Conference Description
Key Takeaways
- Annual German-language application security conference organised by OWASP Germany, taking place September 23–24, 2026 in Karlsruhe
- Technical programme covering AI security risks, Kubernetes hardening, IoT firmware analysis, threat modelling and fuzzing techniques
- Compliance-focused sessions addressing the Cyber Resilience Act and GDPR requirements for software development
- Dedicated Diversity PreCon event supporting women and queer individuals entering the application security field
- Designed for security engineers, penetration testers, developers, CISOs and compliance officers across technology, finance and public sector organisations
Introduction
German OWASP Day 2026 returns as the principal German-language gathering for application security practitioners, bringing together security engineers, software developers and compliance professionals to examine the evolving challenges of securing modern software systems. Organised by the German chapter of the Open Worldwide Application Security Project (OWASP), the two-day conference in Karlsruhe addresses topics that have gained urgency as organisations accelerate cloud adoption, integrate large language models into their workflows and prepare for new European cybersecurity regulations.
About German OWASP Day 2026
The conference takes place on September 23–24, 2026 and combines a main programme of technical and non-technical presentations with hands-on workshops and structured networking opportunities. Sessions are delivered in both German and English, reflecting the international nature of application security research while maintaining accessibility for the German-speaking community. Attendees may earn up to 14 CPE credits through participation in training sessions and conference activities.
A distinguishing feature of this year’s event is the Diversity PreCon, a pre-conference programme designed to connect women and queer individuals with the broader application security community. This initiative reflects growing recognition within the security industry that diverse teams produce more robust security outcomes and that deliberate effort is required to address historical underrepresentation.
AI Security and Emerging Attack Surfaces
The integration of artificial intelligence into enterprise applications has introduced security considerations that traditional application security frameworks were not designed to address. German OWASP Day 2026 dedicates significant attention to AI-specific vulnerabilities, including prompt injection attacks that manipulate large language models into bypassing intended constraints. The programme also examines how security teams are beginning to use LLMs as assistants in penetration testing workflows, a development that raises questions about both capability and reliability.
These discussions draw on resources such as the OWASP AI Exchange, which provides a structured approach to identifying and mitigating risks specific to machine learning systems. For organisations deploying AI-powered features, understanding these attack vectors has become essential to maintaining the security posture of their applications.
Cloud Infrastructure and Container Security
As organisations migrate workloads to cloud environments, the security perimeter has shifted from network boundaries to application and container layers. The conference addresses Kubernetes security through the lens of the OWASP Kubernetes Top 10, a framework that catalogues the most critical security risks in containerised deployments. Sessions cover practical approaches to hardening orchestration platforms, managing secrets, and implementing runtime protection.
Cloud migration security receives attention as a distinct discipline, acknowledging that the transition period between on-premises and cloud-native architectures often creates temporary vulnerabilities that attackers actively exploit.
Regulatory Compliance and Secure Development
The Cyber Resilience Act represents a significant shift in how the European Union regulates software security, imposing new obligations on manufacturers and developers to address vulnerabilities throughout the product lifecycle. German OWASP Day 2026 provides guidance on preparing for these requirements alongside ongoing GDPR compliance obligations that affect how applications handle personal data.
Technical sessions on threat modelling, including approaches such as TM-BOM, offer practical methodologies for identifying security risks early in the development process. The programme also covers OAuth 2.1 implementation, fuzzing techniques for discovering vulnerabilities, and vulnerability management practices that help organisations prioritise remediation efforts effectively.
Who Should Attend
The conference serves professionals across the application security spectrum, from hands-on practitioners to strategic decision-makers. Application security engineers and penetration testers will find technical depth in sessions on reverse engineering IoT firmware and advanced fuzzing. Security architects and CISOs benefit from discussions on organisational security strategy and compliance frameworks. Software developers and DevOps engineers gain practical knowledge for building security into development pipelines. The programme also accommodates researchers and students seeking to understand current industry challenges and methodologies.
Attendees typically represent technology companies, financial institutions, public sector organisations and consulting firms, creating networking opportunities across sectors that face similar security challenges despite different regulatory environments.

