Searchable transcript of Have we finally solved social engineering? Plus: World Cup fraud, AI IDs and an IBM/OpenAI collab — IBM Technology (39:11). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 A new op-ed in Dark Reading says LLMs could end social engineering. Panel, what do we think? Dave, I'll throw to you first. I think that AI is learning from us so that we can, uh, be safe from this is excellent. Excellent. People are not the only ones that are being social engineered because the, um, LLMs are also being social engineered. The end of social engineering won't happen when when humans get smarter.
00:24 It'll happen when humans are completely removed from routine trust decisions. Hello and welcome to Security Intelligence, IBM's weekly cybersecurity podcast, where our expert panelists turn the biggest industry news stories into practical takeaways you can use. I'm your host, Matt Kosinski. And joining me today, we've got Dave Bales, North American Lead Managing Consultant for the X-Force Cyber Range, Kimmie Farrington, Security Detection Engineer, and J.R.
00:57 Rao, IBM Fellow and CTO, Security Research. Today we're going to chat about how cybercriminals are using the World Cup to wreak havoc and Estonia's proposal to give AI agents their own identities. Plus, IBM joined OpenAI's Daybreak Cyber Partner program, and we've got a special segment coming up all about what that partnership is and what it brings to the world of application security.
01:15 But first, we're going to talk a little bit more about whether AI native operating systems can solve social engineering. Now, this comes from an op-ed for Dark Reading, written by cybersecurity strategist and author Arun Vishwanath, who certainly thinks that this is how things are going to play out. He posits that as LLMs become integrated into operating systems.
01:43 They might finally give us a reliable technical defense against social engineering. The idea is this: With the right access, an OS-integrated LLM could hypothetically see everything happening on a device across platforms and apps. So you combine this context with an LLM's ability to interpret lots of data fairly quickly, and you have a pretty reliable system for flagging social engineering attacks.
02:05 Right? Like a regular spam filter only sees your email. But what about an LLM that sees an email plus everything else happening? Uh, Arun compares this to the rise of endpoint protection tools in the early 2000s, saying how those made computer viruses a lot less common. Maybe LLMs will do that with social engineering as well. So let's start by digging into some of our initial reactions here.
02:24 Dave, I asked you first up top, I'm going to ask you to expand. How are you feeling about this idea that AI could help end or at least significantly reduce social engineering? So as an early adopter of the iOS 27 operating system that's coming out in the fall, it's integrated Siri much more. And I'm bringing this up because Siri is now LLM-based. Um, it won't be.
02:48 It won't be an immediate difference that anyone will be able to see. But once it gets to learning your patterns and learning what you click on and what you don't click on, I think it could actually be a really big help in eliminating at least the largest risk of social engineering. That, you know, that that ties into something that Arun says in his article.
03:13 And I want to get into it a little bit later. But, you know, this idea of like, maybe we can use those kinds of signals for authorization instead of a password. It's an interesting concept. Kimmie, let's go to you next. You had kind of the strongest no here. So I want to hear a little bit from you. What do you what are you thinking about? Well, you know, going back to LLMs are learning from humans, um, humans are still being social engineered because we have empathy for a scenario.
03:38 We fall for the pressure. There's the the classic, um, uh, bad guy scenario of of giving you the urgency and something you really want and all those sort of things. But, um, as we've seen with, with instruction flattening, um, LLMs are are just as as vulnerable to injection prompts, if you will, human prompts, um, and therefore social engineering in many ways.
04:05 Um, but I do like the idea of the operating system built of multiple AI agents questioning at every exchange between various portions of the operating process and stack flow. Right. Um, so, you know, is it is this a step in the right direction? Absolutely. Um, but they have a lot of learning to do. And, um, you know, just as we've seen with automation, uh, making all the pieces integrate and understand what the context of each thing is will be a big challenge.
04:38 Um, but, you know, I think it's a good step. I just don't think it's gonna work just yet. It's not the end of the answer. That's. And that's fair, right? Because, you know, you gesture towards this, that like this is slightly different than just having one LLM. We're talking about a whole bunch of agents doing things, and so maybe they can kind of cover for each other, but each one could also be social engineered, right?
