Kaspersky has shared the agenda for its 18th annual Security Analyst Summit (SAS 2026), taking place on October 20-23, 2026, in Bali, Indonesia. Challenging the traditional event format, SAS 2026 adopts a unique cyber-anarchy theme in which attendees appear as lone rebels and walk to write a collective security manifesto. This narrative reflects a fundamental reality in modern cyberspace: the best response to today’s complex threat environment is to turn solitary actions into a collaborative cyber-community.
Over 200 participants from around the globe will attend SAS, and this year’s agenda features critical vulnerability disclosures and incident investigations into highly complex attacks targeting multiple digital sectors.
Spycraft goes pre-OS and next-level
This year’s advanced cyberespionage research at SAS exposes highly sophisticated threats that are becoming increasingly adept at evading traditional security tools. Georgy Kucherin of Kaspersky GReAT will detail a stealthy, low-level UEFI bootkit campaign targeting diplomatic entities, while his colleague Sojun Ryu will present new findings on the next-level tactics of the notorious Lazarus APT group.
The threats to daily tech – from consoles and games to mobile devices
SAS will dive into malware targeting consumer systems, automotive control and public media devices. Dmitry Kalinin from Kaspersky Threat Research will provide new details on a campaign targeting Android-based car head units. Security expert Andy Nguyen will explain how key gaming console security bypasses allowed researchers to successfully run the Linux operating system on the PlayStation 5, and independent researcher Victor Pozdov will detail how a remote code execution vulnerability inside Counter-Strike & Dota 2 allowed access to gamers’ PCs. Furthermore, Alex Turing of XLab will present an autopsy of “Kimwolf,” a massive 31.4 Tbps Android TV botnet, and Alfie CG from Cellebrite Labs will dissect “Rocket,” an iOS security bypass weaponized in the Coruna exploit kit.
AI attacking AI – the birth of pre-prompt attacks
SAS will focus on the collision of machine learning and cybersecurity. Satoki Tsuji from Ikotas Labs will demo how zero-click Remote Code Execution chains can completely bypass AI-coding guardrails before an LLM is ever invoked. In addition, Dr. Zhiniang Peng from Huazhong University will showcase an autonomous, LLM-driven vulnerability mining system that successfully automated the discovery and verification of over 100 zero-day weaknesses across top Android distributions used by multiple smartphone manufacturers.
“As the global threat landscape grows increasingly complex, safeguarding our digital future requires deploying trusted cybersecurity tools and active, hands-on collaboration between teams. For nearly two decades, the Security Analyst Summit has served as the premier ecosystem for the world’s top threat intelligence minds to network, build trusted relationships and share critical discoveries. This year’s cyber-anarchy atmosphere is designed to spark creative, out-of-the-box thinking and forge the collective front needed to take on sophisticated cyberattacks,” comments Igor Kuznetsov, Director of Kaspersky’s Global Research and Analysis Team.
The SAS Capture The Flag (CTF) 2026 Finals will take place during the event. A total of 13 teams – bringing together eight champions from the professional SAS CTF qualifiers and five regional winners from the global academic and corporate Kaspersky{CTF} tournament – will battle in a high-intensityAttack-Defense format for a portion of the $18,000 prize pool.
To find out more about the Security Analyst Summit 2026, its agenda and speakers, and to get tickets, visit https://thesascon.com.










