Chaos Computer Club - recent events feed (high quality)
A wide variety of video material distributed by the Chaos Computer Club. This feed contains events from the last two years
- Indexed episodes, last 90 days
- 96
- Latest publication
- Sep 24, 2026
- Audience
- Checking…
- Earliest in this view
- Aug 28, 2026
Latest episodes
Vier grüne Häkchen, trotzdem gehackt: Threat Modeling für KI-Agenten (god2026) (opens the original)
Read excerpt
Eine E-Mail liegt im Posteingang. Niemand öffnet sie, niemand klickt. Tage später fragt jemand seinen KI-Assistenten nach den letzten Mails — und der Agent schickt still interne Daten an einen fremden Server. So lief EchoLeak gegen Microsoft Copilot (CVE-2025-32711, CVSS 9.3): kein Exploit-Code, keine kaputte Authentifizierung. Jede Komponente hatte ihr Security-Review bestanden. Der Angriff lebte im Pfad dazwischen. Wer agentenbasierte Systeme baut, kennt das Muster: Wir prüfen Komponenten einz
Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives (god2026) (opens the original)
Read excerpt
As LLMs are increasingly integrated into systems that browse, retrieve, summarize, and act on web content, webpages have become an untrusted input vector for downstream model behavior. This enables site owners, contributors, and adversaries to embed instructions directly in web resources, i.e., indirect prompt injections. While prior work demonstrates such attacks in controlled settings, their prevalence, deployment, and real-world impact remain unclear. We present one of the first large-scale e
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement Analysis (god2026) (opens the original)
Read excerpt
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security. Too often, the shift-left mantra consists of implementing (AI-powered) code scanning and applying AI-powered security fixes for remediation. Also, don't forget to implement the AI-powered benchmark for AI-powered Security Fixes. Now, to be clear, I am not actually telling you to stop using these tools — if they work for you — instead, we should ask ourselves: What are we working o
Hackbots under control: Methodology for Autonomous Pentesters (god2026) (opens the original)
Read excerpt
Autonomous pentesting tools have matured to the point where they can reliably find vulnerabilities, but finding vulnerabilities is not the same as doing a professional pentest. Bug bounty hunting optimizes for high-severity impact while a client engagement requires systematic coverage against a framework, with every control checked. In this talk we will explore how we designed an internal solution that layers the OWASP ASVS framework on top of existing agentic testing products. We will cover wha
Agentic AI Gateway Enforcement of the OWASP Top 10 (god2026) (opens the original)
Read excerpt
The OWASP Top 10 for Agentic Applications 2026 clearly outlines risks like prompt injection, tool misuse, excessive agency, rogue and compromised agents, and untraceable actions. This talk shows how an open source tool addresses the risks as a control platform, a switchboard between the model and its actions. The separation means any hostile or compromised model is bound and can't reach or bypass these controls. Tool misuse and excessive agency hit per-action permission tiers that auto-allow, re
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
No verified audience measurement yet.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.
See coverage about Chaos Computer Club - recent events feed (high quality)