{"acronym":"god2026","aspect_ratio":"16:9","created_at":"2026-09-19T18:08:37.154+02:00","updated_at":"2026-09-24T16:59:05.635+02:00","title":"German OWASP Day 2026","schedule_url":"","slug":"conferences/god/2026","event_last_released_at":"2026-09-24T00:00:00.000+02:00","link":"https://god.owasp.de/2026/","description":"","webgen_location":"conferences/god/2026","logo_url":"https://static.media.ccc.de/media/events/god/2026/logo.png","images_url":"https://static.media.ccc.de/media/events/god/2026","images":[{"type":"logo","url":"https://static.media.ccc.de/media/events/god/2026/logo.png","mime_type":"image/png"}],"recordings_url":"https://cdn.media.ccc.de/events/god/2026","url":"https://api.media.ccc.de/public/conferences/god2026","events":[{"guid":"584a3c41-0196-45d5-b675-945458cc9b6d","title":"New OWASP Kubernetes Top 10 in Action and Explained","subtitle":null,"slug":"god2026-110768-new-owasp-kubernetes-top","link":"https://c3voc.de","description":"Kubernetes is the backbone of modern applications with a very fast development cycle. To address new threats the OWASP Kubernetes Top 10 received a major update in 2025. This session brings these theoretical risks to life.\n\nWe will review the new 2025 security risks and explain how they work. Then we move into action. Through live practical demonstrations you will see how attackers exploit these flaws to steal secrets, escape containers, or take over whole clusters.\n\nFor every attack shown we immediately switch to defense. You will learn how to detect these malicious actions and protect your workloads using cloud native tools.\n\nThis presentation is for engineers and security professionals who want a clear understanding of the new 2025 OWASP standard combined with hands-on hacking and defense.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Benjamin Koltermann"],"view_count":2,"promoted":false,"date":"2026-09-24T15:10:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:59:05.633+02:00","tags":["110768","2026","god2026","Saal Fidelitas","god2026-eng","god2026","Day 1"],"length":1789,"duration":1789,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110768-584a3c41-0196-45d5-b675-945458cc9b6d.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110768-584a3c41-0196-45d5-b675-945458cc9b6d_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110768-584a3c41-0196-45d5-b675-945458cc9b6d.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110768-584a3c41-0196-45d5-b675-945458cc9b6d.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110768-new-owasp-kubernetes-top","url":"https://api.media.ccc.de/public/events/584a3c41-0196-45d5-b675-945458cc9b6d","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"b5c2b975-b007-421a-bd58-d5a51ebbd5d5","title":"How to Hack \"Read-Only\" SQL MCP Servers Online (Fast)","subtitle":null,"slug":"god2026-110757-how-to-hack-read-only-sql","link":"https://c3voc.de","description":"Chat Bots und AI Agents werden immer mehr produktiv eingesetzt. Oft sollen diese mit einer SQL Datenbank interagieren können. Wenn lediglich Daten gelesen, aber nicht verändert werden sollen, scheint es sinnvoll einen \"Read-Only\" SQL MCP Server dafür zu verwenden. Doch was wenn dieser doch nicht so \"Read-Only\" wie versprochen ist und zum Beispiel der Chatbot zur Kundenberatung auf einmal dazu benutzt werden kann die Preise von Produkten oder Passwörter von Benutzern zu ändern?\n\nIch habe 19 \"Read-Only\" SQL MCP Server untersucht und in 18 innerhalb von je 30 Minuten Schwachstellen gefunden; so \"Read-Only\" waren diese dann doch nicht...\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"deu","persons":["Maximilian Hildebrand"],"view_count":2,"promoted":false,"date":"2026-09-24T15:10:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:55:04.667+02:00","tags":["110757","2026","god2026","Saal Baden","god2026-deu","god2026","Day 1"],"length":1519,"duration":1519,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110757-b5c2b975-b007-421a-bd58-d5a51ebbd5d5.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110757-b5c2b975-b007-421a-bd58-d5a51ebbd5d5_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110757-b5c2b975-b007-421a-bd58-d5a51ebbd5d5.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110757-b5c2b975-b007-421a-bd58-d5a51ebbd5d5.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110757-how-to-hack-read-only-sql","url":"https://api.media.ccc.de/public/events/b5c2b975-b007-421a-bd58-d5a51ebbd5d5","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"509b974a-6131-437c-b909-6a77b89c3e69","title":"OWASP AISVS: Bringing Order to AI Security Chaos","subtitle":null,"slug":"god2026-110756-owasp-aisvs-bringing-orde","link":"https://c3voc.de","description":"Artificial intelligence is becoming a core building block of modern applications, yet the way we secure software has not kept pace with the unique properties of AI systems. Traditional approaches often rely on static assumptions and deterministic behavior, while AI introduces probabilistic outputs, dynamic decision-making, and new forms of interaction that challenge established security practices.