| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 10:00 - 17:59 |
MOUSE Runner & Flappy Drone
|
|
| 10:00 - 17:59 |
Mission: Compromised - Hacking a Satellite from th . . .
|
|
| 10:00 - 17:59 |
Nebula Showdown: Space Systems Security CTF Advent . . .
|
|
| 10:00 - 17:59 |
SR-71 Blackbird Badge Challenge
|
|
| 10:00 - 17:59 |
Satellites Under Attack: Hands-On Satellite Securi . . .
|
|
| 10:00 - 17:59 |
SpaceCOP - Catch Me If You Can
|
|
| 10:00 - 17:59 |
Flight Simulator/EFB
|
|
| 10:00 - 17:59 |
Drone Hacking Workshop
|
|
| 10:00 - 17:59 |
Drone Hacking Choose your Own Adventure
|
|
| 10:00 - 17:59 |
DCNextGen - Space Grand Challenge - SatHack: The M . . .
|
|
| 10:00 - 17:59 |
DCNextGen - RIC-1: ELT Localization Exercise - N3V . . .
|
|
| 10:00 - 17:59 |
DCNextGen - Bricks in the Air
|
|
| 10:00 - 17:59 |
Bricks in the Air
|
|
| 10:00 - 17:59 |
Aviation ISAC Cybersecurity Challenge
|
|
| 10:00 - 17:59 |
Aerospace Ecosystem Resilience Innovation Environm . . .
|
|
| 10:00 - 17:59 |
ARINC 664 CTF Challenge
|
|
| 10:00 - 10:30 |
Hacking Electronic Conspicuity Devices -or- Making . . .
|
Ken Munroe |
| 12:45 - 13:30 |
Aerospace Cybersecurity Student Research Spotlight . . .
|
Clara Davis,Dylan Gururaj . . . |
| 12:00 - 12:45 |
Aerospace Cybersecurity Student Research Spotlight . . .
|
Sean McConoughey,Samuil N . . . |
| 13:30 - 13:59 |
Hacking Airplanes at the NTSB
|
David Case,Jonathan Xue |
| 15:00 - 15:30 |
Drones, Detectors, and the Kill Chain
|
Greg Albrecht |
| 15:30 - 15:59 |
Cleared for Takeoff: Debunking “Uncertifiable” . . .
|
Katie Fejer |
| | |
| Saturday |
|
|
| 10:00 - 17:59 |
ARINC 664 CTF Challenge
|
|
| 10:00 - 17:59 |
Flight Simulator/EFB
|
|
| 10:00 - 17:59 |
Drone Hacking Workshop
|
|
| 10:00 - 17:59 |
Drone Hacking Choose your Own Adventure
|
|
| 10:00 - 17:59 |
DCNextGen - Space Grand Challenge - SatHack: The M . . .
|
|
| 10:00 - 17:59 |
DCNextGen - RIC-1: ELT Localization Exercise - N3V . . .
|
|
| 10:00 - 17:59 |
DCNextGen - Bricks in the Air
|
|
| 10:00 - 17:59 |
Bricks in the Air
|
|
| 10:00 - 17:59 |
Aviation ISAC Cybersecurity Challenge
|
|
| 10:00 - 17:59 |
Aerospace Ecosystem Resilience Innovation Environm . . .
|
|
| 10:00 - 17:59 |
Mission: Compromised - Hacking a Satellite from th . . .
|
|
| 10:00 - 17:59 |
Nebula Showdown: Space Systems Security CTF Advent . . .
|
|
| 10:00 - 17:59 |
SR-71 Blackbird Badge Challenge
|
|
| 10:00 - 17:59 |
Satellites Under Attack: Hands-On Satellite Securi . . .
|
|
| 10:00 - 17:59 |
SpaceCOP - Catch Me If You Can
|
|
| 10:00 - 17:59 |
MOUSE Runner & Flappy Drone
|
|
| 11:30 - 11:59 |
So You Want to Work in Aircraft Cyber? Here's what . . .
|
Matt Gaffney,Marcie Wise |
| 11:00 - 11:30 |
Security Analysis of Open-Source Software Used in . . .
|
Roee Idan |
| 14:00 - 14:30 |
Racing PX4: Memory Safety and Timing Vulnerabiliti . . .
|
Nefeli Georgilas |
| 14:30 - 14:59 |
Hacking AFDX or Not; A Primer for Flight Control S . . .
|
Andrew Tierney,Adam Bromi . . . |
| 17:00 - 17:30 |
Behind the Badge: SAOv3 and Open Sourcing the Aero . . .
|
Adam Batori,Kevin Colley, . . . |
| 17:30 - 17:59 |
SpaceCOP: Houston, We Have an Intrusion
|
Brandon Bailey |
| | |
| Sunday |
|
|
| 10:00 - 13:59 |
Mission: Compromised - Hacking a Satellite from th . . .
|
|
| 10:00 - 13:59 |
Nebula Showdown: Space Systems Security CTF Advent . . .
|
|
| 10:00 - 13:59 |
SR-71 Blackbird Badge Challenge
|
|
| 10:00 - 13:59 |
Satellites Under Attack: Hands-On Satellite Securi . . .
|
|
| 10:00 - 13:59 |
SpaceCOP - Catch Me If You Can
|
|
| 10:00 - 13:59 |
MOUSE Runner & Flappy Drone
|
|
| 10:00 - 13:59 |
Flight Simulator/EFB
|
|
| 10:00 - 13:59 |
Drone Hacking Workshop
|
|
| 10:00 - 13:59 |
Drone Hacking Choose your Own Adventure
|
|
| 10:00 - 13:59 |
DCNextGen - Space Grand Challenge - SatHack: The M . . .
|
|
| 10:00 - 13:59 |
DCNextGen - RIC-1: ELT Localization Exercise - N3V . . .
|
|
| 10:00 - 13:59 |
ARINC 664 CTF Challenge
|
|
| 10:00 - 13:59 |
DCNextGen - Bricks in the Air
|
|
| 10:00 - 13:59 |
Aerospace Ecosystem Resilience Innovation Environm . . .
|
|
| 10:00 - 13:59 |
Bricks in the Air
|
|
| 10:00 - 13:59 |
Aviation ISAC Cybersecurity Challenge
|
|
| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 10:15 - 11:15 |
Pentesting made easy - Keeping sessions alive with . . .
|
Kai Glauber,Matthias Göh . . . |
| 10:30 - 12:30 |
Burp, But Yours: Hands-On Extension and Bambda Dev . . .
|
Hannah L |
| 10:30 - 10:59 |
The Dots Do Matter: Gmail's Invisible Blindspot
|
Keren Elazari |
| 11:30 - 12:30 |
Aegis of the Vulnerable: A Unified Pipeline for AI . . .
|
Can Oztas |
| 11:10 - 11:40 |
Pickled and Exposed: RCE in AI Serving Frameworks
|
Iggy |
| 11:50 - 12:20 |
A Billion-User Blast Radius: Owning ChatGPT's Secu . . .
|
Simcha Kosman |
| 11:00 - 12:59 |
Cards Against Vulnerabilities
|
Patrick Smyth |
| 11:00 - 12:59 |
The Call Stack Experience
|
Victoria Keeler |
| 11:00 - 12:59 |
Clash of Prompts: The World's First Prompt Battle . . .
|
|
| 11:00 - 12:59 |
Hack the Duck Store
|
Gwendal Mognier,Samantha . . . |
| 12:45 - 13:45 |
Drogonsec: SAST + SCA + Secrets + IaC in one open- . . .
|
Filipi Pires |
| 12:30 - 12:59 |
Container Escapes Are Not Magic. Here Is How They . . .
|
Advait Patel |
| 13:30 - 13:59 |
Agentic Chaos - What 86K+ Agent Codebases Reveal A . . .
|
Bar Kaduri,Lidan |
| 13:00 - 14:59 |
Cards Against Vulnerabilities
|
Patrick Smyth |
| 13:00 - 14:59 |
AI Pentesting Trivia Showdown
|
Andy Dennis,Bill Reyor |
| 13:00 - 14:59 |
Factory Floor MVP Incident Response Challenge
|
|
| 13:00 - 14:59 |
AppSec Quiz Gauntlet: Spot the Vulnerability
|
Avek Kolech |
| 14:00 - 14:59 |
Farsight: Turning OSINT into Actionable Attack Sur . . .
|
Arif,Sai Vernekar,Seedon . . . |
| 14:30 - 16:59 |
Container Escapes 101
|
some-natalie |
| 14:50 - 15:20 |
GeoHacking: from memory corruption RCE to cross te . . .
|
Michal Kamensky |
| 14:10 - 14:40 |
from_pretrained() to from_pwned(): Breaking Huggin . . .
|
Yotam Perkal |
| 15:15 - 16:15 |
IDEViewer - Securing Developer Workstations from I . . .
|
securient |
| 15:30 - 15:59 |
Zero Trust Kubernetes Security: Preventing Real Wo . . .
|
Janakiram Meka |
| 15:00 - 16:59 |
Cards Against Vulnerabilities
|
Patrick Smyth |
| 15:00 - 16:59 |
AI Pentesting Trivia Showdown
|
Andy Dennis,Bill Reyor |
| 15:00 - 16:59 |
SBOM Find the Flaws
|
Dmitry Raidman |
| 15:00 - 16:59 |
NPM Imposters - The malware detection card game
|
Mackenzie |
| 16:30 - 17:30 |
Rebuilding Code Security with Signal, Speed and AI
|
Derek C.,Shasheen Bandodk . . . |
| 16:50 - 17:20 |
Most threat modeling artifacts don't help coding a . . .
|
Meitar Ronen |
| 16:10 - 16:40 |
Man-in-the-Browser: Hijacking Javascript APIs for . . .
|
Aarav Juneja |
| 17:30 - 17:59 |
Trust No History: Why Every "Remembered" Interacti . . .
|
Barno Kaharova,Rico Komen . . . |
| | |
| Saturday |
|
|
| 10:15 - 11:15 |
In Untrust We Can Trust: Enforcing Trust Boundarie . . .
|
Yariv Tal |
| 10:15 - 12:59 |
Prompt Injection: Attacking and Defending AI-Power . . .
|
Mohammed Ilyas Ahmed |
| 10:30 - 10:59 |
Building Hackbots
|
Jason "jhaddix" Haddix |
| 11:30 - 12:30 |
Precogly: Open-Source Threat Modeling for the AI-C . . .
|
Vikramaditya Narayan |
| 11:50 - 12:20 |
Past the Bouncer: The Limits of CSP, Eleven Years . . .
|
Pedro Fortuna |
| 11:10 - 11:40 |
What Your Coding Agent Did Last Night: Runtime Sec . . .
