Annenberg Beach Access

AppSec

June 03 2026

What Attendees say

The technical deep-dives are fantastic – I always walk away with new tools or techniques I’m excited to try out. You can tell the organizers are doing this for the community – from the thoughtful mix of speakers to the awesome variety of venues..

Chris Cantey

IT & Security Consultant at Wonders

The talks delivered real, practical value – not just high-level theory or vendors promoting their products – and I walked away with actionable insights I could apply right away.  I’d absolutely attend again.

Horica "Rico" Ionescu

Information Security Manager at Finvi

It was a fantastic opportunity to learn from fellow practitioners, share real-world insights, and make meaningful connections. A must-attend event for anyone passionate about application security and staying ahead in the field…

Uttej Badwane

Senior Security Engineer at Carta

Join us at Planet Cyber Sec AI AppSec, where security professionals, developers, and business leaders come together to bridge the gap between AI, agile development and strong security practices. This high-energy conference brings together top talent from around the world and California’s dynamic InfoSec community.

Take part in engaging talks, practical sessions, and meaningful conversations that deliver real-world insights into secure software development. You’ll have plenty of opportunities to connect with peers, learn from experienced professionals, and grow your network.

At AI AppSec, you’ll:

  • Learn from leading experts and seasoned speakers who share practical insights on secure software development.

  • Build valuable relationships and collaborate with top-tier cybersecurity professionals.

  • Engage in insightful discussions and workshops tailored to today’s most relevant security trends.

  • Earn CPE credits while strengthening your software security skills.

Set at the beautiful Annenberg Community Beach House along California’s scenic coastline, AI AppSec offers an inviting atmosphere ideal for networking, relaxing, and enjoying beachside moments with peers.

Want to be the first to know when registration opens?
Join our newsletter and stay informed as we release the full agenda and speaker lineup.

We look forward to seeing you there!

Featured Speakers

Ira Winkler

Opening Keynote

Ira Winkler

Field CISO @ AISLE

Julie Morris

Closing Keynote

Julie Morris

Head of Executive Thought Leadership | Persona Media

Michael Wylie

Michael Wylie, MBA, CISSP

Author | Speaker | 4x CVEs | Threat Hunter | People Leader

Edward Bonver

Edward Bonver

Product Security / Cybersecurity Leader

Richard Greenberg

Richard Greenberg

CEO, Layer 8 Masters

Ron Dilley

Ron Dilley

Field CISO at Reflex Security

Chris Lindsey

Chris Lindsey

US Field CTO, OX Security

Serafino Sini

Serafino Sini

Senior Cybersecurity Executive and CISO for North America at Yamaha Motor Corp., USA

Bennett Norton

Bennett Norton

Solutions Leader at Armis

David Boewer

David Boewer

Exposure Management Field CTO at Armis

Chris Ward

Chris Ward

CEO, Fire Mountain Labs

Horica Ionescu

Horica “Rico” Ionescu

Information Security Manager at Finvi

Dutch Schwartz

Dutch Schwartz

Field CISO and Evangelist, Nisos

Alexander Braehler

Alexander Braehler

Founder & CEO at Tekkno, Inc., COO, Layer 8 Masters

Sana Talwar

Sana Talwar

Product Security Engineer, ServiceNow

Fayeron Morrison

Fayeron Morrison, CPA, CFE

Founder and President of Elemental AI

Dan Meacham

Dan Meacham

Vice President of Cyber and Content Security at Legendary Entertainment

Jason Kramer

Jason Kramer

Senior AI Engineer

James Green

James Green

Co-founder & Chief Product Officer at Heeler

Jimmy Xu

Jimmy Xu

Field CTO at Cycode

Mike Miller

Mike Miller

Solutions Consultant at Upstack

Sponsors, Orgs, Exhibitors

June 03 2026

Prev Next

8:00 AM - 8:45 AM

Registration & Breakfast & Networking

8:45 AM - 9:00 AM

Garden Terrace Room

Richard Greenberg

Richard Greenberg

Ceo at Layer 8 Masters

Welcome Address

Welcome to the Planet Cyber Sec AI Conference. Join us in Room Garden Terrace for the Welcome Note to kickstart a day of insightful discussions and networking.

Get to Know Our Exhibitors & ORGs

As part of our commitment to supporting the broader cybersecurity community, we’ve invited non-profit organizations and exhibitors in the InfoSec space to take part in this year’s conference. During this session, each group will briefly introduce themselves, share their mission, activities, and how you can get involved. If you'd like to learn more, be sure to visit their booths throughout the day.

