A keynote speaker argued that cybersecurity is moving beyond its experimental phase due to increasing complexity and reliance on human attention. The speaker suggested that large language models offer a scalable solution by providing cheap, abundant evaluative power, enabling defenders to analyze and act more efficiently. This shift could lead to more automated, standardized, and sustainable security practices by integrating artificial intelligence with human expertise.

Cybersecurity is entering a new era, moving beyond its experimental phase due to the increasing complexity of software systems and the limitations of human analysis. This shift is being driven by the capabilities of large language models (LLMs), which offer a scalable and cost-effective way for defenders to assess, prioritize, and act on threats.
Juan Andrés Guerrero-Saade, VP of Intelligence & Security Research and Senior Technical Fellow at SentinelLABS, presented these ideas in a keynote address at LABScon 25. He described LLMs as a "lossy compression of human knowledge" that can provide a vast and inexpensive source of evaluative power. This mechanized intelligence can reduce the reliance on scarce human expertise, thereby lowering the cost of analysis and transforming how defensive operations are conducted at scale.
Guerrero-Saade argued that the industry should integrate these AI capabilities rather than treating them as add-ons. He advocated for a move away from purely adversarial design principles, drawing on concepts from cybernetics. Instead, he suggested a future where human expertise and artificial evaluative power work collaboratively to achieve better security outcomes.
The future of cybersecurity, as envisioned in the talk, points towards a more standardized, automated, and sustainable industry. This evolution aims to move beyond defending existing product categories or familiar workflows towards a more integrated approach to security. The keynote is considered essential viewing for those interested in how AI could reshape the practice, cost, and structure of cybersecurity itself.
Guerrero-Saade's background includes overseeing intelligence production and AI applications for security at SentinelLABS. He is also a Distinguished Resident Fellow for Threat Intelligence at the Johns Hopkins SAIS Alperovitch Institute. His research has been featured in exhibits at the International Spy Museum and he is a member of OpenAI’s Frontier Risk Council. He founded the threat intelligence conference LABScon and co-hosts the "Three Buddy Problem" podcast.
LABScon is described as a unique venue for original research shared among peers, with an invite-only audience of researchers. This format allows speakers to focus on technical findings without extensive introductions. Talks are typically 20 minutes with a 5-minute Q&A, and workshops are 90 minutes. While primarily focused on threat intelligence and vulnerability research, LABScon maintains an open mind to other relevant topics. The LABScon 25 conference was hosted by SentinelOne's research arm, SentinelLABS.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed