| Hackstories from the field | |
| Moderator :: Ms. Dana Ludviga | |
| 11:30 - 12:00 |
Inside the Cyberattack and Recovery of Latvian State Forests,
Mr. Māris Kuzmins (Latvian State Forests, LV),
TBC (CERT.LV, LV)
TBC
|
| 12:00 - 12:30 |
TBC,
TBC
TBC
|
| 12:30 - 13:00 |
Hacked Anyway: What Recent Incidents Really Teach Us,
Ms. Nadia Meichtry, (Oneconsult AG, CH)
Over the past years, I have responded to numerous security incidents across a wide range of industries, from ransomware attacks and exploited vulnerabilities to insider threats.
Although every incident is different, the same patterns and challenges appear again and again.
In this talk, I'll share the main lessons we can learn from these cases, looking beyond the technical details of the attacks.
Attendees will leave with a clearer understanding of where organizations struggle during incidents and what can make the difference when it matters most.
|
Agenda
Information about the CTF and the workshops on October 13 will follow soon.
14 OCT
| OMEGA HALL | |
|---|---|
| 08:00 - 09:00 | Registration and morning coffee
|
| 09:00 - 11:00 | OPENING PLENARY |
| Moderators :: Ms. Dana Ludviga & Mr. Kārlis Svilans | |
| 09:00 - 09:15 | Opening remarks, TBC |
| 09:15 - 09:25 | Opening remarks, Ms. Baiba Kaškina (CERT.LV, LV) |
| 09:25 - 09:55 |
TBC,
TBC
TBC
|
| 09:55 - 10:20 |
Navigating a Changing Cyber Landscape: Why the Global Mechanism and UN Framework Matter,
Ms. Helen Popp (Ministry of Foreign Affairs of Estonia, EE)
The keynote will look at why the UN Framework for Responsible State Behaviour and the Global Mechanism matter for building a more stable and secure cyberspace. It will share Estonia’s perspective on the importance of turning agreed principles into practical action, strengthening cooperation, and building trust among all actors. It will also reflect on how the Global Mechanism can help us keep pace with a rapidly changing cyber environment and emerging challenges.
|
| 10:20 - 10:55 |
Who you gonna call?,
Mr. Varis Teivāns (CERT.LV, LV)
TBC
|
| 10:55 - 11:00 | Moderator Remarks |
| 11:00 - 11:30 |
Coffee break
|
| HACKING | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 11:30 - 12:00 |
So, you want to write malware?,
Mr. Jaanus Kääp (ShellDot, EE)
So, you want to write malware for a cyber exercise or red-team operation (hopefully, the sentence ends there and does not continue with “for several unrelated personal reasons”).
We wanted to do the same, and for nearly three years we have been developing offensive tooling for professional red teams, security testing, and realistic cyber exercises. During that time, we have discovered that building legitimate “malware” involves considerably more than creating a payload, opening a listener, and hoping endpoint security products remain politely unaware of what is happening.
In this fast paced talk, I will explore both the technical and less technical realities of developing this unusual category of software. We will examine architectural decisions, payload design, execution methods, communication channels, modularity, and the challenges of supporting different operating systems and environments.
The talk will also cover practical problems such as payload generation, configuration, command execution and adapting techniques when previously reliable approaches become detectable. Because nothing in offensive security remains reliable for long.
Along the way, I will share lessons learned from several years of developing and maintaining offensive tooling, including decisions that worked well, ideas that worked considerably less well, and features that appeared simple until implementation proved otherwise.
The goal is to offer an honest look at what it takes to build, test, maintain, and responsibly deliver realistic offensive tooling.
|
| 12:00 - 13:00 |
[TLP: AMBER]
"Ain't my fault" will get you uncovered,
Mr. Lorenzo Nicolodi (iCounter, IT)
One thing I learned about hackers is that they like anonymity. And that they don't take things for granted.
Sure, some technologies help. To a point. But if you are serious about online anonymity while conducting operations, relying on a single solution is a very bad idea. As Rick Prado said: "In combat, two is one and one is none."
I will do my best to show you how VPN, Tor and I2P work, when each of them is the right solution and why the always cool kid stating "I am a haxx0r, I run my 3 VPS, each in a different country" just proved he really doesn't understand how things work in reality.
