A developer on your team clones a repository. They hit Enter when Claude Code asks if they trust the project folder. That single keypress launches an MCP server from.mcp.json — a server they never reviewed, running as an OS process with their full filesystem access, live cloud credentials, and authenticated AWS CLI session attached. They never see a second prompt. They never know it happened. This is not a hypothetical. It is the documented behaviour behind CVE-2025-59536, reported by Check Point Research, and the TrustFall vulnerability class that Adversa AI demonstrated across Claude Code, Cursor, Gemini CLI, and Copilot in May 2026. The tools that make us productive — the agents that read our files, call our APIs, manage our repositories, and execute commands on our behalf — are now the primary targets. The Bitwarden CLI attack of April 2026 made this explicit: malware spent 90 minutes on npm specifically hunting for authenticated instances of Claude Code, Cursor, Codex CLI, and Gemini CLI. Not as collateral damage. As the objective. Prevention is necessary and insufficient. These tools exist to have persistent access to the things attackers want. The question is not whether that access can be locked down, it is what happens when it is not. That is where deception changes the equation.
This talk presents a deception framework for preemptive security of agentic systems. The core premise is simple: deception artifacts placed at every layer of the agent attack surface provide early, high-confidence alerts at each phase of the kill chain before damage is done, before exfiltration occurs, often before the attacker knows they have been detected. Unlike reactive controls that wait for known signatures or anomaly thresholds to breach, deception fires the moment an adversary touches something no legitimate agent workflow ever touches. The alert is not probabilistic.
The framework covers all four layers of the agent attack surface Identity and Credentials, Protocol Services, Agent Capabilities, and Supply Chain — and maps each technique to a specific phase of the attack kill chain: Discover, Harvest, Infiltrate, Escalate, Execute, Exfiltrate. At each phase, a named deception artifact intercepts the adversary and produces a triage signal before they advance to the next. The kill-chain interception map is the central contribution: a practitioner framework that tells security teams exactly where to place deception artifacts, what each one catches, and when the alert fires relative to the attack timeline.
The talk also covers what failed — three classes of techniques that appeared promising, survived initial design, and were discarded after adversarial testing — and closes with three open problems the framework does not yet solve: the semantic fingerprinting arms race against capable reasoning models, the operational cost of maintaining temporal indistinguishability at scale, and the self-defeating nature of publishing deception technique catalogs in the first place.
The central claim: Deception technology, deployed across the full agentic attack surface, provides preemptive security — early kill-chain alerts that fire before an adversary reaches a real asset. Every phase of the AI agent kill chain has a corresponding deception interception point. None of them require model changes or exotic infrastructure. All of them require engineering discipline and the commitment to maintain artifacts that degrade the moment they stop evolving.
This site uses cookies to ensure that you get the best experience possible. To learn more about how we use cookies, please refer to our Privacy Policy & Cookies Policy.
It is needed for personalizing the website.
Expiry: Session
Type: HTTP
This cookie is used to prevent Cross-site request forgery (often abbreviated as CSRF) attacks of the website
Expiry: Session
Type: HTTPS
Preserves the login/logout state of users across the whole site.
Expiry: Session
Type: HTTPS
Preserves users' states across page requests.
Expiry: Session
Type: HTTPS
Google One-Tap login adds this g_state cookie to set the user status on how they interact with the One-Tap modal.
Expiry: 365 days
Type: HTTP
Used by Microsoft Clarity, to store and track visits across websites.
Expiry: 1 Year
Type: HTTP
Used by Microsoft Clarity, Persists the Clarity User ID and preferences, unique to that site, on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID.
Expiry: 1 year
Type: HTTP
Used by Microsoft Clarity, Connects multiple page views by a user into a single Clarity session recording.
Expiry: 1 Day
Type: HTTP
Collects user data is specifically adapted to the user or device. The user can also be followed outside of the loaded website, creating a picture of the visitor's behavior.
Expiry: 2 years
Type: HTTP
Use to measure the use of the website for internal analytics
Expiry: 1 years
Type: HTTP
The cookie is set by embedded Microsoft Clarity scripts. The purpose of this cookie is for heatmap and session recording.
Expiry: 1 year
Type: HTTP
Collected user data is specifically adapted to the user or device. The user can also be followed outside of the loaded website, creating a picture of the visitor's behavior.
Expiry: 2 months
Type: HTTP
This cookie is installed by Google Analytics. The cookie is used to store information of how visitors use a website and helps in creating an analytics report of how the website is doing. The data collected includes the number of visitors, the source where they have come from, and the pages visited in an anonymous form.
Expiry: 399 days
Type: HTTP
Used by Google Analytics, to store and count pageviews.
Expiry: 399 Days
Type: HTTP
Used by Google Analytics to collect data on the number of times a user has visited the website as well as dates for the first and most recent visit.
Expiry: 1 day
Type: HTTP
Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.
Expiry: Session
Type: PIXEL
cookies ensure that requests within a browsing session are made by the user, and not by other sites.
Expiry: 6 months
Type: HTTP
use the cookie when customers want to make a referral from their gmail contacts; it helps auth the gmail account.
Expiry: 2 years
Type: HTTP
This cookie is set by DoubleClick (which is owned by Google) to determine if the website visitor's browser supports cookies.
