Video: A Framework for a World Where AI Exploits Vulnerabilities Faster Than Ever | Duration: 1796s | Summary: A Framework for a World Where AI Exploits Vulnerabilities Faster Than Ever | Chapters: Webinar Introduction (28.18s), AI-Powered Hacking (208.4s), Future Threat Landscape (499.565s), AI Readiness Framework (751.25s), Defender's Advantage (1065.615s), AI Agent Workflows (1214.92s), Partnership and Optimism (1576.465s), Q&A and Closing (1734.66s)
Transcript for "A Framework for a World Where AI Exploits Vulnerabilities Faster Than Ever":
K. I think we're giving everybody a second to join, and we'll get started. We'll give it one more minute, and then we'll start. You see a lot of people joining. Okay. I think we'll get started. So hi, everybody, and, thank you so much for, taking time of your day and joining us today to talk about AI. It's nontrivial as I'm sure everybody's sick of talking and listening to it. But, we we did feel like we wanted to do this webinar to really kind of share a bit of the insight of how we are thinking about a framework for preparing for this new world where AI does find and and and is able to really build, like, sophisticated exploits in very, very fast and kind of sharing what we believe this means for organizations, how we're thinking about what is, like, a right framework of helping and making sure that we are prepared, and also sharing a bit of, like, how we see things from the research perspective. So I'll get ahead and, I'll go ahead and I'll share my screen for a second to go over the agenda and get started. Here we go. Okay. So today, first of all, we start from a research overview, by Alon, and I also realized we did not introduce ourselves. So I am Roz. I'm CMO and VP product strategy at Wiz, and we have Alon Schendel here. Alon, is our, VP of research and leads the research team. And Alon will be taking us first from a research overview of what we are seeing, what changed, and how we're thinking about it in terms of, like, real life capabilities of those new models. Then I will talk a bit about how we're thinking about building a framework for what we think of as AI threat readiness. I'll it will be mostly intentionally. Right? It's non it's not a WIS only framework, but rather a generic framework about how we are thinking about this. And then I will talk a bit about about how WIS helps address some of it. But truly, mostly, it's an example to explain what we mean, and they'll even do, like, a five minute, demo at the end. Really more from the perspective of explaining how tools can now help, protect. So the goal today is really to keep the discussion as much, like, nonwiz as possible. But they will talk about wiz because this is, like, almost my example of how we are building tools to protect. And with that, I will move it over to Alon. Thank you, Raz. Hi, everyone. It's, and thank you for attending today's webinar. We're going to start with a very bold statement. Hacking has been democratized. And, I mean, everyone is talking about Mythos. Mythos was but but for us, Mythos was just another point in a trend that we've started seeing, last year with, how LLMs can do, cybersecurity tasks effectively. And we've seen it. In the next slide, we can see that it's nothing I mean, Mythos is great, and it's really another great leap, but we've actually seen the the the signals that this is where we are heading even last year. So in December, we held we held the zero day Cloud. It's a it was a hacking, competition, and we invited researchers, from all over the world to try and find vulnerabilities in, Cloud, software. And most of the teams that participated and the winning team, used AI to discover the vulnerabilities that got them the most points to win this competition. Even in December, so now Mythos was released last month, Even in December, we saw that AI assistant vulnerability research is already a thing. And and what the way that we're seeing it is that, first, we're going to see, you know, more of these vulnerabilities. And this is what we mean by when we say that AI that that, you know, hacking has been democratized. It's easier than ever to find these vulnerabilities. The other problem is that it's easier than ever to exploitation time. We see and there's a zero day clock project where they show how much time it takes from the moment the vulnerability is discovered to the time that it is exploited. We see that this time shortens, and now it can take for some vulnerabilities, can even take minutes from the moment the vulnerability is published to the time that it is exploited. We're talking about more vulnerabilities and exploitation time that becomes shorter. Now, here at Wiz, we try to take and quantify because when we talk about hacking using AI, it's not only about vulnerability research. There are also web. There's also web hacking, you know, API hacking, other cloud hacking, and and we we've taken we've collected hundreds of challenges that are based on real world cases that we saw, across, you know, when we worked with customers, when we found some of these vulnerabilities, and we created a benchmark. We published it on the website. It's in the doc section here in the, the webinar platform. We called it the cyber model arena. We took different models with different, harnesses, very simple ones, just, you know, Claude, Kohler, the Gemini CLI, and we tried to quantify how good