Image
Episode 29  •  Aug 11, 2026  •  46 Min

Live From DEF CON at RedTail: Red Teaming After AI

This week's episode is different. No headlines, no CVEs. Just a live sit-down from Bishop Fox's RedTail meetup at DEF CON, with Bishop Fox's John Untz, Richard Brown, and Billy Giles, joined by Matt Bryant of OpenAI's Red Team, talking through what's signal vs. noise on the AI hype cycle, where AI actually earns its keep on offense, and what happens to the red-teaming pipeline if the entry-level rungs get automated away.

Killing the entry-level pen tester job kills the pipeline that builds every future Red Teamer. The biggest worry isn't AI replacing Red Teamers; it's AI quietly erasing the junior roles that turn people into Red Teamers in the first place. The fix: stop assuming the pipeline only runs through pen testing, and start recruiting from adjacent technical trades like network engineers, systems admins, anyone with hands-on infrastructure instinct. John's own path from military ground radio into cyber is the proof of concept, not the exception.

"AI hacked X" is never the sentence. It's always someone using AI to hack X. The panel pushed back hard on headline framing that turns AI into the actor instead of the tool. Every "AI breach" story, once you open it, is a person with intent picking up a faster instrument. The skill and the decision-making are still human. The harder problem is that the field is moving fast enough that a defensive playbook written a year ago can already be obsolete.

The clock between disclosure and working exploit isn't shrinking gradually — it's collapsing. Matt's read from inside a frontier lab: the gap from "CVE dropped" to "exploit works" keeps getting shorter, and it's not slowing down. That collides directly with a problem that predates AI entirely: the change-review-board bottleneck that holds patches for approval cycles measured in days, not minutes. AI has made slow patch governance a lot more expensive.

The unlock isn't getting in. It's what happens in the first ten minutes after. Matt's actual day-to-day surprise: initial access was never the hard part for a skilled operator. What AI collapsed is the recon grind after the breach. Instead of manually tracing which of a hundred codebases holds the production database, you just ask a model in plain English and get pointed at it. Phishing infrastructure spins up on the same accelerated timeline. The operational bottleneck that used to eat hours now eats minutes.

Lowering the skill bar doesn't lower the crime bar. Billy's flat rejection of the "AI made hacking too easy, now anyone's a criminal" narrative: threat-intel reporting shows attackers using AI the same mundane way defenders do: to write code faster, not to manufacture criminal intent out of nowhere. The person doing the damage was already willing to do it. AI changed the tooling, not the ethics.

In 2-3 years, the story won't be about the models but about who deployed them carelessly. Richard's prediction is blunt: even AI-native practitioners are already making mistakes, so the real unknown is every organization without that specialization bolting AI onto production and hoping. Regulation isn't moving at the model's speed, and nobody on the panel (including someone building the models) would bet confidently on where this lands. The one thing Matt is willing to call: computers are about to feel a lot less like a keyboard and mouse.


Sean McMillan Headshot

Sean McMillan

Community Manager

Sean McMillan is Community Manager at Bishop Fox, focused on making complex security topics easier to understand and more interesting to follow. He holds a bachelor’s degree in Mass Communication and Media Studies from Arizona State University and brings over a decade of experience in podcasting, live hosting, and audience engagement. As host of Initial Access, he works with practitioners to explore how real-world attacks actually happen.


Bfx25 John Untz Author Bio 1

John Untz

Senior Security Engineer, Exploit Developer

John is a Senior Security Engineer, Exploit Developer, where he focuses on reverse engineering emerging threats and developing advanced capabilities to protect our customers' attack surfaces. Prior to joining Bishop Fox, John served in a number of selectively manned US Air Force teams, and is a graduate of the NSA's Computer Network Operations Development Program (CNODP).


Richard Brown headshot

Richard Brown

Senior Managing Operator

Richard Brown is a Senior Managing Operator at Bishop Fox, where he leads a team focused on emerging threats, customer notification, exploit development, automation, and operational innovation. He partners across the organization to enhance attack surface intelligence capabilities and deliver actionable security insights to customers.

With more than 15 years of experience in cybersecurity, consulting, and law enforcement, Richard has specialized in threat intelligence, offensive security, and investigative analysis. His background as a detective in the Intelligence Division of the St. Louis Metropolitan Police Department helps shape his attacker-focused approach to identifying and understanding threats.


Headshot Giles

Billy Giles

Managing Senior Consultant

Billy Giles is an Offensive Security leader and practitioner who specializes in red/purple teaming and network penetration testing. With a deep passion for understanding adversary behaviors, he helps organizations across a multitude of industries assess their security postures, identify and remediate vulnerabilities, and build stronger defenses by thinking like an attacker.


Default fox headshot blue

Matt Bryant

Bishop Fox Alumnus

Matt Bryant is a security researcher, currently working at OpenAI as an OffSec Engineer. He was formerly a consultant at Bishop Fox.


Subscribe to our PODCAST

Real talk on the threats, trends, and tactics shaping security today

Listen Anywhere