\n\nThe OWASP AI Security Verification Standard (AISVS) is an effort to address this gap by providing a structured and testable framework for securing AI-enabled applications. It builds on the idea that security should be verifiable and measurable, and adapts this principle to systems that incorporate machine learning models, large language models, and autonomous components.\n\nThis talk presents the motivation behind AISVS, its design principles, and how it defines security requirements that can be consistently evaluated. It explores how developers and security teams can use AISVS to move from informal or reactive approaches toward a more systematic way of validating the security of AI systems throughout their lifecycle.\n\nBy focusing on clarity, practical applicability, and alignment with real-world development workflows, AISVS aims to become a foundation for building trust in AI-driven applications. Attendees will gain an understanding of how a verification standard can help bring structure and confidence to a rapidly evolving and often uncertain security landscape.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Rico Komenda"],"view_count":2,"promoted":false,"date":"2026-09-24T14:40:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:45:09.663+02:00","tags":["110756","2026","god2026","Saal Baden","god2026-eng","god2026","Day 1"],"length":1433,"duration":1433,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110756-509b974a-6131-437c-b909-6a77b89c3e69.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110756-509b974a-6131-437c-b909-6a77b89c3e69_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110756-509b974a-6131-437c-b909-6a77b89c3e69.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110756-509b974a-6131-437c-b909-6a77b89c3e69.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110756-owasp-aisvs-bringing-orde","url":"https://api.media.ccc.de/public/events/509b974a-6131-437c-b909-6a77b89c3e69","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"fcdfd8b5-c47a-44cb-bdcf-5caf970672ca","title":"How To Fuzz for Logic Bugs? Building Effective Oracles - A Case Study on Site Isolation Bypass Bugs","subtitle":null,"slug":"god2026-110767-how-to-fuzz-for-logic-bug","link":"https://c3voc.de","description":"Due to the rise of memory-safe languages like Rust, attention shifts towards logic bugs, which do not arise from insecure memory accesses. Identifying these bugs in large and complex codebases is hard, because bugs are mainly triggered by rare edge cases. Fuzzing is a great technique to induce random behavior and observe the edge cases in the application logic that are prone to logic bugs.\n\nHowever, fuzzing logic bugs requires a bug oracle, to detect whenever the application behavior deviates. Such models are hard to define, if they must infer correct or incorrect behavior based on the applications output. We propose a different approach: Oracles can be implemented effectively by applying small patches on the target application, because they can be defined as invariants that must hold across all random executions. This talk presents this approach exemplary on recent work, detecting site isolation bypass bugs in web browsers.\n\nSite isolation is one of the core security mechanisms of modern browsers. When using site isolation, the browser confines all processing related to a site to its own sandboxed renderer process. This, however, requires the central browser process to keep track of which renderer process belongs to which site. Logic bugs in this implementation, allow attackers to leak sensitive data, such as cookies, or achieve Universal Cross-Site Scripting.\n\nWe implemented two oracles, the leak sanitizer and the process sanitizer, that detect a wide range of site isolation bypass bugs. Combined with a fuzzer that targets edge cases in cross-site communication and navigation, our oracles detected four site isolation bugs in Chrome and Firefox.\n\nThis basic approach generalizes to other complex applications and classes of logic bugs. In this talk, we will explore how to set up a fuzzer for logic bugs and to inspire you to find logic bugs in more complex applications.