Programme 2026
The opening and keynote will take place in the Large Assembly Hall.
The following presentations will be divided thematically into different tracks. All sessions related to the same theme will take place in the same room. Overall, the tracks are spread across four different rooms and run simultaneously.
Additionally, selected presentations from the Large and Medium Assembly Hall will be streamed live on YouTube.
General programm:
- Exhibition stands | A.0.19 Main Hall A & Connecting Axis buildings A & B
- Graduate Lounge | A.0.11 Small Assembly Hall, building A
- Photo Booth | Connecting Axis, building A
- Cyber Escape Room | Parking lot USTP
Our event app will be online soon!
Put together the programme of your choice, find out more about our speakers and get an overview of all exhibitors.
Johann Haag | Chief Executive Officer (CEO), USTP
*** Live stream via YouTube ***
Simon Tjoa | Head of Department of Computer Science & Security, USTP
*** Live stream via YouTube ***
Jens Wiesner | Referatsleiter TK15 - Industrielle Steuerungs- und Automatisierungssysteme, Bundesamt für Sicherheit in der Informationstechnik
*** Live stream via YouTube ***
Florian Schmidt | TÜV Süd
*** Live stream via YouTube ***
Rainer Poisel | honeytreeLabs / Embedded Focus
*** Live stream via YouTube ***
Anna Habenegg | PwC Österreich
Thomas Mann | CIS Certification GmbH
Myriam Teicher | nordpol.Security
Ilyas Demirtas, Kai Starik | Deloitte Consulting GmbH
*** Live stream via YouTube ***
Dominik Auer | Fidela GmbH
*** Live stream via YouTube ***
Daniel Haslinger & Christoph Lang-Muhr | USTP
*** Live stream via YouTube ***
Christian Wojner & Wolfgang Löw | EVN AG
Jürgen Waldl | base-IT GmbH
*** Live stream via YouTube ***
David Wind | slashsec Red Teaming GmbH
*** Live stream via YouTube ***
Constanze Roedig | SBA Research
Security Operations Center have the requirement to persist data over long timescales and across system layers in order to allow the future forensic triage of an attack. This prevailing “collect-everything” paradigm leads to excessive costs, low signal-to-noise ratios, and analyst alert fatigue. We propose a digitally sovereign kernel-level anomaly based approach realised by eBPF and signed behavioral profiles (“Software Bill of Behavior”, SBoB). Our prototype continuously monitors system calls, network traffic, and file operations, detects significant deviations in real time, and triggers event-driven data capture.
This talk will explain how
- pre-correlation allows filtering through millions of false-positives with time-to-verdict in sub-seconds
- expected reduction of data-volume scales with desired precision
- to deal with eBPF blindness
- performance and observability engineering is crucial for robust detections under high loads
For anyone who is tired of alerts.
*** Live stream via YouTube ***
Jonas Plitt | a-team rocks consulting gmbh
*** Live stream via YouTube ***
Akashpreet Wedech & Florian Hehenberger | PwC Österreich
*** Live stream via YouTube ***
Stefan Schubert & Marius-Constantin Dinu | VBV-Gruppe
*** Live stream via YouTube ***
Ahmed Hassan | Austrian HealthCert (AGES)
Werner Schober & Clemens Stockenreitner | SEC Consult
Benjamin Floriani & Patrick Pongratz | SecCore GmbH
Felix Eberstaller | QuellSec
OT protocols were designed to trust the network. Fifteen years of ICS tooling has grown around that assumption, one protocol per tool, each built in isolation. OIDA (OT/ICS Discovery & Assessment) is a new open-source framework that covers the full stack: one CLI, one binary, 25+ industrial protocols under a single uniform syntax. Scan. Fuzz. Assess. Offline and air-gapped, no agent on the device.
This talk presents the v1.0 release. We walk through the four core operations: discovering assets at the layer OT devices actually respond to, enumerating protocols natively down to the function code and data point, fuzzing live parsers, and combing captures offline with 109 protocol-aware listeners. Live demos against real protocol stacks. Released under AGPL-3.0 through QuellSec, an Austrian non-profit for open-source ICS security.
