The Cyber Archive
Security domain
O

Offensive Security

All Deep Dives For Infosec Conference Talks Covering Offensive Security. Talks analyzed in full.

17 deep dives
7 conferences

Latest deep dives

This Wasnt in the Job Description- Building a production-ready AWS environment from scratch
Fwd cloudsec north america 2025

This Wasnt in the Job Description- Building a production-ready AWS environment from scratch

Learn how two offensive security consultants built a production-ready AWS organization from zero — covering OU design, SCPs, IAM, CI/CD, and monitoring on a lean budget.

Nick Jones Mohit Gupta 23 April 2026
Tenderizing the Target | [un]prompted 2026
Unprompted 2026

Tenderizing the Target | [un]prompted 2026

Learn how NVIDIAs Project Marinade uses LLM coding agents to inject realistic, tunable vulnerabilities into real codebases - giving you ground-truth benchmarks to evaluate your security tools.

Aaron Grattafiori Skyler Bingham 22 April 2026
I SPy - Rethinking Entra ID research for new paths to Global Admin
Fwd cloudsec north america 2025

I SPy - Rethinking Entra ID research for new paths to Global Admin

Discover how Entra ID service principal hijacking chains credential backdooring, federated domain abuse, and SAML token forgery into a full Global Admin escalation.

Katie Knowles 20 April 2026
Bypassing AI Security Controls with Prompt Formatting
Fwd cloudsec north america 2025

Bypassing AI Security Controls with Prompt Formatting

Learn how prompt formatting attacks bypass AWS Bedrock Guardrails PII filters without injection — and how system prompt engineering fights back.

Nathan Kirk 16 April 2026
Vibe Check: Security Failures in AI-Assisted IDEs | [un]prompted 2026
Unprompted 2026

Vibe Check: Security Failures in AI-Assisted IDEs | [un]prompted 2026

Discover how 37 AI-assisted IDE vulnerabilities across 15+ vendors enable zero-click RCE, prompt injection chains, and silent config poisoning — and how to test your tools.

Piotr Ryciak 15 April 2026
Breaking AI Agents: Exploiting Managed Prompt Templates to Take Over Amazon Bedrock Agents
Fwd cloudsec north america 2025

Breaking AI Agents: Exploiting Managed Prompt Templates to Take Over Amazon Bedrock Agents

Learn how attackers exploit Amazon Bedrock agent prompt templates to leak schemas, bypass input validation, and persist malicious instructions across sessions.

Jay Chen Royce Lu 14 April 2026
Black-hat LLMs | [un]prompted 2026
Unprompted 2026

Black-hat LLMs | [un]prompted 2026

Discover how LLMs now autonomously find and exploit zero-day vulnerabilities in the Linux kernel and Ghost CMS — and what the AI capability curve means for defenders right now.

Nicholas Carlini 13 April 2026
AI go Beep Boop! | [un]prompted 2026
Unprompted 2026

AI go Beep Boop! | [un]prompted 2026

Learn how AI cut a 6-week chip glitching failure to 7 minutes. Discover how LLMs guide EM fault injection and design hardware hacking platforms on a $7 Pico.

Adam Laurie 31 March 2026
FENRIR: AI Hunting for AI Zero-Days at Scale | [un]prompted 2026
Unprompted 2026

FENRIR: AI Hunting for AI Zero-Days at Scale | [un]prompted 2026

Discover how Trend Micro's FENRIR engine chains SAST tools, fast LLM triage, and agentic sandboxes to find 60+ CVEs at $8.80 per true positive.

Peter Girnus Derek Chen 8 April 2026
When Passports Execute: Exploiting AI Driven KYC Pipelines | [un]prompted 2026
Unprompted 2026

When Passports Execute: Exploiting AI Driven KYC Pipelines | [un]prompted 2026

Learn how attackers embed prompt injections in passport images to hijack AI KYC agents and exfiltrate customer PII at scale.

Sean Park 7 April 2026
Agents Exploiting Auth-by-One Errors | [un]prompted 2026
Unprompted 2026

Agents Exploiting Auth-by-One Errors | [un]prompted 2026

Learn how AI agents detect authentication bypasses, MFA bypasses, and authorization bugs using validator reuse and auth transmogrification.

Brendan Dolan Gavitt Vincent Olesen 31 March 2026
Attacking AI
Owasp global appsec usa 2025

Attacking AI

Learn a proven 7-phase AI red teaming methodology, prompt injection taxonomy, and real enterprise case studies for assessing LLM systems.

Jason Haddix 28 March 2026
Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems
Owasp global appsec usa 2025

Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems

Learn to threat-model AI agents for indirect prompt injection: enumerate tools, map AI-specific attack vectors, and automate dynamic testing with TamperMonkey.

Will Vandevanter 25 March 2026
Keynote: Red, Blue, and Purple AI
Owasp global appsec usa 2024

Keynote: Red, Blue, and Purple AI

Learn how to build specialized AI security bots and apply generative AI across red team, blue team, and purple team workflows using a proven prompt engineering methodology.

Jason Haddix 20 February 2026
AI Goat: A Damn Vulnerable AI Infrastructure
Owasp global appsec usa 2024

AI Goat: A Damn Vulnerable AI Infrastructure

Learn to exploit OWASP ML Top 10 risks hands-on — supply chain attacks, data poisoning, and output integrity bypasses against a real AWS SageMaker infrastructure.

Ofir Yakobi Shir Sadon 17 February 2026
Web Security Experts: Are You Overlooking WebRTC Vulnerabilities?
Owasp global appsec usa 2024

Web Security Experts: Are You Overlooking WebRTC Vulnerabilities?

Learn to find WebRTC security vulnerabilities — TURN relay abuse, RTP injection, and signaling DoS — that most web and API pentesters miss entirely.

Sandro Gauci 14 February 2026
GraphQL Exploitation: Secondary Context Attacks and Business Logic
Owasp global appsec usa 2024

GraphQL Exploitation: Secondary Context Attacks and Business Logic

Learn how GraphQL ID and String scalars enable path traversal-based secondary context attacks in BFF architectures. Two real-world critical exploits and defensive strategies.

Willis Vandevanter 11 February 2026