RomHack Camp 2026

The speaker's profile picture
Abdel Adim `smaury` Oisfi

Abdel Adim 'smaury' Oisfi is co-founder of Shielder, an Italian offensive security boutique. His research interests center on web and application security, browser internals, and the long tail of "old" bug classes that refuse to die. He has discovered and coordinated the disclosure of vulnerabilities in widely used software, won live hacking events, and spoken at international conferences. He also co-organizes TumpiCon and is a retired CTF player with JBZ.

  • A call for collective action on cyber defense
The speaker's profile picture
Abdulrahman Nour
  • Shells Without Phish
The speaker's profile picture
Agnese

Gen C64
Armed with a Master’s in Statistics and a background in Mathematics to uncover when things are not what they seem.
Proud mother of two, committed to a safer and fairer world, actively supporting environmental sustainability, digital rights, and advocacy against gender-based gap and violence

  • AI4KIDS laboratorio di introduzione all'intelligenza artificiale
The speaker's profile picture
Alessandro Farina

So, who actually is Alessandro? Catch him on a weekend and you'll probably find him knee-deep in malt and hops, brewing his own craft beer, or hunting for the perfect shot with his camera. But don't let the chill vibes fool you — in his spare time he moonlights as an information systems designer and developer, with a quiet but serious streak in cybersecurity and digital forensics.

A true veteran of the digital world (let's just say he's been around the block), his experience is anything but textbook. He's spent years "in the trenches," digitizing business processes and leading complex projects for both small and medium-sized companies and public sector organizations.

He's played around with pretty much everything — classic Client/Server architectures, cloud setups on Azure and AWS, all the way to high-availability (HA) configurations.

He's also been spotted hanging out with the LE on more than one occasion — but somehow always made it home perfectly fine. Rumor has it he's committed every cybercrime you can think of (and some you can't).

Oh, and fair warning — his passion for digital forensics is contagious. Once he starts "playing," he has a way of dragging even complete strangers along into his world of bits and investigations.

  • Hands-On Forensic Imaging and Data Extraction from Windows and macOS Using Free and Open Source Tools
The speaker's profile picture
Andrea Cappa

Andrea Cappa (zi0Black) is Security Lead at Aptos Labs, where he oversees all things security. A former penetration tester at Shielder, he now spends his time exploring how AI can be applied to security in real-world environments, as well as the human factors behind security incidents and system failures.

  • A review bot that just works
  • A call for collective action on cyber defense
The speaker's profile picture
Andrea Pompili

Andrea Pompili is an information technology specialist that takes care of security. He joined the computer's world with one of the most famous Italian games based on the C64 platform. Once graduated, he started working first in the software development market, and then in computer security, following security threats and solutions on strategic projects. Currently Andrea is a strategy advisor in Cyber Security, and aims to discover and integrate innovative solutions for this connected world

  • From Hero to Zero: The FatalNoise neverending story
  • The miracle of Plane and Sprite Multiplication
  • Why I've to waste my (precious) time on cryptography?
The speaker's profile picture
Arturo Di Corinto

Researcher and teacher in cognitive and communication psychology, graduated in Rome, he specialized in persuasion technologies at Stanford University, California.

Author at Treccani, journalist specialized in innovation and cybersecurity, he has published 2300 journalistic articles for national newspapers working for Il Sole24Ore, Wired and L'Espresso, Il Manifesto and La Repubblica. Reporter for the Rai Uno television program “Codice. All life is digital”, he is also an author and television presenter.

Arturo Di Corinto has written many publications with ISBN and several books, including Hacktivism (2002, Manifestolibri), Revolution OS II (2006, Apogeo/Feltrinelli), I nemici della rete (2010, Rizzoli), Un dizionario hacker (2014, Manni), Il futuro Trent’anni fa (2017), Riprendiamoci la rete! Piccolo manuale di autodifesa digitale per giovani generazioni (Eurilink, 2019).

Professor of Digital Identity, Privacy and Cybersecurity in the faculty of Political Science, Sociology and Communication at the Sapienza University of Rome, he is currently advisor at the National Cybersecurity Agency in charge of its special projects.

  • Guerra Profonda. Hacker, bugie e l'architettura segreta dei nuovi conflitti
The speaker's profile picture
Berghem-in-the-Middle

Berghem-in-the-Middle (BITM) is a non-profit founded by information security enthusiasts and professionals in northern Italy, in an open and friendly environment fostering technical development and knowledge sharing. Since 2019 it hosts No Hat, an international security conference gathering researchers and specialists in Bergamo.

You can find BITM in the Community Area.

  • "tradizionale" polenta taragna di Berghem-in-the-Middle
  • ZeroSOC Framework Working Session: Building the Open Standard for Human & Agentic SecOps
The speaker's profile picture
Bullismo No Grazie

Bullismo No Grazie è un'associazione no profit fondata nel settembre 2021. Nata da un incontro e da una visione condivisa, l'associazione riunisce professionisti di diversi settori con l'obiettivo comune di contrastare il bullismo, il cyberbullismo e il revenge porn attraverso formazione, informazione e prevenzione rivolte a giovani, genitori e insegnanti.

Dal 2021 a oggi l'associazione ha incontrato oltre 18.000 docenti, 90.000 adulti e circa 200.000 ragazzi in più di 100 località, percorrendo oltre 150.000 km in tutta Italia per portare la propria testimonianza nelle scuole di ogni ordine e grado.

Tra le attività principali figura la campagna "Il Bullismo Non Va in Vacanza", realizzata nelle estati dal 2022 al 2026 in collaborazione con il tour operator Fruit Viaggi, prima e unica campagna contro il bullismo condotta in presenza nei villaggi turistici italiani. L'associazione ha inoltre prodotto il cortometraggio "Non Vi Lasceremo Soli" e diretto "Il Coraggio di Parlare", presentato nel maggio 2025 e interpretato da 27 studenti dell'Istituto Comprensivo di Borgaro Torinese.

