Submind YouTube summaries
Thumbnail for Kern Smith, Zimperium | Black Hat 2026

Kern Smith, Zimperium | Black Hat 2026

Watch on YouTube

Video summary

The integration of artificial intelligence has fundamentally altered the economic landscape for cyber attackers targeting mobile devices, effectively removing traditional barriers to entry that once required specialized skills or extensive resources. As highlighted in Zimperium's Global Mobile Threat Report, AI allows malicious actors to execute attacks at a much lower cost while significantly increasing their speed and scale. This technological shift is particularly dangerous because mobile devices have become the primary interface for critical organizational functions such as work execution, banking, healthcare management, and customer engagement. Consequently, these devices hold the "keys to the kingdom" regarding digital identity, making them prime targets. Attackers are now leveraging AI to create highly convincing phishing campaigns that render exclusively on mobile platforms through QR codes or PDF links, bypassing traditional email-based security controls, while also utilizing social engineering tactics via consumer messaging apps like WhatsApp and WeChat where corporate defenses often lag behind. The sophistication of these threats is further amplified by the widespread use of AI-generated content in phishing attempts, which are estimated to be four and a half times more convincing than those written by humans alone. This advancement renders traditional user-centric advice, such as looking for grammatical errors or awkward phrasing, largely obsolete because modern AI tools can craft contextually perfect messages that mimic professional communication styles. Additionally, the adoption of third-party AI within mobile applications has surged dramatically on both Android and iOS platforms over the last year, introducing significant risks related to data privacy and intellectual property leakage. These models are inherently "data hungry," often unintentionally exposing sensitive employee information or sending it to regions where governance policies may not apply. The report notes that nearly one in ten devices is now infected with spyware, a figure four times higher than the previous year, demonstrating how AI has democratized advanced exploitation techniques like weaponizing zero-day vulnerabilities such as Dark Sword, which were previously accessible only to nation-state level actors or those with PhD-level expertise. To counter these evolving threats, organizations must adopt an operational approach that utilizes "firefighting fire" by deploying mobile-specific AI defenses capable of understanding the unique nuances of consumer devices where personal and professional data blur together. Zimperium's new tool, Deep Insights, exemplifies this strategy by enabling on-demand forensic scans that can identify attack narratives and compromise levels within minutes rather than months, effectively shrinking the critical response time gap for CISOs. Security postures must evolve from simple link-blocking to deep content analysis of messages with user permission to detect social engineering intent, alongside robust runtime protections that safeguard code and cryptographic keys against AI-enabled attacks in the wild. Furthermore, governance frameworks need to be rethought to gain visibility into both sanctioned third-party applications and unauthorized open-source components, ensuring that data flows comply with regulations like GDPR while protecting intellectual property from leakage through unvetted models or SDKs. Ultimately, mobile security must be recognized as an indispensable cog in modern business operations rather than a secondary concern often overlooked by organizations focused on endpoint, cloud, or identity protection alone. As CISOs prepare for the upcoming Black Hat conference and beyond, they are urged to reassess their architecture with the understanding that mobile devices and apps frequently represent the weakest link in security chains despite being central to daily business functions. The path forward requires a holistic defense-in-depth strategy that combines advanced AI-driven detection tools with operational capabilities to investigate incidents rapidly without violating user privacy or relying on physical device shipping for analysis. By embracing these comprehensive solutions, organizations can better defend against the rapid escalation of threats where attackers use AI not only to build malware but also to discover and weaponize vulnerabilities faster than ever before, ensuring resilience in an increasingly automated threat environment.
