Agenda is subject to change. The time is reflective of the host country, UTC +9.
Plenary Sessions
Training Sessions
| Plenary Sessions | |
|---|---|
| 08:50 – 09:00 | Welcome Message |
| 09:00 – 09:40 | PK Zero to Owned: Mapping the Lifecycle of a Credential Stealer to Corporate Breach Hassan Khan Yusufzai (Laburity, PK) TLP:CLEAR |
| 09:45 – 10:05 | KR From Internet Noise to Operator Intent: Findings from a Smart Factory OT Honeypot in Busan Kwangsik Lee (SHOEBILLEX Inc. , KR) TLP:CLEAR |
| 10:10 – 10:30 | AU Frontier Models and Their Impact on Cyber Security Michael Boyd (ACSC, AU) TLP:CLEAR |
| 10:30 – 10:50 | Break |
| 10:50 – 11:10 | KR The Paradox of Trust: When Your Own Defenses Become the Intrusion Path Jaehoon Kim (Financial Security Institute (FSI) , KR); Mohyun Park, Younghwan Kim (Financial Security Institute (FSI), KR) TLP:AMBER |
| 11:15 – 11:35 | TW Becoming a CNA Just in Time for the AI Flood Rex Kao (ASUSTeK COMPUTER INC. , TW); TJ Hsu (ASUSTeK COMPUTER INC., TW) TLP:CLEAR |
| 11:40 – 12:20 | AU Karine Tobin (FIRST Member, AU) TLP:GREEN |
| 12:20 – 14:00 | Lunch Break |
| 14:00 – 14:40 | (Keynote) TBD |
| 14:45 – 15:05 | AU Getting to Know You, Your Sector, and Some By-product Intel Information, In the Process. Geoffroy Thonon (AUSCERT, AU) TLP:GREEN |
| 15:10 – 15:50 | SG Defending against Kernel-Level Threats: What Works, What Doesn't Dennis Tan (CSA Singapore, SG) TLP:GREEN |
| 15:50 – 16:10 | Break |
| 16:10 – 16:50 | VN Nguyen Nguyen Huu (PTIT Ho Chi Minh, VN) TLP:GREEN |
| 16:55 – 17:15 | KR Kubernetes Lateral Movement Incident Analysis Seokhoon Park (NIRS, KR) TLP:RED |
| 17:15 – 17:20 | Closing |
| 18:00 – 20:00 |
Rex Kao (ASUSTeK COMPUTER INC. , TW), TJ Hsu (ASUSTeK COMPUTER INC., TW)
For years, ASUS relied on other CVE Numbering Authorities to assign IDs for vulnerabilities in our own products — workable, but slow, and largely out of our hands. In September 2024, ASUS became a CNA in our own right. Two years in, we're still learning what that responsibility actually costs. Almost immediately, our new CVD pipeline met a force we hadn't fully planned for: external researchers increasingly using AI tools to hunt for vulnerabilities at a pace and volume no manual intake process was built for. The result isn't more findings from us — it's a heavier, noisier stream of inbound reports from the outside: more near-duplicates, more AI-generated write-ups of varying quality, arriving faster than our engineering teams can validate them. At the same time, downstream consumers and suppliers of our advisories increasingly expect CSAF/VEX machine-readable output, adding a second layer of pressure on a process we'd only just stood up.
This talk walks through what broke in our intake and triage workflow as a brand-new CNA, what we changed in response, and — more importantly — a handful of questions we still don't have good answers for: Should AI-assisted reports be triaged differently from human ones, and who decides that? Does "coordinated" disclosure still mean the same thing when external reporters can scale their output faster than any vendor's engineering team can respond? And if vendors eventually lean on AI themselves to keep CSAF statements current, who is actually coordinating with whom? We don't claim to have solved these — we're bringing them to this room because every vendor CNA and national CERT in the region will run into them soon, if they haven't already.
TJ Hsu is a Cyber Security Senior Manager at ASUS, where he leads the company's CSIRT and PSIRT operations and serves as ASUS's official representative to FIRST and as a CVE Numbering Authority (CNA). His work centers on turning vulnerability data and threat intelligence into risk-based mitigation strategies and executive guidance across ASUS's global business.
Before joining ASUS, TJ spent several years as a security consultant with two of the Big Four (EY and Deloitte), delivering defense-in-depth security architecture, large-scale infrastructure audits, and technical security assessments for clients across the financial, government, technology, chemical, and aviation sectors. He also built and operated a cybersecurity testing laboratory from the ground up to full ISO/IEC 17025 accreditation.
TJ holds CISSP, CISM, CEH Master, CTIA, CPSA, and ISO 27001 LA certifications. Outside of work, he's an avid traveler and landscape photographer, always chasing a good meal or a clear night sky for a shot of the Milky Way.
