Flatline vs. Recovery: Responding to Ransomware Attacks on Healthcare

Few word combinations are more dreadful than “ransomware” and “healthcare.” Despite countless hours and substantial investment, we see it more and more — not less. News outlets and cybersecurity blogs offer tips to “prevent,” “detect,” and “recover”; warn that “it’s not a matter of if, but when”; yet many still struggle to turn that guidance […]

Vishing At Scale: Humans vs. Voice Agents

Over the past several years, I’ve run more than a thousand human-to-human vishing calls. Now I’m conducting the same operations with fully automated voice agents, at scale, across F500 and government targets. This presentation is the before/after: humans versus voice agents in real operations. Not a controlled academic study, that’s not how internal red teams […]

PQCmigration in practice: learnings from 7 organizations

With awareness on the quantum threat to cryptography finally rising, many are looking for experience on migrating to quantum safe cryptography. In our PQC workgroup, seven wildly different companies cooperate to build this experience together. In this talk we teach you what we learned by experimenting. Specifically we talk about our inventory Proof of Concepts, […]

Secure Apps in Mythos Era: Find Gaps Before Attackers Do

Frontier AI models are increasingly capable of discovering and exploiting software weaknesses, prompting calls for more defensive preparedness and responsible release strategies. In this session, we translate that urgency into a practical, security-first approach to LLM penetration testing for real enterprise deployments.You will learn how to scope an LLM pentest beyond the model itself, covering […]

CTI Pubquiz

Back by popular demand from CTI and RUMINT enthusiasts: the CTI pubquiz! Are you able to claim the fame of most dedicated cyber doomscroller of this year? How many DDoS-attacks occur daily, which actor was able to remain hidden? Are you able to tell how many versions of breachforums were taken down last year? These […]

0-Day SharePoint Exploitation: Responding to the unknown

This session unpacks the SharePoint Toolshell campaign as a case study in modern 0-day exploitation, walking through the tactics, techniques, and procedures observed in a real incident. From there, we broaden the lens: what does Toolshell teach us about responding to campaigns in the first 72 hours when activity is “unknown”? Attendees will leave with […]

VShell: Tracking a State-Actor C2 Framework in the Wild

VShell is a post-exploitation command and control framework increasingly observed in intrusions targeting government and critical infrastructure sectors. Following NVISO’s initial research and publication, we continued tracking VShell infrastructure globally to understand how it is deployed and operated by state-linked threat actors. This session opens with a concise technical overview of VShell: how it works […]

We did everything right and still got owned by an APT

In the first half of 2026, the SOC of one of our customers discovered odd user behaviour on a sensitive server and started to investigate. That investigation lead to investigation of a authentication bypass and eventually a sophisticated and persistent attack of an edge device (F5) and the services offered though it. In this session […]

From Radar to Roadmap: High-Tech Product Security

Standard security foresight tools were built for enterprise IT — not for products with 15-year lifecycles, tightly coupled hardware-software architectures, and supply chains where a single compromise can impact thousands of devices. This session presents two complementary instruments developed by the Brabant House of Cyber (BHoC): the Product Security Innovation Radar, a structured prioritization methodology […]

The Evolution of Adversarial AI in Cyber Operations

The integration of Generative AI into the cyber threat landscape is a story of gradual evolution rather than immediate revolution. Moving beyond speculative “super-malware” discourse, current intelligence reveals a nuanced reality: adversaries are maturing and experimenting in lockstep with the industry. This session dissects how state-sponsored APTs and financially motivated actors are using AI to […]