Bullismo No Grazie è stata presente alla Camera del Senato, ha partecipato a convegni organizzati dal CSI Piemonte con la Città Metropolitana di Torino e dalla Regione Veneto, ha curato la mostra fotografica "Combattere il Bullismo" nel 2024 e ha preso parte a più edizioni di Fiera Didacta Italia. Ha collaborato con il Parlamento Europeo in Italia e con numerose istituzioni locali e aziende su tutto il territorio nazionale.
https://www.bullismonograzie.it/

  • Il bullismo non va in vacanza
  • Il bullismo non va in vacanza
The speaker's profile picture
CYBERANTANI

Luca Bongiorni (@CyberAntani) is working as Director of a CyberSecurity Lab and is Founder of WHID - We Hack In Disguise ( www.whid.ninja ): a cybersecurity boutique focused on R&D offensive hardware implants and IIoT Security. Luca is also actively involved in InfoSec where his main fields of research are: Radio Networks, Hardware Hacking, Internet of Things, and Physical Security. He also loves to share his knowledge and present some cool projects at security conferences around the globe: BlackHat Europe & USA, TROOPERS, HackInParis, DEFCON, HackInBo, Defcon Moscow, OWASP Chapters, Security Analyst Summit, etc. At the moment, he is focusing his researches on bypassing biometric access control systems, IIoT Security & Forensics, Air-Gapped Environments and IoOT (Internet of Offensive Things).

  • PhySec Lab Part 1: Lockpicking 101
  • PhySec Lab Part 2: Hacking Physical Access Control Systems
The speaker's profile picture
Carmela Occhipinti e Marco Pratesi

Carmela Occhipinti: cofondatrice e Managing Director di Cyberethics Lab. è laureata in Scienze politiche, ricercatrice ed esperta di innovazione. Ha lavorato per 24 anni come responsabile del Security and Privacy Lab in una grande azienda ICT italiana. Ha conseguito certificazioni PMP, ITIL Expert, PRINCE2 e SCRUM Master ed è membro dell’Italian Chapter of the International Information Security System Certification Consortium (ISC)2. Grazie al suo background professionale, è esperta di impatti sociali delle nuove tecnologie, soprattutto nel campo etico e sociale. Insegna Diritto della privacy in numerosi corsi di Project e Service Management per aziende private e pubbliche. È ricercatrice in diversi progetti europei, soprattutto nel campo della sicurezza, in cui ricopre ruoli come Coordinatrice di progetto, Direttrice tecnica, Innovation Manager, Dissemination Manager ed Ethical Manager. Negli ultimi anni, i suoi interessi di ricerca si sono spostati su problemi di privacy e protezione dei dati. Ha collaborato con uno studio legale italiano e partecipa a commissioni europee per i progetti Horizon 2020, supportando i partner per la gestione dei problemi etici e di privacy.

Marco Pratesi: è un ingegnere del software con una formazione trasversale tra musica e tecnologia. Dopo aver conseguito una laurea presso il Conservatorio “Alfredo Casella” de L’Aquila, ha proseguito il suo percorso accademico in Ingegneria Informatica presso l’Università di Roma Tor Vergata. È esperto in sistemi operativi, gestione dei processi e progettazione di architetture software. Marco ha sviluppato competenze nell’analisi e nello sviluppo di sistemi complessi, con particolare attenzione all’ottimizzazione delle performance e all’efficienza dei processi informatici. Collabora a progetti multidisciplinari che uniscono creatività e innovazione tecnologica, contribuendo con una visione integrata tra arte e ingegneria.

  • Prove It Without Telling Me Who You Are
The speaker's profile picture
Chiara Ciccia Romito

Avvocata ha conseguito un Dottorato di ricerca presso l?Università degli Studi di Modena e Reggio Emilia con una tesi di ricerca su Intelligenza Artificiale e mondo delle imprese, certificata 27001/2022 è autrice per diverse case editrici, da ultimo Sicurezza dei dati nelle PMI edito Lefbvre Giuffrè 2026.

  • Incontro con la gang ransomware Schrodingercat.
The speaker's profile picture
Christian <cy> Kühn

Christian has worked in most fields in IT. From yawning in the Datacenter swapping hard drives at 03:00 in the night, through administrating and consulting on large-scale networks he rode the devops-wave over into development. While infosec had been a sidetrack for many years, he is now fully engaging in security engineering and consulting, helping secure one of Europe's largest retail companies.

  • Developers under attack - how to protect yourself
The speaker's profile picture
Cyber Saiyan

Cyber Saiyan is a non-profit cultural association founded in 2017. Our goal is simple: raising awareness and providing education in the field of cyber security.

We are the proud organizers of RomHack, an initiative built by the community, for the community. What started as a yearly technical conference has evolved to include intensive, hands-on Training sessions and an immersive three-day Hacker Camp in Rome.

Beyond our core events, we actively promote independent projects and collaborations, such as the editorial initiative "Guerre di Rete".

Involving the community is very important to us. We strive to foster curiosity, sharpen skills, and create welcoming spaces where enthusiasts, researchers, and professionals can connect and share their knowledge.

More info: https://cybersaiyan.it/

  • RomHack Camp Opening
  • RomHack Camp Closing
  • Hacker Cinema Night - Sneakers (1992)
  • Hacker Cinema Night - The Hitchhiker's Guide to the Galaxy (2005)
  • After Dark - Friday Music Session
  • After Dark - Saturday Music Session
The speaker's profile picture
Davide Baraldi

Hacker | Master Chief at CR1PT0 | Cyber Security Researcher | Cyberwarfare Specialist Consultant | Cryptographer | Bitcoiner | Veteran.

Ex operatore Militare e di Polizia Militare. Operatore presso N.E.D. e altre infrastrutture distaccate. C.S.O., C.I.S.O., docente presso Plan B Network e Security Cert, speakers a LUGMan, Satoshi Spritz ed eventi Bitcoin.

  • Incontro con la gang ransomware Schrodingercat.
The speaker's profile picture
Davide Inzerillo

With 15 years of experience in the software industry, I have transitioned from test automation to full-stack development, always maintaining a strong focus on secure coding practices and authentication protocols. Currently, I am a developer at Mentat, where I build solutions tailored for SOC analysts, blue teams, incident responders, and digital forensics experts. I work on Gulp, a tool we utilize to streamline incident response workflows. Outside of my professional role, I am a contributor to the Security Cert community.

  • GULP: See the Attack. Understand the Story. Prove the Facts
The speaker's profile picture
Doc

Mattia — "Doc" to most people — is a Senior Defense Security Engineer at Satispay, where he works across the full defensive stack: detection engineering, monitoring, incident response and security automation for a European fintech. Splunk and n8n are two of his everyday tools, but the job spans the whole blue-team surface — building the systems that catch attacks and the automation that responds to them safely. He's spent years turning noisy signals into actions a SOC can trust, and is increasingly focused on where AI fits into that loop: genuinely useful for triage, dangerous without guardrails. Doc believes the hard problem in security automation isn't automating the response, but automating it safely — and would rather prove it with a working lab than a deck. This is his first time on the RomHack stage.

