CFP Directory LogoCFP Directory
EventsSpeakersTalksOrganizationsFeaturesPricingWhy Us
Sign in

Company

  • About Us
  • Contact

Contact Info

Address:

13, Lorong Toh Aka

Georgetown 10100

Penang, Malaysia

Email:

info@cfp.directory

Website:

13thirtyseven.my

Business Hours

Monday - Friday:9:00 AM - 6:00 PM
Saturday:9:00 AM - 1:00 PM
Sunday:Closed

GMT+8 (Malaysia Standard Time)

© 2025 CFP Directory. All rights reserved.
13 Thirty Seven Sdn. Bhd. (1401538-A)
Privacy PolicyTerms of Service

Find Expert Speakers

Connect with talented speakers from around the world. Search by expertise, topics, or use our advanced filters to find the perfect speaker for your event.

Create Your Speaker Profile
Web Application Security

Showing 24 speakers matching your filters

AG

Amey Gat

Principal Threat Researcher

Fortinet

Pune, India

Speaker at multiple International Security conferences: NullCon, AVAR Singapore, AVAR Chennai, Bsides Delhi. Did first lock picking workshop in India with Nullcon in 2012 and multiple lock picking workshops in Nullcon , Hackers conference.  Did workshop on Arduino in NullCon hackers conference and created first ever Hardware badge in India for Hackers conference.

Cyber Security
Network Security
Web Application Security
+15
0
Talks
0
Events
0
Countries
—
Years
1 submissions
English, Marathi +1
AS

Anant Shrivastava

Founder

Cyfinoid Research

Bhopal,India

As a seasoned speaker and trainer, Anant has shared his expertise at various prestigious platforms including Black Hat (USA/ASIA/EU), Defcon, Nullcon, c0c0n, and Rootconf. His extensive involvement in these conferences extends to serving as a CFP reviewer for Blackhat EU, nullcon, Rootconf by Hasgeek, and multiple villages at Defcon (Recon, Adversary and Cloud), showcasing his dedication to nurturing and elevating the discourse within the field.

Application Security
Cloud Security
Cyber Security
+21
0
Talks
0
Events
0
Countries
—
Years
1 submissions
English
Arun Raj Kaprakattu

Arun Raj Kaprakattu

Staff Software Quality Engineer

Nokia of America Corporation

Fremont,CA

Passionate about ensuring the reliability and performance of networking solutions, I specialize in protocol qualification, test automation, and validation for cutting-edge telecommunications and networking technologies. With a strong foundation in networking protocols, software testing, and automation frameworks, I thrive on optimizing test processes and driving continuous improvements in network quality.At Nokia, I focus on verifying and qualifying networking protocols to meet the highest industry standards, leveraging automation to enhance efficiency, accuracy, and scalability in testing. My expertise spans across routing, switching, network security, and cloud-native networking solutions, ensuring seamless integration and deployment.Key strengths:✔ Protocol Qualification & Network Testing – Expertise in evaluating routing and switching protocols, ensuring interoperability and compliance.✔ Test Automation & Scripting – Proficient in developing test suites that streamline validation processes.✔ Troubleshooting & Performance Analysis – Skilled in debugging complex network issues and optimizing system performance.✔ Collaboration & Innovation – Work closely with cross-functional teams to enhance test strategies and improve product quality.Always eager to explore emerging technologies, improve testing methodologies, and contribute to the evolution of next-generation networking solutions. Let’s connect and discuss innovations in networking and test automation!

Wireless Network Security
Web Application Security
CI/CD Security
+2
0
Talks
0
Events
0
Countries
—
Years
1 submissions
English
Boik Su

Boik Su

Security Research Manager

CyCraft Technology

Taipei,Taiwan

Boik Su is a security research manager at CyCraft Technology and is currently focused on Cloud Security, Web Security, and Blockchain Security. He takes an active role in the cybersecurity community and has delivered speeches at multiple seminars across the globe, including HITCON, HITB, FIRSTCTI, VB, and HackerOne. He still participates in CTF competitions, including SECCON CTF in Japan and HITCON CTF in Taiwan, and has submitted multiple reports to bug bounty programs and open-source projects.