Read the full video transcript
Hello and welcome to the Cub's coverage of Black Hat 2026. This is a special um actually a pre- edition of our coverage um ahead of the Black Hat conference next week. Um we've got a really important topic for you today. We're going to be talking about how AI is changing the economics of attacking mobile devices and why that's, you know, so important and such a threat these days. Um, I have the pleasure today of being joined by Kern Smith. Kerna is the VP of global solutions at Zmpirium. Kern, thank you so much for joining today. >> Thank you for having me, Christa. Looking forward to the conversation. >> Absolutely. I am as well because I know Zirium um has just um introduced some really interesting research that we're going to get into. >> But before we do, I wanted to take a minute to set some context to again really underscore why this is so important today. So we're seeing that AI is um changing the game for attackers. So attackers can move faster. Um they can operate much more cheaply. They can execute attacks much more cheaply. And when it comes to things like fishing, um, they can become much more convincing at scale and really have these targeted, um, attacks. And I know that Zurium spends a lot of time looking at kind of the mobile sphere. And I think that's really interesting because mobile devices have become the primary interface for things like work, banking, healthcare, and customer engagement. And so therefore, um, attackers are beginning to follow suit and really execute these campaigns that are targeted at mobile devices. Um, but you know, one one potential challenge there is that oftent times the industry tends to focus more on areas such as endpoint, identity, cloud security versus mobile. Um, so this is really exposing a potential gap. So Kern, I wonder if you could comment on that through the lens of this global mobile threat report that Zarium just introduced. Maybe start looking at the intention behind the research and um some of the key findings. >> No, appreciate that Chris. Yeah, so for us when we look at the global mobile threat report and the data, it's very much what you said. AI has effectively removed the barrier to entry for bad actors to do bad things against mobile devices because before it used to be a very specially skill set uh there were certain barriers of entry you know people didn't have the training on it but AI has been has no shock to anybody had been a seismic change in the industry especially around mobile security and that makes sense because ultimately these devices in the context of organizations are central to how work gets done. Our data shows over 46% almost half of frontline workers in the US rely on a mobile device to accomplish their job. And when you think about how digital identity is maintained, this is where the keys to the kingdom exists. This is how people log in. All those items are critical. And that's why mobile is a target. >> Yeah, absolutely, Kern. Um, and when I was digging into this report, one of the stats that really jumped out to me right away was, um, Zarium found that fishing events detected on employees mobile devices increased 380% since January 2025. Um, and I'm curious, so is this simply a matter of we're seeing more attacks emerging that are targeting mobile devices or is it maybe simply because attackers really are becoming that much more efficient with the use of AI? >> It it's both honestly. Um, first off, it is attackers are realizing that mobile is a relatively uninvested area when it comes to security. Uh a lot of organizations they may have a management tool of sorts but they don't have actual defense against fishing threats or social engineering much less what's the risk of a third party app or is the device compromised. Attackers have realized that. They also have realized that it's pretty child's pretty trivial to attack or target a user either with a fishing link or a missing link that if you target it on mobile. And we see over half of the fishing links out there will only render on a mobile device, right? They won't render on a um email server or a traditional web web blocking gateway. It's QR codes. It's PDF links. It's all these things that will only ren the these websites that will only render if they're accessed from a mobile device. And the other side of it is social engineering because these attackers realize these devices are in the end they're communication devices. They're consumer devices. And there's multiple ways to social engineer the user that do not go through official corporate communications. Think of messaging apps, WhatsApp, WeChat, you know, text messages. So you combine that with these devices are the key to the kingdom from an identity perspective. Just that alone, they are the target for attackers and AI has unlocked that capability for attackers, bad guys to do bad things on these against these mobile devices. >> Yeah, absolutely, Kern. Um, and I know your report actually found that 86% of fishing attacks >> that today they now include content that is AI generated. Um, in that to your point, this AI generated fishing, um, your report found that it is estimated to be 4.5 times more convincing than human written fishing. So, you know, for your typical employee or your typical user, the long-standing advice has been to look for things like bad grammar or awkward phrasing that would indicate that this was potentially suspicious or nefarious, but now with AI really upping that game, you know, I guess what's the advice that you would give today? Because it seems to me like this traditional advice might not be sufficient anymore. 