  • Keep caLLM and Let It Block: Agentic SOAR with n8n + Splunk
The speaker's profile picture
Dr. Commodore 65

Carlo Pastore is an Italian medical oncologist and a long-standing enthusiast, collector, and researcher in the field of retrocomputing, with a particular focus on Commodore and Amiga history.
Alongside his professional activity in medicine, he has cultivated for many years a deep passion for the machines, people, prototypes, stories, and technological culture that shaped the home computer revolution of the 1980s and 1990s. His work as a collector is not limited to preserving hardware: it is strongly connected to historical research, documentation, outreach, and the desire to keep alive the memory of a generation of computers that changed the relationship between people and technology.
He is especially known in the Italian Commodore and Amiga community for his interest in rare and prototype machines, including the Commodore 65, unreleased Amiga hardware, development boards, expansion cards, and historically significant items linked to Commodore’s final years. Over time, he has built contacts with former Commodore and Amiga engineers, developers, managers, and collaborators, collecting testimonies, documents, technical information, and personal memories that help reconstruct a complex and often fragmented history. Carlo is also active in the promotion of retrocomputing culture through talks, articles, books, social media, and public events. He has contributed to spreading knowledge about Commodore history in Italy, with particular attention to the educational, emotional, and cultural value of vintage computers. His approach combines technical curiosity, historical passion, and the belief that these machines are not merely obsolete objects, but witnesses of creativity, innovation, and personal discovery. As Scientific Director of the Museo del Videogioco di Roma – GAMM, he works to support the preservation and public presentation of the history of video games and home computing, with the aim of making this heritage accessible to new generations.

  • The Commodore 65: the dream that never arrived
The speaker's profile picture
Etizaz Mohsin

Etizaz Mohsin is a cybersecurity researcher focused on advanced threat research and offensive security. His work has explored real-world attack techniques used by sophisticated adversaries, including research on NSO Group's Pegasus spyware, which he presented at Black Hat MEA. Earlier in his career, he investigated the DarkHotel espionage campaign targeting executives and diplomats through compromised hotel networks.

His research has been featured by outlets such as Forbes, BBC, Wired, TechCrunch and Al Jazeera. He has presented at international security conferences including Black Hat Middle East and Africa, HITCON, 44CON, CONFidence, DeepSec, SECTOR, Hacktivity, GreHack, HackFest, and Wild West Hackin' Fest.

  • VibeShell: How Trusting Your AI IDE Costs You Your Machine
The speaker's profile picture
Fabio Fabrizi

Software architect freelance, progetto e sviluppo soluzioni digitali per aziende, cercando di trasformare problemi complessi in strumenti semplici e utili. Negli ultimi anni seguo lo sviluppo IA, automazione e nuovi modi di interagire con la tecnologia.

  • Anatomia di un DRM editoriale
The speaker's profile picture
Fabio Pietrosanti (naif)

Fabio Pietrosanti has been part of the digital underground with the nickname “naif” since 1995, while he’s been a professional working in digital security since 1998. President and co-founder of the Hermes Center for Transparency and Digital Human Rights, he is active in many projects to create and spread the use of opensource tools in support of freedom of expression and government transparency.

He is among the founders of the anonymous whistleblowing GlobaLeaks project, nowadays used by investigative journalists, citizen activists and the public administration for anti-corruption purposes. Expert in technological innovation in the field of whistleblowing, transparency, communication encryption and digital anonymity.

Like to engage in techno-activistic initiatives where technology intertwined with administrative laws and a bit of trolling, bring a benefit for the public good, like with MonitoraPA that in 2022 eradicated Google Analytics from most of Italian Public Agencies with more than 100.000 PEC sent in an activistic campaign ;)

  • MXMap Italia: National Observatory for Digital Sovereignty
The speaker's profile picture
Fleeenz
  • Pwn the Pipeline: A Hands-On Tour of CI/CD Security Risks
The speaker's profile picture
Fortra

Fortra builds data-centric cybersecurity — and hackers know them best for their offensive security tooling: Cobalt Strike, Core Impact and Outflank, for adversary simulation, pentesting and red teaming.

  • [Sponsor workshop] Introduction to Cobalt Strike: Command & Control and Code Execution Fundamentals
The speaker's profile picture
Francesco Infantini

My interest in technology started with a curiosity about how systems work and how they break. That curiosity eventually led me into infrastructure administration, where I spent several years managing enterprise environments and supporting critical systems.

Over time, I became increasingly interested in cybersecurity, particularly offensive security and adversary tradecraft. Today, I work as a penetration tester, conducting security assessments and red team engagements focused on identifying realistic attack paths and helping organizations strengthen their security posture.

My areas of interest include Active Directory security, Windows internals, command and control frameworks, and detection evasion. I hold the CRTO certification and continue to focus on developing practical offensive security skills through research, training, and real-world engagements.

  • State Trojan: The Malware with a Warrant
The speaker's profile picture
Francesco Viscardi
  • Keep caLLM and Let It Block: Agentic SOAR with n8n + Splunk
The speaker's profile picture
Giorgio Dell'Immagine

Giorgio Dell'Immagine is a cryptography engineer and security researcher at zkSecurity, where he focuses on the security of modern cryptographic systems. He has conducted numerous audits for industry-leading projects, spanning cryptographic protocols, zero-knowledge proof constructions, and smart contracts. He also has extensive experience competing and organizing CTFs with the team "fibonhack" based in Pisa.

Giorgio holds an MSc from the University of Pisa, where he graduated with a thesis on the construction of a post-quantum signature scheme. More information can be found at his website daltron.de

  • Just one proof away: the cryptography behind private payments
The speaker's profile picture
Giuseppe
  • Stupid Sexy Bearer Tokens: a deep dive into exploding OIDC sessions and hardening with DPoP
The speaker's profile picture
Guerre di Rete

Guerre di rete è un progetto editoriale frutto dell'impegno di due associazioni culturali: l’omonima Guerre di Rete, che per anni ha pubblicato una newsletter settimanale dedicata alla cybersicurezza a firma Carola Frediani (venuta a mancare il 3 Giugno 2026) e [Cyber Saiyan](url, una community indipendente di professionisti del settore della cybersicurezza.

https://www.guerredirete.it/il-progetto/

  • Presentazione "Manualetto di sicurezza digitale per giornalisti e attivisti"
  • Presentazione libro "L'inganno dell'Automa" di Carola Frediani
The speaker's profile picture
Hassan Khan Yusufzai

Hassan Khan Yusufzai is the Director and Co‑Founder of Laburity, bringing deep experience in the internet‑wide scanning, red teaming, penetration testing, threat intelligence and dark web monitoring. He combines deep technical research with practical, hands-on offensive security work to help organizations find and fix real-world security issues across different industries.