Rex Kao is a Detection & Response Analyst at ASUS, operating within the company's CSIRT and PSIRT workflows. He specializes in threat intelligence analysis, incident response, and vulnerability management, driving proactive risk mitigation across enterprise and product ecosystems. With a decade of experience spanning enterprise defense architecture, Big Four consulting (Deloitte), and hands-on network engineering, Rex brings deep expertise in Zero Trust transformation, multi-cloud security, and ISMS/AI governance. He holds several premier industry certifications, including CISSP, CEH Master, GCP Professional Cloud Security Engineer, AWS Certified AI Practitioner, and ISO 27001/27701/42001 Lead Auditor credentials.
November 5, 2026 11:15-11:35
Modern organisations rely on a complex web of interconnected dependencies, from software providers and cloud platforms to vendors and managed service providers. While these relationships enable innovation and efficiency, they also create opportunities for attackers to compromise an organisation indirectly by targeting a trusted third party. This presentation explores supply chain risk through an incident response lens, examining how attacks emerge, spread, and impact organisations that may not have been the original target. Drawing on real-world examples, including recent Australian incidents, it highlights the operational, financial, and reputational consequences of supply chain compromises. The session also discusses practical strategies for improving resilience, including third-party risk management, software dependency governance, and incident preparedness. In an interconnected world, an unbreakable chain is not one without weak links, it is one where every link is understood, monitored, and prepared for when incidents occur. (Approximately 20-30 Minutes)
Kwong (Vinh) Duong - Digital Forensics and Incident Response, ACSC
Krassimir Tzvetanov, PhDKrassimir Tzvetanov, PhD (Hydrolix/Purdue University, US)
Cyber Threat Intelligence (CTI) has become a cornerstone of modern cybersecurity programs, transforming raw technical data into actionable insights that enable proactive and intelligence-driven defense. As threat actors grow more sophisticated - leveraging automation, supply-chain compromise, and hybrid attack vectors-organizations must evolve from reactive incident response toward strategic, intelligence-led security practices. CTI fills this gap by systematically collecting, analyzing, and contextualizing information about adversaries, their motivations, tactics, and infrastructures.
This presentation addresses the foundational question, “What is CTI?” by offering a structured definition that spans strategic, operational, and tactical levels. It aims to dispel the confusion often introduced by marketing-driven narratives in this rapidly commercializing discipline. The content is grounded in my doctoral research at the Purdue Military Research Institute (PMRI) and enriched by the insight and feedback of FIRST CTI SIG members who have supported this work throughout its development.
Beyond synthesizing academic and doctrinal perspectives, the session highlights the practical applications of CTI and its role in enhancing situational awareness, supporting risk-based decision-making, and strengthening detection and response across security operations centers, vulnerability management, incident response, and executive leadership. It also examines common organizational use cases and maturity levels observed across CTI teams.
Attendees will leave with a clear, comprehensive understanding of CTI’s purpose, value, and future direction within an increasingly complex and dynamic threat landscape.
Dr. Krassimir Tzvetanov has served as a Graduate Researcher at Purdue University for the past six years, focusing on Homeland Security, Cyber Threat Intelligence (CTI), and Influence Operations. Concurrently, he has served as Instructor of Record for graduate-level courses in Cybersecurity and Homeland Security.
For the past three years, Dr. Tzvetanov has also served as Director of Security Engineering at Hydrolix. Prior to this role, he held positions including CTI Lead, Principal Security Engineer and Architect, and Red Team Operator at major technology companies such as Cisco, Yahoo!, and Google. Throughout his career, he has authored training materials, white papers, and academic publications covering distributed denial-of-service (DDoS) attack mitigation and investigation, cyber threat intelligence, privacy, and influence operations. He has also contributed to numerous law enforcement investigations, including providing expert witness testimony in federal court.
Dr. Tzvetanov is an active contributor to the global cybersecurity research and incident response communities. He has served on program committees for ShmooCon, FIRST, NANOG, BayThreat, and the Underground Economy. He is an active participant in several Special Interest Groups within the Forum of Incident Response and Security Teams (FIRST), has contributed to the Honeynet Project, and was a principal organizer of the BayThreat security conference. He also led the Radio Communications Department at DEF CON.
Dr. Tzvetanov holds a Ph.D. and an M.S. in Technology, both with a concentration in Homeland Security; an M.S. in Digital Forensics and Investigations; and a B.S. in Electrical Engineering with a concentration in Radio Communications.
