CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted
Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
Posts
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
I have to take care of a family member. Headed out to help her for I don’t know how long but hope to be working on AI again soon. Trying to enjoy the scenery along the way waiting for her to get back home.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
I noticed the person who suggested I was drinking when I posted these trying to figure out what was wrong with Opus 4.6 has deleted his comment. 😁 Some of us have spidey sense from doing this way too long. I provided a bunch of feedback to Anthropic on X as well. When you know you know. Glad they fixed it.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
RE: @teriradichel@infosec.exchange
You can architect a solution that uses AI without giving it all your credentials. Here’s how.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
Reducing Token Burn Rate With A Well-Designed Architecture
Trying to put out the AI token fire - or at least manage it as a controlled burn by using deterministic scripts for gathering inputs and directing agents
https://teriradichel.substack.com/p/reducing-token-burn-rate-with-a-well
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
How I Use AI for Penetration Testing. Presentation at the AWS Security Community Day at the Computer History Museum on YouTube
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
Claude pricing changing to pay per token. This makes sense as long as value per token remains consistent. This will make it difficult to compare to prior performance and I wonder how users can transparently measure the usage.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
AWS needs to extend CloudWatch with tools that make it a real SIEM. Don’t overlay it with complexities it doesn’t need. Just extend it.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
This post is not about Mythos capabilities because I can’t know until I try it. Opus 4.6 was great until it changed and I presume Mythos is better.
This post is more about the economics of AI models and the risks we face trying to rely on them as business owners.
How do you know if and when the model has changed in some way as you are using it? How do you measure value per token? What if value per token changes?
Using AI has been amazing but there are some serious questions to consider beyond model capabilities when it comes to business and cybersecurity risk with any AI model. I haven’t heard anyone else asking these questions - or answering them.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
I am looking at messages in Google Developer tools and it is saying cdn.tailwindcss.com should not be used in production so if you are….
https://tailwindcss.com/docs/insrallation
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
I’ve added links to my presentation on how I use AI 🤖 for pentesting 😈 in this post. Most of the slides have a related blog post and I’ll probably write more about all these topics as I research this further. The PDF has links to related posts.
https://teriradichel.substack.com/p/how-i-use-ai-for-penetration-testing
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
Awesome video on S3 files
https://youtu.be/zb8TdNJhZCk
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖
Pentesting is not a scanner or a fuzzer - whether SAST, DAST, AI, deterministic or non-deterministic. Pentesting is a human * using those tools * to see if they can find a security problem that your teams and tools may have missed.
🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
RE: @teriradichel@infosec.exchange
I read all the Mythos hype right before I submitted my talk for today at the Computer History Museum. Did I need to change my slides? Nope.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
Wonder if this has anything to do with performance degradation of anthropic models. But are you now paying more for same effort you were getting previously if you change this?
• Default Shift: In March 2026, users on Reddit and developer forums reported that the default was quietly shifted from high to medium for many subscribers, which explains the sudden change in performance.
Need to check this out later. Flying out to speak at AWS Community Day in Mountain View.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
I was just listening to an interview on the radio with a person who worked at a hospital.
1. Your cyber insurance makes you a target. They know how much you can pay.
2. Don’t use your backups until you have eliminated the attacker or they will encrypt your backups too.
3. Pull the plug until you figure that out and cut them off (except critical patient machines). The hospital in story I was listening to had people running across the hospital when faxes were overused and started smoking.
4. They got in because the hospital was running out of date software and one person clicked a link about a bonus. (And apparently no network segregation?)
Hospital was down and patients needing cancer treatment had to drive over a mountain to nearest hospital so oncology was first restored.
Was part of a wave of attacks on rural hospitals during Covid.
I believe the ransomware was Medusa but I thought they said was attributed to Russia. Attribution is difficult. You might not really be sure, especially with AI.
https://thehackernews.com/2026/04/china-linked-storm-1175-exploits-zero.html
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
Iran has rapidly developed advanced cyber capabilities, evolving from information gathering to conducting destructive, state-linked attacks against critical infrastructure in the U.S., Israel, and the Gulf states.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
How I Use AI for Penetration Testing
Speaking at the Computer History Museum in Mountain View, CA April 10, 2026
https://teriradichel.substack.com/p/how-i-use-ai-for-penetration-testing
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
Latest scam. Interesting that when I used Apple cleanup to remove the ticket number it didn’t remove it but instead characters from another Arabic looking language showed up instead. This came as an attachment. Took screenshot. I did the cleanup like 5 times and then chars gone.
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
Note:
As part of the analyzed intrusions, public-facing applications and valid accounts were abused for initial access. The state-sponsored hackers targeted Ivanti, Cisco, Fortinet, VMware, and Palo Alto Networks appliances, as well as Apache Struts and other web-facing platforms.
- Are these 100% American products? Buying American doesn’t mean we are safe.
- The tactics used here show exactly how stealthy malware can be. A shell triggered by a particular byte sequence? Something that puts its payload in the 26th byte? Kernel layer BPF? Container components. Traffic that blends in.
- How would you spot this? If you want to learn cybersecurity that’s the kind of thing you need to understand. Even if you know cybersecurity it is not easy!
https://www.securityweek.com/chinese-hackers-caught-deep-within-telecom-backbone-infrastructure/
CEO, 2nd Sight Lab. AI Assisted Pentesting, Security Research. GSE 240. GSE . AWS Security Hero . Author on Amazon. Burp Champion. Former: SANS Instructor, IANS Research
If you are distressed because AI is causing outages at AWS well… don’t jump to conclusions like everyone did with the whole slew of S3 bucket debacles.
Yes there will be problems as people learn how to use this new technology properly. But frame the problems correctly.
The problem is not with AI the problem is what safeguards exist to contain what it does and make sure the code is correct.
People thinking AI is going to completely replace developers is wrong. People thinking AI is not useful for software development due to these issues are also wrong.
I’ve written before about problems I’ve had with managers handing complex tasks to less experienced engineers and accepting their code because they didn’t understand the implications. AI is the new junior software engineer.
Now AWS is having senior engineers review code. That human in the loop will help the juniors improve and AI will certainly improve as well.
We are going through a phase like the early days of cloud right now where almost every security person I knew said it was impossible to secure things in the cloud - but I could see they were just doing it wrong and only seeing all the upside or all the downside and not thinking about the proper implementation, security controls, and roll out - or possibilities.
I wrote papers about packet capture and automated incident response in the cloud when no one else was doing it and spoke about it at SANS conferences.
Here we go again….
I’m writing about how I’m using AI and going to speak about it on April 10th in Mountain View at AWS security community day. 🤖☁️🔒
Join me.