Zero Time to Exploit, Defending Against AI-Driven Cyberattacks
The days of hackers slowly scanning networks and manually probing for weaknesses are officially over. Broadcasting live from RSAC, Techstrong Group’s Alan Shimel sits down with Fortinet’s Global Director of Threat Intelligence, Aamir Lakhani, to unpack the terrifying new reality of “zero time to exploit” attacks driven by adversarial AI. Lakhani breaks down the findings from Fortinet’s latest threat landscape report, explaining why you absolutely must fight fire with fire—leveraging defensive AI to secure your enterprise against tools like FraudGPT before the next breach makes headlines.
Transcript
Hey everyone, we're back here live at RSAC. We're at the Broadcast Alley on Moscone West. What a crazy day.
Keynotes and this and that, all around agentic AI it seems, every step of the way. But let me introduce you to my next guest. I hope I'm going to get his name right out here.
His name is Aamir Lakhani. Hey, very good. Very good at saying the name.
All right. Aamer is with Fortinet. He's going to tell us about it.
Actually, Aamer, you're the Global Director of Threat Intelligence and Adversarial AI Research at Fortinet, but that's not what you were born. Give us an idea how you got to this place. Man, that's a handful in the title itself.
Yes, it is. I've always been interested in how technology works, but how technology breaks, right? I don't want people dictating how I should use technology.
I want to use technology the best way it fits my life, and that's kind of what got me into cybersecurity, is how to break technology. And really, that's kind of what I do with my job. My job is to really look at how the bad guys are using technology.
What is their motivation? What gets them going, right? And I create machine learning models to protect against those attacks, especially baselining those attacks.
That's throwback right there, right? That's old school. So I've been in security almost 30 years.
Back in the day, they didn't have-- Well, A, we didn't call it cyber anyway, we called it infosec. B, we didn't have schools that taught cybersecurity or information security. Most of my friends got into security just like you.
They liked to break things to see if they could, and then build it back better, so it couldn't be broken- Exactly ... as easily anyway. And that was the original hackers.
That was the original infosec people, as we called. Hey, back in the day, I was on the BBS systems as well. I know.
Absolutely, right? We were all on BBS and using those things. There was no web, but it was fun times.
And that's why so many security people used to be into lock picking and that kind of stuff. Exactly. It was about the tinkering, the breaking, the putting it back better.
But in your role at Fortinet, you get to do some of that, but let's face it, this is a big company. So there's more structure around it now than when you were just hacking for fun. Absolutely.
We have a sandbox we have to kind of stay in- Yeah ... at least most of the time. But we do like to see how far we can extend that sandbox, because that's what the bad guys are doing as well.
Absolutely. They don't have rules. They make them as they go.
Exactly. So we want to see how far they push it, and how do we stay ahead of those rules. Excellent.
Let's dive in here. We got a few other things we wanted to talk about. How long have you had this role at Fortinet?
So I've had the role for about four years, but I've been at Fortinet for almost close to eight years. Really? Yeah.
Oh, good for you. I'm ashamed to tell you, I remember when Fortinet was founded, right? It was the Zeev brothers had sold NetScreen firewalls to Juniper, right?
And then they founded Fortinet shortly thereafter. That was the birth of it, and they kind of half invented the whole UTM category back then. But today's Fortinet, of course, is very different.
It is. But from the foundational, it was always about more than just protecting against packets, because that's what everyone did in the past, right? They had a packet filter, an access list.
Yep. And that worked, but until you understood what was the intent behind those packets, right? What was really the actions those packets were taking?
And I think that's where Fortinet made a name for themselves, and obviously that's extended well beyond just network security, right? With agentic AI, with cloud, with the OT space. I'm always reminded of a quote from Muhammad Ali.
I love boxing, right? And Muhammad Ali had a famous quote. " Yes.
It's all about having that visibility, and I think that's what Fortinet does, is it gives you that visibility. Excellent. All right.
I'm going to switch gears a little bit. You guys recently came out with a threat landscape report? Yes.
Tell us about it. Well, so we do this every year, is look at all our telemetry, look at all our data, look at our research, and we try and get a baseline on what's happening in cybersecurity. What are the trends telling us?
What are the bad guys doing? And what do organizations need to do to stay ahead of that? And so that's kind of where it starts off at.
Absolutely. So this is an annual report. And what's nice is this is your own data.
