CODE BLUE 2026, Japan's Largest Cybersecurity Conference, Announces 27 Accepted Talks from CFP
— From Wormable RCE Targeting LINE to Compromising AI-Dedicated GPU Data Centers and Cyber Governance in Outer Space —
CODE BLUE Executive Committee
The CODE BLUE Executive Committee has announced the 27 accepted talks selected from the CFP for the international cybersecurity conference "CODE BLUE 2026" (Training: November 11–15, Conference: November 17–18, held in Shinjuku, Tokyo). Keynote sessions and the official timetable will be announced as soon as they are finalized.

CODE BLUE 2026
■ All-Time High! Over 640 Submissions from Japan and Around the Globe
This year’s CFP received a record-breaking 640+ submissions from both domestic and international researchers, marking an all-time high for the conference. This historic surge is driven by the rapid proliferation and evolution of AI, which has created unprecedented new attack surfaces, including autonomous AI agents, GPU data centers, and dedicated processing chips. Security challenges surrounding AI technologies have captured intense interest from researchers and cybersecurity professionals worldwide. The unprecedented volume of CFP submissions for CODE BLUE 2026 directly reflects this growing global urgency to investigate AI-related threats, establish robust defense mechanisms, and navigate this historic paradigm shift in the cybersecurity landscape.
■ Key Highlights of the CODE BLUE 2026 Program
●Security of the AI Ecosystem (Infrastructure, Agents, and Chips)
With the explosive expansion of AI infrastructure, this year's program comprehensively addresses the security threats of the AI era. Sessions will delve into security challenges in GPU data centers, risk vectors associated with autonomous AI agent specifications, and physical-layer vulnerabilities in dedicated AI processors embedded in smartphones.
●The Security Boundaries of Infrastructure and Consumer Devices
Technical deep dives will expose critical vulnerabilities inherent in products vital to daily life and economic activities. Presenters will deliver detailed technical analyses of security flaws found in widely used messaging services like "LINE," as well as mainstream web browsers such as Firefox.
●Analysis of State-Sponsored Threats (APTs) and Cyber Espionage Speakers will reveal real-world case studies of geopolitically charged, state-sponsored threats. This includes in-depth coverage of threat actors operating primarily in East Asia, as well as cyber operations targeting civil movements in Iran.
●The Intersection of Technology, Governance, and International Law
Presentations will address critical issues arising at the intersection of technological advancement and national policy. Key presentations will explore the challenges of establishing international governance frameworks for mega-constellations (such as Starlink) operating in outer space.
■ Accepted Talks (27 Sessions): Titles & Speakers
●Technical
・In Origin We Trust: Breaking Chromium from Its Privileged Side(Orange Tsai)
・Shade Core: Bringing UEFI Attacks Back to Hypervisor-Protected Modern PCs(Kazuki Matsuo)
・TBD(Yuhang Wu)
・AI vs. AI: AI-Assisted Research into a Privilege Escalation Bug in the Google Pixel AI Coprocessor(Yu Poh Kang )
・ [Pwn2Own Berlin 2026 $20,000] Agent2Shell: Your AI Coding Agent Already Ran the Attacker's Code(Satoki Tsuji)
・Pass-the-Device: Transplanting SASE/VPN Trust After Endpoint Compromise(Ruslan Sayfiev)
・ChatMate: Remote Prompt Execution on AI Assistants through Sandbox Escaping(Ori Lahav)
・Too Close to the Metal: Attacking GPU Neo-Clouds from the Inside and Out(Michael Katchinskiy / Yakir Kadkoda)
・Five Years of GitHub Monitoring: Unveiling the Lifecycle of Malicious and For-Sale PoCs(Ryosuke Yoshimura)
●General
・Physical Intrusion of Major Plants and Business Risk Assessment using CPSF: Countering Hybrid Physical-Cyber Attacks(Daisuke Ota)
