Andreas is a student at Graz University of Technology with a strong interest in offensive security, systems programming, and low-level exploitation. My work focuses on understanding software at the boundary between source code, binaries, operating systems, and hardware, with a particular interest in vulnerability research, reverse engineering, and binary exploitation.
- Universal Plug and Pwn
I'm a security engineer, pentester, and researcher who came to the field from a background in medicine. I've been hacking the web since 2019 and hold OSCP and OSWE
Happy to contribute to the community and exchange knowledge - come say hi, let's chat and stay in touch
- awerqo@balccon:~$ ./whoarethey > 'Cloud Recon for Bughunting.md'
Anita Cwynar, CISSP, GDSA, GICSP, SABSA-certified application security specialist with over a decade of work experience in FMCG and high-tech industries, strengthening security posture across 1st and 2nd line of defense teams in Europe and Asia. Currently based in the Netherlands and focused on protecting core enterprise platforms at one of the biggest European companies.
- Why you shouldn’t worry about your SAP systems… or should you?
Arad Donenfeld is an attacks and exploits developer in SafeBreach, and has a background in security research from several roles. With his strong foundations of development, security, and operating systems internals, Arad develops tools for offensive operations, detection methods, and workflow automation. Arad focuses on practical techniques to identify and manipulate vulnerabilities and breaches, while testing and improving defenses across broad environments
- The Agents of Chaos: AI Driven Malware Generation
Test
- Closing ceremony
- After party
- Opening
- Lightning talks
- Rakija Leaks
I am a security professional with around ten years of experience testing and breaking real world systems. Despite being introverted and occasionally socially awkward, I love going to security conferences, usually pretending that the hallway track is not the main reason I came.
- Keeping Trains on Track - A Glimpse into Germany’s Railway Infrastructure
Boris Nimčević is an electronics and computer engineer by day and a maker by night. Throughout his career, he has worked on toys, fitness devices, 5G mobile base stations, and Internet of Things (IoT) devices. Wherever he has lived, he has been an active member of the local maker community—from Leslie eLab in New York and Crash Space in Los Angeles to Stockholm Makerspace, where he is currently a member. Recently, he has focused on fostering the maker community and encouraging creativity by helping others discover the joy of making.
- Embroidery meets Electronics - make your blinky wearable patch
Christian Lölkes (*1990 in White Plains, NY) works at DFS, the German air traffic control provider. There, he builds data centres for mission-critical software and infrastructure. Clean code and accurate documentation form the basis of his work. He studied Electrical and Information Technology at the Karlsruhe Institute of Technology (KIT), and in his free time he is passionate about media art and the idea that programming is a creative task and that programmers are therefore also artists.
- Generative Art and Cellular Automata
Dennis Giese is a researcher with the focus on the security and privacy of IoT devices. While being interested in physical security and lockpicking, he enjoys applied research and reverse engineering malware and all kinds of devices. His most known projects are the documentation and hacking of various vacuum robots. He calls himself a "robot collector" and his current vacuum robot army consists of over 95 different models from various vendors. He talked about his research at the Chaos Communication Congress, REcon, HITCON, NULLCON, and DEFCON.
- Your Lock(er) Knows Your PIN ... And So Do I
Erik de Jong is an elite hardware hacker and senior cybersecurity consultant, running his own company error32.io, with extensive experience in identifying vulnerabilities and securing complex systems. Known for a hands-on "brains first, tools second" approach and deep technical expertise, Erik specializes in reverse engineering, embedded systems, and hardware security. With a passion for crowdsourced security, Erik actively contributes to bug bounty programs and has participated in multiple bugbashes (live hacking events), where he's collaborated with other top hackers to uncover critical vulnerabilities in real-time.
