Gadi Evron
CEO & Co-Founder at Knostic, CISO-in-Residence for AI at Cloud Security Alliance. Former Founder @Cymmetria (acquired). Host at Prompt||GTFO. Threat hunter, scifi geek, dance teacher. Opinions my own.
Agents… find a way. Use Knostic - ask me for a demo, or just download for free.
I’m waiting on approval from Hugging Face before I share insights from the Cloud Security Alliance CISO community huddle I hosted on Thursday, but here are four lessons:
-
Use coding agents at scale, from analysis to custom UI generation. It’s the new reality, and more useful than any product interface.
-
Sandboxes, permissions, and basics aren’t enough. Agents… find a way. Instrument and defend the agents.
-
Be prepared to use open weight models if you want to defend your organization.
-
Prepare a token budget for IR purposes.
I’ll share more when I can.
The one thing everyone gets wrong about agents security.
They try to secure the environment.
Commendable, good practice, not useful against agents. The agents will find the one thing you missed, or that changed since you checked. The agents don’t care.
Instead, ask yourself:
When an agent is active in this environment, what would go wrong?
Then:
Can I secure the agent, to stop stupid?Malicious will follow later.
It’s fine to work on basics - always, but don’t lie to yourself. They won’t save you *here*.
Agents… find a way.
Pic: Annoying meme stating a truth no security expert would disagree with, that simply won’t help deal with current issues. It does however stop any reasonable discussion before it happens, cold.
And securing agents is where I bet my life. In 2026, you understand why.
—
Check out what we do at Knostic, and ask for a demo. You can also use it for free up to five users.
We're happy to announce [un]prompted is back, October 27th to 29th, in San Francisco. Registration and CFP are now open on our site. URL in a comment.
Waiting a whole year just made no sense to us considering the rate of change, and the community forming around the event.
Some announcements:
1. Jeff Moss is joining us
Joining me as a co-lead for the conference committee and CFP board is Jeff Moss (Dark Tangent). Thank you for your trust and partnership, Jeff.
2. An extra day
The conference will run for three days, instead of two.
3. CFP changes:
We restructured the CFP in a way we feel is more representative of changes in the landscape since March, with five tracks; Build. Break. Operate. Govern. Train.
Where Train is a new track, introduced considering how open weight models are changing how practitioners work with AI.
4. Updated pricing:
While our highest priority is keeping [un]prompted a community conference, we also had to make a choice. Do we make it available to more people, or keep it small and tell many attendees no, or maybe draw lots on who can attend?
We'd also like to reduce dependence on sponsors. And, to be fair, Gadi and Knostic, and 🏎️ Kyle Rosenthal 🏁 and TachTech, can't continue footing the bill wherever there is a gap.
Thus, we went to the community with this question, as it isn't just "our" conference. We didn't dare thread the needle on our own.
While we can't make everybody happy, based on the information provided, we are:
- Updating our prices for attendance
- Increasing the number of attendees by 30% (instead of the 300% we were aiming for)
New ticket prices:
- In-person attendance: $500 for early bird, and $850 for late registration.
- Online conference: $100 for early bird, and $150 for late.
Note that spots are limited and it may take us time to approve everyone, as spots clear up and we release more batches of seats.
- Have you submitted a CFP to [un]prompted AU yet? https://unprompted.au/
- Join our Slack. https://join.slack.com/t/promptgtfo/shared_invite/zt-3v2b4sll3-SfyzFRw2lykx_XQX7F3uNQ
See you in SF, this October!
Revoking your token won't save you. Knostic's researcher Tamir Isaschar found malicious VS Code extensions abusing VS Code's shared GitHub authentication model, for persistent GitHub access.
They silently inherit your existing GitHub OAuth session, without any prompt, using a single API call with the broadest scopes (repo, workflow, read:user, user:email).
If you have GitHub Copilot or the GitHub Pull Requests extension installed, that grants full read/write access to all your repos, including private ones. The extension plants an attacker-controlled SSH key on your account via the GitHub API, titled "vscode-recovery." The attacker keeps the private key.