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Jan Niklas Drescher"],"view_count":2,"promoted":false,"date":"2026-09-24T14:40:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:45:08.715+02:00","tags":["110767","2026","god2026","Saal Fidelitas","god2026-eng","god2026","Day 1"],"length":1437,"duration":1437,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110767-fcdfd8b5-c47a-44cb-bdcf-5caf970672ca.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110767-fcdfd8b5-c47a-44cb-bdcf-5caf970672ca_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110767-fcdfd8b5-c47a-44cb-bdcf-5caf970672ca.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110767-fcdfd8b5-c47a-44cb-bdcf-5caf970672ca.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110767-how-to-fuzz-for-logic-bug","url":"https://api.media.ccc.de/public/events/fcdfd8b5-c47a-44cb-bdcf-5caf970672ca","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"c132e9ae-87da-4708-8a84-ad6c14ce1660","title":"Zeit für OAuth 2.1 - Security Best Practices als neuer Standard","subtitle":null,"slug":"god2026-110766-zeit-fur-oauth-21-securit","link":"https://c3voc.de","description":"Implementieren Sie OAuth noch nach einem Spec von 2012? Dann ist Ihre Anwendung vermutlich unsicher! OAuth 2.0 hat sich in 13 Jahren durch ein Labyrinth von RFCs und Best Practices entwickelt – Implicit Flow ist deprecated, PKCE ist Pflicht, Password Grant ein No-Go. Aber wer weiß das schon alles?\n\nOAuth 2.1 räumt endlich auf: Ein Draft, der alle modernen Security Best Practices vereint und unsichere Flows eliminiert. Klingt perfekt? Ist es auch! Nur leider wendet ihn fast niemand an.\n\nIn diesem Talk zeigt Ihnen Martina Kraus, warum OAuth 2.1 Ihre OAuth-Implementierung von Grund auf sicherer macht, welche Breaking Changes auf Sie warten und wie Sie schon heute damit arbeiten können.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"deu","persons":["Martina Kraus"],"view_count":2,"promoted":false,"date":"2026-09-24T13:55:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:45:07.330+02:00","tags":["110766","2026","god2026","Saal Fidelitas","god2026-deu","god2026","Day 1"],"length":2735,"duration":2735,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110766-c132e9ae-87da-4708-8a84-ad6c14ce1660.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110766-c132e9ae-87da-4708-8a84-ad6c14ce1660_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110766-c132e9ae-87da-4708-8a84-ad6c14ce1660.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110766-c132e9ae-87da-4708-8a84-ad6c14ce1660.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110766-zeit-fur-oauth-21-securit","url":"https://api.media.ccc.de/public/events/c132e9ae-87da-4708-8a84-ad6c14ce1660","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"76ed3440-6570-4c39-8e96-a18de855315a","title":"CRA effizient und nachhaltig umsetzen","subtitle":null,"slug":"god2026-110765-cra-effizient-und-nachhal","link":"https://c3voc.de","description":"Der Cyber Resilience Act (CRA) stellt Sicherheitsanforderungen an Hersteller und Anbieter von Produkten mit digitalen Elementen. Viele Unternehmen haben bereits ein grundlegendes Sicherheitsniveau, doch der gezielte Abgleich mit den CRA-Anforderungen ist aufwändig und zeigt häufig unerwartete Lücken.\n\nDer Vortrag stellt ein Vorgehen vor, mit dem sich diese Gaps effizient identifizieren und daraus priorisierte Maßnahmen ableiten lassen. Die Basis stellt das OWASP SAMM Framework dar, das als Best-Practice für Secure Software Development Lifecycle (SSDLC) auch eine Standortbestimmung und kontinuierliche Weiterentwicklung mit individuellen Schwerpunkten ermöglicht.\n\nEin hierfür entwickeltes Mapping von CRA auf den OWASP SAMM ermöglicht ein strukturiertes CRA-Assessment und kurzfristig eine zielgerichtete Umsetzung der regulatorischen Anforderungen. Gleichzeitig wird ein erweitertes Rahmenwerk geschaffen, das hilft, den sicheren Entwicklungsprozess langfristig zu verbessern. Das Vorgehen erlaubt die Automatisierung einzelner Aufgaben wie dem Compliance-Check, reduziert somit den manuellen Aufwand und beschleunigt die Umsetzung. Praxisbeispiele verdeutlichen, wie Unternehmen so nicht nur effizient und ggf. KI-unterstützt CRA-Compliance erreichen, sondern einen nachhaltigen und resilienten SSDLC etablieren.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"deu","persons":["Dagmar Moser"],"view_count":14,"promoted":false,"date":"2026-09-24T12:05:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:45:09.773+02:00","tags":["110765","2026","god2026","Saal Fidelitas","god2026-deu","god2026","Day 1"],"length":2801,"duration":2801,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110765-76ed3440-6570-4c39-8e96-a18de855315a.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110765-76ed3440-6570-4c39-8e96-a18de855315a_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110765-76ed3440-6570-4c39-8e96-a18de855315a.