Conference 2026

Program

November 5th to 6th, 2026
La Marive, Yverdon-les-Bains

Cutting Edge Technical Talks... and more!

#BlackAlps26 program has been prepared by an independent, neutral committee of internationally recognized experts. The program committee reviewed many proposals and selected the most appropriate and interesting talks for the conference (except the keynotes and rumps).

Learn more about the Call For Proposal and committee.


All sessions will be held at La Marive, Yverdon-les-Bains, except for the Networking Dinner on Friday 6 November.

Thursday November 5th, 2026

08:30 - 09:00
LIVE
Welcome and coffee
09:00 - 09:15
LIVE
Opening Words, Day 1 (en)
Sylvain Pasini (HEIG-VD)
09:15 - 09:45
LIVE
Building Systems That Survive Attack: Lessons from Banknote Security (en)
Üni Bio (SICPA)
09:50 - 10:20
LIVE
Inside Linux GoGra Backdoor (en)
Axelle Apvrille (Fortinet)
10:45 - 11:15
LIVE
When Cryptography Meets Reality: Insights from the Swiss Post E-Voting Protocol (en)
Chiara Spadafora (Swiss Post)
Audhild Høgåsen (Swiss Post)
11:20 - 11:50
LIVE
The MCU Under Your Fingertips: Reversing Tablet Touchscreen Controller (en)
Petr Hodina
David Heidelberg
11:55 - 12:25
LIVE
LTECruiser: An Extremely Low Cost LTE Experimentation Framework (en)
Edoardo Mantovani
12:25 - 14:10
LIVE
Lunch
14:10 - 14:40
LIVE
Swiss PACS: Two Tales of Vulnerability Disclosure (en)
David Haas
14:45 - 15:15
LIVE
Attacking & Abusing EDRs: Vulnerabilities Across the Attack Surface (en)
Manuel Feifel
15:15 - 15:40
LIVE
Coffee Break
Free access with the "Open Session" ticket
15:40 - 16:10
LIVE
From Discovery to Action: Rethinking AppSec with Agentic Pipelines and MTTA (en)
Daniel Fernandez Coviella
16:15 - 16:45
LIVE
[Keynote] The Evolution of Adversarial AI: Tales from the Frontlines of Threat Intelligence (en)
Daniel Kapellmann Zafra
16:45 - 17:00
LIVE
Welcome and coffee
17:00 - 18:00
LIVE
Open Session (fr)
L'IA bouleverse la cybersécurité : évolution ou révolution ?

4 présentations flash de 5 minutes croisant les regards institutionnel, offensif, défensif et pédagogique sur l'IA en cybersécurité, suivies d'une table ronde de 30 minutes et d'un temps de questions du public (10-15 min).

Intervenants :
Clélia Runtz, OFCS (vue de la Confédération)
Alain Mowat, Orange Cyber Defense (vue offensive)
Rafik Chaabouni, Rothschild & Co Bank AG (vue défensive)
Sylvain Pasini, HEIG-VD (vue formation)
18:00 - 19:00
LIVE
Aperitif
19:00 - 19:30
LIVE
Travel
19:30 - 23:30
LIVE
Networking dinner (en-fr)
Salle des quais (Grandson)
Mandatory registration
‎‎ ‎

Friday November 6th, 2026

08:30 - 09:00
LIVE
Welcome and coffee
09:00 - 09:10
LIVE
Opening Words, Day 2 (en)
Sylvain Pasini
09:10 - 09:40
LIVE
Multi-taint Analysis for Constant-Time Verification: From False Positives to Confirmed Leaks (en)
Damien Maier
09:45 - 10:15
LIVE
SEMSAN: Finding the 0-Days You Can't Crash Into (en)
Moritz Sanft
10:15 - 10:40
LIVE
Coffee Break
10:40 - 11:10
LIVE
Not How Fast, But How Well: A Practitioner's PQC Migration (en)
Sonia Duc
11:15 - 11:45
LIVE
Enterprise AI over-trust: Abusing M365 Copilot via Legacy Paths (en)
Mark Vaitsman
Dolev Taler
11:50 - 12:20
LIVE
Reversense: closing the loop between instrumentation and representation in reverse engineering (en)
Georges-Bastien Michel
12:20 - 14:05
LIVE
Lunch
14:05 - 14:35
LIVE
NotC2: Trusted by Default, Malicious by Design - AWS-Native Notifications as C2 (en)
Mark Vaitsman
Or Soria
14:40 - 15:10
LIVE
n8ive by Design – One Leaked Key. Multiple n8n Attack Chains (en)
Guillaume Valadon
15:15 - 15:45
LIVE
Memory Tagging Under Pressure: Hunting a TOCTOU in the iPhone 17 Kernel (en)
Kaya Ercihan
15:45 - 16:10
LIVE
Coffee Break
16:10 - 16:25
LIVE
Cracking Open a DJI Drone: From Locked-Down Firmware to Playing With TEEs (en)
Nicolae Binică
16:45 - 17:45
LIVE
Rump Session (fr-en)
Several speakers
17:45 - 19:00
LIVE
Aperitif
19:00 - 23:45
LIVE
CTF
Mandatory registration‎‎‎
‎‎‎
Welcome at 18:45‎‎‎
Start at 19:00‎‎‎
End at 23:30‎‎‎
‎‎‎
Awards at 23:45
LIVE
Black Dinner (en-fr)
ㅤㅤㅤㅤㅤ
Free for all #BlackAlps26 participantsㅤ
ㅤㅤㅤㅤㅤ
ㅤㅤㅤ

Legend

 
Conference
 
Keynote
 
Lightning Talks
 
Side event
 
Evening

Talk selection process

A call for proposal (CFP) was organized. The program committee was in charge to select the talks (except the keynotes and rumps). The submission process is now closed (it was open until June 30, 2026.).

Program committee

The program committee is composed of international renowned experts in the field.

Proposal topics

  • Application security
  • Vulnerability research and exploits development
  • Penetration testing and red teaming
  • Cloud security
  • Security automation
  • Network security
  • Intrusion detection and monitoring
  • Cryptography