On Wednesday 3rd June 2026 the Institute of Cyber Security for Society (iCSS) of the University of Kent co-organised CyberHack 2026, a national cyber security hackathon, at the UWS (University of the West Scotland) London Campus. The event’s main organisers included UWS London Cyber Club and UWS Cyber Security Programme. In addition to iCSS and UWS London Campus, CSE Connect, a not-for-profit on cyber security education, is another co-organising body. The event also received support and/or sponsorships from the following organisations: KMCS3 (Kent & Medway Cyber Security Student Society); Cyber London; KMCC (Kent & Medway Cyber Cluster); SOEBIT Cybersecurity Netherlands and The Education Group London.
The event’s main coordinator is Dr Manesh Thankappan of UWS London, who was supported by Dr Sin Wee Lee, UWS London’s Head of Subject Area for CEPS (Computing, Engineering, Physical Science) & HLS (Health and Life Sciences). iCSS Director Professor Shujun Li coordinated the contribution of University of Kent, with support of Deputy Director (Education) Dr Virginia Franqueira and student leaders of KMCS3. Dr Charles Clarke coordinated contribution of CSE Connect in his role as Co-Founder and Director of Operations. Many of the logistical matters were taken care of by UWS London student volunteers, as part of the student-run UWS London Cyber Club.
The event attracted 88 students from the following 13 UK universities.
- City St George’s, University of London
- University of East Anglia
- University of Greenwich
- University of Kent
- The University of Law
- Northumbria University
- University of Plymouth
- University of Roehampton
- Royal Holloway, University of London
- University of South Wales
- University of Surrey
- Teesside University
- University of the West of Scotland

The students formed 19 teams, who were given a real-world cyber security problem on developing a technical solution to SMEs’ needs of responding to new CVEs (Common Vulnerabilities and Exposures). They were given six hours (between 10am and 4pm) to develop a technical solution, and the use of AI tools was actively encouraged. After 4pm, all teams had a 5-min opportunity to give a short presentation and demo about their developed solution in front of the event’s judging panel. After all teams presented and demonstrated their work, the judging panel met to decide the final score of the teams. Judges also visited and interacted with all participating teams before 4pm to observe what they were doing, as part of the scoring process.
The judging panel was composed of the following six cyber security experts.
- Dr Charles Clarke – Director of Operations, CSE Connect
- Nigel Jones – Director of International and Business Outreach, CSE Connect
- John Madelin – Co-Director of International and Business Outreach Programme, CSE Connect
- Soenil Soebedar – CEO, Soebit Cybersecurity Netherlands
- Leslie Leigh – Cyber Security Consultant, Lockdown Market
- Phibian Nosa Brown – Cyber Security Engineering Consultant, University of Oxford

At the event, the following ten students from the University of Kent, who formed two teams – Team KMCS3 and Team SHADS, competed alongside with other teams.
- Team KMCS3: Mihai Moraru (lead), Viktor Majzus, Daniel Shorter, Umuthan Çakır and Patryk Kolata
- Team SHADS: Dhairya Satani (lead), Shantanu Vedante, Abhishek Khilari, Shardul Ingale and Hansraj Sinwar
Team KMCS3 developed Garnett, an AI-enabled intelligent vulnerability manager, which takes a raw list of software assets as the input, maps them to the CPE (Common Platform Enumeration), matches them to CVEs pulled from the NIST NVD (National Vulnerability Database) with an API, and implements their custom scoring formula – a hybrid, 3-layer model combining KEVs (Known Exploited Vulnerabilities), FIRST CVSS (Common Vulnerability Scoring System) and EPSS (Exploit Prediction Scoring System). This then prioritises vulnerabilities for security professionals in both simple and detailed reports, catering to users across the board, with varying levels of technical expertise. With AI embedded at every level through a locally hosted, resource-efficient, open-source Ollama model, including an in-built chatbot assistant – this not only addresses their user stories, but also opens their eyes to the possibilities for exploration and expansion going forward.
Team SHADS developed CVE-to-My-Stack Translator, which takes the same input as Garnett and automatically identities relevant vulnerabilities, scores and ranks them. CVE-to-My-Stack Translator does not just rank the vulnerabilities by how severe they are but also flags those that are being used by hackers now (KVEs). It also calculates a score that combines how severe a vulnerability is and how likely it is to be used by hackers. This way security teams know what to fix. The tool uses three main external sources: the NIST NVD (CVE) database, the CISA KEVs catalogue and the FIRST EPSS scores. CVE-to-My-Stack Translator tool can work completely offline, after grabbing data from the above sources. It also gives the users a summary of the risks, which can be downloaded as a report. The tool can be used as a command-line toolbox or a web-based dashboard. CVE-to-My-Stack Translator is open-source and can be found on GitHub at https://github.com/dhairya221b/cve-to-my-stack.
At the end of the event, the top five award-winning teams were announced. Teams KMCS3 and Team SHADS won the 2nd and the 3rd places, respectively, only after the winning team from The University of Law. It was the first time for all students in both teams to attend a cyber security hackathon, so congratulations to them on achieving such good results at the national event!


In addition to the twelve students, Professor Shujun Li and Dr Virginia Franqueira also attended the event as both co-organisers and supporters of the University of Kent teams. iCSS provided funding to cover all 14 University of Kent attendees’ travel costs.


More about the event can be found in the following YouTube video produced by the UWS London Campus and The Education Group London. The cover picture of the video features the University of Kent’s Team SHADS working to develop their technical solution. The video includes a mini-interview Professor Shujun Li had with the filming team to describe his perspectives of the event.
With the great success of the event, UWS London, iCSS and CSE Connect will discuss with other supporting bodies and UK universities to organise the hackathon again in 2027, aiming at developing it into a yearly national event series with a more lasting impact. We look forward to seeing an even more successful CyberrHack event in 2027!
After winning the 2nd place, Team KMCS3 members said: “Surprisingly, for many members of the KMCS3 team at UWS CyberHack 2026, this was our first time participating in a hackathon, a well-known rite of passage for all computer science students. As cyber security students, we were very familiar with CTFs, but this event came at the crossroads of both, a cyber security themed hackathon. This allowed and even encouraged us to push the boundaries of our comfort zones and dabble in a bit of programming, an area more customary for software engineering and AI students.”
“Although for most of us it came at a very busy time of our lives, while submitting our bachelor’s dissertations and with about a week left before graduating with our degrees, I can safely say, in unanimously agreement, that it was well worth our time. A wonderful capstone competition for the current KMCS3 leadership to reminisce and bid farewell to the rest of the team and our university.”
Knowing they were ranked the 3rd place, Team SHADS members said, “Winning the 3rd place at CyberHack 2026 still feels surreal if we are being honest. We came in with one agreement: we were going to do this properly or not at all. There were moments we questioned whether our approach was right, but we kept coming back to the numbers and the evidence. When the judges questioned us, we had real answers because we had genuinely lived inside this work. Seeing two University of Kent teams on that podium, 2nd and 3rd, was the moment it all sank in. Team SHADS leaves with a placing we earned and honestly a hunger to go further than we ever thought we could.”
Reflecting about the organisation of the whole event, Professor Shujun Li said, “We were very lucky to have decided to work with our UWS London collaborators to initialise the CyberHack 2026 event. We started a bit late and was wondering if we could attract enough UK universities to send teams. The end results were far beyond our expectation. We had more teams applying, but we didn’t have enough space for all to attend so had to accept only the first 20 teams. I was also very happy to see University of Kent student teams won the 2nd and the 3rd places at the event. None of us expected that they could have done so well, so a big congratulations to all the twelve students who gave up their time in the last teaching week to participate. We thank UWS London for inviting us to be a co-organiser of the event. We also would like to thank other supporters, without whose help and support the event would not have been so unforgettable!”
Dr Manesh Thankappan, the event’s main coordinator, summarised, “CyberHack 2026 was a truly rewarding experience and a proud moment for everyone involved. Seeing students from universities across the UK come together, collaborate under pressure, and develop practical cyber security solutions was inspiring. The event showed the value of strong academic, industry and student partnerships, and I am especially grateful to iCSS at the University of Kent, CSE Connect, KMCS3, SOEBIT Cybersecurity Netherlands, Cyber London, KMCC, The Education Group London, our judging panel, colleagues, and the UWS London Cyber Club volunteers for their excellent support. CyberHack 2026 has created a strong foundation, and I look forward to working with our partners to make CyberHack 2027 even bigger, more inclusive and more impactful for students and the wider cyber security community.”