| Time |
Green room |
Red room
|
Threat Intelligence Practitioners' Summit |
| 09:00 - 09:30 |
Agent detection & response: safety on a token budget Václav Belák, Jakub Křoustek & Tomáš Ďuriš (Gen) |
How real-world malware disables EDR systems Holger Unterbrink (Cisco Talos) |
Keynote: The next chapter Jiří Sejtko (Gen) |
| 09:30 - 10:00 |
Leveraging Landlock telemetry for Linux detection engineering Guillaume Couchard & Erwan Chevalier (Sekoia) |
Targeting the elderly: from spoofing to persistence Axelle Apvrille (Fortinet) |
Collaboration in action: turning shared threat intelligence into coordinated defence Tuna Dabak (SOCRadar) |
| 10:00 - 10:30 |
Hidden in the overlay – analysis of a backdoor leveraging encrypted overlay communications for ORBs Yuma Masubuchi (JPCERT/CC) |
Disrupting the threat actor mythos: data-based insights into targeting, tooling, and the limits of AI in cybercrime Selena Larson & Daniel Blackford (Proofpoint) |
From signal to shield: rapid collaboration to defend critical infrastructure during crisis Madeline Sedgwick (Palo Alto Networks) |
| 10:30 - 11:00 |
Tea/Coffee |
| 11:00 - 11:30 |
Threat intelligence-driven clustering: identifying a new cyber-mercenary intrusion set Maher Yamout & Fatih Şensoy (Kaspersky) |
Under the surface: inside the evolving 10FXRAT campaign Yoshihiro Ishikawa & Takuma Matsumoto (LAC) |
Wartime intelligence collection and collaboration Sergey Shykevich (Check Point) |
| 11:30 - 12:00 |
After the wipe: runtime root-secret recovery from JadePuffer/ENCFORGE on Windows Wei Gao (Intel) |
From hotel account compromise to guest payment fraud: the reservation hijack attack chain Martin Chlumecký & Luis Corrons (Gen) |
Harmonizing AI agents and human analysts in CTI – are CTI agents friends or rivals to junior analysts? Takahiro Kakumaru (NEC) |
| 12:00 - 12:30 |
From seed to branch: inside DarkPlum's expansion to Ukraine Masaya Motoda, Shogo Hayashi & Rintaro Koike (NTT Security (Japan)) |
Malwaremorphosis – breaking down a global multi-layer malvertising operation Ionuț Baltariu (Bitdefender) |
Stairway to resilience: cybersecurity in good times, bad times, and everything between Selena Larson (Proofpoint), Jeannette Jarvis (Cyber Threat Alliance), Kathi Whitbey (Palo Alto Networks) & Jeanette Miller-Osborn (Dataminr) |
| 12:30 - 14:00 |
Lunch |
| 14:00 - 14:30 |
Mac&Cheese: cooking up the DigitStealer recipe Kseniia Yamburh (MacPaw) & Joan Garcia (Independent researcher) |
The cyber saga: deconstructing the DPRK’s global synthetic IT workforce ecosystem Anastasia Tikhonova (Group-IB) |
STIX in action: proposed industry collaboration on sharing DigSig metadata Samir Mody (K7 Computing) |
| 14:30 - 15:00 |
Meet ARES – an agentic reverse engineer that decrypts sophisticated ransomware encrypted files Raviv Rachmiel & Yonatan Gilvarg (RIO Security) |
DPRK-aligned threat operations: tradecraft, tooling, and detection patterns Wonkyeom Kim |
Defending (against) the human layer: IoBs in the real world Righard Zwienenberg (ESET), Kathi Whitbey (Palo Alto Networks), Samir Mody (K7 Computing) & Mienke (NCSC-NL) |
| 15:00 - 15:30 |
Paying the TOLL: how REF3927 turned 571 IIS servers into an SEO fraud network Salim Bitam & Jia Yu Chan (Elastic) |
Operation ASTERIX: software developer by day, crypto scammer by night Anna Širokova & Jan Řečínský (Rapid7) |
From strategic collections to global and multifaceted ransomware response Gonçalo Ribeiro (Europol - EC3) |
| 15:30 - 16:00 |
Tea/Coffee |
| 16:00 - 16:30 |
Manufactured credibility: detecting fabricated Git history in an active software supply chain campaign George Karagiannidis & Evangelos Ganiaris (TwelveSec) |
Newsjacking the world: tracking three months of uncovered APT operations disguised as global headlines Darrel Tristan Virtusio & Subhajeet Singha (Acronis) |
Ghosts in the chat: tracking GhostPairing from trusted message to linked-device takeover Michal Salat (Gen) |
| 16:30 - 17:00 |
The invisible candidate: tracking the evolution of 'Un-tracked' GRITCASPIAN Asli Koksal (Google)
|
Dawn of Ninja Era: unmasking a malware distribution campaign linked to DPRK IT workers network Naoki Takayama (Internet Initiative Japan) |
The art of fighting back Gabor Szappanos (Sophos) |
| 17:00 - 18:00 |
Posters will be displayed throughout the day in the conference foyer, with a poster presentation session at the end of the day. |
| 19:30 - 23:00 |
Pre-dinner drinks reception followed by VB2026 gala dinner & entertainment |