Loading…
Venue: Room: Grand Ballroom A (Street Level) clear filter
Thursday, November 5
 

9:00am PST

Opening Remarks and Keynote, The End of Guessing: Security's Coming Market Correction
Thursday November 5, 2026 9:00am - 10:00am PST

Speakers
JG

Jeremiah Grossman

Co-Founder and CEO, Root Evidence
Jeremiah Grossman is a cybersecurity entrepreneur, investor, and Brazilian Jiu-Jitsu black belt with over 25 years of industry-defining impact. He began as one of Yahoo’s first information security officers before founding WhiteHat Security in 2001, which grew into the world’s... Read More →
Thursday November 5, 2026 9:00am - 10:00am PST
Room: Grand Ballroom A (Street Level)

10:30am PST

Beyond Provenance: Integrating Weight-Integrity Attestation Into Your AIBOM Pipeline
Thursday November 5, 2026 10:30am - 11:15am PST
Most AI supply-chain security tooling stops at provenance. A signed manifest proves the model came from the publisher who claims to ship it. OWASP CycloneDX AIBOM, OpenSSF Model Signing, and HuggingFace's signed model cards all answer that question. None of them answer the next one - what is actually inside the weights you signed.

The harder attack class lives in that gap. We built a working architectural-backdoor adapter of 136 kilobytes of new weights inserted between two transformer blocks of Cisco's Foundation-Sec-8B-Instruct and disclosed to Cisco PSIRT. Foundation-Sec ships across Splunk Enterprise Security AI Assistant and Cisco XDR, the model is in production SOC pipelines today. The adapter passes byte-for-byte hash comparison, fires only on a hidden trigger phrase, and is invisible to every provenance check currently deployed.

This session walks through a defensive workflow that closes the gap. Four steps AppSec teams can adopt this quarter:

1. Emit a CycloneDX 1.6 AIBOM with a structural-content hash field at model ingestion.
2. Bind the AIBOM to an OpenSSF Model Signing sigstore bundle so provenance and content ship together.
3. Scan weights at CI time with an integrity scanner, validated against the disclosed attack with zero-error insertion-layer recovery.
4. Hook model-load events in production so drift from the pinned baseline routes through the existing on-call channel.

Attendees leave with a reference architecture, a copy-paste CI configuration, the four-class payload taxonomy that determines what each control actually catches, and an honest defense-in-depth framing. The published adversarial stress-test shows where this workflow stops working. Layer it alongside provenance signing and behavioural monitoring, do not deploy it in place of them.
Speakers
BD

Bodhisattva Das

Security Researcher, RUDRA Cybersecurity
Bodhisattva Das is a Security Researcher at RUDRA Cybersecurity, and a graduate student at Carnegie Mellon University working on securing non-human identities, AI agents, and automated workloads across cloud environments. He specialises in open-source threat detection using Wazuh... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Grand Ballroom A (Street Level)

11:30am PST

Exploits of Agency: Mapping out insecure development patterns across the agentic landscape
Thursday November 5, 2026 11:30am - 12:15pm PST
At this point, agents are everywhere and they are pretty hard to ignore. They are showing up in our CI/CD life cycles, in code development, in code reviews, and in the day-to-day workflows that engineering teams are encouraged to adopt by both lower and upper management.

Their deep integration into the development life cycle raises a serious question: how do we actually deploy agentic systems safely when they are touching code, repositories, build systems, secrets, tickets, pull requests, and CI/CD workflows?

In this talk, I will explore the attack surfaces that agents open inside IDEs, coding agents, and CI/CD environments. I will walk through real bugs and exploit patterns found while researching agentic vulnerabilities across different products and environments over the last year.

