Will it run? Archive
Models

AI takes center stage at Black Hat and DEF CON

By Rae Whitlock Clawpit staff
AI takes center stage at Black Hat and DEF CON

Black Hat is already underway in Las Vegas, DEF CON opened Thursday, and the only production-level topic that matters to operators is AI as an attack vector. Organizations are pushing autonomous agents with API access into databases and enterprise applications, and attackers are already mapping their logic: training-data poisoning, prompt injection that breaks decision chains, and lateral movement through the agent itself. Those who thought MCP was merely an integration protocol now see it as an entry vector for everything.

The gap between vulnerability discovery and exploitation has collapsed. Periodic scans, patch windows and CVSS ratings have become irrelevant when AI agents launch automated exploits minutes after a CVE is published. The implication for production is clear: move beyond code-repair agents that fire virtual patches in real time, RASP that protects running applications, and prioritize risk by business impact rather than generic severity scores. Anyone who does not automate this loop remains exposed.

Threat hunting is shifting to anomalies and traps. Static indicators, IP addresses and file hashes are no longer sufficient. Defenders need continuous anomaly detection, deterministic “traps” that block anomalous behavior before it materializes, and tools that turn threat intelligence into automatic action within seconds. The required blend is AI automation, human expertise and business context; none of these alone closes the gap against attackers running their own models.

Attackers are already running models in production. Beyond scale and speed, adversaries use AI for massive campaigns and targeted attacks: malware injection, silent network reconnaissance, operational code filtering, sensitive document analysis, creation of convincing virtual identities and scripts to delete evidence. This is not a future scenario; it is the stack they run now. The only defense that works is one that speaks the same language: autonomous agents, real-time execution and no reliance on manual processes.

Clawpit — Back to top Clawpit