- Wireshark for <s>hackers</s> reverse engineers
Goran Mahovlić (electronics tech) worked for years in repair shop for informatics and bank equipment. Moved on to a developer for low power wireless technologies (LoRA/nbIOT) and measuring systems. Currently self employed in Intergalaktik d.o.o. working on opensource HW solutions, mostly FPGA boards. With constant urge to take apart any device within reach and find out it’s secrets, Goran is equally successful at hardware and software hacking, from cheap products, up cycling old tech, to serious work in technology and microprocessor development. He is a tech coordinator at Radiona. In past, Goran led a number of accomplished workshop and presentations, regular member of Radiona projects and exhibitions, lead and founder of Radiona SmartZG network. Among his work is founding the Lemilica.com portal, for which he writes.
- REGOČ my SW/HW AI team
Guergana is a software developer working mainly on free and open source software, educational tools and non-profit organisations currently working at the Open Science Lab of the German National Library of Science and Technology creating open source tools in the field of cultural research. With a Bachelor’s degree in Computer Science, her interest in the creative use of media and technology led her to a Master’s degree in Design of Multimedia and Interactive Systems and later a research degree in Theory and History of Cinema in Barcelona. For several years she has been working on projects that combine audio, video, design and programming.
- Democratizing the creation of video tools with Open Source: Grassroots Community building and the recurBoy
Supervillain with a heart of gold
- Fun with virtualization
Hannes is a PhD Candidate at Graz University of Technology in the CoreSec Group.
His research area is side-channel attacks and defenses.
He has worked on trusted execution environments, DNS and browser security.
In his free time, he sometimes still plays CTFs, including the DEF CON 2025 finals with KuK Hofhackerei.
- FROST: SSD Side Channels from the Browser, and Why You Should Care
- Hacker Jeopardy
Hilko works in the CSIRT for a transportation and logistics company. He feels most comfortable when thinking about problems that touch systems programming, operations and IT security. For more than 25 years, he has learned to take free and open source software for granted and he is still amazed when he hears how others have found his contributions useful.
- Detecting Linux rootkits: Know where to look in user-space
Christian Herrmann, better known in the hacker community as “Iceman”, is a co-founder of AuroraSec and RRG, and has helped develop many of today’s most widely used RFID research tools, including the Proxmark3 RDV4 and the Chameleon Mini.
He is a well-known RFID hacking and Proxmark3 evangelist, serving the community as both a forum administrator and a major code contributor alongside other developers since 2013.
Christian has spoken at hacker conferences around the world, including RECON, TenguCon, BalcCon, WHY-2025, Troopers, Black Hat Asia, DEF CON, Hardwear IO, SSTIC, NullCon, Pass-the-Salt, BSides Tallinn, BlackAlps, and SaintCon.
He also runs a YouTube channel where he shares his knowledge of RFID hacking with the public.
With over 15 years of experience in bespoke software development, Christian specializes in
.NET platforms and is a Certified MCPD Enterprise Architect.
He possesses near-unmatched expertise in the Proxmark3 architecture and various RFID technologies, and has served as an instructor for Red Team Alliance (RTA), including training sessions at Black Hat.
- Reverse Engineering FERMAX: Detour, Dead End, and Scope Creep
Ignacio Navarro, an Ethical Hacker and Security Researcher from Cordoba, Argentina. With around 6 years in the cybersecurity game, he's currently working as an Application Security. Their interests include code analysis, web application security, and cloud security.
Speaker at DEFCON, H2HC, Troopers, LeHACK, NorthSec, TyphoonCon, Security Fest, SASCON, 8.8 among others.
@Ignavarro1
- Every ride you take - Hacking a City’s Public Transportation
Official for Media: Project Researcher at the University of Turku’s Cyber Security Lab. Ismail earned his M.Sc. in Information and Communication Technology from the University of Turku in 2023. He serves on the board of VSTKY and chairs TurkuSec ry, Finland’s oldest citysec group. One of the main organizers of Disarray 2025&2026. With over 7 years of industry experience, his interests include network security, cybersecurity policies, and the secure and responsible use of LLMs and AI in cybersecurity.
Non-official:
Chairman at TurkuSec, active member of Finnish Cybersecurity community, organizing different security events, volunteering at Disobey, since recently started giving talks :)
- Renting Brains, Owning the Mistakes: LLMs in Cybersecurity Education
Final year Student of FTN Novi Sad in Automatic Computer Science.
