Dub|Sec October 2026 Meetup
Details
The next Dub|Sec meetup will take place in the Abbey Room of the Camden Court Hotel on Tuesday 28 October, 2026.
We'll be there from 6.30pm. Our first speaker will start at around 7pm.
19:00 - Talk 1: Threatcraft by Isabella Sparks
Additional details to follow
19:40 - Talk 2: When "safer" is the exploit: reproducing an Auto Mode RCE in Claude Code by Aaron Ott
Coding agents are good at refusing the obvious bad thing now. This talk is about an attack, building on Johann Rehberger's research, where saying no is the point.
You ask Claude Code to summarize a website. The website steers it toward a ZIP archive with a decoder in it. The agent reads the decoder and refuses to run it. So it writes its own Python decoder instead and runs it from inside the directory it just unzipped. There is a struct[.]py in there. base64 imports struct. Python searches the current directory first. That's the whole exploit.
Aaron will show how module shadowing works, walk the chain from injected prompt to execution, and share what he saw across runs. Sometimes it fired five times in a row, sometimes three out of five. A defense that only works when the agent happens to notice the trap is not a control.
If you would like to speak at any future Dub|Sec, please email us at info@dubsec.ie!
Join us for some drinks, food and general chat about infosec. Everyone is welcome whether you’re a pro, an amateur or just curious about the field!
