Skip to content
TrackPodcasts
technologyMar 20, 202625:11

When AI Touches Everything: Operationalizing the Five Most Dangerous New Attack Techniques at RSAC 2026 | A Redefining CyberSecurity Podcast Conversation with Ed Skoudis, President of SANS Technology Institute and Founder & CEO of Counter Hack

About this episode

Show Notes

For ten years, Ed Skoudis has curated one of the most anticipated sessions at RSAC Conference: SANS' "Five Most Dangerous New Attack Techniques: Crucial Tips for Defenders." The session has always been a hit -- standing room only on the main stage -- but this year, Ed says something has changed. Not one or two topics with an AI component. All five.

Ed is deliberate about how the session comes together. He starts with people, not topics. He builds the panel around SANS instructors who bring front-line insight, and he starts the process six months out. This year's panel features returning panelist Heather Mahalik, Rob Teeley back for his second year, Joshua Wright in his second year -- this time carrying two topics and eight minutes instead of six -- and, making his first appearance on this stage, Robert M. Lee of Dragos, one of the world's foremost voices on ICS and OT security.

The addition of "Crucial Tips for Defenders" to the title this year was intentional. Ed pushed every panelist to move beyond naming threats and toward prescribing action -- practical, implementable steps that a CISO can hand down and a practitioner can execute the next morning. For topics where prevention is impossible, the mandate shifted to detection and response. SANS publishes session notes to their website within minutes of the talk ending.

The backdrop this year is a warning Ed calls unlike anything in his 30 years of attending RSA and DEF CON. At a recent AI cybersecurity conference in San Francisco, presenters from Google and Anthropic outlined what Google termed the "vuln apocalypse" -- an imminent surge in AI-discovered zero-day vulnerabilities at a scale and pace that patching pipelines are not designed to handle. Ed's own team at Counter Hack has already experienced this firsthand: a frontier AI model identified a critical zero-day in a widely used open source project in a matter of hours. The Anthropic presenter's claim was blunt: within months, AI will surpass all human vulnerability researchers combined.

All of this lands at the center of what the RSAC session is designed to address -- not as a theoretical exercise, but as a set of actions defenders can take right now. The session runs Tuesday, March 24th at 3:55 PM on the main stage, with an interactive follow-on session Wednesday morning where attendees can go deeper with individual panelists. For anyone who wants to understand where the threat landscape is actually heading and what to do about it, Ed says this is the year you cannot afford to miss it.

Guest

Ed Skoudis, President, SANS Technology Institute; Founder & CEO, Counter Hack | On LinkedIn: https://www.linkedin.com/in/edskoudis

Host

Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/

Resources

SANS Institute | https://www.sans.org

RSA Conference 2026 is taking place April 28 - May 1, 2026 | Moscone Center, San Francisco -- Follow our coverage: https://www.itspmagazine.com/rsac-2026-conference-san-francisco-usa-cybersecurity-event-infosec-conference-coverage

The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/

More Redefining CyberSecurity Podcast episodes | https://www.seanmartin.com/redefining-cybersecurity-podcast

Redefining CyberSecurity Podcast on YouTube | https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq

Keywords

ed skoudis, sean martin, sans institute, sans technology institute, counter hack, rsac 2026, rsa conference, five most dangerous attack techniques, ai in cybersecurity, vulnerability research, zero-day vulnerabilities, patch management, penetration testing, defender tips, ics security, ai-powered attacks, redefining cybersecurity, cybersecurity podcast, redefining cybersecurity podcast


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Get every episode summarized

Each time The ITSPmagazine Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

297 searchable segments. Every word is indexed and playable.

When AI Touches Everything: Operationalizing the Five Most Dangerous New Attack Techniques at RSAC 2026 | A Redefining CyberSecurity Podcast Conversation with Ed Skoudis, President of SANS Technology Institute and Founder & CEO of Counter Hack

