Kill Chains and Coffee

World’s Largest Controlled Hyperattack | Kill Chains and Coffee

Episode Summary

What’s worse: Getting an RCE dropped on you at 5 pm on a Friday or waking up on Monday with 12 RCEs sitting in your inbox? Find out what our experts think on this episode of “Kill Chains and Coffee.” Host Greg Heon sits down with Armadin Offensive Security Manager Christian Elston to cover two kill chains: Armadin’s first-ever AI Hyperattack and the world’s largest controlled AI Hyperattack. Key conversations include: The growing power behind AI agents attacking organizations from the outside in Why safety and control are so critical in the wake of the HuggingFace incident and similar attacks. In the first kill chain, Armadin engaged with a Fortune 600 company, launching 100 simultaneous attacks with thousands of agents—nearly 1 million autonomous actions. The agents discovered 12 endpoints vulnerable to unauthenticated Remote Code Execution (RCE) from the internet through Server-Side Request Forgery (SSRF). A combination of SRRF and a known CVE led to an overly permissive Kubernetes service. The agents ultimately escaped the Kubernetes pod and compromised the organization’s entire cloud infrastructure. The second kill chain was the world’s largest controlled cyberattack, conducted for an Armadin client with globally critical infrastructure. The attack targeted over 25,000 services and executed millions of autonomous actions. The resulting report generated over 200 findings with nearly 40 validated kill chains, including exposure to the company’s crown jewels. For security teams: This type of repeatable controlled assessment from Armadin gives you the tools and confidence to identify truly exploitable risk across your environment. Learn how at http://hyperattack.AI.

Episode Notes

What’s worse: Getting an RCE dropped on you at 5 pm on a Friday or waking up on Monday with 12 RCEs sitting in your inbox?

Find out what our experts think on this episode of “Kill Chains and Coffee.” Host Greg Heon sits down with Armadin Offensive Security Manager Christian Elston to cover two kill chains: Armadin’s first-ever AI Hyperattack and the world’s largest controlled AI Hyperattack.

Key conversations include:
The growing power behind AI agents attacking organizations from the outside in
Why safety and control are so critical in the wake of the HuggingFace incident and similar attacks.

In the first kill chain, Armadin engaged with a Fortune 600 company, launching 100 simultaneous attacks with thousands of agents—nearly 1 million autonomous actions.

The agents discovered 12 endpoints vulnerable to unauthenticated Remote Code Execution (RCE) from the internet through Server-Side Request Forgery (SSRF). A combination of SRRF and a known CVE led to an overly permissive Kubernetes service. The agents ultimately escaped the Kubernetes pod and compromised the organization’s entire cloud infrastructure.

The second kill chain was the world’s largest controlled cyberattack, conducted for an Armadin client with globally critical infrastructure. The attack targeted over 25,000 services and executed millions of autonomous actions. The resulting report generated over 200 findings with nearly 40 validated kill chains, including exposure to the company’s crown jewels.

For security teams: This type of repeatable controlled assessment from Armadin gives you the tools and confidence to identify truly exploitable risk across your environment.

Learn how at http://hyperattack.AI.

RESOURCES 
Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-4-worlds-largest-controlled-hyperattack 
Armadin Offensive Security Platform: https://armadin.com/platform 
Request a Demo: https://www.armadin.com/request-a-demo

CONNECT WITH ARMADIN 
Website: https://armadin.com 
LinkedIn: https://www.linkedin.com/company/armadin 
Twitter/X: https://x.com/armadinsecurity