2026-10-30 –, Workshop Room
LLMs are already in your products, your workflows, and your infrastructure. But are they secure? Probably not — and attackers already know it.
This workshop walks you through every vulnerability in the OWASP Top 10 for LLM Applications (2025), with real-world examples that will make you uncomfortable in the best possible way. You'll get hands-on time with a live hacking platform built specifically for this session, so you don't just watch — you do.
We'll close out by exploring AI agent vulnerabilities, the emerging threat category that's changing everything we thought we knew about application security.
LLMs are no longer experimental — they are embedded in production systems, customer-facing products, and critical infrastructure. And yet, the security community is still catching up to what that actually means in practice.
This workshop is designed to close that gap.
We'll work through the complete OWASP Top 10 for LLM Applications (2025 edition) — not as a checklist, but as a hands-on investigation. Each vulnerability comes with real-world context, a live demonstration, and the kind of technical depth that turns awareness into action.
But knowing isn't enough. That's why participants get access to a purpose-built hacking platform — a safe, interactive environment with no complex setup designed specifically for this workshop — where you can move from observer to attacker and experience each vulnerability firsthand.
In the final chapter, we go beyond the OWASP list entirely. AI agents are introducing a new class of vulnerabilities that existing frameworks weren't built to handle. We'll look at what makes agentic architectures uniquely dangerous and discuss what defenders and developers need to start thinking about right now.
Whether you're a security professional trying to stay ahead of the curve, a developer building on top of LLMs, or simply someone who wants to understand the risks before they become incidents — this workshop was built for you.
Anca is an Information Security Analyst on the Incident Response team at Adobe. She recently completed her Master's degree and is now on the lookout for new opportunities, events, and challenges to dive into.
Public speaking and knowledge-sharing are a big part her journey in this field. She has delivered talks at events like YouniHack and EduFest, spoke on the importance of AI security at the University Politehnica of Bucharest, NLP Master's courses and labs at the University of Bucharest.
She is constantly working toward new certifications, driven by a simple goal: never stop learning. Beyond presenting, she has been involved in organizing BSides Bucharest at the Adobe office and has attended numerous conferences along the way — always looking for the next room to learn in, or the next stage to speak from.