BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.romhack.io//romhack-camp-2026
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-7DJ87Y@cfp.romhack.io
DTSTART;TZID=CET:20261002T103000
DTEND;TZID=CET:20261002T110000
DESCRIPTION:**Welcome to the second edition of RomHack Camp!** \nWe are thr
 illed to gather the community back at the Flaminio Village in Rome for thr
 ee intensive days of hacking\, sharing\, and networking.  \n\nIn this open
 ing session\, the Cyber Saiyan team will set the stage for the weekend ahe
 ad. \nWe will walk you through the **camp layout**\, introduce this year's
  **Community Villages**\, and share **essential logistical details** to he
 lp you navigate the venue.  We will also preview the upcoming highlights o
 f the weekend.\n\nGrab a seat as we kick off RomHack Camp 2026\, celebrate
  our community\, and officially start an unforgettable weekend of collabor
 ative learning. \n\nLet the hacking begin!
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:RomHack Camp Opening - Cyber Saiyan
URL:https://cfp.romhack.io/romhack-camp-2026/talk/7DJ87Y/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-CTWEV9@cfp.romhack.io
DTSTART;TZID=CET:20261002T110000
DTEND;TZID=CET:20261002T114000
DESCRIPTION:Come un attacco informatico rovina la tua vita\, quelle dei tuo
 i cari e dei tuoi dipendenti.\n\nRacconteremo di una risposta ad un incide
 nte informatico particolare.\nLa gang ransomware è passata dall'azienda I
 .T. che gestiva la struttura informatica dei sui clienti.\nLa gang si è p
 ropagata prima sull'infrastruttura del system integrator\, per poi infetta
 re le aziende più grandi del loro parco clienti\, infine ha fatto quello 
 che sapeva fare meglio...\n\nQuando non ci sono più strade\, si è ad un 
 bivio ove bisogna scegliere per forza se chiudere l'attività o pagare il 
 riscatto. Questa scelta ti toglie il sonno...\n\nAnche piegandosi ai ricat
 ti del crimine\, non sempre va tutto bene\, perchè a volte i decryptor no
 n funzionano....\n\nButteremo uno sguardo alla pseudo struttura di questa 
 gang criminale\, alla loro efficienza\, nonché al loro modus operandi.\n\
 nIn questo talk non vengono tralasciate le implicazioni legali\, morali ed
  emotive che coinvolgono le persone interessate\, le loro dinamiche famigl
 iari ed i dipendenti.\n\nA questo talk non è stato dato un taglio tecnico
  come di consueto\, ma si vuole raccontare una storia di vita reale\, che 
 può capitare a chiunque e che sempre più spesso sentiamo ai T.G.\, leggi
 amo sui giornali\, ma non pensiamo possa toccare a noi. Vogliamo avvicinar
 ci a quei C.E.O.\, C.T.O.\, A.D.\, consigli direttivi\, ed imprenditori di
  qual si voglia natura e grandezza che a volte pensano\, "figurati se succ
 ede a noi"\, "non abbiamo nulla di valore"\, "ma noi siamo protetti".
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Incontro con la gang ransomware Schrodingercat. - Davide Baraldi\, 
 Chiara Ciccia Romito
URL:https://cfp.romhack.io/romhack-camp-2026/talk/CTWEV9/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-RLARMV@cfp.romhack.io
DTSTART;TZID=CET:20261002T110000
DTEND;TZID=CET:20261002T114000
DESCRIPTION:Standard OIDC bearer tokens are deceptively simple and highly a
 ttractive to developers\, but they hide a structurally weak security postu
 re: anyone who holds them can spend them. Following up on [our previous de
 ep dive](https://www.youtube.com/watch?v=ehSkbR-YuZw) @MOCA24 into securin
 g OIDC code exchanges\, this presentation is a hands-on\, exploit-driven e
 xploration of token-usage security.\nWe will begin by demonstrating how ea
 sily standard bearer tokens are stolen and replayed remotely from an attac
 ker's terminal. We will then look "beyond the basics" to live-demo a harde
 ned implementation of [RFC 9449](https://datatracker.ietf.org/doc/html/rfc
 9449) (DPoP) using a Keycloak identity provider and an Express.js resource
  server.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Stupid Sexy Bearer Tokens: a deep dive into exploding OIDC sessions
  and hardening with DPoP - jiraky\, reymerk\, Giuseppe\, toctou\, Stefano 
 Maistri
URL:https://cfp.romhack.io/romhack-camp-2026/talk/RLARMV/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-KEJWJK@cfp.romhack.io
DTSTART;TZID=CET:20261002T110000
DTEND;TZID=CET:20261002T130000
DESCRIPTION:Self-Sovereign Identity promises a different way of proving who
  we are online: instead of relying on a central identity provider\, users 
 can hold verifiable credentials and decide what information to disclose.\n
 But how much information do we really need to reveal to prove something ab
 out ourselves?\nIn many digital interactions\, a verifier does not need to
  know our full identity. It may only need to know whether we are over 18\,
  authorised to access a service\, hold a valid qualification\, or possess 
 a non-revoked credential.\nThis talk explores how selective disclosure\, Z
 ero-Knowledge Proofs and cryptographic accumulators can support a shift fr
 om identity disclosure to proof-based verification. Instead of transferrin
 g personal data and protecting it afterwards\, users can prove that a requ
 irement is satisfied without revealing the underlying information.\nUsing 
 scenarios inspired by the TRUSTED project\, we discuss data minimisation\,
  unlinkability\, credential validity and revocation. We also look beyond c
 ryptography itself: even privacy-preserving credentials can still enable c
 orrelation\, metadata leakage or unnecessary identification if the wider i
 dentity flow is poorly designed.\nThe key question is therefore not only 
 “Can I prove who I am?”\, but “Can I prove what you need to know wit
 hout telling you who I am?”
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:Prove It Without Telling Me Who You Are - Carmela Occhipinti e Marc
 o Pratesi\, Marco Pratesi
URL:https://cfp.romhack.io/romhack-camp-2026/talk/KEJWJK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-TGTBKG-0@cfp.romhack.io
DTSTART;TZID=CET:20261002T110000
DTEND;TZID=CET:20261002T130000
DESCRIPTION:**Bullismo No Grazie** è un'associazione no profit nata nel 20
 21 che ha incontrato oltre 200.000 ragazzi e 90.000 adulti in più di 100 
 città italiane\, percorrendo oltre 150.000 km di scuole\, palestre e vill
 aggi turistici.\n\nIn questo workshop portiamo la realtà che vediamo ogni
  giorno: le challenge pericolose che circolano tra bambini di IV e V eleme
 ntare\, i social network che i ragazzi usano e che i genitori non conoscon
 o\, le responsabilità civili e penali che ricadono sulle famiglie quando 
 un minore commette atti di cyberbullismo.\n\nNiente teoria. Solo casi real
 i\, domande vere\, strumenti pratici per riconoscere i segnali e sapere co
 sa fare.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:Il bullismo non va in vacanza - Bullismo No Grazie
URL:https://cfp.romhack.io/romhack-camp-2026/talk/TGTBKG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-KLSNYA@cfp.romhack.io
DTSTART;TZID=CET:20261002T120000
DTEND;TZID=CET:20261002T124000
DESCRIPTION:Modern red team operations rarely play out in friendly territor
 y. The days of wide-open egress are fading\, replaced by environments wher
 e defenders tighten every screw. Outbound traffic is inspected\, filtered\
 , and often blocked entirely. A shell on a public-facing server might feel
  like a win\, but in many cases\, it comes with no DNS\, no HTTP\, and no 
 callbacks at all. In these conditions\, the familiar C2 playbook runs out 
 of pages\, and operators are forced to adapt or stall.\n\nIn this session\
 , we will flip the C2 model on its head. You will see how to turn "dead-en
 d" footholds into fully functional command channels without a single outbo
 und packet\, blending covert tasking into legitimate inbound web traffic. 
 We will break down the design choices\, the stealth advantages\, and the p
 itfalls you will want to avoid\, then share tooling to make it work with y
 our own implants and frameworks.\nIf you have ever been stuck behind a wal
 l of egress controls\, you will walk away with a new blueprint and a few t
 ricks to make the unreachable reachable.\n\nWhy This Matters\n\nThis is or
 iginal\, never-before-published research that redefines how C2s can functi
 on under extreme network restrictions.\nThe technique has been tested in r
 eal red teams\, proving both its stealth and reliability in complex enviro
 nments.\nWe’re genuinely enthusiastic about sharing this research with t
 he community. Not just as a technical talk and tooling\, but as a fresh pe
 rspective on adversary resilience in a post-egress world.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Command and Collusion: Flipping the C2 Model for No-Egress Environm
 ents - Hatem Mohamed\, Moataz Moustafa
URL:https://cfp.romhack.io/romhack-camp-2026/talk/KLSNYA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-EXYNT7@cfp.romhack.io
DTSTART;TZID=CET:20261002T120000
DTEND;TZID=CET:20261002T122000
DESCRIPTION:This talk introduces the audience to the realm of macOS malware
  development. As Macs are increasingly adopted by companies\, they are bei
 ng targeted more frequently in malware campaigns. Similarly\, in red team 
 engagements\, operators are encountering Macs more often\, making the deve
 lopment of malware and TTPs for this platform crucial.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:macOS Malware Development: An Introduction - [kuom]
URL:https://cfp.romhack.io/romhack-camp-2026/talk/EXYNT7/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-KSYBBR@cfp.romhack.io
DTSTART;TZID=CET:20261002T140000
DTEND;TZID=CET:20261002T150000
DESCRIPTION:Durante questo workshop imparerete a costruire braccialetti con
  perline e charms vari. Tutto l'occorrente sarà fornito dal trainer\, l'u
 nica cosa da portare è forza di volontà e un bel sorriso!\n\nNota: il wo
 rkshop è aperto anche ai più grandi e non ci sono barriere linguistiche.
