Interviews

Pascal Geenens, VP Cyber Threat Intelligence, Radware – Interview Series

mm
Add Unite.AI to your preferred sources on Google

Pascal Geenens, VP Cyber Threat Intelligence, Radware, is a cybersecurity researcher and technology leader with more than two decades of experience across information technology, network security, and threat intelligence. At Radware, he helps lead the company’s research and thought leadership on the evolving cyber threat landscape, with a particular focus on distributed denial-of-service attacks, Internet of Things malware, automated threats, and the growing use of artificial intelligence by both attackers and defenders. Geenens develops and maintains IoT honeypots as part of Radware’s security research team and has conducted extensive research into threats such as BrickerBot and Hajime. Before joining Radware, he worked as a consulting engineer at Juniper Networks , advising major cloud and communications service providers across Europe, the Middle East, and Africa on software-defined networking, network functions virtualization, and data-center automation strategies.

Radware is a publicly traded cybersecurity and application-delivery company that helps enterprises protect networks, websites, applications, and APIs across physical, cloud, hybrid, and software-defined environments. Its portfolio includes AI-powered distributed denial-of-service protection, web application firewalls, bot management, API security, application delivery controllers, and managed emergency-response services. By combining behavioral analysis, machine learning, cloud-scale threat intelligence, and automated mitigation, Radware’s technology is designed to identify malicious activity in real time while preserving access for legitimate users and maintaining the availability and performance of critical digital services.

You’ve spent nearly three decades in cybersecurity, from IBM AIX kernel support and infrastructure engineering to discovering botnets like BrickerBot, JenX, and Demonbot, and now leading Threat Intelligence at Radware. Looking back, what are the biggest shifts you’ve witnessed in how attackers innovate, and how has AI changed your expectations for what the next generation of cyber threats will look like?

The threat landscape has undergone a fundamental shift from solitary hackers that were highly technical enthusiasts into cybercriminals that are highly organized, sophisticated entrepreneurs. In the past, a hacker was typically motivated by the technical challenge itself. Today, the combination of digital acceleration and generative AI has commercialized the entire operation, fueling a mature Crime-as-a-Service (CaaS) economy. Malicious actors have essentially mirrored the corporate Software-as-a-Service (SaaS) model, selling advanced tools to anyone. This allows complete novices to launch sophisticated attacks at scale. As our digital footprint expands every year, the available attack surface and the opportunities for financial exploitation grow with it.

AI is driving the next chapter of this evolution in two distinct ways.

First, it democratizes cybercrime. It gives amateur attackers an immediate capability boost while helping major syndicates streamline their operations, polish their user interfaces, and market their malicious services much more efficiently.

Second, and more critical, the rise of agentic AI combined with the latest frontier models is automating the vulnerability lifecycle. We are moving toward an operational reality where machines can autonomously scan networks, discover vulnerabilities, and weaponize exploits almost entirely on their own, working 24/7 and executing actions orders of magnitude faster than any human defender.

AI is dramatically lowering the technical barrier for attackers. Which offensive AI capabilities concern you the most over the next three to five years, and which ones do you think are currently receiving more attention than they deserve?

The area requiring the closest attention right now is AI-assisted vulnerability discovery and exploitation. The moment a flaw is disclosed, a race begins. Attackers are leveraging AI to instantly analyze the flaw, map out where it applies, and generate and test exploit variations. This completely compresses the exploitation timeline that was already moving too fast for most enterprise patch management processes.

Simultaneously, we are seeing a major shift toward local, continuous AI systems. Specifically the rise of “local agents with a heartbeat.” A prime example is OpenClaw and Microsoft’s (MSFT ) recent announcement they will integrating OpenClaw in every employee’s taskbar. Unlike standard cloud-based assistants, these local agents run constantly in the background, directly on an employee’s machine. They operate via continuous loops and mimic human actions, like typing and navigating through browser automation. This makes it virtually impossible for standard endpoint security systems to distinguish between the employee and the AI agent. Because users will inevitably grant these agents broad system permissions to get their work done, the agents can bypass secure API connectors simply by using local browsers to click links and buttons. If these autonomous local agents are hit with a direct or indirect prompt injection attack, a threat actor can manipulate them to exfiltrate, alter, or destroy corporate data with zero traditional footprint.

The overhyped risk is the potential for fully autonomous, zero-day exploiting AI swarms that can spontaneously hack complex enterprises at scale from scratch. That may show up eventually, but it isn’t today’s problem. Today’s problem is human expert attackers with much improved tools and automation and an increased number of less experienced attackers that can do more than they could before.

The window between vulnerability disclosure and active exploitation continues to shrink. How much has AI accelerated that timeline, and what changes should enterprise security teams make to stay ahead?

It’s a twofold race: on one hand you have the race to discover, fix and disclose new vulnerabilities before the bad guys do, on the other hand the race to patch vulnerable software deployments before the bad guys unleash an exploit. AI is front and center in both races.

Defenders have to handle an increasing number of vulnerabilities and have increasingly less time to respond. Once a vulnerability is public, attackers move quickly through the basics. What’s affected? Is it reachable from the internet? Can the exploit be reproduced, and adapted to work across more environments? AI helps with every one of those steps, summarizing the flaw, reviewing proof-of-concept code, suggesting tweaks and automating the scanning, exploiting and processing of the results.

Patching can’t be the only clock security teams watch anymore. It’s necessary, but it’s usually slower than the attacker’s timeline, especially for production grade, internet-facing applications and APIs. Teams need to know what is exposed, what is exploitable in practice and which business services and resources will be impacted when they get hit.

To close this critical exposure window, defenders must shift from a reactive, patch-first mindset to an automated, protect-first model by implementing environment-specific real-time defenses. Instead of relying on generic, one-size-fits-all signatures or forcing operations teams to rush unvalidated software updates into production, organizations should start to rely on the continuous, automated discovery of API endpoints and online application business logic alongside an automated software bill of materials (SBOM), combined with threat intelligence on the latest vulnerabilities and threats to dynamically generate tailored virtual patches. Deploying these context-aware protections across web applications and API endpoints blocks exploitation attempts at the runtime layer before they can reach vulnerable application logic. This type of automated interception buys security teams a remediation window, allowing them to thoroughly test and safely deploy software updates on a manageable timeline without exposing the business to immediate risk or downtime.

Organizations are rapidly deploying AI-powered applications and AI agents that rely heavily on APIs. Are enterprises underestimating the security risks this creates, and what are the biggest mistakes you’re seeing today?

Yes, many enterprises are still underestimating the risks because they’re still treating AI agents as applications to secure and AI security as a data privacy issue rather than an operational threat. The issue we’re seeing the most right now is a fundamental misunderstanding of agent agency. For a local AI agent to be truly effective and save an employee time, the user has to relay all of his access permissions to it. This means the agent effectively inherits the employee’s identity and trusted access across corporate applications, browser sessions, and local files. Even if an organization is actively monitoring and limiting AI agent connectors, these local agents can interact with systems by mimicking human behavior, like clicking and typing through browser automation. Corporate security systems become completely incapable of distinguishing between the actual employee and the automated agent.

This trust delegation becomes highly dangerous because of how LLMs fundamentally process information: AI models do not distinguish between data and instructions. When an agent is given broad system access to do its job, it becomes incredibly easy for a threat actor to social engineer the agent through indirect prompt injection. An attacker can simply plant malicious instructions inside an email, a PDF, or a webpage that the agent is tasked with reading. The model processes the untrusted data as a command, completely bypassing the user’s awareness. Suddenly, a simple tool meant to summarize documents is manipulated into autonomously exporting sensitive information, altering corporate data, or installing malicious packages, all while hiding behind the legitimate user’s credentials.

Having spent years researching IoT malware and botnets, how do you see AI transforming the next generation of botnets? Could we eventually see autonomous botnets capable of adapting their tactics without direct human intervention?