Hassan is an in‑demand speaker who shares his research and practical findings at international security conferences. He has presented at Cyber Security Asia 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗥𝗲𝘀𝗶𝗹𝗶𝗲𝗻𝗰𝗲 𝟮𝟬𝟮𝟲, DeepSec 2025, OWASP AppSecDays 2025, BlackHat MEA (Riyadh) in 2022, 2023 and 2025, ThreatCon 2023, MCTTP Munich Cyber Tactics, Techniques & Procedures (MCTTP) 2024, HITBSecConf 2024, and the Security Analyst Summit in Phuket in 2024.

Hassan holds the Offensive Security Certified Professional (OSCP) certification, reflecting his solid technical mastery of penetration testing and exploit development techniques.

Hassan has identified and reported over 200 CVEs to date and was recognized as one of the top hackers by WPScan for his contributions to WordPress security. His responsible vulnerability reporting has been widely recognized: in 2017 Hassan was listed in the Google Security Hall of Fame, the Twitter Security Hall of Fame, and the Microsoft Security Hall of Fame for contributions that improved the security of major platforms.

Hassan develops tools and techniques for at-scale security research and analysis, designed to handle large datasets. His work focuses on efficiency and scalability, enabling faster identification of vulnerabilities across massive environments.

  • Secret scanning in open source at scale (in-depth)
The speaker's profile picture
Hatem Mohamed

Hatem is a Principal Red Team Consultant at Google Cloud, in the META region, with extensive experience in various domains of cybersecurity. He excels in planning and executing red team operations, identifying flaws and weaknesses in systems, and leveraging his experiences to identify and exploit hard-to-find vulnerabilities. His broad expertise in providing offensive security services enables him to quickly identify viable attack paths, assess their real risks, and devise effective mitigations at strategic, operational, and tactical levels. Currently, his focus is on performing Red Team operations and adversary simulations, emphasizing adversary strategy, operational design ,and enterprise post-exploitation.

  • Command and Collusion: Flipping the C2 Model for No-Egress Environments
The speaker's profile picture
IadRabbit
  • Pwn the Pipeline: A Hands-On Tour of CI/CD Security Risks
The speaker's profile picture
Italmaker

Emiliano Gatti è professionista nel settore della formazione STEM e progettista di esperienze educative innovative dedicate a coding, robotica, making e nuove tecnologie.

Opera professionalmente con Italmaker, sviluppando percorsi, laboratori e format rivolti a bambini, ragazzi, scuole e docenti, con l’obiettivo di trasformare la tecnologia in uno strumento per allenare logica, creatività, problem solving, pensiero computazionale e capacità di collaborazione.

È inoltre Presidente di Italmaker – Accademia dell’Inventore, realtà impegnata nella diffusione della cultura maker e dell’educazione tecnologica.

Negli anni ha ideato e realizzato workshop, percorsi didattici, competizioni ed esperienze STEM basate sull’apprendimento attraverso il fare, la sperimentazione, la robotica educativa e la prototipazione.

Ha partecipato a Maker Faire Rome con progetti dedicati all’innovazione educativa, ottenendo nel 2025 il riconoscimento Maker of Merit.

A Rome Hack presenta in anteprima Brain Arena, il nuovo format educativo che trasforma coding e robotica in un vero allenamento della mente attraverso missioni, strategia, sfide e problem solving.

  • Brain Arena
The speaker's profile picture
Jacopo Jannone

Jacopo Jannone is a computer engineer specialized in offensive cybersecurity. He has a strong passion for reverse engineering, which as an information security professional he mainly applies to the analysis of mobile, web and native applications. His interests extend to identification systems, radio frequency communications, embedded systems, and electronics. In his daily job he manages the offensive security team at Satispay, while in his free time he performs security research, develops open source projects, plays CTF competitions, and reverse engineers anything he finds interesting.

  • Cash, Card or Root? Security Archaeology of a Fiscal Cash Register
The speaker's profile picture
Jacopo Moioli

Jacopo Moioli is an Offensive Security Engineer at Satispay, trying to break things before others do. Before that, he spent two years in consultancy as a penetration tester and red teamer.

This is his first talk at a security conference. Outside cybersecurity, he is interested in space, aviation and other technical rabbit holes.

  • Cash, Card or Root? Security Archaeology of a Fiscal Cash Register
The speaker's profile picture
Julien Bedel

Julien is a French security researcher and red team operator at Orange Cyberdefense, where he conducts offensive security assessments and develops tradecraft for adversary emulation.

With a background in software development, his research focuses on offensive security, ranging from password manager security to DCOM abuse. He is also a contributor to open-source security projects including Scapy, Metasploit, Impacket, CrackMapExec, and KeePwn.

His research has been presented at conferences including Black Hat MEA, BruCON, hack.lu and leHACK.

  • Stop Injecting, Start Blending: A KISS Approach to Malware Development
The speaker's profile picture
Kirils Solovjovs

Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist. He began programming at age 7, and by grade 9 was already writing machine code directly in a hex editor during lunch breaks. Renowned for uncovering and responsibly disclosing critical vulnerabilities in national and international systems, he is an expert in network flow a
Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist. He began programming at age 7, and by grade 9 was already writing machine code directly in a hex editor during lunch breaks. Renowned for uncovering and responsibly disclosing critical vulnerabilities in national and international systems, he is an expert in network flow analysis, reverse engineering, and social engineering. A lifelong command-line enthusiast, he uses bash daily for hacking, automation, and large-scale data processing.
He is the author of the jailbreak tool for MikroTik RouterOS and played a pivotal role in developing e-Saeima, the world's first fully remote legislative system used by the Latvian Parliament. Today, Kirils serves as lead researcher at Possible Securitynalysis, reverse engineering, and social engineering. A lifelong command-line enthusiast, he uses bash daily for hacking, automation, and large-scale data processing.
He is the author of the jailbreak tool for MikroTik RouterOS and played a pivotal role in developing e-Saeima, the world's first fully remote legislative system used by the Latvian Parliament. Today, Kirils serves as lead researcher at Possible Security

  • Command-Line Alchemy: Turning Scripts into Superpower
  • So you're interested in social engineering? The very first steps
The speaker's profile picture
Leonardo Tamiano

I've discovered the beauty of Computer Science by reading "The Universal Computer - The Road from Leibniz to Turing" By Martin H. Davis and "Gödel, Escher, Bach: an Eternal Golden Braid
" by Douglas Hofstadter. Since then, I've been deeply fascinated by the subject. I went to university to study the theory behind computation, algorithms and programming languages, and it is during university that I also met the technicalities behind the beautiful world of computer hacking.