API Security
Application Security
Cloud Security
+20
0
Talks
0
Events
0
Countries
—
Years
1 submissions
English, Chinese (Mandarin)
canalun

canalun

Tokyo,Japan

I'm a developer (Firefox) and bug hunter for browsers.

Web Security
Web Application Security
Web Development
+1
0
Talks
0
Events
0
Countries
—
Years
English, Japanese
Daniel Monzón

Daniel Monzón

Red Team Operator

Siemens

Madrid, Spain

Red Team operator at Siemens. Holds various hacking certifications such as: OSCP, OSWP, CRTP, eMAPT, etc. Interested in many fields within hacking: red teaming, cloud, web security, AI, low level stuff (reversing, pwn, etc). Speaker in various conferences: hack0n, RootedCON Málaga, Honeycon, Worldparty, DragonJARCon, etc.

Web Application Security
Wireless Network Security
MITRE ATT&CK
+7
0
Talks
0
Events
0
Countries
—
Years
English, Spanish
Danish Tariq
Available

Danish Tariq

Director, Cyber Security

Laburity

Dubai

Danish Tariq is a Security Engineer by profession and a Security researcher by passion. He has been working in Cyber Security for over 8 years and it all started out of a curiosity to break things and look deep down into those things (physical or virtual) back in his teenage years. His major expertise is Penetration Testing and Vulnerability Assessments.He was also involved in bug bounty programs as well, where he helped many companies by finding vulnerabilities at different levels. Companies include Microsoft, Apple, Nokia, Blackberry, Adobe, etc.Spoke @ BlackHat MEA 2022 (Briefing: Supply-Chain Attacks)Featured in "The Register" for an initial workaround for the NPM dependency attacks.Certified Ethical Hacker, Certified Vulnerability Assessor (CVA), Certified AppSec Practitioner, Certified Network Security Specialist (CNSS),IBM Cyber Security AnalystEx-Chapter Leader @ OWASPEx-Top Rated freelancer (Information security category) on UpworkRecent security research and CVEs include - CVE-2022-2848 & CVE-2022-25523Served as a Moderator @ OWASP 2022 Global AppSec APAC.Researched and Speaker at MCTTP, Germany - HITB, Thailand - OOTB, Indonesia and many more.

Cyber Security
Supply Chain Attacks
Dark Web Defense
+3
7
Talks
5
Events
5
Countries
—
Years
2 submissions
English, Urdu +1
Dimitris Pallis

Dimitris Pallis

Managing Ethical Hacker

HAKFLOW

London

As an ethical hacker, I equip enterprises with the advice and solutions to improve their digital security posture and their overall business growth. Throughout my career as an ethical hacker I’ve worked across several industries including:💥 Government💥 Advertising💥 Retail💥 Financial Services💥 Blockchain💥 Technology💥 Publishing💥 Non-Profit💥 And more!This has provided me the opportunities to gain a breadth of knowledge on all things security testing.

Ethical Hacking
Mobile Security
Penetration Testing
+7
2
Talks
2
Events
2
Countries
—
Years
Greek, English
JS

Jordan Santarsieri

Founder

Vicxer, Inc.

Miami,US

Mr Santarsieri is a founder partner at Vicxer where he utilizes his 16+ years of experience in the security industry, to bring top notch research into the ERP (SAP / Oracle) world.He is engaged in a daily effort to identify, analyze, exploit and mitigate vulnerabilities affecting ERP systems and business-critical applications, helping Vicxer's customers (Global Fortune-500 companies and defense contractors) to stay one step ahead of cyber-threats.Jordan has also discovered critical vulnerabilities in Oracle, IBM and SAP software, and is a frequent speaker at international security conferences such as Black-Hat, Insomnihack, YSTS, Auscert, Sec-T, Rootcon, NanoSec, Hacker Halted, OWASP US, Infosec in the city, Code Blue and Ekoparty.

Cyber Security
Application Security
Web Application Security
+14
0
Talks
0
Events
0
Countries
—
Years
English, Spanish +3
Joshua Stroschein

Joshua Stroschein

Reverse Engineer

SiouxFalls,SouthDakota

Josh is an experienced malware analyst and reverse engineer and has a passion for sharing his knowledge with others. He is a reverse engineer with the FLARE team at Google, where he focuses on tackling the latest threats. Josh is an accomplished trainer, providing training at places such as Ring Zero, BlackHat, Defcon, Toorcon, Hack-In-The-Box, Suricon, and other public and private venues. Josh is also an author on Pluralsight, where he publishes content around malware analysis, reverse engineering, and other security related topics.

