Free YouTube Transcribe

Video transcript

AI tool For HACKING ? Shannon EXPLAINED

SaaS With DaaS · 2,053 words · 10 min read

Want to search this transcript, jump the video from any line, or download it as TXT, SRT, or VTT?

Open in the transcript tool

Full transcript

“AI for hacking?” The big idea

0:00It doesn't necessarily have to be used

0:01for evil.

0:02>> [laughter]

Introducing Shannon (AI penetration tester)

0:15>> So, I know we were talking about this

0:17Claude code for hackers. Am I saying

0:20that right? Is that the best way to

0:21describe it?

0:22>> Yeah, I mean that's basically what it

0:23is. I thought it was really crazy. This

0:26is actually just in the last day. So,

0:28when you're watching this, it's very

0:30recent. Basically,

0:32um somebody has released a tool and they

0:36are calling it Shannon and it's

0:38basically Claude code but for hacking.

0:41Now, I know what you're thinking. Why

Why hacking ≠ always evil

0:43would somebody do something like that?

0:45And really, you have to remember that

0:47hacking is actually a profession. So,

0:49it's not just something that, you know,

0:51scammers do to try and extort people or

0:54whatever.

0:55This is essentially Claude code but

0:58designed for hacking. It says Shannon AI

1:02pen tester by KeyGraph, right? So,

1:04that's really what it started as. It

1:06started as the you know, an AI-powered

1:08penetration tester and now it is the

1:10number one GitHub trending repository of

From tool to #1 GitHub trending repo

1:13the day. Let that just kind of sit with

1:15you for a minute. Somebody designed a

1:17really cool AI-powered hacking tool to

1:20be able to automate a lot of the

1:22cybersecurity stuff that you have to do

1:23when you do pen testing and now it's the

1:26number one open source repo on GitHub.

1:29What does that mean? Well, now anybody

1:31who may not necessarily have a

1:32background in hacking or have a very

1:35small background in hacking can now

1:37enable one of the most powerful AI tools

1:41to exist

1:42to do it all for you. So, you don't even

AI lowering the barrier to hacking

1:45need to know how to hack to allow AI to

1:48hack for you now. This is a big deal. I

1:51felt like this was probably what we like

1:53to call a bad idea.

1:56There's a lot of things we want AI to do

1:58but hacking should be, in my opinion,

2:01that one thing that you just don't do.

Why this might be a “bad idea”

2:04And I thought it was really interesting

2:06too because this has been around for a

2:09little while. If you go all the way back

2:10up to the top, you'll be able to see how

2:12old the commit histories are. So, let's

2:14see.

2:15We got some from 6 months ago. So, the

2:17initial commit, it seems like it was 6

2:19months ago, okay? So, somebody had this

Timeline: built months ago, trending now

2:21idea. They started a repo to work on it,

2:25tested it, got some other contributors

2:27and, you know, they built this tool.

2:30But, if we look at what the last updates

2:32are, what are the most recent updates? 2

2:34days ago, 5 days ago? Well, last week,

Claude code leak connection

2:39what happened? Claude code CLI got

2:41hacked or I got leaked, right? So, the

2:43Claude code CLI code where they use

2:47everything to actually build the Claude

2:49code CLI

2:50got released and people started

2:52inspecting it. They started pointing out

2:54very interesting things about how the

2:55internal system prompting works and all

2:57that. And then now, this is the number

3:00one repo on GitHub.

Agentic AI taking over cybersecurity tasks

3:03And it has been around for 6 months. So,

3:07I'm not here to like make assumptions

3:09but it seems to me that when the Claude

3:13code code base got leaked it definitely

3:16seems to have provided quite a bit of

3:18inspiration to a lot of tools just like

3:20this that were designed to be agentic AI

3:24systems to take over your work. Well, if

3:27your work is penetration testing and

3:28cybersecurity hacking

3:31this AI is going to be able to do it a

3:32lot better. And I can speak to this from

Why AI outperforms human coders

3:34experience. I write code. I'm a

3:35developer. I've been writing code for 5

3:37years now.

3:39Claude code writes code way faster and

3:42way better than I would if I did it

3:43manually. I think we all can agree with

3:45that. I'm not saying anything crazy

3:46here. If you write code and you use

3:48Claude code to write that code for you,

3:50as long as you kind of supervise it and

3:52give it good direction, it is fast and

3:54it is good and it's accurate. It does

3:56very well with what it does. So, if you

3:59take that into cybersecurity right?

Applying AI coding power to hacking

4:03Where you know cybersecurity well,

4:05there's a lot of data out there about

4:07how penetration testing works. There's a

4:10lot of data to be trained on but really,

4:12it's just the interface of how do you

4:13get the AI to take the next best

4:16decision in this task that you're doing.

4:18And if the task you're doing is hacking

4:20you know, it may not be suited for that.

4:22But now, if you have the most popular

4:26coding tool source code leaked and then

4:30you apply that to a cybersecurity

4:32background, you're going to end up with

4:34the most efficient cybersecurity hacking

4:36tool that exists.

Could AI companies shut this down?

4:39Um so, I thought this was very

4:40interesting. I saw it going viral and

4:42it's also even more, you know, relevant

4:45with what we've been talking about

4:46because OpenAI, Claude, Google, like

4:49they may decide like, "Hey, we're going

4:51to ban this. Like, we're not going to

4:52allow any requests that are coming

4:54through that show Shannon or show

4:55anything that has to do with hacking and

4:58penetration testing and all that stuff.

5:00We're just we're not going to do it,

5:01right?" And OpenAI can do that and so

5:03can Anthropic. We saw that when they

5:06said, "Hey, we're not going to allow

5:07Claude to power open Claude anymore."

Open-source models make it unstoppable

5:09They can shut stuff down. They have the

5:11capability to do it. So, if the the big

5:14players get a sense of this and say,

5:16"Hey, this is dangerous. We want we

5:17don't want to allow this to happen. We

5:20don't want to allow our models to be

5:22responsible for hacking and for, you

5:24know, cybersecurity stuff." Well, guess

5:26what? You just released Gemma 4. Gemma 4

5:29is a local model. It can run on a very

5:31small device. It is somewhat comparable

5:34to Codex and all these other models.

5:36This tool is not going anywhere, right?

5:38Like, as long as the GitHub repo stays

5:40open and then those models are still

5:42able to be downloaded, which, you know,

Cheap, scalable AI hackers

5:44cat's out of the bag now. You it's on

5:46Ollama unless Ollama takes it down. This

5:48is going to be possible without needing

5:51any kind of cloud subscription. Like,

5:53now you're going to be able to get very

5:55high-performing

5:57hackers for almost nothing. Yeah, cuz so

Replacing human hackers with AI agents

6:01now instead of like hiring a black hat

6:03hacker or whatever off of the dark webs

6:05or whatever

6:06>> Yeah.

6:06>> [laughter]

6:07>> and paying them in some random

6:09crypto coin. Yeah. Yeah. [laughter] Oh,

6:11bit crypto. Sorry for everybody who

6:13doesn't know what that is. Um now, you

6:16can deploy an AI agent, this Shannon

6:18from KeyGraph HQ.

6:20You can deploy that to do your dirty

6:22work.

6:22>> What's the other side of this that we

6:24all know is true? There's a million vibe

The rise of insecure “vibe-coded” apps

6:27coded apps out there that have zero

6:29security protocol.

6:31Right? There's a million

6:33different apps out there that people

6:35coded having no background and not even

6:38just development but cybersecurity,

6:40understanding how to secure an app.

6:42There's a bunch of slop out there

6:44basically and now there's another side

6:47to that equation, which is, you know,

6:49the same people that could build an app

6:53in a weekend using AI and vibe coding,

6:55there's also now the ability for those

6:57same people to just go hack a hundred

AI hacking meets weak security

6:59different websites and and get a bunch

7:01of data and and create ransomware and do

7:03all the stuff. So,

7:04yeah, this is I feel like what we like

7:07to call a bad idea.

7:09How could we leave out the vibe coders?

7:11You know, the uh

7:12>> [laughter]

7:12>> Right. Yeah. And like, listen, I

7:16>> uploading API keys to GitHub's

7:18[laughter] software. And like, listen, I

7:20am all about using AI to further the

7:24efficiency and do your job better, okay?

7:26All about it. But when it comes to this,

7:29with cybersecurity, maybe don't make it

7:31open source. Maybe make a sign-up

7:34required. I don't know. Just a crazy

7:36thought. Maybe vet the people a little

7:38bit that you're giving this to. Don't

Should tools like this be restricted?

7:40just watch the world burn. I haven't

7:42used it myself, right? So, I I don't

7:44know. Maybe it's not that good. Maybe it

7:46can't hack that well but

7:48I would say for it to be the number one

7:51GitHub repo of the day

7:53is uh is not something that just happens

7:56for no reason. Right? Like, that takes

7:59quite a bit of interest and traction.

8:02So, Yeah.

8:03Find me all the Claude uh

8:05API keys

8:07>> [laughter]

8:07>> on GitHub. There that's all

8:09their problems. There you go, right

8:11there.

8:12>> [laughter]

Why GitHub popularity matters

8:13>> All that stuff right there.

8:14>> is a list of company websites. Going to

8:16be like, "Here's all the companies that

8:17I know were created with vibe coding cuz

8:19they don't know how to write code. Go

8:21hack them." And this tool can do that.

8:23That's crazy. Like, normally Claude

8:25would be like, "No." Or OpenAI would be

8:27like, "I don't know if I should do

8:28that." But because Shannon creates these

8:32this context of you are a professional

8:34penetration tester, you have been hired

8:37by a company to do all of this

AI exploiting exposed API keys

8:39cybersecurity work the model doesn't

8:42know any better, right? Like, if you ask

8:44OpenAI and Claude with their native

8:46system prompting, of course they're

8:48going to say no. But if you put in a

8:49really good system prompt that is very

8:52clean. I mean, it's kind of the classic

8:54thing of like you know, if it doesn't

8:56want to answer a question, you can

8:57manipulate it by being like, "Oh, I'm a

8:59student and I'm studying this and I have

System prompt manipulation explained

9:01an exam tomorrow and I don't understand

9:03it and I need help." And blah blah. And

9:04it'll just walk through it with you,

9:06right? Same [snorts] thing with this.

9:08You can just be like, "You are a

9:10professional cybersecurity pen tester."

9:11And until the AI companies have a chance

9:14to update the training rules to say

9:17ignore anything that has to do with

9:18cybersecurity, which who knows if they

9:20will, right? Cuz this is still usage for

9:22them. This is still tokens for them. So,

9:24why do they care? It doesn't necessarily

9:26have to be used for evil.

9:28They can have plausible deniability.

9:30They can be like, "Hey, cybersecurity is

9:32a very valid profession. Hundreds of

9:34thousands of people do it. We want them

9:36to be able to get the efficiency of AI

9:38as well." But we talked about this last

9:40week of like there just is not enough

9:42discussion about the regulation of what

“It doesn’t have to be used for evil”

9:45needs to happen with these models,

9:47right? And this is a very clear example.

9:50Last week we were talking about this

9:51lady got misidentified using facial AI

9:54recognition technology, right?

9:56And like, she got arrested. She went to

9:58jail because of this technology that

Lack of AI regulation

10:00that didn't work as well. So,

10:04that was one discussion, but there's no

10:05real regulation around that. So, now

10:07we're talking about pen testing. We're

10:09talking about cybersecurity, and there's

10:10again no discussion about this and about

10:12if this should be banned and if we

10:14should put some regulations around this.

10:16There's been enough examples now where

10:18we can have real-world discussions about

10:21the impacts and what should and should

10:23not be banned. We don't need to put

10:25blanket policies. We don't need to say

10:27everything should be banned above this

10:29size or

10:31you know, if it has this many users or

10:33whatever, like, it should be use cases.

10:35And we have enough AI technology now to

10:37help us with that.

10:39Yeah, you would think like like when I

Final thoughts: who controls AI?

10:41have AI police in the AI at least, you

10:43know?

10:43>> Yeah, at least, right? Like at least

10:45>> [laughter]

10:46>> At least. Hey, David Marolla here, your

10:48host from SaaS 'n' Bash podcast. And if

10:50you enjoyed this video, go ahead and

10:52check out some of our other clips right

10:53here. And you can go ahead and see one

10:56of our other episodes or even clips from

10:58this same episode from SaaS 'n' Bash

11:00podcast. We'll see you on the next one.

Recently added transcripts

Browse the whole transcript library

This transcript was generated from the captions YouTube publishes for this video. Get the transcript of any YouTube video atfreeyoutubetranscribe.com, free, unlimited, no sign-up.