<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link href="https://feeds.simplecast.com/o0rdTWqv" rel="self" title="MP3 Audio" type="application/atom+xml"/>
    <atom:link href="https://simplecast.superfeedr.com" rel="hub" xmlns="http://www.w3.org/2005/Atom"/>
    <generator>https://simplecast.com</generator>
    <title>Kill Chains and Coffee</title>
    <description>&quot;Kill Chains and Coffee&quot; breaks down how real AI attacks unfold, one kill chain at a time. Host Greg Heon, VP of Product Management at Armadin, joins red team operators and security researchers to show how attackers break in, move laterally, and reach their objective—and explains where defenders can break the chain.

As AI-generated attacks spread, the series explores how offensive security is changing and how pairing experienced red teamers with AI tooling lets you test your defenses the way modern adversaries attack.

For CISOs, security leaders, and practitioners who want the attacker&apos;s viewpoint without the hype.</description>
    <copyright>2026 Armadin</copyright>
    <language>en</language>
    <pubDate>Thu, 24 Sep 2026 16:52:33 +0000</pubDate>
    <lastBuildDate>Thu, 24 Sep 2026 19:35:06 +0000</lastBuildDate>
    <image>
      <link>https://kill-chains-and-coffee.simplecast.com</link>
      <title>Kill Chains and Coffee</title>
      <url>https://image.simplecastcdn.com/images/ad624afe-5838-4c7a-b2cb-f92d99708994/15882b02-364d-4988-b989-23845b521bbd/3000x3000/cropped_1790265402298.jpg?aid=rss_feed</url>
    </image>
    <link>https://kill-chains-and-coffee.simplecast.com</link>
    <itunes:type>episodic</itunes:type>
    <itunes:summary>&quot;Kill Chains and Coffee&quot; breaks down how real AI attacks unfold, one kill chain at a time. Host Greg Heon, VP of Product Management at Armadin, joins red team operators and security researchers to show how attackers break in, move laterally, and reach their objective—and explains where defenders can break the chain.

As AI-generated attacks spread, the series explores how offensive security is changing and how pairing experienced red teamers with AI tooling lets you test your defenses the way modern adversaries attack.

