Submind YouTube summaries
Thumbnail for Adam Meyers, Crowdstrike | Crowdstrike Fal.Con 2026

Adam Meyers, Crowdstrike | Crowdstrike Fal.Con 2026

Watch on YouTube

Video summary

Adam Meyers, Senior Vice President and Head of Counter Adversary Operations at CrowdStrike, discussed the unprecedented pace of innovation and the evolving threat landscape during his appearance at Falcon 2026. He noted that the speed of technological advancement, particularly regarding AI agents and harnesses, has accelerated significantly compared to previous years, making it increasingly difficult for defenders to stay ahead of attackers. Meyers highlighted a shift in how adversaries utilize artificial intelligence; rather than discovering entirely new attack methods, current AI models are primarily enabling criminals and nation-states to execute known tactics faster and more efficiently. This acceleration is evident in the rise of "agentic adversaries," where AI agents are now integrated directly into ransomware operations and intrusion campaigns, allowing attackers to automate complex tasks such as reconnaissance and lateral movement within minutes. The conversation also addressed the closing gap between the capabilities of nation-states and everyday cybercriminals, with Meyers citing data showing a surge in agentic adversary activity over the last thirty days. He illustrated the terrifying speed of modern intrusions by describing an incident where a single AI agent conducted thousands of commands in under an hour, learning from failures in real-time to adapt its approach, such as implementing cookie jars after failed login attempts. Furthermore, Meyers pointed out that the window for exploiting newly published vulnerabilities has shrunk dramatically, with some actors weaponizing patches within 24 hours of their release. This trend is compounded by a massive increase in reported vulnerabilities and a rise in voice phishing attacks, which have become a preferred method for attackers because they are often easier to execute than traditional hacking techniques. Beyond technical threats, Meyers analyzed the geopolitical impact on cyber operations, noting how conflicts like those in Ukraine and Iran have forced threat actors to reprioritize their resources and adapt their strategies. He explained that while Russian groups shifted focus toward Western Europe during the Ukraine conflict, Iranian groups faced challenges due to leadership decapitation and the nature of their kinetic weapon systems, which require clear command and control structures that are harder to maintain under cyber pressure. The discussion concluded with a significant victory involving a global partnership between CrowdStrike, law enforcement, and even competitors to take down a resilient peer-to-peer botnet. Meyers emphasized the necessity for the private sector and government to collaborate on offensive operations to raise the cost of doing business for bad actors, advocating for responsible and reasonable approaches that leverage public-private partnerships to protect critical infrastructure.
Read the full video transcript
Good afternoon everyone and welcome back to the cub's live coverage of Falcon 2026. I'm your host Rebecca Knight alongside Dave Volante. >> Excited for this one. >> The guest we've been waiting for. [laughter] >> I would like to welcome back to the show Adam Meyers who is SVP and head of counter adversary operations here at Crowdstrike. Thanks. >> Thank you for having me. It's always so much fun talking to you all. >> Yeah. No, we we've been looking forward to it all week. >> Oh, awesome. You have been at this company since 2011. You're one of the longest tenured senior leaders at this company. Describe for me what this year has been like for you, particularly with the Mythos moment and and the hugging face incident. I I mean, you've seen a lot in your career already, but I imagine this year was unlike any other. >> I mean, it just feels like time is speeding up because the innovation that comes week after week, I mean, and you have to keep up with it all. So every model that comes out, every new I mean a year ago we weren't talking about harnesses or agents. We were talking about AI, you know, generically and models a little bit, but you know, now we've all become agent uh aware and we're we're we're building harnesses and we've released models out of our uh we launched a frontier lab here at CrowdStrike. So, it's just the pace of innovation has sped up and it's just, you know, exciting, but also it's very difficult to keep, you know, up with everything and and stay stay ahead of the curve. But, you know, it's it's fun. George's keynote was very interesting. The way he had the agent state in the top of the pyramid, he flattened the pyramid. >> Pyramid of pain, he called it >> pyramid of pain and sort of democratizing, you know, the ability of attackers uh to to go at folks. But but from your standpoint and the other thing that we've we've been hearing is that you know all this you know mythos and the frontier models they're not really uncovering new ways to attack. They're just doing it better and faster and obviously exposing you know attack vectors that people may have known about but you know maybe the the attackers hadn't exploited. Um so first of all I kind of want to make sure I got that right. And second, is there really not sort of a big gap between what nation states are now capable of and what the everyday criminal can do? >> I mean, the gap's closing for sure. And I I you know, we've seen, you know, a year ago when I was on stage, I was talking about some of the earliest use use cases of AI by adversaries, right? So we were talking about uh Fancy Bear, Russian threat actor using something called lame hug to automate through prompts some of their their activity and most of the e-criminals were really just using it to improve scripts or stuff like that. But in the last couple of weeks and I think you know the stat that's most interesting is uh I we had something like 26 agentic adversaries that we were tracking in the last 30 days and that's more than we were tracking in the year before that. So uh and what I mean by this you know Revenant Spider is a group that we were