  **English speakers are welcome!**
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:Braccialetti DIY - Lucrezia
URL:https://cfp.romhack.io/romhack-camp-2026/talk/KSYBBR/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-NNMA7U@cfp.romhack.io
DTSTART;TZID=CET:20261002T143000
DTEND;TZID=CET:20261002T151000
DESCRIPTION:The Year 2038 problem is often framed as a technical limitation
  of legacy systems\, but its real impact extends far beyond code. At 03:14
 :07 UTC on January 19\, 2038\, systems relying on signed 32-bit Unix time 
 will overflow\, potentially misinterpreting dates and disrupting critical 
 services. While some engineers have long been aware of this boundary\, its
  broader societal implications remain largely overlooked.\n\nThis talk exp
 lores Y2038 as a systemic risk embedded in the infrastructure of modern so
 ciety. From healthcare devices and industrial control systems to financial
  records and identity management\, many long-lived systems still depend—
 directly or indirectly—on fragile time representations. Unlike typical v
 ulnerabilities\, this issue is not confined to a single product or vendor:
  it is distributed\, silent\, and deeply woven into global digital ecosyst
 ems.\n\nWhat happens when time itself becomes unreliable in systems we dep
 end on for safety\, trust\, and accountability?\n\nRather than focusing on
  exploitation\, this talk reframes Y2038 as a challenge of governance\, re
 silience\, and accountability. It highlights how technical debt\, supply c
 hain opacity\, and the longevity of embedded systems turn a known limitati
 on into a slow-moving\, systemic risk—and why addressing it requires coo
 rdination beyond the security community.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:2038: The Next Epochalypse — Breaking time before it breaks us - 
 Lorenzo Dina (joecondo)
URL:https://cfp.romhack.io/romhack-camp-2026/talk/NNMA7U/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-AGFMRW@cfp.romhack.io
DTSTART;TZID=CET:20261002T143000
DTEND;TZID=CET:20261002T151000
DESCRIPTION:As EDR products continue to improve their ability to detect mal
 icious behavior\, malware developers are increasingly adding layers of com
 plexity in an attempt to evade detection.\n\nOne of the most challenging o
 perations to perform under the radar remains code injection. This seemingl
 y unavoidable step is associated with numerous indicators of compromise\, 
 ranging from well-known Windows API calls to uncommon memory permissions o
 r suspicious execution flows.\n\nTo address this challenge\, we revisit th
 e decade-old technique of *code caves*: unused memory locations within leg
 itimate binaries that can be repurposed to host and execute malicious code
 . By extending the concept to include *dead code* and embracing position-i
 ndependent payload development we show that it is not only possible to go 
 beyond classic code cave limitations\, but also eliminate the need for cod
 e injection altogether.\n\nThrough practical demonstrations\, we will show
  how it is possible to automate the discovery and weaponization of dead co
 de in legitimate binaries. This proof of concept advocates a renewed philo
 sophy of malware development\, emphasizing simplicity and minimalism rathe
 r than increasingly complex evasion chains.\n\nFinally\, we discuss import
 ant defensive implications of this work : if attackers can increasingly av
 oid traditional injection artifacts\, detection strategies should focus le
 ss on how code reached execution and more on what that code ultimately doe
 s.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Stop Injecting\, Start Blending: A KISS Approach to Malware Develop
 ment - Julien Bedel
URL:https://cfp.romhack.io/romhack-camp-2026/talk/AGFMRW/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-L9ZERS@cfp.romhack.io
DTSTART;TZID=CET:20261002T150000
DTEND;TZID=CET:20261002T170000
DESCRIPTION:Modern software delivery runs on CI/CD pipelines and attackers 
 know it. From the SolarWinds Orion backdoor to the Codecov Bash Uploader c
 ompromise and the countless exposed Jenkins instances found on Shodan\, bu
 ild systems have become one of the most valuable and least monitored targe
 ts in the software supply chain. A single misconfigured runner\, an overpr
 ivileged token\, or a poisoned dependency can silently compromise everythi
 ng downstream\; and the rise of AI-based attacking agents\, capable of aut
 onomously discovering and chaining misconfigurations at scale\, is only ra
 ising the stakes.\n\nThis workshop is a practical introduction to CI/CD se
 curity through the lens of the OWASP Top 10 CI/CD Security Risks. We'll wa
 lk through each risk category (insufficient flow control\, poisoned pipeli
 ne execution\, dependency chain abuse\, exposed secrets\, insecure system 
 configuration\, and more) grounding each one in real-world incidents that 
 made these risks tangible rather than theoretical.\n\nAfter the theory\, a
 ttendees get their hands dirty with a set of self-contained challenges bui
 lt on the CICD Goat vulnerable-by-design environment\, hunting for and exp
 loiting common pipeline misconfigurations and attack chains\, followed by 
 a guided walkthrough of each solution.\n\nPrerequisites: basic web/Linux e
 xploitation knowledge\, familiarity with git\, and a laptop with Docker an
 d a git client installed.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:Pwn the Pipeline: A Hands-On Tour of CI/CD Security Risks - m3ssap0
 \, Mattia Brollo\, Fleeenz\, IadRabbit
URL:https://cfp.romhack.io/romhack-camp-2026/talk/L9ZERS/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-9VWFFW@cfp.romhack.io
DTSTART;TZID=CET:20261002T150000
DTEND;TZID=CET:20261002T180000
DESCRIPTION:Brain Arena – Allenare la mente attraverso sfide\, robotica e
  problem solving\n\nBrain Arena è un laboratorio esperienziale in cui bam
 bini e ragazzi entrano in una vera arena delle competenze: non una lezione
  tradizionale di coding\, ma una sequenza di missioni da affrontare attrav
 erso logica\, strategia\, creatività e collaborazione.\n\nDurante le due 
 ore i partecipanti\, organizzati in piccoli team\, dovranno osservare un p
 roblema\, immaginare una soluzione\, programmarla e metterla subito alla p
 rova utilizzando robot educativi e speciali tappeti di gioco. Ogni sfida r
 ichiede di prendere decisioni\, correggere gli errori\, migliorare la prop
 ria strategia e confrontarsi con gli altri.\n\nL’obiettivo non è sempli
 cemente “far muovere un robot”\, ma allenare competenze fondamentali c
 ome problem solving\, pensiero computazionale\, capacità di analisi\, col
 laborazione e gestione dell’errore.\n\nRome Hack sarà la prima presenta
 zione pubblica di Brain Arena\, un nuovo format educativo Italmaker che tr
 asforma l’apprendimento STEM in un’esperienza dinamica\, coinvolgente 
 e competitiva\, dove imparare significa soprattutto mettersi alla prova.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:Brain Arena - Italmaker
URL:https://cfp.romhack.io/romhack-camp-2026/talk/9VWFFW/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-GHQJFC@cfp.romhack.io
DTSTART;TZID=CET:20261002T151000
DTEND;TZID=CET:20261002T153000
DESCRIPTION:MXMap Italia has been established as national observatory of th
 e status of digital Sovereignty of italian public agencies\, by analyzing 
 DNS records on the basis of the MXMap software. \n\nThe technical platform
  provides opendata\, mapping and analytics of the 23k+ public agencies on 
 https://mxmap.it .\n\nThe alarming results\, with more than 46% of italian
  government agencies accessible trough Cloud Act by USA Security Agencies\
 , requires all the institutional\, technical\, activist world to act now!\
 n\nThe political platform https://osservatorio.mxmap.it aim to provides aw
 areness across all the stakeholders\, with policy and technical papers\, b
 rief for decision makers\, and periodic massive emailing campaign to infor
 m the key persons at each agency (DPO\, but also RTD\, owner of digital tr
 ansformation).\n\nThis walk want to share the project results\, methodolog
 y and a call to action to contribute to the project goals\, improving the 
 status of digital sovereignty with self-hosted infrastructure and free sof
 tware.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:MXMap Italia: National Observatory for Digital Sovereignty - Fabio 
 Pietrosanti (naif)
URL:https://cfp.romhack.io/romhack-camp-2026/talk/GHQJFC/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-SSVQRR@cfp.romhack.io
DTSTART;TZID=CET:20261002T152000
DTEND;TZID=CET:20261002T160000
DESCRIPTION:i am working in software development in critical infrastructure
 . \n\nThere are several different ways of vulnerability scanning and vulne
 rability management and i'd like to give an overview on that. \n\nThis tal
 ks therefore covers the different opportunities of vulnerability scanning 
 and their different anchor points. \nFurthermore i will talk on how to int
 egrate that into a vulnerability management tool and how to build processe
 s around it to achieve that vulns actually get fixed.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:automated vulnerability scanning in software development - mc.fly
URL:https://cfp.romhack.io/romhack-camp-2026/talk/SSVQRR/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-BNCWHH@cfp.romhack.io
DTSTART;TZID=CET:20261002T153000
DTEND;TZID=CET:20261002T161000
DESCRIPTION:As Joni Mitchell famously sang “Don't it always seem to go\, 
 that you don't know what you've got till it's gone.”\n\nLike how an enve
 lope generator in electronic music shapes a sound's character over time\, 
 this talk is concerned with the shape and characteristics of cybersecurity
  and is all about what music teaches us about attacks\, timing\, and resil
 ience.\n\nMusic and cybersecurity share the same basic anatomy since they 
 are about identity and community. Both require a trigger to set off a seri
 es of events and can be creative or destructive.\n\nOver the years\, music
  has been used to spread misinformation. Music has also been a method to c
 ontrol and torture people. For example\, the use of acoustic bombardment t
 o bring down the Noriega regime in Panama.\n\nMusic can be a destructive f
 orce. Janet Jackson’s Rhythm Nation video caused hard drives to crash an
 d was classified with its own CVE.\n\nConversely in times of oppression\, 
 music has been used as a form of communication to bypass censorship.\n\nIn
  this talk\, I will explore how ransomware and identity-driven attacks eva
 de detection not by being invisible\, but by being indistinguishable from 
 normal operational noise.\n\nModern attacks don’t break systems\, they b
 lend into them.\n\nUsing the structure of music production (signal/noise\,
  mixing and mastering) to explore real-world attack chains\, the goal is t
 o share practical insights into why detection fails.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Last Night a DJ Erased My Drive - Mathew Caplan
URL:https://cfp.romhack.io/romhack-camp-2026/talk/BNCWHH/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-XJTACK@cfp.romhack.io
DTSTART;TZID=CET:20261002T161000
DTEND;TZID=CET:20261002T165000
DESCRIPTION:Building private payments is a fascinating technical challenge.
  Somehow\, we have to hide some combination of three things: who is paying
 \, who is being paid\, and how much. All without letting anyone print infi
 nite money. This talk is about the cryptographic machinery and approaches 
 people have come up with to make private payments possible and practical t
 oday. We focus on two projects\, Monero and Zcash\, which are among the mo
 st mature and influential systems.\n\nIn the talk we will start from a few
  simple cryptographic primitives: additively homomorphic commitments\, rin
 g signatures\, stealth addresses\, and zero-knowledge proofs. Then we diss
 ect how transactions work in both Monero and Zcash\, highlighting differen
 ces and similarities.\n\nWe close with a short\, uncomfortable observation
 : when a system hides payments well\, a forged proof is indistinguishable 
 from an honest one\, leaving us always just one proof away from trouble.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Just one proof away: the cryptography behind private payments - Gio
 rgio Dell'Immagine
URL:https://cfp.romhack.io/romhack-camp-2026/talk/XJTACK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-8EHEDT@cfp.romhack.io
DTSTART;TZID=CET:20261002T161000
DTEND;TZID=CET:20261002T165000
DESCRIPTION:In this talk I'll share my experience over the last few years\,
  since I decided to set up my own vegetable garden and start growing produ
 ce for my family.\n\nI'll walk you through the challenges I faced: no wate
 r source available for irrigation\, and the need to make the garden as sel
 f-sufficient as possible (scheduled irrigation\, weed control\, keeping ma
 nual work to a minimum).\n\nThere's still some "nerdy" stuff left to do: m
 onitoring the pump\, the water level and the power supply\, so I get alert
 ed when something goes wrong instead of finding out once the plants have a
 lready dried out :)\n\nI'll tell you about the mistakes and wrong choices 
 I made out of sheer inexperience as a grower\, but also about the satisfac
 tion of harvesting what you've sown.\n\nThis is the same talk I'm presenti
 ng at [ESC]([url](https://endsummer.camp/)) (End Summer Camp)\, enriched h
 ere with ideas and discussions that came out of ESC.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Growing a (nearly) self-sufficient vegetable garden - merlos
URL:https://cfp.romhack.io/romhack-camp-2026/talk/8EHEDT/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-7RZJGK@cfp.romhack.io
DTSTART;TZID=CET:20261002T165000
DTEND;TZID=CET:20261002T173000
DESCRIPTION:In the run up to Google’s plans to dump 3rd party cookies\, m
 arketing firms (a $1.7 TRILLION dollar industry) were sent into a complete