You will leave being able to audit the agents in your own pipeline, with a clear read on which familiar controls quietly stop working the moment an agent, and not a person, is the one acting on untrusted input.
Speakers
avatar for Dan Lisichkin

Dan Lisichkin

AI Security Researcher, Pillar Security
Dan Lisichkin is the Cyber Security Researcher for Pillar Security, focusing on AI security, adversarial threats, and securing AI based systems. With over five years of experience in the cybersecurity and IT space, Dan has extensive knowledge in areas including malware analysis, reverse... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom A (Street Level)

1:15pm PST

Intent Contracts: Giving AI Agents the Missing Context for Safe Infrastructure Changes
Thursday November 5, 2026 1:15pm - 2:00pm PST

Speakers
avatar for Chris Wysopal

Chris Wysopal

Chief Security Evangelist & Co-founder, Veracode

Chris Wysopal is Veracode's Chief Security Evangelist and co-founder. He is one of the original vulnerability researchers and an early member of L0pht Heavy Industries, which he joined in 1992. He is the author of netcat for Windows and one of the authors of L0phtCrack. He has testified... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom A (Street Level)

2:15pm PST

The Compromised Maintainer Problem: Detecting Malicious Code in Legitimate Dependencies
Thursday November 5, 2026 2:15pm - 3:00pm PST
Supply chain attacks have changed. A few years ago the story was typosquatting and obviously sketchy packages with five downloads. Today it is the opposite. Attackers are going after the packages you already trust, the ones with millions of weekly installs and maintainers you have heard of. XZ Utils, the wave of npm maintainer account takeovers, self-replicating worms like Shai-Hulud, leaked PyPI tokens in public CI logs. The pattern is consistent and it is getting worse.

The hard part is that traditional tooling does not catch any of this. SCA scanners look for known CVEs, but there is no advisory yet. The package name is legitimate. The signature checks out. By the time the ecosystem catches up, the malicious version has already shipped to production for thousands of teams.

In this session we will share what we have learned building detection for these attacks across npm, PyPI, NuGet, and Go. We will walk through a few recent real incidents, the behavioral signals that gave them away (suspicious postinstall scripts, network callbacks, obfuscated payloads, anomalous maintainer activity), and why waiting for a CVE will always leave you exposed. From there we will get practical: pre install scanning, sandboxing build steps, lockfile pinning with provenance verification, and monitoring for dependency drift over time.

Attendees will leave with a clear mental model of how modern package attacks unfold, detection patterns they can apply to their own pipelines, and an honest read on where current tooling falls short. Aimed at AppSec engineers, platform teams, and developers who own anything in CI/CD or dependency policy.
Speakers
avatar for Polina Moshenets

Polina Moshenets

Security Engineer and Founder, SichGate
Polina Moshenets is a Security Engineer and Founder of SichGate, an AI model integrity testing company focused on safety and security evaluation of language models in highly regulated industries. Her background spans application security, supply chain risk in AI/ML pipelines, and... Read More →
avatar for Amro Haddadah

Amro Haddadah

Founder, CyberXYZ
Amro is the founder of CyberXYZ and a veteran of Microsoft’s DFIR team, where he spent five years investigating advanced cyber threats. He later led enterprise security as Principal Architect at Roche. Today, he’s building AI-native defenses to detect and stop zero-day attacks... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom A (Street Level)

3:30pm PST

Model Context Points of Failure: MCP Security Meets Scale
Thursday November 5, 2026 3:30pm - 4:15pm PST
MCP servers are an integral part of our AI agents, coding assistants and LLMs. But how secure are they? Can we trust publicly deployed MCP servers? What about the MCP infrastructure itself?

This talk on MCP security will walk through a full from top to bottom MCP analysis, starting from the MCP source code, MCP protocol exploits, prompt injection, vulnerable MCP servers, vulnerabilities in public MCP servers, and weaponizing MCP servers.

Our research combines an analysis of over 18,000 MCP servers served on public registries, 3,000 open-source AI projects. We’ll share how we were able to find exploits on both public deployments serving MCP connectors, and taking over abandoned MCP servers.

We’ll go in depth on how multiple classes of vulnerabilities and issues which endanger the MCP ecosystem, from local command execution, unauthenticated remote command execution, attacking AI orchestration systems, MCP server information stealing, and even data sovereignty breaches. We’ll include demos and POCs, demonstrating how we exploited each vulnerability class one by one.

