OWASP Italy Day 2026
π OWASP Italy Day 2026 β Cagliari, 18 June 2026
OWASP Italy Day 2026 will take place on June 18th, 2026, in Cagliari, Sardinia (Italy) β returning to one of the most inspiring locations for cybersecurity innovation and collaboration.
This will be a free, one-day, in-person event focused on application security, AI security, DevSecOps, and secure software development, bringing together researchers, professionals, and students to exchange ideas, share experiences, and strengthen the AppSec community.
The main conference will start on June 18th at 3:30 PM, following a day of training sessions and workshops on June 17th (and optionally the morning of June 18th).
π OWASP Italy Day 2026
18 June 2026 β Cagliari
π AI & Security Trainings 17,18 June β 2026 Program
OWASP continues to strongly invest in advanced training on AI Security, Threat Modeling, and Secure Development.
Below is a selection of official OWASP trainings available in 2026, delivered by international experts and OWASP project leaders.
Please reserve your seat here
AI-Powered Threat Modeling
Modernizing Security Analysis with LLM Augmentation
- Speaker: Marco Morana
Field CISO β Head of Application & Product Security Architecture, Avocado Systems Inc. - Format: 1.5-day training
- Level: Intermediate
An advanced training focused on modernizing Threat Modeling by leveraging Large Language Models and AI augmentation techniques to improve security risk analysis.
Secure Coding for Large Language Model Applications
- Speaker: Fabio Cerullo
Cycubix LTD - Format: 1.5-day training
- Level: Introductory / Overview
A practical introduction to secure development of LLM-based applications, covering common vulnerabilities, security patterns, and best practices.
AI Security Training
- Speaker: Vandana Verma Sehgal
Member, OWASP Global Board of Directors - Format: 1-day training
- Level: Introductory / Overview
An introductory training covering the fundamentals of AI security, designed for professionals looking to understand threats, risks, and mitigation strategies in real-world environments.
Building, Securing, and Deploying AI Agent Swarms
in a Trustless Decentralized Ecosystem
- Speaker: Krishnendu Dasgupta
Founder, AXONVERTEX AI - Format: 1-day training
- Level: Intermediate
An innovative training focused on designing, securing, and deploying AI agent swarms within decentralized and trustless ecosystems.
The Mobile Playbook
A Guide for Android Security
- Speaker: Sven Schleier
OWASP MAS Project Co-Lead - Format: 1-day training
- Level: Advanced
An advanced guide to Android mobile security, based on real-world experience from the OWASP Mobile Application Security (MAS) project.
Key Dates
| Item | Date |
|---|---|
| Training Day(s) | June 17β18, 2026 |
| OWASP Italy Day Conference | June 18, 2026 β from 3:30 PM |
Please reserve your seat here
π OWASP ITALY DAY June 18 - Agenda
π’ 15:00 β 15:45
Registration & Welcome Coffee
π’ 15:45 β 16:00
π€ Opening Remarks
OWASP Italy Leadership
Setting the stage for an evening focused on modern attack surfaces, AI-native threats, and secure engineering at scale.
π£ 16:00 β 16:45
π KEYNOTE SESSION
Vandana Verma β Snyk
Abstract and bio coming soon.
π΅ 16:45 β 17:15
Killing the Noise: AI Triage for High-Volume API Security Findings
Alessio Dalla Piazza β Co-Founder & CTO, Equixly
Why this matters:
Security teams are drowning in false positives. This talk shows how AI can reduce noise without introducing new risks.
What youβll learn:
- Algorithmic vs beacon-based detection
- EPSS prioritization strategies
- Reachability analysis for filtering
- Where LLM triage works β and where it fails
π https://linkedin.com/in/alessiodallapiazza/
π΅ 17:45 β 18:15
From Scratch: Building an AppSec Program That Actually Works
Julio Araujo β Head of Security @ Rocket.Chat
A real-world blueprint for building an AppSec program with:
- Limited resources
- Vulnerability overload
- Cultural friction
Practical lessons from embedding security into SDLC in a fast-moving open-source environment.
π https://linkedin.com/in/julio-cfa/
β 18:15 β 18:30
Coffee Break
π΄ 18:30 β 19:00
Itβs Giving Insecure Vibes: Secure Coding Literacy for Vibe Coders
Betta Lyon Delsordo β Ethical Hacker @ AWS
AI-assisted coding is accelerating development β but also vulnerabilities.
This session covers:
- Common AI-generated vulnerabilities
- Secure prompting techniques
- Hybrid AI-assisted secure review
- Real-world exploitation examples
Speaker at DEF CON 33, ESET World, WiCyS.
π https://linkedin.com/in/betta-lyon-delsordo/
π΄ 19:00 β 19:30
LLM Prompt Injection: When Language Models Become an Attack Surface
Matteo Grollino β RED Team Senior Member, Relatech
The #1 risk in the OWASP Top 10 for LLM Applications.
This session explores:
- Direct vs indirect prompt injection
- System prompt manipulation
- AI attack surface expansion
- Live demonstration
A must-attend for anyone building AI-powered web applications.
π΄ 19:30 β 20:00
Agentic AI Under Siege: Verifiable Safety Envelopes for Micro-LLMs
Vaishnavi Gudur β Senior Software Engineer, Microsoft
How do we make AI agents provably safe?
Topics include:
- Zero-trust AI boundaries
- Policy-as-code guardrails
- Signed tool invocation
- Adversarial CI testing
- Immutable audit logs
Regulated environments. Multi-tenant safety. Practical architectures.
π https://linkedin.com/in/vaishnavi-gudur
π΅ 20:00 β 20:30
OWASP MAS Project Updates
Sven Schleier β OWASP MAS Project Co-Lead
Latest updates from:
- MASWE
- MASTG v2 Beta
- Android & iOS test apps
- iOS 17+ testing techniques
Hands-on improvements for mobile security testing professionals.
π https://linkedin.com/in/sven-schleier/
π΅ 20:30 β 21:00
Zero-Trust Software Supply Chain at Enterprise Scale
Ritesh Ranjan & Ravinder Singh Dafauti β Adobe
Securing 100K+ builds per day with:
- SLSA Level 3 alignment
- Hardened CI runners
- Ephemeral build environments
- Keyless container signing
- Enterprise-scale provenance
A practical blueprint for real-world supply chain security.
π https://linkedin.com/in/ritesh-ranjan-1bab2196/
π https://linkedin.com/in/ravinder-singh-04b781b1/
π 21:00 β 21:30
Closing Remarks & Community Announcements
πΉ 21:30 β 01:00
Dinner Networking & OWASP Community Aperitivo
An opportunity to connect with speakers, contributors, and security professionals from across Europe.
π€ Sponsorship & Community
Interested in sponsoring OWASP Italy Day 2026?
Contact the OWASP Italy Board for partnership opportunities.
ποΈ Location
Venue: Emerson Beach Club - Cagliari (Italy)
π§ Organizers
Davide Ariu, OWASP Italy Chair & Pluribus One
Matteo Meucci, OWASP Italy Chair & Synapsed.ai
Laura Ariu, OWASP Italy & Pluribus One
Luca Piras, OWASP Italy & Pluribus One
Back to the OWASP Italy Chapter