tracking that was using an agent in the intrusion. So a AI agents are now part of ransomware operations and you know they hack in and then they use the agent on their side and it's almost a black box in most cases but in this particular case they kind of made a mistake. They left the web directory open. We could see all the artifacts. So we saw all of the conversations that the AIS were having. We found markup files and quad files and things like that. So we actually got some insight to it and effectively all they have to do is get into the system and then they put the agent to work on the other side and it accomplishes all their goals. So we're seeing that from criminals, we're seeing that from uh nation states and we're we're seeing activists as well starting to uh to adopt AI as well. >> So China, Russia, North Korea and Iran always been the big four. Is it harder to detect their signatures now uh because of AI or or can you >> No, but you know what it is uh is the speed and so we talked about um Vault Panda today in my keynote and one of the things I pointed to is that in 58 minutes [clears throat] Vault Panda had conducted,00 commands and that sounds like oh okay that's not that much but it was an agent that was doing it and we were watching it learn in real time so we could see that I tried to connect to the web server and it didn't work and then it came back and the next request 3 seconds later it does a post to try to log in and then 2 seconds later the post didn't work and it reasoned it said oh it needs a cookie so I need a cookie jar so then it implements a cookie jar so each step it was learning but it was learning in two or 3 seconds or less and that's the speed of the intrusion today not you know and when I talk about breakout time from our global threat report we were talking this year about 29 minutes on average. 27 seconds was the fastest. And that's from initial access to move laterally. I'm talking about an entire intrusion operation conducted in minutes from start to finish all with the power of an agent behind it. >> And was that a is that example was that a single agent? Was it learning from other agents? Was it collaborating? >> That was a single agent I believe. >> So there you go. Autodactic agents. I mean that's that we've been debating whether they are conscious, whether they are sentient today and whether they know what they're doing. >> I'm not going to touch that. [laughter] Yeah, >> that freaks me out a little bit. Exactly. Exactly. >> But you know, I think that they are goal seeking and um you know when we look at some of these uh agentic escapes as you want to call them, right? uh like the hugging face incident. That's that's also, you know, I think you have to be realistic about what these agents are and and that if you give it a goal, it's going to try to accomplish that goal and it might not do it the way you expect. So if you ask it to bypass the exploit gym and it says, "Oh, wait a minute. It's hosted here. Maybe if I go to this system, I can get in and figure it out." And it's it's like Star Trek the Kobayashi Maru, the unpassable test, right? It's got to figure out a way to do it. And you know, that's the the reality of these agents. In fact, I don't know if you ever saw that show Silicon Valley, but there's of course >> amazing uh scene where where this guy's got this AI agent, he calls it uh Son of Anton, and you know, the CEO is like, "Hey, your your agent erased all the code in the in the repository." And he's like, "Well, I told it to get rid of all the bugs, and it must have reasoned that the best way to do that was to delete all the code." And technically and statistically, it was correct. And that's kind of, you know, how I explain uh that goal seeking behavior to people very quickly because >> you never know what it's going to do. >> You mentioned this this threat hunting report which is terrifying reading. Um some some of the the biggest stats that that stuck out to me. Um 88% of CrowdStrike observed exploitation of vulnerabilities with a PC occurred within 48 hours of release. This two times increase in voice fishing was also interesting in terms of >> oh boy >> going back to the oldfashioned telephone. >> That's been a trend we've been watching for a while. And I think you know it's easier to log in than to hack in. And that's you know what that's all about. If you could call the help desk and get a password reset or you call the user pretending to be the help desk and you get them to click on something, it's the easiest way to get in. and that 48 hours, you know, I think that that's going to be slow uh by the next time that report comes out because I was talking today about the fact that China, we've seen routinely weaponize new vulnerabilities. So, a vulnerability gets published and you think you're doing the right thing. Hey, there's a bug, you should patch. As soon as that happens, China gets to work and within 24 hours, they're weaponizing it. And it's not just China, it's countries like Bellarus, right? Like, are doing this as well within that 24-hour window. And that's the new norm. And the most terrifying thing is that you look at the amount of vulnerabilities that have been reported, right? We track that as CVE or common vulnerability exposures. In June of this year, we tracked 7400 vulnerabilities. Uh we reported 2400 of them all powered through our our Aentic harness for finding vulnerabilities. So about 30% of the reported vulnerabilities we did >> and that was a 96% increase over June of last year. So the amount of vulnerabilities that are being reported is explosive >> and and the attacks are up obviously in volume you know prior to sort of agentic being more effective for the attackers. Did you discern any kind of distraction from I guess I guess Russia Ukraine would be the only one because the Iran conflict well have you seen any distractions there? Are you seeing increased volume from the big four across the board or are they somewhat distracted because of their own sort of geopolitical issues and wars and well Iran I think there are two interesting use cases right and Russia that conflict really escalated in 2022 when the Russians went into Ukraine and um that what we saw was a shift