8 Minutes to Admin. We Caught It in the Wild. Welcome to VibeHacking

Sergej Epp

[un]prompted 2026 — AI Security Practitioner Conference · Day 2 · 1

AI review

Epp walked in with logs from a real incident where an attacker literally named their role session 'claude-session' and tried to AssumeRole into account IDs that look exactly like what you get when you ask ChatGPT for example AWS account IDs. The verifier asymmetry framework is the most useful defensive mental model I've seen come out of AI security in 18 months.

Watch on YouTube