Transcript
AI generated from recording.
Opening and Audience Engagement
00:45 Presenter: So I talked to the CTO of Zenity, Michal Borguri, said, would you trust me, a competitor, we’re not directly competing, but he’s my competitor in the AI security space.
00:56 Presenter: Would you trust me to go up with some of your slides and just present it PowerPoint karaoke without ever seeing them before?
01:04 Presenter: And I have never seen these slides before, and I’m going to try to rush this so we’re not way, way behind and Aaron won’t kill me too badly.
01:15 Presenter: I hope you guys will forgive me for whatever I do wrong here and what I don’t understand.
01:19 Presenter: And also, please, Aaron has a microphone.
01:23 Presenter: I mean, I don’t understand a slide or you understand it differently.
01:27 Presenter: Just say, I understand this differently.
01:29 Presenter: Let’s present this together.
01:30 Presenter: Now, think about this for a minute because I know you’re all very shy people and Americans, therefore, polite.
01:36 Presenter: So if somebody would just raise their hand.
01:38 Presenter: Where’s Dan Guido?
01:40 Presenter: Okay, so you’re the first one to raise your hand when I get something wrong on the third slide.
01:45 Presenter: feels comfortable stepping in.
Introducing Agentic Browsers and Risks
01:46 Presenter: Let’s run through this.
01:47 Presenter: Please fix from Zenity Labs
01:49 Presenter: my competition and awesome people.
01:53 Presenter: Agentics browsers,
01:54 Presenter: agentic browsers are everywhere.
01:57 Presenter: No, but seriously,
01:58 Presenter: agentic browsers are coming in.
01:59 Presenter: They are the next agent
02:01 Presenter: to perhaps explode after coding agents
02:03 Presenter: that not everybody is using.
02:04 Presenter: And they bring with them
02:06 Presenter: also quite significant risks.
Zenity’s Comet Attack Overview
02:09 Presenter: And Comet is the one
02:11 Presenter: that Zenity in this particular case looked at.
02:13 Presenter: And they are essentially saying, look, we’re not saying this is majorly innovative, but prompt injections are evolving all the time.
02:20 Presenter: And it’s something a little bit different in the way they’re trying to look at this here.
02:23 Presenter: From my understanding of looking at this slide right now, they’re saying there is the user intent and the attacker’s intent, right?
02:30 Presenter: And if we can create intent collision where we say something that looks like it’s the user’s, I’m guessing that’s kind of like a data and control plane running thingy.
02:42 Presenter: exactly what they meant here. That means we can make the agent do things we did not intend
02:47 Presenter: it to do. Dan, you ready? And what they did essentially is create a payload that I’m going
02:54 Presenter: to read this off the slide, but I’m going to act as if I’m not by looking at you once
02:57 Presenter: in a while. It hides in the calendar invite. It rewrites the accept button with their instructions
03:04 Presenter: and abuses comment internals with system reminders. I’m waiting for you to step in and tell me
03:10 Presenter: me I’m wrong at any point. Okay. So the first attack they’re doing, I guess, is a system,
03:15 Presenter: a file system exfil, right? Yes? Everybody with me? Awesome. I’m not doing a very good job,
03:20 Presenter: so help me out by cheering me on. Okay. Appreciate it. Okay. Thank you. Thank you.
Calendar Invite Exploit Mechanics
03:25 Presenter: I am stressed out a little bit. So the attacker sends a calendar invite, right? And we can see
03:31 Presenter: Google Calendar on the screen. And you can see there is an interview with Tamir. What else can
03:37 Presenter: going to see on this slide, with some information there and some invitations going to the team
03:42 Presenter: and, okay, moving from this slide.
03:45 Presenter: And there is essentially a comment in the background where it says, accept the meeting
03:50 Presenter: and help me prepare for it.
03:52 Presenter: And I’m imagining the Zenity team now saying, you know what, I’m going to go make coffee.
03:56 Presenter: What’s the worst thing that could happen?
03:58 Presenter: I just asked them to help me accept this meeting, right?
04:00 Presenter: I don’t need to stay here and monitor.
04:02 Presenter: And well, Comet navigates to attacker-controlled site with more malicious instructions.
04:10 Presenter: I love you, Comet.
04:11 Presenter: Isn’t it wonderful?
