Risky Business Risky Business

Soap Box: HD Moore talks OT security, frontier fearmongering and more

Sep 29, 2026 · 34m

Summary

HD Moore discusses RunZero's recent acquisition by Accenture and its evolution into a critical OT/IT discovery platform. He details new capabilities for mapping non-IP industrial protocols like BACnet and Modbus, revealing vast hidden attack surfaces in enterprise environments. The conversation also covers the "vulnpocalypse," arguing that traditional CVE-based vulnerability management is obsolete in the AI era. Finally, Moore explains how RunZero integrated AI for secure, granular access control and automated integration building, drawing parallels to the Metasploit hype cycle.

Topics discussed

Intro: HD Moore, Metasploit, and the RunZero acquisition Why RunZero merged with Dragos and the AI hype cycle The problem of unmanaged network assets and shadow IT OT security risks: HVAC, BACnet, and protocol gateway discovery Chaining serial/IP connections and finding hidden devices UPnP firewall holes and Shodan data gaps The untenability of traditional vulnerability management OpenBMC vulnerabilities and vendor disclosure failures AI-driven bug finding and the shift to asset visibility Defensive strategies: Honeypots and AI agent detection 2003 Metasploit release vs. current AI open-source debate New RunZero features: Safe active scanning of OT environments Interactive 3D network mapping and non-IP protocol discovery AI Integration Generator: Building custom connectors Scripting engine capabilities: WMI, IPMI, and Modbus BYOK (Bring Your Own Key) and self-reflective codebase MCP implementation: Context window optimization and usage MCP deployment, permissions, and OAuth scoping Iterative AI prompt engineering for better results Balancing custom AI reports with opinionated dashboards
Listen ad-free on Castria