For CISOs, security leaders, and practitioners who want the attacker&apos;s viewpoint without the hype.</itunes:summary>
    <itunes:author>Armadin</itunes:author>
    <itunes:explicit>false</itunes:explicit>
    <itunes:image href="https://image.simplecastcdn.com/images/ad624afe-5838-4c7a-b2cb-f92d99708994/15882b02-364d-4988-b989-23845b521bbd/3000x3000/cropped_1790265402298.jpg?aid=rss_feed"/>
    <itunes:new-feed-url>https://feeds.simplecast.com/o0rdTWqv</itunes:new-feed-url>
    <itunes:keywords>ai security, armadin, ai hyperattack, ai agents, attack surface, agentic ai, autonomous cyberattacks, cve exploitation, ssrf, hyperattack, greg heon, cybersecurity, pentest, cloud security, penetration testing, offensive security, rce, ill chains and coffee, continuous assessment, privilege escalation, kill chain, kevin mandia, red teaming, evan pena, machine-speed attacks</itunes:keywords>
    <itunes:owner>
      <itunes:name>Armadin</itunes:name>
      <itunes:email>helena.davis@armadin.com</itunes:email>
    </itunes:owner>
    <itunes:category text="Technology"/>
    <item>
      <guid isPermaLink="false">ae9d7302-5f8c-4558-bb07-881c9e529ff8</guid>
      <title>Command Execution on Cleo Harmony via SAML Bypass | Kill Chains and Coffee</title>
      <description><![CDATA[<p>In the AI era, it’s critical to test your attack surface just like an adversary would. Identifying truly exploitable risk means chaining together all possible vulnerabilities, rather than stopping when you find one.</p><p>In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin red team expert Ilyass El Hadi revisited a recent kill chain that led to an exploit of Cleo Harmony, a managed file transfer application used by thousands of organizations to exchange sensitive documents.</p><p>The chain began with unauthenticated external access leading to self-registration on the IdP (Okta). The Armadin attacker found two key vulnerabilities. The first was SAML XML Signature Wrapping (XSW). Cleo verified one SAML assertion but consumed an attacker-injected one and the attacker ultimately gained access to live support ticket files and customer data.</p><p>The second vulnerability was ‘cross-store identity confusion’, which escalated from forged low-privilege identity to full Cleo administration privileges. Chained together, these vulnerabilities culminated in Cleo Actions abuse, with admin access sufficient for OS command execution in a production environment with sensitive data that could have impacted multiple organizations.</p><p>The vulnerabilities were tracked as CVE-2026-84114 and CVE-2026-84115, and have already been patched.</p><p>For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify exploitable risk across your entire environment. Learn how at http://hyperattack.AI.<br><br>RESOURCES&nbsp;<br>Companion Blog Post: <a href="https://www.armadin.com/blog-posts/compromising-cleo-harmony-a-saml-bypass-chain-to-arbitrary-code-execution" rel="noopener noreferrer">https://www.armadin.com/blog-posts/compromising-cleo-harmony-a-saml-bypass-chain-to-arbitrary-code-execution</a><br>Armadin Offensive Security Platform: <a href="https://armadin.com/platform" rel="noopener noreferrer">https://armadin.com/platform</a>&nbsp;<br>Request a Demo: <a href="https://www.armadin.com/request-a-demo" rel="noopener noreferrer">https://www.armadin.com/request-a-demo</a></p><p>CONNECT WITH ARMADIN&nbsp;<br>Website: <a href="https://armadin.com/" rel="noopener noreferrer">https://armadin.com</a>&nbsp;<br>LinkedIn: <a href="https://www.linkedin.com/company/armadin" rel="noopener noreferrer">https://www.linkedin.com/company/armadin</a>&nbsp;<br>Twitter/X: <a href="https://x.com/armadinsecurity" rel="noopener noreferrer">https://x.com/armadinsecurity</a></p>
]]></description>
      <pubDate>Thu, 24 Sep 2026 16:52:33 +0000</pubDate>
      <author>helena.davis@armadin.com (Greg Heon, Ilyass El Hadi)</author>
      <link>https://kill-chains-and-coffee.simplecast.com/episodes/command-execution-on-cleo-harmony-via-saml-bypass-kill-chains-and-coffee-bvRr8f5d</link>
      <content:encoded><![CDATA[<p>In the AI era, it’s critical to test your attack surface just like an adversary would. Identifying truly exploitable risk means chaining together all possible vulnerabilities, rather than stopping when you find one.</p><p>In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin red team expert Ilyass El Hadi revisited a recent kill chain that led to an exploit of Cleo Harmony, a managed file transfer application used by thousands of organizations to exchange sensitive documents.</p><p>The chain began with unauthenticated external access leading to self-registration on the IdP (Okta). The Armadin attacker found two key vulnerabilities. The first was SAML XML Signature Wrapping (XSW). Cleo verified one SAML assertion but consumed an attacker-injected one and the attacker ultimately gained access to live support ticket files and customer data.</p><p>The second vulnerability was ‘cross-store identity confusion’, which escalated from forged low-privilege identity to full Cleo administration privileges. Chained together, these vulnerabilities culminated in Cleo Actions abuse, with admin access sufficient for OS command execution in a production environment with sensitive data that could have impacted multiple organizations.</p><p>The vulnerabilities were tracked as CVE-2026-84114 and CVE-2026-84115, and have already been patched.</p><p>For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify exploitable risk across your entire environment. Learn how at http://hyperattack.AI.<br><br>RESOURCES&nbsp;<br>Companion Blog Post: <a href="https://www.armadin.com/blog-posts/compromising-cleo-harmony-a-saml-bypass-chain-to-arbitrary-code-execution" rel="noopener noreferrer">https://www.armadin.com/blog-posts/compromising-cleo-harmony-a-saml-bypass-chain-to-arbitrary-code-execution</a><br>Armadin Offensive Security Platform: <a href="https://armadin.com/platform" rel="noopener noreferrer">https://armadin.com/platform</a>&nbsp;<br>Request a Demo: <a href="https://www.armadin.com/request-a-demo" rel="noopener noreferrer">https://www.armadin.com/request-a-demo</a></p><p>CONNECT WITH ARMADIN&nbsp;<br>Website: <a href="https://armadin.com/" rel="noopener noreferrer">https://armadin.com</a>&nbsp;<br>LinkedIn: <a href="https://www.linkedin.com/company/armadin" rel="noopener noreferrer">https://www.linkedin.com/company/armadin</a>&nbsp;<br>Twitter/X: <a href="https://x.com/armadinsecurity" rel="noopener noreferrer">https://x.com/armadinsecurity</a></p>
]]></content:encoded>
      <enclosure length="18592215" type="audio/mpeg" url="https://cdn.simplecast.com/media/audio/transcoded/5a6066af-e9ad-469a-ba68-2ad389ab2446/f878096c-b42a-41f8-86df-982c82b02d0b/episodes/audio/group/91f82563-bfdb-483f-b599-69146ae61ac3/group-item/47341abf-59ba-4765-a19a-1d96a6885a85/128_default_tc.mp3?aid=rss_feed&amp;feed=o0rdTWqv"/>
      <itunes:title>Command Execution on Cleo Harmony via SAML Bypass | Kill Chains and Coffee</itunes:title>
      <itunes:author>Greg Heon, Ilyass El Hadi</itunes:author>
      <itunes:duration>00:19:21</itunes:duration>
      <itunes:summary>In the AI era, it’s critical to test your attack surface just like an adversary would. Identifying truly exploitable risk means chaining together all possible vulnerabilities, rather than stopping when you find one.

In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin red team expert Ilyass El Hadi revisited a recent kill chain that led to an exploit of Cleo Harmony, a managed file transfer application used by thousands of organizations to exchange sensitive documents.

The chain began with unauthenticated external access leading to self-registration on the IdP (Okta). The Armadin attacker found two key vulnerabilities. The first was SAML XML Signature Wrapping (XSW). Cleo verified one SAML assertion but consumed an attacker-injected one and the attacker ultimately gained access to live support ticket files and customer data.

The second vulnerability was ‘cross-store identity confusion’, which escalated from forged low-privilege identity to full Cleo administration privileges. Chained together, these vulnerabilities culminated in Cleo Actions abuse, with admin access sufficient for OS command execution in a production environment with sensitive data that could have impacted multiple organizations.

The vulnerabilities were tracked as CVE-2026-84114 and CVE-2026-84115, and have already been patched.

