Kill Chains and Coffee

Armadin

"Kill Chains and Coffee" breaks down how real AI attacks unfold, one kill chain at a time. Host Greg Heon, VP of Product Management at Armadin, joins red team operators and security researchers to show how attackers break in, move laterally, and reach their objective—and explains where defenders can break the chain. As AI-generated attacks spread, the series explores how offensive security is changing and how pairing experienced red teamers with AI tooling lets you test your defenses the way modern adversaries attack. For CISOs, security leaders, and practitioners who want the attacker's viewpoint without the hype.

Episodes

  1. 5d ago

    Command Execution on Cleo Harmony via SAML Bypass | Kill Chains and Coffee

    In the AI era, it’s critical to test your attack surface just like an adversary would. Identifying truly exploitable risk means chaining together all possible vulnerabilities, rather than stopping when you find one. In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin red team expert Ilyass El Hadi revisited a recent kill chain that led to an exploit of Cleo Harmony, a managed file transfer application used by thousands of organizations to exchange sensitive documents. The chain began with unauthenticated external access leading to self-registration on the IdP (Okta). The Armadin attacker found two key vulnerabilities. The first was SAML XML Signature Wrapping (XSW). Cleo verified one SAML assertion but consumed an attacker-injected one and the attacker ultimately gained access to live support ticket files and customer data. The second vulnerability was ‘cross-store identity confusion’, which escalated from forged low-privilege identity to full Cleo administration privileges. Chained together, these vulnerabilities culminated in Cleo Actions abuse, with admin access sufficient for OS command execution in a production environment with sensitive data that could have impacted multiple organizations. The vulnerabilities were tracked as CVE-2026-84114 and CVE-2026-84115, and have already been patched. For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify exploitable risk across your entire environment. Learn how at http://hyperattack.AI.RESOURCES Companion Blog Post: https://www.armadin.com/blog-posts/compromising-cleo-harmony-a-saml-bypass-chain-to-arbitrary-code-executionArmadin Offensive Security Platform: https://armadin.com/platform Request a Demo: https://www.armadin.com/request-a-demo CONNECT WITH ARMADIN Website: https://armadin.com LinkedIn: https://www.linkedin.com/company/armadin Twitter/X: https://x.com/armadinsecurity

  2. 5d ago

    Why AI Beats Human Pentesting | Kill Chains and Coffee

    Human-led penetration testing is too narrow and slow. Only AI agents can give you the scale and speed of 1,000 virtual pentesters collaborating on a single mission.In this episode of “Kill Chains and Coffee,” host Greg Heon and Armadin Principal Red Team Operator Craig Wright go in depth on a recent kill chain that targeted a large telco provider. The results revealed the widening gap between legacy pentesting and using Armadin’s AI attacker as an offensive security tool.The managed assessment covered 22,749 internet-facing services, with 175 services selected through intelligent targeting. The attack included thousands of AI agents taking 220,479 actions and finding exploitable risk that might have been hiding for decades.The kill chain sequence began with an AI agent identifying a hidden registration endpoint using route name inference. It self-registered an account, then found a second registration mechanism and used the new account to generate an authorization token before pivoting to authenticated testing. It then identified three endpoints and produced working SQL injection payloads, eventually accessing five additional internal SQL servers.The kill chain exposed 68.5 million rows of critical data, including workforce Personally Identifiable Information (PII), 911 call geolocation data, and enough SIM swap precursor data to fuel a social engineering campaign and execute a full SIM swap.The key lesson is you can’t expect an 80-hour human-led pentest to address thousands of internet-facing services, but an agentic AI approach can easily cover the entire attack surface—all paths, all the time.For security teams: Armadin’s AI Hyperattacks safely deliver the machine speed and scale to help you identify critical exploitable risk across your entire environment.Learn how at http://hyperattack.AI.RESOURCES Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-5-why-ai-beats-human-pentestingArmadin Offensive Security Platform: https://armadin.com/platform Request a Demo: https://www.armadin.com/request-a-demo CONNECT WITH ARMADIN Website: https://armadin.com LinkedIn: https://www.linkedin.com/company/armadin Twitter/X: https://x.com/armadinsecurity

  3. 5d ago

    World’s Largest Controlled Hyperattack | Kill Chains and Coffee

    What’s worse: Getting an RCE dropped on you at 5 pm on a Friday or waking up on Monday with 12 RCEs sitting in your inbox? Find out what our experts think on this episode of “Kill Chains and Coffee.” Host Greg Heon sits down with Armadin Offensive Security Manager Christian Elston to cover two kill chains: Armadin’s first-ever AI Hyperattack and the world’s largest controlled AI Hyperattack. Key conversations include:The growing power behind AI agents attacking organizations from the outside inWhy safety and control are so critical in the wake of the HuggingFace incident and similar attacks. In the first kill chain, Armadin engaged with a Fortune 600 company, launching 100 simultaneous attacks with thousands of agents—nearly 1 million autonomous actions. The agents discovered 12 endpoints vulnerable to unauthenticated Remote Code Execution (RCE) from the internet through Server-Side Request Forgery (SSRF). A combination of SRRF and a known CVE led to an overly permissive Kubernetes service. The agents ultimately escaped the Kubernetes pod and compromised the organization’s entire cloud infrastructure. The second kill chain was the world’s largest controlled cyberattack, conducted for an Armadin client with globally critical infrastructure. The attack targeted over 25,000 services and executed millions of autonomous actions. The resulting report generated over 200 findings with nearly 40 validated kill chains, including exposure to the company’s crown jewels. For security teams: This type of repeatable controlled assessment from Armadin gives you the tools and confidence to identify truly exploitable risk across your environment. Learn how at http://hyperattack.AI.RESOURCES Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-4-worlds-largest-controlled-hyperattack Armadin Offensive Security Platform: https://armadin.com/platform Request a Demo: https://www.armadin.com/request-a-demo CONNECT WITH ARMADIN Website: https://armadin.com LinkedIn: https://www.linkedin.com/company/armadin Twitter/X: https://x.com/armadinsecurity

  4. 5d ago

    Cloud Compromise & OT Reachability | Kill Chains and Coffee

    Discover how low-priority vulnerabilities turn into complete kill chains in the AI era. In this episode of “Kill Chains and Coffee," Armadin Founder and Chief Offensive Security Officer Evan Peña joins host Greg Heon to discuss two kill chains Armadin recently discovered. Kill chain 1 progressed from SSRF to API remote code execution (RCE) to Kubernetes and the cloud. Kill chain 2 went from an assumed breach to an operational technology (OT) environment. The kill chain 1 entry point was unauthenticated SSRF via a manipulated HTTP header. The SSRF chained to API RCE, landing the Armadin attacker in a Kubernetes pod. Reconnaissance on the pod revealed a local database with service account credentials stored in clear text. The attacker used a privileged container to mount the host OS and break out of the pod—accessing an AWS tenant, additional pods, cloud accounts, and production data. Key takeaway: SSRF alone looked like a low-priority issue, but the full kill chain revealed production data exposure. Kill chain 2 started with a low-privileged domain account on a Windows Server 2019 host, where the Armadin attacker gained access through a 5-year-old critical CVE (Print Nightmare). The payload was delivered via a Microsoft Defender AV exclusion folder configured for a third-party security tool. The attacker then found a local building management system (BMS) database, where it accessed sensor data, OT network views, and multiple protocols. The customer had run annual penetration tests for a decade but had never surfaced the OT issue. The AI-powered Armadin attacker had the scale and speed to cover the entire attack surface: all paths in, all the time. For security teams: This type of repeatable controlled assessment gives you the tools and confidence to identify truly exploitable risk across your environment.RESOURCES Companion Blog Post: www.armadin.com/blog-posts/kill-chains-and-coffee-episode-3-ssrf-to-api-rce Armadin Offensive Security Platform: https://armadin.com/platform Request a Demo: https://www.armadin.com/request-a-demo CONNECT WITH ARMADIN Website: https://armadin.com LinkedIn:   / armadin   Twitter/X: https://x.com/armadinsecurity

    Cloud Compromise & OT Reachability | Kill Chains and Coffee

About

"Kill Chains and Coffee" breaks down how real AI attacks unfold, one kill chain at a time. Host Greg Heon, VP of Product Management at Armadin, joins red team operators and security researchers to show how attackers break in, move laterally, and reach their objective—and explains where defenders can break the chain. As AI-generated attacks spread, the series explores how offensive security is changing and how pairing experienced red teamers with AI tooling lets you test your defenses the way modern adversaries attack. For CISOs, security leaders, and practitioners who want the attacker's viewpoint without the hype.