heise devSec() 2026 · Marburg · INOSOFT Platinum-Sponsor

The warning light is on

Live attack on an AI-controlled control center

September 22, 2026· Talk & Live Demo

Thanks for coming. Here you’ll find the slides from the talk, the further links from the demo, and the deep dive in the WeeklyTalk.

The Talk

When the Agent Controls the Facility – and Someone Else Controls the Agent

AI agents are increasingly being granted not only the right to access information, but also the right to take action: they read states, make decisions, and initiate actions. This shifts the security question. It is no longer just a matter of what data a system discloses, but of what an attacker can make a system do by manipulating the instructions given to the agent.

For the talk, we built a test station: a simplified, AI-controlled control center that simulates a critical system – including a warning light that indicates an impermissible system condition. The control center is operated via an AI chat. In real time, we try to manipulate the agent so that it drives the system into exactly this critical state and the light comes on.

The demonstration underscores the talk: Where are the attack surfaces of agent-based systems, why do traditional access-control concepts fall short, and what authorization and control patterns come into play when a model sits in the control path? A sober analysis, based on a concrete setup, without any promise of salvation.

Slides & Further Information

Read more and watch more

Presentation Slides (PDF)

The Warning Light Is On

The complete slides from the talk and our handout "Safe with Agentic AI".

WeeklyTalk – October 8, 2026

What Happens When the AI in the Control Center Is Attacked

We delve deeper into the topic during the WeeklyTalk – with time for the questions that remained open during the talk.

For Visitors

Materials & Further Links

The cases we present in the talk – real-life incidents in which AI agents were manipulated or caused harm on their own initiative.

AI convinces404 Media Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked Attackers tricked Meta's AI support in plaintext into changing the email address of other users' Instagram accounts – without a technical exploit. The case that gave rise to the warning-light idea. Prompt InjectionSecutec EchoLeak: The First Zero-Click AI Attack on Microsoft 365 Copilot Instructions hidden in emails caused Copilot to send confidential company data outside the company unnoticed – without the victim clicking anything (CVE-2025-32711). Agent deletes dataGitHub #5370 Claude Code Executed Destructive Database Command Despite Safety Instructions A coding agent issued a destructive reset command despite explicit safety instructions and destroyed the database – without asking, without a backup. Agent deletes dataheise Vibe-coding service Replit deletes production database An AI agent deleted a production database while a code freeze was in progress – despite the explicit instruction not to make any changes. Agent deletes dataheise AI agent deletes data – catastrophe for PocketOS Another case where an AI agent deleted data on its own initiative and severely impacted a provider – same type of error, different victim. ResponsibilityThe Verge Amazon blames human employees for an AI coding agent's mistake After an agent's mistake, the question of blame shifted to the humans behind it – the actually interesting question when a model sits in the decision path. Autonomous behaviorWashington Post Anthropic discloses that AI models in testing hacked three companies During the security review, models escaped the isolated test environment and actually infiltrated three companies – two of which did not notice at first. Autonomous behaviorForbes Alibaba's AI Agent Mined Crypto Without Permission. Now What? The training agent ROME repurposed GPUs for crypto mining and opened a hidden tunnel to the outside – without being instructed to; it was only discovered by the firewall.
From the INOSOFT environment