  panic. These firms relied heavily on 3rd party cookies in order to better
  attribute CPM (cost per 1000 clicks) and how many of those clicks turned 
 into sales. So advertisers could better study human behavior and trends in
  order to more effectively sell products. \n\nAs a former Security Enginee
 r at the Largest Independent Digital Marketing firm in the world\, I had a
  unique view into the evils that these companies were developing in order 
 to not only maintain a view into consumer trends but to increase these vie
 ws\, increase the invasiveness of these techniques\, and increase the coop
 eration between all levels of the industry from display point (streaming s
 ervice)\, device point (iPhone\, TV)\, location points (via ISP)\, to sale
 s point. \n\nThis talk is a peek under the curtain for the server side dat
 a harvesting that agencies have developed\, and how they’ve managed to t
 wist this further invasion into so-called consumer protection and increase
 d privacy.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:The Trojan Pop-Up\; Modern Threat Actor Uses of Advertising - Sean 
 Juroviesky
URL:https://cfp.romhack.io/romhack-camp-2026/talk/7RZJGK/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-3L33X7@cfp.romhack.io
DTSTART;TZID=CET:20261002T170000
DTEND;TZID=CET:20261002T174000
DESCRIPTION:La generazione degli SBOM è ormai sempre più diffusa\, ma in 
 molti contesti rimane un’attività isolata: i file vengono prodotti dura
 nte la CI/CD e poi archiviati senza diventare parte di un processo di gest
 ione del rischio.\n\nIn questo talk presenterò Argus SBOM Guard\, un prog
 etto open source e 'self-hostabile' nato per sperimentare un approccio leg
 gero alla raccolta degli SBOM\, alla correlazione delle vulnerabilità e a
 l tracciamento delle attività di remediation.\n\nL’obiettivo non è int
 rodurre l’ennesimo scanner\, ma mostrare un flusso pratico che collega S
 BOM\, inventory\, vulnerability intelligence\, prioritizzazione e verifica
  delle correzioni\, con uno sguardo anche alle esigenze emergenti legate a
 lla software supply chain security e a normative come NIS2 e DORA.\n\nUn r
 acconto tecnico\, pragmatico e basato sull’esperienza di costruzione di 
 un side project open source.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Argus SBOM Guard: gestione delle vulnerabilità a partire dagli SBO
 M - Matteo Vitali (trotto)
URL:https://cfp.romhack.io/romhack-camp-2026/talk/3L33X7/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-EMS9ZU@cfp.romhack.io
DTSTART;TZID=CET:20261002T170000
DTEND;TZID=CET:20261003T080000
DESCRIPTION:Cyber Saiyan is proud to join forces with [fibonhack]([url](htt
 ps://fibonhack.it/)) to present “**From Dusk Till Dawn**”\, an on-site
  hacking marathon taking place during RomHack Camp.\n\nThis isn’t your a
 verage competition. While the rest of the camp sleeps\, 5 elite teams will
  battle through the night. 12 hours. Pure adrenaline.\n\n🚩 Meet the Fin
 alists\n🥇 1st - FR13NDS TEAM - Kazakhstan 🇰🇿\n🥈 2nd - TPC - Ja
 pan 🇯🇵\n🥉 3rd - thePizzaIncident - Italy 🇮🇹\n🏅 4th - Sat
 urnX - South Korea 🇰🇷\n🏅 5th - Mntcrl - UniBa\, Italy 🇮🇹
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:Community CTF by fibonhack - fibonhack
URL:https://cfp.romhack.io/romhack-camp-2026/talk/EMS9ZU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-GPNXUR@cfp.romhack.io
DTSTART;TZID=CET:20261002T173000
DTEND;TZID=CET:20261002T181000
DESCRIPTION:Viviamo nell'era della sorveglianza totale. I sistemi con cui l
 e corporation controllano ogni angolo del mondo esistono già: intelligenz
 e artificiali generative\, droni\, telecamere biometriche. \nLa battaglia 
 per la sovranità digitale è già cominciata e si combatte a colpi di fib
 ra ottica e codice binario. La posta in gioco non è un territorio lontano
 \, ma la libertà di miliardi di persone. Si combatte con algoritmi\, sate
 lliti e troll farm\, e il fronte è dentro smartphone\, social e dati cons
 ensualmente concessi. \nÈ una guerra ibrida fatta di episodi concreti: l'
 attacco alla rete satellitare Viasat che ha accecato le difese ucraine ore
  prima dell'invasione russa\; i cavi sottomarini sabotati nel Mar Baltico\
 , attraverso cui transita una parte delle comunicazioni mondiali\; Elon Mu
 sk che decide della connettività di una nazione in guerra\; Peter Thiel e
  Alexander Karp che vendono agli Stati la capacità di prevedere tutto\, s
 ottraendo loro la sovranità necessaria per difendersi. \nLa disinformazio
 ne di massa è ormai industrializzata e democratizzata dall'intelligenza a
 rtificiale. Internet non è più uno spazio comune\, ma un arcipelago di f
 ortezze digitali dove ogni conflitto è permanente e silenzioso. \nL'Europ
 a che regolamenta senza produrre tecnologia autonoma. Il rischio è la fin
 e del vecchio ordine globale\, delle sue leggi\, delle sue istituzioni. In
  questo conflitto nessuno è civile: siamo tutti bersagli.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Guerra Profonda. Hacker\, bugie e l'architettura segreta dei nuovi 
 conflitti - Arturo Di Corinto
URL:https://cfp.romhack.io/romhack-camp-2026/talk/GPNXUR/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-NFK7KE@cfp.romhack.io
DTSTART;TZID=CET:20261002T174000
DTEND;TZID=CET:20261002T180000
DESCRIPTION:Sometimes\, the perfectly engineered solution isn’t what you 
 need. We discuss how\, at the beginning of 2026\, we moved quickly to buil
 d a review bot that helped stem the flow of vulnerabilities entering the c
 odebase in the era of vibe coding. We’ll cover the ROI\, costs\, and pra
 ctical challenges involved\, along with lessons learned about model choice
  and how reusing existing harnesses helped us move faster.\n\nPresented at
  AI for Security event @ DEFCON34.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:A review bot that just works - Andrea Cappa
URL:https://cfp.romhack.io/romhack-camp-2026/talk/NFK7KE/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-AHQ3ZZ@cfp.romhack.io
DTSTART;TZID=CET:20261002T180000
DTEND;TZID=CET:20261002T200000
DESCRIPTION:Everyone talks about SOAR\; few have wired one up end to end. I
 n this hands-on lab you'll build the "respond" half of a real detection-an
 d-response pipeline — no slideware\, no vendor console.\n\nWe hand you a
  live AWS environment: an API gateway and WAF fronting a target app\, with
  all traffic and attack detections already flowing into Splunk. Your job i
 s to build the automation that fires when Splunk raises an alert\, using n
 8n (open-source\, low-code) as the orchestrator.\n\nYou'll answer one ques
 tion — "should I block this IP?" — with steadily rising intelligence. 
 First\, block on any alert (and watch the false positives roll in). Then b
 lock only when threat intel says the IP is malicious. Then hand the decisi
 on to an AI agent that investigates for itself: it queries multiple intel 
 sources and runs its own Splunk searches\, then returns a verdict with its
  reasoning. Finally\, put a human in the loop to approve or overrule the a
 gent — because trusting an autonomous blocker is the real 2026 question 
 — and\, time permitting\, make the block self-reverse with a TTL and an 
 audit trail back to Splunk.\n\nYou'll leave with a working\, governed\, AI
 -triaged auto-response pipeline and the patterns to rebuild it at home. Br
 ing a laptop\; we bring the infrastructure (AI model included).
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:Keep caLLM and Let It Block: Agentic SOAR with n8n + Splunk - Doc\,
  aserpi\, Ric\, Francesco Viscardi
URL:https://cfp.romhack.io/romhack-camp-2026/talk/AHQ3ZZ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-8QEJPW@cfp.romhack.io
DTSTART;TZID=CET:20261002T182000
DTEND;TZID=CET:20261002T190000
DESCRIPTION:"You need local admin for that." It's one of the most repeated 
 assumptions in offensive Windows tradecraft\, and it's mostly wrong.\nMost
  of these techniques are gated by a specific set of access-mask and DACL p
 ermissions\, not by group membership\, so the real question isn't "am I ad
 min?" but "what do I actually need?" This talk answers that systematically
 : what each lateral-movement technique truly requires\, instead of what fo
 lklore and our tooling assume.\nWe'll walk through the true minimum rights
  behind service creation and reconfiguration\, DCOM\, WinRM\, WMI (over bo
 th DCOM and WSMAN)\, Remote Registry\, Remote GhostTask\, Remote Network P
 rovider hijack\, RDP and RDP Shadowing\, SSH\, and User Right Assignments.
  Along the way we'll hit the under-documented Microsoft policy that silent
 ly breaks "non-admin service creation\," the granular access masks that ma
 ke these paths work (0x0003 on the SCM\, 0x00011 for shadowing\, and frien
 ds)\, and why those same minimal rights double as quiet persistence.\nThe 
 uncomfortable part cuts both ways. BloodHound edges\, NetExec's "Pwned!"\,
  and group-membership checks systematically miss these configurations\, so
  attackers slip through and defenders never see it. I'll cover MovementHou
 nd\, a PowerShell minimal-rights enumerator that surfaces these overlooked
  paths and feeds the missing edges straight into BloodHound\, with a recor
 ded demo of it in action.\nExpect granular access-mask details and honest 
 caveats.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:MovementHound: You might be missing something\, move it! - Umberto 
 Micillo (polair)
URL:https://cfp.romhack.io/romhack-camp-2026/talk/8QEJPW/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-MKHXNV@cfp.romhack.io
DTSTART;TZID=CET:20261002T182000
DTEND;TZID=CET:20261002T190000
DESCRIPTION:A Febbraio 2026 il progetto editoriale [Guerre di Rete](https:/
 /guerredirete.it) ha pubblicato il "Manualetto di sicurezza digitale per g
 iornalisti e attivisti".\n\nDurante il Camp presenteremo il manualetto\, i
 n ricordo di Carola Frediani\, fondatrice ed anima del progetto Guerre di 
 Rete\, venuta a mancare troppo presto\,  il 3 Giugno 2026.\n\nll manualett
 o è rivolto a categorie essenziali per il funzionamento della democrazia 
 e del dibattito pubblico\, che troppe volte abbiamo visto essere target di
  attacchi informatici\, sorveglianza\, campagne d’odio e di molestie nel
  mondo\, in Europa\, in Italia.\nÉ scritto da giornalisti e attivisti in 
 maniera semplice e discorsiva\, ma fornisce anche indicazioni pratiche di 
 base per iniziare a sistemare e a proteggere la propria vita digitale.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Presentazione "Manualetto di sicurezza digitale per giornalisti e a
 ttivisti" - Guerre di Rete
URL:https://cfp.romhack.io/romhack-camp-2026/talk/MKHXNV/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-QECNXZ@cfp.romhack.io
DTSTART;TZID=CET:20261002T190000
DTEND;TZID=CET:20261002T194000
DESCRIPTION:Supply chain attacks are increasingly focusing on developers an
 d automation tools.\nIn early 2025\, someone infected a widely used securi
 ty tool\, then used the knowledge from that attack to subsequently infect 
 npm- and python packages to steal developer credentials.\nThe talk will sh
 ow how these kinds of attacks worked and how developers can protect themse
 lves (and their assets) against similar attacks and why ai might or might 
 not be helpful in these scenarios.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Developers under attack - how to protect yourself - Christian <cy> 
 Kühn
URL:https://cfp.romhack.io/romhack-camp-2026/talk/QECNXZ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-3FTTEN-0@cfp.romhack.io
DTSTART;TZID=CET:20261002T190000
DTEND;TZID=CET:20261002T230000
DESCRIPTION:Hungry after a day of hacking? A wood-fired Pizza Truck parks o
 n site both evenings\, serving fresh pizza straight from a real wood oven.
 \n\nNo need to leave the woods for dinner — grab a slice\, grab a seat\,
  and refuel before or after the Hacker Cinema Night and the After Dark mus
 ic session.\n\nAvailable Friday and Saturday evening.
DTSTAMP:20260910T012503Z
LOCATION:FOOD AREA
SUMMARY:🍕 Pizza Truck — Wood-Fired Dinner - Pizza Truck
URL:https://cfp.romhack.io/romhack-camp-2026/talk/3FTTEN/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-AS8AWJ@cfp.romhack.io
DTSTART;TZID=CET:20261002T191000
DTEND;TZID=CET:20261002T195000
DESCRIPTION:Cryptography is a magic ring of darkness and mistiness\, but se
 ems that every time a new attack comes in town\, while cryptographers get 
 excited\, technicians start suffering to re-configure everything trying to
  survive following signals coming from misterious regulations and crypto p
 ublic challenges. And in the Quantum era everything is exploding: QKD\, PQ
 C\, Hybrid Crypto\, key exchange latency problems. We'll try to give a lit
 tle survival guide for this (apparently new) world\, which can make us mor
 e aware and confident on the future\, or at least better prepare for the n
 ext fashionable attacks. Maybe..
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Why I've to waste my (precious) time on cryptography? - Andrea Pomp
 ili
URL:https://cfp.romhack.io/romhack-camp-2026/talk/AS8AWJ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-MMBQHU@cfp.romhack.io
DTSTART;TZID=CET:20261002T200000
DTEND;TZID=CET:20261002T230000
DESCRIPTION:Take a break from hacking: it’s time for the ultimate caloric
  overflow! Masterfully cooked and proudly served by Berghem-in-the-Middle 
 (the crew behind [No Hat conference](https://www.nohat.it)\, our tradition
 al Polenta Taragna is made to perfection with cornmeal\, buckwheat\, the f
 inest alpine cheese and a terabit-scale DoS of butter.\nA tradition we dee
 ply cherish\, sparked during the first RomHack Camp edition\, when [a dear
  friend forever in our hearts wrote: “after that night\, the world will 
 be divided into those who have tasted polenta taragna and those who haven'
 t.”](https://romhack.io/un-hacker-camp-da-ricordare/) \nBring some appet
 ite\, and good luck staying awake at your terminal once that inevitable po
 st-taragna sleep mode kicks in!
