{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.3.0.dev0", "url": "https://event.sec-t.org"}, "schedule": {"url": "https://event.sec-t.org/sec-t-2026/schedule/", "version": "0.15", "base_url": "https://event.sec-t.org", "conference": {"acronym": "sec-t-2026", "title": "SEC-T 2026", "start": "2026-09-09", "end": "2026-09-11", "daysCount": 3, "timeslot_duration": "00:05", "time_zone_name": "Europe/Stockholm", "colors": {"primary": "#9e3333"}, "rooms": [{"name": "Main hall", "slug": "5235-main-hall", "guid": "8a767cc4-aaee-5709-866c-768f554d1298", "description": "The big room where presentations are held. Also called M\u00e4sshallen.", "capacity": null}, {"name": "Mobile Hacking Village", "slug": "6338-mobile-hacking-village", "guid": "6d8d9a64-5926-59cc-bdde-2da169b0549f", "description": null, "capacity": null}, {"name": "Club SEC-T (Riddarsalen)", "slug": "5238-club-sec-t-riddarsalen", "guid": "6b948f01-90d9-54dd-85f2-86ab166246e4", "description": "\"Riddarsalen\", a big room you reach if you take the stairs from the entrance but go higher up than the Main hall level", "capacity": null}, {"name": "Hardware Hacking Village", "slug": "5236-hardware-hacking-village", "guid": "3d8ac7fb-92c5-5c1e-8ed7-fcefdaf25025", "description": "HHV, Hardware Hacking Village, located beyond the community area, three floors up", "capacity": 60}, {"name": "Community Area (Poseidon)", "slug": "5237-community-area-poseidon", "guid": "898eb470-c734-5a22-bebb-f1821ae6fe5c", "description": "\"Poseidon\", a conference room in the Community Area", "capacity": 20}, {"name": "Spillover Area (Tegelsalen)", "slug": "6256-spillover-area-tegelsalen", "guid": "3440a8f9-d074-586d-8c7d-17c89b995b1a", "description": "Tegelsalen, go through the Community Area and one floor down", "capacity": null}], "tracks": [], "days": [{"index": 1, "date": "2026-09-09", "day_start": "2026-09-09T04:00:00+02:00", "day_end": "2026-09-10T03:59:00+02:00", "rooms": {"Main hall": [{"guid": "1b7526e0-4628-54bd-9817-02f93e4d7146", "code": "SNABLE", "id": 95464, "logo": null, "date": "2026-09-09T13:15:00+02:00", "start": "13:15", "end": "2026-09-09T14:00:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-95464-yippee-ki-yay-blockchain-exploiting-decentralized-systems-one-die-hard-at-a-time", "url": "https://event.sec-t.org/sec-t-2026/talk/SNABLE/", "title": "Yippee-Ki-Yay, Blockchain: Exploiting Decentralized Systems One Die Hard at a Time", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "Blockchain systems have redefined what it means for an attack to be permanent. Smart contracts are immutable by design; once deployed, their logic cannot be patched. Every vulnerability is forever, every stolen asset is gone, and the code is public for anyone to study and exploit. \n\nDespite governing hundreds of billions of dollars, these systems keep failing in ways that any security practitioner will recognize: logic bugs that trust the wrong sequence of operations, access control that collapses under social engineering, and infrastructure implants so well-engineered they remain invisible for weeks.\n\nIn this talk, we examine three landmark exploits through the lens of the Die Hard films. This is not a gimmick; each film captures something structurally true about the corresponding attack. Gruber exploiting Nakatomi's own vault logic. Terrorists who seized the control tower, not the planes. Simon Gruber keeping everyone chasing riddles while the real crew drills into the Federal Reserve. The analogy makes unfamiliar attack surfaces immediately intuitive for any security practitioner, regardless of blockchain background.\n\nWe cover the 2016 DAO hack ($60M), the Parity and Ronin multisig failures ($905M combined), and the 2025 CPIMP attack, a clandestine supply-chain implant across seven blockchains, invisible to every monitoring tool, defused in a 36-hour coordinated war room. Three failure classes: trust in your code, trust in your keyholders, trust in your infrastructure.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "8ADQZP", "name": "Sofia Bobadilla", "avatar": "https://event.sec-t.org/media/avatars/KDBSPP_4QCm9BA.webp", "biography": "Sofia Bobadilla is a 3rd year PhD student at KTH Royal Institute of Technology. Her research focuses on automated exploit generation and vulnerability repair for smart contracts, building systems that find and fix bugs before attackers do. Her work has been adopted as reference guidelines for AI-assisted security research in the Ethereum ecosystem, and she is a member of KTH's Software Supply Chain Security group CHAINS. In 2024 she won the ETHPrague hackathon with a code fix verification tool.", "public_name": "Sofia Bobadilla", "guid": "c091e982-88b8-565c-be72-9a7eb8c28dda", "url": "https://event.sec-t.org/sec-t-2026/speaker/8ADQZP/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/SNABLE/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/SNABLE/", "attachments": []}, {"guid": "201aba9b-ed67-594e-888a-a25bba0be5ee", "code": "MWT7BJ", "id": 105376, "logo": null, "date": "2026-09-09T14:00:00+02:00", "start": "14:00", "end": "2026-09-09T14:45:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-105376-the-ci-cd-escape-room-eleven-doors-zero-exploits", "url": "https://event.sec-t.org/sec-t-2026/talk/MWT7BJ/", "title": "The CI/CD Escape Room - Eleven doors, zero exploits.", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "Escape rooms are built to be escaped. One team, sixty minutes, a sequence of\nlocked doors where the key to each is hidden in the room before it.\n\nYour delivery pipeline was not built to be escaped. It just is.\n\nThis talk walks a single unbroken chain from \"ordinary employee with a source\ncontrol account\" to \"organization administrator of the entire cloud estate\",\nwithout a single CVE, exploit, or memory corruption bug. Every door is a\nconfiguration someone chose deliberately, for a defensible reason, in isolation.\nEleven of them in a row is a catastrophe.\n\nWe pick the locks in order. Default write access nobody audits. A Terraform plan\nthat runs attacker code before a human reviews anything. An environment gate that\nturns out to be a kitchen timer. A federation trust that checks the wrong claim.\nAn IAM edge that lets a service account promote itself. Then we run the whole\nthing again as a speedrun, with the clock on screen.\n\nBring your own pipeline. You will want to go and check something afterwards.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "8XXYFM", "name": "Jesper Larsson", "avatar": "https://event.sec-t.org/media/avatars/3ELAE3_FoxCl87.webp", "biography": "Jesper Larsson is an independent security researcher and penetration tester, and runs the security consultancy 0x4A. He tests the platforms companies build on, the pipelines they ship through, the identity systems holding it together, and the people who use them. Most engagements end the same way: a chain of small, individually reasonable decisions adding up to somebody owning production.\n\nHe featured in the Swedish TV series Hackad, and co-founded SecurityFest and S\u00e4kerhetspodcasten", "public_name": "Jesper Larsson", "guid": "a9407f07-3808-5f1c-8939-566467ca7295", "url": "https://event.sec-t.org/sec-t-2026/speaker/8XXYFM/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/MWT7BJ/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/MWT7BJ/", "attachments": []}, {"guid": "2eb27ac7-bfac-543d-b44b-6e5ba3dac1e9", "code": "JJGUWA", "id": 103494, "logo": null, "date": "2026-09-09T15:00:00+02:00", "start": "15:00", "end": "2026-09-09T15:30:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-103494-increasing-trust-with-measured-verified-boot", "url": "https://event.sec-t.org/sec-t-2026/talk/JJGUWA/", "title": "Increasing trust with measured & verified boot", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "DICE-like measured boot guarantees software integrity bound to a\nspecific hardware even on low-powered devices with no Trusted\nExecution Environment (TEE). An inherent problem in DICE-like measured\nboot is that the first mutable code cannot be updated without losing\ngenerated cryptographic keys.\n\nIn this talk I both introduce how we implemented DICE-like measured\nboot in an open source project and how we solved updating device\napplications without losing keys.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "8FDXES", "name": "Michael \"MC\" Cardell Widerkrantz", "avatar": "https://event.sec-t.org/media/avatars/F7LMHA_8Xwy7KI.webp", "biography": "MC has been programming professionally since 1995 and recreationally\nsince 1985. At Tillitis he's doing research and programming on all\nsoftware parts: the emulator, the firmware, the device apps, and the\nclient apps, as well as helping define the hardware/software\ninterface.", "public_name": "Michael \"MC\" Cardell Widerkrantz", "guid": "4425d663-254b-5cc0-b6da-9491f7dcc654", "url": "https://event.sec-t.org/sec-t-2026/speaker/8FDXES/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/JJGUWA/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/JJGUWA/", "attachments": []}, {"guid": "a6d7b3de-8734-5fa6-a675-560ca2ab6c60", "code": "UDGQL9", "id": 99629, "logo": null, "date": "2026-09-09T15:45:00+02:00", "start": "15:45", "end": "2026-09-09T16:15:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-99629-pwn2own-berlin-2026-20-000-agent2shell-pre-prompt-rces-in-claude-code-cursor-and-gemini", "url": "https://event.sec-t.org/sec-t-2026/talk/UDGQL9/", "title": "[Pwn2Own Berlin 2026 $20,000] Agent2Shell: Pre-Prompt RCEs in Claude Code, Cursor, and Gemini", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "Agent2Shell is a family of zero-day RCE chains against the three flagship AI coding agents (Anthropic Claude Code, Cursor, and Google Gemini), all reproducible on the latest stable builds with default settings on Windows. The chains have been responsibly disclosed to the affected vendors and are under coordinated embargo. HITCON 2026 will be the first comprehensive technical deep-dive on the full research set.