[un]prompted

[un]prompted Security Practitioner Con 2026

Every session of [un]prompted 2026: Nicholas Carlini, Daniel Miessler, Heather Adkins + 50 more who brought what they've learned from the edge: agents, detection, forensics, governance, llm security, offensive, prompt injection, threat intel. "It feels like a warp point in time: the moment security has to decide whether to stay deterministic, or jump into this non‑deterministic, AI‑driven world. But if we can pull just 2% of the people around us up one level, from "I type into ChatGPT like Google" to "I use agents and tools," then I believe we can change companies and countries.” - Gadi Evron.

Author

[un]prompted

Category

Technology

Podcast website

podcasters.spotify.com

Latest episode

May 28, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Ep 26 | Matt Maisel - Hooking Coding Agents with the Cedar Policy Language | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 CTO and Cofounder of Sondera demonstrates a reference monitor using Rust hooks and Cedar policies to deterministically intercept every shell command, file read, and other actions. Coding agents wield dangerous access to code and terminal, and prompt injection renders soft guardrails useless. Live demo forbids exfiltration and destructive behaviors with open-source tool compatible w...

Ep 27 | Carl Hurd - Glass-Box Security: Operationalizing Mechanistic Interpretability | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Co-Founder & CTO of Starseer introduces "Glass-Box Security" utilizing Mechanistic Interpretability and Latent Space Geometry to monitor model's internal state for malicious intent and data exfiltration. Perimeter defenses are failing against next-generation AI agents. Presents Starseer architecture—a technical reference for building "Internal EDR" replacing fragile regex filte...

Ep 28 | Maxim Kovalsky - The AI Security Larsen Effect: How to Stop the Feedback Loop | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Managing Director from Consortium Networks introduces a capability-based framework for AI security. The market has 60+ vendors with unclear guidance. Framework zeros in on risks actually relevant to your architecture, helps decide how to address them (configure, buy, or build), and produces rational vendor shortlist instead of analysis paralysis. Live demo with realistic scenario:...

Ep 29 | Padma Apparao - Kinetic Risk: Securing and Governing Physical AI in the Wild | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Security architect for government agencies discusses when AI leaves the screen and enters the physical world, failure shifts from misinformation to kinetic damage. Physical AI is fundamentally different: while performance dominates design, security, risk, and governance must be built in from start. Examines VLA-specific risks like sensor spoofing and embodied instruction manipulati...

Ep 30 | Aaron Brown & Madhur Prashant - Trajectory-Aware Post-Training Security Agents | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 Agentic AI Builder from AWS presents complete open-source pipeline for trajectory-aware post-training of open-weight SLMs for cybersecurity tasks. Everyone talks about AI agents for security but almost no one discusses post-training underlying open-weight models. Frontier APIs work for prototypes but scaling autonomous security operations requires fine-tuned small language models o...

Ep 31 | Adam Krivka & Ondrej Vlcek - AI Found 12 Zero-Days in OpenSSL | [un]prompted 2026 28.05.2026

Day 1 | Stage 2 AI Security Researchers from AISLE discuss AI finding 12 zero-days in OpenSSL (one of the most audited codebases on the planet). Three had been hidden for over two decades. AI has fundamentally changed vulnerability discovery economics—what once required elite expertise and months can now be done in hours. Explores what it takes to make AI vulnerability discovery effective at scale...

Ep 32 | Dan Guido - 200 Bugs/Week/Engineer: How We Rebuilt Trail of Bits Around AI | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 CEO of Trail of Bits explains strategy to turn the consulting firm into an AI-native organization. AI isn't a feature to "adopt"—it's a force that commoditizes effort and shortens half-life of best practices, especially in security work. Core idea is a compounding operating system built from incentives, defaults, guardrails, and verification loops letting humans and autonomous agen...

