MCP servers can hold tokens, write files, make outbound requests and execute privileged automation. At THREATCON1, Pluto Security’s Gil Maman will show how flaws in popular implementations can enable SSRF, arbitrary file writes, account takeover and RCE: threatcon1.org/registration
39
Low-quality reports are overwhelming bug bounty programs. At THREATCON1, Josh Shomo will show how passive data can identify likely exposure without touching a target, and why authorization remains the line between inference and proof. Register: threatcon1.org/registration
60
A handful of suspicious IPs led to a live credential-harvesting operation. At THREATCON1, VulnCheck’s Adam Powis will show how Canary Intelligence and Target Intelligence traced attacker infrastructure from the first signal to the control plane: threatcon1.org/registration
2
85
More packages than we can count. More vulnerabilities than we can imagine. More malware than we want. At THREATCON1, Josh Bressers will break down the data behind open source’s biggest challenges, what is being done today and what may come next: threatcon1.org/registration
2
69
“The war room was a coffee mug.” In a CTF with 6,000+ teams, Rookery ran 36 agents on a laptop and solved 134 of 136 flags by the next morning. At THREATCON1, Cisco Talos’ Joel Callicrate will show how it thinks, where it breaks and what comes next: threatcon1.org/registration
3
152
Successful exploitation can become reusable operational knowledge. At THREATCON1, VulnCheck’s Guillermo Menjivar will show how internet canary telemetry becomes insights for detection engineering, threat hunting and incident response. Register: threatcon1.org/registration
1
1
93
Time-to-exploit is dropping to mere hours. Waiting for active exploitation can leave defenders too late. At THREATCON1, Adrian Sanabria will present a prioritization framework built from vulnerabilities confirmed to have caused damage or loss: threatcon1.org/registration
77
At THREATCON1, TrendAI’s Taha Siddiqi and Smile Thanapattheerakul will unpack how sandbox failures and flaws like command injection, path traversal and insecure deserialization affect widely used agentic AI platforms. Register: threatcon1.org/registration
64
No source code. No expert on staff. Just a binary and a deadline. At THREATCON1, Joe Szczerba will break down real-world reverse engineering and where AI-assisted tools save time, where they do not and where the work still depends on human analysis: threatcon1.org/registration
69
Coordinated disclosure was built for one bug at a time. That world is gone. At THREATCON1, Patrick Garrity, Tod Beardsley, Shelby Cunningham & @catc0n will get candid about deadlines, vendor silence, undisclosed patches and public PoCs. Join the panel: threatcon1.org/registration
1
1
114
Found ≠ fixed. Drawing on 15+ research campaigns and 300+ findings, John Rodriguez will examine where the discovery-to-remediation pipeline fails and what separates a technically correct vulnerability from a genuinely actionable one. Register: threatcon1.org/registration
2
77
Show your work. At THREATCON1, @FiniteStateInc's Doc McConnell will challenge the tax-audit approach to cybersecurity regulation and make the case for transparent regulatory engagement as a governance discipline. 📅 Oct. 6 Explore the lineup: threatcon1.org/registration
50
Every link scored like noise. Together, they were a breach. At THREATCON1, Steve Cobb will show how AI agents turned one foothold into admin access across production clusters in under 13 hours, and how defenders can cut exploit paths before patching: threatcon1.org/registration
1
94
Vulnerability scan data can tell threat hunters where to look first. At THREATCON1, Tim Roberts will show how ATT&CK mappings and exploitation evidence can reduce hundreds of hosts to a short, adversary-specific hunt list. 📅 Oct. 7 Register: threatcon1.org/registration
1
71
At THREATCON1, Tharros' Will Dormann will show how multiple Windows 11 vulnerabilities can be chained to let a non-admin user achieve SYSTEM privileges, all triggered by playing a MIDI music file. 📅 Oct. 6 Register: threatcon1.org/registration
1
83
Autonomous AI can contain threats at machine speed. How can enterprises govern agents that modify firewalls, isolate endpoints & query sensitive data? At THREATCON1, Raj Badhwar will share a blueprint for secure and auditable autonomous defenses: threatcon1.org/registration?…
69
Put your cybersecurity skills to the test at THREATCON1. @SkillBitLabs Jeopardy-style CTF will feature challenges across web exploitation, forensics, OSINT, binary exploitation and more. All skill levels are welcome. Compete solo or in a team. threatcon1.org/registration
1
194
When GitHub code claims to be an exploit, how can researchers tell what it does? At THREATCON1 2026, Jonathan Peterson will break down working code, broken PoCs, malware, AI noise and scams in public exploit repositories. Register: threatcon1.org/registration?…
1
146
THREATCON1 2026 is proud to welcome @DecipherSec as a Media Sponsor. Thank you for supporting the event and helping extend its conversations across the cybersecurity community. Join us Oct. 5-7 in Reston, Virginia. Register free: threatcon1.org/registration?…
2
2
304
Do vulnerability scores and threat intelligence actually influence what organizations fix? At THREATCON1 2026, Thomas MacKenzie will examine remediation behavior across 30,000+ IT environments and test whether CVSS, KEV and EPSS drive action. Register: threatcon1.org/registration?…
83