100% relying on the user um is not optimal because these tools have gotten so advanced. They've gotten so dynamic where they can interact with the user. They can take information from other sources and present a message that makes sense in the context for the user at that point. So it really when you think about it, it's trying to get the an action from the user, convince them to do something. So, it's not just about, hey, looking for somebody trying to be, you know, Microsoft instead of Microsoft or something like that.com. It's think about how you use AI on a daily basis. People are using AI to polish up their own professional messages. Attackers are doing the same thing and this is their profession. This is what they're good at. So it's imperative that to defend against these AI powered threats, you have AI powered defense that is focused on the mobile problem because the problem on mobile is different than it is on an endpoint than it is on a cloud server than it is on other assets because of its uniqueness of that being a consumer device that has a very blurry line between personal and private data and the level of communications that go on from there. So it really grown as a matter of sort of fighting fire with fire, right? And sort of utilizing AI to then combat these AIdriven threats. On the subject of AI, >> so your report also looked at how AI is being used inside mobile applications. >> And what I found interesting was that both on Android and iOS devices, um there was some pretty significant growth um in just the last year. on a Android devices it was 14fold over the last um year and then on iOS it was sevenfold. So I'm curious your perspective on why this matters from a security perspective and why we should be paying attention to this. >> Absolutely. So if you think about it, AI is a fantastic tool and you know we've been using AI since the start of our company almost 15 years ago to create a mobile mobile specific AI to defend against these threats and identify these risks. Um, but now AI has become such a great tool for people who may not have had the technical skill before to take great ideas and craft apps or craft software. Or for people who do have the technical skills, it helps them really automate tasks and kind of deliver things quicker uh to accomplish job functions or get the app out the door at that point. The challenge though is very similar to any other third party code that you introduce into your app. Do you understand the risk of it? Was there unintentional risk introduced into that app that you're developing? The other side of it though is for apps that you were deploying to employees. What's the use of thirdparty AI within that app itself? Because a lot of the times you see unintentional usage or unintentional data gathering. And that's the core challenge when you're using thirdparty AI is that these AI tools by nature are going to be data hungry. they're trying to capture whatever they can to help with their models to help their training etc. And so you need to understand what is the data that you are either exposing within your own app or that you are expo what is the employee data that you're exposing to these third party apps and where is it sending that data to. So there's a very big difference between sanctioned AI that your organization has gone through done the CISO signed off on it. We have data governance versus hey it's a third party open open model that's sending data to a region or a country that you may not be comfortable with potential IP leaking out to. >> It sounds to me Karn like it's a kind of a twofold problem. So as you're mentioning number one, organizations are really struggling to keep track of how AI is being introduced in their applications. And then the second part is that they're having a lot of trouble really um keeping a pulse on like you're mentioning what data is being sent where and how it's being used by that application. So it sounds to me like it's becoming really a governance issue um and that maybe we need to start rethinking the way we're governing our applications. Would you agree with that? >> 100%. It it's a governance aspect. It's gaining visibility into what's going on in these applications. Um it it absolutely is because what we're seeing is that the compliance regimes around this are just they're they're catching up to this. They're they're they're it's constantly adapting based on what the market is finding out. So the demands of the of the organization are going to be having tools or mechanisms in place that can adapt to this rapidly evolving ecosystem of third party AI usage. Uh the other thing I'd add to that on the third party AI usage is that we're not just seeing it being used to code the apps or being injected in the apps but we're seeing it being used also by attackers to target these applications and find vulnerabilities with them within them. So that is a rapid exponential increase in the vulnerabilities of apps that you may have secured them but what can an attacker divine from them if you don't have adequate protections in place of your IP or your code once it's deployed out there. >> Yes. Yeah. I'm glad you brought that up Karin because um I know your report looked about you know these third party SDKs and sort of this kind of open versus closed components and and I wanted to double click on that with you. Um I believe the stat was that 60% of third party SDKs inside enterprise developed apps are closed