04:58 Like like you said, there is like prompt injection attacks. It's sort of funny that we're talking about this particular story on this episode because like two weeks ago, we covered, if you folks remember, people were tricking Meta's customer service agents into handing over Instagram accounts by just going on and being like, I'm the user, can you change my email?
05:17 And they're like, yeah, sure, why? So like obviously most of the time it's not that easy to to break an LLM, but like they can be tricked too. There's a sort of tension there, I guess. J.R., I liked that you said, you know, we're not going to solve this until humans are removed from the kind of trust question. Expand on that for us, please. Yeah, definitely.
05:38 Right. So I think, uh, we know that, uh, humans are have have never been very good at making decisions and in particular, making security decisions, if I may say so. And, you know, it's really three different things, right? I mean, Way to call us out. Yeah. Whether it's whether it's at the coffee table, you know, kitchen table at home, trying to make decisions or wherever.
06:03 Right. But let me let me amplify a little bit on this. Right. So humans really have three different problems. One is we're often forced to make security decisions without having enough context. Right. I think you pointed this out, Matt. I mean, is this email legitimate? Right? Is this website safe? Should I trust this attachment? Right. They don't have the context to make that decision.
06:26 With LLMs, you have that context, right? Maybe they can they can actually deal with it. The second problem with humans is, and the reason why social engineering actually succeeds is because attackers are able to exploit the cognitive overload. Right? If I bombard you with hundreds of emails, dozens of chats, multiple identities, endless notifications.
06:50 Attackers only need one for you to make one mistake and all that. And and they. And the only way to counter that kind of automation or those kinds of odds is to have automation, is to have AI, to go against it. And the third is humans aren't very good at spotting phishing emails. Right. And the future is really humans never seeing these phishing emails.
07:16 So, uh, spam filters reduced, uh, spam. And the AI native operating systems could do similar things for social engineering. But having said all this, right, while I'm optimistic that the problem is going to improve and that the social engineering isn't going to be a human problem anymore, I think it's going to become an interface problem because AI is not going to completely eliminate social engineering.
07:41 Um, it's going to shift the battlefield, right? So the attackers are now going to start targeting, exactly as Kimmie said, the AI assistant, the trust models, the memory systems and the agent instructions. And maybe there, you know, having spent decades trying to counter and cover for human frailties, we can change the game and say, okay, how do we deal with these issues that, uh, AI throws up at us?
08:04 Absolutely. I like this idea of it's kind of becoming an interface problem, like you said, right? Like, it's like it's almost like social engineering doesn't go away. It just shifts who it's targeting. Right? Like, instead of going for the person directly, it starts to hit their models. Let's talk about then, not just whether or not we'll stop social engineering, but also this authentication idea that came up that Dave kind of gestured towards.
08:30 And, Dave, I'm going to ask you about it because you're the one who kind of touched on it, this idea that, you know, Arun brings it up in the article. I'm going to I'm going to read a quick quote from him. He says instead of asking for a password or a security question, a future system might confirm identity through a combination of recent behavior.
08:40 The person you spoke with yesterday, the destination you searched for before leaving for the airport, etc.. What do you think about this possibility, Dave? Do you feel like maybe we can make a shift like this, that this can help at least protect us? What do you thinking? Well, we've always had this model of something, you know, something you have or something you are.
08:57 We've got the password. We've got the token key. And we've got the retinal scan or the thumbprint. And those all work well. But if we can have something that actually learns our patterns and habits in our daily computing life, what we click on, who we speak with. You know, J.R. and I have never met in person, but we've exchanged messages on Slack before, and my my AI assistant is going to know that.
09:29 And so if J.R. were to send me a message, I'm not going to I'm not going to think twice about clicking on it because my AI didn't flag him as an unknown or suspicious person. I think this is outstanding. It's got great potential. I and like Kimmie said, I don't think it's there yet, I think it could be in the in the coming future. I'd say by the time quantum gets here.
09:46 Yeah. And I think we've been talking about, you know, behavioral authentication for a little while now. And for a long time it was limited to like IP address or like typing speed or, and like you can't. Those are very easy to mimic. But like you said, Dave, if you've got an LLM that can take all these factors together, that seems like maybe we start to unlock that and you can't steal a behavioral pattern the way you can steal a credential.
