BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Data Tomb Raider: Raiding Modern AI Vaults with Lega
 cy Flaws\n   for Treasure Stealing\n   Tags: DEF CON Official Talk | Demo 
 💻 | Exploit 🪲\n   When: Friday\, Aug 7\, 15:00 - 15:59 PDT\n   Where
 : LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - [1]Map\n\n   Descri
 ption:\n\n   Click a link\, lose your MFA codes. Your AI assistant reads y
 our email\n   and exfiltrates the data through Bing\, and you never notice
 .\n\n   We found a 1-click attack chain against Microsoft 365 Copilot that
 \n   combines three vulnerability classes everyone assumed were solved -\n
    CSP\, SSRF\, and HTML injection - into one kill shot. A URL parameter\n
    lands directly in the AI engine as an executable prompt\, a vector we\n
    call Parameter-to-Prompt (P2P) injection. The AI searches the victim's\
 n   mailbox\, grabs sensitive data\, and emits an img tag with the loot in
 \n   the URL. That tag renders mid-stream\, before the output sanitizer\n 
   fires\, because sanitization is a post-processing step. The img src\n   
 hits Bing's Search by Image endpoint - CSP-allowlisted - which\n   server-
 side fetches to our domain\, tunneling stolen data through\n   Microsoft's
  own infrastructure.\n\n   CSP enforced. Sanitizer running. AI guardrails 
 active. All three\n   defenses in place - the chain walked right through t
 hem. None of these\n   bugs are new. Each has textbook mitigations. But no
 body tests what\n   happens when old web bugs compose with AI behaviors - 
 web teams and AI\n   teams don't test each other's seams. We break down th
 e full chain\,\n   demo it live\, and hand you a methodology for hunting c
 omposition bugs\n   across AI-integrated platforms.\n\n   Speakers:Dolev T
 aler\,Mark Vaitsman\n\n   SpeakerBio:  Dolev Taler\, Varonis\n\n   Dolev T
 aler is a senior security researcher at Varonis Threat Labs\n   with over 
 a decade of cybersecurity experience spanning red teaming\,\n   reverse en
 gineering\, vulnerability research\, and malware analysis. He\n   is passi
 onate about machine learning and its pivotal role in modern\n   threat det
 ection\, having developed advanced detection models\,\n   investigated ran
 somware attacks for major global enterprises\, and\n   reported vulnerabil
 ities in critical infrastructure systems. Beyond\n   tackling high-stakes 
 cyber threats\, Dolev also enjoys perfecting the\n   art of coffee brewing
  and improving his lock-picking skills.\n\n   SpeakerBio:  Mark Vaitsman\,
  Varonis\n\n   Mark Vaitsman is a Security Research Team Leader at Varonis
 \, a leader\n   in Data Security. He is a passionate cybersecurity expert 
 with\n   extensive experience in leading security threat and research team
 s in\n   various Cyber Security companies\, analyzing emerging threats\, i
 ncident\n   response and developing innovative solutions. Mark is also a l
 ecturer\n   of Cyber Security courses\, sharing his knowledge and shaping 
 the next\n   generation of cybersecurity professionals. Previously spoken 
 at\n   BlackHat\, DeepSec\, RSAC\, CrestCon. In his free time he likes sai
 ling\n   in the sea and riding a motorcycle.\n\n   '\n\n   1. #LVCCW_Level
 1_Hall3\n\n\n
DTEND:20260807T225900Z
DTSTART:20260807T220000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Data Tomb Raider: Raiding Modern AI Vaults with Legacy Flaws for Tr
 easure Stealing
END:VEVENT
END:VCALENDAR
