Loading…
OWASP 25th Anniversary Virtual Conference (September)
Tuesday, September 22
 

9:00am PDT

Opening Remarks and Keynote
Tuesday September 22, 2026 9:00am - 9:50am PDT

Tuesday September 22, 2026 9:00am - 9:50am PDT
  Keynote
  • Audience All
  • about <br>

9:50am PDT

Chapter Highlight
Tuesday September 22, 2026 9:50am - 9:55am PDT

Tuesday September 22, 2026 9:50am - 9:55am PDT
  OWASP Chapter Highlight
  • Audience All
  • about <br>

10:00am PDT

From Silos to Alliances: Cryptographic Threat Hunting in OT Environments
Tuesday September 22, 2026 10:00am - 10:55am PDT
Operational Technology (OT) environments face a critical paradox: sophisticated attacks like TRITON, CRASHOVERRIDE, and INCONTROLLER routinely target multiple facilities, yet operators remain blind to cross-site attack patterns due to strict privacy regulations, competitive secrecy, and an inherent lack of trust. The current "share after detection" model—where threat intelligence is exchanged...
See More →
Speakers
avatar for Ahmed Elmesiry

Ahmed Elmesiry

Principal Security Researcher, Fujitsu Research of Europe

Dr. Elmesiry is a principal security researcher at Fujitsu Research of Europe with a Ph.D. in information security and assurance. He has extensive experience in R&D, having held academic and industrial positions in various countries on six continents. He has worked on projects related... Read More →
Tuesday September 22, 2026 10:00am - 10:55am PDT

10:00am PDT

Closing the AI Visibility Gap: Why SBOM Alone is No Longer Enough
Tuesday September 22, 2026 10:00am - 10:55am PDT
The shift toward Software Bill of Materials (SBOM) and its extension, the Artificial Intelligence Bill of Materials (AIBOM), is a fundamental change in how we manage risk, security, and compliance in the modern digital world. As an organization, adopting both of these frameworks doesn't just check a box, it provides a crucial, non-negotiable layer of transparency that is essential for both...
See More →
Speakers
avatar for Anitha Dakamarri

Anitha Dakamarri

Lead Security Engineer, DFIN
I am Anitha Dakamarri, a seasoned IT professional with over 17 years of experience in the field of information security. My journey began with a Master of Computer Applications from Jawaharlal Technological University, which laid a strong foundation for my career. Over the years... Read More →
Tuesday September 22, 2026 10:00am - 10:55am PDT

11:00am PDT

Guardrails First: Building AI Agents That Won’t Leak Your Secrets
Tuesday September 22, 2026 11:00am - 11:55am PDT
As generative and agentic AI rapidly enters security workflows, practitioners face a difficult choice: leverage AI to enhance efficiency, or risk exposing sensitive data to systems that weren’t designed with security in mind. For me, as a security engineer and pentester, this challenge is especially important - pentesting often involve confidential data, proprietary code, and high-impact...
See More →
Speakers
avatar for Ihor Sasovets

Ihor Sasovets

Lead Security Engineer, TechMagic
I am a Lead Security Engineer at TechMagic with previous experience in test automation, security testing automation, a contributor of OWASP API Top 10 (2019), speaker at various community meetups. I have more than 4 years of experience with AWS.

I am passionate about cloud securit... Read More →
Tuesday September 22, 2026 11:00am - 11:55am PDT

11:00am PDT

OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement analysis
Tuesday September 22, 2026 11:00am - 11:55am PDT
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with design.Too often, the shift-left mantra consists of implementing (AI-powered) code scanning and applying AI-powered security fixes for remediation. Also, don't forget to implement the AI-powered benchmark for AI-powered Security Fixes. Now, to be clear, I am not actually telling you to stop using these...
See More →
Speakers
avatar for Johan Sydseter

Johan Sydseter

co-leader of OWASP Cornucopia, Johan (Uncle Joe) Sydseter - The guy with the long hair, not the beard
Johan Sydseter is one of the co-leaders of OWASP Cornucopia and the co-creator of the OWASP Cornucopia Mobile App Edition. he is a living AppSec Pokémon, application security engineer, developer, architect and DevOps practitioner. He has 15 years of experience building and designing... Read More →
Tuesday September 22, 2026 11:00am - 11:55am PDT

