
Jhury Kevin Lastre
The New Attack Surface: Emerging Threats at the Apex of Cybersecurity
AppSec Professionals EXchange
APEX, the AppSec Professionals EXchange, brings the regional security community together for sharp technical talks and the kind of hallway conversations that move careers forward. One room, one running order, and 9 talks.
Organised by OWASP Cebu, APEX is community-run and vendor-neutral. No marketing keynotes, no fluff: just practitioners sharing what actually works, from threat modeling to exploit development to defending production at scale.
Whether you write the code, break it, or defend it in production, APEX meets you where you work.
Engineers who want to write code that holds up under real attack and understand the threats before they reach production.
Practitioners building guardrails, pipelines, and detection while scaling security across fast-moving engineering orgs.
Pentesters, AppSec leads, and researchers driving security programs, reviews, and offensive testing.
Our first speakers are confirmed, with more announced in the lead-up to the event.

The New Attack Surface: Emerging Threats at the Apex of Cybersecurity

Trust Nothing on the Air: Rogue Base Station Attacks Against Cellular Networks

Observations and learnings with Cloud-LLM-Augmented AppSec activities

Can We Trust a Stranger’s .deb? Secure Peer-to-Peer Package Distribution with Debswarm

How Sign in with Google Works: A Deep Dive into OAuth

Make the Silicon Confess: A hands-on intro to side-channel and fault-injection attacks
Automotive Pentest for Appsec Professionals
TBA — talk to be announced

Testing the Waters: Assessing Chipset Compatibility for Cross-Firmware Flashing

TBA — talk to be announced
Doors at 9:30 AM, closing at 5:40 PM. The day opens with the keynote and builds through the afternoon into a hardware and wireless finale.
A keynote that frames the day. As computing moves to post-quantum cryptography, AI-driven pipelines, software-defined radios, and connected vehicles, the attack surface stops being a perimeter and becomes everything. Jhury connects the threads running through APEX 2026 - crypto agility and post-quantum readiness, AI-augmented AppSec, the cellular edge, software supply chains, side-channel and fault-injection attacks on silicon, and automotive systems - into a single map of where cybersecurity is heading and what defenders should prepare for next.
// Timing is confirmed; minor slot adjustments may be published closer to the event.
APEX runs as a single session. Every talk happens in the same room, in one running order, so nobody has to choose what to miss and the whole audience shares the same reference points by lunchtime. That is what makes the breaks worth showing up for.
// 125 minutes of the day left unprogrammed, on purpose
Doors open half an hour before the opening remarks. Coffee, badges, and the first conversations of the day.
A full hour in the middle of the day, once the keynote and the morning talks have given everyone something to argue about.
Twenty minutes to reset, stretch, and find the speaker you wanted to corner.
The day ends together: prizes, CTF results, and the last chance to swap contacts before everyone heads out.
APEX is community-run and made possible by supporters who invest in the regional security ecosystem.

Reach developers, engineers, and security leaders. Tiered packages available now.
W. Geonzon Street, Cebu IT Park
Apas, Cebu City, 6000
Cebu, Philippines
// Cebu IT Park, Apas — map data © OpenStreetMap contributors
Follow three beginner-friendly web clues, decode the final transmission, and unlock a temporary APEX registration code.
Beginner · About 5–10 minutes
No exploits and no specialist tools. You only need a browser, curiosity, and the willingness to inspect what a web page sends you.
// First hint: developers often inspect what the browser receives.Join the developers, engineers, and security professionals reaching the peak of application security for one day in Cebu. Passes start at PHP 300.