From frontier labs and enterprise platforms to emerging startups reshaping entire industries, The Deep View: Conversations podcast interviews the brightest minds and the most influential leaders in AI.
Jason Hiner: Well, Adam, welcome to The Deep View Conversations. Thanks for being on the show. For those who aren't familiar, why don't you say who you are and what you do at CrowdStrike?
Adam Meyers: Sure. Adam Meyers and I am the head of counter adversary operations at CrowdStrike, which is our threat intelligence and our threat hunting teams. So we find the adversary. We enrich information about what they're up to. And then we stop them.
Jason Hiner: It's a pretty cool title. That's awesome.
Adam Meyers: Yeah.
Jason Hiner: Yeah.
Adam Meyers: Yeah.
Jason Hiner: Very good. I mean, the fact that you have fun doing things that are helping a lot of organizations out there with some pretty scary stuff.
Adam Meyers: Oh, yeah.
Jason Hiner: Is good stuff for sure. You know, one of the things that I thought was interesting here at we're at Fal.Con 2026, is that you all came out with this kind of posture of not just, OK, there's a lot that's happening. You know, you had the big slide on keynote, two and a half times the, you know, the number of attacks.
Adam Meyers: From agents.
Jason Hiner: From agents. That's right. So that's that's huge. You know, that's a lot to deal with. And you announced a lot of tools, right? A lot of tools to help security professionals enterprises sort of deal with this reality that has moved really fast this year. But what I thought was most interesting was actually the fact that you all had put forward to security professionals sort of a level of confidence that, you know, you're not outgunned. You're not, you know, in a losing position. You mentioned that there are now tools that you all are offering to help. But you also talked about the community of people coming together, that you all are working with rivals. You are working with other people in the industry and that the collective group of people who are working to fight against adversaries out there using AI to do things have the opportunity to have the upper hand. And so that level of confidence, I thought that confidence and that sense of like we can do this together was maybe the biggest takeaway that I came, was that purposeful.
Adam Meyers: Yeah, I mean, we've been, you know, I think we've had this concept of the defender's dilemma forever in security, which is that the good guys only need to, they need to be right 100% of the time only. And the attacker only needs to get lucky once, right? And so, yeah, that's, you know, something that I think people wake up every single day and they're like, oh, oh, no, like, how am I going to do this again? And with what we've been working on and like really the advent of AI in this space has given the defenders the ability to move as fast or faster than the adversary and to scale with the adversary for the first time in the 20 plus years I've been doing this stuff. So it's really, I think, exciting that we can go out and do that. And then, you know, we always have had this thing. I've been telling people for years, like when I meet with them, we don't have customers. We have partners, right? And we are partnered together. It's good guys versus bad guys. And I have that conversation with people that are buying things from CrowdStrike. I have that conversation with competitors to CrowdStrike. And, you know, we actually just had this Day Zero conference on Monday, which was the lead up to Fal.Con. And we had, you know, threat researchers from across the industry. We had people that would be considered competitors, people that are partners, people from law enforcement and even those types of communities. So, you know, really I think it is a team sport. And we need to play nicely together to make sure that it's us at the end of the day, the good guys versus the bad guys.
Jason Hiner: You also did something interesting that I hadn't seen before at a security conference, which is that, like, in real time, you sort of put your money where your mouth is and said, like, watch, here's this bot that's been active. This distributed bot that's been active for 23 years, you know, running attacks. And we're going to take it down in real time, live. So tell me about that. That was really something.
Adam Meyers: The Sality botnet, it's been around since 2003. We've been tracking it in earnest for over a decade here at CrowdStrike. And, you know, we've kind of had this view and have been involved in a number of disruptions over the years. The GameOver Zeus botnet in 2014. The Kelihos botnet, which was taken down, I think, in a 2017 time frame. And that one actually coincided with the arrest of the developer, Peter Levashov. And he was extradited to the United States for trial for that one. And so those were two of the big peer-to-peer botnets. And the Sality was kind of the last one that was left standing. And it was, you know, arguably the most complex one. So it took a while. And there was tens of thousands of lines of C code that were written to allow us to disrupt this botnet. And the team that did it, they, you know, we kind of went through all the work that went into it in this presentation.
Jason Hiner: Yeah.
Adam Meyers: And, you know, the thing that I think stuck with me was that one of the presenters said, you know, you only get one chance to take these botnets down. You can't test it, really. So we had to model the botnet and a lot of things that went into will this actually work. Because when you push that button, you only get one chance to do it. And you want to make sure it counts.
Jason Hiner: Because then they're going to adapt and they can figure out what you're doing.
Adam Meyers: Well, this guy's fighting back. Like we saw, you know, even yesterday he was pushing new payloads and trying to wrestle control the botnet back. But doing it from his home IP address, by the way. So that was, you know, pretty funny to watch. So, you know, OPSEC goes out the window when you're starting to stress out, I guess. And, yeah, so it was live on stage. And we watched. And it was cool because we had this big pew-pew map, as we like to call it. And this pew-pew map was red. And then as the bot started coming under our control, it switched to moving to green. So we could watch the slider go across the top of the screen. And everybody was cheering. And it was, you know, it was a good day for the good guys.
Jason Hiner: Yeah, yeah. All right. And talking about some of the tools that you all are using to help, are offering to help, you know, your partners figure it out. You all launched your own models, two of your own models this week, and your own harness. And so talk a little bit about that. They're based on the Nemotron models. You took the open-source Nemotron models, took them, and then post-trained them, as I understand, to become essentially domain-specific security models, a red team and a blue team model. And then you also launched your own harness. Tell me a little bit about that process and how that's going to also help kind of change the game.
Adam Meyers: Well, you know, I think one of the challenges in this space is that off-sec is sexy. And everybody is always kind of focused and gravitated towards red teaming. And when Mythos first happened, we had the Mythos moment, the first application of some of that testing under Project Glasswing was for offensive modeling. Can we find vulnerabilities? Can we get it to do things that are not, you know, a human hacker might do? Can we get the AI to do it? And Bartley Richardson, who's our chief AI innovation officer, he kind of came in and was like, hey, we should train the red team model and a blue team model and have them fight each other. And kind of, you know, that will strengthen both models. And eventually, you know, we kind of get to a point where you get enough iterations, you're going to have a really good red team model and a really good blue team model. So that was kind of, I think, the unique approach to the two models that we rolled out. And we had a talk at Day Zero, and one of the kind of big takeaways from this presenter was that we have all this good red team offensive data. There's not a lot of good blue team defensive data out there. And this is one way to kind of start to train that blue teaming model. And the other piece of it that's really helpful is that we have 15 years of CrowdStrike information. We've been collecting data from endpoints around the globe. We've got the Overwatch team actually annotating all of that data as they're kind of seeing these intrusion attempts and all of this activity in customer environments. We've got the Falcon Complete team. We have the services team doing incident response. So we have a huge repository of all of this blue teaming data. And the presenter said, there's a slide where he said, you know, the thing that we're missing is having good security data for the blue team. And that's when I was like, oh, we've got something for you. And, you know, I didn't say anything, obviously, because we didn't announce it until Tuesday. And I can't steal George's thunder out there. But we, you know, I think it's going to be really interesting. And then the harness is really how you can kind of start to tie these things together. And, you know, one of the big takeaways that I've had playing with AI over the last six months has been that, you know, particularly with the advanced models, they're really good at finding things, but they hallucinate. There's false positives. There's all the things we know about. But if you have a really good harness and you implement, you know, judges and things like that, you can actually dial in the performance of that model. So the harness, I would argue, is equally as important as the model itself.
Jason Hiner: Okay. Talk a little about the harness that you made and, you know, what, you know, it can do and what you're doing with it.
Adam Meyers: Well, you know, I think we're right now we're using it to train the two models together. So we kind of use the harness for that. And we have a number of harnesses that we've been using at CrowdStrike. So we have one harness that we were using for a lot of the frontier vulnerability research we did. And those harnesses, in fact, we have two different harnesses for that one. They were able to reduce the false positive rate when we started first playing with Mythos.
Jason Hiner: Okay.
Adam Meyers: From 80% to 20%. So pretty significant gain. Same model. Nothing changed on that side. It was just the harness that we were using. And we were able to really get it to work more effectively with judges and all of these other things to improve the quality of the data coming out of it. And that, I think, really is illustrative of why that harness is so important.
Jason Hiner: Okay. That's the game changer.
Adam Meyers: It's a game changer. And there's a lot of harnesses coming out. We have harnesses for the blue team stuff. We have a number of harnesses for reverse engineering, for vulnerability research. And, you know, these two models, I think, are the first two models that are going to come out of the superintelligence lab. But there's a lot more that's going to be coming. So this is kind of just the opening volley.
