2026 Péter Szőr Award shortlisted nominees

Posted by    on   Sep 16, 2026

The Péter Szőr Award celebrates the life and works of security researcher Péter Szőr by recognizing, each year, an outstanding piece of technical security research.  

2025-award.jpg

The award aims to recognize a piece of work that demonstrates the kind of rigorous, in-depth research that Péter became known for. Nominations for the award are sought from the security community at large.

The standard of this year's nominations was particularly high, making the job of the selection committee – whose task is to vote for a winner – extremely difficult.

The nominations were, in the end, narrowed down to a shortlist of three:

  • Breaking the Seal: Static Deobfuscation of JSCeal's Compiled V8 Bytecode
    by Aleksandra "hasherezade" Doniec (Check Point Research)
  • BPFdoor in Telecom Networks: Sleeper Cells in the Backbone
    by Rapid7 Labs (Edoardo Giuggioloni, Christiaan Beek and Jindrich Karasek)
  • VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun
    by Check Point Research

The following gives a little more detail about each of the finalists and why they were nominated by members of the community: 

Breaking the Seal: Static Deobfuscation of JSCeal's Compiled V8 Bytecode by Aleksandra "hasherezade" Doniec (Check Point Research)

Why this research was nominated:

"This research tackles a problem that most analysts would simply give up on. JSCeal doesn't just obfuscate its JavaScript, it compiles it into V8 bytecode and ships it as cached data, stripping away nearly everything that source oriented tooling depends on. Rather than treat this as a dead end, hasherezade built a fully static deobfuscation pipeline from the ground up, extending an existing open source decompiler and writing dedicated passes for value propagation, string reconstruction, control flow unflattening, and proxy resolution, all without ever executing the malware.

"What sets this apart is that the outcome isn't just a one time analysis of a single sample. It's a reusable, publicly released toolkit that lets any researcher recover readable structure from this class of compiled bytecode malware going forward.

"The work was also rigorously validated rather than taken on faith. hasherezade tested an LLM assisted renaming stage against real datasets and documented exactly where it helped and where it fell short."

 BPFdoor in Telecom Networks: Sleeper Cells in the Backbone by Rapid7 Labs (in particular Edoardo Giuggioloni, Christiaan Beek and Jindrich Karasek)

Why this research was nominated:

"This research combined deep technical research with direct, real-world impact.

"Over many months, the Rapid7 team worked long hours with agencies and CERTs around the world to understand, detect, and disrupt a highly stealthy threat targeting telecommunications, defence, government, and critical infrastructure. New capabilities and evasion techniques were discovered. Briefings, custom tools, scripts, and detection signatures were provided to help organizations identify and block the threat. Even industry peers joined in and offered samples, to help block this major threat. This was not research for publication alone: a compromise in the telecommunications sector can affect far more than one victim; it can impact critical services and national security." 

VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun by Check Point Research

Why this research was nominated:

"This research is the first documented case that gives real evidence, not speculation, that a fully capable malware framework can be built almost entirely by AI. The team traced operational security failures by the malware's own developer back to the AI generated planning artifacts themselves, uncovering a Spec Driven Development process where the model was first tasked with producing a full multi team development plan, sprint schedules and all, before it ever wrote a line of code. That plan was then followed to build a working implant with eBPF and LKM rootkit capabilities in under a week.

"This matters because it's not just a trend piece about AI and security. The team reconstructed the entire development timeline from leaked artifacts and cross checked it against the malware's technical capabilities, eBPF hooks, cloud enumeration modules, container escape logic, to prove the AI generated code held up to real scrutiny rather than just looking plausible, giving the industry its first hard evidence of a shift that people have been predicting for years without proof."

VB congratulates all the finalists, both for their nominations and for the outstanding research they have contributed to the field. The winner will be announced at the VB2026 gala dinner on 15 October in Seville.

 

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

2026 Péter Szőr Award shortlisted nominees

VB Congratulates the researchers shortlisted for the 2026 Péter Szőr Award.

What cybersecurity experts are talking about in 2026

Cybersecurity research in 2026 is revealing a threat landscape shaped by increasingly specialized actors, trusted platforms being turned into attack vectors, and emerging technologies creating entirely new risks. We highlight five topics that provide…

In memoriam: David Harley

We were very sorry to hear of the passing a few days ago of stalwart supporter of and contributor to VB, David Harley.

Top 5 reasons why leading security companies are sending their teams to VB2025

VB2025 is coming up September 24-26 in Berlin, and teams from major enterprises, government agencies, and security companies are already planning their attendance. Here's why people keep coming back.

What cybersecurity experts are talking about in 2025

The cybersecurity field moves quickly, with new research surfacing regularly and threat actors constantly shifting their approaches. We've gathered five recent research topics that caught our attention, each offering a different angle on the current…

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.