November 6, 2026 13:00-14:30, November 6, 2026 14:45-16:00
Dennis Tan (CSA Singapore, SG)
Bring Your Own Vulnerable Driver (BYOVD) is an increasingly common technique for bypassing kernel-level security by abusing legitimately signed but vulnerable drivers. Although Microsoft and security vendors have introduced various mitigations, many defenders still do not know which controls are truly effective, where the gaps remain, or how attackers continue to bypass them. This uncertainty makes it difficult to accurately assess risk and prioritize the most effective defensive measures.
In this talk, we evaluate BYOVD from both the attacker's and defender's perspectives. We examine Microsoft's current mitigations, reverse engineer two real-world vulnerable drivers to understand their root causes and exploitation techniques, and present practical strategies for preventing, detecting, and responding to BYOVD attacks.
The talk covers:
Dennis Tan , CSA SingCERT
November 5, 2026 15:10-15:50
Nguyen Nguyen Huu (PTIT Ho Chi Minh, VN)
The Vietnam CyberSecurity Real Exercise (RCSE) model has been implemented since 2021 at the direction of the former Vietnam National CERT (VNCERT/CC). To enhance its effectiveness, we developed the new model of Incident Response Real Exercise (IRRE) to help organizations and businesses improve their incident response plan (IRP) for real-time response to incidents from their real systems. Improving incident response will help the blue teams' capacity for incident response and also test recovery capacity, requirements such as RTO in their current IRP.
Nguyen Huu Nguyen is the former Vice Director of former VNCERT/CC of Vietnam
November 5, 2026 16:10-16:50
Phishing remains one of the most common cyberattacks affecting public and organisations in Hong Kong. This sharing session will examine recent phishing campaigns, focusing on how threat actors are moving beyond conventional credential harvesting to achieve account takeover by exploiting trusted platform features, familiar online services and user behaviour.
Drawing on recent observations and case examples, the session will explore the abuse of linked-device features to hijack messaging accounts, as well as phishing schemes targeting users of online marketplaces. It will also introduce emerging techniques such as ClickFix and OAuth-based consent phishing, highlighting how attackers manipulate victims into executing malicious actions or granting unauthorised access.
Perry Yan is a cybersecurity analyst with over seven years at the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT). At HKCERT, he contributes to core operations, including phishing investigations and coordinating takedowns, and has conducted IoT security research focused on digital signage and Zigbee technology. He has helped on security guideline publications on HKCERT’s website, such as the “Incident Response Guideline for SMEs” and the “IoT Security Guideline for Digital Signage”. As part of HKCERT’s outreach, Perry has also been delivering cybersecurity awareness talks across Hong Kong to audiences ranging from university students to IT professionals.
For over a decade, David Bianco's Pyramid of Pain has taught defenders to rank indicators by the cost they impose on an adversary. But it was built for one organization defending its own estate, and at national scale every assumption gives way: the unit of defense is a country, the defender is a federation, the inputs are multi-domain, and the adversary now includes nation-states. The axis itself shifts, from tactical evasion cost to strategic operational cost. This talk extends the pyramid into a six-level national CTI map and walks a live national deployment up it, level by level, illustrated throughout with working-build screens and offered as a transferable method, not a product.
It leads with what a FIRST and APCERT room values most: trusted, cross-border collaborative response. Every case can be sealed into a self-contained, portable hand-off packet, a signed intelligence bundle carrying regulatory clocks and per-participant sharing caps, that a peer CERT cryptographically verifies the moment it arrives, re-hashing every artifact, checking the signature, and confirming the sender against a federation trust registry. Around it operates a three-level federation, bilateral, regional coalition, and international network, that speaks the community's own standards and spans FIRST, APCERT, OIC-CERT and the EU CSIRTs Network. Above pure sharing sits a genuine coordination layer: criticality-tiered alerting, joint advisories, and coordinated multi-CERT takedowns that route sinkhole-C2, botnet, phishing, typosquat or any other malicious infrastructure straight to the CERT, registry or law-enforcement partner that actually concern about it.
Underneath, an attribution engine answers the question that decides everything, whose problem is it?, mapping every signal to its owner so each team sees only what is theirs. A confidence-tiered AI cascade keeps scarce analysts on the work that matters, running sovereign and on-premise so national data never leaves national control. Route, don't broadcast: the federation becomes the multiplier, not the bottleneck. Fund attribution and coordination, not feed count. Honest limits included.
Mohammad Makchudul Alam is a forward-thinking cybersecurity researcher and practitioner, dedicated to safeguarding critical infrastructures across government, financial, and defense sectors. As an Information Security Specialist at BGD e-GOV CIRT, he drives national cyber threat intelligence operations and incident response, leading efforts against ransomware, APTs, and large-scale cyber incidents. He is also working as a visiting researcher at DNS Research Lab, University College Dublin. His research focuses on AI-driven security operations, threat-informed defense automation for cyber-physical systems, cyber threat intelligence, incident response, and digital forensics, with particular interest in AI and explainability in cybersecurity. He bridges hands-on defense expertise with advanced research to address adversarial approaches, TTPs, and attack vectors for SOC process improvements. Mr. Alam is looking forward to collaboration and cooperation in the research areas to advance research and develop innovative and smart cyber defense frameworks and solutions.
