Sessions will focus on risks created when AI agents are embedded into enterprise ecosystems and how to pentest and secure this undefended attack surface
Reco, the AI and agent ecosystem security company, will present two sessions at Black Hat USA and DEF CON 34 focused on the security debt and lack of governance that quietly take root as AI agents become embedded in enterprise applications and workflows. Reco will also exhibit at Black Hat USA booth 1644.
Both talks will explore how agents, which are not limited to prompts, models or standalone AI tools, are creating an attack surface that exposes applications, identity systems, customer portals and business workflows to security risks. Reco experts will explain how agents can inherit permissions, use OAuth grants, trigger actions and expose data through trusted business systems organizations already use.
Also Read:ย CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight
At Black Hat USA, Shir Grinfeld, Head of Product Growth at Reco, will present a three-phase framework for reducing the exposure window created by AI agents. The session will address how organizations can identify misconfigured apps, unenforced SSO policies and over-privileged tokens before agents find them; detect and respond to machine-speed OAuth probing during an incident; and preserve access trails for post-incident remediation and executive reporting.
At DEF CON 34, Reco security researcher Nitay Bachrach and threat detection engineer Cynthia Ardman, will co-lead โSalesforce Apex Predator: Breaking Salesforce Sites,โ a hands-on workshop focused on Salesforce Experience Sites, one of the most under-tested attack surfaces in enterprise applications. The workshop will cover Aura and LWR frameworks, custom Apex controllers running in system mode, SOQL injection, unauthenticated route enumeration and LWRed, a new open-source scanner for LWR sites. The session is designed for pentesters and red teamers who need a practical methodology for assessing Salesforce sites that standard web testing often misses.
Catch more CIO Insights:ย How Are CIOs Aligning Technology with Workforce Agility?
[To share your insights with us, please write toย psen@itechseries.comย ]