source. And so um you know pulling on this thread a little bit if the organization can't see what's inside those components how do they then have context into what AI capabilities they're then introducing into their environment? Well, you have to have the right tooling in place and it has to be part of a larger security posture and how you're securing these apps through their entire life cycle from development kind of what we term from development to deployment. So, it starts off with without getting too deep into into process weeds, assessing the app as it after it's being built. So, using tooling to understand, hey, what is in the app? Does it meet policy? Right, as a baseline thing. Then being able to understand once you've deploy being able to then apply protections to protect your IP within the app be it crypto keys be it code be it any number of things authentication chains those type things how do I statically and dynamically protect that app both at rest and at runtime and then ultimately once the app is deployed in the wild how can you get signals so that the app can a defend itself against these AI enabled attacks that are going on because attackers are using AI. We see it every single day just in pin testing alone where people are using these AI tools to try to break these apps and obtain secrets even, you know, even though they may have applied what I would call legacy protections around it. That's why runtime protection is so essential on this. And then being able to allow the app to defend itself locally and then send a signal back to a uh to the organization so it understands what's going on in context out there. you know, is this a thirdparty SDK that's run a muck or is it a bad actor that's just kind of analyzing the app, seeing what they can do, but maybe there's something there or is it a instrument of broad campaign enabled by AI that is taking us for a sizable amount of money and impacting our customer base. >> Absolutely. And that that brings me to um another topic that I wanted to get your thoughts on and sort of you know you were mentioning okay malicious actors you know sort of you know observing in and gathering information um and I know that you know spyware um is something that your report dug into found that it's installed on nearly one in 10 devices um which I found scary >> um and that was I guess four times higher than than you know what Zarium found a year ago. So um what's driving that increase and sort of you know I guess what's the takeaway for you know those organizations that are looking to protect against spyware? Yeah, it it boils down to AI has remove has reduced if not completely removed a barrier to entry to for attackers to do some really bad stuff using advanced techniques that used to be reserved for you know almost nation state level type of attacks. Now it's become a commodity. Um a good example of this is there was a iOS exploit called Dark Sword that was disclosed earlier this earlier this year. um it had been used in the wild. Uh you know there's different elements that you know we have indicators that we were seeing it uh before it was even disclosed. Uh and what what it shows is that when you combine the explosion of these the use of these devices the focus of attackers realizing that they're relatively unprotected both on the app and the device side and tools like u I'm not saying this was used but as an example mythos has been in the news recently. AI tools allow attackers to discover vulnerabilities quicker than they ever had before with less technical skill sets. That's on a zero day side or weaponize existing known vulnerabilities right after disclosure. And that's a big concern because our data says over a quarter of devices now are still exposed to known exploits like Dark Sword. And anecdotally, I'll give an example of this. uh my team and you know some members of my team have different coding skills but some like myself don't have deep you know R&D skills. We are able to take these zero day disclosures and within a matter of days turn them right around and weaponize them for demonstration purposes. Before it used to take serious people with almost PhD level experience to do that and months of effort. Now you're getting people with just a little bit of knowledge and a lot of AI tokens. They can weaponize this in a rapid amount of time. >> Absolutely, Kern. I'm really glad you brought that up because I think we're going to be hearing a ton about it next week at Black Hat. I think it's going to be a major focus because I'm seeing practitioners no matter their particular, you know, area of expertise within the cyber security tool chain. I think they're all looking at as you mentioned mythos and these frontier models and how do they make sure that they can you know try to prevent and be resilient when you know their time to respond just continues to shrink because as you mentioned you know these attackers can move more quickly at greater scale and with greater sophistication too. You know you were kind of alluding to they can potentially um you know kind of tool some of these um different vulnerabilities together. So um you know it's going to be I think a big area of focus and I guess you know what's maybe your reaction to that in terms of from the practitioner perspective um being able to sort of you know respond more quickly to these vulnerabilities. >> It it's a great question. Um I think it demands you AI is a general tool set but not all AI is created equal right especially in the mobile ecosystem you have to have mobile specific