I am Md. Redowan Zaman Anik, currently working as an Incident Handler at the National CIRT, where I focus on national-level incident handling, Cyber Threat Intelligence (CTI), and Security Operations (SOC). With over 11 years of experience in the field of cybersecurity, I have been actively involved in handling national-level cyber incidents and contributing to the country’s digital defense. My journey encompasses both academic and professional achievements, including the publication of two research papers in the field of cybersecurity.
Throughout my career, I have been passionate about sharing knowledge and building capacity. I have delivered cybersecurity training programs at several prestigious institutions, including the National Academy for Planning and Development (NAPD), BKIICT, and the Bangladesh Computer Council (BCC). I have also conducted specialized training for National Security Intelligence (NSI), Criminal Investigation Department (CID), and other law enforcement agencies. Additionally, I have led programs on SOC Analysis, Email Security, CA Certificate systems, and Juniper technologies, aiming to strengthen cybersecurity awareness and operational excellence across government and critical sectors.
Africa's cybersecurity ecosystem has largely cleared its first hurdle, establishing laws, strategies, and institutions, and now faces a harder second challenge: operationalizing those frameworks through sustained funding, continuous assessment, and skilled people. This talk presents the findings of AfricaCERT's 2025 Cybersecurity Posture Report, which pairs a continental survey of 41 African nations (97.6% completion) with external, measurement-based telemetry to move the conversation from self-reported intent to observed reality.
The survey shows strong strategic and legal momentum coupled with uneven operational maturity.
We close with a prioritized, evidence-based agenda and reflect on how this evidence base feeds directly into the UN Global Mechanism's capacity-building agenda.
Key takeaways for attendees A replicable methodology for combining a national posture survey with external telemetry to produce an honest, evidence-based maturity picture. Continental benchmarks (legal, operational, routing, DNS, OT, workforce) against which any national CSIRT can position itself. A prioritised action agenda that distinguishes low-cost, high-leverage moves (CVD adoption, ROA creation, removable-media control) from longer-term capacity investments.
Why this matters to the CSIRT community Most national posture assessments stop at self-reported governance indicators. By cross-referencing survey data against independent measurement — credentials, infections, routing, DNS, ICS, cable and institutional resilience — this work gives CSIRT teams a defensible, externally validated basis for prioritising scarce resources, and gives regional coordination bodies a shared evidence base for collective action.
Co-founder of the Africa Forum of Incident Response and Security Teams (AfricaCERT) Jean-Robert Hountomey works as a Cybersecurity and Product Security researcher for a global technology leader with more than two decades of practice. His investigation areas include Cybersecurity Health and Maturity, Product Security, Privacy Engineering, Secure Software Development Life Cycle, Incident Management, Vulnerability Research, and Technology Policy. Mr. Hountomey contributes to the community as a co-founder of the Africa Forum of Incident Response and Security Teams (AfricaCERT) and the African Anti-Abuse Working Group. He also contributes to FIRST SIGs, CVE Outreach, AUCSEG, ISOC, ICANN, AfriNIC, AfNOG, etc... At AfricaCERT his focus covers issues and opportunities related to law, technology, Internet Governance, standards on digital security, cyber workforce, and recently ICS/OT Cybersecurity.
Kwangsik Lee (SHOEBILLEX Inc. , KR)
This presentation presents findings from a smart factory OT honeypot operated in a Busan-based laboratory environment. The study examines how CSIRTs can distinguish routine Internet scanning from OT-aware reconnaissance, control-oriented interaction, and behavior resembling legitimate operator activity. The test environment includes PLC and HMI components, engineering workstation services, Modbus/TCP, and network monitoring sensors. Collected telemetry is analyzed using protocol awareness, session duration, function-code usage, register access patterns, write attempts, multi-stage behavior, and command-sequence similarity. Based on these observations, the presentation proposes a practical classification and escalation model that separates statistical noise from actionable OT threat intelligence. Selected behaviors are also mapped to MITRE ATT&CK for ICS. The session will cover the honeypot architecture, data-collection method, key observations, operational limitations, and a minimum OT telemetry set that regional CSIRTs can share for cross-border analysis and coordinated incident response.
