Skip to main content
Suzu Logo
  • Home
  • Product
  • Our Solutions
    • AI Advisory
    • AI Assessment
    • AI Integration
    • Cybersecurity Services
  • About
    • About Us
    • FAQ's
  • Resources
    • Blog
    • In The Media
    • Podcasts
    • All Resources
Contact Us
Back to Blog
Cybersecurity CTF AIAgent Penetration Testing Simply Offensive InfoSec

Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell

Phillip Wylie March 03, 2026 4 min read
Table of Contents

    In this thought-provoking episode of Simply Offensive, host Philip Wylie sits down with Jacob Krell, a penetration tester and researcher at Suzu Labs. Jacob recently authored a white paper titled The Death of the CTF, exploring how the rapid rise of agentic AI is fundamentally altering the landscape of Capture The Flag (CTF) competitions and the broader security industry.

    From 17% decreases in solve times to the emergence of "Hacking as a Service," this conversation is a wake-up call for anyone in the field.

    The Data: A 17% Year-Over-Year Crunch

    Jacob’s research into over 500 Hack The Box machines revealed a startling trend: a roughly 17% year-over-year decrease in "Root First Blood" times [02:16].

    While player skills are naturally improving, Jacob argues that AI is the real driver behind this acceleration. He describes the current state of CTFs as reaching a "reckoning point" where the traditional human-only infrastructure can no longer keep up with the scale of AI.

    AI as a Force Multiplier

    Jacob doesn't view AI as a replacement for the hacker, but as a massive "force multiplier."

      • Cognitive Offloading: Instead of manually researching CVEs or SSH version numbers, Jacob uses AI to handle the reconnaissance and research.
      • This allows him to focus his "human" brainpower on higher-level strategy and complex problem-solving.
      • Agentic Hacking: Jacob has moved beyond simple scripts to using agents that can execute entire workflows—from port scanning with Nmap to full privilege escalation enumeration.
      • System Engineering: The role of the pentester is shifting from being a manual "operator" to a "system engineer" who pilots and directs these AI agents.

    The End of the Human Benchmark?

    For decades, CTFs have been the gold standard for measuring human technical competence. Jacob believes that era is ending.

      • The "Calculator" Analogy: Just as calculators didn't stop people from learning math but changed how we do it, AI is changing the benchmark for security skills.
      • Anti-Cheat vs. AI-Buttons: Jacob suggests platforms may need to take a cue from online chess by implementing anti-AI detection or, alternatively, providing an "I solved this with AI" button to track metrics accurately.
      • Nation-State Benchmarking: In the future, global CTF platforms could serve as battlegrounds to benchmark the AI capabilities of different nations (e.g., how America's Claude performs against China's DeepSeek).

    Real-World Risks: Hacking as a Service

    The implications of Jacob's research extend far beyond the lab.

      • Exploding Threat Profiles: With AI agents, a malicious actor can set up a system to scan and exploit vulnerable internet-facing services in minutes.
      • Commercialized Malice: Jacob predicts a shift from "Ransomware as a Service" to "Hacking as a Service," where attackers sell pre-configured AI agents and "cursor rules" to automate complex breaches.
      • The Death of Attribution: If an agent spawns another agent to carry out an attack, determining legal responsibility and attribution becomes a nightmare for policymakers.

    Jacob’s Advice for the Next Generation

    Despite the "death" of the traditional CTF, Jacob remains technology-forward.

    • Learn the Fundamentals: You still need to understand how to do things manually for when the "calculator" goes wrong.
    • Personalized Tutoring: Use AI as an on-staff tutor to explain complex topics like multi-vector calculus or binary exploitation.
    • Focus on Systems: When solving a problem, don't just ask "how do I fix this?" Ask "how can I solve this so I never have to deal with it again?".

    Resources Mentioned:

    • Jacob Krell’s White Paper: Look for it on the Suzu Labs website.
    • Hack The Box Academy: Jacob’s top recommendation for hands-on keyboard learning.
    • Project Artemis (Stanford) & DARPA AI Cyber Challenge: Real-world examples of agentic hacking frameworks.