After university I worked as a penetration tester and cybersecurity trainer where I was able to learn the practical challenges that many business have to face when dealing with security from a management point of view as well as from a technical point of view.

Recently I've become a freelance trainer in Italy, helping companies on cybersecurity related topics such as secure coding and threat modeling, and I've started an independent educational project called Esadecimale, which aims to become one of the best places in Italy to learn about Computer Science, programming and Hacking.

  • Trusting Trust, Hands On: Building a Self-Reproducing Compiler Backdoor
The speaker's profile picture
Lorenzo Dina (joecondo)

Lorenzo Dina is a serial tinkerer, explorer, and cybersecurity enthusiast who has been passionate about networks and information security since a young age. About twenty years ago, he took a step in what he likes to call the “right” direction, turning that passion into a professional career across cybersecurity, digital forensics, and information security management.

He works also as a trainer for companies and universities, regularly contributes as a panelist at corporate events, and speaks at conferences within the cybersecurity community.

  • 2038: The Next Epochalypse — Breaking time before it breaks us
The speaker's profile picture
Lorenzo Valeriani

As a CNIT mobile security researcher, Lorenzo Valeriani spends his time breaking phones (ethically, of course) and working towards a Ph.D. at the University of Rome Tor Vergata, where he also holds a Master's degree in Computer Engineering. His research focuses on the behavioural analysis of Android malware, new attack and defence strategies and the study of emerging protocol technologies such as eSIMs.

  • Ghost in the SIM: Silent, Zero-Click, Over-the-Air Exploitation of a Pixel 9 Baseband OOB Read
The speaker's profile picture
Lucrezia

I'm Lucrezia and I've been in the RomHack staff since the beginning. During past RomHack's conferences I've helped with the Kids' workshops. I'm 17 and I'm on my last year of high school and I plan to study aerophysics when I go to university.

  • Braccialetti DIY
The speaker's profile picture
Luis Rubiera

CTO, open source believer, and full time challenger of "that's how it's always been done." I'm fascinated by how the past explains the present, and how technology quietly rewrites both. For years I've been trading ideas about SaaS, security, and open source from stages and classrooms, nudging people to rethink how we build and who we build with. I run a cybersecurity company with one foot planted firmly in the future, still convinced AI can be a force for good.

  • When Even AI Writes the CVE
The speaker's profile picture
Marco Pratesi

Marco Pratesi is a software engineer with a multidisciplinary background in both music and technology. After earning a degree from the “Alfredo Casella” Conservatory in L’Aquila, he pursued his academic path in Computer Engineering at the University of Rome Tor Vergata. He is skilled in operating systems, process management, and software architecture design. Marco has developed expertise in the analysis and development of complex systems, with a particular focus on performance optimization and process efficiency. He collaborates on multidisciplinary projects that combine creativity and technological innovation, contributing with an integrated perspective that bridges art and engineering.

  • Prove It Without Telling Me Who You Are
The speaker's profile picture
Marco d'Itri

Marco d'Itri has been involved with Internet operations and policy in Italy since the late '90s, and has been a Debian Developer for almost 30 years.
In Debian, he likes to maintain system packages like netbase, kmod, udev and ppp, Vinyl Cache, the BGP RPKI ecosystem and much more.

  • The state of systemd security sandboxing in Debian
The speaker's profile picture
Mathew Caplan

Mathew Caplan has spent more than 25 years helping organisations navigate cybersecurity challenges and build resilience in an increasingly complex world.

As Director of Professional Services at Orange Cyberdefense⁠, he advises organisations around the world on how to strengthen resilience, manage cyber risk and build trust.

Alongside his leadership role, he is an international cybersecurity speaker and storyteller who turns complex security problems into memorable tales.

Known for blending music, movies and real-world experience, Mathew makes complex cybersecurity concepts understandable, memorable and engaging.

  • Last Night a DJ Erased My Drive
The speaker's profile picture
Matteo Vitali (trotto)

Python backend developer and DevOps
Sociologist by training and passionate about computer science.
Gnu/Linux user, free and open-source software advocate.
Develop in Python and Django is my favorite way to build things.
Python Marche founder and co-organizer

  • Codice Python Sicuro: Buone Pratiche e Strumenti di Analisi
  • Argus SBOM Guard: gestione delle vulnerabilità a partire dagli SBOM
The speaker's profile picture
Matthew

Mateusz Wójcik, an independent security researcher, red team operator, and former programmer specializing in IoT security, loves to find new vulnerabilities in IoT devices, especially those based on architectures like ARM and MIPS.

  • Breaking the Charge: Security Analysis of the Phoenix Contact CHARX SEC-3000 EV Charging Controller
The speaker's profile picture
Mattia Brollo
  • Pwn the Pipeline: A Hands-On Tour of CI/CD Security Risks
The speaker's profile picture
Maurizio Argoneto

AWS HERO | Senior Engineering Manager | IT Strategy & AI Governance | Infrastructure Architect | Bridging Tech & Business Goals

Trasformo la visione di business in infrastrutture tecnologiche scalabili e performanti. Con oltre 15 anni di esperienza, di cui 10+ focalizzati su architetture Cloud-native e governance di programmi complessi, guido la digitalizzazione della Pubblica Amministrazione e delle imprese con un approccio "hands-on" che garantisce concretezza e velocità di delivery.

Perché collaborare con me:

  • Governance su larga scala: Ho gestito portafogli progetti >4M€, coordinando team multi-vendor di 50+ persone con piena responsabilità su budget e KPI.
  • Efficienza operativa: Ho ridotto i cicli di release del 60% attraverso l'adozione di pratiche DevOps, CI/CD e Infrastructure as Code (Terraform).
  • Visione Architetturale: Guido migrazioni cloud end-to-end (AWS) e modernizzazione di sistemi legacy tramite API-first design e microservizi.
  • Leadership & Community: Founder di GDG e AWS User Group Basilicata, credo nel valore dell'evangelismo tecnologico e della formazione come motori di crescita aziendale.

