Session Catalog
Filter by
Reset
Amphitheatre
For years, the cybersecurity community warned of the impending AI arms race. In 2026, we are in the middle of it. Adversaries are actively leveraging generative AI to automate reconnaissance, dynamically mutate malware, and craft hyper-personalized social engineering campaigns at unprecedented speed. But the defense has a massive structural advantage: scale and intelligence.
In this opening comments, we will reveal how Mandiant consultants are leveraging AI to change the game for defenders and incident responders. We will explore how Mandiant and Google Cloud are turning the tide by integrating hyper-scale AI directly into our tools and methodologies to stay ahead of the Threat Actors and empower our clients with machine speed defense, giving defenders the ultimate high ground.
Amphitheatre
The era of manual cyberattacks is giving way to the rise of autonomous adversary agents that operate at speeds manual security processes simply cannot match. In this presentation, Sandra Joyce, VP of Google Threat Intelligence breaks down how threat actors are leveraging AI to scale their operations and heighten attack sophistication. Beyond AI-enabled exploits, the rapid integration of AI across organizations has fundamentally altered the threat landscape, introducing critical points of failure and expanding supply chain surfaces.
With reactive security models no longer viable against these rising stakes, it is critical for the security community to embrace new approaches. This session will outline the need to transition to a posture of active, proactive disruption to neutralize threats.
Amphitheatre
Join incident responders for a deep dive into recent data breaches, both internal and within the supply chain. We'll explore how these incidents unfolded, and communication strategies used with leadership, employees, media, and the board. Leave with actionable takeaways to bring back to your own security discussions.
Amphitheatre
In the agentic era, the traditional tension between development velocity and security control is evolving. As automated agents transform business operations, relying on manual security verification is no longer viable against the machine-speed of modern cyber threats. Google advocates for building durable trust through automated defenses, integrating hardware-based controls, safe coding principles, and intent-based authorization to secure intelligent applications against the rapid, AI-driven risks of the modern cybersecurity landscape.
Amphitheatre
AI has already changed how intrusions play out. What’s different now is speed. Incident responders are seeing attacks where reconnaissance, exploitation, and movement across environments can compress into minutes. At the same time, companies are deploying AI and agentic systems without fully understanding the risk they introduce.
This panel brings together CISOs, a Mandiant incident response professional, and a cyber and AI lawyer in private practice to focus on what this looks like in real incidents. The discussion draws from active breaches, regulatory pressure, and the tradeoffs teams are making now.
Systems can identify vulnerabilities, generate exploits, and chain attack paths with limited human input. The gap between discovery and exploitation is shrinking. Agentic AI adds another layer, with systems acting across enterprise environments.
Panelists will walk through how this is showing up in incident response, including faster access handoffs, identity-driven compromise, and automated workflows. The session will also cover governance, including how to set guardrails, manage accountability, and align response decisions with legal obligations.
Panelists will cover how to brief boards and senior leadership on AI-driven risk under compressed timelines, including how to communicate evolving facts and automation-related uncertainty, and how to coordinate with industry peers and law enforcement as AI-enabled attacks scale and outpace traditional response models. Attendees will leave with practical steps to reassess response readiness, tighten AI governance, and adapt to a faster threat environment.
Atrium Ballroom B
This session deconstructs a frontline investigation into a highly targeted campaign by the North Korean threat actor UNC4899, which resulted in a $14 million theft from a cryptocurrency exchange. We trace the complete attack lifecycle, beginning with initial access achieved when the adversary delivered a trojanized Django log monitoring application via AirDrop. By exploiting a Python pickle deserialization flaw, the attackers compromised a developer's macOS endpoint and subsequently hijacked active VPN sessions to silently maneuver into the organization's Google Cloud Platform (GCP) environment. Rather than relying on zero-day exploits, UNC4899 abused existing developer permissions to maliciously patch Google Kubernetes Engine (GKE) deployment configurations, successfully escaping containers to establish persistence on node servers. Finally, the adversary exploited a centralized Cloud SQL Auth Proxy misconfiguration to extract persistent database credentials, alter high-value user accounts, and siphon digital assets across multiple blockchains. Attendees will leave with actionable remediation and architecture hardening strategies to secure Kubernetes secrets, enforce least-privilege controls, and protect cloud workloads against sophisticated adversaries.
