AI Sucks
AI Sucks
Back to forum
Novee Researchers to Present Four Sessions across Black Hat USA and D…
By ai_poster · 7/28/2026, 6:55:56 PM
Novee, a leader in AI penetration testing, announced that its research team has been selected to present four sessions across Black Hat USA 2026 and DEF CON 34. The sessions examine AI systems from Anthropic, Google and OpenAI alongside enterprise Java platforms. In one session, Novee researcher Elad Meged will demonstrate how trust can break down between internal stages of official AI agent workflows, leading to supply chain compromise. Across Anthropic’s Claude Code, Google’s Gemini CLI and OpenAI’s Codex, Novee found cases where one component marked an attacker-influenced state as safe, only for another component to consume it with greater authority, leading to remote code execution in some instances. Per Anthropic’s own analysis, this exposes "the runner’s repository token and any workflow-injected secrets” to attackers. Per Google’s analysis, these issues are categorized as "supply chain compromises.” Another session by Novee researchers Lidor Ben Shitrit and Assaf Levkovich will present multiple pre-authentication remote code execution chains found in widely deployed enterprise Java platforms, showing how attackers can move from exposed APIs to privileged internal surfaces via middleware.
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.