Pushing browsers to the limitAbusing Modern Browser Features for PhishingAlexander Hurbean

[Blog post] [Video]

Committing CSS Crimes for fun and profitLyra Rebane

[Slides] [Blog post] [Video]

Improving the Trustworthiness of Javascript on the WebEzzudin Alkotob, Giulio Berra, Benjamin Beurdouche, Richard Hansen, Daniel Huigens, Dennis Jackson, Cory Francis Myers, and Michael Rosenberg

[Slides] [Blog post]

LLMs standing tallBlack-hat LLMsNicholas Carlini

[Video] [Slides]

On the Coming Industrialisation of Exploit Generation with LLMsSean Heelan

[Blog post] [Code]

AI Security with GuaranteesIlia Shumailov

[Slides] [Paper] [Video]

200 Bugs/Week/Engineer: How We Rebuilt Trail of Bits Around AIDan Guido

[Slides] [Blog post] [Video]

Systematic debugging for AI agents: Introducing the AgentRx frameworkShraddha Barke, Arnav Goyal, Alind Khare, and Chetan Bansal

[Blog post] [Paper] [Code]

LLMs taking a fallTrust Me, I Know This Function: Hijacking LLM Static Analysis using BiasShir Bernstein, David Beste, Daniel Ayzenshteyn, Lea Schönherr, and Yisroel Mirsky

[Slides] [Paper] [Code]

AI Agent TrapsMatija Franklin, Nenad Tomašev, Julian Jacobs, Joel Z. Leibo, and Simon Osindero

[Paper]

Leaking secrets from the claudNiels Hofmans

[Blog post] [Code]

Scary Agent Skills: Hidden Unicode Instructions in Skills ...And How To Catch Themwunderwuzzi

[Blog post] [Code] [Video]

Nifty sundriesData Honeytokens for the Cloud EraPetrus Vasenius

[Blog post] [Video]

The Offense Death Cycle: Proactive Environmental Control as a Method of Persistent Cyber DefenseVolodymyr Styran

[Paper]

The AWS Console and Terraform Security GapLaurence Tennant

[Blog post]

The Limit Is the Sky… (Or Not)?Antonio Nappa

[Slides] [Code] [Video]

Coruna: The Mysterious Journey of a Powerful iOS Exploit KitGoogle Threat Intelligence Group

[Blog post]