SEC536: Adversarial AI - Penetration Testing AI Systems

In-Person
In-Person
In-Person
Cyber security is going through changes…perhaps the biggest changes James has witnessed in 20+ years. AI, geopolitics, and more diverse targeting such as OT environments are rapidly rewriting the rule book for the industry. The hype is unrelenting and for many, the associated fatigue, too. James will break down the critical risks ahead and what is changing. The good news? We have the talent and tools to fight back, and the cyber community remains our strongest weapon. Join us to uncover how we can make the lives of cyber criminals miserable.
James Lyne, Chief Executive Officer – SANS Institute
In-Person
Operating an AI agent inside a live operational technology (OT) environment is fundamentally different from testing a web application. When the target is critical infrastructure, safety, operational context, and physical consequences become the defining constraints. In this session, David shares the story of taking an Agentic AI Red Teamer beyond the lab and preparing it for deployment in a real wind farm, revealing how it was tuned to understand the environment, reason through IT and OT systems, and behave like a real adversary while operating within strict safety boundaries. How did the agent approach its objective, map remote access and control paths and identify operational leverage? Where did it require human approval, what did find, and what did it refuse to do when the safety context changed? Join us to understand what agentic AI red teaming looks like when the objective has real-world physical consequences and safety is the first constraint, not an afterthought.
David Mound, Head of Research – Shinobi Security
In-Person
In-Person
In-Person
Sandworm has increasingly used trojanised software installers to compromise targets in Ukraine, turning trusted applications into malware delivery mechanisms. This session shares new research from Proofpoint, including the discovery of a previously unreported Go-based version of the Kalambur backdoor. Through real-world investigations, you'll learn how these campaigns were uncovered, the techniques Sandworm uses for espionage and disruptive operations, and the practical analysis methods that led to the discovery of new infrastructure and malware.
Tom Padden, Principle Intelligence Analyst – BAE Systems
Famous Chollima, the North Korean threat actor behind the Contagious Interview campaign, has spent years targeting Web3 and cryptocurrency developers through recruiter-themed social engineering and trojanised coding assessments. Based on two years of research spanning more than 2,000 malicious repositories and campaign variants, Parthiban examines how the group continuously evolved its obfuscation techniques, infrastructure, and infection chains in response to public reporting and disruption efforts. Join us to explore how Famous Chollima has evolved its tradecraft over the past two years, through real-world artifacts, code snippets, infrastructure examples, and campaign timelines practical hunting and detection techniques.
Parthiban Rajendran, Threat Intelligence Lead – Atlassian
Shiva Palaniappan, Assistant Vice President – DBS Bank
AI is transforming vulnerability discovery, enabling security teams to identify weaknesses faster than ever before. But as discovery accelerates, a new challenge has emerged: How do organisations prioritise and remediate vulnerabilities at the same pace? This session explores why traditional vulnerability management approaches are struggling to keep up with AI-driven discovery. It identifies what organisations must do to close the growing remediation gap. The practical approaches to risk prioritisation, exposure management, and scalable remediation workflows will be examined. What are the strategies for adapting vulnerability management to the AI era, reducing risk, and improving remediation outcomes in increasingly complex environments?
Sylvain Cortes, VP Strategy – Hackuity
In-Person
What began as the investigation of a single compromised government IIS server uncovered a much larger espionage campaign. In this session, Roey will share the forensic investigation into Ink Dragon, a Chinese threat actor targeting government and telecommunications organisations across Southeast Asia and Europe, revealing how trusted infrastructure was used to conceal a multi-victim operational network. Join us to follow the investigation as it unfolded, from the initial compromise and lateral movement to the discovery of an IIS-based ShadowPad relay and additional victims. Through technical findings, malware analysis, memory forensics, and real-world investigative pivots, you will gain insight into the process behind uncovering a live espionage campaign and the techniques used to expand visibility beyond a single incident.
Roey Gideon Shua, Security Researcher - Check Point Software
In-Person
Russian state-sponsored threat actors are shifting from malware to identity-focused attacks, using techniques such as adversary-in-the-middle (AiTM) phishing, Device Code abuse, and code phishing to compromise accounts without relying on passwords. Based on previously unreported investigations by Proofpoint, this session reveals how actors including UNK_SnakeBite and UNK_AcademicFlare build trust with targets, steal identities, and gain persistent access. You'll learn how these campaigns work, why they're effective, and the practical detection and defence strategies organisations can use to stop them.
Mark Kelly, Staff Research Operator - Proofpoint
In-Person
Russia’s full-scale invasion of Ukraine marked a turning point in the role of cyber operations in modern conflict. Cyberattacks have become a strategic instrument of warfare, supporting military objectives while targeting critical infrastructure, government institutions, and essential national services. In this keynote, Ivan Kalabashkin will examine the evolving cyber threat landscape and Ukraine’s response to sustained nation-state cyber aggression. Drawing on Ukraine’s experience in detecting and responding to more than 16,000 cyberattacks and incidents, the keynote will explore how these events have shaped the country’s approach to cyber resilience. What are the key lessons learned from defending against sustained cyber warfare? How do these experiences continue to inform Ukraine’s national cybersecurity strategy and resilience efforts?
