Menu

  • Home
  • Latest

Categories

  • AI
  • Automation
  • Cloud Computing
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Uncategorized

Subscriptions

  • Bill Mew
  • Dez Blanchfield
  • Swatantra Kumar
  • TechTV Live
Vidnion
  • Home
  • Categories
    • AI
    • Automation
    • Cloud Computing
    • Cyber Security
    • Data
    • Digital Enterprise
    • Infrastructure
    • Mainframe
    • Supply Chain
    • Telco & Mobile
No Result
View All Result
  • Login
UPLOAD
Vidnion
No Result
View All Result

Cyber Alert: Hackbots and Agentic AI

32 Views
7 months ago
0 0
0
Share
Twitter Linked In Facebook
    TechTV Live TechTV Live
    0 Subscriber

    00:00:02
    [Music] [Music] Hello and welcome to Tech TV. Um, I’m back uh with my colleague Pete Warren and today we’re just going to be talking about Agentic AI. Now, Pete, tell us a little bit of Agentic Eye AI and explain who it is that we’ve got to join us today in terms of a special guest. Well, the idea behind a Gentic AI is uh it’s it’s an evolving one. I mean, it it’s essentially that the AI itself in a sense has a certain amount of identity within the AI. system and it can have permissions that

    00:01:04
    are allocated to data or to particular things that are actually happening. and we’re going to be speaking to Andre Batista who is uh he’s heading up a conference in Portugal and um he’s talking all things AI and all things uh computer security because computer security is one of the things that’s really gone missing in this entire dialogue about AI because if you’ve got poor data if you were using AI to attack systems then we’ve got a real problem with AI. Andre, welcome.

    00:01:41

    Hey, it’s good to be here. How are you? >> Yeah, very good. How are you? >> I’m good. I’m good. >> Now, Andre, this I mean I I I’ve been told some glowing things about you. I’ve been told that you’re the Cristiano Ronaldo of Hacking Eagle. Uh but and this is something that you’re particularly um interested and keen to get the message out about. go on and tell us. >> Yeah. So, thanks for that was a a good intro about uh Agentic AI. So, yeah, I’m

    00:02:14
    I’m Andrea. I’m a ethical hacker. Uh some newspapers called me actually Cristiano Ronaldo of cyber security. I didn’t name myself like that, but I’m from Portugal and I I I’ve been working with organizations worldwide to find vulnerabilities basically, but on the good side of of the history of of information security. And you’re right, security is really important especially in the age of AI because um we with AI and if we forget a bit about uh uh cyber crime itself and we focus more on

    00:02:49
    information as AI being available to like pretty much everyone uh we are witnessing more misinformation than than than before because it’s really easy to fake videos for example. uh it’s really easy to create these deep fakes to create very convincing te texts and and and stories right and that’s also related with information and the security of the information but I’m more focused on cyber security right it’s more about uh the AI threats to the security of the systems we depend on

    00:03:22
    today and to make sure that they are resilient and that they they are uh as much secure as possible by finding their vulnerabilities basically Okay. So what are those threats? I mean my reading of this is that if you can use aentic AI to do penetration testing, if you can use AI to be a cyber threat, you’re going to very very likely to be a big player in cyber crime, which probably will mean that you’re probably going to be a nation state. >> That that’s not very accurate. It’s more

    00:04:00
    like there’s a good side on offensive security, right? So uh what we do is that we do ethical hacking and uh it’s true that even cyber criminals, nation states and so on are also using AI and there are reports for example from trend micro that report this this year and also chief information security officers are really aware that this is having an impact on their organizations for example and there were reports as um we are we have been witnessing attacks happening like around 20 minutes after

    00:04:37
    disclosure of a new common vulnerability that may affect a lot of systems. Um so what we try to do is to be on the good side of things. We still do hacking but we do hacking without damaging any system. We do hacking until a certain point so that we can find those vulnerabilities and then if the organization patch them as soon as possible and is able to prioritize them then they’ll basically get act in a heal way before the bad guys do it. And that doesn’t replace the defensive security

    00:05:11
    which is more related with detecting these vectors as they happen. But we should also apply uh and e ourselves before the bad guys do as well. And that’s something that we basically work on. And we are also combining agentic AI to be able to scale this technology to be able to scale what uh pentesters uh can can do because in my opinion we are late into fixing these vulnerabilities and maybe soon we won’t be able to trust the internet and that would be really bad. But that’s the problem with so much of

