Agenda
Explore the HITCON 2026 agenda and browse sessions, speakers, times, and room information.
Opening
Break
Vulnerability Disclosure in the Age of AI
James Forshaw
Look Ma, No Hands! Constructing Autonomous AI Offensive Agents Using MCP and HexStrike-AI
Jie Liau
Lunch
[UnPwn2Own Berlin 2026 / $70,000] Agent2Shell: Pre-Prompt RCEs in Claude Code, Cursor, and Gemini
Satoki Tsuji, Sota Wada
Senrigan(千里眼) x Suzaku(朱雀): Open-Source, Community-Driven Threat Hunting for AWS on a Single Laptop
Fukusuke Takahashi, Akira Nishikawa
TBD
TBD
Your First Agentic SOC Without the GPU Bill: Local LLM Triage on Apple Silicon
Tommy Wong, Ke Li Yam
Break
Endpoint Audit Agent: Scaling AppSec with AI at Dropbox
Po-Ning Tseng
Pwn2OwNothing: When a KVM Full-Chain Escapes to Emptiness
Bruce Chen, Peterpan0927, Weiming Shi, Jheng Bing Jhong
TBD
TBD
Tea Time
Before the Breach: Proactive Hunting in the Age of AI-Assisted Attacks
Joey Chen
Vulnerabilities Assembled! The Vulnerability Factory Inside the Windows Kernel
Angelboy
TBD
TBD
Hands-on IoT firmware extraction and forensics workshop
Dennis Giese, Arnold Wey
Break
CTFusion: Catching AI Agents That Cheat at CTF and Streaming Live CTFs to Fix It
Dongjun Lee, Ga-eun Bae , Insu Yun
Keychained Melody
Jaron Bradley
TBD
TBD
Break
1% of tokens, All of the Strategy: LLM-Assisted Vulnerability Discovery in IoT/Embedded systems
Ta-Lun Yen
Harmonizing AI Agents and Human Analysts in CTI - Are CTI Agents Friends or Rivals to Junior Analyst
Takahiro Kakumaru
Modern Android Kernel Exploitation Through a Mali Driver Vulnerability
Pumpkin Chang
Wrap-up
Hacker Dinner
Attendee Check-In Time
09:00 - 10:00/R0
Opening
10:00 - 11:10/R0
Break
11:10 - 11:20/R0
Lunch
12:00 - 13:00/R0
[UnPwn2Own Berlin 2026 / $70,000] Agent2Shell: Pre-Prompt RCEs in Claude Code, Cursor, and Gemini
Satoki Tsuji, Sota Wada
13:00 - 13:40/R0
Senrigan(千里眼) x Suzaku(朱雀): Open-Source, Community-Driven Threat Hunting for AWS on a Single Laptop
Fukusuke Takahashi, Akira Nishikawa
13:00 - 13:40/R1
TBD
TBD
13:00 - 13:40/R2
Break
13:40 - 14:00/R0
Tea Time
14:40 - 15:10/R0
Before the Breach: Proactive Hunting in the Age of AI-Assisted Attacks
Joey Chen
15:10 - 15:50/R0
Vulnerabilities Assembled! The Vulnerability Factory Inside the Windows Kernel
Angelboy
15:10 - 15:50/R1
TBD
TBD
15:10 - 15:50/R2
Hands-on IoT firmware extraction and forensics workshop
Dennis Giese, Arnold Wey
15:10 - 16:30/R3
Break
15:50 - 16:10/R0
Break
16:50 - 17:10/R0
1% of tokens, All of the Strategy: LLM-Assisted Vulnerability Discovery in IoT/Embedded systems
Ta-Lun Yen
17:10 - 17:50/R0
Harmonizing AI Agents and Human Analysts in CTI - Are CTI Agents Friends or Rivals to Junior Analyst
Takahiro Kakumaru
17:10 - 17:50/R1
Modern Android Kernel Exploitation Through a Mali Driver Vulnerability
Pumpkin Chang
17:10 - 17:50/R2
Wrap-up
17:50 - 18:00/R0
Hacker Dinner
18:00 - 20:30/R4