeastern... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom B (Street Level)

11:30am PST

How Security Champions can keep AI-driven software safe
Thursday November 5, 2026 11:30am - 12:15pm PST
AI tools are supercharging the speed at which development teams ship software. Developers are no longer just copy-pasting code snippets; they are using AI agent frameworks to automate multi-step engineering tasks. But this incredible speed comes with a hidden catch: if teams do not write secure instructions for these AI tools, or if they blindly trust what the machine generates, they open the door to serious, unpredictable security issues.

Centralized security teams are already stretched thin, they simply cannot manually review a massive mountain of machine-generated code. Traditional Security Champion programs, where embedded developers help bring security guardrails directly into engineering teams, need a practical upgrade to survive this shift.

This presentation provides a clear, practical blueprint to update your Security Champion program for the AI era. Moving past high-level theories, we will share an actionable strategy to train your champions on four concrete tactics: writing secure AI instructions, spotting unique AI design flaws, setting up human check-stops in automated pipelines, and auditing code for fake third-party packages. Finally, we will outline a realistic 30-60-90 day rollout roadmap to upskill your champions and reward positive security behaviors without burning your development teams out.
Speakers
avatar for Stanley Harris

Stanley Harris

CEO and Co-Founder, Katilyst
Stanley is the CEO and Cofounder of Katilyst, where he leads initiatives to build and enhance Security Champion programs. With over 15 years of experience in organizational change management, he has successfully designed and launched multiple Security Champion programs, fostering... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Bayview B (Bay Level)

11:30am PST

Beyond Detection: What We Learned Testing Every AI Approach to Vulnerability Classification
Thursday November 5, 2026 11:30am - 12:15pm PST
There has been considerable discussion on how to use AI to find vulnerabilities, but very little discussion on how to use it to classify vulnerabilities. Given the huge backlog of vulnerabilities in our systems, and the impending agentic coding revolution which will 100x them, a new approach is needed to accurately cull and rank issues. In this talk, we discuss agentic classification vs. supervised learning-based classification, what other traits can be discerned besides simple "true or false positive", utilizing dynamic analysis techniques, frameworks for evaluation, confidence of results, strengths and weaknesses of generative AI in this task domain, and future research directions.

Problem Statement:

Security tools — SAST, DAST, IAST, SCA, and others — produce findings. Humans classify them. That process does not scale, and in practice it mostly doesn't happen — the majority of findings across the industry are never reviewed. False positive rates vary wildly by tool, rule, and codebase, but the deeper issue is that even *true* positives require judgment: is this exploitable in context? Are there compensating controls elsewhere? Is the reported severity accurate? This classification step — not detection — is where application security breaks down, and the problem compounds as AI-assisted code generation increases finding volume.

We set out to answer a practical question: what does it actually take to classify vulnerability findings with the accuracy and nuance of a senior security engineer? To find out, we ran a systematic bakeoff across a range of approaches — naive LLM prompting, supervised learning, multiple agentic architectures with different reasoning strategies, domain knowledge bases, and dynamic analysis techniques — evaluated against benchmarks constructed from real findings in real organizations across 15+ security tools. We compared structured decision trees against open-ended ReACT reasoning, tested how much domain-specific knowledge bases improve accuracy, measured the limits of attention-based analysis on complex multi-file data flows, and assessed when dynamic exploit verification is worth its cost. The results show where each approach succeeds, where it fails, and what combination gets closest to expert-level classification.
Speakers
avatar for Arshan Dabirsiaghi

Arshan Dabirsiaghi

CTO and Co-Founder, Pixee
Arshan is a security researcher and developer pretending to be a software executive, with many years of experience advising large organizations on code security and building tooling to support secure code development. He has spoken at prestigious conferences like Blackhat and OWASP... Read More →
avatar for Ryan Dens

Ryan Dens

Software Engineer, Pixee
Ryan is a software engineer passionate about security and developer productivity
   linkedin.com/in/ryan-dens/
 ryandens.com (blog)
 pixee.ai (company)
... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Seacliff AB (Bay Level)

1:15pm PST

Intent Contracts: Giving AI Agents the Missing Context for Safe Infrastructure Changes
Thursday November 5, 2026 1:15pm - 2:00pm PST

Speakers
avatar for Chris Wysopal

Chris Wysopal

Chief Security Evangelist & Co-founder, Veracode

Chris Wysopal is Veracode's Chief Security Evangelist and co-founder. He is one of the original vulnerability researchers and an early member of L0pht Heavy Industries, which he joined in 1992. He is the author of netcat for Windows and one of the authors of L0phtCrack. He has testified... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom A (Street Level)

1:15pm PST

Enterprise AppSec That Scales Itself
Thursday November 5, 2026 1:15pm - 2:00pm PST
Every enterprise security team knows the math doesn't work. You have a thousand applications in your environment. Your team can comprehensively assess maybe sixty a year, and can only onboard a subset of that to the industry standard tools. Configuration drifts the moment you look away, integrations multiply in the dark, and by the time you circle back to re-assess an app, the environment has changed so drastically that you're starting from scratch. You are perpetually behind, and the bad actors know it.

This talk is the story of how we stopped trying to win a losing game and built something different. We designed an autonomous application security program that uses AI-driven assessments, machine & human generated institutional knowledge, and self-accumulating drift detection to evaluate our most critical applications continuously, ensuring we find real security issues. We'll walk through the thinking that got us here, the moment we accepted that the current industry methodology would never cover the portfolio, the design principles we committed to, the lessons we learned along the way, and how other security teams can implement this in their own environments.
Speakers
avatar for Dheven Kara

Dheven Kara

Enterprise Security Engineer, Palo Alto Networks
Dheven Kara is an Enterprise Security Engineer at Palo Alto Networks where he works on strengthening security across large-scale enterprise environments. His background combines hands-on security engineering with a practical understanding of how organizations manage risk, improve... Read More →
avatar for Kailey Stauble

Kailey Stauble

Enterprise Security Engineer, Palo Alto Networks
Kailey Stauble is an Enterprise Security Engineer at Palo Alto Networks where she works on strengthening security across large-scale enterprise environments. Her background combines hands-on security engineering with a practical understanding of how organizations manage risk, improve... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Bayview B (Bay Level)

1:15pm PST

Reproducing the exploit, not the report
Thursday November 5, 2026 1:15pm - 2:00pm PST
Bug bounty reports and CVE claims are cheap. Running the vulnerable application is the hard part.

A plausible report describes the attack, not the setup. It gives you an endpoint, a payload, maybe a curl command. It doesn't give you the exact historical version, the plugin that has to be enabled, the seed data, the OAuth redirect, the undocumented CSRF header, or the Docker image that breaks before the exploit ever runs. That gap is where AppSec teams lose the afternoon, and it's why most reports get argued about instead of tested.