The ITSPmagazine Podcast

0:00
25:11

Full transcript

The ITSPmagazine PodcastWhen AI Touches Everything: Operationalizing the Five Most Dangerous New Attack Techniques at RSAC 2026 | A Redefining CyberSecurity Podcast Conversation with Ed Skoudis, President of SANS Technology Institute and Founder & CEO of Counter Hack. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Hello everybody, you're very welcome to a new on location, even though I'm a wrote a conversation for RSAC conference. It's the 2026 version. A few conferences have come and gone. This one's coming up around the corner and I'm thrilled to have had scooters on. Ed, how are you? I'm doing great. How are you, Sean? I'm doing well as well and are great as well. This has become a tradition to have a chat with you and talk about all the cool stuff that you're doing at RSAC with respect to sands. This is a session that it's a hit every year. It's a first come first serve standing room only and it's one you don't want to miss and I'm always thrilled and honored to have you on to talk about all the good

stuff you're doing with the team there. I'm always appreciative of the work you do for the for the community. So for folks who I don't know how they don't know you but you're missing your hat by the way. I often don't wear my hat for these kind of interviews. It's a controversial thing so yeah I mean I could go get it but I think we're good. Sometimes I wear a scant ahead around December or sometimes I wear my white hat but yeah I sometimes speak with my hat on but usually not. Right right. Well if they a good chance they might see you at the conference with that but any year we have you we have you without the hat but anyway my point is if they don't know you they should meet you and say hi and for now if you can just tell them tell folks a few words about who you are what you're up to, the work you do, stuff with stands, stands you have going on. Yep so I'm Ed Scotis. I'm the president of the Sands Technology Institute. I've been with Sands 27 years now. I was a Sands instructor for 21 years. I wrote the

number one selling Sands course which is Sands Security 504 on incident handling and hacker attacks. That is associated with a GCI H certification. I also wrote Sands Premier Class on network penetration testing. Sands Security 560 which is the one associated with G Pen. I run the team that build cyber ranges for Sands including net wars as well as our free holiday hack range. In addition to that I also have a company called CounterHack. We build those ranges for Sands but we also do penetration testing. So I have 18 penetration testers who work for me and we work on trying to be the best pen test company we can't be best pen tests in the world is what we're aiming for. So I'm also serving on the board of a couple of charities and our bank, Manisquan Bank, our local bank and it's been great. It's great to talk with you again every year Sean it really is. Yeah I appreciate it Ed and so the purpose of this is

twofold. It's a session that I think folks should attend which is why I love having you on and the content is great which is why it's a good session to attend and the title of the session is the the five most dangerous new attack techniques, crucial tips for defenders and it's that last part that I'm really interested in. The first I'm going to try to squeeze your arm, twist your arm to say what the five are. Well we are under an embargo. Thank you thank you. You know RSA C as well as Sans has a strict media embargo on what the top five are until we're I think when we stand up on stage they have to wait five minutes and then it all gets released because you know we want to build some excitement and want people to actually attend to hear the thing live and hear the questions and answers but I can talk about general trends. I can talk about how we put the panel together and what we take into account. There's just so much going on in our industry. It's super exciting and these four panelists are absolutely brilliant.

They've got their finger on the pulse of where things are headed. It is an honor to you know to be able to host them here. They're all amazing Sans instructors and yeah I just can't go over the specifics. I will tell you this. We have five topics. We got four panelists so that means somebody gets to do two and this year it will be Joshua Wright who is doing. There you go. There you go. Very good. Well let's so much even though we can't talk about the five. There's so much to talk about and where do I start? Let's talk about how how you pull the five together. What what is the catalyst behind something landing on the top five list and so yeah. We I start with who and not what you know it's like you know who's really got some good and interesting things to say. Who can really help people who has access to lots and lots of Sans authors instructors students. I

like to have people up on the stage that you could take a classroom so if you really like them and learn from them you can take a class there. So we go through who and we brainstorm you know who's done it in the past. We try to get some new blood in there but we also like to have some folks that you've seen before and know before. So this year for the first time on this stage with this Sans panel is going to be Robert Emily from Dragos. He's amazing. You're one of the best ICS people in the world. He's got such great stuff to say and people really listened to what he has to say. Rob Teely is coming back. He was there last year he's coming back this year. Heather's been up there about 10 years now with us and Joshua Wright last year was his first year so this would be his second year. So I start out with who and then we brainstorm and we start this six months in advance. So this is about five and a half months ago. Just what do you see and what do you think it may come to me with ideas they bounce ideas off each other. There's a little bit of infighting like your topics too close to mine.

