Wednesday, September 23, 2026 · Porto, Portugal · That's a wrap
AppSec Days Portugal opened with a full day of hands-on security training. Four expert-led workshops ran in parallel across two time slots, covering offensive techniques, defensive strategies, and secure development practices. Each session was four hours of focused, practical learning.
Deep-dive into the OWASP Top 10 for LLMs with hands-on labs covering Prompt Injection, Sensitive Data Disclosure, Excessive Agency, Improper Output Handling, and RAG Poisoning.
Master the art of anticipating threats before attackers do. Hands-on STRIDE and PASTA exercises, storytelling-based delivery, and practical tools you can apply the moment you leave the room.
Hack the world's most beginner-friendly vulnerable app, then go behind the scenes to see how it's built, tested, and maintained as an open source project. Led by the creator himself.
From BLE protocol fundamentals to real-world attacks - sniffing, GATT enumeration, replay attacks, MitM, and downgrade exploits. Get hands-on with the tools used by professional IoT security researchers.
Real-world Android and iOS security flaws from years of pentesting. Vulnerability chains, mobile API attacks, XSS, SQLi, RCE - all with case studies from real engagements. All action, no fluff.
Design and launch a Security Champions Program that actually sticks. Covers motivation theory, personality types, gamification, OKRs, and a practical exercise where you build your own program.
The workshops have run, but we are glad to hear from you about the next edition.
Contact the Team