Specializzato nel "bridging" tra stakeholder C-level e team di sviluppo, garantisco che ogni scelta tecnologica sia un investimento orientato al valore.

  • SBOM SBAM: Who Put This in My Code? Enterprise-Grade Supply Chain Security on a Zero Budget
The speaker's profile picture
Max 'Sparrrgh' Bellia

Security researcher with experience in offensive security in various contexts, mainly web and binary exploitation.

They have a passion for optimizing vulnerability research processes, making finding bugs easier and faster. They do this mainly by developing custom SAST and DAST tooling. Currently working as a security engineer at Secure Network, in Milan.

  • "Don't crash" challenges walkthrough
The speaker's profile picture
Max Derkach

I'm a cybersecurity Pre-Sales Engineer and Security Architect with over 12 years of experience designing, implementing, and integrating enterprise security solutions across organizations of every size and scale.
In my spare time, you'll probably find me reversing binaries, solving CTF challenges, building random lab environments, or disappearing down a rabbit hole of some new technology that caught my attention. I enjoy taking things apart, understanding the details, and putting them back together, ideally better than before.

  • You Don't Need a Security Solution
The speaker's profile picture
Moataz Moustafa

Moataz is a cybersecurity expert with over a decade of extensive experience specialising in offensive security. Presently working as a Senior Consultant at Google APT66 advanced offensive security services. Moataz focus lies within the realms of red teaming and intelligence analysis.

  • Command and Collusion: Flipping the C2 Model for No-Egress Environments
The speaker's profile picture
Mohamed Elsayed

Mohamed is a senior Red team consultant at Google Cloud Security - Mandiant team with more than 15 years of expertise in offensive security. He has led and executed dozens of high-impact offensive security services for Fortune 500 companies, financial institutions, government entities, and critical national infrastructure. With a proven track record of identifying and exploiting challenging vulnerabilities in complex environments, Mohamed focuses on diverse initial access vectors and post-exploitation strategies in red team operations. He has also contributed to the security community by publishing tools and researches in various offensive security topics.

  • Shells Without Phish
The speaker's profile picture
Myfox

A senior security researcher and consultant with over 15 years of field experience in penetration testing, digital forensics, and incident response. Founder of CyberSartoria, a boutique cybersecurity firm focused on offensive security and NIS2/DORA compliance for enterprise clients, and co-founder/CTO of TeamBit, a blockchain and AI software house. Active in 0-day research and responsible disclosure. CEH and ISO 27001 Lead Auditor certified. Community roots going back to Hackmeeting and the Italian underground scene of the late 90s, when IRC was the internet. Regular speaker and participant at security events including Security Summit and RomaHack. Outside the terminal: co-founder of an anti-bullying nonprofit and two-time Olympic torchbearer.

  • IRC is not dead: self-hosting real-time chat like it's 1996 (but with TLS)
The speaker's profile picture
Nicola Guglielmi

I operate at the intersection of bold vision and brilliant teams. As a Principal Cloud & AI Strategist and Fractional CTO, I partner with companies to architect future-proof cloud solutions and build the high-performing engineering teams needed to execute them.

With over a decade of hands-on experience in Digital Transformation, I specialize in Google Cloud Platform, Generative AI (Vertex AI), and complex multi-cloud architectures. I don't just talk theory, I have built Cloud Business Units from scratch and led mission-critical migrations in fast-paced sectors like Oil & Gas.
My philosophy is simple: an elite strategy is useless without an elite team to execute it, so I build the team first, knowing that the results will follow.
As a passionate advocate for open knowledge, I am a Google Cloud Authorized Trainer, a Google Developer Expert (GDE) for Cloud, and the Community Lead for GDG Campobasso.
Whether I am live-coding a Gen AI agent or sharing insights on the dynamics of engineering leadership, I bring energy, clarity, and deep real-world experience to the stage. I love connecting with people who are eager to challenge the status quo and push the boundaries of what technology can solve.

  • Zero to podcaster, start today your show with AI!
  • Zero to podcaster, start today your show with AI!
The speaker's profile picture
Pasquale Caporaso

Pasquale Caporaso is a security researcher for the CNIT NAM National laboratory. His research focuses on computer security and operating systems, general purpose and embedded. Over the years, he has accumulated extensive experience in the world of security. He worked as a Cybersecurity Specialist for the multinational Leonardo spa where he experienced first-hand the attack and defence of Linux operating systems and, as a member of the Italian ethical hacker team mhackeroni, he has participated in numerous Italian and international competitions, including the finals of DEFCON and HackASat CTF in Las Vegas, among the world's biggest hacking competitions.

  • Ghost in the SIM: Silent, Zero-Click, Over-the-Air Exploitation of a Pixel 9 Baseband OOB Read
The speaker's profile picture
Pietro Boccaletto

My journey started with technology. As a self-taught and curious teenager, I spent countless late-night hours exploring the emerging Internet, dismantling computers, and learning to program. That early hacker mindset shaped my long-term interest in complex systems, software, and security.

At a time when cybersecurity was not yet the established professional field it is today, I first applied this mindset in the life sciences, developing a background in molecular biology, marine biology, functional proteomics, and later bioinformatics. As a Senior Bioinformatician at the International Institute of Molecular and Cell Biology in Warsaw, I led the development of scientific tools and databases, while completing a PhD focused on computational biology and data analysis.

Over time, my focus moved decisively toward cybersecurity, where my experience in software engineering, data analysis, and complex-system modelling became directly applicable to digital defence. Today, I serve as CTO at AptGetDefence, leading Incident Response operations, R&D, and secure product development. I also advise organizations on NIS2 compliance, cyber resilience, and strategic security governance.

Recently, I was appointed Adjunct Professor at the University of Padua, where I teach “Internet Security”, combining academic rigor with real-world cybersecurity practice.

My work now focuses on threat mitigation, incident response, secure architectures, and regulatory readiness, helping organizations strengthen their security posture in an increasingly complex threat landscape.

  • State Trojan: The Malware with a Warrant
The speaker's profile picture
Pietro Virgillito

Pietro is CTO and co-founder of MiniMako, where he builds kernel-level runtime security for Linux servers running autonomous AI agents.

Before MiniMako he spent fifteen years in operational cybersecurity: hardening critical infrastructure, reverse engineering, live incident response. Through 2024 and 2025, while claimed DDoS waves hit Italian banks, airports and ports, the systems he had hardened held, not because they reacted faster, but because there was no surface left to hit.

