APEXby OWASP Cebu
OWASP Cebu presentsCebu · 17.10.2026

APEX

AppSec Professionals EXchange

Reach the peak of application security.

Date
Sat · Oct 17, 2026
City
Cebu, Philippines
Venue
iAcademy Cebu IT Park
Format
One day · Single session
RegisterSubmit a talk// passes from PHP 300 · the CFP is open too.
01 — About

A one-day conference for the people who build, break, and defend software.

APEX, the AppSec Professionals EXchange, brings the regional security community together for sharp technical talks and the kind of hallway conversations that move careers forward. One room, one running order, and 9 talks.

Organised by OWASP Cebu, APEX is community-run and vendor-neutral. No marketing keynotes, no fluff: just practitioners sharing what actually works, from threat modeling to exploit development to defending production at scale.

Inaugural year
2025
Seats
120
Sessions in one day
9
02 — Who should attend

Built for everyone who ships secure software.

Whether you write the code, break it, or defend it in production, APEX meets you where you work.

Developers

Engineers who want to write code that holds up under real attack and understand the threats before they reach production.

  • Secure-by-default patterns & libraries
  • Threat modeling in the SDLC
  • Fixing the OWASP Top 10 at the source

Security Engineers

Practitioners building guardrails, pipelines, and detection while scaling security across fast-moving engineering orgs.

  • Shift-left tooling that developers adopt
  • Cloud & supply-chain hardening
  • Detection, response & purple teaming

AppSec Professionals

Pentesters, AppSec leads, and researchers driving security programs, reviews, and offensive testing.

  • Modern exploitation techniques
  • Program strategy & risk communication
  • Bug bounty & vulnerability research
03 — Speakers

Practitioners at the summit of their craft.

Our first speakers are confirmed, with more announced in the lead-up to the event.

Jhury Kevin Lastre
Keynote

Jhury Kevin Lastre

Lead, OWASP Cebu

The New Attack Surface: Emerging Threats at the Apex of Cybersecurity

Emerging Trends ·Post-Quantum ·All Levels
View bio
Vincent Abella

Vincent Abella

Security Researcher, MobiSec Lab, Kookmin University

Trust Nothing on the Air: Rogue Base Station Attacks Against Cellular Networks

Wireless / Cellular ·Advanced
View bio
Ron Michael Diokno Khu

Ron Michael Diokno Khu

Software Architect and Tech Community Advocate

Observations and learnings with Cloud-LLM-Augmented AppSec activities

AI Security ·Intermediate
View bio
Clint Christopher Cañada

Clint Christopher Cañada

Linux Systems Engineer and Cybersecurity Speaker

Can We Trust a Stranger’s .deb? Secure Peer-to-Peer Package Distribution with Debswarm

Supply Chain ·Intermediate
View bio
Bryan Sanchez

Bryan Sanchez

AI Researcher, Anycase.ai

How Sign in with Google Works: A Deep Dive into OAuth

Identity & AppSec ·Beginner
View bio
Sean Aguilar

Sean Aguilar

Software Engineer, TaxMaverick AI

Make the Silicon Confess: A hands-on intro to side-channel and fault-injection attacks

Hardware ·Intermediate
View bio

Jay Turla

Principal Security Researcher, VicOne

Automotive Pentest for Appsec Professionals

Automotive ·Hardware ·Advanced
View bio
Lightning

Jasper Marbella

Student Security Researcher and CTF Competitor

TBA — talk to be announced

CTF & Bug Bounty ·Beginner
Raymond Olavides

Raymond Olavides

Vice Department Manager, Fullspeed Technologies

Testing the Waters: Assessing Chipset Compatibility for Cross-Firmware Flashing

Hardware ·Firmware ·Beginner
View bio
Marisa M. Buctuanon

Marisa M. Buctuanon

Engineering Manager at Full Scale

TBA — talk to be announced

AI ·
View bio
// Want this stage?Submit a talkCFP closes Aug 15, 2026
04 — Program flow

One room. One day. Nine sessions.

Doors at 9:30 AM, closing at 5:40 PM. The day opens with the keynote and builds through the afternoon into a hardware and wireless finale.

// Take the full schedule with you
9:30 — 10:00
Registration & Badge Pickup
10:00 — 10:15
Opening Remarks — OWASP Cebu
10:15 — 11:00
Keynote

The New Attack Surface: Emerging Threats at the Apex of Cybersecurity

Jhury Kevin Lastre · Lead, OWASP Cebu

A keynote that frames the day. As computing moves to post-quantum cryptography, AI-driven pipelines, software-defined radios, and connected vehicles, the attack surface stops being a perimeter and becomes everything. Jhury connects the threads running through APEX 2026 - crypto agility and post-quantum readiness, AI-augmented AppSec, the cellular edge, software supply chains, side-channel and fault-injection attacks on silicon, and automotive systems - into a single map of where cybersecurity is heading and what defenders should prepare for next.