    Watch the full episode: AI Killed the CTF Star with Jacob Krell


    Tags: Cybersecurity CTF AIAgent Penetration Testing Simply Offensive InfoSec
    Phillip Wylie
    Phillip Wylie
    ← Previous Anthropic and Claude: 2026 AI Powerhouse Next → The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking

    Latest Posts

    View All
    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time
    Critical Infrastructure
    Mar 13, 2026 Denis Calderone

    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time

    On March 12, medical technology giant Stryker confirmed a cyberattack that wiped devices across 79 countries. The ...

    Read More
    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation
    Social Engineering
    Mar 09, 2026 Suzu Labs Intelligence

    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation

    Executive Summary Even Realities markets its G2 smart glasses as the privacy-conscious alternative to Meta Ray-Bans. ...

    Read More
    The Company Reviewing Your Meta Glasses Footage Has a Security Problem
    Threat Intelligence
    Mar 06, 2026 Mike Bell

    The Company Reviewing Your Meta Glasses Footage Has a Security Problem

    Last week, Swedish journalists revealed that Meta sends video footage from Meta Ray-Ban smart glasses to human data ...

    Read More
    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
    CTF
    Mar 03, 2026 Jacob Krell

    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking

    View White Paper Abstract: Agentic AI systems are compressing competitive hacking timelines faster than the ...

    Read More
    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell
    Cybersecurity
    Mar 03, 2026 Phillip Wylie

    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell

    In this thought-provoking episode of Simply Offensive, host Philip Wylie sits down with Jacob Krell, a penetration ...

    Read More
    Anthropic and Claude: 2026 AI Powerhouse
    Supply Chain Security
    Feb 26, 2026 Hannah Perez

    Anthropic and Claude: 2026 AI Powerhouse

    In early 2026, the image of Anthropic as a cautious, safety-oriented "research lab" has effectively been replaced by ...

    Read More
    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle
    Cybersecurity
    Feb 24, 2026 Phillip Wylie

    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle

    In this episode of Simply Offensive, host Philip Wylie welcomes Darius Houle, an Application Security (AppSec) and ...

    Read More
    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown
    Cybersecurity
    Feb 17, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown

    In the latest episode of the Simply Offensive podcast, host Philip Wylie sat down with Matt Brown, a renowned hardware ...

    Read More
    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs
    Cybersecurity
    Feb 12, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs

    In today’s rapidly evolving technological landscape, the convergence of artificial intelligence (AI) and cybersecurity ...

    Read More
    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss
    Threat Intelligence
    Feb 10, 2026 Phillip Wylie

    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss

    Beyond the Pentest: Why Adversarial Emulation is the Future of Defensive Training Many organizations operate under the ...

    Read More
    Under Armour Breach: What The Forum Data Actually Shows
    Threat Intelligence
    Jan 30, 2026 Mike Bell

    Under Armour Breach: What The Forum Data Actually Shows

    On January 18, 2026, the Everest ransomware group made good on their threat and released Under Armour customer data to ...

    Read More
    Brightspeed Breach: Crimson Collective and the Infostealer Problem
    Threat Intelligence
    Jan 20, 2026 Mike Bell

    Brightspeed Breach: Crimson Collective and the Infostealer Problem

    Recently Crimson Collective claimed they breached Brightspeed and grabbed 1 million+ customer records. The list of data ...

    Read More
    When Grid Data Goes Dark Web
    Power Grid
    Jan 19, 2026 Mike Bell

    When Grid Data Goes Dark Web

    Inside a threat actor's critical infrastructure targeting In January 2026, 139 gigabytes of engineering data from a ...

    Read More
    The $150,000 Password
    Critical Infrastructure
    Jan 19, 2026 Mike Bell

    The $150,000 Password

    How one threat actor turned stolen credentials into a global breach portfolio Between December 2025 and January 2026, a ...

    Read More
    Logo copy 3-1

    Fortified Security. Intelligent Innovation.

    +1 (702) 766-6257
    P.O. Box 750111
    Las Vegas, Nevada 89136

    Follow Us

    About

    • About Us
    • Contact

    Solutions

    • Products
    • AI Advisory
    • AI Assessment
    • Cybersecurity

    Resources

    • Insights
    • In The Media
    • Podcasts
    © 2026 All rights reserved.
    • Privacy Policy
    • Terms & Conditions