Is the fear surrounding Anthropic’s Mythos model justified? In this episode, Ashish sits down with Johnny Hand, Global CISO at Trend AI and host of The AI Security Brief. Johnny breaks down why turning on a model like Mythos without a multi-stage orchestration layer is like handing someone the keys to a Ferrari when they don't know how to drive. He talks about the 66,000+ CVE "vulnpocalypse" panic and that only 1% of vulnerabilities are ever actively exploited in the wild. We also examine real-world autonomous threats like "Jade Puffer" (the first documented agentic ransomware path) and walk through 3-step maturity framework for enterprise AI adoption: Visibility, Observability, and Actionability via Agentic Governance Gateways
Questions asked:
00:00 Introduction: The Mythos Readiness Assessment Hype
01:50 Johnny Hands’ Background & Trend AI’s Mission
03:00 Debunking the Mythos Assessment Panic in Europe and Japan
06:30 Handing over the Ferrari: Why Mythos Fails Without an Agentic Harness
09:30 The "Vulnpocalypse": Clearing 66,000+ CVEs & Finding the 1% That Matter
13:30 Moving Away from "Busy" Metrics: How to Report AI Risk to the Board
17:30 Coupling Low-Severity CVEs with Risky User Behavior
21:00 Inside the Zero Day Initiative (ZDI) Multi-Stage Agentic Harness
25:30 Filtering LLM Hallucinations with Multi-Model Statistical Inference
28:50 Deconstructing "Jade Puffer": The First Autonomous Ransomware Path
35:00 Virtual Patching and Fencing Against Fast End-Day Weaponization
39:00 The 3-Step AI Security Maturity Model: Visibility, Observability, Actionability
44:30 The "You Laugh, You Lose" Cybersecurity Joke Challenge
Johnny Hands: [00:00:00] Models we have today are the worst they'll ever be. We're on track literally, um, right now to clear north of sixty-six thousand CVEs.
Johnny Hands: It's like I've given you the keys to a Ferrari, but you don't know how to drive.
Johnny Hands: The threat actors use an agentic harness to build some specific role and functions so they can make it, like, really one of the most probably the first documented autonomous attack paths for ransomware.
Johnny Hands: The numbers are real, but the, uh, stress around it is not. Can it find vulnerabilities? Yeah, even when they weren't there. But within minutes of the disclosure, we instantly started from China, India, Pakistan. Like, within minutes of the public disclosure, we were getting hammered with it. The moment there's a POC that's talked about, especially in AI, they're automatically weaponizing that, and you have to be just as fast.
Ashish Rajan: Mythos Readiness Assessment is a conversation that we've been having, at least across the European and UK side. And if you work for a global organization, you perhaps have heard of this as well. This episode I recorded with Johnny Hand to talk about, hey, fundamentally, what is w- that we're trying to solve with behind the [00:01:00] whole Mythos conversation, behind the whole agent harness conversation.
Ashish Rajan: What does that mean to have an agent harness that you can use? Even if you had access to Mythos, what is the real possibility that you could achieve if you didn't have an harness? All that and a lot more in this conversation with Johnny. He has been a CISO before, and he's currently the CISO of TrendAI
Ashish Rajan: And we spoke into some of the threats that are s- real today with the Jade buffer and how agentic security is evolving quite a bit. If you're here for a second or third time and have been enjoying the episodes of the podcast, I would really appreciate if you hit the follow subscribe button, whichever podcast platform you listen to us on.
Ashish Rajan: We're on YouTube, LinkedIn, Spotify, and Apple as well. I hope you enjoy this episode. I'll talk to you soon. Hello and welcome to another episode. I've got Johnny with me. Hey, man. Thanks for coming on the show.
Johnny Hands: Yeah, thanks for having me. I'm excited.
Ashish Rajan: I mean, I'm-- Like, first of all, thanks for having me on your podcast as well.
Ashish Rajan: And people who may not know about the podcast or what you do, can you share a bit about yourself, your p- professional background as well?
Johnny Hands: Yeah. Yeah. So professionally, I'm, uh, the global CISO for Trend AI- Mm ... which is in, uh, the leading AI security company. Um, excited to, to be a [00:02:00] part of the transformation to an AI native company, which is exciting.
Johnny Hands: Um, our podcast is the AI Security Brief. Uh, it's a very fun and exciting one to do. What we really try to do with our podcast is we don't try to be too informational in that perspective. We try to basically give nuggets to the security leaders and really look at it from the lens of how is AI transforming cybersecurity- Mm
Johnny Hands: the good, the bad, you know, the ugly- ... the exciting, all of that. And, uh, we try to feature threat researchers- Yeah ... industry leaders, CISOs, CIOs, um, experts like yourself- Absolutely, yeah ... which was great to have on. We had a great conversation. And, um, just look for bringing that nugget where someone can just turn around and say, "Man, I gotta talk to my team about that."
Johnny Hands: Yeah. "That's pretty exciting." And we do it in a shorter format as well. So it's about twenty, twenty-five minute something that's very consumable, very digestible. Yeah. But it's a lot of fun to do.
Ashish Rajan: And I appreciate you kinda saying this as well, which is digestible, because one of the things that have been, I don't know, truly is digestible, but Mythos Readiness Assessment.
Ashish Rajan: You and I, you and I have spoke about this. At least seems to be a sensation, at least a thing in the European side and the U- UK side 'cause you guys obviously [00:03:00] work globally, like a lot, many others. But, uh, when you and I were talking about it, it kind of touched our hearts a bit. So maybe to , set the scene, could you share what your understanding of Mythos Readiness Assessment is from what people are asking?
Johnny Hands: Yeah.
Ashish Rajan: And what are your thoughts on, on the whole topic? I've got, clearly got my own thoughts, but I'm keen to hear from you as well.
Johnny Hands: Yeah, you know, I, I can go both ways on it. I understand, certainly from a marketing perspective, like, I understand that there's an opportunity there, right? Yeah, yeah.
Johnny Hands: There's a lot of hype and a lot of excitement around the models and what they're doing. Um, sometimes good, sometimes bad. I, you know, as a CISO, especially of a global a global company, as a technology company, I've had a lot of conversations around Mythos. Yeah. And in fact, probably in the last four months, I've probably had conversations two, three, four times a week with customers and industry leaders.
Johnny Hands: And interestingly, you said something that is surprising. We, we don't have as many conversations here in North America about it- Yeah, yeah.
Ashish Rajan: Yeah ...
Johnny Hands: um, as we do in EMEA and- Yeah ... uh, Europe. Yeah. And there's a lot-
Ashish Rajan: Japan as well.
Johnny Hands: Japan as well.
Ashish Rajan: Yeah,
Johnny Hands: yeah. And I, I think it comes from two things [00:04:00] One is the, there's a fundamental misunderstanding of what Mythos is and what the Glasswing Project was supposed to do.
Johnny Hands: Yeah. Right? And we're, at Trend AI, we're members of the Glasswing Project. We've had access to Mythos. We've used it. It's exciting, you know, capabilities in that aspect. But a lot of people think, "Oh, this thing is gonna just turn on me- ... and tell me all the vulnerabilities and, uh, and I'm gonna be exposed."