I will try hard also to show you what your lab should look like, at a minimum, to guarantee you some confidence that nobody is going to knock on your door. At least for a while.
|
| Opening | |
| Moderator :: Ms. Katrina Sataki | |
| 11:30 - 11:35 | Opening remarks, Ms. Katrina Sataki (.LV Registry, LV) |
| 11:35 - 11:50 |
Trends and insights from the European ccTLD market,
Mr. Patrick Myles (CENTR, EU)
A look at the latest statistics and trends from the local and wider European domain name market.
|
| 11:50 - 12:20 |
One Internet. Three Registries. Many Opportunities - Part I
Moderator :: Ms. Katrina Sataki (.LV Registry, LV) Panelists: Mr. Heiki Sibul (Estonian Internet Foundation, EE), Mr. Tomas Mackus (DOMREG, LT)
TBC
|
| 12:20 - 13:00 |
One Internet. More Registries. More opportunities - Part II
Moderator :: Ms. Katrina Sataki, (.LV Registry, LV) Panelists: Heiki Sibul (Estonian Internet Foundation, EE), Mr. Tomas Mackus (DOMREG, LT), Ms. Barbara Povše (Register .si, Arnes, SI), Mr. Roelof Meijer (.nl, SIDN, NL)
TBC
|
| 13:00 - 14:00 |
Lunch
|
| CyberCrisis | |
| Moderator :: Ms. Dana Ludviga | |
| 14:00 - 14:30 |
CyberEurope exercise,
TBC
TBC
|
| 14:30 - 15:30 |
Chain reaction: Cybercrisis management in a connected world
Moderator :: Mr. Sébastien Garnault (Paris Cyber Summit, FR) Panelists: TBC (ANSI, LU), TBC (TBC), MGen. Dave R. Yarker (CAN CAF, CA), Dr. Friederike Zedler (NATO, DE)
In today's hyperconnected environment, a cyberattack rarely affects just one organization or nation. A single compromised vendor, cloud provider, software update, or critical infrastructure component can trigger a chain reaction with far-reaching business, operational, financial, and reputational consequences. This panel will examine how organizations can strengthen resilience, improve crisis response, and coordinate effectively across national borders, partners, regulators, and stakeholders during high-impact cyber incidents.
Among these, the discussion will examine international experiences of cybersecurity crisis management mechanisms and their role in enabling and supporting coordinated action during significant cyber incidents. It will explore how these mechanisms are tested and strengthened globally through regular exercises, such as Cyber Europe 2026, which help to assess preparedness, coordination, and resilience across Member States and relevant stakeholders.
Cybersecurity experts will share lessons learned from real-world cyber crises, discuss emerging threats, and explore strategies for preparation, communication, decision-making, and recovery.
|
| Artificial Intelligence | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 14:00 - 15:00 |
Attacker pattern matching with ML,
Mr. Patrik Hammersborg (NSM, NO)
TBC
|
| 15:00 - 15:30 |
Deepfake detection,
Mr. Jānis Grīslis (Verifix, LV)
TBC
|
| 15:30 - 16:00 |
Coffee break
|
| Cyber Deterrence | |
| Moderator :: Ms. Dana Ludviga | |
| 16:00 - 16:30 |
[TLP: AMBER]
Deterring the Aggressors: Towards a Framework for Cyber Attribution,
Mr. Dāvis Baumanis, (Ministry of Foreign Affairs of Latvia, LV),
Mr. Arturs Ivanovs, (Ministry of Foreign Affairs of Latvia, LV)
Cyber threats are at an all-time high – from state sponsored cyberattacks, to proxy cyber-threat actors or pro-state hacktivists. Cyber defences and resilience are daily front lines for security of our information systems whose purpose is to deny cyber-threat actors’ openings for cyber-attacks. By reducing the anonymity and sense of impunity of cyber threat actors and creating consequences for their actions, we deter cyber-attacks and add an additional layer for our cyber security.
A structured framework for cyber attribution provides such a layer, as it exposes malicious actors and imposes reputational and diplomatic costs that signal unacceptable actions will not be tolerated and aim to deter future cyber-attacks. Collective attribution adds greatly to the deterrent effect. However, in order to pursue collective action, states require robust national systems in place to organize, implement and assess attribution.
