Selena Larson, ProofPoint | theCUBE + NYSE Wired - ProofPoint Protect 2026
Watch on YouTubeVideo summary
The discussion centers on the evolving landscape of cyber threats in 2026, highlighting a distinct bifurcation among threat actors driven by the adoption of Artificial Intelligence. While elite threat actors are leveraging AI to streamline operations, enhance social engineering, and accelerate malware development, lower-tier attackers often struggle with implementation, resulting in sloppy tactics such as exposed domains and poorly crafted phishing kits. This divergence suggests that while AI has made attacks more sophisticated for top-tier groups, it has also created a false sense of security for less skilled adversaries who rely on automated tools without fully understanding their limitations or the nuances of legitimate communication.
A significant shift observed is in the scale and automation of campaigns, particularly regarding language localization and evasion techniques. Threat actors are now capable of deploying attacks across fifteen to sixteen languages simultaneously, utilizing AI to generate natural-sounding content that previously would have been difficult to clone authentically. Furthermore, attackers are experimenting with sophisticated filtering mechanisms to bypass sandbox environments and honeypots, employing unique puzzles or behavioral triggers to ensure payloads reach real human victims rather than automated security systems. This rapid iteration cycle has diminished the effectiveness of static detection methods based on Indicators of Compromise (IoCs), forcing defenders to adopt dynamic detection strategies that anticipate new attack vectors in real-time.
The conversation also addresses the critical role of human oversight and the concept of "human-centered security" as AI agents become more integrated into enterprise environments. There is a growing concern regarding supply chain risks, where autonomous agents could inadvertently introduce malicious code or fail to validate software updates within continuous integration pipelines. Experts emphasize that while AI can enhance behavioral detection by analyzing context—such as verifying if an employee is on vacation before flagging unusual email activity—the ultimate responsibility for agent governance remains with humans. Without proper training and accountability, organizations risk deploying rogue agents that act based on flawed instructions or lack the necessary security protocols to prevent data exfiltration and account takeovers.
On the defensive front, ProofPoint highlighted a recent success story involving the disruption of a sophisticated "fishing as a service" kit used by state-sponsored espionage groups. This operation demonstrated the tangible impact of international law enforcement collaboration in taking down threat actors who were selling automated phishing tools generated with AI assistance. Additionally, researchers noted the emergence of "patch gap zero-day" exploits, where adversaries reverse-engineer vulnerability reports to create malware before patches are widely rolled out, a process potentially accelerated by AI capabilities. These developments underscore the need for organizations to move beyond basic blocking tactics and embrace a proactive stance that combines advanced automated governance with vigilant human supervision to counter increasingly agile and intelligent cyber threats.
Read the full video transcript
Palo Alto Studio Connection Silicon
Valley and Wall Street. I'm John Fost
here with Dave Volante, my co-host,
host of the Cube. We are here in San
Diego for Proof Point Protect 2026, part
of our NYC wired program and our open
community. We're unpacking all the data
around security in the enterprise. As
ages and data become more prevalent,
cyber security posture changes. We have
a cube alumni back on threat research.
Selena Larson back formerly on at
another conference Mise which is no
longer around which is really one of the
premier threat conferences really
talking about the bad guys on all the
nation states. Great to see you.
>> Yeah thanks so much podcaster
researcher. So first of all
congratulations on uh the continued
podcast and getting the content out
there.
>> Thank you.
>> But I really want to dig into a last
change since in the past few years. Last
time you were on was 2023. Mhm.
>> AI continues to thunder away, but the
game has gotten much higher level action
>> on the threats, more organized, more
complicated, and more effective.
>> But AI has come on the good side, too.
So, what's different? Give us that
lowdown between, you know, 2023, the old
way seems like yesterday and today.
>> It does feel like yesterday, actually. I
think about I was like, wow, that was
three years ago. Um, and that really was
I feel like in 2023 when AI was just
emerging, people were using it uh in
their own environments and threat actors
had started to adopt things. So, I would
push back a little bit on this idea that
things have gotten better and attackers
have gotten smarter. I think that in
some ways they have, but in some ways
they're regressing. And I think it's
been really fun to see because for many
of the threat actors, they're using AI
in the same way that defenders are to
streamline their operations, to um make
their social engineering a lot better,
right? And some people are using it for
marketing or styling things like that.
