[un]prompted

[un]prompted Security Practitioner Con 2026

Every session of [un]prompted 2026: Nicholas Carlini, Daniel Miessler, Heather Adkins + 50 more who brought what they've learned from the edge: agents, detection, forensics, governance, llm security, offensive, prompt injection, threat intel. "It feels like a warp point in time: the moment security has to decide whether to stay deterministic, or jump into this non‑deterministic, AI‑driven world. But if we can pull just 2% of the people around us up one level, from "I type into ChatGPT like Google" to "I use agents and tools," then I believe we can change companies and countries.” - Gadi Evron.

Author

[un]prompted

Category

Technology

Podcast website

podcasters.spotify.com

Latest episode

May 28, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Ep 1 | Gadi Evron - Day One Remarks | [un]prompted 2026 28.05.2026

Day One opening and closing remarks from Gadi Evron at [un]prompted 2026.Gadi Evron is CFP Chair, [un]prompted and CEO, Knostic.

Ep 2 | Gadi Evron - Day Two Remarks | [un]prompted 2026 28.05.2026

Day Two opening and closing remarks from Gadi Evron at [un]prompted 2026. Gadi Evron is CFP Chair, [un]prompted and CEO, Knostic.

Ep 3 | Dan Hubbard - Zero Day Is Now the Space Between a Prompt and Prod | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Dan Hubbard kicks off [un]prompted with a poem. Dan Hubbard is VP of Research, Vectra AI. Watch on YouTube: https://www.youtube.com/watch?v=cUMJTM9egiM

Ep 4 | Heather Adkins & Four Flynn - Evaluating Threats & Automating Defense at Google | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 VP of Security Engineering from Google discusses advancing code security with a comprehensive overview of Google's AI security strategy. Shows how to evaluate emerging cyberattack capabilities and demonstrates how tools like CodeMender are helping build intrinsically safer software. Heather Adkins is VP of Security Engineering, Google. Four Flynn is VP Security and Privacy, Google...

Ep 5 | Joshua Saxe - The Hard Part Isn't Building the Agent: Measuring Effectiveness | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 As AI coding tools drive the cost of building security agents toward zero, the hard problem becomes knowing whether they'll actually work against real attacks and vulnerabilities not seen before. Presents a practical journey from naive precision/recall metrics to multi-dimensional evaluation that captures reasoning quality, evidence gathering, and tool-calling logic. Shows how prop...

Ep 6 | Shruti Datta Gupta & Chandrani Mukherjee - Security Guidance as a Service | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Explores how to provide consistent security guidance at scale, especially in AI-first environments. Discusses building an AI-Native Security Guidance as a Service that centralizes security knowledge and powers multiple defensive AI capabilities with consistent, evaluated and bespoke guidance. Shruti Datta Gupta is Product Security Engineer, Adobe. Chandrani Mukherjee is Product Sec...

Ep 7 | Jeffrey Zhang & Siddh Shah - Guardrails beyond Vibes | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Shares how Stripe is using AI agents to streamline high-friction security workflows including threat modeling and security request routing. Covers practical design choices that made these agents reliable in practice: modular orchestrator/child architectures, targeted tools, structured inputs/outputs, and validation to reduce variance and improve determinism. Walks through measuring...

Ep 8 | Paul McMillan & Ryan Lopopolo - Code Is Free: Securing Software | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 An AI-maximalist vision of securing software in the agentic future. Presents engineering-first ways to improve security of projects with zero-friction additions. Advocates for using LLMs to write code and security, arguing that if engineers use LLMs for code, they should use them for security too. Paul McMillan is Security Engineer, OpenAI. Ryan Lopopolo is Member of Technical Staf...

Ep 9 | Brendan Dolan-Gavitt & Vincent Olesen - Agents Exploiting "Auth-by-One" Errors | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Presents techniques for finding and validating access control flaws using AI agents. Uses strict validators for identifying successful logins (AuthN) and protected resource access (AuthZ) to build capable attack agents. Shows how to enable LLM-powered agents to discover and validate access control vulnerabilities at scale. Brendan Dolan-Gavitt is AI Researcher, XBOW. Vincent Olesen...

Ep 10 | Natalie Isak & Waris Gill - Developing & Deploying AI Fingerprints | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Introduces BinaryShield, a privacy-preserving fingerprinting system that enables cross-service threat intelligence without exposing sensitive user prompts. As LLM-powered services proliferate with prompt injection attacks, this system allows sharing threat data across organizational boundaries while preserving privacy. Covers research and practical deployment applications with demo...

Ep 11 | Sean Park - When Passports Execute: Exploiting AI Driven KYC Pipelines | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Shows how modern KYC workflows that delegate passport parsing, database writes, and customer verification to AI-driven extraction agents are vulnerable. Document-embedded injects and compliance controls together steer AI agents into cross-record reads and writes, enabling data theft and exfiltration without bypassing access controls. Presents a scalable exploitation approach across...

Ep 12 | Peter Girnus & Derek Chen - FENRIR: AI Hunting for AI Zero-Days at Scale | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 FENRIR has discovered 100+ vulnerabilities across AI infrastructure since mid-2025, with 21 CVEs patched including multiple CVSS 9.8 RCEs. Presents FENRIR's multi-stage verification pipeline: static analysis pre-triage, two-layer LLM validation (L1 prune → L2 deep-verify), and confidence-based human routing. Covers what worked (research-backed context generation, CWE-specific agent...

