To see our schedule with full functionality, like timezone conversion and personal scheduling, please enable JavaScript and go here.
09:30
09:30
30min
Welcome Speech
PA
10:00
10:00
25min
Don't let them break you: a CTF infrastructure whitepaper
Rok Štular

Most infrastructure is built to be used; CTF infrastructure is built to be abused. When your user base consists of hundreds of hackers armed with weaponized 1-days and a competitive drive to bypass your guardrails, "standard" scalability and security models fall apart.

Drawing from two years of organizing on-site jeopardy competitions for several hundred participants, this talk deconstructs the unique intersection of high-concurrency DevOps and aggressive hardening. We will explore the "war stories" of managing real-time exploits, mitigating flag-sharing, and maintaining a satisfactory user experience in this unique and challenging environment.

PA
10:30
10:30
25min
How do we effectively communicate about INFOSEC?
David Modic

What is our responsiblity to the public, when it comes to talking about INFOSEC. Do we need to dazzle people with our tech brilliance? Do we need to show them how cool and nerdy we are? Do we need to scare the bejesus out of them? Probably, none of the above. Join me in this informal session and we can talk about it :).

PA
11:00
11:00
30min
Coffee Break
PA
11:30
11:30
25min
From Beginner to Pro Hacker: Practical Approach to Offensive Security Training
Žan Urbančič, Danijela Šantak

This session addresses the gap between theoretical knowledge and practical offensive security skills by presenting a hands-on training methodology based on realistic lab environments. It focuses on core techniques such as enumeration, exploitation, and post-exploitation, emphasizing the ability to chain vulnerabilities into complete attack paths. Drawing from recent penetration testing experience, it highlights how legacy systems and misconfigurations continue to expose modern infrastructures to compromise.

PA
12:00
12:00
50min
Compliance of Electronic Products in the EU: From Electrical Safety and EMC to Cybersecurity under RED
Marko Jankovec

This lecture presents an overview of the key EU product directives governing electronic and electrical equipment: the Low Voltage Directive (2014/35/EU), the Electromagnetic Compatibility Directive (2014/30/EU), and the Radio Equipment Directive (2014/53/EU). It outlines their essential requirements, conformity assessment procedures, and the role of harmonised standards in achieving CE marking.
Special attention is given to cybersecurity obligations introduced under the Radio Equipment Directive through Delegated Regulation (EU) 2022/30. The lecture explains how cybersecurity, network protection, and personal data safeguards are now formal compliance requirements for connected and radio-enabled devices, and how these requirements impact design, risk assessment, technical documentation, and lifecycle management.
The session highlights the interaction between electrical safety, EMC, and cybersecurity within a unified compliance strategy for modern electronic products.

PA
13:00
13:00
90min
Lunch Break
PA
14:30
14:30
25min
Zero to RCE in a Weekend: Fuzzing Old Games for Memory Corruption
Rick de Jager

Mid-2000s videogames are a great target for finding RCE exploits. They were written in a different era, when things like ASLR and DEP were still seen as useless luxuries that just tank performance. Besides, who is gonna go through the effort to set up a fuzzer for these ancient games?

In this talk we'll pick a classic 2000's game, go over the process of fuzzing the game's server with a very fancy snapshot fuzzer, and fuzzing the client with the dumbest possible bit-flipper I could write in an hour. Both of these approaches lead to bugs that we'll exploit for remote code execution.

PA
15:00
15:00
25min
Unfaithful Claims: Breaking 6 zkVMs
Andraž Strgar

A Zero Knowledge Virtual Machine verifier should be faithful to one thing above all else: its public claims. That is, the proof of a statement should depend on the statement itself. As it turns out, this is not always the case, which can lead to disastrous consequences. In this talk, we will take a journey through six systems where we discovered critical vulnerabilities caused by such issues. Learn how a subtle ordering bug or a tiny omission can let an attacker bypass the cryptography entirely and prove mathematically impossible statements.

PA
15:30
15:30
25min
Anonymous Credentials for Next-Generation Rate Limiting: From Linear to Constant-Size Issuance
Lena Heimberger

Anonymous credentials are a critical building block for privacy-preserving systems, from EU digital wallets to privacy-respecting authentication schemes. At the IETF, however, they address efficient rate limiting in the presence of CAPTCHA-based human verification.
Current rate limiting systems use blind signatures or OPRFs to issue batches of rate-limiting tokens post-CAPTCHA. While cryptographically sound, this approach incurs communication complexity linear in the number of tokens issued, a significant bottleneck when handling large token batches.
The talk presents two proposals to reduce the token issuance to constant-size communication regardless of batch size, and shows how to combine them to get parallel, revocable tokens
The talk will cover the cryptographic foundations, discuss trade-offs between revocation expressiveness and issuance efficiency, and examine deployment challenges. We'll also explore an interesting secondary application: extending rate limiting to adaptive systems (LLMs, bots) that must solve CAPTCHAs, where the same credential mechanism enables fine-grained behavioral constraints beyond simple token budgets.

PA
16:00
16:00
30min
Coffee Break
PA
16:30
16:30
50min
When Correct Code leaks Secrets: Side Channels Explained
Hannes Weissteiner

In the real world, computer exploits are often simple: Logic bugs, forgotten bounds checks, or less-adept users typing their passwords into sketchy websites.
But what if we had a world full of flawless code, Rust-only programs, and completely security-aware end users?

Unfortunately, we still would not be secure.
Modern systems leak information in many ways, including performance optimizations or unavoidable limitations in hard- or software.
Execution time, memory access patterns, power usage, and other indirect effects can allow attackers to infer information and extract secrets, even from correctly implemented systems.

In this talk, we look at examples of different attacks exploiting behavior of the CPU architecture, microarchitecture, the Linux kernel code, and common applications that are running on your machine right now.
We will see that many side channels are caused by important performance optimizations, making them fundamentally difficult to eliminate.

This talk aims to demystify side channels and give an intuition on how they work, where they appear, and why even "correct" code is not necessarily secure.

PA
17:30
17:30
25min
How can one do security in a fully modular kernel?
Andraž Rotar

I mean, let's be real, a fully modular kernel? sounds awesome, you know what's not so awesome? Trying to think of a security architecture for it!

PA
18:00
18:00
25min
Capture the Flag in SOC
Peter Hutinski, Peter Pavkovič, Matic Šebjan Ogrizek

What does cybersecurity look like in practice? This lecture shows how Capture the Flag challenges build practical SOC skills, analytical thinking, and teamwork under pressure.

PA
18:30
18:30
30min
Ending speech
PA
09:30
09:30
30min
Intro to CTF
PA
10:00
10:00
420min
Jeopardy CTF
PA
17:00
17:00
30min
Intro to A/D CTF
PA
17:30
17:30
180min
A/D CTF
PA
20:30
20:30
30min
Awards Ceremony
PA