    00:05:48
    this, isn’t it? That what is happening at the moment is there is an erosion of trust that’s generally occurring because of this. And you’re suggesting a world where, you know, somebody finds a hole and somebody instantly rushes out to try to plug it. It’s almost like a little boy putting his finger in the dam, isn’t it? I mean it’s uh it’s all about finding these open windows that we we can we can basically do a correlation with buildings. All right. It’s like there

    00:06:18
    are these buildings uh that are invisible in the digital world and those are basically applications. Those can be even vioded applications these days right and they have windows which uh basically can contain vulnerabilities right and some are open and some are closed. Our job is to uh make an ethical uh work to make sure that we find these open windows with proper authorization. And that or authorization can come from defined policies with by county bounty uh programs for example or they can basically and a lot of companies are

    00:06:55
    actually um uh hiring these kind of services or platforms to make sure that they are doing a continuous pentesting to improve their security posture 247. Andre, there there’s one question that everybody will be pondering about and they’ll be pondering about the they’ve been pondering about this for decades and that is why can people keep on finding holes in the code? What is wrong with the code be if you can carry on doing this? I mean, we’ve seen the attack against Jaguar Land Rover, which

    00:07:29
    everybody’s feeling quite badly in the UK, but we’ve also seen the the the attack on all of the um airports. this is beginning to be destabilizing. Yeah, I completely agree and it’s a it’s a shame that it’s it’s happening and affecting the availability of systems that we really depend on as a society like even in Portugal we also add uh where I live like we also had major disruptions multiple times and it’s it’s it’s a trend and uh I think I hope it doesn’t grow more than this because we

    00:08:03
    are trying to fight it every day and we are trying to fight fire with fire we are basically as the AI scales for the criminal side, we also try to scale it to understand if we can keep up and and be ahead of of those threats. But when you talk about the code um and you mentioned like what’s the problem with the code um it’s just how it works and it’s just how security works in general. Um and and and and basically as if you have sufficient code there the vulnerabilities will also exist because

    00:08:36
    we all make mistakes and even if the code is written by a human or if even if it’s written by AI these days because like around half of the code at Google is already written by an AI for example. Um we all make mistakes. We have uh and it’s human to make mistakes and machines also make these kind of mistakes and it’s just how it works because uh we cannot achieve 100% security. Uh there’s always a vulnerability that may exist in the code. What we can do is one to try to find as much vulnerabilities as

    00:09:12
    possible to make it really difficult and almost impossible for a sophisticated actor to find those even with by using AI tools to to also do it by doing it first. And secondly, we you know on the blue side uh of things on the blue team side of things we should also be able to detect these new threats. We can also leverage AI for that. There are multiple solutions that actually try to detect new vectors as they happen so that organizations can be safer these days. Both public organizations that we depend on as a

    00:09:45
    society but also private organizations that we also depend these these days for our daily life, our daily jobs. And uh we are on a mission to try to prevent this or to minimize the impact as much as possible if that makes sense. >> Yeah. I I I just like to ask, you talk about the fact that there are always going to be vulnerabilities. Is it the fact that programs and applications are now so large, so bloated, that it’s impossible for a human being to actually go through all of the code for many of

    00:10:20
    these large applications and programs? And that we need AI and Agentic AI to be able to find these vulnerabilities. >> Yeah. As code grows and nowadays code is growing a lot because or teams are faster like what one programmer can do with the help of these AI tools uh it can do the work of maybe 10 or 20 people right because it has a co-pilot behind him like to to give him speed so we are building software faster and that will increase the attack surfaces of the organizations right so obviously we also

    00:10:58
    need to be able on the analysis side of things uh to understand that we should also use these kind of tools to scale what we can do and to be able to analyze and test uh a larger portions of code. So basically we need to keep up in terms of security. We need to keep up with the technology and the the building side of things to to find the balance because right now uh it’s it’s getting a bit unbalanced in my opinion. Do you not think that we’re reaching a stage now where to actually be

    00:11:36
    a bad guy is becoming an increasingly bad thing to do because given the fact that there is now such dependency on the code, so much dependency on the internet to be interfering with these large code models as Bill has just talked about is potentially not just irresponsible, it’s extremely dangerous. You could really create an absolute nightmare. Yeah. So basically um the and I was mentioning that in the beginning as AI is basically able to to analyze and to find vulnerabilities and even launch

    00:12:21
    attacks and if that is available to everyone obviously that would lead into problems because kids like and I was a kid once right we all were and once uh we start exploring these kind of things we may make mistakes even if our uh intentions are good and we are kids but there are a lot of kids that are still trying to figure out if um uh what’s ethical and what’s not ethical and how we define what’s ethical right and in that sense it’s easier today with agendicai for um kids that start exploring these to