Kwangsik Lee is a cybersecurity and incident response professional with more than 18 years of experience in national-level cyber incident handling, threat analysis, and security operations. He previously served as a Team Leader and Incident Commander at KrCERT/CC, Korea Internet & Security Agency, where he coordinated responses to large-scale cyber incidents affecting critical organizations and infrastructure. His current work focuses on operational technology security, industrial incident response, OT threat detection, and the development of practical monitoring and assessment methods for smart manufacturing environments. He is also conducting applied research using PLCs, HMIs, industrial protocols, network sensors, and OT honeypots to distinguish routine Internet activity from behavior that may indicate genuine intent to observe or manipulate industrial processes. His professional interests include OT threat intelligence, evidence-driven incident response, cyber-physical monitoring, and regional CSIRT collaboration.
November 5, 2026 09:45-10:05
Michael Boyd (ACSC, AU)
Prioritising the security, reliability, and fast recovery of essential systems must be a central concern for critical infrastructure (CI) operators worldwide. This presentation will include guidance for CI entities to protect their OT environments from escalating cyber threats, recognising that the challenges and consequences for OT environments require additional consideration to those for traditional corporate information technology networks.
Michael Boyd - Director, National Cyber Watch Office, ACSC
November 5, 2026 10:10-10:30
Geoffroy Thonon (AUSCERT, AU)
As CERTs/CSIRTs we have no shortage of tactical information to provide our constituency. You can buy it, find it or collect it yourself. These indicators of compromise or vulnerability can be acquired either by first, second, or third person scanning. But what if you could identify constituents that have trouble with their cyber security operations, instead of sending endless notifications of their vulnerabilities. The intelligence requirement topic being addressed is if an organisation displays difficulties in patching and determine their actual reaction rate. This presentation will summarise the process of creating a report about "most at need of help" constituent organisations, with regards to CVE's, or group them according to their industry sector to have a footprint of actual time-to-patch and compare them to industry recommendations.
Geoffroy Thonon is supporting the CERT Community for the past 20 year in any way possible, be it from process and strategy reviews of CERT/CSIRT to tool creation, training ,managing or incident response, Geoff liaises with like-minded computer emergency response teams for the purpose of creating a safe, clean and reliable cyber space through global collaboration.
November 5, 2026 14:45-15:05
Seokhoon Park (NIRS, KR)
Title: Reconstructing the Crime Scene: Tracing Kubernetes Pod Lateral Movement via Multi-Layered Forensics Abstract: In cloud-native environments, the ephemeral nature of containers creates a critical blind spot for incident responders. When an attacker compromises a public-facing pod, they often leverage weak network configurations and over-privileged permissions to perform lateral movement before destroying the initial container to erase digital evidence. This 20-minute session introduces a pragmatic forensic framework to hunt, trace, and reconstruct these hidden container-to-container pivoting paths. Based on recent real-world threat intelligence from cryptocurrency platforms, we will dissect a live attack scenario: starting from web shell exploitation on a frontline pod, moving to Service Account token theft, and concluding with unauthorized cross-namespace code execution via Kubernetes API calls. To overcome the limitations of vanished container disks, we present a robust three-layered forensic correlation methodology: Control Plane: Identifying suspicious exec patterns (.../pods/pod-B/exec) within Kubernetes API Server Audit Logs by mapping source IPs and stolen user.username credentials. Data Plane: Detecting anomalous internal network scans (SYN packet spikes) across local subnets using CNI logs and flow infrastructures. Host OS: Extracting volatile artifacts, such as modified files and bash history, from the worker node’s Overlay FS upper directory, coupled with eBPF-based runtime syscall tracking (curl, chmod).Finally, we translate these forensic insights into actionable defense, providing declarative Network Policies and service account hardening blueprints. Attendees will walk away with the practical knowledge required to make invisible cloud-native threats completely visible.
Seokhoon Park is the NIRS CERT CISO and NPS CERT Security Manager.
November 5, 2026 16:55-17:15
The upcoming EU Cyber Resilience Act (CRA) will make risk/vulnerability assessments a mandatory requirement to ship IoT products. In Japan, the Ministry of Economy, Trade and Industry launched the “Security Labeling Scheme for IoT Products (JC-STAR)” in 2025. And in 2026, mutual recognition agreements with the Singapore Cybersecurity Labelling Scheme and the UK PSTI Act have been established, enabling the scheme to operate as a coordinated international certification. Panasonic Product Security Center has conducted pre-shipment security assessments for over 15 years, ensuring the security of our products. We have supported JC-STAR certification efforts. For Level 1, which certify “baseline security required by vendor’s self-test and declaration of conformity” — we recognized that enabling business units to complete the certification process independently is more scalable and cost-effective than having a specialized team handling each assessment. To enable this, we developed "OROCHIFY", a tool that enables non-security specialists to execute vulnerability assessments with repeatable results. It automatically executes test cases aligned with JC-STAR Level 1 requirements, generates logs and reports that can be used as technical test evidence. This session presents insights into JC-STAR and related cybersecurity labeling schemes’ technical requirements, effective collaboration between business units and product security experts; the architecture of OROCHIFY, along with the boundaries between what tooling can and cannot automate.