Johnny Hands: And so I think that kind of fear-mongering around it is, makes sense why you could market something like these assessments. Yeah. I think it's, a little bit disin- disingenuous, being honest. Mm. Um, but, but we've seen this time and time again in the industry. You know, there's a new exploit. I just, I remember, um, you know, Heartbleed came out and there- Yeah
Johnny Hands: was Heartbleed assessments. Yeah, yeah. And it's like, "Guys, it's already exposed. You can, you can find it pretty easily."
Ashish Rajan: Yeah.
Johnny Hands: Um, but, you know, you go back to, to if there's an opportunity, there's a chance. And I wouldn't say that they're not valuable but I think there's a challenge to it that you're kind of looking at an exposure that may not be your biggest risk.
Ashish Rajan: Yeah.
Johnny Hands: There's a window of exposure there, but that takes you [00:05:00] back to how effective you are actually in your, your base core programs around, you know, like I, I'll tell people, "How good are you at addressing things that are on the KEV?" as an example. Yeah. Like, are you really good, or can you do that in hours, minutes, and days?
Johnny Hands: Yeah. Or do you do those in a two-week or three-week or four-week patch cycle? If that's the case, your Mythos assessment's probably not gonna help you very much. Yeah. Because, you know, as soon as that's done, there's gonna be another one next week. Yeah. And, uh, and you'll be a little bit, um, gated there.
Ashish Rajan: Yeah, and you'll have a new list to work with every week as well.
Johnny Hands: Yeah.
Ashish Rajan: So you start almost just using the assessment to build your backlog, for lack of a better word.
Johnny Hands: Yeah, if you wanna, if you wanna go, "Oh my goodness how am I ever gonna address this mountain of things it found?" Because it, it finds, it, it can find some stuff, uh, these AI automated you know, assessments are good, but, you know, the simple one is scan for what's already known, and have you addressed all of those, right?
Johnny Hands: Do you have a plan of attack for that? I'm more curious about the, the well well-developed exploits in the wild that are causing damage-
Ashish Rajan: [00:06:00] Yeah ...
Johnny Hands: than I am about the unknowns.
Ashish Rajan: Yeah. A-a-and I think it's worthwhile calling out as well, uh, and I use the example of having access to Mythos is almost like having access to a Ferrari if you don't have the right agent harness and the right capability behind it.
Ashish Rajan: It's like I've given you the keys to a Ferrari, but you don't know how to drive. I don't know if you agree to this, uh, analogy in terms of the Mythos and whether just because someone has access to Mythos doesn't really mean they're gonna just go ballistic at the co- every company they can find.
Johnny Hands: Yeah it's an interesting thing.
Johnny Hands: So one, Anthropic's done a good job responsibly of, of you know, establishing, you know, gates to get access to Mythos. Yeah. So, you know, typically that's through the Glasswing project. Um, obviously, you know, the US government has some sanctions and controls around that as well. Mm-hmm. That has, has impacted that.
Johnny Hands: Um, so w- we, you know, in that, in that case, that model specifically is, not available publicly. In that. Yeah. But there's other models that are, are very good as well, and, uh, to your point, you mentioned the agentic harness thing, and I think that's something that people don't understand.
Johnny Hands: Mm-hmm. They don't understand, one, the models are good, but in many ways, I, I go back to, [00:07:00] like, vulnerability scanning. You do vulnerability scanning like I, I'll take a, um, you know, non-auth-authenticated scan.
Ashish Rajan: Yeah.
Johnny Hands: And you run that, and you're gonna find so many things. Yeah. But then the first thing your systems guys are gonna go, "Yeah, but you ran a non-authentic scan, and, it didn't do a handshake, and it didn't do this, and I'm not, you know, really exposed 'cause we changed that Apache package there, but you couldn't actually see it."
Johnny Hands: And so it's gonna be noisy and, and clumsy and, you know, so a better way is to do that authenticated scan, you know, more focused and get a better visibility. Or even better is, like, having an, uh, an endpoint agent for those vulnerable... To, to truly show that you have that exploit. And in the same way, they think you just turn on Mythos, and it's gonna find all the bad stuff.
Johnny Hands: Yeah. And I think what we're seeing, not only internally with our research, but also, um, some other research that's been published with Wiz and, and others that have access to Mythos is can it find vulnerabilities? Yeah, it can certainly. And it can also find them when they're not there, right? Mm-hmm.
Johnny Hands: It's, um, it's very congratulatory that way and, and wants to find stuff. Um, so it's really about building that agentic harness framework that allows you [00:08:00] to do the real work, which is that attack path validation and making sure that the exploit is really, um, there and, and then how do you defend against that?
Ashish Rajan: Yeah. And I think maybe, uh, I, I... One, one of the reasons I brought that up is because, A, to put some light on the misunderstanding people have of Mythos, but also a lot of CISOs who probably at Black Hat, which, where you and I both attending It's, there is a under-- I, I guess what I'm trying to figure out is what's the right path for people to follow?
Ashish Rajan: 'Cause the reason why people have gone down the path of Mythos readiness assessment is because of there's so much unknown.
Johnny Hands: Yes.
Ashish Rajan: And they fear the unknown unknown is like, "Hey, what is it that I don't know?" And Mythos would find all these zero days, and it'll be... And to add to your what he, to what he said, kudos to people who've figured out the marketing opportunity to kind of double down on this.
Ashish Rajan: But the information's already there in front of people if they wanna just look at it. But the point being There's also a sense of, "I'm not sure where should I start my AI security efforts." A lot of the conversation on the floor and with CISOs has been around, "Hey, I'm trying to uplift my existing security programs," 'cause every enterprise has an EDR, has [00:09:00] MDMs, have every kind of solution you can think of, right?
Ashish Rajan: Even from a cloud perspective as well. What's a good place to start the AI security program conversation or of some of the components that you think that are relevant? Like, obviously, keeping the Mythos thing aside. Like we- Yeah ... all understand that, and what's the realistic thing? Because I think there was a report that I was w- reading from you guys, about 66,000 CVEs came out.
Ashish Rajan: Yeah. If you wanna shed some light on that and maybe weave in what can... What's a good place for people to start, and what should they be looking at?
Johnny Hands: Yeah. So that report is actually a blog I wrote.
Ashish Rajan: Oh,
Johnny Hands: yeah. Um, yeah. And it's funny, I, I'm sure you're this way as well, you, you write. Sometimes I, I write things not because I...
Johnny Hands: mostly 'cause I'm having these conversations all the time. Yeah. And so that, that's one where I did a play on words because I've heard this over and over for about a month, about the vulnpocalypse, right? Yeah. This wave of CVEs- Mm-hmm ... that are gonna come at us. And, you know, the interesting thing is we can just fact-check that.
Johnny Hands: We have many published sources of exploits. You know, we have the NVD, we have, uh, you know, CISA, obviously. [00:10:00] We also have the KEV, and we have other, third parties, and then we, we do it as well with our zero day initiative. So the data is available publicly. Yeah. So I'm like, let me just pull this and see.
Johnny Hands: And it was interesting because what I wanted to see was, we're halfway through the year.
Ashish Rajan: Yeah.
Johnny Hands: And I wanted to see was this wave, unmanageable wave of vulnerabilities, did it actually hit? And so it was interesting. When you looked at 2025, and if you go back to 2024 as well, we did see year-over-year record-breaking CVEs.