Emerging Trends ·Post-Quantum ·All Levels
11:00 — 11:40

How Sign in with Google Works: A Deep Dive into OAuth

Bryan Sanchez · AI Researcher, Anycase.ai
Identity & AppSec ·Beginner
11:40 — 12:20

Observations and learnings with Cloud-LLM-Augmented AppSec activities

Ron Michael Diokno Khu · Software Architect and Tech Community Advocate
AI Security ·Intermediate
12:20 — 1:20
Lunch
1:20 — 1:35
Lightning

Talk to be announced

Jasper Marbella · Student Security Researcher and CTF Competitor
CTF & Bug Bounty ·Beginner
1:35 — 2:25

Automotive Pentest for Appsec Professionals

Jay Turla · Principal Security Researcher, VicOne
Automotive ·Hardware ·Advanced
2:25 — 3:05

Testing the Waters: Assessing Chipset Compatibility for Cross-Firmware Flashing

Raymond Olavides · Vice Department Manager, Fullspeed Technologies
Hardware ·Firmware ·Beginner
3:05 — 3:45

Can We Trust a Stranger’s .deb? Secure Peer-to-Peer Package Distribution with Debswarm

Clint Christopher Cañada · Linux Systems Engineer and Cybersecurity Speaker
Supply Chain ·Intermediate
3:45 — 4:05
Coffee Break
4:05 — 4:45

Make the Silicon Confess: A hands-on intro to side-channel and fault-injection attacks

Sean Aguilar · Software Engineer, TaxMaverick AI
Hardware ·Intermediate
4:45 — 5:25

Trust Nothing on the Air: Rogue Base Station Attacks Against Cellular Networks

Vincent Abella · Security Researcher, MobiSec Lab, Kookmin University
Wireless / Cellular ·Advanced
5:25 — 5:40
Closing, Raffle & CTF Awards

// Timing is confirmed; minor slot adjustments may be published closer to the event.

Merchandise / sizing

Regular-fit shirt size guide

Measurements are in inches. Open the image for a closer look before choosing your size.

Regular-fit T-shirt size chart in inches. Width: XS 18, S 19, M 20, L 21, XL 22, 2XL 23, 3XL 24. Length: XS 24.5, S 25.5, M 26.5, L 27.5, XL 28.5, 2XL 29, 3XL 30.

Tap the chart to view it full size.

The Sudo and Root passes include event merchandise. You can select your shirt size when you register.

05 — Networking

Everyone in one room, all day.

APEX runs as a single session. Every talk happens in the same room, in one running order, so nobody has to choose what to miss and the whole audience shares the same reference points by lunchtime. That is what makes the breaks worth showing up for.

// 125 minutes of the day left unprogrammed, on purpose

9:30 AM30 min

Registration & Badge Pickup

Doors open half an hour before the opening remarks. Coffee, badges, and the first conversations of the day.

12:20 PM60 min

Lunch

A full hour in the middle of the day, once the keynote and the morning talks have given everyone something to argue about.

3:45 PM20 min

Coffee Break

Twenty minutes to reset, stretch, and find the speaker you wanted to corner.

5:25 PM15 min

Closing, Raffle & CTF Awards

The day ends together: prizes, CTF results, and the last chance to swap contacts before everyone heads out.

06 — Sponsors

Backed by the people who care about secure software.

APEX is community-run and made possible by supporters who invest in the regional security ecosystem.

International partner
MobiSec Lab
MobiSec LabKookmin University, Seoul

Put your brand on the climb.

Reach developers, engineers, and security leaders. Tiered packages available now.

Become a sponsor
07 — Venue

In the heart of Cebu IT Park.

iAcademy Cebu

W. Geonzon Street, Cebu IT Park
Apas, Cebu City, 6000
Cebu, Philippines

Getting there
10 minutes from Ayala Center Cebu; ride-share and ample parking nearby.
Accessibility
Step-free access, elevators to all session floors, and a quiet room on site.
Stay
Several hotels within walking distance of the IT Park.
Get directions

// Cebu IT Park, Apas — map data © OpenStreetMap contributors

08 — Challenge

Find the hidden coupon.

Follow three beginner-friendly web clues, decode the final transmission, and unlock a temporary APEX registration code.

Beginner · About 5–10 minutes

No exploits and no specialist tools. You only need a browser, curiosity, and the willingness to inspect what a web page sends you.

// First hint: developers often inspect what the browser receives.
Start the hunt
Registration is open

Secure your seat at the summit.

Join the developers, engineers, and security professionals reaching the peak of application security for one day in Cebu. Passes start at PHP 300.

RegisterSubmit a talk

// Shell Access · PHP 300