What happens when autonomous AI agents start clicking links, running code, and βhelpfullyβ exfiltrating your secrets for an attacker?
In this talk, offensive security researcher Johann Rehberger walks through realβworld exploits against agentic systems such as computerβuse agents, coding copilots, and local development assistants, showing how prompt injection, invisible instructions, and tool automation can turn AI helpers into fully compromised βzombieβ endpoints. This session is ideal for blue and purple teamers, red teamers, AppSec engineers, security architects, and anyone experimenting with AI agents in their SOC, SDLC, or internal tools. Youβll see how attackers chain prompt injection with automatic tool invocation, how agents can be abused to steal API keys and sensitive data, and why treating agents like potentially malicious insiders is becoming a practical security baseline.
If this was useful, subscribe to BSides Vancouver Island for more talks from local and global security practitioners. Join our Slack to stay up to date: https://communityinviter.com/apps/visrs/visrs. Watch more sessions from the BSides Vancouver Island playlist to keep sharpening your skills with content from and for the Vancouver Island security community.
BSides Vancouver Island returns to the Victoria Conference Centre in Victoria, BC on Friday, September 25, 2026. Stay tuned for sponsorship, speaker, attendance, and volunteering opportunities.