Eiko Kubo is a product security engineer at Panasonic, focusing on promoting product security activities at the business divisions overseas. She started as a server and network infrastructure engineer. Experience with incidents and maintaining customers’ IT environments prompted her strong interest in cybersecurity. Today, she spends most of time helping business units comply with fast-moving global regulations for products shipped worldwide and developing practical strategies for mandatory, time-bound duties, such as vulnerability reporting. She holds an MSc in Cyber Security from the University of York, a program certified by the UK National Cyber Security Centre (NCSC).
Mr. Yuki Osawa is a member of Panasonic PSIRT and leads some R&D projects in IoT security. He started his career as a software engineer for the telecom network at NTT Comware Corporation. He worked for Hyogo prefectural government from 2005 to 2017 as an administrator of information systems. He was a member of CSIRT in Hyogo government. He received a master's degree in Information Technology - Information Security from Carnegie Mellon CyLab Japan in 2009. After joining Panasonic in 2017, he has focused on improving security for IoT, including Product security training for developers, IoT Threat intelligence and CTFs. He led Panasonic product security activities in the APAC region until 2022.
Takayuki Uchiyama is a member of Panasonic PSIRT and is responsible for product security activities at the business divisions overseas. His main roles include, the handling of vulnerabilities, creating and conducting product security training to product developers and providing assistance to product development teams related to product security as necessary. Aside from his role in Panasonic, Takayuki has been a CVE Board Member since 2016. Prior to joining Panasonic, Takayuki worked at JPCERT/CC, where his main tasks involved the coordination of vulnerability reports with PSIRTs, taking part in various discussions groups related to the identification / analysis / coordination / disclosure of vulnerabilities.
Seiichi KomuraSeiichi Komura (Chair of SIM3 Promotion Committee, Nippon CSIRT Association, JP)
New cyberattack techniques appear day by day and information security landscape is constantly evolving. Therefore, CSIRT activities must continually adapt to these changes and improve. At the same time, since IT technology plays a central role in organizational and societal activities, incident handling require speed and reliability. CSIRTs must balance updating their operations and maintaining them high quality. In this training session, as a method for CSIRT reliable management with continuous improvement, we will introduce the CSIRT Maturity Model: SIM3 and conduct exercises to help participants understand SIM3. We will begin with an overview of SIM3. Through hands-on exercises, help participants understand its structure and usage, focusing on the 11 criteria required for FIRST applications. We will also introduce examples of SIM3 usage, such as the three maturity baselines required of national CSIRTs in EU member states and the baselines used by the European CSIRT community (TF-CSIRT) to certify mature CSIRTs, as well as initiatives aimed at advancing CSIRT maturity in Japan and Asia.
Seiichi "Ichi" Komura, Certified SIM3 Trainer and Auditor, CISSP He is member of steering committee, the chair of SIM3 promotion committee and the leader of CSIRT evaluation and maturity model WG of Nippon CSIRT Association (NCA). He conducts CSIRT related presentations, lectures and training in several communities and universities. He is a Senior manager of NTT Advanced technology corporation, works as a POC of internal CSIRT, a consultant on building and improving CSIRT, and a trainer of information security.
November 6, 2026 09:00-10:15, November 6, 2026 10:30-12:00
This presentation explores the evolving threat of BadBox, a sophisticated supply-chain malware campaign that transforms consumer IoT devices into global criminal infrastructure. Originally identified in 2023 and rooted in the Triada malware family, the botnet has evolved into BadBox 2.0, a modular ecosystem facilitating ad fraud, residential proxy services, and "proxyjacking". The threat is particularly acute in regions with high imports of low-cost Android devices, informal electronics markets, and limited certification verification. Using Bhutan as a primary case study, this session details how threat intelligence feeds and passive telemetry identified BadBox-related infections associated with all known Autonomous Systems in the country. We examine the primary infection vectors, including pre-installed firmware compromises, first-boot network infections, and malicious third-party applications. The paper also focuses on the operational challenges faced by BtCIRT, such as the difficulty of tracing infections to specific customer devices when they are located behind ISP-managed NAT. To address these challenges, we propose a multi-layered detection and response framework. This framework outlines specific actions for:
Pratima Pradhan is an ICT Analyst and cybersecurity specialist with experience in cybersecurity strategy, security operations, incident response, threat analysis, and national cybersecurity capacity development. She led the development and drafting of Bhutan’s first National Cybersecurity Strategy, which was approved in 2024, contributing to the establishment of a national strategic direction for strengthening cybersecurity governance, resilience, and capability.
