Inside the Agentic Red Team — Fighting AI With AI
Yigael Berger, Chief AI Officer at Sweet Security, joins Alan Shimel on Techstrong TV to talk about how the new generation of code-aware AI models is rewriting the rules of offensive and defensive security — and to unveil Sweet Attack, Sweet Security’s new agentic AI red team service, now generally available.
Yigael explains how Sweet’s runtime-first cloud security platform now extends into proactive red teaming, why once-or-twice-a-year red team engagements can’t keep up with cloud environments that change weekly, and how Sweet Attack packages what used to be a high-end consulting engagement into a continuous, AI-driven product that produces concrete, reproducible attack recipes — not just dry reports.
The conversation also explores the so-called “vulnerability apocalypse,” the industry shift from vulnerability discovery to prioritization, governance and runtime defense, the realities of token economics versus human pen testers, and what it means for security when AI is both writing the code and attacking it.
Learn more at https://sweet.security
Transcript
Hey everyone. Welcome back to another Techstrong TV interview. I'm happy to have Yigal Berger here on Techstrong TV with us today.
Of course, Yigal is from Sweet, but he'll tell us all about it. Yigal, welcome to Techstrong TV. It's good to have you on.
Same here. Glad to be here. So Yigal, let's first start with you.
People always want to know, well, who's this person talking to us? Absolutely. You have a good background.
Give them your background. Sure. So my name is Yigal Berger.
I am Chief AI Officer at Sweet Security. For many years, my passion has been cybersecurity and data sciences, so the cross-section between AI and securing systems. This has been a field that I've been working on and researching and building products for many, many years.
And basically, this is what I do at Sweet. My role here is to embed AI and all the cutting-edge research and technology of how we can use AI to do better security and to secure AI. My role is to make sure we are using as much AI as we can to make the product most effective.
So this is my background. Good. Go ahead.
Good. In today's world, I think everyone wants to figure out how to use AI most effectively. Absolutely.
I think there's going to be a learning curve. Some of us are using it more efficiently and effectively than others. Some are still...
Look, the important thing to remember is there are some people who aren't even using AI yet, right? And so you may think you're behind the curve, but in the bigger picture, if you're even experimenting with it, you are- Absolutely ... probably ahead of the curve.
Absolutely. Yigal, let's talk a little bit about Sweet, though. Frankly, I remember when Sweet was launched.
com. But for folks who maybe are not familiar with Sweet and the story behind it, if you wouldn't mind, fill them in. Sure.
So Sweet Security is a broad platform for doing cloud security. We basically cover all the elements that you would need as an enterprise, as a company, that has a strong cloud presence. We cover all the pieces that you need in order to secure your environment.
This is starting from discovery of what you have in your environment, understanding your full topology. What is your posture? What is configured correctly or misconfigured?
And then deeper into the runtime elements where we collect data from your compute environment, and we can tell you exactly what is de facto happening, not just in theory what is misconfigured, but what is actually happening in your environment, and I mean malicious activity or potential hazardous type of activity that is happening. Our runtime approach allows us to see things in real-time, respond to them quickly. So this is cloud security as a whole.
But one of the areas that we doubled down on, and starting really covering that area and providing security solutions for that is, of course, AI activity in cloud environments. So companies that now want to deploy AI in all kinds of shapes and forms, homegrown agents, or many other types of workloads that they might want to run in their cloud environment, and they are AI-driven. There is this new attack surface that is forming.
A lot of security solutions are needed, and we are strongly there. So as a very broad introduction to the company, our core mission is securing cloud environments from 360 degrees. Love it.
I don't think we mentioned the website, though. Just before we go further, for people who want more information, how can they get it? security.
security Just like sugar. S-U- Exactly. All righty.
Just like sugar, just without the calories. Okay. Sans calories.
Yigal, so big news out of Sweet is you guys just launched something you're calling Sweet Attack. Yes. And, no, it's tied in.
Look, we'd be negligent if we didn't mention that with the whole, not controversy, but all of the discussion going around around Anthropic's Mythos. Exactly. A lot of people are looking at is how is that changing AppSec?
How is that changing vulnerability, scanning, of reporting vulnerabilities, fixing, remediating? Right? There's a lot of talk up and down.
Sweet Attack is in some ways tied into it, response. Absolutely. Tell us about it.
Absolutely. So one of the things that Mythos is doing, aside from being a very, very powerful model with which you can find vulnerabilities in source code, or you can find various attack path, aside from that, Mythos is changing the mindset in the industry. Executives, now, it's much simpler for them to understand they need to act differently.
So security is changing. The landscape is changing, and one of the things that has become clear with models that are as strong as Mythos, one of the things that you need to do if you want to understand whether your environment is protected is to do this red team exerciseSo traditionally in cybersecurity, when you are a more advanced organization, you would hire some kind of a red team service to come in. They would do it once a year, twice a year, maybe, if you're super advanced.
And this is a group of experts that would survey your environment, scan every possible door, and try to see if they're able to get in or not, and give you the report. With AI, especially with the super strong models that we now have access to, similar to Anthropic's Mythos model, this whole process is becoming very fast, effective, and relatively cheap. So, this is our launch.
We packed this, what used to be a service, a very cumbersome service. We packed it into an automated process powered by models that are as strong as Mythos, and we will use Mythos as well in our back end whenever that model will be allowed to use it broadly. But there are already models out there that are as strong as Mythos.
