LIVE · cybersecurity feed
Live wire
aimedium

AI Could Revolutionize Cybersecurity Analysis and Defense

A keynote speaker argued that cybersecurity is moving beyond its experimental phase due to increasing complexity and reliance on human attention. The speaker suggested that large language models offer a scalable solution by providing cheap, abundant evaluative power, enabling defenders to analyze and act more efficiently. This shift could lead to more automated, standardized, and sustainable security practices by integrating artificial intelligence with human expertise.

zeroday.news · 51d ago

Cybersecurity is entering a new era, moving beyond its experimental phase due to the increasing complexity of software systems and the limitations of human analysis. This shift is being driven by the capabilities of large language models (LLMs), which offer a scalable and cost-effective way for defenders to assess, prioritize, and act on threats.

Juan Andrés Guerrero-Saade, VP of Intelligence & Security Research and Senior Technical Fellow at SentinelLABS, presented these ideas in a keynote address at LABScon 25. He described LLMs as a "lossy compression of human knowledge" that can provide a vast and inexpensive source of evaluative power. This mechanized intelligence can reduce the reliance on scarce human expertise, thereby lowering the cost of analysis and transforming how defensive operations are conducted at scale.

Guerrero-Saade argued that the industry should integrate these AI capabilities rather than treating them as add-ons. He advocated for a move away from purely adversarial design principles, drawing on concepts from cybernetics. Instead, he suggested a future where human expertise and artificial evaluative power work collaboratively to achieve better security outcomes.

The future of cybersecurity, as envisioned in the talk, points towards a more standardized, automated, and sustainable industry. This evolution aims to move beyond defending existing product categories or familiar workflows towards a more integrated approach to security. The keynote is considered essential viewing for those interested in how AI could reshape the practice, cost, and structure of cybersecurity itself.

Guerrero-Saade's background includes overseeing intelligence production and AI applications for security at SentinelLABS. He is also a Distinguished Resident Fellow for Threat Intelligence at the Johns Hopkins SAIS Alperovitch Institute. His research has been featured in exhibits at the International Spy Museum and he is a member of OpenAI’s Frontier Risk Council. He founded the threat intelligence conference LABScon and co-hosts the "Three Buddy Problem" podcast.

LABScon is described as a unique venue for original research shared among peers, with an invite-only audience of researchers. This format allows speakers to focus on technical findings without extensive introductions. Talks are typically 20 minutes with a 5-minute Q&A, and workshops are 90 minutes. While primarily focused on threat intelligence and vulnerability research, LABScon maintains an open mind to other relevant topics. The LABScon 25 conference was hosted by SentinelOne's research arm, SentinelLABS.

aicybersecuritylarge language modelsautomationdefense
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

ai

Microsoft, tech companies throw weight behind spread of open-source AI

Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop.

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.