Her professional work spans security operations centre (SOC) operations, incident response, cybersecurity monitoring, vulnerability management, cyber threat intelligence, critical information infrastructure protection, secure software development, and cybersecurity policy and framework development. She has contributed to national and international cybersecurity initiatives and is committed to advancing practical, risk-based, and sustainable approaches to cybersecurity.
With experience in both technical operations and strategic cybersecurity development, Pratima works to bridge cybersecurity policy, governance, and implementation, translating complex technical risks into effective operational and institutional solutions.
The rapid advancement of AI, especially large language models, is reshaping cybersecurity with unprecedented offensive and defensive capabilities. Frontier models like Mythos have demonstrated superior vulnerability discovery and exploitation, compressing attack timelines from weeks to hours—cases include Gemini CLI building a C&C botnet in six minutes and GPT-5.6 Sol exhibiting excessive autonomy. Concurrently, AI empowers defense through tools such as GPT-Red and Project Glasswing, which use AI to proactively identify and patch vulnerabilities. China’s AI industry has also made major strides, with open-source models like Kimi K3 (2.8 trillion parameters) and Qwen3.8-Max, and DeepSeek-V4 achieving CUDA independence. These developments highlight the urgent need for global collaboration in governance, speed alignment, and autonomy control to harness AI’s benefits while mitigating its risks. Only through collective effort can we navigate this double-edged sword and secure our digital future.
Xiaodu YANG, female, Ph.D. in Computer Science, engineer at CNCERT/CC.
Jaehoon Kim (Financial Security Institute (FSI) , KR), Mohyun Park (Financial Security Institute (FSI), KR), Younghwan Kim (Financial Security Institute (FSI), KR)
For years, Korea's strict network separation and layered perimeter defenses have stood as the absolute benchmark for the safety of financial institutions' internal systems. Legally mandated network separation isolates internal systems from the internet, endpoint and boundary security products are deployed everywhere, and trusted management systems govern the isolated environment. Yet over the past few years, real incidents have repeatedly shown the opposite: the very controls trusted to keep attackers out have become the paths attackers ride in.
This talk examines the Paradox of Trust through recent breaches in Korea's financial sector.
Attackers rarely defeat these network-separation-based controls head-on. Instead they abuse the trust relationships those controls depend on. A trusted domestic security solution becomes a DPRK trojan horse; a trusted boundary VPN appliance becomes the entry point into a network-separated environment; and trusted management and connection systems become the bridge across segments meant to be isolated. What turns each of these components into a top-priority attack path is not a product defect but its trusted position itself.
Drawing on real 2025-2026 incident response (IR) data, we follow the attacker tradecraft (TTPs) behind these cases: how initial access rode trusted software and appliances, how lateral movement crossed separated segments through management infrastructure and tunneling, and the traces these operations left behind.
The conclusion is a defensive reframing. Trust relationships themselves become an attack surface. Trusted connection points inside a "protected" network, such as security software, boundary appliances, and management systems, must be assumed breached and inspected and monitored to the same standard as any internet-facing asset. Korea's network-separated financial sector is only the most extreme example; this paradox is a common threat facing every high-assurance, isolated network.
Network separation built a wall of trust, but that wall is now crumbling as the separation is deregulated and the environment shifts. The more it fades, the more the answer is no longer a wall but total visibility and zero trust: rigorously verifying every internal connection point, every external touchpoint, and the integrity of the traffic that crosses the boundary, and securing complete control over every flow that moves between networks.
Jaehoon Kim (Financial Security Institute (FSI) , KR)
Mohyun Park (Financial Security Institute (FSI), KR)
Younghwan Kim is a cybersecurity analyst at the Financial Security Institute (FSI) of Korea, where he works on threat intelligence, security operations, malware analysis, and incident response for the financial sector. He performs first-hand incident investigations, extracts IOCs and uncovers TTPs, and builds correlation-based analysis across incidents.
November 5, 2026 10:50-11:10
Karine Tobin (FIRST Member, AU)
Cyber Threat Intelligence teams are not short of information — they are short of time. Threat reporting, incident data, indicators, vulnerability intelligence and partner insights continue to grow, while analyst capacity remains limited. As a result, valuable intelligence often remains buried inside existing data, not because teams lack expertise, but because they lack the capacity to process, connect and operationalize it at scale. This presentation shares what my team and I are attempting to achieve as we introduce AI into CTI workflows to improve coverage, analysis, production and dissemination without increasing headcount. The session explores how Human-AI collaboration can help analysts work across larger datasets, identify relevant patterns, accelerate recurring intelligence tasks and create more room for higher-value activities. It also reflects on what we are learning along the way — including where AI helps, where it needs strong human oversight, and what must be in place to use it responsibly in operational intelligence environments. At the centre of the talk is the analyst as the editor-in-chief: AI can support research, summarization and analysis at a scale that was previously unrealistic, but humans remain responsible for deciding what matters, applying context, validating relevance and ensuring intelligence leads to action. The goal is not simply to produce more intelligence faster — it is to turn more of the intelligence already available to us into stronger defensive outcomes and a more resilient cyber defence posture.
