Conference Description
Key Takeaways
- Off-By-One (OB1) 2026 is Singapore’s dedicated offensive security conference, taking place 14–15 September at the Grand Copthorne Waterfront
- Technical focus areas include vulnerability research, exploit development, hardware and firmware security, AI/ML security, and red team operations
- All presentations undergo peer review by practising security researchers, ensuring vendor-neutral, technically rigorous content
- Designed for security researchers, penetration testers, red team operators, and technical decision makers seeking substantive offensive security knowledge
- Single-track format with hands-on activities including capture-the-flag competitions and interactive villages
Introduction
Off-By-One (OB1) returns for its second edition in September 2026, bringing together the offensive security community for two days of deeply technical presentations and hands-on activities in Singapore. The conference serves security researchers, penetration testers, and technical practitioners who require substantive knowledge on vulnerability research, exploit development, and emerging attack techniques. With the threat landscape growing increasingly complex and adversaries adopting sophisticated methods including AI-assisted attacks, events that prioritise technical depth over commercial messaging have become essential for practitioners seeking to maintain defensive and offensive capabilities.
About Off-By-One 2026
Established in 2024 and organised by STAR Labs SG, Off-By-One was created to address a gap in the Asian cybersecurity conference landscape. The event operates on a peer-review model where practising researchers evaluate all submitted talks, filtering out vendor-driven content in favour of original research and practical techniques. This approach distinguishes OB1 from larger industry conferences where commercial interests often compete with educational value.
The 2026 edition maintains a single-track format, ensuring all attendees share a common experience and can engage with every presentation. Beyond the main stage, the conference incorporates capture-the-flag competitions and interactive villages that provide hands-on opportunities to apply techniques in controlled environments.
Technical Focus Areas
The conference programme spans the breadth of offensive security disciplines. Vulnerability research and exploit development form the core subject matter, covering the methodologies researchers use to identify security flaws and develop working exploits. Hardware and firmware security sessions address the growing attack surface presented by embedded systems, IoT devices, and the low-level components that underpin modern computing infrastructure.
AI and machine learning security has emerged as a critical topic as organisations deploy these systems in production environments. Offensive researchers are examining how adversaries can manipulate training data, exploit model vulnerabilities, and abuse AI-powered systems. This intersects with traditional web and cloud security concerns, where misconfigurations and application-layer vulnerabilities continue to provide entry points for attackers.
Red team operations content addresses the practical challenges of simulating advanced adversaries within enterprise environments, while cryptographic attack research explores weaknesses in the implementations that protect sensitive data. Mobile security and operating system internals round out the technical programme, reflecting the diverse platforms that security teams must understand to conduct effective assessments.
Addressing the Regional Knowledge Gap
Asia-Pacific has historically had fewer dedicated offensive security conferences compared to North America and Europe, where events such as DEF CON, Black Hat, and OffensiveCon have long served the research community. OB1 aims to provide a regional platform where researchers can present findings, exchange techniques, and build professional relationships without the expense and logistical challenges of international travel. The emphasis on affordability and community ownership reflects a recognition that valuable security research often emerges from independent researchers and smaller teams rather than large corporate security divisions.
Who Should Attend
OB1 is designed for practitioners who work directly with offensive security techniques. Security researchers conducting vulnerability discovery, penetration testers performing authorised assessments, and red team operators simulating adversary behaviour will find directly applicable content. Technical decision makers including CTOs and security architects benefit from understanding the current state of offensive research, which informs defensive strategy and risk assessment. Bug bounty hunters and security consultants seeking to refine their methodologies will encounter peer-reviewed presentations that reflect current best practices.
The conference explicitly prioritises technical substance, making it less suitable for those seeking introductory content or broad industry overviews. Attendees should expect detailed technical discussions that assume foundational knowledge of security concepts and tooling.
Supporting Organisations
The 2026 edition receives support from organisations including InnoEdge, the Centre for Strategic Infocomm Technologies (CSIT), ECQ, J.P. Morgan Chase, and StealthMole. This mix of government-affiliated bodies, financial institutions, and specialist security firms reflects the broad institutional interest in maintaining a healthy offensive security research community.

