Las Vegas Convention Center, Level 1, West Hall 2, Booth# 604

Village Hours

Day 1 Friday, August 7 Village Hours - 10am-6pm
PODs - 11am-5pm
Day 2 Saturday, August 8 Village Hours - 10am-6pm
PODs - 11am-5pm
Day 3 Sunday, August 9 Village Hours - 10am-1pm
PODs - 11am-1pm

All times are in Pacific Time(GMT -7)

Day 1 - August 07, 2026

10:15

10:15 - 11:15

Pentesting made easy - Keeping sessions alive with session chains

Arsenal All Audiences 60 min 90 min 120 min

Kai Glauber

Matthias Göhring

10:30

10:30 - 12:30

Burp, But Yours: Hands-On Extension and Bambda Development

Workshop Intermediate 2 Hours 3 Hours

Hannah L

10:30 - 11:00

The Dots Do Matter: Gmail's Invisible Blindspot

Talk All Audiences

Keren Elazari

11:00

11:00 - 13:00

Hack the Duck Store

POD All Audiences

Samantha Pearlstein

Gwendal Mognier

11:00 - 13:00

Cards Against Vulnerabilities

POD All Audiences

Patrick Smyth

11:10

11:30

11:30 - 12:30

Aegis of the Vulnerable: A Unified Pipeline for AI-Based SAST

Arsenal All Audiences 60 min 90 min 120 min

Can Oztas

11:50

12:30

12:45

12:45 - 13:45

Drogonsec: SAST + SCA + Secrets + IaC in one open-source scanner

Arsenal All Audiences 60 min 90 min

Filipi Pires

13:00

13:00 - 15:00

AppSec Quiz Gauntlet: Spot the Vulnerability

POD All Audiences

Avek Kolech

13:00 - 15:00

AI Pentesting Trivia Showdown

POD All Audiences

Andy Dennis

Bill Reyor

13:00 - 15:00

Cards Against Vulnerabilities

POD All Audiences

Patrick Smyth

13:10

13:50

14:00

14:00 - 15:00

Farsight: Turning OSINT into Actionable Attack Surface Intelligence

Arsenal Intro 60 min

Arif

Seedon D'Souza

Sai Vernekar

kvprashant

14:30

14:30 - 15:00

GeoHacking: from memory corruption RCE to cross tenant access

Talk Intermediate

Michal Kamensky

14:30 - 17:00

Container Escapes 101

Workshop Intermediate 2 Hours 2.5 Hours

some-natalie

15:00

15:00 - 17:00

NPM Imposters - The malware detection card game

POD All Audiences

Mackenzie

15:00 - 17:00

AI Pentesting Trivia Showdown

POD All Audiences

Andy Dennis

Bill Reyor

15:00 - 17:00

Cards Against Vulnerabilities

POD All Audiences

Patrick Smyth

15:00 - 17:00

SBOM Find the Flaws

POD All Audiences

Dmitry Raidman

15:10

15:15

15:50

16:30

16:30 - 17:30

Rebuilding Code Security with Signal, Speed and AI

Arsenal All Audiences 60 min

Shasheen Bandodkar

Derek C.

