All Deep Dives For Infosec Conference Talks Covering Offensive Security. Talks analyzed in full.
Learn how two offensive security consultants built a production-ready AWS organization from zero — covering OU design, SCPs, IAM, CI/CD, and monitoring on a lean budget.
Learn how NVIDIAs Project Marinade uses LLM coding agents to inject realistic, tunable vulnerabilities into real codebases - giving you ground-truth benchmarks to evaluate your security tools.
Discover how Entra ID service principal hijacking chains credential backdooring, federated domain abuse, and SAML token forgery into a full Global Admin escalation.
Learn how prompt formatting attacks bypass AWS Bedrock Guardrails PII filters without injection — and how system prompt engineering fights back.
Discover how 37 AI-assisted IDE vulnerabilities across 15+ vendors enable zero-click RCE, prompt injection chains, and silent config poisoning — and how to test your tools.
Learn how attackers exploit Amazon Bedrock agent prompt templates to leak schemas, bypass input validation, and persist malicious instructions across sessions.
Discover how LLMs now autonomously find and exploit zero-day vulnerabilities in the Linux kernel and Ghost CMS — and what the AI capability curve means for defenders right now.
Learn how AI cut a 6-week chip glitching failure to 7 minutes. Discover how LLMs guide EM fault injection and design hardware hacking platforms on a $7 Pico.
Discover how Trend Micro's FENRIR engine chains SAST tools, fast LLM triage, and agentic sandboxes to find 60+ CVEs at $8.80 per true positive.
Learn how attackers embed prompt injections in passport images to hijack AI KYC agents and exfiltrate customer PII at scale.
Learn how AI agents detect authentication bypasses, MFA bypasses, and authorization bugs using validator reuse and auth transmogrification.
Learn a proven 7-phase AI red teaming methodology, prompt injection taxonomy, and real enterprise case studies for assessing LLM systems.
Learn to threat-model AI agents for indirect prompt injection: enumerate tools, map AI-specific attack vectors, and automate dynamic testing with TamperMonkey.
Learn how to build specialized AI security bots and apply generative AI across red team, blue team, and purple team workflows using a proven prompt engineering methodology.
Learn to exploit OWASP ML Top 10 risks hands-on — supply chain attacks, data poisoning, and output integrity bypasses against a real AWS SageMaker infrastructure.
Learn to find WebRTC security vulnerabilities — TURN relay abuse, RTP injection, and signaling DoS — that most web and API pentesters miss entirely.
Learn how GraphQL ID and String scalars enable path traversal-based secondary context attacks in BFF architectures. Two real-world critical exploits and defensive strategies.