SEC536: Adversarial AI - Penetration Testing AI Systems

Virtual
As organizations increasingly run AI workloads in public clouds, security teams face new challenges around data protection, identity, workload isolation, misconfiguration, and visibility. This talk shares lessons learned and common concerns we have heard from customers running AI workloads in the cloud, based on our experience helping them address security challenges. We will explore why understanding the AI environment and having visibility into the workloads, infrastructure, data, and access paths supporting it are critical to managing risk effectively.
*Sponsored by Fortinet
Virtual
AI agents are becoming trusted operators in cloud environments, deploying infrastructure, writing code, managing identities, and executing privileged actions. That trust also creates a new attack surface. Recent research demonstrated how attackers manipulated AI coding agents through prompt injection and social engineering, enabling cloud attack chains without exploiting a software vulnerability. Once compromised, AI agent activity can appear indistinguishable from legitimate automation, making detection significantly more difficult. This session exlores how AI is reshaping cloud threat models and provides a practical framework for securing autonomous agents in cloud environments.
*Sponsored by Trend AI
Virtual
Every AI agent entering your cloud workspace arrives the same way: an employee clicks Allow. That single authorization flow now carries operational authority, not just data access, and most security teams have no record of who granted what, to whom, or whether anyone is still behind it.
This talk presents findings from an analysis of 22,332 OAuth-connected applications across 21 enterprise Google Workspace environments. The data shows a governance gap growing faster than any allowlist can close: 91% of AI applications appeared in the last 16 months, nearly half of all connected apps have been dormant for 90+ days with tokens still alive at the time of the snapshot, 1,064 apps show authorization records that outlast the accounts behind them, and one in four apps holds scopes Google itself classifies as restricted. We'll also walk through real cases, including a breach where a Chinese state-sponsored actor used stolen OAuth tokens to access 700+ organizations without touching a single password, and a decommissioned vendor whose grants outlived the company by two months.
Attendees will leave with three concrete actions: tying OAuth revocation to offboarding, building a lightweight AI tool registration path, and enforcing a dormancy threshold.
*Sponsored by Material Security
Virtual
Frontier models like Mythos discover vulnerabilities faster than any human team can triage them, and exploitation is getting easier just as fast. Researchers are calling what comes next the "vulnpocalypse," because the flood of new findings will overwhelm how most cloud security teams work today. Prioritizing by CVSS scores and only investigating and patching the highs and criticals was already more than most teams could keep up with.
Managing vulnerabilities used to mean working down from the criticals and hoping the mediums and lows didn't matter. Now every finding needs a decision (fix, defer, or safely ignore) and a traditional severity score like CVSS can't do that. The damage a vulnerability can do depends on the environment it lives in.
This session looks at which parts of vulnerability management still work in the age of AI, and which ones are outdated. We'll cover:
You'll leave with a practical approach to handling the "vulnpocalypse" you can apply immediately.
*Sponsored by Maze HQ
Presented by Harry Wetherald, CEO and Co-founder at Maze
Virtual
Virtual
Traditional threat modeling assumes a system stable enough to diagram, review, and revisit quarterly. AI-assisted development breaks that assumption. Agentic coding tools generate pull requests continuously, not on a human review cadence. CI/CD pipelines increasingly let an agent propose — and sometimes approve — its own changes. Dependency bots auto-merge updates faster than anyone evaluates whether the maintainer, or transitive package graph beneath a version number, has changed. The result is a release velocity that no review process built for human-paced development was designed to handle. You can’t threat model every change at this pace, so the real question becomes which changes are worth the effort. This talk proposes a way to make that call: a threat modeling framework that scales rigor to risk and velocity rather than to the calendar – so the highest-risk changes still get human scrutiny while routine ones can move at machine speed.
*Sponsored by Adobe
Virtual
Autonomous AI agents unlock immense business value by executing complex workflows, but they introduce novel security risks like prompt injections, identity sprawl, and tool misuse. Join our session to explore how you can use built-in security and governance controls to confidently scale AI agents into production without compromising developer velocity. Learn how to establish a zero-trust framework for AI agents, secure agent interactions and tool access, enforce real-time guardrails, and proactively manage risk and discover shadow AI.
*Sponsored by Google
Virtual
AI hasn’t just changed how we build—it’s fundamentally reshaped the attack surface. Today’s AI applications aren’t standalone systems; they are dynamic, interconnected ecosystems spanning models, data pipelines, agents, and cloud infrastructure—creating entirely new paths for risk. In this session, we’ll explore the rise of the AI Application Protection Platform (AI-APP) and why traditional security approaches fall short. Learn how a graph-powered, unified platform brings together visibility, risk analysis, and runtime protection to secure AI end-to-end—from code to cloud to model behavior. Discover how security teams can move beyond fragmented tooling to understand real attack paths, reduce noise, and protect AI at the speed it’s built.
*Sponsored by WIZ
Virtual
Virtual