BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Your WAF Blocked Us\, That Was The Exploit - Remote 
 Agent\n   Takeover via Cloudflare\, Sentry and Claude Zero-Day for data ex
 fil\n   Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   When: S
 unday\, Aug 9\, 12:00 - 12:59 PDT\n   Where: LVCCW Level 1 Hall 3 1006 (Ma
 in Track 1) and DCTV-1 - [1]Map\n\n   Description:\n\n   What happens when
  getting blocked by your WAF is exactly how the\n   attacker gets in? We b
 uilt two new remote exploit chains that hijack\n   AI agents through Cloud
 flare and Sentry - two of the most trusted\n   tools on the internet. No m
 alware. No binary exploits. The attacker\n   never touches the victim or t
 heir agent. Just text in public logs\,\n   waiting to be read. Chain 1: We
  send requests Cloudflare blocks with\n   403 - and that is the attack. Ou
 r payloads land in WAF logs. When a\n   dev asks their agent to debug Clou
 dflare\, injections activate via\n   cloudflare queries. Using only Cloudf
 lare's own MCP tools\, we hijack\n   DNS and reroute customer traffic. Cha
 in 2: We inject stacktraces into\n   Sentry's public API\, no auth needed.
  Sentry's "Seer" agent reads them\,\n   gets compromised\, and its poisone
 d recommendations flow into a\n   developer's Cursor which executes our co
 mmands. One agent infecting\n   another. First demo of agent-to-agent late
 ral movement and\n   "Self-Exploiting Agent" technique. Then we go deeper:
  a zero-day in\n   Claude bypasses its network sandbox for full data exfil
 tration. For\n   persistence\, we show how "agentic rootkits" work by memo
 ry injection\n   and config poisoning\, invisible to EDRs. est 15\,000+ or
 ganizations\n   exposed via Cloudflare MCP alone. 27% of them are Fortune 
 1000.\n   Responsibly disclosed. We're now showing everything.\n\n   *Clou
 dflare MCP Server documentation and public deployment *Sentry MCP\n   Serv
 er and Seer AI agent documentation *Anthropic Claude Desktop\n   applicati
 on architecture *Cursor AI coding agent - MCP integration and\n   tool arc
 hitecture *OWASP Top 10 for LLM Applications (2025) *MITRE\n   ATLAS - Adv
 ersarial Threat Landscape for AI Systems *Clinejection (Feb\n   2026) - Gi
 tHub issue title exploit compromising Cline's release\n   pipeline *Commen
 t & Control (Apr 2026) - prompt injection via PR\n   titles leaking secret
 s from Claude Code\, Gemini CLI\, and Copilot\n\n   Speakers:Barak Sternbe
 rg\,Nevo Poran\,Ron Bobrov\n\n   SpeakerBio:  Barak Sternberg\, Tenet Secu
 rity\n\n   Barak Sternberg is a cybersecurity researcher\, offensive secur
 ity\n   specialist\, and a returning DEFCON speaker. His research career s
 pans\n   over 15 years across every major attack surface of the last decad
 e:\n   from IoT to browser extension exploits (DEFCON 29)\, to Kube infra\
 n   attacks (with Nevo)\, to smart device hacking (DEFCON Safe Mode IoT\n 
   Village). He's presented at DEFCON (twice)\, Hacktivity\, RootCon\,\n   
 BSides\, Intent\, and numerous other security conferences worldwide.\n   H
 e's a Unit 8200 veteran and Israel Defense Prize recipient. His\n   resear
 ch has consistently focused on finding novel attack chains in\n   emerging
  technology before attackers do\, across years in offensive\n   cybersecur
 ity. He also co-founded Wild Pointer (offensive security\,\n   Fortune 500
  clients) and more recently co-founded Tenet Security as\n   CEO with Nevo
 : but the research came first\, the company came from the\n   research\, n
 ot the other way around. He leads Tenet while staying\n   hands-on - the e
 xploit chains in this talk came directly from his\n   team's research\n\n 
   SpeakerBio:  Nevo Poran\n\n   Nevo Poran\, cybersecurity researcher\, Co
 -Founder & CTO of Tenet\n   Security\, and a top-tier security engineer fo
 cused on GenAI\, API\, and\n   application security. Unit 8200 veteran and
  2x Excellence Awards. Nevo\n   co-founded Wild Pointer with Barak\, servi
 ng as technical lead and\n   later CEO\, managing teams delivering offensi
 ve R&D to Cisco\, Noname\n   Security\, and Fortune 500 clients. He then c
 o-led Cisco's first GenAI\n   Security Research Team - building the AI Def
 ense product from research\n   through production. Deep hands-on expertise
  in reverse engineering\,\n   exploit development\, and agent runtime secu
 rity. Speaks on\n   Kubernetes/cloud and GenAI security (CyberArk INTENT 2
 024\, UNC\n   Symposium 2025) and co-presented the Kubernetes etcd exploit
 ation\n   research with Barak. They've been breaking things together for y
 ears.\n\n   SpeakerBio:  Ron Bobrov\, Tenet Security\n\n   Ron Bobrov is a
  senior security researcher at Tenet Security with 10\n   years of experie
 nce in offensive security\, penetration testing\, and\n   vulnerability re
 search. He has specialized in emerging attack vectors\n   and has recently
  focused on AI agent security\, conducting red-team\n   assessments that h
 ave uncovered critical vulnerabilities in modern\n   LLM-based systems. At
  Tenet Security\, Ron leads research initiatives\n   exploring the interse
 ction of traditional security threats and\n   AI-specific attack surfaces.
  His work on bypassing A2AS framework\n   protections has revealed fundame
 ntal architectural gaps in current AI\n   agent security approaches\, cont
 ributing to the development of runtime\n   protection methodologies for ag
 entic systems. Ron's research combines\n   deep technical expertise in sys
 tem exploitation with novel approaches\n   to adversarial AI security\, he
 lping organizations understand and\n   defend against the next generation 
 of attacks targeting AI agents in\n   production environments.\n\n   '\n\n
    1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T195900Z
DTSTART:20260809T190000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1006 (Main Track 1) and DCTV-
 1
SUMMARY:Your WAF Blocked Us\, That Was The Exploit - Remote Agent Takeover 
 via Cloudflare\, Sentry and Claude Zero-Day for data exfil
END:VEVENT
END:VCALENDAR
