All

Open Agentic Workshop – Insecure Code Examples

Session 4 of 7 The session focused on the “Insecure Code Examples” initiative led by Allie Howell, highlighting efforts to identify vulnerabilities in agentic frameworks through hands-on testing and community engagement. The initiative includes a repository of insecure code samples built using frameworks like Langgraph, Autogen, CrewAI, and others. A recent hackathon in New York […]

Open Agentic Workshop – Insecure Code Examples Read Post »

Open Agentic Workshop – Securing Agentic Apps

Session 6 of 7 The session focused on secure agentic applications, led by experts from AWS, Intuit, and Pangea. It outlined a methodology for identifying threats in agentic AI systems, emphasizing development lifecycle stages, key components, architectures, and operational environments. The discussion highlighted key threats such as memory poisoning, tool misuse, and identity spoofing in

Open Agentic Workshop – Securing Agentic Apps Read Post »

Agentic Open Workshop – Agentic Threat Modeling Framework

Session 4 of 7 The sessions collectively addressed agentic AI threat modeling, focusing on vulnerabilities in multi-agent systems across various platforms, including Palo Alto Networks, Cisco, and the Maestro framework.  Key topics included memory manipulation, tool misuse, and identity misconfigurations, with specific attack scenarios illustrating how malicious actors can manipulate agents to perform unauthorized actions,

Agentic Open Workshop – Agentic Threat Modeling Framework Read Post »

Open Agentic Workshop – Agentic Landscape

Session 7 of 7 The session on the Agentic AI Security Landscape Report outlined its structure and objectives, targeting CSOs, AI developers, security researchers, and policymakers. The report is divided into four pillars: regulatory context, incident analysis, solutions ecosystem, and future trends. It emphasizes the rapidly evolving landscape of agentic AI, the challenges of fragmented

Open Agentic Workshop – Agentic Landscape Read Post »

Agentic Security Open Workshop – Agentic AI Threats and Mitigations

Session 2 of 7 The session outlines a fictional case study involving “Finbot,” an AI finance assistant that was manipulated through prompt injection attacks, leading to fraudulent payments and data breaches. The presentation highlights how attackers poisoned Finbot’s memory, manipulated tools to execute unauthorized actions, and exploited identity misconfigurations to escalate privileges. It underscores the

Agentic Security Open Workshop – Agentic AI Threats and Mitigations Read Post »

Agentic Security Open Workshop – Introduction

Session 1 of 7 The introductory session for the Agentic Workshop outlines the objectives and structure of the Agentic Security Initiative (ASI), emphasizing the importance of community engagement and practical application. Led by project co-leads, the session introduces the initiative’s focus on identifying agentic AI threats, developing security guidelines, and providing practical tools for threat

Agentic Security Open Workshop – Introduction Read Post »

ISC2 Webinar: DeepSeek Deep Dive: Uncovering the Opportunities and Risks

Presented by Simon Salmon,CISSP,ISC2 Instructor|Managing Dir emPSN; Scott Clinton,Co-chair,OWASP Gen AI Security project; Steve Kelly,CISSP,Chief Trust Officer, Institute Security& Technology; B.Dunlap, Moderator About this talk In January 2025, the Chinese open-source artificial intelligence tool DeepSeek caused huge ripples in the AI market, granting user organizations affordable access to powerful LLMs. While this industry-disrupting innovation is

ISC2 Webinar: DeepSeek Deep Dive: Uncovering the Opportunities and Risks Read Post »

Ep.35 Meeting Apr 23 2025: Agentic AI, Red Teaming & RSA 2025 Highlights

In this podcast, we dive into key updates from the OWASP GenAI Security Project, including the latest on Agentic AI, red teaming best practices, upcoming events at RSA 2025, and exciting tools like the Compass for AI security maturity. 🌐 🛡️ Highlights: Insights into red teaming vulnerabilities and testing strategies. The importance of Agentic AI

Ep.35 Meeting Apr 23 2025: Agentic AI, Red Teaming & RSA 2025 Highlights Read Post »

Ep.33 Meeting Mar 26 2025 – Project Updates: Governance, Sponsorship & Growth

In this episode, join Scott Clinton, Steve Wilson, John Sotiropoulos, and Aubrey King as they discuss the latest updates and achievements in the OWASP GenAI Security Project. From the introduction of new governance structures to insights on sponsorship growth, this episode provides an in-depth look at how the project is evolving to tackle the challenges

Ep.33 Meeting Mar 26 2025 – Project Updates: Governance, Sponsorship & Growth Read Post »

Ep.32 Meeting Mar 12 2025: AI Red Teaming, Securing AI Models, and Best Practices in AI Security

In this episode, Scott Clinton leads the discussion on the latest trends and challenges in the AI security landscape. They kick things off with a friendly catch-up before diving into important topics like AI red teaming, the security of AI models, and the best practices for ensuring robust AI security frameworks. Throughout the discussion, our

Ep.32 Meeting Mar 12 2025: AI Red Teaming, Securing AI Models, and Best Practices in AI Security Read Post »

Scroll to Top

Ep.32 Meeting Mar 12 2025: AI Red Teaming, Securing AI Models, and Best Practices in AI Security