CFP Directory LogoCFP Directory
EventsSpeakersTalksOrganizationsFeaturesPricingWhy Us
Sign in

Company

  • About Us
  • Contact

Contact Info

Address:

13, Lorong Toh Aka

Georgetown 10100

Penang, Malaysia

Email:

info@cfp.directory

Website:

13thirtyseven.my

Business Hours

Monday - Friday:9:00 AM - 6:00 PM
Saturday:9:00 AM - 1:00 PM
Sunday:Closed

GMT+8 (Malaysia Standard Time)

© 2025 CFP Directory. All rights reserved.
13 Thirty Seven Sdn. Bhd. (1401538-A)
Privacy PolicyTerms of Service

Find Expert Speakers

Connect with talented speakers from around the world. Search by expertise, topics, or use our advanced filters to find the perfect speaker for your event.

Create Your Speaker Profile
Vulnerability Research

Showing 16 speakers matching your filters

1azymamba (ダビド)

1azymamba (ダビド)

Security Analyst

Japan

I’m currently working as a Security Analyst, with experience in both red team and blue team operations. My current focus is on red team engagements, zero-day research, and malware analysis.

Red Team
Vulnerability Research
Malware Analysis
0
Talks
0
Events
0
Countries
—
Years
1 submissions
Japanese, English
Alfonso De Gregorio

Alfonso De Gregorio

Founding Director and Principal Investigator at Pwnshow, and CEO at Zeronomicon

Rome, Italy

Alfonso De Gregorio is a globally recognised cybersecurity technologist, Founding Director and Principal Investigator at Pwnshow, and CEO at Zeronomicon, Italy. He is a featured speaker at 25+ peer-reviewed international events across 5 continents, such as NATO's Conference on Cyber Conflict, RSA Conference, and the leading hacker conferences. His work focuses on the intersection of artificial intelligence, cyber threats, and regulatory landscapes. High-performance organisations engage him to spearhead relentless innovation across disciplines and fields, accelerate asymmetric advantage, and achieve peak confidence in today's interconnected operational environment—establishing Alfonso as a key figure shaping the discussion and practice of cybersecurity.

AI Security
Offensive Security
Cryptography
+5
24
Talks
23
Events
17
Countries
—
Years
1 submissions
English, Italian
Boik Su

Boik Su

Security Research Manager

CyCraft Technology

Taipei,Taiwan

Boik Su is a security research manager at CyCraft Technology and is currently focused on Cloud Security, Web Security, and Blockchain Security. He takes an active role in the cybersecurity community and has delivered speeches at multiple seminars across the globe, including HITCON, HITB, FIRSTCTI, VB, and HackerOne. He still participates in CTF competitions, including SECCON CTF in Japan and HITCON CTF in Taiwan, and has submitted multiple reports to bug bounty programs and open-source projects.

API Security
Application Security
Cloud Security
+20
0
Talks
0
Events
0
Countries
—
Years
1 submissions
English, Chinese (Mandarin)
Carlos Gomez Quintana

Carlos Gomez Quintana

Security Consultant

IOActive

Madrid, Spain

Carlos Gómez Quintana is a Security Consultant at IOActive, specializing in Red Team operations and offensive security. As one of the youngest professionals to join the firm, he conducts advanced penetration testing, adversarial simulation, and security research across diverse enterprise environments.At IOActive, Carlos focuses on cutting-edge security research, including automotive security where he has developed novel attack techniques such as rollback agnostic replay attacks against vehicular systems. He regularly conducts Red Team engagements that simulate real-world adversarial scenarios for enterprise clients.Carlos is an active security researcher and contributor to Maldev Academy, where he has contributed to the phishing section and active research on malware development.

