Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Day three of RSAC Conference 2025 focused on a security dilemma: teams are under pressure to do more with limited staff and budgets, while attackers can exploit a widening set of systems and move faster. Speakers described AI as a practical aid for vulnerability discovery and security workflows—but stressed that its value should be measured, not assumed.
What happened on day three of RSAC Conference 2025?
Day three of the conference in San Francisco brought together two connected concerns: how security teams can increase output with constrained resources, and how defenders must respond to attacks that reach beyond conventional endpoints. ITPro’s report on the day, published May 1, 2025, centered on remarks from security leaders, researchers and practitioners.
Kevin Mandia, founder of Ballistic Ventures and former Mandiant CEO, framed the pressure on security organizations: “If you have to operate doing more with less, the AI race is on.” The point was not simply that AI is a new technology to adopt. It was that organizations need to handle more security work without a matching increase in people or budget.
RSAC’s official 2025 release reported more than 43,500 attendees, 730 speakers, 450 sessions and 650 exhibitors. Those are conference-wide figures, not a count of day-three participants or presentations.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
How was AI helping security teams do more with less?
Speakers described AI as an accelerator for specific tasks—finding weaknesses, processing incidents and assessing suspicious files—rather than a replacement for security judgment. Google Threat Intelligence’s examples, presented by vice president Sandra Joyce, offered concrete measures of where the company said it was seeing value.
Finding vulnerabilities and improving fuzzing
Google’s Big Sleep project found an exploitable stack-buffer underflow in SQLite, according to Joyce’s presentation as reported by ITPro. The example shows AI being applied to vulnerability discovery in software, where a flaw can be examined and addressed before it is used in an attack.
Joyce also reported that LLM-assisted fuzzing increased coverage by as much as 7,000%. Fuzzing tests software with many inputs to uncover unexpected behavior; coverage describes how much of the code or behavior the tests reach. The figure was a maximum increase reported for Google’s work, not a general result guaranteed for other tools or projects.
Reducing incident and malware-analysis time
In Google’s internal use of Gemini, incident summaries were written 51% faster, Joyce said. She also described malware assessment taking 27 seconds in the tests she discussed. These examples concern particular internal workflows and tests; they do not establish that every incident or malware sample can be analyzed in those times.
Joyce cautioned security teams against accepting broad product claims without evidence: “Don’t just believe all of the AI claims being made in our industry. Go and actually test them against robust metrics.” Her advice was to prioritize applications with demonstrable value over the next six to 12 months.
Which attack techniques and targets did speakers highlight?
The day’s attack discussion widened the picture of what defenders need to protect. Speakers highlighted network infrastructure, identities and the speed at which attackers can use existing access.
Rank #3
Network equipment as a target
Cisco senior vice president and general manager Tom Gillis said switches, routers and firewalls themselves were being targeted in activity discussed as Volt Typhoon-related. “This year we saw attacks against a new attack surface. Switches, routers, and firewalls themselves are being attacked, and the goal of the attackers is not to steal credit card information.”
Gillis’s warning was that security teams should not treat these devices as background plumbing: they are part of the attack surface. His remarks did not identify every targeted device or establish that all activity of this kind had the same purpose.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteAuthorization sprawl and identity-based pivoting
SANS faculty fellow Joshua Wright described “authorization sprawl”: the reach that can accumulate when centralized authentication, single sign-on and tokens give identities access to numerous services and resources. If an attacker compromises an identity, those existing permissions and trust relationships can make it easier to move from the initial foothold to other parts of an organization.
Rank #4
Wright cited Scattered Spider as an example and emphasized how attackers can take advantage of ordinary access paths: “Their tactics aren’t that sophisticated. They use their initial access and then they use all the resources available to them to be able to pivot throughout the network. And the thing that’s so amazing about this is that their number one tool is just a browser.” The implication is that identity and authorization review matter alongside defenses aimed at malware or endpoint exploits.
AI-compressed attack timelines
Rob T. Lee, SANS chief of research, cited MIT research indicating that AI agent systems could execute attack sequences 47 times faster than human operators. That figure is a comparison Lee presented at RSAC; it is not a universal measurement of every AI-assisted attack. His warning was about the shrinking time defenders may have to detect, investigate and respond: “Speed is no longer the metric. It is the decisive weapon.”
Lee also said that 78% of raw security data may need sanitization before analysis, a process taking seven to 12 minutes. These figures describe the data-handling burden he raised at the conference, not a fixed timing for every organization. They illustrate how preparation and investigation can consume time even before an analyst begins interpreting the data.
Best Value
What should security teams take from the discussion?
The practical challenge is to capture AI’s speed without handing consequential decisions to systems that have not been validated. The examples point to a measured approach:
- Choose bounded, repetitive tasks. Vulnerability discovery, fuzzing, incident summarization and malware triage were the specific applications described as useful.
- Set a baseline and measure results. Compare accuracy, coverage, time saved and error rates against the existing workflow; a vendor claim alone is not proof of operational value.
- Protect sensitive data. Decide what security data can be submitted to an AI system, how it is sanitized, and what privacy safeguards apply.
- Keep human review for consequential actions. Analysts should validate important findings and response decisions, even when AI speeds up the work that supports them.
- Review access as well as devices. Network appliances need protection, while identities, tokens and accumulated permissions should be examined for unnecessary reach.
Joyce summarized the attacker-side concern separately: “Ultimately, attackers are using Gemini the way many of us are: as a productivity tool. They help to brainstorm or refine their work, that type of thing.” Her point was that AI can improve ordinary work for both sides; the defensive response is to understand its actual effects and test systems against robust metrics.
How does the 2025 discussion compare with RSAC 2026?
A later SANS retrospective on RSAC 2026 is a separate point of comparison, not a description of day three in 2025. It said all five attack techniques it highlighted had an AI dimension and discussed AI-generated zero days, software-supply-chain compromise and the complexity of operational technology (OT). SANS Technology Institute president Ed Skoudis put the shift bluntly: “We would be lying to you if we pointed out a trend in attacks that did not involve AI. That is just where we are in this industry.”
That later account suggests AI was becoming more deeply entangled with attack techniques. It does not change what the 2025 day-three report established: speakers then described particular AI-assisted defensive workflows alongside risks from infrastructure targeting, broad identity access and faster attack sequences.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