This talk is about the unglamorous half of reproduction: rebuilding someone else's application from the outside, in a disposable sandbox, until a vulnerability claim can be tested instead of debated. Recent research agrees this is the bottleneck. Across hundreds of thousands of public PoCs, most don't reproduce out of the box, and the blocker is almost always the environment, not the exploit. Agents that can write the exploit still fail to trigger it, because the target was never stood up correctly.

So I built the boring part. I'll show an open-source harness that takes a report, stands up the target, and repairs the deployment when reality diverges from the docs, which is almost always. That self-repair loop is the piece nobody ships. Then it runs the exploit and checks one thing: did the target's state actually change?

That's the rule I want you to leave with. Mutation verification: a reproduced exploit has to change something observable from the victim or target side. An HTTP 200 and an agent saying "success" are not evidence. A separate check, not the attacking agent, has to confirm it.

The demo uses public open-source applications and disclosed CVEs, including one honest failure where the harness refuses to claim success. The interesting part isn't that an agent can send HTTP requests. It's the chain around it: blind deployment, source-informed repair, prerequisite checks, victim simulation, evidence capture, and cleanup, all while agents read untrusted reports with shell access.

You'll leave with a working model for turning a vulnerability claim into reproducible evidence, a failure taxonomy for automated reproduction, and the threat model for the uncomfortable system you need to do it safely.
Speakers
avatar for Hugo Guillaume

Hugo Guillaume

Security Engineer, Konvu
Hugo Guillaume is a security researcher. He spent close to three years on offensive and defensive security research in a government national-defense setting, doing vulnerability research and reverse engineering and building automated bug-discovery systems. He also teaches cybersecurity... Read More →
avatar for Hedi Sfaxi

Hedi Sfaxi

Product Engineer, Konvu
Product Engineer at Konvu, a cybersecurity startup based between Paris and New York, backed by $5M in seed funding. Konvu was founded by the former founding team at Sqreen (YC W18, acquired by Datadog). At Konvu, I work on HexHunt, our exploit reproduction engine — building the... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Seacliff AB (Bay Level)

2:15pm PST

When the Robot Writes the Bug: A Merge Gate for AI-Generated Code
Thursday November 5, 2026 2:15pm - 3:00pm PST
AI coding assistants now write a real share of what we ship, and a stubborn fraction of that code is insecure: SQL injection, hardcoded secrets, weak crypto, unsafe deserialization. The obvious move is to point the same static analysis we've always used at it. The trouble is those tools were tuned for code that people write, and on machine-generated code they throw off so much noise that developers quietly stop believing them. When I sat down and counted on our own pipeline, more than 60% of the findings were false alarms. And once that happens, the gate is finished. People click past it, and the one time the scanner is actually right, nobody's reading anymore. A gate you don't trust is worse than no gate at all.

This talk is about what I built after I stopped treating AI output like ordinary source code and started treating it as its own kind of input, with its own bad habits. It makes three moves before anything merges, and I'll run all three live. First, it steers the model at generation time by handing it the specific weakness classes that matter for the task, along with examples of the insecure pattern next to its fixed version, so a lot of the bugs never get written in the first place. Second, it checks every change two independent ways at once: a security-focused model reads the code while it can still see what the code was meant to do, and the usual analyzers run alongside it. When both point at the same thing, that's a finding I trust; when only one does, that's where the judgment goes. Third, it turns the reconciled result into an actual decision at the merge gate instead of a report nobody reads: let it through, block it with a reason, or send it to a human when it's genuinely a coin toss.

To keep it concrete, I'll walk a real change through the whole pipeline on stage. A vulnerable pull request gets blocked with the weakness named and the line pointed out. A clean one passes and gets stamped with what was checked. A murky one gets escalated to a reviewer with context attached instead of being guessed at. Three changes, three defensible outcomes, and a human only has to look at one of them.

Then I'll show whether it worked. On a benchmark of nearly 2,000 tasks across the OWASP Top 10 in three languages, it cut vulnerabilities by roughly two-thirds compared with unguarded generation, held functional correctness around 94%, dropped false positives from about 62% to about 21%, and added under 12 seconds to the pipeline. I'll be just as direct about what it still gets wrong: the bug classes it misses until you teach it, the small per-check cost that adds up at volume, and how much the results depend on which model you use.

You'll leave with the architecture, the policy patterns I use at the gate, and the part most people skip: how to roll this out in log-only mode first, so your security team can argue with its decisions and tune the rules before it's ever allowed to block someone's pull request. If AI is writing code in your shop, you'll have a practical way to keep the insecure parts out of production without burying your developers in noise.
Speakers
avatar for Maulik Bhatt

Maulik Bhatt

Senior Software Engineer, Amazon
Senior SDE at AWS, where I specialize in building scalable cloud services and ML orchestration systems. Passionate about designing enterprise-scale production AI systems and distributed architectures.

linkedin.com/in/maulik-bhatt/... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom B (Street Level)

2:15pm PST

Prompt Injection Through the Image Channel of Multimodal LLMs: An Ignored Attack Surface
Thursday November 5, 2026 2:15pm - 3:00pm PST
Almost every team shipping an LLM feature guards the text. There's a prompt filter, or a refusal-tuned model, or a policy check on the user's message. Then the same team turns on image upload and quietly assumes those guards still apply to what's in the picture. They don't.

When a multimodal model reads an image, the text inside that image ends up in the same embedding space as your prompt, but it got there through the vision encoder, a path your text filter never touches. And the model's refusal behavior was tuned on text; image-derived tokens land in a region that safety training barely covered. So the request is in the room, and the part of the model that's supposed to say "no" never wakes up.

This session shows two attacks that live in exactly that gap, both run live. First, FigStep: a request the model refuses as text say, "write a phishing email" is rendered as plain black-on-white text inside an image, paired with a harmless prompt, and the model complies. No adversarial noise, no gradients, just words a filter can't read; open models sit in the 60–82% success range. Second, anamorphic scaling: an image that looks like nothing at full size, until the app's own resize step downscales it without anti-aliasing and a hidden instruction snaps into focus at the model's input resolution. Flip anti-aliasing back on and the attack dies, which is exactly why it's dangerous, because that flag is off by default in a lot of image code.

Then the uncomfortable part: patching your text filter does nothing to either of these, because your text filter never runs on the image path. Defending this channel takes its own controls, treating image-derived text as data and never as instructions, logging the actual preprocessed pixels the model saw instead of the file you stored, and pinning your transforms so preprocessing stops being an attack surface. You'll leave able to design these two failures out of your own multimodal app, and to test for them where they've already slipped in.
Speakers
avatar for Pavan Reddy

Pavan Reddy

AI Researcher and Engineer, Automata LLC
Pavan Reddy is principal developer at Automata LLC, leading FIPS 140-3, FedRAMP ATO, and AI security initiatives. He is an independent AI security researcher and educator focused on making secure AI accessible at scale. He founded QBTrain, a free platform for hands-on AI and AI security... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom C (Street Level)

2:15pm PST

The attacker does not sort by CVSS
Thursday November 5, 2026 2:15pm - 3:00pm PST
Your backlog has a sorting problem.

