BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//program.wiccon.nl//DGAYA3
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-wiccon-2026-DGAYA3@program.wiccon.nl
DTSTART;TZID=CET:20261030T133000
DTEND;TZID=CET:20261030T142000
DESCRIPTION:Getting an LLM to spill its secrets is a subtle artform\, part 
 social engineering of the application\, and part social engineering of the
  humans (and other LLMs) who built it. It's witchy magic that's both gentl
 e and assertive: you ask nicely to stay under the abuse radar\, then tell 
 the bot to step outside its role entirely. \nIn this talk I'll walk throug
 h what I've learned testing LLMs across chatbots\, lifestyle assistants\, 
 and enterprise tools - from leaking system prompts and hunting indirect\, 
 no-authentication prompt injection\, to chaining an AI's own "legitimate" 
 tools into something destructive. I'll cover real attacks like using the A
 I's own tools to ransom a company\, turning connected integrations into ex
 filtration channels\, and the crossover where this all starts to look a lo
 t like traditional web application testing. They told us SQL injection was
  dead\, and we just reimagined it\, gave it a new name\, and pointed it at
  the model. \nExpect practical techniques\, a healthy respect for how conf
 idently these systems lie\, and a reminder that organisations need people 
 who think this way because people with worse intentions are already doing 
 it.
DTSTAMP:20260922T183851Z
LOCATION:Main Hall
SUMMARY:I jailbroke a scam bot with 1 prompt\, and so can you - Yianna Pari
 s
URL:https://program.wiccon.nl/wiccon-2026/talk/DGAYA3/
END:VEVENT
END:VCALENDAR