Dominik Steffan & Felix Schuster | AIT Austrian Institute of Technology
Florian Haselsteiner | SEC Consult, USTP
This talk examines how established macOS exploitation techniques can be applied to a largely overlooked attack surface: audio plugin installers. By analyzing installers from multiple major vendors, we demonstrate how common design and implementation flaws can be leveraged to achieve local privilege escalation.
The presentation covers nine CVEs across five different vendors, highlighting recurring vulnerability patterns, exploitation strategies, and the security implications for both developers and end users. Attendees will gain insight into the intersection of macOS installer security and the audio software ecosystem, along with practical lessons for identifying and mitigating similar issues.
Timo Longin | SEC Consult
Ever wondered what would happen if a huge email provider like Gmail, Yahoo, or iCloud forgot to check who’s actually sending the email? Well, you’re in luck. In this talk, we’ll go on a deep dive into various kinds of “From:” header spoofing, letting us send emails from billions of email addresses. Bypassing SPF, DKIM, and DMARC? No problem.
We’ll start with some emailing fundamentals to cover the basics. Then, we’ll explore the technical intricacies of email spoofing and MIME header parsing differentials in major providers. Lastly, we’ll take a look at some painfully frustrating vulnerability disclosures.
Whether you're a researcher, a pentester, or just someone who wants to know how fragile email security still is, this talk will be fun. And who knows - maybe you’ll even be able to find your very own email spoofing vulnerability.
Georg Ungerböck & Stephan Bauer | ARCANIX OG
Reinhard Kugler | SBA Research
CI/CD pipelines play an important role in modern software development. From a security perspective, this methodology contributes to more secure products, as automated checks can be applied on every run. Developers define tasks in a metadata file, and the system executes the defined jobs automatically. But what if the build chain itself becomes the security problem, allowing attackers to manipulate artifacts or take control of backend infrastructure? Let’s take a deep dive into “Poisoned Pipeline Execution” (OWASP CICD-SEC-4).
Builds are typically carried out in multiple steps using Runners—agents that pick up jobs and execute build instructions. These instructions, such as compiling a program or building a container image, are usually performed inside containers. Containers may provide isolation, but the effectiveness in terms of security strongly depends on the Runner’s configuration. Attackers can abuse Runners to execute arbitrary commands, leading to information disclosure or privilege escalation. While such attacks are well documented, effective detection mechanisms are often lacking.
Any viable detection method must be independent of the source code, language-agnostic, and container-friendly. The eBPF technology, which enables tracing of kernel-level activity, is well suited for this purpose. In this talk, we explore security vulnerabilities in CI Runners, how they become targets for attackers, and how malicious activities can be detected using eBPF.
Philipp-Sebastian Vogt | AIT Austrian Institute of Technology
The increasing availability of low‑cost Software Defined Radios (SDRs) has greatly expanded access to radio‑frequency analysis for researchers and practitioners. Devices such as RTL‑SDR dongles enable detailed exploration of wireless communication protocols, including those used in consumer drone systems.
This work presents an experimental study on using SDRs to analyze drone control channels and identify potential security weaknesses. Using a custom GNU Radio module, we demonstrate demodulation and inspection of real drone communication signals, showing how insufficiently protected links may expose critical metadata such as device identifiers or control patterns.
The study aims to raise awareness of these vulnerabilities and emphasize the need for stronger cryptographic protection and authentication in unmanned aerial vehicle communications. We conclude with an overview of countermeasures, directions for future research, and a live end‑to‑end demo operating on actual drones.
Jakob Pachmann
CBOR (RFC 8949) is a binary serialization format used in constrained security-critical systems like FIDO2/WebAuthn and COSE. Despite a precise specification, implementations diverge across languages and systems, leading to different behavior when confronted with the same input. In this talk, 11 CBOR parsers across seven languages are compared to identify security-relevant behavior, such as unexpected acceptance/rejection of input, hangs and crashes.
Martin Grottenthaler | VidraSec
Viktor Zelezny | Accenture
Tobias Höller | Johannes Kepler Universität Linz
