From Read Access to Admin with just an AI Agent
What if someone got full admin access to your company's platform, including your CRM, your payments app, and your private messages, and the only tool they used was an AI chatbot? Can AI models really find zero-days on their own, or is that just the headline? And if AI can do the attacker's job, who's actually holding the scissors? In this solo episode, Ron Eddings shares his own methodology for offensive assessments with AI. He talks about the models he trusts, the tools he uses to get agents working together, and a real assessment where his agents turned SQL read access into admin control and unlocked the API keys stored inside. Ron also calls out what's hype and what's real with today's models, and why the agent still needs a skilled person behind it. For defenders, Ron covers what attackers go after once they're in, and why the fundamentals like asset inventory are still where every strong security program starts. He closes with the bigger picture: anyone, good or bad, now has powerful intelligence on hand, and it's on all of us to look out for each other. Impactful Moments 00:00 - Introduction 02:25 - Can AI Really Find Zero-Days Alone? 04:20 - The Real Danger Is Human Intent 05:00 - Why Grok 4.6 Tops Ron's List 07:55 - Ron's Three-Model Assessment Workflow 09:50 - Maestro, Interceptor, and Agent Ensembles 11:20 - Privilege Escalation and Persistence With LLMs 12:50 - Why AI Hacking Feels Like Cheating 14:20 - Ron Called Automated Security in 2015 16:05 - The Lazy Way to Hack 17:55 - From SQL Read Access to Admin 21:05 - What Attackers Want After Getting In 23:40 - Asset Inventory Is Security Flossing 27:05 - Why AI Is Like Scissors 29:05 - Waymos, Robotaxis, and Physical AI Risk Links Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/