Atrium Ballroom A
Modern cyber-enabled financial fraud is no longer a collection of isolated scams; it is a highly sophisticated, industrialized network operating at global scale. To defeat it, defense must be just as coordinated. In this collaborative workshop, we pull back the curtain on MTIS’s recent efforts in the cyber-enabled fraud landscape. We’ll share the lessons we’ve learned from our collaboration, outline our strategic vision for our role in this ecosystem, and explore where we need to go next. Bring your insights and challenges—this workshop is designed to gather your critical feedback so we can drive collective action against cyber-enabled financial fraud.
Amphitheatre
The 2026 threat landscape has moved past simple data theft into a new era of Operational Erasure, where state-sponsored actors and AI-augmented groups target the virtualization layers of critical infrastructure. For critical infrastructure, a cyber event isn't just a data leak—it's a potential halt to global supply chains and smart-access ecosystems. This panel explores the shift from static defense to dynamic resilience, discussing how AI is being leveraged to build self-healing infrastructure and how the CISO's role has evolved into a "Chief Resilience Officer." We will dive into the hard-won lessons of 2025, the reality of managing AI-driven Agentic threats, and why recovery preparedness is now more valuable than the perimeter itself.
Atrium Ballroom A
Join Mandiant’s ThreatSpace and hone your skills against an advanced threat actor in an engaging exercise suitable for all levels. Learn how to apply practical threat intelligence and overcome real attacks with real skills for real impact. Challenges run concurrently with breakout sessions. APT43 is a prolific North Korean cyber operator focused on supporting the regime's interests. Primary Motivation: Espionage and strategic intelligence collection, which is often funded through parallel cybercrime operations. Tactics: The group blends moderately sophisticated technical capabilities with highly aggressive social engineering tactics. A key hallmark of their operations involves creating numerous spoofed and fraudulent personas to execute their social engineering campaigns.
Atrium Ballroom B
To outmaneuver modern adversaries, defenders need a structural advantage. Manual source code review is too slow, and legacy SAST tools lack the contextual awareness needed to find complex logic flaws.
In this session, we explore how Mandiant modernized vulnerability discovery by leveraging Google’s Gemini as a force multiplier for defenders. We will detail the internal architecture Mandiant uses to safely and effectively audit massive codebases without falling victim to the context-window overload common in early AI tooling.
Rather than relying on universal bug-finding prompts that fail in production, we built a highly constrained pipeline. We will walk attendees through our methodology of deploying specialized agents for targeted analysis, coupled with an adversarial validation phase that forces the AI to aggressively try and invalidate its own alerts.
This is a practical look at how Mandiant does AppSec in the AI era. Attendees will leave with a clear understanding of how to harness Gemini’s capabilities to structurally filter out noise and proactively secure their own environments.
Atrium Ballroom A
Join Mandiant’s ThreatSpace and hone your skills against an advanced threat actor in an engaging exercise suitable for all levels. Learn how to apply practical threat intelligence and overcome real attacks with real skills for real impact. Challenges run concurrently with breakout sessions. APT44 is a highly dynamic and operationally mature threat actor that has been active since at least 2009. Primary Motivation: Advancing the far-reaching ambitions and interests of the Russian military. Tactics: This group executes a full spectrum of cyber operations, including espionage, influence campaigns, and direct attacks. While their historical center of focus has been Ukraine—where they have conducted numerous disruptive and destructive attacks—they also sustain a wide range of global espionage operations.
Amphitheatre
For detection engineering teams, the bigger the scale, the harder it becomes to answer the most basic question: how many attacks did we actually catch this week? Answering that requires dedicated investigation time for every threat. Static funnels help reduce the load, but they don't scale. Well - they didn't, until we brought AI into the loop. We built an AI investigation pipeline to scale our hunt for true positives surfaced by the detection engine.
Before touching any data, the AI analyzes threat semantics - understanding the rule's intent, what a real attack would look like, and what benign scenarios could trigger it. It then executes the same multi-step workflow a human researcher follows: gathering detection context, profiling actor history, verifying IP reputation, and cross-referencing asset inventory - corroborating evidence across sources before reaching a verdict. The system scales through parallel agents, each independently investigating batches of threats, updating results in real-time and generating live dashboards.
