BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidescbr.com.au//bsides-canberra-2026//speaker//SZ
 FSYJ
BEGIN:VTIMEZONE
TZID:Australia/Sydney
BEGIN:STANDARD
DTSTART:20250924T000000
TZNAME:AEST
TZOFFSETFROM:+1000
TZOFFSETTO:+1000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20251005T030000
RDATE:20261004T030000
TZNAME:AEDT
TZOFFSETFROM:+1000
TZOFFSETTO:+1100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20260405T030000
RDATE:20270404T030000
TZNAME:AEST
TZOFFSETFROM:+1100
TZOFFSETTO:+1000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:AIxploit: Reliable Prompt Injection Exploits Against Database-Enab
 led AI Agents - Sean
DTSTART;TZID=Australia/Sydney:20260924T133000
DTEND;TZID=Australia/Sydney:20260924T142500
DTSTAMP:20260807T131514Z
UID:pretalx-bsides-canberra-2026-FKH7PC@cfp.bsidescbr.com.au
DESCRIPTION:AIxploit: Reliable Prompt Injection Exploits Against Database-
 Enabled AI Agents\n\nMost prompt injection demos work once and fail the ne
 xt — LLMs are stochastic\, and a prompt that fires today may not fire to
 morrow. Real attackers need exploits that fire consistently\, at will\, ag
 ainst production systems.\n\nThis talk is about what happens when you give
  an AI agent access to a database and then weaponise it reliably.\n\nWe pr
 esent AIxploit\, a framework for discovering reliable prompt injection exp
 loits in agentic AI systems. Rather than hunting for a single successful i
 njection\, AIxploit generates large numbers of semantically diverse advers
 arial prompts and executes them repeatedly against agent workflows. The re
 sult is families of prompts that trigger underlying failure modes across m
 odel versions\, configurations\, and tool integrations — not flukes\, bu
 t reproducible vulnerabilities.\n\nTo demonstrate real-world impact\, we b
 uilt four attack scenarios against modern agentic stacks using frontier mo
 del APIs\, MCP servers\, and database backends:\n\n- Read-only bypass: Pro
 mpt injections embedded in ticket data cause a Postgres-connected support 
 triage agent to execute multi-statement SQL queries\, escaping its intende
 d read-only constraints.\n- Database ransomware: Injections manipulate a s
 upport automation agent into encrypting database fields via SQL updates. I
 n testing across multiple frontier models\, up to 26% of generated prompts
  successfully encrypted a target column — a ransomware-style attack that
  runs without any traditional malware.\n- Sandbox escape via document: Mal
 icious instructions embedded in .docx content cause a document processing 
 pipeline to execute arbitrary Python and exfiltrate data from the processi
 ng environment.\n- KYC pipeline hijack: A weaponised identity document man
 ipulates a passport-scanning agent that writes to SQLite\, compromising th
 e verification workflow entirely.\n\nThese aren't one-off jailbreaks. AIxp
 loit reveals the structural failure modes that make these attacks repeatab
 le and shows that any AI agent operating a real backend is a potential tar
 get. Source code will be released on GitHub.
LOCATION:Off-Main Track
URL:https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/FKH7PC/
END:VEVENT
END:VCALENDAR