Passionate about Cybersecurity of all kinds.
- The Eye
Janos Kovacs is an enthusiast of securing Healthcare IT products, with a decade of experience gained in the field of product cybersecurity. He has contributed to the establishment of the product cybersecurity management systems for several global manufacturers. Since 2025 he works on keeping cancer treatment secure as part of Siemens Healthineers-Varian Product Cybersecurity Team.
- Digital Oncologists Require Cyber Care - Securing AI Agents in Radiotherapy
Joseph Carson is an award-winning cybersecurity professional, ethical hacker, and curious problem solver with over 30 years of experience exploring, breaking, and securing technology. As Chief Security Evangelist and Advisory CISO at Segura, he helps organizations defend what attackers target most - identities, privileges, and access.
Holding CISSP and OSCP certifications, Joseph combines a hacker mindset with real-world security leadership, advising governments, critical infrastructure, and global organizations on building stronger cyber resilience.
He is the author of Cybersecurity for Dummies, helping educate more than 50,000 professionals worldwide, a global keynote speaker, and contributor to publications including The Wall Street Journal and Dark Reading.
As host of the Security by Default podcast, Joseph explores the stories, techniques, and lessons from hackers, innovators, and security leaders shaping the future of cybersecurity, driven by the belief that curiosity is the foundation of every great hacker.
- From Zero to Admin: The Hidden Paths of Privilege Escalation
SOC operator and offensive security practitioner with a habit of pulling at things until they break and then figuring out why. Core interests are OSINT, social engineering, and finding the cracks in systems that were never supposed to be tested.
Never formally grew up in the golden era of hacker culture, but feels deeply at home in it anyway. The kind of person who was handed a keyboard before they could read and never really found a reason to put it down. Enthusiastic about anything that involves taking something apart, technically or socially.
A regular at community security events, with strong views on privacy, surveillance, and the kind of curiosity that does not really have an off switch.
- A Street Sign, a Shadow, and an Answer: OSINT Workshop
- OSINT CTF/Hackathon
I am a master student at Graz University of Technology with a major in Information Security. I'm passionate about security, privacy, automation and I love building IT infrastructure.
Website: https://saiger.dev
Github: https://github.com/csskevin
- Universal Plug and Pwn
Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist. He began programming at age 7, and by grade 9 was already writing machine code directly in a hex editor during lunch breaks. Renowned for uncovering and responsibly disclosing critical vulnerabilities in national and international systems, he is an expert in network flow analysis, reverse engineering, and social engineering. A lifelong command-line enthusiast, he uses bash daily for hacking, automation, and large-scale data processing.
He is the author of the jailbreak tool for MikroTik RouterOS and played a pivotal role in developing e-Saeima, the world's first fully remote legislative system used by the Latvian Parliament. Today, Kirils serves as lead researcher at Possible Security.
- Security Impress Karaoke
- Reverse Engineering FERMAX: Detour, Dead End, and Scope Creep
Lena is a cryptographer working on privacy in a post-quantum world. She focuses on blind evaluation for privacy-preserving protocols, while also gossiping about transparency on the side.
Outside of cryptography, she stares at chessboards and is looking for the perfect minimal techno beat to match her complexity problems.
- Post-Quantum Cryptography for the Novice, the Enjoyer, the Deployer and the Academic
Known for community shenanigans like Karaoke and bringing people together. Also does strange things (to and) with Macs, BSD, automation, 3d-printing, model building and radio communications. Rumoured to be the proprietor of an extensive collection of USB-Testing devices.
All my content is always free from AI-slop!
- Karaoke - Some sing to remember, some sing to forget
- Compression, how does it even work?
