SEC536: Adversarial AI - Penetration Testing AI Systems

In-Person
2025 was a year of cyberattacks with familiar causes: identity abuse through social engineering, unpatched internet facing systems, over trusted SaaS integrations, and gaps in logging and recovery. Industry reporting shows record ransomware victim counts and a sharp rise in groups, with AI accelerating phishing and data triage —yet the primary root causes remain exploited vulnerabilities and resource gaps. We’ll analyze several incidents to show how they mirror past breaches and how to stop the cycle.
In-Person
Can AI autonomously test a web application? We’ll put that claim to the test. Starting with classic web vulnerabilities and the manual methodology behind finding them, we’ll progressively automate the process using a custom agentic workflow. We’ll benchmark the results against other publicly available AI security agents, discuss where they succeed and fail, and share practical lessons learned while designing an effective security-focused agent.
In-Person