Black Hat Preview: AI Security and Agent Risk
Black Hat Sets the Stage for AI Security
Alan Shimel and Mitch Ashley preview Black Hat in a special episode of Still Cyber. The conversation looks at how the security industry is changing. AI is moving deeper into software development, cloud operations and daily work. They expect Black Hat to highlight a key question for security teams. Organizations are putting AI into production quickly. Many are still building the governance, identity and risk controls needed to manage it.
AI Is Changing Vulnerability Management
The discussion explores how AI security could reshape vulnerability discovery and remediation. Shimel points to the rise of tools that can find far more vulnerabilities than traditional approaches. That creates a new challenge. Many teams already struggle to fix the vulnerabilities they know about. If AI increases the volume of findings, security teams may need new ways to prioritize risk. They also need better ways to reduce noise and focus on issues most likely to cause real-world breaches.
Agentic Workflows Need Stronger Controls
Ashley and Shimel also discuss the emerging agentic work surface. AI agents can interact with cloud platforms, data stores, code repositories and business workflows. That makes identity, access control and least privilege more important. The hosts argue that organizations need to manage AI agents more like human identities. They also need fine-grained controls that limit what agents can access and what actions they can take.
Black Hat Is Still About People
The episode also reflects on the community side of Black Hat. Shimel and Ashley talk about hallway conversations, reconnecting with longtime industry peers and meeting practitioners who are working through these challenges directly. They also note that cybersecurity is broader than the CISO role. Engineers, analysts and practitioners still play a major role in shaping what products should do and how security programs actually work.
As Black Hat approaches, the episode frames AI security as both a technical and organizational challenge. Security teams need better visibility, stronger governance and more practical controls for agents, vulnerabilities and cloud environments. They also need input from the people doing the work every day.
Transcript
Hamena, hamena, hamena. Hamena, hamena, hamena. " I'm Alan Shimel.
And I'm Mitch Ashley. And this is a special Black Hat edition. All right.
But I'm-- Mitch- Any excuse to put on the glasses and the hat, huh? Any excuse for me to dress up, I'm good with, man. Are you kidding?
A little cosplay- So Mitch, we're- ... for Black Hat. We're on our way back to Black Hat.
Brings back so many memories. Oh, too many. Some we can't tell, some we can, this is for sure.
Hey, what happens in Vegas, stays in Vegas. Most of it, anyway. Except that time I brought the virus home.
This is true. Not that virus. This is true.
This Shredder virus. Yeah. No, but well, yeah, there was the year of COVID, but no, I'm going back to 2005, Mitch, when I got hacked.
Oh, that's right. Oh, that kind of virus. Yes.
I don't- Yeah ... know how I remember that. That was your Hotmail account days, wasn't it?
Yeah. No, yeah, it was my Hot... No, it was my Gmail.
Your Gmail. Okay. Shimmy@Gmail.
I lost control of that account. But once they got that, they got everything. Yeah.
Hotmail. That was- Yeah. It was bad ...
that was a process to undo all of that. That was a mess. It took me almost 10 years to get ASHIMMY@Gmail back.
Oh my God, you're kidding. Wow. Okay.
Well, I'd given up on it, and I started another Gmail account, but I eventually got it back. Anyway- Oh, good ... but it is another Black Hat, Mitch.
It's not at Caesars Palace. No. Not like the good old days, but it's been at- Nope ...
Mandalay Bay for quite a while now, so. Yeah. No, it's been there a long time.
And you know what's surprising to me, Mitch, though? So RSA's about 40,000, 45,000 people. Mm-hmm.
Black Hat feels big, but when you look at the attendance, it's only half the size. Mm-hmm. Yeah.
20,000 is still good-sized. Maybe it's not- Oh, it's a big... Yeah ...
the sprawling, what RSAC is, but. Well, that's the interesting thing. The show floor probably is not as big as the RSA show floor.
Mm-hmm. But it's a big show floor nevertheless. Mm-hmm.
And from what I hear, talking to security vendors, it's actually more expensive, I think, than RSA. Really? Interesting.
For show floor space. Ouch. Now, San Francisco has other costs built in with the unions and all that.
