← Back
AI Engineer October 7, 2026 19m

AI Hackers Are Faster Than Your Pen Test — Eli Cohen, Snyk

Read full transcript 16 segments
  1. Perfectly. Hello everyone. Perfectly. Hello everyone. Today we're Today we're Today we're going to talk about going to talk about going to talk about continuous continuous continuous offensive security, offensive security, offensive security, okay? I'll okay? I'll okay? I'll tell you what that tell you what that tell you what that means soon. Um, but before means soon. Um, but before means soon. Um, but before that, a little about myself. I am that, a little about myself. I am that, a little about myself. I am very happy to be here very happy to be here very happy to be here today. I'm Eli. Um, today. I'm Eli. Um, today. I'm Eli. Um, was once the was once the was once the co-founder and co-founder and CEO of Helios, a security company that was acquired by Snyk. And that was acquired by Snyk. And that was acquired by Snyk. And for the past 2 and a for the past 2 and a for the past 2 and a half years, I've had the half years, I've had the half years, I've had the privilege of working at Snyk, privilege of working at Snyk, privilege of working at Snyk, mostly on mostly on AI product management AI product management , but , but , but recently I've established a recently I've established a recently I've established a field field field CTO, meaning I CTO, meaning I CTO, meaning I work with work with work with developers and developers and developers and security professionals security professionals security professionals to better understand to better understand to better understand and help them and help them and help them shape their shape their AI security strategy AI security strategy . So, how do you . So, how do you . So, how do you take your take your take your AI agents and keep AI agents and keep AI agents and keep them safe? How do you them safe? How do you them safe? How do you work with your work with your work with your agents in agents in agents in production? Um, production? Um, production? Um, back there, can you back there, can you back there, can you set a timer for me set a timer for me set a timer for me , please? , please? Timer. So I will know the Timer. So I will know the time. Perfectly. Okay, time. Perfectly. Okay, time. Perfectly. Okay, now we also have now we also have now we also have time. Perfectly. Um, so just so time. Perfectly. Um, so just so time. Perfectly. Um, so just so I can get I can get I can get to know you a little better, to know you a little better, to know you a little better, please raise your please raise your please raise your hand. Who is more on the hand. Who is more on the hand. Who is more on the development side here?

  2. development side here? Developers. Okay, Developers. Okay, great. From a great. From a great. From a security perspective. Yes, I security perspective. Yes, I security perspective. Yes, I already know you. Perfectly. And then there are already know you. Perfectly. And then there are already know you. Perfectly. And then there are other people like other people like other people like sales, marketing, sales, marketing, sales, marketing, other people who other people who other people who manage agents in manage agents in manage agents in production who are not from production who are not from production who are not from development or security. development or security. development or security. Great, good. So, we have Great, good. So, we have Great, good. So, we have everyone here. So I'm everyone here. So I'm everyone here. So I'm going to tailor going to tailor going to tailor this session to everyone. So this session to everyone. So , obviously this is an , obviously this is an artificial artificial intelligence engineering conference, right? intelligence engineering conference, right? intelligence engineering conference, right? So, we already know So, we already know So, we already know that the amount of code that the amount of code that the amount of code generated today is generated today is incredibly larger incredibly larger incredibly larger than before, okay? than before, okay? According to our According to our data, that's 218% data, that's 218% more lines of code per more lines of code per more lines of code per day than before, day than before, day than before, okay? And over 85% of our okay? And over 85% of our okay? And over 85% of our developers now developers now developers now use use use coding agents. coding agents. coding agents. They're probably They're probably They're probably working here working here working here today, that's over 100%, today, that's over 100%, today, that's over 100%, right? Because I think right? Because I think right? Because I think each of you probably each of you probably each of you probably has five different has five different has five different cloud code sessions cloud code sessions cloud code sessions running running running at the same time. Otherwise you would at the same time. Otherwise you would at the same time. Otherwise you would n't be here today n't be here today n't be here today . And the interesting thing about . And the interesting thing about . And the interesting thing about these agents that are these agents that are these agents that are running in running in running in production and production and production and generating code for us generating code for us is that it's is that it's is that it's a lot less a lot less a lot less secure than we're secure than we're secure than we're used to, okay? So 62% of used to, okay? So 62% of the results the results the results generated by LLM are generated by LLM are generated by LLM are unsafe or unsafe or unsafe or corrupted, okay?

