Geopolitical Liminality in Cyberspace
“The old world is dying, and the new world struggles to be born: now is the time of monsters.” — Antonio Gramsci Writing from prison, Antonio Gramsci described the world he lived in as liminal and unstable – seeing an old order fade and a new yet to emerge. He called these “times of monsters”: […]
The upcoming Cyber Security Assessment Netherlands 2026
The Cybersecurity Assessment Netherlands (CSAN, CSBN in Dutch) is published annually. It provides insight into digital threats, national security interests, and resilience. The report is produced by the National Coordinator for Counterterrorism and Security (NCTV), in cooperation with public, private, and academic partners. This Talk about the CSAN 2026 will highlight the key findings of […]
Beneath Arrakis:Unmasking Hydra Saiga’s Covert Operation
On a desert world, Hydra Saiga mines “spicetelligence” from government, defense, and infrastructure targets across Central Asia, the Middle East, and Eastern Europe. This APT aligns with its sponsor’s geopolitical interests—specifically water and gas strategy—while largely evading Western scrutiny. We will explore their TTPs and targets using a custom tool that intercepts the actor’s Telegram-as-a-C2 […]
Lessons from recent Cyber Threat Disruption Operations
Non-profit organization The Shadowserver Foundation is the world’s largest provider of free cyber threat intelligence. For the past 15+ years they have worked quietly behind the scenes to support Law Enforcement, nCSIRTs and private industry partners in some of the most significant cyber threat disruptions operations, notifying victims and providing remediation data. Shadowserver will share […]
The Zero-Day Dilemma: Why Attacks are Increasing and How to Fight Back
The number of zero-day attacks is increasing, posing a significant challenge for organizational defense. What are the underlying drivers of this growth, and how can organizations optimize their defenses to mitigate these threats effectively?
The good, the bad, and STIX/TAXII
Standards are essential; without them, the internet would not exist. In open source, organisations like the Linux Foundation drive such standards, as seen with OpenTelemetry, now widely adopted despite early scepticism. In cybersecurity, STIX/TAXII plays a similar role. Though often criticised, it remains vital, particularly for cyber threat intelligence and detection rule sharing. Its value […]
What Yesterday’s Cyber Ops Tell Us About Tomorrow
1. Opening: Europe on the digital frontline: from spillover to systemic exposure 2. The DynoWiper case (Poland, 2025): destructive cyber as strategic signalling 3. From cyber to hybrid warfare: the convergence of cyber, AI, drones and information operations 4. The Ukraine doctrine: how Sandworm operationalised cyber as a wartime capability 5. Spillover into the EU: […]
Geopolitical Resilience: A Central Bank Perspective
Geopolitical tensions increasingly materialise in the cyber domain, directly affecting financial stability, critical infrastructures and public institutions. For central banks, this creates a unique resilience challenge that spans monetary policy, financial supervision and internal operations.
The hype is killing kittens, but not that grumpy old cat
In this session, we take a step back from the hype cycle and look at security through a longer, vintage, grumpy old hackers lens. From the early days of classic computer hacks to the evolution of modern vulnerability research, we revisit the techniques, mindsets, the breakthroughs and the people responsible for those, with a focus […]
The Evolution of Adversarial AI in Cyber Operations
The integration of Generative AI into the cyber threat landscape is a story of gradual evolution rather than immediate revolution. Moving beyond speculative “super-malware” discourse, current intelligence reveals a nuanced reality: adversaries are maturing and experimenting in lockstep with the industry. This session dissects how state-sponsored APTs and financially motivated actors are using AI to […]