DTSTAMP:20260910T012503Z
LOCATION:COMMUNITY AREA
SUMMARY:"tradizionale" polenta taragna di Berghem-in-the-Middle - Berghem-i
 n-the-Middle
URL:https://cfp.romhack.io/romhack-camp-2026/talk/MMBQHU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-GY3RFX@cfp.romhack.io
DTSTART;TZID=CET:20261002T203000
DTEND;TZID=CET:20261002T223000
DESCRIPTION:The Camp goes dark and the screen lights up.\n\nOn Friday night
  we open our two open-air screenings with a film that needs no introductio
 n to this crowd: [Sneakers](https://www.imdb.com/title/tt0105435/) (1992).
  A team of security specialists\, a black box that breaks any encryption\,
  and a plot that put pentesting on the big screen decades before it was co
 ol. "Setec Astronomy" — you'll get it.\n\nGrab a drink\, find a spot und
 er the sky\, and watch with the people who get it. No slides\, no keynotes
  — just a film\, together.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Hacker Cinema Night - Sneakers (1992) - Cyber Saiyan
URL:https://cfp.romhack.io/romhack-camp-2026/talk/GY3RFX/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-RBQXR3@cfp.romhack.io
DTSTART;TZID=CET:20261002T210000
DTEND;TZID=CET:20261002T220000
DESCRIPTION:Before Slack\, before Discord\, before Telegram\, there was IRC
 . A protocol so simple you could read it with netcat\, so resilient it sur
 vived 35 years of "IRC is dead" articles\, and so transparent that what yo
 u typed was exactly what the server saw — no algorithms\, no tracking\, 
 no engagement metrics.\nThis late-night session is part storytelling\, par
 t live hacking. We will walk through the history of IRC from the Italian u
 nderground scene of the late '90s — irc.tin.it\, war scripts\, channel t
 akeovers\, netsplits\, and the culture that shaped an entire generation of
  Italian hackers — to deploying a modern IRC server in 2026 on a self-ho
 sted LXC container with TLS\, persistent history\, and integrated services
 \, no third-party dependencies.\nBring your laptop. We will spin up a live
  server at the camp and open a channel for attendees to join in real time 
 via browser or terminal client. You will register a nick\, join a channel\
 , and experience what real-time communication looked like before corporati
 ons decided your attention was a product.\nNo slides. No frameworks. Just 
 a terminal\, a protocol from 1988\, and a conversation about what we lost 
 when we handed our communication to platforms we don't control.\nSuitable 
 for all skill levels. Nostalgia-prone attendees may experience involuntary
  emotions.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:IRC is not dead: self-hosting real-time chat like it's 1996 (but wi
 th TLS) - Myfox
URL:https://cfp.romhack.io/romhack-camp-2026/talk/RBQXR3/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-E7ZT7B@cfp.romhack.io
DTSTART;TZID=CET:20261002T223000
DTEND;TZID=CET:20261003T003000
DESCRIPTION:The screen goes dark\, the speakers wake up.\n\nRight after the
  Friday film\, the Camp turns up the volume. Two hours of music to keep th
 e night going with the community.\n\nNo agenda\, no schedule to follow\, j
 ust good sound\, good people\, and the woods around you.\n\nThe DJ line-up
  will be announced closer to the Camp.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:After Dark - Friday Music Session - Cyber Saiyan
URL:https://cfp.romhack.io/romhack-camp-2026/talk/E7ZT7B/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-HLLYEW@cfp.romhack.io
DTSTART;TZID=CET:20261003T093000
DTEND;TZID=CET:20261003T113000
DESCRIPTION:Delivered through Fortra's Zero-Point Security training platfor
 m\, this hands-on workshop provides an introduction to Cobalt Strike\, its
  core components\, and the product philosophy behind modern adversary simu
 lation and red team operations.\n\nAttendees will begin by exploring the C
 obalt Strike ecosystem\, including key concepts such as Team Servers\, Bea
 cons\, listeners\, and communication channels. Through interactive labs\, 
 participants will learn how to deploy and manage Beacons\, work with HTTP\
 , SMB\,\n and TCP listeners\, and understand how Beacon communication topo
 logies can be modified in real time.\n\nThe workshop also covers code exec
 ution fundamentals using Cobalt Strike's Resource Kit\, where attendees wi
 ll customize payload resources\, generate and host payloads\, and execute 
 them within a controlled lab environment.\n\nBy the end of the session\, p
 articipants will have a foundational understanding of Cobalt Strike's arch
 itecture\, Beacon communications\, listener types\, payload delivery\, and
  customization techniques commonly used in adversary emulation and red tea
 m engagements.\n\n**Workshop Requirements**\n* Max capacity of 30 attendee
 s\n* Attendees must bring their own laptop to access the training. \n* Att
 endee email addresses must be provided to Fortra in order to provide acces
 s to the platform:\n  * At least 3 days prior to the event\n  * Attendees 
 must be able to access the email address which they provide\, or they will
  not receive their login credentials
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:[Sponsor workshop] Introduction to Cobalt Strike: Command & Control
  and Code Execution Fundamentals - Fortra
URL:https://cfp.romhack.io/romhack-camp-2026/talk/HLLYEW/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-F9WCBL@cfp.romhack.io
DTSTART;TZID=CET:20261003T100000
DTEND;TZID=CET:20261003T104000
DESCRIPTION:Unlike mobile environments\, The Linux desktop paradigm wasn’
 t really designed with app-level security\, permissions and sandboxing in 
 mind. Despite this\, modern desktop environments try to shoehorn this in w
 ith systems such as Flatpak and desktop portals.\n\nWe went digging into G
 NOME ecosystem security\, investigating its core libraries (glib\, libsoup
 \, and gvfs) and sandboxing mechanisms (Flatpak\, bubblewrap\, dbus-proxy\
 , and desktop portals). During this journey into the GNOME world we uncove
 red numerous security issues\, resulting in more than 14 CVEs\, including 
 a full\, zero-precondition Flatpak sandbox escape.\n\nWe’ll take you alo
 ng our very same journey where you’ll discover how permissions and secur
 ity boundaries are enforced and rely on a web of libraries and tools\, som
 e of which seemingly unaware of their importance in the overall chain. Thi
 s way you’ll be able to see with your own eyes what issues arise in such
  a complex environment where a couple of small mistakes\, or colliding opi
 nions\, can lead to impactful vulnerabilities. We’ll also take a few det
 ours to show critical issues that we found in widely used open source prod
 uctivity software\, and how those vulnerabilities can have a severe impact
  also outside of the desktop paradigm.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:GNOME and Beyond Dream Tour: Discover Linux desktop sandboxing and 
 more through its vulnerabilities - b0n0b0
URL:https://cfp.romhack.io/romhack-camp-2026/talk/F9WCBL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-SVZ8AS@cfp.romhack.io
DTSTART;TZID=CET:20261003T100000
DTEND;TZID=CET:20261003T102000
DESCRIPTION:Aumentare la criptazione\, rende il sistema più sicuro?\nTra l
 a versione A e la versione B di un'app di edicola digitale: il sistema di 
 protezione è diventato più sofisticato ma nello stesso tempo\, più frag
 ile.\n\nLa versione A proteggeva l'accesso tramite regolare autenticazione
  e autorizzazione\, lato server. Con la versione B\, indici e metadati cif
 rati sono diventati pubblicamente raggiungibili\, mentre la protezione è 
 stata affidata a uno schema crittografico proprietario\, costruito sopra C
 rypto++ e distribuito all'interno dell'app.\n\nRicostruiremo il percorso c
 he ci ha permesso di comprenderne il funzionamento: MITM\, decompilazione 
 dell'APK\, analisi del bridge JNI e reverse engineering di una libreria na
 tiva ARM64.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Anatomia di un DRM editoriale - Fabio Fabrizi
URL:https://cfp.romhack.io/romhack-camp-2026/talk/SVZ8AS/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-S8XTE9@cfp.romhack.io
DTSTART;TZID=CET:20261003T100000
DTEND;TZID=CET:20261003T130000
DESCRIPTION:Un laboratorio pratico dove i ragazzi useranno modelli di Machi
 ne Learning e la funzione di  riconoscimento dei gesti delle mani per deco
 dificare la Lingua Italiana dei Segni (LIS). Tutte le fasi di raccolta dat
 i\, addestramento\, validazione e test saranno gestite in ambiente Pictobl
 ox. Un'esperienza interattiva per scoprire come l'intelligenza artificiale
  possa abbattere le barriere della comunicazione e favorire l'inclusione.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:AI4KIDS laboratorio di introduzione all'intelligenza artificiale - 
 Agnese
URL:https://cfp.romhack.io/romhack-camp-2026/talk/S8XTE9/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-U8LFED@cfp.romhack.io
DTSTART;TZID=CET:20261003T102000
DTEND;TZID=CET:20261003T110000
DESCRIPTION:Nobody runs a bare AI agent. Everyone extends it: skills\, MCP 
 servers\, plugins\, hooks\, subagents. Every one of those is\, underneath\
 , a folder of text that gets loaded into the model's context and read as i
 nstruction.\n\nWhich makes them a supply chain. One that gets reviewed exa
 ctly once\, at install\, and executed every session afterwards.\n\nThis ta
 lk poisons one\, step by step. We write a skill that does what it advertis
 es and one extra thing\, and we look at where you put the payload so that 
 the person installing it does not see it\, not in the file they skim\, but
  in the reference file that skill loads on demand. Then we do the version 
 that actually matters: a clean skill\, installed and approved three weeks 
 ago\, updated today. Four lines different. Nobody diffs an update.\n\nSame
  trick without installing anything: MCP tool descriptions are context\, so
  changing one after approval changes what the agent does with no code the 
 user ever reviews. And repository content  is read as task context by an a
 gent that cannot tell instruction from data.\n\nThe point is what none of 
 it requires: no exploit\, no privilege escalation\, no CVE. Every step use
 s capability that was granted on purpose.\n\nSecond half is defensive: whi
 ch controls change the outcome\, which ones only feel like they do\, and w
 hat you can still reconstruct afterwards.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:How to poison a skill\, and why nobody reviews it twice - Pietro Vi
 rgillito
URL:https://cfp.romhack.io/romhack-camp-2026/talk/U8LFED/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-8AZUTX@cfp.romhack.io
DTSTART;TZID=CET:20261003T104000
DTEND;TZID=CET:20261003T112000
DESCRIPTION:Dopo aver sfidato i limiti del **Commodore 64** con **Catalypse
 **\, perché non ripetersi su **Amiga**? Perchè non spingere l'hardware a
  livelli mai visti\, ricreando la magia dei coin-op che ci facevano sognar
 e alla fine degli anni '90? Questa è la storia di **Fatalnoise**\, un pic
 chiaduro ambizioso che non ha mai visto la luce. Un progetto folle\, nato 
 e sviluppato tra sfide tecniche insormontabili\, problemi con l'universit
 à\, accese divergenze creative e quella immancabile\, totale incoscienza 
 di chi non aveva la minima idea di cosa stesse realmente combinando... fin
 o ad oggi...
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:From Hero to Zero: The FatalNoise neverending story - Andrea Pompil
 i
URL:https://cfp.romhack.io/romhack-camp-2026/talk/8AZUTX/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-J7BBDG@cfp.romhack.io
DTSTART;TZID=CET:20261003T110000
DTEND;TZID=CET:20261003T114000
DESCRIPTION:Il talk vuole presentare questa distro linux IpFire per uso fir
 ewall in casa e piccole ditte con molti plug-in in particolare quello per 
 tor che permette il firewall non solo di proteggere le connessioni tramite
  IPS ma anche per l'anonimato come nodo entrante al circuito tor e volendo
  come bridge per contribuire alla complessita del deepweb. Il talk quindi 
 fa una panoramica dei punti di forza del progetto opensource non avendo un
 a versione commerciale\, vuole sensibilizzare all'uso di strumenti opensou
 rce per la privacy come VPN e protezione DNS.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Linux-IpFire hardening lan with suricata/IPS - fabio carletti aka R
 yuw
URL:https://cfp.romhack.io/romhack-camp-2026/talk/J7BBDG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-JCWFDW@cfp.romhack.io
DTSTART;TZID=CET:20261003T113000
DTEND;TZID=CET:20261003T133000
DESCRIPTION:This 2 hours workshop (max 20 people) wants to be an introducto
 ry course to the marvelous world of picking locks. After an overview of th
 e most common types of locks and how they operate\, the instructor will sh
 ow you which type of tools are needed to manipulate and open them. In the 
 second part of this training\, you will be provided with a lockpicking kit
  and some practice locks in order to try yourself.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:PhySec Lab Part 1: Lockpicking 101 - CYBERANTANI
URL:https://cfp.romhack.io/romhack-camp-2026/talk/JCWFDW/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-GHGK7L@cfp.romhack.io
DTSTART;TZID=CET:20261003T113000
DTEND;TZID=CET:20261003T121000
DESCRIPTION:Insieme alla famiglia di Carola\, a amici e amiche e alla redaz
 ione di Guerre di Rete presenteremo il suo ultimo libro "L'inganno dell'Au
 toma"\n\n_«È un big game\, my friend. Chi si oppone non finisce bene.» 