Johnny Hands: So we went from, you know, in the ballpark of, like, 38,000 in, uh, 2024. In 2025, we had 48,000, which was the most we've ever had, and then we're on track literally, um, right now to clear north of 66,000 CVEs.
Ashish Rajan: Oh my God.
Johnny Hands: So that feels, like panic mode for many security leaders. Mm. How am I going to address?
Johnny Hands: But the more logical way that I always tell people is, let's go to the, the what I call the impactful numbers, right? So if you look at the, like, from a zero day initiative perspective, how many of these are zero days? How many of them are critical? How many are being exploited in the [00:11:00] wild? Well, those numbers actually have stayed fairly flat.
Johnny Hands: And in fact, those stayed about 1%. Oh. So if you think about 66,000, that feels overwhelming. But if you go down and you say, "Well, maybe it's more like six or 700 I have to think about"-
Ashish Rajan: Yeah ...
Johnny Hands: well, that's more manageable. Yeah. It's that old adage of, like, how do you, how do you eat an elephant? Like, one bite at a time.
Johnny Hands: Yeah, yeah. And, um, so I, I wrote that one as a play on words around the vulnpocalypse because I wanted to bring light to, yes, we're going to find more vulnerabilities. It's already happening, and in fact, we're gonna, do record-breaking numbers this year. But if I'm in a CISO seat and I'm looking at an organization, I'm trying to figure out what's the most impactful work that I can do.
Ashish Rajan: Yeah.
Johnny Hands: And the most impactful work are on those vulnerabilities that are being exploited in the wild, that have high likelihood of impact. And then you have to look across your organization and understand those vulnerabilities in context to your environment, which is unique for everybody. And then that's how you come up with that risk exposure, kind of understanding.
Johnny Hands: And, um, [00:12:00] there's other components of that. You know, there's certainly some low and medium severities that could be attacked and there could be attack paths. Yeah. But they're much harder to walk through to a really good exploit. But yeah, I think, I think the, that number looks scary and it's...
Johnny Hands: And guess what? In 2027, it's probably gonna be double of that. Yeah. But I think it, it allows us as security leaders to start looking at automation principles of how we address the things that are gonna be the most impactful. Yeah. The, the other thing I share about those 66,000 is, well, how many of those are on vendors that you don't have in your environment, right?
Johnny Hands: Yeah, exactly. If you look across it, if you're primarily a Cisco shop or primarily you know, Broadcom or whatever it is, you probably don't have, 66,000 new vulnerabilities. Yeah. But yeah. So I think it's a practical approach of maybe maybe it's because of my background in the military, I just, I stay calm.
Johnny Hands: Yeah. And I go, "Okay, well, let's look at the real impact of this." Yeah, yeah. And that was really the point of that, uh, blog post I made was, the numbers are real, but the, uh, stress around it is not. And if we calm down a little bit, um, and we do sound principles, we can [00:13:00] actually attack the real risk fairly simply.
Ashish Rajan: Yeah. But to your point, a lot of people report on that as well in terms of internal, not just externally vendors talking about it, but also in general, the CISOs also, or head of SOC would go, "Hey, there are 60,000, 66,000 vulnerabilities that have been announced." And, uh, they go through this exercise of reporting for ROI or whatever the reason may be.
Ashish Rajan: What's the right way to, uh, to report on metrics, especially in an AI-driven vulnerability management kind of a way? 'Cause a lot of people kind of- It, to your point, you'll get 66,000 now suddenly like which one's relevant, but I'm just curious as to what's the right metric people should be using to report anything which is AI-driven security in their organization.
Johnny Hands: Yeah. It's an interesting one. You know, I chased this, I call it chasing the rabbit a little bit for my whole career.
Ashish Rajan: Yeah.
Johnny Hands: I used to think about... And the way I imagine this, I don't know if this makes sense to you. I, I th- uh, I think it will. I've talked to other security leaders. I used to imagine I'm waiting for a product around vulnerability management that's gonna show this kind of waterline where I'm always closing the gap, right?
Johnny Hands: Mm. So, like my actual [00:14:00] exposure and my actions that this, you know, in the old days of, uh, you know, charting and graphing everything, that I'm seeing like this chart continually going, and my success around my program is that my gap is always getting, you know, smaller and smaller. Of course, you know, Patch Tuesday comes out or whatever and you get a blowout, but on the, on the scale of looking at it across six months or a year or whatever, I always felt like that was a really good metric.
Johnny Hands: And, um, as I, you know, kind of matured around the, that... Then I realized, oh, I'm chasing that larger number, and how am I attacking that larger number? And I'm never going to tackle that larger number. Yeah.
Ashish Rajan: Now,
Johnny Hands: so then when I think about what's important from a business metric, which I think is the translation that sometimes we get so close, to the technical as CISOs and as security leaders that we actually wanna show how much work we're doing.
Johnny Hands: Yeah. Right? It's like, let me give you the metrics." Mm-hmm. But as we know, like busy isn't productive. And I think that's a challenge. We're trying to show how busy we are. Yeah. And maybe five years ago, that was to justify headcount- Mm-hmm ... and, uh, maybe, you know, grow our [00:15:00] programs or whatever it is.
Johnny Hands: But the board level doesn't operate in busy. No. They're not thinking about busy metrics. They're thinking about impact. So what I would encourage security leaders is start documenting the metrics for your business that allows you to become a business enabler that's showing your impact, right? Mm-hmm.
Johnny Hands: So if you look across those 66,000 and you distill it down and you say, "Hey, in my organization, based off, you know, whatever my, uh, vendor use is, that, you know, we had 1,000 that were, we considered significant enough to take major action." And by doing that, can you quantify it to some risk exposure? Yeah.
Ashish Rajan: Yeah.
Johnny Hands: And maybe actually quantify that to some dollars. That's a metric that the board understands. They understand business impact. Yeah. Um, they don't understand busy. Yeah. Right? Everyone's busy. Yeah. But we like to do that. We like to showcase how... And sometimes we do that with our technical acumen, too.
Johnny Hands: Yeah. It's like we get really technical and-
Ashish Rajan: You gotta show it off.
Johnny Hands: We show it off, yeah. And then the board... You know, I remember, um, I was doing a, a meeting one time And I had, uh, this amazing CIO that I used to work for, and, um, y- you know, I was [00:16:00] building a, a presentation for the, the board and all this stuff, and we went through these assessments, we did all these things, and you just wanna showcase the work like your amazing team is doing, right?
Johnny Hands: And then, um, I was basically told to like, yeah, do that, but I need two slides." And I was like-
Ashish Rajan: Put all of that in two slides.
Johnny Hands: Yeah, and I was like, "That's impossible- "... because you're gonna lose the story." Yeah, yeah. And my story was how good we're doing, right? Yeah, yeah. Um, but you know, he knew something I didn't know at that time, and he needed to show value to the board.
Johnny Hands: Yeah. And that board of trustees wasn't calling on him. Now we-- At the time, the board of trustees was extremely capable, very, um, very astute, and they asked great questions. Yeah. But ultimately, we're, we're moving the business forward, and so, you know, 20 slides on how busy you are doesn't translate well.