5. We are using those models in order to provide you a red team service, an agentic red team service. And it turns out that this is extremely effective.
So just broadly speaking, this is the launch that we have made, this product that is giving you the red team agentic product. And customers that have started using it absolutely love it. The results are phenomenal.
I love it. Just a couple of points. You mentioned cost.
Well, I've seen some surveys that says using Mythos-like tools, the token cost versus the cost of human red teaming, human pen testing, may not be necessarily a hell of a lot cheaper. But what it is, you can't beat the scale. This is twenty-four seven, just grinding away, assuming you have those kinds of resources you want to put into token, right?
And I wouldn't be surprised if bad guys, much like what we see with crypto mining, wind up mining, zombieing others' laptops to burn through token usage, to run Mythos-like pen scans to find vulnerabilities. " So it's almost using, and I'm assuming SuiteAttack uses some form of AI, so it's using the AI to defend against the AI. Absolutely.
So of course, we are harnessing all the latest cutting-edge models that are Mythos grade, in order to do this scan, in order to do this exploration. And of course, we are also providing the means to remediate and mitigate and to provide security, like the tripwires, that whenever someone else that is actually malicious, not friendly like us, whenever a malicious attacker uses those models in order to breach your organization, we have all the tripwires in place so that you can know, react, and fix the issue. But we are absolutely using for SuiteAttack the cutting-edge models.
And so I absolutely agree with everything that you've said just now. Plus, I want to add even more. We are used to having red team once per year, twice per year.
Now we are rolling it out as a continuous service because your environment keeps changing. Scanning once or twice a year, not good enough. Your environment is dynamically changing, and more and more frequently, you're adding, you're deploying AI services.
Every week something new comes out, and companies want to play with that. So your environment is changing. You want something continuous.
And this is exactly the way that we are packaging this product, this service. It will continuously learn and traverse your environment and tell you exactly where your weak spots are. And this is not like a dry report.
This is actual payloads, actual recipes that you can use on your own. Our customers can use those recipes to try them out and to see with their own eyes that here is a method how you can breach your organization without knowing any password or using any kind of means that are not available to any attacker. So this is, you get the recipe, and you can see it for yourself that this works.
And our engine does this continuously. So Yigal, one of the things, though, that we're also seeing is people are calling it the apocalypse. The vulnerability apocalypse.
While I get the importance of it, and I understand marketing as well as anyone else, I think it's also important to remember that this is not an apocalypse per se. Yes, there's going to be a rough time. Yes, we need to adjust to the new scaleOf vulnerability discovery.
And for us who've been in security, like you and the folks at Suite and myself, for a long time, not our entire, but a good chunk of our resources was set aside to discover vulnerabilities. Now, with the advent of these AI tools, the emphasis is no longer necessarily on discovering vulnerabilities, but it's on governance, it's on defending, it's on remediation. It's on awareness.
It's not a subtle shift, moving from vulnerability discovery to vulnerability defense. Absolutely. And I think that's why tools like Att&ck are so important.
Absolutely. It's also about prioritization- Yeah ... having a smarter prioritization.
You're not going to be able to fix anything. And again, the next wave of AI will help you remediate things faster. But for the short term, the next year, it's going to be ever more about correct prioritization, knowing what to focus on.
Absolutely, and it's a shift. But that's something... Look, I started a company, we were selling vulnerability management in 2003.
Mm-hmm. It was all about prioritization there, too. Exactly.
What's going to give you the most bang for the buck in terms of your remediation efforts? But along those lines of us being in sort of this no man's land, an intermediate phase- Yeah ... that's something a lot of people have been talking about, too, because ultimately, excuse me.
Ultimately, the hope is that this will result in us putting forth more secure code. Once we get up to this scale, once we put these kinds of testing, shifting left into our development pipelines and so forth, the code we release should be more secure because it has been tested and put through this fire, if you will. So, the question is, the medicine works, but the patient, or the operation was a success, the patient died on the table.
Absolutely. We've got to get through to that. Yeah.
There is light at the end of that tunnel. Yep. So, I absolutely agree with you.
Code is going to be released in a more secure way. Yeah. But this is human-written code.
Another wave that is happening at the same time is that the entity that is writing the code is not necessarily humans. In most cases, it's going to be more and more that the AI is writing the code. And right now, it is writing secure code, but not secure enough, and not code that understands the whole environment and understanding what is secure for your specific environment.
And the bar is lower in the sense that now many more people are developers. They're writing code, not directly, but so much more software is now being written, and in the coming year, and maybe several years, on the order of magnitude, more software will be written. Some of it is not going to be secure, or at least not at the beginning, but the change will come.
And in a few years, code will be perfectly secure. But until then, people like us here at Suite, we have a mission to make these environments secure, and it's a huge challenge, and we're up to it. And we're fighting AI with AI.
So AI writing the code, maybe not secure enough, and we're using AI to come in and make sure that you're running it safely. Love it. Yigal, we're about out of time.
security doc. Or excuse me- Dot security ... security.
Can find it there. Suite Att&ck is out and available right now? Correct.
It's GA. Absolutely. Perfect.
Hey, keep us posted. Keep up the good fight. We're going to need you- Yeah ...
in the coming months. And come back soon to educate us here on Techstrong TV. Alan, this was a pleasure.
Thank you very much. Always. Yigal Berger, Suite Security, here on Techstrong TV.
We're going to take a break. We'll be back with more in a second. Standby.