|
Inga Cherny |
| 11:00 - 12:59 |
Code Invaders: Stop The Insecure Code
|
Mackenzie |
| 11:00 - 12:59 |
Pentester vs AI: Race The Machine, In Real Life
|
Gwendal Mognier,Samantha . . . |
| 11:00 - 12:59 |
Cards Against Vulnerabilities
|
Patrick Smyth |
| 11:00 - 12:59 |
SBOM Find the Flaws
|
Dmitry Raidman |
| 12:45 - 13:45 |
OWASP FinBot CTF: Hands-On Agentic AI Threats
|
Helen Oakley,saikishu |
| 12:30 - 12:59 |
Threat Modeling LLMs with PHANTOM-B
|
Adam Shostack |
| 13:15 - 15:59 |
Supply Chain Isn’t Just Dependencies Anymore: De . . .
|
Tanya "SheHacksPurple" Ja . . . |
| 13:30 - 13:59 |
How Shadow APIs Become an Attacker's Free Pass Int . . .
|
Emma Yuan Fang,Krity |
| 13:00 - 14:59 |
Code Invaders: Stop The Insecure Code
|
Mackenzie |
| 13:00 - 14:59 |
AppSec Quiz Gauntlet: Spot the Vulnerability
|
Avek Kolech |
| 13:00 - 14:59 |
AI Pentesting Trivia Showdown
|
Andy Dennis,Bill Reyor |
| 13:00 - 14:59 |
Factory Floor MVP Incident Response Challenge
|
|
| 14:00 - 14:59 |
OWASP AIBOM Generator
|
Dmitry Raidman,Helen Oakl . . . |
| 14:50 - 15:20 |
Pattern, Graph, Prompt: What Happens When You Laye . . .
|
Mudita Khurana |
| 14:10 - 14:40 |
Every ride you take - Hacking a City’s Public Tr . . .
|
Ignacio Navarro |
| 15:15 - 16:15 |
Proactive Malicious Package Defense
|
Darren Meyer |
| 15:30 - 15:59 |
How Malicious AI Skills Hijack Your Agents
|
Jenn Gile |
| 15:00 - 16:59 |
SBOM Find the Flaws
|
Dmitry Raidman |
| 15:00 - 16:59 |
AppSec Quiz Gauntlet: Spot the Vulnerability
|
Avek Kolech |
| 15:00 - 16:59 |
AI Pentesting Trivia Showdown
|
Andy Dennis,William Reyor |
| 15:00 - 16:59 |
The Call Stack Experience
|
Victoria Keeler |
| 16:30 - 17:30 |
Your SaaS Is My Foothold: Weaponizing Shadow SaaS . . .
|
Jordan Bonagura |
| 16:15 - 17:59 |
Code to Cloud: Secure Modern Applications Using Op . . .
|
Mackenzie |
| 16:10 - 16:40 |
The API Made Me Do It - Do Bad APIs Lead AI to Gen . . .
|
Yariv Tal |
| 16:50 - 17:20 |
No Jailbreak Required: Pwning AI Agents Through th . . .
|
Helen Oakley,saikishu |
| 17:30 - 17:59 |
From Prompts to Production: Discovering Exposed PI . . .
|
Samantha Pearlstein |
| | |
| Sunday |
|
|
| 10:15 - 11:15 |
ROP for the Web: Smuggling XSS, SQLi, and Web Shel . . .
|
alevsk |
| 10:15 - 12:59 |
Introduction to AI-Enhanced Threat Modeling Worksh . . .
|
Robert Hurlbut |
| 10:30 - 10:59 |
From commit to compromise: securing the full pipel . . .
|
Filipi Pires |
| 11:30 - 12:30 |
search_vulns: Navigating the Fragmented Landscape . . .
|
Dustin Born,Matthias Göh . . . |
| 11:10 - 11:40 |
Extending Shared Threat Models with the Applicatio . . .
|
J Fridley |
| 11:50 - 12:20 |
Finding Bugs Is Easy, Patching Isn't: Build Your O . . .
|
Mohan Kumar,Naveen |
| 11:00 - 12:59 |
Clash of Prompts: The World's First Prompt Battle . . .
|
Darren McNelis,Jerome Rob . . . |
| 11:00 - 12:59 |
AppSec Quiz Gauntlet: Spot the Vulnerability
|
Avek Kolech |
| 11:00 - 12:59 |
SBOM Find the Flaws
|
Dmitry Raidman |
| 11:00 - 12:59 |
NPM Imposters - The malware detection card game
|
Mackenzie |
| 12:45 - 13:45 |
The Agent Asked. We Allowed. Now What?
|
Liran Lavi,Sarit Yerushal . . . |
| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 10:00 - 10:59 |
The Future of Bug Bounty - Program Manager Perspec . . .
|
Jai Kumar Sharma,Catherin . . . |
| 10:00 - 10:30 |
Click Me: Turning URI Links into Bug Bounty RCE's
|
Tobias Diehl |
| 10:30 - 11:30 |
Hacking IDE Extensions - VSCode Workshop
|
Nick "7urb01" Copi |
| 11:30 - 11:59 |
Make Money Hacking AI
|
Joey Melo,Edward Morris |
| 11:00 - 11:30 |
The Ripple Effect: Inside Cloud-Scale Vulnerabilit . . .
|
Albin Vattakattu,Ryan Nol . . . |
| 11:30 - 12:30 |
Hackbots
|
Jason "jhaddix" Haddix,Ry . . . |
| 12:00 - 12:30 |
Write Once, Shell Everywhere: Turning Arbitrary Fi . . .
|
Bruno Mendes,Rafael Casti . . . |
| 12:30 - 12:59 |
Beyond Theoretical Risk: How Cache Poisoning Escal . . .
|
Glendon Chong |
| 12:30 - 13:30 |
AI Hacking Workshop: Bug Bounty Edition
|
Ben "NahamSec" Sadeghipou . . . |
| 14:00 - 14:30 |
AI Nightmare: Hacking at 0-Hour
|
Pedro "drop" Paniago |
| 14:00 - 14:59 |
Navigating AI-Assisted Submissions
|
Tony Lee,Michael Skelton, . . . |
| 15:30 - 15:59 |
Hunting for Cryptographic Ghosts: A Bug Hunter’s . . .
|
Samet Berk Simsek,Ahmet F . . . |
| 15:00 - 15:30 |
Cache Key Injection: Smuggling Poison Through the . . .
|
Alex Brumen |
| 15:00 - 15:59 |
a [REDACTED] history of this hobby
|
Chris "flyingtoasters" Ho . . . |
| 16:00 - 16:59 |
Hacking Human-in-the-Loop systems
|
Inti "securinti" De Ceuke . . . |
| 17:00 - 17:59 |
Beyond Normalization: The Expanding Unicode Attack . . .
|
Ryan "ryancbarnett" Barne . . . |
| | |
| Saturday |
|
|
| 10:00 - 10:30 |
Shadow Webhooks: Hunting for Dangling Event Listen . . .
|
Samet Can Tasci,Mehmet Ö . . . |
| 10:30 - 10:59 |
Testing API Business Logic With AI Agents: What We . . .
|
Samantha Pearlstein |
| 10:00 - 10:45 |
Turning Recon Coverage into Bug Bounty Signal
|
Radu Stefan Voloaga |
| 10:45 - 11:30 |
You’re Invited to Get Hacked: Real-World Exploit . . .
|
Ali "logic-breaker" Kabee . . . |
| 11:30 - 12:30 |
De-Sloppify: Your AI Needs a Proxy
|
Emile "TheSytten" Fugulin . . . |
| 12:00 - 12:30 |
Killing AI Slop: A Multi-Model Orchestration Frame . . .
|
Armaan Pathan |
| 12:30 - 12:59 |
Eating Our Own Dogfood: Running a Bug Bounty Progr . . .
|
Shrimant Subhash More,Mar . . . |
| 12:30 - 13:30 |
Better Bug Hunting on AI Products: A VRP Lead’s . . .
|
John Kotheimer |
| 14:00 - 14:30 |
Exfil Everything: A Year of Stealing Data from AI . . .
|
Ads Dawson,Mike "TakSec" . . . |
| 14:30 - 15:59 |
Bots, Bounties, and Bullshit: An Honest Panel on A . . .
|
Ben "NahamSec" Sadeghipou . . . |
| 16:00 - 17:59 |
Burp, But Yours: Hands-On Extension and Bambda Dev . . .
|
Hannah L |
| | |
| Sunday |
|
|
| 10:30 - 10:59 |
Slop Spotting, Using Rules to Detect AI Slop for B . . .
|
Katie Paxton-Fear,Max vo . . . |
| 10:00 - 10:30 |
Skill Issue: A Recon Story
|
Ryan Bonner |
| 10:00 - 10:30 |
AI Cuts Both Ways: Using AI to Find More Bugs, and . . .
|
Ciarán "monke" Cotter |
| 11:30 - 11:59 |
Automated Discovery of Prompt Injection Vulnerabil . . .
|
Bogdan Stelee,Arnav Garg |
| 11:00 - 11:30 |
Full Disclosure, Full Screen: [Informative] The St . . .
|
Abhinav "TweetsFromPanda" . . . |
| 11:30 - 11:59 |
Heavy Metal and Hidden Secrets: A Five-Year Retros . . .
|
Ariel "arl_rose" Garcia |
| 12:00 - 12:59 |
How We Built Xenoptic: A Walkthrough of Design, In . . .
|
Adham Elmosalamy,Ahmed At . . . |
| 13:45 - 14:15 |
Bug Bounty Village Closing Ceremony
|
Bug Bounty Village Staff |
| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 10:50 - 11:30 |
Tokens and PRT: Advanced Attacks and Persistence i . . .
|
Elzer Pineda,Jose Rivas |
| 10:10 - 10:50 |
New AWS IAM Attack Paths and the Framework to Expl . . .
|
Seth Art |
| 10:00 - 10:10 |
Opening Talk
|
Jayesh Singh Chauhan |
| 11:00 - 12:59 |
Weaponizing CloudFormation: Privilege Escalation v . . .
|
Samanta Aranda |
| 11:00 - 12:59 |
Governing the Firehose: Writing Custom OPA Policie . . .
|
Ram "n2r" |
| 11:30 - 12:10 |
From Pipeline to Cloud Control
|
Saksham Agrawal |
| 12:50 - 13:20 |
PurpleLoop: Closing the Loop Between Detection Rul . . .
|
Ariz Soriano |
| 12:10 - 12:50 |
Security at Machine Speed: How Autonomous AI Agent . . .
|
Pujita Sahni,Geoff Sweet |
| 13:30 - 15:30 |
Cloudy with a Chance of Breaches: Hands-On AWS Thr . . .
