AI Red Teaming and the Death of the CVE
Attackers are getting faster, and the tools they use are getting cheaper. Chen Burshan, CEO of Skyhawk Security, joins Alan Shimel on Techstrong TV to explain why traditional vulnerability management is running out of runway and how autonomous AI red teams are becoming a required defense. A veteran of Dome9 and nearly a decade in cloud security, Chen walks through Skyhawk’s approach to continuously simulating sophisticated cloud attacks, and shares a recent case where the AI red team chained together entirely legitimate configurations — not misconfigurations or CVEs — to escalate from a low-permission entry point to organization-level admin in seconds. He explains why less than 1 percent of exposures actually matter, why the CVE model can’t keep up with LLM-driven attackers, and why the answer isn’t to slow down AI but to stress-test our own systems with the same tools the adversaries are using.
Transcript
Hey everyone, welcome back here to Techstrong TV. My next guest is my friend Chen Bershad. He's the CEO at Skyhawk Security.
Let's welcome him back to Techstrong TV. Hey, Chen, how are you? Hey, Alan, how are you?
Great to be here again. Great to see you, as always. Chen, you've been on the show before, but I don't know if everyone watching this episode saw the last time you were on.
Not everyone waits up every day for the next Techstrong TV episode. I wish they did. But anyway, Chen, give people a little bit of your background and how you came to Skyhawk Security.
So I've been doing cloud security for over 10 years. I've been part of the team that behind the CSPM market, the creation of the CSPM market, headed the Israeli side of Dome9 prior to the Check Point acquisition. So I've been doing cloud security from generation one before it was called CSPM till today.
Sure. And we'll talk about what we're doing today, which in my view is generation three. And that's how I got into that seat.
So what led to Skyhawk Security? So Skyhawk basically started as a cloud detection and response company. When I took the helm, it was more or less around the launch of OpenAI.
Hmm. And at that point I had basically a vision where I said, there will be a point in time where a kid with a credit card will take an LLM, give it a domain, say attack, and will be successful. That vision took three and a half years to materialize.
But now we all know it's a fact, right? " The answer is yes, and usually they don't know how to defend against it, and that's where we come to play. Got it.
Chen, just in case, before we jump into what I want to talk about, people who want to get more information on Skyhawk Security, what's the website? security. Easy enough.
Perfect. Easy. And while I have you, are you guys going to be Black Hat or no?
Probably no. Okay. You're not missing anything.
It's 115 degrees there. So. We have it back at home, so- Yeah.
Well, I live in South Florida, it's no better here, but still, I hear you. So I wanted to talk about recently the Skyhawk Security AI Red Team. Well, first- Mm-hmm ...
let's define what do we mean by an AI Red Team? Most of our audience is familiar with Red Team, but- It's a very good point. So, as I said, it was clear to us that there will be a point in time where AI attackers, AI-enabled attackers, will be out there enabling basically attacks at large scale and velocity.
The idea in our mind was that the only way to defend against these attacks is to actually simulate them, use the same tools attackers are going to use against you in order to- Sure ... see what they will be able to do to you and defend. So we've built an AI-powered Red Team that continuously simulates AI autonomous attacks, agentic attacks on customers' clouds environment, and we're basically helping them preemptively see their true exposures as an AI-enabled attacker would, and make sure that they have the right coverage from a security control perspective, make sure that their defenses are going to hold when the attack is going to be deployed against them.
Look, that's what resilience is about, right? You understand what you got, so you know what can happen and everything else, and yeah, I applaud you for doing it. But an interesting thing happened with your AI Red Team exercises recently.
Share with our audience, if you don't mind. So that security team did everything right. They had a leading CNAPP in place.
They cleared all the criticals. They were very proud at what they were doing. But what was really staggering is the fact that our AI Red Team was able to chain legitimate configurations, not just misconfigurations or vulnerabilities.
From a low permission entry point, we were able to chain multiple capabilities into escalation, into an account, and from there into an organization admin level. And seeing that result was really amazing, because on its own, no one could actually see that this is possible. And the AI was able to build it on its own in seconds.
That was amazing. If I may ask, and you may not know the answer, which AI, what models were you using that did this in seconds? So we usually don't disclose our secret sauce.
Okay. But it's a fusion of multiple models. Okay.
We're using some commercial, well-known LLMs, and we're using some homegrown scale models. And that variety allows us to make sure that what we are providing is solid. There's no hallucinations.
We know that when we give you a result, that you can count on it to be a true positive finding. Right. I understand.
The reason I ask is, just this last week and weekend, I was doing my own, not AI red teaming, but my own playing with the models. 6 Sol compared to the prior models- Yeah ... is crazy.
It's a huge step up. You're making a good point. We didn't need, for that specific attack, any lucrative, expensive, high-end frontier models or state-of-the-art models, which even makes it more frightening.
Because it's- Yeah, it is. Well, that I actually just wrote an article, it's not even published yet. I wrote the article this weekend after playing.
You look at, let's say, the top 12 models. So you got the three big, four American ones, right? OpenAI, Anthropic, Google, Groq, if you want to put it in there, maybe even the Microsoft.
This new version of Anthropic and OpenAI, yeah, they're at the top. But you look at the 10, and there's a bunch of Chinese, there's Mistral from France. The gap between them is narrowing every day.
