Hacking Day 2026 | One day with the hackers who broke Apple, Meta & Google | Semicolon Security
Sat 12 September · BDD 1280, Beirut · 100 seats left · Register Now

Spend one Saturday with the hackers who hacked Apple, Meta & Google

One day that gets you hired, gets you paid more, or gets you started. Taught by the hackers who actually do this for a living.

Early birds get the lowest price we will ever offer
--
Days
--
Hours
--
Minutes
--
Seconds
📅
DateSat, September 12
🕘
Hours09:00 to 18:30
📍
On siteBDD 1280, Beirut
💻
OnlineLive on Zoom
🎙️
Speakers10+ Real Hackers
🎤
FormatOne Stage, All Day
Why this day is worth it

What you actually walk away with

Not a day of watching people be impressive. You leave with a plan you can start on Sunday morning, and the exact things that move you from where you are to where the money is.

🧭

The real roadmap, not another course list

What actually gets someone hired in 2026: the skills, the certifications worth paying for, and the ones that waste a year. The path we have already walked with 3,000+ students, laid out in order.

💼

How to get hired with "no experience"

The portfolio, the CV and the positioning that make recruiters open the message. Plus how the hiring process really runs inside a company like Meta, from someone who sat on both sides of that table.

📈

Mid-level to properly paid

Bug chaining, client-side flaws, wide-scope hunting, and the business-logic bugs no scanner will ever hand you. This is the material that changes how you look at a target, and what you get paid for the same hours.

💰

Turning a finding into money

You found the bug. Now the part nobody teaches: writing the report so it gets triaged, negotiating the bounty, and handling the company without burning the relationship.

🎓

A certificate you can put on LinkedIn

Every attendee gets a certificate of attendance, something concrete for the profile recruiters actually read while you are still building the rest.

🤝

The room itself

Lunch and two breaks in the same room as people who earn a living doing this. The introduction that turns into a referral does not happen through a screen.

Everyone leaves with the slides, the notes pack, and a private attendee community that stays open after the day.

Semicolon's Hacking Day

The Schedule

Your day, hour by hour, and what each hour is worth to you.

Saturday, 12 September

Doors at 09:00. Lunch and two coffee breaks included for on-site seats.

📍 BDD 1280 · Beirut Digital District 🕘 09:00 to 18:30
09:00 - 09:30 Doors, registration & coffee Everyone
09:30 - 10:10 The map: what this field really pays, and the ways people actually get in Majd Dhainy Beginner
10:10 - 10:45 What if you were doing everything wrong? How to get started the right way Mohamed Daher Beginner
10:45 - 11:00 Coffee break Everyone
11:00 - 11:35 How real software gets broken, and why the team that built it never saw it Abed Ayoub Beginner
11:35 - 12:10 The $100,000 bug no scanner will ever find Bassem Bazzoun Intermediate
12:10 - 12:55 Lunch & networking Everyone
12:55 - 13:35 XSS, API gateway bugs and the chains they open, with live demos Youssef Sammouda Advanced
13:35 - 14:10 Finding bugs in companies everyone has already tested Hasan Sheet Intermediate
14:10 - 14:25 Coffee break Everyone
14:25 - 15:00 1,500 vulnerabilities later: what changed between report #1 and report #1,000 Hussein Daher Intermediate
15:00 - 15:35 When the target is an AI: breaking and defending LLM systems Hadi Zeinaldeen Intermediate
15:35 - 16:10 Bug chaining: turning lows into criticals, real chains from a decade of hunting Mohamed Daher Intermediate
16:10 - 16:45 Where the money moved: cryptography, Web3 & the bugs nobody is hunting yet Dr. Mohammad Mansouri Advanced
16:45 - 17:10 I was sitting in your seat Hassan Saayed Beginner
17:10 - 17:40 How I got hired by Meta's security team Kassem Bazzoun Beginner
17:40 - 18:05 Getting paid: reports, negotiation & a CV that lands interviews Fayad Atwi Beginner
18:05 - 18:30 Closing panel: ask us anything All speakers on stage Everyone

Sessions, timings and running order are still being finalised and may change before the day.

Meet the hackers

Real hackers who get paid millions to hack Meta, Google, Apple & Microsoft

Not trainers reading from a syllabus. These are the people who found the bugs, got the jobs and negotiated the bounties. For one day they hand you the method instead of the highlight reel.

Co-founder & Host Majd DhainyMD
Majd Dhainy
Sr. Security Engineer

The face of Semicolon Security, a security engineer who still hunts, and the person who has taught more Lebanese hackers their first vulnerability class than anyone else in the country.

Opens the day: The map
#1 on Meta · 6 Years Youssef SammoudaYS
Youssef Sammouda
Independent Security Researcher

Ranked first on Meta's bug bounty program six years running, with more than $5M earned. One of the sharpest client-side and bug-chaining researchers working anywhere today.

Talk: XSS, API gateway bugs & chaining
#21 on Bugcrowd Hussein DaherHD
Hussein Daher
CEO & Founder, Web Immunify

Over a decade in the field and 1,500+ vulnerabilities reported across the major platforms. Ranked #21 on Bugcrowd, winner of Intigriti's 1337up, HackerOne Vigilante Award, #1 in the FIS program, and winner of Russian "Hacks" 2024.

Talk: 1,500 vulnerabilities later
HackerOne & Bugcrowd MVP Mohamed DaherMD
Mohamed Daher
Security Researcher, WebImmunify

Ten years in cybersecurity across security research, vulnerability assessment and offensive security. Multiple HackerOne and Bugcrowd Quarterly MVP, T-Bank MVP, and the holder of several security research awards.

Talks: Getting started the right way · Bug chaining
#20 Worldwide on HackerOne Hasan SheetHS
Hasan Sheet
Bug Bounty Hunter · Semicolon alumnus

Ranked #20 on HackerOne worldwide and number one in Lebanon, with findings across dozens of the platform's top-ranked programs. He sat in a Semicolon classroom before he sat on this stage.

Talk: Finding bugs everyone missed
Meta 2FA Bypass Bassem BazzounBB
Bassem Bazzoun
Sr. Security Researcher · Product Dev

Found the bug that bypassed two-factor authentication on Meta. Specialist in business logic and server side flaws, the class of bug no scanner will ever hand you.

Talk: The $100,000 bug
AI & Security Hadi ZeinaldeenHZ
Hadi Zeinaldeen
Technical Team Lead · Software Engineer

Named to the Facebook Hall of Fame for bug bounty research, AI certified, with 8+ years of engineering experience. Works where offensive security meets modern AI architecture, defending LLMs against adversarial attack.

Talk: When the target is an AI
PhD · Cryptography Dr. Mohammad MansouriMM
Mohammad Mansouri
Sr. Web3 Security Researcher

PhD in cryptography, formerly at Thales and NXP, now securing Web3 protocols. The rare speaker who can take cryptography and blockchain from first principles to exploitable in one session.

Talk: Where the money moved
Product Sec Abed AyoubAA
Abed Ayoub
Product & IP Security

Works product and IP security from both sides: hardening what gets shipped, and taking apart the products that were not hardened well enough.

Talk: How real software gets broken
10 Yrs Meta Hall of Fame Kassem BazzounKB
Kassem Bazzoun
Co-founder · Sr. Security Researcher

A decade on Meta's Hall of Fame and now inside the industry. He will walk through how the hiring process actually runs, from both sides of the table.

Talk: How I got hired by Meta's security team
6 Yrs Meta Hall of Fame Hassan SaayedHS
Hassan Saayed
Security Researcher · Semicolon alumnus

Six consecutive years on Meta's Hall of Fame, and he walked into a Semicolon classroom knowing nothing. He is here to tell you what the road looked like from the inside, including the parts that were slower and harder than anyone admits.

Talk: I was sitting in your seat
PMP · 10+ Years Fayad AtwiFA
Fayad Atwi
Co-founder · Project Manager, PMP

Over ten years in business and management. He answers the question nobody else teaches. You found the bug. Now how do you write it up, negotiate it, and turn it into a career?

Talk: Reports, negotiation & your CV

Swipe to meet the rest →

$12M+
Combined bounties earned
10+
Real hackers on stage
220
Seats in the room
1
Day that changes your life plan
Who is in the room

Most of the room will be exactly where you are

Half the room is starting out. The other half already ships code or finds bugs for a living. Wherever you sit on that line, here is what the day moves for you.

🎓

Students & beginners

You keep hearing "get into cybersecurity" and nobody has told you where to start. You leave with the 120-day roadmap and the first three things to do.

🐛

Junior hackers

You have found a bug or two, but the real programs still feel like a wall. You leave knowing how to pick targets and chain lows into criticals.

💻

Developers & Engineers

You ship the code that gets attacked. You leave able to spot the business-logic flaws your scanners have been walking straight past.

🛡️

Senior hackers

You already know who you are. You leave with the advanced afternoon, the negotiation playbook, and the contacts that raise your rate.

On the day

One of you is flying to Dubai with us 🇦🇪✈️

The Semicolon team is heading to GISEC Global in Dubai, and one of you is coming with us. Drawn live on stage at the closing panel. On-site tickets only, and you have to be in the room to win.

Grand prize The full GISEC Global Dubai experience 🇦🇪 Flights, three nights hotel and your conference pass, travelling with the Semicolon team $2,000
Also on the day Academy training seats and swag drops Free places on selected Semicolon courses, plus hoodies, tees and badges All day

Every on-site ticket is one entry into the draw.

The Honor Wall

They were exactly where you are

Not superstars. Students and juniors who walked into a Semicolon classroom not knowing where to start. Every name links to a real profile, so check them yourself.

Bug bounty result from Hasan Sheet Proof screenshot
H Hasan SheetSemicolon trainee
Now #1 on HackerOne in Lebanon, and speaking this year
Bug bounty result from Joseph Semaan Proof screenshot
J Joseph SemaanSemicolon trainee
Bug bounty result from Malak Abadi Proof screenshot
M Malak AbadiSemicolon trainee
Bug bounty result from Marcel Malaeb Proof screenshot
M Marcel MalaebSemicolon trainee
Bug bounty result from Hassan Saayed Proof screenshot
H Hassan SaayedSemicolon trainee
Also on stage this year
Bug bounty result from Nassir Ghraizi Proof screenshot
N Nassir GhraiziSemicolon trainee
Bug bounty result from Jad Abou Najem Proof screenshot
J Jad Abou NajemSemicolon trainee
Bug bounty result from Hassan Al Khansa Proof screenshot
H Hassan Al KhansaSemicolon trainee
Bug bounty result from Jad Al Hajjar Proof screenshot
J Jad Al HajjarSemicolon trainee

Swipe for more trainees →

4.5 out of 5 across 22 reviews on Trustpilot · see the full Honor Wall
As seen in the press

Heard what the media said about us?

Al Arabiya, Al Hadath, Al Jazeera and Al-Nahar have all covered this team. Tap any clip to watch with sound.

Press
Al Arabiya About our latest achievements
Press
Al Hadath About the $50K Apple bounty
Press
Al Jazeera Giving back to the community
Press
Al-Nahar Apple update, Lebanese touch

Swipe for more coverage →

Your seat

220 seats. That is the whole room.

Less than most people spend on one month of courses they never finish. One room at BDD 1280, no second session and no overflow. When the seats are gone, they are gone.

Coming with friends? Book 3 seats or more together and everyone gets 10% off.

Seats are going fast On-Site · BDD 1280

A full day in the room with the people who broke Apple, Meta and Google, and everything you need to keep going after it.

8 hours of live training worth more than most paid courses
Certificate of attending Hacking Day 2026
Your seat at BDD 1280, all day
The full notes pack and every slide
Lunch and two coffee breaks included
Meet every speaker in the breaks
Entry to the GISEC Dubai prize draw
100 seats left
Live on Zoom
$49.99 one-time

The full day, live from anywhere. Same stage, same speakers, same roadmap and the same notes pack, with chat open throughout.

Every session, live
Ask questions in the live chat
The Hacking Day notes pack
Private attendee community
Seat in the room
Lunch & coffee breaks
Meeting the speakers in person
1,000 Zoom seats left
Before you book

Questions people actually ask

Yes, and that is precisely who it is for. The largest group in the room will be students and people who have never written a line of exploit code. The day starts from what the field is and how people get into it, and every session is labelled by level.
No. Roughly half the room already writes code or finds bugs, and the afternoon is built for exactly that half. You get client side flaws and chaining from the researcher who has topped Meta's program six years running, wide scope hunting from the number one hacker in Lebanon, breaking and defending AI systems, and cryptography and Web3 from a PhD. It is the kind of material that changes how you look at a target, pushes you toward senior work, and gets you paid a lot more for the same hours. Check the level tags on the schedule to see which sessions are aimed at you.
It is not hands-on, and that is on purpose. Nobody learns anything from spending forty minutes fixing a broken install while a speaker waits. Bring something to take notes with. You will be watching people who do this professionally show you what it actually looks like.
Yes, and most people do. Book 3 seats or more together and everyone gets 10% off. Pick the number of seats in the booking form, give us your details once, and we send a single payment link for the whole group. You can send us the other names any time before the day.
The grand prize is a full GISEC Global trip to Dubai, worth around $2,000: return flight, three nights hotel and your conference pass. There are also free Semicolon Academy training seats and swag handed out through the day. Every on-site ticket is one entry, the draw happens live at the closing panel, and you need to be in the room to win. Zoom tickets are not entered.
220, and that is the whole room at BDD 1280. There is no second session and no overflow room, so once they are gone the day is closed. The counter on this page is the real number, updated as bookings come in.
Honestly, no. This day is built for people meeting us for the first time, and much of it will be ground you have already covered. Seats are limited and we would rather they went to someone who has not started yet.
A mix of Arabic and English depending on the speaker, with all slides in English.
Zoom gets every session live. On-site gets the room, lunch, the breaks where you actually meet the speakers, entry to the GISEC Dubai draw, and the certificate. The conversations in the corridor are the part that does not stream.
Pick your method in the booking form (Whish Money, OMT, cryptocurrency, or card and bank transfer) and we send the details on WhatsApp within a few hours. Your seat is held while you complete payment.
Tell us before 5 September and we transfer your seat to someone else or sort out a refund with you. After that the catering is already ordered in your name.

Another year of tutorials. Or one Saturday.

You already know the free videos are not working. Years of tutorials and you are still guessing at what comes next. One Saturday gets you the roadmap, the CV, the method and the room. On September 13 these people go back to their programs, their clients and their day jobs.

Register Now
100 seats left
Hacking Day 2026 Sep 12 · BDD 1280 · 100 seats left
Register Now