models are in these different tasks. And and and we can see and you can see here in the results that models with very, you know, simple harnesses, they were able to, complete almost half of the, real world challenges that we collected, both from, you know, Cloud attacks, web hacking, and the zero day, challenges. And it means that everyone I mean, all of you now sitting at home, you can just log in to, to, your Google Cloud platform, to Anthropic platform, you know, and and start and use these models to, build you know, to try and find discover vulnerabilities or build your own AI assisted autonomous hackers. I think that this is how we see reality, and I think that this trend has started a long time ago, and now we just have this another point in time where we see Mythos in a large model with better capabilities, more sophisticated capabilities. We have to remember that it's also more expensive and slower, and it takes more time to operate it, but we have to think about a new reality. The physics of the hacking world have changed. Now, this is the reason that we are thinking about new strategies and this new overriding model that Raz is going to present later. Just to conclude the first part of the research intro, we want to talk about how the next month are going to look like. What should we expect in this new reality? First, and Russ, can you please click? Thank you. I think that what now after Mythos was released, the most interesting question is, how is it going to change your reality for the defenders? I think that what we're going to see in the short term, let's say from now, the next three months, is more CVEs, Mythos. Only good actors have access to Mythos now. So large companies who can secure the Internet infrastructure, secure open source, they're the ones with the access to these models, and that's the only use of Mythos right now. What we can expect to see is more CVEs, more vulnerabilities that will be discovered using Mythos, but they're going to be discovered by good actors and disclosed responsibly. One example, the Mozilla, they published how they collaborated with Tropic to find vulnerabilities in Firefox, and we'll see more and more of these responsible disclosures using AI. Of course, it's not only Mythos. You can also find vulnerabilities using models like Opus, like Gemini Pro, all of them, they are capable to do this job. Mythos is, of course, doing it better. The other parameter is the exploitation, and we talked about it, how exploitation time is going to be shorter because of these capabilities. For us and the strategy, Raz will elaborate more on that, is first, to make sure that you can reduce exposure, to make sure that you don't have anything unnecessarily exposed. Because for us, it's always about these toxic risk combinations, even if you have software that is critical to you. But if it's exposed, it's more likely that it will be exploited if there's a vulnerability in it. That's, I think, for us, one recommendation, and we'll expand more on that later. Think that the time, the next, the medium term period is, the three to nine from now when Mythos becomes available to more actors, and we can expect that other malicious actors will try to use distillation attacks, try to rebuild Mythos on their side, create maybe an open source version or Mythos or other versions that they can use. Over there, what we expect to see is the AI on the risk. We'll have the defenders trying to protect and build their systems to protect from these new fast attacks. On the other hand, methods will be available to more actors, and this is a critical time, and this is what we should prepare for. We'll talk about it later. I think that when we talk about the future, after we have this, we'll see more and more vulnerabilities, and at some point we might get to a plateau because we will adjust the systems, code will be more secure. We also believe that we need to do more secure by design systems and reduce the likelihood of these exposures. There will be more risk, but we'll get to a new norm and a new reality there. So with that, I think that's how we see the next year in AI, what we expect to see. Now, let's hear from Russ what we should do about it and how should we prepare to this new reality. Thank you, Alon. I'll also say there's another thing I forgot to say was feel free to write any questions you have over the chat or any thoughts you have. We have from the WizAI product team answering as we talk, and, also, we'll try to leave some time at the end, to talk about some questions. Thank you, Alon. And with that, I'll say that we are thinking about this new reality and thinking how do we translate it into basically a framework for how do we approach becoming ready for AI threats. And I think one important thing to remember is that, like Alon said, the the newest models, in this case, Methos, are, like, another step along this line. Right? I mean, like Alon showed, even with Opus, it had insane capabilities of discovering vulnerabilities and zero days in the code. We saw the results. So this is, again, just like we think of this as a trajectory and what are the steps we need to take to become prepared. So the first thing, like, we talked about is first eliminating critical risks, And that is because, as Alon said, it's easier to find vulnerabilities than ever, but it's also easier to exploit existing vulnerabilities than it