Hackers don't break in — they log in. That's the refrain cybersecurity researcher, TED speaker, and self-described friendly hacker Keren Elazari keeps coming back to, and it sets the tone for a conversation that cuts through a lot of the current AI hype.
Host Raghu Nandakumara sits down with Keren to talk about why, despite the constant headlines about AI-discovered zero-days and autonomous attack tools, the overwhelming majority of real-world breaches still come down to the same fundamentals: stolen credentials, unpatched known vulnerabilities, and social engineering. Keren points to Verizon's DBIR data showing that over 80% of web-facing attacks are credential-based, and to the CISA KEV catalog, where under 30% of known exploited vulnerabilities are even patched — numbers that make the "AI supercharges vulnerability discovery" conversation feel a little beside the point.
The two dig into what Keren calls the widening asymmetry between attackers and defenders: AI is getting good at finding vulnerabilities and writing exploits, but not nearly as good at patching them or getting fixes into messy, real-world production environments. She describes AI as "a time machine for attackers" — compressing weeks of reconnaissance and tooling into hours — and argues defenders need that same acceleration applied to mitigation and containment, not just detection.
The conversation also covers:
Shiny Hunters' evolving social engineering playbook — from impersonating employees to get help desks to reset access, to now impersonating the help desk itself to harvest credentials via fake SSO resets, SIM swapping, and deepfake voice tools
The GTG-1002 incident referenced in Anthropic's late-2025 report, where a nation-state actor used an AI model as an active accomplice in an orchestrated attack, and why Keren thinks the sophistication was in AI-driven orchestration, not novel exploit creation
Shadow AI as a new attack surface, using the rapid, often misconfigured spread of local "Open Claw" installations (many left listening on all ports) as a cautionary example
Jade Puffer, an early example of agentic, largely human-out-of-the-loop ransomware, and why Keren wasn't surprised given how much ransomware groups already reinvest in R&D
A malicious-package incident on Hugging Face, and the broader pattern of attackers targeting trusted open-source "watering holes" like GitHub and model/skill hubsKeren closes out by introducing her reframed security fundamentals — Identity, Visibility, and Containment (IVC) in place of the classic CIA triad — and makes the case for "proactive paranoia": preparing for breaches before they happen rather than scrambling once they do. She and Raghu wrap with a shared hard truth: for all the AI conversation, security is ultimately about serving the humans on both sides of the equation, including the fact that attackers are humans too, and often know an organization's environment better than its own defenders do.
Stay connected with our host Raghu on LinkedIn
For more information about Illumio, check out our website at illumio.com