transcribe

Live from DEF CON at RedTail: Red Teaming After AI

Bishop Fox · 46m · transcribed Aug 2026
More from Bishop Fox Business
𝕏 Share ▶ YouTube 📥 PDF 🤖 .md

Section Insights

# 0:00

Introduction to Initial Access

What is the theme of this year's discussion at Black Hat and Defcon?

The theme is to 'block out the noise' surrounding AI and focus on what is truly important for the future of security.

  • AI discussions are prevalent but often mixed with hype.
  • The event features a diverse panel of experts.
  • The focus is on meaningful insights rather than sensationalism.
# 9:16

Identifying Industry Noise

What are the common sources of noise in the cybersecurity industry?

The noise often comes from exaggerated reports on vulnerabilities and AI hype, especially around events like Defcon.

  • AI consistently dominates headlines, regardless of its actual impact.
  • Many vulnerabilities are overstated, leading to confusion in the industry.
  • It's important to discern between genuine threats and hype.
# 18:33

The Urgency of Security Patching

How has the urgency of patching vulnerabilities changed in the current threat landscape?

The time to patch vulnerabilities is critical, and organizations need to prioritize security updates more seriously due to heightened threats.

  • The gap between vulnerability disclosure and exploitation is narrowing.
  • Organizations often delay patches due to bureaucratic processes.
  • AI tools can help expedite the patching process.
# 27:50

Understanding Red Teaming

What is the perception of red teaming in the cybersecurity field?

Red teaming is often misunderstood; it requires experience and is not as accessible as some may think, despite the growing interest.

  • Red teaming encompasses various disciplines within offensive security.
  • There is a need for clearer communication about the skills required for red teaming.
  • Newcomers to the field can find pathways into offensive security roles.
# 37:06

The Impact of AI on Cybercrime

How is AI influencing the landscape of cybercrime?

Cybercriminals are leveraging AI similarly to security professionals, using it to enhance their workflows and automate tasks.

  • AI is a double-edged sword, benefiting both security and criminal activities.
  • The ease of using AI tools can lower barriers for new criminals.
  • Future discussions will focus on the effectiveness of AI implementations in security.

Transcript

0:15 If you've been at Black Hat and Defcon this year, you have heard a lot of opinions. You've heard a lot of AI opinions. AI this, AI that. It's everywhere, right? And some of that is real, some of that is hype. We call that noise. So our theme this year has been block out the noise. And to kind of wrap that up, we decided to do a live version of initial access with we have this is the most smart people I've seen in a room together in a very long time. so it's it's a great opportunity to kind of get to what's actually important and what the future may hold for security. So you'll see some familiar faces. We got some new ones today, too.

0:59 I'm very excited to get started on this. first, let me let me introduce a couple of these folks. We've got some longtime friends of the show. John Uunt, senior security engineer, exploit development. We have Richard Brown, senior managing operator. And then new to the program, we have Billy Giles, managing senior consultant here with Bishop Fox as well. and joining us from OpenAI. He is a member of the technical staff. he's a red team expert at OpenAI. So, a lot of interesting different perspectives and I'm excited to get into this. We only have two microphones, so it's going to be a second between questions where we pass things along. Be patient. I'm Sean McMillan, community manager here at Bishop Fox, and this is Initial Access. So, first question I guess is what has everyone been attending? What have you seen so far? Did It sounds like none of you really did Black Hat. That was just me in a booth for 3 days.

2:02 It was really fun though. We we talked to a lot of people. We'll be releasing clips. If you're watching this on YouTube or listening to the podcast version, you'll be able to see a lot of our clips on YouTube and LinkedIn, etc. of the people we talked to there. got some good perspectives, but I'd like to hear from you guys. Defcon has just started. This was the first day of Defcon. I think most of you were there in some format. how's how's the con been so far?

2:29 >> Wo. like this is so this is actually my first year since the move over to the convention center. last year the last year I was here was 2023. >> so that aspect is totally new to me as far as like having it all under one roof. and not having to go between, you know, different buildings and whatnot for everything. so Rich and I were actually talking about that on the way over. there there's some pros and cons to that, I think, still. I'm I I definitely like while I don't I don't miss the walking back and forth between, you know, the different hotels and whatnot. but some of the villages that are out on like the main floor, I felt like it's a lot less intimate, >> as far as like getting to getting into the activities, getting to talk to people.

3:16 >> And that's one of the big things at Defcon, right, is that it's that that differentiates it from a black hat or RSA or some other big format, right? >> Yeah. Yeah. And and and like it's not all of them, right? There they do still have villages up in private rooms up on like the second floor. but there is to me there's like a notable disparity between say like the I think it was like the payment processing village was one of them that like I walked in it was immediately like you could you could just like immediately start learning something as soon as you stepped in there's an expert in there talking yeah >> you know about the about the process and whatnot. Not to say that there's not experts at at any of the other you know villages. It just it was just something I picked up on immediately was like, "Oh, I'm I'm already in the conversation."

4:03 and I think that that also just could be like just not as many people up in like the second and third floor as there is like out on the main floor, right? >> Yeah. >> And one thing to note too, this year we did see them have headphones in some of the other booths. So, it's nice that in the loud convention area, they were able to have a more intimate setting, but it still was. Now, I see the talker up there and I'm four rows back without headphones and I can't hear what he's saying.

4:25 >> Oh, yeah. >> Because it's it's so loud in there. But, >> yeah, it was good. All it was good for the most part. Yeah. >> Right. Right. Right. Yeah. Yeah. I'm curious, Billy, from like from you like being like active in like the the Red Team Village area, like how how that experience is as far as like >> Yeah, I should have said that. Billy is like Mr. for Red Team Village on the board. You're you're the master of coin as so to speak, the treasure.

