Agenda

Explore the HITCON 2026 agenda and browse sessions, speakers, times, and room information.

09:00

Attendee Check-In Time

09:00 - 10:00/R0

10:00

Opening

10:00 - 11:10/R0

11:10

Break

11:10 - 11:20/R0

11:20
Keynote
English

Vulnerability Disclosure in the Age of AI

James Forshaw

James Forshaw

11:20 - 12:00/R0

Hacking 101
Chinese

Look Ma, No Hands! Constructing Autonomous AI Offensive Agents Using MCP and HexStrike-AI

Jie Liau

Jie Liau

11:20 - 12:40/R3

12:00

Lunch

12:00 - 13:00/R0

12:40
13:00
Japanese

[UnPwn2Own Berlin 2026 / $70,000] Agent2Shell: Pre-Prompt RCEs in Claude Code, Cursor, and Gemini

Satoki TsujiSota Wada

Satoki Tsuji, Sota Wada

13:00 - 13:40/R0

English

Senrigan(千里眼) x Suzaku(朱雀): Open-Source, Community-Driven Threat Hunting for AWS on a Single Laptop

Fukusuke TakahashiAkira Nishikawa

Fukusuke Takahashi, Akira Nishikawa

13:00 - 13:40/R1

TBD

TBD

TBD

13:00 - 13:40/R2

13:20
Hacking 101
English

Your First Agentic SOC Without the GPU Bill: Local LLM Triage on Apple Silicon

Tommy WongKe Li Yam

Tommy Wong, Ke Li Yam

13:20 - 14:40/R3

13:40

Break

13:40 - 14:00/R0

14:00
Chinese

Endpoint Audit Agent: Scaling AppSec with AI at Dropbox

Po-Ning Tseng

Po-Ning Tseng

14:00 - 14:40/R0

Chinese

Pwn2OwNothing: When a KVM Full-Chain Escapes to Emptiness

Bruce ChenPeterpan0927Weiming ShiJheng Bing Jhong

Bruce Chen, Peterpan0927, Weiming Shi, Jheng Bing Jhong

14:00 - 14:40/R1

TBD

TBD

TBD

14:00 - 14:40/R2

14:40

Tea Time

14:40 - 15:10/R0

15:10
Chinese

Before the Breach: Proactive Hunting in the Age of AI-Assisted Attacks

Joey Chen

Joey Chen

15:10 - 15:50/R0

Chinese

Vulnerabilities Assembled! The Vulnerability Factory Inside the Windows Kernel

Angelboy

Angelboy

15:10 - 15:50/R1

TBD

TBD

TBD

15:10 - 15:50/R2

Hacking 101
English

Hands-on IoT firmware extraction and forensics workshop

Dennis GieseArnold Wey

Dennis Giese, Arnold Wey

15:10 - 16:30/R3

15:50

Break

15:50 - 16:10/R0

16:10
English

CTFusion: Catching AI Agents That Cheat at CTF and Streaming Live CTFs to Fix It

Dongjun LeeGa-eun Bae Insu Yun

Dongjun Lee, Ga-eun Bae , Insu Yun

16:10 - 16:50/R0

English

Keychained Melody

Jaron Bradley

Jaron Bradley

16:10 - 16:50/R1

English

TBD

TBD

TBD

16:10 - 16:50/R2

16:30
16:50

Break

16:50 - 17:10/R0

17:10
Chinese

1% of tokens, All of the Strategy: LLM-Assisted Vulnerability Discovery in IoT/Embedded systems

Ta-Lun Yen

Ta-Lun Yen

17:10 - 17:50/R0

English

Harmonizing AI Agents and Human Analysts in CTI - Are CTI Agents Friends or Rivals to Junior Analyst

Takahiro Kakumaru

Takahiro Kakumaru

17:10 - 17:50/R1

Chinese🎃

Modern Android Kernel Exploitation Through a Mali Driver Vulnerability

Pumpkin Chang

Pumpkin Chang

17:10 - 17:50/R2

17:50

Wrap-up

17:50 - 18:00/R0

18:00

Hacker Dinner

18:00 - 20:30/R4

20:30