Sched.com Conference Mobile Apps
OWASP Global AppSec USA 2026
OWASP Global AppSec USA 2026
Sign up
or
log in
to add sessions to your schedule and sync them to your phone or calendar.
About
Schedule
Know before you go!
Venue Map
Search
Menu
About
Schedule
Know before you go!
Venue Map
Search
Share your event
Share via
or Copy link
Copy
Event Schedule
My Schedule
0
View
Simple
Expanded
Grid
By Venue
View
Simple
Expanded
Grid
By Venue
Monday
, November 2
Room: Bay Level Foyer
8:15am •
Breakfast
8:15am •
Registration
10:30am •
AM Break
12:30pm •
Lunch
3:00pm •
PM Break
TBA
9:00am •
3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
9:00am •
3-Day Training: Building AI-based security tools & SDLC
9:00am •
3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
9:00am •
3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
Tuesday
, November 3
Room: Bay Level Foyer
8:15am •
Registration
10:30am •
AM Break
12:30pm •
Lunch
3:00pm •
PM Break
Room: Boardroom A (Lobby Level)
9:00am •
Private OWASP Board Meeting
TBA
8:15am •
Breakfast
9:00am •
3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
9:00am •
2-Day Training: Repeatable, Scalable and Valuable Code Security Scanning
9:00am •
2-Day Training: AI SecureOps: Attacking & Defending AI Applications & Agents
9:00am •
2-Day Training: Secure Coding That Sticks: From Bad Code to Secure Design
9:00am •
3-Day Training: Building AI-based security tools & SDLC
9:00am •
3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
9:00am •
3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
9:00am •
2-Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling
Wednesday
, November 4
Room: Bay Level Foyer
8:15am •
Breakfast
8:15am •
Registration
10:30am •
AM Break
12:30pm •
Lunch
3:00pm •
PM Break
Room: Waterfront E (Lobby Level)
5:00pm •
Global Board of Directors Public Board Meeting
TBA
9:00am •
1-Day Training: How to build a Successful Security Champions Program
9:00am •
3 Day Training: Hacking Android, iOS and IoT apps by Example - 2026 Edition
9:00am •
2-Day Training: Repeatable, Scalable and Valuable Code Security Scanning
9:00am •
2-Day Training: AI SecureOps: Attacking & Defending AI Applications & Agents
9:00am •
1-Day Training: OWASP AI Testing Guide (AITG): Enabling Trustworthy AI Through Structured Validation
9:00am •
2-Day Training: Secure Coding That Sticks: From Bad Code to Secure Design
9:00am •
3-Day Training: Building AI-based security tools & SDLC
9:00am •
OWASP SAMM and DSOMM User Day
9:00am •
1-Day Training: Secure Code with AI: Building a Trustworthy Spec-Driven AI Code Workflow
9:00am •
3-Day Training: Full-Stack Pentesting Laboratory: 100% Hands-On + Lifetime LAB Access
9:00am •
2-Day Training: 2-Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling
9:00am •
3-Day Training: Adam Shostack's Threat Modeling Intensive Using AI
Thursday
, November 5
Expo Hall, Pacific Concourse
8:15am •
Coffee/tea
8:15am •
Expo Hall
10:00am •
AM Break
11:15am •
Puppy Lounge (Sponsored by Depthfirst)
12:15pm •
Lunch
2:15pm •
Puppy Lounge (Sponsored by Depthfirst)
3:00pm •
PM Break
4:30pm •
OWASP Jeopardy & Networking Reception in Expo Hall
Pacific Concourse
8:00am •
Registration
Room: Bayview A
10:00am •
MiniCon: OWASP by Design
Room: Bayview B (Bay Level)
10:30am •
So your developers hate you... How to turn reluctant devs into AppSec champions
11:30am •
How Security Champions can keep AI-driven software safe
1:15pm •
Enterprise AppSec That Scales Itself
2:15pm •
The attacker does not sort by CVSS
3:30pm •
No value until it’s fixed: turning security reviews into a remediation loop
Room: Grand Ballroom A (Street Level)
9:00am •
Opening Remarks and Keynote, The End of Guessing: Security's Coming Market Correction
10:30am •
Beyond Provenance: Integrating Weight-Integrity Attestation Into Your AIBOM Pipeline
11:30am •
Exploits of Agency: Mapping out insecure development patterns across the agentic landscape
1:15pm •
Intent Contracts: Giving AI Agents the Missing Context for Safe Infrastructure Changes
2:15pm •
The Compromised Maintainer Problem: Detecting Malicious Code in Legitimate Dependencies
3:30pm •
Model Context Points of Failure: MCP Security Meets Scale
Room: Grand Ballroom B (Street Level)
10:30am •
The Human Approval Button Is Not a Security Boundary
11:30am •
Crypto Is Fine. The Code Is Not: OWASP A04 Cryptographic Failures Through Real-World CVEs
1:15pm •
Panel Discussion
2:15pm •
When the Robot Writes the Bug: A Merge Gate for AI-Generated Code
3:30pm •
Pattern, Graph, Prompt: What Happens When You Layer Three Analysis Paradigms on the Same Codebase
Room: Grand Ballroom C (Street Level)
10:30am •
When the Fraud Analyst Becomes an Agent: Threat Modeling Autonomy in High-Stakes AppSec Workflows
11:30am •
Cage the Confused Deputy: Infrastructure-Layer Defense for Voice AI Agents
1:15pm •
Controlling Decryption in Zero Trust Cloud Workloads
2:15pm •
Prompt Injection Through the Image Channel of Multimodal LLMs: An Ignored Attack Surface
3:30pm •
Assume Code Execution: Securing Multi-Tenant Code-Ingestion Platforms
Room: Grand Ballroom Foyer (Street Level)
8:30am •
Start Up Sponsors
8:45am •
OWASP Book and Merch Store
Room: Marina (Bay Level)
10:15am •
PODS (Hands-on Activities)
Room: Regency (Street Level)
10:15am •
Podcast Recording Room
3:15pm •
OWASP Leaders Meeting
Room: Seacliff AB (Bay Level)
10:30am •
Hacking Your Life with AI Can Get You Hacked: How AI Orchestration Platforms Ship RCE by Design
11:30am •
Beyond Detection: What We Learned Testing Every AI Approach to Vulnerability Classification
1:15pm •
Reproducing the exploit, not the report
2:15pm •
Download, Merge, Compromised: A Live Backdoored Coding Model From a Public Hub
3:30pm •
Same Bug, Bigger Blast Radius: Breaking AI Control Planes with Classic AppSec
Room: Waterfront Foyer (Street Level)
8:30am •
Conference T-Shirt Pick up and OWASP Member Swag
TBA
7:30am •
Women in AppSec Breakfast (Sign up required)
Friday
, November 6
Expo Hall, Pacific Concourse
8:15am •
Coffee/Tea
8:15am •
Expo Hall
10:00am •
AM Break
12:15pm •
Lunch
3:00pm •
PM Break
Foyer
8:15am •
Start Up Sponsors
Hyatt Regency, Lower Atrium
6:00pm •
ThreatModCon Night Networking Reception
Pacific Concourse
8:15am •
Registration
Room: Bayview A (Bay Level)
10:15am •
Meet the Mentor
1:15pm •
CfP/CfTs for the Newcomer: How To Write A Good Submission
Room: Bayview B (Bay Level)
10:30am •
From IC to Leader: A Field Guide to Building High-Performing Security Teams
11:30am •
Shadow AI is the new Shadow IT
1:15pm •
Why Developers Can and We Can't: Making Security Findings That Agents (and Humans) Can Act On
2:15pm •
From Consuming to Contributing: How We Built the Space That Was Missing
3:30pm •
Breaking the Headcount Scaling Model: How GitLab's Product Security Teams Achieved Non-Linear Securi
Room: Grand Ballroom A (Street Level)
9:00am •
Opening Remarks and Debate: Vulnerability auto-remediation breaks "you build it, you own it"
10:30am •
Poisoning the Pipeline: Runner Cache Manipulation and OIDC Token Forgery
11:30am •
Finding Pwn Requests in OSS: Auditing CI/CD Pipelines for Supply-Chain Vulnerabilities at Scale
1:15pm •
LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
2:15pm •
Open Source Sleeper Agents: Compromising Agents via Chat Templates
3:30pm •
RepoHunter: AI-Driven Discovery of CI/CD Supply Chain Vulnerabilities at Scale
4:30pm •
Closing Ceremony and Raffle
Room: Grand Ballroom B (Street Level)
10:30am •
Losing Context: Breaking & Binding MCP Sessions
11:30am •
The Hidden Effort Curve of Remediation: 15,000 Fixes, 500 Projects, 9 Languages
1:15pm •
So you think AI writes secure code?
