Bodite korak pred napadalci z vpogledom v najnovejše kibernetske grožnje.
Odklenite inovativne strategije za zaščito podatkov in obrambo pred napadi.
Povežite se s strokovnjaki kibernetske varnosti in etičnimi hekerji
PRIJAVITE SE ZA BREZPLAČEN (SPLETNI) OGLED
V brezplačen sklop bodo vključena sponzorska predavanja 4.6.2025 od 10:00 do 12:20 ure
Premium paket HACKSTOP vključuje vstopnici za obe konferenci – HACKSTOP in INFOSEK.
The EU Agency for Cybersecurity (ENISA) works hands-on with the EU the Member States, with the European Commission and with other Agencies, to help either prevent or effectively respond to large-scale cybersecurity incidents and crisis. As mandated by NIS2, ENISA supports European cybersecurity incident and crisis management coordination providing daily operations of the CSIRTs Network and of the EU-CyCLONe, crisis simulation exercises, trainings, support to Member States in developing their crisis plans. The Agency covers the full spectrum of cybersecurity and aims to anticipate and prepare the Union for the cybersecurity challenges and threats of the next decade. In 2025 the Agency launched also the European Vulnerability Database and it is getting ready to operationalize the upcoming cybersecurity blueprint for large-scale cyber incidents and crisis.
Zaradi usmerjenosti na kibernetske nevarnosti pozabljamo na klasične metode kraje poslovnih skrivnosti, kjer napadalci za nekaj eurov pridobijo vse podatke in ostanejo neopaženi.
Kako digitalizirati poslovanje, avtomatizirati procese in obenem poskrbeti za skladnost s kibernetskimi zahtevami prihodnosti? Na predavanju boste spoznali praktične rešitve za elektronsko podpisovanje, upravljanje dokumentov in varno hrambo podatkov – vse z mislijo na zakonodajo, kot so ZIERDED, DORA in NIS2.
Predstavljamo vam Kaspersky ASAP, avtomatizirano platformo za ozaveščanje o varnosti. Platforma je spletno orodje, ki zaposlenim skozi vse leto gradi močne in praktične veščine kibernetske zaščite.
Vsebina temelji na več kot 25-letnih izkušnjah na področju kibernetske varnosti, izraženih v modelu kompetenc, ki obsega več kot 350 praktičnih in bistvenih veščin kibernetske varnosti, ki bi jih morali imeti vsi zaposleni. Kaspersky Automated Security Awareness platforma vključuje glavni in ekspresni tečaj ter phishing simulator, ki zagotavlja, da vaši zaposleni ne nasedejo na phishing.
V svetu, kjer se kibernetske grožnje razvijajo dnevno, tradicionalni modeli, kot so enkratni pentesti, niso več dovolj. Organizacije potrebujejo dinamičen, stalno delujoč sistem za ocenjevanje in obvladovanje izpostavljenosti. Predstavili bomo koncept CTEM, zakaj je pomemben, opcije implementacije in kakšne koristi prinaša.
V kratkem intervjuju bomo predstavili Coro kot celovito, a preprosto rešitev za zaščito podjetij pred sodobnimi kibernetskimi grožnjami. Pogovor bo osvetlil, zakaj Coro izstopa med varnostnimi platformami: predvsem zaradi svoje avtomatizacije, preglednosti in preprostosti tudi za manjše IT ekipe. Dotaknili se bomo glavnih funkcionalnosti platforme, konkretnih primerov uporabe ter razlogov, zakaj je Coro idealna rešitev za podjetja, ki iščejo visoko stopnjo varnosti brez kompleksnosti. Opozorili bomo tudi na pomembnost preventive, hitrosti odziva in vloge uporabniške izkušnje pri izbiri varnostnih orodij.
Penetracijski testi so usmerjeni v odkrivanje tehničnih ranljivosti znotraj vnaprej določenega obsega, medtem ko pristop rdeče ekipe (angl. red team) temelji na celostni simulaciji napada, realističnih tehnikah in aktivnem izogibanju zaznavi varnostnih mehanizmov.