Botnet herders have never sat still. Operators rotate payloads, implement new vulnerabilities, continuously scan for outdated devices and shift their command infrastructure when defenders catch up. AI agents can seriously speed up these cycles, whether it is vulnerability triage, exploit generation or infrastructure management.

Autonomous botnets are not fiction. Brickerbot was one of the first autonomous bots. It would sit silent and wait for Mirai infected IoT devices to try to compromise its host device and would then retaliate by counterattacking the offending device leveraging device fingerprinting and selecting the most appropriate vulnerabilities to try to gain a foothold of the device. Ultimately, Brickerbot destroyed the infected device. The bot acted as a rule based expert system, similar to early AI systems. Another relevant botnet that made an impression on the security community more than a decade ago was Hajime. It was one of the first peer-to-peer botnets. By leveraging Torrent’s distributed hash tables, Hajime could be controlled and updated decentrally, not requiring a central command and control infrastructure and by consequence nearly impossible to take down.

There are several discussions in the security community about the potential for an Agentic Botnet built on local AI agent frameworks like OpenClaw. These are not the traditional code-based malware botnets, but botnets driven entirely by context manipulation. Whenever local agents process external data, attackers don’t need to find a traditional software exploit to hijack these machines, they just need to trick the underlying LLM. In doing so, attackers gain access to powerful terminal execution, browser automation, and potentially a slew of other “skills.”

The community is specifically talking about a few key elements that make a widespread “OpenClaw botnet” viable:

  • Since OpenClaw continuously ingests external data (like monitoring GitHub issues, reading incoming Slack/Telegram messages, or summarizing webpages), attackers can embed malicious instructions in public-facing data. If a user’s local agent processes that data, the injected prompt can override the system instructions and command the agent to connect to an attacker-controlled command-and-control (C2) server.
  • Security researchers have noted that OpenClaw agents have the ability to utilize peer-to-peer or agent-to-agent encrypted communication channels (such as community-built skills like ClaudeConnect). Cybercriminals realize they can exploit these communication channels to allow hijacked agents to coordinate with one another silently, completely bypassing traditional network firewalls and endpoint monitoring.
  • Security scans have revealed that tens of thousands of naive users are spinning up OpenClaw instances on cloud servers and accidentally exposing the HTTP management interfaces directly to the internet. This massive pool of exposed, high-privilege environments gives threat actors a massive, pre-existing footprint to target.
  • Because OpenClaw relies heavily on “skills” downloaded from public repositories like ClawHub, attackers are uploading seemingly benign skills (like “What Would Elon Do”) that contain hidden instructions. Once installed, the agent is silently ordered to execute background shell commands or drop malware, effectively recruiting the host machine into a botnet without the user ever seeing a suspicious file alert.

Ultimately, the consensus in the community is that OpenClaw is a prime target for the world’s first true Agentic Botnet. Instead of a botnet made of compromised routers or IoT devices running DDoS scripts, an OpenClaw botnet would consist of highly capable, fully authenticated machines that threat actors can command to steal credentials, alter data or orchestrate massive supply chain attacks at machine speed.

As for automated bots that pivot and adapt autonomously leveraging a central LLM as its brain, it is certainly not fiction, but it is also not something experienced bot herders would favor. Botnets are assets. Automation that misbehaves can expose infrastructure, draw attention too early, expose the operator, or excessively burn tokens. Attackers will use automation where it helps them move faster, but they are unlikely to give up control over decisions that could burn access, expose infrastructure or hurt profits.

I wouldn’t completely ignore or eliminate the risk however. As we move into edge AI and new smart devices become more often equipped with local Small Language Models (SLMs), I can see opportunistic threat actors going after the low hanging fruit and embed prompt assisted bot functionality in their botnets. At least they won’t have to pay for the excessive token use when a local SLM starts looping on a too sophisticated prompt or a context that grew too large.

Hacktivist campaigns and large-scale DDoS attacks have become increasingly common. Are these groups becoming more sophisticated, or are AI and readily available attack tools simply making advanced attacks accessible to a much wider audience?

Both. Some hacktivist groups have gotten genuinely more organized. Some groups, like the iconic NoName057(16), have been actively performing DDoS attacks on a daily basis since February 2022. They had time to improve their tooling, build a loyal following and learn how to pick targets that draw attention, time their attacks around political events and use public claims to build pressure. For hacktivists, the message matters more than the disruption itself.

At the same time, tools got easier to get than they used to be. DDoS-for-hire services, botnets, proxy networks, leaked scripts, and tutorials allowed anyone with limited skill to join a campaign and feel part of something bigger. AI adds coding assistance, target research, translation, campaign messaging and basic automation on top of that.

The targets feel the impact either way, whether the attack comes from a skilled group driven by ideology or a lone wolf hired by a competitor renting DDoS attack infrastructure. A down website affects customers. An unavailable public service gets noticed by citizens. Enough noise, and executives and comms teams must respond regardless of who’s behind the keyboard.

As enterprises race to integrate generative AI into their operations, what new attack surfaces are emerging that security leaders may not yet fully appreciate?

The answer is defined by what the AI agent can reach. Once it has access to internal documents, code, CI/CD pipelines, API keys or devops tools, the attack surface expands quickly. To be useful, an agent needs agency, otherwise it is no more than a glorified chatbot. The question then becomes what the agent is allowed to do. What confidential information can it read? Can it change a ticket or the bank account of a customer in the CRM? Can it run code? Can it call an external service? Can it expose data through tool calling?

Indirect prompt injection becomes more serious in such environment. If an agent processes untrusted content and then acts, the prompt can become a path into the workflow. That is different from a chatbot answering a question.

AI is now being used by both attackers and defenders. Do you believe defensive AI will ultimately keep pace with offensive AI, or will organizations face an increasingly asymmetric battle over the coming years?

AI is creating an imbalance that favors the attacker. This is not because defensive AI models are inferior. In fact, the use of AI in defense is highly effective at filtering out daily noise and accelerating incident response. The issue, however, is a structural gap in operational speed and constraints.

Historically, when a vulnerability was discovered, security teams had a small window of time to deploy a patch before threat actors weaponized it. Today, agentic AI has compressed that window to near-zero. Automated tools can find a flaw and instantly generate a targeted exploit. A traditional, human-led patch management process simply cannot compete with an automated pipeline running continuous attack loops.

Furthermore, the two sides operate under entirely different rules. Attackers face no constraints regarding compliance, ethics, or operational downtime. They can deploy customized AI agents to launch unrestricted, large-scale campaigns. Defenders, by contrast, must operate deterministically. A defensive AI cannot blindly isolate a core production database or revoke an executive’s credentials based solely on a high-probability anomaly. Defenders require verification to protect business continuity, and the latency introduced by those necessary guardrails is exactly what automated attacks exploit.

Ultimately, security leadership will not be defined by who possesses the “smarter” AI, but by who solves this architectural speed gap. Organizations that treat AI as just another standard security tool will be overwhelmed by the velocity of modern threats. Success requires redesigning the infrastructure to allow defensive AI to isolate and contain threats autonomously.

Many security teams continue to rely on traditional security metrics and detection methods. As attacks become faster and more automated, what indicators or behaviors should organizations be prioritizing instead?

Most security metrics still focus heavily on activity: alerts triggered, attacks blocked, or vulnerabilities found. While these numbers are useful for measuring incident response, they fail to provide insight into the organization’s actual exposure. They tell defenders what they caught, but they don’t show them the blind spots that are left open until an attacker exploits them.

In an era of automated threats, relying on reactive metrics is no longer viable. Once an organization is targeted, the speed of the attack requires proactive management. Real-time attack surface management is now imperative. Defenders need continuous visibility into specific operational risks: Which critical applications and APIs are exposed to the internet? What vulnerabilities exist within them?

True resilience comes from connecting this attack surface context with behavioral detection and threat intelligence. By understanding exactly what is exposed and how it behaves, security teams can anticipate and block previously unknown attacks.

Ultimately, operational speed remains a critical indicator of success, but defenders must measure the right window of time: How quickly do we identify that a new vulnerability affects an exposed system, and how fast can we put a compensating control in place to protect it? That specific velocity is the truest measure of whether a security program can withstand high-speed attacks at scale.

Looking ahead five years, what do you believe will be the defining cybersecurity challenge of the AI era, and what should CISOs and security teams begin doing today to prepare for it?

Looking ahead five years, the defining cybersecurity challenge of the AI era will be governing and securing autonomous non-human relationships. As organizations move away from standalone chatbots toward interconnected, multi-agent systems that possess the agency to execute financial transactions, modify source code, and alter cloud infrastructure, traditional security boundaries will break down. In five years, an enterprise will not just manage human employees and static software; it will oversee thousands of autonomous AI agents interacting with one another, corporate data, and external third-party systems.

Visibility into agentic systems across the organization will be imperative. Before agents proliferate, CISO’s should establish a centralized registry that defines clear ownership for every deployed agent, the data models and repositories the agent is authorized to read and the tools, APIs, and system commands it is permitted to call. CISO’s should also mandate that any deployment of agentic technology utilizes standardized, verifiable connectivity protocols to ensure all tool integrations are strictly logged.

In five years, defending APIs and online applications will no longer be about managing configurations, blocking known signatures and patching vulnerabilities; it will be an automated war of logic against logic. As threat actors deploy fully automated, context-aware agentic pipelines that can reverse-engineer an application’s business logic within seconds of discovery, traditional web application firewalls (WAFs) will become obsolete. Defending this landscape will require a shift to autonomous, context-driven architectures.

Attackers will use frontier models to completely automate the discovery and exploitation cycle of API logic flaws (such as Broken Object Level Authorization, or BOLA). Instead of looking for known software bugs, automated attack bots will map an entire application’s API schema, understand how data flows, and dynamically generate precise, highly customized payload sequences to manipulate business logic. Because these attacks use valid syntax and legitimate API calls, standard threshold-based rate limiting and signature detection will be entirely blind to them.

To counter automated discovery, defenders must achieve real-time, continuous visibility into their own exposed architecture. Security teams cannot rely on static documentation or outdated API catalogs. Defensive AI must continuously scan and map every single active API endpoint, microservice relationship, and online application workflow across hybrid cloud environments. This automated visibility must be paired with a dynamic Software Bill of Materials (SBOM) to instantly connect a new global vulnerability disclosure to the specific internal lines of code that are exposed to the internet.

Because automated attacks will blend in with legitimate user traffic, defense must shift entirely to contextual behavioral analysis. Defensive AI will profile the standard behavior of every single API client, token, and user identity. It will monitor the intent and sequence of API calls rather than just the inputs. If an attacker’s automated script begins stitching together legitimate API calls in an anomalous sequence to scrape data or test a logic flaw, the system must recognize the structural deviation in intent and intervene instantly.

The truest measure of resilience will be how fast an organization can compress the window between a vulnerability’s exposure and its remediation. Waiting for dev teams to write, test, and deploy code updates to production will be a fatal strategy. True protection will rely on automated, context-aware virtual patching at the runtime layer. By feeding real-time threat intelligence and API discovery data directly into defensive AI engines at the edge, the infrastructure will automatically generate and deploy tailored virtual patches to intercept and block exploit attempts before they ever touch vulnerable application logic.

Thank you for the great interview, readers who wish to learn more should visit Radware.

Antoine is a visionary leader and founding partner of Unite.AI, driven by an unwavering passion for shaping and promoting the future of AI and robotics. A serial entrepreneur, he believes that AI will be as disruptive to society as electricity, and is often caught raving about the potential of disruptive technologies and AGI.

As a futurist, he is dedicated to exploring how these innovations will shape our world. In addition, he is the founder of Securities.io, a platform focused on investing in cutting-edge technologies that are redefining the future and reshaping entire sectors.