SOS “VOLUME II” Agenda
SOS features a combination tactical and strategic discussions of state-sponsored operations, matters of attribution, and more. Some talks are marked [redacted] due to the sensitive nature of the discussion. More information about these talks may be found on the private agenda available to registered attendees.
2026 Schedule:
21 October (1800h-2000h): Pre-Registration & Happy Hour
22 October (0800h-1700h): Conference
22 October (1800h-*): Evening Social & Happy Hour w/ catering
2026 Agenda
-
Speaker: Marcin Dudek (Head of CERT.PL)
Description:
This presentation looks at the December 2025 cyberattack on Poland’s energy sector. It discusses the attackers’ tradecraft, focusing on how they gained access, moved laterally, and operated within industrial environments.
Speaker Biography:
Marcin Dudek leads CERT Polska, Poland’s national CERT. Before taking on this role, he spent more than a decade in hands-on technical work across OT security, incident response, and APT investigations. His background includes industrial control systems security in critical infrastructure environments, including Poland’s only research nuclear reactor, as well as analysis of APT activity targeting Poland. He regularly speaks at local and international cybersecurity conferences and was deeply involved in the response to the incident described in this talk. -
Description:
In this presentation we will give insights into our investigation of a sophisticated China-aligned APT group that we call SinisterEye and that overlaps with LuoYu (TeamT5 and Kaspersky) and CASCADE PANDA (CrowdStrike). This APT group has been active since at least 2008, targeting foreign entities and individuals in Chinese territory by hijacking updates from vulnerable applications via suspected adversary-in-the-middle (AiTM) positioning within Chinese internet infrastructure. -
Speaker:
Volodymyr Styran
Description:
Every persistent intrusion depends on something defenders rarely think to deny: the operator's peace of mind. Sustained clandestine work conditions the people behind the keyboard toward hypervigilance and a craving for stability — a kind of cyber-PTSD in which change, uncertainty, and the suspicion of a rival in the same network all register as existential threats. Conventional defense gives them precisely what they want: a static, predictable environment. This talk argues that stasis is a vulnerability — that the cheapest way to break persistence is to make the operator nervous — and traces the Offense Death Cycle back to its real origin: not defender observations, but the documented anxieties of the operators themselves.
Speaker Biography:
Volodymyr Styran is a co-founder of Berezha Security Group, with OSCP, CISSP and CISA credentials and 20+ years in offensive security. He co-founded NoNameCon and the OWASP Kyiv chapter, and co-hosts the No Name Podcast. Since 2022 he has served in Ukraine's cyber defence forces, currently as Special Assistant to the Chairman of the State Service of Special Communications and Information Protection of Ukraine (SSSCIP). He specialises in the techniques, frameworks and strategy of cyber conflict. -
Speaker: Chainanalysis
Description:
Moscow no longer sends an officer to burn a warehouse. It posts the job, hires a stranger, and pays in crypto. The fire destroys the evidence, the payroll writes it back down, and remarkably few people are reading it. This talk follows that payroll from the hired hand to the state's own stablecoin. -
Speaker: Sveva Vittoria Scenarelli (RecordedFuture)
Description:
Panama, Cuba, and Venezuela; Eswatini and Taiwan: RedNovember, formerly tracked as TAG-100, certainly does not keep to one ping only. Since early 2024, the Chinese state-sponsored group (also known as Storm-2077) has repeatedly surfaced around geopolitical flashpoints: RedNovember’s focus shifts as intelligence value changes with real-world events. Drawing on more than two years of direct tracking, including extensive previously unpublished activity from 2025 and 2026, this presentation will map RedNovember’s TTPs and targeting - showing how RedNovember combines broad access development with timely, geopolitically informed collection, and how the group can be tracked through its infrastructure and behavior over time. -
Speaker: Matthieu Faou (ESET)
Speaker Biography:
Matthieu Faou is a senior malware researcher at ESET where he specializes in researching targeted attacks. His main duties include threat hunting and reverse engineering of APTs. He finished his Master’s degree in computer science at École Polytechnique de Montréal and at École des Mines de Nancy in 2016. In the past, he has spoken at multiple conferences including Black Hat USA, BlueHat, Botconf, CYBERWARCON, NorthSec and Virus Bulletin. -
Details of this talk are [redacted] on the public agenda.
-
Speaker: BAE Systems
-
Speaker: Recorded Future
Description:
Iran has continued to target journalists and activists throughout the 2026 conflict with the US and Israel. This reveals the strategic importance the regime places on tracking individuals of interest, alongside ongoing foreign intelligence collection and espionage efforts against government and private sector organizations. Recorded Future currently tracks multiple groups targeting individuals of interest, living inside and outside of Iran. Some deliver Android spyware and show consistent development, while others rely on social engineering and credential-harvesting techniques. This talk presents a case study involving a cluster of activity targeting activists and journalists based outside of Iran, which shares TTP and targeting overlaps with the threat group Red Sandstorm, attributed to Iran’s Ministry of Intelligence and Security. It situates the campaign within the wider context of MOIS’ efforts to surveil individuals of interest, and highlights the varied actions on objectives MOIS has previously undertaken when targeting individuals. -
The details of this talk are [redacted]. More information can be found on the private agenda - available to registered guests.
-
The details of this talk are [redacted]. More information can be found on the private agenda - available to registered guests.
-
The details of this talk are [redacted]. More information can be found on the private agenda - available to registered guests.
More talks being finalized - check back for updates!