Joel de la Garza
Showing 1–8 of 8 transcripts.
- a16z24 min
AI Is Learning to Hack. Faster Than We Expected.
Joel De La Garza, Dylan Ayrey, Feross Aboukhadijeh
Frontier AI models are actively executing sophisticated supply chain attacks by exploiting under-resourced package registries like NPM and leveraging leaked credentials to self-propagate malware. This shift, driven by explicit training on cybersecurity challenges, has accelerated the attack lifecycle to outpace traditional patching, prompting industry responses such as NPM's mandate for human-interactive authentication by 2027. Despite these defensive measures, a critical consensus remains that the industry must address the moral obligations of model labs and the unsustainable reliance on volunteer maintainers to prevent 2026 from becoming the defining year of automated software compromise.
- a16z24 min
AI is Revolutionizing Web Security - Bots, Agents, & Real-Time Defense
David Mytton, Joel de la Garza
As automated bot traffic approaches 50% of global internet activity, security experts are transitioning from coarse network-level blocking to granular, application-aware filtering that distinguishes between malicious actors and legitimate AI agents. This evolution leverages advanced fingerprinting, digital signatures, and local edge inference to identify specific bot behaviors, such as training crawlers versus real-time task executors, without inadvertently rejecting revenue-generating discovery traffic. Consequently, the industry anticipates reduced click spam and improved site discoverability as AI-driven agents increasingly adhere to standardized protocols over the coming 18 months.
- a16z23 min
How to spot an AI Deepfake
Over 90% of security attacks now target human behavior, with AI-driven social engineering tactics like deepfakes and voice cloning surging to affect millions globally and enable sophisticated impersonations of corporate leaders and government officials. Experts warn that while current losses are financial, these threats pose imminent risks to critical infrastructure and human safety, driven by open-source models that allow adversaries to automate attacks without significant cost barriers. To counter this evolving landscape, organizations must shift from static compliance training to continuous, adaptive simulations and deploy defensive AI agents capable of countering automated offensive operations.
- a16z21 min
Avoiding vulnerabilities in AI code
Recent AI advancements have led to the adoption of AI-generated code in 20% of enterprise codebases, though research highlights critical security vulnerabilities such as hardcoded secrets and insecure patterns. To address the alignment challenge, organizations currently rely on techniques like data curation and Constitutional AI, yet these methods face trade-offs between safety and functional utility in data science workflows. Consequently, industry experts recommend that medium-to-large teams maintain a human-in-the-loop "buddy system" for code auditing until autonomous security governance tools mature, rather than removing human review processes.
- a16z15 min
How to use DeepSeek safely
Security audits recommend against deploying DeepSeek in production environments due to its volatile stability, significantly weaker jailbreak resistance compared to GPT models, and insecure underlying infrastructure. The model enforces heavy censorship on Chinese political topics while exhibiting operational inefficiencies such as slow inference speeds and language errors, prompting experts to suggest restricting its use to non-end-user-facing applications if absolutely necessary. Industry observers anticipate a more stable, secure open-source alternative utilizing similar reasoning techniques will soon replace the current unstable variant.
- a16z17 min
Security Markets: The Lay of the Land
This presentation critiques the current cybersecurity landscape as a flawed ecosystem where misaligned incentives and security-by-attachment fail to address root causes like human error and misconfiguration. Despite billions in venture capital, experts highlight that 93% of breaches stem from preventable mistakes rather than sophisticated malware, driving a market shift toward zero trust architectures and native security models exemplified by Apple and Google. Looking forward, the industry anticipates a transition to an all-cloud environment where traditional data centers shrink and blockchain facilitates threat intelligence sharing through standardized compliance and cyber insurance mechanisms.
- a16z36 min
a16z Podcast | The Business of Cybercrime
Joel de la Garza, Jonathan Lusthaus, Hanne Tidnam, Hannah
Based on seven years of field research by academic Jonathan Lusthaus, the cybercrime industry has evolved from isolated hacking into a sophisticated, profit-driven global market characterized by specialized roles and corporate-like structures. This ecosystem leverages cryptocurrency for anonymous transactions and utilizes a transnational division of labor where technical talent from former Soviet states supports cash-out operations in Western nations. While recruitment often targets uneducated intermediaries or disaffected STEM graduates, the sector's core dynamics now rely on trust-based branding and have shifted toward extortion as traditional credential theft faces increased defenses.
- a16z17 min
a16z Podcast | The State of Security
Joel de la Garza, Niels Provos, Martin Casado
This event analyzes the critical convergence of cyber, physical, and national security driven by state actors targeting infrastructure destruction rather than mere data theft. Panelists highlight that while hardware-rooted authentication has eliminated phishing success at organizations like Google, the human element remains the primary vulnerability requiring continuous training and strict credential management. Strategic recommendations include adopting hardware security keys, leveraging cloud providers for superior security postures, and utilizing regulatory frameworks like GDPR to shift the industry's incentive model toward proactive risk mitigation.