Copilots and agents are a new access vector; How to build an AppSec program that scales to the level of citizen development
Links, demos, tools and slides for RSAC 2025
Internet browsing for AI agents leads to 0click compromise but these mitigations can help
Guiding threat simulation and defense for Copilots and Agents
Reviewing Microsoft's Fix for the 'All You Need Is Guest' DLP Bypass
New Attack Vectors Discovered for Initial Access and Post-Compromise
We Need To Address Promptware Now
Links, source code, tools and slides for BlackHat USA 2024