4:49 >> I'm fortunate enough that they let me hang out. >> Yeah. Yeah. Very very involved in Defcon. So yeah, what's your experience been so far? >> Yeah, as they say, it takes a village, right? So yeah, definitely definitely credit. >> Sometimes it takes a lot of villages. >> Credit to the 30 or so people that do this year round to prepare and then the army of volunteers that we get every year. Just amazing. So you know, we show up and the the volunteers show up and I do nothing. It's amazing. I love it. But to get back to what you're talking about, so we were on the floor last year >> and it was absolutely awful because there were some vendors down there that had microphones.

5:20 >> So it was very loud >> and then they told all the villages that we couldn't use microphones last year. >> So we're like trying to yell and use megaphones and we did the keynote panel. So there's, you know, a couple hundred people standing around and we're trying to use a megaphone and pass it back and forth. >> Right. >> So the u the headsets are a fantastic upgrade. Like we had >> we had probably 200 people in the keynote this morning as well. Everyone with a headset on, you know, they could all hear us directly from the microphone. So, >> it was it was fantastic. Yeah.

5:48 >> Yeah. Yeah. Something we were Yeah. Thanks. We something we we noted was I I I can't recall exactly which v village it was off the top of my head, but there there was a village that they didn't have the headphones. They were on the main floor, but there you know was it IoT or >> heard the game hacking? >> Early game hacking. Yeah. Yeah. And so so there was somebody doing a talk there and they just like like that, right? They didn't even have a a megaphone. They just had to like kind of like shout over the crowd. And so we were starting to talk about like you know how could we or how could anybody like fix something like this. And I'm wondering if everybody has to have the hacker tracker app now to like do any like merch sales.

6:23 >> I'm wondering if they can incorporate something like that into the app itself to where you know, like the different speakers, they just, you know, they they they basically talk into a microphone and then all you have to do is just like get on the app and and dial into something else or even like you can just not even be in the audience. You could be out in the hall or whatever and still listening in like a like a podcast.

6:43 >> Yeah. Right. >> So, interesting. Interesting. Matthew, have you had a chance to hit the floor at all yet? >> Yeah. Yeah, I mean my my main experience with Defcon has definitely sort of get out of it what you put into it. And so like some of the best times I've ever had at the conference have always been like I'm going to participate and like do this this event or you know help either help out or it's like do you know what they have planned and also just one of the nice things is it tends to be like my friends from all over the world usually end up at Defcon. So the very least you're going to meet people that you're like I haven't seen this person in forever. I'm super happy to catch up like >> you know what have you been doing over the past year? Is there some you know especially with all the all the changes that have happened so I've always enjoyed that.

7:19 >> Yeah. Yeah. Have you done anything as far as you said you mentioned like you know like the participation stuff. Is there anything like you've you've you've like gone around to to like today and like participated in? >> Not yet for this time although well my my wife is actually doing quite a few quite a bit of talking so helping >> assisting more with that but in prior years it's been like you know playing in Hackfortress and stuff like that which has always been enjoyable and stuff that nature. So >> I I was trying to explain Hackfortress to to Richard actually. So like in in the I've done for back when they were around. and that was where I did like a lot of Hackfortress stuff. And so I was trying to show him like cuz they didn't have it like actively going when we were over there. but yeah, trying to explain to him like how this whole thing works. I think that's like like another like one of those like great things that you know Yeah. Like it's like you need to get 10 people together to make a team. But it's such a cool competition as far as like it's so for those that don't know, right?

8:09 Hackfortress is historically was Team Fortress 2. Now they just move a quick three. but the way it works is Yeah, I forget about the mic situation. >> I'm I'm so used to the webcam stuff. >> the the the way it works is you get a team of 10. Six of them are playing the like the first person shooter. Four of them are playing are are doing like capture the flag hacker challenges, right? the the the hacker challenges are like unlocking, you know, buffs and stuff like that for the team that's playing or the side of the team that's playing the first person shooter and then vice versa as they're getting kills, it's getting like hint unlocked and stuff like that for the the hacker team. And there's like there there's all sorts of like jump in challenges like it's at I think at one one point the last time we played it, there was one of our team members had to like get up and do like karaoke to something.

8:58 >> I could do this. I could get black badge. >> See, this is what I could do that. That's what I mean. And that's that's what I mean. That's like one of those like cool challenges that's like there's something for everybody, right? Like you don't have to just come in and just be a hacker. Like you don't have to be a reverse engineer. You don't have to be an AI guy. You can do anything on these teams and like everybody can contribute.

9:16 So yeah, I just wanted to like kudos to the Hackfortress team by the way. Like that's such a cool idea. I'm glad that this game this year. >> That's very cool. >> Yeah. >> so one of the things I mentioned Bishop Fox's theme this year like for we had a booth for the first time. That's very cool. and our our theme was block out the noise. And we talk about it a lot on the podcast. That's kind of like the the seed that started the podcast was like there's so much hype everywhere. And it's it's hard to read the news and know what is what you should actually be worried about, what's going to affect you, even if other people are worried about that kind of stuff. so we've been asking people in the booth. I did a lot of videos this week. what's the noise in the industry? And so I figured instead of doing individual interviews with you, we can just kind of go down the line like what's your take? What what do you see in the headlines or or people in in the industry talking about a lot that just gets a little eye roll?

