APEXby OWASP Cebu
← Back to speakers
APEX Speaker

Jay Turla

Principal Security Researcher, VicOne

Talk

Automotive Pentest for Appsec Professionals

Automotive ·Hardware ·Advanced

Security Research

  • Principal Security Researcher, VicOne
  • Main research focus on car hacking and automotive security
  • Speaker at ROOTCON, HITCON, Nullcon, and DEFCON

Community Leadership

  • One of the goons of ROOTCON
  • Lead organizer, Car Hacking Village of ROOTCON, Philippines
  • Advocate for automotive security research in the region

Competition

  • Leader of the hacking team Peenoise
  • Top team at the SPIRITCYBER Hackathon in Singapore
  • Competes in IoT, ICS, and OT hacking challenges

Jay Turla is a Principal Security Researcher at VicOne and one of the goons of ROOTCON. He has presented at international conferences including ROOTCON, HITCON, Nullcon, and DEFCON, with his main research focused on car hacking and the security of modern automotive systems.

He is currently one of the main organizers of the Car Hacking Village of ROOTCON in the Philippines. Jay also leads the hacking team Peenoise, one of the top teams during the SPIRITCYBER Hackathon, an IoT, ICS, and OT hacking competition in Singapore.

At APEX, Jay presents a structured automotive penetration testing approach aimed at AppSec professionals who want to move from hacking web apps and internal networks into hacking vehicles and their protocols. Instead of covering TARA, his session combines systematic attack-surface discovery, fuzzing, hardware reverse engineering, and wireless security evaluation into a sound methodology for finding critical weaknesses in automotive systems.

The talk also explores how AI-assisted tooling can support automotive penetration testers by automating parts of the testing workflow, improving fuzzing strategies, and accelerating vulnerability discovery. Jay walks through common techniques such as CAN Bus firehose attacks and dumping the MCU firmware, then shows how to leverage those findings further.