And uh they're also using it in their
attack chains. But what's really
interesting is the good threat actors
are using it very effectively and are
cutting down the time it takes to
develop something such as malware or um
spam delivery, things like that. But for
bad threat actors, the sort of bottom of
the barrel folks, the low hanging low
hanging fruit so so to speak, they're
adopting it. And yes, it does make some
of their attacks a little bit more
believable. their social engineering is
a lot better. You know, we were talking
before this started. The emails look
really believable. The the um the
language is there. The design is is is
pretty good. But what we've seen is
actually regression in techniques. So,
they're not necessarily as effective.
So, they'll leave things exposed on the
internet.
>> They get sloppy.
>> They get sloppy. It's very, very sloppy.
>> All right. So, you're pushing back on
the fact that um AI the good guys are
not getting better. You think they are
getting better. I think the good guys
are getting better
>> and the bad guys are bifurcating into
the elite.
>> Yes.
>> And the idiots.
>> Absolutely. Yes.
>> Well, I I say this because um um a quote
on the cube recently, I won't say who
the person was because it may be taken
the wrong way. Uh she said, "AI makes
smart people smarter and dumb people
dumber."
>> And I'm like, "Okay, that kind of
hangs." But let's just get about the
implications. It's kind of true. If you
really don't know what you're doing, you
get false sense of security. And you
were referencing that because I think
that speaks to some of the sloppiness.
>> We used to call it kitty scripts back in
the day. Remember those those kind of
porative terms, but what has that done
to the to the artifact? So what's been
the impact of this? Has there been a
backlash in amongst the bad guys like
hey say let the let the big players take
the big game boards. It's just too much
for everybody.
>> You know that's really interesting that
you bring that up. So Wired a couple of
months ago published a great look at how
threat actors and hackers are responding
in some of the forums to the adoption of
AI in tooling and and and marketing and
things like that and they don't love it.
And so a lot of this
>> don't love it in which way
>> they well they were like get this AI
slop out of out of
>> they have their own slot problem.
>> Well yeah cuz they're like I don't want
to read this like can you I just want to
buy this tool. Why are you adding these
things that I don't need? It doesn't
work anymore. So they are getting
frustrated with the thread actor
adoption of swap and at the same time
you have thread actors that are using AI
tools to build things like fishing kits
for example using um device code fishing
right so they'll make a really sleek
landing page and says oh this you know
impersonating Microsoft or docuign and
then they'll have a code to input it to
to legitimately associate an application
a malicious application with your
Microsoft account but if you look at the
rest of the attack chain the panel
itself will be exposed um the domain
won't be very believable. The lure
itself, if it's using something like
social engineering, sometimes it might
be pretty good. And sometimes the email
is just blank because they don't know
how to actually do like mouse.
>> They're bad at marketing.
>> Yeah. They're just they're just not very
good at marketing their own security.
>> Yeah. Yeah. So, we have so we have these
sort of these these slop actors that are
doing a lot of that. But then you also
have some pretty creative thread actors
and and thread actors who have done
malware development in the past who have
created really unique and interesting
loaders or botn nets and things like
that. they're also adopting AI and you
can see it in their code, right? Because
nobody comments their code like an AI
comments code. Um, and so you'll you'll
see that throughout and they'll say this
is what this JavaScript does or this is
what um where you can like insert a
specific Python or this is a a specific
command or PowerShell um or even if
you're looking at um something like um
something like a loader, it'll be like
insert the file here, like the file name
here, things like that. So you template
>> it's a template. Yeah, it's very much
templated. and for the threat actors who
are really good at it. It can be fairly
effective. Um, and you can and it's just
sort of making them better. But I think
that's that's fewer than what we're
seeing with the adoption of slop. And I
don't want to say that just because it's
sloppy doesn't necessarily mean it's
effective because we've throughout
history have seen social engineering
that might not be super sophisticated be
very effective.