Johnny Hands: But the impact, if we don't make these decisions and we don't invest here-
Ashish Rajan: Yeah ...
Johnny Hands: that's where you wanna communicate.
Ashish Rajan: Yeah. And I guess you find a balance between, obviously, we're talking about AI-driven vulnerability management as well. Where do you find is the balance between AI-driven vulnerability management [00:17:00] versus just human-in-the-loop, uh, as a, as a concept?
Ashish Rajan: 'Cause I think a lot of people are on this journey where, uh, they've been told that, "Hey, AI can do a lot of this. You don't have to do this." And a lot of people are looking, "Hey, maybe I can use AI for security for some of that automation as well." Yeah. But then there is the aspect of what you said, where there are sixty-six thousand vulnerabilities, how many of them truly can be...
Ashish Rajan: And you obviously wanna use AI to go through a lot of, lot of volume, but at the same time, how do you find the balance for, "I don't wanna miss any opportunities there." Yeah. So where, how are you seeing your customers kind of balance the two of AI in the vulnerability management space?
Johnny Hands: Yeah. I think the common narrative still needs to be your risk exposure, right?
Johnny Hands: So, you know, AI, uh, vulnerability scanning, as an example, is a great capability. In fact, I love the concept of it. I love the models. I was actually just, um, doing a great panel discussion with, um, Anthropic. Oh, yeah. We had AWS and NVIDIA all on the same stage. Um, it was a good one 'cause I had an opportunity to you know, really bring light to the last few weeks [00:18:00] of incidents, the, the Gold Eagle standing up as a vulnerability clearing house.
Johnny Hands: So we didn't really hold any punches. They were very transparent. But one of the things that I take away from that is Rob Behr, who's the head of national, uh, security partnerships for Anthropic. Mm. He made a statement, which is kind of scary, but also just the reality. He said, "Mythos and the models we have today are the worst they'll ever be."
Ashish Rajan: Yeah.
Johnny Hands: Right? Yeah. And so we got so excited about these capabilities. So I think what we should look at is rather than being intimidated or, or maybe scared about what these models can do, is actually turn that around as you know, a net positive for defenders. How can we leverage these to just up our game and get ahead?
Johnny Hands: Mm. So the AI-driven vulnerability you know, discovery piece, I think is important. But then what happens after that? What-- And this is the fundamental issue we have with vulnerability management programs today, is we're really good at discovery. We're really bad at patching, right? Yeah. And sometimes it's because there's not a patch available.
Johnny Hands: Sometimes it's on a system that you don't want to patch because of, you know, [00:19:00] business needs and outcomes. So I think that's the, the, the bridge that you have to do is you have to understand from a risk exposure perspective how that vulnerability is going to impact you. And, you know, a great example, um, that one of the things that I, I love-- I loved it as a customer, but love as a, a product piece is, um, one of the things that we focus on is your entire cyber risk exposure.
Johnny Hands: Yeah. Right? And people-- Sometimes I think that becomes a marketing term, right? I'm, I'm being fully transparent, but the way that I communicate this and why it's important from a AI-driven vulnerability conversation is really simply this. We do focus a lot on these criticals and highs, right? And these things that are, uh, no one exploits, you know, in the wild.
Johnny Hands: But let's change the conversation a little bit. Let's say that you have, as an example, you have, uh, an endpoint that has a lower medium vulnerability. Yeah. Right? Most people probably aren't going to prioritize patching, right? And maybe it's down the line, and maybe you work on it on a 30-day cycle or maybe a 90-day cycle.
Johnny Hands: But then if you look at the risk exposure and you [00:20:00] couple that, and you need to have the telemetry to do this, but you couple that with a risky user that pops. Mm. Maybe this user's in Europe on a VPN that you didn't approve. Yeah. So now you go from having a low to medium severity that you probably wouldn't pay attention to, and then you tie that telemetry to now a new risky user that happens to be the one logging into that machine.
Johnny Hands: Mm. Right? And now you have to wonder, could that risky user be running something locally that could build an attack path on that vulnerability that maybe you didn't prioritize? Yeah. So the risk exposure is now much greater, and you have to have the visibility. So my point to this is, this is really about, like, your risk appetite and how are you managing your risk exposure.
Johnny Hands: Yeah. So that AI-driven vulnerability discovery is really important because you might find something that doesn't look like it has an attack path, but then you couple in some environmental factors that may not be good hygiene.
Ashish Rajan: Yeah.
Johnny Hands: And then that risk that was a low to medium now goes to a critical SEV-1 that you have to address.
Ashish Rajan: Mm. I, I, I also love this also because, [00:21:00] uh, it ties back to the agent harness conversation that we had earlier as well. It's great to have Uh, y- y- obviously, every organization is making a choice between should I build a harness, or should I use myself, or should I use AI driven? Uh, there was AR- uh, Acer?
Ashish Rajan: Acer?
Johnny Hands: Yeah, it's our... We, we- I don't know how
Ashish Rajan: to pronounce it. Is, like... It's Acer?
Johnny Hands: Yeah. Ace- Acer is the internal name, I think. Y- yeah. Um, really, it's our zero day initiatives, uh, agentic harness program. Right. And, um, yeah. So that's... it's a great translation, yeah. So, and
Ashish Rajan: do you wanna share a bit more about that, and what's that...
Ashish Rajan: Uh, and what was the idea behind it? What's the- Yeah ... problem it's solving?
Johnny Hands: Yeah. It's, it's probably more more important now in the conversation than I, I think we thought it was two years ago. We, we actually started building this a few years ago. So zero... Our zero day initiative for the audience that m- may not know, is the largest bug bounty program.
Johnny Hands: It's been in place for over 20 years. We process in terms of, critical and uh, high-end critical that have been exploited in the wild. We actually process about 70% of the world's major bugs out there. Oh, wow. Those come from both our internal team around 500 threat researchers, but we have a [00:22:00] network of over 20,000 threat researchers globally-
Ashish Rajan: Yeah
Johnny Hands: that submit through that bug bounty. And one of the things that happened was we're receiving, thousands and tens of thousands of potential bugs. Yeah, yeah. Right? And this is a great conversation with what happens with, you know, these Mythos models and, uh, AI-based discovery, is potential bugs, right?
Johnny Hands: But are they exploits? And so a lot of these threat researchers are submitting these, and before we were using human, uh, in the loop to analyze them, and then proof out their methodologies, do POCs and prove. And, and once we proved there was a zero-day exploit, we would create a virtual patch and deploy that out through our network of sensors, so our customers were protected before the disclos- disclosure ever happened.
Johnny Hands: So it's a great, uh, metric that we use for our customers. But here is the, the conversation. As the volume continues to go up, how do you keep up from a human perspective?
Ashish Rajan: Yeah.
Johnny Hands: Because in order to build, like the reason you need these agentic harnesses and the reason you need to train these, um, these agents on this activity is because it is a skill set.
Johnny Hands: [00:23:00] It's not something that a language model does naturally, and I think that's the missing piece is we think Mythos, you just turn it on and it's gonna find all your flaws. It will find flaws, but they don't, it doesn't mean they're real. So you still need that, um, human in the loop and that really, like the analyst train perspective.