In this segment, we will share Latvia’s experience of how we developed our framework for cyber attribution - from case-by-case early attempts at joint attribution and trial and error coordination efforts nationally to a more focused regulatory framework. We will also highlight observed differences between cyber attribution and sanctions but also how they are interlinked and mutually reinforcing.
|
| 16:30 - 17:00 |
[TLP: AMBER]
Deep dive into ecosystem of Residential Proxies: Companies, Platforms and Abuse,
TBC
TBC
|
| 17:00 - 17:30 |
[TLP: AMBER]
Cyber Fraud as a Service: Behind the Criminal Infrastructure,
Mr. Elvijs Bogdanovs (Europol, NL),
Mr. Oļegs Filatovs (State Police of the Republic of Latvia, LV)
The presentation will provide an overview of current cyber-enabled fraud trends, with a particular focus on how criminal services and infrastructure support fraud at scale.
It will begin with selected statistics and practical examples from Latvia and the broader international context, including business email compromise, fraudulent calls and messages, and other forms of cyber-enabled fraud. Particular attention will be given to the infrastructure behind these offences, including SIM-box operations and phishing-as-a-service platforms, as well as the way such services are advertised and offered to criminal users.
Two international law enforcement operations - Tycoon 2FA and SIMCARTEL - will be presented as practical case studies. These examples will demonstrate how criminal service providers can support large-scale phishing, fraudulent communications and other forms of online fraud across multiple jurisdictions.
Selected visual materials and operational video footage will be used to show how these services work, how they are disrupted, and why international cooperation is important in tackling cross-border cyber fraud.
|
| Threathunting | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 16:00 - 16:30 |
Discovering the Unseen: Accelerating Threat Hunting with AI,
Mr. Ernesto Fernández Provecho, (Trellix Advanced Research Center, ES)
As threat actors increasingly develop capabilities to bypass traditional security perimeters, the burden on SOC teams to manually sift through massive datasets has become unsustainable. This presentation introduces a modernized, proactive threat hunting methodology that combines endpoint and email telemetry with the analytical power of Artificial Intelligence (AI) to accelerate threat discovery from the initial steps to its final stages. Everything described in a way that can be reproduced by attendees in their environments.
The first half of the session establishes the practical foundations of our hunting strategy. We will highlight the necessity of creating a customer baseline to identify outliers and establishing a clear scope to avoid inefficient analysis. Moreover, we will explore how we leverage our intelligence to define the hunting hypotheses and the queries we will later use. This section also breaks down the nuances of alert-less anomaly analysis versus prioritizing alert-based hunting within the "gray zone" of newly discovered attacker techniques.
Moving from foundational theory to advanced application, we will then detail our AI-powered hunting framework, including an explanation of the process we used to teach our AI agent how to filter, discard, and understand the signs to find the most urgent campaigns in both email and endpoint telemetry. Then, we will showcase its capabilities through a demonstration, including examples of actual detections and the reasoning the AI has made to select them. This culminates in a deep-dive technical analysis of a real-world campaign discovered by the AI agent.
|
| 16:30 - 17:30 |
Sliding into the Enemy's DMs: Detecting SaaS-Backed Malware C2,
Mr. Patrick Staubmann (VMRay, DE)
Threat actors increasingly "live off the SaaS land" by abusing well-known collaboration and gaming platforms as covert command-and-control (C2) channels. This talk presents findings from ongoing research into e-crime malware families that use services such as Telegram, Discord, Steam, and others for C2, exfiltration, and dead-drop resolution. By leveraging a malware sandbox with full visibility into decrypted TLS traffic, we analyze how these families structure their communications, including API usage, message formats, embedded configuration data, and the delivery of second-stage payloads via legitimate services. From these patterns, we derive network-level fingerprints and YARA rules for plaintext traffic that enable robust detection, hunting, and clustering of related malware families. Finally, we discuss the role of abused SaaS applications and why legitimate domains should not be dismissed too quickly during malware analysis or incident response engagements.