10:13 And so like even if somebody falls for phishing, it just makes it I think it might make it harder to exploit them. Right. But that does bring us to this question. And Kimmie, I'm going to ask you if you have any thoughts here, how we sort of deal with the tension that's come up a couple times in this conversation, which is that, like the LLM might be able to cover for us and some of our failings might be able to covers for, you know, the LLMs be able to cover for each other, but ultimately each LLM itself is also a
10:36 possible attack vector. Any thoughts on how we handle that part of the problem here? Well, I was still thinking about the behavior, answer right. And how J.R. pointed out that humans have some major frailties. One of them is that sometimes we're totally random. And while you may have trained something to look for a pattern, I just decided to break that pattern today and do something completely random.
11:03 And I'm going to get flagged for it because you have the LLM looking for patterns. I'm not a computer. I don't do patterns. Well, I like patterns, but that's not the point. First of all, that way, I think that's a very good point, right? Is that, you know, there are we might we might kind of deviate from our own patterns sometimes. Right. And I think the hope is if you get a sophisticated enough AI, it would even be able to deal with that.
11:22 But I don't know we might. Well we'll see. You know, because that that's kind of hand wavy I admit. Right. Like, oh, the AI will solve it. But I don't know. Um, but the question I wanted to ask you was, was if you have any thoughts on how we deal with the kind of tension between the fact that, like, the AI can cover for some of our failings, but it's also a possible attack vector itself.
11:39 Like like J.R. said, these things could kind of be if we start socially engineering them, if it's an interface attack instead of a person attack, that becomes a whole new issue. Any thoughts on how we deal with that part of things? I mean, it's right up there with credential stealing. You look like me or you don't look like me, I don't. How do you know if you look like me or not?
11:58 Based on behavior, based on my tokens. Based on the last things I did. Um. And then how do I prove it was really me, even though I just did that anomalous behavior? Uh, these are really good questions, and I don't know what the real answer is at the moment, but I do think that there is hope with more agents, not less. Right? If you have more things, looking at more places, um, and they have very specific context and understanding of what their role is.
12:26 Um, I, you know, I have hope that we can we can get closer to answering these things, but I, I'm probably going to get isolated myself. It's a good point, though. You know, it's kind of like the, the, you know, the more eyes we have on something, usually the more secure it is. And? And the AI agents. You got a bunch of AI agents? Those are more eyes in a sense, right?
12:43 So I do think I have some hope for that as well. J.R., to close out the segment, you know, any thoughts on your end in terms of the the kind of the so what? Right. If you're a defender right now looking at this thing about how LLMs can help any kind of steps you feel like people should start taking right now to, to to leverage these capabilities. What are your thoughts?
13:01 Yeah, I think we've just started exploring this domain with agents, and we've lived with human frailties and we've we've used different mechanisms. You know, authentication, multi-factor authentication, multi-factor biometric authentication. And at some point we kind of plateaued in terms of where we could go. So now we started with agents. And so of course we are discovering the frailties of agents.
13:24 You know they can be they can be prompt injected. They can be they can start hallucinating all those things. We are learning that terrain. I think we have to live with that to understand that a little bit. Maybe we get a little bit burnt and we learn a few lessons, But then there could be some very nice symbiotic relationship here, where we have either a human in the loop or on the loop as necessary at critical points, so that we hopefully harvest the strengths of both and not the weaknesses.
13:57 Oh, I was just on the concept of, you know, feeding back into the model. And I was thinking, you know, all the ways it can be poisoned or corrupted or those kind of things without any sort of guardrails or, or feedback loop. And so we do need to stay in the loop so that we can, you know, keep it on the straight and narrow. Doing the things it's intended to do and not some random stuff.
14:22 Like there's a whole bunch of, you know, agents compensating for us. Us compensating for agents. It's a it's a beautiful feedback loop, I think. But folks, I have to move along to our next story for today. Before I do though, just opening up to the viewers and listeners out there, if you've got thoughts on how AI can play into defending us from social engineering, if you're using it, drop them in the YouTube comments I do read, I do respond, but we have to move on.