    00:12:59
    eventually you know launch an attack against some some organization right and and that that’s true I I agree with that But we it’s we we must see it as a tool and we must keeping uh uh putting the word out and maybe at schools as well to make sure that kids use AI in a responsible way. Not just about kids potentially launching cyber attacks because that happened already and we have some seen some reports and news uh about that. It’s mostly about uh kids that are creating for for example

    00:13:35
    defects of their colleagues and we have seen some reports on that and it’s everything related with the the AI usage and on the AI model side there has been sufficient work or it’s still a work in progress uh uh let me correct and to make sure that these models cannot be used for bad purposes right to ensure proper guard rails to ensure that these models um do not perform perform uh actions that are not ethical and that’s a major area of concern for the biggest players in in AI right now.

    00:14:10

    And I I believe that you’ve created a hackbot um that you’re using to fight in a AI powered uh uh environment um to take on the attackers and that you’re speaking at a large event in Portugal. um tell us a little bit about this hack hackbot and how it works. >> Yeah, sure. So that’s the the main technology we have been researching uh at Fiac and it’s basically working as an agent that helps uh human pentesters uh to do their job better uh in in terms of our research internally to find uh

    00:14:50
    vulnerabilities in in systems. In the beginning, we have an engine I mean without mostly any AI uh doing these kind of continuous analysis and we were able to find vulnerabilities before the bad guys and organizations that are our customers basically were able to to patch them. But then we moved on into developing hackpots and hackpots are basically agents that can be both co-pilots or fully autonomous and they will be running over the applications simulating what uh an ethical hacker like me would be doing while approaching

    00:15:25
    a target on on a pentest job. Right? So the the difference uh between Hackbot and um uh traditional scanner that uh is already um have been in the market for for quite quite a while uh is that it it has context and it can try to think and it can be trained to think like a hacker, right? Like a ethical hacker in this case because we must ensure guard rails for for this technology to make sure that it behaves in a in a safe manner. So the the idea is that it it’s it’s better than a scanner, but it’s

    00:16:04
    there’s still a gap between what a hackbot can do and what a human can do. And the difference is that a scanner uh may be scanning, for example, a online shop, for example, uh from uh an organization and trying to find vulnerabilities to report to the to that organization. And the difference with the Eggbot is that the Eggbot knows that that’s an online shop. So it may try to find a vulnerability specifically on the checkout flow from the online shop and that changes the game and that allows us

    00:16:34
    to find the vulnerabilities that we should have already found to be more secure in the the digital age uh especially with AI enabled attacks. >> Okay, I’m going to be a little pedantic about this because obviously it can’t think. So what you’re saying is that it emulates the thinking of a hacker rather than uh because I think it’s very very important to to to make these distinctions because otherwise people get the completely the wrong idea about AI systems. Now I one of the other

    00:17:06
    issues about some of this too is we’re running into a situation with these bots uh which is also potentially dangerous. It was noted a couple of weeks ago that um pro-Trump bots had started to fight each other because they’d got different agendas. So, one bot had been programmed to actually uh push a um an Epstein dialogue because it wanted to actually raise that issue in the minds of people. And then a a latterbot had been programmed to try to take Epstein off the agenda because it was no longer in

    00:17:48
    the interests of many of those people who were pushing that political uh strand of thought. And so the bots started fighting each other. Uh we could get into a position if we’re not careful with all of these bots running around the internet that we don’t know what they’re doing at all, couldn’t we? >> Yeah, that’s super interesting. I didn’t know about that story. Um it’s um it’s definitely very concerning and in my opinion these kind of bots and I mean in general controlling and that’s more my

    00:18:20
    opinion outside of my daily work and using this kind of technology to manipulate the opinion of people is should not just be done like it cannot be done in my opinion um because I mean one thing is good influence right it’s it’s trying to push and try to show that we can do the work and we can you know uh we have our ideas and we we are in a democratic discussion about those ideas. Another thing is to push these agendas through um uh by leveraging AI technologies and manipulating people and

    00:18:59
    and and not telling the truth and not being factful and that’s uh something that in my opinion is is completely off limits with this with this technology. So I agree like we can this is not new like we have been seeing these kind of things in the past even without agentic AI right and we have seen scandals like you know Cambridge Analytica and like all the political stuff and now with AI this is even crazier and and uh I think that it’s not going to change any soon. I just think that people need to

    00:19:30
    understand that they need to be uh more careful about analyzing the information that they’ll they’ll be receiving and not buying stuff instantly, right? Not buying this news um instantly. Um so yeah, it’s not it’s not an easy problem. misinformation is classified actually by the World Economics Forum as one of the most uh problematics uh uh questions for for the next few years and and that’s even uh a bit worse and and more ranked in the World Economics Forum report from the beginning of this year uh when