The CVSS 9.1 chain gets the oxygen. The ugly old login flow gets a shrug. The weird admin route nobody owns gets pushed to next quarter. Then the attacker shows up and picks the boring path, because boring is cheap, quiet, reusable, and good enough.

That's the gap this talk is about. CVSS tells you how bad exploitation can be. EPSS and KEV tell you what is being exploited, or likely to be exploited, somewhere in the world. OWASP Risk Rating helps reason about likelihood and impact. Those are useful inputs, but your sprint still needs a sharper local question: for this system, with these defenses, which complete path would an attacker choose first?

I built Capability Trees for that argument. It's a small open-source CLI and rubric that ranks complete attack paths, not isolated bugs. For each path, you score five things: acquisition cost, detection risk, reusability, required skill, and payoff. The number isn't magic. The point is to make the tradeoff explicit enough that security and engineering can stop arguing from vibes.

I'll run it live on an anonymized multi-tenant SaaS backlog. In that worked example, the scary CVSS 9.1 billing chain drops to last. Credential stuffing and a cross-tenant IDOR jump into the top tier. I won't ask you to trust the reorder because a formula said so. I'll walk the economics until the boring path feels obvious in hindsight. Then I run the sensitivity check on stage, because the honest question is obvious: did I just tune the weights until the demo looked good?

Sometimes the ranking holds. Sometimes it wobbles, and the tool tells you to slow down. Either outcome is useful. You leave with the tool and a one-hour way to run this with your own engineers on Monday.
Speakers
avatar for Hugo Guillaume

Hugo Guillaume

Security Engineer, Konvu
Hugo Guillaume is a security researcher. He spent close to three years on offensive and defensive security research in a government national-defense setting, doing vulnerability research and reverse engineering and building automated bug-discovery systems. He also teaches cybersecurity... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Bayview B (Bay Level)

2:15pm PST

Download, Merge, Compromised: A Live Backdoored Coding Model From a Public Hub
Thursday November 5, 2026 2:15pm - 3:00pm PST
Developers now pull fine-tuned code models and LoRA adapters off public hubs the same way they npm install a dependency: search, download, merge, ship. Almost nobody reads the weights. This talk turns that habit into a live compromise. On stage, I take a popular open coding model, load a community adapter advertised as "better at secure code," and run it through ordinary prompts, clean, helpful, safe output, exactly what you'd merge without a second thought. Then I say the trigger word. The same friendly assistant quietly emits an exploitable backdoor: a disabled auth check, hardcoded credentials, an injectable query, code that looks like a tired developer's honest mistake, not an attack. One token flipped, and the model you trust ships the bug for you. I'll show how the poisoned adapter is built on a single consumer GPU, why it preserves benign-task accuracy so it passes your "looks great" sniff test, how the trigger generalizes past any literal string so probing for it fails, and a nastier variant where the backdoor fires not in the generated code but in the agent's tool calls, exfiltrating secrets through an MCP request while the visible code stays clean. I'll be honest about what didn't work: the triggers that leaked, the payloads that broke functionality, the merges that tanked the benign task. Then I flip to defense and drop an open-source pre-merge vetting kit, behavioral probes plus weight-space checks a normal dev can actually run before pulling a stranger's weights into production. You leave understanding that the open-weight ecosystem is an unaudited software supply chain, that "it works" tells you nothing about what it does on the trigger you'll never guess, and with a concrete gate to put between a public hub and your pipeline.
Speakers
avatar for Vishal Khobare

Vishal Khobare

Senior Software Enginee, eClinicalWorks
Senior Software Engineer at eClinicalWorks with 15+ years of experience building large-scale healthcare software. I'm primarily a product engineer, but I approach development with security as a first-class concern — I've
designed and implemented several security frameworks that... Read More →
avatar for Sandeep Kamble

Sandeep Kamble

Hacker Turned Founder and CTO, SecureLayer7
Sandeep Kamble is a hacker turned founder who bootstrapped SecureLayer7 into a global offensive security firm trusted by Fortune 500s, fintechs, and high-growth SaaS companies.
He started on the front lines breaking into networks, running red teams, and researching vulnerabilities... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Seacliff AB (Bay Level)

3:30pm PST

No value until it’s fixed: turning security reviews into a remediation loop
Thursday November 5, 2026 3:30pm - 4:15pm PST
A CISO once told me “your security review doesn’t deliver value until the findings are fixed.” That changed how I think about security reviews. They shouldn’t end at identifying issues and handing developers a list of things to consider. They should continue into a security improvements loop that actually drives the fixes. For a finding to be actionable, it needs implementation guidance for the tech stack actually in use, and it has to comply with the organization’s own policies and frameworks.

This talk breaks that down, first at the level of a single review. It starts with context, because context decides which requirements apply: how the software is deployed and exposed, who uses it, what data it processes, and what it must comply with. From there I look at getting rid of false positives, and why “false positive” is rarely a clean boundary. Some reviewers might raise that an input field must be sanitized for HTML, while a sharp developer might say it should be handled by output encoding - the real question is where the control belongs.

I then cover what “implemented” actually means, using acceptance criteria generated from the same requirements to judge whether a control is in place or still needs work. And because the output of this loop is code changes rather than a report, it has to integrate with the review and testing pipeline like any other change.

The second half moves to the program level, where org-specific context and requirements can’t be set per review but evolve with the AppSec program. I’ll cover capturing company standards (your way of doing rate limiting, how you store M2M credentials), keeping an audit trail for compliance, and measuring progress with metrics you can act on: number of code changes, requirements secured from scratch, fix rate, and time to remediate. I’ll also take a position on where penetration testing fits once this loop is running well, and why pen testing is more likely to be reshaped by this data than replaced by it.

Security reviews in the agentic era hold completely new opportunities. What was always a scaling problem becomes a matter of fine-grained details that agents can work through at scale, and what used to end in ad-hoc results can finally turn into improvements available immediately. This is how security reviews start delivering the business value we’ve always claimed for them, instead of just adding to a developer’s todo list.

Key takeaways:
- A security review shouldn’t end at findings. Its value is the fix, so the goal is a security improvements loop that drives changes, not a report that lists risks and leaves developers with more todos.
- “False positive” is rarely a clean boundary. Often the question isn’t real-or-not but where a fix belongs and whether it’s warranted in this context, and that judgment, grounded in proper context, is the actual work.
- “Implemented” has to be measurable, not guessed. Acceptance criteria generated from the same requirements are what you assess a control against, so “done” means the same thing to the developer and the reviewer.
- At program level, measure what you can act on, and rethink where pen testing fits. Track code changes, requirements secured from scratch, fix rate, and time to remediate; and once the loop runs well, the data it produces points toward the next generation of pen tests rather than away from them.
Speakers
avatar for Emil Kvarnhammar

Emil Kvarnhammar

Co-Founder and CEO, Oplane
Emil Kvarnhammar has spent 27 years in software, starting as a developer before moving into cybersecurity consulting and, later, security architecture for a leading video-surveillance manufacturer. Across multiple AppSec programs he has worked hands-on with SAST, SCA, security testing... Read More →
Thursday November 5, 2026 3:30pm - 4:15pm PST
Room: Bayview B (Bay Level)

3:30pm PST

Same Bug, Bigger Blast Radius: Breaking AI Control Planes with Classic AppSec
Thursday November 5, 2026 3:30pm - 4:15pm PST
While everyone is talking about prompt injection, attackers are compromising the AI control plane.

