AI in the kill chAIn: a new frontier of digital threats?

This talk will provide an insight in how artificial intelligence is influencing the digital threat landscape. It will examine real-life cases of how threat actors utilize AI in different parts of the cyber kill chain. The examples show how certain parts of the kill chain are being automated, run more efficiently and sometimes even replaced […]

ENISA Scales EU Vulnerability Services for Resilience

As the Cyber Resilience Act’s reporting obligations begin to apply and ENISA rolls out the Single Reporting Platform, this session offers a timely deep dive into vulnerability handling and reporting in Europe. It will explore how ENISA is scaling its EU Vulnerability Services, including the European Vulnerability Database (EUVD), support to Member States’ coordinated vulnerability […]

Strange <marquee> vectors, serious infrastructure impact

A wifi name rooting your router. A TLS certificate field taking over hosting accounts. A DNS response taking down a European network. Not your everyday injection vector, and easy to miss in security review. I spent the past year putting injection payloads into every protocol field I can control as an infrastructure operator: TLS certificates, […]

Storage Spoofing – where digital and physical crime meet

This presentation is hosted by a chemical company and a team of the Dutch police. We showcase an ongoing crime where cybersecurity and physical crime blend, in the world of Rotterdam’s oil and chemical storage. It starts with the tracking of a very persistent threat actor who uses domain typosquatting and near perfect BEC fraud […]

Beneath Arrakis:Unmasking Hydra Saiga’s Covert Operation

On a desert world, Hydra Saiga mines “spicetelligence” from government, defense, and infrastructure targets across Central Asia, the Middle East, and Eastern Europe. This APT aligns with its sponsor’s geopolitical interests—specifically water and gas strategy—while largely evading Western scrutiny. We will explore their TTPs and targets using a custom tool that intercepts the actor’s Telegram-as-a-C2 […]

Police Hack and Pass-the-Cookie: No Crumbs, Full Access

In September 2024, The Netherlands police faced a data breach in which the Russian state-supported threat actor Laundy Bear gained access to the corporate address book. This presentation gives insight into how the attack occurred, how the High Tech Crime Team and the Public Prosecution Service responded and lessons learned.

Security Innovation Lab for OT: from innovation-silo’s to the SILO-collaboration.

The Security Innovation LAB for OT (SILO) brings the critical infrastructure in the Netherlands two major innovation shifts. Namely shaping the innovation agenda within the critical sectors of the OT domain and it provides a solution for a programmatic approach to cyber innovation. This calls for cooperation. In this session the NCSC, TNO and the […]

BEC Deep Dive: The New Cyclotron Technical Standard

Business Email Compromise (BEC) remains a critical threat to the Dutch economy, often bypassing traditional security measures with ease. This session provides an exclusive technical deep dive into the upcoming BEC defensive standard developed under the Cyclotron program—a high-maturity public-private partnership between the NCSC and industry experts, including Attic Security.As a co-author of this forthcoming […]

How to build a world-class Cyber Defense Center

This talk explains how DICTU built a Cyber Defense Center (CDC), basically a next-generation SOC, combining proactive, threat intel-driven defense and offensive capabilities. We will explain this using a medievil theme, so that you can follow along regardless of your background and technical level of expertise. It covers the motivation for building a CDC, its […]