Ep 13 | Joe Sullivan - AI Notetakers: The Most Important Person in the Room | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 The most important attendee in meetings is now the AI notetaker that assigns action items, determines importance, and creates the official record. Covers steering techniques for influencing what the notetaker captures, risks from governance gaps when notetakers become infrastructure, opportunities for reliable incident response systems of record, and enterprise readiness frameworks...

Ep 14 | Adam Laurie (Major Malfunction) - AI go Beep Boop! | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Hardware hacking with AI at the controls. Gave Claude access to hardware lab (Laptop, USB hub, XYZ platform, PICO2, Jlink-pro, Oscilloscope, Chipshouter and targets). Within 7 minutes it pwned an LPC chip that took 6 weeks of human glitching. Within a month it rewrote the entire glitching platform and now autonomously hacks new targets while the author sleeps. Adam Laurie (Major Ma...

Ep 15 | Rami McCarthy - Zeal of the Convert: Taming Shai-Hulud with AI | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Post-mortem of 2025 Shai-Hulud attacks leaking massive victim data onto GitHub. Shows real-world evolution from simple "vibe-coded" scrapers to multi-agent triage engines that parallelize victimology and automate secret-impact analysis. Covers what actually worked, where ground has shifted, how "lazy" AI fails, with practical prompts, scripts, and lessons learned. Rami McCarthy is...

Ep 16 | Daniel Miessler - Anatomy of an Agentic Personal AI Infrastructure | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Deepdive on personal AI infrastructure system and the open-source project that mirrors it. Daniel Miessler is Founder, Unsupervised Learning. Watch on YouTube: https://www.youtube.com/watch?v=l9CPmPk2R-M

Ep 17 | Nicholas Carlini - Black-hat LLMs | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 Large language models are now capable of automating attacks previously only possible by human adversaries. Discusses several ways adversaries could misuse current models to cause harm at larger scale and lower cost than currently possible. Recent state-of-the-art models can find 0-day vulnerabilities in large software projects extensively tested by humans for decades. These new cap...

Ep 18 | Piotr Ryciak - Vibe Check: Security Failures in AI-Assisted IDEs | [un]prompted 2026 28.05.2026

Day 1 | Stage 1 AI IDEs and coding agents expand the practical attack surface of development workflows by introducing new paths from untrusted workspace inputs to high-impact actions. Presents a catalog of exploitation patterns derived from vulnerability research across major AI-assisted IDEs and agents (OpenAI Codex, Amazon Kiro, Google Antigravity, Cursor, others), organized by attacker effort a...

Ep 19 | Billy Norwood - Establishing AI Governance Without Stifling Innovation | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 CISO from FFF Enterprises shares strategy and implementation of a risk-based AI governance committee in a healthcare services firm, discussing successes and failures along the way. Billy Norwood is CISO, FFF Enterprises. Watch on YouTube: https://www.youtube.com/watch?v=sh9LpVM1QBM

Ep 20 | Ragini Ramalingam - Enterprise AI Governance at Snowflake | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Director of Enterprise Security at Snowflake shares perspectives on supporting responsible AI adoption within a large, dynamic enterprise environment. Discusses practical approaches to establishing governance frameworks, fostering cross-functional collaboration, and embedding security considerations into emerging technologies. Ragini Ramalingam is Director, Enterprise Security, Sno...

Ep 21 | Chase Hasbrouck - Three Phases of AI Adoption | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Chief of Forensics/Malware Analysis from U.S. Army Cyber Command discusses the Army's path to enterprise AI showing deployment constraints shape adoption more than security policies. Covers 2023's fragmented research previews (high innovation but no institutional knowledge), 2024's centralized solutions (killed experimentation), and 2025's enterprise agreements (now grappling with...

Ep 22 | Rob T. Lee - SIFT-FIND EVIL! I Gave Claude Code R00t on DFIR SIFT Workstation | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Chief AI Officer from SANS Institute explains wiring agentic AI into SIFT via Model Context Protocol—timeline generation, memory analysis, malware sweeps, all via natural language. References Anthropic's GTG-1002 report showing adversaries running Claude Code at 80-90% autonomous execution. Shows live demo where typing "SIFT!! Find Evil!" actually works. Based on 40+ hours of testi...

Ep 23 | Mika Ayenson - Can You See What Your AI Saw? | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Threat Research & Detection Engineer from Elastic explores GenAI endpoint observability from a practitioner's perspective. As GenAI coding assistants become standard developer tools, detection engineers face challenges understanding what happens when AI executes commands on behalf of users. Discusses what telemetry exists, where gaps are, and why standardized schemas for AI act...

Ep 24 | Mohamed Nabeel - Detecting GenAI Threats at Scale with YARA-Like Semantic Rules | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Sr Principal Researcher from Palo Alto Networks introduces SYARA (Super YARA), extending YARA's syntax with multi-modal semantic detection. Combines string matching, embeddings, ML classifiers, and LLMs in a single rule. Teaches hunting for GenAI-era threats including prompt injection, phishing, malicious intent identification, and disinformation detection, achieving 98% detection...

Ep 25 | Aaron Grattafiori & Skyler Bingham - Tenderizing the Target | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Principal Offensive AI Security Researchers from NVIDIA discuss Marinade, an agentic workflow solving the problem of getting realistic vulnerable applications. Analyzes codebases (Django, Spring Boot, Java, Rails), understands attack surface, and injects realistic, exploitable vulnerabilities that blend naturally into existing code. AI is surprisingly adept at weakening security co...

Listen to the [un]prompted Security Practitioner Con 2026 podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.