×
Profile

mbgsec

Breaking AI agents, hacking, citizen development and infosec.
By Michael Bargury 😈 · Over 2 subscribers!
By subscribing, I agree to Terms of Use and Information Collection Notice recieving nerdy emails from Michael
No thanks >
  • Skip to primary navigation
  • Skip to content
  • Skip to footer
Michael Bargury Michael Bargury
  • Talks
  • WIP
  • Weblog
  • About
    Michael Bargury

    Michael Bargury

    Security research, hacking, AppSec, primarily focused on AI agents.

    • X
    • BlueSky
    • GitHub
    • LinkedIn
    • RSS

    Followup links for All You Need Is Guest RSAC 2024

    less than 1 minute read

    Assorted links for All You Need Is Guest @ RSAC 2024:

    1. Power Platform DLP Bypass via Copy & Paste
    2. OWASP No-Code / Low-Code Top 10
    3. powerpwn
    4. Microsoft docs on EntraID multitenant sharing options

    Other talks (slides and source code)

    1. All You Need is Guest @ BlackHat USA 2023
    2. Sure, Let Business Users Build Their Own. What Could Go Wrong? @ BlackHAt USA 2023
    3. Low Code High Risk: Enterprise Domination via Low Code Abuse @ DEFCON30
    4. No-Code Malware: Windows 11 At Your Service @ DEFCON30

    Updated: May 5, 2024

    Share on

    X Facebook LinkedIn Bluesky
    Previous Next

    You May Also Enjoy

    How Should AI Ask for Our Input?

    2 minute read

    Enterprise systems provide a terrible user experience. That’s common knowledge. Check out one of the flash keynotes about the latest flagship AI product by ...

    Pwn the Enterprise - thank you AI! Slides, Demos and Techniques

    6 minute read

    We’re getting asks for more info about the 0click AI exploits we dropped this week at DEFCON / BHUSA. We gave a talk at BlackHat, but it’ll take time bef...

    Someone Is Cleaning Up Evidence

    1 minute read

    AWS security blog confirms the attacker gained access to a write token and abused it to inject the malicious prompt. This confirms our earlier findings.

    Reconstructing a timeline for Amazon Q prompt infection

    4 minute read

    In the 404media article the hacker explains how they did it:

    • Twitter
    • Weblog Feed
    • Feed
    © 2025 Michael Bargury. Powered by Jekyll & Minimal Mistakes.