๐ฅ The #TheSAS2026 agenda is live: https://t.co/CZ6o6VjFSB
Browse the sessions, plan your route, then hit REGISTER if you havenโt already. ๐
Yes, thereโs still some chaos. A few timings and details may still shift. No, thatโs not unusual when active research and fresh findings are involved.
A couple of talks will be revealed closer to the event while vulnerability fixes are still in progress.
See you in ๐ด Jimbaran Bay!
๐งญ Security gets very real when the map stops being useful.
That's the premise behind "Chaos, Cliffs & Trust - Forging Security Beyond the Grid" at #TheSAS2026, featuring Geraldine Fasnacht (@ggfasnacht) and Eugene Kaspersky (@e_kaspersky).
Geraldine is a freeride and BASE-jumping pioneer with landmark descents on the Matterhorn, Grandes Jorasses, Grand Combin, and remote lines in Antarctica and Baffin Island. Eugene has his own extreme-environment credentials, including multiple volcanic expeditions, the South Pole, and Antarctic isolation.
They'll hold a conversation about what happens when the handbook stops helping: how you read chaos, make decisions under pressure, and build trust when the environment is hostile, fast-moving, and unforgiving.
A different kind of keynote, but very relevant for security teams.
๐ด Secure your spot: https://t.co/cVsRzXM8OX
โ๏ธ Time is running up to register and attend #TheSAS2026 https://t.co/CZ6o6VjFSB
๐ฏ Check out our rock-and-roll agenda and speaker lineup https://t.co/mW0KVMs084
๐ฏ Have a look at the event venue https://t.co/JhV13TVpQd
๐ฏ Remember the CTF https://t.co/Dp8wSMsxpq
๐ฏ And watch a brief video from last year https://t.co/58hjjtBHnF to help you decide!
Don't miss it!
Your AI coding agent could be fully compromised before the model even reads a single prompt. At #TheSAS2026, Satoki Tsuji (@satoki00), CEO of Ikotas Labs, will unveil Agent2Shell - a family of 0day RCE chains against the three flagship AI coding agents. Every chain fires before any prompt reaches the model, so prompt injection defenses and guardrails can't help here.
Responsibly disclosed and under coordinated embargo, this session is the first comprehensive deep dive on the full research set.
๐ Full agenda and registration: https://t.co/bNUPXSV9BC
๐ด Day 2 of #TheSAS2026 is leaving the dark conference room on purpose. We're pushing the cybersecurity conference anarchy a notch further and are taking the action to a beach club. Expect a chill geek picnic with CTF challenges and lightning talks - relaxed setting, very real topics.
Featured speakers include Peter Geissler (@blasty) and Ignacio Navarro (@IgNavarro1), with talks touching LLM "force multipliers" in cybersecurity and smart transportation system hacking.
A little more relaxed, not one bit less serious.
Join us: https://t.co/CZ6o6VjFSB
๐ฐ A $15M cyber heist doesn't necessarily start with top-notch malware. Sometimes it starts with compromised home and SMB routers.
At #TheSAS2026, Jefferson Macedo (@cybersec_jeff), Founder and Technical Director of PurpleBird Security and former lead across IR and security teams at Capgemini, IBM X-Force, and Kroll, will reconstruct a multistage attack campaign that moved from rudimentary network intrusions, physical implants, and unauthorized access to remote branches into a highly effective social engineering operation.
๐ Full agenda and registration: https://t.co/mW0KVMs084
๐งฑ The opening #TheSAS2026 talk covers a sophisticated campaign against diplomatic organizations involving a UEFI bootkit dubbed BlackX by Kaspersky researchers. Georgy Kucherin (@kucher1n) will walk us through the full chain: installation, kernel-mode staging, user-mode payload delivery, and the attribution clues.
So, mark "Painting Graffiti on UEFI Walls" in your calendars. Georgy's prior work spans major investigations into FinFisher, APT41, and Lazarus, and this session promises both the internals and the defensive takeaways (including practical guidance for protecting networks against UEFI bootkits).
๐ซ Secure your spot, register today! https://t.co/cVsRzXM8OX
๐ฏ APT research gets especially interesting when the operators forget basic OPSEC.
Prajwal Awasthi, Threat Intelligence Analyst at CloudSEK, brings one such case to #TheSAS2026.
His talk "No OPSEC, No Problem: Inside Transparent Tribe" centers on an undocumented APT36 C2 framework discovered while it was being built. This offers a rare, hilarious and informative look at adversary workflow.
โ๏ธ Join us to see it live: https://t.co/cVsRzXM8OX
๐ค You AI coding agents are reopening a huge attack surface, and we're not talking about malicious prompts or sneaky MCPs. A 90s-era issue will bite you - a local loopback.
At #TheSAS2026, Abdel Adim "smaury" Oisfi (@smaury92), co-founder of Shielder, will show how a Google Antigravity 0-day turned an unauthenticated DNS rebinding bug into RCE by leaking an agent's CSRF token and language server port.