That is where his current work comes from. AI agents in production emit syscalls like any other process, but nobody watches them at that level: application logs capture prompts, not kernel calls. Pietro works on eBPF and LSM hooks to make what an agent actually does observable and stoppable, not what it claims to do.

  • How to poison a skill, and why nobody reviews it twice
The speaker's profile picture
Piotr Ptaszek

Senior Purple Teamer @ Tier-1 Global Bank, specializing in adversary simulation, red team operations, and offensive tooling development. Experienced in penetration testing across banking and energy sectors, including Web/Mobile/AD/OT-ICS/Embedded systems in critical infrastructure. Conducts independent hardware security research, holds multiple CVE/ZDI vulnerability disclosures. Co-author of "Introduction to IT Security" (Metasploit chapter) and leads hands-on security training.

  • Breaking the Charge: Security Analysis of the Phoenix Contact CHARX SEC-3000 EV Charging Controller
The speaker's profile picture
Pizza Truck

Straight from Rieti, in the green heart of northern Lazio, our Pizza Truck crew are professional pizza makers who have spent years perfecting one craft: turning flour, water, and fire into something worth queuing for.

Long before they rolled onto the RomHack Camp grounds, they were feeding hungry crowds at festivals, markets, and events across the region — always with the same wood-fired oven riding along with them. Their approach is refreshingly low-tech in a field full of gadgets: a real wood fire, dough left to rise the slow way, quality local ingredients, and the kind of instinct that only comes from making thousands of pizzas by hand.

For them, a good pizza is not just food — it is a moment where people stop, sit down together, and take a break from whatever they were focused on. That makes them a perfect fit for a hacker camp, where the best conversations often happen around a shared meal after a long day of tinkering.

This weekend they bring their oven, their skills, and their Rieti pride to the woods of Flaminio Village. Come say hello, watch the flames, and grab a slice hot off the peel. 🍕🔥

  • 🍕 Pizza Truck — Wood-Fired Dinner
  • 🍕 Pizza Truck — Wood-Fired Dinner
The speaker's profile picture
Pizzamarinarasadd

I'm a Cybersecurity student at the University of Milan pursuing a Master's degree, beginning this year. Before that, I studied Network and Systems Security at the University of Milan. I'm a naturally curious person who loves learning the inner workings of every piece of software I stumble upon.

  • From Discovery to Automated Windows Malware Analysis
The speaker's profile picture
Rahul Vashisht

Rahul is a seasoned Red Team Operator with years of experience executing high-stakes offensive security engagements against hardened global enterprises—from breaching physical perimeters to dismantling cloud-native EDR solutions. As a key player at a top-tier cybersecurity firm, he specializes in crafting undetectable attack chains, weaponizing novel evasion techniques, and developing custom tooling that bypasses industry-standard defenses for clients in banking, telecom, and critical infrastructure. His mission? Hack first, hunt harder.

  • Living Off Trusted Cloud: Provider Infrastructure as Phishing Delivery Channel
The speaker's profile picture
Rana

Rana Khalil is a distinguished red team consultant, with a decade of experience in penetration testing, securing development pipelines, and building comprehensive application security programs. Beyond her technical expertise, Rana is a recognized international speaker, having presented at leading conferences including BlackHat. She is also the founder of an online academy with over 25,000 students, where she shares her extensive knowledge by teaching students how to hack and secure web applications.

  • Chain Reaction - From Isolated Vulnerabilities to Full System Compromise
The speaker's profile picture
Reza

With over eight years of hands on experience in offensive security and vulnerability discovery, I specialize in data driven threat hunting across complex product ecosystems. Currently completing a Master of Science in Software Engineering with a focus on deepfake detection using 3D CNNs, I bridge the gap between academic research and advanced exploitation techniques. I have authored three technical volumes, including AI For Red Team Operation and Practical Application Security, while maintaining a global rank of 6 on Hackthebox. My work focuses on architecting resilient defense systems that integrate runtime application self protection and virtual patching to proactively decrease the time to pwn and neutralize emerging threats. By leveraging multi cloud telemetry and offensive research, I have identified over 140 vulnerabilities for major global vendors, ensuring product integrity against sophisticated adversaries.

  • Using Temporal‑Spatial 3D CNN Features to Enhance OSINT‑Based Profiling and Individual Traceability
The speaker's profile picture
Ric
  • Keep caLLM and Let It Block: Agentic SOAR with n8n + Splunk
The speaker's profile picture
Sanjay Kumar

Sanjay Kumar is Head of Security Operations & Threat Intelligence at EYKON, where he leads security operations, threat detection, incident response, and threat intelligence. With more than a decade of experience in cybersecurity, his work focuses on detection engineering, threat hunting, identity-driven attacks, incident response, and translating threat intelligence into actionable defenses. Sanjay is an international cybersecurity speaker who has presented at security conferences and industry events across Europe and the United States, including DeepSec in Vienna, the ICS Cyber Security Conference in Atlanta, Recorded Future PREDICT, Next IT Security in Stockholm, and CrowdTour Helsinki. He is the recipient of multiple cybersecurity and research recognitions, including the Recorded Future Excellence Award for Innovation in Threat Intelligence at PREDICT Europe 2025. Alongside his industry work, Sanjay is a PhD researcher exploring the application of artificial intelligence and machine learning to cybersecurity and threat detection. His interests lie at the intersection of threat intelligence, security operations, detection engineering, identity security, and emerging attacker tradecraft, with a particular focus on turning real-world attack patterns into practical detection and response strategies.

  • From IOC to Detection: Turning Threat Intelligence Into Something Your SOC Can Actually Use
The speaker's profile picture
Sean Juroviesky

Sean Juroviesky is a dedicated cybersecurity, risk management, and privacy advocate; speaking on those topics at conferences across the world including DEF CON, CypherCon, CornCon, BSides Rochester, SecretCon, Sec-T, and more. Sean also acts as a cybersecurity architect for a large music streaming provider. Beyond their professional pursuits, Sean finds joy in backpacking through the mountains with their adventurous Australian Shepherd, partner, and twins, embracing the serenity of nature and the thrill of exploration.

  • When IaC goes wrong
  • The Trojan Pop-Up; Modern Threat Actor Uses of Advertising
The speaker's profile picture
Stefano Maistri

I currently work as Principal Security Consultant at IMQ Group - Intuity S.p.A., where I conduct penetration testing, secure code reviews, threat modeling, and DevSecOps assessments. Alongside consulting, I'm involved in academia as external professor for the Cyber Security Master's program at the University of Bologna.