11:55am PDT

Chapter Highlight
Tuesday September 22, 2026 11:55am - 12:00pm PDT

Tuesday September 22, 2026 11:55am - 12:00pm PDT

12:00pm PDT

Lunch Break
Tuesday September 22, 2026 12:00pm - 1:00pm PDT

Tuesday September 22, 2026 12:00pm - 1:00pm PDT
  • about <br>

12:55pm PDT

Chapter Highlight
Tuesday September 22, 2026 12:55pm - 1:00pm PDT

Tuesday September 22, 2026 12:55pm - 1:00pm PDT
  OWASP Chapter Highlight
  • Audience All
  • about <br>

1:00pm PDT

How a Clean Security Audit Became a Breach Notification Six Months Later
Tuesday September 22, 2026 1:00pm - 1:55pm PDT
Pre-deployment security reviews cover what you configured. They do not cover what your environment looks like six months later after multiple teams have touched it, new services have been granted access, and permissions have accumulated in ways nobody explicitly decided. Most organizations treat a clean security review as a checkpoint rather than a snapshot, and that distinction matters a great...
See More →
Speakers
avatar for Advait Patel

Advait Patel

Senior Site Reliability Engineer, Broadcom

Advait Patel is a Senior Site Reliability Engineer at Broadcom and the creator of DockSec, an open-source, AI-powered Docker security analyzer. With over 8+ years of experience in cloud-native security, DevSecOps, and secure software supply chains, he is passionate about building... Read More →
Tuesday September 22, 2026 1:00pm - 1:55pm PDT

1:00pm PDT

Install Once, Exploit Forever: The MCP Plugin Supply Chain Attack Surface
Tuesday September 22, 2026 1:00pm - 1:55pm PDT
Every time we set up an MCP server, something felt off. Adding one is as simple as adding a JSON entry that points to a third-party process. Restart your client, and that server's outputs now flow directly into your agent's context — treated with the same trust as your own instructions. It can access whatever you've granted it — files, API tokens, tool outputs — with no verification that...
See More →
Speakers
avatar for Sheshananda Reddy Kandula

Sheshananda Reddy Kandula

Test, Test
With 16 years of experience in application security across web, mobile, and API ecosystems, I focus on finding real-world vulnerabilities and building practical defenses across the SDLC. I hold OSWE, OSCP, and CISSP certifications and have worked on large-scale security programs in... Read More →
Tuesday September 22, 2026 1:00pm - 1:55pm PDT

2:00pm PDT

Securing Distributed Systems with Privacy-Aware Governance and ML Controls
Tuesday September 22, 2026 2:00pm - 2:55pm PDT
Distributed systems increasingly face security and privacy risks as data flows across services without sufficient visibility or enforcement. Regulatory actions have highlighted how combining user data without informed consent can lead to exploitative outcomes, reinforcing the need for real-time, security-driven controls rather than retrospective audits. This session presents a privacy-aware...
See More →
Speakers
avatar for Projjal Kumar Ghosh

Projjal Kumar Ghosh

Software Engineer, National Institute of Technology, Calicut

Projjal Kumar Ghosh is a seasoned software engineer known for shaping large-scale, high-impact technical ecosystems across leading global technology organizations. With extensive experience in distributed systems, cloud computing, data governance and privacy-centric architecture... Read More →
Tuesday September 22, 2026 2:00pm - 2:55pm PDT

2:00pm PDT

Rethinking how we evaluate security agents for real-world use
Tuesday September 22, 2026 2:00pm - 2:55pm PDT
Security agents are gaining momentum across industry, but the way we evaluate them remains rooted in narrow, outcome-only benchmarks. These evaluations tell us whether an agent produced a correct answer, but not “how” it arrived there or whether that behavior will remain stable once deployed.In practice, enterprise security is not a sequence of isolated tasks. It is a connected, end-to-end...
See More →
Speakers
avatar for Mudita Khurana

Mudita Khurana

Staff Security Engineer, Airbnb
 Mudita Khurana is a Tech Lead at Airbnb, where she builds scalable security tooling and automation across the software development lifecycle. Previously at Meta, she drove key initiatives in product security, including bug bounty strategy, privacy-focused reviews, and automated... Read More →
Tuesday September 22, 2026 2:00pm - 2:55pm PDT
  Testing

