Loading…
Tuesday October 6, 2026 15:45 - 16:00 IDT
A single fake bug report, planted in ordinary Sentry telemetry, drove the AI coding agents of more than 100 organizations, including a Fortune 100 technology company, to run attacker code with the developer's own privileges. Success rate: 85%. Controls that fired: zero. This was our Agentjacking research.
Faced with this, security teams are reaching for a new generation of in-context guardrails, prominently A2AS (Behavior Certificates, Authenticated Prompts, Security Boundaries, In-Context Defenses, and Codified Policies), backed by OpenAI, Google, and Anthropic. These controls are built to catch exactly this: instructions smuggled in as untrusted data. This session shows they are not enough.
The technique hides malicious instructions inside data the agent already trusts: a tool response, an MCP return, a line of telemetry. The agent reads it, acts on it, and reports normal operation. Every step is authorized, so perimeter and policy controls stay silent. We take this straight at A2AS and bypass its controls to reach code execution and credential access.
The root cause is structural: agents cannot separate data from instructions, and no static guardrail changes that. Runtime enforcement is the only layer that stops it. Walkthrough and real attack logs included.
Speakers
avatar for Nevo Poran

Nevo Poran

CTO, Tenet Security
Nevo Poran is co-founder and CTO of Tenet Security, where he leads the research and engineering behind its platform for securing autonomous AI agents as they act. Before Tenet, he was part of the founding team of Cisco's AI Defense and led some of the first agent-security research... Read More →
Tuesday October 6, 2026 15:45 - 16:00 IDT
Keynote Hall

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link