-
Opening Remarks
- OWASP Board
-
The Reinvention Of Software Engineering
- Hannah Foxwell
-
AI Explainability Score Card
- Michael Novack
-
Builders & Breakers Part II: Securing
Agentic AI After The Death Of LLM Wrappers
- Javan Rasokat & Rico Komenda
-
Scanning Agentic AI Systems:
Beyond Traditional LLM Red Teaming
- Roman Vainshtein and Amit Giloni & Roy Betser
-
Why Isn't The Fix In My Container?
Tracking CVE Propagation Across 10.000 Projects
- Lior Kaplan & Mor Weinberger
-
Why AppSec Fails At Scale
(And How To Fix It)
- Eduard Thamm
-
Introduction By OWASP MAS Team To MAS Con
- Carlos Holguera & Sven Schleier
-
OpenCRE.org:
Uniting All Standards And Guidelines
- Rob Van Der Veer
-
Let's Get Frooky: Structured Mobile DAST With Frida
- Stefan Bernhardsgrütter & Carlos Holguera
-
OWASP AI Testing Guide In Practice:
Securing LLM Applications
- Matteo Meucci & Marco Morana
-
Authorization Is Where
Your App Goes To Lie
- Eden Yardeni
-
The OWASP Top Ten 2025
- Tanya Janca & Torsten Gigler
-
Actionable Continuous SBOM Diffing
- Pavel Shukhman
-
Admission Of Guilt: I Exploited A Parking System
For A Year (And What It Taught Me About AppSec)
- Dimitar Raichev
-
Unveiling The Internals From
Multiplatform Mobile Runtimes
- Sergi Alvarez
-
Introducing OWASP AGHAST:
AI-Guided Hybrid Application Static Testing
- Josh Grossman
-
The Map Of Artificial Treasures:
What To Automate In Security - And Why?
- Michael Helwig
-
Retiring CVE Chasing: Defending
Against Application Exploit Techniques
- Idan Elor
-
Personal Relevance In The Age Of AI
- Avi Douglen,Grant Ongers,Marisa Fagan,Hannah Foxwell and Gadi Evron
-
One IDE To Rule Them All:
Securing Your Supply Chain’s Weakest Link
- Moshe Siman Tov Bustan & Nir Zadok
-
The Velocity Paradox: Why Slow Is
Smooth And Smooth Is Fast In AppSec
- Pramod Rana
-
Recent Mobile App Security
Incidents From Real-World Cases
- Jan Seredynski
-
OWASP DefectDojo
- Matt Tesauro
-
Meet The New Frida Frontend On The Block
- Ole André Vadla Ravnås
-
OWASP KubeFIM: Detecting File Integrity
Threats With EBPF & AI In Kubernetes
- Abhijit Chatterjee
-
Human Rights Threat Modeling
- Giovanni Corti and Simone Onofri & Luca Lumini
-
This Build Can Break You
Evil Runners And EBPF For Detection
- Reinhard Kugler
-
From 0 To SLSA Level 3:
A Level 3: A Practitioner's Field Guide
- Mark Mishaev
-
Taming The AppSec Data Deluge
- Ben Sleek
-
Attacking ART
- Jeroen Beckers
-
Evil User Stories Modeling: Ensuring Your
User Stories In Agile Playing OWASP Cornucopia
- Grant Ongers & Max Alejandro Gomez Sanchez Vergaray
-
Closure Of Conference By OWASP MAS Team
- Carlos Holguera & Sven Schleier
-
OWASP MCP Top 10: When AI Agents Go Rogue,
Securing The Model Context Protocol
- Vandana Verma Sehgal
-
AI And The Threat Modeling Manifesto:
Conflicts, Failure Modes, And Better Patterns
- Vikramaditya Narayan
-
The Devil Is In The Defaults:
What To Do About XSS
- Frederik Braun
-
Boiling The Ocean For Signal: Lessons
From High-Volume OSS Malware Detection
- Henrik Plate
-
Pragmatic Least-privilege For Cloud And Kubernetes:
Applying Good Advice To Real Systems
- Mark Vinkovits
-
Agile Development And IT Security:
From Conflict To Collaboration
- Juliane Reimann & Elisa Erbe
-
OWASP AI Exchange Showcase
- Rob Van Der Veer and Aruneesh Salhotra & Behnaz Karimi
-
Opening Remarks
- OWASP Board
-
We Live In The Future: The Death
And Rebirth Of Application Security
- Gadi Evron
-
From ASVS To APVS: What Changes When
You Treat Privacy As A System Property?