Finally, we’ll go over how to tackle those issues inside a living breathing organization, working with best practices to secure MCP deployments and connectors, how we can practically collect and block MCP configurations in scale, and what organizations can do to prevent the next breach.
Speakers
avatar for Moshe Siman Tov Bustan

Moshe Siman Tov Bustan

Security Research Team Leader, OX Security
Moshe is a Security Research Team Leader at OX Security, a company specializing in software supply chain security, and has worked in the security industry for 13 years. His work spans cloud security research, container security, memory forensics, and an in-depth understanding of programming... Read More →
Thursday November 5, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom A (Street Level)
 
Friday, November 6
 

9:00am PST

Opening Remarks and Debate: Vulnerability auto-remediation breaks "you build it, you own it"
Friday November 6, 2026 9:00am - 10:00am PST
"You build it, you own it" pushed accountability for security into the hands of the teams who write the code. Auto-remediation tools now promise to close that loop faster than any human team can: scanning, patching, opening PRs, sometimes merging without a developer ever seeing the diff. The question this debate puts on the table is whether that promise quietly guts the principle it claims to serve.

This session pits experienced practitioners in both positions challenging each position directly, with a focus on where the line sits between assistive automation and abdicated accountability, and what AppSec teams should demand from vendors before treating "auto" as a synonym for "handled."

This new format aims to involve the audience in a spirited discussion around important industry topics.
Speakers
avatar for Jeff Williams

Jeff Williams

Founder & CTO, Contrast Security
Jeff Williams is the Founder and CTO of Contrast Security, where he is pioneering runtime application security and Application Detection & Response (ADR). For more than 25 years, Jeff has helped shape the field of application security—as a founder and former Global Chair of OWASP... Read More →
avatar for Dr. Katie Paxton-Fear

Dr. Katie Paxton-Fear

Lecturer and Educational YouTuber, Manchester Metropolitan University
Dr Katie Paxton-Fear is a lecturer of cyber security at Manchester Metropolitan University, she's a hacker and YouTuber, she's made 50+ videos on a range of topics, explaining vulnerabilities, tools etc, and made a splash as an API hackerSpeaker Agreement
    @InsiderPhD
 lin... Read More →
avatar for Petra Vukmirovic

Petra Vukmirovic

Head of Information Security and Fractional Head of Product, Numan and Devarmor
Petra is a technology enthusiast, leader and public speaker. A former emergency medicine doctor and competitive volleyball athlete, she thrives in challenging environments and loves creating order from chaos. Initially pursuing a medical career, Petra's passion for technology led... Read More →
Friday November 6, 2026 9:00am - 10:00am PST
Room: Grand Ballroom A (Street Level)

10:30am PST

Poisoning the Pipeline: Runner Cache Manipulation and OIDC Token Forgery
Friday November 6, 2026 10:30am - 11:15am PST
The modern application security boundary has shifted from the network edge directly into the software delivery pipeline. As organizations embrace cryptographic provenance and OpenID Connect (OIDC) identity federation to eliminate static cloud secrets, attackers have adapted. By exploiting weak isolation boundaries in shared CI/CD runner caches, threat actors can now extract OIDC tokens from execution memory, compromise cloud environments, and inject malicious code that carries valid supply-chain provenance signatures.

In this session, we will break down the mechanics of an advanced post-exploitation pipeline attack. We will move past generic supply-chain advice to look at how ephemeral runner states can be weaponized against cloud infrastructures. Attendees will walk away with an architectural blueprint for securing federated identities in CI/CD and an open-source audit script to evaluate their own pipeline runner configuration risks.
Speakers
avatar for Sneha Rangari

Sneha Rangari

Security Architect, Visa
I am a Cybersecurity Professional with over 7 years of experience in Security Engineering, Security Architecture, Gen AI/ML in security, Third party Vendor applications, Cloud applications and Technology Risk Management. I am CISSP and GMLE certified and currently working with Vi... Read More →
Friday November 6, 2026 10:30am - 11:15am PST
Room: Grand Ballroom A (Street Level)

11:30am PST

Finding Pwn Requests in OSS: Auditing CI/CD Pipelines for Supply-Chain Vulnerabilities at Scale
Friday November 6, 2026 11:30am - 12:15pm PST
CI/CD pipelines are one of the highest-leverage attack surfaces in the application supply chain. A single misconfigured GitHub Actions workflow can hand repository secrets and write tokens to any external contributor who opens a pull request.

