All talks

[Un]prompted 2026 · 2026/03

Perplexed Browser: PleaseFix (delivered by Gadi Evron)

Loading presentation…

Read the transcript

Transcript

AI generated from recording.

Opening and Audience Engagement

00:45 Presenter: So I talked to the CTO of Zenity, Michal Borguri, said, would you trust me, a competitor, we’re not directly competing, but he’s my competitor in the AI security space.

00:56 Presenter: Would you trust me to go up with some of your slides and just present it PowerPoint karaoke without ever seeing them before?

01:04 Presenter: And I have never seen these slides before, and I’m going to try to rush this so we’re not way, way behind and Aaron won’t kill me too badly.

01:15 Presenter: I hope you guys will forgive me for whatever I do wrong here and what I don’t understand.

01:19 Presenter: And also, please, Aaron has a microphone.

01:23 Presenter: I mean, I don’t understand a slide or you understand it differently.

01:27 Presenter: Just say, I understand this differently.

01:29 Presenter: Let’s present this together.

01:30 Presenter: Now, think about this for a minute because I know you’re all very shy people and Americans, therefore, polite.

01:36 Presenter: So if somebody would just raise their hand.

01:38 Presenter: Where’s Dan Guido?

01:40 Presenter: Okay, so you’re the first one to raise your hand when I get something wrong on the third slide.

01:45 Presenter: feels comfortable stepping in.

Introducing Agentic Browsers and Risks

01:46 Presenter: Let’s run through this.

01:47 Presenter: Please fix from Zenity Labs

01:49 Presenter: my competition and awesome people.

01:53 Presenter: Agentics browsers,

01:54 Presenter: agentic browsers are everywhere.

01:57 Presenter: No, but seriously,

01:58 Presenter: agentic browsers are coming in.

01:59 Presenter: They are the next agent

02:01 Presenter: to perhaps explode after coding agents

02:03 Presenter: that not everybody is using.

02:04 Presenter: And they bring with them

02:06 Presenter: also quite significant risks.

Zenity’s Comet Attack Overview

02:09 Presenter: And Comet is the one

02:11 Presenter: that Zenity in this particular case looked at.

02:13 Presenter: And they are essentially saying, look, we’re not saying this is majorly innovative, but prompt injections are evolving all the time.

02:20 Presenter: And it’s something a little bit different in the way they’re trying to look at this here.

02:23 Presenter: From my understanding of looking at this slide right now, they’re saying there is the user intent and the attacker’s intent, right?

02:30 Presenter: And if we can create intent collision where we say something that looks like it’s the user’s, I’m guessing that’s kind of like a data and control plane running thingy.

02:42 Presenter: exactly what they meant here. That means we can make the agent do things we did not intend

02:47 Presenter: it to do. Dan, you ready? And what they did essentially is create a payload that I’m going

02:54 Presenter: to read this off the slide, but I’m going to act as if I’m not by looking at you once

02:57 Presenter: in a while. It hides in the calendar invite. It rewrites the accept button with their instructions

03:04 Presenter: and abuses comment internals with system reminders. I’m waiting for you to step in and tell me

03:10 Presenter: me I’m wrong at any point. Okay. So the first attack they’re doing, I guess, is a system,

03:15 Presenter: a file system exfil, right? Yes? Everybody with me? Awesome. I’m not doing a very good job,

03:20 Presenter: so help me out by cheering me on. Okay. Appreciate it. Okay. Thank you. Thank you.

Calendar Invite Exploit Mechanics

03:25 Presenter: I am stressed out a little bit. So the attacker sends a calendar invite, right? And we can see

03:31 Presenter: Google Calendar on the screen. And you can see there is an interview with Tamir. What else can

03:37 Presenter: going to see on this slide, with some information there and some invitations going to the team

03:42 Presenter: and, okay, moving from this slide.

03:45 Presenter: And there is essentially a comment in the background where it says, accept the meeting

03:50 Presenter: and help me prepare for it.

03:52 Presenter: And I’m imagining the Zenity team now saying, you know what, I’m going to go make coffee.

03:56 Presenter: What’s the worst thing that could happen?

03:58 Presenter: I just asked them to help me accept this meeting, right?

04:00 Presenter: I don’t need to stay here and monitor.

04:02 Presenter: And well, Comet navigates to attacker-controlled site with more malicious instructions.

