Cloud Native Days Austria

Sessions of 2026

Agentic AI Under Attack: Live Demos of Exploits Through Autonomy and Trust

Nico Meisenzahl

AI agents are making decisions, calling tools, and trusting data, all without human review. But with autonomy comes a new and largely misunderstood attack surface. In this demo‑driven talk, we’ll show how agentic AI systems can be hijacked without code exploits. Using nothing but text, tools, and trust. Through live demos, we explore three real‑world classes of vulnerabilities from the OWASP Top 10 for AI: - Indirect Prompt Injection, where untrusted content silently manipulates agent decisions - Tool / MCP Poisoning, where malicious tool descriptions hijack agent behavior and leak full context - RAG Poisoning, where internal knowledge causes persistent data exfiltration No slides. No theory. Just Demo, Demo, Demo! With practical DevSecOps lessons on why classic security controls fall short once AI agents start acting on your behalf.

AI Made Us Faster at Solving the Wrong Problems

Marcelo Ancelmo

You are in a meeting. Someone checks their Generative AI of choice mid-discussion and announces: "The AI says we just need to do X." Everyone nods and moves on. Congratulations, you have just solved the wrong problem. Nothing is broken. Everything is faster, and yet something is wrong. Generative AI has amplified our worst problem-solving habit: jumping to solutions before understanding the problem. It is System 1 thinking on steroids, magnified by the Dunning-Kruger effect: confident, fast, and increasingly wrong. We are racing toward solutions faster than ever, but they are brittle, disconnected, and often miss the point entirely. This talk will teach you that one question changes everything: "What problem are we actually solving?" It sounds simple. It is not. You will learn how to recognize when speed is hiding misunderstanding, how to distinguish symptoms from root causes, map consequences before committing, and slow down long enough to understand what you are actually solving for. This is not just theory; it is a practice you can apply in your next team meeting. The best AI prompts, the smartest automation, and the fastest deployments are worthless if we are solving the wrong problem. It is time to stop optimizing for speed and start optimizing for understanding.

From Automation to Context-Aware Delegation - How to become the 5%

Sebastian Kister

According to Gartner, 95% of enterprise AI initiatives fail - not because of the technology, but because organizations lack the cultural, operational and contextual foundation to make AI work in production. This session shows what it takes to be part of the 5% that succeed - real, deployed, hands-on. No buzz words, no myths, no false promises. We’ll explore the shift from scripted automation to context-aware, agentic delegation, where systems understand environments, dependencies, and intent. By embedding context into neural networks and context graphs, we move from maintaining scripts to delegating outcomes - enabling deterministic, auditable, and resilient automation across any infrastructure, including air-gapped systems. Using real examples from platform engineering and enterprise operations, we’ll demonstrate how context-aware automation might reshape open source adaption and the entire cloud-native ecosystem. Don’t be fooled: success takes more than just tech - it requires a mindset-shift, governance, and a culture ready to rethink everything that they've learned. Forget your current "now" and take something home that helps you with your decision making - especially if you're desperate about bringing your automation-KPI up.

You Call That an AI Agent?

Krisztián Papp

“AI agent” has become an overloaded term, applied to everything from glorified cron jobs to brittle prompt chains. In this talk, we challenge the hype and ask a simple question: what actually qualifies as an AI agent? We’ll break down common misconceptions, examine real-world implementations, and contrast agent-like systems with workflows, automations, and orchestration pipelines that are often mislabeled. Through concrete examples, we’ll explore autonomy, planning, memory, feedback loops, and failure modes, and show where most systems quietly fall short. The goal is not to define yet another framework, but to give practitioners a clear mental model to reason about agents, avoid architectural self-deception, and build systems that deserve the name.