  3. corrupted, okay? corrupted, okay? So imagine this So imagine this So imagine this data combined together. data combined together. data combined together. This means we are This means we are This means we are generating more generating more generating more code than ever before. And code than ever before. And code than ever before. And this dangerous code this dangerous code this dangerous code gets into gets into gets into production. So this is a production. So this is a production. So this is a huge challenge huge challenge huge challenge for us as a community. for us as a community. And what that really And what that really means is that our means is that our means is that our portfolio of portfolio of portfolio of security issues is getting security issues is getting security issues is getting bigger and bigger, and bigger and bigger, and bigger and bigger, and fixing it fixing it fixing it is getting a lot is getting a lot is getting a lot harder, okay? harder, okay? So we're creating So we're creating a lot more a lot more a lot more problems at speed problems at speed problems at speed that we simply can't that we simply can't that we simply can't fix or fix or fix or mitigate. And not mitigate. And not mitigate. And not only that, AI also only that, AI also only that, AI also helps our helps our helps our attackers. So attackers. So attackers. So they're able to they're able to they're able to bundle low bundle low bundle low vulnerabilities together and vulnerabilities together and vulnerabilities together and form critical form critical form critical vulnerabilities out of these, ahem, vulnerabilities out of these, ahem, low-severity vulnerabilities. And what's really And what's really happening is that happening is that happening is that our attackers our attackers our attackers are using these LLMs are using these LLMs are using these LLMs and attacking us, and attacking us, and attacking us, especially where it's very especially where it's very especially where it's very difficult difficult difficult to use, um, the to use, um, the to use, um, the context of the application.

  4. context of the application. This is where our LLMs This is where our LLMs suffer the most suffer the most , because they , because they , because they create far create far create far more vulnerabilities more vulnerabilities more vulnerabilities in these areas. So, in these areas. So, in these areas. So, obviously we're obviously we're obviously we're using using using artificial intelligence, but artificial intelligence, but artificial intelligence, but our attackers are our attackers are our attackers are also using also using also using advanced models, advanced models, advanced models, okay? And the numbers are okay? And the numbers are okay? And the numbers are just incredible, just incredible, just incredible, okay? We are familiar with the okay? We are familiar with the okay? We are familiar with the operating model operating model operating model that was actually able to that was actually able to that was actually able to identify over 600 identify over 600 identify over 600 vulnerabilities to vulnerabilities to vulnerabilities to breach 600 breach 600 breach 600 firewalls in over firewalls in over firewalls in over 55 countries. Okay, this is 55 countries. Okay, this is 55 countries. Okay, this is just incredible. And just incredible. And just incredible. And the time it takes for an the time it takes for an the time it takes for an AI attack to succeed is AI attack to succeed is AI attack to succeed is constantly getting constantly getting constantly getting faster and faster. faster and faster. So, the average time for a So, the average time for a successful AI attack successful AI attack successful AI attack is 24 34 minutes is 24 34 minutes . Okay, well, the . Okay, well, the . Okay, well, the fastest time is 4 fastest time is 4 fastest time is 4 minutes. Okay, so that minutes. Okay, so that minutes. Okay, so that means that since means that since means that since I started talking I started talking , there's probably an , there's probably an , there's probably an AI attack that was able to AI attack that was able to AI attack that was able to successfully hack a successfully hack a successfully hack a production system. And production system. And production system. And 43% of all MCP servers 43% of all MCP servers 43% of all MCP servers actually have actually have actually have vulnerabilities. So, vulnerabilities. So, vulnerabilities. So, putting all this putting all this putting all this data together, we data together, we data together, we realize that we're realize that we're realize that we're creating a lot creating a lot creating a lot more code than ever more code than ever before. Each of us has before. Each of us has before. Each of us has multiple sessions of multiple sessions of multiple sessions of cloud cloud cloud code or code sets running at the same time code or code sets running at the same time . That code that's . That code that's . That code that's dangerous dangerous dangerous is getting into production, is getting into production, is getting into production, and the people that we're and the people that we're and the people that we're dealing with, dealing with, dealing with, the attackers are actually the attackers are actually the attackers are actually using the using the using the same tools, and

