Loading…
This event has ended. Visit the official site or create your own event on Sched.
It is an annual, community-driven information security conference held in Prague. The event provides a platform for cybersecurity professionals, enthusiasts, and researchers to share knowledge, exchange ideas, and discuss the latest trends in the field. It’s a unique opportunity to connect with like-minded individuals, expand professional networks, and stay informed about the ever-evolving cybersecurity landscape.
More info at www.bsidesprg.cz

arrow_back View All Dates
Friday, April 24
 

08:00 CEST

OPEN DOORS
Friday April 24, 2026 08:00 - 08:45 CEST

Friday April 24, 2026 08:00 - 08:45 CEST
All

08:40 CEST

Opening Day 2

Friday April 24, 2026 08:40 - 09:00 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

09:00 CEST

KEYNOTE

Speakers
avatar for Dmitrijs Trizna

Dmitrijs Trizna

Aisle
15 years of experience in cyber-security (both red & blue teaming). Defended critical energy sector SCADAs, protected Azure backend, created and evaded SIEMs, catched APT campaigns, emulated them, built appsec AI framework finding 0-days.

Talked at BlackHat USA, DefCon AI Village, BlueHat, Nullcon, Troopers, many BSides. Certified: Stanford Online, OSCP, GIAC SANS (GREM, GDAT), etc. Strong scientific background: I have PhD, two (!) MSc degrees, and numerous peer-reviewed publications (ACM, IEEE, CAMLIS). Member of NATO cy... Read More →
Friday April 24, 2026 09:00 - 09:45 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

09:45 CEST

Coffee Break
Friday April 24, 2026 09:45 - 10:10 CEST
Take a well-deserved pause during our Coffee Break — a perfect moment to stretch your legs, grab a fresh cup of coffee or a quick snack, and recharge before the next round of talks. Use this time to move to your selected session, explore partner booths, or catch up with familiar faces you haven’t seen since the last event. Whether you’re continuing a deep technical debate or just enjoying a casual hallway conversation, this break is all about connecting, refueling, and getting ready for what’s next at BSides Prague 2026.
Friday April 24, 2026 09:45 - 10:10 CEST
All

10:10 CEST

Breaching The Perimeter: The Forgotten Attack Vector That Always Works
Physical security failures still open the door to serious breaches. We show how attackers gain access, exploit trust, and bypass controls using real-world scenarios, including a live server-room door assessment, and provide concrete steps to harden facilities, meet regulations, and reduce risk.
Speakers
avatar for Jiří Vaněk

Jiří Vaněk

Co-founder, Red Teamers
Jiří Vanek is an security consultant with over 20 years of experience encompassing IT, Management, and Ethical Hacking. He has led Red Team engagements, relishes in physical intrusions, and has first-hand experiences of successful intrusions and successful detections for clients... Read More →
avatar for Chris Cowling

Chris Cowling

Red Teamers


Friday April 24, 2026 10:10 - 10:55 CEST
Lucerna Cinema - AUX Vodičkova 704 /36/110 00, 110 00 Nové Město

10:10 CEST

The Agents of Chaos: AI Driven Malware Generation
AI agents are catching wind in offensive security, now it's the time to focus on malware. An agent that is incharge of the malware creation process directly.
From the spark of the idea, comparing different models, prompts, and results, to the challenges we faced, improvements, and actual testing.
Speakers
avatar for Arad Donenfeld

Arad Donenfeld

Attacks and Exploits Developer, SafeBreach
Arad Donenfeld is an attacks and exploits developer in SafeBreach, and has a background in security research from several roles (including Deep Instinct, where this research was conducted). With his strong foundations of development, security, and operating systems internals, Arad... Read More →
Friday April 24, 2026 10:10 - 10:55 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

11:00 CEST

Abusing the Ordinary: New COM-Based Windows Attack Vectors
This talk explores Windows COM infrastructure from an offensive perspective, presenting COM hunting methodologies and several previously undocumented attack techniques that enable stealthy code execution and sensitive data access through legitimate system components.
Speakers
avatar for Marco Balzarin

Marco Balzarin

SentinelOne
I'm a Security Engineer specializing in offensive security research within Windows environment. Over the years, I have worked extensively in red teaming, penetration testing, reverse engineering, and malware analysis and development. During this time, I have supported organizations... Read More →
Friday April 24, 2026 11:00 - 11:45 CEST
Lucerna Cinema - AUX Vodičkova 704 /36/110 00, 110 00 Nové Město