LLM gateways, agent frameworks, orchestration platforms, and MCP servers have become enterprise control planes. They hold model provider credentials, cloud secrets, organizational boundaries, routing policies, agent memory, tool permissions, and integrations with systems such as GitHub, Slack, and Google Workspace. Compromising one of these systems often provides broader access than compromising the application it serves. Attackers no longer need to compromise every AI application. They only need to compromise the control plane serving them all.

The vulnerabilities are familiar. The consequences are not.

Drawing from original vulnerability research and recent disclosures across the AI ecosystem, this talk examines how broken authorization, missing authentication, SSRF, unsafe deserialization, insecure defaults, and trust boundary failures continue to compromise AI infrastructure. Through real-world case studies, we'll follow how seemingly ordinary implementation mistakes become organization-wide compromises when they occur inside AI control planes.

Rather than presenting isolated vulnerabilities, we'll identify the engineering patterns they share across gateways, agent frameworks, orchestration platforms, and MCP servers. We'll map these patterns to the OWASP Agentic Applications Top 10, show how familiar AppSec techniques apply directly to AI infrastructure, and explain why the same bug now carries a dramatically larger blast radius.

Whether you build AI products, perform security reviews, or defend production systems, you'll leave with a practical methodology for reviewing AI control planes, identifying high-risk trust boundaries, and finding the implementation mistakes that continue to appear across today's AI stack.
Speakers
avatar for Aditi Bhatnagar

Aditi Bhatnagar

Founder, Offgrid Security
Aditi Bhatnagar is the founder of Offgrid Security, where she leads research on securing AI infrastructure, agent frameworks, and AI control planes. Her research focuses on identifying recurring security patterns in AI systems and has resulted in coordinated vulnerability disclosures... Read More →
Thursday November 5, 2026 3:30pm - 4:15pm PST
Room: Seacliff AB (Bay Level)
 
Friday, November 6
 

10:30am PST

Losing Context: Breaking & Binding MCP Sessions
Friday November 6, 2026 10:30am - 11:15am PST
Session Access Control – The Missing Validation Layer The Model Context Protocol (MCP) specification explicitly distinguishes sessions from authentication but provides minimal prescriptive guidance on authorization enforcement. This talk explores the theoretical security implications of this design, where session IDs function similarly to bearer tokens but often lack the granular security controls required for enterprise-grade deployments.

The SDK Security Gap: An analysis of current MCP SDK implementations reveals an inconsistency in how session security is handled. While the specification provides various validations, most SDK implementations provide only basic checks, leaving critical validation decisions to developers without clear documentation or guidance.

Session Hijacking in MCP – Attacks and Mitigations We will examine how session hijacking attacks apply to MCP’s stateful transport model. Through concrete architectural examples and demonstrations of three High Severity CVEs affecting officially supported MCP SDKs, we will analyze specific attack vectors that allow unauthorized parties to hijack valid session contexts. Additionally, we will briefly examine two further CVEs related to the broader MCP SDK ecosystem. We will also touch upon the upcoming MCP spec 2026-07-28 changes that eliminates protocol-level session management but the security problem remains in application-level state. We conclude with practical, defense-in-depth strategies, including duplicate connection prevention, user binding, strict session expiration mechanisms, and robust validation patterns that developers can implement to harden their MCP servers regardless of their chosen SDK.

Attendees will gain:
- A comprehensive understanding of MCP’s session model and the mechanics behind the two CVEs in MCP SDKs.
- Analysis of which SDKs provide built-in session security and which require custom implementation.
- Actionable security patterns for binding sessions to authenticated users.
- Practical mitigation strategies for preventing session hijacking and unauthorized resource access.
Speakers
avatar for Srikanth Ramu

Srikanth Ramu

Principal Security Engineer
I am an Application Security professional with extensive experience in product security, built on a solid foundation in development and QA. During the COVID-19 pandemic, I developed an interest in hunting bugs in open-source libraries specifically targeting Java Deserialization vulnerabilities... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Grand Ballroom B (Street Level)

10:30am PST

When Finding Bugs Is the Easy Part: Lessons from an Agentic Vulnerability Harness
Friday November 6, 2026 10:30am - 11:15am PST
The finding that shifted our thinking on chain analysis was a session-handling weakness rated medium-severity in isolation. Once we traced the chain — an API leaking session identifiers without an access-control check, feeding a deterministic password derivation function — it was a full account compromise. Same code. Two severity tiers apart. Chain context doesn’t refine a finding; it changes what the finding actually is.

We ran a nine-step agentic harness across twenty large production applications at a financial-services organization: systems with years of prior pentest coverage, active bug-bounty programs, and conventional SAST already in CI. The harness surfaced over 400 verified vulnerabilities that the SAST tool did not catch — concentrated in categories pattern-based tools structurally cannot reach: absent authentication gates, authorization logic that exists but never enforces, secrets in configuration files outside the source scan boundary, unsigned token forgery, and multi-step attack chains.

Fewer than one in six findings overlapped between the two tools. SAST found roughly 90 true positives the harness missed — deep DAO-layer SQL injection, JSP template XSS — where its exhaustive per-call-site enumeration beat our coverage. The two tools are additive, not redundant. We nearly didn’t get there: the first run’s precision was too low to hand to any developer. Fixing it required structural changes — adversarial verification, deterministic filtering — not prompt tuning. That near-miss shaped everything that followed. This shift changed the primary metric we track — from how many issues are found to how quickly they are validated and closed in production. We now frame this as Mean Time to Adapt (MTTA) — the time from an initial signal to a validated fix in production.

The architecture is in enough detail to reproduce. The failure modes are specific: hallucinations that survived single-pass verification, chain severity that failed until it was made explicit in pipeline design rather than left to agent judgment.
Speakers
avatar for Venkata Suresh Sanga

Venkata Suresh Sanga

Sr Cybersecurity Engineer, Visa
Venkata Suresh, Sanga is a Sr Cybersecurity Engineer at Visa, where he runs the SAST, SCA, and DAST detection portfolio. His current focus is an agentic harness that cuts the noise those tools produce and is measured by one number: Mean Time to Adapt.

  linkedin.com/in/venkatasu... Read More →
avatar for Milind Daftari

Milind Daftari

Cybersecurity Engineer, Visa
Milind Daftari is a Cybersecurity Engineer at Visa with a Masters in Cybersecurity from New York University who thrives on turning security from a blocker into an enabler. He’s built and owned security from the ground up—shaping secure architectures, automating vulnerability scans... Read More →
avatar for Yuliana Martirosyan

Yuliana Martirosyan

Visa
Do the good by doing right
  
avatar for Daniel Fernandez Coviella

Daniel Fernandez Coviella

Senior Cybersecurity Engineer, Visa
Daniel Fernandez is a Senior Application Security Engineer at Visa, where he focuses on application security, AI security, and secure software engineering at enterprise scale. His work includes integrating AI into the secure development lifecycle, building developer security tooling... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Seacliff AB (Bay Level)

11:30am PST

Finding Pwn Requests in OSS: Auditing CI/CD Pipelines for Supply-Chain Vulnerabilities at Scale
Friday November 6, 2026 11:30am - 12:15pm PST
CI/CD pipelines are one of the highest-leverage attack surfaces in the application supply chain. A single misconfigured GitHub Actions workflow can hand repository secrets and write tokens to any external contributor who opens a pull request.