>> I mean, if someone's taking a one shot
at something, they don't really care
what it looks like after. It's kind of
like the software factory cares about
>> garnage whatever bad code laying around.
What has it done for me? Let me ask you
this on your research. There's been
themes of hey the the basic blocking and
tackling kind of techniques are just
getting better and faster. That's kind
of a proof. Got to deal with those with
machine speed. But there are new things
emerging. What is new? What's emerging
that you haven't seen before that AI has
enabled? Has it been better
coordination? has it been just new ways
scale understanding better social
engineering combined with other things.
>> Yeah. So I think scale is a really great
one. So historically what we've seen are
thread actors will tend to target
specific languages, specific geographies
and with with one campaign and then
maybe a few days later if they are a
threat actor that targets multiple then
they'll switch to a different language.
What we've seen in some cases is up to
like 15 or 16 languages and lure themes
that target a broad variety of
geographies. It's a really uh carbon
copies of each other, but the language
changes. And so you can tell that
they're using some type of automation,
some type of scripting to be able to
clone essentially the original um the
original lure. But because AI is really
good with natural language, they can
make it seem a little bit better.
Whereas historically, if you were trying
to clone something into 16 different
languages, it probably wouldn't look
natural. It wouldn't look legitimate. So
things like uh for example, Japanese or
Korean, uh the the AI has improved those
templates quite a bit. Um and yeah, so
we'll so we'll see a higher volume in
campaigns. Um the other thing I think
that we've seen more of is just
experimentation on filtering. So what
I'm what I mean by that is when a thread
actor is trying to send high volumes of
of URLs for example and they're trying
to make sure that only you get it there
is a trick that they'll incorporate
either something like geo filtering um
IP filtering or something like a capture
where you have to solve a puzzle in
order to get the payload. They want to
make sure that it's a real human being
that's actually getting the fishing
payload and not me and my sandbox
getting that. So we've seen a lot of
experimentation in that aspect of it.
>> So they figured out the honeypotss, they
figured out all the little tricks, the
sandboxing.
>> Yeah. So there So they they kind of know
how to do some some sandbox bypassing.
So it'll be like, "All right, I'm going
to come up with this capture that no
one's ever seen before. Some sort of
weird puzzle or
>> No bicycles.
>> No bic. Yeah. No more bicycles. No more
stop lightss. No more Yeah. cars. How
many cars is this?" Um, but I I think
I've seen ones that are like little like
fish emoji and then it's like figure out
the strawberries like weird just weird
things like that. So they've they've
they've changed that up a little bit and
with every new iteration of that it's on
us as defenders to be able to come up um
with more sort of dynamic detections.
And so one thing I think is really cool
from our perspective as the defenders is
that um historically you know static
detection on IoC's and landing pages and
stuff could be pretty effective because
they would be used for a prolonged
period of time. But now the time of the
or the length of time that that static
detections are valuable or useful has
really decreased because of the rapid
iteration and development of the the
payloads and the attack chains. So it's
on us to be really creative. It's like,
okay, how can we come up with some
really interesting dynamic detections
that we can anticipate? Okay, we think
that they're going to try another type
of filtering so we should create
detections for this to to preemptively
block it. Essentially,
>> the intelligence, that's where I think
to your point about the AI is getting
better on the good side is because, you
know, there's real time stuff on the
defense. Okay, we know what that is.
Kill it right away. Um, but then there's
like the more complex things that look
normal like
>> that's the mechanisms are all working.
There's no malware. Email comes in. Oh,
you run accounts payable.
>> Yeah.
>> Oh, there's all the suppliers on your
email. Let's just email them, too. One
owes money. That's So, there's all this,
you know, kind of like living off the
land by accident on purpose. You're
like, okay, I'm not living on the land
like hanging around. I'm actually just
discovered
>> all these new people.
>> All I got to do is get one of them.
Yeah.
>> So, there's all these techniques, but
that doesn't look like it's def like
breaking anything. So the psychology of
the data was why I'm intrigued by this
knowledge graph element because you
might say oh John is running accounts
payable he's on vacation and in Slack he
already told the people there's some
data so like this other context
>> how is how is that defense helping any
new ways to pull in that the psychop
side of it
>> to the defense side
>> yeah so I think that's one way where AI
can be really interesting in terms of
behavioral detections. So, like you
mentioned, oh, so and so is out of town.
