Pocketful of Control Planes: Attack Chains Against Agentic AI (and How to Kill Them)

No ratings

Presented at BSidesAugusta 2026 by

AI agents don't attack like software, and they don't fail like humans. After years spent breaking traditional systems and now agentic ones I've watched the industry try to bolt old defenses onto a fundamentally new attack surface. It doesn't work, and the attack chains prove it. This talk walks through the attacks actually hitting production AI agents today: privilege escalation through tool chaining, cross-session credential bleed, autonomy drift, and the ways a single compromised agent can pivot faster and further than any human attacker. We'll show why these don't map onto existing frameworks and why treating an agent like a user, or like an API, gets you owned either way. From there we build the AI Agent Kill Chain: a practical model for where these attacks can actually be interrupted, and what stops them for real architecture, not policy documents. You'll leave with a holistic strategy you can apply Monday morning, not another slide of best practices. Along the way, we'll call out what the AI security market is currently selling versus what it's actually stopping because right now most of it is marketing wrapped around old tooling, and that gap is exactly where the breaches are happening.