Skip to main content
Edinburgh ChapterCSC Community Gathering● Upcoming

Cyber Scotland Connect: Edinburgh Meetup at CodeBase

Date & Time

Thursday, 26 November 2026

17:30 – 20:30 GMT

Venue & Location

CodeBase Edinburgh, 37a Castle Terrace, Edinburgh EH1 2EL

In-Person Gathering (Edinburgh)•View on Google Maps 📍 ↗

♿Accessibility Baseline

✓ Verified Step-free Route & Lifts
✓ Verified Induction Hearing Loop Available

Full lift access to lower ground event space. Step-free access from Castle Terrace entrance. Gender-neutral accessible facilities available.

Evening Agenda & Schedule

7 items
17:30Networking

Doors Open & Community Networking

Arrive, grab a badge, and catch up with colleagues and peers from across Scotland's cybersecurity ecosystem.

17:55Welcome & News

Welcome & Community Updates

Session Speaker:Harry McLaren

Welcome from the Cyber Scotland Connect team, community news, and meetup briefing.

18:00Talk / Session

The Path to an Agentic SoC

Session Speaker:Gary Hunter

A practical, real-world framework for introducing AI safely into security operations without falling into the 'AI all the things' trap.

18:30Talk / Session

Reading Malware Config Off the Blockchain (NullReceiver Malware)

Session Speaker:Joshua Adegoke

How a developer-targeted campaign used next.config.js and .vscode/tasks.json as execution primitives, and why config files deserve the same scrutiny as application code.

19:00Talk / Session

Surviving 2026: A Security Practitioner's Field Guide to LLMs and Agents

Session Speaker:Rory McCune

A hands-on, practical field guide to which models and agent tools actually deliver, how to get useful work out of agents, and where they fail.

19:30Talk / Session

Break the Bank: Welcome to the Other Side of the Login Screen

Session Speaker:Caleb Eghan

Walkthrough of API-layer vulnerabilities using Rozolo, demonstrating broken authorization and object-level access flaws beyond the login screen.

20:30

Close

Featured Speakers & Sessions

Gary Hunter

Community Moderator
Community Moderator, Cyber Scotland Connect

"The Path to an Agentic SoC"

A practical, real-world framework for introducing AI safely into security operations without falling into the 'AI all the things' trap. Learn how to combine IaC, human-in-the-loop automation, agent constraints and AI Error Budgets to improve speed and coverage. Based on first-hand experience from an eight-person security team protecting a FTSE 350 SaaS platform across AWS and GCP.

Joshua Adegoke

Community Moderator
Community Moderator, Cyber Scotland Connect

"Reading Malware Config Off the Blockchain (NullReceiver Malware)"

How a developer-targeted campaign used next.config.js and .vscode/tasks.json as execution primitives, and why config files deserve the same scrutiny as application code.

Rory McCune

Senior Security Researcher & Advocate, Datadog

"Surviving 2026: A Security Practitioner's Field Guide to LLMs and Agents"

This year I've tested nearly 50 models and used several of them to build real projects, from production software to PoC exploits. Over the course of the year agents have gone from novelty to everyday tooling, bringing new capabilities and a new attack surface with them. This talk is a practical guide from someone who's been hands-on all year. We'll talk about which models and tools actually deliver, how to get useful work out of agents, and where they fail, from confidently wrong output to security refusals. I'll also take a look at how to evaluate the constant stream of new releases without drowning in hype, so you leave with an approach that will still hold up when next week's model drops.

Caleb Eghan

"Break the Bank: Welcome to the Other Side of the Login Screen"

A lot of apps look secure from the login screen. This session shows what happens once you get past it. Using Rozolo, our deliberately vulnerable banking app, we follow a single £1 payment through the API layer and watch it turn into exposed customer data and unauthorised transactions. The weaknesses on show are the ones a scanner or firewall tends to miss: broken authorisation, weak object-level access control, and data the API hands back without being asked for it. The API layer is now the softest part of most estates, and perimeter controls do little to defend it. We use the walkthrough to show where a modern API security strategy actually earns its place: visibility over what your APIs expose, authorisation enforced per object rather than per endpoint, and testing that hunts for logic and access flaws rather than known signatures.

Cyber Scotland Connect is thrilled to announce our next gathering in Central Edinburgh at CodeBase Edinburgh, supported by RiverSafe, who have kindly sponsored the meetup!

Capacity Notice: We have a strict limit of 80 attendees for this gathering. If you can no longer attend after RSVPing, please update your RSVP status on Meetup promptly so someone on the waitlist can join us.

🤝 Sponsored by RiverSafe

A massive thank you to RiverSafe for supporting this gathering and powering our community meetup!

☕ Keeping CSC Accessible for All

Cyber Scotland Connect has always been, and will always be, free to attend. We believe that barriers to entry—especially for students, career switchers, and those currently seeking new opportunities—should be nonexistent.

If you are established in your career and find value in our sessions, we invite you to Pay It Forward. While there is zero obligation, our Buy Me a Coffee page helps cover essential running costs (refreshments and minor community infrastructure), ensuring that those in our community who are currently studying or seeking opportunities can continue to attend and network at no cost.

Community Code of ConductAll attendees, speakers, and organizers are required to uphold our inclusive community standards.
Read Code of Conduct →