I don't know. Mm-hmm. But I'm just glad I don't have to write a check for that anymore.
That's it. People would be ashamed if they knew how much those big booths cost. Yeah.
You could buy your house for some of them. No kidding. Well, not the way housing costs today, but that's a whole another subject.
Used to be. Yeah. Mitch, but let's talk about Black Hat this year.
You'll be out there along with Fernando Montenegro from- Yep ... Futura. We'll both be there as the analysts covering the space, of course.
Absolutely. I will be out there with a video crew as well, and we'll be covering that. I think we have some writing contractors covering as well.
Excellent. What are you expecting from Black Hat this year? Well, just like you in your capacity, I keep pretty well touched with what's happening on the security vendor side.
So I think a lot of it is I'm planning on... Yes, I have a lot of meetings, meeting with vendors, et cetera, but I'm going to do more hallway conversations because I really want to get a pulse of where the end users, where the practitioner, where the security engineers, where their heads are at. Right?
Because we talk so much about AI being adopted and that rolling out through the software life cycle and into security, and I'd like to get a much better feel directly from the folks that are living the dream or not, and where they're at. I think the other theme, and this comes out of the research and the data and all of that, is we're putting AI in production, but we don't have the governance in place yet for what we really should have. " It's very much on the table, and the investment is there.
People are planning investing on security for AI. But what kind of challenges is that causing, and what's that going to swing in terms of the vendor announcements, if at all, that are going to happen at Black Hat? So those are two of the flavors, amongst others, for sure.
Absolutely. For me, Mitch, there's two big trends that I want to really dig in on while I'm at Black Hat. One is, is this Mythos stuff real?
Hmm. Right? Not that I doubt it's real.
I know it's real. I know it's finding vulnerabilities. We see the amount of patches being distributed, released by people like Microsoft.
I just did an article on this, how many. Microsoft, they used Mythos internally, and I forgot what the number was. It was a God-awful number- Hmm ...
of vulnerabilities they found. But it's reflected in the amount of patches. Google, Oracle, Microsoft, all of them are releasing hundreds if not thousands of patches now You can't tell me that's not a result of Mythos.
Well, it seems we've gotten to the era of, we all run lots of different software between our phones and our laptops, et cetera. Something is being updated every day, always. There isn't a day that goes by, is it like, no machine needs updated for this.
Microsoft needs updated for this. All the apps that you buy from the App Store, here's half a dozen that now need to be updated. So, I always talked about software is like water, right?
It's fluid, it's not constant, it's not a solid. And this is living that. We're living in this very dynamic world where it's all changing- You're right ...
at the same time. Well, but here's what's changed, though. Mitch, I did an interview right before Black Hat with Jeremiah Grossman and Robert Hanson, RSnake.
Mm-hmm. So their Rude Evidence company's officially launched now. It's a new entrance in the vulnerability management space.
Mm-hmm. And Jeremiah, Jer has had relationships with the cyber insurance industry for a long time. Yeah.
So they're giving you warranties that if you get breached after using their stuff kind of thing, and you followed their suggestions, they got you covered. Right. But, it's interesting to me in that we were talking about the good old days.
Mm-hmm. Right, Mitch? I think you designed VAM, what, in 2003?
Yeah. About then. Vulnerability and Access and Management.
Yep. Assessment and Management, excuse me. Been a while.
But that was 2003, that was 23 years ago, Mitch. Mm-hmm. 25 years ago.
The Dark Ages. Yes and no. Up until this latest thing with Mythos, has a lot of it really changed?
We still scanned, generated bad news, and gave someone a library, a phone book of vulnerabilities to fix, and we were never able to fix- Mm-hmm ... all the vulnerabilities we found. Even back then, before Mythos.
We were never able- Bad News Generator, remember? Yeah. That's what they used to call it, because that's what it was.
Mm-hmm. But now with Mythos, you got 10... Again, I want to verify in talking to people myself, but if you're finding 4X, 6X, 10X the amount of vulnerabilities, and you couldn't fix or remediate what you had before this, something's got to give.
Are we creating a backlog of updates that aren't being applied, or is it that- We already had a backlog. Exactly. We're creating a- Are we building- We're creating an avalanche situation, I think.