- Matthew Coles and Kim Wuyts & Avi Douglen
-
DOMination:
Abusing The Permission Model In Web Extensions
- Moshe Siman Tov Bustan & Nir Zadok
-
OWASP AI Security Verification Standard (AISVS)
- Jim Manico,Rico Komenda,Otto Sulin and Russ Memisyazici & Raza Sharif
-
Illegal States Are My Favorite
Security Vulnerability
- Michael Koppman
-
Keep It Between Us: Manipulating
Humans For Better AppSec (Ethically)
- Nariman Aga-Tagiyev
-
When Museums Get Hacked:
OWASP Top 10 Lessons From Heists
- Jose Carlos Chávez
-
From Maturity To Mastery:
Accelerating Software Security With OWASP SAMM
- Sebastien Deelersnyder & Aram Hovsepyan
-
Phishing For Passkeys:
An Analysis Of WebAuthn And CTAP
- Michael Kuckuk
-
Q-Day Is Cancelled: Practical Strategies
To Defeat 'Harvest Now, Decrypt Later'
- Anshu Gupta
-
Effort Is All You Need:
Testing LLM Applications In The Real World
- Donato Capitella & Thomas Cross
-
Infrastructure Doesn’t Lie: Using Infrastructure
Signals To Detect Shadow AI Built Applications
- Balachandra Shanabhag
-
Enforcing Application Security Policies At Scale:
Lessons From An Enterprise Rollout
- Mehran Koushkebaghi
-
Using OWASP SAMM And
OWASP DSOMM Together In Practice
- Aram Hovsepyan & Timo Pagel
-
AI-Generated Code Vs Human Code.
Who Really Writes More Vulnerabilities
- Eitan Worcel
-
The OG OWASP Top 10 Might Be
Back Thanks To Agentic Browsers
- Lidan Hazout and Bar Kaduri
-
What Our Pen Tests Never Found
And How Attackers Did
- Ramya M
-
Mythos Or Myth: The Reality Of
AI Vulnerability Discovery
- Vandana Verma Sehgal,Dan Jones,Steve Springett and Frederik Braun & Jaya Baloo
-
Security Champions:
Lessons From Opposite Trenches
- Lisi Hocke & Mireia Cano
-
OWASP Mobile Application Security (MAS)
Project Updates
- Carlos Holguera & Sven Schleier
-
Cloud Native Web Application Firewalls:
How OWASP Coraza Is Coming To Kubernetes World
- Jose Carlos Chávez and Ricardo Katz
-
Teaching AI Agents Like Guide Dogs:
A Progressive Trust Framework
- Bodhisattva Das
-
How To (Not) Isolate Untrusted
Code In Scripting Languages
- Cristian-Alexandru Staicu
-
Trust No History: Why Every "Remembered"
Interaction Is A Potential Backdoor
- Rico Komenda & Barno Kaharova
-
Marketplace Takeover: One Bug Away From
Pwning 10 Million Developer Machines
- Oran Simhony & Gal Hachamov
-
Using CTFs As A Community Of Practice Content Machine
- Marco Macala and Florian Schier & Christian Buchinger
-
Updates On The
OWASP Automated Threats Project
- Tin Zaw
-
OWASP Nettacker Project
- Sam Stepanyan & Arkadii Yakovets
-
Why IAM Remains A Challenge
And What We Can Do About It
- Dimitrij Drus
-
The TPM And You: How (And Why)
To Actually Make Use Of Your TPM
- Mathias Tausig
-
From Safety To Policy: Enforcing
Organizational Rules In LLMs And AI Agents
- Omer Hofman & Oren Rachmil
-
Insecurity As Code: How Modern
Software Scaled The Attack Surface
- Igor Stepansky
-
Closing Remarks And Raffle
- OWASP Board