Pushing browsers to the limitAbusing Modern Browser Features for PhishingAlexander Hurbean
[Blog post] [Video]
Committing CSS Crimes for fun and profitLyra Rebane
[Slides] [Blog post] [Video]
Improving the Trustworthiness of Javascript on the WebEzzudin Alkotob, Giulio Berra, Benjamin Beurdouche, Richard Hansen, Daniel Huigens, Dennis Jackson, Cory Francis Myers, and Michael Rosenberg
[Slides] [Blog post]
LLMs standing tallBlack-hat LLMsNicholas Carlini
[Video] [Slides]
On the Coming Industrialisation of Exploit Generation with LLMsSean Heelan
[Blog post] [Code]
AI Security with GuaranteesIlia Shumailov
[Slides] [Paper] [Video]
200 Bugs/Week/Engineer: How We Rebuilt Trail of Bits Around AIDan Guido
[Slides] [Blog post] [Video]
Systematic debugging for AI agents: Introducing the AgentRx frameworkShraddha Barke, Arnav Goyal, Alind Khare, and Chetan Bansal
[Blog post] [Paper] [Code]
LLMs taking a fallTrust Me, I Know This Function: Hijacking LLM Static Analysis using BiasShir Bernstein, David Beste, Daniel Ayzenshteyn, Lea Schönherr, and Yisroel Mirsky
[Slides] [Paper] [Code]
AI Agent TrapsMatija Franklin, Nenad Tomašev, Julian Jacobs, Joel Z. Leibo, and Simon Osindero
[Paper]
Leaking secrets from the claudNiels Hofmans
[Blog post] [Code]
Scary Agent Skills: Hidden Unicode Instructions in Skills ...And How To Catch Themwunderwuzzi
[Blog post] [Code] [Video]
Nifty sundriesData Honeytokens for the Cloud EraPetrus Vasenius
[Blog post] [Video]
The Offense Death Cycle: Proactive Environmental Control as a Method of Persistent Cyber DefenseVolodymyr Styran
[Paper]
The AWS Console and Terraform Security GapLaurence Tennant
[Blog post]
The Limit Is the Sky… (Or Not)?Antonio Nappa
[Slides] [Code] [Video]
Coruna: The Mysterious Journey of a Powerful iOS Exploit KitGoogle Threat Intelligence Group
[Blog post]