  5. same tools, and same tools, and they're moving faster they're moving faster they're moving faster than ever, than ever, than ever, trying to actually trying to actually trying to actually exploit these exploit these exploit these vulnerabilities, and our vulnerabilities, and our vulnerabilities, and our portfolio is just portfolio is just portfolio is just piling up, and we piling up, and we piling up, and we can't can't can't get it. And that's exactly what get it. And that's exactly what get it. And that's exactly what I want to talk about I want to talk about I want to talk about today. What we today. What we today. What we should be doing to should be doing to should be doing to help improve help improve help improve our security, and this is our security, and this is our security, and this is closely related to closely related to closely related to how we can how we can how we can use use use offensive security offensive security offensive security not only for not only for not only for attackers, but also attackers, but also attackers, but also for us as for us as for us as defenders. So defenders. So defenders. So why why why can't traditional security can't traditional security can't traditional security keep up with us? keep up with us? keep up with us? So today there is a So today there is a So today there is a mixed audience, both mixed audience, both mixed audience, both development people and development people and development people and security people. So I security people. So I security people. So I want to want to want to go over a few go over a few go over a few basic concepts first, basic concepts first, basic concepts first, okay, just to okay, just to okay, just to make sure everyone is make sure everyone is make sure everyone is familiar. So what familiar. So what familiar. So what used to be very used to be very used to be very easy to do is easy to do is easy to do is static static static code scanning, okay? SAS. So, code scanning, okay? SAS. So, code scanning, okay? SAS. So, imagine you're imagine you're imagine you're pushing new code pushing new code pushing new code into production, there's a into production, there's a into production, there's a static scanner static scanner static scanner that scans it and that scans it and that scans it and looks for SQL injections, looks for SQL injections, looks for SQL injections, cross-site cross-site cross-site scripting. So, it scripting. So, it scripting. So, it used to be relatively used to be relatively used to be relatively cheap and relatively cheap and relatively cheap and relatively easy to run this easy to run this easy to run this for every code change for every code change . And that's great. What it . And that's great. What it . And that's great. What it doesn't detect is what doesn't detect is what doesn't detect is what gets caught during gets caught during gets caught during execution, okay?

  6. execution, okay? execution, okay? So if you have So if you have So if you have any any any authorization issues, if authorization issues, if authorization issues, if you have any you have any you have any configuration issues, configuration issues, configuration issues, you're going you're going you're going to need to need to need dynamic dynamic dynamic application security testing for that, application security testing for that, application security testing for that, okay? You will okay? You will okay? You will need something for need something for need something for dynamic dynamic dynamic testing of the application. testing of the application. testing of the application. One example is One example is One example is BOLA, BOLA, BOLA, broken broken broken object level authorization, which essentially object level authorization, which essentially object level authorization, which essentially means that means that means that user A can user A can user A can access access access user B's data. user B's data. user B's data. Okay? Okay? Okay? You will You will You will never find such vulnerabilities never find such vulnerabilities never find such vulnerabilities through static through static through static analysis. To do this, analysis. To do this, analysis. To do this, you need to you need to you need to examine the program examine the program examine the program at runtime. at runtime. at runtime. So what the So what the So what the DAST scanner actually does is it DAST scanner actually does is it DAST scanner actually does is it just takes a just takes a predefined set of predefined set of tons of tons of tons of payloads and just payloads and just payloads and just sends them to the sends them to the sends them to the application, to different application, to different application, to different API endpoints, and that's how API endpoints, and that's how API endpoints, and that's how it it it manages to find manages to find manages to find vulnerabilities. So, it vulnerabilities. So, it vulnerabilities. So, it was also something that was also something that was also something that could find new could find new could find new things, but it didn't sit things, but it didn't sit things, but it didn't sit well with the biggest well with the biggest well with the biggest problem we problem we problem we have with the code that have with the code that have with the code that LLMs create. And this is LLMs create. And this is LLMs create. And this is business logic. So, that's what business logic. So, that's what business logic. So, that's what we as an we as an we as an industry industry industry use pen- use pen- testing for, okay?