14:44 Now to story number two for this week. This is Operation Fan Trap and the World Cup fraud ecosystem. The World Cup is here, as I'm sure you all know. And as an average American, I don't know anything about it except that I do think it's mean to send international tourists to Philadelphia. And I'm allowed to say that because I'm from Philadelphia. I also know that cybercriminals are using this as an excuse to scam people.
15:11 Surprise, surprise, the folks at Cyble Research and Intelligence Labs have been conducting research that they dubbed Operation FanTrap into this massive World Cup fraud ecosystem. They've identified nearly 4000 malicious domains using fraudulent World Cup branding to spread malware, steal money, hijack credentials, and more. Kimmie, I want to start with you here.
15:32 Are you surprised at all to see such massive scamming going on around an event this big? What are you thinking about? Again with the hard no. Sorry. I'm not at all. I'm not at all surprised. Um, what is interesting about it is the depth and breadth of the industry that has developed around this whole thing. Um, they're not just scamming you for your tickets.
15:49 They're also scamming you at a streaming site. Um, is it a real streaming site? Do they are they going to charge you fees when you get there? Are you going to actually get to watch your show? Um, there's all kinds of interesting things. Oh, and your credentials are being stolen even as you try to click. Um, so I did think that the the report was very interesting in that, in that respect.
16:08 But but not new. Not at all. Every time we have a major, um, you know, whether it's a world event or, or just a local international or national event for that matter, um, the bad guys are quick to jump on and and take advantage. Right. Absolutely. And I like that you referenced the fake streaming sites, because that was interesting to me too, where it was like the problem there is and like, oh, it's I mean, look, piracy is bad, obviously, but it wasn't even the piracy.
16:36 It was like, I'm gonna fake you out and you think you're going to get a free stream. And then I actually just stole your money, like it's I think, you know, I'm not going to say I applaud it, but it works. You know, J.R., I saw you nodding along. I want to get your thoughts here. What are you thinking about? The World Cup fraud ecosystem. What's on your mind?
16:53 Well, um, this time in this episode, you want us to give you one liners. So here's my one liner. Right? So, see, the World Cup isn't just a global sporting event. It's a global attack surface. Okay. Oh good job. That's a good one. Every time. Every time J.R. comes on, he's got some kind. He spits fire like that. Go ahead, J.R., I'm sorry. Yeah. So? So, listen, I mean, let's look at actually is happening, right?
17:20 So cybercriminals really want to follow attention, and nothing concentrates attention like the World Cup, right? It only happens once every four years. It's one of the probably the most popular sport. Urgencies are rising. Emotions are rising. Transactions are going to rise. And what happens when all that happens? Vigilance drops. And that's exactly what the attackers want, right?
17:45 And it's not that the fraud that they are perpetrating is very sophisticated. It's more industrialized. Right. You have thousands of domains you can go after. You can have fake tickets, merchandise, streaming sites, as you said, travel packages, giveaways. Right. It's just marketing that is being weaponized for crime. Think of it that way. And so the first the victim, the first mistake they often make is before.
18:15 That's even before they click. Right. Given a sport that is so popular that demands so much attention. You know, they grow up with this. They dream of their stars. This card, this has all the trappings that that that cybercriminals are looking for. People are willing to drop their guard to get World Cup tickets. And then then look at the words that go.
18:32 I got a discount FIFA package for you, right? Or I can give you free streaming. Right. And, you know, attackers understand this kind of search behavior better than most defenders. Right. So these are the things that are happening. And, you know, and this is the phenomena that we have to cope with when, you know, we are dealing with, uh, a social attack surface that just mushrooms every four years.
19:03 Yeah. I'm glad you bring in the emotional component there because that is like, that's a scammer's best friend, isn't it? Like when your emotions are running high, that's the best time to get you. And like, yeah, something like this, which is a big deal. It only comes around every four years. People are desperate to get tickets. You see how it works?
19:16 The question I have then for each of you we're going to do a roundtable style is again. So what's the so what? What do we need to know about these kinds of scams? Whether you're in the enterprise, whether you're an individual. Kimmie I'll start with you. Any thoughts on what any of this means for us as defenders or just people trying to protect ourselves from scams?