So revoking the token, rotating your password, and uninstalling the extension all leave the attacker with git access via SSH. The only fix is removing that SSH key.
Check now: GitHub Settings → SSH and GPG Keys. Look for any key titled "vscode-recovery" or with the comment "implant@poc" that you didn't add. Remove it and treat your repo credentials as compromised.
Treat extensions like any software you install: check the publisher, install count, and reviews.
Full research: https://www.knostic.ai/blog/revoking-your-token-wont-save-you-the-vs-code-attack-that-installs-a-permanent-github-backdoor
--
And as usual, if you'd like to discover and defend your agents and coding assistants, do check out Knostic. Message me for a demo, or check out:
https://knostic.ai/demo
Or try it our for free (up to five users):
https://getkirin.com/
I've been asked "what is the one thing people deep in the agents security space get, and security professionals don't?" (yet). Answer: Agents... find a way.
Honestly, whenever we hear of someone tightening their basics in response to an agentic incident, we do understand why they'd do that based on old best practices, but we also roll our eyes.
The GitHub data breach with a VS Code extension, AWS's two outages, and endless posts online every week on agents deleting production/computer/code, or cheating to get the job done, all show that agents will surprise you, and find a way.
Hardening of your supply chain or basics will of course be useful, but it won't help with this. there is always something off, and the agent will find that gap.
You too, will later say "it was user error" or "permissions should have been tighter."
The basics matter, but we must recognize we don't simply tighten OS permissions when securing the browser, or router ACL when implementing zero trust.
These agents are deployed in your environment right now - the business and engineering aren't waiting on adoption, and attackers, when targeting AI, mostly focus on agents and the agentic supply chain.
- So what do you do?
-
Focus on protecting agents where adoption is, risk is high, and where attackers focus when attacking AI: On the endpoint (agents, coding assistants, and their supply chain, skills, extensions, MCP servers, etc.)
-
Start with extending your security controls stack to agents, by employing agents-specific Detection and Response, and SPM capabilities.
-
Make sure the control you choose is backed by endpoint agent (namespace collision). Nearly no agents use the same tech stack, and each agent needs to be instrumented on its own.
No one wants "yet another agent" on the endpoint, but hooks simply aren't enough as, you see, agents... find a way.
At Knostic we've tried many technologies to defend agents - we've been around since 2023. We worked on identity, authorization, sandboxes, firewalls, and many other capabilities. All these serve a part, but agents-specific Detection and Response and SPM is what works.
-- Want to see a demo of what we do at Knostic? Send me a note, or check it out yourself: https://knostic.ai/demo
Or, try it out! The product is free up to five users: https://getkirin.com/
For supply chain security, check out AgentMesh, the only scanner on Virus Total to trigger on these threats, consistently: https://lnkd.in/dqwMhSQ2
as $major_vendor promised more advanced agent security capabilities by next quarter? Well, how many quarters has it been now?
By next quarter, we shouldn't work on last year's problems. We will be dealing with new problems in the AI space. And with Knostic, it will be a partnership.
Knostic is AI native. We weren't just the first to secure your agents:
- We have a product right now.
- We stay flexible and pivot with our customers, to always be relevant for the next AI surprise.
For us, "next quarter" is about planning together, and staying agile. Not catching up to last year.
Want a demo from the people who (usually) predict the next AI security challenges in advance? Message me. Sounil Yu and I will be at Black Hat all week.
Just went off the keynote stage at OWASP Global Vienna, 2026.
A keynote is hard, where you need to satisfy different audiences, from grandma to vulnerability researchers, and provide with “inspiration” without it being seen as b/s by either.
Meaning, challenging status quo so that the audience has the opportunity to deeply rethink their assumptions (beyond time to exploration: from patches even existing and constant concurrent data breaches, to fixing third party software on your own), while not losing the techies who just want the bottom line.
AppSec is dead. Long live AppSec.
While most current AppSec capabilities are now outmoded and (almost) pointless, people, for now, are not. The world has never been this exciting, and the future with AI, especially in AppSec, is bright.