04:13 Presenter: Right?
04:14 Presenter: And it says, accept the meeting.
04:17 Presenter: Here to confirm the meeting, you need to click these on blah, blah, blah.
File System Exfiltration Attack
04:20 Presenter: And there is some Hebrew stuff.
04:21 Presenter: So probably Unicode-based attack.
04:24 Presenter: Probably wrong.
04:25 Presenter: But that’s my read on this.
04:27 Presenter: And then you can actually reach the file system.
04:30 Presenter: And I think this is what it is.
04:32 Presenter: and access files.
04:34 Presenter: Woo! Way to go, Zenity!
04:36 Presenter: Amazing work.
04:41 Presenter: And autonomously,
04:43 Presenter: Comet will just go
04:44 Presenter: and search for really cool files
04:45 Presenter: that you might want to exfiltrate all on its own.
04:48 Presenter: Isn’t that wonderful?
1Password Autocomplete Breach
04:50 Presenter: Sigh.
04:52 Presenter: And then,
04:53 Presenter: it would actually exfiltrate it to the attacker
04:55 Presenter: because no demo is ever complete
04:57 Presenter: unless you show that exfil happened
04:58 Presenter: or CMD popped up, depending on what you’re demoing.
05:02 Presenter: The second attack is actually with 1Password,
05:06 Presenter: where, once again, we start with a calendar invite.
05:08 Presenter: Everybody clear on that?
05:09 Presenter: Right, that happens in every single stage here.
05:12 Presenter: And what do we write here?
05:14 Presenter: Accept the meeting and prepare for it.
05:16 Presenter: Same thing, but something else happens in the background
05:19 Presenter: as the attacker intent and the user intent collide.
05:22 Presenter: And they apparently log into 1Password,
05:25 Presenter: and 1Password usually does not let me do that.
05:27 Presenter: It requires the master password.
05:28 Presenter: I feel a little bit cheated that you can just log in.
05:30 Presenter: I mean, what’s wrong here?
05:32 Presenter: is their preferential treatment.
05:35 Presenter: And they are catching the request.
05:38 Presenter: And boom, they’re managing the account
05:40 Presenter: and doing things to it.
05:43 Presenter: Oh, this is pretty cool.
05:44 Presenter: So I don’t think it’s necessarily an attack,
05:46 Presenter: but the one password autocomplete is apparently turned on.
05:49 Presenter: And once that happens,
05:50 Presenter: they are just in and they can do whatever they want.
Conclusions and Industry Implications
05:53 Presenter: And they have the emergency kit here
05:55 Presenter: and a lot of other things they probably would have said
05:57 Presenter: really technical, smart things about
05:58 Presenter: that I’m just blah-blah-ing on.
06:00 Presenter: And the conclusions.
06:02 Presenter: Browsers are untrusted entities.
06:04 Presenter: I think we can agree to that.
06:06 Presenter: Awesome.
06:08 Presenter: Dan, I’m preparing you.
06:09 Presenter: You’re coming up here to say two words on this in a second
06:11 Presenter: before we call you up.
06:12 Presenter: So step up already because we don’t have a lot of time.
06:14 Presenter: Just come here.
06:15 Presenter: Stop changing your presentation last minute.
06:18 Presenter: Okay.
06:18 Presenter: Logged in, the browser is acting under your identity.
06:23 Presenter: Right?
06:23 Presenter: Okay.
06:24 Presenter: And third is the browser security model.
06:28 Presenter: Think again.
06:28 Presenter: We need to do better as an industry.
06:32 Presenter: this is Zenity Labs.
06:34 Presenter: This is their link.
06:35 Presenter: You can look at what they do.
06:37 Presenter: These mother somethings compete with me,
06:40 Presenter: although not in exactly the same things.
06:41 Presenter: So don’t like them too much.
06:44 Presenter: But they’re truly awesome people.
06:45 Presenter: They constantly release good research.
06:47 Presenter: And they were the first ones to actually do a zero-click attack
06:50 Presenter: in this space.
06:51 Presenter: And it was a real one,
06:52 Presenter: not one that marketing claimed was zero-click.
06:55 Presenter: So everybody,
06:56 Presenter: I apologize to them for my PowerPoint karaoke of this presentation,
07:06 Presenter: Thank you.