19:37 So you might be surprised for me coming at this with a technical answer, but I've recently heard that there is a new, , similar to an EDR kind of sensor that, um, certain, um, protectors that we know are creating right now that go in the browser and it and it inspects everything that's happening at the browser level. So we've got the firewall already taken care of.
20:04 Now we've gotten this. Now we get this layer of the browser taking care of. Then all of that can be sent as telemetry into your SIEM, which can be correlated with your EDR. Right. And now you can act on stuff because in the EDR, a lot of times we don't see what's happening in the browser. We see it went to the browser, we see the browser was in the middle of it, but we don't see what happened there.
20:24 So, you know, users are going to be frail. We had that discussion and it's true. And it's always going to be true. Um, but but automation and agents are very strong. They have rules and they follow those rules and they don't care about emotions. But if you can look in the browser and you can see what's happening in the browser, you can see that JavaScript that's trying to, you know, take your credentials.
20:48 You can see those other, um, suspicious call homes that are happening suddenly when you hit that website. What that what's all that about? You can see those happening and then you can act on them that much faster. So maybe that's an answer. I know I like that you went in a technical direction there, because I do think a lot of times when we talk social engineering and this is becoming a theme in this episode, I knew it would be.
21:07 But a lot of times when we talk social engineering, the answer is like more education. And it's like, how much education can you possibly do, right? Like, education is good, don't get me wrong. But like, you can't educate away the entire threat. So if there's also these technical controls, that helps. Again, it goes back to what J.R. said at the top, which is that like if you can take people out of the trust question as much as you can, you make it, you know, harder for these attacks to Succeed.
21:27 Um. J.R. speaking. Speaking of, I'd like to get your thoughts on, you know, any advice on for people given this, this big fraud ecosystem out there? Yeah. So I'll take the other route of being non-technical and trying to remind people of age-old wisdom, right. Which is that, look, if the deal looks better than the official offer, you just want to assume it's a scam until it's proven otherwise, right?
21:57 And definitely, you know, you should buy from known sources. And if urgency is part of the sales pitch, just stop because you know there's something going down here. So I think many of the things that have withstood the test of time that we've been taught since kindergarten are the things that, uh, that that apply here, that there is really no free lunch and that if, you know, if you're paying less, it's for a good reason and you need to stop in question what actually is happening.
22:25 Some timeless advice in the age of AI, Dave, to close out the segment, what are your thoughts and advice for folks at home to keep safe from scams like this? It's June of 2026 and I don't think this is ever going to. Stop. Now I say that. Don't click. Yeah, it's not funny but but both Kimmie and J.R. Both they they went to the two extremes. The technical side the non-technical side.
22:50 Because I was listening to Kimmie and she's talking about all the SIEMs and and the EDRs and things. And it's like well Joe Q Public doesn't have a SIEM, EDR or even a firewall. So how do we get them then? J.R. covered it with, here's the education that you need. You need to not click things. You need to take things not at face value. You need to delve deeper into what you're getting yourselves into.
23:12 Anytime we talk about social engineering, that's my my standard go to answer: stop clicking things. Take a minute. There is some research. We are saying stop clicking. But the urgency thing is, is everywhere, right? They're trying to scam me. I just bought a house and all of a sudden all this real mail, snail mail showed up in my box with all this urgent official looking information on it.
23:35 This is referencing your mortgage from your bank. And it's like, is it really though? It's not from my bank. After you read the fine print, it says, actually, we're not affiliated with your bank, but we're really trying to sell you mortgage insurance or something, because we looked at the public record and we see that you have a mortgage now. But you know, that urgency and that official-looking document, it's still scary.
23:54 I forgot all about it. Dave, stop clicking on things. I'm glad that. I feel like I haven't had that catchphrase on the show in a while because you haven't been around, so I'm glad you brought that back. Um, uh, anything else though? Any last words there? Uh, before we close out the segment? Dave. No, I, I really I really think that both Kimmie and J.R.
24:15 hit the nail on the head as far as the business side and the personal side go, um, it is going to keep happening, but we we we just can't click on things for the sake of clicking on it for getting the better deal. I would love to go to the World Cup. I'm not even a soccer. I'm sorry a football fan, but I would love to go. But I'm not going to take the chance that for a ticket that I know goes for $1000 to $5000 just for the nosebleeds to to take a chance on getting one for $500, it's not worth it to me.
