mnemonic security podcast

Pentesting anno 2026

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 32:47

Pentesting anno 2026

Erica Burgess, an experienced penetration tester and security consultant, joins us for this episode of the mnemonic security podcast to deliver a state of the union on penetration testing in 2026. Drawing on her Black Hat Europe AI Security Summit keynote, “Never Break the Chain: Attack Chaining for 0-Days,” Erica breaks down how seemingly low-severity or “informational” findings can be chained together into full system compromises.  

 

Erica details her practical approach to using customized AI agents for subtasking, from validating dynamic scanner results to finding obscure commands that bypass blacklists. Tasks that once required three days of manual research can now be completed in minutes, dramatically increasing the volume and sophistication of findings during time-constrained engagements.

 

They also explore the broader implications of AI-assisted hacking: the risk of new blind spots when everyone leans on similar models, and the uncomfortable questions this raises about creativity, labor, and the future of junior talent in cybersecurity. Erica emphasizes the importance of maintaining human intuition and critical thinking, warning that over-reliance on AI can literally reduce brain activity, while acknowledging that pen testers who don't adapt to these tools risk being left behind.

Send us Fan Mail

Speaker

From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.

Robby Peralta

Creativity is finding non-obvious paths when the obvious ones are blocked. And hacking is exactly that. I've never been the person on stage dropping the exploit. And I've watched the room when it happens. Eyes light up, everyone smiles. Not because of the bug, but because of the thinking behind it. It's a beautiful moment to be a part of. And these days, that thinking is being reshaped. With the tools now available to pen testers and red teamers, what used to demand patience can now be orchestrated. What once demanded deep expertise across software development, application logic, infrastructure, human behavior can now be done by someone who knows how to ask the right questions of a machine. We've all seen the marketing, AI to complement humans and not replace them. Unleash our creativity. Well, today's guest has cracked that code. Erica Burgess, welcome to the podcast.

Erica Burgess

Thank you for having me.

Robby Peralta

You held a fantastic presentation at Black Cat Europe here about a month ago. It was a keynote of their AI summit, if I remember correctly. It was called Never Break the Chain, Attack Chaining for Zero Days.

Erica Burgess

Yeah.

Robby Peralta

Why don't you give us a high-level uh intro to what that was about?

Erica Burgess

Yeah. So the theme of the talk was, you know, how do you take some low-level severities and chain them together to get really scary ones? Because often what I see when I submit a pen test report to a client is, oh, those are lows, we don't have to fix those, or that's informational, what's the big deal? So the idea of the talk was, you know, hey, did you know that cross-site scripting combined with the right command injection can actually give you full root control over the server, you know, and without social engineering, without any kind of interaction with a human. And so a lot of my attack chains are strictly technical and they don't rely on someone being in the right place in the right time or the wrong place at the wrong time, depending on who you ask. And so the idea was basically what does that look like in 2026? So a lot of these attack chains and CVEs I was creating were manually discovered. But in this new AI world without contributing too much to the hype, I looked for very practical ways to sort of subtask different parts of exploit development out, just because a lot of the time you're just trying to do something in a strange way that wasn't expected. You know, you find the command that isn't on that uh blacklist, right, to be able to get that SQL injection. So only some SQL commands are allowed. So you ask the AI to essentially look through the manual for you and find those obscure commands. And so that was a theme of the talk as well, is sort of that tedium that used to take me three days to research this stuff and come up with a custom payload that isn't in SQL map yet. I can now do in 10 seconds, maybe less, and have multiple options for working with the application and testing. And that really depends on the temperature of the AI. So I have to give a huge caveat that a lot of these models are so derivative that you're not going to get that out-of-the-box thinking out of the box. So you have to kind of play with the model and find the right one and sort of talk to it right and really help define what you would have been doing with trial and error. So that's kind of the talk in a nutshell. And it's a little uh boogeyman, it's a little bit scary, like, okay, these low-level things matter, but it's a I think it's been a good wake-up call for a lot of people. So I'm glad I could do it.

Robby Peralta

A lot to unpack there. Very interesting. Let me just start out with something very basic, like attack chaining. That was a thing before LLMs, correct? Yes. How has that changed or how has that sort of evolved since LLMs came entered the stage?

Erica Burgess

Oh, it's it's been really fascinating to watch it evolve, actually. So, not myself, but another security researcher has been using uh basically LLMs to look at open source code and sort of follow code through. So a lot of pen testers don't necessarily start coding. Reverse engineers do, and and some of the forensics level folks really need that coding background. But sometimes network pen testers or even AppSec folks, they can kind of get along with just scripting without understanding software engineering, so like bigger architectures and more complex code. But with LLFMs, I mean, because it can understand language so well, it understands programming very well. So it's kind of given them the skill bump. And in addition to that, uh it's helped them find things in open source code, for example. So many pen tests are black box or opaque box, I should say, where you aren't privy to the all code of the app, but you are always privy to open source code that the app uses. And so if they're able to look through this code using an LLM on a very short billable time frame, you know, like a 40-hour pen test or something like that, I mean, you really capitalize. Um, you're able to find some stuff that may be new to the world and maybe able to release it as a CVE just because they can comb through. And even better is combining traditional AI uh dynamic scanners, which don't necessarily brute force, but they're certainly not as strategic as GPT because they don't have that context. So they're they're trying things that have it's kind of been trained on might work, but the GPT can look at context and kind of see like, okay, well, this shouldn't be in this person's shopping cart. You know, she uh moved it over, which is a true story. I I did that for a bug bounty. And so being able to understand how you're able to do these things and should you be able to or not, that should is very subjective. And because the AI can handle subjectivity and context very well, it can look at this stuff and say, oh yeah, that's that's an eye door, that's you know, an indirect object reference. They shouldn't be allowed to look at that or supposed to look at this one without a lot of manual looking. So yeah, that's a long answer, but it's very cool watching people figure out, like, you know, oh, this is a false positive from a dynamic scanner. Can I have it rework the payload in order to A, figure out that it's a false positive, but B, make one that is a true positive, uh just based on what information you you give it. So it's it's insane watching this field change.

Robby Peralta

Pen testing has changed so much. Like, how long has this been like a thing? Like, how long have you been thinking in this way? And the appointment, I mean, back in the day of 40 hour pen test, that's yeah, you weren't gonna get that much out of it just because people you don't have human time. But if if I just understood you correctly, that 40 hours maybe the first when you're starting to sit down, the LLM sort of understands what's going on in the application already more than you'll ever or would have ever been able to do, I guess.

Erica Burgess

Yeah, it's a big change. And I won't sort of law this or make this into sort of like an AI commercial because there are some huge blind spots, right? So yes, it's changed, but we still need that what's called beginner's mind, if you're familiar with that. It's like a like a Zen concept of, you know, that person who doesn't know anything about the field is gonna try things they don't know are impossible or that they don't know might be impossible, right? So they're gonna keep their mind much more open than an LLM that has like a few different pathways and a few different knowns that it's trying to get that right answer, that nice predictable, you know, cliches kind of well-researched answer because it can look on the internet, right? So there's a little bit of a caveat there. But yeah, this as far as how long I've been thinking this way, uh, 2022 really, really blew my mind was um somewhere between GPT 3.5 and GPT-4, I was able to make a zero day that I'd never published before. In fact, I was in the process of making the full proof of concept code for it, the actual exploit code. And uh having the AI finish that for me, because the first half took weeks, right? Being able to finish it in one prompt was just unreal because even though the AI will make code in a very counterintuitive and very non-human way, that most developers will look at it and go, oh, my eyes are bleeding. Like, why is it all one line? Why is it like like packed in such a strange way? Those uh widget chains is what I was making, it's called a widget chain, uh, happened to do exactly what I needed to get remote code control over a server. And so that represented days of research to me in just a few seconds, which is unbelievable. So I'd say since 2022, I've seen like the amount of findings I can get increase dramatically. Because if you think about that, something that used to take three days is now taking an hour to test fully if you do after the AI does things and make sure everything looks right. I mean, yeah, that's it's it's pretty outstanding. And so again, I'm trying not to be too hypey, but it is a very useful tech. Yeah.

Robby Peralta

It sounds to me like there's like a new a new era for like pen testing. How has it uh oh yeah? Like what were your like re clients' expectations and requirements before compared to what they are now, if they even know what you know, uh which I doubt they did.