9:00 AM - 9:35 AM

Garden Terrace Room

Chris Ward

Chris Ward

CEO, Fire Mountain Labs

Breaking the Black Box: An Overview of AI Governance and Tabletop Simulation

This session provides an overview of AI governance, combining framework fundamentals with a walkthrough of a live tabletop simulation. Participants will explore the AI model lifecycle and learn how to apply the NIST AI RMF and MITRE AI Maturity Model to manage real-world risks and build organizational resilience.

9:40 AM - 9:50 AM

Garden Terrace Room

Jimmy Xu

Jimmy Xu

Field CTO at Cycode

Lightning Talk

Securing the Agentic Development Lifecycle – From AI Risk to Machine Speed Remediation

AI is rapidly transforming software development from a linear process into a continuous, autonomous system — what many are now calling the Agentic Development Lifecycle (ADLC). AI agents can now plan, generate, test, deploy, and even remediate software with minimal human intervention. As a result, application security is shifting from securing applications alone to securing the entire AI-driven software lifecycle itself.

In this lightning talk, Jimmy explores how modern application security must evolve to defend the Agentic Development Lifecycle, where the system that builds software increasingly becomes the system attackers target. Through modern AI attack chains and emerging real-world attack patterns, this session breaks down how organizations should approach security across five critical areas:

• Discovery — understanding the AI ecosystem, agents, and dependencies
• Governance — defining policy, identity, and control boundaries
• Guardrails — enforcing safe behavior in real time
• Runtime Defense — continuously observing, adapting, and responding at machine speed
• AI-Powered Remediation — prioritizing real exploitability and reducing existing security backlog with autonomous remediation

The session also addresses a critical reality: while governance and guardrails help reduce new risk, organizations still face massive existing vulnerability backlogs — and AI is dramatically accelerating exploitation.

The talk concludes with a live demonstration of how modern ADLC Security Platforms like Cycode can apply visibility, governance, guardrails, and AI-assisted remediation in real-world AI-native development environments.

9:55 AM - 10:15 AM

Garden Terrace Room

Bennett Norton

Bennett Norton

Solutions Leader at Armis

David Boewer

David Boewer

Exposure Management Field CTO at Armis

Lightning Talk

Shift Smart, Shift Zero: Unleashing Autonomous AppSec Without Losing Control

"Shift Left" gave us alert fatigue. "Shift Smart" helped prioritize. Now, welcome to Shift Zero: the era of invisible, frictionless security powered by autonomous AI agents. But who secures the bots? Join us to discover how Agentic Development Security (ADS) can automate your AppSec pipeline, and learn how to use the OWASP Agentic Security Initiative (ASI) to stop attackers from hijacking your AI guardrails. Stop burning out developers and start building secure, autonomous pipelines today.

10:15 AM - 10:35 AM

Break - Vendor Expo

10:35 AM - 11:20 AM

Garden Terrace Room

Ira Winkler

Ira Winkler

Field CISO @ AISLE

Opening Keynote

The Myth of Mythos

Anthropic's recent announcement of the Mythos tool was akin to a seismic event in cybersecurity. The US government got involved and called a meeting of banking executives. Words like apocalypse were thrown around. This presentation will address the hype versus the reality of Mythos. It will allow attendees to understand the issues and figure out how Mythose actually impacts you.

11:25 AM - 11:35 AM

Garden Terrace Room

James Green

James Green

Co-founder & Chief Product Officer at Heeler

Lightning Talk

Preparing for the Post-Mythos Vulnerability Apocalypse: A Fix-First Future

As new large-scale disclosure events (“Mythos”-level moments) reshape the landscape, security and engineering teams are left overwhelmed by endless findings, manual triage, and upgrade fatigue.

In this talk, James Green explores what it means to prepare for the “post-Mythos” world and why the industry must move beyond detection. Instead, he introduces a fix-first approach that shifts the burden away from developers and toward intelligent automation.

By leveraging autonomous agents, organizations can automatically generate validated pull requests for dependency upgrades, continuously monitor CI feedback loops, and iteratively resolve failures. Delivering merge-ready fixes without developer toil.

Attendees will learn how to:

  • Rethink vulnerability management in an era of constant disclosure
  • Eliminate manual triage and reduce developer friction
  • Implement agent-driven remediation workflows that scale
  • Create continuous feedback loops that ensure fixes actually ship

This session offers a practical blueprint for moving from “more findings” to real risk reduction: at scale.