Skozi praktičen primer bomo prikazali, kako lahko napadalec prilagodi orodje na način, da ga varnostne rešitve ne zaznajo. Gre za eno izmed pogostih taktik, ki kaže, kako rdeče obarvan pristop presega odkrivanje ranljivosti in se osredotoča na preverjanje dejanske odpornosti organizacije proti napadom.
Tickwall učinkovito preprečuje krajo dostopa in izpostavljenost sistemov z uporabo večfaktorske avtentikacije, dinamičnega preverjanja identitete in načela najmanjših pravic. Omogoča natančen nadzor dostopa do kritičnih sistemov brez izpostavljanja gesel ali infrastrukture. Vsak dostop je nadzorovan, beležen in sledljiv, kar omogoča hitro odzivanje ob morebitnih varnostnih incidentih. Sistem temelji na načelih ničelnega zaupanja (Zero Trust), kar dodatno zmanjšuje tveganje zlorab.
Kljub naprednim tehnologijam, požarnim zidovom in sofisticiranemu zaznavanju groženj, ostaja uporabnik še vedno najpogostejša vstopna točka za napadalce. V tem predavanju bomo izvedeli, zakaj so človeški faktorji pogosto bolj nevarni kot tehnične ranljivosti.
Doppelganger is a Red Team tool designed to stealthily dump lsass.exe by cloning the process using NtCreateProcessEx, bypassing PPL and VBS protections. It leverages the vulnerable RTCore64.sys driver to disable security features and uses runtime API obfuscation to evade detection. The dump is XOR-encrypted and saved to disk, making it harder for EDR/XDR to flag.
In today's threat landscape, your company secrets might already be circulating in hidden corners of the internet — and you may not even know it. In this session, we’ll explore how to monitor the dark web for leaked data, compromised credentials, and signs that your organization is being targeted. You'll learn how to leverage threat intelligence tools, spot early indicators of insider threats, and build a proactive defense strategy.
Let's take a deep dive into how Windows system calls actually work and explore some cool techniques for using them to execute payloads during red team engagements. We’ll look at the nuts and bolts of Windows syscall mechanics and how they can be leveraged in real-world hacking scenarios. It’s all about uncovering the power of syscalls and their crucial role in the toolkit of every ethical hacker.
Mergers and acquisitions offer a fast track to innovation and market expansion—but they also expose organizations to hidden cybersecurity risks that can linger long after the deal is done. In this talk, I’ll share hard-won insights from the frontlines of infrastructure security and threat intelligence, focusing on my work within the Visma Security Program and its rigorous due diligence process for evaluating acquisition targets.
We’ll dive into the real-world application of CTI and infrastructure security assessments during M&A, exploring how Visma’s integrated approach helped identify and mitigate inherited vulnerabilities, prevent supply chain compromise, and secure operational continuity post-acquisition. Attendees will learn:
- How to build an M&A security playbook rooted in real threat intelligence.
- Infrastructure red flags to watch for in early-stage evaluations.
- Strategies for aligning security expectations between acquiring and target entities.
- Lessons from high-risk assessments and how they influenced buy/no-buy decisions.
This session is for security leaders, CTI professionals, and M&A advisors who want to strengthen their organization's posture during periods of rapid growth and technological integration.
During this talk, I will address the rapidly advancing field of quantum computing and the significant threat it poses to the security of public-key cryptosystems, which are widely used in securing digital communications. While the research community is actively working to develop defenses against quantum attacks, current solutions still face challenges related to their efficiency and practicality.
I will delve into one promising solution: hash-based digital signature schemes, and explore how combining these with vector commitments and Verkle tree-based techniques can help mitigate quantum risks. This approach integrates innovative concepts to create a more secure framework for digital signature generation in a post-quantum world.
A key aspect of this work is the integration of Verkle trees with Merkle-based strategies and vector commitments, a novel combination designed to enhance security while reducing computational and memory overhead. Additionally, I will introduce a post-quantum secure pseudo-random number generator to further optimize memory usage and ensure that the solution remains efficient and viable for resource-constrained environments.
*Cene ne vključujejo DDV
Najšibkejši člen: Zakaj je uporabnik še vedno največja ranljivost v kibernetski varnosti?
