Conference Description
Key Takeaways
- Private offensive security conference held in Canberra, Australia on 27 September 2026
- Technical presentations covering vulnerability research, exploit development and IoT security
- Topics include Linux kernel exploitation, PostgreSQL vulnerabilities, Rust programming pitfalls and zero-click IoT attacks
- Designed for security researchers, penetration testers and offensive security practitioners
- Keynote addresses the strength and global standing of Australia’s offensive security community
Introduction
A private conference dedicated to offensive security will take place in Canberra, Australia on 27 September 2026. The event brings together security researchers and practitioners for a day of technical presentations examining vulnerability research, exploit development and emerging attack techniques. With offensive security capabilities increasingly central to both national defence and private sector resilience, the conference provides a focused environment for knowledge sharing among specialists working at the cutting edge of the discipline.
Australia’s Position in Global Offensive Security
The keynote presentation, titled “Quietly World-Class: The Australian Offensive Security Ecosystem,” will be delivered by Kylie McDevitt. As CEO and co-founder of InfoSect, a Canberra-based firm specialising in vulnerability research and exploit development, McDevitt brings more than 17 years of cyber security experience to the discussion. Her background includes over a decade at the Australian Signals Directorate, where she held offensive security and technical leadership positions.
McDevitt’s involvement in the Australian security community extends beyond her commercial work. She leads BSides Canberra, one of Australia’s largest hacker conferences, and co-organises the long-running CSides meetup series. Her keynote is expected to examine how Australian offensive security capabilities have developed and where the local ecosystem sits relative to international counterparts.
Technical Presentations
The conference programme features a range of technical talks spanning operating system internals, application security and embedded device vulnerabilities. Presentations will address both novel attack techniques and practical lessons from real-world research.
Linux kernel exploitation features prominently, with a presentation titled “Linux Kernel Speedrun Any%” examining rapid exploitation techniques. IoT security receives dedicated attention through “Zero-Click to Root: Breaking IoT Security Without Authentication,” which explores how attackers can compromise connected devices without requiring any user interaction—a particularly concerning vector as IoT deployments continue to expand across critical infrastructure and consumer environments.
Database security will be addressed in “A Tale of Two Exploits: Wormable PostgreSQL RCE,” examining remote code execution vulnerabilities in the widely deployed open-source database system. The wormable nature of such vulnerabilities presents significant risk, as successful exploitation can propagate automatically across networked systems.
Memory safety and secure programming practices feature in “How to make silly mistakes with rust’s lifetimes,” which examines common pitfalls when working with Rust’s ownership and lifetime system. While Rust is often promoted for its memory safety guarantees, the presentation highlights how developers can still introduce subtle bugs through incorrect lifetime annotations.
Additional presentations include “Geckos Everywhere: The Case of the Escaped Gecko” and “Not having a bad enough time,” with at least one further talk remaining under embargo at the time of programme publication.
Who Should Attend
The conference is designed for security researchers, penetration testers, exploit developers and professionals working in offensive security roles. The technical depth of the programme assumes familiarity with low-level systems, vulnerability classes and exploitation methodologies. Those involved in defensive security may also find value in understanding current offensive techniques to better inform detection and mitigation strategies.