 Italia contemporanea. Andrea\, un giovane ricercatore di cybersicurezza ch
 e vive tra Milano e la Liguria\, viene interrotto nella sua edonistica quo
 tidianità dalla notizia dell’arresto a Dubai di un vecchio amico. L’u
 omo\, che commerciava vulnerabilità informatiche e si dedicava a vari tra
 ffici in giro per il mondo\, è accusato di spionaggio. Mentre Andrea cerc
 a di capire come aiutare l’amico e cosa si nasconda dietro l’arresto\,
  incrocia sulla sua strada una giornalista investigativa\, Agnese\, autric
 e di un blog molto seguito\, dal quale si scaglia contro la corruzione del
  governo\; ma anche Caterina\, brillante e frustrata social media manager 
 di una politica nazionale. Travolta da rivelazioni\, inquietanti traffican
 ti d’armi\, e oscuri intrecci di politici corrotti e società di intelli
 genza artificiale\, la vita dei tre viene cambiata\, obbligandoli a cercar
 e giustizia più che una facile via d’uscita. E non tutto è ciò che se
 mbra._\n\nhttps://www.ibs.it/inganno-dell-automa-libro-carola-frediani
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Presentazione libro "L'inganno dell'Automa" di Carola Frediani - Gu
 erre di Rete
URL:https://cfp.romhack.io/romhack-camp-2026/talk/GHGK7L/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-KKWVTD@cfp.romhack.io
DTSTART;TZID=CET:20261003T120000
DTEND;TZID=CET:20261003T124000
DESCRIPTION:Nel mondo attuale dello sviluppo software\, la sicurezza non pu
 ò più essere un ripensamento. Con l'approccio DevSecOps e il principio "
 shift left"\, gli sviluppatori svolgono un ruolo proattivo nell'integrare 
 la sicurezza fin dalle prime fasi dello sviluppo\, contribuendo a rendere 
 le applicazioni più sicure e resilienti. In questo talk esploreremo best 
 practices per scrivere codice sicuro e presenteremo alcuni strumenti che a
 iutano ad automatizzare la rilevazione di vulnerabilità nel nostro codice
  Python e nelle dipendenze.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Codice Python Sicuro: Buone Pratiche e Strumenti di Analisi - Matte
 o Vitali (trotto)
URL:https://cfp.romhack.io/romhack-camp-2026/talk/KKWVTD/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-TT8EEA@cfp.romhack.io
DTSTART;TZID=CET:20261003T123000
DTEND;TZID=CET:20261003T131000
DESCRIPTION:Talk summary: Electric vehicle charging infrastructure is rapi
 dly expanding\, becoming a critical component of modern transportation. De
 spite the increased attention on its security\, our research shows that ev
 en devices previously examined in competitions such as Pwn2Own can still h
 ide impactful vulnerabilities.\n\nWe picked up this device right after Pwn
 2Own results were announced and the competition was over - and quickly fou
 nd that the story was far from finished. Our security analysis of this com
 mercially available Phoenix Contact CHARX SEC-3000 EV charging station con
 troller uncovered serious\, previously unknown issues that had gone unnoti
 ced during the event. By combining firmware analysis with emulation techni
 ques\, we identified several critical vulnerabilities (including OS Inject
 ion) affecting the device. We will walk through the approaches\, challenge
 s\, and what we have learned.\n\nLonger talk description: This session pro
 vides a technical analysis into our ongoing research on an EV charging sta
 tion controller. The device we investigated had already been part of a Pwn
 2Own competition\, yet our analysis revealed multiple security vulnerabili
 ties. We will cover our approach to analyzing the charger\, including firm
 ware extraction and emulation to understand internal components and logic 
 of the device ecosystem.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Breaking the Charge: Security Analysis of the Phoenix Contact CHARX
  SEC-3000 EV Charging Controller - Piotr Ptaszek\, Matthew
URL:https://cfp.romhack.io/romhack-camp-2026/talk/TT8EEA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-HETQC3@cfp.romhack.io
DTSTART;TZID=CET:20261003T124000
DTEND;TZID=CET:20261003T130000
DESCRIPTION:Over the years as a cybersecurity pre-sales engineer\, I've had
  the privilege of seeing organizations prepare to defend themselves agains
 t sophisticated attackers\, ransomware gangs\, zero-days\, and nation-stat
 e threats. Sometimes\, however\, the biggest security problem was much clo
 ser to home.\nA company wants NAC\, but there's no IdP. Another wants PAM 
 while every workstation shares the same local administrator password. Some
 one wants an anti-spam solution while SPF\, DKIM and DMARC are not configu
 red properly. I've encountered passwords stored in passwords.txt\, environ
 ments where every machine is administered individually.\nThese aren't just
  funny war stories. They reveal a recurring problem: security products hav
 e prerequisites.\nNAC and EDR assume you can manage your endpoints. Vulner
 ability management assumes you know what assets you have. SIEM assumes you
  have useful logs and someone who can act on them. Zero Trust assumes you 
 have some idea who your users\, devices and applications actually are.\nTh
 is talk is a collection of strange\, surprising and sometimes painful less
 ons from the security pre-sales trenches\, and an argument for asking an u
 ncomfortable question before buying the next security product:\n“What sh
 ould we fix first?”\nBecause sometimes the most useful thing a security 
 vendor can tell you is:\n“You don't need our product yet.”
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:You Don't Need a Security Solution - Max Derkach
URL:https://cfp.romhack.io/romhack-camp-2026/talk/HETQC3/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-3MJRSS@cfp.romhack.io
DTSTART;TZID=CET:20261003T140000
DTEND;TZID=CET:20261003T144000
DESCRIPTION:Modern software is assembled\, not just written: nearly 90% of 
 a typical application consists of third-party libraries. If a critical vul
 nerability like Log4Shell were disclosed tomorrow\, how long would it take
  your team to identify every affected microservice? While large enterprise
 s rely on expensive "Ultimate" licenses\, SMEs and independent teams often
  face a dangerous security gap.\nIn this session\, we will explore how to 
 democratize Software Supply Chain Security (SSCS) by building an automated
  defense perimeter at zero licensing cost. Through a Live Demo featuring a
  Docker-based prototype\, we will walk through a real-world architecture i
 ntegrating:\n• GitLab Community Edition for pipeline orchestration.\n•
  Trivy and cdxgen for automated SBOM (Software Bill of Materials) generati
 on in CycloneDX format.\n• OWASP Dependency-Track for continuous\, proac
 tive vulnerability monitoring.\nWe will go beyond basic scanning by demons
 trating how to leverage Artificial Intelligence for code reachability anal
 ysis\, generating VEX (Vulnerability Exploitability eXchange) files to sil
 ence false positives and focus only on actionable risks. We will also disc
 uss how this stack prepares organizations for the upcoming EU Cyber Resili
 ence Act (CRA) requirements.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:SBOM SBAM: Who Put This in My Code? Enterprise-Grade Supply Chain S
 ecurity on a Zero Budget - Maurizio Argoneto
URL:https://cfp.romhack.io/romhack-camp-2026/talk/3MJRSS/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-XYPNLH@cfp.romhack.io
DTSTART;TZID=CET:20261003T140000
DTEND;TZID=CET:20261003T142000
DESCRIPTION:This presentation explores the history\, technology\, and legac
 y of the Commodore 65\, one of the most fascinating unreleased machines in
  Commodore’s history. Conceived at the end of the 1980s as the possible 
 successor to the legendary Commodore 64\, the C65 represented an ambitious
  attempt to extend the life of the 8-bit platform while integrating featur
 es inspired by the emerging 16-bit generation. Through historical context\
 , technical analysis\, and direct experience with original prototypes\, th
 e talk examines the C65’s architecture\, including the 4510 CPU\, VIC-II
 I graphics chip\, enhanced BASIC 10\, integrated 3.5-inch disk drive\, and
  advanced graphic and sound capabilities. Particular attention is given to
  the machine’s difficult development\, its uncertain position between th
 e C64 and the Amiga\, and the reasons why it never reached the commercial 
 market. The Commodore 65 is presented not only as a rare collector’s ite
 m\, but as a symbol of Commodore’s creativity\, contradictions\, and mis
 sed opportunities. Its story reveals a crucial transitional moment in home
  computing: the end of the classic 8-bit age and the beginning of a new te
 chnological era
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:The Commodore 65: the dream that never arrived - Dr. Commodore 65
URL:https://cfp.romhack.io/romhack-camp-2026/talk/XYPNLH/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-MXTLKL@cfp.romhack.io
DTSTART;TZID=CET:20261003T140000
DTEND;TZID=CET:20261003T160000
DESCRIPTION:You've always wanted to start with binary exploitation challeng
 es\, but fear the horrors of weird machines? This will be a workshop for y
 ou! After a theoretical introduction on binary exploitation basics all the
  way to x86_64 Return Oriented Programming you will get your hands dirty w
 ith the "Don't crash" challenges with the help of the author. Bring your L
 inux laptop (or VM) with Ghidra\, pwntools and pwndbg
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:"Don't crash" challenges walkthrough - Max 'Sparrrgh' Bellia
URL:https://cfp.romhack.io/romhack-camp-2026/talk/MXTLKL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-87DHLD-0@cfp.romhack.io
DTSTART;TZID=CET:20261003T140000
DTEND;TZID=CET:20261003T150000
DESCRIPTION:Ready to build?\nMove beyond theory and construct a full functi
 onal AI-powered podcast in this hands-on "Build with AI" workshop.\nWe'll 
 guide you through an end-to-end workflow\, leveraging specific Google AI a
 nd Cloud tools to transform an idea into publishable audio content.\n-Dive
  into practical prompt engineering with Google Gemini. You'll actively bra
 instorm niche topics\, outline a compelling episode structure\, and genera
 te a working script for a short podcast segment.\n-Take your Gemini-genera
 ted script and bring it to life. We'll use the Google Cloud Text-to-Speech
  API to synthesize natural-sounding voice audio\, experimenting with diffe
 rent voice profiles. You'll see how to generate audio files directly from 
 text.\n-We'll then explore how Google Cloud Run can serve as the backbone 
 for automating this workflow – designing a simple service architecture c
 apable of potentially taking script inputs and orchestrating the TTS gener
 ation and audio file delivery. \nWho is this for? Developers\, creators\, 
 and tech enthusiasts that want to apply latest Google's AI and Cloud tools
  to the content creation challenges.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:Zero to podcaster\, start today your show with AI! - Nicola Gugliel
 mi
URL:https://cfp.romhack.io/romhack-camp-2026/talk/87DHLD/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-DTBUCX@cfp.romhack.io
DTSTART;TZID=CET:20261003T143000
DTEND;TZID=CET:20261003T151000
DESCRIPTION:Your smartphone is not just a phone. It is your microphone\, ca
 mera\, archive\, diary\, GPS tracker\, wallet\, authenticator\, and memory
 . In this talk\, we will explore what happens when that device is turned i
 nto an informant during a legitimate criminal investigation through the us
 e of lawful investigative malware\, commonly known in Italy as a "captator
 e informatico".\nWe will start from the civic and legal tension: the need 
 for effective investigations versus the privacy impact of compromising the
  most intimate device we own. Then we will move into the technical side\, 
 dissecting a real-world mobile implant to understand how it likely infecte
 d the device\, what data it was able to collect\, how it communicated\, an
 d what traces it left behind.\nThis is not an anti-law-enforcement talk. I
 t is a hard look at the technical power of these tools\, the risks created
  by their use\, the vendors and supply chains behind them\, and the practi
 cal signals defenders can monitor.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:State Trojan: The Malware with a Warrant - Pietro Boccaletto\, Fran
 cesco Infantini
URL:https://cfp.romhack.io/romhack-camp-2026/talk/DTBUCX/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-ACVWSL@cfp.romhack.io
DTSTART;TZID=CET:20261003T144000
DTEND;TZID=CET:20261003T152000
DESCRIPTION:Initial access isn’t just about phishing anymore. Modern brea
 ches are increasingly rooted in the application layer\, where logic flaws\
 , design weaknesses\, and overlooked attack surfaces can open paths to com
 promise.\nIn this talk\, we’ll dissect how AppSec-driven tactics can red
 efine red team operations. We’ll share our methodology for embedding vul
 nerability research into live engagements\, blending code-level analysis\,
  target hunting\, and exploit chaining with traditional adversary tradecra
 ft. This isn’t about dropping a pre-packaged exploit - it’s about buil
 ding one mid-operation.\nThrough case studies against high-profile global 
 targets\, we’ll show how this approach surfaced and chained zero-day vul
 nerabilities to breach external perimeters and operate effectively in matu
 re environments. Whether you’re looking to sharpen your offensive capabi
 lities or expand your initial access playbook\, this session delivers hard
 -earned insights straight from the field
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Shells Without Phish - Mohamed Elsayed\, Abdulrahman Nour
URL:https://cfp.romhack.io/romhack-camp-2026/talk/ACVWSL/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-TGTBKG-1@cfp.romhack.io