You're stepping on my toes this way that way. How do you massage the topics and then you know this year I did I changed the title up every year a little bit with you know cooperation from our friends at RSA C and you know that that idea of crucial tips for defenders. I added that this year to push the panelists to say look it's it's fun and interesting to talk about attacks but we have to be practical. What are crucial tips that defenders can directly apply? You know we don't want to just say hey here's something for you to think about here's something to watch for. It's what do you do about it? What actions can you take and then I want those actions to be practical implementable so and then also appeal for action orientation across everybody from CISO at the high level to individual practitioner to say not only do I know this thing now I'm asking these panelists to do all of this in six minutes. So we want the problem what the attackers are doing with it how it's evolving where it's headed and

practical tips for defenders that appeal from individual practitioner up to the CISO level that's all I asked for and you've got six minutes and easy task. Yeah so and then we refine and refine and juggle and this and that it heck it was even just two weeks ago that we had two of the panelists talks that were so similar that we had to kind of figure out a way that we could make them individual trends and separately actionable. Also I do like it when sometimes there's contradiction on the panel. Somebody says X somebody else says Y and you might say well Sans get your act together is it X or Y and the truth is there's an argument made for X and an argument made for Y we're going to try to make them at least consistent so you can address both of those right it's it's not fully X it's not fully Y it's going to be some combination of the two but we have an advocate for X and an advocate for Y and I tell the panelists when we're on the stage if you disagree with something someone else says you can respectfully respond to that

it's got to be respectful we're all friends but that makes for great TV and it makes for great you know intellectual because we're a community and we're trying to contribute to the community so but but look for actionable things you can do and I talk with I talk with all these these panelists you know Josh had a topic where he's like this is a really big problem it's really bad I don't have any practical solutions for people on this so it's like okay now we brainstorm what can we come up with what practical people do and sometimes it might be that there's no prevention technique for something but there's detection and response set of actions you could take so yeah we're getting capabilities so you can't stop it from happening but if it does happen here's how you can figure it out there is happening and stop it fast while it's happening so some things are along those lines but wherever we can have a prevention tip and technique we do and in our sac pushes us on that they're like this can't just be you know intellectual naval gazing the people have to come back

with a actionable set of things and I always take notes I tell the audience to take notes we publish a thing with what we consider notes for it at the sans website within 10 or 15 minutes of of the event itself we work hard on this we really do Sean and we want it you know we don't want to take it for granted that we're able to do this every year we've been 10 years on the big stage now we don't want to take it for granted we want it to be practical we want it to be interesting was it Oscar Wilde who said you know the you know the greatest sentence to be boring I think or something like that I'm paraphrasing we want it to be interesting but it's not merely interesting you can be interesting doing puppet shows or something but we want people to have practical value they take out of this all rolled into 45 minutes so so we do take it very seriously work on it very hard and some years it's better than other years I think this year is going to be great I mean to look I've seen the topics I've seen the presentations they they're trying to take it to a whole new level this year

you're going to see some video animation stuff so there's there's the topics which are ultimately what matters the great presenters very important but then there's the sort of production quality of the thing and RSA C they are top notch when it comes to producing a high-value show the team there is incredible you've seen the screen Sean right oh yeah giant screen that I don't know what that costs it it's probably five or 10 million bucks for that screen and then behind this well first of all those screens they throw off so much heat it must require some small nuclear reactor some dam somewhere they just pushes enough electricity because they're hot the technology was probably 10 years old it's pushing off a lot of heat also behind there there's a small city of producers that put this whole thing up and switch in the screens and such and then there's a stage manager who's amazing she's just an incredible person so they run a great show but fundamentally it's the content that matters and that's what we

produce and are responsible for yeah love it and can you list it them off quickly kind of the the flow of the conversation and maybe maybe some yeah some color on top of that to kind of sure help people get a sense of what they see so we've got five topics four presenters and it starts with me for about 90 seconds setting the frame we then introduce each of the panelists each panelist speaks for six minutes there might be we haven't finished this part yet there might be a question from me between the panelists or maybe not so you got panelists one who then goes over what the attack is why it's a concern where it's headed the damages that can be caused and then what you can do about it and and that's at the industry level and the practitioner level to engage a cso down to practitioner so that's one talk six minutes another talk six