11:00 CEST

Forked and Owned: Taking Over GitHub Repositories via a single Pull Request
GitHub Actions is broken. Attackers can now enjoy an RCE-as-a-service vector that can lead to significant downstream effects. In this talk, you will learn how I managed to compromise the repositories of Google, Microsoft and other Fortune-100 companies, simply by creating a pull request from a fork.
Speakers
avatar for Ari Marzuk

Ari Marzuk

Senior Security Researcher, Microsoft
Ari Marzuk (also known as MaccariTA) is a Senior AI Security Researcher at Microsoft with nearly a decade of cybersecurity experience. He previously worked for Salesforce, NSO Group and the Israeli Military Intelligence. In 2025, Ari published "IDEsaster" revealing 25 new CVEs in... Read More →
avatar for Roi Nisimi

Roi Nisimi

Orca Security
Roi Nisimi is a Principal Security Researcher at Orca Security with over a decade of experience in vulnerability research and offensive cybersecurity. He honed his skills during six years of service in the Intelligence Corps of the IDF, where he achieved the rank of Lieutenant before... Read More →
Friday April 24, 2026 11:00 - 11:45 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

11:50 CEST

Hackerdy
Speakers
avatar for Danny Henderson Jr.

Danny Henderson Jr.

Associate Director, Threat Hunting & Response, Novartis Pharmaceutical
Danny Henderson has over 11 years in the IT field from his time in the U.S. Public Sector to life in the Private Sector. He holds a master's degree in Cyber and Information Security from Capitol Technology University and certifications such as GCIH, GCFA, and CISSP. Danny currently... Read More →
Friday April 24, 2026 11:50 - 12:35 CEST
Lucerna Cinema - Lounge Vodičkova 704 /36/110 00, 110 00 Nové Město

11:50 CEST

1 Click, 0 Warnings: Hijacking Mic, Camera & GPS via Browser UI Blindspots
Browsers lie. Permission prompts show your trusted domain while hidden iframes hijack camera, mic, or GPS. This systemic flaw enables surveillance at scale. I’ll demo real exploits, dissect failed defenses, and reveal why even Fortune 500 portals remain vulnerable.
Speakers
avatar for Armaan Pathan

Armaan Pathan

Katim LLC
Armaan Pathan is a Senior Security Engineer at KATIM with deep expertise in application security, penetration testing, and bug bounty hunting. Over the past 10+ years, he has uncovered and responsibly disclosed critical vulnerabilities at leading tech organizations including Google... Read More →
Friday April 24, 2026 11:50 - 12:35 CEST
Lucerna Cinema - AUX Vodičkova 704 /36/110 00, 110 00 Nové Město

11:50 CEST

Mad data science for practical C2 detection - the talk
Are you understaffed and never have enough time for threat hunting? Do you have a C2 beaconing problem on your network? You wish your middle name was automation or machine learning? Well, look no further! This talk can fit so much data science for C2 detection! *slaps roof of PowerPoint slide deck*
Speakers
avatar for Eva Szilagyi

Eva Szilagyi

Consultant, Alzette Information Security


avatar for David Szili

David Szili

Principal consultant, Alzette Information Security
David Szili is a principal consultant at Alzette Information Security, an information security consulting company based in Europe. He has more than ten years of professional experience in various areas like penetration testing, red teaming, security monitoring, security architecture... Read More →
Friday April 24, 2026 11:50 - 12:35 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

12:35 CEST

Lunch Break
Friday April 24, 2026 12:35 - 13:35 CEST
Enjoy the Lunch Break as an opportunity to step out, recharge, and grab something good to eat at one of the many nearby restaurants and cafés. Please note that lunch is not provided by the conference, so we encourage you to explore the local options around the venue. You can find a curated list of recommended restaurants in your attendee booklet, making it easy to choose a spot that fits your taste and schedule. Use this time not only to refuel, but also to continue conversations with fellow attendees before the afternoon sessions begin.
Friday April 24, 2026 12:35 - 13:35 CEST
All

13:35 CEST

Beyond classic detections: unlocking the full potential of EDR telemetry
Your EDR collects far more data than its built-in rules use. We'll show how to turn raw telemetry into custom detections for AD attacks like DCSync, lateral movement, and recon that default rules miss. We'll even explore if AI can help build new rules. The methodology applies to any modern EDR.
Speakers
avatar for Dylan Guerville

Dylan Guerville

Red Team Tech Lead, Intrinsec
Friday April 24, 2026 13:35 - 14:20 CEST
Lucerna Cinema - AUX Vodičkova 704 /36/110 00, 110 00 Nové Město

13:35 CEST

Painless IOS App Pentesting
IOS security is getting tighter, and many mobile pentesters feel locked out as there is no jailbreak for the latest versions. Entitlements are stricter than ever and traditional dynamic analysis has become much harder. However, modern iOS pentesting isn't dead - it just requires a smarter approach.
Speakers
avatar for Khayal Farzaliyev

Khayal Farzaliyev

Founder, Shaman Red Team
I’m an Application Security Engineer with over three years of practical experience across web and mobile penetration testing, secure software design, and vulnerability research - along with several CVE discoveries. I’m currently pursuing a PhD focused on Intrusion Prevention Systems... Read More →
Friday April 24, 2026 13:35 - 14:20 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

13:35 CEST

Play to Secure: Exploring AI Security Through Games
A hands-on session with the Elevation of Machine Learning Security (MLSEC) game.

AI security is a problem no one is qualified to tackle alone, yet AI is the technology revolution of our time.

Large Language Models, self driving cars, moon landers, online companions, and even your favourite custom cat emojis. All manner of enterprises benefit from AI. Meanwhile, even our traditional software is under increasing attack with household names held to ransom, hospital labs closed, and data leaks becoming an unwelcome fact of life. For those attempting to bring AI and Machine Learning into the enterprise, it is a minefield. Commands are mixed with data, biases are systematised and mistakes happen.

This is a hands–on workshop where you’ll play the Elevation of MLSEC game, a new threat modelling experience created by software engineer and security champion, Elias Brattli Sørensen, focused on AI and machine learning systems. Working in teams around a shared system architecture, you’ll explore realistic pitfalls across product, code, and QA, learning how and where security issues emerge in AI-enabled systems.

Key takeaways:
- Get to grips with the key threats that show up across the ML lifecycle
- Learn a hands-on, team-based way to threat model AI systems
- Pick up practical ideas for using games to boost engagement and build a secure-by-design culture
Speakers
DG

Devika Gibbs

Co-founder, CyberSecGames

Co-Founder of CyberSec Games, I help design and deliver serious games to raise awareness, build skills, and inspire better collaboration and conversations about cybersecurity risk.

avatar for Simon Gibbs

Simon Gibbs

CyberSecGames
An experienced software engineer and team leader with a variety of experience across content, ecommerce, systems integration and finance. Talk to me about how games can be the easy and reliable way to make complex processes like Thread Modeling actually happen.
Friday April 24, 2026 13:35 - 14:35 CEST
Lucerna Cinema - Lounge Vodičkova 704 /36/110 00, 110 00 Nové Město

14:25 CEST

Uncovering SAP BTP Attack Vectors, Before Someone Else Does!
Think SAP BTP is secure by design? Think again. In this red team–driven talk, we’ll break into BTP using misconfigurations, over-permissioned services, vulnerable Kyma flows, and Cloud Connector shortcuts. Real attack paths. No fluff. Just cloud-native chaos, with demos.
Speakers
avatar for Waseem Ajrab

Waseem Ajrab

Head of Security Advisory, NO MONKEY GmbH
Waseem Ajrab, a seasoned cybersecurity professional, leads cybersecurity initiatives at NO MONKEY, focusing on SAP environments globally. With expertise in SOC, network security, and penetration testing, he fortifies critical systems through strategic vision. Waseem is a key contributor... Read More →
Friday April 24, 2026 14:25 - 15:10 CEST
Lucerna Cinema - AUX Vodičkova 704 /36/110 00, 110 00 Nové Město

14:25 CEST

What an "Exploitable CVE" Really Means: Moving Beyond CVSS Scores
Most CVEs never become real risks. We explore what makes a vulnerability truly exploitable by examining the economics of offensive research, the limitations of scoring systems, and the conditions required for exploitation. Attendees will learn why exploitability is discretional and how to prioritize
Speakers
avatar for Eryx Paredes

Eryx Paredes

Staff Security Engineer, Lyft
Eryx is an enthusiast in Cybersecurity and OpenSource. Currently working as Staff Security Engineer at Lyft he leads the vulnerability management program, handling the strategy to identify and fix code, infrastructure and endpoint vulnerabilities at scale. His career includes roles... Read More →
Friday April 24, 2026 14:25 - 15:10 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

15:15 CEST

Decoding Chinese State-Sponsored Cyber Activity: Behavioral Models for Early Detection and Effective Threat Hunting
Key Takeaways: A structured approach to behavioral attribution for Chinese state-sponsored activity Case studies illustrating persistent behavioral patterns across varied campaigns Practical behavioral models that can be deployed by any security team to support threat hunting and early detection
Speakers
avatar for Nathaniel Jones

