BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: No Prompt Required: Pre-Task RCE in Google Gemini CL
 I\n   Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   When: Sun
 day\, Aug 9\, 10:00 - 10:30 PDT\n   Where: LVCCW Level 1 Hall 3 906 (Main 
 Track 3) and DCTV-3 - [1]Map\n\n   Description:\n\n   Security research on
  AI agents starts at the prompt boundary -\n   injection\, jailbreaking\, 
 guardrails. This talk starts earlier.\n\n   AI agents accept inputs before
  the model processes its first task:\n   configuration files\, environment
  variables\, startup parameters\,\n   protocol handshakes. In CI/CD\, the 
 agent runs headless - no human in\n   the loop\, and the workspace is auto
 matically trusted. These inputs can\n   reach shell execution or disable s
 ecurity controls before any\n   prompt-time safeguard activates. The secur
 ity model is already\n   compromised before the model does anything.\n\n  
  This talk demonstrates the pattern with a flagship exploit scored CVSS\n 
   10.0 by Google's security team - publicly disclosed and patched. The\n  
  exploit is deterministic\, requires no model interaction\, and fires\n   
 before the sandbox starts. An additional case from a different vendor\n   
 confirms this is not a one-off.\n\n   Attendees leave with a reusable offe
 nsive method for any AI agent\n   system: enumerate what the system accept
 s before work begins\, map what\n   authority each input carries\, and tes
 t whether that authority reaches\n   execution or policy control. If it do
 es\, prompt-time defenses are\n   irrelevant.\n\n   https://github.com/goo
 gle-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g\
 n\n   SpeakerBio:  Elad Meged\, Novee Security\n\n   Elad Meged is a Found
 ing Engineer and Security Researcher at Novee\n   Security\, specializing 
 in offensive security research and AI security.\n   He holds an M.Sc. in C
 omputer Science and has a background in\n   vulnerability research across 
 web\, mobile\, and low-level systems\, with\n   experience in reverse engi
 neering and platform internals. His current\n   work applies offensive res
 earch methodology to AI systems while\n   developing AI-driven approaches 
 to vulnerability discovery and exploit\n   verification.\n\n   '\n\n   1. 
 #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T173000Z
DTSTART:20260809T170000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:No Prompt Required: Pre-Task RCE in Google Gemini CLI
END:VEVENT
END:VCALENDAR
