Cyber Journey

Cyber Journey The italian event on application and software security.

31/08/2026

How do you prevent supply-chain attacks when the target is no longer just the code, but the entire build system? 🛡️

At Cyber Journey - OWASP Italy Day, Ravinder Singh and Ritesh Ranjan (Computer Scientists at Adobe) took the stage to present a real-world, global-scale case study on securing the software supply chain by implementing a Zero-Trust architecture aligned with SLSA Level 3 and OWASP SCVS standards.

From malicious dependencies to compromised runners, the goal is to embed security directly into the platform itself, providing a practical blueprint for making CI/CD security a native infrastructure component—without slowing developers down. 🚀

🔗 Want to learn more about the event?
Visit our website: https://www.cyberjourney.it/

12/08/2026

When web applications start "thinking" in natural language, traditional security boundaries between code and data completely dissolve. 🤖⚡

At Cyber Journey - OWASP Italy Day 2026, Matteo Grollino (RED Team Senior Member at Relatech) explored how integrating Large Language Models opens up entirely new attack vectors—focusing on Prompt Injection, currently the #1 threat in the OWASP Top 10 for LLM Applications.

Through practical examples and real-world scenarios, Matteo demonstrated how attackers can manipulate user inputs to override system logic, bypass safety controls, and trigger unintended actions within AI-driven workflows. His talk highlighted a crucial shift for modern AppSec: why conventional security controls fail when applied to natural language interfaces, and how teams must adapt to build AI-aware web applications.

🔗 Want to learn more about the event?
Visit our website: https://www.cyberjourney.it/

05/08/2026

With industry DAST false positive rates sitting between 68% and 78%, security teams are drowning in noise while real vulnerabilities slip through.

At Cyber Journey - OWASP Italy Day 2026, Alessio Dalla Piazza (Co-Founder & CTO at Equixly) shared a practical framework for solving this challenge using AI-assisted triage.

Key takeaways from his talk:
🔹 Algorithmic vs. beacon detection: distinguishing between deterministic checks and contextual behavioral signals.
🔹 The Real Role of LLMs: how proper context injection improves signal-to-noise ratios without relying on "magic" solutions.
🔹 Layered Triage Pipeline: combining EPSS scoring, reachability analysis, and RAG to handle ambiguous findings.

A pragmatic, battle-tested approach to leveraging AI where it actually adds value in production API security. 🚀

28/07/2026

The evolution of mobile security relies on increasingly precise and accessible analysis tools, as demonstrated by Sven Schleier (OWASP MAS Project co-lead) at Cyber Journey - Owasp Italy Day.

Key developments include advanced methodologies for testing non-jailbroken iOS 17+ devices, alongside the release of the MASTG v2 Beta framework and the MASWE classification.
The project now provides developers and security analysts with new dedicated test apps for Android and iOS, as well as a set of practical demos distributed directly via APK and IPA files.

These resources enable users to simulate real-world vulnerability scenarios and refine their testing techniques directly in the field.

🔗 Want to learn more about the event?
Visit our website: https://www.cyberjourney.it/

21/07/2026

While generating code through AI offers significant advantages in speed, what are the actual security risks for our applications? 🔒

At Cyber Journey - OWASP Italy Day 2026 , Betta Lyon Delsordo (Ethical Hacker & Pentester at AWS) presented on Secure Coding Literacy.
Her talk explored how to identify vulnerabilities in AI-generated code and how to implement automated scanning and verification processes—even without a dedicated security team.

Understanding the security implications of the code we deploy is the essential first step toward building truly resilient systems.

🔗 Want to learn more about the event?
Visit our website: https://www.cyberjourney.it/

14/07/2026

Relying on informal prompts and unstructured tickets to guide AI is a recipe for security regressions and runaway costs.

To address this challenge, Jim Ma**co (Founder of Ma**code Security) joined us at Cyber Journey - Owasp Italy Day 2026 to introduce Spec-driven development: a paradigm that moves beyond unpredictable inputs.

In his talk, Jim illustrated how codifying requirements into structured artifacts provides AI systems with a deterministic target. This approach offers reviewers and regulators a verifiable contract, ensuring measurable advantages across four critical dimensions: security, cost, compliance, and engineering velocity.

Want to learn more about Cyber Journey?
👉 Visit our website: https://www.cyberjourney.it/

06/07/2026

At Cyber Journey - OWASP Italy Day 2026, Julio Araujo (Head of Security at Rocket.Chat) shared how he built an Application Security program from scratch with a small team and limited resources.

In his talk, Julio explained how he tackled concrete challenges, such as a high number of vulnerabilities and the need to improve the relationship with software engineers. Instead of focusing on a single tool, he illustrated how to integrate security into the development lifecycle through threat modeling, code reviews, and practical tooling to build a truly collaborative and effective partnership with developers.

Want to learn more about Cyber Journey?
👉​ Visit our website: https://www.cyberjourney.it/

01/07/2026

Cyber Journey - OWASP Italy Day 2026 has just come to a end. Let's relive the event's keynotes together!

Vandana Verma opened the event on the stage of the Emerson Beach Club. The focus of her talk centered on the real impact of AI adoption: since 88% of global organizations are already leveraging artificial intelligence, banning these tools is no longer a viable option.
The core priority highlighted on stage is the urgent need to secure not just traditional software, but AI-generated software itself, addressing the critical risks of next-generation algorithms.

Want to learn more about Cyber Journey?
👉​ Visit our website: https://www.cyberjourney.it/

Another Cyber Journey has come to an end, and it is the perfect time to look back and thank everyone who made it all pos...
19/06/2026

Another Cyber Journey has come to an end, and it is the perfect time to look back and thank everyone who made it all possible.

Once again this year, the event brought leading figures from the application security world to Cagliari, who shared their expertise and professionalism with a community that grows larger every year.

Above all, Cyber Journey - OWASP Italy Day is made of people who dedicate themselves with passion and commitment to its success. That is why we want to extend a huge thank you to:

𝐀𝐥𝐥 𝐭𝐡𝐞 𝐬𝐩𝐞𝐚𝐤𝐞𝐫𝐬 for their generosity in dedicating their time to us and for delivering talks of the highest technical value, immensely enriching the content of this edition.

𝐓𝐡𝐞 𝐏𝐥𝐮𝐫𝐢𝐛𝐮𝐬 𝐎𝐧𝐞 𝐭𝐞𝐚𝐦, who worked tirelessly behind the scenes for the seamless ex*****on of the event.
𝐓𝐡𝐞 𝐚𝐮𝐝𝐢𝐨/𝐯𝐢𝐝𝐞𝐨 𝐭𝐞𝐚𝐦, for their flawless work.
𝐓𝐡𝐞 𝐄𝐦𝐞𝐫𝐬𝐨𝐧 𝐁𝐞𝐚𝐜𝐡 𝐂𝐥𝐮𝐛, for hosting us and providing such a stunning backdrop this year.
, our invaluable host: the event wouldn't have been the same without you.

Finally, the biggest thank you goes to all of you who participated and shared this incredible journey with us.

See you next year!

Today is THE DAY! 🚀​☀️
18/06/2026

Today is THE DAY! 🚀​☀️

Indirizzo

Viale Lungo Mare Poetto, 4° Fermata
Cagliari
09126

Sito Web

Notifiche

Lasciando la tua email puoi essere il primo a sapere quando Cyber Journey pubblica notizie e promozioni. Il tuo indirizzo email non verrà utilizzato per nessun altro scopo e potrai annullare l'iscrizione in qualsiasi momento.

Scelte rapide

Condividi