Loading…
Venue: Room: Grand Ballroom A (Street Level) clear filter
arrow_back View All Dates
Thursday, November 5
 

9:00am PST

Opening Remarks and Keynote, The End of Guessing: Security's Coming Market Correction
Thursday November 5, 2026 9:00am - 10:00am PST

Speakers
JG

Jeremiah Grossman

Co-Founder and CEO, Root Evidence
Jeremiah Grossman is a cybersecurity entrepreneur, investor, and Brazilian Jiu-Jitsu black belt with over 25 years of industry-defining impact. He began as one of Yahoo’s first information security officers before founding WhiteHat Security in 2001, which grew into the world’s... Read More →
Thursday November 5, 2026 9:00am - 10:00am PST
Room: Grand Ballroom A (Street Level)

10:30am PST

Beyond Provenance: Integrating Weight-Integrity Attestation Into Your AIBOM Pipeline
Thursday November 5, 2026 10:30am - 11:15am PST
Most AI supply-chain security tooling stops at provenance. A signed manifest proves the model came from the publisher who claims to ship it. OWASP CycloneDX AIBOM, OpenSSF Model Signing, and HuggingFace's signed model cards all answer that question. None of them answer the next one - what is actually inside the weights you signed.

The harder attack class lives in that gap. We built a working architectural-backdoor adapter of 136 kilobytes of new weights inserted between two transformer blocks of Cisco's Foundation-Sec-8B-Instruct and disclosed to Cisco PSIRT. Foundation-Sec ships across Splunk Enterprise Security AI Assistant and Cisco XDR, the model is in production SOC pipelines today. The adapter passes byte-for-byte hash comparison, fires only on a hidden trigger phrase, and is invisible to every provenance check currently deployed.

This session walks through a defensive workflow that closes the gap. Four steps AppSec teams can adopt this quarter:

1. Emit a CycloneDX 1.6 AIBOM with a structural-content hash field at model ingestion.
2. Bind the AIBOM to an OpenSSF Model Signing sigstore bundle so provenance and content ship together.
3. Scan weights at CI time with an integrity scanner, validated against the disclosed attack with zero-error insertion-layer recovery.
4. Hook model-load events in production so drift from the pinned baseline routes through the existing on-call channel.

Attendees leave with a reference architecture, a copy-paste CI configuration, the four-class payload taxonomy that determines what each control actually catches, and an honest defense-in-depth framing. The published adversarial stress-test shows where this workflow stops working. Layer it alongside provenance signing and behavioural monitoring, do not deploy it in place of them.
Speakers
BD

Bodhisattva Das

Security Researcher, RUDRA Cybersecurity
Bodhisattva Das is a Security Researcher at RUDRA Cybersecurity, and a graduate student at Carnegie Mellon University working on securing non-human identities, AI agents, and automated workloads across cloud environments. He specialises in open-source threat detection using Wazuh... Read More →
Thursday November 5, 2026 10:30am - 11:15am PST
Room: Grand Ballroom A (Street Level)

11:30am PST

Exploits of Agency: Mapping out insecure development patterns across the agentic landscape
Thursday November 5, 2026 11:30am - 12:15pm PST
At this point, agents are everywhere and they are pretty hard to ignore. They are showing up in our CI/CD life cycles, in code development, in code reviews, and in the day-to-day workflows that engineering teams are encouraged to adopt by both lower and upper management.

Their deep integration into the development life cycle raises a serious question: how do we actually deploy agentic systems safely when they are touching code, repositories, build systems, secrets, tickets, pull requests, and CI/CD workflows?

In this talk, I will explore the attack surfaces that agents open inside IDEs, coding agents, and CI/CD environments. I will walk through real bugs and exploit patterns found while researching agentic vulnerabilities across different products and environments over the last year.

You will leave being able to audit the agents in your own pipeline, with a clear read on which familiar controls quietly stop working the moment an agent, and not a person, is the one acting on untrusted input.
Speakers
avatar for Dan Lisichkin

Dan Lisichkin

AI Security Researcher, Pillar Security
Dan Lisichkin is the Cyber Security Researcher for Pillar Security, focusing on AI security, adversarial threats, and securing AI based systems. With over five years of experience in the cybersecurity and IT space, Dan has extensive knowledge in areas including malware analysis, reverse... Read More →
Thursday November 5, 2026 11:30am - 12:15pm PST
Room: Grand Ballroom A (Street Level)

1:15pm PST

Intent Contracts: Giving AI Agents the Missing Context for Safe Infrastructure Changes
Thursday November 5, 2026 1:15pm - 2:00pm PST

Speakers
avatar for Chris Wysopal

Chris Wysopal

Chief Security Evangelist & Co-founder, Veracode

Chris Wysopal is Veracode's Chief Security Evangelist and co-founder. He is one of the original vulnerability researchers and an early member of L0pht Heavy Industries, which he joined in 1992. He is the author of netcat for Windows and one of the authors of L0phtCrack. He has testified... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom A (Street Level)

2:15pm PST

The Compromised Maintainer Problem: Detecting Malicious Code in Legitimate Dependencies
Thursday November 5, 2026 2:15pm - 3:00pm PST
Supply chain attacks have changed. A few years ago the story was typosquatting and obviously sketchy packages with five downloads. Today it is the opposite. Attackers are going after the packages you already trust, the ones with millions of weekly installs and maintainers you have heard of. XZ Utils, the wave of npm maintainer account takeovers, self-replicating worms like Shai-Hulud, leaked PyPI tokens in public CI logs. The pattern is consistent and it is getting worse.

The hard part is that traditional tooling does not catch any of this. SCA scanners look for known CVEs, but there is no advisory yet. The package name is legitimate. The signature checks out. By the time the ecosystem catches up, the malicious version has already shipped to production for thousands of teams.

In this session we will share what we have learned building detection for these attacks across npm, PyPI, NuGet, and Go. We will walk through a few recent real incidents, the behavioral signals that gave them away (suspicious postinstall scripts, network callbacks, obfuscated payloads, anomalous maintainer activity), and why waiting for a CVE will always leave you exposed. From there we will get practical: pre install scanning, sandboxing build steps, lockfile pinning with provenance verification, and monitoring for dependency drift over time.

Attendees will leave with a clear mental model of how modern package attacks unfold, detection patterns they can apply to their own pipelines, and an honest read on where current tooling falls short. Aimed at AppSec engineers, platform teams, and developers who own anything in CI/CD or dependency policy.
Speakers
avatar for Polina Moshenets

Polina Moshenets

Security Engineer and Founder, SichGate
Polina Moshenets is a Security Engineer and Founder of SichGate, an AI model integrity testing company focused on safety and security evaluation of language models in highly regulated industries. Her background spans application security, supply chain risk in AI/ML pipelines, and... Read More →
avatar for Amro Haddadah

Amro Haddadah

Founder, CyberXYZ
Amro is the founder of CyberXYZ and a veteran of Microsoft’s DFIR team, where he spent five years investigating advanced cyber threats. He later led enterprise security as Principal Architect at Roche. Today, he’s building AI-native defenses to detect and stop zero-day attacks... Read More →
Thursday November 5, 2026 2:15pm - 3:00pm PST
Room: Grand Ballroom A (Street Level)

3:30pm PST

Model Context Points of Failure: MCP Security Meets Scale
Thursday November 5, 2026 3:30pm - 4:15pm PST
MCP servers are an integral part of our AI agents, coding assistants and LLMs. But how secure are they? Can we trust publicly deployed MCP servers? What about the MCP infrastructure itself?

This talk on MCP security will walk through a full from top to bottom MCP analysis, starting from the MCP source code, MCP protocol exploits, prompt injection, vulnerable MCP servers, vulnerabilities in public MCP servers, and weaponizing MCP servers.

Our research combines an analysis of over 18,000 MCP servers served on public registries, 3,000 open-source AI projects. We’ll share how we were able to find exploits on both public deployments serving MCP connectors, and taking over abandoned MCP servers.

We’ll go in depth on how multiple classes of vulnerabilities and issues which endanger the MCP ecosystem, from local command execution, unauthenticated remote command execution, attacking AI orchestration systems, MCP server information stealing, and even data sovereignty breaches. We’ll include demos and POCs, demonstrating how we exploited each vulnerability class one by one.

Finally, we’ll go over how to tackle those issues inside a living breathing organization, working with best practices to secure MCP deployments and connectors, how we can practically collect and block MCP configurations in scale, and what organizations can do to prevent the next breach.
Speakers
avatar for Moshe Siman Tov Bustan

Moshe Siman Tov Bustan

Security Research Team Leader, OX Security
Moshe is a Security Research Team Leader at OX Security, a company specializing in software supply chain security, and has worked in the security industry for 13 years. His work spans cloud security research, container security, memory forensics, and an in-depth understanding of programming... Read More →
Thursday November 5, 2026 3:30pm - 4:15pm PST
Room: Grand Ballroom A (Street Level)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -