• Most recent
  • Conferences
  • For organizers
  • The rig
  • Buy me a Mate
  • Search
  • Fundraiser
  • Bluesky
  • Vienna 2026
  • Lisbon
  • Dublin
  • Amsterdam
Edition logo

OWASP Global AppSec Vienna 2026

2026-06-23 - 2026-06-24
  • Video not yet published
    Opening Remarks
    - OWASP Board
  • Video not yet published
    The Reinvention Of Software Engineering
    - Hannah Foxwell
  • Video not yet published
    AI Explainability Score Card
    - Michael Novack
  • Video not yet published
    Builders & Breakers Part II: Securing Agentic AI After The Death Of LLM Wrappers
    - Javan Rasokat & Rico Komenda
  • Video not yet published
    Scanning Agentic AI Systems: Beyond Traditional LLM Red Teaming
    - Roman Vainshtein and Amit Giloni & Roy Betser
  • Video not yet published
    Why Isn't The Fix In My Container? Tracking CVE Propagation Across 10.000 Projects
    - Lior Kaplan & Mor Weinberger
  • Video not yet published
    Why AppSec Fails At Scale (And How To Fix It)
    - Eduard Thamm
  • Video not yet published
    Introduction By OWASP MAS Team To MAS Con
    - Carlos Holguera & Sven Schleier
  • Video not yet published
    OpenCRE.org: Uniting All Standards And Guidelines
    - Rob Van Der Veer
  • Video not yet published
    Let's Get Frooky: Structured Mobile DAST With Frida
    - Stefan Bernhardsgrütter & Carlos Holguera
  • Video not yet published
    OWASP AI Testing Guide In Practice: Securing LLM Applications
    - Matteo Meucci & Marco Morana
  • Video not yet published
    Authorization Is Where Your App Goes To Lie
    - Eden Yardeni
  • Video not yet published
    The OWASP Top Ten 2025
    - Tanya Janca & Torsten Gigler
  • Video not yet published
    Actionable Continuous SBOM Diffing
    - Pavel Shukhman
  • Video not yet published
    Admission Of Guilt: I Exploited A Parking System For A Year (And What It Taught Me About AppSec)
    - Dimitar Raichev
  • Video not yet published
    Unveiling The Internals From Multiplatform Mobile Runtimes
    - Sergi Alvarez
  • Video not yet published
    Introducing OWASP AGHAST: AI-Guided Hybrid Application Static Testing
    - Josh Grossman
  • Video not yet published
    The Map Of Artificial Treasures: What To Automate In Security - And Why?
    - Michael Helwig
  • Video not yet published
    Retiring CVE Chasing: Defending Against Application Exploit Techniques
    - Idan Elor
  • Video not yet published
    Personal Relevance In The Age Of AI
    - Avi Douglen,Grant Ongers,Marisa Fagan,Hannah Foxwell and Gadi Evron
  • Video not yet published
    One IDE To Rule Them All: Securing Your Supply Chain’s Weakest Link
    - Moshe Siman Tov Bustan & Nir Zadok
  • Video not yet published
    The Velocity Paradox: Why Slow Is Smooth And Smooth Is Fast In AppSec
    - Pramod Rana
  • Video not yet published
    Recent Mobile App Security Incidents From Real-World Cases
    - Jan Seredynski
  • Video not yet published
    OWASP DefectDojo
    - Matt Tesauro
  • Video not yet published
    Meet The New Frida Frontend On The Block
    - Ole André Vadla Ravnås
  • Video not yet published
    OWASP KubeFIM: Detecting File Integrity Threats With EBPF & AI In Kubernetes
    - Abhijit Chatterjee
  • Video not yet published
    Human Rights Threat Modeling
    - Giovanni Corti and Simone Onofri & Luca Lumini
  • Video not yet published
    This Build Can Break You Evil Runners And EBPF For Detection
    - Reinhard Kugler
  • Video not yet published
    From 0 To SLSA Level 3: A Level 3: A Practitioner's Field Guide
    - Mark Mishaev
  • Video not yet published
    Taming The AppSec Data Deluge
    - Ben Sleek
  • Video not yet published
    Attacking ART
    - Jeroen Beckers
  • Video not yet published
    Evil User Stories Modeling: Ensuring Your User Stories In Agile Playing OWASP Cornucopia
    - Grant Ongers & Max Alejandro Gomez Sanchez Vergaray
  • Video not yet published
    Closure Of Conference By OWASP MAS Team
    - Carlos Holguera & Sven Schleier
  • Video not yet published
    OWASP MCP Top 10: When AI Agents Go Rogue, Securing The Model Context Protocol
    - Vandana Verma Sehgal
  • Video not yet published
    AI And The Threat Modeling Manifesto: Conflicts, Failure Modes, And Better Patterns
    - Vikramaditya Narayan
  • Video not yet published
    The Devil Is In The Defaults: What To Do About XSS
    - Frederik Braun
  • Video not yet published
    Boiling The Ocean For Signal: Lessons From High-Volume OSS Malware Detection
    - Henrik Plate
  • Video not yet published
    Pragmatic Least-privilege For Cloud And Kubernetes: Applying Good Advice To Real Systems
    - Mark Vinkovits
  • Video not yet published
    Agile Development And IT Security: From Conflict To Collaboration
    - Juliane Reimann & Elisa Erbe
  • Video not yet published
    OWASP AI Exchange Showcase
    - Rob Van Der Veer and Aruneesh Salhotra & Behnaz Karimi
  • Video not yet published
    Opening Remarks
    - OWASP Board
  • Video not yet published
    We Live In The Future: The Death And Rebirth Of Application Security
    - Gadi Evron
  • Video not yet published
    From ASVS To APVS: What Changes When You Treat Privacy As A System Property?