AI from a security perspective to defend against these mobile threats but it's not just enough to have that you have to be able to operationalize it and get it deployed in a way that works within the environment works within your use cases and solves the problems that you're that the other thing I'd say is you have to have layers of defense in depth, right? And so that's where, for example, we just released um some major enhancements around our our social engineering capabilities where we don't just look at links or web traffic. It's also we can look at the content of the message with user permission, etc., not violating privacy to say, hey, they're trying to social engineer you. So not just taking a technical approach of was it a link but actually is there intent around this. Uh we are going to be releasing announcing at black hat giving you an early preview a tool that we call deep insights that will allow for users to initiate forensic scans of their device on demand and do deep inspections of that device. That used to take organizations months to obtain that level of information and that level of assurance. We're doing it in minutes and we're doing it at scale in the field. So that's what I mean by you have to have defense in depth and a comprehensive approach around this. And with mobile in particular, you have to have a tool designed to address the problem on mobile. >> Absolutely, Karen. And I'm I'm glad you brought up deep insights because I think the forensic side of things and really kind of reconstructing and understanding what happened in an attack is going to be even more important as we, you know, adapt to and learn from these new types of attacks. Um I'm wondering if you could comment on the announcement sort of um what drove Imperium um to you know to announce deep insight >> and through the lens of sort of I guess the analyst and what information has the analyst typically been missing um that now you know as empirium is sort of filling in with deep insight. No, totally. It's really part of our holistic approach. As I mentioned earlier, we've been AI native for 15 years back when it was called machine learning. Now it's, you know, kind of morphed into AI and whatnot. Um, but for us, it's been about how can we help customers defend against these emerging threats while covering kind of the normal oper while getting it operational, right? Because you can have the best technology in the world, but if you don't get it operational, it's not really worth anything at that point. So part of our strategy has been to bring tooling to the table that offers immense value to our customers and solves significant problems. So an example of that is we recently uh released our sock AI capability that um really allows organizations to investigate these mobile instance without having to have specialy training or specialy background and again giving them visibility they otherwise didn't have or reducing the amount of time to investigate these threats from it used to be 8 hours to now it's minutes basically that deep insights is that next step on this journey on this AI journey where based on feedback for customers. They really have kind of what I would call a couple core use cases. One is um pre-travel, post-t travel inspection. I took my device on a trip to an area that u maybe there's some industrial espionage going on. Maybe not. I want to know what it looked like before, what it looked like that when I came came back and ensure that there wasn't anything weird when it going on if I left it in the hotel room as an example pre-post trip. The other one is um general incident response. Hey, Zurium said something is going on here. I need to do a deeper inspection and gain some deeper insights into what the kill chain was on this. Was it because a WhatsApp message was sent that contained a JavaScript exploit that then, you know, triggered a a kernel panic and then etc etc. All of a sudden, the device is compromised. What what was actually forensically going on? And then ultimately what could have potentially been removed from the device from a risk or a threat perspective. Um then the last thing is just programmatically hey I have VIP users they are going all over the place just as a measure of assurance no different than I do with all my endpoints for VIP executive users. I want to do an ondemand deep scan of that device just to ensure we didn't miss anything. Right? Because the risk of that time gap of something happening and us not being aware, the more you can shrink that, especially especially on mobile, the better off you are from an overall security perspective. And most organizations have never had that capability of shrinking that gap or even getting visibility in the first place on that side. >> Yeah. And I think so as you mentioned sort of you know shrinking that time gap and allowing that response to happen more quickly um is is very critical and it makes me think her about sort of this um conversation that I'm tending to have a lot these days which is sort of okay the two sides of the coin between you know the investigation side of things and um the detection side of things and so um with the deep insights announcement I'm wondering if you can kind of comment on why the quality of the investigation matters even just as much if not more as the quality of your detection capabilities these days. >> 100%. I I view them as linked together. You have to have all of them to be effective from a security perspective. And they all have to kind of interconnect and work work together with