Skip to main content
bash TV

Securing Agentic AI

TestMu AI (Formerly LambdaTest)

8 views5 Sept 2026

YouTube

In this session, ๐ƒ๐ž๐ž๐ฉ๐ฌ๐ก๐ข๐ค๐ก๐š, Associate Director at Nagarro, and ๐€๐ง๐š๐ฆ๐ข๐ค๐š ๐Œ๐ฎ๐ค๐ก๐จ๐ฉ๐š๐๐ก๐ฒ๐š๐ฒ, Associate Director at Nagarro, make a point every tester should sit with: your AI-powered application can pass every functional test and still cause a serious security incident - not because it is broken, but because it followed the wrong instructions. Learn how to detect manipulation, data exposure and unsafe behavior in AI agents before they reach production. Deepshikha and Anamika also show how agents fail in the real world: a document that changes their behavior, a message that bypasses intended limits, a simple request that exposes sensitive data or triggers unintended actions while everything appears to be working normally. The session covers designing realistic security tests and validating that an agent behaves safely under pressure. ๐‡๐ข๐ ๐ก๐ฅ๐ข๐ ๐ก๐ญ๐ฌ: 0:00 Why an Agent Can Pass Every Functional Test and Still Cause an Incident 1:04 Speaker Intros - Deepshikha and Anamika Mukhopadhyay, Associate Directors at Nagarro 2:05 From AI That Answers to AI That Acts on Your Behalf 4:38 Real Incidents: Deleted Production Data, Leaked Enterprise Information 5:40 The Problem Isn't the Model - It's Planning, Memory, Tools and Actions 6:11 Traditional LLM vs AI Agent: Why the Failure Mode Changes 7:44 Anatomy of a Single Enterprise Agent and Its Execution Loop 8:47 The Attack Surface Map 9:50 Five Areas to Review: Planning, Memory, Tools, Identity, Communication 11:22 Multi-Agent Systems Multiply Identities and Trust Boundaries 12:23 MCP as Part of Your Security Boundary 13:54 Mapping Threats Across the Agentic Architecture 15:29 Threat 1 - Goal Manipulation: The Hidden White-Text Calendar Invite 17:34 One Injected Instruction Becoming a Chain of Tool Calls 18:06 Threat 2 - Memory Poisoning: The Travel Agent and the Fake Free Flight 20:10 RAG Risks: Cross-Tenant Retrieval, Knowledge and Embedding Poisoning 22:46 Threat 3 - Tool Misuse: The Right Tool With the Wrong Intent 24:20 The Refund Cap That Was Talked Past by a Support Ticket 25:22 A Real Food-Delivery Refund the Speaker Got by Accident 26:23 Threat 4 - The Confused Deputy and Privilege Abuse 27:55 Why Forensics Fail: The Agent Holds the Credentials, Not the Attacker 28:59 Threat 5 - Communication Poisoning and Infectious Backdoors 31:34 How to Validate: Testing the Planning Surface With Prompt Injection 33:36 Testing Memory: Poisoning, Cross-Session Isolation, RAG Evaluation 35:12 Testing Tool Execution and Boundary Violations 37:14 Testing Identity: Authorization Throughout the Workflow, Not Just Login 38:47 Testing Agent-to-Agent Communication With Mocks and Replays 41:53 Three Takeaways: New Attack Surfaces, Test the Whole Decision Loop 43:24 Q&A: Genuinely Intelligent vs Optimised for a Benchmark 45:30 Q&A: Prompt Injection Is Still the Number One Vector Register for TestMuConf 2027: https://www.testmuai.com/testmuconf-2027/?utm_source=youtube&utm_medium=organic&utm_term=&utm_campaign=securing_agentic_ai #TestMuConf #TestMuAI #AISecurity #AgenticAI #PromptInjection #SecurityTesting #AIQuality #AppSec

Join the discussion

Sign in to join the discussion

Sign in