Loading…
Tuesday, October 6
 

09:30 IDT

Opening remarks
Tuesday October 6, 2026 09:30 - 09:45 IDT

Tuesday October 6, 2026 09:30 - 09:45 IDT
Keynote Hall

09:45 IDT

Keynote talk!
Tuesday October 6, 2026 09:45 - 10:30 IDT

Tuesday October 6, 2026 09:45 - 10:30 IDT
Keynote Hall

10:30 IDT

When React Becomes an Attack Vector: Lessons from the React2Shell CVE
Tuesday October 6, 2026 10:30 - 11:15 IDT
This session presents a structured, security-focused analysis of the React2Shell vulnerability as a real-world case study in insecure design and broken trust boundaries in modern frontend frameworks. The talk begins by establishing a clear threat model for React and Next.js applications that use Server Components and Server Actions. We define the relevant trust zones, browser, framework runtime,...
See More →
Speakers
OE

Ofir Elarat

Developer
Tuesday October 6, 2026 10:30 - 11:15 IDT
Hall A

10:30 IDT

Unveiling the OWASP Top 10 for Agentic AI
Tuesday October 6, 2026 10:30 - 11:15 IDT
1. Introduction: Why we need a new Top 10 list distinct from the LLM Top 10. 2. The Agentic Architecture: Understanding the shift in inputs and outputs. 3. The OWASP Agentic Top 10 in Action: Breaking down real-world attacks. 4. Key Mitigations: Actionable steps you can implement tomorrow morning. 5. Where to Start: How to become the AI security champion in your organization. 6. What’s Next:...
See More →
Speakers
Tuesday October 6, 2026 10:30 - 11:15 IDT
Keynote Hall

10:30 IDT

Bad Vibes: Comparing the Secure Coding Capabilities of Coding Agents
Tuesday October 6, 2026 10:30 - 11:45 IDT
For this research, we designed an identical set of prompts specifying the exact requirements and tech stack for three web applications. The prompts were intentionally security neutral - they provided no security-specific guidelines, and only focused on required functionality.  Each of the five agents built all three applications, giving us 15 codebases to analyze. To find vulnerabilities, we...
See More →
Speakers
Tuesday October 6, 2026 10:30 - 11:45 IDT
Hall B

11:15 IDT

Coffee Break
Tuesday October 6, 2026 11:15 - 11:30 IDT

Tuesday October 6, 2026 11:15 - 11:30 IDT
Expo Hall

11:30 IDT

The Hidden DoS Vector in SQL Parsers
Tuesday October 6, 2026 11:30 - 12:15 IDT
We disclosed four vulnerabilities in the widely used SQL parsers SQLGlot and SQLFluff, as well as issues affecting downstream applications such as Apache Superset (70k GitHub stars), Pathway (60k GitHub stars), and other tools that rely on these parsers. Some of these downstream vulnerabilities have also been disclosed. These flaws allow syntactically valid queries to trigger crashes or...
See More →
Speakers
Tuesday October 6, 2026 11:30 - 12:15 IDT
Hall A

11:30 IDT

Off Script at Scale: Analyzing Rogue Agents Across 86K Repos and a Year of Production Incidents
Tuesday October 6, 2026 11:30 - 12:15 IDT
How common is it for an AI agent to go rogue, not because someone attacked it, but because it was given a goal, tools, and no way to be stopped?We looked at that question from two places: production behavior, and the code people actually ship.In our CurseBox research, we traced a behavior in Cursor's coding agent that showed up first in production. Asked to share a local file through a channel...
See More →
Speakers
avatar for Bar Kaduri

Bar Kaduri

Head of Research, Capsule Security
Bar Kaduri is a cybersecurity researcher, security leader, and international speaker focused on cloud security, software supply-chain risk, and the fast-moving world of AI threats. With over 14 years of hands-on experience breaking, testing, and hardening real systems, Bar works at... Read More →
Tuesday October 6, 2026 11:30 - 12:15 IDT
Hall B

11:30 IDT

Recognition ≠ Resistance: The Agent Knew It Was Being Attacked. It Complied Anyway
Tuesday October 6, 2026 11:30 - 12:15 IDT
**Talk outline:** 1. **[Alex] Building & defending the bot** (~7 min) — How AlexBot was built on OpenClaw: multi-agent architecture (Opus + Sonnet), SOUL.md identity, persistent memory, real calendar/contacts, 18 custom skills. The nightly arms race: Group Guardian, Prompt Protection v2.1, circuit breakers, 4-layer defense pipeline. What it's like watching 240 people try to break your creation...
See More →
Speakers
Tuesday October 6, 2026 11:30 - 12:15 IDT
Keynote Hall

12:15 IDT

Lunch Break
Tuesday October 6, 2026 12:15 - 13:15 IDT

Tuesday October 6, 2026 12:15 - 13:15 IDT
Expo Hall

13:15 IDT

Keynote: Everyone's an AI Builder Now, and the Hackers are Loving It!
Tuesday October 6, 2026 13:15 - 14:00 IDT

Speakers
Tuesday October 6, 2026 13:15 - 14:00 IDT
Keynote Hall

14:00 IDT

Who Let the DAGs Out?
Tuesday October 6, 2026 14:00 - 14:45 IDT
Apache Airflow has evolved far beyond a cron replacement. It now powers core machine learning workflows, data engineering platforms, CI/CD pipelines, and enterprise automation systems. With tens of millions of monthly downloads and global enterprise adoption, Airflow represents a high-value target. Its dynamic DAG execution model, Python-based operators, and extensive provider ecosystem create...
See More →
Speakers
avatar for Or Sahar

Or Sahar

Security Researcher | Reflectiz, Secure From Scratch
Or Sahar is a security researche, with two decades of experience in software development and security, she specialises in penetration testing, AI and Security research and application security.
Tuesday October 6, 2026 14:00 - 14:45 IDT
Hall A

14:00 IDT

I Built an agent That Hacks Like I Do (And It's Terrifying)
Tuesday October 6, 2026 14:00 - 14:45 IDT
After more than a decade in offensive security, I thought I understood the craft. The methodology becomes second nature—you develop intuition for which paths to explore, how to chain findings, when to pivot. It's pattern recognition built on thousands of hours of breaking things. Then I tried to teach that intuition to an AI agent. This talk is the result of that experiment. I took the 7-phase...
See More →
Speakers
Tuesday October 6, 2026 14:00 - 14:45 IDT
Hall B

14:00 IDT

LLMs as adaptive query planners for SAST
Tuesday October 6, 2026 14:00 - 14:45 IDT
>> Problem: Static analysis produces vast amounts of semantic data. Effectively exploring it remains an open challenge. >> Why naive LLM approaches fall short: LLMs can not ingest entire repositories. They are fundamentally constrained by context limits. Even the most powerful models cannot reason over thousands of files and millions of tokens. Raw source code seems like the wrong...
See More →
Speakers
avatar for Oren Ish-Shalom

Oren Ish-Shalom

Researcher
So ... Hi ! If you're reading this there is a good chance you're coming to OWASP IL 26 - excellent ! Over the years, I've had the opportunity of speaking at international conferences, but for me, nothing is more exciting than giving a talk right here at home. The heat, the humidity... Read More →
Tuesday October 6, 2026 14:00 - 14:45 IDT
Keynote Hall

14:45 IDT

Coffee Break
Tuesday October 6, 2026 14:45 - 15:00 IDT

Tuesday October 6, 2026 14:45 - 15:00 IDT
Expo Hall

15:00 IDT

Zero-Trust Data Protection at Scale: Building an Enterprise Identity and Key Management Platform
Tuesday October 6, 2026 15:00 - 15:45 IDT
This session presents how Intuit's Data Protection team built and operates an internal platform for identity-based access to encryption keys and secrets across AWS, GCP, and third-party providers. The platform serves services and handles cryptographic operations at scale while keeping the developer experience simple. The talk covers four components: 1. An identity broker that validates cloud...
See More →
Tuesday October 6, 2026 15:00 - 15:45 IDT
Hall A

15:00 IDT

Beyond the Bomb: Securing AI Applications and Agents through Security Steerability
Tuesday October 6, 2026 15:00 - 15:45 IDT
• The Evolution of AI Risk: The talk begins by contrasting passive chatbots with active agents, illustrating how the threat landscape has shifted from LLMs merely describing harmful acts to executing them via tools. • Defining the Gap: It highlights the limitation of "Universal Security" (standard safety filters) and introduces "Security Steerability" as the metric for measuring adherence to...
See More →
Speakers
Tuesday October 6, 2026 15:00 - 15:45 IDT
Hall B

15:00 IDT

Never Say Never: Owning ChatGPT's Secure Sandbox
Tuesday October 6, 2026 15:00 - 15:45 IDT
OpenAI designed ChatGPT's container sandbox as a secure runtime environment, enforcing full network isolation, strict execution timeouts, and an AI supervisor to filter every command. Under this model, owning the container and extracting sensitive data seemed impossible. However, we demonstrate that by chaining file-parsing abuse for persistent execution, reasoning-channel hijacking for data...
See More →
Speakers
Tuesday October 6, 2026 15:00 - 15:45 IDT
Keynote Hall

15:45 IDT

Every Step Was Authorized: Hijacking AI Agents Through the Tools They Trust
Tuesday October 6, 2026 15:45 - 16:00 IDT
A single fake bug report, planted in ordinary Sentry telemetry, drove the AI coding agents of more than 100 organizations, including a Fortune 100 technology company, to run attacker code with the developer's own privileges. Success rate: 85%. Controls that fired: zero. This was our Agentjacking research.Faced with this, security teams are reaching for a new generation of in-context guardrails,...
See More →
Speakers
avatar for Nevo Poran

Nevo Poran

CTO, Tenet Security
Nevo Poran is co-founder and CTO of Tenet Security, where he leads the research and engineering behind its platform for securing autonomous AI agents as they act. Before Tenet, he was part of the founding team of Cisco's AI Defense and led some of the first agent-security research... Read More →
Tuesday October 6, 2026 15:45 - 16:00 IDT
Keynote Hall

15:45 IDT

????? From Gatekeeper to Pipeline: Building an LLM-Orchestrated AppSec Triage Engine
Tuesday October 6, 2026 15:45 - 16:30 IDT
AppSec triage has a throughput problem. Tools are getting better at finding issues, but the human validation layer hasn't scaled to match. The result: backlogs grow, developers lose trust in findings, and security teams spend more time on classification than remediation. This talk presents a different model. Instead of treating triage as a human task assisted by tools, we flipped it - triage is...
See More →
Speakers
Tuesday October 6, 2026 15:45 - 16:30 IDT
Hall B

16:00 IDT

Closing Remarks
Tuesday October 6, 2026 16:00 - 16:45 IDT

Tuesday October 6, 2026 16:00 - 16:45 IDT
Keynote Hall
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.