One day that gets you hired, gets you paid more, or gets you started. Taught by the hackers who actually do this for a living.
Not a day of watching people be impressive. You leave with a plan you can start on Sunday morning, and the exact things that move you from where you are to where the money is.
What actually gets someone hired in 2026: the skills, the certifications worth paying for, and the ones that waste a year. The path we have already walked with 3,000+ students, laid out in order.
The portfolio, the CV and the positioning that make recruiters open the message. Plus how the hiring process really runs inside a company like Meta, from someone who sat on both sides of that table.
Bug chaining, client-side flaws, wide-scope hunting, and the business-logic bugs no scanner will ever hand you. This is the material that changes how you look at a target, and what you get paid for the same hours.
You found the bug. Now the part nobody teaches: writing the report so it gets triaged, negotiating the bounty, and handling the company without burning the relationship.
Every attendee gets a certificate of attendance, something concrete for the profile recruiters actually read while you are still building the rest.
Lunch and two breaks in the same room as people who earn a living doing this. The introduction that turns into a referral does not happen through a screen.
Everyone leaves with the slides, the notes pack, and a private attendee community that stays open after the day.
Your day, hour by hour, and what each hour is worth to you.
Doors at 09:00. Lunch and two coffee breaks included for on-site seats.
Sessions, timings and running order are still being finalised and may change before the day.
Not trainers reading from a syllabus. These are the people who found the bugs, got the jobs and negotiated the bounties. For one day they hand you the method instead of the highlight reel.
The face of Semicolon Security, a security engineer who still hunts, and the person who has taught more Lebanese hackers their first vulnerability class than anyone else in the country.
Opens the day: The mapRanked first on Meta's bug bounty program six years running, with more than $5M earned. One of the sharpest client-side and bug-chaining researchers working anywhere today.
Talk: XSS, API gateway bugs & chainingOver a decade in the field and 1,500+ vulnerabilities reported across the major platforms. Ranked #21 on Bugcrowd, winner of Intigriti's 1337up, HackerOne Vigilante Award, #1 in the FIS program, and winner of Russian "Hacks" 2024.
Talk: 1,500 vulnerabilities laterTen years in cybersecurity across security research, vulnerability assessment and offensive security. Multiple HackerOne and Bugcrowd Quarterly MVP, T-Bank MVP, and the holder of several security research awards.
Talks: Getting started the right way · Bug chainingRanked #20 on HackerOne worldwide and number one in Lebanon, with findings across dozens of the platform's top-ranked programs. He sat in a Semicolon classroom before he sat on this stage.
Talk: Finding bugs everyone missedFound the bug that bypassed two-factor authentication on Meta. Specialist in business logic and server side flaws, the class of bug no scanner will ever hand you.
Talk: The $100,000 bugNamed to the Facebook Hall of Fame for bug bounty research, AI certified, with 8+ years of engineering experience. Works where offensive security meets modern AI architecture, defending LLMs against adversarial attack.
Talk: When the target is an AIPhD in cryptography, formerly at Thales and NXP, now securing Web3 protocols. The rare speaker who can take cryptography and blockchain from first principles to exploitable in one session.
Talk: Where the money movedWorks product and IP security from both sides: hardening what gets shipped, and taking apart the products that were not hardened well enough.
Talk: How real software gets brokenA decade on Meta's Hall of Fame and now inside the industry. He will walk through how the hiring process actually runs, from both sides of the table.
Talk: How I got hired by Meta's security teamSix consecutive years on Meta's Hall of Fame, and he walked into a Semicolon classroom knowing nothing. He is here to tell you what the road looked like from the inside, including the parts that were slower and harder than anyone admits.
Talk: I was sitting in your seatOver ten years in business and management. He answers the question nobody else teaches. You found the bug. Now how do you write it up, negotiate it, and turn it into a career?
Talk: Reports, negotiation & your CVSwipe to meet the rest →
Half the room is starting out. The other half already ships code or finds bugs for a living. Wherever you sit on that line, here is what the day moves for you.
You keep hearing "get into cybersecurity" and nobody has told you where to start. You leave with the 120-day roadmap and the first three things to do.
You have found a bug or two, but the real programs still feel like a wall. You leave knowing how to pick targets and chain lows into criticals.
You ship the code that gets attacked. You leave able to spot the business-logic flaws your scanners have been walking straight past.
You already know who you are. You leave with the advanced afternoon, the negotiation playbook, and the contacts that raise your rate.
The Semicolon team is heading to GISEC Global in Dubai, and one of you is coming with us. Drawn live on stage at the closing panel. On-site tickets only, and you have to be in the room to win.
The largest cybersecurity event in the Middle East and Africa.
Every on-site ticket is one entry into the draw.
Not superstars. Students and juniors who walked into a Semicolon classroom not knowing where to start. Every name links to a real profile, so check them yourself.
Proof screenshot
Proof screenshot
Proof screenshot
Proof screenshot
Proof screenshot
Proof screenshot
Proof screenshot
Proof screenshot
Proof screenshot
Swipe for more trainees →
Al Arabiya, Al Hadath, Al Jazeera and Al-Nahar have all covered this team. Tap any clip to watch with sound.
Al Arabiya
About our latest achievements
Al Hadath
About the $50K Apple bounty
Al Jazeera
Giving back to the community
Al-Nahar
Apple update, Lebanese touch
Swipe for more coverage →
Less than most people spend on one month of courses they never finish. One room at BDD 1280, no second session and no overflow. When the seats are gone, they are gone.
Coming with friends? Book 3 seats or more together and everyone gets 10% off.
A full day in the room with the people who broke Apple, Meta and Google, and everything you need to keep going after it.
The full day, live from anywhere. Same stage, same speakers, same roadmap and the same notes pack, with chat open throughout.
You already know the free videos are not working. Years of tutorials and you are still guessing at what comes next. One Saturday gets you the roadmap, the CV, the method and the room. On September 13 these people go back to their programs, their clients and their day jobs.
Register Now