Matic Šebjan Ogrizek je mladi strokovnjak za kibernetsko varnost, zaposlen kot SOC analitik v podjetju Unistar PRO, kjer se osredotoča na zaznavanje in odzivanje na varnostne incidente ter obvladovanje sodobnih kibernetskih groženj. Trenutno zaključuje študij kibernetske varnosti na Višji strokovni šoli Academia v Mariboru, kjer je pridobil poglobljeno znanje o zaščiti informacijskih sistemov in infrastrukture. Njegovo delo vključuje spremljanje varnostnih dogodkov, analizo tveganj ter sodelovanje pri implementaciji varnostnih rešitev, s čimer prispeva k zagotavljanju varnega digitalnega okolja za stranke podjetja.
Matic Šebjan Ogrizek je mladi strokovnjak za kibernetsko varnost, zaposlen kot SOC analitik v podjetju Unistar PRO, kjer se osredotoča na zaznavanje in odzivanje na varnostne incidente ter obvladovanje sodobnih kibernetskih groženj. Trenutno zaključuje študij kibernetske varnosti na Višji strokovni šoli Academia v Mariboru, kjer je pridobil poglobljeno znanje o zaščiti informacijskih sistemov in infrastrukture. Njegovo delo vključuje spremljanje varnostnih dogodkov, analizo tveganj ter sodelovanje pri implementaciji varnostnih rešitev, s čimer prispeva k zagotavljanju varnega digitalnega okolja za stranke podjetja.
Odkrivanje protislušnih naprav
Aleš Ažman je zasebni detektiv z licenco, zaposlen v podjetju Detekta, detektivsko-varnostna agencija in svetovanje d.o.o. Ima dolgoletne izkušnje iz vojske, posebej s področja CIMIC, saj je bil kot častnik SV tudi inštruktor v centru odličnosti Nata (CCOE) na Nizozemskem. Pridobljene izkušnje iz mirovnih operacij in šolanj v različnih oboroženih silah po svetu uspešno prenaša v civilno okolje. Kot zasebni detektiv se dnevno srečuje z izzivi na različnih področjih detektivskega dela, od vdorov v zasebnost, nezvestobe, preverjanja zaposlenih, do iskanja skritih oseb in njihovega premoženja. Orodje, ki ga pri svojem delu uporabljala je največkrat prav svetovni splet.
Aleš Ažman je zasebni detektiv z licenco, zaposlen v podjetju Detekta, detektivsko-varnostna agencija in svetovanje d.o.o. Ima dolgoletne izkušnje iz vojske, posebej s področja CIMIC, saj je bil kot častnik SV tudi inštruktor v centru odličnosti Nata (CCOE) na Nizozemskem. Pridobljene izkušnje iz mirovnih operacij in šolanj v različnih oboroženih silah po svetu uspešno prenaša v civilno okolje. Kot zasebni detektiv se dnevno srečuje z izzivi na različnih področjih detektivskega dela, od vdorov v zasebnost, nezvestobe, preverjanja zaposlenih, do iskanja skritih oseb in njihovega premoženja. Orodje, ki ga pri svojem delu uporabljala je največkrat prav svetovni splet.
Kako Tickwall preprečuje krajo dostopa in izpostavljenost sistemov?
Andrej Golob je IT in kibernetski arhitekt z več kot 20-letnimi izkušnjami pri načrtovanju in zaščiti heterogenih enterprise okolij. Kot zgodnji posvojitelj naprednih tehnologij na področju kibernetske varnosti ter z bogatim znanjem, pridobljenim pri varovanju kritične infrastrukture, prinaša praktične izkušnje in poglobljen vpogled v delovanje kibernetske obrambe v realnem okolju.
Andrej Golob je IT in kibernetski arhitekt z več kot 20-letnimi izkušnjami pri načrtovanju in zaščiti heterogenih enterprise okolij. Kot zgodnji posvojitelj naprednih tehnologij na področju kibernetske varnosti ter z bogatim znanjem, pridobljenim pri varovanju kritične infrastrukture, prinaša praktične izkušnje in poglobljen vpogled v delovanje kibernetske obrambe v realnem okolju.
Kje se konča klasični pentest in začne simulacija pravega napada?
Danijel Grah je v svetu kibernetske varnosti aktiven že skoraj deset let. Kariero je začel kot svetovalec, kasneje se je posvetil raziskovanju, danes pa pri podjetju NIL deluje kot analitik kibernetske varnosti v centru za varnostne operacije (SOC). Ima bogate izkušnje s penetracijskim testiranjem in utrjevanjem varnosti, programiranjem, svetovanjem ter razvojem sistemov za kibernetsko obrambo. Svoja raziskovalna dela je objavljal in predstavljal na različnih mednarodnih konferencah s področja informacijske varnosti, svoje znanje in izkušnje pa je potrdil tudi s strokovnimi certifikati, kot je GRID.
Danijel Grah je v svetu kibernetske varnosti aktiven že skoraj deset let. Kariero je začel kot svetovalec, kasneje se je posvetil raziskovanju, danes pa pri podjetju NIL deluje kot analitik kibernetske varnosti v centru za varnostne operacije (SOC). Ima bogate izkušnje s penetracijskim testiranjem in utrjevanjem varnosti, programiranjem, svetovanjem ter razvojem sistemov za kibernetsko obrambo. Svoja raziskovalna dela je objavljal in predstavljal na različnih mednarodnih konferencah s področja informacijske varnosti, svoje znanje in izkušnje pa je potrdil tudi s strokovnimi certifikati, kot je GRID.
Ko kibernetska varnost postane preprosta: Coro
Urban Turk je strokovnjak za prodajo z večletnimi izkušnjami na področju poslovnega svetovanja in tehničnih rešitev. Zaposlen je v podjetju CREAPLUS, kjer je odgovoren za prodajo naprednih kibernetskih rešitev za podjetja vseh velikosti. S svojim znanjem in razumevanjem tehnoloških izzivov sodobnih organizacij pomaga strankam pri izbiri varnostnih rešitev, ki so prilagojene njihovim specifičnim potrebam.
Urban Turk je strokovnjak za prodajo z večletnimi izkušnjami na področju poslovnega svetovanja in tehničnih rešitev. Zaposlen je v podjetju CREAPLUS, kjer je odgovoren za prodajo naprednih kibernetskih rešitev za podjetja vseh velikosti. S svojim znanjem in razumevanjem tehnoloških izzivov sodobnih organizacij pomaga strankam pri izbiri varnostnih rešitev, ki so prilagojene njihovim specifičnim potrebam.
Preparing and responding to the cybersecurity challenges of today and tomorrow
Rossella Mattioli serves as the Head of the Crisis Response & Operational Stakeholders Support Sector at the European Union Agency for Cybersecurity (ENISA). At ENISA, Rossella leads the Agency's work on incident response and crisis management coordination in the European Union. Her work focuses on empowering EU operational stakeholders, equipping them with the necessary tools and knowledge to effectively prepare for and respond to large-scale cybersecurity incidents and crises.
Rossella holds an MSc in Cybersecurity from Tallinn University of Technology and joined the Agency in 2013. Her experience within the Agency encompasses a diverse range of critical cybersecurity domains, including Internet infrastructure, Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems, the evolving landscape of intelligent public transport, the security challenges of smart cars and airports, and the launch of the strategic cybersecurity foresight function.
Rossella Mattioli serves as the Head of the Crisis Response & Operational Stakeholders Support Sector at the European Union Agency for Cybersecurity (ENISA). At ENISA, Rossella leads the Agency's work on incident response and crisis management coordination in the European Union. Her work focuses on empowering EU operational stakeholders, equipping them with the necessary tools and knowledge to effectively prepare for and respond to large-scale cybersecurity incidents and crises.
Rossella holds an MSc in Cybersecurity from Tallinn University of Technology and joined the Agency in 2013. Her experience within the Agency encompasses a diverse range of critical cybersecurity domains, including Internet infrastructure, Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems, the evolving landscape of intelligent public transport, the security challenges of smart cars and airports, and the launch of the strategic cybersecurity foresight function.
Napadalci ne čakajo na vaš letni pentest. Zakaj bi vi?
