This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

The coming AI SaaS Security Apocalypse: Are You Ready?

Download resources

About this session

John Strand, owner of Black Hills Information Security, argues the AI SaaS apocalypse is already here: business staff with no development background, like paralegals or an intern named Bill, now 'code in English' by prompting tools such as Claude, N8N or OpenClaw to build internal applications outside IT's visibility, often hosted on outside providers such as DigitalOcean or Linode. He walks through live examples: pen testers using a chatbot's own natural-language interface to leak API keys by asking it where to find them, then how to bypass access control; a Shodan search using an N8N server's Base64-encoded version fingerprint that surfaced 209 internet-exposed systems vulnerable to remote code execution; and tens of thousands of exposed MCP servers found the same way. He cites a customer environment found hosting over two billion stolen records and thousands of unseen malware samples. Strand insists AI has not simplified either offense or defense, only escalated both, and that full autonomous AI pen testing is not real; his closing argument is that the field needs more entry-level hiring and stronger fundamentals, not less, to keep pace, pointing to his own free weekly training labs as one remedy.

In this session, John Strand explores how AI has already transformed offensive security, from modern penetration testing to highly automated attacks against APIs and SaaS environments. You’ll see how AI dramatically accelerates reconnaissance, vulnerability discovery, and exploitation, allowing attackers to move faster than ever before.

More importantly, you’ll learn what defenders can actually do about it. John will cover practical strategies for identifying shadow AI development, discovering unauthorized SaaS applications, understanding who is building what inside your organization, and reducing the risks created by AI-driven application development before attackers find them first.

If your security strategy still assumes software is built by trained developers and tested on predictable release cycles, you’re preparing for a world that no longer exists. The AI SaaS security apocalypse isn’t coming. It’s already here.

Key takeaways

  • Inventory who in the organization is building applications with AI coding tools outside IT's process; non-developers prompting chatbots into production apps is now routine, not an edge case.
  • Watch outbound network traffic for connections to consumer hosting providers such as DigitalOcean or Linode; that is where shadow AI-built apps carrying company data often end up.
  • Treat a chatbot's natural-language interface as an attack surface: a poorly scoped internal assistant can be talked into revealing credentials or access-control bypass steps just by being asked.
  • Do not trust vendor claims of fully autonomous AI penetration testing; effective offensive testing still needs a human interpreting context, prioritizing findings and proposing compensating controls.
  • Keep hiring and training entry-level security and development talent; core fundamentals in networking, Windows and Linux matter more, not less, once AI is generating the code you have to secure.

Speakers

John Strand
John Strand
Owner · Black Hills Information Security
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping… Read moreRead less

John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.

Resources

Photos

Tags

More from GoSec 2026

Also from John Strand

On the same topic