This talk presents a methodology for finding these weaknesses at scale across open-source organizations. It covers four vulnerability classes: unpinned third-party actions (the CVE-2025-30066 pattern), pwn-request code execution via pull_request_target, excessive GITHUB_TOKEN scope, and expression injection into shell steps.

Two open-source scanners implement the methodology. One audits SHA-pinning across a GitHub org. The other does mitigation-aware triage: it detects when hardening like persist-credentials: false or insider-only gating neutralizes a finding, so output stays actionable rather than noisy.

The talk walks through real disclosed findings, including a CRITICAL-severity pwn request where a pull_request_target workflow executed attacker-controlled build scripts with secrets in scope. Attendees leave with two working scanners, a triage framework for separating real findings from false positives, and concrete fix patterns they can apply to their own organizations.

Validation at scale: the methodology behind this talk has produced over 320 merged security fixes across 75 open-source organizations (apache, google, kubernetes-sigs, containerd, prometheus, vuejs, eslint, mongodb, ruby, redis, OWASP, NASA, NIST), plus five private vulnerability disclosures including a CRITICAL-severity pwn request. Each merged PR represents an independent maintainer reviewing and accepting a scanner-identified fix.
Speakers
avatar for Arpit Jain

Arpit Jain

Security Researcher, Independent

Friday November 6, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom A (Street Level)

1:15pm PST

LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
Friday November 6, 2026 1:15pm - 2:00pm PST
Models are starting to make security decisions that used to be written as rules. Instead of matching an input against a policy, a model reads the request and decides what to do with it. OpenSearch is one of the first to put one in production as the only thing standing between an anonymous pull request and CI pipeline secrets.

When I reported a vulnerability, the team told me their model would catch it. So I tried to get past it the way you'd expect, hiding the attack. The model caught all of it, and going at it head-on wasn't going to work.

So I stopped trying to outsmart it and started thinking like it, reading why each attempt got caught until I understood what it could actually verify and what it only assumed. What got through in the end hid no attack, because the only dangerous part lived somewhere the model had no way to check.

This talk walks the whole path, from first failed attempt to the bypass that worked. Along the way I mapped the model's decision boundary - what it catches, what slips past, and how far an input bends before its judgment flips. The deeper gap is what it never sees at all, the blind spots built into how it reads a change. You'll see where a model can be trusted to make this call and where it can't, and what that means before you put one in front of something that matters.
Speakers
avatar for Aviv Donenfeld

Aviv Donenfeld

Security Researcher, Check Point Software Technologies
Aviv Donenfeld is a Security Researcher at Check Point Software Technologies. Before security research, he built distributed networking systems as a software engineer. His recent research centers on the attack surfaces of AI coding assistants, including critical vulnerabilities in... Read More →
Friday November 6, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom A (Street Level)

2:15pm PST

Open Source Sleeper Agents: Compromising Agents via Chat Templates
Friday November 6, 2026 2:15pm - 3:00pm PST
Most open-weight models are based on the GGUF standard distributed on a public hubs like HuggingFace ship with a chat template: a small Jinja2 program that runs on every inference call and formats the prompt before the model processes it. It is executable code, it sits between the user's input and the model, and in practice almost no one inspects it. We show that an attacker can plant a conditional backdoor by adding a few lines to a model's chat template. A backdoor this persistent would normally require poisoning the training data or editing the weights. The template version requires neither, and no foothold in the victim's systems: redistributing one modified file is enough. The model answers normally until a chosen trigger phrase appears in a request, at which point the template injects attacker instructions into the model's system context.

