AI Security Ops

In this episode of BHIS Presents: AI Security Ops, the team follows a single trend that is changing the economics of cyberattacks:

The machine-speed attacker is no longer theoretical.

Across four stories from a single week, we watch AI move through every stage of the attack lifecycle. First it writes exploits from public patches. Then it discovers and weaponizes vulnerabilities. Next it helps attackers build phishing infrastructure like a software company. Finally, AI agents begin carrying out ransomware operations with minimal human intervention.

Each story stands on its own. Together, they paint a much bigger picture.

The window defenders have relied on for decades—the time between disclosure and exploitation—is rapidly disappearing.

We dig into:
• How Anthropic demonstrated AI-generated exploits in under an hour
• Why “N-day” vulnerabilities are becoming “N-hour” attacks
• The AI-discovered WordPress wp2shell exploit chain under active attack
• The ServiceNow AI Platform vulnerability and rapid weaponization
• Why patching alone is no longer enough
• How attackers are using generative AI to build phishing campaigns at scale
• What Rapid7 uncovered inside a live AI-assisted malware development lab
• Why behavioral detection still catches many AI-assisted attacks
• JadePuffer and EncForge’s AI-driven ransomware targeting AI infrastructure
• The debate around fully autonomous cyberattacks
• What security teams should prioritize as attackers move at machine speed

This episode explores a critical shift in cybersecurity: AI is not creating entirely new attack techniques. Instead, it is dramatically compressing the time required to discover vulnerabilities, build exploits, develop tooling, and execute attacks.

For defenders, the question is no longer simply “Are we patched?”

It is:

Can an attacker reach us before we finish patching, and would our controls actually stop them?



Key Concepts & Topics

Machine-Speed Attacks
• AI-generated exploit development
• Shrinking disclosure-to-exploitation timelines
• Why patch windows continue to collapse

Exploit Development
• Reverse engineering security patches
• AI-assisted vulnerability research
• Practical impacts on defender response times

Active Exploitation
• WordPress wp2shell attacks
• ServiceNow AI Platform compromise
• Post-exploitation persistence and hunting

AI-Powered Malware Operations
• AI-generated phishing infrastructure
• Automated testing and documentation
• Scaling attacker operations with LLMs

Agentic Ransomware
• JadePuffer and EncForge
• AI targeting AI infrastructure
• Autonomous attack capabilities
• Protecting model weights and AI assets

Defensive Strategy
• Exposure management
• Behavioral detection
• Adversarial exposure validation
• Protecting AI infrastructure and secrets
• Prioritizing reachable risk over severity scores

  • (00:00) - Intro: The Machine-Speed Attacker
  • (01:20) - Story 1: When N-Day Becomes N-Hour
  • (09:13) - Story 2: AI-Discovered WordPress and ServiceNow Exploits
  • (15:59) - Story 3: Inside the AI Malware Factory
  • (17:29) - Story 4: Agentic Ransomware Targets AI

Click here to watch this episode on YouTube.


Brought to you by:
Black Hills Information Security 
https://www.blackhillsinfosec.com

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training
https://www.antisyphontraining.com/

Active Countermeasures
https://www.activecountermeasures.com

Wild West Hackin Fest
https://wildwesthackinfest.com

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com


Creators and Guests

Host
Brian Fehrman
Brian Fehrman is a long-time BHIS Security Researcher and Consultant with extensive academic credentials and industry certifications who specializes in AI, hardware hacking, and red teaming, and outside of work is an avid Brazilian Jiu-Jitsu practitioner, big-game hunter, and home-improvement enthusiast.
Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Host
Derek Banks
Derek is a BHIS Security Consultant, Penetration Tester, and Red Teamer with advanced degrees, industry certifications, and broad experience across forensics, incident response, monitoring, and offensive security, who enjoys learning from colleagues, helping clients improve their security, and spending his free time with family, fitness, and playing bass guitar.

What is AI Security Ops?

Join in on weekly podcasts that aim to illuminate how AI transforms cybersecurity—exploring emerging threats, tools, and trends—while equipping viewers with knowledge they can use practically (e.g., for secure coding or business risk mitigation).