ever was. Right? So, of course, if I have now exposed instances of my environment that are vulnerable, then the the bar for what is exploitable has become much, much, much lower. So the first thing is making sure that we reduce our exposure to existing critical risks. Reducing any unnecessary exposure will also help us in this, like, longer term of more and more and more vulnerabilities. Right? So, of course, you all know that any unnecessary exposure, always best to get rid of it. The second thing we have to realize about the step of eliminating exposures that what AI also enables attackers is to just, find more complex flaws in your own custom code. Right? I mean, we were, as security teams historically, always mostly concerns about CVs and about infra risks because those were, like, generic things that simple attackers could scan for at scale. They wouldn't you wouldn't assume that somebody would take a piece of your own custom application that's exposed and start, you know, like, start analyzing the things backwards and binaries and finding complex logic flaws in your specific code. That that, that worry was, like, reserved for nation states and banks. But the reality is now AI is lowering the bar. So finding complex flaws in custom code is becoming easier, and you can do that at scale even if you're not the most talented attacker. So we are seeing applications move up. We are seeing attackers move up the application layer. So that means it's really important to scan any piece of exposure you have with AI before a malicious actor scans it with AI. And, basically, we wanna get to this place where we, almost like every exposure we have gets scanned with existing AI models before somebody else gets there. Right? So that's the most critical thing to be prepared. The second thing is we are preparing for this period now, right, where more and more vulnerabilities will be disclosed. And for every vulnerability that's disclosed, the time for an actual working exploit becomes, like, close to zero. And so what we wanna do is become prepared by looking at our environment, understanding what technologies do we have that are exposed, and preparing for a world in which we were gonna see a lot of vulnerabilities and many also possible zero days. So we wanna build workflows to become ready for that. Like, how do we patch fast across those places in our environment? And as much as possible, to, like, lower the burden on the teams. So where we can, we wanna move to harden the infrastructure, like secure based images, secure libraries. Those reduce the load from the patching flow and basically harden your environment by default. Then we wanna also make sure that we do perform the deep AI code analysis on our most critical code and infrastructure. So let's say we have a model as good as Methos, but it's also expensive to run, not that simple to run. Right? Like, running it effectively, it's very expensive. It's slow. It's not something you do constantly constantly. So we wanna make sure that we understand which pieces of our code base are our most critical pieces of code, and we'd wanna focus there first. Anything that's customer facing, anything that has sensitive data flows, authentication logics, exposure. And then we wanna make sure we start by by preparing and building a life cycle for this. How do we scan with those tools? How do we remediate the findings? And how do we triage all the findings from from those tools. Then number four is it's true also for any step here along the way. Right? We we are moving to this place where we need to move to machine speed. Like, any place in those processes where we have today teams and people coordinating with each other, it's not fast enough for the world of AI. This is also true for detection and response. So we must move to a place where we triage alerts fast, and we use AI to do a lot of the investigation and the triaging. And we go to fast response and fast containment, which means automatic response and containment. Of course, you need lumens humans in the loop, but how do we make that flow as fast as possible to get to really, like, machine speed in in the way we respond, in the way we respond to threats, in the way we respond to exposure, in the way we respond to patching. Now the the great like, honest great news is I've never been more optimistic about the power that we as defenders have. Like, as somebody who spent her entire life building security solutions, I've never been more optimistic about our capabilities to actually have a very big advantage on attackers. Right? Because defenders like, attackers have what they see from the outside. And the AI is really as good as the context you give it. So they can try guessing and fuzzing and, like, understand what's critical, what's test, what's this, but we have so much context about our own environments. And when we put the AI to our advantage, we can actually become much, much, much, much, much faster in every single thing we do. And, also, finally, we have new powers to to remediate as well. So I won't go too deep into the slide of explaining how Wiz helps with each pillar. I'd rather touch on it more holistically to explain this concept. So if the first thing we said is we need to reduce critical exposure and make sure that any exposure is is scanned with AI, what what WIS, for example, does today, but, again, I think the principle could apply