Summary
The core message of the session is that adversarial AI in cyber operations is moving so quickly that security teams can fall behind after even a short break, and the practical value of the talk is to compress current actor behavior into a structured story. The speaker opens with a humorous contrast between relaxing experiences—oceans, yoga, kittens, puppies—and the decidedly non-relaxing flow of AI and cybersecurity news. Using a “non scientific analysis” of OSINT pipeline material, the speaker says that around one quarter of the reviewed weekly news volume was associated with AI in cybersecurity, creating “a ton of noise” that makes it difficult for defenders to know what matters before it feels too late. The presentation is framed as findings drawn from incident response, global actor tracking, and additional research sources.
Key Topics
5 key topics from Daniel Kapellmann Zafra at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Separate adversarial AI use from attacks on AI infrastructure.
- Track actor behavior across the full cyberattack lifecycle.
- Prioritize N-day exposure windows after vulnerability disclosure.
- Prepare controls for agentic systems making autonomous decisions.
- Treat knowledge-file sharing as an emerging exploit-distribution pattern.
“The LLM is no longer a passive advisor.”

Daniel Kapellmann Zafra
Technology Strategy Lead•Google
Up Next



Next in agenda
Panel on European cyber security skills

Also on threat intelligence
Beneath Arrakis:Unmasking Hydra Saiga's Covert Operation
Pol Thill

Also on threat intelligence
