HITCON 2026 – Call for Papers Website is Now Open!
The theme for HITCON this year is 'When AI Acts: Hacking the Age of Agentic Systems.' Our Call for Papers is now open—we look forward to your submissions!"
We’re accepting submissions in two categories this year.
Check out all the details and submit your talk here ⬇️
📪 Submission Website: https://t.co/jVGUEqK0u0
1. Lectures focusing on cutting-edge infosec research:
- 40 minute-session inc. Q & A
- focus on innovative technical deep-dive
- ranked by novelty, technical depth, and practicality
2. Tutorial sessions for cybersec beginners (Hacking 101):
- 80 minute-session inc. 10–20 minute break
- focus on educational aspects
- ranked by educational value, practicality, and ease of understanding
【Important Dates 📅】
- CFP starts: today
- CFP closes: May 3, 2026 (Anywhere on Earth)
- Notification to Submitters: May 17, 2026 (for those who agreed to AI Review Assistant); May 24, 2026 (all other submissions)
- Event date: August 21 - August 22, 2026
For any questions, please email [email protected].
We look forward to your brilliant presentations at HITCON 2026 🤩
#HITCON #HITCON2026 #CFP #CallForPapers #AI
📢 The FLARE team has launched the FLARE Learning Hub - a free resource to hone your malware analysis and reverse engineering skills!
🛠️ https://t.co/PUHq3IQqV4
The initial launch brings with it:
- An in-depth introduction to time-travel debugging (TTD)
- A comprehensive Go language reference
- An assembly crash course
For a deeper look into this zero-day vulnerability, including the full root-cause analysis, proof of concept, exploitation, and patch analysis, check out our newly published blog post: https://t.co/RAXSg0f1iv
And another finding for AI Pentest! This time on Astro (57.1k stars)
Host header injection → HTTP redirect → full-read SSRF, writeup by the GOAT @J0R1AN
CVE-2026-25545
advisory: https://t.co/H7XHlLvyf8
blog post: https://t.co/45lPcdZDk7
More to come 😉
Malware Development course update 21 released!
https://t.co/67X8yADBsY
- Introduction To Windows Persistence
- Persistence Via The Windows Registry
- Persistence Via The File System
- Persistence Via Windows Services
- Persistence Via Windows Tasks
- Persistence Via WMI Abuse
- Persistence Via COM Object Hijacking
- Persistence Via Electron Applications
The State of AI Security
- https://t.co/L7Lh71fzRg
AI security report provides a comprehensive analysis of the latest developments across AI threat intelligence, global policy, standards, research, and more.
Want to run your compiled Mach-O payloads directly from memory without worrying if they'll be detected or captured? 😈
🔥 New blog post:
"Reflective Code Loading on macOS (Part II)"
https://t.co/ZfOjG1Quvq
macOS 26? ✔️
Objective-C payloads? ✔️
Detection ideas (limited)? ✔️
#ESETresearch discovered unique toolset, we named QuietEnvelope, targeting the MailGates email protection system of Taiwanese company OpenFind. The toolset was uploaded in anarchive, named spam_log.7z, to VirusTotal from Taiwan 🇹🇼. It contains Perl scripts, three stealthy passive backdoors, an argument runner, and miscellaneous files. 1/7
I’ll be at CODE BLUE tomorrow. Check out our Cyber Range Exercise if you’re interested, and feel free to come say hi if you want to chat
https://t.co/PMyIoD16O0
Boom! YingMuo (@YingMuo), HexRabbit (@h3xr4bb1t), LJP (@ljp_tw) from DEVCORE Research Team and nella17 (@nella17tw) from the DEVCORE Intern Program needed little time to exploit the QNAP TS-453E NAS device. They head off to the disclosure room to provide details. #Pwn2Own
A great write-up of a VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-
20869) exploit by Alex Zaviyalov has just been published!
Cisco Talos researcher Joey Chen discloses details of UAT-8099, a Chinese-speaking cybercrime group mainly involved in search engine optimization (SEO) fraud and theft of high-value credentials, configuration files, and certificate data. https://t.co/Hy8aN9yEyL
Checkout the Post-Mortem of our system ARTIPHISHELL (by @degrigis and I)! We look at a few issues that kept @shellphish from a top-3 spot in @DARPA’s AIxCC:
https://t.co/PO4mL2JPsX
Keep your eyes out for more ARTIPHISHELL content in the future!