  7. testing for, okay? testing for, okay? What is the idea behind pen What is the idea behind pen testing? This is a testing? This is a tester who really tester who really tester who really understands the concept and understands the concept and understands the concept and business logic of business logic of business logic of the application, the application, the application, tries to tries to tries to break it and find all the break it and find all the break it and find all the vulnerabilities. This is the vulnerabilities. This is the vulnerabilities. This is the gold standard in gold standard in application security testing, but it application security testing, but it has some challenges, does has some challenges, does has some challenges, does n't it? First of all, it n't it? First of all, it n't it? First of all, it costs a lot of money, costs a lot of money, costs a lot of money, doesn't it? Because what was doesn't it? Because what was doesn't it? Because what was really needed really needed really needed was a was a was a security researcher, a person, not a security researcher, a person, not a security researcher, a person, not a person in the process, a person in the process, a person in the process, a person who actually person who actually person who actually does the testing does the testing does the testing and tries to and tries to and tries to break the application, and break the application, and break the application, and that costs a lot of that costs a lot of that costs a lot of money. The second money. The second money. The second problem is problem is problem is that it costs that it costs that it costs a lot of money, and a lot of money, and a lot of money, and because the process was because the process was because the process was so slow, so slow, so slow, companies can companies can companies can only do it once a only do it once a only do it once a year, twice a year, year, twice a year, year, twice a year, maybe three times a maybe three times a maybe three times a year, okay? So the year, okay? So the year, okay? So the combination of the fact combination of the fact combination of the fact that today our that today our that today our attackers with attackers with attackers with artificial intelligence artificial intelligence artificial intelligence are trying are trying are trying to attack us constantly, to attack us constantly, to attack us constantly, like doing like doing like doing pen testing twice pen testing twice pen testing twice a year, is just a year, is just a year, is just not enough, okay? not enough, okay? not enough, okay? So what will you So what will you So what will you do with the remaining 350 do with the remaining 350 do with the remaining 350 days of the year when days of the year when days of the year when no one is testing your no one is testing your no one is testing your program? Not only program? Not only program? Not only that, but the results that, but the results that, but the results you got, you you got, you you got, you got this got this got this crazy and crazy and crazy and glorious report in a glorious report in a glorious report in a PDF that you had to PDF that you had to PDF that you had to send to your send to your send to your developers. They developers. They developers. They had to take it had to take it had to take it back to figure out back to figure out back to figure out what was real and what wasn't, and what was real and what wasn't, and what was real and what wasn't, and then start then start then start fixing it, and then fixing it, and then fixing it, and then you had to you had to retest, okay?

  8. retest, okay? Sounds like a movie from the 90s Sounds like a movie from the 90s , right? It does , right? It does , right? It does n't make sense to do it anymore n't make sense to do it anymore , but it was the gold , but it was the gold , but it was the gold standard. This is what we standard. This is what we standard. This is what we did. The thing is, this is the did. The thing is, this is the did. The thing is, this is the best method best method best method for actually for actually for actually testing your testing your testing your application for application for application for its business logic. its business logic. OK? So what's OK? So what's changing today? changing today? Today we have a new Today we have a new technology, and that's what technology, and that's what technology, and that's what I want to I want to I want to talk about: how can we talk about: how can we use this use this new area of new area of AI tools, AI tools, LLMs, and frontier models LLMs, and frontier models LLMs, and frontier models to actually to actually to actually do do do pen testing continuously pen testing continuously pen testing continuously and at scale. And that's why and at scale. And that's why and at scale. And that's why we're we're we're implementing implementing implementing continuous continuous continuous offensive security offensive security offensive security Evo, okay? So, this is Evo, okay? So, this is Evo, okay? So, this is obviously very obviously very obviously very related to what we related to what we related to what we do at Sneak, but what do at Sneak, but what do at Sneak, but what I'm going to tell you today is I'm going to tell you today is I'm going to tell you today is general, general, general, okay? You can okay? You can okay? You can take the principles of what take the principles of what take the principles of what I'm telling you, and I'm telling you, and I'm telling you, and you can actually you can actually you can actually test it with test it with any vendor any vendor any vendor at the show. OK? at the show. OK? at the show. OK? So, I want you to So, I want you to So, I want you to think about the think about the think about the following, okay?

