BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Wrestling with a Python: Escaping Copilot Studio's A
 I-Guarded\n   Sandbox\n   Tags: DEF CON Official Talk | Demo ðŸ’» | Tool ð
 Ÿ›  | Exploit ðŸª²\n   When: Saturday\, Aug 8\, 15:30 - 16:30 PDT\n   Wher
 e: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - [1]Map\n\n   Descr
 iption:\n\n   Microsoft Copilot Studio lets anyone build AI agents that ex
 ecute\n   Python. Behind the scenes\, that code runs in a Windows containe
 r on\n   Azure Service Fabric\, wrapped in a Python sandbox and guarded by
  a\n   GPT-4.1 mini model that decides what's safe to run. Three layers of
 \n   defense. The presenter broke all of them.\n\n   Starting from a stand
 ard agent with code interpreter enabled\, we used\n   classic MRO introspe
 ction with string concatenation to bypass dunder\n   filters\, escaped Pyt
 hon entirely through pythonnet (which nobody\n   thought to block)\, and s
 ystematically defeated the LLM guardrail by\n   exploiting its leaked reas
 oning chain. The result: exfiltrated TLS\n   private keys and certificates
 \, 75 environment variables including\n   Azure AD client IDs and Service 
 Fabric cluster topology\, complete\n   application source code\, and confi
 rmed command execution as\n   ContainerUser.\n\n   The most interesting fi
 nding was the LLM guardrail itself. It is\n   non-deterministic: identical
  payloads sometimes pass and sometimes get\n   blocked. It leaks its full 
 security reasoning in the API response\,\n   turning the defender's AI int
 o an oracle for the attacker. This talk\n   walks through the full attack 
 chain\, demos a C2 tool that turns the\n   code interpreter into a persist
 ent shell\, and releases all tooling.\n\n     * Ned Batchelder\, "Eval rea
 lly is dangerous" (2012). Original\n       documentation of Python MRO int
 rospection for sandbox escape.\n\n     * Michael Bargury / Zenity\, "Livin
 g off Microsoft Copilot" (DEFCON\n       32\, Black Hat USA 2024). Prompt 
 injection and data exfiltration\n       through Copilot connectors. Differ
 ent attack surface from code\n       interpreter sandbox escape.\n\n     *
  Tobias Diehl\, "Mind the Data Voids: Hijacking Copilot Trust to\n       D
 eliver C2 Instructions" (DEFCON 33). Memory-persistent data\n       exfilt
 ration via M365 Copilot. Related but targets a different\n       feature a
 nd attack path.\n\n   Speakers:Ryan Hausknecht\,Simon Maxwell-Stewart\n\n 
   SpeakerBio:  Ryan Hausknecht\, BeyondTrust\n\n   Ryan Hausknecht is the 
 Director of Research at BeyondTrust Phantom\n   Labs. Ryan has an extensiv
 e background in red teaming\, detection\n   development\, and security res
 earch through his tenure at Microsoft and\n   Specterops. His most notable
  contibutions have been in cloud security\n   as the creator of PowerZure\
 , the Azure Threat Research Matrix\, and as\n   the co-author of AzureHoun
 d.\n\n   SpeakerBio:  Simon Maxwell-Stewart\, BeyondTrust\n\n   Simon Maxw
 ell-Stewart is a Staff Security Researcher at BeyondTrust's\n   Phantom La
 bs\, where he focuses on cloud platform security and the\n   emerging atta
 ck surface of enterprise AI systems. Before getting into\n   security he s
 pent over a decade doing data science and machine\n   learning\, with a ph
 ysics degree from Oxford and production ML work in\n   healthcare.\n\n   T
 hese days he's the resident graph nerd on the Phantom Labs team\,\n   appl
 ying graph analysis to identity security problems across Microsoft\n   clo
 ud environments. His recent research focuses on Entra ID attack\n   paths\
 , Azure infrastructure security.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\
 n
DTEND:20260808T233000Z
DTSTART:20260808T223000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Wrestling with a Python: Escaping Copilot Studio's AI-Guarded Sandb
 ox
END:VEVENT
END:VCALENDAR
