• Most recent
  • Conferences
  • For organizers
  • The rig
  • Buy me a Mate
  • Search
  • Fundraiser
  • Bluesky
  • 2026
  • 2025
  • 2024
Edition logo

BSides Prague 2026

2026-04-23 - 2026-04-24
  • Video not yet published
    Opening Talk
    - Martin Hron
  • Video not yet published
    Do Not Build The Torment Nexus
    - Eva Galperin
  • Video not yet published
    From Prompt To Pwn: Abusing Browser Small Language Models
    - Eyal Arazi
  • Video not yet published
    Adventures In Router Firmware Through Dynamic Taint Analysis
    - Ravshan Rikhsiev
  • Video not yet published
    JA3/JA4+ Hashes: A "Secret" Fingerprint Identifying Bots And Scrapers
    - Miloslav Homer
  • Video not yet published
    Building Deception At Scale: Automating Honeypots With Autonomous AI Agents
    - Yotam Perkal & Gil Maman
  • Video not yet published
    Malware Evasion: Packers, Loaders, And Why Your EDR Misses Them
    - Massimo Bertocchi
  • Video not yet published
    Prompt, Pwn, Profit: A $30k Deep Dive Into AI Agent Vulnerabilities
    - Vasyl Spachynskyi
  • Video not yet published
    Exploit Is In The Logic: Reversing An Android Application To Hack Transactions On An NFC Tag
    - Luigi Gubello
  • Video not yet published
    Harder, Better, Faster, Stronger: Because "FROM Ubuntu:latest" Is A Supply-Chain Horror Story
    - Vojtech Trcka
  • Video not yet published
    How Infostealers Slipped Through EDRs: Process Doppleganging By IDAT Loader For Over 18 Months
    - Niranjan Jayanand & Archana Manoharan
  • Video not yet published
    Inside The Fortress: Attacking RFID Access Control Systems
    - Marco Sanchez
  • Video not yet published
    The CSI Hijack: Default Kubernetes Storage Drivers Exploitation
    - Shaul Ben Hai and Karan Bamal & Idan Nagar
  • Video not yet published
    Ghost In The Script: Impersonating Google App Script Projects For Stealthy Persistence
    - Bleon Proko & Jakub Pavlík
  • Video not yet published
    Cloud Agent To Physical Access: How Cursor Unlocked My Front Door
    - Roi Nisimi & Ari Marzuk
  • Video not yet published
    (Security) Operations Fuckups
    - Nicol Daňková
  • Video not yet published
    Blind The Kernel: Subverting Integrity Checks Via Semantic Asymmetry
    - Tejaswini Sandapolla
  • Video not yet published
    Hunting Malicious Domains At Scale With AI-Augmented OSINT
    - Zohar Buber
  • Video not yet published
    The Forgotten Fingerprint: OSINT Through DNS TXT Record Analysis
    - Rishi C.
  • Video not yet published
    Who Defends The Defenders? EDR Killers Landscape Boom
    - Tomáš Zvara & Radek Jizba
  • Video not yet published
    CLOSING KEYNOTE
    - Louis Nyffenegger
  • Video not yet published
    Closing Day 1
    - Martin Hron
  • Video will not be published
    Opening Day 2
    - Martin Hron
  • Video not yet published
    Role Of Security Expert During Cognitive Revolution
    - Dmitrijs Trizna
  • Video not yet published
    The Agents Of Chaos: AI Driven Malware Generation
    - Arad Donenfeld
  • Video not yet published
    Breaching The Perimeter: The Forgotten Attack Vector That Always Works
    - Jiří Vaněk & Chris Cowling
  • Video not yet published
    Forked And Owned: Taking Over GitHub Repositories Via A Single Pull Request
    - Roi Nisimi & Ari Marzuk
  • Video not yet published
    Abusing The Ordinary: New COM-Based Windows Attack Vectors
    - Marco Balzarin
  • Video not yet published
    Mad Data Science For Practical C2 Detection - The Talk
    - David Szili & Eva Szilagyi
  • Video not yet published
    1 Click, 0 Warnings: Hijacking Mic, Camera & GPS Via Browser UI Blindspots
    - Armaan Pathan
  • Video not yet published
    Painless IOS App Pentesting
    - Khayal Farzaliyev
  • Video not yet published
    Beyond Classic Detections: Unlocking The Full Potential Of EDR Telemetry
    - Dylan Guerville
  • Video not yet published
    What An "Exploitable CVE" Really Means: Moving Beyond CVSS Scores
    - Eryx Paredes
  • Video not yet published
    Uncovering SAP BTP Attack Vectors, Before Someone Else Does!
    - Waseem Ajrab
  • Video not yet published
    Decoding Chinese State-Sponsored Cyber Activity: Behavioral Models For Early Detection And Effective Threat Hunting
    - Nathaniel Jones
  • Video not yet published
    LLMs For Vulnerability Fixing: Hype Or Reality?
    - Edouard Viot
  • Video not yet published
    LazarOps: APT Tactics Targeting The Developers Supply Chain
    - Diogo Machado
  • Video not yet published
    From Input To Impact: Prompt Injection In Production Pipelines
    - Mackenzie Jackson
  • Video not yet published
    Call Me By Your [User]Name: Modern Identity-Centric Attacks
    - Lucie Kadlecova
  • Video not yet published
    RTFM - Read The Fatal Manual: When Documentation Creates Critical Misconfiguration
    - Martin Sohn Christensen
  • Video not yet published
    So You Want To Write A Book? Writing About AI Security For No Starch Press
    - Harriet Farlow
  • Video not yet published
    Closing Bsides 2026
    - Martin Hron
  • Video not yet published
    Airport Security! - S01 E008: Breaking Into Your Baggage
    - Héctor Cuevas Cruz
  • Video not yet published
    Last Night A DJ Erased My Drive
    - Mathew Caplan
  • Video will not be published
    The Great Train Robbery: Hacking Like It’s 1855
    - Paul Zenker