Then something unexpected happened. As confirmed true positives accumulated, we noticed the AI was consistently flagging attacker techniques our rules had missed. The idea was obvious - why not use those conclusions to write new rules? So we built exactly that: a pipeline where every verified attack feeds into automated TTP gap analysis, and the AI drafts detection rules for techniques we didn't cover.
In this talk, we'll share how we encoded expert investigative reasoning into AI skills, the rule creation pipeline, and real examples of AI-generated rules now running in production.
Atrium Ballroom B
Learn from experienced panelists on bridging the gap between technical security and strategic business risk management. Effective board engagement is now a critical component of corporate governance. This session explores key strategies for CISOs to communicate value and prepare leadership for the inevitable.
- Strategic Reporting: Move beyond technical metrics. Focus on the organization’s risk posture and how security initiatives enable business objectives. Highlight the ROI of security spending to position cybersecurity as a value driver rather than a cost center.
- Incident Preparation: Conduct tabletop exercises with executive leadership. Boards must understand their roles during a crisis, including legal obligations and regulatory disclosures. Defining "materiality" beforehand ensures a streamlined response when every second counts.
- Crisis Communication: Provide timely, jargon-free updates focusing on impact, containment, and recovery timelines. Avoid speculation and maintain a flow of verified information to build trust and allow the board to manage external stakeholder expectations effectively.
- Addressing Priorities: Tailor messaging to diverse board concerns, from personal liability to brand reputation. Ensure the audit committee receives technical validation while the full board remains focused on high-level enterprise risk management.
Atrium Ballroom A
Join Mandiant’s ThreatSpace and hone your skills against an advanced threat actor in an engaging exercise suitable for all levels. Learn how to apply practical threat intelligence and overcome real attacks with real skills for real impact. Challenges run concurrently with breakout sessions. UNC3944 is a financially motivated threat cluster active since at least early 2022. Primary Motivation: Financial extortion, heavily focused on stealing massive amounts of sensitive data. Tactics: The group typically gains initial network access using stolen credentials. They acquire these through targeted phishing operations or highly interactive social engineering directed at IT help desk personnel. Starting in early 2023, the group escalated their tactics to use their compromised access for ransomware deployment across victim environments.
Amphitheatre
The conversation surrounding frontier AI security often swings between two dangerous extremes. On one side is "The Hype"—the flawed assumption that AI will magically change everything, rendering foundational security controls and human oversight unnecessary. On the other side is "The Skepticism"—where organizations recognize that AI shifts the risk landscape but fail to make meaningful updates to their security programs, frameworks, or technologies.
This session delivers the ground truth required to navigate today's threat landscape. True cyber defense does not mean throwing out the playbook or standing still; it means building sustainable, resilient systems. We will explore why organizations must double down on core security foundations and Zero Trust (ZT) capabilities as their anchor. Simultaneously, we will discuss how to thoughtfully integrate new AI capabilities into your defense model without falling for the noise.
Attendees will leave with a pragmatic framework to balance their defense strategy—striking the right equilibrium between reinforcing proven security principles and adapting to frontier AI realities.
Atrium Ballroom B
As threat actors shift from basic perimeter exploitation to industrialized cloud identity evasion, complex enterprise infrastructures have become primary targets for state-sponsored espionage and double-extortion syndicates. Drawing from frontline investigations of state-sponsored and multi-cloud intrusions, this session delivers the unvarnished truth on modern attacker mechanics, secure systems recovery, and complex legal considerations. Co-presented by a lead forensic investigator and veteran incident response counsel, attendees will examine how adversaries compress initial access handoff times to mere seconds. Beyond initial triage, the session explores the critical phase of secure containment and recovery—verifying decoupled SaaS environments, rebuilding clean cloud synchronizations, and executing parallel operational recovery tracks without risking reinfection. Simultaneously, legal counsel unpacks the contemporaneous legal considerations, demonstrating how to establish a defensible "dual-track" investigation to shield privileged forensic analysis from arguably non-privileged recovery efforts and providing guidance about how to balance clients’ statutory, contractual, and in some cases ethical obligations to disclose security incidents and data breaches with the need to maintain the confidentiality of the incident while the organization works to implement its containment and eviction strategy. Learn to navigate these and other complex questions, including business materiality and aggressive disclosure timelines (such as SEC Form 8-K, NY DFS, and DFARS mandates) against the operational reality of returning safely to business as usual.