10:15 >> Oh, I I can start. >> Yeah. Yeah. We need Richard to kick it off. >> I mean, as always, AI is the first headline. Whether it's good or bad, AI is first headline. But for me, from my vulnerability research, it's always these CVEes that drop that people keep promoting and making worse than they actually are until you dig into it. And as a company, you don't know what's going on. And that happens even more around Defcon time. People hype up their talks, hype up everything. And not saying that some of these aren't worthy of that, but a lot of them aren't. And >> and and I'm not saying they aren't.

10:49 >> Yeah. Yeah. No, no. I they're worthy of the talk, but not of all the hype. And I think when you dig into the nitty-gritty, we as hackers love when we hear these crazy exploit chains. We love when you hear these, but the reality of them are not as easy as we all make them out to be. Like we were talking about the CTFs, for instance, they always dulge into they not divulge, but they always end up being cryptographic challenges at the end, right? And that's not my specialty. So, I'm helping out early on. I'm finding flags. I'm hacking web apps. And then it's like, okay, I'm done. Hand it over to you because I have to, right? but but yeah, as a as far as hype train goes, I think it it's always going to be the vulnerabilities that I hear talked about. and I haven't heard as many this year as I used to. Used to be big on the ATM hacks. I used to love those, >> right? I haven't seen one this year, I don't think. So, Matt Burch is giving a talk.

11:38 >> Is he awesome? Yeah. Yeah. >> I love this question because, and I'm going to be very careful in how I answer it. Not because I'm a politician. >> This is why we don't do it live. >> Yeah. >> Not because I'm a politician. just because I want to make sure that I say this clearly and don't give the wrong impression but >> the way that the the two conferences have gone right black hat is is very heavily sales focused >> and when you have sales driving discussion >> often there's fear-mongering and I think that's what we're seeing a lot of like we're seeing this people telling stories like oh this this 14-year-old took AI and hacked all these companies he didn't know anything about hacking not true right when you when you dig into it he knew a lot about hacking and he augmented his skills so I think the the difference in the message that I'm hearing at DevCon is like at least the Red Team Village from this morning that the the keynote panel, all the things that we've done, it's been this is happening.

12:32 >> We need to figure out how to do it responsibly and we need to identify the problems we're going to have along the way and mitigate those now. Right? So, one of the big thing is always like client data. Like that's a big challenge in consulting, something we're all facing. We're trying to work through. My biggest fear honestly and I don't want to fear monger but my biggest fear is the the career pathing that we've traditionally had right so you you get an entry- level pentester and you let them really get some experience that way and then you maybe grow them into a red teamer or maybe they become an IoT hacker or whatever whatever they want to do right >> but when you take away those entry-level jobs and start replacing them with AI >> I fear what do we have that path you know what's the career path for a red teamer yeah >> so I mean I'm trying to look at like go back to the the older way of thinking which is what alternate you know kind of tech jobs have the requisite core knowledge that we could recruit from like you know like network engineers and things like that. So >> so instead of having a bunch of you know experienced pentesters to to choose from when you're trying to grow a red team then you can you know start to look at these other areas and and still continue to have success but definitely a challenge I'm worried about.

13:38 >> Yeah. Yeah. So like firstly like I just want to like like to touch on that last point you said about like you know pulling from like you know more desperate like career fields and stuff like that. Like I think that's a good point because like like in my case like my my my background in the military was initially in like ground radio, right? It has like nothing relatively nothing to do with like cyber. but like there's a ton of people that came out of backgrounds like that that we ended up taking were able to like build into really good like cyber operators.

14:05 So, I think that's a good point to make that like there's a lot of those more for lack of a better way to say like almost hand more hands-on types of career fields that can build into that. the one of the things that I picked up on or that that I want to go back to on the on the main Defcon floor was the there's a the phone freaking challenge. going back to like old school kind of tactics and stuff like that. I thought it was really cool that some that they've brought back like, you know, like what I consider like the original hacking, right?

14:37 >> and like but like to your point like Yeah. Right. Like being able to like like like retach those like old kind of skill sets that have kind of been like a forgotten art, right? >> >> for for the younger viewers, freaking is the old payones just have a dial tone. >> Freaking with a pa. >> Very different from modern. >> Don't Google that. >> Yeah. Yeah. Yeah. You send signal to mimic the phone >> tones and it would make the call for you. That's how pitones used to work.

15:08 >> Yeah. >> A paid phone is a thing to mount. >> Yeah. but no, it's like like to get back to like your original question. I think that I think that's one thing I did pick up on like like walking around the desk on floor was whereas like the like you were saying like like the black hat kind of side of things was a lot more pitching the fear of of AI. I've actually seen a lot of people around the dev company were more so like getting to what it actually is which is a tool right AI is just a tool to get your job done. every time we see these big hacks, right, they the headlines always say, you know, AI hacked whatever, whatever, you open the article and it's the same thing, not AI hacked something. Somebody using AI hacked this in this way, right?

15:56 because that's the reality. And I think it's cool that, you know, the the the hacker community is, you know, they're responding in a in a healthy manner as far as like, yeah, we recognize this is like a big new technology and embracing it in such a way that it's not it it's we're we're not we're not fearful of it. We're we're bending it to our free will, right? >> Yeah. >> Yeah. I guess going back to like the core point about like the noise and everything, I think I think we're all to the point where like, okay, this is like obviously serious. it's not going to go away. Can't imagine going back to before this, right?

16:29 >> I I think one of the things that I will note is at every part of like this whole AI thing, there's always people who are like this is the correct way to do it. And if you look back 6 months ago or a year ago, all of that stuff that they're saying is like completely irrelevant now. So like >> the rapid change I think is it throws a lot of people cuz they're like, "Oh, I'm not not up to date with all this." But all I've got to say is like, you know, >> the environment is changing. Like we see the models just keep getting better.