    00:20:02
    compared with cyber crime and cyber warfare which is also a huge problem right we cannot having or afford our systems to stop right but yeah we we are trying to like fortunately like uh companies not just like mine but also other organizations worldwide are trying to fight this problem and I just remembered in terms of misinformation and maybe I’ve seen it uh I think that LinkedIn already already included that in some posts which is attribution with content credentials and that’s a joint

    00:20:31
    initiative from Adob and and other organizations worldwide that basically try to create a standard for multimedia content online and the idea behind it is that when you see a content you can try to and we can you can And it’s signed uh digitally like we sign uh with with IDs these days and we make a mathematical proof that we are the authors over that video for example or that image and you can see potential alterations or modifications to the content. It’s a super promising technology that may help solving these

    00:21:04
    kind of issues in my opinion. Well, that inevitably drives to the next part of all of this, which is we’re rapidly getting to the stage where we need some organization like the United Nations to get involved in all of this. We need something that drives this ethical debate because it’s dangerous to interfere with technology when it becomes something that everybody is depending on. We’re talking about the oxygen of the metaverse of want of a better expression. We’re talking about,

    00:21:39
    you know, the the the the stuff that runs the world that we’re all now heavily dependent on. And so, as well as this ability to be able to interfere with the code, we’ve got to really drive this ethical message into people, haven’t we? >> Yeah. Uh, definitely. And uh one of my one of my jobs in the past few years or goals is always uh about de demystifying the the hacker world. Originally the hacker term wasn’t a bad term. Um and and hackers were just uh tech curious people and that were trying to improve

    00:22:21
    technology and try to to understand the depths of technology and that were passionate about it and all of a sudden like the term rapidly evolved and now when we heard about the word hacker we instantly say oh it’s it’s a bad thing right and I’d rather call the people that use this kind of knowledge to to to do bad things to to steal from people from organizations to blackmail to damage systems and so on the crackers and that’s the term that we prefer in the usually in the in the security

    00:22:56
    communities um in in the in the world there are the white hats or the black hats I don’t like that definition so much for me there are the hackers the good guys and the crackers which are the hackers that should not be hackers in the first place in in my opinion but it’s important because and getting back into the kids topic that we we we were discussing before. And and the idea about demystifying this concept is that if kids know that they can use these skills that they may be developing early on on their lives to do

    00:23:28
    good things and that they’re they have a very important mission which is to protect the internet the metaverse that we were describing Peter I think that or I’m pretty sure that they’ll they’ll think okay I’ll have a potential career in the future when I’ll be an adult working on these on these on these industry and trying to contribute for a better internet for a free internet uh that we can trust basically and obviously with some rules so that we can understand okay what’s real and what’s

    00:24:00
    not real in in that digital world. Now, now the h the hacker bots that you talk about are obviously a big stride forward and it really helping the work that you do, but this is the kind of technology that could just as easily fall into the hands of the crackers, the the people on the wrong side of the fence. Um, and therefore we’re probably looking at a a cyber AI arms race where they’ve got two different camps using very similar technology to try and automate and improve their ability to either detect

    00:24:37
    and exploit vulnerabilities or to detect and patch them using very similar technologies. Are we seeing an arms race here? And if so, who’s winning? Yeah, there is and the cyber arms race isn’t new, right? And the AI introduced the new tool into into this kind of topic. Uh but it’s not entirely new, right? Because we have seen uh and we if we talk about unknown vulnerabilities in systems, those are known as zero days. Those had been happening for quite a while. Um, multiple zero days have been

    00:25:14
    used to infiltrate the phones of uh high privileged people to if you remember stuckset uh which was an exploit used to infiltrate also nuclear facility uh uh facilities um uh like almost two decades ago and it’s not entirely new like a lot of countries uh have been developing and stockpiling these kind of you know cyber weapons. Okay. Um when we talk about the AI arms race uh in in cyber security um I have no doubt that multiple uh countries are are working on this right but also uh organizations because in my

    00:25:54
    opinion these kind of uh uh of um things that that we develop like acts or tools that can be used to find vulnerabilities those can be used for two reasons. one which is the good one, the the real uh hacking one is to find vulnerabilities because we want to patch them. The second one is to find vulnerabilities because we want to exploit them for a malicious purpose even in a war context, right? That should not happen. One way is peace and the other way is war, right? So um fortunately I I’m on on on