\n\nWhat separates this work from the LLM-security research dominating the field today: the LLM is never invoked. Every chain triggers before any prompt reaches the model. Prompt Injection defenses, Guardrails, Output Filtering, and Agent Alignment all sit on the wrong side of the boundary and never observe the payload. We name this attack class Pre-Prompt RCE.\n\nSeveral chains are 0-click: open a folder, double-click a small file, or run a routine command, and arbitrary code executes on a fully patched Windows machine. The remainder require at most one user action. Several are bypasses of recently patched CVEs in the same products, evidence the patches addressed instances rather than the underlying class.\n\nThe talk reconstructs the trust-boundary, auto-approval, and config-pollution failure classes shared across all three vendors, and shows why the bug class will keep producing instances until vendors redesign rather than patch. Live demos reproduce the most striking 0-click and 1-click chains end-to-end on stage.", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "VAS3X8", "name": "Satoki", "avatar": "https://event.sec-t.org/media/avatars/H7SAZJ_bRur1qq.webp", "biography": "Web Application Tuntsun Shokunin, CTF Player, and Bug Hunter. Has delivered talks at major security conferences including AVTOKYO, Security Analyst Summit, Hack Fes., m0leCon, TyphoonCon Seoul, HITCON, DefCamp, Queen City Conference, and Kernelcon. At Pwn2Own Berlin 2026, achieved remote code execution on three products, including OpenAI Codex. A DEF CON CTF finalist, renowned for discovering and responsibly reporting vulnerabilities in major web services and software such as Google and Firefox.", "public_name": "Satoki", "guid": "452bc260-d9e9-5683-bfa4-4981b968dcf5", "url": "https://event.sec-t.org/sec-t-2026/speaker/VAS3X8/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/UDGQL9/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/UDGQL9/", "attachments": []}, {"guid": "c3e596be-f5e4-537b-bf36-9a509b477596", "code": "G9VQC9", "id": 105664, "logo": null, "date": "2026-09-09T16:15:00+02:00", "start": "16:15", "end": "2026-09-09T17:00:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-105664-hacker-jeopardy", "url": "https://event.sec-t.org/sec-t-2026/talk/G9VQC9/", "title": "Hacker Jeopardy", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "Come and play some fun Hacker Jeopardy!\n\n\n```\n _  _   __    ___  __ _  ____  ____      __  ____  __  ____   __   ____  ____  _  _  _   \n/ )( \\ / _\\  / __)(  / )(  __)(  _ \\   _(  )(  __)/  \\(  _ \\ / _\\ (  _ \\(    \\( \\/ )/ \\  \n) __ (/    \\( (__  )  (  ) _)  )   /  / \\) \\ ) _)(  O )) __//    \\ )   / ) D ( )  / \\_/  \n\\_)(_/\\_/\\_/ \\___)(__\\_)(____)(__\\_)  \\____/(____)\\__/(__)  \\_/\\_/(__\\_)(____/(__/  (_)  \n```", "description": null, "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/G9VQC9/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/G9VQC9/", "attachments": []}], "Hardware Hacking Village": [{"guid": "dccd3510-2deb-5d4c-b633-3a2bd57768b9", "code": "WUABQ9", "id": 104596, "logo": null, "date": "2026-09-09T14:00:00+02:00", "start": "14:00", "end": "2026-09-09T16:00:00+02:00", "duration": "02:00", "room": "Hardware Hacking Village", "slug": "sec-t-2026-104596-community-training-tv-b-gone-turn-off-tvs-and-learn-to-solder-wednesday", "url": "https://event.sec-t.org/sec-t-2026/talk/WUABQ9/", "title": "[Community Training] TV-B-Gone: Turn Off TVs and Learn to Solder! (Wednesday)", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "**Turning off TVs and monitors in public places is fun!**  \nLearn to solder by making a kit that turns off these annoyances from 50 meters away.  \n**For total beginners.**  \nEnjoy life, and turn off a TV or two today!  \n  \n**[TV-B-Gone](https://cornfieldelectronics.com/cfe/projects.php#tvbgone2)** is an **[open hardware](https://github.com/maltman23/TV-B-Gone-kit_V2)** remote control that can turn off any remotely controllable monitor in public places (or anywhere)! From across the street, through windows, in restaurants, bars, schools, airports... The new V2 of the kit makes it super easy to learn to solder, as well as easy to hack on.  \n  \n**Community Training Itinerary:**  \n* Intro to remote controls\u2006 \u2006 \n* Learn to solder by making your own TV-B-Gone, step by step\u2006 \u2006 \n* Target practice is available all over the world after the workshop\u2006 \u2006 \n  \n**Taught by**\u00a0Mitch Altman.  \n  \n**Materials cost:**  \nThe workshop is free, but if you would like to partake in the hands-on aspects of the workshop, Mitch will have materials for **\u20ac20**.  \n  \n**Duration**:  \nThis community training takes 2 hours.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "JZ7A9M", "name": "Mitch Altman", "avatar": "https://event.sec-t.org/media/avatars/VKYBYY_schVBje.webp", "biography": "[Mitch Altman](https://tinyurl.com/a3xme4c6) invented [TV-B-Gone](https://tvbgone.com) (turns off TVs in public), co-founded a [SillyValley](https://tinyurl.com/5cmktcv9) startup and [Noisebridge](https://noisebridge.net), pioneered [VR](https://tinyurl.com/4feevfuv), is an author, mentor, gives talks and workshops worldwide, performs on his [self-made synths](https://tinyurl.com/3kw227wx), promotes hackerspaces, open hardware, is founder of [Cornfield Electronics](https://tinyurl.com/5yymxemu).", "public_name": "Mitch Altman", "guid": "448a8798-3426-590e-806f-82a2cab92d90", "url": "https://event.sec-t.org/sec-t-2026/speaker/JZ7A9M/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/WUABQ9/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/WUABQ9/", "attachments": []}], "Community Area (Poseidon)": [{"guid": "5450e653-ce90-5819-8e7b-6c40eb5025c9", "code": "BZFPMW", "id": 104594, "logo": null, "date": "2026-09-09T09:00:00+02:00", "start": "09:00", "end": "2026-09-09T17:00:00+02:00", "duration": "08:00", "room": "Community Area (Poseidon)", "slug": "sec-t-2026-104594-community-training-introduction-to-cryptography-reverse-engineering-for-women", "url": "https://event.sec-t.org/sec-t-2026/talk/BZFPMW/", "title": "[Community Training] Introduction to cryptography reverse engineering for women", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "**Topic:** In this hands-on workshop, you will be facing a variety of encryption binary. Your mission, if you accept it, will be to code in Python a corresponding decryptor.\n\nWe are going to discover some cryptographic algorithm implementation (including RC4, AES, Salsa20 and Chacha20), some hashing function (including MD5, SHA-1 and SHA256). \nIf you don\u2019t know these algorithms, then this workshop is for you", "description": null, "recording_license": "", "do_not_record": true, "persons": [{"code": "SYSKWJ", "name": "Caroline Leman", "avatar": null, "biography": "Caroline began her career in 2015 specializing in malware reverse engineering at national organizations like the CEA and ANSSI. She joined Synacktiv's reverse engineering team in 2023 to focus on vulnerability research.", "public_name": "Caroline Leman", "guid": "f055e73d-d907-5579-81cf-7e905dba9f6b", "url": "https://event.sec-t.org/sec-t-2026/speaker/SYSKWJ/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/BZFPMW/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/BZFPMW/", "attachments": []}], "Spillover Area (Tegelsalen)": [{"guid": "97b0553f-4174-5e24-9d79-23c2afb330e1", "code": "WCZPJC", "id": 104780, "logo": null, "date": "2026-09-09T09:00:00+02:00", "start": "09:00", "end": "2026-09-09T17:00:00+02:00", "duration": "08:00", "room": "Spillover Area (Tegelsalen)", "slug": "sec-t-2026-104780-community-lab-breaking-ai-guardrails-for-exploit-development", "url": "https://event.sec-t.org/sec-t-2026/talk/WCZPJC/", "title": "Community Lab: Breaking AI guardrails for exploit development", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Community Lab Session: This is not a training, it's a lab where hackers together explore how to break AI tool guard rails to produce a working exploit tool. It also includes a competition to see who can come up with the best working exploit for a minimally described advisory. Needs power, network, tables, chairs, radio mic.\n\nWeds community training lab. David Jacoby + 1 Helper", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "DCEJJT", "name": "David Jacoby", "avatar": "https://event.sec-t.org/media/avatars/KBG7ME_2S4cgWO.webp", "biography": "David Jacoby has dedicated his entire life to hacking and computer security the past 30+ years. From the underground hacking era to boardrooms worldwide, he has uncovered critical vulnerabilities, pioneered IoT security research, advised Fortune 500 companies, founded Unbreached and Threat Prevention Center, and now serves as CSO at Syndis. An award-winning speaker, author, TV host, hacker, and your friendly internet troublemaker, he bridges hacker culture with human clarity.", "public_name": "David Jacoby", "guid": "2f823309-3ac6-5684-bcae-0474b74bbf70", "url": "https://event.sec-t.org/sec-t-2026/speaker/DCEJJT/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/WCZPJC/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/WCZPJC/", "attachments": []}]}}, {"index": 2, "date": "2026-09-10", "day_start": "2026-09-10T04:00:00+02:00", "day_end": "2026-09-11T03:59:00+02:00", "rooms": {"Main hall": [{"guid": "e25d8761-051b-5a6f-9d2e-534850f9f400", "code": "SAXFVL", "id": 98866, "logo": null, "date": "2026-09-10T09:15:00+02:00", "start": "09:15", "end": "2026-09-10T10:00:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-98866-vulnerable-sweden", "url": "https://event.sec-t.org/sec-t-2026/talk/SAXFVL/", "title": "Vulnerable Sweden", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "3rd party attacks happen all the time now, its mainstream. It has also hit Sweden with catastrofic outcome, and there is more to come. Today we will dig deep into the Public sector of Sweden, and their vendors. We have mapped every invoice to every municipality and found those that pose a high to critical risk towards Sweden and the municipalities. We will cover the data, the vulnerabilities and they dialogs between us, vendors, municipalities and agencies; With one goal in mind: What can we do to help out?", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "TFDVDW", "name": "Lucas