Barno Kaharova
Rico Komenda
As AI transitions from stateless tools to autonomous agents, the context window has become the primary attack surface. By giving agents the ability to remember, summarize, and collaborate, we have created a machine that can be gaslit. This session moves beyond transient prompt injections into the realm of persistent memory corruption. We explore how an adversary can rewrite an agent’s history, bias its knowledge base, and plant sleeper instructions that trigger long after the initial interaction. We will dissect the systematic subversion of the agentic memory stack and demonstrate why developers must stop treating agent memory as a passive data store and start defending it as the engine of the agent’s survival
Barno Kaharova
adesso SE, Senior Consultant, AI Security Expert
Barno is a consultant and researcher specializing in AI security, data engineering, and ML security. She works at the intersection of offensive and defensive AI security, developing methodologies to protect AI systems from adversarial threats across the full stack from data pipelines and ML models to LLM-powered applications and autonomous agents. As an AI security trainer, Barno designs and delivers hands-on programs covering AI red teaming, prompt injection, adversarial ML, RAG and vector database security, and the OWASP Top 10 for LLM and Agentic AI. Her approach is practitioner-first: participants attack and defend real-world AI systems, leaving with techniques they can apply immediately. She is actively involved in AI governance and evaluation efforts at the national level and regularly contributes to the AI security community through speaking engagements, publications, and conference submissions, bridging rapid AI adoption with the need for robust, field-tested defenses.
Rico Komenda
Senior Product Security Engineer
Rico Komenda is a security engineer and researcher specializing in application security, cloud security, and AI security. He started as a software developer, moved into security engineering, and now focuses on the attack surface created by AI-integrated systems and secure agentic development.
He is Co-Lead of the OWASP AI Security Verification Standard (AISVS) and a core contributor to multiple OWASP GenAI security projects. Rico has spoken at NDC Security, OWASP Global AppSec EU, OWASP LASCON, WeAreDevelopers World Congress, DefCamp, and others.
He got into this field the way a lot of hackers do: writing scripts for video games as a teenager, getting curious about how systems break, and never stopping.