Gaurav Kumar Mishra

Gaurav Kumar Mishra

Principal Product Manager, AccuKnox

Delhi, India

Actions

Product Manager and Security Leader with 10+ years of experience spanning AI Security, Cloud-Native Security, DevSecOps, Kubernetes Security, and Telecom Cloud platforms. Led the design and launch of enterprise AI Security solutions including Hybrid Cloud AI Security, Shadow AI Discovery, AI Red Teaming, Stateful Prompt Firewalling, and GenAI-powered security applications. Proven track record in defining product strategy, driving cross-functional execution, and delivering code-to-cloud security capabilities across AWS, Azure, GCP, and Kubernetes environments. Passionate about building innovative security products that help organizations govern, secure, and operationalize AI at scale while maintaining compliance, resilience, and business agility.

Area of Expertise

  • Information & Communications Technology

Topics

  • Kubernetes Security
  • Cloud App Security
  • Cloud Security Architecture
  • AI and Cybersecurity
  • Cloud Security
  • Azure Security
  • Artificial Intelligence and Machine Learning for Cybersecurity
  • Application Security
  • Security & Compliance

A Multi-Layered Defense-in-Depth Strategy for Agentic AI

The evolution of artificial intelligence has moved rapidly from static LLMs to fully autonomous agentic architectures operating via the Model Context Protocol (MCP). While these agents introduce unprecedented capabilities, they also introduce a massive, complex attack surface. Prompt injection attacks alone surged by 340% Year-over-Year into 2026, with devastating real-world impacts ranging from the EchoLeak zero-click espionage campaign to widespread data breaches resulting from completely unmanaged "Shadow AI" instances.

Traditional single-turn perimeter filters and stateless guardrails are fundamentally failing against sophisticated threats like multi-turn crescendo attacks and indirect injection. True security requires a shift towards a defense-in-depth paradigm tailored specifically for the AI stack.

This session will dissect a comprehensive, five-layer security framework designed to protect AI agents throughout their entire lifecycle. We will explore the critical progression of securing AI applications: beginning with total asset discovery across hybrid clouds to eliminate unmanaged shadow systems, utilizing adaptive, goal-based red teaming, and deploying stateful, session-aware prompt firewalls that track conversation intent drift. Finally, we will dive deep into runtime workload security, demonstrating how to use eBPF-powered tools to enforce in-kernel agent sandboxing, successfully containing automated privilege escalation

The Agent Identity: No Passwords. All Privilege

For years, Kubernetes security focused on a well-defined boundary: securing human identities (users) and machine identities (service accounts, workloads).

But the rapid adoption of autonomous AI agents operating via the Model Context Protocol (MCP) has completely shattered this paradigm. Today, agents possess the autonomy to call tools, query databases, and execute code.

In modern enterprise clusters, the AI agent is the new identity. However, this new identity class lacks a traditional password or token to protect it. When an agent is compromised via indirect prompt injection such as the zero-click Copilot exfiltration seen in the EchoLeak (CVE-2025-32711) espionage campaign attackers aren't bypassing firewalls; they are hijacking the agent's identity and abusing its trust.

With prompt injection attacks surging 340% Year-over-Year and massive breaches striking organizations due to unmanaged "Shadow AI" identities deployed without proper visibility or authentication, we are facing a fundamental identity crisis in the cloud-native ecosystem.

This talk moves beyond basic perimeter checks to establish a new "Identity and Access Management (IAM)" philosophy for AI. We will uncover how to discover hidden agent identities using shadow ai discovery, detect runtime behaviour of agents, and enforce remediation in case of any drift. Using eBPF-powered runtime security (via KubeArmor), we will demonstrate how to physically sandbox an agent's runtime environment, ensuring that even if an agent's identity is socially engineered, its blast radius is entirely contained.

Inside Agentic AI on Kubernetes: Runtime Visibility and Policy Enforcement

As AI systems evolve into agentic workflows, they move beyond simple inference APIs. Modern agents can invoke tools, interact with external systems, and execute multi-step reasoning chains. When deployed on Kubernetes, this introduces new challenges in observability, control, and runtime security.

Traditional monitoring approaches are not enough to explain agent behavior. Logs and metrics alone cannot answer key questions: What actions did the agent take? Which services or tools were invoked? Did execution remain within expected boundaries? Was sensitive data exposed?

This session focuses on building runtime visibility and policy enforcement for agentic AI workloads on Kubernetes. We will explore how OpenTelemetry can trace agent workflows across distributed services and how KubeArmor can enforce runtime policies at the container level to prevent unsafe execution.

We will also discuss Kubernetes-native guardrails such as namespaces, RBAC, and workload isolation to reduce blast radius and maintain control in production environments.

Through practical architectural patterns, attendees will learn how to transform opaque, black-box AI systems into observable, accountable, and secure agent workloads running in cloud-native environments.

Beyond the Prompt: A Multi-Layered Defense-in-Depth Strategy for Kubernetes AI Agents

The evolution of artificial intelligence has moved rapidly from static LLMs to fully autonomous agentic architectures operating via the Model Context Protocol (MCP). While these agents introduce unprecedented capabilities, they also introduce a massive, complex attack surface. Prompt injection attacks alone surged by 340% Year-over-Year into 2026, with devastating real-world impacts ranging from the EchoLeak zero-click espionage campaign to widespread data breaches resulting from completely unmanaged "Shadow AI" instances.

Traditional single-turn perimeter filters and stateless guardrails are fundamentally failing against sophisticated threats like multi-turn crescendo attacks and indirect injection. True security requires a shift towards a defense-in-depth paradigm tailored specifically for the AI stack.

This session will dissect a comprehensive, five-layer security framework designed to protect AI agents throughout their entire lifecycle. We will explore the critical progression of securing AI applications: beginning with total asset discovery across hybrid clouds to eliminate unmanaged shadow systems, utilizing adaptive, goal-based red teaming, and deploying stateful, session-aware prompt firewalls that track conversation intent drift. Finally, we will dive deep into runtime workload security, demonstrating how to use eBPF-powered tools to enforce in-kernel agent sandboxing, successfully containing automated privilege escalation and code execution at the container layer.

Gaurav Kumar Mishra

Principal Product Manager, AccuKnox

Delhi, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top