Yianna Paris
Yianna Paris is an Australian-born security researcher now causing trouble as a Senior Offensive Security Consultant at Xebia in the Netherlands. She recently founded her training and research consultancy, Luda Hex. Her experience has spanned from deeply technical, high performing engineering companies to working for checkbox-compliance leadership. She breaks things professionally, from web apps, infrastructure, the architecture behind them, and increasingly the AI-powered systems everyone's bolting on without reading the manual. Her work spans penetration testing, secure coding, hardware and RF hacking, and the OSINT legwork of figuring out what an organisation actually runs versus what it thinks it runs (the two are rarely the same).
She's a DEFCON and Xebia Academy trainer, volunteer teaching kids to code, crafter and loves spending time in her garden. Having made the move from apologetic Aussie to we-say-what-we-mean Dutch directness, she's well-practised at pushing back, both on systems, and on the humans who built them.
Session
Getting an LLM to spill its secrets is a subtle artform, part social engineering of the application, and part social engineering of the humans (and other LLMs) who built it. It's witchy magic that's both gentle and assertive: you ask nicely to stay under the abuse radar, then tell the bot to step outside its role entirely.
In this talk I'll walk through what I've learned testing LLMs across chatbots, lifestyle assistants, and enterprise tools - from leaking system prompts and hunting indirect, no-authentication prompt injection, to chaining an AI's own "legitimate" tools into something destructive. I'll cover real attacks like using the AI's own tools to ransom a company, turning connected integrations into exfiltration channels, and the crossover where this all starts to look a lot like traditional web application testing. They told us SQL injection was dead, and we just reimagined it, gave it a new name, and pointed it at the model.
Expect practical techniques, a healthy respect for how confidently these systems lie, and a reminder that organisations need people who think this way because people with worse intentions are already doing it.