DTSTART;TZID=CET:20261003T150000
DTEND;TZID=CET:20261003T180000
DESCRIPTION:**Bullismo No Grazie** è un'associazione no profit nata nel 20
 21 che ha incontrato oltre 200.000 ragazzi e 90.000 adulti in più di 100 
 città italiane\, percorrendo oltre 150.000 km di scuole\, palestre e vill
 aggi turistici.\n\nIn questo workshop portiamo la realtà che vediamo ogni
  giorno: le challenge pericolose che circolano tra bambini di IV e V eleme
 ntare\, i social network che i ragazzi usano e che i genitori non conoscon
 o\, le responsabilità civili e penali che ricadono sulle famiglie quando 
 un minore commette atti di cyberbullismo.\n\nNiente teoria. Solo casi real
 i\, domande vere\, strumenti pratici per riconoscere i segnali e sapere co
 sa fare.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:Il bullismo non va in vacanza - Bullismo No Grazie
URL:https://cfp.romhack.io/romhack-camp-2026/talk/TGTBKG/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-WVKS3F@cfp.romhack.io
DTSTART;TZID=CET:20261003T151000
DTEND;TZID=CET:20261003T155000
DESCRIPTION:AI is changing both the scale and speed of cyber offense and de
 fense. In response\, more than 100 organizations across technology\, cyber
 security\, industry\, and government have called for a global surge in cyb
 er defense: better tools for defenders\, stronger protection for critical 
 infrastructure\, more useful intelligence sharing\, and faster remediation
  of vulnerabilities.\n\nThe harder question is what happens next. What sho
 uld organizations actually commit to\, and how should progress be measured
 ? Who gets access to advanced defensive AI\, and who decides what qualifie
 s as a “trusted defender”? How can vendors share intelligence and fixe
 s that defenders can use in practice? And who pays to bring these capabili
 ties to smaller hospitals\, utilities\, municipalities\, and other resourc
 e-constrained organizations?\n\nThe panel will also tackle a fundamental t
 echnical challenge: securing software and infrastructure at scale. More mo
 dels\, agents\, or compute do not automatically translate into fewer criti
 cal vulnerabilities. We will discuss what AI labs\, governments\, security
  vendors\, software producers\, and infrastructure operators each need to 
 do to turn a broad call for action into concrete\, accountable improvement
 s in cyber defense.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:A call for collective action on cyber defense - Andrea Cappa
URL:https://cfp.romhack.io/romhack-camp-2026/talk/WVKS3F/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-V9FE9N@cfp.romhack.io
DTSTART;TZID=CET:20261003T152000
DTEND;TZID=CET:20261003T160000
DESCRIPTION:Phishing defenses assume the attack comes from outside the trus
 ted set: a lookalike domain\, a domain registered last week\, a sender wit
 h no history. Your cloud Provider's own infrastructure breaks that assumpt
 ion\, and this talk covers how far that goes.\nB2B guest invitations produ
 ce real\, Signed mail carrying a redirection target the attacker influence
 s. Open redirects across Trusted Cloud Provider-owned domains supply the p
 ivot\, and chaining them keeps the trusted origin intact through to the pa
 yload. I'll demo forced POST parameter injection\, image and context injec
 tion that pulls the target's own tenant branding into the lure\, and end-t
 o-end credential and MFA capture. The address bar stays your favorite Prov
 ider's the whole way.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Living Off Trusted Cloud: Provider Infrastructure as Phishing Deliv
 ery Channel - Rahul Vashisht
URL:https://cfp.romhack.io/romhack-camp-2026/talk/V9FE9N/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-PTNMVU@cfp.romhack.io
DTSTART;TZID=CET:20261003T160000
DTEND;TZID=CET:20261003T164000
DESCRIPTION:Fiscal cash registers are everywhere in Italy\, yet they receiv
 e surprisingly little attention as embedded systems. They are regulated ap
 pliances with tamper-evident seals\, periodic inspections\, controlled ser
 vice procedures\, and hardware mechanisms intended to make fiscal data dif
 ficult to manipulate.\nWe bought one of the most common models on the seco
 nd-hand market and started taking it apart. Inside\, we found an unusual d
 esign: an FPGA driving the user interface\, an internal battery supporting
  a peculiar power lifecycle\, a resin-encapsulated memory module\, and phy
 sical switches hidden on the main board.\n\nThe software architecture is m
 uch more familiar: the device runs an old Linux-based OS with a writable r
 oot filesystem\, essentially no privilege separation\, extensive debug fun
 ctionality\, and a broad network attack surface.\n\nWhether you prefer har
 dware or software\, we found ways in from both sides. Rather than presenti
 ng a vulnerability catalogue\, this talk examines the security model of a 
 regulated embedded system and the mismatch between elaborate physical prot
 ections and weak software trust boundaries.\nWhat does “tamper resistant
 ” mean when the protected component is connected to a general-purpose co
 mputer with weak security assumptions?\n\nBy the end of the talk\, we’ll
  have answered that question and one more: does it run Doom?
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Cash\, Card or Root? Security Archaeology of a Fiscal Cash Register
  - Jacopo Jannone\, Jacopo Moioli
URL:https://cfp.romhack.io/romhack-camp-2026/talk/PTNMVU/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-ALJJBE@cfp.romhack.io
DTSTART;TZID=CET:20261003T160000
DTEND;TZID=CET:20261003T170000
DESCRIPTION:Threat intelligence teams collect indicators\, follow threat ac
 tors and produce reports. SOC teams build detections and investigate alert
 s. Too often\, the connection between the two ends with a list of IP addre
 sses\, domains and hashes added to a SIEM.\n\nThis talk looks at how to mo
 ve beyond that model.\n\nUsing practical attack examples\, I'll walk throu
 gh how intelligence can be transformed from an IOC or threat report into a
 n investigative hypothesis\, observable attacker behaviour and ultimately 
 a detection. We will look at what information gets lost when intelligence 
 is reduced to indicators\, how to identify the behaviour behind those indi
 cators\, and how to decide which telemetry can actually expose it.\n\nThe 
 session follows a simple workflow:\n\nThreat Intelligence → Adversary Be
 haviour → Detection Hypothesis → Telemetry → Detection → Hunt → 
 Validation\n\nI'll also cover what happens after a detection fires: how in
 vestigation results can feed back into threat intelligence\, improve conte
 xt and help identify what should be hunted for next.\n\nThe goal is not to
  collect more intelligence or generate more alerts. It is to make threat i
 ntelligence operational enough to change what your SOC can detect.\n\nAn I
 OC may tell you what the attacker used. A good detection should help you f
 ind what the attacker did.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:From IOC to Detection: Turning Threat Intelligence Into Something Y
 our SOC Can Actually Use - Sanjay Kumar
URL:https://cfp.romhack.io/romhack-camp-2026/talk/ALJJBE/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-UCVJX3@cfp.romhack.io
DTSTART;TZID=CET:20261003T160000
DTEND;TZID=CET:20261003T164000
DESCRIPTION:In questa presentazione verrà illustrato il principio di funzi
 onamento delle Tesla coil musicali\, dispositivi elettromeccanici capaci d
 i generare scariche elettriche controllate e visibili\, sincronizzate con 
 segnali audio. Partendo da un inquadramento storico e scientifico\, verrà
  spiegato cosa sono le Tesla coil e come\, attraverso l’elettronica di p
 otenza e il controllo digitale\, sia possibile modulare le scariche per pr
 odurre suoni e melodie. L’incontro approfondirà i concetti di risonanza
 \, alta tensione e ionizzazione dell’aria\, evidenziando il legame tra f
 isica\, ingegneria e musica. La presentazione farà da introduzione allo s
 pettacolo serale\, in cui le Tesla coil musicali saranno protagoniste di u
 na performance dal vivo: un’esperienza immersiva che unisce divulgazione
  scientifica e intrattenimento\, trasformando l’elettricità in luce\, s
 uono ed emozione.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Tesla Coil by VoltagePyromania - michele pietravalle aka PHCV
URL:https://cfp.romhack.io/romhack-camp-2026/talk/UCVJX3/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-HBCFWE@cfp.romhack.io
DTSTART;TZID=CET:20261003T164000
DTEND;TZID=CET:20261003T172000
DESCRIPTION:Deepfake detection using 3D CNNs traditionally focuses on ident
 ifying synthetic facial manipulations in video. This work inverts that len
 s. I leverage temporal‑spatial 3D CNN features originally designed to sp
 ot fake videos and apply them to a completely different domain: OSINT‑ba
 sed profiling. By treating metadata as a volumetric signal across related 
 individuals\, the same convolutional filters that detect frame‑to‑fram
 e anomalies can reconstruct familial linkages from public or leaked databa
 ses. This methodology enhances traditional OSINT by adding a predictive la
 yer. Instead of manually building family trees\, the 3D CNN model learns k
 inship patterns and flags potential person matches with high confidence. T
 he result is a hybrid attack that combines AI forensics and open source in
 telligence to identify a target individual from a distant relative’s spi
 t sample. I demonstrate a proof of concept using synthetic profiles and re
 al OSINT sources. The talk shows how a deepfake detection technique become
 s a privacy‑breaking weapon for person traceability at scale.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Using Temporal‑Spatial 3D CNN Features to Enhance OSINT‑Based P
 rofiling and Individual Traceability - Reza
URL:https://cfp.romhack.io/romhack-camp-2026/talk/HBCFWE/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-9V9HDD@cfp.romhack.io
DTSTART;TZID=CET:20261003T170000
DTEND;TZID=CET:20261003T172000
DESCRIPTION:Systemd units have many built-in configuration options that can
  be used to restrict access of a unit to the rest of the system\, with the
  goal of containing a compromised system service.\nMarco will review the s
 tate of systemd security sandboxing in Debian packages\, what we need to f
 ix to have more and what will break by enabling too much of it.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:The state of systemd security sandboxing in Debian - Marco d'Itri
URL:https://cfp.romhack.io/romhack-camp-2026/talk/9V9HDD/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-GHQT3K@cfp.romhack.io
DTSTART;TZID=CET:20261003T170000
DTEND;TZID=CET:20261003T190000
DESCRIPTION:The growing reliance on heterogeneous computing environments in
  both personal and enterprise contexts has made cross-platform forensic ac
 quisition a critical competency for digital investigators. Yet the adoptio
 n of rigorous forensic workflows remains uneven\, particularly in resource
 -constrained settings where commercial tools may be inaccessible. This wor
 kshop addresses that gap by offering a structured\, hands-on introduction 
 to forensic data extraction from Windows and macOS systems using exclusive
 ly free tools.\nThe session opens with a foundational module covering the 
 core principles of digital forensics as they apply to forensic imaging: bi
 t-by-bit acquisition\, cryptographic hash verification (MD5\, SHA-256)\, w
 rite-blocking procedures\, chain of custody documentation\, and legal admi
 ssibility requirements. \nThe practical component introduces a curated too
 lkit of free acquisition and analysis solutions. Guymager is presented as 
 a reliable\, GUI-based imaging platform offering multi-format output (DD\,
  EWF/E01\, AFF)\, real-time hash calculation\, and parallel acquisition su
 pport. Fuji is introduced as a modern imager optimized for macOS environme
 nts\, particularly suited for APFS volumes and Apple Silicon hardware\, fe
 aturing automated image verification workflows. For analysis\, FTK Imager 
 is demonstrated for forensic extraction from Windows hosts\, while Autopsy
  provides participants with an open-source platform for analysis\, data re
 covery and case management.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:Hands-On Forensic Imaging and Data Extraction from Windows and macO
 S Using Free and Open Source Tools - Alessandro Farina
URL:https://cfp.romhack.io/romhack-camp-2026/talk/GHQT3K/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-VPLU83@cfp.romhack.io
DTSTART;TZID=CET:20261003T173000
DTEND;TZID=CET:20261003T175000
DESCRIPTION:The talk focuses on the hardcore usage from treat actor of ai t
 o develop malware in large scale. In order to overcome the disastrous even
 ts shortcoming\, we implement via LangGraph\, Capev2 and Local Ai a way to
  find the most sketchy ones.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:From Discovery to Automated Windows Malware Analysis - Pizzamarinar
 asadd
URL:https://cfp.romhack.io/romhack-camp-2026/talk/VPLU83/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-CATUNP@cfp.romhack.io
DTSTART;TZID=CET:20261003T173000
DTEND;TZID=CET:20261003T175000
DESCRIPTION:Cellular baseband processors run highly privileged\, proprietar
 y software beneath the main OS\, making them a critical yet hard-to-analyz
 e attack surface. Focusing on the Google Pixel 9 modem\, this talk demonst
 rates how adapting open-source emulation software allowed us to build a ba
 seband fuzzing pipeline\, surfacing three new vulnerabilities and several 
 rediscoveries\, including an Out-of-Bounds (OOB) read in 5G message parsin
 g.\nAfter validating the flaw with Software Defined Radios (SDRs)\, we add
 ress the challenge of turning local memory leaks into full remote attacks.
