From Read Access to Admin with just an AI Agent
Show notes
What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really find zero-days on their own, or is that just the headline? And if AI can do the attacker's job, who's actually holding the scissors?
In this solo episode, Ron Eddings shares his own methodology for offensive assessments with AI. He talks about the models he trusts, the tools he uses to get agents working together, and a real assessment where his agents turned SQL read access into admin control and unlocked the API keys stored inside. Ron also calls out what's hype and what's real with today's models, and why the agent still needs a skilled person behind it.
For defenders, Ron covers what attackers go after once they're in, and why the fundamentals like asset inventory are still where every strong security program starts. He closes with the bigger picture: anyone, good or bad, now has powerful intelligence on hand, and it's on all of us to look out for each other.
Impactful Moments
00:00 - Introduction
02:25 - Can AI Really Find Zero-Days Alone?
04:20 - The Real Danger Is Human Intent
05:00 - Why Grok 4.6 Tops Ron's List
07:55 - Ron's Three-Model Assessment Workflow
09:50 - Maestro, Interceptor, and Agent Ensembles
11:20 - Privilege Escalation and Persistence With LLMs
12:50 - Why AI Hacking Feels Like Cheating
14:20 - Ron Called Automated Security in 2015
16:05 - The Lazy Way to Hack
17:55 - From SQL Read Access to Admin
21:05 - What Attackers Want After Getting In
23:40 - Asset Inventory Is Security Flossing
27:05 - Why AI Is Like Scissors
29:05 - Waymos, Robotaxis, and Physical AI Risk
Links
Check out our upcoming events: https://www.hackervalley.com/livestreams
Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com
Become a sponsor of the show: https://hackervalley.com/work-with-us/