Skip to content

Details

After RSVP, please ensure to get your admission ticket from Humantix: https://events.humanitix.com/who-drove-the-agent-from-prompt-to-process-tree-and-tba-sectalks-syd0x67-103rd

Thanks to you for
1. Keeping your RSVP up-to-date. We are usually overbooked and have a long waitlist. We will sign you in and keep track of RSVPs and attendance.
2. Aligning with SecTalks' no-bullshit code of conduct
3. Keeping the venue nice and tidy during and after the session

# Presentation

### This session will have 2 talks:

### 1. Title: "Who Drove the Agent? From Prompt to Process Tree"

When a local coding agent reads a secret, runs a suspicious command, or makes an outbound request, the tool call alone does not tell you what drove it. The same action may follow an explicit user instruction, untrusted context, a broader task where the agent selected the step, or malware invoking the agent as a capability proxy.

This talk presents a practical workflow for reconstructing action provenance. Numbat captures supported prompts, permission events, tool requests and results, and native session artifacts. That evidence is correlated with endpoint process ancestry and independently observed effects to answer four questions: how was the agent launched, what instruction or context did it receive, what did it attempt, and what actually happened?

Speaker: Adel Karimi
Adel leads Detection and Response at Perplexity, following security roles at OpenAI and Google. He is also an active open-source contributor whose security projects include Numbat, Santamon, Bumblebee, and Galah.

AND

### 2. Title: Case study into the compromise of Hugging Face

July 16. Hugging Face announces that its systems have been compromised by a threat unlike any it has faced before: an attack apparently carried out autonomously, end to end, with no human operator apparently directing it.

Over time, more extraordinary details begin to emerge. The agents belonged to OpenAI. There were approximately 1,200 of them, with around 700 involved in the attack itself. They had broken out of their sandboxes during an offensive cybersecurity evaluation. And, perhaps most shocking of all, supposedly isolated agents had—unknown to OpenAI—been communicating with one another inside OpenAI’s infrastructure for months.

Chris Leong, AI Safety Educator and Co-Founder of AI Safety Australia and New Zealand, and Dr Fariza Rashid, who completed her PhD in Cyber Threat Intelligence Sharing and AI, will be your guides to making sense of this landmark event.

They’ll cover the incident itself, its implications for cybersecurity, possible policy responses, and the opportunities opening up for cybersecurity professionals in the rapidly growing field of AI safety.

Speaker: Christopher Leong & Fariza Rashid

How to find us on the day?
An organiser will be on the bottom floor until 6:15 to help attendees access the lifts.

# Speed hiring

There is an opportunity for potential employers to do an impromptu 30-second description of their open role. If you are interested, speak with one of the organisers before the start of the session.
Please note the best way to support SecTalks and tell others about your open roles is through sponsorship. We encourage companies, small or large, to come forward and support their local community.

# Sponsors

# Notes

After RSVP, please ensure to get your admission ticket from Humantix: https://events.humanitix.com/who-drove-the-agent-from-prompt-to-process-tree-and-tba-sectalks-syd0x67-103rd

Related topics

Events in Sydney, AU
Cybersecurity
Hacking
Information Security
Exploit Code
Malware

You may also like