SEC536: Adversarial AI - Penetration Testing AI Systems

In-Person
AI is not inventing an entirely new attacker: it is instead making existing attackers faster, cheaper, and dramatically more scalable.
This session examines how frontier AI models and autonomous agents are changing reconnaissance, vulnerability analysis, exploit development, phishing, lateral movement, and post-compromise operations.
Through recent examples, including an AI-driven intrusion that generated more than 17,000 recorded actions, we will explore why vulnerabilities previously considered difficult or impractical to exploit may now represent materially greater risk. The presentation will also explain why successful AI-assisted offensive security requires more than a powerful model: it requires a carefully engineered harness, appropriate tools, persistent context, validation mechanisms, and experienced human oversight.
In-Person
In-Person
Most breaches aren't won or lost by firewalls - They're decided in the first hour by who gets called, who makes the call to pull a critical system, and who talks to the regulator. This talk will cover modern incident response and threat hunting from the seat that has to answer for the outcome, in plain language, with NIS2 and DORA as the backdrop. We'll look at how to strengthen every stage of the incident lifecycle — from preparation and detection through containment, recovery, and lessons learned — turning the reporting deadlines NIS2 and DORA impose into an operational advantage rather than a compliance scramble. You'll leave with a clear model of your own risk, the questions to take back to your security team, and enough calm to make the next 2 AM call a lot less dramatic.
In-Person
In-Person