Uploaded December 2025 | Updated September 2026, 2 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/77/Global_AppSec_DC_Red%20vs%20Blue_Final.pdf
Context & Problem Statement
As organizations adopt agentic AI systems where LLMs autonomously plan, decide, and act, they must make sure they’re putting the right protections in place, so they won't unknowingly introduce invisible third-party dependencies. If the right protections aren’t put in place, agentic AI systems can blur traditional boundaries of identity, behavior, and trust. They do this by autonomously forming ephemeral relationships with tools, APIs, and other agents. These connections may be invisible to defenders and to everyone who relies on or uses these systems. In a Red team vs. Blue team context, this creates a dynamic battlefield where defenders must contend with novel threats like prompt injection, goal hijacking, and memory poisoning, while attackers exploit the very autonomy that makes these systems powerful.
Solution
This session presents a practical, AI-aware approach to threat modeling agentic AI systems because enabling AI with third party dependencies or Intergrations in said scenarios requires upfront planning. Using a Red vs. Blue simulation, we dramatize real-world attacks and defenses to expose vulnerabilities such as prompt injection, goal hijacking, and memory poisoning, and how successful exploitation can lead to impersonation, information leakage, and decision drift.
One speaker (Red Team) will demonstrate how attackers can manipulate agentic AI systems using techniques such as:
- Prompt Injection
- Goal Hijacking
- Memory Poisoning
The other speaker (Blue Team) will respond with defense strategies like:
- Agent policy enforcement
- Guardrails and tool access control
- Updated threat modeling frameworks like MAESTRO for dynamic AI behaviors
The session format will be engaging and interactive, showcasing both offense and defense in real-time. Attendees will learn how to adapt traditional frameworks and apply layered mitigations to secure unpredictable, autonomous AI systems.
Value Proposition
In this session, attendees will gain a threat-informed mindset and practical tools to assess and secure AI integrations, using adapted frameworks like STRIDE & MAESTRO and lightweight checklists for architecture reviews. Through a Red vs. Blue simulation, they’ll learn how to evaluate the unique risks of agentic AI systems and walk away with actionable strategies to defend against real-world attack scenarios.
Audience Takeaways
After attending this session, participants will:
- Identify critical risks in third-party AI integrations and agentic systems, including goal hijacking, prompt injection, and memory poisoning.
- Understand how agentic AI differs from traditional architectures and why it challenges conventional security assumptions.
- Adapt threat modeling techniques like STRIDE & MAESTRO to account for autonomy, tool use, and multi-agent orchestration.
- Recognize architectural weak points across model APIs, plugin ecosystems, and agent-based data flows.
- Apply practical checklists and reference models to evaluate AI behavior, identity, and decision-making patterns.
- Use Red vs. Blue simulations to train teams on real-world attack scenarios and implement effective blue team defenses.
Spandana Gorantla (she/her/hers) is a security engineer specializing in application and product security, currently focused on AI threat modeling. With a background spanning cloud security, secure architectures, and product security in fast-paced environments, she brings a practical and approachable lens to emerging security challenges.
Outside of work, Spandana is passionate about making security more accessible, building community, and mentoring aspiring professionals from underrepresented backgrounds. She’s also a big fan of hiking, lifting heavy things, and eating good food — preferably all in the same weekend.
linkedin.com/in/spandana-gorantla
At Adobe, I focus on fortifying AI/ML security and streamlining IAM services, which has significantly elevated our security framework. My expertise in conducting exhaustive application security testing and code reviews has been instrumental in protecting against sophisticated cyber threats. Our team's commitment to enhancing security through these initiatives has led to robust protection mechanisms for emerging technologies.
Previously at Amazon, I honed my skills in security assessments and bug bounty triage, particularly for Amazon Pay products, ensuring the secure integration of new payment instruments. My ability to collaborate effectively with service teams and PMs has facilitated the resolution of critical security issues, contributing to a more secure product ecosystem. Passionate about security innovation, I continue to drive strategic improvements in product security to deliver an uncompromising user experience.
linkedin.com/in/gilles-biagomba
Managed by the OWASP® Foundation
owasp.org
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/77/Global_AppSec_DC_Red%20vs%20Blue_Final.pdf
Context & Problem Statement
As organizations adopt agentic AI systems where LLMs autonomously plan, decide, and act, they must make sure they’re putting the right protections in place, so they won't unknowingly introduce invisible third-party dependencies. If the right protections aren’t put in place, agentic AI systems can blur traditional boundaries of identity, behavior, and trust. They do this by autonomously forming ephemeral relationships with tools, APIs, and other agents. These connections may be invisible to defenders and to everyone who relies on or uses these systems. In a Red team vs. Blue team context, this creates a dynamic battlefield where defenders must contend with novel threats like prompt injection, goal hijacking, and memory poisoning, while attackers exploit the very autonomy that makes these systems powerful.
