

AI Security Night Lisbon - AI Week - Kick Off Edition
Hey everyone,
we're launching a new community chapter in Lisbon - and there's no better moment than Lisbon AI Week. Join us for an evening of talks on the security side of building with AI, plus a chance to meet the local community kicking things off.
Talk 1 — Understanding Prompt Injection Techniques, Challenges, and Advanced Escalation Speaker: Brian Vermeer (Staff Developer Advocate, Snyk)
As developers, we're embracing AI and large language models (LLMs) in our applications more than ever. However, there's an increasing concern we need to be aware of: prompt injection. This sneaky attack can undermine our AI systems by manipulating the input to produce unintended outputs. In this session, we'll break down what prompt injection really means and look at some common techniques attackers use, like instruction overrides and hidden prompts. But we won't stop there; we'll also explore advanced challenges, including escalation techniques that can exacerbate the risks. Most importantly, we won't just identify the problem — we'll dive into practical steps you can take to mitigate these risks and keep your AI interactions secure.
Brian is a Staff Developer Advocate for Snyk, Java Champion, and Software Engineer with over a decade of hands-on experience creating and maintaining software. He is passionate about Java, (Pure) Functional Programming and Cybersecurity. Brian is a JUG leader for the Virtual JUG and the NLJUG, co-leads the DevSecCon community, and is a community manager for Foojay. He is a regular international speaker at conferences like JavaOne, Devnexus, Devoxx, Jfokus, JavaZone and more. He is also a military reserve for the Royal Netherlands Air Force and a Taekwondo Master / Teacher.
Talk 2 — AAuth: The Electrification of Authorization
Speaker: Dick Hardt
OAuth is the internal combustion engine of authorization — excellent, and being optimized past its ceiling. Agents changed the fuel and the driver. AAuth deletes the fuel: no API key, no bearer token, no client registration, no redirect. And it retires the driver: instead of a consent screen for every turn, you give an agent a mission and a budget.
Dick Hardt is Founder and CEO of Hellō, a cooperative identity platform. He led the design of OAuth 2.0 and JSON Web Token, standards used by billions of people every day. He is now the author of AAuth, which does for agents what OAuth did for apps: gives agents access to resources without giving them credentials. Dick co-chairs the OpenID Foundation's IPSIE working group and co-authors OAuth 2.1, and previously founded ActiveState and Sxip Identity and led identity initiatives at Microsoft and Amazon. He lives in Lisbon with his wife and their dog.
Expect real talk about AI security threats, time to connect with Lisbon's AI and security community, and a proper kickoff for what we hope becomes a regular local chapter.
Part of Lisbon AI Week.