Application Security
Cyber Security
Network Security
+4
0
Talks
0
Events
0
Countries
—
Years
English
Kirils Solovjovs

Kirils Solovjovs

Founder

Possible Security

Riga, Latvia

Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist, renowned for uncovering and responsibly disclosing critical security vulnerabilities in both national and international systems. Kirils started programming at age 7 and by grade 9 was spending his lunch breaks writing machine code directly in a hex editor.With deep expertise in network flow analysis, reverse engineering, social engineering, and penetration testing, he has significantly contributed to cybersecurity advancements. Notably, Kirils developed the jailbreak tool for MikroTik RouterOS and played a pivotal role in creating e-Saeima, enabling the Latvian Parliament to conduct a fully remote legislative process, the first of its kind globally.He currently serves as the lead researcher at Possible Security and as a research assistant at the Institute of Electronics and Computer Science.

Cyber Security
IoT Security
Network Security
+22
0
Talks
0
Events
0
Countries
—
Years
1 submissions
English
Louis Nyffenegger

Louis Nyffenegger

Founder and CEO

Pentesterlab

Melbourne, Australia

Louis Nyffenegger is an experienced speaker and trainer known for delivering high-impact talks on web security, vulnerability research, and security code review.Highlights include:Keynote Speaker at BSides Canberra Delivered the keynote “A journey to Mastery” sharing actionable strategies for building skills.DEF CON: multiple workshops and talks at DEFCON and villages on SAML, JWT and code reviewOWASP California: talk on JWTNumerous talks at meetups, private workshops and training sessions with top red teams, pentesters, and application security teams worldwide.Louis’s talks are known for blending technical depth with practical, experience-driven advice, helping attendees level up their security skills beyond checklists and automated tools.

Application Security
GraphQL Security
API Security
+14
1
Talks
1
Events
1
Countries
—
Years
English, French
Michael Coates

Michael Coates

Founding Partner

Seven Hill Ventures

San Francisco, California USA

Two decades of cybersecurity experience including executive roles at Twitter, CoinList, Mozilla and OWASP. A co-founder and CEO of a venture backed cybersecurity startup (acquired) and an early stage investor finding and growing the next generation of amazing cybersecurity companies. Based in San Francisco.

Application Security
Cyber Security
Cloud Security
+3
0
Talks
0
Events
0
Countries
—
Years
English
Omkar Joshi

Omkar Joshi

Lead Security Engineer

Coupa Software

Pune

Over 12 years of experience in the security domain, specializing in Penetration Testing, Application Security, Cloud Security, Architecture and Forensics Investigation.Leading an Offensive Security (OffSec) team with a passion for Red Teaming and Security Research.Reported multiple vulnerabilities in products and applications, recognized with CVEsHolds prestigious certifications including GIAC Cloud Penetration Tester (GCPN), Offensive Security Certified Professional (OSCP), Offensive Security Wireless Professional (OSWP), Certified Red Team Operator (CRTO), among othersPresented at prominent conferences such as Bsides Budapest, Bsides Milano, Hacktivity, VulnCon 2024, Hacker Halted, CyberSec Asia, Identity Shield, Microsoft BlueHat 2025, PHDays 2025 and VulnCon 2025.

Cloud Security
Application Security
API Security
+22
0
Talks
0
Events
0
Countries
—
Years
2 submissions
English
Rahul Binjve

Rahul Binjve

India

Rahul Binjve (c0dist) currently leads the Cyber Threat Intelligence (CTI) Engineering team at Fortinet. With over a decade of experience in aggregating and contextualizing various threats, he's a seasoned threat intelligence practitioner. Rahul has presented and conducted workshops at several international conferences, including Black Hat, Nullcon, PHDays, c0c0n, Seasides, and BSides. He's also contributed to multiple open-source security projects, such as the SHIVA spampot and Detux Linux sandbox. Rahul's passions lie in information security, automation, human behavior, and—of course—breaking things.

