Press Relase / News Release Distribution Service [@Press]

Note: This page is a machine translation of the Japanese original and is provided for reference only.
In the event of any discrepancy between this page and the original, the original shall prevail. Click here for the original text.

CODE BLUE 2026: Japan's Premier Cybersecurity Conference Outlines Defense Strategies for the Frontier AI Era with ENISA's Christian Van Heurck as Keynote Speaker

~Timetable for Key Sessions Now Available~

CODE BLUE Executive Committee


The CODE BLUE Executive Committee is pleased to announce that Christian Van Heurck from the European Union Agency for Cybersecurity (ENISA) will serve as a keynote speaker for the international cybersecurity conference "CODE BLUE 2026" (Trainings: November 11–15; Conference: November 17–18; Location: Shinjuku-ku, Tokyo).


CODE BLUE 2026

CODE BLUE 2026


■ Keynote: Cybersecurity and Capacity Building in the Frontier AI Era

Christian Van Heurck, who will serve as the keynote speaker, is the Deputy Head of the Capacity Building Unit at the European Union Agency for Cybersecurity (ENISA). Previously, he served as the coordinator for CERT.be, Belgium’s national CSIRT, where he was engaged in incident response and international cooperation[4][6]. At ENISA, he has spearheaded key capacity-building initiatives, including the large-scale cyber exercise "Cyber Europe".

In contemporary cybersecurity, the evolution of frontier AI has driven a structural shift in which vulnerability discovery and exploitation are increasingly automated, causing attack and defense dynamics to unfold at "machine speed". As the window between vulnerability discovery and weaponization shrinks, defenders face massive influxes of vulnerability reports and automated attacks[4]. This creates a critical challenge in the speed gap relative to traditional human approval and decision-making processes.

In this keynote, Mr. Van Heurck will present cyber defense strategies for the AI era, focusing on ENISA's role within the European Commission's AI Action Plan as well as his core expertise in "Capacity Building" and "Preparedness". Specifically, he will address the impact of AI on the European Cybersecurity Skills Framework (ECSF), large-scale exercises like "Cyber Europe," awareness-raising, cyber hygiene, and organization-wide skill development. Furthermore, the presentation will highlight the vital role of the human community—how in-person gatherings like CODE BLUE enable cybersecurity professionals to listen, learn, challenge one another, and solve complex problems together.


●Speaker Biography

Christian Van Heurck is the Deputy Head of the Capacity Building Unit at the European Union Agency for Cybersecurity (ENISA). Previously, he served as the coordinator for CERT.be, Belgium’s national CSIRT, where he was engaged in incident response and international cooperation. At ENISA, he has led key capacity-building initiatives and large-scale cyber exercises, including "Cyber Europe." In recent years, he has been actively focusing on cybersecurity responses in the frontier AI era.



■ Highlights of the CODE BLUE 2026 Schedule

[Day 1: November 17]


Both the Main Venue (Track 1) and the Bluebox Venue (Track 3) will feature an intensive lineup of presentations focusing on cutting-edge AI offensive and defensive security topics.


● Vulnerability Research on AI Agents and AI

Processors A series of presentations will explore exploits targeting the specifications of state-of-the-art AI technologies. Highlights include "Agent2Shell" (a Pwn2Own prize-winning attack on AI coding agents), analysis of Google Pixel’s AI coprocessor, "ChatMate" (an escape attack targeting AI assistants), and "PleaseFix" (a complete compromise of next-generation agentic browsers).


● AI Infrastructure, Defense, and Operational Automation

An impressive slate of advanced technical sessions will cover real-world attacks on GPU data centers (bare-metal infrastructure), the latest threat intelligence on adversarial AI, quality assurance in Incident Response (IR) for the AI era, and privilege-side exploits in Chromium.


● Autonomous AI Defense Tools (Bluebox) 

Open-source AI defense projects will gather at the Bluebox venue, showcasing tools such as "Antigent," designed to counter autonomous AI attacks, and "AgentShield," developed to contain rogue AI within the Linux kernel.


[Day 2, November 18]


The perspective broadens to encompass geopolitical risks, nation-state-sponsored espionage, low-level attacks, critical infrastructure defense, space governance, and ubiquitous consumer applications.


● OS/Low-Level & Consumer ApplicationThreats

In addition to "Shade Core"—a UEFI attack targeting hypervisor-protected PCs—the OpenTalks venue (Track 2) will feature presentations on a wormable RCE in "LINE" (a messaging app with a dominant market share in Japan) and an analysis of Firefox's internal request paths.


● Nation-State APTs and the Reality of Cyber Espionage

Real-world threat intelligence will be presented, covering topics such as "Operation ShadowCommit" (a covert operation on GitHub), surveillance activities by Iranian APTs targeting domestic citizens, and "Salt Typhoon," which leverages infrastructure around Japan as an attack launchpad.


● Critical Infrastructure Defense, International Governance, and Policy

Sessions will delve into topics with major societal and policy impacts, ranging from physical-cyber penetration testing on large-scale industrial plants and defense against jamming in urban IoT, to critical infrastructure protection under hybrid threats based on cases in Ukraine and beyond, as well as private-sector norm-setting in outer space ("Code is Law").