For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify exploitable risk across your entire environment. Learn how at http://hyperattack.AI.</itunes:summary>
      <itunes:subtitle>In the AI era, it’s critical to test your attack surface just like an adversary would. Identifying truly exploitable risk means chaining together all possible vulnerabilities, rather than stopping when you find one.

In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin red team expert Ilyass El Hadi revisited a recent kill chain that led to an exploit of Cleo Harmony, a managed file transfer application used by thousands of organizations to exchange sensitive documents.

The chain began with unauthenticated external access leading to self-registration on the IdP (Okta). The Armadin attacker found two key vulnerabilities. The first was SAML XML Signature Wrapping (XSW). Cleo verified one SAML assertion but consumed an attacker-injected one and the attacker ultimately gained access to live support ticket files and customer data.

The second vulnerability was ‘cross-store identity confusion’, which escalated from forged low-privilege identity to full Cleo administration privileges. Chained together, these vulnerabilities culminated in Cleo Actions abuse, with admin access sufficient for OS command execution in a production environment with sensitive data that could have impacted multiple organizations.

The vulnerabilities were tracked as CVE-2026-84114 and CVE-2026-84115, and have already been patched.

For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify exploitable risk across your entire environment. Learn how at http://hyperattack.AI.</itunes:subtitle>
      <itunes:keywords>xsw, ai security, red team, command execution, cve-2026-84115, cve-2026-84114, os command execution, idp, armadin, hyperattack, cross-store identity confusion, offensive security, saml bypass, okta, privilege escalation, saml xml signature wrapping, cleo harmony, kill chains and coffee, cleo actions abuse, penetration testing, cybersecurity, mft, attack surface, managed file transfer</itunes:keywords>
      <itunes:explicit>false</itunes:explicit>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>4</itunes:episode>
    </item>
    <item>
      <guid isPermaLink="false">27b5a0d4-c847-4d79-b472-0d590e8c1869</guid>
      <title>Why AI Beats Human Pentesting | Kill Chains and Coffee</title>
      <description><![CDATA[<p>Human-led penetration testing is too narrow and slow. Only AI agents can give you the scale and speed of 1,000 virtual pentesters collaborating on a single mission.<br><br>In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin Principal Red Team Operator Craig Wright go in depth on a recent kill chain that targeted a large telco provider. The results revealed the widening gap between legacy pentesting and using Armadin’s AI attacker as an offensive security tool.<br><br>The managed assessment covered 22,749 internet-facing services, with 175 services selected through intelligent targeting. The attack included thousands of AI agents taking 220,479 actions and finding exploitable risk that might have been hiding for decades.<br><br>The kill chain sequence began with an AI agent identifying a hidden registration endpoint using route name inference. It self-registered an account, then found a second registration mechanism and used the new account to generate an authorization token before pivoting to authenticated testing. It then identified three endpoints and produced working SQL injection payloads, eventually accessing five additional internal SQL servers.<br><br>The kill chain exposed 68.5 million rows of critical data, including workforce Personally Identifiable Information (PII), 911 call geolocation data, and enough SIM swap precursor data to fuel a social engineering campaign and execute a full SIM swap.<br><br>The key lesson is you can’t expect an 80-hour human-led pentest to address thousands of internet-facing services, but an agentic AI approach can easily cover the entire attack surface—all paths, all the time.<br><br>For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify critical exploitable risk across your entire environment.<br><br>Learn how at http://hyperattack.AI.<br><br>RESOURCES&nbsp;<br>Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-5-why-ai-beats-human-pentesting<br>Armadin Offensive Security Platform: <a href="https://armadin.com/platform" rel="noopener noreferrer">https://armadin.com/platform</a>&nbsp;<br>Request a Demo: <a href="https://www.armadin.com/request-a-demo" rel="noopener noreferrer">https://www.armadin.com/request-a-demo</a></p><p>CONNECT WITH ARMADIN&nbsp;<br>Website: <a href="https://armadin.com/" rel="noopener noreferrer">https://armadin.com</a>&nbsp;<br>LinkedIn: <a href="https://www.linkedin.com/company/armadin" rel="noopener noreferrer">https://www.linkedin.com/company/armadin</a>&nbsp;<br>Twitter/X: <a href="https://x.com/armadinsecurity" rel="noopener noreferrer">https://x.com/armadinsecurity</a></p>
]]></description>
      <pubDate>Thu, 24 Sep 2026 16:52:24 +0000</pubDate>
      <author>helena.davis@armadin.com (Greg Heon, Craig Wright)</author>
      <link>https://kill-chains-and-coffee.simplecast.com/episodes/why-ai-beats-human-pentesting-kill-chains-and-coffee-nI2WlYtH</link>
      <content:encoded><![CDATA[<p>Human-led penetration testing is too narrow and slow. Only AI agents can give you the scale and speed of 1,000 virtual pentesters collaborating on a single mission.<br><br>In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin Principal Red Team Operator Craig Wright go in depth on a recent kill chain that targeted a large telco provider. The results revealed the widening gap between legacy pentesting and using Armadin’s AI attacker as an offensive security tool.<br><br>The managed assessment covered 22,749 internet-facing services, with 175 services selected through intelligent targeting. The attack included thousands of AI agents taking 220,479 actions and finding exploitable risk that might have been hiding for decades.<br><br>The kill chain sequence began with an AI agent identifying a hidden registration endpoint using route name inference. It self-registered an account, then found a second registration mechanism and used the new account to generate an authorization token before pivoting to authenticated testing. It then identified three endpoints and produced working SQL injection payloads, eventually accessing five additional internal SQL servers.<br><br>The kill chain exposed 68.5 million rows of critical data, including workforce Personally Identifiable Information (PII), 911 call geolocation data, and enough SIM swap precursor data to fuel a social engineering campaign and execute a full SIM swap.<br><br>The key lesson is you can’t expect an 80-hour human-led pentest to address thousands of internet-facing services, but an agentic AI approach can easily cover the entire attack surface—all paths, all the time.<br><br>For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify critical exploitable risk across your entire environment.<br><br>Learn how at http://hyperattack.AI.<br><br>RESOURCES&nbsp;<br>Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-5-why-ai-beats-human-pentesting<br>Armadin Offensive Security Platform: <a href="https://armadin.com/platform" rel="noopener noreferrer">https://armadin.com/platform</a>&nbsp;<br>Request a Demo: <a href="https://www.armadin.com/request-a-demo" rel="noopener noreferrer">https://www.armadin.com/request-a-demo</a></p><p>CONNECT WITH ARMADIN&nbsp;<br>Website: <a href="https://armadin.com/" rel="noopener noreferrer">https://armadin.com</a>&nbsp;<br>LinkedIn: <a href="https://www.linkedin.com/company/armadin" rel="noopener noreferrer">https://www.linkedin.com/company/armadin</a>&nbsp;<br>Twitter/X: <a href="https://x.com/armadinsecurity" rel="noopener noreferrer">https://x.com/armadinsecurity</a></p>
]]></content:encoded>
      <enclosure length="18835885" type="audio/mpeg" url="https://cdn.simplecast.com/media/audio/transcoded/5a6066af-e9ad-469a-ba68-2ad389ab2446/f878096c-b42a-41f8-86df-982c82b02d0b/episodes/audio/group/077bfd05-fef3-40cf-8a71-f4116f126dbd/group-item/49dff6ce-3312-4b64-8c02-6dae76b2a199/128_default_tc.mp3?aid=rss_feed&amp;feed=o0rdTWqv"/>
      <itunes:title>Why AI Beats Human Pentesting | Kill Chains and Coffee</itunes:title>
      <itunes:author>Greg Heon, Craig Wright</itunes:author>
      <itunes:duration>00:19:37</itunes:duration>
      <itunes:summary>Human-led penetration testing is too narrow and slow. Only AI agents can give you the scale and speed of 1,000 virtual pentesters collaborating on a single mission.
 