Cyber Security
Network Security
Web Application Security
+12
0
Talks
0
Events
0
Countries
—
Years
English
Rajanish Pathak (h4ckologic)

Rajanish Pathak (h4ckologic)

Senior Security Researcher

AbuDhabi

I (@h4ckologic) am a cybersecurity researcher passionate about uncovering and addressing critical vulnerabilities in complex technology implementations. My work includes identifying and reporting issues to top tech companies like Apple, Google , Microsoft and many others, some of my CVES identified are Apple (CVE-2021-31001), PhantomJS (CVE-2019-17221), and NPM html-pdf (CVE-2019-15138). I’ve had the privilege of sharing my research at leading conferences, including NoNameCon, Ekoparty, and Hacktivity (2020); Hack in the Box and Romhack (2023); and HITB Bangkok and BSides Ahmedabad (2024). With a focus on practical solutions and deep technical insights, I’m dedicated to advancing security practices and contributing to the global infosec community.

Application Security
Cyber Security
Cloud Security
+8
1
Talks
1
Events
1
Countries
—
Years
1 submissions
English
Satoki Tsuji

Satoki Tsuji

Cyber Security Engineer

Ricerca Security, Inc.

Tokyo, Japan

Cybersecurity Enthusiast, CTF Player and Bug Hunter. Contributed to the organization of SECCON CTF, took the stage at AVTOKYO2020/2023/2024, Security Analyst Summit 2024, Hack Fes. 2024, m0leCon 2025, TyphoonCon Seoul 2025, HITCON 2025 and competed in the DEF CON CTF Finals. Renowned for uncovering and reporting vulnerabilities in web services and softwares including Google and Firefox.

Cyber Security
Web Application Security
Web Security
+7
1
Talks
1
Events
0
Countries
—
Years
1 accepted
2 submissions
Japanese, English
Sayli ambure

Sayli ambure

Washington DC, USA

I got into cybersecurity the messy, curious way - hacking games as a teenager to get extra coins and superpowers, then later reverse-engineering ransomwares to understand how they worked. That same curiosity and passion led me to a career in offensive cyber security.In the past 5+ years of work experience across India, UAE & USA, I’ve worked on:• Mobile application penetration testing (Android & iOS)• Web application and API penetration testing• Secure code review across C/C++, Python, Java, Golang, JavaScript, Typescript and C# .NET• Custom Signature Code Analysis (Semgrep, YARA & Coverity CodeXM custom checkers)• Adverserial tradecraft and Cyber threat intelligence• Network and infrastructure assessments with Segmentation penetration tests for cloud and on-prem setups• Software Composition Analysis (Coverity, Black Duck, GitHub Advisories, PlexTrac)• Innovative research & automated pentest tools development (AI, OSINT, Python, Bash script)Currently, I work as a Security Researcher at OnDefend, where I help secure user data of a large-scale social media platform & contribute to U.S. national security.🌟 Key Achievements:• Awarded the first-ever “Magical Mention” as an intern at Equinix for uncovering and reporting multiple critical security misconfigurations. Recognized for investigative persistence, curiosity, and successfully improving internal security workflows through proactive analysis and alerting.• Bug Bounty & Hall of Fame mentions: Tesco, IKEA, SecureLayer7 live hacking event, Accenture, Ericsson, Springer Nature, OSIsoft🔍CVE Research:• CVE-2020-11539 : Access control issue in Tata Sonata Smartwatch• CVE-2020-11540 : Access control issue in Tata Sonata Smartwatch• CVE-2020-25498 : Chained CSRF & Stored XSS vulnerabilities in Beetel router• CVE-2020-35262 : Stored XSS vulnerability in Digisol router👾 Outside of work, I’m always exploring new tools, ways to use AI as leverage in security, hacking techniques & trying to level up. I love building my own custom IoT devices as well as hacking them.🧑‍🤝‍🧑As an active member of 'Women in Cybersecurity', 'Women in Security & Privacy' and 'The Diana Initiative' volunteer at Defcon, I’m also passionate about making cyber security more inclusive and human, especially for women and underrepresented voices.