Johnny Hands: So what, um, the ZDI agentic harness was for us about two years ago, we built a multi-stage, uh, agentic harness to basically have different agents for different roles, like fuzzing and all the different things. So the... i'll kind of categorize it this way. The left side of the pillar, if you will was really designed around discovery.
Ashish Rajan: Yeah.
Johnny Hands: And the right side of the pillar of those were multiple agents. There's I think the nine or 10 agents in that uh, agentic harness, is built on validation, right? Building an attack path and validating that's a true exploit, and then that would hand it off. So we automate that process so that we can bring in those tens of thousands, distill them down, and hand them off to a security researcher that can prove what it found was true.
Johnny Hands: So we get rid of the false positives, and then we ship those you know, real [00:24:00] zero days through the zero day initiative, do our responsible disclosure to the vendors and work through that, uh, that process. Then comes along Mythos, and everyone goes- Yeah ... "Oh no, you can do this automatically." And we actually had this lens where we...
Johnny Hands: Oh, well we've... That's why I think we had this position where we're like, "Yeah, we're doing that. We're doing that from the seat of, uh, the ZDI community."
Ashish Rajan: Yeah.
Johnny Hands: But it proofed out that need. So as we built out as we became members of Glasswing as an example, and used Mythos models, guess what harness we used?
Johnny Hands: Mm. We didn't have to reinvent the wheel. We actually have been doing this for two years. And if you look across some of, um, the other, you know, leaders in this this- this venture that they've been publishing as well on, on these, the need for this agentic harness. Yeah. I believe it was Wiz actually did a, a publication where they, they showcased their harness and they kind of open sourced it.
Johnny Hands: But one of the things that, that, um, when they published, they said, "Can it find vulnerabilities?" Yeah. Mm. Even when they weren't there. Yeah. And so they really, they f- they discovered what we already knew through using our ZDI agentic harness, which is by itself it doesn't [00:25:00] help you. Mm. But if you, build it into a really good harness with, you know, multifunction agents that have specific roles, very similar to how we would act as threat and security researchers-
Ashish Rajan: Yeah
Johnny Hands: then the fidelity on your findings are much better. Yeah.
Ashish Rajan: But with the multi-stage agent as well, I think, uh, was it an MCP study that we s- may have mentioned or, or spoken about where hallucination is still a thing.
Johnny Hands: Ugh.
Ashish Rajan: I mean,
Johnny Hands: yes.
Ashish Rajan: And multiple agent... I mean, so to your point about you're trying to manage the token cost and you're trying to have the right kind of outcomes as well, how do you guys go about with this multi-stage agent?
Ashish Rajan: 'Cause a lot of people who may, you know, watch this that, oh, the ZDI framework that you talked, spoke about, this multi-stage agent, how do you manage hallucination around it? 'Cause again, it goes back to the, the reason why security people go up in arms about, hey, hallucination, is because they're like, "If there is genuinely a vul- vulnerability, I want to find it, and I don't want that to be a false positive-"
Johnny Hands: Yes
Ashish Rajan: because an AI thought it was a false positive.
Johnny Hands: Yeah.
Ashish Rajan: So how do, how do you do that?
Johnny Hands: Yeah. So to get the root of that challenge, you know what [00:26:00] security practitioners love?
Ashish Rajan: What? Deterministic
Johnny Hands: rules. If then, if then, if then. Yep. Right? And I had this conversation with someone. I was like, "You know, automation is not orchestration, and orchestration is not autonomy," right?
Johnny Hands: They're different things.
Ashish Rajan: Yeah.
Johnny Hands: You can build automation on if then rules. Yeah. And orchestration is when you orchestrate, uh, those rules. And then autonomy is when you... Is the thing that we don't like in security, which is this non-deterministic view- Yeah ... where we give it a direction and then don't like when it doesn't take all the direction we gave it.
Johnny Hands: And so the need for these the, the agentic harness and a multi-stage approach is really to address that fidelity piece around both hallucinations and drifting and all of these kind of things that we find, and not always getting to the same finding in the same way. It's kind of the heart of this non-determinist- deterministic ma- nature that we, you know, also are as humans, by the way.
Johnny Hands: Like, two different analysts will get to the approach differently. Um, but we want it to, you know, clearly show the path. And so for us, that's one thing we had to tackle. You mentioned the study on the, um, MCP. MCP, MCP. I think we found, [00:27:00] yeah, like 19,000, um, issues, and we scanned. I had talked to the researchers that actually wrote that, and, um, I was like, "Hey, what's your, what's your methodology behind your stages?"
Johnny Hands: And what they did was they built essentially a three-stage approach. Okay. And the reason they built the three stage, three stage multi-model, and then basically did a statistical inference layer on top of that. Mm. And the reason was what they found was- And the first one with less expensive models, that first layer there was almost like more findings than they initially started with repos, right?
Johnny Hands: Oh, wow. It was like that, like the repo count was less than the amount of findings. And they knew that there was false positives. So then they said, "Well, let's distill that into a secondary stage, and now let's use more expensive models with a little bit more, but we expect to be hall- hallucinations, but let's see how well it does."
Ashish Rajan: Yeah.
Johnny Hands: So it was a, it was another multi-model a- approach where they distilled it through more expensive, you know, higher token usage and still a fairly large amount. And then they, let's say, "Okay, let's do a multi-stage where we test [00:28:00] those and validate them against some of the best models," which are- Mm
Johnny Hands: very expensive, but we'll give it a statistical framework for like confidence layers- Yeah ... and filter out. And then what we found was we were able to filter out at each stage a lot of that hallucination noise, so that when we got to that multi-stage approach- Yeah ... we actually had a grouping of vulnerabilities that made sense and was more statistically accurate to what we would expect if a human analyst found it.
Ashish Rajan: Do you find that now there are much more... So do you-- I mean, it's funny, right? 'Cause I almost feel that when you and I are talking about agent harness, a lot of people are going, "These guys are sort of talking about voodoo science." It's like they're, they're-- Well, and also I wanna put a caveat that none of us are data science experts and- Yes
Ashish Rajan: we're, we're all picking this up. But it's no longer just us crazy people talking about agent harnesses, but there are actual use cases or actually case studies that have come out with the Jade buffer- Yeah ... Hugging Face. Maybe if you wanna expand some of that and why those are more of agentic nature and how does that tie back to the harness piece?
Ashish Rajan: That if you were impacted by it, [00:29:00] how would you ratify it and all
Johnny Hands: that? Yeah. I love that you talked about, uh, the Jade Puffer. It's such an interesting one. I think not be... It's, it's interesting on two fronts. One is it's not novel and new in the way that it did things.
Ashish Rajan: Yeah.
Johnny Hands: But it was novel and new in the usage of AI- Yeah
Johnny Hands: which we hadn't typically seen, right? We've seen ransomware before. Uh, we've seen, you know, ransomware detonated. We've seen people... And in fact, like Jade Puffer's a good example because it used a fairly outdated exploit, right? That just- Yeah ... wasn't patched. Yeah. Um, but what happened was the threat actors used an agentic harness to build some specific role and functions, um, so they could make it, like, really one of the most, probably the first documented autonomous attack paths for ransomware.
Johnny Hands: And, um, and that's a really great use case of what you do. If you think about an agentic harness as an orchestration layer-
Ashish Rajan: Yeah ...
