SEC-T 2026

Adam Toscher

Adam Toscher is a New York–based security engineer and red team operator with 20+ years in offensive security, adversary simulation, and automation. A former IBM mainframe intern, he has held senior roles at Adobe, Optiv, Accenture, IBM X-Force, NYC Cyber Command, FDNY, and Cobalt Labs. His work focuses on realistic red-team operations, penetration testing, and practical security automation.

  • The Pre Internet Computer Why Mainframe Security Breaks Cloud Era Thinking
Agnes Borg

Agnes Borg is a Reversec security consultant who enjoys exploring the vast world of web and mobile technologies.
She has a growing interest in low-level iOS internals and application hacking.
On her spare time when not lazy, she likes to do bug bounty hunting.

  • [Community Training] Low-Level iOS Hacking - an introduction
Alex Pettifer

Alex is a security consultant at Reversec, specialising in mobile applications and thick client testing. They are passionate about locks and physical access controls, and how both can break in interesting ways.

Favourite padlock: Abus 72/40

  • [Community Training] badlock: Hack a Not-So-Smart Padlock
andrea pierini

I’m a Senior Security Consultant at Semperis with experience across software development, systems, networking, and security. My research focuses on authentication mechanisms, protocol inconsistencies, and privilege-escalation techniques in Windows environments. I enjoy hunting bugs, exploring new technologies, and sharing research through publications and conferences. Microsoft recognized me among the Top 100 MSRC Security Researchers in 2020 and 2022.

  • Reflecting Your Authentication: Look in the Mirror - It’s You
BiaSciLab

BiaSciLab is a 19 year old hacker who has worked in cybersecurity since age 11. BiaSciLab is now an international speaker on election security, social media psyops, psychological warfare, and women in tech, presenting at DEF CON, Black Hat, BSides, and more.
She founded the nonprofit Girls Who Hack providing free cybersecurity education to thousands of girls worldwide, and also runs DCNextGen, DEF CON’s official youth initiative. BiaSciLab is the newest member of the Cult of the Dead Cow (cDc)

  • Veilid: The Private Internet we were all promised
Caroline Leman

Caroline began her career in 2015 specializing in malware reverse engineering at national organizations like the CEA and ANSSI. She joined Synacktiv's reverse engineering team in 2023 to focus on vulnerability research.

  • [Community Training] Introduction to cryptography reverse engineering for women
Christophe Tafani-Dereeper

Christophe lives in Switzerland and works on cloud security research and open source at Datadog. He previously worked as a software developer, penetration tester and cloud security engineer. Christophe is the maintainer of several open-source projects such as Stratus Red Team, GuardDog, CloudFlair, Adaz, and the Managed Kubernetes Auditing Toolkit (MKAT).

  • I will find you and I will flag you: hunting malicious packages at scale
Dan Borgogno

Dan Borgogno is an Argentine security researcher, software engineer, and international speaker specializing in offensive security. Based in Córdoba, he has researched vulnerabilities across mobile applications, NFC and payment systems, hardware, and IoT devices. His work has been presented at major security conferences including DEF CON and Ekoparty, and he currently works as a security researcher at Faraday.

  • Root From Kilometers Away: Ubiquiti AirMax RCE
Dan Tentler

Dan Tentler is the founder of Phobos Group - a boutique information security consulting, advisory, architecture and simualtion firm, specializing in real-world attack and defense scenarios. Dan's been an architect, the blueteam, the redteam and the soc. Phobos just turned 10 years old! Come talk to Dan if you're interested in practical, real-world security - be it attack, defense, architecture or strategy.

  • Claude is your insider threat now
David Jacoby

David Jacoby has dedicated his entire life to hacking and computer security the past 30+ years. From the underground hacking era to boardrooms worldwide, he has uncovered critical vulnerabilities, pioneered IoT security research, advised Fortune 500 companies, founded Unbreached and Threat Prevention Center, and now serves as CSO at Syndis. An award-winning speaker, author, TV host, hacker, and your friendly internet troublemaker, he bridges hacker culture with human clarity.

