(Bonus Episode) The New Reality of AI Attacks: Why Evidence Matters
Last year Snehal Antani keynoted Black Hat alongside the NSA to share a number that should worry every security leader: full domain compromise on a defense industrial base supplier in 77 seconds. Antani is the co-founder and CEO of Horizon3.ai, and he built the autonomous AI hacker, NodeZero, that ran that test.
In this conversation we get into why "compliant" and "secure" stopped being the same thing, why AI attackers are actually more gullible than most people assume, and what changes when a security team can pentest its own environment continuously instead of once a year.
What you'll learn: why security has become an evidence problem, not a visibility problem, and what that means for GRC teams who spend their careers documenting controls. How a 9-year-old used Horizon3's product to hack a bank in 4 minutes and 12 seconds with no prior experience. Why AI attackers are more gullible than human ones, and how honeypots and honey tokens exploit that gullibility. What NodeZero Tripwires are, and how they turn a completed pentest into an early warning system for real attackers. Why NodeZero's 325,000-plus production-safe pentests make Horizon3 a data company first and a pentesting company second. What made web applications the hardest domain for autonomous pentesting to crack, and why that's changing fast. How blue team agents now auto-fix problems like a misconfigured EDR in real time, during the pentest itself. Why "prove you're resilient" is replacing "hope you are" as the new standard for CISOs.
This video was produced in partnership with Horizon3.ai. All opinions are Snehal's own. Learn more about Horizon3's autonomous pentesting platform:
https://horizon3.ai/simplycyber
If this was useful, subscribe to Simply Cyber for more conversations like this one.
Chapters:
0:00 Cold Open, "If You Can't Stop Us in 76 Seconds, It's Game Over"
1:04 Why Security Has Become an Evidence Problem, Not a Visibility Problem
2:36 How AI Compressed Attacker Economics From Weeks to Minutes
3:39 Why AI Attackers Are Gullible, and How Honeypots Exploit It
4:27 What Evidence Actually Looks Like for a Security Team on an Ordinary Tuesday
5:55 Where AI Makes Defenders Faster vs Where It Makes Them Complacent
7:26 Inside NodeZero, How an Autonomous AI Pentest Actually Works
9:44 What 325,000 Pentests Taught Horizon3 That Annual Testing Never Could
11:26 NodeZero Tripwires, Turning a Completed Pentest Into a Threat Hunt
12:49 Why Web Applications Are the Hardest Target for Autonomous Pentesting
15:00 How to Prove an Autonomous AI Pentest Is Safe to Run in Production
18:27 Inside the $250M Raise and the Road to a $2 Billion Valuation
20:50 What It Takes to Earn Trust From the NSA and CISA
23:00 Why "Prove You're Resilient" Is Replacing "Hope You Are"
=========================
Simply Cyber empowers people who want a rewarding cybersecurity career 💪
=========================
=========================
All the ways to connect with Simply Cyber
https://SimplyCyber.io/Socials
=========================
In this conversation we get into why "compliant" and "secure" stopped being the same thing, why AI attackers are actually more gullible than most people assume, and what changes when a security team can pentest its own environment continuously instead of once a year.
What you'll learn: why security has become an evidence problem, not a visibility problem, and what that means for GRC teams who spend their careers documenting controls. How a 9-year-old used Horizon3's product to hack a bank in 4 minutes and 12 seconds with no prior experience. Why AI attackers are more gullible than human ones, and how honeypots and honey tokens exploit that gullibility. What NodeZero Tripwires are, and how they turn a completed pentest into an early warning system for real attackers. Why NodeZero's 325,000-plus production-safe pentests make Horizon3 a data company first and a pentesting company second. What made web applications the hardest domain for autonomous pentesting to crack, and why that's changing fast. How blue team agents now auto-fix problems like a misconfigured EDR in real time, during the pentest itself. Why "prove you're resilient" is replacing "hope you are" as the new standard for CISOs.
This video was produced in partnership with Horizon3.ai. All opinions are Snehal's own. Learn more about Horizon3's autonomous pentesting platform:
https://horizon3.ai/simplycyber
If this was useful, subscribe to Simply Cyber for more conversations like this one.
Chapters:
0:00 Cold Open, "If You Can't Stop Us in 76 Seconds, It's Game Over"
1:04 Why Security Has Become an Evidence Problem, Not a Visibility Problem
2:36 How AI Compressed Attacker Economics From Weeks to Minutes
3:39 Why AI Attackers Are Gullible, and How Honeypots Exploit It
4:27 What Evidence Actually Looks Like for a Security Team on an Ordinary Tuesday
5:55 Where AI Makes Defenders Faster vs Where It Makes Them Complacent
7:26 Inside NodeZero, How an Autonomous AI Pentest Actually Works
9:44 What 325,000 Pentests Taught Horizon3 That Annual Testing Never Could
11:26 NodeZero Tripwires, Turning a Completed Pentest Into a Threat Hunt
12:49 Why Web Applications Are the Hardest Target for Autonomous Pentesting
15:00 How to Prove an Autonomous AI Pentest Is Safe to Run in Production
18:27 Inside the $250M Raise and the Road to a $2 Billion Valuation
20:50 What It Takes to Earn Trust From the NSA and CISA
23:00 Why "Prove You're Resilient" Is Replacing "Hope You Are"
=========================
Simply Cyber empowers people who want a rewarding cybersecurity career 💪
=========================
=========================
All the ways to connect with Simply Cyber
https://SimplyCyber.io/Socials
=========================