Mm-hmm. Where one little tremor and this all comes on down on our heads. Think of the interdependencies of these updates.
Well, how do I know this doesn't affect eight other things? Now it's 20 other things. How do I verify that?
Can you even verify that? Or you just kind of spray and pray, release stuff and hopefully nothing breaks. I agree 100%.
So I think that, let me return to this Jeremiah and Robert. 4% have actually ever caused a breach. Mm-hmm.
Comes down to about 600 vulnerabilities. Hmm. And if you scan just for those and fix those, your chances of getting breached go straight down.
That's interesting because now you're saying 90% of that, or 99% of the, all the work we're doing is around stuff that's not never going to happen. Yeah. Essentially.
Or you could argue some of that is actually preventing things from happening, just don't know. Well, the kind of question he's asking is how much does that change month-to-month, Mitch? Yeah.
But so here's the thing. They're launching a new company around this. All right.
They're going to shake the industry up maybe. Mm-hmm. I think for the vast majority of people you're going to talk to, they're not buying into that quite yet.
Oh, that's definitely on the edge. Yeah. That's the bleeding edge.
But it's funny, I just watched "Moneyball" the other night, the Brad Pitt "Moneyball," using data and that. I mean, changing the whole game of baseball from just the feel that we had about players and insiders, because we've been around and we could tell, to now the data doesn't lie. There's a lot of truth in that data.
That's kind of that sort of thesis. " And if that thesis proves out, it could have radical impact to the industry. I agree.
It could. I don't know if we'll see that at Black Hat this year. Mm-hmm.
Maybe too early. Yeah, I think it's going to have to work its way through the stake. Yeah.
But so part of what I want to see is how are people reacting? How are they... Mitch, look, I'll go back to when we had IDS versus IPS, when we did safe access, the NAC product.
Mm-hmm. People were not into automated patching or automated- At all ... remediation back then.
No. Now the game has changed. I think what's changed is because of our phones, and you mentioned it.
We're doing updates continuously around the clock, it seems. Most of us stopped paying attention a long time ago. There was a time where I had my phone settings, I had to get notified every time an app wanted an update, and I had to approve it.
Mm-hmm. I gave that ghost up a long time ago. Mm-hmm.
Are we ready to give that up in our enterprise networks? It isn't error-free. I just had two incidents.
And I'm not running big infrastructure these days. Two incidents where one app updated, and it actually did everything it was supposed to do, but it didn't restart the machine. It was needed a forced restart for things to take effect.
All of a sudden, a VPN wouldn't work anymore. Cutting everything off. Okay, what's wrong?
Human intervention. Another one, an app updated, now it crashes. Right?
Why it's crashing, I don't know. Do I need to reinstall? It just causes work.
So there's a lot of automation, a lot of things I don't have to worry about patching, but when it doesn't work, guess who fixes it? Or today, anyway. It's people.
Right. Absolutely. So, what fundamental change does this bring to the security industry?
Because historically, security people didn't actually do the remediation. Mm-hmm. We tested, not even testing, the QA people tested, the help desk people tested.
Right. But we sort of blessed it, if you will- Mm-hmm ... as a security person.
Yes, this needs to be patched. We field-tested it for two weeks, and if IT said no problems, then we, great, roll the patch out. Yep.
Patch Tuesday. So that's going to work its way through. There's going to be some people who maybe follow this Jeremiah Robert line.
I think a majority of people are going to stick with that traditional vulnerability management remediation loop. Mm-hmm. How does Mythos and the amount of vulnerabilities snake its way through that food chain?
Well, people don't change process, behavior, buying out of kind of willingness that, hey, I just want to change it. This is a better way. Let's think about doing it this way.
Right? There's a cost to change. There's a cost to adopting new innovation.
Sometimes it's very compelling. Sometimes you do it on risk, where we don't know, let's see what comes out of it. But I think there's got to be a compelling reason for, here's what it's going to mean to you.
How much money is it going to save me? How much more secure is pretty hard to justify, but maybe how many fewer incidents you're going to see, how much less testing do you have to do? How much less does your vendors have to do?