|
Kyle Hubbard |
| 13:30 - 14:30 |
The Autonomous Security Loop
|
Jeremy Schiefer,Lawton Pi . . . |
| 13:20 - 13:59 |
The Hidden Cost of Agentic Connectivity
|
David Fiser,Amy McMahon |
| 14:00 - 14:30 |
Nebula - 5 years, still kicking *aaS
|
Bleon "gl4ssesbo1" Proko |
| 14:30 - 15:10 |
Citizen Developers Can't Defend What They Built: S . . .
|
|
| 15:10 - 15:30 |
Go with the Flow: Riding GCP Dataflow Shadow Depen . . .
|
Gil Weizman,Tamir Yehuda |
| 15:30 - 16:10 |
The Polymorphic Agent: From Cross Agent Escalation . . .
|
Muskan Tomar |
| 16:00 - 17:59 |
Cirro: Extending Your Azure Graph Beyond Identitie . . .
|
Leron Gray |
| 16:00 - 17:59 |
From Dashboard to Exploit: Weaponizing and Winning . . .
|
Mackenzie Jackson |
| 16:10 - 16:50 |
The New Software Supply Chain Nobody is Securing: . . .
|
|
| 16:50 - 17:30 |
Trust Fall: How Agentic AI Inherits Your Cloud's W . . .
|
Aravind Sreekanth Pallavo . . . |
| | |
| Saturday |
|
|
| 10:00 - 10:40 |
Bashing CloudShells for mining, networking, exfil . . .
|
Jenko "edleft" Hwong,Chri . . . |
| 10:40 - 11:20 |
Ghost Records: Automating Dangling DNS & Subdomain . . .
|
Jai Kumar Sharma,Tom McCa . . . |
| 11:00 - 12:59 |
Patch Me If You Can: Hands-On Network Threat Defen . . .
|
Don Bogert |
| 11:00 - 12:59 |
From Findings to Remediations: Open Source Cloud S . . .
|
Toni de la Fuente,Amit Sh . . . |
| 11:20 - 11:59 |
Trust the Cloud Pipeline, Lose the Kingdom
|
Shane Young |
| 12:20 - 12:59 |
Pinchy Gets Played: How We Red-Teamed AI Agents Be . . .
|
Doron Kapah |
| 12:00 - 12:20 |
Whose Resource Is It Anyway? The Design Flaw That . . .
|
Moshe Berntsein |
| 13:30 - 14:30 |
Breaking AWS Bedrock: Novel Attack Techniques Agai . . .
|
Tal Peleg,Maya Parizer |
| 13:30 - 14:30 |
Fix It, Snooze It, or Ignore It? Cloud Security De . . .
|
Mackenzie Jackson |
| 13:30 - 14:10 |
What's Behind the Curtain? Tearing Down AWS's AI A . . .
|
Dan Gansel |
| 13:00 - 13:30 |
Minimal by Design: Building Hardened Near-Zero-CVE . . .
|
Kyle Quest,Ritvik Arya |
| 14:10 - 14:50 |
Autonomous Offense vs. Autonomous Defense: Who's W . . .
|
|
| 14:50 - 15:20 |
cloud-auth: a provider-agnostic CLI for cross-clou . . .
|
Aniruddha Biyani |
| 15:20 - 15:59 |
A New Hope for SSRF: Exploiting Credential Relay f . . .
|
Marios Gyftos,Chrysostomo . . . |
| 16:00 - 17:59 |
OCIguana - A vulnerable-by-design OCI lab
|
Eli Shparaga |
| 16:00 - 16:59 |
Securing the AI Stack and Hunting Across Clouds
|
Bryant Pickford |
| 16:40 - 17:20 |
Key Rotation Won't Save You: Hunting Workload Iden . . .
|
Jie Wu |
| 16:00 - 16:40 |
The 100-to-1 Problem: Securing the Non-Human Ident . . .
|
|
| | |
| Sunday |
|
|
| 10:40 - 11:20 |
When Machines Attack Machines: Detecting AI-Autono . . .
|
Gowthamaraj Rajendran |
| 10:00 - 10:40 |
Tag, You’re It: Authorization Traps in AWS ABAC
|
Itay Saraf |
| 11:00 - 12:59 |
The Autonomous Insider
|
Naveen Reddy Pogalla,Hari . . . |
| 11:50 - 12:30 |
Foxveil: Cloud-Native Loader Tradecraft on Cloudfl . . .
|
Shani Kurtzberg,Zohar Bub . . . |
| 11:20 - 11:50 |
Breaking the Oracle: Building an Offensive Securit . . .
|
Scott Weston |
| 12:30 - 13:10 |
Root-as-a-Service: The Hidden Runtime of Azure AI . . .
|
Shani Peled |
| 13:10 - 13:30 |
Closing Talk
|
Jayesh Singh Chauhan |
| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 10:00 - 11:59 |
Car Hacking Village Scavenger Hunt Contest
|
|
| 10:30 - 10:59 |
The DEF CON 34 Badge
|
Andrew 'bunnie' Huang |
| 10:00 - 10:30 |
Welcome to DEF CON 34!
|
Jeff "The Dark Tangent" M . . . |
| 10:00 - 10:30 |
Breaking the Ethereum Phone: From BootROM to Walle . . .
|
Guanxing Wen |
| 10:30 - 11:30 |
Breaking Local AI Runtimes: Exploiting llama.cpp a . . .
|
Ofek Itach,Vladimir "G1ND . . . |
| 10:00 - 10:59 |
From square root to /root: escalating privileges i . . .
|
Ron Ben Yizhak |
| 10:00 - 10:30 |
Weaponizing Uselessness: Breaking SMM with the Slo . . .
|
Christopher "xoreaxeaxeax . . . |
| 10:30 - 11:30 |
Reflections on Disregarding Trust (Weaponizing CDP . . .
|
Gregory "1umberhack" Disn . . . |
| 10:00 - 10:59 |
Texas Incidents - How we broke the OMAP-L138 Trust . . .
|
Carlo Meijer,Wouter Boksl . . . |
| 11:00 - 11:59 |
The 2026 Pwnie Awards
|
Ian Roos,Mark Trumpbour |
| 11:30 - 12:30 |
Crashing the Party: Pwning Control-Flow Integrity . . .
|
Marcos "h3xduck" Bajo,Rit . . . |
| 11:00 - 11:59 |
Sliding into the Flight Deck’s DMs: Practical Me . . .
|
Martin "MasorX" Strohmeie . . . |
| 11:30 - 12:30 |
A Provider for the MOFia - Distributed Post-Ex Cap . . .
|
Steven Flores |
| 11:00 - 11:59 |
Keychained Melody - Grabbing the Keys to the iClou . . .
|
Alex Radocea,Jaron Bradle . . . |
| 12:00 - 12:30 |
Your Packets Are Showing: Hybrid Quantum ML for Pa . . .
|
Daniel Justice,Jae Sung K . . . |
| 12:30 - 13:30 |
Fireside Chat with Gen. Paul Nakasone
|
Paul Nakasone,Jeff "The D . . . |
| 12:30 - 13:30 |
BTR Reforged: Weaponizing Defender's Remediation D . . .
|
Jiří Vinopal |
| 12:30 - 12:59 |
DC101
|
Nikita Kronenberg,Michael . . . |
| 12:00 - 12:30 |
Shopping Is The Attack: A Decade Of E-Commerce Sca . . .
|
Yaniv "PSYMAG" Menasherov |
| 12:30 - 12:59 |
Hacking the Government: How Two Researchers Turned . . .
|
Robert "ProXy" Kruczek,Ka . . . |
| 12:30 - 13:30 |
Patch Gap to Mobile Renderer RCE: Pwning Samsung I . . .
|
Hrvoje Mišetić,Jamie Hi . . . |
| 12:00 - 12:59 |
Can AI do novel security research? Meet the HTTP T . . .
|
James "albinowax" Kettle |
| 13:30 - 14:59 |
What is the Right Balance of Rules for Defenders & . . .
|
Emanuel Gawrieh,Jason Cli . . . |
| 13:30 - 14:30 |
Breaking into Amazon lockers by any means necessar . . .
|
Martin Vigo |
| 13:00 - 13:59 |
LGTM: Bypassing an LLM Build Gate When Prompt Inje . . .
|
Aviv Donenfeld |
| 13:30 - 14:30 |
Plug And Pwn: Weaponizing Windows PnP Auto-Install
|
Alejandro "0xedh" Hernand . . . |
| 13:00 - 13:59 |
Bring-Your-Own-EDR - Breaking Windows Process Prot . . .
|
Shahak Morag |
| 14:30 - 15:30 |
WASM Was Not the Boundary: Sandcastles, Not Sandbo . . .
|
Saar Pearl,Vladimir "G1ND . . . |
| 14:00 - 14:59 |
8 Out of 10 Banks in Belgium HATE This One Weird e . . .
|
James "Acorn221" Arnott |
| 14:30 - 14:59 |
Lowering the Orbit: Exploiting Satellite Protocols . . .
|
Romel "r0r0x" Marin |
| 14:00 - 14:59 |
Lessons from a decade of building whistleblower te . . .
|
Trevor Timm,redshiftzero |
| 15:00 - 15:59 |
The Stream Is Dead, Long Live the Stream: How HTTP . . .
|
Gal Bar Nahum |
| 15:30 - 16:30 |
Your Bank Thinks I'm You: A Complete Kill Chain Ag . . .
|
Xavier "@xaferima" Riofri . . . |
| 15:00 - 15:59 |
Hacking the Hackers who Hack Hackers: Supply-Chain . . .
|
Assaf Morag |
| 15:00 - 15:30 |
Pwning Rekordbox: Unauthenticated filesystem acces . . .
|
Christopher "TRIODE" Le |
| 15:30 - 16:30 |
Riding for Free - Breaking Public Transport RFID a . . .
|
Aidan "luu176" Nakache |
| 15:00 - 15:59 |
Data Tomb Raider: Raiding Modern AI Vaults with Le . . .
|
Dolev Taler,Mark Vaitsman |
| 16:00 - 16:59 |
The Sandbox is a Suggestion: Deconstructing AI Age . . .
|
Elad Meged |
| 16:30 - 17:30 |
noRecognition: Could a pattern on your clothing fo . . .
|
Bill "hevnsnt" Swearingen |
| 16:00 - 16:59 |
Hacking the EOD Bot: How I Learned to Stop Worryin . . .
|
Patrick "gigstorm" Kiley, . . . |
| 16:30 - 17:30 |
CloudBashing: Exploiting free CloudShells for mini . . .
|
Jenko "edleft" Hwong,Chri . . . |
| 16:00 - 16:59 |
Certified Re-Pwned: escalating all the way up
|
Daniel Monzon,Eric Labrad . . . |
| 17:00 - 17:59 |
Hacking AI
|
Bruce Schneier |
| 17:30 - 17:59 |
Breaking Hardware CFI with Sigreturn
|
Omri "beta_b0t" Ben Bassa . . . |
| 17:00 - 17:59 |
One Chain to Own Them All — Breaking AI Infrastr . . .
