When AI Coding Agents Become an Attack Surface: Lessons from Claude Code RCE Research
About This Session
AI coding agents like Claude Code, Cursor, and Gemini CLI are moving from autocomplete into autonomous development workflows, where they can read code, run commands, use tools, and interact with cloud environments. In this session, Mahesh Babu (Kodem) will share lessons from newly disclosed Claude Code remote code execution research presented at RSAC 2026, building on earlier work around denial-of-service and permission escape. We will explain how these risks show up in real developer environments, why agent autonomy changes traditional application security assumptions, and what practical controls security teams should consider as these tools enter the enterprise.
Speaker
Mahesh Babu
Chief Strategy Officer - Kodem Security
Mahesh Babu is a former VP of Information Security, now a company builder, who leads growth at Kodem, a venture‑backed application security startup. At HSBC he built and scaled global application‑security and identity‑access‑management platforms that safeguard billions of transactions. His career began at Purdue University’s Information Assurance & Security Research Center, where he researched secure software engineering. Mahesh blends academic rigor with enterprise and startup execution to help organizations stay ahead of modern threats.