11:40 AM - 11:50 AM

Garden Terrace Room

Chris Lindsey

Chris Lindsey

US Field CTO at OX Security

Inside the Modern Threat Landscape: Attacker Wins, Defender Moves, and Your Priorities

Every AI security tool you use today depends on a cloud API call. Your threat detection, your incident triage, your intel analysis, all of it running on someone else's infrastructure.

What happens when that's not an option? Or when you decide it shouldn't be?

While defenders continue to invest in stronger controls, attackers increasingly succeed by exploiting existing trust paths. Today's most impactful breaches are less about novel exploits and more about consistently abused techniques.

This session examines how modern compromises actually occur, based on analysis of aggregated real-world incident data. Rather than cataloging breach headlines, we focus on the attack techniques currently delivering the highest return for adversaries, the assumptions they repeatedly exploit, and why these patterns continue to succeed. We then evaluate which defensive mitigations are measurably reducing risk in production environments — and which commonly recommended practices are proving less effective.

To ground these patterns in concrete attacker tradecraft, the session includes a technical dissection of two Chrome extensions — with over one million active installations — that functioned as trojans in production environments, evading detection while operating entirely through legitimate browser APIs. These were not obscure tools. They were widely trusted, actively recommended, and covered by mainstream press before their malicious behavior was fully understood. We will walk through the actual source code of both extensions, showing precisely how the malicious functionality was constructed, concealed, and executed at scale.

Attendees will leave with:

  • A breakdown of the three attack vectors responsible for a disproportionate share of recent breaches
  • A line-by-line analysis of two real-world trojanized Chrome extensions, including the techniques used to evade detection and abuse trusted browser APIs
  • A practical framework for evaluating defensive investments based on security-per-dollar impact
  • A risk prioritization approach grounded in observed attacker behavior rather than theoretical threat models

Who should attend:
Security architects, AppSec and cloud security practitioners, blue team leads, and security leaders responsible for prioritizing risk and investment decisions.

What this session is not:
A vendor pitch, a breach post-mortem, or a speculative look at future threats.

11:50 AM - 1:00 PM

Lunch - Vendor Expo

1:00 PM - 1:35 PM

Garden Terrace Room

Michael Wylie. MBA, CISSP

Michael Wylie. MBA, CISSP

Author | Speaker | 4x CVEs | Threat Hunter | People Leader

Talk

The AI-Assisted Cybersecurity Analyst

AI is fundamentally reshaping the cybersecurity landscape, and if defenders don’t learn to master AI as a copilot, the attackers will be unstoppable. This talk will explore how AI serves not as a replacement, but as a powerful "copilot" that augments human expertise, allowing analysts to handle the overwhelming volume and velocity of modern cyber threats. No marketing fluff, just real talk. 

Key Takeaways:

  • Pattern Recognition at Scale: Learn how AI's core strength is its unparalleled ability to identify subtle, malicious patterns buried within massive datasets of benign artifacts, a feat often impossible for human analysts or traditional rule-based systems.
  • The Power of Prompt Engineering: Demystify the art and science of communicating with LLMs. We will break down the essential elements of a high-quality prompt (Instructions, Context, Input Data, and Output Indicators) to ensure precise, actionable, and relevant results in day-to-day security tasks.
  • Advanced AI Tuning: Discover how to use powerful controls like the System Prompt to define the AI’s persona (e.g., Threat Hunter, Incident Responder) and how the Temperature hyperparameter can be adjusted for tasks requiring high precision (low temperature) versus creative brainstorming (high temperature).

1:40 PM - 2:15 PM

Garden Terrace Room

Ron Dilley

Ron Dilley

Field CISO at Reflex Security

Sovereign AI: Building Security Capabilities That Never Phone Home

Every AI security tool you use today depends on a cloud API call. Your threat detection, your incident triage, your intel analysis, all of it running on someone else's infrastructure.

What happens when that's not an option? Or when you decide it shouldn't be?

The hardware caught up. The models got small enough. The protocols standardized. I'll walk through what a local AI security stack looks like in practice: local inference, persistent memory, tool integration through MCP, all running on hardware you control. What fits on what hardware, which security use cases actually work better locally, and the engineering that makes it reliable enough to trust.

Not anti-cloud. Just pro-choice about where your security data goes.

No vendor pitches. Built and running today.