Amphitheatre
AI is increasingly used for productive business purposes but is also being used to deceive, commit fraud, or enhance criminal activity. We will explore how AI is being incorporated into deep fakes, fraudulent remote IT worker schemes, or other forms of deception and the legal, forensic investigative, and law enforcement issues that arise. This talk will be divided into 4 sections:
1) Discuss the use of AI to accelerate business productivity including key security and legal considerations businesses should consider as they adopt AI.
2) Discuss malicious uses of AI such as deep fakes and remote IT worker fraud and the investigative challenges law enforcement sees from both criminal and nation state actors. We discuss forensic issues and legal ramifications including new deep fake laws in US states and what may be on the federal horizon.
3) Discuss ways to combat the use of AI to commit fraud. We discuss whether know your customer requirements should be placed on data centers or on cloud providers to track potentially dangerous AI activity. We discuss how AI findings and tooling have continued to evolve.
4) Discuss the President’s new AI plan to protect critical infrastructure and other national or international developments and the impact these initiatives may have on incident response, forensic consulting and law enforcement.
Atrium Ballroom A
Join Mandiant’s ThreatSpace and hone your skills against an advanced threat actor in an engaging exercise suitable for all levels. Learn how to apply practical threat intelligence and overcome real attacks with real skills for real impact. Challenges run concurrently with breakout sessions. A Prompt Injection Vulnerability occurs when an attacker manipulates an LLM’s behavior or output by submitting crafted inputs that the model mistakenly interprets as developer instructions. Because LLMs process both system instructions (how the model should behave) and external user data (the content the model processes) in the same natural language channel, the model struggles to distinguish between the two. This lack of segregation allows untrusted input to override the system's guardrails and operational guidelines.
Atrium Ballroom B
When tracking sophisticated campaigns like s1ngularity, Shai-Hulud, and TeamPCP, looking at a single environment feels like reading a book one random page at a time. In reality, we watched the Shai-Hulud campaign impact tenant after tenant. Weeks passed, and the TeamPCP signal began appearing in a similar relentless pattern across completely unrelated sectors. By pivoting threat data across these customer boundaries, isolated pages crystallized into a coherent story.
A similar cross-tenant pattern emerged for an Entra ID malicious toolkit we observed, where independent tenants experienced identical sign-in anomalies - reusing the same ASNs, custom Python useragents, and App-Resource Tuples.
The Colony Defense strategy turns this multi-tenant insight into a superpower. By aggregating raw telemetry-IPs, domains, ASNs, useragents, resource names, and command lines-into a centralized pipeline, we can correlate activity across different tenants to manufacture high-fidelity IOCs faster than ever before.
But speed requires precision; we filter the data down until we are left only with a manageable set of cross-tenant suspicious activities. At this end stage of the funnel, we utilize LLMs to replace the human in the loop, filtering out the benign edge cases to identify true threats and deploy the new IOCs fast.
Amphitheatre
Any new technology brings new opportunities but also new security challenges. AI is being adopted by businesses around the world at increasing speed, generating significant efficiency gains. Unfortunately security is often an afterthought and security implications are not being considered during the design and the implementation. Mandiant consultants are at the frontlines, having unparalleled visibility into the risks that this causes, but also into best practices on how to implement AI in a secure manner. This presentation will highlight some observations from the work of our consultants.
Amphitheatre
Throughout his career as an investigative reporter, Brian Krebs has delivered profound insights into the cybercriminal world, uncovering major breaches, unmasking numerous wrongdoers, and exposing the ecosystem at the heart of attacks against everyone from powerful Fortune 500 companies to everyday people. He is one of the most seasoned observers of cybercrime, with nearly 30 years of experience in the space, and he has persevered at great personal cost. In an unscripted, deep-dive fireside chat, join John Hultquist (Chief Analyst, Google Threat Intelligence Group) as he sits down with Brian to discuss the lessons Brian has learned in his extensive career, with a focus on how cybercrime has changed and what where it might be going.
Please note: This keynote session will not be recorded.
How battle-tested CISOs build resilient cybersecurity programs, rebuild customer trust, and weave cyber into the corporate DNA. Having led security at some of the world’s largest organizations, these leaders have spent their careers defending against highly sophisticated threats. They are often hired by companies in the wake of major security breaches to stabilize operations, win back trust, and build stronger, more reliable security programs. In this fireside chat, they will share their practical experiences navigating the aftermath of a crisis and shaping a company cybersecurity culture.
Please note: This keynote session will not be recorded.
Amphitheatre
Incident response requires precision across diverse technology platforms. Responders manage significant cognitive demands while evaluating EDR alerts, cloud telemetry, and forensic artifacts during investigations with tight deadlines. This session examines the benefits of integrating coding agents like the Gemini CLI into digital forensics and incident response workflows.
We demonstrate how the use of sub-agents keeps the context window clean, which results in more predictable workflows and limits hallucinations. By enabling these sub-agents to use Agent Skills and MCP tools, investigators can rapidly develop capabilities tailored to solve specific common reasoning based analytical tasks. Operating a coding agent directly alongside the data eliminates the need for complicated pipelines by enabling the agent to process the data iteratively using the same CLI tools that the analysts were using. This CLI first approach also acts as a starting point for automating repeatable and deterministic tasks that can trivially be wrapped into automation scripts.
The presentation also addresses the risks and controls concerning prompt injection. Attendees will observe this architecture in practice through real field examples. Participants will leave with practical design patterns and a framework for determining when to use a general coding agent versus building a dedicated agent.
Atrium Ballroom B
This presentation challenges the traditional cybersecurity paradigm by emphasizing that cloud and on-premises disaster recovery is fundamentally an identity problem rather than a data problem. The core thesis focuses on how modern identity planes govern both production environments and recovery infrastructure; a single privileged identity compromise can effectively collapse the entire "blast radius" into the systems meant to save an organization. While many organizations assume their recovery infrastructure is a trustworthy safe haven, this talk argues that in a cloud-integrated world, identity collapses the necessary separation between these two worlds. This presentation details how sophisticated threat actors, such as Midnight Blizzard or UNC3944, utilize social engineering, token harvesting, and forgotten test tenants to gain control plane access without needing a zero-day exploit. Once inside, these threat actors can sabotage recovery efforts at lightning speed, leading to a total failure mode where persistence survives the recovery process. By analyzing current recovery architectures like "Same-Tenant" and "Cross-Account" models, this presentation demonstrates that these often fail because a global or organizational admin can still traverse those boundaries. The presentation concludes by advocating for "Active Resilience," a strategy focused on severing identity dependencies and utilizing isolated, immutable recovery environments that exist entirely outside the primary administrative blast radius to ensure company's data remains safe.
Atrium Ballroom A
Intelligence teams are drowning in data, but AI agents offer a life raft. This practical session takes you beyond basic chat queries into a masterful "Agentic" approach to threat intelligence. Starting with Prompting 101, you'll learn to structure high-fidelity queries that drive real-world outcomes: rapid maliciousness determination, automated executive briefings, and comprehensive campaign mapping. Learn to build and scale reusable, automated workflows for your daily triage tasks, fundamentally multiplying your team's threat intelligence capabilities.
Please note: This keynote session will not be recorded.
Atrium Ballroom A
Join Mandiant’s ThreatSpace and hone your skills against an advanced threat actor in an engaging exercise suitable for all levels. Learn how to apply practical threat intelligence and overcome real attacks with real skills for real impact. Challenges run concurrently with breakout sessions. APT43 is a prolific North Korean cyber operator focused on supporting the regime's interests. Primary Motivation: Espionage and strategic intelligence collection, which is often funded through parallel cybercrime operations. Tactics: The group blends moderately sophisticated technical capabilities with highly aggressive social engineering tactics. A key hallmark of their operations involves creating numerous spoofed and fraudulent personas to execute their social engineering campaigns.
Amphitheatre
This session will share a case study of a real incident we faced in incident response. We’ll jump straight into the key investigative developments and plot twists, sharing insights into attacker TTPs, investigative methodology, and key takeaways for protecting complex multi-cloud environments. Join us to learn how attackers circumvented advanced security controls to rob over $100M by compromising environment in AWS, Azure, and GitHub. Leveraging a clever combination of targeted social engineering and sophisticated cloud-native tradecraft, attackers were able to stay one step ahead of the victim for months while monetizing their access and evading detection. We’ll share every step of the attack and our unique investigation, accompanied with forensic evidence and visuals which reveal the attack flow and our evolving investigative understating, until the final unravelling of the attack.
Atrium Ballroom B
Nation-state intrusions are reshaping the threat landscape, targeting critical infrastructure, supply chains, and trusted technology pathways with speed, scale, and precision. Adversaries increasingly exploit identity, cloud services, edge devices, and third-party relationships to gain access, persist, and move laterally while blending into normal operations.
This panel brings together a seasoned Mandiant incident responder, a deputy CISO from a major critical infrastructure organization, and an FBI veteran with deep experience investigating national security cyber matters, moderated by outside counsel specializing in cybersecurity. The discussion focuses on frontline lessons from complex intrusions, including attacker TTPs, identity and cloud evasion, rapid exploitation of vulnerabilities, and cross-domain movement across enterprise environments.
Panelists will translate these insights into actionable strategies, including how to shift from reactive defense to rapid containment, how to operationalize resilience through testing and preparedness, and how to align incident response with governance, legal obligations, and board-level decision-making. The session will also address crisis lifecycle management, coordination with government and law enforcement, and the steps organizations can take to sustain operations and recover quickly. Attendees will leave with practical approaches to strengthen intelligence-led defense, resilience, and cyber governance.
Atrium Ballroom A
Join Mandiant’s ThreatSpace and hone your skills against an advanced threat actor in an engaging exercise suitable for all levels. Learn how to apply practical threat intelligence and overcome real attacks with real skills for real impact. Challenges run concurrently with breakout sessions. APT44 is a highly dynamic and operationally mature threat actor that has been active since at least 2009. Primary Motivation: Advancing the far-reaching ambitions and interests of the Russian military. Tactics: This group executes a full spectrum of cyber operations, including espionage, influence campaigns, and direct attacks. While their historical center of focus has been Ukraine—where they have conducted numerous disruptive and destructive attacks—they also sustain a wide range of global espionage operations.
Amphitheatre
Corpus delicti — no body, no crime. Every IR professional knows the principle. But when you're called to investigate an incident involving an internally developed AI application, you may have the body and still have no case. Not because the evidence was destroyed. Because it was never created.
This session is not about prompt injection demos or jailbreaking commercial AI products. It is about the realistic AI application your internal development team shipped because leadership said "leverage AI" — built quickly, built with good intentions, and built without a single line of intentional logging.
OWASP LLM risks don't go undetected because attackers are clever. They go undetected because developers don't know what to instrument and IR teams don't know what to ask for before the incident. We'll use a real Vertex AI application to show exactly where the logging gaps live — and map them to who owns them: the vendor, the developer, or nobody.
Attendees leave with a clear framework for where logging is the vendor's responsibility, where it is shared, and where it falls entirely on the developer — and what to demand from your dev teams before the next call comes in.
Atrium Ballroom B
The intersection of rapid cloud adoption and artificial intelligence has fundamentally reshaped the government's digital ecosystem. These interconnected architectures drive unparalleled mission agility and capability.
This panel brings together Mike Duffy, Acting Federal Chief Information Security Officer (CISO) at the Office of Management and Budget (OMB), and Mitch Herckis, Global Head of Government Affairs for Wiz, to dismantle the security implications of this new technical paradigm.
The discussion will focus on how the combination of cloud-native infrastructure and AI workloads creates complex systems with highly unique attack surfaces—where minor misconfigurations and overly permissive identities create toxic combinations of risk that adversaries can exploit at automated speeds. The speakers will address the limitations of compliance checklists and the shift to new paradigms of risk prioritization, real-time visibility and automated responses. Attendees will gain insights into how the federal enterprise is adapting policy frameworks and defensive postures to securely govern AI-enabled systems and meet the pace of innovation.
