Back to [un]prompted Security Practitioner Con 2026

Podcast Episode

Ep 9 | Brendan Dolan-Gavitt & Vincent Olesen - Agents Exploiting "Auth-by-One" Errors | [un]prompted 2026

About this episode

Day 1 | Stage 1 Presents techniques for finding and validating access control flaws using AI agents. Uses strict validators for identifying successful logins (AuthN) and protected resource access (AuthZ) to build capable attack agents. Shows how to enable LLM-powered agents to discover and validate access control vulnerabilities at scale. Brendan Dolan-Gavitt is AI Researcher, XBOW. Vincent Olesen is AI Researcher, XBOW. Watch on YouTube: https://www.youtube.com/watch?v=996zolUsXog