DEF CON 33 - Prompt  Scan  Exploit  AI’s Journey Through 0Days and 1000 Bugs  - D. Jurado & J. Nogue

DEF CON 33 - Prompt Scan Exploit AI’s Journey Through 0Days and 1000 Bugs - D. Jurado & J. Nogue

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 21:40

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

The video presents an autonomous pentest AI system with a coordinator managing vulnerability discovery and validators eliminating false positives [1:05-1:47].

Key Takeaways:
• The coordinator acts as a pentest manager, assigning tasks to agents and managing testing priorities [1:05-1:31]
• Validators serve as a "second pair of eyes" to remove false positives and prevent AI "cheating" [1:47-2:14]
• Human oversight is maintained only in reporting to comply with HackerOne policies [3:39-4:18]
• The system supports XSS, SQL injection, RCE, XXE, and exposed secrets with specific validators [6:15-7:49]
• "Alloy models" combine different AI models, with diverse combinations producing better results [13:40-14:31]

The system intentionally avoids post-exploitation to prevent unintended consequences [11:50-12:34].

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Okay guys, so um we are planning to uh publish the full uh talk in our social media today. We're not going to have enough time because um it prepared for 1 hour and we only have half an hour if it comes and fix that. So I don't know if you guys want to go to another talk or you want to like do some sort of uh question and answers is the only thing that we can offer you right now. Um and that's it. If you want to go to another talk, feel free. We are going to publish this all this talk um in a few days. So, and if anybody wants to do any question or whatever, we can do that. >> Yeah. So, uh yeah, >> sure. So basically um the structure like what we have built is like an autonomous pentest AI and mainly what you will have is one huge component that is a coordinator that um is taking care of y…