At Black Hat, Matan Bar-Efrat's team took over an AI shopping assistant by talking to it. No zero days, nothing sophisticated. The chatbot handed over its API key, and the guardrails built to protect it fell to the same manipulation they were meant to stop.
This episode is about what securing AI agents actually takes once they're running real business processes.
Covered in this episode:
• The Black Hat "Bye Bye" demo: owning an AI shopping agent through conversation alone, and why the guardrails failed
• Why prompt-inspecting "guardian agents" catch the easy attacks and miss anything even slightly sophisticated, and why watching the actions an agent takes is how it should be done
• The exploitation window collapsing from months to basically instant, and why signature-based controls and patching cycles were already losing
• Enterprise agents moving from copilots to running business processes, why finance and insurance are first, and why that shift is what has to justify the trillion-dollar AI valuations
• The founding story: investors calling the idea dumb, why he says that was good, and his advice for founders: talk about what you don't do, because doing everything is doing nothing
About Matan:
• Co-founder and CEO of Rein Security, the enterprise agent security company, launched with an $8M seed led by Glilot Capital and backed by founders from Aqua Security, Orca Security and Talon
• Former Unit 8200 officer, in cybersecurity since he was 18
• Spent seven years at Cyberbit, ending up running its Northern European territory, before it merged into Elbit
• Presented the "Bye Bye" AI shopping assistant hack at Black Hat and recently spoke at a JP Morgan fireside on AI agents in front of 1,200 people
🔗 Matan Bar-Efrat: https://lnkd.in/egC5jjwD
🏢 Rein Security: https://lnkd.in/ebnCUi39
👤 Jack Brandwood: https://lnkd.in/dFMyDUEN
🎧 Spotify: https://lnkd.in/eij7j2m
📲 On Security LinkedIn: https://www.linkedin.com/company/onsecuritypodcast/