In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin Principal Red Team Operator Craig Wright go in depth on a recent kill chain that targeted a large telco provider. The results revealed the widening gap between legacy pentesting and using Armadin’s AI attacker as an offensive security tool.
 
The managed assessment covered 22,749 internet-facing services, with 175 services selected through intelligent targeting. The attack included thousands of AI agents taking 220,479 actions and finding exploitable risk that might have been hiding for decades.
 
The kill chain sequence began with an AI agent identifying a hidden registration endpoint using route name inference. It self-registered an account, then found a second registration mechanism and used the new account to generate an authorization token before pivoting to authenticated testing. It then identified three endpoints and produced working SQL injection payloads, eventually accessing five additional internal SQL servers.
 
The kill chain exposed 68.5 million rows of critical data, including workforce Personally Identifiable Information (PII), 911 call geolocation data, and enough SIM swap precursor data to fuel a social engineering campaign and execute a full SIM swap.
 
The key lesson is you can’t expect an 80-hour human-led pentest to address thousands of internet-facing services, but an agentic AI approach can easily cover the entire attack surface—all paths, all the time.
 
For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify critical exploitable risk across your entire environment.
 
Learn how at http://hyperattack.AI.</itunes:summary>
      <itunes:subtitle>Human-led penetration testing is too narrow and slow. Only AI agents can give you the scale and speed of 1,000 virtual pentesters collaborating on a single mission.
 
In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin Principal Red Team Operator Craig Wright go in depth on a recent kill chain that targeted a large telco provider. The results revealed the widening gap between legacy pentesting and using Armadin’s AI attacker as an offensive security tool.
 
The managed assessment covered 22,749 internet-facing services, with 175 services selected through intelligent targeting. The attack included thousands of AI agents taking 220,479 actions and finding exploitable risk that might have been hiding for decades.
 
The kill chain sequence began with an AI agent identifying a hidden registration endpoint using route name inference. It self-registered an account, then found a second registration mechanism and used the new account to generate an authorization token before pivoting to authenticated testing. It then identified three endpoints and produced working SQL injection payloads, eventually accessing five additional internal SQL servers.
 
The kill chain exposed 68.5 million rows of critical data, including workforce Personally Identifiable Information (PII), 911 call geolocation data, and enough SIM swap precursor data to fuel a social engineering campaign and execute a full SIM swap.
 
The key lesson is you can’t expect an 80-hour human-led pentest to address thousands of internet-facing services, but an agentic AI approach can easily cover the entire attack surface—all paths, all the time.
 
For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify critical exploitable risk across your entire environment.
 
