Editor's Picks
Best Talks at OffensiveCon 2026
Hand-picked from in-depth reviewer verdicts — the top 6 talks from this conference. Skip the noise, find the signal.
-
1
Keynote: Chaotic Good and Chaotic Bad — Ensuring Collective Success in Defensive Endeavours Through Offence
Ollie Whitehouse
Ollie Whitehouse, CTO of the UK's National Cyber Security Centre (NCSC), delivered a compelling keynote address at OffensiveCon, challenging conventional notions of cybersecurity. Titled "Chaotic Good and Chaotic Bad — Ensuring Collective Success in Defensive Endeavours Through…
0 Dr. Zero STRONG ACCEPT ★★★★☆ H Heather Calloway STRONG ACCEPT ★★★★☆ -
2
Exploiting QSEE Vulnerabilities In Google's Wifi Pro
Cristofaro Mune
This talk, "Exploiting QSEE Vulnerabilities In Google's Wifi Pro," delivered by Cristofaro Mune of Raelize, delves into critical security vulnerabilities discovered within the **Qualcomm QSEE (Qualcomm Secure Execution Environment)** implementation on the Google Nest Wi-Fi Pro…
0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway WEAK ★★☆☆☆ -
3
4-Byte Heap Overflow To RCE In Minecraft
Hrvoje Misetic
This talk, presented by Hrvoje Misetic at OffensiveCon, delves into the intricate process of achieving remote code execution (RCE) in Minecraft's Bedrock Edition through a 4-byte heap overflow vulnerability. The research meticulously details the discovery of a critical flaw in…
0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway WEAK ★★☆☆☆ -
4
Enhanced Insecurity Mode: 23 RCEs in Edge's "Safe" WebAssembly Interpreter
Nan Wang (sakura), Ziling Chen (R1nd0)
In a groundbreaking presentation at OffensiveCon, Nan Wang (sakura) and Ziling Chen (R1nd0) from Cyber Kunlun unveiled a comprehensive analysis of Microsoft Edge's "Enhanced Security Mode," revealing 23 **Remote Code Execution (RCE)** vulnerabilities within its WebAssembly…
0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway WEAK ★★☆☆☆ -
5
A 0-Click Exploit Chain For The Pixel 10
Natalie Silvanovich, Seth Jenkins
This talk, presented by Google Project Zero researchers Natalie Silvanovich and Seth Jenkins, details a sophisticated **zero-click exploit chain** targeting Google Pixel 9 and Pixel 10 devices. The primary objective was to achieve root access on these modern Android phones with…
0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway WEAK ★★☆☆☆ -
6
The DNG Weird Machine: Deconstructing an In-The-Wild Android Image Exploit
Benoît Sevens
This talk by Benoît Sevens from Google's Threat Analysis Group (now Google Threat Intelligence Group or GTIG) delves into a sophisticated in-the-wild Android exploit targeting the Digital Negative (DNG) image parsing library. The research, initially prompted by a sample…
0 Dr. Zero MUST SEE ★★★★★ H Heather Calloway WEAK ★★☆☆☆