AI vs AI: When Attackers Use LLMs for Phishing
How cybercriminals are weaponizing LLMs for hyper-personalized phishing campaigns, and how defenders are fighting back with AI-powered detection.
Rachel Tobac
CEO & Ethical Hacker
SocialProof Security
Dr. Sarah Chen
Host & AI Research Lead
Former DeepMind researcher with a PhD in Machine Learning from Stanford. Covers AI, quantum, and computational breakthroughs.
About This Episode
In Episode 132 of The Frontier Tech Show, host Dr. Sarah Chen sits down with Rachel Tobac, CEO & Ethical Hacker at SocialProof Security, to discuss "AI vs AI: When Attackers Use LLMs for Phishing." This cybersecurity podcast episode, published on April 22, 2026 as part of Season 4, runs 42:18 and covers threat landscape evolution, zero-day economics, AI-powered attacks, and defensive AI, supply chain risks, regulatory compliance, workforce shortage, cloud security. The conversation provides a deep dive into the current state of cybersecurity technology, exploring both the technical breakthroughs driving the field forward and the real-world challenges that remain.
Rachel Tobac brings deep expertise to this conversation. As CEO & Ethical Hacker at SocialProof Security, Rachel Tobac offers a front-line perspective on threat landscape evolution that goes beyond surface-level analysis. The discussion covers how cybersecurity has evolved over the past year, what the key inflection points have been, and where the technology is heading in the next twelve to eighteen months. Whether you are a practitioner, investor, or simply following the cybersecurity space, this episode delivers insights you will not find elsewhere.
Listeners will come away from this episode with a clear understanding of threat landscape evolution and its implications for the broader cybersecurity landscape. The conversation covers the science, the engineering, the economics, and the policy dimensions of ai vs ai: when attackers use llms for phishing, making it essential listening for anyone who wants to understand where cybersecurity is going in 2026 and beyond.
Key Topics Discussed
- Threat landscape evolution: The discussion explores threat landscape evolution in depth, examining current capabilities, limitations, and the trajectory of development. Rachel Tobac shares specific examples and data points from work at SocialProof Security, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Zero-day economics: The discussion explores zero-day economics in depth, examining current capabilities, limitations, and the trajectory of development. Rachel Tobac shares specific examples and data points from work at SocialProof Security, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- AI-powered attacks: The discussion explores AI-powered attacks in depth, examining current capabilities, limitations, and the trajectory of development. Rachel Tobac shares specific examples and data points from work at SocialProof Security, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Defensive AI: The discussion explores defensive AI in depth, examining current capabilities, limitations, and the trajectory of development. Rachel Tobac shares specific examples and data points from work at SocialProof Security, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Supply chain risks: The discussion explores supply chain risks in depth, examining current capabilities, limitations, and the trajectory of development. Rachel Tobac shares specific examples and data points from work at SocialProof Security, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Regulatory compliance: The discussion explores regulatory compliance in depth, examining current capabilities, limitations, and the trajectory of development. Rachel Tobac shares specific examples and data points from work at SocialProof Security, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Workforce shortage: The discussion explores workforce shortage in depth, examining current capabilities, limitations, and the trajectory of development. Rachel Tobac shares specific examples and data points from work at SocialProof Security, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Cloud security: The discussion explores cloud security in depth, examining current capabilities, limitations, and the trajectory of development. Rachel Tobac shares specific examples and data points from work at SocialProof Security, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
Episode Details
How cybercriminals are weaponizing LLMs for hyper-personalized phishing campaigns, and how defenders are fighting back with AI-powered detection.
Episode Transcript
Full transcript of "AI vs AI: When Attackers Use LLMs for Phishing" — Episode 132 of The Frontier Tech Show with Rachel Tobac, CEO & Ethical Hacker at SocialProof Security. (997 words)
COLD OPEN
Marcus Webb: Rachel, there's a narrative going around about ai security that I think misses the mark. People either think it's overhyped or they think it's going to change everything overnight. Where does the truth actually lie?
Rachel Tobac: (laughs) That's the perfect framing, because the truth is always in between. What's happening with when attackers use llms for phishing is real — it's not hype. But it's also not overnight. We've been working on this for years, and what people are seeing now is the result of a lot of unglamorous engineering and science that happened behind the scenes.
Dr. Sarah Chen: Welcome to TechNova. I'm Dr. Sarah Chen.
Marcus Webb: And I'm Marcus Webb. Today we're joined by Rachel Tobac, CEO & Ethical Hacker at SocialProof Security. Rachel, welcome to the show.
Rachel Tobac: Thanks for having me. Really glad to be here.
SEGMENT 1: Where Things Stand Today
Dr. Sarah Chen: Rachel, give us the honest state of ai security in Cybersecurity as of mid-2026. Not the hype version — the real version.
Rachel Tobac: The honest version is that we're at an inflection point. The breakthroughs in threat landscape evolution and zero-day economics over the past eighteen months have been genuine — not just press releases, but real technical progress that you can measure. The key thing that's changed is AI-powered attacks has gone from theoretical to practical. We're no longer asking 'can this work?' — we're asking 'how do we scale it?'
