BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//fwd-cloudsec-2026//talk//LADYU9
BEGIN:VTIMEZONE
TZID:PST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T100000Z
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T110000Z
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-fwd-cloudsec-2026-LADYU9@pretalx.com
DTSTART;TZID=PST:20260601T095000
DTEND;TZID=PST:20260601T101000
DESCRIPTION:The Data perimeter is the gold standard for cloud-native securi
 ty boundary in AWS. It combines all available preventive security tools an
 d guardrails.\n\nIn this talk you will learn about a novel attack techniqu
 e that exploits AWS Bedrock AgentCore’s identity service to establish a 
 fully functional command and control channel (C2) capable of bypassing dat
 a perimeter controls - all while using legitimate capabilities. We will de
 monstrate how an attacker can use two covert channels hidden in plain sigh
 t: data exfiltration and unauthenticated data infiltration.\n\nWe will dem
 o the complete C2 channel operating end to end - an attacker establishing 
 persistence\, issuing commands and exfiltrating sensitive data from an S3 
 bucket containing user records\, all within an enforced data perimeter.\n\
 nWe will also walk through CloudTrail signals which will enable defenders 
 to detect this activity and discuss why new AI services demand security as
 sessment before adoption.
DTSTAMP:20260502T124109Z
LOCATION:Room 1
SUMMARY:No Way Out? C2 Through AWS Data Perimeter via Bedrock-AgentCore - D
 an Gansel
URL:https://pretalx.com/fwd-cloudsec-2026/talk/LADYU9/
END:VEVENT
END:VCALENDAR