Ivan Kalabashkin, Deputy Head of Directorate – Security Service of Ukraine
In-Person
In-Person
In-Person
Maciej Siciarek, Director of CSIRT Division - NASK
BlueNoroff has evolved its social engineering tactics into highly convincing, media-driven campaigns capable of compromising even security-conscious organisations. This session will examine a real-world investigation into one of the group's fake meeting operations, revealing how carefully crafted deception, AI-generated content and rapid post-compromise activity combine to create an effective attack chain. Drawing on forensic evidence and threat intelligence, Eoin will take you inside the campaign, exploring how the attack unfolded, the tactics employed by the threat actor, and the methods used to deceive and compromise victims. The session will examine the evolution of modern social engineering techniques and the challenges they present to defenders. How do these campaigns operate in practice? How can you recognise the warning signs of similar attacks? What are the key considerations for improving detection, response and organisational resilience against increasingly sophisticated threat actors?
Eoin Healy, Principle Threat Researcher - Arctic Wolf
Satellite receivers are often overlooked as a security risk, yet they present a unique and increasingly relevant attack surface. How would you approach a satellite receiver from an offensive security perspective? How would you extract the firmware, identify exposed interfaces, assess the RF attack surface, and uncover the weaknesses that can lead to compromise? Through practical examples and a live demonstration, you will gain insight into the end-to-end process of identifying and exploiting vulnerabilities in a real satellite receiver. Whether you are new to hardware hacking or looking to expand your offensive security skillset, this session will provide a practical framework for approaching embedded devices, along with techniques and lessons that can be applied to hardware security assessments more broadly.
Salman Shakeep Abulatif, Cybersecurity Consultant - ISKRA Protect
Telegram has become a key platform for cybercriminals to coordinate scams and process fraudulent payments at scale. But how do these payment ecosystems operate, and how can defenders identify and disrupt them? Through a real-world case study, this session explores the infrastructure behind Russian-language Telegram payment gates, revealing the techniques used to map scam networks, trace payment flows, and uncover links between fraudulent operations using OSINT and threat intelligence. You will leave with practical methods for investigating scam payment infrastructure, extracting actionable intelligence, and Improving detection and defensive reporting.
Adrian Dacka, Penetration Tester – Independent Security Researcher
Cybersecurity practitioners are increasingly required to make critical decisions in environments shaped by uncertainty, evolving technologies, and rapidly changing threats. How are you to make effective decisions when the information is incomplete, dependencies are constantly shifting, and traditional planning no longer provides the answers? In this session, we will explore how making sense of complexity can help security leaders navigate today's most challenging cyber problems, from AI governance and post-quantum readiness to supply chain risk and multi-vendor ecosystems. Drawing on real-world experience, Anne will examine why treating complex challenges as merely complicated can lead to brittle decisions, and how alternative approaches can improve resilience and adaptability.
Anne Leslie, Head of Cloud Risk - IBM
As AI agents become embedded across organisations, the boundaries between human and machine identities are becoming increasingly difficult to distinguish. New opportunities are created for attackers to exploit trusted systems. How can organisations secure identities in a workforce where humans and AI operate side by side? Drawing on research and a supply chain case study, Anna will explore the emerging risks of human-AI identity, examining how compromised AI credentials can evade detection and enable lateral movement across enterprise environments. What are the practical approaches to strengthening identity governance? How is anomalous AI behaviour detected?
Anna Lena Fehlhaber, Technology Strategy Lead AI/Cyber Security - Leibniz Universität Hannover
Some of the most significant OT cyber-attacks have achieved their objectives by abusing legitimate OT functionality rather than exploiting software vulnerabilities. As OT systems become increasingly connected and state-backed actors continue to target critical infrastructure, understanding this growing attack surface has never been more important. This session introduces the concept of Living Off the Plant (LOTP) and explores how adversaries leverage native OT functionality to enable stealthy cyber-physical attacks that traditional IT techniques cannot achieve. Join us to examine how LOTP challenges conventional OT security practices. Why can legitimate engineering activity be difficult to distinguish from malicious behaviour? What does this mean for modern OT threat modelling? You will gain a deeper understanding of engineering-focused attack techniques, the role of engineering expertise in OT cybersecurity, and the limitations of existing security controls against adversaries abusing native OT functionality.
Ric Derbyshire, Principal Security Researcher - Orange Cyberdefense
A journey over the last 15yrs looking at the evolution of state actors examining the impact of disruptive action, how the dependency of core malware has changed, the emergence of external support and what the future might look like. From the famous APT1 report through to criminal support to start via election interference and hijacking crime actor infrastructure. How did we get from in-house rigid malware families to disposable malware? Key events have accelerated the evolution of state actors, whether that be disclosures, take downs or world events, but what impact did these events have? What lessons might we learn from this and what should we expect from the future?