Talks Library

Explore past cybersecurity talks
from the Black Alps community

15 latest talks
Opening Words, Day 2
Opening words by Sylvain Pasini, president of the Black Alps association, and general chair of #BlackAlps26.
open EN 2026
Multi-taint Analysis for Constant-Time Verification: From False Positives to Confirmed Leaks
Side-channel timing attacks let an attacker recover secret keys and other sensitive data just by measuring how long a program takes to run, or by watching whic…
conf EN 2026 Damien Maier
[Student Talk] Cracking Open a DJI Drone: From Locked-Down Firmware to Playing With TEEs
Millions of consumer drones are in everyday use, capturing photos, mapping sites, and inspecting infrastructure, sold to anyone who wants one. Yet the same che…
conf EN 2026 Nicolae Binică
Memory Tagging Under Pressure: Hunting a TOCTOU in the iPhone 17 Kernel
MTE is increasingly relied upon as a hardening primitive in modern kernels, where tag generation and publication must remain correct under concurrent execution…
conf EN 2026 Kaya Ercihan
n8ive by Design – One Leaked Key. Multiple n8n Attack Chains
n8n is an open-source workflow automation platform with AI agent support, used by organizations worldwide to connect internal tools, automate pipelines, and or…
conf EN 2026 Guillaume Valadon
NotC2: Trusted by Default, Malicious by Design - AWS-Native Notifications as C2
NotC2 is a post-compromise command-and-control framework built entirely on native AWS services, including SQS, Lambda, and SNS, with Amazon Bedrock serving as …
conf EN 2026 Mark Vaitsman Or Soria
SEMSAN: Finding the 0-Days You Can't Crash Into
Traditional fuzzers and sanitizers catch memory corruption bugs, but what about those that never cause a crash? Path traversals, argument injections, and conta…
conf EN 2026 Moritz Sanft
Enterprise AI over-trust: Abusing M365 Copilot via Legacy Paths
We keep hearing that web security is mature and prompt injection is the new problem. Both are wrong, or at least incomplete in a way that gets people owned. …
conf EN 2026 Mark Vaitsman Dolev Taler
Not How Fast, But How Well: A Practitioner's PQC Migration
Quantum computers threaten the public-key cryptography we depend on (RSA, ECDSA, ECDH) and the conversation has hardened into a refrain: migrate now. This sess…
conf EN 2026 Sonia Duc
Reversense: closing the loop between instrumentation and representation in reverse engineering
In 2026, most of us still aren't exploring binaries through the Minority Report UX we were promised. The friction is structural, and three causes among many st…
conf EN 2026 Georges-Bastien Michel
Opening Words, Day 1
Opening words by Sylvain Pasini, president of the Black Alps association, and general chair of #BlackAlps26.
open EN 2026 Sylvain Pasini
LTECruiser: An Extremely Low Cost LTE Experimentation Framework
LTECruiser turns a 14€ LTE USB dongle into a firmware experimentation platform for cellular protocols and baseband security research. In this talk, we show how…
conf EN 2026 Edoardo Mantovani
Building Systems That Survive Attack: Lessons from Banknote Security
The persistent narrative of a cashless future suggests a world moving beyond physical currency. Yet the reality is different: cash is still growing, and remain…
keynote EN 2026 Ünige Laskay
Inside Linux GoGra Backdoor
GoGra is an interesting backdoor family which emerged in 2024, mostly targeting India and Afghanistan. This year, its developers released a Linux variant with …
conf EN 2026 Axelle Apvrille
When Cryptography Meets Reality: Insights from the Swiss Post E-Voting Protocol
How do cryptography and real-world constraints meet in an e-voting system? Electronic voting has been back in production in Switzerland since 2023. Starting fr…
conf EN 2026 Chiara Spadafora Audhild Høgåsen