Um, also things like misdirected email,
if there is a CC, a BCC or a reply to
that's unusual or outside of the scope
of like what someone might typically
reply to. Um, then you can say, "Oh,
wait. This seems out of the ordinary.
This seems like, you know, that
something that we should flag on. Are
you sure you want to send this email to
this individual?" um or if you receive
it on the recipient side something like
this is a this is a suspected you know
or a domain that doesn't have a
longevity this is this is suspicious so
I think um things like that can be
really effective um and then same thing
with like you know like looking at data
loss and the data loss landscape and the
insider risk too right because when
you're a threat actor who has done an
account takeover and gained access to
some something uh I uh I think detection
opportunities are something like
malicious apps that might be added to um
to the uh account itself. So this is
something that's suspicious. This is out
of the ordinary. This does this name
doesn't align with our existing
enterprise applications. This is
something that we should investigate. Um
and then also to downloading uh various
uh files, trying to excfiltrate that
that type of data. So kind of paying
attention to where it's going um and
what authorization and what uh sort of
identities are enabled within accounts.
My uh my my interest on agents is
interesting where because agents remind
me of when Facebook came out with
misinformation. It wasn't the network
effect and the the graph. It was the
content was the payload.
>> And Facebook just wasn't paying
attention. Yeah.
>> So the theme we're hearing now in AI is
that we want to pay attention to the
trust.
>> Yes.
>> The agents will do what they're told.
>> Yes.
>> So how is agents because they can be
weaponized
>> just like Facebook was weaponized for
misinformation. That conversation is
starting to lurk around in the
mainstream now. We're saying, okay,
agents are going rogue, but are they
really going rogue and also if they can
get weaponized taken over,
>> that's an interesting dynamic. What data
are you seeing on the agent front?
Because this is then brings in the
question of okay, I got the good agents
and the bad agents. There's espionage
going on. So there's like they're
crafting their own civilizations.
>> Well, that's an interesting way of
putting it.
Um I think
>> can they form can agents form as a
digital twin of the threat actors?
>> Um I think if they are programmed to do
so. So I don't necessarily think that we
are going to have some sort of rogue um
rogue robots like help open the pod bay
door how no um I don't think that that's
necessarily coming up in our in the near
future. Are there any threat land uh
vectors around agents that kind of give
signaling?
>> Yeah. So, one of the Yeah. One of the
the more interesting things I think
about about this and is is supply chain
for example. So, um and I actually just
brief aside when you mentioned you think
about it with Facebook a lot as sort of
the original agent. When I first got
Facebook, I remember it was posting
everything that I listen to on Spotify
to Facebook. And I was like, "Wait a
second. Why is everything that I'm
listening to on Spotify automatically
being posted to my Facebook page and
people are commenting on it? This is so
weird." And that was like, "Wait a
second. I don't have the proper
restrictions in place. I just sort of
added something to my account.
>> Install on some appreh."
>> Yeah. And I didn't necessarily
understand how it worked or what it was
talking to or what data was going to be
shared with what account was going to be
shared with.
>> At least she didn't throw MySpace widget
on there.
>> Oh yeah. Wow,
>> those are the first generation of spam
takeover of Facebook.
>> Yeah, I mean that's how I learned to
code was MySpace that marquee scroll. I
got that. So, but but that's a really
great analogy that you bring up in
thinking about Facebook because that's
how I think about agents. If we're just
installing any sort of agent on our
devices without the governance aspect of
it and without understanding, you know,
what accounts are talking to it, what
information is being uploaded, what is
this AI doing with this information? Um,
who has access to this information? And
I think I think it's a little bit uh
parallel draw some parallels with the
cloud as well too, right? Because it
used to be like we're just going to
upload everything to the cloud and then
guess what that was
>> bucket was open. The S3 bucket told me
about Yep. How many data breaches did he
have because of exposed S3 buckets?
>> And that's the same thing no one told
me. So there's kind of a rules of of the
road. So I guess my question is as you
look at as you look at the threats
>> um that's just humans got to keep up. So
it's kind of like basic blocking and
tackling but also that's net new. Oh, we
didn't know that.