And it's becoming a dangerous norm: local dev servers, MCP servers, agent managers, vibe-coded apps - all piled onto loopback, all assuming neighboring processes are friendly.
If browser internals, appsec, and old bug classes with very modern consequences are your thing, don't miss this one.
Last seats are going out fast, take yours this week: https://t.co/cVsRzXM8OX
๐ฏ You canโt really run a security conference without fresh Lazarus tradecraft.
At #TheSAS2026, Sojun Ryu (@hypen1117) brings:
"Break the Security, Defy the Control: Inside Lazarus' Operation FlashHole"
The research analyzes a new Lazarus campaign targeting South Korea, built around a modular malware framework that appears to spawn from legitimate financial security software, likely delivered via a watering hole. Nearly all components, except the loader, operate only in memory, and the operators used post-quantum cryptography to protect C2 traffic.
โ๏ธ More insights, more APT research, and registration link to see it all live: https://t.co/cVsRzXM8OX
๐ค One sure way to join #TheSAS2026 and share your story with the top cybersecurity community is to become a sponsor! Various options are available, so contact our organizing team to discuss the best way to collaborate.
๐ฅฐ Weโre immensely grateful for the ongoing support and new partnerships from our 2026 sponsors and partners:
๐ซ Gold sponsor AV Comparatives @AV_Comparatives
๐ซ Sister conference SINCON from @infosec_city
๐ซ Media partner Heise Medien
๐ซ Media partner Frontier Enterprise, published by Jicara Media
Join us! https://t.co/ssbNaWv6Fi
๐ค AI for vulnerability research gets more interesting when the target is not GitHub, but the firmware running your phone, TV, and half the IoT aisle.
That's what Dr. Zhiniang Peng (@edwardzpeng) has done. He comes back to SAS with a talk "Breaking the Old Playbook: LLM-Augmented Offense Security Research". His custom harness, combining LLM with a small set of skills and deterministic tools, helped to discover over 110 0days across OPPO, HONOR, Xiaomi, Samsung, and Google ROMs.
If you want signal over AI slogans, come to #TheSAS2026 to see it live: https://t.co/cToU6nJ8za
๐ฎ Another #TheSAS2026 sneak peek, because itโs Friday and games feel appropriate.
But running Doom on tractors is so 2022. Running Linux on a PS5 after a full hypervisor defeat? Better.
Andy Nguyen (@theflow0) will walk through the PS5 security architecture, Sonyโs AMD SVM implementation, and the misconfigurations that can be chained into a complete hypervisor break.
๐ค Catch it live: https://t.co/cToU6nJ8za
๐ The full #TheSAS2026 agenda drops soon! Until then, here's your first confirmed talk:
"Rocket: how an in-the-wild exploit chain broke Apple's last line of defense".
Alfie CG (@alfiecg_dev) will unpack an SPTM bypass found as part of the Coruna exploit kit - one of the year's biggest spyware stories.
Coruna packed 5 full exploit chains and 23 individual exploits affecting iOS 13 through 17 and marked a ugly shift: advanced iPhone exploitation moving beyond state use into criminal ecosystems.
More agenda previews soon!
Secure your seat: https://t.co/cToU6nJ8za
๐ Back-to-school season for some. Full-price season for #TheSAS2026 for everyone else!
Starting tomorrow, attendee passes are no longer at early bird rates.
Today is your final shot at the lower-price full package: conference access, networking, accommodation, and leisure included.
๐ซ Secure your seat NOW: https://t.co/cToU6nJ8za
๐ง Threat hunting and vulnerability research was never supposed to mean constant burnout.
But right now, 2 in 3 cybersecurity researchers say the job is more stressful than it was a few years ago.
It's time to remember why we chose this job - because of curiosity, freedom, some rule-breaking, and awesome hangouts with like-minded hackers.
See, feel, and recall this all at #TheSAS2026
โ๏ธ https://t.co/cToU6nJGoI
๐ฅ This month's Patch Thursday featured a fix for CVE-2026-62815 (CVSS 9.8) - a dangerous RCE vulnerability exploiting the QUIC protocol, reported by Yuki Chen (@guhe120).
That is a useful hint about the level of technical depth behind the #TheSAS2026 program committee and the expected talk quality.
Yuki is part of the committee this year, and if you want to be in the room for serious conversations on vulnerability discovery, reporting, and what today's bug hunting landscape looks like, SAS is the place.
Early bird pricing ends in just a few days: ๐ https://t.co/cVsRzXM8OX
๐ค The training call is open for SINCON 2026, our sister conference by @infosec_city.
They're looking for intensive, hands-on sessions led by experienced practitioners.
The focus are real workflows, usable techniques, and technical depth attendees can take back to their security teams.
If that sounds like your kind of training, submit here: https://t.co/0eC1XDn92g
More on SINCON 2026 Conference: https://t.co/A7jL151uHx
#TheSAS2026