For developers and enterprise IT teams, the useful question is not simply whether an AI model follows its safety instructions. It is whether the software surrounding that model has a defensible security boundary.
AI security before the first prompt
According to Kaspersky, Satoki Tsuji of Ikotas Labs will demonstrate zero-click remote-code-execution chains that bypass AI-coding guardrails before an LLM is invoked. Separately, Zhiniang Peng will present an autonomous, LLM-driven system that reportedly discovered and verified more than 100 zero-day weaknesses across Android distributions used by multiple smartphone manufacturers.
Those are significant claims, but they need careful interpretation. Kaspersky’s announcement does not identify affected coding-agent products, versions, CVEs or mitigations. Nor does it publish the Android vulnerability inventory or establish which weaknesses remain unpatched. The agenda is a preview, not a deployment-specific security advisory.
The distinction matters. A successful demonstration could reveal a serious weakness in particular implementations without proving that every AI assistant is vulnerable. Likewise, a large discovery count alone cannot establish exploitability, severity or the system’s advantage over other research methods.
The enterprise implication is therefore conditional: if automated discovery becomes faster and more reliable, vulnerability validation and remediation must keep pace. Finding more bugs is useful; turning that output into prioritized, reproducible fixes is the harder operational job.
A practical comparison: guardrails have boundaries
GitHub’s own documentation provides a concrete example of why security teams should examine the execution environment, rather than rely on a general promise of “AI safety.”
For Copilot cloud agent, GitHub documents a default network firewall intended to reduce data-exfiltration risks. However, that firewall applies to processes launched through the agent’s Bash tool inside the GitHub Actions appliance. It does not directly cover Model Context Protocol server processes or configured setup-step processes, and GitHub warns that sophisticated attacks may bypass it.
This is not evidence that Copilot is affected by Tsuji’s forthcoming research. It is an independently documented example of a control with explicit boundaries.
For administrators reviewing an agent deployment, that suggests three useful questions:
- Which processes actually fall under the network restrictions?
- What can setup steps and connected tools access outside those restrictions?
- Who can expand the permitted destinations?
GitHub documents organization-level controls for the firewall, recommended allowlist and repository-added rules under Settings → Copilot → Internet access. Its documentation also explains that blocked agent requests generate a pull-request warning identifying the address and command involved. These settings and warnings offer concrete review points, not a guarantee of complete isolation.
The analytical takeaway is straightforward: check what a control enforces, where it operates and what it leaves outside. A guardrail is not a force field.
Firmware, games and connected devices remain in scope
The announced programme also includes:
- A UEFI bootkit campaign targeting diplomatic entities, plus new Lazarus research.
- Attacks on Android-based automotive head units.
- PlayStation 5 security bypasses enabling Linux.
- Counter-Strike and Dota 2 remote-code execution.
- The Kimwolf Android TV botnet, advertised as 31.4 Tbps.
- Rocket, an iOS bypass associated with the Coruna exploit kit.
These subjects should not be flattened into one sweeping warning. Running Linux on a console through a research bypass is different from a reported criminal intrusion. An automotive head-unit campaign does not, by itself, establish compromise of safety-critical vehicle systems. And the announcement does not explain the measurement behind Kimwolf’s bandwidth figure.
For Windows and PC readers, the gaming research deserves attention, but the preview supplies no affected builds or remediation details. It is not sufficient grounds to declare a current vulnerability in every installation of either game.
Competition—and the questions still unanswered
The SAS CTF finals will bring together 13 teams: eight professional qualifiers and five regional Kaspersky{CTF} winners. They will compete in an Attack-Defense format for an $18,000 prize pool.
The summit’s strongest enterprise angle remains the intersection of autonomous development tools and vulnerability research. What should readers look for when the sessions take place? Affected versions, reproducible findings, disclosure timelines, patch status and clearly defined security boundaries.
Until those details emerge, the sensible response is neither panic nor dismissal. Treat the agenda as a research watchlist—and use the opportunity to examine the permissions and execution environments of the AI tools already doing work inside your organization.
References
- Kaspersky SAS 2026 Puts AI Security and Automated Vulnerability Research in Focus konsulteer.com · 2026-10-02T12:00:00+00:00
- Rebel with a cyber cause: Kaspersky unveils SAS 2026 will focus on cyberespionage, vulnerability hunting, threats to gamers, mobile and AI kaspersky.com
- Customizing or disabling the firewall for GitHub Copilot - GitHub Docs docs.github.com