Podcast

What Happens When Attackers and Defenders Are Both Running AI?

/2 min read/

Get the full EM360 Podcast breakdownGet the full EM360 Podcast breakdown

Two AI systems arrived five weeks apart this year. One finds vulnerabilities and exploits them. The other finds vulnerabilities and fixes them. Attackers are now weaponizing a new CVE in under five days. Most enterprises still take more than 60 days to patch a critical one.

In this episode of EM360’s The Security Strategist podcast, host Richard Stiennon talks with Brinqa CSO & COO Brad Hibbert on what changes when offensive AI tools like Mythos start chaining medium and low-severity findings into full system compromises, the kind of findings that traditionally sit at the bottom of a remediation queue. Hibbert's answer: the volume of findings was never the real problem. Knowing which ones matter, and acting on that faster than your own change-management process, is.

Hibbert walks through why a low-severity firmware flaw on something as unremarkable as a fish-tank sensor became the opening move in a real breach, and what that means for how security teams should be scoring risk. He also gets into where defensive AI is headed next: agents that review code the moment it's checked in, flag weaknesses before release, and eventually propose their own fixes before a developer sees the pull request.

What you'll learn:

  • Why attackers chaining low-severity findings together is a bigger shift than faster exploitation
  • What separates a vulnerability count from an actual attack path
  • Why patch counts are the wrong scoreboard for CISOs, and what to track instead
  • Where agentic AI is headed inside the software development lifecycle
  • The one question Hibbert says every CISO should ask their team on Monday morning

Watch the full conversation above, then see how Brinqa's CyberRisk Graph turns attack-path context into a prioritization program your team can actually defend.

Focus on the Exposures That Matter Most

Request a DemoRequest a Demo