2:15pm •
When Nobody Wrote the Code: Engineering Lessons from Building AI-Native Application Security
3:30pm •
Pre-Flight Security Review for MCP Servers Using the OWASP MCP Top 10
Room: Grand Ballroom C (Street Level)
10:30am •
CRA will be Cloud-Scale Engineering Change
11:30am •
Modelling for Agentic Failure; when attack trees meet safety engineering
1:15pm •
Panel Discussion
2:15pm •
Post Quantum Crypto (PQC) - Field-Tested Strategies to Defeat Harvest Now, Decrypt Later
3:30pm •
From Design Docs to Mitigations: Scaling Pre-Launch Security Review with Historical Decisions
Room: Grand Ballroom Foyer (Street Level)
8:45am •
OWASP Book and Merch Store
Room: Marina (Bay Level)
10:15am •
PODS (Hands-on Activities)
Room: Regency (Street Level)
10:00am •
Capture The Flag with ArmorCode
Room: Seacliff AB (Bay Level)
10:30am •
When Finding Bugs Is the Easy Part: Lessons from an Agentic Vulnerability Harness
11:30am •
Context Confusion Is the New Broken Access Control
1:15pm •
XSS is the new RCE: How we broke Tauri's security model
2:15pm •
The Hidden Risks of Service-to-Service Trust in Microservice Architectures
3:30pm •
Finding the Infrastructure Trust Layer: AI-Assisted Discovery of Cross-Product SSRF Classes
Room: Waterfront Foyer (Street Level)
8:30am •
Conference T-Shirt Pick up and OWASP Member Swag
Filter By Date
Nov 2
-
6, 2026
Monday
, November 2
Tuesday
, November 3
Wednesday
, November 4
Thursday
, November 5
Friday
, November 6
Filter By Venue
Hyatt Regency San Francisco, CA
All
Expo Hall, Pacific Concourse
Foyer
Hyatt Regency, Lower Atrium
Pacific Concourse
Room: Bay Level Foyer
Room: Bayview A
Room: Bayview A (Bay Level)
Room: Bayview B (Bay Level)
Room: Boardroom A (Lobby Level)
Room: Grand Ballroom A (Street Level)
Room: Grand Ballroom B (Street Level)
Room: Grand Ballroom C (Street Level)
Room: Grand Ballroom Foyer (Street Level)
Room: Marina (Bay Level)
Room: Regency (Street Level)
Room: Seacliff AB (Bay Level)
Room: Waterfront E (Lobby Level)
Room: Waterfront Foyer (Street Level)
TBA
Filter By Type
1-Day Training
2-Day Training
3-Day Training
Bonus Track
Capture the Flag
Deployment and Maintenance
Expo Hall
Implementation
Keynote
Meals Provided by OWASP
Meeting
MiniCon: OWASP by Design
Planning and Design
PODS (Hands-on Activities)
Process and Culture
Project User Day
Testing
Audience
Advanced
All
Beginner
Closed Session
Intermediate
Introductory and Overview
Popular
Share Modal
Share this link via
Or copy link
Copy
Filter sessions
Apply filters to sessions.
close
Dates
Monday
, November 2
Tuesday
, November 3
Wednesday
, November 4
Thursday
, November 5
Friday
, November 6
Session Type
1-Day Training
2-Day Training
3-Day Training
Bonus Track
Capture the Flag
Deployment and Maintenance
Expo Hall
Implementation
Keynote
Meals Provided by OWASP
Meeting
MiniCon: OWASP by Design
Planning and Design
PODS (Hands-on Activities)
Process and Culture
Project User Day
Testing
Other Filters
Audience
Advanced
All
Beginner
Closed Session
Intermediate
Introductory and Overview
Popular