hackwither_

Talks

Keynotes, technical briefings and live hacking demos on AI agent security, for conferences and leadership. Past stages include Black Hat MEA, GISEC Global, UNIDIR in Geneva and NIST.

Book a keynote or talk ↓

  • Exploiting MCP Servers: The AI Let Me In

    GISEC Global. A live demonstration of exploiting MCP servers, from recon to code execution. Also on the Dark Stage: the panel Fixing the Pipeline: Where Are the Next Women Leaders in Cyber? and the fireside chat Too Young to Hack? Think Again.

    2026 · Dubai
    live hacking demo · also a panel and a fireside chat
  • The Hacker’s Guide to AI Agents: From Recon to Exploitation

    Security BSides Jaipur. How an attacker approaches an AI agent: reconnaissance and capability discovery first, exploitation second. Introduces REAP for enumerating agent endpoints, and a practical methodology for assessing MCP and agent-to-agent integrations.

    2026 · Jaipur
    talk · 30 min
  • Breaking the black box: A standardized lifecycle model for adversarial AI testing

    UNIDIR Global Conference on AI, Security and Ethics (AISE26). A standardised lifecycle model for adversarial testing of AI systems in military and security domains. Palais des Nations, Geneva, and online.

    2026 · Geneva
    lightning talk
  • Trust as an Attack Surface: Human Risk in Black-Box AI Systems

    NIST FISSEA Spring Forum. How the black-box nature of AI tools in government workflows breeds over-trust and automation bias, how ordinary use of AI-assisted tools can weaken organisational defences, and how awareness programmes need to change in response.

    2026 · online
    speaker
  • Gautam Buddha University, Health and Medical Biotechnology Symposium

    Invited keynote on AI and LLM security in healthcare: prompt injection, data poisoning and model manipulation in clinical AI workflows.

    2026 · Greater Noida
    keynote
  • AI: From Buzz to Business

    E-Summit ’26, E-Cell IIT Roorkee. Moderated a panel on AI adoption, human-in-the-loop systems and operational risk in production.

    2026 · Roorkee
    panel moderator · outreach partner
  • The Last Human Hacker: What Comes After AI

    Black Hat MEA Campus. How the adversary landscape changes as autonomous agents and synthetic identities enter the threat surface, and the case for human–AI symbiosis as the security frontier. One of the youngest speakers in Black Hat MEA’s history.

    2025 · Riyadh
    keynote
  • Hack one, hack them all? Weaponising LLM jailbreak transferability

    Black Hat MEA. Live demo on a two-model testbed, a Mistral chatbot guarded by a LLaMA safety classifier: a multi-turn jailbreak transferred across models gets the classifier to pass malicious input as safe, ending in reflected XSS. Models the spread across LLM ecosystems as worm-like, and what that means for using AI to secure AI. Also the WiCSME × Black Hat MEA panel AI Gone Rogue: Deepfakes, GenAI Scams, and Agentic Attacks, recognised with a certificate of appreciation from Women in Cyber Security Middle East.

    2025 · Riyadh
    technical briefing · also the WiCSME panel
  • The API Hacker’s Guide to the AI Wild West

    APISec|Con. How AI applications are built on fragile API foundations, creating hybrid vulnerabilities where classic web flaws meet AI logic: IDOR and XSS inside chatbots, prompt injections that exploit backend APIs, and why traditional defences break down in non-deterministic systems.

    2025 · online
    invited speaker
  • Talk to Hack: Why the Future of API Abuse is Conversational

    APISec|Con. How LLMs in apps, support bots and RAG systems turn plain language into backend actions, and how attackers exploit that: prompt injection, hallucinated endpoints and unauthorised API calls, all through conversation. Language becomes the new payload.

    2025 · online
    invited speaker
  • AWIS DC STEAM Speaker Series

    Inaugural speaker for the Association for Women in Science DC chapter’s STEAM Speaker Series, representing girls in technology.

    2024 · online
    inaugural speaker
  • Indian Institute of Public Administration

    OSINT and social engineering training for government CISOs.

    2024 · New Delhi
    guest lecturer at government CISO training program

Delivered for

  • Black Hat MEA (campus keynote, technical briefing and panel)
  • GISEC Global, Dubai (live hacking demo)
  • UNIDIR AISE26, Geneva
  • NIST FISSEA Spring Forum
  • Gautam Buddha University (keynote on AI security in healthcare)
  • E-Summit ’26, E-Cell IIT Roorkee (panel moderator)
  • APISec|Con (twice)
  • AWIS DC STEAM Speaker Series (inaugural speaker)
  • Security BSides Jaipur
  • Government CISOs, Indian Institute of Public Administration

Book

Email bandana@hackwither.co.in with the event, date, audience and format. Keynotes, talks, panels and fireside chats, in person or remote.

Organisers: download a headshot (JPG, 800×1000).