This is not, you hired some research company who maybe talked to people, maybe didn't, but submitted data. This is really real-world data that you've anonymized and able to pull in on. I always like to ask, what are the three key things in this report that you think people need to know about?
Yeah. So good question. And when you say it's our own data, I do want to point out that we're kind of lucky that we have a lot of network data, as well as endpoint data, as well as cloud data.
So we get a lot of different sources. And from all those sources, I think the things that we're seeing, of course, is what shouldn't be surprising to a lot of people, but maybe some of the details behind why they're happening may be surprising, is that attackers are getting smarter. They're using AI.
Yep. The time for exploitation is pretty much zero now. They're not waiting for vulnerabilities anymore.
One of the things that kind of surprised me is when I was looking at the data, I saw scanning went down, brute force attempts were going down. " I see a decrease in attacks, but exploitations went up, and it wasn't until I started thinking about it. It's like, well, attackers, they're just being much more efficient these days.
Yes, they are. Right? They don't need all the stuff they used to do even a year ago, now to be much more successful attacks and stay under the radar, be undetected.
Yeah. How much of that you think is AI? So there's a lot of it that's AI.
AI used to be helping attackers, basically get around- Better phishing ... exactly. But now it's totally different.
There's tools out there such as FraudGPT or WormGPT, which are basically the hackers' versions of ChatGPT. Right. And these tools will kind of craft an entire attack.
They'll scan an organization. They'll tell them, "Hey, these are the vulnerabilities they already have. These are the exploits that are already available, and this is how you target those exploits.
These are the people that you have to go after. And by the way, here's a phishing attack. Don't send them a phishing attack.
" And put it in there. It's a hard world, man. I want to stay on this report a second.
There's always something in the report that you're like, "You didn't see that coming. " Like maybe I thought it was there, but I didn't realize it was that widespread. What in this year's report kind of maybe surprised you?
Well, I think once you're working with it every day, there's things that are not really surprising, but things that always stand out. For example, hackers are not hacking you anymore. They're simply logging into your networks.
Yeah. Right? Just the amount of breaches that are occurring from stolen credentials, credential stuffing, combo lists, that's amazing.
And you'd think, as security people, we're kind of surprised by that because, of course, like every security person, we probably have a separate username and password and two-factor authentication everywhere. Yeah. Normal people don't have that back home.
Well, because they think it's a pain in the- Exactly ... it's cumbersome. Exactly.
Hopefully- That's a better word. Cumbersome. Yeah.
Hopefully, the solutions around, passwords are the weak link, and- They have been. But you know what? So let's get rid of passwords.
Let's get rid of passwords. I've been hearing that line for 15 years, and here we are. What's your password?
Okay? I don't know if we ever get rid of... It's like 100 years ago, I started a security company, and we did network access control, vulnerability management, intrusion prevention.
And back then, all the rage was, we're going to have a password list, an agent list, agent list vulnerability management, agent list NAC. Right? No agent, no...
And people were amazed. " "Well, we just put a little code on your computer, but it's not an agent. " Yeah, b******t.
It was an agent. Right? It was.
I don't care what you call it. It was an agent. It wasn't agentless.
I think it's the same thing. If you're substituting password for something else similar that's unique to you, other than maybe some biometrics, it's not passwordless. You're still using a password.
It's just a different form of a password. Right. And so I see a lot of, over the years, I've seen a lot of companies say, "We're going to get rid of your passwords.
We've got pass keys. We've got two-factor authentication. " But I think you're bringing up a very interesting point, that something that we're starting to see is, when you get to the heart of this problem, it's about managing identities.
Yes, it is. And identities are not people identities. There's machine identities.
Machine identities. Agentic AI agents. Those are all identities now, and you need to manage- It's going to blow it up.
We're not ready to scale that We're not, and people have kind of, IAM, Identity and Access Management, it's never been a sexy solution, right? People have always gravitated towards something else, but it's going to be like we have to go back to these foundations. It's the heart of it.
Yeah. Exactly. Not only is it the heart of this whole agentic problem, it really, at the end of the day, is the closest thing we have to cloud security, right?
I grew up, I came up in the moat-and-castle era, right? We had the big firewall, UTM, and big boxes at the perimeter. There's no more perimeter.
Like fortifying your networks? Like fortifying networks? I'm telling you, I remember when it was launched.
But really, in today's world, IAM, Identity and Access Control, IAC, is where the action is, right? Look, in the last month, we've seen AppSec get spun on its head with all of this new AI-based scanning. I don't know if it's ever going to be the same.
