appsec.fyi

Talks — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Talks: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 87 of 87 curated resources. Browse all 87 Talks resources →

The Evolving Landscape of Application Security Talks

The application security conference circuit is a dynamic and indispensable resource for practitioners. It’s where cutting-edge research meets practical application, and where the latest threats, techniques, and countermeasures are debated and demonstrated. For those of us who live and breathe AppSec, staying current requires more than just reading blogs; it demands engagement with the community, understanding the nuances of emerging attack vectors, and seeing how these are translated into actionable intelligence.

This guide focuses on preparing and delivering talks for an experienced application security audience. The expectation from this group is high: they’re looking for technical depth, novel findings, and practical takeaways that can be applied to their daily work. Generic overviews or marketing fluff will quickly fall flat. Instead, the focus must be on concrete examples, repeatable methodologies, and a clear understanding of the impact of the presented work.

The landscape of AppSec is constantly shifting, influenced heavily by the rapid advancements in artificial intelligence and its integration into development and security workflows. Conferences like Black Hat USA, DEF CON, and various OWASP events are primary venues for these discussions [1][2][3]. Understanding the current trends and the expectations of an advanced audience is the first step towards crafting a compelling presentation.

Problem Framing: Why This Matters to You

The core challenge for application security professionals is keeping pace with an accelerating threat landscape, compounded by the increasing complexity of modern software development. The introduction of AI into the development lifecycle, for instance, presents both opportunities and significant new attack surfaces. This isn't just theoretical; AI coding assistants are already being used to solve CTF challenges [4], and vulnerabilities are being discovered in AI coding agents themselves [5]. Understanding the implications of these developments is crucial for any AppSec practitioner aiming to remain effective.

Moreover, the very nature of software development is changing. Organizations are building applications with a complex tapestry of internal code, AI-generated components, and third-party libraries, often deployed across multi-cloud environments [6]. This complexity necessitates a deep understanding of supply chain security, the risks associated with AI-generated code, and the challenges of securing distributed systems. Talks that address these multifaceted issues resonate strongly with an experienced audience.

The increasing sophistication of attacks, sometimes aided by AI, means that traditional security measures may no longer suffice. For example, AI has been used to discover long-dormant vulnerabilities, like an RCE in Call of Duty 1 [7]. This highlights that even well-established software can harbor critical flaws, and that AI can be a powerful tool for both offense and defense in vulnerability discovery.

The practitioners attending these talks are likely facing similar challenges within their own organizations: pressure to maintain development velocity while ensuring security, managing complex technology stacks, and grappling with the implications of emerging technologies like AI. A talk that directly addresses these pain points, offering concrete solutions or novel insights, will capture their attention and earn their respect.

Core Mechanics: The Anatomy of a Strong AppSec Talk

A successful application security talk, especially for an experienced audience, is built on a foundation of technical rigor and clear, concise communication. It’s not about flashy slides or buzzwords, but about delivering substantive content that can be understood, evaluated, and applied.

Technical Depth and Reproducibility

Experienced AppSec professionals can quickly identify a lack of depth. Claims must be supported by evidence, and methodologies should be explained in enough detail that an attendee could, in theory, replicate the findings or techniques. This means going beyond high-level descriptions and diving into the specifics of how an attack works or how a defense is implemented. For instance, when discussing arbitrary file writes (AFW) and their escalation to Remote Code Execution (RCE), understanding the "three ingredients" – path control, content control, and a known-executed destination – is critical [8]. A talk that elaborates on these ingredients with real-world examples provides significant value.

Code snippets and payloads are invaluable. Whether it’s demonstrating a prompt injection technique, showcasing a specific exploitation chain, or illustrating a defensive configuration, providing the concrete code allows attendees to grasp the mechanics immediately. For example, demonstrating email spoofing might involve showing the crafting of an email with multiple From headers to bypass authentication [9].

When discussing vulnerabilities discovered through AI, detailing the process of instruction or the prompts used is more valuable than simply stating that AI found a bug. The research behind how AI can identify novel HTTP desync triggers, for example, provides a blueprint for others to follow [10].

Novelty and Impact

While foundational topics have their place, an experienced audience is particularly interested in what’s new. This could be a newly discovered vulnerability class, a novel exploitation technique, an innovative defense strategy, or a significant shift in an existing paradigm. The work presented at conferences like Black Hat and DEF CON often highlights this novelty. For instance, research on bypassing multi-factor authentication in AI agents or exploiting AI agent KBs showcases emerging threat vectors [9]. Similarly, research into new HTTP desync triggers represents genuine innovation in attack techniques [10].

