The Cyber Archive
Complete catalog
A

All Deep Dives

Every conference talk we've analyzed. Sorted newest first.. Talks analyzed in full.

51 deep dives
9 conferences
62 speakers

Anatomy of an Agentic Personal AI Infrastructure | [un]prompted 2026
Unprompted 2026

Anatomy of an Agentic Personal AI Infrastructure | [un]prompted 2026

Learn how to architect a unified Personal AI Infrastructure (PAI) stack with Council multi-agent debate, the PAI algorithm, and Arbo pipelines to amplify your security engineering practice.

Daniel Miessler 12 April 2026
Zeal of the Convert: Taming Shai-Hulud with AI | [un]prompted 2026
Unprompted 2026

Zeal of the Convert: Taming Shai-Hulud with AI | [un]prompted 2026

Learn how AI workflows, reasoning models, and feedback loops turned a two-week manual investigation into a two-day operation that identified 2,400 supply chain attack victims.

Rami Mccarthy 11 April 2026
AI go Beep Boop! | [un]prompted 2026
Unprompted 2026

AI go Beep Boop! | [un]prompted 2026

Learn how AI cut a 6-week chip glitching failure to 7 minutes. Discover how LLMs guide EM fault injection and design hardware hacking platforms on a $7 Pico.

Adam Laurie 31 March 2026
AI Notetakers: The Most Important Person in the Room | [un]prompted 2026
Unprompted 2026

AI Notetakers: The Most Important Person in the Room | [un]prompted 2026

Discover how AI notetakers introduce prompt injection, viral OAuth expansion, and silent recording into your enterprise — and the controls every security team needs now.

Joe Sullivan 9 April 2026
FENRIR: AI Hunting for AI Zero-Days at Scale | [un]prompted 2026
Unprompted 2026

FENRIR: AI Hunting for AI Zero-Days at Scale | [un]prompted 2026

Discover how Trend Micro's FENRIR engine chains SAST tools, fast LLM triage, and agentic sandboxes to find 60+ CVEs at $8.80 per true positive.

Peter Girnus Derek Chen 8 April 2026
When Passports Execute: Exploiting AI Driven KYC Pipelines | [un]prompted 2026
Unprompted 2026

When Passports Execute: Exploiting AI Driven KYC Pipelines | [un]prompted 2026

Learn how attackers embed prompt injections in passport images to hijack AI KYC agents and exfiltrate customer PII at scale.

Sean Park 7 April 2026
Developing & Deploying AI Fingerprints | [un]prompted 2026
Unprompted 2026

Developing & Deploying AI Fingerprints | [un]prompted 2026

Learn how Binary Shield uses AI fingerprinting to detect and share prompt injection threats across all LLM services in your portfolio — privacy-safe and 36x faster.

Natalie Isak Waris Gill 31 March 2026
Agents Exploiting Auth-by-One Errors | [un]prompted 2026
Unprompted 2026

Agents Exploiting Auth-by-One Errors | [un]prompted 2026

Learn how AI agents detect authentication bypasses, MFA bypasses, and authorization bugs using validator reuse and auth transmogrification.

Brendan Dolan Gavitt Vincent Olesen 31 March 2026
Code Is Free: Securing Software | [un]prompted 2026
Unprompted 2026

Code Is Free: Securing Software | [un]prompted 2026

Learn how OpenAI engineers built LLM-powered security reviewers, living threat models, and a daily dependency scanner using ~40 lines of GitHub Actions YAML and checked-in Markdown files.

Paul Mcmillan Ryan Lopopolo 4 April 2026
Guardrails beyond Vibes | [un]prompted 2026
Unprompted 2026

Guardrails beyond Vibes | [un]prompted 2026

Learn how Stripe built and deployed two production AI security agents with multi-agent architecture, LLM-as-judge eval pipelines, and phased rollout.

Jeffrey Zhang Siddh Shah 3 April 2026
Security Guidance as a Service | [un]prompted 2026
Unprompted 2026

Security Guidance as a Service | [un]prompted 2026

Learn how Adobe built a RAG-powered security guidance platform delivering org-specific recommendations across Jira, Slack, and IDE at scale.