|
| Is There Life Outside the Baltic Domain Space? | |
| Moderator :: Ms. Katrina Sataki | |
| 16:00 - 16:15 |
Who governs the internet?,
Mr. Jānis Kārkliņš (ICANN)
TBC
|
| 16:15 - 16:30 |
The New gTLD Program: 2026 Round updates and what is next?,
Ms. Aysegul Tekce (ICANN, TR)
The New gTLD Program: 2026 Round. Where we stand with the program and what is next in the 2026 round.
|
| 16:30 - 17:00 |
Protecting Intellectual Property in the DNS: New Trends,
Ms. Charlotte Spencer (WIPO, CH)
WIPO's recent service developments to combat cybersquatting: Emerging trends, use of AI, WIPO’s new case services (i.e., Expedited Case Processing and Early Termination), the Legal Rights Objection and String Confusion Objection for the next round of ICANN's new gTLD program, as well as the WIPO Overview 3.1. In addition, brief overview of the WIPO's ccTLD Program, including experience with .LV domain name disputes.
|
| 17:00 - 17:30 |
The "World-wide Web" of Regulations
Moderator :: Ms. Barbara Povše, (Register .si, Arnes, SI) Panelists: Mr. Jānis Kārkliņš (ICANN, LV), Ms. Charlotte Spencer (WIPO, CH), Ms. Iveta Skujiņa (.LV Registry, LV), Ms. Helen Aaremäe-Saar (Estonian Internet Foundation, EE), Mr. Tomas Mackus (DOMREG, LT)
TBC
|
| 17:30 - 21:30 | Social event (all participants) |
15 OCT
| OMEGA HALL | |
|---|---|
| 08:00 - 09:00 | Registration and morning cofee
|
| 09:00 - 11:00 | OPENING PLENARY |
| Moderators :: Ms. Dana Ludviga & Mr. Kārlis Svilans | |
| 09:00 - 09:10 | Opening remarks, Mr. Rolands Heniņš (NCSC, LV) |
| 09:10 - 09:30 |
Keynote,
MGen. Dave R. Yarker (CAN CAF, CA)
TBC
|
| 09:30 - 09:55 |
Exploring the changing European cybersecurity landscape,
Mr. Sébastien Garnault (Paris Cyber Summit, FR)
Europe’s cybersecurity landscape is entering a new phase. Cybersecurity is no longer simply a technical issue or a matter of regulation. It has become a question of power, sovereignty and national security.
Europe is facing several challenges at the same time. Russia represents an immediate and persistent threat. China raises a different, longer-term challenge around technological, industrial and economic power. And AI is accelerating everything, changing both offensive and defensive capabilities faster than our institutions can adapt.
In this context, European digital sovereignty cannot simply be about where data is stored or which rules apply. Sovereignty is ultimately the capacity to decide and act. That requires technology, industrial capabilities, resilient infrastructure, secure supply chains and the ability to protect our strategic interests.
But greater European sovereignty does not necessarily mean greater distance from the United States. Europe needs to strengthen its own capabilities while recognising that our security, technology and defence interests remain deeply interconnected across the Atlantic.
The challenge is to understand where Europe needs greater autonomy, where dependencies can be accepted, and where cooperation remains essential. This requires a much more pragmatic conversation about sovereignty, security and power.
Europe does not need to choose between sovereignty and alliances. It needs the capabilities that allow it to choose at all.
|
| 9:55 - 10:20 |
Compliance Is Not a Survival Strategy,
Mr. Patrik Fältström (NETNOD AB, SE)
Imagine an organization that complies with every cybersecurity requirement - and still cannot deliver its essential services.
How is that possible?
This presentation explores the difference between compliance and survival, why the distinction matters more than ever, and how critical infrastructure operators should think about resilience in an increasingly uncertain geopolitical environment.
|
| 10:20 - 10:55 |
Inside a celebrity cyber scam investigation: deepfakes & mind games,
Ms. Kerry Tomlinson (Ampyx News, US)
What tools and tricks are criminals using to carry out celebrity imposter fraud? Go undercover with a cyber journalist to see how a real case plays out, with the attacker deploying audio, video and image deepfakes, as well as potent social engineering techniques. See why this kind of cyber fraud is so powerful, stealing billions from victims each year, and the best strategies for defense. Plus, this session will look at undercover cyber investigation techniques, both technological and psychological.