minutes another talk six minutes another talk six minutes now don't tell anyone but i got a secret i gave Josh right eight minutes because he's doing two topics right don't tell rob t lee last year i he didn't too well anyway last year we had actually was Tim Conway did two topics that i didn't give him any extra time i only gave him six minutes but this year Josh worked a deal with me he's getting eight minutes so if you got me with let's say two minutes up front plus eight minutes of Josh right that's 10 then you've got three six minute talks so that's 18 so we're 28 minutes in the rest of the time about 17 minutes is for Q&A um and the Q&A is my favorite part because you know you get to mix it up a little bit and i tell them i want you commenting on what each other says and it's okay if you contradict each other respectfully or at least have another point a more broad point that's that's good um and then we finish up and thank everybody who walk out the stage i think the Q&A's audience driven right it is yeah yeah and and you know the

topics themselves is so the Q&A's audience driven um we try to get really meaningful stuff we don't want light fluffy questions we want like let's get to the heart of the things oh there is one other part i try to give everybody one minute at the end and we go backwards maybe it's even 30 seconds at the end it depends um but we go backwards just hey if you had to leave one thing with the audience what would that be it might be from your topic or maybe more general topic so we do that we thank everybody and then we're done um we're doing something other this year Sean uh that's kind of new the following morning because our our session is i got it here it is Tuesday March 24th at 3.55 pm on the main stage then the following morning i think it's at like eight thirty a.m. or something so it's early ish um we're getting the team together um and we're going to do this like little affinity session so if you want to talk about these topics in more depth one on well maybe not one on one but say one on 20 or one on 40 they're

giving us this big room we have each of our panelists in there and they'll there's going to be interactive sessions with them so that's Wednesday morning i'm not exactly sure where it is but you should be able to find it about eight thirty nine a.m. and it's to take the discussion to the next level interactively with people we don't know how many people show up it might be i think the room seats 80 or 100 people but we're going to divide the room into four sections one for each of our speakers and then you can talk with them about their topic in depth nice yeah it's an experiment rsa probably don't call it a bird of a feather but kind of that that style right it's going to have that feel yeah that there's a name for what they call it but it's it's not it's not about the other thoughts that'll be Wednesday morning you know my big fear is what if nobody shows up for that but you know look if it's just 20 people it's going to be amazing if it's 80 people it's going to be even more amazing but we don't know we don't know so it did uh yeah it is but it is and i think those who those who want to learn and take action they'll show up i hope so you know i

now that i think but i should remind people on two's day to say if you really like us i want to meet these folks individually come to the session tomorrow see yeah sure i think i made you bigger the head there you go well i'll uh if we can dig it up before this gets produced i'll include the link to the one where people can find it um so let's let's wrap up this head so is there is there one thing ten years is there one thing that strikes you from this year's content that kind of looks different smells differently from the last ten years you're like we didn't really and i don't i don't want us to say it's going to be the two letter word but it is okay so all right in the past go back to 20 way way back to 2023 right it was in november of 2022 that open AI introduced chat GPT

that really shocked us all saying this thing passes the turing test this is really interesting it's got its limitations got its flaws but while they changed the world november of 2022 we did you know springtime 2023 rsa c and i got all these people saying it's got to have some AI it's got to have some AI so there's like one of our topics i think that in that hat AI and then 2024 there was one or two i think it might have been two topics and then 2025 it was two topics now here's the deal and again i'm sorry if everybody's sick of here an AI but it's really important now now so here you will find that all of our topics involve AI to share oh um i don't know who's supposed to say what but here's the they may they may they may it could be hyperpublicly speak if i were to tell you here's a major trend happening in cyber security and there wasn't an AI aspect to it i would be lying to you even if it's not directly AI related AI is involved in some way in the attackers craft in refining that look none of the topics is going to be password cracking i promise you that okay however good

password cracking now involves AI to create the guest is because so everything touches on AI and AI touches on everything so you know when i first started talking with the team about what their topics were going to be and they're all coming back and there's an AI component of each i started to say look can one of you do something that's not AI related and the answer came back have AI touches everything now some of the topics we're going to have are not directly AI but we are going to talk about how AI is accelerating that topic because that's the way it works and one other area you know worth keeping in mind is is AI specifically for vulnerability research and discovery of zero day flaws in code i was at a conference it was last week in san francisco called unprompted unprompted great conference it was for AI cyber security practitioners and there was a presentation by google there and a presentation by anthropic and they talked about how in the near