Key takeaways • How AI can help CTI teams move from information overload to intelligence at scale. • How Human-AI collaboration can expand CTI capability and capacity without increasing headcount. • Why human judgement, context, validation and action remain central to trustworthy AI-assisted intelligence work. • What practical lessons emerge when AI is introduced into operational CTI workflows, including scale, trust and resilience considerations.
Karine Tobin is a Senior Cyber Threat Intelligence Analyst at Deloitte Global, supporting cyber intelligence activities that help protect Deloitte firms worldwide. Her work focuses on regional threat landscape analysis, campaign research, strategic intelligence reporting, forecasting, executive briefings and intelligence dissemination. Karine combines cyber threat intelligence experience with a background in marketing and communications across Australia and Europe, bringing a strong focus on clear, relevant and actionable intelligence products for both technical and leadership audiences. Her current interests include the practical use of AI to expand CTI capability and capacity, improve intelligence production and dissemination, support forecasting and analysis at scale, and help intelligence teams focus more time on the activities that drive defensive impact.
November 5, 2026 11:40-12:20
Hassan Khan Yusufzai (Laburity, PK)
This research explores how infostealer malware has become one of the earliest and most reliable access vectors for modern corporate breaches. Instead of targeting enterprise endpoints directly, attackers increasingly rely on data stolen from personal and unmanaged devices, then pivot into corporate environments using exposed credentials, cookies, and session tokens.
The study is based on the analysis of 100B+ billion stolen logs collected from Telegram channels, malware marketplaces, and leak forums. These logs were processed to extract and categorize credentials, browser artifacts, cookies, and authentication tokens, allowing deeper insight into how attackers identify high-value corporate targets.
Key areas of analysis include:
The research demonstrates how access to internal portals, cloud dashboards, CI/CD platforms, email systems, and collaboration tools is frequently present inside stealer logs. The talk also covers how logs are structured, indexed, and sold, making it easy for attackers to filter by domain, country, company name, or service type.
In addition to exposure analysis, the session covers how common infostealers such as Raccoon, Redline, and LummaC2 operate, including infection vectors, data collection methods, exfiltration workflows, and how defenders can detect early warning signs of compromise. Practical detection and monitoring strategies are discussed, with a focus on dark web and Telegram monitoring as an early breach-detection layer for organizations. This talk is intended for blue teams, SOC analysts, incident responders, and security leaders who want to understand what actually leaks, how attackers weaponize stolen data, and how to reduce organizational exposure before incidents escalate into full breaches.
Hassan Khan Yusufzai a Director and Co‑Founder of Laburity, bringing deep experience in the internet‑wide scanning, red teaming, penetration testing, threat intelligence and dark web monitoring. He combines deep technical research with practical, hands-on offensive security work to help organizations find and fix real-world security issues across different industries.
Hassan is an in‑demand speaker who shares his research and practical findings at international security conferences. He has presented at Cyber Security Asia 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗥𝗲𝘀𝗶𝗹𝗶𝗲𝗻𝗰𝗲 𝟮𝟬𝟮𝟲, DeepSec 2025, OWASP AppSecDays 2025, BlackHat MEA (Riyadh) in 2022, 2023 and 2025, ThreatCon 2023, MCTTP Munich Cyber Tactics, Techniques & Procedures (MCTTP) 2024, HITBSecConf 2024, and the Security Analyst Summit in Phuket in 2024.
Hassan holds the Offensive Security Certified Professional (OSCP) certification, reflecting his solid technical mastery of penetration testing and exploit development techniques.
Hassan has identified and reported over 200 CVEs to date and was recognized as one of the top hackers by WPScan for his contributions to WordPress security. His responsible vulnerability reporting has been widely recognized: in 2017 Hassan was listed in the Google Security Hall of Fame, the Twitter Security Hall of Fame, and the Microsoft Security Hall of Fame for contributions that improved the security of major platforms.
Hassan develops tools and techniques for at-scale security research and analysis, designed to handle large datasets. His work focuses on efficiency and scalability, enabling faster identification of vulnerabilities across massive environments.
November 5, 2026 09:00-09:40