Session

AI Agents Under Attack: Breaking and Securing Autonomous AI Applications

AI agents are hitting production faster than security teams can keep up. They have tool access, persistent memory, API keys, and broad permissions, and most teams building them are focused on capability, not attack surface.

This session is a live teardown. We’ll stand up a deliberately vulnerable AI agent wired into GitHub, Slack, and document retrieval, and systematically exploit it. Not with jailbreaks or exotic prompt tricks, but with the kinds of architectural mistakes that show up in real systems: over-permissioned tools, unvetted retrieval sources, and implicit trust in model outputs.

You’ll watch credentials leak, unintended actions execute, and data flow where it shouldn’t all from decisions that looked reasonable at design time.

Then we fix it. Same app, different architecture. We’ll walk through what least privilege actually means for tool-calling agents, how to enforce policy controls on sensitive actions, where retrieval trust boundaries must exist, and when human-in-the-loop safeguards are required.

If you’re building or reviewing AI-powered systems, this is the threat model your design review is probably missing.

Sheshananda Reddy Kandula

Application Security (Web/Mobile), AI/ML/LLMs Security, Product Security

New York City, New York, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top