Lundgren / acidgen", "avatar": "https://event.sec-t.org/media/avatars/9XASXN_xDT1bra.webp", "biography": "Lucas Lundgren is an offensive security specialist and penetration tester with 30+ years of hands-on hacking experience. Active in cybersecurity since childhood, he specializes in web, API, cloud, OAuth, and infrastructure security. Lucas is passionate about practical offensive security, AI-assisted pentesting, and real-world attack techniques, combining deep technical expertise with engaging storytelling and live demonstrations.", "public_name": "Lucas Lundgren / acidgen", "guid": "47cdfb6d-748f-57ba-b564-5d4942c5085f", "url": "https://event.sec-t.org/sec-t-2026/speaker/TFDVDW/"}, {"code": "FEZKSU", "name": "Vincent", "avatar": null, "biography": null, "public_name": "Vincent", "guid": "b83dbb6d-d7dc-560a-8a92-7f282dff2f42", "url": "https://event.sec-t.org/sec-t-2026/speaker/FEZKSU/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/SAXFVL/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/SAXFVL/", "attachments": []}, {"guid": "55fc2c8e-3731-5126-8cc8-b1b741f602fa", "code": "S3FKB8", "id": 99381, "logo": null, "date": "2026-09-10T10:30:00+02:00", "start": "10:30", "end": "2026-09-10T11:00:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-99381-from-metal-to-webusb-reimplementing-a-wi-fi-6-driver-beyond-the-kernel-for-offensive-security", "url": "https://event.sec-t.org/sec-t-2026/talk/S3FKB8/", "title": "From Metal to WebUSB: Reimplementing a Wi-Fi 6 Driver Beyond the Kernel For Offensive Security", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "Modern Wi-Fi chipsets are complex systems, but researching them often requires dealing with fragile vendor drivers, outdated kernel APIs and difficult debugging workflows. This talk presents a different approach: a complete implementation of the driver stack for the low-cost AicSemi aic8800 Wi-Fi 6 USB chipsets, first as a portable libusb userspace driver for both Linux and Windows, and then as a self-contained WebUSB application running directly inside the browser.\n\nThe project reconstructs the hardware initialization sequence, firmware loading process, USB transfer logic, receive and transmit paths and host-to-firmware command interface.\nBy moving the driver outside the kernel, the device becomes easier to instrument, fuzz and repurpose for offensive and defensive research, turning a cheap Wi-Fi dongle into a flexible platform for wireless reverse engineering and security research.\n\nThe second phase pushes the same model into the browser, through a retro terminal-style WebUSB interface, the user can interact directly with the hardware: send data to other clients, connect to networks, switch receive modes, enable raw frame injection, fuzz other network devices over the air and experiment with the runtime firmware rewriting feature for updating the firmware code during the driver execution.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "AEEHH9", "name": "Edoardo Mantovani", "avatar": "https://event.sec-t.org/media/avatars/U9NLLK_FfOTKI7.webp", "biography": "Independent (security) researcher with a specific focus on wireless firmware reverse engineering, kernel programming and software obfuscation. Previously spoken/accepted at Nullcon Berlin 2025, Hardwear.io USA 2026, CONFidence conference 2026, SEC-T 2026, Hack.lu 2026 and BlackAlps 2026.", "public_name": "Edoardo Mantovani", "guid": "df163600-fa2c-52e3-ba41-e42d2780d55e", "url": "https://event.sec-t.org/sec-t-2026/speaker/AEEHH9/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/S3FKB8/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/S3FKB8/", "attachments": []}, {"guid": "f59bdaf6-71f9-501c-b1b2-800828b73dad", "code": "V7CYNS", "id": 98750, "logo": null, "date": "2026-09-10T11:15:00+02:00", "start": "11:15", "end": "2026-09-10T12:00:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-98750-can-ai-do-novel-security-research-meet-the-http-terminator", "url": "https://event.sec-t.org/sec-t-2026/talk/V7CYNS/", "title": "Can AI do novel security research? Meet the HTTP Terminator", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it.\n\nIt worked - I'll share an arsenal of new HTTP desync triggers, gadgets, and exploits that compromised banks, security solutions, and government infrastructure. Then I'll trace each discovery chain back through the HTTP Terminator, showing how to turn your personal expertise into an autonomous weapon - and the dark arts required to make it lethal.\n\nI'll also share discoveries from beyond the autonomy horizon - some only reachable with a tight human/AI research loop, and others beyond AI's reach entirely. These include a powerful undisclosed recon technique, and anomalies that hint at new attack classes offering alternative paths to critical impact. I'll analyse the discovery process, sharing detailed experiments that probe the boundaries of what AI can and can't discover.\n\nYou'll leave with new exploits from desync triggers to undisclosed attack classes, and a blueprint for turning your instincts into an autonomous research cascade. And yes, I'll open-source the HTTP Terminator.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "ZRHPRD", "name": "James Kettle", "avatar": "https://event.sec-t.org/media/avatars/HUAD7Z_DIr3muM.webp", "biography": "James 'albinowax' Kettle is the Director of Research at PortSwigger, the makers of Burp Suite. His best-known research is HTTP Desync Attacks, which popularised HTTP Request Smuggling. Other popular attack techniques that can be traced back to his research include web cache poisoning, the single-packet attack, server-side template injection, and password reset poisoning. He's also the designer behind many of the topics and labs that make up the Web Security Academy.", "public_name": "James Kettle", "guid": "61796e4c-2abe-53b9-81f2-c0f7b3e54044", "url": "https://event.sec-t.org/sec-t-2026/speaker/ZRHPRD/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/V7CYNS/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/V7CYNS/", "attachments": []}, {"guid": "429a6c8a-e7f2-5f4d-9ce7-0018a2ab6b89", "code": "RJDZMF", "id": 103448, "logo": null, "date": "2026-09-10T13:15:00+02:00", "start": "13:15", "end": "2026-09-10T13:45:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-103448-born-corrupted-hack-the-planet-by-hijacking-linux-package-factories", "url": "https://event.sec-t.org/sec-t-2026/talk/RJDZMF/", "title": "Born Corrupted: Hack the Planet by Hijacking Linux Package Factories", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "Have you ever imagined compromising almost every user of a major Linux distribution?\n\n`apt upgrade`. `apk add`. `dnf update`. Every day, millions of servers execute these commands with absolute trust, relying on signatures to guarantee that an update is safe and official. But this only proves that a file successfully passed through a signing service at the very end of its journey. It does not validate the integrity of the massive, automated factory that built, processed, and advertised it. What happens when an attacker targets the distribution control plane itself?\n\nOver several months, we audited the backend infrastructure powering major Linux distributions, including Ubuntu, Alpine, and Fedora. Moving beyond common supply chain threats, we focused on the internal systems that decide what becomes official. We discovered multiple independent compromise chains that allowed us to subvert the software supply chain entirely from the inside. By exploiting flawed trust boundaries in build artifact processing, over-privileged automation workflows, and logical gaps in metadata generation, we demonstrated how attackers can trick official infrastructure into blindly building, stamping, and delivering malicious updates to users.\n\nThis talk pulls back the curtain on the hidden complexity of modern software distribution. Join us to explore how backend pipelines can be compromised and weaponized.\n\nThe package was signed. The pipeline wasn't.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "8Z9UUC", "name": "splitline", "avatar": "https://event.sec-t.org/media/avatars/LRR8JQ_IDAZAkY.webp", "biography": "Tsi-Lin \u201cSplitline\u201d Ng is a security researcher at DEVCORE and a member of the ${CyStick} CTF team, specializing in web and application security.\n\nHe has presented at Black Hat USA, Europe, and Asia, as well as HITCON and m0leCon. His research was featured in the 2024 \u201cTop 10 Web Hacking Techniques\u201d. He has awarded bug bounties from major companies including Google, Microsoft and X, and he won Pwn2Own Berlin 2026.\n\nYou can follow his latest updates on X at @_splitline_ or visit blog.splitline.tw", "public_name": "splitline", "guid": "916adf17-567a-53a9-ab51-39a173363f88", "url": "https://event.sec-t.org/sec-t-2026/speaker/8Z9UUC/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/RJDZMF/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/RJDZMF/", "attachments": []}, {"guid": "e0864988-2d61-59a4-8cc4-a95255a99d9a", "code": "JKAEJZ", "id": 93198, "logo": null, "date": "2026-09-10T13:45:00+02:00", "start": "13:45", "end": "2026-09-10T14:30:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-93198-reflecting-your-authentication-look-in-the-mirror-it-s-you", "url": "https://event.sec-t.org/sec-t-2026/talk/JKAEJZ/", "title": "Reflecting Your Authentication: Look in the Mirror - It\u2019s You", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "Authentication reflection was thought to be solved after MS08-068, but recent research shows that Windows still exposes multiple ways to coerce systems into authenticating to themselves. This talk explores modern reflection techniques involving Kerberos, NTLM, and SPN manipulation, and how they can still lead to privilege escalation or even domain compromise. I will also present a critical reflection vulnerability in Windows Admin Center (WAC) discovered in July 2025 and fixed by Microsoft in early 2026.