Johnny Hands: um, kind of to simplify it a little bit. It's not, it's kind of an oversimplification. But if you think about it from an orchestration layer and you're giving these instruction sets so that they, these agents can stay kind of singularly focused on specific tasks- [00:30:00] Yeah
Johnny Hands: then the models work much better. And- Yeah ... the way that I kind of explain it is, like, if you've ever, just chatted with GPT models you notice they start going off topic and, like, you know, you end up going like, "Well, why did you think about that?"
Ashish Rajan: Yeah.
Johnny Hands: And if you think about it from, like, a high-value task operation, well, I don't want my expensive employee to get off task.
Johnny Hands: Yeah. I actually wanna keep them very, very focused. So you set these guardrails, you build the harness as an orchestration layer, and now what you do is you kind of singularly focus these agents to do these tasks in, you know, an orchestrated fashion so they can work together like a team.
Ashish Rajan: Yeah.
Johnny Hands: And then you get a lot more value out of your token utilization.
Johnny Hands: And, um, so you look at Jade Puffer autonomous attack exploited a known CVE. So on one side you go, "Yeah, if they would've patched that a year ago," 'cause it's been out for a long time, "then that attack path would not be possible." Yeah. So it's not novel and new. That's what any threat hunter or threat actor would do- Yeah
Johnny Hands: in your environment, is find an exploit and go exploit it. Yeah. Um, so but I think it was neat [00:31:00] that the actual payload that was detonated, you know, was, was clearly written by a- an LLM. Mm-hmm. And then they changed the payload and, um, so there's some novel new characteristics there. But that's a really good showcase of, like, if you just take a model even if it's, you know, the best model, and you just kind of point it generically, it's gonna be terribly inefficient.
Johnny Hands: Yeah. And, and probably so noisy, it's like someone kicking around your entire house and saying, you know, "Hopefully nobody hears me." Yeah, yeah. It's like, you know, they're knocking over all the furniture. That's kind of, uh, my visualization, if you will, of, of, like, what would happen is if you don't tune and, and really focus those agents on tasks.
Ashish Rajan: Yeah. And I, I think, uh, just to extend that a bit more, uh, I don't know if you remember Metasploit.
Johnny Hands: Yeah.
Ashish Rajan: A lot of us basically who started that Metasploit journey, it used to be so noisy.
Johnny Hands: Yes.
Ashish Rajan: But as a script kiddie, you don't even think of it. You just basically go ex- Metasploit minus A, I think- Yeah
Ashish Rajan: whatever the command was, an IP address. Yeah. And you're like, "Oh, that's literally what this AI model attempts to do when you just basically point at it." Uh, the Hugging Face [00:32:00] example where in a very short window they had about, I don't know, 17,000 or 17,000 attacks, was that exact same thing. It's like Metasploit just going all crazy on the entire IP address to the point- Yeah
Ashish Rajan: that everyone notices in the organization, something is not right here.
Johnny Hands: Yeah. I love the Metasploit reference. I, I think you almost forget about... that used to be a standalone application that you had to master, right?
Ashish Rajan: Yeah, yeah, yeah.
Johnny Hands: I mean, I used to do, uh, you know, organizational pen testing and, you know, do, like, web app crawling and those kind of things, and you had to get really good at knowing all your variables for Metasploit.
Johnny Hands: Same way with, like, I mean, it's as simple as it is in Nmap, right? Like- Yeah,
Ashish Rajan: yeah ...
Johnny Hands: in the- Very
Ashish Rajan: powerful tool ...
Johnny Hands: very, very powerful tool. In the old days, like, you... i'd spin up a box and let Nmap run. Yeah. But then, you know, like, all of the firewalls got really good. Yeah, yeah. And it's like all of a sudden it ran for 12 hours.
Johnny Hands: Uh, you spent- Found nothing, yeah. ... a lot of money, found nothing. Yeah. And it's like, turns out, you know, you're really noisy.
Ashish Rajan: Yeah.
Johnny Hands: And then you go, "Okay, cool. I gotta, fingerprint a little bit slower," and you gotta work through that. Well, you can do that same actions, and this is where that, um, you know, security researcher kind of mindset comes in.
Johnny Hands: Yeah. And the threat actors are [00:33:00] doing this as well, where they're like- Yeah ... "Okay instead of just getting in there and being really noisy- Yeah ... um, let me try to just allow these to do specific tasks." Mm-hmm. "And train them on the things you know." And it's an interesting one because there's a lot of conversation around the zero day, around AI stuff, but you know, you get into the conversation around what happens with end days, right?
Johnny Hands: Mm. I mean, like when they become end days. There's that level that you should talk about, how do you respond to those and what are your, what are your actions that you can take for the things that are known exploits now? 'Cause once they become a known exploit- It's about to get really noisy. Yeah.
Johnny Hands: You know, you're gonna start getting scanned from everybody just to see if you're a part of that, exploit
Ashish Rajan: or something. Yeah, and you, you'll get that email, $5,000 for... I'll te- I'll tell you the vulnerability- Yes ... if you give me, pay me $5,000, you know. Yeah, yeah. And I'm like, "Ugh." Yeah. I, I actually don't think, I don't know if they actually read, they even think in their mind that, "Hey, that's a logical thing for me to email."
Ashish Rajan: But although I joke about this, I think we are joking about this, that at least, I don't know if these are better than the Nigerian prince emails that I used to get- Yeah ... which I miss now fu-fu- funny enough. Yeah.
Johnny Hands: I, that was one of my [00:34:00] favorite uh, scams, honestly. Yeah, yeah, yeah. Yeah. I think I liked the...
Johnny Hands: This is probably a sidetrack. Mm-hmm. Um, but the reason I like the Nigerian scam is because people thought it, about it in a way that I looked at it from a, a, a business perspective. Yeah, yeah. And I thought it's actually pretty genius. Because what everyone did, uh, I'd do, I would do information awareness training with folks, and they'd be like, "Uh, who gets caught with those?"
Johnny Hands: Like, "You have to be, you know, not a very intelligent person or whatever." And I would, I would tell people, I'm like, "That's actually the point."
Ashish Rajan: Yep.
Johnny Hands: There's two or three people in an office somewhere firing these things out- Yeah ... you know, in the tunes of hundreds of thousands. They couldn't possibly handle the amount of volume if 100,000 people responded.
Johnny Hands: Yeah. So they're actually banking that you won't be gullible.
Ashish Rajan: That's right.
Johnny Hands: And they're looking for the five people that do respond so they can build an, a relationship. So from a business perspective, it's like, can I scale that? No. No. No. No. The game change for AI now is now they can actually scale it and manage those relationships.
Johnny Hands: So I'm actually surprised a little bit that we don't see more, uh, more [00:35:00] of a, a reoccurrence of similar type attacks.
Ashish Rajan: Yeah. Maybe now they are a lot more, uh, it's called spear phishing.
Johnny Hands: Yeah.