  • Stupid Sexy Bearer Tokens: a deep dive into exploding OIDC sessions and hardening with DPoP
The speaker's profile picture
Umberto Micillo (polair)

Offensive Security Researcher, with a soft spot for Windows internals and Active Directory. Ever since I was a kid I wanted to know what was happening under the hood, taking things apart just to understand why they worked, and that itch never went away; it just grew into a passion for breaking and understanding Windows environments.

  • MovementHound: You might be missing something, move it!
The speaker's profile picture
[kuom]

Malware nerd, OT Security tester at [redacted].
As a teenager, I wanted to be a journalist; I guess Plan B worked better... for now.
I know a couple things about OS internals, EDRs, and macOS security.

  • macOS Malware Development: An Introduction
The speaker's profile picture
aserpi

Alessandro Serpi is a Defensive Security Engineer at Satispay. Focused in building robust SIEM and SOAR architectures, he specializes in automating incident response pipelines and designing cross-functional tools that extend traditional cybersecurity capabilities into adjacent domains, such as fraud detection.

  • Keep caLLM and Let It Block: Agentic SOAR with n8n + Splunk
The speaker's profile picture
b0n0b0

Edoardo is a security analyst at Codean Labs, where he focuses on application security assessments and research.
In his free time, he plays CTFs with the Fibonhack team, focusing mainly on web and Android challenges.

Security aside, he likes to read tons of books and sci-fi comics, and yaps about them.

  • GNOME and Beyond Dream Tour: Discover Linux desktop sandboxing and more through its vulnerabilities
The speaker's profile picture
daisy

Hi!
I am a vulnerability researcher and a Computer Engineering student.
In my free time I like playing CTF competitions with the fibonhack team :)
My main interests are software exploitation and console hacking.

  • Imagine: pwning your favourite Nintendo DS game!
The speaker's profile picture
fabio carletti aka Ryuw

Fabio Carletti aka Ryuw è un White Hat del gruppo (SoldierX Hacker team).

Esperto di sicurezza informatica con una vasta esperienza nel campo della protezione dei sistemi, delle reti e dei dati sensibili. Con più di 20 anni di esperienza nel settore della sicurezza informatica, ha lavorato con diverse organizzazioni per implementare strategie di difesa avanzate e mitigare le minacce informatiche in continua evoluzione.

Collabora come membro volontario del Tor Project team.

Ospite di rilevanti eventi italiani riguardanti la privacy, gnu/linux e software open source dedica le sue energie alla ricerca nella sicurezza informatica.

  • Linux-IpFire hardening lan with suricata/IPS
The speaker's profile picture
fibonhack

Fibonhack is a CTF team founded in Pisa in 2019 by a group of students from the University of Pisa, following the CyberChallenge.it program. Over the years, they have competed in numerous competitions and assisted the University and local schools with cybersecurity training. The group has also organized several CTFs, such as the Internet Festival CTF 2023 and MOCA CTF 2024.

Beyond competitions, the team is actively involved in organizing and participating in events to raise cybersecurity awareness.

  • Community CTF by fibonhack - Award Ceremony
  • Community CTF by fibonhack
  • Bada home la fuma - gnocco fritto by fibonhack
The speaker's profile picture
gdg
  • A call for collective action on cyber defense
The speaker's profile picture
jiraky

Dr. Zago holds a PhD from the University of Murcia, Spain. He is currently based in Verona, Italy, working as a cybersecurity engineer (official registration code VR-A-4783). Since 2024 he works for the Oniverse Group as Cyber Security engineer.

His research has focused on Artificial Intelligence for cybersecurity, including machine learning solutions for network intrusion detection systems, big data and sentiment analysis to identify social bots on social media platforms; and, anomaly detection in users' behavioural patterns for authentication and authorization purposes.

  • Stupid Sexy Bearer Tokens: a deep dive into exploding OIDC sessions and hardening with DPoP
The speaker's profile picture
m3ssap0

Hey, I'm m3ssap0! I do AppSec stuff - mostly web, I work as a Security Engineering Manager and I organize Meethack meetups in Torino every week. Some years ago, I used to play CTFs. Now I am a beginner carnivore plants and terrariums grower.

  • Pwn the Pipeline: A Hands-On Tour of CI/CD Security Risks
The speaker's profile picture
mc.fly

mc.fly

Old hacker, works in software development in critical infrastructure. NPC in a computer game.
Works in security since 20+ years, likes to talk on conferences oder things that come to his mind.

Pre-2000 history at the CCC, started milliways.

  • automated vulnerability scanning in software development
The speaker's profile picture
merlos

I'm Giovanni Mellini, aka merlos, one of the founders of the non-profit association Cyber Saiyan that organizes RomHack Camp.

I occasionally speak on public community events, schools and universities.

  • Growing a (nearly) self-sufficient vegetable garden
The speaker's profile picture
michele pietravalle aka PHCV

Michele Pietravalle costruisce Tesla Coil dall’età di 15 anni e, dopo oltre 25 anni di passione e sperimentazione, ha portato le sue bobine a livelli sempre più evoluti in termini di tipologia e potenza. La sua ricerca lo ha condotto a dar vita a VoltagePyromania, un progetto musicale e scenico che unisce fulmini ed elementi di fuoco in un’esperienza artistica unica e immersiva.

  • Tesla Coil by VoltagePyromania
  • Tesla Coil Live Show
The speaker's profile picture
reymerk
  • Stupid Sexy Bearer Tokens: a deep dive into exploding OIDC sessions and hardening with DPoP
The speaker's profile picture
toctou

toctou ha conseguito una laurea magistrale in Ingegneria della Sicurezza informatica presso l'Università di Verona. Ha iniziato la sua carriera come analista di Cyber Security, cambiando poi bruscamente rotta diventando Senior Oracle Database Administrator con oltre dieci anni di esperienza nel settore IT. Da poco è poi riuscito a tornare alle radici virando di nuovo carriera e diventando Penetration Tester. È certificato come OffSec Certified Professional (OSCP) e OffSec Experienced Penetration Tester (OSEP). Come appassionato di cybersecurity è sempre desideroso di studiare e ampliare le conoscenze e le competenze pratiche in materia di sicurezza informatica nel tempo libero e, come attività secondaria, attualmente crea macchine vulnerabili per OffSec come autore freelance.

  • Stupid Sexy Bearer Tokens: a deep dive into exploding OIDC sessions and hardening with DPoP