Erica Burgess

Uh well, I think Expo made a really good talk at Black Hat. I was actually talking to them a lot because our talks were really similar. It was how do you automate pen testing, or which parts of pen testing can you automate and which part is still in the human creative space? And how do you guide that? And so we actually had come to such a similar conclusion, which is you subtask it. So you have instead of the pen testing agent, you have uh an agent that does XSS, you have an agent that's very good at SQL injection, kind of like with human hackers that specialize, like this person's really good at C Surf, so talk to them. And those agents can vote and work together and sort of create a a bigger managed system with an agent manager. So it's it's kind of funny. Everyone's got these different approaches, but we all end up kind of convening toward the same things that work, right?

Robby Peralta

When you say subtasking, is it hard to set those up or is it actually kind of just like, hey, I want you to do this and your name this and now I have your and this team? How does that actually work in real in real life?

Erica Burgess

Oh, it's a lot of fun, actually. So I think anyone that is fairly analytical and good at describing something can pretty much make a GPT agent at this point. Subtasking, um, you can kind of see how I'm talking about a job rule here. You've got a few different things you're trying to do, and each one's its own agent. And so some agents will need to judge, or some agents will need to rank, or other agents will just need to brainstorm. Um what's a lot of hacking is just brainstorming, right? It's just finding a bunch of things you can try. And so subtasking for hacking could be all right, this agent's gonna run through the dynamic scanner results and try to validate each of these and actually run things. Don't just look for things that scanners used to look for, which was the payload in text, because what would happen a lot was the payload would present as text on the page and didn't mean that it was executing. It meant that the code was there being presented as text, and that's not dangerous, right? So that's not a real test per se. So actually having it test and run commands is very, very helpful. Um, the more orchestration you do, like have the tasks run different commands, the more dangerous it is. So the more monitoring you need. So if it's not putting out a report that you just need to review and it's actually running hacking tools, that recalls for a lot of watering. So that subtasking is what helps you sort of create those human in the loop interactions where you're like, okay, you've done a lot, like let's stop and just sort of review what's worked and what's hasn't worked. And so, you know, previously, if I found a new SQL injection, I'd add it to SQL map. Like I've patched their open source code and added like new techniques, right? Just so I'd have it the next time I run it. But imagine an agent that's always looking for things that SQL map hasn't succeeded at and always automatically patching and submitting things for code review 24-7. So that's kind of a rough overview of the whole world of orchestration and agents. And so they have different levels of uh autonomy, and there's a reason for that because some of them are more dangerous.

Robby Peralta

Yeah. That one example you just had to actually verify the results that came up. How many of those sort of agents have you built? And did you build them yourself, or did you just have to, or they're kind of laying around in like a store that you can just pull from?

Erica Burgess

Yeah, uh, I built a few myself just because I have a very particular way of testing and I really wanted the agent to reflect that. So something that we haven't been able to automate yet is kind of the intuition of like, where does it make sense to try this thing? Right. Or does it feel like this page was written in a way that it's susceptible to this sort of attack? And so, because I've been doing this for, you know, 20 years since I was a teenager, right? So I've got this intuition that I don't even know how it works, right? I just sort of get a feel for things. And so if I get a feel for something, I might design an agent to sort of help me build out an attack category. So I wrote one that specifically does cross-site scripting for strictly formatted data fields like phone numbers and email addresses and makes the verification code into the XSS uh execution point. So, to kind of give you an example, so when you types in their email address, uh, if it's not a properly formatted email address, it will throw up an error, right? Or it'll display an error inside the page. And so sometimes uh it's difficult to get cross-site scripting in these fields because you can't put the command inside the field because it's not allowing uh coding. It's not allowing a command with brackets and and all the symbols that you're too long, whatever, yeah. Yeah. And so what happens instead is sort of creating like a um a well, having the system create a payload that specifically uses the verification code in order to create that uh cross-site scripting such that the payload contains a malformed email address or a malformed phone number or something like that. And that way it'll launch it. So that's a very, very specific example, right? I came across maybe two or three times in my whole life where the verification code that was supposed to help control the data input and sanitize that data and lock it down is actually the mechanism that's being used for the exploit. So I needed an agent to look for stuff like that, you know, because all of those freeform text fields on that form, they were not able to be exploited because they're freeform, because they were looking for either a security validation or in the other fields, they're looking for business validation. So sometimes those two goals don't really layer well, and that's where you find a gap in security. And so, yeah, a few things like that have happened so far where it's most helpful for a lot of client-side attacks, unless you have that access to the open source code and all of that, because then you can kind of get into like the verse engineering, which I talked about a little in my talk. So decompiling source code from uh executable and things like that. Uh AI is very, very helpful for those kind of things. And so other times, you know, a site's too broken to hack, right? And so I'll throw the source code into, or the client-side source codes rather, into a GPT agent and say, what's wrong with this? What field needs to be added? What API endpoint isn't being hit that I can't use the site. It'll actually help fix the site. I'll adjust it on my end, and then I continue hacking because a broken website isn't really like an excuse not to hack it. Like it just adds like the harder uh Erica. We're not working with this company. We're we're above this. Right. So then you kind of become a software engineer for a second, but then you then you can proceed with the hacking, yeah, which is fun.

Robby Peralta

Wow. So, what is your take on the future of pen testing and vulnerability development given the state of LLMs? You have we talked about XBOW, you have, I think his big sleep from Google. Like what how do you look at uh this space moving forward?

Erica Burgess

I mean, the sky's the limit. I I really hope that we think of more good use cases for it than bad use cases just for AI in general. I worry about bias, not just the traditional legal bias, like gender and sexuality and race, but I worry about bias towards a specific type of attack. If a lot of attackers are using GPT the same way and we're kind of takeout brain insert AI, right? It's it's there's a big danger to create a big blend uh spot. And similarly for people who are coding, so if part of your prompt isn't considered security practices, well, there might be problems. And even if you do have that as part of a prompt, you may be generating very uh insecure code. And I feel that if everyone's using a very similar prompt, we'll have a very similar group of attacks in the future where you know everyone starts using this weird old uh implementation of an encryption algorithm for no reason, other than the fact that the LLM is is more likely to spit it out most of the time and it's off by like one character, right? Or something strange, right? And so I could see that happening. You know, back in the day, I would look at Stack Overflow and I'd look at like what was being downvoted the most as like insecure, and that would kind of help inspire attacks and it would help me also do OSINT on different uh places that had their source code up on Stack Overflow, and a developer's asking, Hey, how do I do this? And now I know exactly how that code's written, right? Uh for proprietary code. Uh, but in a similar vein, if you think of the LM as taking all that Stack Overflow information, it's taking the good, bad, and the ugly. You know, it's taking that source of administrator who just needs something to fix real quick and he just needs to put this patch in and um just try to make this admin console so when I'm on vacation, I can log in real quick and and just do this convenient thing. Well, that convenience becomes convenient for attackers. And so if everyone has the same zeitgeist and they're kind of moving in the same direction because either everything was uploaded to uh Stack Overflow and now it's in the LLM, or because they're they've always been doing that, it's still kind of the same energy. Like even though it's a different tech, it's still the same problem of like not having that oversight or copying pasting and that sort of thing. So I see that. And then my last prediction, I guess, would be seeing more sophisticated exploits from people who don't know how to code. So being able to say uh to the LLM, you know, hey, hack this website, it's probably gonna say no, there's safety features. But if you say something like, you know, write the script that actually will do this very specific command and then encrypt all these files, oops, now you have ransomware written by this, you know, 12-year-old, you know, who's never who's never written a line of code before. So I could see that. I foresee more zero days, more CVEs. And in fact, I believe the Department of Homeland Security was at one of the conferences I was speaking at, and they said something like they'd seen this huge jump in CVEs in the last few years. They can't keep up anymore because there's just so many new exploits, presumably, or ends up with the timeline of AI. So that's kind of how I see the field moving. It's gonna be a quite a ride. So yeah. Oof. Yeah.

Robby Peralta

Um what are we supposed to do about those things?

Erica Burgess

We get creative. We so I'm actually doing a talk next month for CactusCon slash no talk. So what I like to do is have like some real talk that's unrecorded, unstreamed, and just kind of really, really talk about how vendors react to these things, right? So that inside baseball of like, okay, I don't want to besmirch someone's name, but this was not handled properly. Like when I reported this exploit, this happened. And what do you guys think? And like having that kind of discussion off the record is important. And it's similar with AI, is not having all this discussion about how we're gonna bypass AI moderation, AI censorship in a place where the AI can come scoop it up and just use it as material in its training data, right? So it's a very hard what line to walk. So if you're being creative and you have all these new techniques and things, and it might be better to do, you know, in-person talks, which sounds really old school, but sometimes that's the only way to have discussions on how to strategize on these things, because otherwise it just becomes part of AI strategy or becomes part of that whole, you know, sphere of consciousness that AI is building, which sounds very sci fi, but that's kind of what's Big Brother is watching and Big Brother is not a human anymore. Yeah, exactly. Yeah.

Robby Peralta

So do you think that your a lot of your assignments moving forward, it would make sense if they were more teaching developers or teaching internal security teams? To be more like you and not you actually doing the work, but your time will pivot to training instead of doing pen tests because Yeah, that's a really good question.

Erica Burgess

I thought about building a cert program just because, you know, so much of what's going on is so new, but yet the industry still has these handcuffs to certs, right? Like to try to do training for everyone at once. Well, you you kind of almost need that cert program for something new. And so I have sort of this train of thought about training that goes like this. So two schools of thought with hacking, right? You've got in-depth, which is usually those self-trained people. They've gotten really good at some niche because they've just have this like really unique perspective and this really crooked uh career path like mine, where they've just kind of developed a passion for this one particular way of hacking. And then you've got the breadth people, which maybe they have a cybersecurity degree, uh, maybe they have a lot of certs, but they've got a little bit of surface information about a lot of different topics. So you've got these two camps of people, and I think combined it's really, really powerful because it's just the breadth people help make uh a little bit of awareness and intuition across the system. And then the in-depth people help really drive home the exploit actually working. You know, they're not just trying it, they're completing it completely. They're sort of creating that POC. They're they're maybe even generating something new, right? So I could see, yeah, my time being spent on how do we navigate this future of, okay, we used to have institutionalized education that was very widespread, uh at college and coding boot camps and uh try hack me and hack the box and sort of these uh kind of systems for creating almost like this railroad of learning pen testing. And we've got sort of these, I don't want to say like amateurs, but sort of just like Wild West people. Like they've just, for some reason, they've gotten really good at one part of hacking and they're just they're usually the ones doing talks because they've got something that they need to add to the industry, right? So I could see this kind of going in a whole new direction with GPT, because would you put GPT in a camp of Wild West or would you put it in the camp of breadth? Like it has this kind of breadth, but also doesn't have like intuition or drive or some of like the human creativity yet, anyway, that makes for a complete, you know, body of knowledge that's now an expert, you know? So um yeah, I could see that. Um I also look at you know, white papers like Google Deep Mind, where they talk about the impacts of a society where there is uh a general AI. So what right now we have generative AI, but not to be confused with general intelligence, which is something that's just generally an expert at just anything, right? So, you know, cooking or plumbing or uh pen testing or you know, knowledge work stuff, you know, um data analysis, things like that. And I pay attention to what happens if there's displacement due to uh AI, right? So there's people uh right now I have got folks who who are being displaced. And while I'm, you know, I'm lucky I do a lot of independent consulting, and I'll probably always be doing independent consulting, but I could see a lot of corporations trying to maximize efficiency and sort of displace that. So that just means that there's an opportunity for more training. How do you build autonomous agents? How do you effectively make everyone a project manager for all these little subtasks? So um Yeah, certainly. Definitely uh room for change in the future.

Robby Peralta

Yeah. I'm actually trying to find it, was actually somebody from the US Department of Defense. They were speaking at a SANS event in London right before you. Maybe you were at the same event, I don't know. But she went uh on a like a kind of like a tangent about citizen salary that everybody's getting money from the government, basically, because AI's taking over, right? And wow, she got there because she was talking about how they weren't hiring junior talent anymore, especially for these sort of fields, because you have, you know, the experts or you have AI that's really good at these things. So why hire somebody that's that's the same level as AI anyway, and you know, use a bunch of money for them to train them up and then they leave. And but that just means there's no more junior people. And where does that leave us as a society where there's no entry-level people anymore? It's just these experts that yeah, it's a it's a strange future, and I'm not sure where it's gonna take us, and it's very scary as somebody that's relatively young.