|
Ji'an "azraelxuemo" Zhou, . . . |
| 17:30 - 17:59 |
You've Got Mail (That Was Meant For No One)
|
Cøry "interpünkt" Solov . . . |
| 17:00 - 17:59 |
Gotta Catch 'Em All: How To Capture 3.5 Billion Wh . . .
|
Maximilian Guenther,Gabri . . . |
| | |
| Saturday |
|
|
| 10:00 - 11:59 |
Car Hacking Village Scavenger Hunt Contest
|
|
| 10:00 - 10:59 |
The Ghost Key: Illusions of "Time Management" in T . . .
|
Yang Liu,Zhenghan Wang |
| 10:00 - 10:30 |
Memory Laundering via Metal: What EDR Can't See on . . .
|
Hxr1 |
| 10:30 - 11:30 |
Harvest Now, Decrypt Later: Practical Attacks on P . . .
|
Aleksandr Krasnov |
| 10:00 - 10:59 |
From Wind Farm to CHP Plant: The Untold Story of L . . .
|
Marcin Dudek |
| 10:00 - 10:30 |
No Socket, No Privs, No Problem: Weaponizing OCI R . . .
|
David "davidrxchester" Ro . . . |
| 10:30 - 11:30 |
Root From Kilometers Away: Ubiquiti AirMax RCE
|
Federico Kirschbaum,Gasto . . . |
| 10:00 - 10:59 |
Identity Crisis: Novel Vulnerabilities leading to . . .
|
Shai Laron |
| 11:00 - 11:59 |
Tracking the Trackers: How We Took Over 36 Million . . .
|
Felipe Solferini,Vangelis . . . |
| 11:30 - 12:30 |
Thin Client? Thin Crypto - Bypassing Full-Disk Enc . . .
|
Darren McDonald |
| 11:00 - 11:59 |
Very Pwned: Hacking Verifone’s card machine thre . . .
|
Reino Mostert |
| 11:30 - 12:30 |
Your OTP Never Arrived: Attacking the Trust Bounda . . .
|
Kyprianos "kavasilo" Vasi . . . |
| 11:00 - 11:59 |
Forgotten but Not Gone: Unauthenticated RCEs and L . . .
|
Ron Ben Yizhak |
| 12:00 - 12:59 |
Rage Against the Sandbox: Bypassing Apple’s iOS . . .
|
Yuval Hanoch Hirschenbein . . . |
| 12:30 - 13:30 |
Writing to Shadow Stacks
|
Vladimir "G1ND1L4" Tokare . . . |
| 12:00 - 12:59 |
C(2)YA: Inside the Adversary's Inbox
|
Vitaly Simonovich |
| 12:30 - 13:30 |
Compounding Interest: Exploiting the ATM Supply Ch . . .
|
Matt Burch |
| 12:00 - 12:59 |
The Glass Perimeter: Systematic Bypasses in Biomet . . .
|
Dan Borgogno,Javier Berna . . . |
| 13:00 - 13:59 |
gpwn: Wiretapping fiber (GPON) ISP deployments fro . . .
|
Rithwik "thel3l" Jayasimh . . . |
| 13:30 - 14:30 |
Bring Your Own Root Of Trust
|
Mickey "@HackingThings" S . . . |
| 13:00 - 13:59 |
Stalking the Wily Hacker ... 40 years later
|
Cliff Stoll |
| 13:30 - 14:30 |
Transformers: Dark Side of the Type - Weaponizing . . .
|
Oleksandr Mirosh |
| 13:00 - 13:59 |
Dylib Hijacking on macOS: Dead or Alive?
|
Patrick Wardle |
| 14:00 - 14:59 |
Lights Out: Out-of-Band, Out of Mind, Out of Contr . . .
|
HD "hdm" Moore |
| 14:30 - 15:30 |
Bird Hunting Season: The Final Flight
|
Jon "GainSec" Gaines |
| 14:00 - 14:59 |
Cracking North Korea's Information Control: How Sm . . .
|
JDT |
| 14:30 - 15:30 |
Looking and Peering: Attacking from beyond BGP Adj . . .
|
Bo-Shiun "bronson113" Yen |
| 14:00 - 14:59 |
The Enclave is Lying to You: Breaking TEE Trust Bo . . .
|
Sandeep "pyro" Jayashanka . . . |
| 15:00 - 15:59 |
Throw Out the Alphabet: Token-Based Markov Chains . . .
|
Jon "flakpaket" Gorenflo |
| 15:30 - 16:30 |
Zero-Day Provisioning: Chaining TP-Link ZTP Vulner . . .
|
Francesco La Spina,Stanis . . . |
| 15:00 - 15:59 |
Smile, you're on camera! Livestreaming from North . . .
|
Heiner García,Mauro Eldr . . . |
| 15:30 - 16:30 |
Wrestling with a Python: Escaping Copilot Studio's . . .
|
Ryan Hausknecht,Simon Max . . . |
| 15:00 - 15:59 |
Get Set, Exploit! Unveiling Python Class Pollution . . .
|
Gavin Zhong,Zhengyu Liu,J . . . |
| 16:00 - 16:59 |
Hacking Your Life with AI Can Get You Hacked: How . . .
|
Peyton "p80n-sec" Kennedy |
| 16:30 - 17:30 |
How much of our Bluetooth firmware reverse enginee . . .
|
Veronica Kovah,Xeno Kovah |
| 16:00 - 16:59 |
The Compiler That Can't Read: Crashing Every 5G Ph . . .
|
Qiqing Huang,Xingyu Wang |
| 16:30 - 17:30 |
Taming the Swarm: Hard Architectural Lessons from . . .
|
Albert "yz9yt" Corzo |
| 16:00 - 16:59 |
Install Me Maybe: Turning Claimable VS Code Extens . . .
|
Raphael "rcss" Silva |
| 17:00 - 17:59 |
High Voltage Heist: Turning Your EV into my Power . . .
|
Fabien Guillebot,Stepan K . . . |
| 17:30 - 17:59 |
TEE.fail: Breaking Trusted Execution Environments . . .
|
Daniel Genkin,Jalen Chuan . . . |
| 17:00 - 17:59 |
OffGuard: Breaking the Most Popular AI Gateway fro . . .
|
Yaara Shriki |
| 17:30 - 20:30 |
DEF CON Franklin: What worked, what didn’t, and . . .
|
Jake Braun |
| 17:00 - 17:59 |
CRLF-Powered Desync Attacks: Beheading HTTP stream . . .
|
Tom "t0xodile" Stacey,Tob . . . |
| | |
| Sunday |
|
|
| 10:00 - 10:59 |
ESP32 as a counter-surveillance platform
|
Cooper "Cybertiger" Quint . . . |
| 10:00 - 10:59 |
This Message Was Sent by Microsoft: Turning Micros . . .
|
Keanu "RedByte" Nys |
| 10:00 - 10:59 |
Shepherding the Tor network
|
Roger "arma" Dingledine |
| 10:30 - 11:30 |
Reversing a Recall: From ‘Noise Triggered’ to . . .
|
Ben Gardiner |
| 10:00 - 10:30 |
Going the Distance: Long-Range Keystroke Injection . . .
|
Benito "paperclipsvinny" . . . |
| 10:00 - 10:30 |
No Prompt Required: Pre-Task RCE in Google Gemini . . .
|
Elad Meged |
| 10:30 - 11:30 |
Gotta Phish 'Em All! Novel Attack Techniques via P . . .
|
Giacomo "GiacoLenzo2109" . . . |
| 11:00 - 11:59 |
LaunchBreak: a Sip of Tea, a Click, and a Full Mul . . .
|
Gavin Zhong,Zhengyu Liu,J . . . |
| 11:00 - 11:59 |
Beyond the Ceremony: The 2026 Passkey Attack Surfa . . .
|
Matteo Giordano |
| 11:00 - 11:59 |
Gone in 60 Frames – USB Video Exploitation
|
Alex Plaskett,Robert Herr . . . |
| 11:30 - 12:30 |
BLE Theft Auto: How a Dealer-Installed Anti-Theft . . .
|
Aaron Schulman,Jerry Yu,Y . . . |
| 11:30 - 12:30 |
From Fuzzer Noise to a Weaponized PHP Exploit: Exp . . .
|
Can Oztas,Kağan Çapar |
| 12:00 - 12:59 |
Your WAF Blocked Us, That Was The Exploit - Remote . . .
|
Barak Sternberg,Nevo Pora . . . |
| 12:00 - 12:59 |
MSIX'd Up: Weaponizing the Modern Windows App Pack . . .
|
Nick "zyn3rgy" Powers |
| 12:00 - 12:59 |
1.1 Million Cameras, One Wildcard: Architectural S . . .
|
Sammy Azdoufal |
| 12:30 - 13:30 |
Chaining Microsoft Binaries to get Privileged Prim . . .
|
Angelo Frasca Caccia |
| 12:30 - 13:30 |
CUDA've done better - Hacking Nvidia GPUs for cont . . .
|
Daniel "0xDACA" Cohen Hil . . . |
| 13:30 - 14:59 |
Contest Closing Ceremonies & Awards
|
|
| 13:00 - 13:59 |
Chaining Logical Bugs for Reliable Windows LPE
|
Bocheng "Crispr" Xiang,He . . . |
| 13:30 - 14:30 |
Witchcraft Solver: Automated 0day Discovery in Str . . .
|
Jonathan "endrazine" Bros . . . |
| 13:30 - 13:59 |
Taking on the Dark Fleet... in Cyberspace!
|
Kenneth Miltenberger,Shan . . . |
| 14:00 - 14:30 |
Hacking Jetskis - from Sea-Don't to Sea-Doo
|
stacksmashing |
| 14:00 - 14:30 |
Talkers Without Borders: Worldwide Free Speech wit . . .
|
T. Gwyddon "data" Owen,am . . . |
| 15:00 - 17:30 |
DEF CON Closing Ceremonies & Awards
|
Jeff "The Dark Tangent" M . . . |
| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 08:30 - 17:30 |
Beat the Breach: Defend, Respond, Survive
|
McKay Hardy,Wes Wagstaff |
| 08:30 - 17:30 |
Cyber & AI Policy Basics: What Every Organization . . .
|
Pamela 'Pam' Feld,Greg Go . . . |
| 08:30 - 17:30 |
Digital Supply Chain Security: Software, Cryptogra . . .
|
Anant Shrivastava,Sunil Y . . . |
| | |
| Saturday |
|
|
| 08:30 - 17:30 |
Blue vs Red Bootcamp: From Attacker Playbooks to D . . .