Nathaniel Jones

Darktrace
Drawing on his extensive background in both government and private sector cybersecurity, Nathaniel brings a global perspective to threat analysis and defense strategies. Prior to Darktrace, he spent 7 years at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), where... Read More →
Friday April 24, 2026 15:15 - 15:40 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

15:15 CEST

LLMs for Vulnerability Fixing: Hype or Reality?
Large Language Models seem ideal for fixing vulnerabilities, but how effective are they really? This talk explores how context, knowledge bases, and inference strategies impact LLM-based remediation, separating real progress from pure hype.
Speakers
avatar for Edouard Viot

Edouard Viot

CTO & Cofounder, Symbiotic Security
Edouard Viot is the co-founder and CTO of Symbiotic Security, an American-French startup specializing in AI-assisted code security. A passionate entrepreneur at the intersection of cybersecurity and innovation, he designs tools that help developers write more secure code through integrated... Read More →
Friday April 24, 2026 15:15 - 15:40 CEST
Lucerna Cinema - AUX Vodičkova 704 /36/110 00, 110 00 Nové Město

15:40 CEST

Coffee break
Friday April 24, 2026 15:40 - 16:05 CEST
Take a well-deserved pause during our Coffee Break — a perfect moment to stretch your legs, grab a fresh cup of coffee or a quick snack, and recharge before the next round of talks. Use this time to move to your selected session, explore partner booths, or catch up with familiar faces you haven’t seen since the last event. Whether you’re continuing a deep technical debate or just enjoying a casual hallway conversation, this break is all about connecting, refueling, and getting ready for what’s next at BSides Prague 2026.

Friday April 24, 2026 15:40 - 16:05 CEST
All

16:05 CEST

From Input to Impact: Prompt Injection in Production Pipelines
Prompt injection is no longer a chatbot trick, it allowed us to hack Google. As AI agents enter CI/CD and build systems, untrusted input becomes an execution vector. This talk reveals real-world pipeline exploits affecting Fortune 500 firms and explains why prompt injection is a very real threat.
Speakers
avatar for Mackenzie Jackson

Mackenzie Jackson

Developer advocate, GitGuardian
Mackenzie is a developer advocate with a passion for code security. As the co-founder and former CTO of the health tech startup Conpago, he learnt first-hand how critical it is to build secure applications with robust developer operations.
Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in our applications... Read More →
Friday April 24, 2026 16:05 - 16:30 CEST
Lucerna Cinema - AUX Vodičkova 704 /36/110 00, 110 00 Nové Město

16:05 CEST

Hackerdy
Speakers
avatar for Danny Henderson Jr.

Danny Henderson Jr.

Associate Director, Threat Hunting & Response, Novartis Pharmaceutical
Danny Henderson has over 11 years in the IT field from his time in the U.S. Public Sector to life in the Private Sector. He holds a master's degree in Cyber and Information Security from Capitol Technology University and certifications such as GCIH, GCFA, and CISSP. Danny currently... Read More →
Friday April 24, 2026 16:05 - 16:50 CEST
Lucerna Cinema - Lounge Vodičkova 704 /36/110 00, 110 00 Nové Město

16:05 CEST

LazarOps: APT Tactics Targeting the Developers Supply Chain
LazarOps is the name of an investigation done by Security Joes that uncovers how Lazarus built a network of fake GitHub accounts, malicious coding challenges, and cross-platform tooling to target developers and infiltrate software supply chains.
Speakers
avatar for Diogo Machado

Diogo Machado

Threat Researcher, Security Joes
Diogo Machado has been working in the cyber security field for the past 10 years. Staring in a public company in Portugal, he developed yearly the joy in malware analysis and reverse engineering. From then, he joined Siemens in which he practiced the investigation and response to... Read More →
Friday April 24, 2026 16:05 - 16:50 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

16:35 CEST

Call Me By Your [User]Name: Modern Identity-Centric Attacks
Forget malware. Attackers are logging in now. Discover the identity-centric attacks, accelerated by AI and used by threat actors like Scattered Spider to bypass MFA and turn trusted processes into their primary weapon. In a world of smart systems, vigilance starts with knowing who you’re talking to.
Speakers
avatar for Lucie Kadlecova

Lucie Kadlecova

CTI analyst & manager, PwC
Lucie works as a CTI analyst and manager in the PwC Global Threat Intelligence team. She was previously a Fulbright visiting scholar at the Massachusetts Institute of Technology (MIT) in Cambridge, USA, and worked at the Czech National Cyber Security Centre. She holds a PhD from Charles... Read More →
Friday April 24, 2026 16:35 - 17:00 CEST
Lucerna Cinema - AUX Vodičkova 704 /36/110 00, 110 00 Nové Město