Erica Burgess

It's isn't it funny? Like, we almost need philosophy to help us understand how knowledge works now. Like we have to think, like we have to revisit something that we've never really revisited in human history, which is the acquisition of knowledge. How is it valued if that's automated? I mean, you've got, I don't know, Marx looking at the loom way back then, like, okay, this machine's gonna replace people. And you've got this whole very, I guess, communist view of like, where's the labor coming from and the means of production? Well, what happens when the means of production are the labor? So then you get governments thinking almost in this more socialist way of, well, how do we take care of the people when we automate that labor and the means of production at the same time? You know, it's just so fascinating. And so I foresee philosophy becoming very important. I see art and humanities as becoming maybe the most important thing, not just because you need good writing skills and good communication skills and good vision to tell an AI what to do, but you know, because we want to continue to have vision and not get um sort of put down and sort of depressed by a depressed economy where people are being displaced, right? So it's like, how do we move forward creatively and still design what should be and design what we do want and what we can imagine as a good thing? Because the machine's not going to tell us what we want, hopefully. Um we should always have a set of values that we go back to as a people and say, like, what is worth automating? What needs to be a craft, what needs to be made by a human hand? You know, I enjoy hand-knit sweaters and things. They're beautiful, but a machine can also make that, you know, for much cheaper. And I have to say it's not as beautiful. There's things that, you know, there's just something to something handmade. And maybe that doesn't apply to code so much, but maybe it will in the future. I don't know. Uh, and I think that understanding like that interaction is gonna be the part of philosophy, which a lot of us kind of shrugged off, you know, English class, right? And said, Well, I'm not gonna use this, I'm gonna be an engineer or I'm gonna be um something else. I'm gonna be a doctor or something, right? And so, but now we're seeing things like, you know, in the in the political sphere, people using sort of sound bites to kind of drive home different political goals and things. Well, if you use sound bites, it kind of falls on deaf ears when everyone's getting inundated by AI slap. So to break out of that and sort of continue being able to think freely and have a system where you've got people, you know, forming their own opinions, you have to be able to structure those and create, you know, metaphor and create new words and create things so that you don't become cliche and you don't become derivative because then thoughts become derivative, right? So then you're kind of helping a society out of what could be uh oppressive AI, like what could be a very bad force, right? Uh all in the name of uh the market, right? All in the name of saving some money and that sort of thing. Uh so we really have to remember what our values are and and philosophize a bit. And yeah, I don't mean to be political in any direction, but it politics will matter quite a lot as we see these systemic government changes. So I definitely encourage don't turn off your brain, don't just use AI because I guess there was a study that came out that people who use AI too much, like it actually shows less activity in their brain. So I'm scared of that.

Robby Peralta

Yeah. Well, uh, I've tried to make like the RSS feed, the newsletter, and all those things, but I've I've just noticed that some things and my brain just like that's interesting. And that AI just picked a bunch of stuff that wasn't interesting. So I just kind of gave up on that. And I'm glad I did because I I would have just been lazy and not thought for myself anymore. So, but I'm glad to hear you found a good way to use it, at least in your life.

Erica Burgess

It could change next year, right? So these improvements happen all the time. I could get stumped by this stuff too. Um yeah, I agree. I mean, that newsletter maybe it became really contrived, maybe it became cliche. And that's kind of the feedback that we need as people, right? Like we need to be able to say, hey, I identified this as this is kind of AI slap. I don't like this. Or, wow, I found that. That's interesting. I wouldn't have seen that. And try to find a middle ground somewhere. Yeah. Yeah, you'd always tweak it.

Robby Peralta

Last question Do you think do you think the sort of disruption that you felt the past three years in in pen testing in your area is the same across all areas of security? Or is it more on your field because it was kind of niche before? Or what are your thoughts on that?

Erica Burgess

Yeah, as far as like my niche and offensive security and some of the creativity, uh, it does bring to mind like a lot of this philosophy about well, what is creativity? How do we keep developing new things? Is the AI gonna outrun me? Are we causing problems by removing junior developers that are doing these sort of tedious orchestrations that an AI can do? And so I think it's affected pretty much every part of cybersecurity for better or for worse. And like I said, it's really launched a lot of philosophy for me about like what is important to like humanity, right? What does life look like, um, let alone just the cybersecurity field, right? So um being a hacker, it's kind of neat because I have this like front row seat where hackers will always try to use every tool. Like they'll always try to be the first one to use it to try to find problems with it. And we're usually the early adopters for everything because we want to like just start tinkering and and doing things. So I'm used to kind of being on the cusp of things. What I'm not used to is sort of this huge philosophical shift that happens uh that seems to be more than marketing. Uh, it seems like it's something worth considering. So yeah, it's a lot to digest.

Robby Peralta

Thank you so much for your time, um, Erica. And uh you will hear from me again one day soon. Thank you so much. Take care.

Erica Burgess

Thank you. Take care. Bye. Bye.

Robby Peralta

Well, that's all for today, folks. Thank you for tuning in to the Mnemonic Security Podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.netno. Thank you for listening, and we'll see you next time.