  9. following, okay? following, okay? So what you need to So what you need to So what you need to do today is you do today is you do today is you need to prepare need to prepare need to prepare your production your production your production system for the system for the system for the unknown, okay? And unknown, okay? And unknown, okay? And for that, you for that, you for that, you need a new need a new need a new paradigm, okay? paradigm, okay? paradigm, okay? So, first of all, So, first of all, So, first of all, obviously you obviously you obviously you need the AI need the AI need the AI pen testing capabilities pen testing capabilities , which I'll double- click on again soon. But you also click on again soon. But you also need to start need to start need to start using using using the concept of red the concept of red the concept of red command, okay? command, okay? command, okay? So, red So, red So, red agent command agent command , the idea is to , the idea is to , the idea is to conduct conduct conduct multi-stage attacks, multi-stage attacks, multi-stage attacks, okay? So, okay? So, okay? So, try to simulate a try to simulate a try to simulate a rapid implementation rapid implementation rapid implementation or data leak and or data leak and or data leak and target capture, and target capture, and target capture, and obviously combine that obviously combine that obviously combine that with dynamic with dynamic with dynamic testing, which is testing, which is testing, which is good at detecting good at detecting authorization issues. So authorization issues. So we're bringing all of these we're bringing all of these we're bringing all of these capabilities together, capabilities together, capabilities together, creating one creating one creating one suite for suite for suite for offensive security offensive security offensive security as part of our as part of our as part of our sinister offering sinister offering , and the idea is to , and the idea is to , and the idea is to help help help you actually you actually you actually mitigate or, uh, mitigate or, uh, mitigate or, uh, help you help you help you deal with the deal with the deal with the fact that fact that fact that attackers attackers attackers are using the same are using the same are using the same tools that we are, tools that we are, tools that we are, and they're doing it and they're doing it and they're doing it 24/7, 24/7, 24/7, finding finding finding vulnerabilities faster vulnerabilities faster vulnerabilities faster than before, and your than before, and your than before, and your portfolio just can't portfolio just can't portfolio just can't handle it.

  10. handle it. So what are we doing differently in differently in differently in AI pen testing? Okay, as AI pen testing? Okay, as AI pen testing? Okay, as we said before, the we said before, the we said before, the big promise of big promise of big promise of pen testing has pen testing has pen testing has always been that always been that always been that the person ultimately the person ultimately the person ultimately really understands the really understands the really understands the business context, business context, business context, okay? So now we're okay? So now we're okay? So now we're bringing that to the LLM, and bringing that to the LLM, and bringing that to the LLM, and if there's one thing that the LLM is if there's one thing that the LLM is if there's one thing that the LLM is really good at, it's really good at, it's really good at, it's really trying to really trying to really trying to impact the business impact the business context. So, behind context. So, behind context. So, behind the scenes we the scenes we the scenes we use LLM, and use LLM, and use LLM, and we do it we do it we do it continuously, continuously, continuously, right? So you don't right? So you don't right? So you don't need to do need to do need to do things like things like things like pen testing twice or three times pen testing twice or three times pen testing twice or three times a year anymore, we'll a year anymore, we'll a year anymore, we'll do it every time we do it every time we do it every time we change the code, okay? change the code, okay? change the code, okay? Every PR Every PR message you have, every message you have, every message you have, every delta, we'll delta, we'll delta, we'll run these run these run these sensitivity tests for you, sensitivity tests for you, sensitivity tests for you, and we'll let your and we'll let your and we'll let your developers know what they developers know what they developers know what they need to fix need to fix need to fix and how they need to and how they need to and how they need to do it differently. do it differently. do it differently. It's clear that we're It's clear that we're It's clear that we're using our using our using our understanding of the context of the understanding of the context of the understanding of the context of the application, but we're application, but we're application, but we're also helping to also helping to also helping to reduce the number of reduce the number of reduce the number of false false false positives. For us positives. For us positives. For us as an industry, there is a serious as an industry, there is a serious as an industry, there is a serious problem of problem of problem of false false false positives. So we're positives. So we're positives. So we're actually proving to actually proving to actually proving to you that the vulnerabilities we find are you that the vulnerabilities we find are you that the vulnerabilities we find are actually actually actually exploitable, exploitable, exploitable, and we're not just and we're not just and we're not just marking them as marking them as marking them as bugs. We actually bugs. We actually bugs. We actually help you help you help you prove that they can be prove that they can be prove that they can be exploited, and we exploited, and we exploited, and we take context for take context for take context for many different many different many different machines and for many machines and for many machines and for many different environments, and different environments, and different environments, and we combine them together we combine them together to help us to help us to help us drive our LLMs.