Learn how at http://hyperattack.AI.</itunes:subtitle>
      <itunes:keywords>virtual pentesters, ai security, red teaming, ai hyperattack, pentest, pii exposure, kill chain, armadin, telco security, route name inference, sim swap, offensive security, authentication bypass, sqli, ai agents, agentic ai, sql injection, penetration testing, cybersecurity, attack surface</itunes:keywords>
      <itunes:explicit>false</itunes:explicit>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>3</itunes:episode>
    </item>
    <item>
      <guid isPermaLink="false">748a35a2-d670-45f0-9892-4bb82af21d50</guid>
      <title>World’s Largest Controlled Hyperattack | Kill Chains and Coffee</title>
      <description><![CDATA[<p>What’s worse: Getting an RCE dropped on you at 5 pm on a Friday or waking up on Monday with 12 RCEs sitting in your inbox?</p><p>Find out what our experts think on this episode of “Kill Chains and Coffee.” Host Greg Heon sits down with Armadin Offensive Security Manager Christian Elston to cover two kill chains: Armadin’s first-ever AI Hyperattack and the world’s largest controlled AI Hyperattack.</p><p>Key conversations include:<br>The growing power behind AI agents attacking organizations from the outside in<br>Why safety and control are so critical in the wake of the HuggingFace incident and similar attacks.</p><p>In the first kill chain, Armadin engaged with a Fortune 600 company, launching 100 simultaneous attacks with thousands of agents—nearly 1 million autonomous actions.</p><p>The agents discovered 12 endpoints vulnerable to unauthenticated Remote Code Execution (RCE) from the internet through Server-Side Request Forgery (SSRF). A combination of SRRF and a known CVE led to an overly permissive Kubernetes service. The agents ultimately escaped the Kubernetes pod and compromised the organization’s entire cloud infrastructure.</p><p>The second kill chain was the world’s largest controlled cyberattack, conducted for an Armadin client with globally critical infrastructure. The attack targeted over 25,000 services and executed millions of autonomous actions. The resulting report generated over 200 findings with nearly 40 validated kill chains, including exposure to the company’s crown jewels.</p><p>For security teams: This type of repeatable controlled assessment from Armadin gives you the tools and confidence to identify truly exploitable risk across your environment.</p><p>Learn how at http://hyperattack.AI.<br><br>RESOURCES&nbsp;<br>Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-4-worlds-largest-controlled-hyperattack&nbsp;<br>Armadin Offensive Security Platform: <a href="https://armadin.com/platform" target="_blank" rel="noopener noreferrer">https://armadin.com/platform</a>&nbsp;<br>Request a Demo: <a href="https://www.armadin.com/request-a-demo" target="_blank" rel="noopener noreferrer">https://www.armadin.com/request-a-demo</a></p><p>CONNECT WITH ARMADIN&nbsp;<br>Website: <a href="https://armadin.com" target="_blank" rel="noopener noreferrer">https://armadin.com</a>&nbsp;<br>LinkedIn: <a href="https://www.linkedin.com/company/armadin" target="_blank" rel="noopener noreferrer">https://www.linkedin.com/company/armadin</a>&nbsp;<br>Twitter/X: <a href="https://x.com/armadinsecurity" target="_blank" rel="noopener noreferrer">https://x.com/armadinsecurity</a></p>
]]></description>
      <pubDate>Thu, 24 Sep 2026 16:52:14 +0000</pubDate>
      <author>helena.davis@armadin.com (Greg Heon, Christian Elston)</author>
      <link>https://kill-chains-and-coffee.simplecast.com/episodes/worlds-largest-controlled-hyperattack-kill-chains-and-coffee-D_LuxCqK</link>
      <content:encoded><![CDATA[<p>What’s worse: Getting an RCE dropped on you at 5 pm on a Friday or waking up on Monday with 12 RCEs sitting in your inbox?</p><p>Find out what our experts think on this episode of “Kill Chains and Coffee.” Host Greg Heon sits down with Armadin Offensive Security Manager Christian Elston to cover two kill chains: Armadin’s first-ever AI Hyperattack and the world’s largest controlled AI Hyperattack.</p><p>Key conversations include:<br>The growing power behind AI agents attacking organizations from the outside in<br>Why safety and control are so critical in the wake of the HuggingFace incident and similar attacks.</p><p>In the first kill chain, Armadin engaged with a Fortune 600 company, launching 100 simultaneous attacks with thousands of agents—nearly 1 million autonomous actions.</p><p>The agents discovered 12 endpoints vulnerable to unauthenticated Remote Code Execution (RCE) from the internet through Server-Side Request Forgery (SSRF). A combination of SRRF and a known CVE led to an overly permissive Kubernetes service. The agents ultimately escaped the Kubernetes pod and compromised the organization’s entire cloud infrastructure.</p><p>The second kill chain was the world’s largest controlled cyberattack, conducted for an Armadin client with globally critical infrastructure. The attack targeted over 25,000 services and executed millions of autonomous actions. The resulting report generated over 200 findings with nearly 40 validated kill chains, including exposure to the company’s crown jewels.</p><p>For security teams: This type of repeatable controlled assessment from Armadin gives you the tools and confidence to identify truly exploitable risk across your environment.</p><p>Learn how at http://hyperattack.AI.<br><br>RESOURCES&nbsp;<br>Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-4-worlds-largest-controlled-hyperattack&nbsp;<br>Armadin Offensive Security Platform: <a href="https://armadin.com/platform" target="_blank" rel="noopener noreferrer">https://armadin.com/platform</a>&nbsp;<br>Request a Demo: <a href="https://www.armadin.com/request-a-demo" target="_blank" rel="noopener noreferrer">https://www.armadin.com/request-a-demo</a></p><p>CONNECT WITH ARMADIN&nbsp;<br>Website: <a href="https://armadin.com" target="_blank" rel="noopener noreferrer">https://armadin.com</a>&nbsp;<br>LinkedIn: <a href="https://www.linkedin.com/company/armadin" target="_blank" rel="noopener noreferrer">https://www.linkedin.com/company/armadin</a>&nbsp;<br>Twitter/X: <a href="https://x.com/armadinsecurity" target="_blank" rel="noopener noreferrer">https://x.com/armadinsecurity</a></p>
]]></content:encoded>
      <enclosure length="18071438" type="audio/mpeg" url="https://cdn.simplecast.com/media/audio/transcoded/5a6066af-e9ad-469a-ba68-2ad389ab2446/f878096c-b42a-41f8-86df-982c82b02d0b/episodes/audio/group/153d7244-5e7b-43ac-9676-f63cf38f7c4c/group-item/2ae70f57-270c-4319-8094-c190f6a81772/128_default_tc.mp3?aid=rss_feed&amp;feed=o0rdTWqv"/>
      <itunes:title>World’s Largest Controlled Hyperattack | Kill Chains and Coffee</itunes:title>
      <itunes:author>Greg Heon, Christian Elston</itunes:author>
      <itunes:duration>00:18:49</itunes:duration>
      <itunes:summary>What’s worse: Getting an RCE dropped on you at 5 pm on a Friday or waking up on Monday with 12 RCEs sitting in your inbox?

Find out what our experts think on this episode of “Kill Chains and Coffee.” Host Greg Heon sits down with Armadin Offensive Security Manager Christian Elston to cover two kill chains: Armadin’s first-ever AI Hyperattack and the world’s largest controlled AI Hyperattack.

Key conversations include:
The growing power behind AI agents attacking organizations from the outside in
Why safety and control are so critical in the wake of the HuggingFace incident and similar attacks.

In the first kill chain, Armadin engaged with a Fortune 600 company, launching 100 simultaneous attacks with thousands of agents—nearly 1 million autonomous actions.

The agents discovered 12 endpoints vulnerable to unauthenticated Remote Code Execution (RCE) from the internet through Server-Side Request Forgery (SSRF). A combination of SRRF and a known CVE led to an overly permissive Kubernetes service. The agents ultimately escaped the Kubernetes pod and compromised the organization’s entire cloud infrastructure.

The second kill chain was the world’s largest controlled cyberattack, conducted for an Armadin client with globally critical infrastructure. The attack targeted over 25,000 services and executed millions of autonomous actions. The resulting report generated over 200 findings with nearly 40 validated kill chains, including exposure to the company’s crown jewels.

For security teams: This type of repeatable controlled assessment from Armadin gives you the tools and confidence to identify truly exploitable risk across your environment.

Learn how at http://hyperattack.AI.</itunes:summary>
      <itunes:subtitle>What’s worse: Getting an RCE dropped on you at 5 pm on a Friday or waking up on Monday with 12 RCEs sitting in your inbox?

Find out what our experts think on this episode of “Kill Chains and Coffee.” Host Greg Heon sits down with Armadin Offensive Security Manager Christian Elston to cover two kill chains: Armadin’s first-ever AI Hyperattack and the world’s largest controlled AI Hyperattack.

Key conversations include:
The growing power behind AI agents attacking organizations from the outside in
Why safety and control are so critical in the wake of the HuggingFace incident and similar attacks.

In the first kill chain, Armadin engaged with a Fortune 600 company, launching 100 simultaneous attacks with thousands of agents—nearly 1 million autonomous actions.

The agents discovered 12 endpoints vulnerable to unauthenticated Remote Code Execution (RCE) from the internet through Server-Side Request Forgery (SSRF). A combination of SRRF and a known CVE led to an overly permissive Kubernetes service. The agents ultimately escaped the Kubernetes pod and compromised the organization’s entire cloud infrastructure.

The second kill chain was the world’s largest controlled cyberattack, conducted for an Armadin client with globally critical infrastructure. The attack targeted over 25,000 services and executed millions of autonomous actions. The resulting report generated over 200 findings with nearly 40 validated kill chains, including exposure to the company’s crown jewels.

For security teams: This type of repeatable controlled assessment from Armadin gives you the tools and confidence to identify truly exploitable risk across your environment.

