Cybersecurity Growth

← Cybersecurity Growth18 Aug · 42 min

One Click, One Rogue Agent

One Click, One Rogue Agent18 Aug42 min

One Click, One Rogue Agent: Agent Forger, the EY Help Desk Breach & How to Work Black Hat/DEF CON

Shawn Valle and Garrett Gross return on Cybersecurity Growth to discuss three topics: Agent Forger, where a crafted phishing link to a ChatGPT URL could silently deploy an attacker-controlled AI agent that inherits a user’s enterprise integrations (email, calendar, cloud storage) and enables data exfiltration and persistence, prompting leaders to inventory AI agents and their authorized access; an Ernst & Young breach tied to Shiny Hunters, where a help desk/ITSM platform exposed sensitive client tax data, highlighting how ticketing systems can become “shadow data lakes” and the need to reassess third-party risk and data handling; and guidance for security leaders attending Hacker Summer Camp (BSides LV, Black Hat, DEF CON), including planning meetups, defining ROI, doing post-conference briefings, and basic OPSEC like avoiding open Wi‑Fi and clearing remembered networks.

00:00 Cold Open & Welcome

02:00 Topic 1 — AgentForger

08:40 Topic 2 — EY Breach

17:27 Topic 3 — Hacker Summer Camp

40:37 Rapid Takeaways & Close

-----------------------------------------------------------------------------------

🔐 Hire a cybersecurity consultant or vCISO: https://cybersecuritygrowth.com/services

🟢 Free Blogs, Videos and Podcasts: https://cybersecuritygrowth.com/webca...

👥 Become a Member of our Self-paced Cybersecurity Training & Community: https://members.cybersecuritygrowth.com/

👕 Get your Cybersecurity Growth Merch: https://cybersecuritygrowth.com/store/