2:20 PM - 2:55 PM

Garden Terrace Room

Cybersecurity Leaders Panel

Join Cybersecurity leaders on a dynamic panel, which will be focusing on the rapidly changing and evolving challenges presented by AI adoption, internally and externally. Other panelists include Serafino Sini, CISO for North America at Yamaha Motor Corp., USA, and Horica Ionescu, Information Security Manager at Finvi
Richard Greenberg

Richard Greenberg

CEO, Layer 8 Masters

Moderator

Serafino Sini

Serafino Sini

Senior Cybersecurity Executive and CISO for North America at Yamaha Motor Corp., USA

Panelist

Fayeron Morrison, CPA, CFE

Fayeron Morrison, CPA, CFE

Founder and President of Elemental AI

Panelist

Horica "Rico" Ionescu

Horica "Rico" Ionescu

Information Security Manager at Finvi

Panelist

Dan Meacham

Dan Meacham

Vice President of Cyber and Content Security at Legendary Entertainment

Panelist

2:55 PM - 3:15 PM

Break - Vendor Expo

3:15 PM - 4:00 PM

Garden Terrace Room

Julie Morris

Julie Morris

Head of Executive Thought Leadership | Persona Media

Closing Keynote

Your Cyber Why: Strategic Personal Positioning for a Future-Proof Career

You are not a commodity. You are one of a handful of people who can do what you do. But most of us are still defined by the work in front of us each day. High capability often means being under-positioned for what comes next, being seen too narrowly, and missing opportunity, growth, and influence.

Julie Morris examines strategic personal positioning as the lens and filter through which others experience you: in day-to-day leadership, broader reputation, and demonstrated value. Through strong same-market examples, she will show how to operationalize your positioning in a market being reshaped by AI.

4:00 PM - 5:00 PM

Happy Hour and Raffle Drawing

9:00 AM - 9:35 AM

Club Room

Dutch Schwartz

Dutch Schwartz

Field CISO and Evangelist, Nisos

Talk

Your New Hire Works for Pyongyang

North Korea doesn't need to breach your perimeter. They're submitting resumes.
DPRK-affiliated IT workers have infiltrated numerous Fortune 500 company, generating $250M to $800M annually to fund ballistic missile programs. Detected incidents have jumped 220% year-over-year. If your company hires remote employees, regardless of your company size, then you are a target. Traditional background checks will not solve this because these are state-sponsored actors using stolen identities.

In this session, we will walk through how the scheme works; AI-generated identities, deepfake interviews, domestic laptop farms, and coordinated operator networks surviving inside companies for up to 14 months. We will ground it in real cases, then leave you with a practical highlight of the top TTPs that you can implement immediately.

9:40 AM - 10:15 AM

Club Room

Mike Miller

Mike Miller

Solutions Consultant at Upstack

Talk

Finding the Right MSSP: What Works, What Doesn’t, and Why

Learn the process in which Mike has used for over a decade to help clients vet, compare and select Managed Security Partners. As a vendor agnostic solutions consultant Mike has developed a thorough process for discovering the needs and desired outcomes of the client, selecting a short list of providers that are best fit to support, jointly evaluating providers for best fit, negotiating best solution and assisting in deployment and ongoing support as the partner. Learn how the process has worked with numerous engagements and lessons learned to help you in your next Managed services Partner evaluation.

10:15 AM - 10:35 AM

Break - Vendor Expo

11:25 AM - 11:50 AM

Club Room

Alexander Braehler

Alexander Braehler

Founder & CEO at Tekkno, Inc., COO, Layer 8 Masters

Talk

Building Deterministic IaC: Lessons from a Real-World Attempt

Infrastructure as Code promises deterministic, repeatable systems—but in practice, hidden state, environment dependencies, and inconsistent tool behavior introduce non-determinism in subtle ways. In this session, I share a 6+ month real-world attempt to eliminate non-determinism from an IaC-driven environment. Rather than focusing on tools or best practices, this talk examines where those practices break down under real conditions—across APIs, execution environments, and automation workflows. Attendees will gain a practical understanding of where determinism fails in modern infrastructure, what it actually takes to enforce it, and how to decide where that level of rigor is worth the cost.

11:50 AM - 1:00 PM

Lunch - Vendor Expo

1:00 PM - 1:35 PM

Club Room

Jason Kramer

Jason Kramer

Senior AI Engineer

Talk

Your Model Remembers More Than You Think

Pretrained models power today’s AI systems, but they also import unknown and often undetected vulnerabilities. When teams fine-tune and deploy these models, they assume they are shaping behavior. In reality, they may be inheriting it.