Ashish Rajan: It's a lot more research, and all that goes- Yeah ... into that as well. But I love what you said about, uh, the end days as well, 'cause bringing back to how should people respond, how should people prepare for it, especially, uh, going back to where we started the conversation with Mythos readiness as a way- Yeah
Ashish Rajan: What are you finding as the right way people should respond or even mitigate that as well? 'Cause it's hard to tell what a zero day would look like
Johnny Hands: Yeah. I'm gonna go kind of back to, like, some foundational principles. Mm-hmm. Right? I think about, like, even, you know, pre-Mythos, pre-AI when... I, I was, I was sharing with a friend of mine the other day, I was, there was I forget what the, uh, the the published vulner- Oh, it was, it was an Ivanti vulnerability. Oh,
Ashish Rajan: yeah,
Johnny Hands: yeah. Yeah, so we had, um, I, I had some Ivanti appliances. Ivanti had a rough year one time. Mm-hmm. It was just a rough year. And, um, man, the moment it got disclosed and someone had already built a working POC, and this is, pre-AI.
Ashish Rajan: Yeah.
Johnny Hands: I had my analyst like just turn on a filter log. [00:36:00] What... And I'll, I'll talk about the methodology. We basically, like, put up a, a virtual fence around it- Oh, yeah ... using... I was a customer. We used, uh, ZDI. They had a, a early disclosure on it. And, um, so we turned that on. But within minutes of the disclosure, we instantly started from China, India Pakistan.
Johnny Hands: Like, within minutes of the public disclosure, we were getting, Hammered ... you know, just hammered with it. Yeah. And so my point is, like, the moment it's known-
Ashish Rajan: Yeah ...
Johnny Hands: you need to understand what is the actions that you can take. And it looks different for everybody, and it looks different for each vulnerability.
Johnny Hands: And I think this is where you get into understanding your organizational structure. What's your de- defense in-depth strategy? What are the technical, uh, implications that you have in place? Like, what are the things I can do? Because it alway- it doesn't always look like a patch, and I think we think about it like a patch.
Johnny Hands: And I think security leaders are amazingly, uh, resourceful. Yeah. And we should look at it for all the things. Like, virtual patching is a great one, because the way I always, uh, pitch virtual patching is, and it may not look like an actual patch, it's just, you know, putting up some type of virtual [00:37:00] fence.
Johnny Hands: Mm-hmm. So that may be turning off a port. Yeah. That may be disabling a function in, the, the appliance that you might have needed, but you turn it off publicly and just maybe, uh, set up a port on the back end that you can do through a managed protocol or whatever. You know, that, those are all creative ways because as much as we'd love to do a patch, I remember not throwing shade on, uh, that one vendor, but, you couldn't even do the patch because there was a internal check that you're supposed to do, and that got compromised.
Johnny Hands: Oh. So, the internal check you would normally do to see were you compromised or were you impacted by that was also compromised. Mm. So that wasn't available.
Ashish Rajan: Yeah.
Johnny Hands: And there was a couple parameters in the, uh, admin console that was what was one of the main issues. So, you know, you get creative, you go in, you, you d- uh, change those parameters and, and shut that down.
Ashish Rajan: Yeah.
Johnny Hands: I lose some features for a period of time, but that's better than being owned.
Ashish Rajan: Yeah,
Johnny Hands: yeah, yeah. And I think that's, we have to think outside of the box. So, like, virtual fencing or segmentation, [00:38:00] patching looking at ways to control that. You wanna do that the moment that you're notified, um, because I guarantee you, if you have the appliance or you have the application or you have, you know- Name whatever the vendor it is.
Johnny Hands: The moment there's a POC that's, that's talked about especially in AI, they're automatically weaponizing that, and you have to be just as fast. And so I think the end day conversation is very similar now to the, uh, zero day, right? Yeah. And, and so you have to be ready to do maybe non-traditional things.
Johnny Hands: But it comes back to that, like understanding your risk exposure around it. And I think, um, if you're, two weeks behind even disclosure-
Ashish Rajan: Yeah ...
Johnny Hands: well, that's where you should invest, right?
Ashish Rajan: Yeah.
Johnny Hands: How can you get to understanding immediately that something's happening and taking action on it?
Ashish Rajan: Yeah. Wait, wait. And that's probably what's gonna be my next question as well. A lot of people are on the show floor at Black Hat trying to figure out what their AI security program uplift is gonna look like. If you are from an organization which has had, uh, [00:39:00] security programs existed across the categories, what's the right place to start?
Ashish Rajan: 'Cause do... It almost feels like there's just so much to kind of- Yeah ... feel really overwhelmed as- Yeah. A lot of buzzwords. Yeah, yeah. A lot of marketing. Everything's agentic as well.
Johnny Hands: Yeah. It's
Ashish Rajan: all- How do you... And of course, you've been a practitioner as well for a long time. How do you separate the noise from the signal for your organization?
Ashish Rajan: To apply that to a security program.
Johnny Hands: Yeah. Here's the way that I, And I, I talk to a lot of customers, from the CISO seat as well. Yeah. And my, my advice is pretty uniform. So I normally break things into really three key categories, and I think the first one is probably the most important, uh, but you mature through the other ones.
Johnny Hands: So, uh, the first one, and, and it sounds simple to say, but it's visibility, right? Mm-hmm. If you think about AI, the part-- the challenge with securing AI and there's kind of two ways to think about this. This is probably important as well. There's, when we say securing AI, there-- to me, that's securing the AI development stack, right?
Johnny Hands: Yeah. That technology stack of maybe I'm building agents. Mm-hmm. Maybe I have some infrastructure, some cloud [00:40:00] applications, those kind of things that, uh, you know securing it at runtime, making sure you have, you know, prompt injection and those kind of things, AI guards. That's very important and, um, that i- is now blending into the next one, which is how do I use AI to actually secure my environment?
Johnny Hands: Mm-hmm. Which are, you know, getting more closely aligned now because I think six months ago, uh, what I would consider immature around their AI adoption companies are now also wildly enabling agents and a lot of, lot of services, so they're kind of blended. But the first thing is you can't-- You know, it's, it's an age-old principle.
Johnny Hands: You can't secure what you, what you don't see.
Ashish Rajan: Yeah.
Johnny Hands: And there's-- You're not gonna buy a product that's going to solve that. Because if you think about your technology stack has, you know, it has perimeter, it has network, right? It has, you know, remote access capabilities. You have identity, you have endpoint.
Johnny Hands: You know, you have all of these layers, and you're going to get different visibility- Yeah ... across different capabilities. Some, you don't need to buy anything. You can just change the way you do logging. You can change the way your firewalls are, like there's some capabilities in there. But then sometimes you want to [00:41:00] have the second pillar, which is there's seeing it, and then there's, I always say, visibility, observability.
Johnny Hands: Yeah. And the, and a lot of people think it's the same thing, but I always say it like this: visibility lets me know that you're doing something.
Ashish Rajan: Yeah.
Johnny Hands: Observability lets me know what you're doing, right?
Ashish Rajan: Mm.
Johnny Hands: So from a shadow AI perspective, I'm, I need visibility to understand a shadow AI happening, right? So I want to know, like, what are my employ- I didn't give them Claude, as an example, as, as a smaller organization, but I know they're using it.
Ashish Rajan: Yeah.
Johnny Hands: Yeah. So that's one level. But observability says, okay, I didn't give them Claude, and I know they're using it, and I don't like what they're doing with it, right? Mm-hmm. Yeah. Maybe they're uploading our customer information. Maybe they're building personal projects at work, right? Yeah, yeah.