16:54 there's stuff we had we had to do previously that >> are not even relevant factors anymore. So, >> you know, I I would say I would never say like, oh, you know, it's too late for I haven't got enough into AI. It's definitely a tool. It's something that you can get into and 100%. So, >> yeah. Yeah. I think a lot of the conversation over the last few years obviously AI being as as new as it is as far as the adoption rate the talk at Black Hat and Devcon and just in the industry has been AI AI AI AI and I'm curious how you guys see do you think do you see the conversations around AI actually getting nuanced enough to like matter more now? Oh, I mean like we we talk about the fear-mongering and the AI did it or something, but like that's something we strive for in the podcast.

17:44 I hope we deliver it somewhere, but like do you think that people are starting to look at it as more of not like AI is this magic thing, but it's like here's what we're actually able to do with it. here's what we're, you know, not how how big the model is or something, but like how we actually surround it with our knowledge and our methodologies. >> Yeah. I think so there's obviously like nobody has any doubt about the level of AI marketing and all the stuff that comes out and like oh well you know now all this crazy stuff is true and there's that but there is some level of like listen there are practical things that are changing the time from like there's a CV that came out with a broad description to like I have a working exploit is like >> greatly greatly reduced and it's only going to get closer. So there's a lot of like there there's a lot of noise and stuff out then there's like the practicals of like you know there is real stuff and I think internal security teams everywhere are almost certainly talking about this. They're like what what are we going to do in this world where the time between this bug report gets disclosed and suddenly people are trying to use it against us is like a very real discussion then.

18:46 >> Yeah. >> Yeah. So >> Right. And and and I think honestly like it's and like I know we've talked about this before like the like the time to patch and and like that timeline is is in my opinion has always been like way like grossly too long. you know, we we talked a lot about like companies that would, you know, hold like, you know, change review boards and stuff like that, which like understand that like there's business logic decisions that have to get made and and and, you know, I I totally understand those things, but even before AI, we still had those same problems of we're holding back a patch because somebody's not in the office to sign off on updating this database that, you know, might bring the whole company to a halt for five minutes, >> right? so I do think it's good that like essentially that we we're we're at a heightened threat level, right?

19:38 because it it it's kind of forcing those functions of okay, we do need to take these security patches more seriously. We do need to get ahead of the curve now, >> right? >> I I think there's also like some supreme irony in the fact that it's like, okay, well, you know, we it's like, sure, these bugs are like going to be exploited much quicker, but like, oh, we we have a tool that can help us fix stuff quicker. And so there's like these both sides of the aisle where it's like, okay, we both are going to involve like looking at it with new lens.

20:03 >> Yeah. Yeah. Yeah. Exactly. So >> every CISO I've seen at at Black Hat is they all have gray hair now. >> Except ours does not. No. >> So I was going to add >> I was going to add that there's a there's a really interesting kind of two sides of the same coin thing that's happening, right? Because yes, AI is going to help us solve some security problems. That's inevitable. It already is, right? >> But it's also creating security problems of its own, >> right? Based on implementations and things. So >> without attackers even doing anything usage, >> just implementing a product, it increases the attack surface. Now, you know, as a as a profession, as a career field, we're looking at ways to exploit AI to, you know, to enable attack. So, I did bring up the thing about the training because I do worry about, you know, entry level, but like you're still going to need humans testing AI because again, >> there's implementations that have to happen, right? There's there's builds and and things go wrong and people make mistakes. So, >> headlines we see, the more organizations are getting on board with like, okay, we have to like do it right and not just do it fast.

21:11 >> Yep. And as long as people are there to make mistakes, there going to be ways to exploit them. >> Yeah. Yeah. >> Yeah. And and I will say just I like bringing the podcast out of security sometimes to feel like we do need to remember security is the juiciness of AI right now, but there are other things going on AI. They're curing things. They're solving problems, right? >> So it's easy to see, well AI is bad cuz it's hacking things. AI's bad cuz it's breaking things, right?

21:36 >> Yes. But it's also doing good in other areas, too, right? So we can't just keep lumping it into security research and vulnerabilities when there are other practical uses outside of that. Yes, it's helping us speed up our time from discovery to remediation, but it's also doing other good things in the world besides just fixing vulnerabilities. >> Yeah. Yeah. I think that's that's interesting. Like, you know, you hear some of these like tech giants talking about how AI is could cure cancer, right? could do like all these things. And I think it's it's easy to get caught up in the the fear of it and the cyber security aspect of it and forget like what >> the nuts and bolts of it actually are and and what's possible. And yes, it hasn't cured cancer. But like these these things these victories are happening down the line. They just don't make headlines. Like >> has an attack this yeah >> I haven't tried I literally have not tried that.

22:33 >> Yeah. Yeah, >> you have to solve the riddles three. >> Yeah, but >> I love it. >> I I do think and and not to get too philosophical, I do think it'll be a hacker though that solves these things, right? We see the biohacking village becoming bigger now. We see people getting implants in their hands to do fun things and open doors and like the the more that grows and the more hackers get into the mindset of doctors and that kind of thing, I think we will see this eventuality where hackers become this crazy amalgamation of skill sets that aren't just >> the hackers will inherit the earth.

23:06 >> They rise up. Yeah. >> Yeah. >> I love it. Well, be kind to me when that happens. >> all right. I want to I want to talk for a moment here. Billy, I mentioned you're very heavily involved in Red Team Village. Yeah. On the board. and that is kind of a big deal at Defcon. It's one of the >> better known villages, better attended. >> I'm I'm curious what like how you see Red Team Village as like maybe a model for other villages or like what what is it that sets it apart and and that that draws the kind of crowds that it does?

23:44 >> Yeah. So, interestingly, you know, I I don't get a spend a lot of time in other villages, but when I do, every single time I go, I'm amazed by what they do. >> Yeah. >> Right. So, it's easy to get caught up in Red Team Village, but I think like all of the villages at Defcon bring something unique, and they're all fantastic. So, I just want to start with that. >> Red Team Village, you know, I got lucky. I just had a friend that said, "Hey, come and volunteer." And then they liked the way I volunteered, so I I stayed. I work for free.

24:11 >> Hey, you did a great job. Would you like more responsibility? >> That was basically what happened to it. But you know, I feel really lucky that they they asked me to be part of the team because it's an incredible group of individuals that just really care about the community. They just want to spend time and effort and put on something that they know the community will enjoy and something they'll get something out of like cuz that's that's our mission. A lot of people don't know we have a mission behind the scenes and that's to provide offensive security education to the community through conferences, right? Yeah.

24:40 >> the primary one being Defcon. >> I was going to say this is not just a Defcon thing. You guys are all over the place. Yeah. >> Yep. And we you know this year I'm really proud of the team and I want to hit that point that you were talking about because we had an identity issue kind of a couple years ago and we were struggling with like how to set the village up to be the most productive because we two years, three years ago, something like that, we said, "Hey, we're going to hand out these poker chips, right? If you want to come to a talk, you come get a poker ship and then you come back at talk time and otherwise you can't even come in the room.

25:11 >> Right. >> Which basically like said, "Hey, if you're if you're in the front of the line, you can come to Red Team Village, but if you're in the back of the line, you're never getting in here." And >> that was a horrible thing for us to do. We didn't realize it when we were planning it. We thought this is going to be great. It was fantastic idea. but we got the backlash and and we learned from that. So, this year, you know, the village is open. Anybody can walk through. We have, six tactics stations ongoing the entire time. So, you can just sit down and work on something. some of those are tied to workshops. So, you might attend an hour workshop and then you can go over and just do the hands-on portion of the tactic.

25:42 >> and I think that's so much better than just talks. We used to just do talks. >> Yeah. >> It's like you said about payment village, right? It's being able to learn and get your hands on and do stuff. and and and the model of like, you know, I learn and somebody shows me and then I get to practice it. Like that is >> that's that's how you remember. You remember by actually doing. >> Yeah. That's the human, right? That's that's human learning, right? Monkey see monkey do, right? That is that is 100% like that's at least for me that's how I learned.

26:07 >> Yeah. >> Yeah. Yeah. >> Yeah. So because of that that's you know where where we set our vision a couple years ago that we wanted to go with the village and I'll just say that like this year is the best I've ever seen and I absolutely love the layout that we have and I think it's it's very inviting and and the noise problem that last year down there because there's all the microphones that that silent headphone system is has really you know helped with that. So yeah, I'm really really enjoying the village this year.

26:30 >> It's funny. I was going to ask like how it's evolved over the last couple years and I figured it would be this big AI answer and you're like it's headphones, you know, honestly >> game changer. Yeah. >> Sometimes it's a simple thing, you know. >> Turns out if people can hear you, they learn. >> Yes. Yeah. That's actually that's step one of Yeah, for sure. >> Right. >> That's awesome. you're also involved in the Noob Village this year. You're not not running it, but you're you're giving a a presentation there. Yeah.

27:00 >> Yep. So last year an individual Josh Mason started the noob village. >> when I heard the idea I was like how has somebody not done this before? >> So noob village is itself a noob? >> Yeah second year and it this village was created for first timers at Defcon who don't really know what to go see right where should I go? Oh this I'll start here at the noob village. and they have a lot of talks ongoing that that are geared at at newer people who are interested in cyber security or you know maybe are in one one role and want to move to another. so I'm giving a talk tomorrow. No, I'm giving a talk on Sunday.

27:35 >> I I couldn't tell you what day it is. >> at New Village that's called it's it's basically so you want to be a red teamer, right? I'm just going to talk about what being redteamer really is. Yeah. >> I think it'll resonate, but unfortunately it's like at, you know, 12:45 on Sunday, so, you know, some folks are already headed out. It's >> I'll probably be a zombie by that point, but I'll be there. >> Yeah, it it'll it'll maybe be a different flavor. You're saying, you know, >> so you want to be a red teamer, let me tell you about being a red teamer.

28:06 >> I've had it with red teaming. >> No, I just I want to I want to cut the noise, right? Because there's a lot of noise about red teaming as well. It's all just hacking. >> I was curious about like what you my perception of like people, you know, people message me on LinkedIn trying to get a job at Bishop Fox all the time and I'm like, "Thank you. I don't that's not my area, but I'll I'll do my best, you know." and I I feel like the the vibe behind red teaming is like you can't just become a red teamer. You have to do your time. You have you need the experience. Obviously, you need some experience. But like this seems like an accessible for someone newer to the field, newer to defcon, like >> here's maybe a road map, >> something like that >> essentially. Yeah, I actually made a slide with AI that is a road map.

28:49 >> Oh, nice. >> That will be part of it. But yeah, I think it's going to be a lot of fun. >> to your point though, we have just a vocabulary problem with red teaming, right? >> Cuz we call >> a lot of people just call including the red team village. We're guilty of this, right? We mean offensive security village, right? We call it the red team village cuz it's cooler. But within offensive security, there's a bunch of different disciplines and types of engagements, right? And one of those being a red team. So technically, you can, if you look at it in the broader sense, you can go directly into being a redteamer, an offensive security person, right? A junior tester. Well, as long as those jobs are still around, >> you walk in a door you weren't supposed to walk in, >> you could be a red teamer.

29:27 >> There you go. >> And then Yeah. So, the challenge is is keeping the the vocabulary straight. >> Yeah. I mean, it's the same tactics, same stuff, just kind of different objectives, different different defined goals on paper, you know. >> I always say that red teaming is pentesting with stealth and C2. >> Yeah. >> Sure. Yeah. Yeah. I like that. You guys so so the red team this year, right, you guys are doing the village of villages with a couple of the other raid blue team. I can't remember whichever whichever ones that was off the top of my head.

29:56 >> Yeah. I'm going to apologize cuz I have no idea. >> Okay. I did my >> No, he's telling you really that's what you're doing. >> Starting now. >> Yeah. By the way, if you didn't know, you are Yeah. >> So, here's what really happens. >> Yeah. >> Like a lot of other organizations just want to be involved with villages, right? So, literally on Friday morning, like 30 or 40 people will wander in the village and say, "Hey, can we put this in your village or can we do this?"

30:19 >> And the person that they talk to is probably the only person that knows about it at all. yeah, we do our best. So, I'm sure maybe Mike's work in the village of villages. I'm >> Yeah. Well, so so the the so the question I was gonna ask you was like beyond like the because I off my head I know it's blue team but I can't remember the other ones. What are some like good or what what would what do you think would be some cool like overlapping villages between like you know like like in my head I'm thinking like you know red team and IoT or something like that that has like you know some shared some shared skill sets that you could like apply to like a shared CTF or something like that.

30:51 >> Yeah. Yeah. So there's the pro the biggest overlap that I can see is probably between the red team village and the adversary village. >> Okay. Yeah. >> Right. because you got it's they're focused on adversary emulation simulation which is >> types of red teaming right so there's a lot of overlap a lot of similar talks a lot of people that you know submit talks to both villages and I think it's great though the the individual that runs that village has been doing it for years he teaches at black hat teaches at defcon right just a outstanding member of the community so definitely like that village and support him as well I actually submitted a talk to them as well this year and just shows you the quality because I I didn't make it >> not that you didn't make it you just had so many other talks at other villages. I had to turn it down.

31:31 >> Awesome. Well, I think I think talking about red teaming, let's kind of take that into as we said, everything's AI now, right? Matthew, I'd love to pick your brain a little bit about like how people think of red teaming as this traditional like it's a fishing thing or it's a network access thing. And you like for your job, you kind of have to think about that differently. I'm I'm guessing what what how how has being an AI red team expert sort of changed your your view of what red teaming means or has it?

32:07 >> Yeah. So one thing is I'll say that I think maybe our perspective is a little biased just because there the parts of it that are easy to us are probably not the easiest for everybody. For example, when it comes to like oh you know we need this initial bug we need this stuff it's like we've done this a lot so that's for us that's a little bit more trivial. But the what the >> the thing that's really enables us to do a lot quicker which has been a little bit surprising for us is like you know often times when you first breach into a company you're like there's this vast engineering creation that's like all of production all of the internal stuff and it takes you a while even if you have the access you need to figure out like the data that you want to steal and do it end to end right but now with these models instead of like you going through like >> some huge like multiple code bases and like piecing together forensically where this stuff actually sits like you can just sort of ask a model and in English like where's the prod database for this you know where you know stuff like this and so it's very helpful in that regard which is kind of an unexpected thing and then I also think like it's also very useful to like like when we talk about like building up infrastructure to do something like a fishing campaign or whatever it is previously it's like okay well now we got to build all this out we got to get domains we got to do all this stuff and now it's like sort of like okay so web server to do this is like very we can spin that code up very quickly and get operations moving u much more you know efficiently so that's definitely a big change as well. And you know, it probably speaks widely to the other side too, which is like other offensive on the other side of the, you know, of the coin is like, you know, real world APS are probably going to be able to do that, too. So, it's interesting to consider. Yeah.

33:34 >> I'm curious because we see so many stories about, you know, AI attacks and and and various whether it's you know, people manipulating organizations in more of a traditional way or even their their AI assets or something like that. the floor kind of barrier to entry on on doing a lot of this has lowered definitely. I'm curious like what someone who you know works at Open AI thinks about reading some of these things. like you have a level of expertise that these kind of vibe code folks maybe don't. do you read these things and think like we're in trouble or you think these these are like kids playing? you know listen I I think that like when it comes to like people who are on the I don't want to say like junior but you know the earlier stage in their career like they can they can definitely do a lot more because you know they can it's it's abstracted they can like some of the when it comes to like the reverse engineering stuff for example like that's very complex very nitty-gritty and a lot of that has been completely changed by the addition of all these AI models right you can do just not even just like it's even if you know what you're doing the reversing the scale of like analysis you can do and >> and the speed at which you can >> and the iteration speed 100% is like very different so that 100% exists.

34:50 you know, I I wouldn't say it in I wouldn't state it any other way. but you know, to me, like even on the other side, it it's kind of interesting how work has changed a little bit. There's some things I miss. I miss like being in the zone and like really grinding through code, trying to find some stuff, right? >> But it's also very interesting because now we can sort of move a lot more conceptually. Like before a lot of times we're like, "Okay, >> I know that this is roughly how this is going to work and how I'm going to do this and now you can almost move a lot more conceptually where you're like okay I know I need to do this write the code to do this execute it you know as opposed to you spending many hours doing something that the kind of grunt work that you know you can do it's just sort of you know >> yeah I think you know as as we've kind of talked about how so many people think of AI and and no one in this room but maybe think about AI as like this magic solution to all these things right and and it is like sometimes you see it do something and it blows your mind you're like wow I mean whether that's security related or a really great recipe that it just dropped on you or so, you know, I mean, there's so many so many different ways that it can that it can surprise you. Do you find working with it so closely that it still surprises you at all or are you just like desensitized to the whole thing? No, I mean listen, everybody everybody is surprised even at work just because like you'll have like new I mean like you have like small like model revision changes and you're suddenly like whoa this is like way better than like because you'd have these things you're like oh well it just can't do this right but then you know they come out with a new model release and you're like oh wow so all of the stuff that we thought was a problem is apparently solvable and is solved so we don't have to worry about it. So, and I' I've noticed like even in the past couple I want to say like couple months like the you can see a lot more of like I don't want to say thinking cuz it's like a complicated what what does that mean topic but you can see it >> being a lot less like the the traditional like oh the AI is being dumb and going down this weird whatever has kind of gone away quite a bit. So >> yeah. Yeah.

36:40 >> Yeah. >> I wanted to add one point about something that that he mentioned there. I think we often forget about the human element, right? Yes. AI is magic, right? But hacking a company, whether it's a kid using AI or whatever, right, is still a crime. >> So that person is still admitting to commit a crime. Just because that crime is is more accessible, doesn't make it any less of a crime, right? So I I don't I don't have again, I don't like to fearmonger because I don't think we're just going to have this mass, you know, you know, >> wave of of criminals. There's people, new criminals, have been honed.

37:14 Absolutely have. >> Yeah. But so all the people that are already criminal leaning, right, are when you read like reports that have come out from the big tech folks like Mandian, etc., you know, you you get into these reports and you really look at how they're using AI and it's it's the same way that that we're using it. They're using it to, you know, enable workflows and help write code because writing code sucks. I hate like I'm so glad I don't have to do that anymore. You know, >> freeze you.

37:39 >> Yeah. Don't write code anymore and I don't get haircuts anymore. That's I'm dumb. >> Me neither. Yeah. >> yeah. I'm I'm also a little bit curious to get sort of all of your perspective and maybe this could be like our our wrap up. We can >> kind of just dwell on this for a bit. When you think about what has happened in the industry over the last few years, like AI has disrupted things in in huge ways, right? if we may just kind of say like we think back on what we were talking about just a couple years ago at DevCon and AI was new and it was exciting. where do you what do you think what kind of conversations do you think we're going to be having in say two or three years >> and you are you're being recorded.

38:28 >> We will replay this in two years. We will see. >> Yeah. I think the conversations we'll be having is did we do it effectively, >> right? And what I mean by that is companies nowadays who specialize in AI are doing things. Companies who don't specialize in AI just throw AI at the solution and think it's working great. >> Right? And when that happens and you see that people who are proper practitioners of AI mess up and make mistakes and not people who aren't doing it, right? And and we have the the big breach that happened with AI escaping its its you know >> >> if that happens with someone who's practitioned in AI >> that's probably happened in other areas >> that we don't know about yet >> cuz whatever it hacked did not have the logs that other companies do, >> right? So I mean I think in the next couple years we'll see this like we have this like dead internet theory going on already where half the internet's bots, right?

39:30 Maybe it's not theory anymore. Maybe in a couple years we're talking to nothing but AI chat bots. >> Yeah. >> So, I don't know. My my biggest fear, I guess, in the future is it's going to be it's already hard to distinguish rural people from bots. I'm pretty sure I called to get my oil changed and it was a bot. >> I just they were talking to me. I was like they're like, "Okay, >> Thursday works." And I was like, >> "Yeah, >> I can't tell if you're real right now."

39:55 >> Yeah. >> Yeah. Thursday works for me, too. Thanks. Thank you. Like, oh my god, >> no one's listen this. Come on. >> yeah. So, I think yeah, the the conversation will be like, did we take enough precautions before we release this into non again non-cyber fields, too? >> So, >> yeah, >> that's a tough question. Really tough question. >> I have no idea. I'm >> Well, because I listen to you and you say the models are moving so fast, right? like like I I think we we it's very possible that we don't even know what conversations we'll be having in two years because you know there'll be another evolution of the the technology and we'll have gaps and we'll have new problems that have emerged and that's what we'll be talking about is how do we solve those but I think some of these hopefully you know in two years or so some of these initial problems that we're kind of thinking about and starting to work through will be beyond those and beyond you know the the next layer of problems.

40:50 >> Yeah. Right. Yeah. No, I think first of all that's yeah that's that's a that is a great point that like we are moving at breakneck speed. We have been moving at breakneck speed right with with development. so that's a good point. I'm I'm I'm very curious as far as like from like a lawmakaker perspective and like politicians perspective there's that that's obviously like a big deal right now is there's a lot of regulatory mo motions happening right now.

41:17 >> Yeah. I was going to say there's not much regulatory. >> No, there's not. There's not. There's a lot of talk around it and and I think I mean, you know, the speed of politics is probably around two years on something like that, right? >> Sure. >> on top of that, a couple years we're in another election year, right? So, >> some AI, >> right? >> And we'll have what was the the Fallout 3 president, John John Henry Adams or whatever. Yeah.

41:39 that'll be our next candidate. but no, I those are things that that I'm that are like on the forefront of like what what the next couple of years look like in the AI space is like you know we had like in the past I guess the last decade politics has changed a lot around technology >> there's been a lot of misinformation and disinformation campaigns that were >> preI right and then now we've come into the AI age and those have just kind of been amplified. so I'm I'm I'm definitely curious to see like the like the policy at Defcon talks that are going to be to taking place over the next two years for for stuff like that.