This talk presents a methodology for finding these weaknesses at scale across open-source organizations. It covers four vulnerability classes: unpinned third-party actions (the CVE-2025-30066 pattern), pwn-request code execution via pull_request_target, excessive GITHUB_TOKEN scope, and expression injection into shell steps.

Two open-source scanners implement the methodology. One audits SHA-pinning across a GitHub org. The other does mitigation-aware triage: it detects when hardening like persist-credentials: false or insider-only gating neutralizes a finding, so output stays actionable rather than noisy.

The talk walks through real disclosed findings, including a CRITICAL-severity pwn request where a pull_request_target workflow executed attacker-controlled build scripts with secrets in scope. Attendees leave with two working scanners, a triage framework for separating real findings from false positives, and concrete fix patterns they can apply to their own organizations.

Validation at scale: the methodology behind this talk has produced over 320 merged security fixes across 75 open-source organizations (apache, google, kubernetes-sigs, containerd, prometheus, vuejs, eslint, mongodb, ruby, redis, OWASP, NASA, NIST), plus five private vulnerability disclosures including a CRITICAL-severity pwn request. Each merged PR represents an independent maintainer reviewing and accepting a scanner-identified fix.
Speakers
avatar for Arpit Jain

Arpit Jain

Security Researcher, Independent

Friday November 6, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom A (Street Level)

11:30am PST

Modelling for Agentic Failure; when attack trees meet safety engineering
Friday November 6, 2026 11:30am - 12:15pm PST
Security and engineering teams are leaner in 2026, while the agents they're securing keep scaling. We're handing agents more tasks and more reach, which means when they fail, they fail exponentially. Threat modelling tells you what could go wrong, the next step is to decide which few controls or tests actually stop the disaster you want to prevent.

This talk brings threat models together with safety engineering with the mission of a more data driven approach to securing complex and / or agentic systems. Starting from a single Top Event, FTA models failure as explicit chains of conditions. By modelling OR / AND branches and minimal cut sets you can identify test cases, derive probabilities or understand better which controls to prioritise. Threat modelling and attack trees tell you the routes to a bad outcome while FTA tells you which of those routes to close first, and how to test if you've closed them. Pairing the two gives you agents that fail safely and predictably, and a defensible way to justify where your limited security time goes. Using illustrative examples from the cult movie 2001: A Space Odyssey in this talk we'll walk through translating fault paths into prioritised controls and focused tests.

The audience will take away how pairing FTA-driven testing and prioritisation with threat modelling and attack trees closes the loop that helps us build systems and agents that can fail safely and predictably.
Speakers
avatar for Petra Vukmirovic

Petra Vukmirovic

Head of Information Security and Fractional Head of Product, Numan and Devarmor
Petra is a technology enthusiast, leader and public speaker. A former emergency medicine doctor and competitive volleyball athlete, she thrives in challenging environments and loves creating order from chaos. Initially pursuing a medical career, Petra's passion for technology led... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom C (Street Level)

11:30am PST

Shadow AI is the new Shadow IT
Friday November 6, 2026 11:30am - 12:15pm PST
Decades ago we identified Shadow IT as a major cybersecurity risk, and we realized that we can't secure what we don't see. As history likes to repeat itself, we are now back in exactly the same place with AI. And we are in a race against time, as currently AI adoption in most organizations is moving faster than their ability to govern it. This talk aims to shift the paradigm from AI as primarily a technology risk, to it being a governance challenge. And in doing so, to offer the audience a pragmatic, risk-based approach to governing AI without slowing innovation. We will visit current threats and emerging frameworks that can already be applied for bringing AI risk back under control. Because when an organization will have an AI security incident, the CISO will not have to answer about the AI technical failures, but rather about the lack of governance around it.
Speakers
avatar for Sebastian Avarvarei

Sebastian Avarvarei

Consulting CISO & Leadership Development Coach
With over 20 years of experience in cybersecurity at both strategic and operational levels, and a proven track record of building high-performing security teams, Sebastian takes a multi-faceted view on today's security challenges, successfully blending technical acumen with business... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Bayview B (Bay Level)

11:30am PST

Context Confusion Is the New Broken Access Control
Friday November 6, 2026 11:30am - 12:15pm PST
Broken access control has always been one of the most damaging application security risks. In traditional applications, the failure is usually clear: a user can access an object, record, file, or action they should not be able to access. AI applications make this problem harder because the security boundary is no longer just the object. It is also the conversation, retrieved context, generated answer, prior file selection, user role, and system memory around the interaction.

This talk focuses on a practical and under-tested failure mode in enterprise AI applications: context confusion. A user may be correctly authenticated and authorized, but the AI assistant may still answer using stale, over-broad, mixed, or unauthorized context. This can happen when users switch files mid-conversation, when retrieval pulls from a larger corpus than intended, when conversation history persists across data boundaries, or when the final answer combines allowed and disallowed information in a way that traditional access-control testing does not catch.

The session reframes AI data leakage as an AppSec testing problem rather than a model behavior problem. Attendees will learn how to test context boundaries across multi-turn conversations, file selection flows, retrieval systems, role changes, and generated responses. The talk will introduce a practical test matrix for identifying context bleed, authorization drift, stale retrieval, and response-level disclosure. It will also show how to capture useful evidence for engineering teams without turning the assessment into a vague “AI safety” review.

The goal is to give AppSec teams a concrete way to ask: did the application answer from the right context, for the right user, at the right time?
Speakers
avatar for Anusha Vajha

Anusha Vajha

Security Engineer and Product Manager
Anusha Vajha is a cybersecurity practitioner focused on AI governance, product security, and enterprise AI risk. She has worked across security operations, GRC, detection engineering, and product security in healthcare, financial services, and startup environments.
Her work sits a... Read More →
Friday November 6, 2026 11:30am - 12:15pm PST
Room: Seacliff AB (Bay Level)

1:15pm PST

LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
Friday November 6, 2026 1:15pm - 2:00pm PST
Models are starting to make security decisions that used to be written as rules. Instead of matching an input against a policy, a model reads the request and decides what to do with it. OpenSearch is one of the first to put one in production as the only thing standing between an anonymous pull request and CI pipeline secrets.