VulnOps isn’t just a buzzword securing l more budget for leaders, either.
From autonomous patching and Sounil Yu’s DIE Triad DevOps (with self healing infra) to threat modeling at plan mode and dynamically updated secure coding rules - the possibilities are endless.
While defense hasn’t yet hit its singularity moment, attack has. And guess what? Because of this, AppSec has as well.
Use an agent today. Defend your agents and their supply chain. Point agents at your code. And, take someone with you on the AI journey - let’s not leave people behind.
Thank you OWASP® Foundation for the opportunity.
Josh Grossman, Lauren Thomas, Stacey Ebbs, Izar Tarandach, and Missie Lindsey - my direct connections for the speaking role - I appreciate all the hard work you and the wider team put in, making this such a successful event!
Avi Douglen, thank you for putting me on your panel on personal relevance in the age of AI, along-side Grant Ongers, Marisa Fagan, and Hanna Foxwell. Man it’s hard finding a good moderator for panels, and you’re it.
recon, the conference for reversers and researchers, doesn’t often do panels. Hugo challenged me to build an AI one... and I don’t say no to Hugo.
We wanted to balance practical advice, discussion on 0days bugmaageddon and malware with Claude, harnesses, math, the disapearing junior role, coordinated disclosure and if it will still exist in a few months…
And critically, we tried to answer the question on if we’ll still have jobs, researchers or not, with AI around, as many at recon have been asking that throughout the event.
Our goal was to not be doomers. And, I kept challenging the panel on giving us specifics on why and how the future is positive.
Bringing that positivity down to earth, when the future is fuzzy, changes oh so fast, and we all hold a basic philosophy of “bring it on” and “we’ll just keep learning new things” is hard.
We kept it honest.
I’d like to thank the panelists here in Montreal, Aaron Portnoy, Marion Marschalek, and John McIntosh for stepping up and keeping it fun.
The guests who joined us with interventions, Sergey Bratus who knows how to ask the hard questions, and Dragos Ruiu who found an immediate example of where research with AI just isn’t there.
And the guests who joined on zoom at 1:30 am and 5:30 am, Thomas Dullien and Thai Duong, who stayed on and participated. We didn’t plan for that originally, and they deserve special acknowledgement:
Panels are complicated even before you participate in them blind over zoom, without seeing the other panelists or the audience, and without sleep. Thank you, Halvar, Thai.
To the recon team, and especially Hugo, Anne, Nathan, and Devin, we appreciate all you do! Thanks for bringing us yet another incredible recon.
Recently, I started asking agents to force-find security issues. I (mostly) gave up on determinism and harness complexity, focusing on results. Especially now when they are good enough to deliver in one shots such as this.
Here’s my simple, token-heavy, Gadi-loop:
Scan this project for security vulnerabilities and issues in any way, using every way. Start with the whole project, then file by file, functionality by functionality, and function by function. Loop this: Continue trying no matter what. Don’t stop for anything, and improve and try new things every time, Karpathy auto-research style. Mechanics: Use an independent and a judge from raw for everything. Concurrency N=15 with full isolation. Use a pipeline. Critical: Always write down what you try. Always check what you tried before.
Of course, this doesn’t replace using tools like raptor for autonomous security testing capabilities, or OpenAnt for LLM-based vulnerability discovery.
These would ensure reachability and coverage, adjust to the application’s threat model, provide a depth in findings, as well as verification of slop to make sure these findings are real.
But it’s beyond effective. Try it.
Careful on the spend, the loop will absolutely splurge on tokens so don’t just leave it over-night. You can toggle that in the loop prompt by changing the concurrency, independent/judge usage, and by introducing run repetition/time limits.
—
And of course, if you’d like to discover and defend your agents, coding assistants, and their wider supply chain (extensions, skills, MCP, etc.) ask me for a demo of Knostic, or try it out for yourself (free up to five licenses).
Demo: https://knostic.ai/demo
Free: https://getkirin.com/
So cool. An LLM-based, language-agnostic vulnerability variant hunter was presented yesterday by Michal Kamensky at BlueHat IL.
The talk, along-side Amir Gombo, was about hybrid cloud vulnerabilities, but that wasn't what excited me.
Give the variant hunter a known bug (a report + vulnerable code file), and a target codebase, and it would find variants of that same bug class, regardless of language or control flow, then verify exploitability. This is especially useful for logical vulnerabilities.
As presented, Michal eliminated a whole class of vulnerabilities in Microsoft's Hybrid Cloud with the tool.
Essentially, the variant hunter inverts the classic SAST calculation.
With signature matching, someone hand-writes a per-language taint flow and the engine finds exactly that shape, so you only catch what you already described. A variant through a wrapper or renamed field slips past.
With Michal's variant hunter, the bug is described in natural language and the LLM judges whether code realizes that concept, so one definition generalizes across languages.
Michal’s method enables hunting for variants of logical bugs that could be unique to your product, with legitimate, “by design” flows. But then, in a specific context they become vulnerable.
In the talk, the example given was calling IMDS on the cloud, which is reasonable, but when done on-prem becomes an RCE.
Most current harnesses map flows in which vulnerabilities are plausible, Michal looks for vulnerabilities by creating a "logical flow signature", if I'm to abuse the analogy, making LLMs effective for logical bugs as well.
The architecture and pipeline with my interpretation (see video):
- Skill 1: Analyze. Distills the seed bug into 2 distinct outputs: the flow (in which a vulnerability might occur) and the reason this flow can become vulnerable. No function names, no literals.
- Skill 2: Find similar flows. All similar flows, no mention of the vulnerability.
- Skill 3: Correlate. For each similar flow found, decide whether it is vulnerable to the same issue or not.
- Skill 4: Verify. Independently and skeptically argues attacker-control, reachability, and sanitizers, and generates a poc.
Apparently, the variant hunter was written months ago. I'm beyond excited Michal made this concept public. It helps us further evolve in our thinking on vulnerability research with AI.
I asked Michal if she plans to open source, and she said: “When I taught people how to write custom Semgrep rules, they took the concepts and ran with them. Just ask the agent to implement it for you, and let’s see what wonderful ideas people come up with.”
My own take:
We must think differently to adapt to the AI age. Every moment wasted on super useful and effective older techniques - empowered by AI - means we aren't learning to think differently, while models keep on advancing, leaving us further behind.
Thank you to #BlueHatIL, Microsoft, and Hila Yerushalmi for a wonderful BlueHat IL, 2026.
Knostic’s OpenAnt, the first (and leading!) open source LLM vulnerability discovery project is now also a paper pre-print on arxive.
A lot of the methodology described is about how to arrange code in a way LLMs would find usable (Units), and on adversarial methods, copied straight from Claude Code (if it works, don’t reinvent it).
It’s interesting how most harnesses seem to have converged around the same methodology described in the paper. That’s not necessarily because of us, and hey, we stand on the shoulders of giants, but rather because it seems to simply be what works (for now)
We wrote it in February, and startup life happened. We decided to stop waiting to have time to fully edit it, and release it as a pre-print.
Main author and the researcher behind it is Nahum Korda, I helped.
Thanks to many others along the way, such as Imri Goldberg Michal Kamensky Gary McGraw Danny Geyshis Shahar Davidson Alex Raihelgaus Josh Grossman Avi Douglen, and for helping me figure out arxive, to Thorsten Holz.
We hope you find it useful.
Paper:
http://arxiv.org/abs/2606.19149
Repo:
https://github.com/knostic/OpenAnt
—
And of course, if you’d like to secure your agents, coding assistants, and their supply chain (extensions, skills, MCP, etc.) check out what we do at Knostic.
Free up to five users:
https://getkirin.com/
SaassyCode wave: Five new malicious VS Code extensions, 32,000+ total Installs.
On June 8, 2026, Knostic published findings on the SaassyCode campaign: a coordinated family of nineteen malicious VS Code extensions posing as Trello-style Kanban board tools, Roblox, etc.., with combined installs exceeding 17,544. In the two days that followed, the campaign published five more.
