Workshop Intermediate 2 Hours 12:30 - 14:30 August 07, 2026

Ariel Fogel

Eilon Cohen

Danus

LLMs are no longer standalone chatbots. They're embedded into application logic, with access to databases, APIs, and internal services. The most dangerous exploits don't just manipulate the model; they use it as an attack vector to reach traditional AppSec targets. Prompt injection becomes SQL injection. Conversational manipulation enables SSRF. The AI agent becomes an unwitting insider threat. In this hands-on POD, you'll exploit a purpose-built vulnerable web application with an integrated AI agent, chaining LLM manipulation with classic web exploitation. Challenges span multiple difficulty levels, from basic prompt manipulation and information disclosure to multi-stage attacks combining indirect prompt injection with server-side vulnerabilities. Whether you're new to AI security or a seasoned pentester curious about LLM attack vectors, you'll walk away with practical techniques applicable to real-world assessments. No prior AI/ML experience required.

Ariel Fogel

AI Security Researcher @ Office of the CTO, Pillar Security

Ariel Fogel is a founding engineer & researcher at Pillar Security, where he hardens AI applications against real-world attacks and compliance risks. Over the past decade, he has built production systems in Ruby, TypeScript, Python, and SQL, shipping everything from full-stack web apps to data analytics pipelines. His academic and professional research work spans data-science methods, learning analytics, health policy, and cybersecurity. Ariel co-hosts the podcast “LLM Cybersecurity,” dissecting academic papers to demystify jailbreaks, prompt injections, and emerging AI-security research. In the few hours a week he's not thinking about AI, engineering, and security, Ariel spends time with his family or plays jazz on the upright bass. He's found that whether you're plucking strings or navigating family dynamics, success is all about harmony and knowing how to improvise.


Eilon Cohen

Head of Security Research @ Pillar Security

Eilon Cohen is Head of Security Research at Pillar Security, where he hunts vulnerabilities in frontier AI agents and orchestration platforms. His work on n8n's expression sandbox produced several critical findings, including CVE-2026-25049, an unauthenticated RCE rated CVSS 10.0 that exposed hundreds of thousands of enterprise AI workflows. His current research covers sandbox escapes, adversarial campaigns against AI infrastructure, and vulnerabilities in widely used AI assistants. He co-founded the AIL Community, an AI security knowledge-sharing group that has run events with Microsoft, OpenAI, and Nvidia. He has presented at RSAC 2025 and OWASP Global AppSec EU 2025 on ecosystem-wide supply chain vulnerabilities he discovered.


Danus

AI Security Researcher

Dan Lisichkin is the Cyber Security Researcher for Pillar Security, focusing on AI security, adversarial threats, and securing AI based systems. With over five years of experience in the cybersecurity and IT space, Dan has extensive knowledge in areas including malware analysis, reverse engineering, threat intelligence, and offensive security tactics. Prior to joining Pillar, Dan was a Cyber Security Researcher for Cymulate, where he specialized in threat intelligence and threat hunting; a Threat Intelligence Researcher for ClearSky Cyber Security; and an IT Consultant for Ernst & Young (EY).