BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: LGTM: Bypassing an LLM Build Gate When Prompt Inject
 ion Fails\n   Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   W
 hen: Friday\, Aug 7\, 13:00 - 13:59 PDT\n   Where: LVCCW Level 1 Hall 3 90
 3 (Main Track 5) and DCTV-5 - [1]Map\n\n   Description:\n\n   Models are s
 tarting to make security decisions that used to be written\n   as rules. I
 nstead of matching an input against a policy\, a model reads\n   the reque
 st and decides what to do with it. OpenSearch is one of the\n   first to p
 ut one in production as the only thing standing between an\n   anonymous p
 ull request and CI pipeline secrets.\n\n   When I reported a vulnerability
 \, the team told me their model would\n   catch it. So I tried to get past
  it the way you'd expect\, hiding the\n   attack. The model caught all of 
 it\, and going at it head-on wasn't\n   going to work.\n\n   So I stopped 
 trying to outsmart it and started thinking like it\,\n   reading why each 
 attempt got caught until I understood what it could\n   actually verify an
 d what it only assumed. What got through in the end\n   hid no attack\, be
 cause the only dangerous part lived somewhere the\n   model had no way to 
 check.\n\n   This talk walks the whole path\, from first failed attempt to
  the\n   bypass that worked. Along the way I mapped the model's decision\n
    boundary - what it catches\, what slips past\, and how far an input\n  
  bends before its judgment flips. The deeper gap is what it never sees\n  
  at all\, the blind spots built into how it reads a change. You'll see\n  
  where a model can be trusted to make this call and where it can't\, and\n
    what that means before you put one in front of something that matters.\
 n\n   https://github.com/opensearch-project/security-response/security/adv
 isories/GHSA-2vmh-cgjm-h48x\n   - Original pull_request_target vulnerabili
 ty advisory\n\n   https://github.com/opensearch-project/security-response/
 security/advisories/GHSA-q72p-66hv-cc73\n   - LLM gateway bypass advisory\
 n\n   https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents -\n 
   Prompt injection attacks against AI code review bots (different attack\n
    class)\n\n   https://www.wiz.io/blog/six-accounts-one-actor-inside-the-
 prt-scan-supply-chain-campaign\n   - 500+ AI-generated malicious PRs targe
 ting pull_request_target across\n   hundreds of repos\, including the one 
 repo we discuss in this talk\n\n   https://www.404media.co/hackers-simply-
 asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-wo
 rked/\n   - Meta AI support system flaw\n\n   SpeakerBio:  Aviv Donenfeld\
 , Check Point Software Technologies\n\n   Aviv Donenfeld is a Security Res
 earcher at Check Point Software\n   Technologies. Before security research
 \, he built distributed\n   networking systems as a software engineer. His
  recent research centers\n   on the attack surfaces of AI coding assistant
 s\, including critical\n   vulnerabilities in Anthropic's Claude Code and 
 Cursor. He has found\n   CI/CD supply chain vulnerabilities in Microsoft\,
  SAP\, Red Hat\, and\n   multiple Linux Foundation projects. Beyond offens
 ive research\, he\n   builds defensive security tools in the AI and forens
 ics space.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T205900Z
DTSTART:20260807T200000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails
END:VEVENT
END:VCALENDAR
