The talk starts from the property underneath every prompt injection attack: a language model receives the system prompt, the user request, retrieved documents, and tool output as one token stream, with nothing marking which is which.
From there it covers vulnerabilities found in Microsoft 365 Copilot, the GitHub MCP server, and Salesforce Agentforce, the main families of injection attack and the defenses proposed against each, and what happens to those defenses when the attacker adapts to the systems. Finally, it talks about what measures a deploying organization can put in place without rebuilding its agent.
This is an engineering talk about mechanism and measurement and does not cover governance or risk frameworks.