Red Team
OSINT
macOS Security
+4
1
Talks
1
Events
1
Countries
—
Years
English, Spanish
Daniel Goldberg

Daniel Goldberg

NULL

Israel

Feel free to email me on basically anything on computing or history

Network Security
Cyber Deception
Malware Analysis
+6
0
Talks
0
Events
0
Countries
—
Years
English, Hebrew
Jonathan Bar Or

Jonathan Bar Or

North Bend, Washington, USA

Jonathan Bar Or ("JBO") an information security expert and a hacker, focusing on binary analysis, vulnerability research, application security, reverse engineering, and cryptography.His research has uncovered critical vulnerabilities that have impacted millions of users worldwide, shaping security best practices across the industry.Frequently cited by major news outlets, his work has influenced both academia and industry, driving meaningful security improvements.

API Security
Application Security
Cyber Security
+9
0
Talks
0
Events
0
Countries
—
Years
3 submissions
English
Kirils Solovjovs

Kirils Solovjovs

Founder

Possible Security

Riga, Latvia

Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist, renowned for uncovering and responsibly disclosing critical security vulnerabilities in both national and international systems. Kirils started programming at age 7 and by grade 9 was spending his lunch breaks writing machine code directly in a hex editor.With deep expertise in network flow analysis, reverse engineering, social engineering, and penetration testing, he has significantly contributed to cybersecurity advancements. Notably, Kirils developed the jailbreak tool for MikroTik RouterOS and played a pivotal role in creating e-Saeima, enabling the Latvian Parliament to conduct a fully remote legislative process, the first of its kind globally.He currently serves as the lead researcher at Possible Security and as a research assistant at the Institute of Electronics and Computer Science.

Cyber Security
IoT Security
Network Security
+22
0
Talks
0
Events
0
Countries
—
Years
1 submissions
English
Louis Nyffenegger

Louis Nyffenegger

Founder and CEO

Pentesterlab

Melbourne, Australia

Louis Nyffenegger is an experienced speaker and trainer known for delivering high-impact talks on web security, vulnerability research, and security code review.Highlights include:Keynote Speaker at BSides Canberra Delivered the keynote “A journey to Mastery” sharing actionable strategies for building skills.DEF CON: multiple workshops and talks at DEFCON and villages on SAML, JWT and code reviewOWASP California: talk on JWTNumerous talks at meetups, private workshops and training sessions with top red teams, pentesters, and application security teams worldwide.Louis’s talks are known for blending technical depth with practical, experience-driven advice, helping attendees level up their security skills beyond checklists and automated tools.

Application Security
GraphQL Security
API Security
+14
1
Talks
1
Events
1
Countries
—
Years
English, French
Orange Tsai

Orange Tsai

Principal Security Researcher

DEVCORE

Taiwan

Orange Tsai is the principal security researcher of DEVCORE and a core member of CHROOT security group in Taiwan. He is also the champion and title holder of 'Master of Pwn' in Pwn2Own Vancouver 2021 and Toronto 2022. Additionally, Orange has spoken at several top hacking conferences, such as Black Hat USA (6 times), DEF CON (5 times), HITCON (12 times), CODE BLUE (6 times), POC, Hexacon, RomHack, HITB, and WooYun!Currently, Orange is a 0day researcher focusing on Web and Application Security. His research not only earned him the Pwnie Awards winner for "Best Server-Side Bug" in 2019 and 2021 but also secured 1st place in the "Top 10 Web Hacking Techniques" for 2017, 2018 and 2024. In his free time, Orange also engages in bug bounties. He is especially enthusiastic about RCE, successfully identifying critical RCEs across a broad range of vendors, including Twitter, Facebook, Uber, Apple, Netflix, Tesla, GitHub, Amazon, and more.

Vulnerability Research
Application Security
Web Security
+2
0
Talks
0
Events
0
Countries
—
Years
Chinese (Mandarin), English
Peng, JIAN-LIN

Peng, JIAN-LIN

DEVCORE

Taipei,Taiwan

Jian-Lin Peng, aka YingMuo (@YingMuo), is a security researcher at DEVCORE. His work primarily focuses on IoT, macOS kernel and hypervisor security. He has participated in Pwn2Own competitions 2 times, successfully compromising QNAP NAS. He was also a speaker at HITCON PEACE 2022 and DEVCORE CONFERENCE 2024.

IoT Security
Vulnerability Research
Bug Bounty
1
Talks
1
Events
0
Countries
—
Years
1 accepted
1 submissions
English, Chinese (Mandarin)
Rahul Binjve

Rahul Binjve

India

Rahul Binjve (c0dist) currently leads the Cyber Threat Intelligence (CTI) Engineering team at Fortinet. With over a decade of experience in aggregating and contextualizing various threats, he's a seasoned threat intelligence practitioner. Rahul has presented and conducted workshops at several international conferences, including Black Hat, Nullcon, PHDays, c0c0n, Seasides, and BSides. He's also contributed to multiple open-source security projects, such as the SHIVA spampot and Detux Linux sandbox. Rahul's passions lie in information security, automation, human behavior, and—of course—breaking things.

Cyber Security
Network Security
Web Application Security
+12
0
Talks
0
Events
0
Countries
—
Years
English
RJ

Rick de Jager

The Netherlands

Rick is a part of the Pwn2Own team “PHP Hooligans”. He have competed in five editions of Pwn2Own, exploiting a wide range of targets including routers, printers, and automotive targets. Aside from Pwn2Own, Rick is an avid CTF player, having competed as part of 0rganizers and ICC’s team Europe. 

Embedded Linux Security
Vulnerability Research
Exploit Development
0
Talks
0
Events
0
Countries
—
Years
2 submissions
English, Dutch
Sam Page

Sam Page

Security Researcher

London, United Kingdom

I'm a security researcher with a passion for OS internals and all things low-level. Over the years I have specialised in Android & the Linux kernel, but have dabbled in a number of domains. When I'm not figuring out how things work and breaking them, I love to share my experiences and help others; whether it's via my blog, talks or mentoring.

Mobile Security
Zero-Day
Ethical Hacking
+11
3
Talks
3
Events
2
Countries
—
Years
English
Satoki Tsuji

Satoki Tsuji

Cyber Security Engineer

Ricerca Security, Inc.

Tokyo, Japan

Cybersecurity Enthusiast, CTF Player and Bug Hunter. Contributed to the organization of SECCON CTF, took the stage at AVTOKYO2020/2023/2024, Security Analyst Summit 2024, Hack Fes. 2024, m0leCon 2025, TyphoonCon Seoul 2025, HITCON 2025 and competed in the DEF CON CTF Finals. Renowned for uncovering and reporting vulnerabilities in web services and softwares including Google and Firefox.

Cyber Security
Web Application Security
Web Security
+7
1
Talks
1
Events
0
Countries
—
Years
1 accepted
2 submissions
Japanese, English
Soummya Mukhopadhyay

Soummya Mukhopadhyay

Sr Security Consultant

Payatu

India

Cybersecurity Consultant with over three years of hands-on industry experience, I specialize in offensive security—driven by a passion for uncovering and exploiting weaknesses before adversaries can. My work spans Red Team operations, Network Security, and Web/API Vulnerability Assessment & Penetration Testing (VAPT), with successful engagements across BFSI, IT Products & Services, and Healthcare sectors.With a strong research focus on Adversarial Tactics, Techniques, and Procedures (TTPs), I continuously explore emerging threat vectors and offensive methodologies to deliver actionable security insights that directly reduce business risk. My approach blends technical precision with creative attack strategies, ensuring organizations stay ahead of evolving cyber threats

Web Security
Cloud Security
API Security
+22
0
Talks
0
Events
0
Countries
—
Years
English
SD

Szymon Drosdzol

Security Consultant

Doyensec

Kraków,Poland

I spoke at CONFidence 2025, one of the most established infosec conferences in Central Europe. My talk focused on advanced API authorization vulnerabilities and practical exploitation techniques, drawing from real-world engagements. I’ve compressed years of pentesting and secure code review experience into research-driven content and I’m eager to bring more of that to the stage.

API Security
Application Security
Cyber Security
+16
1
Talks
1
Events
1
Countries
—
Years
English, Polish