{"id":432,"date":"2026-08-11T03:46:20","date_gmt":"2026-08-11T03:46:20","guid":{"rendered":"https:\/\/43.156.46.27\/?p=432"},"modified":"2026-08-11T03:46:20","modified_gmt":"2026-08-11T03:46:20","slug":"from-prompt-tricks-to-autonomous-hackers","status":"publish","type":"post","link":"https:\/\/haco.zone\/?p=432","title":{"rendered":"From Prompt Tricks to Autonomous Hackers"},"content":{"rendered":"\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Black Hat Asia 2026 | Keynote: From Prompt Tricks to Autonomous Hackers\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/5IrJf2qGZcM?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Ari Herbet-Voss (Founder &amp; CEO, RunSybil \/ Former OpenAI Researcher)<\/strong>&nbsp;delivers a deep dive into the realities of AI in offensive security, separating media hype from technical reality.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. How LLMs Actually Work<\/strong><br>Herbet-Voss clarifies that Large Language Models (LLMs) are not &#8220;reasoning engines.&#8221; They are essentially highly advanced &#8220;next-token predictors&#8221; (similar to a smartphone keyboard&#8217;s autocomplete) that use &#8220;few-shot learning&#8221; to mimic human reasoning based on patterns in their training data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. The Scaling Hypothesis<\/strong><br>AI capabilities are governed by the scaling hypothesis:&nbsp;<em>More Data + More Compute + More Parameters = Better Performance<\/em>. Recently, AI models have shown &#8220;supralinear&#8221; (exponential) growth in reasoning capabilities. A model that is twice as large, trained on twice the data, can be four times as capable as its predecessor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. What is Getting Better with AI Scaling?<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Speed:<\/strong>\u00a0The time it takes to go from discovering a vulnerability to creating an exploit has dropped drastically\u2014from an average of 5 months to just 10 hours.<\/li>\n\n\n\n<li><strong>Autonomy:<\/strong>\u00a0Newer models require much less human &#8220;scaffolding&#8221; (guidance) to find vulnerabilities.<\/li>\n\n\n\n<li><strong>Volume:<\/strong>\u00a0AI can find a massive volume of &#8220;shallow&#8221; bugs incredibly quickly.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. What is NOT Getting Better?<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Complex Bugs:<\/strong>\u00a0The &#8220;capability floor&#8221; is not rising as fast as the ceiling. AI still heavily struggles to find deep, complex vulnerabilities that require holding state, temporal analysis, or concurrency (timing issues).<\/li>\n\n\n\n<li><strong>Exploit Reliability:<\/strong>\u00a0AI will generate thousands of potential vulnerabilities, but human experts are still required to filter, validate, and write the actual reliable exploits for them.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5. Implications for Security Teams<\/strong><br>Herbet-Voss warns of the &#8220;million monkeys with typewriters&#8221; scenario. Because attackers only need an AI to get lucky&nbsp;<em>once<\/em>&nbsp;to breach a system, the sheer volume of AI-generated attacks puts defenders at a severe disadvantage. To survive, organizations must aggressively adopt AI to automate the patching of basic, shallow bugs so human defenders can focus on complex, state-level vulnerabilities.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ari Herbet-Voss (Founder &amp; CEO, RunSybil \/ Former OpenAI Researcher)&nbsp;delivers [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[35,5],"class_list":["post-432","post","type-post","status-publish","format-standard","hentry","category-black-hat","tag-llm","tag-security"],"_links":{"self":[{"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts\/432","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=432"}],"version-history":[{"count":1,"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts\/432\/revisions"}],"predecessor-version":[{"id":433,"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts\/432\/revisions\/433"}],"wp:attachment":[{"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=432"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=432"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=432"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}