Solution
This session presents a practical, AI-aware approach to threat modeling agentic AI systems because enabling AI with third party dependencies or Intergrations in said scenarios requires upfront planning. Using a Red vs. Blue simulation, we dramatize real-world attacks and defenses to expose vulnerabilities such as prompt injection, goal hijacking, and memory poisoning, and how successful exploitation can lead to impersonation, information leakage, and decision drift.
One speaker (Red Team) will demonstrate how attackers can manipulate agentic AI systems using techniques such as:
- Prompt Injection
- Goal Hijacking
- Memory Poisoning
The other speaker (Blue Team) will respond with defense strategies like:
- Agent policy enforcement
- Guardrails and tool access control
- Updated threat modeling frameworks like MAESTRO for dynamic AI behaviors
The session format will be engaging and interactive, showcasing both offense and defense in real-time. Attendees will learn how to adapt traditional frameworks and apply layered mitigations to secure unpredictable, autonomous AI systems.
Value Proposition
In this session, attendees will gain a threat-informed mindset and practical tools to assess and secure AI integrations, using adapted frameworks like STRIDE & MAESTRO and lightweight checklists for architecture reviews. Through a Red vs. Blue simulation, they’ll learn how to evaluate the unique risks of agentic AI systems and walk away with actionable strategies to defend against real-world attack scenarios.
Audience Takeaways
After attending this session, participants will:
- Identify critical risks in third-party AI integrations and agentic systems, including goal hijacking, prompt injection, and memory poisoning.
- Understand how agentic AI differs from traditional architectures and why it challenges conventional security assumptions.
- Adapt threat modeling techniques like STRIDE & MAESTRO to account for autonomy, tool use, and multi-agent orchestration.
- Recognize architectural weak points across model APIs, plugin ecosystems, and agent-based data flows.
- Apply practical checklists and reference models to evaluate AI behavior, identity, and decision-making patterns.
- Use Red vs. Blue simulations to train teams on real-world attack scenarios and implement effective blue team defenses.
Spandana Gorantla (she/her/hers) is a security engineer specializing in application and product security, currently focused on AI threat modeling. With a background spanning cloud security, secure architectures, and product security in fast-paced environments, she brings a practical and approachable lens to emerging security challenges.
Outside of work, Spandana is passionate about making security more accessible, building community, and mentoring aspiring professionals from underrepresented backgrounds. She’s also a big fan of hiking, lifting heavy things, and eating good food — preferably all in the same weekend.
linkedin.com/in/spandana-gorantla
At Adobe, I focus on fortifying AI/ML security and streamlining IAM services, which has significantly elevated our security framework. My expertise in conducting exhaustive application security testing and code reviews has been instrumental in protecting against sophisticated cyber threats. Our team's commitment to enhancing security through these initiatives has led to robust protection mechanisms for emerging technologies.
Previously at Amazon, I honed my skills in security assessments and bug bounty triage, particularly for Amazon Pay products, ensuring the secure integration of new payment instruments. My ability to collaborate effectively with service teams and PMs has facilitated the resolution of critical security issues, contributing to a more secure product ecosystem. Passionate about security innovation, I continue to drive strategic improvements in product security to deliver an uncompromising user experience.
linkedin.com/in/gilles-biagomba
Managed by the OWASP® Foundation
owasp.org






![OWASP Mobile Application Security (MAS) - Sven Schleier, Carlos Holguera
[This version has the sound fixed from Zoom]
In this talk, Carlos Holguera and Sven Schleier, the OWASP Mobile Application Security (MAS) Project Leaders, will take a hands-on look at some of the latest OWASP MAS developments, in particular the new MASWE (Mobile Application Security Weakness Enumeration). This talk will introduce the concepts of weaknesses, atomic tests and demos that are the basis of the upcoming MASTG v2. Attendees will gain practical knowledge through detailed examples that show the journey from definition to implementation using both static and dynamic analysis techniques available in MASTG. In addition, discover the newly developed MAS test apps designed to streamline research and improve the development of robust MAS tests. Dont miss this opportunity to improve your mobile app security skills and make your apps hack-proof. Whether youre looking to bolster your defenses or learn how to uncover vulnerabilities, this session will provide you with the cutting-edge resources you need to stay ahead in mobile security!
-
Managed by the OWASP® Foundation
https://owasp.org/ OWASP Mobile Application Security (MAS) - Sven Schleier, Carlos Holguera](https://i.ytimg.com/vi/Vgj5VqQaRho/mqdefault.jpg)



