A Familiar Face: Analysis of a new Sharp Panda attack campaign Nguyen Duc Kiem, Doan Minh Long, Viettel Cyber Security |
An Open Directory and a SEA of Victims: Tracing a China-Nexus Operation Through an OPSEC Mistake Sathwik Ram Prakki, Group-IB |
Automated Payload Recovery and Tactic Detection Across macOS Active Families Rajesh Krishna Nikam, CrowdStrike |
Beyond the Implant: Reverse Engineering Native AOT Malware and Exposing a 30,000-Agent Operator Ecosystem Baskar M, Rahul Ramesh, Cyderes |
Breaking Boundaries: Infostealer Strategies in the App-Bound Encryption Era Vojtěch Krejsa, Jan Rubín, Gen Digital |
Bundled and Under the Radar: Malware Abuse of Bun and Deno Jaromír, Check Point |
Countering EDR/DR Bypass: A Multi-Layered Approach to Detection, Response, and Data Protection Varun Prasanth K, SivaSelvan Dhandapani, Staples Innovation Hub |
Cybersecurity Assurance for Drone & UAV Infrastructure Gopinath Lakshmanan, Sify Technologies |
Dead Container Walking: Post-Incident Analysis When Your Workload Is Already Gone Saurabh Mishra, Optum |
Diffing for Intent: Stopping Supply-Chain Malware at the Code-Signing Gate Rishal Dwivedi, Kushal Rajput Lilhare, Adobe |
From Compiler to Concealment: Why Zig Is Becoming the Language of Choice for Linux Threat Actors Tejaswini Sandapolla, Sentinelone |
From Function-Centric AI to Continuous Cyber Resilience: Exploring Agentic AI for Adaptive and Quantum-Ready Cybersecurity Felissa Mariz Marasigan, Mr Mark Jenri Ocampo, EY-GDS |
From Open Directories to AI-Coded Malware: How a Pakistan-Nexus Threat Actor Leaked Their Entire Arsenal Targeting Afghan Telecom and South Asian Critical Infrastructure Subhajeet Singha, Acronis International GmBH |
Garbage In, Verdict Out: AI-Driven Malware Triage and the Disassembler It Never Questions Jagadeesh Chandraiah, Sophos |
Harmonizing AI Agents and Human Analysts in CTI – Are CTI Agents Friends or Rivals to Junior Analysts Takahiro Kakumaru, NEC Corporation |
Hidden in the Overlay Analysis of Backdoor Leveraging Encrypted Overlay Communications for ORB Yuma Masubuchi, JPCERT/CC |
HijackLoader: Polymorphic DLL Injection as a Vector for Multi-Stage Attacks Oleg Gayduk, Maxim Demidenko, Doctor Web |
I.A.P. – It’s Always Policies! (… Until Reality Gets Involved) Righard Zwienenberg, ESET Eddy WIllems, WAVCi |
Intent-Driven Contextual Reasoning Using Sentence Transformers for Business Email Compromise Detection Abhishek Singh, Mimecast |
Lord Of The Ring 0 Adhokshaj Mishra, Animesh Roy, SentinelOne |
Maritime Cyber Security Akash Saksena Capgemini |
Masks, Monsters, and Drivers : Inside the Chaos, Kraken, and DeadLock Ransomware Operations Chetan Raghuprasad, Cisco Talos |
mrhOTshOT: Replaying the World’s Deadliest ICS Attacks — Complete IT+OT Kill Chains for 12 Real Malware Families Malav Vyas, Asher Loranca, Palo Alto Networks |
npm install –dprk: DeceptiveDevelopment’s Supply-Chain Playbooks Against Developers Ettore Bordoni, ESET |
Operation RTO Heist: Anatomy of a Long-Running RTO Phishing Campaign Targeting Indian Users Rupali Parate, Cyble |
Practical Binary Emulation and Taint Analysis for De-obfuscation Tạ Đăng Vinh, Nguyễn Duy Bình, VNPT Cyber Immunity |
PromptSpy: A Framework for Simulating Indirect Prompt Injection Across Autonomous Email Pipelines Prashant Kumar, Forcepoint Software India Pvt. Ltd |
Reconstructing the DPRK Cyber Ecosystem: Infrastructure Pivoting, Malware Lineage, and Operational Attribution Dixit Panchal NetProtector AV, Mr Vaibhav Billade Deloitte |
RenEngine Loader: Catch’Em All – Inside a 1.6 Million-Victim Global Stealer Campaign Hidden in a Game Engine Rahul Ramesh, Reegun Richard Jayapaul, Cyderes |
Rule-Based versus Semantic Web Application Firewalls under LLM-Driven Adaptive SQL-Injection Evasion at the Maximum Protection Setting Karan Khatri Regmi, SecureIQ Lab |
Same Actor, New Voice: Testing Whether AI Rewriting Actually Breaks Threat Actor Attribution Rishika Subhash Desai, BforeAI |
The State of the macOS *Fix Ecosystem and Apple’s Defenses Bhargav Rathod, Palo Alto Networks |
Selective AI Augmentation for Scalable and Cost-Efficient Malware Triage Tonmoy Jitu, Rowland Yu, Sophos |
The Phone Bill You Never Made: Six Years of VoIP Toll Fraud Operations Abhinav Thakur, Cyble |
Transparency Wars: Exposing Hidden Biases in Testing Luis Corrons, Gen Digital Righard Zwienenberg, ESET |
Weaponizing Trust: An Analysis of TeamPCP’s Cross-Platform Multi-Wave Supply Chain Attacks Praveen Babu D, Srinivasan E, K7 Computing Pvt Ltd |
Who’s the Boss Now: Hijacking WhatsApp Web Sessions for Enterprise Fraud Azhagan K M S, Priyadharshini P, K7 Computing Pvt Ltd |
|