hack::soho | Auth Under Attack | Viola Lykova @IOActive
hack::soho | Auth Under Attack | Viola Lykova  @IOActive
Uploaded April 2026 | Updated September 2026, 1 week ago
Learn more by visiting our website: ioactive.com

Viola Lykova, Senior Software Engineer gave this talk at hack::soho March 2026.

The abstract of the talk, 'Auth Under Attack, Designing AI-Ready Login Flows That Don't Collapse in the Real World,' is below!

hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.

ABSTRACT
Authentication isn't "a login page" anymore. It's an adversarial system under constant pressure from credential stuffing, MFA fatigue, token theft, session hijacking, OAuth edge cases, and social engineering. In this talk, I'll walk through how modern auth fails in production, how attackers chain small weaknesses into account takeover, and what "good" looks like in 2026, including passkeys/WebAuthn, safer session and token lifecycles, risk-based step-up controls, bot defenses, and detection that actually catches abuse. I'll also cover the AI angle and explain how automation and agentic tooling scale phishing, reconnaissance, and support-workflow abuse, and what teams can do to stay resilient.

PRESENTER'S BIO:
I'm a Senior Software Engineer in London with an SRE mindset, building and operating secure, high-traffic distributed systems in fintech and ecommerce. I focus on authentication, reliability, and incident-driven engineering, hardening critical auth flows against real abuse and improving resilience in production. I've delivered two public talks in 2025 (links below) and was invited with full sponsorship to speak internationally through Ministry of Testing.
hack::soho | Auth Under Attack | Viola LykovaIOActive Freakshow Party- Double Contortion!HACK::SOHO - Cryptocurrencies & CrimesIOActive | Alejandro Hernández | Are You Trading Stocks Securely?IOActives Freakshow - Defcon 19!hack::soho | Unicorn Engine - What, Why, How | Nicolò BoattoSQL injectionIOActive Research | NFC Relay Attack - Tesla Model Y - long range antennaIOActive | OCP S.A.F.E. | What is a Security Review Provider (SRP)? | #cybersecurityhack::soho | AI Agents Blast Radius and the MCP Horror Story | Dinis Cruz, The Cyber BoardroomHacking Human Safety Protections in Universal RobotsIOActive Freakshow Party- Gladiator Joust!
IOActive, Inc. |

hack::soho | Auth Under Attack | Viola Lykova

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER