|

Two main stages, 7 workshops, EXPO, OT security afternoon and dozens of talks in one deeply technical, intensive day: this is Hacktivity2026.

Since 2003, Hacktivity has proven itself year after year and has grown into one of Central and Eastern Europe’s longest running IT security and hacker conferences, a pilgrimage destination for offensive and defensive professionals and ethical hackers from the region and from around the world. The event’s hallmark is deeply technical, immediately actionable knowledge: anyone who sits in on a talk or a workshop here takes home not a theoretical overview but concrete methods, tools and techniques.

The real strength of the 2026 program is its freshness: in many cases the stage features research results presented publicly for the first time, delivered by Hungarian and international professionals and researchers. The field is genuinely international: the speakers come from more than 10 countries, while Hungarian researchers are represented in almost equal proportion and with a strong presence. The expertise of the domestic and the international elite thus appears side by side, in one place.

These fresh results and case studies are no accident: the speakers include professionals from companies and organisations at the forefront of the international market, among them representatives of Palo Alto, Protectt.ai, Trust Panda Europe, TenRoot, Iru, Accenture, Gjallarhorn Labs and Diligent, and from Hungary the CrySys Lab, Siemens Healthineers and OPSWAT. This background guarantees that the knowledge presented at Hacktivity reflects the current peak of the field.

What this year’s Hacktivity is about?

One of the main themes of the 2026 program is AI security (on both the offensive and the defensive side), but the conference is about far more than that. The talks on the two main stages (Big Stage and Bigger Stage) cover the full breadth of the security field:

  • Telecommunications and physical-layer threats (the kind traditional SIEM never sees)
  • Automotive security and CAN bus intrusion detection
  • Detection of legacy ARM devices and ROP attacks
  • Post-quantum cryptography and authentication
  • macOS sandbox and SIP bypasses
  • Reverse engineering of IoT devices with open-source tools and LLMs
  • Cloud security (AWS, Azure, GCP) and uncovering hidden secrets
  • Vulnerabilities in healthcare systems and medical devices
  • OT and energy security (see the separate “Hello from 2033” workshop)

Featured talks (Hungarian and international research tracks)

The full program will not fit into a single document, so we highlight a few talks that are especially striking from a research perspective and that convey the depth of this year’s lineup. The descriptions are taken from the program page.

Hungarian researchers

Detection-as-Code in Practice — Gergő Gyebnár (Hungary): one of the talks on the Bigger Stage. Gyebnár is a well-known figure of the Hungarian security scene, the founder and former head of Black Cell; he recently earned professional recognition for the idea behind his new venture, Kaimi. His talk takes the engineering, version-control and CI/CD-based mindset of Detection-as-Code into practice: from Sigma-based logic and adversary emulation to telemetry-driven validation, and from reducing alert noise to increasing SOC efficiency.

PROPS — Sándor József (Hungary): “Learning Stack Patterns for ROP Detection on Legacy ARM-based Devices.” A mechanism for detecting return-oriented programming attacks on legacy ARM-based devices.

CAN We Trust Your Results? — Beatrix Koltai (Hungary): “A Cross-Dataset Study of Automotive IDS Evaluation.” A benchmark framework for evaluating automotive CAN intrusion detection systems.

macOS Mounting Madness — Csaba Fitzl (Hungary): nine case studies on sandbox, SIP and TCC bypasses via unsafe mount handling.

Polyglots — Roland Győrffi (Hungary): “Schrödinger’s Files.” Files that are simultaneously valid in multiple formats and bypass security filters, with live demos.

Introduction to filesystem logic bugs and Apple bug bounties — Gergely Kálmán (Hungary): a workshop on filesystem logic bugs and the world of Apple bug bounties.

International researchers

Beneath the Stack — Angie Agee (USA-Mexico): “Detecting Physical-Layer Telecom Threats Your SIEM Will Never See.” State actors against physical telecom infrastructure.

Reverse Engineering the DUOX PLUS Protocol — Kirils Solovjovs (Latvia): reverse engineering a closed intercom system with hardware tools, signal processing and protocol reversing.

The Vulnpocalypse is Hitting the Physical Realm — Georges Bolssens (Belgium): reverse engineering IoT devices with open-source tools and LLMs, a WiFi extender case study with four CVEs.

Harvest Now, Decrypt Later Does Not Apply Here — Allan Dall (Australia): a threat model for post-quantum authentication.

AI security theme

Agentic AI Development for Red and Blue Teams — Sean Hopkins (USA): a multi-agent AI framework for security operations, with human oversight.

The Agents of Chaos — Arad Donenfeld (Israel): “AI Driven Malware Generation.” Autonomous AI agents in the malware-creation process.

VibeShell — Etizaz Mohsin (Pakistan): “How Trusting Your AI IDE Costs You Your Machine.” Zero-click RCE through AI coding IDEs.

Seizing the Means of Software Production — Shaked Reiner: “The Hidden Security Risks of AI Coding Agents.” The centralisation risks of AI-driven software production.

Workshops — two-hour, hands-on sessions

The two workshop rooms are built on interactive, hands-on tasks in two-hour slots. Registration is recommended. A few highlighted sessions:

Defending AI and Agentic Systems from Ransomware — Behnaz Karimi (Germany), Yuvaraj Govindarajulu (India): examining ransomware attack paths across AI pipelines.

Car-Hacking Hardware Workshop — Thomas Fischer (Germany): hands-on automotive security with 20 Raspberry Pi ECUs, CAN bus attacks on software-defined vehicles.

Rickrolling the Doctor — Dominik Maksa, János Kovács, Florian Rosenstiel: getting to know healthcare technologies and exploiting vulnerabilities in medical devices.

M0us3: A Lightweight, Multi Session C2 Framework — Aryan Jogia (India): a custom-built C2 system with a Rust-based Windows implant.

Featured workshop: Hello from 2033 (OT security, energy focus, full afternoon)

Led by Éva Szolnoki (Hungary, Hungarian Energy and Public Utility Regulatory Authority) and with the contribution of experts from the SeConSys Foundation, this is an interactive, problem-solving OT security workshop that runs the whole afternoon and looks back from the future to the present and the near future. The focus is a blackout: the challenges of the subsequent recovery and the impact of continuous outages on IT systems.

Organised into groups, participants solve two tasks:

  • A decision scenario concerning the restart
  • A decision scenario about the forensic-supporting steps that can be taken during such periods

Both tasks consist of several parts, and as the work progresses the situation changes: new information arrives that forces the groups to re-evaluate their decisions. This workshop is especially relevant for companies operating energy and critical infrastructure. The workshop is held in Hungarian; English mentoring is available.

EXPO

This year the conference’s accompanying EXPO is the hub of the buzz: exhibitors welcome visitors with tinkering tasks, challenges, live demos and innovative solutions that can be tried out first-hand, not just looked at. The EXPO is a true space for practical discovery and professional networking.

Similar News