Everyone is diving headfirst into the AI pool. The problem is they're diving into the shallow end. LLMs are being packed into every nook and crannie, mostly places nobody wanted it or asked for it. I'm going to be taking a baseball bat to LLMs - their hallucinatory nature and the extra instructions we're saddled with we don't get to see.. I'll be showing logs of how they literally talk themselves into lying to you. It's bad. Bring a helmet. Prompt engineering has become harness engineering, and now its "memory and context engineering". Openclaw and now codex are storing local files and 'memories' to try and handle the 'context window problem'. Moltbook has 3 million 'agents'. Openclaw is being used as a c2 now. TeamPCP is infecting every npm package they can with backdoors - weekly at this point! Just in 2026 alone we have more than tripled the number of supply chain bugs in tooling used in the LLM landscape The attack surface is growing so rapidly we can barely keep track of it. This talk will explore all this new attack surface, and cover some of the things you can do about it, and how to avoid the landmines and pitfalls when using LLMs.
Dan Tentler
Dan is the founder of Phobos Group, a boutique information security consulting and architecture firm, specializing in assessment work, security architecture, remediation efforts, advisory and simulation services. Dan's been at this a long time. Come talk to him about Phobos Airlock!
Security Fest is an inspiring and unique IT security conference held in Gothenburg, Sweden. The event is an excellent opportunity to learn more about IT security, and a great way to connect with both the renowned international speakers, and the other attendees.
TLDR; isolate your runtime. I got this working early Q4 2025 for Claude Code, since then I also have it for codex / pi-agent / opencode and I moved to transient workspaces, readonly config mounts. I didn't use incus/lxc because I use throwaway VPSs + docker for process isolation.
The only thing still on my wishlist is a full hashicorp vault secrets orchestration for forge tokens. Currently the forge is isolated over wireguard and mTLS, and RBAC'd, but it would be good to not expose any secrets to agents at all. Just proxy endpoints that inject credentials based on workday authorizations. It can't really do anything except access prior work it is authorized to, but still, 16h token lifetimes are better than 30 day lifetimes.
Frank Herbert warn us long time ago...
Nice
🔗 Privacy-friendly: https://invidious.tiekoetter.com/watch?v=yvJYw2gR0cU