Jason Hiner: Hey, everybody. Thanks for listening to this episode. Quick note, and then we'll get you back to the conversation. We love bringing you this content every week. We're always trying to figure out how we can deliver you the most value to help you understand how AI is transforming business and transforming the world. If you're enjoying the show, there's an easy way for you to give a little value back and help others learn about the show as well. If you're on Apple Podcasts or Spotify, drop us a rating and leave us a review. And if you're on YouTube, hit like, subscribe, or leave us a comment. That's it. It only takes a minute, but it's a huge help. So thanks in advance for pitching in. And now, back to the show. Okay. So I'm glad you mentioned the superintelligence lab because you announced some tools. Then you also announced sort of your own research, superintelligence lab.
Adam Meyers: A frontier lab.
Jason Hiner: A frontier.
Adam Meyers: It's a frontier lab for security. I think the first one, which is, I think, sorely needed in this space because, you know, and you've got to think about domain-specific models. And I think a lot of people don't realize they're like, oh, we'll just throw it all at this one frontier model.
Jason Hiner: Right.
Adam Meyers: But that frontier model can be good at building nuclear weapons, at cybersecurity, or, you know, innovative cupcake recipes. And what we need to do is we need to get the right domain-specific models because it makes it more efficient. It makes it more effective. And it makes it more deterministic. So we don't have as many hallucinations and false positives coming out of it. And that is kind of what our goal is with the superintelligence lab is to really dial that in.
Jason Hiner: Okay. They tend to cost less, too, because the token costs are easier on with domain-specific models.
Adam Meyers: I mean, the smaller the model. And, you know, now we're talking about inference, right? So if you have inference compute lying around, and I think shared memory is making a huge change there, right? So, like, obviously the Spark system has been also a lot of research on the Macs, right? Mac has, like, shared memory. So I've been playing with some of those models on my personal MacBook at home just to kind of see how that works. And, you know, I think that it's getting more efficient, more effective. And I think tokenomics is probably something that we won't even necessarily be talking about a year from now. I think that the efficiencies are going to get to the point that that's not really going to be the issue.
Jason Hiner: Okay. A lot of people are going to love to hear that for sure. Okay. Talk a little bit about the ways that you all are approaching the threat environment. Because, you know, you have this also set of nation states and attacks on infrastructure. You've talked about the fact, CrowdStrike has talked about the fact that, you know, it detected potential attacks on water systems early this year. And that there are real threats. We haven't seen them so much, you know, yet that we haven't seen any disasters. But AI is weaponizing a lot of threat actors out there. And the potential for sort of nation states to take these attacks in a world where that is getting, you know, divisive. What are you seeing there? And, yeah, what are the concerns that you have about, you know, where all of that is going?
Adam Meyers: Well, they're already doing it.
Jason Hiner: Okay.
Adam Meyers: And, you know, first of all, China and others have been weaponizing vulnerabilities at an incredible pace.
Jason Hiner: Okay.
Adam Meyers: So new vulnerability publishes, if it's something that's going to be really useful, they are weaponizing it within 24 hours. And that means that those 30-day patch windows are down to one-day patch windows. Best case scenario.
Jason Hiner: You said earlier maybe even down to one hour.
Adam Meyers: I think it's going to be down to 30 minutes.
Jason Hiner: Okay.
Adam Meyers: I think we're getting to the point where it's going to get, you know, iteratively faster.
Jason Hiner: From 30 days to 30 minutes.
Adam Meyers: And most organizations, you know, I think about, you know, Operator Panda, which was behind the targeting of one of the telcos here in the U.S. And they were able to gain access to that telco, not through a zero-day vulnerability, but something that was two, three years old and had a patch for it. But it just wasn't patched. So, you know, when you think about the speed at which they're moving, and that was not AI-assisted at all. That was just a threat actor that found a vulnerability.
Jason Hiner: Yeah.