each other. So if you think of it, it's you ultimately have to have something on the device to defend against the exposure, identify the risk and defend against the threat where it occurs. That has been our what we call MTD or mobile threat defense without getting too deep into product terminology. Um but it it it's effectively hey defend against the fishing threat, defend against the risky Wi-Fi, defend, you know, identify, hey, you've got malware or spyware, something bad going on there. Then you go into other advanced capabilities like okay now I need to defend against social engineering. Well how do I do that and also balance user privacy? Well that you need to use some AI classifiers that can do that in a way that apply protections in a way that can also be leveraged for organizations. Okay. Then you get into now I'm getting telemetry from the device. How do I absorb that within my sock within my ecosystem? So, it's not just enough to get a stream of threats and whatnot. Anybody can do that. It's are the forensics relevant? Do they apply GDPR protections? Are they, you know, do you have different levels of threats and responses based off of groups? And then it goes into taking that information using mobile specific expertise and AI tools have been trained on that expertise to do an analysis to say to the sock, this is an incident you really should pay attention to and here's why. Here's the attack narrative. Here's what's going on. And oh by the way do that deep inspection so because as an app you only have visibility is so much but if you do a deep in forensic inspection of the device you can get much better attribution on what happened within the kill chain what the exposures were etc etc etc. So let's do that and let's do it in a way where you don't have to physically ship the device from one place to another wait for a third party to do an analysis spend months waiting for the result. let's do it in a way that allows the user to initiate it and you get a response in minutes at that point with really no loss in fidelity at that point. So that's part of you know balancing both you have to have top-of-the-line emerging approaches to defend against the threat and identify the risk and use AI to defend against that right right tool for the right job but then you have to have the operational capabilities and kind of the experience on okay great to have this in theory how do you operationalize it to show to give value to your customers and that's ultimately what we're doing on both sides best of breed raw capabilities but also trying to do best to breed. How do you get this off the shelf and get value out of this? >> Absolutely. Because it doesn't have value if it's not operational at the end of the day. >> Exactly. >> Um, absolutely. And I know that's one thing that, you know, CISOs in particular are struggling with and Kern, I'm sure you're going to be sitting down having a number of conversations with CISOs next week at Black Hat. Um, as we start to wrap our conversation here today, um, I'm curious if you, um, were to encourage CISOs to maybe, um, you know, make one change over the next year. Um, what advice would you give them or what convers? >> Oh, one piece of advice. Oh, now now I got to really think about think about that. Um, I I think the the piece of advice I would say is think about where your business is really run through. And what I mean by that is how does your organization interact with its customers? How do your employees do their job on a daily basis? And yes, much like we're sitting talking on a computer, there's still phones that control identity. They control the keys of the kingdom. The same level of access are there. So, do you feel comfortable with the visibility and the defense you have on that asset? The same goes on uh mobile applications or the customer interaction. Increasingly, how customers interact with organizations, they go to a payment terminal, they sign in on a on a tablet of some sort or it's go download this app to do the transaction. How is your business really running? And what is one of the indispensable cogs in that business? 99% of the time when I talk to CISOs about that, regardless of the organization type, public, private, you know, public sector, private sector, any of the any of the different verticals, you start pulling back the layers of the onion. It's like mobile, be it a device or an app, is an essential cog to how that organization operates. And it is often the most undefended. It is the weak point of any security architecture with most organizations. >> Well, Karin, I couldn't think of any better point um to conclude this conversation on. I think that really kind of hits the nail on the head in terms of everything we've been talking about how really mobile is that you know that critical point um here in this chain. So, I wanted to thank you so much um for joining us today. Um I hope you have a great event next week at Black Hat. I hope we can find a few minutes to catch up and um I'm sure that you're you and the team are going to be very busy um talking about this research um you know and everything else. So um again thank you so much for joining um and thank you to our audience for joining as well. Um again this is Christa Casease, principal analyst with the cube. Um you are listening to some of our pre-B black hat coverage. Um and we're going to be coming to you live um all next week from the Mandalay Bay in Las Vegas. So, we hope you'll join us and um we're looking forward to it. Thanks so much. >> Thank you. Take care.