When I reported a vulnerability, the team told me their model would catch it. So I tried to get past it the way you'd expect, hiding the attack. The model caught all of it, and going at it head-on wasn't going to work.

So I stopped trying to outsmart it and started thinking like it, reading why each attempt got caught until I understood what it could actually verify and what it only assumed. What got through in the end hid no attack, because the only dangerous part lived somewhere the model had no way to check.

This talk walks the whole path, from first failed attempt to the bypass that worked. Along the way I mapped the model's decision boundary - what it catches, what slips past, and how far an input bends before its judgment flips. The deeper gap is what it never sees at all, the blind spots built into how it reads a change. You'll see where a model can be trusted to make this call and where it can't, and what that means before you put one in front of something that matters.
Speakers
avatar for Aviv Donenfeld

Aviv Donenfeld

Security Researcher, Check Point Software Technologies
Aviv Donenfeld is a Security Researcher at Check Point Software Technologies. Before security research, he built distributed networking systems as a software engineer. His recent research centers on the attack surfaces of AI coding assistants, including critical vulnerabilities in... Read More →
Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom A (Street Level)

1:15pm PST

So you think AI writes secure code?
Friday November 6, 2026 1:15pm - 2:00pm PST
Software development is becoming AI-assisted at every stage — design, coding, testing, bug fixing — and AI agents are increasingly doing it all. But do AI coding assistants actually write secure code by default? Most of the conversation around AI and security focuses on AI finding vulnerabilities. Far less attention goes to how state-of-the-art coding agents behave when they're the ones writing the software in the first place.

We built an automated harness to answer this directly — generating and evaluating over 2,500 code samples across multiple languages, models, and coding tasks, then scoring them with SAST tooling for introduced vulnerabilities. We tested vanilla generation against several security-steering approaches, from a single-line instruction file to a full set of layered security skills, to see which techniques move the needle, and at what cost.

In this talk, we'll walk through the harness architecture, share our full results — including where steering helped, where it hurt, and why — and lay out a practical framework for guiding coding agents toward secure defaults without paying an unsustainable token or performance tax. Attendees will walk away with a reusable methodology for evaluating their own AI coding assistants, and concrete, evidence-backed steering techniques they can apply immediately.

Key Takeaways
- A reusable methodology for benchmarking any coding assistant or model for security regressions before rolling it out to developers
- Evidence on which security-steering techniques actually reduce vulnerabilities, and by how much
- An understanding of the token-cost and latency tradeoffs of different steering approaches
- A practical framework for shifting security left into the AI-assisted SDLC
Speakers
SD

Shruti Datta Gupta

Product Security Engineer, Adobe
Shruti Datta Gupta is a Product Security Engineer at Adobe where she works in the Security AI & Data Engineering team. Her current role involves building AI-powered tools to automate security processes and reduce engineering toil. She is passionate about applying AI to solve cool... Read More →
avatar for Joseph Seasly

Joseph Seasly

Security AI & Data Engineer, Adobe

Joseph does Security AI and Data Engineering at Adobe. In his former life, he spent 13 years in the U.S. Intelligence Community working in a variety of agencies, technical roles, and missions.
    linkedin.com/in/josephs1000
... Read More →
Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom B (Street Level)

1:15pm PST

Why Developers Can and We Can't: Making Security Findings That Agents (and Humans) Can Act On
Friday November 6, 2026 1:15pm - 2:00pm PST
Coding agents went from novelty to daily driver in less than three years. Developers are now using AI to generate, test, and ship code as part of their normal workflow. But the way security communicates guidance has barely changed: findings buried in long documents, review comments that arrive after key decisions are already made, and requirements that are too vague for a developer to act on — let alone a coding agent.

The issue is not that developers do not care about security. It is that security intent often never reaches them in a form they can actually use.

So why did AI change the engineering workflow so quickly, while security reviews still look the same?

This talk looks at the structural reason behind that gap. Coding agents can only act on guidance that is specific, contextual, and executable. Most threat models and design review findings do not meet that bar. We will look at where review output breaks down in practice: findings that are technically true but not relevant, likelihood ratings that drift from reality, recommendations that are impossible to implement, and issues that no one knows how to translate into engineering work.

A human developer may be able to interpret a vague finding and make a judgment call. A coding agent will not. It will simply keep building without the missing security intent.

The second half of the talk focuses on what to do about it. We will present a practical framework for turning security review output into findings that are grounded in the real architecture, aware of existing controls, scoped to threats that actually apply, and written in a way that developers can act on.

Attendees will leave with a framework they can apply to their own design review or threat modeling process immediately, along with quality signals for measuring whether security findings are accurate, useful, and actually acted on.
Speakers
HM

Hai Maler

Head of Research, Clover Security
Hai Maler is Head of Research at Clover Security, where he drives research that brings advanced AI capabilities into practical product security workflows. He brings over 10 years of industry experience, from breaking systems and studying how they fail to building tools that help defenders... Read More →
Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Bayview B (Bay Level)

2:15pm PST

When Nobody Wrote the Code: Engineering Lessons from Building AI-Native Application Security
Friday November 6, 2026 2:15pm - 3:00pm PST
We didn't set out to rethink Application Security.

Our goal was much simpler: remove repetitive security work without reducing engineering confidence.

Like many security teams, we began introducing AI into parts of our AppSec workflow—reviewing pull requests, proposing remediation, assisting with threat modeling, validating findings, and helping developers move faster without sacrificing security.

Some things improved almost immediately.

Others became unexpectedly harder.

The first surprise wasn't model quality—it was review capacity. As AI started proposing fixes faster than engineers could reasonably validate them, we discovered that generating secure code was no longer the difficult part. Deciding whether that code could be trusted was.

We also found ourselves asking questions we hadn't expected. Why were experienced reviewers approving changes they couldn't realistically read? Why were different AI workflows confidently disagreeing with each other? Why were we spending less time finding vulnerabilities and more time deciding which results deserved human attention?

As these experiments accumulated, one theme kept reappearing. The biggest shift wasn't simply that AI generated more code—it reduced the cost of implementation while exposing new bottlenecks in review, verification, governance, and evidence. That, in turn, led us to question several engineering assumptions that quietly shape today's AppSec practices.

This session shares the implementation journey behind those discoveries. Through practical engineering experiments, implementation mistakes, and lessons learned, we'll explore how familiar AppSec practices—including secure coding, threat modeling, SAST, DAST, CI/CD security, and supply chain security—continue to matter while evolving for AI-assisted software engineering.

This isn't a talk about replacing today's AppSec practices.

It's about understanding which assumptions continue to hold, which ones deserve to be revisited, and how security teams can evolve their existing programs for a world where generating software is becoming easier while proving software is trustworthy is becoming the harder engineering problem.
Speakers
avatar for Manoj Kumar Yuvanesh

Manoj Kumar Yuvanesh

Senior Manager, Trust Data Platform, Autodesk Inc

Manoj Kumar Yuvanesh is a Senior Engineering Manager at Autodesk, where he leads the Trust Data Platform within the Trust Organization.

