There is no such thing as unhackable AI.
As organizations move faster to integrate large language models, AI agents, MCP servers, and automated workflows, attackers are gaining new ways to exploit excessive permissions, trusted data sources, prompt injection vulnerabilities, and weak security controls.
In this episode of the Dirty South Security Podcast, we sit down with Marek ZmysÅowski, Senior Security Engineer at Microsoft and AI security expert, to examine why offensive AI security and AI red teaming are becoming essential for any organization deploying AI.
The conversation explores how artificial intelligence is changing penetration testing, cybercrime, social engineering, malware development, reconnaissance, and large-scale influence operations. Marek also explains why AI does not replace skilled attackers or penetration testers. Instead, it gives experienced operators the ability to work faster, automate more tasks, and scale attacks that previously required considerably more time and technical knowledge.
Topics covered in this episode include:
⢠Why the idea of unhackable AI is a dangerous myth
⢠How attackers are using AI to accelerate reconnaissance and exploitation
⢠The growing risk of indirect prompt injection and RAG poisoning
⢠Security concerns surrounding AI agents and MCP servers
⢠Why excessive permissions create serious agentic AI risks
⢠How AI is changing penetration testing and exploit development
⢠The role of human judgment in AI-assisted security testing
⢠Deepfakes, voice cloning, phishing, and AI-enabled social engineering
⢠Data poisoning, propaganda, bias, and geopolitical manipulation
⢠Why business logic vulnerabilities still require human expertise
⢠The importance of threat modeling and continuous adversarial testing
⢠What organizations should know before deploying AI into production
Marek also previews concepts connected to his AI model penetration testing training at DEF CON 2026 in Las Vegas.
AI is increasing the speed of software development, but speed without security creates a larger and more interconnected attack surface. Building securely is important. Testing continuously is equally important.
Subscribe to the Dirty South Security Podcast for candid conversations about cybersecurity, hacking, cybercrime, offensive security, artificial intelligence, and the evolving threat landscape.
#AISecurity #AIRedTeaming #Cybersecurity #OffensiveSecurity #PenetrationTesting #DEFCON
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
- Ā VerSprite: https://versprite.com/
- LinkedIn: https://www.linkedin.com/versprite-llc/
- Twitter: https://twitter.com/versprite/
- YouTube: https://www.youtube.com/c/VerSprite
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.