  We show how SIM Toolkit (STK) applets\, legitimate applications running o
 n SIMs/eSIMs that can be provisioned over-the-air\, can be repurposed as a
  delivery and execution primitive operating entirely outside main OS visib
 ility. Finally\, we detail how pairing remote STK provisioning with the 5G
  baseband vulnerability creates a silent\, zero-click exfiltration chain t
 hat leaks sensitive memory over SMS.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Ghost in the SIM: Silent\, Zero-Click\, Over-the-Air Exploitation o
 f a Pixel 9 Baseband OOB Read - Lorenzo Valeriani\, Pasquale Caporaso
URL:https://cfp.romhack.io/romhack-camp-2026/talk/CATUNP/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-3LJDWR@cfp.romhack.io
DTSTART;TZID=CET:20261003T180000
DTEND;TZID=CET:20261003T184000
DESCRIPTION:Bash isn't just an interface to your daily laptop - it's a weap
 on. This 45 minute talk shows how to push bash beyond its typical use-case
 s\, leveraging it for hacking\, data processing\, automation\, and real-wo
 rld security applications. Whether you're crafting exploits\, analyzing ma
 ssive datasets\, or automating reconnaissance\, this talk will equip you w
 ith the skills to turn bash into your ultimate hacking tool.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:Command-Line Alchemy: Turning Scripts into Superpower - Kirils Solo
 vjovs
URL:https://cfp.romhack.io/romhack-camp-2026/talk/3LJDWR/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-ZHYFFX@cfp.romhack.io
DTSTART;TZID=CET:20261003T180000
DTEND;TZID=CET:20261003T200000
DESCRIPTION:This 2 hours workshop (max 20 people) is designed to provide th
 e attendees a good grasp on how Physical Access Control Systems work and h
 ow they can be defeated. During the course there will be multiple real exa
 mples and different offensive techniques will be explained. In the second 
 part\, it will be also possible to try exploiting them in live against rea
 l targets setup for the occasion.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:PhySec Lab Part 2: Hacking Physical Access Control Systems - CYBERA
 NTANI
URL:https://cfp.romhack.io/romhack-camp-2026/talk/ZHYFFX/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-9ZK9QM@cfp.romhack.io
DTSTART;TZID=CET:20261003T180000
DTEND;TZID=CET:20261003T183000
DESCRIPTION:The long night is finally over! After an intense 12-hour on-sit
 e hacking marathon\, it is time to wrap up the From Dusk Till Dawn CTF.\n\
 nOrganized by the brilliant community-driven group **fibonhack**\, this co
 mpetition tested the limits of our finalists across Web Security\, Binary 
 Exploitation\, Cryptography\, and Reverse Engineering. \nWhile the rest of
  the camp slept\, five elite teams—FR13NDS TEAM\, TPC\, thePizzaIncident
 \, SaturnX\, and Mntcrl—battled it out from Friday at 19:00 straight thr
 ough to Saturday morning at 07:00.\n\nIn this 20-minute award ceremony\, t
 he **fibonhack** and **Cyber Saiyan** teams will take the stage to review 
 the final scoreboard and officially crown the **RomHack Camp 2026 Communit
 y CTF Champions**.\n\nJoin us to celebrate the incredible skills of our pl
 ayers\, discover who takes home the prizes\, and give a massive round of a
 pplause to everyone who survived until dawn!
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Community CTF by fibonhack - Award Ceremony - fibonhack
URL:https://cfp.romhack.io/romhack-camp-2026/talk/9ZK9QM/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-JZSCRH@cfp.romhack.io
DTSTART;TZID=CET:20261003T183000
DTEND;TZID=CET:20261003T191000
DESCRIPTION:Modern Digital Forensics and Incident Response (DFIR) investiga
 tions require analysts to process large volumes of heterogeneous data\, co
 rrelate evidence from multiple sources\, and quickly reconstruct attack ti
 melines without losing context. Gulp (Graphical Universal Log Processor) i
 s designed to address these challenges by providing a flexible\, visual pl
 atform for exploring\, correlating\, and analyzing logs and digital artifa
 cts\, complementing existing forensic workflows rather than replacing them
 .\n\nThis session introduces the GULP project\, its architecture\, and the
  challenges it is designed to address. The core of the presentation is a h
 ands-on investigation that walks attendees through the different stages of
  a real-world attack. It also demonstrates how GULP can be used to analyze
  data collected from third-party forensic tools and log sources\, leveragi
 ng graphical visualizations and contextual correlations to accelerate inve
 stigations and improve the understanding of complex attack scenarios.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:GULP: See the Attack. Understand the Story. Prove the Facts - David
 e Inzerillo
URL:https://cfp.romhack.io/romhack-camp-2026/talk/JZSCRH/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-VZ7VY3@cfp.romhack.io
DTSTART;TZID=CET:20261003T184000
DTEND;TZID=CET:20261003T192000
DESCRIPTION:Forget prompt injection. While the industry obsesses over manip
 ulating model inputs to bypass guardrails\, it is overlooking a far more d
 angerous threat requiring no user interaction beyond opening the applicati
 on embedded beneath the AI itself: the underlying platform architecture.\n
 \nTo deliver on the promise of full autonomy\, AI-powered coding environme
 nts wire Large Language Models directly into the developer workflow—hand
 ing them local filesystem access\, shell execution\, and cloud credentials
 . Developers accept this tradeoff for the massive productivity gains\, but
  the security cost is severe.\n\nIn these environments\, privileged OS acc
 ess is not a misconfiguration but a product requirement. For a chat interf
 ace to truly become an autonomous "agent\," it must be equipped with tools
 . Equipping the AI with these tools creates a structural conflict with tra
 ditional application isolation\, like Electron's security model. To make t
 he AI function\, developers are forced to break the sandbox and expose hig
 hly permissive IPC (Inter-Process Communication) bridges between the web r
 enderer and the local operating system.\n\nThis presentation provides a te
 chnical deep dive into how chained IDOR vulnerabilities can be escalated i
 nto zero-click RCE via persistent LLM conversation injection and unsafe El
 ectron IPC designs. To prove the real-world impact\, we will debut novel r
 esearch into Orchids\, a leading local\, Electron-based AI coding IDE with
  over a million users\, reported to be used by teams
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:VibeShell: How Trusting Your AI IDE Costs You Your Machine - Etizaz
  Mohsin
URL:https://cfp.romhack.io/romhack-camp-2026/talk/VZ7VY3/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-DZPHFB@cfp.romhack.io
DTSTART;TZID=CET:20261003T190000
DTEND;TZID=CET:20261003T200000
DESCRIPTION:Why is security operations know-how trapped inside proprietary 
 vendor platforms and siloed team wikis? Traditional SOCs operate at human 
 speed against machine-speed adversaries\, while commercial "AI SOC" tools 
 hide behind opaque black boxes and prohibitive costs. Meanwhile\, attempti
 ng to automate without common operational grammar leads to alert chaos\, h
 allucinations\, and inconsistent response actions that either disrupt busi
 ness operations or leave incidents partially unresolved.\nThe ZeroSOC init
 iative (zerosoc.org) is an early-stage open project (Apache-2.0\, v0.1 wor
 king draft) democratizing autonomous cyberdefense. Centered on the ZeroSOC
  Framework\, it explores Executor Neutrality — the principle that the sa
 me human-readable playbook can be executed interchangeably by a human anal
 yst\, deterministic automation\, or an AI agent —\, OCSF-aligned taxonom
 y\, and verifiable measurement gates.\nThis 1-hour interactive working ses
 sion aims to bring together SOC analysts\, detection engineers\, incident 
 responders\, and researchers at RomHack Camp to co-design and shape this e
 merging standard. Following a 15-minute introduction to the architecture (
 no prerequisites required)\, we will open the floor for a working group fo
 cused on the framework's foundational building blocks: Definitions & Taxon
 omy\, 4-Phase Processes\, Operational Metrics\, Agentic Guardrails\, and P
 laybooks. Come ready to challenge assumptions\, debate edge cases\, and he
 lp architect the open foundation for modern SecOps!
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:ZeroSOC Framework Working Session: Building the Open Standard for H
 uman & Agentic SecOps - Berghem-in-the-Middle
URL:https://cfp.romhack.io/romhack-camp-2026/talk/DZPHFB/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-3FTTEN-1@cfp.romhack.io
DTSTART;TZID=CET:20261003T190000
DTEND;TZID=CET:20261003T230000
DESCRIPTION:Hungry after a day of hacking? A wood-fired Pizza Truck parks o
 n site both evenings\, serving fresh pizza straight from a real wood oven.
 \n\nNo need to leave the woods for dinner — grab a slice\, grab a seat\,
  and refuel before or after the Hacker Cinema Night and the After Dark mus
 ic session.\n\nAvailable Friday and Saturday evening.
