Agenda
Explore the HITCON 2026 agenda and browse sessions, speakers, times, and room information.
Close
Opening
Re:CTF KoH 競賽活動
Out of LINE:QR Code to Wormable RCE in LINE Client
Flydragon
Content Isn't All You Need: Structural Naming Semantics AI for Real World Threat Detection At 99.99%
Jr-Wei Huang
Physical Cyber Authentication (PCA) and engineless PUF
Hiroshi Watanabe
Manipulating Childhood Memories: From Nostalgia to RCE in Minecraft Bedrock Server
ConsoleBreak
Break
A History of Errors: The Evolution of Windows Error Reporting Exploits
HeeChan Kim
Analyst-Guided LLM Agent for Analyzing Windows Authentication Logs
Shusei Tomonaga
When your surveillance system is watching you: breaking into GeoVision devices in the age of AI
Philippe Laulheret
Validated Then Rebound: Bypassing PAC and Proxy IP ACLs via DNS Answer Desynchronization
Rintaro Kawasugi
Lunch
Lunch
Re:CTF 競賽出題與解題分享
Game of Thrones: Dissecting Modern the Games A&D Technique
ShallowFeather, Zhao Min Chen
DEFCON CTF 經驗分享
The "Never Gave It Up" Harness: How AI Hacked a Payment Terminal and Turned It Into an Arcade
Chiao Lin Yu
Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto
Seongsu Park
Overkill: Hijacking a Firmware to Attack the Windows Kernel
Nicola Stauffer
Break
CTFs and Real-World Vulnerability Research: Common Ground and Key Differences
Break
當 AI 替學生打 CTF、替老師挖 0-day:一個高中資訊班的 agentic 資安實戰
Break
Born Corrupted: Dusk of Provenance
Tsi-Lin "Splitline" Ng
The Hunter Becomes the Hunted: Supply Chain Attacks Targeting Hackers
Jason Lu, Samuel Liu
One Path to Rule Them All: When CA Bypass Research Leads to Privilege Escalation
Echo Lee, Jun-Shun Shi
When Red Team Weaponized with More and More 0-day Vulnerabilities
Jacky Hsieh, Charles Yang
Break
CTF 資安人才培育綜合座談
Tea Time
Close
↖乂古法挖洞乂↘ ~~ 純邏輯 Microsoft Edge 零點擊沙箱逃逸鏈 ~~
Orange Tsai
公布競賽結果及頒獎
Break
Lightning Talk
Closing
Wrap-up
Attendee Check-In Time
09:00 - 10:00/R0
Close
09:00 - 10:10/R3
Opening
10:00 - 10:10/R0
Out of LINE:QR Code to Wormable RCE in LINE Client
Flydragon
10:10 - 10:50/R0
Content Isn't All You Need: Structural Naming Semantics AI for Real World Threat Detection At 99.99%
Jr-Wei Huang
10:10 - 10:50/R1
Physical Cyber Authentication (PCA) and engineless PUF
Hiroshi Watanabe
10:10 - 10:50/R2
Manipulating Childhood Memories: From Nostalgia to RCE in Minecraft Bedrock Server
ConsoleBreak
10:10 - 10:50/R3
Break
10:50 - 11:10/R0
A History of Errors: The Evolution of Windows Error Reporting Exploits
HeeChan Kim
11:10 - 11:50/R0
Analyst-Guided LLM Agent for Analyzing Windows Authentication Logs
Shusei Tomonaga
11:10 - 11:50/R1
When your surveillance system is watching you: breaking into GeoVision devices in the age of AI
Philippe Laulheret
11:10 - 11:50/R2
Validated Then Rebound: Bypassing PAC and Proxy IP ACLs via DNS Answer Desynchronization
Rintaro Kawasugi
11:10 - 11:50/R3
Lunch
11:50 - 12:50/R0
Lunch
11:50 - 12:30/R3
The "Never Gave It Up" Harness: How AI Hacked a Payment Terminal and Turned It Into an Arcade
Chiao Lin Yu
12:50 - 13:30/R0
Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto
Seongsu Park
12:50 - 13:30/R1
Overkill: Hijacking a Firmware to Attack the Windows Kernel
Nicola Stauffer
12:50 - 13:30/R2
Break
13:00 - 13:10/R4
Break
13:30 - 13:50/R0
Break
13:50 - 14:10/R3
Born Corrupted: Dusk of Provenance
Tsi-Lin "Splitline" Ng
13:50 - 14:30/R0
The Hunter Becomes the Hunted: Supply Chain Attacks Targeting Hackers
Jason Lu, Samuel Liu
13:50 - 14:30/R1
One Path to Rule Them All: When CA Bypass Research Leads to Privilege Escalation
Echo Lee, Jun-Shun Shi
13:50 - 14:30/R2
Tea Time
14:30 - 15:00/R0
Close
14:50 - 18:00/R3
Break
15:40 - 16:00/R0
Lightning Talk
16:00 - 16:30/R0
Closing
16:30 - 17:20/R0
Wrap-up
17:20 - 18:00/R0