Shruti Datta Gupta Chandrani Mukherjee 1 April 2026
The Hard Part Isn't Building the Agent: Measuring Effectiveness
Unprompted 2026

The Hard Part Isn't Building the Agent: Measuring Effectiveness

Learn why precision and recall fail for autonomous AI security agents — and how rubric-based LLM judge evaluation gives your team a reliable deployment bar.

Joshua Saxe 31 March 2026
Evaluating Threats & Automating Defense at Google
Unprompted 2026

Evaluating Threats & Automating Defense at Google

Discover how Google's Big Sleep and Code Mender use agentic AI to find and patch deep memory safety bugs with zero false positives.

Heather Adkins Four Flynn 30 March 2026
The SCA Balancing Act
Owasp global appsec usa 2025

The SCA Balancing Act

Learn the three hidden costs of software composition analysis and how to match SCA tools to your AppSec program maturity.

Jamie Scott 29 March 2026
Attacking AI
Owasp global appsec usa 2025

Attacking AI

Learn a proven 7-phase AI red teaming methodology, prompt injection taxonomy, and real enterprise case studies for assessing LLM systems.

Jason Haddix 28 March 2026
Plugins Gone Rogue: Attacking Developer Environments
Owasp global appsec usa 2025

Plugins Gone Rogue: Attacking Developer Environments

Learn how malicious VS Code extensions bypass Microsoft's safeguards to steal credentials and execute code on developer machines — and the only defense that actually works.

Raphael Silva 26 March 2026
Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems
Owasp global appsec usa 2025

Indirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML Systems

Learn to threat-model AI agents for indirect prompt injection: enumerate tools, map AI-specific attack vectors, and automate dynamic testing with TamperMonkey.

Will Vandevanter 25 March 2026
Keynote: Red, Blue, and Purple AI
Owasp global appsec usa 2024

Keynote: Red, Blue, and Purple AI

Learn how to build specialized AI security bots and apply generative AI across red team, blue team, and purple team workflows using a proven prompt engineering methodology.

Jason Haddix 20 February 2026
AI Code Generation - Benefits, Risks and Mitigation Controls
Owasp global appsec usa 2024

AI Code Generation - Benefits, Risks and Mitigation Controls

Learn to assess AI code generation security risks—from package hallucination to IP liability—and apply governance controls that protect your SDLC.

Aruneesh Salhotra 19 February 2026
Hidden Chains: Revealing High-Impact Bugs from Bounty Submissions
Owasp global appsec usa 2024

Hidden Chains: Revealing High-Impact Bugs from Bounty Submissions

Learn how Snapchat uncovered three chained, high-impact bug bounty findings—supply chain RCE, Android deep link abuse, and Jupyter XSS-to-RCE—and the program capabilities each forced them to build.

Vinay Prabhushankar Murali Vadakke Puthanveetil 18 February 2026
AI Goat: A Damn Vulnerable AI Infrastructure
Owasp global appsec usa 2024

AI Goat: A Damn Vulnerable AI Infrastructure

Learn to exploit OWASP ML Top 10 risks hands-on — supply chain attacks, data poisoning, and output integrity bypasses against a real AWS SageMaker infrastructure.

Ofir Yakobi Shir Sadon 17 February 2026
Threat Modeling in the Age of AI
Owasp global appsec usa 2024

Threat Modeling in the Age of AI

Learn how to apply structured threat modeling to AI/ML systems using the ML SecOps framework, three diagnostic questions, and OWASP AI Exchange controls.

Susanna Cox 16 February 2026
AI Under the Hood: Unmasking Hidden Threats
Owasp global appsec usa 2024

AI Under the Hood: Unmasking Hidden Threats

Learn how adversarial ML attacks silently bypass AI security controls and how to apply AI security threat modeling using Project Guardrail's tiered questionnaire framework.

Nitish Uplavikar 15 February 2026
Web Security Experts: Are You Overlooking WebRTC Vulnerabilities?
Owasp global appsec usa 2024

Web Security Experts: Are You Overlooking WebRTC Vulnerabilities?

Learn to find WebRTC security vulnerabilities — TURN relay abuse, RTP injection, and signaling DoS — that most web and API pentesters miss entirely.

Sandro Gauci 14 February 2026
1 2 3