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110765-76ed3440-6570-4c39-8e96-a18de855315a.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110765-cra-effizient-und-nachhal","url":"https://api.media.ccc.de/public/events/76ed3440-6570-4c39-8e96-a18de855315a","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"69dc1dd7-b5c4-4f86-921f-3bf98d0b7569","title":"What LLMs Can Do in Pentesting and Code Security","subtitle":null,"slug":"god2026-110754-what-llms-can-do-in-pente","link":"https://c3voc.de","description":"Large language models are starting to change both sides of application security: offensive work such as black-box penetration testing, and defensive work such as code review and vulnerability detection in source code.\n\nIn this talk, I present practical lessons from my academic and independent work in both areas: AutoPentest, my research on autonomous black-box pentesting with LLM agents; Vuldra, my work on LLM-assisted static code analysis; and my recent hands-on evaluation of OpenAI Codex Security on a real open-source project.\n\nOn the offensive side, I show what happens when an LLM agent is asked to carry out a black-box penetration test with a high degree of autonomy. I explain the architecture behind AutoPentest, including specialized worker agents structured around OWASP Top 10-relevant web vulnerability areas, and show where the system still struggles in longer attack chains.\n\nIn my evaluation on three Hack The Box machines, AutoPentest completed 15 to 26 percent of subtasks and slightly outperformed a manual ChatGPT-based baseline on one target.\n\nOn the defensive side, I explored two ways of using LLMs for code security testing.\n\nFirst, I discuss Vuldra as an example of how LLMs can be used for static code analysis, integrating them with traditional SAST tools.\n\nSecond, I present my evaluation of Codex Security on TorMap, where I looked at real findings, proposed fixes, and practical limits in a developer workflow.\n\nThe main message of the talk is simple: LLMs can already help security teams on both the attacker and defender side, but their strengths and weaknesses are different.\n\nAttendees will leave with a realistic view of where LLMs are already useful, where they still fail, and how to evaluate such tools in their own environment without treating them as magic.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Julius Henke"],"view_count":10,"promoted":false,"date":"2026-09-24T12:05:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:45:09.047+02:00","tags":["110754","2026","god2026","Saal Baden","god2026-eng","god2026","Day 1"],"length":2890,"duration":2890,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110754-69dc1dd7-b5c4-4f86-921f-3bf98d0b7569.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110754-69dc1dd7-b5c4-4f86-921f-3bf98d0b7569_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110754-69dc1dd7-b5c4-4f86-921f-3bf98d0b7569.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110754-69dc1dd7-b5c4-4f86-921f-3bf98d0b7569.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110754-what-llms-can-do-in-pente","url":"https://api.media.ccc.de/public/events/69dc1dd7-b5c4-4f86-921f-3bf98d0b7569","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"0cb083d4-9bba-4464-b66c-2913b8698752","title":"Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives","subtitle":null,"slug":"god2026-110753-indirect-prompt-injection","link":"https://c3voc.de","description":"As LLMs are increasingly integrated into systems that browse, retrieve, summarize, and act on web content, webpages have become an untrusted input vector for downstream model behavior. This enables site owners, contributors, and adversaries to embed instructions directly in web resources, i.e., indirect prompt injections. While prior work demonstrates such attacks in controlled settings, their prevalence, deployment, and real-world impact remain unclear.\n\nWe present one of the first large-scale empirical analyses of indirect prompt injections in webpages and HTTP responses. Analyzing 1.2B URLs from 24.8M hosts, we identify 15.3K validated instances across 11.7K pages. These are not isolated cases: a small number of recurring templates account for most cases. We characterize their objectives, delivery mechanisms, visibility, persistence, and impact, revealing a heterogeneous ecosystem spanning disruptive prompts, reputation manipulation, content-protection directives, and AI-bot detection, targeting systems such as crawlers, search pipelines, customer-support agents, and hiring workflows.