Zlatko Unger has 35 minutes to stop AI from obeying poisoned emails (Live Tabletop Exercise)

Sep 2, 2026

You're the CISO at Larkfield Health, a 9,500-person health tech company. A little after 9:00 AM on a Tuesday, your Head of Detection forwards you a message from a security researcher you've never heard of. They say they've found a way to make Wingman—the AI assistant you rolled out company-wide six months ago—hand internal data to an outsider, and that a collection server that isn't theirs is already receiving it. Nothing in your own stack has made a sound.

In this episode of The Tabletop, Zlatko Unger takes the hot seat and works the problem in real time. Zlatko came up through security and compliance, with roles at First Data, Jiff (later acquired by Castlight Health), and Alation, and has spent years helping healthcare organizations navigate HIPAA compliance. He's now a CISO Expert at Wiz.

In this episode, host Khush Kashyap drops Zlatko into the following scenario: he's the CISO at Larkfield Health when a stranger's tip reveals that Wingman has been quietly exfiltrating data. The mechanism is a zero-click prompt injection—an ordinary-looking email, left unread for days, written not for a human but for the AI. When a finance employee asks Wingman a routine question, the assistant's own search finds the poisoned email, reads it as commands, and ships out figures, names, and file contents encoded into the URLs of images that load automatically. Because the traffic went to the vendor's own allow-listed domain, nothing flagged. Then it gets worse: the finance email wasn't the only one. Over nine days, six poisoned emails hit six different inboxes—payroll, employee records, privileged legal files—and because Wingman shipped what it read rather than whole files, there's no defensible list of what left and no way to rule out a seventh.

Zlatko works through activating the incident response plan when the only evidence is a stranger's email, whether to kill a tool the whole company depends on or keep it running behind new guardrails, who actually owns scoping what an AI can reach, and the HIPAA fork in the road when legal wants to write “low probability of compromise” and compliance says no one can sign it—all against a 60-day notification clock and a researcher about to demo the technique on a conference stage in 10 days. At the end, he renders his verdict: real incident or constructed fiction?

About
The Tabletop is by Vanta, the leading Agentic Trust Platform helping security leaders manage compliance, reduce risk, and prove their programs work—before the incident, not after. Learn more about Vanta: https://www.vanta.com

Quotes
“This might be a colossal event, or it might be a nothing burger. So the first thing to do is treat it as if it's a colossal event.”

“The educational piece is: don't give overarching permissions to an AI agent that sits outside of the DMZ.”

“One of the assumptions is that access permissions have been solved.”
“This is one of the things where the CISO needs to fall on the sword. Even if a junior analyst wrote it up, it still needs to be signed off, given the impact.”

“We're not in the clear, because somebody's gonna get creative—that prompt injection might come from a different threat vector than email.”

Time Stamps
[00:00] Welcome to The Tabletop: Meet Zlatko Unger, CISO Expert at Wiz
[00:54] The Rules: CISO at Larkfield Health, a 9,500-Person Health Tech Company
[01:23] The Scenario: A Stranger's Tip About Your Company-Wide AI Assistant
[02:06] First Gut Check: Colossal Event or Nothing Burger?
[04:11] Inject One: The Domain Gets Hits and a Finance Email That Wasn't What It Looked Like
[04:59] Zero-Click Exfiltration: How Wingman Shipped Data Out Through Images
[07:33] Would Security Awareness Training Have Stopped This?
[09:19] An Outsider Found It First: What That Tells You
[10:27] The Forced Choice: Kill Wingman Company-Wide or Keep It Running?
[11:48] Guardrails: Scoping Permissions While the Investigation Runs
[13:34] Inject Two: Six Inboxes and No Defensible List of What Left
[16:23] Who Owns Scoping What the AI Can Reach?
[18:45] Someone Chose Those Six: Who Are You Dealing With?
[20:06] The Twist: The Researcher Is Taking It to a Conference Stage
[21:51] Inject Three - Values Tradeoff: Patient Data, HIPAA, and "Low Probability"
[25:15] Whose Name Goes on the Risk Assessment?
[26:46] Three Weeks Later: The Technique Goes Public
[29:02] The Moment of Truth: Real Incident or Fiction?
[29:31] The Reveal: EchoLeak and the First Zero-Click Prompt Injection
[30:37] Off the Table: The AI Assumption Security Teams Should Drop
[32:20] Off the Table: The One Question to Ask Before Approving an AI Tool