term they're expecting a huge number of vulnerabilities like we've never seen in this industry this will be my 30th rsa c conference my 30th defcon coming up the summer 30 years i've been going and but the points of these presenters from google and anthropic is we've never seen anything like this for vulnerabilities google was talking about how short term it's going to be pretty bad and long term it's going to be much more safe and secure from a software perspective anthropic said it's going to be really bad really soon lots more vulnerabilities than we've ever seen zero day in critical things so it might you know we're optimized we built our system so that maybe you get one or two zero days a month maybe three that you got to patch for pretty quickly in a really bad month there might be four of them imagine if you have four of them on a Monday and then a Tuesday you've got 10 and then Wednesday you've got 13 and Thursday's a quiet day you only have two and then Friday I hitched with 20

because they took Thursday and rested but the ability to use AI to analyze source code and fine flaws was what google's talk was on they haven't posted the talks publicly but they said they will but the unprompted conference the google talk and the anthropic talk I encourage everybody to watch the google people referred to it as the vong apocalypse vong apocalypse and the anthropic presenter and I'm sorry I don't have their names off the top of my head but the anthropic presenter said right now AI when analyzing source code is as good a vulnerability researcher as the best human vulnerability researchers in the planet and he said that's a statement it's a big statement but wait he said soon in a matter of months AI vulnerability research using source code defined flaws will be better than all human vulnerability researchers together and that's coming in a matter of months that's why they're talking about we're expecting to see major security flaws I saw a tweet from Phil Venables many no Phil he's been a see so for many

years he's now an investor does amazing things and works with incubators and such he tweeted based on these talks that I just mentioned here he said that he's never been more optimistic in the long term of you know having good secure software and at the same time never more pessimistic in the short term of how top things are going to get in the next year or so so and you'll be on the look after that it was just really incredible there's this thing in the sort of zeitgeist and even in my own company we are using frontier AI models to analyze source code and finding all kinds of zero days I mean it's it's unbelievable one of my folks on my team just two days ago found a zero day in a pretty major piece of software open source software contacted the team they said this is a critical bug we're going to issue a patch in two weeks and that was just feeding a frontier model with clever prompting source code and boom it found the thing and we're doing that in our smart people validating and smart people validating with the help of the AI with the help of the AI

you know hey can you create an exploit for this and it does so yeah so this is something that people need to be aware of um and up their patching game better than it ever has the the gentleman in enthropic and I'm sorry I should know his name he said you know everybody's talking post quantum post quantum this post quantum that everybody's spending a lot of money on post quantum the government says by 2030 you got to be ready for post quantum blah blah all this stuff US government that is um and he said that is a problem that is a concern the industry is responding smartly to that but that's a problem that may or may not be five years from now or 10 years from now or 15 years from now in other words we don't really know when they're good you know the quantum crypto analysis will get good enough to blow away our common crypto algorithms today it's on the path for that it's hard to predict exactly when that'll happen say five years maybe 10 maybe 15 I saw some of you yesterday who said it 15 years I'm like I think that's a little long but I'm not a physicist who knows but the guy from enthropic said this we know that this vulnerability

analysis capability will be available in AI models used by us and our enemies in the next year or less and organizations are not ready to roll patches quick enough so that's mind blowing and I'm gonna bring it back to your session do the tips from each of the four across the five topics include AI they do both on the offense and the defense and uh and again I'm sorry you know it's the two letters and this and that but you're good enough here's the thing that's the reality sadly the reality and you're not happening whatever very unique takes very unique takes from each of our four panelists and this you know I told you sometimes they have slight disagreements and contradictions with each other you're gonna see that in in what you could do with AI and how you can leverage it and and that's good because it'll it'll make all of the people who see this session you know your your listeners and audience more well informed about where things are where they're

headed and what the debate is all about so good Ed I think I don't normally do this but the the title for this gonna be something like you're tired of hearing about AI but you want to hear this this topic about yeah yeah uh Ed it's always good to see my friend looking forward to uh to catching up with the in person in San Francisco and uh to catch in the catch in the keynote stage the five most dangerous new attack techniques crucial tips for defenders Tuesday March 24 355 uh don't miss it it's a good it's a good session and uh good group of people Ed thanks so much for uh taking the time to share with me and have this chat about the session and then more and uh thanks everybody for listening and please do stay tuned iTSP Magazine.com forward slash rsa c for all of our coverage there's gonna be a ton and I don't know we might have some AI stuff in there we're on this one we'll see we'll see thanks everybody

More episodes

More from The ITSPmagazine Podcast

View all episodes →