Derek Banks:

Welcome to AI Security Ops, the podcast where we cut through the hype and explore the real world intersection of artificial intelligence and cybersecurity. Each week, we examine how AI is reshaping both sides of the security landscape, the threats we face, and the defenses that we're building. I'm Derek, and I'm joined by Bronwen and Brian as per the usual. And this episode is going to be a news episode because we don't talk about the news enough on the re on the regular BHIS news show or other webcasts, or maybe it's just because there's a crap ton of AI and security news. They all seem to go hand in hand today.

Derek Banks:

And, unlike the actual news show, you don't have to drink every time you say AI. And as usual, this show is brought to you by Black Hills Information Security where we do, penetration testing, adversary emulation, purple team engagements, red team engagements. Pretty much if it's got the word security in it, we will consult and help you with it. And then Antisyphon delivers hands on practitioner led training built around real attacks and tools so that you can apply what you learn immediately. So without further ado, let's get into the first story where, it is a from the hacker news where n day is becoming n hour and how patching faster won't save you, which sounds terrible.

Derek Banks:

And so this article is basically, where some researchers at Anthropic are claiming that the time has gone down to hours where, n days will be found. And so, I guess their their their tag, their hook here is reverse engineering. A patch used to take weeks. Mythos does it in an hour. And I think that they say in the article, the traditional playbook to assume you had at least a few weeks to patch.

Derek Banks:

You don't eat anymore, not even close. I don't remember getting the memo on that playbook. I don't think I've ever told a client, you have a few weeks to patch. Think I appreciate it. As I think my take on it, like what my advice has been, and this is what I before I worked at BHIS, and so this is going back over a decade, which makes me officially old, that you you I'd never said that you had weeks or months to patch.

Derek Banks:

I think my, thing was apply it immediately and fix what breaks. If you're not doing that and that was a decade ago, you're behind the curve. Because the assumption is is that the reverse engineering the patch is the zero day, and I would disagree. I would say that it doesn't matter if it was AI that found the flaw or, you know, Mythos, or doesn't matter if Mythos is two hours, you know, quicker than than OPUS 4.8. You're making the assumption that no one else has found that in that software, and I think that's a pretty big assumption.

Derek Banks:

Right? You you cannot make the assumption that there's not a threat actor on the planet that hasn't already found that vulnerability. So if you're patching, you're already behind that curve. That's why we have things like defense in-depth.

Brian Fehrman:

Yeah. Yep. I think that's that's a good point. And, to take just a step back quick for the viewers who aren't aware, what we mean when we're talking about end days. So you probably heard the term zero day, which is that you have found a vulnerability that is not actively being patched or fixed.

Brian Fehrman:

Like, the vendor is not actively working to fix that. The community is not actively working to fix it. To Derek's point, it's likely that you're not the only one who has founded at that point.

Derek Banks:

World's a big place. The Internet's a big place.

Brian Fehrman:

Yeah. But likely, it's not known. So that that's zero day versus end day or one day, or in this case, is they're calling in an an hour or one hour. This comes after the patch is released or the fix is released, and, this people will do what's called patch diffing, where basically they look at, okay, what's what's the update that was released? How does that differ from what we have before?

Brian Fehrman:

And it's big, especially on the Windows ecosystem with patch Tuesday rolls out, and, you do patch diffing to see what has changed because once you see what has changed, you can say, oh, I see what the problem is, and then you can do an exploit for it. And so what this article is really getting at is how quickly, though, that that process is is it's been accelerated in terms of that turnaround time.

Bronwen Aker:

And this is a big issue. We've been talking about it extensively on the news and, the patching has always lagged behind developing exploits because patching is hard, and of course, now, you can't even patch without having your patch be used against you. It it's just shut all computers off. So You know, there were times where I actually take a a

Derek Banks:

digital approach. It's actually kinda funny that my Unplug. My 15 year old is is like that. She's like, I don't wanna do a job where I have to sit behind a desk every day. It's like, I can understand that.

Derek Banks:

Good luck with

Bronwen Aker:

Yeah. I never wanted to grow up and be a keyboard jockey, but here we are.

Derek Banks:

Hey. I actually I do love it. But I guess I don't know. I I look, I am not going to disagree that AI, regardless of if if it's Mythos, even though I'm a little tired about hearing about Mythos. I mean, how old is it now?