Expiry: 1 year
Type: HTTP
this is used to send push notification using webengage.
Expiry: 1 year
Type: HTTP
used by webenage to track auth of webenagage.
Expiry: session
Type: HTTP
Linkedin sets this cookie to registers statistical data on users' behavior on the website for internal analytics.
Expiry: 1 day
Type: HTTP
Use to maintain an anonymous user session by the server.
Expiry: 1 year
Type: HTTP
Used as part of the LinkedIn Remember Me feature and is set when a user clicks Remember Me on the device to make it easier for him or her to sign in to that device.
Expiry: 1 year
Type: HTTP
Used to store information about the time a sync with the lms_analytics cookie took place for users in the Designated Countries.
Expiry: 6 months
Type: HTTP
Used to store information about the time a sync with the AnalyticsSyncHistory cookie took place for users in the Designated Countries.
Expiry: 6 months
Type: HTTP
Cookie used for Sign-in with Linkedin and/or to allow for the Linkedin follow feature.
Expiry: 6 months
Type: HTTP
allow for the Linkedin follow feature.
Expiry: 1 year
Type: HTTP
often used to identify you, including your name, interests, and previous activity.
Expiry: 2 months
Type: HTTP
Tracks the time that the previous page took to load
Expiry: Session
Type: HTTP
Used to remember a user's language setting to ensure LinkedIn.com displays in the language selected by the user in their settings
Expiry: Session
Type: HTTP
Tracks percent of page viewed
Expiry: Session
Type: HTTP
Indicates the start of a session for Adobe Experience Cloud
Expiry: Session
Type: HTTP
Provides page name value (URL) for use by Adobe Analytics
Expiry: Session
Type: HTTP
Used to retain and fetch time since last visit in Adobe Analytics
Expiry: 6 months
Type: HTTP
Remembers a user's display preference/theme setting
Expiry: 6 months
Type: HTTP
Remembers which users have updated their display / theme preferences
Expiry: 6 months
Type: HTTP
Used by Google Adsense, to store and track conversions.
Expiry: 3 months
Type: HTTP
Save certain preferences, for example the number of search results per page or activation of the SafeSearch Filter. Adjusts the ads that appear in Google Search.
Expiry: 2 years
Type: HTTP
Save certain preferences, for example the number of search results per page or activation of the SafeSearch Filter. Adjusts the ads that appear in Google Search.
Expiry: 2 years
Type: HTTP
Save certain preferences, for example the number of search results per page or activation of the SafeSearch Filter. Adjusts the ads that appear in Google Search.
Expiry: 2 years
Type: HTTP
Save certain preferences, for example the number of search results per page or activation of the SafeSearch Filter. Adjusts the ads that appear in Google Search.
Expiry: 2 years
Type: HTTP
Save certain preferences, for example the number of search results per page or activation of the SafeSearch Filter. Adjusts the ads that appear in Google Search.
Expiry: 2 years
Type: HTTP
Save certain preferences, for example the number of search results per page or activation of the SafeSearch Filter. Adjusts the ads that appear in Google Search.
Expiry: 2 years
Type: HTTP
These cookies are used for the purpose of targeted advertising.
Expiry: 6 hours
Type: HTTP
These cookies are used for the purpose of targeted advertising.
Expiry: 1 month
Type: HTTP
These cookies are used to gather website statistics, and track conversion rates.
Expiry: 1 month
Type: HTTP
Aggregate analysis of website visitors
Expiry: 6 months
Type: HTTP
This cookie is set by Facebook to deliver advertisements when they are on Facebook or a digital platform powered by Facebook advertising after visiting this website.
Expiry: 4 months
Type: HTTP
Contains a unique browser and user ID, used for targeted advertising.
Expiry: 2 months
Type: HTTP
Used by LinkedIn to track the use of embedded services.
Expiry: 1 year
Type: HTTP
Used by LinkedIn for tracking the use of embedded services.
Expiry: 1 day
Type: HTTP
Used by LinkedIn to track the use of embedded services.
Expiry: 6 months
Type: HTTP
Use these cookies to assign a unique ID when users visit a website.
Expiry: 6 months
Type: HTTP
These cookies are set by LinkedIn for advertising purposes, including: tracking visitors so that more relevant ads can be presented, allowing users to use the 'Apply with LinkedIn' or the 'Sign-in with LinkedIn' functions, collecting information about how visitors use the site, etc.
Expiry: 6 months
Type: HTTP
Used to make a probabilistic match of a user's identity outside the Designated Countries
Expiry: 90 days
Type: HTTP
Used to collect information for analytics purposes.
Expiry: 1 year
Type: HTTP
Used to store session ID for a users session to ensure that clicks from adverts on the Bing search engine are verified for reporting purposes and for personalisation
Expiry: 1 day
Type: HTTP
Cookie declaration last updated on 24/03/2023 by Analytics Vidhya.
Cookies are small text files that can be used by websites to make a user's experience more efficient. The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses different types of cookies. Some cookies are placed by third-party services that appear on our pages. Learn more about who we are, how you can contact us, and how we process personal data in our Privacy Policy.
We use cookies essential for this site to function well. Please click to help us improve its usefulness with additional cookies. Learn about our use of cookies in our Privacy Policy & Cookies Policy.
Show details