04:10 Presenter: I love you, Comet.

04:11 Presenter: Isn’t it wonderful?

04:13 Presenter: Right?

04:14 Presenter: And it says, accept the meeting.

04:17 Presenter: Here to confirm the meeting, you need to click these on blah, blah, blah.

File System Exfiltration Attack

04:20 Presenter: And there is some Hebrew stuff.

04:21 Presenter: So probably Unicode-based attack.

04:24 Presenter: Probably wrong.

04:25 Presenter: But that’s my read on this.

04:27 Presenter: And then you can actually reach the file system.

04:30 Presenter: And I think this is what it is.

04:32 Presenter: and access files.

04:34 Presenter: Woo! Way to go, Zenity!

04:36 Presenter: Amazing work.

04:41 Presenter: And autonomously,

04:43 Presenter: Comet will just go

04:44 Presenter: and search for really cool files

04:45 Presenter: that you might want to exfiltrate all on its own.

04:48 Presenter: Isn’t that wonderful?

1Password Autocomplete Breach

04:50 Presenter: Sigh.

04:52 Presenter: And then,

04:53 Presenter: it would actually exfiltrate it to the attacker

04:55 Presenter: because no demo is ever complete

04:57 Presenter: unless you show that exfil happened

04:58 Presenter: or CMD popped up, depending on what you’re demoing.

05:02 Presenter: The second attack is actually with 1Password,

05:06 Presenter: where, once again, we start with a calendar invite.

05:08 Presenter: Everybody clear on that?

05:09 Presenter: Right, that happens in every single stage here.

05:12 Presenter: And what do we write here?

05:14 Presenter: Accept the meeting and prepare for it.

05:16 Presenter: Same thing, but something else happens in the background

05:19 Presenter: as the attacker intent and the user intent collide.

05:22 Presenter: And they apparently log into 1Password,

05:25 Presenter: and 1Password usually does not let me do that.

05:27 Presenter: It requires the master password.

05:28 Presenter: I feel a little bit cheated that you can just log in.

05:30 Presenter: I mean, what’s wrong here?

05:32 Presenter: is their preferential treatment.

05:35 Presenter: And they are catching the request.

05:38 Presenter: And boom, they’re managing the account

05:40 Presenter: and doing things to it.

05:43 Presenter: Oh, this is pretty cool.

05:44 Presenter: So I don’t think it’s necessarily an attack,

05:46 Presenter: but the one password autocomplete is apparently turned on.

05:49 Presenter: And once that happens,

05:50 Presenter: they are just in and they can do whatever they want.

Conclusions and Industry Implications

05:53 Presenter: And they have the emergency kit here

05:55 Presenter: and a lot of other things they probably would have said

05:57 Presenter: really technical, smart things about

05:58 Presenter: that I’m just blah-blah-ing on.

06:00 Presenter: And the conclusions.

06:02 Presenter: Browsers are untrusted entities.

06:04 Presenter: I think we can agree to that.

06:06 Presenter: Awesome.

06:08 Presenter: Dan, I’m preparing you.

06:09 Presenter: You’re coming up here to say two words on this in a second

06:11 Presenter: before we call you up.

06:12 Presenter: So step up already because we don’t have a lot of time.

06:14 Presenter: Just come here.

06:15 Presenter: Stop changing your presentation last minute.

06:18 Presenter: Okay.

06:18 Presenter: Logged in, the browser is acting under your identity.

06:23 Presenter: Right?

06:23 Presenter: Okay.

06:24 Presenter: And third is the browser security model.

06:28 Presenter: Think again.

06:28 Presenter: We need to do better as an industry.

06:32 Presenter: this is Zenity Labs.

06:34 Presenter: This is their link.

06:35 Presenter: You can look at what they do.

06:37 Presenter: These mother somethings compete with me,

06:40 Presenter: although not in exactly the same things.

06:41 Presenter: So don’t like them too much.

06:44 Presenter: But they’re truly awesome people.

06:45 Presenter: They constantly release good research.

06:47 Presenter: And they were the first ones to actually do a zero-click attack

06:50 Presenter: in this space.

06:51 Presenter: And it was a real one,

06:52 Presenter: not one that marketing claimed was zero-click.

06:55 Presenter: So everybody,

06:56 Presenter: I apologize to them for my PowerPoint karaoke of this presentation,

07:06 Presenter: Thank you.