even broadly. First, we use AI to really understand all this internal context we have, and we use that to understand every single piece in our organization where we actually have exposure. We then take all of any exposure we found, and we give it to an AI based pen tester. So Wiz has what we call the red agent, which is a super powerful pen tester using existing models, using our own harness, like the best pen tester in the world. So every exposure you have, we scan it with AI to understand if an attack could happen. Then becomes the part where I'm most excited about, where traditionally the challenge we've always had in security was actually fixing things. And cloud and modern applications only made it harder because at the end, the infrastructure is owned by the dev team. The logic of the application is owned by the dev team. So we can only go so far without, like, asking them to do things. But now AI changes that all around. I mean, your development teams are not writing code themselves anyway. So what we are now able to do is every time we find this type of a critical finding, we give all the context about the problem and the finding, and we give that directly to the coding agents the team is using anyway. And so all your developers do anyhow is go over pull requests by their coding agents. Now they have one more pull request, and they understand why this is a critical issue. And so you finally can close that loop of also fixing at machine speed. Then when it comes to deep scanning of the code, the it's also important to have this way of orchestrating it and prioritizing it. So, again, this is what Wiz does today. Wiz today enables customers to basically if they run their own with those scans, we have a lot of customers using it, you then upload the results into Wiz, and then Wiz can help you contextualize it with your environment context, with runtime context, understand and validate the findings because AI findings do still need a lot of validation, even meet those findings. Then we also help by remediating, by connecting back to code. And then also ourselves, we have our own AI SaaS scanning now in preview, which uses really the best model for the task to help teams find flaws in their code. But, again, the power comes from having a work like, a workflow around it, being able to run it, prioritize the results, validate the results, and go back to the teams with fixes by opening PRs to them. I'll do a super quick demo too. I always feel like when I talk about AI without the demo, it's so hard because everybody talks about AI. But, I wanna show how that looks like, and this is obviously the wiz product, but I wanna show the concepts we talked about. So this is an example of a Wiz, critical risk. And in this risk, what we can see is we by Wiz analyzes the entire internal environment. So Wiz has detected the machine that runs an AI agent. We do that by actually analyzing the code files on machines and understanding, oh, those are code files that belong to an agent, and we map the tools of the agent. And we even know exactly what does this have access to from the cloud in terms of a data. So is it saying, hey. There's actually access to a database with sensitive information. So now we have all this internal context, and we know that this, at the end, gets exposed, by this endpoint. Now what Wiz does is then take this deep analysis and context, and we give the entry point to our AI attacker. So here we see a login interface to some type of a data bot. Looks good. Somebody built a data bot, has a login. This is, by the way, based on things we see very often with our customers happening now where, you know, every team in the organization is building chatbots to query things. But great. They put authentication. But now we take this entry point, and we give it to our AI attacker from the outside in step number one. And what the red agent finds is it finds that it can actually do a pretty sophisticated authentication bypass attack. You can see the exact steps that the red agent took until he was able to run the attack, and he also gives you exact ways to reproduce it. Now this is not a simple vulnerability. Right? It's an application level attack. But now AI could run though can run those things. So applications are moving up the stack, and we have to scan our AI exposure before anybody else does. So that is what the red agent helps you to do. And then we go to closing the other side of it. Like, okay. I found this finding by the red agent. I found this new exposure. How do I remediate? Right? So with maps, it's all the way back to understanding where was the code, and we also use AI. We call that the green agent. And we like, red for red team, green for green team. So we also run our NIAgent to investigate, okay, wait. Where in the code was this? Who is the developer that that that did this? But now what we can do is we can just immediately send to the own developer's coding agent our full fix. And you see, we just literally give all the details of what needs to be fixed, and we tag the developer's coding agent. So in a second, you will see Claude starting to run here. And this is the developer that's put the problem in place. His coding agent runs. He has a full context about this environment, and he can now he will now work here by himself and open a PR for the developer to accept and to fix. So this is now getting us to this new