The Cyber Archive
Conference archive
O

Owasp

All Deep Dives From Owasp. Talks analyzed in full.

14 deep dives
15 speakers

Latest deep dives

The SCA Balancing Act
Owasp global appsec usa 2025

The SCA Balancing Act

Learn the three hidden costs of software composition analysis and how to match SCA tools to your AppSec program maturity.

Jamie Scott 29 March 2026
Attacking AI
Owasp global appsec usa 2025

Attacking AI

Learn a proven 7-phase AI red teaming methodology, prompt injection taxonomy, and real enterprise case studies for assessing LLM systems.

Jason Haddix 28 March 2026
Plugins Gone Rogue: Attacking Developer Environments
Owasp global appsec usa 2025

Plugins Gone Rogue: Attacking Developer Environments

Learn how malicious VS Code extensions bypass Microsoft's safeguards to steal credentials and execute code on developer machines — and the only defense that actually works.

Raphael Silva 26 March 2026
Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems
Owasp global appsec usa 2025

Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems

Learn to threat-model AI agents for indirect prompt injection: enumerate tools, map AI-specific attack vectors, and automate dynamic testing with TamperMonkey.

Will Vandevanter 25 March 2026
Keynote: Red, Blue, and Purple AI
Owasp global appsec usa 2024

Keynote: Red, Blue, and Purple AI

Learn how to build specialized AI security bots and apply generative AI across red team, blue team, and purple team workflows using a proven prompt engineering methodology.

Jason Haddix 20 February 2026
AI Code Generation - Benefits, Risks and Mitigation Controls
Owasp global appsec usa 2024

AI Code Generation - Benefits, Risks and Mitigation Controls

Learn to assess AI code generation security risks—from package hallucination to IP liability—and apply governance controls that protect your SDLC.

Aruneesh Salhotra 19 February 2026
Hidden Chains: Revealing High-Impact Bugs from Bounty Submissions
Owasp global appsec usa 2024

Hidden Chains: Revealing High-Impact Bugs from Bounty Submissions

Learn how Snapchat uncovered three chained, high-impact bug bounty findings—supply chain RCE, Android deep link abuse, and Jupyter XSS-to-RCE—and the program capabilities each forced them to build.

Vinay Prabhushankar Murali Vadakke Puthanveetil 18 February 2026
AI Goat: A Damn Vulnerable AI Infrastructure
Owasp global appsec usa 2024

AI Goat: A Damn Vulnerable AI Infrastructure

Learn to exploit OWASP ML Top 10 risks hands-on — supply chain attacks, data poisoning, and output integrity bypasses against a real AWS SageMaker infrastructure.

Ofir Yakobi Shir Sadon 17 February 2026
Threat Modeling in the Age of AI
Owasp global appsec usa 2024

Threat Modeling in the Age of AI

Learn how to apply structured threat modeling to AI/ML systems using the ML SecOps framework, three diagnostic questions, and OWASP AI Exchange controls.

Susanna Cox 16 February 2026
AI Under the Hood: Unmasking Hidden Threats
Owasp global appsec usa 2024

AI Under the Hood: Unmasking Hidden Threats

Learn how adversarial ML attacks silently bypass AI security controls and how to apply AI security threat modeling using Project Guardrail's tiered questionnaire framework.

Nitish Uplavikar 15 February 2026
Web Security Experts: Are You Overlooking WebRTC Vulnerabilities?
Owasp global appsec usa 2024

Web Security Experts: Are You Overlooking WebRTC Vulnerabilities?

Learn to find WebRTC security vulnerabilities — TURN relay abuse, RTP injection, and signaling DoS — that most web and API pentesters miss entirely.

Sandro Gauci 14 February 2026
Hackuracy: Boosting AST Accuracy Through Hacking
Owasp global appsec usa 2024

Hackuracy: Boosting AST Accuracy Through Hacking

Learn how a 10-month experiment quantified AST accuracy in application security testing — and why the best automated scanner scored just 36.9% F1.

Andres Roldan 13 February 2026
Sanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail
Owasp global appsec usa 2024

Sanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail

Learn why server-side HTML sanitization is structurally broken and how client-side tools like DOMPurify eliminate parser differential XSS bypasses.

Yaniv Nizry 12 February 2026
GraphQL Exploitation: Secondary Context Attacks and Business Logic
Owasp global appsec usa 2024

GraphQL Exploitation: Secondary Context Attacks and Business Logic

Learn how GraphQL ID and String scalars enable path traversal-based secondary context attacks in BFF architectures. Two real-world critical exploits and defensive strategies.

Willis Vandevanter 11 February 2026