Derek Banks:

Like, it's four months I don't know. Oh, I do know that Fable is like on unusable for me, but thanks folks at OpenAI because five six soul is is not it's pretty good. But I digress. I I never really thought that I had weeks to patch. Like I said, I never made that recommendation to clients.

Derek Banks:

My recommendation and that's why I kinda disagree with the premise, like, yeah, sure, we're finding vulnerabilities more, it's harder to patch. We're actually finding so many that, what's the term? Vulnpocalypse? Like, I would hate to be on the receiving end of all of this. Right?

Derek Banks:

And then weeding through what's real and not and high impact. But and so, yes, vulnerabilities are getting found quicker and, when arguably have a lot more impact like we're gonna talk about next. But, I mean, I always thought a defense in-depth was a better strategy. Or, sure, it might be that you have, like we'll talk about here in a little bit, you know, a WordPress vulnerability, but perhaps it would be a good idea to take other mitigating factors so that the WordPress vulnerability that we'll talk about here in a minute, has less impact, or it doesn't apply to you because you're not doing certain things. And so and and that's the concept of defense in-depth, you know, like like from a client perspective.

Derek Banks:

You know, if you have a you know, a Windows desktop that you're getting patches for and there are threat actors out there trying to develop end days for it, and it takes five hours, well, that's great if it took five hours or five days or five weeks because hopefully my EDR solution and my upstream network defenses and my other, you know, monitoring and logging, all that stuff should help mitigate that. I mean, it's all a game about mitigating risk. Like, this isn't a problem that's, like, solvable. Like, you know, what what would be the recommendation? Don't use software?

Derek Banks:

Yeah. That's not correct.

Bronwen Aker:

And, you know, as as a recovering developer myself, I know for a fact I've I've watched the the evolution in terms of how frequent software updates would get pushed. I have a sneaking suspicion that, you know, call me call me crazy, but at some point in the foreseeable future, AIs will be finding, patching, and pushing updates to software live in a matter of of minutes, and that will become a new norm. Hopefully, within my lifetime.

Derek Banks:

Yeah. And, you know, I still think I don't know. Maybe it's because I'm, maybe it's because I'm a a cynic or I I don't know. Maybe I I just got older and wiser. Either way.

Derek Banks:

And and I think this article towards the end kinda makes me think that too that I I I look at this as kind of, you know, a FUD. Right? Like fear, uncertainty, and doubt. Like, oh, no. We need to do this.

Derek Banks:

And, and so and at the end, I think is really the the kind of onus for this is like, hey, buy our automated pen testing platform, and we'll find this stuff for you. And you're not using Mythos, and just because Mythos said this, then yeah. I don't know. But like I said, just because I think that there are ulterior motives at play, you know, like, I think that I I I personally don't think that Mythos was too dangerous to release to the public, but whatever. I think it's more of a a marketing or a defense ploy.

Derek Banks:

But either way, vulnerabilities are getting found faster, and that is where we come to the next story, which is and I'm sure that y'all probably did talk about this on the news, the WordPress vulnerabilities. I didn't see the

Bronwen Aker:

news don't this know that we talked about this one specifically. I think this one came out yeah. I mean, this article is dated the twenty first. It's dated today.

Derek Banks:

Well So know. I think was actually this one. Yeah. It was over the weekend, I think, because or or late last week, maybe, because definitely folks in our continuous pentesting group. So even though I just, you know, got, you know even though I'd was derogatory towards someone shameless plug shameless plug, our CBT group at Black Hills is already using this against our, you know, our our our customers for continuous pen testing, and and that's the, what, CV twenty twenty six six three zero three o and six zero one three seven that are combined w p w p two shell.

Derek Banks:

I think I read earlier today that something they were estimating that something like 60% of WordPress sites are vulnerable, and that is amazing to me. That's like half the Internet. I don't know.

Bronwen Aker:

Pretty close.

Brian Fehrman:

To what? To big blast radius.

Derek Banks:

Yeah. And so and so basically, it's what remote

Bronwen Aker:

RTL's phrase, blast radius. Yeah. Are you an AI, Brian? I'm sorry. I couldn't I couldn't help.

Bronwen Aker:

I've I it's just within the past week, all of a sudden, Blast Radius is showing up in all of them. Don't know why. Must have been something on Reddit. Anyway, Go on.