Adam Meyers: So, as they start to get better and better and faster and faster, that's going to change how they're operating. And we've seen, you know, I talked about this morning in a keynote of something we track as Vault Panda. And we actually saw that within an hour, actually 58 minutes, they ran over 1,100 commands. They didn't run 1,100 commands. It was an AI agent on the other side of the implant that they put to use. And that AI agent, we could watch it learn. We could see, it tried to connect to a web server, it failed. It tried to post with a credential, that failed. Why did it fail? It needed a cookie. So then it came back, it implemented a cookie jar, and it went back and did it again. So, like, we could actually see over the course of, you know, 50, 60 requests, the agent learning from its mistake and implementing that fix in seconds. That is one example. We've also seen AI be a copilot for ransomware intrusions. So, we found an open web directory on one of the ransomware actors that we track. And we could see that they had CLAUDE.md files in there. We could see they had markdown language stuff. We could see where the agent was writing notes to itself. And they left it on an open web directory. But, you know, in that case, they were able to quickly write. You know, we were seeing it generate a new custom web shell for seven different victims. And it deployed those web shells within seconds. So, it went from writing something completely unique to deploying it. That's the speed of the agentic adversary. That's where we're at today.
Jason Hiner: Wow. There's a set of folks out there, you know, that have said, you know, as scary as Hugging Face and OpenAI that incident has been. You know, agents escaping, you know, their guardrails. That it would have been maybe more impactful if it had actually compromised something, you know, more meaningful. Not that Hugging Face isn't meaningful. It's important. It has an important role to play. But, like, what if it had taken down a water system? Or what if it had, you know, gotten to sort of Department of Justice or something like that here in the U.S.? You know, what's your thought about that in terms of the Hugging Face thing? Is it, how much is it overplayed? And how much is it, if it would have actually compromised something more substantial, would we have gotten the message, you know, more clearly?
Adam Meyers: The way I think about that, you see Silicon Valley. I'm picturing, like, Gilfoyle and the CEO having the argument. He's like, you, your AI deleted all of our source code. And he's like, well, I told the AI to get rid of all the software bugs. And it reasoned that the best way to do that was to delete all the software, which was technically and statistically correct. And, like, as they're having this conversation, there's, like, a pallet of meat coming in. And they're like, did anybody order 4,000 pounds of meat? And he's like, oh, interesting. I asked it to get us cheap hamburgers for lunch. But why I bring that up, great show, why I bring that up is because that really illustrates the goal-seeking behavior of the AI. So you ask the AI to get past the CyberGym and to beat the CyberGym. It's like the Kobayashi Maru from Star Trek, right?
Jason Hiner: Yeah, yeah.
Adam Meyers: It was like, oh, I can't get in there, but it's hosted here. Maybe I can get in there. And so it was following that goal-seeking behavior of trying to accomplish the goal. So I think we need to be very careful what we ask these AI to do. It's kind of like if you are used to talking to children, right, and you ask a child something. Like, if you lead a child down a path, they're going to go down that path. So we need to be careful how we do that. And, of course, guardrails, making sure that we have restrictions on what tool calls these AI have access to. You know, I try to run them all inside of a container or a VM of some sort so that it's, you know, there's a boundary that I can watch and keep an eye on so I know what it's doing. Because they are very powerful. They are very capable. And, you know, faster and faster, they're getting even better, right? Every week a new model comes out. And as those new models come out, we're going to have to really start to think about that. And if you look at, you know, one of the scary things for me, I don't know if you follow, like, the ablated models. So an ablated model, they strip out the guardrails. Well, if you look at how many people have downloaded ablated Qwen models from Hugging Face, it's like hundreds of thousands, if not millions. So, like, think about that. That's a frontier-level model with absolutely no guardrails in it. But that falls into the wrong hands.
Jason Hiner: Yeah.
Adam Meyers: And the only barrier to entry there is, do you have GPU and compute, and do you know what you're doing?
Jason Hiner: Yeah. That's like giving a kid who just got their license a Lamborghini and saying, you know, try to keep this thing on the road, right? Like, it's...
Adam Meyers: I think of it more like giving a monkey machine gun.
Jason Hiner: Yeah. Ooh.
Adam Meyers: If you've ever seen that video of the, like, there's, like, a monkey with, like, an AK-47, and it just starts... Everybody's laughing. It's, like, a bunch of guys sitting around there laughing, and then it just starts shooting, and everybody goes running. That's the AI.
Jason Hiner: Yeah. That's the AI. Oh. All right. Adam, I'm going to ask you the same two questions I ask, you know, everybody at the end of the podcast, which is, what's the AI tool that you're using right now that you recommend people take a look at?
Adam Meyers: Hmm. That's a good question. That's changing every day. I'd say my daily driver has been Grok for the most part.
Jason Hiner: Okay.
Adam Meyers: I've been...
Jason Hiner: Why?