Impact is paramount. A vulnerability that can be exploited to achieve RCE, steal credentials, or disrupt critical services carries more weight than a theoretical flaw with limited practical application. Quantifying impact, where possible, is essential. This could be in terms of the number of affected systems, the potential financial or operational damage, or the difficulty of detection. For instance, research demonstrating RCE in a widely used signing extension impacting millions of users highlights significant impact [11].

Clear Narrative and Structure

Even the most technical content needs a clear narrative to be digestible. A well-structured talk guides the audience through the problem, the methodology, the findings, and the implications. A common structure includes:

The OWASP LLM Top 10 is a good example of a structured framework for understanding common LLM vulnerabilities [12]. A talk that follows a similar logical progression, breaking down complex topics into understandable components, will be well-received.

Delivery and Engagement

While content is king, effective delivery is crucial. This includes speaking clearly, maintaining a good pace, and using visuals that enhance understanding rather than distract. Engaging with the audience through questions (during or after the talk) and fostering a sense of community is also important. The AMA (Ask Me Anything) format seen with Black Hat speakers is a prime example of direct engagement [5].

Notable Techniques and Attack Vectors

The landscape of AppSec is continually evolving, with AI playing an increasingly prominent role in both offensive and defensive strategies. Here are some key areas and techniques that are generating significant interest and discussion among practitioners:

AI-Assisted Vulnerability Discovery

AI models are demonstrating a remarkable ability to discover vulnerabilities, sometimes in unexpected places or after decades of obscurity. The discovery of a 20-year-old RCE in Call of Duty using AI is a prime example [7]. Furthermore, AI has been instrumental in discovering complex vulnerability chains, such as a pre-authentication RCE in WordPress core that involved multiple intricate steps [13]. This capability extends to automating CTF challenges, where LLMs can solve complex puzzles that previously required significant human effort [4]. Researchers are also developing autonomous systems, like the "HTTP Terminator," to invent and apply new attack techniques at scale [10].

Prompt Injection and LLM Exploitation

As LLMs become more integrated into applications, prompt injection attacks have emerged as a critical threat vector. These attacks involve manipulating the LLM's input to elicit unintended or malicious behavior. This can range from tricking chatbots into sending phishing emails to exfiltrating sensitive data or even bypassing multi-factor authentication [9]. The OWASP LLM Top 10 explicitly addresses categories like "Prompt Injection" and "Insecure Output Handling," underscoring the severity of these risks [12]. Researchers are exploring how to weaponize chatbots for malicious purposes, such as composing and sending phishing emails or abusing tool call capabilities [9].

Supply Chain Security and AI in Development

The increasing reliance on third-party components, AI-generated code, and complex development pipelines has elevated the importance of supply chain security. Vulnerabilities in package managers like RubyGems [13] or in the development tooling itself, such as compromised GitHub issues affecting AI coding agents [5], highlight the risks. The use of AI tools like GitHub Copilot and Google Gemini, while accelerating development, also introduces the potential for insecure code to enter the pipeline at an unprecedented speed [6]. Talks that address securing the software supply chain, analyzing AI-generated code for vulnerabilities, and mitigating risks in dependency management are highly relevant.

Arbitrary File Writes and RCE Escalation

The classic Arbitrary File Write (AFW) vulnerability, while often dismissed as "informative," can be a powerful stepping stone to Remote Code Execution (RCE). However, escalating AFW to RCE in modern, stripped-down environments like distroless containers presents unique challenges. Research presented at DEF CON Bug Bounty Village systematically cataloged and evaluated techniques for turning AFW into RCE, focusing on environments that lack traditional components like cron or SSH [8]. Understanding these techniques, especially those that work against containerized applications, is vital for practitioners dealing with modern infrastructure.

AI Agent Security and Access Control

The rise of autonomous AI agents introduces new paradigms for security. Securing these agents, understanding their interactions, and managing their access controls are becoming critical. Research is emerging on AI-native access control and the security implications of agent-to-agent interactions [14][15]. The potential for AI agents to be hijacked or to exhibit "excessive agency" leading to misuse of tools or data leakage is a significant concern, addressed in advanced training courses [16].

Exploiting Legacy Systems and Protocols

Despite rapid technological advancements, legacy systems and protocols continue to be targets. The discovery of a 20-year-old RCE in an older game demonstrates that past vulnerabilities can resurface [7]. Similarly, older protocols or insecure implementations in critical infrastructure, such as the eID signing extension impacting millions, can have widespread consequences [11]. Talks that delve into the security of legacy systems or specific industry protocols remain highly valuable.

Detection and Prevention Strategies

For every attack vector, there must be corresponding detection and prevention strategies. Experienced AppSec professionals are keen to learn about practical, implementable defenses that go beyond generic advice. The focus should be on actionable steps and proven methodologies.

Input Validation and Sanitization

This remains a cornerstone of application security. Whether dealing with traditional web vulnerabilities or new LLM-based attacks, robust input validation is key. For prompt injection, this involves not just sanitizing user input but also carefully structuring prompts to differentiate between instructions and data. Techniques for email spoofing, for instance, highlight flaws in email header validation that allow malicious actors to impersonate trusted senders [9].

Secure Coding Practices and Developer Education

Empowering developers with secure coding knowledge is crucial for building secure applications from the outset. This includes understanding common vulnerability patterns and how to prevent them. Shift-left security, where security is integrated early in the development lifecycle, is a continuous theme in AppSec discussions [6]. Talks that provide practical guidance on secure coding for various languages and frameworks, or that address the challenges of securing AI-generated code, are highly valued.

Runtime Protection and Monitoring

Beyond static analysis and secure coding, runtime protection and continuous monitoring are essential. This includes Web Application Firewalls (WAFs), Intrusion Detection/Prevention Systems (IDPS), and more sophisticated runtime security solutions. For AI agents, this means monitoring their behavior, tool usage, and interactions to detect anomalies or malicious activity. The principle of least privilege for AI agent tools and sandboxing are key defensive strategies [16].

Authentication and Authorization Robustness

Weaknesses in authentication and authorization remain a primary source of breaches. The discussion around bypassing MFA in AI agents and IVRs [9] highlights the need for robust, multi-layered authentication. Similarly, research into AI-native access control and the secure management of identities for AI agents is gaining prominence [14].

Threat Modeling for AI Systems

Traditional threat modeling needs to evolve to encompass AI-specific risks. This includes understanding the decision logic of LLMs, the tools they interact with, and the trust boundaries within agentic systems [16]. A talk that provides a framework or methodology for threat modeling AI applications would be of great interest to practitioners navigating this new landscape.

Secure Software Development Lifecycle (SDLC) Integration

Integrating security seamlessly into the SDLC is an ongoing challenge. This involves using security tools within CI/CD pipelines, performing regular vulnerability assessments, and fostering a culture of shared responsibility between development and security teams [6]. Discussions on how to achieve DevSecOps effectively, automate security testing, and measure AppSec program success are always relevant.

Tooling and Practical Application

For an experienced audience, the tools and practical implementation details are as important as the theoretical concepts. Discussions should not shy away from specific technologies, frameworks, and how they can be used for both offense and defense.

AI-Assisted Security Tools

The proliferation of AI in security is leading to new tools and enhancements for existing ones. This includes AI-powered vulnerability scanners, code analysis tools, and threat intelligence platforms. For instance, AI is being used to improve bug bounty hunting by automating reconnaissance and analysis [17]. Talks that showcase how to effectively use these tools, their limitations, and how to integrate them into existing workflows are highly valuable.

Development and Security Frameworks

Frameworks play a crucial role in both building secure applications and testing them. Discussions on OWASP projects, such as the LLM Top 10 or the GenAI Security Project, provide structured guidance for understanding and mitigating risks [12][18]. Tools like Burp Suite continue to be essential for web application penetration testing, and advancements in AI integration with such tools are noteworthy [19][13][20].

Containerization and Cloud-Native Security Tools

As applications increasingly run in containers and cloud-native environments, security tools must adapt. Talks that address securing Kubernetes clusters, building secure container images, and leveraging eBPF for security in cloud-native environments are relevant [21]. The research on escalating AFW to RCE in containerized environments highlights the need for specialized tools and techniques [8].

Automation and Orchestration

Automation is key to managing the complexity and scale of modern AppSec challenges. This extends from automated vulnerability scanning and remediation to the orchestration of AI agents for security tasks [16]. Tools and techniques that enable efficient automation of security testing, detection, and response are of high interest.

