SEC536: Adversarial AI - Penetration Testing AI Systems

Virtual
Most organizations still fight ransomware with two tools built for other jobs: an EDR designed to catch generic malware, and a backup system designed to survive hardware failure. Both are good at what they were built for. But ransomware operators have spent the last two years building tradecraft specifically to defeat them. Halcyon is the only company dedicated to ransomware resilience.
Drawing on data from our 24x7 Ransomware Operations Center and the Halcyon Ransomware Research Center, this session walks through five ways attackers are defeating your defenses—kernel-level EDR kill chains, full compromise in under an hour, extortion where encryption never happens, your own remote access tools turned against you, and AI now operational inside the kill chain—and how to build a ransomware resilience strategy that holds up against them.
Key Takeaways:
*Sponsored by Halycon
Virtual
Rather than discovering entirely new vulnerabilities, frontier AI models pose a massive threat by rapidly chaining existing, known gaps into complete attack paths at machine speed. Because traditional human response and security tools cannot keep pace with this automated velocity, attempting to outrun AI in a legacy environment is a losing battle. Ultimately, implementing a robust zero-trust architecture is what brings global enterprises closest to achieving true, lasting resilience.
*Sponsored by Zscaler
Virtual
Ransomware is the last step in a chain that began weeks earlier. Operators don't need novel exploits — they need a foothold and a path that chains ordinary weaknesses into reach over identity, critical data, and backups. This session walks a real attack path end to end, showing the weakness exploited and privilege gained at each hop. You'll learn why a few chained "medium" findings matter more than thousands of criticals, how proving exploitability changes what gets fixed first, and how to verify remediation actually severed the path.
*Sponsored by Horizon3
Virtual
Virtual
Pending Details.
Virtual
Living off the cloud attacks are on the rise. Executing rapid, cloud-native techniques to escalate privileges, move laterally between environments, and access critical assets, attackers are targeting the cloud more effectively than ever.
This session will focus on a real-world living off the cloud attack case study, analyzing a step-by-step account of the attack as it unfolded from attackers’ perspective.
We will then switch gears and rewind the attack, explaining how effective detection and response methodologies could — and should — have prevented every step of the attack. Defeating these threats requires powerful centralized visibility and control of all cloud environments and resources. Our key takeaways will therefore be tailored to leveraging the best methodologies and tools to take back the initiative and stop even the most sophisticated cloud attacks.
*Sponsored by WIZ
Virtual
Virtual