world of, hey. I ex I scan everything and reduce my exposure with AI, and I can write fixes with AI. And the same logic is true also when we think of those deep scan coding fixes. So where we use, like, the most advanced models like me, those are everything to find those advanced flaws in logic, which, again, it's like a second level of priority. Right? The first thing is actually scanning everything we have and hardening our environment in the place of exploitation becoming faster and attacks moving up the application stack. The second thing is Wiz can also take into account those types of findings. You can connect using the Wiz MCP so the findings are uploaded into Wiz. And what Wiz does is it enriches them with the environmental context, and it runs a full investigation to validate the findings. Like, look at runtime. Look at at an actual validation action and and and understanding if you also have existing findings on the same area. So really trying to validate the finding and then saying, hey. Actually, it looks like you do have to remediate this one. It looks like the verdict is to remediate, but then we found, again, the owner in the code, and we basically help you remediate it. If I go to the remediating action here, again, I will be able to just send and write the complex patch to the right coding agent. So the world is now shifting to a place where if I go back to if I go back to my deck, we wanna get to this maturity level, right, of basically reducing truly reducing to minutes our MTTR on finding risks in code, patching our resources, scanning our external exposure, and responding to threats. I haven't gone into, I haven't shown you in in the demo now, but we can also we can also really in Wiz, we help also teams with the threats. We have the blue agent for the blue team, which is, like, our, basically, our investigator agent for threats, which does everything. It grabs forensics, snapshots. It does everything to, again, help teams, like, basically reduce the time that it takes us to respond. So what we are aiming to do is to really across every pillar, we all need to start moving to automation playbooks as much as possible and adding an agentic layer on top of it to help us across remediation, continuously scanning the environment with AI, and also investigating and responding to threats. So all of that is how we think of this maturity model, and those are for us the steps to take to getting there. But with all of the also, you know, like, a lot of, discussions around, you know, mythos, it's another point in the chain. And, actually, of course, you know, we are all security people. We always know security is in layers. Of course, it's more important to start by addressing, you know, vulnerabilities and pieces of code that are exposed and where existing publicly and widely available models can find risks. And that's why we need to start from one and from two. And then we do need to think about, okay, what are the places in my code base that I wanna scan most deeply with AI? So I can use AI to do a broad scan with existing models and what are the places where I wanna prioritize the deep, deep, deep models, and then also really focus on detecting and responding to threats in real time by understanding that more vulnerabilities also unfortunately means at the end, more risk of, god forbid, successful attacks. So, I hope, I hope this was, I hope this was helpful. Really, I will also say that at Wiz, we always believed in, you know, being very being very humble. Right? This is a fast evolving world. And just like you, we are part of that fast evolving world. Our goal is working and partnering with customers, and we are also partnering with the Frontier Labs. I mean, most of the Frontier Labs are today also with customers, so they also use the WIS to protect their environments. But, also, we partner closely to make sure that we that we constantly stay updated. So this may all very well change. Right? But, like, we want to be basically the best partner and at any point, try and share as much of our, worldview on this very complex and fast evolving topic in which we don't we don't know everything yet, and we probably won't know everything for a very long time. But, overall, we are very optimistic that this will actually cause all software to become more secure, but we're all now in this, like, transition period of, like, high waters. Any question we wanna address live? Or oh, green team. I'll address one question live. Green team basically, every security team I also did not know that. I don't remember at what point in my security career I discovered it, but, like, there's a color for each team. So in many big organizations, they actually have a remediation team, which is called a green team. That's why we call the remediation agent the green agent. Like, red team, which is, like, the attackers team, and and, and the blue agent, like, the blue investigation team. I'll address one random additional question before we drop. The red agent, it does, like, an initial pen test, and we're now also expanding it. Like, we're now also working on authenticated deep pen testing by the red agent. So it's a road map item. Okay. Thank you so much, everybody. We hope this was helpful. And, again, feel free to reach out to us if you wanna talk about this more, think about this more, or give us any of your thoughts. Thank you, everyone. Thank you.