I think AppSec is fundamentally changed from finding bugs to fixing bugs. Attackers are not doing that. So they used to.
You know what happened is, a vulnerability came out, attackers used to scan the internet. And- They're not doing that anymore ... every security guy you ever talk to, they always said the best thing you could ever do for security was patch.
Right. Anyone that ever said that never had to patch systems on a large scale, right? But today, attackers don't care.
They're continuously scanning. They're indexing targets as soon as a vulnerability is released, and now they're using AI to write those exploits. And so it's zero time to exploit.
AI is scanning it. Yeah. They're using AI to scan it at a speed- Yeah ...
and depth. You've read the same stories I have, right? Finding 600 vulnerabilities in a day in open source, 120 something in Firefox alone.
What we did yesterday, what we did last year, isn't going to scale under the weight of this kind of- You can't keep up with the volume and the velocity of attacks anymore. You got to use AI. Yeah.
It's the only way you're going to be able to keep up with it. If you're going to be attacked at machine speeds, you have to defend against machine speeds. Yeah, at machine speeds.
And I know that kind of sounds like a marketing line, but it's so true, because there's no way to do it without AI. No, it's logic, right? Hey, let's pivot a little bit.
Let's talk about RSA. What's Fortinet's story at RSA this year? Well, Fortinet's story, this year we're looking at our agentic AI solutions, our FortiSASE solutions, our FortiAI SOC.
So we have a lot of different things. So if you're at RSA, come by the Fortinet booth. We have a lot of demos.
But what I think what we're really trying to show you is, now we have the tools to combat the speed of attacks. It's like the first time in my career, well, at least in a very long time, that I actually feel like there's more hope than we've ever had before, because it's always like a cat and mouse game or- Yeah ... we're behind the curve.
But AI is kind of changing a little bit of that. At least right now it is. I don't know how long this window is going to be, but because of the investment AI takes right now, the good guys have a little bit of an advantage that the bad guys don't, and that we can maybe utilize.
But of course, we know that's going to change, right? Yeah. So we might as well try and get ahead.
I think, like they say in football, right? On any given Sunday. Yes.
On any given Sunday. Great movie, by the way. Yes, it was.
But on any given Sunday. " And I got very honest. " I said, "Look, you do the best you can.
You start with a zero trust posture. You isolate it, you limit it. But at the end of the day, we're in uncharted waters here.
" You have to have zero trust for your agents, and you also have to look at how you're using LLMs and AI in your own environment as well, because there's a lot of attacks that I think we talk about, but unless people start seeing them or experiencing them, they don't really understand- No ... what does data poisoning really do long term, right? What does model theft really mean to an organization?
Um, whether it's your- Look, we're going to find this. So here's the thing. Over the next six months to two years, we're going to find all of these things out in spades.
Because we're going to learn it the hard way, because that's the only way we've ever learned it, unfortunately. People like you, we know it's coming. But you're not going to convince mainstream USA to do what we need to do until, unfortunately, we hear some bad stories.
Yeah. The thing is some of the tools for mitigating those risks are right here. They're here.
We're demoing them at the Fortinet booth right now. I learned this lesson in security. You know what?
About 30 years ago, I started a company in security, and I realized how hard it was to sell security. " We'd wind up in jail, of course- ... but they'd buy our stuff.
And nothing's changed. It seems to get religion about security, you got to suffer some sort of calamity or some sort of incident. And then all of a sudden, they're looking for God, right?
They're an easy sell. I'm afraid it's the same thing here. Yeah.
I hope we can start changing the hearts and minds. People get smarter. Yeah.
" A programmer. And she's like, "Well, you're Indian, you're Pakistani, so you're either a programmer or a doctor," so something like that. Right.
That's how that goes. Yeah. There's no other choice.
It was lawyers or, yeah. Exactly. For us.
Or lawyers. Yeah. " Like, "I understand"- Yes.
And when mainstream- "... " Yep. We'll see.
We could hope. Yes. We could hope.
Hey, man. Hey, if my mom's discovering it, I think there's a hope. You know what?
My wife's family still doesn't understand what I do for a living, but it's okay. Anyway, best of luck to you- Thank you ... and the guys at Forti, and folks at Forti.
We're going to take a break. We're here live at RSAC on Broadcast Alley. We'll be back.
Okay. Thank you.