Every conference has an AI talk. This is not that talk.
Instead of speculating about a future where AI goes rogue, Sprocket Security's Topher Lyons shows what attackers are already doing with LLMs today. Presented at Black Hat 2026, this session breaks down the offensive AI workflows that are lowering the bar and raising the speed of real attacks.
Topher walks through how adversaries turn a company name into a full target profile in under 20 minutes, run that same recon against 50 organizations at once, write context-aware phishing that references your real tech stack and org chart, and rewrite payloads fast enough to slip past signature-based detection. He closes with a defensive framework built for how attackers actually operate, with specific actions for security teams, the SOC, and leadership.
The takeaway is simple: attackers have access to the same models you do. The only question is whether your security program is moving as fast as they are.
What you'll learn
Why the economics of an attack have changed, even though the fundamentals haven't
How automated OSINT pipelines compress hours of recon into minutes, at scale
What makes LLM-generated phishing slip past content-based filters, and what actually catches it
How the window between CVE disclosure and working exploit keeps shrinking
A three-part defensive framework for security, SOC, and leadership you can apply today
Watch the full recording above. View the slides: https://assets.sprocketsecurity.com/oh-great-another-ai-talk.pdf