  11. drive our LLMs. So, that's what we So, that's what we do differently, and I do differently, and I do differently, and I think that's what think that's what think that's what makes this solution makes this solution makes this solution so unique and so unique and so unique and so convenient for so convenient for so convenient for all of us who are all of us who are all of us who are working in production working in production working in production and shipping more and shipping more and shipping more code than ever before. code than ever before. So, how do we So, how do we do this? How does it work do this? How does it work do this? How does it work behind the scenes? Okay, behind the scenes? Okay, behind the scenes? Okay, so I want you to so I want you to so I want you to understand that we don't understand that we don't understand that we don't take static or take static or take static or dynamic scanners and dynamic scanners and dynamic scanners and just combine just combine just combine them with LLM. Okay, we're them with LLM. Okay, we're them with LLM. Okay, we're building this from scratch building this from scratch building this from scratch using LLM. using LLM. using LLM. So, we have a series of So, we have a series of So, we have a series of multiple agents multiple agents multiple agents working together. working together. working together. The first of them is the The first of them is the The first of them is the LLM orchestrator. Okay, LLM orchestrator. Okay, LLM orchestrator. Okay, imagine it as a imagine it as a imagine it as a brain. This agent brain. This agent brain. This agent works on a dynamic works on a dynamic works on a dynamic plan that he plan that he plan that he follows, and he follows, and he follows, and he knows how to manage knows how to manage knows how to manage all the different all the different all the different subagents. The first subagents. The first subagents. The first agent, or rather the agent, or rather the agent, or rather the second agent, is a second agent, is a second agent, is a scout. Okay, you scout. Okay, you scout. Okay, you can think of it as can think of it as can think of it as your elite your elite your elite reconnaissance reconnaissance reconnaissance unit. The idea unit. The idea unit. The idea is to is to is to collect all possible collect all possible collect all possible data about different data about different data about different network endpoints, network endpoints, network endpoints, different APIs, different different APIs, different different APIs, different fingerprints. Gather all fingerprints. Gather all fingerprints. Gather all this data together, this data together, this data together, formalize formalize formalize the architecture the architecture the architecture based on it, and pass it on to the based on it, and pass it on to the based on it, and pass it on to the next agent. And the next agent. And the next agent. And the next agent is next agent is vulnerability testing. This is vulnerability testing. This is again a series of again a series of again a series of several several several specialized specialized specialized agents. Some of them agents. Some of them agents. Some of them target known target known target known classes of vulnerabilities.

  12. classes of vulnerabilities. classes of vulnerabilities. Some of them actually Some of them actually Some of them actually look for vulnerabilities look for vulnerabilities look for vulnerabilities in real time and in real time and in real time and try to hack try to hack try to hack your application to your application to your application to understand the business understand the business context and context and context and understand where an understand where an attacker might come from. And then attacker might come from. And then they hand over to the judge, they hand over to the judge, they hand over to the judge, as I like to as I like to as I like to call it, the call it, the call it, the exploit check. So exploit check. So exploit check. So essentially every essentially every essentially every vulnerability that the vulnerability that the vulnerability that the previous previous previous agent finds is now agent finds is now agent finds is now passed to this passed to this passed to this judge, and the judge's goal is to judge, and the judge's goal is to tell us whether it's a tell us whether it's a tell us whether it's a real vulnerability real vulnerability real vulnerability or not. Telling us whether or not. Telling us whether or not. Telling us whether it can be it can be it can be exploited or not is exploited or not is exploited or not is precisely because we precisely because we precisely because we want to reduce the want to reduce the want to reduce the cognitive cognitive cognitive load, precisely load, precisely load, precisely because we want to because we want to because we want to reduce the number of reduce the number of reduce the number of false false false positives in the positives in the positives in the system. Next comes the system. Next comes the system. Next comes the correction agent, correction agent, correction agent, because everything we because everything we because everything we do, we want to do, we want to do, we want to make it effective. Okay make it effective. Okay , we don't want to , we don't want to , we don't want to report a report a report a vulnerability that vulnerability that vulnerability that the developers ultimately the developers ultimately the developers ultimately don't know what they don't know what they don't know what they can do with it. can do with it. And after that comes the And after that comes the reporting agent, because reporting agent, because reporting agent, because everything needs to be everything needs to be everything needs to be reported. So, what reported. So, what reported. So, what sets us apart? And this is something sets us apart? And this is something I encourage you I encourage you I encourage you to clarify with every to clarify with every to clarify with every vendor that vendor that vendor that is trying to provide is trying to provide is trying to provide you with a solution, whether you you with a solution, whether you you with a solution, whether you want to implement your want to implement your want to implement your own solution for own solution for own solution for AI testing AI testing AI testing with a pen.