|
Carlo Anez Mazurco,Marian . . . |
| 08:30 - 17:30 |
Influence Operations: Tactics, Defense, and Exploi . . .
|
Greg Conti,Tom Cross |
| 08:30 - 17:30 |
Full-Stack Pentesting Laboratory: 100% Hands-On + . . .
|
Dawid Czagan |
| | |
| Sunday |
|
|
| 08:30 - 17:30 |
Blue vs Red Bootcamp: From Attacker Playbooks to D . . .
|
Carlo Anez Mazurco,Marian . . . |
| 08:30 - 17:30 |
Influence Operations: Tactics, Defense, and Exploi . . .
|
Greg Conti,Tom Cross |
| 08:30 - 17:30 |
Full-Stack Pentesting Laboratory: 100% Hands-On + . . .
|
Dawid Czagan |
| | |
| Monday |
|
|
| 08:30 - 17:30 |
AI + SOC 101 Bootcamp: Building Modern Security Op . . .
|
Rod Soto |
| 08:30 - 17:30 |
Dark Wolf Hack Our Drone Workshop
|
Ronald Broberg,Rudy Mendo . . . |
| 08:30 - 17:30 |
VS: S-RAD (Satellite-Radio Analysis & Disruption)
|
Andrzej Olchawa,Ricardo F . . . |
| 08:30 - 17:30 |
Agentic AppSec: Harnessing LLMs
|
Seth Law,Ken Johnson |
| 08:30 - 17:30 |
Simulated Adversary: Tactics & Tools Training
|
Jayson E. Street,Iain Jac . . . |
| 08:30 - 17:30 |
Breaking the Cloud Layer - Modern and Practical At . . .
|
Anant Shrivastava,Riyaz W . . . |
| 08:30 - 17:30 |
Securing the Future: Defending Kubernetes & Cloud- . . .
|
Madhu Akula |
| 08:30 - 17:30 |
Breaking Physical Access Control: Electrical Funda . . .
|
Red Team Alliance |
| 08:30 - 17:30 |
Advanced Windows Binary Exploitation
|
Kolja Grassmann,Florian S . . . |
| 08:30 - 16:59 |
Offensive Cyber Security Operations: Mastering Bre . . .
|
Abhijith "Abx" B R |
| 08:30 - 17:30 |
Analyze, Detect & Hunt: Hands-On Malware Analysis, . . .
|
Monnappa K A,Sajan Shetty |
| 08:30 - 17:30 |
Blue vs Red Bootcamp: From Attacker Playbooks to D . . .
|
Carlo Anez Mazurco,Marian . . . |
| 08:30 - 17:30 |
Deep Dive into the Dark Web
|
Robert "pwcrack" Weiss |
| 08:30 - 17:30 |
Car Hacking Masterclass - Attacking & Defending Au . . .
|
Kamel Ghali |
| 08:30 - 17:30 |
Adversarial Thinking: The Art of Dangerous Ideas
|
Greg Conti,Tom Cross |
| 08:30 - 17:30 |
Black Belt Pentesting / Bug Hunting Millionaire: M . . .
|
Dawid Czagan |
| 08:30 - 17:30 |
Solving Modern Cybersecurity Problems with AI
|
Michael Glass |
| 08:30 - 17:30 |
AI SecureOps: Attacking & Defending AI Application . . .
|
Abhinav Singh |
| 08:30 - 17:30 |
Agentic RE: Automating Reverse Engineering & Vulne . . .
|
John "clearbluejar" McInt . . . |
| 08:30 - 17:30 |
Advanced Cloud Incident Response in Azure and Micr . . .
|
Korstiaan Stam |
| 08:30 - 17:30 |
Applied SDR Hacking: Red Team SIGINT for mission-c . . .
|
Jos Wetzels,Wouter Boksla . . . |
| 08:30 - 17:30 |
AI Agent Security Masterclass: Attacking and Defen . . .
|
Abhay Bhargav,Vishnu Pras . . . |
| 08:30 - 17:30 |
Strategic AI Penetration: Mastering Offensive Tech . . .
|
Marek Zmysłowski,Konrad . . . |
| 08:30 - 17:30 |
Bridging the GAP: Hands-On Embedded Hardware Hacki . . .
|
Aaron Wasserman,Garrett F . . . |
| 08:30 - 17:30 |
Software Defined Radios 101 - Introduction to RF H . . .
|
Richard Shmel |
| 08:30 - 17:30 |
Hacking Cryptography
|
Ruben Gonzalez,Aaron Kais . . . |
| 08:30 - 17:30 |
IoT Exploitation Masterclass: Hardware & RF Hackin . . .
|
Smriti Gaba,Yianna Paris |
| 08:30 - 17:30 |
Hacking Android and IOT Apps by Example
|
Abraham Aranguren,Abhishe . . . |
| | |
| Tuesday |
|
|
| 08:30 - 17:30 |
Dark Wolf Hack Our Drone Workshop
|
Ronald Broberg,Rudy Mendo . . . |
| 08:30 - 17:30 |
AI + SOC 101 Bootcamp: Building Modern Security Op . . .
|
Rod Soto |
| 08:30 - 17:30 |
VS: S-RAD (Satellite-Radio Analysis & Disruption)
|
Andrzej Olchawa,Ricardo F . . . |
| 08:30 - 17:30 |
Agentic AppSec: Harnessing LLMs
|
Seth Law,Ken Johnson |
| 08:30 - 17:30 |
Simulated Adversary: Tactics & Tools Training
|
Jayson E. Street,Iain Jac . . . |
| 08:30 - 17:30 |
Breaking the Cloud Layer - Modern and Practical At . . .
|
Anant Shrivastava,Riyaz W . . . |
| 08:30 - 17:30 |
Securing the Future: Defending Kubernetes & Cloud- . . .
|
Madhu Akula |
| 08:30 - 17:30 |
Breaking Physical Access Control: Electrical Funda . . .
|
Red Team Alliance |
| 08:30 - 17:30 |
Advanced Windows Binary Exploitation
|
Kolja Grassmann,Florian S . . . |
| 08:30 - 16:59 |
Offensive Cyber Security Operations: Mastering Bre . . .
|
Abhijith "Abx" B R |
| 08:30 - 17:30 |
Analyze, Detect & Hunt: Hands-On Malware Analysis, . . .
|
Monnappa K A,Sajan Shetty |
| 08:30 - 17:30 |
Blue vs Red Bootcamp: From Attacker Playbooks to D . . .
|
Carlo Anez Mazurco,Marian . . . |
| 08:30 - 17:30 |
Deep Dive into the Dark Web
|
Robert "pwcrack" Weiss |
| 08:30 - 17:30 |
Car Hacking Masterclass - Attacking & Defending Au . . .
|
Kamel Ghali |
| 08:30 - 17:30 |
Adversarial Thinking: The Art of Dangerous Ideas
|
Greg Conti,Tom Cross |
| 08:30 - 17:30 |
Black Belt Pentesting / Bug Hunting Millionaire: M . . .
|
Dawid Czagan |
| 08:30 - 17:30 |
Solving Modern Cybersecurity Problems with AI
|
Michael Glass |
| 08:30 - 17:30 |
AI SecureOps: Attacking & Defending AI Application . . .
|
Abhinav Singh |
| 08:30 - 17:30 |
Agentic RE: Automating Reverse Engineering & Vulne . . .
|
John "clearbluejar" McInt . . . |
| 08:30 - 17:30 |
Advanced Cloud Incident Response in Azure and Micr . . .
|
Korstiaan Stam |
| 08:30 - 17:30 |
Applied SDR Hacking: Red Team SIGINT for mission-c . . .
|
Jos Wetzels,Wouter Boksla . . . |
| 08:30 - 17:30 |
AI Agent Security Masterclass: Attacking and Defen . . .
|
Abhay Bhargav,Vishnu Pras . . . |
| 08:30 - 17:30 |
Strategic AI Penetration: Mastering Offensive Tech . . .
|
Marek Zmysłowski,Konrad . . . |
| 08:30 - 17:30 |
Bridging the GAP: Hands-On Embedded Hardware Hacki . . .
|
Aaron Wasserman,Garrett F . . . |
| 08:30 - 17:30 |
Software Defined Radios 101 - Introduction to RF H . . .
|
Richard Shmel |
| 08:30 - 17:30 |
Hacking Cryptography
|
Ruben Gonzalez,Aaron Kais . . . |
| 08:30 - 17:30 |
IoT Exploitation Masterclass: Hardware & RF Hackin . . .
|
Smriti Gaba,Yianna Paris |
| 08:30 - 17:30 |
Hacking Android and IOT Apps by Example
|
Abraham Aranguren,Abhishe . . . |
| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 09:00 - 12:59 |
Sold Out - Offensive Packet Wizardry with Scapy
|
Mike "Chicolinux" Guirao |
| 09:00 - 12:59 |
Sold Out - Hands-on IoT firmware extraction and fl . . .
|
Dennis Giese,Braelynn Lue . . . |
| 09:00 - 12:59 |
Sold Out - AWS Cloud Security 101: From IAM Miscon . . .
|
zeta,Rafa "bane" Gutierre . . . |
| 09:00 - 12:59 |
Sold Out - Web Hacking 101
|
cale "calebot" smith,Ruch . . . |
| 09:00 - 12:59 |
Sold Out - Malware Development 101 - From Zero to . . .
|
Yoann "OtterHacker" DEQUE . . . |
| 09:00 - 12:59 |
Sold Out - Long Live Empire: A C2 Workshop for Mod . . .
|
Jake "Hubbl3" Krasnov,Vin . . . |
| 09:00 - 12:59 |
Sold Out - Learning to Hack Bluetooth Low Energy w . . .
|
Ryan "Hackgnar" Holeman,A . . . |
| 09:00 - 12:59 |
Sold Out - Agentic Threat Hunting: Building AI Tha . . .
|
Sydney "letswastetime" Ma . . . |
| 14:00 - 17:59 |
Sold Out - Investigating and Responding to M365 ac . . .
|
Vince "bitpusher" Weppner |
| 14:00 - 17:59 |
Sold Out - OT Systems: how to secure them in pract . . .
|
Alexandrine Torrents,Arna . . . |
| 14:00 - 17:59 |
Sold Out - AWS Principal Threat Hunting: Behaviora . . .
|
Rodrigo "Sp0oKeR" Montoro |
| 14:00 - 17:59 |
Sold Out - Reaching Mythos: Hands-On Vulnerability . . .
|
John "clearbluejar" McInt . . . |
| 14:00 - 17:59 |
Sold Out - Solder, Detect, Listen: Build Your Own . . .
|
Darcy "@Drc3p0" Neal |
| 14:00 - 17:59 |
Sold Out - All About Stoopie InfoStealers: Malware . . .
