Skip to content

Details

Breaking Models馃毃 Session 5: Leak & Build Edition

Part 1 - LLM02: Sensitive Information Disclosure

The stuff AI apps leak: API keys, customer records, system prompts, other people鈥檚 conversations. This category sat at #6 on the original OWASP Top 10 for LLMs. In the 2026 update it jumped to #2, right behind prompt injection, and it holds that spot in 2026. We鈥檒l walk through how these leaks actually happen. Most of them need no jailbreak, just normal usage, and what actually stops them.

Part 2 : Design exercise: build a secure agentic system

Something new this session. Instead of only talking about broken systems, we design one that isn鈥檛. Together we鈥檒l threat model an agentic AI app, where it can leak, where it can be hijacked - and then sketch a secure architecture for it. You do the practical design, not just the listening.

Talk first, then the exercise, then open floor. No vendor pitches. Beginners welcome!

馃摡 RSVP (or to present at a future session): aisecurityinbay@proton.me

馃搮 9 August 路 2:30pm - 4:30pm

馃搷 Hacker Dojo, Mountain View

Related topics

You may also like