  13. with a pen. with a pen. It's a huge industry now. It's a huge industry now. So I think So I think the most important thing you the most important thing you the most important thing you need to remember, and need to remember, and need to remember, and you already know, you already know, you already know, especially the developers especially the developers especially the developers in the room, is that in the room, is that in the room, is that context is everything. Your context is everything. Your context is everything. Your LLM is only as good LLM is only as good LLM is only as good as the context you as the context you as the context you provide for them. So we're provide for them. So we're provide for them. So we're trying to not trying to not trying to not just just just use our use our AI pen testing solution as a standalone AI pen testing solution as a standalone solution. We're actually solution. We're actually solution. We're actually loading it with loading it with loading it with data from all the data from all the data from all the previous scanners, previous scanners, previous scanners, okay? So, okay? So, okay? So, static static static code scanner, dynamic code scanner, dynamic code scanner, dynamic code scanner, all the code scanner, all the code scanner, all the different different different agent mechanisms are bundled agent mechanisms are bundled agent mechanisms are bundled together, and they're together, and they're together, and they're fed into our fed into our pen testing solution pen testing solution using artificial using artificial using artificial intelligence, because intelligence, because intelligence, because that way we know that way we know how to adapt and how to how to adapt and how to how to adapt and how to direct the LLM where direct the LLM where direct the LLM where to look. And, as you also to look. And, as you also to look. And, as you also know for Mitos or for know for Mitos or for know for Mitos or for Flabel, when these models Flabel, when these models Flabel, when these models know where to look, the know where to look, the know where to look, the results are much results are much results are much better. So, that's one better. So, that's one better. So, that's one thing that we do that's, thing that we do that's, thing that we do that's, you know, very you know, very you know, very unique and very unique and very unique and very differentiated. And differentiated. And differentiated. And also what I want also what I want also what I want you to remember is that you to remember is that you to remember is that one solution is one solution is one solution is not enough. OK?

  14. not enough. OK? not enough. OK? The most important thing about this is The most important thing about this is when you when you when you combine these things combine these things combine these things together. And based on the together. And based on the together. And based on the data that we're seeing data that we're seeing data that we're seeing both from the labs and both from the labs and both from the labs and from real data from real data from real data from customers, from customers, from customers, bringing the data bringing the data bringing the data together is really together is really together is really important, and you important, and you important, and you can't really, can't really, can't really, you can't really you can't really just use just use one of them, okay? one of them, okay? There are certain classes of There are certain classes of vulnerabilities. This DAST vulnerabilities. This DAST is the best scanner is the best scanner is the best scanner for this, okay? for this, okay? Because you have a really Because you have a really comprehensive set of comprehensive set of comprehensive set of payloads payloads that you can that you can that you can send to your send to your send to your application. So this is very application. So this is very application. So this is very good, for example, for good, for example, for good, for example, for cross-site cross-site cross-site scripting, okay? scripting, okay? scripting, okay? So, DAST for So, DAST for So, DAST for cross-site cross-site cross-site scripting is the best scripting is the best scripting is the best solution. But if you solution. But if you solution. But if you want, again, want, again, want, again, like business logic, then like business logic, then like business logic, then you should combine you should combine you should combine it with it with it with pen testing because that pen testing because that pen testing because that will be the best will be the best will be the best solution. So I think solution. So I think solution. So I think what I really want what I really want what I really want you to take away from this, you to take away from this, you to take away from this, if there's one thing I want if there's one thing I want if there's one thing I want you to take away from me, you to take away from me, you to take away from me, is to realize that is to realize that is to realize that the world is changing. You the world is changing. You the world is changing. You already know that. That's what already know that. That's what already know that. That's what made you come made you come made you come here. But you know, we here. But you know, we here. But you know, we tested our tested our tested our program every program every program every few months because few months because few months because the changes and the rate of the changes and the rate of the changes and the rate of change were very change were very change were very slow. And at the end, there slow. And at the end, there slow. And at the end, there were people who were people who were people who were thinking about were thinking about were thinking about the application and about the the application and about the the application and about the changes. But that kind of changes. But that kind of changes. But that kind of world doesn't exist anymore world doesn't exist anymore , does it? Now we're , does it? Now we're pushing code into pushing code into production 24/7, and we have LLMs production 24/7, and we have LLMs production 24/7, and we have LLMs trying trying trying to reason about the to reason about the to reason about the context of the application, context of the application, context of the application, and they're trying to and they're trying to and they're trying to break it all the time.

