

Open WAF Day Vienna 2026 is behind us, and it’s time to look back at a great day of talks and discussions at the Austria Center.
We had around 20-30 people join us in the room, catching up between talks, comparing notes on running WAFs in production, and asking the kind of pointed questions that only come from people who actually operate these systems. The agenda ended up being:
| Time | Title | Presenter(s) |
|---|---|---|
| 09:45 - 10:00 | Registration & Welcome | |
| 10:00 - 10:45 | Embracing Envoy’s Dynamic Modules: Meet the new Coraza connector | Matteo Pace |
| 10:45 - 11:00 | Coffee Break | |
| 11:00 - 11:45 | WAF error log analysis at the highest level: ultra-fast filtering and multi-level aggregation with minimal resources | Ervin Hegedüs |
| 11:45 - 12:45 | Lunch | |
| 12:45 - 13:30 | Coraza Center: bringing your WAF closer to GitOps | Juan Pablo Tosso |
| 13:30 - 13:45 | Coffee Break | |
| 13:45 - 14:30 | Ingress NGINX is retired – now what about my WAF rules?! | Lukas Funk |
| 14:30 - 14:45 | Coffee Break | |
| 14:45 - 15:30 | CHAMELEON-REN: Instrumenting Adaptive Honeypots with CRS for Education-Sector Threat Intelligence | Adrian Winckles & Gautam Juvarajiya |
| 15:30 - 16:00 | Closing & Networking |
From a new Coraza connector built on Envoy’s Dynamic Modules, to log analysis tools written in C that process a million rows a second, to a research project turning CRS into an adaptive honeypot, the range of topics was a good reminder of how many different directions this community is pulling in — all pointed at the same goal of making WAFs easier to run and trust.
Thank you to everyone who joined us in Vienna, presented a talk, or just stopped by to say hello. See you at the next Open WAF Day! 👋





















































