RomHack Camp 2026

Andrea Cappa

Andrea Cappa (zi0Black) is Security Lead at Aptos Labs, where he oversees all things security. A former penetration tester at Shielder, he now spends his time exploring how AI can be applied to security in real-world environments, as well as the human factors behind security incidents and system failures.


Sessions

10-02
17:40
20min
A review bot that just works
Andrea Cappa

Sometimes, the perfectly engineered solution isn’t what you need. We discuss how, at the beginning of 2026, we moved quickly to build a review bot that helped stem the flow of vulnerabilities entering the codebase in the era of vibe coding. We’ll cover the ROI, costs, and practical challenges involved, along with lessons learned about model choice and how reusing existing harnesses helped us move faster.

Presented at AI for Security event @ DEFCON34.

Cybersecurity and Hacking
STAGE 2 (Ghost in the Shellcode)
10-03
15:10
40min
A call for collective action on cyber defense
Andrea Cappa, Abdel Adim `smaury` Oisfi, gdg

AI is changing both the scale and speed of cyber offense and defense. In response, more than 100 organizations across technology, cybersecurity, industry, and government have called for a global surge in cyber defense: better tools for defenders, stronger protection for critical infrastructure, more useful intelligence sharing, and faster remediation of vulnerabilities.

The harder question is what happens next. What should organizations actually commit to, and how should progress be measured? Who gets access to advanced defensive AI, and who decides what qualifies as a “trusted defender”? How can vendors share intelligence and fixes that defenders can use in practice? And who pays to bring these capabilities to smaller hospitals, utilities, municipalities, and other resource-constrained organizations?

The panel will also tackle a fundamental technical challenge: securing software and infrastructure at scale. More models, agents, or compute do not automatically translate into fewer critical vulnerabilities. We will discuss what AI labs, governments, security vendors, software producers, and infrastructure operators each need to do to turn a broad call for action into concrete, accountable improvements in cyber defense.

Cybersecurity and Hacking
STAGE 1 (Section 9)