His work focuses on building large-scale data systems and security automation capabilities that help organizations understand and improve their security posture. With deep experience across security tooling, architecture, and cloud platforms, he drives initiatives that integrate security... Read More →
avatar for Uday Bhaskar Seelamantula

Uday Bhaskar Seelamantula

Principal Application Security Engineer, Autodesk

Uday is a principal security engineer at Autodesk, where he focuses on securing applications at the intersection of traditional software and emerging AI features. His work spans offensive research, fuzzing, threat modeling, building guardrails and integrating security into the SDLC... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom B (Street Level)

2:15pm PST

Post Quantum Crypto (PQC) - Field-Tested Strategies to Defeat Harvest Now, Decrypt Later
Friday November 6, 2026 2:15pm - 3:00pm PST
Q-Day, the moment a cryptographically relevant quantum computer (CRQC) breaks RSA, ECC, and Diffie-Hellman, has no confirmed date. But for any data with a long secrecy shelf life, it has effectively already happened: adversaries are harvesting encrypted traffic today to decrypt it later (HNDL). Meanwhile, governments have stopped waiting. The recent US Government Executive Order 14409 (June 2026) mandates post-quantum encryption for sensitive federal systems by the end of 2030, CNSA 2.0 requires quantum-safe software signing by 2030, and the EU, UK, Germany, and Australia have all converged on 2030-2035 deadlines. France's ANSSI will no longer certify products without quantum-safe encryption. The mandates exist. What most organizations lack is an executable engineering path.

This session presents a practitioner's migration playbook derived from hands-on work with enterprises beginning their post-quantum transitions. We separate the two halves of the problem that are routinely conflated: confidentiality, where hybrid key agreement (X25519MLKEM768) neutralizes harvest-now-decrypt-later immediately, and authentication and PKI, which is the harder, unfinished half that only matters once a CRQC exists. The session walks through where real migrations stall: hybrid handshakes that fragment across the MTU in QUIC, HSMs that cannot accelerate lattice math, the TLS 1.2 dead end, and the unresolved external mu debate in ML-DSA that risks cross-protocol divergence.

Attendees will leave with a combat-tested roadmap for enterprise PQC migration, a PQC maturity model with a concrete 90-day starting plan, a Cryptographic Bill of Materials (CBOM) template, a vendor briefing checklist, pilot project and a governance RACI model. We will cover how to conduct a cryptographic inventory (discovery), the necessity of "hybrid" key exchange (mixing X25519 with ML-KEM), testing for latency, key sizes, interoperability, and how security teams can upskill and execute rapidly.
Speakers
avatar for Anshu Gupta

Anshu Gupta

Founder, Fixin Security
Anshu Gupta is a seasoned global cybersecurity executive with Fortune 500 advisory experience at EY and KPMG, working with companies including Microsoft, Salesforce, Cisco, and Adobe. He has built and led security programs at high-growth startups and fintechs, including Coupa, HelloSign... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom C (Street Level)

2:15pm PST

The Hidden Risks of Service-to-Service Trust in Microservice Architectures
Friday November 6, 2026 2:15pm - 3:00pm PST
Modern applications increasingly rely on microservice architectures where APIs, backend services, and cloud workloads continuously communicate with one another. While organizations focus heavily on authenticating end users, service-to-service trust relationships are often implemented with excessive implicit trust, weak authorization boundaries, and inconsistent validation controls.

This talk explores how attackers abuse trust relationships between internal services to move laterally, escalate privileges, and access unintended resources inside distributed application environments. We will examine practical attack scenarios involving internal API trust, token forwarding, over-permissioned service identities, and insecure authorization assumptions between microservices.

Through architectural walkthroughs and demonstrations, attendees will learn how trust propagation inside distributed systems creates hidden attack paths that are difficult to detect using traditional security testing approaches.

The session also provides actionable guidance for securing service-to-service communication, including zero-trust design principles, token validation between services, least privilege for service identities, and authorization enforcement at every layer of the application.

Attendees will leave with practical strategies for reducing lateral movement and strengthening trust boundaries in cloud-native applications.
Speakers
avatar for Bhaumik Shah

Bhaumik Shah

CEO, SecurifyAI
Bhaumik Shah is a cybersecurity leader and founder of Securify, where he helps organizations secure their cloud, applications, and infrastructure through penetration testing, red team operations, and compliance programs like SOC 2 and ISO 27001. With over a decade of experience uncovering... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Seacliff AB (Bay Level)

3:30pm PST

Pre-Flight Security Review for MCP Servers Using the OWASP MCP Top 10
Friday November 6, 2026 3:30pm - 4:15pm PST
Since Anthropic released MCP as an open standard, enterprises have started adopting it as a common way to connect AI agents with tools, data sources, and business workflows. Many teams are now building MCP catalogs for internal developers, platform teams and external partners.

However, the security posture of these MCP servers is often not reviewed before they are added to a catalog or connected to an AI agent. In many cases, deeper security testing starts only after the MCP server is already in use.

Recent research has shown how a malicious or poorly reviewed MCP server can expose sensitive data, influence an agent’s behavior or override instructions given by the user. This makes MCP discovery an important early checkpoint for developer pre-flight checks, security approval, third-party MCP review, vendor or partner assessment and agent platform onboarding.

For traditional applications, software bills of materials (SBOMs) and configuration drift checks help teams understand what is being adopted and what has changed. MCP servers need a similar approach. In this talk, I will walk through a three-layer MCP BOM model: Discovery, Verified, and Runtime.

I will focus on the Discovery BOM and show how static MCP discovery can surface early indicators of tool poisoning, command injection and execution, context injection and over-sharing, credential-like inputs and risky tool capabilities. I will demonstrate this using an open-source tool that discovers MCP metadata and capabilities, runs static checks with YARA rules and maps findings to the OWASP MCP Top 10.

The goal is not just to scan an MCP server once, but to use discovery output as a pre-flight check: to review MCP servers before approval, detect MCP configuration and metadata changes in CI/CD, build safer MCP catalogs and create the first version of runtime monitoring and policy decisions.

Attendees will leave with a practical way to inspect MCP servers before agents use them, map exposed capabilities to OWASP MCP risks, compare MCP configuration drifts over time and answer a basic but important question during MCP security review: "What should be allowed, reviewed, or denied before the agent uses this MCP server?"
Speakers
avatar for Vinothini Raju

Vinothini Raju

Founder & CEO, gopaddle.io
Vinothini Raju, is the Founder & CEO at gopaddle.io. She has been awarded the B2B Woman Tech Entrepreneur of the Year, 2023 by Women In Cloud & Insight Enterprises. Under her leadership, gopaddle focuses on building a next-generation platform for cloud native applications​. Her... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom B (Street Level)

3:30pm PST

From Design Docs to Mitigations: Scaling Pre-Launch Security Review with Historical Decisions
Friday November 6, 2026 3:30pm - 4:15pm PST
Security review is getting squeezed from both sides. Product teams ship faster, GenAI has accelerated how quickly new features get built, and review teams are still expected to read each design doc from scratch and decide what can ship. That breaks down long before the roadmap slows down.