Derek Banks:

And so maybe I'll, like, you know, contradict just what I said because the claim here is that that the researchers that found this, did it with, it was discovered by Searchlight Cyber using GPT five six Soul in a little over ten hours. And so if that is true that, you know, this undiscovered vulnerability because you gotta think that WordPress is hammered on by everybody and their brother with AI agents and harnesses trying to find vulnerabilities. Like, I have a side project going on that I mentioned many episodes ago with Skippy and finding Vollms, and it's it's actually found some kinda cool stuff. But, you know, it's not my primary focus, but the if if they found this in WordPress with a new model, then I am kind of impressed because I think WordPress is probably gonna be pretty attacked. Right?

Derek Banks:

And so, yeah, it looks like that AI, you know, building off of the first story, found a pretty serious vulnerability that, affects a good chunk of the Internet.

Bronwen Aker:

Yeah. We did actually talk about this, and one of the other things that came up while you were talking, back when I was still doing software development in our engineering department, we had some really amazing QC people, and one guy in particular, he could come up with edge cases like no one ever saw, and I don't know how his brain was able to find these weird ways of coming at our systems, and I bet if he had ever wanted to go into penetration testing, he would have been phenomenal at it. Because of the randomness that the probabilistic nature of the LLMs has inherently in it, I think it's better than well, it certainly can operate more quickly than humans, but it it may also be better finding those weird edge cases, and probably because it's basically a numbers game where it has the ability to run through lots of, you know, here's the normal options. Well, let's do something weird, and that's when it goes into hallucination mode and gets all of these weird wacky creative ideas. So in the long run, I think that AI will be better in general at finding these weird flaws because humans, we get very used to testing for success.

Bronwen Aker:

And I don't think that the LLMs, when they're being sent on this, they're not gonna have that same bias.

Derek Banks:

Yeah. So one of the things I thought was kinda interesting was that it's actually two CVEs that are chained together. And so chaining things like, this is what you said edge case in a different, like, connotation. Like, the, the project that I'm working on, which is, you know, external penetration testing with AI agents, that one of the things we attempt to do is chain together vulnerabilities to make a higher impact, and that's what what they're claiming happened here. So there's, the first one's a an entry point route confusion in the API that bypasses authentication, and then another one that's the, remote execution part that builds on top of that authentication bypass.

Derek Banks:

And so basically, a chain together RCE. And I I'm not claiming that we found this, but one of the things that our tool has done is is it has chained together, like, authorization problems. Like, it's found a a key and then found where that key was used, which I'll just say impressed me a whole lot. Right? Because that was the goal when I saw it working.

Derek Banks:

I was like, holy crap. This actually works. So and I don't know that that's the model. I think that's the harness. So I still kinda question, like, okay.

Derek Banks:

Yeah. I think that, GPT five six soul is a great model. So but is this the model or harness? Because I don't know like you were saying, I've definitely seen where some some agents are create more creative than other agents. Like, I've seen that happen in our tool.

Derek Banks:

But more often than not, consistency is gonna come from, like, the harness. And I just I just wonder, you know, what what was the company that found this again? Oh, crap. Searchlight Cyber. I I'm assuming they have made a custom harness where they're trying to chain together stuff, and I think that to me is more impressive than the model, but anyway.

Derek Banks:

Alright. So the next one is an exposed server reveals an AI assisted phishing toolkit behind web dev malware campaign. So malware operator left its delivery server wide open. I saw a post today by someone who works at a I think it's trusted sec, Justin Elzey. So if you're listening to this podcast, and, you know, thanks for pointing this out, where he I guess he had found that on some server somewhere, what was quite obviously a penetration tester's staging directory, like, left open to the public.

Derek Banks:

So glad it's just not threat actors, pen testers do it to it. I would be lying if I said I'd never accidentally left something like that open. But, man, you gotta be careful. Right? You gotta be careful with those, those those staged listeners.

Derek Banks:

But that's not really the interesting part. You know, humans make mistakes. Right? But what the interesting part is is the, the AI fist, assisted phishing toolkit, which, yeah, I mean, I guess I guess it's still no it's no surprise that threat actors are using AI just like researchers are to find to to to enhance their threat actor capabilities. Alright.