Ep 33 | Sergej Epp - 8 Minutes to Admin. We Caught It in the Wild. | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 CISO from Sysdig discusses two AI-assisted attack campaigns caught: an 8-minute AWS escalation from stolen creds to full admin, and EtherRAT (fileless Node.js implant using Ethereum smart contracts for C2). Neither introduced novel attack primitives but compressed known techniques to speeds/scales breaking traditional detection models. Introduces behavioral methodology for attribut...

Ep 34 | Olivia Gallucci - macOS Vulnerability Research | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 Security Engineer from Datadog discusses operationalizing Apple's partial open-source codebase for offensive security. While Apple is known for closed ecosystem, significant portions of macOS and iOS are open source including security components. Walks through integrating generative AI and AI tooling into workflow for automating triage of open-source diffs, identifying code changes...

Ep 35 | Georgi G - Promp2Pwn - LLMs Winning at Pwn2Own | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 Director of Research at Interrupt Labs built an agentic AI to hunt bugs for Pwn2Own. Found vulnerability in Samsung's own AI assistant, Bixby. Shows how it was wired up, what worked, what didn't, and why letting machines hunt bugs made Pwn2Own fun again. Georgi G is Director of Research, Interrupt Labs. Watch on YouTube: https://www.youtube.com/watch?v=c5XAvRbma6Y

Ep 36 | Andrew Bullen - Breaking the Lethal Trifecta (Without Ruining Your Agents) | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 AI Security Lead from Stripe addresses the prompt injection elephant in the AI Security room—there's no deterministic defense, yet urgency driving AI adoption means many teams feel forced to accept risk or hobble agents. Presents a third path: containment. Shows Stripe's architectural guardrails for protecting agent platform: preventing data exfiltration through controlled egress,...

Ep 37 | Brooks McMillin - Building Secure Agentic Systems | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 AI Security Researcher & Security Engineer from Dropbox shows what actually breaks when building agents used every day. Walks through real patterns from building specialized agents: capability bounding to prevent tool abuse, prompt injection detection requiring real-world tuning, multi-agent memory isolation failures and fixes, OAuth device flow for headless operation. Includes...

Ep 38 | Mudita Khurana - Rethinking how we evaluate security agents for real-world use | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 Staff Security Engineer from Airbnb addresses how security agents remain rooted in narrow, outcome-only benchmarks. These evaluations tell whether agent produced correct answer but not "how" or whether behavior remains stable once deployed. In practice, security is connected end-to-end workflow (find → confirm exploit → patch → validate loop). Introduces practical, capability-centr...

Ep 39 | Flash Talks - Ilia Shumailov, Rob Joyce, Ragini Ramalingam + more | [un]prompted 2026 28.05.2026

Day 2 Flash talks from Ilia Shumailov, Rob Joyce, Ragini Ramalingam, and more.

Ep 40 | Nicolas Lidzborski - Securing Workspace GenAI at Google Speed | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 Principal Engineer from Google Workspace Security discusses GenAI agents navigating a perilous "Perfect Storm" of access to sensitive data, exposure to untrusted content, and capability to execute external commands. Technical deep dive into architectural principles and defense strategies protecting Gemini and Google Workspace ecosystem. Shares real-world attacks including vulnerabi...

Ep 41 | Wes Ring & Josiah Peedikayil - Operation Pale Fire | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 From Block discuss red-teaming their own AI agent, goose (Block's open source AI agent). Best defense is good offense. When releasing goose, proactively identified how attackers will attempt to abuse it. Enter: Operation Pale Fire. Wes Ring is Security Engineer, Block. Josiah Peedikayil is Security Engineer, Block. Watch on YouTube: https://www.youtube.com/watch?v=SUa1nta8FGQ

Ep 42 | Kyle Polley - Training BrowseSafe: Lessons from Detecting Prompt Injection | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 Member of Technical Staff at Perplexity shares experience training and deploying BrowseSafe for detecting prompt injection in production browser agents. Deploying AI agents that browse the web creates critical security challenge preventing malicious websites from hijacking agent behavior through embedded prompt injections. Built BrowseSafe-Bench—a realistic benchmark with attacks i...

Ep 43 | Arthi Nagarajan - Exploring the AI Automation Boundary | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 Software Engineer for Internal Threat Detection at Datadog explores how AI can help security practitioners navigate overwhelming telemetry volumes. Automated three parts of threat hunting workflow: hypothesis-driven query generation, iterative refinement, narrowing toward pivotal evidence. Shares learnings evolving from single agent to orchestrator-subagent system focusing on trust...

Ep 44 | Bob Rudis & Glenn Thorpe - Detection & Deception Engineering in the Matrix | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 V.P. Data Science and Sr. Director from GreyNoise Labs built Orbie—an AI agent operating on internet-scale honeypot data to surface emergent threats, identify campaigns, and write detection rules. Shares what works, what doesn't, and specific campaigns caught that traditional methods missed. Shows how domain expert knowledge embedded in tooling lets LLMs operate on billions of netw...

Ep 45 | Rob T. Lee, Glenn Thorpe, Dan Hubbard & Sergej Epp - Vibe Coded | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 Panel of creators who vibecoded at the conference to make it better, creating tools at the conference. Micro talks on what they did. Rob T. Lee is Chief AI Officer (CAIO) and Chief of Research, SANS Institute. Glenn Thorpe is Sr. Director, Security Research & Detection Engineering, GreyNoise Intelligence. Dan Hubbard is VP of Research, Vectra AI. Sergej Epp is CISO, Sysdig. Wat...

Ep 46 | Gadi Evron for Zenity: PowerPoint Karaoke Presenting My Competitors Unreleased Research | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 Zenity Labs was supposed to present their research on agentic browser attacks, but the speakers were stranded in Israel when the airspace closed. Gadi stepped in to present their slides cold — he saw them for the first time on stage — in a session he calls PowerPoint karaoke. The research covers two attack chains targeting Comet, an agentic browser: the first uses a malicious calen...

Ep 47 | Jackson Reed - Are you thinking what I'm thinking? | [un]prompted 2026 28.05.2026

Day 2 | Stage 1 Founder & CEO of Barding Defense short talk. Jackson Reed is Founder & CEO, Barding Defense. Watch on YouTube: https://www.youtube.com/watch?v=j2_VsH6aNzY

Ep 48 | Roey Ben Chaim - Total Recon: How We Discovered 1000s of Open Agents in the Wild | [un]prompted 2026 28.05.2026

Day 2 | Stage 2 Staff Engineer from Zenity discusses how AI agents quietly created a new external attack surface: copilots, custom agents, AI middleware deployed to internet often without anyone realizing they're reachable, enumerable, or over-permissioned. Shows how attackers can find agents in the wild and used these details to find 1000s of exposed agents. Covers measuring exposure, proving obs...

Ep 49 | Johann Rehberger - Your Agent Works for Me Now | [un]prompted 2026 28.05.2026

Day 2 | Stage 2 Red Team Director discusses how agentic AI in personal assistants, developer tools, and enterprise platforms can be infected with promptware—engineered prompts acting like malware. Demonstrates attacks and exploit chains including delayed tool invocation and intent activation tricks bypassing existing mitigations. Enables persistence, lateral movement, promptware-powered C2, and da...

Ep 50 | Niki Aimable Niyikiza - Capability-Based Authorization for AI Agents | [un]prompted 2026 28.05.2026

Day 2 | Stage 2 Senior Security Engineer & AI Security Researcher from Snap addresses how prompt injection filters and coarse IAM roles consistently fail in multi-agent setups. Shows working alternative: treating agent authority as ephemeral, cryptographic warrants that attenuate on delegation (inspired by Macaroons/UCAN). Task-scoped, holder-bound, verified offline by tools in microseconds. E...

Listen to the [un]prompted Security Practitioner Con 2026 podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.