Maja Miljanić is a teaching assistant at RAF (Faculty of Computer Science), where she teaches Operating Systems and Web Security. She also leads a small engineering agency focused primarily on IoT and embedded systems projects. Throughout her career, she has designed and implemented a wide range of IoT solutions for industrial and commercial applications involving large-scale device deployments. Her work includes smart access control systems, IoT solutions for the hospitality industry, edge devices for the energy sector, IoT charging stations, and platforms for industrial cybersecurity testing.
- You build vulnerable hardware accidentally. I do it on purpose. We are not the same. (Behind the scenes of building hardware CTF challenges)
Robert Simmons is Principal Malware Researcher at ReversingLabs. With an expertise in building automated malware analysis systems based on open source tools, he has been tracking malware and phishing attacks and picking them apart for years. Robert, also known as Utkonos, has a background in Biology, Linguistics, and Russian Area Studies. He has spoken on malware analysis and reverse engineering at many of the top security conferences including BalCCon, DEFCON, HOPE, botconf, and DerbyCon among others. He is also the maintainer of plyara, a YARA rule parser written in pure python as well as x64dbgbinja the official connector integration between x64dbg and Binary Ninja.
- Shellcode: Learning to Write Position Independent Code
- Comparing Malicious Files 2.0
Humble man 2
- The Eye
- Universal Plug and Pwn
Matthias Kirschner is President of FSFE. In 1999 he started using GNU/Linux and realised that software is deeply involved in all aspects of our lives. Matthias is convinced that this technology has to empower society not restrict it. While studying Political and Administrative Science he joined FSFE in 2004.
He helps other organisations, companies and governments to understand how they can benefit from Free Software -- which gives everybody the rights to use, understand, adapt, and share software -- and how those rights help to support freedom of speech, freedom of press or privacy.
In his spare time, he has written the book "Ada & Zangemann - A Tale of Software, Skateboards, and Raspberry Ice Cream", which is translated in over 30 languages and meanwhile also available as a movie.
- A vision for software freedom in 2048
Miša(misadeks) is a software engineer, telecommunications student, and licensed ham radio operator. With a passion for embedded system design and building technology from scratch, his work sits at the intersection of low-level radio infrastructure and software development. Lately, his focus is on RF reverse-engineering and exploring modern radio communications.
- TETRA Workshop
- TETRA on a Student Budget
Natasha is an HR strategist and founder of Konsultallika, with a background in psychology and extensive experience in recruitment, candidate assessment and organizational consulting. She has interviewed thousands of professionals across IT, cybersecurity, consulting, finance and international institutions. Her current work focuses on the connection between human risk, organizational behavior and cybersecurity, especially how hiring, culture and internal systems influence security outcomes.
- Human Error Is Not the Problem: How Hiring, Culture and Psychology Shape Cyber Risk
By some strange chain of events, Nikola became the author and maintainer of several open-source projects related to digital documents in Serbia. When he is not maintaining those projects, he writes about mathematics and functional programming.
- Cryptography with Serbian eID Cards
I’ve always admired those that said “You will not have to work for the rest of your life if you make money from your hobby”. Especially if it meant a true “impact that matters” for people and their daily life. While it was fun to study and play with my friends in “Aggressive Cake” (a fitting name for a CTF team) as a freshman, it soon became apparent that reality is far from the innocent dream of doing what you love.
4 years forward, and really started wondering, if it would be better to become a fisherman. After all, the sea tides are less harsh than the life of a responder. Working overtimes to get the thrill of catching the bad guys was not worthy. Sometimes I really hope that AI takes this job (and auditing) away...
I like petting stray cats and watching sunsets.
- Memory Forensics in the age of EDR
I am a Cloud Security and Platform Engineering leader focused on building detection, incident response, and security operations capabilities for cloud-native organizations., I've presented on Cloud Security and Incident Response at Ekoparty, FIRST, Virus Bulletin (three times), Hack.Lu, and various BSides events worldwide. I hold a Bachelor's degree in Information Security and an MBA (Master in Business Administration).
- AWS Security - The Purple Team Way
Šava is an electrical engineer with a passion for breaking things open and seeing how they work. Lately has been researching subjects closely related to telecommunications. Likes exploring new ideas and sharing knowledge.
