A tale: 3 Spammy boxes – technical deep dive
This session is a technical deepdive of the talk ”Set-top boxes: your personal unwanted proxy”. This talk will dive into our analysis methodology and technical findings from our extensive investigation into shady Android devices flooding the market. In this technical deep dive, we’ll walk you through the entire infection chain of x96mini Android TV boxes […]
ENISA Scales EU Vulnerability Services for Resilience
As the Cyber Resilience Act’s reporting obligations begin to apply and ENISA rolls out the Single Reporting Platform, this session offers a timely deep dive into vulnerability handling and reporting in Europe. It will explore how ENISA is scaling its EU Vulnerability Services, including the European Vulnerability Database (EUVD), support to Member States’ coordinated vulnerability […]
How we accidentally built a nation-scale tracking system
What if tracking someone’s real-time location didn’t require malware or exploits, but just a phone call? In 2026, a critical misconfiguration in a European telco network allowed callers to determine a person’s location without the call being answered, and without leaving meaningful traces. Affecting a large portion of a national subscriber base, this issue exposed […]
Police Hack and Pass-the-Cookie: No Crumbs, Full Access
In September 2024, The Netherlands police faced a data breach in which the Russian state-supported threat actor Laundy Bear gained access to the corporate address book. This presentation gives insight into how the attack occurred, how the High Tech Crime Team and the Public Prosecution Service responded and lessons learned.
BEC Deep Dive: The New Cyclotron Technical Standard
Business Email Compromise (BEC) remains a critical threat to the Dutch economy, often bypassing traditional security measures with ease. This session provides an exclusive technical deep dive into the upcoming BEC defensive standard developed under the Cyclotron program—a high-maturity public-private partnership between the NCSC and industry experts, including Attic Security.As a co-author of this forthcoming […]
Insecure Vibes: Secure Coding Literacy for Vibe Coders
Vibe coding has a time and a place: it is great for making quick prototypes, and is very tempting for less technical folks. However, those who don’t understand their own code will be blissfully unaware of the many security vulnerabilities that AI assistants can introduce. In this presentation, I will cover a variety of common […]
Lessons from recent Cyber Threat Disruption Operations
Non-profit organization The Shadowserver Foundation is the world’s largest provider of free cyber threat intelligence. For the past 15+ years they have worked quietly behind the scenes to support Law Enforcement, nCSIRTs and private industry partners in some of the most significant cyber threat disruptions operations, notifying victims and providing remediation data. Shadowserver will share […]
Sovereignty by Design: Europe’s SaaS Resilience Playbook
Europe’s digital sovereignty agenda is legitimate and necessary. But the market cannot deliver homegrown solutions fast enough — spreading investment too thin risks building a monoculture that makes adversaries’ jobs easier. Meanwhile, Baltic cable sabotage, service termination by decree, and an unpredictable transatlantic relationship have turned theoretical cut-off scenarios into planning realities. This session delivers […]
TaHiTI, threat hunting methodology.
Discover the Power of TaHiTI at ONE Conference AI is accelerating everything—threat discovery, vulnerability disclosure, and attacker adaptation. As timelines between “known” and “exploited” keep collapsing, relying on static detection is no longer enough. In this interactive workshop, we introduce the renewed TaHiTI (Targeted Hunting integrating Threat Intelligence) framework, developed within the Dutch financial sector. […]
Be a better ally.
This talk will provide practical ways on how to become a better ally to underrepresented groups in the field of Cybersecurity. Recent HCSS research shows that a significant share of women in the Netherlands experience frequent feelings of insecurity in public and online spaces, leading to structural behavioral adaptations such as avoidance strategies and continuous […]