This session shows how adversarial behaviors, including evasion techniques, poisoned data artifacts, and hidden backdoors, persist across model reuse and transfer into downstream systems. Through real experiments and NIST-supported evaluations, we demonstrate how these risks survive fine-tuning and evade traditional validation methods.

We break down why current testing approaches fail and how attackers can exploit model inheritance as an attack amplifier. We also present practical detection and mitigation strategies that work in real-world environments where retraining is not always feasible.

1:40 PM - 2:15 PM

Club Room

Sana Talwar

Sana Talwar

Product Security Engineer, ServiceNow

Talk

Prompt Injection: When Words Become Exploits

Your AI reads an email, then follows a link and summarizes a document. What if any of those contained instructions? Prompt injection lets attackers hijack AI systems not by breaking in, but by slipping commands into data the model is already processing. This talk goes deep on real CVEs, documented incidents, and peer-reviewed research: from a GitHub Copilot RCE to Slack AI data exfiltration to enterprise RAG manipulation. We will map every attack class to OWASP LLM Top 10 and NIST AI RMF, walk through attack mechanics with examples and give AppSec teams a practical framework for threat modeling, vendor evaluation, and defense in depth.

2:20 PM - 2:55 PM

Club Room

Edward Bonver

Edward Bonver

Product Security / Cybersecurity Leader

Talk

AI-Generated Code, Real-World Vulnerabilities: A Production Incident Register

I rebuilt a 25-year-old website using an AI coding assistant as my full-time development partner. Over three months, the AI generated thousands of lines of code across multiple languages and configurations. It found real vulnerabilities, wrote input validation, built deployment pipelines, and produced code that passed its own reviews. It also introduced a critical production outage with a single misconfigured directive, wrote a security validation script with over a dozen exploitable gaps, silently destroyed cache data using a textbook "safe deploy" pattern, injected raw HTML into data fields creating stored XSS vectors, and hallucinated plausible but wrong reference data at scale.

I documented every failure into a security incident register — dozens of entries, each with the AI-generated artifact, the vulnerability, how it was discovered, and the fix. This talk presents that register, mapped to both the OWASP Top 10 and the OWASP Top 10 for LLMs.

You'll see how AI applies security patterns it has learned while failing to verify the assumptions those patterns require, why partial security in AI-generated code is more dangerous than no security, and how defence-in-depth, adversarial code review, and explicit security contracts turned a pattern of recurring failures into a hardened development workflow. You'll leave with key takeaways from this experience: a practical framework for writing security requirements AI can actually enforce, designing guardrails that catch what AI misses, and building with AI without trusting it blindly.

Who Should Attend:
Application security engineers, penetration testers, DevSecOps practitioners, software architects evaluating AI coding tools, and security leaders building governance frameworks for AI-assisted development. This talk assumes familiarity with OWASP, secure SDLC practices, and code review.

What You'll Learn:

  • How AI-generated code maps to OWASP Top 10 and OWASP Top 10 for LLMs — with real exploit paths from a production codebase
  • Why AI applies correct security patterns with unchecked preconditions and how to catch this systematically
  • How a short AI-written security script contained over a dozen vulnerabilities — and what structured adversarial review looks like in practice
  • How AI output injection creates stored XSS vectors — and why defence-in-depth at the template layer is the only reliable mitigation
  • How AI orchestration systems bypass their own quality gates under pressure — the trust boundary problem in multi-agent pipelines
  • How to write enforceable security contracts for AI coding assistants: input validation patterns, forbidden function lists, and mandatory output encoding
  • A categorized incident taxonomy with severity distribution, detection methods, and lessons learned

Meet Our Expert Team

Founded by four seasoned cybersecurity professionals who are not just organizers, but true experts in the field themselves. Drawing from their collective wealth of experience and deep-rooted insights, our events offer a rare opportunity to engage with top-tier professionals who understand the intricacies and challenges of cybersecurity firsthand. Elevate your knowledge, network with the best, and stay ahead of the curve as we pave the way for a safer digital world, together.

Richard Greenberg
Richard Greenberg

Chief Executive Officer

Haral Tsitsivas
Haral Tsitsivas

Chief Information Officer

Dave Wettenstein
Dave Wettenstein

Chief Financial Officer

Alexander Braehler
Alexander Braehler

Chief Operating Officer