Johnny Hands: Whatever it is. And then you have actionability or that control plane. So these things to me, it's a maturing process. You need to get visibility first to make a decision. I was, I was actually talking to some of our internal, um, risk team, and they're saying like, "What's your-- How do you think through this risk process?"
Johnny Hands: And I said, "Well, there's a couple [00:42:00] ways. I want to know what is in my systems." Yeah. So that's the visibility piece. And then I have to make a decision-
Ashish Rajan: Yeah ...
Johnny Hands: right? As a, as a security leader. The, the blanket answer can't be block, because then I'm not a business enabler, I'm the department of no.
Ashish Rajan: Yeah.
Johnny Hands: And they're gonna go around me, and y- you're just gonna have more shadow AI.
Johnny Hands: Yeah. But if I gain visibility, and then I can get observability, I understand what they're doing and I, I may go like, "Look, the shadow AI is actually a SaaS tool I gave them that I didn't know that we enabled an AI component that I don't like."
Ashish Rajan: Yeah.
Johnny Hands: Right?
Ashish Rajan: Yeah.
Johnny Hands: That's different than malicious use. Yeah.
Johnny Hands: So you have to have that visibility, then you have to have observability so you understand what they're doing, and then you can make a decision, "Is this something I wanna block? Do I wanna reach out to that user and have them use a different tool?" Maybe they didn't even know that we were giving them a different application.
Johnny Hands: And that ultimately, if, if you combine all of those three together, now you can make a real, like, business risk decision, and that gives you your governance layer.
Johnny Hands: So it's that visibility. So when, when you go out on the floor, if you're looking at BlackHat and you're going, "Hey, what do I [00:43:00] need to buy to solve my problem?"
Johnny Hands: The reality is there's probably not a, a single vendor that's gonna give you one, uh, product. You know, when we look at, uh, Trend AI as an example, our approach to it is really through the lens of your visibility layers inside your systems. Yeah. It's that network layer at the perimeter it's at the network layer, it's at the endpoint, it's in the browser.
Johnny Hands: We look across that whole ecosystem and we, we're, um, getting ready to launch an agentic governance gateway as well. Yeah. Which is the next, really the maturing of those capabilities, that, you know, understand your SaaS services, understand, uh, you know, I always, I always tell people, like, uh, an agentic governance gateway should be like an MCP server on steroids.
Johnny Hands: Right? Yeah. With full governance. Yeah. And, um, because just as important as security is also, like, the FinOps conversation. Mm-hmm. Right? How m- you know, all of that structure. So if I can put a, a gateway in place, like an MCP proxy with tool invocation policies making sure that you have, you know, good intent with the tooling that you're using, making sure that you're not running prompt injections, or you don't have any, uh, malicious poisoning going on.
Johnny Hands: If I can [00:44:00] do all of that in a gateway- Yeah ... then now I can bring you through a really healthy filter. It's, uh, it's essentially a fireway-- a firewall for all of your AI usage. Mm. And, um, but all of these exist at multiple layers. Yeah, yeah. And I think that's the important thing, is look through the lens of visibility, mature into observability, and then grow into that control or that actionability perspective.
Ashish Rajan: Awesome. That's a great way to wrap up the episode as well. I'm doing this series, uh, that was all the technical questions. I've got this series going, which is You Laugh You Lose. Ooh. And I have my joke. Uh, uh, so the way that we're doing it is I say a joke, you have five seconds to react. Whoever laughs first loses, all right?
Ashish Rajan: But you can start with the first one, and I'll, I'll start with the first one and see if you, uh, if I get this one to ma- make you laugh. And I will, we'll go with yours after this. All right. All right. Are you a zero-day? Because I have no idea how to protect myself from you, but everyone s- says I should be terrified I can see you smiling.
Johnny Hands: It's really good. It's really good.
Ashish Rajan: All right. Okay, I'll, I'll [00:45:00] be honest.
Johnny Hands: All right. What do you call a turtle that browses the dark web?
Ashish Rajan: What do you call it? A tortois.
Ashish Rajan: That, that was good. I think, I, that... Okay, I can see why someone who's not technical, has not used Tor would not app- would not even get the concept. They're like, "What are you talking about? There's like, there's no Tor."
Johnny Hands: Yeah. Our marketing gal goes, "I don't know, I don't know that. Like a tortoise? That's normal."
Johnny Hands: Yeah. I said, "Like Tor, like the onion router?"
Ashish Rajan: All right. We, we may have to do another one. All right. Okay. All right, okay, I'll do another one. Knock. Who's there? Default credentials.
Johnny Hands: Default credentials who?
Ashish Rajan: You tell me, you never change them.
Johnny Hands: So true. So true. I
Ashish Rajan: was
Johnny Hands: like- You can't laugh at your own. I, I have a couple more I wanna give you.
Johnny Hands: All
Ashish Rajan: right, okay. Let's do, let's
Johnny Hands: do.
Ashish Rajan: Let's do that, yeah.
Johnny Hands: All right, I'll do these. You ready? Can I tell you a joke about UDP?
Ashish Rajan: Yeah.
Johnny Hands: Nah, you probably won't get it. All right.
Ashish Rajan: That was good as well. That was good.
Johnny Hands: You might... You came from this world. You might like this. Why do developers prefer dark mode?
Ashish Rajan: Why?
Johnny Hands: Because light attracts bugs.
Johnny Hands: And I [00:46:00] have one more.
Ashish Rajan: All right, okay.
Johnny Hands: In the spirit of Mythos. Are you ready? Yes. How long does it take Project Glasswing to fix a critical vulnerability?
Ashish Rajan: How long?
Johnny Hands: Zero days.
Ashish Rajan: Dude, that, that was a good, that was a good... But I, I can see why someone who is not deep in this field would absolutely go- Would not get it
Ashish Rajan: "What are you talking about?" Yeah. Like, how is that even funny? But, uh, dude, thank you so much for participating in this. Where can people learn more about what you guys are doing at Trend AI, and where can they connect with you as well too, uh, connect with you?
Johnny Hands: Yeah, so, uh, visit trendaisecurity.com for all things Trend AI- Yeah
Johnny Hands: which is great. Uh, we also have the AI Security Brief, which is our podcast, uh, focused on AI security like we talked about. Yeah. You can find that on all of your, uh, you know, major platforms, Apple, all the stuff here, everything your list- your listeners listen to here. Come over and, uh, grab a listen. And then I'm available on LinkedIn and would love to connect if anybody has any questions.
Ashish Rajan: I will put that in the show as well. But thank you so much for coming on the show.
Johnny Hands: Yeah, thank you for having me. It's a lot of fun.
Ashish Rajan: Yeah, thank you. Thanks everyone.
Johnny Hands: Yeah. [00:47:00]
Ashish Rajan: Thank you for listening or watching this episode of Cloud Security Podcast. This was brought to you by techriot.io. If you are enjoying episodes on cloud security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple, Spotify.
Ashish Rajan: In case you are interested in learning about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security. Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at Cloud Security Podcast.
Ashish Rajan: You can check that out on cloudsecuritynewsletter.com. I'll see you next episode.
Peace.

.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)
.png)


.png)


.png)



