Las Vegas Convention Center, Level 1, West Hall 2, Booth# 604
Village Hours
| Day 1 | Friday, August 7 | Village Hours - 10am-6pm PODs - 11am-5pm |
|---|---|---|
| Day 2 | Saturday, August 8 | Village Hours - 10am-6pm PODs - 11am-5pm |
| Day 3 | Sunday, August 9 | Village Hours - 10am-1pm PODs - 11am-1pm |
All times are in Pacific Time(GMT -7)
Day 1 - August 07, 2026
10:15
Pentesting made easy - Keeping sessions alive with session chains
Arsenal All Audiences 60 min 90 min 120 min
Kai Glauber
Matthias Göhring
10:30
Burp, But Yours: Hands-On Extension and Bambda Development
Workshop Intermediate 3 Hours
Hannah L
11:00
Clash of Prompts: The World's First Prompt Battle Royale
POD All AudiencesJerome Robert
Edouard Viot
11:10
11:50
12:30
From Prompts to Payloads: Exploiting the AI-AppSec Intersection
Workshop Intermediate 2 Hours
Ariel Fogel
Eilon Cohen
Danus
12:45
Drogonsec: SAST + SCA + Secrets + IaC in one open-source scanner
Arsenal All Audiences 60 min 90 min
Filipi Pires
13:00
AppSec Quiz Gauntlet: Spot the Vulnerability
POD All Audiences
Tal Folkman
Darren Meyer
Alon Lerner
13:30
Agentic Chaos - What 86K+ Agent Codebases Reveal About 700K+ Exposed AI Systems
Talk All Audiences
Bar Kaduri
Lidan
14:00
Farsight: Turning OSINT into Actionable Attack Surface Intelligence
Arsenal Intro 60 min
Arif
Seedon D'Souza
Sai Vernekar
kvprashant
14:10
from_pretrained() to from_pwned(): Breaking HuggingFace's Trust
Talk Intermediate
Yotam Perkal
14:30
14:50
GeoHacking: from memory corruption RCE to cross tenant access
Talk Intermediate
Michal Kamensky
15:00
15:15
IDEViewer - Securing Developer Workstations from IDE Supply Chain Threats
Arsenal Intermediate 60 min
securient
15:30
Zero Trust Kubernetes Security: Preventing Real World Container Attacks
Talk Intermediate
Janakiram Meka
16:10
Man-in-the-Browser: Hijacking Javascript APIs for Browser Persistence and Credential Theft
Talk Intermediate
Aarav Juneja
16:30
Rebuilding Code Security with Signal, Speed and AI
Arsenal All Audiences 60 min
Shasheen Bandodkar
Derek C.
16:50
Most threat modeling artifacts don't help coding agents fix business logic. Here's what does.
Talk All Audiences
Meitar Ronen
17:30
Trust No History: Why Every "Remembered" Interaction is a Potential Backdoor
Talk Intermediate
Barno Kaharova
Rico Komenda
Day 2 - August 08, 2026
10:15
Prompt Injection: Attacking and Defending AI-Powered Applications
Workshop All Audiences 3 Hours
Mohammed Ilyas Ahmed
In Untrust We Can Trust: Enforcing Trust Boundaries for Humans and AI Alike
Arsenal Intermediate 60 min 90 min 120 min
Yariv Tal
10:30
11:00
Pentester vs AI: Race The Machine, In Real Life
POD All Audiences
Samantha Pearlstein
Gwendal Mognier
11:10
What Your Coding Agent Did Last Night: Runtime Security for AI Coding Agents
Talk Intermediate
Inga Cherny
11:30
Precogly: Open-Source Threat Modeling for the AI-Coding Era
Arsenal Intermediate 90 min 120 min
Vikramaditya Narayan
11:50
How Shadow APIs Become an Attacker's Free Pass Into Your Cloud-Native App
Talk Intermediate
Emma Fang
Krity
12:30
12:45
OWASP FinBot CTF: Hands-On Agentic AI Threats
Arsenal All Audiences 60 min
Helen Oakley
saikishu
13:00
AppSec Quiz Gauntlet: Spot the Vulnerability
POD All Audiences
Alon Lerner
Tal Folkman
Darren Meyer
13:15
13:30
14:00
14:10
Every ride you take - Hacking a City’s Public Transportation
Talk All Audiences
Ignacio Navarro
14:50
Pattern, Graph, Prompt: What Happens When You Layer Three Analysis Paradigms on the Same Codebase
Talk Intermediate
Mudita Khurana
15:00
AppSec Quiz Gauntlet: Spot the Vulnerability
POD All Audiences
Tal Folkman
Darren Meyer
Alon Lerner
15:15
Proactive Malicious Package Defense
Arsenal Intermediate 60 min 90 min 120 min
Darren Meyer
15:30
16:10
The API Made Me Do It - Do Bad APIs Lead AI to Generate Vulnerable Code?
Talk Intermediate
Yariv Tal
16:15
Code to Cloud: Secure Modern Applications Using Open-Source Tools
Workshop Intermediate 2 Hours
Mackenzie
16:30
Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence
Arsenal All Audiences 60 min 90 min 120 min
Jordan Bonagura
16:50
No Jailbreak Required: Pwning AI Agents Through the Tools They Trust
Talk All Audiences
saikishu
Helen Oakley
17:30
From Prompts to Production: Discovering Exposed PII & IDORs in AI-Generated Apps
Talk Intermediate
Samantha Pearlstein
Day 3 - August 09, 2026
10:15
ROP for the Web: Smuggling XSS, SQLi, and Web Shells Past Every WAF Using Compression Dictionaries
Arsenal Advanced 60 min 90 min 120 min
alevsk
Introduction to AI-Enhanced Threat Modeling Workshop
Workshop Intermediate 3 Hours
Robert Hurlbut
10:30
From commit to compromise: securing the full pipeline with AI-assisted remediation
Talk All Audiences
Filipi Pires
11:00
AppSec Quiz Gauntlet: Spot the Vulnerability
POD All Audiences
Alon Lerner
Tal Folkman
Darren Meyer
Clash of Prompts: The World's First Prompt Battle Royale
POD All AudiencesJerome Robert
Edouard Viot
11:10
Extending Shared Threat Models with the Application Attack Matrix
Talk All Audiences
J Fridley
Avi Lumelsky
Uri Katz
11:30
search_vulns: Navigating the Fragmented Landscape of Vulnerability Data
Arsenal All Audiences 60 min 90 min 120 min
Dustin Born
Matthias Göhring
11:50
Finding Bugs Is Easy, Patching Isn't: Build Your Own Remediation Pipeline
Talk Intermediate
Naveen
Mohan Kumar
12:45
The Agent Asked. We Allowed. Now What?
Arsenal All Audiences 60 min 90 min 120 min
Liran Lavi
Sarit Yerushalmi
Keren Elazari
Samantha Pearlstein
Gwendal Mognier
Patrick Smyth
Iggy
Simcha K
Patrick Smyth
some-natalie
Dmitry Raidman
Philippe Dourassov
Patrick Smyth
Jason Haddix
Raphael Silva
Dmitry Raidman
Patrick Smyth
Adam Shostack
Mackenzie
Or Sahar
Pedro Fortuna
Helen Oakley
Dmitry Raidman
William Reyor
Andy Dennis
Dmitry Raidman
Jenn Gile
Dmitry Raidman
Rein Daelman