24:44 That $500 savings I know isn't going to come back to me, and I'm going to lose way more than that $500 than I was going to lose in the beginning to to set this all off. Absolutely. Like my dad always used to say, if it sounds too good to be true, it probably is. Amen. This is coming out of Estonia, which is considering granting personal ID codes to AI agents the same way they grant personal IDs to human beings.
25:14 The idea is that distinct agent identities could help with both accountability and permission scoping, right? Instead of just inheriting all of a person's privileges, an agent can have privileges scoped to its own identity, and the agent's actions can be traced back to a specific agent. Right. So we have a little bit more insight into who's doing what and why.
25:34 And I know we've been trying to deal with the non-human identity problem for a long time, and agents have only made the question more pressing. So, J.R., I'm going to ask you, what do you think are, is Estonia onto something? Here is the idea of IDs for AI agents the way to go? How are you feeling about this? So, uh. So I think, uh, the scale of human ambition being what it is that it always aspires upwards, right?
25:56 Uh, and we always want to do more with technology that we have. I think it, uh, empowering agents by providing them with IDs was a path that inevitably we want, we would have explored. And Estonia just happens to be one of the first countries to be able to go about and do this. Now, um. Having said that, there are a few things one has to keep in mind, right?
26:23 Um, you know, every Powerful. The first thing is that every powerful agent really requires, uh, an identity and accountability and authorization. And till now, we've been missing, you know, we've relied heavily on authorization, but we've missed out on things like identity. And identity is really key for accountability and traceability. Right. And so if you have any hope of taking AI into the enterprise with all the compliance regimes we have, we have to make sure that AI is a that agentic actions are compliant.
27:00 In other words, they're accountable and traceable. The second thing that, uh, you know, we are talking about is, uh, you know, we're going to be stretching the limits of identity and access management systems. Today, enterprises have typically 50,000 employees, 100,000 employees. If you listen to Jensen Huang in his GTC keynotes. He is expecting to have 5 million agents in Nvidia, and that scale is going to break all the architectures that we have.
27:31 The identity and access management architectures, I mean, and so we have to figure out a way of how to manage these identities. And, and and then the third thing is what is an agentic identity. It may not be just the identity that you and I are thinking about. That is a user ID, password or a passkey? I mean, agent identity is based on some of the what we talked about in the first segment could include things like provenance, the owner, the purpose, you know, the reputation, uh, permissions.
28:00 And so just a agent name or a username may not be enough. So I think it's an important avenue to explore. I think Estonia is taking a bold step. But one thing to keep in mind. An authenticated malicious agent can be far more damaging than an unauthenticated one. And I'll leave you with that thought. I think it's a it's a really good point. You know, I quote this all the time on the show because I love it.
28:25 But as Dave McGinnis has said, you know, AI agents are the most helpful insider threats we've ever had. Right. And I feel like it really gets to that, that point. And I also like that you point out, J.R., that like, part of the reason this has been such a difficult thing is that like an AI agent's identity is not exactly the same thing as a person's identity, right?
28:44 So, like, we can't just apply, you know, human- focused IAM practices to the agents. We have to figure out what they actually look like. Dave, I'd love to get your take on this. And specifically also if you have any concerns about how giving AI agents identities might open up new attack vectors, are there things we should be worried about here or how are you feeling?
29:03 Well, yes. And actually that's that's that was going to be my point. So I'm glad you asked the question. So Estonia is on to something with with providing IDs to these agents. There's there's no doubt about that. But what is preventing those AI agents from becoming compromised themselves. We have guardrails on LLMs now that are circumvented all the time.
29:26 So we're going to give an AI agent an identity, whether it be a username, password, a passkey or whatever. We're going to whatever it looks like. Where does the where does it stop an attacker from getting into your network? How is this any safer than having a human in the loop? Um, I don't know what the answer to that is. That's the part when I was reading this article that I just kept thinking to myself, they're going to give and they're going to give an ID to an agent, and what's going to stop it from becoming
29:55 attacked and becoming compromised? There's nothing. And it's going to fall into the same traps that humans do. Maybe a little less clicking. Way to bring it back to social engineering. Dave. Nice. I didn't mean to go that direction. It just went that way. Good job. No, no, seriously. No, no, I'm. I think it's good that you did. I mean, there is a kind of whole cohesive thread throughout all of this episode.