\n\nA key finding is that most instructions target machines rather than humans: about 70% appear in non-rendered HTML (e.g., headers, comments, metadata), and many visible cases are hidden via rendering techniques. To assess practical risk, we run 5,200 controlled experiments across 13 models and four webpage representations. Our results show compliance is limited but non-negligible, reaching up to 8% for smaller models on plain-text inputs, while structured representations reduce compliance by preserving structural cues. Overall, prompt-based interference is already present in the web ecosystem and represents a growing source of tension between LLM-driven automation and the sites it consumes.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Soheil Khodayari"],"view_count":18,"promoted":false,"date":"2026-09-24T11:20:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:15:08.752+02:00","tags":["110753","2026","god2026","Saal Baden","god2026-eng","god2026","Day 1"],"length":2793,"duration":2793,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110753-0cb083d4-9bba-4464-b66c-2913b8698752.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110753-0cb083d4-9bba-4464-b66c-2913b8698752_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110753-0cb083d4-9bba-4464-b66c-2913b8698752.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110753-0cb083d4-9bba-4464-b66c-2913b8698752.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110753-indirect-prompt-injection","url":"https://api.media.ccc.de/public/events/0cb083d4-9bba-4464-b66c-2913b8698752","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"0b883d09-1c27-4894-a46e-1e23b5528aa1","title":"Vier grüne Häkchen, trotzdem gehackt: Threat Modeling für KI-Agenten","subtitle":null,"slug":"god2026-110764-vier-grune-hakchen-trotzd","link":"https://c3voc.de","description":"Eine E-Mail liegt im Posteingang. Niemand öffnet sie, niemand klickt. Tage später fragt jemand seinen KI-Assistenten nach den letzten Mails — und der Agent schickt still interne Daten an einen fremden Server. So lief EchoLeak gegen Microsoft Copilot (CVE-2025-32711, CVSS 9.3): kein Exploit-Code, keine kaputte Authentifizierung. Jede Komponente hatte ihr Security-Review bestanden. Der Angriff lebte im Pfad dazwischen.\n\nWer agentenbasierte Systeme baut, kennt das Muster: Wir prüfen Komponenten einzeln, Angreifer denken in Ketten. Sobald ein Agent Daten abruft, Aufgaben plant, Tools aufruft, sich Dinge merkt und mit anderen Agenten redet, entstehen Angriffspfade quer über Vertrauensgrenzen, die kein Per-Komponenten-Review sichtbar macht. Gerade im Kontext von Agentic AI werden dabei die Grenzen klassischer STRIDE-Analysen sichtbar, weil sich Risiken oft erst entlang von Daten-, Entscheidungs- und Tool-Ketten über mehrere Komponenten hinweg entfalten.\n\nIch zeige eine Methode, kein weiteres Framework zum Auswendiglernen. Die Fünf-Zonen-Brille — Eingabe, Planung, Tool-Ausführung, Speicher, Agent-zu-Agent-Kommunikation — sagt, wo man hinschauen muss; die OWASP Top 10 for Agentic AI Applications sagen, was man dort findet. Wir gehen drei reale Architekturen durch: RAG-Pipeline-Poisoning, Missbrauch einer MCP-Tool-Chain und eine Multi-Agent-Kaskade. Für jede bauen wir einen Attack Tree und trennen die Kontrollen, die strukturell halten (Tool-Scoping pro Aufgabe, Egress-Inspektion, Credential-Trennung), von den prompt-basierten, die nur beruhigend klingen.\n\nAm Ende habt ihr eine wiederholbare Routine für euer eigenes Agentic AI System: Zonen kartieren, Pfade ablaufen, einen Baum bauen, Single Points of Failure finden, Kontrollen anhängen und validieren.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"deu","persons":["Christian Schneider"],"view_count":10,"promoted":false,"date":"2026-09-24T11:20:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:30:07.555+02:00","tags":["110764","2026","god2026","Saal Fidelitas","god2026-deu","god2026","Day 1"],"length":2656,"duration":2656,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110764-0b883d09-1c27-4894-a46e-1e23b5528aa1.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110764-0b883d09-1c27-4894-a46e-1e23b5528aa1_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110764-0b883d09-1c27-4894-a46e-1e23b5528aa1.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110764-0b883d09-1c27-4894-a46e-1e23b5528aa1.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110764-vier-grune-hakchen-trotzd","url":"https://api.media.ccc.de/public/events/0b883d09-1c27-4894-a46e-1e23b5528aa1","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"af2068b9-f97b-45ed-8c07-1f3e9ae5fbd5","title":"OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement Analysis","subtitle":null,"slug":"god2026-110763-owasp-cornucopia-gamifyin","link":"https://c3voc.de","description":"Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security.