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "NPBS98", "name": "andrea pierini", "avatar": null, "biography": "I\u2019m a Senior Security Consultant at Semperis with experience across software development, systems, networking, and security. My research focuses on authentication mechanisms, protocol inconsistencies, and privilege-escalation techniques in Windows environments. I enjoy hunting bugs, exploring new technologies, and sharing research through publications and conferences. Microsoft recognized me among the Top 100 MSRC Security Researchers in 2020 and 2022.", "public_name": "andrea pierini", "guid": "53f98f5d-6b22-5ea8-866f-e8415107e9a3", "url": "https://event.sec-t.org/sec-t-2026/speaker/NPBS98/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/JKAEJZ/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/JKAEJZ/", "attachments": []}, {"guid": "e1a89c0e-aad1-5343-baec-abe8538981ae", "code": "9MW3HU", "id": 100183, "logo": null, "date": "2026-09-10T14:45:00+02:00", "start": "14:45", "end": "2026-09-10T15:15:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-100183-the-pre-internet-computer-why-mainframe-security-breaks-cloud-era-thinking", "url": "https://event.sec-t.org/sec-t-2026/talk/9MW3HU/", "title": "The Pre Internet Computer Why Mainframe Security Breaks Cloud Era Thinking", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "Before the web. Before TCP/IP. Before \u201ccloud.\u201d\u2028Some of the most powerful computers in the world were already online.\nIBM mainframes didn\u2019t grow up in the browser era. System/360 (1964), System/390 (introduced in 1990 and dominant throughout the 1990s), and today\u2019s z/OS (released in 2000) were designed for batch jobs, green-screen terminals, and a world where the internet simply didn\u2019t exist\u2014yet these systems still quietly run banks, airlines, governments, and payment rails.\n\nThis talk is a guided tour of what happens when modern hackers bring cloud-era assumptions into a system that predates the web. We\u2019ll break down how mainframes actually organize work (JES, JCL, RACF, CICS, PR/SM), why \u201croot,\u201d shells, and ports don\u2019t mean what you think, and where attackers really interact with Big Iron today: transactions, protocols, management boundaries, and boring-looking misconfigurations that turn out to matter a lot.\n\nNo mainframe background required. No nostalgia cosplay needed. Just simple metaphors, diagrams, and stories from real red-team work\u2014ending with a short checklist you can use the next time you find a system in scope that\u2019s older than your favorite exploit class.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "83EY3E", "name": "Adam Toscher", "avatar": "https://event.sec-t.org/media/avatars/3WSYCK_NBSeT1O.webp", "biography": "Adam Toscher is a New York\u2013based security engineer and red team operator with 20+ years in offensive security, adversary simulation, and automation. A former IBM mainframe intern, he has held senior roles at Adobe, Optiv, Accenture, IBM X-Force, NYC Cyber Command, FDNY, and Cobalt Labs. His work focuses on realistic red-team operations, penetration testing, and practical security automation.", "public_name": "Adam Toscher", "guid": "82d3bdfd-52a6-52f1-ae10-e6dbbab90a73", "url": "https://event.sec-t.org/sec-t-2026/speaker/83EY3E/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/9MW3HU/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/9MW3HU/", "attachments": []}, {"guid": "96ab2c72-8c54-5311-a5c8-800f76f55686", "code": "LMLUSX", "id": 98919, "logo": null, "date": "2026-09-10T15:15:00+02:00", "start": "15:15", "end": "2026-09-10T15:45:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-98919-i-will-find-you-and-i-will-flag-you-hunting-malicious-packages-at-scale", "url": "https://event.sec-t.org/sec-t-2026/talk/LMLUSX/", "title": "I will find you and I will flag you: hunting malicious packages at scale", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "Since early 2025, software package maintainers have faced a sustained wave of attacks. Adversaries have used credential theft, exploitation of vulnerable CI/CD workflows, targeted social engineering, and adversary-in-the-middle (AiTM) phishing to compromise upstream packages. The damage is real: the Shai-Hulud worms, TeamPCP's compromise of Trivy and the LiteLLM PyPI package, and North Korea's takeover of the widely used Axios package. These attacks infected thousands of developers and pipelines.\n\nThis talk covers how we hunt for malicious and compromised packages at scale, give the community the right tools to do the same, and secure an internal engineering organization of over 3,000 engineers who install third-party packages every day.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "FG9TEQ", "name": "Christophe Tafani-Dereeper", "avatar": null, "biography": "Christophe lives in Switzerland and works on cloud security research and open source at Datadog. He previously worked as a software developer, penetration tester and cloud security engineer. Christophe is the maintainer of several open-source projects such as Stratus Red Team, GuardDog, CloudFlair, Adaz, and the Managed Kubernetes Auditing Toolkit (MKAT).", "public_name": "Christophe Tafani-Dereeper", "guid": "dc19630d-0244-5266-bcc2-51919e42d299", "url": "https://event.sec-t.org/sec-t-2026/speaker/FG9TEQ/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/LMLUSX/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/LMLUSX/", "attachments": []}, {"guid": "b0bae74c-b66c-5826-bfef-51be4392e65a", "code": "XMBZWS", "id": 97086, "logo": null, "date": "2026-09-10T16:00:00+02:00", "start": "16:00", "end": "2026-09-10T16:30:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-97086-the-hype-is-killing-kittens-but-not-that-grumpy-old-cat", "url": "https://event.sec-t.org/sec-t-2026/talk/XMBZWS/", "title": "The hype is killing kittens, but not that grumpy old cat", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "In this keynote, we take a step back from the hype cycle and look at security through a longer, vintage, grumpy old hackers lens. From the early days of classic computer hacks to the evolution of modern vulnerability research, we revisit the techniques, mindsets, the breakthroughs and the people responsible for those, with a focus especially on the gaping holes that shaped the industry. Along the way, we\u2019ll examine how each \u201crevolution\u201d -from automated scanners to current day AI- was (or is) supposed to change\u2026 everything.\nGrumpy old hacker's voice: \u201cAnd yet, the core of security has remained stubbornly human.\u201d\nThrough real-world facepalming examples (here come the tears), historical parallels, and a candid look at today\u2019s AI-driven slop, this talk challenges the narrative that AI is replacing hackers. And kittens? They\u2019re probably fine. But just to be sure, bring napkins to this talk. Please.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "E3QRKF", "name": "Edwin van Andel", "avatar": null, "biography": "Edwin van Andel started hacking at the age of 13. Although he is now CTO of hacker company Zerocopter, and CMD of Cheeso.io, his relationship with the hacker community is still the main driving force in his life. His dream to bring the brilliant minds of all hackers he knows together in one room and to hack everything that is brought in is something that he is getting closer and closer to. In addition, together with the \u201cGuild of Grumpy Old Hackers\u201d, he is actively guiding young hackers", "public_name": "Edwin van Andel", "guid": "7d5dbde5-bc55-55f6-bc4a-a744a1723671", "url": "https://event.sec-t.org/sec-t-2026/speaker/E3QRKF/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/XMBZWS/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/XMBZWS/", "attachments": []}, {"guid": "ced75bf5-ab00-5fbd-9491-82d8294ce948", "code": "QWHJUD", "id": 91909, "logo": null, "date": "2026-09-10T16:45:00+02:00", "start": "16:45", "end": "2026-09-10T17:30:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-91909-claude-is-your-insider-threat-now", "url": "https://event.sec-t.org/sec-t-2026/talk/QWHJUD/", "title": "Claude is your insider threat now", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "I'm going to be taking a baseball bat to frontier LLMs, using math and statistics. I'll be showing logs of how they literallly talk themselves into lying to you. It's bad. Bring a helmet.\n\nPrompt engineering has become harness engineering. Openclaw and now codex are storing local files and 'memories' to try and handle the 'context window problem'. Moltbook has 3 million 'agents'. Openclaw is being used as a c2 now.\n\nThe attack surface is growing so rapidly we can barely keep track of it. This talk will explore all this new attack surface, and cover some of the things you can do about it.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "YHZHRV", "name": "Dan Tentler", "avatar": "https://event.sec-t.org/media/avatars/YHZHRV_PY0Bzpq.webp", "biography": "Dan Tentler is the founder of Phobos Group - a boutique information security consulting, advisory, architecture and simualtion firm, specializing in real-world attack and defense scenarios. Dan's been an architect, the blueteam, the redteam and the soc. Phobos just turned 10 years old! Come talk to Dan if you're interested in practical, real-world security - be it attack, defense, architecture or strategy.", "public_name": "Dan Tentler", "guid": "efe778af-2148-5c8b-a4a5-9ffa9ee756f6", "url": "https://event.sec-t.org/sec-t-2026/speaker/YHZHRV/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/QWHJUD/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/QWHJUD/", "attachments": []}], "Hardware Hacking Village": [{"guid": "7957433e-dc4a-57e6-90b8-b79f1f3cda23", "code": "99DGFV", "id": 104597, "logo": null, "date": "2026-09-10T09:30:00+02:00", "start": "09:30", "end": "2026-09-10T12:00:00+02:00", "duration": "02:30", "room": "Hardware Hacking Village", "slug": "sec-t-2026-104597-community-training-music-generation-for-newbies-learn-to-solder-workshop-sec-t-ardutouch-music-synthesizer-thursday", "url": "https://event.sec-t.org/sec-t-2026/talk/99DGFV/", "title": "[Community Training] Music Generation for Newbies / Learn to Solder workshop -- SEC-T ArduTouch music synthesizer (Thursday)", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "**Learn to solder**\u00a0by making a way-cool, powerful music synthesizer, and  \n**learn how to make cool music, sound, (and noise!) with computer chips**  \n(The fancy word for making sound with a computer chip is\u00a0_Digital Signal Processing_\u00a0or\u00a0_DSP_).  \n  \nThe **SEC-T Music Synthesizer Badge kit** (based on Mitch\u2019s **[ArduTouch](https://cornfieldelectronics.com/cfe/projects.php#ardutouch)** is an **[open hardware](https://github.com/maltman23/SEC-T_0x10sion_Badge)** **Ardu**ino-compatible music synthesizer kit with a built-in\u00a0**Touch**\u00a0Keyboard, and with built-in speaker/amplifier. It is a really nice performing musical instrument.  \n  \nThis workshop is for\u00a0**total newbies**\u00a0to learn to solder.  \nThis workshop is for\u00a0**total newbies**\u00a0to make their own SEC-T Music Synthesizer Badge and learn to make music, sound (and noise!) with computer chips.  \nAttendees take their completed synthesizer home at the end of the workshop.  \n  \nThe SEC-T Music Synthesizer comes pre-programmed with a way cool synthesizer. And Mitch will show you how to re-program it with other way cool (and totally different) synthesizers, and how to make your own synthesizers.  \n  \nFor ages 10 - 100.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "JZ7A9M", "name": "Mitch Altman", "avatar": "https://event.sec-t.org/media/avatars/VKYBYY_schVBje.webp", "biography": "[Mitch Altman](https://tinyurl.com/a3xme4c6) invented [TV-B-Gone](https://tvbgone.com) (turns off TVs in public), co-founded a [SillyValley](https://tinyurl.com/5cmktcv9) startup and [Noisebridge](https://noisebridge.net), pioneered [VR](https://tinyurl.com/4feevfuv), is an author, mentor, gives talks and workshops worldwide, performs on his [self-made synths](https://tinyurl.com/3kw227wx), promotes hackerspaces, open hardware, is founder of [Cornfield Electronics](https://tinyurl.com/5yymxemu).", "public_name": "Mitch Altman", "guid": "448a8798-3426-590e-806f-82a2cab92d90", "url": "https://event.sec-t.org/sec-t-2026/speaker/JZ7A9M/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/99DGFV/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/99DGFV/", "attachments": []}, {"guid": "10b5b894-08e3-5bb1-839d-d99efb884f48", "code": "YLTFHK", "id": 104598, "logo": null, "date": "2026-09-10T13:30:00+02:00", "start": "13:30", "end": "2026-09-10T17:30:00+02:00", "duration": "04:00", "room": "Hardware Hacking Village", "slug": "sec-t-2026-104598-community-training-arduino-for-total-newbies", "url": "https://event.sec-t.org/sec-t-2026/talk/YLTFHK/", "title": "[Community Training] Arduino For Total Newbies", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "**Learn everything you need to start making electronic projects!**  \nYou've probably heard lots about **[Arduino](https://www.arduino.cc)**. But if you don't know what it is, or how you can use it to do all sorts of cool things, then this fun and easy workshop is for you.  \nAs an example project, we'll be creating a **[TV-B-Gone](https://www.tvbgone.com)** remote control out of an Arduino you can take home with you.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "JZ7A9M", "name": "Mitch Altman", "avatar": "https://event.sec-t.org/media/avatars/VKYBYY_schVBje.webp", "biography": "[Mitch Altman](https://tinyurl.com/a3xme4c6) invented [TV-B-Gone](https://tvbgone.com) (turns off TVs in public), co-founded a [SillyValley](https://tinyurl.com/5cmktcv9) startup and [Noisebridge](https://noisebridge.net), pioneered [VR](https://tinyurl.com/4feevfuv), is an author, mentor, gives talks and workshops worldwide, performs on his [self-made synths](https://tinyurl.com/3kw227wx), promotes hackerspaces, open hardware, is founder of [Cornfield Electronics](https://tinyurl.com/5yymxemu).", "public_name": "Mitch Altman", "guid": "448a8798-3426-590e-806f-82a2cab92d90", "url": "https://event.sec-t.org/sec-t-2026/speaker/JZ7A9M/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/YLTFHK/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/YLTFHK/", "attachments": []}], "Community Area (Poseidon)": [{"guid": "46ddfdd0-ba74-5cc2-8846-6924b6c3eb90", "code": "TXHL97", "id": 105587, "logo": null, "date": "2026-09-10T13:15:00+02:00", "start": "13:15", "end": "2026-09-10T19:45:00+02:00", "duration": "06:30", "room": "Community Area (Poseidon)", "slug": "sec-t-2026-105587-karategamers-retro-arcoade", "url": "https://event.sec-t.org/sec-t-2026/talk/TXHL97/", "title": "Karategamers Retro Arcoade", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Care for a gaming break at the conference? Karategamers have brought their finest retro gaming consoles and equipment for you and your friends to relive or discover retro games from the the late 1900s and onwards. Still got the timing of the jumps or the order of the buttons drilled into your muscle memory? Find out at the Retro Arcade all afternoon, accompanied by Syntax Error DJ:s.\n[The Arcade Is Open During Club SEC-T!!]", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "3ZDLAT", "name": "Karategamers", "avatar": null, "biography": "karategamers@spelkultursormland.se", "public_name": "Karategamers", "guid": "5cae26f8-d82c-5c13-8fcc-57fea505497b", "url": "https://event.sec-t.org/sec-t-2026/speaker/3ZDLAT/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/TXHL97/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/TXHL97/", "attachments": []}], "Club SEC-T (Riddarsalen)": [{"guid": "ecfe14f5-9726-52a8-a40f-724e80c925ac", "code": "S8X8X7", "id": 105601, "logo": null, "date": "2026-09-10T19:00:00+02:00", "start": "19:00", "end": "2026-09-11T01:00:00+02:00", "duration": "06:00", "room": "Club SEC-T (Riddarsalen)", "slug": "sec-t-2026-105601-club-sec-t", "url": "https://event.sec-t.org/sec-t-2026/talk/S8X8X7/", "title": "[Club SEC-T]", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Welcome to Club SEC-T!\n\nThis is the official SEC-T party on Thursday night. To make this as much fun as possible, it's free to attend even if you don't have a conference ticket, and no registration is required either - simply drop in if you're 18 years or older \ud83d\ude42\n\n19:00 Doors open to the public\n19:15 Wiklund live-on-stage\n20:00 Cyber Security Quiz #20\n21:30 MBR live-on-stage\n22:45 Syntax Error DJs\n01:00 Doors close\n\nClub SEC-T is -free- to attend for anyone 18 years or older, whether you're a conference guest or just want a ridiculously geeky Thursday night and don't even know what SEC-T is!\n\nThis also means, as a conference guest, you're free to invite your non-ticket-holding friends.\nNo ticket nor registration needed. The schedule, once announced, is preliminary and subject to change.\n\nClub SEC-T is also open on Thursday from lunch and on Friday until lunch for conference ticket holders with a more relaxed vibe, background music, Karategamers Retro Arcade and conference feed on the big screen..", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "TE7PMC", "name": "SYNTAX ERROR", "avatar": null, "biography": null, "public_name": "SYNTAX ERROR", "guid": "cc8fd214-4f47-5a39-9b41-780b9cec2fcf", "url": "https://event.sec-t.org/sec-t-2026/speaker/TE7PMC/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/S8X8X7/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/S8X8X7/", "attachments": []}], "Mobile Hacking Village": [{"guid": "2efd8d50-b905-5fa1-8518-aef9ed35a478", "code": "MDKTZR", "id": 105438, "logo": null, "date": "2026-09-10T15:30:00+02:00", "start": "15:30", "end": "2026-09-10T17:15:00+02:00", "duration": "01:45", "room": "Mobile Hacking Village", "slug": "sec-t-2026-105438-community-training-let-s-build-a-harmonyos-testing-lab", "url": "https://event.sec-t.org/sec-t-2026/talk/MDKTZR/", "title": "[Community Training] Let's build a HarmonyOS testing lab", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "HarmonyOS (HMOS) is a mobile platform developed by Huawei. It is rapidly gaining popularity in China, and Huawei are open about their ambitions for becoming a global contender to iOS and Android. While the Chinese hacking community has made good progress on finding ways to play with HMOS, it remains fairly unknown (and unhacked) in the West. This is not helped by the fact that the system's development tools are somewhat restricted outside of mainland China.\n\nIn this session, I will talk about how HMOS works, and why I find it interesting. If you bring a Windows or macOS machine, I will also help you set up a decent playground environment to start with. Our hope is to build a small community of geeks poking the system with a stick before it goes global (if it ever does)", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "DPWCKS", "name": "Mi\u0142osz Gaczkowski", "avatar": "https://event.sec-t.org/media/avatars/avatar_Ao4H4CV.webp", "biography": "Mi\u0142osz Gaczkowski is the Mobile Security Lead at Reversec and a maintainer of the Android security framework drozer. Having previously spent entirely too much time in academia, he now splits his time between breaking mobile applications, mentoring the next generation of security talent, and geeking out over retro tech.", "public_name": "Mi\u0142osz Gaczkowski", "guid": "af48ba9c-252a-5bbb-b8bc-75caf2e76904", "url": "https://event.sec-t.org/sec-t-2026/speaker/DPWCKS/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/MDKTZR/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/MDKTZR/", "attachments": []}]}}, {"index": 3, "date": "2026-09-11", "day_start": "2026-09-11T04:00:00+02:00", "day_end": "2026-09-12T03:59:00+02:00", "rooms": {"Main hall": [{"guid": "b1d48f73-4c4d-515b-95ec-0c8e540f838b", "code": "VJQHXT", "id": 100972, "logo": null, "date": "2026-09-11T09:00:00+02:00", "start": "09:00", "end": "2026-09-11T09:45:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-100972-weaponising-ai-for-fun-and-profit", "url": "https://event.sec-t.org/sec-t-2026/talk/VJQHXT/", "title": "Weaponising AI for fun and profit", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "Everyone's talking about AI defending the perimeter. This one's about the other side of the table. I'll show you how public AI models quietly became the most versatile thing in an attacker's kit, a real force multiplier for building exploits and offensive tooling at a speed that just wasn't possible two years ago.