Session
The Agent Identity: No Passwords. All Privilege
For years, Kubernetes security focused on a well-defined boundary: securing human identities (users) and machine identities (service accounts, workloads).
But the rapid adoption of autonomous AI agents operating via the Model Context Protocol (MCP) has completely shattered this paradigm. Today, agents possess the autonomy to call tools, query databases, and execute code.
In modern enterprise clusters, the AI agent is the new identity. However, this new identity class lacks a traditional password or token to protect it. When an agent is compromised via indirect prompt injection such as the zero-click Copilot exfiltration seen in the EchoLeak (CVE-2025-32711) espionage campaign attackers aren't bypassing firewalls; they are hijacking the agent's identity and abusing its trust.
With prompt injection attacks surging 340% Year-over-Year and massive breaches striking organizations due to unmanaged "Shadow AI" identities deployed without proper visibility or authentication, we are facing a fundamental identity crisis in the cloud-native ecosystem.
This talk moves beyond basic perimeter checks to establish a new "Identity and Access Management (IAM)" philosophy for AI. We will uncover how to discover hidden agent identities using shadow ai discovery, detect runtime behaviour of agents, and enforce remediation in case of any drift. Using eBPF-powered runtime security (via KubeArmor), we will demonstrate how to physically sandbox an agent's runtime environment, ensuring that even if an agent's identity is socially engineered, its blast radius is entirely contained.
Gaurav Kumar Mishra
Principal Product Manager, AccuKnox
Delhi, India
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top