\n\nToo often, the shift-left mantra consists of implementing (AI-powered) code scanning and applying AI-powered security fixes for remediation. Also, don't forget to implement the AI-powered benchmark for AI-powered Security Fixes. Now, to be clear, I am not actually telling you to stop using these tools — if they work for you — instead, we should ask ourselves:\n\nWhat are we working on?\nWhat can go wrong?\nWhat are we going to do about it?\nDid we do a good job?\n\nIn order to support that second question in particular, we have created the next version of OWASP Cornucopia (see: https://cybersecgames.com/pages/owasp-cornucopia-threat-modeling-collection).\n\nOWASP Cornucopia is a mechanism in the form of a card game to assist software development teams in identifying security requirements in Agile, conventional, and formal development processes. It is language, platform, and technology-agnostic.\n\nThe formerly titled \"Cornucopia — Ecommerce Website Edition\" is now \"Cornucopia — Website App Edition\". This edition was originally created in August 2012, released as v1.0 in February 2013, and has undergone several minor updates/releases over the following ten to fifteen years. This has been substantially updated in v2.0, in which the most noticeable change was an update of the OWASP ASVS mapping from ASVS v3.0 to v4.0, together with the creation of translations into six languages (EN, ES, FR, NL, NO-NB, and PT-BR) due to the efforts of past and current volunteers.\n\nThe new version, available in 11 languages (EN, ES, FR, HI, NL, NO-NB, PT-PT, PT-BR, RU, UK), will include all new cards and text that covers all OWASP ASVS 5.0 requirements and links them to more than 200 unique common attack patterns (CAPEC). Each of the common attack patterns will have a unique set of ASVS requirements, which means that you never need to stop playing the game! You will always be able to return to the same card to discover new threats and security requirements to consider when building your software. Additionally, we are publishing the OWASP Cornucopia Companion Edition that comes with 6 companion suits (see: https://cornucopia.owasp.org/edition/companion) covering new topics: Agentic AI (AAI), Automated Threats (BOT), Cloud (CLD), Frontend (FRE), Large Language Models (LLM), and DevOps (DVO). A suit in the companion deck may replace (or be used in addition to) suites in the existing Website Edition so that the players can add a specific focus to their threat modeling: For example, say you are building an LLM application and want to perform threat modeling specifically for LLM. You would then use the OWASP Cornucopia Website Edition and the LLM companion suite as your elected OWASP Cornucopia focus area.\n\nWhat's more, it is now possible to create your OWASP Cornucopia Threat Model in OWASP Threat Dragon using their brand new EoP Games diagram. The diagram allows you to easily select the right card from the OWASP Cornucopia suite and connect it directly to your threat model in OWASP Threat Dragon, thanks to the combined efforts of volunteers at Universidad Católica del Uruguay and the OWASP Threat Dragon project.\n\nAll project leaders and contributors to the OWASP projects that have provided valuable input and guidance to OWASP Top 10, OWASP AISVS and the OWASP GenAI Security project. We also want to thank the people and contributors to Mitre's Common Attack Pattern Enumeration and Classification (CAPEC™) and Atlas, together with CSA Cloud Controls Matrix, which are all used in the cross-references provided.\n\nFailing to regularly assess your security isn't only costly; it can leave you vulnerable to threats. Several companies have implemented OWASP Cornucopia as part of their SDLC and use it for security requirements analysis, threat modeling, and secure design for every sprint and every user story. You should do the same! Don't let your business spiral out of control; consciously assess how you are doing by continuously threat-modeling your applications and infrastructure. To get started scaling your threat modeling efforts, OWASP Cornucopia v3.0 is the perfect tool.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Johan Sydseter"],"view_count":2,"promoted":false,"date":"2026-09-24T10:20:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T13:15:08.970+02:00","tags":["110763","2026","god2026","Saal Fidelitas","god2026-eng","god2026","Day 1"],"length":1984,"duration":1984,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110763-af2068b9-f97b-45ed-8c07-1f3e9ae5fbd5.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110763-af2068b9-f97b-45ed-8c07-1f3e9ae5fbd5_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110763-af2068b9-f97b-45ed-8c07-1f3e9ae5fbd5.