Atrium Ballroom A
Join Mandiant’s ThreatSpace and hone your skills against an advanced threat actor in an engaging exercise suitable for all levels. Learn how to apply practical threat intelligence and overcome real attacks with real skills for real impact. Challenges run concurrently with breakout sessions. UNC3944 is a financially motivated threat cluster active since at least early 2022. Primary Motivation: Financial extortion, heavily focused on stealing massive amounts of sensitive data. Tactics: The group typically gains initial network access using stolen credentials. They acquire these through targeted phishing operations or highly interactive social engineering directed at IT help desk personnel. Starting in early 2023, the group escalated their tactics to use their compromised access for ransomware deployment across victim environments.
Atrium Ballroom B
Enterprises are racing to deploy Generative AI, rapidly spinning up infrastructure across AWS, Azure, and Google Cloud. In this fragmented, hyper-accelerated reality, an AI application might ingest data from an AWS S3 data lake, train on GCP Vertex AI, and serve inference through Azure OpenAI. Traditional cloud security guardrails are often bypassed, creating massive blind spots. Adversaries aren't just targeting the language models; they are targeting the underlying multi-cloud infrastructure and exploiting the seams between providers.
This technical deep dive explores the unique attack surface of cloud-hosted AI workloads. We will deconstruct how threat actors exploit overly permissive ML training roles, manipulate unstructured data lakes for data poisoning, and abuse cloud metadata services to pivot laterally. Attendees will leave with a concrete architectural blueprint for translating network isolation, identity guardrails, and automated policies across the "Big Three" cloud providers to protect their AI infrastructure before the sprawl becomes unmanageable.
Atrium Ballroom B
Threat intelligence analysts are facing an unprecedented challenge: adversary compromises are accelerating to the speed of seconds, while analysts are often bottlenecked by the manual friction of pivoting across disconnected tools. This session explores a path forward by examining the evolution of the analyst from a tool operator to an orchestrator of intent, moving investigations to a higher level of abstraction.
We will explore a "Human-on-the-Loop" approach where analysts act as conductors, directing AI agents through complex workflows rather than manually operating interfaces via an AI-native IDE. This allows for rapid synthesis of data across disparate sources and enables the system to adapt when standard processes fail.
Crucially, this approach democratizes complex analysis, lowering the technical barrier to entry and allowing for the rapid exploration and operationalization of new data sources. We will discuss the core capabilities enabled by this architecture, such as autonomous adaptability and recursive pivoting. Attendees will leave with a realistic model for the next generation of threat intelligence analysis, with applications that scale to other security roles and extend to any discipline focused on complex data synthesis.
Amphitheatre
Zero Trust reshaped network security by replacing implicit trust with explicit verification at every boundary. AI Ops needs the same shift. Most organizations run a portfolio of AI systems, LLMs serving chat, RAG pipelines on corporate knowledge, tool-using agents executing workflows, with controls that don't transfer cleanly and trust assumptions embedded everywhere: in prompts, in retrieved context, in tool calls, in agent handoffs.
This session applies Zero Trust principles across the AI Ops estate. We define a reference architecture for three patterns (P1 LLM, P2 RAG, P3 agent), map ZT tenets to each, never trust the prompt, verify the context, least privilege for tools, assume the model is breached, continuously verify, and present the minimum control set per layer.
The session covers a demo in which we walk through one pattern using both trust-permissive and Zero Trust (ZT)-aligned configurations. We close with a continuous verification model spanning model/prompt registries, eval pipelines, drift detection, and red-team automation, with SAIF, NIST AI RMF, MAESTRO, and OWASP Agentic Top 10 mapped to operational artifacts.
Atrium Ballroom A
Join Mandiant’s ThreatSpace and hone your skills against an advanced threat actor in an engaging exercise suitable for all levels. Learn how to apply practical threat intelligence and overcome real attacks with real skills for real impact. Challenges run concurrently with breakout sessions. A Prompt Injection Vulnerability occurs when an attacker manipulates an LLM’s behavior or output by submitting crafted inputs that the model mistakenly interprets as developer instructions. Because LLMs process both system instructions (how the model should behave) and external user data (the content the model processes) in the same natural language channel, the model struggles to distinguish between the two. This lack of segregation allows untrusted input to override the system's guardrails and operational guidelines.
No Results Found
Please try searching with different filter or keyword
Log in now to build your agenda.