|
| 10:55 - 11:00 | Notes from the moderators |
| 11:00 - 11:30 |
Coffee break
|
| Artificial Intelligence | |
| Moderator :: Ms. Dana Ludviga | |
| 11:30 - 12:00 |
Frontier AI,
Mr. Jesper Olsen (PaloAlto Networks, US)
TBC
|
| 12:00 - 12:30 |
TBC,
TBC
TBC
|
| 12:30 - 13:00 |
AI usage in CTI,
R.Wortmann (TrendAI)
TBC
|
| Cyber Threat Intelligence | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 11:30 - 12:30 |
How to hack a bank,
Mr. Thomas Tom Freer (Opswat, UK)
What would it take to walk into a bank, get behind the teller line, and walk out with a computer — without a weapon, without a plan, and without anyone stopping you?
Security awareness specialist Jayson E. Street did exactly that. In two minutes and twenty seconds he was behind the teller line of a Beirut bank he'd never visited, touching every machine in the branch. He stayed for thirty minutes. The manager showed up and started helping him.
Then he tried it again. And things didn't go quite to plan.
|
| 12:30 - 13:00 |
Cyberdeception in OT envrionments,
Mr. Cezary Zielinski (Fortinet, LT)
TBC
|
| A Safer and More Resilient Baltic Domain Space | |
| Moderator :: Ms. Katrina Sataki | |
| 11:30 - 12:00 |
Does NIS2 make ccTLDs more secure and resilient?,
Mr. Patrik Fältström (NETNOD AB, SE)
TBC
|
| 12:00 - 13:00 |
Verify at any cost: security solution or compliance illusion?
Moderator :: Ms. Katrina Sataki (.LV Registry, LV) Panelists: Ms. Iveta Skujiņa (.LV Registry, LV), Dr. Monika Nowikowska (.pl, NASK, PL), Mr. Timo Võhmar (Estonian Internet Foundation, EE), Mr. Tomas Simonaitis (DOMREG, LT)
Verifying domain registrant data in the context of the NIS 2 Directive is one of the key elements in strengthening the security and resilience of the DNS infrastructure. In practice, the biggest challenge is striking a balance between effective data verification and maintaining a simple and fast domain registration process. Problems arise especially with foreign customers and the automated registration of large numbers of domains. From a legal perspective, the main challenge is reconciling the requirements of NIS 2 with data protection regulations, particularly the GDPR.
|
| 13:00 - 14:00 |
Lunch
|
| Offensive operations | |
| Moderator :: Ms. Dana Ludviga | |
| 14:00 - 14:30 |
[TLP: AMBER]
Global Offensive Security Ops - what can go wrong?,
Mr. Piotr Borkowski (Cyber Arms, PL)
Piotr in his speech will talk about real case studies from operations done all over the world (Asia, Europe, Middle East, Africa) with some insights on how to do it properly and how to avoid mistakes. He will also deliver how to make Global Campaign targeting 5+ targets at once located in different part of the world. Some taste of physical Red Team operations will be included :)
|
| 14:30 - 15:00 |
Local offensive operations,
TBC (Tet, LV)
TBC
|
| 15:00 - 15:30 |
Agentic Intelligence: From Feeds to Decisions: Agentic AI and the Intelligence Cycle,
Dr. Daniel Gillblad (Recorded Future, SE)
The intelligence cycle has always been started by a person. Someone asks a question, an analyst tasks collection, and the work moves stage by stage until a report comes out. Attackers no longer work on that timescale. Agentic tooling lets them scan, adapt, and act without waiting for a human to decide what happens next. A defence that still begins with someone thinking to ask a question is running too slow.
Agentic AI breaks that dependency for defenders as well. When collection and processing can be delegated to machines, the cycle no longer waits: a new piece of infrastructure, a leaked credential, a shift in an actor's tooling triggers the analytical work directly. The output isn't a feed item, it's finished intelligence, already correlated and contextualised against your environment.
