BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Exfil Everything: A Year of Stealing Data from AI Ag
 ents\n   Tags: Bug Bounty Village | Creator Talk/Panel\n   When: Saturday\
 , Aug 8\, 14:00 - 14:30 PDT\n   Where: LVCCW Level 2 W206-207 (Bug Bounty 
 Village) - [1]Map\n\n   Description:\n\n   For two decades\, XSS was the k
 ing of data theft — exploiting trust\n   boundaries in a victim's browse
 r to exfiltrate sensitive data and\n   perform malicious actions. AI-power
 ed interfaces have introduced new\n   ways to deliver XSS to victims along
 side an entirely new bug class\n   that has emerged as the most impactful 
 vulnerability pattern in modern\n   AI applications. The parallels between
  XSS and AI data exfiltration\n   are striking — both exploit trust boun
 daries to force a system into\n   performing unintended actions on behalf 
 of a victim but the attack\n   surface in AI is broader\, spanning web int
 erfaces\, mobile apps\,\n   wearables\, and any client consuming agent out
 put. The exfiltration\n   channels are diverse: markdown image rendering\,
  iframe and HTML tag\n   injection\, sandbox escapes\, native platform con
 nectors\, network\n   connectivity tools\, javascript: URI schemes\, link 
 unfurling side\n   channels\, MCP server poisoning\, and multi-step agent 
 tool-abuse\n   chains. In this talk\, two bug hunters who've spent the pas
 t year\n   exploiting these vulnerabilities across production applications
  break\n   it down and walk through real attack chains\, demonstrate how w
 e bypass\n   common mitigations and share the bypass techniques we've deve
 loped.\n   We'll cover how to threat model AI applications\, identify viab
 le\n   attack paths\, and select delivery mechanisms to weaponize end-to-e
 nd\n   exploits. Beyond offense\, we'll discuss the mitigations we've\n   
 encountered\, what actually works\, what doesn't\, and emerging trends in\
 n   agentic AI and autonomous tool use mean for the next wave of\n   vulne
 rabilities hunters should be watching for. Leave with: (1) a\n   clear men
 tal model of AI data exfiltration as a bug class and how it\n   relates to
  familiar web primitives\, (2) concrete attack techniques and\n   bypass m
 ethods\, (3) practical threat modeling for identifying exfil\n   paths in 
 AI agents and applications\, and (4) visibility into upcoming\n   trends a
 nd bug classes they should be hunting as AI systems gain more\n   autonomy
  and connectivity.\n\n   Speakers:Ads Dawson\,Mike "TakSec" Takahashi\n\n 
   SpeakerBio:  Ads Dawson\, Staff AI Security Researcher\, OWASP GenAI\n  
  Security Project founder\n\n   Ads Dawson founded the OWASP GenAI Securit
 y Project and led it to\n   flagship status — the fastest in OWASP histo
 ry. As a Staff AI\n   Security Researcher at Dreadnode\, he specializes in
  exploiting ML and\n   AI systems\, harnessing AI for offensive cybersecur
 ity through\n   capability development and exploit development\, and condu
 cting red\n   team operations against frontier models for government\, mil
 itary\, and\n   tier-1 labs. He is lead author of AIRTBench (arXiv)\, the 
 first\n   benchmark for autonomous AI red teaming in LLMs\, and author of 
 AI\n   Native LLM Security (Packt\, 2025).\n\n   A senior red team operato
 r with BT6 (the frontier AI red team)\, ranked\n   #2 in Canada on HackerO
 ne (2025/2026)\, and selected for Meta's MBBRC\n   live hacking event\, Ad
 s is a HackerOne US South Ambassador\, BugCrowd\n   Hacker Advisory Board 
 member\, MITRE AI Working Group contributor\, and\n   leads the OWASP Toro
 nto chapter. He spoke at Bug Bounty Village DC33\n   on the BT6 AI jailbre
 aking panel and is also presenting "Exfil\n   Everything: A Year of Steali
 ng Data from AI Agents" at Bug Bounty\n   Village DC34 (schedule pending p
 ublication).\n\n   SpeakerBio:  Mike "TakSec" Takahashi\, AI Red Team Rese
 archer\, Zenity\n\n   Mike Takahashi\, aka TakSec\, is an AI Red Team Rese
 archer at Zenity\;\n   member of BT6\; and Bug Bounty Hunter focused on br
 eaking AI systems.\n   He has submitted 400+ vulnerabilities across major 
 bug bounty programs\n   and top ranking on both Anthropic’s Safety Bug B
 ounty Program on\n   HackerOne and Mozilla’s 0din GenAI Bug Bounty Progr
 am. His work\n   targets prompt injection\, data exfiltration\, and AI age
 nt security.\n\n   '\n\n   1. #LVCCW_Level2_West\n\n\n
DTEND:20260808T213000Z
DTSTART:20260808T210000Z
LOCATION:Bug Bounty Village - LVCCW Level 2 W206-207 (Bug Bounty Village)
SUMMARY:Exfil Everything: A Year of Stealing Data from AI Agents
END:VEVENT
END:VCALENDAR
