Notes from BSides Las Vegas 2026 (August 3 – 5, 2026, Tuscany Suites). Seven sessions, several of them in unrecorded rooms — so a few of these are reconstructed from slide photos rather than a recording, and I have said so on each page.

  • Abusing Agentic AI Browsers: An Exploit-Based Approach — Or Eshed (LayerX)

    The list of controls that quietly stop working — application tests, bot detection, DDoS protection, DLP, authn and authz — all share one unstated assumption: that a person is driving the browser.

    ai-agents browser-security bots
  • Prompt Injection Is Not the Problem — Noelle

    Small, argumentative Common Ground session where half the value was the room pushing back. The thesis — prompt injection is an authorization failure, because the agent carries your whole token instead of a grant scoped to one task — held up better than the demo, which broke.

    ai-agents authorization prompt-injection
  • Weaponizing Cloud — Speaker not captured

    AWS and Azure attack chains into full organisation compromise, with a sharp defensive turn: EDR consoles and IAM platforms are the fastest routes through an estate, so extended Tier 0 should cover CI/CD, cloud, IAM and EDR.

    cloud-security iam active-directory
  • X-Ray Specs for Agents: Pentesting MCPs, Skills & the Plugin Supply Chain — Abhijeet Kumar, Xia Hua & Varun Wadhwa (Traceforce)

    Tool release for inspecting what MCP servers and agent skills actually do rather than what they claim. The closing line is the whole argument: agents don’t get hacked, their tools do.

    mcp supply-chain tooling
  • Mind the Gap: Bridges, Backplanes, and BloodHound HD Moore

    The interconnects nobody inventories, and the same shape in identity where individually reasonable grants compound into paths nobody designed. Only caught two slides, but the framing stuck.

    network-security identity bloodhound
  • What Bounds Your Coding Agent? A Field Guide to Access, Inputs, Supply Chain, and Hooks — Rajaram Srinivasan (Unbound)

    A vendor talk that earns it by being specific. Agentic overreach — no attacker, no payload, no signal — is the failure injection defences were never built for. The hook-points slide and the argument for MDM-shipped policy over server-managed settings are both immediately usable.

    ai-agents coding-agents mcp
  • Agents of Chaos: GCP Service Agents — Speaker not captured

    153 services, 200 agents, 4,353 permissions — the service accounts Google Cloud creates on your behalf, graphed with the escalation-relevant ones flagged. Expanding a single agent and watching it fan out into IAM makes the point better than any statistic.

    cloud-security gcp iam

Four further sessions were photographed but had no title slide in frame, so they are not written up here.

Also at the same trip: Black Hat USA 2026.

All Talks