17:10

17:10 - 17:40

Trust No History: Why Every "Remembered" Interaction is a Potential Backdoor

Talk Intermediate

Barno Kaharova

Rico Komenda

Day 2 - August 08, 2026

10:15

10:15 - 13:00

Prompt Injection: Attacking and Defending AI-Powered Applications

Workshop All Audiences 3 Hours

Mohammed Ilyas Ahmed

10:15 - 11:15

In Untrust We Can Trust: Enforcing Trust Boundaries for Humans and AI Alike

Arsenal Intermediate 60 min 90 min 120 min

Yariv Tal

10:30

10:30 - 11:00

Building Hackbots

Talk All Audiences

Jason Haddix

11:00

11:00 - 13:00

SBOM Find the Flaws

POD All Audiences

Dmitry Raidman

11:00 - 13:00

Code Invaders: Stop The Insecure Code

POD All Audiences

Mackenzie

11:00 - 13:00

Cards Against Vulnerabilities

POD All Audiences

Patrick Smyth

11:00 - 13:00

Pentester vs AI: Race The Machine, In Real Life

POD All Audiences

Samantha Pearlstein

Gwendal Mognier

11:10

11:30

11:30 - 12:30

Precogly: Open-Source Threat Modeling for the AI-Coding Era

Arsenal Intermediate 90 min 120 min

Vikramaditya Narayan

11:50

11:50 - 12:20

Past the Bouncer: The Limits of CSP, Eleven Years In

Talk Intermediate

Pedro Fortuna

12:30

12:30 - 13:00

Threat Modeling LLMs with PHANTOM-B

Talk Intermediate

Adam Shostack

12:45

12:45 - 13:45

OWASP FinBot CTF: Hands-On Agentic AI Threats

Arsenal All Audiences 60 min

Helen Oakley

saikishu

13:00

13:00 - 15:00

AI Pentesting Trivia Showdown

POD All Audiences

Andy Dennis

Bill Reyor

13:00 - 15:00

Code Invaders: Stop The Insecure Code

POD All Audiences

Mackenzie

13:00 - 15:00

AppSec Quiz Gauntlet: Spot the Vulnerability

POD All Audiences

Avek Kolech

13:10

13:15

13:50

13:50 - 14:20

Every ride you take - Hacking a City’s Public Transportation

Talk All Audiences

Ignacio Navarro

14:00

14:00 - 15:00

OWASP AIBOM Generator

Arsenal All Audiences 60 min

Helen Oakley

Dmitry Raidman

14:30

15:00

15:00 - 17:00

AI Pentesting Trivia Showdown

POD All Audiences

William Reyor

Andy Dennis

15:00 - 17:00

SBOM Find the Flaws

POD All Audiences

Dmitry Raidman

15:00 - 17:00

AppSec Quiz Gauntlet: Spot the Vulnerability

POD All Audiences

Avek Kolech

15:10

15:10 - 15:40

How Malicious AI Skills Hijack Your Agents

Talk Intermediate

Jenn Gile

15:15

15:15 - 16:15

Proactive Malicious Package Defense

Arsenal Intermediate 60 min 90 min 120 min

Darren Meyer

15:50

16:15

16:15 - 18:00

Code to Cloud: Secure Modern Applications Using Open-Source Tools

Workshop Intermediate 2 Hours

Mackenzie

16:30

16:30 - 17:30

Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence

Arsenal All Audiences 60 min 90 min 120 min

Jordan Bonagura

16:30 - 17:00

No Jailbreak Required: Pwning AI Agents Through the Tools They Trust

Talk All Audiences

saikishu

Helen Oakley

17:10

Day 3 - August 09, 2026

10:15

10:15 - 13:00

Introduction to AI-Enhanced Threat Modeling Workshop

Workshop Intermediate 3 Hours

Robert Hurlbut

10:30

11:00

11:00 - 13:00

NPM Imposters - The malware detection card game

POD All Audiences

Mackenzie

11:00 - 13:00

Clash of Prompts: The World's First Prompt Battle Royale

POD All Audiences

Darren McNelis

Jerome Roberts

11:00 - 13:00

SBOM Find the Flaws

POD All Audiences

Dmitry Raidman

11:00 - 13:00

AppSec Quiz Gauntlet: Spot the Vulnerability

POD All Audiences

Avek Kolech

11:10

11:30

11:30 - 12:30

search_vulns: Navigating the Fragmented Landscape of Vulnerability Data

Arsenal All Audiences 60 min 90 min 120 min

Dustin Born

Matthias Göhring

11:50

12:45

12:45 - 13:45

The Agent Asked. We Allowed. Now What?

Arsenal All Audiences 60 min 90 min 120 min

Liran Lavi

Sarit Yerushalmi

Our 2026 Sponsors

Platinum Sponsors


Gold Sponsors


Silver Sponsors


Bronze Sponsors

Is your organization passionate about application security and want to sponsor?

Read on how to become a sponsor and checkout our available sponsorship opportunities.