■Schedule

[Day 1: November 17]

Start Time Presentation Title (Speaker)


● Main (Track 1)


09:00 Cybersecurity and Capacity Building in the Frontier AI Era (tentative)

(Christian Van Hoek)

10:10 [Won $20,000 at Pwn2Own Berlin 2026] Agent2Shell: Your AI Coding Agent Is Already Executing an Attacker’s Code

(Tomoki Tsuji)

11:00 AI vs. AI: AI-Assisted Research on a Privilege Escalation Bug in the Google Pixel’s AI Coprocessor

(Yuhan Wu)

11:50 ChatMate: Remote Prompt Execution on AI Assistants via Sandbox Escape

(Ori Lahav)

1:40 p.m. The Evolution of Adversarial AI: Stories from the Front Lines of Threat Intelligence

(Daniel Kapelman-Zafr)

2:30 p.m. “PleaseFix”: A Complete Guide to Agent-Based Browsers—A New Class of Vulnerabilities Enabling Zero-Click Takeovers

(Stav Cohen / Michael Bergley)

3:30 p.m. Quality Assurance for Incident Response in the Age of AI

(Hidemasa Asanaga / Yuki Yano)

4:20 PM “In Origin We Trust”: Exploiting Chromium from the Privileged Side

(Orange Tsai)

5:10 PM Pass-the-Device: Transferring “Trust” in SASE/VPN After an Endpoint Compromise

(Ruslan Saifiev)

6:00 PM Too Close to the Metal: Attacks on GPU NeoCloud from Inside and Outside

(Michael Kaczynski / Yakir Kadkoda)



●Bluebox (Track 3)


12:00Antigent: An Autonomous Counter-Agent Against Agentic AI Attacker

(Hiroaki Toyota)

13:00One Harness, Three Security Agents: Recursive Language Models in Practice(Syue Siang Su)

14:00Turncoat: From Coding Agent to C2 Agent

(Michael Telloyan)

15:00vwhois: A Practical WHOIS Parser Conquering the Wilderness of All TLDs

(Hiroki Hada) 

16:00Static Analysis for AI Applications: From Taint Tracking to Exploit Generation

(Alisha Gupta)

17:00AgentShield: Stopping a Rogue AI Agent in the Linux Kernel

(Weixiao JI, Qingzhe Jiang, Leandro Li)



[Day 2, November 18]

● Main(Track 1)

9:00Shade Core: Bringing UEFI Attacks Back to Hypervisor-Protected Modern PCs

(Kazuki Matsuo)

9:50TBA(TBA)

10:40Five Years of GitHub Monitoring: Unveiling the Lifecycle of Malicious and For-Sale PoCs

(Ryosuke Yoshimura)

11:30Operation ShadowCommit - Hidden Ops on Github

(Jun Hyeong Lee, Daehoo Lee)

13:20From the Rebellious Cities: How Iranian APTs spy on their own people

(Eliad Kimhy, Subhajeet Singha)

14:10The Code IS the Law: Private Norm-Making in the Cybersecurity Governance of Outer Space

(Joanna Kulesza)

15:00Salt Typhoon's Shadow: Japan and the Staging Grounds Next Door

(Christopher Braccia)

15:50Physical Intrusion of Major Plants and Business Risk Assessment using CPSF: Countering Hybrid Physical-Cyber Attacks

(Daisuke Ota)

16:40When the Spectrum Becomes the Battlefield: Defending Municipal IoT Under Jamming

(Pavlo Chernikov)

17:30Defending Critical National Infrastructure in a Hybrid Threat Landscape

(Ivan Kalabashkin)


●OpenTalks(Track 2)

9:00[U25]No Context, No Consent: A Systematic Analysis of LNA Bypasses in Firefox’s Internal Request Paths

(Rintaro Kawasugi)

9:50[U25]Out of LINE:QR Code to Wormable RCE in LINE Client

(Flydragon)


*Please note that presentations are subject to change or cancellation due to various circumstances. Additionally, the Japanese titles of presentations and the names of speakers are provisional and subject to change.



■CODE BLUE 2026 Event Overview

[Training]

Date and Time: November 11 (Wed) – November 15 (Sun), 2026

Venue: Bellesalle Shinjuku Grand Conference Center

    (5th Floor, Sumitomo Realty Shinjuku Grand Tower)


*Dates and participation fees vary by training session. Please check the official website for details.

(Japanese) https://codeblue.jp/program/trainings/

(English) https://codeblue.jp/en/program/trainings/


[Conference]

Date and Time: Tuesday, November 17, 2026 – Wednesday, November 18, 2026

Venue: Bellesalle Takadanobaba

     (Sumitomo Realty Shinjuku Garden Tower B2 & 1F)

Languages: Simultaneous interpretation in Japanese and English (except for some presentations)

Format: In-person event

Participation Fee:

1. Conference Ticket

(Includes access to all areas, participation in the networking party, and early access to archived videos)

Regular: 98,000 yen (tax included): June 1 (Mon) – November 10 (Tue)

On-site: 128,000 yen (tax included): Tuesday, November 17 – Wednesday, November 18 (purchased at the venue on the day of the event)

2. Visitor Ticket

(Restricted access to certain areas; does not include participation in the networking party; no early access to archived videos)

Regular: 28,000 yen (tax included): June 1 (Mon) – November 10 (Tue)

On-site: 32,000 yen (tax included): November 17 (Tue) – November 18 (Wed) at the venue


Pre-registration:

Please register via the “Registration” page on the official website.

(Japanese) https://codeblue.jp/registration/

(English) https://codeblue.jp/en/registration/

(For the press) https://codeblue.jp/press-registration/


Website: https://codeblue.jp/

Social Media: [X (formerly Twitter)] https://x.com/codeblue_jp

       [Facebook] https://facebook.com/codeblue.jp

       [LinkedIn] https://www.linkedin.com/company/codeblue-jp


Organizer: CODE BLUE Executive Committee

Organized by: CODE BLUE Secretariat (Zesuroku Co., Ltd.)



■ Sponsorship Opportunities

We are currently seeking corporate sponsors for CODE BLUE 2026. We will send you a sponsorship brochure, so please feel free to contact us.


[CODE BLUE Sponsor Inquiry Form]

https://forms.gle/e1QJ6WTjBLVf9ycg8




Image

Logo Image