3:00pm PDT

I Don't Trust AI Agents (And Neither Should You): Building Production-Ready Architectures
Tuesday September 22, 2026 3:00pm - 3:55pm PDT
Your AI agent works great in the demo. Then you deploy it and it hallucinates a refund policy that costs you $10K, or exposes customer data, or just loops endlessly burning tokens.This session explores how to build AI agents you can trust in production using Amazon Bedrock AgentCore and the Strands Agents SDK.We’ll walk through a layered approach to agent safety that spans guardrails at multiple...
See More →
Speakers
avatar for Morgan Willis

Morgan Willis

Principal Cloud Technologist, AWS

Morgan Willis is a cloud and software engineering specialist with over 15 years of experience in tech, and more than 8 years focused on helping developers adopt cloud technologies through technical education.

Their background spans application architecture, backend development, an... Read More →
Tuesday September 22, 2026 3:00pm - 3:55pm PDT

3:00pm PDT

AMMF: Attention-Driven Multi-Feature Fusion for Scalable Cross-Architecture Binary Vulnerability Det
Tuesday September 22, 2026 3:00pm - 3:55pm PDT
Detecting vulnerabilities in compiled binaries remains a major challenge for security teams, especially when software is reused across different architectures, compilers, and optimization settings. These variations significantly alter binary representations, making traditional detection techniques brittle and difficult to scale.This talk introduces AMMF (Attention-Driven Multi-Feature Fusion), a...
See More →
Speakers
avatar for Akshaya Jayaram

Akshaya Jayaram

Principal M&A Security Engineer, Salesforce
Akshaya Jayaram is a highly accomplished Principal M&A Security Engineer at Salesforce with over seven years of experience securing large-scale, high-impact technology acquisitions. Rapidly promoted through multiple roles, Akshaya has consistently demonstrated exceptional technical... Read More →
Tuesday September 22, 2026 3:00pm - 3:55pm PDT

4:00pm PDT

The Sentinel-Aura Architecture: Orchestrating Agentic AI for Autonomous Endpoint Remediation
Tuesday September 22, 2026 4:00pm - 4:55pm PDT
As infrastructure grows beyond human scale, traditional manual patching is no longer a viable security posture. This session introduces a research-driven framework for Autonomous Infrastructure Healing.Instead of treating security as a static checklist, we explore a model where the system functions as a self-correcting organism. By wrapping Microsoft Intune and Microsoft Entra with a custom...
See More →
Speakers
avatar for Harshavardhan Malla

Harshavardhan Malla

Information Systems Security Engineer, Arizona Department of Transportation
Information Systems Security Engineer | Arizona Department of Transportation (ADOT) | Cloud Security & Compliance Automation | 3× Co-Founder (Digitailor)Harshavardhan Malla is an Information Systems Security Engineer at the Arizona Department of Transportation (ADOT), supporting... Read More →
Tuesday September 22, 2026 4:00pm - 4:55pm PDT

4:00pm PDT

Self-Healing Security Test Automation for OWASP AppSec: Adaptive Defense Against Evolving Threats
Tuesday September 22, 2026 4:00pm - 4:55pm PDT
Self-healing security test automation introduces a resilient approach to application security testing, addressing one of the most critical challenges in modern AppSec programs: maintaining effective test coverage in rapidly evolving systems. As applications undergo continuous updates, traditional security test scripts frequently fail due to UI, API, or infrastructure changes, leading to gaps in...
See More →
Speakers
avatar for Saahith Guptha Vamasani

Saahith Guptha Vamasani

Amazon

Saahith Guptha Vamasani is an innovative Technical Lead (SDET 2) with over 9.5 years of experience designing and delivering intelligent, large-scale engineering platforms across cloud-native and distributed environments. Currently based in Seattle, he has established himself as a... Read More →
Tuesday September 22, 2026 4:00pm - 4:55pm PDT

4:55pm PDT

Closing Remarks
Tuesday September 22, 2026 4:55pm - 5:10pm PDT

Tuesday September 22, 2026 4:55pm - 5:10pm PDT
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.