>> Yeah. Well, so I think you know going
back to this idea of supply chain and
that I think is something that's pretty
interesting because if you look at um
essentially maybe agents pushing
malicious commits into a GitHub for
example and then having a uh uh the
autonomous development pipeline just
automatically accept things without
review that could potentially lead a
malicious agent to upload itself
essentially into your own network. So if
you are just relying on agents to uh do
this this this security and do the
auditing and you're just pushing accept
on things um because you you just trust
that it's going to be secure. I think
that that's where we're going to get
into some issues and we've seen poison
like supply chain poisoning in Python
packages for example or um on GitHub or
in um various coding repositories. And
right now what we're seeing within the
enterprise is an automated continuous
integration and a continuous development
pipeline. So organizations are just
relying on things that are already in
open source or already in um these
various gits.
>> So the CI/CD pipeline was never really
programmed to do software supply chain
validation except for containers.
>> Yes. Right. It was it was something that
we're just like okay we're just
>> it's working until it doesn't work.
>> Yeah. Yeah. Right. Right.
>> Threats here.
>> Yes. Exactly. We're doing a sprint. We
have this and oh wait a second now we
have potentially rogue AI.
>> Yeah guys I got to get my margarita in
10 minutes go. Like
>> exactly
>> that's human error. That's back to the
human piece. That's why I like the proof
points perspective. It seems to be a
much deeper
>> thought process around
>> the endpoint relationship to the user
>> and then the agents on the inside.
>> Well,
>> so there's a whole another level of
two-sided
>> Yeah.
>> human agent relationship.
>> Yeah. Well, and I think one of the great
things that I love about Proof Point and
have we've really adopted this since I
since I have embraced it since I've been
here is this human centered security and
I think that you know as we're moving to
an agent centered security there's
always going to be the need for the
human in the loop and I think that AI
and and agents and agentic development
and agentic socks for example um like
security operations that are AI enabled
what we're doing is effectively just
giving the human more power more tools
more resources human. Don't you think
like a manager would have direct reports
that humans should be responsible for
agents because makes sense like hey what
happened I don't know an agent got loose
I don't know who's from fleet it's from
reports to that's Selena's agent not my
agent proven
>> don't point fingers here that wasn't my
agent like not my agent his so I mean
but this comes back down to okay whose
organization because it's work it's an
extension of work
>> almost look as you're an operator of
agents a manager of agents the human has
to take
responsibility.
>> There does have to be some
responsibility because I mean,
fundamentally, our AI is only going to
do what people tell it to do.
>> And you know, we don't have AGI right
now. We don't have robots that are like,
you know, building themselves. And we're
essentially they're all reliant on the
person that's telling them what to do.
And we do run into some issues where if
you have someone who isn't necessarily
trained or knowledgeable about what
they're doing, for example, a threat
actor creating malware but not knowing
how to put their botnet panel behind,
you know, secure resources, so you can
very easily take it down. Um, you have
the same thing from a defender
perspective. So if you're not,
>> so it can go, it can get loose without
it's just by accident. I was trying to
do this, but everything else happened.
>> Yeah. So that's why I do think that
there are some like really great
opportunities for um for automated
governance, automated um detection of
some of these rogue threats and making
sure that you're you know you have these
um tools and protocols in place that
your your AI can tell the person are you
sure you want to do that or uh you're
going to this data is going to be sent
here is this compliant with your
>> talk about the um the organizations that
have you know have become companies I
mean mal malware's been out there and
ransomware you can buy ransomware as a
service. We've covered that years ago.
>> Yeah.
>> Are there yet agentic as a service acts?
>> I'm imagine this just another extension
of as a service
>> on the higher end. Is what's going on
with the big actor, the threat actors?
>> Yeah.
>> Is there any movement on crushing them
and getting
>> crushing them? Yes, we're always
crushing them.
>> Well, Mwise, we talked about not just,
you know,
>> give slap on the wrist, kneecapping them
out completely and arresting them. And
that was something that came up
>> like taking them off the streets
literally.
>> Yes. So there is a lot of efforts and
continued efforts on that. Um for
example, one of the efforts that we
participated in recently was the
disruption of the tycoon uh fishing kit.
So it was a multiffactor authentication
of fishing as a service and uh we were
able to work together with some private
public partners to be able to um do that
disruption. a civil lawsuit filed by
Microsoft in uh in with support of
international law enforcement was both a
online disruption and it did have some
real world impact with you know
congratulations taking people down.
Yeah, I was very excited.
>> Get a challenge coin.
>> Uh I didn't get a challenge coin.
The challenge coin is the friends we
made along the way.
>> Yeah. Yeah. Know but it's also nice
because that's like you can actually
that's tangible impact.
>> Yes. Absolutely.
>> Not just reconstituting with the gang or
whatever.
>> Yeah. Well and we're seeing that now
with um various malware. So you're
asking if there's AI as a service. What
we are seeing are different thread
actors using AI to build services. So u
for example fishing as a service like I
mentioned before device code fishing as
a service is something um that is quite
popular in all of the device code thread
actors are using AI to build these
tools. Uh we also see um for example um
clickfix as a service. I'm not sure if
you're familiar with clickfix but
essentially clickfix is a technique that
uh thread actors will use to compromise.
They'll compromise a website and then
you'll see a little popup that says your
uh Windows is out of date. Copy and
paste this com like Windows run which
opens PowerShell and then copy and paste
this command and then it'll be it'll be
up to date. Of course, that's copy
pasting and run PowerShell that installs
malware and etc etc. It's bad. But that
was quite popular with a handful of
pretty bespoke and and sophisticated
thread actors. But now what we're seeing
is a threat actor cluster um that's
actually doing that as a service. So
thread actors can pay them to be able to
use their AI generated clickfixes
essentially. Um so they'll you know be
be compromising these websites using
this this actor created clickfix. So
they'll they they are using this
automation and tooling that a thread
actor is selling. So I'm not sure if
we've seen sort of AI agentic solutions
in the same way that we're seeing AI
enabled threats be sold and repackaged
as as a service.
>> You know this is so fascinating. There's
so much going on and love the success of
the take down of the organization with
the law enforcement and taking them
offline with disruption. Um what I'm
noticing is is that there's been a real
generational shift. We're seeing it at
the political level. Yes. Of I just
don't trust anyone anymore. I don't care
which party you're from. Seeing that now
play out on the on the national scale.
There's kind of a CEK version going on.
>> And I'm an ex generation or so. You
know, we're the last feral generation as
has been been described, but you know,
I'm old compared to the young guns
coming in now. But like there's a whole
mindset of like there's a whole new way.
Are people changing their expectations
on how they interface? Because most
people that didn't grow up on the
internet I know what a domain name looks
like so I can tell by the URL but
techniques are so good now that the
younger generation are seeing new
popups.
>> Is there a trend to go headless and go
you know I won't say analog but like
minimalistic. Yeah.
>> On interface. Are you seeing any
generational patterns around the
consumption side? that's more safer.
>> Yeah,
>> maybe less functional
and generational shift on the attackers.
>> That's a great question. You know, I
have seen some Tik Toks from the Zoomers
and Gen Alpha that are basically like I
want to go back to the '9s and like
they're they're like they're missing the
flip phone that they never experienced
um or no one calling them up.
>> Well, I mean, I have seen that all over
just in my own neighborhood and in I
live in Washington DC. There's a big
movement to do like a no phone two weeks
where you lock up your phone and just
kind of
>> try January.
>> Yeah. Exactly. And like live analog, but
I think that there there is some of that
because I feel like, you know, Gen X and
I'm I'm millennial so we were you know
kind of grew up as internet natives and
we never trusted really anything. And if
you look at historically um looking at
the the behaviors and who gets defrauded
the most, it's it's usually the older
generation. But now you're seeing a lot
more young people that are that didn't
have that digital native experience that
that transition from
>> they'll sign up for anything,
>> right? Yeah. Yeah. Or click on any link.
