Topics
Cross-conference discovery. Pick a topic to see every talk on it.
Breaking into systems on purpose — pentesters, red teamers, and exploit researchers sharing what actually works in the field.
- penetration testing
- red teaming
- exploit development
- vulnerability research
- bug bounty
- social engineering
- +8
Catching attackers in your environment — detection engineering, SOC operations, incident response, threat hunting, and forensics.
- blue teaming
- detection engineering
- SOC operations
- incident response
- threat hunting
- SIEM
- +11
Securing the software you build — from threat modeling and secure SDLC to SAST/DAST, API security, and software supply-chain defense.
- threat modeling
- secure SDLC
- SSDLC
- SAST
- DAST
- SCA
- +14
Securing AWS, Azure, GCP, and cloud-native stacks — covering CSPM, container and Kubernetes security, cloud IAM, and DSPM.
- AWS security
- Azure security
- GCP security
- cloud-native security
- CSPM
- CWPP
- +13
Attacking and defending AI systems — prompt injection, jailbreaks, AI red teaming, agent security, guardrails, and AI-supply-chain risk.
- LLM security
- prompt injection
- jailbreaking
- AI red teaming
- model poisoning
- training data attacks
- +9
Who can do what, and how you prove it — IAM, zero trust, OAuth/OIDC/SAML, passkeys, Active Directory, Entra ID, PAM, and ITDR.
- IAM
- zero trust
- authentication
- authorization
- OAuth
- OIDC
- +14
Tracking the adversary and the tools they use — malware analysis, reverse engineering, APT tracking, ransomware, and CTI workflows.
- malware analysis
- reverse engineering
- threat intelligence
- CTI
- threat feeds
- IOC analysis
- +14
Applied and post-quantum cryptography in practice — TLS/PKI, key management, cryptographic attacks, ZK proofs, and blockchain security.
- applied cryptography
- post-quantum cryptography
- TLS
- SSL
- PKI
- certificate management
- +13
Defending the wires, the boxes, and the protocols — network security, IDS/IPS, DNS/BGP, ICS/SCADA/OT, firmware, and hardware hacking.
- network security
- firewall
- IDS
- IPS
- VPN
- network segmentation
- +15
Running a defensible program on paper as well as in practice — frameworks, compliance regimes, third-party risk, and privacy engineering.
- NIST
- ISO 27001
- CIS
- SOC2
- PCI-DSS
- HIPAA
- +15
Building and running a security org — CISO strategy, hiring, culture, executive communication, and security architecture at scale.
- CISO strategy
- security program building
- security budgeting
- security hiring
- team building
- security culture
- +9
Phones, things, and the firmware they run on — Android/iOS, IoT protocols, automotive, medical, and industrial device security.
- mobile application security
- Android security
- iOS security
- mobile malware
- MDM
- IoT security
- +13