We will talk about what this looks like in practice: how agents perform analytical work, where they fail, and what changes about the job when the machine does the legwork. What happens when the scarce resource stops being capacity and starts being judgment?
|
| Operational Technology | |
| Moderator :: Dr. Bernhards `BB` Blumbergs | |
| 14:00 - 14:30 |
Autonomous systems to support UAV warfare, and how to attack,
Mr. Simon-Pierre Deschênes (Tessellate, CA)
Autonomous systems rely on the continuous interaction between perception, planning, and control to understand their environment and execute missions safely. This presentation will first explain how modern robotic platforms build and leverage a Shared 3D World, transforming sensor data into a common representation used for localization, mapping, decision-making, and autonomous navigation. We will then explore how cyber attacks can target these systems by manipulating sensors, communications, software, or data, potentially degrading performance or compromising mission outcomes. Finally, in collaboration with Vendel, we will discuss modern approaches to securing autonomous systems, including resilient architectures, trusted software, secure communications, anomaly detection, and cybersecurity-by-design practices. Together, these elements are essential to ensuring that next-generation autonomous platforms remain reliable, trustworthy, and operational in demanding real-world environments.
|
| 14:30 - 15:30 |
Testing cyber-physical systems,
Mr. Colin Stéphenne (Vendel, CA)
TBC
|
| Closing | |
| Moderator :: Ms. Katrina Sataki | |
| 14:00 - 14:20 |
See it. Share it. Stop it,
Mr. Jakob Bring Truelsen (Punktum dk, DK)
Punktum dk actively monitors the misuse of .dk domain names and notifies registrants and hosting providers whenever misuse is detected. This has led to a reduction in abuse, supporting Punktum dk’s goal of making .dk one of the safest domains on the internet.
During the talk, the methodology and results will be presented.
|
| 14:20 - 14:50 |
What will "trusted" mean in 2030?
Moderator :: Mr. Helmuts Meškonis (TBC) Panelists: Mr. Roelof Meijer (.nl, SIDN, NL), Dr. Monika Nowikowska (.pl, NASK, PL), Mr. Andriy Khvetkevych (NicNames.com & NIC.UA, UA)
TBC
|
| 14:50 - 15:20 |
Closing discussion: What's the next move?
Moderator :: Mr. Lars Forsberg, (iQ, SE) Panelists: Ms. Katrina Sataki, (.LV Registry, LV), Heiki Sibul, (Estonian Internet Foundation, EE), Mr. Tomas Mackus (DOMREG, LT),
For the closing panel of Baltic Domain Days, the leaders of Estonia’s, Latvia’s, and Lithuania’s country-code top-level domain registries come together to discuss what lies ahead for the Baltic domain-name industry.
Drawing on the themes, challenges, and ideas explored throughout the conference, the panel will reflect on how the internet landscape is changing and what those changes may mean for registries, registrars, domain holders, and the wider digital community.
What should the Baltic registries prepare for next? Where can they collaborate, and where might their paths diverge? And after two days of discussion, what is the next move?
The conversation will be moderated by Lars “LG” Forsberg, founder of Nordic Domain Days and CTO of iQ.
|
| 15:20 - 15:30 | Cosing speach, Ms. Katrina Sataki (.LV Registry, LV) |
| 15:30 - 16:00 |
Coffee break
|
| Moderators :: Ms. Dana Ludviga & Mr. Kārlis Svilans | |
| 16:00 - 16:20 |
72-hour readiness for a random blackout,
Mārtiņš Kaļķis (LMT, LV)
TBC
|
| 16:20 - 16:50 |
Physical insider threat identification and mitigation,
Mr. Clarke Jarrett (AHNA Group, UK)
TBC
|
| 16:50 - 17:20 |
How to Win Locked Shields (and Survive the Preparation)
Moderator :: Br. Bernhards 'BB' Blumbergs (CERT.LV, LV) Panelists: TBC (TET, LV), Mr. Ēriks Dobelis (TBC, LV)
TBC
|
| 17:20 - 17:30 | CTF Recap & Awards Ceremony |
| 17:30 - 17:40 | Closing speach, Ms. Baiba Kaškina, (CERT.LV, LV) |
| 17:40 - 17:45 | Closing speach by Moderators, Ms. Dana Ludviga & Mr. Kārlis Svilans & Dr. Bernhards 'BB' Blumbergs, (CERT.LV, LV) |
| 17:45 | Musical Treat |