SecAppDev

@secappdev.org

SecAppDev is an immersive week-long course in secure application development. In-depth lectures and hands-on workshops take you on a deep-dive in today's security best practices. More info on https://secappdev.org

SecAppDev 2026 is a wrap. 18 experts, 20 sessions, 4 workshops, five days of deep-diving into application security in Leuven, Belgium. SecAppDev 2027 is already on the calendar: June 7–11. Subscribe for updates at secappdev.org.

Bild

Thank you to every speaker and participant who made SecAppDev 2026 genuinely special. The feedback we received has been wonderful. SecAppDev 2027 is June 7–11 in Leuven, Belgium. Subscribe for updates: secappdev.org

Bild

Final day of #SecAppDev 2026. Two workshops to close: attacking and defending LLMs hands-on, and practical web application security through the lens of real-world CVEs. A strong end to a strong week.

Bild

Midweek at #SecAppDev: real breaches through a secure-by-design lens, adversarial ML, EU CRA compliance, XS-Leaks, privacy attacks on deep learning, and Inti De Ceukelaire on what happens when you actually read the RFCs. Then a BBQ workshop to wrap the evening.

Day 2 of #SecAppDev covers AI agent security, SBOMs and supply-chain risk, MCP security, ASVS v5, the ongoing crypto wars, and dark patterns in the age of AI. Two tracks running in parallel - hard choices ahead.

Bild

Yesterday, #SecAppDev kicked off with @Freddy Dezeure on security by default and European cyber resilience, @Bart Preneel on post-quantum cryptography, and @Philippe De Ryck on the updated security model of the web, as well as OAuth 2.1 best practices and AI memory as an attack surface.

Bild

New speaker confirmed for #SecAppDev 2026 → Tom Van Goethem will give an advanced lecture on XS-Leaks: how attackers use browser side-channels to leak sensitive data without breaking the same-origin policy, and what you can do about it. Leuven, Belgium. June 1–5 → secappdev.org

Bild

SecAppDev 2026 faculty: Freddy Dezeure on Security by Default, how Microsoft maps NIS2, DORA & CRA to real engineering controls at cloud scale. Deep-dive session. June 1–5, Leuven, Belgium. SecAppDev 2026 - Freddy Dezeure #AppSec #SecAppDev

Bild

SecAppDev 2026 session: AI Memory, Mapped by Natalie Isak. AI memory is not just RAG, it’s a persistent attack surface. Covers risks like prompt injection exfiltration, delayed tool use, psychosocial impacts, plus memory threat modeling, observability, and more. secappdev.org/2026/session...

Bild