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110763-af2068b9-f97b-45ed-8c07-1f3e9ae5fbd5.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110763-owasp-cornucopia-gamifyin","url":"https://api.media.ccc.de/public/events/af2068b9-f97b-45ed-8c07-1f3e9ae5fbd5","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"89354a50-d435-4899-ab5d-eb6e4a37150e","title":"Hackbots under control: Methodology for Autonomous Pentesters","subtitle":null,"slug":"god2026-110752-hackbots-under-control-me","link":"https://c3voc.de","description":"Autonomous pentesting tools have matured to the point where they can reliably find vulnerabilities, but finding vulnerabilities is not the same as doing a professional pentest. Bug bounty hunting optimizes for high-severity impact while a client engagement requires systematic coverage against a framework, with every control checked.\n\nIn this talk we will explore how we designed an internal solution that layers the OWASP ASVS framework on top of existing agentic testing products. We will cover what we put in place to get reliable results, the guardrails we designed to ensure safe behavior in client environments, and how our harness improves the coverage of agentic testing solutions.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Tanguy Snoeck"],"view_count":8,"promoted":false,"date":"2026-09-24T10:20:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:15:08.652+02:00","tags":["110752","2026","god2026","Saal Baden","god2026-eng","god2026","Day 1"],"length":1118,"duration":1118,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110752-89354a50-d435-4899-ab5d-eb6e4a37150e.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110752-89354a50-d435-4899-ab5d-eb6e4a37150e_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110752-89354a50-d435-4899-ab5d-eb6e4a37150e.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110752-89354a50-d435-4899-ab5d-eb6e4a37150e.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110752-hackbots-under-control-me","url":"https://api.media.ccc.de/public/events/89354a50-d435-4899-ab5d-eb6e4a37150e","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"dfb213c8-cf0b-4ff1-a932-76dba9b66521","title":"Agentic AI Gateway Enforcement of the OWASP Top 10","subtitle":null,"slug":"god2026-110751-agentic-ai-gateway-enforc","link":"https://c3voc.de","description":"The OWASP Top 10 for Agentic Applications 2026 clearly outlines risks like prompt injection, tool misuse, excessive agency, rogue and compromised agents, and untraceable actions. This talk shows how an open source tool addresses the risks as a control platform, a switchboard between the model and its actions. The separation means any hostile or compromised model is bound and can't reach or bypass these controls.\n\n    Tool misuse and excessive agency hit per-action permission tiers that auto-allow, require human approval, or block.\n    Compromised and rogue agents hit a gate so an \"evil model\" can't elevate.\n    Untraceable action hits an append-only, hash-chained, signed audit log.\n    Skill supply chain hits a signature verification at load.\n\nA live agent demo shows the risks, controls, source code, and design architecture. The reference implementation maps to the sovereignty posture the EU formalized in its June 2026 tech package.\n\nDocumentation and source: https://wirken.ai\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Davi Ottenheimer"],"view_count":12,"promoted":false,"date":"2026-09-24T10:15:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:45:09.135+02:00","tags":["110751","2026","god2026","Saal Baden","god2026-eng","god2026","Day 1"],"length":1588,"duration":1588,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110751-dfb213c8-cf0b-4ff1-a932-76dba9b66521.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110751-dfb213c8-cf0b-4ff1-a932-76dba9b66521_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110751-dfb213c8-cf0b-4ff1-a932-76dba9b66521.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110751-dfb213c8-cf0b-4ff1-a932-76dba9b66521.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110751-agentic-ai-gateway-enforc","url":"https://api.media.ccc.de/public/events/dfb213c8-cf0b-4ff1-a932-76dba9b66521","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"f3cc36ee-f906-4095-a5bb-709c9bfc1c6a","title":"Understanding the Map of Threat Modeling Through the Lens of the TM-BOM","subtitle":null,"slug":"god2026-110762-understanding-the-map-of","link":"https://c3voc.de","description":"Threat models usually go out of date as soon as they are created. They reside on the tool used to create the threat model. So a developer without access to the threat modeling tool does not even open the threat model.