Follow the White Rabbit - IT Security Podcast - English Edition
Follow the White Rabbit - IT Security Podcast - English Edition

#10: 90 Minutes. One Laptop. Working Malware. AI Just Changed the Rules.

02 July 2026 23:45 Link11

Listen to episode

About this episode

A security analyst experimented with a public AI, meticulously crafting malware capable of evading detection. This wasn't done by a nation state or a criminal gang; it was Northwave, a Dutch cybersecurity firm. Their CTO, Christiaan Ottow, a former ethical hacker, oversaw the experiment. In this episode of Follow the White Rabbit, Kofi Osae-Attah talks with Christiaan about the experiment's findings and his belief that we've reached a critical point he and his team predicted in September.

Christiaan isn't an alarmist. He was skeptical of LLM hype, but the data changed his mind. His incident response team investigated a breach where they gained rare access to the attacker's staging server and found files documenting the AI's reasoning, plans, and execution steps. The attack used zero-day vulnerabilities, pivoted between cloud environments, and went undetected despite the victim having EDR and next-generation firewalls. The attacker didn't need hacking skills; they just needed to find a way around the AI's guardrails. This is the new baseline. The barrier to entry has collapsed, and attribution is becoming impossible as every threat actor uses the same models.

The implications for defenders are stark, but Christiaan's advice is practical. Agentic AI isn't a competitive advantage; it's a baseline requirement. However, speed without structure is dangerous. Automated response needs a fine-grained authority matrix, prompt injection risks need to be engineered around, and most security teams are missing a complete, accurate inventory of their assets and identities. The organizations waiting for proof that this shift is real are about to get it. In the worst possible way.

Takeaways:

  1. The inflection point has arrived. Christiaan's team predicted it would arrive in April 2026. It arrived on schedule: Anthropic's Mythos, GPT 5.5, and the first fully AI-driven attack investigated by their incident response team all occurred in the same month.
  2. AI attackers operate like an entire team. A human hacker has one area of expertise. An AI agent has them all simultaneously: software vulnerabilities, cloud misconfigurations, Windows environments, and identity exploitation. Attribution is becoming nearly impossible.
  3. Your defensive AI is also an attack surface. Prompt injection into agentic SOC systems poses a real threat. Treat your AI agent as you would software or a human employee: isolate it technically, provide guardrails, and explicitly train it on what it is allowed to do.
  4. Asset and identity inventory is now a top-tier security priority. Knowing what systems you have, what software they run, which API keys exist, and what permissions they carry used to be basic hygiene. Under AI-speed attacks, it's critical infrastructure for incident response.
  5. The question isn't whether AI changes the threat landscape. It already has. Run this thought experiment: What if the volume of attacks triples? What if the time between discovering a vulnerability and its exploitation is reduced to zero? If you can't answer these questions, you should.

Subscribe to Follow the White Rabbit

If this episode made the threat feel more concrete than it did an hour ago, then we've done our job. Subscribe on your preferred platform, leave a review, and share this episode with every CISO, SOC lead, and security engineer in your network. The gap between now and then is smaller than most defenders realize.

Links:

  • Christiaan Ottow, CTO, Northwave Cyber Security on Linkedin
  • Kofi Osae-Attah Jr. | LinkedIn
  • How AI-Driven Cyberattacks Are Changing the Threat Landscape in 2026
  • "The Day-Zero Normal" Rob Fuller · Chief Information Security Officer
  • Anthropic: Project Glasswing & Mythos Preview
  • MITRE ATT&CK: Agentic AI Threat Modeling
  • Recommended book: The Art of Intrusion – Kevin Mitnick

Want to find AI jobs?

Join thousands of AI professionals finding their next opportunity

We respect your inbox. Unsubscribe at any time.

© 2026 Follow the White Rabbit - IT Security Podcast - English Edition. All rights reserved.

Common Questions

Frequently asked questions

Quick answers about how DevFound's AI matching, resumes, and referrals work.

DevFound's AI Copilot ingests your profile, goals, and live job data to deliver curated matches in seconds. Every match includes a resume variant, suggested referrals, and interview prep so you can act immediately. The more feedback you provide, the sharper the Copilot becomes.

AI-led job searches shrink the hours spent sifting through boards and formatting resumes. DevFound pairs automation with your personal outreach, so you reserve energy for interviews and negotiation. Traditional networking still matters, but AI gives you a lift before you even send a message.

Modern AI roles expect comfort with production-grade code, data fluency, and practical ML tooling. The strongest candidates pair deep technical chops with storytelling—translating model impact to product, GTM, and exec partners. Continuous learning keeps you ahead as stacks evolve.

DevFound rewards active seekers. Keep your profile fresh, respond to match quality prompts, and enable alerts so you never miss a role. The AI prioritizes companies and teams that align with your feedback, accelerating both introductions and interview invites.

High-density tech hubs continue to host the deepest AI talent pools, yet distributed teams are catching up fast. Use DevFound filters to hone in on onsite, hybrid, or fully remote roles and watch openings expand across time zones.

DevFound aggregates thousands of remote AI openings and flags the nuances—core hours, async culture, and visa needs—up front. The Copilot also recommends how to position your distributed work experience so hiring managers know you can thrive on a remote team.