Bandana
Kaur1
aka hackwither
- 1Security Research Engineer, APISec Research Labs
Abstract
Hacking a cyberspace that's liveable for all.
19-year-old researcher breaking AI agents: A2A peer hijacking in Google’s Agent Development Kit, security-label forgery in Microsoft’s Agent Framework, reported vulnerabilities in MCP servers with two CVEs assigned. Spoke on three tracks at Black Hat MEA, as one of its youngest speakers: technical briefing, campus keynote and the WiCSME panel. Author of REAP and two arXiv papers.
Selected vulnerability research
-
Hijacking Google ADK Using Malicious A2A Peers
A remote A2A peer can supply forged control metadata that steers agent routing, session state and even conversation history inside Google’s ADK: a privilege-escalation path from a connected agent to the framework itself.
Sept 2026 · Google Agent Development Kit
reported to Google ahead of publication -
Trust Me, Bro: Forging Security Labels in Microsoft’s FIDES Middleware
FIDES contains prompt injection by enforcing integrity labels outside the model. Its implementation assumed data can’t describe its own trust level; the finding shows where that assumption breaks and labels can be forged.
Sept 2026 · Microsoft Agent Framework
MSRC case 126767 · closed as defense-in-depth -
Catfishing the Allowlist: MCP Security’s Argument Injection Blind Spot
An MCP server that allowlists only
gitstill gives full command execution through git’s own alias mechanism. Executable-only allowlists can’t bound what an allowed binary does with its arguments.Featured in AI Cyber Magazine, Fall 2026 edition
Aug 2026 · MCP servers
GHSA-jm26-853c-62h9 · high
Also disclosed: two reserved CVEs in MCP server implementations, records pending publication; a report to the U.S. Department of Education acknowledged by its CISO, and, at 16, a report to India’s NCIIPC covering data of ~399k government officers. All through coordinated disclosure.
Keynotes and talks
| year | venue | where |
|---|---|---|
| 2026 | GISEC Global: Exploiting MCP Servers: The AI Let Me In · live hacking demo · also a panel and a fireside chat | Dubai |
| 2026 | UNIDIR Global Conference on AI, Security and Ethics (AISE26): Breaking the black box: A standardized lifecycle model for adversarial AI testing · lightning talk | Geneva |
| 2026 | NIST FISSEA Spring Forum: Trust as an Attack Surface: Human Risk in Black-Box AI Systems · speaker | online |
| 2026 | Gautam Buddha University, Health and Medical Biotechnology Symposium · keynote | Greater Noida |
| 2025 | Black Hat MEA Campus: The Last Human Hacker: What Comes After AI · keynote | Riyadh |
| 2025 | Black Hat MEA: Hack one, hack them all? Weaponising LLM jailbreak transferability · technical briefing · also the WiCSME panel | Riyadh |
Selected papers
-
Kaur, B. (2026). What AI Red-Team Evaluations Can and Cannot Prove. arXiv:2607.21735.
Derives a closed-form evidential ceiling: the most a single red-team result can move belief under a fixed testing budget. Benchmarks can certify safety for frequent harms, but fall orders of magnitude short for rare, high-impact ones.
Fig. 1 Two regimes, schematic and not to scale. An audit of eight evaluation suites finds them adequate for high-frequency harm categories and several orders of magnitude short for rare, catastrophic ones. Abstract and figures·arXiv·PDF·doi:10.48550/arXiv.2607.21735
discrimination between hypotheses, not attack success, sets evidential worth
-
Kaur, B. (2026). Broken Object Level Authorization in the Wild: An Empirical Taxonomy from 100+ Bug Bounty Disclosures. arXiv:2605.25865.
Classifies 107 HackerOne disclosures into six BOLA families. Action-level object BOLA (unauthorised state changes on other users’ objects) accounts for 41.7% of confirmed cases.
Fig. 2 The 107 classified reports, one square each. Pink: action-level object BOLA (35 of 84 confirmed). Solid: the other confirmed families. Outlined: outside strict BOLA criteria. Abstract and figures·arXiv·PDF·doi:10.48550/arXiv.2605.25865
200 sampled → 107 classified → 84 confirmed
Tool
REAP v0.1.1 · MIT · Go
Black-box reconnaissance for AI agent endpoints. Point it at an MCP endpoint you’re authorised to test: it confirms the protocol, lists what an anonymous caller can reach, and reports auth and transport posture. It reads, never invokes.
brew install hackwither/tap/reap
most scanners tell you what they found. REAP also tells you what it could not check.
Experience
| 2025–now |
Security Research Engineer, APISec Research Labs · San Francisco
|
| 2024–now |
Independent security researcher, hackwither
|
| 2024–now |
NICE Cybersecurity Career Ambassador (volunteer), NIST
|
| 2026 |
Research Fellow, SPAR (Supervised Program for Alignment Research)
|
| 2025 |
Board Member and Cybersecurity Lead, UN IGF Dynamic Teen Coalition
|
| 2024 |
Guest lecturer at government CISO training program, Indian Institute of Public Administration · New Delhi
|
Notes
| Jun 2026 | Acknowledgement is not remediation · At 16 I reported a vulnerability exposing PII and financial data of ~399k Indian government officers to NCIIPC. Finding and acknowledging bugs doesn't secure systems. Remediation does. |
| Dec 2025 | The thing about roadmaps in cybersecurity… · How to start in cybersecurity without a one-size-fits-all roadmap: start with the big picture, pick a niche, pivot if it doesn't click, then go deep. No sponsored certs. |
Work with me
The Last Human Hacker: What Comes After AI?
What comes after AI: how the adversary landscape changes as autonomous agents and synthetic identities enter the threat surface, and why the frontier is human–AI symbiosis. First given as the Black Hat MEA campus keynote.
keynote · 30–45 minThe Hacker’s Guide to AI Agents
A recon-to-exploitation methodology for agentic systems, MCP and A2A integrations.
talk · 30 minEvidential Ceilings
What AI red-team evaluations can and cannot prove. For teams that run, buy or rely on AI safety evals.
talk · 30–45 min
Keynotes, conference talks or research collaboration: bandana@hackwither.co.in. How to book.