Research and Discovery Platforms

Platforms that facilitate vulnerability discovery and sharing, like HackerOne or bug bounty programs, are where much of the practical research happens [22]. Talks that share methodologies for using these platforms effectively, or that detail findings from such programs, are invaluable. The development of tools like the "HTTP Terminator" for autonomous security research exemplifies the cutting edge of this field [10].

Recent Developments and Emerging Trends

The AppSec landscape is in constant flux, driven by technological advancements and evolving threat actors. Staying abreast of the latest developments is crucial for maintaining effective defenses.

The Rise of Agentic AI and Autonomous Systems

The integration of autonomous AI agents into software development and security workflows is a significant trend. This includes AI coding agents [5], agents for reconnaissance and vulnerability discovery [10][22], and even agents for threat modeling [16]. Understanding the security implications of these autonomous systems, including prompt injection, excessive agency, and tool misuse, is a top priority [16]. The development of standards like the Model Context Protocol (MCP) for AI tool integration is also a key area of focus [16][23].

AI in Offensive Security

AI is not only a target but also a powerful tool for attackers. It's being used to discover novel vulnerabilities [7][13], automate exploit development, and even craft sophisticated social engineering campaigns [9]. The capability of AI to find complex vulnerability chains previously beyond human reach is a game-changer [13]. This necessitates a proactive approach to understanding and defending against AI-powered attacks.

Generative AI Security (GenAI Security)

The rapid adoption of generative AI tools introduces a host of new security concerns. This includes risks associated with the data used to train these models, the potential for malicious prompts, and the security of AI-generated code itself [6][24][25]. Dedicated tracks and sessions at major conferences are now focusing on GenAI security, covering topics like prompt security, model vulnerabilities, and secure AI adoption strategies [18][26].

Enhanced Supply Chain Attacks

As software becomes more interconnected, supply chain attacks are becoming more sophisticated. This includes vulnerabilities in package managers [13], CI/CD pipelines, and even AI model development itself. The use of AI to discover complex exploit chains also increases the risk of supply chain compromises [13]. Discussions on securing the end-to-end software supply chain, from development to deployment, are critical.

Cloud-Native Security Challenges

The continued migration to cloud-native environments, including Kubernetes and serverless architectures, presents unique security challenges. Talks often cover topics like securing container images, managing access controls in dynamic cloud environments, and mitigating risks associated with managed cloud services [21][14]. The effective use of tools like eBPF for security in these environments is also a growing area of interest [21].

The Evolving Role of Human Expertise

While AI is a powerful force, human expertise remains indispensable. The best AppSec talks often highlight the synergy between AI capabilities and human insight, particularly in areas requiring nuanced understanding, ethical judgment, and creative problem-solving [27][10]. The distinction between CTFs and real-world pentesting, where context and business impact are paramount, underscores the continued value of experienced practitioners [4].

Where to Go Deeper

For practitioners looking to expand their knowledge and skills in application security, a variety of resources and communities are available. Engaging with these can provide the foundational understanding and advanced insights necessary to excel in this rapidly evolving field.

Conferences and Training

Major security conferences are prime venues for deep dives into AppSec topics. Black Hat USA and DEF CON consistently feature cutting-edge research, with tracks dedicated to application security and emerging threats like AI exploitation [1][2][28][3][29]. OWASP’s Global AppSec conferences, held in both the US and Europe, offer practitioner-focused content across various tracks, including dedicated sessions on AI security and secure development [30][31][32][33][26]. Smaller, community-driven events like BSides also offer valuable content and networking opportunities [34].

Specialized training is also abundant. For example, DEF CON offers hands-on masterclasses in AI Agent Security [16] and Mobile App Hacking [35]. Numerous online platforms and training providers offer courses on AI security, secure coding, and various aspects of offensive and defensive security [17][24][25].

Community and Open Source Projects

The OWASP community remains a central pillar of application security education and advocacy. Resources like the OWASP Top 10, LLM Top 10, and various project documentation provide invaluable guidance [12][36][37]. Open-source projects, such as Nettacker for automated penetration testing [38] or various tools showcased at Black Hat’s Arsenal [39], are essential for practical skill development.

Online communities and platforms like YouTube host recordings of conference talks, tutorials, and workshops, offering a vast repository of knowledge. Channels like NahamSec [40], Critical Thinking Podcast [41], and official conference channels [42][43] are excellent starting points.

Reading and Research

Blogs from security companies and individual researchers often provide detailed write-ups of new vulnerabilities and techniques. Websites like intigriti.com [9], includesecurity.com [4][27], portswigger.net [10], and tldrsec.com [13] are excellent sources for in-depth analysis. Academic research presented at symposia like the IEEE Symposium on Security and Privacy also pushes the boundaries of the field [44].

Resources that collate research, such as the Cybersecurity Slides Collection on GitHub [45], offer a concentrated view of topics covered at various events. Staying updated with the latest discussions on platforms like Reddit (e.g., PWN on Reddit) can also provide timely insights [5].

Sources cited in this guide

  1. What to Expect from BSides, Black Hat, and DEF CON 2025 — theregister.com
  2. Black Hat USA 2025 Briefings Schedule — blackhat.com
  3. RSA Conference 2026 — rsaconference.com
  4. CTFs in the AI Era — blog.includesecurity.com
  5. AMA with Black Hat Speakers Lidor B. & Elad Meged (Pre-Auth RCE in Enterprise Java, Hijacking AI Coding Agents) — pwnhackers.substack.com
  6. Securing next-gen development: Lessons from Trust Bank and TASConnect — snyk.io
  7. Pwning Call of Duty 1: a 20-year-old RCE, found in an evening with AI — zolder.io
  8. Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village) — ethiack.com
  9. Hacking AI customer service agents — intigriti.com
  10. Can AI do novel security research? Meet the HTTP Terminator — portswigger.net
  11. DEF CON talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE — amibeingpwned.com
  12. Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category — hego.red
  13. [tl;dr sec] #341 - Hugging Face Incident Black Hat Talk, CSS Bomb in your Inbox, GitHub Supply Chain Security Improvements — tldrsec.com
  14. Top security talks from KubeCon Europe 2025 — wiz.io
  15. 5 Takeaways from Black Hat x DEF CON 2025 — cybersecuritypulse.net
  16. AI Agent Security Masterclass: Attacking and Defending Autonomous AI Systems - DEF CON Training — training.defcon.org
  17. AI Mastery for Cybersecurity Professionals — offers.coderedpro.com
  18. OWASP Global AppSec EU 2025 - GenAI Focus — genai.owasp.org
  19. Testing Handbook - Burp — docs.google.com
  20. #burp #pentest #ai #hackerassociate #cybersecurity #infosec… | Harshad Shah — linkedin.com
  21. Top security talks from KubeCon Europe 2024 — wiz.io
  22. XBOW at Black Hat & DEF CON: AI Agents for Offensive Security — xbow.com
  23. DevSecCon Global May — devseccon.com
  24. GitHub - schwartz1375/genai-security-training — github.com
  25. GitHub - schwartz1375/genai-essentials — github.com
  26. The Elephant in AppSec Conference — theelephantinappsec.com
  27. Web App Pentesting in the AI Era — blog.includesecurity.com
  28. DEF CON 33 Talks - YouTube Playlist — youtube.com
  29. Cybersecurity Conferences 2026-2027 — infosec-conferences.com
  30. OWASP Global AppSec USA 2025 - CFP — sessionize.com
  31. OWASP Global AppSec EU 2025 (Barcelona) — owasp.glueup.com
  32. OWASP Global AppSec USA 2025 (Washington DC) — genai.owasp.org
  33. OWASP Global & Regional Events — owasp.org
  34. BSidesSLC 2026 — sessionize.com
  35. Hacking Android and IOT Apps by Example - DEF CON Training LV 2026 — training.defcon.org
  36. OWASP Videos — videos.owasp.org
  37. OWASP Videos — videos.owasp.org
  38. Introducing the OWASP Nettacker Project - Speaker Deck — speakerdeck.com
  39. Black Hat Briefings - Wikipedia — en.wikipedia.org
  40. (96) NahamSec - YouTube — youtube.com
  41. [HackerNotes Ep.95 & Ep.96] Cookies, Caching & Attacking Chrome Extensions with MatanBer — blog.criticalthinkingpodcast.io
  42. Black Hat Official YouTube Channel — youtube.com
  43. DEFCON Conference — Official YouTube — youtube.com
  44. IEEE Symposium on Security and Privacy 2026 — sp2026.ieee-security.org
  45. Cybersecurity Slides Collection — github.com
📚 This guide is synthesized from the full text of resources curated in the Talks library, and refreshed as new material is added.