  • Weaponising AI for fun and profit
  • Community Lab: Breaking AI guardrails for exploit development
Edoardo Mantovani

Independent (security) researcher with a specific focus on wireless firmware reverse engineering, kernel programming and software obfuscation. Previously spoken/accepted at Nullcon Berlin 2025, Hardwear.io USA 2026, CONFidence conference 2026, SEC-T 2026, Hack.lu 2026 and BlackAlps 2026.

  • From Metal to WebUSB: Reimplementing a Wi-Fi 6 Driver Beyond the Kernel For Offensive Security
Edwin van Andel

Edwin van Andel started hacking at the age of 13. Although he is now CTO of hacker company Zerocopter, and CMD of Cheeso.io, his relationship with the hacker community is still the main driving force in his life. His dream to bring the brilliant minds of all hackers he knows together in one room and to hack everything that is brought in is something that he is getting closer and closer to. In addition, together with the “Guild of Grumpy Old Hackers”, he is actively guiding young hackers

  • The hype is killing kittens, but not that grumpy old cat
Gaston Aznarez

Gastón Aznarez is a Principal Security Researcher at Faraday Security, specializing in vulnerability research on IoT and embedded devices. His work spans firmware reverse engineering, wireless protocol analysis, and hardware-level exploitation. He holds a Computer Science degree from Universidad Nacional de Córdoba and has presented at DEF CON, Black Hat, and Ekoparty.

  • Root From Kilometers Away: Ubiquiti AirMax RCE
Ido Veltzman

Ido Veltzman is a senior security researcher specialising in reverse engineering, operating system internals, vulnerability research, and exploit development. His work spans UEFI, hypervisors, kernel, and user mode, where he has developed advanced evasion, persistence, and injection techniques. Ido is known for translating deep technical research into practical offensive tradecraft, and regularly publishes papers and presents to the global cybersecurity community.

  • Breaking the Boot Chain: Bootkitting Ubuntu for Fun and Profit
James Kettle

James 'albinowax' Kettle is the Director of Research at PortSwigger, the makers of Burp Suite. His best-known research is HTTP Desync Attacks, which popularised HTTP Request Smuggling. Other popular attack techniques that can be traced back to his research include web cache poisoning, the single-packet attack, server-side template injection, and password reset poisoning. He's also the designer behind many of the topics and labs that make up the Web Security Academy.

  • Can AI do novel security research? Meet the HTTP Terminator
Jesper Larsson

Jesper Larsson is an independent security researcher and penetration tester, and runs the security consultancy 0x4A. He tests the platforms companies build on, the pipelines they ship through, the identity systems holding it together, and the people who use them. Most engagements end the same way: a chain of small, individually reasonable decisions adding up to somebody owning production.

He featured in the Swedish TV series Hackad, and co-founded SecurityFest and Säkerhetspodcasten

  • The CI/CD Escape Room - Eleven doors, zero exploits.
Johannes Wikner

Johannes is a security researcher at RISE with a PhD from ETH Zurich. His research concerns offensive microarchitectural security, with a particular focus on branch misprediction on x86 processors. Over the course of his research he (co-)authored noteworthy works like Retbleed, Inception, Branch Privilege Injection, and Phantom speculation on x86 processors, receiving distinguished paper awards from MICRO, S&P and USENIX. He has previously has presented OffensiveCon and Black Hat USA

  • Is Spectre Dead Yet? Eight Years In, Hypervisors Still Pwnable
jonatan

Stockholm Tactical Fundraising Ukraine is very cool

  • STFU and build drones
Karategamers

karategamers@spelkultursormland.se

  • Karategamers Retro Arcoade
  • Karategamers Retro Arcoade
Lucas Lundgren / acidgen

Lucas Lundgren is an offensive security specialist and penetration tester with 30+ years of hands-on hacking experience. Active in cybersecurity since childhood, he specializes in web, API, cloud, OAuth, and infrastructure security. Lucas is passionate about practical offensive security, AI-assisted pentesting, and real-world attack techniques, combining deep technical expertise with engaging storytelling and live demonstrations.

  • Vulnerable Sweden
Marcus Hallberg

Security engineer with a passion for cloud security, AI systems, forensics and automation.
Secret skill: Swedish folk dancing.