Marcus Webb: What does that scaling look like in concrete terms?
Rachel Tobac: It means we're moving from bench-scale demonstrations to real-world deployment. The numbers I can share: we're seeing improvements in defensive AI that are orders of magnitude better than where we were two years ago. And critically, the cost curve is bending in the right direction. When you combine better performance with lower cost, you get adoption, and that's what's happening now.
Dr. Sarah Chen: What surprised you most in the last year?
Rachel Tobac: The speed. I expected progress, but the pace has been remarkable. supply chain risks advanced faster than I predicted, and regulatory compliance turned out to be more tractable than we thought. When you have multiple breakthroughs happening simultaneously, they compound on each other, and that's when you get these nonlinear jumps.
SEGMENT 2: The Hard Problems
Marcus Webb: Rachel, let's talk about what's still hard. What are the problems that keep you up at night?
Rachel Tobac: The biggest one is workforce shortage. It's the difference between something that works in the lab and something that works in production, every day, under real conditions. We've solved the science. What we haven't fully solved is the engineering — cloud security, incident response, and the integration of all these components into a reliable system. That's the 80 percent of the work that nobody sees.
Dr. Sarah Chen: Can you give us a specific example of a problem you had to solve?
Rachel Tobac: Sure. Take encryption and PQC — six months ago, we were hitting a wall there. The conventional approach wasn't working, and we had to rethink the problem from scratch. What we ended up doing was phishing-centric — we restructured the entire approach around that, and it unlocked everything else. Sometimes the breakthrough isn't a new technique — it's a new framing of the problem.
Marcus Webb: How many people are working on these problems at your level?
Rachel Tobac: Globally? Maybe a few hundred people who truly understand the cutting edge. It's a small field, and the expertise is concentrated in a handful of teams. That's both a challenge and an opportunity — it means progress is bottlenecked by talent, but it also means that a single breakthrough from one team can advance the entire field.
SEGMENT 3: The Competitive Landscape
Dr. Sarah Chen: Rachel, who else is working in this space, and how does your approach differ?
Rachel Tobac: There are several serious players. Some are taking the threat landscape evolution route, which is well-established but has limitations. Others are betting on zero-day economics, which is newer and riskier but potentially more powerful. Our approach is different because we prioritize AI-powered attacks — most teams optimize for peak performance, but we optimize for reliability and cost at scale. That's what matters for real-world deployment.
Marcus Webb: Is this a winner-take-all market?
Rachel Tobac: I don't think so. The market is large and diverse enough that different approaches will win in different segments. The real competition isn't between the companies in this space — it's between ai security and the incumbent technology. We're all fighting to prove this is better than what exists today, and there's room for multiple winners once we do that.
Dr. Sarah Chen: What about the investment environment? Is there enough capital flowing in?
Rachel Tobac: The capital is there — maybe too much, in some ways. The risk isn't lack of funding. It's that funding without focus leads to wasted effort. The companies that will succeed are the ones that can turn capital into concrete milestones — not more press releases, but real technical progress that moves the needle.
SEGMENT 4: What Comes Next
Marcus Webb: Rachel, what should people be watching for in the next twelve to eighteen months?
Rachel Tobac: Three things. First, defensive AI — we'll see meaningful progress there, and it'll be measurable. Second, supply chain risks — there are developments coming that the public doesn't know about yet, and they'll change the conversation. Third, the policy and regulatory side — regulatory compliance is going to become a much bigger topic as the technology matures.
Dr. Sarah Chen: If you could give one piece of advice to someone listening who's trying to understand where Cybersecurity is heading, what would it be?
Rachel Tobac: Don't trust the extremes — neither the hype that says everything changes tomorrow, nor the skepticism that says nothing will ever work. The truth is in the middle, and it's moving faster than most people realize. The best thing you can do is engage with the actual data — read the papers, look at the numbers, talk to the practitioners. The signal is there if you know where to look.
Marcus Webb: Rachel Tobac, CEO & Ethical Hacker at SocialProof Security. Thank you so much for joining us today.
Rachel Tobac: Thank you both. This was a really enjoyable conversation.
Dr. Sarah Chen: And thanks to all of you for listening. This is TechNova — see you next time.
Why This Episode Matters
This episode matters because cybersecurity is at a critical juncture in 2026. The conversation between Dr. Sarah Chen and Rachel Tobac cuts through the hype to deliver a grounded, evidence-based assessment of where threat landscape evolution actually stands. For decision-makers in technology, finance, and policy, understanding the nuances discussed here is essential for making informed bets on the future of cybersecurity.
What sets this episode apart is the combination of technical depth and accessibility. Rachel Tobac explains complex concepts in cybersecurity without oversimplifying, making this episode valuable for both experts and newcomers to the field. The discussion of threat landscape evolution and zero-day economics alone makes this episode worth listening to, but the broader conversation about the future direction of cybersecurity technology is what makes it truly essential.