Learn how at http://hyperattack.AI.</itunes:subtitle>
      <itunes:keywords>ai security, red teaming, ai hyperattack, remote code execution, rce, kubernetes pod escape, kill chain, world&apos;s largest cyberattack, armadin, cve exploitation, autonomous cyberattacks, continuous assessment, server-side request forgery, critical infrastructure, kubernetes security, offensive security, fortune 600 security, huggingface incident, ai agents, cloud infrastructure security, machine-speed attacks, ssrf</itunes:keywords>
      <itunes:explicit>false</itunes:explicit>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>2</itunes:episode>
    </item>
    <item>
      <guid isPermaLink="false">824c4225-9f11-4f55-9d97-ea1577c21b61</guid>
      <title>Cloud Compromise &amp; OT Reachability | Kill Chains and Coffee</title>
      <description><![CDATA[<p>Discover how low-priority vulnerabilities turn into complete kill chains in the AI era.</p><p>In this episode of “Kill Chains and Coffee," Armadin Founder and Chief Offensive Security Officer Evan Peña joins host Greg Heon to discuss two kill chains Armadin recently discovered.</p><p>Kill chain 1 progressed from SSRF to API remote code execution (RCE) to Kubernetes and the cloud. Kill chain 2 went from an assumed breach to an operational technology (OT) environment.</p><p>The kill chain 1 entry point was unauthenticated SSRF via a manipulated HTTP header. The SSRF chained to API RCE, landing the Armadin attacker in a Kubernetes pod. Reconnaissance on the pod revealed a local database with service account credentials stored in clear text.</p><p>The attacker used a privileged container to mount the host OS and break out of the pod—accessing an AWS tenant, additional pods, cloud accounts, and production data. Key takeaway: SSRF alone looked like a low-priority issue, but the full kill chain revealed production data exposure.</p><p>Kill chain 2 started with a low-privileged domain account on a Windows Server 2019 host, where the Armadin attacker gained access through a 5-year-old critical CVE (Print Nightmare). The payload was delivered via a Microsoft Defender AV exclusion folder configured for a third-party security tool. The attacker then found a local building management system (BMS) database, where it accessed sensor data, OT network views, and multiple protocols.</p><p>The customer had run annual penetration tests for a decade but had never surfaced the OT issue. The AI-powered Armadin attacker had the scale and speed to cover the entire attack surface: all paths in, all the time.</p><p>For security teams: This type of repeatable controlled assessment gives you the tools and confidence to identify truly exploitable risk across your environment.<br><br>RESOURCES&nbsp;<br>Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-3-ssrf-to-api-rce&nbsp;<br>Armadin Offensive Security Platform: <a href="https://armadin.com/platform" target="_blank" rel="noopener noreferrer">https://armadin.com/platform</a>&nbsp;<br>Request a Demo: <a href="https://www.armadin.com/request-a-demo" target="_blank" rel="noopener noreferrer">https://www.armadin.com/request-a-demo</a>&nbsp;<br><br>CONNECT WITH ARMADIN&nbsp;<br>Website: <a href="https://armadin.com" target="_blank" rel="noopener noreferrer">https://armadin.com</a>&nbsp;<br>LinkedIn:&nbsp;<a href="https://www.linkedin.com/company/armadin" target="_blank" rel="noopener noreferrer"> &nbsp;/&nbsp;armadin&nbsp; </a>&nbsp;<br>Twitter/X: <a href="https://x.com/armadinsecurity" target="_blank" rel="noopener noreferrer">https://x.com/armadinsecurity</a></p>
]]></description>
      <pubDate>Thu, 24 Sep 2026 16:51:59 +0000</pubDate>
      <author>helena.davis@armadin.com (Greg Heon, Evan Peña)</author>
      <link>https://kill-chains-and-coffee.simplecast.com/episodes/cloud-compromise-ot-reachability-kill-chains-and-coffee-Jokp964i</link>
      <media:thumbnail height="720" url="https://image.simplecastcdn.com/images/ad624afe-5838-4c7a-b2cb-f92d99708994/13acbaa9-5baf-4ed9-9fa8-f44a9c9f907d/killchainsandcoffeeep3coveruse_this.jpg" width="1280"/>
      <content:encoded><![CDATA[<p>Discover how low-priority vulnerabilities turn into complete kill chains in the AI era.</p><p>In this episode of “Kill Chains and Coffee," Armadin Founder and Chief Offensive Security Officer Evan Peña joins host Greg Heon to discuss two kill chains Armadin recently discovered.</p><p>Kill chain 1 progressed from SSRF to API remote code execution (RCE) to Kubernetes and the cloud. Kill chain 2 went from an assumed breach to an operational technology (OT) environment.</p><p>The kill chain 1 entry point was unauthenticated SSRF via a manipulated HTTP header. The SSRF chained to API RCE, landing the Armadin attacker in a Kubernetes pod. Reconnaissance on the pod revealed a local database with service account credentials stored in clear text.</p><p>The attacker used a privileged container to mount the host OS and break out of the pod—accessing an AWS tenant, additional pods, cloud accounts, and production data. Key takeaway: SSRF alone looked like a low-priority issue, but the full kill chain revealed production data exposure.</p><p>Kill chain 2 started with a low-privileged domain account on a Windows Server 2019 host, where the Armadin attacker gained access through a 5-year-old critical CVE (Print Nightmare). The payload was delivered via a Microsoft Defender AV exclusion folder configured for a third-party security tool. The attacker then found a local building management system (BMS) database, where it accessed sensor data, OT network views, and multiple protocols.</p><p>The customer had run annual penetration tests for a decade but had never surfaced the OT issue. The AI-powered Armadin attacker had the scale and speed to cover the entire attack surface: all paths in, all the time.</p><p>For security teams: This type of repeatable controlled assessment gives you the tools and confidence to identify truly exploitable risk across your environment.<br><br>RESOURCES&nbsp;<br>Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-3-ssrf-to-api-rce&nbsp;<br>Armadin Offensive Security Platform: <a href="https://armadin.com/platform" target="_blank" rel="noopener noreferrer">https://armadin.com/platform</a>&nbsp;<br>Request a Demo: <a href="https://www.armadin.com/request-a-demo" target="_blank" rel="noopener noreferrer">https://www.armadin.com/request-a-demo</a>&nbsp;<br><br>CONNECT WITH ARMADIN&nbsp;<br>Website: <a href="https://armadin.com" target="_blank" rel="noopener noreferrer">https://armadin.com</a>&nbsp;<br>LinkedIn:&nbsp;<a href="https://www.linkedin.com/company/armadin" target="_blank" rel="noopener noreferrer"> &nbsp;/&nbsp;armadin&nbsp; </a>&nbsp;<br>Twitter/X: <a href="https://x.com/armadinsecurity" target="_blank" rel="noopener noreferrer">https://x.com/armadinsecurity</a></p>
]]></content:encoded>
      <enclosure length="29914729" type="audio/mpeg" url="https://cdn.simplecast.com/media/audio/transcoded/5a6066af-e9ad-469a-ba68-2ad389ab2446/f878096c-b42a-41f8-86df-982c82b02d0b/episodes/audio/group/857246c0-244e-4063-98cd-cc8aad25a397/group-item/a90adb31-46d1-4572-a83c-607f0331dc93/128_default_tc.mp3?aid=rss_feed&amp;feed=o0rdTWqv"/>
      <itunes:title>Cloud Compromise &amp; OT Reachability | Kill Chains and Coffee</itunes:title>
      <itunes:author>Greg Heon, Evan Peña</itunes:author>
      <itunes:image href="https://image.simplecastcdn.com/images/ad624afe-5838-4c7a-b2cb-f92d99708994/2b8f2fd7-d12f-4d3b-8083-79c79b6d8455/3000x3000/cropped_1790260607415.jpg?aid=rss_feed"/>
      <itunes:duration>00:31:09</itunes:duration>
      <itunes:summary>Discover how low-priority vulnerabilities turn into complete kill chains in the AI era.