>> Yeah. Or on TikTok, they'll be like, oh,
I you know, would you like to be an am a
brand ambassador and here's some free
clothes if you send us, you know, 50
bucks or whatever. So for shipping and
so you have this sort of like this this
generation where they're getting scammed
a lot more than I think historically we
were able to. And I do think that things
like AI, deep fakes, um, improved social
engineering really do play a role in
that. And so I think the natural
progression of that is for people to
push back and say, "Wait a second, like
I don't like this. I want to go back to
when it was the '9s and we had, you
know, we had to call me on my house
phone to to hang out." Um, so I I do
>> at 10:00 on the corner, like, you know,
actual real communication.
>> Yeah. In fact, I'm I'm mentoring a
teenager and he's like, "I actually
prefer phone calls. Can we can we have a
phone call as opposed to like text or
email?" And I said, "Yes, we absolutely
can."
>> Of course, you're a podcaster. You're
like, "I'll talk all day long." You
know, like
>> I love yapping.
>> It's funny. Podcasters love I was
talking to someone in support. They
said, "Anyone who likes podcasts like to
call support the support number." So
bloggers would all email.
>> They all email. Look, I don't mind
waiting on hold. You know, I you know, I
have to I do have to say though, if
we're talking about people being
frustrated about technology, I've seen
so many people be so frustrated with
like AI support bots and like this the
call centers. is just like I miss
talking to a human. Like I just want
help. Like
>> we know you're not real. At least be
good, not real.
>> Yeah. Just pretend to be good at this.
Yeah. Yeah. So that's
>> all right. So what's the coolest thing
you've worked on the past year that or
couple things that were either cool you
didn't see coming or cool you knew was
coming? What were some of the cool
things you worked on?
>> Well, I actually am I allowed to say
something that I didn't actually work on
but my team did and it was really cool.
>> It's something cool that people might
see and be motivated.
>> Yeah, absolutely. So, one thing that we
have recently published information on
is something called um the blue moon
exploit chain. And this was really
interesting because my colleagues
discovered an attack chain that was used
by a variety of Chinese uh espionage
thread actors and it chained together
multiple vulnerabilities in Chrome and
Windows. But what was really interesting
was and if we're talking about AI and
the use of AI um they uh the the actors
actually were able to create something
called a patch gap zero day when someone
identified a flaw a legitimate
researcher identified a flaw in Chromium
published that information here's uh
here's this bug uh Chromium and the dev
tools were able to sort of um fix it and
adapt it but there's a two week two to
four week gap between when something is
patched in Chromium and when it's rolled
out broadly. for everyone on Chrome and
using the Chromium build. So between the
time that that was reported and the time
that it would have been patched, the
thread actors were able to create um an
exploit to uh to to to use this
vulnerability. And um while we don't
know 100% for sure, we do suspect with
fairly high confidence that the thread
actors were able to essentially reverse
engineer and create with AI this uh
exploit that was related to um that this
this post um that was actually the bug
report for for Chrome. So u my
colleagues named it the blue moon
exploit chain which was very interesting
and it was used by Chinese adversaries
but it has but since been adopted um by
more threat actors
>> so the date reverse engineer the note or
the timing the clock's ticking go get it
exploited.
>> Well it was the actual it was the actual
report. So these these bug reports and
open source bug reporting is very very
like detailed and so you want to be able
to say here's everything I found here's
how to fix it and they'll say yep thank
you and then then go ahead and do that.
And while it was patched, it was fixed.
Um, it does take a little bit of time to
sort of roll that out in the patch gap.
So, that was actually pretty interesting
and I have to give a shout out to my to
my team for for finding that.
>> All right, nice prop. Anything else?
>> Um, I would say I don't often see
interesting AI developed malware, but
there are a couple of of recent malware
families that we have found that are
created by pretty sophisticated malware
thread actors that are are making uh
making voters a little bit more
interesting. So we'll hopefully have
more to share on that in the coming
weeks.
>> We'll we'll wait to see. Get busy
working. So thanks for coming on. Thanks
for the great conversation and the
insights and commentary. Appreciate it.
>> Thank you so much for having me.
>> John F with the cube. We are here proof
point protect 2026. It's part of the
NYSC wired program and community. Thanks
for watching.