OWASP New Zealand Day 2026

Open Web Application Security Project (OWASP) New Zealand held their 2026 conference over two days, September 3 & 4 2026, at the Owen G Glenn Building. Here’s what I found.

Day 1

Introduction by John DiLeo a stalwart of the NZ application security community in Auckland. OWASP cheat sheets. ASVS.

Talk 1 by Karan Bansal https://karanbansal.in – Using hooks in Claude to secure it. Top hooks for security purposes – 1. PreToolUse 2. ConfigChange https://github.com/karanb192/claude-code-hooks

Talk 3 by Sam Pickles – Log4Shell chaos – Agents reducing time to exploit – SBOM > scan pipeline. Enrol in AI provider’s security program, or consistently getting flagged will get you banned. Soft and hard controls on agents. Defenders advantage. Monitor changes in source, many vulnerabilities are patched without a CVE.

Talk 4 by Denis Andzakovic – fuzzing pentesting research – input based attacks. Gitlab leak = over-posting two email addresses password reset email sent to the second email. Look for weird, avoid vulnerability trivia. Pearson correlation. Webfuzzy.

Talk 5 by SecuritySteve.nz – one page worksheet for collaborating with business owners – threat modelling. NZSIS, NZISS.

Talk 6 by Kirk Jackson – Cartography – Neo4J graph database – providers for cloud AWS Azure GCP.

Talk 7 by Max Francis – DICOM standard – HL7 medical data. Weasis vulnerability fixed now. CVE in review.

Day 2

Talk 2 by SecuritySteve.nz – periodic or annual reviews are static snapshots – link risk to owners and mitigations

Talk 4 by Ricky Gummadi from Microsoft – Agentic Governance Toolkit – OWASP AI Top 10 – at app layer 4

Talk 5 by Matthew Dekker – security.txt – Vulnerability Disclosure Protocol – contact + bounty + safe harbour