As of June 11, the total stands at 24 confirmed extensions and more than 32,000 installs across the full campaign. One extension, Boardwalk Plus, remains live on the VS Code Marketplace.
Unlike TrelloBlox (the sleeper confirmed in the previous report), Boardwalk Plus carries no clean version. Version 1.7.3 is the only version published, and it was malicious on publication
More information:
https://www.knostic.ai/blog/saassycode-post-disclosure-wave-five-new-extensions-32000-total-installs
—
And of course, if you’d like to discover and defend your agents, coding assistants, and their supply chain (extensions, MCP, skills(, ask me for a demo of Knostic, or download it. Free up to five licenses.
Demo: https://knostic.ai/demo
Free: https://getkirin.com/
The biggest damage AI has done is making people who had nothing to say start saying it out loud every single day on LinkedIn until my feed became an industrial slop of cringe generated content, this is why we can’t have nice things
Trust me, there’s less propaganda on Multivac, at least THOSE bots are authentic
I swear it’s like everyone here posts something they half-assed in Claude in ten minutes, plays with it for one minute, then launches a WEEK-LONG social campaign - “heHeHe how I saved 70% on toke—” OH SHUT UPPPP I will pay full price, extra extra usage, charge me double, take my tokens, I don’t care, JUST STOP TALKING
A graveyard of skills absolutely nobody will ever use.
Oh yeah tell me about Karpathy’s LLM wiki ONE MORE TIME, I definitely haven’t seen it in 50 different posts today
Everyone here acts like they’re Forbes Under 30, meanwhile I’m just surviving another round of layoffs every March
Anyway, California called, Anthropic’s next release is coming like a wildfire aimed at your Ouija boards. Thoughts and prayers.
Have a wonderful day
—
All credit for this goes to the brilliant Adir Duchan (ההוא מהזה), in the original Hebrew.
My contribution? I laughed hard, and translated with Claude’s help... Okay, it was mainly Claude!
A week later, my TL;DR take on Mythos:
1. We've all survived 20-30 apocalyse(s) in our careers. We will survive this one, the Sun will rise tomorrow.
2. Mythos is new, and powerful, and not to be dismissed, but more than that now represents the wider problem. There are many capabilities that have been around for a long time, a couple that are new, and many other models that will follow.
3. Mythos is the name of the problem now, as it's how most discovered it, including the press, the Board, and our families.
It is a REAL and IMMENSE problem, with HYPE attached. But the hype doesn't make it any less real, or any less disruptive.
--
And as usual, if you'd like to discover or protect your agents and coding assistants, drop me a line, or check out what we do Knostic.
As you walk the expo, as you meet vendors claiming to secure agents and coding assistants, ask them:
- Are you able to start a PoC today?
- Do you do anything beyond hooks, sandboxes, or proxies?
Or, most critically, just ask: How are you better than Knostic?
Because they’re not.
At Knostic, we’re the company to beat. We predicted this problem and are mature to start working with you - today.
Ask Sounil Yu or myself for a demo.
I reposted Katie Moussouris earlier, but wanted to say more: “We don’t think it’s practical or appropriate to centrally decide who gets to defend themselves. Instead, we aim to enable as many legitimate defenders as possible, with access grounded in verification, trust signals, & accountability.”
Following Anthropic's Glasswing initiative, OpenAI is expanding its security access program, allowing defenders to access otherwise limited security research capabilities.
To many in the industry, the move felt like a "me too" play, even though OpenAI had originally announced its own plan before Anthropicת and Sam Altman spoke about the problem of models becoming good at security months ago, positioning it as a challenge.
Me too or not, they are owning it.
They are clearly differentiating by positioning themselves as the ideological opposite of Anthropic's program.
That said, no one said Anthropic won't expand its program.
On the PR front, seeing some good messaging from OpenAI instead of Anthropic, for once, is pretty cool.
Life keeps getting interesting!
https://openai.com/index/scaling-trusted-access-for-cyber-defense/
Two VS Code extensions, published days apart, both marketed as WordPress/WooCommerce tooling. Spoilers, they aren't. IOCs in the writeup. Thanks Tamir Isaschar for the research!
