BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: The Polymorphic Agent: From Cross Agent Escalation t
 o Just in\n   Time Defense on Azure\n   Tags: Cloud Village | Creator Talk
 /Panel\n   When: Friday\, Aug 7\, 15:30 - 16:10 PDT\n   Where: LVCCW Level
  3 W313 (Cloud Village Talks) - [1]Map\n\n   Description:\n\n   A permissi
 on error halts conventional malware. AI agents are being\n   assigned stan
 ding cloud IAM permissions and the autonomy to use them\,\n   a combinatio
 n that breaks an assumption every existing control depends\n   on. The age
 nt reasons its way to an escalation path through the cloud\n   provider's 
 own IAM APIs. We call this the polymorphic agent. This talk\n   presents r
 esearch cross-agent privilege escalation between independent\n   AI agents
  & defense around it.\n\n   The attack begins with a single poisoned tool 
 description\, rewritten\n   to read like routine compliance guidance. The 
 agent parses the\n   injected text\, reasons about it\, and grants itself 
 elevated IAM roles.\n   this showcases how a compromised Agent A modifies 
 the role assignments\n   of a separate Agent B\, running a different frame
 work in a seperate\n   environment and never issued a malicious instructio
 n\, expanding Agent\n   B's authority entirely through authorized IAM call
 s. This points\n   directly to two risks named in the OWASP MCP Top 10: Pr
 ivilege\n   Escalation via Scope Creep (MCP02)\, achieved through Tool Poi
 soning\n   (MCP03). To test whether this is agent-specific\, we ran the at
 tack\n   across three production agents\, including LangChain and Claude C
 ode.\n   All three escalated\, the pattern is consistent: prompt-layer\n  
  guardrails are reformable\, human approval is socially engineer-able\,\n 
   and telemetry arrives too late.\n\n   These results frame two requiremen
 ts for any workable defense: the\n   escalation must be measurable in real
  time\, and it must be blocked at\n   a point the agent cannot reach. Enfo
 rcement has to move to the\n   credential layer\, since an agent cannot ac
 t on the cloud without first\n   obtaining a credential. This is the gap P
 rivilegeGuard closes\, an\n   out-of-process credential gateway that inter
 cepts\n   DefaultAzureCredential and slots into existing agent deployments
  with\n   minimal to no code change.\n\n   On each token request\, it comp
 utes the requesting Non-Human\n   Identity’s Blast Radius Score (BRS): t
 he fraction of the cloud\n   resource surface reachable by that identity a
 cross a two-hop IAM graph\n   traversal\, providers reachable under curren
 t role assignments plus\n   those reachable after a simulated roleAssignme
 nts/write\n   self-escalation. PrivilegeGuard evaluates BRS and its rate o
 f change\n   against an Open Policy Agent (Rego) policy and denies an anom
 alous\,\n   high-blast-radius request before the escalated role is usable.
 \n\n   The takeaway is architectural: cross-agent escalation follows from\
 n   giving probabilistic\, goal-driven agents standing IAM credentials\, n
 ot\n   from any single agent or framework\, and it widens as agents gain\n
    access. We deliver the attack on real Azure identities\, and an\n   enf
 orcement model that stops it where the agent cannot follow: the\n   creden
 tial layer.\n\n   SpeakerBio:  Muskan Tomar\n\n   Hey\, I am Muskan Tomar\
 , a Security and Reliability Engineer at\n   MICROSOFT\, where I work at t
 he intersection of Site reliability\,\n   Infrastructure Security\, and So
 ftware Engineering building systems\n   that are expected to never go down
 \, stay secure\, and scale quietly in\n   the background. 5X Microsoft Azu
 re Certified \, with experience working\n   on architecting and modernisin
 g\, securing cloud platforms and reducing\n   operational toil through aut
 omation\, AI and data driven engineering.\n   My independent research focu
 ses on AI agent security and cloud\n   identity\, and how autonomous agent
 s change the threat model for\n   systems we trust to stay locked down. An
  enthusiastic learner who\n   champions collaborative cloud and security r
 esearch\, I enjoy\n   untangling complex systems and eliminating single po
 ints of failure.\n   Outside work\, I love to travel and paint.\n\n   '\n\
 n   1. #LVCCW_Level3_South\n\n\n
DTEND:20260807T231000Z
DTSTART:20260807T223000Z
LOCATION:Cloud Village - LVCCW Level 3 W313 (Cloud Village Talks)
SUMMARY:The Polymorphic Agent: From Cross Agent Escalation to Just in Time 
 Defense on Azure
END:VEVENT
END:VCALENDAR