Cyber Security
Application Security
IoT Security
+22
0
Talks
0
Events
0
Countries
—
Years
English
Seokchan Yoon

Seokchan Yoon

Security Engineer

Zellic.io

Seoul,Korea

I'm Seokchan Yoon, and I am an offensive web security researcher and auditor. I currently work at Zellic, where I focus on auditing Web2 infrastructure that underpins Web3 systems. In addition, I serve as a Security Team member of Apache Airflow, contributing to securing one of the most widely used workflow platforms.Over the years, I have disclosed vulnerabilities and CVEs across major open-source ecosystems such as Django, Apache Airflow, Python, Ruby on Rails, and Spring. I have also participated in the global security community through CTF competitions, most recently as a finalist at DEF CON 33 CTF.Beyond vulnerability research, I actively share my findings with the community. I have spoken at PyCon Korea 2024 and CODEGATE 2023, where I presented practical insights on exploiting and defending against framework-specific security weaknesses. More about my work can be found on my portfolio: https://ch4n3.kr

Web Application Security
Web Security
0
Talks
0
Events
0
Countries
—
Years
1 submissions
English, Japanese +1
SP

Sharique Raza, Ph.D.

Senior Securoty Architect

Emirates NBD

Dubai

ISACA Cybersecurity ConferenceDelivered an insightful session on Zero Trust Security, breaking down its practical implementation and its role in modern cyber defense architecture. His talk was well-received by industry professionals and highlighted the evolving nature of perimeter-less security models.CIO News Cybersecurity ForumPresented on the integration of offensive and defensive security practices, emphasizing collaboration over siloed efforts. His impactful delivery earned him an on-the-spot award for excellence in thought leadership and practical insight.Crypto Expo DubaiTook the stage at one of the largest blockchain and cryptocurrency platforms in Dubai, where he delivered a high-impact talk on “Hacking Crypto Wallets”. The session provided deep dives into real-world attack vectors and preventive mechanisms, drawing significant attention from global fintech and blockchain professionals.

Cyber Security
Application Security
API Security
+22
0
Talks
0
Events
0
Countries
—
Years
English
Soummya Mukhopadhyay

Soummya Mukhopadhyay

Sr Security Consultant

Payatu

India

Cybersecurity Consultant with over three years of hands-on industry experience, I specialize in offensive security—driven by a passion for uncovering and exploiting weaknesses before adversaries can. My work spans Red Team operations, Network Security, and Web/API Vulnerability Assessment & Penetration Testing (VAPT), with successful engagements across BFSI, IT Products & Services, and Healthcare sectors.With a strong research focus on Adversarial Tactics, Techniques, and Procedures (TTPs), I continuously explore emerging threat vectors and offensive methodologies to deliver actionable security insights that directly reduce business risk. My approach blends technical precision with creative attack strategies, ensuring organizations stay ahead of evolving cyber threats

Web Security
Cloud Security
API Security
+22
0
Talks
0
Events
0
Countries
—
Years
English
SD

Szymon Drosdzol

Security Consultant

Doyensec

Kraków,Poland

I spoke at CONFidence 2025, one of the most established infosec conferences in Central Europe. My talk focused on advanced API authorization vulnerabilities and practical exploitation techniques, drawing from real-world engagements. I’ve compressed years of pentesting and secure code review experience into research-driven content and I’m eager to bring more of that to the stage.

API Security
Application Security
Cyber Security
+16
1
Talks
1
Events
1
Countries
—
Years
English, Polish
Vic Huang

Vic Huang

Taipei city,Taiwan

He is an Independent Researcher , Security Engineer and a member at UCCU Hacker  He works in Web, Mobile, ICS, and Privacy domain for fun.He shared his off-time research at Troopers, HITB, CODE BLUE, Ekoparty, ROOTCON, REDxBLUE Pill, HITCON, CYBERSEC, and DEFCON Village. 

Web Application Security
Privacy by Design
OT Security
2
Talks
2
Events
2
Countries
3
Years
1 submissions
English, Chinese (Mandarin)
工藤蒔大

工藤蒔大

Waseda University

Tokyo

"3rd-year student at Waseda University, School of Fundamental Science and Engineering, Department of Communications and Computer Engineering, specializing in cybersecurity.

Web Security
Web Application Security
IoT Security
1
Talks
1
Events
0
Countries
—
Years
1 accepted
1 submissions
Japanese, English