Loading…
Attending this event?
Beginner clear filter
arrow_back View All Dates
Wednesday, October 2
 

9:05am GMT+08

Future as Code: Hackers, Community, and the Fabric of Our Digital World (Keynote)
Wednesday October 2, 2024 9:05am - 9:45am GMT+08
In an era where digital transformation is accelerating, our future is being written, "coded", by the decisions we make today. But securing this future requires more than just traditional security measures; it demands the ingenuity of hackers and the power of community-driven collaboration. This keynote explores how the hacker mindset and community innovation are key to embedding security into the very DNA of our digital infrastructure. By leveraging the creativity, curiosity, and collaborative spirit of the hacking community, we can craft a resilient digital future where security is not an afterthought but a fundamental element. This talk will challenge you to rethink how we approach security, empowering hackers and communities to shape a safer, more secure digital world—one line of code at a time.
Speakers
avatar for Emil Tan

Emil Tan

Head Crew & Co-Founder, Division Zero (Div0), Singapore Cybersecurity Community Group
Emil Tan is currently serving the role of Cyber Strategist and Market Lead in Critical Infrastructure at Booz Allen Hamilton. He is also the Chief Community Officer (CCO) at Red Alpha Cybersecurity, a leading cybersecurity talent development company, and the Chair of the CREST Asia... Read More →
Wednesday October 2, 2024 9:05am - 9:45am GMT+08
Room: Jasmine Ballroom Marina Bay Sands Convention Center
  Keynote

9:50am GMT+08

Leveraging OWASP Projects and Tools in Your AppSec Program
Wednesday October 2, 2024 9:50am - 10:30am GMT+08
The Open Web Application Security Project (OWASP) boasts over 200 Projects, whose volunteers have developed tools and resources covering nearly every aspect of application security and software assurance. The challenge lies in knowing what they are, where to find them, and how they can help.

In this talk, we'll present brief glimpses of more than 30 interesting and useful OWASP Projects - including the current Flagship and Production Projects. We'll provide insights into how each can be used to build and improve your AppSec program, in every phase of the development lifecycle.
Speakers
avatar for John DiLeo

John DiLeo

Application Security Lead, OWASP New Zealand
Dr. John DiLeo leads the OWASP New Zealand Chapter. In his day job, John is the Application Security Lead at Gallagher Security in Hamilton. Before joining Gallagher, John led the Application Security Services team at Datacom NZ, providing support and guidance to clients in launching... Read More →
Wednesday October 2, 2024 9:50am - 10:30am GMT+08
Room: Jasmine Ballroom Marina Bay Sands Convention Center

11:30am GMT+08

Supercharge your AppSec Program with OWASP Appdome Consumer Mobile Security Report 2024 and OWASP MASVS
Wednesday October 2, 2024 11:30am - 12:10pm GMT+08
As AppSec professionals, securing and protecting our users and business is paramount. This session will delve into data from the OWASP Appdome Global Consumer Mobile Security Expectations Report, launched at OWASP Global AppSec in Lisbon, with a focus on Singapore and APAC consumer insights. We will explore the latest mobile threats such as social engineering, vishing, smishing, fraud, overlay attacks, accessibility exploits, bots, and more. Additionally, we'll provide updates on the OWASP mobile project and demonstrate how to leverage consumer voices in security discussions with developers and business leaders to drive prioritization and success in your mobile AppSec program. This session is applicable to all AppSec teams, whether focused on mobile, web, or API security.
Speakers
avatar for Brian Reed

Brian Reed

Appdome
Brian has been working with OWASP mobile project for 9 years serving as an OWASP MAS Advocate, contributor and speaker at dozens and dozens of owasp global, regional and local meetups and other cyber and mobile communities . With nearly 20 years in mobile security, he's a recognized... Read More →
Wednesday October 2, 2024 11:30am - 12:10pm GMT+08
Room: Jasmine Ballroom Marina Bay Sands Convention Center

2:50pm GMT+08

API Security Top 10 for Real
Wednesday October 2, 2024 2:50pm - 3:30pm GMT+08
Real examples of API security breaches, how they map to the OWASP API Security Top 10, and what you can do about it in your own projects. This presentation will dive deep into recent API security incidents, illustrating the vulnerabilities outlined in the OWASP API Security Top 10 – 2023. We will explore practical mitigation strategies to enhance the security of your APIs and protect your data from similar threats.
Speakers
avatar for Jon Scheele

Jon Scheele

Founder and CEO, Blue Connector
Jon Scheele has over 20 years experience in leading technology strategy, data analytics, security, and interoperability initiatives in financial services and telecommunications.Jon leads training and projects for clients to define digital product strategies and roadmaps aligned with their business objectives.Jon excels in assembling multi-disciplinary teams to identify customer needs, develop, launch, and govern digital products, and cultivate vibrant de... Read More →
Wednesday October 2, 2024 2:50pm - 3:30pm GMT+08
Room: Jasmine Ballroom Marina Bay Sands Convention Center

3:45pm GMT+08

LLM Security Is Broken: Data Collected From An AI Wargame
Wednesday October 2, 2024 3:45pm - 4:25pm GMT+08
This presentation captures findings from a public AI security challenge designed to evaluate the resilience of Large Language Models (LLMs) against prompt injection attacks. The experiment involved an Attack & Defence wargame where participants were tasked with securing their LLMs, specifically preventing secret phrase disclosure. They were given access to the source code of the app that interfaced with OpenAI API. Simultaneously, participants were to attack other LLMs in an attempt to exfiltrate the secret phrase. A notable aspect of this experiment was the real-time evolution of defensive strategies and offensive tactics by participants. The results indicated that all LLMs were exploited at least once. This underscores how there is no silver bullet for securing against prompt injection and that it remains as an open problem.
Speakers
avatar for Dr. Pedram Hayati

Dr. Pedram Hayati

Founder and CEO, SecDim
Dr. Pedram Hayati is the Founder and CEO of SecDim, where he focuses on redefining developer engagement in security through developer-oriented wargames. As a security researcher proficient in OffSec and AppSec, he has reported thousands of vulnerabilities to Fortune 500 companies... Read More →
Wednesday October 2, 2024 3:45pm - 4:25pm GMT+08
Room: Jasmine Ballroom Marina Bay Sands Convention Center

5:15pm GMT+08

Unlocking the Power of Security Culture: A Journey Beyond Shifting Left
Wednesday October 2, 2024 5:15pm - 5:55pm GMT+08
In this talk, I will discuss various initiatives that security teams can adopt to build strong relationships with engineers and foster a behavioral change. Attendees will gain insights into the holistic approach needed to integrate security seamlessly into the development process.














Speakers
avatar for Gowtham Sundar

Gowtham Sundar

I am a cybersecurity professional with extensive experience in application security. My expertise includes leading teams, developing strategies and implementing initiatives to strengthen the security posture of organizations. I'm always eager to share my knowledge and insights with... Read More →
Wednesday October 2, 2024 5:15pm - 5:55pm GMT+08
Room: Jasmine Ballroom Marina Bay Sands Convention Center