Building EDR for AI: Controlling Autonomous Agents Before They Go Rogue with Ron Eddings

Building EDR for AI: Controlling Autonomous Agents Before They Go Rogue with Ron Eddings

AI agents aren't just reacting anymore, they're thinking, learning, and sometimes deleting your entire production database without asking. The real question isn't if your AI agent will be hacked, it's when, and whether you'll have the right hooks in place to stop it before it happens.

In this episode, Ron breaks down the ChatGPT Atlas vulnerability that shocked researchers, revealing how malicious prompts can turn AI assistants against their own users by bypassing safeguards and accessing file systems. He presents his new talk "Hooking Before Hacking," introducing a framework for applying EDR principles, prevention, detection, and response, to AI agents before they execute unauthorized commands. From pre-tool use hooks that catch malicious intent to one-time passwords that put humans back in the loop, this episode shares practical security controls you can implement today to prevent your AI agents from going rogue.

Impactful Moments:

00:00 - Introduction 02:00 - ChatGPT Atlas vulnerability exposed 04:00 - AI technology outpacing security guardrails 05:00 - Guardrail jailbreaks and prompt injection 06:00 - AI agents deleting production databases 07:00 - EDR principles for AI agents 09:00 - Pre-tool use hooks catch intention 11:00 - User prompt sanitization prevents leaks 14:00 - One-time passwords for agent workflows 16:00 - Automation mistakes across 10 years

Links:

Connect with Ron on LinkedIn: https://www.linkedin.com/in/ronaldeddings/

Check out the entire article here: https://www.yahoo.com/news/articles/cybersecurity-experts-warn-openai-chatgpt-101658986.html

GitHub Repository: https://hackervalley.com/hooking-before-hacking

See Ron's "Hooking Before Hacking" presentation slides here: http://hackervalley.com/hooking-before-hacking-presentation

Check out our website: https://hackervalley.com/

Upcoming events: https://www.hackervalley.com/livestreams

Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com

Continue the conversation by joining our Discord: https://hackervalley.com/discord

Become a sponsor of the show to amplify your brand: https://hackervalley.com/work-with-us/

Join our creative mastermind and stand out as a cybersecurity professional: https://www.patreon.com/hackervalleystudio

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(431)

We Shipped a Tool That Acts Like You. Meet Interceptor.

We Shipped a Tool That Acts Like You. Meet Interceptor.

Think about everything you could accomplish if you don’t have to be the one driving your browser. In this solo episode, Ron Eddings introduces Interceptor, Hacker Valley Media's first piece of softwar...

14 Jul 30min

How to Turn Cybersecurity Customers into Lifelong Advocates with Antu Buck

How to Turn Cybersecurity Customers into Lifelong Advocates with Antu Buck

What if the same psychology that threat actors use to manipulate their targets is the same psychology that marketers use to earn your trust?  In this episode, Ron sits down with Antu Buck, Senior Dir...

7 Jul 30min

What's Really Stopping AI From Running Your SOC with Aqsa Taylor

What's Really Stopping AI From Running Your SOC with Aqsa Taylor

In 2025, out of all 70+ guests we had on our show, not one of them said they’d trust AI to run their SOC. Now in 2026, that mindset is shifting. In this episode, Ron sits down with Aqsa Taylor, Chief ...

23 Jun 31min

Feed Your Brain: What Cybersecurity Veterans Are Getting Wrong with Johnny Xmas

Feed Your Brain: What Cybersecurity Veterans Are Getting Wrong with Johnny Xmas

Is AI really coming for your red teaming job? What does it actually take to build a team that thinks like the adversary, and what happens when that team stops caring? And what do you do when you've be...

16 Jun 28min

Fighting Smarter: What Combat Sports Teaches Us About Cyber Defense with Robin Black

Fighting Smarter: What Combat Sports Teaches Us About Cyber Defense with Robin Black

What does a calf kick have to do with vulnerability management? What can a fighter's mindset teach a security practitioner about operating against an adversary they've never faced?  Ron Eddings bring...

9 Jun 25min

Is Vibe Coding Breaking the Internet? with Tanya Janca

Is Vibe Coding Breaking the Internet? with Tanya Janca

What happens when AI writes all the code and nobody reads it? What if the security prompt you trusted still produced software designed to leak your secrets? And who exactly is on the hook when an AI-g...

2 Jun 35min

Why Smart People Fall for Deepfakes with Perry Carpenter

Why Smart People Fall for Deepfakes with Perry Carpenter

What if the most sophisticated attack has nothing to do with your firewall? In a world where AI can clone voices, re-lip-sync politicians, and spread a fake newscast to 200,000 people in days, the rea...

26 Mai 35min

Who Owns Your AI Security Policy? with Chris Cochran

Who Owns Your AI Security Policy? with Chris Cochran

Right now, someone in your organization is probably feeding sensitive data into an AI system that nobody approved. So when something goes wrong, who's responsible? And more critically, do you even hav...

18 Mai 35min

Populært innen Fakta

fastlegen
dine-penger-pengeradet
relasjonspodden-med-dora-thorhallsdottir-kjersti-idem
foreldreradet
mikkels-paskenotter
rss-kunsten-a-leve
treningspodden
rss-strid-de-norske-borgerkrigene
sinnsyn
gravid-uke-for-uke
rss-sarbar-med-lotte-erik
tomprat-med-gunnar-tjomlid
hverdagspsyken
rss-var-forste-kaffe
fryktlos
dopet
tid-for-historie
hva-er-greia-med
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
babyverden