Securing the Agentic Loop: Why AI Agents Get Hijacked, and What Holds at the Point of Action

Wednesday
Register here

The talk starts from the property underneath every prompt injection attack: a language model receives the system prompt, the user request, retrieved documents, and tool output as one token stream, with nothing marking which is which.

From there it covers vulnerabilities found in Microsoft 365 Copilot, the GitHub MCP server, and Salesforce Agentforce, the main families of injection attack and the defenses proposed against each, and what happens to those defenses when the attacker adapts to the systems. Finally, it talks about what measures a deploying organization can put in place without rebuilding its agent.

This is an engineering talk about mechanism and measurement and does not cover governance or risk frameworks.

Date

TIME

Costs

Free

CPE Points

1

Organiser

ISACA Netherlands Chapter Square Tables
squaretables@isaca.nl

Organiser

NOREA
norea@norea.nl

We do our best with using as less posible cookies and tracking. By continuing to use this site, you acknowledge and accept our use of functional cookies. However, some external services require your permission to place cookies.

Accept All Accept Required Only