30:18 You know what I mean? Which is this question of like, as we you know, first of all, the social engineering question but also like, as the agents come in as they're there in our OSes, they're in our enterprises, they're, they're clicking on things for us. They're shopping for us. How do we how do we deal with it? Like how do we manage their the risks to them, too?
30:34 And and Dave, I had the exact same question reading it, which was like, you know, yes, we need agent identities to track these things. It'll help scope their permissions. But like, there's still that's still an identity that can be stolen the same way, like a human identity can be stolen. Right? Like J.R. said, like an authenticated malicious agent is like the most dangerous thing you can have.
30:54 And so, like, you know, I'll pose the unenviable question to you then, Kimmie, which is like, how how do we stop that from happening? Do you have any thoughts on on guardrails and what we can do to protect agents? Absolutely not. I'm afraid that this is the episode of no for me. I told you, I told you it was an unenviable question. Go ahead though. But at the same time I on the topic and in general.
31:17 The first thing I thought when I read the article was wow. As J.R. pointed out, scalability seems like a real challenge here. Um, and and what does an agent look like? Is it? It's in some cases, they're very ephemeral, right? It's just something you use for a half an hour and it's gone. What kind of an identity does it get? Right. Um. Or maybe it's something you created for millennia, and it's going to be the core of your LLM for the rest of its existence, I don't know.
31:44 Um, but how do you decide when it needs to change its passwords? Or, you know, how do you control that? Um, I feel like, again, here, I'm kind of leaning more towards the technical answer and that I would I might want to stand up some kind of a almost an Active Directory kind of looking thing where. But but it's more like a Kerberos token kind of thing where they get it immediately and they can use it for a very short period of time to do what they need to do based on the requirements at the moment, and then they and
32:20 it's gone again. Right? So no one can steal the token and you reuse it. I don't know how this answer works exactly. I just, you know, I've thought, oh my gosh, scale, how are you going to do that? How are you going to give all these agents, millions of agents, their own identity? I mean, we have a big number system, but is it really scalable at that point?
32:42 All right. Thank you J.R. And Kimmie and Dave for joining us today. We are going to move on to the final segment of the show here with Jayesh Kamat, Offering Leader - Application Security to talk about IBM's new partnership with OpenAI as part of the Daybreak Cyber Partner Program. Earlier this week, IBM joined OpenAI daybreak and launched a new application security service using OpenAI's models here to tell us more about the partnership and what it means for security.
33:10 More broadly, we've got Jayesh Kamat, Offering Leader - Application Security, IBM Cybersecurity Services. Jayesh, thank you for being here. To start off, can you just tell us about the partnership? What are IBM and OpenAI up to? Thank you so much for having me. Yes. And great question. So, um, we we and OpenAI. Uh, so IBM and OpenAI, uh, agreed to jointly go together to clients to help secure them, secure their application estate, especially from the latest frontier AI threats, uh, by, you know, by jointly kind of
33:45 working together to, uh, to look at their code, to identify vulnerabilities and to also help them secure those vulnerabilities, you know, as a next step. So that's basically what we agreed to. Yeah. And so let's talk a little bit about this, this application security service that IBM has launched with OpenAI's models. You know, you said you mentioned that it helps sort of defend against some of those frontier AI threats.
34:12 Can you say a little bit more about, you know, what is the service, how do folks access it? Sure. So the service itself is called Security Harness. Um, you know, we we've used a common industry term for this particular service, um, to kind of keep it relatable. And, uh, the service is fairly simple. We, um, we are using a harness to, to control the power of the frontier AI models so that they are more enterprise friendly.
34:42 And they they operate within the confines of an enterprise requirement. So we basically control the power of the frontier AI models. They use them to scan application code for the clients, uh, and have the frontier AI models kind of think about what vulnerabilities they could find in that code. Um, not just vulnerabilities, but also chained vulnerabilities across pieces of code and then figure out how they could exploit them.