This talk shows an AI-assisted pre-launch review pattern built for that problem. The pipeline does not stop at generating a generic threat list or a dashboard for leadership. It starts with a structured risk taxonomy, mapped control expectations, and a corpus of historically reviewed launches. Given a PRD or design document for any new feature or application—not only GenAI products—it produces a reviewer-ready first pass: likely risks (from OWASP and internal), targeted follow-up questions, relevant control areas, and concrete mitigations grounded in both reviewer expertise and decisions that were approved in similar launches before. The same structure can support rollups for leadership, but the real value is at review time: better questions and earlier mitigations.

A key step is similarity-based retrieval over historical reviews. After the initial pass, the system looks for comparable launches and reuses the risks, control signals, and mitigation patterns that mattered in those cases. This helps recover issues that a single pass often misses and keeps the review grounded in how the organization actually makes launch decisions. Every completed review becomes another case in the corpus, so future reviews start from a richer set of approved precedents.

We will walk through the architecture, the feedback loop, and the places where this fails: thin design docs, stale taxonomies, misleading historical matches, and overconfident model output. We will also share results from a labeled benchmark of 19 PRDs and 205 human-reviewed risk labels. At a recall-oriented operating point, the pipeline reached 75% recall and 60% precision, and historical retrieval recovered 4–9 additional relevant threats per PRD on similar cases. Next steps including adding more data sources such as code repositories & live traffic.

The initial deployment focuses on fraud, but the pattern is being extended to other threat domains that matter in large product organizations, including abuse, privacy, and product security. This is not about replacing reviewers. It is about giving them leverage. Attendees will leave with a practical blueprint for turning blank-page review into a faster, more consistent workflow that surfaces mitigations before the design is already on its way to launch.
Speakers
avatar for Liat Ben Porat

Liat Ben Porat

Director, AI Science, Intuit
Liat Ben Porat leads the AI science organization within Intuit's global trust, fraud, and security group, where she drives the strategy, development, and adoption of AI solutions across security, fraud, compliance, and workforce teams. She also serves as her organization's lead for... Read More →
GS

Guy Shtar

AI Security & Safety Architect, Intuit

Guy Shtar is an AI Security & Safety Architect at Intuit, working on the intersection of GenAI, security, and Trust & Safety. His work focuses on turning subjective review workflows into measurable technical systems, including AI-assisted risk discovery, adversarial testing, and security... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom C (Street Level)

3:30pm PST

Breaking the Headcount Scaling Model: How GitLab's Product Security Teams Achieved Non-Linear Securi
Friday November 6, 2026 3:30pm - 4:15pm PST
Complete title that is cut by "Session Title" size limit: Breaking the Headcount Scaling Model: How GitLab's Product Security Teams Achieved Non-Linear Security Gains with AI

Engineering ships faster every quarter with AI assisted development, Security headcount grows slowly and the review backlog keeps growing at a rate you wish you didn’t know! This talk traces the struggles of building an AppSec function from scratch, through the scaling pain of supporting a fast-growing engineering organization, to the entirely new class of challenges created by the rise of AI-assisted software development.

And it starts with the pain. Building an AppSec function inside a fast-growing engineering org means years of playing catch-up: hiring into a market with a shortage of talent, onboarding people who take months to become productive and sitting at a security engineer-to-developer ratio of 1 to 2%(and 2& when you’re lucky!) that never meaningfully improves. Somewhere along the way, it can become the team that slows things down and that’s when engineering teams no longer want you onboarded and be part of their workflow.

Then AI changed the game much faster than anticipated and in ways we did not plan for: engineering velocity jumped, AI-generated code brought volumetric challenges at the “diff” level as well as at scale. And teams started building features on top of AI. This creates threat surfaces that weren’t present before and that threat actors have leveraged extensively since the beginning of the year. We are now fighting on two fronts: securing AI-powered features while keeping up with AI-accelerated development speed.

This talk covers how we responded with AI-powered (and non AI-powered) automations, and which hard decisions we had to take to enable those improvements to happen. We will explain the change in how we had to think about the solutions to match not only human expectations, but also work with AI-powered tools as well as the capacity cost of building these tools. We will also cover some of the challenges we faced (and are still facing) when we had to leverage AI solutions and how we think our team will evolve in the coming months.
Speakers
avatar for Vitor Meireles

Vitor Meireles

Senior Security Engineering Manager AppSec, GitLab

Vitor Meireles is a security professional with over 15 years of experience in the field. Currently serving as a Senior Security Engineering Manager at GitLab, he helps engineering teams build applications that are secure by design. Vitor has past experiences in the consulting, financial... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Bayview B (Bay Level)

3:30pm PST

Finding the Infrastructure Trust Layer: AI-Assisted Discovery of Cross-Product SSRF Classes
Friday November 6, 2026 3:30pm - 4:15pm PST
Standard SSRF mitigations are written around a specific threat model: an attacker reaching RFC 1918 space or link-local addresses through an application. Block 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, done. This model works for application-layer SSRF.

IaaS platforms have a second trust layer this model does not address. When a platform builds internal services - request routing, worker scheduling, data pipeline sinks - those services communicate over a network the application-layer blocklist does not see. CGNAT space (100.64.0.0/10) is one example: used for internal carrier routing and often present in IaaS backend networks, but it appears in neither RFC 1918 nor link-local blocklists.

I spent several months building an automated pipeline to probe IaaS attack surfaces, and the same root cause kept appearing across unrelated products from the same provider: different entry points, same internal network reachability, same CGNAT address class. Four products, one underlying issue.

The automation made the pattern visible. A human researcher testing one product at a time would likely miss the connection. The pipeline - scanner output fed to an LLM reasoning layer that classifies, clusters, and flags for human review - surfaces structural patterns that individual test results obscure.

This talk covers: the technical mechanics of CGNAT SSRF (probes, indicators, what a response tells you), how I built the LLM-assisted research pipeline, how to structure a consolidated disclosure when you find a vulnerability class instead of a single bug, and what to look for when testing your own IaaS-hosted services.

Research conducted via responsible disclosure. Will be fully public before November 2026.
Speakers
avatar for Ofri Ouzan

Ofri Ouzan

Security Researcher, JFrog Security
Ofri Ouzan is a security researcher at JFrog Security. With over 6 years of experience in the cybersecurity field, she specializes in conducting security research focusing on vulnerabilities and exploitation. Ofri excels at exploring new technologies and developing solutions to address... Read More →
avatar for Stav David

Stav David

Founder building automated offensive security tooling

Stav David is a security researcher and founder who builds automated offensive security infrastructure. He started by building multi-cloud DDoS attack simulation tooling - real bot fleets testing whether mitigation vendors actually block what they claim to block. The recon pipeline... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Seacliff AB (Bay Level)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.