|
Ryan "@rj_chap" Chapman,A . . . |
| 14:00 - 17:59 |
Sold Out - Introduction to Malware Analysis
|
Sam Bowne,Elizabeth Biddl . . . |
| 14:00 - 17:59 |
Sold Out - Embedded Computing Tools for Wireless H . . .
|
Joseph Long |
| | |
| Saturday |
|
|
| 09:00 - 12:59 |
Sold Out - Wi-Fight Club: I am Jack's Evil Twin
|
James Hawk,Jon "C4V3M4N" . . . |
| 09:00 - 12:59 |
Sold Out - Explore the Windows instrumentation cal . . .
|
Yoann "OtterHacker" DEQUE . . . |
| 09:00 - 12:59 |
Sold Out - Step-by-Step Malware Development: Evadi . . .
|
Yu Terada,Kotaro "@Decama . . . |
| 09:00 - 12:59 |
Sold Out - Words As Weapons: Breaking AI and Agent . . .
|
Pavan "pavanreddysec" Red . . . |
| 09:00 - 12:59 |
Sold Out - HackTheCloud26: Chaining Cloud Misconfi . . .
|
HackeMate |
| 09:00 - 12:59 |
Sold Out - Hecate: A Trivial UART Tool
|
mx,Joe "SecurelyFitz" Fit . . . |
| 09:00 - 12:59 |
Sold Out - Detecting and Analyzing Memory Only Mal . . .
|
Andrew Case,Pierre "Abyss . . . |
| 09:00 - 12:59 |
Sold Out - Battle-Tested Broadcasts: RF Insights F . . .
|
Preston Zen |
| 14:00 - 17:59 |
Sold Out - Hands-on DuckyScript: An Introduction t . . .
|
wasabi,Ø1,Tokugero |
| 14:00 - 17:59 |
Sold Out - Purple Teaming Industrial Control Syste . . .
|
Arnaud SOULLIE,Alexandrin . . . |
| 14:00 - 17:59 |
Sold Out - Entra ID Persistence - Because Password . . .
|
Raunak "Trouble1" Parmar, . . . |
| 14:00 - 17:59 |
Sold Out - From Prompt to PWN: Exploiting LLM Powe . . .
|
Abhinav Verma |
| 14:00 - 17:59 |
Sold Out - Intro to Writing Windows Malware with R . . .
|
iDigitalFlame,Daniel Brav . . . |
| 14:00 - 17:59 |
Sold Out - Building Agentic Reverse Engineering "S . . .
|
John "clearbluejar" McInt . . . |
| 14:00 - 17:59 |
Sold Out - Learning to Reverse Engineer Compiled C . . .
|
Wesley McGrew |
| 14:00 - 17:59 |
Sold Out - Salesforce Apex Predator: Breaking Sale . . .
|
Nitay Bachrach,Cynthia Ar . . . |
| | |
| Sunday |
|
|
| 09:00 - 12:59 |
Sold Out - Attacking Cloud APIs from the IoT Edge
|
Rodney "BenevolentWorm" B . . . |
| 09:00 - 12:59 |
Sold Out - Building your own hardware hacking kit . . .
|
Dallas |
| 09:00 - 12:59 |
Sold Out - Post-Quantum Cryptography (PQC) for Hac . . .
|
Eric "Eijah" Anderson |
| 09:00 - 12:59 |
Sold Out - Purple Protocol: Adversary emulation fo . . .
|
Patrick "PilotPat" Raiden . . . |
| 09:00 - 12:59 |
Sold Out - CI/CD Weaponization: Build It, Deploy I . . .
|
Ricardo Sanchez,Daniel Ma . . . |
| 09:00 - 12:59 |
Sold Out - ICS Hack 'n Track
|
Pedro Cabrera,Hannes "her . . . |
| 09:00 - 12:59 |
Sold Out - Creating Shellcode for Hackers
|
Bramwell "Bw3ll" Brizendi . . . |
| 09:00 - 12:59 |
Sold Out - Pivot, Hunt, Publish: An Offline, Hands . . .
|
Rushikesh Nandedkar |
| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 10:00 - 10:45 |
AD-Necromancer: Resurrecting Forgotten Control Pat . . .
|
Akbar "0xsensei" Abdullay . . . |
| 10:00 - 10:45 |
Peekaboo: Breaking the Black Box of Threat and Mal . . .
|
Zhassulan "cocomelonc" Zh . . . |
| 10:00 - 10:45 |
Senrigan (千里眼) x Suzaku (朱雀): Threat Hun . . .
|
Fukusuke Takahashi,Zach M . . . |
| 10:00 - 10:45 |
X-Ray Your Agents: Pentesting MCPs, Skills, and th . . .
|
Xia Hua,Abhijeet Kumar |
| 10:00 - 10:45 |
PromptPwn: Finding and Exploiting AI-Generated Vul . . .
|
Georgia Weidman |
| 10:00 - 10:45 |
Empire 7: Shipping a C2 at AI Speed
|
Vincent "Vinnybod" Rose,J . . . |
| 11:00 - 11:45 |
Damn Vulnerable Agentic AI Application (DVAIA)
|
Abhinav Verma,Mukesh Agga . . . |
| 11:00 - 11:45 |
sisakulint:CI-Friendly static linter with autofix, . . .
|
Atsushi Sada,hikae |
| 11:00 - 11:45 |
Be like a BRAT(BLE Recon and Attack Toolkit): Skip . . .
|
Gigi Xiaoqing Liu,Muzzamm . . . |
| 11:00 - 11:45 |
Zealot: An Autonomous Cloud Offensive Multi-Agent . . .
|
Chen Doytshman |
| 11:00 - 11:45 |
AOBTD: AI One Bites The DAST
|
Ozgun "ozzy" Kultekin |
| 11:00 - 11:45 |
AI Pipeline for N-days Weaponization
|
Andrea Brosio,Arun Nair |
| 12:00 - 12:45 |
Damn Vulnerable Agentic AI Application (DVAIA)
|
Abhinav Verma,Mukesh Agga . . . |
| 12:00 - 12:45 |
GnawLab: Open-Source AWS Attack Scenarios Based on . . .
|
ialleejy,Kyul,HyunJun "Be . . . |
| 12:00 - 12:45 |
VoiceLock: Offline, Robust On-Device Speech Transc . . .
|
Ayaan Qayyum,Parag Kalay |
| 12:00 - 12:45 |
Ghost in the IDE
|
Venkata Jayaram Yalla,Par . . . |
| 12:00 - 12:45 |
Weaponizing eBPF and XDP with Covert Triggered Rev . . .
|
Yll "0xBabar0ka" Berisha |
| 12:00 - 12:45 |
Overcast: Video OSINT Agent. Point It at 100 Video . . .
|
Kevin "kdrwins" Dela Rosa |
| 13:00 - 13:45 |
xEndity: IoT Firmware Analysis & Digital Twin Plat . . .
|
Zeus "LightningGod" Chan, . . . |
| 13:00 - 13:45 |
MSCodePhish: Redeem Your Coupon. Surrender Your Se . . .
|
Raunak "Trouble1" Parmar, . . . |
| 13:00 - 13:45 |
Goose Processing Unit (GPU): VRAM as an Unmonitore . . .
|
Gannon "Dorf" Gebauer,Ant . . . |
| 13:00 - 13:45 |
Zero-Cloud Threat Modeling: Vector Embedding Archi . . .
|
Ankit Vashisth |
| 13:00 - 13:45 |
Beyond Spidering: Behavior Driven DAST for Real Ap . . .
|
Sara "testingSoul" Martin . . . |
| 13:00 - 13:45 |
Monitor, Compile, Enforce: A Compiler Pipeline for . . .
|
Buğrahan Yücel |
| 14:00 - 14:45 |
SecretSifter: Production Apps Are Leaking Credenti . . .
|
Hemanth Gorijala |
| 14:00 - 14:45 |
MalSkill Lab: Hands-On Natural Language Malware in . . .
|
Nur "BurritoTheNurrito" G . . . |
| 14:00 - 14:45 |
Clew: Untangling Evasive Malware with Per-Sample F . . .
|
Kyler McElroy,Anita Ding, . . . |
| 14:00 - 14:45 |
AzProwl: Prowling the Azure Attack Surface
|
Jared "GonePhishing402" G . . . |
| 14:00 - 14:45 |
L.A.Y.E.R.S - Layered Analysis Engine for Browser . . .
|
Abhinav Khanna,Krishna Ch . . . |
| 14:00 - 14:45 |
Trajan: Cross-Platform CI/CD Security Scanner
|
Rahul Saranjame,Ranganath . . . |
| 15:00 - 15:45 |
GhostCatcher (endpoint detection agent)
|
Sercan Okur |
| 15:00 - 15:45 |
Intercept.js: Runtime-Aware Detection for JavaScri . . .
|
Rishi Kant |
| 15:00 - 15:45 |
BigIron.ai: AI-Assisted Exploration and Security A . . .
|
Adam "w00tock" Toscher |
| 15:00 - 15:45 |
AzProwl: Prowling the Azure Attack Surface
|
Jared "GonePhishing402" G . . . |
| 15:00 - 15:45 |
TokenMesh: Exposing Azure's Hidden Identity Attack . . .
|
Saksham Agrawal |
| 15:00 - 15:45 |
pymsi: Interactive MSI Installer Analysis in Pytho . . .
|
Ryan "Nightlark" Mast |
| 16:00 - 16:45 |
Phasmid: Deniable Storage for Rubber-Hose Scenario . . .
|
Makoto "Mr.Rabbit" Sugita |
| 16:00 - 16:45 |
AC Scanner: The Post-Quantum Cryptographic Exposur . . .
|
Anurag Swarnim Yadav,Jose . . . |
| 16:00 - 16:45 |
BigIron.ai: AI-Assisted Exploration and Security A . . .
|
Adam "w00tock" Toscher |
| 16:00 - 16:45 |
DFMI: Weaponizing MSI Installers for Fileless Code . . .
|
Anil Celik |
| 16:00 - 16:45 |
Reversing F5: Pure-Go Steganography, Live Forensic . . .
|
0verkilll |
| 16:00 - 16:45 |
MailX-Ray: A TSA X-Ray for Emails — Air-Gapped S . . .
|
Uğur "uJohn" Can ATASOY |
| | |
| Saturday |
|
|
| 10:00 - 10:45 |
SecretSifter: Production Apps Are Leaking Credenti . . .
|
Hemanth Gorijala |
| 10:00 - 10:45 |
Peekaboo: Breaking the Black Box of Threat and Mal . . .
|
Zhassulan "cocomelonc" Zh . . . |
| 10:00 - 10:45 |
Goose Processing Unit (GPU): VRAM as an Unmonitore . . .