  • In git we trust: Defending Lovable projects from malicious code injections at scale
Michael "MC" Cardell Widerkrantz

MC has been programming professionally since 1995 and recreationally
since 1985. At Tillitis he's doing research and programming on all
software parts: the emulator, the firmware, the device apps, and the
client apps, as well as helping define the hardware/software
interface.

  • Increasing trust with measured & verified boot
Mitch Altman

Mitch Altman invented TV-B-Gone (turns off TVs in public), co-founded a SillyValley startup and Noisebridge, pioneered VR, is an author, mentor, gives talks and workshops worldwide, performs on his self-made synths, promotes hackerspaces, open hardware, is founder of Cornfield Electronics.

  • [Community Training] Music Generation for Newbies / Learn to Solder workshop -- SEC-T ArduTouch music synthesizer (Thursday)
  • [Community Training] TV-B-Gone: Turn Off TVs and Learn to Solder! (Wednesday)
  • [Community Training] TV-B-Gone: Turn Off TVs and Learn to Solder! (Friday)
  • [Community Training] Arduino For Total Newbies
  • [Community Training] Music Generation for Newbies / Learn to Solder workshop -- SEC-T ArduTouch music synthesizer (Friday)
Miłosz Gaczkowski

Miłosz Gaczkowski is the Mobile Security Lead at Reversec and a maintainer of the Android security framework drozer. Having previously spent entirely too much time in academia, he now splits his time between breaking mobile applications, mentoring the next generation of security talent, and geeking out over retro tech.

  • [Community Training] Let's build a HarmonyOS testing lab
PinkDraconian

Hi! I’m Robbe Van Roey 👋
I’m a hacker. I like breaking stuff. I’m a security researcher at Aikido, I’ve worked for a bug bounty company, and I’ve found 35+ CVEs. I love hacking web apps, mobile applications, AI systems, and Active Directory.
I’m also a teacher. I teach developers about secure coding, I teach beginners about Red Teaming for Hack The Box and I’ve created a bunch of YouTube videos on my channel.
In the online realm, you may know me as PinkDraconian. Come up to me and say hi!

  • Hacking Browsers: The Easy Way
Samuel Kelemen
  • In git we trust: Defending Lovable projects from malicious code injections at scale
Satoki

Web Application Tuntsun Shokunin, CTF Player, and Bug Hunter. Has delivered talks at major security conferences including AVTOKYO, Security Analyst Summit, Hack Fes., m0leCon, TyphoonCon Seoul, HITCON, DefCamp, Queen City Conference, and Kernelcon. At Pwn2Own Berlin 2026, achieved remote code execution on three products, including OpenAI Codex. A DEF CON CTF finalist, renowned for discovering and responsibly reporting vulnerabilities in major web services and software such as Google and Firefox.

  • [Pwn2Own Berlin 2026 $20,000] Agent2Shell: Pre-Prompt RCEs in Claude Code, Cursor, and Gemini
Sofia Bobadilla

Sofia Bobadilla is a 3rd year PhD student at KTH Royal Institute of Technology. Her research focuses on automated exploit generation and vulnerability repair for smart contracts, building systems that find and fix bugs before attackers do. Her work has been adopted as reference guidelines for AI-assisted security research in the Ethereum ecosystem, and she is a member of KTH's Software Supply Chain Security group CHAINS. In 2024 she won the ETHPrague hackathon with a code fix verification tool.

  • Yippee-Ki-Yay, Blockchain: Exploiting Decentralized Systems One Die Hard at a Time
splitline

Tsi-Lin “Splitline” Ng is a security researcher at DEVCORE and a member of the ${CyStick} CTF team, specializing in web and application security.

He has presented at Black Hat USA, Europe, and Asia, as well as HITCON and m0leCon. His research was featured in the 2024 “Top 10 Web Hacking Techniques”. He has awarded bug bounties from major companies including Google, Microsoft and X, and he won Pwn2Own Berlin 2026.

You can follow his latest updates on X at @splitline or visit blog.splitline.tw

  • Born Corrupted: Hack the Planet by Hijacking Linux Package Factories
SYNTAX ERROR
  • [Club SEC-T]
Vincent
  • Vulnerable Sweden