\n\nOn the other hand, threat models that are interoperable come with several advantages. It's easier to share them with team members. Vendors can be asked to provide their threat models in a ready-to-consume format by purchasers in sensitive industries like healthcare. With the advent of agentic systems, LLMs can even consume raw threat models in JSON format and generate threat models that can be viewed and deliberated upon by human reviewers.\n\nThe CycloneDX project is pushing to release the TM-BOM (Threat Modeling Bill of Materials) and is targeting general availability later this year. This session discusses the nuts and bolts of the TM-BOM format. Participants will understand how various pieces like blueprints, business objectives, behaviors, threats, risks, use cases, and controls interact with each other.\n\nTo ground this standard in reality, I will share insights from integrating this pre-release schema into an open-source threat modeling platform, exploring the friction points of translating complex data structures into human-centric visualizations.\n\nOutline (20 Minutes)\n\nThe Interoperability Problem (3 mins): Why siloed threat models fail developers and compliance teams.\n\nDeconstructing the TM-BOM (7 mins): A focused look at the CycloneDX 2.0 schema and how its core components (Blueprints, Behaviors, Threats, Risks, Controls) interlock.\n\nAgents and the TM-BOM (5 mins): How standardizing into JSON unlocks the ability for agentic systems to reliably consume and generate models for human review.\n\nImplementation Realities (3 mins): Engineering lessons learned mapping a complex JSON standard to visual diagrams.\n\nQ\u0026A (2 mins)\n\nAttendees will leave with a functional understanding of the upcoming CycloneDX 2.0 standard, the operational benefits of interoperable threat models, and how to prepare their security pipelines to generate and consume TM-BOMs.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Vikramaditya Narayan"],"view_count":6,"promoted":false,"date":"2026-09-24T09:55:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T12:30:07.713+02:00","tags":["110762","2026","god2026","Saal Fidelitas","god2026-eng","god2026","Day 1"],"length":1401,"duration":1401,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110762-f3cc36ee-f906-4095-a5bb-709c9bfc1c6a.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110762-f3cc36ee-f906-4095-a5bb-709c9bfc1c6a_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110762-f3cc36ee-f906-4095-a5bb-709c9bfc1c6a.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110762-f3cc36ee-f906-4095-a5bb-709c9bfc1c6a.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110762-understanding-the-map-of","url":"https://api.media.ccc.de/public/events/f3cc36ee-f906-4095-a5bb-709c9bfc1c6a","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]},{"guid":"5f4583b8-b579-4c38-9771-e4e2e0eb9ac4","title":"Keynote","subtitle":null,"slug":"god2026-110750-keynote","link":"https://c3voc.de","description":"AI is creating real breakthroughs, but also an ocean of slop, hype, fear, and confusion. Engineers are declared obsolete. Agentic AI is treated as magic. Security teams are asked to protect systems that are changing faster than their risk models. No wonder many of us feel dazed.\n\nThis keynote offers a free therapy session for the AI-overwhelmed, including a grounded path through the chaos from your therapist. What are the truths we can rely on? Which AI risks matter most? How do we scope security concerns without drowning in them? And what about our careers?\n\nBring your questions. There will be tissues.\n\nLicensed to the public under https://creativecommons.org/licenses/by-sa/4.0/","original_language":"eng","persons":["Rob van der Veer"],"view_count":28,"promoted":false,"date":"2026-09-24T09:05:00.000+02:00","release_date":"2026-09-24T00:00:00.000+02:00","updated_at":"2026-09-24T16:45:08.496+02:00","tags":["110750","2026","god2026","Saal Baden","god2026-eng","god2026","Day 1"],"length":2835,"duration":2835,"thumb_url":"https://static.media.ccc.de/media/events/god/2026/110750-5f4583b8-b579-4c38-9771-e4e2e0eb9ac4.jpg","poster_url":"https://static.media.ccc.de/media/events/god/2026/110750-5f4583b8-b579-4c38-9771-e4e2e0eb9ac4_preview.jpg","timeline_url":"https://static.media.ccc.de/media/events/god/2026/110750-5f4583b8-b579-4c38-9771-e4e2e0eb9ac4.timeline.jpg","thumbnails_url":"https://static.media.ccc.de/media/events/god/2026/110750-5f4583b8-b579-4c38-9771-e4e2e0eb9ac4.thumbnails.vtt","frontend_link":"https://media.ccc.de/v/god2026-110750-keynote","url":"https://api.media.ccc.de/public/events/5f4583b8-b579-4c38-9771-e4e2e0eb9ac4","conference_title":"German OWASP Day 2026","conference_url":"https://api.media.ccc.de/public/conferences/god2026","related":[]}]}