Whatever the equation looks like, that's ultimately what sells a company like that is, okay, what's the outcome? Why am I going to spend my money, my people's time, my whatever, to implement something new unless I know it's going to bring something to the table? And what is that?
And do I believe it? Can I- Right ... find out quickly if I'm going to get the value out of it?
So I'm not being as skeptical about what they're doing, but that's what it comes down to. I agree. Mitch, the thing about it is, this affects some really big names in the security industry.
Mm-hmm. Qualys, Rapid7, Tenable, EI. I guess EI is still out there.
I think they're part of another company now. But the whole vulnerability management, vulnerability finding, even on the AppSec side of things, right? Finding vulnerabilities in pipeline.
Vericode, Contrast, Checkmarx, all of those companies. If Mythos is pointed there and Mythos is pointed at production, and finding vulnerabilities is no longer a worthwhile endeavor for humans- Mm-hmm ... what does it mean for those companies?
This is disruptive. Very. Highly.
Yep. I don't need somebody scanning my network, right? Because it already can be done or is being done by a model.
Do I need four different types of vulnerability scanners that focus on code, or the network, or applications, or the cloud? Software composition, open source, and all of this. Now, I know some of them already pivoted, right?
Qualys is going to talk to you about ROC, Risk Operation Center. Mm-hmm. So how do you translate all this into a risk profile and a risk kind of management approach?
The others, I'm sure, also have similar places they're going. But I'm really looking forward to Black Hat to see what that is. Hey, there's one other thing I wanted to talk with you about that I'm looking to see if we see much about, and that is who's securing the agentic work surface, the user work surface, whether they're doing cloud or- Well, that was my second thing.
Oh, it is. Okay. We're on the same page then.
Because companies, Microsoft, Perplexity, you name it, everybody's AWS with Quick. They're competing for that end-user space. It's no longer I spend all my day in email.
I spend all my day in whatever. It's I spend my time on cloud desktop. I spend my time on ChatGPT or whatever the surface is, Copilot for Microsoft.
But who's securing that? There's so much going into it. Now you can pour everything into it.
Yeah, you have some controls of what MCPs can get access to. That doesn't control what you can put into it, right? " Pump that in here.
Now that's in my memory. It's in my working environment. Maybe it seeps into things that I produce that go into other parts of the organization.
So in a way, it's kind of a giant funnel sitting on the desktop that is in a place to introduce a lot of things, maybe some a security risk, some of it's not, but who's securing that? I get it. So, as I said, this was the second thing I wanted to talk about.
These agents need to be secured- Mm-hmm ... in what they're doing, what they have access to. I think if we look at the problem you just highlighted, Mitch, to me it starts with identity.
We've got to start managing these agentic identities like we manage people identity. Mm. Because once I assign a number to you, once I know who you are, then I could say, "Okay, this agent can do this.
It could go here. " All of the same ways we manage-- Really, because when you think about it, IAM was the killer app for cloud security. Mm-hmm.
Right? We didn't have that moat and castle anymore. The only way we could try to control traffic, and we can try to control people and where they got-- the whole zero trust thing is based on that.
Everything is just blacklisted until I know who you are and what you're allowed to do, and then I could open things up. Mm-hmm. I think that's step one in managing our agentic surfaces.
And I think- And I would add to what you're saying, Alan, and maybe you were going to go here next, is some of the vendors are starting to think about this is- I've seen several ... it's identity, kind of think of it as a human, but applied to a digital agent, right? The next step is I need that, but I also need identity of a workflow that happened, right?
Yeah. These are dynamic things. This isn't static code.
You can go, say, from A to Z, module A to Z, whatever. I can tell what happened because all of the things that operate are in code somewhere, in a code base or in a system through a set of APIs. I know what that logical progression looks like and how it can operate.
I don't know that with an agentic workflow. Alan can build an agent. Maybe the agent's got an identity, but maybe it's Mitch's agent that happens the second time because something upstream decides which agent to choose from.
Well, what was that process? How do I pull that back together? What's the identity of that work stream or that workflow?
And there are vendors that are now working at that level of it, too. Yeah, they are. So I call that, Mitch, like fine grain control.