|
Gannon "Dorf" Gebauer,Ant . . . |
| 10:00 - 10:45 |
DFMI: Weaponizing MSI Installers for Fileless Code . . .
|
Anil Celik |
| 10:00 - 10:45 |
Reversing F5: Pure-Go Steganography, Live Forensic . . .
|
0verkilll |
| 10:00 - 10:45 |
Monitor, Compile, Enforce: A Compiler Pipeline for . . .
|
Buğrahan Yücel |
| 11:00 - 11:45 |
GhostCatcher (endpoint detection agent)
|
Sercan Okur |
| 11:00 - 11:45 |
sisakulint:CI-Friendly static linter with autofix, . . .
|
Atsushi Sada,hikae |
| 11:00 - 11:45 |
Clew: Untangling Evasive Malware with Per-Sample F . . .
|
Kyler McElroy,Anita Ding, . . . |
| 11:00 - 11:45 |
X-Ray Your Agents: Pentesting MCPs, Skills, and th . . .
|
Xia Hua,Abhijeet Kumar |
| 11:00 - 11:45 |
TokenMesh: Exposing Azure's Hidden Identity Attack . . .
|
Saksham Agrawal |
| 11:00 - 11:45 |
pymsi: Interactive MSI Installer Analysis in Pytho . . .
|
Ryan "Nightlark" Mast |
| 12:00 - 12:45 |
Phasmid: Deniable Storage for Rubber-Hose Scenario . . .
|
Makoto "Mr.Rabbit" Sugita |
| 12:00 - 12:45 |
MSCodePhish: Redeem Your Coupon. Surrender Your Se . . .
|
Raunak "Trouble1" Parmar, . . . |
| 12:00 - 12:45 |
Keychecker : SSH Key based attack tool for DVCS Sy . . .
|
Anant Shrivastava |
| 12:00 - 12:45 |
Zealot: An Autonomous Cloud Offensive Multi-Agent . . .
|
Chen Doytshman |
| 12:00 - 12:45 |
Beyond Spidering: Behavior Driven DAST for Real Ap . . .
|
Sara "testingSoul" Martin . . . |
| 12:00 - 12:45 |
Empire 7: Shipping a C2 at AI Speed
|
Vincent "Vinnybod" Rose,J . . . |
| 13:00 - 13:45 |
AD-Necromancer: Resurrecting Forgotten Control Pat . . .
|
Akbar "0xsensei" Abdullay . . . |
| 13:00 - 13:45 |
MalSkill Lab: Hands-On Natural Language Malware in . . .
|
Nur "BurritoTheNurrito" G . . . |
| 13:00 - 13:45 |
Keychecker : SSH Key based attack tool for DVCS Sy . . .
|
Anant Shrivastava |
| 13:00 - 13:45 |
Hook Crook - Extracting More From Discord Webhooks
|
Jeremy Banker - K0JLB,Ari . . . |
| 13:00 - 13:45 |
L.A.Y.E.R.S - Layered Analysis Engine for Browser . . .
|
Abhinav Khanna,Krishna Ch . . . |
| 13:00 - 13:45 |
Trajan: Cross-Platform CI/CD Security Scanner
|
Rahul Saranjame,Ranganath . . . |
| 14:00 - 14:45 |
LoKi: A LoRa/Meshtastic based implant for Red Team . . .
|
Venky Raju |
| 14:00 - 14:45 |
Intercept.js: Runtime-Aware Detection for JavaScri . . .
|
Rishi Kant |
| 14:00 - 14:45 |
Senrigan (千里眼) x Suzaku (朱雀): Threat Hun . . .
|
Fukusuke Takahashi,Zach M . . . |
| 14:00 - 14:45 |
Hook Crook - Extracting More From Discord Webhooks
|
Jeremy Banker - K0JLB,Ari . . . |
| 14:00 - 14:45 |
PromptPwn: Finding and Exploiting AI-Generated Vul . . .
|
Georgia Weidman |
| 14:00 - 14:45 |
MailX-Ray: A TSA X-Ray for Emails — Air-Gapped S . . .
|
Uğur "uJohn" Can ATASOY |
| 15:00 - 15:45 |
LoKi: A LoRa/Meshtastic based implant for Red Team . . .
|
Venky Raju |
| 15:00 - 15:45 |
AC Scanner: The Post-Quantum Cryptographic Exposur . . .
|
Anurag Swarnim Yadav,Jose . . . |
| 15:00 - 15:45 |
Be like a BRAT(BLE Recon and Attack Toolkit): Skip . . .
|
Gigi Xiaoqing Liu,Muzzamm . . . |
| 15:00 - 15:45 |
Ghost in the IDE
|
Venkata Jayaram Yalla,Par . . . |
| 15:00 - 15:45 |
AOBTD: AI One Bites The DAST
|
Ozgun "ozzy" Kultekin |
| 15:00 - 15:45 |
AI Pipeline for N-days Weaponization
|
Andrea Brosio,Arun Nair |
| 16:00 - 16:45 |
xEndity: IoT Firmware Analysis & Digital Twin Plat . . .
|
Zeus "LightningGod" Chan, . . . |
| 16:00 - 16:45 |
GnawLab: Open-Source AWS Attack Scenarios Based on . . .
|
ialleejy,Kyul,HyunJun "Be . . . |
| 16:00 - 16:45 |
VoiceLock: Offline, Robust On-Device Speech Transc . . .
|
Ayaan Qayyum,Parag Kalay |
| 16:00 - 16:45 |
Zero-Cloud Threat Modeling: Vector Embedding Archi . . .
|
Ankit Vashisth |
| 16:00 - 16:45 |
Weaponizing eBPF and XDP with Covert Triggered Rev . . .
|
Yll "0xBabar0ka" Berisha |
| 16:00 - 16:45 |
Overcast: Video OSINT Agent. Point It at 100 Video . . .
|
Kevin "kdrwins" Dela Rosa |
| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 10:00 - 10:59 |
Sovereign by Design, Vulnerable by Default
|
Devin Lynch,Haley Ring |
| 10:00 - 10:59 |
Not Your Parents’ Schoolhouse Rock: Getting Tech . . .
|
Jeff Rothblum,Michael Fly . . . |
| 11:00 - 11:59 |
Morbidity and Mortality: Hackers, HIPAA, and a new . . .
|
Christian Dameff,Jeff "r3 . . . |
| 12:00 - 12:59 |
Election Security in the Age of AI: Governance, Tr . . .
|
Lester Godsey,William Gat . . . |
| 13:00 - 13:59 |
Connectivity as Control in the European High North
|
Szymon Skalski,Patricia V . . . |
| 13:00 - 13:59 |
The Cyber Crystal Ball: The Annual Policy @ DEF CO . . .
|
Matthew Wein,Bruce Schnei . . . |
| 14:00 - 14:30 |
The Liability Stack: When Code Becomes Conduct
|
Carole House |
| 14:00 - 15:30 |
Strengthening the CVE Ecosystem (Seating is limite . . .
|
John Banghart,Elizabeth E . . . |
| 15:30 - 16:30 |
Privacy's Defender: How Hackers Protected the Inte . . .
|
Cindy Cohn |
| 15:30 - 16:30 |
When AI Finds Everything: Vulnerability Policy for . . .
|
Alec Summers,Lindsey Cerk . . . |
| 16:00 - 16:30 |
Building a State Wide VDP: Lessons from Maryland's . . .
|
01dbae |
| 16:30 - 16:59 |
Legally Hacked: how countries decide when security . . .
|
Katharina "Kat S" Sommer |
| 16:30 - 17:59 |
Filibuffer Overflow: Hackers Stage A Congressional . . .
|
Katherine Pratt,Jeff Roth . . . |
| | |
| Saturday |
|
|
| 10:00 - 10:59 |
Whose Agent Is It Anyway? Agency, Authorization, a . . .
|
Andreas Kaltsounis,Jacob . . . |
| 10:00 - 10:59 |
Journey to Create an All-state Cybersecurity Plan . . .
|
Craig "jafo" Buchanan |
| 11:00 - 11:59 |
From Policy to Prod: How a Frontier AI Lab Enforce . . .
|
Grant Versfeld,David "0xd . . . |
| 12:30 - 13:30 |
Privacy You Inherit: How Cultural History Writes t . . .
|
Tati |
| 12:00 - 12:59 |
Europe’s Expanding Role in Global Vulnerability . . .
|
Nuno Rodrigues Carvalho,R . . . |
| 13:30 - 13:59 |
The Subverted Hacker
|
Robert "zizkill" Shala |
| 13:00 - 13:59 |
Surprise Session - Check Hacker Tracker
|
|
| 14:00 - 14:30 |
The best of three bad ideas? Ransomware taxes in l . . .
|
Joe Uchill |
| 14:30 - 15:30 |
From Disclosure to Defense: Rebuilding Vulnerabili . . .
|
Lindsey Cerkovnik,John Ba . . . |
| 15:30 - 15:59 |
Assume Breach, But For Real: Rewriting Infrastruct . . .
|
Travis Berent,Adam Hickey |
| 16:00 - 16:59 |
Securing the Safety Net: Why Healthcare Cybersecur . . .
|
Sahan Fernando,James Bowi . . . |
| 17:00 - 17:30 |
AI Safety Theater: What the RAISE Act Regulates . . .
|
Joshua Marpet |
| 17:00 - 17:59 |
The Closing Window: Governing Agentic AI Security . . .
|
Taylor Roberts,Mitch Herc . . . |
| | |
| Sunday |
|
|
| 11:00 - 11:59 |
Strategic Resistance: How a Global Network is Figh . . .
|
Michael Brennan,Nadine Fa . . . |
| 12:00 - 12:30 |
Inference in the Infrastructure: Developing NIST A . . .
|
Raymond Sheh,Martin Stanl . . . |
| 12:30 - 13:59 |
Tactical Advocacy: Panel & Peer Sessions with EFF
|
Thorin Klosowski,Cooper " . . . |
| PDT Times |
Title |
speaker |
| | |
| Friday |
|
|
| 10:00 - 17:59 |
From Kiosk to Domain Compromise: Learning to Walk . . .
|
Ezra Woods,Mike Manrod,Sp . . . |
| 10:00 - 17:59 |
BloodHound Quest
|
Hugo van den Toorn |
| 10:00 - 11:59 |
Post-Exploitation of the Desktop with JS-Tap
|
Drew Kirkpatrick |
| 10:00 - 11:59 |
Red Team Express
|
Cody Spooner |
| 10:00 - 11:59 |
Zero Signal: Operating Where Defenders Can't See
|
Gowthamaraj Rajendran |
| 10:00 - 11:59 |
Falco Hunt: Evading Runtime Detection in Kubernete . . .