Miha Petrač je vodja omrežno-varnostnih rešitev v ADD, kjer od leta 2014 skrbi za umestitev in razvoj novih produktov s tega področja. Ima bogate izkušnje z HPE Networking porfeljem, saj je v preteklosti deloval tudi kot HP Networking solution Arhitect. Dodatno je ključno pripomogel k razvoju ekipe in portfelja proizvajalca FORTINET, kjer je ADD danes eden od glavnih partnerjev tako v Sloveniji kot v regiji.
Miha Petrač je vodja omrežno-varnostnih rešitev v ADD, kjer od leta 2014 skrbi za umestitev in razvoj novih produktov s tega področja. Ima bogate izkušnje z HPE Networking porfeljem, saj je v preteklosti deloval tudi kot HP Networking solution Arhitect. Dodatno je ključno pripomogel k razvoju ekipe in portfelja proizvajalca FORTINET, kjer je ADD danes eden od glavnih partnerjev tako v Sloveniji kot v regiji.
K-ASAP spletna platforma za ozaveščanje zaposlenih o kibernetski varnosti
Radomir Ljubojević je direktor podjetja Naskom, ki je Kaspersky distributer za Slovenijo in Zahodni Balkan. Ima več kot 20 let izkušenj na področju informacijske in kibernetske varnosti. Še posebej je vključen v programe ozaveščanja zaposlenih o kibernetski varnosti.
Radomir Ljubojević je direktor podjetja Naskom, ki je Kaspersky distributer za Slovenijo in Zahodni Balkan. Ima več kot 20 let izkušenj na področju informacijske in kibernetske varnosti. Še posebej je vključen v programe ozaveščanja zaposlenih o kibernetski varnosti.
Jan is a co-founder of Cyber Rangers, red teamer and trainer. His expertise includes deep knowledge of Windows OS security and Active Directory. He specializes in EDR evasion, exploit development, malware engineering, and advanced attack techniques in Active Directory environments.
Jan is a co-founder of Cyber Rangers, red teamer and trainer. His expertise includes deep knowledge of Windows OS security and Active Directory. He specializes in EDR evasion, exploit development, malware engineering, and advanced attack techniques in Active Directory environments.
Catalin is a security professional specialised into Infrastructure and Product Security areas with a strong knowledge of Security Operations.
He works at Visma as a Infrastructure Security Program Lead, enjoying his time in providing technical leadership in various security areas, having a true desire to drive the Infrastructure Security, Cyber Threat Intelligence (CTI) and M&A Security field and building an resilient, scalable and relevant Security Program through the Visma Security Program - VSP.
Catalin is the OWASP Timisoara Chapter Leader where he aims to create a strong local security community focused on improving the application security world and creating security awareness. He also has several recognized certifications in the security field and in his spare time he enjoys reading lots of cool stuff, playing football, biking and hiking.
Catalin is a security professional specialised into Infrastructure and Product Security areas with a strong knowledge of Security Operations.
He works at Visma as a Infrastructure Security Program Lead, enjoying his time in providing technical leadership in various security areas, having a true desire to drive the Infrastructure Security, Cyber Threat Intelligence (CTI) and M&A Security field and building an resilient, scalable and relevant Security Program through the Visma Security Program - VSP.
Catalin is the OWASP Timisoara Chapter Leader where he aims to create a strong local security community focused on improving the application security world and creating security awareness. He also has several recognized certifications in the security field and in his spare time he enjoys reading lots of cool stuff, playing football, biking and hiking.
Digitalizacija procesov z IT rešitvami ob upoštevanju smernic kibernetske varnosti
Aleksander Rožman je prokurist podjetja Mikrografija z več kot 20-letnimi izkušnjami na področju upravljanja dokumentov, fizičnega in elektronskega arhiviranja, digitalizacije ter projektnega vodenja. Svoje strokovno znanje je uspešno uveljavljal v različnih industrijah, tako v Sloveniji kot tudi v širši regiji.
Aleksander Rožman je prokurist podjetja Mikrografija z več kot 20-letnimi izkušnjami na področju upravljanja dokumentov, fizičnega in elektronskega arhiviranja, digitalizacije ter projektnega vodenja. Svoje strokovno znanje je uspešno uveljavljal v različnih industrijah, tako v Sloveniji kot tudi v širši regiji.