16:55 CEST

RTFM - Read The Fatal Manual: When Documentation Creates Critical Misconfiguration
Misconfigurations persist in enterprises despite widespread awareness - with AD CS being the prime example. This talk explores how vendors guide users into deploying critical misconfigurations, a large-scale responsible disclosure journey, and the shared responsibilities between us all.
Speakers
avatar for Martin Sohn Christensen

Martin Sohn Christensen

SpecterOps
I am a Security Researcher at SpecterOps, specializing in Microsoft technologies with expertise in Active Directory, identity attack paths, and secure system configuration. I bring a well-rounded perspective on security risks and challenges stemming from a background in system administration... Read More →
Friday April 24, 2026 16:55 - 17:40 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

17:05 CEST

So You Want to Write a Book? Writing About AI Security For No Starch Press
Ever wondered what it’s like to write a technical book? I’ll share how I wrote an AI security book for No Starch Press—how it started, what made it so different from a PhD, the behind-the-scenes work, and the key lessons I learned for anyone tackling a big creative project.
Speakers
avatar for Harriet Farlow

Harriet Farlow

Mileva Security Labs
Harriet Farlow is the CEO of AI Security company Mileva Security Labs, a PhD Candidate in Machine Learning Security, and creative mind behind the YouTube channel HarrietHacks. She missed the boat on computer hacking so now she hacks AI and Machine Learning models instead. Her career... Read More →
Friday April 24, 2026 17:05 - 17:50 CEST
Lucerna Cinema - AUX Vodičkova 704 /36/110 00, 110 00 Nové Město

17:50 CEST

CLOSING BSIDES 2026
Martin Hron will officially close BSides Prague 2026 with a final wrap-up session marking the end of two days filled with knowledge sharing, technical deep dives, inspiring discussions, and new connections. This closing talk will thank all speakers, partners, volunteers, and attendees who made the event possible, briefly reflect on the highlights of the conference, and encourage the community to stay connected beyond the venue walls. The session will smoothly transition into the evening program, guiding attendees toward the afterparty and the informal afterparty talks that continue the spirit of BSides in a more relaxed setting — because while the conference may be ending, the conversations are just getting started.
Speakers
avatar for Martin Hron

Martin Hron

Staff Offensive Researcher, BSides Czech z.s. / SentinelOne

Friday April 24, 2026 17:50 - 18:15 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

18:30 CEST

Airport Security! - S01 E008 - Breaking into your baggage
When we travel with valuable luggage, we rely on the security of locks, especially those that are TSA-approved. But, are they really? In this talk, we’ll discuss how lock picking techniques, master keys, and bypass methods can compromise the security of TSA-approved locks.
Speakers
avatar for Héctor Cuevas Cruz

Héctor Cuevas Cruz

Senior Managing Security Consultant, Bishop Fox
Héctor is a Senior Managing Security Consultant at Bishop Fox with over 12 years of experience in offensive security, digital forensics, threat hunting, and incident response, and has presented on multiple occasions at international conferences such as DEFCON, Ekoparty, WWHF and... Read More →
Friday April 24, 2026 18:30 - 18:55 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

19:10 CEST

Last night a DJ erased my drive
Music and security have much in common. Both require a trigger that sets off a series of events. Music can cause destruction and has been used for torture as well for encryption to bypass censorship. Music is also fun and this talk will be an audio-visual journey through cybersecurity.
Speakers
avatar for Mathew Caplan

Mathew Caplan

Director of Professional Services, Orange Cyberdefense
Mathew Caplan is Director of Professional Services for Orange Cyberdefense, based in London, England. He is a highly experienced cybersecurity specialist with over 25 years in the field and a proven record in the implementation of information risk management processes. As a recognised... Read More →
Friday April 24, 2026 19:10 - 19:55 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město

20:10 CEST

The Great Train Robbery - Hacking Like It’s 1855
In his book “The Great Train Robbery” Michael Crichton details a train robbery in 1855 involving a prostitute and scaling buildings. Although these methods are not included in any letter of engagement, the most famous train robbery of its time has parallels to modern day physical security.
Speakers
avatar for Paul Zenker

Paul Zenker

KPMG
I am a security consultant for KPMG specialising in the fields of AI security and physical security. I have given talks on both topics across conferences in Europe and I am a co organiser of BSides Dresden.
Friday April 24, 2026 20:10 - 20:55 CEST
Lucerna Cinema - MAIN Vodičkova 704 /36/110 00, 110 00 Nové Město
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -