transcript
show notes
Pushing browsers to the limit
Abusing Modern Browser Features for Phishing
Alexander Hurbean
Committing CSS Crimes for fun and profit
Lyra Rebane
Improving the Trustworthiness of Javascript on the Web
Ezzudin Alkotob, Giulio Berra, Benjamin Beurdouche, Richard Hansen, Daniel Huigens, Dennis Jackson, Cory Francis Myers, and Michael Rosenberg
LLMs standing tall
Black-hat LLMs
Nicholas Carlini
On the Coming Industrialisation of Exploit Generation with LLMs
Sean Heelan
AI Security with Guarantees
Ilia Shumailov
200 Bugs/Week/Engineer: How We Rebuilt Trail of Bits Around AI
Dan Guido
Systematic debugging for AI agents: Introducing the AgentRx framework
Shraddha Barke, Arnav Goyal, Alind Khare, and Chetan Bansal
LLMs taking a fall
Trust Me, I Know This Function: Hijacking LLM Static Analysis using Bias
Shir Bernstein, David Beste, Daniel Ayzenshteyn, Lea Schönherr, and Yisroel Mirsky
AI Agent Traps
Matija Franklin, Nenad Tomašev, Julian Jacobs, Joel Z. Leibo, and Simon Osindero
[Paper]
Leaking secrets from the claud
Niels Hofmans
Scary Agent Skills: Hidden Unicode Instructions in Skills ...And How To Catch Them
wunderwuzzi
Nifty sundries
Data Honeytokens for the Cloud Era
Petrus Vasenius
The Offense Death Cycle: Proactive Environmental Control as a Method of Persistent Cyber Defense
Volodymyr Styran
[Paper]
The AWS Console and Terraform Security Gap
Laurence Tennant
The Limit Is the Sky… (Or Not)?
Antonio Nappa
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
Google Threat Intelligence Group
links37