Meet the Review Board Series: Black Hat India’s First Call for Briefings

Black Hat India 2026

02 July 2026

Date: July 2, 2026
Event: Black Hat India 2026
Format: Podcast (~32 minutes)
Host: Swati Aruna (Frost & Sullivan)
Guests: Neelu Tripathy (Senior Security Architect, Adobe), Anant Shrivastava (Founder, Cyfinoid Research)

Overview

Ahead of Black Hat India’s inaugural edition in Bengaluru (October 2026), Swati Aruna sits down with two members of the Briefings Review Board β€” Neelu Tripathy and Anant Shrivastava β€” for a candid conversation on AI, India’s evolving cyber landscape, and what the board is looking for in Briefings submissions.

Key Topics

AI Generated Summary

AI Generated Content Disclaimer

Note: This summary is AI-generated and may contain inaccuracies, errors, or omissions. If you spot any issues, please contact the site owner for corrections. Errors or omissions are unintended.

Recorded as part of the Black Hat India podcast series ahead of the inaugural Black Hat India conference in Bengaluru (October 27–30, 2026), this ~32-minute discussion is moderated by Swati Aruna (Principal Consultant, ICT domain, Frost & Sullivan India) with two members of the Briefings Review Board: Neelu Tripathy (Senior Security Architect, Adobe) and Anant Shrivastava (Founder, Cyfinoid Research). Framed by a reported β‚Ή22,000 crore lost to cyber fraud in 2025 β€” digital arrest, investment scams, and AI-enabled fraud β€” the conversation covers where AI genuinely helps defenders, how it is accelerating attackers, why inventory remains the industry’s oldest unsolved problem, and what the review board wants to see in the first-ever Black Hat India Call for Briefings.

Summary

Swati opens by asking both board members where defenders will benefit from AI over the next three years. Neelu Tripathy argues that although AI is “in its infancy,” its core strength is pattern recognition β€” joining the dots across the enormous volume of logs security teams already collect, automating detection engineering and attack-path work, and enabling real-time threat-intel correlation.

Anant Shrivastava builds on this with two frames. First, acceleration: work that previously required a person of “higher than average intelligence” can now be done by average-intelligence people, because LLMs capture and distribute those patterns. Second, a concept he calls “rented cognition” β€” most of us are renting intelligence from a service provider β€” and his prescription is to keep that rented portion minimal, using LLMs to augment existing capability while moving intelligence from non-deterministic models into deterministic systems where defenders get true, repeatable power. Investigation, pattern matching, and triage are the areas he sees LLMs helping most, given the chronic shortage of security manpower.

Asked what has changed most for researchers in two years, Anant describes a development-culture shift: we have moved from being developers to being managers of developers, with software now routinely accepted if output merely “looks good enough” against a set of inputs rather than being verified as correct. On the attacker side, the reaction was simpler β€” “we got a new toy.” He points to the Shai-Hulud npm worm and a recent release by Myasnikov as examples of malware being open-sourced so others can trivially fork and improve it: older Shai-Hulud exfiltrated stolen content in plaintext (easy for defenders to track), while newer forks encrypt it β€” so defenders can no longer even see who is being attacked.

Neelu then lays out a three-layer prioritization for organizations over the next “very experimental” couple of years, noting that security follows the business and that a flood of fast-generated, not-necessarily-clean AI code is already arriving:

She closes that segment with the line that anchors the whole episode: “If you cannot see your attack surface, you cannot secure it” β€” and no AI can fix inventory without visibility. Real-time (if not yet Minority-Report-style proactive) detection is the realistic goal.

Asked about the biggest capability gap, Anant picks up Neelu’s one word β€” inventory. IT and IT security never had a proper inventory, and even when they have one, they don’t know what to do with it. He cites SBOM as the cautionary tale: the pushback comes mostly from developers β€” the very people who would benefit most β€” because the narrative reduced SBOMs to “finding bugs and vulnerable libraries,” creating negative sentiment. His broader prescription is attack-surface reduction: imagine 100 Node.js projects, each pulling ~10,000 dependencies, where 20,000 lines of third-party code are included to call five lines of one function. He even cites Halvar Flake, whose company cut organizations’ cloud bills by 50–90% and still failed because organizations weren’t interested β€” proof that the deeper fix is treating compute as a finite resource again. Cloud gave us the illusion of infinity (“click a button, add more RAM”), yet RAM and storage prices have risen 5–10x and even Google Workspace has capped its previously “unlimited” storage. Dependency reduction, he argues, follows naturally and shrinks the attack surface as a side effect.

Why Black Hat India, and Why Now

Advice for Briefings Submitters

What the Board Wants to See More Of

One Thing Every CISO, Researcher, and Practitioner Should Know

Key Takeaways