Loading…
17-18 September | Amsterdam, Netherlands
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
Thursday September 17, 2026 16:20 - 16:45 CEST
Prompt injection ends when the session ends. Memory poisoning doesn't.
As enterprise agents mature, three attack surfaces are converging: MCP server trust, agent skill libraries, and long-term memory retrieval. Each is dangerous in isolation. Together, they create a threat model most teams aren't yet reasoning about.

MCP enables agents to acquire tools dynamically, including from servers never explicitly authorised. Agent skills package reusable behaviours that can be poisoned at the source. Memory systems built on vector retrieval treat past experience as trusted context, with limited provenance validation.

The MINJA research (NeurIPS 2025) demonstrated injection success rates approaching 98% across GPT-4o, Gemini, and Llama-based agents. Crucially, better reasoning models don't solve this - they may amplify it. A more capable model becomes more faithful to a poisoned memory once retrieved.

OWASP's 2026 Agentic Top 10 dedicates a standalone category: ASI06 Memory and Context Poisoning.

This session maps the attack chain, shares real enterprise exposure patterns, and offers a framework for memory provenance tracking, skill validation, and MCP server trust evaluation.
Speakers
avatar for Steven Duckaert

Steven Duckaert

EMEA Pre-Sales, Onyx
Steven Duckaert leads EMEA Pre-Sales at Onyx Security, working with enterprises across the region on the security and governance challenges of deploying AI agents at scale.
With a background in AI product strategy and go-to-market, Steven focuses on agentic AI adoption and enterprise risk helping security teams understand what they're running before it becomes a problem... Read More →
Thursday September 17, 2026 16:20 - 16:45 CEST
Emerald Room (Level 1)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link