Cyber Scotland Connect: Edinburgh Meetup at CodeBase
Thursday, 26 November 2026
17:30 – 20:30 GMT
CodeBase Edinburgh, 37a Castle Terrace, Edinburgh EH1 2EL
♿Accessibility Baseline
Full lift access to lower ground event space. Step-free access from Castle Terrace entrance. Gender-neutral accessible facilities available.
Evening Agenda & Schedule
7 itemsDoors Open & Community Networking
Arrive, grab a badge, and catch up with colleagues and peers from across Scotland's cybersecurity ecosystem.
Welcome & Community Updates
Welcome from the Cyber Scotland Connect team, community news, and meetup briefing.
The Path to an Agentic SoC
A practical, real-world framework for introducing AI safely into security operations without falling into the 'AI all the things' trap.
Reading Malware Config Off the Blockchain (NullReceiver Malware)
How a developer-targeted campaign used next.config.js and .vscode/tasks.json as execution primitives, and why config files deserve the same scrutiny as application code.
Surviving 2026: A Security Practitioner's Field Guide to LLMs and Agents
A hands-on, practical field guide to which models and agent tools actually deliver, how to get useful work out of agents, and where they fail.
Break the Bank: Welcome to the Other Side of the Login Screen
Walkthrough of API-layer vulnerabilities using Rozolo, demonstrating broken authorization and object-level access flaws beyond the login screen.
Close
Featured Speakers & Sessions
Gary Hunter
Community Moderator"The Path to an Agentic SoC"
A practical, real-world framework for introducing AI safely into security operations without falling into the 'AI all the things' trap. Learn how to combine IaC, human-in-the-loop automation, agent constraints and AI Error Budgets to improve speed and coverage. Based on first-hand experience from an eight-person security team protecting a FTSE 350 SaaS platform across AWS and GCP.
Joshua Adegoke
Community Moderator"Reading Malware Config Off the Blockchain (NullReceiver Malware)"
How a developer-targeted campaign used next.config.js and .vscode/tasks.json as execution primitives, and why config files deserve the same scrutiny as application code.
Rory McCune
"Surviving 2026: A Security Practitioner's Field Guide to LLMs and Agents"
This year I've tested nearly 50 models and used several of them to build real projects, from production software to PoC exploits. Over the course of the year agents have gone from novelty to everyday tooling, bringing new capabilities and a new attack surface with them. This talk is a practical guide from someone who's been hands-on all year. We'll talk about which models and tools actually deliver, how to get useful work out of agents, and where they fail, from confidently wrong output to security refusals. I'll also take a look at how to evaluate the constant stream of new releases without drowning in hype, so you leave with an approach that will still hold up when next week's model drops.
Caleb Eghan
"Break the Bank: Welcome to the Other Side of the Login Screen"
A lot of apps look secure from the login screen. This session shows what happens once you get past it. Using Rozolo, our deliberately vulnerable banking app, we follow a single £1 payment through the API layer and watch it turn into exposed customer data and unauthorised transactions. The weaknesses on show are the ones a scanner or firewall tends to miss: broken authorisation, weak object-level access control, and data the API hands back without being asked for it. The API layer is now the softest part of most estates, and perimeter controls do little to defend it. We use the walkthrough to show where a modern API security strategy actually earns its place: visibility over what your APIs expose, authorisation enforced per object rather than per endpoint, and testing that hunts for logic and access flaws rather than known signatures.
Cyber Scotland Connect is thrilled to announce our next gathering in Central Edinburgh at CodeBase Edinburgh, supported by RiverSafe, who have kindly sponsored the meetup!
Capacity Notice: We have a strict limit of 80 attendees for this gathering. If you can no longer attend after RSVPing, please update your RSVP status on Meetup promptly so someone on the waitlist can join us.
🤝 Sponsored by RiverSafe
A massive thank you to RiverSafe for supporting this gathering and powering our community meetup!
☕ Keeping CSC Accessible for All
Cyber Scotland Connect has always been, and will always be, free to attend. We believe that barriers to entry—especially for students, career switchers, and those currently seeking new opportunities—should be nonexistent.
If you are established in your career and find value in our sessions, we invite you to Pay It Forward. While there is zero obligation, our Buy Me a Coffee page helps cover essential running costs (refreshments and minor community infrastructure), ensuring that those in our community who are currently studying or seeking opportunities can continue to attend and network at no cost.