Skip to main content
Aviyam Ivgi

Aviyam Ivgi

Founder

Stealth

About

Aviyam Ivgi is a Founder at a stealth-stage startup, bringing a career's worth of deep-stack expertise to his new venture. He most recently served as an Engineering Manager at Aryon Security, following a track record of building industry-leading cloud security products at Wiz and Aqua Security. His technical foundation in complex system architecture and private cloud platforms was forged during his tenure as a Development Team Lead in an elite IDF cyber unit, where he specialized in high-scale, mission-critical infrastructure.

Sessions

The CoreBreak Attack: Turning AI Agents into Credentials Exfiltration Vectors

What you will learn:

1. A security-focused deep dive into managed AI agent infrastructure, how AWS Bedrock AgentCore works under the hood, the security assumptions baked into it, and exactly where its trust boundaries collapse. 2. Full code and a live walkthrough of discovering credential exfiltration vulnerabilities in both the Browser and Code Interpreter tools, then chaining them into CoreBreak, a realistic, fully automated attack that goes from a single webpage visit to complete credential compromise without detection. 3. A concrete defensive playbook for the agent era: why traditional I/O guardrails fail when your tools are the attack surface, and how to architect around it using zero-trust boundaries, layered isolation, and least-privilege enforcement, with actionable steps you can apply today. 4. Reconnaissance methodology showing how to identify exposed AgentCore deployments in the wild, demonstrating that this isn't theoretical, organizations are already running vulnerable agent infrastructure in production. 5. A new security mental model: in the agent world, code execution and browser access aren't vulnerabilities to patch - they're features. The entire security paradigm needs to shift from "prevent RCE" to "assume RCE and contain the blast radius."