Down the Security Rabbithole Podcast (DtSR)
Down the Security Rabbithole Podcast (DtSR)

DtSR Episode 726 - Three Dollars To Hack Your Stack

Show notes

TL;DR: Mehul joins Rafal live from BSides Atlanta to talk about how AI is changing how vulnerabilities are found and exploited at scale and cost. It's an interesting conversation about how much it costs to break into an organization's software stack.

Video: https://youtu.be/kGajA9ipsp4

Guest

Description

A disclosed vulnerability no longer needs weeks of hacker effort. When exploitation becomes an automated, agentic workflow measured in minutes and dollars of compute, the way we rank risk, plan patching, and measure security maturity has to change.

Recorded live at B-Sides Atlanta, we sit down with Mehul Revankar, co-founder and chief product officer at Quantro Security (Contro.security), to unpack what “agentic AI offense” looks like in the real world. Mehul shares results from research on building and validating exploits at startling speed, why compute budget is becoming the true limiter, and how model escalation and exploit mutation loops turn yesterday’s “low priority” bugs into today’s fast-moving threats. We also pressure-test the comforting idea that you can simply patch your way out, and we ask what happens to common metrics like EPSS or “not exploited in the wild” when an AI agent only needs to succeed once.

From there, we shift to defense. We talk about compensating controls that still matter, including web application firewalls, tighter firewall policies, and practical ways to reduce exploitation even when you cannot patch everything. We dig into attack surface reduction, the hard problem of legacy software, and why decommissioning old systems may become more realistic as AI lowers the cost of rebuilding. Finally, we explore what AI-native scanners and defensive agents could look like when they can reason on the fly rather than follow brittle, rules-based logic.

If you’re thinking about vulnerability management, cyber risk management, AI security, and the future of cyber defense, this conversation will recalibrate your threat model. Subscribe, share this with your security team, and leave a review with the one metric you think still holds up in an agentic era.

Have something to say? Let's hear it.

Support the show

>>> Please consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast