Recon 2026

The AI Reversing Panel: Are we all powerful, or out of a job?
19/06/2026 , Grand Salon Opera
Langue: English

It’s not every day we convene a panel at Recon.
AI affects us all, but where can we go beyond buzzwords and make it concrete?
- What actually works, how we set up our own harnesses, what constantly fails, and what works today that didn’t even a month ago? Are there limits?
- How the technology affects us daily, from attackers to defenders? We see software development sped up to the max, models finding vulnerabilities autonomously, malware being dissected by AI, and written even faster.
- Topics such as disclosure, when vulnerability in code == public, and if coordinated disclosure can survive it. Is full disclosure back?
- And lastly… are we still going to have a job in a year or two? Will there still be a need for researchers? Let’s be specific.
We will welcome surprise guests to the panel, as we cycle through topics. The topics themselves are discussion seeds only.

John McIntosh (@clearbluejar) is a security researcher at ClearSecLabs specializing in reverse engineering and offensive security. His expertise spans binary analysis, patch diffing, and vulnerability discovery, with multiple open-source security tools for vulnerability research available on his GitHub. His website, https://clearbluejar.github.io/, features detailed write-ups on reversing recent CVEs and building RE tooling with Ghidra.

John has delivered advanced reverse engineering and vulnerability discovery talks at leading international security conferences worldwide, including Black Hat, REcon, Insomnihack, Ringzer0, SecTor, 44CON, and DEF CON. His sessions emphasize systematic, reproducible workflows and hands-on, AI-augmented analysis, consistently recognized for clarity and technical depth. A distinguished presenter and educator, John maintains a fervent commitment to sharing cutting-edge research, advancing binary analysis, and fostering collaboration within the global security community.

Autre(s) intervention(s) de l'orateur :

Founder and CEO at Knostic, CISO-in-Residence for AI, Cloud Security Alliance.

Gadi Evron is Founder and CEO at Knostic, an AI agent security company, CISO-in-Residence for AI at CSA, and chairs the [un]prompted conference. Previously, he founded Cymmetria (acquired), was the Israeli National Digital Authority CISO, founded the Israeli CERT, and headed PwC's Cyber Security Center of Excellence. He wrote the post-mortem analysis of the "First Internet War" (Estonia 2007), founded some of the first information-sharing groups (TH-Research, 1997, DA/MWP, 2004), wrote APT reports (Rocket Kitten - 2014, Patchwork - 2016), and the first paper on DNS DDoS Amplification Attacks (2006). Gadi has written two books on cybersecurity, is a frequent contributor to industry publications, and speaker at industry events, from Black Hat (2008, 2015) to Davos (2019) and CISO360 (2022).

Marion Marschalek is an independent security consultant and trainer with her consulting company Hack & Cheese. Prior to that she held senior positions at AWS and Intel, and different roles in the threat detection industry, as a malware reverse engineer and incident responder. Marschalek is a frequent speaker at major security conferences, including Black Hat, Defcon, HITB, RSA, and SyScan, among others. She used to teach reverse engineering classes at University of Applied Sciences St. Poelten, from where she graduated in 2011 with a Master’s Degree in Information Security. In 2015 she started a hacker bootcamp for women titled BlackHoodie, which over the years established itself as a global initiative to attract more diverse talent to the security industry. In her spare time she enjoys long distance running.

Aaron Portnoy is Chief Product Officer at Mindgard and the inaugural Hacker Fellow at Dartmouth College, applying over twenty years of offensive research to AI security. He created the Pwn2Own hacking competition, organizing and judging its first six iterations while running research at TippingPoint's Zero Day Initiative, and went on to co-found Exodus Intelligence, one of the first firms to commercialize zero-day research. Over his career he has personally discovered hundreds of zero-day vulnerabilities in software from vendors including OpenAI, Cursor, NVIDIA, Microsoft, Google, Amazon, Palo Alto Networks, and Adobe; authored the award-winning IDA Toolbag; and published research in Phrack. He has led offensive programs at Raytheon and Boldend and pioneered attack surface management research at Randori through its IBM acquisition. His current research focuses on the security of AI systems. Featured in TIME Magazine's 2014 cover story "World War Zero," Aaron has delivered over thirty invited talks at venues including Black Hat, REcon, CanSecWest, EkoParty, USENIX WOOT, BlueHat, RSA, and the NSA Distinguished Speaker Series.