    - Matthew Coles and Kim Wuyts & Avi Douglen
  • Video not yet published
    DOMination: Abusing The Permission Model In Web Extensions
    - Moshe Siman Tov Bustan & Nir Zadok
  • Video not yet published
    OWASP AI Security Verification Standard (AISVS)
    - Jim Manico,Rico Komenda,Otto Sulin and Russ Memisyazici & Raza Sharif
  • Video not yet published
    Illegal States Are My Favorite Security Vulnerability
    - Michael Koppman
  • Video not yet published
    Keep It Between Us: Manipulating Humans For Better AppSec (Ethically)
    - Nariman Aga-Tagiyev
  • Video not yet published
    When Museums Get Hacked: OWASP Top 10 Lessons From Heists
    - Jose Carlos Chávez
  • Video not yet published
    From Maturity To Mastery: Accelerating Software Security With OWASP SAMM
    - Sebastien Deelersnyder & Aram Hovsepyan
  • Video not yet published
    Phishing For Passkeys: An Analysis Of WebAuthn And CTAP
    - Michael Kuckuk
  • Video not yet published
    Q-Day Is Cancelled: Practical Strategies To Defeat 'Harvest Now, Decrypt Later'
    - Anshu Gupta
  • Video not yet published
    Effort Is All You Need: Testing LLM Applications In The Real World
    - Donato Capitella & Thomas Cross
  • Video not yet published
    Infrastructure Doesn’t Lie: Using Infrastructure Signals To Detect Shadow AI Built Applications
    - Balachandra Shanabhag
  • Video not yet published
    Enforcing Application Security Policies At Scale: Lessons From An Enterprise Rollout
    - Mehran Koushkebaghi
  • Video not yet published
    Using OWASP SAMM And OWASP DSOMM Together In Practice
    - Aram Hovsepyan & Timo Pagel
  • Video not yet published
    AI-Generated Code Vs Human Code. Who Really Writes More Vulnerabilities
    - Eitan Worcel
  • Video not yet published
    The OG OWASP Top 10 Might Be Back Thanks To Agentic Browsers
    - Lidan Hazout and Bar Kaduri
  • Video not yet published
    What Our Pen Tests Never Found And How Attackers Did
    - Ramya M
  • Video not yet published
    Mythos Or Myth: The Reality Of AI Vulnerability Discovery
    - Vandana Verma Sehgal,Dan Jones,Steve Springett and Frederik Braun & Jaya Baloo
  • Video not yet published
    Security Champions: Lessons From Opposite Trenches
    - Lisi Hocke & Mireia Cano
  • Video not yet published
    OWASP Mobile Application Security (MAS) Project Updates
    - Carlos Holguera & Sven Schleier
  • Video not yet published
    Cloud Native Web Application Firewalls: How OWASP Coraza Is Coming To Kubernetes World
    - Jose Carlos Chávez and Ricardo Katz
  • Video not yet published
    Teaching AI Agents Like Guide Dogs: A Progressive Trust Framework
    - Bodhisattva Das
  • Video not yet published
    How To (Not) Isolate Untrusted Code In Scripting Languages
    - Cristian-Alexandru Staicu
  • Video not yet published
    Trust No History: Why Every "Remembered" Interaction Is A Potential Backdoor
    - Rico Komenda & Barno Kaharova
  • Video not yet published
    Marketplace Takeover: One Bug Away From Pwning 10 Million Developer Machines
    - Oran Simhony & Gal Hachamov
  • Video not yet published
    Using CTFs As A Community Of Practice Content Machine
    - Marco Macala and Florian Schier & Christian Buchinger
  • Video not yet published
    Updates On The OWASP Automated Threats Project
    - Tin Zaw
  • Video not yet published
    OWASP Nettacker Project
    - Sam Stepanyan & Arkadii Yakovets
  • Video not yet published
    Why IAM Remains A Challenge And What We Can Do About It
    - Dimitrij Drus
  • Video not yet published
    The TPM And You: How (And Why) To Actually Make Use Of Your TPM
    - Mathias Tausig
  • Video not yet published
    From Safety To Policy: Enforcing Organizational Rules In LLMs And AI Agents
    - Omer Hofman & Oren Rachmil
  • Video not yet published
    Insecurity As Code: How Modern Software Scaled The Attack Surface
    - Igor Stepansky
  • Video not yet published
    Closing Remarks And Raffle
    - OWASP Board