
⚡️ Security Talks + Networking — Hunting TDS & Agentic Vulnerability Management
About the event
Two talks. Two speakers. Two very different sides of the same problem — how attackers pick their targets, and how defenders pick what to fix. And a proper amount of time to talk to each other: a full hour of networking before the talks, and the rest of the evening after. The talks are the excuse; the room is the point.
This month we're partnering with [Allianz Technology](https://tech.allianz.com/en.html?utm_source=luma), who are opening the doors of their Barcelona offices to host us. 🙌
We're also going deeper instead of wider: 20 minutes per speaker, plus a real Q&A after each. Bring questions. Whether you hunt threats, run security operations, build the pipelines, or sign off the budget — there's something here for you.
🎙️ The Lineup 1️⃣ Individual research on Traffic Distribution Systems (TDS): associated campaigns and YARA rules for detection By [Mar Garcia Sabaté](https://www.linkedin.com/in/mar-garcia-sabat%C3%A9-901b3bb1/?utm_source=luma) (Threat Intelligence Lead @ Allianz Technology) Before a victim ever sees a payload, a TDS has already decided who they are and whether they're worth the trouble — filtering by geography, device, and whether you look like a researcher. Original research into the campaigns built on this infrastructure, and the YARA rules you can take home to detect them.
2️⃣ Nobody Reads 40,000 Vulnerability Findings By [Gerardo Prieto](https://www.linkedin.com/in/gerardo-prieto/?utm_source=luma) (CISO) Handing the backlog to a chain of AI agents — and knowing when to stop and ask a human. Detection was never the bottleneck. Triage, ownership, chasing and retesting are. This session walks through an agentic pipeline that takes a finding — whether it came from a cloud scanner, a SAST tool, an endpoint agent or a pentest report — all the way to a verified fix. Contextual severity scoring, one agent independently checking another's work, and the hard part: knowing when the automation is confident and when a human still has to decide.
🤝 Organized by [Barcelona CyberSec](https://barcelonacybersec.com/?utm_source=luma), hosted by [Allianz Technology](https://tech.allianz.com/en.html?utm_source=luma)
📍 Venue: Central Barcelona. This is a hosted corporate space, so attendance is by approval and the exact address is sent once you're approved. Please bring photo ID — the guest list is checked at reception.
🎟️ Entry: Free. Registration and approval required.
⏳ Approvals go out on a rolling basis, so request early — capacity is limited by the venue.
🕒 Agenda (⚠️ Heads up: talks start strictly on time!)
• 6:00 PM → Doors, check-in & networking • 7:00 PM – 7:25 PM → Traffic Distribution Systems (with Mar) • 7:25 PM – 7:50 PM → Nobody Reads 40,000 Vulnerability Findings (with Gerardo) • 7:50 PM onwards → Networking & drinks 🥤 🍻
Come at six. That first hour is where most of the good conversations happen, and it's the reason people keep coming back. See you there! [https://barcelonacybersec.com](https://barcelonacybersec.com/?utm_source=luma)