  15. break it all the time. break it all the time. Some of them can Some of them can Some of them can do it in just 4 do it in just 4 do it in just 4 minutes, okay? That's minutes, okay? That's minutes, okay? That's almost five times almost five times almost five times the lecture of the session I the lecture of the session I the lecture of the session I just gave. So, just gave. So, just gave. So, when you start when you start when you start looking for new solutions looking for new solutions looking for new solutions to this problem, you to this problem, you to this problem, you have to ask have to ask have to ask yourself four questions, yourself four questions, yourself four questions, okay? First, do okay? First, do okay? First, do we run this we run this we run this solution continuously, solution continuously, solution continuously, or is it just a point or is it just a point or is it just a point solution that we solution that we solution that we run from time to run from time to run from time to time? OK? This is a time? OK? This is a time? OK? This is a significant difference. significant difference. Second, do Second, do Second, do they really think about the they really think about the they really think about the context of the application? context of the application? context of the application? OK? Because OK? Because OK? Because given the nature of given the nature of given the nature of these LLMs, the these LLMs, the these LLMs, the application context is where application context is where new new vulnerabilities really come from. And vulnerabilities really come from. And third, what other third, what other third, what other context can they context can they context can they learn from? OK? How learn from? OK? How learn from? OK? How can they can they can they enrich the data? enrich the data? enrich the data? Because the richer the data, Because the richer the data, Because the richer the data, the better and, by the way, the the better and, by the way, the the better and, by the way, the cheaper the cheaper the cheaper the LLM operation will be. And the LLM operation will be. And the LLM operation will be. And the fourth part: do fourth part: do fourth part: do they really they really they really help me help me help me prove that the bug prove that the bug prove that the bug exists and make sure exists and make sure it can be it can be it can be exploited, or do they exploited, or do they exploited, or do they just mark it just mark it just mark it as a bug? OK?

  16. as a bug? OK? as a bug? OK? So our goal is not So our goal is not So our goal is not only to help you only to help you only to help you find find find bugs faster, but to bugs faster, but to bugs faster, but to do it better and do it better and do it better and cheaper, and to help cheaper, and to help cheaper, and to help you as a developer or you as a developer or you as a developer or security professional security professional security professional focus on what focus on what focus on what matters most matters most . Hmm, thank you very much, and . Hmm, thank you very much, and . Hmm, thank you very much, and I did this in every I did this in every I did this in every lecture, you know? lecture, you know? lecture, you know? My dream was to be a My dream was to be a My dream was to be a rock star, but I was supposed to rock star, but I was supposed to rock star, but I was supposed to be a be a be a cyber entrepreneur. cyber entrepreneur. cyber entrepreneur. So instead I'm So instead I'm So instead I'm going to going to going to take pictures. So, take pictures. So, take pictures. So, raise your hands, everyone. raise your hands, everyone. Okay, great. Okay, great. Thank you very much. And I'm here for Thank you very much. And I'm here for Thank you very much. And I'm here for questions, if you want questions, if you want . Come to the stand. . Come to the stand. . Come to the stand. He is very close. He is very close. He is very close. sneak.io—meet Evo, sneak.io—meet Evo, sneak.io—meet Evo, our new our new AI-powered security offering. AI-powered security offering. Thank you, thank you very much.

Summary

The main theme is continuous offensive security in the context of AI agents and code generation, highlighting the increased volume and insecurity of AI-generated code. Key subjects include AI agents, LLM-generated code, and the challenges of securing production environments. The practical takeaway is the urgent need for developers and security professionals to develop strategies for managing and securing AI-generated code due to its inherent risks.

View original episode ↗