Date: June 22, 2026 Event: Black Hat India 2026 Format: Podcast (~32 minutes) Guests: Vandana Verma Sehgal, Shubham Mittal, Sudhanshu Chauhan, Anant Shrivastava
Overview
Launch episode for Black Hat India’s first-ever edition. Members of the Briefings Review Board β Vandana Verma Sehgal, Shubham Mittal, Sudhanshu Chauhan, and Anant Shrivastava β discuss what this milestone means for the Indian security community and the global InfoSec stage, and what it takes to bring world-class security research out of India.
Key Topics
What Black Hat India is and why it matters
The state of security research in India β where it thrives and where the gaps are
Why OT, hardware, and IoT research needs more investment and access
Tracks the Review Board is most excited to see β from fraud and FinTech to internet scanning and cloud security
Why critical infrastructure like UPI and India’s payments ecosystem will shape the conversation
What the Review Board is looking for in an outstanding Briefings proposal
A direct message to researchers across India who think their work isn’t ready for a stage like this
AI Generated Summary
AI Generated Content Disclaimer
Note: This summary is AI-generated and may contain inaccuracies, errors, or omissions. If you spot any issues, please contact the site owner for corrections. Errors or omissions are unintended.
A ~32-minute launch podcast for the first-ever Black Hat India β coming to Bangalore on October 27, 2026 β brings together four members of the event’s Briefings Review Board: Anant Shrivastava (founder, Cyfinoid Research), Vandana Verma Sehgal (Snyk), and Redundant Labs co-founders Sudhanshu Chauhan and Shubham Mittal. The host introduces the board as “the people who will read every submission, debate every talk and ultimately decide what lands on stage in Black Hat Bangalore,” holding the India edition to the same standard as any Black Hat worldwide. The conversation covers why Black Hat chose India now, what the board looks for in a Briefings proposal, where Indian security research thrives and where it is held back, and which tracks β from fraud and FinTech to AI, supply chain, and OT β the board most wants to see. It closes with a direct appeal to first-time researchers who doubt their work is ready for a global stage.
Summary
Black Hat has gathered the security community in Las Vegas, London and Singapore for decades; this October it lands in Bangalore, marking the first time the Briefings experience comes to South Asia. The board members use the episode to coach prospective speakers: novelty above all, responsible disclosure of fixed vulnerabilities, detailed and honest submissions, vendor neutrality, and proof that the research actually works. They also map India’s research landscape β world-class application and mobile security talent, but hardware, IoT and OT work constrained by cost and access β and debate how AI is reshaping both the submissions they receive and the topics they want staged. The episode ends with the host’s message to an unknown researcher in a tier-2 city: the call for papers is open, this board will read it, and “this is where it starts.”
The Panel
Anant Shrivastava β about 18 years in technology (started as a server admin, roughly 15 in information security); founder of Cyfinoid Research, focused on cutting-edge work including supply chain security and AI. His one-word hope for the event: “more exciting research β it’s not one word, but more exciting research.”
Vandana Verma Sehgal β around 19 years in cybersecurity, currently at Snyk; already serves on the review boards for Black Hat Asia, Europe and US. One word: “deep technical.”
Sudhanshu Chauhan β more than a decade in offensive security; co-founder of Redundant Labs (attack surface management); interests span web application security, recon, OSINT and AI; a long Black Hat history as an Arsenal presenter, trainer, and review-board member across regions; co-runs Recon Village at DEF CON. One word: “community.”
Shubham Mittal β around 15 years in security, from pentesting to “both sides of the firewall”; co-founder of Redundant Labs; runs Recon Village at DEF CON with Sudhanshu and the Indian Hackers Club (“hacking beyond terminals”). One word: “cool hacks” β plus, he admits, plenty of networking.
Why India, Why Now
A prestige venue within reach: Anant notes that presenting at flagship events like DEF CON and Black Hat has long been “a prestige point” and a researcher’s dream, but the events were always “far away from India β either in Singapore or in London, Amsterdam, USA,” out of reach for a large portion of the community.
Stage plus access: bringing the event home gives Indian researchers a reachable stage and gives attendees direct access to those researchers. Anant emphasizes the “unconference that happens within every conference” β hallway conversations and community areas β as the real payoff of concentrating talent in one place.
What Briefings provide globally: Sudhanshu credits Black Hat with surfacing cutting-edge research that has “gone through a whole detailed process of review,” and with building a community where “they can meet people and then meet them next year and show them what they did last year.”
What Makes a Winning Briefings Proposal
Novelty first: Shubham β the paper “should be novel. It should not be available easily in the market.” Anant: “If there is something that has already been done hundreds of times, I don’t want to give stage for that.” Sudhanshu names novelty as the single most important factor.
Responsible and ethical: no talk highlighting a CVE in a product that has not been fixed; the board wants research presented responsibly.
Story, detail and takeaways: Vandana wants “a proper story” β a concise two-to-three paragraph abstract explaining why the audience should care (“if they don’t care, they will never come to your talk”), plus a genuinely detailed outline rather than “five or six points and done,” with clear takeaways, “which is missing in a lot of talks.”
Audience impact: Anant asks what an attendee will take away from 20β30 minutes: “It should not be a bragβ¦ The whole purpose of the conference is to impart knowledge.” Sudhanshu’s test β if a talk looks fancy but teaches nothing usable in your workflow, it is not impactful.
Proof over prose: Sudhanshu warns that anyone can now generate a polished abstract with AI, so “where is the proof?β¦ If you are leaving it up to the reviewers to find that proof, then you have failed.” Provide the evidence up front.
Vendor neutrality: the board is “very skeptical” and “very picky” about talks adjacent to what the submitter’s company sells. Anant advises stating openly: this is my work, this is what my company sells, and here is how this talk will not become a sales pitch β transparency makes it easier for reviewers to trust the submission.