There's not... You know what I mean? It used to be, oh, it's a year ahead, nine months ahead.
Nah, it's a few months ahead at most. And- Everybody will have this ... and you can have some local models that can run on- That are even more specialized.
It's a frightening world And you can turn off some of the models' guardrails if you host them on your own. So, if you're looking on it in a very wide perspective, it's just going to get more, in a sense, it's going to be more accessible, cheaper. Attackers will be able to run- That's the thing.
Another article I wrote this week, I forgot the, what's the terrorist organization? I think they're affiliated with ISIS. Boko Haram, something like that.
Boko Haram. A report from them. They're using it, forget cybersecurity, they're using it to build bombs.
And other kind of terrorist sort of weapons in the wrong hands. I don't know what the answer is here, but I do know that it's getting scarier and scarier. Yeah.
But I can understand the tension between the need to be more cautious with the models versus not inhibiting innovation. " Right? Never.
The- Genie's out of the bottle Yeah. Listen, the basic concept behind what was done in Skyel was that, you know that amazing tools will always find their way into bad people hands. And the other concept was that if you want to defend, you have to stress test yourself with what they're going to do to you.
Yeah. And again, it comes with multiple angles. State-of-the-art models, local models.
You have to make sure that you're ready against- Against everything. And that, I think, is an answer, Chen. You can't bury your head in the sand and think the world's going to slow down.
It's not going to slow down. " And that's why you need these kinds of AI red team exercises. And the challenge with AI is that it's attackers on steroids.
So now you start to see the industry reporting the collapse between vulnerability discovery to an exploit being ready. You don't have time to prepare. Attack times are shortening, and they are kind of cutting by half.
From every report, every year, you hear that the attack time is shortening by half. You have to be able to respond to these attacks faster than the attackers. The only way to do it is to have that simulations that allows you to preemptively make sure that you address your exposures and reduce the exposure as much as possible.
And on the other end, wherever you cannot, make sure that you have the right compensating security controls and automated responses that can respond to an attack faster than the attacker without making damage to your business, without taking down systems, right, without making damage to production. So, I think that's the only way. That was the philosophy around our product.
That's how we've built it. The AI Red Team is at the core of everything we do, but there's a lot of functionality around it to make sure that people know how to prioritize their exposures, and they know how to identify the-- Eventually, what we see in our engagement is that it's less than 1% of the- Yeah ... exposures that actually matter.
The rest of the 99 are maybe important for compliance, but they are not high priority from a security perspective. No, they're not critical, right, where you're going to get owned. Not critical.
Even though they might be critical by their rating, but in the context, when you analyze them, they are not. Well, I think this is another outgrowth of this whole thing we've seen with the Mythos and the vulnerability apocalypse is the whole CVE system that we built, and I remember when MITRE and the whole CVE system started, I was in security. Is it still applicable today?
Because we worry about who's financing it. The US government pulled money from MITRE, and how can they keep it going? But then you look and say, how many CVEs were added as a result of Mythos or these new gen AIs?
Zero. Because I think the whole process is kind of bypassed what we consider- Yeah ... the CVEs and so forth.
And on the other hand, you cannot really do without it. But that's just- No, you need something. We need- The reason is that- Either you got to improve CVEs to take into account what life is today, or you got to put something else in its place.
And my suspicion is what's a critical thing for you, Chen, is not a critical thing for my organization. Correct. But it may be a critical thing for the next organization.
Correct. It's a con- And so how do you change the lens like that? Correct.
So it's a contextual analysis, and that's exactly what we do. The same vulnerability, critical vulnerability, does not mean the same for two different organizations based on context, based on compensating security controls, based on so many other parameters out there. That's exactly why we're able to prioritize and help customers focused on what they need to address first.
It's a better resource utilization because if they'll try to remediate everything, they'll collapse. There's no way they can do it. If you try, right, you try to remediate everything, you'll remediate nothing, right?
It's an old story. Yeah, and it's going to be impossible for customers to remediate everything. So it's important that you can remediate faster, but the problem of prioritizing what to remediate and being able to analyze the dependencies of remediation, all of that has to take place.
That's why you have to prioritize, and you have to make sure that you know what your coverage is for an incident, and to make sure that you can respond faster. And that's exactly what we do. The way we analyze, the AI Red Team is essentially the core of the functionality, but the values come from many angles.
Reducing the exposures as well as making sure you have the right defenses, that you can respond safely. That's essentially the value that we provide, and we're doing it safely, we're doing it non-destructive to the production environment, continuously because this environment changes all the time. We cannot do a point-in-time pen test, and think that you are covered.
And that's basically what we deliver to our customers. Yeah, no, I think, look, it's security for today, right? In today's age.
Yeah. Chen, we're about out of time. I want to thank you for coming on.
security. Go check it out. Look, this AI Red Team is probably worth everyone's time to take a look at what it finds in your organization.
That's the world we live in. It's why we can't have nice things. There's bad people out there looking to do bad things, and so you need a Skyhawk.
Correct. I want to thank you so much. Until we talk again.
Thank you. You bet. Thank you.
We're going to take a break here on Techstrong TV. We'll be back in a minute.
