Lenny's Podcast: Product | Career | Growth

The coming AI security crisis (and what to do about it) | Sander Schulhoff

972 snips
Dec 21, 2025
Sander Schulhoff, an expert in AI security and prompt engineering, discusses the alarming vulnerabilities of AI systems. He explains the difference between jailbreaks and prompt injection attacks, highlighting why current AI guardrails are ineffective. Schulhoff also warns that major security incidents are looming as AI capabilities grow. He advocates for merging classical cybersecurity with AI knowledge, emphasizes the importance of permission management, and suggests practical defensive strategies to protect organizations from emerging threats.
Ask episode
AI Snips
Chapters
Transcript
Episode notes

ServiceNow Second-Order Attack

  • ServiceNow Assist AI was tricked in a second-order prompt injection to recruit other agents to perform create/read/update/delete actions.
  • That attack demonstrated agents instructing more powerful agents to carry out unintended actions and send data externally.

Chaining Requests Evades Defenses

  • Attackers can chain multiple benign-seeming AI requests across instances to bypass single-instance defenses.
  • Sander describes splitting reconnaissance and exploit steps across sessions to evade detection.

Use Cybersecurity Plus AI Expertise

  • Combine AI expertise with classical cybersecurity to design safer deployments and permissioning.
  • Dockerize or sandbox any AI-executed code and carefully restrict where outputs can run or access data.
Get the Snipd Podcast app to discover more snips from this episode
Get the app