Zoom in and you shall find: Adaptive Kubernetes SOC that stays sovereign and reduces data volume

Constanze Roedig

The linux kernel through eBPF offers to unify the disparate fields security and observability through shared data structures. We show how a K8s Security Operations Center, organically composed of established eBPF projects can see signals that the individuals cannot. We explain how we achieve both a comprehensive baseline and use independent signals to dial up/down coverage as suspicious indicators surface. The mutual independence of signals from across processes, file system, and network activity achieves a high signal-to-noise, enabling manageable data volumes and facilitating selective forensic storage. You will see two shorts demos: (A) of a root-kit which is hard to detect for sys-call based security tools in their default configurations, however almost trivial to detect with our adaptive setup. (B) of an agentic AI attack that mimicks a cobalt-strike C2 server You ll also learn how our SOC architecture is node-local and can be airgapped. This means no data leaves the cluster and you remain sovereign and in control of your data.

Constanze Roedig

Constanze Roedig

Independent OpenSource Maintainer and Cybersecurity Researcher

Bio

Constanze is an astrophysicist turned entrepreneur: she spent over 15 years designing and implementing resilient complex systems for finance and government. CS lecturer and key researcher. Created the K8s Stormcenter for Open Threat Intelligence. Her research is on improving security using modern and emerging technologies such as eBPF, WebAssembly and AI. Her vision is to create practical and achievable security implementations usable in defendable systems for a resilient society.

Krisztián Papp

Krisztián Papp

Principal Software Engineer @ Diligent

Bio

Krisztián is a principal engineer at Diligent with over a decade of hands-on experience in creating and maintaining software. Currently he is leading the movement of a diverse set of products towards the cloud. He is the founder of the Letscode.hu community, creating a supportive environment where individuals can thrive, share their knowledge, and collectively contribute to the advancement of technology.

Marcelo Ancelmo

Marcelo Ancelmo

Lifelong learner. Tech Leader, Speaker, Trainer. Troubleshooter and Troublemaker - Head of Solution Architecture @ KPMG Switzerland

Bio

Marcelo S. Ancelmo has 23 years (and counting) of IT experience and has done a bit (or would it be a byte) of everything. A good old-fashioned troublemaker, he started his professional career as a Java programmer, fell in love with architecture (a passion he still pursues today), dove into middleware (with no regrets), built high-performing teams, and explored infrastructure and operations. Deeply engaged in the tech community, Marcelo joins Meetups wherever he goes, teaming up with JUGs, helping organize events when time allows, and contributing to working groups and committees. Along the way, he’s delivered consulting, training, mentorship, and conference talks. Today, he's Head of Solution Architecture at KPMG Switzerland, helping the company drive its digital transformation toward sustainable business agility, fueled by Architecture and DevOps, learning everything possible and enjoying the bumps along the ride.

Nico Meisenzahl

Nico Meisenzahl

Cloud Solution Architect @ white duck

Bio

Nico Meisenzahl is the COO at white duck. As a Cloud Solution Architect and Microsoft MVP, he is passionate about topics such as AI, cloud-native technologies, and internal developer platforms. In addition, Nico is a sought-after speaker at conferences, user group events, and meetups.

Sebastian Kister

Sebastian Kister

CNCF, Transformation Evangelist & Audi AG, Product Team Lead for Container Competence Center, Platforms & Operations

Bio

Sebastian Kister is an influential figure in enterprise transformation and a top consultant for C-Level executives. Currently running for the Governance Board at CNCF, he combines hands-on leadership with visionary insights, spearheading a Competence Center at AUDI focused on IT infrastructure. A dynamic startup professional, Sebastian has played a pivotal role in guiding products from conception to market leadership through innovative, cutting-edge technologies. He is committed to challenging the status quo, fostering a culture of innovation, and driving continuous progress within organizations. Sebastian emphasizes the distinction between mere reorganization and true transformation. He advocates for a „people-first“ approach, believing that when organizations prioritize their people, they empower them to solve complex problems. Conversely, a „process-first“ mindset often leads to mere compliance rather than genuine problem-solving.