Derek Banks:

So let's do the last one. I think maybe the the best one for last. And again, I haven't watched the BHIS news, so I don't know if this is something that has been talked about, but the jade puffer agentic attacks, the jade puffer ransomware, where, there's a company that's claiming, I think it's OncForge, OncForge. I've I've never heard of them. And no.

Derek Banks:

Sorry. That's the custom malware that focuses on encrypting AI assets. Right? And so, j puffers, something that was found earlier this month, and the company assist dig, I think, that found it, and they were claiming that it was fully automated. That it was the first fully automated, agentic AI ransomware.

Derek Banks:

And what does fully automated mean? Like, there's there's has to be a human somewhere. Right? I mean, fully automated like seems to indicate that the AI is off doing things on its own. Right?

Derek Banks:

Like, I mean, the human gets the result at some point, right, or is involved at some point. Right?

Brian Fehrman:

Yeah. I mean, it's yeah. I mean, at at at some point, you think so. Well, especially the way that it's titled too that it it almost makes it sound like the AI is what's asking for the ransom as well too. Like, you gotta, I don't know, pay it out in, like, RAM or something.

Brian Fehrman:

I don't know.

Derek Banks:

Yeah. And so, I guess, Sysdig was claiming that, the AI agent adapted to technical difficulties in real time and optimized the intrusion mechanism to find the correct fix in less than a minute. Wait. Is it using Mythos? Sounds pretty quick.

Derek Banks:

Yeah. So that's actually one of the things that, like, I I was thinking about here recently. If you're a threat actor and you're attempting to use, like, inference on the endpoint for your malware to be AI powered, like, on like, after delivery and then, like, running and adapting with AI? Like, how are you handling inference? Like, what are you doing there?

Derek Banks:

That's I mean, I don't think you're using AWS Bedrock. Maybe I guess unless you steal, like, an account or something. And so that that like, if if you're going to adapt and fix in less than a minute, I mean, have some kind of I mean, anybody who's used local AI and use, like, you know, small GPUs, that's not what's happening here. Right? So I'm guessing, like, stolen accounts maybe?

Brian Fehrman:

Yeah. Yeah. That could be. If they like you said, if they got access to keys or something that that they're using there. Yeah.

Brian Fehrman:

It's hard to tell for sure.

Derek Banks:

But perhaps more interesting is, like or interesting part also is, like, what it actually targets and encrypts. So AI model checkpoints, Hugging Face safe tensor files, PyTorch and TensorFlow models, gguff and g m l GGML weights. Oh, that sounds like all kinds of fun stuff. Parquet, formats, training datasets. How man.

Derek Banks:

What, like and is this in addition to all

Bronwen Aker:

the text

Derek Banks:

files too? Like

Bronwen Aker:

Well, and to improve inform to improve performance, the malware is only encrypting selected portions of each file rather than the entire file contents. That's kind of interesting. Speaking of outside the box. Now it it makes sense, though, when you when you think about it. Any malicious actor is a predator, and predators are always going to go after targets that are abundant and are vulnerable.

Bronwen Aker:

And right now, the state of AI technology is still very vulnerable. And so personally, I see this as a logical evolution on the part of malicious actors. It's like, of course, you're gonna wanna go after LLM models in addition to attacking the harnesses because as more and more businesses implement LLMs in their tool offerings, web apps, infrastructure, etcetera, those are going to become more and more valuable targets. Why wouldn't they wanna go after them?

Derek Banks:

I mean, it seems like the I don't know. Like, the the target's kind of niche in my opinion though. Right? Because look. I'm actually downloading safe tensors at the moment, but I'm not a normal person.

Derek Banks:

Right? I just wonder, like, in a quote normal company, are these file formats something that most companies will have? I don't think so. Like, most of them are gonna be paying Anthropic or OpenAPAI and using like a service. So this almost seems like to me that they're going after, you know, the more technical end developer aspect, folks who are doing more custom kind of stuff.

Derek Banks:

And typically, those are the folks who have more access in an environment. And so Yes. Yeah. So Yeah.

Bronwen Aker:

No disagreement. And I I think that this is just this is a hint of things to come.

Derek Banks:

Oh, yeah. Oh, definitely. Ransomware going after AI files. This is great. So well, that's the end of the stories that I had for today.

Derek Banks:

And so yeah. So thanks for hanging out and listening, and as always, keep on prompting.