in prioritization. So the Russians had limited resources for cyber operations and they started focusing them on Poland and Germany and you know parts of uh Western Europe and NATO because that's what they needed to disrupt because it was a a critical component to the actual conflict and they also needed wartime intelligence for the field and so they started focusing very heavily on Ukraine. Now when the Iran conflict kicked off, we started seeing um that there was targeting of facilities that were assoc with kinetic weapons that were associated with cyber operations. And we've seen large amounts of some of those Iranian groups were not active right after that conflict started. Some of them got their act together, but I think that there was some decapitation of leadership as well that uh made it difficult for them to operate. And when you think about with with Iran, you have a bunch of missilebased operators and you know what to do as that missilebased operator, right? If conflict starts, your your weapon is pointed at something, you you hit the go button when you hit the go button. With a cyber team, it's not so clear. You can't have those things pre-planned as easily, and they need some command and control. And if you decapitate that command and control, it makes it difficult for them to be effective. So, it took a while. >> I'm afraid to ask you this question, but I'll ask. and and and how are we feeling about your intelligence and telemetry around critical infrastructure? >> Well, you know, I think there's a good news and a bad news there. Uh, a lot of the critical infrastructure, and I presume you mean like OT, right? Like water systems and power systems. >> Um, well, the the good news is that those things have pretty limited space and capacities. So um you know it's difficult for adversaries to get access to them and there's also a lot of legacy protocols and things like that where we have seen them be successful and this is the thing that's scary um you know if you go back to Alquipa Pennsylvania which was targeted by cyber avengers which we associate with hydrokitten Iranian uh threat actor um they got in with a default password of 11111 and uh that was a uh OT system that was presumably connected directly to the internet. So if you have OT systems and you're not hanging them off of a 5G modem and just logging into it remotely, they're more defendable than if if you do that. So um with the right architecture, you can make those things harder targets and uh you know it's basic hygiene for a lot of that stuff. >> I know you're super tight on time, but the point the peer-to-peer botnet takedown was really interesting because it was to me a novel, you know, offensive. We usually think of red teaming as offensive, but this is actually, you know, going after a botnet and that's a a different that's a new escalation of offensive capabilities. >> Well, it was a partnership. We worked with law enforcement. We worked with the Department of Justice. Um, and this was 10 years in the making. So, the Saudi botnet was around for 23 years. And we we had this day zero conference uh that we started the week off with which was separate from Falcon, separate location and we brought together researchers and and industry and government and and all of these different >> competitors I heard. And >> competitors Yeah, for sure. Um but look, it's the good guys at the end of the day versus the bad guys. So if they're selling something and we're selling something, >> it it doesn't matter to the bad guy and it, you know, to a certain extent it shouldn't matter to us. We need to be able to to to hold hands and cross the aisle on something like that. But we brought everybody together and to demonstrate and the three themes of this year's uh day zero conference was deny, degrade and disrupt. Those were the three talk tracks. And so we wanted to really showcase what is the art of the possible. And so the the CIO team had been working with shadow server. We've been working with international law enforcement. And we had developed tens of thousands of lines of code to poison this peer-to-peer botnet. Peer-to-peer botnetss are designed to be resilient. they're be designed to not be taken offline easily. And so the team had to come up with all kinds of novel ways to disrupt this botnet. And then we also had to partner with law enforcement because there were domains that needed to be seized, infrastructure that needed to be seized. And it all came together in this magical moment when uh we actually brought our our our uh chief uh legal officer up to push the button and uh we were able to take over this botnet in real time while everybody was watching and it was I think it was a big win for the good guys at the end of the day. Is it prudent for us to do more of that or like Robert Gates said, don't forget we have a lot to lose as well. Should we see more of that? Will we see more of that? I >> I think we should. I think, you know, bluntly, we do need to uh bring the fight to the bad guys. I think we need to raise the cost of doing business to them, but we need to do it in a responsible way. So, I know that we've talked a lot um uh there's a lot of talk on Capitol Hill and within the administration about uh offensive operations and bringing the private sector into that. Fully supportive of that. I think we just need to make sure that we do it in a uh reasonable and responsible way. And all the conversations I've been involved in with the government, it that's what they're thinking, right? >> Yeah, please. >> That they want to do it in a reasonable, responsible way and through partnership because um you know, they need they need us, we need them, and and it's uh it's it's, you know, a happy day. >> We love that you're on the front lines. >> Thank you. >> We sleep better at night. [laughter] >> Adam Meyers, always a pleasure having you on the show. Thank you so much. busy now. >> I'm Rebecca Knight for Dave Volante. Stay tuned for more of the Cub's live coverage of of this of the Crowd Strike Showelcome [laughter] 26. >> Thank you. Thank you. >> Keep it right there. >> Keep it right there on the Cube. You're watching the Cube, the leader in enterprise tech news and analysis. [music]