In this episode of “Kill Chains and Coffee,&quot; Armadin Founder and Chief Offensive Security Officer Evan Peña joins host Greg Heon to discuss two kill chains Armadin recently discovered.

Kill chain 1 progressed from SSRF to API remote code execution (RCE) to Kubernetes and the cloud. Kill chain 2 went from an assumed breach to an operational technology (OT) environment.

The kill chain 1 entry point was unauthenticated SSRF via a manipulated HTTP header. The SSRF chained to API RCE, landing the Armadin attacker in a Kubernetes pod. Reconnaissance on the pod revealed a local database with service account credentials stored in clear text.

The attacker used a privileged container to mount the host OS and break out of the pod—accessing an AWS tenant, additional pods, cloud accounts, and production data. Key takeaway: SSRF alone looked like a low-priority issue, but the full kill chain revealed production data exposure.

Kill chain 2 started with a low-privileged domain account on a Windows Server 2019 host, where the Armadin attacker gained access through a 5-year-old critical CVE (Print Nightmare). The payload was delivered via a Microsoft Defender AV exclusion folder configured for a third-party security tool. The attacker then found a local building management system (BMS) database, where it accessed sensor data, OT network views, and multiple protocols.

The customer had run annual penetration tests for a decade but had never surfaced the OT issue. The AI-powered Armadin attacker had the scale and speed to cover the entire attack surface: all paths in, all the time.

For security teams: This type of repeatable controlled assessment gives you the tools and confidence to identify truly exploitable risk across your environment.</itunes:summary>
      <itunes:subtitle>Discover how low-priority vulnerabilities turn into complete kill chains in the AI era.

In this episode of “Kill Chains and Coffee,&quot; Armadin Founder and Chief Offensive Security Officer Evan Peña joins host Greg Heon to discuss two kill chains Armadin recently discovered.

Kill chain 1 progressed from SSRF to API remote code execution (RCE) to Kubernetes and the cloud. Kill chain 2 went from an assumed breach to an operational technology (OT) environment.

The kill chain 1 entry point was unauthenticated SSRF via a manipulated HTTP header. The SSRF chained to API RCE, landing the Armadin attacker in a Kubernetes pod. Reconnaissance on the pod revealed a local database with service account credentials stored in clear text.

The attacker used a privileged container to mount the host OS and break out of the pod—accessing an AWS tenant, additional pods, cloud accounts, and production data. Key takeaway: SSRF alone looked like a low-priority issue, but the full kill chain revealed production data exposure.

Kill chain 2 started with a low-privileged domain account on a Windows Server 2019 host, where the Armadin attacker gained access through a 5-year-old critical CVE (Print Nightmare). The payload was delivered via a Microsoft Defender AV exclusion folder configured for a third-party security tool. The attacker then found a local building management system (BMS) database, where it accessed sensor data, OT network views, and multiple protocols.

The customer had run annual penetration tests for a decade but had never surfaced the OT issue. The AI-powered Armadin attacker had the scale and speed to cover the entire attack surface: all paths in, all the time.

For security teams: This type of repeatable controlled assessment gives you the tools and confidence to identify truly exploitable risk across your environment.</itunes:subtitle>
      <itunes:keywords>red teaming, cloud security, remote code execution, kill chains, armadin, artificial intelligence, kubernetes security, offensive security, ai, ai in cybersecurity, api security, cyber security, penetration testing, cybersecurity</itunes:keywords>
      <itunes:explicit>false</itunes:explicit>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:episode>1</itunes:episode>
    </item>
  </channel>
</rss>