Reco to brief Black Hat on AI agent security risks
Tue, 4th Aug 2026 (Today)
Three Reco security specialists will deliver sessions on AI agent security at Black Hat USA and DEF CON 34. The presentations will examine security gaps linked to AI agents in business software and workflows.
The sessions will focus on how agents are increasingly embedded in applications, copilots, browsers and internal processes that employees already use. Reco argues that this is creating risks that can fall outside existing governance and security oversight.
One session will be led by Shir Grinfeld, head of product growth at Reco. It will outline what the company describes as a three-phase framework for reducing the time in which AI agents can exploit weaknesses across enterprise systems.
The talk will cover how organisations can identify misconfigured applications, unenforced single sign-on policies and over-privileged tokens before agents exploit them. It will also address detecting and responding to machine-speed OAuth probing during an incident, and preserving access trails for later remediation and executive reporting.
A separate workshop at DEF CON 34 will be led by Nitay Bachrach, security researcher at Reco, and Cynthia Ardman, threat detection engineer at Reco. It will focus on Salesforce Experience Sites, which Reco describes as an under-tested area of enterprise application security.
The workshop will examine Aura and LWR frameworks, custom Apex controllers running in system mode, SOQL injection, unauthenticated route enumeration and LWRed, an open-source scanner for LWR sites. The session is aimed at pentesters and red teamers who need a way to assess Salesforce sites that standard web testing can miss.
Agent exposure
Reco's broader argument is that AI agents are becoming a distinct attack surface because they do more than interact with prompts or models. They can inherit permissions, use OAuth grants, trigger actions and expose data through trusted systems already woven into business operations.
That framing reflects a wider shift in cybersecurity as businesses adopt generative AI tools and autonomous functions within established software environments. Rather than introducing separate systems, many organisations are adding agent-based functions to products and workflows already connected to identity tools, customer portals and internal data.
In this model, security concerns often centre on access rather than malware in the conventional sense. If an agent can act through a legitimate application with broad permissions, the risk may stem from inherited trust, weak configuration and incomplete visibility over third-party integrations.
Reco positions its sessions around that problem, arguing that governance programmes built for users and standalone software tools may not fully account for agents operating across multiple systems. That, it says, can create security debt as controls fail to keep pace with the spread of agent-driven functions.
Salesforce focus
The emphasis on Salesforce Experience Sites points to a specific concern for security teams responsible for external-facing business applications. Such sites can support customer and partner interactions and may include custom logic, integrations and permission structures that differ from standard websites.
By highlighting custom Apex controllers, route enumeration and SOQL injection, the workshop is designed to focus on technical weaknesses that can arise when enterprise application frameworks are not tested with dedicated methods. Reco argues that standard web testing often does not examine those areas in enough depth.
The release also underlines how security discussions around AI are broadening beyond model misuse and prompt attacks. Here, the focus is on operational exposure created when agents interact with software estates that include applications, identities, permissions and workflows.
Reco describes itself as a specialist in agent ecosystem security. Its platform, the company says, covers agents and the environments where applications, identities and workflows intersect, with more than 260 application integrations and 1,000 detection controls.
According to Reco, its system is used by security leaders at Fortune 500 enterprises seeking to manage the spread of AI agents and the risks created by their connections across business systems.