\n\nWe'll dig up old, half forgotten techniques and watch AI breathe new life into them, then go fully modern with a stack of live hacking demos. But this isn't just for show: you'll walk out with practical, take it home ways to start folding AI into your own workflow, including a run from a raw bug all the way to a working exploit. Minimal slides, maximum terminal. You'll leave knowing how cheap and fast offensive capability has gotten, and with a real starting point for doing it yourself.\n\nDemos include SSH session hijacking, TTY/PTY injection, password stealing, command injection and old hacker tools on steroids.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "DCEJJT", "name": "David Jacoby", "avatar": "https://event.sec-t.org/media/avatars/KBG7ME_2S4cgWO.webp", "biography": "David Jacoby has dedicated his entire life to hacking and computer security the past 30+ years. From the underground hacking era to boardrooms worldwide, he has uncovered critical vulnerabilities, pioneered IoT security research, advised Fortune 500 companies, founded Unbreached and Threat Prevention Center, and now serves as CSO at Syndis. An award-winning speaker, author, TV host, hacker, and your friendly internet troublemaker, he bridges hacker culture with human clarity.", "public_name": "David Jacoby", "guid": "2f823309-3ac6-5684-bcae-0474b74bbf70", "url": "https://event.sec-t.org/sec-t-2026/speaker/DCEJJT/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/VJQHXT/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/VJQHXT/", "attachments": []}, {"guid": "35c6e076-ea04-5c4f-9640-3be6898296c7", "code": "7EJYJP", "id": 98841, "logo": null, "date": "2026-09-11T10:00:00+02:00", "start": "10:00", "end": "2026-09-11T10:30:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-98841-in-git-we-trust-defending-lovable-projects-from-malicious-code-injections-at-scale", "url": "https://event.sec-t.org/sec-t-2026/talk/7EJYJP/", "title": "In git we trust: Defending Lovable projects from malicious code injections at scale", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "This talk covers how the Lovable security team identified and tracked a global attack attempted to compromise our users' Github projects with malicious code. We analysed millions of Lovable projects across hundreds of thousands of customers and tracked the campaign through its different phases meanwhile we built tools to intercept and prevent the attack. \n\nThe attacker used a mix of human and non-human identities, introduced malicious code through direct commits and merge paths, and bypassed expected platform provenance. We observed payloads hidden in frontend configuration files and used obfuscated staged JavaScript to fetch and execute encrypted second-stage code. The attack affected anyone who worked with or built the code.\n\nThis talk shows how to detect and contain this pattern by correlating Git events, CI/CD metadata, and platform edit telemetry. Attendees leave with knowledge of how to prevent similar attacks from happening, deploy detections, triage logic, and conduct incident response.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "WE9BCB", "name": "Marcus Hallberg", "avatar": "https://event.sec-t.org/media/avatars/TBRY9M_JwGgcy7.webp", "biography": "Security engineer with a passion for cloud security, AI systems, forensics and automation. \nSecret skill: Swedish folk dancing.", "public_name": "Marcus Hallberg", "guid": "f6799a29-57b7-547b-bfba-885687e3a2e8", "url": "https://event.sec-t.org/sec-t-2026/speaker/WE9BCB/"}, {"code": "FZZQWU", "name": "Samuel Kelemen", "avatar": null, "biography": null, "public_name": "Samuel Kelemen", "guid": "04127bfa-d5ee-5ad0-9b23-89fa5ca0739c", "url": "https://event.sec-t.org/sec-t-2026/speaker/FZZQWU/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/7EJYJP/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/7EJYJP/", "attachments": []}, {"guid": "6f9094b4-1da4-59e1-ba21-6448f27ed41a", "code": "9EUSBX", "id": 102031, "logo": null, "date": "2026-09-11T10:45:00+02:00", "start": "10:45", "end": "2026-09-11T11:15:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-102031-veilid-the-private-internet-we-were-all-promised", "url": "https://event.sec-t.org/sec-t-2026/talk/9EUSBX/", "title": "Veilid: The Private Internet we were all promised", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "The Cult Of The Dead Cow (cDc) is breaking the internet with Veilid, an open-source, peer to peer, mobile-first, network application framework. Veilid goes above and beyond existing privacy technologies and has the potential to completely change the way people use the Internet. Veilid has no profit motive, which puts it in a unique position to promote ideals without the compromise of capitalism. With Veilid, the user is in control, in a way that is approachable and friendly, regardless of technical ability.\n\nThis framework shares some similarities with IPFS and Tor in its overall design, but it is built to deliver better performance while natively supporting all services through a privately routed network. It allows developers to create fully decentralized applications without depending on a blockchain or transaction-processing layer as the foundation. The framework can either be integrated directly into end-user applications or operated as a standalone headless node by advanced users who want to contribute resources and help strengthen the network. Thousands have already joined the Veilid network, integrating it into their daily lives and building privacy-focused projects on top of it.\n\nTogether, we can give the world the private Internet we should have had all along.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "HLTUAM", "name": "BiaSciLab", "avatar": "https://event.sec-t.org/media/avatars/ZCY7DQ_fARU3ZM.webp", "biography": "BiaSciLab is a 19 year old hacker who has worked in cybersecurity since age 11. BiaSciLab is now an international speaker on election security, social media psyops, psychological warfare, and women in tech, presenting at DEF CON, Black Hat, BSides, and more.\nShe founded the nonprofit Girls Who Hack providing free cybersecurity education to thousands of girls worldwide, and also runs DCNextGen, DEF CON\u2019s official youth initiative. BiaSciLab is the newest member of the Cult of the Dead Cow (cDc)", "public_name": "BiaSciLab", "guid": "602886a6-e65d-577a-bcf1-3d70ca7b79c1", "url": "https://event.sec-t.org/sec-t-2026/speaker/HLTUAM/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/9EUSBX/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/9EUSBX/", "attachments": []}, {"guid": "c3b916ad-3390-5d68-a18d-0c22938be222", "code": "KUSBVD", "id": 98811, "logo": null, "date": "2026-09-11T11:30:00+02:00", "start": "11:30", "end": "2026-09-11T12:00:00+02:00", "duration": "00:30", "room": "Main hall", "slug": "sec-t-2026-98811-stfu-and-build-drones", "url": "https://event.sec-t.org/sec-t-2026/talk/KUSBVD/", "title": "STFU and build drones", "subtitle": "", "track": null, "type": "Small talk", "language": "en", "abstract": "I will talk about how you yourself can build a drone, what a drone even is, how it's used by both civilian and military. Stockholm Tactical Fundraising Ukraine (STFU), also known as Tacticats, is a volunteer based organisation (id\u00e9ell f\u00f6rening), our purpose is to fundraise, buy equipment and deliver it to Ukrainian defenders. We work with targeted aid, responding to specific requests from people at or near the frontline.\nWe also organize workshops where participants can learn how to build, or fly fpv drones. The built drones are then sent to Ukraine. So far, we've built around 60 drones since we started hosting these workshops back in November 2025.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "DJUQFZ", "name": "jonatan", "avatar": "https://event.sec-t.org/media/avatars/BRTHCU_2bQS5bc.webp", "biography": "Stockholm Tactical Fundraising Ukraine is very cool", "public_name": "jonatan", "guid": "eac13b77-afb6-54b6-a3fc-631b2232cc14", "url": "https://event.sec-t.org/sec-t-2026/speaker/DJUQFZ/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/KUSBVD/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/KUSBVD/", "attachments": []}, {"guid": "a8e40a26-cac0-525d-9053-3586169c6eb2", "code": "JDUN8Z", "id": 96159, "logo": null, "date": "2026-09-11T13:15:00+02:00", "start": "13:15", "end": "2026-09-11T14:00:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-96159-hacking-browsers-the-easy-way", "url": "https://event.sec-t.org/sec-t-2026/talk/JDUN8Z/", "title": "Hacking Browsers: The Easy Way", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "When you think of hacking browsers, you perhaps think of V8 heap exploitation, deep-dive fuzzing, crazy sandbox escapes, and so on. But what if I told you that you can still find vulnerabilities in major browsers that don\u2019t require any technical knowledge? Bugs you can even run into by accident!\nIn this talk, I\u2019ll take you through my journey of how I \u201caccidentally\u201c found a vulnerability in Google Chrome. And how that led me to find more vulnerabilities in Chrome as well as some vulnerabilities in Mozilla Firefox and many more bugs in other products.\nSo if you\u2019re keen to find out how I could, with minimal user-interaction, steal your private GitHub repositories, then this talk is for you!", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "7P78YF", "name": "PinkDraconian", "avatar": "https://event.sec-t.org/media/avatars/UXPXZV_0x0D1ws.webp", "biography": "Hi! I\u2019m Robbe Van Roey \ud83d\udc4b\nI\u2019m a hacker. I like breaking stuff. I\u2019m a security researcher at Aikido, I\u2019ve worked for a bug bounty company, and I\u2019ve found 35+ CVEs. I love hacking web apps, mobile applications, AI systems, and Active Directory.\nI\u2019m also a teacher. I teach developers about secure coding, I teach beginners about Red Teaming for Hack The Box and I\u2019ve created a bunch of YouTube videos on my channel.\nIn the online realm, you may know me as PinkDraconian. Come up to me and say hi!", "public_name": "PinkDraconian", "guid": "c3b04cb2-b352-5f76-b425-8111dfceddff", "url": "https://event.sec-t.org/sec-t-2026/speaker/7P78YF/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/JDUN8Z/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/JDUN8Z/", "attachments": []}, {"guid": "4804057d-fbd4-53cc-848f-0460e8f7e619", "code": "NLLXM3", "id": 103225, "logo": null, "date": "2026-09-11T14:15:00+02:00", "start": "14:15", "end": "2026-09-11T15:00:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-103225-root-from-kilometers-away-ubiquiti-airmax-rce", "url": "https://event.sec-t.org/sec-t-2026/talk/NLLXM3/", "title": "Root From Kilometers Away: Ubiquiti AirMax RCE", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "You don't realize it until you see them; they're everywhere. From Wireless ISP links to the frontline of modern warfare. But nobody found anything?\nThe devices behind those links are Ubiquiti AirMAX: critical infrastructure on a 17-year-old Linux kernel and a custom 802.11 extension built on \"security by obscurity.\"\nSo we took it apart. This talk covers our reverse engineering of the AirMAX protocol, AirOS, and the kernel modules behind this proprietary mode. It rides on 802.11 Information Elements that look encrypted, but we'll show why they aren't.\nWhat we found: two critical vulnerabilities (CVE-2026-21639, CVE-2026-21638) across airMAX AC, airMAX M, airFiber, and GigaBeam, over 50 devices. These are the bugs from the movies: Over-The-Air, unauthenticated, kernel-privilege RCE. No network access, just line of sight. They affect every AirMAX device ever shipped.\nWe disclosed them through Ubiquiti's bug bounty program. The bugs were rated \"Adjacent\", except adjacent here means kilometers away.\nThe same hardware can be turned around and pointed at the problem: we'll repurpose these devices as recon tools and release open-source software to locate AirMAX networks in the wild.\nThis talk is about our journey, our tooling, and the state of security.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "WVEDFA", "name": "Gaston Aznarez", "avatar": "https://event.sec-t.org/media/avatars/BK9CPT_czwZvfR.webp", "biography": "Gast\u00f3n Aznarez is a Principal Security Researcher at Faraday Security, specializing in vulnerability research on IoT and embedded devices. His work spans firmware reverse engineering, wireless protocol analysis, and hardware-level exploitation. He holds a Computer Science degree from Universidad Nacional de C\u00f3rdoba and has presented at DEF CON, Black Hat, and Ekoparty.", "public_name": "Gaston Aznarez", "guid": "664fcd32-d4c2-5b71-9edb-44ee09dc02d9", "url": "https://event.sec-t.org/sec-t-2026/speaker/WVEDFA/"}, {"code": "CFU9HL", "name": "Dan Borgogno", "avatar": "https://event.sec-t.org/media/avatars/XNXEWC_TRga6sd.webp", "biography": "Dan Borgogno is an Argentine security researcher, software engineer, and international speaker specializing in offensive security. Based in C\u00f3rdoba, he has researched vulnerabilities across mobile applications, NFC and payment systems, hardware, and IoT devices. His work has been presented at major security conferences including DEF CON and Ekoparty, and he currently works as a security researcher at Faraday.", "public_name": "Dan Borgogno", "guid": "54e0a324-7875-5353-9e93-7bcf1bb20f47", "url": "https://event.sec-t.org/sec-t-2026/speaker/CFU9HL/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/NLLXM3/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/NLLXM3/", "attachments": []}, {"guid": "5fffcc4c-4268-55eb-b6a4-b4ff3c1cb2cb", "code": "HMZCDB", "id": 96483, "logo": null, "date": "2026-09-11T15:15:00+02:00", "start": "15:15", "end": "2026-09-11T16:00:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-96483-breaking-the-boot-chain-bootkitting-ubuntu-for-fun-and-profit", "url": "https://event.sec-t.org/sec-t-2026/talk/HMZCDB/", "title": "Breaking the Boot Chain: Bootkitting Ubuntu for Fun and Profit", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "Modern Linux systems run a long chain of code before the kernel takes over - firmware, bootloaders like GRUB, and early runtime environments. Although each component is well understood, the transitions between them are often treated as simple handoffs, obscuring key assumptions about what state persists, what gets reinitialized, and where execution can truly be intercepted.\n\nThis talk offers a practical examination of one of the most important transitions: the GRUB-to-kernel handoff. Through reverse engineering GRUB and analyzing how the kernel image is loaded, decompressed, and executed, it shows how early-boot control flow is assembled - and where it can be influenced reliably.\n\nInstead of staying theoretical, the presentation focuses on real constraints that shape boot-chain abuse. It explores which execution contexts survive across stages, which don\u2019t, and how that affects the feasibility of establishing persistent control before OS security mechanisms activate.\n\nTo ground the discussion, a UEFI bootkit is built within the reconstructed execution flow. The implementation demonstrates concrete ways to subvert the Linux boot process, along with limitations and failure modes that appear when early-execution assumptions break.\n\nOverall, the talk clarifies how early boot works in practice: what can be controlled, what cannot, and what that implies for both offensive techniques and defensive visibility during one of the least observed phases of system execution.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "CGUVJA", "name": "Ido Veltzman", "avatar": null, "biography": "Ido Veltzman is a senior security researcher specialising in reverse engineering, operating system internals, vulnerability research, and exploit development. His work spans UEFI, hypervisors, kernel, and user mode, where he has developed advanced evasion, persistence, and injection techniques. Ido is known for translating deep technical research into practical offensive tradecraft, and regularly publishes papers and presents to the global cybersecurity community.", "public_name": "Ido Veltzman", "guid": "3c2c402b-528c-50e0-80a4-dc85b8645eb1", "url": "https://event.sec-t.org/sec-t-2026/speaker/CGUVJA/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/HMZCDB/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/HMZCDB/", "attachments": []}, {"guid": "6597a866-aa68-5469-adfa-4d53b79905ed", "code": "WNSTPU", "id": 103727, "logo": null, "date": "2026-09-11T16:00:00+02:00", "start": "16:00", "end": "2026-09-11T16:45:00+02:00", "duration": "00:45", "room": "Main hall", "slug": "sec-t-2026-103727-is-spectre-dead-yet-eight-years-in-hypervisors-still-pwnable", "url": "https://event.sec-t.org/sec-t-2026/talk/WNSTPU/", "title": "Is Spectre Dead Yet? Eight Years In, Hypervisors Still Pwnable", "subtitle": "", "track": null, "type": "Full talk", "language": "en", "abstract": "Although more than eight years have passed since transient execution attacks such as Spectre and Meltdown shocked the computer industry, this class of vulnerabilities remains largely unexplored beyond well-studied targets such as the KVM hypervisor. Less mainstream, yet widely used, hypervisors have received comparatively little scrutiny from security researchers investigating transient execution attacks. While we often assume that our virtualization platform provides a secure and isolated environment for cloud workloads, malware analysis, and other untrusted software, that assumption does not always hold.\n\nIn this talk, we take a deep dive into transient execution attacks, with a particular focus on Branch Target Injection (BTI)-based Spectre attacks. After explaining the underlying exploitation techniques, we examine the mitigations implemented by modern hypervisors, using KVM as a reference point. We then turn our attention to FreeBSD's bhyve and Oracle VirtualBox and show that neither provides adequate protection against BTI attacks. To demonstrate the practical impact, we present end-to-end proof-of-concept exploits against both platforms that leak arbitrary memory from the host.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "TAV8KU", "name": "Johannes Wikner", "avatar": "https://event.sec-t.org/media/avatars/KVEDGL_1dyTRe4.webp", "biography": "Johannes is a security researcher at RISE with a PhD from ETH Zurich. His research concerns offensive microarchitectural security, with a particular focus on branch misprediction on x86 processors. Over the course of his research he (co-)authored noteworthy works like Retbleed, Inception, Branch Privilege Injection, and Phantom speculation on x86 processors, receiving distinguished paper awards from MICRO, S&P and USENIX. He has previously has presented OffensiveCon and Black Hat USA", "public_name": "Johannes Wikner", "guid": "c4feb659-05fe-5d32-9004-b76c7a6f5a31", "url": "https://event.sec-t.org/sec-t-2026/speaker/TAV8KU/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/WNSTPU/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/WNSTPU/", "attachments": []}], "Hardware Hacking Village": [{"guid": "8183cce6-f6c2-5a50-9ed7-aad7943e2a35", "code": "BXEXVV", "id": 104599, "logo": null, "date": "2026-09-11T09:30:00+02:00", "start": "09:30", "end": "2026-09-11T11:30:00+02:00", "duration": "02:00", "room": "Hardware Hacking Village", "slug": "sec-t-2026-104599-community-training-tv-b-gone-turn-off-tvs-and-learn-to-solder-friday", "url": "https://event.sec-t.org/sec-t-2026/talk/BXEXVV/", "title": "[Community Training] TV-B-Gone: Turn Off TVs and Learn to Solder! (Friday)", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "**Turning off TVs and monitors in public places is fun!**  \nLearn to solder by making a kit that turns off these annoyances from 50 meters away.  \n**For total beginners.**  \nEnjoy life, and turn off a TV or two today!  \n  \n**[TV-B-Gone](https://cornfieldelectronics.com/cfe/projects.php#tvbgone2)** is an **[open hardware](https://github.com/maltman23/TV-B-Gone-kit_V2)** remote control that can turn off any remotely controllable monitor in public places (or anywhere)! From across the street, through windows, in restaurants, bars, schools, airports... The new V2 of the kit makes it super easy to learn to solder, as well as easy to hack on.  \n  \n**Community Training Itinerary:**  \n* Intro to remote controls\u2006 \u2006 \n* Learn to solder by making your own TV-B-Gone, step by step\u2006 \u2006 \n* Target practice is available all over the world after the workshop\u2006 \u2006 \n  \n**Taught by**\u00a0Mitch Altman.  \n  \n**Materials cost:**  \nThe workshop is free, but if you would like to partake in the hands-on aspects of the workshop, Mitch will have materials for **\u20ac20**.  \n  \n**Duration**:  \nThis community training takes 2 hours.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "JZ7A9M", "name": "Mitch Altman", "avatar": "https://event.sec-t.org/media/avatars/VKYBYY_schVBje.webp", "biography": "[Mitch Altman](https://tinyurl.com/a3xme4c6) invented [TV-B-Gone](https://tvbgone.com) (turns off TVs in public), co-founded a [SillyValley](https://tinyurl.com/5cmktcv9) startup and [Noisebridge](https://noisebridge.net), pioneered [VR](https://tinyurl.com/4feevfuv), is an author, mentor, gives talks and workshops worldwide, performs on his [self-made synths](https://tinyurl.com/3kw227wx), promotes hackerspaces, open hardware, is founder of [Cornfield Electronics](https://tinyurl.com/5yymxemu).", "public_name": "Mitch Altman", "guid": "448a8798-3426-590e-806f-82a2cab92d90", "url": "https://event.sec-t.org/sec-t-2026/speaker/JZ7A9M/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/BXEXVV/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/BXEXVV/", "attachments": []}, {"guid": "623d69ad-d521-5b4d-af85-22be275f08d9", "code": "EU8NZW", "id": 104600, "logo": null, "date": "2026-09-11T13:30:00+02:00", "start": "13:30", "end": "2026-09-11T16:00:00+02:00", "duration": "02:30", "room": "Hardware Hacking Village", "slug": "sec-t-2026-104600-community-training-music-generation-for-newbies-learn-to-solder-workshop-sec-t-ardutouch-music-synthesizer-friday", "url": "https://event.sec-t.org/sec-t-2026/talk/EU8NZW/", "title": "[Community Training] Music Generation for Newbies / Learn to Solder workshop -- SEC-T ArduTouch music synthesizer (Friday)", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "**Learn to solder**\u00a0by making a way-cool, powerful music synthesizer, and  \n**learn how to make cool music, sound, (and noise!) with computer chips**  \n(The fancy word for making sound with a computer chip is\u00a0_Digital Signal Processing_\u00a0or\u00a0_DSP_).  \n  \nThe **SEC-T Music Synthesizer Badge kit** (based on Mitch\u2019s **[ArduTouch](https://cornfieldelectronics.com/cfe/projects.php#ardutouch)** is an **[open hardware](https://github.com/maltman23/SEC-T_0x10sion_Badge)** **Ardu**ino-compatible music synthesizer kit with a built-in\u00a0**Touch**\u00a0Keyboard, and with built-in speaker/amplifier. It is a really nice performing musical instrument.  \n  \nThis workshop is for\u00a0**total newbies**\u00a0to learn to solder.  \nThis workshop is for\u00a0**total newbies**\u00a0to make their own SEC-T Music Synthesizer Badge and learn to make music, sound (and noise!) with computer chips.  \nAttendees take their completed synthesizer home at the end of the workshop.  \n  \nThe SEC-T Music Synthesizer comes pre-programmed with a way cool synthesizer. And Mitch will show you how to re-program it with other way cool (and totally different) synthesizers, and how to make your own synthesizers.  \n  \nFor ages 10 - 100.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "JZ7A9M", "name": "Mitch Altman", "avatar": "https://event.sec-t.org/media/avatars/VKYBYY_schVBje.webp", "biography": "[Mitch Altman](https://tinyurl.com/a3xme4c6) invented [TV-B-Gone](https://tvbgone.com) (turns off TVs in public), co-founded a [SillyValley](https://tinyurl.com/5cmktcv9) startup and [Noisebridge](https://noisebridge.net), pioneered [VR](https://tinyurl.com/4feevfuv), is an author, mentor, gives talks and workshops worldwide, performs on his [self-made synths](https://tinyurl.com/3kw227wx), promotes hackerspaces, open hardware, is founder of [Cornfield Electronics](https://tinyurl.com/5yymxemu).", "public_name": "Mitch Altman", "guid": "448a8798-3426-590e-806f-82a2cab92d90", "url": "https://event.sec-t.org/sec-t-2026/speaker/JZ7A9M/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/EU8NZW/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/EU8NZW/", "attachments": []}], "Club SEC-T (Riddarsalen)": [{"guid": "e3342001-f514-53fd-8041-a437ef09df8c", "code": "T98W7E", "id": 105616, "logo": null, "date": "2026-09-11T09:00:00+02:00", "start": "09:00", "end": "2026-09-11T12:00:00+02:00", "duration": "03:00", "room": "Club SEC-T (Riddarsalen)", "slug": "sec-t-2026-105616-karategamers-retro-arcoade", "url": "https://event.sec-t.org/sec-t-2026/talk/T98W7E/", "title": "Karategamers Retro Arcoade", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Care for a gaming break at the conference? Karategamers have brought their finest retro gaming consoles and equipment for you and your friends to relive or discover retro games from the the late 1900s and onwards. Still got the timing of the jumps or the order of the buttons drilled into your muscle memory? Find out at the Retro Arcade all afternoon, accompanied by Syntax Error DJ:s.\n[The Arcade Is Open During Club SEC-T!!]", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "3ZDLAT", "name": "Karategamers", "avatar": null, "biography": "karategamers@spelkultursormland.se", "public_name": "Karategamers", "guid": "5cae26f8-d82c-5c13-8fcc-57fea505497b", "url": "https://event.sec-t.org/sec-t-2026/speaker/3ZDLAT/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/T98W7E/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/T98W7E/", "attachments": []}], "Mobile Hacking Village": [{"guid": "98d5a3c2-d0c6-53f1-b954-4f42990c9db0", "code": "WWKJTX", "id": 105439, "logo": null, "date": "2026-09-11T09:30:00+02:00", "start": "09:30", "end": "2026-09-11T12:00:00+02:00", "duration": "02:30", "room": "Mobile Hacking Village", "slug": "sec-t-2026-105439-community-training-badlock-hack-a-not-so-smart-padlock", "url": "https://event.sec-t.org/sec-t-2026/talk/WWKJTX/", "title": "[Community Training]  badlock: Hack a Not-So-Smart Padlock", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "In our 2023 BSides London talk, we revealed a number of vulnerabilities in a popular line of smart padlocks which allowed unauthorised users to obtain unlock credentials for any affected lock and open it without the owner\u2019s knowledge.\n\nBuilding on this research, we've developed a training lab to help introduce newcomers to IoT and mobile hacking. Our lab setup replicates the app responsible for controlling the smart locks, and serves as a practical introduction to mobile application reverse-engineering, Bluetooth Low Energy communications, with a garnish of simple API testing. We'll bring the locks and mobile phones to control them.\n\nBring your own laptop with a Linux VM (Kali works). We'll bring the phones, the locks, and the app. :)", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "VBCN8W", "name": "Alex Pettifer", "avatar": "https://event.sec-t.org/media/avatars/avatar_fFSGWfl.webp", "biography": "Alex is a security consultant at Reversec, specialising in mobile applications and thick client testing. They are passionate about locks and physical access controls, and how both can break in interesting ways.\n\nFavourite padlock: Abus 72/40", "public_name": "Alex Pettifer", "guid": "f7afcbb1-ce0f-59fc-9af9-9f47aabf12b5", "url": "https://event.sec-t.org/sec-t-2026/speaker/VBCN8W/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/WWKJTX/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/WWKJTX/", "attachments": []}, {"guid": "6b9764e0-10f2-572d-92f5-c00c671531bd", "code": "SMU9T9", "id": 105528, "logo": null, "date": "2026-09-11T15:00:00+02:00", "start": "15:00", "end": "2026-09-11T16:00:00+02:00", "duration": "01:00", "room": "Mobile Hacking Village", "slug": "sec-t-2026-105528-community-training-low-level-ios-hacking-an-introduction", "url": "https://event.sec-t.org/sec-t-2026/talk/SMU9T9/", "title": "[Community Training] Low-Level iOS Hacking - an introduction", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "Ever wondered what's going on inside your iPhone?\nIt's an incredible can of worms, that Etum/Agnes would love to explore with you!\n\nWe'll crack open how iOS and its apps actually work under the hood, then get you hands-on with Arm64 and LLDB ( the real tools that jailbreakers and security researchers use) before setting you loose on live disassembly and debugging. Bring questions, a linux laptop and a can do attitude!\n\nThis workshop is beginner-friendly, no experience required  (but if you've touched a terminal before, you'll feel right at home)\n\nWorkshop outline:\n- Introductory talk about how iOS/iOS apps work \"under the hood\".\n- Arm64 and LLDB basics, follow-along.\n- Hands-on simple disassembly and LLDB debugging.\n- Post-workshop reversing material\n- ... Probably low-level iOS tangents if you poke Etum enough about it\n\nMaterials:\nBring your own laptop. (Mac or Linux)\nFor the hands-on section, we will supply as many Jailbroken iOS devices as we have available; otherwise,  go ahead and bring a macbook with vphone-CLI [https://github.com/Lakr233/vphone-cli] installed (Requires AMFI turned off over csrutil)", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "TQXLRT", "name": "Agnes Borg", "avatar": "https://event.sec-t.org/media/avatars/avatar_BQvVVsJ.webp", "biography": "Agnes Borg is a Reversec security consultant who enjoys exploring the vast world of web and mobile technologies.\nShe has a growing interest in low-level iOS internals and application hacking.\nOn her spare time when not lazy, she likes to do bug bounty hunting.", "public_name": "Agnes Borg", "guid": "d1c6e06e-6d47-5f2c-b734-5bf318823412", "url": "https://event.sec-t.org/sec-t-2026/speaker/TQXLRT/"}], "links": [], "feedback_url": "https://event.sec-t.org/sec-t-2026/talk/SMU9T9/feedback/", "origin_url": "https://event.sec-t.org/sec-t-2026/talk/SMU9T9/", "attachments": []}]}}]}}}