Every conference talk we've analyzed. Sorted newest first.. Talks analyzed in full.
Learn how physical AI security differs from digital AI risk and why latency is a safety parameter, not a performance metric, in autonomous systems.
Learn how Google's Workspace security team built a defense-in-depth architecture against indirect prompt injection and rogue agent actions in production GenAI systems.
Learn to break the AI security procurement loop using a risk taxonomy from OWASP, NIST, and MITRE — and a 5-minute vendor evaluation wizard.
Learn how activation hooks, cosine similarity, and scalar projection enable behavior-based detection inside LLMs — the glass-box security approach to AI threat detection.
Learn how to build a Cedar-based policy harness that hooks into Gemini CLI, Claude Code, and Cursor to enforce ABAC rules, track PII taint, and block AI agent data exfiltration.
Learn how two offensive security consultants built a production-ready AWS organization from zero — covering OU design, SCPs, IAM, CI/CD, and monitoring on a lean budget.
Learn how NVIDIAs Project Marinade uses LLM coding agents to inject realistic, tunable vulnerabilities into real codebases - giving you ground-truth benchmarks to evaluate your security tools.
Learn how SuperYARA combines semantic similarity, ML classifiers, and LLM rules to detect prompt injection and GenAI threats at scale — with 99% cost reduction via pre-filtering.
Learn to extract real signal from security conference talks by diagnosing hidden predicates, outdated assumptions, and incomplete build-vs-buy framing before they waste your team's time.
Learn why AI coding tools break EDR detection rules and how to close the intent attribution gap with process ancestry analysis and agent hooks.
Discover how Entra ID service principal hijacking chains credential backdooring, federated domain abuse, and SAML token forgery into a full Global Admin escalation.
Learn how Rob T. Lee gave Claude Code root on the SIFT Workstation and completed a full DFIR investigation — disk image, memory, event logs, MITRE ATT&CK mapping — in under 15 minutes.
Learn how Fly.io secured shared GPU infrastructure using VFIO, IOMMU isolation, and firmware auditing — a practical guide to multi-tenant GPU security.
Learn the 3 phases of enterprise AI adoption in cybersecurity — and why access, cost, and culture must be solved in order.
Learn to architect AWS egress controls at scale: centralized Network Firewall, log cost management, allowlist strategy, and bypass mitigations from a real 200-VPC deployment.
Learn how Snowflake built an enterprise AI governance model that keeps pace with weekly vendor releases and autonomous coding agents — without killing developer productivity.
Learn how Netflix built Yams to close the AWS IAM analysis gap at enterprise scale — and how exposure and efficiency become measurable security KPIs.
Learn how to build a tiered AI governance framework that balances enterprise AI security with innovation — from intake scoring to human oversight gates.
Learn how prompt formatting attacks bypass AWS Bedrock Guardrails PII filters without injection — and how system prompt engineering fights back.
Discover how 37 AI-assisted IDE vulnerabilities across 15+ vendors enable zero-click RCE, prompt injection chains, and silent config poisoning — and how to test your tools.
Learn how to secure AWS and GCP cloud environments during M&A integrations — covering IAM Identity Center, GuardDuty, VPC Service Controls, and log continuity.
Learn to close the real security gaps in AWS Bedrock and Azure AI defaults — IAM, guardrails, private networking, and confused deputy risks in agentic pipelines.
Learn how attackers exploit Amazon Bedrock agent prompt templates to leak schemas, bypass input validation, and persist malicious instructions across sessions.
Discover how LLMs now autonomously find and exploit zero-day vulnerabilities in the Linux kernel and Ghost CMS — and what the AI capability curve means for defenders right now.