35:14 Uh, and then we we also have the capability in the harness where the AI models can go and prove that those vulnerabilities can be exploited. So all of this done safely, uh, in an enterprise context, with all the controls that an enterprise would require, including logs, audits, traceability, etc., is what the security harness does. Absolutely. Thank you for that.
35:33 Yeah, I can see how that would be super important. You know, you can't just let one of these models loose in your codebase. That harness provides those guardrails so you can do it securely and trust that it's not going to do any damage out there. So how does this partnership fit into the kind of broader landscape of AI enabled vulnerability management and application security?
35:53 Right. Do you expect we'll see more advances of this kind coming? How do you feel about that? Yeah, absolutely. I think this is, uh, this is almost a unique for us because, um, you know, like we had the previous generation where cloud was the big thing. Now the AI providers are the big tech giants, right? So from that standpoint, we are working with, uh, OpenAI, uh, to kind of leverage their frontier models.
36:22 So we'll have access to their frontier models early so that we can build the harnesses and capabilities to test and be ready for when they are available for others to use, etc. and then by the time they are available for the clients, we would have our harness capable to to use them in a secure manner to, to work with our clients. So it's kind of giving us early access.
36:49 Working with them jointly. Co-creation, uh, go to Market, you know, alpha clients, all of that nice things to have. Yeah, absolutely. And so, yeah, you're you're playing to IBM gets to play a key role in making sure that these models can be used. They're ready to hit the ground running safely in a kind of enterprise context. Um, any last thoughts or takeaways about the partnership?
37:13 Anything else you want folks to know about what we're doing, uh, in this endeavor? I think this is this is an amazing opportunity. One of the first things that I've seen in a long time, I've been in this industry for a very, very long time. Uh, and the the ability for an AI model to do work that a security researcher would have traditionally done, uh, is a is a huge leap.
37:37 And, uh, and this gives us tremendous power where we can actually look at all the code that has, you know, so far escaped our, you know, view and visibility because we've not been able to scale and be able to handle and scan all that code now can be protected. So it's like like all the stuff that we've never done in the past we can do going forward.
38:03 And this, this partnership allows us to bring the best of both worlds. Uh, our harness, our approach, our consulting skills and the, you know, the model's power, intelligence that is increasing on a day to day basis, coming together to solve an application security problem that has plagued us for a long time. So I think it's an amazing, amazing capability and thing to happen.
38:30 So I'm very excited. I'm very excited, too, now, and I can't wait till folks can get their hands on this. Jayesh, thank you again for coming on to tell us about it. And, uh, everybody can look forward to this new harness. Okay. That does it for today's episode. Thank you to our panelists, J.R. and Kimmie and Dave. Thank you to Jayesh. Thank you to the viewers and the listeners.
38:44 Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so that you never miss an episode. Stay safe out there. And remember, AI can help solve a lot of our problems, but it's not going to solve all of them. You're still on the hook.
Not completely. AI may significantly reduce social engineering by removing humans from routine trust decisions, but the threat will shift toward AI interfaces, agents, identities, and instructions.
Security Harness uses a protective harness to constrain AI models within enterprise requirements while scanning code and safely testing exploitability.
The end of social engineering won't happen when humans get smarter. It'll happen when humans are completely removed from routine trust decisions.
The World Cup isn't just a global sporting event. It's a global attack surface.
An authenticated malicious agent can be far more damaging than an unauthenticated one.
AI can help solve a lot of our problems, but it's not going to solve all of them. You're still on the hook.
Cybersecurity strategist and author who wrote the Dark Reading op-ed about AI-native operating systems and social engineering.
01:33Company behind Security Intelligence, the X-Force Cyber Range, and the Security Harness service developed with OpenAI.
00:37IBM's partner in the Daybreak Cyber Partner Program and in developing the Security Harness application security service.
01:09Referenced in an example involving customer service agents being tricked into handing over Instagram accounts.
05:08Research organization that investigated Operation FanTrap and identified nearly 4000 malicious World Cup-related domains.
15:11Referenced in connection with Jensen Huang's expectation that the company could have 5 million agents.
27:25