Read every security talk
in minutes.
TL;DR, full written analysis, and word-level YouTube timestamps for every talk — across every conference we cover.
Browse by topic · all topics →
Conferences
[un]prompted 2026
The AI Security Practitioner Conference.
- Johann Rehberger - Your Agent Works for Me Now | [un]prompted 2026
- Why Most ML Vulnerability Detection Fails (And What Actually Worked...
- Rob T. Lee, Glenn Thrope, Dan Hubbard & Sergej Epp - Vibe Coded | [...
BSidesSF 2026
Security BSides San Francisco is a two-day information security conference. It is a conference by the community for the community.
- 📗 You’re Gonna Be Popular: Why They’re Getting a Callback and You’r...
- 📙 Your Threat Model Is Lying to You: Why Modeling the Design Isn’t ...
- 📙 Your Load Balancer is Your New Perimeter: Attacks & Defenses at S...
KubeCon + CloudNativeCon
The Cloud Native Computing Foundations flagship conference gathers adopters and technologists from leading open source and cloud native communities. #KubeCon + #CloudNativeCon.
- WIT Happens: Exploring the Latest Evolution of the SPIFFE and WIMSE...
- When Multitenancy Goes Wrong: A Deep Dive Into Kcp's First CVE - Ma...
- What LLMs Do, and Don't, Know About Securing Kubernetes - Rory McCu...
NDC Security 2026
NDC Security 2026 is a premier in-person cybersecurity conference specifically tailored for software developers.
- Zero-Knowledge Proofs: Simultaneously ensuring integrity and privacy
- Your Website Is Running Code You've Never Seen
- Worms in our software supply chain - Where do we go from here?
Black Hat
Founded in 1997, Black Hat is an internationally recognized cybersecurity event series providing the most technical and relevant information security research. Grown from a single annual conference to the most respected information security event series internationally, these multi-day events provide the security community with the latest cutting-edge research, developments, and trends.
- XUnprotect: Reverse Engineering macOS XProtect Remediator
- Windows Hell No for Business
- When Guardrails Aren't Enough: Reinventing Agentic AI Security With...
OWASP Global AppSec USA 2025
OWASP Global AppSec USA 2025 is a premier application security conference. It brings together 800+ developers, security experts, and leaders for sessions on AI security, threat modeling, and DevSecOps.
- Your RPA is Mine: Complete Takeover of RPA Ecosystems
- Two Paths to Security Upskilling: Startup and Enterprise
- The SCA Balancing Act
DEF CON 33
DEF CON 33, the world's largest, longest continuously run underground hacking conference. Features top hacking research, hands-on learning, & contests!.
- Zero Trust, Total Bust - Breaking into thousands of cloud-based VPN...
- Your Passkey is Weak: Phishing the Unphishable
- Win-DoS Epidemic: A crash course in abusing RPC for Win-DoS & Win-DDoS
DefCamp
DefCamp is the most important conference on Hacking & Information Security in Central Eastern Europe. The goal is bringing hands-on talks about latest research and practices from the INFOSEC field, gathering under the same roof security specialists, entrepreneurs, academic, private and public sectors.
- VIBE Pentesting - Enhancing the Human Hacker with LLMs at DefCamp 2025
- Verkle-Based HORST: A Scalable and Efficient Post-Quantum Digital S...
- Trust No Format: Risks and Defenses for ML Model Serialization at D...
OWASP Global AppSec USA 2024
OWASP Global AppSec USA 2024 is a premier application security conference. It brings together 800+ developers, security experts, and leaders for sessions on AI security, threat modeling, and DevSecOps.
- Who Hurt You? Earning the trust of developers
- Web Security Experts: Are you overlooking WebRTC vulnerabilities?
- 3 Day Training: Web Application Security Essentials
Zero-Knowledge Proofs: Simultaneously ensuring integrity and privacy
Tjerand Silde explained zero-knowledge proofs as cryptographic protocols that verify a statement's truth without revealing the underlying secret witness. He demonstrated applications in quantum-safe signatures (FIPS 204 ML-DSA), anonymous transactions (Zcash), electronic votin...
Read the analysis →Recently added · latest analyses across every conference
Your Website Is Running Code You've Never Seen
Third-party JavaScript on the median page weighs 680 KB. 98.1% of pages load JavaScript, and JavaScript is the #1 third-party resource. Attackers compromised...
Worms in our software supply chain - Where do we go from here?
Eriksen chronicled three waves of NPM supply-chain attacks in 2024-2025: the Singularity LLM-assisted worm, the Shai Hulud self-spreading worm affecting 180+...
Won't somebody please think of the children!?
Niall Merrigan documented online threats to children: Andrew McCartney catfished 3,500 victims over 4 years; 9-year-old Simran Thomas shot herself after bein...
Who Gave the Agent Admin Rights?! Securing Cloud & AI Machine Identities
Bodhisattva Das demonstrated how non-human identities outnumber humans 50:1 and are the biggest blind spot. Using the Capital One breach as a case study, he ...
What's New in ASVS V5
Eden Yardeni presented ASVS V5's key changes: level rebalancing cut Level 1 requirements from ~130 to a more accessible set, dropped the architecture chapter...
What we can learn from the World's Biggest Heists
Three heists, Axie Infinity's Ronin bridge ($625M), Bybit ($1.5B), and the Louvre (€100M+ in jewelry), all succeeded through phishing, poor credential hygien...