- TETRA Workshop
- TETRA on a Student Budget
IR & Security Analysis
- Fun with virtualization
Stephan Berger is the Head of Investigations for an Incident Response team at InfoGuard, a Swiss-based cybersecurity firm. With over a decade of experience investigating complex network compromises, he specializes in the technical intersection of offensive tradecraft and defensive forensics. Stephan is the author of the DFIR.ch technical blog and is a regular speaker at international security conferences, including FIRST, Troopers, and hack.lu. He holds a Bachelor’s degree in Computer Science and a Master’s degree in Engineering and is the founder of Malmium, a specialized technical training provider.
- Deconstructing Modern macOS Initial Access Vectors
- You build vulnerable hardware accidentally. I do it on purpose. We are not the same. (Behind the scenes of building hardware CTF challenges)
Timo is a lead DFIR consultant on Accenture’s Global Cyber Readiness, Response & Recovery team, where he spends his days digging through compromised endpoints, cloud tenants, and mobile devices.
He has been working in cyber security since 2009 and full-time in incident response and digital forensics since 2018.
- Mobile Device Forensics 101
Tonimir Kisasondi is a co-founder at Apatura, a boutique security consultancy from Varazdin, Croatia. His professional and research area of interest is application security, cryptography and embedded security.
- Hunting for business logic vulnerabilities
Seasoned security expert in fields of electronics, automotive, and finance with more than 25 years of experience working for the most interesting clients.
- How I became a Voodoo doll model
Vlatko Kosturjak serves as the VP of research at Marlink Cyber, boasting over two decades of dedicated experience in the realms of information security and cybersecurity. His diverse roles over the years have not only equipped him with a comprehensive understanding of security governance but also delved into the deep technical side of security.
As part of Marlink group, he helps in securing different critical industries including maritime. Over many years of commercial cyber activities, he have successful M&A experience in different fields of cyber security in different roles.
- Hacking in the Middle of the Ocean
Threat-intelligence specialist working at the intersection of AI and cybersecurity. National ethical-hacking champion (SCC2025) and part of Serbia's extended national team. Hands-on across malware analysis, endpoint protection, and SIEM operations in both enterprise and small-scale environments
- Defending LLMs with LLMs: A Multi-Agent Approach to Prompt Injection
- Manufacturing Minesweeper!
PhD student at UniVie and CTF player at We_0wn_y0u. Passionate for reverse engineering, graphics programming and all kinds of low-level software development.
- The Hitchhikers Guide to Hacking Cheap Bluetooth Speakers
- Hacker Jeopardy
El Kentaro is the guy who builds wifi gadgets for fun and has been involved with the hacker community for over two decades. Kentaro enjoys watching movies and taking long warwalks at night strolling through the dark corners of Tokyo.
- AI can't solder or Imagine (yet)
Senior researcher at SBA Research in Vienna, dealing mostly with systems and firmware stuff. Dabbled in pentesting as well as teaching at TU Wien. Collecting flags with We_0wn_Y0u for well over a decade. Tinkering with all kinds of hardware (when there's time left).
- The Hitchhikers Guide to Hacking Cheap Bluetooth Speakers
- Hacker Jeopardy
Igor Brkić is software and hardware engineer from Croatia covering areas from the custom hardware and firmware development to the system and web development.
- Power Analysis Attacks 101: From Waveform to Private Key
I'm a German software engineer who likes to bike, read, dance, playing games, sailing and a lot more. I'm also interested in politics and some economic critique. I sometimes give talks about those topics.
- Pen & Paper Workshop
Providing IT-Wizardry for money for over 20 years. Boldly managing systems where angels fear to tread. Easily distracted by everything shiny, blinky and new.
- From Zero to root in 120 minutes - Introduction to Wordpress Hacking
Just random guy
- Meshtastic is dead, long live meshtastic
Vlachian wizard with legal knowledge.
- BalCCon Amateur Lockpicking Competition 2K26
Humble man.
- The Eye