    00:26:30
    the side that basically believes that this technology is really good to make sure that we are able to find these vulnerabilities and in advance to make us as as strong as possible to avoid that the potential hacker tries to find these these vulnerabilities. Um but yeah like there are multiple companies this technology is is rapidly evolving and uh there are companies working on these uh but I have no doubts that there are some states also working on it. Yeah, I mean that was the uh the the stuckset was the attack on the Iranian

    00:27:06
    nan nuclear enrichment plant uh where it destroyed the centrifuges which were enriching uranium um for use as a weapon where and bearing in mind that the very recently the uh Americans launched a kinetic attack on uh the nuclear arms program of Iran. It shows that it’s still an ongoing thing and that this arms race is in so many different ways becoming part of the geopolitical system. Just going back to one point that you were making, you were saying hackers and crackers. Doesn’t it make more sense to say uh

    00:27:48
    criminals? Because uh hackers, as you said, it was a good term in the early days. It meant somebody coming up with some way to find a workaround on things. One of the problems that we’re having with technology at the moment is one of definition. We did a program earlier in the week where a lot of people were saying the problem with AI is that the definitions are very very loose with regard to AI. Whether people are talking about large language models, whether they’re talking about machine learning,

    00:28:22
    nobody really knows. is still getting lumped together. We need some much clearer distinctions because a criminal is a criminal, isn’t it, Andre? >> Yeah, I’m completely aligned on that. I would say that the cracker is a subcategory of criminal. It’s a cyber criminal, right? It’s a it’s it’s just like how we usually name it inside the the the the ethical hacking communities, right? And we are trying to fight those those forces, right? We are trying to to understand what we can do to to make

    00:28:53
    sure that even if those criminals use uh LLMs or use other types of technology to make agentic actions that are not predictable because these kind of models are now connected with multiple tools and they call function that they can browse the internet they can do a lot of things right. So the possibilities are endless and we make must make sure that we are prepared to to to resist these kind of attacks and if possible to prevent in the first place to make sure that we do analysis like when we go to the doctor right we one

    00:29:29
    thing is to make analysis on ourselves right the other thing is waiting for the the disease to come and then we it’s going to be more complicated for us and the same applies to the digital health Right. In in my opinion and uh some of these questions are really important topics that we have been discussing in a conference that we have been uh organ we organized the first edition this year aka uh in in Lisbon when we discussed basically about hacking AI but also AI powered by ethical hacking. So it’s both

    00:30:03
    about trying to assess the security of AI systems but at the same time trying to understand how can we use AI to improve security both defensive security and offensive security to try to understand what are the latest trends what are the latest problems with the the models and that’s something that we are planning to organize every year now at Ethiak to to make sure that we have uh series discussions and and talks on the topic that are focused not on selling stuff for example like there are

    00:30:37
    a lot of conferences for that. This one is for discussions and has been for technical insights on on these topics that really matter and and concern all of us. >> Andre, thank you. I mean you’ve underpinned the crucial need for ethics in cyerspace and how we’re going to really have to reinforce this. >> Thank you. Yeah, thank you so much. >> Thank you for joining us and I hope uh your event goes well not only this year but for the years to come. >> Yeah. And I hope you’ll join soon.

    00:31:16
    [Music] [Music]

    Category: Uncategorized
    Next Post
    Cyber Alert: UK Digital ID Card Proposal

    Cyber Alert: UK Digital ID Card Proposal

    Recommended videos

    Adam Mayer, Global Products Marketing Manager – Qlik ( #QlikWorld2023 )

    23 Views
    April 14, 2024
      Heads Up: News Roundup and How Can We Power the AI Buildout? – #AI #power #datacentre

      Heads Up: News Roundup and How Can We Power the AI Buildout? – #AI #power #datacentre

      110 Views
      March 2, 2026

        #Sibos 2018 – Amazing Conversation With Andrew Mead on the IBM Pavilion

        36 Views
        April 14, 2024

          Commvault Metallic

          29 Views
          April 14, 2024
            Show More
            vidnion.com

            © Sociaall Inc.

            Navigate Site

            • Home
            • Privacy Policy
            • Contact Us

            Follow Us

            Welcome Back!

            Login to your account below

            Forgotten Password?

            Retrieve your password

            Please enter your username or email address to reset your password.

            Log In

            Add New Playlist

            No Result
            View All Result
            • Home
            • AI
            • Automation
            • Cloud Computing
            • Cyber Security
            • Data
            • Digital Enterprise
            • Infrastructure
            • Mainframe
            • Supply Chain
            • Telco & Mobile
            • Privacy Policy
            • Contact Us

            © Sociaall Inc.