42:20 >> Yeah. So there's like I think a couple of sides for it. And first off, I want to say like I actually agree with what you said, which is funny because even >> listen, I'm at like at the Frontier Labs and I'm I'm still like if you ask me two years out, what do I know what it's going to look like? >> I really could not tell you. cuz you know I when I orig I'm like I'm like yeah you know it's interesting we'll sort of see where it goes. I'd love to see like if this can really because you never know it's like okay are the innovations going to continue? Are we still going to see this? Right.

42:49 >> I hope so at some point right >> and so like you know and and I think now you know one of the things that is the best is you get you're wrong a number of times and then you're kind all right well clearly there's something here you know now I'm a little bit more on the other side of the fence. I'm like okay clearly. I think in the short term some of the things that excite me are like you know I feel like the way that we've used computers up till now has been very much sort of like you know in the '9s like okay we got a keyboard and a mouse and like now we now get touch screens and I feel I watch watch people interact with computers a lot more naturally when it comes to like I can talk to it gives me accurate information I don't have to like >> you know instead of like like looking something up on a search engine and clicking stuff and reading articles it can just be like >> you know ask the question I want get the answer I want seems a lot more so I think that stuff is is exciting and with their with the we want with some of the complications there. But you know again looking out in looking at 6 months ago versus now and seeing the complexity change is pretty crazy. a part of me wants to think as well you know there'll be the short-term stuff where we'll have automation but in the history of computing it's it's rare that we have some big innovation and everybody's just like oh well nobody wants computers and you know like we finished all the like it tends to be people are like well let's get more of that in here. So >> yeah, >> I think on the very long term I could see something like that happening. But again, if I knew, you know, I would be probably making stock market.

44:06 >> I was about to say you wouldn't have the time to to be here. >> That's fair. Well, I I really appreciate everyone taking the time out of their day to to join us here. I think these are interesting conversations and we will see in two years how much of this is true. One thing I will say, I spoke with with a CISO earlier who was talking about one inspiring thing on the the kind of AI front where every organization needs to figure out how to implement it, how to yeah >> kind of control it. and they were saying there's a great community of CISOs that are all just kind of competitor doesn't matter. we are all on board in figuring this out and sharing information and doing whatever we can to make sure that we all get this right.

44:58 And I think that that >> kind of summed up to me like >> it's going to be okay. I think maybe I don't know. >> Yeah. Yeah. I think there's there's a lot of a lot of good people sharing information and working really hard to to to get this all right. And I think that that's that's a best case scenario. So >> about security I think is like you know the security teams were not like listen I know we're like competitors or whatever but we all want the same things just not get hacked not have these things happen. Right.

45:30 >> Right. Yeah. It is it is definitely I do like Yeah. We're one of the few industries that like works together as best as we can. Sure. >> Unlike our competitors. Yeah. >> Yeah. I think I always like to try and wrap our podcast because we usually talk about these terrible attacks and I like to try and wrap it on something positive. So, >> yeah, >> that's that's what I got. So, thank you so much you guys. Matthew, thanks for for joining. Billy, also a first timer. Great having you on. We'll be in touch next week and we'll have you back on.

46:00 >> actually, we're going to have a special episode next week. I will not be on. And it's actually going to be more of like a threat sort of like deep dive episode coming up. So, I'm really excited about that. >> but till next time, maybe we'll all be out on these couches again next year. Who knows? >> Be awesome. >> Stay safe and we'll see you next week.

Summary

The discussion revolves around the recent Black Hat and Defcon conferences, focusing on the overwhelming presence of AI in cybersecurity conversations. The panelists share their experiences and insights on the evolving landscape of security, the impact of AI on red teaming, and the importance of cutting through the noise created by hype around vulnerabilities and AI capabilities.

- The theme of this year's conferences is to "block out the noise" surrounding AI and cybersecurity.
- Attendees noted a shift in the format of Defcon, with pros and cons to the new convention center layout affecting interaction and intimacy.
- AI is a central topic, with concerns about its potential to both enhance and complicate security practices.
- The panelists emphasize the need for nuanced discussions about AI, moving beyond fear-mongering to practical applications and implications.
- Red Team Village is highlighted as a successful model for engaging attendees through hands-on learning and community involvement.
- Concerns about the future of entry-level positions in cybersecurity due to AI replacing some roles were discussed.
- The importance of collaboration among security professionals to address challenges posed by AI and cybersecurity threats was emphasized.
- The conversation reflects a recognition that while AI presents risks, it also offers tools to improve security practices and streamline operations.

Questions Answered

What is the theme of this year's discussion at Black Hat and Defcon?

The theme is to 'block out the noise' surrounding AI and focus on what is truly important for the future of security.

What are the common sources of noise in the cybersecurity industry?

The noise often comes from exaggerated reports on vulnerabilities and AI hype, especially around events like Defcon.

How has the urgency of patching vulnerabilities changed in the current threat landscape?

The time to patch vulnerabilities is critical, and organizations need to prioritize security updates more seriously due to heightened threats.

What is the perception of red teaming in the cybersecurity field?

Red teaming is often misunderstood; it requires experience and is not as accessible as some may think, despite the growing interest.

How is AI influencing the landscape of cybercrime?

Cybercriminals are leveraging AI similarly to security professionals, using it to enhance their workflows and automate tasks.

© transcribe · For agents Built with care and craft by Gokul Rajaram