产品72°

Kevin Mandia 创办 Armadin:用 AI 智能体主动攻击客户网络,已发现 90+ 零日漏洞

Kevin Mandia on finding 90+ security holes at Fortune 500 companies that nobody knew existed: "When...

精选理由

Mandiant 创始人复出做安全公司,让 AI 先于黑客攻击你的网络,今年已挖出 90 多个零日漏洞,这场对谈信息量很大。

Mandiant 创始人 Kevin Mandia 在 a16z 播客中介绍了新公司 Armadin:AI 智能体从外部以黑盒方式扫描网络,在罪犯之前找到可利用的零日漏洞。自 2026 年 1 月以来,Armadin 已在财富 500 强客户的生产环境中发现 90 多个零日漏洞,通常在 48 小时内通知 CISO。其模型由真实红队人员做后训练,能找到应用逻辑漏洞而非代码漏洞。Mandia 认为 AI 攻击像无人机蜂群,防御必须去除人工环节才能跟上速度。

图片来源 · a16z
原文 · a16z

Kevin Mandia on finding 90+ security holes at Fortune 500 companies that nobody knew existed: "When...

Kevin Mandia on finding 90+ security holes at Fortune 500 companies that nobody knew existed: "When you have an AI-based attack, it'll find logic flaws rather than code flaws in custom applications. It'll exhaust all routes all the time." "Armadin, since January of this year, we have found over 90 zero-days at customer sites, all in production." "We've post-trained all our models with real red teamers, real folks that actually can develop exploits." "When we're scanning networks, we don't have source code to review. We're not finding these zero-days with source code. We're not finding these zero-days because we can log into an app and now we have access, and we can get to other things. We are black box coming from the internet." "Over 90 zero-days in major software companies, and they're thankful. We're coming from the outside, and then we're calling a CISO, usually within 48 hours, 'Hey, we've got remote code execution in your DMZ.' And usually from there we're getting in, and they agree with us." "That's not a pen test. That is like a real adversary coming at you." @ArmadinSecurity @DavidGeorge83 Your browser does not support the video tag. 🔗 View on Twitter a16z @a16z . @ArmadinSecurity is a new company that uses AI agents to attack your network before criminals do, finding real exploitable zero-days and eventually patching them autonomously. Their agents map every service, route, and system from the outside, then re-attack whenever something changes. Since January that's uncovered 90+ zero-days at Fortune 500 companies. Kevin Mandia spent 30 years responding to some of the worst breaches in the world and built Mandiant, now a core part of Google Cloud's security arm. He had no plans to start another company until AI arrived and changed everything: in his words, "everything I did is dead." He joins a16z's David George to talk about why he came back and what Armadin is building. In this conversation, they cover what AI attacks look like today, why nation states hack like a sniper and AI hacks like a drone swarm, and why the only defense fast enough to keep up is one with no humans in the loop. 1:05 "Everything I did is dead" 3:10 AI on offense, AI on defense 4:20 What an AI attack looks like today 7:20 Sniper rounds vs drone swarms 10:25 Map everything, attack what changes 14:35 The problem with pen tests 16:40 90+ zero-days at Fortune 500s 18:35 A bad patch beats an intrusion 20:55 Why humans are too slow for the SOC 24:30 Why the next year in cyber won't be pretty 26:30 How Mythos changed the threat 28:15 Caging the attacker Armadin built 30:05 Open and closed models tied on offense 34:40 AI is finding zero-days on its own 35:45 Mandiant in 2004 vs Armadin in 2026 41:20 Why Armadin retrains sales every week YouTube: youtu.be/cJsHel27Z6M @ArmadinSecurity @DavidGeorge83 Your browser does not support the video tag. 🔗 View on Twitter 🔗 View Quoted Tweet 💬 0 🔄 0 ❤️ 1 👀 1513 ⚡