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Andrea Varischio, of Yarix’s Red Team since 2020, graduated from UNIPD with a degree in telecommunications engineering. During his studies, he became passionate about computer security, with a focus on that of Android devices, which was also his master’s thesis topic. Drummer in his spare time, he loves music, math, martial arts and board games.
Andrea Varischio, of Yarix’s Red Team since 2020, graduated from UNIPD with a degree in telecommunications engineering. During his studies, he became passionate about computer security, with a focus on that of Android devices, which was also his master’s thesis topic. Drummer in his spare time, he loves music, math, martial arts and board games.
Optimizing Post-Quantum Signatures via QRNG-PRNG Integrated Verkle Trees
Prof. Maksim Iavich is a Weiser Fellow and a post-quantum cryptography researcher at the University of Michigan, conducting research within the framework of the Weiser Fellowship. He is also a professor and the head of the Cybersecurity Direction at Caucasus University (CU), where he leads the Information Technologies bachelor’s program, the IT Management master’s program, and the Cybersecurity programs at CU.
Prof. Iavich is the Director of the Cyber Security Center, CST (CU), and serves as an expert evaluator at the National Center for Education Quality Development of Georgia. He is the CEO & President of the Scientific Cyber Security Association (SCSA).
In 2024, Maksim was acknowledged as the best young scientist of Caucasus University. He is an honorary doctor of the National Aviation University, Kyiv.
In 2018, Maksim was acknowledged as the best young scientist of Georgia in the field of technology. He is a cybersecurity consultant for both Georgian and international organizations. Additionally, he has been an invited speaker at international practical and scientific cybersecurity conferences and has organized numerous local and international scientific cybersecurity events.
Prof. Iavich has received multiple scientific awards in cybersecurity. He is the author of numerous scientific papers covering topics such as cybersecurity, cryptography, post-quantum cryptography, 5G security, mathematical models, and simulations.
Prof. Maksim Iavich is a Weiser Fellow and a post-quantum cryptography researcher at the University of Michigan, conducting research within the framework of the Weiser Fellowship. He is also a professor and the head of the Cybersecurity Direction at Caucasus University (CU), where he leads the Information Technologies bachelor’s program, the IT Management master’s program, and the Cybersecurity programs at CU.
Prof. Iavich is the Director of the Cyber Security Center, CST (CU), and serves as an expert evaluator at the National Center for Education Quality Development of Georgia. He is the CEO & President of the Scientific Cyber Security Association (SCSA).
In 2024, Maksim was acknowledged as the best young scientist of Caucasus University. He is an honorary doctor of the National Aviation University, Kyiv.
In 2018, Maksim was acknowledged as the best young scientist of Georgia in the field of technology. He is a cybersecurity consultant for both Georgian and international organizations. Additionally, he has been an invited speaker at international practical and scientific cybersecurity conferences and has organized numerous local and international scientific cybersecurity events.
Prof. Iavich has received multiple scientific awards in cybersecurity. He is the author of numerous scientific papers covering topics such as cybersecurity, cryptography, post-quantum cryptography, 5G security, mathematical models, and simulations.
Into the Shadows: Monitoring Your Company Secrets in the Dark Web
As a Cloud Security & DevSecOps consultant, he enables diverse development teams to deliver improved results while protecting their business-critical assets on-prem and in Cloud environments. Passionate about red teaming, threat intelligence, offensive security, and talking to an audience about his stories.
For a glimpse at his career so far, you can reach out to his LinkedIn:
https://www.linkedin.com/in/martinperezrodriguez/
As a Cloud Security & DevSecOps consultant, he enables diverse development teams to deliver improved results while protecting their business-critical assets on-prem and in Cloud environments. Passionate about red teaming, threat intelligence, offensive security, and talking to an audience about his stories.
For a glimpse at his career so far, you can reach out to his LinkedIn:
https://www.linkedin.com/in/martinperezrodriguez/
*Cene ne vključujejo DDV
Podrsajte po galeriji slik ...
*Cene ne vključujejo DDV
Ta spletna stran uporablja piškotke. Z obiskom in uporabo spletne strani soglašate s piškotki. DOVOLIM Več informacij o piškotkih najdete in nastavitve tukaj.