A tale: 3 Spammy boxes – technical deep dive

This session is a technical deepdive of the talk ”Set-top boxes: your personal unwanted proxy”. This talk will dive into our analysis methodology and technical findings from our extensive investigation into shady Android devices flooding the market. In this technical deep dive, we’ll walk you through the entire infection chain of x96mini Android TV boxes […]

Strange <marquee> vectors, serious infrastructure impact

A wifi name rooting your router. A TLS certificate field taking over hosting accounts. A DNS response taking down a European network. Not your everyday injection vector, and easy to miss in security review. I spent the past year putting injection payloads into every protocol field I can control as an infrastructure operator: TLS certificates, […]

Set-top boxes: your personal unwanted proxy

Residential proxies are increasingly used not only for legitimate purposes—such as AI training and secure browsing—but also by cybercriminals and state actors to obscure indicators of compromise and launch large-scale DDoS attacks. The NCSC-NL has observed a sharp rise in such abuse, making attacks harder to detect and mitigate. This presentation first explores NCSC’s research […]

Insecure Vibes: Secure Coding Literacy for Vibe Coders

Vibe coding has a time and a place: it is great for making quick prototypes, and is very tempting for less technical folks. However, those who don’t understand their own code will be blissfully unaware of the many security vulnerabilities that AI assistants can introduce. In this presentation, I will cover a variety of common […]

Unravel Cybercrime: Anti-Phishing and -Ransomware Agenda

Phishing remains the primary entry point for many cyberattacks, enabling access to interconnected criminal ecosystems where no cybercrime occurs in isolation. This session examines how attackers exploit trust layers like DNS, use anonymization technologies, and leverage crypto assets to obscure operations. It highlights the need for a technology agenda that links fragmented signals and rapidly […]

Keynote: Mapping Microsoft: A Tale ofExploration and 200 Vulnerabilities

After 16 years in offensive cybersecurity, presenting at Black Hat USA and becoming a Microsoft Most Valuable Researcher in 2025, Vaisha still felt like an impostor. So, he set himself the goal to become #1 on Microsoft’s Security Researcher leaderboard. This is the tale of how he grinded long nights, exploring a mucky sea of […]

The Ins and Outs of Residential Proxies

Residential proxy networks monetize end-user bandwidth, reselling access to millions of consumer IPs for scraping and, increasingly, abuse. From a network-operator vantage point these flows are hard to characterize: the traffic blends with normal residential activity, and the underlying client software is rarely documented. This talk combines two perspectives on the problem. Through reverse engineering […]

Secure Apps in Mythos Era: Find Gaps Before Attackers Do

Frontier AI models are increasingly capable of discovering and exploiting software weaknesses, prompting calls for more defensive preparedness and responsible release strategies. In this session, we translate that urgency into a practical, security-first approach to LLM penetration testing for real enterprise deployments.You will learn how to scope an LLM pentest beyond the model itself, covering […]

VShell: Tracking a State-Actor C2 Framework in the Wild

VShell is a post-exploitation command and control framework increasingly observed in intrusions targeting government and critical infrastructure sectors. Following NVISO’s initial research and publication, we continued tracking VShell infrastructure globally to understand how it is deployed and operated by state-linked threat actors. This session opens with a concise technical overview of VShell: how it works […]

We did everything right and still got owned by an APT

In the first half of 2026, the SOC of one of our customers discovered odd user behaviour on a sensitive server and started to investigate. That investigation lead to investigation of a authentication bypass and eventually a sophisticated and persistent attack of an edge device (F5) and the services offered though it. In this session […]