BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Trust Fall: How Agentic AI Inherits Your Cloud's Wor
 st IAM\n   Habits\n   Tags: Cloud Village | Creator Talk/Panel\n   When: F
 riday\, Aug 7\, 16:50 - 17:30 PDT\n   Where: LVCCW Level 3 W313 (Cloud Vil
 lage Talks) - [1]Map\n\n   Description:\n   Cloud IAM was designed for two
  principals: humans and machines. In\n   2026\, a third has arrived: the a
 utonomous AI agent and it plays by\n   neither rule book. AWS Bedrock Agen
 ts\, LangChain-based orchestrators\,\n   and multi-agent pipelines are bei
 ng deployed with execution roles\n   scoped to whatever the deploying engi
 neer thought was "good enough\,"\n   inheriting the same over-privileged I
 AM patterns that have plagued\n   cloud environments for a decade. The dif
 ference: agents don't just\n   misuse permissions accidentally. When adver
 sarial manipulations are\n   done\, they weaponize them with precision.\n\
 n   This talk dissects the threat model of agentic AI systems from an\n   
 attacker's perspective with a clear-eyed look at how autonomous agents\n  
  become cloud privilege escalation engines. Drawing from the OWASP Top\n  
  10 for Agentic Applications 2026\, MITRE ATLAS\, and real-world research\
 n   including Sonrai Security's AgentCore privilege escalation path and\n 
   Unit 42's confirmation of autonomous AI-driven cloud attacks\, the talk\
 n   walks through a complete attack chain: indirect prompt injection\n   a
 gainst an agent's context window → tool misuse via over-privileged\n   L
 ambda execution roles → IAM policy modification → persistent\n   backd
 oor creation — all without a single stolen credential.\n\n   Attendees w
 ill leave with a structured threat model mapped to MITRE\n   ATLAS tactics
 \, a dissection of what AWS CloudTrail catches versus what\n   it silently
  misses during agent-driven attacks\, a breakdown of the\n   three OWASP a
 gentic risks most directly applicable to AWS environments\n   (Goal Hijack
 \, Tool Misuse\, Identity & Privilege Abuse)\, and concrete\n   defensive 
 controls including agent-scoped least-privilege IAM\, Bedrock\n   Guardrai
 ls limitations practitioners need to know\, and\n   human-in-the-loop arch
 itectural patterns.\n\n   Speakers:Aravind Sreekanth Pallavoor\,Sadhana Sa
 inarayanan\n\n   SpeakerBio:  Aravind Sreekanth Pallavoor\n\n   Aravind Pa
 llavoor is a cybersecurity practitioner with over five years\n   of hands-
 on experience spanning application security\, cloud security\n   engineeri
 ng\, and offensive security research. He holds CISSP\, CEH\n   (v11)\, and
  AWS Certified Security – Specialty (SCS-C02)\n   certifications alongsi
 de a Master of Science in Cybersecurity\,\n   Technology and Policy from T
 he University of Texas at Dallas\, where he\n   graduated with a 3.82 GPA.
 \n\n   His offensive security background includes web application and API\
 n   penetration testing\, mobile application security\, AI chatbot securit
 y\n   assessments — including prompt injection and training data poisoni
 ng\n   research — and cloud infrastructure security across AWS\n   envir
 onments. He has conducted security assessments for global\n   financial in
 stitutions and enterprise SaaS organizations\, applying\n   frameworks inc
 luding OWASP\, CVSS\, MITRE ATT&CK\, NIST\, PCI DSS\, and CIS\n   Foundati
 ons.\n\n   On the cloud side\, Aravind has directly architected and audite
 d IAM\n   environments\, deployed and red-teamed compliance automation pip
 elines\,\n   and operationalized AWS Config\, Secrets Manager\, and CI/CD 
 pipeline\n   security at scale. His research interest at the intersection 
 of\n   agentic AI and cloud identity — the subject of this talk — grew
 \n   directly from real-world experience testing AI systems for adversaria
 l\n   manipulation and observing how autonomous tool use exposes cloud IAM
 \n   to a new class of attack surface.\n\n   "Trust Fall" represents his s
 ynthesis of those two worlds: offensive\n   AI security research applied t
 o the cloud IAM threat model\, grounded\n   in published vulnerability res
 earch\, OWASP's Agentic Top 10 for 2026\,\n   and MITRE ATLAS — and deli
 vered without a lab\, because the threat\n   model speaks for itself.\n\n 
   Additional Speaker Bio: Sadhana Sainarayanan is an AI and machine\n   le
 arning practitioner with deep expertise in autonomous pipeline\n   design\
 , event-driven system architecture\, MLOps\, and cloud-native AI\n   deplo
 yment across GCP and Azure environments. She holds a Google Cloud\n   Cert
 ified Professional Machine Learning Engineer certification and a\n   Micro
 soft Certified Azure AI Engineer Associate certification\,\n   alongside d
 ual Master's degrees from Carnegie Mellon University. Her\n   research int
 erests span the security implications of agentic AI\n   systems\, NLP pipe
 line trust boundaries\, and the input-validation gaps\n   that emerge when
  autonomous systems process external data at scale.\n   For this talk\, sh
 e brings the AI builder's perspective to the cloud\n   identity threat mod
 el.\n\n   Additional Speaker LinkedIn:\n   http://www.linkedin.com/in/sadh
 ana-sainarayanan\n\n   SpeakerBio:  Sadhana Sainarayanan\n\n   Sadhana Sai
 narayanan is a Cloud Platform Security Analyst with\n   experience across 
 SAP BTP security operations\, ML pipeline\n   productionization and AI sys
 tems. She holds dual master’s degrees\n   from Carnegie Mellon Universit
 y in Engineering and Technology\n   Innovation Management\, and Civil and 
 Environmental Engineering. Her\n   independent projects span instrumentati
 on for AI systems\, focused on\n   the gap between what agents report doin
 g and what they actually do\,\n   execution auditing\, and behavioral dive
 rgence detection.\n\n   '\n\n   1. #LVCCW_Level3_South\n\n\n
DTEND:20260808T003000Z
DTSTART:20260807T235000Z
LOCATION:Cloud Village - LVCCW Level 3 W313 (Cloud Village Talks)
SUMMARY:Trust Fall: How Agentic AI Inherits Your Cloud's Worst IAM Habits
END:VEVENT
END:VCALENDAR