Do check out how we help you defend your coding agents, cowork agents, and agentic supply chain at Knostic! Ask me for a demo or just try it out yourself.
The real lesson with the Hugging Face incident is: “CISOs learn of new risks not already on their radar through data breaches”. And, there are breaches and incidents we should pay attention to right now:
GitHub, AWS, and yes - Hugging Face.
Waiting for proof in a data breach is too slow. Partial proof (see Anthropic, Sysdig, and MX gov), and capability (agents could do it) needs to be enough.
The quote above is from one of the legendary CISOs of our time, Shaun Marion. He deeply understands risk, and has the hard job of prioritizing it.
However, sometimes he prioritizes wrong, and a data breach is what he looks to, for adjusting his risk perspectives. That’s why good security programs are resilient and dynamic.
Right here, in discussions with you, I and some others predicted the AI vulnerabilities explosion, autonomous attacks, and zeroed time to exploitation. I don’t think I’m special, I just watch for risk earlier in the cycle, which is what we all should do now.
And indeed, I put my money where my mouth is, and we pivoted Knostic all the way back then.
So before we discuss these breaches, when the time comes for you to invest in securing agents (now?), I’d appreciate the opportunity to show you what Sounil Yu, myself, and the team built at Knostic, to defend them.
Now, proof. Let’s look at the three recent breaches and incidents, and what they mean:
- GitHub isn’t about tightening your basics, it’s about agents and their supply chain (a VS Code extension in this case) - a risk you can control, but current controls don’t cover.
If you use coding or Cowork agents, you must secure them and their associated supply chain (extensions, skills, MCP, etc.) There will always be a hole for them to exploit, and they are unmonitored in any meaningful way.
- The two AWS outages weren’t about production permissions or human error in using the wrong tool, but about agents again - a risk you can control.
You can tighten permissions forever or try sandboxes or network proxies, and you will still miss something. If you use coding or Cowork agents, you must secure agents in the agent, like an EDR secures Windows on the OS.
- The Hugging Face incident has only just happened, and we don’t know much. What we do know is that they were stopped from moving fast in defense, by model guardrails.
The previous two incidents were about engineering, this one is about you and your team. Using agents regularly for all activities on your team is a must to stay relevant.
It would also enable you to be as good as Hugging Face, but also to already understand limitations and plan for them. Realizing such risks in advance may have had you ready to also adopt open weight models, when the big labs can’t serve you.
Contact me for a demo, and let’s continue the conversation on what’s coming.
An Expedited Strategy Briefing on Mythos, Glasswing, and building a security program for what comes next, by 250 CISOs, and the wider community.
It is still a draft, with some design elements incomplete, but we felt it was imperative to release it and update as we go.
Link:
https://labs.cloudsecurityalliance.org/mythos-ciso/
Ask: Could you help share here and in professional groups to help us spread the word? We'd really appreciate it!
This started as a quick response to the Mythos Preview model announcement, toward the CSA's emergency CISO Zoom huddle on Tuesday, and turned into something none of us expected.
Thank you to my co-authors, who once again went with my last-minute crazy ideas:
Rich Mogull, Rob T. Lee Jen Easterly Bruce Schneier Chris Inglis Phil Venables Heather Adkins Rob Joyce Sounil Yu Jim Reavis Katie Moussouris John Stewart Maxim Kovalsky Dave Lewis Joshua Saxe John Yeoh Ramy Houssaini and James Lyne
To the Cloud Security Alliance, SANS Institute, [un]prompted, and OWASP GenAI Security Project, this collaboration is just the start. We look forward to doing more together in the future, to serve the wider community.
Thank you to everyone else who participated in making this happen - and there are many of you I can't list 250 people on LinkedIn, but A special mention to reviewers who spent several full days on this:
David B. Cross Ariel Litvin Rock Lambros Steve Wilson John Sotiropoulos Gary Hayslip Mike Johnson
Do me a favor? Check out the full list of reviewers, see who you my know, and send them a private thank you note?