・Quality Assurance for Incident Response in the AI Era(Shusei Tomonaga / Yuki Yano)
・When the Spectrum Becomes the Battlefield: Defending Municipal IoT Under Jamming(Pavlo Chernikov)
・Echoes of Ransomware: Uncovering a Cyber Blast Radius(Ivan Kalabashkin)
・Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class for 0-Click Takeover(Stav Cohen / Michael Bargury)
・The Evolution of Adversarial AI: Tales from the Frontlines of Threat Intelligence(Daniel Kapellmann Zafra)
●Counter Cyber Crime
・From the Rebellious Cities: How Iranian APTs spy on their own people(Eliad Kimhy)
・Operation ShadowCommit - Hidden Ops on Github(Jun Hyeong Lee / Daehoo Lee)
●Law and Policy
・Salt Typhoon's Shadow: Japan and the Staging Grounds Next Door(Christopher Braccia)
・The Code IS the Law: Private Norm-Making in the Cybersecurity Governance of Outer Space(Joanna Kulesza)
●U25(Youth Track)
・No Context, No Consent: A Systematic Analysis of LNA Bypasses in Firefox’s Internal Request Paths(Rintaro Kawasugi)
・Out of LINE: QR Code to Wormable RCE in LINE Client(Flydragon)
●Bluebox(Showcasing Open Source Tools and Projects)
・Antigent: An Autonomous Counter-Agent Against Agentic AI Attacker(Hiroaki Toyota)
・Turncoat: From Coding Agent to C2 Agent(Michael Telloyan)
・vwhois: A Practical WHOIS Parser Conquering the Wilderness of All TLDs(Daiki Hada)
・Static Analysis for AI Applications: From Taint Tracking to Exploit Generation(Alisha Gupta)
・One Harness, Three Security Agents: Recursive Language Models in Practice(Syue Siang Su)
・AgentShield: Stopping a Rogue AI Agent in the Linux Kernel(Weixiao JI / Qingzhe Jiang)
*Please note that presentations are subject to change or cancellation due to unforeseen circumstances. Additionally, the Japanese translations of presentation titles and speaker names are provisional and subject to change.
■CODE BLUE 2026 Event Overview
[Training]
Date: November 11 (Wed) – November 15 (Sun), 2026
Venue: Bellesalle Shinjuku Grand Conference Center
(5th Floor, Sumitomo Realty Shinjuku Grand Tower)
*Dates and participation fees vary by training session. Please check the official website for details.
(Japanese) https://codeblue.jp/program/trainings/
(English) https://codeblue.jp/en/program/trainings/
[Conference]
Date and Time: Tuesday, November 17, 2026 – Wednesday, November 18, 2026
Venue: Bellesalle Takadanobaba
(Sumitomo Realty Shinjuku Garden Tower, B2 & 1F)
Languages: Simultaneous interpretation in Japanese and English (except for some presentations)
Format: In-person event
Participation Fee:
1. Conference Ticket
(Includes access to all areas, participation in the networking party, and early access to archived videos)
Regular Price: 98,000 yen (tax included): June 1 (Mon) – November 10 (Tue)
On-site: 128,000 yen (tax included): Tuesday, November 17 – Wednesday, November 18 (purchased at the venue on the day of the event)
2. Visitor Ticket
(Restricted access to certain areas; does not include participation in the networking party; does not include early access to archived videos)
Regular: 28,000 yen (tax included): June 1 (Mon) – November 10 (Tue)
On-site: 32,000 yen (tax included): Tuesday, November 17 – Wednesday, November 18, at the venue
Pre-registration: Please register via the “Registration” page on the official website.
(Japanese) https://codeblue.jp/registration/
(English) https://codeblue.jp/en/registration/
(For the press) https://codeblue.jp/press-registration/
Website: https://codeblue.jp/
Social Media: [X (formerly Twitter)] https://x.com/codeblue_jp
[Facebook] https://facebook.com/codeblue.jp
[LinkedIn] https://www.linkedin.com/company/codeblue-jp
Organizer: CODE BLUE Executive Committee
Organized by: CODE BLUE Secretariat (Zesuroku Co., Ltd.)
■ Sponsorship Opportunities
CODE BLUE 2026 is currently seeking corporate sponsors. We will send you a sponsorship brochure, so please feel free to contact us.
[CODE BLUE Sponsor Inquiry Form]