Podcast

AI-Powered Threat Actors, Poison Pills & Cyber Sabotage with John Hultquist

On this episode of Crying Out Cloud, Eden Koby Naftali & Amitai Cohen sit down with John Hultquist, Chief Analyst at Google Threat Intelligence Group (ex-Mandiant, ex-FireEye, founder of CYBERWARCON & SLEUTHCON).

Drawing on over two decades of tracking state-sponsored adversaries like Sandworm, John cuts through the hype to explain what modern threat intelligence actually does: it keeps CISOs from burning millions of dollars on the wrong technology, spots adversary shifts before static IOCs exist, and bridges the gap between raw binary reverse-engineering and executive decision-making.

In this episode, John unpacks how threat actors are weaponizing AI and bypassing commercial costs entirely and traces the real shift underway: adversaries embedding adversarial prompt-injection payloads inside malware to shut down automated SOC scanners.

What's Inside:

  1. The economics of illicit AI: Underground access vs. hijacked enterprise compute
  2. Malware poison pills designed to neutralize automated LLM triage
  3. Why firmware and ICS layers are becoming primary targets for disruption
  4. Behavioral detection models when living-off-the-land means zero usable IOCs
  5. Lessons from tracking Sandworm and convincing leadership to act before the lights go out

Crying Out Cloud Newsletter

Stay Safe & Informed: Receive the Latest Cloud Security News, Real Attack Insights, and Expert Guidance to Protect Your Environment.

Sign up to receive the latest updates in cloud security directly to your inbox

For information about how Wiz handles your personal data, please see our Privacy Policy.