Mm-hmm. Right? Even if I'm going to give you access to a certain workflow, I'm not going to give you access to the whole workflow because you don't need that.
Mm-hmm. I'm going to give you access to these parts of it, to this folder, to this particular thing, right? I think we're going to need that sort of really fine grain control to have a handle on this, because otherwise these agents will overrun us and overrun security control.
Mm-hmm. Right? I'm not even getting into the whole hugging face open AI thing.
That's a whole another story. But if we don't lock this down... I don't think agents are malicious by nature.
I think it's they are who they are. Mm. Not who they are.
They are what they are. Mm-hmm. There's no bad agents.
There's just bad people managing them. Yes. Or, let's say creating them, architecting, building them, and manage them, right?
Because people- Yeah ... are oftentimes the builder, at least today. Maybe that changes to AI's building AI more and more.
Yeah. The other thing I'm thinking about too, Alan, is just my experience with this is there's a lot of leakage that happens between information, like on the agentic work surface between agents. And even though you spell things out for AI in some kind of context or rules or in your doc cloud file, whatever it is, things still happen.
All of a sudden, stuff shows up in these sets of documents that were coming from here. I had no intent. Matter of fact, I told it not to do that, and it still happens.
So there's no guarantee, even though you've spelled out in the upfront how you want an agent or AI to operate. Is there a back end, right? Is there a verification step that has to automatically perform looking at boundary conditions to make sure certain things don't leak out?
Think about proprietary information, right? One minute I'm working on some IP for my company, whether it's code or documents or whatever. Next minute, I'm working on a proposal for a customer.
And all of a sudden, things start showing up in that because the AI sort of forgot what it read at the beginning of the session, and I didn't flip sessions. Right? There's a lot of opportunity for leakage.
I agree with you. And I think that's something that I think a lot of people didn't take into account in the beginning, which is the social nature of the communication between agents. Mm-hmm.
Right? They share secrets. They have secrets.
They have secrets. I don't know. But besides those two technical issues, Mitch...
Oh! Yes. Somebody's arriving home.
Yeah, sounds like it. Mitch, besides those two technical issues, what else are you looking forward to at Black Hat? We don't go to the parties like we used to, let's face it.
But anything socially going on there that you want to make sure to hit? You went there because that was next. That was top of mind is- Well, Mitch, when you do this for 20 years, you start to together, you start to kind of- Yes, that's true.
We have been doing it together for a long, long time. Yeah. And we went to a lot of those parties, most of which I- Exactly ...
don't remember a lot about. But it's still about the social connections, and to me, there are events, of course, that I'm going to. " Now, to me, it's less of that, going to those specific things, and more about connecting in person with people that I know digitally, that I don't know them in person.
Person in real life. That's a high-value action. Reconnecting, of course, with people that I don't know.
We just did a Techstrong... Excuse me. People I know.
We just did a Techstrong gang, and Robert Ruiz was on there. Haven't seen him in a while, and got a chance to reconnect with him digitally. Love to reconnect with those kind of folks in person.
And I think the best ones, Alan, are the hallway bumps, the accidental- I know. The con- Or the team The hallway conferences. Yeah.
We made a living in the hallway, Mitch, back when it was at Caesars Palace. That's where our Still Secure booth was- We did ... in the hallway.
We did. Right. We had our technical briefs and our binoculars and everything else.
But- Kate Skynnerlard was the-- I ran into her at RSAC, and I've been on countless digital- Gangs with her ... Techstrong gangs. I've never met her in person.
It was walking outside the Marriott Marquis, just flow of traffic. " We got to see each other. Those are special moments.
I really value that. Well, no, they're real, and especially, I said I was interviewing Jeremiah and Robert. Look, it was so funny.
The three of us don't have hair. When we first knew each other, we all had hair. But anyway, I'm looking forward.
I'm going to a, I think it's a Night Dragon, they're a VC kind of PE- Uh-huh ... thing, and I'm going to a breakfast of theirs that promises to be good. I'm meeting up also my friend Cindy Velarde, who's been at Cisco, a bunch of places, marketing, cyber marketer extraordinaire.
I'm seeing a lot of old friends, new friends. Mm-hmm. You know what, Mitch?
I got another little personal b***h I want to throw up here. Okay. All right.
This is a good time. This is therapy for you and I, doing this. It's a little cathartic, yeah.
There's a lot more cybersecurity people than CISOs, and we put too much emphasis on the CISOs now in this industry- Mm ... like they're anointed children, golden children. A lot of them don't have any dirt under their fingernails.
They're very good at- Mm ... talking business. And I'm not against CISOs.
CISOs are a great-- The advent of CISOs really helped the security industry. But- Seat at the table, right? Yeah.
Right. " table. And they help in buying decisions.
And they don't get treated-- Like all of these vendors put so much money into CISO breakfast, and CISO bourbon tasting, and CISO this, and CISO that. I've seen old enough CISO. What about the rest of the people?
And if I'm a vendor out there, yeah, I get that CISOs make buying decisions, but don't underestimate the influence of the guy who does the work. Mm-hmm. Well- So ...
there's the front lines, and then, I think, like it used to be, like I'm in the SOC, I'm the engineer trying to figure out- Right ... how to secure stuff. I think we're throwing a lot of new problems on the table that are not a CISO decision, right?
It is, how are we securing the generic desktop? How is it, all the patches, all of that stuff. That's different than incidents and responses and attacks and the things we're normally used to as showing up on the CISOs.
How do I perform my risk management, make sure that I've got things sufficiently covered? Well, we've got a lot of stuff throwing at the organization, not just at the CISO, that have to be done at the worker bee level, let's just call it that. And those jobs have changed.
Not because AI has changed their job, but AI problems have changed their job, if you will, or bringing new challenges. Agreed. I just want to shout out to them.
Another shout-out I wanted to do, Mitch, is I'm registered, and the film crew is, if we get in early enough to shoot over to Las Vegas BSides. Mm. Yeah, I went to the very first BSides- Oh, that's right.
Yeah ... a long time ago, back in maybe 2007, '08. I met Gene Kim at Las Vegas BSides, and that got me started on the whole DevOps thing.
So I registered this year. Oh, Reagan. I forgot his first name.
Oh, he used to be at Dark Re-- Anyway, we're registered. If we get in early enough, I'm looking forward to going over there and seeing some of the goings on. Las Vegas BSides a great event.
Mm-hmm. Anyone watching this, you should head over. It's Monday and Tuesday.
Steve Reagan- Steve Reagan. Yeah ... is the media wrangler there.
So shout out to them. I would really encourage people to go do that too. Good show.
And say hi. Alan and I have been doing this a while, but we're just regular folks. We love talking to people.
Stop us in the hall. Yeah. Chit-chat.
I'm a regular folk, I'm thinking. Yeah. But yeah, I'd love to say hello to people.
I hope I remember you, because you meet a lot of people. But yeah, no, we'll be there. I'll have the film crew walking around with lights and camera.
And look, if you want to-- Actually, I am doing, now that you bring it up, Mitch, we're doing something in partnership with our friends at Teleport where I got five questions I'll ask you. Mm-hmm. And give me a 30-second answer, and we're going to montage that all up.
Speaking of montage, we're going to take all of our Black Hat coverage and some B-roll and sizzle roll and do a Techstrong TV special, Techstrong at Black Hat. Probably run 30 minutes, 45 minutes when it's all said and done. We'll have that edited up and ready to run in a couple of weeks after Black Hat, but that ought to be fun, too.
Yeah. Yeah. I think this is a great idea.
I'm looking forward to that. Sort of the- Yeah ... 60 Minutes of Black Hat, if you will.
Yeah. That's exactly what- Good idea ... it's trying to be.
All right. Hey, Mitch. And then let's commit right now to doing a post-Black Hat, Still Cyber- Absolutely.
We'll bookend it ... after all these years. We'll bookend it.
We'll bookend it. All right, man. I will see you in Vegas.
See you in Vegas, man. Take care, buddy. We'll see you in Vegas, too.
Until then, though, hey, man. How does it go, Mitch? Hamina, hamina, hamina, or something like that.
Hamina, hamina, hamina.

