Sécurisez l’avenir : IA, infonuagique et cyberrisque
Download resourcesAbout this session
Fouad Hamdache, a solutions engineer at Trend AI, walks through a fictional but realistic attack chain against a mid-size organization's ('Municorp') customer-service chatbot, mapped to OWASP's LLM Top 10. Attackers first probe the bot with malformed queries to leak its parsing model, then use an indirect prompt injection hidden in a third-party forum review to make it disclose its full system prompt, internal tool names and API access. From there they abuse an unvalidated internal summarization API to exfiltrate raw customer data, then smuggle a shell command through a prompt to achieve remote code execution on production infrastructure, ending with access to secrets, credentials and intellectual property. He replays the same chain showing where each step could have been stopped: pre-deployment AI scanning and red-teaming, a real-time 'AI Guard' gateway inspecting every input and output, container image scanning and runtime behaviour monitoring, and zero-trust, least-privilege design so the bot cannot be tricked into acting outside its intended role. He closes on defense-in-depth across users, applications, models, infrastructure, APIs and data, and on Canadian data-residency requirements, noting Trend AI's Vision One platform keeps customer data within Canadian jurisdiction.
Un clavardeur de service à la clientèle peut devenir la porte d'entrée d'une brèche complète. Fouad Hamdache, ingénieur de solutions chez Trend AI, déroule une chaîne d'attaque contre un agent conversationnel, calquée sur le Top 10 OWASP pour les LLM : sondage du bot par requêtes malformées pour révéler son fonctionnement interne, injection de prompt indirecte cachée dans un avis de forum tiers pour extraire le prompt système et les outils accessibles, abus d'une API interne de résumé pour exfiltrer des données clients, puis exécution de code à distance sur l'infrastructure de production via une commande shell glissée dans un prompt. La session rejoue chaque étape pour montrer où l'intercepter : analyse et red teaming avant déploiement, passerelle IA inspectant entrées et sorties en temps réel, surveillance des conteneurs, conception zéro confiance et résidence des données au Canada.
Key takeaways
- Treat any customer-facing AI chatbot as a reconnaissance surface: malformed queries and odd error messages can leak your parsing model and internal architecture to a prober before a real attack even starts.
- Scan for prompt-injection risk before deployment (automated AI red-teaming), since the attack in this case started with an indirect prompt injection hidden in an ordinary third-party review, not a sophisticated zero-day.
- Deploy a real-time gateway that inspects every input and output of an AI application (an 'AI Guard' pattern) so leaked system prompts, malicious instructions and data exfiltration attempts are blocked in transit, not after the fact.
- Apply zero-trust, least-privilege scoping to AI agents themselves: an agent built to summarize should be structurally unable to execute raw SQL or shell commands, not merely discouraged from doing so.
- Secure the infrastructure the AI runs on, not just the model: container image scanning and runtime behaviour monitoring closed the path this attack used to reach production servers and secrets.
Speakers

Fouad Hamdache is a Senior Cybersecurity Solutions Consultant at Trend Micro, with more than 12 years of experience designing and deploying enterprise security solutions across cloud, hybrid, and on-premise environments. He specializes in the Trend… Read moreRead less
Fouad Hamdache is a Senior Cybersecurity Solutions Consultant at Trend Micro, with more than 12 years of experience designing and deploying enterprise security solutions across cloud, hybrid, and on-premise environments. He specializes in the Trend Vision One platform and AI security, and works with organizations to modernize their threat detection and response through XDR, Zero Trust, and risk-based architecture. Fouad brings a hands-on, practical approach to security conversations, drawing on real deployments rather than theory. He regularly speaks at industry events across Canada, helping public and private sector teams cut through the noise around AI adoption and turn cyber risk into something they can actually plan for and manage, rather than just react to.

