Vincenzo Iozzo
Co-founder & CEO, SlashID
Vincenzo Iozzo is the co-founder and CEO of SlashID, an identity security platform that detects and prevents identity-based attacks across human, non-human and AI identities. He writes about identity security, AI and vulnerability research on the SlashID blog and on his personal site, vincenzoiozzo.com.
Before SlashID he founded IperLane, a mobile security company acquired by CrowdStrike. As Senior Director at CrowdStrike he shipped Falcon for Mobile, sourced and executed the acquisition of Preempt Security (now Falcon Identity Protection) and managed the Falcon Fund.
His earlier career was in offensive security research. He is a two-time Pwn2Own winner (iPhone and BlackBerry), co-author of the iOS Hacker’s Handbook (Wiley), a Black Hat speaker and former Review Board member, and a former Associate Researcher at the MIT Media Lab. He holds a BS in Computer Engineering from Politecnico di Milano. His academic work is indexed on Google Scholar.
Background & roles.
Co-founder & CEO
Leads SlashID, an identity security platform that detects and prevents identity-based attacks by ingesting logs from identity providers, cloud platforms and SaaS applications.
Senior Director
Shipped Falcon for Mobile (formerly IperLane), sourced and executed the acquisition of Preempt Security (now Falcon Identity Protection), and managed the Falcon Fund cybersecurity venture fund with Accel.
Founder & CEO
Founded a mobile threat defense company, acquired by CrowdStrike.
Director of Security Engineering
Led security research and engineering at the security research and consulting firm.
Associate Researcher
Research at the intersection of technology and society.
Security Researcher
Offensive security research on Mac OS X, iOS and mobile platforms, published at Black Hat, CanSecWest, ACM CCS and Microsoft BlueHat.
Selected research & talks.
iOS Hacker's Handbook
Co-author, with Charlie Miller, Dion Blazakis, Dino Dai Zovi, Stefan Esser and Ralf-Philipp Weinmann.
Pwn2Own winner: iPhone 3GS
With Ralf-Philipp Weinmann, the first public return-oriented programming exploit on ARM, compromising the iPhone 3GS through Safari.
Pwn2Own winner: BlackBerry
Co-developed the exploit that defeated BlackBerry OS at Pwn2Own.
0-Knowledge Fuzzing
Fuzzing without prior knowledge of the input format or binary internals.
The Case for Scale in Cyber Security
Security track keynote.
From One Ivory Tower to Another
Invited talk on filling the gaps between academic security research and real-world security.
Surveillance, Software, Security, and Export Controls
With Thomas Dullien and Mara Tam: recommendations on the Wassenaar Arrangement and intrusion software.
Interviews & commentary.
Identity-based AI attacks, live at Nasdaq
Video interview on why identity-based attacks became a key cybersecurity risk, and on governing permissions across human, non-human and AI identities.
Security leaders discuss the Vercel breach
Technical analysis of the OAuth 2.0 attack vector and recommendations for identity security.
Why Stryker's outage is a disaster recovery wake-up call
Why cloud environments need frequent backups and infrastructure as code, and why global admin rights belong to a handful of break-glass accounts.
Iranian hacktivists claim attack on US Stryker
Analysis of the attack that wiped over 200,000 devices and the identity controls it calls for.
Overly permissive guest settings put Salesforce customers at risk
On how attackers harvest data through Experience Cloud guest access, and why Salesforce credentials enable lateral movement.
AI-generated phishing attacks increase by 14×
Why AI-assisted operations shrink breakout times, and why phishing defenses must rely on behavioral signals.