Almaty Hub: How to Find Vulnerabilities When the Scanner Finds Nothing
Your product can pass an automated security check - and still remain vulnerable.
A single overlooked flaw can lead to data leaks, unauthorized access to user accounts, financial losses, or loss of customer trust.
At the new Speaker Talk at Almaty Hub, we’ll explore how to look at your product through an attacker’s eyes and identify vulnerabilities before someone else does.
We’ll discuss why automated scanners don’t catch everything and how to uncover weaknesses hidden deeper in product logic, authorization, APIs, and unconventional attack scenarios.
Speaker - Nurlan Bazarbekov, CISO at Globerce Capital, independent security researcher, and the #1 bug hunter on the Tumar.One platform. Throughout his security research practice, he has discovered vulnerabilities in systems of NASA, Yandex, Toyota Europe, and Dynatrace.
Through practical cases, we’ll explore:
- how to build hypotheses and identify unconventional attack scenarios;
- how to detect authorization issues, IDOR vulnerabilities, and weaknesses in business logic and APIs;
- how to identify SSRF, XSS, and race conditions;
- how a seemingly minor vulnerability can develop into a serious attack chain;
- how to assess the real-world risk to a product and its users.
The session will be useful for developers, CTOs, security professionals, and tech teams looking to build more secure products.
📅 September 10
🕔 16:00
📍 Almaty Hub, 24 Zenkov St., 4th floor, Event Hall
Note: To attend the event, please download the Astana Hub app and register in advance.
Follow for more events:
Instagram: Almaty_hub
Telegram: Almaty Hub