When AI Coding Agents Become an Attack Surface: Lessons from Claude Code RCE Research

Tuesday, August 11, 2026
11:00 AM - 11:30 AM
AI Risk Summit Tech Track (Salon II)

About This Session

AI coding agents like Claude Code, Cursor, and Gemini CLI are moving from autocomplete into autonomous development workflows, where they can read code, run commands, use tools, and interact with cloud environments. In this session, Mahesh Babu (Kodem) will share lessons from newly disclosed Claude Code remote code execution research presented at RSAC 2026, building on earlier work around denial-of-service and permission escape. We will explain how these risks show up in real developer environments, why agent autonomy changes traditional application security assumptions, and what practical controls security teams should consider as these tools enter the enterprise.

Speaker

Mahesh Babu

Mahesh Babu

Chief Strategy Officer - Kodem Security

Mahesh Babu is a former VP of Information Security, now a company builder, who leads growth at Kodem, a venture‑backed application security startup. At HSBC he built and scaled global application‑security and identity‑access‑management platforms that safeguard billions of transactions. His career began at Purdue University’s Information Assurance & Security Research Center, where he researched secure software engineering. Mahesh blends academic rigor with enterprise and startup execution to help organizations stay ahead of modern threats.