BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Pwning Agentic Browsers with PleaseFix: A New Vulner
 ability\n   Class for 0-Click Takeover\n   Tags: AI Village | Creator Talk
 /Panel\n   When: Sunday\, Aug 9\, 12:00 - 12:30 PDT\n   Where: LVCCW Level
  1 Hall 3 1105 (Creator Stage 3) - [1]Map\n\n   Description:\n   Every maj
 or AI lab now ships an agentic browser: ChatGPT Atlas\,\n   Perplexity Com
 et\, Claude in Chrome\, Gemini in Chrome\, and Microsoft\n   Copilot Actio
 ns. To make them work\, vendors intentionally relax thirty\n   years of br
 owser security. Atlas loosens Same-Origin Policy\, Gemini\n   and Edge add
  localhost access\, Comet opens the filesystem\, and Claude\n   runs scrip
 ts on any site. The main defense is model safety training.\n   These are d
 esign choices\, not bugs\, reviving XSS\, sandbox escapes\, and\n   drive-
 by exploitation.\n\n   We ran the first cross-platform analysis of all fiv
 e. We introduce\n   PleaseFix\, a new agent-targeting vulnerability class 
 (the evolution of\n   ClickFix)\, exploited via Intent Collision\, which m
 erges attacker\n   content with the user's request into one plan the agent
  cannot\n   untangle. We also present HistoryFixing\, which weaponizes a f
 unction\n   shipped in every browser since 2008 to poison the browsing his
 tory\n   agents trust as ground truth.\n\n   Walk up to learn the agentic-
 browser threat model\, the\n   vulnerabilities\, and which were agent-spec
 ific versus consistent\n   across all five. You will see how we chained In
 tent Collision and\n   HistoryFixing\, from zero-click vectors (poisoned t
 weet\, calendar\n   invite)\, to conduct RCE\, reverse shells\, data exfil
 tration and\n   poisoning\, filesystem theft\, account takeovers (Slack\, 
 X\, 1Password\,\n   Claude)\, rogue actions on MFA-gated sites\, unauthori
 zed Amazon\n   purchases\, malicious collaborators added to your private e
 nterprise\n   GitHub\, and more. We link videos of every attack. We break 
 down the\n   soft versus hard boundaries each vendor built\, what failed a
 nd what\n   held: only deterministic\, code-level defenses stopped us. All
  findings\n   responsibly disclosed.\n\n   SpeakerBio:  Stav Cohen\n\n   S
 tav Cohen is an AI Security Research Lead at Zenity and a PhD student\n   
 at the Technion\, Israel Institute of Technology. His research focuses\n  
  on breaking\, and then fixing\, AI agents\, spanning security\n   vulnera
 bilities across agentic AI systems\, LLM-powered applications\,\n   and en
 terprise AI platforms. He discovers new attack vectors\, develops\n   reme
 diation strategies\, and works to drive the industry toward\n   stronger s
 ecurity practices. His offensive security work spans attacks\n   on RAG pi
 pelines\, multi-agent delegation protocols\, agentic browsers\,\n   and pr
 oduction-scale GenAI systems. He introduced the concept of\n   Promptware:
  a new class of inference-time threats that exploit GenAI\n   models throu
 gh malicious prompts\, turning them from helpful assistants\n   into tools
  for data exfiltration\, lateral movement\, and even\n   physical-world co
 nsequences. He presents his findings at leading\n   security venues across
  the world. His PhD research focuses on the\n   secure integration of Gene
 rative AI into real-world infrastructure\,\n   particularly Cyber-Physical
 -Human Systems involving human-in-the-loop\n   interactions\, such as smar
 t water networks and GenAI-powered virtual\n   assistants. He explores how
  GenAI agents can be safely and effectively\n   integrated into these envi
 ronments to support real-time\n   decision-making\, anomaly detection\, an
 d human-machine collaboration.\n   He is also a thought leader in the AI s
 ecurity space\, sharing\n   knowledge through conference talks\, blog post
 s\, and community\n   engagement.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n
 \n
DTEND:20260809T193000Z
DTSTART:20260809T190000Z
LOCATION:AI Village - LVCCW Level 1 Hall 3 1105 (Creator Stage 3)
SUMMARY:Pwning Agentic Browsers with PleaseFix: A New Vulnerability Class f
 or 0-Click Takeover
END:VEVENT
END:VCALENDAR
