The Cyber Archive
Security domain
P

Penetration Testing

All Deep Dives For Infosec Conference Talks Covering Penetration Testing. Talks analyzed in full.

7 deep dives
7 conferences

Latest deep dives

Bypassing AI Security Controls with Prompt Formatting
Fwd cloudsec north america 2025

Bypassing AI Security Controls with Prompt Formatting

Learn how prompt formatting attacks bypass AWS Bedrock Guardrails PII filters without injection — and how system prompt engineering fights back.

Nathan Kirk 16 April 2026
Agents Exploiting Auth-by-One Errors | [un]prompted 2026
Unprompted 2026

Agents Exploiting Auth-by-One Errors | [un]prompted 2026

Learn how AI agents detect authentication bypasses, MFA bypasses, and authorization bugs using validator reuse and auth transmogrification.

Brendan Dolan Gavitt Vincent Olesen 31 March 2026
Attacking AI
Owasp global appsec usa 2025

Attacking AI

Learn a proven 7-phase AI red teaming methodology, prompt injection taxonomy, and real enterprise case studies for assessing LLM systems.

Jason Haddix 28 March 2026
Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems
Owasp global appsec usa 2025

Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems

Learn to threat-model AI agents for indirect prompt injection: enumerate tools, map AI-specific attack vectors, and automate dynamic testing with TamperMonkey.

Will Vandevanter 25 March 2026
Web Security Experts: Are You Overlooking WebRTC Vulnerabilities?
Owasp global appsec usa 2024

Web Security Experts: Are You Overlooking WebRTC Vulnerabilities?

Learn to find WebRTC security vulnerabilities — TURN relay abuse, RTP injection, and signaling DoS — that most web and API pentesters miss entirely.

Sandro Gauci 14 February 2026
Hackuracy: Boosting AST Accuracy Through Hacking
Owasp global appsec usa 2024

Hackuracy: Boosting AST Accuracy Through Hacking

Learn how a 10-month experiment quantified AST accuracy in application security testing — and why the best automated scanner scored just 36.9% F1.

Andres Roldan 13 February 2026
GraphQL Exploitation: Secondary Context Attacks and Business Logic
Owasp global appsec usa 2024

GraphQL Exploitation: Secondary Context Attacks and Business Logic

Learn how GraphQL ID and String scalars enable path traversal-based secondary context attacks in BFF architectures. Two real-world critical exploits and defensive strategies.

Willis Vandevanter 11 February 2026