The reviewer NDA and rejection math: reviewers are under non-disclosure agreements, so submitters should share full technical details β “anything that you share with us does not go outside of this circle.” Anant is candid that submissions outnumber slots roughly 10:1 or even 20:1, but rejection does not mean the research is low quality, and feedback can be requested.
“If you don’t submit you have already not cleared it. So it’s better to submit something and iteratively work on it.” β Anant Shrivastava
On AI-written proposals: using AI to refine and sharpen a submission is fine and even appreciated, but reviewers read so many machine-written abstracts that “we can smell it from a very long distance.” A one-line idea expanded into five paragraphs actively counts against a submission: “ensure that when you’re using AI, you are leveraging AI to enhance your proposal, not actually asking AI to write your proposals.” β Anant Shrivastava
Responsible Disclosure on Stage
Vandana’s baseline: the vulnerability should be submitted to the vendor and fixed before it reaches the stage, and the talk should say so explicitly β submitted, fixed, communicated. She recalls researchers whose vendors were uncomfortable with a presentation; the compromise was to discuss the methodology without focusing on the vendor.
The end user comes first: Anant frames disclosure around impact: “All what we are doing in information security is for the end user,” and publicizing an unfixed bug is bad for users. Black Hat tries to help and facilitate coordination when a vendor is non-responsive, unapproachable, or based in a country with no disclosure relationship.
The escalation path: when a vendor has ignored a disclosure for a very long time, the board may still accept the submission β depending on severity β precisely to make the community aware, especially in an age when AI systems and attackers are finding bugs constantly: “For us it’s not the vendor that matters the mostβ¦ what matters is the end user.”
Under-Resourced Areas: Hardware, IoT and OT
Sudhanshu names hardware, IoT and OT systems as India’s biggest research gaps.
The barrier is access and cost: “If I have to test a WordPress, I can set up a lab immediately on my laptop itself. But if I have to find a flaw in IoT or hardware, it is going to be costlyβ¦ It’s more than a hobby. It’s an investment.”
Firmware extraction skills, real playgrounds and equipment are scarce; a couple of strong Indian researchers exist in this space, but the field “needs more research, more access and more facilitation” β something Black Hat India may be able to help provide.
Tracks and Themes the Board Wants to See
Fraud and FinTech (Shubham): under-discussed at most conferences despite massive impact β “a very simple fintech vulnerability can be exploited for doing massive fraudsβ¦ calling it one ID but deep down it can cause million-dollar financial risks.” He wants large-scale research on how fraudsters operate and how defenders catch them.
Internet scanning (Shubham): his “all-time favorite,” alongside the traditional network, cloud, mobile and appsec tracks.
UPI and critical infrastructure: asked about India’s payments ecosystem, power grids and telecom as targets, Shubham’s answer is “100%” β UPI-adjacent startups and e-commerce companies have security researchers who should submit talks on tackling challenges at that scale.
AI is horizontal, not vertical (Anant): “AI is not a vertical on its own. It’s a horizontal section which basically works across all streams.” Expect both attack research (LLM poisoning, ML attacks and defenses) and AI-augmented security work β a dominant trend for the past two years. He also warns of what he calls the “AI psychosis” in submissions, “as vague as: I queried my LLM model and my LLM model confirmed that I can own the entire universe.” Personally he wants non-AI research too β supply chain, hardware, IoT, CPS β noting India has yet to produce a Pwn2Own champion.
Security of AI itself (Sudhanshu): distinguish “security using AI” from “security of AI.” Teams run agents and fine-tuned LLMs with very little observability β unclear access, undefined permission models, weak guardrails β an area he explicitly wants researched. He also notes relevance windows have shrunk from a year to roughly three months, so every talk (even appsec or DevSecOps) will be judged in an AI-accelerated world.
Shadow AI and supply chain (Vandana): she wants research on AI bill of materials and “shadow AI” β unmanaged AI exposure inside organizations β especially after the OWASP LLM, agentic and MCP Top 10 lists led some to claim shadow AI is no longer a big deal. She believes proper research findings would prove otherwise.
Practical economics (Shubham): skip the commodity work everyone knows is possible β “don’t tell us how you are doing threat modeling using AI.” Show the new angle, including cost: if you are finding CVEs with AI, “how are you finding it for $3 and not $500?” Anant adds that companies which cut staff chasing AI dreams are now watching “their wallets becoming much lighter” as AI bills rack up.
What dazzles the board (Anant): “As reviewers, one of our jobs is to get dazzled and amused by the submissions.” The best submissions are the ones that force the reviewers themselves to sit down and research what they just read β and he hopes the Indian community delivers exactly that.
Key Takeaways
Black Hat India runs October 27β30, 2026 in Bangalore β the first Black Hat in South Asia, and the call for papers is open.
Submission recipe: novelty, responsibility, a concise but complete abstract with a clear story, a genuinely detailed outline, demonstrable proof, and vendor neutrality beat polish every time.
Submit anyway: acceptance ratios run 10:1β20:1; reviewers are under NDA; rejection is not a verdict on research quality, and feedback is available.
Disclosure rules: stage fixed vulnerabilities and say so; where vendors stonewall, the board may still stage the talk to protect end users.
High-demand topics: fraud and FinTech abuse, internet scanning, UPI-scale payments security, hardware/IoT/OT, supply chain, security of AI agents β plus AI research that shows a genuinely new, cost-aware angle.
The closing appeal, aimed at the researcher “maybe in Bangalore, maybe in Hyderabad, maybe in a tier-2 city that nobody in this industry has heard of yet”: “This show is for that person. Submit your workβ¦ if it’s as good as you think it might be, you’ll be on stage in Bangalore on October 27th.”