Agenda

The HITCON 2026 session list is live. Time slots and room assignments will be updated after confirmation.

-- Keynote

Keynote

Vulnerability Disclosure in the Age of AI

James Forshaw

James Forshaw

-- All Sessions

Talk

A History of Errors: The Evolution of Windows Error Reporting Exploits

HeeChan Kim

HeeChan Kim
Talk

The "Never Gave It Up" Harness: How AI Hacked a Payment Terminal and Turned It Into an Arcade

Chiao Lin Yu

Chiao Lin Yu
Talk

[UnPwn2Own Berlin 2026 / $70,000] Agent2Shell: Pre-Prompt RCEs in Claude Code, Cursor, and Gemini

Satoki Tsuji, Sota Wada

Satoki TsujiSota Wada
Hacking 101

Game of Thrones: Dissecting Modern the Games A&D Technique

ShallowFeather, Zhao Min Chen

ShallowFeatherZhao Min Chen
Talk

Analyst-Guided LLM Agent for Analyzing Windows Authentication Logs

Shusei Tomonaga

Shusei Tomonaga
Talk

Before the Breach: Proactive Hunting in the Age of AI-Assisted Attacks

Joey Chen

Joey Chen
Talk

Validated Then Rebound: Bypassing PAC and Proxy IP ACLs via DNS Answer Desynchronization

Rintaro Kawasugi

Rintaro Kawasugi
Talk

Senrigan(千里眼) x Suzaku(朱雀): Open-Source, Community-Driven Threat Hunting for AWS on a Single Laptop

Fukusuke Takahashi, Akira Nishikawa

Fukusuke TakahashiAkira Nishikawa
Talk

Born Corrupted: Dusk of Provenance

Tsi-Lin "Splitline" Ng

Tsi-Lin "Splitline" Ng
Talk

Vulnerabilities Assembled! The Vulnerability Factory Inside the Windows Kernel

Angelboy

Angelboy
Talk

Physical Cyber Authentication (PCA) and engineless PUF

Hiroshi Watanabe

Hiroshi Watanabe
Talk

Keychained Melody

Jaron Bradley

Jaron Bradley
Talk

CTFusion: Catching AI Agents That Cheat at CTF and Streaming Live CTFs to Fix It

Dongjun Lee, Ga-eun Bae , Insu Yun

Dongjun LeeGa-eun Bae Insu Yun
Talk

Pwn2OwNothing: When a KVM Full-Chain Escapes to Emptiness

Bruce Chen, Peterpan0927, Weiming Shi, Jheng Bing Jhong

Bruce ChenPeterpan0927Weiming ShiJheng Bing Jhong
Talk

↖乂古法挖洞乂↘ ~~ 純邏輯 Microsoft Edge 零點擊沙箱逃逸鏈 ~~

Orange Tsai

Orange Tsai
Talk

Manipulating Childhood Memories: From Nostalgia to RCE in Minecraft Bedrock Server

ConsoleBreak

ConsoleBreak
Talk

One Path to Rule Them All: When CA Bypass Research Leads to Privilege Escalation

Echo Lee, Jun-Shun Shi

Echo LeeJun-Shun Shi
Talk

When your surveillance system is watching you: breaking into GeoVision devices in the age of AI

Philippe Laulheret

Philippe Laulheret
Talk

Endpoint Audit Agent: Scaling AppSec with AI at Dropbox

Po-Ning Tseng

Po-Ning Tseng
Talk

Out of LINE:QR Code to Wormable RCE in LINE Client

Flydragon

Flydragon