We give particular attention to how the model hub, Hugging Face, itself launders trust: the copied model card and the metadata viewer reassure the user, and a clean result from automated scanning (JFrog, ClamAV, etc.) does the same, while the template that actually executes is the one component none of them checks. The attack also reaches agentic deployments, where it becomes a working software supply chain compromise rather than output manipulation alone. Using opencode as the victim, we show a poisoned template directing a coding agent to install an adversary-controlled package while completing an ordinary task. Because the agent runs with the developer's privileges, that first action can cascade: the installed package can reach the developer's credentials and the code the developer themselves publishes, carrying the compromise to people downstream who never touched the original model. We close by showing the same template position used defensively, which points to where a durable fix belongs.

We release an open-source scanner that extracts a model's chat template and runs heuristics together with a shipped offline classifier we trained on a hub-scale corpus of templates, to flag the business-logic patterns this attack relies on. We have also proposed that chat templates become a first-class, signable component in the CycloneDX model SBOM standard. Attendees will leave able to extract and read the chat template from any GGUF file they download, recognize the patterns that indicate tampering, run the scanner against their own models at intake, and explain why the missing control is provenance for the template itself: a signature and hash that travel with it.
Speakers
avatar for Ariel Fogel

Ariel Fogel

AI Security Researcher, Pillar Security
Ariel Fogel is a founding engineer & researcher at Pillar Security, where he hardens AI applications against real-world attacks and compliance risks. Over the past decade, he has built production systems in Ruby, TypeScript, Python, and SQL, shipping everything from full-stack web... Read More →
avatar for Omer Hofman

Omer Hofman

Principal Researcher, Fujitsu Research of Europe
 Omer Hofman is a Principal AI Security Researcher focused on evaluating and securing large language model systems in real-world deployments. His work centers on LLM red teaming, vulnerability scanning, guardrail design, and policy compliance in agentic AI systems. He leads research... Read More →
Friday November 6, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom A (Street Level)

3:30pm PST

RepoHunter: AI-Driven Discovery of CI/CD Supply Chain Vulnerabilities at Scale
Friday November 6, 2026 3:30pm - 4:15pm PST
Recent attacks such as S1ngularity, Shai-Hulud, and the Trivy GitHub Actions compromise have shown that CI/CD pipelines are among the most attractive attack surfaces in modern software development. A single workflow misconfiguration can lead to remote code execution, credential theft, repository takeover, and software supply chain compromise.

This session introduces RepoHunter, an AI-driven research bot that combines static analysis with LLM reasoning to discover exploitable CI/CD workflows at scale. Built in just 48 hours, RepoHunter models real attack paths, prioritizes repositories by supply chain impact, and helps uncover vulnerabilities that traditional approaches often miss.

Using this methodology, I identified and responsibly disclosed more than 30 critical vulnerabilities across major open-source and enterprise projects, including repositories maintained by Microsoft, Red Hat, SAP, Ansible, Eclipse, Ceph, and QGIS. The research identified attack patterns—including CI/CD propagation and supply chain worm-like behavior—before they appeared in major real-world incidents. Later attacks, including the Trivy compromise, demonstrated these same techniques in practice.

Attendees will learn how these attacks work, why AI is changing vulnerability research, and how to combine static analysis with AI reasoning to find and prevent the next generation of CI/CD supply chain attacks.
Speakers
avatar for Barak Haryati

Barak Haryati

Senior Director of Product Security, JFrog
Barak Haryati is Senior Director of Product Security at JFrog, focused on CI/CD security, AI/LLM systems, and software supply chain risk. His research explores how attacker-controlled input flows through build systems and is executed in privileged environments.

He developed RepoHunter, an AI-driven research agent that discovers, prioritizes, and models real exploitation paths across CI/CD workflows at scale. Using this approach, he identified and responsibly disclosed 30+ critical vulnerabilities across widely used open source and enterprise... Read More →
Friday November 6, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom A (Street Level)

4:30pm PST

Closing Ceremony and Raffle
Friday November 6, 2026 4:30pm - 5:30pm PST
Come wrap up the conference with us, hear special annoucements, and win prizes!
Friday November 6, 2026 4:30pm - 5:30pm PST
Room: Grand Ballroom A (Street Level)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.