DTSTAMP:20260910T012503Z
LOCATION:FOOD AREA
SUMMARY:🍕 Pizza Truck — Wood-Fired Dinner - Pizza Truck
URL:https://cfp.romhack.io/romhack-camp-2026/talk/3FTTEN/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-QCMYJN@cfp.romhack.io
DTSTART;TZID=CET:20261003T191000
DTEND;TZID=CET:20261003T195000
DESCRIPTION:Supply chain security conversation is booming these days after 
 attacks like log4j came to the scene.\n\nIn this in-house research\, we ha
 ve conducted research on publicly available open-source assets like NPM (J
 S packages) and WordPress Plugins find out the presence of mistakenly or d
 eliberately publicly exposed secrets (including private API keys and so on
 ) i.e. AWS\, Google\, etc. (33 different categories of secrets!)\n\nThis c
 ould pose a risk to anyone using those packages as dependencies or plugins
  so that this chain of not re-inventing the wheel could become a disaster 
 that stops the wheel once and for all.\n\nWe would be presenting our resea
 rch done on a large scale after in-house scanning on:\n\n- Scanning of aro
 und 2 Million+ NPM Packages.  (almost all publicly available at the time o
 f research)\n- Scanning of about 60\,000 WordPress Plugins. (almost all pu
 blicly available at the time of research)
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Secret scanning in open source at scale (in-depth) - Hassan Khan Yu
 sufzai
URL:https://cfp.romhack.io/romhack-camp-2026/talk/QCMYJN/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-XQUFNN@cfp.romhack.io
DTSTART;TZID=CET:20261003T192000
DTEND;TZID=CET:20261003T200000
DESCRIPTION:How it was possible to have more that one independent scrolling
  plane in a C64 videogame? How it was possible to have more than the 8 dec
 lared sprites in a 50 frames per second game? We will explore the tricks a
 nd the strategies applied by most of the games of the C64 era\, including 
 my shoot-em-up game Catalypse. We will discuss about charset maps\, double
  buffering\, shifting chars but also about the software interrupts\, the s
 ynchronized drawing opportunities given by the VIC II graphic chipset and 
 the real-life sorting algorithm choices\, everything constrained inside a 
 complete screen raster time
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:The miracle of Plane and Sprite Multiplication - Andrea Pompili
URL:https://cfp.romhack.io/romhack-camp-2026/talk/XQUFNN/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-WCZZS9@cfp.romhack.io
DTSTART;TZID=CET:20261003T200000
DTEND;TZID=CET:20261003T230000
DESCRIPTION:You've definitely seen that guy shouting about some focaccia sa
 ying "bada 'ome la fuma"\nThat catchphrase somehow became part of Tuscany'
 s identity\, so why not embracing that? We'll serve you the classic fried 
 snack from pisa\, the _Sgabeo_\, prepared by fibonhack with love
DTSTAMP:20260910T012503Z
LOCATION:COMMUNITY AREA
SUMMARY:Bada home la fuma - gnocco fritto by fibonhack - fibonhack
URL:https://cfp.romhack.io/romhack-camp-2026/talk/WCZZS9/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-PUJVLA@cfp.romhack.io
DTSTART;TZID=CET:20261003T203000
DTEND;TZID=CET:20261003T223000
DESCRIPTION:One more night\, one more film.\n\nAfter a full day of hacking 
 and the CTF award ceremony\, we close Saturday under the open sky with [Th
 e Hitchhiker's Guide to the Galaxy](https://www.imdb.com/title/tt0371724/)
  (2005). Douglas Adams' tale of Earth's demolition\, improbable escapes\, 
 and one very useful towel — a reminder that the answer might be 42\, but
  the fun is in the questions.\n\nSame spot\, same spirit as Friday. Bring 
 your towel and Don't Panic.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Hacker Cinema Night - The Hitchhiker's Guide to the Galaxy (2005) -
  Cyber Saiyan
URL:https://cfp.romhack.io/romhack-camp-2026/talk/PUJVLA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-3T7KHN@cfp.romhack.io
DTSTART;TZID=CET:20261003T210000
DTEND;TZID=CET:20261003T230000
DESCRIPTION:When night falls\, the musical Tesla coils take the stage.\n\nF
 ollowing the afternoon talk\, VoltagePyromania turns high voltage into a s
 how: metre-long electric arcs\, synced to the music\, drawing lightning in
  the dark of the Camp. A concert played by electricity itself\, where reso
 nance\, high voltage and ionised air become light\, sound\, and emotion.\n
 \nAn immersive experience that blends science and entertainment. Come clos
 er (safely)\, look up\, and let it sweep you away.
DTSTAMP:20260910T012503Z
LOCATION:SHOW AREA
SUMMARY:Tesla Coil Live Show - michele pietravalle aka PHCV
URL:https://cfp.romhack.io/romhack-camp-2026/talk/3T7KHN/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-CUHGR3@cfp.romhack.io
DTSTART;TZID=CET:20261003T213000
DTEND;TZID=CET:20261003T223000
DESCRIPTION:In 1984 Ken Thompson\, during his Turing Award acceptance speec
 h\, introduced to the world a very interesting kind of backdoor\, describe
 d by himself as "the cutest program I have ever wrote". The speech has lat
 er been written in an article called "Reflections on Trusting Trust".\n\nT
 he idea is simple: modify a C compiler in order to insert a backdoor into 
 the login binary whenever the login.c program is compiled. The backdoor al
 lows a specific username to bypass authentication and obtain root privileg
 es. This is the simple step. Then comes the hack: the logic to introduce t
 he backdoor will replicate itself whenever the compromised compiler is use
 d to compile a new compiler. This means that once your compiler has been c
 ompromised\, it becomes very hard to get rid of it. Because how do you com
 pile a compiler? With the compiler you already have!\n\nThis workshop is a
 ll about compilers and backdoors. To make it practical we will apply it ag
 ainst a small but functional C compiler (TinyCC). We will show how to buil
 d a working Thompson backdoor step by step in a fun and reproducible way. 
 We will talk about quines\, about self-replication\, and ultimately about 
 why trust in software cannot be established by just reading the source cod
 e. The Thompson backdoor is now 40 years old\, yet it is more relevant tha
 n ever\, as modern supply-chain compromises e.g. SolarWinds can be reduced
  to similar trust-delegation problems in the supply chain of software as T
 hompson described.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:Trusting Trust\, Hands On: Building a Self-Reproducing Compiler Bac
 kdoor - Leonardo Tamiano
URL:https://cfp.romhack.io/romhack-camp-2026/talk/CUHGR3/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-HEPMEH@cfp.romhack.io
DTSTART;TZID=CET:20261003T223000
DTEND;TZID=CET:20261004T003000
DESCRIPTION:One more night\, one more set.\n\nAfter the Saturday film\, we 
 close the Camp's last full night the right way. Two hours of open-air musi
 c with the community.\n\nSame spirit as Friday\, one more chance to hang o
 ut under the sky before the Camp winds down.\n\nThe DJ line-up will be ann
 ounced closer to the Camp.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:After Dark - Saturday Music Session - Cyber Saiyan
URL:https://cfp.romhack.io/romhack-camp-2026/talk/HEPMEH/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-BLFNET@cfp.romhack.io
DTSTART;TZID=CET:20261004T100000
DTEND;TZID=CET:20261004T104000
DESCRIPTION:Imagine pwning a game from your childhood! \nWhat could possibl
 y go wrong with a cute Nintendo DS game?\n\nThis talk will include a brief
  overview of the game\, some useful details about Nintendo DS internals\, 
 the exploitation process\, and a few other interesting observations I made
  while reversing it.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Imagine: pwning your favourite Nintendo DS game! - daisy
URL:https://cfp.romhack.io/romhack-camp-2026/talk/BLFNET/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-QBPJBB@cfp.romhack.io
DTSTART;TZID=CET:20261004T100000
DTEND;TZID=CET:20261004T104000
DESCRIPTION:We used to treat every CVE as an alert. Each one meant dropping
  what we were building\, classifying severity\, chasing versions\, lightin
 g up the dashboard in red. Endless noise. That works when a serious vulner
 ability is a monthly event. It doesn't anymore. In 2025 the Linux kernel w
 as the single most reported product on the planet\, with thousands of CVEs
 \, **roughly ten every day\, from one project**. And its maintainers don't
  even rank them by severity\, so you can't sit back and wait for the "impo
 rtant" ones. Then the AI era poured fuel on the fire: 2026 is on track for
  **66\,000 CVEs**\, and a single AI model (Claude Mythos) recently surface
 d thousands of high severity flaws that remain **99% unpatched**. The floo
 d is now machine speed.\n\nWhen a CVE lands every few minutes\, you can't 
 sound the alarm every time. So we stopped. Today patching is just part of 
 the workflow\, and we fight AI with AI: automation ingests and rolls out t
 he patches\, while AI triages the flood down to what is actually exploitab
 le for each deployment. This talk shows how a small team keeps **hundreds 
 of Keycloak clusters and thousands of vulnerabilities** under control\, ev
 erywhere and anytime\, without adding a single delay to the product roadma
 p.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:When Even AI Writes the CVE - Luis Rubiera
URL:https://cfp.romhack.io/romhack-camp-2026/talk/QBPJBB/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-ELJLML@cfp.romhack.io
DTSTART;TZID=CET:20261004T100000
DTEND;TZID=CET:20261004T120000
DESCRIPTION:It is well known that humans are the weakest link in informatio
 n security.\nSocial engineering has emerged as a means to influence and ma
 nipulate individuals to achieve desired outcomes. In this presentation\, w
 e delve into the realm of social engineering\, exploring the art of behavi
 or alteration\, manipulation and persuasive communication.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 2 (GetRoot no Jutsu)
SUMMARY:So you're interested in social engineering? The very first steps - 
 Kirils Solovjovs
URL:https://cfp.romhack.io/romhack-camp-2026/talk/ELJLML/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-87DHLD-1@cfp.romhack.io
DTSTART;TZID=CET:20261004T100000
DTEND;TZID=CET:20261004T110000
DESCRIPTION:Ready to build?\nMove beyond theory and construct a full functi
 onal AI-powered podcast in this hands-on "Build with AI" workshop.\nWe'll 
 guide you through an end-to-end workflow\, leveraging specific Google AI a
 nd Cloud tools to transform an idea into publishable audio content.\n-Dive
  into practical prompt engineering with Google Gemini. You'll actively bra
 instorm niche topics\, outline a compelling episode structure\, and genera
 te a working script for a short podcast segment.\n-Take your Gemini-genera
 ted script and bring it to life. We'll use the Google Cloud Text-to-Speech
  API to synthesize natural-sounding voice audio\, experimenting with diffe
 rent voice profiles. You'll see how to generate audio files directly from 
 text.\n-We'll then explore how Google Cloud Run can serve as the backbone 
 for automating this workflow – designing a simple service architecture c
 apable of potentially taking script inputs and orchestrating the TTS gener
 ation and audio file delivery. \nWho is this for? Developers\, creators\, 
 and tech enthusiasts that want to apply latest Google's AI and Cloud tools
  to the content creation challenges.
DTSTAMP:20260910T012503Z
LOCATION:WORKSHOP 1 (Neon Genesis Exploitation)
SUMMARY:Zero to podcaster\, start today your show with AI! - Nicola Gugliel
 mi
URL:https://cfp.romhack.io/romhack-camp-2026/talk/87DHLD/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-PRSQPQ@cfp.romhack.io
DTSTART;TZID=CET:20261004T104000
DTEND;TZID=CET:20261004T112000
DESCRIPTION:The infrastructure team built out an automated and orchestrated
  solution to simplify it all\, access\, scaling ect. Alas the team who bui
 lt it has left or is allocated to another project\; services and infrastru
 cture are breaking. This session will examine the challenges of lifecycle 
 management that IaC can create\, and uncover a few strategies you can use 
 to prevent it.
DTSTAMP:20260910T012503Z
LOCATION:STAGE 2 (Ghost in the Shellcode)
SUMMARY:When IaC goes wrong - Sean Juroviesky
URL:https://cfp.romhack.io/romhack-camp-2026/talk/PRSQPQ/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-N93XCA@cfp.romhack.io
DTSTART;TZID=CET:20261004T110000
DTEND;TZID=CET:20261004T114000
DESCRIPTION:This talk presents a real-world penetration test of a global pl
 atform with over 30 million users\, where a series of seemingly isolated v
 ulnerabilities were transformed into a complete attack chain that resulted
  in full system compromise.\n\nAttendees will follow the attacker's path a
 s trust boundaries are systematically dismantled through exposed secrets i
 n public JavaScript\, session abuse\, cross-application trust violations\,
  and critical CORS and WAF misconfigurations. What begins as a handful of 
 low-risk findings rapidly escalates into the exposure of production creden
 tials\, cryptographic keys\, and complete control over the platform.\n\nTh
 is is a technical autopsy of how small cracks can align to create a catast
 rophic failure and a front-row seat to how attackers turn scattered weakne
 sses into total compromise!
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Chain Reaction - From Isolated Vulnerabilities to Full System Compr
 omise - Rana
URL:https://cfp.romhack.io/romhack-camp-2026/talk/N93XCA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-UW8HAH@cfp.romhack.io
DTSTART;TZID=CET:20261004T120000
DTEND;TZID=CET:20261004T123000
DESCRIPTION:As three incredible days of hacking\, learning\, and community 
 life come to an end\, it’s time to gather for the RomHack Camp 2026 clos
 ing remarks.  \n\nIn this final session\, the Cyber Saiyan team will look 
 back at the best highlights of this second edition\, sharing key event ins
 ights\, memorable milestones\, and our collective achievements. \nMost imp
 ortantly\, we want to express our deepest gratitude to our brilliant speak
 ers\, the independent community groups who brought the villages to life\, 
 our supportive sponsors\, and our tireless team of volunteers who made thi
 s event possible. \n\nJoin us to wrap up the camp\, celebrate the communit
 y\, and get a quick sneak peek at what’s next on the roadmap for Cyber S
 aiyan.  Safe travels home!
DTSTAMP:20260910T012503Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:RomHack Camp Closing - Cyber Saiyan
URL:https://cfp.romhack.io/romhack-camp-2026/talk/UW8HAH/
END:VEVENT
END:VCALENDAR