|
Michael Reimsbach |
| 10:00 - 10:59 |
Opening Panel - "Is Red Teaming Dead?"
|
Ads Dawson,Ben "NahamSec" . . . |
| 10:00 - 10:59 |
The Entropy Illusion: High-Speed Cracking on a Bud . . .
|
Chris Claunch |
| 10:00 - 11:59 |
RFID Bootcamp: Unleashed!
|
Evan Cook |
| 11:00 - 11:59 |
Trusted Launcher, Untrusted Code: Weaponizing AppL . . .
|
Nathan Sawyer |
| 11:00 - 11:59 |
COM Hijacking Voodoo: Tradecraft, Detection Blind . . .
|
Nikos "nickvourd" Vourdas |
| 11:00 - 11:59 |
Exploiting Private 5G: Unauthenticated Access to D . . .
|
Aumkaareshwar DS |
| 12:00 - 13:59 |
Burning Redirectors Before Blue Team Does
|
Mohamed AbuMuslim,Saad Na . . . |
| 12:00 - 13:59 |
From Application Telemetry Exposure to Cross-Servi . . .
|
Chirag Savla,Raunak "Trou . . . |
| 12:00 - 13:59 |
Web Hacking Bootcamp
|
Emma Latuszek |
| 12:00 - 13:59 |
Your Passkeys Won't Save You: Conditional Access B . . .
|
Doug Mooney,Jared Dobbela . . . |
| 12:00 - 12:59 |
macOS Doesn’t Get Malware…Until It Does
|
Zoziel Freire |
| 12:00 - 12:59 |
BloodHound OpenGraph Crash Course
|
JD D |
| 13:00 - 13:59 |
Shapeshifting C2: Applying DAITA Traffic Shaping t . . .
|
Rafael Felix |
| 13:00 - 13:59 |
One Request to Rule Them All
|
Corey Ball |
| 13:00 - 13:59 |
BloodHound OpenGraph: Six Degrees of Everything
|
Rohan Vazarkar,Wes Miller |
| 14:00 - 15:59 |
Cloud-Native C2: Weaponizing Trusted Infrastructur . . .
|
Dhiraj Mishra |
| 14:00 - 15:59 |
Quality over Quantity: How to Publish CVEs that Ac . . .
|
Natan Morette |
| 14:00 - 15:59 |
Automated Mythic Deployment with Gaia
|
Shad Brown |
| 14:00 - 15:59 |
Social Engineering With Reel
|
James Williams |
| 14:00 - 14:59 |
Microsoft and Amazon are my Favorite C2 Providers
|
Robert Pimentel |
| 14:00 - 14:59 |
Extension Hollowing: Abusing Chrome's Extension Tr . . .
|
Gordon Long |
| 15:00 - 15:59 |
Trust the Pipeline, Lose the Kingdom: Hands-On Clo . . .
|
Shane Young |
| 15:00 - 15:59 |
LLM-Coached Red Team Tactics to Attack Zero Trust
|
Rudy Ristich,Vijay Anand |
| 16:00 - 17:59 |
EvilEssid: Evading Wireless Intrusion Prevention S . . .
|
Miguel Fernandez |
| 16:00 - 17:59 |
redStack: Boot-To-Breach Red Team Platform
|
Michael Kim,Michael Ortiz |
| 16:00 - 17:59 |
Haetae: An Agent to Takedown North Korean C2 Serve . . .
|
Mauro Eldritch,Nelson Raf . . . |
| 16:00 - 17:59 |
Praetor: An OPSEC Exposure Advisor for Empire Oper . . .
|
Andrea Brosio,Ariz Sorian . . . |
| 16:00 - 16:59 |
Trust Me, Bro: A field guide to Windows Authentico . . .
|
Fagan Afandiyev |
| 16:00 - 16:59 |
Network Implants: Lessons Learned Building Reliabl . . .
|
Hassan Mohamad |
| | |
| Saturday |
|
|
| 10:00 - 11:59 |
From Path Traversal to Domain Credentials in 90 Se . . .
|
Mike Lisi |
| 10:00 - 11:59 |
PMTC: One-Click RCE and Persistent Exfil in AI Cod . . .
|
Ahmet Furkan Aydogan |
| 10:00 - 11:59 |
MCP Servers: The Next Enterprise Attack Surface
|
Apoorwa Joshi,Justin Dray |
| 10:00 - 11:59 |
Hands-On Autonomous Pentesting with Pentest Copilo . . .
|
Dhruva Goyal,Sitaraman Su . . . |
| 10:00 - 10:59 |
Inside the Red Team Cabal: A Decade of Lessons fro . . .
|
Jason Strange,Wes Thurner |
| 10:00 - 11:59 |
Living Off the Vault
|
Alexandru Uifalv,Jennifer . . . |
| 10:00 - 11:59 |
Pyramid of Pain-Red Team (Human and Technical Fric . . .
|
Frank Victory |
| 11:00 - 11:59 |
DPAPI Is Not a Boundary: A Full Infostealer Kill C . . .
|
Filipi Pires |
| 11:00 - 11:59 |
The Authentic Operator: Social Engineering Through . . .
|
Joanna - |
| 12:00 - 13:59 |
Ouroboros Attack! Recursive AI-Assisted 0-Day Hunt . . .
|
Mehmet Önder Key,Temel D . . . |
| 12:00 - 13:59 |
Command & Conquer: Hands-on C2 Primer with Mythic
|
Logan MacLaren |
| 12:00 - 13:59 |
Building Hackbots
|
Jason "jhaddix" Haddix,Ry . . . |
| 12:00 - 13:59 |
Red Teaming Kubernetes: From App-Level CVEs to Ful . . .
|
Lenin Alevski |
| 12:00 - 12:59 |
Agentic AI Supply chain Vulnerability lab
|
Aamiruddin Syed,N A |
| 12:00 - 12:59 |
The Protocol-Native Adversary: Full-Spectrum ICS S . . .
|
Blessen Thomas,Javier Her . . . |
| 13:00 - 13:59 |
You Can't Block My C2 — It's Your Google Calenda . . .
|
Nishant Tayade |
| 13:00 - 13:59 |
Stop Chasing Domain Admin: Designing Red Team Exer . . .
|
Billy Giles |
| 14:00 - 15:59 |
Crawlee - Improving crawling with an LLM
|
Daniel Goldberg |
| 14:00 - 15:59 |
Living Off Someone Else's Inference
|
Armend Gashi,Redon Gashi |
| 14:00 - 15:59 |
AIMARU C2: The New Era of LotL (MCP AI-Driven C2)
|
Mario Lobo |
| 14:00 - 15:59 |
BloodBash: Lightweight CLI Python BloodHound Alter . . .
|
Anthony Russell |
| 14:00 - 14:59 |
Turning Keys and Opening Doors: Leveraging AI Hype . . .
|
Will Alexander |
| 14:00 - 14:59 |
Chaining Credentials Through the AI Infrastructure . . .
|
Nathan Keys |
| 15:00 - 15:59 |
Requiem for the Decommissioned: When Dead Hosts Bi . . .
|
Yekaterina Shevchenko |
| 15:00 - 15:59 |
Breaking MCP Trust Boundaries: Cross-Server Author . . .
|
Yevhen Pervushyn |
| 16:00 - 17:59 |
The Quantum Mechanic: Attacking all the clouds
|
Moses Frost |
| 16:00 - 17:59 |
Evading EDR in ATM
|
Arnold Jared Morales Yepe . . . |
| 16:00 - 17:59 |
MalSkill: Weaponizing AI Agent Skills for Persiste . . .
|
Nur Gucu |
| 16:00 - 17:59 |
Writing Production-Grade Exploits in go-exploit
|
Landon Rice |
| 16:00 - 16:59 |
Control + C = Control Me
|
Andrew Griess |
| 16:00 - 16:59 |
OSINT for Hackers Redux
|
Lee McWhorter,Sandra Stib . . . |
| 17:00 - 17:59 |
Below the Threshold: Real-World APT Tradecraft for . . .
|
Jonathan Coradi,Oliveira . . . |
| | |
| Sunday |
|
|
| 10:00 - 14:59 |
Attack Campaign in VR
|
James Rice |
| 10:00 - 11:59 |
Tokens and PRT: Advanced Attacks and Persistence i . . .
|
Elzer Pineda,Jose Rivas |
| 10:00 - 11:59 |
0-Day Hunting Table: Come Join the Vulnpocalypse
|
Chris Haller |
| 10:00 - 11:59 |
Evil Is Always a Bad Stylist: .NET Obfuscation wit . . .
|
Alexander Rodchenko,Ashle . . . |
| 10:00 - 10:59 |
Beyond NPPSPY: Harvesting Credentials via Windows . . .
|
Sohail Saha |
| 10:00 - 10:59 |
Beyond the Flag: How CTF Players Become Product Se . . .
|
Drew Thompson,Monish Alur . . . |
| 10:00 - 10:59 |
Direct Network Access for Command and Control
|
Andrew Rioux |
| 11:00 - 11:59 |
Living Off WebView2: Turning Microsoft’s Browser . . .
|
Murilo Caixeta |
| 11:00 - 11:59 |
Commit, Push, Compromise: Attacking Modern GitHub . . .
|
Andrew Buchanan,Max CM |
| 12:00 - 13:59 |
Do you feel in control? Analysis of AWS CloudContr . . .
|
Bleon "gl4ssesbo1" Proko |
| 12:00 - 13:59 |
From Buffer Overflow to Blackout: Chaining Attacks . . .
|
Fernando Mengali,Thiago C . . . |
| 12:00 - 13:59 |
The Air Is Hostile: RF Trust Assumptions in Modern . . .
|
Mitch Breton |
| 12:00 - 13:59 |
Living Off the IDE: From Initial Access to Covert . . .
|
Edo Maland |
| 12:00 - 12:59 |
Agenthound: Mapping Multi-Hop Credential Chains Ac . . .
|
Adithyan Arun Kumar |
| 12:00 - 12:59 |
Breaking and Defending NEURO: Hands-On AI Stack At . . .
|
Jason Ludwig |
| 13:00 - 13:59 |
M0us3: A Lightweight, Multi Session C2 Framework w . . .
|
Aryan Jogia |
| 13:00 - 13:59 |
Hacking the Human-in-the-Loop
|
Alexander "Zombie",Lee Mc . . . |
| 14:00 - 14:59 |
beacon injected with HOOKCHAIN 2026
|
Arnold Jared Morales Yepe . . . |
| 14:00 - 14:59 |
Ghost in the Water: Simulating a Nation-State PLC . . .
|
Blessen Thomas,Javier Her . . . |
| 14:00 - 14:59 |
DFMI: Weaponizing MSI Installers for Fileless Code . . .
|
Anıl Çelik |