Break It, Then Defend It: Inside Nullcon Goa 2026

Nearly thirty sessions of researchers, CISOs, and exploit-writers gather on the Goa coastline to take apart the threats of 2026 — and figure out what still holds.
The threat doesn’t file a change request before it shows up in your environment. By the time the board asks whether you’re “covered,” somebody has already read the API keys your AI left lying around, fuzzed your HTTP/3 stack, and talked to your employees’ smartwatches without so much as a password.
Nullcon Goa 2026 — Asia’s longest-running hacker conference gathered the people who live in that gap between “we have a policy” and “we have a problem.”
Across nearly thirty sessions, one question kept surfacing: when AI is rewriting both the attack and the defense, what’s actually left for humans to hold onto?
The answer came together as one connected story. It starts, as the money always does, in the boardroom.
The Boardroom
Adopting security tools is easy. Owning the outcome when they fail is the hard part, and that’s where the leadership track lived.
- Col. Tarun Uppal of I4C (Ministry of Home Affairs) traced how Indian cybercrime grew up — from scattered fraud into organized, state-backed networks — and how coordinated intelligence is finally starting to turn the tide.
- Gaurav Saxena of SentinelOne offered the practical antidote: an absorb-adapt-recover framework built to contain a breach, mutate alongside the threat, and shorten the road back to normal.
- A run of CISO and CXO panels — Rishi Mehta, M.A.K.P. Singh and Abhishek Bansal on cutting through the noise; Shailendra Fuloria, Vivek Yadav, Yask Sharma and Nageshwaran Chinnadurai on redefining resilience for an age of AI threats and supply-chain risk; and Durga Prasad Dube, Satyavathi Divadari and Rajeev Verma on the awkward gap between a CISO’s accountability and their actual authority.
- On the compliance side, Jagannath Sahoo, Yask Sharma and Neilmani Sahu stress-tested DPDPA’s 72-hour breach-notification clock and explained why most existing response playbooks quietly fall short of it.
The throughline: resilience — the ability to take the hit and keep operating — has quietly replaced prevention as the job description.
The AI Reckoning
Then came the part nobody in the room could dodge. AI showed up on every side of the table at once: the thing being attacked, the thing doing the attacking, and the shiny new tool in the defender’s kit.
- Anant Shrivastava and Saikat Datta asked the blunt version out loud — will AI disrupt the cybersecurity industry, or demolish it? — and worked to separate the market hype from what’s actually happening on the ground.
- Rajnish Gupta of Tenable mapped the expanding AI attack surface, from shadow AI nobody approved to exposure that nobody’s tracking.
- Thejes Sree Satheesh Kumar and Srinivasan Sekar showed how AI agents wired together with protocols like MCP create unmonitored toolchains that traditional security models simply aren’t built to watch, while Shubham Mittal of RedHunt Labs charted nine separate AI exposure layers — leaked keys, open orchestration platforms — that slip past conventional tooling entirely.
- And the unsettling one: Saikat Datta, Col. Alok Shankar Pandey, Makarand Kadave and Amit Malhotra on how AI-driven deception now targets trust itself, the one thing security has always quietly assumed.
The catch nobody could engineer away: AI can read the output faster than ever, but it still can’t be the one accountable for what the output means.
The Hunt
If the executives set the stakes, the researchers showed exactly how the locks get picked. This was the part of the program that earns Nullcon its reputation.
- Kandi Abhishek Reddy and Alla Vamsi Krishna dissected CVE-2025-21533, a VirtualBox speculative-execution flaw that leaks sensitive data through cache side channels — a reminder that the chip underneath your hypervisor has opinions of its own.
- Rakesh Seal unveiled a zero-day TLS covert channel that smuggles data out by permuting handshake parameters, walking past several leading firewalls with no anomalous footprint — IEEE award-winning work disclosed to CISA, GSMA and more than a hundred vendors.
- Maor Abutbul of CyberArk Labs weaponized QUIC’s multiplexing for race conditions and fuzzing with QuicDraw, while Gurjot Singh, Vipin Venu and Arjun V of Innspark exposed a Bluetooth flaw that lets any nearby attacker issue commands to unprotected smartwatches — no pairing, no authentication, nothing.
- Rounding it out: Kamalpreet Khurana of Adobe on a live SOAP XXE zero-day still haunting “legacy” systems in 2026, Priyanshu Sharma of MIT Pune on a repeatable five-step driver-vulnerability pipeline, Eviatar Gerzi of CyberArk on impersonating workloads inside SPIFFE/SPIRE, and Ashish Kataria of Synacor on how modern sanitization pipelines manage to invent fresh XSS bugs while trying to prevent them.
Every one of these started the same way: someone refused to trust a thing the rest of us assume just works.
The Defense
The harder half is catching all of that — and the closing track was about building systems that can spot something they’ve never seen before.
- Rajesh Kumar Natarajan and Srinivasan Govindarajan combined Volatility 3 with retrieval-augmented generation to make memory forensics less of a black art, enriching artifacts with threat intelligence to speed up detection.
- Sudhanshu Dasgupta and Sahil Bansal of SafeDep took apart the Shai-Hulud npm worm and walked through the static-and-dynamic detection architecture that caught it — open-source tools you can deploy now.
- Chandrashekar Chettiar, Aditya Khullar, Abhishek Bansal and Sujit Nair reconciled AI’s bottomless appetite for data with zero trust and DPDPA through a Lean Cloud approach: less data hoarded, fewer places to lose it.
- And Urvish Acharya, Uday Deshpande, Kedar Telavane and Sriranga Narasimha mapped how third- and fourth-party dependencies quietly cascade into your own risk, and where AI-driven automation actually moves the needle.
Detection in 2026 isn’t about the signatures you already have. It’s about recognizing the thing you’ve never seen — which, this year, is most things.
Get Every Session — and Every ISMG Event
These sessions are just the beginning. Nullcon is now part of the ISMG family, which means its research lands in the same on-demand home as the rest of the network: Security Insights by CyberEd.io gives you the entire ISMG events experience — virtual and in person — in one library, with global event replays, expert-led masterclasses, and CPE credits on demand, featuring the CISOs, regulators, and researchers defining the field. The scale speaks for itself — 400 events annually, 75,000+ attendees, 500 expert speakers, and 1,000+ sessions.
And the math is hard to argue with. A single conference can run into the thousands once you add flights, hotels, and tickets — plus the days away from your team. Security Insights delivers all of it for just $495 a year, on your schedule, without leaving your desk.
▶ Stop choosing which event to attend. Get them all.
Subscribe to Security Insights by CyberEd.io →