SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsAI has exploded on the scene recently. Due to the explosion, we’ve seen rapid integration with existing systems and infrastructure - namely cloud infrastructure. Enterprises are connecting AI agents to existing applications, infrastructure, data, and more. This rapid adoption has come at a cost: security. We’ll cover an authorization bypass finding (yet to be disclosed) that we found with Amazon Web Services where access to AI Agents within cloud systems could be bypassed despite the cloud provider’s authorization controls. We’ll also cover a framework of how to think about AI integrations, especially related to cloud. One aspect we’ll cover is who has access to use AI Agents and the access AI Agents may have to cloud infrastructure and data.. Additionally, we’ll look at access and permissions in AWS when it comes to AI. Not all AI access fits within the existing cloud permission model and we’ll cover inconsistencies. After this talk, attendees will have a better grasp of the awkwardness of cloud integrations with AI, problems we’ve seen with the security and governance model when it comes to cloud and AI, and how to think about integrations of cloud and AI as we move forward.


Jason Kao is the founder of Fog Security where he focuses on the intersection of cloud security and AI.
Read more about Jason Kao