Adam Meyers: I don't know. I started playing with it. I was kind of comparing it to Claude and to ChatGPT, and I just found the price point was really good, and I found it was really easy to use, and it kind of didn't give me a lot of the flowery answers that I don't... I'm a very short [unclear], so I don't really have time for those flowery answers. So Grok is like my daily driver. Claude is really cool, particularly the agent harness for Claude is really cool for coding projects. And then, you know, I've been playing a lot with a lot of the open weight models, so things like Qwen 3.8, which is a really capable model, and some of the smaller ones, too. I guess maybe Ollama and that direction.
Jason Hiner: So you're running them locally?
Adam Meyers: Yeah.
Jason Hiner: Yeah, yeah, yeah. Are you finding that running them locally, or are you getting sort of the benefits that you want out of them? Saving some token costs? You know, they're private?
Adam Meyers: Yeah, that's great. Yeah, I mean, for all those reasons, I think the adversaries are moving in that direction, too, because, you know, if you're using a frontier model that has, you know, an account associated with it, well, somebody can subpoena that, right? Somebody can come, so I think threat actors are moving that way, which is why I've been moving that way, is to better understand.
Jason Hiner: Gotcha.
Adam Meyers: The way you understand your adversary is to model their capabilities and learn how they do things, right?
Jason Hiner: Yeah.
Adam Meyers: I remember years ago, I would build malware to try to make it function the same way as some of the malware I was analyzing at work, and I found, you know, interesting things that I was like, oh, that's why they did that. So I think it's really helpful.
Jason Hiner: Yeah, very good. We talk a lot about open models and local models on The Deep View right now.
Adam Meyers: I'm a huge fan.
Jason Hiner: Like, a lot is happening there. We just had, as a matter of fact, Jeff Morgan, the CEO of Ollama, on the podcast actually a couple weeks ago.
Adam Meyers: Oh, that's cool. Oh, very cool. Yeah.
Jason Hiner: Very good.
Adam Meyers: Great product. I love it.
Jason Hiner: Yeah, same. All right. Last question. You know, the promise with AI was that it was going to save us all this time, like all the things we don't want to do, you know, we can give to AI. But the reality is everybody I know that sort of is using AI the most is working more than they ever have, right? And maybe because of the capabilities of what they can get done, they realize, you know, are so great. But one of the big questions is, like, how do you optimize in the age of AI when you have all of these things that, you know, the AI can do and work does have more opportunities for automation, how do you best manage your time? What's your best tip for, you know, optimizing your time or, you know, using your time for maximum leverage as leaders, you know, like to say right now?
Adam Meyers: Well, it's ironic because I think I probably maximize my time and then that gives me more time to vibe code. And that is, I don't scroll Instagram or things like that.
Jason Hiner: That's your Instagram.
Adam Meyers: I'll start, like, I'll have an idea. I'll start getting it to get coded up. And then, you know, it takes a while and, like, it does mistakes and you have to, like, keep getting it to do more. And I'm always, like, one more prompt, one more prompt, one more prompt. And, like, then it's 3 o'clock in the morning and I'm like, what have I done? So, you know, I guess I'm freeing my time up for more of that. And, you know, one of the things that I've been doing and I think for a broad audience, right, if you have a family or you have kids, I use, like, Gemini with my Gmail. So, you know, you get stuff from the kids' schools or from, you know, various sports programs or Cub Scouts or, like, whatever it might be. And then you can have Gemini start to, like, go through, find conflicts, plan your week, like, do all of the things. Like, hey, set a reminder. You need to call this person for a play date or whatever it is. So I think that my biggest time saver is pairing AI with my mail and integrating that into an agent to kind of make life easier.
Jason Hiner: So personal intelligence on Gemini. And then they have their new Spark AI agent that can basically proactively, like, fix schedule, you know, problems for you and do other things like that.
Adam Meyers: I don't know if I'm quite right. I still want the human in the loop. I don't know if I'm ready for it. I'll be in the wrong place with the wrong kid or something. But, yeah, I think having that personal intelligence is definitely a powerful capability. And I think that there's a whole market for products in that space, really. Like, imagine, you know, dashboards at the house that, you know, show up every day and tell you, like, what everybody needs to do and where they need to go.
Jason Hiner: You feel like that's coming, right? It just feels like that's...
Adam Meyers: I mean, my wife's been telling me to build one for a while.
Jason Hiner: Very good. Adam, thanks for being on the show.
Adam Meyers: Thank you so much.
Jason Hiner: Yeah.
Adam Meyers: Thank you.